CN1937489A

Network key management and session key updating method

Abstract

A method for network key peopleagement and session key update. The implementation steps of the key peopleagement method include: constructing a key agreement request group, constructing a key agreement response group, and constructing a key agreement confirmation group. The implementation steps of the multicast key peopleagement method include the multicast master key agreement protocol and the multicast session key distribution protocol. The multicast master key agreement protocol is the key update announcement packet, the key agreement request packet is constructed, the key agreement response packet is constructed, and the key agreement confirmation packet is constructed. The multicast session key distribution protocol is the multicast session key request, Multicast session key distribution. The invention solves the problems of low efficiency of negotiation and update of the multicast session key in the background technology and complicated system state peopleagement. The invention can realize different levels of session keys for different services, make full use of the broadcast channel for multicast session key negotiation, and the update of the multicast session key is more flexible.

Term

Term ended

Projected expiry passed 23 September 2026, -0 years ago.

  1. Priority and filed
  2. Published
  3. Projected expiry
  4. Today

8 claims: 6 independent, 2 dependent

  1. 1
    First 第 1. A network unicast key peopleagement method, which is characterized in that the method includes the following steps:(1) Constructing a key agreement request group: During initial key negotiation, or a mobile terminal requires key update or a base station When the session key update notification packet is sent, the mobile terminal sends a key agreement request packet to the base station to activate the key agreement process;(2) Construct a key agreement response packet: (2.1) The base station receives the key agreement request from the mobile terminal Divide the crucian carp to construct a key agreement response packet;(2. 2) If the base station sends a key update notification packet in advance, the base station checks whether the value of the corresponding field in the key update notification packet and the key agreement request packet are the same;If they are the same, Beibu creates the key agreement response packet;if they are not the same, discards the key agreement request packet without any processing;(2.3) The base station sends the key agreement response packet to the mobile terminal to derive the unicast session encryption key and Integrity check key;(3) Construct a key agreement confirmation group: After receiving the key agreement response packet sent by the base station, the mobile terminal uses the key encryption key derived from the authorization key corresponding to the authorization key to identify the AKID The decryption obtains the session key material TEKM, and uses the random number selected by the base station and the mobile terminal to derive the session encryption key and the integrity check key to construct the key agreement confirmation group. 1. 一种网络单播密钥管理方法,其特征在于:该方法旳蜩涉骤包竜: (1)构造密钥协商请求分组: 初始密钥协商时,或移动终端要求密钥更新或H痢基站发送的会话密钥更新通告分 组时,移动终端向基站发送密钥协商请求分组,以激活密钥协商过程; ⑵构造密钥协商响应分组: (2.1)基站收到移动终端雄的密钥协商请求分鲫构造密钥协商响应分组; (2. 2)如果基站在先发送了密钥更新通告分组,贝U基站检验密钥更新通告分组与密 钥协商请求分组中相应字段的取值是否相同;如果相同,贝购造密钥协商响应分组;不 相同,丢弃密钥协商请求分组而不作任何处理; (2. 3)基站向移动终端发送密钥协商响应分组,导出单播会话加密密钥和完整性校 验密钥; (3)构造密钥协商确认分组: 移动终端收到基站发送的密钥协商响应分组后,利用授权密钥标识AKID对应的授 权密钥所导出的密钥加密密钥解密得到会话密钥材料TEKM,并利用基站和移动终端选 取的随机数导出会话加密密钥和完整性校验密钥,构造密钥协商确认分组。
  2. 3
    A multicast key peopleagement method, characterized in that:the implementation steps of the method include: (1) Multicast master key agreement protocol: (1.1) Constructing a key report group: The base station needs to update the session key, and When the mobile terminal has not submitted a request to update the session key, the base station reports the magnetic key ® to the mobile terminal to notify the mobile terminal to steal the key;the key notification is only for stealing the MW family of keys, and in the initial key agreement (1.2) Constructing the key agreement request packet: During the initial key agreement process, or when the mobile terminal receives the key update notification packet sent by the base station, the mobile terminal sends the key agreement request packet to the base station to activate Key agreement process;(1.3) Construct a key agreement response group: (1.3.1) The key agreement request of the base station and the mobile terminal can construct a key agreement response (1.3. 3. 2) If the base station has sent a key update notification packet in advance, the base station checks whether the values of the corresponding fields in the key update notification packet and the key agreement request packet are the same;if they are the same, the base station constructs another key agreement response group;If they are not the same, discard the key agreement request packet without any processing;(1.3.3) The base station sends a key agreement response packet to the mobile terminal, and derives the multicast key encryption key GKEK and the multicast message integrity check key GMIK;(1.4) Construct a key agreement confirmation group: The mobile terminal receives the key agreement response from the base station tank and decrypts it with the key encryption key guided by the authorization key O<AKID corresponding to the authorization key to obtain the session The key material is plain text TEKM to construct a key agreement confirmation packet;the mobile terminal sends the key agreement confirmation packet to the base station;derives the multicast key encryption key GKEK and the multicast message integrity check key GMK;(2) Group Broadcast session key distribution protocol: (2.1) Group key request: When the mobile terminal needs to negotiate or update the multicast session key, the mobile terminal sends a multicast session key request packet to the base station;(2.2) Multicast session key distribution : When the base station receives the multicast session key request packet sent by the mobile terminal, the base station sends the multicast session key distribution ratio a to the mobile terminal;when the station needs to update the multicast key, the base station broadcasts the broadcast session to all mobile terminals Key distribution group. 3.—种组播密钥管理方法,其特征在于:该方法的实现步骤包括: (1) 组播主密钥协商协议: (1.1) 构造密钥告分组: 基站需要会话密钥更新,而移动终端尚未提出更新会话密钥请求时,基站向移动终 端磁密钥® 告分组,通知移动终驰行窃密钥彌;知舌密钥 告価仅 在窃密钥MW族,在初始密钥协商时不囲; (1.2) 构造密钥协商请求分组: 在初始密钥协商过程中,或移动终端收到基站发送的密钥更新通告分组时,移动终 端向基站发送密钥协商请求分组,以激活密钥协商过程; (1.3) 构造密钥协商响应分组: (1.3.1) 基站愉移动终端罐的密钥协商请求构造密钥协商响应沁 (1. 3. 2)如果基站在先发送了密钥更新通告分组贝IJ基站检验密钥更新通告分组与 密钥协商请求分组中相应字段的取值是否相同;如果相同,贝U构造密钥协商响应另组; 不相同,则丢弃密钥协商请求分组而不作任何处理; (1.3.3) 基站向移动终端发送密钥协商响应分组,导出组播密钥加密密钥GKEK和 组播消息完整性校验密钥GMIK; (1.4)构造密钥协商确认分组: 移动终端收到基站罐的密钥协商响应分輛利用授权密钥O<AKID对应的授 权密钥所导岀的密钥加密密钥解密,得到会话密钥材料明文TEKM,构造密钥协商确认 分组;移动终端将密钥协商确认分组发送给基站;导出组播密钥加密密钥GKEK和组播 消息完整性校验密钥GMK; (2) 组播会话密钥分发协议: (2.1) 组密钥请求: 移动终端需要协商或更新组播会话密钥时,移动终端向基站发送组播会话密钥请求 分组; (2.2) 组播会话密钥分发: 基站收到移动终端发送的组播会话密钥请求分组时,基站向移动终端发送组播会话 密钥分发比a;讎站需要组播密钥更新时,基站向所有移动终端广删播会话密钥分 发分组。 200610104679.4 p. 200610104679.4 第