CN102932784A

Terminal communication method and device

Abstract

The embodiment of the invention provides a terminal communication method and a terminal communication device. The method comprises the steps that: a first device carries out encryption on service information by using a derivative key of a root key of a terminal communication key, wherein the root key of the terminal communication key is generated by a root key generated through authentication and key agreement AKA by the first device and a second device, the first device is a terminal, and the second device is a network side device, or the first device is a network side device, and the second device is a terminal; and the first device sends the service information subjected to encryption to the second device, so that the second device carries out decryption on the received service information by using the derivative key of the root key of the terminal communication key. According to the embodiment of the invention, the confidentiality or integrity protection on service information transmitted between the terminal and the network side device is realized.

Term

No projected expiry on record.

  1. Priority and filed
  2. Published
  3. Today

39 claims: 25 independent, 14 dependent

  1. 1
    The communication method of terminal, comprising a characterised, comprising:The first device for communication terminal key are key derived from bottom to encrypt the service information, the root key generation of the terminal communication same as the key is the first device and second device authentication and key consulted AKA generating, wherein the first device is a terminal;the second device for network side device;Or, wherein the first device for network side device;the second device is a terminal;After the first device to encrypt the service information sending of the second device, so of the second device uses a communication terminal key are key derived a key service information to the receiving to a. 1. 一种终端的通信方法,其特征在于,包括: 第一设备采用终端通信密钥的根密钥的衍生密钥对业务信息进行加密,所述终端通信密钥的根密钥由所述第一设备和第二设备认证和密钥协商AKA之后生成的根密钥生成,所述第一设备为终端,所述第二设备为网络侧设备;或者,所述第一设备为网络侧设备,所述第二设备为终端; 所述第一设备将加密后的业务信息发送给所述第二设备,以使得所述第二设备采用所述终端通信密钥的根密钥的衍生密钥对接收的业务信息进行解密。
  2. 2
    The method according to the I that a characterised by, wherein the first device is a communication terminal key are key derived a key front service information carried out the encryption farther, comprising:The first device with of the second device end of the algorithm to consult, wherein the root key generation of communication terminal key to the algorithm of by to the derived a key for. 2.根据权利要求I所述的方法,其特征在于,所述第一设备采用终端通信密钥的根密钥的衍生密钥对业务信息进行加密之前,还包括: 所述第一设备与所述第二设备进行算法协商,以确定根据所述终端通信密钥的根密钥生成所述衍生密钥采用的算法。
  3. 3
    Method according to claim I or 2, characterised is composed, wherein the service information of encrypted farther comprising:The first device switches to the root key generation of communication terminal key to the algorithm algorithm identifier of the derived a key for. 3.根据权利要求I或2所述的方法,其特征在于,所述加密后的业务信息中还包括:所述第一设备根据所述终端通信密钥的根密钥生成所述衍生密钥采用的算法的算法标识。
  4. 5
    The method according to the I that a characterised by, according to the root key generation of communication terminal key to the algorithm for derived from the key, a first device and said second to device and a pre-formed. 5.根据权利要求I所述的方法,其特征在于,根据所述终端通信密钥的根密钥生成所述衍生密钥采用的算法,在所述第一设备和所述第二设备上预先配置。
  5. 6
    The method according to any one of claims that comprising a characterised, wherein the service information of encrypted farther comprising:A identifier, wherein rate identifier is used to differentiate different terminal communication terminal key are key, so of the second base device of rate identifier search the corresponding communication terminal key are key. 6.根据权利要求1-5任一项所述的方法,其特征在于,所述加密后的业务信息中还包括:索引标识,所述索引标识用于区分不同终端的终端通信密钥的根密钥,以使所述第二设备根据所述索引标识查找对应的终端通信密钥的根密钥。
  6. 7
    The method according to any one of claims that comprising a characterised, wherein the service information of encrypted farther comprising:First alarming message weighted code MAC, wherein the first RECEIVED by said first and changes to the derived a key back to the service information of the arc-shaped integrity generating, so of the second base device of MAC first end of the complete data to the service information of receiving. 7.根据权利要求1-6任一项所述的方法,其特征在于,所述加密后的业务信息中还包括:第一消息鉴权码MAC,所述第一MAC由所述第一设备根据所述衍生密钥对所述业务信息进行完整性保护后生成,以使所述第二设备根据所述第一 MAC对接收的业务信息进行完整性验证。
  7. 8
    The method according any one of claims 1-7 one of claims that comprising a characterised, wherein the communication terminal key are key derived a key at least comprises:The confidentiality protection and protecting alarm of key and a confidentiality protection and protecting alarm of key, a press button and a confidentiality protection and protecting alarm of key and a user plane confidentiality protection key and a radio resource control signal RRC no hole accessing layer NAS hierarchical service data or multiple probable of. 8.根据权利要求1-7任一项所述的方法,其特征在于,所述终端通信密钥的根密钥的衍生密钥至少包括:业务数据的机密性保护和完整性保护密钥、非接入层NAS层的机密性保护和完整性保护密钥、过程密钥、无线资源控制RRC信令的机密性保护和完整性保护密钥、面向用户面的机密性保护密钥中的一种或多种。
  8. 11
    The method according to 1-10 one of claims that comprising a characterised, the root key generation of the terminal communication same as the key is the first device and second device recent AKA generation. 11.根据权利要求1-10任一项所述的方法,其特征在于,所述终端通信密钥的根密钥由所述第一设备和所述第二设备最近一次AKA之后生成的根密钥生成。
  9. 12
    The method according to 1-11 one of claims that comprising a characterised, wherein the service information of encrypted farther comprising a MAC, wherein the RECEIVED by said first device switches long-term evolution LTE system of key derived a protecting alarm key back to the service information of the arc-shaped integrity generating, so of the second base device of MAC second end of the complete data to the service information of receiving, the root key generation of the LTE system of the key is the first device and second device AKA generation. 12.根据权利要求1-11任一项所述的方法,其特征在于,所述加密后的业务信息中还包括第二MAC,所述第二MAC由所述第一设备根据长期演进LTE系统的根密钥衍生的完整性保护密钥对所述业务信息进行完整性保护后生成,以使所述第二设备根据所述第二 MAC对接收的业务信息进行完整性验证,所述LTE系统的根密钥由所述第一设备和所述第二设备AKA之后生成的根密钥生成。
  10. 13
    The method according to 1-12 one of claims that comprising a characterised, wherein the first device front of the second device used for the service information of encrypted of the online no hole, and when or the first device to of the second device used for the service information of encrypted is in a no hole and on-line, or the first device front of the second device used for the service information of encrypted is in attached to the state;or the first device to of the second device is used to the service information of encrypted not to NAS involve and accessing and AS. 13.根据权利要求1-12任一项所述的方法,其特征在于,所述第一设备向所述第二设备发送所述加密后的业务信息之前处于不在线状态,或者所述第一设备向所述第二设备发送所述加密后的业务信息时处于不在线状态,或者所述第一设备向所述第二设备发送所述加密后的业务信息之前处于去附着状态,或者所述第一设备向所述第二设备发送所述加密后的业务信息不涉及NAS和接入层AS。
  11. 14
    The communication method of terminal, comprising a characterised, comprising:The second device and receiving device sends' service information, wherein the service information by said first device is communication terminal key the derived a key encryption of two key, a tinned key generation of the communication terminal key are key by said first device and second device consulted AKA generated by the authentication and a key, wherein the first device is a terminal;the second device for network side device;Or, wherein the first device for network side device;the second device is a terminal;The second device uses the communication terminal key are key derived a key to the service information to a. 14. 一种终端的通信方法,其特征在于,包括: 第二设备接收第一设备发送的业务信息,所述业务信息由所述第一设备采用终端通信密钥的根密钥的衍生密钥加密,所述终端通信密钥的根密钥由所述第一设备和所述第二设备根据认证和密钥协商AKA之后生成的根密钥生成,所述第一设备为终端,所述第二设备为网络侧设备;或者,所述第一设备为网络侧设备,所述第二设备为终端; 所述第二设备采用所述终端通信密钥的根密钥的衍生密钥对所述业务信息进行解密。
  12. 17
    The method according to 14-16 one of claims that comprising a characterised, wherein a service information farther comprising:A identifier, wherein rate identifier is used to differentiate different terminal communication terminal key are key;The second device uses the communication terminal key are key derived a key front of the service information carried out the decryption farther, comprising: The second base device of rate identifier search the corresponding communication terminal key are key. 17.根据权利要求14-16任一项所述的方法,其特征在于,所述业务信息中还包括:索引标识,所述索引标识用于区分不同终端的终端通信密钥的根密钥;所述第二设备采用所述终端通信密钥的根密钥的衍生密钥对所述业务信息进行解密之前,还包括: 所述第二设备根据所述索引标识查找对应的终端通信密钥的根密钥。
  13. 18
    The method according to 14-17 one of claims that comprising a characterised, the root key generation of the terminal communication same as the key is the first device and second device recent AKA generation. 18.根据权利要求14-17任一项所述的方法,其特征在于,所述终端通信密钥的根密钥由所述第一设备和所述第二设备最近一次AKA之后生成的根密钥生成。
  14. 19
    The method according to 14-18 one of claims that comprising a characterised, wherein a service information farther comprisingFirst alarming message weighted code MAC, wherein the first RECEIVED by said first and changes to the derived a key back to the service information of the arc-shaped integrity generating, wherein the second device uses the communication terminal key are derived key and a back to the service information carried out the decryption farther, comprising:The second device switches to the first MAC, to the service information end of the complete apparatus. 19.根据权利要求14-18任一项所述的方法,其特征在于,所述业务信息中还包括••第一消息鉴权码MAC,所述第一 MAC由所述第一设备根据所述衍生密钥对所述业务信息进行完整性保护后生成,所述第二设备采用所述终端通信密钥的根密钥的衍生密钥对所述业务信息进行解密之后,还包括: 所述第二设备根据所述第一 MAC,对所述业务信息进行完整性验证。
  15. 20
    The method according to 14-19 one of claims that characterised is a front, wherein the second device and first device for the service information, wherein the online no hole, and when or the second device and first device for the service information of the no hole in the front, or the second device and first device for the service information, and is attached to the state, or the second receiving device to the first device for the service information to involve no hole accessing layer NAS and accessing and AS. 20.根据权利要求14-19任一项所述的方法,其特征在于,所述第二设备接收所述第一设备发送的业务信息之前处于不在线状态,或者所述第二设备接收所述第一设备发送的业务信息时处于不在线状态,或者所述第二设备接收所述第一设备发送的业务信息之前处于去附着状态,或者所述第二设备接收所述第一设备发送的业务信息不涉及非接入层NAS和接入层AS。
  16. 21
    The method according to 14-20 one of claims that comprising a characterised; and second device for network layer device; and second device comprises a base station and mobility management entity, wherein the second receiving device and device for service information, specifically comprising:The base station receives to the first device for the service information, wherein a service information a rate identifier, wherein Suo GongI the identifier is used to differentiate different terminal communication terminal key are key;The base station by a light identifier to the mobility management entity;The mobility management entity to the locating identifier, made of the corresponding the communication terminal key of button and an upwards no hole accessing layer NAS counter value;and according to the communication terminal key are key and NAS and a counter, a process the key;The mobility management entity to the press button to the base station. 21.根据权利要求14-20任一项所述的方法,其特征在于,若所述第二设备为网络层设备,则所述第二设备包括基站和移动管理实体,所述第二设备接收第一设备发送的业务信息,具体包括: 所述基站接收所述第一设备发送的业务信息,所述业务信息中包括索引标识,所述索弓I标识用于区分不同终端的终端通信密钥的根密钥; 所述基站将所述索引标识发送给所述移动管理实体; 所述移动管理实体根据所述索引标识,查找对应的终端通信密钥的根密钥和上行非接入层NAS计数器值,并根据所述终端通信密钥的根密钥和所述上行NAS计数器值,生成过程密钥; 所述移动管理实体将所述过程密钥发送给所述基站。
  17. 25
    The device for communication terminal, comprising a characterised, comprising:The processor, by communication terminal key are key derived a key encrypts the service information, the root key generation of the communication terminal key key are connected to the device and second device authentication and key for communication terminal is consulted AKA generating, wherein the device for communication terminal is a terminal;the second device for network side device;Or, wherein device for communication terminal for network side device;the second device is a terminal;The memorizers, wherein the communication terminal key are key for storage;The transmitter, comprising a encrypt the service information sending of the second device, so of the second device uses a communication terminal key are key derived a key service information to the receiving to a. 25. 一种用于终端通信的设备,其特征在于,包括: 处理器,用于采用终端通信密钥的根密钥的衍生密钥对业务信息进行加密,所述终端通信密钥的根密钥由所述用于终端通信的设备和第二设备认证和密钥协商AKA之后生成的根密钥生成,所述用于终端通信的设备为终端,所述第二设备为网络侧设备;或者,所述用于终端通信的设备为网络侧设备,所述第二设备为终端; 存储器,用于存储所述终端通信密钥的根密钥; 发送器,用于将加密后的业务信息发送给所述第二设备,以使得所述第二设备采用所述终端通信密钥的根密钥的衍生密钥对接收的业务信息进行解密。
  18. 30
    According to the device according to 25-29 one of claims a communication terminal, comprising a characterised, wherein the service information of encrypted farther comprising:A identifier, wherein rate identifier is used to differentiate different terminal communication terminal key are key, so of the second base device of rate identifier search the corresponding communication terminal key are key. 30.根据权利要求25-29任一项所述的用于终端通信的设备,其特征在于,所述加密后的业务信息中还包括:索引标识,所述索引标识用于区分不同终端的终端通信密钥的根密钥,以使所述第二设备根据所述索引标识查找对应的终端通信密钥的根密钥。
  19. 31
    According to the device according to 25-30 one of claims a communication terminal, comprising a characterised, wherein the processor is further used for:According to any one of terminal, a confirm is used to encrypt of service information the derived from the key and a to the root key generation of communication terminal key to the algorithm for derived a key for. 31.根据权利要求25-30任一项所述的用于终端通信的设备,其特征在于,所述处理器还用于:根据终端的特性,确定用于加密所述业务信息的衍生密钥类型以及根据所述终端通信密钥的根密钥生成所述衍生密钥采用的算法。
  20. 32
    According to the device according to 25-31 one of claims a communication terminal, comprising a characterised, the root key generation of the memorizer storage the communication terminal key key are connected to the device for communication terminal and a second the device recent AKA generation. 32.根据权利要求25-31任一项所述的用于终端通信的设备,其特征在于,所述存储器存储的终端通信密钥的根密钥由所述用于终端通信的设备和所述第二设备最近一次AKA之后生成的根密钥生成。
  21. 33
    According to the device according to 25-32 one of claims a communication terminal, comprising a characterised, wherein the transmitter front of the second device used for the service information of encrypted, wherein a terminal the communication device is the online no hole;theThe or, wherein a transmitter to of the second device used for the service information of encrypted, wherein a terminal the communication device is the online no hole;theOr, wherein the transmitter front of the second device used for the service information of encrypted, wherein a terminal the communication device is in attached to the;andOr, wherein a transmitter to of the second device is used to the service information of encrypted not to involve no hole accessing layer NAS and accessing and AS. 33.根据权利要求25-32任一项所述的用于终端通信的设备,其特征在于,所述发送器向所述第二设备发送所述加密后的业务信息之前,所述用于终端通信的设备处于不在线状态;或者,所述发送器向所述第二设备发送所述加密后的业务信息时,所述用于终端通信的设备处于不在线状态;或者,所述发送器向所述第二设备发送所述加密后的业务信息之前,所述用于终端通信的设备处于去附着状态;或者,所述发送器向所述第二设备发送所述加密后的业务信息不涉及非接入层NAS和接入层AS。
  22. 34
    The device for communication terminal, comprising a characterised, comprising:A receiver, for receiving the first device sends' service information, wherein the service information by said first device is communication terminal key the derived a key encryption of two key, a tinned key generation of the communication terminal key key are formed by the device for communication terminal and first device consulted AKA generated by the authentication and a key, wherein the first device is a terminal, and apparatus for communication terminal for network side device;Or, wherein the first device for network side device, and apparatus for communication terminal of the terminal;The memorizers, wherein the communication terminal key are key for storage;The processor, a man-machine to the communication terminal key are key derived a key to the service information to a. 34. 一种用于终端通信的设备,其特征在于,包括: 接收器,用于接收第一设备发送的业务信息,所述业务信息由所述第一设备采用终端通信密钥的根密钥的衍生密钥加密,所述终端通信密钥的根密钥由所述用于终端通信的设备和所述第一设备根据认证和密钥协商AKA之后生成的根密钥生成,所述第一设备为终端,所述用于终端通信的设备为网络侧设备;或者,所述第一设备为网络侧设备,所述用于终端通信的设备为终端; 存储器,用于存储所述终端通信密钥的根密钥; 处理器,用于采用所述终端通信密钥的根密钥的衍生密钥对所述业务信息进行解密。
  23. 37
    According to the device according to 34-36 one of claims a communication terminal, comprising a characterised, wherein a service information farther comprising:A identifier, wherein rate identifier is used to differentiate different terminal communication terminal key are key;And the processor is further used for: To the locating identifier search the corresponding communication terminal key are key. 37.根据权利要求34-36任一项所述的用于终端通信的设备,其特征在于,所述业务信息中还包括:索引标识,所述索引标识用于区分不同终端的终端通信密钥的根密钥;则所述处理器还用于:根据所述索引标识查找对应的终端通信密钥的根密钥。
  24. 38
    According to the device according to 34-37 one of claims a communication terminal, comprising a characterised, wherein the memorizer storage the root key generation of the communication terminal key key are connected to the first device and terminal for communication device recent AKA generation. 38.根据权利要求34-37任一项所述的用于终端通信的设备,其特征在于,所述存储器存储的所述终端通信密钥的根密钥由所述第一设备和所述用于终端通信的设备最近一次AKA之后生成的根密钥生成。
  25. 39
    According to the device according to 34-38 one of claims a communication terminal, comprising characterised, a front of the receiver receives the first device for the service information, wherein a terminal the communication device is the online no hole;theThe or, wherein the receiver receives the first device for the service information, wherein a terminal the communication device is the online no hole;theOr, front of the receiver receives the first device for the service information, wherein a terminal the communication device is in attached to the;andOr, wherein the receiver receives to the first device for the service information to involve no hole accessing layer NAS and accessing and AS. 39.根据权利要求34-38任一项所述的用于终端通信的设备,其特征在于,所述接收器接收所述第一设备发送的业务信息之前,所述用于终端通信的设备处于不在线状态;或者,所述接收器接收所述第一设备发送的业务信息时,所述用于终端通信的设备处于不在线状态;或者,所述接收器接收所述第一设备发送的业务信息之前,所述用于终端通信的设备处于去附着状态;或者,所述接收器接收所述第一设备发送的业务信息不涉及非接入层NAS和接入层AS。
Independent claims25