WO2024001086A1 - 一种基于共享密钥进行数据通信的方法、装置、设备和介质 - Google Patents
一种基于共享密钥进行数据通信的方法、装置、设备和介质 Download PDFInfo
- Publication number
- WO2024001086A1 WO2024001086A1 PCT/CN2022/140617 CN2022140617W WO2024001086A1 WO 2024001086 A1 WO2024001086 A1 WO 2024001086A1 CN 2022140617 W CN2022140617 W CN 2022140617W WO 2024001086 A1 WO2024001086 A1 WO 2024001086A1
- Authority
- WO
- WIPO (PCT)
- Prior art keywords
- application
- key
- identifier
- platform
- terminal device
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Ceased
Links
Images
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/08—Key distribution or management, e.g. generation, sharing or updating, of cryptographic keys or passwords
- H04L9/0816—Key establishment, i.e. cryptographic processes or cryptographic protocols whereby a shared secret becomes available to two or more parties, for subsequent use
- H04L9/085—Secret sharing or secret splitting, e.g. threshold schemes
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/06—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols the encryption apparatus using shift registers or memories for block-wise or stream coding, e.g. DES systems or RC4; Hash functions; Pseudorandom sequence generators
- H04L9/0643—Hash functions, e.g. MD5, SHA, HMAC or f9 MAC
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/08—Key distribution or management, e.g. generation, sharing or updating, of cryptographic keys or passwords
- H04L9/0861—Generation of secret information including derivation or calculation of cryptographic keys or passwords
Definitions
- the disclosure relates to the field of communication technology, and specifically to a method, device, equipment and medium for data communication based on a shared key.
- AKMA authentication and key management for applications
- a shared key between the APP side and the application backend can be generated for the application based on the shared key between the terminal and the network (denoted as K AUSF ) generated during the initial network authentication and key negotiation process. KAF .
- the remote UE User Equipment, terminal equipment
- the remote UE and the application platform cannot directly use
- the AKMA mechanism generates a shared key for the application layer.
- the purpose of this disclosure is to provide a method, device, equipment and medium for data communication based on a shared key, so as to overcome, at least to a certain extent, the problems between the remote UE and the application platform caused by the limitations and defects of related technologies.
- the problem of poor communication reliability is to provide a method, device, equipment and medium for data communication based on a shared key, so as to overcome, at least to a certain extent, the problems between the remote UE and the application platform caused by the limitations and defects of related technologies.
- the problem of poor communication reliability is to provide a method, device, equipment and medium for data communication based on a shared key, so as to overcome, at least to a certain extent, the problems between the remote UE and the application platform caused by the limitations and defects of related technologies.
- a method for data communication based on a shared key including: obtaining identification information of a remote terminal device; generating a terminal application identification according to the identification information of the remote terminal device; The terminal application identifier and the application platform key generate a corresponding application key; the terminal application identifier, the application key and the application key identifier are fed back to the remote terminal device, and the remote terminal device is Configured to send an application key identifier and a terminal application identifier to the relay application management platform through an application session request, so that the relay application management platform is configured to generate a corresponding application based on the terminal application identifier and the application platform key.
- the remote terminal device and the relay application management platform perform data communication based on the application key.
- the method before obtaining the identification information of the remote terminal device, further includes: performing primary authentication with the application layer and generating an anchor key; and generating an application platform based on the anchor key.
- key and the application key identifier requesting the establishment of an application session with the relay application management platform; sending the application key identifier to the relay application management platform, and the relay application management platform is configured to
- the application layer authentication and key management anchor function sends the application key identifier and the application platform identifier, and the application layer authentication and key management anchor function is configured to determine the application platform password based on the anchor key. key, and feedback the application platform key, the validity period of the application platform key and the terminal general public user identification to the relay application management platform; through the shared application platform key and the relay application Management platform for data communication.
- generating the corresponding application key according to the terminal application identifier and the application platform key includes: substituting the terminal application identifier and the application platform key into a key derivation function for calculation; The corresponding application key is determined according to the key derivation function.
- the method further includes: obtaining a communication identifier of the remote terminal device; generating an IPv6 interface identifier according to the communication identifier, and determining the corresponding remote terminal device according to the IPv6 interface identifier.
- the identification information ; allocate the IPv6 interface identification to the corresponding remote terminal device.
- the method further includes: obtaining a communication identifier of the remote terminal device; generating an IPv6 interface identifier according to the communication identifier, and determining the corresponding remote terminal device according to the IPv6 interface identifier. identification information; in response to the received data stream of the remote terminal device, use the generated IPv6 interface identifier to replace the IPv6 interface identifier in the data stream.
- the communication identifier includes at least one of MSISDN, GPSI, IMSI, SUPI, and MAC address.
- a device for data communication based on a shared key including: an acquisition module configured to acquire identification information of a remote terminal device; and a generating module configured to obtain identification information of a remote terminal device according to the The identification information of the device generates a terminal application identification; the generation module is configured to generate a corresponding application key according to the terminal application identification and the application platform key; the interaction module is configured to generate the terminal application identification, the application password The key and the application key identification are fed back to the remote terminal device.
- the remote terminal device is configured to send the application key identification and the terminal application identification to the relay application management platform through an application session request for the relay.
- the application management platform is configured to generate a corresponding application key according to the terminal application identification and application platform key, and the remote terminal device and the relay application management platform perform data communication based on the application key.
- an electronic device including: a memory; and a processor coupled to the memory, the processor being configured to perform any one of the above based on instructions stored in the memory. method described in the item.
- a computer-readable storage medium on which a program is stored.
- the program is executed by a processor, the method for data communication based on a shared key as described in any one of the above is implemented.
- the terminal application is finally The identity, application key and application key identification are fed back to the remote terminal device, and the remote terminal device is configured to send the application key identification and terminal application identification to the relay application management platform through the application session request for relay application management.
- the platform is configured to generate the corresponding application key based on the terminal application identification and application platform key.
- the remote terminal device and the relay application management platform conduct data communication based on the application key without upgrading the core network. This meets the secure communication requirements between the remote UE and the application management platform, and expands the application scenarios for near-domain communication.
- Figure 1 shows a schematic diagram of an exemplary system architecture in which a solution for data communication based on a shared key according to an embodiment of the present invention can be applied;
- Figure 2 is a schematic diagram of the 3GPP application layer authentication and key management architecture applied to the external application platform AF in an exemplary embodiment of the present disclosure
- Figure 3 is a schematic diagram of the authentication and key agreement process in an exemplary embodiment of the present disclosure
- Figure 4 is an interactive schematic diagram of data communication based on a shared key in an exemplary embodiment of the present disclosure
- Figure 5 is an interactive schematic diagram of the application layer key derivation process in an exemplary embodiment of the present disclosure
- Figure 6 is a flow chart of a method for data communication based on a shared key in an exemplary embodiment of the present disclosure
- Figure 7 is a flow chart of another method for data communication based on a shared key in an exemplary embodiment of the present disclosure.
- Figure 8 is a flow chart of another method for data communication based on a shared key in an exemplary embodiment of the present disclosure
- Figure 9 is a flow chart of another method for data communication based on a shared key in an exemplary embodiment of the present disclosure.
- Figure 10 is a flow chart of another method for data communication based on a shared key in an exemplary embodiment of the present disclosure
- Figure 11 shows a schematic diagram of an application layer key derivation process to which embodiments of the present invention can be applied;
- Figure 12 shows a schematic diagram of the system architecture of a data communication scheme based on a shared key that can apply an embodiment of the present invention
- Figure 13 shows a schematic diagram of a data communication solution based on a shared key to which embodiments of the present invention can be applied;
- Figure 14 shows a schematic diagram of a data communication interaction process based on a shared key to which embodiments of the present invention can be applied;
- Figure 15 is a block diagram of a device for data communication based on a shared key in an exemplary embodiment of the present disclosure
- Figure 16 is a block diagram of an electronic device in an exemplary embodiment of the present disclosure.
- Example embodiments will now be described more fully with reference to the accompanying drawings.
- Example embodiments may, however, be embodied in various forms and should not be construed as limited to the examples set forth herein; rather, these embodiments are provided so that this disclosure will be thorough and complete, and will fully convey the concepts of the example embodiments.
- the described features, structures or characteristics may be combined in any suitable manner in one or more embodiments.
- numerous specific details are provided to provide a thorough understanding of embodiments of the disclosure.
- those skilled in the art will appreciate that the technical solutions of the present disclosure may be practiced without one or more of the specific details described, or other methods, components, devices, steps, etc. may be adopted.
- well-known technical solutions have not been shown or described in detail to avoid obscuring aspects of the disclosure.
- FIG. 1 shows a schematic diagram of an exemplary system architecture to which a solution for data communication based on a shared key according to an embodiment of the present invention can be applied.
- the system architecture 100 may include one or more of terminal devices 101, 102, 103, a network 104 and a server 105.
- the network 104 is a medium used to provide communication links between the terminal devices 101, 102, 103 and the server 105.
- Network 104 may include various connection types, such as wired, wireless communication links, or fiber optic cables, among others.
- the number of terminal devices, networks and servers in Figure 1 is only illustrative. Depending on implementation needs, there can be any number of end devices, networks, and servers.
- the wireless network may also have other network functions, and the server 105 may be a server cluster composed of multiple servers, etc.
- terminal devices 101, 102, 103 Users can use terminal devices 101, 102, 103 to interact with the server 105 through the network 104 to receive or send messages, etc.
- the terminal devices 101, 102, and 103 may be various electronic devices with display screens, including but not limited to smart phones, tablet computers, portable computers, desktop computers, and so on.
- the terminal equipment described here, in addition to the terminal's own software and hardware functions, may also include application APP software to realize the above functions.
- the method for data communication based on a shared key provided by the embodiments of the present invention is generally executed by a network element in the communication network.
- a device for data communication based on a shared key is generally provided in the network element. .
- UDM Unified Data Management, unified data management functions, 3GPP AKA authentication, user identification, access authorization, registration, mobility, subscription, SMS management, etc.
- AUSF AuthenticationServer Function, authentication server function, realizes 3GPP and non-3GPP access authentication.
- AMF Access and Mobility Management Function, access and mobility management function, performs registration, connection, reachability, and mobility management.
- NEF Network Exposure Function, network opening function, opens the ability of each NF, converts internal and external information, and can also be used in edge computing scenarios.
- AF Application Function, application functions, various application platforms.
- UE User Equipment
- user equipment refers to various user terminal equipment.
- RAN Radio Access Network, wireless access network.
- HPLMN Home Public Land Mobile Network, local public land mobile network.
- ME Mobile Equipment, mobile equipment.
- IPv6 Internet Protocol Version 6, the abbreviation of Internet Protocol Version 6, is the next generation IP protocol designed by the Internet Engineering Task Force to replace IPv4.
- AAnf Application layer authentication and key management anchor function.
- FIG. 2 is a schematic diagram of the 3GPP application layer authentication and key management architecture applied to the external application platform AF in an exemplary embodiment of the present disclosure.
- the 3GPP application layer authentication and key management architecture 200 applied to the external application platform AF includes UDM, AUSF, AMF, RAN, NEF, UE, AF and AAnf, and performs application layer authentication as shown in the figure. and key management.
- Figure 3 is a schematic diagram of the authentication and key agreement process in an exemplary embodiment of the present disclosure.
- the 3GPP application layer authentication and key management architecture 300 applied to the internal application platform AF includes UDM, AUSF, AMF, RAN, UE, AF and AAnf, and performs application layer authentication and key management as shown in Figure 3. Key management.
- FIG. 4 is an interactive schematic diagram of data communication based on a shared key in an exemplary embodiment of the present disclosure.
- the interactive process 400 of data communication based on a shared key includes two parts: HPLMN and Serving Network.
- K AUSF is determined in HPLMN
- KAMF is determined based on K SEAF in the Serving Network
- K N3IWF and K are determined based on KAMF .
- Figure 5 is an interactive schematic diagram of the application layer key derivation process in an exemplary embodiment of the present disclosure.
- the application layer key derivation process 500 includes two processes of determining KAKMA by KAUSF and then determining K AF by KAKMA .
- FIG. 6 is a flowchart of a method for data communication based on a shared key in an exemplary embodiment of the present disclosure.
- a method for data communication based on a shared key may include:
- Step S602 Obtain the identification information of the remote terminal device.
- Step S604 Generate a terminal application identifier according to the identification information of the remote terminal device.
- Step S606 Generate a corresponding application key according to the terminal application identification and application platform key.
- Step S608 Feed back the terminal application identifier, the application key, and the application key identifier to a remote terminal device.
- the remote terminal device is configured to send an application to the relay application management platform through an application session request. Key identification and terminal application identification, so that the relay application management platform is configured to generate a corresponding application key according to the terminal application identification and application platform key, and the remote terminal device and the relay The application management platform performs data communication based on the application key.
- the terminal application is finally The identity, application key and application key identification are fed back to the remote terminal device, and the remote terminal device is configured to send the application key identification and terminal application identification to the relay application management platform through the application session request for relay application management.
- the platform is configured to generate the corresponding application key based on the terminal application identification and application platform key.
- the remote terminal device and the relay application management platform conduct data communication based on the application key without upgrading the core network. This meets the secure communication requirements between the remote UE and the application management platform, and expands the application scenarios for near-domain communication.
- the method before obtaining the identification information of the remote terminal device, the method further includes:
- Step S702 Perform primary authentication with the application layer and generate an anchor key.
- Step S704 Generate an application platform key and the application key identifier based on the anchor key.
- Step S706 Request to establish an application session with the relay application management platform.
- Step S708 Send the application key identification to the relay application management platform.
- the relay application management platform is configured to send the application key identification and application platform to the application layer authentication and key management anchor function.
- identification, the application layer authentication and key management anchor function is configured to determine the application platform key based on the anchor key, and combine the application platform key, the validity period of the application platform key, and The terminal's general public user identity is fed back to the relay application management platform.
- Step S710 Perform data communication with the relay application management platform through the shared application platform key.
- generating a corresponding application key according to the terminal application identification and application platform key includes:
- Step S802 Substitute the terminal application identifier and the application platform key into a key derivation function for calculation.
- Step S804 Determine the corresponding application key according to the key derivation function.
- 3GPP refers to "HMAC: Keyed-Hashing for Message Authentication” in IETF RFC 2104 and ISO/IEC 10118-3:2004. "Information Technology–Security techniques–Hash-functions–Part 3: Dedicated hash-functions”.
- the above parameter expression may also be in the following manner:
- FC You can select one of the fields 0xF0-0xFE reserved by 3GPP (0xF0 and 0xFE are both hexadecimal);
- UE-APP-ID UE-ID
- HMAC is a method of using a one-way hash function to construct a message authentication code, where the H in HMAC means Hash.
- the one-way hash function used in HMAC is not limited to one type. Any high-strength one-way hash function can be used for HMAC. If a new one-way hash function is designed in the future, it can also be used.
- HMAC constructed using SHA-1, SHA-224, SHA-256, SHA-384, and SHA-512 are called HMAC-SHA1, HMAC-SHA-224, HMAC-SHA-384, and HMAC-SHA-512 respectively.
- the calculation steps of HMAC include:
- Key padding If the key is shorter than the block length of the one-way hash function, 0s need to be padded at the end until its length reaches the block length of the one-way hash function. If the key is longer than the block length, a one-way hash function is used to find the hash value of the key, and then this hash value is used as the HMAC key.
- XOR the padded key and ipad XOR the padded key with the bit sequence called ipad.
- ipad is a bit sequence formed by repeating the bit sequence 00110110 until it reaches the packet length, where i in ipad means inner.
- the value obtained by the XOR operation is a bit sequence with the same block length as the one-way hash function and related to the key. This bit sequence is called ipadkey here.
- XOR of the padded key and opad XOR the padded key with a bit sequence called opad.
- opad is a bit sequence formed by repeating the bit sequence 01011100 until the packet length is reached. , where o in opad means outer.
- the result of the XOR operation is also a bit sequence with the same block length as the one-way hash function and related to the key. This bit sequence is called opadkey here.
- the method for data communication based on a shared key further includes:
- Step S902 Obtain the communication identifier of the remote terminal device.
- Step S904 Generate an IPv6 interface identifier based on the communication identifier, and determine identification information of the corresponding remote terminal device based on the IPv6 interface identifier.
- Step S906 Allocate the IPv6 interface identifier to the corresponding remote terminal device.
- the relay UE needs to obtain the ID of the remote UE.
- the ID of the remote UE can be MSISDN/GPSI, IMSI/SUPI, MAC address, etc.
- the subsequent UE can allocate the IPv6 interface ID to the remote UE after generating the IPv6 interface ID using the remote UE ID.
- the method for data communication based on a shared key further includes:
- Step S1002 Obtain the communication identifier of the remote terminal device.
- Step S1004 Generate an IPv6 interface identifier based on the communication identifier, and determine identification information of the corresponding remote terminal device based on the IPv6 interface identifier.
- Step S1006 In response to the received data stream of the remote terminal device, use the generated IPv6 interface identifier to replace the IPv6 interface identifier in the data stream.
- the source IPv6 interface ID needs to be replaced in the data stream of the remote UE with the IPv6 interface ID generated using the remote UE ID.
- the core network while realizing data communication between the remote terminal device and the relay application management platform based on the application key, the core network needs to separately count the traffic of different source IPv6 interface IDs, respectively. Generate traffic records and send them to the IT system for billing.
- the communication identifier includes at least one of MSISDN, GPSI, IMSI, SUPI, and MAC address.
- IMSI International Mobile Subscriber Identification Number (International Mobile Subscriber Identification Number). It is a symbol that distinguishes mobile users. It is stored in the EF-IMSI file of the SIM card and can be used to distinguish effective information about mobile users. IMSI is the ID number of the SIM card, which can distinguish each SIM card. IMSI consists of a string of decimal digits, with a maximum length of 15 digits. Most of the actual IMSI lengths are 15 digits.
- MSISDN MobileSubscriber International ISDN number
- MSISDN numbers MobileSubscriber International ISDN number
- NDC National Destination Code
- domestic destination code also known as network access code
- network access code is assigned to each network operator by the communications authorities of each country.
- China Mobile's network access codes are 134 ⁇ 139, 150 ⁇ 152, 188, etc.
- China Unicom's are 130 ⁇ 132, 185 ⁇ 186, etc.
- China Telecom's are 133, 153, 180, 189, etc.
- SUPI Subscription Permanent Identifier, user permanent identification, similar to 4G's IMSI.
- the true identity of the mobile phone is called SUPI (SUbscription Permanent Identifier, user permanent identifier) in 5G, similar to IMSI.
- the ciphertext encrypted by the public key is called SUCI (Subscription Concealed Identifier, user hidden identifier), and SUCI is transmitted to the base station Then, the base station directly uploads it to the core network.
- GPSI Generic PublicSubscription Identifier, a universal public user identifier, which is equivalent to the MSISDN of 4G. There is not necessarily a one-to-one correspondence between SUPI and GPSI. If a user accesses different data networks, there will be multiple GPSI identifiers, and the network needs to add the external network GPSI Build a relationship with SUPI. NEF can realize the mapping relationship between External GPSI and Inter GPSI, and the UDR stores the mapping relationship between Internal GPSI and SUPI.
- MAC Medium/Media Access Control address, used to represent the identifier of each site on the Internet, expressed in hexadecimal numbers, with a total of six bytes (48 bits). Among them, the first three bytes are codes (high-order 24 bits) assigned to different manufacturers by the IEEE registration management agency RA, also known as "Organizationally Unique Identifier", and the last three bytes are (lower 24 bits) is assigned by each manufacturer to the adapter interface produced, called an extended identifier (uniqueness). An address block can generate 2 different addresses. The MAC address is actually the adapter address or adapter identifier.
- Figure 11 shows a schematic diagram of an application layer key derivation process to which embodiments of the present invention can be applied.
- the application layer key derivation process 1100 includes: adding a new KAPP derived from K AF (the required number is determined according to the number of remote UEs).
- the KAPPn is generated and sent by the relay ME ad hoc network.
- FIG. 12 shows a schematic diagram of a system architecture of a data communication scheme based on a shared key that can be applied according to an embodiment of the present invention.
- the system architecture may include a remote terminal device 1202, a relay terminal device 1204, a wireless network and the Internet 1210.
- a wireless network is a medium used to provide a communication link between end devices and servers.
- the wireless network may include base stations 1206, user plane functions 1208, access and mobility management functions 1212, and session management functions 1214. Connection types of wireless networks include, but are not limited to, wired, wireless communication links, or fiber optic cables.
- Figure 13 shows a schematic diagram of a data communication solution based on a shared key to which embodiments of the present invention can be applied.
- the solution for data communication based on shared keys includes the following processes:
- Step S1302 The relay UE completes the main authentication, generates the shared key K AUSF , generates the anchor key KAKMA and the application key identification A-KID based on K AUSF , and completes the negotiation and generation of K AF with the platform AF.
- Step S1304 The remote UE establishes a connection with the relay UE, and the relay UE obtains the remote UE ID.
- Step S1306 The relay UE generates a UE-APP-ID for the remote UE, and uses the UE-APP-ID and K AF to generate K-app.
- Step S1308 The relay UE sends the UE-APP-ID, application key K-app and A-KID to the remote UE.
- Step S1310 The application platform AF uses the UE-APP-ID and the application platform key K AF to generate the application key K-app.
- Step S1312 K-app is used for secure communication between the remote UE and the platform AF.
- Figure 14 shows a schematic diagram of a data communication interaction process based on a shared key to which embodiments of the present invention can be applied.
- the data communication interaction process based on the shared key mainly involves the remote UE1402, the relay UE1404, the authentication server function 1406, the application layer authentication and key management anchor function (AAnf) 1408, and the network opening function (NEF).
- the relay UE 1404 and the application layer authentication and key management anchor function (AAnf) 1408 perform master authentication and K AKMA key establishment, and the relay UE 1404 generates A-KID and K AF , carried out between the relay UE1404 and the relay application management platform (AF) 1412.
- the relay application management platform AF1412 sends A-KID and AF_ID, and obtains K AF , K AF validity period, and mobile phone number GPSI from AAnF via NEF. Waiting, the application session establishment response between the relay UE1404 and the relay application management platform (AF) 1412, the relay UE1404 uses the shared key K AF to perform secure communication, and then the remote UE and the relay application management platform (AF) Secure communication between 1412 is mainly achieved through the following steps:
- the remote UE1402 establishes a secure connection with the relay UE1404, and the relay UE1404 obtains the ID of the remote UE1402.
- the relay UE1404 uses the ID of the remote UE1402 to generate UE_APP_ID.
- Relay UE1404 uses UE_APP_ID and K AF to generate K_app.
- the relay UE1404 sends UE_APP_ID, K_app, and A-KID to the remote UE1402.
- Application session establishment request (A-KID, UE_APP_ID) between the remote UE 1402 and the relay application management platform (AF) 1412.
- the relay application management platform (AF) 1412 uses UE_APP_ID and K AF to generate K_app.
- the remote UE 1402 and the relay application management platform (AF) 1412 use the shared key K_app to communicate securely.
- the present disclosure also provides a device for data communication based on a shared key, which can be used to execute the above method embodiments.
- Figure 15 is a block diagram of a device for data communication based on a shared key in an exemplary embodiment of the present disclosure.
- a device 1500 for data communication based on a shared key may include:
- the acquisition module 1502 is configured to obtain the identification information of the remote terminal device.
- the generation module 1504 is configured to generate a terminal application identification according to the identification information of the remote terminal device.
- the generation module 1504 is configured to generate a corresponding application key according to the terminal application identification and application platform key.
- the interaction module 1506 is configured to feed back the terminal application identifier, the application key, and the application key identifier to a remote terminal device, and the remote terminal device is configured to request relay application management through an application session request.
- the platform sends the application key identification and the terminal application identification so that the relay application management platform is configured to generate the corresponding application key according to the terminal application identification and the application platform key, and the remote terminal device communicates with the The relay application management platform performs data communication based on the application key.
- the interaction module 1506 is further configured to: perform primary authentication with the application layer and generate an anchor key; generate an application platform key and the application secret key based on the anchor key.
- Key identification requesting the establishment of an application session with the relay application management platform; sending the application key identification to the relay application management platform, the relay application management platform being configured to provide application layer authentication and key management
- the anchor point function sends the application key identification and application platform identification
- the application layer authentication and key management anchor point function is configured to determine the application platform key according to the anchor point key and transfer the application
- the platform key, the validity period of the application platform key and the terminal general public user identification are fed back to the relay application management platform; data communication is performed with the relay application management platform through the shared application platform key.
- the generation module 1504 is further configured to: substitute the terminal application identifier and the application platform key into a key derivation function for calculation; determine the corresponding key derivation function according to the key derivation function. Application key.
- the interaction module 1506 is further configured to: obtain the communication identifier of the remote terminal device; generate an IPv6 interface identifier based on the communication identifier, and determine the corresponding IPv6 interface identifier based on the IPv6 interface identifier. Identification information of the remote terminal device; allocate the IPv6 interface identifier to the corresponding remote terminal device.
- the interaction module 1506 is further configured to: obtain the communication identifier of the remote terminal device; generate an IPv6 interface identifier based on the communication identifier, and determine the corresponding IPv6 interface identifier based on the IPv6 interface identifier. Identification information of the remote terminal device; in response to the received data stream of the remote terminal device, use the generated IPv6 interface identifier to replace the IPv6 interface identifier in the data stream.
- the communication identifier includes at least one of MSISDN, GPSI, IMSI, SUPI, and MAC address.
- an electronic device capable of implementing the above method is also provided.
- FIG. 16 An electronic device 1600 according to this embodiment of the invention is described below with reference to FIG. 16 .
- the electronic device 1600 shown in FIG. 16 is only an example and should not bring any limitations to the functions and scope of use of the embodiments of the present invention.
- electronic device 1600 is embodied in the form of a general computing device.
- the components of the electronic device 1600 may include, but are not limited to: the above-mentioned at least one processing unit 1610, the above-mentioned at least one storage unit 1620, and a bus 1630 connecting different system components (including the storage unit 1620 and the processing unit 1610).
- the storage unit stores program code, and the program code can be executed by the processing unit 1610, so that the processing unit 1610 performs various exemplary methods according to the present invention described in the above-mentioned "Example Method" section of this specification. Implementation steps.
- the processing unit 1610 may perform the method shown in the embodiment of the present disclosure.
- the storage unit 1620 may include a readable medium in the form of a volatile storage unit, such as a random access storage unit (RAM) 16201 and/or a cache storage unit 16202, and may further include a read-only storage unit (ROM) 16203.
- RAM random access storage unit
- ROM read-only storage unit
- Storage unit 1620 may also include a program/utility 16204 having a set of (at least one) program modules 16205 including, but not limited to: an operating system, one or more application programs, other program modules, and program data, Each of these examples, or some combination, may include the implementation of a network environment.
- program/utility 16204 having a set of (at least one) program modules 16205 including, but not limited to: an operating system, one or more application programs, other program modules, and program data, Each of these examples, or some combination, may include the implementation of a network environment.
- Bus 1630 may be a local area representing one or more of several types of bus structures, including a memory unit bus or memory unit controller, a peripheral bus, a graphics acceleration port, a processing unit, or using any of a variety of bus structures. bus.
- Electronic device 1600 may also communicate with one or more external devices 1640 (e.g., keyboard, pointing device, Bluetooth device, etc.), may also communicate with one or more devices that enable a user to interact with electronic device 1600, and/or with Any device (eg, router, modem, etc.) that enables the electronic device 1600 to communicate with one or more other computing devices. This communication may occur through input/output (I/O) interface 1650.
- the electronic device 1600 may also communicate with one or more networks (eg, a local area network (LAN), a wide area network (WAN), and/or a public network, such as the Internet) through the network adapter 1660. As shown, network adapter 1660 communicates with other modules of electronic device 1600 via bus 1630.
- network adapter 1660 communicates with other modules of electronic device 1600 via bus 1630.
- the example embodiments described here can be implemented by software, or can be implemented by software combined with necessary hardware. Therefore, the technical solution according to the embodiment of the present disclosure can be embodied in the form of a software product, which can be stored in a non-volatile storage medium (which can be a CD-ROM, U disk, mobile hard disk, etc.) or on the network , including several instructions to cause a computing device (which may be a personal computer, a server, a terminal device, a network device, etc.) to execute a method according to an embodiment of the present disclosure.
- a computing device which may be a personal computer, a server, a terminal device, a network device, etc.
- a computer-readable storage medium is also provided, on which a program product capable of implementing the method described above in this specification is stored.
- various aspects of the present invention can also be implemented in the form of a program product, which includes program code.
- the program product is run on a terminal device, the program code is used to cause the The terminal device performs the steps according to various exemplary embodiments of the present invention described in the "Exemplary Method" section above in this specification.
- the program product for implementing the above method according to the embodiment of the present invention may adopt a portable compact disk read-only memory (CD-ROM) and include the program code, and may be run on a terminal device, such as a personal computer.
- a readable storage medium may be any tangible medium containing or storing a program that may be used by or in combination with an instruction execution system, apparatus or device.
- the program product may take the form of any combination of one or more readable media.
- the readable medium may be a readable signal medium or a readable storage medium.
- the readable storage medium may be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, device or device, or any combination thereof. More specific examples (non-exhaustive list) of readable storage media include: electrical connection with one or more conductors, portable disk, hard disk, random access memory (RAM), read only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber, portable compact disk read-only memory (CD-ROM), optical storage device, magnetic storage device, or any suitable combination of the above.
- a computer-readable signal medium may include a data signal propagated in baseband or as part of a carrier wave carrying readable program code therein. Such propagated data signals may take many forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination of the above.
- a readable signal medium may also be any readable medium other than a readable storage medium that can send, propagate, or transport the program for use by or in connection with an instruction execution system, apparatus, or device.
- Program code embodied on a readable medium may be transmitted using any suitable medium, including but not limited to wireless, wireline, optical cable, RF, etc., or any suitable combination of the foregoing.
- Program code for performing the operations of the present invention may be written in any combination of one or more programming languages, including object-oriented programming languages such as Java, C++, etc., as well as conventional procedural Programming language—such as "C" or a similar programming language.
- the program code may execute entirely on the user's computing device, partly on the user's device, as a stand-alone software package, partly on the user's computing device and partly on a remote computing device, or entirely on the remote computing device or server execute on.
- the remote computing device may be connected to the user computing device through any kind of network, including a local area network (LAN) or a wide area network (WAN), or may be connected to an external computing device, such as provided by an Internet service. (business comes via Internet connection).
- LAN local area network
- WAN wide area network
- the remote terminal device by obtaining the identification information of the remote terminal device, generating the terminal application identification according to the identification information of the remote terminal equipment, and then generating the corresponding application key according to the terminal application identification and the application platform key, finally the terminal application identification,
- the application key and application key identification are fed back to the remote terminal device, and the remote terminal device is configured to send the application key identification and terminal application identification to the relay application management platform through the application session request, so that the relay application management platform can be It is configured to generate the corresponding application key based on the terminal application identification and application platform key.
- the remote terminal device and the relay application management platform conduct data communication based on the application key. Without the need to upgrade the core network, It meets the secure communication requirements between remote UE and application management platform, and expands the application scenarios of near-domain communication.
Landscapes
- Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Power Engineering (AREA)
- Mobile Radio Communication Systems (AREA)
- Telephone Function (AREA)
Abstract
Description
Claims (10)
- 一种基于共享密钥进行数据通信的方法,其特征在于,适用于中继终端设备,所述基于共享密钥进行数据通信的方法包括:获取远端终端设备的标识信息;根据所述远端终端设备的标识信息生成终端应用标识;根据所述终端应用标识和应用平台密钥生成相应的应用密钥;将所述终端应用标识、所述应用密钥和所述应用密钥标识反馈至远端终端设备,所述远端终端设备被配置为通过应用会话请求向中继应用管理平台发送应用密钥标识和终端应用标识,以供所述中继应用管理平台被配置为能够根据所述终端应用标识和应用平台密钥生成相应的应用密钥,所述远端终端设备与所述中继应用管理平台基于所述应用密钥进行数据通信。
- 如权利要求1所述的基于共享密钥进行数据通信的方法,其特征在于,在获取远端终端设备的标识信息前,还包括:通过与应用层进行主认证并生成锚点密钥;基于所述锚点密钥生成应用平台密钥和所述应用密钥标识;请求与所述中继应用管理平台建立应用会话;向所述中继应用管理平台发送所述应用密钥标识,所述中继应用管理平台被配置为向应用层认证和密钥管理锚点功能发送所述应用密钥标识和应用平台标识,所述应用层认证和密钥管理锚点功能被配置为根据所述锚点密钥确定所述应用平台密钥,并将所述应用平台密钥、所述应用平台密钥的有效期和终端通用公共用户标识反馈至所述中继应用管理平台;通过共享的所述应用平台密钥与所述中继应用管理平台进行数据通信。
- 如权利要求1所述的基于共享密钥进行数据通信的方法,其特征在于,根据终端应用标识和应用平台密钥生成相应的应用密钥包括:将所述终端应用标识和所述应用平台密钥代入密钥导出函数进行计算;根据所述密钥导出函数确定相应的应用密钥。
- 如权利要求3所述的基于共享密钥进行数据通信的方法,其特征在于,所述密钥导出函数的表达式包括:K-APP=HMAC-SHA-256(K AF,S);S=FC||P0||L0,其中,所述HMAC-SHA-256(K AF,S)表征以所述K AF和所述S为参数的密钥导出函数,所述K AF表征所述应用平台密钥,所述K-APP表征所述应用密钥,所述S表征中间参数,所述FC表征3GPP的保留字段,所述P0表征所述终端应用标识,所述L0表征所述终端应用标识的字符长度。
- 如权利要求1-4中任一项所述的基于共享密钥进行数据通信的方法,其特征在于,还包括:获取远端终端设备的通信标识符;根据所述通信标识符生成IPv6接口标识,并根据所述IPv6接口标识确定对应的远端终端设备的标识信息;将所述IPv6接口标识分配至对应的远端终端设备。
- 如权利要求1-4中任一项所述的基于共享密钥进行数据通信的方法,其特征在于,还包括:获取远端终端设备的通信标识符;根据所述通信标识符生成IPv6接口标识,并根据所述IPv6接口标识确定对应的远端终端设备的标识信息;响应于接收到的所述远端终端设备的数据流,采用生成的IPv6接口标识替换所述数据流中的IPv6接口标识。
- 如权利要求6所述的基于共享密钥进行数据通信的方法,其特征在于,所述通信标识符包括MSISDN、GPSI、IMSI、SUPI、MAC地址中的至少一种。
- 一种基于共享密钥进行数据通信的装置,其特征在于,包括:获取模块,设置为获取远端终端设备的标识信息;生成模块,设置为根据所述远端终端设备的标识信息生成终端应用标识;所述生成模块,设置为根据所述终端应用标识和应用平台密钥生成相应的应用密钥;交互模块,设置为将所述终端应用标识、所述应用密钥和所述应用密钥标识反馈至远端终端设备,所述远端终端设备被配置为通过应用会话请求向中继应用管理平台发送应用密钥标识和终端应用标识,以供所述中继应用管理平台被配置为能够根据所述终端应用标识和应用平台密钥生成相应的应用密钥,所述远端终端设备与所述中继应用管理平台基于所述应用密钥进行数据通信。
- 一种电子设备,其特征在于,包括:存储器;以及耦合到所述存储器的处理器,所述处理器被配置为基于存储在所述存储器中的指令,执行如权利要求1-7任一项所述的基于共享密钥进行数据通信的方法。
- 一种计算机可读存储介质,其上存储有程序,该程序被处理器执行时实现如权利要求1-7任一项所述的基于共享密钥进行数据通信的方法。
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| CN202210745225.4A CN115150075B (zh) | 2022-06-27 | 2022-06-27 | 基于共享密钥进行数据通信的方法、装置、设备和介质 |
| CN202210745225.4 | 2022-06-27 |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| WO2024001086A1 true WO2024001086A1 (zh) | 2024-01-04 |
Family
ID=83410628
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| PCT/CN2022/140617 Ceased WO2024001086A1 (zh) | 2022-06-27 | 2022-12-21 | 一种基于共享密钥进行数据通信的方法、装置、设备和介质 |
Country Status (2)
| Country | Link |
|---|---|
| CN (1) | CN115150075B (zh) |
| WO (1) | WO2024001086A1 (zh) |
Families Citing this family (1)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN115150075B (zh) * | 2022-06-27 | 2024-12-24 | 中国电信股份有限公司 | 基于共享密钥进行数据通信的方法、装置、设备和介质 |
Citations (4)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US20210360742A1 (en) * | 2018-10-03 | 2021-11-18 | Apple Inc. | Systems, methods, and apparatuses for enabling relay services for user equipment to access 5gc via a residential gateway |
| WO2022019627A1 (en) * | 2020-07-20 | 2022-01-27 | Samsung Electronics Co., Ltd. | Methods and systems for establishing secure communication in wireless communication system |
| WO2022088029A1 (zh) * | 2020-10-30 | 2022-05-05 | 华为技术有限公司 | 密钥获取方法和通信装置 |
| CN115150075A (zh) * | 2022-06-27 | 2022-10-04 | 中国电信股份有限公司 | 基于共享密钥进行数据通信的方法、装置、设备和介质 |
Family Cites Families (4)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN113348690B (zh) * | 2019-01-14 | 2024-01-30 | 瑞典爱立信有限公司 | 用于安全的方法和装置 |
| CN113162758B (zh) * | 2020-01-23 | 2023-09-19 | 中国移动通信有限公司研究院 | 一种密钥生成方法及设备 |
| MX2022010227A (es) * | 2020-02-21 | 2022-09-19 | Ericsson Telefon Ab L M | Seleccion de funcion de servidor de autenticacion en autenticacion y administracion de claves. |
| CN113543126B (zh) * | 2020-03-31 | 2023-02-28 | 华为技术有限公司 | 密钥获取方法及装置 |
-
2022
- 2022-06-27 CN CN202210745225.4A patent/CN115150075B/zh active Active
- 2022-12-21 WO PCT/CN2022/140617 patent/WO2024001086A1/zh not_active Ceased
Patent Citations (4)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US20210360742A1 (en) * | 2018-10-03 | 2021-11-18 | Apple Inc. | Systems, methods, and apparatuses for enabling relay services for user equipment to access 5gc via a residential gateway |
| WO2022019627A1 (en) * | 2020-07-20 | 2022-01-27 | Samsung Electronics Co., Ltd. | Methods and systems for establishing secure communication in wireless communication system |
| WO2022088029A1 (zh) * | 2020-10-30 | 2022-05-05 | 华为技术有限公司 | 密钥获取方法和通信装置 |
| CN115150075A (zh) * | 2022-06-27 | 2022-10-04 | 中国电信股份有限公司 | 基于共享密钥进行数据通信的方法、装置、设备和介质 |
Non-Patent Citations (2)
| Title |
|---|
| HUAWEI, HISILICON: "Solution on key management in UE-to-network relay based on primary authentication", 3GPP DRAFT; S3-203432, 3RD GENERATION PARTNERSHIP PROJECT (3GPP), MOBILE COMPETENCE CENTRE ; 650, ROUTE DES LUCIOLES ; F-06921 SOPHIA-ANTIPOLIS CEDEX ; FRANCE, vol. SA WG3, no. E-meeting; 20201109 - 20201120, 16 November 2020 (2020-11-16), Mobile Competence Centre ; 650, route des Lucioles ; F-06921 Sophia-Antipolis Cedex ; France , XP051955237 * |
| QUALCOMM INCORPORATED: "Sending UE identifier to the AKMA AF", 3GPP DRAFT; S3-203191, 3RD GENERATION PARTNERSHIP PROJECT (3GPP), MOBILE COMPETENCE CENTRE ; 650, ROUTE DES LUCIOLES ; F-06921 SOPHIA-ANTIPOLIS CEDEX ; FRANCE, vol. SA WG3, no. e-meeting; 20201109 - 20201120, 30 October 2020 (2020-10-30), Mobile Competence Centre ; 650, route des Lucioles ; F-06921 Sophia-Antipolis Cedex ; France , XP051949767 * |
Also Published As
| Publication number | Publication date |
|---|---|
| CN115150075A (zh) | 2022-10-04 |
| CN115150075B (zh) | 2024-12-24 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| US12348959B2 (en) | Session request method and apparatus, terminal, and storage medium | |
| US20230033598A1 (en) | Network key processing method and system and related device | |
| CN101406021B (zh) | 基于sim的认证 | |
| EP4271015B1 (en) | Registration method and apparatus, authentication method and apparatus, routing indicator determining method and apparatus, entity, and terminal | |
| US8091116B2 (en) | Communication system and method | |
| CN111327583B (zh) | 一种身份认证方法、智能设备及认证服务器 | |
| CN112512045B (zh) | 一种通信系统、方法及装置 | |
| US20220225095A1 (en) | External Authentication Method, Communication Apparatus, and Communication System | |
| US8582542B2 (en) | Communication system and method | |
| CN105682253A (zh) | 建立通信的方法、设备、终端和计算机可读存储介质 | |
| KR20050027015A (ko) | 셀룰러 시스템과 연관된 보안값(들)에 기초하여 무선근거리 네트워크에 대한 액세스를 인증하는 방법 | |
| US12207350B2 (en) | System and methods for subscriber identifier authentication and privacy | |
| JP2015503303A (ja) | セキュリティで保護された通信システムおよび通信方法 | |
| CN102685856A (zh) | 无线通信方法与无线直接连接通信系统 | |
| WO2019149006A1 (zh) | 获取、提供无线接入点接入信息的方法、设备以及介质 | |
| US9807819B1 (en) | Cross-technology session continuity | |
| WO2020147602A1 (zh) | 一种认证方法、装置和系统 | |
| WO2021081900A1 (zh) | 通信方法及相关装置 | |
| WO2024001086A1 (zh) | 一种基于共享密钥进行数据通信的方法、装置、设备和介质 | |
| US12477343B2 (en) | Mobile virtual network operator network access control | |
| JP2022076669A (ja) | 情報処理装置、情報処理プログラム、及び通信システム | |
| KR100684965B1 (ko) | 인터넷 프로토콜 버젼 6 식별자를 이용하여 인터넷프로토콜 버젼 6 주소를 자동으로 생성하는 방법 | |
| CN118614099A (zh) | 基于tls-psk的用于接入边缘数据网络的认证机制 | |
| CN110933670A (zh) | 一种实现主认证增强的安全usim卡及终端的主认证方法 | |
| CN109155913B (zh) | 网络连接方法、安全节点的确定方法及装置 |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| 121 | Ep: the epo has been informed by wipo that ep was designated in this application |
Ref document number: 22949162 Country of ref document: EP Kind code of ref document: A1 |
|
| NENP | Non-entry into the national phase |
Ref country code: DE |
|
| 122 | Ep: pct application non-entry in european phase |
Ref document number: 22949162 Country of ref document: EP Kind code of ref document: A1 |
|
| 32PN | Ep: public notification in the ep bulletin as address of the adressee cannot be established |
Free format text: NOTING OF LOSS OF RIGHTS PURSUANT TO RULE 112(1) EPC (EPO FORM 1205A DATED 03.04.2025) |
|
| 122 | Ep: pct application non-entry in european phase |
Ref document number: 22949162 Country of ref document: EP Kind code of ref document: A1 |