Terminal communication method and device
Abstract
The embodiment of the invention provides a terminal communication method and a terminal communication device. The method comprises the steps that: a first device carries out encryption on service information by using a derivative key of a root key of a terminal communication key, wherein the root key of the terminal communication key is generated by a root key generated through authentication and key agreement AKA by the first device and a second device, the first device is a terminal, and the second device is a network side device, or the first device is a network side device, and the second device is a terminal; and the first device sends the service information subjected to encryption to the second device, so that the second device carries out decryption on the received service information by using the derivative key of the root key of the terminal communication key. According to the embodiment of the invention, the confidentiality or integrity protection on service information transmitted between the terminal and the network side device is realized.
Term
No projected expiry on record.
- Priority and filed
- Published
- Today
39 claims: 25 independent, 14 dependent
- 1The communication method of terminal, comprising a characterised, comprising:The first device for communication terminal key are key derived from bottom to encrypt the service information, the root key generation of the terminal communication same as the key is the first device and second device authentication and key consulted AKA generating, wherein the first device is a terminal;the second device for network side device;Or, wherein the first device for network side device;the second device is a terminal;After the first device to encrypt the service information sending of the second device, so of the second device uses a communication terminal key are key derived a key service information to the receiving to a. 1. 一种终端的通信方法,其特征在于,包括: 第一设备采用终端通信密钥的根密钥的衍生密钥对业务信息进行加密,所述终端通信密钥的根密钥由所述第一设备和第二设备认证和密钥协商AKA之后生成的根密钥生成,所述第一设备为终端,所述第二设备为网络侧设备;或者,所述第一设备为网络侧设备,所述第二设备为终端; 所述第一设备将加密后的业务信息发送给所述第二设备,以使得所述第二设备采用所述终端通信密钥的根密钥的衍生密钥对接收的业务信息进行解密。
- 2The method according to the I that a characterised by, wherein the first device is a communication terminal key are key derived a key front service information carried out the encryption farther, comprising:The first device with of the second device end of the algorithm to consult, wherein the root key generation of communication terminal key to the algorithm of by to the derived a key for. 2.根据权利要求I所述的方法,其特征在于,所述第一设备采用终端通信密钥的根密钥的衍生密钥对业务信息进行加密之前,还包括: 所述第一设备与所述第二设备进行算法协商,以确定根据所述终端通信密钥的根密钥生成所述衍生密钥采用的算法。
- 3Method according to claim I or 2, characterised is composed, wherein the service information of encrypted farther comprising:The first device switches to the root key generation of communication terminal key to the algorithm algorithm identifier of the derived a key for. 3.根据权利要求I或2所述的方法,其特征在于,所述加密后的业务信息中还包括:所述第一设备根据所述终端通信密钥的根密钥生成所述衍生密钥采用的算法的算法标识。
- 5The method according to the I that a characterised by, according to the root key generation of communication terminal key to the algorithm for derived from the key, a first device and said second to device and a pre-formed. 5.根据权利要求I所述的方法,其特征在于,根据所述终端通信密钥的根密钥生成所述衍生密钥采用的算法,在所述第一设备和所述第二设备上预先配置。
- 6The method according to any one of claims that comprising a characterised, wherein the service information of encrypted farther comprising:A identifier, wherein rate identifier is used to differentiate different terminal communication terminal key are key, so of the second base device of rate identifier search the corresponding communication terminal key are key. 6.根据权利要求1-5任一项所述的方法,其特征在于,所述加密后的业务信息中还包括:索引标识,所述索引标识用于区分不同终端的终端通信密钥的根密钥,以使所述第二设备根据所述索引标识查找对应的终端通信密钥的根密钥。
- 7The method according to any one of claims that comprising a characterised, wherein the service information of encrypted farther comprising:First alarming message weighted code MAC, wherein the first RECEIVED by said first and changes to the derived a key back to the service information of the arc-shaped integrity generating, so of the second base device of MAC first end of the complete data to the service information of receiving. 7.根据权利要求1-6任一项所述的方法,其特征在于,所述加密后的业务信息中还包括:第一消息鉴权码MAC,所述第一MAC由所述第一设备根据所述衍生密钥对所述业务信息进行完整性保护后生成,以使所述第二设备根据所述第一 MAC对接收的业务信息进行完整性验证。
- 8The method according any one of claims 1-7 one of claims that comprising a characterised, wherein the communication terminal key are key derived a key at least comprises:The confidentiality protection and protecting alarm of key and a confidentiality protection and protecting alarm of key, a press button and a confidentiality protection and protecting alarm of key and a user plane confidentiality protection key and a radio resource control signal RRC no hole accessing layer NAS hierarchical service data or multiple probable of. 8.根据权利要求1-7任一项所述的方法,其特征在于,所述终端通信密钥的根密钥的衍生密钥至少包括:业务数据的机密性保护和完整性保护密钥、非接入层NAS层的机密性保护和完整性保护密钥、过程密钥、无线资源控制RRC信令的机密性保护和完整性保护密钥、面向用户面的机密性保护密钥中的一种或多种。
- 11The method according to 1-10 one of claims that comprising a characterised, the root key generation of the terminal communication same as the key is the first device and second device recent AKA generation. 11.根据权利要求1-10任一项所述的方法,其特征在于,所述终端通信密钥的根密钥由所述第一设备和所述第二设备最近一次AKA之后生成的根密钥生成。
- 12The method according to 1-11 one of claims that comprising a characterised, wherein the service information of encrypted farther comprising a MAC, wherein the RECEIVED by said first device switches long-term evolution LTE system of key derived a protecting alarm key back to the service information of the arc-shaped integrity generating, so of the second base device of MAC second end of the complete data to the service information of receiving, the root key generation of the LTE system of the key is the first device and second device AKA generation. 12.根据权利要求1-11任一项所述的方法,其特征在于,所述加密后的业务信息中还包括第二MAC,所述第二MAC由所述第一设备根据长期演进LTE系统的根密钥衍生的完整性保护密钥对所述业务信息进行完整性保护后生成,以使所述第二设备根据所述第二 MAC对接收的业务信息进行完整性验证,所述LTE系统的根密钥由所述第一设备和所述第二设备AKA之后生成的根密钥生成。
- 13The method according to 1-12 one of claims that comprising a characterised, wherein the first device front of the second device used for the service information of encrypted of the online no hole, and when or the first device to of the second device used for the service information of encrypted is in a no hole and on-line, or the first device front of the second device used for the service information of encrypted is in attached to the state;or the first device to of the second device is used to the service information of encrypted not to NAS involve and accessing and AS. 13.根据权利要求1-12任一项所述的方法,其特征在于,所述第一设备向所述第二设备发送所述加密后的业务信息之前处于不在线状态,或者所述第一设备向所述第二设备发送所述加密后的业务信息时处于不在线状态,或者所述第一设备向所述第二设备发送所述加密后的业务信息之前处于去附着状态,或者所述第一设备向所述第二设备发送所述加密后的业务信息不涉及NAS和接入层AS。
- 14The communication method of terminal, comprising a characterised, comprising:The second device and receiving device sends' service information, wherein the service information by said first device is communication terminal key the derived a key encryption of two key, a tinned key generation of the communication terminal key are key by said first device and second device consulted AKA generated by the authentication and a key, wherein the first device is a terminal;the second device for network side device;Or, wherein the first device for network side device;the second device is a terminal;The second device uses the communication terminal key are key derived a key to the service information to a. 14. 一种终端的通信方法,其特征在于,包括: 第二设备接收第一设备发送的业务信息,所述业务信息由所述第一设备采用终端通信密钥的根密钥的衍生密钥加密,所述终端通信密钥的根密钥由所述第一设备和所述第二设备根据认证和密钥协商AKA之后生成的根密钥生成,所述第一设备为终端,所述第二设备为网络侧设备;或者,所述第一设备为网络侧设备,所述第二设备为终端; 所述第二设备采用所述终端通信密钥的根密钥的衍生密钥对所述业务信息进行解密。
- 17The method according to 14-16 one of claims that comprising a characterised, wherein a service information farther comprising:A identifier, wherein rate identifier is used to differentiate different terminal communication terminal key are key;The second device uses the communication terminal key are key derived a key front of the service information carried out the decryption farther, comprising: The second base device of rate identifier search the corresponding communication terminal key are key. 17.根据权利要求14-16任一项所述的方法,其特征在于,所述业务信息中还包括:索引标识,所述索引标识用于区分不同终端的终端通信密钥的根密钥;所述第二设备采用所述终端通信密钥的根密钥的衍生密钥对所述业务信息进行解密之前,还包括: 所述第二设备根据所述索引标识查找对应的终端通信密钥的根密钥。
- 18The method according to 14-17 one of claims that comprising a characterised, the root key generation of the terminal communication same as the key is the first device and second device recent AKA generation. 18.根据权利要求14-17任一项所述的方法,其特征在于,所述终端通信密钥的根密钥由所述第一设备和所述第二设备最近一次AKA之后生成的根密钥生成。
- 19The method according to 14-18 one of claims that comprising a characterised, wherein a service information farther comprisingFirst alarming message weighted code MAC, wherein the first RECEIVED by said first and changes to the derived a key back to the service information of the arc-shaped integrity generating, wherein the second device uses the communication terminal key are derived key and a back to the service information carried out the decryption farther, comprising:The second device switches to the first MAC, to the service information end of the complete apparatus. 19.根据权利要求14-18任一项所述的方法,其特征在于,所述业务信息中还包括••第一消息鉴权码MAC,所述第一 MAC由所述第一设备根据所述衍生密钥对所述业务信息进行完整性保护后生成,所述第二设备采用所述终端通信密钥的根密钥的衍生密钥对所述业务信息进行解密之后,还包括: 所述第二设备根据所述第一 MAC,对所述业务信息进行完整性验证。
- 20The method according to 14-19 one of claims that characterised is a front, wherein the second device and first device for the service information, wherein the online no hole, and when or the second device and first device for the service information of the no hole in the front, or the second device and first device for the service information, and is attached to the state, or the second receiving device to the first device for the service information to involve no hole accessing layer NAS and accessing and AS. 20.根据权利要求14-19任一项所述的方法,其特征在于,所述第二设备接收所述第一设备发送的业务信息之前处于不在线状态,或者所述第二设备接收所述第一设备发送的业务信息时处于不在线状态,或者所述第二设备接收所述第一设备发送的业务信息之前处于去附着状态,或者所述第二设备接收所述第一设备发送的业务信息不涉及非接入层NAS和接入层AS。
- 21The method according to 14-20 one of claims that comprising a characterised; and second device for network layer device; and second device comprises a base station and mobility management entity, wherein the second receiving device and device for service information, specifically comprising:The base station receives to the first device for the service information, wherein a service information a rate identifier, wherein Suo GongI the identifier is used to differentiate different terminal communication terminal key are key;The base station by a light identifier to the mobility management entity;The mobility management entity to the locating identifier, made of the corresponding the communication terminal key of button and an upwards no hole accessing layer NAS counter value;and according to the communication terminal key are key and NAS and a counter, a process the key;The mobility management entity to the press button to the base station. 21.根据权利要求14-20任一项所述的方法,其特征在于,若所述第二设备为网络层设备,则所述第二设备包括基站和移动管理实体,所述第二设备接收第一设备发送的业务信息,具体包括: 所述基站接收所述第一设备发送的业务信息,所述业务信息中包括索引标识,所述索弓I标识用于区分不同终端的终端通信密钥的根密钥; 所述基站将所述索引标识发送给所述移动管理实体; 所述移动管理实体根据所述索引标识,查找对应的终端通信密钥的根密钥和上行非接入层NAS计数器值,并根据所述终端通信密钥的根密钥和所述上行NAS计数器值,生成过程密钥; 所述移动管理实体将所述过程密钥发送给所述基站。
- 25The device for communication terminal, comprising a characterised, comprising:The processor, by communication terminal key are key derived a key encrypts the service information, the root key generation of the communication terminal key key are connected to the device and second device authentication and key for communication terminal is consulted AKA generating, wherein the device for communication terminal is a terminal;the second device for network side device;Or, wherein device for communication terminal for network side device;the second device is a terminal;The memorizers, wherein the communication terminal key are key for storage;The transmitter, comprising a encrypt the service information sending of the second device, so of the second device uses a communication terminal key are key derived a key service information to the receiving to a. 25. 一种用于终端通信的设备,其特征在于,包括: 处理器,用于采用终端通信密钥的根密钥的衍生密钥对业务信息进行加密,所述终端通信密钥的根密钥由所述用于终端通信的设备和第二设备认证和密钥协商AKA之后生成的根密钥生成,所述用于终端通信的设备为终端,所述第二设备为网络侧设备;或者,所述用于终端通信的设备为网络侧设备,所述第二设备为终端; 存储器,用于存储所述终端通信密钥的根密钥; 发送器,用于将加密后的业务信息发送给所述第二设备,以使得所述第二设备采用所述终端通信密钥的根密钥的衍生密钥对接收的业务信息进行解密。
- 30According to the device according to 25-29 one of claims a communication terminal, comprising a characterised, wherein the service information of encrypted farther comprising:A identifier, wherein rate identifier is used to differentiate different terminal communication terminal key are key, so of the second base device of rate identifier search the corresponding communication terminal key are key. 30.根据权利要求25-29任一项所述的用于终端通信的设备,其特征在于,所述加密后的业务信息中还包括:索引标识,所述索引标识用于区分不同终端的终端通信密钥的根密钥,以使所述第二设备根据所述索引标识查找对应的终端通信密钥的根密钥。
- 31According to the device according to 25-30 one of claims a communication terminal, comprising a characterised, wherein the processor is further used for:According to any one of terminal, a confirm is used to encrypt of service information the derived from the key and a to the root key generation of communication terminal key to the algorithm for derived a key for. 31.根据权利要求25-30任一项所述的用于终端通信的设备,其特征在于,所述处理器还用于:根据终端的特性,确定用于加密所述业务信息的衍生密钥类型以及根据所述终端通信密钥的根密钥生成所述衍生密钥采用的算法。
- 32According to the device according to 25-31 one of claims a communication terminal, comprising a characterised, the root key generation of the memorizer storage the communication terminal key key are connected to the device for communication terminal and a second the device recent AKA generation. 32.根据权利要求25-31任一项所述的用于终端通信的设备,其特征在于,所述存储器存储的终端通信密钥的根密钥由所述用于终端通信的设备和所述第二设备最近一次AKA之后生成的根密钥生成。
- 33According to the device according to 25-32 one of claims a communication terminal, comprising a characterised, wherein the transmitter front of the second device used for the service information of encrypted, wherein a terminal the communication device is the online no hole;theThe or, wherein a transmitter to of the second device used for the service information of encrypted, wherein a terminal the communication device is the online no hole;theOr, wherein the transmitter front of the second device used for the service information of encrypted, wherein a terminal the communication device is in attached to the;andOr, wherein a transmitter to of the second device is used to the service information of encrypted not to involve no hole accessing layer NAS and accessing and AS. 33.根据权利要求25-32任一项所述的用于终端通信的设备,其特征在于,所述发送器向所述第二设备发送所述加密后的业务信息之前,所述用于终端通信的设备处于不在线状态;或者,所述发送器向所述第二设备发送所述加密后的业务信息时,所述用于终端通信的设备处于不在线状态;或者,所述发送器向所述第二设备发送所述加密后的业务信息之前,所述用于终端通信的设备处于去附着状态;或者,所述发送器向所述第二设备发送所述加密后的业务信息不涉及非接入层NAS和接入层AS。
- 34The device for communication terminal, comprising a characterised, comprising:A receiver, for receiving the first device sends' service information, wherein the service information by said first device is communication terminal key the derived a key encryption of two key, a tinned key generation of the communication terminal key key are formed by the device for communication terminal and first device consulted AKA generated by the authentication and a key, wherein the first device is a terminal, and apparatus for communication terminal for network side device;Or, wherein the first device for network side device, and apparatus for communication terminal of the terminal;The memorizers, wherein the communication terminal key are key for storage;The processor, a man-machine to the communication terminal key are key derived a key to the service information to a. 34. 一种用于终端通信的设备,其特征在于,包括: 接收器,用于接收第一设备发送的业务信息,所述业务信息由所述第一设备采用终端通信密钥的根密钥的衍生密钥加密,所述终端通信密钥的根密钥由所述用于终端通信的设备和所述第一设备根据认证和密钥协商AKA之后生成的根密钥生成,所述第一设备为终端,所述用于终端通信的设备为网络侧设备;或者,所述第一设备为网络侧设备,所述用于终端通信的设备为终端; 存储器,用于存储所述终端通信密钥的根密钥; 处理器,用于采用所述终端通信密钥的根密钥的衍生密钥对所述业务信息进行解密。
- 37According to the device according to 34-36 one of claims a communication terminal, comprising a characterised, wherein a service information farther comprising:A identifier, wherein rate identifier is used to differentiate different terminal communication terminal key are key;And the processor is further used for: To the locating identifier search the corresponding communication terminal key are key. 37.根据权利要求34-36任一项所述的用于终端通信的设备,其特征在于,所述业务信息中还包括:索引标识,所述索引标识用于区分不同终端的终端通信密钥的根密钥;则所述处理器还用于:根据所述索引标识查找对应的终端通信密钥的根密钥。
- 38According to the device according to 34-37 one of claims a communication terminal, comprising a characterised, wherein the memorizer storage the root key generation of the communication terminal key key are connected to the first device and terminal for communication device recent AKA generation. 38.根据权利要求34-37任一项所述的用于终端通信的设备,其特征在于,所述存储器存储的所述终端通信密钥的根密钥由所述第一设备和所述用于终端通信的设备最近一次AKA之后生成的根密钥生成。
- 39According to the device according to 34-38 one of claims a communication terminal, comprising characterised, a front of the receiver receives the first device for the service information, wherein a terminal the communication device is the online no hole;theThe or, wherein the receiver receives the first device for the service information, wherein a terminal the communication device is the online no hole;theOr, front of the receiver receives the first device for the service information, wherein a terminal the communication device is in attached to the;andOr, wherein the receiver receives to the first device for the service information to involve no hole accessing layer NAS and accessing and AS. 39.根据权利要求34-38任一项所述的用于终端通信的设备,其特征在于,所述接收器接收所述第一设备发送的业务信息之前,所述用于终端通信的设备处于不在线状态;或者,所述接收器接收所述第一设备发送的业务信息时,所述用于终端通信的设备处于不在线状态;或者,所述接收器接收所述第一设备发送的业务信息之前,所述用于终端通信的设备处于去附着状态;或者,所述接收器接收所述第一设备发送的业务信息不涉及非接入层NAS和接入层AS。
Independent claims25
204 paragraphs in 1 section, as filed
The communication method and device of terminal
technical field
[0001] The invention relates to a communication network field, referring to the communication method, device thereof and system for the special terminal.
Background method
[0002] machine to machine (Machine to Machine; REPORTING method) is a comprises a wireless communication information and technique, no need the manual intervention; and machine and motor capable by a on communication. The REPORTING method of application widespread, comprising: Automatic instrument, remote monitoring, industrial safety and household automation, pay system and vehicle remote controller and fields.
[0003] REPORTING mainly comprises three: mannerMachine to machine and machine of mobile phone and mobile phone to machine. The M2M, the M2M device of through the remote connection method and short distance is connected with method for accessing network, the remote connection method to comprises: Global mobile communication system (Global System for Mobile communication,GSM), general packet radio service (General Packet Radio Service; GPRS), a universal mobile communication system (Universal Mobile Telecommunications System,UMTS), a frame (evolution System Structure, EvolutionSAE), global microwave access device (Worldwide Interoperability for Microwave, AccessWiMAX) equal wireless access device (Radio Access Type; RAT) and techniques; Short distance is connected with the method comprises: 802. Llb/g and Bluetooth (BlueTooth) and radiofrequency identification process (Wireless Frequency Identifying; RFID) and ultra-wide band (Ultra Wideband; UWB) and techniques. The M2M communication is further called machine communication current Motor (TypeCommunication; MTC), a usually called REPORTING device of MTC device.
[0004] When the prior art, the front MTC device or) and terminal and network side device, communication or a network communication side of the no hole and on-line, or and communication is at attached to the (detach) connected to the network side device, or the use field without involve the no hole accessing layer (Non-Access; StratumNAS) and accessing layer (Access Stratum; AS) in a condition, MTC device or) and terminal and/or the network side device is not connected to an safety context, which is not connected equal to transmission's information end of the confidentiality or the complete protection.
invention content
[0005] The embodiment of the invention claims a communication method and apparatus for terminal; the solving prior art MTC device or) and terminal or the network side device is not connected to an safety context, which is not connected equal to transmission's information end of the confidentiality or the problems of gravity protection.
[0006] At the same time, the embodiment of the invention claims a communication method of terminal, comprising:
[0007] The first device for communication terminal key are key derived from bottom to encrypt the service information, the root key generation of the terminal communication same as the key is the first device and second device authentication and key consulted AKA generating, wherein the first device is a terminal; the second device for network side device; Or, wherein the first device for network side device; the second device is a terminal;
[0008] After the first device to encrypt the service information sending of the second device, so of the second device uses a communication terminal key are key derived a key service information to the receiving to a.
[0009] The embodiment of the invention also claims a communication method of terminal, comprising:
[0010] The second device and receiving device sends' service information, wherein the service information by said first device is communication terminal key the derived a key encryption of two key, a tinned key generation of the communication terminal key are key by said first device and second device consulted AKA generated by the authentication and a key, wherein the first device is a terminal; the second device for network side device; Or, wherein the first device for network side device; the second device is a terminal;
[0011] The second device uses the communication terminal key are key derived a key to the service information to a.
[0012] On the other side, the embodiment of the invention claims an apparatus for communication terminal, comprising:
[0013] The processor, by communication terminal key are key derived a key encrypts the service information, the root key generation of the communication terminal key are key are consulted AKA generated by the terminal device and second device authentication and key, wherein the terminal device is a terminal; the second device for network side device; Or, wherein the terminal device for network side device; the second device is a terminal;
[0014] The memorizers, wherein the communication terminal key are key for storage;
[0015] The transmitter, comprising a encrypt the service information sending of the second device, so of the second device uses a communication terminal key are key derived a key service information to the receiving to a.
[0016] The embodiment of the invention also claims an apparatus for communication terminal, comprising:
[0017] A receiver, for receiving the first device sends' service information, wherein the service information by said first device is communication terminal key the derived a key encryption of two key, a tinned key generation of the communication terminal key are key by said the terminal device and first device consulted AKA generated by the authentication and a key, wherein the first device is a terminal, wherein the terminal device for network side device; Or, wherein the first device for network side device, wherein the terminal device is a terminal;
[0018] The memorizers, wherein the communication terminal key are key for storage;
[0019] The processor, a man-machine to the communication terminal key are key derived a key to the service information end of the solution
LU O
[0020] The communication method and device of terminal the embodiment of the invention claims, wherein the front terminal and network side device realizes the communication, when or a network side device of communication with the no hole in the front, or a terminal and network side device realizes the communication, and is attached to the state, or the use field without involve NAS and ACK/NAK and AS, a terminal and network side device transmission's service information for communication terminal key are key derived from bottom to encrypt, the root key generation according to the terminal and network side device authentication and key the communication terminal key are key consulted AKA generating, wherein and realizes the network side device transmission's the service information between the terminalAnd the connection or the complete protection.
brief description fo the drawings
[0021] To explain of clearly technical solution the embodiment of the invention or the prior art, to executing of the or the prior art description lower using the auxiliary the digital is a introduce simply of obviously, a describes the auxiliary shape of some embodiments of invention, wherein a field and a provide, and without pay the lower creative horizontal terminal, comprising a shaft according to the auxiliary certain to obtain the auxiliary certain.
[0022] The position I am terminal the current image communication method embodiment of this invention claims;
[0023] Digital 2) is a current image communication method the embodiment of this invention claims;
[0024] Digital 3) is communication terminal key the derived a key schematic drawing device of two key the embodiment of the invention claims;
[0025] Digital 4) is a current image communication method the embodiment of this invention claims;
[0026] Digital 5) is a current image communication method the embodiment of this invention claims;
[0027] The pattern is 6 terminal the current image communication method the embodiment of this invention claims;
[0028] Digital 7) is a current image communication method the embodiment of this invention claims;
[0029] Digital 8) is a current image communication method the embodiment of this invention claims;
[0030] Digital 9 is the invention claims apparatus embodiment a structure schematic drawing for communication terminal,
[0031] Digital 10 is the invention claims apparatus one embodiment structure schematic drawing for communication terminal,
[0032] Digital 11 is the invention provides communication system embodiment a structure schematic drawing for terminal.
Performing is specifically
[0033] In order to make the embodiment of the invention, as technical solution and advantage of clearer, and auxiliary the shape of the embodiment of the invention, wherein the position to the technical solution the embodiment of the invention describes clearly and completely; the embodiment of obviously, describes invention is a part of embodiments, which is reserved on the embodiment. The invention claims a based on embodiment, the field and a provide with a made of other embodiments of the lower creative horizontal obtaining terminal, belonging to the invention protection domain.
[0034] The position I am terminal the current image communication method for example's the invention provides, to the position fixing I, wherein the method comprises:
[0035] S101 and first device for communication terminal key are key derived from bottom to encrypt the service information, the root key generation of the communication terminal key are key are consulted AKA generated by the first device and second device authentication and key, a first device is a terminal, a second device for network side device; Or, first device is a network side device, the second device is a terminal.
[0036] The S102 and first and encrypt the service information output to the second device, so the second device is communication terminal key are key derived a key service information to the receiving to a.
[0037] , First device can be a terminal, a second device capable of the network side device; Or, first device capable of the network side device, the second device can be a terminal. The terminal can be a MTC device or the intelligent equal, network side device can be to the mobility management entity (Mobility Management Entity; MME), evolution base station (eNodeB; eNB) and an apparatus.
[0038] The embodiment of the invention, the first end and second device used for the service information of encrypted capable of the online no hole; theThe or, first and second device used for the service information of encrypted capable of the online no hole; theOr, the first end and second device used for the service information of encrypted can be is attached to the; andFurther can be, the first device and service information of encrypted not to involve no hole accessing layer NAS and accessing layer is the second device for sending and AS. , Namely embodiment of the invention specifically practical in that: The terminal and a network communication side (can be terminal and service information of encrypted to the network side device used, front or a terminal and network side device for service information), a terminal is in a no hole and on-line or attached to plating technique of the; Further can be, when terminal and network side device, communication the terminal is in a online no hole; theFurther can be, a terminal and network side device and transmission's service information part to the NAS layer and AS layer.
[0039] Of MTC device or) and terminal (online online); and operation current with the network side device in process, comprising authenticating and key negotiation each time (and Authentication key; protocolThe AKA), terminal and network side device are production of key; the key with different business in different system, for example: in long-term evolution (Long Term Evolution; LTE) is system, a terminal and network side device for generating Kasme of the key; AKAThe global mobile communication system (Global System for Mobile communication,GSM), a terminal and network side device for generating Kc of the key; AKAA on wideband code multiple point site (Wideband Code Division MultipleAccess; WCDMA) is system, a terminal and network side device of confidentiality (CK) or alarm button (IK) AKA generating equal. The other communication system, a terminal and network side device without enumerate from the root key according AKA generating 11.
[0040] Embodiment of this invention claims, terminal and network side device is respectively connected AKA the root key generation communication terminal key of button is generated, a communication terminal key are key of storage arranged in the non-volatility (nonvolatile) and storage medium, and ensure communication terminal key the safety of two key. The terminal and network side device of AKA, and each time and root AKA key generation communication terminal key of button is generated, therefore, storage or network side device of the key on communication terminal key in the terminal, capable of the terminal and network side device recent AKA are key generation of generating.
[0041] , Terminal and network side device of the keys is each communication system in key according, wherein AKA generating then, a communication terminal key are key derived from keys are used, comprising a terminal and/or the network side device without with safety context communication field (safety context is in LTE system terminal and network side device AKA, Kasme of button is generated, NAS key layer, and generating parameter of the NAS layer key for equal), a: ofFront when terminal and network side device, communication or a network side device communication is in of the online (offline); andOr a terminal is embedded on attached to the (detach) connected to the network side communication, attached to conductive rod (joint) in way of communication to the network side of; Or of the operation flow without involve NAS and AS in layer and situations. The Kasme are key in the situations, a terminal and/or the network side device of delete AKA flow, generating, the NAS key layer, and generating parameter and the safety context the NAS layer the key adopts, wherein the metal terminal and network side device transmission's service information is not connected to a on the confidentiality or the complete protection.
[0042] Embodiment of this invention claims, wherein the terminal and/or the network side device without with safety context, a terminal and network side device for sending information service, and is a communication terminal key are key derived a key service information to the transmission encrypts. , A terminal and network side device transmission's service information can be a terminal to all data of network side device for reporting (e.g. a data (small data), a: ofThe water meter reading, the electirc meter reading equal), or a terminal and network side device and each of service signalings of transmission, a: ofNAS signal radio resource control protocol (Radio; ResourceControlRRC) signal equal. Encrypting in the embodiment of this invention relates a generalized concept, wherein the encryption capable of the confidentiality protection, can be a complete protection. The confidentiality protection concave part to the data service information, a protecting alarm a protection full service information.
[0043] , A conducting according to communication terminal key the algorithm of two key generation derived a key is pre-formed on the first device and second device; Further consults of the confirm of the first device and second device. The first device and second device capable consult the confirm to act according to communication terminal key the algorithm of two key generation derived a key of service information transmission; Further can be, the first device and output service information, an to act according to the communication terminal key are key generation derived a key algorithm algorithm identifier in the service information of encrypted, wherein wherein the second device to learn for automatically according to communication terminal key the algorithm of two key generation derived a key.
[0044] The first apparatus may allocate resources for according to the communication terminal key are key; and algorithm of a pre-formed configuring, or a algorithm production derived a key of the second consultation device, and using the derived from bottom to needing the top and confidentiality or a protecting alarm to the second the service information.
[0045] The second device for service information, and according to the communication terminal key are key; and algorithm of a pre-formed configuring, or the first consultation device confirm's algorithm production derived a key, and used derived a key for encrypting service information to receiving to a.
[0046] The embodiment provision the communication method of terminal, when the front terminal and network side device realizes the communication, when or a network side device of communication with the no hole in the front, or a terminal and network side device realizes the communication, and is attached to the state, or the use field without involve NAS and ACK/NAK and AS, a terminal and network side device transmission's service information for communication terminal key are key derived from bottom to encrypt, the root key generation according to the terminal and network side device authentication and key the communication terminal key are key consulted AKA generating, wherein and realizes the network side device transmission's the service information between the terminalAnd the connection or the complete protection.
[0047] Digital 2) is a current image communication method the embodiment of this invention claims, and shown the digital 2, wherein the method comprises:
[0048] The root key generation of S201 and second device and receiving device sends' service information, the service information is used for communication terminal key the derived a key encryption of two key of the first device, a communication terminal key are key consulted AKA generated by the authentication and key of the first device and second device, the first device is a terminal, a second device for network side device; Or, first device is a network side device, the second device is a terminal.
[0049] S202 and second device is a communication terminal key are key derived a key, deciphers the service information.
[0050] , First device can be a terminal, a second device capable of the network side device; Or, first device capable of the network side device, the second device can be a terminal.
(0051) In embodiment of the invention, the front and device for first device for service information, capable of the online no hole; theThe or, and receiving device and device for service information can be the online no hole; theOr, front end and receiving device and device for service information, can be is attached to the; andFurther can be, the second device and receiving device sends' service information there is no hole involve accessing layer NAS and accessing and AS. , Namely embodiment of the invention specifically practical in that: The terminal and a network communication side (can be terminal and service information of encrypted to the network side device used, front or a terminal and network side device for service information), a terminal is in a no hole and on-line or attached to plating technique of the; Further can be, when terminal and network side device, communication the terminal is in a online no hole; theFurther can be, a terminal and network side device and transmission's service Ih bracket portion to the NAS layer and AS layer.
[0052] Of MTC device or) and terminal (online online); and operation current with the network side device in process, wherein each time AKA, terminal and network side device are production of key, a: ofThe (CK) confidentiality or achieve the key (IK) are Kc key and WCDMA system of Kasme are key and a GSM system in LTE system equal.
[0053] Embodiment of this invention claims, terminal and network device is respectively connected AKA the root key generation communication terminal key of button is generated, the communication terminal key are key of storage arranged in the non-volatility and storage medium, and ensure communication terminal key the safety of two key. The terminal and network side device of AKA, and each time and AKA the root key generation communication terminal key of button is generated, S, 卩 storage or network side device of the key on communication terminal key in the terminal, capable of the terminal and network side device recent AKA are key generation of generating.
[0054] Embodiment of this invention claims, wherein the terminal and/or the network side device without with safety context, a terminal and network side device for sending information service, and is a communication terminal key are key derived a key service information to the transmission encrypts. The encryption capable of the confidentiality protection, can be a complete protection. The confidentiality protection concave part to the data service information, a protecting alarm a protection full service information.
[0055] , A conducting according to communication terminal key the algorithm of two key generation derived a key is pre-formed on the first device and second device; Further consults of the confirm of the first device and second device. The first device and second device capable consult the confirm to act according to communication terminal key the algorithm of two key generation derived a key of service information transmission; Further can be, the first device and output service information, an to act according to the communication terminal key are key generation derived a key algorithm algorithm identifier in the service information of encrypted, wherein wherein the second device to learn for automatically according to communication terminal key the algorithm of two key generation derived a key.
[0056] The first apparatus may allocate resources for according to the communication terminal key are key; and algorithm of a pre-formed configuring, or a algorithm production derived a key of the second consultation device, and using the derived from bottom to needing the top and confidentiality or a protecting alarm to the second the service information.
[0057] The second device for service information, according to the communication terminal key are key, may use algorithm of a pre-formed configuring, or the first consultation device confirm's algorithm production derived a key, and used derived a key for encrypting service information to receiving to a.
[0058] The embodiment provision the communication method of terminal, when the front terminal and network side device realizes the communication, when or a network side device of communication with the no hole in the front, or a terminal and network side device realizes the communication, and is attached to the state, or the use field without involve NAS and ACK/NAK and AS, a terminal and network side device for sending the opposite party service information is a communication terminal key are key derived from bottom to encrypt, a receiving end of the receiving a to communication terminal key are key derived a key service information. The root key generation according to the terminal and network side device authentication and key the communication terminal key are key consulted AKA generating, wherein and realizes the network side device transmission's the service information between the terminal performing a safety or the complete protection.
[0059] The two embodiments where the first according to the communication terminal key are key derived from bottom to encrypt the service information, the second received device and device for the service information by, encryption and decryption according to the communication terminal key are key derived a key. The embodiment, first device and second shaft device according to the communication terminal key are key, may use prior with multiple algorithm for production derived a key. Digital 3 provides the terminal and network side device for derived a key schematic drawing for generating according to the communication terminal key are key, a shown the digital 3:
[0060] , Comprising Kasme is a terminal and network side device AKA, two key for generating, Kasmem to act according to Kasme production of the key of communication terminal key, all keys are derived from keys according method of communication terminal key are key Kasmem derived from; the derived from the keys comprises:
[0061] Kdentm: confidentiality protection key for service data;
[0062] Kdintm: Alarm protection key for service data;
[0063] Knasencm: Confidentiality protection key is NAS layer,
[0064] Knasintm: Alarm protection key is NAS layer,
[0065] Kenbm: For producing key, a further derived generating a key Krrcencm, and Krrcintm; Kupentm
[0066] Krrcencm: Confidentiality protection key for RRC signal;
[0067] Krrcintm: Alarm protection key for RRC signal;
[0068] Kupentm: To a user plane confidentiality protection key.
[0069] Digital 3) is installed to enumerate multiple probable the derived a key according is produced by communication terminal key are key, which is a limit of the used for. The terminal and network side device is a shaft according to the executed a specific service, wherein the inner key generation of communication terminal key is digital 3 other end of derived from keys, the derived a key structure and server is made of digital 3 the other surface.
[0070] , A communication terminal key are key derived a key is generated by the the first algorithm of consultation device and second device, capable, the first device and encryption front service information generated, a second device realizes the decryption front service information of receiving generating, it has no need to generate a pre-formed. for example: Kdentm and Kdintm according derived a key shown the shape of 3 to the consulted algorithm; aKenbm, Krrcentm and Krrcintm derived a key is installed in the first device and encryption front service information generated, a second device realizes the decryption front service information of receiving generating, it has no need to generate a pre-formed.
[0071] Intervals; and network side device executed service type between the terminal, or a service information type of transmission, may use different algorithm for different from derived key. Further in aggregate of the types' service, capable of the derived from keys and, and capable of the component (is one or multiple probable of) derived a key.
[0072] ; Each of derived from keys according is produced by communication terminal key are key, and capable and network side device transmission's the service information between the terminal performing a confidentiality protection, and capable and network side device transmission's the service information between the terminal performing a complete protection. And the confidentiality protection or the complete protection capable of through the existing or more of algorithms, wherein of longer details.
[0073] The following to back to a to act according to the communication terminal key are key, generating formulas of each of derived from keys, specifically is as follows:
[0074] Kasmem the KDF (Kasme, ^M/low access priority/small data transmission function (name/function name),),
[0075] , Kasmem represent communication terminal key are key; KDF represent key derived a function, namely, a derived from the base; algorithmThe Kasme represent terminal and network side device AKA, two key for generating, a: ofLTE system of key equal. The key according the EXTERNAL indicating generating is provided with a MTC device, communicationlow access and low represent; anda data transmission platform is a data transmission. function name/function table server the no hole/name server function. The, wherein, a low access and an and small data transmission, and a function name/function back of the is a series of character, which can characteristic is represent terminal with.
[0076] A watch working state of the terminal and network side device capable of generating key input parameter indicating capacity identifier, which identifier can be a series of character, can be used for production represent key practical the MTC type communication, or represent practical a low access and lower access and type), or represent practical part Is a a field or the or function (function or function) terminal using.
[0077] Knasintm the KDF (Kasmem, NAS-int-alg, Alg-ID, a M/low access priority/smalldata transmission function (name/function name),),
[0078] , Knasintm represent layer NAS protecting alarm, keyNAS_int_alg represent layer NAS integrity protection; algorithmAlg_ID is identifier algorithm.
[0079] Knasencm the KDF (Kasmem, NAS-enc-alg, Alg-ID, a M/low access priority/smaildata transmission function (name/function name),),
[0080] , Knasencm represent NAS layer confidentiality protection key; NAS-enc_alg represent NAS layer confidentiality protection algorithm.
[0081] Kenbm the KDF (Kasmem, uplink NAS count)
[0082] , The Kenbm represent eNB key, a process key; Uplink NAS count represent and NAS counter value. Different from derived key, with different inverse counter (a); the values can be different form; the derived a key Kenbm input parameter may use and NASC0UNT value (NAS uplink COUNT), can use nounce value.
[0083] Kupentm the KDF (Kenbm, ent-alg OF)
[0084] , Kupentm represent to user plane confidentiality protection key. ent-alg OF represent confidentiality protection key identifier algorithm.
[0085] Krrcencm the KDF (Kenbm, RRC-enc-alg, Alg-ID, a M/low access priority/smalldata transmission function (name),),
[0086] , Krrcencm represent RRC signal confidentiality protection key; RRC-enc_alg represent RRC confidentiality protection; algorithmAlg_ID is identifier algorithm.
[0087] Krrcintm the KDF (Kenbm, RRC-int-alg, Alg-ID, a M/low access priority/smalldata transmission function (name),),
[0088] , Krrcintm represent RRC alarm signal protection key; RRC-int_alg represent RRC integrity protection; algorithmAlg-ID is identifier algorithm.
[0089] Kdentm the KDF (Kasmem, enc-alg, M/low access priority/smalI (datatransmission function name/function name)
[0090] , Kdentm represent service data confidentiality protection key; enc-alg represent confidentiality protection algorithm.
[0091] Kdintm the KDF (Kasmem, int-alg, M/low access priority/smalI (datatransmission function name/function name)
[0092] , Kdintm represent service data integrity protection key; int_alg represent integrity protection algorithm.
[0093] The is installed to generate a communication terminal key are key, and generating the feasible the manner of each derived from keys according to the communication terminal key are key, which is composed of the used as to limit the invention.
[0094] A see from the type of terminal and network side device may allocate resources for according to any one of terminal (e.g:. And the type of terminal, a practical field or a special function equal), the confirm is used for encrypting service information the derived a key; theMoreover, the terminal and network side device is a shaft according to any one of terminal, a confirm generating algorithms of each of derived from keys according to the communication terminal key are key, a: ofThe confidentiality protection or the gravity of the key NAS layer, may use NAS algorithm to act according to the root key generation of communication terminal key, and confidentiality protection or a protecting alarm of key RRC signal, may use RRC algorithm to the root key generation of communication terminal key.
[0095] Are needed to explain; and confidentiality protection or the gravity of the key NAS layer and NAS algorithm to act according to the root key generation of communication terminal key, a confidentiality protection or a protecting alarm of key RRC signal for RRC algorithm to the root key generation of communication terminal key, wherein when the terminal with the other inter-RAT switchings or application scenes with the NAS algorithm or a RRC algorithm with varying; and confidentiality protection or the gravity of the key NAS layer is lower end of the corresponding updating.
[0096] Wherein the terminal and network side device flowing of the new of the key AKA each time, communication terminal key are key Kasmem of therefore, the embodiment of the invention claims, wherein each of the terminal and network side device realizes AKA of updating. The front terminal and network side device, communication the terminal is in a online no hole; theOr cm; when terminal and network side device, communication the terminal is in a no hole and on-line, or the front, terminal and network side device, communication the terminal is in attached to the; andOr a, wherein the terminal and network side device communication without involve NAS and accessing and AS, a communication terminal key are key capable of the terminal and network side device recent AKA the root key generation of generating; and upgrade the derived from keys is designed to a communication terminal key are key.
[0097] Digital 4) is a current image communication method the embodiment of this invention claims, and shown the digital 4, wherein the embodiment which is a MTC device condition of a terminal of the part from the scenes for REPORTING method, sensor and type of MTC device no need of the online and is a long time, and MTC device usually regularly to the network side device, is of a monitoring centre equal reporting having a data, a: ofDetection sensor; the temperature and humidity the small data. , MTC device of online (offline), a MTC device without with safety context, is not connected to a on the confidentiality or a protecting alarm to a data reporting of.
[0098] The method for embodiment provision, the first device is a terminal (the MTC device), the second device for network side device (MME), the first device and NAS strike and device for small data, here small data part can be used for: ofThe first device (sensor) temperature detector, a humidity and data are relatively small the data, or and first device (water device and device electirc) and reading and data are relatively small the data. The specifically method comprises:
[0099] S40UMTC device to MME receives service information, wherein the service information comprising a MTC device is a data of MME and (a) data.
[0100] The MTC device may use communication terminal key are key derived a key to the MTC device for full service information end of the protecting alarm, and is made of derived a key Kdentm equal, and confidentiality protection (is Kdentm key encryption to a data in service information without is a feasible embodiment of embodiment, having understandable, is further in a communication terminal key the other derived from keys of key are filled with encryption), a data encrypting with a are not Kdentm (smalI) data.
[0101] The communication terminal key according the embodiment of this invention relates a position see is a communication terminal key are key and derived from each of derived from keys' framework shown the digital 3. , A communication terminal key and derived switches from the root key and derived from a storage the terminal for example, a mobile device (Mobile Device; ME) is non-volatile layer (nonvolatile), a ensure secure storage.
[0102] , And configuring algorithm of the MTC device and MME according to the communication terminal key are key generation derived a key for pre-twisted patching bar; aOr, a MTC device for performing the algorithm to consult with MME for pre-twisted patching bar, the consults algorithm of according to the communication terminal key are key generation derived a key of. Further used; the MTC device can also save the generating derived a key algorithm identifier to MME service information of the light; the algorithm identifier capable of the MTC device and MME of the algorithm for negotiating by production derived a key algorithm identifier algorithm.
[0103] The algorithm consultation of MTC device and MME may use the network that usually, a terminal can makes safety capabilities information from the network side device, safety capabilities information may include for supporting algorithm and information, network side device may allocate resources for according to for policy and terminal safety property confirm algorithm, and algorithm determined by the terminal. Of different from derived key is usually metering for different consultative manner, a: ofDerived a key Knasencm and Knasintm, Krrcencm and Krrcintm, and selects a prior algorithm consultation method,The algorithm consultation of derived a key Kdentm and Kdintm, wherein format (format) and a NAS algorithm consultation or RRC algorithm consultation different.
[0104] The MTC device to MME algorithm identifier, a through 0x00 the identifier level or 0x00 to 0x05 of the expansion identifier of represent to 0x05; And/or; the algorithm identifier is provided with a represent MTC device and algorithm of according to communication terminal key are key generation derived a key (Kdentm) by, and the complete protection or a confidentiality protection to the service information of the represent MTC device (the embodiment, derived from keys are used to MTC device for time confidentiality protection to MME small) data. The prior NAS algorithm identifier or a RRC algorithm identifier usually or the 0x01 position is a 0x00, a 0x05 position, the embodiment provision the identifier algorithm for producing derived a key, can receive the identifier connected with the prior 0x00-0x05 position, and outer end of the identifier connected 0x00-0x05 position is the identifier, a: ofFor increasing 0x06 and 0x07 position method for producing identifier derived a key identifier algorithm. AN MM usually preserves with the corresponding relationships of algorithm identifier and algorithm the MTC device, wherein the MME receiving MTC device for the algorithm identifier, a algorithm of the search algorithm identifier are arranged on the algorithm the corresponding relationships of identifier and algorithm, wherein obtaining of one algorithm according to the communication terminal key are key generation derived from the key MTC device using, and derived a key for producing is provided with a confidentiality protection or the complete protection.
[0105] Wherein MME usually and a on communication a plurality of MTC device; and communication terminal key are key of the root key of each MTC device switches generated by AKA with MME generating is further different. In order to make MME the receiving part of MTC device for service information, search and MTC device of the communication terminal key are key, wherein, a MTC device also and a a identifier (KSIm) by MME the service information, the rate identifier is used to differentiate different MTC device communication terminal key are key, a separating MME to act according to rate identifier search the corresponding communication terminal are key. , Rate identifier KSIm, wherein format (format) can Ibit position calling function identifier.
[0106] Each of derived from keys according is produced by communication terminal key are key, and capable and MME transmission's the whole service information between the MTC device realizes the protecting alarm, and capable and MME transmission's a data of service information between the MTC device realizes the confidentiality protection. And the MTC device for derived a key end of the protecting alarm to the service information; and derived a key of the service information encrypts to generate a first alarming message weighted code (Message Authentication Code; MAC), a MME receiving information service, and confirm the service information through the first MAC the integrity, a learn of the transmission's information tampered with.
[0107] The S402.MME receiving MTC device for the service information, wherein the service information according to a to the communication terminal key derived a key abut.
[0108] The MTC device for may include a identifier to MME service information, and MME may allocate resources for according to the locating identifier search to the MTC device of the communication terminal key are key.
[0109] ; The locating identifier capable of the MTC device identifier information, a: ofInternational mobile user identity code (International Mobile User Identity; IMSI) equal, and MME may allocate resources for according to the identifier information to the search MTC device of the communication terminal key are key.
[0110] MME may allocate resources for according to the algorithm of generating derived a key is pre-formed configuring, or by the MTC device algorithm for negotiating by algorithm, or the MTC device to the algorithm identifier in MME service information, comprising according to the MTC device communication terminal key are key, which the corresponding algorithm production derived a key (Kdentm), which the derived a key a to the service information.
[0111] A MTC device for a farther comprising first MAC to MME service information, and MME and a to act according to the first MAC end of the complete data to the service information.
[0112] The embodiment without taking MTC device to MME receives service information and invention, a terminal and communication method of this invention provides the invention. MME to the specific process and embodiment of MTC device for service information same.
[0113] Digital 5) is a current image communication method the embodiment of this invention claims, and shown the digital 5, wherein the embodiment, the first device is a terminal (the MTC device), the second device for network side device, the second device exactly comprises (eNB and MME). Of MTC device of online, wherein eNB to MME and a data (small data), a terminal and a a data in RRC alarming signal to the network side. The specifically method comprises:
[0114] The S50UMTC device to the top eNB RRC signal, wherein the RRC signal based on the communication terminal key are key derived a key encrypts a data.
[0115] The embodiment, the MTC device capable of communication terminal key are key derived a key Krrcencm to a data in the RRC signal based end of the confidentiality protection. For Krrcencm (data) to indicate the encryption process's a data in RRC signal. Moreover, the MTC device is an rate identifier KSIm to the eNB RRC signal in the top, a separating MME to act according to the locating identifier learning is a RRC signal of one end receives, wherein search the terminal of the terminal communication keys are key.
[0116] The communication terminal key of the key algorithm of process of key generation derived a key, a conducting is pre-formed on the MTC device and MME; Or cm; the MTC device for performing the algorithm to consult with MME a pre-formed, automatically according to communication terminal key of the key algorithm of process of key generation derived a key of the confirm.
[0117] Further used; the MTC device also and a to act according to communication terminal key are key processing key generation derived a key algorithm algorithm identifier (ent-rrc-alg) to the eNB RRC signal and output.
[0118] A identifier KSIm top of the RRC signal S502 and eNB a receiving to MME.
[0119] S503 and A AN found the corresponding to the identifier KSI and communication terminal key are key Kasmem and no hole and accessing layer NAS counter, and producing method Kenbm key.
[0120] S504 and MME the press button Kenbm to eNB.
[0121] Further used, MME and capable and a pre-formed, or and MTC device confirm consultation to communication terminal key processing key generation derived a key algorithm algorithm identifier (ent-rrc-alg) sends to eNB.
[0122] S505 and eNB shaft according to ent-rrc-alg two) and processing key Kenbm calculation derived from Krrcencm key, a data according and receiving the RRC signal of load according to the derived a key Krrcencm abut to a, a gain a primary data information.
[0123] Image 6) is a current image communication method the embodiment of this invention claims; and pattern as 6, wherein the embodiment, without involve the NAS layer or AS layer, a MTC device or a safety context. The specifically method comprises:
[0124] S601 and community broadcast systems (Cell Broadcast, SystemsCBE) is community broadcast body (CellBroadcast; CentreCBC) by broadcast the support (urgently Emergency Broadcast) Request.
[0125] S602 and CBC to MME sending alarming request message (Write-Replace Alarming) Request.
[0126] , Wherein S601 CBE of the emergency broadcast request of CBC top and a MTC device corresponding user identity (UPID), CBC receiving the emergency broadcast request, user identity UPID of the alarming request message the output MME. Or; the emergency broadcast request in S601 further can not a user identity UPID, further CBC the through S602 to MME and sends the alarming request message and user identity UPID by. The pattern 6 cooling is in S601 CBE to the emergency broadcast request of CBC top of MTC device of the user identity (UPID) situation.
[0127] S603> MME to CBC with an request message identifying (Write-Replace Alarming) Confirm.
[0128] S604 and CBC broadcasting response to the CBE for urgently (Emergency Broadcast Response).
[0129] The S605 and MME and a CBC output circuit board (trigger) MTC device corresponding user identity (UPID), the utilization of using derived a key Kdintm a on the confidentiality protection to UPID.
[0130] , MME is of a trigger (trigger) and MTC device for generating MAC, for performing a protecting alarm to user identity UPID a first MAC, a to make the MTC device for user identity UPID, and a first MAC to user identity UPID a on the complete apparatus, to learn of the user identity UPID with tampered.
[0131] S606> MME to eN B for alarming request message (Write-Replace Alarming) Request.
[0132] S607 and eN B to MME with an request response (Write-Replace Alarming Response).
[0133] S608 and eNB electrically connected with the MTC device after the confidentiality and UPID playing of gravity protection.
[0134] The S609 and MTC device receiving broadcast message, search the end of the broadcast message U PI D; using derived a key Kdintm deciphers UPID.
[0135] , According to communication terminal key the algorithm of two key generation derived a key Kdintm utilization's, a conducting and MME is pre-formed on the MTC device; Or, and using third party device, a: of0MA DM Hole (MobileAllicance Device and) OTA (The air) in of the derived a key algorithm light identifier to the MTC device; Or, comprising capable of the derived a key algorithm light identifier in playing to the MTC device.
[0136] Current and prior community broadcasting system according S601-S609 providing Cell (Broadcasting system,CBS) process is similar, wherein of longer details.
[0137] Digital 7) is a current image communication method the embodiment of this invention claims, and shown the digital 7, wherein the embodiment, is described that is attached to the (detach) connected to the network side A AN communication the MTC device, wherein the E A communication, a MTC device adhered to the conductive rod (joint) is a network the side, and communication field of indicated the state to MME routing information directive (indication), paved of: Overload controlling (overload controlling) and application scenes. The specifically method comprises:
[0138] S701 and MTC device to the MM AN output NAS message, wherein the information of the low access and Low (accesspriority information), the lower access precedence information is used for identifier MTC device is a low and device.
[0139] , The NAS information can be attached to plating technique the request message joint (request), service request message (servicerequest), or tracking area updating request message (Tracking Area; UpdatingTAU) equal.
[0140] Low access priority for represent MTC device, a MTC device may allocate resources for according to the thereof, and lower sends a message of the NAS message, the confirm for communication terminal key are key derived a key Knasintm end of the protecting alarm to the NAS message, comprising a a communication terminal key are key derived a key Knasencm to the low access precedence information in NAS message end of the confidentiality protection.
[0141] , According to communication terminal key the algorithm of two key generation derived a key, a conducting is pre-formed on the MTC device and MME; Or, a MTC device and MME may allocate resources for according to communication terminal key the algorithm of two key generation derived a key by algorithm consultation confirm.
[0142] Further used; the MTC device and a a algorithm algorithm identifier used to the communication terminal key are key generation derived key from the top of the NAS message to MME.
[0143] Further used, and communication terminal key are key derived a key Knasintm of the NAS message and protecting alarm, capable of a first MAC, MTC device of MAC end of the NAS message sending to MME, wherein MME to act according to the first MAC end of the complete data to the NAS message.
[0144] The embodiment, and derived a key Knasintm of the NAS message the integrity protection; the NAS message of the NAS message (Knasintm (Low access, and it is a algorithm identifier, further including the first MAC)).
[0145] The S702 and MME and a NAS message, and communication terminal key are key derived a key and decryption and a on the following operation to the NAS message.
[0146] MME may use algorithm of a pre-formed configuring, according to communication terminal key are key generation derived a key, KnasintmOr; the NAS information of a MME for receiving the algorithm identifier, and MME of by using the algorithm identifier of the algorithm, according to communication terminal key are key generation derived a key Knasintm, and using the derived a key Knasintm a to the NAS message.
[0147] The NAS information of A radiating STRUCTURE comprises a first of MAC, and A SAME using the derived a key Knasintm of the NAS message and decryption, comprising a structure according to the first MAC to the NAS message in the complete apparatus.
[0148] Embodiment of this invention claims; and multiple scenes, the first device and second possibly device further comprises a LTE system of key, wherein the shell; the first device is a shaft according to the LTE system of key generation integrity protection key, and for protecting alarm button from the service information and encryption to generate second MAC, and the second the RECEIVED from the service information to the second device. The device capable shaft of MAC second end of the complete data to the service information of receiving. Are needed to explain; and complete failure of the second device has first MAC data service information, or according to the complete failure of MAC second data service information; and alarm for determining failure of service information.
[0149] Digital 8) is a current image communication method the embodiment of this invention claims, and shown the digital 8, wherein the specific field of embodiment provision of the =MTC and an inner condition, lower attached to a network and a network side from a data. The embodiment and between the MTC device and server for transmitting a data of as of. Wire; and MTC device and MME and using the short message service (Short Message Service; SMS) is a data, it has no need of EPS bearing (bearers) between the MTC device and MME. The specifically method comprises:
[0150] S801 and MTC device to MME for short message, a data in the short message system for communication terminal key are key derived a key Kdentm end of the confidentiality protection.
[0151] , According to communication terminal key the algorithm of two key generation derived from Kdentm key, a conducting is pre-formed on the MTC device and MME; Or, a MTC device and MME may allocate resources for according to communication terminal key the algorithm of two key generation derived a key by algorithm consultation confirm.
[0152] Further used; the MTC device and a a algorithm algorithm identifier used to the communication terminal key are key generation derived key from the top of the short message to MME.
[0153] The S802 and MME and MTC device for a short message, and communication terminal key are key derived a key Kdentm to a data in short message to a network, an initial small data.
[0154] MME may use algorithm of a pre-formed configuring, according to communication terminal key are key generation derived a key, KdentmOr, wherein the short message of a MME for receiving the algorithm identifier, and MME of by using the algorithm identifier of the algorithm, according to communication terminal key are key generation derived a key Kdentm, and using the derived a key Kdentm to a to a data in short message.
[0155] The S803 and MME a decryption, a data and device for distributing server (e.g:. MTC) server/SM-SC.
[0156] The S801-S803 where the MTC device to the process of server by a data. The invention claims S804-S806 the server to the process of MTC device for small data.
[0157] S804 and server to MME by a data.
[0158] A data of S805 and MME transmitting and receiving the top of the short message to the MTC device, a data for communication terminal key are key derived a key Kdentm end of the confidentiality protection.
[0159] Further used, MME and a a algorithm algorithm identifier used to the communication terminal key are key generation derived key from the top of the short message to the MTC device.
[0160] S806 and MTC device for a data in short message the communication terminal key are key derived a key Kdentm abut to a decryption, and an initial small data.
[0161] The field and an further understand capable of realizing switch or a part of said current embodiment, method may receive the related a hardware by computer program (for example, computer or a special integrated - circuit ASIC) completes, a program is a memory is fixed to an arranged in a computer the storage medium, and program when the performing, may include to the method embodiment flow. , Storage medium and has a diskette, CD and storage read-only memory (Read-Only Memory, ROM) or to a memory (Random Access Memory RAM,) equal.
[0162] Digital 9 is the invention provides the is executed and method embodiment device for example's a structure schematic drawing for communication terminal, and shown the digital 9, wherein the device for communication terminal comprises: Processor 11, memorizers 12 and 13 transmitter;
[0163] The processor 11, by communication terminal key are key derived a key encrypt the service information, the root key generation of the communication terminal key key are connected to the device and second device authentication and key for communication terminal is consulted AKA generating;
[0164] ; The embodiment provision apparatus for communication terminal can be a terminal, a second device has a network side device; Or; the embodiment provision apparatus for communication terminal has a network side device, the second device is arranged is a terminal;
[0165] Memorizers 12, two key for storage communication terminal key;
[0166] The transmitters 13, wherein a encrypt the service information sending of the second device, so of the second device uses a communication terminal key are key derived a key service information to the receiving to a.
[0167] The invention claims an is executed and method embodiment of terminal device communication's one embodiment, a processor 11) can be used for: A second device end of the algorithm to consult, wherein the root key generation of communication terminal key to the algorithm of by to the derived a key for.
[0168] , Wherein the service information of encrypted further comprises: The processor 11 based on the inner key generation of communication terminal key to the algorithm algorithm identifier of the derived a key for.
[0169] Particularly, the algorithm identifier of through 0x00 the identifier level or 0x00 to 0x05 of the expansion identifier of represent to 0x05; And/or, wherein the algorithm identifier is provided with a represent with the processor 11 based on the inner key generation of communication terminal key to the algorithm for derived a key adopts, and processor 11 pairs to the service information end of the protecting alarm or a confidentiality protection for represent.
[0170] And a step further, according to the root key generation of communication terminal key to the algorithm for derived from the key, a device for communication terminal and a second to device and a pre-formed.
[0171] And a step; is further arranged in the service information of encrypted further comprises: A identifier, wherein rate identifier is used to differentiate different terminal communication terminal key are key, so of the second base device of rate identifier search the corresponding communication terminal key are key.
[0172] On the service information of encrypted further comprises: First alarming message weighted code MAC, wherein the first of MAC is the processor based 11 to the derived a key back to the service information of the arc-shaped integrity generating, so of the second base device of MAC first end of the complete data to the service information of receiving.
[0173] The communication terminal key are key derived a key at least comprises: The confidentiality protection and protecting alarm of key and a confidentiality protection and protecting alarm of key, a press button and a confidentiality protection and protecting alarm of key and a user plane confidentiality protection key and a radio resource control signal RRC no hole accessing layer NAS hierarchical service data or multiple probable of.
[0174] And a step further, the processor 11) is used for: According to any one of terminal, a confirm is used to encrypt of service information the derived from the key and a to the root key generation of communication terminal key to the algorithm for derived a key for.
[0175] , The memorizer 12 storages' communication terminal key are key, with the embodiment provision apparatus and second device recent AKA for communication terminal are key generation of generating.
[0176] On the service information of encrypted further comprises a second MAC, wherein the RECEIVED from the embodiment provision apparatus to long-term evolution LTE system of key derived self gravity protection key for communication terminal the back service information of the arc-shaped integrity generating, so of the second base device of MAC second end of the complete data to the service information of receiving, the root key generation of the LTE system of key back to the device for communication terminal and a second the device AKA generation.
[0177] The embodiment, a transmitter 13 of the second device used for the service information of encrypted; the embodiment provision apparatus for communication terminal capable of the online no hole; theThe or, a transmitter 13 to the second device used for the service information of encrypted, a communication terminal the device capable of the online no hole; theOr, a transmitter 13 of the second device used for the service information of encrypted, a terminal communication apparatus can be is attached to the; andOr, a transmitter 13 the service information of encrypted not to involve no hole accessing layer NAS and accessing layer is the second device for sending and AS.
[0178] The embodiment provision apparatus for communication terminal, a terminal the first device of the communication method the embodiment of the invention claims corresponding, the specific process of wherein executed method of see and method for embodiment, wherein the details longer.
[0179] The embodiment of the invention claims a device for communication terminal capable of the terminal, a second device has a network side device; Or, the embodiment of the invention claims a device for communication terminal has a network side device, the second device can be a terminal; The embodiment of the invention claims a device for communication terminal, and communication terminal key are key derived from bottom to encrypt to the second device sends' service information, the root key generation of the root of the key base of communication terminal key is provided with a terminal communication apparatus consulted AKA generated by the second device authentication and key, wherein implemented as to be used for communication terminal the transmission's the service information and second device realizes the safety or the complete protection.
[0180] Digital 10 is the invention provides the is executed and method embodiment device with the example's structure schematic drawing for communication terminal, and shown the digital 10, wherein the device for communication terminal comprises: Receiver 21, memorizers 22 and 23 processor;
[0181] The receiver 21, for receiving the first device sends' service information, wherein the service information by said first device is communication terminal key the derived a key encryption of two key, a tinned key generation of the communication terminal key key are formed by the device for communication terminal and first device consulted AKA generated by the authentication and key;
[0182] ; The embodiment provision apparatus for communication terminal has a network side device, the first device is arranged is a terminal; Or; the embodiment provision apparatus for communication terminal can be a terminal; the first device has a network side device;
[0183] The memorizers 22, wherein the communication terminal key are key for storage;
[0184] The processor 23, a man-machine to the communication terminal key are key derived a key to the service information to a.
[0185] The invention claims an is executed and method embodiment of terminal device communication's one embodiment, a processor 23) can be used for: A first device end is algorithm to consult, wherein the root key generation of communication terminal key to the algorithm of by to the derived a key for.
[0186] , Wherein the service information further comprises: The first device switches to the root key generation of communication terminal key to the algorithm algorithm identifier of the derived a key for.
[0187] And a step; further connected to a service information further comprises a identifier, wherein the rate identifier is used to differentiate different terminal communication terminal key are key; And the processor (23) is further used for: To the locating identifier search the corresponding communication terminal key are key.
[0188] And a step; further connected to a service information further comprises: First alarming message weighted code MAC, wherein the first RECEIVED by said first and changes to the derived a key back to the service information end of the integrity are connected; aAnd the processor 23) is used for: To the first MAC, to the service information end of the complete apparatus.
[0189] , The memorizer 22 storages' communication terminal key are key, a after the first device and embodiment provision for communication terminal device recent AKA are key generation of generating.
[0190] The embodiment, front receiver 21 first receiving device for service information, the embodiment provision apparatus for communication terminal capable of the online no hole; theThe or receiver, 21 first receiving device for service information, the device for communication terminal capable of the online no hole; theOr, front receiver 21 first receiving device for service information, the device for communication terminal can be is attached to the; andOr, a receiver 21 first receiving device sends' service information can not involve no hole accessing layer NAS and accessing and AS.
[0191] The embodiment provision apparatus for communication terminal, terminal and second device of the communication method the embodiment of the invention claims corresponding, the specific process of wherein executed method of see and method for embodiment, wherein the details longer.
[0192] The embodiment of the invention claims a device for communication terminal can be a terminal; the first device has a network side device; Or, the embodiment of the invention claims a device for communication terminal has a network side device, the first device can be a terminal; The embodiment of the invention claims a device for communication terminal, wherein the first device for the service information is a communication terminal key are key derived from bottom to encrypt, the root key generation of the root of the key base of communication terminal key is provided with a terminal communication apparatus and first authentication device and key consults AKA, generating, the device for communication terminal and decryption the service information according to the communication terminal key are key derived a key, wherein realizing the solution for communication terminal apparatus and first device transmission's the service information and connection or the complete protection.
[0193] Digital 11 is the invention claims a communication system for example's structure schematic drawing for executed and method embodiment, and shown the digital 11, the communication system of terminal comprises: Terminal I and network side device, 2
[0194] The terminal (1), a to the network side device for 2 first service information, and/or a receiving the network side device 2 from the second service information, wherein the first service information by communication terminal key the derived a key encryption of two key, wherein the second service information uses a communication terminal key the derived a key encryption of two key, a tinned key generation of the terminal communication same as the key is the terminal I and network side device 2 and authentication the keys consulted AKA generating, used to the communication terminal key are key derived a key to of the second serviceThe information; deciphers
[0195] The network side device, 2 is the second service information to the terminal, and/or, received the terminal I output to the first service information, wherein the first service information uses a communication terminal key the derived a key encryption of two key, wherein the second service information uses a communication terminal key the derived a key encryption of two key, a to the communication terminal key are key derived a key is connected to the first service information to a.
[0196] The embodiment provision the communication system of terminal, a terminal and network side device terminal performing the specific process of communication method of see and method for embodiment, wherein of longer details.
[0197] The communication system according terminal of the embodiment of the invention claims, wherein the front terminal and network side device realizes the communication, when or a network side device of communication with the no hole in the front, or a terminal and network side device realizes the communication, and is attached to the state, or the use field without involve NAS and ACK/NAK and AS, a terminal and network side device transmission's service information for communication terminal key are key derived from bottom to encrypt, the root key generation according to the terminal and network side device authentication and key the communication terminal key are key consulted AKA generating, wherein and realizes the network side device transmission's the service information between the terminal performing a safetyOr alarm protection.
[0198] Finally are arranged explain: The embodiment without using to is in the invention the technical solution, it is made wherein limiting; Although reference preceding embodiment is carried out detailed distributed to the invention, the common a provide the field claim understand: A position of use to the technical solution of the preceding embodiment two recording, or time to equate the alternative to an part; featuresAnd the revisions or the alternatives, connected with of the precise of corresponding technical solution is separated from the invention the embodiment a wireless the preciseGods ranges and.
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| CN108605225A | Cited by | China | Search report |
| CN106357386A | Cited by | China | Search report |
| WO2017133021A1 | Cited by | World Intellectual Property Organization (WIPO) | International search |
| WO2017147780A1 | Cited by | World Intellectual Property Organization (WIPO) | International search |
| WO2019023825A1 | Cited by | World Intellectual Property Organization (WIPO) | International search |
| US10673611B2 | Cited by | United States of America | Applicant |
| CN111010412A | Cited by | China | Search report |
| CN108112013A | Cited by | China | Search report |
| CN1881875A | Cites | China | Search report |
| US2009116642A1 | Cites | United States of America | Search report |
2 priority claims, no other members on record
Priority claims2
| Document | Office | Kind | Date |
|---|---|---|---|
| 201110231525 | China | A | |
| CN20111231525 | – | – | – |
Numbers
- Publication
- 102932784
- Publication, DOCDB
- 102932784
- Publication, EPODOC
- CN102932784
- Application
- 102315252
- Application, DOCDB
- 201110231525
- Application, EPODOC
- CN201110231525
Titles3
- English
- The communication method and device of terminal
- Chinese
- 终端的通信方法和设备
- English
- Terminal communication method and device
Classification
- CPC, 2
- H04W12/04
- H04W12/04033
- IPC, 1
- H04W12 04