Key distribution method and device, mobile terminal, communication equipment and storage medium
Abstract
The embodiment of the present invention provides a method for issuing a key, a mobile terminal, a communication device, and a storage medium. The method extracts authentication information and a user key according to the received authentication schedule, and generates the first verification according to the key generation rule. Key, and return an authentication response message to the mobile network side. After receiving the authentication response message, the mobile network side also obtains the corresponding authentication information and the user key to generate a second verification key, and compares the first key information Encryption, the third key is obtained and returned to the mobile terminal, and the mobile terminal decrypts the third key information according to the first verification key to obtain the first key information. Based on this mutual method, the key is obtained Issuing to ensure the security of mobile terminals when accessing the mobile network, and also to ensure the real-time update of the key, reduce the tampering of the key, further improve the security, and greatly improve the security performance of the system.

Term
12.3 yearsto projected expiry
Projected expiry 24 December 2038, counted from filing; an application has no term until it is granted.
- Priority and filed
- Published
- Today
- Projected expiry
22 claims: 3 independent, 19 dependent
- 1一种密钥发放方法,应用于移动终端侧,其特征在于,该方法包括: 接收所述移动网络侧发送的第三密钥信息;所述第三密钥信息为所述移动网络侧基于 第二验证密钥加密第一密钥信息的结果获得;所述第二验证密钥为由所述移动网络侧基于 网络用户密钥生成或由所述移动网络侧基于解密第三验证密钥的结果获得;所述第三验证 密钥由所述移动终端基于加密所述第二验证密钥的结果获得,并发送给所述移动网络侧; 基于使用第一验证密钥或所述第二验证密钥解密所述第三密钥信息的结果生成所述 第一密钥信息,所述第一验证密钥为所述移动终端基于终端用户密钥生成; 所述网络用户密钥为用户密钥在所述移动网络侧的备份,所述终端用户密钥为所述用 户密钥在所述移动终端的备份。
- 2如权利要求1所述的密钥发放方法,其特征在于,所述方法还包括: 所述第一密钥信息或所述第三密钥信息中包含密钥更新时间; 在所述密钥更新时间超期后,向所述移动网络侧发送请求所述第三密钥信息的消息。
- 3如权利要求1所述的密钥发放方法,其特征在于,所述方法还包括: 基于所述终端用户密钥和派生信息生成所述第一验证密钥,其中,所述派生信息由所 述移动终端发送给所述移动网络侧,或由所述移动终端接收自所述移动网络侧。
- 4如权利要求1所述的密钥发放方法,其特征在于,所述方法还包括: 存储与所述第一密钥信息相对应的网络信息,或存储与所述第三密钥信息相对应的网 络信息。
- 5如权利要求1所述的密钥发放方法,其特征在于,所述方法还包括: 接收所述移动网络侧发送的验证信息; 基于所述第一验证密钥或所述第二验证密钥以及所述第三密钥信息校验所述验证信 息,或,基于所述第一验证密钥或所述第二验证密钥以及所述第一密钥信息校验所述验证 信息。
- 6如权利要求1所述的密钥发放方法,其特征在于,所述第三验证密钥由所述移动终端 基于加密所述第二验证密钥的结果获得的步骤还包括: 所述移动终端基于保密密钥加密所述第二验证密钥的结果获得,所述保密密钥为所述 移动网络侧的公钥或与所述移动网络侧共享的对称密钥。 7 .一种密钥发放方法,应用于移动终端侧的安全功能,其特征在于,所述方法包括: 收到来自所述移动终端侧的终端设备的第一调用,并返回所述第一调用的结果;所述 第一调用的结果不包含第一验证密钥,或所述第一调用的结果包含第二派生信息,或所述 第一调用的结果包含第三验证密钥;其中,所述第一验证密钥基于终端用户密钥生成,所述 第二派生信息用于与所述终端用户密钥一起生成第一验证密钥,所述第三验证密钥为基于 加密第二验证密钥的结果获得,所述终端用户密钥为用户密钥在所述移动终端侧的安全功 能上的备份;收到来自所述移动终端侧的终端设备的第二调用,并返回所述第二调用的结 果;所述第二调用包含第三密钥信息,所述第二调用的结果不包含第一密钥信息;其中,所 述第一密钥信息为基于使用所述第一验证密钥或所述第二验证密钥解密所述第三密钥信 息的结果生成。 8.根据权利要求7所述的密钥发放方法,其特征在于,所述第一调用包含第一派生信 息,所述第一验证密钥基于所述终端用户密钥和所述第一派生信息生成。
- 79. 根据权利要求7所述的密钥发放方法,其特征在于,所述第一调用的结果包含第二派 生信息,所述第一验证密钥基于所述终端用户密钥和所述第二派生信息生成。
- 810. 根据权利要求7所述的密钥发放方法,其特征在于,所述方法还包括: 存储与所述第一密钥信息相对应的网络信息。
- 911. 根据权利要求7所述的密钥发放方法,其特征在于,所述第三验证密钥基于加密第 二验证密钥的结果获得包括: 所述第三验证密钥基于保密密钥加密第二验证密钥的结果获得,所述保密密钥为移动 网络侧的公钥或与移动网络侧共享的对称密钥。
- 1012. 根据权利要求7所述的方法,其特征在于,所述方法还包括: 收到来自所述移动终端侧的终端设备的第三调用;所述第三调用的输入参数包含验证 信息和部分或全部第三密钥信息,或所述第三调用的输入参数包含验证信息和基于部分或 全部第三密钥信息生成的计算结果; 返回所述第三调用的结果,所述第三调用的结果包含使用所述第一验证密钥或所述第 二验证密钥基于所述输入参数校验所述验证信息的结果; 其中,所述第三密钥信息用于使用所述第一验证密钥或所述第二验证密钥解密所述第 三密钥信息的结果生成第一密钥信息。
- 1113. 一种密钥发放方法,应用于移动终端侧的终端设备,其特征在于,所述方法包括: 接收来自移动网络侧的第三密钥信息,向所述移动终端侧的安全功能发起第二调用, 所述第二调用包含所述第三密钥信息; 所述第三密钥信息是所述移动网络侧基于第二验证密钥加密第一密钥信息的结果获 得,所述第二验证密钥是所述移动网络侧基于网络用户密钥生成,或所述第二验证密钥是 所述移动网络侧基于解密第三验证密钥的结果获得,所述第三验证密钥由所述移动终端发 送给所述移动网络侧,所述网络用户密钥为用户密钥在所述移动网络侧的备份。
- 1214. 根据权利要求13所述的密钥发放方法,其特征在于,所述方法还包括: 向所述移动终端侧的安全功能发起第一调用,接收所述第一调用的结果,所述第一调 用的结果包含所述第三验证密钥。
- 1315. 根据权利要求13所述的密钥发放方法,其特征在于,所述方法还包括: 向所述移动终端侧的安全功能发起第三调用,所述第三调用的输入参数包含验证信息 和部分或全部所述第三密钥信息,或所述第三调用的输入参数包含验证信息和基于部分或 全部所述第三密钥信息生成的计算结果; 接收所述移动终端侧的安全功能返回的验证结果,所述验证结果为使用所述第一验证 密钥或所述第二验证密钥基于所述输入参数校验所述验证信息的结果。
- 1416. 根据权利要求13所述的密钥发放方法,其特征在于,所述方法还包括: 向所述移动终端侧的安全功能发起第一调用,接收所述第一调用的结果,所述第一调 用包含第一派生信息,所述第一派生信息用于与终端用户密钥一起生成第一验证密钥,并 由所述移动终端侧的终端设备生成,或接收自所述移动网络侧,所述第一验证密钥用于解 密所述第三密钥信息,所述终端用户密钥为所述用户密钥在所述移动终端侧的备份。
- 1517. 根据权利要求16所述的密钥发放方法,其特征在于,所述方法还包括: 向所述移动网络侧发送所述第一派生信息。
- 1618. 根据权利要求13所述的密钥发放方法,其特征在于,所述方法还包括: 向所述移动终端侧的安全功能发起第一调用,接收所述第一调用的结果,所述第一调 用的结果包含第二派生信息,所述第二派生信息用于与终端用户密钥一起生成第一验证密 钥,所述第一验证密钥用于解密所述第三密钥信息,所述终端用户密钥为所述用户密钥在 所述移动终端侧的备份; 向所述移动网络侧发送所述第二派生信息。
- 1719. 一种密钥发放方法,应用于移动网络侧的第一核心网功能,其特征在于,所述方法 包括: 向移动终端发送第三密钥信息;或, 向第二核心网功能发送第一密钥信息,接收到来自所述第二核心网功能发送的第三密 钥信息,发送所述第三密钥信息给移动终端; 其中,所述第三密钥信息基于第二验证密钥以及第一密钥信息生成;所述第二验证密 钥为通过解密第三验证密钥生成,或由所述第二核心网功能基于网络用户密钥生成;所述 第三验证密钥接收自所述移动终端,所述网络用户密钥为用户密钥在所述第二核心网功能 侧的备份。
- 1820. 根据权利要求19所述的密钥发放方法,其特征在于,所述方法还包括: 向第二核心网功能发送密钥请求; 接收来自所述第二核心网功能的所述第二验证密钥。
- 1921. 根据权利要求20所述的密钥发放方法,其特征在于,所述密钥请求包含第三派生信 息;所述第三派生信息接收自所述移动终端,用于与所述网络用户密钥一起生成所述第二 验证密钥。
- 2022. 根据权利要求21所述的密钥发放方法,其特征在于,所述密钥请求还包含所述第三 验证密钥,所述第三验证密钥接收自所述移动终端。
- 2123. 根据权利要求19所述的密钥发放方法,其特征在于,所述方法还包括: 向所述移动终端发送第一派生信息;所述第一派生信息接收自所述第二核心网功能, 用于与所述网络用户密钥一起生成所述第二验证密钥。
- 2224. 根据权利要求19所述的密钥发放方法,其特征在于,所述方法还包括: 向所述移动终端发送验证信息; 其中,所述验证信息是基于所述第二验证密钥与部分或全部所述第三密钥信息生成; 或基于所述第二验证密钥与第一计算结果生成,所述第一计算结果基于部分或全部所述第 三密钥信息生成;或基于所述第二验证密钥与部分或全部所述第一密钥信息生成;或基于 所述第二验证密钥与第二计算结果生成,所述第二计算结果基于部分或全部所述第一密钥 信息生成。 25 .一种密钥发放方法,应用于第二核心网功能,其特征在于,所述方法包括: 接收到来自第一核心网功能的第一密钥信息,向所述第一核心网功能发送第三密钥信 息,所述第三密钥信息基于所述第一密钥信息和第二验证密钥生成,所述第二验证密钥基 于网络用户密钥生成,或基于解密第三验证密钥生成,所述第三验证密钥接收自所述第一 核心网功能;或, 接收到来自第一核心网功能的第二派生信息,向所述第一核心网功能发送第二验证密 钥,所述第二验证密钥基于所述第二派生信息与网络用户密钥生成;或, 向第一核心网功能发送第一派生信息,以及,向所述第一核心网功能发送第二验证密 钥,所述第二验证密钥基于所述第一派生信息与网络用户密钥生成; 所述网络用户密钥为用户密钥在所述第二核心网功能侧的备份。 26 .一种移动终端,其特征在于,包括: 第一接收模块,用于接收所述移动网络侧发送的第三密钥信息;所述第三密钥信息为 所述移动网络侧基于第二验证密钥加密第一密钥信息的结果获得;所述第二验证密钥为由 所述移动网络侧基于网络用户密钥生成或由所述移动网络侧基于解密第三验证密钥的结 果获得;所述第三验证密钥由所述移动终端基于加密所述第二验证密钥的结果获得,并发 送给所述移动网络侧; 第一密钥生成模块,用于基于使用第一验证密钥或所述第二验证密钥解密所述第三密 钥信息的结果生成所述第一密钥信息,所述第一验证密钥为所述移动终端基于终端用户密 钥生成,其中所述网络用户密钥为用户密钥在所述移动网络侧的备份,所述终端用户密钥 为所述用户密钥在所述移动终端的备份。 27 .一种密钥发放装置,其特征在于,包括: 第一调用模块,用于收到来自所述移动终端侧的终端设备的第一调用,并返回所述第 一调用的结果;所述第一调用的结果不包含第一验证密钥,或所述第一调用的结果包含第 二派生信息,或所述第一调用的结果包含第三验证密钥;其中,所述第一验证密钥基于终端 用户密钥生成,所述第二派生信息用于与所述终端用户密钥一起生成第一验证密钥,所述 第三验证密钥为基于加密第二验证密钥的结果获得,所述终端用户密钥为用户密钥在所述 移动终端侧的安全功能上的备份; 第二调用模块,用于收到来自所述移动终端侧的终端设备的第二调用,并返回所述第 二调用的结果;所述第二调用包含第三密钥信息,所述第二调用的结果不包含第一密钥信 息;其中,所述第一密钥信息为基于使用所述第一验证密钥或所述第二验证密钥解密所述 第三密钥信息的结果生成。 28 .一种移动终端,其特征在于,包括: 第二接收模块,用于接收来自移动网络侧的第三密钥信息,并向密钥发放装置发起第 二调用,所述第二调用包含所述第三密钥信息; 所述第三密钥信息是所述移动网络侧基于第二验证密钥加密第一密钥信息的结果获 得,所述第二验证密钥是所述移动网络侧基于网络用户密钥生成,或所述第二验证密钥是 所述移动网络侧基于解密第三验证密钥的结果获得,所述第三验证密钥由所述移动终端发 送给所述移动网络侧,所述网络用户密钥为用户密钥在所述移动网络侧的备份。 29 .一种通信设备,其特征在于,包括: 第一发送模块,用于向移动终端发送第三密钥信息;或,向第二核心网功能发送第一密 钥信息; 第三接收模块,用于接收到来自所述第二核心网功能发送的第三密钥信息,发送所述 第三密钥信息给移动终端; 其中,所述第三密钥信息基于第二验证密钥以及第一密钥信息生成;所述第二验证密 钥为通过解密第三验证密钥生成,或由所述第二核心网功能基于网络用户密钥生成;所述 第三验证密钥接收自所述移动终端,所述网络用户密钥为用户密钥在所述第二核心网功能 侧的备份。 30. 一种通信设备,其特征在于,包括:第四接收模块和第二发送模块; 所述第四接收模块用于接收到来自第一核心网功能的第一密钥信息,所述第二发送模 块用于向所述第一核心网功能发送第三密钥信息,所述第三密钥信息基于所述第一密钥信 息和第二验证密钥生成,所述第二验证密钥基于网络用户密钥生成,或基于解密第三验证 密钥生成,所述第三验证密钥接收自所述第一核心网功能;或, 所述第四接收模块用于接收到来自第一核心网功能的第二派生信息,所述第二发送模 块用于向所述第一核心网功能发送第二验证密钥,所述第二验证密钥基于所述第二派生信 息与网络用户密钥生成;或, 所述第二发送模块用于向第一核心网功能发送第一派生信息,以及,所述第二发送模 块向所述第一核心网功能发送第二验证密钥,所述第二验证密钥基于所述第一派生信息与 网络用户密钥生成,所述网络用户密钥为用户密钥在所述第二核心网功能侧的备份。 31. 一种通信设备,其特征在于,包括:处理器、存储器、通信单元和通信总线; 所述通信总线用于实现所述处理器、所述通信单元和所述存储器之间的无线通信连 接; 所述处理器用于执行存储器中存储的一个或者多个第一程序,以实现如权利要求1至6 任一项所述的密钥发放方法的步骤; 所述处理器用于执行存储器中存储的一个或者多个第二程序,以实现如权利要求7至 12任一项所述的密钥发放方法的步骤; 所述处理器用于执行存储器中存储的一个或者多个第三程序,以实现如权利要求13至 18任一项所述的密钥发放方法的步骤 所述处理器用于执行存储器中存储的一个或者多个第四程序,以实现如权利要求19至 24任一项所述的密钥发放方法的步骤; 所述处理器用于执行存储器中存储的一个或者多个第五程序,以实现如权利要求25所 述的密钥发放方法的步骤。 32. 一种计算机可读存储介质,所述计算机可读存储介质存储有一个或者多个第一计 算机程序、第二计算机程序、第三计算机程序、第四计算机程序和第二计算机程序,所述一 个或者多个第一计算机程序可被一个或者多个处理器执行,以实现如权利要求1至6任一项 所述的密钥发放方法的步骤; 所述一个或者多个第二计算机程序可被一个或者多个处理器执行,以实现如权利要求 7至12任一项所述的密钥发放方法的步骤; 所述一个或者多个第三计算机程序可被一个或者多个处理器执行,以实现如权利要求 13至18任一项所述的密钥发放方法的步骤 所述一个或者多个第四计算机程序可被一个或者多个处理器执行,以实现如权利要求 19至24任一项所述的密钥发放方法的步骤; 所述一个或者多个第五计算机程序可被一个或者多个处理器执行,以实现如权利要求 25所述的密钥发放方法的步骤。
Independent claims22
462 paragraphs, as filed
Key issuing method and device, mobile terminal, communication equipment and storage mediumTechnical field
[0001] The embodiment of the present invention relates to but not limited to the field of communication technology, and specifically relates to but not limited to a key issuing method and device, mobile terminal, communication device, and storage medium.
Background technique
[0002] The 3rd Generation Partnership Project (3GPP) has formulated specifications for various mobile networks, and mobile networks deployed in accordance with these specifications are also being attacked by various pseudo base stations, leading to an attack that can be implemented. The main reason is that the mobile terminal cannot authenticate the authenticity of the base station, and thus accepts various instructions sent by the pseudo base station.
[0003] In order to authenticate the base station (authentic), key information must be issued on the base station and the mobile terminal, so that the base station can protect the sent message or part of the message according to the key information, so that the mobile terminal can The message sent by the base station is authenticated according to the key information, and the authenticity of the base station can be authenticated, so that the pseudo base station cannot access the mobile network to obtain the key information.
[0004] 3GPP has formulated the authentication and key agreement (Authentication and Key Agreement, AKA) specification between the mobile network and the mobile terminal, but this specification can only enable the mobile network to issue the key information associated with the subscriber to the mobile terminal. It protects various communications of users, but cannot issue key information associated with the base station, and cannot realize the authenticity authentication of the base station by the mobile terminal. That is to say, the current authenticity authentication can only be realized after mutual communication is established. , This way will cause security problems.
Summary of the invention
[0005] The embodiments of the present invention provide a method and device for issuing a key, a mobile terminal, a communication device, and a storage medium to solve the problem that the mobile terminal cannot obtain the authentication key when accessing the mobile network in the prior art. Lead to technical problems with low communication security.
[0006] In order to solve the above technical problems, an embodiment of the present invention provides a method for issuing a key, which is applied to a mobile terminal side, and the method includes:
[0007] receiving the third key information sent by the mobile network side; the third key information is obtained by the mobile network side encrypting the first key information based on the second verification key; the second The verification key is generated by the mobile network side based on the network user key or obtained by the mobile network side based on the result of decrypting the third verification key; the third verification key is obtained by the mobile terminal based on the encryption of the third verification key. The result of the second verification key is obtained and sent to the mobile network side;
[0008] The first key information is generated based on the result of using the first verification key or the second verification key to decrypt the third key information, and the first verification key is based on the mobile terminal End user key generation;
[0009] The network user key is a backup of the user key on the mobile network side, and the terminal user key is a backup of the user key on the mobile terminal.
[0010] In order to solve the above technical problems, an embodiment of the present invention also provides a key issuance method, which is applied to the security function of the mobile terminal side, and the method includes:
[0011] The first call from the terminal device on the mobile terminal side is received, and the result of the first call is returned; the result of the first call does not include the first verification key, or the first call The result of contains the second derivative information, or the result of the first call contains the third verification key; wherein, the first verification key is generated based on the end user key, and the second derivative information is used to communicate with the The terminal user key is used together to generate a first verification key, the third verification key is obtained based on the result of encrypting the second verification key, and the end user key is the security function of the user key on the mobile terminal side The second call is received from the terminal device on the mobile terminal side, and the result of the second call is returned; the second call contains the third key information, and the result of the second call is not Contains first key information; wherein, the first key information is generated based on the result of decrypting the third key information using the first verification key or the second verification key.
[0012] In order to solve the above technical problems, embodiments of the present invention also provide a method for issuing a key, which is applied to a terminal device on the mobile terminal side, and the method includes:
[0013] Receive the third key information from the mobile network side, initiate a second call to the security function of the mobile terminal side, the second call contains the third key information;
[0014] The third key information is obtained by the mobile network side encrypting the first key information based on the second verification key, and the second verification key is the mobile network side based on the network user key Or the second verification key is obtained by the mobile network side based on the result of decrypting the third verification key, the third verification key is sent by the mobile terminal to the mobile network side, and the network The user key is a backup of the user key on the mobile network side.
[0015] In order to solve the above technical problem, an embodiment of the present invention also provides a key issuance method, which is applied to the first core network function on the mobile network side, and the method includes:
[0016] Send the third key information to the mobile terminal; or,
[0017] Send the first key information to the second core network function, receive the third key information sent from the second core network function, and send the third key information to the mobile terminal;
[0018] Wherein, the third key information is generated based on the second verification key and the first key information; the second verification key is generated by decrypting the third verification key, or is generated by the second core The network function is generated based on the network user key; the third verification key is received from the mobile terminal, and the network user key is a backup of the user key on the second core network function side.
[0019] In order to solve the above technical problem, an embodiment of the present invention also provides a key issuance method, which is applied to the second core network function, and the method includes:
[0020] receiving first key information from the first core network function, and sending third key information to the first core network function, where the third key information is based on the first key information and the first key information 2. Verification key generation, the second verification key is generated based on a network user key, or a third verification key is decrypted, the third verification key is received from the first core network function; or,
[0021] The second derivative information from the first core network function is received, and a second verification key is sent to the first core network function, where the second verification key is based on the second derivative information and the network user secret Key generation; or,
[0022] Sending the first derivative information to the first core network function, and sending a second verification key to the first core network function, the second verification key being based on the first derivative information and the network user secret Key generation
[0023] The network user key is a backup of the user key on the second core network function side.
[0024] In order to solve the above technical problem, an embodiment of the present invention also provides a mobile terminal, including:
[0025] The first receiving module is used to receive the third key information sent by the mobile network side; the third key information
The information is obtained by the mobile network side encrypting the first key information based on the second verification key; the second verification key is generated by the mobile network side based on the network user key or generated by the mobile network side Obtained based on the result of decrypting the third verification key; the third verification key is obtained by the mobile terminal based on the result of encrypting the second verification key, and sent to the mobile network side;
[0026] The first key generation module is configured to generate the first key information based on the result of using the first verification key or the second verification key to decrypt the third key information, the first The verification key is generated by the mobile terminal based on the terminal user key, wherein the network user key is a backup of the user key on the mobile network side, and the terminal user key is the user key in the Backup of mobile terminal.
[0027] In order to solve the above technical problems, an embodiment of the present invention also provides a key issuing device, including:
[0028] The first invocation module is used to receive the first invocation from the terminal device on the mobile terminal side and return the result of the first invocation; the result of the first invocation does not include the first verification key , Or the result of the first call includes second derived information, or the result of the first call includes a third verification key; wherein the first verification key is generated based on the end user key, and the second The derived information is used to generate a first verification key together with the terminal user key, the third verification key is obtained based on the result of encrypting the second verification key, and the end user key is the user key in the The backup on the security function of the mobile terminal side;
[0029] The second call module is used to receive a second call from the terminal device on the mobile terminal side and return the result of the second call; the second call includes third key information, the The result of the second call does not include the first key information; wherein the first key information is based on the result of decrypting the third key information using the first verification key or the second verification key generate.
[0030] In order to solve the above technical problems, an embodiment of the present invention also provides a mobile terminal, including:
[0031] The second receiving module is used to receive the third key information from the mobile network side and initiate a second call to the key issuing device, the second call containing the third key information;
[0032] The third key information is obtained by the mobile network side encrypting the first key information based on the second verification key, and the second verification key is the mobile network side based on the network user key Or the second verification key is obtained by the mobile network side based on the result of decrypting the third verification key, the third verification key is sent by the mobile terminal to the mobile network side, and the network The user key is a backup of the user key on the mobile network side.
[0033] In order to solve the above technical problems, an embodiment of the present invention also provides a communication device, including:
[0034] The first sending module is used to send the third key information to the mobile terminal; or, to send the first key information to the second core network function;
[0035] The third receiving module is used to receive the third key information sent from the second core network function, and send the third key information to the mobile terminal;
[0036] Wherein, the third key information is generated based on the second verification key and the first key information; the second verification key is generated by decrypting the third verification key, or is generated by the second core The network function is generated based on the network user key; the third verification key is received from the mobile terminal, and the network user key is a backup of the user key on the second core network function side.
[0037] In order to solve the above technical problem, an embodiment of the present invention also provides a communication device, including: a fourth receiving module and a second sending module;
[0038] The fourth receiving module is used to receive the first key information from the first core network function, and the second sending module is used to send the third key information to the first core network function, so The third key information is based on the first key
Key information and a second verification key, the second verification key is generated based on a network user key, or a third verification key is decrypted, the third verification key is received from the first core network function ;or,
[0039] The fourth receiving module is configured to receive second derivative information from the first core network function, and the second sending module is configured to send a second verification key to the first core network function, and the The second verification key is generated based on the second derived information and the network user key; or,
[0040] The second sending module is configured to send the first derivative information to the first core network function, and the second sending module sends a second verification key to the first core network function, and the second The verification key is generated based on the first derivative information and a network user key, and the network user key is a backup of the user key on the second core network function side.
[0041] In order to solve the above technical problems, an embodiment of the present invention also provides a communication device, including a processor, a memory, a communication unit, and a communication bus;
[0042] The communication bus is used to implement a wireless communication connection between the processor, the communication unit, and the memory;
[0043] A communication device, which is characterized by comprising: a processor, a memory, a communication unit, and a communication bus;
[0044] The communication bus is used to implement a wireless communication connection between the processor, the communication unit, and the memory;
[0045] The processor is configured to execute one or more first programs stored in the memory to implement the steps of the key issuance method as described above;
[0046] The processor is configured to execute one or more second programs stored in the memory to implement the steps of the key issuance method as described above;
[0047] The processor is used to execute one or more third programs stored in the memory to implement the steps of the key issuing method as described above
[0048] The processor is configured to execute one or more fourth programs stored in the memory to implement the steps of the key issuance method as described above;
[0049] The processor is configured to execute one or more fifth programs stored in the memory to implement the steps of the key issuance method as described above.
[0050] In order to solve the above technical problems, embodiments of the present invention also provide a computer-readable storage medium, and the computer-readable storage medium stores one or more first computer programs, second computer programs, and third computer programs. A program, a fourth computer program, and a second computer program, the one or more first computer programs may be executed by one or more processors to implement the steps of the key issuing method as described above;
[0051] The one or more second computer programs may be executed by one or more processors to implement the steps of the key issuance method as described above;
[0052] The one or more third computer programs may be executed by one or more processors to implement the steps of the key issuance method as described above
[0053] The one or more fourth computer programs may be executed by one or more processors to implement the steps of the key issuance method as described above;
[0054] The one or more fifth computer programs may be executed by one or more processors to implement the steps of the key issuance method as described above.
[0055] The beneficial effects of the present invention are:
[0056] A key issuing method and device, mobile terminal, communication equipment, and computer provided according to an embodiment of the present invention
A readable storage medium, the method extracts the authentication information and the user key according to the received authentication schedule, generates the first authentication key according to the key generation rule, and returns an authentication response message to the mobile network side, and the mobile network side is in After receiving the authentication response message, it also obtains the corresponding authentication information and user key to generate a second verification key, encrypts the first key information, obtains the third key and returns it to the mobile terminal, and the mobile terminal verifies according to the first The key decrypts the third key information to obtain the first key information. Based on this mutual way, the key is issued to ensure the security of the mobile terminal when accessing the mobile network, and also to ensure The key is updated in real time, the tampering of the key is reduced, the security is further improved, and the security performance of the system is greatly improved.
[0057] Other features and corresponding beneficial effects of the present invention are described in the following part, and it should be understood that at least part of the beneficial effects will become apparent from the description in the present invention.
Description of the drawings
[0058] FIG. 1 is a flowchart of a method for issuing a key according to Embodiment 1 of the present invention;
[0059] FIG. 2 is another flowchart of the key issuing method provided by the second embodiment of the present invention;
[0060] FIG. 3 is a schematic diagram of a first structure of a mobile terminal according to Embodiment 3 of the present invention;
[0061] FIG. 4 is a schematic diagram of a second structure of a mobile terminal according to Embodiment 3 of the present invention;
[0062] FIG. 5 is a schematic diagram of a third structure of a mobile terminal according to Embodiment 3 of the present invention;
[0063] FIG. 6 is a schematic diagram of the first structure of a communication device according to Embodiment 4 of the present invention;
[0064] FIG. 7 is a schematic diagram of a second structure of a communication device according to Embodiment 4 of the present invention;
[0065] FIG. 8 is a schematic diagram of a third structure of a communication device according to Embodiment 4 of the present invention;
[0066] FIG. 9 is a schematic structural diagram of a communication system provided by Embodiment 5 of the present invention;
[0067] FIG. 10 is a schematic diagram of a key distribution architecture of a mobile terminal according to an embodiment of the present invention;
[0068] FIG. 11 is a schematic diagram of a mobile terminal key issuance process provided by the sixth embodiment of the present invention;
[0069] FIG. 12 is a schematic diagram of a mobile terminal key issuance process according to Embodiment 7 of the present invention;
[0070] FIG. 13 is a schematic diagram of a key issuance process for a mobile terminal according to Embodiment 8 of the present invention;
[0071] FIG. 14 is a schematic diagram of a mobile terminal key issuance process provided by the ninth embodiment of the present invention;
[0072] FIG. 15 is a schematic diagram of a key issuance process of a mobile terminal according to the tenth embodiment of the present invention;
[0073] FIG. 16 is a schematic diagram of a key issuance process for a mobile terminal according to the eleventh embodiment of the present invention;
[0074] FIG. 17 is a schematic diagram of a key update process of a mobile terminal according to the twelfth embodiment of the present invention.
Detailed ways
[0075] In order to make the objectives, technical solutions, and advantages of the present invention clearer, the following describes the embodiments of the present invention in further detail through specific implementations in conjunction with the accompanying drawings. It should be understood that the specific embodiments described here are only used to explain the present invention, but not to limit the present invention.
[0076] Embodiment One:
[0077] Please refer to FIG. 1 for the key issuance method provided in this embodiment. The method is mainly applied to a mobile terminal. The specific implementation steps are as follows:
[0078] S11, extract the authentication information and the user key according to the received authentication schedule.
[0079] In practical applications, the authentication information includes at least one of a random character string RAND, an authentication parameter AUTN, a challenge response RES, and a session key, and may even be a secret key directly generated by the mobile terminal. The user key is
It is stored on the mobile terminal, base station and mobile network at the same time.
[0080] S12: Generate a first verification key according to the authentication information and the user key.
[0081] In this step, it is also necessary to combine a certain algorithm to calculate. Preferably, the algorithm can be a calculation algorithm of some keys or some encryption algorithms. Specifically, the authentication information and user password are used as input Parameters, the first verification key is generated according to the key generation rule.
[0082] Further, after the first verification key is generated, it is convenient to realize the key correspondence between the mobile terminal and the mobile network side, and it is also necessary to return an authentication response message to the mobile network side.
[0083] In practical applications, the response message may be at least one of an authentication request, a key provision request, and a challenge response, and different messages will carry different information, which can be used and provided according to actual conditions.
[0084] S13. Receive the third key information sent by the mobile network side.
[0085] The third key information is a second verification key pair generated by the mobile network side according to the authentication response message and the key generation rule and stored in the first core network on the mobile network side After the first key information is encrypted, the obtained key information.
[0086] In this embodiment, after receiving the authentication response message on the mobile network side, the authentication information and the user key are obtained as input parameters, and the second authentication key is generated by combining the same key generation rules as the mobile terminal. The second verification key and the first key information generate corresponding third key information. The generation process can be a key generation process or an encryption process, where the key is the second verification key. key.
[0087] S14. Decrypt the third key information according to the first verification key to obtain first key information.
[0088] In this embodiment, a verification key is not always valid, and may be updated under certain circumstances or special conditions, that is, the third verification key is paired with the third verification key according to the first verification key. After the key information is decrypted and the first key information is obtained, it also includes:
[0089] storing the first key information in the mobile terminal, and setting a key update time;
[0090] When it is detected that the key update time is reached, a key update step is performed to obtain new first key information from the mobile network side.
[0091] In this embodiment, the authentication information for generating the first verification key or the second verification key can be specifically obtained in two ways, one is generated by the mobile terminal itself, and then sent to the mobile network. The device on the side; the other is generated by the device on the mobile network, and then returned to the mobile terminal.
[0092] In this embodiment, if the authentication information is generated by the mobile network side, the method further includes:
[0093] The mobile terminal side sends a key provision request to the mobile network side; the key provision request carries indication information indicating that the verification key is obtained, and the key provision request is used to control the The mobile network side generates authentication information, the authentication information includes at least a random character string RAND, an authentication parameter AUTN, a challenge response, and a session key; [0094] The extraction of authentication information according to the received authentication schedule includes:
[0095] receiving the authentication request returned by the mobile network side according to the key provision request;
[0096] Extract the authentication information carried in the authentication request, where the authentication information includes a random character string RAND, an authentication parameter AUTN, a challenge response RES, and a session key.
[0097] In this embodiment, the generating a first verification key according to the authentication information and the user key according to the key generation rule, and returning an authentication response message to the mobile network side includes:
[0098] With a random character string RAND as an input parameter, a first protection key and a challenge response are generated according to the user key and the random character string according to the key generation rule;
[0099] The challenge response is carried in an authentication response message and sent to the mobile network side.
[0100] Further, after the mobile network side encrypts the first key information according to the second verification key generated by the authentication response message and the key generation rule, the obtained key information includes:
[0101] The mobile network side obtains the first key information from the first core network;
[0102] Generate a second protection key according to the random character string in the authentication information and the user key;
[0103] Generate third key information based on the second protection key and the first key information.
[0104] The decrypting the third key information according to the first verification key to obtain the first key information includes: decrypting the third key information according to the first protection password, Obtain the first key information.
[0105] In this embodiment, if the authentication information is generated by the mobile terminal, extracting the authentication information according to the received authentication schedule includes:
[0106] According to the network access request initiated by the mobile terminal itself;
[0107] Generate authentication information based on the access network request, and the authentication information includes a random character string RAND, or a secret key.
[0108] When the mobile terminal is generated based on the authentication information, if the random string RAND is generated based on the access network request, the first verification is generated according to the authentication information and the user key according to the key generation rule Key, and returning an authentication response message to the mobile network side includes:
[0109] Taking a random character string as an input parameter, and generating a first protection key according to the user key and the random character string according to the key generation rule;
[0110] The mobile terminal sends a key provision request to the mobile network side, and the key provision request carries the random character string;
[0111] If the secret key is generated based on the access network request, the first verification key is generated according to the authentication information and the user key according to the key generation rule, and sent to the mobile network side Returning the authentication response message includes: [0112] Encrypting the secret key based on the preset public key to obtain the transmission key;
[0113] The transmission key is carried in a key provision request and sent to the mobile network side, and the key provision request is used as the authentication response message.
[0114] In this embodiment, if the mobile terminal generates the first protection key according to the user key and the random character string according to the key generation rule, the first protection key received by the mobile terminal The three-key information is the key obtained after the mobile network side encrypts the first key information according to the random character string sent by the mobile terminal and the second protection key generated by the key generation rule information.
[0115] If the mobile terminal generates the transmission key according to the authentication information and the user key according to the key generation rule, the mobile network side generates the transmission key according to the authentication response message and the key generation rule After the first key information is encrypted by the second verification key, the obtained key information includes:
[0116] The mobile network side decrypts the transmission key through the private key corresponding to the public key to obtain the secret key;
[0117] The first key information is encrypted based on the secret key to obtain the third key information.
[0118] In practical applications, the mobile terminal is also divided into security function and terminal equipment function modules, where the security function refers to the UIM card, SIM card and other telephone cards, and the terminal equipment can be understood as the current For communication mobile phones and the like, the specific implementation of the key issuance method on the security function is as follows:
[0119] The security function receives the first call from the terminal device on the mobile terminal side, and returns the first call
The result; the result of the first call does not contain the first verification key, or the result of the first call contains the second derived information, or the result of the first call contains the third verification key; where The first verification key is generated based on the end user key, the second derivative information is used to generate the first verification key together with the end user key, and the third verification key is based on the encryption of the second verification key. The result of the key is obtained, the terminal user key is the backup of the user key on the security function of the mobile terminal side; the second call from the terminal device on the mobile terminal side is received, and the second call is returned. The result of the call; the second call contains the third key information, and the result of the second call does not contain the first key information; wherein the first key information is based on the use of the first verification key Or the second verification key is generated as a result of decrypting the third key information.
[0120] Wherein the result of the first call contains the first derivative information and the second derivative information, and when the first derivative information is contained, the first verification key is based on the end user key and the first derivative information. Derived information is generated. The first derivative information here is sent by the terminal device to the USIM, which may be generated by the terminal device or sent from the network when it is received.
[0121] If the result of the first call includes second derivative information, the first verification key is generated based on the end user key and the second derivative information.
[0122] The third verification key is obtained based on the result of encrypting the second verification key with the secret key, and the secret key is a public key on the mobile network side or a symmetric key shared with the mobile network side.
[0123] In this embodiment, the security function is also used to store network information corresponding to the first key information.
[0124] The key issuance method in the security function also includes receiving a third call from the terminal device; the input parameters of the third call include verification information and part or all of the third key information, or the The input parameters of the third call include verification information and calculation results generated based on part or all of the third key information;
[0125] The security function returns the result of the third call, and the result of the third call includes using the first verification key or the second verification key to verify the verification based on the input parameter The result of the information;
[0126] Wherein, the third key information is used to use the first verification key or the second verification key to decrypt the third key information to generate first key information.
[0127] For the key issuance method implemented on the terminal device, the specific implementation steps are as follows:
[0128] The terminal device receives third key information from the mobile network side, and initiates a second call to the security function, where the second call includes the third key information;
[0129] The third key information is obtained by encrypting the first key information by the mobile network side according to a second verification key, and the second verification key is generated by the mobile network side based on a network user key, Or the second verification key is obtained by decrypting the third verification key by the mobile network side, and the third verification key is sent by the mobile terminal to the mobile network side.
[0130] Further, the terminal device is further configured to initiate a first call to a security function, and receive a result of the first call, and the result of the first call includes the third verification key.
[0131] Further, the terminal device is also used to initiate a third call to the security function, and the input parameters of the third call include verification information and part or all of the third key information, or the first 3. The input parameters of the call include verification information and calculation results generated based on part or all of the third key information;
[0132] receiving a verification result returned by the security function, where the verification result is a result of verifying the verification information based on the input parameter using the first verification key or the second verification key.
[0133] In this embodiment, the terminal device is also used to initiate a first call to the security function, and receive the first call
As a result, the first call contains first derived information, and the first derived information is used to generate a first verification key together with the terminal user key, which is generated by the terminal device, or received from the mobile On the network side, the first verification key is used to decrypt the third key information.
[0134] In this embodiment, the terminal device is further configured to send the first derivative information to the mobile network side, and the first derivative information is used to generate a first verification key together with the terminal user key , And generated by the terminal device, and the first verification key is used to decrypt the third key information.
[0135] In this embodiment, the terminal device is also used to initiate a first call to the security function, and receive a result of the first call, and the result of the first call includes second derivative information, and the second The derivative information is used to generate a first verification key together with the terminal user key, the first verification key is used to decrypt the third key information; and the second derivative information is sent to the mobile network side.
[0136] In this embodiment, the key issuance method on the terminal device is specifically implemented as follows:
[0137] receiving third key information from the mobile network side, and initiating a second call to the security function of the mobile terminal side, where the second call includes the third key information;
[0138] The third key information is obtained by the mobile network side encrypting the first key information based on the second verification key, and the second verification key is the mobile network side based on the network user key Or the second verification key is obtained by the mobile network side based on the result of decrypting the third verification key, the third verification key is sent by the mobile terminal to the mobile network side, and the network The user key is a backup of the user key on the mobile network side.
[0139] In this embodiment, the method further includes:
[0140] A first call is initiated to the security function on the mobile terminal side, and a result of the first call is received, and the result of the first call includes the third verification key.
[0141] In this embodiment, the method further includes:
[0142] A third call is initiated to the security function on the mobile terminal side, and the input parameters of the third call include verification information and part or all of the third key information, or the input parameters of the third call include Verification information and calculation results generated based on part or all of the third key information;
[0143] Receive the verification result returned by the security function of the mobile terminal, where the verification result is the verification of the verification information based on the input parameter using the first verification key or the second verification key result.
[0144] In this embodiment, the method further includes:
[0145] Initiate a first call to the security function on the mobile terminal side, and receive the result of the first call. The first call includes first derivative information, and the first derivative information is used to communicate with the terminal user key. The first verification key is generated together, and is generated by the terminal device on the mobile terminal side, or received from the mobile network side, the first verification key is used to decrypt the third key information, the terminal The user key is a backup of the user key on the mobile terminal side.
[0146] In this embodiment, the method further includes:
[0147] Send the first derivative information to the mobile network side.
[0148] Further, the method further includes:
[0149] Initiate a first call to the security function on the mobile terminal side, and receive the result of the first call. The result of the first call includes second derivative information, and the second derivative information is used to communicate with the terminal user. The keys together generate a first verification key, the first verification key is used to decrypt the third key information, and the terminal user key is a backup of the user key on the mobile terminal side;
[0150] Send the second derivative information to the mobile network side.
[0151] In summary, the key issuance method provided in this embodiment extracts the authentication information and the user key according to the received authentication schedule, generates the first verification key according to the key generation rules, and moves to the The network side returns an authentication response message. After receiving the authentication response message, the mobile network side also obtains the corresponding authentication information and the user key to generate the second authentication key, and encrypts the first key information to obtain the third key and Return to the mobile terminal, and the mobile terminal decrypts the third key information according to the first verification key to obtain the first key information. Based on this mutual method, the key is issued to ensure that the mobile terminal is accessing The security issue of mobile network also guarantees the real-time update of the key, reduces the tampering of the key, further improves the security, and greatly improves the security performance of the system.
[0152] The second embodiment:
[0153] Please refer to FIG. 2 for the key issuance method provided in this embodiment. The method is mainly applied to one end of a mobile network. The mobile network side includes a first core network and a second core network. The specific implementation steps are as follows :
[0154] S21: Receive a key provision request from the mobile terminal side.
[0155] S22. According to the key provision request and the user key, a second verification key is generated according to a key generation rule.
[0156] S23, encrypting the first key information stored in the first core network on the mobile network side based on the second verification key to obtain third key information.
[0157] S24. Return the third key information to the mobile terminal.
[0158] In this embodiment, the authentication information for generating the second verification key can be specifically obtained in two ways, one is generated by the mobile terminal and then sent to the device on the mobile network side; the other It is generated by the device on the mobile network itself, and then returned to the mobile terminal.
[0159] If it is generated by the mobile network itself, the second verification key generated according to the key provision request and the user key according to the key generation rule includes:
[0160] extract the instruction information used to instruct to obtain the verification key carried in the key provision request;
[0161] Generate authentication information according to the instruction information, where the authentication information includes a random character string RAND;
[0162] A second verification key generated according to the key generation rule based on the random character string and the user key.
[0163] Further, after the authentication information is generated according to the instruction information, the method further includes:
[0164] sending an authentication request carrying the authentication information to the mobile terminal; and receiving an authentication response message returned from the mobile terminal based on the authentication request.
[0165] In practical applications, since the mobile network itself can have two situations, one is to include two core networks at the same time, that is, the first core network and the second core network, and the other is to include only the first core. When the network includes two core networks, and the second verification key is a protection key, the first password stored in the first core network on the mobile network side is based on the second verification key. The key information is encrypted, and the obtained third key information includes:
[0166] The first core network encrypts the first key information according to the second protection key generated by the second core network based on the random character string and the user key to obtain the third key. Key information
[0167] Or,
[0168] When receiving the authentication response message, the first core network obtains the first key information and sends it to the second core network; the second core network obtains the first key information according to the second protection key pair The first key information is encrypted to obtain the third key information.
[0169] In this embodiment, the first key information can specifically exist in two forms, one is to directly exist as the first key information, and the form is stored on the first core network, and the other is Is stored in the form of the second key information
While this form is stored on the base station, the second key information is generated based on the first key information. When the first core network cannot obtain direct first key information, it will choose to pass Another type of key information generation, that is, the key issuance method also includes:
[0170] When the first core network cannot obtain the first password information, obtain second key information from the base station side, and generate a second protection key according to the random character string and the user key, Generate third key information based on the second protection key and the second key information; the second key information is associated with the first key information, and the first key information and Common parameter generation of the base station.
[0171] In this embodiment, when the authentication information is generated by the mobile terminal, the authentication information will be carried in the request sent by the mobile terminal and sent, that is, the key provision request and The user key, the second verification key generated according to the key generation rule includes:
[0172] Extract the authentication information carried in the key provision request; the authentication information is generated by the mobile terminal and includes at least a random character string RAND;
[0173] Based on the random character string and the user key, the second verification key is generated according to the key generation rule.
[0174] In practical applications, the authentication information sent by the mobile terminal can be a random character string or a secret key. At this time, the authentication information sent by the mobile terminal is based on the secret generated by the mobile terminal. The transmission key generated by the key.
[0175] After receiving the authentication information on the mobile network side, a second verification key is generated according to the received information, and the second verification key may be a protection key or a secret key.
[0176] If the second verification key is a secret key, the first key information stored in the first core network on the mobile network side is encrypted based on the second verification key, The obtained third key information includes:
[0177] The first core network receives the secret key generated by the second core network based on the random character string and the user key, and encrypts the first key information according to the secret key to obtain the secret key. The third key information.
[0178] At this time, the second verification key generated in accordance with the key generation rule according to the key provision request and the user key includes:
[0179] The first core network extracts the transmission key carried in the key provision request; the transmission key is obtained by the mobile terminal encrypting the secret key of the mobile terminal based on a preset public key;
[0180] decrypting the transmission key by the private key corresponding to the public key to obtain the secret key of the mobile terminal;
[0181] The first key information stored in the first core network on the mobile network side is encrypted based on the second verification key, and the obtained third key information includes: according to the mobile terminal Encrypting the first key information with a secret key to obtain the third key information.
[0182] In this embodiment, from the perspective of security, there will still be updates and modifications to the second verification key, that is, after the third key information is returned to the mobile terminal, The method also includes:
[0183] detecting whether there is an update of the first key information;
[0184] If it exists, resend the third key information to the mobile terminal;
[0185] Wherein, the third key information is generated based on the second verification key and the updated first key information, or the third key information is based on the secret key of the mobile terminal and The updated first key information is generated.
[0186] In this embodiment, when the key issuance method is implemented on the first core network function on the mobile network side, the details are as follows:
[0187] Send the third key information to the mobile terminal; or,
[0188] sending the first key information to the second core network function, receiving the third key information sent from the second core network function, and sending the third key information to the mobile terminal;
[0189] Wherein, the third key information is generated based on the second verification key and the first key information; the second verification key is generated by decrypting the third verification key, or is generated by the second core The network function is generated based on the network user key; the third verification key is received from the mobile terminal, and the network user key is a backup of the user key on the second core network function side.
[0190] Further, when interacting with the second core network function, it further includes sending a key request to the second core network function; [0191] receiving the second verification key from the second core network function.
[0192] In this embodiment, the key request includes third derivative information; the third derivative information is received from the mobile terminal and used to generate the second verification key together with the network user key. The third derivative information includes the aforementioned second derivative information + part or all of the first derivative information (generated by the terminal).
[0193] Further, the key request further includes the third verification key, and the third verification key is received from the mobile terminal.
[0194] Further, when the mobile terminal interacts, the method further includes: sending first derivative information to the mobile terminal; the first derivative information is received from the second core network function and used to communicate with the network-side user key The second verification key is generated together.
[0195] Further, verification information may also be sent to the mobile terminal;
[0196] Wherein, the verification information is generated based on the second verification key and part or all of the third key information; or generated based on the second verification key and the first calculation result, the first A calculation result is generated based on part or all of the third key information; or generated based on the second verification key and part or all of the first key information; or based on the second verification key and the second verification key. The calculation result is generated, and the second calculation result is generated based on part or all of the first key information.
[0197] For the implementation on the second core network function, it is specifically: receiving the first key information from the first core network function, and sending the third key information to the first core network function, the first The three-key information is generated based on the first key information and the second verification key, the second verification key is generated based on the network user key, or the third verification key is decrypted, the third verification key The key is received from the first core network function; or,
[0198] After receiving the second derivative information from the first core network function, send a second verification key to the first core network function, where the second verification key is based on the second derivative information and the network user secret Key generation; or,
[0199] Sending the first derivative information to the first core network function, and sending a second verification key to the first core network function, the second verification key being based on the first derivative information and the network user secret Key generation
[0200] The network user key is a backup of the user key on the second core network function side.
[0201] Further, the second verification key is generated based on decrypting a third verification key, and the third verification key is received from the first core network function.
[0202] In summary, the key issuance method provided in this embodiment extracts the authentication information and the user key according to the received authentication schedule, generates the first verification key according to the key generation rule, and moves to the The network side returns an authentication response message. After receiving the authentication response message, the mobile network side also obtains the corresponding authentication information and the user key to generate the second authentication key, and encrypts the first key information to obtain the third key and Return to the mobile terminal, and the mobile terminal decrypts the third key information according to the first verification key to obtain the first key information, which is implemented based on this mutual method
The issuance of the key ensures the security of the mobile terminal when it accesses the mobile network, and also ensures the real-time update of the key, reduces the tampering of the key, further improves the security, and greatly improves the security of the system. performance.
[0203] Embodiment Three:
[0204] This embodiment provides a mobile terminal. As shown in FIG. 3, the mobile terminal includes a calling module 31, a first key generation module 32, a first communication module 33, and a decryption module 34, wherein
[0205] The calling module 31 is used to extract the authentication information and the user key according to the received authentication schedule;
[0206] The first key generation layer module 32 is configured to generate a first verification key according to the authentication information and the user key according to the key generation rule;
[0207] The first communication module 33 is configured to return an authentication response message to the mobile network side; and to receive third key information sent by the mobile network side, where the third key information is the mobile network side Key information obtained after encrypting the first key information stored in the first core network on the mobile network side by a second verification key generated according to the authentication response message and the key generation rule;
[0208] The decryption module 34 is configured to decrypt the third key information according to the first verification key to obtain first key information.
[0209] In this embodiment, the calling module 31, the first key generation module 32, the first communication module 33, and the decryption module 34 are also used to implement the steps of the key issuance method provided in the first embodiment above. Refer to the description of the above-mentioned embodiments for the specific implementation process of each step of the function, and will not be repeated here.
[0210] Further, the embodiment of the present invention also provides another structure of a mobile terminal. As shown in FIG. 4, the mobile terminal includes a security function module 41 and a terminal device module 42, wherein,
[0211] The terminal device module 42 sends an authentication schedule to the security function module 41;
[0212] The security function module 41 extracts the authentication information and the user key according to the received authentication schedule; according to the authentication information and the user key, generates a first authentication key according to the key generation rule, and moves to the The network side returns an authentication response message;
[0213] The terminal device module 42 receives the third key information sent by the mobile network side, and sends it to the security function module 41, and the third key information is the mobile network side according to the The authentication response message and the second verification key generated by the key generation rule encrypt the first key information stored in the first core network on the mobile network side, and the key information obtained;
[0214] The security function module 41 decrypts the third key information according to the first verification key to obtain first key information.
[0215] In this embodiment, the security function module 41 and the terminal device module 42 are also used to implement the functions of each step of the key issuance method provided in the first embodiment. For the specific implementation process of each step, refer to the above The description of the embodiment will not be repeated here.
[0216] In this practical application, the security function module 41 is specifically used to receive a call from a terminal device, the call uses at least a random character string RAND as an input parameter, and generates protection based on the user key and the random character string. key and the challenge response, and returns the call, returns the information contained in the returned response to the challenge, does not include the protection key; or, [0217] received from the calling terminal device, returns a random string RAND, The RAND is used to generate a protection key together with the user key; or,
[0218] After receiving the call from the terminal device, it returns a random string transmission key, which is generated based on the secret key and the public key.
[0219] Further, the security function module 41 is also used to receive a call from a terminal device, and the input parameter of the call includes part or all of the third key information;
[0220] Generate a first key according to the protection key and the input parameters; or,
[0221] Generate a second key according to the protection key and the input parameters; or,
[0222] A first key is generated according to the protection key and the input parameters, and then a second key is generated based on the first key.
[0223] Further, the security function module 41 is further configured to generate a fourth key according to the secret key and the first key or the second key;
[0224] Return the fourth key to the terminal device.
[0225] Further, the security function module 41 is also used to store the first key, or store the second key, and store corresponding to the first key or the second key Network information.
[0226] Further, before returning the RAND, the security function module 41 is also used to generate the RAND or read the stored RAND;
[0227] Generate a protection key based on the RAN D and the user key.
[0228] Further, before returning the transmission key, the security function module 41 is also used to generate the secret key or read the stored secret key;
[0229] The transmission key is generated based on the secret key and the public key.
[0230] In practical applications, the terminal device module 42 is specifically configured to receive a message from a mobile network that carries the third key information;
[0231] storing the third key information, or calling a security function, and the input parameter of the call includes part or all of the third key information;
[0232] Wherein, the third key information is generated based on the protection key and the first key information or the second key information, or the third key information is based on the secret key and the first key information or the second key information. 2. Key information generation;
[0233] Wherein, the protection key is generated based on a user key, the second key information is generated based on the first key information or matched with the first key information, and the secret key is generated by The safety function is generated or stored in the safety function.
[0234] Further, the terminal device 42 is also configured to receive fourth key information returned by the security function, where the fourth key information is based on the secret key and the first key information or the first key information. Two key information generation.
[0235] Further, before receiving the message carrying the third key information from the mobile network, the terminal device 42 is further configured to send a key provision request to the mobile network, and the key provision The request carries indication information, and the indication information indicates initialization or update.
[0236] Further, the terminal device 42 is also used to store network information corresponding to the third key.
[0237] Further, the terminal device 42 is also used to send a random character string RAND to the mobile network, and the
RAND is received from the security function and used to generate the protection key together with the user key; or,
[0238] Send a transmission key to the mobile network, the transmission key received from a security function.
[0239] Further, the embodiment of the present invention also provides another structure of a mobile terminal. As shown in FIG. 5, the mobile terminal includes: a first processor 51, a first memory 52, a first communication unit 53, and The first communication bus 54;
[0240] The first communication bus 54 is used to implement a wireless communication connection between the first processor 51, the first communication unit 53, and the first memory 52;
[0241] The first processor 51 is configured to execute one or more first programs stored in the first memory 52 to implement the steps of the key issuance method provided in the first embodiment above, and the specific implementation process of each step With reference to the description of the foregoing embodiments, the details will not be repeated here.
[0242] In this embodiment, the structure of the mobile terminal may also be implemented by the first receiving module and the first key generating module, specifically:
[0243] The first receiving module is configured to receive the third key information sent by the mobile network side; the third key information is the method used by the mobile network side to encrypt the first key information based on the second verification key The result is obtained; the second verification key is generated by the mobile network side based on the network user key or obtained by the mobile network side based on the result of decrypting the third verification key; the third verification key is obtained by the The mobile terminal is obtained based on the result of encrypting the second verification key, and sent to the mobile network side;
[0244] The first key generation module is configured to generate the first key information based on the result of using the first verification key or the second verification key to decrypt the third key information, the first The verification key is generated by the mobile terminal based on the terminal user key, wherein the network user key is a backup of the user key on the mobile network side, and the terminal user key is the user key in the Backup of mobile terminal.
[0245] Further, the structure of the mobile terminal may also include a second receiving module, where the second receiving module is configured to receive the third key information from the mobile network side and initiate a second call to the key issuing device, The second call includes the third key information;
[0246] The third key information is obtained by encrypting the first key information by the mobile network side according to a second verification key, and the second verification key is generated by the mobile network side based on a network user key, Or the second verification key is obtained by decrypting the third verification key by the mobile network side, and the third verification key is sent by the mobile terminal to the mobile network side.
[0247] In this embodiment, a key issuance device may also be provided in the mobile terminal in a manner, and the key issuance device includes:
[0248] The first invocation module is configured to receive the first invocation from the terminal device on the mobile terminal side and return the result of the first invocation; the result of the first invocation does not include the first verification key , Or the result of the first call includes second derived information, or the result of the first call includes a third verification key; wherein the first verification key is generated based on the end user key, and the second The derived information is used to generate the first verification key together with the terminal user key, the third verification key is obtained based on the result of encrypting the second verification key, and the end user key is the user key in the The backup on the security function of the mobile terminal side;
[0249] The second invocation module is configured to receive a second invocation from the terminal device on the mobile terminal side and return the result of the second invocation; the second invocation includes third key information, and The result of the second call does not include the first key information; wherein the first key information is based on the result of decrypting the third key information using the first verification key or the second verification key generate.
[0250] In this embodiment, it may also be a mobile terminal, including:
[0251] The second receiving module is configured to receive third key information from the mobile network side and initiate a second call to the key issuing device, where the second call includes the third key information;
[0252] The third key information is obtained by the mobile network side encrypting the first key information based on the second verification key, and the second verification key is the mobile network side based on the network user key Or the second verification key is obtained by the mobile network side based on the result of decrypting the third verification key, and the third verification key is obtained by the mobile terminal
The terminal sends to the mobile network side, and the network user key is a backup of the user key on the mobile network side.
[0253] Embodiment Four:
[0254] This embodiment provides a communication device. As shown in FIG. 6, the communication device includes a second communication module 61, a second key generation module 62, and an encryption module 63, where
[0255] The second communication module 61 is configured to receive a key provision request from the mobile terminal side;
[0256] The second key generation module 62 is configured to generate a second verification key according to the key generation rule according to the key provision request and the user key;
[0257] The encryption module 63 is configured to encrypt the first key information stored in the first core network on the mobile network side based on the second verification key to obtain third key information;
[0258] The second communication module 61 is further configured to return the third key information to the mobile terminal.
[0259] In this embodiment, the second communication module 61, the second key generation module 62, and the encryption module 63 are also used to implement the functions of each step of the key issuance method provided in the second embodiment above. For the specific implementation process of the steps, refer to the description of the foregoing embodiments, which will not be repeated here.
[0260] Further, the embodiment of the present invention also provides another structure of a communication device. As shown in FIG. 7, the communication device includes an authentication function module 71, a base station protection function module 72, and an authentication and subscription data management function module 73. , Where [0261] the authentication function module 71 receives a key provision request sent by the mobile terminal;
[0262] The base station protection function module 72 forwards the key provision request to the authentication and subscription data management function module 73;
[0263] The authentication and contract data management function module 73 generates a second verification key in accordance with the key generation rule according to the key provision request and the user key; the second verification key pair is stored in the store based on the second verification key pair. The third key information obtained by encrypting the first key information in the first core network on the mobile network side;
[0264] The authentication function module 71 returns the third key information to the mobile terminal.
[0265] In this embodiment, the authentication function module 71, the base station protection function module 72, and the authentication and subscription data management function module 73 are also used to implement the functions of each step of the key issuance method provided in the second embodiment. For the specific implementation process of each step, refer to the description of the above-mentioned embodiments, which will not be repeated here.
[0266] In this embodiment, the authentication function module 71 and the base station protection function module 72 are combined as one function module.
[0267] In practical applications, for the authentication function module 71, the base station protection function module 72, and the authentication and subscription data management function module 73, when implementing the key issuance method provided in the second embodiment, they can also be implemented in the following sequence of steps: Specifically:
[0268] The authentication function module 71 receives a key provision request sent by the mobile terminal;
[0269] The base station protection function module 72 forwards the key provision request to the authentication and subscription data management function module;
[0270] The authentication and subscription data management function module 73 generates a second verification key according to the key provision request and the user key according to the key generation rule;
[0271] The base station protection function module 72 encrypts the first key information stored in the first core network on the mobile network side based on the second verification key to obtain third key information;
[0272] The authentication function module 71 returns the third key information to the mobile terminal.
[0273] In practical applications, the communication device includes a first core network and a second core network, where
[0274] The specific implementation of the authentication function module 71 and the base station protection function module 72 on the first core network may be as follows:
[0275] Send the third key information to the mobile terminal; or,
[0276] Send the first key information or the second key information to the second core network function, receive the third key information sent from the second core network function, and send the third key information to the mobile terminal;
[0277] Wherein, the third key information is generated based on the protection key and the first key information or the second key information, or the third key information is based on the secret key and the first key information or the second key information. 2. Key information generation;
[0278] Wherein, the protection key is generated based on the user key of the mobile terminal, and the second key information is generated based on the first key information or matched with the first key information, so The secret key is generated by the mobile terminal or stored in the mobile terminal.
[0279] Further, the communication device is further configured to send the third key information to the mobile terminal after receiving the protection key or the secret key;
[0280] Wherein, the third key information is generated according to the protection key and the first key information or the second key information, or the third key information is generated according to the secret key information. The key and the first key information or the second key information are generated.
[0281] The communication device is further configured to send the third key information to the mobile terminal after the first key information or the second key information is updated;
[0282] Wherein, the third key information is generated according to the protection key and the updated first key information or the updated second key information, or, the third key The information is generated according to the secret key and the updated first key information or the updated second key information.
[0283] The communication device is further configured to receive a key provision request from the terminal, and send a second message to the second core network function, the message carrying indication information, and the indication information indicates requesting the protection key or In the secret key, the key provision request passes through the second core network function or does not pass through the second core network function.
[0284] The communication device is also used to send a random character string RAND to the second core network function. The RAND is received from the mobile terminal and used to generate the protection together with the user key of the mobile terminal. Key.
[0285] The communication device is further configured to send a transmission key to the second core network function, where the transmission key is received from the mobile terminal and used to generate the secret key.
[0286] The authentication and subscription data management function module 73 on the second core network is specifically configured to receive a second message carrying instruction information, and send a protection key to the first core network function, where the protection key is based on the user password. Key generation.
[0287] In practical applications, the communication device may also include a third core network. At this time, the communication device is also used to receive a third message that carries the first key information or the second key information, and to The mobile terminal sends third key information, where the third key information is generated based on the protection key and the first key information or the second key information, or the third key information is based on Generating a secret key and the first key information or the second key information;
[0288] Wherein, the protection key is generated based on the user key of the mobile terminal, the secret key is generated by the mobile terminal or stored in the mobile terminal, and the second key information is based on the The first key information is generated or matched with the first key information.
[0289] The communication device is further configured to receive a fourth message requesting an authentication vector, calculate a new random character string RAND' based on the random character string RAND, generate and send a session key based on the RAND', or receive the request The fourth message of the authentication vector, the message carries a random string RAND, and the session key is generated and sent based on the RAND, or the fourth message requesting the authentication vector is received, and the message carries the transmission key, based on the transmission key and The private key generates a secret key and sends it;
[0290] Wherein, the session key is used to generate a protection key, and the protection key or the secret key is used to process the first key information or the second key information to generate the third key information, so The second key information is generated based on the first key information or matched with the first key information.
[0291] Further, the embodiment of the present invention also provides a structure of another communication device. As shown in FIG. 8, the mobile terminal includes: a second processor 81, a second memory 82, a second communication unit 83, and The second communication bus 84;
[0292] The second communication bus 84 is used to implement a wireless communication connection between the second processor 81, the second communication unit 83, and the second memory 82;
[0293] The second processor 81 is configured to execute one or more first programs stored in the second memory 82 to implement the steps of the key issuance method provided in the second embodiment above, and the specific implementation process of each step With reference to the description of the foregoing embodiments, the details will not be repeated here.
[0294] Embodiment Five:
[0295] This embodiment provides a communication device. As shown in FIG. 9, the communication device includes a mobile terminal 91 and a communication device 92, and communication between the mobile terminal 91 and the communication device 92 is established through a base station;
[0296] The mobile terminal 91 sends a key provision request to the communication device 92;
[0297] The communication device 92 generates authentication information according to the key provision request, and returns it to the mobile terminal 91;
[0298] The mobile terminal 91 generates a first verification key according to the key generation rules according to the authentication information and the user key, and returns an authentication response message to the communication device 92;
[0299] After receiving the authentication response message, the communication device 92 stores the second verification key pair generated according to the authentication information, the user key, and the key generation rule in the communication device Encrypting the first key information of, obtain the third key information, and return the third key information to the mobile terminal 91;
[0300] The mobile terminal 91 decrypts the third key information according to the first verification key to obtain first key information.
[0301] In practical applications, each device ternary of the communication system can also implement the key issuance methods provided in the first and second embodiments through the following sequence, that is, the mobile terminal 91 first initiates a request to access the network , And generate authentication information, generate a first authentication key based on the authentication information and the user key, and send the authentication information to the communication device 92;
[0302] The communication device 92 encrypts the first key information stored in the communication device according to the authentication information, the user key, and the second verification key generated by the key generation rule to obtain Third key information, and return the third key information to the mobile terminal 91;
[0303] The mobile terminal 91 decrypts the third key information according to the first verification key to obtain first key information.
[0304] In this embodiment, the mobile terminal 91 and the communication device 92 are also used to implement the functions of each step of the key issuance method provided in the first and second embodiments above. For the specific implementation process of each step, refer to the above The description of the embodiment will not be repeated here.
[0305] In practical applications, the mobile terminal 91 and the communication device 92 may also be specifically implemented by using the mobile terminal and communication equipment provided in the third to fourth embodiments above.
[0306] In this embodiment, a structure of another communication device is also provided, and the communication device includes:
[0307] The first sending module is used to send the third key information to the mobile terminal; or, to send the third key information to the second core network function.
A key information;
[0308] The third receiving module is configured to receive the third key information sent from the second core network function, and send the third key information to the mobile terminal;
[0309] Wherein, the third key information is generated based on the second verification key and the first key information; the second verification key is generated by decrypting the third verification key, or is generated by the second core The network function is generated based on the network user key; the third verification key is received from the mobile terminal, and the network user key is a backup of the user key on the second core network function side.
[0310] In this embodiment, a structure of another communication device is also provided, and the communication device includes:
[0311] The fourth receiving module is configured to receive first key information from a first core network function, and the second sending module is configured to send third key information to the first core network function, so The third key information is generated based on the first key information and the second verification key, the second verification key is generated based on the network user key, or is generated based on the decrypted third verification key, the third The verification key is received from the first core network function; or,
[0312] The fourth receiving module is configured to receive second derivative information from the first core network function, and the second sending module is configured to send a second verification key to the first core network function, and the The second verification key is generated based on the second derived information and the network user key; or,
[0313] The second sending module is configured to send the first derivative information to the first core network function, and the second sending module sends a second verification key to the first core network function, and the second The verification key is generated based on the first derivative information and a network user key, and the network user key is a backup of the user key on the second core network function side.
[0314] Embodiment 6:
[0315] The key issuance method provided by the embodiment of the present invention will be described in detail below in conjunction with specific specific application scenarios, specifically in conjunction with the system structure in FIG. 10, which can be basically divided into the following components: Mobile terminals, base stations and mobile networks, and the mobile network includes a first core network and a second core network.
[0316] FIG. 10 is a schematic diagram of the architecture of the key distribution system equipment of the present invention, including the following functions and interfaces:
[0317] Security function F1: located in the mobile terminal F3, used to interact with the terminal device F2 through the internal device interface S10 of the mobile terminal F3 to obtain and process the protected key information provided by the network, the security function F1 can also prevent the terminal device F2 from obtaining key information. This function can be a software function running on the terminal device F2, or running on a USIM card (Universal Subscriber Identity Module), or a UICC card, which is independent of the terminal device F2 and forms the mobile terminal F3 together with the terminal device F2. In the security hardware;
[0318] Terminal device F2 (equivalent to the processor, communication module and other modules in the mobile terminal): it is the communication, computing, storage and other hardware devices of the mobile terminal F3,
[0319] The terminal device F2 is used to interact with the base station F4 through the air signaling and data interface S1, and interact with the authentication function F5 through the signaling interface S8 to receive various communication services provided by the mobile network. The message is transmitted through the signaling interface S1 and the signaling interface S3,
[0320] The terminal device F2 can also directly interact with the base station protection function F6 through the signaling interface S9 to receive key distribution and maintenance services. The messages on the signaling interface S9 can pass through the signaling interface S8 and the signaling interface S4. transmission;
[0321] Mobile terminal F3: includes a security function F1 and a terminal device F2;
[0322] Base station F4: is the access network software function or hardware device of the mobile network, used to interact with the mobile terminal F3 through the control signaling and the data interface S1 to provide the mobile terminal F1 with communications and other services provided by the mobile network, Such as eNB (4G base station) or gNB (5G base station);
[0323] Authentication function F5: is a software function or hardware device of the core network of the mobile network, used to interact with the base station F4 through the signaling interface S3, so that the mobile network mobile terminal F3 can realize mutual authentication, such as MME (Mobility Management Entity, Network node), or SEAF (Security Anchor Function), or AMF (Access and Mobility Management Function);
[0324] Base Station Protection Function (BSPF) F5: used to interact with the authentication service function F7 through the signaling interface S5 (direct interaction), or to interact with the authentication service through the signaling interfaces S4 and S6 through the authentication function F5 The function F7 interacts (indirect interaction) to obtain the protection information of the protection key information; and sends the protected key information to the mobile terminal F3 through the base station F4 through the signaling interface S2 and the signaling interface S1, or through the authentication function F5 and The base station F4 sends the protected key information to the mobile terminal F3 through the signaling interface S4, the signaling interface S3, and the signaling interface S1; the message on the signaling interface S5 can be transmitted via the signaling interface S4 and the signaling interface S6, The message on the signaling interface S2 can be transmitted via the signaling interface S4 and the signaling interface S3; the base station protection function F6 can be part of the authentication function F5 (that is, the two functions are combined as one function), and there is no signaling at this time Interface S4, signaling interface S2 is equivalent to signaling interface S3, and signaling interface S5 is equivalent to signaling interface S6;
[0325] Authentication service function F7: used to interact with the subscription data management function F8 through the signaling interface S7, obtain key information related to the user, and provide the information to the authentication function F5 through the signaling interface S6, or through a letter The interface S5 is provided to the base station protection function F6, or the authentication function F5 is provided to the base station protection function F6 through the signaling interface S6 and the signaling interface S4. This function can be AUSF (Authentication Server Function), and this function can also be co-located with the contract data management function F8;
[0326] Subscription data management function F8: Store and process user-related data, generate information for authenticating the user and user-related key information based on the user-related data, and provide it to the authentication service function F7 through the signaling interface S7, if If the contract data management function F8 and the authentication service function F7 are co-located, there is no signaling interface S8. The function can be UDM or HSS. [0327] In this embodiment, the process of implementing the key issuance method of the present application based on the hardware structure provided in FIG. 10, the specific process steps are shown in FIG. 11, and the process includes:
[0328] S201: The base station protection function F6 stores first key information. The first key information includes one or more keys, and may also include a key validity period to facilitate key update. The key is the private key of the network, or the symmetric shared key of the network. The base station F4 stores second key information, which is associated with the first key information. For example, when the key in the first key information is one or more private keys, the second key information When the key of is one or more public keys corresponding to these private keys, or the key in the first key information is one or more symmetric shared key information of the network, the secret key in the second key information The key is the same as the key in the first key information, or is derived from the key in the first key information (for example, based on the key in the first key information and a constant string to generate the second key information Key, the commonly used method is to use a hash function such as HMAC-SHA-256), the base station protection function F6 can also store all or part of the second key information (only the key in the second key information, or store All the second key information content). The second key information may also include the key validity period, which is not greater than the key validity period in the first key information (which may be the same).
[0329] S202: Optionally, the mobile terminal F3 sends a key provision request to the authentication function F5, such as sending a Key
The Provisioning Request message or the Registration Request message may carry indication information, which indicates initialization. More specifically, the terminal device F2 may send the request;
[0330] S203: The authentication function F5 receives the key provision request, or the authentication function F5 is triggered by the base station protection function F6 to provide the key to the designated user, and the authentication function F5 sends an authentication request to the authentication service function F7, such as sending an Authentication Request message , The message can carry instruction information, and the instruction information display indicates that protection is needed
Key, the authentication service function F7 requests user authentication information from the subscription data management function F8, including the random character string RAND, authentication parameters AUTN, challenge response, and session key. The request message can carry indication information. The subscription data management function F8 generates RAND, generates AUTN, session key, and expected challenge response XRES based on RAN D.
[0331] In this embodiment, the method for generating the session key and XRES includes:
[0332] Method one, generate the session key and XRES with the user key;
[0333] Manner 2: Based on the derived key of the user key as input, call the key derivation function KDF or hash function to generate the session key and XRES, the session key includes the confidentiality protection key CKp and/or integrity protection The key IKp, KDF function or hash function can be the HMAC-SHA-256 function or other hash (HASH) functions. The input parameters of the function for generating the session key and XRES can also have RAND, AUTN, service network identification, or For other parameters such as the service network name, the parameters for generating XRES include RAND, and the parameters or functions for generating XRES must be different from those for generating session keys. If the subscription data management function F8 receives the instruction information, the generated session key should be different from the session key generated when the instruction information is not received. For example, the generated parameters are not exactly the same except RAND, or the generated function is different, or The RAN D value is increased or decreased by a constant as the RAND input parameter.
[0334] S204: The authentication service function F7 sends an authentication response to the authentication function F5, such as sending Authentication
Response, carries authentication information, such as RAND and AUTN, and can also carry a user key or a derived key, which is derived from the user key.
[0335] S205: The authentication function F5 sends an authentication request to the mobile terminal F3, such as sending User Authentication
Request message. The message carries authentication information, such as RAND and AUTN. More specifically, the terminal device F2 may receive an authentication request from the authentication function F5.
[0336] S206: The terminal device F2 invokes the authentication operation of the security function F1, and inputs the authentication information as a parameter, such as input
RAND and AUTN, you can also enter the network identification and so on. If the security function F1 is a software function running on the terminal device F2, the calling of this step and the subsequent steps 207 to 208 are internal operations of the terminal device F2.
[0337] S207: The security function F1 generates a session key and a challenge response RES according to the authentication information and the user key stored therein, and the session key and RES are generated in the same manner as the subscription data management function F8 described in step 203 to generate a session The key is the same as XRES. The security function F1 generates a protection key based on the session key, for example, the protection key is equal to the session key, or the protection key is derived based on parameters such as the session key or network name, or uses a part of the session key. There can be one or multiple protection keys, such as confidentiality protection keys and integrity protection keys.
[0338] S208: The security function F1 returns a call result to the terminal device F2, and the returned call result is the challenge response RES.
[0339] S209: The terminal device F2 sends an authentication response to the authentication function F5, such as sending User Authentication
Response message, the message carries the challenge response RES.
[0340] S210: The authentication function F5 sends an authentication execution to the authentication service function F7, such as sending Authentication
The Confirmation message carries the challenge response RES.
[0341] S211: The authentication service function F7 generates a protection key or an intermediate session key according to the session key and other parameters, such as RAND, AUTN, or network identification. If the embodiment adopts the generation of the protection key, the protection key is generated. The key method is the same as that of the security function F1 generating the protection key. In the embodiment, if an intermediate session key is generated, the session key is the result of an intermediate state in the step of generating the protection key by the security function F1 (such as the security function F1 uses the method of generating the second session key based on the session key, and so on, and finally generating the protection key based on the nth session key, the intermediate session key can use the security function F1 to generate the second session key. Mode, or mode of the nth session key, and so on). The authentication service function F7 may also request the subscription data management function F8 to return the protection key or the intermediate session key. intermediate
The session key can contain one or more keys.
[0342] S212: The authentication service function F7 sends an authentication confirmation to the authentication function F5, such as sending Authentication
Acknowledge message, the message carries the protection key or intermediate session key.
[0343] S213: If the embodiment adopts the method of sending the intermediate session key, the authentication function F5 may generate another intermediate key based on the received intermediate session key (for example, the security function F1 may generate the first session key based on the user key). Key, the second session key is generated based on the first session key, and so on, until the protection key is generated, the received intermediate key can be the same key as the k-th session key, and the other An intermediate key may be the same key as the nth session key), or generate a protection key. If the embodiment adopts the method of sending the protection key, the authentication function F5 directly uses the protection key. The authentication function F5 sends a protection request to the base station protection function F6, such as sending a Key Request message, which carries an intermediate key or a protection key. If the embodiment adopts the method of sending the intermediate key, the base station protection function derives the protection key based on the received intermediate key. If the embodiment adopts the method of sending the protection key, the base station protection function F6 directly uses the received protection key. key. The base station protection function F6 can store the protection key to facilitate the operation of the subsequent update process. If the base station protection function F6 is co-located with the authentication function F5, the process of this step and the subsequent steps 214 to 215 are internal operations of the authentication function F5.
[0344] S214: The base station protection function F6 generates third key information based on the protection key and the first key information, or the base station protection function F6 generates third key information based on the protection key and the second key information. Adopt overall processing or batch processing, such as encrypting the first or second key information with the confidentiality protection key CKp as a whole, and/or, using the integrity protection key IKp to encrypt the first or second key information as a whole Or the entire encrypted first or second key information is integrity protected, and finally the third key information is generated. Or the base station protection function F6 generates the key in the third key information based on the protection key and the key in the first or second key information, and other information in the third key information is the same as the first key. The corresponding information in the information is the same or has been processed one by one, such as using a protection key for encryption and/or complete protection. Or use the confidentiality protection key CKp to encrypt the keys in the first or second key information one by one, and generate the third key information based on the encryption result, based on the third key information (equivalent to the calculation result generated using equal calculation ) And IKp to generate verification information, such as HASH calculation using the third key information and IKp (for example, using HMAC-SHA-256), or after hashing the third key information (for example, using SHA-256), Generate verification information with calculation results and IKp (for example, using HMAC-SHA-256).
[0345] S215: The base station protection function F6 sends a protection response to the authentication function F5, such as sending a Key Response message, which carries the third key information.
[0346] S216: The authentication function F5 sends a key provision response to the mobile terminal F3, such as sending Key Provisioning
The Response message, the message carries the third key information, and more specifically, it may be that the terminal device F2 receives the key provision response from the authentication function F5.
[0347] An embodiment is: the terminal device F2 can store the received third key information, and at the same time store the corresponding network identification or network name information, so that the anti-counterfeiting base station function can be subsequently provided for multiple networks.
[0348] Another embodiment is to continue to execute S217~S218.
[0349] S217: The terminal device F2 invokes the key storage operation of the security function F1, and inputs all or part of the third key information as parameters, and can also input the network identification or network name, and the input parameters can be used to obtain the first key The key in the information (the third key information is generated based on the first key information in the embodiment) or the key in the second key information (the third key information is generated based on the second key information in the embodiment). The security function F1 can also store corresponding network identification or network name information at the same time, so that it can subsequently provide anti-counterfeiting base station functions for multiple networks. If the security function F1 is a software function running on the terminal device F2, the calling of this step and the process of the subsequent step 218 are internal operations of the terminal device F2.
[0350] S218: The security function F1 generates the key in the first key information according to the generated protection key and input parameters, such as decrypting the input parameters with CKp, and/or, using IKp to verify the decrypted information or verify the input parameters . Alternatively, the security function F1 generates second key information based on the generated protection key and input parameters, such as decrypting the input parameters with CKp, and/or using IKp to verify the decrypted information or verify the input parameters. Or, after the security function F1 generates the key in the first key information according to the above operation, it generates the key in the second key information according to the key in the first key information. The security function F1 can store the key in the first key information, or store the key in the second key information, or store the input parameters so that when needed later, perform the above operations to obtain the key in the first key information Or the key in the second key information.
[0351] Another embodiment is that after performing steps 217 to 218, the security function F1 generates an encryption key, and generates fourth key information based on the encryption key and the first key information or the second key information, and Return to the terminal device F2, and the terminal device F2 stores the fourth key information.
[0352] Another embodiment is: the messages in step 202, step 205, step 209, and step 216 are that the mobile terminal F3 directly interacts with the base station protection function F6 (through the interface S1 and the interface S2, or the interface S1, the interface S3, And interface S4), so that step 203, step 204, step 210, and step 212 are for the base station protection function F6 to directly interact with the authentication service function F7 (through interface S5, or interface S4 and interface S6), and step 213 and step 215 are not Need it.
[0353] Another embodiment is: the messages in step 202, step 205, step 209, and step 216 are that the mobile terminal F3 directly interacts with the base station protection function F6 (through the interface S1 and the interface S2, or the interface S1, the interface S3, And interface S4), so that step 203, step 204, step 210, and step 212 are for the base station protection function F6 to directly interact with the authentication service function F7 (through interface S5, or interface S4 and interface S6), and step 213 and step 215 are not Need it.
[0354] Another embodiment is: after step 216 and before step 217, the terminal device F2 stores the third key information. Steps 217 and 218 do not need to be executed at this time, but are executed when needed, so as to obtain the first key information. A key information authenticates the message sent by the base station F4.
[0355] Another embodiment is: instead of executing 217 to 218, the terminal device F2 compares part or all of the third key information or the calculation result based on part or all of the third key information (for example, using SHA-256) with The received verification information (the verification information from step 214 is sent through the authentication function F5) is sent to the safety function F1, and the safety function F1 is verified based on the input parameters and the verification information, for example, the expected verification information is calculated based on the input parameters and IKp (For example, use HMACSHA-256), and then compare the expected verification information with the entered verification information, and the security function F1 returns the verification result to the terminal device F2.
[0356] Since then, in the case of using the asymmetric key system, the mobile terminal F3 has the mobile network private key, and the base station F4 has the mobile network public key, and the base station can use the mobile network public key pair to send to the mobile terminal F3. The entire content of the message or part of the content in the message is digitally signed. The mobile terminal F3 can use the mobile network private key to verify the digital signature, so that it can determine whether the message has been tampered with (digitally sign the entire content), and it can also determine whether the base station It is a pseudo base station (digitally sign all or part of the content). In the case of using a symmetric key system, the mobile terminal F3 has the first key information and can obtain the second key information based on the first key information, or with the second key information, the base station F4 sends to the mobile terminal F4 based on the second key information. The entire content of the message of the terminal F3 or part of the message generates the message authentication code MAC, and the mobile terminal F3 can use the second key information to verify the MAC, so as to determine whether the message has been tampered with (generate the MAC with the entire content), and It can be judged whether the base station is a pseudo base station (generating MAC with all or part of the content).
[0357] Embodiment Seven:
[0358] FIG. 12 is a schematic diagram of a key issuance process of a mobile terminal according to an embodiment of the present invention. The process includes:
[0359] S301~S309: Same as described in S201~S209 in FIG. 11.
[0360] S310: The authentication function F5 sends a protection request to the base station protection function F6, such as sending a Key Request. If the base station protection function F6 is co-located with the authentication function F5, the process of this step and the subsequent step 311 are internal operations of the authentication function F5.
[0361] S311: The base station protection function F6 sends a protection response to the authentication function F5, such as sending a Key Response message, which carries the first key information or the second key information.
[0362] S312: The authentication function F5 sends an authentication execution to the authentication service function F7, such as sending an Authentication Confirmation message, which carries the challenge response and the first key information, or carries the challenge response and the second key information. [0363] S313: The authentication service function F7 generates a protection key according to the session key and other parameters, such as RAND, AUTN, or network identification, etc., and the generation method is the same as that of the security function F1 in step 307 to generate the protection key. The authentication service function F7 can also request the contract data management function F8 to generate a protection key, and return the protection key to the authentication service function F7. The way the contract data management function F8 generates the protection key and the way the security function F1 generates the protection key the same. The authentication service function F7 generates the third key information based on the protection key and the first key information, for example, encrypts the first key information with the confidentiality protection key CKp, and/or uses the integrity protection key IKp to pair the first key information. The key information or the encrypted first key information is integrity protected, and finally the third key information is generated. Or the authentication service function F7 generates the third key information based on the protection key and the second key information, for example, encrypts the second key information with the confidentiality protection key CKp, and/or uses the integrity protection key IKp to The second key information or the encrypted second key information is integrity protected, and finally the third key information is generated. recognize The certificate service function F7 can also send the first key information or the second key information to the contract data management function F8, and the contract data management function F8 performs the above operations to generate the third key information, and then returns the third key information Give the authentication service function F7.
[0364] S314: The authentication service function F7 sends an authentication confirmation to the authentication function F5, such as sending Authentication
The Acknowledge message carries the third key information.
[0365] S315~S317: Same as the description of steps 216 to 218 in FIG. 11.
[0366] Another embodiment is: the message in step 302, step 305, step 309, and step 316 is that the mobile terminal F3 directly interacts with the base station protection function F6 (through the interface S1 and the interface S2, or the interface S1, the interface S3, And interface S4), so that step 303, step 304, step 312, and step 314 are for the base station protection function F6 to directly interact with the authentication service function F7 (through interface S5, or interface S4 and interface S6), and step 310 and step 311 are not Need it.
[0367] Another embodiment is: after step 315 and before step 316, the terminal device F2 stores the third key information. Steps 316 and 317 do not need to be executed at this time, but are executed when needed, so as to obtain the first key information. A key information authenticates the message sent by the base station F4.
[0368] Embodiment 8:
[0369] FIG. 13 is a schematic diagram of a key issuance process of a mobile terminal according to an embodiment of the present invention. In this embodiment, the base station protection function F6 and the authentication function F5 are separately provided, and the process includes:
[0370] S401: The description is the same as that of S201 in FIG. 11.
[0371] S402: The mobile terminal F3 sends a key provision request to the base station protection function F6, such as sending Key
The Provisioning Request message, more specifically, may be the terminal device F2 sending the request.
[0372] S403: The base station protection function F6 sends an authentication request to the authentication function F5, such as sending Authentication
Required message.
[0373] S404~S413: Same as described in S203~S212 in FIG. 11.
[0374] S414: The authentication function F5 sends an authentication response to the base station protection function F6, such as sending Authentication
Acknowledge message, the message carries the protection key, and the base station protection function F6 can store the protection key to facilitate the operation of the subsequent update process.
[0375] S415: The same as the description of S214 in FIG. 11.
[0376] S416: The base station protection function F6 sends a key provision response to the mobile terminal F3, such as sending Key
Provisioning Response message, the message carries third key information. More specifically, it may be that the terminal device F2 receives a key provision response from the base station protection function F6.
[0377] S417~S418: Same as described in S217~S218 in FIG. 11.
[0378] Another embodiment is: after step 416 and before step 417, the terminal device F2 stores the third key information. Steps 417 and 418 do not need to be executed at this time, but are executed when needed, so as to obtain the first key information. A key information authenticates the message sent by the base station F4.
[0379] Example Nine:
[0380] FIG. 14 is a schematic diagram of a key issuance process of a mobile terminal according to an embodiment of the present invention, and the process includes:
[0381] S501: The description is the same as S201 in FIG. 11.
[0382] S502: The mobile terminal F3 needs to initiate a network access request. Specifically, the terminal device F2 needs to initiate a network access request, so the key generation operation of the security function F1 is invoked. The operation may include a random character string RANDue.
[0383] S503: If the security function F1 does not have a protection key, generate a random character string RANDue, or read a random character string RANDue, or use the RANDue in the key generation operation called by the terminal device F2, and the security function F1 is based on the user secret The key and RANDue generate a protection key.
[0384] S504: The security function F1 returns RANDue to the terminal device F2.
[0385] S505: The terminal device F2 initiates a key provision request to the authentication function F5, such as sending Key Provisioning
Request message, or send Registration Request message, the message carries RANDue.
[0386] S506: The authentication function F5 sends an authentication request to the authentication service function F7, such as sending Authentication
Request message, the message carries RANDue.
[0387] S507: The authentication service function F7 requests an authentication vector from the contract data management function, carrying RANDue, and after obtaining the authentication vector, the authentication service function F7 triggers the subsequent standard network and terminal mutual authentication process, such as standard EPS AKA or 5G AKA Or EAP-AKA' process.
[0388] S508: The subscription data management function F8 generates a protection key based on the received RANDue and the user key of the corresponding user, for example, using a hash function such as HMAC-SHA-256.
[0389] S509~S515: Same as described in steps S212~S218 in FIG. 11.
[0390] Another embodiment is: after step 513 and before step 514, the terminal device F2 stores the third key information. Steps 514 and 515 do not need to be executed at this time, but are executed when needed, so as to obtain the first key information. A key information authenticates the message sent by the base station F4.
[0391] Embodiment Ten:
[0392] FIG. 15 is a schematic diagram of a key issuance process of a mobile terminal according to an embodiment of the present invention, and the process includes:
[0393] S601: The description is the same as step S201 in FIG. 11.
[0394] S602: The mobile terminal F3 wants to initiate a network access request, specifically the terminal device F2 wants to initiate a network access request, and then invokes the key generation operation of the security function F1.
[0395] S603: If the security function F1 has not sent a secret key to the mobile network (not related to the user key), generate a secret key or read the stored secret key. The security function F1 is based on the home network public key And secret key generation
Transmission keys, such as using the home network public key to encrypt the secret key, or generating a transmission key based on the home network shared key and secret key, such as deriving an encryption key based on the home network shared key, and then using the encryption key to encrypt the secret Key generation transmission key.
[0396] S604: The security function F1 returns the transmission key to the terminal device F2.
[0397] S605: The terminal device F2 initiates a key provision request to the authentication function F5, such as sending Key Provisioning
Request message, or send Registration Request message, the message carries the transmission key.
[0398] S606: The authentication function F5 sends an authentication request to the authentication service function F7, such as sending Authentication
Request message, the message carries the transmission key.
[0399] S607: The authentication service function F7 requests an authentication vector from the contract data management function, and carries the transmission key. After the authentication service function F7 obtains the authentication vector, it triggers the subsequent standard network and terminal mutual authentication process, such as standard EPS AKA or 5G AKA or EAP-AKA' process.
[0400] S608: The contract data management function F8 uses the home network private key (matched with the home network public key) to generate a secret key based on the received transmission key, for example, uses the home network private key to decrypt the transmission key to obtain the secret key , Or use the shared key of the home network to generate the secret key, for example, use the shared key of the home network to derive the encryption key, and then use the encryption key to decrypt the transmission key to obtain the secret key.
[0401] S609~S615: Same as described in steps S212~S218 in FIG. 11, except that the protection key is replaced with a secret key.
[0402] Another embodiment is: after step 613 and before step 614, the terminal device F2 stores the third key information. Steps 614 and 615 do not need to be executed at this time, but are executed when needed, so as to obtain the first key information. A key information authenticates the message sent by the base station F4.
[0403] Another embodiment is: instead of executing 614 to 615, the terminal device F2 compares part or all of the third key information or the calculation result based on part or all of the third key information (for example, using SHA-256) with The received verification information (the verification information from step 611 is sent through the authentication function F5) is sent to the security function F1, and the security function F1 performs verification based on the input parameters and the verification information, such as calculating expectations based on the input parameters and the secret key Verify the information (for example, use HMAC-SHA-256), and then compare the expected verification information with the entered verification information, and the security function F1 returns the verification result to the terminal device F2.
[0404] Embodiment 11:
[0405] FIG. 16 is a schematic diagram 6 of a mobile terminal key issuance process according to the sixth embodiment of the present invention, and the process includes:
[0406] S701: The description is the same as step S201 in FIG. 11.
[0407] S702: The mobile terminal F3 needs to initiate a request to access the network. Specifically, the terminal device F2 needs to initiate a request to access the network, and then invokes the key generation operation of the security function F1.
[0408] S703: If the security function F1 does not have a secret key (it has nothing to do with the user key), generate a secret key, and the security function F1 generates a transmission key based on the visited network public key and the secret key, such as using the visited network public key Encrypt the secret key.
[0409] S704: The security function F1 returns the transmission key to the terminal device F2.
[0410] S705: The terminal device F2 initiates a key provision request to the base station protection function F6, such as sending a Key
Provisioning Request message, or sending Registration Request message, the message carries the transmission key.
[0411] S706: The base station protection function F6 generates a secret key based on the received transmission key and the visited network private key (matched with the visited network public key), for example, uses the visited network private key to decrypt the transmission key to obtain the secret key. Then perform the operation as described in step S214 in FIG. 11, except that the protection key is replaced with the secret key.
[0412] In another embodiment, step 705 passes through the authentication function F5, and then step 706 may be that the authentication function F5 first obtains the secret key, and then transmits the secret key to the base station protection function F6, and then F6 executes again in FIG. 2 The operation described in step 214 only replaces the protection key with the secret key.
[0413] S707~S709: Same as described in steps S416~S418 in FIG. 13, except that the protection key is replaced with a secret key.
[0414] In another embodiment, step 705 passes the authentication function F5, then step 706 may be that the authentication function F5 first obtains the secret key, and then F6 transmits the first key information or the second key information to the authentication function F5. After that, the authentication function F5 performs the operation described in step 214 in FIG. 2, except that the protection key is replaced with the secret key.
[0415] Another embodiment is: after step 707 and before step 708, the terminal device F2 stores the third key information. Steps 708 and 709 do not need to be executed at this time, but are executed when needed, so as to obtain the first key information. A key information authenticates the message sent by the base station F4.
[0416] Embodiment 12:
[0417] FIG. 17 is a schematic diagram of a key update process of a mobile terminal according to an embodiment of the present invention. The process includes:
[0418] S801: The same as the description of step S201 in FIG. 11, except that the first key information in the base station protection function F6 has been updated, so the second key information in the corresponding base station F4 has also been updated, and If it carries indication information, the indication information indicates an update.
[0419] S802: Optionally, the mobile terminal F3 sends a key provision request to the base station protection function F6, such as sending Key
The Provisioning Request message, more specifically, may be the terminal device F2 sending the request. Another embodiment is that the base station protection function F6 triggers the process of subsequent steps 803 to 806 due to the key update. The first key information or the second key information may include the key update time, or the third key information may include the key update time, and the mobile terminal F3 may send the key after the expiration date according to the key update time therein. Provide request.
[0420] S803~S806: The same description as steps S415~418 in FIG. 13.
[0421] Another embodiment is that step S803 generates third key information based on the secret key and the first key information or the second key information, and step S806 is based on the secret key and part or all of the third key information Generate the key in the first key information or the key in the second key information.
[0422] In this embodiment, in addition to the foregoing implementation, there are also the following implementations: the first key information or the second key information stored in the security function F1, or the first key information stored in the terminal device F2 The three key information and the protection key in the security function F1 can be obtained by the same or similar methods described in Figure 11 to Figure 14, or can be obtained by other methods, such as the O TA mechanism, that is, the base station protection function F6 will Related information is transmitted to the subscription data management. Under other mechanisms, such as the OTA mechanism, the protection key may be independent of the user key. Therefore, the solution of the following embodiment has no correlation with the solution described in FIGS. 11-14.
[0423] Embodiment 13:
[0424] This embodiment provides this embodiment also provides a computer-readable storage medium, which is included in the storage medium for storing information (such as computer-readable instructions, data structures, computer program modules, or other data). ) Volatile or non-volatile, removable or non-removable media implemented in any method or technology. Computer-readable storage media include but are not limited to RAM (Random Access Memory), ROM (Read-Only Memory, read-only memory), EEPROM (Electrically E rasable Programmable read only memory) Storage), flash memory or other storage technology, CD-ROM (Compact Disc Read-Only Memory), digital versatile disk (DVD) or other optical storage, magnetic cassettes, magnetic tapes, disk storage or other magnetic storage devices , Or any other information that can be used to store desired information and that can be accessed by a computer
His medium.
[0425] In an example, the computer-readable storage medium in this embodiment may be used to store one or more of the first computer program, the second computer program, the third computer program, the fourth computer program, and the second computer program. The one or more of the foregoing computer programs may be executed by one or more processors to implement the steps of the key issuance method described in each of the foregoing embodiments.
[0426] This embodiment also provides a computer program (or computer software). The computer program can be distributed on a computer-readable medium and executed by a computable device to implement the key as shown in the above embodiments. At least one step of the dispensing method; and in some cases, at least one step shown or described may be performed in a different order than described in the above-mentioned embodiment.
[0427] This embodiment also provides a computer program product, including a computer-readable device, and the computer-readable device stores the computer program as shown above. The computer-readable device in this embodiment may include the computer-readable storage medium as shown above.
[0428] It can be seen that those skilled in the art should understand that all or some of the steps in the method disclosed above, the functional modules/units in the system, and the device can be implemented as software (computer programs executable by a computing device can be used). Code to achieve), firmware, hardware and their appropriate combination. In the hardware implementation, the division between functional modules/units mentioned in the above description does not necessarily correspond to the division of physical components; for example, one physical component may have multiple functions, or one function or step may consist of several physical components. The components are executed cooperatively. Some physical components or all physical components can be implemented as software executed by a processor, such as a central processing unit, a digital signal processor, or a microprocessor, or as hardware, or as an integrated circuit, such as an application specific integrated circuit .
[0429] In addition, as is well known to those of ordinary skill in the art, communication media usually contain computer-readable instructions, data structures, computer program modules, or other data in a modulated data signal such as carrier waves or other transmission mechanisms, and may include Any information delivery medium. Therefore, the present invention is not limited to any specific combination of hardware and software.
[0430] The above content is a further detailed description of the embodiments of the present invention in combination with specific implementations, and it cannot be considered that the specific implementations of the present invention are limited to these descriptions. For those of ordinary skill in the technical field to which the present invention belongs, a number of simple deductions or substitutions can be made without departing from the concept of the present invention, which should be regarded as belonging to the protection scope of the present invention.
1 sheet
Sheet 1
Every citation, both waysCites: the store holds 14 of 15
| Document | Relation | Office | Category | Cited during | Relevant claims |
|---|---|---|---|---|---|
| US12137341B2 | Cited by | United States of America | – | Search report | – |
| US2023061362A1 | Cited by | United States of America | – | Search report | – |
| WO0122685A1 | Cites | World Intellectual Property Organization (WIPO) | A | Search report | 1-32 |
| CN101552668A | Cites | China | A | Search report | 1-32 |
| CN101778381A | Cites | China | A | Search report | 1-32 |
| CN101990201A | Cites | China | A | Search report | 1-32 |
| CN102196436A | Cites | China | A | Search report | 1-32 |
| CN102932784A | Cites | China | A | Search report | 1-32 |
| CN104010305A | Cites | China | A | Search report | 1-32 |
| CN105207774A | Cites | China | A | Search report | 1-32 |
| CN105792194A | Cites | China | A | Search report | 1-32 |
| CN108076460A | Cites | China | A | Search report | 1-32 |
| CN108092958A | Cites | China | A | Search report | 1-32 |
| CN1848995A | Cites | China | A | Search report | 1-32 |
| WO2009094942A1 | Cites | World Intellectual Property Organization (WIPO) | A | Search report | 1-32 |
| WO2012024906A1 | Cites | World Intellectual Property Organization (WIPO) | A | Search report | 1-32 |
| HUAWEI ; HISILICON: "S3-170042 "Network lying about its public key; Is it a security issue?"", 3GPP TSG_SA\\WG3_SECURITY, no. 3, 29 January 2017 (2017-01-29) | Non-patent | – | – | Search report | – |
| 田野;刘斐;徐海东;: "新型伪基站安全分析研究", 电信工程技术与标准化, no. 08, 15 August 2013 (2013-08-15) | Non-patent | – | – | Search report | – |
1 member in 1 office
Priority claims2
| Document | Office | Kind | Date |
|---|---|---|---|
| 201811583792 | China | A | |
| CN201811583792 | – | – | – |
Members1
| Document | Office | Kind | |
|---|---|---|---|
| CN110536289AThis record | China | A |
3 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Patent grantGrantedGR01 | GR01 | |
| Entry into force of request for substantive examinationSE01 | SE01 | |
| PublicationPB01 | PB01 |
Numbers
- Publication
- 110536289
- Publication, DOCDB
- 110536289
- Publication, EPODOC
- CN110536289
- Application
- 11583792
- Application, DOCDB
- 201811583792
- Application, EPODOC
- CN201811583792
Titles2
- Chinese
- 密钥发放方法及其装置、移动终端、通信设备和存储介质
- English
- Key issuing method and device, mobile terminal, communication equipment and storage medium
Classification
- CPC, 6
- H04W12/02
- H04W12/06
- H04L9/0819
- H04L9/0822
- H04L9/3226
- H04W12/10
- IPC, 7
- H04W12 02
- H04W12 06
- H04W12 10
- H04L9 32
- H04L9 08
- H04W12 03
- H04W12 0431