WO2023212904A1 - 中继通信的方法及设备 - Google Patents
中继通信的方法及设备 Download PDFInfo
- Publication number
- WO2023212904A1 WO2023212904A1 PCT/CN2022/091126 CN2022091126W WO2023212904A1 WO 2023212904 A1 WO2023212904 A1 WO 2023212904A1 CN 2022091126 W CN2022091126 W CN 2022091126W WO 2023212904 A1 WO2023212904 A1 WO 2023212904A1
- Authority
- WO
- WIPO (PCT)
- Prior art keywords
- terminal device
- key
- message
- information
- signature
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Ceased
Links
Images
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W12/00—Security arrangements; Authentication; Protecting privacy or anonymity
- H04W12/08—Access security
Definitions
- Embodiments of the present application relate to the field of communications, and more specifically, to a method and device for relaying communications.
- Embodiments of the present application provide a method and device for relay communication, which can ensure the security of terminal identities and the confidentiality and integrity of communication data, thereby ensuring the confidentiality and integrity of data transmitted by both parties and preventing other devices and even relay devices from of eavesdropping.
- a method for relaying communication which method includes:
- the first terminal device receives the authentication request message sent by the second terminal device through the relay device;
- the authentication request message includes at least one of the following: information about the user to which the second terminal device belongs, information about the user to which the relay device belongs, the first temporary public key generated by the second terminal device, Signature, the signature of the relay device, and relevant information of the relay device;
- the information about the user to whom the second terminal device belongs includes the signature certificate of the second terminal device, or the information about the user to whom the second terminal device belongs includes the identification of the second terminal device and the PVT and KPAK of the second terminal device.
- the information of the user of the relay device includes the signature certificate of the relay device, or the information of the user of the relay device includes the identification of the relay device and the PVT and KPAK of the relay device;
- the input parameters of the signature include at least one of the following: the information of the user to which the second terminal device belongs and the first temporary public key;
- the input parameters of the signature of the relay device include at least one of the following: the signature of the second terminal device and the information of the user to which the relay device belongs; the first temporary public key and the relevant information of the relay device are used for the first terminal device to derive the first key;
- the relevant information of the relay device includes one of the following: the The identity information of the relay device, the random number generated by the relay device, and the counter generated by the relay
- a method for relaying communication which method includes:
- the second terminal device sends an authentication request message to the first terminal device through the relay device;
- the authentication request message includes at least one of the following: information about the user to which the second terminal device belongs, the first temporary public key generated by the second terminal device, the signature of the second terminal device, and relevant information about the relay device. ;
- the information about the user to whom the second terminal device belongs includes the signature certificate of the second terminal device, or the information about the user to whom the second terminal device belongs includes the identification of the second terminal device and the PVT and KPAK of the second terminal device.
- the input parameters of the signature of the second terminal device include at least one of the following: information about the user to which the second terminal device belongs and the first temporary public key; related information about the first temporary public key and the relay device for The first terminal device derives a first key; the relevant information of the relay device includes one of the following: identity information of the relay device, a random number generated by the relay device, and a counter generated by the relay device.
- a method for relaying communication which method includes:
- the relay device receives an authentication request message sent by the second terminal device; wherein the authentication request message includes at least one of the following: information about the user to which the second terminal device belongs, the first temporary public key generated by the second terminal device, the The signature of the second terminal device; wherein the information about the user to whom the second terminal device belongs includes the signature certificate of the second terminal device, or the information about the user to whom the second terminal device belongs includes the identification of the second terminal device and the third terminal device.
- the PVT and KPAK of the second terminal device; the input parameters of the signature of the second terminal device include at least one of the following: the information of the user to which the second terminal device belongs and the first temporary public key; the first temporary public key and the middle
- the relevant information of the relay device is used by the first terminal device to derive the first key
- the relay device sends a verified authentication request message to the first terminal device; wherein, the verification
- the subsequent authentication request message includes at least one of the following: information about the user to whom the second terminal device belongs, information about the user to whom the relay device belongs, the first temporary public key, the signature of the second terminal device, the signature of the relay device.
- Signature relevant information of the relay device; wherein, the information of the user to which the relay device belongs includes the signature certificate of the relay device, or the information of the user to which the relay device belongs includes the identification of the relay device and the relay device.
- the fourth aspect provides a method for relaying communication, which method includes:
- the first terminal device sends the first message to the second terminal device through the relay device;
- the first message includes at least one of the following: security capability information of the first terminal device, security policy information of the first terminal device, information of the user to which the first terminal device belongs, a third message generated by the first terminal device.
- security capability information of the first terminal device security policy information of the first terminal device
- information of the user to which the first terminal device belongs a third message generated by the first terminal device.
- the information about the user to whom the first terminal device belongs includes the signature certificate of the first terminal device, or the information about the user to whom the first terminal device belongs includes the identification of the first terminal device and the PVT and KPAK of the first terminal device.
- the input parameters of the signature of the first terminal device include at least one of the following: information of the user to which the first terminal device belongs, the second temporary public key, M bits of the identification of the first key, the second The signature of the terminal device;
- the first message is integrity protected by the first message verification code generated based on the first key
- the input parameters of the first message verification code include at least one of the following: the security capability of the first terminal device Information, the security policy information of the first terminal device, the information of the user to which the first terminal device belongs, the first random number, the second temporary public key, the M bits, and the signature of the first terminal device;
- the second temporary public key and the relevant information of the relay device are used by the second terminal device to derive the first key, the first random number, the first key and the third key generated by the second terminal device.
- Two random numbers are used to derive a second key.
- the second key is used to derive an integrity protection key and/or a confidentiality protection key.
- the identity of the first key is composed of the M bits and the first
- the other N bits of the key's identification are combined, and M and N are both positive integers;
- the relevant information of the relay device includes one of the following: the identity information of the relay device, the random number generated by the relay device, Counter generated by this relay device.
- the fifth aspect provides a method for relaying communication, which method includes:
- the second terminal device receives the first message sent by the first terminal device through the relay device;
- the first message includes at least one of the following: security capability information of the first terminal device, security policy information of the first terminal device, information of the user to which the first terminal device belongs, and information of the user to which the relay device belongs. , the first random number generated by the first terminal device, the second temporary public key generated by the first terminal device, the M bits of the identification of the first key generated by the first terminal device, the first terminal device signature, the signature of the relay device, and the first message verification code;
- the information about the user to whom the first terminal device belongs includes the signature certificate of the first terminal device, or the information about the user to whom the first terminal device belongs includes the identification of the first terminal device and the public verification command of the first terminal device.
- brand PVT and the public authentication key KPAK of the key management server the information of the user of the relay device includes the signature certificate of the relay device, or the information of the user of the relay device includes the identification of the relay device and the PVT and KPAK of the relay device
- the input parameters of the signature of the first terminal device include at least one of the following: information of the user to which the first terminal device belongs, the second temporary public key, and the identification M of the first key bits, the signature of the second terminal device
- the input parameters of the signature of the relay device include at least one of the following: information of the user to which the relay device belongs, the signature of the first terminal device, the signature of the second terminal device sign;
- the first message is integrity protected by the first message verification code generated based on the first key
- the input parameters of the first message verification code include at least one of the following: the security capability of the first terminal device Information, the security policy information of the first terminal device, the information of the user to which the first terminal device belongs, the information of the user to which the relay device belongs, the first random number, the second temporary public key, the M bits, The signature of the first terminal device and the signature of the relay device;
- the second temporary public key and the relevant information of the relay device are used by the second terminal device to derive the first key, the first random number, the first key and the third key generated by the second terminal device.
- Two random numbers are used to derive a second key.
- the second key is used to derive an integrity protection key and/or a confidentiality protection key.
- the identity of the first key is composed of the M bits and the first
- the other N bits of the key's identification are combined, and M and N are both positive integers;
- the relevant information of the relay device includes one of the following: the identity information of the relay device, the random number generated by the relay device, Counter generated by this relay device.
- a sixth aspect provides a method for relaying communications, which method includes:
- the relay device receives the first message sent by the first terminal device; wherein the first message includes at least one of the following: security capability information of the first terminal device, security policy information of the first terminal device, Information about the user to whom the device belongs, the first random number generated by the first terminal device, the second temporary public key generated by the first terminal device, M bits of the identification of the first key generated by the first terminal device, The signature of the first terminal device, the first message verification code; wherein the information of the user to which the first terminal device belongs includes the signature certificate of the first terminal device, or the information of the user to which the first terminal device belongs includes the first The identification of the terminal device and the PVT and KPAK of the first terminal device; the input parameters of the signature of the first terminal device include at least one of the following: information of the user to which the first terminal device belongs, the second temporary public key, the third M bits of the identification of a key, the signature of the second terminal device; wherein the first message is integrity protected by the first message verification code generated based on the first key, and the first message The input
- the communication unit is also used to send the first message after verification to the second terminal device; wherein, The first message after the verification includes at least one of the following: security capability information of the first terminal device, security policy information of the first terminal device, information of the user to which the first terminal device belongs, information of the user to which the relay device belongs.
- the information of the user to which the relay device belongs includes the relay device
- the signature certificate of the relay device, or the information of the user to which the relay device belongs includes the identification of the relay device and the PVT and KPAK of the relay device
- the input parameters of the signature of the relay device include at least one of the following: the relay device The information of the user, the signature of the first terminal device, the signature of the second terminal device, and the first message after verification;
- the second temporary public key and the relevant information of the relay device are used by the second terminal device to derive the first key, the first random number, the first key and the third key generated by the second terminal device.
- Two random numbers are used to derive a second key.
- the second key is used to derive an integrity protection key and/or a confidentiality protection key.
- the identity of the first key is composed of the M bits and the first
- the other N bits of the key's identification are combined, and M and N are both positive integers;
- the relevant information of the relay device includes one of the following: the identity information of the relay device, the random number generated by the relay device, Counter generated by this relay device.
- a seventh aspect provides a terminal device for executing the method in the first aspect.
- the terminal device includes a functional module for executing the method in the first aspect.
- An eighth aspect provides a terminal device for executing the method in the second aspect.
- the terminal device includes a functional module for executing the method in the above second aspect.
- a ninth aspect provides a relay device for performing the method in the above third aspect.
- the relay device includes a functional module for executing the method in the above third aspect.
- a tenth aspect provides a terminal device for executing the method in the fourth aspect.
- the terminal device includes a functional module for executing the method in the fourth aspect.
- An eleventh aspect provides a terminal device for performing the method in the fifth aspect.
- the terminal device includes a functional module for executing the method in the fifth aspect.
- a twelfth aspect provides a relay device for performing the method in the above-mentioned sixth aspect.
- the relay device includes a functional module for executing the method in the sixth aspect.
- a terminal device including a processor and a memory; the memory is used to store a computer program, and the processor is used to call and run the computer program stored in the memory, so that the terminal device executes the above first aspect Or the method in the second aspect, or causing the terminal device to perform the method in the fourth or fifth aspect.
- a relay device including a processor and a memory; the memory is used to store a computer program, and the processor is used to call and run the computer program stored in the memory, so that the relay device executes the above-mentioned first step.
- a fifteenth aspect provides a device for implementing the method in any one of the above-mentioned first to sixth aspects.
- the device includes: a processor, configured to call and run a computer program from a memory, so that a device installed with the device executes the method in any one of the above-mentioned first to sixth aspects.
- a sixteenth aspect provides a computer-readable storage medium for storing a computer program, the computer program causing a computer to execute the method in any one of the above-mentioned first to sixth aspects.
- a computer program product including computer program instructions, which cause a computer to execute the method in any one of the above-mentioned first to sixth aspects.
- An eighteenth aspect provides a computer program that, when run on a computer, causes the computer to execute the method in any one of the above-mentioned first to sixth aspects.
- the first terminal device can generate the first key based on the authentication request message sent by the second terminal device through the relay device, and the authentication request message is protected through signature verification. . and a first random number generated by the first terminal device, a first key and a second random number generated by the second terminal device for deriving a second key, the second key being used for deriving an integrity protection key and/or
- the confidentiality protection key can ensure the identity security of the first terminal device and the second terminal device and the confidentiality and integrity of the communication data, thereby ensuring the confidentiality and integrity of the data transmitted by both parties and preventing other devices and even relay devices from being intercepted. tapping.
- the first random number and the first key generated by the first terminal device and the second random number generated by the second terminal device are used to derive the second key.
- the key is used to derive the integrity protection key and/or the confidentiality protection key, which can ensure the identity security of the first terminal device and the second terminal device and the confidentiality and integrity of the communication data, thereby ensuring the confidentiality of the data transmitted by both parties. and integrity to prevent eavesdropping by other devices or even relay devices.
- Figure 1 is a schematic diagram of a communication system architecture applied in an embodiment of the present application.
- Figures 2 to 4 are respectively schematic flow charts for establishing secure communication in the UE-to-UE relay scenario provided by this application.
- FIG. 5 is a schematic flow chart of L3 relay communication provided by this application.
- Figure 6 is a schematic flowchart of a method for relaying communications provided according to an embodiment of the present application.
- Figure 7 is a schematic diagram of the key hierarchical structure involved in the embodiment of the present application.
- Figure 8 is a schematic flowchart of another method of relaying communications provided according to an embodiment of the present application.
- Figure 9 is a schematic flowchart of yet another method of relaying communication provided according to an embodiment of the present application.
- Figure 10 is a schematic flowchart of yet another method of relaying communication provided according to an embodiment of the present application.
- Figure 11 is a schematic flowchart of yet another method of relaying communication provided according to an embodiment of the present application.
- Figure 12 is a schematic flowchart of yet another method of relaying communication provided according to an embodiment of the present application.
- Figures 13 to 15 are respectively schematic flowcharts for establishing secure communication in a UE-to-UE relay scenario provided by embodiments of the present application.
- Figure 16 is a schematic block diagram of a terminal device provided according to an embodiment of the present application.
- Figure 17 is a schematic block diagram of another terminal device provided according to an embodiment of the present application.
- Figure 18 is a schematic block diagram of a relay device provided according to an embodiment of the present application.
- Figure 19 is a schematic block diagram of yet another terminal device provided according to an embodiment of the present application.
- Figure 20 is a schematic block diagram of yet another terminal device provided according to an embodiment of the present application.
- Figure 21 is a schematic block diagram of another relay device provided according to an embodiment of the present application.
- Figure 22 is a schematic block diagram of a communication device provided according to an embodiment of the present application.
- Figure 23 is a schematic block diagram of a device provided according to an embodiment of the present application.
- Figure 24 is a schematic block diagram of a communication system provided according to an embodiment of the present application.
- GSM Global System of Mobile communication
- CDMA Code Division Multiple Access
- WCDMA Wideband Code Division Multiple Access
- GPRS General Packet Radio Service
- LTE Long Term Evolution
- LTE-A Advanced long term evolution
- NR New Radio
- NTN Non-Terrestrial Networks
- UMTS Universal Mobile Telecommunication System
- WLAN Wireless Local Area Networks
- IoT Internet of Things
- WiT wireless fidelity
- 5G fifth-generation communication
- the communication system in the embodiments of the present application can be applied to a carrier aggregation (Carrier Aggregation, CA) scenario, a dual connectivity (Dual Connectivity, DC) scenario, or a standalone (Standalone, SA) scenario. ) network deployment scenario, or applied to Non-Standalone (NSA) network deployment scenario.
- Carrier Aggregation, CA Carrier Aggregation
- DC Dual Connectivity
- SA standalone
- NSA Non-Standalone
- the communication system in the embodiments of the present application can be applied to unlicensed spectrum, where the unlicensed spectrum can also be considered as shared spectrum; or, the communication system in the embodiments of the present application can also be applied to licensed spectrum, Among them, licensed spectrum can also be considered as unshared spectrum.
- the communication system in the embodiment of the present application can be applied to the FR1 frequency band (corresponding to the frequency band range 410MHz to 7.125GHz), can also be applied to the FR2 frequency band (corresponding to the frequency band range 24.25GHz to 52.6GHz), and can also be applied to The new frequency band, for example, corresponds to the frequency band range of 52.6 GHz to 71 GHz or the high frequency band corresponding to the frequency band range of 71 GHz to 114.25 GHz.
- the embodiments of this application describe various embodiments in combination with network equipment and terminal equipment.
- the terminal equipment may also be called user equipment (User Equipment, UE), access terminal, user unit, user station, mobile station, mobile station, remote station, remote terminal, mobile device, user terminal, terminal, wireless communication equipment, user agent or user device, etc.
- User Equipment User Equipment
- the terminal device can be a station (STATION, ST) in the WLAN, a cellular phone, a cordless phone, a Session Initiation Protocol (Session Initiation Protocol, SIP) phone, a wireless local loop (Wireless Local Loop, WLL) station, or a personal digital assistant.
- PDA Personal Digital Assistant
- handheld devices with wireless communication capabilities computing devices or other processing devices connected to wireless modems, vehicle-mounted devices, wearable devices, next-generation communication systems such as terminal devices in NR networks, or in the future Terminal equipment in the evolved Public Land Mobile Network (PLMN) network, etc.
- PLMN Public Land Mobile Network
- the terminal device can be deployed on land, including indoor or outdoor, handheld, wearable or vehicle-mounted; it can also be deployed on water (such as ships, etc.); it can also be deployed in the air (such as aircraft, balloons and satellites). superior).
- the terminal device may be a mobile phone (Mobile Phone), a tablet computer (Pad), a computer with a wireless transceiver function, a virtual reality (Virtual Reality, VR) terminal device, or an augmented reality (Augmented Reality, AR) terminal.
- Equipment wireless terminal equipment in industrial control, wireless terminal equipment in self-driving, wireless terminal equipment in remote medical, wireless terminal equipment in smart grid , wireless terminal equipment in transportation safety, wireless terminal equipment in smart city (smart city) or wireless terminal equipment in smart home (smart home), vehicle-mounted communication equipment, wireless communication chip/application specific integrated circuit (ASIC)/system on chip (System on Chip, SoC), etc.
- ASIC application specific integrated circuit
- the terminal device may also be a wearable device.
- Wearable devices can also be called wearable smart devices. It is a general term for applying wearable technology to intelligently design daily wear and develop wearable devices, such as glasses, gloves, watches, clothing and shoes, etc.
- a wearable device is a portable device that is worn directly on the body or integrated into the user's clothing or accessories. Wearable devices are not just hardware devices, but also achieve powerful functions through software support, data interaction, and cloud interaction.
- wearable smart devices include full-featured, large-sized devices that can achieve complete or partial functions without relying on smartphones, such as smart watches or smart glasses, and those that only focus on a certain type of application function and need to cooperate with other devices such as smartphones.
- FIG. 1 exemplarily shows a communication system 100 to which the present application is applied.
- a first terminal device 110 and a second terminal device 120 communicate through a relay device 130.
- the communication system 100 may also include other devices, which are not limited in the embodiments of this application.
- the communication device may include a first terminal device 110, a second terminal device 120 and a relay device 130 with communication functions.
- the first terminal device 110 and the second terminal device 120 may be The specific equipment mentioned above will not be described again here.
- the relay device 130 in the embodiment of this application may be a terminal device or a network device.
- the network device can be a device used to communicate with mobile devices.
- the network device can be an access point (AP) in WLAN, a base station (Base Transceiver Station, BTS) in GSM or CDMA, or it can be WCDMA
- the base station (NodeB, NB) in LTE can also be the evolutionary base station (Evolutional Node B, eNB or eNodeB) in LTE, or a relay station or access point, or a vehicle-mounted device, a wearable device, and a network device in an NR network, or Base station (gNB) or network equipment in the future evolved PLMN network or network equipment in the NTN network, etc.
- AP access point
- BTS Base Transceiver Station
- BTS Base Transceiver Station
- gNB Base station
- the relay device 130 may be a network device, and the network device may have mobile characteristics.
- the network device may be a mobile device.
- network devices may be satellites or balloon stations.
- the satellite can be a low earth orbit (LEO) satellite, a medium earth orbit (MEO) satellite, a geosynchronous orbit (geostationary earth orbit, GEO) satellite, a high elliptical orbit (High Elliptical Orbit, HEO) satellite ) satellite, etc.
- the network device may also be a base station installed on land, water, or other locations.
- the relay device 130 may be a network device, and the network device may provide services for a cell.
- the terminal device communicates with the network device through the transmission resources (for example, frequency domain resources, or spectrum resources) used by the cell.
- the cell can be a cell corresponding to a network device (such as a base station).
- the cell can belong to a macro base station or a base station corresponding to a small cell.
- the small cell here can include: urban cell (Metro cell), micro cell Micro cell, Pico cell, Femto cell, etc. These small cells have the characteristics of small coverage and low transmit power, and are suitable for providing high-rate data transmission services.
- the first terminal device may be a mobile phone, a machine facility, a Customer Premise Equipment (CPE), industrial equipment, a vehicle, etc.; the second terminal device may be the first terminal device.
- CPE Customer Premise Equipment
- Peer communication equipment of terminal equipment such as mobile phones, industrial equipment, vehicles, etc.
- the "instruction” mentioned in the embodiments of this application may be a direct instruction, an indirect instruction, or an association relationship.
- a indicates B which can mean that A directly indicates B, for example, B can be obtained through A; it can also mean that A indirectly indicates B, for example, A indicates C, and B can be obtained through C; it can also mean that there is an association between A and B. relation.
- correlate can mean that there is a direct correspondence or indirect correspondence between the two, it can also mean that there is an associated relationship between the two, or it can mean indicating and being instructed, configuration and being. Configuration and other relationships.
- predefinition or “preconfiguration” can be achieved by pre-saving corresponding codes, tables or other methods that can be used to indicate relevant information in devices (for example, including terminal devices and network devices).
- devices for example, including terminal devices and network devices.
- predefined can refer to what is defined in the protocol.
- the "protocol” may refer to a standard protocol in the communication field, which may include, for example, LTE protocol, NR protocol, and related protocols applied in future communication systems. This application does not limit this.
- the current stage mainly includes the following three solutions.
- Solution 1 uses asymmetric encryption technology to protect communication between the source UE and the target UE. Based on the mutual authentication of the source UE and the target UE, and assuming that the relay is trustworthy, a connection is established between the source UE and the target UE, and the public keys of both parties are used to protect end-to-end security.
- Option 2 the security establishment process between UE1 and UE2 in the UE-to-UE relay scenario.
- UE1 and UE2 establish PC5 connections with relay device 1 (relay 1) respectively, and then assume that UE1 and UE2 The shared key and key ID are configured.
- UE1 sends a message verification code (Message Authentication Code, MAC) to UE2 through relay device 1.
- MAC message Authentication Code
- remote UE1 and remote UE2 establish secure PC5 links with the relay device.
- Remote UE1, relay device, and remote UE2 are directly discovered by the 5G Name Management Network Element (Direct Discovering Name Management).
- Function, DDNMF DDNMF
- proximity communication service's key management network element Prose Key Management Function, PKMF
- the remote UE1 and the remote UE2 obtain the shared key (Identity, ID) and key from PKMF in advance.
- the UE (remote UE1 and remote UE2) and the relay device will also obtain the corresponding keys from PKMF and establish PC5 secure connections respectively.
- the shared key is used to establish a secure channel between the remote UE1 and the remote UE2.
- the 5G Layer-3 (L3) terminal and terminal relay (UE-to-UE Relay) based on Internet Protocol (Internet Protocol, IP) routing involved in this application
- IP Internet Protocol
- Proximity-based Services Proximity-based Services
- ProSe5G UE-to-UE Relay listens to the configured L2ID and responds with its address and corresponding information, enabling other UEs to establish unicast connections with the relay. Any terminal that wants to use ProSe 5G UE-to-UE Relay needs to establish a unicast L2 link with UE-to-UE Relay and configure IP. ProSe 5G UE-to-UE Relay assigns IP addresses/prefixes to other terminals. As part of the unicast L2 link establishment process, ProSe 5G UE-to-UE Relay combines the peer terminal user information of the unicast link (or the prose service provided by the peer terminal) and the IP address/prefix assigned to the terminal.
- ProSe 5G UE-to-UE Relay provides DNS servers for other terminals.
- the (source) UE needs to communicate with another (target) UE or needs to discover a prose service through the prose 5g UE-to-UE relay, it sends a DNS query to the target UE (based on the target user information) through the unicast link to the relay , the relay will return the IP address/prefix of the target endpoint.
- the source UE encapsulates IP data or non-IP data in an IP data packet and sends it to the relay through a unicast L2 connection.
- the relay will serve as a route for IP and send the IP data packet to the corresponding unicast L2 connection.
- Target UE Each unicast L2 connection acts as an IP interface.
- UE-to-UE relay scenario security communication solutions all have some flaws.
- the default relay is trustworthy, so there are restrictions on strong assumptions, and when the UE negotiates security capabilities, they are all clear text messages, which may suffer Tampering, in addition, the source and authenticity of the public key and the source of the communication key in Scheme 1 are not clear (for example, it is not determined whether to determine the source of the communication key through negotiation or one-way encryption), and it does not involve the use of public key technology.
- Key management solution. Solution 2 does not mention the process of preconfiguring the shared key, and the solution process is controversial. The process of option three is more complicated, has too many interactions, and is not light enough. Therefore, it is necessary to explore a simpler way to establish a secure connection without losing security, and explore a more efficient key management structure to ensure the confidentiality and integrity of UE identity security and communication data.
- this application proposes a relay communication solution that can ensure the security of the terminal identity and the confidentiality and integrity of the communication data, thereby ensuring the confidentiality and integrity of the data transmitted by both parties and preventing other devices and even relay devices from of eavesdropping.
- FIG. 6 is a schematic flowchart of a communication relay method 200 according to an embodiment of the present application. As shown in Figure 6, the communication relay method 200 may include at least part of the following content:
- the first terminal device receives the authentication request message sent by the second terminal device through the relay device; wherein the authentication request message includes at least one of the following: information about the user to which the second terminal device belongs, information about the user to whom the relay device belongs. information, the first temporary public key generated by the second terminal device, the signature of the second terminal device, the signature of the relay device, and relevant information of the relay device; wherein, the information of the user to which the second terminal device belongs includes The signature certificate of the second terminal device, or the information of the user to which the second terminal device belongs includes the identification of the second terminal device and the PVT and KPAK of the second terminal device; the information of the user to which the relay device belongs includes the The signature certificate of the relay device, or the information of the user to which the relay device belongs includes the identification of the relay device and the PVT and KPAK of the relay device; the input parameters of the signature of the second terminal device include at least one of the following: the The information of the user of the second terminal device and the first temporary public key; the input parameters of the signature of the second
- This embodiment is based on the ECCSI signature scheme to establish a secure connection in a UE-to-UE relay scenario under a layer 3 (L3) architecture.
- L3 layer 3
- the embodiments of this application are applied to the UE-to-UE relay scenario under the L3 architecture, that is, the first terminal device and the second terminal device communicate through the relay device.
- the relay connection between the first terminal device and the second terminal device may be a PC5 link.
- the first terminal device may be a source device or a source terminal
- the second terminal device may be a target device or a target terminal
- the relay device may be a relay terminal
- the input parameters of the signature of the second terminal device include at least one of the following: information of the user to which the second terminal device belongs and the first temporary public key. That is, the second terminal device may generate a signature of the second terminal device based on at least one of the information of the user to which the second terminal device belongs and the first temporary public key.
- the input parameters of the relay device's signature include at least one of the following: the signature of the second terminal device and the information of the user to which the relay device belongs. That is, the relay device may generate the signature of the relay device based on at least one of the signature of the second terminal device and the information of the user to which the relay device belongs.
- the signature of the second terminal device is generated by the signature private key of the second terminal device.
- the signing certificate and signing private key of the second terminal device may be pre-configured for the second terminal device through a secure channel by a trusted central key management server (Key Management Service, KMS).
- KMS trusted central key management server
- the secure channel can establish a secure connection between the second terminal device and the KMS based on the Authentication and Key Management for Applications (AKMA) mechanism or the Generic Bootstrapping Architecture (GBA) mechanism.
- AKMA Authentication and Key Management for Applications
- GBA Generic Bootstrapping Architecture
- the KMS can be managed directly by the operator or be a third-party service provider that has a commercial relationship with the operator.
- the information about the user to which the second terminal device belongs includes the identity of the second terminal device and the public verification token (Public Validation Token, PVT) of the second terminal device and the public authentication of the key management server.
- PVT Public Validation Token
- the signature of the second terminal device is generated by the Secret Signing Key (SSK) of the second terminal device.
- SSK Secret Signing Key
- the PVT, KPAK, and secret signature key (SSK) of the second terminal device may be pre-configured by the trusted center KMS for the second terminal device through a secure channel.
- the secure channel may be based on the AKMA mechanism or the GBA mechanism to establish a secure connection between the second terminal device and the KMS.
- the KMS may be directly managed by the operator or be a third-party service provider that has a commercial relationship with the operator.
- the signature of the relay device is generated by the signature private key of the relay device.
- the signing certificate and signing private key of the relay device may be pre-configured for the relay device by the trusted center KMS through a secure channel.
- the secure channel can be based on the AKMA mechanism or the GBA mechanism to establish a secure connection between the relay device and the KMS.
- the KMS can be directly managed by the operator or a third-party service provider that has a commercial relationship with the operator.
- the signature of the relay device is encrypted by the secret signature of the relay device.
- Key SSK
- the PVT, KPAK, and secret signature key (SSK) of the relay device may be pre-configured for the relay device by the trusted center KMS through a secure channel.
- the secure channel can be based on the AKMA mechanism or the GBA mechanism to establish a secure connection between the relay device and the KMS.
- the KMS can be directly managed by the operator or a third-party service provider that has a commercial relationship with the operator.
- the signature certificate of the second terminal device and the signature certificate of the relay device are valid, and the signature verification of the second terminal device based on the signature certificate of the second terminal device is successful, and based on the
- the signature certificate of the relay device successfully verifies the signature of the relay device
- the first terminal device generates a second temporary private key
- the first terminal device generates a second temporary private key based on the first temporary public key and the relevant information of the relay device. information and the second temporary private key to derive the first key.
- the first terminal device may verify the validity of the signature certificate of the second terminal device and the signature certificate of the relay device based on one or more signature certificates stored locally. For example, if there is a signature certificate consistent with the signature certificate of the second terminal device in the signature certificate stored locally on the first terminal device, the signature certificate of the second terminal device is valid; and the signature stored locally on the first terminal device If the certificate contains a signing certificate that is consistent with the signing certificate of the relay device, the signing certificate of the relay device is valid.
- one or more signature certificates stored locally on the first terminal device may be pre-configured by the KMS.
- the KPAK of the second terminal device and the KPAK of the relay device are valid, and the signature verification of the second terminal device based on the identity of the second terminal device and the PVT of the second terminal device is successful.
- the first terminal device generates a second temporary private key, and the first terminal device generates a second temporary private key according to the first terminal device.
- the first key is derived from a temporary public key, relevant information of the relay device and the second temporary private key.
- the first terminal device may verify the validity of the KPAK of the second terminal device and the KPAK of the relay device based on one or more KPAKs stored locally. For example, if there is a KPAK consistent with the KPAK of the second terminal device in the KPAK stored locally on the first terminal device, the KPAK of the second terminal device is valid; and there is a KPAK consistent with the KPAK stored locally on the first terminal device. In the case where the KPAK of the relay device is consistent with the KPAK, the KPAK of the relay device is valid.
- one or more KPAKs stored locally on the first terminal device may be preconfigured by the KMS.
- the first terminal device may derive the first secret key based on the first temporary public key generated by the second terminal device, the relevant information of the relay device, and the second temporary private key generated by the first terminal device.
- the relevant information of the relay device includes one of the following: identity information of the relay device, a random number generated by the relay device, and a counter generated by the relay device.
- the second terminal device may derive the first key based on the second temporary public key generated by the first terminal device, the relevant information of the relay device, and the first temporary private key generated by the second terminal device.
- the relevant information of the relay device includes one of the following: identity information of the relay device, a random number generated by the relay device, and a counter generated by the relay device.
- the first temporary public key generated by the second terminal device is paired with the first temporary private key generated by the second terminal device
- the second temporary public key generated by the first terminal device is paired with the second temporary private key generated by the first terminal device. pair.
- the first terminal device can calculate the first key based on the first temporary public key, relevant information of the relay device, and the second temporary private key using the ECIES algorithm; the second terminal device can calculate the first key based on the second temporary public key. , the relevant information of the relay device and the first temporary private key, and use the ECIES algorithm to calculate the first key.
- the first terminal device sends the first message to the second terminal device through the relay device;
- the first message includes at least one of the following: security capability information of the first terminal device, security policy information of the first terminal device, information of the user to which the first terminal device belongs, a third message generated by the first terminal device.
- security capability information of the first terminal device security policy information of the first terminal device
- information of the user to which the first terminal device belongs a third message generated by the first terminal device.
- a random number a second temporary public key generated by the first terminal device paired with the second temporary private key, M bits of the identification of the first key generated by the first terminal device, the first terminal Device signature, first message verification code;
- the information about the user to whom the first terminal device belongs includes the signature certificate of the first terminal device, or the information about the user to whom the first terminal device belongs includes the identification of the first terminal device and the PVT and KPAK of the first terminal device.
- the input parameters of the signature of the first terminal device include at least one of the following: information of the user to which the first terminal device belongs, the second temporary public key, M bits of the identification of the first key, the second The signature of the terminal device;
- the first message is integrity protected by the first message verification code generated based on the first key
- the input parameters of the first message verification code include at least one of the following: the security capability of the first terminal device Information, the security policy information of the first terminal device, the information of the user to which the first terminal device belongs, the first random number, the second temporary public key, the M bits, and the signature of the first terminal device;
- the second temporary public key and the relevant information of the relay device are used by the second terminal device to derive the first key, the first random number, the first key and the third key generated by the second terminal device.
- Two random numbers are used to derive a second key.
- the second key is used to derive an integrity protection key and/or a confidentiality protection key.
- the identity of the first key is composed of the M bits and the first The other N bits of the key's identifier are combined, and M and N are both positive integers.
- the first random number and the first key generated by the first terminal device and the second random number generated by the second terminal device are used to derive the second key. That is, the first terminal device derives the second key based on at least the first random number, the first key and the second random number, and the first terminal device can derive the integrity protection key and/or the secret based on the second key.
- the first terminal device can securely protect the sent message based on the integrity protection key and/or the confidentiality protection key.
- the second terminal device may derive the second key based on at least the first random number, the first key and the second random number, and the second terminal device may derive the integrity protection key and/or the secret based on the second key.
- the second terminal device can securely protect the sent message based on the integrity protection key and/or the confidentiality protection key.
- the input parameters of the first message verification code include at least one of the following: security capability information of the first terminal device, security policy information of the first terminal device, the first random number, the third 2.
- Temporary public key, the M bits that is, the first terminal device can be based on the security capability information of the first terminal device, the security policy information of the first terminal device, the first random number, the information of the user to which the first terminal device belongs, and the second temporary At least one of the public key, the M bits, and the signature of the first terminal device is used to generate the first message verification code.
- the input parameters of the first message verification code include: the security capability information of the first terminal device, the security policy information of the first terminal device, the first random number, and the information of the user to which the first terminal device belongs. , the second temporary public key, the M bits, and the signature of the first terminal device.
- the second terminal device may generate a first message verification based on the security capability information of the first terminal device, the security policy information of the first terminal device, the first random number, the second temporary public key, and the M bits. code and compare it with the first message verification code contained in the first message. If they are consistent, the first message verification code is valid.
- the first message is an authentication response message, or the first message is a safe mode command message.
- the security capability information of the first terminal device may be a list of cryptographic algorithms supported by the first terminal device.
- the security policy information of the first terminal device may be whether the first terminal device supports confidentiality protection or integrity protection.
- the security policy information of the first terminal device includes: the security policy information of the first terminal device on the control plane, and/or the security policy information of the first terminal device on the user plane.
- the M bits may be the highest M bits of the identity of the first key, and the N bits may be the lowest N bits of the identity of the first key; or, The M bits may be the first M bits of the identifier of the first key, and the N bits may be the last N bits of the identifier of the first key; or, the M bits may be are the even-numbered bits of the identifier of the first key, and the N bits may be the odd-numbered bits of the identifier of the first key.
- the values of M and N may be the same or different, which is not limited by this application.
- the first terminal device receives the second message sent by the second terminal device through the relay device;
- the second message includes at least one of the following: the second random number generated by the second terminal device, N bits of the identification of the first key generated by the second terminal device, x bits of the identifier of the generated second key, the security algorithm selected by the second terminal device, the security policy selected by the second terminal device, and the second message verification code;
- the second message is integrity protected through the second message verification code generated based on the second key, or the second message is integrity protected through the third integrity protection key generated based on the second key.
- the second message verification code performs integrity protection, and the input parameters of the second message verification code include at least one of the following: the second random number, the N bits, the x bits, and the second terminal device selected Security algorithm, the security policy selected by the second terminal device;
- the identifier of the second key is obtained by combining the x bits and the other y bits of the identifier of the second key, and both x and y are positive integers.
- the x bits may be the highest x bits of the identity of the second key, and the y bits may be the lowest y bits of the identity of the second key; or, The x bits may be the first x bits of the identifier of the second key, and the y bits may be the last y bits of the identifier of the second key; or, the x bits may be are the even-numbered bits of the identifier of the second key, and the y bits may be the odd-numbered bits of the identifier of the second key.
- the values of x and y may be the same or different, which is not limited by this application.
- the first terminal device if the information carried in the second message has not been tampered with, the first terminal device generates the second random number based on at least the first random number, the first key and the second random number. key, the first terminal device generates an integrity protection key and/or a confidentiality protection key based on the second key, and the first terminal device combines the M bits and the N bits to obtain the The identification of the first key, the first terminal device generates y bits of the identification of the second key, and combines the x bits and the y bits to obtain the identification of the second key;
- the first terminal device When the second message verification code is valid, the first terminal device generates an integrity protection key and/or a secret based on the security algorithm selected by the second terminal device, the second key, and the second key.
- the security protection key and the security policy selected by the second terminal device are used to communicate with the second terminal device.
- the input parameters of the second message verification code include: the second random number, the N bits, the x bits, the security algorithm selected by the second terminal device, the security strategy.
- the first terminal device may generate a second message verification code based on the second random number, the N bits, the x bits, the security algorithm selected by the second terminal device, and the security policy selected by the second terminal device. , and compared with the second message verification code contained in the second message. If they are consistent, the second message verification code is valid.
- the second message is encrypted by the first key, and the second message also includes a third message verification code
- the second message is integrity protected by the third message verification code generated based on the first key
- the input parameters of the third message verification code include at least one of the following: the second random number, the N bits, the x bits, the security algorithm selected by the second terminal device, and the security policy selected by the second terminal device.
- the second message may not be encrypted by the first key, or the second message may not be encrypted.
- the first terminal device decrypts the second message according to the first key; if the information carried in the second message is not tampered with, the first terminal device at least decrypts the second message according to the first random key. number, the first key and the second random number to generate the second key, the first terminal device generates an integrity protection key and/or a confidentiality protection key based on the second key, and the first The terminal device combines the M bits and the N bits to obtain the identity of the first key, the first terminal device generates y bits of the identity of the second key, and combines the x bits Combine with the y bits to obtain the identity of the second key;
- the first terminal device When the second message verification code and the third message verification code are valid, the first terminal device generates integrity based on the security algorithm selected by the second terminal device and the second key. The protection key and/or the confidentiality protection key and the security policy selected by the second terminal device are communicated with the second terminal device.
- the input parameters of the third message verification code include: the second random number, the N bits, the x bits, the security algorithm selected by the second terminal device, the security strategy.
- the first terminal device may generate a third message verification code based on the second random number, the N bits, the x bits, the security algorithm selected by the second terminal device, and the security policy selected by the second terminal device. , and compared with the third message verification code contained in the second message. If they are consistent, the third message verification code is valid.
- the second terminal device may select a security algorithm based on the security capability information of the first terminal device, and/or the second terminal device may select a security policy based on the security policy information of the first terminal device.
- the first terminal device may use the first random number, the first key, the second random number, the source identifier, the target identifier, the length of the first random number, the second random number. At least one of the length of the number, the length of the source identifier, and the length of the target identifier is used to generate the second key.
- the source identifier is used to identify the source end of the relay connection between the first terminal device and the second terminal device
- the target identifier is used to identify the intermediate connection between the first terminal device and the second terminal device.
- the destination of the connection may also include other system setting parameters, such as one or more fixed parameters specified by 3GPP.
- the first message is an authentication response message
- the second message is a Secure Mode Command (Secure Mode Command, SMC) message.
- SMC Secure Mode Command
- the first message is a Secure Mode Command (SMC) message
- the second message is a Secure Mode response message.
- SMC Secure Mode Command
- the first terminal device sends the third message to the second terminal device through the relay device;
- the third message is used to indicate that the security mode establishment is completed, the third message is encrypted by the target key, and the third message includes at least one of the following: the y bits of the identification of the second key, Fourth message verification code;
- the target key includes one of the following: the first key, the second key, and a confidentiality protected key derived from the second key;
- the third message is integrity protected through the fourth message verification code generated based on the second key, or the third message is integrity protected through the third message verification code generated based on the integrity protection key derived based on the second key.
- the four-message verification code performs integrity protection, and the input parameters of the fourth message verification code include the y bits.
- the second terminal device decrypts the third message using the target key; provided that the information carried in the third message has not been tampered with, and the third message
- the second terminal device combines the x bits and the y bits to obtain the identity of the second key.
- the second terminal device can generate a fourth message verification code based on the y bits, and compare it with the fourth message verification code contained in the third message. If the comparison is consistent, the fourth message verification code The message verification code is valid.
- the third message is a security mode complete message (security mode complete).
- the first terminal device receives an error message sent by the second terminal device through the relay device; wherein the error message includes at least one of the following: cause information, a fifth message verification code; wherein the error message
- the reason information is used to indicate that the security policy of the second terminal device conflicts with the first terminal device, or the reason information is used to indicate that the first message verification code verification fails, or the reason information is used to indicate that the second terminal device
- the security algorithm negotiation between the device and the first terminal device fails, and the input parameters of the fifth message verification code include at least one of the following: the reason information;
- the first terminal device determines that the security mode establishment fails, and/or the first terminal device re-initiates the security mode establishment process.
- the error message may also be integrity protected.
- the cause information is used to indicate that the security policy of the second terminal device conflicts with the first terminal device.
- the second terminal device does not support the security policy information of the first terminal device carried in the first message. .
- the cause information is used to indicate that the security algorithm negotiation between the second terminal device and the first terminal device failed.
- the second terminal device does not support the security capabilities of the first terminal device carried in the first message. information.
- a discovery and path selection process is performed between the first terminal device, the relay device and the second terminal device.
- the first terminal device sends a direct communication request to the second terminal device through the relay device to trigger the secure connection of the PC5 link between the first terminal device and the relay device, and between the relay device and the second relay device.
- the direct communication request includes at least one of the following: a source identifier and a target identifier; wherein the source identifier is used to identify the source end of the relay connection between the first terminal device and the second terminal device, and the target identifier Used to identify the target end of the relay connection between the first terminal device and the second terminal device.
- the direct communication request may also include the identification (K D ID) of the first key.
- the second terminal device may not initiate the authentication process, that is, the authentication request message may not be sent, that is, the above S210 may be omitted. Not executed.
- the first terminal device receives the authentication request message sent by the second terminal device through the relay device. That is, in the case where the first message does not include the identification of the first key, the second terminal device initiates an authentication process to obtain the first key. Alternatively, in the case where the second terminal device ignores the identification of the first key included in the first message, the second terminal device initiates an authentication process to re-obtain the first key.
- the first key may be K D
- the identifier of the first key may be K D ID
- the second key may be K D -SESS
- the identifier of the second key may be K D-SESS ID.
- the input parameters when generating the first key include: a second temporary private key (Ephemeral private key2) generated by the first terminal device, a first temporary private key generated by the second terminal device.
- the input parameters when generating the first key include: the second temporary public key (Ephemeral public key2) generated by the first terminal device, the first temporary private key (Ephemeral private key2) generated by the second terminal device.
- the first temporary public key is paired with the first temporary private key
- the second temporary public key is paired with the second temporary private key.
- the integrity protection key includes an integrity protection key for the control plane (KD -CPint ) and an integrity protection key for the user plane ( KD-UPint ); and/or the confidentiality
- the protection keys include a confidentiality protection key for the control plane (K D-CPenc ) and a confidentiality protection key for the user plane (K D-UPenc ).
- the input parameters of the integrity protection key include at least one of the following: the second key, the selected algorithm type identifier, the length of the selected algorithm type identifier, and the integrity protection algorithm identifier. , the length of the integrity protection algorithm identifier. That is, the second key may be generated based on at least one of the second key, the selected algorithm type identifier, the length of the selected algorithm type identifier, the integrity protection algorithm identifier, and the length of the integrity protection algorithm identifier. Integrity protected key.
- the input parameters of the integrity protection key may also include some system setting parameters.
- the integrity protection key is automatically updated.
- the input parameters of the confidentiality protection key include at least one of the following: the second key, the selected algorithm type identifier, the length of the selected algorithm type identifier, the confidentiality protection algorithm identification , the length of the confidentiality protection algorithm identifier. That is, the second key may be generated based on at least one of the second key, the selected algorithm type identifier, the length of the selected algorithm type identifier, the confidentiality protection algorithm identifier, and the length of the confidentiality protection algorithm identifier. Confidentiality protects keys.
- the input parameters of the confidentiality protection key may also include some system setting parameters.
- the confidentiality protection key is automatically updated.
- the selected algorithm type identifier may be represented by "Control Plane Integrity Protection Algorithm" or by setting a specific value.
- the selected algorithm type identifier may be represented by "Control Plane Confidentiality Protection Algorithm" or by setting a specific value.
- the selected algorithm type identifier may be represented by "User Plane Integrity Protection Algorithm" or by setting a specific value.
- the selected algorithm type identifier may be represented by "user plane confidentiality protected algorithm” or by setting a specific value.
- Root key Signature private key/secret signing key (Secret Signing Key, SSK) is the root of trust for UE-to-UE relay unicast link security.
- SSK secret Signing Key
- UE ID user identification
- PVT public key parameter
- K D Elliptic Curve-Based Certificateless Signatures for Identity-Based Encryption
- Users each generate a temporary public and private key pair, and use the Elliptic Curve Integrated Encryption Scheme (ECIES) algorithm to generate K D.
- ECIES Elliptic Curve Integrated Encryption Scheme
- the signature generated by the source device user ensures the authenticity of the identity and the authenticity of the temporary public key. Integrity and non-repudiation.
- the signature generated by the target device user ensures the authenticity of the identity and the integrity and non-repudiation of the temporary public key. This ensures that only the source device and the target device can obtain the key K D . Therefore, the signature private key or SSK is the root of trust that ensures secure communication between the source device and the target device.
- K D The key length is at least 256 bits (bits) and is generated by both the source device and the target device through temporary public and private key negotiation. Based on the root key, K D is updated by rerunning the authentication process. K D is used to generate the next layer key K D-sess . The key can be saved even if there is no active communication session between the source and target devices. K D ID can be used to identify K D .
- the input parameters during generation include: UE-1's temporary private key Ephemeral private key2, UE-2's temporary public key Ephemeral public key1, and the identity information of UE-relay, or UE- Random number generated by relay, or counter COUNT generated by UE-relay; for UE-2, the input parameters during generation include: UE-1's temporary public key Ephemeral public key2, UE-2's temporary private key Ephemeral private key1 , and the identity of UE-relay, or the random number generated by UE-relay, or the counter COUNT generated by UE-relay.
- K D-sess The key length is at least 256 bits. K D-sess is used to derive the next level of integrity protection or confidentiality protection key. K D -sess can be refreshed based on K D by rerunning the secure connection establishment process or the related key update process. K D-sess ID is used to identify K D-sess . KD-sess is derived from KD using key derivation algorithms such as HMAC-SHA-256 or HMAC-SM3. The input parameters of K D-sess must at least include the key K D , the random number Nonce_1 (that is, the first random number generated by the first terminal device), and the random number Nonce_2 (that is, the second random number generated by the second terminal device).
- the input parameters of K D-sess may also include but are not limited to at least one of the following: source ID (Source ID), destination ID (Destination ID), the length of the random number Nonce_1, the length of the random number Nonce_2, the source ID (Source ID) length, destination ID (Destination ID) length.
- the input parameters of K D-sess can also include other system setting parameters, such as one or more fixed parameters specified by 3GPP.
- K D-CPint The key length is at least 128 bits. This key can be used for control plane data integrity protection.
- the key is derived by K D-sess using key derivation algorithms such as HMAC-SHA-256 or HMAC-SM3. Come.
- the input parameters of K D-CPint must contain at least the key K D-sess , the selected algorithm type identifier (such as "control plane integrity protection algorithm” or setting a specific value to represent it) and the selected algorithm type identifier.
- the length of the symbol, the integrity protection algorithm identifier and the length of the integrity protection algorithm identifier, and other system setting parameters can be used as optional input parameters.
- K D -CPint is automatically updated when K D- sess is automatically refreshed.
- K D-CPenc The key length is at least 128 bits. This key can be used for control plane data confidentiality protection.
- the key is derived by K D-sess using key derivation algorithms such as HMAC-SHA-256 or HMAC-SM3. Come.
- the input parameters of K D-CPenc must contain at least the key K D-sess , the selected algorithm type identifier (such as "Control Plane Confidentiality Protection Algorithm" or set a specific value to represent it) and the selected algorithm type identifier
- the length, the confidentiality protection algorithm identifier and the length of the confidentiality protection algorithm identifier, and other system setting parameters can be used as optional input parameters.
- K D -CPenc is automatically updated when K D- sess is automatically refreshed.
- K D-UPint The key length is at least 128 bits. This key can be used for user plane data integrity protection.
- the key is derived by K D-sess using key derivation algorithms such as HMAC-SHA-256 or HMAC-SM3. Come.
- the input parameters of K D-UPint must contain at least the key K D-sess , the selected algorithm type identifier (such as "user plane integrity protection algorithm” or setting a specific value to represent it) and the selected algorithm type identifier.
- the length of the symbol, the integrity protection algorithm identifier and the length of the integrity protection algorithm identifier, and other system setting parameters can be used as optional input parameters.
- K D -UPint is automatically updated when K D-sess is automatically refreshed.
- K D-UPenc The key length is at least 128 bits. This key can be used for user plane data confidentiality protection.
- the key is derived by K D-sess using key derivation algorithms such as HMAC-SHA-256 or HMAC-SM3. Come.
- the input parameters of K D-UPenc must contain at least the key K D-sess , the selected algorithm type identifier (such as "user plane confidentiality protection algorithm” or setting a specific value to represent it) and the selected algorithm type identifier.
- the length of the character, the confidentiality protection algorithm identifier and the length of the confidentiality protection algorithm identifier, and other system setting parameters can be used as optional input parameters.
- K D -UPenc is automatically updated when K D -sess is automatically refreshed.
- ECCSI in this application is only an example and is not limited to this algorithm. It can also be replaced by other identity-based public key signature and public key encryption algorithms. While replacing the public key algorithm, all requests Parameters related to the public key algorithm in the message need to be replaced accordingly.
- the key derivation function used by the first terminal device and the second terminal device in this application is not limited to HMAC-SHA-256 or HMAC-SM3, and includes any key derivation function that meets computational security.
- the input parameters of the key derivation function in this application are not limited to the necessary parameters mentioned above, and may include other optional parameters, such as fixed parameters set by the application system.
- the information elements in all interactive messages in the secure communication establishment process in this application are not limited to the content mentioned in the above solution, and optional information elements due to application system requirements can also be added.
- the first random number, the first key and the second random number generated by the second terminal device are used to derive the second key
- the second key is used to derive the integrity protection key and /or confidentiality protection key, which can ensure the identity security of the first terminal device and the second terminal device and the confidentiality and integrity of the communication data, thereby ensuring the confidentiality and integrity of the data transmitted by both parties and preventing other devices from even relaying Device eavesdropping.
- the embodiments of this application are applicable to the secure communication establishment process between the first terminal device (source device) and the second terminal device (target device) under the 5G Layer-3 (L3) UE-to-UE relay architecture.
- this secure communication establishment process can establish a secure connection between the source device and the target device without the need for network-side authentication and key distribution processes.
- This secure communication establishment process relies on public key signature technology to ensure the identity authenticity of the user device and the non-repudiation of the message. It can resist replay attacks, man-in-the-middle attacks, disguise and other active attacks, while ensuring the integrity of the authentication process messages.
- the ECIES algorithm is used to establish a secure environment only between the source device and the target device, ensuring the confidentiality and integrity of the data transmitted by both the source device and the target device, thereby preventing eavesdropping by external adversaries and even relay devices; ensuring security The scalability of the communication establishment mechanism.
- the secure communication establishment process can realize the security negotiation of the user plane and control plane security policies between the source device and the target device, as well as the encryption and integrity protection algorithms supported by both parties, and can achieve integrity. Protect against tampering and downgrade attacks.
- the first terminal device side embodiment of the present application is described in detail above with reference to FIGS. 6 to 7 .
- the second terminal device side embodiment of the present application is described in detail with reference to FIG. 8 . It should be understood that the second terminal device side implementation The example corresponds to the first terminal device side embodiment, and similar descriptions may refer to the first terminal device side embodiment.
- FIG 8 is a schematic flowchart of a communication relay method 300 according to an embodiment of the present application. As shown in Figure 8, the communication relay method 300 may include at least part of the following content:
- the second terminal device sends an authentication request message to the first terminal device through the relay device; wherein the authentication request message includes at least one of the following: information about the user to which the second terminal device belongs, the first user generated by the second terminal device.
- a temporary public key, the signature of the second terminal device, and relevant information of the relay device; wherein the information of the user to which the second terminal device belongs includes the signature certificate of the second terminal device, or the user to whom the second terminal device belongs The user's information includes the identification of the second terminal device and the PVT and KPAK of the second terminal device;
- the input parameters of the signature of the second terminal device include at least one of the following: the information of the user to which the second terminal device belongs and the third A temporary public key; the first temporary public key and the relevant information of the relay device are used by the first terminal device to derive the first key;
- the relevant information of the relay device includes one of the following: the identity of the relay device Information, a random number generated by the relay device, and a counter generated by the relay device.
- This embodiment is based on the ECCSI signature scheme to establish a secure connection in a UE-to-UE relay scenario under a layer 3 (L3) architecture.
- L3 layer 3
- the embodiments of this application are applied to the UE-to-UE relay scenario under the L3 architecture, that is, the first terminal device and the second terminal device communicate through the relay device.
- the relay connection between the first terminal device and the second terminal device may be a PC5 link.
- the first terminal device may be a source device or a source terminal
- the second terminal device may be a target device or a target terminal
- the relay device may be a relay terminal
- the input parameters of the signature of the second terminal device include at least one of the following: information of the user to which the second terminal device belongs and the first temporary public key. That is, the second terminal device may generate a signature of the second terminal device based on at least one of the information of the user to which the second terminal device belongs and the first temporary public key.
- the input parameters of the relay device's signature include at least one of the following: the signature of the second terminal device and the information of the user to which the relay device belongs. That is, the relay device may generate the signature of the relay device based on at least one of the signature of the second terminal device and the information of the user to which the relay device belongs.
- the signature of the second terminal device is generated by the signature private key of the second terminal device.
- the signing certificate and signing private key of the second terminal device may be pre-configured for the second terminal device through a secure channel by a trusted central key management server (KMS).
- KMS trusted central key management server
- the secure channel can be based on the application's authentication and key management (AKMA) mechanism or the general boot architecture (GBA) mechanism to establish a secure connection between the second terminal device and the KMS.
- AKMA application's authentication and key management
- GBA general boot architecture
- the KMS can be directly managed by the operator or is a third-party service provider that has a commercial relationship with the operator.
- the signature of the second terminal device is determined by the second terminal device.
- the device's Secret Signing Key (SSK) is generated.
- the PVT, KPAK, and secret signature key (SSK) of the second terminal device may be pre-configured by the trusted center KMS for the second terminal device through a secure channel.
- the secure channel may be based on the AKMA mechanism or the GBA mechanism to establish a secure connection between the second terminal device and the KMS.
- the KMS may be directly managed by the operator or be a third-party service provider that has a commercial relationship with the operator.
- the second terminal device receives the first message sent by the first terminal device through the relay device;
- the first message includes at least one of the following: security capability information of the first terminal device, security policy information of the first terminal device, information of the user to which the first terminal device belongs, and information of the user to which the relay device belongs. , the first random number generated by the first terminal device, the second temporary public key paired with the second temporary private key generated by the first terminal device, the identification of the first key generated by the first terminal device M bits, the signature of the first terminal device, the signature of the relay device, and the first message verification code;
- the information about the user to whom the first terminal device belongs includes the signature certificate of the first terminal device, or the information about the user to whom the first terminal device belongs includes the identification of the first terminal device and the PVT and KPAK of the first terminal device.
- the information of the user of the relay device includes the signature certificate of the relay device, or the information of the user of the relay device includes the identification of the relay device and the PVT and KPAK of the relay device;
- the input parameters of the signature include at least one of the following: information about the user to which the first terminal device belongs, the second temporary public key, M bits of the identification of the first key, and the signature of the second terminal device;
- the input parameters of the relay device's signature include at least one of the following: information about the user to which the relay device belongs, the signature of the first terminal device, and the signature of the second terminal device;
- the first message is integrity protected by the first message verification code generated based on the first key
- the input parameters of the first message verification code include at least one of the following: the security capability of the first terminal device Information, the security policy information of the first terminal device, the information of the user to which the first terminal device belongs, the information of the user to which the relay device belongs, the first random number, the second temporary public key, the M bits, The signature of the first terminal device and the signature of the relay device;
- the second temporary public key and the relevant information of the relay device are used by the second terminal device to derive the first key, the first random number, the first key and the third key generated by the second terminal device.
- Two random numbers are used to derive a second key.
- the second key is used to derive an integrity protection key and/or a confidentiality protection key.
- the identity of the first key is composed of the M bits and the first The other N bits of the key's identifier are combined, and M and N are both positive integers.
- the input parameters of the first message verification code include at least one of the following: security capability information of the first terminal device, security policy information of the first terminal device, user information of the user to which the first terminal device belongs. information, the information of the user to which the relay device belongs, the first random number, the second temporary public key, and the M bits. That is, the first terminal device can be based on the security capability information of the first terminal device, the security policy information of the first terminal device, the first random number, the second temporary public key, the M bits, and the At least one of the signature of the first terminal device and the signature of the relay device generates the first message verification code.
- the first random number and the first key generated by the first terminal device and the second random number generated by the second terminal device are used to derive the second key. That is, the first terminal device derives the second key based on at least the first random number, the first key and the second random number, and the first terminal device can derive the integrity protection key and/or the secret based on the second key.
- the first terminal device can securely protect the sent message based on the integrity protection key and/or the confidentiality protection key.
- the second terminal device may derive the second key based on at least the first random number, the first key and the second random number, and the second terminal device may derive the integrity protection key and/or the secret based on the second key.
- the second terminal device can securely protect the sent message based on the integrity protection key and/or the confidentiality protection key.
- the signature of the first terminal device is generated by the signature private key of the first terminal device, or, In the case where the information of the user to which the first terminal device belongs includes the identification of the first terminal device and the PVT and KPAK of the first terminal device, the signature of the first terminal device is determined by the secret signature key of the first terminal device. generate.
- the signature of the relay device is generated by the signature private key of the relay device, or, in the relay device
- the signature of the relay device is generated by the secret signature key of the relay device.
- the first message is an authentication response message, or the first message is a safe mode command message.
- the security capability information of the first terminal device may be a list of cryptographic algorithms supported by the first terminal device.
- the security policy information of the first terminal device may be whether the first terminal device supports confidentiality protection or integrity protection.
- the security policy information of the first terminal device includes: the security policy information of the first terminal device on the control plane, and/or the security policy information of the first terminal device on the user plane.
- the M bits may be the highest M bits of the identity of the first key, and the N bits may be the lowest N bits of the identity of the first key; or, The M bits may be the first M bits of the identifier of the first key, and the N bits may be the last N bits of the identifier of the first key; or, the M bits may be are the even-numbered bits of the identifier of the first key, and the N bits may be the odd-numbered bits of the identifier of the first key.
- the values of M and N may be the same or different, which is not limited by this application.
- the second terminal device checks the signature certificate of the first terminal device and the signature certificate of the relay device respectively, and in the case where the signature certificate of the first terminal device and the signature certificate of the relay device are valid Next, the second terminal device verifies the signature of the first terminal device based on the signature certificate of the first terminal device, and the second terminal device verifies the signature of the relay device based on the signature certificate of the relay device. ; Or, the second terminal device separately checks the KPAK of the first terminal device and the KPAK of the relay device.
- the KPAK of the first terminal device and the KPAK of the relay device are valid, and based on the first Verifying the signature of the first terminal device based on the identity of the terminal device and the PVT of the first terminal device, and verifying the signature of the relay device based on the identity of the relay device and the PVT of the relay device;
- the second terminal device When the signature of the first terminal device and the signature of the relay device are verified successfully, and the information carried in the first message has not been tampered with, the second terminal device generates a second random number, and the second terminal device generates a second random number.
- the second key is generated based on at least the first random number, the first key and the second random number, and the second terminal device generates an integrity protection key and/or a confidentiality protection key based on the second key.
- key, and the second terminal device generates N bits of the identifier of the first key, and combines the M bits and the N bits to obtain the identifier of the first key.
- the second terminal device may use the first random number, the first key, the second random number, the source identifier, the target identifier, the length of the first random number, the second random number. At least one of the length of the number, the length of the source identifier, and the length of the target identifier is used to generate the second key.
- the source identifier is used to identify the source end of the relay connection between the first terminal device and the second terminal device
- the target identifier is used to identify the intermediate connection between the first terminal device and the second terminal device.
- the destination of the connection may also include other system setting parameters, such as one or more fixed parameters specified by 3GPP.
- the input parameters of the first message verification code include: the security capability information of the first terminal device, the security policy information of the first terminal device, the first random number, the second temporary public key, the M bits.
- the second terminal device may generate a first message verification based on the security capability information of the first terminal device, the security policy information of the first terminal device, the first random number, the second temporary public key, and the M bits. code and compare it with the first message verification code contained in the first message. If they are consistent, the first message verification code is valid.
- the second terminal device when the first message verification code is valid, sends a second message to the first terminal device through the relay device; wherein the second message includes at least one of the following : the second random number, the N bits, the x bits of the identifier of the second key generated by the second terminal device, the security algorithm selected by the second terminal device, the Security policy, second message verification code;
- the second message is integrity protected through the second message verification code generated based on the second key, or the second message is integrity protected through the third integrity protection key generated based on the second key.
- the second message verification code performs integrity protection, and the input parameters of the second message verification code include at least one of the following: the second random number, the N bits, the x bits, and the second terminal device selected Security algorithm, the security policy selected by the second terminal device;
- the identifier of the second key is obtained by combining the x bits and the other y bits of the identifier of the second key, and both x and y are positive integers.
- the input parameters of the second message verification code include: the second random number, the N bits, the x bits, the security algorithm selected by the second terminal device, the security strategy.
- the first terminal device may generate a second message verification code based on the second random number, the N bits, the x bits, the security algorithm selected by the second terminal device, and the security policy selected by the second terminal device. , and compared with the second message verification code contained in the second message. If they are consistent, the second message verification code is valid.
- the x bits may be the highest x bits of the identity of the second key, and the y bits may be the lowest y bits of the identity of the second key; or, The x bits may be the first x bits of the identifier of the second key, and the y bits may be the last y bits of the identifier of the second key; or, the x bits may be are the even-numbered bits of the identifier of the second key, and the y bits may be the odd-numbered bits of the identifier of the second key.
- the values of x and y may be the same or different, which is not limited by this application.
- the second message is encrypted by the first key, and the second message also includes a third message verification code
- the second message is integrity protected by the third message verification code generated based on the first key
- the input parameters of the third message verification code include at least one of the following: the second random number, the N bits, the x bits, the security algorithm selected by the second terminal device, and the security policy selected by the second terminal device.
- the second message may not be encrypted by the first key, or the second message may not be encrypted.
- the input parameters of the third message verification code include: the second random number, the N bits, the x bits, the security algorithm selected by the second terminal device, the security strategy.
- the first terminal device may generate a third message verification code based on the second random number, the N bits, the x bits, the security algorithm selected by the second terminal device, and the security policy selected by the second terminal device. , and compared with the third message verification code contained in the second message. If they are consistent, the third message verification code is valid.
- the second terminal device may select a security algorithm based on the security capability information of the first terminal device, and/or the second terminal device may select a security policy based on the security policy information of the first terminal device.
- the first message is an authentication response message and the second message is a secure mode command (SMC) message.
- SMC secure mode command
- the first message is a safe mode command (SMC) message and the second message is a safe mode response message.
- SMC safe mode command
- the first terminal device may derive the first secret key based on the first temporary public key generated by the second terminal device, the relevant information of the relay device, and the second temporary private key generated by the first terminal device. key.
- the second terminal device may derive the first key based on the second temporary public key generated by the first terminal device, the relevant information of the relay device, and the first temporary private key generated by the second terminal device.
- the first temporary public key generated by the second terminal device is paired with the first temporary private key generated by the second terminal device
- the second temporary public key generated by the first terminal device is paired with the second temporary private key generated by the first terminal device. pair.
- the first terminal device can calculate the first key based on the first temporary public key, relevant information of the relay device, and the second temporary private key using the ECIES algorithm; the second terminal device can calculate the first key based on the second temporary public key. , the relevant information of the relay device and the first temporary private key, and use the ECIES algorithm to calculate the first key.
- the second terminal device receives the third message sent by the first terminal device through the relay device;
- the third message is used to indicate that the security mode establishment is completed, the third message is encrypted by the target key, and the third message includes at least one of the following: the identification of the second key generated by the first terminal device y bits, the fourth message verification code;
- the target key includes one of the following: the first key, the second key, and a confidentiality protected key derived from the second key;
- the third message is integrity protected through the fourth message verification code generated based on the second key, or the third message is integrity protected through the third message verification code generated based on the integrity protection key derived based on the second key.
- the four-message verification code performs integrity protection, and the input parameters of the fourth message verification code include the y bits.
- the second terminal device decrypts the third message using the target key
- the second terminal device When the information carried in the third message has not been tampered with and the fourth message verification code is valid, the second terminal device combines the x bits and the y bits to obtain the second The identity of the key.
- the second terminal device can generate a fourth message verification code based on the y bits, and compare it with the fourth message verification code contained in the third message. If the comparison is consistent, the fourth message verification code The message verification code is valid.
- the third message is a security mode complete message (security mode complete).
- the second terminal device sends an error message to the first terminal device through the relay device; wherein the error message includes at least one of the following: cause information, a fifth message verification code; wherein the cause The information is used to indicate that the security policy of the second terminal device conflicts with the first terminal device, or the reason information is used to indicate that the first message verification code verification fails, or the reason information is used to indicate that the second terminal device
- the security algorithm negotiation with the first terminal device fails, and the input parameters of the fifth message verification code include at least one of the following: the reason information.
- the first terminal device determines that the security mode establishment fails, and/or the first terminal device re-initiates the security mode establishment process.
- the error message may also be integrity protected.
- the cause information is used to indicate that the security policy of the second terminal device conflicts with the first terminal device.
- the second terminal device does not support the security policy information of the first terminal device carried in the first message. .
- the cause information is used to indicate that the security algorithm negotiation between the second terminal device and the first terminal device failed.
- the second terminal device does not support the security capabilities of the first terminal device carried in the first message. information.
- the second terminal device receives the direct communication request sent by the first terminal device through the relay device; wherein the direct communication request includes at least one of the following: source identification, target identification; wherein the source The identifier is used to identify the source end of the relay connection between the first terminal device and the second terminal device, and the target identifier is used to identify the target of the relay connection between the first terminal device and the second terminal device. end.
- the direct communication request may also include the identification (K D ID) of the first key.
- the second terminal device may not send the authentication request message.
- the first terminal device receives the authentication request message sent by the second terminal device through the relay device. That is, in the case where the first message does not include the identification of the first key, the second terminal device initiates an authentication process to obtain the first key. Alternatively, in the case where the second terminal device ignores the identification of the first key included in the first message, the second terminal device initiates an authentication process to re-obtain the first key.
- the first key may be K D
- the identifier of the first key may be K D ID
- the second key may be K D -SESS
- the identifier of the second key may be K D-SESS ID.
- the integrity protection key includes an integrity protection key for the control plane (KD -CPint ) and an integrity protection key for the user plane ( KD-UPint ); and/or the confidentiality
- the protection keys include a confidentiality protection key for the control plane (K D-CPenc ) and a confidentiality protection key for the user plane (K D-UPenc ).
- the input parameters of the integrity protection key include at least one of the following: the second key, the selected algorithm type identifier, the length of the selected algorithm type identifier, and the integrity protection algorithm identifier. , the length of the integrity protection algorithm identifier. That is, the second key may be generated based on at least one of the second key, the selected algorithm type identifier, the length of the selected algorithm type identifier, the integrity protection algorithm identifier, and the length of the integrity protection algorithm identifier. Integrity protected key.
- the input parameters of the integrity protection key may also include some system setting parameters.
- the integrity protection key is automatically updated.
- the input parameters of the confidentiality protection key include at least one of the following: the second key, the selected algorithm type identifier, the length of the selected algorithm type identifier, the confidentiality protection algorithm identification , the length of the confidentiality protection algorithm identifier. That is, the second key may be generated based on at least one of the second key, the selected algorithm type identifier, the length of the selected algorithm type identifier, the confidentiality protection algorithm identifier, and the length of the confidentiality protection algorithm identifier. Confidentiality protects keys.
- the input parameters of the confidentiality protection key may also include some system setting parameters.
- the confidentiality protection key is automatically updated.
- the first random number, the first key and the second random number generated by the second terminal device are used to derive the second key
- the second key is used to derive the integrity protection key and /or confidentiality protection key, which can ensure the identity security of the first terminal device and the second terminal device and the confidentiality and integrity of the communication data, thereby ensuring the confidentiality and integrity of the data transmitted by both parties and preventing other devices from even relaying Device eavesdropping.
- the embodiments of this application are applicable to the secure communication establishment process between the first terminal device (source device) and the second terminal device (target device) under the 5G Layer-3 (L3) UE-to-UE relay architecture.
- this secure communication establishment process can establish a secure connection between the source device and the target device without the need for network-side authentication and key distribution processes.
- This secure communication establishment process relies on public key signature technology to ensure the identity authenticity of the user device and the non-repudiation of the message. It can resist replay attacks, man-in-the-middle attacks, disguise and other active attacks, while ensuring the integrity of the authentication process messages.
- the ECIES algorithm is used to establish a secure environment only between the source device and the target device, ensuring the confidentiality and integrity of the data transmitted by both the source device and the target device, thereby preventing eavesdropping by external adversaries and even relay devices; ensuring security The scalability of the communication establishment mechanism.
- the secure communication establishment process can realize the security negotiation of the user plane and control plane security policies between the source device and the target device, as well as the encryption and integrity protection algorithms supported by both parties, and can achieve integrity. Protect against tampering and downgrade attacks.
- the first terminal device side embodiment and the second terminal device side embodiment of the present application are described in detail above with reference to FIGS. 6 to 8 .
- the relay device side embodiment of the present application is described in detail with reference to FIG. 9 . It should be understood that , the relay device side embodiment corresponds to the first terminal device side embodiment and the second terminal device side embodiment. Similar descriptions can be made with reference to the first terminal device side embodiment and the second terminal device side embodiment.
- FIG. 9 is a schematic flowchart of a communication relay method 400 according to an embodiment of the present application.
- the communication relay method 400 may include at least part of the following content:
- the relay device receives the authentication request message sent by the second terminal device; wherein the authentication request message includes at least one of the following: information about the user to which the second terminal device belongs, and the first temporary public key generated by the second terminal device. , the signature of the second terminal device; wherein the information of the user to whom the second terminal device belongs includes the signature certificate of the second terminal device, or the information of the user to which the second terminal device belongs includes the identification and identification of the second terminal device.
- the PVT and KPAK of the second terminal device; the input parameters of the signature of the second terminal device include at least one of the following: information about the user to which the second terminal device belongs and the first temporary public key;
- the relay device sends a verified authentication request message to the first terminal device; wherein, The authentication request message after verification includes at least one of the following: information about the user to whom the second terminal device belongs, information about the user to whom the relay device belongs, the first temporary public key, the signature of the second terminal device, the relay device The signature of the device, and the relevant information of the relay device; wherein, the information of the user to whom the relay device belongs includes the signature certificate of the relay device, or the information of the user to whom the relay device belongs includes the identification of the relay device and the PVT and KPAK of the relay device; the input parameters of the signature of the relay device include at least one of the following: the signature of the second terminal device and the information
- This embodiment is based on the ECCSI signature scheme to establish a secure connection in the UE-to-UE relay scenario under the L3 architecture.
- the embodiments of this application are applied to the UE-to-UE relay scenario under the L3 architecture, that is, the first terminal device and the second terminal device communicate through the relay device.
- the relay connection between the first terminal device and the second terminal device may be a PC5 link.
- the first terminal device may be a source device or a source terminal
- the second terminal device may be a target device or a target terminal
- the relay device may be a relay terminal
- the input parameters of the signature of the second terminal device include at least one of the following: information of the user to which the second terminal device belongs and the first temporary public key. That is, the second terminal device can generate a signature of the second terminal device based on at least one of the information of the user to which the second terminal device belongs and the first temporary public key.
- the input parameters of the relay device's signature include at least one of the following: the signature of the second terminal device and the information of the user to which the relay device belongs. That is, the relay device may generate the signature of the relay device based on at least one of the signature of the second terminal device and the information of the user to which the relay device belongs.
- the relay device may verify the validity of the signature certificate of the second terminal device based on one or more signature certificates stored locally. For example, if there is a signature certificate consistent with the signature certificate of the second terminal device among the signature certificates stored locally on the relay device, the signature certificate of the second terminal device is valid.
- one or more signing certificates stored locally on the relay device may be preconfigured by the KMS.
- the relay device may verify the validity of the KPAK of the second terminal device based on one or more KPAKs stored locally. For example, if there is a KPAK consistent with the KPAK of the second terminal device among the KPAKs stored locally on the relay device, the KPAK of the second terminal device is valid.
- one or more KPAKs stored locally on the first terminal device may be preconfigured by the KMS.
- the first terminal device may derive the first key based on the first temporary public key generated by the second terminal device, relevant information of the relay device, and the second temporary private key generated by the first terminal device.
- the second terminal device may derive the first key based on the second temporary public key generated by the first terminal device, the relevant information of the relay device, and the first temporary private key generated by the second terminal device.
- the first temporary public key generated by the second terminal device is paired with the first temporary private key generated by the second terminal device
- the second temporary public key generated by the first terminal device is paired with the second temporary private key generated by the first terminal device. pair.
- the first terminal device can calculate the first key based on the first temporary public key, relevant information of the relay device, and the second temporary private key using the ECIES algorithm; the second terminal device can calculate the first key based on the second temporary public key. , the relevant information of the relay device and the first temporary private key, and use the ECIES algorithm to calculate the first key.
- the signature of the second terminal device is generated by the signature private key of the second terminal device.
- the signing certificate and signing private key of the second terminal device may be pre-configured for the second terminal device through a secure channel by a trusted central key management server (KMS).
- KMS trusted central key management server
- the secure channel can be based on the application's authentication and key management (AKMA) mechanism or the general boot architecture (GBA) mechanism to establish a secure connection between the second terminal device and the KMS.
- AKMA application's authentication and key management
- GBA general boot architecture
- the KMS can be directly managed by the operator or is a third-party service provider that has a commercial relationship with the operator.
- the signature of the second terminal device is determined by the second terminal device.
- the device's Secret Signing Key (SSK) is generated.
- the PVT, KPAK, and secret signature key (SSK) of the second terminal device may be pre-configured by the trusted center KMS for the second terminal device through a secure channel.
- the secure channel may be based on the AKMA mechanism or the GBA mechanism to establish a secure connection between the second terminal device and the KMS.
- the KMS may be directly managed by the operator or be a third-party service provider that has a commercial relationship with the operator.
- the signature of the relay device is generated by the signature private key of the relay device.
- the signing certificate and signing private key of the relay device may be pre-configured for the relay device by the trusted center KMS through a secure channel.
- the secure channel can be based on the AKMA mechanism or the GBA mechanism to establish a secure connection between the relay device and the KMS.
- the KMS can be directly managed by the operator or a third-party service provider that has a commercial relationship with the operator.
- the signature of the relay device is encrypted by the secret signature of the relay device.
- Key SSK
- the PVT, KPAK, and secret signature key (SSK) of the relay device may be pre-configured for the relay device by the trusted center KMS through a secure channel.
- the secure channel can be based on the AKMA mechanism or the GBA mechanism to establish a secure connection between the relay device and the KMS.
- the KMS can be directly managed by the operator or a third-party service provider that has a commercial relationship with the operator.
- the relay device receives the first message sent by the first terminal device; wherein the first message includes at least one of the following: security capability information of the first terminal device, Security policy information, information about the user to which the first terminal device belongs, the first random number generated by the first terminal device, the second temporary public key generated by the first terminal device, the first password generated by the first terminal device M bits of the identification key, the signature of the first terminal device, and the first message verification code; wherein the information of the user to which the first terminal device belongs includes the signature certificate of the first terminal device, or the first terminal device
- the information of the user to whom the device belongs includes the identification of the first terminal device and the PVT and KPAK of the first terminal device;
- the input parameters of the signature of the first terminal device include at least one of the following: information of the user to which the first terminal device belongs, The second temporary public key, the M bits of the identification of the first key, and the signature of the second terminal device; wherein the first message is processed through the first message verification code generated based on the first key Integrity protection, and
- the first random number, the first key and the second random number generated by the second terminal device are used to derive a second key.
- the second key is used to derive the integrity protection key.
- key and/or confidentiality protection key the identity of the first key is obtained by combining the M bits and the other N bits of the identity of the first key, where M and N are both positive integers.
- the relay device sends the first message after verification to the second terminal device; wherein , the first message after the verification includes at least one of the following: security capability information of the first terminal device, security policy information of the first terminal device, information of the user to which the first terminal device belongs, user information to which the relay device belongs information, the first random number generated by the first terminal device, the second temporary public key generated by the first terminal device paired with the second temporary private key, the first key generated by the first terminal device M bits of identification, the signature of the first terminal device, the signature of the relay device, and the first message verification code; wherein the information of the user to which the relay device belongs includes the signature certificate of the relay device, or the The information of the user to
- the first random number and the first key generated by the first terminal device and the second random number generated by the second terminal device are used to derive the second key. That is, the first terminal device derives the second key based on at least the first random number, the first key and the second random number, and the first terminal device can derive the integrity protection key and/or the secret based on the second key.
- the first terminal device can securely protect the sent message based on the integrity protection key and/or the confidentiality protection key.
- the second terminal device may derive the second key based on at least the first random number, the first key and the second random number, and the second terminal device may derive the integrity protection key and/or the secret based on the second key.
- the second terminal device can securely protect the sent message based on the integrity protection key and/or the confidentiality protection key.
- the input parameters of the first message verification code include at least one of the following: security capability information of the first terminal device, security policy information of the first terminal device, the first random number, the third 2.
- Temporary public key, the M bits that is, the first terminal device can be based on the security capability information of the first terminal device, the security policy information of the first terminal device, the first random number, the second temporary public key, and the M bits. At least one of them generates the first message verification code.
- the input parameters of the first message verification code include: the security capability information of the first terminal device, the security policy information of the first terminal device, the first random number, the second temporary public key, the M bits.
- the second terminal device may generate a first message verification based on the security capability information of the first terminal device, the security policy information of the first terminal device, the first random number, the second temporary public key, and the M bits. code and compare it with the first message verification code contained in the first message. If they are consistent, the first message verification code is valid.
- the first message is an authentication response message, or the first message is a safe mode command message.
- the security capability information of the first terminal device may be a list of cryptographic algorithms supported by the first terminal device.
- the security policy information of the first terminal device may be whether the first terminal device supports confidentiality protection or integrity protection.
- the security policy information of the first terminal device includes: the security policy information of the first terminal device on the control plane, and/or the security policy information of the first terminal device on the user plane.
- the M bits may be the highest M bits of the identity of the first key, and the N bits may be the lowest N bits of the identity of the first key; or, The M bits may be the first M bits of the identifier of the first key, and the N bits may be the last N bits of the identifier of the first key; or, the M bits may be are the even-numbered bits of the identifier of the first key, and the N bits may be the odd-numbered bits of the identifier of the first key.
- the values of M and N may be the same or different, which is not limited by this application.
- the relay device forwards the second message sent by the second terminal device to the first terminal device
- the second message includes at least one of the following: the second random number generated by the second terminal device, N bits of the identification of the first key generated by the second terminal device, x bits of the identifier of the generated second key, the security algorithm selected by the second terminal device, the security policy selected by the second terminal device, and the second message verification code;
- the second message is integrity protected through the second message verification code generated based on the second key, or the second message is integrity protected through the third integrity protection key generated based on the second key.
- the second message verification code performs integrity protection, and the input parameters of the second message verification code include at least one of the following: the second random number, the N bits, the x bits, and the second terminal device selected Security algorithm, the security policy selected by the second terminal device;
- the identifier of the second key is obtained by combining the x bits and the other y bits of the identifier of the second key, and both x and y are positive integers.
- the x bits may be the highest x bits of the identity of the second key, and the y bits may be the lowest y bits of the identity of the second key; or, The x bits may be the first x bits of the identifier of the second key, and the y bits may be the last y bits of the identifier of the second key; or, the x bits may be are the even-numbered bits of the identifier of the second key, and the y bits may be the odd-numbered bits of the identifier of the second key.
- the values of x and y may be the same or different, which is not limited by this application.
- the input parameters of the second message verification code include: the second random number, the N bits, the x bits, the security algorithm selected by the second terminal device, the security strategy.
- the first terminal device may generate a second message verification code based on the second random number, the N bits, the x bits, the security algorithm selected by the second terminal device, and the security policy selected by the second terminal device. , and compared with the second message verification code contained in the second message. If they are consistent, the second message verification code is valid.
- the second message is encrypted by the first key, and the second message also includes a third message verification code
- the second message is integrity protected by the third message verification code generated based on the first key
- the input parameters of the third message verification code include at least one of the following: the second random number, the N bits, the x bits, the security algorithm selected by the second terminal device, and the security policy selected by the second terminal device.
- the input parameters of the third message verification code include: the second random number, the N bits, the x bits, the security algorithm selected by the second terminal device, the security strategy.
- the first terminal device may generate a third message verification code based on the second random number, the N bits, the x bits, the security algorithm selected by the second terminal device, and the security policy selected by the second terminal device. , and compared with the third message verification code contained in the second message. If they are consistent, the third message verification code is valid.
- the second terminal device may select a security algorithm based on the security capability information of the first terminal device, and/or the second terminal device may select a security policy based on the security policy information of the first terminal device.
- the first terminal device may use the first random number, the first key, the second random number, the source identifier, the target identifier, the length of the first random number, the second random number. At least one of the length of the number, the length of the source identifier, and the length of the target identifier is used to generate the second key.
- the second terminal device can use the first random number, the first key, the second random number, the source identifier, the target identifier, the length of the first random number, the length of the second random number, the The second key is generated using at least one of the length of the source identifier and the length of the target identifier.
- the source identifier is used to identify the source end of the relay connection between the first terminal device and the second terminal device
- the target identifier is used to identify the intermediate connection between the first terminal device and the second terminal device.
- the destination of the connection may also include other system setting parameters, such as one or more fixed parameters specified by 3GPP.
- the first message is an authentication response message and the second message is a secure mode command (SMC) message.
- SMC secure mode command
- the first message is a safe mode command (SMC) message and the second message is a safe mode response message.
- SMC safe mode command
- the relay device forwards the third message sent by the first terminal device to the second terminal device;
- the third message is used to indicate that the security mode establishment is completed, the third message is encrypted by the target key, and the third message includes at least one of the following: the identification of the second key generated by the first terminal device y bits, the fourth message verification code;
- the target key includes one of the following: the first key, the second key, and a confidentiality protected key derived from the second key;
- the third message is integrity protected through the fourth message verification code generated based on the second key, or the third message is integrity protected through the third message verification code generated based on the integrity protection key derived based on the second key.
- the four-message verification code performs integrity protection, and the input parameters of the fourth message verification code include the y bits.
- the second terminal device decrypts the third message using the target key; provided that the information carried in the third message has not been tampered with, and the third message
- the second terminal device combines the x bits and the y bits to obtain the identity of the second key.
- the second terminal device can generate a fourth message verification code based on the y bits, and compare it with the fourth message verification code contained in the third message. If the comparison is consistent, the fourth message verification code The message verification code is valid.
- the third message is a security mode complete message (security mode complete).
- the relay device forwards the error message sent by the second terminal device to the first terminal device; wherein the error message includes at least one of the following: cause information, fifth message verification code; wherein, The reason information is used to indicate that the security policy of the second terminal device conflicts with the first terminal device, or the reason information is used to indicate that the first message verification code verification fails, or the reason information is used to indicate that the second terminal device
- the security algorithm negotiation between the terminal device and the first terminal device fails, and the input parameters of the fifth message verification code include at least one of the following: the reason information.
- the first terminal device determines that the security mode establishment fails, and/or the first terminal device re-initiates the security mode establishment process.
- the error message may also be integrity protected.
- the cause information is used to indicate that the security policy of the second terminal device conflicts with the first terminal device.
- the second terminal device does not support the security policy information of the first terminal device carried in the first message. .
- the cause information is used to indicate that the security algorithm negotiation between the second terminal device and the first terminal device failed.
- the second terminal device does not support the security capabilities of the first terminal device carried in the first message. information.
- the relay device forwards the direct communication request sent by the first terminal device to the second terminal device; wherein the direct communication request includes at least one of the following: a source identifier, a target identifier; wherein, the The source identifier is used to identify the source end of the relay connection between the first terminal device and the second terminal device, and the target identifier is used to identify the source end of the relay connection between the first terminal device and the second terminal device. target end.
- the direct communication request may also include the identification (K D ID) of the first key.
- the second terminal device may not send the authentication request message.
- the first terminal device receives the authentication request message sent by the second terminal device through the relay device. That is, in the case where the first message does not include the identification of the first key, the second terminal device initiates an authentication process to obtain the first key. Alternatively, in the case where the second terminal device ignores the identification of the first key included in the first message, the second terminal device initiates an authentication process to re-obtain the first key.
- the first key may be K D
- the identifier of the first key may be K D ID
- the second key may be K D -SESS
- the identifier of the second key may be K D-SESS ID.
- the integrity protection key includes an integrity protection key for the control plane (KD -CPint ) and an integrity protection key for the user plane ( KD-UPint ); and/or the confidentiality
- the protection keys include a confidentiality protection key for the control plane (K D-CPenc ) and a confidentiality protection key for the user plane (K D-UPenc ).
- the input parameters of the integrity protection key include at least one of the following: the second key, the selected algorithm type identifier, the length of the selected algorithm type identifier, and the integrity protection algorithm identifier. , the length of the integrity protection algorithm identifier. That is, the second key may be generated based on at least one of the second key, the selected algorithm type identifier, the length of the selected algorithm type identifier, the integrity protection algorithm identifier, and the length of the integrity protection algorithm identifier. Integrity protected key.
- the input parameters of the integrity protection key may also include some system setting parameters.
- the integrity protection key is automatically updated.
- the input parameters of the confidentiality protection key include at least one of the following: the second key, the selected algorithm type identifier, the length of the selected algorithm type identifier, the confidentiality protection algorithm identification , the length of the confidentiality protection algorithm identifier. That is, the second key may be generated based on at least one of the second key, the selected algorithm type identifier, the length of the selected algorithm type identifier, the confidentiality protection algorithm identifier, and the length of the confidentiality protection algorithm identifier. Confidentiality protects keys.
- the input parameters of the confidentiality protection key may also include some system setting parameters.
- the confidentiality protection key is automatically updated.
- the first random number, the first key and the second random number generated by the second terminal device are used to derive the second key
- the second key is used to derive the integrity protection key and /or confidentiality protection key, which can ensure the identity security of the first terminal device and the second terminal device and the confidentiality and integrity of the communication data, thereby ensuring the confidentiality and integrity of the data transmitted by both parties and preventing other devices from even relaying Device eavesdropping.
- the embodiments of this application are applicable to the secure communication establishment process between the source device (first terminal device) and the target device (second terminal device) under the 5G Layer-3 (L3) UE-to-UE relay architecture.
- this secure communication establishment process can establish a secure connection between the source device and the target device without the need for network-side authentication and key distribution processes.
- This secure communication establishment process relies on public key signature technology to ensure the identity authenticity of the user device and the non-repudiation of the message. It can resist replay attacks, man-in-the-middle attacks, disguise and other active attacks, while ensuring the integrity of the authentication process messages.
- the ECIES algorithm is used to establish a secure environment only between the source device and the target device, ensuring the confidentiality and integrity of the data transmitted by both the source device and the target device, thereby preventing eavesdropping by external adversaries and even relay devices; ensuring security The scalability of the communication establishment mechanism.
- the secure communication establishment process can realize the security negotiation of the user plane and control plane security policies between the source device and the target device, as well as the encryption and integrity protection algorithms supported by both parties, and can achieve integrity. Protect against tampering and downgrade attacks.
- FIG 10 is a schematic flow chart of a communication relay method 500 according to an embodiment of the present application.
- the communication relay method 500 may include at least part of the following content:
- the first terminal device sends a first message to the second terminal device through the relay device; wherein the first message includes at least one of the following: security capability information of the first terminal device, security policy of the first terminal device Information, information about the user to which the first terminal device belongs, the first random number generated by the first terminal device, the second temporary public key generated by the first terminal device, and the identification of the first key generated by the first terminal device M bits, the signature of the first terminal device, the first message verification code; wherein the information of the user to which the first terminal device belongs includes the signature certificate of the first terminal device, or the user to whom the first terminal device belongs
- the information includes the identification of the first terminal device and the PVT and KPAK of the first terminal device;
- the input parameters of the signature of the first terminal device include at least one of the following: information of the user to which the first terminal device belongs, the second Temporary public key, M bits of the identification of the first key, and signature of the second terminal device; wherein, the first message is integrity protected through the first message verification code generated based on
- the input parameters of the first message verification code include at least one of the following: security capability information of the first terminal device, security policy information of the first terminal device, information of the user to which the first terminal device belongs, The random number, the second temporary public key, the M bits, and the signature of the first terminal device; wherein the second temporary public key and the relevant information of the relay device are used by the second terminal device to derive the third A key, the first random number, the first key and the second random number generated by the second terminal device are used to derive a second key, the second key is used to derive the integrity protection key and/ Or a confidentiality protection key, the identity of the first key is obtained by combining the M bits and the other N bits of the identity of the first key, where M and N are both positive integers; where, the relay The relevant information of the device includes one of the following: the identity information of the relay device, the random number generated by the relay device, and the counter generated by the relay device.
- This embodiment is based on the ECCSI signature scheme to establish a secure connection in the UE-to-UE relay scenario under the L3 architecture.
- the embodiments of this application are applied to the UE-to-UE relay scenario under the L3 architecture, that is, the first terminal device and the second terminal device communicate through the relay device.
- the relay connection between the first terminal device and the second terminal device may be a PC5 link.
- the first random number and the first key generated by the first terminal device and the second random number generated by the second terminal device are used to derive the second key. That is, the first terminal device derives the second key based on at least the first random number, the first key and the second random number, and the first terminal device can derive the integrity protection key and/or the secret based on the second key.
- the first terminal device can securely protect the sent message based on the integrity protection key and/or the confidentiality protection key.
- the second terminal device may derive the second key based on at least the first random number, the first key and the second random number, and the second terminal device may derive the integrity protection key and/or the secret based on the second key.
- the second terminal device can securely protect the sent message based on the integrity protection key and/or the confidentiality protection key.
- the input parameters of the first message verification code include at least one of the following: security capability information of the first terminal device, security policy information of the first terminal device, the first random number, the third 2.
- Temporary public key, the M bits that is, the first terminal device can be based on the security capability information of the first terminal device, the security policy information of the first terminal device, the first random number, the second temporary public key, and the M bits. At least one of them generates the first message verification code.
- the input parameters of the first message verification code include: the security capability information of the first terminal device, the security policy information of the first terminal device, the first random number, the second temporary public key, the M bits.
- the second terminal device may generate a first message verification based on the security capability information of the first terminal device, the security policy information of the first terminal device, the first random number, the second temporary public key, and the M bits. code and compare it with the first message verification code contained in the first message. If they are consistent, the first message verification code is valid.
- the first message is an authentication response message, or the first message is a safe mode command message.
- the security capability information of the first terminal device may be a list of cryptographic algorithms supported by the first terminal device.
- the security policy information of the first terminal device may be whether the first terminal device supports confidentiality protection or integrity protection.
- the security policy information of the first terminal device includes: the security policy information of the first terminal device on the control plane, and/or the security policy information of the first terminal device on the user plane.
- the M bits may be the highest M bits of the identity of the first key, and the N bits may be the lowest N bits of the identity of the first key; or, The M bits may be the first M bits of the identifier of the first key, and the N bits may be the last N bits of the identifier of the first key; or, the M bits may be are the even-numbered bits of the identifier of the first key, and the N bits may be the odd-numbered bits of the identifier of the first key.
- the values of M and N may be the same or different, which is not limited by this application.
- the first terminal device receives the second message sent by the second terminal device through the relay device;
- the second message includes at least one of the following: the second random number generated by the second terminal device, N bits of the identification of the first key generated by the second terminal device, x bits of the identifier of the generated second key, the security algorithm selected by the second terminal device, the security policy selected by the second terminal device, and the second message verification code;
- the second message is integrity protected through the second message verification code generated based on the second key, or the second message is integrity protected through the third integrity protection key generated based on the second key.
- the second message verification code performs integrity protection, and the input parameters of the second message verification code include at least one of the following: the second random number, the N bits, the x bits, and the second terminal device selected Security algorithm, the security policy selected by the second terminal device;
- the identifier of the second key is obtained by combining the x bits and the other y bits of the identifier of the second key, and both x and y are positive integers.
- the first terminal device if the information carried in the second message has not been tampered with, the first terminal device generates the second random number based on at least the first random number, the first key and the second random number. key, the first terminal device generates an integrity protection key and/or a confidentiality protection key based on the second key, and the first terminal device combines the M bits and the N bits to obtain the The identification of the first key, the first terminal device generates y bits of the identification of the second key, and combines the x bits and the y bits to obtain the identification of the second key;
- the first terminal device When the second message verification code is valid, the first terminal device generates an integrity protection key and/or a secret based on the security algorithm selected by the second terminal device, the second key, and the second key.
- the security protection key and the security policy selected by the second terminal device are used to communicate with the second terminal device.
- the second message is encrypted by the first key, and the second message also includes a third message verification code
- the second message is integrity protected by the third message verification code generated based on the first key
- the input parameters of the third message verification code include at least one of the following: the second random number, the N bits, the x bits, the security algorithm selected by the second terminal device, and the security policy selected by the second terminal device.
- the second message may not be encrypted by the first key, or the second message may not be encrypted.
- the first terminal device decrypts the second message according to the first key; if the information carried in the second message is not tampered with, the first terminal device at least decrypts the second message according to the first random key. number, the first key and the second random number to generate the second key, the first terminal device generates an integrity protection key and/or a confidentiality protection key based on the second key, and the first The terminal device combines the M bits and the N bits to obtain the identity of the first key, the first terminal device generates y bits of the identity of the second key, and combines the x bits Combine with the y bits to obtain the identity of the second key;
- the first terminal device When the second message verification code is valid and the third message verification code is valid, the first terminal device generates a complete message based on the security algorithm selected by the second terminal device, the second key, and the second key.
- the security protection key and/or the confidentiality protection key and the security policy selected by the second terminal device are used to communicate with the second terminal device.
- the x bits may be the highest x bits of the identity of the second key, and the y bits may be the lowest y bits of the identity of the second key; or, The x bits may be the first x bits of the identifier of the second key, and the y bits may be the last y bits of the identifier of the second key; or, the x bits may be are the even-numbered bits of the identifier of the second key, and the y bits may be the odd-numbered bits of the identifier of the second key.
- the values of x and y may be the same or different, which is not limited by this application.
- the input parameters of the second message verification code include: the second random number, the N bits, the x bits, the security algorithm selected by the second terminal device, the security strategy.
- the first terminal device may generate a second message verification code based on the second random number, the N bits, the x bits, the security algorithm selected by the second terminal device, and the security policy selected by the second terminal device. , and compared with the second message verification code contained in the second message. If they are consistent, the second message verification code is valid.
- the input parameters of the third message verification code include: the second random number, the N bits, the x bits, the security algorithm selected by the second terminal device, the security strategy.
- the first terminal device may generate a third message verification code based on the second random number, the N bits, the x bits, the security algorithm selected by the second terminal device, and the security policy selected by the second terminal device. , and compared with the third message verification code contained in the second message. If they are consistent, the third message verification code is valid.
- the second terminal device may select a security algorithm based on the security capability information of the first terminal device, and/or the second terminal device may select a security policy based on the security policy information of the first terminal device.
- the first terminal device may use the first random number, the first key, the second random number, the source identifier, the target identifier, the length of the first random number, the second random number. At least one of the length of the number, the length of the source identifier, and the length of the target identifier is used to generate the second key.
- the source identifier is used to identify the source end of the relay connection between the first terminal device and the second terminal device
- the target identifier is used to identify the intermediate connection between the first terminal device and the second terminal device.
- the destination of the connection may also include other system setting parameters, such as one or more fixed parameters specified by 3GPP.
- the first message is an authentication response message and the second message is a secure mode command (SMC) message.
- SMC secure mode command
- the first message is a safe mode command (SMC) message and the second message is a safe mode response message.
- SMC safe mode command
- the first terminal device sends the third message to the second terminal device through the relay device;
- the third message is used to indicate that the security mode establishment is completed, the third message is encrypted by the target key, and the third message includes at least one of the following: the y bits of the identification of the second key, Fourth message verification code;
- the target key includes one of the following: the first key, the second key, and a confidentiality protected key derived from the second key;
- the third message is integrity protected through the fourth message verification code generated based on the second key, or the third message is integrity protected through the third message verification code generated based on the integrity protection key derived based on the second key.
- the four-message verification code performs integrity protection, and the input parameters of the fourth message verification code include the y bits.
- the second terminal device decrypts the third message using the target key; provided that the information carried in the third message has not been tampered with, and the third message
- the second terminal device combines the x bits and the y bits to obtain the identity of the second key.
- the second terminal device can generate a fourth message verification code based on the y bits, and compare it with the fourth message verification code contained in the third message. If the comparison is consistent, the fourth message verification code The message verification code is valid.
- the third message is a security mode complete message (security mode complete).
- the first terminal device receives an error message sent by the second terminal device through the relay device; wherein the error message includes at least one of the following: cause information, a fifth message verification code; wherein the error message
- the reason information is used to indicate that the security policy of the second terminal device conflicts with the first terminal device, or the reason information is used to indicate that the first message verification code verification fails, or the reason information is used to indicate that the second terminal device
- the security algorithm negotiation between the device and the first terminal device fails, and the input parameters of the fifth message verification code include at least one of the following: the reason information;
- the first terminal device determines that the security mode establishment fails, and/or the first terminal device re-initiates the security mode establishment process.
- the error message may also be integrity protected.
- the cause information is used to indicate that the security policy of the second terminal device conflicts with the first terminal device.
- the second terminal device does not support the security policy information of the first terminal device carried in the first message. .
- the cause information is used to indicate that the security algorithm negotiation between the second terminal device and the first terminal device failed.
- the second terminal device does not support the security capabilities of the first terminal device carried in the first message. information.
- the first terminal device receives the authentication request message sent by the second terminal device through the relay device;
- the authentication request message includes at least one of the following: information about the user to which the second terminal device belongs, information about the user to which the relay device belongs, the first temporary public key generated by the second terminal device, Signature, the signature of the relay device, and relevant information of the relay device;
- the information about the user to whom the second terminal device belongs includes the signature certificate of the second terminal device, or the information about the user to whom the second terminal device belongs includes the identification of the second terminal device and the PVT and KPAK of the second terminal device.
- the information of the user of the relay device includes the signature certificate of the relay device, or the information of the user of the relay device includes the identification of the relay device and the PVT and KPAK of the relay device;
- the input parameters of the signature include at least one of the following: the information of the user to which the second terminal device belongs and the first temporary public key;
- the input parameters of the signature of the relay device include at least one of the following: the signature of the second terminal device and the information of the user to which the relay device belongs; the first temporary public key and the relevant information of the relay device are used by the first terminal device to derive the first key.
- the input parameters of the signature of the second terminal device include at least one of the following: information of the user to which the second terminal device belongs and the first temporary public key. That is, the second terminal device may generate a signature of the second terminal device based on at least one of the information of the user to which the second terminal device belongs and the first temporary public key.
- the input parameters of the relay device's signature include at least one of the following: the signature of the second terminal device and the information of the user to which the relay device belongs. That is, the relay device may generate the signature of the relay device based on at least one of the signature of the second terminal device and the information of the user to which the relay device belongs.
- the signature of the second terminal device is generated by the signature private key of the second terminal device.
- the signing certificate and signing private key of the second terminal device may be pre-configured for the second terminal device through a secure channel by the trusted center KMS.
- the secure channel may be based on the AKMA mechanism or the GBA mechanism to establish a secure connection between the second terminal device and the KMS.
- the KMS may be directly managed by the operator or be a third-party service provider that has a commercial relationship with the operator.
- the signature of the second terminal device is determined by the second terminal device.
- the device's Secret Signing Key (SSK) is generated.
- the PVT, KPAK, and secret signature key (SSK) of the second terminal device may be pre-configured by the trusted center KMS for the second terminal device through a secure channel.
- the secure channel may be based on the AKMA mechanism or the GBA mechanism to establish a secure connection between the second terminal device and the KMS.
- the KMS may be directly managed by the operator or be a third-party service provider that has a commercial relationship with the operator.
- the signature of the relay device is generated by the signature private key of the relay device.
- the signing certificate and signing private key of the relay device may be pre-configured for the relay device by the trusted center KMS through a secure channel.
- the secure channel can be based on the AKMA mechanism or the GBA mechanism to establish a secure connection between the relay device and the KMS.
- the KMS can be directly managed by the operator or a third-party service provider that has a commercial relationship with the operator.
- the signature of the relay device is encrypted by the secret signature of the relay device.
- Key SSK
- the PVT, KPAK, and secret signature key (SSK) of the relay device may be pre-configured for the relay device by the trusted center KMS through a secure channel.
- the secure channel can be based on the AKMA mechanism or the GBA mechanism to establish a secure connection between the relay device and the KMS.
- the KMS can be directly managed by the operator or a third-party service provider that has a commercial relationship with the operator.
- the signature certificate of the second terminal device and the signature certificate of the relay device are valid, and the signature verification of the second terminal device based on the signature certificate of the second terminal device is successful, and based on the
- the signature certificate of the relay device successfully verifies the signature of the relay device
- the first terminal device generates a second temporary private key
- the first terminal device generates a second temporary private key based on the first temporary public key and the relevant information of the relay device. information and the second temporary private key to derive the first key.
- the first terminal device may verify the validity of the signature certificate of the second terminal device and the signature certificate of the relay device based on one or more signature certificates stored locally. For example, if there is a signature certificate consistent with the signature certificate of the second terminal device in the signature certificate stored locally on the first terminal device, the signature certificate of the second terminal device is valid; and the signature stored locally on the first terminal device If the certificate contains a signing certificate that is consistent with the signing certificate of the relay device, the signing certificate of the relay device is valid.
- one or more signature certificates stored locally on the first terminal device may be pre-configured by the KMS.
- the KPAK of the second terminal device and the KPAK of the relay device are valid, and the signature verification of the second terminal device based on the identity of the second terminal device and the PVT of the second terminal device is successful.
- the first terminal device generates a second temporary private key, and the first terminal device generates a second temporary private key according to the first terminal device.
- the first key is derived from a temporary public key, relevant information of the relay device and the second temporary private key.
- the first terminal device may verify the validity of the KPAK of the second terminal device and the KPAK of the relay device based on one or more KPAKs stored locally. For example, if there is a KPAK consistent with the KPAK of the second terminal device in the KPAK stored locally on the first terminal device, the KPAK of the second terminal device is valid; and there is a KPAK consistent with the KPAK stored locally on the first terminal device. In the case where the KPAK of the relay device is consistent with the KPAK, the KPAK of the relay device is valid.
- one or more KPAKs stored locally on the first terminal device may be preconfigured by the KMS.
- the first terminal device may derive the first secret key based on the first temporary public key generated by the second terminal device, the relevant information of the relay device, and the second temporary private key generated by the first terminal device. key.
- the second terminal device may derive the first key based on the second temporary public key generated by the first terminal device, the relevant information of the relay device, and the first temporary private key generated by the second terminal device.
- the first temporary public key generated by the second terminal device is paired with the first temporary private key generated by the second terminal device
- the second temporary public key generated by the first terminal device is paired with the second temporary private key generated by the first terminal device. pair.
- the first terminal device can calculate the first key based on the first temporary public key, relevant information of the relay device, and the second temporary private key using the ECIES algorithm; the second terminal device can calculate the first key based on the second temporary public key. , the relevant information of the relay device and the first temporary private key, and use the ECIES algorithm to calculate the first key.
- the first terminal device sends a direct communication request to the second terminal device through the relay device; wherein the direct communication request includes at least one of the following: a source identifier, a target identifier; wherein the source identifier The target identifier is used to identify the source end of the relay connection between the first terminal device and the second terminal device, and the target identifier is used to identify the target end of the relay connection between the first terminal device and the second terminal device. .
- the direct communication request may also include the identification (K D ID) of the first key.
- the second terminal device may not initiate the authentication process, that is, the second terminal device may not send the authentication request message.
- the first terminal device receives the authentication request message sent by the second terminal device through the relay device. That is, in the case where the first message does not include the identification of the first key, the second terminal device initiates an authentication process to obtain the first key. Alternatively, in the case where the second terminal device ignores the identification of the first key included in the first message, the second terminal device initiates an authentication process to re-obtain the first key.
- the first key may be K D
- the identifier of the first key may be K D ID
- the second key may be K D -SESS
- the identifier of the second key may be K D-SESS ID.
- the integrity protection key includes an integrity protection key for the control plane (KD -CPint ) and an integrity protection key for the user plane ( KD-UPint ); and/or the confidentiality
- the protection keys include a confidentiality protection key for the control plane (K D-CPenc ) and a confidentiality protection key for the user plane (K D-UPenc ).
- the input parameters of the integrity protection key include at least one of the following: the second key, the selected algorithm type identifier, the length of the selected algorithm type identifier, and the integrity protection algorithm identifier. , the length of the integrity protection algorithm identifier. That is, the algorithm may be generated based on at least one of the second key, the selected algorithm type identifier, the length of the selected algorithm type identifier, the integrity protection algorithm identifier, and the length of the integrity protection algorithm identifier. Integrity protected key.
- the input parameters of the integrity protection key may also include some system setting parameters.
- the integrity protection key is automatically updated.
- the input parameters of the confidentiality protection key include at least one of the following: the second key, the selected algorithm type identifier, the length of the selected algorithm type identifier, the confidentiality protection algorithm identification , the length of the confidentiality protection algorithm identifier. That is, the second key may be generated based on at least one of the second key, the selected algorithm type identifier, the length of the selected algorithm type identifier, the confidentiality protection algorithm identifier, and the length of the confidentiality protection algorithm identifier. Confidentiality protects keys.
- the input parameters of the confidentiality protection key may also include some system setting parameters.
- the confidentiality protection key is automatically updated.
- the selected algorithm type identifier may be represented by "Control Plane Integrity Protection Algorithm" or by setting a specific value.
- the selected algorithm type identifier may be represented by "Control Plane Confidentiality Protection Algorithm" or by setting a specific value.
- the selected algorithm type identifier may be represented by "User Plane Integrity Protection Algorithm" or by setting a specific value.
- the selected algorithm type identifier may be represented by "user plane confidentiality protected algorithm” or by setting a specific value.
- ECCSI in this application is only an example and is not limited to this algorithm. It can also be replaced by other identity-based public key signature and public key encryption algorithms. While replacing the public key algorithm, all requests Parameters related to the public key algorithm in the message need to be replaced accordingly.
- the key derivation function used by the first terminal device and the second terminal device in this application is not limited to HMAC-SHA-256 or HMAC-SM3, and includes any key derivation function that meets computational security.
- the input parameters of the key derivation function in this application are not limited to the necessary parameters mentioned above, and may include other optional parameters, such as fixed parameters set by the application system.
- the information elements in all interactive messages in the secure communication establishment process in this application are not limited to the content mentioned in the above solution, and optional information elements due to application system requirements can also be added.
- the first random number, the first key and the second random number generated by the second terminal device are used to derive the second key
- the second key is used to derive the integrity protection key and /or confidentiality protection key, which can ensure the identity security of the first terminal device and the second terminal device and the confidentiality and integrity of the communication data, thereby ensuring the confidentiality and integrity of the data transmitted by both parties and preventing other devices from even relaying Device eavesdropping.
- the embodiments of this application are applicable to the secure communication establishment process between the first terminal device (source device) and the second terminal device (target device) under the 5G Layer-3 (L3) UE-to-UE relay architecture.
- this secure communication establishment process can establish a secure connection between the source device and the target device without the need for network-side authentication and key distribution processes.
- This secure communication establishment process relies on public key signature technology to ensure the identity authenticity of the user device and the non-repudiation of the message. It can resist replay attacks, man-in-the-middle attacks, disguise and other active attacks, while ensuring the integrity of the authentication process messages.
- the ECIES algorithm is used to establish a secure environment only between the source device and the target device, ensuring the confidentiality and integrity of the data transmitted by both the source device and the target device, thereby preventing eavesdropping by external adversaries and even relay devices; ensuring security The scalability of the communication establishment mechanism.
- the secure communication establishment process can realize the security negotiation of the user plane and control plane security policies between the source device and the target device, as well as the encryption and integrity protection algorithms supported by both parties, and can achieve integrity. Protect against tampering and downgrade attacks.
- the first terminal device side embodiment of the present application is described in detail above with reference to FIG. 10
- the second terminal device side embodiment of the present application is described in detail below with reference to FIG. 11 . It should be understood that the second terminal device side embodiment is different from the second terminal device side embodiment.
- the terminal device side embodiments correspond to each other, and similar descriptions may refer to the first terminal device side embodiment.
- FIG 11 is a schematic flowchart of a communication relay method 600 according to an embodiment of the present application.
- the communication relay method 600 may include at least part of the following content:
- the second terminal device receives the first message sent by the first terminal device through the relay device; wherein the first message includes at least one of the following: the security capability information of the first terminal device, the security capability information of the first terminal device.
- Policy information information about the user to which the first terminal device belongs, information about the user to which the relay device belongs, the first random number generated by the first terminal device, the second temporary public key generated by the first terminal device, the first M bits of the identification of the first key generated by the terminal device, the signature of the first terminal device, the signature of the relay device, and the first message verification code; wherein, the information of the user to which the first terminal device belongs includes the The signature certificate of the first terminal device, or the information of the user to which the first terminal device belongs includes the identification of the first terminal device and the PVT and KPAK of the first terminal device; the information of the user to which the relay device belongs includes the relay The signature certificate of the device, or the information of the user to which the relay device belongs includes the identification of the relay device and the PVT and KPAK of the
- This embodiment is based on the ECCSI signature scheme to establish a secure connection in the UE-to-UE relay scenario under the L3 architecture.
- the embodiments of this application are applied to the UE-to-UE relay scenario under the L3 architecture, that is, the first terminal device and the second terminal device communicate through the relay device.
- the relay connection between the first terminal device and the second terminal device may be a PC5 link.
- the first random number and the first key generated by the first terminal device and the second random number generated by the second terminal device are used to derive the second key. That is, the first terminal device derives the second key based on at least the first random number, the first key and the second random number, and the first terminal device can derive the integrity protection key and/or the secret based on the second key.
- the first terminal device can securely protect the sent message based on the integrity protection key and/or the confidentiality protection key.
- the second terminal device may derive the second key based on at least the first random number, the first key and the second random number, and the second terminal device may derive the integrity protection key and/or the secret based on the second key.
- the second terminal device can securely protect the sent message based on the integrity protection key and/or the confidentiality protection key.
- the input parameters of the first message verification code include at least one of the following: security capability information of the first terminal device, security policy information of the first terminal device, the first random number, the third 2.
- Temporary public key, the M bits that is, the first terminal device can be based on the security capability information of the first terminal device, the security policy information of the first terminal device, the first random number, the second temporary public key, and the M bits. At least one of them generates the first message verification code.
- the signature of the first terminal device is generated by the signature private key of the first terminal device, or, In the case where the information of the user to which the first terminal device belongs includes the identification of the first terminal device and the PVT and KPAK of the first terminal device, the signature of the first terminal device is determined by the secret signature key of the first terminal device.
- the signature of the relay device is generated by the signature private key of the relay device, or, in the relay device
- the signature of the relay device is generated by the secret signature key of the relay device.
- the first message is an authentication response message, or the first message is a safe mode command message.
- the security capability information of the first terminal device may be a list of cryptographic algorithms supported by the first terminal device.
- the security policy information of the first terminal device may be whether the first terminal device supports confidentiality protection or integrity protection.
- the security policy information of the first terminal device includes: the security policy information of the first terminal device on the control plane, and/or the security policy information of the first terminal device on the user plane.
- the M bits may be the highest M bits of the identity of the first key, and the N bits may be the lowest N bits of the identity of the first key; or, The M bits may be the first M bits of the identifier of the first key, and the N bits may be the last N bits of the identifier of the first key; or, the M bits may be are the even-numbered bits of the identifier of the first key, and the N bits may be the odd-numbered bits of the identifier of the first key.
- the values of M and N may be the same or different, which is not limited by this application.
- the second terminal device checks the signature certificate of the first terminal device and the signature certificate of the relay device respectively, and in the case where the signature certificate of the first terminal device and the signature certificate of the relay device are valid Next, the second terminal device verifies the signature of the first terminal device based on the signature certificate of the first terminal device, and the second terminal device verifies the signature of the relay device based on the signature certificate of the relay device. ; Or, the second terminal device separately checks the KPAK of the first terminal device and the KPAK of the relay device.
- the second terminal device If the KPAK of the first terminal device and the KPAK of the relay device are valid, and based on the first Verify the signature of the first terminal device based on the identity of the terminal device and the PVT of the first terminal device, and verify the signature of the relay device based on the identity of the relay device and the PVT of the relay device; in the If the signature of the first terminal device and the signature of the relay device are verified successfully, and the information carried in the first message has not been tampered with, the second terminal device generates a second random number, and the second terminal device at least generates a second random number based on The first random number, the first key and the second random number generate the second key, and the second terminal device generates an integrity protection key and/or a confidentiality protection key based on the second key, And the second terminal device generates N bits of the identifier of the first key, and combines the M bits and the N bits to obtain the identifier of the first key.
- the second terminal device may use the first random number, the first key, the second random number, the source identifier, the target identifier, the length of the first random number, the second random number. At least one of the length of the number, the length of the source identifier, and the length of the target identifier is used to generate the second key.
- the source identifier is used to identify the source end of the relay connection between the first terminal device and the second terminal device
- the target identifier is used to identify the intermediate connection between the first terminal device and the second terminal device.
- the destination of the connection may also include other system setting parameters, such as one or more fixed parameters specified by 3GPP.
- the input parameters of the first message verification code include: the security capability information of the first terminal device, the security policy information of the first terminal device, the first random number, the second temporary public key, the M bits.
- the second terminal device may generate a first message verification based on the security capability information of the first terminal device, the security policy information of the first terminal device, the first random number, the second temporary public key, and the M bits. code and compare it with the first message verification code contained in the first message. If they are consistent, the first message verification code is valid.
- the second terminal device when the first message verification code is valid, sends a second message to the first terminal device through the relay device; wherein the second message includes at least one of the following : the second random number, the N bits, the x bits of the identifier of the second key generated by the second terminal device, the security algorithm selected by the second terminal device, the Security policy, second message verification code;
- the second message is integrity protected through the second message verification code generated based on the second key, or the second message is integrity protected through the third integrity protection key generated based on the second key.
- the second message verification code performs integrity protection, and the input parameters of the second message verification code include at least one of the following: the second random number, the N bits, the x bits, and the second terminal device selected Security algorithm, the security policy selected by the second terminal device;
- the identifier of the second key is obtained by combining the x bits and the other y bits of the identifier of the second key, and both x and y are positive integers.
- the input parameters of the second message verification code include: the second random number, the N bits, the x bits, the security algorithm selected by the second terminal device, the security strategy.
- the first terminal device may generate a second message verification code based on the second random number, the N bits, the x bits, the security algorithm selected by the second terminal device, and the security policy selected by the second terminal device. , and compared with the second message verification code contained in the second message. If they are consistent, the second message verification code is valid.
- the x bits may be the highest x bits of the identity of the second key, and the y bits may be the lowest y bits of the identity of the second key; or, The x bits may be the first x bits of the identifier of the second key, and the y bits may be the last y bits of the identifier of the second key; or, the x bits may be are the even-numbered bits of the identifier of the second key, and the y bits may be the odd-numbered bits of the identifier of the second key.
- the values of x and y may be the same or different, which is not limited by this application.
- the second message is encrypted by the first key, and the second message also includes a third message verification code
- the second message is integrity protected by the third message verification code generated based on the first key
- the input parameters of the third message verification code include at least one of the following: the second random number, the N bits, the x bits, the security algorithm selected by the second terminal device, and the security policy selected by the second terminal device.
- the second message may not be encrypted by the first key, or the second message may not be encrypted.
- the input parameters of the third message verification code include: the second random number, the N bits, the x bits, the security algorithm selected by the second terminal device, the security strategy.
- the first terminal device may generate a third message verification code based on the second random number, the N bits, the x bits, the security algorithm selected by the second terminal device, and the security policy selected by the second terminal device. , and compared with the third message verification code contained in the second message. If they are consistent, the third message verification code is valid.
- the second terminal device may select a security algorithm based on the security capability information of the first terminal device, and/or the second terminal device may select a security policy based on the security policy information of the first terminal device.
- the first message is an authentication response message and the second message is a secure mode command (SMC) message.
- SMC secure mode command
- the first message is a safe mode command (SMC) message and the second message is a safe mode response message.
- SMC safe mode command
- the first terminal device may derive the first secret key based on the first temporary public key generated by the second terminal device, the relevant information of the relay device, and the second temporary private key generated by the first terminal device. key.
- the second terminal device may derive the first key based on the second temporary public key generated by the first terminal device, the relevant information of the relay device, and the first temporary private key generated by the second terminal device.
- the first temporary public key generated by the second terminal device is paired with the first temporary private key generated by the second terminal device
- the second temporary public key generated by the first terminal device is paired with the second temporary private key generated by the first terminal device. pair.
- the first terminal device can calculate the first key based on the first temporary public key, relevant information of the relay device, and the second temporary private key using the ECIES algorithm; the second terminal device can calculate the first key based on the second temporary public key. , the relevant information of the relay device and the first temporary private key, and use the ECIES algorithm to calculate the first key.
- the second terminal device receives the third message sent by the first terminal device through the relay device;
- the third message is used to indicate that the security mode establishment is completed, the third message is encrypted by the target key, and the third message includes at least one of the following: the identification of the second key generated by the first terminal device y bits, the fourth message verification code;
- the target key includes one of the following: the first key, the second key, and a confidentiality protected key derived from the second key;
- the third message is integrity protected through the fourth message verification code generated based on the second key, or the third message is integrity protected through the third message verification code generated based on the integrity protection key derived based on the second key.
- the four-message verification code performs integrity protection, and the input parameters of the fourth message verification code include the y bits.
- the second terminal device decrypts the third message using the target key
- the second terminal device When the information carried in the third message has not been tampered with and the fourth message verification code is valid, the second terminal device combines the x bits and the y bits to obtain the second The identity of the key.
- the second terminal device can generate a fourth message verification code based on the y bits, and compare it with the fourth message verification code contained in the third message. If the comparison is consistent, the fourth message verification code The message verification code is valid.
- the third message is a security mode complete message (security mode complete).
- the second terminal device sends an error message to the first terminal device through the relay device; wherein the error message includes at least one of the following: cause information, a fifth message verification code; wherein the cause The information is used to indicate that the security policy of the second terminal device conflicts with the first terminal device, or the reason information is used to indicate that the first message verification code verification fails, or the reason information is used to indicate that the second terminal device
- the security algorithm negotiation with the first terminal device fails, and the input parameters of the fifth message verification code include at least one of the following: the reason information.
- the first terminal device determines that the security mode establishment fails, and/or the first terminal device re-initiates the security mode establishment process.
- the error message may also be integrity protected.
- the cause information is used to indicate that the security policy of the second terminal device conflicts with the first terminal device.
- the second terminal device does not support the security policy information of the first terminal device carried in the first message. .
- the cause information is used to indicate that the security algorithm negotiation between the second terminal device and the first terminal device failed.
- the second terminal device does not support the security capabilities of the first terminal device carried in the first message. information.
- the second terminal device sends an authentication request message to the first terminal device through the relay device;
- the authentication request message includes at least one of the following: information about the user to which the second terminal device belongs, the first temporary public key generated by the second terminal device, the signature of the second terminal device, and relevant information about the relay device. ;
- the information about the user to whom the second terminal device belongs includes the signature certificate of the second terminal device, or the information about the user to whom the second terminal device belongs includes the identification of the second terminal device and the PVT and KPAK of the second terminal device.
- the input parameters of the signature of the second terminal device include at least one of the following: information about the user to which the second terminal device belongs and the first temporary public key; related information about the first temporary public key and the relay device for The first terminal device derives a first key.
- the input parameters of the signature of the second terminal device include at least one of the following: information of the user to which the second terminal device belongs and the first temporary public key. That is, the second terminal device may generate a signature of the second terminal device based on at least one of the information of the user to which the second terminal device belongs and the first temporary public key.
- the input parameters of the relay device's signature include at least one of the following: the signature of the second terminal device and the information of the user to which the relay device belongs. That is, the relay device may generate the signature of the relay device based on at least one of the signature of the second terminal device and the information of the user to which the relay device belongs.
- the signature of the second terminal device is generated by the signature private key of the second terminal device.
- the signing certificate and signing private key of the second terminal device may be pre-configured for the second terminal device through a secure channel by a trusted central key management server (KMS).
- KMS trusted central key management server
- the secure channel can be based on the application's authentication and key management (AKMA) mechanism or the general boot architecture (GBA) mechanism to establish a secure connection between the second terminal device and the KMS.
- AKMA application's authentication and key management
- GBA general boot architecture
- the KMS can be directly managed by the operator or is a third-party service provider that has a commercial relationship with the operator.
- the signature of the second terminal device is determined by the second terminal device.
- the device's Secret Signing Key (SSK) is generated.
- the PVT, KPAK, and secret signature key (SSK) of the second terminal device may be pre-configured by the trusted center KMS for the second terminal device through a secure channel.
- the secure channel can be based on the AKMA mechanism or the GBA mechanism to establish a secure connection between the second terminal device and the KMS.
- the KMS can be directly managed by the operator or a third-party service provider that has a commercial relationship with the operator.
- the second terminal device receives the direct communication request sent by the first terminal device through the relay device; wherein the direct communication request includes at least one of the following: source identification, target identification; wherein the source The identifier is used to identify the source end of the relay connection between the first terminal device and the second terminal device, and the target identifier is used to identify the target of the relay connection between the first terminal device and the second terminal device. end.
- the direct communication request may also include the identification (K D ID) of the first key.
- the second terminal device may not initiate the authentication process, that is, the second terminal device may not send the authentication request message.
- the first terminal device receives the authentication request message sent by the second terminal device through the relay device. That is, in the case where the first message does not include the identification of the first key, the second terminal device initiates an authentication process to obtain the first key. Alternatively, in the case where the second terminal device ignores the identification of the first key included in the first message, the second terminal device initiates an authentication process to re-obtain the first key.
- the first key may be K D
- the identifier of the first key may be K D ID
- the second key may be K D -SESS
- the identifier of the second key may be K D-SESS ID.
- the integrity protection key includes an integrity protection key for the control plane (KD -CPint ) and an integrity protection key for the user plane ( KD-UPint ); and/or the confidentiality
- the protection keys include a confidentiality protection key for the control plane (K D-CPenc ) and a confidentiality protection key for the user plane (K D-UPenc ).
- the input parameters of the integrity protection key include at least one of the following: the second key, the selected algorithm type identifier, the length of the selected algorithm type identifier, and the integrity protection algorithm identifier. , the length of the integrity protection algorithm identifier. That is, the second key may be generated based on at least one of the second key, the selected algorithm type identifier, the length of the selected algorithm type identifier, the integrity protection algorithm identifier, and the length of the integrity protection algorithm identifier. Integrity protected key.
- the input parameters of the integrity protection key may also include some system setting parameters.
- the integrity protection key is automatically updated.
- the input parameters of the confidentiality protection key include at least one of the following: the second key, the selected algorithm type identifier, the length of the selected algorithm type identifier, the confidentiality protection algorithm identification , the length of the confidentiality protection algorithm identifier. That is, the second key may be generated based on at least one of the second key, the selected algorithm type identifier, the length of the selected algorithm type identifier, the confidentiality protection algorithm identifier, and the length of the confidentiality protection algorithm identifier. Confidentiality protects keys.
- the input parameters of the confidentiality protection key may also include some system setting parameters.
- the confidentiality protection key is automatically updated.
- the first random number, the first key and the second random number generated by the second terminal device are used to derive the second key
- the second key is used to derive the integrity protection key and /or confidentiality protection key, which can ensure the identity security of the first terminal device and the second terminal device and the confidentiality and integrity of the communication data, thereby ensuring the confidentiality and integrity of the data transmitted by both parties and preventing other devices from even relaying Device eavesdropping.
- the embodiments of this application are applicable to the secure communication establishment process between the first terminal device (source device) and the second terminal device (target device) under the 5G Layer-3 (L3) UE-to-UE relay architecture.
- this secure communication establishment process can establish a secure connection between the source device and the target device without the need for network-side authentication and key distribution processes.
- This secure communication establishment process relies on public key signature technology to ensure the identity authenticity of the user device and the non-repudiation of the message. It can resist replay attacks, man-in-the-middle attacks, disguise and other active attacks, while ensuring the integrity of the authentication process messages.
- the ECIES algorithm is used to establish a secure environment only between the source device and the target device, ensuring the confidentiality and integrity of the data transmitted by both the source device and the target device, thereby preventing eavesdropping by external adversaries and even relay devices; ensuring security The scalability of the communication establishment mechanism.
- the secure communication establishment process can realize the security negotiation of the user plane and control plane security policies between the source device and the target device, as well as the encryption and integrity protection algorithms supported by both parties, and can achieve integrity. Protect against tampering and downgrade attacks.
- the first terminal device side embodiment and the second terminal device side embodiment of the present application are described in detail above with reference to Figures 10 to 11.
- the relay device side embodiment of the present application is described in detail with reference to Figure 12. It should be understood that , the relay device side embodiment corresponds to the first terminal device side embodiment and the second terminal device side embodiment. Similar descriptions can be made with reference to the first terminal device side embodiment and the second terminal device side embodiment.
- FIG 12 is a schematic flowchart of a communication relay method 700 according to an embodiment of the present application. As shown in Figure 12, the communication relay method 700 may include at least part of the following content:
- the relay device receives the first message sent by the first terminal device; wherein the first message includes at least one of the following: security capability information of the first terminal device, security policy information of the first terminal device, Information about the user to which a terminal device belongs, the first random number generated by the first terminal device, the second temporary public key generated by the first terminal device, and the M bits of the identification of the first key generated by the first terminal device.
- the information of the user to which the first terminal device belongs includes the signature certificate of the first terminal device, or the information of the user to which the first terminal device belongs includes the The identification of the first terminal device and the PVT and KPAK of the first terminal device;
- the input parameters of the signature of the first terminal device include at least one of the following: information of the user to which the first terminal device belongs, the second temporary public key, M bits of the identification of the first key, the signature of the second terminal device; wherein the first message is integrity protected by the first message verification code generated based on the first key, and the third
- the input parameters of a message verification code include at least one of the following: security capability information of the first terminal device, security policy information of the first terminal device, information of the user to which the first terminal device belongs, the first random number, the The second temporary public key, the M bits, the signature of the first terminal device;
- the relay device sends the first message after verification to the second terminal device; wherein, The first message after the verification includes at least one of the following: security capability information of the first terminal device, security policy information of the first terminal device, information of the user to which the first terminal device belongs, information of the user to which the relay device belongs.
- the information of the user to which the relay device belongs includes the relay device
- the signature certificate of the device, or the information of the user to which the relay device belongs includes the identification of the relay device and the PVT and KPAK of the relay device
- the input parameters of the signature of the relay device include at least one of the following: the relay Information about the user to whom the device belongs, the signature of the first terminal device, the signature of the second terminal device, and the first message after verification; wherein, the second temporary public key and the relevant information of the relay device are used for the third The two terminal devices derive the first key, the first random number, the first key and the second random number generated by the second terminal device are used to derive the second key, and the second key is used to
- the identity of the first key is obtained by combining the M bits with the other N bits of the identity of the first key.
- M and N are both positive integers.
- the relevant information of the relay device includes one of the following: the identity information of the relay device, the random number generated by the relay device, and the counter generated by the relay device.
- This embodiment is based on the ECCSI signature scheme to establish a secure connection in the UE-to-UE relay scenario under the L3 architecture.
- the embodiments of this application are applied to the UE-to-UE relay scenario under the L3 architecture, that is, the first terminal device and the second terminal device communicate through the relay device.
- the relay connection between the first terminal device and the second terminal device may be a PC5 link.
- the first random number and the first key generated by the first terminal device and the second random number generated by the second terminal device are used to derive the second key. That is, the first terminal device derives the second key based on at least the first random number, the first key and the second random number, and the first terminal device can derive the integrity protection key and/or the secret based on the second key.
- the first terminal device can securely protect the sent message based on the integrity protection key and/or the confidentiality protection key.
- the second terminal device may derive the second key based on at least the first random number, the first key and the second random number, and the second terminal device may derive the integrity protection key and/or the secret based on the second key.
- the second terminal device can securely protect the sent message based on the integrity protection key and/or the confidentiality protection key.
- the input parameters of the first message verification code include at least one of the following: security capability information of the first terminal device, security policy information of the first terminal device, the first random number, the third 2.
- Temporary public key, the M bits that is, the first terminal device can be based on the security capability information of the first terminal device, the security policy information of the first terminal device, the first random number, the second temporary public key, and the M bits. At least one of them generates the first message verification code.
- the input parameters of the first message verification code include: the security capability information of the first terminal device, the security policy information of the first terminal device, the first random number, the second temporary public key, the M bits.
- the second terminal device may generate a first message verification based on the security capability information of the first terminal device, the security policy information of the first terminal device, the first random number, the second temporary public key, and the M bits. code and compare it with the first message verification code contained in the first message. If they are consistent, the first message verification code is valid.
- the first message is an authentication response message, or the first message is a safe mode command message.
- the security capability information of the first terminal device may be a list of cryptographic algorithms supported by the first terminal device.
- the security policy information of the first terminal device may be whether the first terminal device supports confidentiality protection or integrity protection.
- the security policy information of the first terminal device includes: the security policy information of the first terminal device on the control plane, and/or the security policy information of the first terminal device on the user plane.
- the M bits may be the highest M bits of the identity of the first key, and the N bits may be the lowest N bits of the identity of the first key; or, The M bits may be the first M bits of the identifier of the first key, and the N bits may be the last N bits of the identifier of the first key; or, the M bits may be are the even-numbered bits of the identifier of the first key, and the N bits may be the odd-numbered bits of the identifier of the first key.
- the values of M and N may be the same or different, which is not limited by this application.
- the relay device forwards the second message sent by the second terminal device to the first terminal device
- the second message includes at least one of the following: the second random number generated by the second terminal device, N bits of the identification of the first key generated by the second terminal device, x bits of the identifier of the generated second key, the security algorithm selected by the second terminal device, the security policy selected by the second terminal device, and the second message verification code;
- the second message is integrity protected through the second message verification code generated based on the second key, or the second message is integrity protected through the third integrity protection key generated based on the second key.
- the second message verification code performs integrity protection, and the input parameters of the second message verification code include at least one of the following: the second random number, the N bits, the x bits, and the second terminal device selected Security algorithm, the security policy selected by the second terminal device;
- the identifier of the second key is obtained by combining the x bits and the other y bits of the identifier of the second key, and both x and y are positive integers.
- the x bits may be the highest x bits of the identity of the second key, and the y bits may be the lowest y bits of the identity of the second key; or, The x bits may be the first x bits of the identifier of the second key, and the y bits may be the last y bits of the identifier of the second key; or, the x bits may be are the even-numbered bits of the identifier of the second key, and the y bits may be the odd-numbered bits of the identifier of the second key.
- the values of x and y may be the same or different, which is not limited by this application.
- the input parameters of the second message verification code include: the second random number, the N bits, the x bits, the security algorithm selected by the second terminal device, the security strategy.
- the first terminal device may generate a second message verification code based on the second random number, the N bits, the x bits, the security algorithm selected by the second terminal device, and the security policy selected by the second terminal device. , and compared with the second message verification code contained in the second message. If they are consistent, the second message verification code is valid.
- the second message is encrypted by the first key, and the second message also includes a third message verification code
- the second message is integrity protected by the third message verification code generated based on the first key
- the input parameters of the third message verification code include at least one of the following: the second random number, the N bits, the x bits, the security algorithm selected by the second terminal device, and the security policy selected by the second terminal device.
- the second message may not be encrypted by the first key, or the second message may not be encrypted.
- the input parameters of the third message verification code include: the second random number, the N bits, the x bits, the security algorithm selected by the second terminal device, the security strategy.
- the first terminal device may generate a third message verification code based on the second random number, the N bits, the x bits, the security algorithm selected by the second terminal device, and the security policy selected by the second terminal device. , and compared with the third message verification code contained in the second message. If they are consistent, the third message verification code is valid.
- the second terminal device may select a security algorithm based on the security capability information of the first terminal device, and/or the second terminal device may select a security policy based on the security policy information of the first terminal device.
- the first terminal device may use the first random number, the first key, the second random number, the source identifier, the target identifier, the length of the first random number, the second random number. At least one of the length of the number, the length of the source identifier, and the length of the target identifier is used to generate the second key.
- the second terminal device can use the first random number, the first key, the second random number, the source identifier, the target identifier, the length of the first random number, the length of the second random number, the The second key is generated using at least one of the length of the source identifier and the length of the target identifier.
- the source identifier is used to identify the source end of the relay connection between the first terminal device and the second terminal device
- the target identifier is used to identify the intermediate connection between the first terminal device and the second terminal device.
- the destination of the connection may also include other system setting parameters, such as one or more fixed parameters specified by 3GPP.
- the first message is an authentication response message
- the second message is a Secure Mode Command (Secure Mode Command, SMC) message.
- SMC Secure Mode Command
- the first message is a Secure Mode Command (SMC) message
- the second message is a Secure Mode response message.
- SMC Secure Mode Command
- the relay device forwards the third message sent by the first terminal device to the second terminal device;
- the third message is used to indicate that the security mode establishment is completed, the third message is encrypted by the target key, and the third message includes at least one of the following: the identification of the second key generated by the first terminal device y bits, the fourth message verification code;
- the target key includes one of the following: the first key, the second key, and a confidentiality protected key derived from the second key;
- the third message is integrity protected through the fourth message verification code generated based on the second key, or the third message is integrity protected through the third message verification code generated based on the integrity protection key derived based on the second key.
- the four-message verification code performs integrity protection, and the input parameters of the fourth message verification code include the y bits.
- the second terminal device decrypts the third message using the target key; provided that the information carried in the third message has not been tampered with, and the third message
- the second terminal device combines the x bits and the y bits to obtain the identity of the second key.
- the second terminal device can generate a fourth message verification code based on the y bits, and compare it with the fourth message verification code contained in the third message. If the comparison is consistent, the fourth message verification code The message verification code is valid.
- the third message is a security mode complete message (security mode complete).
- the relay device forwards the error message sent by the second terminal device to the first terminal device; wherein the error message includes at least one of the following: cause information, fifth message verification code; wherein, The reason information is used to indicate that the security policy of the second terminal device conflicts with the first terminal device, or the reason information is used to indicate that the first message verification code verification fails, or the reason information is used to indicate that the second terminal device
- the security algorithm negotiation between the terminal device and the first terminal device fails, and the input parameters of the fifth message verification code include at least one of the following: the reason information.
- the first terminal device determines that the security mode establishment fails, and/or the first terminal device re-initiates the security mode establishment process.
- the error message may also be integrity protected.
- the cause information is used to indicate that the security policy of the second terminal device conflicts with the first terminal device.
- the second terminal device does not support the security policy information of the first terminal device carried in the first message. .
- the cause information is used to indicate that the security algorithm negotiation between the second terminal device and the first terminal device failed.
- the second terminal device does not support the security capabilities of the first terminal device carried in the first message. information.
- the relay device receives an authentication request message sent by the second terminal device; wherein the authentication request message includes at least one of the following: information about the user to which the second terminal device belongs, and generated by the second terminal device.
- the input parameters of the signature of the second terminal device include at least one of the following: the information of the user to which the second terminal device belongs and the first temporary public key;
- the first temporary public key and the related information of the relay device are used by the first terminal device to derive the first key;
- the relay device sends a verified authentication request message to the first terminal device; wherein, the verification
- the subsequent authentication request message includes at least one of the following: information about the user to whom the second terminal device belongs, information about the user to whom the relay device belongs, the first temporary public key, the signature of the second terminal device, the signature of the relay device.
- Signature relevant information of the relay device; wherein, the information of the user to which the relay device belongs includes the signature certificate of the relay device, or the information of the user to which the relay device belongs includes the identification of the relay device and the relay device.
- the PVT and KPAK of the device; the input parameters of the signature of the relay device include at least one of the following: the signature of the second terminal device and the information of the user to which the relay device belongs.
- the input parameters of the signature of the second terminal device include at least one of the following: information of the user to which the second terminal device belongs and the first temporary public key. That is, the second terminal device may generate a signature of the second terminal device based on at least one of the information of the user to which the second terminal device belongs and the first temporary public key.
- the input parameters of the relay device's signature include at least one of the following: the signature of the second terminal device and the information of the user to which the relay device belongs. That is, the relay device may generate the signature of the relay device based on at least one of the signature of the second terminal device and the information of the user to which the relay device belongs.
- the relay device may verify the validity of the signature certificate of the second terminal device based on one or more signature certificates stored locally. For example, if there is a signature certificate consistent with the signature certificate of the second terminal device among the signature certificates stored locally on the relay device, the signature certificate of the second terminal device is valid.
- one or more signing certificates stored locally on the relay device may be preconfigured by the KMS.
- the relay device may verify the validity of the KPAK of the second terminal device based on one or more KPAKs stored locally. For example, if there is a KPAK consistent with the KPAK of the second terminal device among the KPAKs stored locally on the relay device, the KPAK of the second terminal device is valid.
- one or more KPAKs stored locally on the first terminal device may be preconfigured by the KMS.
- the first terminal device may derive the first key based on the first temporary public key generated by the second terminal device, relevant information of the relay device, and the second temporary private key generated by the first terminal device.
- the second terminal device may derive the first key based on the second temporary public key generated by the first terminal device, the relevant information of the relay device, and the first temporary private key generated by the second terminal device.
- the first temporary public key generated by the second terminal device is paired with the first temporary private key generated by the second terminal device
- the second temporary public key generated by the first terminal device is paired with the second temporary private key generated by the first terminal device. pair.
- the first terminal device can calculate the first key based on the first temporary public key, relevant information of the relay device, and the second temporary private key using the ECIES algorithm; the second terminal device can calculate the first key based on the second temporary public key. , the relevant information of the relay device and the first temporary private key, and use the ECIES algorithm to calculate the first key.
- the signature of the second terminal device is generated by the signature private key of the second terminal device.
- the signing certificate and signing private key of the second terminal device may be pre-configured for the second terminal device through a secure channel by a trusted central key management server (KMS).
- KMS trusted central key management server
- the secure channel can be based on the application's authentication and key management (AKMA) mechanism or the general boot architecture (GBA) mechanism to establish a secure connection between the second terminal device and the KMS.
- AKMA application's authentication and key management
- GBA general boot architecture
- the KMS can be directly managed by the operator or is a third-party service provider that has a commercial relationship with the operator.
- the signature of the second terminal device is determined by the second terminal device.
- the device's Secret Signing Key (SSK) is generated.
- the PVT, KPAK, and secret signature key (SSK) of the second terminal device may be pre-configured by the trusted center KMS for the second terminal device through a secure channel.
- the secure channel may be based on the AKMA mechanism or the GBA mechanism to establish a secure connection between the second terminal device and the KMS.
- the KMS may be directly managed by the operator or be a third-party service provider that has a commercial relationship with the operator.
- the signature of the relay device is generated by the signature private key of the relay device.
- the signing certificate and signing private key of the relay device may be pre-configured for the relay device by the trusted center KMS through a secure channel.
- the secure channel can be based on the AKMA mechanism or the GBA mechanism to establish a secure connection between the relay device and the KMS.
- the KMS can be directly managed by the operator or a third-party service provider that has a commercial relationship with the operator.
- the signature of the relay device is encrypted by the secret signature of the relay device.
- Key SSK
- the PVT, KPAK, and secret signature key (SSK) of the relay device may be pre-configured for the relay device by the trusted center KMS through a secure channel.
- the secure channel can be based on the AKMA mechanism or the GBA mechanism to establish a secure connection between the relay device and the KMS.
- the KMS can be directly managed by the operator or a third-party service provider that has a commercial relationship with the operator.
- the relay device forwards the direct communication request sent by the first terminal device to the second terminal device; wherein the direct communication request includes at least one of the following: a source identifier, a target identifier; wherein, the The source identifier is used to identify the source end of the relay connection between the first terminal device and the second terminal device, and the target identifier is used to identify the source end of the relay connection between the first terminal device and the second terminal device. target end.
- the direct communication request may also include the identification (K D ID) of the first key.
- the second terminal device may not send an authentication request message or initiate an authentication process.
- the first terminal device receives the authentication request message sent by the second terminal device through the relay device. That is, in the case where the first message does not include the identification of the first key, the second terminal device initiates an authentication process to obtain the first key. Alternatively, in the case where the second terminal device ignores the identification of the first key included in the first message, the second terminal device initiates an authentication process to re-obtain the first key.
- the first key may be K D
- the identifier of the first key may be K D ID
- the second key may be K D -SESS
- the identifier of the second key may be K D-SESS ID.
- the integrity protection key includes an integrity protection key for the control plane (KD -CPint ) and an integrity protection key for the user plane ( KD-UPint ); and/or the confidentiality
- the protection keys include a confidentiality protection key for the control plane (K D-CPenc ) and a confidentiality protection key for the user plane (K D-UPenc ).
- the input parameters of the integrity protection key include at least one of the following: the second key, the selected algorithm type identifier, the length of the selected algorithm type identifier, and the integrity protection algorithm identifier. , the length of the integrity protection algorithm identifier. That is, the second key may be generated based on at least one of the second key, the selected algorithm type identifier, the length of the selected algorithm type identifier, the integrity protection algorithm identifier, and the length of the integrity protection algorithm identifier. Integrity protected key.
- the input parameters of the integrity protection key may also include some system setting parameters.
- the integrity protection key is automatically updated.
- the input parameters of the confidentiality protection key include at least one of the following: the second key, the selected algorithm type identifier, the length of the selected algorithm type identifier, the confidentiality protection algorithm identification , the length of the confidentiality protection algorithm identifier. That is, the second key may be generated based on at least one of the second key, the selected algorithm type identifier, the length of the selected algorithm type identifier, the confidentiality protection algorithm identifier, and the length of the confidentiality protection algorithm identifier. Confidentiality protects keys.
- the input parameters of the confidentiality protection key may also include some system setting parameters.
- the confidentiality protection key is automatically updated.
- the first random number, the first key and the second random number generated by the second terminal device are used to derive the second key
- the second key is used to derive the integrity protection key and /or confidentiality protection key, which can ensure the identity security of the first terminal device and the second terminal device and the confidentiality and integrity of the communication data, thereby ensuring the confidentiality and integrity of the data transmitted by both parties and preventing other devices from even relaying Device eavesdropping.
- the embodiments of this application are applicable to the secure communication establishment process between the source device (first terminal device) and the target device (second terminal device) under the 5G Layer-3 (L3) UE-to-UE relay architecture.
- this secure communication establishment process can establish a secure connection between the source device and the target device without the need for network-side authentication and key distribution processes.
- This secure communication establishment process relies on public key signature technology to ensure the identity authenticity of the user device and the non-repudiation of the message. It can resist replay attacks, man-in-the-middle attacks, disguise and other active attacks, while ensuring the integrity of the authentication process messages.
- the ECIES algorithm is used to establish a secure environment only between the source device and the target device, ensuring the confidentiality and integrity of the data transmitted by both the source device and the target device, thereby preventing eavesdropping by external adversaries and even relay devices; ensuring security The scalability of the communication establishment mechanism.
- the secure communication establishment process can realize the security negotiation of the user plane and control plane security policies between the source device and the target device, as well as the encryption and integrity protection algorithms supported by both parties, and can achieve integrity. Protect against tampering and downgrade attacks.
- Embodiment 1 as shown in Figure 13, assuming that no secure connection has been established between all devices before, secure communication in the UE-to-UE relay scenario under the L3 architecture can be established through some or all of the steps from S11 to S17.
- UE1 may be the first terminal device
- UE2 may be the second terminal device
- K D may be the first key
- K D-SESS may be the second key.
- UE1 can send a direct communication request to UE2 through UE-to-UE relay, including the following parameters:
- Source ID (Source ID), which is used to identify the source end of the relay connection between UE1 and UE2;
- Destination ID which is used to identify the target end of the relay connection between UE1 and UE2.
- the K D ID can be included in the direct communication request.
- UE2 After UE2 receives the direct communication request, if UE2 already has a K D ID and security environment, and a link security context between different (Source ID, Destination ID) groups is established between UE1 and UE2, then the optional , UE2 can omit the authentication process and directly execute the security mode command message, or, considering higher security, continue to execute the authentication process and create a new security environment under the Source ID and Destination ID group; if UE1 and UE2 establish a secure connection for the first time, Then UE2 must perform the authentication process through UE-to-UE relay and UE1.
- UE-to-UE relay After UE2 receives the direct communication request, if UE2 already has a K D ID and security environment, and a link security context between different (Source ID, Destination ID) groups is established between UE1 and UE2, then the optional UE2 can omit the authentication process and directly execute the security mode command message, or, considering higher security, continue to execute the authentication process and create a new security
- S12.UE2 first generates a pair of temporary public and private keys, namely the first temporary public key and the first temporary private key, and then communicates with UE1 through UE-to-UE relay. Specifically, UE2 sends an authentication request message, including the following parameters:
- the information of the user to which UE2 belongs where the information of the user to which UE2 belongs includes the signature certificate of UE2, or the information of the user to which UE2 belongs includes the identity of UE2 and the PVT and KPAK of UE2;
- the signature of UE2 wherein the input parameters of the signature of UE2 include at least one of the following: "information of the user to which UE2 belongs” and "first temporary public key”.
- the UE-to-UE relay After receiving the authentication request message, the UE-to-UE relay verifies the validity of the signature certificate in the information of the user to which UE2 belongs (for example, the UE-to-UE relay verifies the validity of the signature certificate of UE2 based on the locally stored information), If the signature certificate is valid, the UE-to-UE relay verifies the signature of UE2 based on the signature certificate of UE2; or, the UE-to-UE relay verifies the validity of UE2's KPAK in the information of the user to which UE2 belongs (specifically, UE-to-UE relay verifies the validity of UE2's KPAK based on locally stored information.
- UE-to- UE relay verifies UE2's signature based on UE2's identity and UE2's PVT.
- the UE-to-UE relay sends a verified authentication request message to UE1.
- the verified authentication request message also includes the following parameters:
- the information of the user to which the UE-to-UE relay belongs includes the signature certificate of the UE-to-UE relay.
- the information of the user to which the UE-to-UE relay belongs includes the UE-to -The identification of UE relay and the PVT and KPAK of UE-to-UE relay;
- Signature 1 of UE-to-UE relay where the input parameters in signature 1 of UE-to-UE relay include at least one of the following: "UE2's signature” and "information of the user to which UE-to-UE relay belongs";
- the relevant information of the UE-to-UE relay includes one of the following: the identity information of the UE-to-UE relay, the random number generated by the UE-to-UE relay, Counter generated by this UE-to-UE relay.
- UE1 After receiving the verified authentication request message, UE1 checks the signature certificate of UE2 and the signature certificate of UE-to-UE relay respectively. If the signature certificate of UE2 and the signature certificate of UE-to-UE relay are valid, , UE1 verifies the signature of UE2 based on the signature certificate of UE2, and UE1 verifies the signature of UE-to-UE relay based on the signature certificate of UE-to-UE relay; or, UE1 checks the KPAK and UE-to of UE2 respectively.
- the KPAK of UE relay when the KPAK of UE2 and the KPAK of UE-to-UE relay are valid, and the signature of UE2 is verified based on the identification of UE2 and the PVT of UE2, and the identification of UE-to-UE relay is based on Verify the signature of the UE-to-UE relay with the PVT of the UE-to-UE relay. If the signature of UE2 and the signature of the UE-to-UE relay are verified successfully, then UE1 generates a temporary public and private key pair, that is, the second temporary public key and the second temporary private key.
- UE1 generates a temporary public key and a second temporary private key based on the first temporary public key and the UE-to -
- the relevant information of the UE relay and the second temporary private key use the ECIES algorithm to calculate the shared key K D and generate M bits of the K D ID.
- the K D ID is used to identify the K D .
- UE1 sends an authentication response message through UE-to-UE relay, including the following parameters:
- UE1 security capability information (optional);
- Information about the user to which UE1 belongs includes the identity of UE1 and the PVT and KPAK of UE1;
- the first random number (Nonce_1);
- the signature of UE1 where the signature input parameters of UE1 include at least one of the following: "information of the user to which UE1 belongs”, “second temporary public key”, “first random number (Nonce_1)”, “M numbers of K D ID”Bits” and “UE2's signature”;
- the authentication response message is integrity protected through the first message verification code generated based on K D
- the input parameters of the first message verification code include at least one of the following: UE1's security capability information, UE1's security policy Information, the information of the user to which UE1 belongs, the first random number (Nonce_1), the second temporary public key, the M bits of K D ID, and the signature of UE1.
- the security capability information of UE1 and the security policy information of UE1 may not be sent in the authentication response message.
- the UE-to-UE relay After receiving the authentication response message, the UE-to-UE relay verifies the validity of the signature certificate in the information of the user to which UE1 belongs (for example, the UE-to-UE relay verifies the validity of the signature certificate of UE1 based on the locally stored information). If The signature certificate is valid, and the UE-to-UE relay verifies the signature of UE1 based on the signature certificate of UE1; or, the UE-to-UE relay verifies the validity of UE1's KPAK in the information of the user to which UE1 belongs (specifically, UE-to-UE relay verifies the validity of UE1's KPAK based on locally stored information.
- UE-to-UE relay verifies UE1's signature based on UE1's identity and UE1's PVT. Finally, if the signature verification of UE1 is successful, the UE-to-UE relay sends the verification response message to UE2.
- the verification response message contains the following parameters:
- UE1 security capability information (optional);
- the first random number (Nonce_1);
- Information about the user to which UE1 belongs includes the identity of UE1 and the PVT and KPAK of UE1;
- Signature 2 of the UE-to-UE relay where the input parameters of the signature 2 of the UE-to-UE relay include at least one of the following: "Information of the user to which the UE-to-UE relay belongs”, “Signature of UE1", “ UE2's signature” and "authentication response message after verification”;
- UE2 After receiving the verified authentication response message, UE2 checks the signature certificate of UE1 and the signature certificate of UE-to-UE relay respectively. If the signature certificate of UE1 and the signature certificate of UE-to-UE relay are valid, UE2 verifies the signature of UE1 based on the signature certificate of UE1, and UE2 verifies the signature of UE-to-UE relay based on the signature certificate of UE-to-UE relay; alternatively, UE2 checks UE1's KPAK and UE-to- The KPAK of UE relay, when the KPAK of UE1 and the KPAK of UE-to-UE relay are valid, and the signature of UE1 is verified based on the identity of UE1 and the PVT of UE1, and the signature of UE1 is verified based on the identity of UE-to-UE relay and The PVT of the UE-to-UE relay verifies the signature of the UE-to-UE relay.
- UE2 verifies the integrity of the information contained in the authentication response message based on the first temporary private key, UE-to-UE relay related information and the second temporary Public key, use the ECIES algorithm to calculate the shared key K D.
- UE2 When the first message verification code is qualified, UE2 generates N bits of K D ID and combines the N bits of K D ID with the received The M bits of K D ID are combined to generate and store the complete K D ID, which is subsequently used to identify K D .
- both UE1 and UE2 have performed authentication and root key negotiation, and then UE2 starts processing the authentication response message.
- UE2 negotiates the security policy and security algorithm, then generates a second random number (Nonce_2), and uses the first random number and the second random number to and KD to calculate KD -SESS and other keys (i.e. KD -CPint , KD -CPenc , KD -UPint , KD -UPenc ). In addition, UE2 generates x bits of K D-SESS .
- UE2 sends an integrity-protected security mode command message to UE1 through UE-to-UE relay.
- the security mode command message contains the following parameters:
- the second random number (Nonce_2);
- the security policy selected by UE2 is the security policy selected by UE2;
- the second message verification code wherein the security mode command message is integrity protected by the second message verification code generated based on K D-SESS , or the security mode command message is integrity protected by the integrity derived based on K D-SESS
- the second message verification code generated by the key is integrity protected, and the input parameters of the second message verification code include at least one of the following: a second random number (Nonce_2), N bits of K D ID, K D - x bits of the SESS ID, the security algorithm selected by UE2, and the security policy selected by UE2.
- the security policies of UE2 and UE1 conflict with each other, or the first message verification code fails to be verified, or the security algorithm negotiation between UE2 and UE1 fails, UE2 will reply with an error message, where the error message includes cause information. and the fifth message verification code; wherein the reason information is used to indicate that the security policies of UE2 and UE1 conflict, or the reason information is used to indicate that the first message verification code verification fails, or the reason information is used to indicate that UE2 and UE1
- the security algorithm negotiation of UE1 failed; the input parameters of the fifth message verification code at least include: the reason information.
- UE1 determines that the security mode establishment fails, and/or, UE1 re-initiates the security mode establishment process.
- UE1 After receiving the security mode command message, UE1 determines whether the information carried in the security mode command message has been tampered with. If it has not been tampered with, then UE1 combines the M bits of K D ID and the N bits of K D ID to obtain K D ID, and UE1 calculates K D-SESS and other keys (i.e.
- UE1 when the second message verification code is valid, UE1 generates the integrity protection key and/or confidentiality protection key based on the security algorithm selected by UE2, K D-SESS , and the K D-SESS selected by UE2. Security policy to communicate with UE2.
- UE1 sends a security mode end message to UE2.
- the security mode end message is encrypted by the target key, and the security mode end message includes at least one of the following: y bits of K D-SESS ID, the fourth message Verification code; wherein, the target key includes one of the following: K D , K D-SESS , K D-CPenc , K D-UPenc ; wherein, the security mode end message passes the fourth key generated based on K D-SESS
- the message verification code performs integrity protection, or the security mode end message performs integrity protection through the fourth message verification code generated based on the integrity protection key derived from KD-SESS , and the input parameters of the fourth message verification code Includes y bits of K D-SESS ID.
- UE2 verifies whether the fourth message check code is valid. If valid, UE2 combines x bits of K D-SESS ID and y bits of K D-SESS ID to obtain K D-SESS ID, and saves it. K D-SESS ID. UE2 communicates with UE1 according to the security algorithm and K D-SESS selected by UE2, generates an integrity protection key and/or a confidentiality protection key based on K D-SESS , and a security policy selected by UE2.
- Embodiment 2 as shown in Figure 14, assuming that no secure connection has been established between all devices before, secure communication in the UE-to-UE relay scenario under the L3 architecture can be established through some or all of the steps in S21 to S27.
- UE1 may be the first terminal device
- UE2 may be the second terminal device
- K D may be the first key
- K D-SESS may be the second key.
- UE1 can send a direct communication request to UE2 through UE-to-UE relay, including the following parameters:
- Source ID (Source ID), which is used to identify the source end of the relay connection between UE1 and UE2;
- Destination ID which is used to identify the target end of the relay connection between UE1 and UE2.
- the K D ID can be included in the direct communication request.
- UE2 After UE2 receives the direct communication request, if UE2 already has a K D ID and security environment, and a link security context between different (Source ID, Destination ID) groups is established between UE1 and UE2, then the optional , UE2 can omit the authentication process and directly execute the security mode command message, or, considering higher security, continue to execute the authentication process and create a new security environment under the Source ID and Destination ID group; if UE1 and UE2 establish a secure connection for the first time, Then UE2 must perform the authentication process through UE-to-UE relay and UE1.
- UE-to-UE relay After UE2 receives the direct communication request, if UE2 already has a K D ID and security environment, and a link security context between different (Source ID, Destination ID) groups is established between UE1 and UE2, then the optional UE2 can omit the authentication process and directly execute the security mode command message, or, considering higher security, continue to execute the authentication process and create a new security
- S22.UE2 first generates a pair of temporary public and private keys, namely the first temporary public key and the first temporary private key, and then communicates with UE1 through UE-to-UE relay. Specifically, UE2 sends an authentication request message, including the following parameters:
- the information of the user to which UE2 belongs where the information of the user to which UE2 belongs includes the signature certificate of UE2, or the information of the user to which UE2 belongs includes the identity of UE2 and the PVT and KPAK of UE2;
- the signature of UE2 wherein the input parameters of the signature of UE2 include at least one of the following: "information of the user to which UE2 belongs” and "first temporary public key”.
- the UE-to-UE relay After receiving the authentication request message, the UE-to-UE relay verifies the validity of the signature certificate in the information of the user to which UE2 belongs (for example, the UE-to-UE relay verifies the validity of the signature certificate of UE2 based on the locally stored information), If the signature certificate is valid, the UE-to-UE relay verifies the signature of UE2 based on the signature certificate of UE2; or, the UE-to-UE relay verifies the validity of UE2's KPAK in the information of the user to which UE2 belongs (specifically, UE-to-UE relay verifies the validity of UE2's KPAK based on locally stored information.
- UE-to- UE relay verifies UE2's signature based on UE2's identity and UE2's PVT.
- the UE-to-UE relay sends a verified authentication request message to UE1.
- the verified authentication request message also includes the following parameters:
- the information of the user to which the UE-to-UE relay belongs includes the signature certificate of the UE-to-UE relay.
- the information of the user to which the UE-to-UE relay belongs includes the UE-to -The identification of UE relay and the PVT and KPAK of UE-to-UE relay;
- the signature of the UE-to-UE relay where the input parameters in the signature of the UE-to-UE relay include at least one of the following: "UE2's signature” and "information of the user to which the UE-to-UE relay belongs";
- the relevant information of the UE-to-UE relay includes one of the following: the identity information of the UE-to-UE relay, the random number generated by the UE-to-UE relay, Counter generated by this UE-to-UE relay.
- UE1 After receiving the verified authentication request message, UE1 checks the signature certificate of UE2 and the signature certificate of UE-to-UE relay respectively. If the signature certificate of UE2 and the signature certificate of UE-to-UE relay are valid, , UE1 verifies the signature of UE2 based on the signature certificate of UE2, and UE1 verifies the signature of UE-to-UE relay based on the signature certificate of UE-to-UE relay; or, UE1 checks the KPAK and UE-to of UE2 respectively.
- the KPAK of UE relay when the KPAK of UE2 and the KPAK of UE-to-UE relay are valid, and the signature of UE2 is verified based on the identification of UE2 and the PVT of UE2, and the identification of UE-to-UE relay is based on Verify the signature of the UE-to-UE relay with the PVT of the UE-to-UE relay. If the signature of UE2 and the signature of the UE-to-UE relay are verified successfully, then UE1 generates a temporary public and private key pair, that is, the second temporary public key and the second temporary private key.
- UE1 generates a temporary public key and a second temporary private key based on the first temporary public key and the UE-to -
- the relevant information of the UE relay and the second temporary private key use the ECIES algorithm to calculate the shared key K D and generate M bits of the K D ID.
- the K D ID is used to identify the K D .
- UE1 sends a safe mode command message through UE-to-UE relay, including the following parameters:
- UE1 security capability information (optional);
- Information about the user to which UE1 belongs includes the identity of UE1 and the PVT and KPAK of UE1;
- the first random number (Nonce_1);
- the signature of UE1 where the signature input parameters of UE1 include at least one of the following: "information of the user to which UE1 belongs”, “second temporary public key”, “first random number (Nonce_1)”, “N of K D ID Bits” and “UE2's signature”;
- the authentication response message is integrity protected through the first message verification code generated based on K D
- the input parameters of the first message verification code include at least one of the following: UE1's security capability information, UE1's security policy Information, the first random number (Nonce_1), the second temporary public key, M bits of K D ID.
- the security capability information of UE1 and the security policy information of UE1 may not be sent in the authentication response message.
- the UE-to-UE relay After receiving the authentication response message, the UE-to-UE relay verifies the validity of the signature certificate in the information of the user to which UE1 belongs (for example, the UE-to-UE relay verifies the validity of the signature certificate of UE1 based on the locally stored information). If The signature certificate is valid, and the UE-to-UE relay verifies the signature of UE1 based on the signature certificate of UE1; or, the UE-to-UE relay verifies the validity of UE1's KPAK in the information of the user to which UE1 belongs (specifically, UE-to-UE relay verifies the validity of UE1's KPAK based on locally stored information.
- UE-to-UE relay verifies UE1's signature based on UE1's identity and UE1's PVT. Finally, if the signature verification of UE1 is successful, the UE-to-UE relay sends the verification response message to UE2.
- the verification response message contains the following parameters:
- UE1 security capability information (optional);
- the first random number (Nonce_1);
- Information about the user to which UE1 belongs includes the identity of UE1 and the PVT and KPAK of UE1;
- Signature 2 of the UE-to-UE relay where the input parameters of the signature 2 of the UE-to-UE relay include at least one of the following: "Information of the user to which the UE-to-UE relay belongs", “Signature of UE1” and “ UE2's signature” and "authentication response message after verification”;
- UE2 After receiving the verified security mode command message, UE2 checks the signature certificate of UE1 and the signature certificate of UE-to-UE relay respectively. If the signature certificate of UE1 and the signature certificate of UE-to-UE relay are valid, , UE2 verifies the signature of UE1 based on the signature certificate of UE1, and UE2 verifies the signature of UE-to-UE relay based on the signature certificate of UE-to-UE relay; or, UE2 checks the KPAK and UE-to of UE1 respectively.
- -KPAK of UE relay when UE1's KPAK and UE-to-UE relay's KPAK are valid, and the signature of UE1 is verified based on the identity of UE1 and the PVT of UE1, and the identity of UE-to-UE relay is based on Verify the signature of the UE-to-UE relay with the PVT of the UE-to-UE relay. If the signature verification of UE1 and the UE-to-UE relay is successful, UE2 verifies the integrity of the information contained in the security mode command message based on the first temporary private key, the relevant information of the UE-to-UE relay and the second The temporary public key uses the ECIES algorithm to calculate the shared key K D.
- UE2 When the first message verification code is qualified, UE2 generates N bits of K D ID and combines the N bits of K D ID with the received The M bits of the K D ID are combined to generate and store the complete K D ID, which is subsequently used to identify K D . At this time, both UE1 and UE2 have performed authentication and root key negotiation, and then UE2 begins to process the security mode command message. If the security mode command message contains the security capability information of UE1 and the security policy information of UE1, UE2 negotiates the security policy and security algorithm, and then generates a second random number (Nonce_2), and uses the first random number and the second random number. numbers and KD to calculate KD -SESS and other keys (i.e. KD -CPint , KD -CPenc , KD -UPint , KD-UPenc ). In addition, UE2 generates x bits of K D-SESS .
- KD -CPint KD -CPenc
- UE2 sends an integrity-protected security mode response message to UE1 through UE-to-UE relay.
- the security mode response message contains the following parameters:
- the second random number (Nonce_2);
- the security policy selected by UE2 is the security policy selected by UE2;
- the second message verification code wherein the security mode response message is integrity protected through the second message verification code generated based on K D-SESS , or the security mode command message is integrity protected through the integrity derived based on K D-SESS
- the second message verification code generated by the key is integrity protected, and the input parameters of the second message verification code include at least one of the following: a second random number (Nonce_2), N bits of K D ID, K D - x bits of the SESS ID, the security algorithm selected by UE2, and the security policy selected by UE2;
- a third message verification code wherein the security mode response message is integrity protected by the third message verification code generated based on K D , and the input parameters of the third message verification code include at least one of the following: a second random number (Nonce_2), N bits of K D ID, x bits of K D-SESS ID, security algorithm selected by UE2, and security policy selected by UE2.
- Nonce_2 a second random number
- N bits of K D ID N bits of K D ID
- x bits of K D-SESS ID security algorithm selected by UE2
- security policy selected by UE2 security policy selected by UE2.
- the security mode response message is encrypted by KD .
- the security mode response message may not be encrypted by KD , or the security mode response message may not be encrypted.
- the security policies of UE2 and UE1 conflict with each other, or the first message verification code fails to be verified, or the security algorithm negotiation between UE2 and UE1 fails, UE2 will reply with an error message, where the error message includes cause information. and the fifth message verification code; wherein the reason information is used to indicate that the security policies of UE2 and UE1 conflict, or the reason information is used to indicate that the first message verification code verification fails, or the reason information is used to indicate that UE2 and UE1
- the security algorithm negotiation of UE1 failed; the input parameters of the fifth message verification code at least include: the reason information.
- UE1 determines that the security mode establishment fails, and/or, UE1 re-initiates the security mode establishment process.
- UE1 After receiving the security mode response message, UE1 determines whether the information carried in the security mode response message has been tampered with. If it has not been tampered with, then UE1 combines the M bits of K D ID and the N bits of K D ID to obtain K D ID, and UE1 calculates K D-SESS and other keys (i.e.
- UE1 when the second message verification code and the third message verification code are valid, UE1 generates the integrity protection key and/or confidentiality based on the security algorithm selected by UE2, K D- SESS. Protect the key, the security policy selected by UE2, and communicate with UE2.
- UE1 sends a security mode end message to UE2.
- the security mode end message is encrypted by the target key, and the security mode end message includes at least one of the following: y bits of K D-SESS ID, the fourth message Verification code; wherein, the target key includes one of the following: K D , K D-SESS , K D-CPenc , K D-UPenc ; wherein, the security mode end message passes the fourth key generated based on K D-SESS
- the message verification code performs integrity protection, or the security mode end message performs integrity protection through the fourth message verification code generated based on the integrity protection key derived from KD-SESS , and the input parameters of the fourth message verification code Includes y bits of K D-SESS ID.
- UE2 verifies whether the fourth message check code is valid. If valid, UE2 combines x bits of K D-SESS ID and y bits of K D-SESS ID to obtain K D-SESS ID, and saves it. K D-SESS ID. UE2 communicates with UE1 according to the security algorithm and K D-SESS selected by UE2, generates an integrity protection key and/or a confidentiality protection key based on K D-SESS , and a security policy selected by UE2.
- Embodiment 3 as shown in Figure 15, assuming that no secure connection has been established between all devices before, secure communication in the UE-to-UE relay scenario under the L3 architecture can be established through some or all of the steps in S31 to S37.
- UE1 may be the first terminal device
- UE2 may be the second terminal device
- K D may be the first key
- K D-SESS may be the second key.
- UE1 can send a direct communication request to UE2 through UE-to-UE relay, including the following parameters:
- Source ID (Source ID), which is used to identify the source end of the relay connection between UE1 and UE2;
- Destination ID which is used to identify the target end of the relay connection between UE1 and UE2;
- S32.UE1 sends a safe mode command message through UE-to-UE relay, including the following parameters:
- UE1 security capability information (optional);
- the first random number (Nonce_1);
- the signature of UE1 where the signature input parameters of UE1 include at least one of the following: "information of the user to which UE1 belongs”, “second temporary public key”, “first random number (Nonce_1)”, “N of K D ID Bits” and “UE2's signature”;
- the security mode command message is integrity protected through the first message verification code generated based on K D , and the input parameters of the first message verification code include at least one of the following: UE1's security capability information, UE1's security Policy information, the first random number (Nonce_1).
- the security capability information of UE1 and the security policy information of UE1 may not be sent in the security mode command message.
- the UE-to-UE relay After receiving the security mode command message, the UE-to-UE relay verifies the validity of the signature certificate in the information of the user to which UE1 belongs (for example, the UE-to-UE relay verifies the validity of the signature certificate of UE1 based on the locally stored information), If the signature certificate is valid, the UE-to-UE relay verifies the signature of UE1 based on the signature certificate of UE1; alternatively, the UE-to-UE relay verifies the validity of UE1's KPAK in the information of the user to which UE1 belongs (specifically , UE-to-UE relay verifies the validity of UE1's KPAK based on locally stored information.
- UE-to-UE relay verifies UE1's signature based on UE1's identity and UE1's PVT. Finally, if the signature verification of UE1 is successful, the UE-to-UE relay sends a secure mode command message to UE2, including the following parameters:
- the information of the user to which the UE-to-UE relay belongs includes the signature certificate of the UE-to-UE relay.
- the information of the user to which the UE-to-UE relay belongs includes the UE-to -The identification of UE relay and the PVT and KPAK of UE-to-UE relay;
- Signature 2 of the UE-to-UE relay where the input parameters of the signature 2 of the UE-to-UE relay include at least one of the following: "Information of the user to which the UE-to-UE relay belongs", “Signature of UE1" and “ UE2's signature”;
- UE2 After receiving the security mode command message, UE2 checks the signature certificate of UE1 and the signature certificate of UE-to-UE relay respectively. When the signature certificate of UE1 and the signature certificate of UE-to-UE relay are valid, UE2 based on UE1's signature certificate verifies UE1's signature, and UE2 verifies the UE-to-UE relay's signature based on the UE-to-UE relay's signature certificate; alternatively, UE2 checks UE1's KPAK and UE-to-UE relay respectively.
- KPAK when the KPAK of UE1 and the KPAK of UE-to-UE relay are valid, and the signature of UE1 is verified based on the identity of UE1 and the PVT of UE1, and the signature of UE1 is verified based on the identity of UE-to-UE relay and the UE-
- the PVT of the to-UE relay verifies the signature of the UE-to-UE relay. If the signature verification of UE1 and the UE-to-UE relay is successful, UE2 verifies the integrity of the information contained in the security mode command message, and if the first message verification code is qualified, both UE1 and UE2 authenticate and The root key is negotiated, and then UE2 starts processing the security mode command message.
- the security mode command message contains the security capability information of UE1 and the security policy information of UE1, UE2 negotiates the security policy and security algorithm, and then generates a second random number (Nonce_2), and uses the first random number and the second random number.
- numbers and KD to calculate KD -SESS and other keys (i.e. KD -CPint , KD -CPenc , KD -UPint , KD-UPenc ).
- KD -CPint KD -CPenc
- KD -UPint KD-UPenc
- UE2 sends an integrity-protected security mode response message and forwards it to UE1 through the UE-to-UE relay.
- the security mode response message contains the following parameters:
- the second random number (Nonce_2);
- the security policy selected by UE2 is the security policy selected by UE2;
- the second message verification code wherein the security mode response message is integrity protected through the second message verification code generated based on K D-SESS , or the security mode command message is integrity protected through the integrity derived based on K D-SESS
- the second message verification code generated by the key is integrity protected, and the input parameters of the second message verification code include at least one of the following: a second random number (Nonce_2), x bits of the K D-SESS ID, The security algorithm selected by UE2 and the security policy selected by UE2;
- a third message verification code wherein the security mode response message is integrity protected by the third message verification code generated based on K D , and the input parameters of the third message verification code include at least one of the following: a second random number (Nonce_2), x bits of K D-SESS ID, the security algorithm selected by UE2, and the security policy selected by UE2.
- a second random number (Nonce_2)
- x bits of K D-SESS ID the security algorithm selected by UE2
- the security policy selected by UE2 the security policy selected by UE2.
- the security mode response message is encrypted by KD .
- the security mode response message may not be encrypted by KD , or the security mode response message may not be encrypted.
- the security policies of UE2 and UE1 conflict with each other, or the first message verification code fails to be verified, or the security algorithm negotiation between UE2 and UE1 fails, UE2 will reply with an error message, where the error message includes cause information. and the fifth message verification code; wherein the reason information is used to indicate that the security policies of UE2 and UE1 conflict, or the reason information is used to indicate that the first message verification code verification fails, or the reason information is used to indicate that UE2 and UE1
- the security algorithm negotiation of UE1 failed; the input parameters of the fifth message verification code at least include: the reason information.
- UE1 determines that the security mode establishment fails, and/or, UE1 re-initiates the security mode establishment process.
- UE1 After receiving the security mode response message, UE1 determines whether the information carried in the security mode response message has been tampered with. If it has not been tampered with, then UE1 combines the M bits of K D ID and the N bits of K D ID to obtain K D ID, and UE1 calculates K D-SESS and other keys (i.e.
- UE1 when the second message verification code and the third message verification code are valid, UE1 generates the integrity protection key and/or confidentiality based on the security algorithm selected by UE2, K D- SESS. Protect the key, the security policy selected by UE2, and communicate with UE2.
- UE1 sends a security mode end message to UE2.
- the security mode end message is encrypted by the target key, and the security mode end message includes at least one of the following: y bits of K D-SESS ID, the fourth message Verification code; wherein, the target key includes one of the following: K D , K D-SESS , K D-CPenc , K D-UPenc ; wherein, the security mode end message passes the fourth key generated based on K D-SESS
- the message verification code performs integrity protection, or the security mode end message performs integrity protection through the fourth message verification code generated based on the integrity protection key derived from KD-SESS , and the input parameters of the fourth message verification code Includes y bits of K D-SESS ID.
- UE2 verifies whether the fourth message check code is valid. If valid, UE2 combines x bits of K D-SESS ID and y bits of K D-SESS ID to obtain K D-SESS ID, and saves it. K D-SESS ID. UE2 communicates with UE1 according to the security algorithm and K D-SESS selected by UE2, generates an integrity protection key and/or a confidentiality protection key based on K D-SESS , and a security policy selected by UE2.
- Figure 16 shows a schematic block diagram of a terminal device 800 according to an embodiment of the present application.
- the terminal device 800 is a first terminal device, and the terminal device 800 includes:
- Communication unit 810 configured to receive an authentication request message sent by the second terminal device through the relay device
- the authentication request message includes at least one of the following: information about the user to which the second terminal device belongs, information about the user to which the relay device belongs, the first temporary public key generated by the second terminal device, Signature, the signature of the relay device, and relevant information of the relay device;
- the information about the user to whom the second terminal device belongs includes the signature certificate of the second terminal device, or the information about the user to whom the second terminal device belongs includes the identification of the second terminal device and the public verification command of the second terminal device.
- brand PVT and the public authentication key KPAK of the key management server the information of the user of the relay device includes the signature certificate of the relay device, or the information of the user of the relay device includes the identification of the relay device and the The PVT and KPAK of the relay device;
- the input parameters of the signature of the second terminal device include at least one of the following: the information of the user to which the second terminal device belongs and the first temporary public key;
- the input parameters of the signature of the relay device Including at least one of the following: the signature of the second terminal device and the information of the user to which the relay device belongs; the first temporary public key and the relevant information of the relay device are used by the first terminal device to derive the first key;
- the relevant information of the relay device includes one of the following: the identity information of the relay device, the random
- the signature of the second terminal device is generated by the signature private key of the second terminal device, or, In the case where the information of the user to which the second terminal device belongs includes the identification of the second terminal device and the PVT and KPAK of the second terminal device, the signature of the second terminal device is determined by the secret signature key of the second terminal device. generate; and/or,
- the signature of the relay device is generated by the signature private key of the relay device, or when the information about the user of the relay device includes In the case of the relay device's identification and the relay device's PVT and KPAK, the relay device's signature is generated by the relay device's secret signature key.
- the terminal device 800 further includes: a processing unit 820;
- the signature certificate of the second terminal device and the signature certificate of the relay device are valid, and the signature verification of the second terminal device based on the signature certificate of the second terminal device is successful, and the signature certificate of the relay device is valid. If the signature verification of the relay device is successful, the processing unit 820 is configured to generate a second temporary private key, and the processing unit 820 is configured to generate a second temporary private key based on the first temporary public key, the relevant information of the relay device and the third A second temporary private key is derived from the first key; or,
- the KPAK of the second terminal device and the KPAK of the relay device are valid, and the signature verification of the second terminal device based on the identity of the second terminal device and the PVT of the second terminal device is successful, and based on the relay If the identification of the device and the PVT of the relay device successfully verify the signature of the relay device, the processing unit 820 is configured to generate a second temporary private key, and the processing unit 820 is configured to generate a second temporary public key based on the first temporary public key. , the relevant information of the relay device and the second temporary private key to derive the first key.
- the communication unit 810 is also used to send the first message to the second terminal device through the relay device;
- the first message includes at least one of the following: security capability information of the first terminal device, security policy information of the first terminal device, information of the user to which the first terminal device belongs, a third message generated by the first terminal device.
- security capability information of the first terminal device security policy information of the first terminal device
- information of the user to which the first terminal device belongs a third message generated by the first terminal device.
- a random number a second temporary public key generated by the first terminal device paired with the second temporary private key, M bits of the identification of the first key generated by the first terminal device, the first terminal Device signature, first message verification code;
- the information about the user to whom the first terminal device belongs includes the signature certificate of the first terminal device, or the information about the user to whom the first terminal device belongs includes the identification of the first terminal device and the PVT and KPAK of the first terminal device.
- the input parameters of the signature of the first terminal device include at least one of the following: information of the user to which the first terminal device belongs, the second temporary public key, M bits of the identification of the first key, the second The signature of the terminal device;
- the first message is integrity protected by the first message verification code generated based on the first key
- the input parameters of the first message verification code include at least one of the following: the security capability of the first terminal device Information, the security policy information of the first terminal device, the information of the user to which the first terminal device belongs, the first random number, the second temporary public key, the M bits, and the signature of the first terminal device;
- the second temporary public key and the relevant information of the relay device are used by the second terminal device to derive the first key, the first random number, the first key and the third key generated by the second terminal device.
- Two random numbers are used to derive a second key.
- the second key is used to derive an integrity protection key and/or a confidentiality protection key.
- the identity of the first key is composed of the M bits and the first The other N bits of the key's identifier are combined, and M and N are both positive integers.
- the communication unit 810 is also used to receive the second message sent by the second terminal device through the relay device;
- the second message includes at least one of the following: the second random number generated by the second terminal device, N bits of the identification of the first key generated by the second terminal device, x bits of the identifier of the generated second key, the security algorithm selected by the second terminal device, the security policy selected by the second terminal device, and the second message verification code;
- the second message is integrity protected through the second message verification code generated based on the second key, and the input parameters of the second message verification code include at least one of the following: the second random number, the N bits, the x bits, the security algorithm selected by the second terminal device, and the security policy selected by the second terminal device;
- the identifier of the second key is obtained by combining the x bits and the other y bits of the identifier of the second key, and both x and y are positive integers.
- the second message is encrypted by the first key, and the second message also includes a third message verification code
- the second message is integrity protected through the third message verification code generated based on the first key, or the second message is integrity protected through the third message verification code generated based on the integrity protection key derived based on the second key.
- the second message verification code performs integrity protection
- the input parameters of the third message verification code include at least one of the following: the second random number, the N bits, the x bits, and the second terminal device selected Security algorithm, the security policy selected by the second terminal device.
- the terminal device 800 further includes: a processing unit 820;
- the processing unit 820 is configured to generate the second key based on at least the first random number, the first key and the second random number.
- the unit 820 is used to generate an integrity protection key and/or a confidentiality protection key according to the second key, and the processing unit 820 is used to combine the M bits and the N bits to obtain the first secret key.
- the identification of the second key, the processing unit 820 is used to generate y bits of the identification of the second key, and combine the x bits and the y bits to obtain the identification of the second key;
- the communication unit 810 is also configured to generate an integrity protection key based on the second key and/or the security algorithm selected by the second terminal device and the second key. Or the confidentiality protection key and the security policy selected by the second terminal device are used to communicate with the second terminal device.
- the terminal device 800 further includes: a processing unit 820;
- the processing unit 820 is configured to decrypt the second message according to the first key
- the processing unit 820 is configured to generate the second key based on at least the first random number, the first key and the second random number.
- the unit 820 is used to generate an integrity protection key and/or a confidentiality protection key according to the second key, and the processing unit 820 is used to combine the M bits and the N bits to obtain the first secret key.
- the identification of the second key, the processing unit 820 is used to generate y bits of the identification of the second key, and combine the x bits and the y bits to obtain the identification of the second key;
- the communication unit 810 is also configured to generate The integrity protection key and/or the confidentiality protection key and the security policy selected by the second terminal device are communicated with the second terminal device.
- the input parameters of the integrity protection key include at least one of the following: the second key, the selected algorithm type identifier, the length of the selected algorithm type identifier, and the integrity protection algorithm identifier.
- the length of the integrity protection algorithm identifier; and/or, the input parameters of the confidentiality protection key include at least one of the following: the second key, the selected algorithm type identifier, the selected algorithm type identifier Length, confidentiality protection algorithm identifier, length of the confidentiality protection algorithm identifier.
- the first message is an authentication response message
- the second message is a safe mode command message
- the first message is a safe mode command message
- the second message is a safe mode response message
- the communication unit 810 is also used to send a third message to the second terminal device through the relay device;
- the third message is used to indicate that the security mode establishment is completed, the third message is encrypted by the target key, and the third message includes at least one of the following: the y bits of the identification of the second key, Fourth message verification code;
- the target key includes one of the following: the first key, the second key, and a confidentiality protected key derived from the second key;
- the third message is integrity protected through the fourth message verification code generated based on the second key, or the third message is integrity protected through the third message verification code generated based on the integrity protection key derived based on the second key.
- the four-message verification code performs integrity protection, and the input parameters of the fourth message verification code include the y bits.
- the communication unit 810 is also used to receive an error message sent by the second terminal device through the relay device; wherein the error message includes at least one of the following: cause information, fifth message verification code; wherein , the reason information is used to indicate that the security policy of the second terminal device conflicts with the first terminal device, or the reason information is used to indicate that the first message verification code verification fails, or the reason information is used to indicate that the third If the security algorithm negotiation between the second terminal device and the first terminal device fails, the input parameters of the fifth message verification code include at least one of the following: the reason information;
- the processing unit 820 is also configured to determine that the security mode establishment fails, and/or, the processing unit 820 is also configured to reinitiate the security mode establishment process.
- the integrity protection key includes an integrity protection key for the control plane and an integrity protection key for the user plane; and/or the confidentiality protection key includes a confidentiality protection key for the control plane. and user plane confidentiality protecting keys.
- the communication unit 810 is also configured to send a direct communication request to the second terminal device through the relay device;
- the direct communication request includes at least one of the following: source identifier, target identifier;
- the source identifier is used to identify the source end of the relay connection between the first terminal device and the second terminal device
- the target identifier is used to identify the intermediate connection between the first terminal device and the second terminal device. The destination of the connection.
- the above-mentioned communication unit may be a communication interface or transceiver, or an input/output interface of a communication chip or a system on a chip.
- the above-mentioned processing unit may be one or more processors.
- terminal device 800 may correspond to the first terminal device in the method embodiment of the present application, and the above and other operations and/or functions of each unit in the terminal device 800 are respectively intended to realize what is shown in Figure 6
- the corresponding process of the first terminal device in the method 200 is shown, and for the sake of simplicity, it will not be described again here.
- Figure 17 shows a schematic block diagram of a terminal device 900 according to an embodiment of the present application.
- the terminal device 900 is a second terminal device, and the terminal device 900 includes:
- Communication unit 910 configured to send an authentication request message to the first terminal device through the relay device
- the authentication request message includes at least one of the following: information about the user to which the second terminal device belongs, the first temporary public key generated by the second terminal device, the signature of the second terminal device, and relevant information about the relay device. ;
- the information about the user to whom the second terminal device belongs includes the signature certificate of the second terminal device, or the information about the user to whom the second terminal device belongs includes the identification of the second terminal device and the public verification command of the second terminal device.
- the public authentication key KPAK of the brand PVT and the key management server; the input parameters of the signature of the second terminal device include at least one of the following: the information of the user to which the second terminal device belongs and the first temporary public key; the first The temporary public key and the relevant information of the relay device are used by the first terminal device to derive the first key; the relevant information of the relay device includes one of the following: the identity information of the relay device, the Random number, counter generated by this relay device.
- the signature of the second terminal device is generated by the signature private key of the second terminal device, or, In the case where the information of the user to which the second terminal device belongs includes the identification of the second terminal device and the PVT and KPAK of the second terminal device, the signature of the second terminal device is determined by the secret signature key of the second terminal device. generate.
- the communication unit 910 is also configured to receive the first message sent by the first terminal device through the relay device;
- the first message includes at least one of the following: security capability information of the first terminal device, security policy information of the first terminal device, information of the user to which the first terminal device belongs, and information of the user to which the relay device belongs. , the first random number generated by the first terminal device, the second temporary public key paired with the second temporary private key generated by the first terminal device, the identification of the first key generated by the first terminal device M bits, the signature of the first terminal device, the signature of the relay device, and the first message verification code;
- the information about the user to whom the first terminal device belongs includes the signature certificate of the first terminal device, or the information about the user to whom the first terminal device belongs includes the identification of the first terminal device and the PVT and KPAK of the first terminal device.
- the information of the user of the relay device includes the signature certificate of the relay device, or the information of the user of the relay device includes the identification of the relay device and the PVT and KPAK of the relay device;
- the input parameters of the signature include at least one of the following: information about the user to which the first terminal device belongs, the second temporary public key, M bits of the identification of the first key, and the signature of the second terminal device;
- the input parameters of the relay device's signature include at least one of the following: information about the user to which the relay device belongs, the signature of the first terminal device, and the signature of the second terminal device;
- the first message is integrity protected by the first message verification code generated based on the first key
- the input parameters of the first message verification code include at least one of the following: the security capability of the first terminal device Information, the security policy information of the first terminal device, the information of the user to which the first terminal device belongs, the information of the user to which the relay device belongs, the first random number, the second temporary public key, the M bits, The signature of the first terminal device and the signature of the relay device;
- the second temporary public key and the relevant information of the relay device are used by the second terminal device to derive the first key, the first random number, the first key and the third key generated by the second terminal device.
- Two random numbers are used to derive a second key.
- the second key is used to derive an integrity protection key and/or a confidentiality protection key.
- the identity of the first key is composed of the M bits and the first The other N bits of the key's identifier are combined, and M and N are both positive integers.
- the signature of the first terminal device is generated by the signature private key of the first terminal device, or, In the case where the information of the user to which the first terminal device belongs includes the identification of the first terminal device and the PVT and KPAK of the first terminal device, the signature of the first terminal device is determined by the secret signature key of the first terminal device. generate; and/or,
- the signature of the relay device is generated by the signature private key of the relay device, or when the information about the user of the relay device includes In the case of the relay device's identification and the relay device's PVT and KPAK, the relay device's signature is generated by the relay device's secret signature key.
- the terminal device 900 further includes: a processing unit 920;
- the processing unit 920 is configured to check the signature certificate of the first terminal device and the signature certificate of the relay device respectively. If the signature certificate of the first terminal device and the signature certificate of the relay device are valid, the processing unit 920 is also configured to verify the signature of the first terminal device based on the signature certificate of the first terminal device, and the processing unit 920 is also configured to verify the signature of the relay device based on the signature certificate of the relay device; Alternatively, the processing unit 920 is also configured to check the KPAK of the first terminal device and the KPAK of the relay device respectively.
- the KPAK of the first terminal device and the KPAK of the relay device are valid, and based on the third Verifying the signature of the first terminal device based on the identification of a terminal device and the PVT of the first terminal device, and verifying the signature of the relay device based on the identification of the relay device and the PVT of the relay device;
- the processing unit 920 is configured to generate a second random number.
- the processing unit 920 is also configured to generate the second key based on at least the first random number, the first key and the second random number.
- the processing unit 920 is also configured to generate an integrity protection key and/or based on the second key. or confidentiality protection key, and the processing unit 920 is also used to generate N bits of the identification of the first key, and combine the M bits and the N bits to obtain the N bits of the first key. logo;
- the communication unit 910 is also configured to send a second message to the first terminal device through the relay device; wherein the second message includes at least one of the following: the second The random number, the N bits, the x bits of the identifier of the second key generated by the second terminal device, the security algorithm selected by the second terminal device, the security policy selected by the second terminal device, the Two message verification code;
- the second message is integrity protected through the second message verification code generated based on the second key, or the second message is integrity protected through the third integrity protection key generated based on the second key.
- the second message verification code performs integrity protection, and the input parameters of the second message verification code include at least one of the following: the second random number, the N bits, the x bits, and the second terminal device selected Security algorithm, the security policy selected by the second terminal device;
- the identifier of the second key is obtained by combining the x bits and the other y bits of the identifier of the second key, and both x and y are positive integers.
- the second message is encrypted by the first key, and the second message also includes a third message verification code
- the second message is integrity protected by the third message verification code generated based on the first key
- the input parameters of the third message verification code include at least one of the following: the second random number, the N bits, the x bits, the security algorithm selected by the second terminal device, and the security policy selected by the second terminal device.
- the first message is an authentication response message
- the second message is a safe mode command message
- the first message is a safe mode command message
- the second message is a safe mode response message
- the input parameters of the integrity protection key include at least one of the following: the second key, the selected algorithm type identifier, the length of the selected algorithm type identifier, and the integrity protection algorithm identifier.
- the length of the integrity protection algorithm identifier; and/or, the input parameters of the confidentiality protection key include at least one of the following: the second key, the selected algorithm type identifier, the selected algorithm type identifier Length, confidentiality protection algorithm identifier, length of the confidentiality protection algorithm identifier.
- the communication unit 910 is also configured to receive a third message sent by the first terminal device through the relay device;
- the third message is used to indicate that the security mode establishment is completed, the third message is encrypted by the target key, and the third message includes at least one of the following: the identification of the second key generated by the first terminal device y bits, the fourth message verification code;
- the target key includes one of the following: the first key, the second key, and a confidentiality protected key derived from the second key;
- the third message is integrity protected through the fourth message verification code generated based on the second key, or the third message is integrity protected through the third message verification code generated based on the integrity protection key derived based on the second key.
- the four-message verification code performs integrity protection, and the input parameters of the fourth message verification code include the y bits.
- the terminal device 900 further includes: a processing unit 920;
- the processing unit 920 is configured to decrypt the third message through the target key
- the processing unit 920 is also configured to combine the x bits and the y bits to obtain the The identifier of the second key.
- the communication unit 910 is also configured to send an error message to the first terminal device through the relay device; wherein the error message includes at least one of the following: cause information, a fifth message verification code; wherein, The reason information is used to indicate that the security policy of the second terminal device conflicts with the first terminal device, or the reason information is used to indicate that the first message verification code verification fails, or the reason information is used to indicate that the second terminal device
- the security algorithm negotiation between the terminal device and the first terminal device fails, and the input parameters of the fifth message verification code include at least one of the following: the reason information.
- the integrity protection key includes an integrity protection key for the control plane and an integrity protection key for the user plane; and/or the confidentiality protection key includes a confidentiality protection key for the control plane. and user plane confidentiality protecting keys.
- the communication unit 910 is also configured to receive a direct communication request sent by the first terminal device through the relay device;
- the direct communication request includes at least one of the following: source identifier, target identifier;
- the source identifier is used to identify the source end of the relay connection between the first terminal device and the second terminal device
- the target identifier is used to identify the intermediate connection between the first terminal device and the second terminal device. The destination of the connection.
- the above-mentioned communication unit may be a communication interface or transceiver, or an input/output interface of a communication chip or a system on a chip.
- the above-mentioned processing unit may be one or more processors.
- terminal device 900 may correspond to the second terminal device in the method embodiment of the present application, and the above and other operations and/or functions of each unit in the terminal device 900 are respectively to implement the functions shown in Figure 8
- the corresponding process of the second terminal device in method 300 is shown, and for the sake of simplicity, it will not be described again here.
- FIG. 18 shows a schematic block diagram of a relay device 1000 according to an embodiment of the present application.
- the relay device 1000 includes:
- the communication unit 1010 is configured to receive an authentication request message sent by a second terminal device; wherein the authentication request message includes at least one of the following: information about the user to which the second terminal device belongs, a first temporary public address generated by the second terminal device. key, the signature of the second terminal device; wherein the information about the user to whom the second terminal device belongs includes the signature certificate of the second terminal device, or the information about the user to whom the second terminal device belongs includes the identification of the second terminal device and the PVT and KPAK of the second terminal device; the input parameters of the signature of the second terminal device include at least one of the following: information of the user to which the second terminal device belongs and the first temporary public key; the first temporary public key Information related to the relay device is used by the first terminal device to derive the first key;
- the communication unit 1010 is also configured to send an authentication request message after verification to the first terminal device; wherein , the authentication request message after verification includes at least one of the following: information about the user to whom the second terminal device belongs, information about the user to whom the relay device belongs, the first temporary public key, the signature of the second terminal device, the The signature of the relay device, and the relevant information of the relay device; wherein, the information of the user to whom the relay device belongs includes the signature certificate of the relay device, or the information of the user to whom the relay device belongs includes the identification and identification of the relay device.
- the PVT and KPAK of the relay device; the input parameters of the relay device's signature include at least one of the following: the signature of the second terminal device and the information of the user to which the relay device belongs; wherein, the relevant information of the relay device Including one of the following: the identity information of the relay device, the random number generated by the relay device, and the counter generated by the relay device.
- the signature of the second terminal device is generated by the signature private key of the second terminal device, or, In the case where the information of the user to which the second terminal device belongs includes the identification of the second terminal device and the PVT and KPAK of the second terminal device, the signature of the second terminal device is determined by the secret signature key of the second terminal device. generate; and/or,
- the signature of the relay device is generated by the signature private key of the relay device, or when the information about the user of the relay device includes In the case of the relay device's identification and the relay device's PVT and KPAK, the relay device's signature is generated by the relay device's secret signature key.
- the communication unit 1010 is also configured to receive the first message sent by the first terminal device;
- the first message includes at least one of the following: security capability information of the first terminal device, security policy information of the first terminal device, information of the user to which the first terminal device belongs, a third message generated by the first terminal device.
- the information of the user to whom the first terminal device belongs includes the signature certificate of the first terminal device, or the information of the user to which the first terminal device belongs includes the identification of the first terminal device and the PVT and PVT of the first terminal device.
- the input parameters of the signature of the first terminal device include at least one of the following: information of the user to which the first terminal device belongs, the second temporary public key, the M bits of the identification of the first key, the third A signature of two terminal devices; wherein the first message is integrity protected by the first message verification code generated based on the first key, and the input parameters of the first message verification code include at least one of the following: the third Security capability information of a terminal device, security policy information of the first terminal device, information of the user to which the first terminal device belongs, the first random number, the second temporary public key, the M bits, the first The signature of the terminal device;
- the communication unit 1010 is also configured to send the first message after verification to the second terminal device; wherein , the first message after the verification includes at least one of the following: security capability information of the first terminal device, security policy information of the first terminal device, information of the user to which the first terminal device belongs, user information to which the relay device belongs information, the first random number generated by the first terminal device, the second temporary public key generated by the first terminal device paired with the second temporary private key, the first key generated by the first terminal device M bits of identification, the signature of the first terminal device, the signature of the relay device, and the first message verification code; wherein the information of the user to which the relay device belongs includes the signature certificate of the relay device, or, The information of the user to
- the second temporary public key and the relevant information of the relay device are used by the second terminal device to derive the first key, the first random number, the first key and the third key generated by the second terminal device.
- Two random numbers are used to derive a second key.
- the second key is used to derive an integrity protection key and/or a confidentiality protection key.
- the identity of the first key is composed of the M bits and the first The other N bits of the key's identifier are combined, and M and N are both positive integers.
- the communication unit 1010 is also used to forward the second message sent by the second terminal device to the first terminal device;
- the second message includes at least one of the following: the second random number generated by the second terminal device, N bits of the identification of the first key generated by the second terminal device, x bits of the identifier of the generated second key, the security algorithm selected by the second terminal device, the security policy selected by the second terminal device, and the second message verification code;
- the second message is integrity protected through the second message verification code generated based on the second key, or the second message is integrity protected through the third integrity protection key generated based on the second key.
- the second message verification code performs integrity protection, and the input parameters of the second message verification code include at least one of the following: the second random number, the N bits, the x bits, and the second terminal device selected Security algorithm, the security policy selected by the second terminal device;
- the identifier of the second key is obtained by combining the x bits and the other y bits of the identifier of the second key, and both x and y are positive integers.
- the second message is encrypted by the first key, and the second message also includes a third message verification code
- the second message is integrity protected by the third message verification code generated based on the first key
- the input parameters of the third message verification code include at least one of the following: the second random number, the N bits, the x bits, the security algorithm selected by the second terminal device, and the security policy selected by the second terminal device.
- the first message is an authentication response message
- the second message is a safe mode command message
- the first message is a safe mode command message
- the second message is a safe mode response message
- the communication unit 1010 is also used to forward the third message sent by the first terminal device to the second terminal device;
- the third message is used to indicate that the security mode establishment is completed, the third message is encrypted by the target key, and the third message includes at least one of the following: the identification of the second key generated by the first terminal device y bits, the fourth message verification code;
- the target key includes one of the following: the first key, the second key, and a confidentiality protected key derived from the second key;
- the third message is integrity protected through the fourth message verification code generated based on the second key, or the third message is integrity protected through the third message verification code generated based on the integrity protection key derived based on the second key.
- the four-message verification code performs integrity protection, and the input parameters of the fourth message verification code include the y bits.
- the communication unit 1010 is also used to forward the error message sent by the second terminal device to the first terminal device; wherein the error message includes at least one of the following: cause information, fifth message verification code ;
- the reason information is used to indicate that the security policy of the second terminal device conflicts with the first terminal device, or the reason information is used to indicate that the first message verification code verification fails, or the reason information is used to indicate
- the security algorithm negotiation between the second terminal device and the first terminal device fails, and the input parameters of the fifth message verification code include at least one of the following: the reason information.
- the integrity protection key includes an integrity protection key for the control plane and an integrity protection key for the user plane; and/or the confidentiality protection key includes a confidentiality protection key for the control plane. and user plane confidentiality protecting keys.
- the communication unit 1010 is also configured to forward the direct communication request sent by the first terminal device to the second terminal device;
- the direct communication request includes at least one of the following: source identifier, target identifier;
- the source identifier is used to identify the source end of the relay connection between the first terminal device and the second terminal device
- the target identifier is used to identify the intermediate connection between the first terminal device and the second terminal device. The destination of the connection.
- the above-mentioned communication unit may be a communication interface or transceiver, or an input/output interface of a communication chip or a system on a chip.
- relay device 1000 may correspond to the relay device in the method embodiment of the present application, and the above and other operations and/or functions of each unit in the relay device 1000 are respectively to implement FIG. 9
- the corresponding process of the relay device in the method 400 shown is not repeated here for the sake of simplicity.
- Figure 19 shows a schematic block diagram of a terminal device 1100 according to an embodiment of the present application.
- the terminal device 1100 is a first terminal device, and the terminal device 1100 includes:
- Communication unit 1110 configured to send the first message to the second terminal device through the relay device
- the first message includes at least one of the following: security capability information of the first terminal device, security policy information of the first terminal device, information of the user to which the first terminal device belongs, a third message generated by the first terminal device.
- security capability information of the first terminal device security policy information of the first terminal device
- information of the user to which the first terminal device belongs a third message generated by the first terminal device.
- the information about the user to whom the first terminal device belongs includes the signature certificate of the first terminal device, or the information about the user to whom the first terminal device belongs includes the identification of the first terminal device and the PVT and KPAK of the first terminal device.
- the input parameters of the signature of the first terminal device include at least one of the following: information of the user to which the first terminal device belongs, the second temporary public key, M bits of the identification of the first key, the second The signature of the terminal device;
- the first message is integrity protected by the first message verification code generated based on the first key
- the input parameters of the first message verification code include at least one of the following: the security capability of the first terminal device Information, the security policy information of the first terminal device, the information of the user to which the first terminal device belongs, the first random number, the second temporary public key, the M bits, and the signature of the first terminal device;
- the second temporary public key and the relevant information of the relay device are used by the second terminal device to derive the first key, the first random number, the first key and the third key generated by the second terminal device.
- Two random numbers are used to derive a second key.
- the second key is used to derive an integrity protection key and/or a confidentiality protection key.
- the identity of the first key is composed of the M bits and the first The other N bits of the key's identification are combined, and M and N are both positive integers;
- the relevant information of the relay device includes one of the following: identity information of the relay device, a random number generated by the relay device, and a counter generated by the relay device.
- the communication unit 1110 is also used to receive the second message sent by the second terminal device through the relay device;
- the second message includes at least one of the following: the second random number generated by the second terminal device, N bits of the identification of the first key generated by the second terminal device, x bits of the identifier of the generated second key, the security algorithm selected by the second terminal device, the security policy selected by the second terminal device, and the second message verification code;
- the second message is integrity protected through the second message verification code generated based on the second key, or the second message is integrity protected through the third integrity protection key generated based on the second key.
- the second message verification code performs integrity protection, and the input parameters of the second message verification code include at least one of the following: the second random number, the N bits, the x bits, and the second terminal device selected Security algorithm, the security policy selected by the second terminal device;
- the identifier of the second key is obtained by combining the x bits and the other y bits of the identifier of the second key, and both x and y are positive integers.
- the second message is encrypted by the first key, and the second message also includes a third message verification code
- the second message is integrity protected by the third message verification code generated based on the first key
- the input parameters of the third message verification code include at least one of the following: the second random number, the N bits, the x bits, the security algorithm selected by the second terminal device, and the security policy selected by the second terminal device.
- the terminal device 1100 further includes: a processing unit 1120;
- the processing unit 1120 is configured to generate the second key based on at least the first random number, the first key and the second random number.
- the unit 1120 is used to generate an integrity protection key and/or a confidentiality protection key according to the second key, and the processing unit 1120 is used to combine the M bits and the N bits to obtain the first secret key.
- the identification of the second key, the processing unit 1120 is used to generate y bits of the identification of the second key, and combine the x bits and the y bits to obtain the identification of the second key;
- the communication unit 1110 is also configured to generate an integrity protection key based on the second key and/or the security algorithm selected by the second terminal device and the second key. Or the confidentiality protection key and the security policy selected by the second terminal device are used to communicate with the second terminal device.
- the processing unit 1120 is configured to decrypt the second message according to the first key
- the processing unit 1120 is configured to generate the second key based on at least the first random number, the first key and the second random number.
- the unit 1120 is used to generate an integrity protection key and/or a confidentiality protection key according to the second key, and the processing unit 1120 is used to combine the M bits and the N bits to obtain the first secret key.
- the identification of the second key, the processing unit 1120 is used to generate y bits of the identification of the second key, and combine the x bits and the y bits to obtain the identification of the second key;
- the communication unit 1110 is also configured to generate The integrity protection key and/or the confidentiality protection key and the security policy selected by the second terminal device are communicated with the second terminal device.
- the input parameters of the integrity protection key include at least one of the following: the second key, the selected algorithm type identifier, the length of the selected algorithm type identifier, and the integrity protection algorithm identifier.
- the length of the integrity protection algorithm identifier; and/or, the input parameters of the confidentiality protection key include at least one of the following: the second key, the selected algorithm type identifier, the selected algorithm type identifier Length, confidentiality protection algorithm identifier, length of the confidentiality protection algorithm identifier.
- the first message is an authentication response message
- the second message is a safe mode command message
- the first message is a safe mode command message
- the second message is a safe mode response message
- the communication unit 1110 is also used to send a third message to the second terminal device through the relay device;
- the third message is used to indicate that the security mode establishment is completed, the third message is encrypted by the target key, and the third message includes at least one of the following: the y bits of the identification of the second key, Fourth message verification code;
- the target key includes one of the following: the first key, the second key, and a confidentiality protected key derived from the second key;
- the third message is integrity protected through the fourth message verification code generated based on the second key, or the third message is integrity protected through the third message verification code generated based on the integrity protection key derived based on the second key.
- the four-message verification code performs integrity protection, and the input parameters of the fourth message verification code include the y bits.
- the communication unit 1110 is also configured to receive an error message sent by the second terminal device through the relay device; wherein the error message includes at least one of the following: cause information, fifth message verification code; wherein , the reason information is used to indicate that the security policy of the second terminal device conflicts with the first terminal device, or the reason information is used to indicate that the first message verification code verification fails, or the reason information is used to indicate that the third If the security algorithm negotiation between the second terminal device and the first terminal device fails, the input parameters of the fifth message verification code include at least one of the following: the reason information;
- the processing unit 1120 is configured to determine that the security mode establishment fails, and/or the processing unit 1120 is configured to reinitiate the security mode establishment process.
- the integrity protection key includes an integrity protection key for the control plane and an integrity protection key for the user plane; and/or the confidentiality protection key includes a confidentiality protection key for the control plane. and user plane confidentiality protecting keys.
- the communication unit 1110 is also configured to receive an authentication request message sent by the second terminal device through the relay device;
- the authentication request message includes at least one of the following: information about the user to which the second terminal device belongs, information about the user to which the relay device belongs, the first temporary public key generated by the second terminal device, Signature, the signature of the relay device, and relevant information of the relay device;
- the information about the user to whom the second terminal device belongs includes the signature certificate of the second terminal device, or the information about the user to whom the second terminal device belongs includes the identification of the second terminal device and the PVT and KPAK of the second terminal device.
- the information of the user of the relay device includes the signature certificate of the relay device, or the information of the user of the relay device includes the identification of the relay device and the PVT and KPAK of the relay device;
- the input parameters of the signature include at least one of the following: the information of the user to which the second terminal device belongs and the first temporary public key;
- the input parameters of the signature of the relay device include at least one of the following: the signature of the second terminal device and the information of the user to which the relay device belongs; the first temporary public key and the relevant information of the relay device are used by the first terminal device to derive the first key.
- the signature of the second terminal device is generated by the signature private key of the second terminal device, or, In the case where the information of the user to which the second terminal device belongs includes the identification of the second terminal device and the PVT and KPAK of the second terminal device, the signature of the second terminal device is determined by the secret signature key of the second terminal device. generate; and/or,
- the signature of the relay device is generated by the signature private key of the relay device, or when the information about the user of the relay device includes In the case of the relay device's identification and the relay device's PVT and KPAK, the relay device's signature is generated by the relay device's secret signature key.
- the terminal device 1100 further includes: a processing unit 1120;
- the signature certificate of the second terminal device and the signature certificate of the relay device are valid, and the signature verification of the second terminal device based on the signature certificate of the second terminal device is successful, and the signature certificate of the relay device is valid. If the signature verification of the relay device is successful, the processing unit 1120 is configured to generate a second temporary private key paired with the second temporary public key, and the processing unit 1120 is configured to generate a second temporary private key based on the first temporary public key and the second temporary public key.
- the first key is derived from the relevant information of the relay device and the second temporary private key; or,
- the KPAK of the second terminal device and the KPAK of the relay device are valid, and the signature verification of the second terminal device based on the identity of the second terminal device and the PVT of the second terminal device is successful, and based on the relay If the identification of the device and the PVT of the relay device successfully verify the signature of the relay device, the processing unit 1120 is configured to generate a second temporary private key paired with the second temporary public key, and the processing unit 1120 Used to derive the first key according to the first temporary public key, the relevant information of the relay device and the second temporary private key.
- the communication unit 1110 is also configured to send a direct communication request to the second terminal device through the relay device;
- the direct communication request includes at least one of the following: source identifier, target identifier;
- the source identifier is used to identify the source end of the relay connection between the first terminal device and the second terminal device
- the target identifier is used to identify the intermediate connection between the first terminal device and the second terminal device. The destination of the connection.
- the above-mentioned communication unit may be a communication interface or transceiver, or an input/output interface of a communication chip or a system on a chip.
- the above-mentioned processing unit may be one or more processors.
- terminal device 1100 may correspond to the first terminal device in the method embodiment of the present application, and the above and other operations and/or functions of each unit in the terminal device 1100 are respectively intended to realize what is shown in Figure 10
- the corresponding process of the first terminal device in method 500 is shown, and for the sake of simplicity, it will not be described again here.
- Figure 20 shows a schematic block diagram of a terminal device 1200 according to an embodiment of the present application.
- the terminal device 1200 is a second terminal device, and the terminal device 1200 includes:
- Communication unit 1210 configured to receive the first message sent by the first terminal device through the relay device
- the first message includes at least one of the following: security capability information of the first terminal device, security policy information of the first terminal device, information of the user to which the first terminal device belongs, and information of the user to which the relay device belongs. , the first random number generated by the first terminal device, the second temporary public key generated by the first terminal device, the M bits of the identification of the first key generated by the first terminal device, the first terminal device signature, the signature of the relay device, and the first message verification code;
- the information about the user to whom the first terminal device belongs includes the signature certificate of the first terminal device, or the information about the user to whom the first terminal device belongs includes the identification of the first terminal device and the public verification command of the first terminal device.
- brand PVT and the public authentication key KPAK of the key management server the information of the user of the relay device includes the signature certificate of the relay device, or the information of the user of the relay device includes the identification of the relay device and the PVT and KPAK of the relay device
- the input parameters of the signature of the first terminal device include at least one of the following: information of the user to which the first terminal device belongs, the second temporary public key, and the identification M of the first key bits, the signature of the second terminal device
- the input parameters of the signature of the relay device include at least one of the following: information of the user to which the relay device belongs, the signature of the first terminal device, the signature of the second terminal device sign;
- the first message is integrity protected by the first message verification code generated based on the first key
- the input parameters of the first message verification code include at least one of the following: the security capability of the first terminal device Information, the security policy information of the first terminal device, the information of the user to which the first terminal device belongs, the first random number, the second temporary public key, the M bits, and the signature of the first terminal device;
- the second temporary public key and the relevant information of the relay device are used by the second terminal device to derive the first key, the first random number, the first key and the third key generated by the second terminal device.
- Two random numbers are used to derive a second key.
- the second key is used to derive an integrity protection key and/or a confidentiality protection key.
- the identity of the first key is composed of the M bits and the first The other N bits of the key's identification are combined, and M and N are both positive integers;
- the relevant information of the relay device includes one of the following: identity information of the relay device, a random number generated by the relay device, and a counter generated by the relay device.
- the signature of the first terminal device is generated by the signature private key of the first terminal device, or, In the case where the information of the user to which the first terminal device belongs includes the identification of the first terminal device and the PVT and KPAK of the first terminal device, the signature of the first terminal device is determined by the secret signature key of the first terminal device. generate; and/or,
- the signature of the relay device is generated by the signature private key of the relay device, or when the information about the user of the relay device includes In the case of the relay device's identification and the relay device's PVT and KPAK, the relay device's signature is generated by the relay device's secret signature key.
- the terminal device 1200 further includes: a processing unit 1220;
- the processing unit 1220 is configured to check the signature certificate of the first terminal device and the signature certificate of the relay device respectively. If the signature certificate of the first terminal device and the signature certificate of the relay device are valid, the processing unit 1220 is used to verify the signature of the first terminal device based on the signature certificate of the first terminal device, and the second terminal device verifies the signature of the relay device based on the signature certificate of the relay device; or, the The processing unit 1220 is configured to check the KPAK of the first terminal device and the KPAK of the relay device respectively.
- the KPAK of the first terminal device and the KPAK of the relay device are valid, and based on the KPAK of the first terminal device, verifying the signature of the first terminal device based on the identity and the PVT of the first terminal device, and verifying the signature of the relay device based on the identity of the relay device and the PVT of the relay device;
- the processing unit 1220 is configured to generate a second random number.
- the processing unit 1220 is configured to generate an integrity protection key and/or a secret based on at least the first random number, the first key and the second random number.
- sexually protected key and the processing unit 1220 is used to generate N bits of the identification of the first key, and combine the M bits and the N bits to obtain the identification of the first key;
- the communication unit 1210 is also configured to send a second message to the first terminal device through the relay device; wherein the second message includes at least one of the following: the second The random number, the N bits, the x bits of the identifier of the second key generated by the second terminal device, the security algorithm selected by the second terminal device, the security policy selected by the second terminal device, the Two message verification code;
- the second message is integrity protected through the second message verification code generated based on the second key, or the second message is integrity protected through the third integrity protection key generated based on the second key.
- the second message verification code performs integrity protection, and the input parameters of the second message verification code include at least one of the following: the second random number, the N bits, the x bits, and the second terminal device selected Security algorithm, the security policy selected by the second terminal device;
- the identifier of the second key is obtained by combining the x bits and the other y bits of the identifier of the second key, and both x and y are positive integers.
- the second message is encrypted by the first key, and the second message also includes a third message verification code
- the second message is integrity protected by the third message verification code generated based on the first key
- the input parameters of the third message verification code include at least one of the following: the second random number, the N bits, the x bits, the security algorithm selected by the second terminal device, and the security policy selected by the second terminal device.
- the first message is an authentication response message
- the second message is a safe mode command message
- the first message is a safe mode command message
- the second message is a safe mode response message
- the input parameters of the integrity protection key include at least one of the following: the second key, the selected algorithm type identifier, the length of the selected algorithm type identifier, and the integrity protection algorithm identifier.
- the length of the integrity protection algorithm identifier; and/or, the input parameters of the confidentiality protection key include at least one of the following: the second key, the selected algorithm type identifier, the selected algorithm type identifier Length, confidentiality protection algorithm identifier, length of the confidentiality protection algorithm identifier.
- the communication unit 1210 is also configured to receive a third message sent by the first terminal device through the relay device;
- the third message is used to indicate that the security mode establishment is completed, the third message is encrypted by the target key, and the third message includes at least one of the following: the identification of the second key generated by the first terminal device y bits, the fourth message verification code;
- the target key includes one of the following: the first key, the second key, and a confidentiality protected key derived from the second key;
- the third message is integrity protected through the fourth message verification code generated based on the second key, or the third message is integrity protected through the third message verification code generated based on the integrity protection key derived based on the second key.
- the four-message verification code performs integrity protection, and the input parameters of the fourth message verification code include the y bits.
- the terminal device 1200 further includes: a processing unit 1220;
- the processing unit 1220 is configured to decrypt the third message through the target key
- the processing unit 1220 is also configured to combine the x bits and the y bits to obtain the The identifier of the second key.
- the communication unit 1210 is also configured to send an error message to the first terminal device through the relay device; wherein the error message includes at least one of the following: cause information, fifth message verification code; wherein, The reason information is used to indicate that the security policy of the second terminal device conflicts with the first terminal device, or the reason information is used to indicate that the first message verification code verification fails, or the reason information is used to indicate that the second terminal device
- the security algorithm negotiation between the terminal device and the first terminal device fails, and the input parameters of the fifth message verification code include at least one of the following: the reason information.
- the integrity protection key includes an integrity protection key for the control plane and an integrity protection key for the user plane; and/or the confidentiality protection key includes a confidentiality protection key for the control plane. and user plane confidentiality protecting keys.
- the communication unit 1210 is also configured to send an authentication request message to the first terminal device through the relay device;
- the authentication request message includes at least one of the following: information about the user to which the second terminal device belongs, the first temporary public key generated by the second terminal device, the signature of the second terminal device, and relevant information about the relay device. ;
- the information about the user to whom the second terminal device belongs includes the signature certificate of the second terminal device, or the information about the user to whom the second terminal device belongs includes the identification of the second terminal device and the public verification command of the second terminal device.
- the public authentication key KPAK of the brand PVT and the key management server; the input parameters of the signature of the second terminal device include at least one of the following: the information of the user to which the second terminal device belongs and the first temporary public key; the first The temporary public key and related information of the relay device are used by the first terminal device to derive the first key.
- the signature of the second terminal device is generated by the signature private key of the second terminal device, or, In the case where the information of the user to which the second terminal device belongs includes the identification of the second terminal device and the PVT and KPAK of the second terminal device, the signature of the second terminal device is determined by the secret signature key of the second terminal device. generate.
- the communication unit 1210 is also used to receive a direct communication request sent by the first terminal device through the relay device;
- the direct communication request includes at least one of the following: source identifier, target identifier;
- the source identifier is used to identify the source end of the relay connection between the first terminal device and the second terminal device
- the target identifier is used to identify the intermediate connection between the first terminal device and the second terminal device. The destination of the connection.
- the above-mentioned communication unit may be a communication interface or transceiver, or an input/output interface of a communication chip or a system on a chip.
- the above-mentioned processing unit may be one or more processors.
- terminal device 1200 may correspond to the second terminal device in the method embodiment of the present application, and the above and other operations and/or functions of each unit in the terminal device 1200 are respectively to implement the functions shown in Figure 11
- the corresponding process of the second terminal device in method 600 is shown, and for the sake of simplicity, it will not be described again here.
- Figure 21 shows a schematic block diagram of a relay device 1300 according to an embodiment of the present application. As shown in Figure 21, the relay device 1300 includes:
- Communication unit 1310 configured to receive the first message sent by the first terminal device
- the first message includes at least one of the following: security capability information of the first terminal device, security policy information of the first terminal device, information of the user to which the first terminal device belongs, a third message generated by the first terminal device.
- the information about the user to whom the first terminal device belongs includes the signature certificate of the first terminal device, or the information about the user to whom the first terminal device belongs includes the identification of the first terminal device and the public verification command of the first terminal device.
- the input parameters of the signature of the first terminal device include at least one of the following: information of the user to which the first terminal device belongs, the second temporary public key, the first M bits of the identification of the key, the signature of the second terminal device; wherein the first message is integrity protected by the first message verification code generated based on the first key, and the first message verification
- the input parameters of the code include at least one of the following: security capability information of the first terminal device, security policy information of the first terminal device, information of the user to which the first terminal device belongs, the first random number, the second temporary The public key, the M bits, the signature of the first terminal device;
- the communication unit 1310 is also used to send the first message after verification to the second terminal device; wherein , the first message after the verification includes at least one of the following: security capability information of the first terminal device, security policy information of the first terminal device, information of the user to which the first terminal device belongs, user information to which the relay device belongs information, the first random number generated by the first terminal device, the second temporary public key generated by the first terminal device paired with the second temporary private key, the first key generated by the first terminal device M bits of identification, the signature of the first terminal device, the signature of the relay device, the relevant information of the relay device, and the first message verification code; wherein, the information of the user to which the relay device belongs includes the The signature certificate of the relay
- the second temporary public key and the relevant information of the relay device are used by the second terminal device to derive the first key, the first random number, the first key and the third key generated by the second terminal device.
- Two random numbers are used to derive a second key.
- the second key is used to derive an integrity protection key and/or a confidentiality protection key.
- the identity of the first key is composed of the M bits and the first
- the other N bits of the key's identification are combined, and M and N are both positive integers; among them, the relevant information of the relay device includes one of the following: the identity information of the relay device, the random number generated by the relay device. Count, the counter generated by this relay device.
- the communication unit 1310 is also used to forward the second message sent by the second terminal device to the first terminal device; wherein the second message includes at least one of the following: generated by the second terminal device The second random number, N bits of the identifier of the first key generated by the second terminal device, x bits of the identifier of the second key generated by the second terminal device, the second The security algorithm selected by the terminal device, the security policy selected by the second terminal device, and the second message verification code; wherein the second message is integrity protected by the second message verification code generated based on the second key, or , the second message is integrity protected by the second message verification code generated based on the integrity protection key derived from the second key, and the input parameters of the second message verification code include at least one of the following: the first 2 random numbers, the N bits, the x bits, the security algorithm selected by the second terminal device, and the security policy selected by the second terminal device; wherein, the identity of the second key is represented by the x bits bit is combined with other y bits of the identifier of
- the second message is encrypted by the first key, and the second message also includes a third message verification code
- the second message is integrity protected by the third message verification code generated based on the first key
- the input parameters of the third message verification code include at least one of the following: the second random number, the N bits, the x bits, the security algorithm selected by the second terminal device, and the security policy selected by the second terminal device.
- the first message is an authentication response message
- the second message is a safe mode command message
- the first message is a safe mode command message
- the second message is a safe mode response message
- the communication unit 1310 is also used to forward the third message sent by the first terminal device to the second terminal device; wherein the third message is used to indicate that the security mode establishment is completed, and the third message Encryption is performed using the target key, and the third message includes at least one of the following: y bits of the identification of the second key generated by the first terminal device, and a fourth message verification code; wherein, the target key Including one of the following: the first key, the second key, a confidentiality protection key derived from the second key; wherein the third message is verified by the fourth message generated based on the second key code for integrity protection, or the third message is integrity protected by the fourth message verification code generated based on the integrity protection key derived from the second key, and the input parameters of the fourth message verification code include the y bits.
- the communication unit 1310 is also used to forward the error message sent by the second terminal device to the first terminal device; wherein the error message includes at least one of the following: cause information, fifth message verification code ;
- the reason information is used to indicate that the security policy of the second terminal device conflicts with the first terminal device, or the reason information is used to indicate that the first message verification code verification fails, or the reason information is used to indicate
- the security algorithm negotiation between the second terminal device and the first terminal device fails, and the input parameters of the fifth message verification code include at least one of the following: the reason information.
- the integrity protection key includes an integrity protection key for the control plane and an integrity protection key for the user plane; and/or the confidentiality protection key includes a confidentiality protection key for the control plane. and user plane confidentiality protecting keys.
- the communication unit 1310 is also configured to receive an authentication request message sent by the second terminal device; wherein the authentication request message includes at least one of the following: information about the user to which the second terminal device belongs, the second terminal device.
- the first temporary public key generated by the terminal device, the signature of the second terminal device; wherein the information of the user to which the second terminal device belongs includes the signature certificate of the second terminal device, or the information of the user to which the second terminal device belongs It includes the identification of the second terminal device, the public verification token PVT of the second terminal device and the public authentication key KPAK of the key management server;
- the input parameters of the signature of the second terminal device include at least one of the following: the first The information of the user to which the two terminal devices belong and the first temporary public key; the first temporary public key and the relevant information of the relay device are used for the first terminal device to derive the first key;
- the communication unit 1310 is also configured to send an authentication request message after verification to the first terminal device; wherein , the authentication request message after verification includes at least one of the following: information about the user to whom the second terminal device belongs, information about the user to whom the relay device belongs, the first temporary public key, the signature of the second terminal device, the The signature of the relay device, and the relevant information of the relay device; wherein, the information of the user to whom the relay device belongs includes the signature certificate of the relay device, or the information of the user to whom the relay device belongs includes the identification and identification of the relay device.
- the PVT and KPAK of the relay device; the input parameters of the signature of the relay device include at least one of the following: the signature of the second terminal device
- the signature of the second terminal device is generated by the signature private key of the second terminal device, or, In the case where the information of the user to which the second terminal device belongs includes the identification of the second terminal device and the PVT and KPAK of the second terminal device, the signature of the second terminal device is determined by the secret signature key of the second terminal device. generate; and/or,
- the signature of the relay device is generated by the signature private key of the relay device, or when the information about the user of the relay device includes In the case of the relay device's identification and the relay device's PVT and KPAK, the relay device's signature is generated by the relay device's secret signature key.
- the communication unit 1310 is also used to forward the direct communication request sent by the first terminal device to the second terminal device; wherein the direct communication request includes at least one of the following: source identification, target identification; Wherein, the source identifier is used to identify the source end of the relay connection between the first terminal device and the second terminal device, and the target identifier is used to identify the intermediate connection between the first terminal device and the second terminal device. The destination of the connection.
- the above-mentioned communication unit may be a communication interface or transceiver, or an input/output interface of a communication chip or a system on a chip.
- relay device 1300 may correspond to the relay device in the method embodiment of the present application, and the above and other operations and/or functions of each unit in the relay device 1300 are respectively to implement Figure 12
- the corresponding process of the relay device in the method 700 shown is not repeated here for the sake of simplicity.
- Figure 22 is a schematic structural diagram of a communication device 1400 provided by an embodiment of the present application.
- the communication device 1400 shown in Figure 22 includes a processor 1410.
- the processor 1410 can call and run a computer program from the memory to implement the method in the embodiment of the present application.
- communication device 1400 may also include memory 1420.
- the processor 1410 can call and run the computer program from the memory 1420 to implement the method in the embodiment of the present application.
- the memory 1420 may be a separate device independent of the processor 1410, or may be integrated into the processor 1410.
- the communication device 1400 may also include a transceiver 1430, and the processor 1410 may control the transceiver 1430 to communicate with other devices, specifically, may send information or data to other devices, or Receive information or data from other devices.
- the transceiver 1430 may include a transmitter and a receiver.
- the transceiver 1430 may further include an antenna, and the number of antennas may be one or more.
- the communication device 1400 may be a terminal device according to the embodiment of the present application, and the communication device 1400 may implement the corresponding processes implemented by the first terminal device or the second terminal device in each method of the embodiment of the present application. , for the sake of brevity, will not be repeated here.
- the communication device 1400 can be a relay device in the embodiment of the present application, and the communication device 1400 can implement the corresponding processes implemented by the relay device in the various methods of the embodiment of the present application. For simplicity, in This will not be described again.
- Figure 23 is a schematic structural diagram of the device according to the embodiment of the present application.
- the device 1500 shown in Figure 23 includes a processor 1510.
- the processor 1510 can call and run a computer program from the memory to implement the method in the embodiment of the present application.
- device 1500 may also include memory 1520.
- the processor 1510 can call and run the computer program from the memory 1520 to implement the method in the embodiment of the present application.
- the memory 1520 may be a separate device independent of the processor 1510, or may be integrated into the processor 1510.
- the device 1500 may also include an input interface 1530.
- the processor 1510 can control the input interface 1530 to communicate with other devices or chips. Specifically, it can obtain information or data sent by other devices or chips.
- the device 1500 may also include an output interface 1540.
- the processor 1510 can control the output interface 1540 to communicate with other devices or chips. Specifically, it can output information or data to other devices or chips.
- the device can be applied to the terminal device in the embodiment of the present application, and the device can implement the corresponding processes implemented by the first terminal device or the second terminal device in each method of the embodiment of the present application. For the sake of simplicity , which will not be described in detail here.
- the device can be applied to the relay device in the embodiments of the present application, and the device can implement the corresponding processes implemented by the relay device in the various methods of the embodiments of the present application. For the sake of brevity, they will not be repeated here. Repeat.
- the devices mentioned in the embodiments of this application may also be chips.
- it can be a system-on-a-chip, a system-on-a-chip, a system-on-a-chip or a system-on-a-chip, etc.
- Figure 24 is a schematic block diagram of a communication system 1600 provided by an embodiment of the present application. As shown in Figure 24, the communication system 1600 includes a first terminal device 1610, a relay device 1620 and a second terminal device 1630.
- the first terminal device 1610 can be used to implement the corresponding functions implemented by the first terminal device in the above method
- the relay device 1620 can be used to implement the corresponding functions implemented by the relay device in the above method
- the The second terminal device 1630 may be used to implement the corresponding functions implemented by the second terminal device in the above method, which will not be described again for the sake of simplicity.
- the processor in the embodiment of the present application may be an integrated circuit chip and has signal processing capabilities.
- each step of the above method embodiment can be completed through an integrated logic circuit of hardware in the processor or instructions in the form of software.
- the above-mentioned processor can be a general-purpose processor, a digital signal processor (Digital Signal Processor, DSP), an application specific integrated circuit (Application Specific Integrated Circuit, ASIC), an off-the-shelf programmable gate array (Field Programmable Gate Array, FPGA) or other available processors.
- DSP Digital Signal Processor
- ASIC Application Specific Integrated Circuit
- FPGA Field Programmable Gate Array
- a general-purpose processor may be a microprocessor or the processor may be any conventional processor, etc.
- the steps of the method disclosed in conjunction with the embodiments of the present application can be directly implemented by a hardware decoding processor, or executed by a combination of hardware and software modules in the decoding processor.
- the software module can be located in random access memory, flash memory, read-only memory, programmable read-only memory or electrically erasable programmable memory, registers and other mature storage media in this field.
- the storage medium is located in the memory, and the processor reads the information in the memory and completes the steps of the above method in combination with its hardware.
- non-volatile memory can be read-only memory (Read-Only Memory, ROM), programmable read-only memory (Programmable ROM, PROM), erasable programmable read-only memory (Erasable PROM, EPROM), electrically removable memory. Erase programmable read-only memory (Electrically EPROM, EEPROM) or flash memory. Volatile memory may be Random Access Memory (RAM), which is used as an external cache.
- RAM Random Access Memory
- RAM static random access memory
- DRAM dynamic random access memory
- DRAM synchronous dynamic random access memory
- SDRAM double data rate synchronous dynamic random access memory
- Double Data Rate SDRAM DDR SDRAM
- enhanced SDRAM ESDRAM
- Synchlink DRAM SLDRAM
- Direct Rambus RAM Direct Rambus RAM
- the memory in the embodiment of the present application can also be a static random access memory (static RAM, SRAM), a dynamic random access memory (dynamic RAM, DRAM), Synchronous dynamic random access memory (synchronous DRAM, SDRAM), double data rate synchronous dynamic random access memory (double data rate SDRAM, DDR SDRAM), enhanced synchronous dynamic random access memory (enhanced SDRAM, ESDRAM), synchronous connection Dynamic random access memory (synch link DRAM, SLDRAM) and direct memory bus random access memory (Direct Rambus RAM, DR RAM) and so on. That is, memories in embodiments of the present application are intended to include, but are not limited to, these and any other suitable types of memories.
- Embodiments of the present application also provide a computer-readable storage medium for storing computer programs.
- the computer-readable storage medium can be applied to the terminal device in the embodiment of the present application, and the computer program causes the computer to perform the various methods implemented by the first terminal device or the second terminal device in the embodiment of the present application.
- the corresponding process, for the sake of brevity, will not be repeated here.
- the computer-readable storage medium can be applied to the relay device in the embodiment of the present application, and the computer program causes the computer to execute the corresponding processes implemented by the relay device in the various methods of the embodiment of the present application, in order to It’s concise and I won’t go into details here.
- An embodiment of the present application also provides a computer program product, including computer program instructions.
- the computer program product can be applied to the terminal device in the embodiments of the present application, and the computer program instructions cause the computer to perform the methods implemented by the first terminal device or the second terminal device in the embodiments of the present application.
- the corresponding process will not be repeated here for the sake of brevity.
- the computer program product can be applied to the relay device in the embodiment of the present application, and the computer program instructions cause the computer to execute the corresponding processes implemented by the relay device in the various methods of the embodiment of the present application.
- the computer program instructions cause the computer to execute the corresponding processes implemented by the relay device in the various methods of the embodiment of the present application.
- An embodiment of the present application also provides a computer program.
- the computer program can be applied to the terminal device in the embodiment of the present application.
- the computer program When the computer program is run on the computer, the computer performs the various methods of the embodiment of the present application by the first terminal device or the second terminal device. For the sake of simplicity, the corresponding process implemented by the terminal device will not be described again here.
- the computer program can be applied to the relay device in the embodiment of the present application.
- the computer program When the computer program is run on the computer, the computer performs the corresponding steps implemented by the relay device in each method of the embodiment of the present application. The process, for the sake of brevity, will not be repeated here.
- the disclosed systems, devices and methods can be implemented in other ways.
- the device embodiments described above are only illustrative.
- the division of the units is only a logical function division. In actual implementation, there may be other division methods.
- multiple units or components may be combined or can be integrated into another system, or some features can be ignored, or not implemented.
- the coupling or direct coupling or communication connection between each other shown or discussed may be through some interfaces, and the indirect coupling or communication connection of the devices or units may be in electrical, mechanical or other forms.
- the units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place, or they may be distributed to multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.
- each functional unit in each embodiment of the present application can be integrated into one processing unit, each unit can exist physically alone, or two or more units can be integrated into one unit.
- the functions are implemented in the form of software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium.
- the technical solution of the present application is essentially or the part that contributes to the existing technology or the part of the technical solution can be embodied in the form of a software product.
- the computer software product is stored in a storage medium, including Several instructions are used to cause a computer device (which may be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in various embodiments of this application.
- the aforementioned storage media include: U disk, mobile hard disk, read-only memory (ROM), random access memory (Random Access Memory, RAM), magnetic disk or optical disk and other media that can store program code. .
Landscapes
- Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Mobile Radio Communication Systems (AREA)
Abstract
本申请实施例提供了一种中继通信的方法及设备,能够保证终端身份安全与通信数据的机密性与完整性,从而确保双方传输数据的机密性和完整性,防止其他设备甚至中继设备的窃听。
Description
本申请实施例涉及通信领域,并且更具体地,涉及一种中继通信的方法及设备。
在通过中继设备(relay)实现源终端和目标终端通信的架构(终端至终端中继(UE-to-UE relay))中,如何保证终端身份安全与通信数据的机密性与完整性,是一个需要解决的问题。
发明内容
本申请实施例提供了一种中继通信的方法及设备,能够保证终端身份安全与通信数据的机密性与完整性,从而确保双方传输数据的机密性和完整性,防止其他设备甚至中继设备的窃听。
第一方面,提供了一种中继通信的方法,该方法包括:
第一终端设备接收第二终端设备通过中继设备发送的认证请求消息;
其中,该认证请求消息包括以下至少之一:该第二终端设备所属用户的信息,该中继设备所属用户的信息,该第二终端设备生成的第一临时公钥,该第二终端设备的签名,该中继设备的签名,该中继设备的相关信息;
其中,该第二终端设备所属用户的信息包括该第二终端设备的签名证书,或者,该第二终端设备所属用户的信息包括该第二终端设备的标识和该第二终端设备的PVT和KPAK;该中继设备所属用户的信息包括该中继设备的签名证书,或者,该中继设备所属用户的信息包括该中继设备的标识和该中继设备的PVT和KPAK;该第二终端设备的签名的输入参数包括以下至少之一:该第二终端设备所属用户的信息和该第一临时公钥;该中继设备的签名的输入参数包括以下至少之一:该第二终端设备的签名和该中继设备所属用户的信息;该第一临时公钥和该中继设备的相关信息用于该第一终端设备派生第一密钥;该中继设备的相关信息包括以下之一:该中继设备的身份信息,该中继设备生成的随机数,该中继设备生成的计数器。
第二方面,提供了一种中继通信的方法,该方法包括:
第二终端设备通过中继设备向第一终端设备发送认证请求消息;
其中,该认证请求消息包括以下至少之一:该第二终端设备所属用户的信息,该第二终端设备生成的第一临时公钥,该第二终端设备的签名,该中继设备的相关信息;
其中,该第二终端设备所属用户的信息包括该第二终端设备的签名证书,或者,该第二终端设备所属用户的信息包括该第二终端设备的标识和该第二终端设备的PVT和KPAK;该第二终端设备的签名的输入参数包括以下至少之一:该第二终端设备所属用户的信息和该第一临时公钥;该第一临时公钥和该中继设备的相关信息用于该第一终端设备派生第一密钥;该中继设备的相关信息包括以下之一:该中继设备的身份信息,该中继设备生成的随机数,该中继设备生成的计数器。
第三方面,提供了一种中继通信的方法,该方法包括:
中继设备接收第二终端设备发送的认证请求消息;其中,该认证请求消息包括以下至少之一:该第二终端设备所属用户的信息,该第二终端设备生成的第一临时公钥,该第二终端设备的签名;其中,该第二终端设备所属用户的信息包括该第二终端设备的签名证书,或者,该第二终端设备所属用户的信息包括该第二终端设备的标识和该第二终端设备的PVT和KPAK;该第二终端设备的签名的输入参数包括以下至少之一:该第二终端设备所属用户的信息和该第一临时公钥;该第一临时公钥和该中继设备的相关信息用于该第一终端设备派生该第一密钥;
在该第二终端设备的签名证书有效,且基于该第二终端设备的签名证书对该第二终端设备的签名验证成功的情况下,或者,在该第二终端设备的KPAK有效,且基于该第二终端设备的标识和该第二终端设备的PVT对该第二终端设备的签名验证成功的情况下,该中继设备向该第一终端设备发送验证之后的认证请求消息;其中,该验证之后的认证请求消息包括以下至少之一:该第二终端设备所属用户的信息,该中继设备所属用户的信息,该第一临时公钥,该第二终端设备的签名,该中继设备的签名,该中继设备的相关信息;其中,该中继设备所属用户的信息包括该中继设备的签名证书,或者,该中继设备所属用户的信息包括该中继设备的标识和该中继设备的PVT和KPAK;该中继设备的签名的输入参数包括以下至少之一:该第二终端设备的签名和该中继设备所属用户的信息;该中继设备的相关信息包括以下之一:该中继设备的身份信息,该中继设备生成的随机数,该中继设备生成的计数器。
第四方面,提供了一种中继通信的方法,该方法包括:
第一终端设备通过中继设备向第二终端设备发送第一消息;
其中,该第一消息包括以下至少之一:该第一终端设备的安全能力信息,该第一终端设备的安全策略信息,该第一终端设备所属用户的信息,该第一终端设备生成的第一随机数,该第一终端设备生成的第二临时公钥,该第一终端设备生成的第一密钥的标识的M个比特位,该第一终端设备的签名,第一消息验证码;
其中,该第一终端设备所属用户的信息包括该第一终端设备的签名证书,或者,该第一终端设备所属用户的信息包括该第一终端设备的标识和该第一终端设备的PVT和KPAK;该第一终端设备的签名的输入参数包括以下至少之一:该第一终端设备所属用户的信息,该第二临时公钥,该第一密钥的标识的M个比特位,该第二终端设备的签名;
其中,该第一消息通过基于该第一密钥生成的该第一消息验证码进行完整性保护,且该第一消息验证码的输入参数包括以下至少之一:该第一终端设备的安全能力信息,该第一终端设备的安全策略信息,该第一终端设备所属用户的信息,该第一随机数,该第二临时公钥,该M个比特位,该第一终端设备的签名;
其中,该第二临时公钥和该中继设备的相关信息用于该第二终端设备派生该第一密钥,该第一随机数、该第一密钥和该第二终端设备生成的第二随机数用于派生第二密钥,该第二密钥用于派生完整性保护密钥和/或机密性保护密钥,该第一密钥的标识由该M个比特位与该第一密钥的标识的另外N个比特位合并得到,M和N均为正整数;该中继设备的相关信息包括以下之一:该中继设备的身份信息,该中继设备生成的随机数,该中继设备生成的计数器。
第五方面,提供了一种中继通信的方法,该方法包括:
第二终端设备接收第一终端设备通过中继设备发送的第一消息;
其中,该第一消息包括以下至少之一:该第一终端设备的安全能力信息,该第一终端设备的安全策略信息,该第一终端设备所属用户的信息,该中继设备所属用户的信息,该第一终端设备生成的第一随机数,该第一终端设备生成的第二临时公钥,该第一终端设备生成的第一密钥的标识的M个比特位,该第一终端设备的签名,该中继设备的签名,第一消息验证码;
其中,该第一终端设备所属用户的信息包括该第一终端设备的签名证书,或者,该第一终端设备所属用户的信息包括该第一终端设备的标识和该第一终端设备的公共验证令牌PVT和密钥管理服务器的公共认证密钥KPAK;该中继设备所属用户的信息包括该中继设备的签名证书,或者,该中继设备所属用户的信息包括该中继设备的标识和该中继设备的PVT和KPAK;该第一终端设备的签名的输入参数包括以下至少之一:该第一终端设备所属用户的信息,该第二临时公钥,该第一密钥的标识的M个比特位,该第二终端设备的签名;该中继设备的签名的输入参数包括以下至少之一:该中继设备所属用户的信息,该第一终端设备的签名,该第二终端设备的签名;
其中,该第一消息通过基于该第一密钥生成的该第一消息验证码进行完整性保护,且该第一消息验证码的输入参数包括以下至少之一:该第一终端设备的安全能力信息,该第一终端设备的安全策略信息,该第一终端设备所属用户的信息,该中继设备所属用户的信息,该第一随机数,该第二临时公钥,该M个比特位,该第一终端设备的签名,该中继设备的签名;
其中,该第二临时公钥和该中继设备的相关信息用于该第二终端设备派生该第一密钥,该第一随机数、该第一密钥和该第二终端设备生成的第二随机数用于派生第二密钥,该第二密钥用于派生完整性保护密钥和/或机密性保护密钥,该第一密钥的标识由该M个比特位与该第一密钥的标识的另外N个比特位合并得到,M和N均为正整数;该中继设备的相关信息包括以下之一:该中继设备的身份信息,该中继设备生成的随机数,该中继设备生成的计数器。
第六方面,提供了一种中继通信的方法,该方法包括:
中继设备接收第一终端设备发送的第一消息;其中,该第一消息包括以下至少之一:该第一终端设备的安全能力信息,该第一终端设备的安全策略信息,该第一终端设备所属用户的信息,该第一终端设备生成的第一随机数,该第一终端设备生成的第二临时公钥,该第一终端设备生成的第一密钥的标识的M个比特位,该第一终端设备的签名,第一消息验证码;其中,该第一终端设备所属用户的信息包括该第一终端设备的签名证书,或者,该第一终端设备所属用户的信息包括该第一终端设备的标识和该第一终端设备的PVT和KPAK;该第一终端设备的签名的输入参数包括以下至少之一:该第一终端设备所属用户的信息,该第二临时公钥,该第一密钥的标识的M个比特位,该第二终端设备的签名;其中,该第一消息通过基于该第一密钥生成的该第一消息验证码进行完整性保护,且该第一消息验证码的输入参数包括以下至少之一:该第一终端设备的安全能力信息,该第一终端设备的安全策略信息,该第一终端设备所属用户的信息,该第一随机数,该第二临时公钥,该M个比特位,该第一终端设备的签名;
在该第一终端设备的签名证书有效,且基于该第一终端设备的签名证书对该第一终端设备的签名 验证成功的情况下,或者,在该第一终端设备的KPAK有效,且基于该第一终端设备的标识和该第一终端设备的PVT对该第一终端设备的签名验证成功的情况下,该通信单元还用于向该第二终端设备发送验证之后的第一消息;其中,该验证之后的第一消息包括以下至少之一:该第一终端设备的安全能力信息,该第一终端设备的安全策略信息,该第一终端设备所属用户的信息,该中继设备所属用户的信息,该第一终端设备生成的第一随机数,该第一终端设备生成的与该第二临时私钥配对的第二临时公钥,该第一终端设备生成的该第一密钥的标识的M个比特位,该第一终端设备的签名,该中继设备的签名,该中继设备的相关信息,第一消息验证码;其中,该中继设备所属用户的信息包括该中继设备的签名证书,或者,该中继设备所属用户的信息包括该中继设备的标识和该中继设备的PVT和KPAK;该中继设备的签名的输入参数包括以下至少之一:该中继设备所属用户的信息,该第一终端设备的签名,该第二终端设备的签名,该验证之后的第一消息;
其中,该第二临时公钥和该中继设备的相关信息用于该第二终端设备派生该第一密钥,该第一随机数、该第一密钥和该第二终端设备生成的第二随机数用于派生第二密钥,该第二密钥用于派生完整性保护密钥和/或机密性保护密钥,该第一密钥的标识由该M个比特位与该第一密钥的标识的另外N个比特位合并得到,M和N均为正整数;该中继设备的相关信息包括以下之一:该中继设备的身份信息,该中继设备生成的随机数,该中继设备生成的计数器。
第七方面,提供了一种终端设备,用于执行上述第一方面中的方法。
具体地,该终端设备包括用于执行上述第一方面中的方法的功能模块。
第八方面,提供了一种终端设备,用于执行上述第二方面中的方法。
具体地,该终端设备包括用于执行上述第二方面中的方法的功能模块。
第九方面,提供了一种中继设备,用于执行上述第三方面中的方法。
具体地,该中继设备包括用于执行上述第三方面中的方法的功能模块。
第十方面,提供了一种终端设备,用于执行上述第四方面中的方法。
具体地,该终端设备包括用于执行上述第四方面中的方法的功能模块。
第十一方面,提供了一种终端设备,用于执行上述第五方面中的方法。
具体地,该终端设备包括用于执行上述第五方面中的方法的功能模块。
第十二方面,提供了一种中继设备,用于执行上述第六方面中的方法。
具体地,该中继设备包括用于执行上述第六方面中的方法的功能模块。
第十三方面,提供了一种终端设备,包括处理器和存储器;该存储器用于存储计算机程序,该处理器用于调用并运行该存储器中存储的计算机程序,使得该终端设备执行上述第一方面或第二方面中的方法,或者,使得该终端设备执行上述第四方面或第五方面中的方法。
第十四方面,提供了一种中继设备,包括处理器和存储器;该存储器用于存储计算机程序,该处理器用于调用并运行该存储器中存储的计算机程序,使得该中继设备执行上述第三方面中的方法,或者,使得该中继设备执行上述第六方面中的方法。
第十五方面,提供了一种装置,用于实现上述第一方面至第六方面中的任一方面中的方法。
具体地,该装置包括:处理器,用于从存储器中调用并运行计算机程序,使得安装有该装置的设备执行如上述第一方面至第六方面中的任一方面中的方法。
第十六方面,提供了一种计算机可读存储介质,用于存储计算机程序,该计算机程序使得计算机执行上述第一方面至第六方面中的任一方面中的方法。
第十七方面,提供了一种计算机程序产品,包括计算机程序指令,所述计算机程序指令使得计算机执行上述第一方面至第六方面中的任一方面中的方法。
第十八方面,提供了一种计算机程序,当其在计算机上运行时,使得计算机执行上述第一方面至第六方面中的任一方面中的方法。
通过上述第一方面至第三方面的技术方案,第一终端设备可以基于第二终端设备通过中继设备发送的认证请求消息生成第一密钥,且该认证请求消息通过签名验证的方式进行保护。以及第一终端设备生成的第一随机数、第一密钥和第二终端设备生成的第二随机数用于派生第二密钥,第二密钥用于派生完整性保护密钥和/或机密性保护密钥,能够保证第一终端设备和第二终端设备的身份安全与通信数据的机密性与完整性,从而确保双方传输数据的机密性和完整性,防止其他设备甚至中继设备的窃听。
通过上述第四方面至第六方面的技术方案,第一终端设备生成的第一随机数、第一密钥和第二终端设备生成的第二随机数用于派生第二密钥,第二密钥用于派生完整性保护密钥和/或机密性保护密钥,能够保证第一终端设备和第二终端设备的身份安全与通信数据的机密性与完整性,从而确保双方传输数据的机密性和完整性,防止其他设备甚至中继设备的窃听。
图1是本申请实施例应用的一种通信系统架构的示意性图。
图2至图4分别是本申请提供的UE-to-UE中继场景中的建立安全通信的示意性流程图。
图5是本申请提供的一种L3中继通信的示意性流程图。
图6是根据本申请实施例提供的一种中继通信的方法的示意性流程图。
图7是本申请实施例所涉及的密钥分层结构的示意性图。
图8是根据本申请实施例提供的另一种中继通信的方法的示意性流程图。
图9是根据本申请实施例提供的再一种中继通信的方法的示意性流程图。
图10是根据本申请实施例提供的再一种中继通信的方法的示意性流程图。
图11是根据本申请实施例提供的再一种中继通信的方法的示意性流程图。
图12是根据本申请实施例提供的再一种中继通信的方法的示意性流程图。
图13至图15分别是本申请实施例提供的UE-to-UE中继场景中的建立安全通信的示意性流程图。
图16是根据本申请实施例提供的一种终端设备的示意性框图。
图17是根据本申请实施例提供的另一种终端设备的示意性框图。
图18是根据本申请实施例提供的一种中继设备的示意性框图。
图19是根据本申请实施例提供的再一种终端设备的示意性框图。
图20是根据本申请实施例提供的再一种终端设备的示意性框图。
图21是根据本申请实施例提供的另一种中继设备的示意性框图。
图22是根据本申请实施例提供的一种通信设备的示意性框图。
图23是根据本申请实施例提供的一种装置的示意性框图。
图24是根据本申请实施例提供的一种通信系统的示意性框图。
下面将结合本申请实施例中的附图,对本申请实施例中的技术方案进行描述,显然,所描述的实施例是本申请一部分实施例,而不是全部的实施例。针对本申请中的实施例,本领域普通技术人员在没有做出创造性劳动前提下所获得的所有其他实施例,都属于本申请保护的范围。
本申请实施例的技术方案可以应用于各种通信系统,例如:全球移动通讯(Global System of Mobile communication,GSM)系统、码分多址(Code Division Multiple Access,CDMA)系统、宽带码分多址(Wideband Code Division Multiple Access,WCDMA)系统、通用分组无线业务(General Packet Radio Service,GPRS)、长期演进(Long Term Evolution,LTE)系统、先进的长期演进(Advanced long term evolution,LTE-A)系统、新无线(New Radio,NR)系统、NR系统的演进系统、非授权频谱上的LTE(LTE-based access to unlicensed spectrum,LTE-U)系统、非授权频谱上的NR(NR-based access to unlicensed spectrum,NR-U)系统、非地面通信网络(Non-Terrestrial Networks,NTN)系统、通用移动通信系统(Universal Mobile Telecommunication System,UMTS)、无线局域网(Wireless Local Area Networks,WLAN)、物联网(internet of things,IoT)、无线保真(Wireless Fidelity,WiFi)、第五代通信(5th-Generation,5G)系统或其他通信系统等。
通常来说,传统的通信系统支持的连接数有限,也易于实现,然而,随着通信技术的发展,移动通信系统将不仅支持传统的通信,还将支持例如,设备到设备(Device to Device,D2D)通信,机器到机器(Machine to Machine,M2M)通信,机器类型通信(Machine Type Communication,MTC),车辆间(Vehicle to Vehicle,V2V)通信,或车联网(Vehicle to everything,V2X)通信等,本申请实施例也可以应用于这些通信系统。
在一些实施例中,本申请实施例中的通信系统可以应用于载波聚合(Carrier Aggregation,CA)场景,也可以应用于双连接(Dual Connectivity,DC)场景,还可以应用于独立(Standalone,SA)布网场景,或者应用于非独立(Non-Standalone,NSA)布网场景。
在一些实施例中,本申请实施例中的通信系统可以应用于非授权频谱,其中,非授权频谱也可以认为是共享频谱;或者,本申请实施例中的通信系统也可以应用于授权频谱,其中,授权频谱也可以认为是非共享频谱。
在一些实施例中,本申请实施例中的通信系统可以应用于FR1频段(对应频段范围410MHz到7.125GHz),也可以应用于FR2频段(对应频段范围24.25GHz到52.6GHz),还可以应用于新的频段例如对应52.6GHz到71GHz频段范围或对应71GHz到114.25GHz频段范围的高频频段。
本申请实施例结合网络设备和终端设备描述了各个实施例,其中,终端设备也可以称为用户设备(User Equipment,UE)、接入终端、用户单元、用户站、移动站、移动台、远方站、远程终端、移动设备、用户终端、终端、无线通信设备、用户代理或用户装置等。
终端设备可以是WLAN中的站点(STATION,ST),可以是蜂窝电话、无绳电话、会话启动协议(Session Initiation Protocol,SIP)电话、无线本地环路(Wireless Local Loop,WLL)站、个人数字助理(Personal Digital Assistant,PDA)设备、具有无线通信功能的手持设备、计算设备或连接到无线调制解调器的其它处理设备、车载设备、可穿戴设备、下一代通信系统例如NR网络中的终端设备,或者未来演进的公共陆地移动网络(Public Land Mobile Network,PLMN)网络中的终端设备等。
在本申请实施例中,终端设备可以部署在陆地上,包括室内或室外、手持、穿戴或车载;也可以部署在水面上(如轮船等);还可以部署在空中(例如飞机、气球和卫星上等)。
在本申请实施例中,终端设备可以是手机(Mobile Phone)、平板电脑(Pad)、带无线收发功能的电脑、虚拟现实(Virtual Reality,VR)终端设备、增强现实(Augmented Reality,AR)终端设备、工业控制(industrial control)中的无线终端设备、无人驾驶(self driving)中的无线终端设备、远程医疗(remote medical)中的无线终端设备、智能电网(smart grid)中的无线终端设备、运输安全(transportation safety)中的无线终端设备、智慧城市(smart city)中的无线终端设备或智慧家庭(smart home)中的无线终端设备、车载通信设备、无线通信芯片/专用集成电路(application specific integrated circuit,ASIC)/系统级芯片(System on Chip,SoC)等。
作为示例而非限定,在本申请实施例中,该终端设备还可以是可穿戴设备。可穿戴设备也可以称为穿戴式智能设备,是应用穿戴式技术对日常穿戴进行智能化设计、开发出可以穿戴的设备的总称,如眼镜、手套、手表、服饰及鞋等。可穿戴设备即直接穿在身上,或是整合到用户的衣服或配件的一种便携式设备。可穿戴设备不仅仅是一种硬件设备,更是通过软件支持以及数据交互、云端交互来实现强大的功能。广义穿戴式智能设备包括功能全、尺寸大、可不依赖智能手机实现完整或者部分的功能,例如:智能手表或智能眼镜等,以及只专注于某一类应用功能,需要和其它设备如智能手机配合使用,如各类进行体征监测的智能手环、智能首饰等。
图1示例性地示出了本申请应用的通信系统100,在该通信系统100中,第一终端设备110与第二终端设备120通过中继设备130进行通信。该通信系统100还可以包括其他设备,本申请实施例对此不做限定。
应理解,本申请实施例中系统中具有通信功能的设备可称为通信设备。以图1示出的通信系统100为例,通信设备可包括具有通信功能的第一终端设备110、第二终端设备120和中继设备130,第一终端设备110和第二终端设备120可以为上文所述的具体设备,此处不再赘述。
本申请实施例中的中继设备130可以是终端设备,也可以是网络设备。其中,网络设备可以是用于与移动设备通信的设备,网络设备可以是WLAN中的接入点(Access Point,AP),GSM或CDMA中的基站(Base Transceiver Station,BTS),也可以是WCDMA中的基站(NodeB,NB),还可以是LTE中的演进型基站(Evolutional Node B,eNB或eNodeB),或者中继站或接入点,或者车载设备、可穿戴设备以及NR网络中的网络设备或者基站(gNB)或者未来演进的PLMN网络中的网络设备或者NTN网络中的网络设备等。
在本申请实施例中,中继设备130可以是网络设备,网络设备可以具有移动特性,例如网络设备可以为移动的设备。在一些实施例中,网络设备可以为卫星、气球站。例如,卫星可以为低地球轨道(low earth orbit,LEO)卫星、中地球轨道(medium earth orbit,MEO)卫星、地球同步轨道(geostationary earth orbit,GEO)卫星、高椭圆轨道(High Elliptical Orbit,HEO)卫星等。在一些实施例中,网络设备还可以为设置在陆地、水域等位置的基站。
在本申请实施例中,中继设备130可以是网络设备,网络设备可以为小区提供服务,终端设备通过该小区使用的传输资源(例如,频域资源,或者说,频谱资源)与网络设备进行通信,该小区可以是网络设备(例如基站)对应的小区,小区可以属于宏基站,也可以属于小小区(Small cell)对应的基站,这里的小小区可以包括:城市小区(Metro cell)、微小区(Micro cell)、微微小区(Pico cell)、毫微微小区(Femto cell)等,这些小小区具有覆盖范围小、发射功率低的特点,适用于提供高速率的数据传输服务。
应理解,本文中术语“系统”和“网络”在本文中常被可互换使用。本文中术语“和/或”,仅仅是一种描述关联对象的关联关系,表示可以存在三种关系,例如,A和/或B,可以表示:单独存在A,同时存在A和B,单独存在B这三种情况。另外,本文中字符“/”,一般表示前后关联对象是一种“或”的关系。
应理解,本文涉及第一终端设备和第二终端设备,第一终端设备例如手机,机器设施,用户前端设备(Customer Premise Equipment,CPE),工业设备,车辆等;第二终端设备可以是第一终端设备的对端通信设备,例如手机,工业设备,车辆等。
本申请的实施方式部分使用的术语仅用于对本申请的具体实施例进行解释,而非旨在限定本申 请。本申请的说明书和权利要求书及所述附图中的术语“第一”、“第二”、“第三”和“第四”等是用于区别不同对象,而不是用于描述特定顺序。此外,术语“包括”和“具有”以及它们任何变形,意图在于覆盖不排他的包含。
应理解,在本申请的实施例中提到的“指示”可以是直接指示,也可以是间接指示,还可以是表示具有关联关系。举例说明,A指示B,可以表示A直接指示B,例如B可以通过A获取;也可以表示A间接指示B,例如A指示C,B可以通过C获取;还可以表示A和B之间具有关联关系。
在本申请实施例的描述中,术语“对应”可表示两者之间具有直接对应或间接对应的关系,也可以表示两者之间具有关联关系,也可以是指示与被指示、配置与被配置等关系。
本申请实施例中,“预定义”或“预配置”可以通过在设备(例如,包括终端设备和网络设备)中预先保存相应的代码、表格或其他可用于指示相关信息的方式来实现,本申请对于其具体的实现方式不做限定。比如预定义可以是指协议中定义的。
本申请实施例中,所述“协议”可以指通信领域的标准协议,例如可以包括LTE协议、NR协议以及应用于未来的通信系统中的相关协议,本申请对此不做限定。
为便于理解本申请实施例的技术方案,以下通过具体实施例详述本申请的技术方案。以下相关技术作为可选方案与本申请实施例的技术方案可以进行任意结合,其均属于本申请实施例的保护范围。本申请实施例包括以下内容中的至少部分内容。
为实现UE-to-UE中继场景中的安全通信,现阶段主要包含如下三种方案。
方案一,如图2所示,使用非对称加密技术来保护源UE和目标UE之间的通信的方法。在源UE和目标UE互相认证的基础上,并假设中继是可信的,在源UE和目标UE之间建立连接,利用双方公钥来保护端到端安全。
方案二,如图3所示,UE-to-UE中继场景中UE1和UE2之间的安全建立过程,UE1和UE2分别与中继设备1(relay 1)建立PC5连接,然后假定UE1和UE2之间与配置了共享密钥和密钥ID,最后UE1通过中继设备1给UE2发送消息验证码(Message Authentication Code,MAC),UE2验证消息MAC后再回复消息给UE1。
方案三,如图4所示,远端UE1和远端UE2与中继设备建立安全PC5链路,远端UE1、中继设备、远端UE2被5G直接发现名称管理网元(Direct Discovering Name Management Function,DDNMF)和邻近通信服务的密钥管理网元(Prose Key Management Function,PKMF)提供发现和中继安全秘密材料。远端UE1和远端UE2预先从PKMF获得共享密钥(key)标识(Identity,ID)以及key。然后,UE(远端UE1和远端UE2)和中继设备也会从PKMF获得相应密钥,分别建立PC5安全连接,最后远端UE1和远端UE2之间利用共享密钥建立安全通道。
为便于更好的理解本申请实施例,对本申请所涉及的基于互联网协议(Internet Protocol,IP)路由的5G层3(Layer-3,L3)终端与终端中继(UE-to-UE Relay)的临近业务(Proximity-based Services,ProSe)进行说明。具体的,基于L3建立UE-to-UE relay连接的流程如图5所示。UE-1和UE-2都可使用UE-to-UE relay服务。Prose 5G UE-to-UE Relay定期发送“中继发现(Relay discovery)”消息,宣布其可用于该区域内的其他终端。ProSe 5G UE-to-UE Relay也支持发现的查询和响应方式。ProSe5G UE-to-UE Relay监听已配置的L2ID,并将其地址和相应信息作为响应,使其他UE能够与中继建立单播连接。任何想要使用ProSe 5G UE-to-UE Relay的终端都需要与UE-to-UE Relay建立单播L2链路,并配置IP。ProSe 5G UE-to-UE Relay为其他终端分配IP地址/前缀。作为单播L2链路建立过程的一部分,ProSe 5G UE-to-UE Relay将单播链路的对端终端用户信息(或对端终端提供的散文服务)和分配给终端的IP地址/前缀的关联存储到其域名系统(Domain Name System,DNS)条目中。ProSe 5G UE-to-UE Relay为其他终端提供DNS服务器。当(源)UE需要沟通与另一个(目标)UE或需要通过prose 5g UE-to-UE relay发现一个prose服务,它通过单播链接给中继发送一个DNS查询目标UE(基于目标用户信息),中继将返回目标终端的IP地址/前缀。源UE将IP数据或非IP数据封装在IP数据包中,通过单播L2连接发送到中继,中继将作为IP的路由,将IP数据包发送到相应的单播L2连接上,发送给目标UE。每个单播L2连接作为IP的接口。
为便于更好的理解本申请实施例,对本申请所解决的问题进行说明。
UE-to-UE中继场景安全通信方案均存在部分缺陷,比如上述方案一中默认relay是可信的,因此存在强假设条件的限制,并且在UE协商安全能力时均为明文消息,可能遭受篡改,另外方案一中公钥的来源和真实性、以及通信密钥来源不明确,(比如没有确定通过协商方式还是单向加密来确定通信密钥来源),同时未涉及采用公钥技术下的密钥管理方案。方案二未提及预配置共享密钥的过程,同时方案流程存在争议。方案三的流程较为复杂,交互次数过多,不够轻便。因此需探究更为简便且不失安全性的安全连接建立方式,并探究更为高效的密钥管理结构,从而保证UE身份安全与通信数 据的机密性与完整性。
基于上述问题,本申请提出了一种中继通信的方案,能够保证终端身份安全与通信数据的机密性与完整性,从而确保双方传输数据的机密性和完整性,防止其他设备甚至中继设备的窃听。
以下通过具体实施例详述本申请的技术方案。
图6是根据本申请实施例的中继通信的方法200的示意性流程图,如图6所示,该中继通信的方法200可以包括如下内容中的至少部分内容:
S210,第一终端设备接收第二终端设备通过中继设备发送的认证请求消息;其中,该认证请求消息包括以下至少之一:该第二终端设备所属用户的信息,该中继设备所属用户的信息,该第二终端设备生成的第一临时公钥,该第二终端设备的签名,该中继设备的签名,该中继设备的相关信息;其中,该第二终端设备所属用户的信息包括该第二终端设备的签名证书,或者,该第二终端设备所属用户的信息包括该第二终端设备的标识和该第二终端设备的PVT和KPAK;该中继设备所属用户的信息包括该中继设备的签名证书,或者,该中继设备所属用户的信息包括该中继设备的标识和该中继设备的PVT和KPAK;该第二终端设备的签名的输入参数包括以下至少之一:该第二终端设备所属用户的信息和该第一临时公钥;该中继设备的签名的输入参数包括以下至少之一:该第二终端设备的签名和该中继设备所属用户的信息;该第一临时公钥和该中继设备的相关信息用于该第一终端设备派生第一密钥;该中继设备的相关信息包括以下之一:该中继设备的身份信息,该中继设备生成的随机数,该中继设备生成的计数器。
本实施例基于ECCSI签名方案,建立层3(layer3,L3)架构下的UE-to-UE中继场景下的安全连接。具体的,本申请实施例应用于L3架构下的UE-to-UE中继场景,也即,第一终端设备与第二终端设备之间通过中继设备进行通信。例如,第一终端设备与第二终端设备之间的中继连接可以是PC5链路。
在本申请实施例中,该第一终端设备可以是源设备或源终端,该第二终端设备可以是目标设备或目标终端。该中继设备可以是中继终端。
在本申请实施例中,该第二终端设备的签名的输入参数包括以下至少之一:该第二终端设备所属用户的信息和该第一临时公钥。也即,该第二终端设备可以基于该第二终端设备所属用户的信息和该第一临时公钥中的至少之一,生成该第二终端设备的签名。
在本申请实施例中,该中继设备的签名的输入参数包括以下至少之一:该第二终端设备的签名和该中继设备所属用户的信息。也即,该中继设备可以基于该第二终端设备的签名和该中继设备所属用户的信息中的至少之一,生成该中继设备的签名。
在一些实施例中,在该第二终端设备所属用户的信息包括该第二终端设备的签名证书的情况下,该第二终端设备的签名由该第二终端设备的签名私钥生成。可选地,该第二终端设备的签名证书和签名私钥可以是可信中心密钥管理服务器(Key Management Service,KMS)通过安全通道为该第二终端设备预先配置的。该安全通道可以基于应用程序的身份验证和密钥管理(Authentication and Key Management for Applications,AKMA)机制或者通用引导架构(Generic Bootstrapping Architecture,GBA)机制来建立该第二终端设备与KMS的安全连接,该KMS可以直接由运营商来负责管理或者是与运营商有商业关系的第三方服务提供商。
在一些实施例中,在该第二终端设备所属用户的信息包括该第二终端设备的标识和该第二终端设备的公共验证令牌(Public Validation Token,PVT)和密钥管理服务器的公共认证密钥(Key Management Service Public Authentication Key,KPAK)的情况下,该第二终端设备的签名由该第二终端设备的秘密签名密钥(Secret Signing Key,SSK)生成。可选地,该第二终端设备的PVT和KPAK、以及秘密签名密钥(SSK)可以是可信中心KMS通过安全通道为该第二终端设备预先配置的。该安全通道可以基于AKMA机制或者GBA机制来建立该第二终端设备与KMS的安全连接,该KMS可以直接由运营商来负责管理或者是与运营商有商业关系的第三方服务提供商。
在一些实施例中,在该中继设备所属用户的信息包括该中继设备的签名证书的情况下,该中继设备的签名由该中继设备的签名私钥生成。可选地,该中继设备的签名证书和签名私钥可以是可信中心KMS通过安全通道为该中继设备预先配置的。该安全通道可以基于AKMA机制或者GBA机制来建立该中继设备与KMS的安全连接,该KMS可以直接由运营商来负责管理或者是与运营商有商业关系的第三方服务提供商。
在一些实施例中,在该中继设备所属用户的信息包括该中继设备的标识、该中继设备的PVT和KPAK的情况下,该中继设备的签名由该中继设备的秘密签名密钥(SSK)生成。可选地,该中继设备的PVT和KPAK、以及秘密签名密钥(SSK)可以是可信中心KMS通过安全通道为该中继设备预先配置的。该安全通道可以基于AKMA机制或者GBA机制来建立该中继设备与KMS的安全连接, 该KMS可以直接由运营商来负责管理或者是与运营商有商业关系的第三方服务提供商。
在一些实施例中,在该第二终端设备的签名证书和该中继设备的签名证书有效,且基于该第二终端设备的签名证书对该第二终端设备的签名验证成功,以及基于该中继设备的签名证书对该中继设备的签名验证成功的情况下,该第一终端设备生成第二临时私钥,以及该第一终端设备根据该第一临时公钥、该中继设备的相关信息和该第二临时私钥派生该第一密钥。
具体的,该第一终端设备可以基于其本地存储的一个或多个签名证书,验证该第二终端设备的签名证书和该中继设备的签名证书的有效性。例如,在第一终端设备本地存储的签名证书中存在与第二终端设备的签名证书一致的签名证书的情况下,该第二终端设备的签名证书有效;以及在第一终端设备本地存储的签名证书中存在与中继设备的签名证书一致的签名证书的情况下,该中继设备的签名证书有效。可选地,该第一终端设备本地存储的一个或多个签名证书可以由KMS预配置。
在一些实施例中,在该第二终端设备的KPAK和该中继设备的KPAK有效,且基于该第二终端设备的标识和该第二终端设备的PVT对该第二终端设备的签名验证成功,以及基于该中继设备的标识和该中继设备的PVT对该中继设备的签名验证成功的情况下,该第一终端设备生成第二临时私钥,以及该第一终端设备根据该第一临时公钥、该中继设备的相关信息和该第二临时私钥派生该第一密钥。
具体的,该第一终端设备可以基于其本地存储的一个或多个KPAK,验证该第二终端设备的KPAK和该中继设备的KPAK的有效性。例如,在第一终端设备本地存储的KPAK中存在与第二终端设备的KPAK一致的KPAK的情况下,该第二终端设备的KPAK有效;以及在第一终端设备本地存储的KPAK中存在与中继设备的KPAK一致的KPAK的情况下,该中继设备的KPAK有效。可选地,该第一终端设备本地存储的一个或多个KPAK可以由KMS预配置。
具体的,在本申请实施例中,第一终端设备可以根据第二终端设备生成的第一临时公钥、中继设备的相关信息和第一终端设备生成的第二临时私钥派生第一密钥。其中,该中继设备的相关信息包括以下之一:该中继设备的身份信息,该中继设备生成的随机数,该中继设备生成的计数器。
相应的,第二终端设备可以根据第一终端设备生成的第二临时公钥、中继设备的相关信息和第二终端设备生成的第一临时私钥派生第一密钥。其中,该中继设备的相关信息包括以下之一:该中继设备的身份信息,该中继设备生成的随机数,该中继设备生成的计数器。
其中,第二终端设备生成的第一临时公钥与第二终端设备生成的第一临时私钥配对,第一终端设备生成的第二临时公钥与第一终端设备生成的第二临时私钥配对。
具体例如,第一终端设备可以根据第一临时公钥、中继设备的相关信息和第二临时私钥,并使用ECIES算法计算出第一密钥;第二终端设备可以根据第二临时公钥、中继设备的相关信息和第一临时私钥,并使用ECIES算法计算出第一密钥。
在一些实施例中,该第一终端设备通过该中继设备向该第二终端设备发送第一消息;
其中,该第一消息包括以下至少之一:该第一终端设备的安全能力信息,该第一终端设备的安全策略信息,该第一终端设备所属用户的信息,该第一终端设备生成的第一随机数,该第一终端设备生成的与该第二临时私钥配对的第二临时公钥,该第一终端设备生成的该第一密钥的标识的M个比特位,该第一终端设备的签名,第一消息验证码;
其中,该第一终端设备所属用户的信息包括该第一终端设备的签名证书,或者,该第一终端设备所属用户的信息包括该第一终端设备的标识和该第一终端设备的PVT和KPAK;该第一终端设备的签名的输入参数包括以下至少之一:该第一终端设备所属用户的信息,该第二临时公钥,该第一密钥的标识的M个比特位,该第二终端设备的签名;
其中,该第一消息通过基于该第一密钥生成的该第一消息验证码进行完整性保护,且该第一消息验证码的输入参数包括以下至少之一:该第一终端设备的安全能力信息,该第一终端设备的安全策略信息,该第一终端设备所属用户的信息,该第一随机数,该第二临时公钥,该M个比特位,该第一终端设备的签名;
其中,该第二临时公钥和该中继设备的相关信息用于该第二终端设备派生该第一密钥,该第一随机数、该第一密钥和该第二终端设备生成的第二随机数用于派生第二密钥,该第二密钥用于派生完整性保护密钥和/或机密性保护密钥,该第一密钥的标识由该M个比特位与该第一密钥的标识的另外N个比特位合并得到,M和N均为正整数。
在本申请实施例中,第一终端设备生成的第一随机数、第一密钥和第二终端设备生成的第二随机数用于派生第二密钥。也即,第一终端设备至少根据第一随机数、第一密钥和第二随机数派生第二密钥,以及第一终端设备可以基于第二密钥派生完整性保护密钥和/或机密性保护密钥,从而第一终端设备可以基于完整性保护密钥和/或机密性保护密钥对发送的消息进行安全保护。同理,第二终端设 备至少根据第一随机数、第一密钥和第二随机数派生第二密钥,以及第二终端设备可以基于第二密钥派生完整性保护密钥和/或机密性保护密钥,从而第二终端设备可以基于完整性保护密钥和/或机密性保护密钥对发送的消息进行安全保护。
在本申请实施例中,该第一消息验证码的输入参数包括以下至少之一:该第一终端设备的安全能力信息,该第一终端设备的安全策略信息,该第一随机数,该第二临时公钥,该M个比特位。也即,该第一终端设备可以基于该第一终端设备的安全能力信息、该第一终端设备的安全策略信息、该第一随机数、该第一终端设备所属用户的信息、该第二临时公钥、该M个比特位、该第一终端设备的签名中的至少之一,生成该第一消息验证码。
具体例如,假设该第一消息验证码的输入参数包括:该第一终端设备的安全能力信息、该第一终端设备的安全策略信息、该第一随机数、该第一终端设备所属用户的信息、该第二临时公钥、该M个比特位、该第一终端设备的签名。该第二终端设备可以基于该第一终端设备的安全能力信息、该第一终端设备的安全策略信息、该第一随机数、该第二临时公钥、该M个比特位生成第一消息验证码,并与该第一消息中包含的该第一消息验证码进行比较,若比较一致的情况下,该第一消息验证码有效。
在一些实施例中,该第一消息为认证响应消息,或者,该第一消息为安全模式命令消息。
在一些实施例中,该第一终端设备的安全能力信息可以是该第一终端设备支持的密码算法列表。
在一些实施例中,该第一终端设备的安全策略信息可以是该第一终端设备是否支持机密性保护或完整性保护。其中,该第一终端设备的安全策略信息包括:该第一终端设备在控制面的安全策略信息,和/或,该第一终端设备在用户面的安全策略信息。
在一些实施例中,该M个比特位可以是该第一密钥的标识的最高M个比特位,该N个比特位可以是该第一密钥的标识的最低N个比特位;或者,该M个比特位可以是该第一密钥的标识的前M个比特位,该N个比特位可以是该第一密钥的标识的后N个比特位;或者,该M个比特位可以是该第一密钥的标识的偶数位的比特位,该N个比特位可以是该第一密钥的标识的奇数位的比特位。
在一些实施例中,M与N的取值可以相同,也可以不同,本申请对此并不限定。
在一些实施例中,该第一终端设备接收该第二终端设备通过该中继设备发送的第二消息;
其中,该第二消息包括以下至少之一:该第二终端设备生成的该第二随机数,该第二终端设备生成的该第一密钥的标识的N个比特位,该第二终端设备生成的该第二密钥的标识的x个比特位,该第二终端设备选取的安全算法,该第二终端设备选取的安全策略,第二消息验证码;
其中,该第二消息通过基于该第二密钥生成的该第二消息验证码进行完整性保护,或者,该第二消息通过基于该第二密钥派生的完整性保护密钥生成的该第二消息验证码进行完整性保护,且该第二消息验证码的输入参数包括以下至少之一:该第二随机数,该N个比特位,该x个比特位,该第二终端设备选取的安全算法,该第二终端设备选取的安全策略;
其中,该第二密钥的标识由该x个比特位与该第二密钥的标识的另外y个比特位合并得到,x和y均为正整数。
在一些实施例中,该x个比特位可以是该第二密钥的标识的最高x个比特位,该y个比特位可以是该第二密钥的标识的最低y个比特位;或者,该x个比特位可以是该第二密钥的标识的前x个比特位,该y个比特位可以是该第二密钥的标识的后y个比特位;或者,该x个比特位可以是该第二密钥的标识的偶数位的比特位,该y个比特位可以是该第二密钥的标识的奇数位的比特位。
在一些实施例中,x与y的取值可以相同,也可以不同,本申请对此并不限定。
在一些实施例中,在该第二消息中携带的信息未遭受篡改的情况下,该第一终端设备至少根据该第一随机数、该第一密钥和该第二随机数生成该第二密钥,该第一终端设备根据该第二密钥生成完整性保护密钥和/或机密性保护密钥,以及该第一终端设备将该M个比特位和该N个比特位合并得到该第一密钥的标识,该第一终端设备生成该第二密钥的标识的y个比特位,并将该x个比特位和该y个比特位合并得到该第二密钥的标识;
在该第二消息验证码有效的情况下,该第一终端设备根据该第二终端设备选取的安全算法、该第二密钥、基于该第二密钥生成完整性保护密钥和/或机密性保护密钥、该第二终端设备选取的安全策略,与该第二终端设备进行通信。
具体例如,假设该第二消息验证码的输入参数包括:该第二随机数、该N个比特位、该x个比特位、该第二终端设备选取的安全算法、该第二终端设备选取的安全策略。该第一终端设备可以基于该第二随机数、该N个比特位、该x个比特位、该第二终端设备选取的安全算法、该第二终端设备选取的安全策略生成第二消息验证码,并与该第二消息中包含的该第二消息验证码进行比较,若比较一致的情况下,该第二消息验证码有效。
在一些实施例中,该第二消息通过该第一密钥进行加密,且该第二消息还包括第三消息验证码;
其中,该第二消息通过基于该第一密钥生成的该第三消息验证码进行完整性保护,且该第三消息验证码的输入参数包括以下至少之一:该第二随机数,该N个比特位,该x个比特位,该第二终端设备选取的安全算法,该第二终端设备选取的安全策略。
在一些实施例中,该第二消息也可以不通过该第一密钥进行加密,或者,该第二消息可以不加密。
在一些实施例中,该第一终端设备根据该第一密钥解密该第二消息;在该第二消息中携带的信息未遭受篡改的情况下,该第一终端设备至少根据该第一随机数、该第一密钥和该第二随机数生成该第二密钥,该第一终端设备根据该第二密钥生成完整性保护密钥和/或机密性保护密钥,以及该第一终端设备将该M个比特位和该N个比特位合并得到该第一密钥的标识,该第一终端设备生成该第二密钥的标识的y个比特位,并将该x个比特位和该y个比特位合并得到该第二密钥的标识;
在该第二消息验证码和该第三消息验证码有效的情况下,该第一终端设备根据该第二终端设备选取的安全算法、该第二密钥、基于该第二密钥生成完整性保护密钥和/或机密性保护密钥、该第二终端设备选取的安全策略,与该第二终端设备进行通信。
具体例如,假设该第三消息验证码的输入参数包括:该第二随机数、该N个比特位、该x个比特位、该第二终端设备选取的安全算法、该第二终端设备选取的安全策略。该第一终端设备可以基于该第二随机数、该N个比特位、该x个比特位、该第二终端设备选取的安全算法、该第二终端设备选取的安全策略生成第三消息验证码,并与该第二消息中包含的该第三消息验证码进行比较,若比较一致的情况下,该第三消息验证码有效。
具体的,该第二终端设备可以基于该第一终端设备的安全能力信息选取安全算法,和/或,该第二终端设备可以基于该第一终端设备的安全策略信息选取安全策略。
在一些实施例中,该第一终端设备可以根据该第一随机数、该第一密钥、该第二随机数,以及源标识、目标标识、该第一随机数的长度、该第二随机数的长度、该源标识的长度、该目标标识的长度中的至少之一,生成该第二密钥。其中,该源标识用于标识该第一终端设备与该第二终端设备之间的中继连接的源端,该目标标识用于标识该第一终端设备与该第二终端设备之间的中继连接的目标端。另外,该第二密钥的输入参数还可以包括其他系统设定参数,如3GPP指定的一个或多个固定参数。
在一些实施例中,该第一消息为认证响应消息,该第二消息为安全模式命令(Secure Mode Command,SMC)消息。
在一些实施例中,该第一消息为安全模式命令(Secure Mode Command,SMC)消息,该第二消息为安全模式响应消息。
在一些实施例中,该第一终端设备通过该中继设备向该第二终端设备发送第三消息;
其中,该第三消息用于指示安全模式建立完成,该第三消息通过目标密钥进行加密,且该第三消息包括以下至少之一:该第二密钥的标识的该y个比特位,第四消息验证码;
其中,该目标密钥包括以下之一:该第一密钥,该第二密钥,该第二密钥派生的机密性保护密钥;
其中,该第三消息通过基于该第二密钥生成的该第四消息验证码进行完整性保护,或者,该第三消息通过基于该第二密钥派生的完整性保护密钥生成的该第四消息验证码进行完整性保护,该第四消息验证码的输入参数包括该y个比特位。
在一些实施例中,对于该第二终端设备,该第二终端设备通过该目标密钥对该第三消息进行解密;在该第三消息中携带的信息未遭受篡改的情况下,且该第四消息验证码有效的情况下,该第二终端设备将该x个比特位与该y个比特位合并得到该第二密钥的标识。具体的,该第二终端设备可以基于该y个比特位生成第四消息验证码,并与该第三消息中包含的该第四消息验证码进行比较,若比较一致的情况下,该第四消息验证码有效。
具体例如,该第三消息为安全模式结束消息(security mode complete)。
在一些实施例中,该第一终端设备接收该第二终端设备通过该中继设备发送的错误消息;其中,该错误消息包括以下至少之一:原因信息,第五消息验证码;其中,该原因信息用于指示该第二终端设备与该第一终端设备的安全策略冲突,或者,该原因信息用于指示该第一消息验证码验证失败,或者,该原因信息用于指示该第二终端设备与该第一终端设备的安全算法协商失败,该第五消息验证码的输入参数包括以下至少之一:该原因信息;
在该第五消息验证码有效的情况下,该第一终端设备确定安全模式建立失败,和/或,该第一终端设备重新发起安全模式建立流程。
在一些实施例中,该错误消息也可以受完整性保护。
具体例如,该原因信息用于指示该第二终端设备与该第一终端设备的安全策略冲突,例如,该第二终端设备不支持该第一消息中携带的该第一终端设备的安全策略信息。
具体例如,该原因信息用于指示该第二终端设备与该第一终端设备的安全算法协商失败,例如, 该第二终端设备不支持该第一消息中携带的该第一终端设备的安全能力信息。
在一些实施例中,该第一终端设备、该中继设备和第二终端设备之间进行发现和路径选择过程。该过程中第一终端设备通过该中继设备向第二终端设备发送直接通信请求触发第一终端设备与该中继设备、该中继设备与第二中继设备间PC5链路的安全连接的建立,和第一终端设备与第二终端设备间端到端的安全连接的建立;
其中,该直接通信请求包括以下至少之一:源标识,目标标识;其中,该源标识用于标识该第一终端设备与该第二终端设备之间的中继连接的源端,该目标标识用于标识该第一终端设备与该第二终端设备之间的中继连接的目标端。
在一些实施例中,当在该第一终端设备和该第二终端设备之间建立不同(Source ID、Destination ID)组之间的链接或者在更新该链接的第二密钥(K
D-SESS)时,该直接通信请求还可以包括该第一密钥的标识(K
D ID)。
具体例如,在该直接通信请求包括该第一密钥的标识(K
D ID)的情况下,该第二终端设备可以不发起认证流程,即不发送认证请求消息,也即,上述S210可以省略不执行。
具体例如,在该直接通信请求不包括该第一密钥的标识(K
D ID)的情况下,或者,在该第二终端设备忽略该直接通信请求中包括的该第一密钥的标识(K
D ID)的情况下,该第一终端设备接收该第二终端设备通过该中继设备发送的认证请求消息。也即,在该第一消息不包括该第一密钥的标识的情况下,该第二终端设备发起认证流程,以获取该第一密钥。或者,在该第二终端设备忽略该第一消息中包括的该第一密钥的标识的情况下,该第二终端设备发起认证流程,以重新获取该第一密钥。
在一些实施例中,该第一密钥可以是K
D,该第一密钥的标识可以是K
D ID;该第二密钥可以是K
D-SESS,该第二密钥的标识可以是K
D-SESS ID。
在一些实施例中,对于第一终端设备而言,生成第一密钥时的输入参数包括:第一终端设备生成的第二临时私钥(Ephemeral private key2)、第二终端设备生成的第一临时公钥(Ephemeral public key1),以及中继设备的身份信息,或者中继设备生成的随机数,或者中继设备生成的计数器(COUNT)。对于第二终端设备而言,生成第一密钥时的输入参数包括:第一终端设备生成的第二临时公钥(Ephemeral public key2)、第二终端设备生成的第一临时私钥(Ephemeral private key1),以及中继设备的身份信息,或者中继设备生成的随机数,或者中继设备生成的计数器(COUNT)。其中,第一临时公钥与第一临时私钥配对,第二临时公钥与第二临时私钥配对。
在一些实施例中,该完整性保护密钥包括控制面的完整性保护密钥(K
D-CPint)和用户面的完整性保护密钥(K
D-UPint);和/或,该机密性保护密钥包括控制面的机密性保护密钥(K
D-CPenc)和用户面的机密性保护密钥(K
D-UPenc)。
在一些实施例中,该完整性保护密钥的输入参数包括以下至少之一:该第二密钥,选定的算法类型标识符,选定的算法类型标识符的长度,完整性保护算法标识,完整性保护算法标识的长度。也即,可以基于该第二密钥、选定的算法类型标识符、选定的算法类型标识符的长度、完整性保护算法标识、完整性保护算法标识的长度中的至少之一,生成该完整性保护密钥。
可选地,该完整性保护密钥的输入参数还可以包括一些系统设定参数。在该第二密钥自动刷新时,该完整性保护密钥自动更新。
在一些实施例中,该机密性保护密钥的输入参数包括以下至少之一:该第二密钥,选定的算法类型标识符,选定的算法类型标识符的长度,机密性保护算法标识,机密性保护算法标识的长度。也即,可以基于该第二密钥、选定的算法类型标识符、选定的算法类型标识符的长度、机密性保护算法标识、机密性保护算法标识的长度中的至少之一,生成该机密性保护密钥。
可选地,该机密性保护密钥的输入参数还可以包括一些系统设定参数。在该第二密钥自动刷新时,该机密性保护密钥自动更新。
在一些实施例中,对于控制面的完整性保护密钥(K
D-CPint),选定的算法类型标识符可以通过“控制面完整性保护算法”或设置特定值来表示。
在一些实施例中,对于控制面的机密性保护密钥(K
D-CPenc),选定的算法类型标识符可以通过“控制面机密性保护算法”或设置特定值来表示。
在一些实施例中,对于用户面的完整性保护密钥(K
D-CPint),选定的算法类型标识符可以通过“用户面完整性保护算法”或设置特定值来表示。
在一些实施例中,对于用户面的机密性保护密钥(K
D-CPenc),选定的算法类型标识符可以通过“用户面机密性保护算法”或设置特定值来表示。
具体例如,本申请所涉及的密钥分层结构可以如图7所示。
根密钥:签名私钥/秘密签名密钥(Secret Signing Key,SSK)是UE-to-UE relay单播链路安全的 信任根。SSK与用户标识(UE ID),公钥参数PVT组成基于身份的公钥签名算法(Elliptic Curve-Based Certificateless Signatures for Identity-Based Encryption,ECCSI)算法中用户的签名公私钥对。用户各自生成临时公私钥对,通过使用基于椭圆曲线的加密方案(Elliptic Curve Integrated Encryption Scheme,ECIES)算法来生成K
D,另外,源设备用户生成的签名,从而保证身份真实性与临时公钥的完整性、不可否认性。目标设备用户生成的签名,从而保证身份真实性与临时公钥的完整性、不可否认性。从而保证仅有源设备和目标设备双方才可以获得密钥K
D,故签名私钥或SSK是保障源设备与目标设备之间安全通信的信任根。
K
D:密钥长度至少为256比特(bits),由源设备和目标设备双方通过临时公私钥协商生成。基于根密钥,通过重新运行认证流程来更新K
D。K
D用于生成下一层密钥K
D-sess。即使源设备与目标设备之间没有活动的通信会话,那么也可以保存该密钥。K
D ID可以用来标识K
D。
K
D:对于UE-1而言,生成时的输入参数包括:UE-1的临时私钥Ephemeral private key2、UE-2的临时公钥Ephemeral public key1、以及UE-relay的身份信息,或者UE-relay生成的随机数,或者UE-relay生成的计数器COUNT;对于UE-2而言,生成时的输入参数包括:UE-1的临时公钥Ephemeral public key2、UE-2的临时私钥Ephemeral private key1、以及UE-relay的身份,或者UE-relay生成的随机数,或者UE-relay生成的计数器COUNT。
K
D-sess:密钥长度至少为256bits,K
D-sess用于派生下一层完整性保护或机密性保护密钥。可以基于K
D,通过重新运行安全连接建立流程或者相关的密钥更新流程来刷新K
D-sess。K
D-sess ID用于标识K
D-sess。K
D-sess由K
D使用HMAC-SHA-256或HMAC-SM3等密钥派生算法衍生而成。K
D-sess的输入参数至少必须含有密钥K
D、随机数Nonce_1(即第一终端设备生成的第一随机数)、随机数Nonce_2(即第二终端设备生成的第二随机数)。可选地,K
D-sess的输入参数还可以包括但不限于以下至少之一:源标识(Source ID)、目标标识(Destination ID)、随机数Nonce_1的长度、随机数Nonce_2的长度、源标识(Source ID)的长度、目标标识(Destination ID)的长度。另外,K
D-sess的输入参数还可以包括其他系统设定参数,如3GPP指定的一个或多个固定参数。
K
D-CPint:密钥长度至少为128bits,该密钥可以用于控制面数据完整性保护,该密钥由K
D-sess使用HMAC-SHA-256或HMAC-SM3等密钥派生算法衍生而来。K
D-CPint的输入参数至少必须含有密钥K
D-sess、所选定的算法类型标识符(比如“控制面完整性保护算法”或设置特定值来表示)及该选定的算法类型标识符的长度,完整性保护算法标识以及该完整性保护算法标识的长度,其他系统设定参数可以作为可选输入参数。在K
D-sess自动刷新时,K
D-CPint自动更新。
K
D-CPenc:密钥长度至少为128bits,该密钥可以用于控制面数据机密性保护,该密钥由K
D-sess使用HMAC-SHA-256或HMAC-SM3等密钥派生算法衍生而来。K
D-CPenc的输入参数至少必须含有密钥K
D-sess,所选定的算法类型标识符(比如“控制面机密性保护算法”或设置特定值来表示)及选定的算法类型标识符的长度,机密性保护算法标识以及该机密性保护算法标识的长度,其他系统设定参数可以作为可选输入参数。在K
D-sess自动刷新时,K
D-CPenc自动更新。
K
D-UPint:密钥长度至少为128bits,该密钥可以用于用户面数据完整性保护,该密钥由K
D-sess使用HMAC-SHA-256或HMAC-SM3等密钥派生算法衍生而来。K
D-UPint的输入参数至少必须含有密钥K
D-sess,所选定的算法类型标识符(比如“用户面完整性保护算法”或设置特定值来表示)及该选定的算法类型标识符的长度,完整性保护算法标识以及该完整性保护算法标识的长度,其他系统设定参数可以作为可选输入参数。在K
D-sess自动刷新时,K
D-UPint自动更新。
K
D-UPenc:密钥长度至少为128bits,该密钥可以用于用户面数据机密性保护,该密钥由K
D-sess使用HMAC-SHA-256或HMAC-SM3等密钥派生算法衍生而来。K
D-UPenc的输入参数至少必须含有密钥K
D-sess,所选定的算法类型标识符(比如“用户面机密性保护算法”或设置特定值来表示)及该选定的算法类型标识符的长度,机密性保护算法标识以及该机密性保护算法标识的长度,其他系统设定参数可以作为可选输入参数。在K
D-sess自动刷新时,K
D-UPenc自动更新。
在一些实施例中,本申请中的ECCSI仅为示例,并不局限于该算法,也可以使用其他基于身份的公钥签名和公钥加密算法来替换,在替换公钥算法的同时,所有请求消息中与公钥算法相关的参数需要作相应替换。
在一些实施例中,本申请中第一终端设备和第二终端设备使用的密钥派生函数不局限于HMAC-SHA-256或HMAC-SM3,包括任何一种满足计算安全的密钥派生函数。
在一些实施例中,本申请中密钥派生函数的输入参数不局限于上述提到的必要参数,可以含有其他可选参数,比如应用系统设置固定参数。
在一些实施例中,本申请中安全通信建立流程中所有交互消息中的信息元素并不局限于上述方案中提到的内容,也可以增加由于应用系统要求的可选信息元素。
因此,在本申请实施例中,第一随机数、第一密钥和第二终端设备生成的第二随机数用于派生第二密钥,第二密钥用于派生完整性保护密钥和/或机密性保护密钥,能够保证第一终端设备和第二终端设备的身份安全与通信数据的机密性与完整性,从而确保双方传输数据的机密性和完整性,防止其他设备甚至中继设备的窃听。
本申请实施例适用于5G层3(Layer-3,L3)UE-to-UE relay架构下第一终端设备(源设备)和第二终端设备(目标设备)之间的安全通信建立流程。在用户设备拥有相应公私钥的前提下,该安全通信建立流程无需网络侧认证和分发密钥流程,即可建立源设备和目标设备之间的安全连接。该安全通信建立流程借助公钥签名技术,能够确保用户设备的身份真实性和消息不可否认性,能够抗重放攻击、中间人攻击、伪装等多种主动攻击,同时保证认证流程消息的完整性,并且利用ECIES算法,从而建立仅在源设备和目标设备之间的安全环境,确保源设备和目标设备双方传输数据的机密性和完整性,从而防止外部敌手甚至中继设备的窃听;保证了安全通信建立机制的可扩展性,另外,该安全通信建立流程能够实现源设备和目标设备之间用户面和控制面安全策略、以及双方所支持加密和完整性保护算法的安全协商,能够实现完整性保护,抵抗篡改和降级攻击。
上文结合图6至图7,详细描述了本申请的第一终端设备侧实施例,下文结合图8,详细描述本申请的第二终端设备侧实施例,应理解,第二终端设备侧实施例与第一终端设备侧实施例相互对应,类似的描述可以参照第一终端设备侧实施例。
图8是根据本申请实施例的中继通信的方法300的示意性流程图,如图8所示,该中继通信的方法300可以包括如下内容中的至少部分内容:
S310,第二终端设备通过中继设备向第一终端设备发送认证请求消息;其中,该认证请求消息包括以下至少之一:该第二终端设备所属用户的信息,该第二终端设备生成的第一临时公钥,该第二终端设备的签名,该中继设备的相关信息;其中,该第二终端设备所属用户的信息包括该第二终端设备的签名证书,或者,该第二终端设备所属用户的信息包括该第二终端设备的标识和该第二终端设备的PVT和KPAK;该第二终端设备的签名的输入参数包括以下至少之一:该第二终端设备所属用户的信息和该第一临时公钥;该第一临时公钥和该中继设备的相关信息用于该第一终端设备派生第一密钥;该中继设备的相关信息包括以下之一:该中继设备的身份信息,该中继设备生成的随机数,该中继设备生成的计数器。
本实施例基于ECCSI签名方案,建立层3(layer3,L3)架构下的UE-to-UE中继场景下的安全连接。具体的,本申请实施例应用于L3架构下的UE-to-UE中继场景,也即,第一终端设备与第二终端设备之间通过中继设备进行通信。例如,第一终端设备与第二终端设备之间的中继连接可以是PC5链路。
在本申请实施例中,该第一终端设备可以是源设备或源终端,该第二终端设备可以是目标设备或目标终端。该中继设备可以是中继终端。
在本申请实施例中,该第二终端设备的签名的输入参数包括以下至少之一:该第二终端设备所属用户的信息和该第一临时公钥。也即,该第二终端设备可以基于该第二终端设备所属用户的信息和该第一临时公钥中的至少之一,生成该第二终端设备的签名。
在本申请实施例中,该中继设备的签名的输入参数包括以下至少之一:该第二终端设备的签名和该中继设备所属用户的信息。也即,该中继设备可以基于该第二终端设备的签名和该中继设备所属用户的信息中的至少之一,生成该中继设备的签名。
在一些实施例中,在该第二终端设备所属用户的信息包括该第二终端设备的签名证书的情况下,该第二终端设备的签名由该第二终端设备的签名私钥生成。可选地,该第二终端设备的签名证书和签名私钥可以是可信中心密钥管理服务器(KMS)通过安全通道为该第二终端设备预先配置的。该安全通道可以基于应用程序的身份验证和密钥管理(AKMA)机制或者通用引导架构(GBA)机制来建立该第二终端设备与KMS的安全连接,该KMS可以直接由运营商来负责管理或者是与运营商有商业关系的第三方服务提供商。
在一些实施例中,在该第二终端设备所属用户的信息包括该第二终端设备的标识和该第二终端设备的PVT和KPAK的情况下,该第二终端设备的签名由该第二终端设备的秘密签名密钥(SSK)生成。可选地,该第二终端设备的PVT和KPAK、以及秘密签名密钥(SSK)可以是可信中心KMS通过安全通道为该第二终端设备预先配置的。该安全通道可以基于AKMA机制或者GBA机制来建立该第二终端设备与KMS的安全连接,该KMS可以直接由运营商来负责管理或者是与运营商有商业关系的第三方服务提供商。
在一些实施例中,该第二终端设备接收该第一终端设备通过该中继设备发送的第一消息;
其中,该第一消息包括以下至少之一:该第一终端设备的安全能力信息,该第一终端设备的安全 策略信息,该第一终端设备所属用户的信息,该中继设备所属用户的信息,该第一终端设备生成的第一随机数,该第一终端设备生成的与该第二临时私钥配对的第二临时公钥,该第一终端设备生成的该第一密钥的标识的M个比特位,该第一终端设备的签名,该中继设备的签名,第一消息验证码;
其中,该第一终端设备所属用户的信息包括该第一终端设备的签名证书,或者,该第一终端设备所属用户的信息包括该第一终端设备的标识和该第一终端设备的PVT和KPAK;该中继设备所属用户的信息包括该中继设备的签名证书,或者,该中继设备所属用户的信息包括该中继设备的标识和该中继设备的PVT和KPAK;该第一终端设备的签名的输入参数包括以下至少之一:该第一终端设备所属用户的信息,该第二临时公钥,该第一密钥的标识的M个比特位,该第二终端设备的签名;该中继设备的签名的输入参数包括以下至少之一:该中继设备所属用户的信息,该第一终端设备的签名,该第二终端设备的签名;
其中,该第一消息通过基于该第一密钥生成的该第一消息验证码进行完整性保护,且该第一消息验证码的输入参数包括以下至少之一:该第一终端设备的安全能力信息,该第一终端设备的安全策略信息,该第一终端设备所属用户的信息,该中继设备所属用户的信息,该第一随机数,该第二临时公钥,该M个比特位,该第一终端设备的签名,该中继设备的签名;
其中,该第二临时公钥和该中继设备的相关信息用于该第二终端设备派生该第一密钥,该第一随机数、该第一密钥和该第二终端设备生成的第二随机数用于派生第二密钥,该第二密钥用于派生完整性保护密钥和/或机密性保护密钥,该第一密钥的标识由该M个比特位与该第一密钥的标识的另外N个比特位合并得到,M和N均为正整数。
在本申请实施例中,该第一消息验证码的输入参数包括以下至少之一:该第一终端设备的安全能力信息,该第一终端设备的安全策略信息,该第一终端设备所属用户的信息、该中继设备所属用户的信息、该第一随机数,该第二临时公钥,该M个比特位。也即,该第一终端设备可以基于该第一终端设备的安全能力信息、该第一终端设备的安全策略信息、该第一随机数、该第二临时公钥、该M个比特位、该第一终端设备的签名、该中继设备的签名中的至少之一,生成该第一消息验证码。
在本申请实施例中,第一终端设备生成的第一随机数、第一密钥和第二终端设备生成的第二随机数用于派生第二密钥。也即,第一终端设备至少根据第一随机数、第一密钥和第二随机数派生第二密钥,以及第一终端设备可以基于第二密钥派生完整性保护密钥和/或机密性保护密钥,从而第一终端设备可以基于完整性保护密钥和/或机密性保护密钥对发送的消息进行安全保护。同理,第二终端设备至少根据第一随机数、第一密钥和第二随机数派生第二密钥,以及第二终端设备可以基于第二密钥派生完整性保护密钥和/或机密性保护密钥,从而第二终端设备可以基于完整性保护密钥和/或机密性保护密钥对发送的消息进行安全保护。
在一些实施例中,在该第一终端设备所属用户的信息包括该第一终端设备的签名证书的情况下,该第一终端设备的签名由该第一终端设备的签名私钥生成,或者,在该第一终端设备所属用户的信息包括该第一终端设备的标识和该第一终端设备的PVT和KPAK的情况下,该第一终端设备的签名由该第一终端设备的秘密签名密钥生成。
在一些实施例中,在该中继设备所属用户的信息包括该中继设备的签名证书的情况下,该中继设备的签名由该中继设备的签名私钥生成,或者,在该中继设备所属用户的信息包括该中继设备的标识和该中继设备的PVT和KPAK的情况下,该中继设备的签名由该中继设备的秘密签名密钥生成。
在一些实施例中,该第一消息为认证响应消息,或者,该第一消息为安全模式命令消息。
在一些实施例中,该第一终端设备的安全能力信息可以是该第一终端设备支持的密码算法列表。
在一些实施例中,该第一终端设备的安全策略信息可以是该第一终端设备是否支持机密性保护或完整性保护。其中,该第一终端设备的安全策略信息包括:该第一终端设备在控制面的安全策略信息,和/或,该第一终端设备在用户面的安全策略信息。
在一些实施例中,该M个比特位可以是该第一密钥的标识的最高M个比特位,该N个比特位可以是该第一密钥的标识的最低N个比特位;或者,该M个比特位可以是该第一密钥的标识的前M个比特位,该N个比特位可以是该第一密钥的标识的后N个比特位;或者,该M个比特位可以是该第一密钥的标识的偶数位的比特位,该N个比特位可以是该第一密钥的标识的奇数位的比特位。
在一些实施例中,M与N的取值可以相同,也可以不同,本申请对此并不限定。
在一些实施例中,该第二终端设备分别检查该第一终端设备的签名证书和该中继设备的签名证书,在该第一终端设备的签名证书和该中继设备的签名证书有效的情况下,该第二终端设备基于该第一终端设备的签名证书对该第一终端设备的签名进行验证,以及该第二终端设备基于该中继设备的签名证书对该中继设备的签名进行验证;或者,该第二终端设备分别检查该第一终端设备的KPAK和该中继设备的KPAK,在该第一终端设备的KPAK和该中继设备的KPAK有效的情况下,且基于该第一 终端设备的标识和该第一终端设备的PVT对该第一终端设备的签名进行验证,以及基于该中继设备的标识和该中继设备的PVT对该中继设备的签名进行验证;
在该第一终端设备的签名和该中继设备的签名验证成功,且该第一消息中携带的信息未遭受篡改的情况下,该第二终端设备生成第二随机数,该第二终端设备至少根据该第一随机数、该第一密钥和该第二随机数生成该第二密钥,该第二终端设备根据该第二密钥生成完整性保护密钥和/或机密性保护密钥,以及该第二终端设备生成该第一密钥的标识的N个比特位,并将该M个比特位和该N个比特位合并得到该第一密钥的标识。
在一些实施例中,该第二终端设备可以根据该第一随机数、该第一密钥、该第二随机数,以及源标识、目标标识、该第一随机数的长度、该第二随机数的长度、该源标识的长度、该目标标识的长度中的至少之一,生成该第二密钥。其中,该源标识用于标识该第一终端设备与该第二终端设备之间的中继连接的源端,该目标标识用于标识该第一终端设备与该第二终端设备之间的中继连接的目标端。另外,该第二密钥的输入参数还可以包括其他系统设定参数,如3GPP指定的一个或多个固定参数。
具体例如,假设该第一消息验证码的输入参数包括:该第一终端设备的安全能力信息、该第一终端设备的安全策略信息、该第一随机数、该第二临时公钥、该M个比特位。该第二终端设备可以基于该第一终端设备的安全能力信息、该第一终端设备的安全策略信息、该第一随机数、该第二临时公钥、该M个比特位生成第一消息验证码,并与该第一消息中包含的该第一消息验证码进行比较,若比较一致的情况下,该第一消息验证码有效。
在一些实施例中,在该第一消息验证码有效的情况下,该第二终端设备通过该中继设备向该第一终端设备发送第二消息;其中,该第二消息包括以下至少之一:该第二随机数,该N个比特位,该第二终端设备生成的该第二密钥的标识的x个比特位,该第二终端设备选取的安全算法,该第二终端设备选取的安全策略,第二消息验证码;
其中,该第二消息通过基于该第二密钥生成的该第二消息验证码进行完整性保护,或者,该第二消息通过基于该第二密钥派生的完整性保护密钥生成的该第二消息验证码进行完整性保护,且该第二消息验证码的输入参数包括以下至少之一:该第二随机数,该N个比特位,该x个比特位,该第二终端设备选取的安全算法,该第二终端设备选取的安全策略;
其中,该第二密钥的标识由该x个比特位与该第二密钥的标识的另外y个比特位合并得到,x和y均为正整数。
具体例如,假设该第二消息验证码的输入参数包括:该第二随机数、该N个比特位、该x个比特位、该第二终端设备选取的安全算法、该第二终端设备选取的安全策略。该第一终端设备可以基于该第二随机数、该N个比特位、该x个比特位、该第二终端设备选取的安全算法、该第二终端设备选取的安全策略生成第二消息验证码,并与该第二消息中包含的该第二消息验证码进行比较,若比较一致的情况下,该第二消息验证码有效。
在一些实施例中,该x个比特位可以是该第二密钥的标识的最高x个比特位,该y个比特位可以是该第二密钥的标识的最低y个比特位;或者,该x个比特位可以是该第二密钥的标识的前x个比特位,该y个比特位可以是该第二密钥的标识的后y个比特位;或者,该x个比特位可以是该第二密钥的标识的偶数位的比特位,该y个比特位可以是该第二密钥的标识的奇数位的比特位。
在一些实施例中,x与y的取值可以相同,也可以不同,本申请对此并不限定。
在一些实施例中,该第二消息通过该第一密钥进行加密,且该第二消息还包括第三消息验证码;
其中,该第二消息通过基于该第一密钥生成的该第三消息验证码进行完整性保护,且该第三消息验证码的输入参数包括以下至少之一:该第二随机数,该N个比特位,该x个比特位,该第二终端设备选取的安全算法,该第二终端设备选取的安全策略。
在一些实施例中,该第二消息也可以不通过该第一密钥进行加密,或者,该第二消息可以不加密。
具体例如,假设该第三消息验证码的输入参数包括:该第二随机数、该N个比特位、该x个比特位、该第二终端设备选取的安全算法、该第二终端设备选取的安全策略。该第一终端设备可以基于该第二随机数、该N个比特位、该x个比特位、该第二终端设备选取的安全算法、该第二终端设备选取的安全策略生成第三消息验证码,并与该第二消息中包含的该第三消息验证码进行比较,若比较一致的情况下,该第三消息验证码有效。
具体的,该第二终端设备可以基于该第一终端设备的安全能力信息选取安全算法,和/或,该第二终端设备可以基于该第一终端设备的安全策略信息选取安全策略。
在一些实施例中,该第一消息为认证响应消息,该第二消息为安全模式命令(SMC)消息。
在一些实施例中,该第一消息为安全模式命令(SMC)消息,该第二消息为安全模式响应消息。
具体的,在本申请实施例中,第一终端设备可以根据第二终端设备生成的第一临时公钥、中继设 备的相关信息和第一终端设备生成的第二临时私钥派生第一密钥。相应的,第二终端设备可以根据第一终端设备生成的第二临时公钥、该中继设备的相关信息和第二终端设备生成的第一临时私钥派生第一密钥。其中,第二终端设备生成的第一临时公钥与第二终端设备生成的第一临时私钥配对,第一终端设备生成的第二临时公钥与第一终端设备生成的第二临时私钥配对。
具体例如,第一终端设备可以根据第一临时公钥、中继设备的相关信息和第二临时私钥,并使用ECIES算法计算出第一密钥;第二终端设备可以根据第二临时公钥、中继设备的相关信息和第一临时私钥,并使用ECIES算法计算出第一密钥。
在一些实施例中,该第二终端设备接收该第一终端设备通过该中继设备发送的第三消息;
其中,该第三消息用于指示安全模式建立完成,该第三消息通过目标密钥进行加密,且该第三消息包括以下至少之一:该第一终端设备生成的该第二密钥的标识的y个比特位,第四消息验证码;
其中,该目标密钥包括以下之一:该第一密钥,该第二密钥,该第二密钥派生的机密性保护密钥;
其中,该第三消息通过基于该第二密钥生成的该第四消息验证码进行完整性保护,或者,该第三消息通过基于该第二密钥派生的完整性保护密钥生成的该第四消息验证码进行完整性保护,该第四消息验证码的输入参数包括该y个比特位。
在一些实施例中,该第二终端设备通过该目标密钥对该第三消息进行解密;
在该第三消息中携带的信息未遭受篡改的情况下,且该第四消息验证码有效的情况下,该第二终端设备将该x个比特位与该y个比特位合并得到该第二密钥的标识。
具体的,该第二终端设备可以基于该y个比特位生成第四消息验证码,并与该第三消息中包含的该第四消息验证码进行比较,若比较一致的情况下,该第四消息验证码有效。
具体例如,该第三消息为安全模式结束消息(security mode complete)。
在一些实施例中,该第二终端设备通过该中继设备向该第一终端设备发送错误消息;其中,该错误消息包括以下至少之一:原因信息,第五消息验证码;其中,该原因信息用于指示该第二终端设备与该第一终端设备的安全策略冲突,或者,该原因信息用于指示该第一消息验证码验证失败,或者,该原因信息用于指示该第二终端设备与该第一终端设备的安全算法协商失败,该第五消息验证码的输入参数包括以下至少之一:该原因信息。
具体的,对于该第一终端设备,在该第五消息验证码有效的情况下,该第一终端设备确定安全模式建立失败,和/或,该第一终端设备重新发起安全模式建立流程。
在一些实施例中,该错误消息也可以受完整性保护。
具体例如,该原因信息用于指示该第二终端设备与该第一终端设备的安全策略冲突,例如,该第二终端设备不支持该第一消息中携带的该第一终端设备的安全策略信息。
具体例如,该原因信息用于指示该第二终端设备与该第一终端设备的安全算法协商失败,例如,该第二终端设备不支持该第一消息中携带的该第一终端设备的安全能力信息。
在一些实施例中,该第二终端设备接收该第一终端设备通过该中继设备发送的直接通信请求;其中,该直接通信请求包括以下至少之一:源标识,目标标识;其中,该源标识用于标识该第一终端设备与该第二终端设备之间的中继连接的源端,该目标标识用于标识该第一终端设备与该第二终端设备之间的中继连接的目标端。
在一些实施例中,当在第一终端设备和第二终端设备之间建立不同(Source ID、Destination ID)组之间的链接或者在更新该链接的第二密钥(K
D-SESS)时,该直接通信请求还可以包括该第一密钥的标识(K
D ID)。
具体例如,在该直接通信请求包括该第一密钥的标识(K
D ID)的情况下,该第二终端设备可以不发送认证请求消息。
具体例如,在该直接通信请求不包括该第一密钥的标识(K
D ID)的情况下,或者,在该第二终端设备忽略该直接通信请求中包括的该第一密钥的标识(K
D ID)的情况下,该第一终端设备接收该第二终端设备通过该中继设备发送的认证请求消息。也即,在该第一消息不包括该第一密钥的标识的情况下,该第二终端设备发起认证流程,以获取该第一密钥。或者,在该第二终端设备忽略该第一消息中包括的该第一密钥的标识的情况下,该第二终端设备发起认证流程,以重新获取该第一密钥。
在一些实施例中,该第一密钥可以是K
D,该第一密钥的标识可以是K
D ID;该第二密钥可以是K
D-SESS,该第二密钥的标识可以是K
D-SESS ID。
在一些实施例中,该完整性保护密钥包括控制面的完整性保护密钥(K
D-CPint)和用户面的完整性保护密钥(K
D-UPint);和/或,该机密性保护密钥包括控制面的机密性保护密钥(K
D-CPenc)和用户面的机密性保护密钥(K
D-UPenc)。
在一些实施例中,该完整性保护密钥的输入参数包括以下至少之一:该第二密钥,选定的算法类 型标识符,选定的算法类型标识符的长度,完整性保护算法标识,完整性保护算法标识的长度。也即,可以基于该第二密钥、选定的算法类型标识符、选定的算法类型标识符的长度、完整性保护算法标识、完整性保护算法标识的长度中的至少之一,生成该完整性保护密钥。
可选地,该完整性保护密钥的输入参数还可以包括一些系统设定参数。在该第二密钥自动刷新时,该完整性保护密钥自动更新。
在一些实施例中,该机密性保护密钥的输入参数包括以下至少之一:该第二密钥,选定的算法类型标识符,选定的算法类型标识符的长度,机密性保护算法标识,机密性保护算法标识的长度。也即,可以基于该第二密钥、选定的算法类型标识符、选定的算法类型标识符的长度、机密性保护算法标识、机密性保护算法标识的长度中的至少之一,生成该机密性保护密钥。
可选地,该机密性保护密钥的输入参数还可以包括一些系统设定参数。在该第二密钥自动刷新时,该机密性保护密钥自动更新。
因此,在本申请实施例中,第一随机数、第一密钥和第二终端设备生成的第二随机数用于派生第二密钥,第二密钥用于派生完整性保护密钥和/或机密性保护密钥,能够保证第一终端设备和第二终端设备的身份安全与通信数据的机密性与完整性,从而确保双方传输数据的机密性和完整性,防止其他设备甚至中继设备的窃听。
本申请实施例适用于5G层3(Layer-3,L3)UE-to-UE relay架构下第一终端设备(源设备)和第二终端设备(目标设备)之间的安全通信建立流程。在用户设备拥有相应公私钥的前提下,该安全通信建立流程无需网络侧认证和分发密钥流程,即可建立源设备和目标设备之间的安全连接。该安全通信建立流程借助公钥签名技术,能够确保用户设备的身份真实性和消息不可否认性,能够抗重放攻击、中间人攻击、伪装等多种主动攻击,同时保证认证流程消息的完整性,并且利用ECIES算法,从而建立仅在源设备和目标设备之间的安全环境,确保源设备和目标设备双方传输数据的机密性和完整性,从而防止外部敌手甚至中继设备的窃听;保证了安全通信建立机制的可扩展性,另外,该安全通信建立流程能够实现源设备和目标设备之间用户面和控制面安全策略、以及双方所支持加密和完整性保护算法的安全协商,能够实现完整性保护,抵抗篡改和降级攻击。
上文结合图6至图8,详细描述了本申请的第一终端设备侧实施例和第二终端设备侧实施例,下文结合图9,详细描述本申请的中继设备侧实施例,应理解,中继设备侧实施例与第一终端设备侧实施例和第二终端设备侧实施例相互对应,类似的描述可以参照第一终端设备侧实施例和第二终端设备侧实施例。
图9是根据本申请实施例的中继通信的方法400的示意性流程图,如图9所示,该中继通信的方法400可以包括如下内容中的至少部分内容:
S410,中继设备接收第二终端设备发送的认证请求消息;其中,该认证请求消息包括以下至少之一:该第二终端设备所属用户的信息,该第二终端设备生成的第一临时公钥,该第二终端设备的签名;其中,该第二终端设备所属用户的信息包括该第二终端设备的签名证书,或者,该第二终端设备所属用户的信息包括该第二终端设备的标识和该第二终端设备的PVT和KPAK;该第二终端设备的签名的输入参数包括以下至少之一:该第二终端设备所属用户的信息和该第一临时公钥;
S420,在该第二终端设备的签名证书有效,且基于该第二终端设备的签名证书对该第二终端设备的签名验证成功的情况下,或者,在该第二终端设备的KPAK有效,且基于该第二终端设备的标识和该第二终端设备的PVT对该第二终端设备的签名验证成功的情况下,该中继设备向该第一终端设备发送验证之后的认证请求消息;其中,该验证之后的认证请求消息包括以下至少之一:该第二终端设备所属用户的信息,该中继设备所属用户的信息,该第一临时公钥,该第二终端设备的签名,该中继设备的签名,该中继设备的相关信息;其中,该中继设备所属用户的信息包括该中继设备的签名证书,或者,该中继设备所属用户的信息包括该中继设备的标识和该中继设备的PVT和KPAK;该中继设备的签名的输入参数包括以下至少之一:该第二终端设备的签名和该中继设备所属用户的信息;其中,该第一临时公钥和该中继设备的相关信息用于该第一终端设备派生该第一密钥;该中继设备的相关信息包括以下之一:该中继设备的身份信息,该中继设备生成的随机数,该中继设备生成的计数器。
本实施例基于ECCSI签名方案,建立L3架构下的UE-to-UE中继场景下的安全连接。具体的,本申请实施例应用于L3架构下的UE-to-UE中继场景,也即,第一终端设备与第二终端设备之间通过中继设备进行通信。例如,第一终端设备与第二终端设备之间的中继连接可以是PC5链路。
在本申请实施例中,该第一终端设备可以是源设备或源终端,该第二终端设备可以是目标设备或目标终端。该中继设备可以是中继终端。
在本申请实施例中,该第二终端设备的签名的输入参数包括以下至少之一:该第二终端设备所属用户的信息和该第一临时公钥。也即,该第二终端设备可以基于该第二终端设备所属用户的信息和该 第一临时公钥中的至少之一,生成该第二终端设备的签名。
在本申请实施例中,该中继设备的签名的输入参数包括以下至少之一:该第二终端设备的签名和该中继设备所属用户的信息。也即,该中继设备可以基于该第二终端设备的签名和该中继设备所属用户的信息中的至少之一,生成该中继设备的签名。
具体的,该中继设备可以基于其本地存储的一个或多个签名证书,验证该第二终端设备的签名证书的有效性。例如,在中继设备本地存储的签名证书中存在与第二终端设备的签名证书一致的签名证书的情况下,该第二终端设备的签名证书有效。可选地,该中继设备本地存储的一个或多个签名证书可以由KMS预配置。
具体的,该中继设备可以基于其本地存储的一个或多个KPAK,验证该第二终端设备的KPAK的有效性。例如,在中继设备本地存储的KPAK中存在与第二终端设备的KPAK一致的KPAK的情况下,该第二终端设备的KPAK有效。可选地,该第一终端设备本地存储的一个或多个KPAK可以由KMS预配置。
在本申请实施例中,第一终端设备可以根据第二终端设备生成的第一临时公钥、中继设备的相关信息和第一终端设备生成的第二临时私钥派生第一密钥。相应的,第二终端设备可以根据第一终端设备生成的第二临时公钥、中继设备的相关信息和第二终端设备生成的第一临时私钥派生第一密钥。其中,第二终端设备生成的第一临时公钥与第二终端设备生成的第一临时私钥配对,第一终端设备生成的第二临时公钥与第一终端设备生成的第二临时私钥配对。
具体例如,第一终端设备可以根据第一临时公钥、中继设备的相关信息和第二临时私钥,并使用ECIES算法计算出第一密钥;第二终端设备可以根据第二临时公钥、中继设备的相关信息和第一临时私钥,并使用ECIES算法计算出第一密钥。
在一些实施例中,在该第二终端设备所属用户的信息包括该第二终端设备的签名证书的情况下,该第二终端设备的签名由该第二终端设备的签名私钥生成。可选地,该第二终端设备的签名证书和签名私钥可以是可信中心密钥管理服务器(KMS)通过安全通道为该第二终端设备预先配置的。该安全通道可以基于应用程序的身份验证和密钥管理(AKMA)机制或者通用引导架构(GBA)机制来建立该第二终端设备与KMS的安全连接,该KMS可以直接由运营商来负责管理或者是与运营商有商业关系的第三方服务提供商。
在一些实施例中,在该第二终端设备所属用户的信息包括该第二终端设备的标识和该第二终端设备的PVT和KPAK的情况下,该第二终端设备的签名由该第二终端设备的秘密签名密钥(SSK)生成。可选地,该第二终端设备的PVT和KPAK、以及秘密签名密钥(SSK)可以是可信中心KMS通过安全通道为该第二终端设备预先配置的。该安全通道可以基于AKMA机制或者GBA机制来建立该第二终端设备与KMS的安全连接,该KMS可以直接由运营商来负责管理或者是与运营商有商业关系的第三方服务提供商。
在一些实施例中,在该中继设备所属用户的信息包括该中继设备的签名证书的情况下,该中继设备的签名由该中继设备的签名私钥生成。可选地,该中继设备的签名证书和签名私钥可以是可信中心KMS通过安全通道为该中继设备预先配置的。该安全通道可以基于AKMA机制或者GBA机制来建立该中继设备与KMS的安全连接,该KMS可以直接由运营商来负责管理或者是与运营商有商业关系的第三方服务提供商。
在一些实施例中,在该中继设备所属用户的信息包括该中继设备的标识、该中继设备的PVT和KPAK的情况下,该中继设备的签名由该中继设备的秘密签名密钥(SSK)生成。可选地,该中继设备的PVT和KPAK、以及秘密签名密钥(SSK)可以是可信中心KMS通过安全通道为该中继设备预先配置的。该安全通道可以基于AKMA机制或者GBA机制来建立该中继设备与KMS的安全连接,该KMS可以直接由运营商来负责管理或者是与运营商有商业关系的第三方服务提供商。
在一些实施例中,该中继设备接收该第一终端设备发送的第一消息;其中,该第一消息包括以下至少之一:该第一终端设备的安全能力信息,该第一终端设备的安全策略信息,该第一终端设备所属用户的信息,该第一终端设备生成的第一随机数,该第一终端设备生成的第二临时公钥,该第一终端设备生成的该第一密钥的标识的M个比特位,该第一终端设备的签名,第一消息验证码;其中,该第一终端设备所属用户的信息包括该第一终端设备的签名证书,或者,该第一终端设备所属用户的信息包括该第一终端设备的标识和该第一终端设备的PVT和KPAK;该第一终端设备的签名的输入参数包括以下至少之一:该第一终端设备所属用户的信息,该第二临时公钥,该第一密钥的标识的M个比特位,该第二终端设备的签名;其中,该第一消息通过基于该第一密钥生成的该第一消息验证码进行完整性保护,且该第一消息验证码的输入参数包括以下至少之一:该第一终端设备的安全能力信息,该第一终端设备的安全策略信息,该第一终端设备所属用户的信息,该第一随机数,该第二临时 公钥,该M个比特位,该第一终端设备的签名;其中,该第二临时公钥和该中继设备的相关信息用于该第二终端设备派生该第一密钥,该第一随机数、该第一密钥和该第二终端设备生成的第二随机数用于派生第二密钥,该第二密钥用于派生完整性保护密钥和/或机密性保护密钥,该第一密钥的标识由该M个比特位与该第一密钥的标识的另外N个比特位合并得到,M和N均为正整数。
具体的,在该第一终端设备的签名证书有效,且基于该第一终端设备的签名证书对该第一终端设备的签名验证成功的情况下,或者,在该第一终端设备的KPAK有效,且基于该第一终端设备的标识和该第一终端设备的PVT对该第一终端设备的签名验证成功的情况下,该中继设备向该第二终端设备发送验证之后的第一消息;其中,该验证之后的第一消息包括以下至少之一:该第一终端设备的安全能力信息,该第一终端设备的安全策略信息,该第一终端设备所属用户的信息,该中继设备所属用户的信息,该第一终端设备生成的第一随机数,该第一终端设备生成的与该第二临时私钥配对的第二临时公钥,该第一终端设备生成的该第一密钥的标识的M个比特位,该第一终端设备的签名,该中继设备的签名,第一消息验证码;其中,该中继设备所属用户的信息包括该中继设备的签名证书,或者,该中继设备所属用户的信息包括该中继设备的标识和该中继设备的PVT和KPAK;该中继设备的签名的输入参数包括以下至少之一:该中继设备所属用户的信息,该第一终端设备的签名,该第二终端设备的签名,该验证之后的第一消息;
在本申请实施例中,第一终端设备生成的第一随机数、第一密钥和第二终端设备生成的第二随机数用于派生第二密钥。也即,第一终端设备至少根据第一随机数、第一密钥和第二随机数派生第二密钥,以及第一终端设备可以基于第二密钥派生完整性保护密钥和/或机密性保护密钥,从而第一终端设备可以基于完整性保护密钥和/或机密性保护密钥对发送的消息进行安全保护。同理,第二终端设备至少根据第一随机数、第一密钥和第二随机数派生第二密钥,以及第二终端设备可以基于第二密钥派生完整性保护密钥和/或机密性保护密钥,从而第二终端设备可以基于完整性保护密钥和/或机密性保护密钥对发送的消息进行安全保护。
在本申请实施例中,该第一消息验证码的输入参数包括以下至少之一:该第一终端设备的安全能力信息,该第一终端设备的安全策略信息,该第一随机数,该第二临时公钥,该M个比特位。也即,该第一终端设备可以基于该第一终端设备的安全能力信息、该第一终端设备的安全策略信息、该第一随机数、该第二临时公钥、该M个比特位中的至少之一,生成该第一消息验证码。
具体例如,假设该第一消息验证码的输入参数包括:该第一终端设备的安全能力信息、该第一终端设备的安全策略信息、该第一随机数、该第二临时公钥、该M个比特位。该第二终端设备可以基于该第一终端设备的安全能力信息、该第一终端设备的安全策略信息、该第一随机数、该第二临时公钥、该M个比特位生成第一消息验证码,并与该第一消息中包含的该第一消息验证码进行比较,若比较一致的情况下,该第一消息验证码有效。
在一些实施例中,该第一消息为认证响应消息,或者,该第一消息为安全模式命令消息。
在一些实施例中,该第一终端设备的安全能力信息可以是该第一终端设备支持的密码算法列表。
在一些实施例中,该第一终端设备的安全策略信息可以是该第一终端设备是否支持机密性保护或完整性保护。其中,该第一终端设备的安全策略信息包括:该第一终端设备在控制面的安全策略信息,和/或,该第一终端设备在用户面的安全策略信息。
在一些实施例中,该M个比特位可以是该第一密钥的标识的最高M个比特位,该N个比特位可以是该第一密钥的标识的最低N个比特位;或者,该M个比特位可以是该第一密钥的标识的前M个比特位,该N个比特位可以是该第一密钥的标识的后N个比特位;或者,该M个比特位可以是该第一密钥的标识的偶数位的比特位,该N个比特位可以是该第一密钥的标识的奇数位的比特位。
在一些实施例中,M与N的取值可以相同,也可以不同,本申请对此并不限定。
在一些实施例中,该中继设备将该第二终端设备发送的第二消息转发至该第一终端设备;
其中,该第二消息包括以下至少之一:该第二终端设备生成的该第二随机数,该第二终端设备生成的该第一密钥的标识的N个比特位,该第二终端设备生成的该第二密钥的标识的x个比特位,该第二终端设备选取的安全算法,该第二终端设备选取的安全策略,第二消息验证码;
其中,该第二消息通过基于该第二密钥生成的该第二消息验证码进行完整性保护,或者,该第二消息通过基于该第二密钥派生的完整性保护密钥生成的该第二消息验证码进行完整性保护,且该第二消息验证码的输入参数包括以下至少之一:该第二随机数,该N个比特位,该x个比特位,该第二终端设备选取的安全算法,该第二终端设备选取的安全策略;
其中,该第二密钥的标识由该x个比特位与该第二密钥的标识的另外y个比特位合并得到,x和y均为正整数。
在一些实施例中,该x个比特位可以是该第二密钥的标识的最高x个比特位,该y个比特位可以 是该第二密钥的标识的最低y个比特位;或者,该x个比特位可以是该第二密钥的标识的前x个比特位,该y个比特位可以是该第二密钥的标识的后y个比特位;或者,该x个比特位可以是该第二密钥的标识的偶数位的比特位,该y个比特位可以是该第二密钥的标识的奇数位的比特位。
在一些实施例中,x与y的取值可以相同,也可以不同,本申请对此并不限定。
具体例如,假设该第二消息验证码的输入参数包括:该第二随机数、该N个比特位、该x个比特位、该第二终端设备选取的安全算法、该第二终端设备选取的安全策略。该第一终端设备可以基于该第二随机数、该N个比特位、该x个比特位、该第二终端设备选取的安全算法、该第二终端设备选取的安全策略生成第二消息验证码,并与该第二消息中包含的该第二消息验证码进行比较,若比较一致的情况下,该第二消息验证码有效。
在一些实施例中,该第二消息通过该第一密钥进行加密,且该第二消息还包括第三消息验证码;
其中,该第二消息通过基于该第一密钥生成的该第三消息验证码进行完整性保护,且该第三消息验证码的输入参数包括以下至少之一:该第二随机数,该N个比特位,该x个比特位,该第二终端设备选取的安全算法,该第二终端设备选取的安全策略。
具体例如,假设该第三消息验证码的输入参数包括:该第二随机数、该N个比特位、该x个比特位、该第二终端设备选取的安全算法、该第二终端设备选取的安全策略。该第一终端设备可以基于该第二随机数、该N个比特位、该x个比特位、该第二终端设备选取的安全算法、该第二终端设备选取的安全策略生成第三消息验证码,并与该第二消息中包含的该第三消息验证码进行比较,若比较一致的情况下,该第三消息验证码有效。
具体的,该第二终端设备可以基于该第一终端设备的安全能力信息选取安全算法,和/或,该第二终端设备可以基于该第一终端设备的安全策略信息选取安全策略。
在一些实施例中,该第一终端设备可以根据该第一随机数、该第一密钥、该第二随机数,以及源标识、目标标识、该第一随机数的长度、该第二随机数的长度、该源标识的长度、该目标标识的长度中的至少之一,生成该第二密钥。以及该第二终端设备可以根据该第一随机数、该第一密钥、该第二随机数,以及源标识、目标标识、该第一随机数的长度、该第二随机数的长度、该源标识的长度、该目标标识的长度中的至少之一,生成该第二密钥。
其中,该源标识用于标识该第一终端设备与该第二终端设备之间的中继连接的源端,该目标标识用于标识该第一终端设备与该第二终端设备之间的中继连接的目标端。另外,该第二密钥的输入参数还可以包括其他系统设定参数,如3GPP指定的一个或多个固定参数。
在一些实施例中,该第一消息为认证响应消息,该第二消息为安全模式命令(SMC)消息。
在一些实施例中,该第一消息为安全模式命令(SMC)消息,该第二消息为安全模式响应消息。
在一些实施例中,该中继设备将该第一终端设备发送的第三消息转发至该第二终端设备;
其中,该第三消息用于指示安全模式建立完成,该第三消息通过目标密钥进行加密,且该第三消息包括以下至少之一:该第一终端设备生成的该第二密钥的标识的y个比特位,第四消息验证码;
其中,该目标密钥包括以下之一:该第一密钥,该第二密钥,该第二密钥派生的机密性保护密钥;
其中,该第三消息通过基于该第二密钥生成的该第四消息验证码进行完整性保护,或者,该第三消息通过基于该第二密钥派生的完整性保护密钥生成的该第四消息验证码进行完整性保护,该第四消息验证码的输入参数包括该y个比特位。
在一些实施例中,对于该第二终端设备,该第二终端设备通过该目标密钥对该第三消息进行解密;在该第三消息中携带的信息未遭受篡改的情况下,且该第四消息验证码有效的情况下,该第二终端设备将该x个比特位与该y个比特位合并得到该第二密钥的标识。
具体的,该第二终端设备可以基于该y个比特位生成第四消息验证码,并与该第三消息中包含的该第四消息验证码进行比较,若比较一致的情况下,该第四消息验证码有效。
具体例如,该第三消息为安全模式结束消息(security mode complete)。
在一些实施例中,该中继设备将该第二终端设备发送的错误消息转发至该第一终端设备;其中,该错误消息包括以下至少之一:原因信息,第五消息验证码;其中,该原因信息用于指示该第二终端设备与该第一终端设备的安全策略冲突,或者,该原因信息用于指示该第一消息验证码验证失败,或者,该原因信息用于指示该第二终端设备与该第一终端设备的安全算法协商失败,该第五消息验证码的输入参数包括以下至少之一:该原因信息。
具体的,在该第五消息验证码有效的情况下,该第一终端设备确定安全模式建立失败,和/或,该第一终端设备重新发起安全模式建立流程。
在一些实施例中,该错误消息也可以受完整性保护。
具体例如,该原因信息用于指示该第二终端设备与该第一终端设备的安全策略冲突,例如,该第 二终端设备不支持该第一消息中携带的该第一终端设备的安全策略信息。
具体例如,该原因信息用于指示该第二终端设备与该第一终端设备的安全算法协商失败,例如,该第二终端设备不支持该第一消息中携带的该第一终端设备的安全能力信息。
在一些实施例中,该中继设备将该第一终端设备发送的直接通信请求转发至该第二终端设备;其中,该直接通信请求包括以下至少之一:源标识,目标标识;其中,该源标识用于标识该第一终端设备与该第二终端设备之间的中继连接的源端,该目标标识用于标识该第一终端设备与该第二终端设备之间的中继连接的目标端。
在一些实施例中,当在该第一终端设备和该第二终端设备之间建立不同(Source ID、Destination ID)组之间的链接或者在更新该链接的第二密钥(K
D-SESS)时,该直接通信请求还可以包括该第一密钥的标识(K
D ID)。
具体例如,在该直接通信请求包括该第一密钥的标识(K
D ID)的情况下,该第二终端设备可以不发送认证请求消息。
具体例如,在该直接通信请求不包括该第一密钥的标识(K
D ID)的情况下,或者,在该第二终端设备忽略该直接通信请求中包括的该第一密钥的标识(K
D ID)的情况下,该第一终端设备接收该第二终端设备通过该中继设备发送的认证请求消息。也即,在该第一消息不包括该第一密钥的标识的情况下,该第二终端设备发起认证流程,以获取该第一密钥。或者,在该第二终端设备忽略该第一消息中包括的该第一密钥的标识的情况下,该第二终端设备发起认证流程,以重新获取该第一密钥。
在一些实施例中,该第一密钥可以是K
D,该第一密钥的标识可以是K
D ID;该第二密钥可以是K
D-SESS,该第二密钥的标识可以是K
D-SESS ID。
在一些实施例中,该完整性保护密钥包括控制面的完整性保护密钥(K
D-CPint)和用户面的完整性保护密钥(K
D-UPint);和/或,该机密性保护密钥包括控制面的机密性保护密钥(K
D-CPenc)和用户面的机密性保护密钥(K
D-UPenc)。
在一些实施例中,该完整性保护密钥的输入参数包括以下至少之一:该第二密钥,选定的算法类型标识符,选定的算法类型标识符的长度,完整性保护算法标识,完整性保护算法标识的长度。也即,可以基于该第二密钥、选定的算法类型标识符、选定的算法类型标识符的长度、完整性保护算法标识、完整性保护算法标识的长度中的至少之一,生成该完整性保护密钥。
可选地,该完整性保护密钥的输入参数还可以包括一些系统设定参数。在该第二密钥自动刷新时,该完整性保护密钥自动更新。
在一些实施例中,该机密性保护密钥的输入参数包括以下至少之一:该第二密钥,选定的算法类型标识符,选定的算法类型标识符的长度,机密性保护算法标识,机密性保护算法标识的长度。也即,可以基于该第二密钥、选定的算法类型标识符、选定的算法类型标识符的长度、机密性保护算法标识、机密性保护算法标识的长度中的至少之一,生成该机密性保护密钥。
可选地,该机密性保护密钥的输入参数还可以包括一些系统设定参数。在该第二密钥自动刷新时,该机密性保护密钥自动更新。
因此,在本申请实施例中,第一随机数、第一密钥和第二终端设备生成的第二随机数用于派生第二密钥,第二密钥用于派生完整性保护密钥和/或机密性保护密钥,能够保证第一终端设备和第二终端设备的身份安全与通信数据的机密性与完整性,从而确保双方传输数据的机密性和完整性,防止其他设备甚至中继设备的窃听。
本申请实施例适用于5G层3(Layer-3,L3)UE-to-UE relay架构下源设备(第一终端设备)和目标设备(第二终端设备)之间的安全通信建立流程。在用户设备拥有相应公私钥的前提下,该安全通信建立流程无需网络侧认证和分发密钥流程,即可建立源设备和目标设备之间的安全连接。该安全通信建立流程借助公钥签名技术,能够确保用户设备的身份真实性和消息不可否认性,能够抗重放攻击、中间人攻击、伪装等多种主动攻击,同时保证认证流程消息的完整性,并且利用ECIES算法,从而建立仅在源设备和目标设备之间的安全环境,确保源设备和目标设备双方传输数据的机密性和完整性,从而防止外部敌手甚至中继设备的窃听;保证了安全通信建立机制的可扩展性,另外,该安全通信建立流程能够实现源设备和目标设备之间用户面和控制面安全策略、以及双方所支持加密和完整性保护算法的安全协商,能够实现完整性保护,抵抗篡改和降级攻击。
图10是根据本申请实施例的中继通信的方法500的示意性流程图,如图10所示,该中继通信的方法500可以包括如下内容中的至少部分内容:
S510,第一终端设备通过中继设备向第二终端设备发送第一消息;其中,该第一消息包括以下至少之一:该第一终端设备的安全能力信息,该第一终端设备的安全策略信息,该第一终端设备所属用户的信息,该第一终端设备生成的第一随机数,该第一终端设备生成的第二临时公钥,该第一终端设 备生成的第一密钥的标识的M个比特位,该第一终端设备的签名,第一消息验证码;其中,该第一终端设备所属用户的信息包括该第一终端设备的签名证书,或者,该第一终端设备所属用户的信息包括该第一终端设备的标识和该第一终端设备的PVT和KPAK;该第一终端设备的签名的输入参数包括以下至少之一:该第一终端设备所属用户的信息,该第二临时公钥,该第一密钥的标识的M个比特位,该第二终端设备的签名;其中,该第一消息通过基于该第一密钥生成的该第一消息验证码进行完整性保护,且该第一消息验证码的输入参数包括以下至少之一:该第一终端设备的安全能力信息,该第一终端设备的安全策略信息,该第一终端设备所属用户的信息,该第一随机数,该第二临时公钥,该M个比特位,该第一终端设备的签名;其中,该第二临时公钥和该中继设备的相关信息用于该第二终端设备派生该第一密钥,该第一随机数、该第一密钥和该第二终端设备生成的第二随机数用于派生第二密钥,该第二密钥用于派生完整性保护密钥和/或机密性保护密钥,该第一密钥的标识由该M个比特位与该第一密钥的标识的另外N个比特位合并得到,M和N均为正整数;其中,该中继设备的相关信息包括以下之一:该中继设备的身份信息,该中继设备生成的随机数,该中继设备生成的计数器。
本实施例基于ECCSI签名方案,建立L3架构下的UE-to-UE中继场景下的安全连接。具体的,本申请实施例应用于L3架构下的UE-to-UE中继场景,也即,第一终端设备与第二终端设备之间通过中继设备进行通信。例如,第一终端设备与第二终端设备之间的中继连接可以是PC5链路。
在本申请实施例中,第一终端设备生成的第一随机数、第一密钥和第二终端设备生成的第二随机数用于派生第二密钥。也即,第一终端设备至少根据第一随机数、第一密钥和第二随机数派生第二密钥,以及第一终端设备可以基于第二密钥派生完整性保护密钥和/或机密性保护密钥,从而第一终端设备可以基于完整性保护密钥和/或机密性保护密钥对发送的消息进行安全保护。同理,第二终端设备至少根据第一随机数、第一密钥和第二随机数派生第二密钥,以及第二终端设备可以基于第二密钥派生完整性保护密钥和/或机密性保护密钥,从而第二终端设备可以基于完整性保护密钥和/或机密性保护密钥对发送的消息进行安全保护。
在本申请实施例中,该第一消息验证码的输入参数包括以下至少之一:该第一终端设备的安全能力信息,该第一终端设备的安全策略信息,该第一随机数,该第二临时公钥,该M个比特位。也即,该第一终端设备可以基于该第一终端设备的安全能力信息、该第一终端设备的安全策略信息、该第一随机数、该第二临时公钥、该M个比特位中的至少之一,生成该第一消息验证码。
具体例如,假设该第一消息验证码的输入参数包括:该第一终端设备的安全能力信息、该第一终端设备的安全策略信息、该第一随机数、该第二临时公钥、该M个比特位。该第二终端设备可以基于该第一终端设备的安全能力信息、该第一终端设备的安全策略信息、该第一随机数、该第二临时公钥、该M个比特位生成第一消息验证码,并与该第一消息中包含的该第一消息验证码进行比较,若比较一致的情况下,该第一消息验证码有效。
在一些实施例中,该第一消息为认证响应消息,或者,该第一消息为安全模式命令消息。
在一些实施例中,该第一终端设备的安全能力信息可以是该第一终端设备支持的密码算法列表。
在一些实施例中,该第一终端设备的安全策略信息可以是该第一终端设备是否支持机密性保护或完整性保护。其中,该第一终端设备的安全策略信息包括:该第一终端设备在控制面的安全策略信息,和/或,该第一终端设备在用户面的安全策略信息。
在一些实施例中,该M个比特位可以是该第一密钥的标识的最高M个比特位,该N个比特位可以是该第一密钥的标识的最低N个比特位;或者,该M个比特位可以是该第一密钥的标识的前M个比特位,该N个比特位可以是该第一密钥的标识的后N个比特位;或者,该M个比特位可以是该第一密钥的标识的偶数位的比特位,该N个比特位可以是该第一密钥的标识的奇数位的比特位。
在一些实施例中,M与N的取值可以相同,也可以不同,本申请对此并不限定。
在一些实施例中,该第一终端设备接收该第二终端设备通过该中继设备发送的第二消息;
其中,该第二消息包括以下至少之一:该第二终端设备生成的该第二随机数,该第二终端设备生成的该第一密钥的标识的N个比特位,该第二终端设备生成的该第二密钥的标识的x个比特位,该第二终端设备选取的安全算法,该第二终端设备选取的安全策略,第二消息验证码;
其中,该第二消息通过基于该第二密钥生成的该第二消息验证码进行完整性保护,或者,该第二消息通过基于该第二密钥派生的完整性保护密钥生成的该第二消息验证码进行完整性保护,且该第二消息验证码的输入参数包括以下至少之一:该第二随机数,该N个比特位,该x个比特位,该第二终端设备选取的安全算法,该第二终端设备选取的安全策略;
其中,该第二密钥的标识由该x个比特位与该第二密钥的标识的另外y个比特位合并得到,x和y均为正整数。
在一些实施例中,在该第二消息中携带的信息未遭受篡改的情况下,该第一终端设备至少根据该第一随机数、该第一密钥和该第二随机数生成该第二密钥,该第一终端设备根据该第二密钥生成完整性保护密钥和/或机密性保护密钥,以及该第一终端设备将该M个比特位和该N个比特位合并得到该第一密钥的标识,该第一终端设备生成该第二密钥的标识的y个比特位,并将该x个比特位和该y个比特位合并得到该第二密钥的标识;
在该第二消息验证码有效的情况下,该第一终端设备根据该第二终端设备选取的安全算法、该第二密钥、基于该第二密钥生成完整性保护密钥和/或机密性保护密钥、该第二终端设备选取的安全策略,与该第二终端设备进行通信。
在一些实施例中,该第二消息通过该第一密钥进行加密,且该第二消息还包括第三消息验证码;
其中,该第二消息通过基于该第一密钥生成的该第三消息验证码进行完整性保护,且该第三消息验证码的输入参数包括以下至少之一:该第二随机数,该N个比特位,该x个比特位,该第二终端设备选取的安全算法,该第二终端设备选取的安全策略。
在一些实施例中,该第二消息也可以不通过该第一密钥进行加密,或者,该第二消息可以不加密。
在一些实施例中,该第一终端设备根据该第一密钥解密该第二消息;在该第二消息中携带的信息未遭受篡改的情况下,该第一终端设备至少根据该第一随机数、该第一密钥和该第二随机数生成该第二密钥,该第一终端设备根据该第二密钥生成完整性保护密钥和/或机密性保护密钥,以及该第一终端设备将该M个比特位和该N个比特位合并得到该第一密钥的标识,该第一终端设备生成该第二密钥的标识的y个比特位,并将该x个比特位和该y个比特位合并得到该第二密钥的标识;
在该第二消息验证码有效和该第三消息验证码有效的情况下,该第一终端设备根据该第二终端设备选取的安全算法、该第二密钥、基于该第二密钥生成完整性保护密钥和/或机密性保护密钥、该第二终端设备选取的安全策略,与该第二终端设备进行通信。
在一些实施例中,该x个比特位可以是该第二密钥的标识的最高x个比特位,该y个比特位可以是该第二密钥的标识的最低y个比特位;或者,该x个比特位可以是该第二密钥的标识的前x个比特位,该y个比特位可以是该第二密钥的标识的后y个比特位;或者,该x个比特位可以是该第二密钥的标识的偶数位的比特位,该y个比特位可以是该第二密钥的标识的奇数位的比特位。
在一些实施例中,x与y的取值可以相同,也可以不同,本申请对此并不限定。
具体例如,假设该第二消息验证码的输入参数包括:该第二随机数、该N个比特位、该x个比特位、该第二终端设备选取的安全算法、该第二终端设备选取的安全策略。该第一终端设备可以基于该第二随机数、该N个比特位、该x个比特位、该第二终端设备选取的安全算法、该第二终端设备选取的安全策略生成第二消息验证码,并与该第二消息中包含的该第二消息验证码进行比较,若比较一致的情况下,该第二消息验证码有效。
具体例如,假设该第三消息验证码的输入参数包括:该第二随机数、该N个比特位、该x个比特位、该第二终端设备选取的安全算法、该第二终端设备选取的安全策略。该第一终端设备可以基于该第二随机数、该N个比特位、该x个比特位、该第二终端设备选取的安全算法、该第二终端设备选取的安全策略生成第三消息验证码,并与该第二消息中包含的该第三消息验证码进行比较,若比较一致的情况下,该第三消息验证码有效。
具体的,该第二终端设备可以基于该第一终端设备的安全能力信息选取安全算法,和/或,该第二终端设备可以基于该第一终端设备的安全策略信息选取安全策略。
在一些实施例中,该第一终端设备可以根据该第一随机数、该第一密钥、该第二随机数,以及源标识、目标标识、该第一随机数的长度、该第二随机数的长度、该源标识的长度、该目标标识的长度中的至少之一,生成该第二密钥。其中,该源标识用于标识该第一终端设备与该第二终端设备之间的中继连接的源端,该目标标识用于标识该第一终端设备与该第二终端设备之间的中继连接的目标端。另外,该第二密钥的输入参数还可以包括其他系统设定参数,如3GPP指定的一个或多个固定参数。
在一些实施例中,该第一消息为认证响应消息,该第二消息为安全模式命令(SMC)消息。
在一些实施例中,该第一消息为安全模式命令(SMC)消息,该第二消息为安全模式响应消息。
在一些实施例中,该第一终端设备通过该中继设备向该第二终端设备发送第三消息;
其中,该第三消息用于指示安全模式建立完成,该第三消息通过目标密钥进行加密,且该第三消息包括以下至少之一:该第二密钥的标识的该y个比特位,第四消息验证码;
其中,该目标密钥包括以下之一:该第一密钥,该第二密钥,该第二密钥派生的机密性保护密钥;
其中,该第三消息通过基于该第二密钥生成的该第四消息验证码进行完整性保护,或者,该第三消息通过基于该第二密钥派生的完整性保护密钥生成的该第四消息验证码进行完整性保护,该第四消息验证码的输入参数包括该y个比特位。
在一些实施例中,对于该第二终端设备,该第二终端设备通过该目标密钥对该第三消息进行解密;在该第三消息中携带的信息未遭受篡改的情况下,且该第四消息验证码有效的情况下,该第二终端设备将该x个比特位与该y个比特位合并得到该第二密钥的标识。具体的,该第二终端设备可以基于该y个比特位生成第四消息验证码,并与该第三消息中包含的该第四消息验证码进行比较,若比较一致的情况下,该第四消息验证码有效。
具体例如,该第三消息为安全模式结束消息(security mode complete)。
在一些实施例中,该第一终端设备接收该第二终端设备通过该中继设备发送的错误消息;其中,该错误消息包括以下至少之一:原因信息,第五消息验证码;其中,该原因信息用于指示该第二终端设备与该第一终端设备的安全策略冲突,或者,该原因信息用于指示该第一消息验证码验证失败,或者,该原因信息用于指示该第二终端设备与该第一终端设备的安全算法协商失败,该第五消息验证码的输入参数包括以下至少之一:该原因信息;
在该第五消息验证码有效的情况下,该第一终端设备确定安全模式建立失败,和/或,该第一终端设备重新发起安全模式建立流程。
在一些实施例中,该错误消息也可以受完整性保护。
具体例如,该原因信息用于指示该第二终端设备与该第一终端设备的安全策略冲突,例如,该第二终端设备不支持该第一消息中携带的该第一终端设备的安全策略信息。
具体例如,该原因信息用于指示该第二终端设备与该第一终端设备的安全算法协商失败,例如,该第二终端设备不支持该第一消息中携带的该第一终端设备的安全能力信息。
在一些实施例中,该第一终端设备接收该第二终端设备通过该中继设备发送的认证请求消息;
其中,该认证请求消息包括以下至少之一:该第二终端设备所属用户的信息,该中继设备所属用户的信息,该第二终端设备生成的第一临时公钥,该第二终端设备的签名,该中继设备的签名,该中继设备的相关信息;
其中,该第二终端设备所属用户的信息包括该第二终端设备的签名证书,或者,该第二终端设备所属用户的信息包括该第二终端设备的标识和该第二终端设备的PVT和KPAK;该中继设备所属用户的信息包括该中继设备的签名证书,或者,该中继设备所属用户的信息包括该中继设备的标识和该中继设备的PVT和KPAK;该第二终端设备的签名的输入参数包括以下至少之一:该第二终端设备所属用户的信息和该第一临时公钥;该中继设备的签名的输入参数包括以下至少之一:该第二终端设备的签名和该中继设备所属用户的信息;该第一临时公钥和该中继设备的相关信息用于该第一终端设备派生该第一密钥。
在本申请实施例中,该第二终端设备的签名的输入参数包括以下至少之一:该第二终端设备所属用户的信息和该第一临时公钥。也即,该第二终端设备可以基于该第二终端设备所属用户的信息和该第一临时公钥中的至少之一,生成该第二终端设备的签名。
在本申请实施例中,该中继设备的签名的输入参数包括以下至少之一:该第二终端设备的签名和该中继设备所属用户的信息。也即,该中继设备可以基于该第二终端设备的签名和该中继设备所属用户的信息中的至少之一,生成该中继设备的签名。
在一些实施例中,在该第二终端设备所属用户的信息包括该第二终端设备的签名证书的情况下,该第二终端设备的签名由该第二终端设备的签名私钥生成。可选地,该第二终端设备的签名证书和签名私钥可以是可信中心KMS通过安全通道为该第二终端设备预先配置的。该安全通道可以基于AKMA机制或者GBA机制来建立该第二终端设备与KMS的安全连接,该KMS可以直接由运营商来负责管理或者是与运营商有商业关系的第三方服务提供商。
在一些实施例中,在该第二终端设备所属用户的信息包括该第二终端设备的标识和该第二终端设备的PVT和KPAK的情况下,该第二终端设备的签名由该第二终端设备的秘密签名密钥(SSK)生成。可选地,该第二终端设备的PVT和KPAK、以及秘密签名密钥(SSK)可以是可信中心KMS通过安全通道为该第二终端设备预先配置的。该安全通道可以基于AKMA机制或者GBA机制来建立该第二终端设备与KMS的安全连接,该KMS可以直接由运营商来负责管理或者是与运营商有商业关系的第三方服务提供商。
在一些实施例中,在该中继设备所属用户的信息包括该中继设备的签名证书的情况下,该中继设备的签名由该中继设备的签名私钥生成。可选地,该中继设备的签名证书和签名私钥可以是可信中心KMS通过安全通道为该中继设备预先配置的。该安全通道可以基于AKMA机制或者GBA机制来建立该中继设备与KMS的安全连接,该KMS可以直接由运营商来负责管理或者是与运营商有商业关系的第三方服务提供商。
在一些实施例中,在该中继设备所属用户的信息包括该中继设备的标识、该中继设备的PVT和 KPAK的情况下,该中继设备的签名由该中继设备的秘密签名密钥(SSK)生成。可选地,该中继设备的PVT和KPAK、以及秘密签名密钥(SSK)可以是可信中心KMS通过安全通道为该中继设备预先配置的。该安全通道可以基于AKMA机制或者GBA机制来建立该中继设备与KMS的安全连接,该KMS可以直接由运营商来负责管理或者是与运营商有商业关系的第三方服务提供商。
在一些实施例中,在该第二终端设备的签名证书和该中继设备的签名证书有效,且基于该第二终端设备的签名证书对该第二终端设备的签名验证成功,以及基于该中继设备的签名证书对该中继设备的签名验证成功的情况下,该第一终端设备生成第二临时私钥,以及该第一终端设备根据该第一临时公钥、该中继设备的相关信息和该第二临时私钥派生该第一密钥。
具体的,该第一终端设备可以基于其本地存储的一个或多个签名证书,验证该第二终端设备的签名证书和该中继设备的签名证书的有效性。例如,在第一终端设备本地存储的签名证书中存在与第二终端设备的签名证书一致的签名证书的情况下,该第二终端设备的签名证书有效;以及在第一终端设备本地存储的签名证书中存在与中继设备的签名证书一致的签名证书的情况下,该中继设备的签名证书有效。可选地,该第一终端设备本地存储的一个或多个签名证书可以由KMS预配置。
在一些实施例中,在该第二终端设备的KPAK和该中继设备的KPAK有效,且基于该第二终端设备的标识和该第二终端设备的PVT对该第二终端设备的签名验证成功,以及基于该中继设备的标识和该中继设备的PVT对该中继设备的签名验证成功的情况下,该第一终端设备生成第二临时私钥,以及该第一终端设备根据该第一临时公钥、该中继设备的相关信息和该第二临时私钥派生该第一密钥。
具体的,该第一终端设备可以基于其本地存储的一个或多个KPAK,验证该第二终端设备的KPAK和该中继设备的KPAK的有效性。例如,在第一终端设备本地存储的KPAK中存在与第二终端设备的KPAK一致的KPAK的情况下,该第二终端设备的KPAK有效;以及在第一终端设备本地存储的KPAK中存在与中继设备的KPAK一致的KPAK的情况下,该中继设备的KPAK有效。可选地,该第一终端设备本地存储的一个或多个KPAK可以由KMS预配置。
具体的,在本申请实施例中,第一终端设备可以根据第二终端设备生成的第一临时公钥、中继设备的相关信息和第一终端设备生成的第二临时私钥派生第一密钥。相应的,第二终端设备可以根据第一终端设备生成的第二临时公钥、中继设备的相关信息和第二终端设备生成的第一临时私钥派生第一密钥。其中,第二终端设备生成的第一临时公钥与第二终端设备生成的第一临时私钥配对,第一终端设备生成的第二临时公钥与第一终端设备生成的第二临时私钥配对。
具体例如,第一终端设备可以根据第一临时公钥、中继设备的相关信息和第二临时私钥,并使用ECIES算法计算出第一密钥;第二终端设备可以根据第二临时公钥、中继设备的相关信息和第一临时私钥,并使用ECIES算法计算出第一密钥。
在一些实施例中,该第一终端设备通过该中继设备向该第二终端设备发送直接通信请求;其中,该直接通信请求包括以下至少之一:源标识,目标标识;其中,该源标识用于标识该第一终端设备与该第二终端设备之间的中继连接的源端,该目标标识用于标识该第一终端设备与该第二终端设备之间的中继连接的目标端。
在一些实施例中,当在该第一终端设备和该第二终端设备之间建立不同(Source ID、Destination ID)组之间的链接或者在更新该链接的第二密钥(K
D-SESS)时,该直接通信请求还可以包括该第一密钥的标识(K
D ID)。
具体例如,在该直接通信请求包括该第一密钥的标识(K
D ID)的情况下,该第二终端设备可以不发起认证流程,即不发送认证请求消息。
具体例如,在该直接通信请求不包括该第一密钥的标识(K
D ID)的情况下,或者,在该第二终端设备忽略该直接通信请求中包括的该第一密钥的标识(K
D ID)的情况下,该第一终端设备接收该第二终端设备通过该中继设备发送的认证请求消息。也即,在该第一消息不包括该第一密钥的标识的情况下,该第二终端设备发起认证流程,以获取该第一密钥。或者,在该第二终端设备忽略该第一消息中包括的该第一密钥的标识的情况下,该第二终端设备发起认证流程,以重新获取该第一密钥。
在一些实施例中,该第一密钥可以是K
D,该第一密钥的标识可以是K
D ID;该第二密钥可以是K
D-SESS,该第二密钥的标识可以是K
D-SESS ID。
在一些实施例中,该完整性保护密钥包括控制面的完整性保护密钥(K
D-CPint)和用户面的完整性保护密钥(K
D-UPint);和/或,该机密性保护密钥包括控制面的机密性保护密钥(K
D-CPenc)和用户面的机密性保护密钥(K
D-UPenc)。
在一些实施例中,该完整性保护密钥的输入参数包括以下至少之一:该第二密钥,选定的算法类型标识符,选定的算法类型标识符的长度,完整性保护算法标识,完整性保护算法标识的长度。也即, 可以基于该第二密钥、选定的算法类型标识符、选定的算法类型标识符的长度、完整性保护算法标识、完整性保护算法标识的长度中的至少之一,生成该完整性保护密钥。
可选地,该完整性保护密钥的输入参数还可以包括一些系统设定参数。在该第二密钥自动刷新时,该完整性保护密钥自动更新。
在一些实施例中,该机密性保护密钥的输入参数包括以下至少之一:该第二密钥,选定的算法类型标识符,选定的算法类型标识符的长度,机密性保护算法标识,机密性保护算法标识的长度。也即,可以基于该第二密钥、选定的算法类型标识符、选定的算法类型标识符的长度、机密性保护算法标识、机密性保护算法标识的长度中的至少之一,生成该机密性保护密钥。
可选地,该机密性保护密钥的输入参数还可以包括一些系统设定参数。在该第二密钥自动刷新时,该机密性保护密钥自动更新。
在一些实施例中,对于控制面的完整性保护密钥(K
D-CPint),选定的算法类型标识符可以通过“控制面完整性保护算法”或设置特定值来表示。
在一些实施例中,对于控制面的机密性保护密钥(K
D-CPenc),选定的算法类型标识符可以通过“控制面机密性保护算法”或设置特定值来表示。
在一些实施例中,对于用户面的完整性保护密钥(K
D-CPint),选定的算法类型标识符可以通过“用户面完整性保护算法”或设置特定值来表示。
在一些实施例中,对于用户面的机密性保护密钥(K
D-CPenc),选定的算法类型标识符可以通过“用户面机密性保护算法”或设置特定值来表示。
具体例如,本申请所涉及的密钥分层结构可以如图6所示。
在一些实施例中,本申请中的ECCSI仅为示例,并不局限于该算法,也可以使用其他基于身份的公钥签名和公钥加密算法来替换,在替换公钥算法的同时,所有请求消息中与公钥算法相关的参数需要作相应替换。
在一些实施例中,本申请中第一终端设备和第二终端设备使用的密钥派生函数不局限于HMAC-SHA-256或HMAC-SM3,包括任何一种满足计算安全的密钥派生函数。
在一些实施例中,本申请中密钥派生函数的输入参数不局限于上述提到的必要参数,可以含有其他可选参数,比如应用系统设置固定参数。
在一些实施例中,本申请中安全通信建立流程中所有交互消息中的信息元素并不局限于上述方案中提到的内容,也可以增加由于应用系统要求的可选信息元素。
因此,在本申请实施例中,第一随机数、第一密钥和第二终端设备生成的第二随机数用于派生第二密钥,第二密钥用于派生完整性保护密钥和/或机密性保护密钥,能够保证第一终端设备和第二终端设备的身份安全与通信数据的机密性与完整性,从而确保双方传输数据的机密性和完整性,防止其他设备甚至中继设备的窃听。
本申请实施例适用于5G层3(Layer-3,L3)UE-to-UE relay架构下第一终端设备(源设备)和第二终端设备(目标设备)之间的安全通信建立流程。在用户设备拥有相应公私钥的前提下,该安全通信建立流程无需网络侧认证和分发密钥流程,即可建立源设备和目标设备之间的安全连接。该安全通信建立流程借助公钥签名技术,能够确保用户设备的身份真实性和消息不可否认性,能够抗重放攻击、中间人攻击、伪装等多种主动攻击,同时保证认证流程消息的完整性,并且利用ECIES算法,从而建立仅在源设备和目标设备之间的安全环境,确保源设备和目标设备双方传输数据的机密性和完整性,从而防止外部敌手甚至中继设备的窃听;保证了安全通信建立机制的可扩展性,另外,该安全通信建立流程能够实现源设备和目标设备之间用户面和控制面安全策略、以及双方所支持加密和完整性保护算法的安全协商,能够实现完整性保护,抵抗篡改和降级攻击。
上文结合图10,详细描述了本申请的第一终端设备侧实施例,下文结合图11,详细描述本申请的第二终端设备侧实施例,应理解,第二终端设备侧实施例与第一终端设备侧实施例相互对应,类似的描述可以参照第一终端设备侧实施例。
图11是根据本申请实施例的中继通信的方法600的示意性流程图,如图11所示,该中继通信的方法600可以包括如下内容中的至少部分内容:
S610,第二终端设备接收第一终端设备通过中继设备发送的第一消息;其中,该第一消息包括以下至少之一:该第一终端设备的安全能力信息,该第一终端设备的安全策略信息,该第一终端设备所属用户的信息,该中继设备所属用户的信息,该第一终端设备生成的第一随机数,该第一终端设备生成的第二临时公钥,该第一终端设备生成的第一密钥的标识的M个比特位,该第一终端设备的签名,该中继设备的签名,第一消息验证码;其中,该第一终端设备所属用户的信息包括该第一终端设备的签名证书,或者,该第一终端设备所属用户的信息包括该第一终端设备的标识和该第一终端设备的 PVT和KPAK;该中继设备所属用户的信息包括该中继设备的签名证书,或者,该中继设备所属用户的信息包括该中继设备的标识和该中继设备的PVT和KPAK;该第一终端设备的签名的输入参数包括以下至少之一:该第一终端设备所属用户的信息,该第二临时公钥,该第一密钥的标识的M个比特位,该第二终端设备的签名;该中继设备的签名的输入参数包括以下至少之一:该中继设备所属用户的信息,该第一终端设备的签名,该第二终端设备的签名;其中,该第一消息通过基于该第一密钥生成的该第一消息验证码进行完整性保护,且该第一消息验证码的输入参数包括以下至少之一:该第一终端设备的安全能力信息,该第一终端设备的安全策略信息,该第一终端设备所属用户的信息,该第一随机数,该第二临时公钥,该M个比特位,该第一终端设备的签名;其中,该第二临时公钥和该中继设备的相关信息用于该第二终端设备派生该第一密钥,该第一随机数、该第一密钥和该第二终端设备生成的第二随机数用于派生第二密钥,该第二密钥用于派生完整性保护密钥和/或机密性保护密钥,该第一密钥的标识由该M个比特位与该第一密钥的标识的另外N个比特位合并得到,M和N均为正整数;其中,该中继设备的相关信息包括以下之一:该中继设备的身份信息,该中继设备生成的随机数,该中继设备生成的计数器。
本实施例基于ECCSI签名方案,建立L3架构下的UE-to-UE中继场景下的安全连接。具体的,本申请实施例应用于L3架构下的UE-to-UE中继场景,也即,第一终端设备与第二终端设备之间通过中继设备进行通信。例如,第一终端设备与第二终端设备之间的中继连接可以是PC5链路。
在本申请实施例中,第一终端设备生成的第一随机数、第一密钥和第二终端设备生成的第二随机数用于派生第二密钥。也即,第一终端设备至少根据第一随机数、第一密钥和第二随机数派生第二密钥,以及第一终端设备可以基于第二密钥派生完整性保护密钥和/或机密性保护密钥,从而第一终端设备可以基于完整性保护密钥和/或机密性保护密钥对发送的消息进行安全保护。同理,第二终端设备至少根据第一随机数、第一密钥和第二随机数派生第二密钥,以及第二终端设备可以基于第二密钥派生完整性保护密钥和/或机密性保护密钥,从而第二终端设备可以基于完整性保护密钥和/或机密性保护密钥对发送的消息进行安全保护。
在本申请实施例中,该第一消息验证码的输入参数包括以下至少之一:该第一终端设备的安全能力信息,该第一终端设备的安全策略信息,该第一随机数,该第二临时公钥,该M个比特位。也即,该第一终端设备可以基于该第一终端设备的安全能力信息、该第一终端设备的安全策略信息、该第一随机数、该第二临时公钥、该M个比特位中的至少之一,生成该第一消息验证码。
在一些实施例中,在该第一终端设备所属用户的信息包括该第一终端设备的签名证书的情况下,该第一终端设备的签名由该第一终端设备的签名私钥生成,或者,在该第一终端设备所属用户的信息包括该第一终端设备的标识和该第一终端设备的PVT和KPAK的情况下,该第一终端设备的签名由该第一终端设备的秘密签名密钥生成;和/或,在该中继设备所属用户的信息包括该中继设备的签名证书的情况下,该中继设备的签名由该中继设备的签名私钥生成,或者,在该中继设备所属用户的信息包括该中继设备的标识和该中继设备的PVT和KPAK的情况下,该中继设备的签名由该中继设备的秘密签名密钥生成。
在一些实施例中,该第一消息为认证响应消息,或者,该第一消息为安全模式命令消息。
在一些实施例中,该第一终端设备的安全能力信息可以是该第一终端设备支持的密码算法列表。
在一些实施例中,该第一终端设备的安全策略信息可以是该第一终端设备是否支持机密性保护或完整性保护。其中,该第一终端设备的安全策略信息包括:该第一终端设备在控制面的安全策略信息,和/或,该第一终端设备在用户面的安全策略信息。
在一些实施例中,该M个比特位可以是该第一密钥的标识的最高M个比特位,该N个比特位可以是该第一密钥的标识的最低N个比特位;或者,该M个比特位可以是该第一密钥的标识的前M个比特位,该N个比特位可以是该第一密钥的标识的后N个比特位;或者,该M个比特位可以是该第一密钥的标识的偶数位的比特位,该N个比特位可以是该第一密钥的标识的奇数位的比特位。
在一些实施例中,M与N的取值可以相同,也可以不同,本申请对此并不限定。
在一些实施例中,该第二终端设备分别检查该第一终端设备的签名证书和该中继设备的签名证书,在该第一终端设备的签名证书和该中继设备的签名证书有效的情况下,该第二终端设备基于该第一终端设备的签名证书对该第一终端设备的签名进行验证,以及该第二终端设备基于该中继设备的签名证书对该中继设备的签名进行验证;或者,该第二终端设备分别检查该第一终端设备的KPAK和该中继设备的KPAK,在该第一终端设备的KPAK和该中继设备的KPAK有效的情况下,且基于该第一终端设备的标识和该第一终端设备的PVT对该第一终端设备的签名进行验证,以及基于该中继设备的标识和该中继设备的PVT对该中继设备的签名进行验证;在该第一终端设备的签名和该中继设备的签名验证成功,且该第一消息中携带的信息未遭受篡改的情况下,该第二终端设备生成第二随机数, 该第二终端设备至少根据该第一随机数、该第一密钥和该第二随机数生成该第二密钥,该第二终端设备根据该第二密钥生成完整性保护密钥和/或机密性保护密钥,以及该第二终端设备生成该第一密钥的标识的N个比特位,并将该M个比特位和该N个比特位合并得到该第一密钥的标识。
在一些实施例中,该第二终端设备可以根据该第一随机数、该第一密钥、该第二随机数,以及源标识、目标标识、该第一随机数的长度、该第二随机数的长度、该源标识的长度、该目标标识的长度中的至少之一,生成该第二密钥。其中,该源标识用于标识该第一终端设备与该第二终端设备之间的中继连接的源端,该目标标识用于标识该第一终端设备与该第二终端设备之间的中继连接的目标端。另外,该第二密钥的输入参数还可以包括其他系统设定参数,如3GPP指定的一个或多个固定参数。
具体例如,假设该第一消息验证码的输入参数包括:该第一终端设备的安全能力信息、该第一终端设备的安全策略信息、该第一随机数、该第二临时公钥、该M个比特位。该第二终端设备可以基于该第一终端设备的安全能力信息、该第一终端设备的安全策略信息、该第一随机数、该第二临时公钥、该M个比特位生成第一消息验证码,并与该第一消息中包含的该第一消息验证码进行比较,若比较一致的情况下,该第一消息验证码有效。
在一些实施例中,在该第一消息验证码有效的情况下,该第二终端设备通过该中继设备向该第一终端设备发送第二消息;其中,该第二消息包括以下至少之一:该第二随机数,该N个比特位,该第二终端设备生成的该第二密钥的标识的x个比特位,该第二终端设备选取的安全算法,该第二终端设备选取的安全策略,第二消息验证码;
其中,该第二消息通过基于该第二密钥生成的该第二消息验证码进行完整性保护,或者,该第二消息通过基于该第二密钥派生的完整性保护密钥生成的该第二消息验证码进行完整性保护,且该第二消息验证码的输入参数包括以下至少之一:该第二随机数,该N个比特位,该x个比特位,该第二终端设备选取的安全算法,该第二终端设备选取的安全策略;
其中,该第二密钥的标识由该x个比特位与该第二密钥的标识的另外y个比特位合并得到,x和y均为正整数。
具体例如,假设该第二消息验证码的输入参数包括:该第二随机数、该N个比特位、该x个比特位、该第二终端设备选取的安全算法、该第二终端设备选取的安全策略。该第一终端设备可以基于该第二随机数、该N个比特位、该x个比特位、该第二终端设备选取的安全算法、该第二终端设备选取的安全策略生成第二消息验证码,并与该第二消息中包含的该第二消息验证码进行比较,若比较一致的情况下,该第二消息验证码有效。
在一些实施例中,该x个比特位可以是该第二密钥的标识的最高x个比特位,该y个比特位可以是该第二密钥的标识的最低y个比特位;或者,该x个比特位可以是该第二密钥的标识的前x个比特位,该y个比特位可以是该第二密钥的标识的后y个比特位;或者,该x个比特位可以是该第二密钥的标识的偶数位的比特位,该y个比特位可以是该第二密钥的标识的奇数位的比特位。
在一些实施例中,x与y的取值可以相同,也可以不同,本申请对此并不限定。
在一些实施例中,该第二消息通过该第一密钥进行加密,且该第二消息还包括第三消息验证码;
其中,该第二消息通过基于该第一密钥生成的该第三消息验证码进行完整性保护,且该第三消息验证码的输入参数包括以下至少之一:该第二随机数,该N个比特位,该x个比特位,该第二终端设备选取的安全算法,该第二终端设备选取的安全策略。
在一些实施例中,该第二消息也可以不通过该第一密钥进行加密,或者,该第二消息可以不加密。
具体例如,假设该第三消息验证码的输入参数包括:该第二随机数、该N个比特位、该x个比特位、该第二终端设备选取的安全算法、该第二终端设备选取的安全策略。该第一终端设备可以基于该第二随机数、该N个比特位、该x个比特位、该第二终端设备选取的安全算法、该第二终端设备选取的安全策略生成第三消息验证码,并与该第二消息中包含的该第三消息验证码进行比较,若比较一致的情况下,该第三消息验证码有效。
具体的,该第二终端设备可以基于该第一终端设备的安全能力信息选取安全算法,和/或,该第二终端设备可以基于该第一终端设备的安全策略信息选取安全策略。
在一些实施例中,该第一消息为认证响应消息,该第二消息为安全模式命令(SMC)消息。
在一些实施例中,该第一消息为安全模式命令(SMC)消息,该第二消息为安全模式响应消息。
具体的,在本申请实施例中,第一终端设备可以根据第二终端设备生成的第一临时公钥、中继设备的相关信息和第一终端设备生成的第二临时私钥派生第一密钥。相应的,第二终端设备可以根据第一终端设备生成的第二临时公钥、中继设备的相关信息和第二终端设备生成的第一临时私钥派生第一密钥。其中,第二终端设备生成的第一临时公钥与第二终端设备生成的第一临时私钥配对,第一终端设备生成的第二临时公钥与第一终端设备生成的第二临时私钥配对。
具体例如,第一终端设备可以根据第一临时公钥、中继设备的相关信息和第二临时私钥,并使用ECIES算法计算出第一密钥;第二终端设备可以根据第二临时公钥、中继设备的相关信息和第一临时私钥,并使用ECIES算法计算出第一密钥。
在一些实施例中,该第二终端设备接收该第一终端设备通过该中继设备发送的第三消息;
其中,该第三消息用于指示安全模式建立完成,该第三消息通过目标密钥进行加密,且该第三消息包括以下至少之一:该第一终端设备生成的该第二密钥的标识的y个比特位,第四消息验证码;
其中,该目标密钥包括以下之一:该第一密钥,该第二密钥,该第二密钥派生的机密性保护密钥;
其中,该第三消息通过基于该第二密钥生成的该第四消息验证码进行完整性保护,或者,该第三消息通过基于该第二密钥派生的完整性保护密钥生成的该第四消息验证码进行完整性保护,该第四消息验证码的输入参数包括该y个比特位。
在一些实施例中,该第二终端设备通过该目标密钥对该第三消息进行解密;
在该第三消息中携带的信息未遭受篡改的情况下,且该第四消息验证码有效的情况下,该第二终端设备将该x个比特位与该y个比特位合并得到该第二密钥的标识。
具体的,该第二终端设备可以基于该y个比特位生成第四消息验证码,并与该第三消息中包含的该第四消息验证码进行比较,若比较一致的情况下,该第四消息验证码有效。
具体例如,该第三消息为安全模式结束消息(security mode complete)。
在一些实施例中,该第二终端设备通过该中继设备向该第一终端设备发送错误消息;其中,该错误消息包括以下至少之一:原因信息,第五消息验证码;其中,该原因信息用于指示该第二终端设备与该第一终端设备的安全策略冲突,或者,该原因信息用于指示该第一消息验证码验证失败,或者,该原因信息用于指示该第二终端设备与该第一终端设备的安全算法协商失败,该第五消息验证码的输入参数包括以下至少之一:该原因信息。
具体的,对于该第一终端设备,在该第五消息验证码有效的情况下,该第一终端设备确定安全模式建立失败,和/或,该第一终端设备重新发起安全模式建立流程。
在一些实施例中,该错误消息也可以受完整性保护。
具体例如,该原因信息用于指示该第二终端设备与该第一终端设备的安全策略冲突,例如,该第二终端设备不支持该第一消息中携带的该第一终端设备的安全策略信息。
具体例如,该原因信息用于指示该第二终端设备与该第一终端设备的安全算法协商失败,例如,该第二终端设备不支持该第一消息中携带的该第一终端设备的安全能力信息。
在一些实施例中,该第二终端设备通过该中继设备向该第一终端设备发送认证请求消息;
其中,该认证请求消息包括以下至少之一:该第二终端设备所属用户的信息,该第二终端设备生成的第一临时公钥,该第二终端设备的签名,该中继设备的相关信息;
其中,该第二终端设备所属用户的信息包括该第二终端设备的签名证书,或者,该第二终端设备所属用户的信息包括该第二终端设备的标识和该第二终端设备的PVT和KPAK;该第二终端设备的签名的输入参数包括以下至少之一:该第二终端设备所属用户的信息和该第一临时公钥;该第一临时公钥和该中继设备的相关信息用于该第一终端设备派生第一密钥。
在本申请实施例中,该第二终端设备的签名的输入参数包括以下至少之一:该第二终端设备所属用户的信息和该第一临时公钥。也即,该第二终端设备可以基于该第二终端设备所属用户的信息和该第一临时公钥中的至少之一,生成该第二终端设备的签名。
在本申请实施例中,该中继设备的签名的输入参数包括以下至少之一:该第二终端设备的签名和该中继设备所属用户的信息。也即,该中继设备可以基于该第二终端设备的签名和该中继设备所属用户的信息中的至少之一,生成该中继设备的签名。
在一些实施例中,在该第二终端设备所属用户的信息包括该第二终端设备的签名证书的情况下,该第二终端设备的签名由该第二终端设备的签名私钥生成。可选地,该第二终端设备的签名证书和签名私钥可以是可信中心密钥管理服务器(KMS)通过安全通道为该第二终端设备预先配置的。该安全通道可以基于应用程序的身份验证和密钥管理(AKMA)机制或者通用引导架构(GBA)机制来建立该第二终端设备与KMS的安全连接,该KMS可以直接由运营商来负责管理或者是与运营商有商业关系的第三方服务提供商。
在一些实施例中,在该第二终端设备所属用户的信息包括该第二终端设备的标识和该第二终端设备的PVT和KPAK的情况下,该第二终端设备的签名由该第二终端设备的秘密签名密钥(SSK)生成。可选地,该第二终端设备的PVT和KPAK、以及秘密签名密钥(SSK)可以是可信中心KMS通过安全通道为该第二终端设备预先配置的。该安全通道可以基于AKMA机制或者GBA机制来建立该第二终端设备与KMS的安全连接,该KMS可以直接由运营商来负责管理或者是与运营商有商业关 系的第三方服务提供商。
在一些实施例中,该第二终端设备接收该第一终端设备通过该中继设备发送的直接通信请求;其中,该直接通信请求包括以下至少之一:源标识,目标标识;其中,该源标识用于标识该第一终端设备与该第二终端设备之间的中继连接的源端,该目标标识用于标识该第一终端设备与该第二终端设备之间的中继连接的目标端。
在一些实施例中,当在该第一终端设备和该第二终端设备之间建立不同(Source ID、Destination ID)组之间的链接或者在更新该链接的第二密钥(K
D-SESS)时,该直接通信请求还可以包括该第一密钥的标识(K
D ID)。
具体例如,在该直接通信请求包括该第一密钥的标识(K
D ID)的情况下,该第二终端设备可以不发起认证流程,即不发送认证请求消息。
具体例如,在该直接通信请求不包括该第一密钥的标识(K
D ID)的情况下,或者,在该第二终端设备忽略该直接通信请求中包括的该第一密钥的标识(K
D ID)的情况下,该第一终端设备接收该第二终端设备通过该中继设备发送的认证请求消息。也即,在该第一消息不包括该第一密钥的标识的情况下,该第二终端设备发起认证流程,以获取该第一密钥。或者,在该第二终端设备忽略该第一消息中包括的该第一密钥的标识的情况下,该第二终端设备发起认证流程,以重新获取该第一密钥。
在一些实施例中,该第一密钥可以是K
D,该第一密钥的标识可以是K
D ID;该第二密钥可以是K
D-SESS,该第二密钥的标识可以是K
D-SESS ID。
在一些实施例中,该完整性保护密钥包括控制面的完整性保护密钥(K
D-CPint)和用户面的完整性保护密钥(K
D-UPint);和/或,该机密性保护密钥包括控制面的机密性保护密钥(K
D-CPenc)和用户面的机密性保护密钥(K
D-UPenc)。
在一些实施例中,该完整性保护密钥的输入参数包括以下至少之一:该第二密钥,选定的算法类型标识符,选定的算法类型标识符的长度,完整性保护算法标识,完整性保护算法标识的长度。也即,可以基于该第二密钥、选定的算法类型标识符、选定的算法类型标识符的长度、完整性保护算法标识、完整性保护算法标识的长度中的至少之一,生成该完整性保护密钥。
可选地,该完整性保护密钥的输入参数还可以包括一些系统设定参数。在该第二密钥自动刷新时,该完整性保护密钥自动更新。
在一些实施例中,该机密性保护密钥的输入参数包括以下至少之一:该第二密钥,选定的算法类型标识符,选定的算法类型标识符的长度,机密性保护算法标识,机密性保护算法标识的长度。也即,可以基于该第二密钥、选定的算法类型标识符、选定的算法类型标识符的长度、机密性保护算法标识、机密性保护算法标识的长度中的至少之一,生成该机密性保护密钥。
可选地,该机密性保护密钥的输入参数还可以包括一些系统设定参数。在该第二密钥自动刷新时,该机密性保护密钥自动更新。
因此,在本申请实施例中,第一随机数、第一密钥和第二终端设备生成的第二随机数用于派生第二密钥,第二密钥用于派生完整性保护密钥和/或机密性保护密钥,能够保证第一终端设备和第二终端设备的身份安全与通信数据的机密性与完整性,从而确保双方传输数据的机密性和完整性,防止其他设备甚至中继设备的窃听。
本申请实施例适用于5G层3(Layer-3,L3)UE-to-UE relay架构下第一终端设备(源设备)和第二终端设备(目标设备)之间的安全通信建立流程。在用户设备拥有相应公私钥的前提下,该安全通信建立流程无需网络侧认证和分发密钥流程,即可建立源设备和目标设备之间的安全连接。该安全通信建立流程借助公钥签名技术,能够确保用户设备的身份真实性和消息不可否认性,能够抗重放攻击、中间人攻击、伪装等多种主动攻击,同时保证认证流程消息的完整性,并且利用ECIES算法,从而建立仅在源设备和目标设备之间的安全环境,确保源设备和目标设备双方传输数据的机密性和完整性,从而防止外部敌手甚至中继设备的窃听;保证了安全通信建立机制的可扩展性,另外,该安全通信建立流程能够实现源设备和目标设备之间用户面和控制面安全策略、以及双方所支持加密和完整性保护算法的安全协商,能够实现完整性保护,抵抗篡改和降级攻击。
上文结合图10至图11,详细描述了本申请的第一终端设备侧实施例和第二终端设备侧实施例,下文结合图12,详细描述本申请的中继设备侧实施例,应理解,中继设备侧实施例与第一终端设备侧实施例和第二终端设备侧实施例相互对应,类似的描述可以参照第一终端设备侧实施例和第二终端设备侧实施例。
图12是根据本申请实施例的中继通信的方法700的示意性流程图,如图12所示,该中继通信的方法700可以包括如下内容中的至少部分内容:
S710,中继设备接收第一终端设备发送的第一消息;其中,该第一消息包括以下至少之一:该第 一终端设备的安全能力信息,该第一终端设备的安全策略信息,该第一终端设备所属用户的信息,该第一终端设备生成的第一随机数,该第一终端设备生成的第二临时公钥,该第一终端设备生成的第一密钥的标识的M个比特位,该第一终端设备的签名,第一消息验证码;其中,该第一终端设备所属用户的信息包括该第一终端设备的签名证书,或者,该第一终端设备所属用户的信息包括该第一终端设备的标识和该第一终端设备的PVT和KPAK;该第一终端设备的签名的输入参数包括以下至少之一:该第一终端设备所属用户的信息,该第二临时公钥,该第一密钥的标识的M个比特位,该第二终端设备的签名;其中,该第一消息通过基于该第一密钥生成的该第一消息验证码进行完整性保护,且该第一消息验证码的输入参数包括以下至少之一:该第一终端设备的安全能力信息,该第一终端设备的安全策略信息,该第一终端设备所属用户的信息,该第一随机数,该第二临时公钥,该M个比特位,该第一终端设备的签名;
S720,在该第一终端设备的签名证书有效,且基于该第一终端设备的签名证书对该第一终端设备的签名验证成功的情况下,或者,在该第一终端设备的KPAK有效,且基于该第一终端设备的标识和该第一终端设备的PVT对该第一终端设备的签名验证成功的情况下,该中继设备向该第二终端设备发送验证之后的第一消息;其中,该验证之后的第一消息包括以下至少之一:该第一终端设备的安全能力信息,该第一终端设备的安全策略信息,该第一终端设备所属用户的信息,该中继设备所属用户的信息,该第一终端设备生成的第一随机数,该第一终端设备生成的与该第二临时私钥配对的第二临时公钥,该第一终端设备生成的该第一密钥的标识的M个比特位,该第一终端设备的签名,该中继设备的签名,该中继设备的相关信息,该第一消息验证码;其中,该中继设备所属用户的信息包括该中继设备的签名证书,或者,该中继设备所属用户的信息包括该中继设备的标识和该中继设备的PVT和KPAK;该中继设备的签名的输入参数包括以下至少之一:该中继设备所属用户的信息,该第一终端设备的签名,该第二终端设备的签名,该验证之后的第一消息;其中,该第二临时公钥和该中继设备的相关信息用于该第二终端设备派生该第一密钥,该第一随机数、该第一密钥和该第二终端设备生成的第二随机数用于派生第二密钥,该第二密钥用于派生完整性保护密钥和/或机密性保护密钥,该第一密钥的标识由该M个比特位与该第一密钥的标识的另外N个比特位合并得到,M和N均为正整数;该中继设备的相关信息包括以下之一:该中继设备的身份信息,该中继设备生成的随机数,该中继设备生成的计数器。
本实施例基于ECCSI签名方案,建立L3架构下的UE-to-UE中继场景下的安全连接。具体的,本申请实施例应用于L3架构下的UE-to-UE中继场景,也即,第一终端设备与第二终端设备之间通过中继设备进行通信。例如,第一终端设备与第二终端设备之间的中继连接可以是PC5链路。
在本申请实施例中,第一终端设备生成的第一随机数、第一密钥和第二终端设备生成的第二随机数用于派生第二密钥。也即,第一终端设备至少根据第一随机数、第一密钥和第二随机数派生第二密钥,以及第一终端设备可以基于第二密钥派生完整性保护密钥和/或机密性保护密钥,从而第一终端设备可以基于完整性保护密钥和/或机密性保护密钥对发送的消息进行安全保护。同理,第二终端设备至少根据第一随机数、第一密钥和第二随机数派生第二密钥,以及第二终端设备可以基于第二密钥派生完整性保护密钥和/或机密性保护密钥,从而第二终端设备可以基于完整性保护密钥和/或机密性保护密钥对发送的消息进行安全保护。
在本申请实施例中,该第一消息验证码的输入参数包括以下至少之一:该第一终端设备的安全能力信息,该第一终端设备的安全策略信息,该第一随机数,该第二临时公钥,该M个比特位。也即,该第一终端设备可以基于该第一终端设备的安全能力信息、该第一终端设备的安全策略信息、该第一随机数、该第二临时公钥、该M个比特位中的至少之一,生成该第一消息验证码。
具体例如,假设该第一消息验证码的输入参数包括:该第一终端设备的安全能力信息、该第一终端设备的安全策略信息、该第一随机数、该第二临时公钥、该M个比特位。该第二终端设备可以基于该第一终端设备的安全能力信息、该第一终端设备的安全策略信息、该第一随机数、该第二临时公钥、该M个比特位生成第一消息验证码,并与该第一消息中包含的该第一消息验证码进行比较,若比较一致的情况下,该第一消息验证码有效。
在一些实施例中,该第一消息为认证响应消息,或者,该第一消息为安全模式命令消息。
在一些实施例中,该第一终端设备的安全能力信息可以是该第一终端设备支持的密码算法列表。
在一些实施例中,该第一终端设备的安全策略信息可以是该第一终端设备是否支持机密性保护或完整性保护。其中,该第一终端设备的安全策略信息包括:该第一终端设备在控制面的安全策略信息,和/或,该第一终端设备在用户面的安全策略信息。
在一些实施例中,该M个比特位可以是该第一密钥的标识的最高M个比特位,该N个比特位可以是该第一密钥的标识的最低N个比特位;或者,该M个比特位可以是该第一密钥的标识的前M个 比特位,该N个比特位可以是该第一密钥的标识的后N个比特位;或者,该M个比特位可以是该第一密钥的标识的偶数位的比特位,该N个比特位可以是该第一密钥的标识的奇数位的比特位。
在一些实施例中,M与N的取值可以相同,也可以不同,本申请对此并不限定。
在一些实施例中,该中继设备将该第二终端设备发送的第二消息转发至该第一终端设备;
其中,该第二消息包括以下至少之一:该第二终端设备生成的该第二随机数,该第二终端设备生成的该第一密钥的标识的N个比特位,该第二终端设备生成的该第二密钥的标识的x个比特位,该第二终端设备选取的安全算法,该第二终端设备选取的安全策略,第二消息验证码;
其中,该第二消息通过基于该第二密钥生成的该第二消息验证码进行完整性保护,或者,该第二消息通过基于该第二密钥派生的完整性保护密钥生成的该第二消息验证码进行完整性保护,且该第二消息验证码的输入参数包括以下至少之一:该第二随机数,该N个比特位,该x个比特位,该第二终端设备选取的安全算法,该第二终端设备选取的安全策略;
其中,该第二密钥的标识由该x个比特位与该第二密钥的标识的另外y个比特位合并得到,x和y均为正整数。
在一些实施例中,该x个比特位可以是该第二密钥的标识的最高x个比特位,该y个比特位可以是该第二密钥的标识的最低y个比特位;或者,该x个比特位可以是该第二密钥的标识的前x个比特位,该y个比特位可以是该第二密钥的标识的后y个比特位;或者,该x个比特位可以是该第二密钥的标识的偶数位的比特位,该y个比特位可以是该第二密钥的标识的奇数位的比特位。
在一些实施例中,x与y的取值可以相同,也可以不同,本申请对此并不限定。
具体例如,假设该第二消息验证码的输入参数包括:该第二随机数、该N个比特位、该x个比特位、该第二终端设备选取的安全算法、该第二终端设备选取的安全策略。该第一终端设备可以基于该第二随机数、该N个比特位、该x个比特位、该第二终端设备选取的安全算法、该第二终端设备选取的安全策略生成第二消息验证码,并与该第二消息中包含的该第二消息验证码进行比较,若比较一致的情况下,该第二消息验证码有效。
在一些实施例中,该第二消息通过该第一密钥进行加密,且该第二消息还包括第三消息验证码;
其中,该第二消息通过基于该第一密钥生成的该第三消息验证码进行完整性保护,且该第三消息验证码的输入参数包括以下至少之一:该第二随机数,该N个比特位,该x个比特位,该第二终端设备选取的安全算法,该第二终端设备选取的安全策略。
在一些实施例中,该第二消息也可以不通过该第一密钥进行加密,或者,该第二消息可以不加密。
具体例如,假设该第三消息验证码的输入参数包括:该第二随机数、该N个比特位、该x个比特位、该第二终端设备选取的安全算法、该第二终端设备选取的安全策略。该第一终端设备可以基于该第二随机数、该N个比特位、该x个比特位、该第二终端设备选取的安全算法、该第二终端设备选取的安全策略生成第三消息验证码,并与该第二消息中包含的该第三消息验证码进行比较,若比较一致的情况下,该第三消息验证码有效。
具体的,该第二终端设备可以基于该第一终端设备的安全能力信息选取安全算法,和/或,该第二终端设备可以基于该第一终端设备的安全策略信息选取安全策略。
在一些实施例中,该第一终端设备可以根据该第一随机数、该第一密钥、该第二随机数,以及源标识、目标标识、该第一随机数的长度、该第二随机数的长度、该源标识的长度、该目标标识的长度中的至少之一,生成该第二密钥。以及该第二终端设备可以根据该第一随机数、该第一密钥、该第二随机数,以及源标识、目标标识、该第一随机数的长度、该第二随机数的长度、该源标识的长度、该目标标识的长度中的至少之一,生成该第二密钥。
其中,该源标识用于标识该第一终端设备与该第二终端设备之间的中继连接的源端,该目标标识用于标识该第一终端设备与该第二终端设备之间的中继连接的目标端。另外,该第二密钥的输入参数还可以包括其他系统设定参数,如3GPP指定的一个或多个固定参数。
在一些实施例中,该第一消息为认证响应消息,该第二消息为安全模式命令(Secure Mode Command,SMC)消息。
在一些实施例中,该第一消息为安全模式命令(Secure Mode Command,SMC)消息,该第二消息为安全模式响应消息。
在一些实施例中,该中继设备将该第一终端设备发送的第三消息转发至该第二终端设备;
其中,该第三消息用于指示安全模式建立完成,该第三消息通过目标密钥进行加密,且该第三消息包括以下至少之一:该第一终端设备生成的该第二密钥的标识的y个比特位,第四消息验证码;
其中,该目标密钥包括以下之一:该第一密钥,该第二密钥,该第二密钥派生的机密性保护密钥;
其中,该第三消息通过基于该第二密钥生成的该第四消息验证码进行完整性保护,或者,该第三 消息通过基于该第二密钥派生的完整性保护密钥生成的该第四消息验证码进行完整性保护,该第四消息验证码的输入参数包括该y个比特位。
在一些实施例中,对于该第二终端设备,该第二终端设备通过该目标密钥对该第三消息进行解密;在该第三消息中携带的信息未遭受篡改的情况下,且该第四消息验证码有效的情况下,该第二终端设备将该x个比特位与该y个比特位合并得到该第二密钥的标识。
具体的,该第二终端设备可以基于该y个比特位生成第四消息验证码,并与该第三消息中包含的该第四消息验证码进行比较,若比较一致的情况下,该第四消息验证码有效。
具体例如,该第三消息为安全模式结束消息(security mode complete)。
在一些实施例中,该中继设备将该第二终端设备发送的错误消息转发至该第一终端设备;其中,该错误消息包括以下至少之一:原因信息,第五消息验证码;其中,该原因信息用于指示该第二终端设备与该第一终端设备的安全策略冲突,或者,该原因信息用于指示该第一消息验证码验证失败,或者,该原因信息用于指示该第二终端设备与该第一终端设备的安全算法协商失败,该第五消息验证码的输入参数包括以下至少之一:该原因信息。
具体的,在该第五消息验证码有效的情况下,该第一终端设备确定安全模式建立失败,和/或,该第一终端设备重新发起安全模式建立流程。
在一些实施例中,该错误消息也可以受完整性保护。
具体例如,该原因信息用于指示该第二终端设备与该第一终端设备的安全策略冲突,例如,该第二终端设备不支持该第一消息中携带的该第一终端设备的安全策略信息。
具体例如,该原因信息用于指示该第二终端设备与该第一终端设备的安全算法协商失败,例如,该第二终端设备不支持该第一消息中携带的该第一终端设备的安全能力信息。
在一些实施例中,该中继设备接收该第二终端设备发送的认证请求消息;其中,该认证请求消息包括以下至少之一:该第二终端设备所属用户的信息,该第二终端设备生成的第一临时公钥,该第二终端设备的签名;其中,该第二终端设备所属用户的信息包括该第二终端设备的签名证书,或者,该第二终端设备所属用户的信息包括该第二终端设备的标识和该第二终端设备的PVT和KPAK;该第二终端设备的签名的输入参数包括以下至少之一:该第二终端设备所属用户的信息和该第一临时公钥;该第一临时公钥和该中继设备的相关信息用于该第一终端设备派生该第一密钥;
在该第二终端设备的签名证书有效,且基于该第二终端设备的签名证书对该第二终端设备的签名验证成功的情况下,或者,在该第二终端设备的KPAK有效,且基于该第二终端设备的标识和该第二终端设备的PVT对该第二终端设备的签名验证成功的情况下,该中继设备向该第一终端设备发送验证之后的认证请求消息;其中,该验证之后的认证请求消息包括以下至少之一:该第二终端设备所属用户的信息,该中继设备所属用户的信息,该第一临时公钥,该第二终端设备的签名,该中继设备的签名,该中继设备的相关信息;其中,该中继设备所属用户的信息包括该中继设备的签名证书,或者,该中继设备所属用户的信息包括该中继设备的标识和该中继设备的PVT和KPAK;该中继设备的签名的输入参数包括以下至少之一:该第二终端设备的签名和该中继设备所属用户的信息。
在本申请实施例中,该第二终端设备的签名的输入参数包括以下至少之一:该第二终端设备所属用户的信息和该第一临时公钥。也即,该第二终端设备可以基于该第二终端设备所属用户的信息和该第一临时公钥中的至少之一,生成该第二终端设备的签名。
在本申请实施例中,该中继设备的签名的输入参数包括以下至少之一:该第二终端设备的签名和该中继设备所属用户的信息。也即,该中继设备可以基于该第二终端设备的签名和该中继设备所属用户的信息中的至少之一,生成该中继设备的签名。
具体的,该中继设备可以基于其本地存储的一个或多个签名证书,验证该第二终端设备的签名证书的有效性。例如,在中继设备本地存储的签名证书中存在与第二终端设备的签名证书一致的签名证书的情况下,该第二终端设备的签名证书有效。可选地,该中继设备本地存储的一个或多个签名证书可以由KMS预配置。
具体的,该中继设备可以基于其本地存储的一个或多个KPAK,验证该第二终端设备的KPAK的有效性。例如,在中继设备本地存储的KPAK中存在与第二终端设备的KPAK一致的KPAK的情况下,该第二终端设备的KPAK有效。可选地,该第一终端设备本地存储的一个或多个KPAK可以由KMS预配置。
在本申请实施例中,第一终端设备可以根据第二终端设备生成的第一临时公钥、中继设备的相关信息和第一终端设备生成的第二临时私钥派生第一密钥。相应的,第二终端设备可以根据第一终端设备生成的第二临时公钥、中继设备的相关信息和第二终端设备生成的第一临时私钥派生第一密钥。其中,第二终端设备生成的第一临时公钥与第二终端设备生成的第一临时私钥配对,第一终端设备生成 的第二临时公钥与第一终端设备生成的第二临时私钥配对。
具体例如,第一终端设备可以根据第一临时公钥、中继设备的相关信息和第二临时私钥,并使用ECIES算法计算出第一密钥;第二终端设备可以根据第二临时公钥、中继设备的相关信息和第一临时私钥,并使用ECIES算法计算出第一密钥。
在一些实施例中,在该第二终端设备所属用户的信息包括该第二终端设备的签名证书的情况下,该第二终端设备的签名由该第二终端设备的签名私钥生成。可选地,该第二终端设备的签名证书和签名私钥可以是可信中心密钥管理服务器(KMS)通过安全通道为该第二终端设备预先配置的。该安全通道可以基于应用程序的身份验证和密钥管理(AKMA)机制或者通用引导架构(GBA)机制来建立该第二终端设备与KMS的安全连接,该KMS可以直接由运营商来负责管理或者是与运营商有商业关系的第三方服务提供商。
在一些实施例中,在该第二终端设备所属用户的信息包括该第二终端设备的标识和该第二终端设备的PVT和KPAK的情况下,该第二终端设备的签名由该第二终端设备的秘密签名密钥(SSK)生成。可选地,该第二终端设备的PVT和KPAK、以及秘密签名密钥(SSK)可以是可信中心KMS通过安全通道为该第二终端设备预先配置的。该安全通道可以基于AKMA机制或者GBA机制来建立该第二终端设备与KMS的安全连接,该KMS可以直接由运营商来负责管理或者是与运营商有商业关系的第三方服务提供商。
在一些实施例中,在该中继设备所属用户的信息包括该中继设备的签名证书的情况下,该中继设备的签名由该中继设备的签名私钥生成。可选地,该中继设备的签名证书和签名私钥可以是可信中心KMS通过安全通道为该中继设备预先配置的。该安全通道可以基于AKMA机制或者GBA机制来建立该中继设备与KMS的安全连接,该KMS可以直接由运营商来负责管理或者是与运营商有商业关系的第三方服务提供商。
在一些实施例中,在该中继设备所属用户的信息包括该中继设备的标识、该中继设备的PVT和KPAK的情况下,该中继设备的签名由该中继设备的秘密签名密钥(SSK)生成。可选地,该中继设备的PVT和KPAK、以及秘密签名密钥(SSK)可以是可信中心KMS通过安全通道为该中继设备预先配置的。该安全通道可以基于AKMA机制或者GBA机制来建立该中继设备与KMS的安全连接,该KMS可以直接由运营商来负责管理或者是与运营商有商业关系的第三方服务提供商。
在一些实施例中,该中继设备将该第一终端设备发送的直接通信请求转发至该第二终端设备;其中,该直接通信请求包括以下至少之一:源标识,目标标识;其中,该源标识用于标识该第一终端设备与该第二终端设备之间的中继连接的源端,该目标标识用于标识该第一终端设备与该第二终端设备之间的中继连接的目标端。
在一些实施例中,当在该第一终端设备和该第二终端设备之间建立不同(Source ID、Destination ID)组之间的链接或者在更新该链接的第二密钥(K
D-SESS)时,该直接通信请求还可以包括该第一密钥的标识(K
D ID)。
具体例如,在该直接通信请求包括该第一密钥的标识(K
D ID)的情况下,该第二终端设备可以不发送认证请求消息或不发起认证流程。
具体例如,在该直接通信请求不包括该第一密钥的标识(K
D ID)的情况下,或者,在该第二终端设备忽略该直接通信请求中包括的该第一密钥的标识(K
D ID)的情况下,该第一终端设备接收该第二终端设备通过该中继设备发送的认证请求消息。也即,在该第一消息不包括该第一密钥的标识的情况下,该第二终端设备发起认证流程,以获取该第一密钥。或者,在该第二终端设备忽略该第一消息中包括的该第一密钥的标识的情况下,该第二终端设备发起认证流程,以重新获取该第一密钥。
在一些实施例中,该第一密钥可以是K
D,该第一密钥的标识可以是K
D ID;该第二密钥可以是K
D-SESS,该第二密钥的标识可以是K
D-SESS ID。
在一些实施例中,该完整性保护密钥包括控制面的完整性保护密钥(K
D-CPint)和用户面的完整性保护密钥(K
D-UPint);和/或,该机密性保护密钥包括控制面的机密性保护密钥(K
D-CPenc)和用户面的机密性保护密钥(K
D-UPenc)。
在一些实施例中,该完整性保护密钥的输入参数包括以下至少之一:该第二密钥,选定的算法类型标识符,选定的算法类型标识符的长度,完整性保护算法标识,完整性保护算法标识的长度。也即,可以基于该第二密钥、选定的算法类型标识符、选定的算法类型标识符的长度、完整性保护算法标识、完整性保护算法标识的长度中的至少之一,生成该完整性保护密钥。
可选地,该完整性保护密钥的输入参数还可以包括一些系统设定参数。在该第二密钥自动刷新时,该完整性保护密钥自动更新。
在一些实施例中,该机密性保护密钥的输入参数包括以下至少之一:该第二密钥,选定的算法类 型标识符,选定的算法类型标识符的长度,机密性保护算法标识,机密性保护算法标识的长度。也即,可以基于该第二密钥、选定的算法类型标识符、选定的算法类型标识符的长度、机密性保护算法标识、机密性保护算法标识的长度中的至少之一,生成该机密性保护密钥。
可选地,该机密性保护密钥的输入参数还可以包括一些系统设定参数。在该第二密钥自动刷新时,该机密性保护密钥自动更新。
因此,在本申请实施例中,第一随机数、第一密钥和第二终端设备生成的第二随机数用于派生第二密钥,第二密钥用于派生完整性保护密钥和/或机密性保护密钥,能够保证第一终端设备和第二终端设备的身份安全与通信数据的机密性与完整性,从而确保双方传输数据的机密性和完整性,防止其他设备甚至中继设备的窃听。
本申请实施例适用于5G层3(Layer-3,L3)UE-to-UE relay架构下源设备(第一终端设备)和目标设备(第二终端设备)之间的安全通信建立流程。在用户设备拥有相应公私钥的前提下,该安全通信建立流程无需网络侧认证和分发密钥流程,即可建立源设备和目标设备之间的安全连接。该安全通信建立流程借助公钥签名技术,能够确保用户设备的身份真实性和消息不可否认性,能够抗重放攻击、中间人攻击、伪装等多种主动攻击,同时保证认证流程消息的完整性,并且利用ECIES算法,从而建立仅在源设备和目标设备之间的安全环境,确保源设备和目标设备双方传输数据的机密性和完整性,从而防止外部敌手甚至中继设备的窃听;保证了安全通信建立机制的可扩展性,另外,该安全通信建立流程能够实现源设备和目标设备之间用户面和控制面安全策略、以及双方所支持加密和完整性保护算法的安全协商,能够实现完整性保护,抵抗篡改和降级攻击。
以下通过实施例1至实施例3详述本申请UE-to-UE中继场景安全通信建立流程。
实施例1,如图13所示,假设所有设备之间在此之前没有建立任何安全连接,可以通过S11至S17中的部分或全部步骤建立L3架构下的UE-to-UE中继场景安全通信。具体的,UE1可以是第一终端设备,UE2可以是第二终端设备,K
D可以是第一密钥,K
D-SESS可以是第二密钥。
S11.发现和路径选择过程。具体的,在发现和路径选择过程中,UE1可以通过UE-to-UE relay向UE2发送直接通信请求,包括以下参数:
源标识(Source ID),该源标识用于标识UE1与UE2之间的中继连接的源端;
目标标识(Destination ID),该目标标识用于标识UE1与UE2之间的中继连接的目标端。
可选地,当在UE1和UE2之间建立不同(Source ID、Destination ID)组之间的链接或者在更新该链接的密钥K
D-SESS时,那么此时若K
D ID存在,那么该直接通信请求中可以包含K
D ID。当UE2接收到该直接通信请求后,若UE2已具备K
D ID及安全环境,同时UE1和UE2之间建立不同(Source ID、Destination ID)组之间的链接安全上下文时,那么可选的是,UE2可以省略认证流程,直接执行安全模式命令消息,或者,考虑更高安全性,继续执行认证流程,创建该Source ID与Destination ID组下的崭新安全环境;若UE1和UE2初次建立安全连接,那么UE2必须通过UE-to-UE relay和UE1执行认证流程。
S12.UE2首先产生一对临时公私钥,即第一临时公钥和第一临时私钥,然后通过UE-to-UE relay与UE1进行通信。具体的,UE2发送认证请求消息,包括以下参数:
UE2所属用户的信息,其中,UE2所属用户的信息包括UE2的签名证书,或者,UE2所属用户的信息包括UE2的标识和UE2的PVT和KPAK;
该第一临时公钥;
UE2的签名,其中,UE2的签名的输入参数包括以下至少之一:“UE2所属用户的信息”和“第一临时公钥”。
S13.在收到认证请求消息后,UE-to-UE relay验证UE2所属用户的信息中的签名证书有效性(例如,UE-to-UE relay根据本地存储信息验证UE2的签名证书有效性),如果签名证书是有效的,UE-to-UE relay基于UE2的签名证书对UE2的签名进行验证;或者,UE-to-UE relay验证UE2所属用户的信息中的UE2的KPAK有效性(具体的,UE-to-UE relay根据本地存储信息验证UE2的KPAK有效性,例如,在UE-to-UE relay本地存储的KPAK中存在与UE2的KPAK一致的KPAK,UE2的KPAK有效),UE-to-UE relay基于UE2的标识和UE2的PVT对UE2的签名进行验证。
最后,如果UE2的签名验证有效,那么UE-to-UE relay向UE1发送验证之后的认证请求消息,验证之后的认证请求消息除了包括上述认证请求消息内的全部内容外,还包括以下参数:
UE-to-UE relay所属用户的信息,其中,UE-to-UE relay所属用户的信息包括UE-to-UE relay的签名证书,或者,UE-to-UE relay所属用户的信息包括UE-to-UE relay的标识和UE-to-UE relay的PVT和KPAK;
UE-to-UE relay的签名1,其中,UE-to-UE relay的签名1中输入参数包括以下至少之一:“UE2 的签名”和“UE-to-UE relay所属用户的信息”;
UE-to-UE relay的相关信息,其中,该UE-to-UE relay的相关信息包括以下之一:该UE-to-UE relay的身份信息,该UE-to-UE relay生成的随机数,该UE-to-UE relay生成的计数器。
S14.在收到验证之后的认证请求消息后,UE1分别检查UE2的签名证书和UE-to-UE relay的签名证书,在UE2的签名证书和UE-to-UE relay的签名证书有效的情况下,UE1基于UE2的签名证书对UE2的签名进行验证,以及UE1基于UE-to-UE relay的签名证书对UE-to-UE relay的签名进行验证;或者,UE1分别检查UE2的KPAK和UE-to-UE relay的KPAK,在UE2的KPAK和UE-to-UE relay的KPAK有效的情况下,且基于UE2的标识和UE2的PVT对UE2的签名进行验证,以及基于UE-to-UE relay的标识和UE-to-UE relay的PVT对UE-to-UE relay的签名进行验证。如果UE2的签名和UE-to-UE relay的签名验证成功,那么UE1产生临时公私钥对,即第二临时公钥和第二临时私钥,然后,UE1根据第一临时公钥、UE-to-UE relay的相关信息和第二临时私钥,使用ECIES算法,计算出共享密钥K
D,并且生成K
D ID的M个比特位,K
D ID用于标识K
D。
最后,UE1通过UE-to-UE relay发送认证响应消息,包括以下参数:
UE1的安全能力信息(可选);
UE1的安全策略信息(可选);
UE1所属用户的信息,其中,UE1所属用户的信息包括UE1的标识和UE1的PVT和KPAK;
第一随机数(Nonce_1);
第二临时公钥;
K
D ID的M个比特位;
UE1的签名,其中,UE1的签名输入参数包括以下至少之一:“UE1所属用户的信息”、“第二临时公钥”、“第一随机数(Nonce_1)”、“K
D ID的M个比特位”和“UE2的签名”;
第一消息验证码。
具体的,该认证响应消息通过基于K
D生成的该第一消息验证码进行完整性保护,且该第一消息验证码的输入参数包括以下至少之一:UE1的安全能力信息,UE1在安全策略信息,UE1所属用户的信息,第一随机数(Nonce_1),该第二临时公钥,K
D ID的M个比特位,UE1的签名。
若UE1的安全能力和UE1的安全策略没有更新,那么在认证响应消息中可以不发送UE1的安全能力信息和UE1的安全策略信息。
S15.收到认证响应消息后,UE-to-UE relay验证UE1所属用户的信息中的签名证书有效性(例如,UE-to-UE relay根据本地存储信息验证UE1的签名证书有效性),如果签名证书是有效的,UE-to-UE relay基于UE1的签名证书对UE1的签名进行验证;或者,UE-to-UE relay验证UE1所属用户的信息中的UE1的KPAK的有效性(具体的,UE-to-UE relay根据本地存储信息验证UE1的KPAK有效性,例如,在UE-to-UE relay本地存储的KPAK中存在与UE1的KPAK一致的KPAK,UE1的KPAK有效),UE-to-UE relay基于UE1的标识和UE1的PVT对UE1的签名进行验证。最后,如果UE1的签名验证成功,UE-to-UE relay向UE2发送验证之后的认证响应消息,其中,验证之后的认证响应消息包含以下参数:
UE1的安全能力信息(可选);
UE1的安全策略信息(可选);
第一随机数(Nonce_1);
UE1所属用户的信息,其中,UE1所属用户的信息包括UE1的标识和UE1的PVT和KPAK;
第二临时公钥;
K
D ID的M个比特位;
UE1的签名;
UE-to-UE relay所属用户的信息;
UE-to-UE relay的签名2,其中,该UE-to-UE relay的签名2输入参数包括以下至少之一:“UE-to-UE relay所属用户的信息”、“UE1的签名”、“UE2的签名”和“验证之后的认证响应消息”;
第一消息验证码。
S16.收到验证之后的认证响应消息后,UE2分别检查UE1的签名证书和UE-to-UE relay的签名证书,在UE1的签名证书和UE-to-UE relay的签名证书有效的情况下,UE2基于UE1的签名证书对UE1的签名进行验证,以及UE2基于UE-to-UE relay的签名证书对UE-to-UE relay的签名进行验证;或者,UE2分别检查UE1的KPAK和UE-to-UE relay的KPAK,在UE1的KPAK和UE-to-UE relay的KPAK有效的情况下,且基于UE1的标识和UE1的PVT对UE1的签名进行验证,以及基于UE-to-UE relay的标识和UE-to-UE relay的PVT对UE-to-UE relay的签名进行验证。如果UE1的签名和UE-to-UE relay的签名验证成功,UE2验证认证响应消息中包含的信息的完整性,UE2基于第一临时私钥、UE-to-UE relay的相关信息和第二临时公钥,利用ECIES算法计算出共享密钥K
D,在第一消息验证码合格的情况下,UE2生成K
D ID的N个比特位,并将K
D ID的N个比特位与接收到的K
D ID的M个比特位合并,生成并存储完整的K
D ID,后续用于标识K
D。此时,UE1和UE2双方进行了认证和根密钥协商,之后UE2开始处理认证响应消息。若该认证响应消息中包含UE1的安全能力信息与UE1的安全策略信息,UE2协商出安全策略与安全算法,然后生成第二随机数(Nonce_2),并根据利用第一随机数、第二随机数和K
D计算K
D-SESS和其他密钥(即K
D-CPint、K
D-CPenc、K
D-UPint、K
D-UPenc)。另外UE2生成K
D-SESS的x个比特位。
最后,UE2通过UE-to-UE relay发送一个受完整性保护的安全模式命令消息给UE1,其中,安全模式命令消息中包含以下参数:
第二随机数(Nonce_2);
K
D ID的N个比特位;
K
D-SESS ID的x个比特位;
UE2选取的安全算法;
UE2选取的安全策略;
第二消息验证码,其中,该安全模式命令消息通过基于K
D-SESS生成的该第二消息验证码进行完整性保护,或者,该安全模式命令消息通过基于K
D-SESS派生的完整性保护密钥生成的该第二消息验证码进行完整性保护,且该第二消息验证码的输入参数包括以下至少之一:第二随机数(Nonce_2)、K
D ID的N个比特位、K
D-SESS ID的x个比特位、UE2选取的安全算法、UE2选取的安全策略。
需要注意的是,如果UE2与UE1的安全策略相互冲突,或者,第一消息验证码验证失败,或者,UE2与UE1的安全算法协商失败,UE2将回复错误消息,其中,该错误消息包括原因信息和第五消息校验码;其中,该原因信息用于指示UE2与UE1的安全策略冲突,或者,该原因信息用于指示第一消息验证码验证失败,或者,该原因信息用于指示UE2与UE1的安全算法协商失败;该第五消息验证码的输入参数至少包括:该原因信息。在第五消息验证码有效的情况下,UE1确定安全模式建立失败,和/或,UE1重新发起安全模式建立流程。
S17.接收到安全模式命令消息后,UE1判断安全模式命令消息中携带的信息是否遭受篡改,若未篡改,那么UE1将K
D ID的M个比特位和K
D ID的N个比特位合并得到K
D ID,以及UE1采用与UE2相同的方式计算K
D-SESS以及其他密钥(即K
D-CPint、K
D-CPenc、K
D-UPint、K
D-UPenc),UE1生成K
D-SESS ID的y个比特位,并且UE1将K
D-SESS ID的x个比特位和K
D-SESS ID的y个比特位合并得到K
D-SESS ID,并保存K
D-SESS ID。然后,UE1验证第二消息校验码是否有效,若有效,UE1准备以新安全环境来保护后续通信。
具体的,在第二消息验证码有效的情况下,UE1根据UE2选取的安全算法、K
D-SESS、基于K
D-SESS生成完整性保护密钥和/或机密性保护密钥、UE2选取的安全策略,与UE2进行通信。
进一步地,UE1向UE2发送安全模式结束消息,该安全模式结束消息通过目标密钥进行加密,且该安全模式结束消息包括以下至少之一:K
D-SESS ID的y个比特位,第四消息验证码;其中,该目标密钥包括以下之一:K
D、K
D-SESS、K
D-CPenc、K
D-UPenc;其中,该安全模式结束消息通过基于K
D-SESS生成的该第四消息验证码进行完整性保护,或者,该安全模式结束消息通过基于K
D-SESS派生的完整性保护密钥生成的该第四消息验证码进行完整性保护,该第四消息验证码的输入参数包括K
D-SESS ID的y个比特位。
具体的,UE2验证第四消息校验码是否有效,若有效,UE2将K
D-SESS ID的x个比特位和K
D-SESS ID的y个比特位合并得到K
D-SESS ID,并保存K
D-SESS ID。UE2根据UE2选取的安全算法、K
D-SESS、基于K
D-SESS生成完整性保护密钥和/或机密性保护密钥、UE2选取的安全策略,与UE1进行通信。
实施例2,如图14所示,假设所有设备之间在此之前没有建立任何安全连接,可以通过S21至S27中的部分或全部步骤建立L3架构下的UE-to-UE中继场景安全通信。具体的,UE1可以是第一终端设备,UE2可以是第二终端设备,K
D可以是第一密钥,K
D-SESS可以是第二密钥。
S21.发现和路径选择过程。具体的,在发现和路径选择过程中,UE1可以通过UE-to-UE relay向UE2发送直接通信请求,包括以下参数:
源标识(Source ID),该源标识用于标识UE1与UE2之间的中继连接的源端;
目标标识(Destination ID),该目标标识用于标识UE1与UE2之间的中继连接的目标端。
可选地,当在UE1和UE2之间建立不同(Source ID、Destination ID)组之间的链接或者在更新该链接的密钥K
D-SESS时,那么此时若K
D ID存在,那么该直接通信请求中可以包含K
D ID。当UE2接收到该直接通信请求后,若UE2已具备K
D ID及安全环境,同时UE1和UE2之间建立不同(Source ID、Destination ID)组之间的链接安全上下文时,那么可选的是,UE2可以省略认证流程,直接执行安全模式命令消息,或者,考虑更高安全性,继续执行认证流程,创建该Source ID与Destination ID组下的崭新安全环境;若UE1和UE2初次建立安全连接,那么UE2必须通过UE-to-UE relay和UE1执行认证流程。
S22.UE2首先产生一对临时公私钥,即第一临时公钥和第一临时私钥,然后通过UE-to-UE relay与UE1进行通信。具体的,UE2发送认证请求消息,包括以下参数:
UE2所属用户的信息,其中,UE2所属用户的信息包括UE2的签名证书,或者,UE2所属用户的信息包括UE2的标识和UE2的PVT和KPAK;
该第一临时公钥;
UE2的签名,其中,UE2的签名的输入参数包括以下至少之一:“UE2所属用户的信息”和“第一临时公钥”。
S23.在收到认证请求消息后,UE-to-UE relay验证UE2所属用户的信息中的签名证书有效性(例如,UE-to-UE relay根据本地存储信息验证UE2的签名证书有效性),如果签名证书是有效的,UE-to-UE relay基于UE2的签名证书对UE2的签名进行验证;或者,UE-to-UE relay验证UE2所属用户的信息中的UE2的KPAK有效性(具体的,UE-to-UE relay根据本地存储信息验证UE2的KPAK有效性,例如,在UE-to-UE relay本地存储的KPAK中存在与UE2的KPAK一致的KPAK,UE2的KPAK有效),UE-to-UE relay基于UE2的标识和UE2的PVT对UE2的签名进行验证。
最后,如果UE2的签名验证有效,那么UE-to-UE relay向UE1发送验证之后的认证请求消息,验证之后的认证请求消息除了包括上述认证请求消息内的全部内容外,还包括以下参数:
UE-to-UE relay所属用户的信息,其中,UE-to-UE relay所属用户的信息包括UE-to-UE relay的签名证书,或者,UE-to-UE relay所属用户的信息包括UE-to-UE relay的标识和UE-to-UE relay的PVT和KPAK;
UE-to-UE relay的签名,其中,UE-to-UE relay的签名中输入参数包括以下至少之一:“UE2的签名”和“UE-to-UE relay所属用户的信息”;
UE-to-UE relay的相关信息,其中,该UE-to-UE relay的相关信息包括以下之一:该UE-to-UE relay的身份信息,该UE-to-UE relay生成的随机数,该UE-to-UE relay生成的计数器。
S24.在收到验证之后的认证请求消息后,UE1分别检查UE2的签名证书和UE-to-UE relay的签名证书,在UE2的签名证书和UE-to-UE relay的签名证书有效的情况下,UE1基于UE2的签名证书对UE2的签名进行验证,以及UE1基于UE-to-UE relay的签名证书对UE-to-UE relay的签名进行验证;或者,UE1分别检查UE2的KPAK和UE-to-UE relay的KPAK,在UE2的KPAK和UE-to-UE relay的KPAK有效的情况下,且基于UE2的标识和UE2的PVT对UE2的签名进行验证,以及基于UE-to-UE relay的标识和UE-to-UE relay的PVT对UE-to-UE relay的签名进行验证。如果UE2的签名和UE-to-UE relay的签名验证成功,那么UE1产生临时公私钥对,即第二临时公钥和第二临时私钥,然后,UE1根据第一临时公钥、UE-to-UE relay的相关信息和第二临时私钥,使用ECIES算法,计算出共享密钥K
D,并且生成K
D ID的M个比特位,K
D ID用于标识K
D。
最后,UE1通过UE-to-UE relay发送安全模式命令消息,包括以下参数:
UE1的安全能力信息(可选);
UE1的安全策略信息(可选);
UE1所属用户的信息,其中,UE1所属用户的信息包括UE1的标识和UE1的PVT和KPAK;
第一随机数(Nonce_1);
第二临时公钥;
K
D ID的M个比特位;
UE1的签名,其中,UE1的签名输入参数包括以下至少之一:“UE1所属用户的信息”、“第二临时公钥”、“第一随机数(Nonce_1)”、“K
D ID的N个比特位”和“UE2的签名”;
第一消息验证码。
具体的,该认证响应消息通过基于K
D生成的该第一消息验证码进行完整性保护,且该第一消息验证码的输入参数包括以下至少之一:UE1的安全能力信息,UE1在安全策略信息,第一随机数(Nonce_1),该第二临时公钥,K
D ID的M个比特位。
若UE1的安全能力和UE1的安全策略没有更新,那么在认证响应消息中可以不发送UE1的安全能力信息和UE1的安全策略信息。
S25.收到认证响应消息后,UE-to-UE relay验证UE1所属用户的信息中的签名证书有效性(例如,UE-to-UE relay根据本地存储信息验证UE1的签名证书有效性),如果签名证书是有效的,UE-to-UE relay基于UE1的签名证书对UE1的签名进行验证;或者,UE-to-UE relay验证UE1所属用户的信息中的UE1的KPAK的有效性(具体的,UE-to-UE relay根据本地存储信息验证UE1的KPAK有效性,例如,在UE-to-UE relay本地存储的KPAK中存在与UE1的KPAK一致的KPAK,UE1的KPAK有效),UE-to-UE relay基于UE1的标识和UE1的PVT对UE1的签名进行验证。最后,如果UE1的签名验证成功,UE-to-UE relay向UE2发送验证之后的认证响应消息,其中,验证之后的认证响应消息包含以下参数:
UE1的安全能力信息(可选);
UE1的安全策略信息(可选);
第一随机数(Nonce_1);
UE1所属用户的信息,其中,UE1所属用户的信息包括UE1的标识和UE1的PVT和KPAK;
第二临时公钥;
K
D ID的M个比特位;
UE1的签名;
UE-to-UE relay所属用户的信息;
UE-to-UE relay的签名2,其中,该UE-to-UE relay的签名2输入参数包括以下至少之一:“UE-to-UE relay所属用户的信息”、“UE1的签名”和“UE2的签名”和“验证之后的认证响应消息”;
第一消息验证码。
S26.收到验证之后的安全模式命令消息后,UE2分别检查UE1的签名证书和UE-to-UE relay的签名证书,在UE1的签名证书和UE-to-UE relay的签名证书有效的情况下,UE2基于UE1的签名证书对UE1的签名进行验证,以及UE2基于UE-to-UE relay的签名证书对UE-to-UE relay的签名进行验证;或者,UE2分别检查UE1的KPAK和UE-to-UE relay的KPAK,在UE1的KPAK和UE-to-UE relay的KPAK有效的情况下,且基于UE1的标识和UE1的PVT对UE1的签名进行验证,以及基于UE-to-UE relay的标识和UE-to-UE relay的PVT对UE-to-UE relay的签名进行验证。如果UE1的签名和UE-to-UE relay的签名验证成功,UE2验证安全模式命令消息中包含的信息的完整性,UE2基于第一临时私钥、UE-to-UE relay的相关信息和第二临时公钥,利用ECIES算法计算出共享密钥K
D,在第一消息验证码合格的情况下,UE2生成K
D ID的N个比特位,并将K
D ID的N个比特位与接收到的K
D ID的M个比特位合并,生成并存储完整的K
D ID,后续用于标识K
D。此时,UE1和UE2双方进行了认证和根密钥协商,之后UE2开始处理安全模式命令消息。若该安全模式命令消息中包含UE1的安全能力信息与UE1的安全策略信息,UE2协商出安全策略与安全算法,然后生成第二随机数(Nonce_2),并根据利用第一随机数、第二随机数和K
D计算K
D-SESS和其他密钥(即K
D-CPint、K
D-CPenc、K
D-UPint、K
D-UPenc)。另外UE2生成K
D-SESS的x个比特位。
最后,UE2通过UE-to-UE relay发送一个受完整性保护的安全模式响应消息给UE1,其中,安全模式响应消息中包含以下参数:
第二随机数(Nonce_2);
K
D ID的N个比特位;
K
D-SESS ID的x个比特位;
UE2选取的安全算法;
UE2选取的安全策略;
第二消息验证码,其中,该安全模式响应消息通过基于K
D-SESS生成的该第二消息验证码进行完整性保护,或者,该安全模式命令消息通过基于K
D-SESS派生的完整性保护密钥生成的该第二消息验证码进行完整性保护,且该第二消息验证码的输入参数包括以下至少之一:第二随机数(Nonce_2)、K
D ID的N个比特位、K
D-SESS ID的x个比特位、UE2选取的安全算法、UE2选取的安全策略;
第三消息验证码,其中,该安全模式响应消息通过基于K
D生成的该第三消息验证码进行完整性保护,且该第三消息验证码的输入参数包括以下至少之一:第二随机数(Nonce_2)、K
D ID的N个比特位、K
D-SESS ID的x个比特位、UE2选取的安全算法、UE2选取的安全策略。
具体的,该安全模式响应消息通过K
D进行加密。该安全模式响应消息也可以不通过K
D进行加密,或者,该安全模式响应消息也可以不加密。
需要注意的是,如果UE2与UE1的安全策略相互冲突,或者,第一消息验证码验证失败,或者,UE2与UE1的安全算法协商失败,UE2将回复错误消息,其中,该错误消息包括原因信息和第五消息校验码;其中,该原因信息用于指示UE2与UE1的安全策略冲突,或者,该原因信息用于指示第一消息验证码验证失败,或者,该原因信息用于指示UE2与UE1的安全算法协商失败;该第五消息验证码的输入参数至少包括:该原因信息。在第五消息验证码有效的情况下,UE1确定安全模式建立 失败,和/或,UE1重新发起安全模式建立流程。
S27.接收到安全模式响应消息后,UE1判断安全模式响应消息中携带的信息是否遭受篡改,若未篡改,那么UE1将K
D ID的M个比特位和K
D ID的N个比特位合并得到K
D ID,以及UE1采用与UE2相同的方式计算K
D-SESS以及其他密钥(即K
D-CPint、K
D-CPenc、K
D-UPint、K
D-UPenc),UE1生成K
D-SESS ID的y个比特位,并且UE1将K
D-SESS ID的x个比特位和K
D-SESS ID的y个比特位合并得到K
D-SESS ID,并保存K
D-SESS ID。然后,UE1验证第二消息校验码和第三消息校验码是否有效,若均有效,UE1准备以新安全环境来保护后续通信。
具体的,在第二消息验证码和第三消息校验码有效的情况下,UE1根据UE2选取的安全算法、K
D-SESS、基于K
D-SESS生成完整性保护密钥和/或机密性保护密钥、UE2选取的安全策略,与UE2进行通信。
进一步地,UE1向UE2发送安全模式结束消息,该安全模式结束消息通过目标密钥进行加密,且该安全模式结束消息包括以下至少之一:K
D-SESS ID的y个比特位,第四消息验证码;其中,该目标密钥包括以下之一:K
D、K
D-SESS、K
D-CPenc、K
D-UPenc;其中,该安全模式结束消息通过基于K
D-SESS生成的该第四消息验证码进行完整性保护,或者,该安全模式结束消息通过基于K
D-SESS派生的完整性保护密钥生成的该第四消息验证码进行完整性保护,该第四消息验证码的输入参数包括K
D-SESS ID的y个比特位。
具体的,UE2验证第四消息校验码是否有效,若有效,UE2将K
D-SESS ID的x个比特位和K
D-SESS ID的y个比特位合并得到K
D-SESS ID,并保存K
D-SESS ID。UE2根据UE2选取的安全算法、K
D-SESS、基于K
D-SESS生成完整性保护密钥和/或机密性保护密钥、UE2选取的安全策略,与UE1进行通信。
实施例3,如图15所示,假设所有设备之间在此之前没有建立任何安全连接,可以通过S31至S37中的部分或全部步骤建立L3架构下的UE-to-UE中继场景安全通信。具体的,UE1可以是第一终端设备,UE2可以是第二终端设备,K
D可以是第一密钥,K
D-SESS可以是第二密钥。
S31.发现和路径选择过程。具体的,在发现和路径选择过程中,UE1可以通过UE-to-UE relay向UE2发送直接通信请求,包括以下参数:
源标识(Source ID),该源标识用于标识UE1与UE2之间的中继连接的源端;
目标标识(Destination ID),该目标标识用于标识UE1与UE2之间的中继连接的目标端;
K
D ID。
S32.UE1通过UE-to-UE relay发送安全模式命令消息,包括以下参数:
UE1的安全能力信息(可选);
UE1的安全策略信息(可选);
第一随机数(Nonce_1);
UE1的签名,其中,UE1的签名输入参数包括以下至少之一:“UE1所属用户的信息”、“第二临时公钥”、“第一随机数(Nonce_1)”、“K
D ID的N个比特位”和“UE2的签名”;
第一消息验证码。
具体的,该安全模式命令消息通过基于K
D生成的该第一消息验证码进行完整性保护,且该第一消息验证码的输入参数包括以下至少之一:UE1的安全能力信息,UE1在安全策略信息,第一随机数(Nonce_1)。
若UE1的安全能力和UE1的安全策略没有更新,那么在安全模式命令消息中可以不发送UE1的安全能力信息和UE1的安全策略信息。
S33.收到安全模式命令消息后,UE-to-UE relay验证UE1所属用户的信息中的签名证书有效性(例如,UE-to-UE relay根据本地存储信息验证UE1的签名证书有效性),如果签名证书是有效的,UE-to-UE relay基于UE1的签名证书对UE1的签名进行验证;或者,UE-to-UE relay验证UE1所属用户的信息中的UE1的KPAK的有效性(具体的,UE-to-UE relay根据本地存储信息验证UE1的KPAK有效性,例如,在UE-to-UE relay本地存储的KPAK中存在与UE1的KPAK一致的KPAK,UE1的KPAK有效),UE-to-UE relay基于UE1的标识和UE1的PVT对UE1的签名进行验证。最后,如果UE1的签名验证成功,UE-to-UE relay发送安全模式命令消息转发给UE2,包含以下参数:
UE1所属用户的信息;
第二临时公钥;
K
D ID的M个比特位;
UE1的签名;
UE-to-UE relay所属用户的信息,其中,UE-to-UE relay所属用户的信息包括UE-to-UE relay的签名证书,或者,UE-to-UE relay所属用户的信息包括UE-to-UE relay的标识和UE-to-UE relay的PVT 和KPAK;
UE-to-UE relay的签名2,其中,该UE-to-UE relay的签名2输入参数包括以下至少之一:“UE-to-UE relay所属用户的信息”、“UE1的签名”和“UE2的签名”;
第一消息验证码。
S34.收到安全模式命令消息后,UE2分别检查UE1的签名证书和UE-to-UE relay的签名证书,在UE1的签名证书和UE-to-UE relay的签名证书有效的情况下,UE2基于UE1的签名证书对UE1的签名进行验证,以及UE2基于UE-to-UE relay的签名证书对UE-to-UE relay的签名进行验证;或者,UE2分别检查UE1的KPAK和UE-to-UE relay的KPAK,在UE1的KPAK和UE-to-UE relay的KPAK有效的情况下,且基于UE1的标识和UE1的PVT对UE1的签名进行验证,以及基于UE-to-UE relay的标识和UE-to-UE relay的PVT对UE-to-UE relay的签名进行验证。如果UE1的签名和UE-to-UE relay的签名验证成功,UE2验证安全模式命令消息中包含的信息的完整性,以及在第一消息验证码合格的情况下,UE1和UE2双方进行了认证和根密钥协商,之后UE2开始处理安全模式命令消息。若该安全模式命令消息中包含UE1的安全能力信息与UE1的安全策略信息,UE2协商出安全策略与安全算法,然后生成第二随机数(Nonce_2),并根据利用第一随机数、第二随机数和K
D计算K
D-SESS和其他密钥(即K
D-CPint、K
D-CPenc、K
D-UPint、K
D-UPenc)。另外UE2生成K
D-SESS的x个比特位。
最后,UE2发送一个完整性保护的安全模式响应消息通过UE-to-UE relay转发给UE1,其中,安全模式响应消息中包含以下参数:
第二随机数(Nonce_2);
K
D ID的N个比特位;
K
D-SESS ID的x个比特位;
UE2选取的安全算法;
UE2选取的安全策略;
第二消息验证码,其中,该安全模式响应消息通过基于K
D-SESS生成的该第二消息验证码进行完整性保护,或者,该安全模式命令消息通过基于K
D-SESS派生的完整性保护密钥生成的该第二消息验证码进行完整性保护,且该第二消息验证码的输入参数包括以下至少之一:第二随机数(Nonce_2)、K
D-SESS ID的x个比特位、UE2选取的安全算法、UE2选取的安全策略;
第三消息验证码,其中,该安全模式响应消息通过基于K
D生成的该第三消息验证码进行完整性保护,且该第三消息验证码的输入参数包括以下至少之一:第二随机数(Nonce_2)、K
D-SESS ID的x个比特位、UE2选取的安全算法、UE2选取的安全策略。
具体的,该安全模式响应消息通过K
D进行加密。该安全模式响应消息也可以不通过K
D进行加密,或者,该安全模式响应消息也可以不加密。
需要注意的是,如果UE2与UE1的安全策略相互冲突,或者,第一消息验证码验证失败,或者,UE2与UE1的安全算法协商失败,UE2将回复错误消息,其中,该错误消息包括原因信息和第五消息校验码;其中,该原因信息用于指示UE2与UE1的安全策略冲突,或者,该原因信息用于指示第一消息验证码验证失败,或者,该原因信息用于指示UE2与UE1的安全算法协商失败;该第五消息验证码的输入参数至少包括:该原因信息。在第五消息验证码有效的情况下,UE1确定安全模式建立失败,和/或,UE1重新发起安全模式建立流程。
S35.接收到安全模式响应消息后,UE1判断安全模式响应消息中携带的信息是否遭受篡改,若未篡改,那么UE1将K
D ID的M个比特位和K
D ID的N个比特位合并得到K
D ID,以及UE1采用与UE2相同的方式计算K
D-SESS以及其他密钥(即K
D-CPint、K
D-CPenc、K
D-UPint、K
D-UPenc),UE1生成K
D-SESS ID的y个比特位,并且UE1将K
D-SESS ID的x个比特位和K
D-SESS ID的y个比特位合并得到K
D-SESS ID,并保存K
D-SESS ID。然后,UE1验证第二消息校验码和第三消息校验码是否有效,若均有效,UE1准备以新安全环境来保护后续通信。
具体的,在第二消息验证码和第三消息校验码有效的情况下,UE1根据UE2选取的安全算法、K
D-SESS、基于K
D-SESS生成完整性保护密钥和/或机密性保护密钥、UE2选取的安全策略,与UE2进行通信。
进一步地,UE1向UE2发送安全模式结束消息,该安全模式结束消息通过目标密钥进行加密,且该安全模式结束消息包括以下至少之一:K
D-SESS ID的y个比特位,第四消息验证码;其中,该目标密钥包括以下之一:K
D、K
D-SESS、K
D-CPenc、K
D-UPenc;其中,该安全模式结束消息通过基于K
D-SESS生成的该第四消息验证码进行完整性保护,或者,该安全模式结束消息通过基于K
D-SESS派生的完整性保护密钥生成的该第四消息验证码进行完整性保护,该第四消息验证码的输入参数包括K
D-SESS ID的y个比特位。
具体的,UE2验证第四消息校验码是否有效,若有效,UE2将K
D-SESS ID的x个比特位和K
D-SESS ID的y个比特位合并得到K
D-SESS ID,并保存K
D-SESS ID。UE2根据UE2选取的安全算法、K
D-SESS、基于K
D-SESS生成完整性保护密钥和/或机密性保护密钥、UE2选取的安全策略,与UE1进行通信。
上文结合图6至图15,详细描述了本申请的方法实施例,下文结合图16至图21,详细描述本申请的装置实施例,应理解,装置实施例与方法实施例相互对应,类似的描述可以参照方法实施例。
图16示出了根据本申请实施例的终端设备800的示意性框图。如图16所示,该终端设备800为第一终端设备,该终端设备800包括:
通信单元810,用于接收第二终端设备通过中继设备发送的认证请求消息;
其中,该认证请求消息包括以下至少之一:该第二终端设备所属用户的信息,该中继设备所属用户的信息,该第二终端设备生成的第一临时公钥,该第二终端设备的签名,该中继设备的签名,该中继设备的相关信息;
其中,该第二终端设备所属用户的信息包括该第二终端设备的签名证书,或者,该第二终端设备所属用户的信息包括该第二终端设备的标识和该第二终端设备的公共验证令牌PVT和密钥管理服务器的公共认证密钥KPAK;该中继设备所属用户的信息包括该中继设备的签名证书,或者,该中继设备所属用户的信息包括该中继设备的标识和该中继设备的PVT和KPAK;该第二终端设备的签名的输入参数包括以下至少之一:该第二终端设备所属用户的信息和该第一临时公钥;该中继设备的签名的输入参数包括以下至少之一:该第二终端设备的签名和该中继设备所属用户的信息;该第一临时公钥和该中继设备的相关信息用于第一终端设备派生第一密钥;该中继设备的相关信息包括以下之一:该中继设备的身份信息,该中继设备生成的随机数,该中继设备生成的计数器。
在一些实施例中,在该第二终端设备所属用户的信息包括该第二终端设备的签名证书的情况下,该第二终端设备的签名由该第二终端设备的签名私钥生成,或者,在该第二终端设备所属用户的信息包括该第二终端设备的标识和该第二终端设备的PVT和KPAK的情况下,该第二终端设备的签名由该第二终端设备的秘密签名密钥生成;和/或,
在该中继设备所属用户的信息包括该中继设备的签名证书的情况下,该中继设备的签名由该中继设备的签名私钥生成,或者,在该中继设备所属用户的信息包括该中继设备的标识和该中继设备的PVT和KPAK的情况下,该中继设备的签名由该中继设备的秘密签名密钥生成。
在一些实施例中,该终端设备800还包括:处理单元820;
在该第二终端设备的签名证书和该中继设备的签名证书有效,且基于该第二终端设备的签名证书对该第二终端设备的签名验证成功,以及基于该中继设备的签名证书对该中继设备的签名验证成功的情况下,该处理单元820用于生成第二临时私钥,以及该处理单元820用于根据该第一临时公钥、该中继设备的相关信息和该第二临时私钥派生该第一密钥;或者,
在该第二终端设备的KPAK和该中继设备的KPAK有效,且基于该第二终端设备的标识和该第二终端设备的PVT对该第二终端设备的签名验证成功,以及基于该中继设备的标识和该中继设备的PVT对该中继设备的签名验证成功的情况下,该处理单元820用于生成第二临时私钥,以及该处理单元820用于根据该第一临时公钥、该中继设备的相关信息和该第二临时私钥派生该第一密钥。
在一些实施例中,该通信单元810还用于通过该中继设备向该第二终端设备发送第一消息;
其中,该第一消息包括以下至少之一:该第一终端设备的安全能力信息,该第一终端设备的安全策略信息,该第一终端设备所属用户的信息,该第一终端设备生成的第一随机数,该第一终端设备生成的与该第二临时私钥配对的第二临时公钥,该第一终端设备生成的该第一密钥的标识的M个比特位,该第一终端设备的签名,第一消息验证码;
其中,该第一终端设备所属用户的信息包括该第一终端设备的签名证书,或者,该第一终端设备所属用户的信息包括该第一终端设备的标识和该第一终端设备的PVT和KPAK;该第一终端设备的签名的输入参数包括以下至少之一:该第一终端设备所属用户的信息,该第二临时公钥,该第一密钥的标识的M个比特位,该第二终端设备的签名;
其中,该第一消息通过基于该第一密钥生成的该第一消息验证码进行完整性保护,且该第一消息验证码的输入参数包括以下至少之一:该第一终端设备的安全能力信息,该第一终端设备的安全策略信息,该第一终端设备所属用户的信息,该第一随机数,该第二临时公钥,该M个比特位,该第一终端设备的签名;
其中,该第二临时公钥和该中继设备的相关信息用于该第二终端设备派生该第一密钥,该第一随机数、该第一密钥和该第二终端设备生成的第二随机数用于派生第二密钥,该第二密钥用于派生完整性保护密钥和/或机密性保护密钥,该第一密钥的标识由该M个比特位与该第一密钥的标识的另外N个比特位合并得到,M和N均为正整数。
在一些实施例中,该通信单元810还用于接收该第二终端设备通过该中继设备发送的第二消息;
其中,该第二消息包括以下至少之一:该第二终端设备生成的该第二随机数,该第二终端设备生成的该第一密钥的标识的N个比特位,该第二终端设备生成的该第二密钥的标识的x个比特位,该第二终端设备选取的安全算法,该第二终端设备选取的安全策略,第二消息验证码;
其中,该第二消息通过基于该第二密钥生成的该第二消息验证码进行完整性保护,且该第二消息验证码的输入参数包括以下至少之一:该第二随机数,该N个比特位,该x个比特位,该第二终端设备选取的安全算法,该第二终端设备选取的安全策略;
其中,该第二密钥的标识由该x个比特位与该第二密钥的标识的另外y个比特位合并得到,x和y均为正整数。
在一些实施例中,该第二消息通过该第一密钥进行加密,且该第二消息还包括第三消息验证码;
其中,该第二消息通过基于该第一密钥生成的该第三消息验证码进行完整性保护,或者,该第二消息通过基于该第二密钥派生的完整性保护密钥生成的该第二消息验证码进行完整性保护,且该第三消息验证码的输入参数包括以下至少之一:该第二随机数,该N个比特位,该x个比特位,该第二终端设备选取的安全算法,该第二终端设备选取的安全策略。
在一些实施例中,该终端设备800还包括:处理单元820;
在该第二消息中携带的信息未遭受篡改的情况下,该处理单元820用于至少根据该第一随机数、该第一密钥和该第二随机数生成该第二密钥,该处理单元820用于根据该第二密钥生成完整性保护密钥和/或机密性保护密钥,以及该处理单元820用于将该M个比特位和该N个比特位合并得到该第一密钥的标识,该处理单元820用于生成该第二密钥的标识的y个比特位,并将该x个比特位和该y个比特位合并得到该第二密钥的标识;
在该第二消息验证码有效的情况下,该通信单元810还用于根据该第二终端设备选取的安全算法、该第二密钥、基于该第二密钥生成完整性保护密钥和/或机密性保护密钥、该第二终端设备选取的安全策略,与该第二终端设备进行通信。
在一些实施例中,该终端设备800还包括:处理单元820;
该处理单元820用于根据该第一密钥解密该第二消息;
在该第二消息中携带的信息未遭受篡改的情况下,该处理单元820用于至少根据该第一随机数、该第一密钥和该第二随机数生成该第二密钥,该处理单元820用于根据该第二密钥生成完整性保护密钥和/或机密性保护密钥,以及该处理单元820用于将该M个比特位和该N个比特位合并得到该第一密钥的标识,该处理单元820用于生成该第二密钥的标识的y个比特位,并将该x个比特位和该y个比特位合并得到该第二密钥的标识;
在该第二消息验证码和该第三消息验证码有效的情况下,该通信单元810还用于根据该第二终端设备选取的安全算法、该第二密钥、基于该第二密钥生成完整性保护密钥和/或机密性保护密钥、该第二终端设备选取的安全策略,与该第二终端设备进行通信。
在一些实施例中,该完整性保护密钥的输入参数包括以下至少之一:该第二密钥,选定的算法类型标识符,选定的算法类型标识符的长度,完整性保护算法标识,完整性保护算法标识的长度;和/或,该机密性保护密钥的输入参数包括以下至少之一:该第二密钥,选定的算法类型标识符,选定的算法类型标识符的长度,机密性保护算法标识,机密性保护算法标识的长度。
在一些实施例中,该第一消息为认证响应消息,该第二消息为安全模式命令消息。
在一些实施例中,该第一消息为安全模式命令消息,该第二消息为安全模式响应消息。
在一些实施例中,该通信单元810还用于通过该中继设备向该第二终端设备发送第三消息;
其中,该第三消息用于指示安全模式建立完成,该第三消息通过目标密钥进行加密,且该第三消息包括以下至少之一:该第二密钥的标识的该y个比特位,第四消息验证码;
其中,该目标密钥包括以下之一:该第一密钥,该第二密钥,该第二密钥派生的机密性保护密钥;
其中,该第三消息通过基于该第二密钥生成的该第四消息验证码进行完整性保护,或者,该第三消息通过基于该第二密钥派生的完整性保护密钥生成的该第四消息验证码进行完整性保护,该第四消息验证码的输入参数包括该y个比特位。
在一些实施例中,该通信单元810还用于接收该第二终端设备通过该中继设备发送的错误消息;其中,该错误消息包括以下至少之一:原因信息,第五消息验证码;其中,该原因信息用于指示该第二终端设备与该第一终端设备的安全策略冲突,或者,该原因信息用于指示该第一消息验证码验证失败,或者,该原因信息用于指示该第二终端设备与该第一终端设备的安全算法协商失败,该第五消息验证码的输入参数包括以下至少之一:该原因信息;
在该第五消息验证码有效的情况下,该处理单元820还用于确定安全模式建立失败,和/或,该 处理单元820还用于重新发起安全模式建立流程。
在一些实施例中,该完整性保护密钥包括控制面的完整性保护密钥和用户面的完整性保护密钥;和/或,该机密性保护密钥包括控制面的机密性保护密钥和用户面的机密性保护密钥。
在一些实施例中,该通信单元810还用于通过该中继设备向该第二终端设备发送直接通信请求;
其中,该直接通信请求包括以下至少之一:源标识,目标标识;
其中,该源标识用于标识该第一终端设备与该第二终端设备之间的中继连接的源端,该目标标识用于标识该第一终端设备与该第二终端设备之间的中继连接的目标端。
在一些实施例中,上述通信单元可以是通信接口或收发器,或者是通信芯片或者片上系统的输入输出接口。上述处理单元可以是一个或多个处理器。
应理解,根据本申请实施例的终端设备800可对应于本申请方法实施例中的第一终端设备,并且终端设备800中的各个单元的上述和其它操作和/或功能分别为了实现图6所示方法200中第一终端设备的相应流程,为了简洁,在此不再赘述。
图17示出了根据本申请实施例的终端设备900的示意性框图。如图17所示,该终端设备900为第二终端设备,该终端设备900包括:
通信单元910,用于通过中继设备向第一终端设备发送认证请求消息;
其中,该认证请求消息包括以下至少之一:该第二终端设备所属用户的信息,该第二终端设备生成的第一临时公钥,该第二终端设备的签名,该中继设备的相关信息;
其中,该第二终端设备所属用户的信息包括该第二终端设备的签名证书,或者,该第二终端设备所属用户的信息包括该第二终端设备的标识和该第二终端设备的公共验证令牌PVT和密钥管理服务器的公共认证密钥KPAK;该第二终端设备的签名的输入参数包括以下至少之一:该第二终端设备所属用户的信息和该第一临时公钥;该第一临时公钥和该中继设备的相关信息用于该第一终端设备派生第一密钥;该中继设备的相关信息包括以下之一:该中继设备的身份信息,该中继设备生成的随机数,该中继设备生成的计数器。
在一些实施例中,在该第二终端设备所属用户的信息包括该第二终端设备的签名证书的情况下,该第二终端设备的签名由该第二终端设备的签名私钥生成,或者,在该第二终端设备所属用户的信息包括该第二终端设备的标识和该第二终端设备的PVT和KPAK的情况下,该第二终端设备的签名由该第二终端设备的秘密签名密钥生成。
在一些实施例中,该通信单元910还用于接收该第一终端设备通过该中继设备发送的第一消息;
其中,该第一消息包括以下至少之一:该第一终端设备的安全能力信息,该第一终端设备的安全策略信息,该第一终端设备所属用户的信息,该中继设备所属用户的信息,该第一终端设备生成的第一随机数,该第一终端设备生成的与该第二临时私钥配对的第二临时公钥,该第一终端设备生成的该第一密钥的标识的M个比特位,该第一终端设备的签名,该中继设备的签名,第一消息验证码;
其中,该第一终端设备所属用户的信息包括该第一终端设备的签名证书,或者,该第一终端设备所属用户的信息包括该第一终端设备的标识和该第一终端设备的PVT和KPAK;该中继设备所属用户的信息包括该中继设备的签名证书,或者,该中继设备所属用户的信息包括该中继设备的标识和该中继设备的PVT和KPAK;该第一终端设备的签名的输入参数包括以下至少之一:该第一终端设备所属用户的信息,该第二临时公钥,该第一密钥的标识的M个比特位,该第二终端设备的签名;该中继设备的签名的输入参数包括以下至少之一:该中继设备所属用户的信息,该第一终端设备的签名,该第二终端设备的签名;
其中,该第一消息通过基于该第一密钥生成的该第一消息验证码进行完整性保护,且该第一消息验证码的输入参数包括以下至少之一:该第一终端设备的安全能力信息,该第一终端设备的安全策略信息,该第一终端设备所属用户的信息,该中继设备所属用户的信息,该第一随机数,该第二临时公钥,该M个比特位,该第一终端设备的签名,该中继设备的签名;
其中,该第二临时公钥和该中继设备的相关信息用于该第二终端设备派生该第一密钥,该第一随机数、该第一密钥和该第二终端设备生成的第二随机数用于派生第二密钥,该第二密钥用于派生完整性保护密钥和/或机密性保护密钥,该第一密钥的标识由该M个比特位与该第一密钥的标识的另外N个比特位合并得到,M和N均为正整数。
在一些实施例中,在该第一终端设备所属用户的信息包括该第一终端设备的签名证书的情况下,该第一终端设备的签名由该第一终端设备的签名私钥生成,或者,在该第一终端设备所属用户的信息包括该第一终端设备的标识和该第一终端设备的PVT和KPAK的情况下,该第一终端设备的签名由该第一终端设备的秘密签名密钥生成;和/或,
在该中继设备所属用户的信息包括该中继设备的签名证书的情况下,该中继设备的签名由该中继 设备的签名私钥生成,或者,在该中继设备所属用户的信息包括该中继设备的标识和该中继设备的PVT和KPAK的情况下,该中继设备的签名由该中继设备的秘密签名密钥生成。
在一些实施例中,该终端设备900还包括:处理单元920;
该处理单元920用于分别检查该第一终端设备的签名证书和该中继设备的签名证书,在该第一终端设备的签名证书和该中继设备的签名证书有效的情况下,该处理单元920还用于基于该第一终端设备的签名证书对该第一终端设备的签名进行验证,以及该处理单元920还用于基于该中继设备的签名证书对该中继设备的签名进行验证;或者,该处理单元920还用于分别检查该第一终端设备的KPAK和该中继设备的KPAK,在该第一终端设备的KPAK和该中继设备的KPAK有效的情况下,且基于该第一终端设备的标识和该第一终端设备的PVT对该第一终端设备的签名进行验证,以及基于该中继设备的标识和该中继设备的PVT对该中继设备的签名进行验证;
在该第一终端设备的签名和该中继设备的签名验证成功,且该第一消息中携带的信息未遭受篡改的情况下,该处理单元920用于生成第二随机数,该处理单元920还用于至少根据该第一随机数、该第一密钥和该第二随机数生成该第二密钥,该处理单元920还用于根据该第二密钥生成完整性保护密钥和/或机密性保护密钥,以及该处理单元920还用于生成该第一密钥的标识的N个比特位,并将该M个比特位和该N个比特位合并得到该第一密钥的标识;
在该第一消息验证码有效的情况下,该通信单元910还用于通过该中继设备向该第一终端设备发送第二消息;其中,该第二消息包括以下至少之一:该第二随机数,该N个比特位,该第二终端设备生成的该第二密钥的标识的x个比特位,该第二终端设备选取的安全算法,该第二终端设备选取的安全策略,第二消息验证码;
其中,该第二消息通过基于该第二密钥生成的该第二消息验证码进行完整性保护,或者,该第二消息通过基于该第二密钥派生的完整性保护密钥生成的该第二消息验证码进行完整性保护,且该第二消息验证码的输入参数包括以下至少之一:该第二随机数,该N个比特位,该x个比特位,该第二终端设备选取的安全算法,该第二终端设备选取的安全策略;
其中,该第二密钥的标识由该x个比特位与该第二密钥的标识的另外y个比特位合并得到,x和y均为正整数。
在一些实施例中,该第二消息通过该第一密钥进行加密,且该第二消息还包括第三消息验证码;
其中,该第二消息通过基于该第一密钥生成的该第三消息验证码进行完整性保护,且该第三消息验证码的输入参数包括以下至少之一:该第二随机数,该N个比特位,该x个比特位,该第二终端设备选取的安全算法,该第二终端设备选取的安全策略。
在一些实施例中,该第一消息为认证响应消息,该第二消息为安全模式命令消息。
在一些实施例中,该第一消息为安全模式命令消息,该第二消息为安全模式响应消息。
在一些实施例中,该完整性保护密钥的输入参数包括以下至少之一:该第二密钥,选定的算法类型标识符,选定的算法类型标识符的长度,完整性保护算法标识,完整性保护算法标识的长度;和/或,该机密性保护密钥的输入参数包括以下至少之一:该第二密钥,选定的算法类型标识符,选定的算法类型标识符的长度,机密性保护算法标识,机密性保护算法标识的长度。
在一些实施例中,该通信单元910还用于接收该第一终端设备通过该中继设备发送的第三消息;
其中,该第三消息用于指示安全模式建立完成,该第三消息通过目标密钥进行加密,且该第三消息包括以下至少之一:该第一终端设备生成的该第二密钥的标识的y个比特位,第四消息验证码;
其中,该目标密钥包括以下之一:该第一密钥,该第二密钥,该第二密钥派生的机密性保护密钥;
其中,该第三消息通过基于该第二密钥生成的该第四消息验证码进行完整性保护,或者,该第三消息通过基于该第二密钥派生的完整性保护密钥生成的该第四消息验证码进行完整性保护,该第四消息验证码的输入参数包括该y个比特位。
在一些实施例中,该终端设备900还包括:处理单元920;
该处理单元920用于通过该目标密钥对该第三消息进行解密;
在该第三消息中携带的信息未遭受篡改的情况下,且该第四消息验证码有效的情况下,该处理单元920还用于将该x个比特位与该y个比特位合并得到该第二密钥的标识。
在一些实施例中,该通信单元910还用于通过该中继设备向该第一终端设备发送错误消息;其中,该错误消息包括以下至少之一:原因信息,第五消息验证码;其中,该原因信息用于指示该第二终端设备与该第一终端设备的安全策略冲突,或者,该原因信息用于指示该第一消息验证码验证失败,或者,该原因信息用于指示该第二终端设备与该第一终端设备的安全算法协商失败,该第五消息验证码的输入参数包括以下至少之一:该原因信息。
在一些实施例中,该完整性保护密钥包括控制面的完整性保护密钥和用户面的完整性保护密钥; 和/或,该机密性保护密钥包括控制面的机密性保护密钥和用户面的机密性保护密钥。
在一些实施例中,该通信单元910还用于接收该第一终端设备通过该中继设备发送的直接通信请求;
其中,该直接通信请求包括以下至少之一:源标识,目标标识;
其中,该源标识用于标识该第一终端设备与该第二终端设备之间的中继连接的源端,该目标标识用于标识该第一终端设备与该第二终端设备之间的中继连接的目标端。
在一些实施例中,上述通信单元可以是通信接口或收发器,或者是通信芯片或者片上系统的输入输出接口。上述处理单元可以是一个或多个处理器。
应理解,根据本申请实施例的终端设备900可对应于本申请方法实施例中的第二终端设备,并且终端设备900中的各个单元的上述和其它操作和/或功能分别为了实现图8所示方法300中第二终端设备的相应流程,为了简洁,在此不再赘述。
图18示出了根据本申请实施例的中继设备1000的示意性框图。如图18所示,该中继设备1000包括:
通信单元1010,用于接收第二终端设备发送的认证请求消息;其中,该认证请求消息包括以下至少之一:该第二终端设备所属用户的信息,该第二终端设备生成的第一临时公钥,该第二终端设备的签名;其中,该第二终端设备所属用户的信息包括该第二终端设备的签名证书,或者,该第二终端设备所属用户的信息包括该第二终端设备的标识和该第二终端设备的PVT和KPAK;该第二终端设备的签名的输入参数包括以下至少之一:该第二终端设备所属用户的信息和该第一临时公钥;该第一临时公钥和该中继设备的相关信息用于该第一终端设备派生该第一密钥;
在该第二终端设备的签名证书有效,且基于该第二终端设备的签名证书对该第二终端设备的签名验证成功的情况下,或者,在该第二终端设备的KPAK有效,且基于该第二终端设备的标识和该第二终端设备的PVT对该第二终端设备的签名验证成功的情况下,该通信单元1010还用于向该第一终端设备发送验证之后的认证请求消息;其中,该验证之后的认证请求消息包括以下至少之一:该第二终端设备所属用户的信息,该中继设备所属用户的信息,该第一临时公钥,该第二终端设备的签名,该中继设备的签名,该中继设备的相关信息;其中,该中继设备所属用户的信息包括该中继设备的签名证书,或者,该中继设备所属用户的信息包括该中继设备的标识和该中继设备的PVT和KPAK;该中继设备的签名的输入参数包括以下至少之一:该第二终端设备的签名和该中继设备所属用户的信息;其中,该中继设备的相关信息包括以下之一:该中继设备的身份信息,该中继设备生成的随机数,该中继设备生成的计数器。
在一些实施例中,在该第二终端设备所属用户的信息包括该第二终端设备的签名证书的情况下,该第二终端设备的签名由该第二终端设备的签名私钥生成,或者,在该第二终端设备所属用户的信息包括该第二终端设备的标识和该第二终端设备的PVT和KPAK的情况下,该第二终端设备的签名由该第二终端设备的秘密签名密钥生成;和/或,
在该中继设备所属用户的信息包括该中继设备的签名证书的情况下,该中继设备的签名由该中继设备的签名私钥生成,或者,在该中继设备所属用户的信息包括该中继设备的标识和该中继设备的PVT和KPAK的情况下,该中继设备的签名由该中继设备的秘密签名密钥生成。
在一些实施例中,该通信单元1010还用于接收该第一终端设备发送的第一消息;
其中,该第一消息包括以下至少之一:该第一终端设备的安全能力信息,该第一终端设备的安全策略信息,该第一终端设备所属用户的信息,该第一终端设备生成的第一随机数,该第一终端设备生成的第二临时公钥,该第一终端设备生成的该第一密钥的标识的M个比特位,该第一终端设备的签名,第一消息验证码;其中,该第一终端设备所属用户的信息包括该第一终端设备的签名证书,或者,该第一终端设备所属用户的信息包括该第一终端设备的标识和该第一终端设备的PVT和KPAK;该第一终端设备的签名的输入参数包括以下至少之一:该第一终端设备所属用户的信息,该第二临时公钥,该第一密钥的标识的M个比特位,该第二终端设备的签名;其中,该第一消息通过基于该第一密钥生成的该第一消息验证码进行完整性保护,且该第一消息验证码的输入参数包括以下至少之一:该第一终端设备的安全能力信息,该第一终端设备的安全策略信息,该第一终端设备所属用户的信息,该第一随机数,该第二临时公钥,该M个比特位,该第一终端设备的签名;
在该第一终端设备的签名证书有效,且基于该第一终端设备的签名证书对该第一终端设备的签名验证成功的情况下,或者,在该第一终端设备的KPAK有效,且基于该第一终端设备的标识和该第一终端设备的PVT对该第一终端设备的签名验证成功的情况下,该通信单元1010还用于向该第二终端设备发送验证之后的第一消息;其中,该验证之后的第一消息包括以下至少之一:该第一终端设备的安全能力信息,该第一终端设备的安全策略信息,该第一终端设备所属用户的信息,该中继设备所属 用户的信息,该第一终端设备生成的第一随机数,该第一终端设备生成的与该第二临时私钥配对的第二临时公钥,该第一终端设备生成的该第一密钥的标识的M个比特位,该第一终端设备的签名,该中继设备的签名,该第一消息验证码;其中,该中继设备所属用户的信息包括该中继设备的签名证书,或者,该中继设备所属用户的信息包括该中继设备的标识和该中继设备的PVT和KPAK;该中继设备的签名的输入参数包括以下至少之一:该中继设备所属用户的信息,该第一终端设备的签名,该第二终端设备的签名,该验证之后的第一消息;
其中,该第二临时公钥和该中继设备的相关信息用于该第二终端设备派生该第一密钥,该第一随机数、该第一密钥和该第二终端设备生成的第二随机数用于派生第二密钥,该第二密钥用于派生完整性保护密钥和/或机密性保护密钥,该第一密钥的标识由该M个比特位与该第一密钥的标识的另外N个比特位合并得到,M和N均为正整数。
在一些实施例中,该通信单元1010还用于将该第二终端设备发送的第二消息转发至该第一终端设备;
其中,该第二消息包括以下至少之一:该第二终端设备生成的该第二随机数,该第二终端设备生成的该第一密钥的标识的N个比特位,该第二终端设备生成的该第二密钥的标识的x个比特位,该第二终端设备选取的安全算法,该第二终端设备选取的安全策略,第二消息验证码;
其中,该第二消息通过基于该第二密钥生成的该第二消息验证码进行完整性保护,或者,该第二消息通过基于该第二密钥派生的完整性保护密钥生成的该第二消息验证码进行完整性保护,且该第二消息验证码的输入参数包括以下至少之一:该第二随机数,该N个比特位,该x个比特位,该第二终端设备选取的安全算法,该第二终端设备选取的安全策略;
其中,该第二密钥的标识由该x个比特位与该第二密钥的标识的另外y个比特位合并得到,x和y均为正整数。
在一些实施例中,该第二消息通过该第一密钥进行加密,且该第二消息还包括第三消息验证码;
其中,该第二消息通过基于该第一密钥生成的该第三消息验证码进行完整性保护,且该第三消息验证码的输入参数包括以下至少之一:该第二随机数,该N个比特位,该x个比特位,该第二终端设备选取的安全算法,该第二终端设备选取的安全策略。
在一些实施例中,该第一消息为认证响应消息,该第二消息为安全模式命令消息。
在一些实施例中,该第一消息为安全模式命令消息,该第二消息为安全模式响应消息。
在一些实施例中,该通信单元1010还用于将该第一终端设备发送的第三消息转发至该第二终端设备;
其中,该第三消息用于指示安全模式建立完成,该第三消息通过目标密钥进行加密,且该第三消息包括以下至少之一:该第一终端设备生成的该第二密钥的标识的y个比特位,第四消息验证码;
其中,该目标密钥包括以下之一:该第一密钥,该第二密钥,该第二密钥派生的机密性保护密钥;
其中,该第三消息通过基于该第二密钥生成的该第四消息验证码进行完整性保护,或者,该第三消息通过基于该第二密钥派生的完整性保护密钥生成的该第四消息验证码进行完整性保护,该第四消息验证码的输入参数包括该y个比特位。
在一些实施例中,该通信单元1010还用于将该第二终端设备发送的错误消息转发至该第一终端设备;其中,该错误消息包括以下至少之一:原因信息,第五消息验证码;其中,该原因信息用于指示该第二终端设备与该第一终端设备的安全策略冲突,或者,该原因信息用于指示该第一消息验证码验证失败,或者,该原因信息用于指示该第二终端设备与该第一终端设备的安全算法协商失败,该第五消息验证码的输入参数包括以下至少之一:该原因信息。
在一些实施例中,该完整性保护密钥包括控制面的完整性保护密钥和用户面的完整性保护密钥;和/或,该机密性保护密钥包括控制面的机密性保护密钥和用户面的机密性保护密钥。
在一些实施例中,该通信单元1010还用于将该第一终端设备发送的直接通信请求转发至该第二终端设备;
其中,该直接通信请求包括以下至少之一:源标识,目标标识;
其中,该源标识用于标识该第一终端设备与该第二终端设备之间的中继连接的源端,该目标标识用于标识该第一终端设备与该第二终端设备之间的中继连接的目标端。
在一些实施例中,上述通信单元可以是通信接口或收发器,或者是通信芯片或者片上系统的输入输出接口。
应理解,根据本申请实施例的中继设备1000可对应于本申请方法实施例中的中继设备,并且中继设备1000中的各个单元的上述和其它操作和/或功能分别为了实现图9所示方法400中中继设备的相应流程,为了简洁,在此不再赘述。
图19示出了根据本申请实施例的终端设备1100的示意性框图。如图19所示,该终端设备1100为第一终端设备,该终端设备1100包括:
通信单元1110,用于通过中继设备向第二终端设备发送第一消息;
其中,该第一消息包括以下至少之一:该第一终端设备的安全能力信息,该第一终端设备的安全策略信息,该第一终端设备所属用户的信息,该第一终端设备生成的第一随机数,该第一终端设备生成的第二临时公钥,该第一终端设备生成的第一密钥的标识的M个比特位,该第一终端设备的签名,第一消息验证码;
其中,该第一终端设备所属用户的信息包括该第一终端设备的签名证书,或者,该第一终端设备所属用户的信息包括该第一终端设备的标识和该第一终端设备的PVT和KPAK;该第一终端设备的签名的输入参数包括以下至少之一:该第一终端设备所属用户的信息,该第二临时公钥,该第一密钥的标识的M个比特位,该第二终端设备的签名;
其中,该第一消息通过基于该第一密钥生成的该第一消息验证码进行完整性保护,且该第一消息验证码的输入参数包括以下至少之一:该第一终端设备的安全能力信息,该第一终端设备的安全策略信息,该第一终端设备所属用户的信息,该第一随机数,该第二临时公钥,该M个比特位,该第一终端设备的签名;
其中,该第二临时公钥和该中继设备的相关信息用于该第二终端设备派生该第一密钥,该第一随机数、该第一密钥和该第二终端设备生成的第二随机数用于派生第二密钥,该第二密钥用于派生完整性保护密钥和/或机密性保护密钥,该第一密钥的标识由该M个比特位与该第一密钥的标识的另外N个比特位合并得到,M和N均为正整数;
其中,该中继设备的相关信息包括以下之一:该中继设备的身份信息,该中继设备生成的随机数,该中继设备生成的计数器。
在一些实施例中,该通信单元1110还用于接收该第二终端设备通过该中继设备发送的第二消息;
其中,该第二消息包括以下至少之一:该第二终端设备生成的该第二随机数,该第二终端设备生成的该第一密钥的标识的N个比特位,该第二终端设备生成的该第二密钥的标识的x个比特位,该第二终端设备选取的安全算法,该第二终端设备选取的安全策略,第二消息验证码;
其中,该第二消息通过基于该第二密钥生成的该第二消息验证码进行完整性保护,或者,该第二消息通过基于该第二密钥派生的完整性保护密钥生成的该第二消息验证码进行完整性保护,且该第二消息验证码的输入参数包括以下至少之一:该第二随机数,该N个比特位,该x个比特位,该第二终端设备选取的安全算法,该第二终端设备选取的安全策略;
其中,该第二密钥的标识由该x个比特位与该第二密钥的标识的另外y个比特位合并得到,x和y均为正整数。
在一些实施例中,该第二消息通过该第一密钥进行加密,且该第二消息还包括第三消息验证码;
其中,该第二消息通过基于该第一密钥生成的该第三消息验证码进行完整性保护,且该第三消息验证码的输入参数包括以下至少之一:该第二随机数,该N个比特位,该x个比特位,该第二终端设备选取的安全算法,该第二终端设备选取的安全策略。
在一些实施例中,该终端设备1100还包括:处理单元1120;
在该第二消息中携带的信息未遭受篡改的情况下,该处理单元1120用于至少根据该第一随机数、该第一密钥和该第二随机数生成该第二密钥,该处理单元1120用于根据该第二密钥生成完整性保护密钥和/或机密性保护密钥,以及该处理单元1120用于将该M个比特位和该N个比特位合并得到该第一密钥的标识,该处理单元1120用于生成该第二密钥的标识的y个比特位,并将该x个比特位和该y个比特位合并得到该第二密钥的标识;
在该第二消息验证码有效的情况下,该通信单元1110还用于根据该第二终端设备选取的安全算法、该第二密钥、基于该第二密钥生成完整性保护密钥和/或机密性保护密钥、该第二终端设备选取的安全策略,与该第二终端设备进行通信。
在一些实施例中,该处理单元1120用于根据该第一密钥解密该第二消息;
在该第二消息中携带的信息未遭受篡改的情况下,该处理单元1120用于至少根据该第一随机数、该第一密钥和该第二随机数生成该第二密钥,该处理单元1120用于根据该第二密钥生成完整性保护密钥和/或机密性保护密钥,以及该处理单元1120用于将该M个比特位和该N个比特位合并得到该第一密钥的标识,该处理单元1120用于生成该第二密钥的标识的y个比特位,并将该x个比特位和该y个比特位合并得到该第二密钥的标识;
在该第二消息验证码和该第三消息验证码有效的情况下,该通信单元1110还用于根据该第二终端设备选取的安全算法、该第二密钥、基于该第二密钥生成完整性保护密钥和/或机密性保护密钥、 该第二终端设备选取的安全策略,与该第二终端设备进行通信。
在一些实施例中,该完整性保护密钥的输入参数包括以下至少之一:该第二密钥,选定的算法类型标识符,选定的算法类型标识符的长度,完整性保护算法标识,完整性保护算法标识的长度;和/或,该机密性保护密钥的输入参数包括以下至少之一:该第二密钥,选定的算法类型标识符,选定的算法类型标识符的长度,机密性保护算法标识,机密性保护算法标识的长度。
在一些实施例中,该第一消息为认证响应消息,该第二消息为安全模式命令消息。
在一些实施例中,该第一消息为安全模式命令消息,该第二消息为安全模式响应消息。
在一些实施例中,该通信单元1110还用于通过该中继设备向该第二终端设备发送第三消息;
其中,该第三消息用于指示安全模式建立完成,该第三消息通过目标密钥进行加密,且该第三消息包括以下至少之一:该第二密钥的标识的该y个比特位,第四消息验证码;
其中,该目标密钥包括以下之一:该第一密钥,该第二密钥,该第二密钥派生的机密性保护密钥;
其中,该第三消息通过基于该第二密钥生成的该第四消息验证码进行完整性保护,或者,该第三消息通过基于该第二密钥派生的完整性保护密钥生成的该第四消息验证码进行完整性保护,该第四消息验证码的输入参数包括该y个比特位。
在一些实施例中,该通信单元1110还用于接收该第二终端设备通过该中继设备发送的错误消息;其中,该错误消息包括以下至少之一:原因信息,第五消息验证码;其中,该原因信息用于指示该第二终端设备与该第一终端设备的安全策略冲突,或者,该原因信息用于指示该第一消息验证码验证失败,或者,该原因信息用于指示该第二终端设备与该第一终端设备的安全算法协商失败,该第五消息验证码的输入参数包括以下至少之一:该原因信息;
在该第五消息验证码有效的情况下,该处理单元1120用于确定安全模式建立失败,和/或,该处理单元1120用于重新发起安全模式建立流程。
在一些实施例中,该完整性保护密钥包括控制面的完整性保护密钥和用户面的完整性保护密钥;和/或,该机密性保护密钥包括控制面的机密性保护密钥和用户面的机密性保护密钥。
在一些实施例中,该通信单元1110还用于接收该第二终端设备通过该中继设备发送的认证请求消息;
其中,该认证请求消息包括以下至少之一:该第二终端设备所属用户的信息,该中继设备所属用户的信息,该第二终端设备生成的第一临时公钥,该第二终端设备的签名,该中继设备的签名,该中继设备的相关信息;
其中,该第二终端设备所属用户的信息包括该第二终端设备的签名证书,或者,该第二终端设备所属用户的信息包括该第二终端设备的标识和该第二终端设备的PVT和KPAK;该中继设备所属用户的信息包括该中继设备的签名证书,或者,该中继设备所属用户的信息包括该中继设备的标识和该中继设备的PVT和KPAK;该第二终端设备的签名的输入参数包括以下至少之一:该第二终端设备所属用户的信息和该第一临时公钥;该中继设备的签名的输入参数包括以下至少之一:该第二终端设备的签名和该中继设备所属用户的信息;该第一临时公钥和该中继设备的相关信息用于该第一终端设备派生该第一密钥。
在一些实施例中,在该第二终端设备所属用户的信息包括该第二终端设备的签名证书的情况下,该第二终端设备的签名由该第二终端设备的签名私钥生成,或者,在该第二终端设备所属用户的信息包括该第二终端设备的标识和该第二终端设备的PVT和KPAK的情况下,该第二终端设备的签名由该第二终端设备的秘密签名密钥生成;和/或,
在该中继设备所属用户的信息包括该中继设备的签名证书的情况下,该中继设备的签名由该中继设备的签名私钥生成,或者,在该中继设备所属用户的信息包括该中继设备的标识和该中继设备的PVT和KPAK的情况下,该中继设备的签名由该中继设备的秘密签名密钥生成。
在一些实施例中,该终端设备1100还包括:处理单元1120;
在该第二终端设备的签名证书和该中继设备的签名证书有效,且基于该第二终端设备的签名证书对该第二终端设备的签名验证成功,以及基于该中继设备的签名证书对该中继设备的签名验证成功的情况下,该处理单元1120用于生成与该第二临时公钥配对的第二临时私钥,以及该处理单元1120用于根据该第一临时公钥、该中继设备的相关信息和该第二临时私钥派生该第一密钥;或者,
在该第二终端设备的KPAK和该中继设备的KPAK有效,且基于该第二终端设备的标识和该第二终端设备的PVT对该第二终端设备的签名验证成功,以及基于该中继设备的标识和该中继设备的PVT对该中继设备的签名验证成功的情况下,该处理单元1120用于生成与该第二临时公钥配对的第二临时私钥,以及该处理单元1120用于根据该第一临时公钥、该中继设备的相关信息和该第二临时私钥派生该第一密钥。
在一些实施例中,该通信单元1110还用于通过该中继设备向该第二终端设备发送直接通信请求;
其中,该直接通信请求包括以下至少之一:源标识,目标标识;
其中,该源标识用于标识该第一终端设备与该第二终端设备之间的中继连接的源端,该目标标识用于标识该第一终端设备与该第二终端设备之间的中继连接的目标端。
在一些实施例中,上述通信单元可以是通信接口或收发器,或者是通信芯片或者片上系统的输入输出接口。上述处理单元可以是一个或多个处理器。
应理解,根据本申请实施例的终端设备1100可对应于本申请方法实施例中的第一终端设备,并且终端设备1100中的各个单元的上述和其它操作和/或功能分别为了实现图10所示方法500中第一终端设备的相应流程,为了简洁,在此不再赘述。
图20示出了根据本申请实施例的终端设备1200的示意性框图。如图20所示,该终端设备1200为第二终端设备,该终端设备1200包括:
通信单元1210,用于接收第一终端设备通过中继设备发送的第一消息;
其中,该第一消息包括以下至少之一:该第一终端设备的安全能力信息,该第一终端设备的安全策略信息,该第一终端设备所属用户的信息,该中继设备所属用户的信息,该第一终端设备生成的第一随机数,该第一终端设备生成的第二临时公钥,该第一终端设备生成的第一密钥的标识的M个比特位,该第一终端设备的签名,该中继设备的签名,第一消息验证码;
其中,该第一终端设备所属用户的信息包括该第一终端设备的签名证书,或者,该第一终端设备所属用户的信息包括该第一终端设备的标识和该第一终端设备的公共验证令牌PVT和密钥管理服务器的公共认证密钥KPAK;该中继设备所属用户的信息包括该中继设备的签名证书,或者,该中继设备所属用户的信息包括该中继设备的标识和该中继设备的PVT和KPAK;该第一终端设备的签名的输入参数包括以下至少之一:该第一终端设备所属用户的信息,该第二临时公钥,该第一密钥的标识的M个比特位,该第二终端设备的签名;该中继设备的签名的输入参数包括以下至少之一:该中继设备所属用户的信息,该第一终端设备的签名,该第二终端设备的签名;
其中,该第一消息通过基于该第一密钥生成的该第一消息验证码进行完整性保护,且该第一消息验证码的输入参数包括以下至少之一:该第一终端设备的安全能力信息,该第一终端设备的安全策略信息,该第一终端设备所属用户的信息,该第一随机数,该第二临时公钥,该M个比特位,该第一终端设备的签名;
其中,该第二临时公钥和该中继设备的相关信息用于该第二终端设备派生该第一密钥,该第一随机数、该第一密钥和该第二终端设备生成的第二随机数用于派生第二密钥,该第二密钥用于派生完整性保护密钥和/或机密性保护密钥,该第一密钥的标识由该M个比特位与该第一密钥的标识的另外N个比特位合并得到,M和N均为正整数;
其中,该中继设备的相关信息包括以下之一:该中继设备的身份信息,该中继设备生成的随机数,该中继设备生成的计数器。
在一些实施例中,在该第一终端设备所属用户的信息包括该第一终端设备的签名证书的情况下,该第一终端设备的签名由该第一终端设备的签名私钥生成,或者,在该第一终端设备所属用户的信息包括该第一终端设备的标识和该第一终端设备的PVT和KPAK的情况下,该第一终端设备的签名由该第一终端设备的秘密签名密钥生成;和/或,
在该中继设备所属用户的信息包括该中继设备的签名证书的情况下,该中继设备的签名由该中继设备的签名私钥生成,或者,在该中继设备所属用户的信息包括该中继设备的标识和该中继设备的PVT和KPAK的情况下,该中继设备的签名由该中继设备的秘密签名密钥生成。
在一些实施例中,该终端设备1200还包括:处理单元1220;
该处理单元1220用于分别检查该第一终端设备的签名证书和该中继设备的签名证书,在该第一终端设备的签名证书和该中继设备的签名证书有效的情况下,该处理单元1220用于基于该第一终端设备的签名证书对该第一终端设备的签名进行验证,以及该第二终端设备基于该中继设备的签名证书对该中继设备的签名进行验证;或者,该处理单元1220用于分别检查该第一终端设备的KPAK和该中继设备的KPAK,在该第一终端设备的KPAK和该中继设备的KPAK有效的情况下,且基于该第一终端设备的标识和该第一终端设备的PVT对该第一终端设备的签名进行验证,以及基于该中继设备的标识和该中继设备的PVT对该中继设备的签名进行验证;
在该第一终端设备的签名和该中继设备的签名验证成功,且该第一消息中携带的信息未遭受篡改的情况下,该处理单元1220用于生成第二随机数,该处理单元1220用于至少根据该第一随机数、该第一密钥和该第二随机数生成该第二密钥,该处理单元1220用于根据该第二密钥生成完整性保护密钥和/或机密性保护密钥,以及该处理单元1220用于生成该第一密钥的标识的N个比特位,并将该M 个比特位和该N个比特位合并得到该第一密钥的标识;
在该第一消息验证码有效的情况下,该通信单元1210还用于通过该中继设备向该第一终端设备发送第二消息;其中,该第二消息包括以下至少之一:该第二随机数,该N个比特位,该第二终端设备生成的该第二密钥的标识的x个比特位,该第二终端设备选取的安全算法,该第二终端设备选取的安全策略,第二消息验证码;
其中,该第二消息通过基于该第二密钥生成的该第二消息验证码进行完整性保护,或者,该第二消息通过基于该第二密钥派生的完整性保护密钥生成的该第二消息验证码进行完整性保护,且该第二消息验证码的输入参数包括以下至少之一:该第二随机数,该N个比特位,该x个比特位,该第二终端设备选取的安全算法,该第二终端设备选取的安全策略;
其中,该第二密钥的标识由该x个比特位与该第二密钥的标识的另外y个比特位合并得到,x和y均为正整数。
在一些实施例中,该第二消息通过该第一密钥进行加密,且该第二消息还包括第三消息验证码;
其中,该第二消息通过基于该第一密钥生成的该第三消息验证码进行完整性保护,且该第三消息验证码的输入参数包括以下至少之一:该第二随机数,该N个比特位,该x个比特位,该第二终端设备选取的安全算法,该第二终端设备选取的安全策略。
在一些实施例中,该第一消息为认证响应消息,该第二消息为安全模式命令消息。
在一些实施例中,该第一消息为安全模式命令消息,该第二消息为安全模式响应消息。
在一些实施例中,该完整性保护密钥的输入参数包括以下至少之一:该第二密钥,选定的算法类型标识符,选定的算法类型标识符的长度,完整性保护算法标识,完整性保护算法标识的长度;和/或,该机密性保护密钥的输入参数包括以下至少之一:该第二密钥,选定的算法类型标识符,选定的算法类型标识符的长度,机密性保护算法标识,机密性保护算法标识的长度。
在一些实施例中,该通信单元1210还用于接收该第一终端设备通过该中继设备发送的第三消息;
其中,该第三消息用于指示安全模式建立完成,该第三消息通过目标密钥进行加密,且该第三消息包括以下至少之一:该第一终端设备生成的该第二密钥的标识的y个比特位,第四消息验证码;
其中,该目标密钥包括以下之一:该第一密钥,该第二密钥,该第二密钥派生的机密性保护密钥;
其中,该第三消息通过基于该第二密钥生成的该第四消息验证码进行完整性保护,或者,该第三消息通过基于该第二密钥派生的完整性保护密钥生成的该第四消息验证码进行完整性保护,该第四消息验证码的输入参数包括该y个比特位。
在一些实施例中,该终端设备1200还包括:处理单元1220;
该处理单元1220用于通过该目标密钥对该第三消息进行解密;
在该第三消息中携带的信息未遭受篡改的情况下,且该第四消息验证码有效的情况下,该处理单元1220还用于将该x个比特位与该y个比特位合并得到该第二密钥的标识。
在一些实施例中,该通信单元1210还用于通过该中继设备向该第一终端设备发送错误消息;其中,该错误消息包括以下至少之一:原因信息,第五消息验证码;其中,该原因信息用于指示该第二终端设备与该第一终端设备的安全策略冲突,或者,该原因信息用于指示该第一消息验证码验证失败,或者,该原因信息用于指示该第二终端设备与该第一终端设备的安全算法协商失败,该第五消息验证码的输入参数包括以下至少之一:该原因信息。
在一些实施例中,该完整性保护密钥包括控制面的完整性保护密钥和用户面的完整性保护密钥;和/或,该机密性保护密钥包括控制面的机密性保护密钥和用户面的机密性保护密钥。
在一些实施例中,该通信单元1210还用于通过该中继设备向该第一终端设备发送认证请求消息;
其中,该认证请求消息包括以下至少之一:该第二终端设备所属用户的信息,该第二终端设备生成的第一临时公钥,该第二终端设备的签名,该中继设备的相关信息;
其中,该第二终端设备所属用户的信息包括该第二终端设备的签名证书,或者,该第二终端设备所属用户的信息包括该第二终端设备的标识和该第二终端设备的公共验证令牌PVT和密钥管理服务器的公共认证密钥KPAK;该第二终端设备的签名的输入参数包括以下至少之一:该第二终端设备所属用户的信息和该第一临时公钥;该第一临时公钥和该中继设备的相关信息用于该第一终端设备派生第一密钥。
在一些实施例中,在该第二终端设备所属用户的信息包括该第二终端设备的签名证书的情况下,该第二终端设备的签名由该第二终端设备的签名私钥生成,或者,在该第二终端设备所属用户的信息包括该第二终端设备的标识和该第二终端设备的PVT和KPAK的情况下,该第二终端设备的签名由该第二终端设备的秘密签名密钥生成。
在一些实施例中,该通信单元1210还用于接收该第一终端设备通过该中继设备发送的直接通信 请求;
其中,该直接通信请求包括以下至少之一:源标识,目标标识;
其中,该源标识用于标识该第一终端设备与该第二终端设备之间的中继连接的源端,该目标标识用于标识该第一终端设备与该第二终端设备之间的中继连接的目标端。
在一些实施例中,上述通信单元可以是通信接口或收发器,或者是通信芯片或者片上系统的输入输出接口。上述处理单元可以是一个或多个处理器。
应理解,根据本申请实施例的终端设备1200可对应于本申请方法实施例中的第二终端设备,并且终端设备1200中的各个单元的上述和其它操作和/或功能分别为了实现图11所示方法600中第二终端设备的相应流程,为了简洁,在此不再赘述。
图21示出了根据本申请实施例的中继设备1300的示意性框图。如图21所示,该中继设备1300包括:
通信单元1310,用于接收第一终端设备发送的第一消息;
其中,该第一消息包括以下至少之一:该第一终端设备的安全能力信息,该第一终端设备的安全策略信息,该第一终端设备所属用户的信息,该第一终端设备生成的第一随机数,该第一终端设备生成的第二临时公钥,该第一终端设备生成的第一密钥的标识的M个比特位,该第一终端设备的签名,第一消息验证码;其中,该第一终端设备所属用户的信息包括该第一终端设备的签名证书,或者,该第一终端设备所属用户的信息包括该第一终端设备的标识和该第一终端设备的公共验证令牌PVT和密钥管理服务器的公共认证密钥KPAK;该第一终端设备的签名的输入参数包括以下至少之一:该第一终端设备所属用户的信息,该第二临时公钥,该第一密钥的标识的M个比特位,该第二终端设备的签名;其中,该第一消息通过基于该第一密钥生成的该第一消息验证码进行完整性保护,且该第一消息验证码的输入参数包括以下至少之一:该第一终端设备的安全能力信息,该第一终端设备的安全策略信息,该第一终端设备所属用户的信息,该第一随机数,该第二临时公钥,该M个比特位,该第一终端设备的签名;
在该第一终端设备的签名证书有效,且基于该第一终端设备的签名证书对该第一终端设备的签名验证成功的情况下,或者,在该第一终端设备的KPAK有效,且基于该第一终端设备的标识和该第一终端设备的PVT对该第一终端设备的签名验证成功的情况下,该通信单元1310还用于向该第二终端设备发送验证之后的第一消息;其中,该验证之后的第一消息包括以下至少之一:该第一终端设备的安全能力信息,该第一终端设备的安全策略信息,该第一终端设备所属用户的信息,该中继设备所属用户的信息,该第一终端设备生成的第一随机数,该第一终端设备生成的与该第二临时私钥配对的第二临时公钥,该第一终端设备生成的该第一密钥的标识的M个比特位,该第一终端设备的签名,该中继设备的签名,该中继设备的相关信息,该第一消息验证码;其中,该中继设备所属用户的信息包括该中继设备的签名证书,或者,该中继设备所属用户的信息包括该中继设备的标识和该中继设备的PVT和KPAK;该中继设备的签名的输入参数包括以下至少之一:该中继设备所属用户的信息,该第一终端设备的签名,该第二终端设备的签名,该验证之后的第一消息;
其中,该第二临时公钥和该中继设备的相关信息用于该第二终端设备派生该第一密钥,该第一随机数、该第一密钥和该第二终端设备生成的第二随机数用于派生第二密钥,该第二密钥用于派生完整性保护密钥和/或机密性保护密钥,该第一密钥的标识由该M个比特位与该第一密钥的标识的另外N个比特位合并得到,M和N均为正整数;其中,该中继设备的相关信息包括以下之一:该中继设备的身份信息,该中继设备生成的随机数,该中继设备生成的计数器。
在一些实施例中,该通信单元1310还用于将该第二终端设备发送的第二消息转发至该第一终端设备;其中,该第二消息包括以下至少之一:该第二终端设备生成的该第二随机数,该第二终端设备生成的该第一密钥的标识的N个比特位,该第二终端设备生成的该第二密钥的标识的x个比特位,该第二终端设备选取的安全算法,该第二终端设备选取的安全策略,第二消息验证码;其中,该第二消息通过基于该第二密钥生成的该第二消息验证码进行完整性保护,或者,该第二消息通过基于该第二密钥派生的完整性保护密钥生成的该第二消息验证码进行完整性保护,且该第二消息验证码的输入参数包括以下至少之一:该第二随机数,该N个比特位,该x个比特位,该第二终端设备选取的安全算法,该第二终端设备选取的安全策略;其中,该第二密钥的标识由该x个比特位与该第二密钥的标识的另外y个比特位合并得到,x和y均为正整数。
在一些实施例中,该第二消息通过该第一密钥进行加密,且该第二消息还包括第三消息验证码;
其中,该第二消息通过基于该第一密钥生成的该第三消息验证码进行完整性保护,且该第三消息验证码的输入参数包括以下至少之一:该第二随机数,该N个比特位,该x个比特位,该第二终端设备选取的安全算法,该第二终端设备选取的安全策略。
在一些实施例中,该第一消息为认证响应消息,该第二消息为安全模式命令消息。
在一些实施例中,该第一消息为安全模式命令消息,该第二消息为安全模式响应消息。
在一些实施例中,该通信单元1310还用于将该第一终端设备发送的第三消息转发至该第二终端设备;其中,该第三消息用于指示安全模式建立完成,该第三消息通过目标密钥进行加密,且该第三消息包括以下至少之一:该第一终端设备生成的该第二密钥的标识的y个比特位,第四消息验证码;其中,该目标密钥包括以下之一:该第一密钥,该第二密钥,该第二密钥派生的机密性保护密钥;其中,该第三消息通过基于该第二密钥生成的该第四消息验证码进行完整性保护,或者,该第三消息通过基于该第二密钥派生的完整性保护密钥生成的该第四消息验证码进行完整性保护,该第四消息验证码的输入参数包括该y个比特位。
在一些实施例中,该通信单元1310还用于将该第二终端设备发送的错误消息转发至该第一终端设备;其中,该错误消息包括以下至少之一:原因信息,第五消息验证码;其中,该原因信息用于指示该第二终端设备与该第一终端设备的安全策略冲突,或者,该原因信息用于指示该第一消息验证码验证失败,或者,该原因信息用于指示该第二终端设备与该第一终端设备的安全算法协商失败,该第五消息验证码的输入参数包括以下至少之一:该原因信息。
在一些实施例中,该完整性保护密钥包括控制面的完整性保护密钥和用户面的完整性保护密钥;和/或,该机密性保护密钥包括控制面的机密性保护密钥和用户面的机密性保护密钥。
在一些实施例中,该通信单元1310还用于接收该第二终端设备发送的认证请求消息;其中,该认证请求消息包括以下至少之一:该第二终端设备所属用户的信息,该第二终端设备生成的第一临时公钥,该第二终端设备的签名;其中,该第二终端设备所属用户的信息包括该第二终端设备的签名证书,或者,该第二终端设备所属用户的信息包括该第二终端设备的标识和该第二终端设备的公共验证令牌PVT和密钥管理服务器的公共认证密钥KPAK;该第二终端设备的签名的输入参数包括以下至少之一:该第二终端设备所属用户的信息和该第一临时公钥;该第一临时公钥和该中继设备的相关信息用于该第一终端设备派生该第一密钥;
在该第二终端设备的签名证书有效,且基于该第二终端设备的签名证书对该第二终端设备的签名验证成功的情况下,或者,在该第二终端设备的KPAK有效,且基于该第二终端设备的标识和该第二终端设备的PVT对该第二终端设备的签名验证成功的情况下,该通信单元1310还用于向该第一终端设备发送验证之后的认证请求消息;其中,该验证之后的认证请求消息包括以下至少之一:该第二终端设备所属用户的信息,该中继设备所属用户的信息,该第一临时公钥,该第二终端设备的签名,该中继设备的签名,该中继设备的相关信息;其中,该中继设备所属用户的信息包括该中继设备的签名证书,或者,该中继设备所属用户的信息包括该中继设备的标识和该中继设备的PVT和KPAK;该中继设备的签名的输入参数包括以下至少之一:该第二终端设备的签名和该中继设备所属用户的信息。
在一些实施例中,在该第二终端设备所属用户的信息包括该第二终端设备的签名证书的情况下,该第二终端设备的签名由该第二终端设备的签名私钥生成,或者,在该第二终端设备所属用户的信息包括该第二终端设备的标识和该第二终端设备的PVT和KPAK的情况下,该第二终端设备的签名由该第二终端设备的秘密签名密钥生成;和/或,
在该中继设备所属用户的信息包括该中继设备的签名证书的情况下,该中继设备的签名由该中继设备的签名私钥生成,或者,在该中继设备所属用户的信息包括该中继设备的标识和该中继设备的PVT和KPAK的情况下,该中继设备的签名由该中继设备的秘密签名密钥生成。
在一些实施例中,该通信单元1310还用于将该第一终端设备发送的直接通信请求转发至该第二终端设备;其中,该直接通信请求包括以下至少之一:源标识,目标标识;其中,该源标识用于标识该第一终端设备与该第二终端设备之间的中继连接的源端,该目标标识用于标识该第一终端设备与该第二终端设备之间的中继连接的目标端。
在一些实施例中,上述通信单元可以是通信接口或收发器,或者是通信芯片或者片上系统的输入输出接口。
应理解,根据本申请实施例的中继设备1300可对应于本申请方法实施例中的中继设备,并且中继设备1300中的各个单元的上述和其它操作和/或功能分别为了实现图12所示方法700中中继设备的相应流程,为了简洁,在此不再赘述。
图22是本申请实施例提供的一种通信设备1400示意性结构图。图22所示的通信设备1400包括处理器1410,处理器1410可以从存储器中调用并运行计算机程序,以实现本申请实施例中的方法。
在一些实施例中,如图22所示,通信设备1400还可以包括存储器1420。其中,处理器1410可以从存储器1420中调用并运行计算机程序,以实现本申请实施例中的方法。
其中,存储器1420可以是独立于处理器1410的一个单独的器件,也可以集成在处理器1410中。
在一些实施例中,如图22所示,通信设备1400还可以包括收发器1430,处理器1410可以控制该收发器1430与其他设备进行通信,具体地,可以向其他设备发送信息或数据,或接收其他设备发送的信息或数据。
其中,收发器1430可以包括发射机和接收机。收发器1430还可以进一步包括天线,天线的数量可以为一个或多个。
在一些实施例中,该通信设备1400具体可为本申请实施例的终端设备,并且该通信设备1400可以实现本申请实施例的各个方法中由第一终端设备或第二终端设备实现的相应流程,为了简洁,在此不再赘述。
在一些实施例中,该通信设备1400具体可为本申请实施例的中继设备,并且该通信设备1400可以实现本申请实施例的各个方法中由中继设备实现的相应流程,为了简洁,在此不再赘述。
图23是本申请实施例的装置的示意性结构图。图23所示的装置1500包括处理器1510,处理器1510可以从存储器中调用并运行计算机程序,以实现本申请实施例中的方法。
在一些实施例中,如图23所示,装置1500还可以包括存储器1520。其中,处理器1510可以从存储器1520中调用并运行计算机程序,以实现本申请实施例中的方法。
其中,存储器1520可以是独立于处理器1510的一个单独的器件,也可以集成在处理器1510中。
在一些实施例中,该装置1500还可以包括输入接口1530。其中,处理器1510可以控制该输入接口1530与其他设备或芯片进行通信,具体地,可以获取其他设备或芯片发送的信息或数据。
在一些实施例中,该装置1500还可以包括输出接口1540。其中,处理器1510可以控制该输出接口1540与其他设备或芯片进行通信,具体地,可以向其他设备或芯片输出信息或数据。
在一些实施例中,该装置可应用于本申请实施例中的终端设备,并且该装置可以实现本申请实施例的各个方法中由第一终端设备或第二终端设备实现的相应流程,为了简洁,在此不再赘述。
在一些实施例中,该装置可应用于本申请实施例中的中继设备,并且该装置可以实现本申请实施例的各个方法中由中继设备实现的相应流程,为了简洁,在此不再赘述。
在一些实施例中,本申请实施例提到的装置也可以是芯片。例如可以是系统级芯片,系统芯片,芯片系统或片上系统芯片等。
图24是本申请实施例提供的一种通信系统1600的示意性框图。如图24所示,该通信系统1600包括第一终端设备1610、中继设备1620和第二终端设备1630。
其中,该第一终端设备1610可以用于实现上述方法中由第一终端设备实现的相应的功能,该中继设备1620可以用于实现上述方法中由中继设备实现的相应的功能,以及该第二终端设备1630可以用于实现上述方法中由第二终端设备实现的相应的功能,为了简洁,在此不再赘述。
应理解,本申请实施例的处理器可能是一种集成电路芯片,具有信号的处理能力。在实现过程中,上述方法实施例的各步骤可以通过处理器中的硬件的集成逻辑电路或者软件形式的指令完成。上述的处理器可以是通用处理器、数字信号处理器(Digital Signal Processor,DSP)、专用集成电路(Application Specific Integrated Circuit,ASIC)、现成可编程门阵列(Field Programmable Gate Array,FPGA)或者其他可编程逻辑器件、分立门或者晶体管逻辑器件、分立硬件组件。可以实现或者执行本申请实施例中的公开的各方法、步骤及逻辑框图。通用处理器可以是微处理器或者该处理器也可以是任何常规的处理器等。结合本申请实施例所公开的方法的步骤可以直接体现为硬件译码处理器执行完成,或者用译码处理器中的硬件及软件模块组合执行完成。软件模块可以位于随机存储器,闪存、只读存储器,可编程只读存储器或者电可擦写可编程存储器、寄存器等本领域成熟的存储介质中。该存储介质位于存储器,处理器读取存储器中的信息,结合其硬件完成上述方法的步骤。
可以理解,本申请实施例中的存储器可以是易失性存储器或非易失性存储器,或可包括易失性和非易失性存储器两者。其中,非易失性存储器可以是只读存储器(Read-Only Memory,ROM)、可编程只读存储器(Programmable ROM,PROM)、可擦除可编程只读存储器(Erasable PROM,EPROM)、电可擦除可编程只读存储器(Electrically EPROM,EEPROM)或闪存。易失性存储器可以是随机存取存储器(Random Access Memory,RAM),其用作外部高速缓存。通过示例性但不是限制性说明,许多形式的RAM可用,例如静态随机存取存储器(Static RAM,SRAM)、动态随机存取存储器(Dynamic RAM,DRAM)、同步动态随机存取存储器(Synchronous DRAM,SDRAM)、双倍数据速率同步动态随机存取存储器(Double Data Rate SDRAM,DDR SDRAM)、增强型同步动态随机存取存储器(Enhanced SDRAM,ESDRAM)、同步连接动态随机存取存储器(Synchlink DRAM,SLDRAM)和直接内存总线随机存取存储器(Direct Rambus RAM,DR RAM)。应注意,本文描述的系统和方法的存储器旨在包括但不限于这些和任意其它适合类型的存储器。
应理解,上述存储器为示例性但不是限制性说明,例如,本申请实施例中的存储器还可以是静态随机存取存储器(static RAM,SRAM)、动态随机存取存储器(dynamic RAM,DRAM)、同步动态随机存取存储器(synchronous DRAM,SDRAM)、双倍数据速率同步动态随机存取存储器(double data rate SDRAM,DDR SDRAM)、增强型同步动态随机存取存储器(enhanced SDRAM,ESDRAM)、同步连接动态随机存取存储器(synch link DRAM,SLDRAM)以及直接内存总线随机存取存储器(Direct Rambus RAM,DR RAM)等等。也就是说,本申请实施例中的存储器旨在包括但不限于这些和任意其它适合类型的存储器。
本申请实施例还提供了一种计算机可读存储介质,用于存储计算机程序。
在一些实施例中,该计算机可读存储介质可应用于本申请实施例中的终端设备,并且该计算机程序使得计算机执行本申请实施例的各个方法中由第一终端设备或第二终端设备实现的相应流程,为了简洁,在此不再赘述。
在一些实施例中,该计算机可读存储介质可应用于本申请实施例中的中继设备,并且该计算机程序使得计算机执行本申请实施例的各个方法中由中继设备实现的相应流程,为了简洁,在此不再赘述。
本申请实施例还提供了一种计算机程序产品,包括计算机程序指令。
在一些实施例中,该计算机程序产品可应用于本申请实施例中的终端设备,并且该计算机程序指令使得计算机执行本申请实施例的各个方法中由第一终端设备或第二终端设备实现的相应流程,为了简洁,在此不再赘述。
在一些实施例中,该计算机程序产品可应用于本申请实施例中的中继设备,并且该计算机程序指令使得计算机执行本申请实施例的各个方法中由中继设备实现的相应流程,为了简洁,在此不再赘述。
本申请实施例还提供了一种计算机程序。
在一些实施例中,该计算机程序可应用于本申请实施例中的终端设备,当该计算机程序在计算机上运行时,使得计算机执行本申请实施例的各个方法中由第一终端设备或第二终端设备实现的相应流程,为了简洁,在此不再赘述。
在一些实施例中,该计算机程序可应用于本申请实施例中的中继设备,当该计算机程序在计算机上运行时,使得计算机执行本申请实施例的各个方法中由中继设备实现的相应流程,为了简洁,在此不再赘述。
本领域普通技术人员可以意识到,结合本文中所公开的实施例描述的各示例的单元及算法步骤,能够以电子硬件、或者计算机软件和电子硬件的结合来实现。这些功能究竟以硬件还是软件方式来执行,取决于技术方案的特定应用和设计约束条件。专业技术人员可以对每个特定的应用来使用不同方法来实现所描述的功能,但是这种实现不应认为超出本申请的范围。
所属领域的技术人员可以清楚地了解到,为描述的方便和简洁,上述描述的系统、装置和单元的具体工作过程,可以参考前述方法实施例中的对应过程,在此不再赘述。
在本申请所提供的几个实施例中,应该理解到,所揭露的系统、装置和方法,可以通过其它的方式实现。例如,以上所描述的装置实施例仅仅是示意性的,例如,所述单元的划分,仅仅为一种逻辑功能划分,实际实现时可以有另外的划分方式,例如多个单元或组件可以结合或者可以集成到另一个系统,或一些特征可以忽略,或不执行。另一点,所显示或讨论的相互之间的耦合或直接耦合或通信连接可以是通过一些接口,装置或单元的间接耦合或通信连接,可以是电性,机械或其它的形式。
所述作为分离部件说明的单元可以是或者也可以不是物理上分开的,作为单元显示的部件可以是或者也可以不是物理单元,即可以位于一个地方,或者也可以分布到多个网络单元上。可以根据实际的需要选择其中的部分或者全部单元来实现本实施例方案的目的。
另外,在本申请各个实施例中的各功能单元可以集成在一个处理单元中,也可以是各个单元单独物理存在,也可以两个或两个以上单元集成在一个单元中。
所述功能如果以软件功能单元的形式实现并作为独立的产品销售或使用时,可以存储在一个计算机可读取存储介质中。针对这样的理解,本申请的技术方案本质上或者说对现有技术做出贡献的部分或者该技术方案的部分可以以软件产品的形式体现出来,该计算机软件产品存储在一个存储介质中,包括若干指令用以使得一台计算机设备(可以是个人计算机,服务器,或者网络设备等)执行本申请各个实施例所述方法的全部或部分步骤。而前述的存储介质包括:U盘、移动硬盘、只读存储器(Read-Only Memory,ROM)、随机存取存储器(Random Access Memory,RAM)、磁碟或者光盘等各种可以存储程序代码的介质。
以上所述,仅为本申请的具体实施方式,但本申请的保护范围并不局限于此,任何熟悉本技术领域的技术人员在本申请揭露的技术范围内,可轻易想到变化或替换,都应涵盖在本申请的保护范围之内。因此,本申请的保护范围应所述以权利要求的保护范围为准。
Claims (92)
- 一种中继通信的方法,其特征在于,包括:第一终端设备接收第二终端设备通过中继设备发送的认证请求消息;其中,所述认证请求消息包括以下至少之一:所述第二终端设备所属用户的信息,所述中继设备所属用户的信息,所述第二终端设备生成的第一临时公钥,所述第二终端设备的签名,所述中继设备的签名,所述中继设备的相关信息;其中,所述第二终端设备所属用户的信息包括所述第二终端设备的签名证书,或者,所述第二终端设备所属用户的信息包括所述第二终端设备的标识和所述第二终端设备的公共验证令牌PVT和密钥管理服务器的公共认证密钥KPAK;所述中继设备所属用户的信息包括所述中继设备的签名证书,或者,所述中继设备所属用户的信息包括所述中继设备的标识和所述中继设备的PVT和KPAK;所述第二终端设备的签名的输入参数包括以下至少之一:所述第二终端设备所属用户的信息和所述第一临时公钥;所述中继设备的签名的输入参数包括以下至少之一:所述第二终端设备的签名和所述中继设备所属用户的信息;所述第一临时公钥和所述中继设备的相关信息用于所述第一终端设备派生第一密钥;所述中继设备的相关信息包括以下之一:所述中继设备的身份信息,所述中继设备生成的随机数,所述中继设备生成的计数器。
- 如权利要求1所述的方法,其特征在于,在所述第二终端设备所属用户的信息包括所述第二终端设备的签名证书的情况下,所述第二终端设备的签名由所述第二终端设备的签名私钥生成,或者,在所述第二终端设备所属用户的信息包括所述第二终端设备的标识和所述第二终端设备的PVT和KPAK的情况下,所述第二终端设备的签名由所述第二终端设备的秘密签名密钥生成;和/或,在所述中继设备所属用户的信息包括所述中继设备的签名证书的情况下,所述中继设备的签名由所述中继设备的签名私钥生成,或者,在所述中继设备所属用户的信息包括所述中继设备的标识和所述中继设备的PVT和KPAK的情况下,所述中继设备的签名由所述中继设备的秘密签名密钥生成。
- 如权利要求1或2所述的方法,其特征在于,所述方法还包括:在所述第二终端设备的签名证书和所述中继设备的签名证书有效,且基于所述第二终端设备的签名证书对所述第二终端设备的签名验证成功,以及基于所述中继设备的签名证书对所述中继设备的签名验证成功的情况下,所述第一终端设备生成第二临时私钥,以及所述第一终端设备根据所述第一临时公钥、所述中继设备的相关信息和所述第二临时私钥派生所述第一密钥;或者,在所述第二终端设备的KPAK和所述中继设备的KPAK有效,且基于所述第二终端设备的标识和所述第二终端设备的PVT对所述第二终端设备的签名验证成功,以及基于所述中继设备的标识和所述中继设备的PVT对所述中继设备的签名验证成功的情况下,所述第一终端设备生成第二临时私钥,以及所述第一终端设备根据所述第一临时公钥、所述中继设备的相关信息和所述第二临时私钥派生所述第一密钥。
- 如权利要求3所述的方法,其特征在于,所述方法还包括:所述第一终端设备通过所述中继设备向所述第二终端设备发送第一消息;其中,所述第一消息包括以下至少之一:所述第一终端设备的安全能力信息,所述第一终端设备的安全策略信息,所述第一终端设备所属用户的信息,所述第一终端设备生成的第一随机数,所述第一终端设备生成的与所述第二临时私钥配对的第二临时公钥,所述第一终端设备生成的所述第一密钥的标识的M个比特位,所述第一终端设备的签名,第一消息验证码;其中,所述第一终端设备所属用户的信息包括所述第一终端设备的签名证书,或者,所述第一终端设备所属用户的信息包括所述第一终端设备的标识和所述第一终端设备的PVT和KPAK;所述第一终端设备的签名的输入参数包括以下至少之一:所述第一终端设备所属用户的信息,所述第二临时公钥,所述第一密钥的标识的M个比特位,所述第二终端设备的签名;其中,所述第一消息通过基于所述第一密钥生成的所述第一消息验证码进行完整性保护,且所述第一消息验证码的输入参数包括以下至少之一:所述第一终端设备的安全能力信息,所述第一终端设备的安全策略信息,所述第一终端设备所属用户的信息,所述第一随机数,所述第二临时公钥,所述M个比特位,所述第一终端设备的签名;其中,所述第二临时公钥和所述中继设备的相关信息用于所述第二终端设备派生所述第一密钥,所述第一随机数、所述第一密钥和所述第二终端设备生成的第二随机数用于派生第二密钥,所述第二密钥用于派生完整性保护密钥和/或机密性保护密钥,所述第一密钥的标识由所述M个比特位与所述第一密钥的标识的另外N个比特位合并得到,M和N均为正整数。
- 如权利要求4所述的方法,其特征在于,所述方法还包括:所述第一终端设备接收所述第二终端设备通过所述中继设备发送的第二消息;其中,所述第二消息包括以下至少之一:所述第二终端设备生成的所述第二随机数,所述第二终端设备生成的所述第一密钥的标识的N个比特位,所述第二终端设备生成的所述第二密钥的标识的x个比特位,所述第二终端设备选取的安全算法,所述第二终端设备选取的安全策略,第二消息验证码;其中,所述第二消息通过基于所述第二密钥生成的所述第二消息验证码进行完整性保护,或者,所述第二消息通过基于所述第二密钥派生的完整性保护密钥生成的所述第二消息验证码进行完整性保护,且所述第二消息验证码的输入参数包括以下至少之一:所述第二随机数,所述N个比特位,所述x个比特位,所述第二终端设备选取的安全算法,所述第二终端设备选取的安全策略;其中,所述第二密钥的标识由所述x个比特位与所述第二密钥的标识的另外y个比特位合并得到,x和y均为正整数。
- 如权利要求5所述的方法,其特征在于,所述第二消息通过所述第一密钥进行加密,且所述第二消息还包括第三消息验证码;其中,所述第二消息通过基于所述第一密钥生成的所述第三消息验证码进行完整性保护,且所述第三消息验证码的输入参数包括以下至少之一:所述第二随机数,所述N个比特位,所述x个比特位,所述第二终端设备选取的安全算法,所述第二终端设备选取的安全策略。
- 如权利要求5所述的方法,其特征在于,所述方法还包括:在所述第二消息中携带的信息未遭受篡改的情况下,所述第一终端设备至少根据所述第一随机数、所述第一密钥和所述第二随机数生成所述第二密钥,所述第一终端设备根据所述第二密钥生成完整性保护密钥和/或机密性保护密钥,以及所述第一终端设备将所述M个比特位和所述N个比特位合并得到所述第一密钥的标识,所述第一终端设备生成所述第二密钥的标识的y个比特位,并将所述x个比特位和所述y个比特位合并得到所述第二密钥的标识;在所述第二消息验证码有效的情况下,所述第一终端设备根据所述第二终端设备选取的安全算法、所述第二密钥、基于所述第二密钥生成完整性保护密钥和/或机密性保护密钥、所述第二终端设备选取的安全策略,与所述第二终端设备进行通信。
- 如权利要求6所述的方法,其特征在于,所述方法还包括:所述第一终端设备根据所述第一密钥解密所述第二消息;在所述第二消息中携带的信息未遭受篡改的情况下,所述第一终端设备至少根据所述第一随机数、所述第一密钥和所述第二随机数生成所述第二密钥,所述第一终端设备根据所述第二密钥生成完整性保护密钥和/或机密性保护密钥,以及所述第一终端设备将所述M个比特位和所述N个比特位合并得到所述第一密钥的标识,所述第一终端设备生成所述第二密钥的标识的y个比特位,并将所述x个比特位和所述y个比特位合并得到所述第二密钥的标识;在所述第二消息验证码有效和所述第三消息验证码的情况下,所述第一终端设备根据所述第二终端设备选取的安全算法、所述第二密钥、基于所述第二密钥生成完整性保护密钥和/或机密性保护密钥、所述第二终端设备选取的安全策略,与所述第二终端设备进行通信。
- 如权利要求7或8所述的方法,其特征在于,所述完整性保护密钥的输入参数包括以下至少之一:所述第二密钥,选定的算法类型标识符,选定的算法类型标识符的长度,完整性保护算法标识,完整性保护算法标识的长度;和/或,所述机密性保护密钥的输入参数包括以下至少之一:所述第二密钥,选定的算法类型标识符,选定的算法类型标识符的长度,机密性保护算法标识,机密性保护算法标识的长度。
- 如权利要求5或7所述的方法,其特征在于,所述第一消息为认证响应消息,所述第二消息为安全模式命令消息。
- 如权利要求6或8所述的方法,其特征在于,所述第一消息为安全模式命令消息,所述第二消息为安全模式响应消息。
- 如权利要求7至9中任一项所述的方法,其特征在于,所述方法还包括:所述第一终端设备通过所述中继设备向所述第二终端设备发送第三消息;其中,所述第三消息用于指示安全模式建立完成,所述第三消息通过目标密钥进行加密,且所述第三消息包括以下至少之一:所述第二密钥的标识的所述y个比特位,第四消息验证码;其中,所述目标密钥包括以下之一:所述第一密钥,所述第二密钥,所述第二密钥派生的机密性保护密钥;其中,所述第三消息通过基于所述第二密钥生成的所述第四消息验证码进行完整性保护,或者,所述第三消息通过基于所述第二密钥派生的完整性保护密钥生成的所述第四消息验证码进行完整性保护,所述第四消息验证码的输入参数包括所述y个比特位。
- 如权利要求4所述的方法,其特征在于,所述方法还包括:所述第一终端设备接收所述第二终端设备通过所述中继设备发送的错误消息;其中,所述错误消息包括以下至少之一:原因信息,第五消息验证码;其中,所述原因信息用于指示所述第二终端设备与所述第一终端设备的安全策略冲突,或者,所述原因信息用于指示所述第一消息验证码验证失败,或者,所述原因信息用于指示所述第二终端设备与所述第一终端设备的安全算法协商失败,所述第五消息验证码的输入参数包括以下至少之一:所述原因信息;在所述第五消息验证码有效的情况下,所述第一终端设备确定安全模式建立失败,和/或,所述第一终端设备重新发起安全模式建立流程。
- 如权利要求4至13中任一项所述的方法,其特征在于,所述完整性保护密钥包括控制面的完整性保护密钥和用户面的完整性保护密钥;和/或,所述机密性保护密钥包括控制面的机密性保护密钥和用户面的机密性保护密钥。
- 如权利要求1至14中任一项所述的方法,其特征在于,所述方法还包括:所述第一终端设备通过所述中继设备向所述第二终端设备发送直接通信请求;其中,所述直接通信请求包括以下至少之一:源标识,目标标识;其中,所述源标识用于标识所述第一终端设备与所述第二终端设备之间的中继连接的源端,所述目标标识用于标识所述第一终端设备与所述第二终端设备之间的中继连接的目标端。
- 一种中继通信的方法,其特征在于,包括:第二终端设备通过中继设备向第一终端设备发送认证请求消息;其中,所述认证请求消息包括以下至少之一:所述第二终端设备所属用户的信息,所述第二终端设备生成的第一临时公钥,所述第二终端设备的签名,所述中继设备的相关信息;其中,所述第二终端设备所属用户的信息包括所述第二终端设备的签名证书,或者,所述第二终端设备所属用户的信息包括所述第二终端设备的标识和所述第二终端设备的公共验证令牌PVT和密钥管理服务器的公共认证密钥KPAK;所述第二终端设备的签名的输入参数包括以下至少之一:所述第二终端设备所属用户的信息和所述第一临时公钥;所述第一临时公钥和所述中继设备的相关信息用于所述第一终端设备派生第一密钥;所述中继设备的相关信息包括以下之一:所述中继设备的身份信息,所述中继设备生成的随机数,所述中继设备生成的计数器。
- 如权利要求16所述的方法,其特征在于,在所述第二终端设备所属用户的信息包括所述第二终端设备的签名证书的情况下,所述第二终端设备的签名由所述第二终端设备的签名私钥生成,或者,在所述第二终端设备所属用户的信息包括所述第二终端设备的标识和所述第二终端设备的PVT和KPAK的情况下,所述第二终端设备的签名由所述第二终端设备的秘密签名密钥生成。
- 如权利要求16或17所述的方法,其特征在于,所述方法还包括:所述第二终端设备接收所述第一终端设备通过所述中继设备发送的第一消息;其中,所述第一消息包括以下至少之一:所述第一终端设备的安全能力信息,所述第一终端设备的安全策略信息,所述第一终端设备所属用户的信息,所述中继设备所属用户的信息,所述第一终端设备生成的第一随机数,所述第一终端设备生成的第二临时公钥,所述第一终端设备生成的所述第一密钥的标识的M个比特位,所述第一终端设备的签名,所述中继设备的签名,第一消息验证码;其中,所述第一终端设备所属用户的信息包括所述第一终端设备的签名证书,或者,所述第一终端设备所属用户的信息包括所述第一终端设备的标识和所述第一终端设备的PVT和KPAK;所述中继设备所属用户的信息包括所述中继设备的签名证书,或者,所述中继设备所属用户的信息包括所述中继设备的标识和所述中继设备的PVT和KPAK;所述第一终端设备的签名的输入参数包括以下至少之一:所述第一终端设备所属用户的信息,所述第二临时公钥,所述第一密钥的标识的M个比特位,所述第二终端设备的签名;所述中继设备的签名的输入参数包括以下至少之一:所述中继设备所属用户的信息,所述第一终端设备的签名,所述第二终端设备的签名,所述验证之后的第一消息;其中,所述第一消息通过基于所述第一密钥生成的所述第一消息验证码进行完整性保护,且所述第一消息验证码的输入参数包括以下至少之一:所述第一终端设备的安全能力信息,所述第一终端设备的安全策略信息,所述第一终端设备所属用户的信息,所述中继设备所属用户的信息,所述第一随机数,所述第二临时公钥,所述M个比特位,所述第一终端设备的签名,所述中继设备的签名;其中,所述第二临时公钥和所述中继设备的相关信息用于所述第二终端设备派生所述第一密钥,所述第一随机数、所述第一密钥和所述第二终端设备生成的第二随机数用于派生第二密钥,所述第二密钥用于派生完整性保护密钥和/或机密性保护密钥,所述第一密钥的标识由所述M个比特位与所述第一密钥的标识的另外N个比特位合并得到,M和N均为正整数。
- 如权利要求18所述的方法,其特征在于,在所述第一终端设备所属用户的信息包括所述第一终端设备的签名证书的情况下,所述第一终端设备的签名由所述第一终端设备的签名私钥生成,或者,在所述第一终端设备所属用户的信息包括所述第一终端设备的标识和所述第一终端设备的PVT和KPAK的情况下,所述第一终端设备的签名由所述第一终端设备的秘密签名密钥生成;和/或,在所述中继设备所属用户的信息包括所述中继设备的签名证书的情况下,所述中继设备的签名由所述中继设备的签名私钥生成,或者,在所述中继设备所属用户的信息包括所述中继设备的标识和所述中继设备的PVT和KPAK的情况下,所述中继设备的签名由所述中继设备的秘密签名密钥生成。
- 如权利要求19所述的方法,其特征在于,所述方法还包括:所述第二终端设备分别检查所述第一终端设备的签名证书和所述中继设备的签名证书,在所述第一终端设备的签名证书和所述中继设备的签名证书有效的情况下,所述第二终端设备基于所述第一终端设备的签名证书对所述第一终端设备的签名进行验证,以及所述第二终端设备基于所述中继设备的签名证书对所述中继设备的签名进行验证;或者,所述第二终端设备分别检查所述第一终端设备的KPAK和所述中继设备的KPAK,在所述第一终端设备的KPAK和所述中继设备的KPAK有效的情况下,且基于所述第一终端设备的标识和所述第一终端设备的PVT对所述第一终端设备的签名进行验证,以及基于所述中继设备的标识和所述中继设备的PVT对所述中继设备的签名进行验证;在所述第一终端设备的签名和所述中继设备的签名验证成功,且所述第一消息中携带的信息未遭受篡改的情况下,所述第二终端设备生成第二随机数,所述第二终端设备至少根据所述第一随机数、所述第一密钥和所述第二随机数生成所述第二密钥,所述第二终端设备根据所述第二密钥生成完整性保护密钥和/或机密性保护密钥,以及所述第二终端设备生成所述第一密钥的标识的N个比特位,并将所述M个比特位和所述N个比特位合并得到所述第一密钥的标识;在所述第一消息验证码有效的情况下,所述第二终端设备通过所述中继设备向所述第一终端设备发送第二消息;其中,所述第二消息包括以下至少之一:所述第二随机数,所述N个比特位,所述第二终端设备生成的所述第二密钥的标识的x个比特位,所述第二终端设备选取的安全算法,所述第二终端设备选取的安全策略,第二消息验证码;其中,所述第二消息通过基于所述第二密钥生成的所述第二消息验证码进行完整性保护,或者,所述第二消息通过基于所述第二密钥派生的完整性保护密钥生成的所述第二消息验证码进行完整性保护,且所述第二消息验证码的输入参数包括以下至少之一:所述第二随机数,所述N个比特位,所述x个比特位,所述第二终端设备选取的安全算法,所述第二终端设备选取的安全策略;其中,所述第二密钥的标识由所述x个比特位与所述第二密钥的标识的另外y个比特位合并得到,x和y均为正整数。
- 如权利要求20所述的方法,其特征在于,所述第二消息通过所述第一密钥进行加密,且所述第二消息还包括第三消息验证码;其中,所述第二消息通过基于所述第一密钥生成的所述第三消息验证码进行完整性保护,且所述第三消息验证码的输入参数包括以下至少之一:所述第二随机数,所述N个比特位,所述x个比特位,所述第二终端设备选取的安全算法,所述第二终端设备选取的安全策略。
- 如权利要求20所述的方法,其特征在于,所述第一消息为认证响应消息,所述第二消息为安全模式命令消息。
- 如权利要求21所述的方法,其特征在于,所述第一消息为安全模式命令消息,所述第二消息为安全模式响应消息。
- 如权利要求20至23中任一项所述的方法,其特征在于,所述完整性保护密钥的输入参数包括以下至少之一:所述第二密钥,选定的算法类型标识符,选定的算法类型标识符的长度,完整性保护算法标识,完整性保护算法标识的长度;和/或,所述机密性保护密钥的输入参数包括以下至少之一:所述第二密钥,选定的算法类型标识符,选定的算法类型标识符的长度,机密性保护算法标识,机密性保护算法标识的长度。
- 如权利要求20至24中任一项所述的方法,其特征在于,所述方法还包括:所述第二终端设备接收所述第一终端设备通过所述中继设备发送的第三消息;其中,所述第三消息用于指示安全模式建立完成,所述第三消息通过目标密钥进行加密,且所述第三消息包括以下至少之一:所述第一终端设备生成的所述第二密钥的标识的y个比特位,第四消息验证码;其中,所述目标密钥包括以下之一:所述第一密钥,所述第二密钥,所述第二密钥派生的机密性保护密钥;其中,所述第三消息通过基于所述第二密钥生成的所述第四消息验证码进行完整性保护,或者,所述第三消息通过基于所述第二密钥派生的完整性保护密钥生成的所述第四消息验证码进行完整性保护,所述第四消息验证码的输入参数包括所述y个比特位。
- 如权利要求25所述的方法,其特征在于,所述方法还包括:所述第二终端设备通过所述目标密钥对所述第三消息进行解密;在所述第三消息中携带的信息未遭受篡改的情况下,且所述第四消息验证码有效的情况下,所述第二终端设备将所述x个比特位与所述y个比特位合并得到所述第二密钥的标识。
- 如权利要求18所述的方法,其特征在于,所述方法还包括:所述第二终端设备通过所述中继设备向所述第一终端设备发送错误消息;其中,所述错误消息包括以下至少之一:原因信息,第五消息验证码;其中,所述原因信息用于指示所述第二终端设备与所述第一终端设备的安全策略冲突,或者,所述原因信息用于指示所述第一消息验证码验证失败,或者,所述原因信息用于指示所述第二终端设备与所述第一终端设备的安全算法协商失败,所述第五消息验证码的输入参数包括以下至少之一:所述原因信息。
- 如权利要求18至27中任一项所述的方法,其特征在于,所述完整性保护密钥包括控制面的完整性保护密钥和用户面的完整性保护密钥;和/或,所述机密性保护密钥包括控制面的机密性保护密钥和用户面的机密性保护密钥。
- 如权利要求16至28中任一项所述的方法,其特征在于,所述方法还包括:所述第二终端设备接收所述第一终端设备通过所述中继设备发送的直接通信请求;其中,所述直接通信请求包括以下至少之一:源标识,目标标识;其中,所述源标识用于标识所述第一终端设备与所述第二终端设备之间的中继连接的源端,所述目标标识用于标识所述第一终端设备与所述第二终端设备之间的中继连接的目标端。
- 一种中继通信的方法,其特征在于,包括:中继设备接收第二终端设备发送的认证请求消息;其中,所述认证请求消息包括以下至少之一:所述第二终端设备所属用户的信息,所述第二终端设备生成的第一临时公钥,所述第二终端设备的签名;其中,所述第二终端设备所属用户的信息包括所述第二终端设备的签名证书,或者,所述第二终端设备所属用户的信息包括所述第二终端设备的标识和所述第二终端设备的公共验证令牌PVT和密钥管理服务器的公共认证密钥KPAK;所述第二终端设备的签名的输入参数包括以下至少之一:所述第二终端设备所属用户的信息和所述第一临时公钥;在所述第二终端设备的签名证书有效,且基于所述第二终端设备的签名证书对所述第二终端设备的签名验证成功的情况下,或者,在所述第二终端设备的KPAK有效,且基于所述第二终端设备的标识和所述第二终端设备的PVT对所述第二终端设备的签名验证成功的情况下,所述中继设备向第一终端设备发送验证之后的认证请求消息;其中,所述验证之后的认证请求消息包括以下至少之一:所述第二终端设备所属用户的信息,所述中继设备所属用户的信息,所述第一临时公钥,所述第二终端设备的签名,所述中继设备的签名,所述中继设备的相关信息;其中,所述中继设备所属用户的信息包括所述中继设备的签名证书,或者,所述中继设备所属用户的信息包括所述中继设备的标识和所述中继设备的PVT和KPAK;所述中继设备的签名的输入参数包括以下至少之一:所述第二终端设备的签名和所述中继设备所属用户的信息;其中,所述第一临时公钥和所述中继设备的相关信息用于第一终端设备派生第一密钥;所述中继设备的相关信息包括以下之一:所述中继设备的身份信息,所述中继设备生成的随机数,所述中继设备生成的计数器。
- 如权利要求30所述的方法,其特征在于,在所述第二终端设备所属用户的信息包括所述第二终端设备的签名证书的情况下,所述第二终端设备的签名由所述第二终端设备的签名私钥生成,或者,在所述第二终端设备所属用户的信息包括所述第二终端设备的标识和所述第二终端设备的PVT和KPAK的情况下,所述第二终端设备的签名由所述第二终端设备的秘密签名密钥生成;和/或,在所述中继设备所属用户的信息包括所述中继设备的签名证书的情况下,所述中继设备的签名由所述中继设备的签名私钥生成,或者,在所述中继设备所属用户的信息包括所述中继设备的标识和所述中继设备的PVT和KPAK的情况下,所述中继设备的签名由所述中继设备的秘密签名密钥生成。
- 如权利要求30或31所述的方法,其特征在于,所述方法还包括:所述中继设备接收所述第一终端设备发送的第一消息;其中,所述第一消息包括以下至少之一:所述第一终端设备的安全能力信息,所述第一终端设备的安全策略信息,所述第一终端设备所属用户的信息,所述第一终端设备生成的第一随机数,所述第一终端设备生成的第二临时公钥,所述第一终端设备生成的所述第一密钥的标识的M个比特位,所述第一终端设备的签名,第一消息验证码;其 中,所述第一终端设备所属用户的信息包括所述第一终端设备的签名证书,或者,所述第一终端设备所属用户的信息包括所述第一终端设备的标识和所述第一终端设备的PVT和KPAK;所述第一终端设备的签名的输入参数包括以下至少之一:所述第一终端设备所属用户的信息,所述第二临时公钥,所述第一密钥的标识的M个比特位,所述第二终端设备的签名;其中,所述第一消息通过基于所述第一密钥生成的所述第一消息验证码进行完整性保护,且所述第一消息验证码的输入参数包括以下至少之一:所述第一终端设备的安全能力信息,所述第一终端设备的安全策略信息,所述第一终端设备所属用户的信息,所述第一随机数,所述第二临时公钥,所述M个比特位,所述第一终端设备的签名;在所述第一终端设备的签名证书有效,且基于所述第一终端设备的签名证书对所述第一终端设备的签名验证成功的情况下,或者,在所述第一终端设备的KPAK有效,且基于所述第一终端设备的标识和所述第一终端设备的PVT对所述第一终端设备的签名验证成功的情况下,所述中继设备向所述第二终端设备发送验证之后的第一消息;其中,所述验证之后的第一消息包括以下至少之一:所述第一终端设备的安全能力信息,所述第一终端设备的安全策略信息,所述第一终端设备所属用户的信息,所述中继设备所属用户的信息,所述第一终端设备生成的第一随机数,所述第一终端设备生成的与所述第二临时私钥配对的第二临时公钥,所述第一终端设备生成的所述第一密钥的标识的M个比特位,所述第一终端设备的签名,所述中继设备的签名,所述第一消息验证码;其中,所述中继设备所属用户的信息包括所述中继设备的签名证书,或者,所述中继设备所属用户的信息包括所述中继设备的标识和所述中继设备的PVT和KPAK;所述中继设备的签名的输入参数包括以下至少之一:所述中继设备所属用户的信息,所述第一终端设备的签名,所述第二终端设备的签名,所述验证之后的第一消息;其中,所述第二临时公钥和所述中继设备的相关信息用于所述第二终端设备派生所述第一密钥,所述第一随机数、所述第一密钥和所述第二终端设备生成的第二随机数用于派生第二密钥,所述第二密钥用于派生完整性保护密钥和/或机密性保护密钥,所述第一密钥的标识由所述M个比特位与所述第一密钥的标识的另外N个比特位合并得到,M和N均为正整数。
- 如权利要求32所述的方法,其特征在于,所述方法还包括:所述中继设备将所述第二终端设备发送的第二消息转发至所述第一终端设备;其中,所述第二消息包括以下至少之一:所述第二终端设备生成的所述第二随机数,所述第二终端设备生成的所述第一密钥的标识的N个比特位,所述第二终端设备生成的所述第二密钥的标识的x个比特位,所述第二终端设备选取的安全算法,所述第二终端设备选取的安全策略,第二消息验证码;其中,所述第二消息通过基于所述第二密钥生成的所述第二消息验证码进行完整性保护,或者,所述第二消息通过基于所述第二密钥派生的完整性保护密钥生成的所述第二消息验证码进行完整性保护,且所述第二消息验证码的输入参数包括以下至少之一:所述第二随机数,所述N个比特位,所述x个比特位,所述第二终端设备选取的安全算法,所述第二终端设备选取的安全策略;其中,所述第二密钥的标识由所述x个比特位与所述第二密钥的标识的另外y个比特位合并得到,x和y均为正整数。
- 如权利要求33所述的方法,其特征在于,所述第二消息通过所述第一密钥进行加密,且所述第二消息还包括第三消息验证码;其中,所述第二消息通过基于所述第一密钥生成的所述第三消息验证码进行完整性保护,且所述第三消息验证码的输入参数包括以下至少之一:所述第二随机数,所述N个比特位,所述x个比特位,所述第二终端设备选取的安全算法,所述第二终端设备选取的安全策略。
- 如权利要求33所述的方法,其特征在于,所述第一消息为认证响应消息,所述第二消息为安全模式命令消息。
- 如权利要求34所述的方法,其特征在于,所述第一消息为安全模式命令消息,所述第二消息为安全模式响应消息。
- 如权利要求32至36中任一项所述的方法,其特征在于,所述方法还包括:所述中继设备将所述第一终端设备发送的第三消息转发至所述第二终端设备;其中,所述第三消息用于指示安全模式建立完成,所述第三消息通过目标密钥进行加密,且所述第三消息包括以下至少之一:所述第一终端设备生成的所述第二密钥的标识的y个比特位,第四消息验证码;其中,所述目标密钥包括以下之一:所述第一密钥,所述第二密钥,所述第二密钥派生的机密性保护密钥;其中,所述第三消息通过基于所述第二密钥生成的所述第四消息验证码进行完整性保护,或者, 所述第三消息通过基于所述第二密钥派生的完整性保护密钥生成的所述第四消息验证码进行完整性保护,所述第四消息验证码的输入参数包括所述y个比特位。
- 如权利要求32所述的方法,其特征在于,所述方法还包括:所述中继设备将所述第二终端设备发送的错误消息转发至所述第一终端设备;其中,所述错误消息包括以下至少之一:原因信息,第五消息验证码;其中,所述原因信息用于指示所述第二终端设备与所述第一终端设备的安全策略冲突,或者,所述原因信息用于指示所述第一消息验证码验证失败,或者,所述原因信息用于指示所述第二终端设备与所述第一终端设备的安全算法协商失败,所述第五消息验证码的输入参数包括以下至少之一:所述原因信息。
- 如权利要求32至38中任一项所述的方法,其特征在于,所述完整性保护密钥包括控制面的完整性保护密钥和用户面的完整性保护密钥;和/或,所述机密性保护密钥包括控制面的机密性保护密钥和用户面的机密性保护密钥。
- 如权利要求30至39中任一项所述的方法,其特征在于,所述方法还包括:所述中继设备将所述第一终端设备发送的直接通信请求转发至所述第二终端设备;其中,所述直接通信请求包括以下至少之一:源标识,目标标识;其中,所述源标识用于标识所述第一终端设备与所述第二终端设备之间的中继连接的源端,所述目标标识用于标识所述第一终端设备与所述第二终端设备之间的中继连接的目标端。
- 一种中继通信的方法,其特征在于,包括:第一终端设备通过中继设备向第二终端设备发送第一消息;其中,所述第一消息包括以下至少之一:所述第一终端设备的安全能力信息,所述第一终端设备的安全策略信息,所述第一终端设备所属用户的信息,所述第一终端设备生成的第一随机数,所述第一终端设备生成的第二临时公钥,所述第一终端设备生成的第一密钥的标识的M个比特位,所述第一终端设备的签名,第一消息验证码;其中,所述第一终端设备所属用户的信息包括所述第一终端设备的签名证书,或者,所述第一终端设备所属用户的信息包括所述第一终端设备的标识和所述第一终端设备的PVT和KPAK;所述第一终端设备的签名的输入参数包括以下至少之一:所述第一终端设备所属用户的信息,所述第二临时公钥,所述第一密钥的标识的M个比特位,所述第二终端设备的签名;其中,所述第一消息通过基于所述第一密钥生成的所述第一消息验证码进行完整性保护,且所述第一消息验证码的输入参数包括以下至少之一:所述第一终端设备的安全能力信息,所述第一终端设备的安全策略信息,所述第一终端设备所属用户的信息,所述第一随机数,所述第二临时公钥,所述M个比特位,所述第一终端设备的签名;其中,所述第二临时公钥和所述中继设备的相关信息用于所述第二终端设备派生所述第一密钥,所述第一随机数、所述第一密钥和所述第二终端设备生成的第二随机数用于派生第二密钥,所述第二密钥用于派生完整性保护密钥和/或机密性保护密钥,所述第一密钥的标识由所述M个比特位与所述第一密钥的标识的另外N个比特位合并得到,M和N均为正整数;其中,所述中继设备的相关信息包括以下之一:所述中继设备的身份信息,所述中继设备生成的随机数,所述中继设备生成的计数器。
- 如权利要求41所述的方法,其特征在于,所述方法还包括:所述第一终端设备接收所述第二终端设备通过所述中继设备发送的第二消息;其中,所述第二消息包括以下至少之一:所述第二终端设备生成的所述第二随机数,所述第二终端设备生成的所述第一密钥的标识的N个比特位,所述第二终端设备生成的所述第二密钥的标识的x个比特位,所述第二终端设备选取的安全算法,所述第二终端设备选取的安全策略,第二消息验证码;其中,所述第二消息通过基于所述第二密钥生成的所述第二消息验证码进行完整性保护,或者,所述第二消息通过基于所述第二密钥派生的完整性保护密钥生成的所述第二消息验证码进行完整性保护,且所述第二消息验证码的输入参数包括以下至少之一:所述第二随机数,所述N个比特位,所述x个比特位,所述第二终端设备选取的安全算法,所述第二终端设备选取的安全策略;其中,所述第二密钥的标识由所述x个比特位与所述第二密钥的标识的另外y个比特位合并得到,x和y均为正整数。
- 如权利要求42所述的方法,其特征在于,所述第二消息通过所述第一密钥进行加密,且所述第二消息还包括第三消息验证码;其中,所述第二消息通过基于所述第一密钥生成的所述第三消息验证码进行完整性保护,且所述第三消息验证码的输入参数包括以下至少之一:所述第二随机数,所述N个比特位,所述x个比特位,所述第二终端设备选取的安全算法,所述第二终端设备选取的安全策略。
- 如权利要求42所述的方法,其特征在于,所述方法还包括:在所述第二消息中携带的信息未遭受篡改的情况下,所述第一终端设备至少根据所述第一随机数、所述第一密钥和所述第二随机数生成所述第二密钥,所述第一终端设备根据所述第二密钥生成完整性保护密钥和/或机密性保护密钥,以及所述第一终端设备将所述M个比特位和所述N个比特位合并得到所述第一密钥的标识,所述第一终端设备生成所述第二密钥的标识的y个比特位,并将所述x个比特位和所述y个比特位合并得到所述第二密钥的标识;在所述第二消息验证码有效的情况下,所述第一终端设备根据所述第二终端设备选取的安全算法、所述第二密钥、基于所述第二密钥生成完整性保护密钥和/或机密性保护密钥、所述第二终端设备选取的安全策略,与所述第二终端设备进行通信。
- 如权利要求43所述的方法,其特征在于,所述方法还包括:所述第一终端设备根据所述第一密钥解密所述第二消息;在所述第二消息中携带的信息未遭受篡改的情况下,所述第一终端设备至少根据所述第一随机数、所述第一密钥和所述第二随机数生成所述第二密钥,所述第一终端设备根据所述第二密钥生成完整性保护密钥和/或机密性保护密钥,以及所述第一终端设备将所述M个比特位和所述N个比特位合并得到所述第一密钥的标识,所述第一终端设备生成所述第二密钥的标识的y个比特位,并将所述x个比特位和所述y个比特位合并得到所述第二密钥的标识;在所述第二消息验证码有效和所述第三消息验证码有效的情况下,所述第一终端设备根据所述第二终端设备选取的安全算法、所述第二密钥、基于所述第二密钥生成完整性保护密钥和/或机密性保护密钥、所述第二终端设备选取的安全策略,与所述第二终端设备进行通信。
- 如权利要求44或45所述的方法,其特征在于,所述完整性保护密钥的输入参数包括以下至少之一:所述第二密钥,选定的算法类型标识符,选定的算法类型标识符的长度,完整性保护算法标识,完整性保护算法标识的长度;和/或,所述机密性保护密钥的输入参数包括以下至少之一:所述第二密钥,选定的算法类型标识符,选定的算法类型标识符的长度,机密性保护算法标识,机密性保护算法标识的长度。
- 如权利要求42或44所述的方法,其特征在于,所述第一消息为认证响应消息,所述第二消息为安全模式命令消息。
- 如权利要求43或45所述的方法,其特征在于,所述第一消息为安全模式命令消息,所述第二消息为安全模式响应消息。
- 如权利要求44至46中任一项所述的方法,其特征在于,所述方法还包括:所述第一终端设备通过所述中继设备向所述第二终端设备发送第三消息;其中,所述第三消息用于指示安全模式建立完成,所述第三消息通过目标密钥进行加密,且所述第三消息包括以下至少之一:所述第二密钥的标识的所述y个比特位,第四消息验证码;其中,所述目标密钥包括以下之一:所述第一密钥,所述第二密钥,所述第二密钥派生的机密性保护密钥;其中,所述第三消息通过基于所述第二密钥生成的所述第四消息验证码进行完整性保护,或者,所述第三消息通过基于所述第二密钥派生的完整性保护密钥生成的所述第四消息验证码进行完整性保护,所述第四消息验证码的输入参数包括所述y个比特位。
- 如权利要求41所述的方法,其特征在于,所述方法还包括:所述第一终端设备接收所述第二终端设备通过所述中继设备发送的错误消息;其中,所述错误消息包括以下至少之一:原因信息,第五消息验证码;其中,所述原因信息用于指示所述第二终端设备与所述第一终端设备的安全策略冲突,或者,所述原因信息用于指示所述第一消息验证码验证失败,或者,所述原因信息用于指示所述第二终端设备与所述第一终端设备的安全算法协商失败,所述第五消息验证码的输入参数包括以下至少之一:所述原因信息;在所述第五消息验证码有效的情况下,所述第一终端设备确定安全模式建立失败,和/或,所述第一终端设备重新发起安全模式建立流程。
- 如权利要求41至50中任一项所述的方法,其特征在于,所述完整性保护密钥包括控制面的完整性保护密钥和用户面的完整性保护密钥;和/或,所述机密性保护密钥包括控制面的机密性保护密钥和用户面的机密性保护密钥。
- 如权利要求41至51中任一项所述的方法,其特征在于,所述方法还包括:所述第一终端设备接收所述第二终端设备通过所述中继设备发送的认证请求消息;其中,所述认证请求消息包括以下至少之一:所述第二终端设备所属用户的信息,所述中继设备所属用户的信息,所述第二终端设备生成的第一临时公钥,所述第二终端设备的签名,所述中继设备 的签名,所述中继设备的相关信息;其中,所述第二终端设备所属用户的信息包括所述第二终端设备的签名证书,或者,所述第二终端设备所属用户的信息包括所述第二终端设备的标识和所述第二终端设备的公共验证令牌PVT和密钥管理服务器的公共认证密钥KPAK;所述中继设备所属用户的信息包括所述中继设备的签名证书,或者,所述中继设备所属用户的信息包括所述中继设备的标识和所述中继设备的PVT和KPAK;所述第二终端设备的签名的输入参数包括以下至少之一:所述第二终端设备所属用户的信息和所述第一临时公钥;所述中继设备的签名的输入参数包括以下至少之一:所述第二终端设备的签名和所述中继设备所属用户的信息;所述第一临时公钥和所述中继设备的相关信息用于所述第一终端设备派生所述第一密钥。
- 如权利要求52所述的方法,其特征在于,在所述第二终端设备所属用户的信息包括所述第二终端设备的签名证书的情况下,所述第二终端设备的签名由所述第二终端设备的签名私钥生成,或者,在所述第二终端设备所属用户的信息包括所述第二终端设备的标识和所述第二终端设备的PVT和KPAK的情况下,所述第二终端设备的签名由所述第二终端设备的秘密签名密钥生成;和/或,在所述中继设备所属用户的信息包括所述中继设备的签名证书的情况下,所述中继设备的签名由所述中继设备的签名私钥生成,或者,在所述中继设备所属用户的信息包括所述中继设备的标识和所述中继设备的PVT和KPAK的情况下,所述中继设备的签名由所述中继设备的秘密签名密钥生成。
- 如权利要求52或53所述的方法,其特征在于,所述方法还包括:在所述第二终端设备的签名证书和所述中继设备的签名证书有效,且基于所述第二终端设备的签名证书对所述第二终端设备的签名验证成功,以及基于所述中继设备的签名证书对所述中继设备的签名验证成功的情况下,所述第一终端设备生成与所述第二临时公钥配对的第二临时私钥,以及所述第一终端设备根据所述第一临时公钥、所述中继设备的相关信息和所述第二临时私钥派生所述第一密钥;或者,在所述第二终端设备的KPAK和所述中继设备的KPAK有效,且基于所述第二终端设备的标识和所述第二终端设备的PVT对所述第二终端设备的签名验证成功,以及基于所述中继设备的标识和所述中继设备的PVT对所述中继设备的签名验证成功的情况下,所述第一终端设备生成与所述第二临时公钥配对的第二临时私钥,以及所述第一终端设备根据所述第一临时公钥、所述中继设备的相关信息和所述第二临时私钥派生所述第一密钥。
- 如权利要求41至54中任一项所述的方法,其特征在于,所述方法还包括:所述第一终端设备通过所述中继设备向所述第二终端设备发送直接通信请求;其中,所述直接通信请求包括以下至少之一:源标识,目标标识;其中,所述源标识用于标识所述第一终端设备与所述第二终端设备之间的中继连接的源端,所述目标标识用于标识所述第一终端设备与所述第二终端设备之间的中继连接的目标端。
- 一种中继通信的方法,其特征在于,包括:第二终端设备接收第一终端设备通过中继设备发送的第一消息;其中,所述第一消息包括以下至少之一:所述第一终端设备的安全能力信息,所述第一终端设备的安全策略信息,所述第一终端设备所属用户的信息,所述中继设备所属用户的信息,所述第一终端设备生成的第一随机数,所述第一终端设备生成的第二临时公钥,所述第一终端设备生成的第一密钥的标识的M个比特位,所述第一终端设备的签名,所述中继设备的签名,第一消息验证码;其中,所述第一终端设备所属用户的信息包括所述第一终端设备的签名证书,或者,所述第一终端设备所属用户的信息包括所述第一终端设备的标识和所述第一终端设备的公共验证令牌PVT和密钥管理服务器的公共认证密钥KPAK;所述中继设备所属用户的信息包括所述中继设备的签名证书,或者,所述中继设备所属用户的信息包括所述中继设备的标识和所述中继设备的PVT和KPAK;所述第一终端设备的签名的输入参数包括以下至少之一:所述第一终端设备所属用户的信息,所述第二临时公钥,所述第一密钥的标识的M个比特位,所述第二终端设备的签名;所述中继设备的签名的输入参数包括以下至少之一:所述中继设备所属用户的信息,所述第一终端设备的签名,所述第二终端设备的签名,所述验证之后的第一消息;其中,所述第一消息通过基于所述第一密钥生成的所述第一消息验证码进行完整性保护,且所述第一消息验证码的输入参数包括以下至少之一:所述第一终端设备的安全能力信息,所述第一终端设备的安全策略信息,所述第一终端设备所属用户的信息,所述第一随机数,所述第二临时公钥,所述M个比特位,所述第一终端设备的签名;其中,所述第二临时公钥和所述中继设备的相关信息用于所述第二终端设备派生所述第一密钥, 所述第一随机数、所述第一密钥和所述第二终端设备生成的第二随机数用于派生第二密钥,所述第二密钥用于派生完整性保护密钥和/或机密性保护密钥,所述第一密钥的标识由所述M个比特位与所述第一密钥的标识的另外N个比特位合并得到,M和N均为正整数;其中,所述中继设备的相关信息包括以下之一:所述中继设备的身份信息,所述中继设备生成的随机数,所述中继设备生成的计数器。
- 如权利要求56所述的方法,其特征在于,在所述第一终端设备所属用户的信息包括所述第一终端设备的签名证书的情况下,所述第一终端设备的签名由所述第一终端设备的签名私钥生成,或者,在所述第一终端设备所属用户的信息包括所述第一终端设备的标识和所述第一终端设备的PVT和KPAK的情况下,所述第一终端设备的签名由所述第一终端设备的秘密签名密钥生成;和/或,在所述中继设备所属用户的信息包括所述中继设备的签名证书的情况下,所述中继设备的签名由所述中继设备的签名私钥生成,或者,在所述中继设备所属用户的信息包括所述中继设备的标识和所述中继设备的PVT和KPAK的情况下,所述中继设备的签名由所述中继设备的秘密签名密钥生成。
- 如权利要求57所述的方法,其特征在于,所述方法还包括:所述第二终端设备分别检查所述第一终端设备的签名证书和所述中继设备的签名证书,在所述第一终端设备的签名证书和所述中继设备的签名证书有效的情况下,所述第二终端设备基于所述第一终端设备的签名证书对所述第一终端设备的签名进行验证,以及所述第二终端设备基于所述中继设备的签名证书对所述中继设备的签名进行验证;或者,所述第二终端设备分别检查所述第一终端设备的KPAK和所述中继设备的KPAK,在所述第一终端设备的KPAK和所述中继设备的KPAK有效的情况下,且基于所述第一终端设备的标识和所述第一终端设备的PVT对所述第一终端设备的签名进行验证,以及基于所述中继设备的标识和所述中继设备的PVT对所述中继设备的签名进行验证;在所述第一终端设备的签名和所述中继设备的签名验证成功,且所述第一消息中携带的信息未遭受篡改的情况下,所述第二终端设备生成第二随机数,所述第二终端设备至少根据所述第一随机数、所述第一密钥和所述第二随机数生成所述第二密钥,所述第二终端设备根据所述第二密钥生成完整性保护密钥和/或机密性保护密钥,以及所述第二终端设备生成所述第一密钥的标识的N个比特位,并将所述M个比特位和所述N个比特位合并得到所述第一密钥的标识;在所述第一消息验证码有效的情况下,所述第二终端设备通过所述中继设备向所述第一终端设备发送第二消息;其中,所述第二消息包括以下至少之一:所述第二随机数,所述N个比特位,所述第二终端设备生成的所述第二密钥的标识的x个比特位,所述第二终端设备选取的安全算法,所述第二终端设备选取的安全策略,第二消息验证码;其中,所述第二消息通过基于所述第二密钥生成的所述第二消息验证码进行完整性保护,或者,所述第二消息通过基于所述第二密钥派生的完整性保护密钥生成的所述第二消息验证码进行完整性保护,且所述第二消息验证码的输入参数包括以下至少之一:所述第二随机数,所述N个比特位,所述x个比特位,所述第二终端设备选取的安全算法,所述第二终端设备选取的安全策略;其中,所述第二密钥的标识由所述x个比特位与所述第二密钥的标识的另外y个比特位合并得到,x和y均为正整数。
- 如权利要求58所述的方法,其特征在于,所述第二消息通过所述第一密钥进行加密,且所述第二消息还包括第三消息验证码;其中,所述第二消息通过基于所述第一密钥生成的所述第三消息验证码进行完整性保护,且所述第三消息验证码的输入参数包括以下至少之一:所述第二随机数,所述N个比特位,所述x个比特位,所述第二终端设备选取的安全算法,所述第二终端设备选取的安全策略。
- 如权利要求58所述的方法,其特征在于,所述第一消息为认证响应消息,所述第二消息为安全模式命令消息。
- 如权利要求59所述的方法,其特征在于,所述第一消息为安全模式命令消息,所述第二消息为安全模式响应消息。
- 如权利要求58至61中任一项所述的方法,其特征在于,所述完整性保护密钥的输入参数包括以下至少之一:所述第二密钥,选定的算法类型标识符,选定的算法类型标识符的长度,完整性保护算法标识,完整性保护算法标识的长度;和/或,所述机密性保护密钥的输入参数包括以下至少之一:所述第二密钥,选定的算法类型标识符,选定的算法类型标识符的长度,机密性保护算法标识,机密性保护算法标识的长度。
- 如权利要求58至62中任一项所述的方法,其特征在于,所述方法还包括:所述第二终端设备接收所述第一终端设备通过所述中继设备发送的第三消息;其中,所述第三消息用于指示安全模式建立完成,所述第三消息通过目标密钥进行加密,且所述第三消息包括以下至少之一:所述第一终端设备生成的所述第二密钥的标识的y个比特位,第四消息验证码;其中,所述目标密钥包括以下之一:所述第一密钥,所述第二密钥,所述第二密钥派生的机密性保护密钥;其中,所述第三消息通过基于所述第二密钥生成的所述第四消息验证码进行完整性保护,或者,所述第三消息通过基于所述第二密钥派生的完整性保护密钥生成的所述第四消息验证码进行完整性保护,所述第四消息验证码的输入参数包括所述y个比特位。
- 如权利要求63所述的方法,其特征在于,所述方法还包括:所述第二终端设备通过所述目标密钥对所述第三消息进行解密;在所述第三消息中携带的信息未遭受篡改的情况下,且所述第四消息验证码有效的情况下,所述第二终端设备将所述x个比特位与所述y个比特位合并得到所述第二密钥的标识。
- 如权利要求56或57所述的方法,其特征在于,所述方法还包括:所述第二终端设备通过所述中继设备向所述第一终端设备发送错误消息;其中,所述错误消息包括以下至少之一:原因信息,第五消息验证码;其中,所述原因信息用于指示所述第二终端设备与所述第一终端设备的安全策略冲突,或者,所述原因信息用于指示所述第一消息验证码验证失败,或者,所述原因信息用于指示所述第二终端设备与所述第一终端设备的安全算法协商失败,所述第五消息验证码的输入参数包括以下至少之一:所述原因信息。
- 如权利要求56至65中任一项所述的方法,其特征在于,所述完整性保护密钥包括控制面的完整性保护密钥和用户面的完整性保护密钥;和/或,所述机密性保护密钥包括控制面的机密性保护密钥和用户面的机密性保护密钥。
- 如权利要求56至66中任一项所述的方法,其特征在于,所述方法还包括:所述第二终端设备通过所述中继设备向所述第一终端设备发送认证请求消息;其中,所述认证请求消息包括以下至少之一:所述第二终端设备所属用户的信息,所述第二终端设备生成的第一临时公钥,所述第二终端设备的签名,所述中继设备的相关信息;其中,所述第二终端设备所属用户的信息包括所述第二终端设备的签名证书,或者,所述第二终端设备所属用户的信息包括所述第二终端设备的标识和所述第二终端设备的公共验证令牌PVT和密钥管理服务器的公共认证密钥KPAK;所述第二终端设备的签名的输入参数包括以下至少之一:所述第二终端设备所属用户的信息和所述第一临时公钥;所述第一临时公钥和所述中继设备的相关信息用于所述第一终端设备派生第一密钥。
- 如权利要求67所述的方法,其特征在于,在所述第二终端设备所属用户的信息包括所述第二终端设备的签名证书的情况下,所述第二终端设备的签名由所述第二终端设备的签名私钥生成,或者,在所述第二终端设备所属用户的信息包括所述第二终端设备的标识和所述第二终端设备的PVT和KPAK的情况下,所述第二终端设备的签名由所述第二终端设备的秘密签名密钥生成。
- 如权利要求56至68中任一项所述的方法,其特征在于,所述方法还包括:所述第二终端设备接收所述第一终端设备通过所述中继设备发送的直接通信请求;其中,所述直接通信请求包括以下至少之一:源标识,目标标识;其中,所述源标识用于标识所述第一终端设备与所述第二终端设备之间的中继连接的源端,所述目标标识用于标识所述第一终端设备与所述第二终端设备之间的中继连接的目标端。
- 一种中继通信的方法,其特征在于,包括:中继设备接收第一终端设备发送的第一消息;其中,所述第一消息包括以下至少之一:所述第一终端设备的安全能力信息,所述第一终端设备的安全策略信息,所述第一终端设备所属用户的信息,所述第一终端设备生成的第一随机数,所述第一终端设备生成的第二临时公钥,所述第一终端设备生成的第一密钥的标识的M个比特位,所述第一终端设备的签名,第一消息验证码;其中,所述第一终端设备所属用户的信息包括所述第一终端设备的签名证书,或者,所述第一终端设备所属用户的信息包括所述第一终端设备的标识和所述第一终端设备的公共验证令牌PVT和密钥管理服务器的公共认证密钥KPAK;所述第一终端设备的签名的输入参数包括以下至少之一:所述第一终端设备所属用户的信息,所述第二临时公钥,所述第一密钥的标识的M个比特位,第二终端设备的签名;其中,所述第一消息通过基于所述第一密钥生成的所述第一消息验证码进行完整性保护,且所述第一消息验证码的输入参数包括以下至少之一:所述第一终端设备的安全能力信息,所述第一终端设备的安全策略信息,所述第一终端设备所属用户的信息,所述第一随机数,所述第二临时公钥,所述M个比特 位,所述第一终端设备的签名;在所述第一终端设备的签名证书有效,且基于所述第一终端设备的签名证书对所述第一终端设备的签名验证成功的情况下,或者,在所述第一终端设备的KPAK有效,且基于所述第一终端设备的标识和所述第一终端设备的PVT对所述第一终端设备的签名验证成功的情况下,所述中继设备向所述第二终端设备发送验证之后的第一消息;其中,所述验证之后的第一消息包括以下至少之一:所述第一终端设备的安全能力信息,所述第一终端设备的安全策略信息,所述第一终端设备所属用户的信息,所述中继设备所属用户的信息,所述第一终端设备生成的第一随机数,所述第一终端设备生成的与所述第二临时私钥配对的第二临时公钥,所述第一终端设备生成的所述第一密钥的标识的M个比特位,所述第一终端设备的签名,所述中继设备的签名,所述中继设备的相关信息,所述第一消息验证码;其中,所述中继设备所属用户的信息包括所述中继设备的签名证书,或者,所述中继设备所属用户的信息包括所述中继设备的标识和所述中继设备的PVT和KPAK;所述中继设备的签名的输入参数包括以下至少之一:所述中继设备所属用户的信息,所述第一终端设备的签名,所述第二终端设备的签名,所述验证之后的第一消息;其中,所述第二临时公钥和所述中继设备的相关信息用于所述第二终端设备派生所述第一密钥,所述第一随机数、所述第一密钥和所述第二终端设备生成的第二随机数用于派生第二密钥,所述第二密钥用于派生完整性保护密钥和/或机密性保护密钥,所述第一密钥的标识由所述M个比特位与所述第一密钥的标识的另外N个比特位合并得到,M和N均为正整数;其中,所述中继设备的相关信息包括以下之一:所述中继设备的身份信息,所述中继设备生成的随机数,所述中继设备生成的计数器。
- 如权利要求70所述的方法,其特征在于,所述方法还包括:所述中继设备将所述第二终端设备发送的第二消息转发至所述第一终端设备;其中,所述第二消息包括以下至少之一:所述第二终端设备生成的所述第二随机数,所述第二终端设备生成的所述第一密钥的标识的N个比特位,所述第二终端设备生成的所述第二密钥的标识的x个比特位,所述第二终端设备选取的安全算法,所述第二终端设备选取的安全策略,第二消息验证码;其中,所述第二消息通过基于所述第二密钥生成的所述第二消息验证码进行完整性保护,或者,所述第二消息通过基于所述第二密钥派生的完整性保护密钥生成的所述第二消息验证码进行完整性保护,且所述第二消息验证码的输入参数包括以下至少之一:所述第二随机数,所述N个比特位,所述x个比特位,所述第二终端设备选取的安全算法,所述第二终端设备选取的安全策略;其中,所述第二密钥的标识由所述x个比特位与所述第二密钥的标识的另外y个比特位合并得到,x和y均为正整数。
- 如权利要求71所述的方法,其特征在于,所述第二消息通过所述第一密钥进行加密,且所述第二消息还包括第三消息验证码;其中,所述第二消息通过基于所述第一密钥生成的所述第三消息验证码进行完整性保护,且所述第三消息验证码的输入参数包括以下至少之一:所述第二随机数,所述N个比特位,所述x个比特位,所述第二终端设备选取的安全算法,所述第二终端设备选取的安全策略。
- 如权利要求71所述的方法,其特征在于,所述第一消息为认证响应消息,所述第二消息为安全模式命令消息。
- 如权利要求72所述的方法,其特征在于,所述第一消息为安全模式命令消息,所述第二消息为安全模式响应消息。
- 如权利要求71至74中任一项所述的方法,其特征在于,所述方法还包括:所述中继设备将所述第一终端设备发送的第三消息转发至所述第二终端设备;其中,所述第三消息用于指示安全模式建立完成,所述第三消息通过目标密钥进行加密,且所述第三消息包括以下至少之一:所述第一终端设备生成的所述第二密钥的标识的y个比特位,第四消息验证码;其中,所述目标密钥包括以下之一:所述第一密钥,所述第二密钥,所述第二密钥派生的机密性保护密钥;其中,所述第三消息通过基于所述第二密钥生成的所述第四消息验证码进行完整性保护,或者,所述第三消息通过基于所述第二密钥派生的完整性保护密钥生成的所述第四消息验证码进行完整性保护,所述第四消息验证码的输入参数包括所述y个比特位。
- 如权利要求70所述的方法,其特征在于,所述方法还包括:所述中继设备将所述第二终端设备发送的错误消息转发至所述第一终端设备;其中,所述错误消息包括以下至少之一:原因信息,第五消息验证码;其中,所述原因信息用于指示所述第二终端设备与所述第一终端设备的安全策略冲突,或者,所述原因信息用于指示所述第一消息验证码验证失败, 或者,所述原因信息用于指示所述第二终端设备与所述第一终端设备的安全算法协商失败,所述第五消息验证码的输入参数包括以下至少之一:所述原因信息。
- 如权利要求70至76中任一项所述的方法,其特征在于,所述完整性保护密钥包括控制面的完整性保护密钥和用户面的完整性保护密钥;和/或,所述机密性保护密钥包括控制面的机密性保护密钥和用户面的机密性保护密钥。
- 如权利要求70至76中任一项所述的方法,其特征在于,所述方法还包括:所述中继设备接收所述第二终端设备发送的认证请求消息;其中,所述认证请求消息包括以下至少之一:所述第二终端设备所属用户的信息,所述第二终端设备生成的第一临时公钥,所述第二终端设备的签名;其中,所述第二终端设备所属用户的信息包括所述第二终端设备的签名证书,或者,所述第二终端设备所属用户的信息包括所述第二终端设备的标识和所述第二终端设备的PVT和KPAK;所述第二终端设备的签名的输入参数包括以下至少之一:所述第二终端设备所属用户的信息和所述第一临时公钥;所述第一临时公钥和所述中继设备的相关信息用于所述第一终端设备派生所述第一密钥;在所述第二终端设备的签名证书有效,且基于所述第二终端设备的签名证书对所述第二终端设备的签名验证成功的情况下,或者,在所述第二终端设备的KPAK有效,且基于所述第二终端设备的标识和所述第二终端设备的PVT对所述第二终端设备的签名验证成功的情况下,所述中继设备向所述第一终端设备发送验证之后的认证请求消息;其中,所述验证之后的认证请求消息包括以下至少之一:所述第二终端设备所属用户的信息,所述中继设备所属用户的信息,所述第一临时公钥,所述第二终端设备的签名,所述中继设备的签名,所述中继设备的相关信息;其中,所述中继设备所属用户的信息包括所述中继设备的签名证书,或者,所述中继设备所属用户的信息包括所述中继设备的标识和所述中继设备的PVT和KPAK;所述中继设备的签名的输入参数包括以下至少之一:所述第二终端设备的签名和所述中继设备所属用户的信息。
- 如权利要求78所述的方法,其特征在于,在所述第二终端设备所属用户的信息包括所述第二终端设备的签名证书的情况下,所述第二终端设备的签名由所述第二终端设备的签名私钥生成,或者,在所述第二终端设备所属用户的信息包括所述第二终端设备的标识和所述第二终端设备的PVT和KPAK的情况下,所述第二终端设备的签名由所述第二终端设备的秘密签名密钥生成;和/或,在所述中继设备所属用户的信息包括所述中继设备的签名证书的情况下,所述中继设备的签名由所述中继设备的签名私钥生成,或者,在所述中继设备所属用户的信息包括所述中继设备的标识和所述中继设备的PVT和KPAK的情况下,所述中继设备的签名由所述中继设备的秘密签名密钥生成。
- 如权利要求70至79中任一项所述的方法,其特征在于,所述方法还包括:所述中继设备将所述第一终端设备发送的直接通信请求转发至所述第二终端设备;其中,所述直接通信请求包括以下至少之一:源标识,目标标识;其中,所述源标识用于标识所述第一终端设备与所述第二终端设备之间的中继连接的源端,所述目标标识用于标识所述第一终端设备与所述第二终端设备之间的中继连接的目标端。
- 一种终端设备,其特征在于,所述终端设备为第一终端设备,所述终端设备包括:通信单元,用于接收第二终端设备通过中继设备发送的认证请求消息;其中,所述认证请求消息包括以下至少之一:所述第二终端设备所属用户的信息,所述中继设备所属用户的信息,所述第二终端设备生成的第一临时公钥,所述第二终端设备的签名,所述中继设备的签名,所述中继设备的相关信息;其中,所述第二终端设备所属用户的信息包括所述第二终端设备的签名证书,或者,所述第二终端设备所属用户的信息包括所述第二终端设备的标识和所述第二终端设备的公共验证令牌PVT和密钥管理服务器的公共认证密钥KPAK;所述中继设备所属用户的信息包括所述中继设备的签名证书,或者,所述中继设备所属用户的信息包括所述中继设备的标识和所述中继设备的PVT和KPAK;所述第二终端设备的签名的输入参数包括以下至少之一:所述第二终端设备所属用户的信息和所述第一临时公钥;所述中继设备的签名的输入参数包括以下至少之一:所述第二终端设备的签名和所述中继设备所属用户的信息;所述第一临时公钥和所述中继设备的相关信息用于所述第一终端设备派生第一密钥;所述中继设备的相关信息包括以下之一:所述中继设备的身份信息,所述中继设备生成的随机数,所述中继设备生成的计数器。
- 一种终端设备,其特征在于,所述终端设备为第二终端设备,所述终端设备包括:通信单元,用于通过中继设备向第一终端设备发送认证请求消息;其中,所述认证请求消息包括以下至少之一:所述第二终端设备所属用户的信息,所述第二终端 设备生成的第一临时公钥,所述第二终端设备的签名,所述中继设备的相关信息;其中,所述第二终端设备所属用户的信息包括所述第二终端设备的签名证书,或者,所述第二终端设备所属用户的信息包括所述第二终端设备的标识和所述第二终端设备的公共验证令牌PVT和密钥管理服务器的公共认证密钥KPAK;所述第二终端设备的签名的输入参数包括以下至少之一:所述第二终端设备所属用户的信息和所述第一临时公钥;所述第一临时公钥和所述中继设备的相关信息用于所述第一终端设备派生第一密钥;所述中继设备的相关信息包括以下之一:所述中继设备的身份信息,所述中继设备生成的随机数,所述中继设备生成的计数器。
- 一种中继设备,其特征在于,包括:通信单元,用于接收第二终端设备发送的认证请求消息;其中,所述认证请求消息包括以下至少之一:所述第二终端设备所属用户的信息,所述第二终端设备生成的第一临时公钥,所述第二终端设备的签名;其中,所述第二终端设备所属用户的信息包括所述第二终端设备的签名证书,或者,所述第二终端设备所属用户的信息包括所述第二终端设备的标识和所述第二终端设备的公共验证令牌PVT和密钥管理服务器的公共认证密钥KPAK;所述第二终端设备的签名的输入参数包括以下至少之一:所述第二终端设备所属用户的信息和所述第一临时公钥;所述第一临时公钥和所述中继设备的相关信息用于第一终端设备派生第一密钥;在所述第二终端设备的签名证书有效,且基于所述第二终端设备的签名证书对所述第二终端设备的签名验证成功的情况下,或者,在所述第二终端设备的KPAK有效,且基于所述第二终端设备的标识和所述第二终端设备的PVT对所述第二终端设备的签名验证成功的情况下,所述通信单元还用于向所述第一终端设备发送验证之后的认证请求消息;其中,所述验证之后的认证请求消息包括以下至少之一:所述第二终端设备所属用户的信息,所述中继设备所属用户的信息,所述第一临时公钥,所述第二终端设备的签名,所述中继设备的签名,所述中继设备的相关信息;其中,所述中继设备所属用户的信息包括所述中继设备的签名证书,或者,所述中继设备所属用户的信息包括所述中继设备的标识和所述中继设备的PVT和KPAK;所述中继设备的签名的输入参数包括以下至少之一:所述第二终端设备的签名和所述中继设备所属用户的信息;所述中继设备的相关信息包括以下之一:所述中继设备的身份信息,所述中继设备生成的随机数,所述中继设备生成的计数器。
- 一种终端设备,其特征在于,所述终端设备为第一终端设备,所述终端设备包括:通信单元,用于通过中继设备向第二终端设备发送第一消息;其中,所述第一消息包括以下至少之一:所述第一终端设备的安全能力信息,所述第一终端设备的安全策略信息,所述第一终端设备所属用户的信息,所述第一终端设备生成的第一随机数,所述第一终端设备生成的第二临时公钥,所述第一终端设备生成的第一密钥的标识的M个比特位,所述第一终端设备的签名,第一消息验证码;其中,所述第一终端设备所属用户的信息包括所述第一终端设备的签名证书,或者,所述第一终端设备所属用户的信息包括所述第一终端设备的标识和所述第一终端设备的公共验证令牌PVT和密钥管理服务器的公共认证密钥KPAK;所述第一终端设备的签名的输入参数包括以下至少之一:所述第一终端设备所属用户的信息,所述第二临时公钥,所述第一密钥的标识的M个比特位,所述第二终端设备的签名;其中,所述第一消息通过基于所述第一密钥生成的所述第一消息验证码进行完整性保护,且所述第一消息验证码的输入参数包括以下至少之一:所述第一终端设备的安全能力信息,所述第一终端设备的安全策略信息,所述第一终端设备所属用户的信息,所述第一随机数,所述第二临时公钥,所述M个比特位,所述第一终端设备的签名;其中,所述第二临时公钥和所述中继设备的相关信息用于所述第二终端设备派生所述第一密钥,所述第一随机数、所述第一密钥和所述第二终端设备生成的第二随机数用于派生第二密钥,所述第二密钥用于派生完整性保护密钥和/或机密性保护密钥,所述第一密钥的标识由所述M个比特位与所述第一密钥的标识的另外N个比特位合并得到,M和N均为正整数;所述中继设备的相关信息包括以下之一:所述中继设备的身份信息,所述中继设备生成的随机数,所述中继设备生成的计数器。
- 一种终端设备,其特征在于,所述终端设备为第二终端设备,所述终端设备包括:通信单元,用于接收第一终端设备通过中继设备发送的第一消息;其中,所述第一消息包括以下至少之一:所述第一终端设备的安全能力信息,所述第一终端设备的安全策略信息,所述第一终端设备所属用户的信息,所述中继设备所属用户的信息,所述第一终端设备生成的第一随机数,所述第一终端设备生成的第二临时公钥,所述第一终端设备生成的第一密钥的标识的M个比特位,所述第一终端设备的签名,所述中继设备的签名,第一消息验证码;其中,所述第一终端设备所属用户的信息包括所述第一终端设备的签名证书,或者,所述第一终 端设备所属用户的信息包括所述第一终端设备的标识和所述第一终端设备的公共验证令牌PVT和密钥管理服务器的公共认证密钥KPAK;所述中继设备所属用户的信息包括所述中继设备的签名证书,或者,所述中继设备所属用户的信息包括所述中继设备的标识和所述中继设备的PVT和KPAK;所述第一终端设备的签名的输入参数包括以下至少之一:所述第一终端设备所属用户的信息,所述第二临时公钥,所述第一密钥的标识的M个比特位,所述第二终端设备的签名;所述中继设备的签名的输入参数包括以下至少之一:所述中继设备所属用户的信息,所述第一终端设备的签名,所述第二终端设备的签名,所述验证之后的第一消息;其中,所述第一消息通过基于所述第一密钥生成的所述第一消息验证码进行完整性保护,且所述第一消息验证码的输入参数包括以下至少之一:所述第一终端设备的安全能力信息,所述第一终端设备的安全策略信息,所述第一终端设备所属用户的信息,所述第一随机数,所述第二临时公钥,所述M个比特位,所述第一终端设备的签名;其中,所述第二临时公钥和所述中继设备的相关信息用于所述第二终端设备派生所述第一密钥,所述第一随机数、所述第一密钥和所述第二终端设备生成的第二随机数用于派生第二密钥,所述第二密钥用于派生完整性保护密钥和/或机密性保护密钥,所述第一密钥的标识由所述M个比特位与所述第一密钥的标识的另外N个比特位合并得到,M和N均为正整数;所述中继设备的相关信息包括以下之一:所述中继设备的身份信息,所述中继设备生成的随机数,所述中继设备生成的计数器。
- 一种中继设备,其特征在于,包括:通信单元,用于接收第一终端设备发送的第一消息;其中,所述第一消息包括以下至少之一:所述第一终端设备的安全能力信息,所述第一终端设备的安全策略信息,所述第一终端设备所属用户的信息,所述第一终端设备生成的第一随机数,所述第一终端设备生成的第二临时公钥,所述第一终端设备生成的第一密钥的标识的M个比特位,所述第一终端设备的签名,第一消息验证码;其中,所述第一终端设备所属用户的信息包括所述第一终端设备的签名证书,或者,所述第一终端设备所属用户的信息包括所述第一终端设备的标识和所述第一终端设备的公共验证令牌PVT和密钥管理服务器的公共认证密钥KPAK;所述第一终端设备的签名的输入参数包括以下至少之一:所述第一终端设备所属用户的信息,所述第二临时公钥,所述第一密钥的标识的M个比特位,第二终端设备的签名;其中,所述第一消息通过基于所述第一密钥生成的所述第一消息验证码进行完整性保护,且所述第一消息验证码的输入参数包括以下至少之一:所述第一终端设备的安全能力信息,所述第一终端设备的安全策略信息,所述第一终端设备所属用户的信息,所述第一随机数,所述第二临时公钥,所述M个比特位,所述第一终端设备的签名;在所述第一终端设备的签名证书有效,且基于所述第一终端设备的签名证书对所述第一终端设备的签名验证成功的情况下,或者,在所述第一终端设备的KPAK有效,且基于所述第一终端设备的标识和所述第一终端设备的PVT对所述第一终端设备的签名验证成功的情况下,所述通信单元还用于向所述第二终端设备发送验证之后的第一消息;其中,所述验证之后的第一消息包括以下至少之一:所述第一终端设备的安全能力信息,所述第一终端设备的安全策略信息,所述第一终端设备所属用户的信息,所述中继设备所属用户的信息,所述第一终端设备生成的第一随机数,所述第一终端设备生成的与所述第二临时私钥配对的第二临时公钥,所述第一终端设备生成的所述第一密钥的标识的M个比特位,所述第一终端设备的签名,所述中继设备的签名,所述中继设备的相关信息,所述第一消息验证码;其中,所述中继设备所属用户的信息包括所述中继设备的签名证书,或者,所述中继设备所属用户的信息包括所述中继设备的标识和所述中继设备的PVT和KPAK;所述中继设备的签名的输入参数包括以下至少之一:所述中继设备所属用户的信息,所述第一终端设备的签名,所述第二终端设备的签名,所述验证之后的第一消息;其中,所述第二临时公钥和所述中继设备的相关信息用于所述第二终端设备派生所述第一密钥,所述第一随机数、所述第一密钥和所述第二终端设备生成的第二随机数用于派生第二密钥,所述第二密钥用于派生完整性保护密钥和/或机密性保护密钥,所述第一密钥的标识由所述M个比特位与所述第一密钥的标识的另外N个比特位合并得到,M和N均为正整数;所述中继设备的相关信息包括以下之一:所述中继设备的身份信息,所述中继设备生成的随机数,所述中继设备生成的计数器。
- 一种终端设备,其特征在于,包括:处理器、存储器和收发器,所述收发器用于实现消息收发,所述存储器用于存储计算机程序,所述处理器用于调用并运行所述存储器中存储的计算机程序,使得所述终端设备执行如权利要求1至15中任一项所述的方法,或者,使得所述终端设备执行如权利要求16至29中任一项所述的方法,或者,使得所述终端设备执行如权利要求41至55中任一项所述的方法,或者,使得所述终端设备执行如权利要求56至69中任一项所述的方法。
- 一种中继设备,其特征在于,包括:处理器、存储器和收发器,所述收发器用于实现消息收 发,所述存储器用于存储计算机程序,所述处理器用于调用并运行所述存储器中存储的计算机程序,使得所述中继设备执行如权利要求30至40中任一项所述的方法,或者,使得所述中继设备执行如权利要求70至80中任一项所述的方法。
- 一种芯片,其特征在于,包括:处理器,用于从存储器中调用并运行计算机程序,使得安装有所述芯片的设备执行如权利要求1至15中任一项所述的方法,或者,执行如权利要求16至29中任一项所述的方法,或者,执行如权利要求30至40中任一项所述的方法,或者,执行如权利要求41至55中任一项所述的方法,或者,执行如权利要求56至69中任一项所述的方法,或者,执行如权利要求70至80中任一项所述的方法。
- 一种计算机可读存储介质,其特征在于,用于存储计算机程序,所述计算机程序使得计算机执行如权利要求1至15中任一项所述的方法,或者,执行如权利要求16至29中任一项所述的方法,或者,执行如权利要求30至40中任一项所述的方法,或者,执行如权利要求41至55中任一项所述的方法,或者,执行如权利要求56至69中任一项所述的方法,或者,执行如权利要求70至80中任一项所述的方法。
- 一种计算机程序产品,其特征在于,包括计算机程序指令,该计算机程序指令使得计算机执行如权利要求1至15中任一项所述的方法,或者,执行如权利要求16至29中任一项所述的方法,或者,执行如权利要求30至40中任一项所述的方法,或者,执行如权利要求41至55中任一项所述的方法,或者,执行如权利要求56至69中任一项所述的方法,或者,执行如权利要求70至80中任一项所述的方法。
- 一种计算机程序,其特征在于,所述计算机程序使得计算机执行如权利要求1至15中任一项所述的方法,或者,执行如权利要求16至29中任一项所述的方法,或者,执行如权利要求30至40中任一项所述的方法,或者,执行如权利要求41至55中任一项所述的方法,或者,执行如权利要求56至69中任一项所述的方法,或者,执行如权利要求70至80中任一项所述的方法。
Priority Applications (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| CN202280084389.5A CN118402262A (zh) | 2022-05-06 | 2022-05-06 | 中继通信的方法及设备 |
| PCT/CN2022/091126 WO2023212904A1 (zh) | 2022-05-06 | 2022-05-06 | 中继通信的方法及设备 |
Applications Claiming Priority (1)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| PCT/CN2022/091126 WO2023212904A1 (zh) | 2022-05-06 | 2022-05-06 | 中继通信的方法及设备 |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| WO2023212904A1 true WO2023212904A1 (zh) | 2023-11-09 |
Family
ID=88646083
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| PCT/CN2022/091126 Ceased WO2023212904A1 (zh) | 2022-05-06 | 2022-05-06 | 中继通信的方法及设备 |
Country Status (2)
| Country | Link |
|---|---|
| CN (1) | CN118402262A (zh) |
| WO (1) | WO2023212904A1 (zh) |
Citations (5)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| WO2019000405A1 (zh) * | 2017-06-30 | 2019-01-03 | 华为技术有限公司 | 一种认证方法及终端、网络设备 |
| CN110022320A (zh) * | 2019-04-08 | 2019-07-16 | 北京深思数盾科技股份有限公司 | 一种通信配对方法及通信装置 |
| WO2022067841A1 (zh) * | 2020-10-01 | 2022-04-07 | 华为技术有限公司 | 一种安全通信方法、装置及系统 |
| US20220109996A1 (en) * | 2020-10-01 | 2022-04-07 | Qualcomm Incorporated | Secure communication link establishment for a ue-to-ue relay |
| WO2022079572A1 (en) * | 2020-10-12 | 2022-04-21 | Telefonaktiebolaget Lm Ericsson (Publ) | Relay ue and remote ue authorization |
-
2022
- 2022-05-06 CN CN202280084389.5A patent/CN118402262A/zh active Pending
- 2022-05-06 WO PCT/CN2022/091126 patent/WO2023212904A1/zh not_active Ceased
Patent Citations (5)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| WO2019000405A1 (zh) * | 2017-06-30 | 2019-01-03 | 华为技术有限公司 | 一种认证方法及终端、网络设备 |
| CN110022320A (zh) * | 2019-04-08 | 2019-07-16 | 北京深思数盾科技股份有限公司 | 一种通信配对方法及通信装置 |
| WO2022067841A1 (zh) * | 2020-10-01 | 2022-04-07 | 华为技术有限公司 | 一种安全通信方法、装置及系统 |
| US20220109996A1 (en) * | 2020-10-01 | 2022-04-07 | Qualcomm Incorporated | Secure communication link establishment for a ue-to-ue relay |
| WO2022079572A1 (en) * | 2020-10-12 | 2022-04-21 | Telefonaktiebolaget Lm Ericsson (Publ) | Relay ue and remote ue authorization |
Non-Patent Citations (2)
| Title |
|---|
| HUAWEI, HISILICON: "5G ProSe: New solution on e2e authentication between two UE2 in the UE-to- UE relay scenario", 3GPP DRAFT; S3-203442, 3RD GENERATION PARTNERSHIP PROJECT (3GPP), MOBILE COMPETENCE CENTRE ; 650, ROUTE DES LUCIOLES ; F-06921 SOPHIA-ANTIPOLIS CEDEX ; FRANCE, vol. SA WG3, no. e-meeting; 20201109 - 20201120, 16 November 2020 (2020-11-16), Mobile Competence Centre ; 650, route des Lucioles ; F-06921 Sophia-Antipolis Cedex ; France, XP052469609 * |
| INTERDIGITAL INC.: "KI #4, Sol #9 Update: Support of Privacy when using UE-to-UE Relay", 3GPP DRAFT; S2-2003817, 3RD GENERATION PARTNERSHIP PROJECT (3GPP), MOBILE COMPETENCE CENTRE ; 650, ROUTE DES LUCIOLES ; F-06921 SOPHIA-ANTIPOLIS CEDEX ; FRANCE, vol. SA WG2, no. Elbonia; 20200601 - 20200612, 22 May 2020 (2020-05-22), Mobile Competence Centre ; 650, route des Lucioles ; F-06921 Sophia-Antipolis Cedex ; France , XP051889839 * |
Also Published As
| Publication number | Publication date |
|---|---|
| CN118402262A (zh) | 2024-07-26 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| US11129009B2 (en) | Method and apparatus for providing secure communication in a self-organizing network | |
| CN108702626B (zh) | 无线广域网(wwan)无线局域网(wlan)聚合保全 | |
| US7499547B2 (en) | Security authentication and key management within an infrastructure based wireless multi-hop network | |
| CN111726804B (zh) | 用于集成小型小区和Wi-Fi网络的统一认证 | |
| US20150127949A1 (en) | System and method for integrated mesh authentication and association | |
| WO2023283789A1 (zh) | 一种安全通信方法及装置、终端设备、网络设备 | |
| US20250024261A1 (en) | Communication method and apparatus | |
| WO2023143022A1 (zh) | 用于随机接入过程中数据处理的方法和装置 | |
| WO2023137760A1 (zh) | 无线通信方法、远端ue、ausf以及amf | |
| CN120238862A (zh) | 一种通信方法及装置 | |
| WO2023212904A1 (zh) | 中继通信的方法及设备 | |
| WO2024060149A1 (zh) | 密钥验证方法、密钥获取方法及设备 | |
| WO2023212903A1 (zh) | 中继通信的方法及设备 | |
| US20250234252A1 (en) | Authenticated encryption with associated data (aead) modes during mobility scenarios | |
| US20260128876A1 (en) | Synchronizing devices based on a sequence number or key mismatch | |
| US20260129438A1 (en) | Synchronizing devices based on a temporary id mismatch | |
| US20250233728A1 (en) | Authenticated encryption with associated data (aead) modes for non-access stratum (nas) and access stratum (as) security | |
| US20260082276A1 (en) | Communication method, and device | |
| JP7634641B2 (ja) | デバイスのアクセス認証方法、端末デバイス及びクラウドプラットフォーム | |
| WO2023141914A1 (zh) | 信息保护方法和设备 | |
| WO2026093996A1 (en) | Synchronizing devices based on a temporary id mismatch | |
| WO2026025341A1 (zh) | 传输方法、终端设备和网络设备 | |
| WO2025229235A1 (en) | Apparatuses and methods for secure communication in a wireless communications system | |
| WO2026093994A1 (en) | Synchronizing devices based on a sequence number or key mismatch | |
| WO2026073511A1 (zh) | 通信方法、装置、设备以及存储介质 |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| 121 | Ep: the epo has been informed by wipo that ep was designated in this application |
Ref document number: 22940598 Country of ref document: EP Kind code of ref document: A1 |
|
| WWE | Wipo information: entry into national phase |
Ref document number: 202280084389.5 Country of ref document: CN |
|
| NENP | Non-entry into the national phase |
Ref country code: DE |
|
| 122 | Ep: pct application non-entry in european phase |
Ref document number: 22940598 Country of ref document: EP Kind code of ref document: A1 |