Updating negotiation method for authorization key and device thereof
Abstract
An updating negotiation method for the authorization key and a device thereof is applied in a communication network. In the network side, the control parameter for controlling the authorization key updating is set; the terminal transmits the request message for key updating to the network side, which carries the information corresponding to the control parameter for controlling the authorization key updating; the network side receives the request message for key updating, then determines whether the information corresponding to the control parameter for controlling the authorization key updating is valid, based on the reserved control parameter, if yes, processes the key updating, if no, ends the procedure. According to present invention, it is prevented that the illegal user updates the authorization key by the user card cloned illegally.

Term
No projected expiry on record.
- Priority
- Filed
- Published
- Today
18 claims: 4 independent, 14 dependent
- 1A method for negotiating a key update, wherein a control parameter for controlling an update of an authentication key is preset on a network side; the method includes:The terminal sends a key update request message and related information of a control parameter for controlling the authentication key update to the network side;After receiving the key update request message, the network side determines whether the related information of the control parameter from the terminal is legal according to the control parameter saved by the network side, and performs authentication when the related information of the control parameter is legal. Key update.
- 8The method according to any one of claims 1, 2, 4, 5 or 6, wherein the method further comprises:when the terminal sends a key update request message to the network side, carrying the first random number generated by the terminal;After receiving the key update request message sent by the terminal, the network side calculates the second calculation result according to the authentication key of the corresponding terminal user and the first random number, and sends the second calculation result to the terminal;After receiving the second calculation result sent by the network side, the terminal calculates the first calculation result according to the authentication key saved by the terminal and the first random number, and the terminal compares whether the second calculation result and the first calculation result are consistent. If it is inconsistent, it is considered that the network side is illegal, and the key update process is ended;otherwise, the related information of the control parameter for controlling the authentication key update is sent to the network side.
- 14An apparatus for implementing a key update negotiation, which is used to implement a key update negotiation between a terminal and a network side, and is characterized by:a key update request message generating unit, configured to generate a key update request message requesting to update the authentication key;An authentication key saving unit, configured to save an authentication key of the terminal;a control parameter obtaining unit, configured to acquire a control parameter for controlling the update of the authentication key;and a related information generating unit of the control parameter, configured to generate related information according to the control parameter acquired by the control parameter acquiring unit when requesting the update of the authentication key .
- 17An apparatus for implementing a key update negotiation, which is used to implement a key update negotiation between a terminal and a network side, and is characterized by:An authentication key saving unit, configured to save an authentication key of the terminal;a control parameter storage unit, configured to store a control parameter for controlling the update of the authentication key;a key update request message receiving unit, configured to receive a key update request message from the terminal requesting to update the authentication key;a related information parsing unit of the control parameter, configured to parse relevant information of the control parameter of the control authentication key update from the terminal;The related information verification unit of the control parameter is configured to determine, according to the control parameter stored by the control parameter storage unit, whether the related information from the terminal is legal after receiving the key update request message.
Independent claims4
140 paragraphs in 1 section, as filed
0001Key update negotiation method and device
0002The present invention relates to communication security technologies, and in particular, to an authentication key update negotiation method and apparatus.
0003Background technique
0004In the Global System for Mobile Communication (GSM), the International Mobile Subscriber Identification (IMSI) is stored in the mobile terminal, and the authentication key KI is in the home location register/authentication center (HLR). In the /AUC, Home Location Register/Authentication Center, IMSI and KI are saved for the mobile terminal for mutual authentication of the mobile terminal and the network. Among them, IMSI and KI remain unchanged throughout the life of the user card.
0005Existing third generation (3G, 3<sup>Rf</sup> In the mobile communication system, the international mobile subscriber identity IMSI, the authentication key KI and the serial number SQNMS are stored in the mobile terminal, and the IMSI, the KI and the serial number SQNHE are saved for the mobile terminal in the HLR/AUC for mobile The terminal and the network authenticate each other. Among them, IMSI and KI remain unchanged throughout the life of the user card.
0006The existing authentication procedures for 3G communication systems are mainly:
0007The HLR/AUC generates a random number RAND, generates an expected response XRES, an encryption key CK, an integrity key IK according to the random numbers RAND and KI, and generates a message authentication code according to the RAND, the serial number SQNHE, the KI, and the authentication management domain AMF. MAC-A, according to MAC-A. SQNHE, the anonymous key AK and AMF get the authentication token AUTN (Authentication Token).
0008The authentication quintuple is composed of RAND and XRES, CK, IK and AUTN, and the quintuple is sent to the mobile switching center/visit location register (MSC VLR, Mobile Switch Center/Visit Location Register) for storage. Of course, in practice, the HLR/AUC sends the corresponding one or more five-tuples to the MSC/VLR at the request of the MSC/VLR.
0009At the time of authentication, the MSC/VLR sends the RAND and AUTN corresponding to the quintuple to the terminal; the terminal verifies the consistency of the AUTN according to the KI saved by itself, and if the consistency certificate fails, the authentication failure information is returned to the MSC/VLR. If the consistency verification is passed, it is determined whether the SQNHE belongs to an acceptable range: If it belongs, the terminal determines that the network authentication is passed, and the terminal returns its own authentication response to the MSC/VLR, and updates according to the SQNHE in the AUTN. SQNMS; The MSC/VLR compares the authentication response returned by the terminal with the XRES in the corresponding quintuple to determine the legitimacy of the terminal. If it is determined that the SQNHE is not within the acceptable range, the terminal generates a resynchronization token AUTS (Resynchronisation Token) according to the SQNMS. Returning a resynchronization request or a Synchronisation Failure message to the MSC/VLR, and attaching the generated resynchronization flag AUTS, That is, the message contains AUTS. When the MSC VLR receives the resynchronization flag AUTS, it sends the AUTS and the RAND in the corresponding quintuple to the HLR/AUC. The HLR/AUC judges the legality of the AUTS according to the corresponding saved KI and the received RAM. If it is not legal, the HLR AUC returns the AUTS invalid information to the MSC/VLR; if it is determined that the AUTS is legal, the HLR/AUC is based on the AUTS. SQNMS in the update SQNHE, And a new authentication quintuple is sent to the MSC/VLR; after receiving the new quintuple, the MSC/VLR deletes the corresponding quintuple of the day and re-authenticates the terminal by using the new quintuple. 1
0010The terminal determines whether the SQNHE is acceptable by comparing whether the SQNHMS in the saved SQNMS and the AUTN meet the predetermined condition, and the predetermined condition may be that the difference between the SQNHE and the SQNMS is within a predetermined range, for example, whether (SQNHE - SQNMS) ) is greater than 0, or whether (SQNHE - SQNMS) is greater than 0 and less than 256. If the difference between the SQNHE and the SQNMS is within the predetermined range, it is determined that the SQNHE is acceptable; otherwise, it is determined that the SQNHE is unacceptable.
0011Whether it is the second-generation GSM system or the three-generation Wideband Code Division Multiple Access (WCDMA) system, there may be user card cloning. User card cloning is a ubiquitous problem in GSM system applications, and it is easy to operate; WCDMA system enhances the security of the protocol, making the authentication key in the user card more secure. However, those skilled in the art know that the key to cloning a user card is to break the authentication key of the user card. Therefore, like the GSM system, in the WCDMA system, WCDMA is made due to the invariance of the authentication key in the user card. This security of the system is also temporary. It is difficult to ensure that the authentication key in the user card is not compromised in future applications. Therefore, the problem of the user card being cloned cannot be fundamentally solved in the WCDMA system.
0012The phenomenon of cloning a user card not only causes losses to legitimate users, but also affects the service quality of operators. One of the most effective means of anti-user card cloning in the prior art is to continuously update the authentication key of the user card, and by updating the authentication key, the purpose of preventing the illegal user card from continuing to be used can be achieved. For example, by constantly updating the authentication key of the user card, it is possible to avoid or find that the legitimate user card is cloned. According to this method, by using the authentication key update, it is possible to effectively prevent the simultaneous use of the legitimate user card and the cloned user card. For example, by updating the authentication key, the legitimate user card can make the cloned user card unable to pass the authentication, and thus cannot continue to use.
0013However, the problem with this scheme is that it is impossible to prevent the illegal user card from updating the authentication key by the same method. For example, before the legitimate user card updates the authentication key, the user card and the legal user card are clamped. When the right key is the same, the cloned user card preemptively initiates the negotiation process of updating the authentication key, so that the authentication key stored in the HLR/AUC and the authentication key in the cloned user card are updated synchronously, the legal user Since the authentication key of the card is not updated, it becomes an invalid authentication key, and the legitimate user card cannot be used.
0014Although, in this case, when the legitimate user finds that his user card cannot be used, he can realize that the user card is cloned, and can change the authentication key in the HLR/AUC to the business hall and refresh the user card at the same time. The authentication key makes the authentication key in the HLR/AUC and the authentication key of the user card again consistent, so that the legitimate user card can continue to be used, and the illegally cloned user card can no longer be used, but this processing The process can cause problems for the user and also increase the workload of the staff of the business hall.
0015Therefore, how to effectively negotiate the update of the authentication key makes it impossible for the cloned user card to perform a valid authentication key update operation, which is a problem worth studying.
0016Summary of the invention
0017The present invention provides a key update negotiation method and device, which can prevent an illegal user from updating the authentication key by cloning the user card, thereby causing the legitimate user card to continue to be used.
0018According to an aspect of the present invention, a key update negotiation method is configured to preset a control parameter for controlling an authentication key update on a network side, where the method includes:
0019The terminal sends a key update request message and related information of a control parameter for controlling the authentication key update to the network side;
0020After receiving the key update request message, the network side determines whether the related information of the control parameter from the terminal is legal according to the control parameter saved by the network side, and performs the check when the related information of the control parameter is legal. The right key is updated.
0021Optionally, the related information of the control parameter used to control the update of the authentication key is the control parameter itself, and is carried in the key update request message;
0022Determining, according to the control parameter saved by the network side, whether the control parameter related information from the terminal is legal: whether the network side saves the control parameter saved by the network side and the control parameter from the terminal are consistent; The related information is considered to be legal; otherwise, the related request information is considered illegal.
0023Optionally, the related information of the control parameter used to control the authentication key update is calculated according to the control parameter;
0024Determining whether the control parameter related information from the terminal is legal according to the control parameter saved by the network side is specifically: the network side performs corresponding calculation according to the control parameter saved by the network side, and compares the calculated calculation result with the Whether the related information of the control parameter of the terminal is consistent; if the information is consistent, the related information is considered to be legal; otherwise, the related information is considered to be illegal.
0025Optionally, the calculating according to the control parameter is specifically: the terminal calculates, according to the control parameter and the authentication key used to control the authentication key update, the related information;
0026The network side performs corresponding calculation according to the control parameter saved by the network side. Specifically, the network side performs corresponding calculation according to the control parameter saved by the network side and the authentication key of the corresponding terminal user.
0027Optionally, the calculating according to the control parameter is specifically: the terminal calculates the related information according to a control parameter used to control the update of the authentication key and a random number;
0028The network side performs corresponding calculation according to the control parameter saved by the network side, and specifically: performing corresponding calculation according to the control parameter saved by the network side and the random number;
0029The random number is saved or generated by the terminal and sent to the network side, or generated by the network side and sent to the terminal.
0030Optionally, the calculating according to the control parameter is specifically: the terminal calculates the related information according to a control parameter, an authentication key, and a random number used to control the authentication key update;
0031The network side performs corresponding calculation according to the control parameter saved by the network side, and specifically: performing corresponding calculation according to the control parameter and the authentication key saved by the network side and the random number;
0032The random number is saved or generated by the terminal and sent to the network side, or generated by the network side and sent to the terminal.
0033Optionally, the terminal further includes performing an authentication key update; the terminal and the network side performing the key update are: the terminal and the network side respectively perform calculation according to the authentication key and the random number, and generate a new test by using a consistent algorithm. Right key.
0034Optionally, the method further includes: when the terminal sends a key update request message to the network side, carrying the first random number generated by the terminal;
0035After receiving the key update request message sent by the terminal, the network side calculates a second calculation result according to the authentication key of the corresponding terminal user and the first random number, and sends the second calculation result to the terminal;
0036After receiving the second calculation result sent by the network side, the terminal calculates the first calculation result according to the authentication key saved by the terminal and the first random number, and the terminal compares whether the second calculation result and the first calculation result are consistent. If they are inconsistent, the network side is considered to be illegal, and the key update process is ended; otherwise, the related information of the control parameters for controlling the authentication key update is sent to the network side.
0037Optionally, after receiving the key update request message sent by the terminal, the network side further generates a second random number and sends the second random number to the terminal;
0038The calculating according to the control parameter is specifically: the terminal calculates, according to the obtained control parameter, the saved authentication key, the first random number, and the second random number, the related information of the obtained control parameter;
0039The network side performs corresponding calculation according to the control parameter saved by the network side, where the network side saves the control parameter saved by the network side, the authentication key of the corresponding terminal user, and the first random number and the second random number. Performing a calculation to obtain a fourth calculation result, the network side compares the fourth calculation result calculated by itself with the related information, and if the information is inconsistent, the related information is considered to be illegal; otherwise, the network side determines the authentication according to the corresponding terminal user. The key and the first random number and at least one of the second random numbers are calculated to generate a new authentication key.
0040Optionally, the method further includes: the terminal performing an authentication key update.
0041Optionally, the terminal includes a user equipment and a user card, and the preset control parameter refers to a control parameter set in the user equipment or a control parameter set in the user card.
0042Optionally, the control parameter is a password, or an identity of the terminal, or any value customized by the user.
0043According to another aspect of the present invention, an apparatus for implementing a key update negotiation is used to implement key update negotiation between a terminal and a network side;
0044a key update request message generating unit, configured to generate a key update request message requesting to update the authentication key;
0045An authentication key saving unit, configured to save an authentication key of the terminal;
0046a control parameter obtaining unit, configured to acquire a control parameter for controlling the update of the authentication key; and a related information generating unit of the control parameter, configured to generate related information according to the control parameter acquired by the control parameter acquiring unit when requesting the update of the authentication key .
0047Optionally, the method further includes: a random number obtaining unit, configured to acquire a random number and provide the related information generating unit of the control parameter;
0048The related information generating unit of the control parameter generates related information according to the control parameter acquired by the control parameter acquiring unit, specifically: generating the control parameter itself, or generating according to the control parameter calculation, or calculating according to the control parameter and the authentication key. Generated, or generated based on control parameters, authentication keys, and random numbers.
0049Optionally, the method further includes: the device is located in the terminal; the terminal includes a user equipment and a user card; the key update request message generating unit, the authentication key holding unit, the related information generating unit of the control parameter, and the random The number acquisition unit is located in the user card; the control parameter acquisition unit is located in the user equipment or the user card.
0050According to still another aspect of the present invention, an apparatus for implementing a key update negotiation is used to implement key update negotiation between a terminal and a network side;
0051An authentication key holding unit, configured to store an authentication key of the terminal; a control parameter storage unit, configured to store a control parameter for controlling the update of the authentication key; and a key update request message receiving unit, configured to receive the request from the terminal Updating a key update request message of the authentication key;
0052a related information parsing unit of the control parameter, configured to parse relevant information of the control parameter of the control authentication key update from the terminal;
0053The related information verification unit of the control parameter is configured to determine, according to the control parameter stored by the control parameter storage unit, whether the related information from the terminal is legal after receiving the key update request message.
0054Optionally, the method further includes: a random number unit, configured to obtain a random number and provide the related information verification unit of the control parameter.
0055In the technical solution provided by the present invention, when transmitting a key update request, the terminal is required to carry a related information of a control parameter, and the network side verifies the validity of the related information of the control parameter, thereby determining that the key is updated. Whether the request message is legal, so that the network side avoids the problem of incorrectly responding to the key update request of the illegally cloned user card and the resulting normal user card being unusable. Therefore, even if the illegal user clones the user card, the authentication key cannot be updated by the cloned user card, thereby preventing the illegal user from updating the authentication key through the illegally cloned user card.
0056Since the legal user card can be set to the business hall by the identity or obtain the corresponding control parameter for controlling the authentication key update, the method can ensure that the legitimate user effectively performs the negotiation operation of the authentication key. In this way, the legitimate user card updates the authentication key continuously or periodically, which not only improves the security of the authentication key, but also prevents the normal use of the cloned user card.
DRAWINGS
00581 is a flow chart of a specific embodiment of the present invention.
00592 is a flow chart of a first embodiment of a specific embodiment of the present invention.
0060Figure 3 is a flow chart of a second embodiment of a specific embodiment of the present invention.
00614 is a flow chart of a third embodiment of a specific embodiment of the present invention.
0062Detailed ways
0063In the key update negotiation method of the present invention, the key update control parameter is set on the network side HLR/AUC, and the terminal transmits the relevant information of the control parameter to the HLR/AUC when requesting the key update, and the network side HLR/AUC passes the terminal. Transmitting the related information to distinguish whether the user card requesting the key update is a legitimate user card, thereby ensuring that the HLR/AUC does not erroneously respond to a key update request initiated by an illegal clone user card, thereby ensuring that the cloned user card cannot be Long-term normal use.
0064In the present invention, control parameters for controlling the authentication of the authentication key may be set in the subscription data of the HLR/AUC terminal user. When the terminal needs to negotiate with the HLR/AUC to update the authentication key, it sends a key update request message to the HLR/AUC, and carries related information of the control parameter used to control the authentication key update, and the network side saves the information according to the self. The control parameter for controlling the authentication key update is used to verify whether the related information of the control parameter for controlling the authentication key update carried in the request key update message of the terminal is legal, thereby determining whether to perform the key update operation. When the control parameters saved by the terminal or input by the terminal user are consistent with the control parameters set by the HLR/AUC, The HLR/AUC determines that the related information of the control parameter for controlling the authentication key update carried in the request key update message of the terminal is legal. In this way, since the cloned user card does not know the control parameter information corresponding to the legal user card setting in the HLR7AUC, the cloned user card requests the authentication key update when negotiating with the HLR/AUC to update the authentication key. The message cannot carry the correct information about the control parameters used to control the authentication key update. Therefore, the HLR/AUC determines the control for controlling the authentication key update carried in the message requesting the key update. The information about the parameters is invalid. In this way, the cloned user card cannot effectively negotiate the update of the authentication key with the HLR/AUC.
0065In the present invention, the message transmission for negotiating the key update between the terminal and the HLR/AUC may be implemented by unstructured supplementary (additional) service data (USSD, Unstructured Supplementary Services Data), or may be implemented by a short message, or This is achieved by adding special signaling messages.
0066The control parameter used to control the key update of the present invention may be a password, such as a user PIN code (SPIN, Subscriber Personal Identification Number), or may be an identity of a terminal, such as an international mobile station device of the terminal. Identification (IMEI,
0067International Mobile Station Equipment Identity ); Of course, it can also be an arbitrary value customized by the user, for example, the user's alias, the user's avatar information, or the summary information of the user's avatar data, and the like. The specific embodiments of the present invention will be described in detail below with reference to the accompanying drawings.
0068In this embodiment, a control parameter for controlling the authentication key update is set in the subscription data of the corresponding end user in the HLR/AUC. The user can save the control parameters in the HLR/AUC's own subscription data through the business hall, or through the service telephone interface or the service website provided by the business hall. Of course, the control parameter can also be randomly generated by the HLR/AUC, and This control parameter is provided to the corresponding end user. The terminal includes a user equipment UE and a user card.
0069Referring to FIG. 1, when the authentication key needs to be updated, the following process is performed: In step 100, the HLR/AUC pre-stores the control parameters of the corresponding terminal user for controlling the authentication key update.
0070Step 101: The terminal acquires a control parameter, and obtains related information of the control parameter according to the control parameter.
0071Step 103: The terminal sends a key update request message to the network side, where the request message carries related information of a control parameter used to control the authentication key update.
0072Step 105: After receiving the key update request message, the network side determines whether the related information of the control parameter in the key update request message is legal according to the control parameter saved by itself; if it is legal, step 107 is performed; otherwise, End the key update process.
0073In step 107, the HLR/AUC generates a new authentication key.
0074After the HLR/AUC generates a new authentication key, the authentication of the terminal can be performed by replacing the original authentication key with the new authentication key. That is, the HLR/AUC generates an authentication tuple with a new authentication key. The authentication tuple includes a random number RAND, an expected response XRES, an encryption key CK, an integrity key IK, and an authentication token AUTN. When the authentication tuple is generated, the HLR/AUC calculates XRES, CK, and IK using the RAND generated by the random number generator and the new authentication key KI saved by itself. The AUTN is also generated according to RAND, KI, serial number SQNHE, and authentication management domain AMF.
0075When performing step 101 or step 103, the terminal may also generate a new authentication key. Only when the terminal and the HLR/AUC respectively generate a new authentication key, the two parties can pass the authentication when they use the new authentication key for mutual authentication. In practice, there may be cases where the terminal updates the authentication key, but the HLR/AUC does not update the authentication key. For example, for some reason, the HLR/AUC determines that the request message for updating the key by the terminal is illegal. The HLR/AUC will not update the authentication key. At this time, the terminal will not pass the authentication of the network by using the newly generated authentication key. In this case, the terminal can also use the original authentication key to access the network. Perform authentication. Therefore, after updating the authentication key, the terminal should also save the old authentication key before using the new authentication key to authenticate the network, and use the new authentication key to authenticate the network. , then delete the old authentication key.
0076The terminal includes a user equipment UE and a user card.
0077In step 101, the terminal acquiring the control parameter may be a UE corresponding to the storage control parameter, and the terminal directly acquiring the control parameter saved by the UE; or the user card may save the control parameter, and the terminal directly acquiring the control parameter saved by the user card; The terminal may prompt the user to input a control parameter, and the terminal acquires the control parameter according to the user input.
0078When neither the UE nor the user card saves the control parameter, the user may need to update the authentication key, that is, when the related information needs to be generated according to the control parameter, the UE prompts the user to input the control parameter, and the UE obtains the location according to the user input. The control parameters are described. The advantage of saving the control parameters in the UE or user card of the terminal is: It is not necessary to have the user input control parameters each time the authentication key is updated, which will have a better user experience.
0079In step 101, the related information of the control parameter obtained according to the control parameter may be the control parameter itself. Correspondingly, in step 105, the related information of the control parameter in the key update request message is determined according to the control parameter saved by itself. Whether it is legal or not means: The network side compares the control parameters saved by the network with the control parameters in the key update request message. If they are consistent, the related information is considered to be legal; otherwise, the related request information is considered illegal.
0080In step 101, the related information of the control parameter obtained according to the control parameter may be obtained by calculating the related information according to the control parameter, and correspondingly, determining, in step 105, the key update request message according to the control parameter saved by itself. Whether the relevant information of the control parameter is legal means that: the network side HLR/AUC performs corresponding calculation according to the control parameter saved by itself, and obtains a calculation result, and compares the calculation result calculated by the self and the control parameter in the key update request message. Whether the related information is consistent. If they are consistent, the related information is considered to be legal; otherwise, the related information is considered illegal.
0081In order to better illustrate the idea and meaning of the invention, the invention will be described in detail below by way of specific embodiments.
0082Please refer to FIG. 2. FIG. 2 shows a first embodiment of a specific embodiment of the present invention. In this embodiment, the terminal performs calculation according to the authentication key when calculating the related information, that is, the terminal calculates the related information according to the obtained control parameter and the authentication key; correspondingly, the network side HLR/AUC is based on itself. The saved control parameter and the authentication key of the corresponding terminal user are correspondingly calculated, and a calculation result is obtained, and the HLR/AUC compares the calculation result calculated by the self and the related information in the key update request message. To determine whether the request message is legal.
0083At step 200, the HLR/AUC pre-stores the control parameters of the corresponding end user for controlling the authentication key update.
0084Step 201: The terminal acquires control parameters, and calculates related information of the control parameter according to the control parameter and the authentication key.
0085Step 203: The terminal sends a key update request message to the network side, where the request message carries related information of a control parameter used to control the authentication key update.
0086Step 205: After receiving the key update request message, the network side HLR/AUC calculates a calculation result according to the control parameter saved by the user and the authentication key of the corresponding terminal user.
0087Step 207: The HLR/AUC compares the calculation result calculated by the self and the related information of the control parameter in the key update request message. If they are consistent, it is considered legal, and step 209 is performed; otherwise, the key update process is ended.
0088In step 209, the HLR/AUC generates a new authentication key.
0089In practice, since the authentication key is stored in the user card, if the control parameter is set in the user equipment UE, when the user card needs to calculate the related information according to the control parameter, the UE needs to transmit the control parameter to the user card. If the control parameter is set in the user card, when the user card needs to calculate the related information according to the control parameter, the control parameter saved by the user may be directly obtained, and the UE does not need to transmit the control parameter to the user card.
0090In this embodiment, in step 201, the terminal may use a random number instead of the authentication key to generate the related information. Correspondingly, in step 205, the HLR/AUC may calculate the calculation result according to the control parameter saved by itself and the random number, for the control parameter in the key update request message in step 207. Relevant information is compared for consistency. The random number may be saved or generated by the terminal and sent to the HLR/AUC, or may be generated by the HLR/AUC and sent to the terminal. In a specific implementation, the terminal may save the random number sent by the network side when the terminal is last authenticated. Alternatively, before transmitting the request key update message to the HLR/AUC, the terminal first sends a request message requesting a random number to the HLR/AUC, and the HLR/AUC sends the generated random number to the terminal through the message response. Or the terminal sends an update key preparation message to the HLR/AUC before sending the request key update message to the HLR/AUC, and carries the random number saved or generated by the terminal, and the HLR/AUC receives the message. After that, the random number is saved for subsequent processing of the key update request message.
0091For the security of the key update request message and the security of the newly generated authentication key, when the related information of the control parameter is generated, the random number and the authentication key may be simultaneously used, and at the same time, the authentication key is generated. It can be done according to a random number.
0092Please refer to FIG. 3. FIG. 3 shows a second embodiment of a specific embodiment of the present invention. In the embodiment, when the terminal generates the related information according to the acquired control parameter, the terminal performs not only according to the authentication key but also according to the random number, that is, the terminal calculates according to the obtained control parameter, the authentication key, and the random number. Correspondingly, the network side HLR/AUC performs corresponding calculation according to the control parameter saved by itself and the authentication key of the corresponding terminal user and the random number, and obtains a calculation result, and the HLR/AUC is compared by Whether the calculation result obtained by the self-calculation and the related information carried in the key update request message are consistent to determine whether the request message is legal or not, to determine whether to perform a key update operation. The random number is saved or generated by the terminal and sent to the network side, or generated by the network side and sent to the terminal. In this embodiment, the random number is generated by the network side and sent to the terminal.
0093At step 300, the HLR/AUC pre-stores the control parameters of the corresponding terminal user for controlling the authentication key update.
0094Step 301: The terminal sends a key update request message to the network side HLR/AUC.
0095Step 303: After receiving the key update request message sent by the terminal, the HLR/AUC generates a random number and sends the data to the terminal.
0096Step 305: The terminal calculates, according to the obtained control parameter, the authentication key, and the random number, information about the control parameter, and calculates a new weighting key according to the random number and the authentication key.
0097Here, the terminal acquiring the control parameter may be the UE corresponding to the storage control parameter, and the terminal directly acquiring the control parameter saved by the UE; or the user card may save the control parameter, and the terminal directly acquiring the control parameter saved by the user card; The terminal prompts the user to input a control parameter, and the terminal acquires the control parameter according to the user input.
0098When neither the UE nor the user card saves the control parameter, the user may need to update the authentication key, that is, when the related information needs to be generated according to the control parameter, the UE prompts the user to input the control parameter, and the UE obtains the location according to the user input. The control parameters are described. The advantage of saving control parameters in the UE or user card of the terminal is that the user is not required to enter control parameters each time the authentication key is updated, which results in a better user experience.
0099Step 307: The terminal sends the related information to the network side.
0100Step 309: After receiving the key update request message, the network side HLR/AUC calculates a calculation result according to the control parameter saved by the user and the authentication key of the corresponding terminal user and the random number.
0101Step 311: The HLR/AUC compares the calculation result calculated by the HLR/AUC with the related information, and if it is consistent, it is considered legal, and then performs step 313; otherwise, the key update process ends.
0102Step 313: The HLR/AUC calculates a new authentication key according to an algorithm that matches the authentication key of the corresponding terminal user and the random number by using the terminal to calculate a new authentication key.
0103In practice, since the authentication key is stored in the user card, if the control parameter is set in the user equipment UE, when the user card needs to calculate the related information according to the control parameter, the UE needs to transmit the control parameter to the user card. If the control parameter is set in the user card, when the user card needs to calculate the related information according to the control parameter, the control parameter saved by the user may be directly obtained, and the UE does not need to transmit the control parameter to the user card.
0104In order to further enhance the security of the user card, for the second embodiment, the terminal may further generate a random number, and use the random number and the random number generated by the network side to participate in the calculation of the related information, and the new authentication key. Calculation; It is also possible to increase the terminal's authentication of the HLR AUC.
0105Please refer to FIG. 4. FIG. 4 shows a third embodiment of a specific embodiment of the present invention. In the embodiment, when the terminal generates the related information according to the obtained control parameter, the terminal uses not only the authentication key but also two random numbers, where the first random number is generated by the terminal and sent to the HLR/AUC. The second random number is generated by the HLR/AUC and sent to the terminal. That is, the terminal calculates the related information according to the obtained control parameter, the authentication key, the first random number, and the second random number; correspondingly, the network side HLR/AUC according to the control parameter saved by itself, the corresponding terminal user The authentication key, the first random number and the second random number are correspondingly calculated to obtain a calculation result, and the HLR/AUC compares the calculation result calculated by the self and the related information carried in the key update request message. Consistently determine whether the request message is legal to determine whether to perform a key update operation. When the key update operation is performed, both the terminal and the HLR/AUC perform calculations based on the first random number and the second random number.
0106At step 400, the HLR/AUC pre-stores the control parameters of the corresponding end user for controlling the authentication key update.
0107Step 401: The terminal generates a first random number, sends a key update request message to the network side HLR/AUC, and carries the random number.
0108Step 403: After receiving the key update request message sent by the terminal, the HLR/AUC generates a second random number, according to the authentication key of the corresponding terminal user, the control parameter saved in advance by itself, the first random number, and the second random number. Calculating according to the first algorithm to obtain a second calculation result, and then transmitting the second random number and the second calculation result to the terminal.
0109Step 405: After receiving the second random number and the second calculation result sent by the HLR/AUC, the terminal according to the first algorithm according to the saved authentication key, the obtained control parameter, the first random number, and the second random number. The calculation is performed to obtain the first calculation result.
0110Step 407: The terminal compares whether the second calculation result and the first calculation result are consistent. If they are consistent, the HLR/AUC is considered to be legal, and step 409 is performed; otherwise, the HLR/AUC is considered illegal, and the key update procedure is ended.
0111Step 409: The terminal calculates, according to the acquired control parameter, the saved authentication key, the first random number, and the second random number, the second algorithm to obtain related information of the control parameter, and according to the first random number, the second The random number and the authentication key are calculated to generate a new authentication key, and the terminal sends the generated related information to the HLR/AUC.
0112The terminal acquiring the control parameter may be the UE corresponding to the storage control parameter, and the terminal directly acquires the control parameter saved by the UE; or the user card saves the control parameter, and the terminal directly obtains the control parameter saved by the user card; or the terminal prompts the user Entering control parameters, the terminal acquires the control parameters according to user input.
0113When neither the UE nor the user card saves the control parameter, the user may need to update the authentication key, that is, when the related information needs to be generated according to the control parameter, the UE prompts the user to input the control parameter, and the UE obtains the control parameter according to the user input. The control parameters. The advantage of saving control parameters in the UE or user card of the terminal is that the user is not required to enter control parameters each time the authentication key is updated, which results in a better user experience.
0114Step 411: After receiving the related information sent by the terminal, the network side HLR/AUC according to the control parameter saved by itself, the authentication key of the corresponding terminal user, the first random number, and the second random number according to the second The algorithm performs calculation to obtain the fourth calculation result.
0115Step 413: The HLR/AUC compares the calculated fourth calculation result with the related information received from the terminal. If they are consistent, the related information is considered to be legal, and step 415 is performed; otherwise, the key update process is ended. .
0116Step 415: The HLR/AUC calculates, according to an authentication key, a first random number, and a second random number of the corresponding terminal user, an algorithm that is consistent with the terminal to calculate a new authentication key, to generate a new authentication key.
0117When the terminal calculates the new authentication key in step 415 and the HLR/AUC in step 415, the terminal may also calculate only according to any one of the corresponding authentication key and the two random numbers. In the case where the new authentication key is calculated only based on the corresponding authentication key and the first random number, the operation of the terminal generating the new authentication key may not be performed in step 409, but is performed in step 401. A corresponding simplified application can be obtained by a person skilled in the art according to the embodiment and the simplified indication. Therefore, the simplified embodiment will not be described in detail herein.
0118As a simplified process, when the HLR/AUC calculates the second calculation result in step 403, it may be performed only according to the corresponding authentication key, the control parameter saved by itself and the first random number, and the second random number does not participate. Correspondingly, in step 405, the terminal may perform the first calculation result only according to the saved authentication key, the acquired control parameter, and the first random number, and the second random number does not participate in the calculation. . A corresponding simplified application can be obtained by those skilled in the art according to the embodiment and the simplified indication. Therefore, the simplified embodiment is not described in the present invention.
0119Of course, as a further processing, when the HLR/AUC calculates the second calculation result in step 403, it may be performed only according to the corresponding authentication key and the first random number, and the saved control parameter and the second random number are performed. Correspondingly, in step 405, the terminal may perform the first calculation result only according to the saved authentication key and the first random number, and the acquired control parameter and the second random number are not Participate in the calculation. A corresponding simplified application can be obtained by a person skilled in the art according to the embodiment and the presentization indication. Therefore, the simplified embodiment is not described in the present invention.
0120As a simplified process, when the terminal generates the related information in step 409, the terminal may calculate the related information of the control parameter based on the obtained control parameter, the saved authentication key, and the second random number, and the A random number does not participate in the calculation; correspondingly, when the fourth calculation result is calculated in step 411, the HLR7AUC calculates only the control parameter saved by itself, the authentication key of the corresponding terminal user, and the second random number to obtain the fourth The result is calculated and the first random number does not participate in the calculation. A corresponding simplified application can be obtained by those skilled in the art according to the embodiment and the simplified indication. Therefore, the present invention will not be described again.
0121It will be readily understood by those skilled in the art that the operation of calculating the fourth calculation result in step 411 can also be completed in step 403.
0122The first algorithm and the second algorithm may be the same. In practice, the calculation result may be changed by adjusting the parameter order. For example, when calculating the first calculation result and the second calculation result, performing the calculation according to the authentication key and the first random number, and then combining the calculation with other operation parameters; calculating the related information and the fourth calculation The result is first calculated according to the authentication key and the control parameter, and then combined with other operational parameters. The algorithm design will ensure that after adjusting the parameter order, different output results will be obtained.
0123The MSC/VLR is a circuit domain device. For a packet domain network, the corresponding MSC/VLR device is a Serving General Packet Radio Service Support Node (SGSN), so the present invention can be equally applied to a packet domain. .
0124In each of the foregoing specific implementations or embodiments, the terminal and the HLR/AUC generate a new authentication key, and calculate a first calculation result, a second calculation result, calculate related information of the control parameter, calculate a fourth calculation result, and the like. The calculation may be performed using a mature digest algorithm, and the corresponding digest algorithm may be referred to the book "Applied Cryptography" or related algorithm papers or reports; in particular, for the second and third embodiments, when a new key is generated, The algorithm of generating the encryption key CK or the integrity key IK by the random number RAND and the authentication key KI mentioned in the 3GPP protocol can be used.
0125The control parameter used to control the key update of the present invention may be a password, for example, a user PI code SPIN; or an identity of a terminal, such as an IMEI of the terminal; or, of course, a user-defined one. The value, for example, the user's alias, the user's avatar information, or a summary of the user's avatar data, and so on.
0126In an embodiment of the present invention, an apparatus for implementing key update negotiation for implementing key update negotiation between a terminal and a network side includes:
0127a key update request message generating unit, configured to generate a key update request message requesting to update the authentication key;
0128An authentication key saving unit, configured to save an authentication key of the terminal;
0129a control parameter obtaining unit, configured to acquire a control parameter for controlling the update of the authentication key; and a related information generating unit of the control parameter, configured to generate related information according to the control parameter acquired by the control parameter acquiring unit when requesting the update of the authentication key .
0130The apparatus may further include a random number acquisition unit for acquiring a random number and providing the related information generating unit of the control parameter.
0131The related information generating unit of the control parameter generates related information according to the control parameter acquired by the control parameter acquiring unit, specifically: generating the control parameter itself, or generating according to the control parameter calculation, or calculating according to the control parameter and the authentication key. Generated, or generated based on control parameters, authentication keys, and random numbers.
0132The device is located in the terminal; the terminal includes a user equipment and a user card; the key update request message generating unit, the authentication key holding unit, the related information generating unit of the control parameter, and the random number obtaining unit are located in the user card. The control parameter acquisition unit is located in the user equipment or the user card.
0133In another embodiment of the present invention, an apparatus for implementing key update negotiation for realizing key update negotiation between a terminal and a network side includes: an authentication key holding unit, configured to save an authentication secret of the terminal key;
0134a control parameter storage unit, configured to store a control parameter for controlling the update of the authentication key; a key update request message receiving unit, configured to receive a key update request message from the terminal requesting to update the authentication key;
0135a related information parsing unit of the control parameter, configured to parse relevant information of the control parameter of the control authentication key update from the terminal;
0136The related information verification unit of the control parameter is configured to determine, according to the control parameter stored by the control parameter storage unit, whether the related information from the terminal is legal after receiving the key update request message.
0137The apparatus may further include: a random number unit, a related information verification unit for acquiring the random number and providing the control parameter.
0138The apparatus of this embodiment may be located in the HLR/AUC on the network side.
0139For the specific working process of the device in the embodiment of the present invention, reference may be made to the process of the foregoing method, and details are not described herein.
0140It should be noted that each unit may be an independent entity, and may be combined and split according to requirements and actual conditions, and details are not described herein.
0141It is to be understood that the foregoing is only a preferred embodiment of the present invention, and is not intended to limit the invention, and any modifications, equivalents, improvements, etc., which are within the spirit and scope of the present invention, are included in the present invention. Within the scope of protection.
4 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4
Every citation, both ways
| Document | Relation | Office | Category | Cited during |
|---|---|---|---|---|
| US8737616B2 | Cited by | United States of America | – | Applicant |
| US9031240B2 | Cited by | United States of America | – | Applicant |
| US10999065B2 | Cited by | United States of America | – | Applicant |
| US8144877B2 | Cited by | United States of America | – | Applicant |
| US8300827B2 | Cited by | United States of America | – | Applicant |
| US10057769B2 | Cited by | United States of America | – | Applicant |
| US8023658B2 | Cited by | United States of America | – | Applicant |
| CN1209939A | Cites | China | X | Search report |
| US6907239B1 | Cites | United States of America | A | Search report |
5 members in 2 offices
Priority claims6
| Document | Office | Kind | Date |
|---|---|---|---|
| 200510037046 | China | A | |
| 200510113030 | China | A | |
| CN2005137046 | – | – | – |
| CN20051113030 | – | – | – |
| 2005100370461 | – | – | – |
| 2005101130304 | – | – | – |
Members5
| Document | Office | Kind | |
|---|---|---|---|
| CN1835633A | China | A | |
| WO2007025484A1This record | World Intellectual Property Organization (WIPO) | A1 | |
| CN100346668C | China | C | |
| CN101160784A | China | A | |
| CN101160784B | China | B |
5 legal events, as 2 offices reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | Office | |
|---|---|---|---|
| Ep: pct application non-entry in european phase122 | 122 | WO | |
| Wipo information: entry into national phaseWWE | WWE | WO | |
| Non-entry into the national phaseNENP | NENP | DE | |
| Wipo information: entry into national phaseWWE | WWE | WO | |
| Ep: the epo has been informed by wipo that ep was designated in this application121 | 121 | WO |
Numbers
- Publication
- 2007/025484
- Publication, DOCDB
- 2007025484
- Publication, EPODOC
- WO2007025484
- Application
- 2257
- Application, DOCDB
- 2006002257
- Application, EPODOC
- WO2006CN02257
Titles2
- English
- UPDATING NEGOTIATION METHOD FOR AUTHORIZATION KEY AND DEVICE THEREOF
- French
- PROCEDE DE NEGOCIATION DE MISE A JOUR POUR CLE D'AUTORISATION ET DISPOSITIF ASSOCIE
Classification
- CPC, 2
- H04L9/0891
- H04L63/06
- IPC, 1
- H04L9 32
Designated states4
- Regional, 4
- Zimbabwe
- Turkmenistan
- Türkiye
- Togo