WO2025119355A1 - 交互方法、装置、系统、终端及网络侧设备 - Google Patents
交互方法、装置、系统、终端及网络侧设备 Download PDFInfo
- Publication number
- WO2025119355A1 WO2025119355A1 PCT/CN2024/137563 CN2024137563W WO2025119355A1 WO 2025119355 A1 WO2025119355 A1 WO 2025119355A1 CN 2024137563 W CN2024137563 W CN 2024137563W WO 2025119355 A1 WO2025119355 A1 WO 2025119355A1
- Authority
- WO
- WIPO (PCT)
- Prior art keywords
- information
- security
- terminal
- target
- algorithm
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Pending
Links
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W12/00—Security arrangements; Authentication; Protecting privacy or anonymity
- H04W12/03—Protecting confidentiality, e.g. by encryption
- H04W12/037—Protecting confidentiality, e.g. by encryption of the control plane, e.g. signalling traffic
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W12/00—Security arrangements; Authentication; Protecting privacy or anonymity
- H04W12/03—Protecting confidentiality, e.g. by encryption
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W12/00—Security arrangements; Authentication; Protecting privacy or anonymity
- H04W12/10—Integrity
- H04W12/106—Packet or message integrity
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W12/00—Security arrangements; Authentication; Protecting privacy or anonymity
- H04W12/60—Context-dependent security
- H04W12/69—Identity-dependent
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W4/00—Services specially adapted for wireless communication networks; Facilities therefor
- H04W4/20—Services signaling; Auxiliary data signalling, i.e. transmitting data via a non-traffic channel
Definitions
- the present application belongs to the field of communication technology, and specifically relates to an interaction method, device, system, terminal and network side equipment.
- small data transmission mainly includes small data transmission initiated by the mobile terminal (Mobile Originated SDT, MO-SDT) transmitted on the physical uplink shared channel (PUSCH) of the uplink message 3 (Msg3) or the configured grant (Configured Grant, CG) triggered by the terminal, or small data transmission terminated by the mobile terminal (Mobile Terminated SDT, MT-SDT) triggered by the downlink.
- PUSCH physical uplink shared channel
- Msg3 uplink message 3
- configured Grant Configured Grant, CG
- small data transmission terminated by the mobile terminal Mobile Terminated SDT, MT-SDT
- the embodiments of the present application provide an interactive method, apparatus, system, terminal and network-side equipment, which can solve the problem of large delay in small data transmission.
- an interaction method comprising:
- the terminal receives target wireless signaling, where the target wireless signaling includes first identification information and first target information, where the first target information includes at least one of encryption information and integrity protection information;
- the terminal When the terminal is related to the first identification information, the terminal performs at least one of the following:
- the first operation includes at least one of the following:
- the second operation includes at least one of the following:
- the first security requirement is generated based on the first derived information, and the first security requirement includes at least one of a key and a secret stream;
- the first derived information includes at least one of the following: a core network-related key, a non-access layer NAS layer-related key, an access network-related key, an access layer AS layer-related key, and a key in a terminal context;
- the fourth derived information includes at least one of the following: a core network-related key, a non-access layer NAS layer-related key, an access network-related key, an access layer AS layer-related key, a key in a terminal context, and the third security parameter;
- the second security requirement includes at least one of a key and a secret stream.
- an interaction method comprising:
- the access network node sends a target wireless signaling, where the target wireless signaling includes first identification information and first target information, where the first target information includes at least one of encryption information and integrity protection information;
- the encryption information and integrity protection information are generated based on a first security requirement, and the first security requirement includes at least one of a secret key and a secret stream.
- a third aspect provides an interaction method, comprising:
- the core network node sends third information or target data to the access network node, where the third information includes second identification information and second target information;
- the second target information includes at least one of the following:
- Second security assistance information wherein the second security assistance information includes information in the terminal core network context
- the first algorithm information packet security requirement derives at least one of an algorithm, a confidentiality algorithm, and an integrity algorithm; the first security requirement includes at least one of a secret key and a secret stream, the third security requirement includes at least one of a secret key and a secret stream, and the second identification information indicates a terminal, or is generated by a terminal identification, or indicates a group of terminals.
- an interaction method comprising:
- the access network node sends a target wireless signaling, where the target wireless signaling includes first identification information and first target information, where the first target information includes at least one of encryption information and integrity protection information, where the encryption information and the integrity protection information are generated based on the first security requirement;
- the terminal receives the target wireless signaling
- the terminal When the terminal is related to the first identification information, the terminal performs at least one of the following:
- the first operation includes at least one of the following:
- the second operation includes at least one of the following:
- the first security requirement is generated based on the first derived information, and the first security requirement includes at least one of a secret key and a secret stream;
- the first derived information includes at least one of the following: a core network-related key, a non-access layer NAS layer-related key, an access network-related key, an access layer AS layer-related key, a key in a terminal context, information in a terminal core network context, first identification information, and information in a terminal access network context;
- the fourth derived information includes at least one of the following: a core network-related key, a non-access layer NAS layer-related key, an access network-related key, an access layer AS layer-related key, a key in a terminal context, information in a terminal core network context, first identification information, information in a terminal access network context, and the third security parameter;
- the second security requirement includes at least one of a key and a secret stream.
- an interactive device comprising:
- a first receiving module configured to receive a target wireless signaling, wherein the target wireless signaling includes first identification information and first target information, wherein the first target information includes at least one of encryption information and integrity protection information;
- the first execution module is configured to execute at least one of the following:
- the first operation includes at least one of the following:
- the second operation includes at least one of the following:
- the first security requirement is generated based on the first derived information, and the first security requirement includes at least one of a key and a secret stream; the first derived information and the fourth derived information include at least one of the following: a core network-related key, a non-access layer NAS layer-related key, an access network-related key, an access layer AS layer-related key, and a key in the terminal context; the second security requirement includes at least one of a key and a secret stream.
- an interactive device comprising:
- a first sending module configured to send a target wireless signaling, wherein the target wireless signaling includes first identification information and first target information, wherein the first target information includes at least one of encryption information and integrity protection information;
- the encryption information and integrity protection information are generated based on a first security requirement, and the first security requirement includes at least one of a secret key and a secret stream.
- an interactive device comprising:
- a second sending module used to send third information or target data to the access network node, wherein the third information includes second identification information and second target information;
- the second target information includes at least one of the following:
- Second security assistance information wherein the second security assistance information includes information in the terminal core network context
- the first algorithm information packet security requirement derives at least one of an algorithm, a confidentiality algorithm, and an integrity algorithm; the first security requirement includes at least one of a secret key and a secret stream, the third security requirement includes at least one of a secret key and a secret stream, and the second identification information indicates a terminal.
- an interactive system comprising: an access network node and a terminal, wherein:
- the access network node is used to send target wireless signaling, the target wireless signaling includes first identification information and first target information, the first target information includes at least one of encryption information and integrity protection information, wherein the encryption information and the integrity protection information are generated based on the first security requirement;
- the terminal is used to receive the target wireless signaling; and when the terminal is related to the first identification information, perform at least one of the following:
- the first operation includes at least one of the following:
- the second operation includes at least one of the following:
- the first security requirement is generated based on the first derived information, and the first security requirement includes at least one of a secret key and a secret stream;
- the first derived information and the fourth derived information include at least one of the following: a core network-related key, a non-access layer NAS layer-related key, an access network-related key, an access layer AS layer-related key, a key in the terminal context, information in the terminal core network context, first identification information, and information in the terminal access network context;
- the second security requirement includes at least one of a key and a secret stream.
- a terminal comprising a processor and a memory, wherein the memory stores a program or instruction that can be run on the processor, and when the program or instruction is executed by the processor, the steps of the method described in the first aspect are implemented.
- a terminal comprising a processor and a communication interface, wherein the communication interface is used to receive target wireless signaling, the target wireless signaling includes first identification information and first target information, the first target information includes at least one of encryption information and integrity protection information; and perform at least one of the following:
- the first operation includes at least one of the following:
- the second operation includes at least one of the following:
- the first security requirement is generated based on the first derived information, and the first security requirement includes at least one of a key and a secret stream; the first derived information and the fourth derived information include at least one of the following: a core network-related key, a non-access layer NAS layer-related key, an access network-related key, an access layer AS layer-related key, and a key in the terminal context; the second security requirement includes at least one of a key and a secret stream.
- a network side device which includes a processor and a memory, wherein the memory stores programs or instructions that can be run on the processor, and when the program or instructions are executed by the processor, the steps of the method described in the second aspect are implemented, or the steps of the method described in the third aspect are implemented.
- a network side device including a processor and a communication interface, wherein the communication interface is used to send a target wireless signaling, wherein the target wireless signaling includes first identification information and first target information, wherein the first target information includes at least one of encryption information and integrity protection information; wherein the encryption information and integrity protection information are generated based on a first security requirement, wherein the first security requirement includes at least one of a secret key and a secret stream
- the communication interface is used to send third information or target data to the access network node, the third information including second identification information and second target information;
- the second target information includes at least one of the following:
- Second security assistance information wherein the second security assistance information includes information in the terminal core network context
- the first algorithm information packet security requirement derives at least one of an algorithm, a confidentiality algorithm, and an integrity algorithm; the first security requirement includes at least one of a secret key and a secret stream, the third security requirement includes at least one of a secret key and a secret stream, and the second identification information indicates a terminal.
- a readable storage medium on which a program or instruction is stored.
- the program or instruction is executed by a processor, the steps of the method described in the first aspect are implemented, or the steps of the method described in the second aspect are implemented, or the steps of the method described in the third aspect are implemented.
- a wireless communication system including: a terminal and a network side device, wherein the terminal can be used to execute the steps of the method described in the first aspect, and the network side device can be used to execute the steps of the method described in the second aspect and the third aspect.
- a chip comprising a processor and a communication interface, wherein the communication interface is coupled to the processor, and the processor is used to run a program or instructions to implement the method as described in the first aspect, or to implement the method as described in the second aspect, or to implement the steps of the method as described in the third aspect.
- a computer program/program product is provided, wherein the computer program/program product is stored in a storage medium, and the program/program product is executed by at least one processor to implement the method as described in the first aspect, or the method as described in the second aspect, or the steps of the method as described in the third aspect.
- a terminal receives a target wireless signaling, wherein the target wireless signaling includes first identification information and first target information, wherein the first target information includes at least one of encryption information and integrity protection information; when the terminal is related to the first identification information, the terminal performs at least one of a first operation and a second operation.
- the transmission of downlink data or signaling can be completed based on the target wireless signaling, or the transmission of data or signaling can be realized in the first interactive information between the terminal and the network side device after the target wireless signaling; therefore, the embodiment of the present application reduces the data transmission delay.
- FIG1 is a block diagram of a wireless communication system to which an embodiment of the present application can be applied;
- FIG2 is one of the flow charts of the interaction method provided in the embodiment of the present application.
- FIG3 is a second flow chart of the interaction method provided in an embodiment of the present application.
- FIG4 is a third flow chart of the interaction method provided in an embodiment of the present application.
- FIG5 is a fourth flow chart of the interaction method provided in an embodiment of the present application.
- FIG6 is a fifth flow chart of the interaction method provided in an embodiment of the present application.
- FIG7 is a schematic diagram of a structure of an interactive device provided in an embodiment of the present application.
- FIG8 is a second schematic diagram of the structure of the interactive device provided in an embodiment of the present application.
- FIG9 is a third schematic diagram of the structure of the interactive device provided in an embodiment of the present application.
- FIG10 is a schematic diagram of the structure of a communication device provided in an embodiment of the present application.
- FIG11 is a schematic diagram of the structure of a terminal provided in an embodiment of the present application.
- FIG12 is a schematic diagram of the structure of a network side device provided in an embodiment of the present application.
- FIG13 is a schematic diagram of the structure of another network side device provided in an embodiment of the present application.
- first, second, etc. of the present application are used to distinguish similar objects, and are not used to describe a specific order or sequence. It should be understood that the terms used in this way are interchangeable where appropriate, so that the embodiments of the present application can be implemented in an order other than those illustrated or described herein, and the objects distinguished by “first” and “second” are generally of one type, and the number of objects is not limited, for example, the first object can be one or more.
- “or” in the present application represents at least one of the connected objects.
- “A or B” covers three schemes, namely, Scheme 1: including A but not including B; Scheme 2: including B but not including A; Scheme 3: including both A and B.
- the character "/" generally indicates that the objects associated with each other are in an "or” relationship.
- LTE Long Term Evolution
- LTE-A Long Term Evolution
- CDMA Code Division Multiple Access
- TDMA Time Division Multiple Access
- FDMA Frequency Division Multiple Access
- OFDMA Orthogonal Frequency Division Multiple Access
- SC-FDMA Single-carrier Frequency Division Multiple Access
- NR New Radio
- FIG1 shows a block diagram of a wireless communication system applicable to the embodiment of the present application.
- the wireless communication system includes a terminal 11 and a network side device 12 .
- the terminal 11 can be a mobile phone, a tablet computer (Tablet Personal Computer), a laptop computer (Laptop Computer), a notebook computer, a personal digital assistant (PDA), a handheld computer, a netbook, an ultra-mobile personal computer (Ultra-mobile Personal Computer, UMPC), a mobile Internet device (Mobile Internet Device, MID), an augmented reality (Augmented Reality, AR), a virtual reality (Virtual Reality, VR) device, a robot, a wearable device (Wearable Device), a flight vehicle (flight vehicle), a vehicle user equipment (VUE), a shipborne equipment, a pedestrian terminal (Pedestrian User Equipment, PUE), a smart home (home appliances with wireless communication functions, such as refrigerators, televisions, washing machines or furniture, etc.), a game console, a personal computer (Personal Computer, PC
- Wearable devices include: smart watches, smart bracelets, smart headphones, smart glasses, smart jewelry (smart bracelets, smart bracelets, smart rings, smart necklaces, smart anklets, smart anklets, etc.), smart wristbands, smart clothing, etc.
- the vehicle-mounted device can also be called a vehicle-mounted terminal, a vehicle-mounted controller, a vehicle-mounted module, a vehicle-mounted component, a vehicle-mounted chip or a vehicle-mounted unit, etc. It should be noted that the specific type of the terminal 11 is not limited in the embodiment of the present application.
- the network side device 12 may include an access network system or a core network device, wherein the access network system may also be referred to as a radio access network (Radio Access Network, RAN) device, a radio access network function or a radio access network unit.
- the access network system may include a base station, a wireless local area network (Wireless Local Area Network, WLAN) access point (Access Point, AP) or a wireless fidelity (Wireless Fidelity, WiFi) node, etc.
- WLAN wireless Local Area Network
- AP Access Point
- WiFi wireless Fidelity, WiFi
- the base station can be called Node B (Node B, NB), Evolved Node B (Evolved Node B, eNB), the next generation Node B (the next generation Node B, gNB), New Radio Node B (New Radio Node B, NR Node B), access point, Relay Base Station (Relay Base Station, RBS), Serving Base Station (Serving Base Station, SBS), Base Transceiver Station (Base Transceiver Station, BTS), radio base station, radio transceiver, base Basic Service Set (BSS), Extended Service Set (ESS), home Node B (HNB), home evolved Node B (home evolved Node B), Transmission Reception Point (TRP) or other appropriate term in the field, as long as the same technical effect is achieved, the base station is not limited to specific technical vocabulary. It should be noted that, in the embodiments of the present application, only the base station in the NR system is taken as an example for introduction, and the specific type of the base station is not limited.
- the core network equipment may include but is not limited to at least one of the following: core network nodes, core network functions, mobility management entity (Mobility Management Entity, MME), access mobility management function (Access and Mobility Management Function, AMF), session management function (Session Management Function, SMF), user plane function (User Plane Function, UPF), policy control function (Policy Control Function, PCF), policy and charging rules function unit (Policy and Charging Rules Function, PCRF), edge application service discovery function (Edge Application Server Discovery ...
- MME mobility management entity
- AMF Access and Mobility Management Function
- SMF Session Management Function
- SMF Session Management Function
- UPF User Plane Function
- Policy Control Function Policy Control Function
- PCRF Policy and Charging Rules Function
- edge application service discovery function Edge Application Server Discovery ...
- the characteristic of efficient small data transmission is that for the terminal (UE) in non-Radio Resource Control (RRC) connection state, it avoids excessive signaling overhead caused by RRC state transition and RRC connection establishment process, and completes the purpose of small data transmission through a very simple signaling process.
- the non-RRC connection state can include the idle state (IDLE) and the inactive (INACTIVE) state.
- the characteristic of the small data transmission scheme is that the current Data Radio Bearer (DRB) of the UE is in a suspended state, not a released state. Therefore, the UE can resume the DRB before sending a ResumeRequest message, and then use RRC signaling to piggyback small data. At this time, the UE can transmit data on the DRB just like the CONNECTED UE. This avoids state transitions and achieves the purpose of efficient small data transmission with less signaling overhead.
- DRB Data Radio Bearer
- the update method is to perform the next key update operation according to the parameters provided to it by the network side device for calculating the next hop key when the UE enters the suspended state.
- the data to be transmitted for small data transmission is carried on the dedicated traffic channel (DTCH) and multiplexed with the uplink RRCConnectionResumeRequest message for transmission. Similarly, if there is a downlink reply message, it can also be carried on the DTCH and multiplexed with the downlink RRCConnectionRelease message for transmission. Both uplink and downlink data are encrypted and the next key after the update is used for encryption operation.
- DTCH dedicated traffic channel
- small data can be transmitted on Msg3 PUSCH in a 4-step Random Access Channel (RACH) process.
- Small data can also be transmitted on MsgA PUSCH in a 2-step RACH process, or on PUSCH resources scheduled by a configured grant (CG) configured in the RRC inactive state.
- RACH-based small data transmission Small data transmission in 2-step RACH and 4-step RACH processes is called RACH-based small data transmission, and small data transmission based on PUSCH scheduled by a configured grant is called CG-based small data transmission.
- the network In the LTE system, the network (NW) carries the MT-EDT trigger message through the paging message, and then the UE initiates the EDT process. After receiving the UE's request message (carrying the MT-EDT cause value), the NW concatenates the RRC response message with the DRB data into a protocol data unit and sends it to the UE, ultimately realizing the reception of downlink services.
- Data transmission in idle or inactive state is a special transmission mechanism, which allows UE to send and receive UE dedicated data (UE dedicated data) with the NW side without entering the connected state.
- small data transmission is mainly transmitted in the uplink Msg3 triggered by the terminal or MO-SDT transmitted on CG PUSCH, or MT-SDT triggered by the downlink.
- an interaction method of the present application is proposed, that is, the first broadcast signal that the UE can receive, such as paging, is used to directly deliver data or data transmission resources to the UE, thereby reducing the message interaction process.
- an embodiment of the present application provides an interaction method. As shown in FIG. 2 , the interaction method includes:
- Step 201 The terminal receives target wireless signaling, where the target wireless signaling includes first identification information and first target information, where the first target information includes at least one of encryption information and integrity protection information;
- Step 202 When the terminal is related to the first identification information, the terminal performs at least one of the following:
- the first operation includes at least one of the following:
- the second operation includes at least one of the following:
- the first security requirement is generated based on the first derived information, and the first security requirement includes at least one of a key and a secret stream;
- the first derived information includes at least one of the following: a core network-related key, a non-access layer NAS layer-related key, an access network-related key, an access layer AS layer-related key, and a key in a terminal context;
- the fourth derived information includes at least one of the following: a core network-related key, a non-access layer NAS layer-related key, an access network-related key, an access layer AS layer-related key, a key in a terminal context, and the third security parameter;
- the second security requirement includes at least one of a key and a secret stream.
- the above-mentioned first identification information can be understood as a target identification or a part of the identification intercepted from the target identification, and the target identification may include at least one of a user identification, a group identification, a connection identification, a bearer identification, a thing identification and an interaction identification.
- the encryption information can be understood as information obtained after security processing is performed on at least part of the content to be transmitted, and the integrity protection information can be understood as integrity information associated with the content to be transmitted, which is a media access control (MAC) value.
- the first target information includes encryption information and integrity protection information, it can be understood that the content to be transmitted is processed for security and integrity, and the first target information is finally obtained.
- the terminal being associated with the first identification information can be understood as the relevant identification of the terminal being associated with the first identification information.
- the target wireless signaling includes a user identification.
- the terminal can be considered to be associated with the first identification information.
- the terminal can perform the above-mentioned first operation.
- the terminal may discard the received first target information.
- the above-mentioned target wireless signaling can be understood as wireless signaling that the terminal can receive in an idle state or an inactive state.
- the terminal when the terminal is related to the first identification information, the terminal performs a first operation based on the first security requirement, so that the transmission of downlink data or signaling can be achieved without other interactive information, thereby reducing the data transmission delay.
- the first target information includes at least one of encryption information and integrity protection information, the first operation is performed by the first security requirement of the terminal, thereby improving the security of the transmission.
- the terminal when the terminal is related to the first identification information, the terminal performs a second operation, so that the transmission of data or signaling can be achieved in the first interactive information between the subsequent terminal and the network side device, thereby reducing the data transmission delay.
- the content transmitted by the access network node can be obtained, which may specifically include signaling or data.
- the above-mentioned key stream may be a string generated based on a secret key and other parameters.
- the above-mentioned core network-related keys may include long-term keys (Long Term Key), authentication-related keys (Kausf), security and authentication-related keys (Kseaf), AMF keys (Kamf), mobility management entity (Mobility Management Entity, MME) keys (Kasme), etc.
- NAS layer related keys may include NAS encryption key (Knas_enc), NAS integrity key (Knas_int), etc.
- Access network-related keys may include base station keys (such as Kenb, Kgnb, NH, Kenb*, Kgnb*, Ks-enb, Ks-gnb, etc.).
- base station keys such as Kenb, Kgnb, NH, Kenb*, Kgnb*, Ks-enb, Ks-gnb, etc.
- AS layer related keys may include signaling encryption key (Krrc_enc), signaling integrity key (Krrc_int), data encryption key (Kup_enc), data integrity key (Kup_int), etc.
- the keys in the terminal context may include any one of or a combination of at least two of the core network related keys, the non-access layer NAS layer related keys, the access network related keys, and the access layer AS layer related keys.
- a terminal receives a target wireless signaling, wherein the target wireless signaling includes first identification information and first target information, wherein the first target information includes at least one of encryption information and integrity protection information; when the terminal is related to the first identification information, the terminal performs at least one of a first operation and a second operation.
- the transmission of downlink data or signaling can be completed based on the target wireless signaling, or the transmission of data or signaling can be realized in the first interactive information between the terminal and the network side device after the target wireless signaling; therefore, the embodiment of the present application reduces the data transmission delay.
- the access network node receives third information or target data from the core network node, and the third information includes third identification information and second target information;
- the third information includes second identification information and second target information
- the second target information includes at least one of the following:
- Second security assistance information wherein the second security assistance information includes information in the terminal core network context
- the second identification information is used to indicate a terminal, or is generated by a terminal identification, or indicates a group of terminals, or is related to the first identification information.
- the access network node may acquire or generate the first security requirement based on the second target information, and send the target wireless signaling based on the third information.
- the access network node generates the first security requirement based on at least one of the second derived information and the security requirement derivation algorithm, wherein the second derived information includes at least one of the following: an access network related key, an AS layer related key, a key in a terminal context, at least part of the first security auxiliary information, at least part of the second security auxiliary information, first identification information, and information in a terminal access network context.
- the second derived information includes at least one of the following: an access network related key, an AS layer related key, a key in a terminal context, at least part of the first security auxiliary information, at least part of the second security auxiliary information, first identification information, and information in a terminal access network context.
- the second identification information may be a global user temporary identifier (Globally Unique Temporary Identifier, GUTI), and the first identification information may be RNTI; or the second identification information is GUTI, and the first identification information is a short-term mobile subscriber identification (Short Term Mobile Subscriber Identity, S-TMSI); or the second identification information and the first identification information are both S-TMSI.
- GUTI Globally Unique Temporary Identifier
- RNTI Globally Unique Temporary Identifier
- S-TMSI Short Term Mobile Subscriber Identity
- the above-mentioned target data can be understood as data to be transmitted.
- the above-mentioned third information may also include the above-mentioned target data.
- the above-mentioned target data is associated with the above-mentioned encryption information or integrity protection information, that is, the access network device can generate encryption information and integrity protection information based on at least part of the data in the target data.
- part of the data can be transmitted through the target wireless signaling
- the remaining part of the data is associated with the second information, that is, the second information can be generated based on the remaining part of the data.
- the data to be transmitted may not be carried in the target wireless signaling.
- the above-mentioned encryption information is encrypted resource information
- the above-mentioned second information is encrypted target data (or encrypted data generated based on the target data).
- the third information includes at least one of the following:
- the second target information and the second identification information are one-to-one or multiple mappings
- the second identification information and the second target information are a one-to-zero or one mapping
- K is less than or equal to the number of second identification information included in the third information.
- the second target information and the second identification information are one-to-one or multi-mapping, which can be understood as: the second target information can have a one-to-one mapping relationship with the second identification information, or a one-to-many mapping relationship.
- the second target information and the second identification information are one-to-one mapping; or all the second target information and the second identification information are one-to-many mapping; or part of the second target information and the second identification information are one-to-one mapping, and part of the second target information and the second identification information are one-to-many mapping.
- the second identification information and the second target information are one-to-zero or one-to-one mappings, which can be understood as: the second identification information can have a one-to-one mapping relationship with the second target information, or a one-to-zero mapping relationship, wherein the one-to-zero mapping relationship indicates that the second identification information does not have any second target information mapped thereto.
- all the second identification information and the second target information are one-to-one mappings; or part of the second identification information and the second target information are one-to-one mappings, and part of the second identification information and the second target information are one-to-zero mappings.
- K second identification information there is a corresponding relationship between K second identification information and all second target information.
- K is equal to the number of second identification information included in the target wireless signaling, it can be understood that all second identification information has mapped second target information; when K is less than the number of second identification information included in the target wireless signaling, it can be understood that only part of the second identification information has mapped second target information, and part of the second identification information does not have mapped second target information.
- the mapping relationship between the second target information and the second identification information can include at least one of the following: a one-to-one mapping relationship; a one-to-many mapping relationship.
- the second identification information is used to indicate a terminal, or is generated by a terminal identification, or indicates a group of terminals, or is related to the first identification information.
- the access network node performs at least one of the following:
- the first calculation parameter includes at least one of the following:
- the second derived information includes at least one of the following:
- the third operation includes at least one of the following:
- a second security requirement based on fourth derived information and at least one of the first security requirements, the second security requirement including at least one of a key and a secret stream, the fourth derived information including at least one of the following: a core network-related key, a non-access stratum NAS layer-related key, an access network-related key, an AS layer-related key, and a key in a terminal context;
- the second information is sent to the terminal.
- the access network node may perform security processing on at least part of the content of the first information and report it to the core network node.
- the core network node may also generate the first security requirement or the third security requirement based on at least one of the third derived information and the security requirement derivation algorithm;
- the third derived information includes at least one of the following: a core network related key, a NAS layer related key, a key in a terminal context, the first algorithm information, the second security parameter, and at least part of the second security auxiliary information.
- the core network node can be understood or replaced by a device or system having a core network function, that is, it can be referred to as a core network device or a core network system, or it can also be referred to as a core network function.
- the access network node can be understood as a device or system having an access network function, that is, it can be referred to as an access network device or system, or it can also be referred to as a base station or an access network function.
- the first target information further includes first safety auxiliary information
- the first security auxiliary information includes at least one of first algorithm information, first security parameter, and second security parameter;
- the first algorithm information includes at least one of the following:
- the first security requirement being further generated based on the security requirement derivation algorithm
- At least one of a confidentiality algorithm and an integrity algorithm is also performed based on at least one of the confidentiality algorithm and the integrity algorithm.
- the above-mentioned confidentiality algorithm may include an encryption algorithm and a decryption algorithm
- the above-mentioned integrity algorithm may include an algorithm for generating a check code, or an algorithm for checking or verifying a check code.
- the first security parameter is used to represent NAS counting information, such as the number of downlink NAS signaling times, or the number of uplink NAS signaling times, or the number of NAS signaling times (the sum of the number of downlink NAS signaling times and the number of uplink NAS signaling times);
- the second security parameter is used to represent the counting information of access network signaling or the counting information of data packets.
- the second security parameter can be the number of downlink access network signaling times, the number of uplink access network signaling times, or the number of access network signaling times (that is, the sum of the number of downlink access network signaling times and the number of uplink access network signaling times), or it can be the number of downlink data packets, the number of uplink data packets, or the number of data packets (that is, the number of downlink data packets and the number of uplink data packets).
- the third security parameter can be understood as the counting information for representing access network signaling or data message counting information.
- the second security parameter can be the number of downlink access network signaling, the number of uplink access network signaling, or the number of access network signaling (i.e., the sum of the number of downlink access network signaling and the number of uplink access network signaling), or the number of downlink data messages, the number of uplink data messages, or the number of data messages (i.e., the number of downlink data messages and the number of uplink data messages).
- the third security parameter is different from the second security parameter.
- downlink NAS signaling can be understood or replaced by NAS downlink signaling
- downlink NAS signaling can be understood or replaced by NAS downlink signaling
- the downlink access network signaling can be understood or replaced by AS downlink signaling
- the uplink access network signaling can be understood or replaced by AS uplink signaling
- the access network signaling can be understood or replaced by AS signaling.
- the data message can be understood or replaced by a protocol data message.
- the first security requirement is also generated based on the security requirement derivation algorithm, which can be understood as the first security requirement is generated based on the first derived information and the security requirement derivation algorithm indicated by the access network node.
- the security requirement derivation algorithm can also belong to the content of the first derived information, that is, the first security requirement is also generated based on the security requirement derivation algorithm, which can be understood as the first security requirement is generated based on the information in the first derived information other than the security requirement derivation algorithm indicated by the access network node and the security requirement derivation algorithm indicated by the access network node to generate the first security requirement.
- the security requirement derivation algorithm for generating the first security requirement can be agreed upon by the protocol.
- the first derived information further includes at least one of the following:
- the first identification information is the first identification information.
- the terminal performs a first operation based on the first security requirement, including:
- the terminal performs the first operation based on the first security requirement and a first calculation parameter, where the first calculation parameter includes at least one of the following:
- At least part of the first safety assistance information At least part of the first safety assistance information.
- the first security auxiliary information included in the first calculation parameter may be the same as or different from, or partially the same as, at least part of the content of the first security auxiliary information included in the first derived information.
- the first security auxiliary information includes two parts of information, one part of which (such as the first security parameter) is used to perform the first operation, and the other part (such as the second security parameter) is used to generate a security requirement.
- the information in the terminal core network context includes at least one of the following:
- the terminal's group identification information The terminal's group identification information
- the information in the terminal access network context includes at least one of the following:
- the terminal's group identification information The terminal's group identification information
- the method includes at least one of the following:
- the terminal generates the second security requirement based on at least one of: the first security requirement, the fourth derived information, and the third security parameter;
- the terminal performs security protection on the first information or part of the first information based on at least one of the following: the first security requirement or the second security requirement, a first calculation parameter, and the third security parameter;
- the terminal performs security processing on the second information or part of the second information based on at least one of the following: the first security requirement or the second security requirement, a first calculation parameter, and the third security parameter.
- the second security requirement is generated based on the third security parameter or the third security parameter and other related information
- the security processing is performed based on the third security parameter or the third security parameter and other related information.
- the third security parameter can be understood as information for updating security requirements and security processing, and since the security requirements and security processing used can be updated based on the third security parameter, the security of transmission is improved.
- the terminal when the first information does not include the third security parameter, the terminal generates the second security requirement based on at least one of the following: the first security requirement and the fourth derived information.
- the terminal performs security processing on the second information or part of the second information based on at least one of the following: the first security requirement or the second security requirement and the first calculation parameter.
- the security protection includes at least one of confidentiality protection, encryption, and integrity protection; the security processing includes at least one of decryption, confidentiality processing, integrity processing, and integrity verification.
- the target wireless signaling includes at least one of the following:
- At least one pair of first identification information and first target information At least one pair of first identification information and first target information
- the first target information and the first identification information are one-to-one or multiple mappings
- the first identification information and the first target information are a one-to-zero or one mapping
- N is less than or equal to the number of first identification information included in the target wireless signaling.
- the first target information and the first identification information are one-to-one or multi-mapping, which can be understood as: the first target information can have a one-to-one mapping relationship with the first identification information, or a one-to-many mapping relationship.
- the first target information and the first identification information are one-to-one mapping; or all the first target information and the first identification information are one-to-many mapping; or part of the first target information and the first identification information are one-to-one mapping, and part of the first target information and the first identification information are one-to-many mapping.
- the first identification information and the first target information are one-to-zero or one-to-one mappings, which can be understood as: the first identification information can have a one-to-one mapping relationship with the first target information, or a one-to-zero mapping relationship, wherein the one-to-zero mapping relationship indicates that the first identification information does not have the first target information mapped thereto.
- all the first identification information and the first target information are one-to-one mappings; or part of the first identification information and the first target information are one-to-one mappings, and part of the first identification information and the first target information are one-to-zero mappings.
- N there is a corresponding relationship between N first identification information and all first target information.
- N is equal to the number of first identification information included in the target wireless signaling, it can be understood that all first identification information has mapped first target information; when N is less than the number of first identification information included in the target wireless signaling, it can be understood that only part of the first identification information has mapped first target information, and part of the first identification information does not have mapped first target information.
- the mapping relationship between the first target information and the first identification information can include at least one of the following: a one-to-one mapping relationship; a one-to-many mapping relationship.
- the terminal is in an idle state or an inactive state, or is in an idle state or an inactive state before sending the first information, or is in an idle state or an inactive state before receiving the second information.
- the idle state includes two situations: the core network idle state and the wireless idle state.
- the core network idle state refers to a state of the terminal. In this state, the core network cannot directly send a NAS message targeting the terminal (paging must be performed first), or the terminal cannot directly send a NAS message to the core network (corresponding sending resources must be obtained first). It can also be said that there is no NAS connection between the terminal and the core network.
- the wireless idle state means that the terminal has no resources to send signaling to the base station to establish a wireless point-to-point connection between the terminal and the base station (there are terminal-specific wireless resources to send and receive information, including proprietary scrambling resources, such as Radio Network Temporary Identifier (RNTI));
- the inactive state refers to a state of the terminal. In this state, the terminal is not in the core network idle state, and there is a connection or tunnel for the terminal between the core network and the base station, but there is no wireless point-to-point connection between the terminal and the base station.
- the state of the terminal can also be defined using other names. There are other behaviors between the terminal and the base station.
- the core network cannot directly send NAS messages targeting the terminal.
- This state may use a new name, but it still corresponds to the idle state (i.e., the core network idle state) description of this application, such as the terminal non-core network idle state (NAS messages targeting the terminal can be sent directly), there is a wireless point-to-point connection between the terminal and the base station, but there is no connection for the terminal between the core network and the base station (for example, the uplink or downlink NAS message is based on the UE ID to identify the source or target, rather than based on the connection or tunnel identifier (Tunnel endpoint identifier, TEID)).
- This state can be defined using other names, but it still corresponds to the inactive state description of this application. For example, there is a NAS connection but the connection between the terminal to the base station and then to the core network is incomplete.
- the terminal after the terminal enters the inactive state and before receiving the target wireless signaling, the terminal does not send information to the access network system.
- the method before the terminal receives the target wireless signaling, the method further includes:
- the terminal sends second algorithm information to the network side, where the second algorithm information is used to indicate at least one of the following: an algorithm supported by the terminal and an algorithm used by the terminal;
- the algorithm includes at least one of a security requirement derivation algorithm, a confidentiality algorithm, and an integrity algorithm.
- the terminal sending the second algorithm information to the network side can be understood as the terminal sending a NAS message to the core network node, and the NAS message can include the above-mentioned second algorithm information.
- the access network node forwards the NAS message to the core network node, it can carry at least one of the algorithm supported by the access network node and the algorithm used by the access network node.
- the core network node may indicate the first algorithm information to the access network node.
- the first identification information indicates a terminal, or is generated by a terminal identification, or indicates a group of terminals.
- the terminal identifications when the first identification information is generated by a terminal identification, different terminal identifications may generate the same first identification information. For example, the terminal identifications of a group of terminals may generate the same first identification information.
- the target wireless signaling includes any one of broadcast signaling, paging signaling, wireless short message, and system message;
- the target wireless signaling is sent through at least one of a paging channel (Paging Channel, PCH), a multicast channel (Multicast Channel, MCH), a broadcast channel (Broadcast Channel, BCH) and a downlink shared channel (Downlink Shared Channel, DL-SCH);
- a paging channel Paging Channel, PCH
- MCH multicast channel
- BCH Broadcast Channel
- DL-SCH Downlink Shared Channel
- the target wireless signaling is sent through at least one of a physical downlink control channel (PDCCH), a physical downlink shared channel (PDSCH), a physical broadcast channel (PBCH) and a physical multicast channel (PMCH).
- a physical downlink control channel (PDCCH)
- PDSCH physical downlink shared channel
- PBCH physical broadcast channel
- PMCH physical multicast channel
- the above-mentioned target wireless signaling may be a paging message in a new format sent through PCH (i.e., a paging message containing resource information and/or data), or may be a signaling sent in PCH, wherein the target wireless signaling includes a traditional paging message (i.e., a paging message that does not contain resource information and data), as well as resource information and/or data, or may be a traditional paging message sent in PCH, as well as sending resource information through PDCCH and/or sending data through PDSCH.
- the above-mentioned wireless short message can be understood as a short message (Short Message) involved in wireless signaling, and not a short message involved in Short Messaging/Message Service (SMS).
- SMS Short Messaging/Message Service
- FIG3 when the terminal is in an idle state, the interaction process is shown in FIG3 , which specifically includes the following steps:
- the terminal sends a NAS message to the core network.
- the access network node forwards the NAS message to the core network node, it carries the algorithm indication information supported by the terminal (i.e., the second algorithm information), and may further carry the algorithm indication information supported by the access network node.
- the core network node may optionally save the algorithm indication information supported by the terminal, or the algorithm indication information supported by the terminal and the access network node.
- Step 32 The core network node sends information 1 to the access network node, for example, via a Paging message or an incentive message.
- information 1 includes a first user identifier, a security requirement (including at least one of a secret key and a secret stream), and the security requirement can be generated based on at least one of a key in the terminal core network context, a first user identifier, and a first security parameter.
- information 1 may also include at least one of a first security parameter and an algorithm indication, and the algorithm indication is used to indicate the first algorithm information.
- At least part of the other information in the information 1 except the first user identifier can be associated with the first user identifier, so that other information associated with multiple first user identifiers can be carried.
- at least part of the other information in the information 1 except the first user identifier can also be set to be associated with the first user identifier.
- Step 33 The access network node may perform operation 1 based on information 1, where operation 1 includes at least one of an encryption operation and a security operation.
- the resource information such as SRB information, DRB information, MAC CE scheduling information, grant information, etc.
- other information elements such as data in the target wireless signaling
- the second user identifier can be generated based on the first user identifier, for example, the first user identifier is a user identifier assigned by the core network node (such as TMSI), and the second user identifier is a user identifier assigned by the access network node (such as RNTI), or the first user identifier is a user identifier assigned by the access network node, and the second user identifier is a user identifier assigned by the core network node.
- the first user identifier is a user identifier assigned by the core network node (such as TMSI)
- the second user identifier is a user identifier assigned by the access network node (such as RNTI)
- the first user identifier is a user identifier assigned by the access network node
- the second user identifier is a user identifier assigned by the core network node.
- a security operation is performed on at least one of the resource information, encrypted resource information and other information elements (such as data in the target wireless signaling); for example, a MAC value is calculated using a key and an agreed or indicated algorithm.
- the security operation can also be performed based on at least one of the first security parameter and the second security parameter, that is, the MAC value is calculated using at least one of the first security parameter and the second security parameter as input to the algorithm.
- step 33 and subsequent steps are not performed.
- Step 34 The access network node broadcasts information 2 via an air interface, for example, via a Paging message, a system message, or an activation message, or sends information 2 in the first message sent to the terminal.
- the information 2 includes the first user identifier or the second user identifier and at least one of the following: encrypted resource information and a MAC value.
- other information except the user identification (first user identification or second user identification) in the above information 2 may be associated with the user identification, thereby carrying other information associated with multiple user identifications.
- other information except the user identification in the above information 2 may be unrelated to the user identification.
- the information 2 may also include at least one of an algorithm indication, a first security parameter, and a second security parameter. At least part of the information may be independent of or related to the user identification.
- step 35 the terminal generates a security requirement (the security requirement includes at least one of a secret key or a secret stream, and the generation method of the security requirement is the same as step 32, which will not be repeated here) and executes operation 2, which includes at least one of a decryption operation and a security verification operation.
- a security requirement includes at least one of a secret key or a secret stream, and the generation method of the security requirement is the same as step 32, which will not be repeated here
- operation 2 which includes at least one of a decryption operation and a security verification operation.
- the resource information is decrypted using a key or a secret stream (for example, decryption using a key and an agreed or indicated algorithm, or an XOR operation based on a secret stream).
- a key or a secret stream for example, decryption using a key and an agreed or indicated algorithm, or an XOR operation based on a secret stream.
- the above decryption operation can also be performed using a received user identity, a third user identity obtained based on the received user identity (for example, TMSI is obtained by receiving RNTI, or vice versa), a first security parameter, and a second security parameter (that is, the relevant parameters are also used as input parameters during decryption).
- the security verification operation when the security requirements include a key, the resource information and/or encrypted resource information is security verified (for example, the target MAC value is calculated using the key and an agreed or indicated algorithm and compared with the received MAC).
- the security verification can also use the received user identifier, a third user identifier obtained based on the received user identifier, the first security parameter 1 and at least one of the second security parameters (that is, the relevant parameters are also used as input in the process of calculating the target MAC value).
- the terminal may also generate a new security requirement based on the key in the context of the terminal core network or the access network (for example, using the corresponding key and the agreed parameters and/or the information sent by the received access network node to generate a new security requirement).
- the terminal sends signaling and/or data to the base station based on resource information (for example, uplink resource information), and may perform the process of sending signaling and/or data based on the aforementioned security check, such as sending after the security check is successful.
- the signaling may include at least one of the following:
- the information after the security operation is performed on the entire signaling (the entire plaintext signaling), the entire encrypted signaling, some elements in the signaling (plaintext elements), or some encrypted elements in the signaling (the MAC value calculated using the key and the agreed or indicated algorithm).
- the data to be sent may be data encrypted based on the key or secret stream in the security requirements or new security requirements, data fully secured based on the key in the security requirements or new security requirements, or data encrypted and fully secured based on the key in the security requirements or new security requirements.
- the above-mentioned encryption and/or security operations can also be performed based on the received user identifier, a third user identifier obtained based on the received user identifier, the first security parameter, the second security parameter 2 and at least one of the third security parameters.
- the sent signaling or data may include plain text security parameter 3 (security parameter 3 as part of the entire signaling, or part of the data, or one of the partial information elements, but not the entire encrypted signaling, nor one of the partial encrypted information elements).
- plain text security parameter 3 security parameter 3 as part of the entire signaling, or part of the data, or one of the partial information elements, but not the entire encrypted signaling, nor one of the partial encrypted information elements.
- the access network node may generate a new security requirement based on a key in the terminal access network context or a security requirement received from a core network node (e.g., using a corresponding key and agreed parameters and/or information sent by the access network node to the terminal to generate a new security requirement).
- the access network node receives signaling and/or data from the terminal based on resource information (e.g., uplink resource information).
- the access network node performs at least one of the following on the signaling:
- the entire signaling (the entire ciphertext signaling), the entire decrypted (plaintext) signaling, some cells in the signaling (ciphertext cells), and/or some decrypted cells in the signaling (plaintext cells) (using the key and the target MAC value calculated by the agreed or indicated algorithm and comparing the received MAC value);
- the access network node performs at least one of the following on the received data:
- the access network node may perform the above-mentioned operation on the data based on the integrity check of the received signaling, such as processing if successful.
- the above-mentioned integrity check and/or decryption operation may also be performed based on the sent user identifier, a third user identifier obtained based on the sent user identifier, a first security parameter, a second security parameter, and a third security parameter (i.e., in the process of calculating the XMAC value and in the process of decryption, the corresponding parameters are also used as input).
- the access network node and the terminal can continue to execute subsequent signaling and data transmission processes.
- the terminal sends at least one of signaling and data to the access network node based on the resource information, and the access network node can report relevant information to the core network node after receiving the information sent by the terminal based on the uplink resource information.
- the specific encryption operation and security operation can refer to the description of the above embodiment, which will not be repeated here.
- the access network node receives signaling or data from the core network node, and sends signaling and/or data to the terminal based on the downlink resource information.
- the specific process can refer to the above embodiment and will not be repeated here.
- Embodiment 2 when the terminal is in the INACTIVE state, is different from Embodiment 1 in that:
- Data interaction between core network nodes and access network nodes is performed based on the user plane.
- the secret key in the security requirement is the secret key in the terminal access network context.
- the first security parameter does not participate in the interaction process, that is, the information sent during the interaction process in Example 1, the information used to generate security keys, perform security operations, encryption operations, etc., or the like, do not contain the first security parameter.
- information 2 does not contain the first security parameter, and the security requirements are not generated based on the first security parameter.
- an embodiment of the present application further provides an interaction method.
- the interaction method includes:
- Step 401 The access network node sends a target wireless signaling, where the target wireless signaling includes first identification information and first target information, where the first target information includes at least one of encryption information and integrity protection information;
- the encryption information and integrity protection information are generated based on a first security requirement, and the first security requirement includes at least one of a secret key and a secret stream.
- the method before the access network node sends the target wireless signaling, the method further includes:
- the access network node receives third information or target data from the core network node;
- the third information includes second identification information and second target information
- the second target information includes at least one of the following:
- Second security assistance information wherein the second security assistance information includes information in the terminal core network context
- the second identification information is used to indicate a terminal, or is generated by a terminal identification, or indicates a group of terminals, or is related to the first identification information; and the first algorithm information includes at least one of the following:
- Security element derivation algorithm confidentiality algorithm, and integrity algorithm.
- the third information includes at least one of the following:
- the second target information and the second identification information are one-to-one or multiple mappings
- the second identification information and the second target information are a one-to-zero or one mapping
- K is less than or equal to the number of second identification information included in the third information.
- the first target information further includes at least one of the following:
- the first safety auxiliary information includes at least one of first algorithm information, a first safety parameter, and a second safety parameter.
- the method comprises:
- the access network node performs at least one of the following:
- the first calculation parameter includes at least one of the following:
- the second derived information includes at least one of the following:
- the third operation includes at least one of the following:
- a second security requirement is generated based on fourth derived information and at least one of the first security requirements, the second security requirement including at least one of a key and a secret stream, the fourth derived information including at least one of the following: a core network-related key, a non-access layer NAS layer-related key, an access network-related key, an AS layer-related key, a key in a terminal context, and the third security parameter.
- the method comprises at least one of the following:
- the access network node performs security processing on the first information or part of the first information based on at least one of the following: the first security requirement or the second security requirement, the first calculation parameter, and the third security parameter;
- the access network node performs security protection on the second information or part of the second information based on at least one of the following: the first security requirement or the second security requirement, the first calculation parameter, and the third security parameter.
- the security protection includes at least one of confidentiality protection, encryption, and integrity protection; the security processing includes at least one of decryption, confidentiality processing, integrity processing, and integrity verification.
- the terminal is in an idle state or an inactive state, or is in an idle state or an inactive state before sending the first information, or is in an idle state or an inactive state before receiving the second information.
- the target wireless signaling includes at least one of the following:
- At least one pair of first identification information and first target information At least one pair of first identification information and first target information
- the first target information and the first identification information are one-to-one or multiple mappings
- the first identification information and the first target information are a one-to-zero or one mapping
- N is less than or equal to the number of first identification information included in the target wireless signaling.
- the first identification information indicates a terminal, or is generated by a terminal identifier, or indicates a group of terminals.
- the target wireless signaling is any one of broadcast signaling, paging signaling, wireless short message, and system message;
- the target wireless signaling is sent through at least one of a paging channel PCH, a multicast channel MCH, a broadcast channel BCH, and a downlink shared channel DL-SCH;
- the target wireless signaling is sent via at least one of a physical downlink control channel PDCCH, a physical downlink shared channel PDSCH, a physical broadcast channel PBCH, and a physical multicast channel PMCH.
- PDCCH physical downlink control channel
- PDSCH physical downlink shared channel
- PBCH physical broadcast channel
- PMCH physical multicast channel
- an embodiment of the present application further provides an interaction method.
- the interaction method includes:
- Step 501 The core network node sends third information or target data to the access network node, where the third information includes second identification information and second target information;
- the second target information includes at least one of the following:
- Second security assistance information wherein the second security assistance information includes information in the terminal core network context
- the first algorithm information packet security requirement derives at least one of an algorithm, a confidentiality algorithm, and an integrity algorithm; the first security requirement includes at least one of a secret key and a secret stream, the third security requirement includes at least one of a secret key and a secret stream, and the second identification information indicates a terminal, or is generated by a terminal identification, or indicates a group of terminals.
- the method further comprises:
- the core network node generates the first security requirement or the third security requirement based on at least one of the third derived information and the security requirement derivation algorithm;
- the third derived information includes at least one of the following: a core network related key, a NAS layer related key, a key in a terminal context, the first algorithm information, the second security parameter, and at least part of the second security auxiliary information.
- the third information includes at least one of the following:
- the second target information and the second identification information are one-to-one or multiple mappings
- the second identification information and the second target information are a one-to-zero or one mapping
- K is less than or equal to the number of second identification information.
- the method further comprises:
- the core network node receives second algorithm information from the terminal, where the second algorithm information is used to indicate at least one of the following: an algorithm supported by the terminal and an algorithm used by the terminal;
- the first algorithm information is generated based on the second algorithm information.
- the embodiment of the present application further provides an interaction method.
- the interaction method includes:
- Step 601 The access network node sends a target wireless signaling, wherein the target wireless signaling includes first identification information and first target information, wherein the first target information includes at least one of encryption information and integrity protection information, wherein the encryption information and the integrity protection information are generated based on a first security requirement;
- Step 602 the terminal receives the target wireless signaling
- Step 603 When the terminal is related to the first identification information, the terminal performs at least one of the following:
- the first operation includes at least one of the following:
- the second operation includes at least one of the following:
- the first security requirement is generated based on the first derived information, and the first security requirement includes at least one of a secret key and a secret stream;
- the first derived information includes at least one of the following: a core network-related key, a non-access layer NAS layer-related key, an access network-related key, an access layer AS layer-related key, a key in a terminal context, information in a terminal core network context, first identification information, and information in a terminal access network context;
- the fourth derived information includes at least one of the following: a core network-related key, a non-access layer NAS layer-related key, an access network-related key, an access layer AS layer-related key, a key in a terminal context, information in a terminal core network context, first identification information, information in a terminal access network context, and the third security parameter;
- the second security requirement includes at least one of a key and a secret stream.
- the method further comprises:
- the core network node sends third information or target data to the access network node, where the third information includes second identification information and second target information;
- the access network node learns or generates the first security requirement based on the second target information, and sends the target wireless signaling based on the third information;
- the second target information includes at least one of the following: the first security requirement or the third security requirement, the first algorithm information, the second security parameter, and the second security auxiliary information;
- the first algorithm information includes at least one of the security requirement derivation algorithm, the confidentiality algorithm, and the integrity algorithm;
- the second security auxiliary information includes information in the terminal core network context
- the third security requirement includes at least one of a secret key and a secret stream
- the second identification information indicates the terminal, or is generated by the terminal identification, or indicates a group of terminals, or is related to the first identification information.
- the access network node generating the first security requirement based on the second target information includes:
- the access network node generates the first security requirement based on at least one of the second derived information and the security requirement derivation algorithm
- the second derived information includes at least one of the following: access network related keys, AS layer related keys, keys in the terminal context, at least part of the content of the first security auxiliary information, at least part of the content of the second security auxiliary information, first identification information, and information in the terminal access network context.
- the method further comprises:
- the core network node generates the first security requirement or the third security requirement based on at least one of the third derived information and the security requirement derivation algorithm;
- the third derived information includes at least one of the following: a core network related key, a NAS layer related key, a key in a terminal context, the second security parameter, and at least part of the content of the second security auxiliary information.
- the target wireless signaling includes first safety assistance information
- the first derived information includes at least part of the first safety auxiliary information
- the first safety auxiliary information includes at least one of first algorithm information, first safety parameter, and second safety parameter.
- the above-mentioned terminal can also execute the various steps of the terminal in the embodiment of Figure 2 above
- the above-mentioned access network node can also execute the various steps of the access network node in the embodiment of Figure 4 above
- the core network node can also execute the various steps executed by the core network node in Figure 5 above.
- the interactive method provided in the embodiment of the present application can be executed by an interactive device or an interactive system.
- the interactive device and the interactive system provided in the embodiment of the present application are described by taking the method of executing the interactive method by an interactive device as an example.
- an embodiment of the present application further provides an interactive device.
- the interactive device 700 includes:
- a first receiving module 701 is configured to receive a target wireless signaling, where the target wireless signaling includes first identification information and first target information, where the first target information includes at least one of encryption information and integrity protection information;
- the first execution module 702 is configured to execute at least one of the following:
- the first operation includes at least one of the following:
- the second operation includes at least one of the following:
- the first security requirement is generated based on the first derived information, and the first security requirement includes at least one of a key and a secret stream; the first derived information and the fourth derived information include at least one of the following: a core network-related key, a non-access layer NAS layer-related key, an access network-related key, an access layer AS layer-related key, and a key in the terminal context; the second security requirement includes at least one of a key and a secret stream.
- the first target information also includes first safety auxiliary information
- the first security auxiliary information includes at least one of first algorithm information, first security parameter, and second security parameter;
- the first algorithm information includes at least one of the following:
- the first security requirement being further generated based on the security requirement derivation algorithm
- At least one of a confidentiality algorithm and an integrity algorithm is also performed based on at least one of the confidentiality algorithm and the integrity algorithm.
- the first derived information further includes at least one of the following:
- the first identification information is the first identification information.
- the first execution module 702 is specifically configured to execute the first operation based on the first safety requirement and a first calculation parameter, where the first calculation parameter includes at least one of the following:
- At least part of the first safety assistance information At least part of the first safety assistance information.
- the information in the terminal core network context includes at least one of the following:
- the terminal's group identification information The terminal's group identification information
- the information in the terminal access network context includes at least one of the following:
- the terminal's group identification information The terminal's group identification information
- the first execution module 702 is further configured to execute at least one of the following:
- the second information or part of the second information is securely processed based on at least one of the following: the first security requirement or the second security requirement, a first calculation parameter, and the third security parameter.
- the security protection includes at least one of confidentiality protection, encryption, and integrity protection; the security processing includes at least one of decryption, confidentiality processing, integrity processing, and integrity verification.
- the target wireless signaling includes at least one of the following:
- At least one pair of first identification information and first target information At least one pair of first identification information and first target information
- the first target information and the first identification information are one-to-one or multiple mappings
- the first identification information and the first target information are a one-to-zero or one mapping
- N is less than or equal to the number of first identification information included in the target wireless signaling.
- the terminal is in an idle state or an inactive state, or is in an idle state or an inactive state before sending the first information, or is in an idle state or an inactive state before receiving the second information.
- the first execution module 702 is further used to: send second algorithm information to the network side, where the second algorithm information is used to indicate at least one of the following: an algorithm supported by the terminal, an algorithm used by the terminal;
- the algorithm includes at least one of a security requirement derivation algorithm, a confidentiality algorithm, and an integrity algorithm.
- the first identification information indicates a terminal, or is generated by a terminal identifier, or indicates a group of terminals.
- the target wireless signaling includes any one of broadcast signaling, paging signaling, wireless short message, and system message;
- the target wireless signaling is sent through at least one of a paging channel PCH, a multicast channel MCH, a broadcast channel BCH, and a downlink shared channel DL-SCH;
- the target wireless signaling is sent via at least one of a physical downlink control channel PDCCH, a physical downlink shared channel PDSCH, a physical broadcast channel PBCH, and a physical multicast channel PMCH.
- PDCCH physical downlink control channel
- PDSCH physical downlink shared channel
- PBCH physical broadcast channel
- PMCH physical multicast channel
- an embodiment of the present application further provides an interactive device.
- the interactive device 800 includes:
- a first sending module 801 is used to send a target wireless signaling, where the target wireless signaling includes first identification information and first target information, where the first target information includes at least one of encryption information and integrity protection information;
- the encryption information and integrity protection information are generated based on a first security requirement, and the first security requirement includes at least one of a secret key and a secret stream.
- the interaction device further includes:
- a second receiving module used to receive third information or target data from a core network node
- the third information includes second identification information and second target information
- the second target information includes at least one of the following:
- Second security assistance information wherein the second security assistance information includes information in the terminal core network context
- the second identification information is used to indicate a terminal, or is generated by a terminal identification, or indicates a group of terminals, or is related to the first identification information; and the first algorithm information includes at least one of the following:
- Security element derivation algorithm confidentiality algorithm, and integrity algorithm.
- the third information includes at least one of the following:
- the second target information and the second identification information are one-to-one or multiple mappings
- the second identification information and the second target information are a one-to-zero or one mapping
- K is less than or equal to the number of second identification information included in the third information.
- the first target information further includes at least one of the following:
- the first safety auxiliary information includes at least one of first algorithm information, a first safety parameter, and a second safety parameter.
- the interaction device 800 further includes:
- the second execution module is configured to execute at least one of the following:
- the first calculation parameter includes at least one of the following:
- the second derived information includes at least one of the following:
- the third operation includes at least one of the following:
- a second security requirement is generated based on fourth derived information and at least one of the first security requirements, the second security requirement including at least one of a key and a secret stream, the fourth derived information including at least one of the following: a core network-related key, a non-access layer NAS layer-related key, an access network-related key, an AS layer-related key, a key in a terminal context, and the third security parameter.
- the second execution module is further configured to execute at least one of the following:
- the second information or part of the second information is securely protected based on at least one of the following: the first security requirement or the second security requirement, the first calculation parameter, and the third security parameter.
- the security protection includes at least one of confidentiality protection, encryption, and integrity protection; the security processing includes at least one of decryption, confidentiality processing, integrity processing, and integrity verification.
- the terminal is in an idle state or an inactive state, or is in an idle state or an inactive state before sending the first information, or is in an idle state or an inactive state before receiving the second information.
- the target wireless signaling includes at least one of the following:
- At least one pair of first identification information and first target information At least one pair of first identification information and first target information
- the first target information and the first identification information are one-to-one or multiple mappings
- the first identification information and the first target information are a one-to-zero or one mapping
- N is less than or equal to the number of first identification information included in the target wireless signaling.
- the first identification information indicates a terminal, or is generated by a terminal identifier, or indicates a group of terminals.
- the target wireless signaling is any one of broadcast signaling, paging signaling, wireless short message, and system message;
- the target wireless signaling is sent through at least one of a paging channel PCH, a multicast channel MCH, a broadcast channel BCH, and a downlink shared channel DL-SCH;
- the target wireless signaling is sent via at least one of a physical downlink control channel PDCCH, a physical downlink shared channel PDSCH, a physical broadcast channel PBCH, and a physical multicast channel PMCH.
- PDCCH physical downlink control channel
- PDSCH physical downlink shared channel
- PBCH physical broadcast channel
- PMCH physical multicast channel
- an embodiment of the present application further provides an interactive device.
- the interactive device 900 includes:
- a second sending module 901 is used to send third information or target data to the access network node, where the third information includes second identification information and second target information;
- the second target information includes at least one of the following:
- Second security assistance information wherein the second security assistance information includes information in the terminal core network context
- the first algorithm information packet security requirement derives at least one of an algorithm, a confidentiality algorithm, and an integrity algorithm; the first security requirement includes at least one of a secret key and a secret stream, the third security requirement includes at least one of a secret key and a secret stream, and the second identification information indicates a terminal.
- the interaction device 900 further includes:
- a third execution module configured to generate the first security requirement or the third security requirement based on at least one of third derived information and the security requirement derivation algorithm
- the third derived information includes at least one of the following: a core network related key, a NAS layer related key, a key in a terminal context, the first algorithm information, the second security parameter, and at least part of the second security auxiliary information.
- the third information includes at least one of the following:
- the second target information and the second identification information are one-to-one or multiple mappings
- the second identification information and the second target information are a one-to-zero or one mapping
- K is less than or equal to the number of second identification information.
- the interaction device 900 further includes:
- a third receiving module is used to receive second algorithm information from the terminal, where the second algorithm information is used to indicate at least one of the following: an algorithm supported by the terminal, and an algorithm used by the terminal;
- the first algorithm information is generated based on the second algorithm information.
- the interactive device in the embodiment of the present application may be an electronic device, such as an electronic device with an operating system, or a component in an electronic device, such as an integrated circuit or a chip.
- the electronic device may be a terminal, or may be other devices other than a terminal.
- the terminal may include but is not limited to the types of terminal 11 listed above, and other devices may be servers, network attached storage (NAS), etc., which are not specifically limited in the embodiment of the present application.
- the interactive device provided in the embodiment of the present application can implement each process implemented by the method embodiments of Figures 2 to 5 and achieve the same technical effect. To avoid repetition, it will not be repeated here.
- the embodiment of the present application further provides an interactive system, the interactive system comprising: an access network node and a terminal, wherein:
- the access network node is used to send target wireless signaling, the target wireless signaling includes first identification information and first target information, the first target information includes at least one of encryption information and integrity protection information, wherein the encryption information and the integrity protection information are generated based on the first security requirement;
- the terminal is used to receive the target wireless signaling; and when the terminal is related to the first identification information, perform at least one of the following:
- the first operation includes at least one of the following:
- the second operation includes at least one of the following:
- the first security requirement is generated based on the first derived information, and the first security requirement includes at least one of a secret key and a secret stream;
- the first derived information and the fourth derived information include at least one of the following: a core network-related key, a non-access layer NAS layer-related key, an access network-related key, an access layer AS layer-related key, a key in the terminal context, information in the terminal core network context, first identification information, and information in the terminal access network context;
- the second security requirement includes at least one of a key and a secret stream.
- the interactive system further includes a core network node, and the core network node is used to send third information or target data to the access network node, where the third information includes the second identification information and the second target information;
- the access network node learns or generates the first security requirement based on the second target information, and sends the target wireless signaling based on the third information;
- the second target information includes at least one of the following: the first security requirement or the third security requirement, the first algorithm information, the second security parameter, and the second security auxiliary information;
- the first algorithm information includes at least one of the security requirement derivation algorithm, the confidentiality algorithm, and the integrity algorithm;
- the second security auxiliary information includes information in the terminal core network context
- the third security requirement includes at least one of a secret key and a secret stream
- the second identification information indicates the terminal, or is generated by the terminal identification, or indicates a group of terminals, or is related to the first identification information.
- the access network node is specifically configured to generate the first security requirement based on at least one of the second derived information and the security requirement derivation algorithm;
- the second derived information includes at least one of the following: access network related keys, AS layer related keys, keys in the terminal context, at least part of the content of the first security auxiliary information, at least part of the content of the second security auxiliary information, first identification information, and information in the terminal access network context.
- the core network node is further configured to generate the first security requirement or the third security requirement based on at least one of the third derived information and the security requirement derivation algorithm;
- the third derived information includes at least one of the following: a core network related key, a NAS layer related key, a key in a terminal context, the second security parameter, and at least part of the content of the second security auxiliary information.
- the target wireless signaling includes first safety assistance information
- the first derived information includes at least part of the first safety auxiliary information
- the first safety auxiliary information includes at least one of first algorithm information, first safety parameter, and second safety parameter.
- the interactive system may include at least two of the terminals, access network nodes and core network nodes in the above-mentioned embodiments.
- an embodiment of the present application also provides a communication device 1000, including a processor 1001 and a memory 1002, and the memory 1002 stores a program or instruction that can be executed on the processor 1001.
- the program or instruction is executed by the processor 1001
- the various steps of the above-mentioned interaction method embodiment are implemented, and the same technical effect can be achieved. To avoid repetition, it will not be repeated here.
- the embodiment of the present application also provides a terminal, including a processor and a communication interface, the communication interface is coupled to the processor, and the processor is used to run a program or instruction to implement the steps in the method embodiment shown in Figure 2.
- This terminal embodiment corresponds to the above-mentioned terminal side method embodiment, and each implementation process and implementation method of the above-mentioned method embodiment can be applied to the terminal embodiment and can achieve the same technical effect.
- Figure 11 is a schematic diagram of the hardware structure of a terminal implementing an embodiment of the present application.
- the terminal 1100 includes but is not limited to: a radio frequency unit 1101, a network module 1102, an audio output unit 1103, an input unit 1104, a sensor 1105, a display unit 1106, a user input unit 1107, an interface unit 1108, a memory 1109 and at least some of the components of a processor 1110.
- the terminal 1100 can also include a power supply (such as a battery) for supplying power to each component, and the power supply can be logically connected to the processor 1110 through a power management system, so as to implement functions such as charging, discharging, and power consumption management through the power management system.
- a power supply such as a battery
- the terminal structure shown in FIG11 does not constitute a limitation on the terminal, and the terminal can include more or fewer components than shown in the figure, or combine certain components, or arrange components differently, which will not be described in detail here.
- the input unit 1104 may include a graphics processing unit (GPU) 11041 and a microphone 11042, and the graphics processor 11041 processes the image data of the static picture or video obtained by the image capture device (such as a camera) in the video capture mode or the image capture mode.
- the display unit 1106 may include a display panel 11061, and the display panel 11061 may be configured in the form of a liquid crystal display, an organic light emitting diode, etc.
- the user input unit 1107 includes a touch panel 11071 and at least one of other input devices 11072.
- the touch panel 11071 is also called a touch screen.
- the touch panel 11071 may include two parts: a touch detection device and a touch controller.
- Other input devices 11072 may include, but are not limited to, a physical keyboard, function keys (such as a volume control key, a switch key, etc.), a trackball, a mouse, and a joystick, which will not be repeated here.
- the RF unit 1101 can transmit the data to the processor 1110 for processing; in addition, the RF unit 1101 can send uplink data to the network side device.
- the RF unit 1101 includes but is not limited to an antenna, an amplifier, a transceiver, a coupler, a low noise amplifier, a duplexer, etc.
- the memory 1109 can be used to store software programs or instructions and various data.
- the memory 1109 may mainly include a first storage area for storing programs or instructions and a second storage area for storing data, wherein the first storage area may store an operating system, an application program or instruction required for at least one function (such as a sound playback function, an image playback function, etc.), etc.
- the memory 1109 may include a volatile memory or a non-volatile memory.
- the non-volatile memory may be a read-only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM), or a flash memory.
- the volatile memory may be a random access memory (RAM), a static random access memory (SRAM), a dynamic random access memory (DRAM), a synchronous dynamic random access memory (SDRAM), a double data rate synchronous dynamic random access memory (DDRSDRAM), an enhanced synchronous dynamic random access memory (ESDRAM), a synchronous link dynamic random access memory (SLDRAM) and a direct memory bus random access memory (DRRAM).
- RAM random access memory
- SRAM static random access memory
- DRAM dynamic random access memory
- SDRAM synchronous dynamic random access memory
- DDRSDRAM double data rate synchronous dynamic random access memory
- ESDRAM enhanced synchronous dynamic random access memory
- SLDRAM synchronous link dynamic random access memory
- DRRAM direct memory bus random access memory
- the processor 1110 may include one or more processing units; optionally, the processor 1110 integrates an application processor and a modem processor, wherein the application processor mainly processes operations related to an operating system, a user interface, and application programs, and the modem processor mainly processes wireless communication signals, such as a baseband processor. It is understandable that the modem processor may not be integrated into the processor 1110.
- the radio frequency unit 1101 is configured to receive a target wireless signaling, wherein the target wireless signaling includes first identification information and first target information, wherein the first target information includes at least one of encryption information and integrity protection information;
- the first operation includes at least one of the following:
- the second operation includes at least one of the following:
- the first security requirement is generated based on the first derived information, and the first security requirement includes at least one of a key and a secret stream;
- the first derived information includes at least one of the following: a core network-related key, a non-access layer NAS layer-related key, an access network-related key, an access layer AS layer-related key, and a key in the terminal context;
- the fourth derived information includes at least one of the following: a core network-related key, a non-access layer NAS layer-related key, an access network-related key, an access layer AS layer-related key, a key in the terminal context, and the third security parameter;
- the second security requirement includes at least one of a key and a secret stream.
- the embodiment of the present application also provides a network side device, including a processor and a communication interface, the communication interface is coupled to the processor, and the processor is used to run a program or instruction to implement the steps of the method embodiment shown in Figure 4.
- the network side device embodiment corresponds to the above-mentioned network side device method embodiment, and each implementation process and implementation method of the above-mentioned method embodiment can be applied to the network side device embodiment, and can achieve the same technical effect.
- the embodiment of the present application also provides a network side device.
- the network side device 1200 includes: an antenna 1201, a radio frequency device 1202, a baseband device 1203, a processor 1204 and a memory 1205.
- the antenna 1201 is connected to the radio frequency device 1202.
- the radio frequency device 1202 receives information through the antenna 1201 and sends the received information to the baseband device 1203 for processing.
- the baseband device 1203 processes the information to be sent and sends it to the radio frequency device 1202.
- the radio frequency device 1202 processes the received information and sends it out through the antenna 1201.
- the method executed by the network-side device in the above embodiment may be implemented in the baseband device 1203, which includes a baseband processor.
- the baseband device 1203 may include, for example, at least one baseband board, on which multiple chips are arranged, as shown in Figure 12, one of which is, for example, a baseband processor, which is connected to the memory 1205 through a bus interface to call the program in the memory 1205 and execute the network side device operations shown in the above method embodiment.
- the network side device may also include a network interface 1206, which is, for example, a Common Public Radio Interface (CPRI).
- CPRI Common Public Radio Interface
- the network side device 1200 of the embodiment of the present application also includes: instructions or programs stored in the memory 1205 and executable on the processor 1204.
- the processor 1204 calls the instructions or programs in the memory 1205 to execute the method executed by each module shown in Figure 8 and achieves the same technical effect. To avoid repetition, it will not be repeated here.
- the embodiment of the present application further provides a network side device.
- the network side device 1300 includes: a processor 1301, a network interface 1302, and a memory 1303.
- the network interface 1302 is, for example, a common public radio interface (CPRI).
- CPRI common public radio interface
- the network side device 1300 of the embodiment of the present application also includes: instructions or programs stored in the memory 1303 and executable on the processor 1301.
- the processor 1301 calls the instructions or programs in the memory 1303 to execute the methods executed by the modules shown in Figure 9 and achieve the same technical effect. To avoid repetition, it will not be repeated here.
- An embodiment of the present application also provides a readable storage medium, on which a program or instruction is stored.
- a program or instruction is stored.
- the various processes of the above-mentioned interaction method embodiment are implemented and the same technical effect can be achieved. To avoid repetition, it will not be repeated here.
- the processor is the processor in the terminal described in the above embodiment.
- the readable storage medium includes a computer readable storage medium, such as a computer read-only memory ROM, a random access memory RAM, a magnetic disk or an optical disk.
- the readable storage medium may be a non-transient readable storage medium.
- An embodiment of the present application further provides a chip, which includes a processor and a communication interface, wherein the communication interface is coupled to the processor, and the processor is used to run programs or instructions to implement the various processes of the above-mentioned interaction method embodiment, and can achieve the same technical effect. To avoid repetition, it will not be repeated here.
- the chip mentioned in the embodiments of the present application can also be called a system-level chip, a system chip, a chip system or a system-on-chip chip, etc.
- the embodiments of the present application further provide a computer program/program product, which is stored in a storage medium and is executed by at least one processor to implement the various processes of the above-mentioned interaction method embodiment and can achieve the same technical effect. To avoid repetition, it will not be described here.
- An embodiment of the present application also provides a wireless communication system, including: a terminal and a network side device, wherein the terminal can be used to execute the steps of the terminal side interaction method as described above, and the network side device can be used to execute the steps of the access network node and core network node interaction method as described above.
Landscapes
- Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Mobile Radio Communication Systems (AREA)
Abstract
本申请公开了一种交互方法、装置、系统、终端及网络侧设备,属于通信技术领域,本申请实施例的交互方法包括:终端接收目标无线信令,目标无线信令包括第一标识信息以及第一目标信息,第一目标信息包括加密信息与完整性保护信息中的至少一项;在终端与第一标识信息相关的情况下执行以下至少一项:解密加密信息;对加密信息进行机密性处理;对第一目标信息进行机密性处理;校验或验证完整性保护信息;对第一目标信息进行安全处理;对第一目标信息进行完整性校验或完整性处理;基于完整性保护信息进行完整性校验或完整性处理;生成第二安全要件;向接入网节点发送第一信息;向接入网节点发送携带第三安全参数的第一信息;从接入网节点接收第二信息。
Description
相关申请的交叉引用
本申请要求于2023年12月07日提交中国专利局、申请号为202311673987.9、发明名称为“交互方法、装置、系统、终端及网络侧设备”的中国专利申请的优先权,其全部内容通过引用结合在本申请中。
本申请属于通信技术领域,具体涉及一种交互方法、装置、系统、终端及网络侧设备。
随着通信技术的发展,在通信系统中,为了提高数据传输的效率,终端可以在不进入连接态的情况下,和网络侧设备进行终端专属数据(UE dedicate data)的收发,即小数据传输(Small Data Transmission,SDT)。目前小数据传输主要包括在终端触发的上行消息3(Msg3)或者配置授权(Configured Grant,CG)的物理上行共享信道(Physical Uplink Shared Channel,PUSCH)上传输的移动终端发起的小数据传输(Mobile Originated SDT,MO-SDT)或者下行触发的移动终端终止的小数据传输(Mobile Terminated SDT,MT-SDT)。这样,仍然需要终端和网络侧设备进行多次消息交互,才能完成小数据的交互,这样将会导致小数据传输的时延较大。
本申请实施例提供一种交互方法、装置、系统、终端及网络侧设备,能够解决小数据传输的时延较大问题。
第一方面,提供了一种交互方法,包括:
终端接收目标无线信令,所述目标无线信令包括第一标识信息以及第一目标信息,所述第一目标信息包括加密信息与完整性保护信息中的至少一项;
在所述终端与所述第一标识信息相关的情况下,所述终端执行以下至少一项:
基于第一安全要件执行第一操作;
第二操作;
其中,所述第一操作包括以下至少一项:
解密所述加密信息;
对所述加密信息进行机密性处理;
对所述第一目标信息进行机密性处理;
校验或验证所述完整性保护信息;
对所述第一目标信息进行安全处理;
对所述第一目标信息进行完整性校验或完整性处理;
基于所述完整性保护信息,对以下至少一项进行完整性校验或完整性处理:所述第一目标信息、所述第一目标信息中的部分内容、和所述解密的结果;
其中,所述第二操作包括以下至少一项:
基于第四派生信息和所述第一安全要件中的至少一项生成第二安全要件;
向接入网节点发送第一信息;
向接入网节点发送携带第三安全参数的第一信息;
从接入网节点接收第二信息;
其中,所述第一安全要件基于第一派生信息生成,所述第一安全要件包括密钥和密流中的至少一项;所述第一派生信息包括以下至少一项:核心网相关密钥、非接入层面NAS层相关密钥、接入网相关密钥、接入层面AS层相关密钥、和终端上下文中的密钥;所述第四派生信息包括以下至少一项:核心网相关密钥、非接入层面NAS层相关密钥、接入网相关密钥、接入层面AS层相关密钥、终端上下文中的密钥、和所述第三安全参数;所述第二安全要件包括密钥和密流中的至少一项。
第二方面,提供了一种交互方法,包括:
接入网节点发送目标无线信令,所述目标无线信令包括第一标识信息以及第一目标信息,所述第一目标信息包括加密信息与完整性保护信息中的至少一项;
其中,所述加密信息和完整性保护信息基于第一安全要件生成,所述第一安全要件包括秘钥和密流中的至少一项。
第三方面,提供了一种交互方法,包括:
核心网节点向接入网节点发送第三信息或目标数据,所述第三信息包括第二标识信息和第二目标信息;
其中,所述第二目标信息包括以下至少一项:
第一安全要件或第三安全要件;
第一算法信息;
第二安全参数;
第二安全辅助信息,所述第二安全辅助信息包括终端核心网上下文中的信息;
其中,所述第一算法信息包安全要件派生算法、机密性算法、和完整性算法中的至少一项;所述第一安全要件包括秘钥和密流中的至少一项,所述第三安全要件包括秘钥和密流中的至少一项,所述第二标识信息指示终端,或由终端标识生成,或指示一组终端。
第四方面,提供了一种交互方法,包括:
接入网节点发送目标无线信令,所述目标无线信令包括第一标识信息以及第一目标信息,所述第一目标信息包括加密信息与完整性保护信息中的至少一项,其中,所述加密信息和完整性保护信息基于第一安全要件生成;
终端接收所述目标无线信令;
在所述终端与所述第一标识信息相关的情况下,所述终端执行以下至少一项:
基于第一安全要件执行第一操作;
第二操作;
其中,所述第一操作包括以下至少一项:
解密所述加密信息;
对所述加密信息进行机密性处理;
对所述第一目标信息进行机密性处理;
校验或验证所述完整性保护信息;
对所述第一目标信息进行安全处理;
对所述第一目标信息进行完整性校验或完整性处理;
基于所述完整性保护信息,对以下至少一项进行完整性校验或完整性处理:所述第一目标信息、所述第一目标信息中的部分内容、和所述解密的结果;
其中,所述第二操作包括以下至少一项:
基于第四派生信息和所述第一安全要件中的至少一项生成第二安全要件;
向接入网节点发送第一信息;
向接入网节点发送携带第三安全参数的第一信息;
从接入网节点接收第二信息;
其中,所述第一安全要件基于第一派生信息生成,所述第一安全要件包括秘钥和密流中的至少一项;所述第一派生信息包括以下至少一项:核心网相关密钥、非接入层面NAS层相关密钥、接入网相关密钥、接入层面AS层相关密钥、终端上下文中的密钥、终端核心网上下文中的信息、第一标识信息、和终端接入网上下文中的信息;所述第四派生信息包括以下至少一项:核心网相关密钥、非接入层面NAS层相关密钥、接入网相关密钥、接入层面AS层相关密钥、终端上下文中的密钥、终端核心网上下文中的信息、第一标识信息、终端接入网上下文中的信息、和所述第三安全参数;所述第二安全要件包括密钥和密流中的至少一项。
第五方面,提供了一种交互装置,包括:
第一接收模块,用于接收目标无线信令,所述目标无线信令包括第一标识信息以及第一目标信息,所述第一目标信息包括加密信息与完整性保护信息中的至少一项;
第一执行模块,用于执行以下至少一项:
基于第一安全要件执行第一操作;
第二操作;
其中,所述第一操作包括以下至少一项:
解密所述加密信息;
对所述加密信息进行机密性处理;
对所述第一目标信息进行机密性处理;
校验或验证所述完整性保护信息;
对所述第一目标信息进行安全处理;
对所述第一目标信息进行完整性校验或完整性处理;
基于所述完整性保护信息,对以下至少一项进行完整性校验或完整性处理:所述第一目标信息、所述第一目标信息中的部分内容、和所述解密的结果;
其中,所述第二操作包括以下至少一项:
基于第四派生信息和所述第一安全要件中的至少一项生成第二安全要件;
向接入网节点发送第一信息;
从接入网节点接收第二信息;
其中,所述第一安全要件基于第一派生信息生成,所述第一安全要件包括密钥和密流中的至少一项;所述第一派生信息和所述第四派生信息包括以下至少一项:核心网相关密钥、非接入层面NAS层相关密钥、接入网相关密钥、接入层面AS层相关密钥、和终端上下文中的密钥;所述第二安全要件包括密钥和密流中的至少一项。
第六方面,提供了一种交互装置,包括:
第一发送模块,用于发送目标无线信令,所述目标无线信令包括第一标识信息以及第一目标信息,所述第一目标信息包括加密信息与完整性保护信息中的至少一项;
其中,所述加密信息和完整性保护信息基于第一安全要件生成,所述第一安全要件包括秘钥和密流中的至少一项。
第七方面,提供了一种交互装置,包括:
第二发送模块,用于向接入网节点发送第三信息或目标数据,所述第三信息包括第二标识信息和第二目标信息;
其中,所述第二目标信息包括以下至少一项:
第一安全要件或第三安全要件;
第一算法信息;
第二安全参数;
第二安全辅助信息,所述第二安全辅助信息包括终端核心网上下文中的信息;
其中,所述第一算法信息包安全要件派生算法、机密性算法、和完整性算法中的至少一项;所述第一安全要件包括秘钥和密流中的至少一项,所述第三安全要件包括秘钥和密流中的至少一项,所述第二标识信息指示终端。
第八方面,提供了一种交互系统,包括:接入网节点和终端,其中,
所述接入网节点用于发送目标无线信令,所述目标无线信令包括第一标识信息以及第一目标信息,所述第一目标信息包括加密信息与完整性保护信息中的至少一项,其中,所述加密信息和完整性保护信息基于第一安全要件生成;
所述终端用于接收所述目标无线信令;并在所述终端与所述第一标识信息相关的情况下,执行以下至少一项:
基于第一安全要件执行第一操作;
第二操作;
其中,所述第一操作包括以下至少一项:
解密所述加密信息;
对所述加密信息进行机密性处理;
对所述第一目标信息进行机密性处理;
校验或验证所述完整性保护信息;
对所述第一目标信息进行安全处理;
对所述第一目标信息进行完整性校验或完整性处理;
基于所述完整性保护信息,对以下至少一项进行完整性校验或完整性处理:所述第一目标信息、所述第一目标信息中的部分内容、和所述解密的结果;
其中,所述第二操作包括以下至少一项:
基于第四派生信息和所述第一安全要件中的至少一项生成第二安全要件;
向接入网节点发送第一信息;
从接入网节点接收第二信息;
其中,所述第一安全要件基于第一派生信息生成,所述第一安全要件包括秘钥和密流中的至少一项;所述第一派生信息和所述第四派生信息包括以下至少一项:核心网相关密钥、非接入层面NAS层相关密钥、接入网相关密钥、接入层面AS层相关密钥、终端上下文中的密钥、终端核心网上下文中的信息、第一标识信息、和终端接入网上下文中的信息;所述第二安全要件包括密钥和密流中的至少一项。
第九方面,提供了一种终端,该终端包括处理器和存储器,所述存储器存储可在所述处理器上运行的程序或指令,所述程序或指令被所述处理器执行时实现如第一方面所述的方法的步骤。
第十方面,提供了一种终端,包括处理器及通信接口,其中,所述通信接口用于接收目标无线信令,所述目标无线信令包括第一标识信息以及第一目标信息,所述第一目标信息包括加密信息与完整性保护信息中的至少一项;执行以下至少一项:
基于第一安全要件执行第一操作;
第二操作;
其中,所述第一操作包括以下至少一项:
解密所述加密信息;
对所述加密信息进行机密性处理;
对所述第一目标信息进行机密性处理;
校验或验证所述完整性保护信息;
对所述第一目标信息进行安全处理;
对所述第一目标信息进行完整性校验或完整性处理;
基于所述完整性保护信息,对以下至少一项进行完整性校验或完整性处理:所述第一目标信息、所述第一目标信息中的部分内容、和所述解密的结果;
其中,所述第二操作包括以下至少一项:
基于第四派生信息和所述第一安全要件中的至少一项生成第二安全要件;
向接入网节点发送第一信息;
从接入网节点接收第二信息;
其中,所述第一安全要件基于第一派生信息生成,所述第一安全要件包括密钥和密流中的至少一项;所述第一派生信息和所述第四派生信息包括以下至少一项:核心网相关密钥、非接入层面NAS层相关密钥、接入网相关密钥、接入层面AS层相关密钥、和终端上下文中的密钥;所述第二安全要件包括密钥和密流中的至少一项。
第十一方面,提供了一种网络侧设备,该网络侧设备包括处理器和存储器,所述存储器存储可在所述处理器上运行的程序或指令,所述程序或指令被所述处理器执行时实现如第二方面所述的方法的步骤,或实现如第三方面所述的方法的步骤。
第十二方面,提供了一种网络侧设备,包括处理器及通信接口,其中,所述通信接口用于发送目标无线信令,所述目标无线信令包括第一标识信息以及第一目标信息,所述第一目标信息包括加密信息与完整性保护信息中的至少一项;其中,所述加密信息和完整性保护信息基于第一安全要件生成,所述第一安全要件包括秘钥和密流中的至少一项
或者,所述通信接口用于向接入网节点发送第三信息或目标数据,所述第三信息包括第二标识信息和第二目标信息;
其中,所述第二目标信息包括以下至少一项:
第一安全要件或第三安全要件;
第一算法信息;
第二安全参数;
第二安全辅助信息,所述第二安全辅助信息包括终端核心网上下文中的信息;
其中,所述第一算法信息包安全要件派生算法、机密性算法、和完整性算法中的至少一项;所述第一安全要件包括秘钥和密流中的至少一项,所述第三安全要件包括秘钥和密流中的至少一项,所述第二标识信息指示终端。
第十三方面,提供了一种可读存储介质,所述可读存储介质上存储程序或指令,所述程序或指令被处理器执行时实现如第一方面所述的方法的步骤,或者实现如第二方面所述的方法的步骤,或者实现如第三方面所述的方法的步骤。
第十四方面,提供了一种无线通信系统,包括:终端及网络侧设备,所述终端可用于执行如第一方面所述的方法的步骤,所述网络侧设备可用于执行如第二方面和第三方面所述的方法的步骤。
第十五方面,提供了一种芯片,所述芯片包括处理器和通信接口,所述通信接口和所述处理器耦合,所述处理器用于运行程序或指令,实现如第一方面所述的方法,或实现如第二方面所述的方法,或者实现如第三方面所述的方法的步骤。
第十六方面,提供了一种计算机程序/程序产品,所述计算机程序/程序产品被存储在存储介质中,所述程序/程序产品被至少一个处理器执行以实现如第一方面所述的方法,或实现如第二方面所述的方法,或者实现如第三方面所述的方法的步骤。
本申请实施例通过终端接收目标无线信令,所述目标无线信令包括第一标识信息以及第一目标信息,所述第一目标信息包括加密信息与完整性保护信息中的至少一项;在所述终端与所述第一标识信息相关的情况下,所述终端执行第一操作和第二操作中的至少一项。这样可以基于目标无线信令完成下行数据或信令的传输,或者在目标无线信令之后终端与网络侧设备的第一条交互信息中即可实现数据或信令的传输;因此,本申请实施例降低了数据传输时延。
图1是本申请实施例可应用的一种无线通信系统的框图;
图2是本申请实施例提供的交互方法流程图之一;
图3是本申请实施例提供的交互方法流程图之二;
图4是本申请实施例提供的交互方法流程图之三;
图5是本申请实施例提供的交互方法流程图之四;
图6是本申请实施例提供的交互方法流程图之五;
图7是本申请实施例提供的交互装置结构示意图之一;
图8是本申请实施例提供的交互装置结构示意图之二;
图9是本申请实施例提供的交互装置结构示意图之三;
图10是本申请实施例提供的通信设备的结构示意图;
图11是本申请实施例提供的终端的结构示意图;
图12是本申请实施例提供的一种网络侧设备的结构示意图;
图13是本申请实施例提供的另一种网络侧设备的结构示意图。
下面将结合本申请实施例中的附图,对本申请实施例中的技术方案进行清楚描述,显然,所描述的实施例是本申请一部分实施例,而不是全部的实施例。基于本申请中的实施例,本领域普通技术人员所获得的所有其他实施例,都属于本申请保护的范围。
本申请的术语“第一”、“第二”等是用于区别类似的对象,而不用于描述特定的顺序或先后次序。应该理解这样使用的术语在适当情况下可以互换,以便本申请的实施例能够以除了在这里图示或描述的那些以外的顺序实施,且“第一”、“第二”所区别的对象通常为一类,并不限定对象的个数,例如第一对象可以是一个,也可以是多个。此外,本申请中的“或”表示所连接对象的至少其中之一。例如“A或B”涵盖三种方案,即,方案一:包括A且不包括B;方案二:包括B且不包括A;方案三:既包括A又包括B。字符“/”一般表示前后关联对象是一种“或”的关系。
值得指出的是,本申请实施例所描述的技术不限于长期演进型(Long Term Evolution,LTE)/LTE的演进(LTE-Advanced,LTE-A)系统,还可用于其他无线通信系统,诸如码分多址(Code Division Multiple Access,CDMA)、时分多址(Time Division Multiple Access,TDMA)、频分多址(Frequency Division Multiple Access,FDMA)、正交频分多址(Orthogonal Frequency Division Multiple Access,OFDMA)、单载波频分多址(Single-carrier Frequency Division Multiple Access,SC-FDMA)或其他系统。本申请的术语“系统”和“网络”常被可互换地使用,所描述的技术既可用于以上提及的系统和无线电技术,也可用于其他系统和无线电技术。以下描述出于示例目的描述了新空口(New Radio,NR)系统,并且在以下大部分描述中使用NR术语,但是这些技术也可应用于NR系统应用以外的系统,如第6代(6th Generation,6G)通信系统。
图1示出本申请实施例可应用的一种无线通信系统的框图。无线通信系统包括终端11和网络侧设备12。其中,终端11可以是手机、平板电脑(Tablet Personal Computer)、膝上型电脑(Laptop Computer)、笔记本电脑、个人数字助理(Personal Digital Assistant,PDA)、掌上电脑、上网本、超级移动个人计算机(Ultra-mobile Personal Computer,UMPC)、移动上网装置(Mobile Internet Device,MID)、增强现实(Augmented Reality,AR)、虚拟现实(Virtual Reality,VR)设备、机器人、可穿戴式设备(Wearable Device)、飞行器(flight vehicle)、车载设备(Vehicle User Equipment,VUE)、船载设备、行人终端(Pedestrian User Equipment,PUE)、智能家居(具有无线通信功能的家居设备,如冰箱、电视、洗衣机或者家具等)、游戏机、个人计算机(Personal Computer,PC)、柜员机或者自助机等终端侧设备。可穿戴式设备包括:智能手表、智能手环、智能耳机、智能眼镜、智能首饰(智能手镯、智能手链、智能戒指、智能项链、智能脚镯、智能脚链等)、智能腕带、智能服装等。其中,车载设备也可以称为车载终端、车载控制器、车载模块、车载部件、车载芯片或车载单元等。需要说明的是,在本申请实施例并不限定终端11的具体类型。网络侧设备12可以包括接入网系统或核心网设备,其中,接入网系统也可以称为无线接入网(Radio Access Network,RAN)设备、无线接入网功能或无线接入网单元。接入网系统可以包括基站、无线局域网(Wireless Local Area Network,WLAN)接入点(Access Point,AP)或无线保真(Wireless Fidelity,WiFi)节点等。其中,基站可被称为节点B(Node B,NB)、演进节点B(Evolved Node B,eNB)、下一代节点B(the next generation Node B,gNB)、新空口节点B(New Radio Node B,NR Node B)、接入点、中继站(Relay Base Station,RBS)、服务基站(Serving Base Station,SBS)、基收发机站(Base Transceiver Station,BTS)、无线电基站、无线电收发机、基本服务集(Basic Service Set,BSS)、扩展服务集(Extended Service Set,ESS)、家用B节点(home Node B,HNB)、家用演进型B节点(home evolved Node B)、发送接收点(Transmission Reception Point,TRP)或所属领域中其他某个合适的术语,只要达到相同的技术效果,所述基站不限于特定技术词汇,需要说明的是,在本申请实施例中仅以NR系统中的基站为例进行介绍,并不限定基站的具体类型。
核心网设备可以包含但不限于如下至少一项:核心网节点、核心网功能、移动管理实体(Mobility Management Entity,MME)、接入移动管理功能(Access and Mobility Management Function,AMF)、会话管理功能(Session Management Function,SMF)、用户平面功能(User Plane Function,UPF)、策略控制功能(Policy Control Function,PCF)、策略与计费规则功能单元(Policy and Charging Rules Function,PCRF)、边缘应用服务发现功能(Edge Application Server Discovery Function,EASDF)、统一数据管理(Unified Data Management,UDM)、统一数据仓储(Unified Data Repository,UDR)、归属用户服务器(Home Subscriber Server,HSS)、集中式网络配置(Centralized network configuration,CNC)、网络存储功能(Network Repository Function,NRF)、网络开放功能(Network Exposure Function,NEF)、本地NEF(Local NEF,或L-NEF)、绑定支持功能(Binding Support Function,BSF)、应用功能(Application Function,AF)等。需要说明的是,在本申请实施例中仅以NR系统中的核心网设备为例进行介绍,并不限定核心网设备的具体类型。
为了方便理解,以下对本申请实施例涉及的一些内容进行说明:
一、小数据传输(Small Data Transmission,SDT)。
高效小数据传输的特点是对于非无线资源控制(Radio Resource Control,RRC)连接态的终端(UE),避免因此引起的RRC状态转换和RRC连接建立过程的造成过多信令开销,通过极简单的信令过程即完成小数据传输的目的。其中,非RRC连接态可以包括空闲态(IDLE)和非激活(INACTIVE)态。
小数据传输方案的特点是UE当前数据无线承载(Data Radio Bearer,DRB)都是处于挂起的状态,而不是释放的状态。因而,UE在发送恢复请求(ResumeRequest)消息前可以先恢复DRB,然后再用RRC信令来捎带小数据,这时和连接(CONNECTED)态UE一样可以在DRB上传输数据。从而避免进行状态转换,以较小的信令开销达到高效小数据传输的目的。
小数据传输由于使用的是DRB传输,接入层面(Attached Storage,AS)安全已经激活,因此小数据传输可以对数据进行必要的安全保护,例如数据加密和完整性保护等操作。从安全角度,由于UE在挂起状态有可能已经移动到其它的基站下,因此此时UE重新发包所使用的安全密钥是需要更新的。更新的方法就按照UE在进入挂起状态时,网络侧设备提供给它的用于计算下一跳密钥的参数,进行下一个密钥的更新操作。
小数据传输的待传数据在专用业务信道(Dedicated Traffic Channel,DTCH)上承载,与上行RRCConnectionResumeRequest消息进行复用之后进行传输。类似的,如果有回复的下行消息,也可以在DTCH上承载,与下行RRCConnectionRelease消息复用传输。上下行的数据都是加密的,使用更新后的下一个密钥进行加密操作。
可选地,可以基于4步(4-step)随机接入信道(Random Access Channel,RACH)过程中的Msg3 PUSCH上传输小数据。小数据还可以在2-step RACH过程中MsgA PUSCH上传输,或者在RRC inactive状态下配置的配置授权(configured grant,CG)调度的PUSCH资源上传输。在2-step RACH和4-step RACH过程中的小数据传输称之为基于RACH(RACH based)小数据传输,基于configured grant调度的PUSCH的小数据传输称为CG based小数据传输。
二、移动终止的早期数据传输(Mobile Terminated Early Data Transmission,MT-EDT)。
在LTE系统中,网络(Network,NW)会通过寻呼(paging)消息携带MT-EDT触发消息,随后UE发起EDT过程,NW在接收到UE的请求消息(携带MT-EDT的原因值)后,把RRC响应消息串接上DRB数据,一并成一个协议数据单元,发送给UE,最终实现下行业务的接收。
Idle态或inactive态下的数据传输是一种特殊的传输机制,其允许UE在不进入连接态的情况下,和NW侧进行UE专属数据(UE dedicate data)收发。目前小数据传输主要在终端促发的上行Msg3或者CG PUSCH上传输的MO-SDT,或者下行促发的MT-SDT。如何在寻呼消息中数据传输或者调度数据传输尚未有对应的方案。为此,提出了本申请的交互方法,即通过paging等UE能接收到的第一条广播信号,直接将数据或数据传输资源递交给UE,减少了消息交互过程。
下面结合附图,通过一些实施例及其应用场景对本申请实施例提供的交互方法进行详细地说明。
参照图2,本申请实施例提供了一种交互方法,如图2所示,该交互方法包括:
步骤201,终端接收目标无线信令,所述目标无线信令包括第一标识信息以及第一目标信息,所述第一目标信息包括加密信息与完整性保护信息中的至少一项;
步骤202,在所述终端与所述第一标识信息相关的情况下,所述终端执行以下至少一项:
基于第一安全要件执行第一操作;
第二操作;
其中,所述第一操作包括以下至少一项:
解密所述加密信息;
对所述加密信息进行机密性处理;
对所述第一目标信息进行机密性处理;
校验或验证所述完整性保护信息;
对所述第一目标信息进行安全处理;
对所述第一目标信息进行完整性校验或完整性处理;
基于所述完整性保护信息,对以下至少一项进行完整性校验或完整性处理:所述第一目标信息、所述第一目标信息中的部分内容、和所述解密的结果;
其中,所述第二操作包括以下至少一项:
基于第四派生信息和所述第一安全要件中的至少一项生成第二安全要件;
向接入网节点发送第一信息;
向接入网节点发送携带第三安全参数的第一信息;
从接入网节点接收第二信息;
其中,所述第一安全要件基于第一派生信息生成,所述第一安全要件包括密钥和密流中的至少一项;所述第一派生信息包括以下至少一项:核心网相关密钥、非接入层面NAS层相关密钥、接入网相关密钥、接入层面AS层相关密钥、和终端上下文中的密钥;所述第四派生信息包括以下至少一项:核心网相关密钥、非接入层面NAS层相关密钥、接入网相关密钥、接入层面AS层相关密钥、终端上下文中的密钥、和所述第三安全参数;所述第二安全要件包括密钥和密流中的至少一项。
本申请实施例中,上述第一标识信息可以理解为目标标识或对目标标识截取的一部分标识,该目标标识可以包括用户标识、组标识、连接标识、承载标识、事物标识和交互标识中的至少一项。
可选地,上述加密信息可以理解为对待传输的内容中的至少部分内容进行安全性处理后得到的信息,上述完整性保护信息可以理解为与待传输的内容关联的完保信息,为媒体接入控制(Medium Access Control,MAC)值。在第一目标信息包括加密信息与完整性保护信息时,可以连理解为对传输的内容即进行安全处理,又进行了完整性处理,最终得到第一目标信息。
可选地,所述终端与所述第一标识信息相关可以理解为所述终端的相关标识与第一标识信息关联,例如,目标无线信令包括用户标识,在目标无线信令中包含的用户标识包括终端的用户标识的情况下,可以认为所述终端与所述第一标识信息相关,此时终端可以执行上述第一操作。
应理解,在所述终端与所述第一标识信息不相关的情况下,所述终端可以丢弃接收到的第一目标信息。
需要说明的是,上述目标无线信令可以理解为终端在空闲态或非激活态能够接收到的无线信令。在一些实施例中,在所述终端与所述第一标识信息相关的情况下,所述终端基于第一安全要件执行第一操作,这样无需其他交互信息即可实现下行数据或信令的传输,从而可以降低数据传输时延。与此同时,由于第一目标信息包括加密信息与完整性保护信息中的至少一项,由终端第一安全要件执行第一操作,从而提高传输的安全性,在一些实施例中,在所述终端与所述第一标识信息相关的情况下,终端执行第二操作,从而可以在后续终端与网络侧设备的第一条交互信息中即可实现数据或信令的传输,从而可以降低数据传输时延。
可选地,解密所述加密信息后,可以获得接入网节点传输的内容,具体可以包括信令或数据。
可选地,上述密流(KeyStream)可以为基于秘钥及其他参数生成的字符串。
可选地,上述核心网相关密钥可以包括长期密钥(Long Term Key)、认证相关密钥(Kausf)、安全及认证相关密钥(Kseaf)、AMF密钥(Kamf)、移动管理实体(Mobility Management Entity,MME)密钥(Kasme)等。
NAS层相关密钥可以包括NAS加密密钥(Knas_enc)、NAS完保密钥(Knas_int)等。
接入网相关密钥可以包括基站密钥(如Kenb、Kgnb、NH、Kenb*、Kgnb*、Ks-enb、Ks-gnb等)。
AS层相关密钥可以包括信令加密密钥(Krrc_enc)、信令完保密钥(Krrc_int)、数据加密密钥(Kup_enc)、数据完保密钥(Kup_int)等。
终端上下文中的密钥可以包括核心网相关密钥、非接入层面NAS层相关密钥、接入网相关密钥、和接入层面AS层相关密钥中的任意一个或至少两个组合成的密钥。
本申请实施例通过终端接收目标无线信令,所述目标无线信令包括第一标识信息以及第一目标信息,所述第一目标信息包括加密信息与完整性保护信息中的至少一项;在所述终端与所述第一标识信息相关的情况下,所述终端执行第一操作和第二操作中的至少一项。这样可以基于目标无线信令完成下行数据或信令的传输,或者在目标无线信令之后终端与网络侧设备的第一条交互信息中即可实现数据或信令的传输;因此,本申请实施例降低了数据传输时延。
需要说明的是,接入网设备发送目标无线信令之前,所述接入网节点从核心网节点接收第三信息或目标数据,所述第三信息包括第三标识信息和第二目标信息;
其中,所述第三信息包括第二标识信息和第二目标信息;
所述第二目标信息包括以下至少一项:
所述第一安全要件或第三安全要件,所述第三安全要件包括秘钥和密流中的至少一项;
第一算法信息;
第二安全参数;
第二安全辅助信息,所述第二安全辅助信息包括终端核心网上下文中的信息;
其中,所述第二标识信息用于指示终端,或由终端标识生成,或指示一组终端,或与所述第一标识信息相关。
本申请实施例中,所述接入网节点可以基于所述第二目标信息获知或生成所述第一安全要件,并基于所述第三信息发送所述目标无线信令。
例如,在一些实施例中,所述接入网节点基于第二派生信息和所述安全要件派生算法中的至少一项生成所述第一安全要件。其中,所述第二派生信息包括以下至少一项:接入网相关密钥、AS层相关密钥、终端上下文中的密钥、所述第一安全辅助信息中的至少部分内容、所述第二安全辅助信息中的至少部分内容、第一标识信息、和终端接入网上下文中的信息。
可选地,第二标识信息可以为全局用户临时标示(Globally Unique Temporary Identifier,GUTI),第一标识信息可以是RNTI;或者第二标识信息是GUTI,第一标识信息是短期移动用户识别标识(Short Term Mobile Subscriber Identity,S-TMSI);或者第二标识信息和第一标识信息都是S-TMSI。
可选地,上述目标数据可以理解为待传输数据,在一些实施例中,上述第三信息还可以包括上述目标数据。上述目标数据与上述加密信息或完整性保护信息关联,即接入网设备可以基于目标数据中的至少部分数据生成加密信息以及完整性保护信息。也就是说,通过目标无线信令可以传输部分数据,剩余部分的数据与第二信息关联,即可以基于剩余部分的数据生成第二信息。当然在一些实施例中,也可以不在目标无线信令中携带待传输数据,例如,上述加密信息为加密的资源信息,上述第二信息为加密的目标数据(或者为基于目标数据生成的加密数据)。
本申请实施例中,上述第三信息包括以下至少一项:
至少一个第二标识信息和至少一个第二目标信息;
至少一对第二标识信息与第二目标信息;
其中,所述第二目标信息与所述第二标识信息为一到一或多映射;
或者,所述第二标识信息与所述第二目标信息为一到零或一映射;
或者,K个第二标识信息与所有第二目标信息存在对应关系,且K小于或等于所述第三信息中包含的第二标识信息的数量。
本申请实施例中,第二目标信息与第二标识信息为一到一或多映射可以理解为:第二目标信息可以与第二标识信息存在一到一的映射关系,或者存在一到多的映射关系。例如,所有的第二目标信息与第二标识信息均为一到一映射;或所有的第二目标信息与第二标识信息均为一到多映射;或部分第二目标信息与第二标识信息为一到一映射,部分第二目标信息与第二标识信息为一到多映射。
第二标识信息与第二目标信息为一到零或一映射可以理解为:第二标识信息可以与第二目标信息存在一到一的映射关系,或者存在一到零的映射关系,其中一到零的映射关系表示第二标识信息不存在与之映射的第二目标信息。例如,所有的第二标识信息与第二目标信息均为一到一映射;或部分第二标识信息与第二目标信息为一到一映射,部分第二标识信息与第二目标信息为一到零映射。
可选地,对于K个第二标识信息与所有第二目标信息存在对应关系,在K等于所述目标无线信令包含的第二标识信息的数量的情况下,可以理解为所有的第二标识信息存在映射的第二目标信息;在K小于所述目标无线信令包含的第二标识信息的数量的情况下,可以理解为仅部分第二标识信息存在映射的第二目标信息,部分第二标识信息不存在映射的第二目标信息。其中,第二目标信息与第二标识信息的映射关系可以包括以下至少一项:一到一的映射关系;一到多的映射关系。
可选地,在一些实施例中,所述第二标识信息用于指示终端,或由终端标识生成,或指示一组终端,或与所述第一标识信息相关。
可选地,在一些实施例中,所述接入网节点执行以下至少一项:
基于安全要件派生算法生成所述第一安全要件;
基于第二派生信息生成所述第一安全要件;
基于机密性算法生成所述加密信息;
基于完整性算法生成所述完整性保护信息;
基于第一计算参数生成所述加密信息与所述完整性保护信息中的至少一项;
第三操作;
其中,所述第一计算参数包括以下至少一项:
终端接入网上下文中的信息;
所述第一标识信息;
第一安全辅助信息中的至少部分内容;
第二安全辅助信息中的至少部分内容;
第一算法信息;
所述第二派生信息包括以下至少一项:
接入网相关密钥;
接入层面AS层相关密钥;
终端上下文中的密钥;
第三安全要件;
终端接入网上下文中的信息;
所述第一标识信息;
第一安全辅助信息中的至少部分内容;
第二安全辅助信息中的至少部分内容;
第一算法信息;
所述第三操作包括以下至少一项:
基于第四派生信息和所述第一安全要件中的至少一项生成第二安全要件,所述第二安全要件包括密钥和密流中的至少一项,所述第四派生信息包括以下至少一项:核心网相关密钥、非接入层面NAS层相关密钥、接入网相关密钥、AS层相关密钥、和终端上下文中的密钥;
从终端接收第一信息;
向终端发送第二信息。
可选地,在接入网节点接收到第一信息后,可以对第一信息的至少部分内容进行安全处理,并上报给核心网节点。
可选地,核心网节点向接入网节点发送第一安全要件或第三安全要件之前,还可以基于第三派生信息和所述安全要件派生算法中的至少一项生成所述第一安全要件或所述第三安全要件;
其中,所述第三派生信息包括以下至少一项:核心网相关密钥、NAS层相关密钥、终端上下文中的密钥、所述第一算法信息、所述第二安全参数、和所述第二安全辅助信息中的至少部分内容。
需要说明的是,在本申请实施例中,上述核心网节点可以理解或替换为具有核心网功能的设备或系统,即可以称之为核心网设备或核心网系统,也可以称之为核心网功能。上述接入网节点可以理解为具有接入网功能的设备或系统,即可以称之为接入网设备或系统,也可以称之为基站或接入网功能。
可选地,在一些实施例中,所述第一目标信息还包括第一安全辅助信息;
其中,所述第一安全辅助信息包括第一算法信息、第一安全参数、和第二安全参数中的至少一项;
所述第一算法信息包括以下至少一项:
安全要件派生算法,所述第一安全要件还基于所述安全要件派生算法生成;
机密性算法和完整性算法中至少一项,所述第一操作还基于所述机密性算法和完整性算法中至少一项执行。
本申请实施例中,上述机密性算法可以包括加密算法和解密算法,上述完整性算法可以包括生成校验码的算法、或者包括校验或验证校验码的算法。
可选地,所述第一安全参数用于表示NAS的计数信息,例如下行NAS信令次数,或上行NAS信令次数,或NAS信令次数(下行NAS信令次数与上行NAS信令次数的和值);所述第二安全参数用于表示接入网信令的计数信息或数据报文的计数信息,例如第二安全参数可以为下行接入网信令次数、上行接入网信令次数、或接入网信令次数(即下行接入网信令次数与上行接入网信令次数的和值),也可以为下行数据报文数、上行数据报文数、或数据报文数(即下行数据报文数和上行数据报文数)。上述第三安全参数可以理解为用于表示接入网信令的计数信息或数据报文的计数信息,例如第二安全参数可以为下行接入网信令次数、上行接入网信令次数、或接入网信令次数(即下行接入网信令次数与上行接入网信令次数的和值),也可以为下行数据报文数、上行数据报文数、或数据报文数(即下行数据报文数和上行数据报文数)。可选地,在一些实施例中,该第三安全参数与第二安全参数不同。
应理解,上述下行NAS信令可以理解或替换为NAS下行信令,下行NAS信令可以理解或替换为NAS下行信令。下行接入网信令可以理解或替换为AS下行信令,上行接入网信令可以理解或替换为AS上行信令,接入网信令可以理解或替换为AS信令。数据报文可以理解或替换为协议数据报文。
可选地,所述第一安全要件还基于所述安全要件派生算法生成可以理解为,第一安全要件基于第一派生信息和接入网节点指示的安全要件派生算法生成。在一些实施例中,安全要件派生算法也可以属于第一派生信息的内容,即所述第一安全要件还基于所述安全要件派生算法生成可以理解为所述第一安全要件基于第一派生信息中除接入网节点指示的安全要件派生算法之外的信息和接入网节点指示的安全要件派生算法生成第一安全要件。应理解,在第一目标信息不包括安全要件派生算法的情况下,生成第一安全要件的安全要件派生算法可以由协议约定。
可选地,在一些实施例中,所述第一派生信息还包括以下至少一项:
第一安全辅助信息中的至少部分内容;
终端核心网上下文中的信息;
终端接入网上下文中的信息;
所述第一标识信息。
可选地,在一些实施例中,所述终端基于第一安全要件执行第一操作,包括:
所述终端基于所述第一安全要件以及第一计算参数执行所述第一操作,所述第一计算参数包括以下至少一项:
终端核心网上下文中的信息;
终端接入网上下文中的信息;
所述第一标识信息;
第一安全辅助信息中的至少部分内容。
本申请实施例中,第一计算参数包含的第一安全辅助信息中的至少部分内容可以与第一派生信息中包含的第一安全辅助信息中的至少部分内容相同或不同,或部分相同。例如,在一些实施例中,第一安全辅助信息包括两部分信息,其中一部分信息(如第一安全参数)用于执行所述第一操作,另一部分(如第二安全参数)用于生成安全要件。
可选地,在一些实施例中,所述终端核心网上下文中的信息,包括以下至少一项:
终端的标识信息;
终端的组标识信息;
NAS信令的计数信息;
NAS上行信令的计数信息;
NAS下信令的计数信息;
通过NAS传输的协议数据报文的计数信息;
通过NAS传输的上行协议数据报文的计数信息;
通过NAS传输的下行协议数据报文的计数信息;
或,所述终端接入网上下文中的信息,包括以下至少一项:
终端的标识信息;
终端的组标识信息;
AS信令的计数信息;
AS上行信令的计数信息;
AS下行信令的计数信息;
协议数据报文的计数信息;
上行协议数据报文的计数信息;
下行协议数据报文的计数信息。
可选地,在一些实施例中,所述方法包括以下至少一项:
所述终端基于以下至少一项生成所述第二安全要件:所述第一安全要件、所述第四派生信息、和所述第三安全参数;
所述终端基于以下至少一项,对所述第一信息或所述第一信息中的部分内容进行安全保护:所述第一安全要件或所述第二安全要件,第一计算参数,和所述第三安全参数;
所述终端基于以下至少一项,对所述第二信息或所述第二信息中的部分内容进行安全处理:所述第一安全要件或所述第二安全要件,第一计算参数,和所述第三安全参数。
在一些实施例中,在第一信息包括第三安全参数的情况下,上述第二安全要件基于第三安全参数或第三安全参数与其他相关信息生成,与此同时安全处理基于第三安全参数或第三安全参数与其他相关信息执行。该第三安全参数可以理解为用于更新安全要件和安全处理的信息,由于可以基于第三安全参数更新使用的安全要件和安全处理,从而提高了传输的安全性。
在一些实施例中,第一信息不包括第三安全参数的情况下,所述终端基于以下至少一项生成所述第二安全要件:所述第一安全要件,所述第四派生信息。所述终端基于以下至少一项,对所述第二信息或所述第二信息中的部分内容进行安全处理:所述第一安全要件或所述第二安全要件,第一计算参数。
需要说明的是,在本申请实施例中,所述安全保护包括机密性保护、加密、和完整性保护中的至少一项;所述安全处理包括解密、机密性处理、完整性处理、完整性校验中的至少一项。
可选地,在一些实施例中,所述目标无线信令包括以下至少一项:
至少一个第一标识信息和至少一个第一目标信息;
至少一对第一标识信息与第一目标信息;
其中,第一目标信息与第一标识信息为一到一或多映射;
或者,第一标识信息与第一目标信息为一到零或一映射;
或者,N个第一标识信息与所有第一目标信息存在对应关系,且N小于或等于所述目标无线信令中包含的第一标识信息的数量。
本申请实施例中,第一目标信息与第一标识信息为一到一或多映射可以理解为:第一目标信息可以与第一标识信息存在一到一的映射关系,或者存在一到多的映射关系。例如,所有的第一目标信息与第一标识信息均为一到一映射;或所有的第一目标信息与第一标识信息均为一到多映射;或部分第一目标信息与第一标识信息为一到一映射,部分第一目标信息与第一标识信息为一到多映射。
第一标识信息与第一目标信息为一到零或一映射可以理解为:第一标识信息可以与第一目标信息存在一到一的映射关系,或者存在一到零的映射关系,其中一到零的映射关系表示第一标识信息不存在与之映射的第一目标信息。例如,所有的第一标识信息与第一目标信息均为一到一映射;或部分第一标识信息与第一目标信息为一到一映射,部分第一标识信息与第一目标信息为一到零映射。
可选地,对于N个第一标识信息与所有第一目标信息存在对应关系,在N等于所述目标无线信令包含的第一标识信息的数量的情况下,可以理解为所有的第一标识信息存在映射的第一目标信息;在N小于所述目标无线信令包含的第一标识信息的数量的情况下,可以理解为仅部分第一标识信息存在映射的第一目标信息,部分第一标识信息不存在映射的第一目标信息。其中,第一目标信息与第一标识信息的映射关系可以包括以下至少一项:一到一的映射关系;一到多的映射关系。
可选地,在一些实施例中,所述终端为空闲态或非激活态,或在发送所述第一信息前为空闲态或非激活态,或在接收所述第二信息前为空闲态或非激活态。
本申请实施例中,空闲态包括核心网空闲态和无线空闲态两种情况,核心网空闲态指终端的一种状态,该状态下核心网不能直接发送以该终端为目标的NAS消息(必须先寻呼),或终端不能直接向核心网发送NAS消息(必须先获得相应的发送资源),也可称终端与核心网间无NAS连接,无线空闲态指终端没有资源向基站发送信令建立终端与基站间的无线点对点连接(有终端的专有无线资源来收发信息,包括专有扰码资源,比如无线网络临时标识(Radio Network Temporary Identifier,RNTI);非激活态指终端的一种状态,该状态下终端非核心网空闲态,核心网与基站之间有针对终端的连接或隧道,但终端和基站之间没有无线点对点连接。终端的状态还可以使用其他名称定义,终端和基站之间有其他行为,比如终端和基站之间有无线点对点连接,但核心网不能直接发送以终端为目标的NAS消息,这种状态可能会使用新名称,但仍对应于本申请的空闲态(即核心网空闲态)描述,比如终端非核心网空闲态(可以直接发送以终端为目标的NAS消息),终端和基站之间有无线点对点连接,但核心网和基站之间没有针对终端的连接(比如上行或下行NAS消息基于UE ID标识源或目标,而非基于连接或隧道标识(Tunnel endpoint identifier,TEID)),这种状态可以采用其他名称定义,但仍对应与本申请的非激活态描述。例如,有NAS连接但终端到基站再到核心网之间的连接不完整。
可选地,在本申请实施例中,在终端进入到非激活态后,到接收所述目标无线信令之前,所述终端未向所述接入网系统发送信息。
可选地,在一些实施例中,所述终端接收目标无线信令之前,所述方法还包括:
所述终端向网络侧发送第二算法信息,所述第二算法信息用于指示以下至少一项:所述终端支持的算法、所述终端使用的算法;
其中,所述算法包括安全要件派生算法、机密性算法、和完整性算法中至少一项。
本申请实施例中,所述终端向网络侧发送第二算法信息可以理解为所述终端向核心网节点发送NAS消息,该NAS消息可以包括上述第二算法信息。进一步的,接入网节点转发NAS消息给核心网节点时,可以携带接入网节点支持的算法和接入网节点使用的算法中的至少一项。
可选地,核心网节点接收到第二算法信息后可以向接入网节点指示第一算法信息。
可选地,在一些实施例中,所述第一标识信息指示终端,或者由终端标识生成,或者指示一组终端。
本申请实施例中,在第一标识信息由终端标识生成的情况下,不同终端标识可以生成相同的第一标识信息,例如,一组终端的终端标识可以生成相同的第一标识信息。
可选地,在一些实施例中,所述目标无线信令包括广播信令、寻呼信令、无线短消息、和系统消息中的任一项;
或者,所述目标无线信令通过寻呼信道(Paging Channel,PCH)、多播信道(Multicast Channel,MCH)、广播信道(Broadcast Channel,BCH)和下行共享信道(Downlink Shared Channel,DL-SCH)中的至少一项发送;
或者,所述目标无线信令通过物理下行控制信道(Physical downlink control channel,PDCCH)、物理下行共享信道(Physical downlink shared channel,PDSCH)、物理广播信道(Physical broadcast channel,PBCH)和物理多播信道(Physical Multicast Channel,PMCH)中的至少一项发送。
本申请实施例中,上述目标无线信令可以是通过PCH发送的新格式的paging消息(即包含资源信息和/或数据的paging消息),可以是PCH中发送的信令,该目标无线信令包含传统的paging消息(即不包含资源信息和数据的paging消息),以及资源信息和/或数据,还可以是PCH中发送传统的paging消息,以及通过PDCCH发送资源信息和/或PDSCH发送数据。
可选地,上述无线短消息可以理解为无线信令涉及的短消息(Short Message),并非是短信服务(Short Messaging/Message Service,SMS)中涉及的短消息。
为了更好的理解本申请,以下通过一些示例进行详细说明。
实施例一,在终端处于idle态下,交互的流程如图3所示,具体包括以下步骤:
步骤31,终端向核心网发送NAS消息,接入网节点转发NAS消息给核心网节点时,携带终端支持的算法指示信息(即第二算法信息),也可以进一步携带接入网节点支持的算法指示信息,核心网节点可选地保存终端支持的算法指示信息,或终端和接入网节点支持的算法指示信息。
步骤32,核心网节点向接入网节点发送信息1,例如可以通过Paging消息或激励消息发送。
其中,信息1中包括第一用户标识、安全要件(包括秘钥和密流中的至少一项),该安全要件可以基于终端核心网上下文中的密钥、第一用户标识和第一安全参数中的至少一项生成。可选地,信息1中还可以包括第一安全参数和算法指示中的至少一项,该算法指示用于指示第一算法信息。
可选地,信息1中除第一用户标识以外的其他信息中至少部分信息可以与第一用户标识关联,从而可以携带多个第一用户标识关联的其他信息。当然在其他实施例中,也可以设置信息1中除第一用户标识以外的其他信息中至少部分信息与第一用户标识。
步骤33,接入网节点可以基于信息1执行操作1,该操作1包括加密操作和完保操作中的至少一项。
对于加密操作:使用秘钥或密流对资源信息(如SRB信息、DRB信息、MAC CE调度信息、grant信息等)和其他信元(如目标无线信令中的数据)中的至少一项进行加密(例如使用密钥以及约定或指示的算法加密,或使用密流进行异或操作),资源信息可以包括上行资源信息和下行资源信息中的至少一项;其中,在安全要件包括秘钥的情况下,加密的行为可以基于第一用户标识、第二用户标识、第一安全参数和第二安全参数中的至少一项执行。
其中,第二用户标识可以基于第一用户标识生成,例如第一用户标识是核心网节点分配的用户标识(如TMSI),第二用户标识为接入网节点分配的用户标识(如RNTI),或者第一用户标识是接入网节点分配的用户标识,第二用户标识为核心网节点分配的用户标识。
对于完保操作:在安全要件包括秘钥的情况下,对资源信息、加密的资源信息和其他信元(如目标无线信令中的数据)中的至少一项进行完保操作;例如使用密钥以及约定或指示的算法计算MAC值,可选地,完保操作还可以基于第一安全参数和第二安全参数中的至少一项执行,即计算MAC值是将第一安全参数和第二安全参数中的至少一项作为算法的输入。
可选地,在一些实施例中,在算法指示不支持的情况下,则不执行步骤33以及后续步骤。
步骤34,接入网节点通过空口广播信息2,例如通过Paging消息、系统消息、或激励消息等进行发送。或者在向终端发送的第一条消息中发送信息2。
该信息2包括第一用户标识或第二用户标识以及以下至少一项:加密的资源信息和MAC值。
可选地,上述信息2中除用户标识(第一用户标识或第二用户标识)以外的其他信息可以与用户标识关联,从而可以携带多个用户标识关联的其他信息。当然在其他实施例中,上述信息2中除用户标识以外的其他信息可以与用户标识无关。
可选地,信息2中还可以包括算法指示、第一安全参数和第二安全参数中的至少一项。这些信息中的至少部分可以与用户标识无关或相关。
需要说明的是,上述信息2中除用户标识由承载信息2的消息携带,其他信息可以是在消息中携带,也可以是在承载消息的信令(如RLC层信令、MAC层信令)中携带。
至此,终端和接入网节点之间完成安全激活,后续的消息和数据交互可以进行安全保护。
步骤35,终端生成安全要件(该安全要件包括秘钥或密流中的至少一项,安全要件的生成方式与步骤32相同,在此不再赘述)并执行操作2,操作2包括解密操作和完保校验操作中的至少一项。
对于解密操作,使用密钥或密流对资源信息进行解密(例如使用密钥以及约定或指示的算法解密,或基于密流进行异或操作)。在安全要件包括密钥的情况下,还可以使用接收到的用户标识、基于接收到的用户标识获得的第三用户标识(比如收到RNTI获得TMSI,或反之)、第一安全参数和第二安全参数执行上述解密操作(即解密时还将相关参数作为输入参数)。
对于完保校验操作,在安全要件包括密钥的情况下,对资源信息和/或加密的资源信息进行完保校验(例如使用密钥以及约定或指示的算法计算目标MAC值并与接收到的MAC进行比较),完保校验还可以使用接收到的用户标识、基于接收到的用户标识获得的第三用户标识、第一安全参数1和第二安全参数中的至少一项(即计算目标MAC值的过程中还将相关参数作为输入)。
可选地,在步骤35之后,终端还可以基于终端核心网上行文或接入网上下文中的密钥生成新的安全要件(比如使用相应密钥以及约定的参数和/或接收到的接入网节点发送的信息生成新的安全要件)。终端基于资源信息(比如上行资源信息)向基站发送信令和/或数据,可以基于前述完保校验执行发送信令和/或数据的过程,比如完保校验成功后发送。信令中可以包括以下至少一项:
基于安全要件或新的安全要件中的密钥或密流加密的信令整体或信令中的部分信元(使用密钥以及约定或指示的算法加密,或使用密流进行异或操作);
在安全要件或新的安全要件包括密钥的情况下,对信令整体(明文信令整体)、加密的信令整体、信令中的部分信元(明文信元)、或信令中的部分加密信元进行完保操作后的信息(使用密钥以及约定或指示的算法计算出的MAC值)。
发送数据可以是基于安全要件或新的安全要件中的密钥或密流加密后的数据,也可以是基于安全要件或新的安全要件中的密钥完保后的数据,也可以是基于安全要件或新的安全要件中的密钥加密和完保后的数据。
可选地,在安全要件或新的安全要件包括密钥的情况下,上述加密和/或完保操作还可以基于接收到的用户标识、基于接收到的用户标识获得的第三用户标识、第一安全参数、第二安全参数2和第三安全参数中的至少一项执行。
在使用了安全参数3的情况下,发送的信令或数据可以包括明文的安全参数3(安全参数3作为信令整体的一部分,或数据的一部分,或部分信元中的一个,但不是加密后的信令整体,也不是部分加密信元中的一个)。
可选地,接入网节点可以基于终端接入网上下文中的密钥或从核心网节点收到的安全要件生成新的安全要件(比如使用相应密钥以及约定的参数和/或接入网节点发送给终端的信息生成新的安全要件)。接入网节点基于资源信息(比如上行资源信息)从终端接收信令和/或数据。
可选地,接入网节点对信令执行以下至少一项:
基于安全要件或新的安全要件中的密钥或密流解密信令或信令中的部分信元;
基于安全要件或新的安全要件中的密钥对对信令整体(密文信令整体)、解密的(明文)信令整体、信令中的部分信元(密文信元)、和/或信令中的部分解密信元(明文信元)进行完保校验(使用密钥以及约定或指示的算法计算出的目标MAC值并比较接收到的MAC值);
向核心网节点发送解密后的信令整体或信令中的部分解密信元。
可选地,接入网节点对接收到的数据执行以下至少一项:
基于安全要件或新的安全要件中的密钥或密流解密数据;
基于安全要件或新的安全要件中的密钥对数据进行完保校验;
向核心网节点发送数据或解密后的数据(明文数据)。
可选地,接入网节点可以基于对接收到的信令的完保校验执行上述对数据的操作,比如成功则处理。上述完保校验和/或解密操作还可以基于发送的用户标识、基于发送的用户标识获得的第三用户标识、第一安全参数、第二安全参数和第三安全参数执行(即计算XMAC值的过程中、解密的过程中,还将相应参数作为输入)。
在完成上述操作流程后,接入网节点和终端可以继续执行后续的信令和数据传输流程。
例如,终端基于资源信息向接入网节点发送信令和数据中的至少一项,接入网节点基于上行资源信息接收到的终端发送的信息后,可以向核心网节点上报相关信息。具体的加密操作和完保操作可以参照上述实施例的描述,在此不再赘述。
例如,接入网节点从核心网节点接收到信令或数据,基于下行资源信息向终端发送信令和/或数据,具体的过程可以参照上述实施例,在此不再赘述。
实施例二,在终端处于INACTIVE态下,与实施例一的区别在于:
1、核心网节点与接入网节点之间的数据交互是基于用户面执行的。
2、接入网节点基于终端接入网上下文中的秘钥生成安全要件的情况下,该安全要件中的秘钥就是终端接入网上下文中的秘钥。
3、第一安全参数不参与交互流程,即实施例一中交互过程中的发送的信息、用于生成安全秘钥,执行安全操作、加密操作等信息或行为都不包含第一安全参数。例如,信息2中不包含第一安全参数,不基于第一安全参数生成安全要件等。
参照图4,本申请实施例还提供了一种交互方法,如图4所示,该交互方法包括:
步骤401,接入网节点发送目标无线信令,所述目标无线信令包括第一标识信息以及第一目标信息,所述第一目标信息包括加密信息与完整性保护信息中的至少一项;
其中,所述加密信息和完整性保护信息基于第一安全要件生成,所述第一安全要件包括秘钥和密流中的至少一项。
可选地,所述接入网节点发送目标无线信令之前,所述方法还包括:
所述接入网节点从核心网节点接收第三信息或目标数据;
其中,所述第三信息包括第二标识信息和第二目标信息;
所述第二目标信息包括以下至少一项:
所述第一安全要件或第三安全要件,所述第三安全要件包括秘钥和密流中的至少一项;
第一算法信息;
第二安全参数;
第二安全辅助信息,所述第二安全辅助信息包括终端核心网上下文中的信息;
其中,所述第二标识信息用于指示终端,或由终端标识生成,或指示一组终端,或与所述第一标识信息相关;所述第一算法信息包括以下至少一项:
安全要件派生算法、机密性算法、和完整性算法。
可选地,所述第三信息包括以下至少一项:
至少一个第二标识信息和至少一个第二目标信息;
至少一对第二标识信息与第二目标信息;
其中,所述第二目标信息与所述第二标识信息为一到一或多映射;
或者,所述第二标识信息与所述第二目标信息为一到零或一映射;
或者,K个第二标识信息与所有第二目标信息存在对应关系,且K小于或等于所述第三信息中包含的第二标识信息的数量。
可选地,所述第一目标信息还包括以下至少一项:
第一安全辅助信息,所述第一安全辅助信息包括第一算法信息、第一安全参数、和第二安全参数中的至少一项。
可选地,所述方法包括:
所述接入网节点执行以下至少一项:
基于第二派生信息和安全要件派生算法中的至少一项生成所述第一安全要件;
还基于机密性算法生成所述加密信息;
还基于完整性算法生成所述完整性保护信息;
还基于第一计算参数生成所述加密信息与所述完整性保护信息中的至少一项;
第三操作;
其中,所述第一计算参数包括以下至少一项:
终端接入网上下文中的信息;
所述第一标识信息;
第一安全辅助信息中的至少部分内容;
第二安全辅助信息中的至少部分内容;
其中,所述第二派生信息包括以下至少一项:
接入网相关密钥;
接入层面AS层相关密钥;
终端上下文中的密钥;
第三安全要件;
终端接入网上下文中的信息;
所述第一标识信息;
第一安全辅助信息中的至少部分内容;
第二安全辅助信息中的至少部分内容;
所述第三操作包括以下至少一项:
从终端接收第一信息;
从终端接收携带第三安全参数的第一信息;
向终端发送第二信息;
基于第四派生信息和所述第一安全要件中的至少一项生成第二安全要件,所述第二安全要件包括密钥和密流中的至少一项,所述第四派生信息包括以下至少一项:核心网相关密钥、非接入层面NAS层相关密钥、接入网相关密钥、AS层相关密钥、终端上下文中的密钥、和所述第三安全参数。
可选地,所述方法包括以下至少一项:
所述接入网节点基于以下至少一项,对所述第一信息或所述第一信息中的部分内容进行安全处理:所述第一安全要件或所述第二安全要件,所述第一计算参数,和所述第三安全参数;
所述接入网节点基于以下至少一项,对所述第二信息或所述第二信息中的部分内容进行安全保护:所述第一安全要件或所述第二安全要件,所述第一计算参数,和所述第三安全参数。
可选地,所述安全保护包括机密性保护、加密、和完整性保护中的至少一项;所述安全处理包括解密、机密性处理、完整性处理、完整性校验中的至少一项。
可选地,所述终端为空闲态或非激活态,或在发送所述第一信息前为空闲态或非激活态,或在接收所述第二信息前为空闲态或非激活态。
可选地,所述目标无线信令包括以下至少一项:
至少一个第一标识信息和至少一个第一目标信息;
至少一对第一标识信息与第一目标信息;
其中,第一目标信息与第一标识信息为一到一或多映射;
或者,第一标识信息与第一目标信息为一到零或一映射;
或者,N个第一标识信息与所有第一目标信息存在对应关系,且N小于或等于所述目标无线信令包含的第一标识信息的数量。
可选地,所述第一标识信息指示终端,或者由终端标识生成,或者指示一组终端。
可选地,所述目标无线信令为广播信令、寻呼信令、无线短消息、系统消息中的任一项;
或者,所述目标无线信令通过寻呼信道PCH、多播信道MCH、广播信道BCH和下行共享信道DL-SCH中的至少一项发送;
或者,所述目标无线信令通过物理下行控制信道PDCCH、物理下行共享信道PDSCH、物理广播信道PBCH和物理多播信道PMCH中的至少一项发送。
参照图5,本申请实施例还提供了一种交互方法,如图5所示,该交互方法包括:
步骤501,核心网节点向接入网节点发送第三信息或目标数据,所述第三信息包括第二标识信息和第二目标信息;
其中,所述第二目标信息包括以下至少一项:
第一安全要件或第三安全要件;
第一算法信息;
第二安全参数;
第二安全辅助信息,所述第二安全辅助信息包括终端核心网上下文中的信息;
其中,所述第一算法信息包安全要件派生算法、机密性算法、和完整性算法中的至少一项;所述第一安全要件包括秘钥和密流中的至少一项,所述第三安全要件包括秘钥和密流中的至少一项,所述第二标识信息指示终端,或由终端标识生成,或指示一组终端。
可选地,所述方法还包括:
所述核心网节点基于第三派生信息和所述安全要件派生算法中的至少一项生成所述第一安全要件或所述第三安全要件;
其中,所述第三派生信息包括以下至少一项:核心网相关密钥、NAS层相关密钥、终端上下文中的密钥、所述第一算法信息、所述第二安全参数、和所述第二安全辅助信息中的至少部分内容。
可选地,所述第三信息包括以下至少一项:
至少一个第二标识信息和至少一个第二目标信息;
至少一对第二标识信息与第二目标信息;
其中,所述第二目标信息与所述第二标识信息为一到一或多映射;
或者,所述第二标识信息与所述第二目标信息为一到零或一映射;
或者,K个第二标识信息与所有第二目标信息存在对应关系,且K小于或等于第二标识信息的数量。
可选地,所述方法还包括:
所述核心网节点从所述终端接收第二算法信息,所述第二算法信息用于指示以下至少一项:所述终端支持的算法、所述终端使用的算法;
其中,所述第一算法信息基于所述第二算法信息生成。
参照图6,本申请实施例还提供了一种交互方法,如图6所示,该交互方法包括:
步骤601,接入网节点发送目标无线信令,所述目标无线信令包括第一标识信息以及第一目标信息,所述第一目标信息包括加密信息与完整性保护信息中的至少一项,其中,所述加密信息和完整性保护信息基于第一安全要件生成;
步骤602,终端接收所述目标无线信令;
步骤603,在所述终端与所述第一标识信息相关的情况下,所述终端执行以下至少一项:
基于第一安全要件执行第一操作;
第二操作;
其中,所述第一操作包括以下至少一项:
解密所述加密信息;
对所述加密信息进行机密性处理;
对所述第一目标信息进行机密性处理;
校验或验证所述完整性保护信息;
对所述第一目标信息进行安全处理;
对所述第一目标信息进行完整性校验或完整性处理;
基于所述完整性保护信息,对以下至少一项进行完整性校验或完整性处理:所述第一目标信息、所述第一目标信息中的部分内容、和所述解密的结果;
其中,所述第二操作包括以下至少一项:
基于第四派生信息和所述第一安全要件中的至少一项生成第二安全要件;
向接入网节点发送第一信息;
向接入网节点发送携带第三安全参数的第一信息;
从接入网节点接收第二信息;
其中,所述第一安全要件基于第一派生信息生成,所述第一安全要件包括秘钥和密流中的至少一项;所述第一派生信息包括以下至少一项:核心网相关密钥、非接入层面NAS层相关密钥、接入网相关密钥、接入层面AS层相关密钥、终端上下文中的密钥、终端核心网上下文中的信息、第一标识信息、和终端接入网上下文中的信息;所述第四派生信息包括以下至少一项:核心网相关密钥、非接入层面NAS层相关密钥、接入网相关密钥、接入层面AS层相关密钥、终端上下文中的密钥、终端核心网上下文中的信息、第一标识信息、终端接入网上下文中的信息、和所述第三安全参数;所述第二安全要件包括密钥和密流中的至少一项。
可选地,所述方法还包括:
核心网节点向接入网节点发送第三信息或目标数据,所述第三信息包括第二标识信息和第二目标信息;
所述接入网节点基于所述第二目标信息获知或生成所述第一安全要件,并基于所述第三信息发送所述目标无线信令;
其中,所述第二目标信息包括以下至少一项:所述第一安全要件或第三安全要件、第一算法信息、第二安全参数、和第二安全辅助信息;所述第一算法信息包安全要件派生算法、机密性算法、和完整性算法中的至少一项;
其中,所述第二安全辅助信息包括终端核心网上下文中的信息,所述第三安全要件包括秘钥和密流中的至少一项,所述第二标识信息指示终端,或由终端标识生成,或指示一组终端,或与所述第一标识信息相关。
可选地,所述接入网节点基于所述第二目标信息生成所述第一安全要件包括:
所述接入网节点基于第二派生信息和所述安全要件派生算法中的至少一项生成所述第一安全要件;
其中,所述第二派生信息包括以下至少一项:接入网相关密钥、AS层相关密钥、终端上下文中的密钥、所述第一安全辅助信息中的至少部分内容、所述第二安全辅助信息中的至少部分内容、第一标识信息、和终端接入网上下文中的信息。
可选地,所述方法还包括:
所述核心网节点基于第三派生信息和所述安全要件派生算法中的至少一项生成所述第一安全要件或所述第三安全要件;
其中,所述第三派生信息包括以下至少一项:核心网相关密钥、NAS层相关密钥、终端上下文中的密钥、所述第二安全参数、和所述第二安全辅助信息中的至少部分内容。
可选地,所述目标无线信令包括第一安全辅助信息;
和/或,所述第一派生信息包括第一安全辅助信息中的至少部分内容;
其中,所述第一安全辅助信息包括第一算法信息、第一安全参数、和第二安全参数中的至少一项。
本申请实施例中,上述终端还可以执行上述图2实施例中终端的各个步骤,上述接入网节点还可以执行上述图4实施例中接入网节点的各个步骤,核心网节点还可以执行上述图5中核心网节点执行的各个步骤,详情可参照上述实施例的描述,为了避免重复在此不再赘述。
本申请实施例提供的交互方法,执行主体可以为交互装置或交互系统。本申请实施例中以交互装置执行交互方法的方法为例,说明本申请实施例提供的交互装置和交互系统。
参照图7,本申请实施例还提供了一种交互装置,如图7所示,该交互装置700包括:
第一接收模块701,用于接收目标无线信令,所述目标无线信令包括第一标识信息以及第一目标信息,所述第一目标信息包括加密信息与完整性保护信息中的至少一项;
第一执行模块702,用于执行以下至少一项:
基于第一安全要件执行第一操作;
第二操作;
其中,所述第一操作包括以下至少一项:
解密所述加密信息;
对所述加密信息进行机密性处理;
对所述第一目标信息进行机密性处理;
校验或验证所述完整性保护信息;
对所述第一目标信息进行安全处理;
对所述第一目标信息进行完整性校验或完整性处理;
基于所述完整性保护信息,对以下至少一项进行完整性校验或完整性处理:所述第一目标信息、所述第一目标信息中的部分内容、和所述解密的结果;
其中,所述第二操作包括以下至少一项:
基于第四派生信息和所述第一安全要件中的至少一项生成第二安全要件;
向接入网节点发送第一信息;
从接入网节点接收第二信息;
其中,所述第一安全要件基于第一派生信息生成,所述第一安全要件包括密钥和密流中的至少一项;所述第一派生信息和所述第四派生信息包括以下至少一项:核心网相关密钥、非接入层面NAS层相关密钥、接入网相关密钥、接入层面AS层相关密钥、和终端上下文中的密钥;所述第二安全要件包括密钥和密流中的至少一项。
可选地,所述第一目标信息还包括第一安全辅助信息;
其中,所述第一安全辅助信息包括第一算法信息、第一安全参数、和第二安全参数中的至少一项;
所述第一算法信息包括以下至少一项:
安全要件派生算法,所述第一安全要件还基于所述安全要件派生算法生成;
机密性算法和完整性算法中至少一项,所述第一操作还基于所述机密性算法和完整性算法中至少一项执行。
可选地,所述第一派生信息还包括以下至少一项:
第一安全辅助信息中的至少部分内容;
终端核心网上下文中的信息;
终端接入网上下文中的信息;
所述第一标识信息。
可选地,所述第一执行模块702具体用于基于所述第一安全要件以及第一计算参数执行所述第一操作,所述第一计算参数包括以下至少一项:
终端核心网上下文中的信息;
终端接入网上下文中的信息;
所述第一标识信息;
第一安全辅助信息中的至少部分内容。
可选地,所述终端核心网上下文中的信息,包括以下至少一项:
终端的标识信息;
终端的组标识信息;
NAS信令的计数信息;
NAS上行信令的计数信息;
NAS下信令的计数信息;
通过NAS传输的协议数据报文的计数信息;
通过NAS传输的上行协议数据报文的计数信息;
通过NAS传输的下行协议数据报文的计数信息;
或,所述终端接入网上下文中的信息,包括以下至少一项:
终端的标识信息;
终端的组标识信息;
AS信令的计数信息;
AS上行信令的计数信息;
AS下行信令的计数信息;
协议数据报文的计数信息;
上行协议数据报文的计数信息;
下行协议数据报文的计数信息。
可选地,所述第一执行模块702还用于执行以下至少一项:
基于以下至少一项,对所述第一信息或所述第一信息中的部分内容进行安全保护:所述第一安全要件或所述第二安全要件,第一计算参数,和所述第三安全参数;
基于以下至少一项,对所述第二信息或所述第二信息中的部分内容进行安全处理:所述第一安全要件或所述第二安全要件,第一计算参数,和所述第三安全参数。
可选地,所述安全保护包括机密性保护、加密、和完整性保护中的至少一项;所述安全处理包括解密、机密性处理、完整性处理、完整性校验中的至少一项。
可选地,所述目标无线信令包括以下至少一项:
至少一个第一标识信息和至少一个第一目标信息;
至少一对第一标识信息与第一目标信息;
其中,第一目标信息与第一标识信息为一到一或多映射;
或者,第一标识信息与第一目标信息为一到零或一映射;
或者,N个第一标识信息与所有第一目标信息存在对应关系,且N小于或等于所述目标无线信令中包含的第一标识信息的数量。
可选地,所述终端为空闲态或非激活态,或在发送所述第一信息前为空闲态或非激活态,或在接收所述第二信息前为空闲态或非激活态。
可选地,所述第一执行模块702还用于:向网络侧发送第二算法信息,所述第二算法信息用于指示以下至少一项:所述终端支持的算法、所述终端使用的算法;
其中,所述算法包括安全要件派生算法、机密性算法、和完整性算法中至少一项。
可选地,所述第一标识信息指示终端,或者由终端标识生成,或者指示一组终端。
可选地,所述目标无线信令包括广播信令、寻呼信令、无线短消息、和系统消息中的任一项;
或者,所述目标无线信令通过寻呼信道PCH、多播信道MCH、广播信道BCH和下行共享信道DL-SCH中的至少一项发送;
或者,所述目标无线信令通过物理下行控制信道PDCCH、物理下行共享信道PDSCH、物理广播信道PBCH和物理多播信道PMCH中的至少一项发送。
参照图8,本申请实施例还提供了一种交互装置,如图8所示,该交互装置800包括:
第一发送模块801,用于发送目标无线信令,所述目标无线信令包括第一标识信息以及第一目标信息,所述第一目标信息包括加密信息与完整性保护信息中的至少一项;
其中,所述加密信息和完整性保护信息基于第一安全要件生成,所述第一安全要件包括秘钥和密流中的至少一项。
可选地,所述交互装置还包括:
第二接收模块,用于从核心网节点接收第三信息或目标数据;
其中,所述第三信息包括第二标识信息和第二目标信息;
所述第二目标信息包括以下至少一项:
所述第一安全要件或第三安全要件,所述第三安全要件包括秘钥和密流中的至少一项;
第一算法信息;
第二安全参数;
第二安全辅助信息,所述第二安全辅助信息包括终端核心网上下文中的信息;
其中,所述第二标识信息用于指示终端,或由终端标识生成,或指示一组终端,或与所述第一标识信息相关;所述第一算法信息包括以下至少一项:
安全要件派生算法、机密性算法、和完整性算法。
可选地,所述第三信息包括以下至少一项:
至少一个第二标识信息和至少一个第二目标信息;
至少一对第二标识信息与第二目标信息;
其中,所述第二目标信息与所述第二标识信息为一到一或多映射;
或者,所述第二标识信息与所述第二目标信息为一到零或一映射;
或者,K个第二标识信息与所有第二目标信息存在对应关系,且K小于或等于所述第三信息中包含的第二标识信息的数量。
可选地,所述第一目标信息还包括以下至少一项:
第一安全辅助信息,所述第一安全辅助信息包括第一算法信息、第一安全参数、和第二安全参数中的至少一项。
可选地,所述交互装置800还包括:
第二执行模块,用于执行以下至少一项:
基于第二派生信息和安全要件派生算法中的至少一项生成所述第一安全要件;
还基于机密性算法生成所述加密信息;
还基于完整性算法生成所述完整性保护信息;
还基于第一计算参数生成所述加密信息与所述完整性保护信息中的至少一项;
第三操作;
其中,所述第一计算参数包括以下至少一项:
终端接入网上下文中的信息;
所述第一标识信息;
第一安全辅助信息中的至少部分内容;
第二安全辅助信息中的至少部分内容;
其中,所述第二派生信息包括以下至少一项:
接入网相关密钥;
接入层面AS层相关密钥;
终端上下文中的密钥;
第三安全要件;
终端接入网上下文中的信息;
所述第一标识信息;
第一安全辅助信息中的至少部分内容;
第二安全辅助信息中的至少部分内容;
所述第三操作包括以下至少一项:
从终端接收第一信息;
从终端接收携带第三安全参数的第一信息;
向终端发送第二信息;
基于第四派生信息和所述第一安全要件中的至少一项生成第二安全要件,所述第二安全要件包括密钥和密流中的至少一项,所述第四派生信息包括以下至少一项:核心网相关密钥、非接入层面NAS层相关密钥、接入网相关密钥、AS层相关密钥、终端上下文中的密钥、和所述第三安全参数。
可选地,所述第二执行模块还用于执行以下至少一项:
基于以下至少一项,对所述第一信息或所述第一信息中的部分内容进行安全处理:所述第一安全要件或所述第二安全要件,所述第一计算参数,和所述第三安全参数;
基于以下至少一项,对所述第二信息或所述第二信息中的部分内容进行安全保护:所述第一安全要件或所述第二安全要件,所述第一计算参数,和所述第三安全参数。
可选地,所述安全保护包括机密性保护、加密、和完整性保护中的至少一项;所述安全处理包括解密、机密性处理、完整性处理、完整性校验中的至少一项。
可选地,所述终端为空闲态或非激活态,或在发送所述第一信息前为空闲态或非激活态,或在接收所述第二信息前为空闲态或非激活态。
可选地,所述目标无线信令包括以下至少一项:
至少一个第一标识信息和至少一个第一目标信息;
至少一对第一标识信息与第一目标信息;
其中,第一目标信息与第一标识信息为一到一或多映射;
或者,第一标识信息与第一目标信息为一到零或一映射;
或者,N个第一标识信息与所有第一目标信息存在对应关系,且N小于或等于所述目标无线信令包含的第一标识信息的数量。
可选地,所述第一标识信息指示终端,或者由终端标识生成,或者指示一组终端。
可选地,所述目标无线信令为广播信令、寻呼信令、无线短消息、系统消息中的任一项;
或者,所述目标无线信令通过寻呼信道PCH、多播信道MCH、广播信道BCH和下行共享信道DL-SCH中的至少一项发送;
或者,所述目标无线信令通过物理下行控制信道PDCCH、物理下行共享信道PDSCH、物理广播信道PBCH和物理多播信道PMCH中的至少一项发送。
参照图9,本申请实施例还提供了一种交互装置,如图9所示,该交互装置900包括:
第二发送模块901,用于向接入网节点发送第三信息或目标数据,所述第三信息包括第二标识信息和第二目标信息;
其中,所述第二目标信息包括以下至少一项:
第一安全要件或第三安全要件;
第一算法信息;
第二安全参数;
第二安全辅助信息,所述第二安全辅助信息包括终端核心网上下文中的信息;
其中,所述第一算法信息包安全要件派生算法、机密性算法、和完整性算法中的至少一项;所述第一安全要件包括秘钥和密流中的至少一项,所述第三安全要件包括秘钥和密流中的至少一项,所述第二标识信息指示终端。
可选地,所述交互装置900还包括:
第三执行模块,用于基于第三派生信息和所述安全要件派生算法中的至少一项生成所述第一安全要件或所述第三安全要件;
其中,所述第三派生信息包括以下至少一项:核心网相关密钥、NAS层相关密钥、终端上下文中的密钥、所述第一算法信息、所述第二安全参数、和所述第二安全辅助信息中的至少部分内容。
可选地,所述第三信息包括以下至少一项:
至少一个第二标识信息和至少一个第二目标信息;
至少一对第二标识信息与第二目标信息;
其中,所述第二目标信息与所述第二标识信息为一到一或多映射;
或者,所述第二标识信息与所述第二目标信息为一到零或一映射;
或者,K个第二标识信息与所有第二目标信息存在对应关系,且K小于或等于第二标识信息的数量。
可选地,所述交互装置900还包括:
第三接收模块,用于从所述终端接收第二算法信息,所述第二算法信息用于指示以下至少一项:所述终端支持的算法、所述终端使用的算法;
其中,所述第一算法信息基于所述第二算法信息生成。
本申请实施例中的交互装置可以是电子设备,例如具有操作系统的电子设备,也可以是电子设备中的部件,例如集成电路或芯片。该电子设备可以是终端,也可以为除终端之外的其他设备。示例性的,终端可以包括但不限于上述所列举的终端11的类型,其他设备可以为服务器、网络附属存储器(Network Attached Storage,NAS)等,本申请实施例不作具体限定。
本申请实施例提供的交互装置能够实现图2至图5的方法实施例实现的各个过程,并达到相同的技术效果,为避免重复,这里不再赘述。
本申请实施例还提供了一种交互系统,该交互系统包括:接入网节点和终端,其中,
所述接入网节点用于发送目标无线信令,所述目标无线信令包括第一标识信息以及第一目标信息,所述第一目标信息包括加密信息与完整性保护信息中的至少一项,其中,所述加密信息和完整性保护信息基于第一安全要件生成;
所述终端用于接收所述目标无线信令;并在所述终端与所述第一标识信息相关的情况下,执行以下至少一项:
基于第一安全要件执行第一操作;
第二操作;
其中,所述第一操作包括以下至少一项:
解密所述加密信息;
对所述加密信息进行机密性处理;
对所述第一目标信息进行机密性处理;
校验或验证所述完整性保护信息;
对所述第一目标信息进行安全处理;
对所述第一目标信息进行完整性校验或完整性处理;
基于所述完整性保护信息,对以下至少一项进行完整性校验或完整性处理:所述第一目标信息、所述第一目标信息中的部分内容、和所述解密的结果;
其中,所述第二操作包括以下至少一项:
基于第四派生信息和所述第一安全要件中的至少一项生成第二安全要件;
向接入网节点发送第一信息;
从接入网节点接收第二信息;
其中,所述第一安全要件基于第一派生信息生成,所述第一安全要件包括秘钥和密流中的至少一项;所述第一派生信息和所述第四派生信息包括以下至少一项:核心网相关密钥、非接入层面NAS层相关密钥、接入网相关密钥、接入层面AS层相关密钥、终端上下文中的密钥、终端核心网上下文中的信息、第一标识信息、和终端接入网上下文中的信息;所述第二安全要件包括密钥和密流中的至少一项。
可选地,所述交互系统还包括核心网节点,所述核心网节点用于向接入网节点发送第三信息或目标数据,所述第三信息包括第二标识信息和第二目标信息;
所述接入网节点基于所述第二目标信息获知或生成所述第一安全要件,并基于所述第三信息发送所述目标无线信令;
其中,所述第二目标信息包括以下至少一项:所述第一安全要件或第三安全要件、第一算法信息、第二安全参数、和第二安全辅助信息;所述第一算法信息包安全要件派生算法、机密性算法、和完整性算法中的至少一项;
其中,所述第二安全辅助信息包括终端核心网上下文中的信息,所述第三安全要件包括秘钥和密流中的至少一项,所述第二标识信息指示终端,或由终端标识生成,或指示一组终端,或与所述第一标识信息相关。
可选地,所述接入网节点具体用于基于第二派生信息和所述安全要件派生算法中的至少一项生成所述第一安全要件;
其中,所述第二派生信息包括以下至少一项:接入网相关密钥、AS层相关密钥、终端上下文中的密钥、所述第一安全辅助信息中的至少部分内容、所述第二安全辅助信息中的至少部分内容、第一标识信息、和终端接入网上下文中的信息。
可选地,所述核心网节点还用于基于第三派生信息和所述安全要件派生算法中的至少一项生成所述第一安全要件或所述第三安全要件;
其中,所述第三派生信息包括以下至少一项:核心网相关密钥、NAS层相关密钥、终端上下文中的密钥、所述第二安全参数、和所述第二安全辅助信息中的至少部分内容。
可选地,所述目标无线信令包括第一安全辅助信息;
和/或,所述第一派生信息包括第一安全辅助信息中的至少部分内容;
其中,所述第一安全辅助信息包括第一算法信息、第一安全参数、和第二安全参数中的至少一项。
需要说明的是,上述对交互系统的说明仅仅是部分举例,交互系统可以包括前述各个实施例中的终端、接入网节点以及核心网节点中的至少两项。
如图10所示,本申请实施例还提供一种通信设备1000,包括处理器1001和存储器1002,存储器1002上存储有可在所述处理器1001上运行的程序或指令,该程序或指令被处理器1001执行时实现上述交互方法实施例的各个步骤,且能达到相同的技术效果,为避免重复,这里不再赘述。
本申请实施例还提供一种终端,包括处理器和通信接口,所述通信接口和所述处理器耦合,所述处理器用于运行程序或指令,实现如图2所示方法实施例中的步骤。该终端实施例与上述终端侧方法实施例对应,上述方法实施例的各个实施过程和实现方式均可适用于该终端实施例中,且能达到相同的技术效果。具体地,图11为实现本申请实施例的一种终端的硬件结构示意图。
该终端1100包括但不限于:射频单元1101、网络模块1102、音频输出单元1103、输入单元1104、传感器1105、显示单元1106、用户输入单元1107、接口单元1108、存储器1109以及处理器1110等中的至少部分部件。
本领域技术人员可以理解,终端1100还可以包括给各个部件供电的电源(比如电池),电源可以通过电源管理系统与处理器1110逻辑相连,从而通过电源管理系统实现管理充电、放电以及功耗管理等功能。图11中示出的终端结构并不构成对终端的限定,终端可以包括比图示更多或更少的部件,或者组合某些部件,或者不同的部件布置,在此不再赘述。
应理解的是,本申请实施例中,输入单元1104可以包括图形处理单元(Graphics Processing Unit,GPU)11041和麦克风11042,图形处理器11041对在视频捕获模式或图像捕获模式中由图像捕获装置(如摄像头)获得的静态图片或视频的图像数据进行处理。显示单元1106可包括显示面板11061,可以采用液晶显示器、有机发光二极管等形式来配置显示面板11061。用户输入单元1107包括触控面板11071以及其他输入设备11072中的至少一种。触控面板11071,也称为触摸屏。触控面板11071可包括触摸检测装置和触摸控制器两个部分。其他输入设备11072可以包括但不限于物理键盘、功能键(比如音量控制按键、开关按键等)、轨迹球、鼠标、操作杆,在此不再赘述。
本申请实施例中,射频单元1101接收来自网络侧设备的下行数据后,可以传输给处理器1110进行处理;另外,射频单元1101可以向网络侧设备发送上行数据。通常,射频单元1101包括但不限于天线、放大器、收发信机、耦合器、低噪声放大器、双工器等。
存储器1109可用于存储软件程序或指令以及各种数据。存储器1109可主要包括存储程序或指令的第一存储区和存储数据的第二存储区,其中,第一存储区可存储操作系统、至少一个功能所需的应用程序或指令(比如声音播放功能、图像播放功能等)等。此外,存储器1109可以包括易失性存储器或非易失性存储器。其中,非易失性存储器可以是只读存储器(Read-Only Memory,ROM)、可编程只读存储器(Programmable ROM,PROM)、可擦除可编程只读存储器(Erasable PROM,EPROM)、电可擦除可编程只读存储器(Electrically EPROM,EEPROM)或闪存。易失性存储器可以是随机存取存储器(Random Access Memory,RAM),静态随机存取存储器(Static RAM,SRAM)、动态随机存取存储器(Dynamic RAM,DRAM)、同步动态随机存取存储器(Synchronous DRAM,SDRAM)、双倍数据速率同步动态随机存取存储器(Double Data Rate SDRAM,DDRSDRAM)、增强型同步动态随机存取存储器(Enhanced SDRAM,ESDRAM)、同步连接动态随机存取存储器(Synch link DRAM,SLDRAM)和直接内存总线随机存取存储器(Direct Rambus RAM,DRRAM)。本申请实施例中的存储器1109包括但不限于这些和任意其它适合类型的存储器。
处理器1110可包括一个或多个处理单元;可选的,处理器1110集成应用处理器和调制解调处理器,其中,应用处理器主要处理涉及操作系统、用户界面和应用程序等的操作,调制解调处理器主要处理无线通信信号,如基带处理器。可以理解的是,上述调制解调处理器也可以不集成到处理器1110中。
其中,射频单元1101,用于接收目标无线信令,所述目标无线信令包括第一标识信息以及第一目标信息,所述第一目标信息包括加密信息与完整性保护信息中的至少一项;
在终端与所述第一标识信息相关的情况下,执行以下至少一项:
基于第一安全要件执行第一操作;
第二操作;
其中,所述第一操作包括以下至少一项:
解密所述加密信息;
对所述加密信息进行机密性处理;
对所述第一目标信息进行机密性处理;
校验或验证所述完整性保护信息;
对所述第一目标信息进行安全处理;
对所述第一目标信息进行完整性校验或完整性处理;
基于所述完整性保护信息,对以下至少一项进行完整性校验或完整性处理:所述第一目标信息、所述第一目标信息中的部分内容、和所述解密的结果;
其中,所述第二操作包括以下至少一项:
基于第四派生信息和所述第一安全要件中的至少一项生成第二安全要件;
向接入网节点发送第一信息;
向接入网节点发送携带第三安全参数的第一信息;
从接入网节点接收第二信息;
其中,所述第一安全要件基于第一派生信息生成,所述第一安全要件包括密钥和密流中的至少一项;所述第一派生信息包括以下至少一项:核心网相关密钥、非接入层面NAS层相关密钥、接入网相关密钥、接入层面AS层相关密钥、和终端上下文中的密钥;所述第四派生信息包括以下至少一项:核心网相关密钥、非接入层面NAS层相关密钥、接入网相关密钥、接入层面AS层相关密钥、终端上下文中的密钥、和所述第三安全参数;所述第二安全要件包括密钥和密流中的至少一项。可以理解,本实施例中提及的各实现方式的实现过程可以参照终端侧方法实施例的相关描述,并达到相同或相应的技术效果,为避免重复,在此不再赘述。
本申请实施例还提供一种网络侧设备,包括处理器和通信接口,所述通信接口和所述处理器耦合,所述处理器用于运行程序或指令,实现如图4所示的方法实施例的步骤。该网络侧设备实施例与上述网络侧设备方法实施例对应,上述方法实施例的各个实施过程和实现方式均可适用于该网络侧设备实施例中,且能达到相同的技术效果。
具体地,本申请实施例还提供了一种网络侧设备。如图12所示,该网络侧设备1200包括:天线1201、射频装置1202、基带装置1203、处理器1204和存储器1205。天线1201与射频装置1202连接。在上行方向上,射频装置1202通过天线1201接收信息,将接收的信息发送给基带装置1203进行处理。在下行方向上,基带装置1203对要发送的信息进行处理,并发送给射频装置1202,射频装置1202对收到的信息进行处理后经过天线1201发送出去。
以上实施例中网络侧设备执行的方法可以在基带装置1203中实现,该基带装置1203包括基带处理器。
基带装置1203例如可以包括至少一个基带板,该基带板上设置有多个芯片,如图12所示,其中一个芯片例如为基带处理器,通过总线接口与存储器1205连接,以调用存储器1205中的程序,执行以上方法实施例中所示的网络侧设备操作。
该网络侧设备还可以包括网络接口1206,该接口例如为通用公共无线接口(Common Public Radio Interface,CPRI)。
具体地,本申请实施例的网络侧设备1200还包括:存储在存储器1205上并可在处理器1204上运行的指令或程序,处理器1204调用存储器1205中的指令或程序执行图8所示各模块执行的方法,并达到相同的技术效果,为避免重复,故不在此赘述。
具体地,本申请实施例还提供了一种网络侧设备。如图13所示,该网络侧设备1300包括:处理器1301、网络接口1302和存储器1303。其中,网络接口1302例如为通用公共无线接口(common public radio interface,CPRI)。
具体地,本申请实施例的网络侧设备1300还包括:存储在存储器1303上并可在处理器1301上运行的指令或程序,处理器1301调用存储器1303中的指令或程序执行图9所示各模块执行的方法,并达到相同的技术效果,为避免重复,故不在此赘述。
本申请实施例还提供一种可读存储介质,所述可读存储介质上存储有程序或指令,该程序或指令被处理器执行时实现上述交互方法实施例的各个过程,且能达到相同的技术效果,为避免重复,这里不再赘述。
其中,所述处理器为上述实施例中所述的终端中的处理器。所述可读存储介质,包括计算机可读存储介质,如计算机只读存储器ROM、随机存取存储器RAM、磁碟或者光盘等。在一些示例中,可读存储介质可以是非瞬态的可读存储介质。
本申请实施例另提供了一种芯片,所述芯片包括处理器和通信接口,所述通信接口和所述处理器耦合,所述处理器用于运行程序或指令,实现上述交互方法实施例的各个过程,且能达到相同的技术效果,为避免重复,这里不再赘述。
应理解,本申请实施例提到的芯片还可以称为系统级芯片,系统芯片,芯片系统或片上系统芯片等。
本申请实施例另提供了一种计算机程序/程序产品,所述计算机程序/程序产品被存储在存储介质中,所述计算机程序/程序产品被至少一个处理器执行以实现上述交互方法实施例的各个过程,且能达到相同的技术效果,为避免重复,这里不再赘述。
本申请实施例还提供了一种无线通信系统,包括:终端及网络侧设备,所述终端可用于执行如上所述终端侧的交互方法的步骤,所述网络侧设备可用于执行如上所述接入网节点和核心网节点的交互方法的步骤。
需要说明的是,在本文中,术语“包括”、“包含”或者其任何其他变体意在涵盖非排他性的包含,从而使得包括一系列要素的过程、方法、物品或者装置不仅包括那些要素,而且还包括没有明确列出的其他要素,或者是还包括为这种过程、方法、物品或者装置所固有的要素。在没有更多限制的情况下,由语句“包括一个……”限定的要素,并不排除在包括该要素的过程、方法、物品或者装置中还存在另外的相同要素。此外,需要指出的是,本申请实施方式中的方法和装置的范围不限按示出或讨论的顺序来执行功能,还可包括根据所涉及的功能按基本同时的方式或按相反的顺序来执行功能,例如,可以按不同于所描述的次序来执行所描述的方法,并且还可以添加、省去、或组合各种步骤。另外,参照某些示例所描述的特征可在其他示例中被组合。
通过以上的实施方式的描述,本领域的技术人员可以清楚地了解到上述实施例方法可借助计算机软件产品加必需的通用硬件平台的方式来实现,当然也可以通过硬件。该计算机软件产品存储在存储介质(如ROM、RAM、磁碟、光盘等)中,包括若干指令,用以使得终端或者网络侧设备执行本申请各个实施例所述的方法。
上面结合附图对本申请的实施例进行了描述,但是本申请并不局限于上述的具体实施方式,上述的具体实施方式仅仅是示意性的,而不是限制性的,本领域的普通技术人员在本申请的启示下,在不脱离本申请宗旨和权利要求所保护的范围情况下,还可做出很多形式的实施方式,这些实施方式均属于本申请的保护之内。
Claims (47)
- 一种交互方法,其中,包括:终端接收目标无线信令,所述目标无线信令包括第一标识信息以及第一目标信息,所述第一目标信息包括加密信息与完整性保护信息中的至少一项;在所述终端与所述第一标识信息相关的情况下,所述终端执行以下至少一项:基于第一安全要件执行第一操作;第二操作;其中,所述第一操作包括以下至少一项:解密所述加密信息;对所述加密信息进行机密性处理;对所述第一目标信息进行机密性处理;校验或验证所述完整性保护信息;对所述第一目标信息进行安全处理;对所述第一目标信息进行完整性校验或完整性处理;基于所述完整性保护信息,对以下至少一项进行完整性校验或完整性处理:所述第一目标信息、所述第一目标信息中的部分内容、和所述解密的结果;其中,所述第二操作包括以下至少一项:基于第四派生信息和所述第一安全要件中的至少一项生成第二安全要件;向接入网节点发送第一信息;向接入网节点发送携带第三安全参数的第一信息;从接入网节点接收第二信息;其中,所述第一安全要件基于第一派生信息生成,所述第一安全要件包括密钥和密流中的至少一项;所述第一派生信息包括以下至少一项:核心网相关密钥、非接入层面NAS层相关密钥、接入网相关密钥、接入层面AS层相关密钥、和终端上下文中的密钥;所述第四派生信息包括以下至少一项:核心网相关密钥、非接入层面NAS层相关密钥、接入网相关密钥、接入层面AS层相关密钥、终端上下文中的密钥、和所述第三安全参数;所述第二安全要件包括密钥和密流中的至少一项。
- 根据权利要求1所述的方法,其中,所述第一目标信息还包括第一安全辅助信息;其中,所述第一安全辅助信息包括第一算法信息、第一安全参数、和第二安全参数中的至少一项;所述第一算法信息包括以下至少一项:安全要件派生算法,所述第一安全要件还基于所述安全要件派生算法生成;机密性算法和完整性算法中至少一项,所述第一操作还基于所述机密性算法和完整性算法中至少一项执行。
- 根据权利要求1或2所述的方法,其中,所述第一派生信息还包括以下至少一项:第一安全辅助信息中的至少部分内容;终端核心网上下文中的信息;终端接入网上下文中的信息;所述第一标识信息。
- 根据权利要求1至3任一项所述的方法,其中,所述终端基于第一安全要件执行第一操作,包括:所述终端基于所述第一安全要件以及第一计算参数执行所述第一操作,所述第一计算参数包括以下至少一项:终端核心网上下文中的信息;终端接入网上下文中的信息;所述第一标识信息;第一安全辅助信息中的至少部分内容。
- 根据权利要求3或4所述的方法,其中,所述终端核心网上下文中的信息,包括以下至少一项:终端的标识信息;终端的组标识信息;NAS信令的计数信息;NAS上行信令的计数信息;NAS下信令的计数信息;通过NAS传输的协议数据报文的计数信息;通过NAS传输的上行协议数据报文的计数信息;通过NAS传输的下行协议数据报文的计数信息;或,所述终端接入网上下文中的信息,包括以下至少一项:终端的标识信息;终端的组标识信息;AS信令的计数信息;AS上行信令的计数信息;AS下行信令的计数信息;协议数据报文的计数信息;上行协议数据报文的计数信息;下行协议数据报文的计数信息。
- 根据权利要求1至5中任一项所述的方法,其中,所述方法包括以下至少一项:所述终端基于以下至少一项,对所述第一信息或所述第一信息中的部分内容进行安全保护:所述第一安全要件或所述第二安全要件,第一计算参数,和所述第三安全参数;所述终端基于以下至少一项,对所述第二信息或所述第二信息中的部分内容进行安全处理:所述第一安全要件或所述第二安全要件,第一计算参数,和所述第三安全参数。
- 根据权利要求6所述的方法,其中,所述安全保护包括机密性保护、加密、和完整性保护中的至少一项;所述安全处理包括解密、机密性处理、完整性处理、完整性校验中的至少一项。
- 根据权利要求1至7中任一项所述的方法,其中,所述目标无线信令包括以下至少一项:至少一个第一标识信息和至少一个第一目标信息;至少一对第一标识信息与第一目标信息;其中,第一目标信息与第一标识信息为一到一或多映射;或者,第一标识信息与第一目标信息为一到零或一映射;或者,N个第一标识信息与所有第一目标信息存在对应关系,且N小于或等于所述目标无线信令中包含的第一标识信息的数量。
- 根据权利要求1至8中任一项所述的方法,其中,所述终端为空闲态或非激活态,或在发送所述第一信息前为空闲态或非激活态,或在接收所述第二信息前为空闲态或非激活态。
- 根据权利要求1至9中任一项所述的方法,其中,所述终端接收目标无线信令之前,所述方法还包括:所述终端向网络侧发送第二算法信息,所述第二算法信息用于指示以下至少一项:所述终端支持的算法、所述终端使用的算法;其中,所述算法包括安全要件派生算法、机密性算法、和完整性算法中至少一项。
- 根据权利要求1至10任一项所述的方法,其中,所述第一标识信息指示终端,或者由终端标识生成,或者指示一组终端。
- 根据权利要求1至11任一项所述的方法,其中,所述目标无线信令包括广播信令、寻呼信令、无线短消息、和系统消息中的任一项;或者,所述目标无线信令通过寻呼信道PCH、多播信道MCH、广播信道BCH和下行共享信道DL-SCH中的至少一项发送;或者,所述目标无线信令通过物理下行控制信道PDCCH、物理下行共享信道PDSCH、物理广播信道PBCH和物理多播信道PMCH中的至少一项发送。
- 一种交互方法,其中,包括:接入网节点发送目标无线信令,所述目标无线信令包括第一标识信息以及第一目标信息,所述第一目标信息包括加密信息与完整性保护信息中的至少一项;其中,所述加密信息和完整性保护信息基于第一安全要件生成,所述第一安全要件包括秘钥和密流中的至少一项。
- 根据权利要求13所述的方法,其中,所述接入网节点发送目标无线信令之前,所述方法还包括:所述接入网节点从核心网节点接收第三信息或目标数据;其中,所述第三信息包括第二标识信息和第二目标信息;所述第二目标信息包括以下至少一项:所述第一安全要件或第三安全要件,所述第三安全要件包括秘钥和密流中的至少一项;第一算法信息;第二安全参数;第二安全辅助信息,所述第二安全辅助信息包括终端核心网上下文中的信息;其中,所述第二标识信息用于指示终端,或由终端标识生成,或指示一组终端,或与所述第一标识信息相关;所述第一算法信息包括以下至少一项:安全要件派生算法、机密性算法、和完整性算法。
- 根据权利要求14所述的方法,其中,所述第三信息包括以下至少一项:至少一个第二标识信息和至少一个第二目标信息;至少一对第二标识信息与第二目标信息;其中,所述第二目标信息与所述第二标识信息为一到一或多映射;或者,所述第二标识信息与所述第二目标信息为一到零或一映射;或者,K个第二标识信息与所有第二目标信息存在对应关系,且K小于或等于所述第三信息中包含的第二标识信息的数量。
- 根据权利要求13至15中任一项所述的方法,其中,所述第一目标信息还包括以下至少一项:第一安全辅助信息,所述第一安全辅助信息包括第一算法信息、第一安全参数、和第二安全参数中的至少一项。
- 根据权利要求13至16中任一项所述的方法,其中,所述方法包括:所述接入网节点执行以下至少一项:基于第二派生信息和安全要件派生算法中的至少一项生成所述第一安全要件;还基于机密性算法生成所述加密信息;还基于完整性算法生成所述完整性保护信息;还基于第一计算参数生成所述加密信息与所述完整性保护信息中的至少一项;第三操作;其中,所述第一计算参数包括以下至少一项:终端接入网上下文中的信息;所述第一标识信息;第一安全辅助信息中的至少部分内容;第二安全辅助信息中的至少部分内容;其中,所述第二派生信息包括以下至少一项:接入网相关密钥;接入层面AS层相关密钥;终端上下文中的密钥;第三安全要件;终端接入网上下文中的信息;所述第一标识信息;第一安全辅助信息中的至少部分内容;第二安全辅助信息中的至少部分内容;所述第三操作包括以下至少一项:从终端接收第一信息;从终端接收携带第三安全参数的第一信息;向终端发送第二信息;基于第四派生信息和所述第一安全要件中的至少一项生成第二安全要件,所述第二安全要件包括密钥和密流中的至少一项,所述第四派生信息包括以下至少一项:核心网相关密钥、非接入层面NAS层相关密钥、接入网相关密钥、AS层相关密钥、终端上下文中的密钥、和所述第三安全参数。
- 根据权利要求17所述的方法,其中,所述方法包括以下至少一项:所述接入网节点基于以下至少一项,对所述第一信息或所述第一信息中的部分内容进行安全处理:所述第一安全要件或所述第二安全要件,所述第一计算参数,和所述第三安全参数;所述接入网节点基于以下至少一项,对所述第二信息或所述第二信息中的部分内容进行安全保护:所述第一安全要件或所述第二安全要件,所述第一计算参数,和所述第三安全参数。
- 根据权利要求18所述的方法,其中,所述安全保护包括机密性保护、加密、和完整性保护中的至少一项;所述安全处理包括解密、机密性处理、完整性处理、完整性校验中的至少一项。
- 根据权利要求17至19中任一项所述的方法,其中,所述终端为空闲态或非激活态,或在发送所述第一信息前为空闲态或非激活态,或在接收所述第二信息前为空闲态或非激活态。
- 根据权利要求13至20中任一项所述的方法,其中,所述目标无线信令包括以下至少一项:至少一个第一标识信息和至少一个第一目标信息;至少一对第一标识信息与第一目标信息;其中,第一目标信息与第一标识信息为一到一或多映射;或者,第一标识信息与第一目标信息为一到零或一映射;或者,N个第一标识信息与所有第一目标信息存在对应关系,且N小于或等于所述目标无线信令包含的第一标识信息的数量。
- 根据权利要求13至21任一项所述的方法,其中,所述第一标识信息指示终端,或者由终端标识生成,或者指示一组终端。
- 根据权利要求13至22任一项所述的方法,其中,所述目标无线信令为广播信令、寻呼信令、无线短消息、系统消息中的任一项;或者,所述目标无线信令通过寻呼信道PCH、多播信道MCH、广播信道BCH和下行共享信道DL-SCH中的至少一项发送;或者,所述目标无线信令通过物理下行控制信道PDCCH、物理下行共享信道PDSCH、物理广播信道PBCH和物理多播信道PMCH中的至少一项发送。
- 一种交互方法,其中,包括:核心网节点向接入网节点发送第三信息或目标数据,所述第三信息包括第二标识信息和第二目标信息;其中,所述第二目标信息包括以下至少一项:第一安全要件或第三安全要件;第一算法信息;第二安全参数;第二安全辅助信息,所述第二安全辅助信息包括终端核心网上下文中的信息;其中,所述第一算法信息包安全要件派生算法、机密性算法、和完整性算法中的至少一项;所述第一安全要件包括秘钥和密流中的至少一项,所述第三安全要件包括秘钥和密流中的至少一项,所述第二标识信息指示终端,或由终端标识生成,或指示一组终端。
- 根据权利要求24所述的方法,其中,所述方法还包括:所述核心网节点基于第三派生信息和所述安全要件派生算法中的至少一项生成所述第一安全要件或所述第三安全要件;其中,所述第三派生信息包括以下至少一项:核心网相关密钥、NAS层相关密钥、终端上下文中的密钥、所述第一算法信息、所述第二安全参数、和所述第二安全辅助信息中的至少部分内容。
- 根据权利要求24或25所述的方法,其中,所述第三信息包括以下至少一项:至少一个第二标识信息和至少一个第二目标信息;至少一对第二标识信息与第二目标信息;其中,所述第二目标信息与所述第二标识信息为一到一或多映射;或者,所述第二标识信息与所述第二目标信息为一到零或一映射;或者,K个第二标识信息与所有第二目标信息存在对应关系,且K小于或等于第二标识信息的数量。
- 根据权利要求24至26中任一项所述的方法,其中,所述方法还包括:所述核心网节点从所述终端接收第二算法信息,所述第二算法信息用于指示以下至少一项:所述终端支持的算法、所述终端使用的算法;其中,所述第一算法信息基于所述第二算法信息生成。
- 一种交互方法,其中,包括:接入网节点发送目标无线信令,所述目标无线信令包括第一标识信息以及第一目标信息,所述第一目标信息包括加密信息与完整性保护信息中的至少一项,其中,所述加密信息和完整性保护信息基于第一安全要件生成;终端接收所述目标无线信令;在所述终端与所述第一标识信息相关的情况下,所述终端执行以下至少一项:基于第一安全要件执行第一操作;第二操作;其中,所述第一操作包括以下至少一项:解密所述加密信息;对所述加密信息进行机密性处理;对所述第一目标信息进行机密性处理;校验或验证所述完整性保护信息;对所述第一目标信息进行安全处理;对所述第一目标信息进行完整性校验或完整性处理;基于所述完整性保护信息,对以下至少一项进行完整性校验或完整性处理:所述第一目标信息、所述第一目标信息中的部分内容、和所述解密的结果;其中,所述第二操作包括以下至少一项:基于第四派生信息和所述第一安全要件中的至少一项生成第二安全要件;向接入网节点发送第一信息;向接入网节点发送携带第三安全参数的第一信息;从接入网节点接收第二信息;其中,所述第一安全要件基于第一派生信息生成,所述第一安全要件包括秘钥和密流中的至少一项;所述第一派生信息包括以下至少一项:核心网相关密钥、非接入层面NAS层相关密钥、接入网相关密钥、接入层面AS层相关密钥、终端上下文中的密钥、终端核心网上下文中的信息、第一标识信息、和终端接入网上下文中的信息;所述第四派生信息包括以下至少一项:核心网相关密钥、非接入层面NAS层相关密钥、接入网相关密钥、接入层面AS层相关密钥、终端上下文中的密钥、终端核心网上下文中的信息、第一标识信息、终端接入网上下文中的信息、和所述第三安全参数;所述第二安全要件包括密钥和密流中的至少一项。
- 根据权利要求28所述的方法,其中,所述方法还包括:核心网节点向接入网节点发送第三信息或目标数据,所述第三信息包括第二标识信息和第二目标信息;所述接入网节点基于所述第二目标信息获知或生成所述第一安全要件,并基于所述第三信息发送所述目标无线信令;其中,所述第二目标信息包括以下至少一项:所述第一安全要件或第三安全要件、第一算法信息、第二安全参数、和第二安全辅助信息;所述第一算法信息包安全要件派生算法、机密性算法、和完整性算法中的至少一项;其中,所述第二安全辅助信息包括终端核心网上下文中的信息,所述第三安全要件包括秘钥和密流中的至少一项,所述第二标识信息指示终端,或由终端标识生成,或指示一组终端,或与所述第一标识信息相关。
- 根据权利要求29所述的方法,其中,所述接入网节点基于所述第二目标信息生成所述第一安全要件包括:所述接入网节点基于第二派生信息和所述安全要件派生算法中的至少一项生成所述第一安全要件;其中,所述第二派生信息包括以下至少一项:接入网相关密钥、AS层相关密钥、终端上下文中的密钥、所述第一安全辅助信息中的至少部分内容、所述第二安全辅助信息中的至少部分内容、第一标识信息、和终端接入网上下文中的信息。
- 根据权利要求29所述的方法,其中,所述方法还包括:所述核心网节点基于第三派生信息和所述安全要件派生算法中的至少一项生成所述第一安全要件或所述第三安全要件;其中,所述第三派生信息包括以下至少一项:核心网相关密钥、NAS层相关密钥、终端上下文中的密钥、所述第二安全参数、和所述第二安全辅助信息中的至少部分内容。
- 根据权利要求28至31中任一项所述的方法,其中,所述目标无线信令包括第一安全辅助信息;和/或,所述第一派生信息包括第一安全辅助信息中的至少部分内容;其中,所述第一安全辅助信息包括第一算法信息、第一安全参数、和第二安全参数中的至少一项。
- 一种交互装置,应用于终端,其中,包括:第一接收模块,用于接收目标无线信令,所述目标无线信令包括第一标识信息以及第一目标信息,所述第一目标信息包括加密信息与完整性保护信息中的至少一项;第一执行模块,用于执行以下至少一项:基于第一安全要件执行第一操作;第二操作;其中,所述第一操作包括以下至少一项:解密所述加密信息;对所述加密信息进行机密性处理;对所述第一目标信息进行机密性处理;校验或验证所述完整性保护信息;对所述第一目标信息进行安全处理;对所述第一目标信息进行完整性校验或完整性处理;基于所述完整性保护信息,对以下至少一项进行完整性校验或完整性处理:所述第一目标信息、所述第一目标信息中的部分内容、和所述解密的结果;其中,所述第二操作包括以下至少一项:基于第四派生信息和所述第一安全要件中的至少一项生成第二安全要件;向接入网节点发送第一信息;从接入网节点接收第二信息;其中,所述第一安全要件基于第一派生信息生成,所述第一安全要件包括密钥和密流中的至少一项;所述第一派生信息和所述第四派生信息包括以下至少一项:核心网相关密钥、非接入层面NAS层相关密钥、接入网相关密钥、接入层面AS层相关密钥、和终端上下文中的密钥;所述第二安全要件包括密钥和密流中的至少一项。
- 根据权利要求33所述的交互装置,其中,所述第一目标信息还包括第一安全辅助信息;其中,所述第一安全辅助信息包括第一算法信息、第一安全参数、和第二安全参数中的至少一项;所述第一算法信息包括以下至少一项:安全要件派生算法,所述第一安全要件还基于所述安全要件派生算法生成;机密性算法和完整性算法中至少一项,所述第一操作还基于所述机密性算法和完整性算法中至少一项执行。
- 根据权利要求33或34所述的交互装置,其中,所述第一派生信息还包括以下至少一项:第一安全辅助信息中的至少部分内容;终端核心网上下文中的信息;终端接入网上下文中的信息;所述第一标识信息。
- 根据权利要求33至35任一项所述的交互装置,其中,所述基于第一安全要件执行第一操作,包括:所述第一执行模块基于所述第一安全要件以及第一计算参数执行所述第一操作,所述第一计算参数包括以下至少一项:终端核心网上下文中的信息;终端接入网上下文中的信息;所述第一标识信息;第一安全辅助信息中的至少部分内容。
- 一种交互装置,应用于接入网节点,其中,包括:第一发送模块,用于发送目标无线信令,所述目标无线信令包括第一标识信息以及第一目标信息,所述第一目标信息包括加密信息与完整性保护信息中的至少一项;其中,所述加密信息和完整性保护信息基于第一安全要件生成,所述第一安全要件包括秘钥和密流中的至少一项。
- 根据权利要求37所述的交互装置,其中,所述交互装置还包括:第二接收模块,用于在所述第一发送模块发送目标无线信令之前,从核心网节点接收第三信息或目标数据;其中,所述第三信息包括第二标识信息和第二目标信息;所述第二目标信息包括以下至少一项:所述第一安全要件或第三安全要件,所述第三安全要件包括秘钥和密流中的至少一项;第一算法信息;第二安全参数;第二安全辅助信息,所述第二安全辅助信息包括终端核心网上下文中的信息;其中,所述第二标识信息用于指示终端,或由终端标识生成,或指示一组终端,或与所述第一标识信息相关;所述第一算法信息包括以下至少一项:安全要件派生算法、机密性算法、和完整性算法。
- 根据权利要求38所述的交互装置,其中,所述第三信息包括以下至少一项:至少一个第二标识信息和至少一个第二目标信息;至少一对第二标识信息与第二目标信息;其中,所述第二目标信息与所述第二标识信息为一到一或多映射;或者,所述第二标识信息与所述第二目标信息为一到零或一映射;或者,K个第二标识信息与所有第二目标信息存在对应关系,且K小于或等于所述第三信息中包含的第二标识信息的数量。
- 一种交互装置,应用于核心网节点,其中,包括:第二发送模块,用于向接入网节点发送第三信息或目标数据,所述第三信息包括第二标识信息和第二目标信息;其中,所述第二目标信息包括以下至少一项:第一安全要件或第三安全要件;第一算法信息;第二安全参数;第二安全辅助信息,所述第二安全辅助信息包括终端核心网上下文中的信息;其中,所述第一算法信息包安全要件派生算法、机密性算法、和完整性算法中的至少一项;所述第一安全要件包括秘钥和密流中的至少一项,所述第三安全要件包括秘钥和密流中的至少一项,所述第二标识信息指示终端。
- 根据权利要求40所述的交互装置,其中,所述交互装置还包括:第三执行模块,用于基于第三派生信息和所述安全要件派生算法中的至少一项生成所述第一安全要件或所述第三安全要件;其中,所述第三派生信息包括以下至少一项:核心网相关密钥、NAS层相关密钥、终端上下文中的密钥、所述第一算法信息、所述第二安全参数、和所述第二安全辅助信息中的至少部分内容。
- 根据权利要求40或41所述的交互装置,其中,所述第三信息包括以下至少一项:至少一个第二标识信息和至少一个第二目标信息;至少一对第二标识信息与第二目标信息;其中,所述第二目标信息与所述第二标识信息为一到一或多映射;或者,所述第二标识信息与所述第二目标信息为一到零或一映射;或者,K个第二标识信息与所有第二目标信息存在对应关系,且K小于或等于第二标识信息的数量。
- 根据权利要求40至42中任一项所述的交互装置,其中,所述交互装置还包括:第三接收模块,用于从所述终端接收第二算法信息,所述第二算法信息用于指示以下至少一项:所述终端支持的算法、所述终端使用的算法;其中,所述第一算法信息基于所述第二算法信息生成。
- 一种终端,其中,包括处理器和存储器,所述存储器存储可在所述处理器上运行的程序或指令,所述程序或指令被所述处理器执行时实现如权利要求1至12任一项所述的交互方法的步骤。
- 一种网络侧设备,其中,包括处理器和存储器,所述存储器存储可在所述处理器上运行的程序或指令,所述程序或指令被所述处理器执行时实现如权利要求13至32任一项所述的交互方法的步骤。
- 一种交互系统,其中,包括:网络侧设备和终端,其中,所述网络侧设备被配置用于执行如权利要求13至32任一项所述的交互方法的步骤,所述终端被配置用于执行如权利要求1至12任一项所述的交互方法的步骤。
- 一种可读存储介质,其中,所述可读存储介质上存储程序或指令,所述程序或指令被处理器执行时实现如权利要求1至32任一项所述的交互方法的步骤。
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| CN202311673987.9A CN120128917A (zh) | 2023-12-07 | 2023-12-07 | 交互方法、装置、系统、终端及网络侧设备 |
| CN202311673987.9 | 2023-12-07 |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| WO2025119355A1 true WO2025119355A1 (zh) | 2025-06-12 |
Family
ID=95927948
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| PCT/CN2024/137563 Pending WO2025119355A1 (zh) | 2023-12-07 | 2024-12-06 | 交互方法、装置、系统、终端及网络侧设备 |
Country Status (2)
| Country | Link |
|---|---|
| CN (1) | CN120128917A (zh) |
| WO (1) | WO2025119355A1 (zh) |
Citations (5)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN108347726A (zh) * | 2017-01-25 | 2018-07-31 | 中兴通讯股份有限公司 | 移动网络小数据的安全传输方法及装置 |
| US20210329452A1 (en) * | 2018-09-03 | 2021-10-21 | Nec Corporation | Core network device, access network device, communication terminal, communication system, and communication method |
| CN115696319A (zh) * | 2021-07-27 | 2023-02-03 | 华为技术有限公司 | 一种通信方法及装置 |
| US20230073757A1 (en) * | 2020-02-06 | 2023-03-09 | Nokia Technologies Oy | Guti reallocation for mt-edt |
| WO2023143418A1 (zh) * | 2022-01-27 | 2023-08-03 | 维沃移动通信有限公司 | 设备鉴权方法、装置、终端及网络功能 |
-
2023
- 2023-12-07 CN CN202311673987.9A patent/CN120128917A/zh active Pending
-
2024
- 2024-12-06 WO PCT/CN2024/137563 patent/WO2025119355A1/zh active Pending
Patent Citations (5)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN108347726A (zh) * | 2017-01-25 | 2018-07-31 | 中兴通讯股份有限公司 | 移动网络小数据的安全传输方法及装置 |
| US20210329452A1 (en) * | 2018-09-03 | 2021-10-21 | Nec Corporation | Core network device, access network device, communication terminal, communication system, and communication method |
| US20230073757A1 (en) * | 2020-02-06 | 2023-03-09 | Nokia Technologies Oy | Guti reallocation for mt-edt |
| CN115696319A (zh) * | 2021-07-27 | 2023-02-03 | 华为技术有限公司 | 一种通信方法及装置 |
| WO2023143418A1 (zh) * | 2022-01-27 | 2023-08-03 | 维沃移动通信有限公司 | 设备鉴权方法、装置、终端及网络功能 |
Also Published As
| Publication number | Publication date |
|---|---|
| CN120128917A (zh) | 2025-06-10 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| US11924635B2 (en) | Security authentication method and apparatus thereof, and electronic device | |
| US20220272511A1 (en) | Subscription data management method and apparatus | |
| CN101442742A (zh) | 一种实现移动集群组呼端到端加密的方法、系统及设备 | |
| WO2024153014A1 (zh) | 消息传输方法、装置及设备 | |
| US20240031981A1 (en) | Paging Method and Apparatus, Terminal, and Network Side Device | |
| WO2025119355A1 (zh) | 交互方法、装置、系统、终端及网络侧设备 | |
| WO2025119381A1 (zh) | 安全通信方法、装置、系统、终端及网络侧设备 | |
| EP4231681B1 (en) | Trusted relay communication methods, system and readable storage medium | |
| JP7520153B2 (ja) | 鍵取得方法、鍵取得装置、ユーザ機器、ネットワーク側機器および可読記憶媒体 | |
| WO2024067337A1 (zh) | 终端鉴权方法、终端及网络侧设备 | |
| WO2025119357A1 (zh) | 交互方法、装置、系统、终端及网络侧设备 | |
| WO2023005898A1 (zh) | 多终端联合会话管理方法、网络侧设备及终端 | |
| WO2025168047A1 (zh) | 无线通信方法、装置、设备及存储介质 | |
| WO2025214273A1 (zh) | 无线通信方法、装置及设备 | |
| WO2025185719A1 (zh) | 无线通信方法、装置及设备 | |
| US20250254605A1 (en) | Relay communication method and apparatus, communication device, and storage medium | |
| WO2025185705A1 (zh) | 标识指示方法、装置、终端设备及第一网络节点 | |
| WO2025055786A1 (zh) | 认证处理方法、装置、终端及网络侧设备 | |
| CN121842666A (zh) | 认证方法、装置及设备 | |
| WO2025209485A1 (zh) | 激活安全的方法、终端及网络侧设备 | |
| WO2024041469A1 (zh) | 寻呼消息处理方法、装置、通信设备及可读存储介质 | |
| WO2025124383A1 (zh) | 通信方法、装置、用户设备、基站及存储介质 | |
| WO2024235025A1 (zh) | 用户面定位连接的通信方法、终端及网络侧设备 | |
| CN120614597A (zh) | 无线通信方法、装置及设备 | |
| WO2024193512A1 (zh) | 数据处理方法、装置、网络侧设备及终端设备 |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| 121 | Ep: the epo has been informed by wipo that ep was designated in this application |
Ref document number: 24899988 Country of ref document: EP Kind code of ref document: A1 |