WO2025161024A1 - 无线通信方法及通信设备 - Google Patents
无线通信方法及通信设备Info
- Publication number
- WO2025161024A1 WO2025161024A1 PCT/CN2024/075830 CN2024075830W WO2025161024A1 WO 2025161024 A1 WO2025161024 A1 WO 2025161024A1 CN 2024075830 W CN2024075830 W CN 2024075830W WO 2025161024 A1 WO2025161024 A1 WO 2025161024A1
- Authority
- WO
- WIPO (PCT)
- Prior art keywords
- algorithm
- type
- information
- terminal device
- supports
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Pending
Links
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W12/00—Security arrangements; Authentication; Protecting privacy or anonymity
- H04W12/03—Protecting confidentiality, e.g. by encryption
Definitions
- the present application relates to the field of communication technology, and more specifically to a wireless communication method and communication device.
- 256-bit encryption algorithms may be used for symmetric encryption between communicating devices. Consequently, different devices may support encryption algorithms of varying strengths. The challenge of how these devices negotiate these algorithms remains unresolved.
- the present application provides a wireless communication method and a communication device.
- the following introduces various aspects involved in the present application.
- a wireless communication method including: a first device receives first information, the first information being used to indicate whether a first terminal device supports a first type of algorithm, the first type of algorithm being a 256-bit encryption algorithm; the first device determines a first algorithm based on the first information, the first algorithm being an encryption algorithm used between the first device and the first terminal device.
- a wireless communication method including: a first terminal device receives a first message sent by a first device, the first message including indication information of a first algorithm, the first algorithm being an encryption algorithm used between the first device and the first terminal device; wherein the first algorithm is determined based on the first information, the first information is used to indicate whether the first terminal device supports a first type of algorithm, and the first type of algorithm is a 256-bit encryption algorithm.
- a communication device which is a first device, and includes: a receiving module for receiving first information, wherein the first information is used to indicate whether the first terminal device supports a first type of algorithm, and the first type of algorithm is a 256-bit encryption algorithm; and a determination module for determining a first algorithm based on the first information, and the first algorithm is an encryption algorithm used between the first device and the first terminal device.
- a communication device which is a first terminal device, and the communication device includes: a receiving module for receiving a first message sent by a first device, the first message including indication information of a first algorithm, and the first algorithm is an encryption algorithm used between the first device and the first terminal device; wherein the first algorithm is determined based on the first information, and the first information is used to indicate whether the first terminal device supports a first type of algorithm, and the first type of algorithm is a 256-bit encryption algorithm.
- a communication device comprising a memory and a processor, wherein the memory is used to store a program, and the processor is used to call the program in the memory so that the terminal device executes the method described in the first aspect.
- a communication device comprising a memory and a processor, wherein the memory is used to store a program, and the processor is used to call the program in the memory so that the network device executes the method described in the second aspect.
- a device comprising a processor for calling a program from a memory so that the device executes the method as described in the first aspect or the second aspect.
- a chip comprising a processor for calling a program from a memory so that a device equipped with the chip executes the method described in the first aspect or the second aspect.
- a computer-readable storage medium on which a program is stored, wherein the program enables a computer to execute the method as described in the first aspect or the second aspect.
- a computer program product comprising a program, wherein the program enables a computer to execute the method as described in the first aspect or the second aspect.
- a computer program is provided, wherein the computer program enables a computer to execute the method as described in the first aspect or the second aspect.
- the first device can determine whether the first terminal device supports a 256-bit encryption algorithm based on the first information. Based on this, the first device can implement encryption algorithm negotiation with the first terminal device, which helps the communication system achieve parallel support of different encryption algorithm strengths.
- FIG1 is a schematic structural diagram of a wireless communication system to which an embodiment of the present application is applicable.
- FIG2 is a schematic flowchart of the key generation process in the 5G security key architecture.
- FIG3 is a schematic flow chart of the NAS security mode command process.
- FIG4 is a schematic flow chart of the AS security mode command process.
- FIG5 is a schematic flowchart of a wireless communication method provided in an embodiment of the present application.
- 6A-6B are schematic flow charts of a wireless communication method provided in another embodiment of the present application.
- FIG7 is a schematic flowchart of a wireless communication method provided in Embodiment 1 of the present application.
- 9A-9B are schematic flow charts of a wireless communication method provided in Embodiment 5 of the present application.
- FIG10 is a schematic structural diagram of a communication device provided in an embodiment of the present application.
- FIG11 is a schematic structural diagram of a communication device provided in another embodiment of the present application.
- FIG12 is a schematic structural diagram of a communication device provided in an embodiment of the present application.
- FIG1 is a schematic diagram of a communication system architecture applicable to an embodiment of the present application.
- the network architecture may include terminal devices, access network (AN) network elements, and core network network elements.
- the technical solutions of the embodiments of the present application can be applied to various communication systems, such as: sixth-generation (6G) communication systems, fifth-generation (5G) systems or new radio (NR), long-term evolution (LTE) systems, LTE frequency division duplex (FDD) systems, LTE time division duplex (TDD) systems, etc.
- 6G sixth-generation
- 5G fifth-generation
- NR new radio
- LTE long-term evolution
- FDD frequency division duplex
- TDD time division duplex
- future communication systems such as sixth-generation mobile communication systems and satellite communication systems, etc.
- the terminal device in the embodiment of the present application may also be referred to as user equipment (UE), access terminal, user unit, user station, mobile station, mobile station (MS), mobile terminal (MT), remote station, remote terminal, mobile device, user terminal, terminal, wireless core network element, user agent or user device.
- the terminal device in the embodiment of the present application may be a device that provides voice and/or data connectivity to a user, and may be used to connect people, objects and machines, such as a handheld device with wireless connection function, a vehicle-mounted device, etc.
- the terminal device in the embodiment of the present application may be a mobile phone, a tablet computer (Pad), a laptop computer, a PDA, a mobile internet device (MID), a wearable device, a virtual reality (VR) device, an augmented reality (AR) device, a wireless terminal in industrial control (industrial control), or a wearable device.
- the terminal device can be used to connect to a wireless terminal, a wireless terminal in self-driving, a wireless terminal in remote medical surgery, a wireless terminal in a smart grid, a wireless terminal in transportation safety, a wireless terminal in a smart city, a wireless terminal in a smart home, etc.
- the terminal device can be used to act as a base station.
- the terminal device can act as a dispatching entity that provides sidelink signals between terminal devices in vehicle-to-everything (V2X) or device-to-device (D2D).
- V2X vehicle-to-everything
- D2D device-to-device
- a cellular phone and a car communicate with each other using sidelink signals.
- Cellular phones and smart home devices communicate with each other without relaying communication signals through a base station.
- An access network element can be an access network device. This device is used by terminals to wirelessly access the network architecture and is primarily responsible for air interface-side radio resource management, quality of service (QoS) management, data compression and encryption, and other functions. Access network devices can also be referred to as radio access network (RAN) devices, such as base stations.
- RAN radio access network
- base station can broadly cover the following names or be replaced by the following names, such as: NodeB, evolved NodeB (eNB), next generation NodeB (gNB), relay station, access point, transmitting and receiving point (TRP), transmitting point (TP), master eNB (MeNB), secondary eNB (SeNB), multi-standard radio (MSR) node, home base station, network controller, access node, wireless node, access point (AP), transmission node, transceiver node, baseband unit (BBU), remote radio unit (RRU), active antenna unit (AAU), remote radio head (RRH), central unit (CU), distributed unit (DU), positioning node, etc.
- NodeB evolved NodeB
- gNB next generation NodeB
- TRP transmitting and receiving point
- TP transmitting point
- MeNB master eNB
- SeNB secondary eNB
- MSR multi-standard radio
- the base station can be a macro base station, a micro base station, a relay node, a donor node or the like, or a combination thereof.
- the base station can also refer to a communication module, a modem or a chip for being provided in the aforementioned device or apparatus.
- the base station can also be a mobile switching center and a device that performs the base station function in D2D, V2X, machine-to-machine (M2M) communications, a network side device in a 6G network, a device that performs the base station function in a future communication system, and the like.
- the base station can support networks with the same or different access technologies. The embodiments of the present application do not limit the specific technology and specific device form adopted by the access network device.
- Base stations can be fixed or mobile.
- a helicopter or drone can be configured to act as a mobile base station, and one or more cells can move based on the location of the mobile base station.
- a helicopter or drone can be configured to act as a device that communicates with another base station.
- the access network device in the embodiments of the present application may refer to a CU or a DU, or the access network device may include a CU and a DU.
- the gNB may also include an AAU.
- the types of core network elements may include user plane function (UPF) network element, access and mobility management function (AMF) network element, session management function (SMF) network element, policy control function (PCF) network element, application function (AF), data network (DN), network slice selection function (NSSF), authentication server function (AUSF), unified data management function (UDM), network exposure function (NEF), network repository function (NRF), and network slice-specific authentication and authorization function (NSSAAF).
- UPF user plane function
- AMF access and mobility management function
- SMF session management function
- PCF policy control function
- AF application function
- DN data network
- NSSF network slice selection function
- AUSF authentication server function
- UDM unified data management function
- NEF network exposure function
- NSSAAF network exposure function
- NSSAAF network exposure function
- NSSAAF network exposure function
- NSSAAF network exposure function
- NSSAAF network exposure function
- NSSAAF network exposure function
- NSSAAF network exposure function
- NSSAAF network exposure function
- the network elements in Figure 1 can be network elements in hardware devices, software functions running on dedicated hardware, or virtualized functions implemented on a platform (e.g., a cloud platform).
- the network elements included in the entire network architecture are illustrated by way of example. In the embodiments of the present application, the network elements included in the entire network architecture are not limited.
- the network architecture shown in FIG1 does not limit the network architecture.
- the network architecture may include more or fewer network elements than shown, or may combine certain network elements.
- the AN or RAN is represented by (R)AN.
- network devices and terminal devices can be deployed on land, including indoors or outdoors, handheld or vehicle-mounted; they can also be deployed on water; they can also be deployed in the air on aircraft, balloons, and satellites.
- the embodiments of this application do not limit the scenarios in which network devices and terminal devices are located.
- Symmetric encryption algorithms used in 5G security include 128-NEA1, 128-NEA2, and 128-NEA-3. These three symmetric encryption algorithms correspond to Snow 3G, the Advanced Encryption Standard (AES), and the Zu Chongzhi (ZUC) algorithm, respectively. Details of these three symmetric encryption algorithms are shown in Table 1.
- the fourth generation (4G) also uses these three symmetric encryption algorithms, named 128-EEA1, 128-EEA2, and 128-EEA3.
- the length of the generated key can be shown in Figure 2.
- the length of the key used to protect the session i.e., to protect the security of the NAS and AS layers
- Each AMF can configure a list of algorithms allowed for use through network management, namely a list of NAS integrity algorithms and a list of NAS encryption algorithms. These lists should be sorted according to the priority determined by the operator.
- the AMF can select a NAS encryption algorithm and a NAS integrity protection algorithm.
- the AMF can then initiate the NAS security mode command procedure and include the selected algorithm and UE security capabilities in the message sent to the UE (to detect attackers modifying the UE security capabilities).
- the AMF can select the NAS algorithm with the highest priority based on the list sorting.
- the NAS security mode command process can be shown in Figure 3, including steps S310 to S360.
- step S310 the AMF enables integrity protection.
- the AMF can select the corresponding security algorithm (encryption algorithm and integrity algorithm) to enable integrity protection based on the UE security capabilities and the locally configured algorithm list.
- step S320 the AMF sends a NAS security mode command (SMC) message to the UE.
- SMC NAS security mode command
- the NAS SMC can include the algorithm selected by the AMF and the UE security capabilities, as well as a NAS key change indication (e.g., K_AMF_change_flag), a NAS key set identifier (ngKSI), an Anti-Bidding down Between Architectures (ABBA) parameter, a request initial NAS message flag, a NAS message authentication code (MAC), etc.
- K_AMF_change_flag a NAS key set identifier
- ngKSI NAS key set identifier
- ABBA Anti-Bidding down Between Architectures
- MAC NAS message authentication code
- the UE can verify the integrity of the NAS SMC message, and if successful, it can enable uplink encryption, downlink decryption and integrity protection.
- the UE can verify the integrity of the NAS SMC message to confirm that the message has not been tampered with, and then confirm that it has not been subjected to a price reduction attack by checking the UE security capabilities returned by the AMF. After the UE verification is successful, it can use the algorithm selected by the AMF to enable encryption and integrity protection at the NAS layer.
- the AMF can enable uplink decryption.
- the UE can send a NAS security mode complete message to the AMF, which may include a complete initial NAS message in the NAS container and a NAS MAC.
- the AMF enables downlink encryption.
- the source AMF may send the UE security capabilities to the target AMF, which may then send the selected algorithms to the UE.
- the target AMF may send this information to the UE via the source AMF using a NAS container.
- the target AMF may use a NAS SMC procedure to activate the selected algorithms between the target AMF and the UE.
- Each gNB/ng-eNB can be configured through network management with a list of allowed algorithms: an integrity algorithm list and a cipher algorithm list. These lists can be ordered according to operator-determined priorities.
- the AMF can send the UE's 5G security capabilities to the gNB/ng-eNB.
- the gNB/ng-eNB selects the algorithm with the highest priority from its configured list that is also present in the UE's 5G security capabilities.
- the selected algorithm can be indicated to the UE during the AS SMC procedure.
- the selected cipher algorithm can be used for encryption of user plane data and radio resource control (RRC) signaling.
- RRC radio resource control
- the selected integrity algorithm can be used for integrity protection of user plane data and RRC signaling.
- the AS security mode command process may be as shown in Figure 4, including steps S410 to S470.
- the gNB or ng-eNB enables RRC integrity protection.
- the gNB or ng-eNB may select the corresponding RRC and user plane (UP) protection security algorithms based on the UE security capabilities and the locally configured algorithm list to enable RRC integrity protection.
- the gNB or ng-eNB may send an AS SMC message to the UE.
- the AS SMC message may include the algorithm selected by the gNB or ng-eNB, the UE security capabilities, and message authentication code-integrity (MAC-I) information.
- the gNB or ng-eNB may enable RRC downlink encryption.
- step S440 the UE verifies the integrity of the AS SMC message and, if successful, enables RRC integrity protection and RRC downlink decryption.
- the UE can verify the integrity of the message through (MAC-I) to confirm that the message has not been tampered with, and confirm that it has not been subjected to price reduction attacks by checking the UE security capabilities returned by the gNB or ng-eNB. After the UE verification is successful, it can use the algorithm selected by the gNB or ng-eNB to enable RRC layer encryption and integrity protection and downlink decryption.
- the UE can send a request to the gNB or The ng-eNB sends an AS SMC message, which may include a MAC-I.
- the UE may enable RRC uplink encryption.
- the gNB or ng-eNB may enable RRC uplink decryption.
- the source base station can send the UE's security capabilities and the security algorithm used by the source cell to the target base station.
- the target base station can select an algorithm based on the UE security capabilities and the locally configured algorithm list. If different algorithms are selected, the target base station can carry the selected algorithm in the handover command message sent by the source base station to the UE.
- the algorithm selected by the target base station must be carried.
- the target base station must send the UE security capabilities to the AMF for AMF verification. If they are inconsistent with the locally stored UE security capabilities, the AMF will carry the UE security capabilities in the path switch acknowledgment message sent to the target base station. After the target base station reselects the algorithm, it uses intra-cell handover and UE update algorithms.
- the source AMF may send the UE's security capabilities to the target AMF, and the target AMF may send an NGAP HANDOVER REQUEST message to the target eNB, which includes the UE's security capabilities.
- the source eNB may send a source-to-target transparent container to the target eNB, which includes the algorithm used by the source cell.
- the target eNB may select an algorithm based on the UE's security capabilities and a locally configured algorithm list. If different algorithms are selected, the target eNB sends the selected algorithm in a Handover Command message to the UE.
- a quantum computer is a device that exploits quantum mechanical phenomena (superposition and entanglement) to perform calculations and manipulate data.
- the security foundation of currently popular cryptographic algorithms is built on a number of intractable mathematical problems. Due to the inherent parallel nature of quantum computers, some quantum algorithms can solve difficult mathematical problems more efficiently than classical algorithms, posing a serious and present security threat to contemporary cryptography.
- An attacker can use the Grover algorithm on a quantum computer to halve the effective key size, thereby halving the security strength of symmetric key algorithms. Therefore, to achieve quantum attack resistance, the key size of symmetric key algorithms must be doubled.
- 128-bit symmetric key algorithms such as AES-128, SNOW 3G, and ZUC-128 are the foundation of NAS signaling, RRC signaling, and UP data security. To combat quantum attacks, the introduction of 256-bit symmetric key algorithms into the system could be considered; the need for longer MACs requires further study.
- the encryption algorithms used in NAS signaling, RRC signaling, and user data in 4G and 5G systems are all 128-bit symmetric algorithms.
- radio access network equipment e.g., gNBs and ng-eNBs
- core network equipment e.g., AMFs
- 6G communication systems deploy communication entities supporting high-strength algorithms. Therefore, the communication system inevitably contains entities supporting different encryption algorithm strengths. Therefore, it is necessary to design algorithm negotiation methods between these entities to enable the phased introduction and parallel support of 128-bit and 256-bit encryption algorithms.
- the first device can determine whether the first terminal device supports a 256-bit encryption algorithm based on the first information. Based on this, the first device can implement encryption algorithm negotiation with the first terminal device, which helps the communication system achieve parallel support of different encryption algorithm strengths.
- an embodiment of the present application provides a wireless communication method that can be performed by a first device and a first terminal device.
- the first device can be the access network device described above, such as a gNB.
- the first device can also be the core network element (or "core network device") described above, such as an AMF.
- the first terminal device can be any of the terminal devices described above, and the first terminal device can establish a connection with the first device.
- the method shown in FIG5 may include steps S510 to S520.
- step S510 the first device receives the first information.
- the first information may be used to indicate whether the first terminal device supports a first type of algorithm, which is a 256-bit encryption algorithm. That is, the first device may determine whether the first terminal device supports a 256-bit algorithm based on the first information.
- step S520 the first device may determine the first algorithm based on the first information, which is the encryption algorithm used between the first device and the first terminal device. That is, the first device may determine the first algorithm based on the first terminal device. Whether the terminal device supports the 256-bit algorithm, determines the encryption algorithm between the terminal device and the first terminal device to achieve algorithm negotiation.
- the 256-bit algorithm in the embodiment of the present application may refer to the Snow 3G 256-based algorithm, the AES 256-based algorithm, and the ZUC 256-based algorithm.
- the encryption in the embodiment of the present application may refer to authenticated encryption, and the 256-bit algorithm in the embodiment of the present application may be used for authenticated encryption.
- Authenticated encryption is a joint algorithm that can perform encryption and/or integrity protection in a separate process. Authenticated encryption can perform encryption and/or integrity protection accordingly based on the input of the algorithm.
- the first information is described in detail below.
- the first information may include one or more of the following: one or more first identifiers; first indication information; and second indication information.
- the first information may include one or more first identifiers, and the one or more first identifiers may be used to indicate the one or more first type of algorithms supported by the first terminal device.
- the first information may include a first identifier to indicate the 256 algorithm supported by the first terminal device.
- the first terminal device does not support a 256-bit encryption algorithm, the first information may not include the first identifier. That is, one or more first identifiers may constitute a list of 256-bit algorithms supported by the first terminal device, and the first information may include the algorithm list.
- the first identifier may be an algorithm identifier.
- identifier 256-NEA1 can be used to represent the snow 5G 256-bits algorithm
- identifier 256-NEA2 can be used to represent the AES 256-bits algorithm
- identifier 256-NEA3 can be used to represent the ZUC 256-bits algorithm. Based on the first identifier, it helps the first device to clarify the 256-bit encryption algorithm supported by the first terminal device.
- the first information may include first indication information, and the first indication information may be used to indicate whether the first terminal device supports the first type of algorithm.
- the form of the first indication information may not be limited.
- the first indication information may occupy one bit.
- the value of the first indication information is the first value, it may indicate that the first terminal device supports the 256-bit encryption algorithm.
- the value of the first indication information is the second value, it may indicate that the first terminal device does not support the 256-bit encryption algorithm.
- the first information includes this bit, it may indicate that the first terminal device supports the 256-bit encryption algorithm.
- the first information does not include this bit, it may indicate that the first terminal device does not support the 256-bit encryption algorithm. Based on the first indication information, it helps the first device to quickly determine whether the first terminal device supports the 256-bit encryption algorithm.
- the first information may include second indication information, which may be used to indicate the use of the first type of algorithm as the first algorithm. That is, if the first terminal device supports a 256-bit encryption algorithm, the first information may include second indication information to instruct the first device to use the 256-bit encryption algorithm as the encryption algorithm between the first device and the first terminal device.
- the form of the second indication information is not limited.
- the second indication information may occupy one bit. When the value of the second indication information is the first value, it may indicate that the 256-bit encryption algorithm is used as the encryption algorithm between the first device and the first terminal device.
- the value of the second indication information is the second value, it may indicate that the 256-bit encryption algorithm is not used as the encryption algorithm between the first device and the first terminal device.
- the first information includes this bit, it may indicate that the 256-bit encryption algorithm is used as the encryption algorithm between the first device and the first terminal device.
- the first information does not include this bit, it may indicate that the 256-bit encryption algorithm is not used as the encryption algorithm between the first device and the first terminal device. Based on the second indication information, the first device is helped to determine the first algorithm more efficiently.
- the first information may also include multiple types of the above information, which will not be described in detail here.
- the first information may further include third indication information, which may be used to indicate that the first type of algorithm is used to perform encryption and/or integrity protection. If the first type of algorithm is used to perform encryption, it indicates that the first type of algorithm can be used to perform the encryption behavior in the authenticated encryption described above. If the first type of algorithm is used to perform integrity protection, it indicates that the first type of algorithm can be used to perform the integrity protection behavior in the authenticated encryption described above. Furthermore, the third indication information may be carried in the first indication information or the second indication information.
- the first information can be carried in the first capability information, and the first capability information can be used to indicate the security capabilities of the first terminal device. That is, the first capability information can be the security capability information of the first terminal device, and the first device can determine whether the first terminal device supports 256-bit encryption algorithms based on the security capability information of the first terminal device.
- the first capability information can be sent by the first terminal device to the first device, or the first capability information can be sent by a core network device (such as an AMF) to the first device, or the first capability information can be sent by another first device to the first device. For example, when the first terminal device initially accesses the first device, the first terminal device can report its own security capability information to the first device.
- the core network device can also send the security capability information of the first terminal device to the first device (in this case, the first device is an access network device).
- the source first device can send the security capability information of the first terminal device to the target first device. Based on the first capability information, the first device can determine the encryption algorithm used between the first device and the first terminal device.
- the first device may prioritize the 128-bit encryption algorithm as the encryption algorithm used between them.
- the first device may prioritize the second-type algorithm as the first algorithm. That is, when the first terminal device does not support a 256-bit encryption algorithm, the first device can select a 128-bit encryption algorithm as the encryption algorithm used between the two. Based on this, it is helpful to achieve coordination of the encryption algorithms between the first terminal device and the first device.
- the first device is a core network device. If the core network device determines to use the first type of algorithm based on the first information, the core network device can directly use a 256-bit key for NAS encryption (which can be authenticated encryption). If the core network device determines to use the second type of algorithm based on the first information, the core network device can use the Trunc function (i.e., truncation method) on the generated 256-bit key KNASenc to generate a 128-bit key for NAS encryption (which can be authenticated encryption). As another example, the first device is an access network device.
- Trunc function i.e., truncation method
- the access network device can directly use a 256-bit key for AS encryption (which can be authenticated encryption).
- the access network device can use the Trunc function on the keys KRRCenc and KUPenc to generate 128-bit keys, respectively, for protecting the RRC layer and the UP (user) plane (which can be authenticated encryption).
- the first device after the first device determines the first algorithm based on the first information, it can send a first message to the first terminal device, where the first message includes indication information that may include the first algorithm. That is, after the first device determines the first algorithm based on the first information, it can indicate the first algorithm to the first terminal device, which helps to implement encryption algorithm negotiation between the device and the first terminal device.
- the use of the first algorithm can be as follows. If the first terminal device determines to use the first type of algorithm based on the first message, the first terminal device can directly use a 256-bit key for encryption with the first device (which can be authenticated encryption).
- the first terminal device determines to use the second type of algorithm based on the first message, the first terminal device can use the Trunc function (i.e., truncation method) on the generated 256-bit key KNASenc to generate a 128-bit key for encryption with the first device (which can be authenticated encryption).
- Trunc function i.e., truncation method
- the wireless communication method of the embodiment of the present application may further include step S630.
- the first device sends the second information to the second device
- the second information can be used to indicate the second algorithm
- the second algorithm can be the encryption algorithm used between the second device and the first terminal device
- the second algorithm can be determined by the first device based on the first information. That is, the first device can negotiate the encryption algorithm used between the second device and the first terminal device based on the first information.
- the first device can be a master node (MN) (also known as a main base station), and the second device can be a secondary node (SN) (also known as a secondary base station).
- MN master node
- SN secondary node
- the MN can negotiate the encryption algorithm used between the SN and the terminal device based on the first information. Based on this, it is helpful to achieve coordination of the encryption algorithms between the first terminal device and the second device.
- the wireless communication method of the embodiment of the present application may further include step S630.
- step S630 the first device sends first information to the second device, and the first information can be used by the second device to determine a second algorithm, and the second algorithm can be an encryption algorithm between the second device and the first terminal device. That is, the first device can send the first information to the second device to help the second device determine the encryption algorithm between the second device and the first terminal device.
- the first device may be an MN
- the second device may be an SN.
- the MN may send the first information to the SN so that the SN can negotiate the encryption algorithm used between the SN and the terminal device. Based on this, it helps to achieve coordination of the encryption algorithms between the first terminal device and the second device.
- the wireless communication method of the embodiments of the present application is described in detail below in conjunction with Examples 1 to 5.
- Examples 1 and 2 take the first device being the core network device AMF as an example
- Examples 3 to 5 take the first device being the access network device gNB/ng-eNB as an example.
- the first information in each of the following embodiments is carried in the UE security capability.
- the UE security capability may include a 256-bit algorithm identifier supported by the UE (i.e., one or more first identifiers)/an indication of the UE supporting a 256-bit algorithm (i.e., first indication information)/an indication of using a 256-bit algorithm (i.e., second indication information).
- step S710 the UE sends a NAS message to the AMF.
- the NAS message may include the UE's security capabilities, which may include the 256-bit algorithm identifier supported by the UE or an indication that the 256-bit algorithm is supported.
- step S720 the AMF enables integrity protection.
- the AMF may select the corresponding security algorithm (encryption algorithm and integrity algorithm) to enable integrity protection based on the UE security capabilities and the locally configured algorithm list. It is worth noting that in the AMF's locally configured algorithm list that supports the 256-bit algorithm, the supported 256-bit algorithm has a higher priority than the supported 128-bit algorithm.
- the AMF may give priority to the 256-bit algorithm. If the AMF does not support the 256-bit algorithm, the AMF may select the 128-bit algorithm. In step S730, the AMF sends a NAS SMC message to the UE.
- the NAS SMC may include the algorithm selected by the AMF and the UE security capabilities, etc. The remaining steps are the same as the NAS algorithm negotiation process shown in FIG3 and are not described again here.
- algorithm negotiation is performed between the UE and the AMF in a handover or mobile registration update scenario.
- the AMF serving the UE changes.
- the source AMF may send the UE security capabilities to the target AMF, which may include a 256-bit algorithm identifier supported by the UE or an indication that the UE supports a 256-bit algorithm.
- the UE may send a NAS message containing the UE security capabilities to the target AMF, which may include a 256-bit algorithm identifier supported by the UE or an indication that the UE supports a 256-bit algorithm or an indication that a 256-bit algorithm is used between the AMF and the UE.
- the AMF may select the corresponding security algorithm (encryption algorithm and integrity algorithm) to enable integrity protection based on the UE security capabilities and the locally configured algorithm list. The remaining steps will not be repeated here.
- Embodiment 1 When the communication system requires NAS security protection to use a 256-bit algorithm and a core network device with 256-bit capability is deployed, based on Embodiment 1 and Embodiment 2, algorithm negotiation can be achieved between the UE and the core network device, which facilitates the phased introduction and parallel support of 128-bit and 256-bit encryption algorithms.
- step S810 the gNB/ng-eNB obtains the UE's security capabilities, which may include identifiers of 256-bit algorithms supported by the UE or an indication that the UE supports 256-bit algorithms.
- the gNB/ng-eNB obtains the UE's security capabilities through UE reporting or AMF transmission.
- step S820 the gNB/ng-eNB enables integrity protection.
- the gNB/ng-eNB may select the corresponding security algorithm for RRC and UP protection based on the UE's security capabilities and the locally configured algorithm list.
- step S830 the gNB/ng-eNB sends an AS SMC message to the UE.
- the AS SMC message contains the algorithm selected by the gNB/ng-eNB and the UE's security capabilities. The remaining steps are identical to the AS algorithm negotiation process shown in Figure 4 and are not repeated here.
- algorithm negotiation is performed between the UE and the gNB/ng-eNB in an Xn handover or N2 handover scenario.
- the gNB/ng-eNB serving the UE changes.
- the source eNB may send the target eNB the UE's security capabilities and the security algorithm used by the source cell.
- the UE's security capabilities may include a 256-bit algorithm identifier supported by the UE or an indication that the UE supports 256-bit algorithms.
- the target eNB may select an algorithm based on the UE's security capabilities and a locally configured algorithm list.
- supported 256-bit algorithms have higher priority than supported 128-bit algorithms. If the gNB/ng-eNB also supports the 256-bit algorithm, the gNB/ng-eNB may prioritize the 256-bit algorithm. If the gNB/ng-eNB does not support the 256-bit algorithm, the gNB/ng-eNB may select the 128-bit algorithm.
- the target base station selects a different algorithm, for example, in a system interoperability scenario, a UE supporting the 256-bit algorithm switches from a base station with a low algorithm strength to a base station with a high algorithm strength, the target base station can carry the selected 256-bit algorithm in the handover command message sent by the source base station to the UE.
- the target base station needs to send the UE security capabilities to the AMF for AMF verification. If the UE security capabilities are inconsistent with the locally stored UE security capabilities, the AMF will send the UE security capabilities in the path switch acknowledgment message to the target base station. After the target base station reselects the algorithm, it will use the intra-cell switching and UE update algorithm.
- algorithm negotiation is performed in a dual-connectivity handover scenario between a UE and a gNB/ng-eNB.
- a dual-connectivity scenario there is a primary base station (MN) and a secondary base station (SN).
- Possible base station handover scenarios include: 1. MN handover with unchanged SN; 2. MN handover with SN handover; and 3. MN handover with unchanged SN handover.
- MN handover occurs, the algorithm negotiation between the MN and the UE is the same as in the third embodiment.
- the MN can send the UE's security capabilities to the target SN for algorithm negotiation between the UE and the SN.
- the MN can negotiate a security algorithm between the UE and the SN based on the list of algorithms supported by the SN sent by the local/SN and the UE's security capabilities.
- the UE's security capabilities can include a 256-bit identifier of the algorithms supported by the UE, or an indication that the UE supports a 256-bit algorithm.
- FIG10 is a schematic diagram of the structure of a communication device provided by an embodiment of the present application.
- the communication device 1000 shown in FIG10 is a first device.
- the communication device 1000 may include a receiving module 1010 and a determining module 1020.
- the receiving module 1010 may be configured to receive first information, where the first information may be used to indicate whether the first terminal device supports a first type of algorithm, where the first type of algorithm may be a 256-bit encryption algorithm; and the determining module 1020 may be configured to determine a first algorithm based on the first information, where the first algorithm may be an encryption algorithm used between the first device and the first terminal device.
- the first information may include one or more first identifiers, and the one or more first identifiers may be used to indicate the one or more first type of algorithms supported by the first terminal device.
- the first information may include first indication information, and the first indication information may be used to indicate whether the first terminal device supports the first type of algorithm.
- the first information may include second indication information, and the second indication information may be used to instruct the first device to use the first type of algorithm as the first algorithm.
- the first information may be carried in first capability information, and the first capability information may be used to indicate the security capability of the first terminal device.
- the first device determining the first algorithm based on the first information may include: if the first terminal device supports the first type of algorithm and the first device supports the first type of algorithm, the first device may preferentially select the first type of algorithm as the first algorithm; if the first terminal device supports the first type of algorithm but the first device does not support the first type of algorithm, the first device may select the second type of algorithm as the first algorithm, where the second type of algorithm is a 128-bit encryption algorithm. If the first terminal device does not support the first type of algorithm, the first device may select the second type of algorithm as the first algorithm.
- the communication device 1000 may further include a first sending module 1030.
- the sending module 1030 may be configured to send second information to the second device.
- the second information may be configured to indicate a second algorithm.
- the second algorithm may be an encryption algorithm between the second device and the first terminal device.
- the second algorithm may be determined by the first device based on the first information.
- the communication device 1000 may further include a second sending module 1040.
- the sending module 1040 may be configured to send first information to the second device, where the first information may be used by the second device to determine a second algorithm, which is an encryption algorithm between the second device and the first terminal device.
- the first device may be an access network device.
- the first device may be a core network device.
- FIG 11 is a schematic diagram of the structure of a communication device provided in another embodiment of the present application.
- the communication device 1100 shown in Figure 11 is a first terminal device, and the communication device 1100 may include a receiving module 1110 and a using module 1120.
- the receiving module 1110 may be used to receive a first message sent by a first device, and the first message may include indication information of a first algorithm, and the first algorithm may be an encryption algorithm used between the first device and the first terminal device; the using module 1120 may be used to use the first algorithm to perform encryption with the first device; wherein the first algorithm may be determined based on the first information, and the first information may be used to indicate whether the first terminal device supports a first type of algorithm, and the first type of algorithm is a 256-bit encryption algorithm.
- the first information may include one or more first identifiers, and the one or more first identifiers may be used to indicate the one or more first type of algorithms supported by the first terminal device.
- the first information may include first indication information, and the first indication information may be used to indicate whether the first terminal device supports the first type of algorithm.
- the first information may include second indication information, and the second indication information may be used to instruct the first device to use the first type of algorithm as the first algorithm.
- the first algorithm may be an algorithm of the first type.
- the first algorithm may be a second type of algorithm, which is a 128-bit encryption algorithm.
- the first algorithm may be the second type of algorithm.
- the communication device may further include a sending module 1130.
- the sending module 1130 may be configured to send the first information to the first device before the first terminal device receives the first message sent by the first device.
- the first information is carried in first capability information, and the first capability information can be used to indicate the security capability of the first terminal device.
- the first device may be an access network device or a core network device.
- Figure 12 is a schematic diagram of the structure of a communication device according to an embodiment of the present application.
- the dashed lines in Figure 12 indicate that the unit or module is optional.
- Apparatus 1200 may be used to implement the method described in the above method embodiment.
- Apparatus 1200 may be a chip, a terminal device, or a network device.
- the apparatus 1200 may include one or more processors 1210.
- the processors 1210 may support the apparatus 1200 in implementing the methods described in the method embodiments above.
- the processor 1210 may be a general-purpose processor or a special-purpose processor.
- the processor may be a central processing unit (CPU).
- the processor may be another general-purpose processor, a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field programmable gate array (FPGA), or other programmable logic device, discrete gate or transistor logic device, discrete hardware component, etc.
- a general-purpose processor may be a microprocessor or any conventional processor.
- the apparatus 1200 may also include one or more memories 1220.
- the memories 1220 store programs that can be executed by the processor 1210, causing the processor 1210 to perform the methods described in the method embodiments above.
- the memory 1220 may be independent of the processor 1210 or integrated into the processor 1210.
- the apparatus 1200 may further include a transceiver 1230.
- the processor 1210 may communicate with other devices or chips via the transceiver 1230.
- the processor 1210 may transmit and receive data with other devices or chips via the transceiver 1230.
- the present invention also provides a computer-readable storage medium for storing a program.
- the computer-readable storage medium can be applied to the communication device provided in the present invention, and the program enables a computer to execute the method in each embodiment of the present invention.
- the present application also provides a computer program product.
- the computer program product includes a program.
- the computer program product can be applied to the communication device provided in the present application, and the program enables a computer to execute the method in each embodiment of the present application.
- the embodiments of the present application also provide a computer program.
- the computer program can be applied to the communication device provided in the embodiments of the present application, and the computer program enables a computer to execute the methods in the various embodiments of the present application.
- the term "indication” may refer to a direct indication, an indirect indication, or an indication of an association.
- “A indicates B” may refer to a direct indication of B, e.g., B can obtain information through A; it may refer to an indirect indication of B, e.g., A indicates C, e.g., B can obtain information through C; or it may refer to an association between A and B.
- B corresponding to A means that B is associated with A and B can be determined based on A.
- determining B based on A does not mean determining B based solely on A, but B can also be determined based on A and/or other information.
- the term "corresponding" may indicate a direct or indirect correspondence between the two, or may indicate a direct or indirect correspondence between the two. It has an associative relationship, which can also be a relationship of indication and indication, configuration and configuration, etc.
- the “protocol” may refer to a standard protocol in the communications field, for example, it may include an LTE protocol, an NR protocol, and related protocols used in future communication systems, and the present application does not limit this.
- the term "and/or” is simply a description of the association relationship between related objects, indicating that three relationships can exist.
- a and/or B can represent: A exists alone, A and B exist at the same time, and B exists alone.
- the character "/" in this document generally indicates that the related objects are in an "or” relationship.
- the term “include” can refer to direct inclusion or indirect inclusion.
- the term “include” in the embodiments of this application can be replaced with “indicates” or “is used to determine.”
- “A includes B” can be replaced with “A indicates B” or "A is used to determine B.”
- the size of the serial numbers of the above-mentioned processes does not mean the order of execution.
- the execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of the present application.
- the disclosed systems, devices, and methods can be implemented in other ways.
- the device embodiments described above are merely illustrative.
- the division of the units is merely a logical functional division.
- other division methods may be used, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not implemented.
- the coupling or direct coupling or communication connection between each other shown or discussed can be through some interfaces, indirect coupling or communication connection between devices or units, and can be electrical, mechanical, or other forms.
- the units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the present embodiment.
- the functional units in the various embodiments of this application can be integrated into a processing unit, each unit can exist physically separately, or two or more units can be integrated into a single unit.
- all or part of the embodiments can be implemented by software, hardware, firmware or any combination thereof.
- all or part of the embodiments can be implemented in the form of a computer program product.
- the computer program product includes one or more computer instructions.
- the computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device.
- the computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another computer-readable storage medium.
- the computer instructions can be transmitted from one website, computer, server or data center to another website, computer, server or data center by wired (such as coaxial cable, optical fiber, digital subscriber line (DSL)) or wireless (such as infrared, wireless, microwave, etc.) means.
- the computer-readable storage medium can be any available medium that can be read by a computer or a data storage device such as a server or data center that includes one or more available media integrated.
- the available medium may be a magnetic medium (e.g., a floppy disk, a hard disk, a magnetic tape), an optical medium (e.g., a digital versatile disc (DVD)), or a semiconductor medium (e.g., a solid state disk (SSD)), etc.
Landscapes
- Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Mobile Radio Communication Systems (AREA)
Abstract
提供了一种无线通信方法及通信设备,该方法包括:第一设备接收第一信息,所述第一信息用于指示第一终端设备是否支持第一类型的算法,所述第一类型的算法为256位的加密算法;所述第一设备基于所述第一信息确定第一算法,所述第一算法为所述第一设备与所述第一终端设备之间使用的加密算法。在本申请中,第一设备可以根据第一信息确定第一终端设备是否支持256位的加密算法。基于此,第一设备可以实现与第一终端设备之间的加密算法协商,有助于通信系统实现不同加密算法强度的并行支持。
Description
本申请涉及通信技术领域,并且更为具体地涉及一种无线通信方法及通信设备。
在无线通信系统中,为了抵抗量子攻击,可能会引入256位(或称“256比特(bits)”)的加密算法进行通信设备之间的对称加密。因此,不同的通信设备可能会支持不同强度的加密算法。此时,这些通信设备之间如何进行算法协商,是一个有待解决的问题。
发明内容
本申请提供一种无线通信方法及通信设备。下面对本申请涉及的各个方面进行介绍。
第一方面,提供一种无线通信方法,包括:第一设备接收第一信息,所述第一信息用于指示第一终端设备是否支持第一类型的算法,所述第一类型的算法为256位的加密算法;所述第一设备基于所述第一信息确定第一算法,所述第一算法为所述第一设备与所述第一终端设备之间使用的加密算法。
第二方面,提供一种无线通信方法,包括:第一终端设备接收第一设备发送的第一消息,所述第一消息包括第一算法的指示信息,所述第一算法为所述第一设备与所述第一终端设备之间使用的加密算法;其中,所述第一算法基于第一信息确定,所述第一信息用于指示所述第一终端设备是否支持第一类型的算法,所述第一类型的算法为256位的加密算法。
第三方面,提供一种通信设备,所述通信设备为第一设备,所述通信设备包括:接收模块,用于接收第一信息,所述第一信息用于指示第一终端设备是否支持第一类型的算法,所述第一类型的算法为256位的加密算法;确定模块,用于基于所述第一信息确定第一算法,所述第一算法为所述第一设备与所述第一终端设备之间使用的加密算法。
第四方面,提供一种通信设备,所述通信设备为第一终端设备,所述通信设备包括:接收模块,用于接收第一设备发送的第一消息,所述第一消息包括第一算法的指示信息,所述第一算法为所述第一设备与所述第一终端设备之间使用的加密算法;其中,所述第一算法基于第一信息确定,所述第一信息用于指示所述第一终端设备是否支持第一类型的算法,所述第一类型的算法为256位的加密算法。
第五方面,提供一种通信设备,包括存储器和处理器,所述存储器用于存储程序,所述处理器用于调用所述存储器中的程序,以使所述终端设备执行如第一方面所述的方法。
第六方面,提供一种通信设备,包括存储器和处理器,所述存储器用于存储程序,所述处理器用于调用所述存储器中的程序,以使所述网络设备执行如第二方面所述的方法。
第七方面,提供一种装置,包括处理器,用于从存储器中调用程序,以使所述装置执行如第一方面或第二方面所述的方法。
第八方面,提供一种芯片,包括处理器,用于从存储器调用程序,使得安装有所述芯片的设备执行如第一方面或第二方面所述的方法。
第九方面,提供一种计算机可读存储介质,其上存储有程序,所述程序使得计算机执行如第一方面或第二方面所述的方法。
第十方面,提供一种计算机程序产品,包括程序,所述程序使得计算机执行如第一方面或第二方面所述的方法。
第十一方面,提供一种计算机程序,所述计算机程序使得计算机执行如第一方面或第二方面所述的方法。
在本申请中,第一设备可以根据第一信息确定第一终端设备是否支持256位的加密算法。基于此,第一设备可以实现与第一终端设备之间的加密算法协商,有助于通信系统实现不同加密算法强度的并行支持。
图1是本申请实施例适用的无线通信系统的结构示意图。
图2是5G安全密钥架构中密钥产生过程的示意性流程图。
图3是NAS安全模式命令过程的示意性流程图。
图4是AS安全模式命令过程的示意性流程图。
图5是本申请一实施例提供的无线通信方法的示意性流程图。
图6A~6B是本申请另一实施例提供的无线通信方法的示意性流程图。
图7是本申请的实施例一提供的无线通信方法的示意性流程图。
图8是本申请的实施例三提供的无线通信方法的示意性流程图。
图9A~9B是本申请的实施例五提供的无线通信方法的示意性流程图。
图10是本申请一实施例提供的通信设备的结构示意图。
图11是本申请另一实施例提供的通信设备的结构示意图。
图12是本申请实施例提供的通信装置的结构示意图。
下面将结合附图,对本申请中的技术方案进行描述。
通信系统架构
图1为本申请实施例适用的一种通信系统架构的示意图。该网络架构可以包括终端设备、接入网(access network,AN)网元以及核心网网元。
应理解,本申请实施例的技术方案可以应用于各种通信系统,例如:第六代(6th generation,6G)通信系统、第五代(5th generation,5G)系统或新无线(new radio,NR)、长期演进(long term evolution,LTE)系统、LTE频分双工(frequency division duplex,FDD)系统、LTE时分双工(time division duplex,TDD)等。本申请提供的技术方案还可以应用于未来的通信系统,如第六代移动通信系统,又如卫星通信系统,等等。
本申请实施例中的终端设备也可以称为用户设备(user equipment,UE)、接入终端、用户单元、用户站、移动站、移动台(mobile station,MS)、移动终端(mobile terminal,MT)、远方站、远程终端、移动设备、用户终端、终端、无线核心网网元、用户代理或用户装置。本申请实施例中的终端设备可以是指向用户提供语音和/或数据连通性的设备,可以用于连接人、物和机,例如具有无线连接功能的手持式设备、车载设备等。本申请的实施例中的终端设备可以是手机(mobile phone)、平板电脑(Pad)、笔记本电脑、掌上电脑、移动互联网设备(mobile internet device,MID)、可穿戴设备,虚拟现实(virtual reality,VR)设备、增强现实(augmented reality,AR)设备、工业控制(industrial control)中的无线终
端、无人驾驶(self driving)中的无线终端、远程手术(remote medical surgery)中的无线终端、智能电网(smart grid)中的无线终端、运输安全(transportation safety)中的无线终端、智慧城市(smart city)中的无线终端、智慧家庭(smart home)中的无线终端等。可选地,终端设备可以用于充当基站。例如,终端设备可以充当调度实体,其在车辆外联(vehicle-to-everything,V2X)或设备到设备(device to device,D2D)等中的终端设备之间提供侧行链路信号。比如,蜂窝电话和汽车利用侧行链路信号彼此通信。蜂窝电话和智能家居设备之间通信,而无需通过基站中继通信信号。
接入网网元可以为接入网设备。接入网设备可以是终端通过无线方式接入到该网络架构中的接入设备,主要负责空口侧的无线资源管理、服务质量(quality of service,QoS)管理、数据压缩和加密等。接入网设备也可以称为无线接入网(radio access network,RAN)设备,如接入网设备可以是基站。基站可以广义的覆盖如下中的各种名称,或与如下名称进行替换,比如:节点B(NodeB)、演进型基站(evolved NodeB,eNB)、下一代基站(next generation NodeB,gNB)、中继站、接入点、传输点(transmitting and receiving point,TRP)、发射点(transmitting point,TP)、主站(master eNB,MeNB)、辅站(secondary eNB,SeNB)、多标准无线(multi-standard radio,MSR)节点、家庭基站、网络控制器、接入节点、无线节点、接入点(access point,AP)、传输节点、收发节点、基带单元(base band unit,BBU)、射频拉远单元(remote radio unit,RRU)、有源天线单元(active antenna unit,AAU)、射频头(remote radio head,RRH)、中心单元(central unit,CU)、分布式单元(distributed unit,DU)、定位节点等。基站可以是宏基站、微基站、中继节点、施主节点或类似物,或其组合。基站还可以指用于设置于前述设备或装置内的通信模块、调制解调器或芯片。基站还可以是移动交换中心以及D2D、V2X、机器到机器(machine-to-machine,M2M)通信中承担基站功能的设备、6G网络中的网络侧设备、未来的通信系统中承担基站功能的设备等。基站可以支持相同或不同接入技术的网络。本申请的实施例对接入网设备所采用的具体技术和具体设备形态不做限定。
基站可以是固定的,也可以是移动的。例如,直升机或无人机可以被配置成充当移动基站,一个或多个小区可以根据该移动基站的位置移动。在其他示例中,直升机或无人机可以被配置成用作与另一基站通信的设备。
在一些部署中,本申请实施例中的接入网设备可以是指CU或者DU,或者,接入网设备包括CU和DU。gNB还可以包括AAU。
核心网网元的类型(type)可以包括用户面功能(user plane function,UPF)网元、接入和移动性管理功能(access and mobility management function,AMF)网元、会话管理功能(session management function,SMF)网元、策略控制功能(policy control function,PCF)网元、应用功能(application function,AF)、数据网络(data network,DN)、网络切片选择功能(network slice selection function,NSSF)、鉴权服务功能(authentication server function,AUSF)、统一数据管理功能(unified data management,UDM)、网络开放功能(the network exposure function,NEF)、网络仓储功能(network repository function,NRF)、网络切片选择的认证和授权功能(network slice-specific authentication and authorization function,NSSAAF)。此外,一些网络(例如5G网络)还在核心网中增加了网络数据分析功能(network data analytics function,NWDAF)。NWDAF可以进一步分为分析逻辑功能(analytics logical function,AnLF)和模型训练逻辑功能(model training logical function,MTLF)。在一些通信系统(例如5G系统)中,核心网网元也可以称为网络功能(network function,NF)。
图1中的各网元既可以是硬件设备中的网络元件,也可以是在专用硬件上运行的软件功能,或者是平台(例如,云平台)上实施例化的虚拟化功能。需要说明的是,在上述图所示的网络架构中,仅仅是示
例性说明整个网络架构中所包括的网元。在本申请实施例中,并不限定整个网络架构中所包括的网元。
本领域技术人员可以理解,图1中示出的网络架构并不构成对网络架构的限定,具体实现时,该网络架构可以包括比图示更多或更少的网元,或者组合某些网元等。应理解,图1中以(R)AN的方式表征AN或RAN。
在一些场景中,网络设备和终端设备可以部署在陆地上,包括室内或室外、手持或车载;也可以部署在水面上;还可以部署在空中的飞机、气球和卫星上。本申请实施例中对网络设备和终端设备所处的场景不做限定。
对称加密算法(ciphering algorithm)和密钥架构
5G安全中使用的对称加密算法可以包括128-NEA1、128-NEA2、128-NEA-3。这三种对称加密算法分别对应snow 3G、高级加密标准(advanced encryption standard,AES)算法和祖冲之(zuchongzhi,ZUC)算法,这三种对称加密算法的详细内容可以如表1所示。第四代(4th generation,4G)中同样也使用了这三种对称加密算法,分别命名为128-EEA1、128-EEA2、128-EEA3。
表1对称加密算法表
5G安全密钥架构中,产生密钥的长度可以如图2所示。由图2可知,用于保护会话(即保护NAS与AS层安全)的密钥长度均是128比特。
NAS算法协商
每个AMF可以通过网络管理配置允许使用的算法列表,即一份NAS完整性算法(integrity algorithm)列表和一份NAS加密算法列表,这些列表应根据运营商决定的优先级进行排序。为了建立NAS安全上下文,AMF可以选择一种NAS加密算法和一种NAS完整性保护算法。然后,AMF可以启动NAS安全模式命令过程,并在发送给UE的消息中包含所选算法和UE安全能力(以检测攻击者对UE安全能力的修改),AMF可以根据列表排序选择具有最高优先级的NAS算法。
NAS安全模式命令过程可以如图3所示,包括步骤S310~S360。在步骤S310,AMF开启完整性保护。AMF可以根据UE安全能力与本地配置的算法列表,选择对应的安全算法(加密算法和完整性算法)以开启完整性保护。在步骤S320,AMF向UE发送NAS安全模式命令(security mode command,SMC)消息。NAS SMC中可以包含AMF所选择的算法和UE安全能力,以及NAS密钥改变指示(例如K_AMF_change_flag)、NAS密钥集标识符(NAS key set identifier,ngKSI)、防架构之间降价攻击(Anti-Bidding down Between Architectures,ABBA)参数(parameter)、请求初始NAS消息标志(request initial NAS message flag)、NAS消息验证码(message authentication code,MAC)等。
在步骤S330,UE可以通过验证NAS SMC消息的完整性,如果成功则可以开启上行加密、下行解密和完整性保护。UE可以通过验证NAS SMC消息的完整性,确认该消息未被篡改,然后通过检查AMF返回的UE安全能力,确认未遭受降价攻击。UE验证成功后,可以使用AMF选择的算法开启NAS层的加密和完整性保护。在步骤S340,AMF可以开启上行解密。在步骤S350,UE可以向AMF发送NAS安全模式完成(security mode complete)消息,其中可以包括NAS容器中的完成初始NAS消息(complete initial NAS message in NAS container)以及NAS MAC等。在步骤S360,AMF开启下行加密。
如果发生了AMF的改变,例如N2切换或者移动注册更新,则源AMF可以将UE安全能力发给目标AMF,目标AMF可以向UE发送选择好的算法。在N2切换的场景下,目标AMF可以用NAS容器(container),通过源AMF向UE发送该信息。在移动注册更新的场景下,目标AMF与UE间可以使用NAS SMC过程激活其选择的算法。
AS算法协商
每个gNB/ng-eNB可以通过网络管理配置允许使用的算法列表,即一份完整性算法列表和一份加密算法列表,这些列表可以根据运营商决定的优先级进行排序。当在gNB/ng-eNB与UE间建立AS安全上下文时,AMF可以向gNB/ng-eNB发送UE的5G安全能力。gNB/ng-eNB可以从其配置列表中选择具有最高优先级且也存在于UE的5G安全能力中的算法,所选择的算法可以在AS SMC过程中向UE指示。所选加密算法可以用于用户平面数据和无线资源控制(radio resource control,RRC)信令的加密,所选择的完整性算法可以用于用户平面数据和RRC信令的完整性保护。
AS安全模式命令过程可以如图4所示,包括步骤S410~S470。在步骤S410,gNB或ng-eNB开启RRC完整性保护。gNB或ng-eNB可以根据UE安全能力与本地配置的算法列表,选择对应的RRC和用户面(user plane,UP)保护的安全算法,以开启RRC完整性保护。在步骤S420,gNB或ng-eNB可以向UE发送AS SMC消息。AS SMC消息中可以包含gNB或ng-eNB所选择的算法和UE安全能力以及消息验证码-完整性(message authentication code-integrity,MAC-I)信息。在步骤S430,gNB或ng-eNB可以开启RRC下行加密。在步骤S440,UE验证AS SMC消息的完整性,如果成功,则开启RRC完整性保护和RRC下行解密。UE可以通过(MAC-I)验证该消息的完整性,确认该消息未被篡改,通过检查gNB或ng-eNB返回的UE安全能力,确认未遭受降价攻击。UE验证成功后,可以使用gNB或ng-eNB选择的算法开启RRC层的加密和完整性保护以及下行解密。在步骤S450,UE可以向gNB或
ng-eNB发送AS SMC消息,其中可以包含MAC-I。在步骤S460,UE可以开启RRC上行加密。在步骤S470,gNB或ng-eNB可以开启RRC上行解密。
对于Xn切换过程,UE从源基站切换到目标基站,源基站可以向目标基站发送UE的安全能力和源小区(source cell)使用的安全算法,目标基站可以根据UE安全能力与本地配置的算法列表选择算法,如果选择了不同的算法,则目标基站可以通过源基站向UE发送的交接命令(handover command)消息中携带该选好的算法。在4G基站和5G基站之间切换时必须携带目标基站选择的算法。目标基站必须给AMF发送UE安全能力用于AMF验证,如果和本地存储的UE安全能力不一致,则AMF向目标基站发送的路径转换确认(path switch acknowledge)消息中携带UE安全能力,目标基站重新选择算法后,使用小区内(intra-cell)切换与UE更新算法。
对于N2切换,源AMF可以向目标AMF发送UE的安全能力,目标AMF可以向目标基站发送NGAP移交请求(NGAP HANDOVER REQUEST)消息,其中包含UE的安全能力。源基站可以向目标基站发送源到目标的透明容器(source to target transparent container),其中包含source cell使用的算法。目标基站可以根据UE安全能力与本地配置的算法列表选择算法,如果选择了不同的算法,则目标基站向UE发送的handover command消息中携带该选好的算法。
量子安全算法
量子计算机是一种利用量子力学现象(叠加和纠缠)进行计算和操纵数据的设备。当前流行的密码算法的安全基础,建立在一些棘手的数学问题上。由于量子计算机固有的并行属性,所以一些量子算法可以比经典算法更有效地解决困难的数学问题,这对当代密码学构成了严重而现实的安全威胁。攻击者可以在量子计算机上使用Grover算法将有效密钥大小减半,即将对称密钥算法的安全强度减半。因此,为了实现抗量子攻击,对称密钥算法的密钥规模必须加倍。AES-128、SNOW 3G和ZUC-128等128位对称密钥算法,是NAS信令、RRC信令和UP数据安全性的基础。为抵抗量子攻击,可以考虑在系统中引入256位的对称密钥算法,是否需要引入更长的MAC仍需进一步研究。
如前文所述,4G、5G系统中使用的NAS信令、RRC信令,和用户数据的加密算法均是128位的对称加密算法。随着终端、无线接入网设备(例如gNB、ng-eNB)、核心网设备(例如AMF)支持算法能力的升级,这些通信实体可能将逐渐增强算法能力,支持256bits算法以抵御量子攻击,例如在6G通信系统中部署了支持高强度算法的通信实体。因此在通信系统中无可避免的存在支持不同加密算法强度的实体。因此需要设计这些实体间的算法协商方式,使得128位加密算法与256位加密算法可以分阶段引入和并行支持。
基于此,下面对本申请实施例的方法进行详细介绍。在本申请中,第一设备可以根据第一信息确定第一终端设备是否支持256位的加密算法。基于此,第一设备可以实现与第一终端设备之间的加密算法协商,有助于通信系统实现不同加密算法强度的并行支持。
如图5所示,本申请实施例提供了一种无线通信方法,该方法可以由第一设备和第一终端设备执行。其中,第一设备可以是前文所述的接入网设备,例如gNB。第一设备也可以是前文所述的核心网网元(或称“核心网设备”),例如AMF。第一终端设备可以是前文所述的任一终端设备,第一终端设备可以与第一设备建立连接。
图5所示的方法可以包括步骤S510~S520。在步骤S510,第一设备接收第一信息。第一信息可以用于指示第一终端设备是否支持第一类型的算法,第一类型的算法为256位的加密算法。即第一设备可以根据第一信息确定第一终端设备是否支持256位的算法。在步骤S520,第一设备可以基于第一信息确定第一算法,第一算法为第一设备与第一终端设备之间使用的加密算法。即第一设备可以基于第一终
端设备是否支持256位的算法,确定与第一终端设备之间的加密算法以实现算法协商。值得注意的是,本申请实施例中的256位的算法可以指Snow 3G 256-为基础的(based)算法、AES 256-based算法、ZUC 256-based算法。本申请实施例中的加密可以指可认证的加密(authenticated encryption),本申请实施例中的256位的算法可以用于可认证的加密。可认证的加密是一种联合的算法,可以在一个单独的过程中执行加密和/或完整性保护。可认证的加密可以根据算法的输入,对应地执行加密和/或完整性保护。
下面对第一信息进行详细说明。第一信息可以包括以下中的一种或多种:一个或多个第一标识;第一指示信息;第二指示信息。
作为一个示例,若第一终端设备支持第一类型的算法,则第一信息可以包括一个或多个第一标识,一个或多个第一标识可以用于指示第一终端设备支持的一个或多个第一类型的算法。若第一终端设备支持256位的加密算法,则第一信息可以包括第一标识以指示第一终端设备支持的256算法。若第一终端设备不支持256位的加密算法,则第一信息中可以不包括第一标识。即一个或多个第一标识可以组成第一终端设备支持的256位算法的列表,第一信息可以包括该算法列表。其中,第一标识可以是算法标识。例如,标识256-NEA1可以用于表示snow 5G 256bits算法,标识256-NEA2可以用于表示AES256bits算法,标识256-NEA3可以用于表示ZUC 256bits算法。基于第一标识,有助于第一设备明确第一终端设备支持的256位的加密算法。
作为另一个示例,第一信息可以包括第一指示信息,第一指示信息可以用于指示第一终端设备是否支持第一类型的算法。在本申请中,第一指示信息的形式可以不作限定。示例性地,第一指示信息可以占据一个比特位。当第一指示信息的取值为第一值时,可以表示第一终端设备支持256位的加密算法。当第一指示信息的取值为第二值时,可以表示第一终端设备不支持256位的加密算法。或者,当第一信息包括该比特位时,可以表示第一终端设备支持256位的加密算法。当第一信息不包括该比特位时,可以表示第一终端设备不支持256位的加密算法。基于第一指示信息,有助于第一设备快速确定第一终端设备是否支持256位的加密算法。
作为另一个示例,若第一终端设备支持第一类型的算法,第一信息可以包括第二指示信息,第二指示信息可以用于指示使用第一类型的算法作为第一算法。即当第一终端设备支持256位的加密算法时,第一信息可以包括第二指示信息,以指示第一设备使用256位的加密算法作为第一设备和第一终端设备之间的加密算法。在本申请中,第二指示信息的形式可以不作限定。示例性地,第二指示信息可以占据一个比特位。当第二指示信息的取值为第一值时,可以表示使用256位的加密算法作为第一设备和第一终端设备之间的加密算法。当第二指示信息的取值为第二值时,可以表示不使用256位的加密算法作为第一设备和第一终端设备之间的加密算法。或者,当第一信息包括该比特位时,可以表示使用256位的加密算法作为第一设备和第一终端设备之间的加密算法。当第一信息不包括该比特位时,可以表示不使用256位的加密算法作为第一设备和第一终端设备之间的加密算法。基于第二指示信息,有助于第一设备更高效地确定第一算法。
值得注意的是,第一信息也可以包括上述信息中的多种,在此不再进行赘述。
在一些实现方式中,第一信息还可以包括第三指示信息,第三指示信息可以用于指示第一类型的算法用于执行加密和/或完整性保护。如果第一类型的算法用于执行加密,即表示第一类型的算法可以用于执行前文所述的可认证的加密中的加密行为。如果第一类型的算法用于执行完整性保护,即表示第一类型的算法可以用于执行前文所述的可认证的加密中的完整性保护行为。进一步地,第三指示信息可以承载于第一指示信息或第二指示信息中。
第一信息可以承载于第一能力信息,第一能力信息可以用于指示第一终端设备的安全能力。即第一能力信息可以是第一终端设备的安全能力信息,第一设备可以基于第一终端设备的安全能力信息,确定第一终端设备是否支持256位的加密算法。第一能力信息可以由第一终端设备发送给第一设备,或者第一能力信息也可以由核心网设备(例如AMF)发送给第一设备,或者第一能力信息还可以由其他第一设备发送给第一设备。例如,当第一终端设备初始接入第一设备时,第一终端设备可以向第一设备上报自身的安全能力信息。又如,当第一终端设备初始接入第一设备时,核心网设备也可以向第一设备发送第一终端设备的安全能力信息(此时第一设备是接入网设备)。又如,当第一终端设备与第一设备连接过程中的由于切换或移动注册更新等导致第一设备变更,则源第一设备可以向目标第一设备发送第一终端设备的安全能力信息。基于第一能力信息,有助于第一设备确定第一设备与第一终端设备之间使用的加密算法。
下面对第一设备如何确定第一算法进行详细介绍。示例性地,第一设备基于第一信息确定第一算法可以包括不同的情况。在一种情况中,若第一终端设备支持第一类型的算法,且第一设备支持第一类型的算法,则第一设备可以优先选择第一类型的算法作为第一算法。即当第一终端设备和第一设备都支持256位的加密算法时,则第一设备优先选择256位的加密算法作为两者之间使用的加密算法。在另一种情况中,若第一终端设备支持第一类型的算法,但第一设备不支持第一类型的算法,则第一设备可以选择第二类型的算法作为第一算法,第二类型的算法为128位的加密算法。即当第一终端设备支持256位的加密算法,但第一设备不支持256位的加密算法时,则第一设备可以选择128位的加密算法作为两者之间使用的加密算法。在另一种情况中,若第一终端设备不支持第一类型的算法,则第一设备可以选择第二类型的算法作为第一算法。即当第一终端设备不支持256位的加密算法时,则第一设备可以选择128位的加密算法作为两者之间使用的加密算法。基于此,有助于实现第一终端设备和第一设备之间的加密算法的协调。
进一步地,对第一设备如何使用第一算法进行举例介绍。作为一个示例,第一设备是核心网设备。如果核心网设备根据第一信息,确定使用第一类型的算法,则核心网设备可以直接使用256bits密钥用于NAS加密(可以是可认证的加密)。如果核心网设备根据第一信息,确定使用第二类型的算法,则核心网设备可以对生成的256bits密钥KNASenc使用Trunc函数(即截断的方式),生成128bits的密钥用于NAS加密(可以是可认证的加密)。作为另一个示例,第一设备是接入网设备。接入网设备根据第一信息确定使用第一类型的算法时,则接入网设备可以直接使用256bits密钥用于AS加密(可以是可认证的加密)。接入网设备根据第一信息确定使用第二类型的算法时,接入网设备可以对密钥KRRCenc和KUPenc使用Trunc函数,生成128bits的密钥,分别用于保护RRC层和UP(用户)面(可以是可认证的加密)。
在一些实现方式中,第一设备根据第一信息确定第一算法后,可以向第一终端设备发送第一消息,第一消息包括可以包括第一算法的指示信息。即第一设备根据第一信息确定第一算法后,可以向第一终端设备指示第一算法,有助于实现和第一终端设备之间的加密算法协商。第一终端设备根据第一消息确定第一算法后,对第一算法的使用可以如下示例。如果第一终端设备根据第一消息,确定使用第一类型的算法,则第一终端设备可以直接使用256bits密钥用于与第一设备之间的加密(可以是可认证的加密)。如果第一终端设备根据第一消息,确定使用第二类型的算法,则第一终端设备可以对生成的256bits密钥KNASenc使用Trunc函数(即截断的方式),生成128bits的密钥用于与第一设备之间的加密(可以是可认证的加密)。
在一些实现方式中,参见图6A所示,本申请实施例的无线通信方法还可以包括步骤S630。在步骤
S630,第一设备向第二设备发送第二信息,第二信息可以用于指示第二算法,第二算法可以为第二设备和第一终端设备之间使用的加密算法,第二算法可以由第一设备基于第一信息确定。即第一设备可以基于第一信息,协商出第二设备和第一终端设备之间使用的加密算法。例如,在双连接场景中,第一设备可以是主节点(masternode,MN)(又称主基站),第二设备可以是辅节点(secondarynode,SN)(又称辅基站),当发生SN的切换时,MN可以基于第一信息为SN协商出SN与终端设备之间使用的加密算法。基于此,有助于实现第一终端设备和第二设备之间的加密算法的协调。
在另一些实现方式中,参见图6B所示,本申请实施例的无线通信方法还可以包括步骤S630。在步骤S630,第一设备向第二设备发送第一信息,第一信息可以用于第二设备确定第二算法,第二算法可以为第二设备与第一终端设备之间的加密算法。即第一设备可以向第二设备发送第一信息,以帮助第二设备确定第二设备与第一终端设备之间的加密算法。例如,在双连接场景中,第一设备可以是MN,第二设备可以是SN,当发生SN的切换时,MN可以向SN发送第一信息,以便SN协商出SN与终端设备之间使用的加密算法。基于此,有助于实现第一终端设备和第二设备之间的加密算法的协调。
下面结合实施例一~实施例五对本申请实施例的无线通信方法进行详细介绍。其中,实施例一和实施例二以第一设备是核心网设备AMF为例,实施例三~实施例五以第一设备是接入网设备gNB/ng-eNB为例。示例性地,下面各实施例中的第一信息承载于UE安全能力。UE安全能力中可以包含UE支持的256bits算法标识(即一个或多个第一标识)/UE支持256bits的算法的指示(indicator of supporting256bits algorithm)(即第一指示信息)/使用256bits的算法的指示(即第二指示信息)。
实施例一
参见图7,在实施例一中,UE与AMF之间在初始接入过程中进行算法协商。在步骤S710,UE向AMF发送NAS消息,NAS消息中可以包括UE的安全能力,其中可以包含UE支持的256bits算法标识或支持256bits算法的指示。在步骤S720,AMF开启完整性保护。AMF可以根据UE安全能力与本地配置的算法列表,选择对应的安全算法(加密算法和完整性算法)以开启完整性保护。值得注意的是,支持256bits算法的AMF本地配置的算法列表中,所支持的256bits算法比所支持的128bits算法具有更高优先级。当AMF也支持256bits的算法,则AMF可以优先选择256bits的算法。当AMF不支持256bits的算法,则AMF可以选择128bits的算法。在步骤S730,AMF向UE发送NAS SMC消息。NAS SMC中可以包含AMF所选择的算法和UE安全能力等。其余步骤与图3所示的NAS算法协商过程相同,在此不再赘述。
实施例二
在实施例二中,UE与AMF之间在切换或移动注册更新场景中进行算法协商。在切换或移动注册更新场景中,服务UE的AMF发生改变。UE从源AMF切换到目标AMF,源AMF可以将UE安全能力发送给目标AMF,其中可以包含UE支持的256bits算法标识或UE支持256bits算法的指示。或者,UE可以向目标AMF发送包含UE安全能力的NAS消息,其中包含UE支持的256bits算法标识或UE支持256bits算法的指示或AMF和UE之间使用256bits的算法的指示。AMF可以根据UE安全能力与本地配置的算法列表,选择对应的安全算法(加密算法和完整性算法)以开启完整性保护,其余步骤在此不再进行赘述。
当通信系统要求NAS的安全保护使用256bits算法且部署了256bits能力的核心网设备时,基于实施例一和实施例二,可以实现UE与核心网设备间的算法协商,有助于128位与256位加密算法的分阶段引入和并行支持。
实施例三
参见图8,在实施例三中,UE与gNB/ng-eNB之间在初始接入过程中进行算法协商。在步骤S810,gNB/ng-eNB获取UE的安全能力,其中可以包含UE支持的256bits算法标识或UE支持256bits算法的指示。gNB可以通过UE上报或AMF发送,获取到UE的安全能力。在步骤S820,gNB/ng-eNB开启完整性保护。gNB/ng-eNB可以根据UE安全能力与本地配置的算法列表,选择对应的RRC和UP保护的安全算法。值得注意的是,支持256bits算法的gNB/ng-eNB本地配置的算法列表中,所支持的256bits算法比所支持的128bits算法具有更高优先级。当gNB/ng-eNB也支持256bits的算法,则gNB/ng-eNB可以优先选择256bits的算法。当gNB/ng-eNB不支持256bits的算法,则gNB/ng-eNB可以选择128bits的算法。在步骤S830,gNB/ng-eNB向UE发送AS SMC消息。AS SMC中可以包含gNB/ng-eNB所选择的算法和UE安全能力等。其余步骤与图4所示的AS算法协商过程相同,在此不再赘述。
实施例四
在实施例四中,UE与gNB/ng-eNB之间在Xn切换或N2切换场景中进行算法协商。在Xn切换或N2切换场景,服务UE的gNB/ng-eNB发生改变。UE从源基站切换到目标基站,源基站可以向目标基站发送UE的安全能力和source cell使用的安全算法。其中,UE的安全能力可以包含UE支持的256bits算法标识或UE支持256bits算法的指示。目标基站可以根据UE安全能力与本地配置的算法列表选择算法。值得注意的是,支持256bits算法的gNB/ng-eNB本地配置的算法列表中,所支持的256bits算法比所支持的128bits算法具有更高优先级。当gNB/ng-eNB也支持256bits的算法,则gNB/ng-eNB可以优先选择256bits的算法。当gNB/ng-eNB不支持256bits的算法,则gNB/ng-eNB可以选择128bits的算法。
如果目标基站选择了不同的算法,例如在系统互操作的场景,支持256bits算法的UE从低算法强度的基站切换到高算法强度的基站,则目标基站可以通过源基站向UE发送的handover command消息中携带选好的256bits算法。
目标基站需要给AMF发送UE安全能力,用于AMF验证,如果和本地存储的UE安全能力不一致,则AMF向目标基站发送的path switch acknowledge消息中携带UE安全能力,目标基站重新选择算法后,使用intra-cell切换与UE更新算法。
实施例五
在实施例五中,UE与gNB/ng-eNB之间双连接的切换场景中进行算法协商。在双连接场景中,存在主基站MN与辅助基站SN,可能的基站切换场景包括:1.MN切换,SN不变;2.MN切换,SN切换;3.MN不变,SN切换。其中,当MN发生切换时,MN与UE间的算法协商与实施例三相同。
当MN不变而SN发生切换时,参见图9A,MN可以向目标SN发送UE的安全能力,用于UE与SN间的算法协商。或者参见图9B,MN可以根据本地的/SN发送的SN所支持的算法列表,和UE的安全能力,为UE和SN协商出安全算法。其中,UE的安全能力中可以包含UE支持的256bits算法标识,或者包含UE支持256bits算法的指示。
当通信系统要求AS的安全保护使用256bits算法且部署了256bits能力的接入网设备时,基于实施例三~实施例五,可以实现UE与接入网设备间的算法协商,有助于128位与256位加密算法的分阶段引入和并行支持。
上文结合图1至图9,详细描述了本申请的方法实施例,下面结合图10至图12,详细描述本申请的装置实施例。应理解,方法实施例的描述与装置实施例的描述相互对应,因此,未详细描述的部分可以参见前面方法实施例。
图10是本申请一实施例提供的通信设备的结构示意图。图10所示的通信设备1000为第一设备,
通信设备1000可以包括接收模块1010和确定模块1020。接收模块1010可以用于接收第一信息,第一信息可以用于指示第一终端设备是否支持第一类型的算法,第一类型的算法可以为256位的加密算法;确定模块1020可以用于基于第一信息确定第一算法,第一算法可以为第一设备与第一终端设备之间使用的加密算法。
在一些实现方式中,若第一终端设备支持第一类型的算法,第一信息可以包括一个或多个第一标识,一个或多个第一标识可以用于指示第一终端设备支持的一个或多个第一类型的算法。
在一些实现方式中,第一信息可以包括第一指示信息,第一指示信息可以用于指示第一终端设备是否支持第一类型的算法。
在一些实现方式中,若第一终端设备支持第一类型的算法,第一信息可以包括第二指示信息,第二指示信息可以用于指示第一设备使用第一类型的算法作为第一算法。
在一些实现方式中,第一信息可以承载于第一能力信息,第一能力信息可以用于指示第一终端设备的安全能力。
在一些实现方式中,第一设备基于第一信息确定第一算法可以包括:若第一终端设备支持第一类型的算法,且第一设备支持第一类型的算法,则第一设备可以优先选择第一类型的算法作为第一算法;若第一终端设备支持第一类型的算法,但第一设备不支持第一类型的算法,则第一设备可以选择第二类型的算法作为第一算法,第二类型的算法为128位的加密算法。若第一终端设备不支持第一类型的算法,则第一设备可以选择第二类型的算法作为第一算法。
在一些实现方式中,通信设备1000还可以包括第一发送模块1030。发送模块1030可以用于向第二设备发送第二信息,第二信息可以用于指示第二算法,第二算法可以为第二设备和第一终端设备之间的加密算法,第二算法可以由第一设备基于第一信息确定。
在一些实现方式中,通信设备1000还可以包括第二发送模块1040。发送模块1040可以用于向第二设备发送第一信息,第一信息可以用于第二设备确定第二算法,第二算法为第二设备与第一终端设备之间的加密算法。
在一些实现方式中,第一设备可以为接入网设备。
在一些实现方式中,第一设备可以为核心网设备。
图11是本申请另一实施例提供的通信设备的结构示意图。图11所示的通信设备1100为第一终端设备,通信设备1100可以包括接收模块1110和使用模块1120。接收模块1110可以用于接收第一设备发送的第一消息,第一消息可以包括第一算法的指示信息,第一算法可以为第一设备与第一终端设备之间使用的加密算法;使用模块1120可以用于使用第一算法进行与第一设备之间的加密;其中,第一算法可以基于第一信息确定,第一信息可以用于指示第一终端设备是否支持第一类型的算法,第一类型的算法为256位的加密算法。
在一些实现方式中,若第一终端设备支持第一类型的算法,第一信息可以包括一个或多个第一标识,一个或多个第一标识可以用于指示第一终端设备支持的一个或多个第一类型的算法。
在一些实现方式中,第一信息可以包括第一指示信息,第一指示信息可以用于指示第一终端设备是否支持第一类型的算法。
在一些实现方式中,若第一终端设备支持第一类型的算法,第一信息可以包括第二指示信息,第二指示信息可以用于指示第一设备使用第一类型的算法作为第一算法。
在一些实现方式中,若第一终端设备支持第一类型的算法,且第一设备支持第一类型的算法,则第一算法可以为第一类型的算法。
在一些实现方式中,若第一终端设备支持第一类型的算法,但第一设备不支持第一类型的算法,则第一算法可以为第二类型的算法,第二类型的算法为128位的加密算法。
在一些实现方式中,若第一终端设备不支持第一类型的算法,则第一算法可以为第二类型的算法。
在一些实现方式中,通信设备还可以包括发送模块1130。发送模块1130可以用于在第一终端设备接收第一设备发送的第一消息之前,向第一设备发送第一信息。
在一些实现方式中,第一信息承载于第一能力信息,第一能力信息可以用于指示第一终端设备的安全能力。
在一些实现方式中,第一设备可以为接入网设备或核心网设备。
图12是本申请实施例的通信装置的结构示意图。图12中的虚线表示该单元或模块为可选的。该装置1200可用于实现上述方法实施例中描述的方法。装置1200可以是芯片、终端设备或网络设备。
装置1200可以包括一个或多个处理器1210。该处理器1210可支持装置1200实现前文方法实施例所描述的方法。该处理器1210可以是通用处理器或者专用处理器。例如,该处理器可以为中央处理单元(central processing unit,CPU)。或者,该处理器还可以是其他通用处理器、数字信号处理器(digital signal processor,DSP)、专用集成电路(application specific integrated circuit,ASIC)、现成可编程门阵列(field programmable gate array,FPGA)或者其他可编程逻辑器件、分立门或者晶体管逻辑器件、分立硬件组件等。通用处理器可以是微处理器或者该处理器也可以是任何常规的处理器等。装置1200还可以包括一个或多个存储器1220。存储器1220上存储有程序,该程序可以被处理器1210执行,使得处理器1210执行前文方法实施例所描述的方法。存储器1220可以独立于处理器1210也可以集成在处理器1210中。装置1200还可以包括收发器1230。处理器1210可以通过收发器1230与其他设备或芯片进行通信。例如,处理器1210可以通过收发器1230与其他设备或芯片进行数据收发。
本申请实施例还提供一种计算机可读存储介质,用于存储程序。该计算机可读存储介质可应用于本申请实施例提供的通信设备中,并且该程序使得计算机执行本申请各个实施例中的方法。
本申请实施例还提供一种计算机程序产品。该计算机程序产品包括程序。该计算机程序产品可应用于本申请实施例提供的通信设备中,并且该程序使得计算机执行本申请各个实施例中的方法。
本申请实施例还提供一种计算机程序。该计算机程序可应用于本申请实施例提供的通信设备中,并且该计算机程序使得计算机执行本申请各个实施例中的方法。
应理解,本申请中的通信设备的全部或部分功能也可以通过在硬件上运行的软件功能来实现,或者通过平台(例如云平台)上实例化的虚拟化功能来实现。
应理解,本申请中术语“系统”和“网络”可以被可互换使用。另外,本申请使用的术语仅用于对本申请的具体实施例进行解释,而非旨在限定本申请。本申请的说明书和权利要求书及所述附图中的术语“第一”、“第二”、“第三”和“第四”等是用于区别不同对象,而不是用于描述特定顺序。此外,术语“包括”和“具有”以及它们任何变形,意图在于覆盖不排他的包含。
在本申请的实施例中,提到的“指示”可以是直接指示,也可以是间接指示,还可以是表示具有关联关系。举例说明,A指示B,可以表示A直接指示B,例如B可以通过A获取;也可以表示A间接指示B,例如A指示C,B可以通过C获取;还可以表示A和B之间具有关联关系。
在本申请实施例中,“与A相应的B”表示B与A相关联,根据A可以确定B。但还应理解,根据A确定B并不意味着仅仅根据A确定B,还可以根据A和/或其它信息确定B。
在本申请实施例中,术语“对应”可表示两者之间具有直接对应或间接对应的关系,也可以表示两者之间
具有关联关系,也可以是指示与被指示、配置与被配置等关系。
本申请实施例中,所述“协议”可以指通信领域的标准协议,例如可以包括LTE协议、NR协议以及应用于未来的通信系统中的相关协议,本申请对此不做限定。
本申请实施例中术语“和/或”,仅仅是一种描述关联对象的关联关系,表示可以存在三种关系,例如,A和/或B,可以表示:单独存在A,同时存在A和B,单独存在B这三种情况。另外,本文中字符“/”,一般表示前后关联对象是一种“或”的关系。
本申请的实施例中,所述“包括”可以指直接包括,也可以指间接包括。可选地,可以将本申请实施例中提到的“包括”替换为“指示”或“用于确定”。例如,A包括B,可以替换为A指示B,或A用于确定B。
在本申请的各种实施例中,上述各过程的序号的大小并不意味着执行顺序的先后,各过程的执行顺序应以其功能和内在逻辑确定,而不应对本申请实施例的实施过程构成任何限定。
在本申请所提供的几个实施例中,应该理解到,所揭露的系统、装置和方法,可以通过其它的方式实现。例如,以上所描述的装置实施例仅仅是示意性的,例如,所述单元的划分,仅仅为一种逻辑功能划分,实际实现时可以有另外的划分方式,例如多个单元或组件可以结合或者可以集成到另一个系统,或一些特征可以忽略,或不执行。另一点,所显示或讨论的相互之间的耦合或直接耦合或通信连接可以是通过一些接口,装置或单元的间接耦合或通信连接,可以是电性,机械或其它的形式。所述作为分离部件说明的单元可以是或者也可以不是物理上分开的,作为单元显示的部件可以是或者也可以不是物理单元,即可以位于一个地方,或者也可以分布到多个网络单元上。可以根据实际的需要选择其中的部分或者全部单元来实现本实施例方案的目的。另外,在本申请各个实施例中的各功能单元可以集成在一个处理单元中,也可以是各个单元单独物理存在,也可以两个或两个以上单元集成在一个单元中。
在上述实施例中,可以全部或部分地通过软件、硬件、固件或者其任意组合来实现。当使用软件实现时,可以全部或部分地以计算机程序产品的形式实现。所述计算机程序产品包括一个或多个计算机指令。在计算机上加载和执行所述计算机程序指令时,全部或部分地产生按照本申请实施例所述的流程或功能。所述计算机可以是通用计算机、专用计算机、计算机网络、或者其他可编程装置。所述计算机指令可以存储在计算机可读存储介质中,或者从一个计算机可读存储介质向另一个计算机可读存储介质传输,例如,所述计算机指令可以从一个网站站点、计算机、服务器或数据中心通过有线(例如同轴电缆、光纤、数字用户线(digital subscriber line,DSL))或无线(例如红外、无线、微波等)方式向另一个网站站点、计算机、服务器或数据中心进行传输。所述计算机可读存储介质可以是计算机能够读取的任何可用介质或者是包含一个或多个可用介质集成的服务器、数据中心等数据存储设备。所述可用介质可以是磁性介质,(例如,软盘、硬盘、磁带)、光介质(例如,数字通用光盘(digital video disc,DVD))或者半导体介质(例如,固态硬盘(solid state disk,SSD))等。
以上所述,仅为本申请的具体实施方式,但本申请的保护范围并不局限于此,任何熟悉本技术领域的技术人员在本申请揭露的技术范围内,可轻易想到变化或替换,都应涵盖在本申请的保护范围之内。因此,本申请的保护范围应以所述权利要求的保护范围为准。
Claims (47)
- 一种无线通信方法,其特征在于,包括:第一设备接收第一信息,所述第一信息用于指示第一终端设备是否支持第一类型的算法,所述第一类型的算法为256位的加密算法;所述第一设备基于所述第一信息确定第一算法,所述第一算法为所述第一设备与所述第一终端设备之间使用的加密算法。
- 根据权利要求1所述的方法,其特征在于,若所述第一终端设备支持所述第一类型的算法,所述第一信息包括一个或多个第一标识,所述一个或多个第一标识用于指示所述第一终端设备支持的一个或多个所述第一类型的算法。
- 根据权利要求1或2所述的方法,其特征在于,所述第一信息包括第一指示信息,所述第一指示信息用于指示所述第一终端设备是否支持所述第一类型的算法。
- 根据权利要求1或2所述的方法,其特征在于,若所述第一终端设备支持所述第一类型的算法,所述第一信息包括第二指示信息,所述第二指示信息用于指示所述第一设备使用所述第一类型的算法作为所述第一算法。
- 根据权利要求1至4中任一项所述的方法,其特征在于,所述第一信息承载于第一能力信息,所述第一能力信息用于指示所述第一终端设备的安全能力。
- 根据权利要求1至5中任一项所述的方法,其特征在于,所述第一设备基于所述第一信息确定第一算法包括:若所述第一终端设备支持所述第一类型的算法,且所述第一设备支持所述第一类型的算法,则所述第一设备优先选择所述第一类型的算法作为所述第一算法;若所述第一终端设备支持所述第一类型的算法,但所述第一设备不支持所述第一类型的算法,则所述第一设备选择第二类型的算法作为所述第一算法,所述第二类型的算法为128位的加密算法;若所述第一终端设备不支持所述第一类型的算法,则所述第一设备选择所述第二类型的算法作为所述第一算法。
- 根据权利要求1至6中任一项所述的方法,其特征在于,所述方法还包括:所述第一设备向第二设备发送第二信息,所述第二信息用于指示第二算法,所述第二算法为所述第二设备和所述第一终端设备之间使用的加密算法,所述第二算法由所述第一设备基于所述第一信息确定。
- 根据权利要求1至7中任一项所述的方法,其特征在于,所述方法还包括:所述第一设备向第二设备发送所述第一信息,所述第一信息用于所述第二设备确定第二算法,所述第二算法为所述第二设备与所述第一终端设备之间的加密算法。
- 根据权利要求1至8中任一项所述的方法,其特征在于,所述第一设备为接入网设备。
- 根据权利要求1至6中任一项所述的方法,其特征在于,所述第一设备为核心网设备。
- 一种无线通信方法,其特征在于,包括:第一终端设备接收第一设备发送的第一消息,所述第一消息包括第一算法的指示信息,所述第一算法为所述第一设备与所述第一终端设备之间使用的加密算法;第一终端设备使用所述第一算法进行与所述第一设备之间的加密;其中,所述第一算法基于第一信息确定,所述第一信息用于指示所述第一终端设备是否支持第一类型的算法,所述第一类型的算法为256位的加密算法。
- 根据权利要求11所述的方法,其特征在于,若所述第一终端设备支持所述第一类型的算法,所述第一信息包括一个或多个第一标识,所述一个或多个第一标识用于指示所述第一终端设备支持的一个或多个所述第一类型的算法。
- 根据权利要求11或12所述的方法,其特征在于,所述第一信息包括第一指示信息,所述第一指示信息用于指示所述第一终端设备是否支持所述第一类型的算法。
- 根据权利要求11或12所述的方法,其特征在于,若所述第一终端设备支持所述第一类型的算法,所述第一信息包括第二指示信息,所述第二指示信息用于指示所述第一设备使用所述第一类型的算法作为所述第一算法。
- 根据权利要求11至14中任一项所述的方法,其特征在于,若所述第一终端设备支持所述第一类型的算法,且所述第一设备支持所述第一类型的算法,则所述第一算法为所述第一类型的算法。
- 根据权利要求11至15中任一项所述的方法,其特征在于,若所述第一终端设备支持所述第一类型的算法,但所述第一设备不支持所述第一类型的算法,则所述第一算法为第二类型的算法,所述第二类型的算法为128位的加密算法。
- 根据权利要求11至16中任一项所述的方法,其特征在于,若所述第一终端设备不支持所述第一类型的算法,则所述第一算法为所述第二类型的算法。
- 根据权利要求11至17中任一项所述的方法,其特征在于,在所述第一终端设备接收第一设备发送的第一消息之前,所述方法还包括:所述第一终端设备向所述第一设备发送所述第一信息。
- 根据权利要求18所述的方法,其特征在于,所述第一信息承载于第一能力信息,所述第一能力信息用于指示所述第一终端设备的安全能力。
- 根据权利要求11至19中任一项所述的方法,其特征在于,所述第一设备为接入网设备或核心网设备。
- 一种通信设备,其特征在于,所述通信设备为第一设备,所述通信设备包括:接收模块,用于接收第一信息,所述第一信息用于指示第一终端设备是否支持第一类型的算法,所述第一类型的算法为256位的加密算法;确定模块,用于基于所述第一信息确定第一算法,所述第一算法为所述第一设备与所述第一终端设备之间使用的加密算法。
- 根据权利要求21所述的通信设备,其特征在于,若所述第一终端设备支持所述第一类型的算法,所述第一信息包括一个或多个第一标识,所述一个或多个第一标识用于指示所述第一终端设备支持的一个或多个所述第一类型的算法。
- 根据权利要求21或22所述的通信设备,其特征在于,所述第一信息包括第一指示信息,所述第一指示信息用于指示所述第一终端设备是否支持所述第一类型的算法。
- 根据权利要求21或22所述的通信设备,其特征在于,若所述第一终端设备支持所述第一类型的算法,所述第一信息包括第二指示信息,所述第二指示信息用于指示所述第一设备使用所述第一类型的算法作为所述第一算法。
- 根据权利要求21至24中任一项所述的通信设备,其特征在于,所述第一信息承载于第一能力信息,所述第一能力信息用于指示所述第一终端设备的安全能力。
- 根据权利要求21至25中任一项所述的通信设备,其特征在于,所述第一设备基于所述第一信息确定第一算法包括:若所述第一终端设备支持所述第一类型的算法,且所述第一设备支持所述第一类型的算法,则所述第一设备优先选择所述第一类型的算法作为所述第一算法;若所述第一终端设备支持所述第一类型的算法,但所述第一设备不支持所述第一类型的算法,则所述第一设备选择第二类型的算法作为所述第一算法,所述第二类型的算法为128位的加密算法;若所述第一终端设备不支持所述第一类型的算法,则所述第一设备选择所述第二类型的算法作为所述第一算法。
- 根据权利要求21至26中任一项所述的通信设备,其特征在于,所述通信设备还包括:第一发送模块,用于向第二设备发送第二信息,所述第二信息用于指示第二算法,所述第二算法为所述第二设备和所述第一终端设备之间使用的加密算法,所述第二算法由所述第一设备基于所述第一信息确定。
- 根据权利要求21至26中任一项所述的通信设备,其特征在于,所述通信设备还包括:第二发送模块,用于向第二设备发送所述第一信息,所述第一信息用于所述第二设备确定第二算法,所述第二算法为所述第二设备与所述第一终端设备之间的加密算法。
- 根据权利要求21至28中任一项所述的通信设备,其特征在于,所述第一设备为接入网设备。
- 根据权利要求21至26中任一项所述的通信设备,其特征在于,所述第一设备为核心网设备。
- 一种通信设备,其特征在于,所述通信设备为第一终端设备,所述通信设备包括:接收模块,用于接收第一设备发送的第一消息,所述第一消息包括第一算法的指示信息,所述第一算法为所述第一设备与所述第一终端设备之间使用的加密算法;使用模块,用于使用所述第一算法进行与所述第一设备之间的加密;其中,所述第一算法基于第一信息确定,所述第一信息用于指示所述第一终端设备是否支持第一类型的算法,所述第一类型的算法为256位的加密算法。
- 根据权利要求31所述的通信设备,其特征在于,若所述第一终端设备支持所述第一类型的算法,所述第一信息包括一个或多个第一标识,所述一个或多个第一标识用于指示所述第一终端设备支持的一个或多个所述第一类型的算法。
- 根据权利要求31或32所述的通信设备,其特征在于,所述第一信息包括第一指示信息,所述第一指示信息用于指示所述第一终端设备是否支持所述第一类型的算法。
- 根据权利要求31或32所述的通信设备,其特征在于,若所述第一终端设备支持所述第一类型的算法,所述第一信息包括第二指示信息,所述第二指示信息用于指示所述第一设备使用所述第一类型的算法作为所述第一算法。
- 根据权利要求31至34中任一项所述的通信设备,其特征在于,若所述第一终端设备支持所述第一类型的算法,且所述第一设备支持所述第一类型的算法,则所述第一算法为所述第一类型的算法。
- 根据权利要求31至35中任一项所述的通信设备,其特征在于,若所述第一终端设备支持所述第一类型的算法,但所述第一设备不支持所述第一类型的算法,则所述第一算法为第二类型的算法,所述第二类型的算法128位的加密算法。
- 根据权利要求31至36中任一项所述的通信设备,其特征在于,若所述第一终端设备不支持所述第一类型的算法,则所述第一算法为所述第二类型的算法。
- 根据权利要求31至37中任一项所述的通信设备,其特征在于,所述通信设备还包括:发送模块,用于在所述第一终端设备接收第一设备发送的第一消息之前,向所述第一设备发送所 述第一信息。
- 根据权利要求38所述的通信设备,其特征在于,所述第一信息承载于第一能力信息,所述第一能力信息用于指示所述第一终端设备的安全能力。
- 根据权利要求31至39中任一项所述的通信设备,其特征在于,所述第一设备为接入网设备或核心网设备。
- 一种通信设备,其特征在于,包括收发器、存储器和处理器,所述存储器用于存储程序,所述处理器用于调用所述存储器中的程序,并控制所述收发器接收或发送信号,以使所述通信设备执行如权利要求1-10中任一项所述的方法。
- 一种通信设备,其特征在于,包括收发器、存储器和处理器,所述存储器用于存储程序,所述处理器用于调用所述存储器中的程序,并控制所述收发器接收或发送信号,以使所述通信设备执行如权利要求11-20中任一项所述的方法。
- 一种装置,其特征在于,包括处理器,用于从存储器中调用程序,以使所述装置执行如权利要求1-10或11-20中任一项所述的方法。
- 一种芯片,其特征在于,包括处理器,用于从存储器调用程序,使得安装有所述芯片的设备执行如权利要求1-10或11-20中任一项所述的方法。
- 一种计算机可读存储介质,其特征在于,其上存储有程序,所述程序使得计算机执行如权利要求1-10或11-20中任一项所述的方法。
- 一种计算机程序产品,其特征在于,包括程序,所述程序使得计算机执行如权利要求1-10或11-20中任一项所述的方法。
- 一种计算机程序,其特征在于,所述计算机程序使得计算机执行如权利要求1-10或11-20中任一项所述的方法。
Priority Applications (1)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| PCT/CN2024/075830 WO2025161024A1 (zh) | 2024-02-04 | 2024-02-04 | 无线通信方法及通信设备 |
Applications Claiming Priority (1)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| PCT/CN2024/075830 WO2025161024A1 (zh) | 2024-02-04 | 2024-02-04 | 无线通信方法及通信设备 |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| WO2025161024A1 true WO2025161024A1 (zh) | 2025-08-07 |
Family
ID=96589333
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| PCT/CN2024/075830 Pending WO2025161024A1 (zh) | 2024-02-04 | 2024-02-04 | 无线通信方法及通信设备 |
Country Status (1)
| Country | Link |
|---|---|
| WO (1) | WO2025161024A1 (zh) |
Citations (5)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US20190082325A1 (en) * | 2017-09-08 | 2019-03-14 | Futurewei Technologies, Inc. | Method and Device for Negotiating Security and Integrity Algorithms |
| CN113423104A (zh) * | 2018-04-09 | 2021-09-21 | 华为技术有限公司 | 安全协商方法、终端设备和网络设备 |
| WO2021238280A1 (zh) * | 2020-05-29 | 2021-12-02 | 华为技术有限公司 | 一种通信方法、装置及系统 |
| CN114245377A (zh) * | 2020-09-07 | 2022-03-25 | 中国移动通信有限公司研究院 | 接入认证方法、装置、设备及存储介质 |
| WO2022198671A1 (zh) * | 2021-03-26 | 2022-09-29 | 华为技术有限公司 | 一种通信方法及装置 |
-
2024
- 2024-02-04 WO PCT/CN2024/075830 patent/WO2025161024A1/zh active Pending
Patent Citations (5)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US20190082325A1 (en) * | 2017-09-08 | 2019-03-14 | Futurewei Technologies, Inc. | Method and Device for Negotiating Security and Integrity Algorithms |
| CN113423104A (zh) * | 2018-04-09 | 2021-09-21 | 华为技术有限公司 | 安全协商方法、终端设备和网络设备 |
| WO2021238280A1 (zh) * | 2020-05-29 | 2021-12-02 | 华为技术有限公司 | 一种通信方法、装置及系统 |
| CN114245377A (zh) * | 2020-09-07 | 2022-03-25 | 中国移动通信有限公司研究院 | 接入认证方法、装置、设备及存储介质 |
| WO2022198671A1 (zh) * | 2021-03-26 | 2022-09-29 | 华为技术有限公司 | 一种通信方法及装置 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| US11533610B2 (en) | Key generation method and related apparatus | |
| US10187370B2 (en) | Fast-accessing method and apparatus | |
| US10798082B2 (en) | Network authentication triggering method and related device | |
| CN112020067B (zh) | 获取安全上下文的方法、装置和通信系统 | |
| CN109561427A (zh) | 一种通信方法及相关装置 | |
| CN109246696B (zh) | 密钥处理方法以及相关装置 | |
| CN113382404B (zh) | 用于获取ue安全能力的方法和设备 | |
| WO2019153994A1 (zh) | 安全协商方法及装置 | |
| US12317361B2 (en) | Data transmission method and apparatus | |
| US20260019807A1 (en) | Wlan multi-link tdls key derivation | |
| WO2020119815A1 (zh) | 一种安全上下文隔离的方法、装置及系统 | |
| CN119605315A (zh) | 用于控制用户设备的方法和装置 | |
| US20240275520A1 (en) | Communication method and apparatus | |
| CN111866872B (zh) | 一种通信方法及装置 | |
| CN112654046A (zh) | 用于注册的方法和装置 | |
| WO2021201729A1 (en) | Faster release or resume for ue in inactive state | |
| WO2023098209A1 (zh) | 一种数据传输保护方法、设备及系统 | |
| WO2022148469A1 (zh) | 一种安全保护方法、装置和系统 | |
| CN111465060A (zh) | 一种确定安全保护方式的方法、装置及系统 | |
| WO2024164839A1 (zh) | 一种密码算法协商方法及装置 | |
| WO2020238596A1 (zh) | 切换的方法、装置和通信系统 | |
| WO2025161024A1 (zh) | 无线通信方法及通信设备 | |
| WO2023213191A1 (zh) | 安全保护方法及通信装置 | |
| WO2025161027A1 (zh) | 无线通信方法及通信设备 | |
| CN119032628A (zh) | 安全建立的方法、通信方法及装置 |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| 121 | Ep: the epo has been informed by wipo that ep was designated in this application |
Ref document number: 24921077 Country of ref document: EP Kind code of ref document: A1 |