WO2025185705A1 - 标识指示方法、装置、终端设备及第一网络节点 - Google Patents
标识指示方法、装置、终端设备及第一网络节点Info
- Publication number
- WO2025185705A1 WO2025185705A1 PCT/CN2025/081056 CN2025081056W WO2025185705A1 WO 2025185705 A1 WO2025185705 A1 WO 2025185705A1 CN 2025081056 W CN2025081056 W CN 2025081056W WO 2025185705 A1 WO2025185705 A1 WO 2025185705A1
- Authority
- WO
- WIPO (PCT)
- Prior art keywords
- information
- key
- terminal device
- encrypted identification
- identification information
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Pending
Links
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W12/00—Security arrangements; Authentication; Protecting privacy or anonymity
- H04W12/03—Protecting confidentiality, e.g. by encryption
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W12/00—Security arrangements; Authentication; Protecting privacy or anonymity
- H04W12/60—Context-dependent security
- H04W12/69—Identity-dependent
Definitions
- the present application relates to the field of communications, and more specifically, to an identification indication method, apparatus, terminal equipment, and a first network node.
- a terminal device encrypts its identifier using the network's public key and sends the encrypted identifier to the network. Upon receiving the encrypted identifier, the network decrypts it using its private key to obtain the terminal device's identifier.
- terminal devices do not have the ability to encrypt identification, such as not having the network's public key or not having the computing power to use public key encryption, which makes it impossible to ensure the security of the terminal device's indication identification information.
- the embodiments of the present application provide an identification indication method, apparatus, terminal device, and first network node, which can ensure the security of identification information indicated by the terminal device.
- a method for indicating an identity comprising at least one of the following:
- the terminal device sends first information to the first network node
- the terminal device receives second information from the first network node
- the first information includes first encrypted identification information, the first encrypted identification information is generated based on the first identification and the first key of the terminal device, and the first information or the first encrypted identification information includes at least one of the stored information of the terminal device and the information received by the terminal device from the second network node;
- the second information includes second encrypted identification information, and the second encrypted identification information is generated based on the first identification and the second key of the terminal device.
- a method for indicating an identity comprising at least one of the following:
- the first network node receives first information from the terminal device
- the first network node sends second information to the terminal device
- the first information includes first encrypted identification information, which is generated based on the first identification and the first key of the terminal device;
- the second information includes second encrypted identification information, and the second encrypted identification information is generated based on the first identification and the second key of the terminal device.
- a marking indicating device comprising at least one of the following:
- a first sending unit configured to send first information to a first network node
- a receiving unit configured to receive second information from the first network node
- the first information includes first encrypted identification information, the first encrypted identification information is generated based on the first identification and the first key of the terminal device, and the first information or the first encrypted identification information includes at least one of the stored information of the terminal device and the information received by the terminal device from the second network node;
- the second information includes second encrypted identification information, and the second encrypted identification information is generated based on the first identification and the second key of the terminal device.
- a marking indicating device comprising at least one of the following:
- a receiving unit configured to receive first information from a terminal device
- a sending unit configured to send second information to a terminal device
- the first information includes first encrypted identification information, which is generated based on the first identification and the first key of the terminal device;
- the second information includes second encrypted identification information, and the second encrypted identification information is generated based on the first identification and the second key of the terminal device.
- a terminal device which includes a processor and a memory, wherein the memory stores programs or instructions that can be run on the processor, and when the program or instructions are executed by the processor, the steps of the method described in the first aspect are implemented.
- a terminal device comprising a processor and a communication interface, wherein the communication interface is configured to perform at least one of the following:
- the first information includes first encrypted identification information, the first encrypted identification information is generated based on the first identification and the first key of the terminal device, and the first information or the first encrypted identification information is included in at least one of the stored information of the terminal device and the information received by the terminal device from the second network node;
- the second information includes second encrypted identification information, and the second encrypted identification information is generated based on the first identification and the second key of the terminal device.
- a first network node comprising a processor and a memory, wherein the memory stores a program or instruction that can be run on the processor, and when the program or instruction is executed by the processor, the steps of the method described in the second aspect are implemented.
- a first network node comprising a processor and a communication interface, wherein the communication interface is configured to perform at least one of the following:
- the first information includes first encrypted identification information, which is generated based on the first identification and the first key of the terminal device;
- the second information includes second encrypted identification information, and the second encrypted identification information is generated based on the first identification and the second key of the terminal device.
- a readable storage medium on which a program or instruction is stored.
- the program or instruction is executed by a processor, the steps of the method described in the first aspect are implemented, or the steps of the method described in the second aspect are implemented.
- a wireless communication system comprising: a terminal device and a first network node, wherein the terminal device can be used to execute the steps of the method described in the first aspect, and the first network node can be used to execute the steps of the method described in the second aspect.
- a chip which includes a processor and a communication interface, wherein the communication interface is coupled to the processor, and the processor is used to run programs or instructions to implement the steps of the method described in the first aspect, or to implement the steps of the method described in the second aspect.
- a computer program/program product is provided, wherein the computer program/program product is stored in a storage medium, and the program/program product is executed by at least one processor to implement the steps of the method described in the first aspect.
- a terminal device sends first information to a first network node; wherein the first information includes first encrypted identification information, which is generated based on the first identifier and a first key of the terminal device, and the first information or the first encrypted identification information includes at least one of the stored information of the terminal device and the information received by the terminal device from a second network node.
- the terminal device can obtain the first information or the first encrypted identification information from at least one of the stored information of the terminal device and the information received by the terminal device from the second network node.
- the identifier can be encrypted or decrypted based on the terminal's existing information, regardless of whether the terminal has a public key or public key decryption capability.
- the terminal device receives second information from the first network node; wherein the second information includes second encrypted identification information, which is generated based on the terminal device's first identifier and the second key. This is equivalent to the terminal device receiving the second encrypted identification information from the first network node. Therefore, even if the terminal device does not have the ability to encrypt the identification, the security of the identification information indicated by the terminal device can be guaranteed.
- FIG1 is a schematic diagram of a system architecture provided in an embodiment of the present application.
- FIG2 is a schematic flowchart of an identification indication method provided in an embodiment of the present application.
- FIG3 is a schematic flowchart of another identification indication method provided in an embodiment of the present application.
- FIG4 is a schematic flowchart of another identification indication method provided in an embodiment of the present application.
- FIG5 is a schematic block diagram of an identification indicating device provided in an embodiment of the present application.
- FIG6 is a schematic block diagram of another identification indicating device provided in an embodiment of the present application.
- FIG7 is a schematic block diagram of a communication device provided in an embodiment of the present application.
- FIG8 is a schematic diagram of the hardware structure of a terminal provided in an embodiment of the present application.
- FIG9 is a schematic block diagram of a network-side device provided in an embodiment of the present application.
- FIG10 is a schematic block diagram of another network-side device provided in an embodiment of the present application.
- first, second, etc. in this application are used to distinguish similar objects, and are not used to describe a specific order or sequence. It should be understood that the terms used in this way are interchangeable where appropriate, so that the embodiments of the present application can be implemented in an order other than those illustrated or described herein, and the objects distinguished by “first” and “second” are generally of the same type, and do not limit the number of objects, for example, the first object can be one or more.
- “or” in this application represents at least one of the connected objects. For example, “A or B” covers three options, namely, Option 1: including A but not including B; Option 2: including B but not including A; Option 3: including both A and B.
- the character "/" generally indicates that the objects associated before and after are in an "or” relationship.
- indication in this application can be either a direct indication (or explicit indication) or an indirect indication (or implicit indication).
- a direct indication can be understood as the sender explicitly informing the receiver of specific information, the operation to be performed, or the requested result, etc. in the instruction sent;
- an indirect indication can be understood as the receiver determining the corresponding information based on the instruction sent by the sender, or making a judgment and determining the operation to be performed or the requested result, etc. based on the judgment result.
- LTE Long Term Evolution
- LTE-A Long Term Evolution
- CDMA Code Division Multiple Access
- TDMA Time Division Multiple Access
- FDMA Frequency Division Multiple Access
- OFDMA Orthogonal Frequency Division Multiple Access
- SC-FDMA Single-carrier Frequency Division Multiple Access
- NR New Radio
- 6G 6th Generation
- FIG1 shows a block diagram of a wireless communication system applicable to an embodiment of the present application.
- the wireless communication system includes a terminal 11 and a network-side device 12 .
- the terminal 11 can be a mobile phone, a tablet computer (Tablet Personal Computer), a laptop computer (Laptop Computer), a notebook computer, a personal digital assistant (PDA), a handheld computer, a netbook, an ultra-mobile personal computer (UMPC), a mobile Internet device (MID), an augmented reality (AR), a virtual reality (VR) device, a robot, a wearable device (Wearable Device), a flight vehicle, a vehicle user equipment (VUE), a ship-borne equipment, a pedestrian user equipment (PUE), a smart home (home appliances with wireless communication functions, such as refrigerators, televisions, washing machines or furniture, etc.), a game console, a personal computer (PC), an ATM or a self-service machine and other terminal-side devices.
- PC personal computer
- ATM an ATM or a self-service machine and other terminal-side devices.
- Wearable devices include: smart watches, smart bracelets, smart headphones, smart glasses, smart jewelry (smart bracelets, smart bracelets, smart rings, smart necklaces, smart anklets, smart anklets, etc.), smart wristbands, smart clothing, etc.
- the vehicle-mounted device can also be called a vehicle-mounted terminal, vehicle-mounted controller, vehicle-mounted module, vehicle-mounted component, vehicle-mounted chip or vehicle-mounted unit, etc. It should be noted that the specific type of the terminal 11 is not limited in the embodiment of the present application.
- the network side device 12 may include an access network device or a core network device.
- the access network equipment can also be called radio access network (Radio Access Network, RAN) equipment, radio access network function or radio access network unit.
- the access network equipment may include base stations, wireless local area network (Wireless Local Area Network, WLAN) access points (Access Point, AP) or wireless fidelity (Wireless Fidelity, WiFi) nodes, etc.
- WLAN wireless Local Area Network
- AP Access Point
- WiFi Wireless Fidelity
- the base station can be called node B (Node B, NB), evolved node B (Evolved Node B, eNB), the next generation node B (the next generation node B, gNB), new radio node B (New Radio Node B, NR Node B), access point, relay station (Relay Base Station, RBS), serving base station (Serving Base Station, SBS), base transceiver station (Base Transceiver Station, BTS), radio base station, radio transceiver, base The Basic Service Set (BSS), Extended Service Set (ESS), Home Node B (HNB), Home Evolved Node B, Transmission Reception Point (TRP) or other appropriate terms in the field, as long as the same technical effect is achieved, the base station is not limited to specific technical terms. It should be noted that in the embodiments of the present application, only the base station in the NR system is introduced as an example, and the specific type of the base station is not limited.
- the core network equipment may include but is not limited to at least one of the following: core network nodes, core network functions, mobility management entity (MME), access mobility management function (AMF), session management function (SMF), user plane function (UPF), policy control function (PCF), policy and charging rules function unit (PCRF), edge application service discovery function (Edge Application Server Discovery
- MME mobility management entity
- AMF access mobility management function
- SMF session management function
- UPF user plane function
- PCF policy control function
- PCF policy and charging rules function unit
- Edge Application Server Discovery The following functions are used in the present invention to implement the NR network: Function, EASDF), Unified Data Management (UDM), Unified Data Repository (UDR), Home Subscriber Server (HSS), Centralized Network Configuration (CNC), Network Repository Function (NRF), Network Exposure Function (NEF), Local NEF (L-NEF), Binding Support Function (BSF), Application Function (AF), etc.
- EASDF Unified Data Management
- UDR Unified Data Repository
- the specific type of the core network equipment is not limited. But not limited to at least one of the following: core network node, core network function, Mobility Management Entity (MME), Access Mobility Management Function (AMF), Session Management Function (SMF), User Plane Function (UPF), Policy Control Function (PCF), Policy and Charging Rules Function (PCRF), Edge Application Server Discovery Function (Edge Application Server Discovery Function),
- the following functions are used for the NR equipment: EASDF), Unified Data Management (UDM), Unified Data Repository (UDR), Home Subscriber Server (HSS), Centralized Network Configuration (CNC), Network Repository Function (NRF), Network Exposure Function (NEF), Local NEF (L-NEF), Binding Support Function (BSF), Application Function (AF), etc.
- EASDF Unified Data Management
- UDR Unified Data Repository
- HSS Home Subscriber Server
- CNC Centralized Network Configuration
- NRF Network Repository Function
- NEF Network Exposure Function
- L-NEF Binding Support Function
- BSF
- FIG2 is a schematic flowchart of a method 210 for indicating an identity according to an embodiment of the present application.
- the identification indication method 210 may include at least part of the following contents:
- the terminal device sends first information to the first network node
- the first information includes first encrypted identification information, which is generated based on the first identification and first key of the terminal device, and the first information or the first encrypted identification information includes at least one of the storage information of the terminal device and the information received by the terminal device from the second network node.
- the first network node includes at least one of the following: UE, access network equipment, AMF, UDM, AF, AuC.
- the first network to which the first network node belongs may be a 3GPP network, such as a 5G network or a future 6G network.
- the second network node includes at least one of the following: UE, access network equipment, AMF, UDM, AF, AuC, AUSF.
- the second network to which the second network node belongs may be the same as or different from the first network.
- the second network may be a 3GPP network, such as a 5G network or a future 6G network, or may even be a non-3GPP network.
- the first encrypted identification information may be generated by encrypting the first identification based on the first key, or the first encrypted identification information may be generated by using an encryption algorithm with the first identification and the first key as input.
- the terminal device can obtain the first encrypted identification information from at least one of the stored information of the terminal device and the information received by the terminal device from the second network node.
- the terminal device can obtain the first encrypted identification information from at least one of the stored information of the terminal device and the information received by the terminal device from the second network node.
- the first network node decrypts the first encrypted identification information based on at least one of the following:
- the associated key is a corresponding private key.
- the first information further includes fourth information, and the first encrypted identification information is further generated based on the fourth information.
- the first encrypted identification information is generated based on the first identification, the first key and the fourth information.
- the first information further includes fourth information
- the method 210 further includes:
- the first network node decrypts the first encrypted identification information based on at least one of the following:
- the associated key is a corresponding private key.
- the first information further includes a first verification code, where the first verification code is generated based on at least one of the following:
- the first encrypted identification information and the third key are the first encrypted identification information and the third key.
- the method 210 further includes:
- the terminal device generates the first verification code based on the first encryption identifier and the third key.
- a network node (which may be the first network node, the second network node, or other network nodes) may generate the first verification code based on the first encryption identifier and the third key, and configure it to the terminal device.
- the first information further includes a first verification code
- the method 210 further includes:
- the first network node verifies the first verification code based on at least one of the following:
- the first encrypted identification information and the third key are the first encrypted identification information and the third key.
- the first verification code is a verification code generated by a network node (which may be a first network node, a second network node, or another network node) and preconfigured for the terminal device, and the first network node verifies the first verification code based on at least one of the following:
- the first identifier and an associated key of the first key are identical to each other.
- the first verification code is a verification code generated by the terminal device, and the first network node verifies the first verification code based on the first encrypted identification information and a third key.
- the first information further includes a first verification code and fourth information, where the first verification code is generated based on at least one of the following:
- the first encrypted identification information the third key and the fourth information.
- the method 210 further includes:
- the terminal device generates the first verification code based on the first encryption identifier, the third key and the fourth information.
- a network node (which may be the first network node, the second network node, or other network node) may generate the first verification code based on the first encryption identifier, the third key and the fourth information, and configure it to the terminal device.
- the first information further includes a first check code and fourth information
- the method 210 further includes:
- the first network node verifies the first verification code based on at least one of the following:
- the first identifier a key associated with the first key, and the fourth information
- the first encrypted identification information the third key and the fourth information.
- the first verification code is a verification code generated by a network node (which may be a first network node, a second network node, or another network node) and preconfigured for the terminal device, and the first network node verifies the first verification code based on at least one of the following:
- the first identifier a key associated with the first key, and the fourth information
- the first verification code is a verification code generated by the terminal device, and the first network node verifies the first verification code based on the first encryption identification information, the third key and the fourth information.
- the first information further includes at least one of the following:
- a third key identifier, index, or indication corresponding to the third key is a third key identifier, index, or indication corresponding to the third key.
- the first key corresponding to the first key indicates an index or identifier of the first key.
- the third key corresponding to the third key indicates an index or identifier of the first key.
- the terminal device is unknown to the first key.
- the terminal device is unaware of the first key because it has not obtained or received the first key from the network side, and thus will not generate the first information and/or the first encryption identifier, because the first information and/or the first encryption identifier need to be generated based on the first key.
- the first key is a symmetric key, or a shared key, or is not an asymmetric key or is not a public key.
- the first key may be a public key of an asymmetric key, or may be a symmetric key.
- Symmetric-key algorithms and shared keys use the same key for both encryption and decryption.
- Asymmetric-key cryptography also known as public-key cryptography, is a different type of encryption. In this method, keys are divided into a pair: a public key and a private key.
- the public key is public and can be freely distributed to anyone, while the private key is kept secret and known only to the holder.
- the public key is used to encrypt information, while the private key is used to decrypt it.
- the fourth information may be any information used for or involved in generating the first encryption identifier, and the present application does not limit its specific content.
- the verification code involved in this application can be used to verify the integrity and accuracy of data. For example, taking the first verification code as an example, which is generated based on the first identifier and the first key, after receiving the first information, the first network node regenerates the verification code based on the first identifier and the first key, and verifies the first verification code based on the regenerated verification code. If the regenerated verification code successfully matches the first verification code, it means that the information has not been tampered with or damaged during transmission, and the information is complete and accurate. This is because only when the correct identifier and key are used and the information itself has not changed can the generated verification code be guaranteed to be the same as the first verification code.
- the first network node can determine that the information transmission has failed, or require the terminal device to resend or retransmit the first information.
- FIG3 is a schematic flowchart of the identification indication method 220 according to an embodiment of the present application.
- the identification indication method 220 may include at least part of the following contents:
- the terminal device receives second information from the first network node
- the second information includes second encrypted identification information, and the second encrypted identification information is generated based on the first identification and the second key of the terminal device.
- the first network node includes at least one of the following: UE, access network equipment, AMF, UDM, AF, AuC.
- the first network to which the first network node belongs may be a 3GPP network, such as a 5G network or a future 6G network.
- the first network node obtains or generates the second encrypted identification information, it sends the second information to the terminal device.
- the first network node may receive the second information from a third communication node; or the first network node may decrypt the second encrypted identification information received from the third communication node; or the first network node may generate the second encrypted identification; or the first network node may send the second encrypted identification generated by the first network node to the third network node.
- the third communication node includes at least one of the following: AUSF, UDM, AF, and AuC.
- the second encrypted identification information may be generated by encrypting the first identification based on the second key, or the second encrypted identification information may be generated by using an encryption algorithm with the first identification and the second key as input.
- the terminal device receives the second encrypted identification information from the first network node, which avoids the terminal device from encrypting the identification of the terminal device. Therefore, even if the terminal device does not have the ability to encrypt the identification, the security of the identification information indicated by the terminal device can be guaranteed.
- the method 220 further includes at least one of the following:
- the terminal device stores the second encrypted identification information or the second information
- the terminal device sends third information to a third network node, where the third information includes the second encryption identification information or the second information.
- the method 220 further includes:
- the first network node generates the second encrypted identification information based on the second key and the first identification.
- the first network node before sending the second information, the first network node generates the second encrypted identification information based on the second key and the first identification.
- the second information further includes fifth information, and the second encrypted identification information is further generated based on the fifth information.
- the method 220 further includes:
- the first network node generates the second encrypted identification information based on the second key, the first identification and the fifth information.
- the first network node before sending the second information, the first network node generates the second encrypted identification information based on the second key, the first identification and the fifth information.
- the second information further includes a second verification code, where the second verification code is generated based on at least one of the following:
- the second encrypted identification information and the fourth key are the same.
- the method 220 further includes:
- the terminal device verifies the second verification code based on the second encrypted identification information and the fourth key.
- the terminal device After receiving the second information, the terminal device verifies the second verification code based on the second encryption identification information and the fourth key.
- the method 220 further includes:
- the first network node generates the second verification code based on at least one of the following:
- the second encrypted identification information and the fourth key are the same.
- the first network node before sending the second information, the first network node generates the second check code based on at least one of the following:
- the second encrypted identification information and the fourth key are the same.
- the second information further includes a second check code and fifth information, where the second check code is generated based on at least one of the following:
- the second encrypted identification information, the fourth key and the fifth information are the second encrypted identification information, the fourth key and the fifth information.
- the method 220 further includes:
- the terminal device verifies the second verification code based on the second encryption identification information, the fourth key and the fifth information.
- the terminal device verifies the second verification code based on the second encryption identification information, the fourth key and the fifth information.
- the method 220 further includes:
- the first network node generates the second verification code based on at least one of the following:
- the second encrypted identification information, the fourth key and the fifth information are the second encrypted identification information, the fourth key and the fifth information.
- the second check code may also be generated by a network node other than the first network node, and this application does not make any specific limitation on this.
- the second information further includes at least one of the following:
- a fourth key identifier, index, or indication corresponding to the fourth key is
- the terminal device is unaware of the second key.
- the terminal device is unaware of the second key because it has not obtained or received the second key from the network side, and thus will not generate the second information and/or the second encryption identifier, because the second information and/or the second encryption identifier need to be generated based on the second key.
- the second key is a symmetric key, or a shared key, or is not an asymmetric key or is not a public key.
- the second key may be a public key of an asymmetric key, or may be a symmetric key.
- Symmetric-key algorithms and shared keys use the same key for both encryption and decryption.
- Asymmetric-key cryptography also known as public-key cryptography, is a different type of encryption. In this method, keys are divided into a pair: a public key and a private key.
- the public key is public and can be freely distributed to anyone, while the private key is kept secret and known only to the holder.
- the public key is used to encrypt information, while the private key is used to decrypt it.
- the third information may be any information used to carry the second encrypted identification information, and this application does not limit its specific content.
- the fifth information may be any information used for or involved in generating the second encrypted identification, and this application does not limit its specific content.
- the verification code involved in this application can be used to verify the integrity and accuracy of data.
- the second verification code as an example, which is generated based on the second encrypted identification information and the fourth key
- the terminal device After the terminal device receives the second information, it regenerates the verification code based on the second encrypted identification information and the fourth key, and verifies the second verification code based on the regenerated verification code. If the regenerated verification code and the second verification code match successfully, it means that the information has not been tampered with or damaged during the transmission process, and the information is complete and accurate. This is because only when the correct identifier and key are used and the information itself has not changed can the generated verification code be guaranteed to be the same as the first verification code.
- the terminal device can determine that the information transmission has failed, or request the first network node to resend or retransmit the second information.
- FIG4 is a schematic flowchart of the identification indication method 230 according to an embodiment of the present application.
- the identification indication method 230 may include at least part of the following contents:
- the terminal device receives second information from the first network node
- the second information includes second encrypted identification information and a second verification code, and the second encrypted identification information is generated based on the first identification and the second key of the terminal device.
- the first network node includes at least one of the following: UE, access network equipment, AMF, UDM, AF, AuC.
- the first network to which the first network node belongs may be a 3GPP network, such as a 5G network or a future 6G network.
- the first network node obtains or generates the second encrypted identification information, it sends the second information to the terminal device.
- the first network node obtains or generates the second verification code, it sends the second information to the terminal device.
- the first network node may receive the second information from a third communication node; or the first network node may decrypt the second encrypted identification information received from the third communication node; or the first network node may generate the second encrypted identification; or the first network node may send the second encrypted identification generated by the first network node to the third network node.
- the third communication node includes at least one of the following: AUSF, UDM, AF, and AuC.
- the second encrypted identification information may be generated by encrypting the first identification based on the second key, or the second encrypted identification information may be generated by using an encryption algorithm with the first identification and the second key as input.
- the terminal device receives the second encrypted identification information from the first network node, which avoids the terminal device from encrypting the identification of the terminal device. Therefore, even if the terminal device does not have the ability to encrypt the identification, the security of the identification information indicated by the terminal device can be guaranteed.
- the terminal device verifies the second verification code. For example, when the second verification code is generated based on the third key and the second encryption identifier, the terminal device verifies the second verification code based on the third key and the second encryption identifier information.
- S233 The terminal device generates a first verification code based on the fourth key and the second encryption identification information.
- the terminal device sends third information to the second network node, wherein the third information includes the second encrypted identification information and the first verification code.
- S235 The second network node verifies the first verification code based on the fourth key and the second encryption identification information.
- third key and the fourth key may be the same or different.
- the identification indication method provided in the embodiment of the present application can be executed by an identification indication device.
- the identification indication device provided in the embodiment of the present application is described by taking the identification indication method executed by the identification indication device as an example.
- FIG5 is a schematic block diagram of an identification indicating device 300 provided according to an embodiment of the present application.
- the identification indicating device 300 includes at least one of the following:
- a first sending unit 310 is configured to send first information to a first network node
- the receiving unit 320 is configured to receive second information from the first network node
- the first information includes first encrypted identification information, the first encrypted identification information is generated based on the first identification and the first key of the terminal device, and the first information or the first encrypted identification information includes at least one of the stored information of the terminal device and the information received by the terminal device from the second network node;
- the second information includes second encrypted identification information, and the second encrypted identification information is generated based on the first identification and the second key of the terminal device.
- the apparatus 300 further includes at least one of the following:
- a storage unit configured to store the second encrypted identification information or the second information
- the second sending unit is configured to send third information to a third network node, where the third information includes the second encryption identification information or the second information.
- the first information further includes fourth information, and the first encrypted identification information is further generated based on the fourth information.
- the first information further includes a first verification code, where the first verification code is generated based on at least one of the following:
- the first encrypted identification information and the third key are the first encrypted identification information and the third key.
- the apparatus 300 further includes:
- the first generating unit is configured to generate the first verification code based on the first encryption identifier and the third key.
- the first information further includes a first verification code and fourth information, where the first verification code is generated based on at least one of the following:
- the first encrypted identification information the third key and the fourth information.
- the apparatus 300 further includes:
- the second generating unit is configured to generate the first verification code based on the first encryption identifier, the third key, and the fourth information.
- the first information further includes at least one of the following:
- a third key identifier, index, or indication corresponding to the third key is a third key identifier, index, or indication corresponding to the third key.
- the second information further includes fifth information, and the second encrypted identification information is further generated based on the fifth information.
- the second information further includes a second verification code, where the second verification code is generated based on at least one of the following:
- the second encrypted identification information and the fourth key are the same.
- the apparatus 300 further includes:
- a first verification unit is configured to verify the second verification code based on the second encryption identification information and the fourth key.
- the second information further includes a second check code and fifth information, where the second check code is generated based on at least one of the following:
- the second encrypted identification information, the fourth key and the fifth information are the second encrypted identification information, the fourth key and the fifth information.
- the apparatus 300 further includes:
- a second verification unit is configured to verify the second verification code based on the second encryption identification information, the fourth key, and the fifth information.
- the second information further includes at least one of the following:
- a fourth key identifier, index, or indication corresponding to the fourth key is
- the terminal device is unaware of at least one of the first key and the second key.
- identification indication device 300 provided in the embodiment of the present application may correspond to the terminal device in the method embodiment of the present application, and the various units in the identification indication device 300 are respectively for implementing the corresponding processes of method 210 shown in Figure 2, method 220 shown in Figure 3 or method 230 shown in Figure 4. For the sake of brevity, they will not be repeated here.
- FIG6 is a schematic block diagram of an identification indicating device 400 provided according to an embodiment of the present application.
- the identification indicating device 400 includes at least one of the following:
- the receiving unit 410 is configured to receive first information from a terminal device
- the sending unit 420 is configured to send the second information to the terminal device
- the first information includes first encrypted identification information, which is generated based on the first identification and the first key of the terminal device;
- the second information includes second encrypted identification information, and the second encrypted identification information is generated based on the first identification and the second key of the terminal device.
- the apparatus 400 further includes:
- a first decryption unit is configured to decrypt the first encrypted identification information based on at least one of the following:
- the first information further includes fourth information
- the apparatus 400 further includes:
- a second decryption unit is configured to decrypt the first encrypted identification information based on at least one of the following:
- the first information further includes a first verification code
- the apparatus 400 further includes:
- a first verification unit is configured to verify the first verification code based on at least one of the following:
- the first encrypted identification information and the third key are the first encrypted identification information and the third key.
- the first information further includes a first check code and fourth information
- the apparatus 400 further includes:
- a second verification unit is configured to verify the first verification code based on at least one of the following:
- the first identifier a key associated with the first key, and the fourth information
- the first encrypted identification information the third key and the fourth information.
- the first information further includes at least one of the following:
- a third key identifier, index, or indication corresponding to the third key is a third key identifier, index, or indication corresponding to the third key.
- the apparatus 400 further includes:
- the first generating unit is configured to generate the second encrypted identification information based on the second key and the first identification.
- the second information further includes fifth information, and the second encrypted identification information is further generated based on the fifth information.
- the apparatus 400 further includes:
- the second generating unit is configured to generate the second encrypted identification information based on the second key, the first identification and the fifth information.
- the second information further includes a second verification code, where the second verification code is generated based on at least one of the following:
- the second encrypted identification information and the fourth key are the same.
- the apparatus 400 further includes:
- the third generating unit is configured to generate the second verification code based on at least one of the following:
- the second encrypted identification information and the fourth key are the same.
- the second information further includes a second check code and fifth information, where the second check code is generated based on at least one of the following:
- the second encrypted identification information, the fourth key and the fifth information are the second encrypted identification information, the fourth key and the fifth information.
- the apparatus 400 further includes:
- a fourth generating unit is configured to generate the second verification code based on at least one of the following:
- the second encrypted identification information, the fourth key and the fifth information are the second encrypted identification information, the fourth key and the fifth information.
- the second information further includes at least one of the following:
- a fourth key identifier, index, or indication corresponding to the fourth key is
- identification and indication device 400 provided in the embodiment of the present application may correspond to the first network node in the method embodiment of the present application, and the various units in the identification and indication device 400 are respectively for implementing the corresponding processes of method 210 shown in Figure 2, method 220 shown in Figure 3 or method 230 shown in Figure 4. For the sake of brevity, they will not be repeated here.
- the identification indicating device in the embodiment of the present application can be an electronic device, such as an electronic device with an operating system, or a component in an electronic device, such as an integrated circuit or a chip.
- the electronic device can be a terminal device or a first network node, and the first network node can be a network-side device or other device.
- the type of terminal can include but is not limited to the type of terminal 11 listed above
- the type of network-side device can include but is not limited to the type of network-side device 12 listed above
- other devices can be servers, network attached storage (NAS), etc., which are not specifically limited in the embodiment of the present application.
- the identification indication device provided in the embodiment of the present application can implement the various processes implemented in the method embodiments of Figures 2 to 4 and achieve the same technical effects. To avoid repetition, they will not be described here.
- the embodiment of the present application also provides a communication device 500, as shown in Figure 7, the communication device 500 includes a processor 501 and a memory 502, and the memory 502 stores a program or instruction that can be run on the processor 501, and the program or instruction, when executed by the processor 501, implements the various steps of the above-mentioned identification indication method embodiment.
- the communication device 500 is a terminal device
- the program or instruction when executed by the processor 501, it implements the various steps performed by the terminal device in the above-mentioned identification indication method embodiment, and can achieve the same technical effect.
- the communication device 500 When the communication device 500 is a first network node, when the program or instruction is executed by the processor 501, it implements the various steps performed by the first network node in the above-mentioned identification indication method embodiment, and can achieve the same technical effect. To avoid repetition, it will not be repeated here.
- the present application also provides a terminal including a processor and a communication interface, wherein the communication interface is coupled to the processor, and the processor is configured to execute a program or instruction to implement the steps of the identification indication method embodiment described above.
- This terminal embodiment corresponds to the above-described terminal-side method embodiment, and each implementation process and implementation method of the above-described method embodiment is applicable to this terminal embodiment and can achieve the same technical effects.
- FIG8 is a schematic diagram of the hardware structure of a terminal 600 implementing an embodiment of the present application.
- the terminal 600 includes but is not limited to: a radio frequency unit 601, a network module 602, an audio output unit 603, an input unit 604, a sensor 605, a display unit 606, a user input unit 607, an interface unit 608, a memory 609 and at least some of the components of the processor 610.
- the terminal 600 may also include a power supply (such as a battery) to power various components.
- the power supply may be logically connected to the processor 610 through a power management system, thereby implementing functions such as charging, discharging, and power consumption management through the power management system.
- the terminal structure shown in FIG8 does not constitute a limitation of the terminal.
- the terminal may include more or fewer components than shown, or combine certain components, or have different component arrangements, which will not be described in detail here.
- the input unit 604 may include a graphics processing unit (GPU) 6041 and a microphone 6042, and the graphics processor 6041 processes the image data of the static picture or video obtained by the image capture device (such as a camera) in the video capture mode or the image capture mode.
- the display unit 606 may include a display panel 6061, and the display panel 6061 may be configured in the form of a liquid crystal display, an organic light emitting diode, etc.
- the user input unit 607 includes a touch panel 6071 and at least one of the other input devices 6072.
- the touch panel 6071 is also called a touch screen.
- the touch panel 6071 may include two parts: a touch detection device and a touch controller.
- Other input devices 6072 may include but are not limited to a physical keyboard, function keys (such as volume control keys, switch keys, etc.), a trackball, a mouse, and a joystick, which will not be repeated here.
- the radio frequency unit 601 may transmit the data to the processor 610 for processing. Furthermore, the radio frequency unit 601 may send uplink data to the network-side device.
- the radio frequency unit 601 includes, but is not limited to, an antenna, an amplifier, a transceiver, a coupler, a low-noise amplifier, a duplexer, and the like.
- the memory 609 can be used to store software programs or instructions and various data.
- the memory 609 may mainly include a first storage area for storing programs or instructions and a second storage area for storing data.
- the first storage area may store an operating system, applications or instructions required for at least one function (such as a sound playback function, an image playback function, etc.).
- the memory 609 may include a volatile memory or a non-volatile memory.
- the non-volatile memory may be a read-only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM), or a flash memory.
- the volatile memory may be a random access memory (RAM), a static random access memory (SRAM), a dynamic random access memory (DRAM), a synchronous dynamic random access memory (SDRAM), a double data rate synchronous dynamic random access memory (DDRSDRAM), an enhanced synchronous dynamic random access memory (ESDRAM), a single link dynamic random access memory (SLDRAM), and a direct RAM bus random access memory (DRRAM).
- RAM random access memory
- SRAM static random access memory
- DRAM dynamic random access memory
- SDRAM synchronous dynamic random access memory
- DDRSDRAM double data rate synchronous dynamic random access memory
- ESDRAM enhanced synchronous dynamic random access memory
- SLDRAM single link dynamic random access memory
- DRRAM direct RAM bus random access memory
- Processor 610 may include one or more processing units.
- processor 610 integrates an application processor and a modem processor.
- the application processor primarily handles operations related to the operating system, user interface, and application programs, while the modem processor primarily processes wireless communication signals, such as a baseband processor. It is understood that the modem processor may not be integrated into processor 610.
- the radio frequency unit 601 is configured to perform at least one of the following:
- the first information includes first encrypted identification information, the first encrypted identification information is generated based on the first identification and the first key of the terminal device, and the first information or the first encrypted identification information includes at least one of the stored information of the terminal device and the information received by the terminal device from the second network node;
- the second information includes second encrypted identification information, and the second encrypted identification information is generated based on the first identification and the second key of the terminal device.
- the terminal 600 may serve as the first communication node mentioned above.
- the radio frequency unit 601 is configured to perform at least one of the following:
- the first information includes first encrypted identification information, which is generated based on the first identification and first key of the terminal device; the second information includes second encrypted identification information, which is generated based on the first identification and second key.
- a terminal device sends first information to a first network node; wherein the first information includes first encrypted identification information, which is generated based on the first identifier and a first key of the terminal device, and the first information or the first encrypted identification information includes at least one item of stored information on the terminal device and information received by the terminal device from a second network node.
- the terminal device can obtain the first information or the first encrypted identification information from at least one item of stored information on the terminal device and information received from the second network node.
- the terminal device receives second information from the first network node; wherein the second information includes second encrypted identification information, which is generated based on the first identifier and a second key of the terminal device. In other words, the terminal device receives the second encrypted identification information from the first network node.
- the terminal device receives the second encrypted identification information from the first network node.
- the present application also provides a network-side device, including a processor and a communication interface, wherein the communication interface is coupled to the processor, and the processor is configured to execute a program or instruction to implement the steps of the identification indication method embodiment shown above.
- This network-side device embodiment corresponds to the above-mentioned network-side device method embodiment, and each implementation process and implementation method of the above-mentioned method embodiment can be applied to this network-side device embodiment and can achieve the same technical effects.
- the network-side device 700 includes an antenna 71, a radio frequency device 72, a baseband device 73, a processor 74, and a memory 75.
- Antenna 71 is connected to radio frequency device 72.
- radio frequency device 72 receives information via antenna 71 and sends the received information to baseband device 73 for processing.
- baseband device 73 processes the information to be transmitted and sends it to radio frequency device 72.
- Radio frequency device 72 processes the received information and then sends it through antenna 71.
- the method executed by the network-side device in the above embodiment may be implemented in the baseband device 73 , which includes a baseband processor.
- the baseband device 73 may include, for example, at least one baseband board, on which multiple chips are arranged, as shown in Figure 8, one of the chips is, for example, a baseband processor, which is connected to the memory 75 through a bus interface to call the program in the memory 75 to execute the network device operations shown in the above method embodiment.
- the network side device may also include a network interface 76, which is, for example, a Common Public Radio Interface (CPRI).
- CPRI Common Public Radio Interface
- the network side device 700 of the embodiment of the present application also includes: instructions or programs stored in the memory 75 and executable on the processor 74.
- the processor 74 calls the instructions or programs in the memory 75 to execute the methods of executing the modules shown in FIG6 and achieve the same technical effect. To avoid repetition, it will not be described here.
- an embodiment of the present application further provides a network-side device.
- the network-side device 800 includes a processor 801, a network interface 802, and a memory 803.
- the network interface 802 is, for example, a common public radio interface (CPRI).
- CPRI common public radio interface
- the network side device 800 of the embodiment of the present application also includes: instructions or programs stored in the memory 803 and can be run on the processor 801.
- the processor 801 calls the instructions or programs in the memory 803 to execute the method of execution of each module shown in Figure 6 and achieve the same technical effect. To avoid repetition, it will not be repeated here.
- An embodiment of the present application also provides a readable storage medium, on which a program or instruction is stored.
- a program or instruction is stored.
- the various processes of the above-mentioned identification indication method embodiment are implemented and the same technical effect can be achieved. To avoid repetition, it will not be repeated here.
- the processor is the processor in the terminal described in the above embodiment.
- the readable storage medium includes a computer-readable storage medium, such as a computer read-only memory (ROM), a random access memory (RAM), a magnetic disk, or an optical disk.
- ROM computer read-only memory
- RAM random access memory
- magnetic disk such as a hard disk, a hard disk, or a magnetic disk.
- optical disk such as a hard disk, a hard disk, or an optical disk.
- the readable storage medium may be a non-transitory readable storage medium.
- An embodiment of the present application further provides a chip, which includes a processor and a communication interface, wherein the communication interface is coupled to the processor, and the processor is used to run programs or instructions to implement the various processes of the above-mentioned identification indication method embodiment, and can achieve the same technical effect. To avoid repetition, it will not be repeated here.
- the chip mentioned in the embodiments of the present application can also be called a system-level chip, a system chip, a chip system or a system-on-chip chip, etc.
- An embodiment of the present application further provides a computer program/program product, which is stored in a storage medium.
- the computer program/program product is executed by at least one processor to implement the various processes of the above-mentioned identification indication method embodiment and can achieve the same technical effect. To avoid repetition, it will not be repeated here.
- An embodiment of the present application also provides a communication system, including: a terminal and a first communication node, wherein the terminal can be used to execute the corresponding steps of the identification indication method described above, and the first communication node can be used to execute the corresponding steps of the identification indication method described above.
- the computer software product is stored in a storage medium (such as ROM, RAM, magnetic disk, optical disk, etc.) and includes a number of instructions for enabling a terminal or network-side device to execute the methods described in each embodiment of the present application.
- a storage medium such as ROM, RAM, magnetic disk, optical disk, etc.
Landscapes
- Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Mobile Radio Communication Systems (AREA)
- Telephonic Communication Services (AREA)
Abstract
本申请公开了一种标识指示方法、装置、终端设备及第一网络节点,属于通信领域,该方法包括:包括以下至少一项:终端设备向第一网络节点发送第一信息;终端设备从第一网络节点接收第二信息;其中,第一信息包括第一加密标识信息,第一加密标识信息是基于终端的第一标识和第一密钥生成的,且第一信息或第一加密标识信息包括在终端设备的存储信息和终端设备从第二网络节点接收的信息中的至少一项;其中,第二信息包括第二加密标识信息,第二加密标识信息是基于终端设备的第一标识和第二密钥生成的。
Description
相关申请的交叉引用
本申请要求于2024年03月08日提交中国专利局、申请号为202410267951.9、发明名称为“标识指示方法、装置、终端设备及第一网络节点”的中国专利申请的优先权,其全部内容通过引用结合在本申请中。
本申请涉及通信领域,并且更具体地,涉及一种标识指示方法、装置、终端设备及第一网络节点。
相关技术中,终端设备会使用网络的公钥加密终端设备的标识,并将加密的标识发送给网络。相应的,网络收到加密的标识后,网络会使用网络的私钥,对加密的标识进行解密,从而获得终端设备的标识。
然而,某些终端设备不具备加密标识的能力,比如没有网络的公钥或不具备使用公钥加密的算力,进而导致无法保证终端设备指示标识信息的安全性。
本申请实施例提供了一种标识指示方法、装置、终端设备及第一网络节点,能够保证终端设备指示标识信息的安全性。
第一方面,提供了一种标识指示方法,包括以下至少一项:
终端设备向第一网络节点发送第一信息;
终端设备从第一网络节点接收第二信息;
其中,所述第一信息包括第一加密标识信息,所述第一加密标识信息是基于所述终端设备的第一标识和第一密钥生成的,且所述第一信息或所述第一加密标识信息包括在所述终端设备的存储信息和所述终端设备从第二网络节点接收的信息中的至少一项;
其中,所述第二信息包括第二加密标识信息,所述第二加密标识信息是基于所述终端设备的第一标识和第二密钥生成的。
第二方面,提供了一种标识指示方法,包括以下至少一项:
第一网络节点从终端设备接收第一信息;
第一网络节点向终端设备发送第二信息;
其中,所述第一信息包括第一加密标识信息,所述第一加密标识信息是基于所述终端设备的第一标识和第一密钥生成的;
其中,所述第二信息包括第二加密标识信息,所述第二加密标识信息是基于所述终端设备的第一标识和第二密钥生成的。
第三方面,提供了一种标识指示装置,包括以下至少一项:
第一发送单元,用于向第一网络节点发送第一信息;
接收单元,用于从第一网络节点接收第二信息;
其中,所述第一信息包括第一加密标识信息,所述第一加密标识信息是基于终端设备的第一标识和第一密钥生成的,且所述第一信息或所述第一加密标识信息包括在所述终端设备的存储信息和所述终端设备从第二网络节点接收的信息中的至少一项;
其中,所述第二信息包括第二加密标识信息,所述第二加密标识信息是基于终端设备的第一标识和第二密钥生成的。
第四方面,提供了一种标识指示装置,包括以下至少一项:
接收单元,用于从终端设备接收第一信息;
发送单元,用于向终端设备发送第二信息;
其中,所述第一信息包括第一加密标识信息,所述第一加密标识信息是基于所述终端设备的第一标识和第一密钥生成的;
其中,所述第二信息包括第二加密标识信息,所述第二加密标识信息是基于所述终端设备的第一标识和第二密钥生成的。
第五方面,提供了一种终端设备,该终端设备包括处理器和存储器,所述存储器存储可在所述处理器上运行的程序或指令,所述程序或指令被所述处理器执行时实现如第一方面所述的方法的步骤。
第六方面,提供了一种终端设备,包括处理器及通信接口,其中,所述通信接口用于执行以下至少一项:
向第一网络节点发送第一信息;
从第一网络节点接收第二信息;
其中,所述第一信息包括第一加密标识信息,所述第一加密标识信息是基于终端设备的第一标识和第一密钥生成的,且所述第一信息或所述第一加密标识信息包括在终端设备的存储信息和所述终端设备从第二网络节点接收的信息中的至少一项;
其中,所述第二信息包括第二加密标识信息,所述第二加密标识信息是基于所述终端设备的第一标识和第二密钥生成的。
第七方面,提供了一种第一网络节点,该第一网络节点包括处理器和存储器,所述存储器存储可在所述处理器上运行的程序或指令,所述程序或指令被所述处理器执行时实现如第二方面所述的方法的步骤。
第八方面,提供了一种第一网络节点,包括处理器及通信接口,其中,所述通信接口用于执行以下至少一项:
从终端设备接收第一信息;
向终端设备发送第二信息;
其中,所述第一信息包括第一加密标识信息,所述第一加密标识信息是基于所述终端设备的第一标识和第一密钥生成的;
其中,所述第二信息包括第二加密标识信息,所述第二加密标识信息是基于所述终端设备的第一标识和第二密钥生成的。
第九方面,提供了一种可读存储介质,所述可读存储介质上存储程序或指令,所述程序或指令被处理器执行时实现如第一方面所述的方法的步骤,或者实现如第二方面所述的方法的步骤。
第十方面,提供了一种无线通信系统,包括:终端设备及第一网络节点,所述终端设备可用于执行如第一方面所述的方法的步骤,所述第一网络节点可用于执行如第二方面所述的方法的步骤。
第十一方面,提供了一种芯片,所述芯片包括处理器和通信接口,所述通信接口和所述处理器耦合,所述处理器用于运行程序或指令,实现如第一方面所述的方法的步骤,或实现如第二方面所述的方法的步骤。
第十二方面,提供了一种计算机程序/程序产品,所述计算机程序/程序产品被存储在存储介质中,所述程序/程序产品被至少一个处理器执行以实现如第一方面所述的方法的步骤。
本申请实施例中,终端设备向第一网络节点发送第一信息;其中,所述第一信息包括第一加密标识信息,所述第一加密标识信息是基于所述终端设备的第一标识和第一密钥生成的,且所述第一信息或所述第一加密标识信息包括在所述终端设备的存储信息和所述终端设备从第二网络节点接收的信息中的至少一项。相当于,所述终端设备可以从所述终端设备的存储信息和所述终端设备从第二网络节点接收的信息中的至少一项获取所述第一信息或第一加密标识信息,由此,即便所述终端设备不具备对标识的加密能力,也能够保证终端设备指示标识信息的安全性,也就是说,本申请通过采用终端存储信息或终端接收到的信息进行标识的加密,从而可以使得不管终端是否具有公钥或公钥解密能力,都可以根据终端的已有信息完成标识的加密或解密。终端设备从第一网络节点接收第二信息;其中,所述第二信息包括第二加密标识信息,所述第二加密标识信息是基于所述终端设备的第一标识和第二密钥生成的。相当于,所述终端设备从所述第一网络节点接收第二加密标识信息,由此,即便所述终端设备不具备对标识的加密能力,也能够保证终端设备指示标识信息的安全性。
为了更清楚地说明本申请实施例的技术方案,下面将对本申请实施例描述中所需要使用的附图作简单地介绍,显而易见地,下面描述中的附图仅仅是本申请的一些实施例,对于本领域普通技术人员来讲,在不付出创造性劳动性的前提下,还可以根据这些附图获得其他的附图。
图1是本申请实施例提供的一种系统架构的示意性图。
图2是本申请实施例提供的一种标识指示方法的示意性流程图。
图3是本申请实施例提供的另一种标识指示方法的示意性流程图。
图4是本申请实施例提供的另一种标识指示方法的示意性流程图。
图5是本申请实施例提供的一种标识指示装置的示意性框图。
图6是本申请实施例提供的另一种标识指示装置的示意性框图。
图7是本申请实施例提供的一种通信设备的示意性框图。
图8是本申请实施例提供的一种终端的硬件结构示意图。
图9是本申请实施例提供的一种网络侧设备的示意性框图。
图10是本申请实施例提供的另一种网络侧设备的示意性框图。
下面将结合本申请实施例中的附图,对本申请实施例中的技术方案进行清楚描述,显然,所描述的实施例是本申请一部分实施例,而不是全部的实施例。基于本申请中的实施例,本领域普通技术人员所获得的所有其他实施例,都属于本申请保护的范围。
本申请的术语“第一”、“第二”等是用于区别类似的对象,而不用于描述特定的顺序或先后次序。应该理解这样使用的术语在适当情况下可以互换,以便本申请的实施例能够以除了在这里图示或描述的那些以外的顺序实施,且“第一”、“第二”所区别的对象通常为一类,并不限定对象的个数,例如第一对象可以是一个,也可以是多个。此外,本申请中的“或”表示所连接对象的至少其中之一。例如“A或B”涵盖三种方案,即,方案一:包括A且不包括B;方案二:包括B且不包括A;方案三:既包括A又包括B。字符“/”一般表示前后关联对象是一种“或”的关系。
本申请的术语“指示”既可以是一个直接的指示(或者说显式的指示),也可以是一个间接的指示(或者说隐含的指示)。其中,直接的指示可以理解为,发送方在发送的指示中明确告知了接收方具体的信息、需要执行的操作或请求结果等内容;间接的指示可以理解为,接收方根据发送方发送的指示确定对应的信息,或者进行判断并根据判断结果确定需要执行的操作或请求结果等。
值得指出的是,本申请实施例所描述的技术不限于长期演进型(Long Term Evolution,LTE)/LTE的演进(LTE-Advanced,LTE-A)系统,还可用于其他无线通信系统,诸如码分多址(Code Division Multiple Access,CDMA)、时分多址(Time Division Multiple Access,TDMA)、频分多址(Frequency Division Multiple Access,FDMA)、正交频分多址(Orthogonal Frequency Division Multiple Access,OFDMA)、单载波频分多址(Single-carrier Frequency-Division Multiple Access,SC-FDMA)或其他系统。本申请实施例中的术语“系统”和“网络”常被可互换地使用,所描述的技术既可用于以上提及的系统和无线电技术,也可用于其他系统和无线电技术。以下描述出于示例目的描述了新空口(New Radio,NR)系统,并且在以下大部分描述中使用NR术语,但是这些技术也可应用于NR系统以外的系统,如第6代(6th Generation,6G)通信系统。
图1示出本申请实施例可应用的一种无线通信系统的框图。
如图1所示,无线通信系统包括终端11和网络侧设备12。其中,终端11可以是手机、平板电脑(Tablet Personal Computer)、膝上型电脑(Laptop Computer)、笔记本电脑、个人数字助理(Personal Digital Assistant,PDA)、掌上电脑、上网本、超级移动个人计算机(Ultra-mobile Personal Computer,UMPC)、移动上网装置(Mobile Internet Device,MID)、增强现实(Augmented Reality,AR)、虚拟现实(Virtual Reality,VR)设备、机器人、可穿戴式设备(Wearable Device)、飞行器(flight vehicle)、车载设备(Vehicle User Equipment,VUE)、船载设备、行人终端(Pedestrian User Equipment,PUE)、智能家居(具有无线通信功能的家居设备,如冰箱、电视、洗衣机或者家具等)、游戏机、个人计算机(Personal Computer,PC)、柜员机或者自助机等终端侧设备。可穿戴式设备包括:智能手表、智能手环、智能耳机、智能眼镜、智能首饰(智能手镯、智能手链、智能戒指、智能项链、智能脚镯、智能脚链等)、智能腕带、智能服装等。其中,车载设备也可以称为车载终端、车载控制器、车载模块、车载部件、车载芯片或车载单元等。需要说明的是,在本申请实施例并不限定终端11的具体类型。
网络侧设备12可以包括接入网设备或核心网设备。
其中,接入网设备也可以称为无线接入网(Radio Access Network,RAN)设备、无线接入网功能或无线接入网单元。接入网设备可以包括基站、无线局域网(Wireless Local Area Network,WLAN)接入点(Access Point,AP)或无线保真(Wireless Fidelity,WiFi)节点等。其中,基站可被称为节点B(Node B,NB)、演进节点B(Evolved Node B,eNB)、下一代节点B(the next generation Node B,gNB)、新空口节点B(New Radio Node B,NR Node B)、接入点、中继站(Relay Base Station,RBS)、服务基站(Serving Base Station,SBS)、基收发机站(Base Transceiver Station,BTS)、无线电基站、无线电收发机、基本服务集(Basic Service Set,BSS)、扩展服务集(Extended Service Set,ESS)、家用B节点(home Node B,HNB)、家用演进型B节点(home evolved Node B)、发送接收点(Transmission Reception Point,TRP)或所述领域中其他某个合适的术语,只要达到相同的技术效果,所述基站不限于特定技术词汇,需要说明的是,在本申请实施例中仅以NR系统中的基站为例进行介绍,并不限定基站的具体类型。
核心网设备可以包含核心网设备可以包含但不限于如下至少一项:核心网节点、核心网功能、移动管理实体(Mobility Management Entity,MME)、接入移动管理功能(Access and Mobility Management Function,AMF)、会话管理功能(Session Management Function,SMF)、用户平面功能(User Plane Function,UPF)、策略控制功能(Policy Control Function,PCF)、策略与计费规则功能单元(Policy and Charging Rules Function,PCRF)、边缘应用服务发现功能(Edge Application Server Discovery Function,EASDF)、统一数据管理(Unified Data Management,UDM)、统一数据仓储(Unified Data Repository,UDR)、归属用户服务器(Home Subscriber Server,HSS)、集中式网络配置(Centralized network configuration,CNC)、网络存储功能(Network Repository Function,NRF)、网络开放功能(Network Exposure Function,NEF)、本地NEF(Local NEF,或L-NEF)、绑定支持功能(Binding Support Function,BSF)、应用功能(Application Function,AF)等。需要说明的是,在本申请实施例中仅以NR系统中的核心网设备为例进行介绍,并不限定核心网设备的具体类型。但不限于如下至少一项:核心网节点、核心网功能、移动管理实体(Mobility Management Entity,MME)、接入移动管理功能(Access and Mobility Management Function,AMF)、会话管理功能(Session Management Function,SMF)、用户平面功能(User Plane Function,UPF)、策略控制功能(Policy Control Function,PCF)、策略与计费规则功能单元(Policy and Charging Rules Function,PCRF)、边缘应用服务发现功能(Edge Application Server Discovery Function,EASDF)、统一数据管理(Unified Data Management,UDM)、统一数据仓储(Unified Data Repository,UDR)、归属用户服务器(Home Subscriber Server,HSS)、集中式网络配置(Centralized network configuration,CNC)、网络存储功能(Network Repository Function,NRF)、网络开放功能(Network Exposure Function,NEF)、本地NEF(Local NEF,或L-NEF)、绑定支持功能(Binding Support Function,BSF)、应用功能(Application Function,AF)等。需要说明的是,在本申请实施例中仅以NR系统中的核心网设备为例进行介绍,并不限定核心网设备的具体类型。
下面结合附图,通过一些实施例及其应用场景对本申请实施例提供的标识指示方法进行详细地说明。
图2是根据本申请实施例的标识指示方法210的示意性流程图。
如图2所示,该标识指示方法210可以包括如下内容中的至少部分内容:
S211,终端设备向第一网络节点发送第一信息;
其中,所述第一信息包括第一加密标识信息,所述第一加密标识信息是基于所述终端设备的第一标识和第一密钥生成的,且所述第一信息或所述第一加密标识信息包括在所述终端设备的存储信息和所述终端设备从第二网络节点接收的信息中的至少一项。
示例性地,所述第一网络节点包括以下中至少一项:UE、接入网设备、AMF、UDM、AF、AuC。
示例性地,所述第一网络节点所属的第一网络可以是3GPP网络,比如5G网络或未来6G网络。
示例性地,所述第二网络节点包括以下中至少一项:UE、接入网设备、AMF、UDM、AF、AuC、AUSF。
示例性地,所述第二网络节点所属的第二网络可以和所述第一网络相同或不同。例如,所述第二网络可以是3GPP网络,比如5G网络或未来6G网络,甚至可以是非3GPP网络。
示例性地,所述第一加密标识信息可以是所述第一标识基于所述第一密钥加密生成的,或所述第一加密标识信息可以是以所述第一标识和所述第一密钥为输入利用加密算法生成的。
本申请实施例中,所述终端设备可以从所述终端设备的存储信息和所述终端设备从第二网络节点接收的信息中的至少一项获取所述第一加密标识信息,由此,即便所述终端设备不具备对标识的加密能力,也能够保证终端设备指示标识信息的安全性。
在一些实施例中,所述第一网络节点基于以下至少一项解密所述第一加密标识信息:
所述第一密钥;
所述第一密钥的关联密钥。
示例性地,所述第一密钥不是对称密钥(即第一密钥为公钥)时,所述关联密钥为相应的私钥。
在一些实施例中,所述第一信息还包括第四信息,所述第一加密标识信息还基于所述第四信息生成。
示例性地,所述第一加密标识信息基于所述第一标识、所述第一密钥和所述第四信息生成。
在一些实施例中,所述第一信息还包括第四信息,所述方法210还包括:
所述第一网络节点基于以下至少一项解密所述第一加密标识信息:
所述第一密钥和所述第四信息;
所述第一密钥的关联密钥和所述第四信息。
示例性地,所述第一密钥不是对称密钥(即第一密钥为公钥)时,所述关联密钥为相应的私钥。
在一些实施例中,所述第一信息还包括第一校验码,所述第一校验码是基于以下至少一项生成的:
所述第一标识和所述第一密钥;
所述第一加密标识信息和第三密钥。
在一些实施例中,所述方法210还包括:
所述终端设备基于所述第一加密标识和所述第三密钥生成所述第一校验码。
当然,在其他可替代实施例中,也可以由网络节点(可以是第一网络节点、第二网络节点、或其他网络节点)基于所述第一加密标识和所述第三密钥生成所述第一校验码,并配置给所述终端设备。
在一些实施例中,所述第一信息还包括第一校验码,所述方法210还包括:
所述第一网络节点基于以下至少一项校验所述第一校验码:
所述第一标识和所述第一密钥;
所述第一标识和所述第一密钥的关联密钥;
所述第一加密标识信息和第三密钥。
示例性地,所述第一校验码是网络节点(可以是第一网络节点、第二网络节点、或其他网络节点)生成并预配置给所述终端设备的校验码,所述第一网络节点基于以下至少一项校验所述第一校验码:
所述第一标识和所述第一密钥;
所述第一标识和所述第一密钥的关联密钥。
示例性地,所述第一校验码是所述终端设备生成的校验码,所述第一网络节点基于所述第一加密标识信息和第三密钥校验所述第一校验码。
在一些实施例中,所述第一信息还包括第一校验码和第四信息,所述第一校验码是基于以下至少一项生成的:
所述第一标识、所述第一密钥和所述第四信息;
所述第一加密标识信息、第三密钥和所述第四信息。
在一些实施例中,所述方法210还包括:
所述终端设备基于所述第一加密标识、所述第三密钥和所述第四信息生成所述第一校验码。
当然,在其他可替代实施例中,也可以由网络节点(可以是第一网络节点、第二网络节点、或其他网络节点)基于所述第一加密标识、所述第三密钥和所述第四信息生成所述第一校验码,并配置给所述终端设备。
在一些实施例中,所述第一信息还包括第一校验码和第四信息,所述方法210还包括:
所述第一网络节点基于以下至少一项校验所述第一校验码:
所述第一标识、所述第一密钥和所述第四信息;
所述第一标识、所述第一密钥的关联密钥和所述第四信息;
所述第一加密标识信息、第三密钥和所述第四信息。
示例性地,所述第一校验码是网络节点(可以是第一网络节点、第二网络节点、或其他网络节点)生成并预配置给所述终端设备的校验码,所述第一网络节点基于以下至少一项校验所述第一校验码:
所述第一标识、所述第一密钥和所述第四信息;
所述第一标识、所述第一密钥的关联密钥和所述第四信息;
示例性地,所述第一校验码是所述终端设备生成的校验码,所述第一网络节点基于所述第一加密标识信息、第三密钥和所述第四信息校验所述第一校验码。
在一些实施例中,所述第一信息还包括以下至少一项:
所述第一密钥对应的第一密钥标识或索引或指示;
第三密钥对应的第三密钥标识或索引或指示。
示例性地,所述第一密钥对应的第一密钥指示所述第一密钥的索引或标识。
示例性地,所述第三密钥对应的第三密钥指示所述第一密钥的索引或标识。
在一些实施例中,所述终端设备不知晓(is unknown)所述第一密钥。
示例性地,所述终端设备不知晓所述第一密钥,因其未获取或未从网络侧接收所述第一密钥,从而也不会生成所述第一信息和/或第一加密标识,因为所述第一信息和/或第一加密标识是需要基于所述第一密钥生成的。
在一些实施例中,所述第一密钥为对称密钥、或共享密钥、或不为非对称密钥或不是公钥。
示例性地,所述第一密钥可以是非对称密钥的公钥,或可以是对称密钥。
示例性地,对称密钥(Symmetric-key algorithm)和共享密钥在加密和解密过程中使用相同的密钥。非对称密钥(public-key cryptography)又称为公开密钥加密,则是一种不同的加密方式。在这种方式中,密钥被分为一对,即公钥和私钥。公钥是公开的,可以自由地分发给任何人使用,而私钥则是保密的,只有持有者自己知道。公钥用于加密信息,而私钥则用于解密信息。
应当理解,本申请中,所述第四信息可以是用于或参与生成第一加密标识的任意一种信息,本申请对其具体内容不作限定。
此外,本申请涉及的校验码可用于校验数据的完整性和准确性。例如,以所述第一校验码是基于所述第一标识和所述第一密钥生成的为例,所述第一网络节点收到所述第一信息后,基于所述第一标识和所述第一密钥,重新生成校验码,并基于重新生成的校验码对所述第一校验码进行校验。如果重新生成的校验码和所述第一校验码匹配成功,则说明信息在传输过程中没有被篡改或损坏,并且信息是完整和准确的。这是因为只有使用正确的标识和密钥,并且信息本身没有发生变化,才能保证生成的校验码与所述第一校验码相同。如果重新生成的校验码与所述第一校验码匹配未成功,则说明信息在传输过程中被篡改或损坏,或者,所述终端设备和所述第一网络节点使用的标识和密钥不一致。在这种情况下,所述第一网络节点可以确定信息传输失败,或要求所述终端设备重新发送或重传所述第一信息。
图3是根据本申请实施例的标识指示方法220的示意性流程图。
如图3所示,该标识指示方法220可以包括如下内容中的至少部分内容:
S221,终端设备从第一网络节点接收第二信息;
其中,所述第二信息包括第二加密标识信息,所述第二加密标识信息是基于所述终端设备的第一标识和第二密钥生成的。
示例性地,所述第一网络节点包括以下中至少一项:UE、接入网设备、AMF、UDM、AF、AuC。
示例性地,所述第一网络节点所属的第一网络可以是3GPP网络,比如5G网络或未来6G网络。
示例性地,所述第一网络节点获取或生成所述第二加密标识信息后,向所述终端设备发送所述第二信息。
示例性地,所述第一网络节点可以从第三通信节点接收所述第二信息;或者所述第一网络节点可以解密从第三通信节点接收的第二加密标识信息;或者所述第一网络节点可以生成所述第二加密标识;或所述第一网络节点可以向第三网络节点发送由所述第一网络节点生成的第二加密标识。可选的,所述第三通信节点包括以下至少一项:AUSF、UDM、AF、AuC。
示例性地,所述第二加密标识信息可以是所述第一标识基于所述第二密钥加密生成的,或所述第二加密标识信息可以是以所述第一标识和所述第二密钥为输入利用加密算法生成的。
本实施例中,所述终端设备从所述第一网络节点接收第二加密标识信息,避免了所述终端设备对所述终端设备的标识进行加密,由此,即便所述终端设备不具备对标识的加密能力,也能够保证终端设备指示标识信息的安全性。
在一些实施例中,所述方法220还包括以下至少一项:
所述终端设备保存所述第二加密标识信息或所述第二信息;
所述终端设备向第三网络节点发送第三信息,所述第三信息包括所述第二加密标识信息或所述第二信息。
在一些实施例中,所述方法220还包括:
所述第一网络节点基于所述第二密钥和所述第一标识生成所述第二加密标识信息。
示例性地,所述第一网络节点发送所述第二信息之前,基于所述第二密钥和所述第一标识生成所述第二加密标识信息。
在一些实施例中,所述第二信息还包括第五信息,所述第二加密标识信息还基于所述第五信息生成。
在一些实施例中,所述方法220还包括:
所述第一网络节点基于所述第二密钥、所述第一标识和所述第五信息生成所述第二加密标识信息。
示例性地,所述第一网络节点发送所述第二信息之前,基于所述第二密钥、所述第一标识和所述第五信息生成所述第二加密标识信息。
在一些实施例中,所述第二信息还包括第二校验码,所述第二校验码是基于以下至少一项生成的:
所述第一标识和所述第二密钥;
所述第二加密标识信息和第四密钥。
在一些实施例中,所述方法220还包括:
所述终端设备基于所述第二加密标识信息和所述第四密钥校验所述第二校验码。
示例性地,所述终端设备收到所述第二信息后,基于所述第二加密标识信息和所述第四密钥校验所述第二校验码。
在一些实施例中,所述方法220还包括:
所述第一网络节点基于以下至少一项生成所述第二校验码:
所述第一标识和所述第二密钥;
所述第二加密标识信息和第四密钥。
示例性地,所述第一网络节点发送所述第二信息之前,基于以下至少一项生成所述第二校验码:
所述第一标识和所述第二密钥;
所述第二加密标识信息和第四密钥。
在一些实施例中,所述第二信息还包括第二校验码和第五信息,所述第二校验码是基于以下至少一项生成的:
所述第一标识、所述第二密钥和所述第五信息;
所述第二加密标识信息、第四密钥和所述第五信息。
在一些实施例中,所述方法220还包括:
所述终端设备基于所述第二加密标识信息、所述第四密钥和所述第五信息校验所述第二校验码。
示例性地,所述终端设备发送所述第二信息之前,基于所述第二加密标识信息、所述第四密钥和所述第五信息校验所述第二校验码。
在一些实施例中,所述方法220还包括:
所述第一网络节点基于以下至少一项生成所述第二校验码:
所述第一标识、所述第二密钥和所述第五信息;
所述第二加密标识信息、第四密钥和所述第五信息。
当然,在其他可替代实施例中,所述第二校验码也可以由除所述第一网络节点之外的网络节点生成,本申请对此不作具体限定。
在一些实施例中,所述第二信息还包括以下至少一项:
所述第二密钥对应的第二密钥标识或索引或指示;
第四密钥对应的第四密钥标识或索引或指示。
在一些实施例中,所述终端设备不知晓所述第二密钥。
示例性地,所述终端设备不知晓所述第二密钥,因其未获取或未从网络侧接收所述第二密钥,从而也不会生成所述第二信息和/或第二加密标识,因为所述第二信息和/或第二加密标识是需要基于所述第二密钥生成的。
在一些实施例中,所述第二密钥为对称密钥、或共享密钥、或不为非对称密钥或不是公钥。
示例性地,所述第二密钥可以是非对称密钥的公钥,或可以是对称密钥。
示例性地,对称密钥(Symmetric-key algorithm)和共享密钥在加密和解密过程中使用相同的密钥。非对称密钥(public-key cryptography)又称为公开密钥加密,则是一种不同的加密方式。在这种方式中,密钥被分为一对,即公钥和私钥。公钥是公开的,可以自由地分发给任何人使用,而私钥则是保密的,只有持有者自己知道。公钥用于加密信息,而私钥则用于解密信息。
应当理解,所述第三信息可以是用于携带所述第二加密标识信息的任意一种信息,本申请对其具体内容不作限定。类似的,所述第五信息可以是用于或参与生成第二加密标识的任意一种信息,本申请对其具体内容不作限定。
此外,本申请涉及的校验码可用于校验数据的完整性和准确性。例如,以所述第二校验码是基于所述第二加密标识信息和第四密钥生成的为例,所述终端设备收到所述第二信息后,基于所述第二加密标识信息和第四密钥,重新生成校验码,并基于重新生成的校验码对所述第二校验码进行校验。如果重新生成的校验码和所述第二校验码匹配成功,则说明信息在传输过程中没有被篡改或损坏,并且信息是完整和准确的。这是因为只有使用正确的标识和密钥,并且信息本身没有发生变化,才能保证生成的校验码与所述第一校验码相同。如果重新生成的校验码与所述第二校验码匹配未成功,则说明信息在传输过程中被篡改或损坏,或者,所述终端设备和所述终端设备使用的标识和密钥不一致。在这种情况下,所述终端设备可以确定信息传输失败,或要求所述第一网络节点重新发送或重传所述第二信息。
此外,上文涉及的第三密钥和第四密钥可以不同或相同,本申请对此不作具体限定。
图4是根据本申请实施例的标识指示方法230的示意性流程图。
如图4所示,该标识指示方法230可以包括如下内容中的至少部分内容:
S231,终端设备从第一网络节点接收第二信息;
其中,所述第二信息包括第二加密标识信息和第二校验码,所述第二加密标识信息是基于所述终端设备的第一标识和第二密钥生成的。
示例性地,所述第一网络节点包括以下中至少一项:UE、接入网设备、AMF、UDM、AF、AuC。
示例性地,所述第一网络节点所属的第一网络可以是3GPP网络,比如5G网络或未来6G网络。
示例性地,所述第一网络节点获取或生成所述第二加密标识信息后,向所述终端设备发送所述第二信息。
示例性地,所述第一网络节点获取或生成所述第二校验码后,向所述终端设备发送所述第二信息。
示例性地,所述第一网络节点可以从第三通信节点接收所述第二信息;或者所述第一网络节点可以解密从第三通信节点接收的第二加密标识信息;或者所述第一网络节点可以生成所述第二加密标识;或所述第一网络节点可以向第三网络节点发送由所述第一网络节点生成的第二加密标识。可选的,所述第三通信节点包括以下至少一项:AUSF、UDM、AF、AuC。
示例性地,所述第二加密标识信息可以是所述第一标识基于所述第二密钥加密生成的,或所述第二加密标识信息可以是以所述第一标识和所述第二密钥为输入利用加密算法生成的。
本实施例中,所述终端设备从所述第一网络节点接收第二加密标识信息,避免了所述终端设备对所述终端设备的标识进行加密,由此,即便所述终端设备不具备对标识的加密能力,也能够保证所述终端设备指示标识信息的安全性。
S232,所述终端设备校验所述第二校验码,比如第二校验码基于第三密钥和所述第二加密标识生成时,所述终端设备基于所述第三密钥和所述第二加密标识信息校验所述第二校验码。
S233,所述终端设备基于第四密钥和所述第二加密标识信息生成第一校验码。
S234,所述终端设备向第二网络节点发生第三信息,其中,所述第三信息包括所述第二加密标识信息和所述第一校验码。
S235,所述第二网络节点基于第四密钥和所述第二加密标识信息校验所述第一校验码。
应当理解,所述第三密钥和所述第四密钥可以是相同的,也可以是不同的。
本申请实施例提供的标识指示方法,执行主体可以为标识指示装置。本申请实施例中以标识指示装置执行标识指示方法为例,说明本申请实施例提供的标识指示装置。
图5是根据本申请实施例提供的标识指示装置300的示意性框图。
如图5所示,所述标识指示装置300包括以下至少一项:
第一发送单元310,用于向第一网络节点发送第一信息;
接收单元320,用于从第一网络节点接收第二信息;
其中,所述第一信息包括第一加密标识信息,所述第一加密标识信息是基于终端设备的第一标识和第一密钥生成的,且所述第一信息或所述第一加密标识信息包括在所述终端设备的存储信息和所述终端设备从第二网络节点接收的信息中的至少一项;
其中,所述第二信息包括第二加密标识信息,所述第二加密标识信息是基于所述终端设备的第一标识和第二密钥生成的。
在一些实施例中,所述装置300还包括以下至少一项:
保存单元,用于保存所述第二加密标识信息或所述第二信息;
第二发送单元,用于向第三网络节点发送第三信息,所述第三信息包括所述第二加密标识信息或所述第二信息。
在一些实施例中,所述第一信息还包括第四信息,所述第一加密标识信息还基于所述第四信息生成。
在一些实施例中,所述第一信息还包括第一校验码,所述第一校验码是基于以下至少一项生成的:
所述第一标识和所述第一密钥;
所述第一加密标识信息和第三密钥。
在一些实施例中,所述装置300还包括:
第一生成单元,用于基于所述第一加密标识和所述第三密钥生成所述第一校验码。
在一些实施例中,所述第一信息还包括第一校验码和第四信息,所述第一校验码是基于以下至少一项生成的:
所述第一标识、所述第一密钥和所述第四信息;
所述第一加密标识信息、第三密钥和所述第四信息。
在一些实施例中,所述装置300还包括:
第二生成单元,用于基于所述第一加密标识、所述第三密钥和所述第四信息生成所述第一校验码。
在一些实施例中,所述第一信息还包括以下至少一项:
所述第一密钥对应的第一密钥标识或索引或指示;
第三密钥对应的第三密钥标识或索引或指示。
在一些实施例中,所述第二信息还包括第五信息,所述第二加密标识信息还基于所述第五信息生成。
在一些实施例中,所述第二信息还包括第二校验码,所述第二校验码是基于以下至少一项生成的:
所述第一标识和所述第二密钥;
所述第二加密标识信息和第四密钥。
在一些实施例中,所述装置300还包括:
第一校验单元,用于基于所述第二加密标识信息和所述第四密钥校验所述第二校验码。
在一些实施例中,所述第二信息还包括第二校验码和第五信息,所述第二校验码是基于以下至少一项生成的:
所述第一标识、所述第二密钥和所述第五信息;
所述第二加密标识信息、第四密钥和所述第五信息。
在一些实施例中,所述装置300还包括:
第二校验单元,用于基于所述第二加密标识信息、所述第四密钥和所述第五信息校验所述第二校验码。
在一些实施例中,所述第二信息还包括以下至少一项:
所述第二密钥对应的第二密钥标识或索引或指示;
第四密钥对应的第四密钥标识或索引或指示。
在一些实施例中,所述终端设备不知晓所述第一密钥和所述第二密钥中的至少一项。
应理解,本申请实施例提供的标识指示装置300可对应于本申请方法实施例中的终端设备,并且标识指示装置300中的各个单元分别为了实现图2所示的方法210、图3所示的方法220或图4所示的方法230的相应流程,为了简洁,在此不再赘述。
在本申请实施例中,
图6是根据本申请实施例提供的标识指示装置400的示意性框图。
如图6所示,该标识指示装置400包括以下至少一项:
接收单元410,用于从终端设备接收第一信息;
发送单元420,用于向终端设备发送第二信息;
其中,所述第一信息包括第一加密标识信息,所述第一加密标识信息是基于所述终端设备的第一标识和第一密钥生成的;
其中,所述第二信息包括第二加密标识信息,所述第二加密标识信息是基于所述终端设备的第一标识和第二密钥生成的。
在一些实施例中,所述装置400还包括:
第一解密单元,用于基于以下至少一项解密所述第一加密标识信息:
所述第一密钥;
所述第一密钥的关联密钥。
在一些实施例中,所述第一信息还包括第四信息,所述装置400还包括:
第二解密单元,用于基于以下至少一项解密所述第一加密标识信息:
所述第一密钥和所述第四信息;
所述第一密钥的关联密钥和所述第四信息。
在一些实施例中,所述第一信息还包括第一校验码,所述装置400还包括:
第一校验单元,用于基于以下至少一项校验所述第一校验码:
所述第一标识和所述第一密钥;
所述第一标识和所述第一密钥的关联密钥;
所述第一加密标识信息和第三密钥。
在一些实施例中,所述第一信息还包括第一校验码和第四信息,所述装置400还包括:
第二校验单元,用于基于以下至少一项校验所述第一校验码:
所述第一标识、所述第一密钥和所述第四信息;
所述第一标识、所述第一密钥的关联密钥和所述第四信息;
所述第一加密标识信息、第三密钥和所述第四信息。
在一些实施例中,所述第一信息还包括以下至少一项:
所述第一密钥对应的第一密钥标识或索引或指示;
第三密钥对应的第三密钥标识或索引或指示。
在一些实施例中,所述装置400还包括:
第一生成单元,用于基于所述第二密钥和所述第一标识生成所述第二加密标识信息。
在一些实施例中,所述第二信息还包括第五信息,所述第二加密标识信息还基于所述第五信息生成。
在一些实施例中,所述装置400还包括:
第二生成单元,用于基于所述第二密钥、所述第一标识和所述第五信息生成所述第二加密标识信息。
在一些实施例中,所述第二信息还包括第二校验码,所述第二校验码是基于以下至少一项生成的:
所述第一标识和所述第二密钥;
所述第二加密标识信息和第四密钥。
在一些实施例中,所述装置400还包括:
第三生成单元,用于基于以下至少一项生成所述第二校验码:
所述第一标识和所述第二密钥;
所述第二加密标识信息和第四密钥。
在一些实施例中,所述第二信息还包括第二校验码和第五信息,所述第二校验码是基于以下至少一项生成的:
所述第一标识、所述第二密钥和所述第五信息;
所述第二加密标识信息、第四密钥和所述第五信息。
在一些实施例中,所述装置400还包括:
第四生成单元,用于基于以下至少一项生成所述第二校验码:
所述第一标识、所述第二密钥和所述第五信息;
所述第二加密标识信息、第四密钥和所述第五信息。
在一些实施例中,所述第二信息还包括以下至少一项:
第二密钥对应的第二密钥标识或索引或指示;
第四密钥对应的第四密钥标识或索引或指示。
应理解,本申请实施例提供的标识指示装置400可对应于本申请方法实施例中的第一网络节点,并且标识指示装置400中的各个单元分别为了实现图2所示的方法210、图3所示的方法220或图4所示的方法230的相应流程,为了简洁,在此不再赘述。
在本申请实施例中,
本申请实施例中的标识指示装置可以是电子设备,例如具有操作系统的电子设备,也可以是电子设备中的部件,例如集成电路或芯片。该电子设备可以是终端设备或第一网络节点,该第一网络节点可以是网络侧设备或其他设备。示例性的,终端的类型可以包括但不限于上述所列举的终端11的类型,网络侧设备的类型可以包括但不限于上述所列举的网络侧设备12的类型,其他设备可以为服务器、网络附属存储器(Network Attached Storage,NAS)等,本申请实施例不作具体限定。
本申请实施例提供的标识指示装置能够实现图2至图4的方法实施例实现的各个过程,并达到相同的技术效果,为避免重复,这里不再赘述。
本申请实施例还提供一种通信设备500,如图7所示,该通信设备500包括处理器501和存储器502,存储器502上存储有可在所述处理器501上运行的程序或指令,该程序或指令被处理器501执行时实现上述标识指示方法实施例的各个步骤。例如,该通信设备500为终端设备时,该程序或指令被处理器501执行时实现上述标识指示方法实施例中由终端设备执行的各个步骤,且能达到相同的技术效果。该通信设备500为第一网络节点时,该程序或指令被处理器501执行时实现上述标识指示方法实施例中由第一网络节点执行的各个步骤,且能达到相同的技术效果,为避免重复,这里不再进行赘述。
本申请实施例还提供一种终端,包括处理器和通信接口,所述通信接口和所述处理器耦合,所述处理器用于运行程序或指令,实现如上所述的标识指示方法实施例中的步骤。该终端实施例与上述终端侧方法实施例对应,上述方法实施例的各个实施过程和实现方式均可适用于该终端实施例中,且能达到相同的技术效果。
具体地,图8为实现本申请实施例的一种终端600的硬件结构示意图。
如图8所示,该终端600包括但不限于:射频单元601、网络模块602、音频输出单元603、输入单元604、传感器605、显示单元606、用户输入单元607、接口单元608、存储器609以及处理器610等中的至少部分部件。
本领域技术人员可以理解,终端600还可以包括给各个部件供电的电源(比如电池),电源可以通过电源管理系统与处理器610逻辑相连,从而通过电源管理系统实现管理充电、放电以及功耗管理等功能。图8中示出的终端结构并不构成对终端的限定,终端可以包括比图示更多或更少的部件,或者组合某些部件,或者不同的部件布置,在此不再赘述。
应理解的是,本申请实施例中,输入单元604可以包括图形处理器(Graphics Processing Unit,GPU)6041和麦克风6042,图形处理器6041对在视频捕获模式或图像捕获模式中由图像捕获装置(如摄像头)获得的静态图片或视频的图像数据进行处理。显示单元606可包括显示面板6061,可以采用液晶显示器、有机发光二极管等形式来配置显示面板6061。用户输入单元607包括触控面板6071以及其他输入设备6072中的至少一种。触控面板6071,也称为触摸屏。触控面板6071可包括触摸检测装置和触摸控制器两个部分。其他输入设备6072可以包括但不限于物理键盘、功能键(比如音量控制按键、开关按键等)、轨迹球、鼠标、操作杆,在此不再赘述。
本申请实施例中,射频单元601接收来自网络侧设备的下行数据后,可以传输给处理器610进行处理;另外,射频单元601可以向网络侧设备发送上行数据。通常,射频单元601包括但不限于天线、放大器、收发信机、耦合器、低噪声放大器、双工器等。
存储器609可用于存储软件程序或指令以及各种数据。存储器609可主要包括存储程序或指令的第一存储区和存储数据的第二存储区,其中,第一存储区可存储操作系统、至少一个功能所需的应用程序或指令(比如声音播放功能、图像播放功能等)等。此外,存储器609可以包括易失性存储器或非易失性存储器。其中,非易失性存储器可以是只读存储器(Read-Onl7 Memor7,ROM)、可编程只读存储器(Programmable ROM,PROM)、可擦除可编程只读存储器(Erasable PROM,EPROM)、电可擦除可编程只读存储器(Electricall7 EPROM,EEPROM)或闪存。易失性存储器可以是随机存取存储器(Random Access Memor7,RAM),静态随机存取存储器(Static RAM,SRAM)、动态随机存取存储器(D7namic RAM,DRAM)、同步动态随机存取存储器(S7nchronous DRAM,SDRAM)、双倍数据速率同步动态随机存取存储器(Double Data Rate SDRAM,DDRSDRAM)、增强型同步动态随机存取存储器(Enhanced SDRAM,ESDRAM)、同步连接动态随机存取存储器(S7nch link DRAM,SLDRAM)和直接内存总线随机存取存储器(Direct Rambus RAM,DRRAM)。本申请实施例中的存储器609包括但不限于这些和任意其它适合类型的存储器。
处理器610可包括一个或多个处理单元;可选的,处理器610集成应用处理器和调制解调处理器,其中,应用处理器主要处理涉及操作系统、用户界面和应用程序等的操作,调制解调处理器主要处理无线通信信号,如基带处理器。可以理解的是,上述调制解调处理器也可以不集成到处理器610中。
在一种实现方式中,该射频单元601用于执行以下至少一项:
向第一网络节点发送第一信息;
从第一网络节点接收第二信息;
其中,所述第一信息包括第一加密标识信息,所述第一加密标识信息是基于终端设备的第一标识和第一密钥生成的,且所述第一信息或所述第一加密标识信息包括在所述终端设备的存储信息和所述终端设备从第二网络节点接收的信息中的至少一项;
其中,所述第二信息包括第二加密标识信息,所述第二加密标识信息是基于所述终端设备的第一标识和第二密钥生成的。
在另一种实现方式中,该终端600可作为上文涉及的第一通信节点,基于此,该射频单元601用于执行以下至少一项:
从终端设备接收第一信息;
向终端设备发送第二信息;
其中,所述第一信息包括第一加密标识信息,所述第一加密标识信息是基于所述终端设备的第一标识和第一密钥生成的,所述第二信息包括第二加密标识信息,所述第二加密标识信息是基于所述第一标识和第二密钥生成的。
本申请实施例中,终端设备向第一网络节点发送第一信息;其中,所述第一信息包括第一加密标识信息,所述第一加密标识信息是基于所述终端设备的第一标识和第一密钥生成的,且所述第一信息或所述第一加密标识信息包括在所述终端设备的存储信息和所述终端设备从第二网络节点接收的信息中的至少一项。相当于,所述终端设备可以从所述终端设备的存储信息和所述终端设备从第二网络节点接收的信息中的至少一项获取所述第一信息或所述第一加密标识信息,由此,即便所述终端设备不具备对标识的加密能力,也能够保证终端设备指示标识信息的安全性。终端设备从第一网络节点接收第二信息;其中,所述第二信息包括第二加密标识信息,所述第二加密标识信息是基于所述终端设备的第一标识和第二密钥生成的。相当于,所述终端设备从所述第一网络节点接收第二加密标识信息,由此,即便所述终端设备不具备对标识的加密能力,也能够保证终端设备指示标识信息的安全性。
可以理解,本实施例中提及的各实现方式的实现过程可以参照方法实施例的相关描述,并达到相同或相应的技术效果,为避免重复,在此不再赘述。
本申请实施例还提供一种网络侧设备,包括处理器和通信接口,所述通信接口和所述处理器耦合,所述处理器用于运行程序或指令,实现如上所示的标识指示方法实施例的步骤。该网络侧设备实施例与上述网络侧设备方法实施例对应,上述方法实施例的各个实施过程和实现方式均可适用于该网络侧设备实施例中,且能达到相同的技术效果。
具体地,本申请实施例还提供了一种网络侧设备。如图9所示,该网络侧设备700包括:天线71、射频装置72、基带装置73、处理器74和存储器75。天线71与射频装置72连接。在上行方向上,射频装置72通过天线71接收信息,将接收的信息发送给基带装置73进行处理。在下行方向上,基带装置73对要发送的信息进行处理,并发送给射频装置72,射频装置72对收到的信息进行处理后经过天线71发送出去。
以上实施例中网络侧设备执行的方法可以在基带装置73中实现,该基带装置73包括基带处理器。
基带装置73例如可以包括至少一个基带板,该基带板上设置有多个芯片,如图8所示,其中一个芯片例如为基带处理器,通过总线接口与存储器75连接,以调用存储器75中的程序,执行以上方法实施例中所示的网络设备操作。
该网络侧设备还可以包括网络接口76,该接口例如为通用公共无线接口(Common Public Radio Interface,CPRI)。
具体地,本申请实施例的网络侧设备700还包括:存储在存储器75上并可在处理器74上运行的指令或程序,处理器74调用存储器75中的指令或程序执行图6所示的各模块执行的方法,并达到相同的技术效果,为避免重复,故不在此赘述。
具体地,本申请实施例还提供了一种网络侧设备。如图10所示,该网络侧设备800包括:处理器801、网络接口802和存储器803。其中,网络接口802例如为通用公共无线接口(common public radio interface,CPRI)。
具体地,本申请实施例的网络侧设备800还包括:存储在存储器803上并可在处理器801上运行的指令或程序,处理器801调用存储器803中的指令或程序执行图6所示的各模块执行的方法,并达到相同的技术效果,为避免重复,故不在此赘述。
本申请实施例还提供一种可读存储介质,所述可读存储介质上存储有程序或指令,该程序或指令被处理器执行时实现上述标识指示方法实施例的各个过程,且能达到相同的技术效果,为避免重复,这里不再赘述。
其中,所述处理器为上述实施例中所述的终端中的处理器。所述可读存储介质,包括计算机可读存储介质,如计算机只读存储器ROM、随机存取存储器RAM、磁碟或者光盘等。在一些示例中,可读存储介质可以是非瞬态的可读存储介质。
本申请实施例另提供了一种芯片,所述芯片包括处理器和通信接口,所述通信接口和所述处理器耦合,所述处理器用于运行程序或指令,实现上述标识指示方法实施例的各个过程,且能达到相同的技术效果,为避免重复,这里不再赘述。
应理解,本申请实施例提到的芯片还可以称为系统级芯片,系统芯片,芯片系统或片上系统芯片等。
本申请实施例另提供了一种计算机程序/程序产品,所述计算机程序/程序产品被存储在存储介质中,所述计算机程序/程序产品被至少一个处理器执行以实现上述标识指示方法实施例的各个过程,且能达到相同的技术效果,为避免重复,这里不再赘述。
本申请实施例还提供了一种通信系统,包括:终端及第一通信节点,所述终端可用于执行如上所述的标识指示方法的相应步骤,所述第一通信节点可用于执行如上所述的标识指示方法的相应步骤。
需要说明的是,在本文中,术语“包括”、“包含”或者其任何其他变体意在涵盖非排他性的包含,从而使得包括一系列要素的过程、方法、物品或者装置不仅包括那些要素,而且还包括没有明确列出的其他要素,或者是还包括为这种过程、方法、物品或者装置所固有的要素。在没有更多限制的情况下,由语句“包括一个……”限定的要素,并不排除在包括该要素的过程、方法、物品或者装置中还存在另外的相同要素。此外,需要指出的是,本申请实施方式中的方法和装置的范围不限按示出或讨论的顺序来执行功能,还可包括根据所涉及的功能按基本同时的方式或按相反的顺序来执行功能,例如,可以按不同于所描述的次序来执行所描述的方法,并且还可以添加、省去或组合各种步骤。另外,参照某些示例所描述的特征可在其他示例中被组合。
通过以上的实施方式的描述,本领域的技术人员可以清楚地了解到上述实施例方法可借助计算机软件产品加必需的通用硬件平台的方式来实现,当然也可以通过硬件。该计算机软件产品存储在存储介质(如ROM、RAM、磁碟、光盘等)中,包括若干指令,用以使得终端或者网络侧设备执行本申请各个实施例所述的方法。
上面结合附图对本申请的实施例进行了描述,但是本申请并不局限于上述的具体实施方式,上述的具体实施方式仅仅是示意性的,而不是限制性的,本领域的普通技术人员在本申请的启示下,在不脱离本申请宗旨和权利要求所保护的范围情况下,还可做出很多形式的实施方式,这些实施方式均属于本申请的保护之内。
Claims (50)
- 一种标识指示方法,其中,包括以下至少一项:终端设备向第一网络节点发送第一信息;终端设备从第一网络节点接收第二信息;其中,所述第一信息包括第一加密标识信息,所述第一加密标识信息是基于所述终端设备的第一标识和第一密钥生成的,且所述第一信息或所述第一加密标识信息包括在所述终端设备的存储信息和所述终端设备从第二网络节点接收的信息中的至少一项;其中,所述第二信息包括第二加密标识信息,所述第二加密标识信息是基于所述终端设备的第一标识和第二密钥生成的。
- 根据权利要求1所述的方法,其中,所述方法还包括以下至少一项:所述终端设备保存所述第二加密标识信息或所述第二信息;所述终端设备向第三网络节点发送第三信息,所述第三信息包括所述第二加密标识信息或所述第二信息。
- 根据权利要求1或2所述的方法,其中,所述第一信息还包括第四信息,所述第一加密标识信息还基于所述第四信息生成。
- 根据权利要求1至3中任一项所述的方法,其中,所述第一信息还包括第一校验码,所述第一校验码是基于以下至少一项生成的:所述第一标识和所述第一密钥;所述第一加密标识信息和第三密钥。
- 根据权利要求4所述的方法,其中,所述方法还包括:所述终端设备基于所述第一加密标识和所述第三密钥生成所述第一校验码。
- 根据权利要求1至3中任一项所述的方法,其中,所述第一信息还包括第一校验码和第四信息,所述第一校验码是基于以下至少一项生成的:所述第一标识、所述第一密钥和所述第四信息;所述第一加密标识信息、第三密钥和所述第四信息。
- 根据权利要求6所述的方法,其中,所述方法还包括:所述终端设备基于所述第一加密标识、所述第三密钥和所述第四信息生成所述第一校验码。
- 根据权利要求1至7中任一项所述的方法,其中,所述第一信息还包括以下至少一项:所述第一密钥对应的第一密钥标识或索引或指示;第三密钥对应的第三密钥标识或索引或指示。
- 根据权利要求1至8中任一项所述的方法,其中,所述第二信息还包括第五信息,所述第二加密标识信息还基于所述第五信息生成。
- 根据权利要求1至9中任一项所述的方法,其中,所述第二信息还包括第二校验码,所述第二校验码是基于以下至少一项生成的:所述第一标识和所述第二密钥;所述第二加密标识信息和第四密钥。
- 根据权利要求10所述的方法,其中,所述方法还包括:所述终端设备基于所述第二加密标识信息和所述第四密钥校验所述第二校验码。
- 根据权利要求1至9中任一项所述的方法,其中,所述第二信息还包括第二校验码和第五信息,所述第二校验码是基于以下至少一项生成的:所述第一标识、所述第二密钥和所述第五信息;所述第二加密标识信息、第四密钥和所述第五信息。
- 根据权利要求12所述的方法,其中,所述方法还包括:所述终端设备基于所述第二加密标识信息、所述第四密钥和所述第五信息校验所述第二校验码。
- 根据权利要求1至13中任一项所述的方法,其中,所述第二信息还包括以下至少一项:所述第二密钥对应的第二密钥标识或索引或指示;第四密钥对应的第四密钥标识或索引或指示。
- 根据权利要求1至14中任一项所述的方法,其中,所述终端设备不知晓所述第一密钥和所述第二密钥中的至少一项。
- 一种标识指示方法,其中,包括以下至少一项:第一网络节点从终端设备接收第一信息;第一网络节点向终端设备发送第二信息;其中,所述第一信息包括第一加密标识信息,所述第一加密标识信息是基于所述终端设备的第一标识和第一密钥生成的;其中,所述第二信息包括第二加密标识信息,所述第二加密标识信息是基于所述终端设备的第一标识和第二密钥生成的。
- 根据权利要求16所述的方法,其中,所述方法还包括:所述第一网络节点基于以下至少一项解密所述第一加密标识信息:所述第一密钥;所述第一密钥的关联密钥。
- 根据权利要求16所述的方法,其中,所述第一信息还包括第四信息,所述方法还包括:所述第一网络节点基于以下至少一项解密所述第一加密标识信息:所述第一密钥和所述第四信息;所述第一密钥的关联密钥和所述第四信息。
- 根据权利要求16至18中任一项所述的方法,其中,所述第一信息还包括第一校验码,所述方法还包括:所述第一网络节点基于以下至少一项校验所述第一校验码:所述第一标识和所述第一密钥;所述第一标识和所述第一密钥的关联密钥;所述第一加密标识信息和第三密钥。
- 根据权利要求16至18中任一项所述的方法,其中,所述第一信息还包括第一校验码和第四信息,所述方法还包括:所述第一网络节点基于以下至少一项校验所述第一校验码:所述第一标识、所述第一密钥和所述第四信息;所述第一标识、所述第一密钥的关联密钥和所述第四信息;所述第一加密标识信息、第三密钥和所述第四信息。
- 根据权利要求16至20中任一项所述的方法,其中,所述第一信息还包括以下至少一项:所述第一密钥对应的第一密钥标识或索引或指示;第三密钥对应的第三密钥标识或索引或指示。
- 根据权利要求16至21中任一项所述的方法,其中,所述方法还包括:所述第一网络节点基于所述第二密钥和所述第一标识生成所述第二加密标识信息。
- 根据权利要求16至21中任一项所述的方法,其中,所述第二信息还包括第五信息,所述第二加密标识信息还基于所述第五信息生成。
- 根据权利要求23所述的方法,其中,所述方法还包括:所述第一网络节点基于所述第二密钥、所述第一标识和所述第五信息生成所述第二加密标识信息。
- 根据权利要求16至24中任一项所述的方法,其中,所述第二信息还包括第二校验码,所述第二校验码是基于以下至少一项生成的:所述第一标识和所述第二密钥;所述第二加密标识信息和第四密钥。
- 根据权利要求25所述的方法,其中,所述方法还包括:所述第一网络节点基于以下至少一项生成所述第二校验码:所述第一标识和所述第二密钥;所述第二加密标识信息和第四密钥。
- 根据权利要求16至24中任一项所述的方法,其中,所述第二信息还包括第二校验码和第五信息,所述第二校验码是基于以下至少一项生成的:所述第一标识、所述第二密钥和所述第五信息;所述第二加密标识信息、第四密钥和所述第五信息。
- 根据权利要求27所述的方法,其中,所述方法还包括:所述第一网络节点基于以下至少一项生成所述第二校验码:所述第一标识、所述第二密钥和所述第五信息;所述第二加密标识信息、第四密钥和所述第五信息。
- 根据权利要求16至28中任一项所述的方法,其中,所述第二信息还包括以下至少一项:第二密钥对应的第二密钥标识或索引或指示;第四密钥对应的第四密钥标识或索引或指示。
- 一种标识指示装置,其中,包括以下至少一项:第一发送单元,用于向第一网络节点发送第一信息;接收单元,用于从第一网络节点接收第二信息;其中,所述第一信息包括第一加密标识信息,所述第一加密标识信息是基于终端设备的第一标识和第一密钥生成的,且所述第一信息或所述第一加密标识信息包括在所述终端设备的存储信息和所述终端设备从第二网络节点接收的信息中的至少一项;其中,所述第二信息包括第二加密标识信息,所述第二加密标识信息是基于终端设备的第一标识和第二密钥生成的。
- 根据权利要求30所述的装置,其中,所述装置还包括以下至少一项:保存单元,用于保存所述第二加密标识信息或所述第二信息;第二发送单元,用于向第三网络节点发送第三信息,所述第三信息包括所述第二加密标识信息或所述第二信息。
- 根据权利要求30或31所述的装置,其中,所述第一信息还包括第四信息,所述第一加密标识信息还基于所述第四信息生成。
- 根据权利要求30至32中任一项所述的装置,其中,所述第一信息还包括第一校验码,所述第一校验码是基于以下至少一项生成的:所述第一标识和所述第一密钥;所述第一加密标识信息和第三密钥。
- 根据权利要求30至32中任一项所述的装置,其中,所述第一信息还包括第一校验码和第四信息,所述第一校验码是基于以下至少一项生成的:所述第一标识、所述第一密钥和所述第四信息;所述第一加密标识信息、第三密钥和所述第四信息。
- 根据权利要求30至34中任一项所述的装置,其中,所述第二信息还包括第五信息,所述第二加密标识信息还基于所述第五信息生成。
- 根据权利要求30至35中任一项所述的装置,其中,所述第二信息还包括第二校验码,所述第二校验码是基于以下至少一项生成的:所述第一标识和所述第二密钥;所述第二加密标识信息和第四密钥。
- 根据权利要求30至35中任一项所述的装置,其中,所述第二信息还包括第二校验码和第五信息,所述第二校验码是基于以下至少一项生成的:所述第一标识、所述第二密钥和所述第五信息;所述第二加密标识信息、第四密钥和所述第五信息。
- 一种标识指示装置,其中,包括以下至少一项:接收单元,用于从终端设备接收第一信息;发送单元,用于向终端设备发送第二信息;其中,所述第一信息包括第一加密标识信息,所述第一加密标识信息是基于所述终端设备的第一标识和第一密钥生成的;其中,所述第二信息包括第二加密标识信息,所述第二加密标识信息是基于所述终端设备的第一标识和第二密钥生成的。
- 根据权利要求38所述的装置,其中,所述装置还包括:第一解密单元,用于基于以下至少一项解密所述第一加密标识信息:所述第一密钥;所述第一密钥的关联密钥。
- 根据权利要求38所述的装置,其中,所述第一信息还包括第四信息,所述装置还包括:第二解密单元,用于基于以下至少一项解密所述第一加密标识信息:所述第一密钥和所述第四信息;所述第一密钥的关联密钥和所述第四信息。
- 根据权利要求38至40中任一项所述的装置,其中,所述第一信息还包括第一校验码,所述装置还包括:第一校验单元,用于基于以下至少一项校验所述第一校验码:所述第一标识和所述第一密钥;所述第一标识和所述第一密钥的关联密钥;所述第一加密标识信息和第三密钥。
- 根据权利要求38至40中任一项所述的装置,其中,所述第一信息还包括第一校验码和第四信息,所述装置还包括:第二校验单元,用于基于以下至少一项校验所述第一校验码:所述第一标识、所述第一密钥和所述第四信息;所述第一标识、所述第一密钥的关联密钥和所述第四信息;所述第一加密标识信息、第三密钥和所述第四信息。
- 根据权利要求38至42中任一项所述的装置,其中,所述装置还包括:第一生成单元,用于基于所述第二密钥和所述第一标识生成所述第二加密标识信息。
- 根据权利要求38至42中任一项所述的装置,其中,所述第二信息还包括第五信息,所述第二加密标识信息还基于所述第五信息生成。
- 根据权利要求44所述的装置,其中,所述装置还包括:第二生成单元,用于基于所述第二密钥、所述第一标识和所述第五信息生成所述第二加密标识信息。
- 根据权利要求38至45中任一项所述的装置,其中,所述第二信息还包括第二校验码,所述第二校验码是基于以下至少一项生成的:所述第一标识和所述第二密钥;所述第二加密标识信息和第四密钥。
- 根据权利要求38至46中任一项所述的装置,其中,所述第二信息还包括第二校验码和第五信息,所述第二校验码是基于以下至少一项生成的:所述第一标识、所述第二密钥和所述第五信息;所述第二加密标识信息、第四密钥和所述第五信息。
- 一种终端设备,其中,包括处理器和存储器,所述存储器存储可在所述处理器上运行的程序或指令,所述程序或指令被所述处理器执行时实现根据权利要求1至15中任一项所述的标识指示方法的步骤。
- 一种第一网络节点,其中,包括处理器和存储器,所述存储器存储可在所述处理器上运行的程序或指令,所述程序或指令被所述处理器执行时实现根据权利要求16至29中任一项所述的标识指示方法的步骤。
- 一种可读存储介质,其中,所述可读存储介质上存储程序或指令,所述程序或指令被处理器执行时实现根据权利要求1至15中任一项所述的标识指示方法的步骤,或者实现根据权利要求16至29中任一项所述的标识指示方法的步骤。
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| CN202410267951.9A CN120614590A (zh) | 2024-03-08 | 2024-03-08 | 标识指示方法、装置、终端设备及第一网络节点 |
| CN202410267951.9 | 2024-03-08 |
Publications (2)
| Publication Number | Publication Date |
|---|---|
| WO2025185705A1 true WO2025185705A1 (zh) | 2025-09-12 |
| WO2025185705A8 WO2025185705A8 (zh) | 2025-10-02 |
Family
ID=96931311
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| PCT/CN2025/081056 Pending WO2025185705A1 (zh) | 2024-03-08 | 2025-03-06 | 标识指示方法、装置、终端设备及第一网络节点 |
Country Status (2)
| Country | Link |
|---|---|
| CN (1) | CN120614590A (zh) |
| WO (1) | WO2025185705A1 (zh) |
Citations (4)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| WO2018053804A1 (zh) * | 2016-09-23 | 2018-03-29 | 华为技术有限公司 | 一种加密保护方法及相关设备 |
| CN113766495A (zh) * | 2020-05-30 | 2021-12-07 | 华为技术有限公司 | 信息保护方法、系统及通信装置 |
| CN114501417A (zh) * | 2020-11-12 | 2022-05-13 | 华为技术有限公司 | 一种信息发送方法及装置 |
| CN116600290A (zh) * | 2022-02-07 | 2023-08-15 | 华为技术有限公司 | 网络校验的方法和装置 |
-
2024
- 2024-03-08 CN CN202410267951.9A patent/CN120614590A/zh active Pending
-
2025
- 2025-03-06 WO PCT/CN2025/081056 patent/WO2025185705A1/zh active Pending
Patent Citations (4)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| WO2018053804A1 (zh) * | 2016-09-23 | 2018-03-29 | 华为技术有限公司 | 一种加密保护方法及相关设备 |
| CN113766495A (zh) * | 2020-05-30 | 2021-12-07 | 华为技术有限公司 | 信息保护方法、系统及通信装置 |
| CN114501417A (zh) * | 2020-11-12 | 2022-05-13 | 华为技术有限公司 | 一种信息发送方法及装置 |
| CN116600290A (zh) * | 2022-02-07 | 2023-08-15 | 华为技术有限公司 | 网络校验的方法和装置 |
Also Published As
| Publication number | Publication date |
|---|---|
| CN120614590A (zh) | 2025-09-09 |
| WO2025185705A8 (zh) | 2025-10-02 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| US12368701B2 (en) | Subscription data management method and apparatus | |
| EP4021048B1 (en) | Identity authentication method and apparatus | |
| WO2024131793A1 (zh) | 读写器的管理方法、终端及网络侧设备 | |
| US20250344065A1 (en) | Message transmission method and apparatus, and device | |
| WO2023202631A1 (zh) | 签约方法、装置、通信设备、物联网设备及网元 | |
| WO2023143418A1 (zh) | 设备鉴权方法、装置、终端及网络功能 | |
| US20230328532A1 (en) | Communication method and apparatus for trusted or untrusted relay, terminal, and network side device | |
| WO2025185705A1 (zh) | 标识指示方法、装置、终端设备及第一网络节点 | |
| WO2024012279A1 (zh) | 信息传输方法、装置及设备 | |
| WO2023005898A1 (zh) | 多终端联合会话管理方法、网络侧设备及终端 | |
| WO2025214273A1 (zh) | 无线通信方法、装置及设备 | |
| WO2025209485A1 (zh) | 激活安全的方法、终端及网络侧设备 | |
| WO2025055786A1 (zh) | 认证处理方法、装置、终端及网络侧设备 | |
| WO2025185719A1 (zh) | 无线通信方法、装置及设备 | |
| WO2025185746A1 (zh) | 无线通信方法、装置及设备 | |
| EP4664958A1 (en) | Data processing method and apparatus, network side device and terminal device | |
| WO2025168047A1 (zh) | 无线通信方法、装置、设备及存储介质 | |
| WO2025209362A1 (zh) | 通信方法、装置、设备及存储介质 | |
| CN120786363A (zh) | 安全信息的交互方法、装置、设备及系统 | |
| CN122002280A (zh) | 网络切换的方法、终端及网络侧设备 | |
| WO2025119357A1 (zh) | 交互方法、装置、系统、终端及网络侧设备 | |
| WO2024255685A1 (zh) | 数据传输方法、装置及通信设备 | |
| CN121842666A (zh) | 认证方法、装置及设备 | |
| CN120264414A (zh) | 信息处理方法、装置及通信设备 | |
| CN120128916A (zh) | 安全通信方法、装置、系统、终端及网络侧设备 |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| 121 | Ep: the epo has been informed by wipo that ep was designated in this application |
Ref document number: 25767445 Country of ref document: EP Kind code of ref document: A1 |