Method of negotiating the encryption algorithms
Abstract
A method of realizing negotiation of the encryption algorithms, which relates to the field of mobile communication or data communication, includes the step of identifying negotiation the encryption algorithms of both sides, the communication of the both sides is started when the negotiation is passed. Said negotiation the step of identifying the encryption algorithm identifier of the security protocol. Said encryption algorithm identifier includes algorithm identifier indicating a selected encryption algorithm, characterized in that said identifying the encryption algorithm identifier include the step of identifying the country code. As adding the country code, the producers needn't special negotiation when their different equipments communicate with each other in security protocol, at one time standardization, and settle the matter of some countries having their own special security protocols.
Term
Term ended
Projected expiry passed 25 August 2023, 3.1 years ago.
- Priority
- Filed
- Published
- Projected expiry
- Today
7 claims: 1 independent, 6 dependent
- 1A method of negotiating encryption algorithm, comprising a step of authenticating the encryption algorithm identifier in the security protocol, said encryption algorithm identifier containing an algorithm identifier identifying the chosen encryption algorithm, wherein also comprises a step of authenticating a Country Mobile Identifier (CMI).
32 paragraphs, as filed
Field of the Invention
0001The present invention relates to mobile communication and data communication fields, particularly to a method of implementing secret communication in mobile communication and data communication through negotiating encryption algorithms.
Background of the Invention
0002In the traditional mobile communication or data communication field, to implement unified scale and application of devices, usually relevant standards are specified to support interconnection and intercommunication among the devices around the world. Particularly to the information security field, usually several standard encryption algorithms are specified to implement secure interconnection and intercommunication among network devices of different operators and different countries; the standard algorithms shall be universal globally; the communication between subscribers is implemented through negotiating the standard algorithms.
0003For example, in the typical data communication security field, IPSec is used widely as the security mechanism for the interconnected networks around the world; encrypted communication can be implemented between different network devices through IPSec. To ensure successful encrypted communication between different devices, several standard encryption algorithms are defined in IPSec. During communication, the encryption algorithm used between the two parties is negotiated through Security Association (SA). Data Encryption Standard (DES), 3DES and Advanced Encryption Standard (AES) encryption algorithms are defined in IPSec as common standard encryption algorithms; Message Digest Algorithm 5 (MD5) and Secure Hash Algorithm (SHA-1) algorithms are used as common standard signature algorithms.
0004Similarly, in wireless 3G communication systems, the algorithms used for subscriber information encryption shall also be standard algorithms instead of non-standard encryption algorithms. Standard algorithms are negotiated through security protocols. For example, presently, Kasumi standard algorithm has been defined for 3G communications.
0005In some countries, due to the information security management policies, the standard encryption algorithms developed by other countries are forbidden to use indomestic communication systems; for example, all of the algorithms mentioned above are forbidden to use in the devices. To meet the demand for domestic application, some manufacturers have developed private encryption algorithms permitted in the country and the encryption algorithms substitute for standard algorithms in actual application. This will result in special algorithm identifiers in some devices. Therefore, it is difficult to implement interconnection and intercommunication between devices from different manufacturers because the devices are unable to negotiate effectively with each other. This has brought severe problem to applications. Often, the consequence is: the devices that are to be interconnected with each other have to be devices from the same manufacturer, ornegotiationbetweendevices is required. This is not suitable for the trend of application globalization of communication network devices.
0006In the communication field, the communication between different devices is implemented through protocol negotiation. Therefore, when secret communication between different devices is required, security parameters have to be negotiated between the devices. The security parameters may include security algorithm, key, start time of encryption, random number, etc. The security parameters for different system and for different requirements are not identical. Negotiation for encryption algorithm is necessary when the encryption algorithm is not fixed in some system.
0007As a result, the prior art can't meet the challenge in consideration of application globalization as well as demands of some countries for special security requirements.
Summary of the Invention
0008An object of the present invention is to provide a solution for the problems in above special application cases, i.e., it implements global secret communication through adding a Country Mobile Identifier (CMI) in the Algorithm Identifier (AI) of the traditional SA.
0009A method of negotiating encryption algorithm, comprises a step of authenticating the encryption algorithm identifier in the security protocol, said encryption algorithm identifier containing an algorithm identifier identifying the chosen encryptionalgorithm, and also comprises a step of authenticating a CMI.
0010Said CMI is in the encryption algorithm identifier.
0011Said CMI, corresponding to different countries, constitutes a CMI set.
0012Said CMI is an identifier assigned by the International Organization for Standardization (ISO).
0013Said CMI may be a Global Mobile Identifier (GMI).
0014In said method of negotiating encryption algorithm, for a country or an operator that has no special requirement for the information security algorithm, the CMI is substituted with a global mobile identifier, and the algorithm identifier is the specified standard algorithm identifier.
0015In said method of negotiating encryption algorithm, for a country or an operator that has special requirements for the information security algorithm, the algorithm identifier is the standard algorithm permitted by the country or the operator.
0016Through adding a CMI, the devices fromdifferent manufacturers will no longer require negotiation between manufacturers the to implement secret intercommunication; in the meantime, through standardization, the demands of countries with special security requirements can be met.
Detailed Description of the Embodiments
0017In the communication field, communication between different devices is implemented through protocol negotiation. Therefore, when secret communication between different devices is required, the security parameters between each other have to be negotiated and authenticated through a security protocol. After successful negotiation, the devices may communication with each other. The security parameters may include security algorithm, key, start time of encryption, and random number, etc. The security parameters for different system and for different requirements are not identical. Negotiation for encryption algorithm is necessary when the encryption algorithm is not fixed in some system.
0018In the traditional methodof negotiating encryption algorithm, the negotiation comprises a step of authenticating the encryption algorithm identifier in the security protocol; said encryption algorithm identifier contains an algorithm identifier identifying the chosen encryption algorithm. The method according to the present invention comprises a step of authenticating the encryption algorithm identifier, and the step of authenticating the encryption algorithm identifier also comprises a step of authenticating a CMI; said CMI is in the encryption algorithm identifier, as shown in table 1: <tables id="tabl0001" num="0001"><table frame="all"><title>table 1</title><tgroup cols="2" colsep="1" rowsep="0"><colspec colnum="1" colname="col1" colwidth="78.75mm" /><colspec colnum="2" colname="col2" colwidth="78.75mm" /><tbody valign="top"><row rowsep="1"><entry namest="col1" nameend="col1" align="center">CMI (Country Mobile Identifier)</entry><entry namest="col2" nameend="col2" align="center">AI (Algorithm Identifier)</entry></row></tbody></tgroup></table></tables>
0019It can be seen that the encryption algorithm identifier according to the present invention comprises two parts: CMI and AI.
0020In the CMI, each country is assigned a fixed code, which may employ the identifier assigned by ISO; all of the CMIs constitute a CMI set.
0021In said CMI set, A GMI is also assigned.
0022Since the algorithm identifier corresponding to each country may be different, for a standard algorithm that is used globally, the determined GMI may be used as the CMI. Countries or operators that have no special requirement for the information security algorithm may prefer a standard algorithm; in this case, the CMI of the security algorithm is GMI; and the corresponding algorithm identifier usually indicates an available standard algorithm.
0023However, countries or operators that have special security requirements for the information encryption algorithm maybe do not expect to use standard algorithms; in this case, the CMI of the security algorithm is the CMI of the country; and the corresponding algorithm identifier usually indicates a standard algorithm permitted in the country.
0024Above algorithm identifier shall be standardized, so that standard and nonstandard entries may be included in a device from any manufacturer because the encryption algorithm identifier parameters in the security protocol include CMI and AI. When the intercommunicating devices employ standard entries, the CMIs in the security protocols of the two intercommunicating devices will be both GMI; when the intercommunicating devices employ nonstandard entries, the CMI in the security protocol of two intercommunicating devices will be the CMI of the corresponding country. This can overcome the problems in intercommunication between different devices when there are special security requirements.
0025It is assumed that device A in company A is to communicate with device B in company B through a secure communication connection. The secure communication connection has to be implemented with a security protocol command P; the security protocol comprises a security parameter - Security Algorithm Identifier (SAI), which is 12 bits in length, wherein the first 8 bits represent CMI, the rest 4 bits represent AI. Suppose "00000000" represents GMI, "0000"~"1111" represents algorithms 1~16, the CMI of the device is "00001111": <ul id="ul0001" list-style="none" compact="compact"><li>If the two devices will communicate with standard algorithm 3, the communication process is as follows: <ul id="ul0002" list-style="none" compact="compact"><li>1. A sets the SAI as "000000000011" and sends the security protocol command P1 composed of a list comprising the parameter and other security parameters to B;</li><li>2. B determines the standard algorithm that is supported by both devices through acknowledging the SAI received, chooses the standard algorithm 3 as the encryption algorithm, and returns an acknowledgement message;</li><li>3. Device A and Device B encrypt/decrypt subsequent communication information with the standard algorithm to accomplish the secure communication between the two.</li><li>4. In above case, if device A and device B support multiple standard algorithms, multiple SAIs will be contained in the security protocol during the negotiation process; however, the CMI part is "00000000".</li></ul></li><li>If the two devices have to communicate with the non-standard algorithm 2 permitted by the country, the communication process is as follows: <ul id="ul0003" list-style="none" compact="compact"><li>1. A sets the SAI as "000011110010" and sends the security protocol command P1 composed of the parameter and other security parameters to device B.</li><li>2. B determines the non-standard algorithm that is supported by both devices through acknowledging the SAI received, chooses the non-standard algorithm 2 as the encryption algorithm, and returns an acknowledgement message.</li><li>3. Device A and Device B encrypt/decrypt subsequent communication information with the non-standard algorithm 2 to accomplish the secure communication between the two.</li><li>4. In above case, if device A and device B support multiple non-standard algorithms, multiple SAIs will be contained in the security protocol during the negotiation process; however, the CMI part is "00001111".</li></ul></li></ul>
0026Through above processes, effective communication between different devices can be implemented in standard or special applications, and both standard and special security requirements are met.
0027It can be seen that the present invention can meet the demand of countries with standard security requirements as well as the demand of countries with special requirements in secure intercommunication between communication networks around the world, so that devices from different manufacturers will no longer require negotiation between the manufacturers for secure intercommunication; in addition, through standardization, the demand of countries with special security requirements can be met.
0028Though the present invention is described with above preferred embodiments, it is understood the protecting scope of the present invention is not limited by the embodiments. Those skilled in the art may implement modifications or replacements according to the disclosure of the present invention; however, any such modification or replacement shall fall into the protection scope of the present invention. Therefore, the protection scope is only defined by the claims.
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| US8908863B2 | Cited by | United States of America | Applicant |
| US9729523B2 | Cited by | United States of America | Applicant |
| WO0059253A1 | Cites | World Intellectual Property Organization (WIPO) | Search report |
| WO0135691A1 | Cites | World Intellectual Property Organization (WIPO) | Search report |
5 members in 4 offices
Priority claims3
| Document | Office | Kind | Date |
|---|---|---|---|
| 02128990 | China | – | |
| 02128990 | China | A | |
| 0300719 | China | W |
Members5
| Document | Office | Kind | |
|---|---|---|---|
| CN1479480A | China | A | |
| WO2004019549A1 | World Intellectual Property Organization (WIPO) | A1 | |
| AU2003257804A1 | Australia | A1 | |
| EP1536591A1This record | European Patent Office (EPO) | A1 | |
| EP1536591A4 | European Patent Office (EPO) | A4 |
13 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Application deemed to be withdrawnWithdrawn18D | 18D | |
| Information on the status of an ep patent application or granted ep patentGrantedSTATUS: THE APPLICATION IS DEEMED TO BE WITHDRAWNSTAA | STAA | |
| First examination report despatched17Q | 17Q | |
| Supplementary search report drawn up and despatchedA4 | A4 | |
| Information provided on ipc code assigned before grantRIC1 | RIC1 | |
| Information provided on ipc code assigned before grantRIC1 | RIC1 | |
| Information provided on ipc code assigned before grantRIC1 | RIC1 | |
| Information provided on ipc code assigned before grantRIC1 | RIC1 | |
| Request for extension of the european patent (deleted)DAX | DAX | |
| Request for examination filed17P | 17P | |
| Designated contracting statesAK | AK | |
| Request for extension of the european patentAX | AX | |
| Public reference made under article 153(3) epc to a published international application that has entered the european phaseORIGINAL CODE: 0009012PUAI | PUAI |
Numbers
- Publication
- 1536591
- Application
- 37921012
Titles3
- German
- VERFAHREN ZUM AUSHANDELN DER VERSCHLÜSSELUNGSALGORITHMEN
- English
- METHOD OF NEGOTIATING THE ENCRYPTION ALGORITHMS
- French
- PROCEDE DE NEGOCIATION D'ALGORITHMES DE CODAGE
Classification
- CPC, 7
- H04L63/0428
- H04L9/32
- H04L63/123
- H04L63/205
- H04L2209/80
- H04W12/001
- H04W12/10
- IPC, 6
- H04L9 00
- H04L9 12
- H04L9 14
- H04L29 06
- H04W12 00
- H04W12 02
Designated states2
- Contracting states, 1
- Türkiye
- Extension states, 1
- North Macedonia