EP3668043A1

Method for identifying encrypted data stream, device, storage medium, and system

Abstract

Embodiments of the present invention provide a method for identifying an encrypted data stream, a device, a readable storage medium and a system. The method can be applied to a core network device, and the method includes: receiving a data packet carrying authentication data which is sent by a user equipment (UE), where the authentication data includes a first authentication parameter, a first authentication result and an application identifier; obtaining, based on the first authentication parameter and a second authentication parameter, a second authentication result according to a set authentication algorithm, where the second authentication parameter is a pre-stored authentication parameter corresponding to the application identifier; establishing an association relationship between characteristic information of the data packet and the application identifier when the second authentication result is consistent with the first authentication result in comparison, where the association relationship is used for subsequently identifying an encrypted data stream which is sent by the UE and corresponds to the application identifier.

EP3668043A1, drawing sheet 1
Sheet 1 of 16

Term

Projected expiry 3 May 2038.

  1. Priority
  2. Filed
  3. Published
  4. Today
  5. Projected expiry

65 claims: 13 independent, 52 dependent

  1. 1
    A method for identifying an encrypted data stream, wherein the method is applied to a core network device, and the method comprises:receiving a data packet carrying authentication data sent by a user equipment (UE);wherein the authentication data comprises a first authentication parameter, a first authentication result and an application identifier;obtaining, based on the first authentication parameter and a second authentication parameter, a second authentication result according to a set authentication algorithm;wherein the second authentication parameter is a pre-stored authentication parameter corresponding to the application identifier;and establishing an association relationship between characteristic information of the data packet and the application identifier when the second authentication result is consistent with the first authentication result in comparison;wherein the association relationship is used for subsequently identifying an encrypted data stream which is sent by the UE and corresponds to the application identifier;the characteristic information of the data packet can comprise at least one or more of: an Internet protocol (IP) source address, an IP source port number, an IP destination address, an IP destination port number, a MAC source address, an IP source port number, a media access control MAC destination address, a MAC destination port number, a protocol type, and a virtual local area network (VLAN) label.
  2. 6
    The method according to any one of claims 2 to 4, wherein the first authentication parameter comprises a random number;the second authentication parameter comprises a public key Ka.
  3. 7
    The method according to any one of claims 2 to 4, wherein the obtaining, based on the first authentication parameter and a second authentication parameter, a second authentication result according to a set authentication algorithm comprises:obtaining, by a control plane of the core network device, the second authentication result according to the set authentication algorithm based on the first authentication parameter and the second authentication parameter.
  4. 8
    The method according to any one of claims 2 to 4, wherein the establishing an association relationship between characteristic information of the data packet and the application identifier when the second authentication result is consistent with the first authentication result in comparison comprises:transmitting, by a control plane of the core network device, a comparison result to the user plane of the core network when the second authentication result is consistent with the first authentication result in comparison;and establishing, by the user plane of the core network device, the association relationship between the characteristic information of the data packet and the application identifier.
  5. 13
    The method according to any one of claims 1 to 12, wherein the method further comprises:receiving effective time information sent by the UE;wherein the effective time information is used for indicating an effective duration of the association relationship for identifying the encrypted data stream.
  6. 16
    A method for transmitting an encrypted data stream, wherein the method is applied to a core network device, and the method comprises:receiving an effective time message sent by a user equipment (UE) after an association relationship between characteristic information of a data packet and an application identifier is established;wherein the effective time information is used for indicating an effective duration of the association relationship for identifying an encrypted data stream;performing, within the effective duration, encrypted data stream transmission with the UE based on the association relationship;receiving a release indication message sent by the UE;and releasing the association relationship based on the release indication message.
  7. 18
    A method for identifying an encrypted data stream, wherein the method is applied to a user equipment (UE), and the method comprises:sending a data packet carrying authentication data;wherein the authentication data is used for the core network device to perform authentication, and the authentication data comprises: a first authentication parameter, a first authentication result and an application identifier.
  8. 23
    The method according to any one of claims 18 to 22, wherein the method further comprises:sending an effective time message to the core network device;wherein the effective time information is used for indicating an effective duration of an association relationship between characteristic information of the data packet and the application identifier for identifying an encrypted data stream.
  9. 24
    The method according to any one of claims 18 to 22, wherein the method further comprises:sending a release indication message to the core network device;wherein the release indication message is used for releasing the association relationship.
  10. 25
    A method for transmitting an encrypted data stream, wherein the method is applied to a user equipment (UE), and the method comprises:sending an effective time message to a core network device;wherein the effective time information is used for indicating an effective duration of an association relationship between characteristic information of a data packet and an application identifier for identifying an encrypted data stream;performing, within the effective duration, encrypted data stream transmission with the core network device based on the association relationship;and sending a release indication message to the core network device;wherein the release indication message is used for releasing the association relationship.
  11. 26
    A method for identifying an encrypted data stream, wherein the method is applied to a core network device, and the method comprises:receiving service description information sent by a user equipment (UE);wherein the service description information comprises an application identifier and/or data stream description information;the data stream description information comprises at least one of: an IP source address, an IP source port number, an IP destination address, an IP destination port number, a MAC source address, a MAC source port number, a MAC destination address, a MAC destination port number, a protocol type and a VLAN label;and identifying an encrypted data stream transmitted by the UE according to an established association relationship between characteristic information of a data packet and the application identifier.
  12. 30
    The method according to any one of claims 27 to 29, wherein before identifying an encrypted data stream transmitted by the UE according to an established association relationship between characteristic information of a data packet and the application identifier, the method further comprises:determining that the service description information is credible.
  13. 33
    A method for identifying an encrypted data stream, wherein the method is applied to a user equipment (UE), and the method comprises:sending service description information to a core network device;wherein the service description information comprises an application identifier and/or data stream description information;the data stream description information comprises at least one of: an IP source address, an IP source port number, an IP destination address, an IP destination port number, a MAC source address, a MAC source port number, a MAC destination address, a MAC destination port number, a protocol type, and a VLAN label.
  14. 37
    The method according to any one of claims 33 to 36, wherein the method further comprises:sending authentication information to the core network device;wherein the authentication information comprises an authentication parameter and a first authentication result.
  15. 38
    A core network device, comprising:a first receiving part, an authenticating part and an establishing part;wherein, the first receiving part is configured to receive a data packet carrying authentication data sent by a user equipment (UE);wherein the authentication data comprises a first authentication parameter, a first authentication result and an application identifier;the authenticating part is configured to obtain, based on the first authentication parameter and a second authentication parameter, a second authentication result according to a set authentication algorithm;wherein the second authentication parameter is a pre-stored authentication parameter corresponding to the application identifier;and the establishing part is configured to establish an association relationship between characteristic information of the data packet and the application identifier when the second authentication result is consistent with the first authentication result in comparison;wherein the association relationship is used for subsequently identifying an encrypted data stream which is sent by the UE and corresponds to the application identifier;the characteristic information of the data packet can comprise at least one or more of: an Internet protocol (IP) source address, an IP source port number, an IP destination address, an IP destination port number, a MAC source address, an IP source port number, a media access control MAC destination address, a MAC destination port number, a protocol type, and a virtual local area network (VLAN) label.
  16. 45
    The core network device according to any one of claims 38 to 44, wherein the first receiving part is further configured to receive effective time information sent by the UE;wherein the effective time information is used for indicating an effective duration of the association relationship for identifying the encrypted data stream.
  17. 48
    A core network device, comprising:a message receiving part, a first transmitting part and a control part;wherein the message receiving part is configured to receive an effective time message sent by a user equipment (UE) after an association relationship between characteristic information of a data packet and an application identifier is established;wherein the effective time information is used for indicating an effective duration of the association relationship for identifying an encrypted data stream;the first transmitting part is configured to perform, within the effective duration, encrypted data stream transmission with the UE based on the association relationship;the message receiving part is further configured to receive a release indication message sent by the UE;and the control part is configured to release the association relationship based on the release indication message.
  18. 50
    A user equipment (UE), wherein the UE comprises:a second sending part configured to send a data packet carrying authentication data;wherein the authentication data is used for the core network device to perform authentication, and the authentication data comprises: a first authentication parameter, a first authentication result and an application identifier.
  19. 55
    The UE according to any one of claims 50 to 54, wherein the second sending part is further configured to send an effective time message to the core network device;wherein the effective time information is used for indicating an effective duration of an association relationship between characteristic information of the data packet and the application identifier for identifying an encrypted data stream.
  20. 56
    The UE according to any one of claims 50 to 54, wherein the second sending part is further configured to send a release indication message to the core network device;wherein the release indication message is used for releasing an association relationship.
  21. 57
    A UE, wherein the UE comprises:a message sending part and a second transmitting part, wherein the message sending part is configured to send an effective time message to a core network device;wherein the effective time information is used for indicating an effective duration of an association relationship between characteristic information of a data packet and an application identifier for identifying an encrypted data stream;the second transmitting part is configured to perform, within the effective duration, encrypted data stream transmission with the core network device based on the association relationship;and the message sending part is further configured to send a release indication message to the core network device;wherein the release indication message is used for releasing the association relationship.
  22. 58
    A core network device, comprising an information receiving part and an identifying part; wherein, the information receiving part is configured to receive service description information sent by a user equipment (UE); wherein the service description information comprises an application identifier and/or data stream description information; the data stream description information comprises at least one of:an IP source address, an IP source port number, an IP destination address, an IP destination port number, a MAC source address, a MAC source port number, a MAC destination address, a MAC destination port number, a protocol type and a VLAN label;and the identifying part is configured to identify an encrypted data stream transmitted by the UE according to an established association relationship between characteristic information of a data packet and the application identifier.
  23. 59
    A UE, comprising an information sending part configured to send service description information to a core network device; wherein the service description information comprises an application identifier and/or data stream description information; the data stream description information comprises at least one of:an IP source address, an IP source port number, an IP destination address, an IP destination port number, a MAC source address, a MAC source port number, a MAC destination address, a MAC destination port number, a protocol type, and a VLAN label.
  24. 60
    A core network device, wherein a first network interface, a first memory and a first processor;wherein, the first network interface is configured to receive and send signals in a process of receiving and sending information with other external network elements;the first memory is configured to store a computer program operable on the first processor;and the first processor is configured to perform steps of the method according to any one of claims 1 to 15 or any one of claims 16 to 17 or any one of claims 26 to 32 when running the computer program.
  25. 62
    A computer readable medium, having a program for identifying an encrypted data stream stored thereon, wherein the program for identifying an encrypted data stream implements steps of the method according to any one of claims 1 to 15 or any one of claims 18 to 24 when executed by at least one processor.
  26. 64
    A computer readable medium, having a program for identifying an encrypted data stream stored thereon, wherein the program for identifying an encrypted data stream implements steps of the method according to any one of claims 26 to 32 or any one of claims 33 to 37 when executed by at least one processor.
  27. 65
    A system for identifying an encrypted traffic, comprising a core network device and a user equipment, wherein, the user equipment is configured to send a data packet carrying authentication data; wherein the authentication data is used for the core network device to perform authentication, and the authentication data comprises:a first authentication parameter, a first authentication result and an application identifier;the core network device is configured to receive the data packet which is sent by a user equipment (UE) and carries the authentication data;obtain, based on the first authentication parameter and a second authentication parameter, a second authentication result according to a set authentication algorithm;wherein the second authentication parameter is a pre-stored authentication parameter corresponding to the application identifier;and establish an association relationship between characteristic information of the data packet and the application identifier when the second authentication result is consistent with the first authentication result in comparison;wherein the association relationship is used for subsequently identifying an encrypted data stream which is sent by the UE and corresponds to the application identifier.
Independent claims27