WO2013174267A1 - 无线局域网络的安全建立方法及系统、设备 - Google Patents
无线局域网络的安全建立方法及系统、设备 Download PDFInfo
- Publication number
- WO2013174267A1 WO2013174267A1 PCT/CN2013/076088 CN2013076088W WO2013174267A1 WO 2013174267 A1 WO2013174267 A1 WO 2013174267A1 CN 2013076088 W CN2013076088 W CN 2013076088W WO 2013174267 A1 WO2013174267 A1 WO 2013174267A1
- Authority
- WO
- WIPO (PCT)
- Prior art keywords
- key
- user equipment
- network element
- network
- element device
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Ceased
Links
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W12/00—Security arrangements; Authentication; Protecting privacy or anonymity
- H04W12/04—Key management, e.g. using generic bootstrapping architecture [GBA]
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W84/00—Network topologies
- H04W84/02—Hierarchically pre-organised networks, e.g. paging networks, cellular networks, WLAN [Wireless Local Area Network] or WLL [Wireless Local Loop]
- H04W84/10—Small scale networks; Flat hierarchical networks
- H04W84/12—WLAN [Wireless Local Area Networks]
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/06—Network architectures or network communication protocols for network security for supporting key management in a packet data network
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W12/00—Security arrangements; Authentication; Protecting privacy or anonymity
- H04W12/04—Key management, e.g. using generic bootstrapping architecture [GBA]
- H04W12/043—Key management, e.g. using generic bootstrapping architecture [GBA] using a trusted network node as an anchor
- H04W12/0431—Key distribution or pre-distribution; Key agreement
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W76/00—Connection management
- H04W76/10—Connection setup
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L2463/00—Additional details relating to network architectures or network communication protocols for network security covered by H04L63/00
- H04L2463/061—Additional details relating to network architectures or network communication protocols for network security covered by H04L63/00 applying further key derivation, e.g. deriving traffic keys from a pair-wise master key
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W12/00—Security arrangements; Authentication; Protecting privacy or anonymity
- H04W12/06—Authentication
Definitions
- WLAN Wireless Local Area Network
- WLAN networks for use in hotspots such as airports, stations, hotels, etc. to offload UE data traffic.
- operators generally deploy WLANs in open mode, and any UE can access WLAN nodes.
- the WLAN node redirects the UE to a specific webpage. After the user corresponding to the UE enters the correct username/password on the webpage, the UE can access the internet.
- the embodiments of the present invention provide a method, a system, and a device for establishing a security of a wireless local area network, which are used to improve the security performance of the communication between the UE and the WLAN in the prior art, and are used to improve the UE and the UE. Security performance between WLANs.
- the embodiment of the present invention provides a method for establishing a security of a wireless local area network, including: acquiring, by a user equipment, a first key; the first key being a network element in the user equipment and the accessed mobile communication network The shared key of the device when performing air interface security or the shared key deduction according to the user equipment and the network element device in the accessed mobile communication network when performing air interface security;
- the derivation parameter is determined by the user equipment and the network element device by negotiation;
- the user equipment establishes a secure connection between the derivation key and the WLAN node that obtained the derivation key, and the derivation key obtained by the WLAN node and the deduction of the user equipment acquired by the user equipment
- the keys are the same.
- the embodiment of the present invention further provides a security establishment method for a wireless local area network, including: receiving, by a WLAN node, an identity identifier of the user equipment sent by a user equipment; the WLAN node to the user The network element device in the mobile communication network accessed by the device sends a key request message carrying the identity identifier of the user equipment;
- the WLAN node receives the derivation key corresponding to the identity identifier of the user equipment sent by the network element device; the derivation key is derived by the network element device according to the first key and the derivation parameter.
- the first key is a shared key when the user equipment and the network element device perform air interface security, or is derived from a shared key when the user equipment and the network element device perform air interface security.
- the derivation parameter is determined by the user equipment and the network element device; the WLAN node establishes a secure connection between the derivation key and the user equipment that obtains the derivation key.
- the derivation key acquired by the user equipment is the same as the derivation key acquired by the WLAN node.
- the embodiment of the present invention further provides a security establishment method for a wireless local area network, including: receiving, by the network element device in the mobile communication network accessed by the user equipment, a key request message sent by the wireless local area network node;
- the key request message carries an identifier of the user equipment;
- the network element device obtains a corresponding derivation key according to the identity identifier of the user equipment in the key request message; the derivation key is performed by the network element device according to the first key and the derivation parameter
- the first key is a shared key when the network element device and the user equipment perform air interface security or a shared key when the network element device and the user equipment perform air interface security.
- the derivation parameter is determined by the network element device and the user equipment; the network element device sends the derivation key to the wireless local area network node for the wireless
- the local area network node establishes a secure connection between the derivation key and the user equipment that obtains the derivation key, and the derivation key acquired by the user equipment and the wireless local area network node receive the network element device to send The derivation key is the same.
- the embodiment of the present invention further provides a method for establishing a security of a wireless local area network, including: acquiring, by a user equipment, a first key; where the first key is in the user equipment and the accessed mobile communication network The shared key of the first network element device when performing air interface security or the shared key derivation when the user equipment and the first network element device in the accessed mobile communication network perform air interface security;
- the user equipment performs extended authentication protocol authentication with the first network element device or the second network element device according to the authentication user name and the authentication credential;
- the second network element device is configured in the mobile communication network.
- a network element device other than the first network element device the second network element device obtains the authentication user name and the authentication credential from the first network element device; or the second network element device Obtaining, by the first network element device, an identity identifier of the user equipment and the first key, and generating, according to the identity identifier of the user equipment and the first key, the generated username and location Authenticated credentials;
- the user equipment establishes a secure connection with the wireless local area network node after the authentication is completed.
- the embodiment of the present invention further provides a security establishment method for a wireless local area network, including:
- the first network element device in the mobile communication network that is accessed by the user equipment acquires the authentication user name and the authentication credential of the user equipment; the authentication user name and the authentication credential are based on the identity identifier of the user equipment and
- the first key is a shared key when the user equipment and the first network element device or the second network element device in the accessed mobile communication network perform air interface security or Obtaining according to the shared key deduction of the user equipment and the first network element device or the second network element device when performing air interface security;
- the first network element device performs extended authentication protocol authentication with the user equipment according to the authentication user name and the authentication credential;
- the first network element device After the authentication of the extended authentication protocol is successful, the first network element device sends an authentication completion to the wireless local area network node to indicate that a secure connection is established between the wireless local area network node and the user equipment.
- the embodiment of the present invention further provides a user equipment, including:
- An acquiring module configured to acquire a first key;
- the first key is a shared key when performing air interface security with a network element device in an accessed mobile communication network or according to the user equipment and access
- the network element device in the communication network is derived from the shared key deduction when performing air interface security;
- a derivation module configured to perform a derivation key according to the first key and the derivation parameter acquired by the acquiring module, where the derivation parameter is determined by the user equipment and the network element device; Establishing a secure connection between the derivation key derived from the derivation module and the WLAN node that obtains the derivation key, and the derivation key acquired by the WLAN node and the user equipment acquire The derivation key is the same.
- the embodiment of the present invention further provides a WLAN node device, which is characterized by:
- a receiving module configured to receive an identifier of the user equipment that is sent by the user equipment
- a sending module configured to send, to the network element device in the mobile communication network that is accessed by the user equipment, the a key request message of the identity identifier of the user equipment
- the receiving module is further configured to receive a derivation key corresponding to the identity identifier of the user equipment sent by the network element device, where the derivation key is performed by the network element device according to the first key and the derivation parameter
- the first key is a shared key when the user equipment and the network element device perform air interface security, or the air interface is executed according to the user equipment and the network element device in the accessed mobile communication network.
- the derivation parameter is determined by the user equipment and the network element device by using the shared key derivation;
- a establishing module configured to establish a secure connection between the derivation key received by the receiving module and the user equipment that obtains the derivation key, where the derivation key acquired by the user equipment is acquired by the WLAN node
- the derivation key is the same.
- the embodiment of the present invention further provides a network element device, where the network element device is located in a mobile communication network that is accessed by the user equipment, where the network element device includes:
- a receiving module configured to receive a key request message sent by a WLAN node; the key request message carries an identity identifier of the user equipment;
- An obtaining module configured to acquire, according to the identifier of the user equipment in the key request message received by the receiving module, a corresponding derivation key; the derivation key is based on the first key and the derivation parameter Performing a derivation; the first key is obtained by performing a shared key with the user equipment when performing air interface security or according to a shared key deduction when the user equipment performs air interface security;
- the derivation parameter is determined in agreement with the user equipment;
- the sending module is configured to send, to the WLAN node, the derivation key acquired by the acquiring module, where the WLAN node is based on the Establishing a secure connection between the derivation key and the user equipment that obtains the derivation key, the derivation key acquired by the user equipment, and the wireless local area network node receiving the derivation key sent by the network element device the same.
- the embodiment of the present invention further provides a security establishment system for a wireless local area network, including: the user equipment, the wireless local area network node device, and the network element device as described above.
- the embodiment of the present invention further provides a user equipment, including:
- An acquiring module configured to acquire a first key, where the first key is a shared key when the user equipment and the first network element device in the accessed mobile communication network perform air interface security or according to the user The device and the first network element device in the accessed mobile communication network are derived from the shared key deduction when performing the air interface security;
- a generating module configured to generate an authentication username and an authentication credential according to the identifier of the user equipment and the first key derivation of the acquiring module
- An authentication module configured to perform extended authentication protocol authentication with the first network element device or the second network element device according to the authentication user name and the authentication credential generated by the generating module, where the second network element device is a network element device other than the first network element device in the mobile communication network; the second network element device acquiring the authentication user name and the authentication credential from the first network element device; Obtaining, by the second network element device, the identity identifier of the user equipment and the first key from the first network element device, and deriving according to the identity identifier of the user equipment and the first key Generating the authentication username and the authentication credential;
- a establishing module configured to establish a secure connection with the WLAN node after the authentication module performs the extended authentication protocol authentication.
- the embodiment of the present invention further provides a network element device, where the network element device is located in a mobile communication network that is accessed by the user equipment, where the network element device includes:
- An obtaining module configured to obtain an authentication user name and an authentication credential of the user equipment, where the authentication user name and the authentication credential are generated according to an identifier of the user equipment and a first key deduction;
- a key is a shared key when the network element device or the second network element device of the user equipment performs air interface security, or performs air interface security according to the user equipment and the network element device or the second network element device. When the shared key is derived;
- An authentication module configured to expand with the user equipment according to the authentication username and the authentication credential Exhibition certification agreement certification;
- a sending module configured to send an authentication completion to the WLAN node after the extended authentication protocol is successfully authenticated, to indicate that a secure connection is established between the WLAN node and the user equipment.
- the embodiment of the present invention further provides a security establishment system for a wireless local area network, including: the user equipment and the network element device as described above.
- the security establishment method, system and device of the WLAN of the embodiment of the present invention can establish a secure connection between the UE and the WLAN node based on the derivation key, and the derivation key is deduced according to the first key and the derivation parameter, and the first key is obtained.
- the key is obtained by the user equipment and the shared key of the network element device in the accessed mobile communication network when performing air interface security or derived from the shared key; or the UE generates and generates according to the identity identifier of the UE and the first key.
- the user name and the authentication password are authenticated; and the UE performs EAP authentication with the network element device in the mobile communication network accessed by the UE according to the authentication user name and the authentication password, and establishes a secure connection between the UE and the WLAN node after the authentication is completed.
- the foregoing technical solution of the embodiment of the present invention can overcome the problem that the WLAN works in the open mode in the prior art, and the UE and the WLAN node do not establish a secure connection, and the data between the UE and the WLAN node is transmitted in a clear text manner, causing the UE to The security scheme of the communication between the WLAN nodes is poor.
- FIG. 1 is a flowchart of a method for establishing security of a WLAN according to the present invention.
- FIG. 2 is a flowchart of a method for establishing a security of a WLAN according to another embodiment of the present invention.
- FIG. 3 is a flowchart of a method for establishing security of a WLAN according to still another embodiment of the present invention.
- FIG. 4 is a signaling diagram of a method for establishing a security of a WLAN according to an embodiment of the present invention.
- FIG. 5 is a signaling diagram of a method for establishing security of a WLAN according to another embodiment of the present invention.
- FIG. 6 is a flowchart of a method for establishing security of a WLAN according to another embodiment of the present invention.
- FIG. 7 is a flowchart of a method for establishing security of a WLAN according to still another embodiment of the present invention.
- FIG. 8 is a schematic structural diagram of a UE according to an embodiment of the present invention.
- FIG. 9 is a schematic structural diagram of a UE according to another embodiment of the present invention.
- FIG. 10 is a schematic structural diagram of a WLAN node device according to an embodiment of the present invention.
- FIG. 11 is a schematic structural diagram of a network element device according to an embodiment of the present invention.
- FIG. 12 is a schematic structural diagram of a network element device according to another embodiment of the present invention.
- FIG. 13 is a schematic structural diagram of a UE according to another embodiment of the present invention.
- FIG. 14 is a schematic structural diagram of a network element device according to still another embodiment of the present invention.
- FIG. 15 is a schematic structural diagram of a security establishment system of a WLAN according to an embodiment of the present invention.
- FIG. 16 is a schematic structural diagram of a WLAN security establishing system according to another embodiment of the present invention.
- FIG. 1 is a flowchart of a method for establishing security of a WLAN according to an embodiment of the present invention.
- the execution entity of the WLAN security establishment method in this embodiment is a UE.
- the security establishment method of the WLAN in this embodiment may specifically include the following steps:
- the UE acquires a first key.
- the first key in this embodiment is a shared key when the network element device in the mobile communication network accessed by the UE and the UE is performing air interface security or according to the network element device in the mobile communication network accessed by the UE and the UE.
- the shared key deduction is performed when performing air interface security.
- the UE performs derivation according to the first key and the derivation parameter to obtain a derivation key.
- the derivation parameter is determined by the UE and the network element device.
- the UE establishes a secure connection between the devaluation key and the WLAN node that obtains the derivation key.
- the derivation key acquired by the WLAN node is the same as the derivation key acquired by the UE.
- the technical solution of the embodiment requires the WLAN node to obtain the derivation key.
- the WLAN node can request the derivation key from the network element device, and the network element device is based on the first key and the derivation.
- the parameter derivation obtains the derivation key, so that both the UE and the WLAN node can know the derivation key, and based on the push
- the key is played, and a secure connection is established between the UE and the WLAN node.
- both the UE and the network element device can learn the derivation parameters, and the derivation parameters can be considered as determined by the two parties.
- the derivation parameters may specifically be one or more.
- the derivation parameters may be agreed in advance by the UE and the network element device, or may be negotiated online when deriving the derivation key.
- the UE may provide some parameters as derivation parameters and then inform the network element device.
- the network element device provides some parameters as derivation parameters, and then informs the network element device.
- some parameters may be provided by the UE or some parameters may be provided by the network element device, and then the UE and the network element device exchange the parameters respectively provided by the UE, and the corresponding derivation parameters are jointly provided by the UE and the parameters provided by the network element device.
- the security establishment method of the WLAN in this embodiment by using the foregoing technical solution, the UE and the WLAN node can establish a secure connection based on the derivation key, which can overcome the WLAN working in the open mode, the UE and the WLAN node in the prior art. A security connection is not established, and the data between the UE and the WLAN node is transmitted in a clear text manner, which causes a defect in the security of communication between the UE and the WLAN node.
- the technical solution of the embodiment can be used in the UE and the WLAN node. Establish a secure connection between each other to improve the security of communication between the UE and the WLAN node.
- the embodiment further includes: the UE sending the identity identifier of the UE to the WLAN node, and the WLAN node sends the identifier to the network according to the identity identifier of the UE.
- the meta device requests to obtain a derivation key corresponding to the UE.
- step 101 may specifically include: performing, by the UE, the second key according to the first key and the derivation parameter, that is, the derivation key at this time is Is the second key.
- KDF ( , ) is a key derivation function ( KDF ) function, K and derivation parameters are used as inputs to the function, and Kw is the output of the function.
- the second key Kw HMAC-SHA256 (K, "WPAAVPA2 Personal”); the hash message authentication code (HMAC) is a type of cryptographic algorithm, HMAC-SHA256 ( , ) indicates a cryptographic algorithm function, "WPAAVPA2 Personal” is the agreed derivation parameter for deriving the second key Kw, and is used to identify the way the second key Kw is used by the UE and the WLAN network to pass the WPA/WPA2 personal.
- Establish a WLAN secure connection Establishing a WLAN secure connection through WPA/WPA2 personal is UE and The WLAN node establishes a method for establishing a WLAN security connection based on the pre-shared key.
- the pre-shared key between the UE and the WLAN network is the second key Kw.
- K is still the first key.
- the UE may establish a secure connection with the WLAN node according to the second key.
- the second key is obtained by the UE according to the first key and the derivation parameters determined by the UE, and can ensure that different UEs have different second keys, and each UE can be based on its corresponding
- the second key establishes a secure connection with the WLAN node, thereby effectively ensuring a secure connection between the UE and the WLAN node.
- step 101 may specifically include: performing, by the UE, deriving the second key according to the first key and the derivation parameter;
- the identity identifier of the WLAN node is derived to obtain a third key, wherein the UE can acquire the identity identifier of the WLAN node when starting to access the WLAN node.
- the network element device can also obtain the identity identifier of the WLAN node, and derive the third key according to the second key and the identity identifier of the WLAN node.
- the WLAN node may send a key request message carrying the identity identifier of the UE and the identity identifier of the WLAN node to the network element device.
- the network element device can know that the third key needs to be deduced according to the second key and the identity identifier of the WLAN node, and the third key is sent to the WLAN node.
- the third key can be known to both the UE side and the WLAN node side.
- HMAC-SHA256 ( , ) represents a cryptographic algorithm function and Kw represents a second key.
- the UE may establish a secure connection with the WLAN node according to the third key.
- the same UE can be used to establish a secure connection between the WLAN node and the WLAN node based on the second key.
- the security of the connection established between the UE and the WLAN node can be further enhanced.
- the WLAN node may send the identity identifier to the network element device, but this is not the method by which the network element device uniquely obtains the WLAN node identity identifier.
- the network element device may obtain the identity identifier of the WLAN node by using other methods.
- the network element device may receive a key request message that is sent by the WLAN node and carries the identity identifier of the UE, and may obtain the IP address of the WLAN node, and then according to the The IP address of the WLAN node acquires the identity identifier of the WLAN node.
- the network element device may also obtain the identity identifier of the WLAN node by using other methods.
- the WLAN node can also be a WLAN The MAC address of the node or other identity information that uniquely identifies the WLAN node.
- the identity identifier of the UE is a media access control (MAC) address of the UE, and an international mobile subscriber identity of the UE (International Mobile Subscriber Identification) Number; IMSI), UE's Temperate Mobile Subscribe Identity (TMSI), UE's Packet Temperate Mobile Subscribe Identity (P-TMSI), UE's global unique temporary identity (Globally Unique) Temporary Identity; GUTI), System Architecture Evolution Temporary Mobile Subscriber Identity (S-TMSI), UE's Radio Network Temporary Identifier (RNTI) or UE's mobile station international call Mobile Station International Integrated Services Digital Network Number (MSISDN).
- IMSI International Mobile Subscriber Identification
- TMSI Temperate Mobile Subscribe Identity
- P-TMSI Packet Temperate Mobile Subscribe Identity
- GUTI Globally Unique Temporary Identity
- S-TMSI System Architecture Evolution Temporary Mobile Subscriber Identity
- RNTI Radio Network Temporary Identifier
- MSISDN Mobile Station International Integrated Services Digital Network Number
- the network element device itself can acquire the identity identifier of the UE, and the UE does not need to send the identity of the UE to the network element device.
- Identifier When the identity identifier of the UE is the MAC address of the WLAN interface of the UE (or other identity identifier of the UE that the network element device cannot learn from itself), the UE in the above method is further based on the second key and the receiving network. Before the identity identifier of the WLAN node sent by the meta-device is derived to obtain the third key, the UE further sends the identity identifier of the UE to the network element device. Specifically, the UE may send the identity identifier of the UE to the network element device in an encrypted manner.
- the mobile communication network may be a Global System For Mobile Communication (GSM) network, a Universal Mobile Telecommunications System (UMTS), Long Term Evolution (LTE) system, Code Division Multiple Access (CDMA) network or General Packet Radio Service (GPRS) network; network element equipment can be base station controller of GSM network (Base Station Controller; BSC), UMTS Radio Network Controller (RNC), GPRS network Serving GPRS Support Node (SGSN), LTE system mobility management entity (Mobility Management Entity; MME ) or a base station (such as an eNB in an LTE system).
- GSM Global System For Mobile Communication
- UMTS Universal Mobile Telecommunications System
- LTE Long Term Evolution
- CDMA Code Division Multiple Access
- GPRS General Packet Radio Service
- network element equipment can be base station controller of GSM network (Base Station Controller; BSC), UMTS Radio Network Controller (RNC), GPRS network Serving GPRS Support Node (SGSN), LTE system mobility management entity (Mobility Management Ent
- the first key of step 100 in the foregoing embodiment for example, when the mobile communication network is a GSM network, and the corresponding network element device is a BSC, the UE The shared key with the BSC is Kc.
- Kc KDF
- the corresponding network element device is an SGSN in the core network node
- the shared key between the UE and the SGSN is Kc
- the first key K may be Kc, or a key derived from Kc. .
- the corresponding network element device is an RNC
- the shared key between the UE and the SGSN is CK/IK.
- the corresponding network element device is the MME in the core network node
- the shared key between the UE and the MME is Kasme, Knas.int or Knas.enc.
- the corresponding network element device may also be a shared key between the eNB, the UE and the eNB, Kenb, Krrc.int, Krrc.enc. Kup.enc, Kup.int, the first key.
- K may be a key in Kenb, Krrc.int. Krrc.enc. Kup.enc, Kup.int, etc., or may be a key derived from one or more of these keys.
- Method 1 The UE sends the identity identifier of the UE to the MME in a Non-Access Stratum (NAS) Security Mode Complete (SMP) message, and the MME forwards the identity identifier of the UE to the eNB through the S1 message. ;
- NAS Non-Access Stratum
- SMP Security Mode Complete
- Method 2 The UE sends the identity identifier of the UE to the eNB in the RRC message.
- the UE sends the UE's identity identifier (such as a MAC address) to the network element device and the WLAN node; the UE's identity identifier (such as a MAC address)
- the UE's identity identifier such as a MAC address
- the user's privacy may be exposed, so there is a need to secure the transmission of the UE's identity identifier (such as a MAC address) in some way.
- the transmission of the UE's identity identifier (such as a MAC address) can be protected in several ways:
- the UE's identity identifier (such as a MAC address) is transmitted in the encrypted message, such as some Radio Resource Control (RRC) messages, or a Non-Access Stratum (NAS).
- RRC Radio Resource Control
- NAS Non-Access Stratum
- the message can be cryptographically protected, so that the identity identifier of the UE can be transmitted in these encrypted RRC messages or NAS messages, thereby protecting the confidentiality of the identity identifier transmission of the UE, and preventing the attacker from using the identity identifier of the UE to the user.
- Privacy causes harm, such as Set tracking and so on.
- the RRC message or the NAS message that can be encrypted may include the following message: Attach Complete message, Routing Area Update (RAU) message completion (Complete), Tracking Area Update ( (Complete) message, Non-access Stratum Security Mode Complete (NAS SMC) message or UE capability transfer message, and so on.
- RAU Routing Area Update
- Complete Tracking Area Update
- NAS SMC Non-access Stratum Security Mode Complete
- the carrier may not have encryption enabled. Therefore, all RRC/NAS signaling cannot be protected.
- the UE and the controller/core network node can derive the fourth key Ka based on the first key K.
- the fourth key Ka is used to XOR the identity identifier of the UE, thereby ensuring the security of the identity identifier transmission of the UE.
- the fourth key Ka's deduction may also require the participation of some derivation parameters. These derivation parameters may require interaction between the UE and the network side.
- the MAC anonymity is a string indicating that the purpose of the key derivation in this embodiment is to implement the MAC address hiding function.
- the security establishment method of the WLAN in the foregoing embodiment by using the foregoing technical solution, the UE and the WLAN node can establish a secure connection based on the derivation key, which can overcome the WLAN working in the open mode, the UE and the WLAN node in the prior art. A security connection is not established, and the data between the UE and the WLAN node is transmitted in a clear text manner, which causes a defect in the security of communication between the UE and the WLAN node.
- the technical solution of the embodiment can be used in the UE and the WLAN node. Establish a secure connection between each other to improve the security of communication between the UE and the WLAN node.
- FIG. 2 is a flowchart of a method for establishing a security of a WLAN according to another embodiment of the present invention.
- the execution entity of the WALN security establishment method in this embodiment is a WLAN node.
- the security establishment method of the WALN in this embodiment may specifically include the following steps:
- the WLAN node receives an identity identifier of the UE sent by the UE.
- the WLAN node sends a key request message carrying the identity identifier of the UE to the network element device in the mobile communication network accessed by the UE.
- the WLAN node receives the derivation key corresponding to the identity identifier of the UE sent by the network element device.
- the derivation key is obtained by the network element device according to the first key and the derivation parameter, where the first key is The shared key of the UE and the network element device when performing the air interface security or the shared key derivation when the UE and the network element device perform the air interface security; the derivation parameter is determined by the UE and the network element device.
- the WLAN node establishes a secure connection between the UE based on the derivation key and the UE that obtains the derivation key.
- the derivation key obtained by the UE is the same as the derivation key obtained by the WLAN node, that is, when the technical solution of the embodiment is implemented, the UE can also obtain the derivation key, for example, the UE can perform the deduction according to the first key and the UE.
- the derivation of the parameter results in a derivation key.
- both the UE and the WLAN node can obtain the derivation key, and the security connection can be established based on the derivation key to ensure the security of communication between the UE and the WLAN node.
- the embodiment of the present invention is different from the foregoing embodiment shown in FIG. 1 in that: the foregoing embodiment shown in FIG. 1 describes the technical solution of the present invention on the UE side, and the present embodiment describes the technical solution of the present invention on the WLAN node side, and the remaining implementation. The process is completely the same. For details, refer to the description of the embodiment shown in FIG. 1 above, and details are not described herein again.
- the security establishment method of the WLAN in this embodiment by using the foregoing technical solution, the UE and the WLAN node can establish a secure connection based on the derivation key, which can overcome the WLAN working in the open mode, the UE and the WLAN node in the prior art. A security connection is not established, and the data between the UE and the WLAN node is transmitted in a clear text manner, which causes a defect in the security of communication between the UE and the WLAN node.
- the technical solution of the embodiment can be used in the UE and the WLAN node. Establish a secure connection between each other to improve the security of communication between the UE and the WLAN node.
- the "the WLAN node receives the derivation key corresponding to the identity identifier of the UE sent by the network element device” may specifically include: a WLAN node receiving network. a second key corresponding to the identity identifier of the UE sent by the meta-device, where the second key is determined by the network element device according to the identity identifier of the UE and the identity identifier of the UE stored in the network element device and the second key The second key is obtained by the network element device according to the first key and the derivation parameter; in the technical solution, the derivation key is the second key.
- the corresponding step 203 may specifically include: the WLAN node establishes a secure connection with the UE based on the second key.
- the second key is derived by using the first key and the derivation parameters determined by the UE, and can ensure that different UEs have different second keys, and each UE can be based on its corresponding second secret.
- a secure connection is established between the key and the WLAN node, so that a secure connection between the UE and the WLAN node can be effectively ensured.
- the step 202 "the WLAN node receives the derivation key corresponding to the identity identifier of the UE sent by the network element device” may include: the WLAN node receives the third key sent by the network element device, and the third key Deriving the network element device according to the second key and the identity identifier of the WLAN node; the second key is the identity identifier of the network element device according to the UE and the identity identifier of the UE stored in the network element device and the second secret Obtained by the correspondence between the keys; the second key is obtained by the network element device according to the first key and the derivation parameters determined in consultation with the UE.
- the network element device may receive the key request message that carries the identity identifier of the UE sent by the WLAN node, obtain the IP address of the WLAN node, and obtain the identity identifier of the WLAN node according to the IP address of the WLAN node, and apply the actual identifier.
- the medium network element device may also use other methods to obtain the identity identifier of the WLAN node.
- the WLAN node can be a WLAN node SSID, or a MAC address of a WLAN node or other identity information that uniquely identifies the WLAN node.
- the WLAN node establishes a security connection with the UE based on the derivation key, which may include: the WLAN node establishes a secure connection with the UE based on the third key.
- the derivation key is the third key, and the technical solution can ensure that the same UE uses different third keys when accessing the WLAN from different WLAN nodes, and each UE can be based on the corresponding Compared with establishing a secure connection between the WLAN node, the second key can further enhance the security of the connection established between the UE and the WLAN node.
- the WLAN node sends a key request carrying the identity identifier of the UE to the network element device in the mobile communication network accessed by the UE.
- the message may include: the WLAN node sends a key request message carrying the identity identifier of the UE and the identity identifier of the WLAN node to the network element device.
- the network element device can directly obtain the identity identifier of the WLAN node without indirectly obtaining the identity identifier of the WLAN node.
- the mobile communication network in the foregoing embodiment may be a GSM network, a UMTS, an LTE system, a CDMA network or a GPRS network; the network element device may be a BSC or a UMTS of the GSM network.
- RNC Radio Network Controller
- SGSN of GPRS network MME of LTE system or eNB in LTE system.
- the identity identifier of the UE is the MAC of the UE. Address, IMSI of the UE, TMSI of the UE, P-TMSI of the UE, GUTI of the UE, S-TMSI of the UE, RNTI of the UE, or MSISDN of the UE.
- the security establishment method of the WLAN in the foregoing embodiment by using the foregoing technical solution, the UE and the WLAN node can establish a secure connection based on the derivation key, which can overcome the WLAN working in the open mode, the UE and the WLAN node in the prior art. A security connection is not established, and the data between the UE and the WLAN node is transmitted in a clear text manner, which causes a defect in the security of communication between the UE and the WLAN node.
- the technical solution of the embodiment can be used in the UE and the WLAN node. Establish a secure connection between each other to improve the security of communication between the UE and the WLAN node.
- FIG. 3 is a flowchart of a method for establishing security of a WLAN according to still another embodiment of the present invention.
- the execution entity of the WLAN security establishment method in this embodiment is a network element device in the mobile communication network.
- the security establishment method of the WLAN in this embodiment may specifically include the following steps:
- the network element device in the mobile communication network that the UE accesses receives the key request message sent by the WLAN node; the key request message carries the identity identifier of the UE;
- the network element device acquires a corresponding derivation key according to the identity identifier of the UE in the key request message.
- the derivation key is obtained by the network element device according to the first key and the derivation parameter; wherein the first key is a shared key of the network element device and the UE when performing air interface security or according to the network element device and The UE derives the shared key derivation when performing air interface security.
- the derivation parameters are determined by the NE device in consultation with U.
- the network element device sends a derivation key to the WLAN node, so that the WLAN node establishes a secure connection between the derivation key and the U E that obtains the derivation key.
- the derivation key obtained by the UE is the same as the derivation key sent by the WLAN node to the network element device.
- the embodiment of the present invention is different from the embodiment shown in FIG. 1 or FIG. 2 in that: the foregoing embodiment shown in FIG. 1 describes the technical solution of the present invention on the UE side, and the embodiment shown in FIG. 2 describes the present invention on the WLAN node side.
- the technical solution, and the present embodiment describes the technical solution of the present invention on the network element device side in the mobile communication network, and the rest of the implementation process is completely the same. For details, refer to the description of the embodiment shown in FIG. 1 or FIG. 2, and no longer Narration.
- the security establishment method of the WLAN in this embodiment by adopting the above technical solution, the UE and the UE
- the WLAN nodes can establish a secure connection based on the derivation key, and can overcome the WLAN work in the open mode in the prior art.
- the UE and the WLAN node do not establish a secure connection, and the data between the UE and the WLAN node is transmitted in clear text.
- the security scheme of the communication between the UE and the WLAN node is poor.
- the technical solution of the embodiment can establish a secure connection between the UE and the WLAN node, and improve the security of communication between the UE and the WLAN node.
- the method further includes the following steps: 303.
- the network element device acquires the first key.
- step 303 “the network element device acquires the first key”
- step 301 “the network element device according to the identity identifier of the UE in the key request message.
- the network element device derives the second key according to the first key and the derivation parameter
- the corresponding step 301 may include: the network element device according to the second key and the identity identifier of the UE The correspondence between the two, and the identity identifier of the UE in the key request message, acquires the second key. That is, the derivation key in this embodiment is the second key.
- the corresponding step 302 the network element device sends the derivation key to the WLAN node for the WLAN node to establish a secure connection with the UE based on the derivation key
- the network element device sends the second key to the WLAN node.
- the WLAN node to establish a secure connection with the UE based on the second key.
- step 303 “the network element device acquires the first key”
- step 301 “the network element device obtains the corresponding derivation key according to the identity identifier of the UE in the key request message”
- the corresponding step 300 “the network element device receives the key request message carrying the identity identifier of the UE sent by the WLAN node” may further include: A key request message sent by the WLAN node carrying the identity identifier of the UE and the identity identifier of the WLAN node.
- the network element device may not carry the identity identifier of the WLAN node in the bearer key request message sent by the WLAN node, but the network element device itself obtains the identity identifier of the WLAN node, for example, the network element device may After receiving the key request message of the WLAN node that is sent by the WLAN node, the IP address of the WLAN node is obtained, and the identity identifier of the WLAN node is obtained according to the IP address of the WLAN node. Can be used Other methods obtain the identity identifier of the WLAN node.
- the WLAN node may be a WLAN node SSID, or a MAC address of a WLAN node or other identity information capable of uniquely identifying a WLAN node.
- the network element device obtains the corresponding derivation key according to the identity identifier of the UE in the key request message, which may include the following steps:
- the network element device acquires the second key according to the correspondence between the second key and the identity identifier of the UE, and the identity identifier of the UE in the key request message;
- the network element device derives the third key according to the second key and the identity identifier of the WLAN node in the key request message. That is, in the technical solution, the derivation key is the third key.
- the corresponding step 302 the network element device sends the derivation key to the WLAN node for the WLAN node to establish a secure connection with the UE based on the derivation key
- the network element device sends the third key to the WLAN node. , for the WLAN node to establish a secure connection with the UE based on the third key.
- the mobile communication network in the foregoing embodiment may be a GSM network, a UMTS, an LTE system, a CDMA network, or a GPRS network; the network element device may be a GSM network.
- BSC RNC of UMTS, SGSN of GPRS network, MME of LTE system or eNB in LTE system.
- the identity identifier of the UE is a MAC address of the UE, an IMSI of the UE, a TMSI of the UE, a P-TMSI of the UE, a GUTI of the UE, and a S of the UE.
- the step 300 before the network element device receives the key request message that carries the identity identifier of the UE sent by the WLAN node, may further include:
- the network element device receives the identity identifier of the UE sent by the UE.
- the network element device may receive the identifier of the UE that is sent by the UE in an encrypted manner.
- the encrypted message may be an encrypted Attach Complete message, a RAU message Complete message, or a TAU Complete message. , NAS SMC message or UE capability transfer message and so on.
- the identifier of the UE can be effectively protected by using the foregoing solution, so that the security of the derivation key can be effectively ensured, and the security connection between the UE and the WLAN node is further effectively enhanced.
- the optional technical solutions that can be applied to the network element device in the optional embodiment of the embodiment shown in FIG. 1 can be used in the optional embodiment of the embodiment shown in FIG.
- the security establishment method of the WLAN in the foregoing embodiment by using the foregoing technical solution, the UE and the WLAN node can establish a secure connection based on the derivation key, which can overcome the WLAN working in the open mode, the UE and the WLAN node in the prior art.
- a security connection is not established, and the data between the UE and the WLAN node is transmitted in a clear text manner, which causes a defect in the security of communication between the UE and the WLAN node.
- the technical solution of the embodiment can be used in the UE and the WLAN node. Establish a secure connection between each other to improve the security of communication between the UE and the WLAN node.
- FIG. 4 is a signaling diagram of a method for establishing a security of a WLAN according to an embodiment of the present invention.
- the mobile communication network as the GSM network
- the network element device as the BSC
- the UE's identity identifier as the MAC address of the UE as an example.
- the security establishment method of the WLAN in this embodiment may specifically include the following steps:
- the UE accesses the GSM network, and performs air interface security with the BSC in the GSM network.
- the UE and the BSC obtain the shared key when performing the air interface security, and acquire the first key based on the shared key.
- the first key is the shared key or derived based on the shared key.
- the UE sends a MAC address of the UE to the BSC.
- the UE may carry the MAC address of the UE in the RRC message to send to the BSC.
- the BSC may obtain from the BSC, and the step 401 may be omitted.
- the UE and the BSC derive the second key according to the first key and the derivation parameter.
- the derivation parameter can be determined by negotiation between the UE and the BSC. Steps 401 and 402 can be in no order.
- the BSC stores a correspondence between a MAC address of the UE and a second key.
- the WLAN node sends a key request message carrying the MAC address of the UE to the BSC. For example, when the UE sends the WiFi message to the WLAN node when the UE accesses the WLAN node, the MAC address of the UE is already notified to the WLAN node. There is technology and will not be described here.
- the BSC obtains a second key corresponding to the UE according to the MAC address of the UE in the key request message and the correspondence between the MAC address of the UE and the second key.
- the BSC sends the second key to the WLAN node.
- the UE and the WLAN node establish a WLAN secure connection based on the second key.
- the key request message sent by the WLAN node to the BSC may further carry the identifier of the WLAN node.
- the UE and the BSC may perform the second key and The identity identifier of the WLAN node is deduced to obtain a third key, and the corresponding BSC sends the third key to the WLAN node, and the corresponding UE and the WLAN node establish a secure connection based on the third key.
- the security establishment method of the WLAN in this embodiment by using the foregoing technical solution, the UE and the WLAN node can establish a secure connection based on the second key or the third key, which can overcome the WLAN working in the open mode in the prior art.
- the technical solution of the present embodiment is adopted, the security connection between the UE and the WLAN node is not established, and the data between the UE and the WLAN node is transmitted in a clear text manner, which causes a poor security performance of communication between the UE and the WLAN node.
- a secure connection can be established between the UE and the WLAN node to improve the security of communication between the UE and the WLAN node.
- FIG. 5 is a signaling diagram of a method for establishing security of a WLAN according to another embodiment of the present invention. This embodiment is based on the foregoing embodiment, and the technical solution of the embodiment of the present invention is described in detail by taking the mobile communication network as the LTE network, the network element device as the eNB, and the identity identifier of the UE as the MAC address of the UE as an example.
- the security establishment method of the WLAN in this embodiment may specifically include the following steps:
- the UE accesses the LTE network, and performs air interface security with the eNB in the LTE network, and the UE and the eNB obtain the shared key when performing the air interface security, and acquire the first key based on the shared key;
- the first key is the shared key or derived based on the shared key.
- the UE sends a MAC address of the UE to the MME.
- the UE sends the MAC address of the UE to the MME in the NAS SMC.
- the MME sends a MAC address of the UE to the eNB.
- the MME forwards the MAC address of the UE to the eNB through the SI message.
- the UE may also send the MAC address of the UE to the eNB in an RRC message.
- the BSC may obtain the BSC from itself, and the step 401 may be omitted.
- the UE and the eNB derive the second key according to the first key and the derivation parameter.
- the derivation parameter may be determined by the UE and the eNB through negotiation. Step 503 and step 501
- the eNB stores a correspondence between a MAC address of the UE and a second key.
- the WLAN node sends a key request message that carries the MAC address of the UE and the identity identifier of the WLAN node to the eNB.
- the eNB acquires a second key corresponding to the UE according to the MAC address of the UE in the key request message and the correspondence between the MAC address of the UE and the second key.
- the eNB and the UE derive a third key based on the WLAN node identifier in the second key and the key request message.
- the eNB sends the third key to the WLAN node.
- the UE and the WLAN node establish a WLAN secure connection based on the third key.
- the security establishment method of the WLAN in this embodiment by using the foregoing technical solution, the UE and the WLAN node can establish a secure connection based on the third key, which can overcome the WLAN working in the open mode, the UE and the WLAN in the prior art.
- a security connection is not established between the nodes, and the data between the UE and the WLAN node is transmitted in a clear text manner, which causes a defect in the security of the communication between the UE and the WLAN node.
- the technical solution of the embodiment can be used in the UE and the WLAN.
- a secure connection is established between the nodes to improve the security of communication between the UE and the WLAN node.
- FIG. 4 and 5 are only two alternative forms of the embodiment of the present invention. According to the embodiments shown in FIG. 1 to FIG. 3 and the corresponding alternative embodiments, other aspects of the present invention can also be inferred.
- the signaling diagram of the embodiment is not repeated here - for example.
- FIG. 6 is a flowchart of a method for establishing security of a WLAN according to another embodiment of the present invention. As shown in FIG. 6, the WLAN security establishment method of the embodiment is performed by the UE, and the security establishment method of the WLAN in this embodiment may specifically include the following steps:
- the UE acquires the first key.
- the first key in this embodiment is a shared key when the UE and the first network element device in the accessed mobile communication network perform air interface security, or the first key is a mobile communication network according to the UE and the access.
- the first network element device in the execution of the shared key deduction when performing the air interface security; the UE generates the authentication user name and the authentication credential according to the identity identifier of the UE and the first key deduction.
- the UE performs an Extensible Authentication Protocol (EAP) authentication according to the authentication user name and the authentication credential, and the first network element device or the second network element device.
- EAP Extensible Authentication Protocol
- the UE establishes a secure connection with the WLAN node after the authentication is completed.
- the second network element device in this embodiment obtains the authentication user name and the authentication credential from the first network element device; or the second network element device obtains the identity identifier and the first key of the UE from the first network element device, And generating an authentication username and an authentication credential according to the identity identifier of the UE and the first key derivation.
- the first network element device and the second network element device are only named for two network element devices. In actual applications, the names of the two network element devices can also be interchanged.
- the security establishment method of the WLAN in this embodiment by using the foregoing technical solution, the UE generates an authentication user name and an authentication password according to the identity identifier of the UE and the first key; and the UE connects to the UE according to the authentication user name and the authentication password.
- the network element device in the incoming mobile communication network performs EAP authentication, and the UE establishes a secure connection with the WLAN node after the authentication is completed.
- the first key is the user equipment and the network element device in the accessed mobile communication network.
- the shared key when performing air interface security or derived from the shared key.
- the UE and the WLAN node do not establish a secure connection, and the data between the UE and the WLAN node is transmitted in a clear text manner, resulting in the UE and the WLAN.
- the security scheme of the communication between the nodes is poor.
- a secure connection can be established between the UE and the WLAN node, and the security of communication between the UE and the WLAN node is improved.
- the mobile communication network in the foregoing embodiment may be a GSM network, a UMTS, an LTE system, a CDMA network, or a GPRS network;
- the network element device may be a BSC of a GSM network, an RNC of a UMTS, an SGSN of a GPRS network, or an LTE system.
- MME or eNB in the LTE system may be a GSM network, a UMTS, an LTE system, a CDMA network, or a GPRS network;
- the network element device may be a BSC of a GSM network, an RNC of a UMTS, an SGSN of a GPRS network, or an LTE system.
- MME or eNB in the LTE system.
- the identity identifier of the UE in the foregoing embodiment is a MAC address of the UE, an IMSI of the UE, a TMSI of the UE, a P-TMSI of the UE, a GUTI of the UE, an S-TMSI of the UE, an RNTI of the UE, or a UE.
- MSISDN MSISDN.
- FIG. 7 is a flowchart of a method for establishing a security of a WLAN according to still another embodiment of the present invention.
- the WLAN security establishment method of the embodiment is the first network element device, and the security establishment method of the WLAN in this embodiment may include the following steps:
- the first network element device in the mobile communication network accessed by the UE acquires the authentication user name and the authentication credential of the UE.
- the authentication user name and the authentication credential in this embodiment are generated according to the identifier of the UE and the first key derivation; the first key is the first network element device or the second in the UE and the accessed mobile communication network.
- the shared key of the network element device when performing air interface security, or the first key is a shared key when the air interface security is performed according to the first network element device or the second network element device in the mobile communication network that the UE accesses. Deduced from the deduction.
- the first network element device performs EAP authentication with the UE according to the authentication user name and the authentication credential. 702. After the EAP authentication is completed, the first network element device sends the authentication completion to the WLAN node to indicate that the WLAN node establishes security with the UE. connection.
- the embodiment is different from the embodiment shown in FIG. 6 in that: the embodiment shown in FIG. 6 describes the technical solution of the present invention on the UE side, and the embodiment is described on the first network element device side in the mobile communication network.
- the rest of the implementation process is completely the same.
- refer to the description of the embodiment shown in FIG. 6 and details are not described herein again.
- the first network element device obtains the authentication user name and the authentication credential of the UE, and performs EAP authentication with the UE according to the authentication user name and the authentication password, and completes the authentication. And sending an authentication completion to the WLAN node to indicate that the WLAN node establishes a secure connection with the UE; wherein the authentication username and the authentication credential are generated according to the identifier of the UE and the first key derivation; the first key is the UE The shared key of the first network element device or the second network element device in the mobile communication network that is connected to perform the air interface security or derived from the shared key.
- the embodiment it is possible to overcome the problem that the WLAN works in the open mode, and the UE and the WLAN node do not establish a secure connection, and the data between the UE and the WLAN node is transmitted in a clear text manner, resulting in the UE and the WLAN.
- the security scheme of the communication between the nodes is poor.
- a secure connection can be established between the UE and the WLAN node, and the security of communication between the UE and the WLAN node is improved.
- step 700 "The first network element device in the mobile communication network accessed by the UE acquires the authentication user name and the authentication credential of the UE" may specifically include the following steps: (1) The first network element device receives the identity identifier of the UE of the UE and the first key sent by the second network element device, where the first key is a shared key of the UE and the second network element device when performing air interface security or Based on the shared key deduction;
- the first network element device generates an authentication user name and an authentication credential according to the identity identifier of the UE and the first key derivation.
- the step of the first network element device to receive the authentication user name and the authentication credential of the UE in the mobile communication network that is accessed by the UE may include:
- the authentication user name and the authentication credential are generated by the second network element device according to the identifier of the UE and the first key, and the first key is the air interface performed by the UE and the second network element device.
- the shared key at security time or derived from the shared key.
- the method may further include the following steps: Step 100: The first network element device in the mobile communication network that is accessed by the UE acquires the authentication user name and the authentication credential of the UE. (a) the first network element device obtains the first key; the first key is the shared key of the first network element device and the UE when performing air interface security or derived according to the shared key;
- the first network element device generates an authentication user name and an authentication credential according to the identity identifier of the UE and the first key derivation.
- the mobile communication network in the foregoing embodiment may be a GSM network, a UMTS, an LTE system,
- the CDMA network or the GPRS network may be a BSC of a GSM network, an RNC of a UMTS, an SGSN of a GPRS network, an MME of an LTE system, or an eNB in an LTE system.
- the identity identifier of the UE in the foregoing embodiment is a MAC address of the UE, an IMSI of the UE, a TMSI of the UE, a P-TMSI of the UE, a GUTI of the UE, an S-TMSI of the UE, an RNTI of the UE, or a UE.
- MSISDN MSISDN.
- the first network element device obtains the authentication user name and the authentication credential of the UE, and performs EAP authentication with the UE according to the authentication user name and the authentication password, and after the authentication is completed, the UE and the WLAN node are configured. Establishing a secure connection; wherein the authentication username and the authentication credential are generated according to the UE identifier and the first key derivation; the first key is the first network element device or the second in the UE and the accessed mobile communication network; The shared key of the network element device when performing air interface security or derived from the shared key.
- the UE and the WLAN node do not establish a secure connection, and the data between the UE and the WLAN node is transmitted in a clear text manner, resulting in the UE and the WLAN.
- the security scheme of the communication between the nodes is poor.
- the technical solution of the embodiment of the present invention can establish a secure connection between the UE and the WLAN node, and improve the security of communication between the UE and the WLAN node.
- the aforementioned program can be stored in a computer readable storage medium.
- the program when executed, performs the steps including the foregoing method embodiments; and the foregoing storage medium includes: a medium that can store program codes, such as a ROM, a RAM, a magnetic disk, or an optical disk.
- FIG. 8 is a schematic structural diagram of a UE according to an embodiment of the present invention. As shown in FIG. 8, the UE in this embodiment may specifically include an obtaining module 10, a derivation module 11, and an establishing module 12.
- the obtaining module 10 is configured to acquire the first key, where the first key is the shared key of the UE in the mobile communication network of the embodiment and the network element device in the accessed mobile communication network, or the first secret Key is According to the shared key deduction of the network element device in the mobile communication network that the UE and the access mobile network performs when performing air interface security.
- the derivation module 11 is connected to the acquisition module 10.
- the derivation module 11 is configured to derive a derivation key according to the first key and the derivation parameters acquired by the acquisition module 10, and the derivation parameters are determined by the UE and the network element device.
- the establishing module 12 is connected to the derivation module 11.
- the establishing module is configured to establish a secure connection between the derivation key derived from the derivation module 11 and the WLAN node that obtains the derivation key, and the derivation key acquired by the WLAN node and the UE acquires The derivation key is the same.
- the WLAN node may request the derivation key from the network element device, and the network element device derives the derivation key according to the first key and the derivation parameter.
- both the UE and the network element device can learn the derivation parameters, and the derivation parameters can be considered as determined by the two parties.
- the derivation parameters may specifically be one or more.
- the derivation parameters may be agreed in advance by the UE and the network element device, or may be negotiated online when deriving the derivation key.
- the UE may provide some parameters as derivation parameters and then inform the network element device.
- the network element device provides some parameters as derivation parameters, and then informs the network element device.
- some parameters may be provided by the UE or some parameters may be provided by the network element device, and then the UE and the network element device exchange the parameters respectively provided by the UE, and the corresponding derivation parameters are jointly provided by the UE and the parameters provided by the network element device.
- the security establishment of the WLAN is the same as that of the foregoing method in the foregoing method.
- the security establishment of the WLAN is the same as that of the foregoing method in the foregoing method.
- the UE can establish a secure connection with the WLAN node based on the derivation key, and the WLAN can work in the open mode, and the UE and the WLAN node do not establish a secure connection.
- the data between the UE and the WLAN node is transmitted in a clear text manner, which causes a defect in the security of communication between the UE and the WLAN node.
- a secure connection can be established between the UE and the WLAN node. Improve the security of communication between the UE and the WLAN node.
- FIG. 9 is a schematic structural diagram of a UE according to another embodiment of the present invention. As shown in FIG. 9, the UE in this embodiment may further include the following technical solutions on the basis of the foregoing embodiment shown in FIG. 8.
- the UE in this embodiment includes a transmitting module 13.
- the sending module 13 is configured to send the identity identifier of the UE to the WLAN node, so that the WLAN node requests the network element device to obtain the derivation key corresponding to the UE according to the identity identifier of the UE.
- the derivation module 11 is specifically configured to perform a derivation according to the first key and the derivation parameters acquired by the obtaining module 10 to obtain a second key; the establishing module 12 is specifically configured to be deduced according to the derivation module 11 The second key is established to establish a secure connection with the WLAN node.
- the derivation module 11 is specifically configured to derive a second key according to the first key and the derivation parameter; and derive a third according to the second key and the identity identifier of the WLAN node. Key; The UE may acquire the identity identifier of the WLAN node when starting to access the WLAN node.
- the network element device can also obtain the identity identifier of the WLAN node, and derive the third key according to the second key and the identity identifier of the WLAN node.
- the establishing module 23 is specifically configured to establish a secure connection with the WLAN node according to the third key derived by the derivation module 11.
- the identifier of the UE is the MAC address of the UE, the IMSI of the UE, the TMSI of the UE, the P-TMSI of the UE, the GUTI of the UE, the S-TMSI of the UE, the RNTI of the UE, or UE's MSISDN.
- the sending module 13 in the UE in this embodiment is further configured to: when the identity identifier of the UE is the MAC address of the WLAN interface of the UE, send the identity identifier of the UE to the network element device.
- the sending module 13 is specifically configured to: when the identity identifier of the UE is the media access control address of the WLAN interface of the UE, send the identity identifier of the UE to the network element device in an encrypted manner.
- the UE in this embodiment may further include a carrying module, configured to perform an Attach Complete message, a RAID Complete message, a TAU Complete message, a NAS SMC message, or a capacity migration of the UE.
- the transfer identifier carries the identity identifier of the UE, and the sending module 13 sends an encrypted Attach Complete message carrying the identity identifier of the UE, a RAU message complete message (Complete) message, and TAU completion by the sending module 13 at the network element device. (Complete) message, NAS SMC message or UE capability transfer message, etc.
- the mobile communication network may be a GSM network, a UMTS, an LTE system, a CDMA network, or a GPRS network;
- the network element device may be a BSC of a GSM network, an RNC of a UMTS, an SGSN of a GPRS network, or an LTE network.
- the security of the WLAN is the same as that of the foregoing method in the foregoing embodiment.
- the UE of the foregoing embodiment by using the foregoing module, can enable the UE to establish a secure connection with the WLAN node based on the derivation key, and can overcome the WLAN work in the open mode in the prior art, and the UE and the WLAN node do not establish a secure connection.
- the data between the UE and the WLAN node is transmitted in a clear text manner, which causes a defect in the security of communication between the UE and the WLAN node.
- a secure connection can be established between the UE and the WLAN node.
- FIG. 10 is a schematic structural diagram of a WLAN node device according to an embodiment of the present invention.
- the WLAN node device in this embodiment may specifically include: a receiving module 20, a sending module 21, and a building module 22.
- the receiving module 20 is configured to receive the identity identifier of the UE that is sent by the UE, and the sending module 21 is configured to be connected to the receiving module 20, where the sending module 21 is configured to send, by the network element device in the mobile communication network accessed by the UE, the a key request message of the identity identifier of the UE; the receiving module 20 is further configured to receive a derivation key corresponding to the identity identifier of the UE sent by the network element device; the derivation key is a network element device according to the first key and the derivation parameter
- the first key is a shared key when the UE and the network element device perform air interface security, or the first key is derived from the shared key when the UE and the network element device perform air interface security.
- the derivation parameter is determined by the UE and the network element device.
- the determination of the derivation parameter may refer to the description of the related embodiment.
- the establishing module 22 is connected to the receiving module 20, and the establishing module 22 is configured to establish a secure connection between the derivation key received by the receiving module 20 and the UE that obtains the derivation key, where the derivation key acquired by the UE and the WLAN node acquire The derivation key is the same, for example, the UE can derive the derivation key according to the first key and the derivation parameter.
- the WLAN node device in this embodiment implements the security establishment of the WLAN by using the above-mentioned modules.
- the implementation mechanism of the foregoing method is the same. For details, refer to the description of the foregoing related method embodiments, and details are not described herein again.
- the WLAN node device in this embodiment can implement the secure connection between the UE and the WLAN node based on the derivation key by using the foregoing module, and can overcome the WLAN work in the open mode in the prior art, and the UE and the WLAN node do not establish security.
- the connection between the UE and the WLAN node is transmitted in a clear text manner, which causes a defect in the security of the communication between the UE and the WLAN node.
- a secure connection can be established between the UE and the WLAN node. Improve the security of communication between the UE and the WLAN node.
- the receiving module 20 is specifically configured to receive a second key corresponding to the identity identifier of the UE sent by the network element device, where the second key is a network element device according to the Obtaining the identity identifier of the UE and the correspondence between the identity identifier of the UE and the second key stored in the network element device; the second key is derived by the network element device according to the first key and the derivation parameter In this embodiment, the derivation key is the second key.
- the establishing module 22 is specifically configured to establish a secure connection with the UE based on the second key received by the receiving module 20.
- the sending module 21 is specifically configured to the network element based on the foregoing embodiment shown in FIG.
- the device sends a key request message carrying the identity identifier of the UE and the identity identifier of the WLAN node received by the receiving module 20;
- the receiving module 20 is specifically configured to receive a third key sent by the network element device, where the third key is a network And deriving from the second key and the identity identifier of the WLAN node;
- the second key is a network element device according to the identity identifier of the UE and the identity identifier and the second key of the UE stored in the network element device
- the second key is obtained by the network element device according to the first key and the derivation parameter.
- the derivation key is the third key.
- the establishing module 22 is specifically configured to establish a secure connection with the UE based on the third key received by the receiving module 20.
- the identity identifier of the UE is a MAC address of the UE, an IMSI of the UE, a TMSI of the UE, a P-TMSI of the UE, a GUTI of the UE, and an S-TMSI of the UE. , the RNTI of the UE or the MSISDN of the UE.
- the mobile communication network may be a GSM network, a UMTS, an LTE system, a CDMA network, or a GPRS network;
- the network element device may be a BSC of a GSM network, an RNC of a UMTS, or a GPRS.
- the WLAN node device of the foregoing embodiment implements the security establishment of the WLAN by using the foregoing module.
- the implementation mechanism of the foregoing method is the same. For details, refer to the description of the foregoing related method embodiments, and details are not described herein again.
- the WLAN node device of the foregoing embodiment can implement the secure connection between the UE and the WLAN node based on the derivation key by using the foregoing module, and can overcome the problem that the WLAN works in the open mode in the prior art, and the UE and the WLAN node do not establish security.
- the connection between the UE and the WLAN node is transmitted in a clear text manner, which causes a defect in the security of the communication between the UE and the WLAN node.
- a secure connection can be established between the UE and the WLAN node. Improve the security of communication between the UE and the WLAN node.
- FIG. 11 is a schematic structural diagram of a network element device according to an embodiment of the present invention.
- the network element device of this embodiment is located in a mobile communication network accessed by the UE.
- the network element device of this embodiment may specifically include: a receiving module 30, an obtaining module 31, and a sending module 32.
- the receiving module 30 is configured to receive a key request message sent by the WLAN node, where the key request message carries the identity identifier of the UE; the obtaining module 31 is connected to the receiving module 30, and the obtaining module 31 is configured to receive according to the receiving module 30.
- the shared key is used to perform the air interface security, or the first key is derived from the shared key when the network element device and the UE perform the air interface security; the derivation parameter is the network element device and the UE.
- the sending module 32 is connected to the obtaining module 31, and the sending module 32 is configured to send the derivation key acquired by the obtaining module 31 to the WLAN node, so that the WLAN node establishes between the UE based on the derivation key and the UE that obtains the derivation key. Secure connection.
- the derivation key obtained by the UE is the same as the derivation key sent by the WLAN node to the network element device.
- the network element device of this embodiment implements the security establishment of the WLAN by using the above-mentioned modules.
- the implementation mechanism of the foregoing related method embodiment is the same. For details, refer to the description of the foregoing related method embodiments, and details are not described herein again.
- the network element device of this embodiment can implement the secure connection between the UE and the WLAN node based on the derivation key by using the foregoing module, and can overcome the problem that the WLAN works in the open mode in the prior art, and the UE and the WLAN node do not establish security.
- the connection between the UE and the WLAN node is transmitted in a clear text manner, which causes a defect in the security of the communication between the UE and the WLAN node.
- a secure connection can be established between the UE and the WLAN node. Improve the security of communication between the UE and the WLAN node.
- FIG. 12 is a schematic structural diagram of a network element device according to another embodiment of the present invention. As shown in FIG. 12, the network element device of this embodiment may further include the following technical solutions on the basis of the foregoing embodiment shown in FIG.
- the obtaining module 31 is further configured to obtain the first key before acquiring the corresponding derivation key according to the identity identifier of the UE in the key request message.
- the network element device of this embodiment further includes a derivation module 33 and an establishment module 34.
- the derivation module 33 is connected to the acquisition module 31, and is configured to acquire, according to the identity identifier of the UE in the key request message, the acquisition module 31, after acquiring the first key, according to the acquisition module 31.
- the first key and the derivation parameter are deduced to obtain a second key;
- the establishing module 34 is connected to the derivation module 33, and the establishing module 34 is configured to establish a correspondence between the second key deduced by the derivation module 33 and the identity identifier of the UE. relationship.
- the corresponding obtaining module 31 is also connected to the establishing module 34, specifically for the correspondence between the second key established by the establishing module 34 and the identity identifier of the UE, and the identity of the UE in the key request message.
- the second key is obtained; that is, the derivation key is the second key in the technical solution.
- the corresponding sending module 32 is specifically configured to send the second key acquired by the acquiring module 31 to the WLAN node, so that the WLAN node establishes a secure connection with the UE based on the second key.
- the derivation module 33 is further configured to obtain the corresponding derivation key according to the identity identifier of the UE in the key request message after the acquiring module 31 acquires the first key.
- the second key is obtained by deriving according to the first key and the derivation parameter acquired by the obtaining module 31;
- the establishing module 34 is further configured to: when the correspondence between the second key acquired by the acquiring module 31 and the identifier of the UE is established, the receiving module 30 is specifically configured to receive the identifier of the carrying UE and the WLAN node sent by the WLAN node.
- the key request message of the identity identifier; the obtaining module 31 is specifically configured to use the correspondence between the second key established by the establishing module 34 and the identity identifier of the UE, and the UE in the key request message received by the receiving module 30. And the second identifier is obtained according to the second key and the identifier of the WLAN node in the key request message; the sending module 32 is specifically configured to send the obtaining module 31 to the WLAN node. Obtaining a third key for the WLAN node to establish a secure connection with the UE based on the third key. That is, in the technical solution, the derivation key is the third key.
- the identity identifier of the UE is the MAC address of the UE, the IMSI of the UE, the TMSI of the UE, the P-TMSI of the UE, the GUTI of the UE, the S-TMSI of the UE, and the UE. RNTI or MSISDN of the UE.
- the receiving module 30 is further configured to: when the identity identifier of the UE is the MAC address of the WLAN interface of the UE, receive the identity identifier of the UE sent by the UE.
- the receiving module 30 is further configured to: when the identity identifier of the UE is the MAC address of the WLAN interface of the UE, receive the identity identifier of the UE that is sent by the UE in an encrypted manner.
- the mobile communication network may be a GSM network, a UMTS, an LTE system, a CDMA network, or a GPRS network; the network element may be a BSC of a GSM network, an RNC of a UMTS, or a GPRS network.
- the network element device of this embodiment implements the security establishment of the WLAN by using the above-mentioned modules.
- the implementation mechanism of the foregoing related method embodiment is the same. For details, refer to the description of the foregoing related method embodiments, and details are not described herein again.
- the network element device of this embodiment can implement the secure connection between the UE and the WLAN node based on the derivation key by using the foregoing module, and can overcome the problem that the WLAN works in the open mode in the prior art, and the UE and the WLAN node do not establish security.
- the connection between the UE and the WLAN node is transmitted in a clear text manner, which causes a defect in the security of the communication between the UE and the WLAN node.
- a secure connection can be established between the UE and the WLAN node. Improve the security of communication between the UE and the WLAN node.
- FIG. 13 is a schematic structural diagram of a UE according to another embodiment of the present invention.
- the IE of this embodiment may specifically include an obtaining module 40, a generating module 41, an authentication module 42 and an establishing module 43.
- the obtaining module 40 is configured to acquire a first key, where the first key is a shared key when the UE performs air interface security with the first network element device in the accessed mobile communication network, or according to the UE and the access Mobile
- the first network element device in the communication network is derived from the shared key derivation when performing the air interface security; the generating module 41 generates the authentication user name and the authentication credential according to the identity identifier of the UE and the first key obtained by the obtaining module 40.
- the authentication module 42 is connected to the generating module 41.
- the authentication module 42 is configured to perform EAP authentication with the first network element device or the second network element device according to the authentication user name and the authentication credential generated by the generating module 41.
- the second network element device is mobile.
- the establishing module 43 is connected to the authentication module 42.
- the establishing module 43 is configured to establish a secure connection with the WLAN node after the authentication module 42 performs EAP authentication.
- the security establishment of the WLAN is the same as that of the foregoing method in the foregoing method.
- the security establishment of the WLAN is the same as that of the foregoing method in the foregoing method.
- the UE in this embodiment can generate an authentication user name and an authentication password according to the identity identifier of the UE and the first key by using the foregoing module UE; and the UE is in accordance with the authentication user name and the authentication password and the mobile communication network accessed by the UE.
- the network element device performs EAP authentication, and the UE establishes a secure connection with the WLAN node after the authentication is completed.
- the first key is the shared secret between the user equipment and the network element device in the accessed mobile communication network when performing air interface security.
- the key is derived from the shared key.
- the UE and the WLAN node do not establish a secure connection, and the data between the UE and the WLAN node is transmitted in a clear text manner, resulting in the UE and the WLAN.
- the security scheme of the communication between the nodes is poor.
- a secure connection can be established between the UE and the WLAN node, and the security of communication between the UE and the WLAN node is improved.
- the identity identifier of the UE is a MAC address of the UE, an IMSI of the UE, a TMSI of the UE, a P-TMSI of the UE, a GUTI of the UE, and an S-TMSI of the UE.
- the mobile communication network may be a GSM network, a UMTS, an LTE system, a CDMA network, or a GPRS network;
- the network element device may be a BSC of a GSM network, an RNC of a UMTS, or a GPRS network.
- FIG. 14 is a schematic structural diagram of a network element device according to another embodiment of the present invention.
- the network element device in this embodiment is located in a mobile communication network accessed by the UE.
- the network element device of this embodiment includes The module 50, the authentication module 51 and the sending module 52 are taken.
- the obtaining module 50 is configured to obtain an authentication user name and an authentication credential of the UE.
- the authentication user name and the authentication credential are generated according to the identifier of the UE and the first key.
- the first key is the UE and the network element device or The shared key of the second network element device when performing air interface security, or the first key is derived from the shared key when the UE and the network element device or the second network element device perform air interface security.
- the authentication module 51 is connected to the obtaining module 50.
- the authentication module 51 is configured to perform EAP authentication with the UE according to the authentication user name and the authentication credential.
- the sending module 52 is connected to the authentication module 51, and the sending module 52 is configured to perform EAP authentication after the authentication module 51 performs the EAP authentication. Sending an authentication completion to the WLAN node to indicate that a secure connection is established between the WLAN node and the UE.
- the network element device of this embodiment implements the security establishment of the WLAN by using the above-mentioned modules.
- the implementation mechanism of the foregoing related method embodiment is the same. For details, refer to the description of the foregoing related method embodiments, and details are not described herein again.
- the network element device of this embodiment can obtain the authentication user name and the authentication credential of the UE by using the foregoing module, and perform EAP authentication with the UE according to the authentication user name and the authentication password, and establish a connection between the UE and the WLAN node after the authentication is completed. a secure connection; wherein the authentication username and the authentication credential are generated according to the UE identifier and the first key derivation; the first key is the first network element device or the second network in the UE and the accessed mobile communication network
- the shared key of the metadevice when performing air interface security or derived from the shared key.
- the UE and the WLAN node do not establish a secure connection, and the data between the UE and the WLAN node is transmitted in a clear text manner, resulting in the UE and the WLAN.
- the security scheme of the communication between the nodes is poor.
- the technical solution of the embodiment of the present invention can establish a secure connection between the UE and the WLAN node, and improve the security of communication between the UE and the WLAN node.
- the obtaining module 50 is specifically configured to receive an identity identifier of the UE and a first key of the UE sent by the second network element device, where the first key is And the shared key generated by the UE and the second network element device when performing air interface security or according to the shared key deduction of the UE and the second network element device when performing air interface security; and according to the identity identifier and the first secret of the UE The key deduction generates an authentication username and an authentication credential.
- the obtaining module 50 is specifically configured to receive the authentication user name and the authentication credential sent by the second network element device, where the authentication user name and the authentication credential are the second network element.
- the device is generated according to the identifier of the UE and the first key, and the first key is a shared key when the UE and the second network element device perform air interface security, or is performed according to the UE and the second network element device.
- the obtaining module 50 is specifically configured to acquire the first key; the first key is a shared secret between the first network element device and the UE when performing air interface security.
- the key is derived according to the shared key of the first network element device and the UE when performing air interface security; and the authentication user name and the authentication credential are generated according to the identity identifier of the UE and the first key derivation.
- the identifier of the UE is the MAC address of the UE, the TMSI of the IMSL UE of the UE, the P-TMSI of the UE, the GUTI of the UE, the S-TMSI of the UE, the RNTI of the UE, or the UE. MSISDN.
- the mobile communication network may be a GSM network, a UMTS, an LTE system, a CDMA network, or a GPRS network;
- the network element device may be a BSC of a GSM network, an RNC of a UMTS, an SGSN of a GPRS network, or an LTE network.
- the network element device of the foregoing embodiment implements the security establishment of the WLAN by using the foregoing module, and the implementation mechanism of the related method embodiment is the same.
- the implementation mechanism of the related method embodiment is the same.
- the network element device of the foregoing embodiment can obtain the authentication user name and the authentication credential of the UE by using the foregoing module, and perform EAP authentication with the UE according to the authentication user name and the authentication password, and after the authentication is completed, the UE and the WLAN node are established. a secure connection; wherein the authentication user name and the authentication credential are generated according to the identifier of the UE and the first key derivation; the first key is a shared secret between the UE and the network element device or the second network element device when performing air interface security The key is derived from the shared key of the UE and the network element device or the second network element device.
- the UE and the WLAN node do not establish a secure connection, and the data between the UE and the WLAN node is transmitted in a clear text manner, resulting in the UE and the WLAN.
- the security scheme of the communication between the nodes is poor.
- a secure connection can be established between the UE and the WLAN node, and the security of communication between the UE and the WLAN node is improved.
- FIG. 15 is a schematic structural diagram of a security establishment system of a WLAN according to an embodiment of the present invention.
- the security establishment system of the WLAN in this embodiment includes: a UE 60, a WLAN node setting, and a network element setting 62.
- the UE 60, the WLAN node set name 1 and the network element set ⁇ 62 communicate with each other.
- the UE 60 is configured to acquire the first key; the first key is a shared key when the UE 60 and the network element device 62 in the accessed mobile communication network perform air interface security, or performs air interface security according to the UE 60 and the network element device 62.
- the shared key is derived.
- the UE 60 derives the derivation key based on the first key and the derivation parameters.
- the derivation parameters are determined by the UE 60 and the network element device 62.
- UE60 is also used to WLAN nodes
- the device 61 transmits the identity identifier of the UE.
- the WLAN node device 61 receives the identity identifier of the UE that the UE 60 transmits, and transmits a key request message carrying the identity identifier of the UE to the network element device 62.
- the network element device 62 receives the key request message that is sent by the WLAN node device 61 and carries the identity identifier of the UE.
- the corresponding derivation key is obtained according to the identity identifier of the UE in the key request message.
- the derivation key is the network element.
- the device 62 derives the derivation based on the first key and the derivation parameters; the network element device 62 transmits the acquired derivation key to the WLAN node device 61.
- the WLAN node device 61 receives the derivation key corresponding to the identity identifier of the UE sent by the network element device 62. Thus, both the UE 60 and the WLAN node device 61 acquire the derivation key, and the UE 60 and the WLAN node device 61 establish security according to the derivation key. connection.
- the UE 60 in this embodiment may specifically adopt the UE in the foregoing embodiment of FIG. 8 or FIG. 9.
- the WLAN node device 61 in this embodiment may specifically adopt the WLAN node in FIG. 8 and subsequent alternative embodiments.
- the network element device 62 in this embodiment may be specifically configured by using the network element device in the foregoing embodiment shown in FIG. 11 or FIG. 12, and may adopt the foregoing embodiments shown in FIG. 1 to FIG. 3 and corresponding subsequent optional embodiments.
- For the security establishment of the WLAN refer to the description of the related embodiments in detail, and details are not described herein again.
- the UE and the WLAN node can establish a secure connection based on the derivation key, which can overcome the WLAN working in the open mode in the prior art.
- the UE does not establish a secure connection between the UE and the WLAN node, and the data between the UE and the WLAN node is transmitted in a clear text manner, which causes a defect in the security of the communication between the UE and the WLAN node.
- the technical solution of the embodiment can be used. Establish a secure connection between the UE and the WLAN node to improve the security of communication between the UE and the WLAN node.
- FIG. 16 is a schematic structural diagram of a WLAN security establishing system according to another embodiment of the present invention.
- the security establishment system of the WLAN in this embodiment includes: a UE 70 and a first network element device 71 and a WLAN node device 72.
- the UE 70 and the first network element device 71 and the WLAN node device 72 communicate with each other.
- the UE 70 is configured to acquire a first key, where the first key is used by the UE 70 and the first network element device 71 or the second network element device (not shown) in the accessed mobile communication network to perform air interface security.
- the shared key is obtained according to the shared key deduction of the UE 70 and the first network element device 71 or the second network element device when performing air interface security; the UE generates an authentication user according to the identity identifier of the UE and the first key deduction. Name and authentication credential;
- the first network element device 71 also acquires the authentication username and authentication credential of the UE.
- the first network element device 71 when the first key is the UE 70 and the first network element device 71 in the accessed mobile communication network is executing The first network element device 71 also acquires the first key, and generates the authentication user name and the authentication credential according to the identity identifier and the first key derivation of the UE. .
- the first network element device 71 When the first key is the shared key of the UE 70 and the second network element device in the accessed mobile communication network when performing air interface security or derived from the shared key. At this time, the first network element device 71 also obtains the authentication user name and the authentication credential from the second network element device; the authentication user name and the authentication credential are generated by the second network element device according to the UE's identity identifier and the first key deduction. . Or the first network element device 71 also obtains the identity identifier and the first key of the UE from the second network element device, and the first network element device generates the authentication user name according to the identity identifier of the UE and the first key. Certification credentials. The first network element device 71 and the second network element device communicate with each other.
- the UE 70 and the first network element device 71 both obtain the authentication user name and the authentication credential, and then the UE 70 and the first network element device 71 perform EAP authentication according to the authentication user name and the authentication credential, and after the authentication is completed, the first A network element device 71 sends an authentication completion to the WLAN node device 72 to instruct the UE 70 to establish a secure connection with the WLAN node device 72.
- the WLAN node device 72 forwards the authentication message, and the authentication message involved in the EAP authentication may refer to the related prior art.
- the UE 70 in this embodiment may specifically adopt the UE in the foregoing embodiment shown in FIG. 11.
- the first network element device 71 in this embodiment may specifically adopt the network element device in the foregoing embodiment shown in FIG.
- the security scheme of the WLAN can be implemented by using the foregoing technical solutions of the embodiment shown in FIG. 6 and FIG. 7 and the corresponding subsequent optional embodiments. For details, refer to the description of the related embodiments, and details are not described herein.
- the security establishment system of the WLAN in this embodiment by using the foregoing UE, the WLAN node device, and the network element device, the UE can generate an authentication user name and an authentication password according to the identity identifier of the UE and the first key; and the UE is based on the authentication user.
- the name and the authentication password are EAP-authenticated with the network element device in the mobile communication network accessed by the UE, and a secure connection is established between the UE and the WLAN node after the authentication is completed; wherein the first key is the user equipment and the accessed mobile communication network.
- the shared element of the network element device in the execution of the air interface security or derived from the shared key.
- the UE and the WLAN node do not establish a secure connection, and the data between the UE and the WLAN node is transmitted in a clear text manner, resulting in the UE and the WLAN.
- the security scheme of the communication between the nodes is poor.
- a secure connection can be established between the UE and the WLAN node, and the security of communication between the UE and the WLAN node is improved.
- the device embodiments described above are merely illustrative, with the unit illustrated as a separate component
- the components displayed as the unit may or may not be physical units, that is, may be located in one place, or may be distributed to at least two network units. Some or all of the modules may be selected according to actual needs to achieve the purpose of the solution of the embodiment. Those of ordinary skill in the art can understand and implement without deliberate labor.
Landscapes
- Engineering & Computer Science (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Computer Security & Cryptography (AREA)
- Computer Hardware Design (AREA)
- Computing Systems (AREA)
- General Engineering & Computer Science (AREA)
- Mobile Radio Communication Systems (AREA)
Abstract
本发明实施例提供一种无线局域网络的安全建立方法及系统、设备。其方法包括:UE获取第一密钥;该第一密钥为UE与接入的移动通信网络中的网元设备在执行空口安全时的共享密钥或者根据共享密钥推演得出的;UE根据第一密钥和推演参数进行推演得到推演密钥;UE根据推演密钥与获取到推演密钥的WLAN节点之间建立安全连接,WLAN节点获取到的推演密钥与UE获取的推演密钥相同。采用本发明实施例的技术方案,能够在UE和WLAN之间建立安全连接,提高UE与WLAN之间通信的安全性。
Description
无线局域网络的安全建立方法及系统、 设备
本申请要求于 2012年 5月 23日提交中国专利局、申请号为 201210161427.0、 发明名称为"无线局域网络的安全建立方法及系统、设备"的中国专利申请的优先 权, 其全部内容通过引用结合在本申请中。 技术领域 本发明实施例涉及通信技术领域, 尤其涉及一种无线局域网络的安全建立 方法及系统、 设备。 背景技术
随着支持上网功能的智能终端之类的用户设备(User Equipment; UE )的广 泛普及, 人们开始使用 UE进行大量的数据业务。 近几年来, 运营商网络的数据 业务流量增长很快。 为了适应这种趋势, 运营商和设备厂商开始积极考虑各种 各样的减轻运营商网络负担的方法。 无线局域网络 ( Wireless Local Area Network; WLAN )是一种无线接入技术, WLAN技术能够提供较高的传输速率, 被认为是运营商部署的广域无域网的有益补充。 在机场、 厂商等热点地区, WLAN技术能够使得用户通过 WLAN进行数据业务, 从而减轻运营商核心网络 的负担。
目前许多运营商已经部署了 WLAN网络用在如机场、 车站、 酒店等热点地 区以分流(offload ) UE的数据流量。 在这些已有的部署方案中, 运营商一般将 WLAN部署成 open模式, 任何 UE均可接入 WLAN节点。 当 UE要连入因特网 ( internet ) 时, WLAN节点将 UE重定向至一个特定的 web网页, UE对应的用户 在网页上输入正确的用户名 /密码后, UE便可以接入 internet
由于 WLAN节点工作在 open模式下, UE和 WLAN节点之间不建立安全连接, UE和 WLAN节点之间的数据以明文方式传输,导致 UE与 WLAN节点之间通信的 安全性能较差。 发明内容 本发明实施例提供一种无线局域网络的安全建立方法及系统、 设备, 用以 弥补现有技术中 UE与 WLAN之间通信的安全性能较差的缺陷, 用于提高 UE与
WLAN之间的安全性能。
一方面, 本发明实施例提供一种无线局域网络的安全建立方法, 包括: 用户设备获取第一密钥; 所述第一密钥为所述用户设备与接入的移动通信 网络中的网元设备在执行空口安全时的共享密钥或者根据所述用户设备与接入 的移动通信网络中的网元设备在执行空口安全时的共享密钥推演得出的;
所述用户设备根据所述第一密钥和推演参数进行推演得到推演密钥; 所述 推演参数为所述用户设备与所述网元设备协商确定的;
所述用户设备根据所述推演密钥与获取到推演密钥的无线局域网络节点之 间建立安全连接, 所述无线局域网络节点获取到的推演密钥与所述用户设备获 取的所述推演密钥相同。
另一方面, 本发明实施例还提供一种无线局域网络的安全建立方法, 包括: 无线局域网络节点接收用户设备发送的所述用户设备的身份标识符; 所述无线局域网络节点向所述用户设备接入的移动通信网络中的网元设备 发送携带所述用户设备的身份标识符的密钥请求消息;
所述无线局域网络节点接收所述网元设备发送的所述用户设备的身份标识 符对应的推演密钥; 所述推演密钥为所述网元设备根据第一密钥和推演参数进 行推演得到, 所述第一密钥为所述用户设备与所述网元设备在执行空口安全时 的共享密钥或者根据所述用户设备与所述网元设备在执行空口安全时的共享密 钥推演得出的; 所述推演参数为所述用户设备与所述网元设备协商确定的; 所述无线局域网络节点基于所述推演密钥与获取到推演密钥的所述用户设 备之间建立安全连接, 所述用户设备获取到的推演密钥与所述无线局域网络节 点获取的所述推演密钥相同。
再一方面, 本发明实施例还提供一种无线局域网络的安全建立方法, 包括: 用户设备接入的移动通信网络中的网元设备接收无线局域网络节点发送的 密钥请求消息; 所述密钥请求消息中携带有所述用户设备的身份标识符;
所述网元设备根据所述密钥请求消息中的所述用户设备的身份标识符, 获 取对应的推演密钥; 所述推演密钥为所述网元设备根据第一密钥和推演参数进 行推演得到; 所述第一密钥为所述网元设备与所述用户设备在执行空口安全时 的共享密钥或者根据所述网元设备与所述用户设备在执行空口安全时的共享密 钥推演得出的; 所述推演参数为所述网元设备与所述用户设备协商确定的; 所述网元设备向所述无线局域网络节点发送所述推演密钥, 以供所述无线
局域网络节点基于所述推演密钥与获取到推演密钥的所述用户设备之间建立安 全连接, 所述用户设备获取到的推演密钥与所述无线局域网络节点接收所述网 元设备发送的所述推演密钥相同。
又一方面, 本发明实施例还提供一种无线局域网络的安全建立方法, 包括: 用户设备获取第一密钥; 所述第一密钥为所述用户设备与接入的移动通信 网络中的第一网元设备在执行空口安全时的共享密钥或者根据所述用户设备与 接入的移动通信网络中的第一网元设备在执行空口安全时的共享密钥推演得出 的;
所述用户设备根据所述用户设备的身份标识符和所述第一密钥推演生成认 证用户名和认证信任状;
所述用户设备根据所述认证用户名和所述认证信任状与第一网元设备或者 第二网元设备进行扩展认证协议认证; 所述第二网元设备为所述移动通信网络 中的所述第一网元设备之外的其他网元设备; 所述第二网元设备从所述第一网 元设备处获取所述认证用户名和所述认证信任状; 或者所述第二网元设备从所 述第一网元设备处获取所述用户设备的身份标识符和所述第一密钥, 并根据所 述用户设备的身份标识符和所述第一密钥推演生成所述认证用户名和所述认证 信任状;
所述用户设备在认证完成后与所述无线局域网络节点之间建立安全连接。 再另一方面, 本发明实施例还提供一种无线局域网络的安全建立方法, 包 括:
用户设备接入的移动通信网络中的第一网元设备获取所述用户设备的认证 用户名和认证信任状; 所述认证用户名和所述认证信任状为根据所述用户设备 的身份标识符和第一密钥推演生成的; 所述第一密钥为所述用户设备与接入的 移动通信网络中的所述第一网元设备或者第二网元设备在执行空口安全时的共 享密钥或者根据所述用户设备与所述第一网元设备或者第二网元设备在执行空 口安全时的共享密钥推演得出的;
所述第一网元设备根据所述认证用户名和所述认证信任状与用户设备进行 扩展认证协议认证;
所述第一网元设备在所述扩展认证协议认证成功后, 向所述无线局域网络 节点发送认证完成, 以指示所述无线局域网络节点与所述用户设备之间建立安 全连接。
再另一方面, 本发明实施例还提供一种用户设备, 包括:
获取模块, 用于获取第一密钥; 所述第一密钥为与接入的移动通信网络中 的网元设备在执行空口安全时的共享密钥或者根据所述用户设备与接入的移动 通信网络中的网元设备在执行空口安全时的共享密钥推演得出的;
推演模块, 用于根据所述获取模块获取的所述第一密钥和推演参数进行推 演得到推演密钥; 所述推演参数为所述用户设备与所述网元设备协商确定的; 建立模块, 用于根据所推演模块推演得到的所述述推演密钥与获取到推演 密钥的无线局域网络节点之间建立安全连接, 所述无线局域网络节点获取到的 推演密钥与所述用户设备获取的所述推演密钥相同。
再另一方面, 本发明实施例还提供一种无线局域网络节点设备, 其特征在 于, 包括:
接收模块, 用于接收用户设备发送的所述用户设备的身份标识符; 发送模块, 用于向所述用户设备接入的移动通信网络中的网元设备发送携 带所述接收模块接收的所述用户设备的身份标识符的密钥请求消息;
所述接收模块, 还用于接收所述网元设备发送的所述用户设备的身份标识 符对应的推演密钥; 所述推演密钥为所述网元设备根据第一密钥和推演参数进 行推演得到, 所述第一密钥为所述用户设备与所述网元设备在执行空口安全时 的共享密钥或者根据所述用户设备与接入的移动通信网络中的网元设备在执行 空口安全时的共享密钥推演得出的; 所述推演参数为所述用户设备与所述网元 设备协商确定的;
建立模块, 用于基于所述接收模块接收的所述推演密钥与获取到推演密钥 的所述用户设备之间建立安全连接, 所述用户设备获取到的推演密钥与无线局 域网络节点获取的所述推演密钥相同。
再另一方面, 本发明实施例还提供一种网元设备, 位于用户设备接入的移 动通信网络中, 所述网元设备包括:
接收模块, 用于接收无线局域网络节点发送的密钥请求消息; 所述密钥请 求消息中携带有所述用户设备的身份标识符;
获取模块, 用于根据所述接收模块接收的所述密钥请求消息中的所述用户 设备的身份标识符, 获取对应的推演密钥; 所述推演密钥为根据第一密钥和推 演参数进行推演得到; 所述第一密钥为与所述用户设备在执行空口安全时的共 享密钥或者根据与所述用户设备在执行空口安全时的共享密钥推演得出的; 所
述推演参数为与所述用户设备协商确定的;发送模块, 用于向所述无线局域网络 节点发送所述获取模块获取到的所述推演密钥, 以供所述无线局域网络节点基 于所述推演密钥与获取到推演密钥的所述用户设备之间建立安全连接, 所述用 户设备获取到的推演密钥与所述无线局域网络节点接收所述网元设备发送的所 述推演密钥相同。
再另一方面, 本发明实施例还提供一种无线局域网络的安全建立系统, 包 括: 如上所述的用户设备、 所述的无线局域网络节点设备和所述的网元设备。
再另一方面, 本发明实施例还提供一种用户设备, 包括:
获取模块, 用于获取第一密钥; 所述第一密钥为所述用户设备与接入的移 动通信网络中的第一网元设备在执行空口安全时的共享密钥或者根据所述用户 设备与接入的移动通信网络中的第一网元设备在执行空口安全时的共享密钥推 演得出的;
生成模块, 用于根据所述用户设备的身份标识符和所述获取模块的所述第 一密钥推演生成认证用户名和认证信任状;
认证模块, 用于根据所述生成模块生成的所述认证用户名和所述认证信任 状与第一网元设备或者第二网元设备进行扩展认证协议认证, 所述第二网元设 备为所述移动通信网络中的所述第一网元设备之外的其他网元设备; 所述第二 网元设备从所述第一网元设备处获取所述认证用户名和所述认证信任状; 或者 所述第二网元设备从所述第一网元设备处获取所述用户设备的身份标识符和所 述第一密钥, 并根据所述用户设备的身份标识符和所述第一密钥推演生成所述 认证用户名和所述认证信任状;
建立模块, 用于在所述认证模块进行扩展认证协议认证完成后与所述无线 局域网络节点之间建立安全连接。
再另一方面, 本发明实施例还提供一种网元设备, 位于用户设备接入的移 动通信网络中, 所述网元设备包括:
获取模块, 用于获取所述用户设备的认证用户名和认证信任状; 所述认证 用户名和所述认证信任状为根据所述用户设备的身份标识符和第一密钥推演生 成的; 所述第一密钥为所述用户设备所述网元设备或者第二网元设备在执行空 口安全时的共享密钥或者根据所述用户设备与所述网元设备或者第二网元设备 在执行空口安全时的共享密钥推演得出的;
认证模块, 用于根据所述认证用户名和所述认证信任状与用户设备进行扩
展认证协议认证;
发送模块, 用于在所述扩展认证协议认证成功后, 向所述无线局域网络节 点发送认证完成, 以指示所述无线局域网络节点与所述用户设备之间建立安全 连接。
再另一方面, 本发明实施例还提供一种无线局域网络的安全建立系统, 包 括: 如上所述的用户设备和所述的网元设备。
本发明实施例的无线局域网络的安全建立方法及系统、 设备, UE与 WLAN 节点之间能够基于推演密钥建立安全连接, 推演密钥根据第一密钥和推演参数 进行推演得到, 第一密钥为用户设备与接入的移动通信网络中的网元设备在执 行空口安全时的共享密钥或者根据共享密钥推演得出的;或者 UE根据 UE的身份 标识符和第一密钥推演生成认证用户名和认证密码; 并由 UE根据认证用户名和 认证密码与 UE接入的移动通信网络中的网元设备进行 EAP认证, 并在认证完成 后 UE与 WLAN节点之间建立安全连接。 采用本发明实施例的上述技术方案, 能 够克服现有技术中 WLAN工作在 open模式下, UE和 WLAN节点之间不建立安全 连接, UE和 WLAN节点之间的数据以明文方式传输, 导致 UE与 WLAN节点之间 通信的安全性能较差的缺陷,采用本发明实施例的技术方案,能够在 UE和 WLAN 节点之间建立安全连接, 提高 UE与 WLAN节点之间通信的安全性。 附图说明 为了更清楚地说明本发明实施例或现有技术中的技术方案, 下面将对实施 例或现有技术描述中所需要使用的附图作一筒单地介绍, 显而易见地, 下面描 述中的附图是本发明的一些实施例, 对于本领域普通技术人员来讲, 在不付出 创造性劳动性的前提下, 还可以根据这些附图获得其他的附图。 图 1为本发明提供的一种 WLAN的安全建立方法的流程图。
图 2为本发明另一实施例提供的 WLAN的安全建立方法的流程图。
图 3为本发明再一实施例提供的 WLAN的安全建立方法的流程图。
图 4为本发明一实施例提供的 WLAN的安全建立方法的信令图。
图 5为本发明另一实施例提供的 WLAN的安全建立方法的信令图。
图 6为本发明又一实施例提供的 WLAN的安全建立方法的流程图。
图 7为本发明再另一实施例提供的 WLAN的安全建立方法的流程图。
图 8为本发明一实施例提供的 UE的结构示意图。
图 9为本发明另一实施例提供的 UE的结构示意图。
图 10为本发明实施例提供的 WLAN节点设备的结构示意图。
图 11为本发明一实施例提供的网元设备的结构示意图。
图 12为本发明另一实施例提供的网元设备的结构示意图。
图 13为本发明再一实施例提供的 UE的结构示意图。
图 14为本发明再一实施例提供的网元设备的结构示意图。
图 15为本发明一实施例提供的 WLAN的安全建立系统的结构示意图。 图 16为本发明另一实施例提供的 WLAN的安全建立系统的结构示意图。 具体实施方式 为使本发明实施例的目的、 技术方案和优点更加清楚, 下面将结合本发明 实施例中的附图, 对本发明实施例中的技术方案进行清楚、 完整地描述, 显然, 所描述的实施例是本发明一部分实施例, 而不是全部的实施例。 基于本发明中 的实施例, 本领域普通技术人员在没有作出创造性劳动前提下所获得的所有其 他实施例, 都属于本发明保护的范围。
图 1为本发明实施例提供的一种 WLAN的安全建立方法的流程图。 如图 1所 示, 本实施例的 WLAN的安全建立方法的执行主体为 UE。 本实施例的 WLAN的 安全建立方法, 具体可以包括如下步骤:
100、 UE获取第一密钥;
本实施例中的第一密钥为 UE与 UE接入的移动通信网络中的网元设备在执 行空口安全时的共享密钥或者根据 UE与 UE接入的移动通信网络中的网元设备 在执行空口安全时的共享密钥推演得出的。
101、 UE根据第一密钥和推演参数进行推演得到推演密钥;
其中该推演参数为 UE和网元设备确定的。
102、 UE根据推演密钥与获取到推演密钥的 WLAN节点之间建立安全连接。 WLAN节点获取到的推演密钥与 UE获取的推演密钥相同。 亦即本实施例的 技术方案在实施时需要 WLAN节点亦能够获取到该推演密钥, 例如 WLAN节点 可以向网元设备中请求获取推演密钥, 而网元设备是根据第一密钥和推演参数 推演得到推演密钥, 这样 UE和 WLAN节点均可以得知该推演密钥, 并基于该推
演密钥, UE与 WLAN节点之间建立安全连接。
本实施例中, UE与网元设备均可以获知推演参数, 可以认为推演参数是两 者协商确定的。 推演参数具体可以为一个或者多个。 例如推演参数可以为 UE和 网元设备事先约定好的, 或者在推演推演密钥时在线协商的。 例如可以由 UE提 供一些参数作为推演参数, 然后告知网元设备。 或者由网元设备提供一些参数 作为推演参数, 然后告知网元设备。 或者可以由 UE提供一些参数或者由网元设 备提供一些参数, 然后 UE和网元设备交换各自提供的参数, 此时对应的推演参 数由 UE提供给参数和网元设备提供的参数共同组成。
本实施例的无线局域网络的安全建立方法, 通过采用上述技术方案, UE与 WLAN节点之间能够基于推演密钥建立安全连接, 能够克服现有技术中 WLAN 工作在 open模式下, UE和 WLAN节点之间不建立安全连接, UE和 WLAN节点之 间的数据以明文方式传输, 导致 UE与 WLAN节点之间通信的安全性能较差的缺 陷, 采用本实施例的技术方案, 能够在 UE和 WLAN节点之间建立安全连接, 提 高 UE与 WLAN节点之间通信的安全性。
可选地, 在上述图 1所示实施例的技术方案的基础上, 还可以包括如下可选 技术方案, 构成图 1所示实施例的可选实施例。
在图 1所示实施例的可选实施例中, 在步骤 102之前, 所述实施例还包括: UE向 WLAN节点发送 UE的身份标识符, 以供 WLAN节点根据 UE的身份标识符, 向网元设备请求获取 UE对应的推演密钥。
可选地, 在图 1所示实施例的可选实施例中, 步骤 101 , 具体可以包括: UE 根据第一密钥和推演参数进行推演得到第二密钥, 即此时的推演密钥即为第二 密钥。 例如 UE具体可以采用如下方式: Kw=KDF ( K, 推演参数)推演得到第 二密钥; 其中 Kw为第二密钥, K为第一密钥, 推演参数为 UE和网元设备协商确 定好的, KDF ( , )为一个密钥推演功能 (key derivation function; KDF)函数, K 和推演参数作为该函数的输入, Kw作为该函数的输出。
例如在本发明实施例中可以取第二密钥 Kw = HMAC-SHA256 (K, "WPAAVPA2 Personal");哈希消息认证码 (Hashed Message Authentication Code; HMAC) 是一类密码算法, HMAC- SHA256 ( , )表示一个密码算法函数, "WPAAVPA2 Personal" 为约定好的用于推演第二密钥 Kw的推演参数, 用于标 识第二密钥 Kw被 UE和 WLAN网络用于通过 WPA/WPA2 personal的方式建立 WLAN安全连接。 通过 WPA/WPA2 personal的方式建立 WLAN安全连接是 UE和
WLAN节点基于预共享密钥的方式, 建立 WLAN安全连接的方法, 详细可以参 考相关现有技术, 在此不再赘述。 本实施例中 UE和 WLAN网络之间的预共享密 钥, 即为第二密钥 Kw。 本实施例中 K仍为第一密钥。
此时对应的步骤 102 ,具体可以为 UE根据第二密钥与 WLAN节点之间建立安 全连接。 采用该技术方案, 该第二密钥是 UE根据第一密钥和与 UE协商确定的推 演参数进行推演得到, 可以保证不同的 UE具有不同的第二密钥, 每一 UE可以基 于其对应的第二密钥与 WLAN节点之间建立安全连接, 从而能够有效地保证 UE 和 WLAN节点之间的安全连接。
可选地, 在图 1所示实施例的可选实施例中, 步骤 101 , 具体可以包括: UE 根据第一密钥和推演参数进行推演得到第二密钥; UE再根据第二密钥和 WLAN 节点的身份标识符推演得到第三密钥, 其中 UE在开始接入 WLAN节点的时候, 可以获取到 WLAN节点的身份标识符。 而本实施例中, 在网元设备一侧, 网元 设备也可以获取到该 WLAN节点的身份标识符, 并根据第二密钥和 WLAN节点 的身份标识符进行推演得到第三密钥。 例如 WLAN节点在向网元设备请求密钥 时, 可以向网元设备发送携带 UE的身份标识符和 WLAN节点的身份标识符的密 钥请求消息。 这样网元设备便可以知道需要根据第二密钥和 WLAN节点的身份 标识符推演第三密钥, 并将该第三密钥发送给 WLAN节点。 这样 UE侧和 WLAN 节点侧均可以获知该第三密钥。 例如当 WLAN节点的身份标识符为 WLAN节点 的服务集标识( Service Set Identifier; SSID ) , 该第三密钥可以采用如下方式推 演得到: 第三密钥= HMAC-SHA256 (Kw, WLAN节点的 SSID)。 HMAC- SHA256 ( , )表示一个密码算法函数, Kw表示第二密钥。 此时对应的步骤 102, 具体可 以为 UE根据第三密钥与 WLAN节点之间建立安全连接。 采用该技术方案, 可以 保证同一 UE在从不同的 WLAN节点接入 WLAN时, 采用不同的第三密钥, 与上 述每一 UE可以基于其对应的第二密钥与 WLAN节点之间建立安全连接相比, 能 够进一步增强 UE与 WLAN节点之间建立的连接的安全性。 当然, 在推演第三密 钥的过程中, WLAN节点可以将身份标识符发给网元设备, 但这不是网元设备 唯一获取 WLAN节点身份标识符的方法。 网元设备可以通过其他方法来获取 WLAN节点的身份标识符, 例如网元设备可以接收 WLAN节点发送的携带 UE的 身份标识符的密钥请求消息,可以获取该 WLAN节点的 IP地址,再根据该 WLAN 节点的 IP地址获取该 WLAN节点的身份标识符,实际应用中还网元设备还可以采 用其他方法获取 WLAN节点的身份标识符。 此外, WLAN节点也可以是 WLAN
节点的 MAC地址或者其他的能够唯一标识 WLAN节点的身份信息。
可选地, 在图 1所示实施例的可选实施例中, UE的身份标识符为 UE的媒体 访问控制 ( Media Access Control; MAC ) 地址、 UE的国际移动用户识别码 ( International Mobile Subscriber Identification Number; IMSI ) 、 UE的临时移动 用户识别码( Temperate Mobile Subscription Identity; TMSI ) 、 UE的分组临时移 动用户识别码 ( Packet Temperate Mobile Subscription Identity; P-TMSI ) 、 UE 的全球唯一临时身份 ( Globally Unique Temporary Identity; GUTI ) 、 UE的系统 架构演进临时移动客户身份 ( System Architecture Evolution Temporary Mobile Subscriber Identity; S-TMSI )、 UE的无线网络临时标识( Radio Network Temporary Identifier; RNTI )或者 UE的移动台国际电话综合业务数字网号码( Mobile Station international Integrated Services Digital Network Number; MSISDN ) 。
进一步可选地, 当 UE的身份标识符为上述除 MAC地址之外的其他的时候, 网元设备自身能够获取该 UE的身份标识符, 此时 UE不需要向网元设备发送该 UE的身份标识符。 而当 UE的身份标识符为 UE的 WLAN接口的 MAC地址 (或者 为网元设备无法从自身获知的 UE的其他身份标识符)时, 上述方法中的 "UE再 根据第二密钥和接收网元设备发送的 WLAN节点的身份标识符推演得到第三密 钥" 之前, 还包括 UE向网元设备发送 UE的身份标识符。 具体地, UE可以采用 加密的方式向网元设备发送 UE的身份标识符。
可选地, 在图 1所示实施例的可选实施例中, 移动通信网络可以为全球移动 通信( Global System For Mobile Communication; GSM ) 网络、 通用移动通讯系 统( Universal Mobile Telecommunications System; UMTS )、长期演进( Long Term Evolution; LTE ) 系统、 码分多址( Code Division Multiple Access; CDMA ) 网 络或通用分组无线服务( General Packet Radio Service; GPRS)网络; 网元设备可 以为 GSM 网络的基站控制器(Base Station Controller; BSC ) 、 UMTS的无线网 络控制器 ( Radio Network Controller; RNC ) 、 GPRS 网络的服务 GPRS支持节 点 ( Serving GPRS Support Node; SGSN ) 、 LTE系统的移动管理实体( Mobility Management Entity; MME )或者基站 (如 LTE系统中的 eNB ) 。
可选地, 在图 1所示实施例的可选实施例中, 对于上述实施例中的步骤 100 的第一密钥, 例如当移动通信网络为 GSM网络, 对应的网元设备为 BSC, UE与 BSC之间的共享密钥为 Kc。 第一密钥 K可以为 Kc, 或根据 Kc, 使用密钥推演功 能推演得到的密钥, 如K=KDF ( Kc , "K for WLAN" ) 。
当移动通信网络为 GPRS网络, 对应的网元设备为核心网节点中的 SGSN , UE与 SGSN之间的共享密钥为 Kc , 第一密钥 K可以为 Kc, 或根据 Kc推演得到的 密钥。
当移动通信网络为 UMTS , 对应的网元设备为 RNC , UE与 SGSN之间进行共 享密钥为 CK/IK。第一密钥 K可以为 CK/IK中的任何一个密钥,或根据 CK,或 IK, 或两者推演得到一个密钥, 例如可以取第一密钥 K= CKIIIK。
当移动通信网络为 LTE, 对应的网元设备为核心网节点中的 MME, UE与 MME之间的共享密钥为 Kasme、 Knas .int或者 Knas.enc。 第一密钥 K可以为此三 个密钥中的任何一个密钥, 或根据此三个密钥中的一个或数个密钥推演得到的 密钥。 例如可以取第一密钥 K=Knas.int XOR Knas.enc。
当移动通信网络为 LTE网络时, 对应的网元设备还可以为 eNB , UE和 eNB 之间的共享密钥 Kenb、 Krrc.int、 Krrc.enc. Kup.enc、 Kup.int, 第一密钥 K可以是 Kenb、 Krrc.int. Krrc.enc. Kup.enc、 Kup.int等中的一个密钥, 也可以是根据这 些密钥中的一个或多个推演得到的密钥。 例如在本实施例中, 可以取第一密钥 K=Kenb。
当移动通信网络为 LTE网络时, 对应的网元设备还可以为 eNB时, 对应上述 实施例中的 "UE向网元设备送 UE的身份标识符" 具体可以采用如下两种方法: 方法一: UE在非接入层( Non-Access Stratum; NAS ) 安全模式结束( Security mode complete; SMP )消息中将 UE的身份标识符发给 MME, MME将 UE的身份 标识符通过 S 1消息转发给 eNB;
方法二: UE在 RRC消息中将 UE的身份标识符发给 eNB。
可选地, 在图 1所示实施例的可选实施例中, 其中 101中 UE向网元设备和 WLAN节点发送 UE的身份标识符 (如 MAC地址) ; UE的身份标识符 (如 MAC 地址)可能会暴露用户的隐私, 因此需要通过一些方式对 UE的身份标识符(如 MAC地址)的传输进行安全保护。 UE的身份标识符(如 MAC地址)的传输可通 过如下几种方式进行保护:
第一种情况、 在加密的消息中传输 UE的身份标识符(如 MAC地址) , 例如 一些无线资源控制协议(Radio Resource Control; RRC ) 消息, 或者非接入层 ( Non-Access Stratum; NAS ) 消息可以进行加密保护, 因此可以在这些加密的 RRC消息或者 NAS消息中传输 UE的身份标识符,从而可以保护 UE的身份标识符 传输的机密性, 防止攻击者利用 UE的身份标识符对用户的隐私造成危害, 如位
置追踪等。
其中可加密的 RRC消息或者 NAS消息可以包括如下消息: 附着完成( Attach Complete ) 消息、 路由区 i或更新 ( Routing Area Update; RAU ) 消息完成 ( Complete )、 跟踪区域更新( Tracking Area Update; )完成( Complete )消息、 非接入层安全模式结束 ( Non-access Stratum Security Mode Complete; NAS SMC ) 消息或者 UE 的容量迁移 ( capability transfer ) 消息等等。
但是,在某些网络中,运营商可能没有开启加密功能。 因此所有的 RRC/NAS 信令都无法进行保护。 在这种情况下, UE和控制器 /核心网节点可根据第一密钥 K推演得到第四密钥 Ka。 利用第四密钥 Ka对 UE的身份标识符进行异或操作, 从 而保证了 UE的身份标识符传输的安全性。 第四密钥 Ka的推演可能也需要一些推 演参数的参与。 这些推演参数可能需要在 UE和网络侧进行交互。 本实施例中, 推演第四密钥 Ka的一个例子是 Ka = HMAC-SHA256 (K, "MAC anonymity" )。 MAC anonymity为一个字符串,用于表示本实施例中密钥推演的目的是用于实现 MAC地址隐藏功能。
上述实施例的无线局域网络的安全建立方法, 通过采用上述技术方案, UE 与 WLAN节点之间能够基于推演密钥建立安全连接, 能够克服现有技术中 WLAN工作在 open模式下, UE和 WLAN节点之间不建立安全连接, UE和 WLAN 节点之间的数据以明文方式传输, 导致 UE与 WLAN节点之间通信的安全性能较 差的缺陷, 采用本实施例的技术方案, 能够在 UE和 WLAN节点之间建立安全连 接, 提高 UE与 WLAN节点之间通信的安全性。
图 2为本发明另一实施例提供的 WLAN的安全建立方法的流程图。 如图 2所 示, 本实施例的 WALN的安全建立方法的执行主体为 WLAN节点。 本实施例的 WALN的安全建立方法, 具体可以包括如下步骤:
200、 WLAN节点接收 UE发送的 UE的身份标识符;
201、 WLAN节点向 UE接入的移动通信网络中的网元设备发送携带 UE的身 份标识符的密钥请求消息;
202、 WLAN节点接收网元设备发送的 UE的身份标识符对应的推演密钥; 本实施例中该推演密钥为网元设备根据第一密钥和推演参数进行推演得 到,第一密钥为 UE与网元设备在执行空口安全时的共享密钥或者根据 UE与网元 设备在执行空口安全时的共享密钥推演得出的; 推演参数为 UE与网元设备协商 确定的。
203、 WLAN节点基于推演密钥与获取到推演密钥的 UE之间建立安全连接。 其中 UE获取到的推演密钥与 WLAN节点获取的推演密钥相同, 亦即本实施 例的技术方案在实现时, UE亦能够获取到该推演密钥, 例如 UE可以根据第一密 钥和推演参数推演得到推演密钥, 详细可以参考上述图 1所示实施例的记载。 这 样, 采用本实施例的技术方案, UE和 WLAN节点均可以获取到推演密钥, 便能 够基于该推演密钥建立安全连接, 保证 UE与 WLAN节点之间通信的安全性。
本实施例与上述图 1所示实施例的区别仅在于: 上述图 1所示实施例在 UE侧 描述本发明的技术方案, 而本实施例在 WLAN节点侧描述本发明的技术方案, 其余实施过程完全相同, 详细可以参考上述图 1所示实施例的记载, 在此不再赘 述。
本实施例的无线局域网络的安全建立方法, 通过采用上述技术方案, UE与 WLAN节点之间能够基于推演密钥建立安全连接, 能够克服现有技术中 WLAN 工作在 open模式下, UE和 WLAN节点之间不建立安全连接, UE和 WLAN节点之 间的数据以明文方式传输, 导致 UE与 WLAN节点之间通信的安全性能较差的缺 陷, 采用本实施例的技术方案, 能够在 UE和 WLAN节点之间建立安全连接, 提 高 UE与 WLAN节点之间通信的安全性。
可选地, 在上述图 2所示实施例的技术方案的基础上, 还可以包括如下可选 技术方案, 构成图 2所示实施例的可选实施例。
在图 2所示实施例的可选实施例中, 上述实施例的步骤 202中 "WLAN节点 接收网元设备发送的 UE的身份标识符对应的推演密钥",具体可以包括: WLAN 节点接收网元设备发送的 UE的身份标识符对应的第二密钥, 第二密钥为网元设 备根据 UE的身份标识符以及网元设备中存储的 UE的身份标识符与第二密钥之 间的对应关系获取的; 第二密钥为网元设备根据第一密钥和推演参数进行推演 得到; 在该技术方案中, 推演密钥为第二密钥。 此时对应的步骤 203 "WLAN节 点基于推演密钥与 UE之间建立安全连接" , 具体可以包括: WLAN节点基于第 二密钥与 UE之间建立安全连接。 采用该技术方案, 第二密钥采用第一密钥和与 UE协商确定的推演参数进行推演得到, 可以保证不同的 UE具有不同的第二密 钥, 每一 UE可以基于其对应的第二密钥与 WLAN节点之间建立安全连接, 从而 能够有效地保证 UE和 WLAN节点之间的安全连接。
采用上述方案, 不同的 UE具有不同的第二密钥, 能够增强 UE和 WLAN节点 之间的安全连接; 但是当同一 UE采用不同的 WLAN节点接入 WLAN的时候, 还
是采用相同的第二密钥与 WLAN节点建立安全连接, 因此还是给 UE接入 WLAN 带来一定的安全隐患, 为了解决该问题, 可选地, 在图 2所示实施例的可选实施 例中, 还可以包括下述方案:
上述实施例中的步骤 202 "WLAN节点接收网元设备发送的 UE的身份标识符 对应的推演密钥" , 具体可以包括: WLAN节点接收网元设备发送的第三密钥, 该第三密钥为网元设备根据第二密钥与 WLAN节点的身份标识符推演得到的; 第二密钥为网元设备根据 UE的身份标识符以及网元设备中存储的 UE的身份标 识符与第二密钥之间的对应关系获取的; 第二密钥为网元设备根据第一密钥和 与 UE协商确定的推演参数进行推演得到。 其中网元设备可以接收 WLAN节点发 送的携带 UE的身份标识符的密钥请求消息之后, 获取该 WLAN节点的 IP地址, 再根据该 WLAN节点的 IP地址获取该 WLAN节点的身份标识符,实际应用中网元 设备还可以采用其他方法获取 WLAN节点的身份标识符。 此外, WLAN节点可 以是 WLAN节点 SSID、 或者 WLAN节点的 MAC地址或者其他的能够唯一标识 WLAN节点的身份信息。
对应地上述实施例中的步骤 203 "WLAN节点基于推演密钥与 UE之间建立安 全连接" , 具体可以包括: WLAN节点基于第三密钥与 UE之间建立安全连接。 在该方案中推演密钥为第三密钥, 采用该技术方案, 可以保证同一 UE在从不同 的 WLAN节点接入 WLAN时, 采用不同的第三密钥, 与上述每一 UE可以基于其 对应的第二密钥与 WLAN节点之间建立安全连接相比, 能够进一步增强 UE与 WLAN节点之间建立的连接的安全性。
进一步可选地, 对于推演密钥为第三密钥时, 上述实施例中的步骤 201 "WLAN节点向 UE接入的移动通信网络中的网元设备发送携带 UE的身份标识 符的密钥请求消息" , 具体可以包括: WLAN节点向网元设备发送携带 UE的身 份标识符和 WLAN节点的身份标识符的密钥请求消息。 此时网元设备可以直接 获取该 WLAN节点的身份标识符, 而不用再去间接获取该 WLAN节点的身份标 识符。
在图 2所示实施例的可选实施例中, 上述实施例中的移动通信网络可以为 GSM网络、 UMTS, LTE系统、 CDMA网络或 GPRS网络; 网元设备可以为 GSM 网络的 BSC、 UMTS的 RNC、 GPRS 网络的 SGSN、 LTE系统的 MME或者 LTE系 统中的 eNB。
可选地, 在图 1所示实施例的可选实施例中, UE的身份标识符为 UE的 MAC
地址、 UE的 IMSI、 UE的 TMSI、 UE的 P-TMSI、 UE的 GUTI、 UE的 S-TMSI、 UE 的 RNTI或者 UE的 MSISDN。
需要说明的是, 上述图 1所示实施例的可选实施例中的能够应用在 WLAN节 点侧的可选技术方案, 均可以用于在图 2所示实施例的可选实施例中, 详细可以 参考上述图 1所示实施例的可选实施例, 在此不再赘述。
上述实施例的无线局域网络的安全建立方法, 通过采用上述技术方案, UE 与 WLAN节点之间能够基于推演密钥建立安全连接, 能够克服现有技术中 WLAN工作在 open模式下, UE和 WLAN节点之间不建立安全连接, UE和 WLAN 节点之间的数据以明文方式传输, 导致 UE与 WLAN节点之间通信的安全性能较 差的缺陷, 采用本实施例的技术方案, 能够在 UE和 WLAN节点之间建立安全连 接, 提高 UE与 WLAN节点之间通信的安全性。
图 3为本发明再一实施例提供的 WLAN的安全建立方法的流程图。 如图 3所 示, 本实施例的 WLAN的安全建立方法的执行主体为移动通信网络中的网元设 备。 本实施例的 WLAN的安全建立方法, 具体可以包括如下步骤:
300、 UE接入的移动通信网络中的网元设备接收 WLAN节点发送的密钥请求 消息; 该密钥请求消息中携带有 UE的身份标识符;
301、 网元设备根据密钥请求消息中的 UE的身份标识符,获取对应的推演密 钥;
本实施例中该推演密钥为网元设备根据第一密钥和推演参数进行推演得 到; 其中第一密钥为网元设备与 UE在执行空口安全时的共享密钥或者根据网元 设备与 UE在执行空口安全时的共享密钥推演得出的。 推演参数为网元设备与 U 协商确定的。
302、 网元设备向 WLAN节点发送推演密钥, 以供 WLAN节点基于推演密钥 与获取到推演密钥的 U E之间建立安全连接。
其中 UE获取到的推演密钥与 WLAN节点接收网元设备发送的推演密钥相 同。 本实施例与上述图 1或者图 2所示实施例的区别仅在于: 上述图 1所示实施例 在 UE侧描述本发明的技术方案,图 2所示实施例在 WLAN节点侧描述本发明的技 术方案, 而本实施例在移动通信网络中的网元设备侧描述本发明的技术方案, 其余实施过程完全相同, 详细可以参考上述图 1或者图 2所示实施例的记载, 在 此不再赘述。
本实施例的无线局域网络的安全建立方法, 通过采用上述技术方案, UE与
WLAN节点之间能够基于推演密钥建立安全连接, 能够克服现有技术中 WLAN 工作在 open模式下, UE和 WLAN节点之间不建立安全连接, UE和 WLAN节点之 间的数据以明文方式传输, 导致 UE与 WLAN节点之间通信的安全性能较差的缺 陷, 采用本实施例的技术方案, 能够在 UE和 WLAN节点之间建立安全连接, 提 高 UE与 WLAN节点之间通信的安全性。
可选地, 在上述图 3所示实施例的技术方案的基础上, 还可以包括如下可选 技术方案, 构成图 3所示实施例的可选实施例。
在图 3所示实施例的可选实施例中, 在步骤 301之前还包括如下步骤: 303、 网元设备获取第一密钥。
可选地, 在图 3所示实施例的可选实施例中, 步骤 303 "网元设备获取第一 密钥"之后, 步骤 301 "网元设备根据密钥请求消息中的 UE的身份标识符, 获取 对应的推演密钥" 之前, 还可以包括如下步骤:
( 1 ) 网元设备根据第一密钥和推演参数进行推演得到第二密钥;
( 2 )建立第二密钥与 UE的身份标识符之间的对应关系。
此时对应的步骤 301 "网元设备根据密钥请求消息中的 UE的身份标识符,获 取对应的推演密钥" , 具体可以包括: 网元设备根据第二密钥与 UE的身份标识 符之间的对应关系、 以及密钥请求消息中的 UE的身份标识符, 获取第二密钥。 即本实施例中的推演密钥为第二密钥。
此时对应的步骤 302 "网元设备向 WLAN节点发送推演密钥, 以供 WLAN节 点基于推演密钥与 UE之间建立安全连接" , 具体可以包括: 网元设备向 WLAN 节点发送第二密钥, 以供 WLAN节点基于第二密钥与 UE之间建立安全连接。
或者进一步可选地, 当在步骤 303 "网元设备获取第一密钥"之后, 步骤 301 "网元设备根据密钥请求消息中的 UE的身份标识符, 获取对应的推演密钥" 之 前, 还包括上述步骤(1 )和(2 ) 的时候, 此时对应的步骤 300 "网元设备接收 WLAN节点发送的携带 UE的身份标识符的密钥请求消息" 还可以具体包括: 网 元设备接收 WLAN节点发送的携带 UE的身份标识符和 WLAN节点的身份标识符 的密钥请求消息。 或者可选地, 网元设备接收 WLAN节点发送的携带密钥请求 消息中也可以不携带 WLAN节点的身份标识符, 而由网元设备自己去获取 WLAN节点的身份标识符, 例如网元设备可以接收 WLAN节点发送的携带 UE的 身份标识符的密钥请求消息之后,获取该 WLAN节点的 IP地址,再根据该 WLAN 节点的 IP地址获取该 WLAN节点的身份标识符,实际应用中网元设备还可以采用
其他方法获取 WLAN节点的身份标识符。 此外, WLAN节点可以是 WLAN节点 SSID 、 或者 WLAN节点的 MAC地址或者其他的能够唯一标识 WLAN节点的身 份信息。
此时对应的步骤 301 "网元设备根据密钥请求消息中的 UE的身份标识符,获 取对应的推演密钥" , 具体可以包括如下步骤:
( a )网元设备根据第二密钥与 UE的身份标识符之间的对应关系、 以及密钥 请求消息中的 UE的身份标识符, 获取第二密钥;
( b )网元设备根据第二密钥与密钥请求消息中的 WLAN节点的身份标识符 推演得到第三密钥。 即该技术方案中, 推演密钥为第三密钥。
此时对应的步骤 302 "网元设备向 WLAN节点发送推演密钥, 以供 WLAN节 点基于推演密钥与 UE之间建立安全连接" , 具体可以包括: 网元设备向 WLAN 节点发送第三密钥, 以供 WLAN节点基于第三密钥与 UE之间建立安全连接。
可选地, 在图 3所示实施例的可选实施例中, 上述实施例中的移动通信网络 可以为 GSM网络、 UMTS、 LTE系统、 CDMA网络或 GPRS网络; 网元设备可以 为 GSM 网络的 BSC、 UMTS的 RNC、 GPRS 网络的 SGSN、 LTE系统的 MME或 者 LTE系统中的 eNB。
可选地, 在图 3所示实施例的可选实施例中, UE的身份标识符为 UE的 MAC 地址、 UE的 IMSI、 UE的 TMSI、 UE的 P-TMSI、 UE的 GUTI、 UE的 S-TMSI、 UE 的 RNTI或者 UE的 MSISDN。
进一步可选地, 当 UE的身份标识符为 UE的 WLAN接口的 MAC地址时, 步 骤 300 "网元设备接收 WLAN节点发送的携带 UE的身份标识符的密钥请求消息" 之前, 还可以包括: 网元设备接收 UE发送的 UE的身份标识符。 例如网元设备具 体可以接收 UE采用加密的方式发送的 UE的身份标识符,例如加密的消息可以为 加密的附着完成( Attach Complete )消息、 RAU消息完成( Complete )消息、 TAU 完成( Complete )消息、 NAS SMC消息或者 UE 的容量迁移( capability transfer ) 消息等等消息。 这样, 采用上述方案可以对 UE的身份标识符进行有效地保护, 从而能够有效地保证推演密钥的安全性, 进一步有效地增强了 UE和 WLAN节点 之间的安全性连接。
需要说明的是, 上述图 1所示实施例的可选实施例中的能够应用在网元设备 侧的可选技术方案, 均可以用于在图 3所示实施例的可选实施例中, 详细可以参 考上述图 1所示实施例的可选实施例, 在此不再赘述。
上述实施例的无线局域网络的安全建立方法, 通过采用上述技术方案, UE 与 WLAN节点之间能够基于推演密钥建立安全连接, 能够克服现有技术中 WLAN工作在 open模式下, UE和 WLAN节点之间不建立安全连接, UE和 WLAN 节点之间的数据以明文方式传输, 导致 UE与 WLAN节点之间通信的安全性能较 差的缺陷, 采用本实施例的技术方案, 能够在 UE和 WLAN节点之间建立安全连 接, 提高 UE与 WLAN节点之间通信的安全性。
图 4为本发明一实施例提供的 WLAN的安全建立方法的信令图。 本实施例在 上述实施例的基础上, 以移动通信网络为 GSM网络, 网元设备为 BSC, UE的身 份标识符为 UE的 MAC地址为例详细介绍本发明实施例的技术方案。
如图 4所示, 本实施例的 WLAN的安全建立方法, 具体可以包括如下步骤:
400、 UE接入 GSM网络, 并与 GSM网络中的 BSC执行空口安全, UE和 BSC 获取执行空口安全时的共享密钥, 并基于该共享密钥获取第一密钥;
例如可以参考上述图 1-图 3所示实施例的记载, 第一密钥为该共享密钥或者 才艮据该共享密钥推演得出的。
401、 UE向 BSC发送 UE的 MAC地址;
例如 UE可以在 RRC消息中携带 UE的 MAC地址以发送给 BSC。本发明实施例 中当 UE的身份标识符为 MAC地址之外的其他时, BSC可以从自身中获取到, 可 以省去该步骤 401。
402、 UE和 BSC根据第一密钥和推演参数推演得到第二密钥;
本实施例中该推演参数可以由 UE和 BSC协商确定。 步骤 401和步骤 402可以 无先后顺序。
403、 BSC存储该 UE的 MAC地址与第二密钥的对应关系;
404、 WLAN节点向 BSC发送携带 UE的 MAC地址的密钥请求消息; 例如在 UE接入 WLAN节点时向 WLAN节点发送 WiFi消息时已经将该 UE的 MAC地址告诉给 WLAN节点, 详细可以参考相关现有技术, 在此不再赘述。
405、 BSC根据密钥请求消息中的 UE的 MAC地址以及 UE的 MAC地址与第二 密钥的对应关系, 获取该 UE对应的第二密钥;
406、 BSC向 WLAN节点发送给第二密钥;
407、 UE和 WLAN节点基于该第二密钥建立 WLAN安全连接。
本实施例中 WLAN节点向 BSC发送的密钥请求消息中还可以携带 WLAN节 点的身份标识符, 此时步骤 405之后, 可以执行 UE和 BSC基于该第二密钥和
WLAN节点的身份标识符进行推演得到第三密钥,此时对应的 BSC向 WLAN节点 发送该第三密钥, 此时对应的 UE和 WLAN节点基于该第三密钥建立安全连接。
本实施例的无线局域网络的安全建立方法, 通过采用上述技术方案, UE与 WLAN节点之间能够基于第二密钥或者第三密钥建立安全连接, 能够克服现有 技术中 WLAN工作在 open模式下, UE和 WLAN节点之间不建立安全连接, UE和 WLAN节点之间的数据以明文方式传输, 导致 UE与 WLAN节点之间通信的安全 性能较差的缺陷, 采用本实施例的技术方案, 能够在 UE和 WLAN节点之间建立 安全连接, 提高 UE与 WLAN节点之间通信的安全性。
图 5为本发明另一实施例提供的 WLAN的安全建立方法的信令图。 本实施例 在上述实施例的基础上, 以移动通信网络为 LTE网络, 网元设备为 eNB , UE的 身份标识符为 UE的 MAC地址为例详细介绍本发明实施例的技术方案。
如图 5所示, 本实施例的 WLAN的安全建立方法, 具体可以包括如下步骤:
500、 UE接入 LTE网络, 并与 LTE网络中的 eNB执行空口安全, UE和 eNB获 取执行空口安全时的共享密钥, 并基于该共享密钥获取第一密钥;
例如可以参考上述图 1-图 3所示实施例的记载, 第一密钥为该共享密钥或者 才艮据该共享密钥推演得出的。
501、 UE向 MME发送 UE的 MAC地址;
例如 UE在 NAS SMC中将 UE的 MAC地址发给 MME。
502、 MME向 eNB发送 UE的 MAC地址;
例如 MME将 UE的 MAC地址通过 SI消息转发给 eNB。
可选地, UE也可以在 RRC消息中将 UE的 MAC地址发给 eNB。
本发明实施例中当 UE的身份标识符为 MAC地址之外的其他时, BSC可以从 自身中获取到, 可以省去该步骤 401。
503、 UE和 eNB根据第一密钥和推演参数推演得到第二密钥;
本实施例中该推演参数可以由 UE和 eNB协商确定。 步骤 503和步骤 501步骤
502可以无先后顺序。
504、 eNB存储该 UE的 MAC地址与第二密钥的对应关系;
505、 WLAN节点向 eNB发送携带 UE的 MAC地址和 WLAN节点身份标识符 的密钥请求消息;
例如在 UE接入 WLAN节点时向 WLAN节点发送 WiFi消息时已经将该 UE的 MAC地址告诉给 WLAN节点, 详细可以参考相关现有技术, 在此不再赘述。
506、 eNB根据密钥请求消息中的 UE的 MAC地址以及 UE的 MAC地址与第二 密钥的对应关系, 获取该 UE对应的第二密钥;
507、 eNB和 UE基于该第二密钥和密钥请求消息中的 WLAN节点身份标识符 推演得到第三密钥;
508、 eNB向 WLAN节点发送给第三密钥;
509、 UE和 WLAN节点基于该第三密钥建立 WLAN安全连接。
本实施例的无线局域网络的安全建立方法, 通过采用上述技术方案, UE与 WLAN节点之间能够基于第三密钥建立安全连接, 能够克服现有技术中 WLAN 工作在 open模式下, UE和 WLAN节点之间不建立安全连接, UE和 WLAN节点之 间的数据以明文方式传输, 导致 UE与 WLAN节点之间通信的安全性能较差的缺 陷, 采用本实施例的技术方案, 能够在 UE和 WLAN节点之间建立安全连接, 提 高 UE与 WLAN节点之间通信的安全性。
上述图 4和图 5仅为本发明实施例的两种可选形式的实施例, 根据上述图 1- 图 3所示实施例及对应的可选实施例中, 还可以推理得到本发明的其他实施例的 信令图, 在此不再——举例赘述。
图 6为本发明又一实施例提供的 WLAN的安全建立方法的流程图。 如图 6所 示, 本实施例的 WLAN的安全建立方法的执行主体为 UE, 本实施例的 WLAN的 安全建立方法, 具体可以包括如下步骤:
600、 UE获取第一密钥;
本实施例中的第一密钥为 UE与接入的移动通信网络中的第一网元设备在执 行空口安全时的共享密钥, 或者第一密钥为根据 UE与接入的移动通信网络中的 第一网元设备在执行空口安全时的共享密钥推演得出的; UE根据 UE的身份标识 符和第一密钥推演生成认证用户名和认证信任状。
601、 UE根据认证用户名和认证信任状与第一网元设备或者第二网元设备进 行扩展认证协议 ( Extensible Authentication Protocol; EAP )认证;
602、 UE在认证完成后与 WLAN节点之间建立安全连接。
本实施例中的 EAP认证过程详细可以参考现有技术中的 EAP认证,在此不再 赘述。
本实施例中的第二网元设备从第一网元设备处获取认证用户名和认证信任 状; 或者第二网元设备从第一网元设备处获取 UE的身份标识符和第一密钥, 并 根据 UE的身份标识符和第一密钥推演生成认证用户名和认证信任状。 本实施例
中的第一网元设备和第二网元设备仅为对两个网元设备进行命名, 实际应用中, 两个网元设备的名称亦可以互换。
本实施例的无线局域网络的安全建立方法, 通过采用上述技术方案, UE根 据 UE的身份标识符和第一密钥推演生成认证用户名和认证密码; 并由 UE根据认 证用户名和认证密码与 UE接入的移动通信网络中的网元设备进行 EAP认证, 并 在认证完成后 UE与 WLAN节点之间建立安全连接; 其中第一密钥为用户设备与 接入的移动通信网络中的网元设备在执行空口安全时的共享密钥或者根据共享 密钥推演得出的。 采用本实施例的上述技术方案, 能够克服现有技术中 WLAN 工作在 open模式下, UE和 WLAN节点之间不建立安全连接, UE和 WLAN节点之 间的数据以明文方式传输, 导致 UE与 WLAN节点之间通信的安全性能较差的缺 陷, 采用本实施例的技术方案, 能够在 UE和 WLAN节点之间建立安全连接, 提 高 UE与 WLAN节点之间通信的安全性。
可选地,上述实施例中的移动通信网络可以为 GSM网络、 UMTS、 LTE系统、 CDMA网络或 GPRS网络; 网元设备可以为 GSM 网络的 BSC、 UMTS的 RNC、 GPRS 网络的 SGSN、 LTE系统的 MME或者 LTE系统中的 eNB。
可选地, 上述实施例中的 UE的身份标识符为 UE的 MAC地址、 UE的 IMSI、 UE的 TMSI、 UE的 P-TMSI、 UE的 GUTI、 UE的 S-TMSI、 UE的 RNTI或者 UE的 MSISDN。
图 7为本发明再另一实施例提供的 WLAN的安全建立方法的流程图。 如图 7 所示, 本实施例的 WLAN的安全建立方法的执行主体为第一网元设备, 本实施 例的 WLAN的安全建立方法, 具体可以包括如下步骤:
700、 UE接入的移动通信网络中的第一网元设备获取 UE的认证用户名和认 证信任状;
本实施例中的认证用户名和认证信任状为根据 UE的身份标识符和第一密钥 推演生成的; 第一密钥为 UE与接入的移动通信网络中的第一网元设备或者第二 网元设备在执行空口安全时的共享密钥, 或者第一密钥为根据 UE与接入的移动 通信网络中的第一网元设备或者第二网元设备在执行空口安全时的共享密钥推 演得出的。
701、 第一网元设备根据认证用户名和认证信任状与 UE进行 EAP认证; 702、 第一网元设备在 EAP认证完成后, 向 WLAN节点发送认证完成, 以指 示 WLAN节点与 UE之间建立安全连接。
本实施例与上述图 6所示实施例的区别仅在于: 上述图 6所示实施例在 UE侧 描述本发明的技术方案, 而本实施例在移动通信网络中的第一网元设备侧描述 本发明的技术方案, 其余实施过程完全相同, 详细可以参考上述图 6所示实施例 的记载, 在此不再赘述。
本实施例的无线局域网络的安全建立方法, 通过采用上述技术方案, 第一 网元设备获取 UE的认证用户名和认证信任状, 并根据认证用户名和认证密码与 UE进行 EAP认证,并在认证完成后,向 WLAN节点发送认证完成,以指示 WLAN 节点与 UE之间建立安全连接;其中认证用户名和认证信任状为根据 UE的身份标 识符和第一密钥推演生成的; 第一密钥为 UE与接入的移动通信网络中的第一网 元设备或者第二网元设备在执行空口安全时的共享密钥或者根据共享密钥推演 得出的。采用本实施例的上述技术方案, 能够克服现有技术中 WLAN工作在 open 模式下, UE和 WLAN节点之间不建立安全连接, UE和 WLAN节点之间的数据以 明文方式传输, 导致 UE与 WLAN节点之间通信的安全性能较差的缺陷, 采用本 发明实施例的技术方案, 能够在 UE和 WLAN节点之间建立安全连接, 提高 UE与 WLAN节点之间通信的安全性。
可选地, 在上述图 7所示实施例的技术方案的基础上, 还可以包括如下可选 技术方案, 构成图 7所示实施例的可选实施例。
在图 7所示实施例的可选实施例中, 步骤 700 "UE接入的移动通信网络中的 第一网元设备获取 UE的认证用户名和认证信任状" , 具体可以包括如下步骤: ( 1 ) 第一网元设备接收第二网元设备发送的 UE的 UE的身份标识符和第一 密钥, 该第一密钥为 UE与第二网元设备在执行空口安全时的共享密钥或者根据 共享密钥推演得出的;
( 2 )第一网元设备根据 UE的身份标识符和第一密钥推演生成认证用户名和 认证信任状。
或者可选地, 步骤 700 "UE接入的移动通信网络中的第一网元设备获取 UE 的认证用户名和认证信任状" , 具体可以包括: 第一网元设备接收第二网元设 备发送的认证用户名和认证信任状, 该认证用户名和认证信任状为第二网元设 备根据 UE的身份标识符和第一密钥推演生成的,第一密钥为 UE与第二网元设备 在执行空口安全时的共享密钥或者根据共享密钥推演得出的。
或者进一步可选地, 步骤 700 "UE接入的移动通信网络中的第一网元设备获 取 UE的认证用户名和认证信任状" , 具体可以包括如下步骤:
( a )第一网元设备获取第一密钥; 述第一密钥为第一网元设备与 UE在执行 空口安全时的共享密钥或者根据共享密钥推演得出的;
( b )第一网元设备根据 UE的身份标识符和第一密钥推演生成认证用户名和 认证信任状。
可选地,上述实施例中的移动通信网络可以为 GSM网络、 UMTS、 LTE系统、
CDMA网络或 GPRS网络; 网元设备可以为 GSM 网络的 BSC、 UMTS的 RNC、 GPRS 网络的 SGSN、 LTE系统的 MME或者 LTE系统中的 eNB。
可选地, 上述实施例中的 UE的身份标识符为 UE的 MAC地址、 UE的 IMSI、 UE的 TMSI、 UE的 P-TMSI、 UE的 GUTI、 UE的 S-TMSI、 UE的 RNTI或者 UE的 MSISDN。
需要说明的是, 上述图 6所示实施例的可选实施例中的能够应用在网元设备 侧的可选技术方案, 均可以用于在图 7所示实施例的可选实施例中, 详细可以参 考上述图 6所示实施例的可选实施例, 在此不再赘述。
通过采用上述实施例的技术方案, 第一网元设备获取 UE的认证用户名和认 证信任状, 并根据认证用户名和认证密码与 UE进行 EAP认证, 并在认证完成后, 使得 UE与 WLAN节点之间建立安全连接; 其中认证用户名和认证信任状为根据 UE的身份标识符和第一密钥推演生成的; 第一密钥为 UE与接入的移动通信网络 中的第一网元设备或者第二网元设备在执行空口安全时的共享密钥或者根据共 享密钥推演得出的。采用本实施例的上述技术方案,能够克服现有技术中 WLAN 工作在 open模式下, UE和 WLAN节点之间不建立安全连接, UE和 WLAN节点之 间的数据以明文方式传输, 导致 UE与 WLAN节点之间通信的安全性能较差的缺 陷,采用本发明实施例的技术方案, 能够在 UE和 WLAN节点之间建立安全连接, 提高 UE与 WLAN节点之间通信的安全性。
本领域普通技术人员可以理解: 实现上述各方法实施例的全部或部分步骤 可以通过程序指令相关的硬件来完成。 前述的程序可以存储于一计算机可读取 存储介质中。 该程序在执行时, 执行包括上述各方法实施例的步骤; 而前述的 存储介质包括: ROM、 RAM, 磁碟或者光盘等各种可以存储程序代码的介质。
图 8为本发明一实施例提供的 UE的结构示意图。如图 8所示,本实施例的 UE, 具体可以包括获取模块 10、 推演模块 11和建立模块 12。
其中获取模块 10用于获取第一密钥; 该第一密钥为本实施例的 UE与接入的 移动通信网络中的网元设备在执行空口安全时的共享密钥, 或者该第一密钥为
根据 UE与接入的移动通信网络中的网元设备在执行空口安全时的共享密钥推演 得出的。 推演模块 11与获取模块 10连接, 推演模块 11用于根据获取模块 10获取 的第一密钥和推演参数进行推演得到推演密钥, 推演参数为 UE和网元设备协商 确定的。 建立模块 12与推演模块 11连接, 建立模块用于根据推演模块 11推演得 到的推演密钥与获取到推演密钥的 WLAN节点之间建立安全连接, WLAN节点 获取到的推演密钥与 UE获取的推演密钥相同, 例如 WLAN节点可以向网元设备 中请求获取推演密钥, 网元设备根据第一密钥和推演参数推演得到推演密钥。
本实施例中, UE与网元设备均可以获知推演参数, 可以认为推演参数是两 者协商确定的。 推演参数具体可以为一个或者多个。 例如推演参数可以为 UE和 网元设备事先约定好的, 或者在推演推演密钥时在线协商的。 例如可以由 UE提 供一些参数作为推演参数, 然后告知网元设备。 或者由网元设备提供一些参数 作为推演参数, 然后告知网元设备。 或者可以由 UE提供一些参数或者由网元设 备提供一些参数, 然后 UE和网元设备交换各自提供的参数, 此时对应的推演参 数由 UE提供给参数和网元设备提供的参数共同组成。
本实施例的 UE, 通过采用上述模块实现 WLAN的安全建立与上述相关方法 实施例的实现机制相同, 详细可以参考上述相关方法实施例的记载, 在此不再 赘述,
本实施例的 UE, 通过采用上述模块, UE能够与 WLAN节点之间能够基于推 演密钥建立安全连接, 能够克服现有技术中 WLAN工作在 open模式下, UE和 WLAN节点之间不建立安全连接, UE和 WLAN节点之间的数据以明文方式传输, 导致 UE与 WLAN节点之间通信的安全性能较差的缺陷, 采用本实施例的技术方 案, 能够在 UE和 WLAN节点之间建立安全连接, 提高 UE与 WLAN节点之间通信 的安全性。
图 9为本发明另一实施例提供的 UE的结构示意图。 如图 9所示, 本实施例的 UE, 在上述图 8所示实施例的基础上, 还可以包括如下技术方案。
本实施例的 UE中包括发送模块 13。该发送模块 13用于向 WLAN节点发送 UE 的身份标识符, 以供 WLAN节点根据 UE的身份标识符, 向网元设备请求获取 UE 对应的推演密钥。
可选地, 本实施例的 UE中, 推演模块 11具体用于根据获取模块 10获取的第 一密钥和推演参数进行推演得到第二密钥; 建立模块 12具体用于根据推演模块 11推演得打的第二密钥与 WLAN节点之间建立安全连接。
可选地, 本实施例的 UE中, 推演模块 11具体用于根据第一密钥和推演参数 进行推演得到第二密钥; 并根据第二密钥和 WLAN节点的身份标识符推演得到 第三密钥; UE在开始接入 WLAN节点的时候, 可以获取到 WLAN节点的身份标 识符。 而本实施例中, 在网元设备一侧, 网元设备也可以获取到该 WLAN节点 的身份标识符, 并根据第二密钥和 WLAN节点的身份标识符进行推演得到第三 密钥。 建立模块 23具体用于根据推演模块 11推演得到的第三密钥与 WLAN节点 之间建立安全连接。
可选地,本实施例的 UE中, UE的身份标识符为 UE的 MAC地址、 UE的 IMSI、 UE的 TMSI、 UE的 P-TMSI、 UE的 GUTI、 UE的 S-TMSI、 UE的 RNTI或者 UE的 MSISDN。
进一步可选地,本实施例的 UE中的发送模块 13还用于当 UE的身份标识符为 UE的 WLAN接口的 MAC地址时, 向网元设备发送 UE的身份标识符。 例如该发 送模块 13具体用于当 UE的身份标识符为 UE的 WLAN接口的媒体访问控制地址 时, 采用加密的方式向网元设备发送 UE的身份标识符。 例如本实施例的 UE中还 可以包括携带模块, 用于在附着完成( Attach Complete ) 消息、 RAID' 息完成 ( Complete ) 消息、 TAU完成(Complete ) 消息、 NAS SMC消息或者 UE 的容 量迁移( capability transfer )消息等等中携带 UE的身份标识符, 并由发送模块 13 在网元设备发送携带 UE的身份标识符的加密的附着完成(Attach Complete ) 消 息、 RAU消息完成(Complete ) 消息、 TAU完成(Complete ) 消息、 NAS SMC 消息或者 UE 的容量迁移 ( capability transfer ) 消息等等。
可选地, 本实施例的 UE中, 移动通信网络可以为 GSM网络、 UMTS、 LTE 系统、 CDMA网络或 GPRS网络; 网元设备可以为 GSM 网络的 BSC、 UMTS的 RNC、 GPRS 网络的 SGSN、 LTE系统的 MME或者 LTE系统中的 eNB。
上述实施例的 UE, 通过采用上述模块实现 WLAN的安全建立与上述相关方 法实施例的实现机制相同, 详细可以参考上述相关方法实施例的记载, 在此不 再赘述,
上述实施例的 UE, 通过采用上述模块, UE能够与 WLAN节点之间能够基于 推演密钥建立安全连接, 能够克服现有技术中 WLAN工作在 open模式下, UE和 WLAN节点之间不建立安全连接, UE和 WLAN节点之间的数据以明文方式传输, 导致 UE与 WLAN节点之间通信的安全性能较差的缺陷, 采用本实施例的技术方 案, 能够在 UE和 WLAN节点之间建立安全连接, 提高 UE与 WLAN节点之间通信
的安全性。
图 10为本发明实施例提供的 WLAN节点设备的结构示意图。 如图 10所示, 本实施例的 WLAN节点设备中, 具体可以包括: 接收模块 20、 发送模块 21和建 立模块 22。
其中接收模块 20用于接收 UE发送的 UE的身份标识符;发送模块 21与接收模 块 20连接, 发送模块 21用于向 UE接入的移动通信网络中的网元设备发送携带接 收模块 20接收的 UE的身份标识符的密钥请求消息; 接收模块 20还用于接收网元 设备发送的 UE的身份标识符对应的推演密钥; 该推演密钥为网元设备根据第一 密钥和推演参数进行推演得到, 该第一密钥为 UE与网元设备在执行空口安全时 的共享密钥, 或者该第一密钥为根据 UE与网元设备在执行空口安全时的共享密 钥推演得出的; 推演参数为 UE和网元设备协商确定的, 例如该推演参数的确定 可以参考上述相关实施例的记载。 建立模块 22与接收模块 20连接, 建立模块 22 用于基于接收模块 20接收的推演密钥与获取到推演密钥的 UE之间建立安全连 接, 其中 UE获取到的推演密钥与 WLAN节点获取的所述推演密钥相同, 例如 UE 可以才艮据第一密钥和推演参数推演得到推演密钥。
本实施例的 WLAN节点设备, 通过采用上述模块实现 WLAN的安全建立与 上述相关方法实施例的实现机制相同, 详细可以参考上述相关方法实施例的记 载, 在此不再赘述,
本实施例的 WLAN节点设备, 通过采用上述模块能够实现 UE与 WLAN节点 之间基于推演密钥建立安全连接, 能够克服现有技术中 WLAN工作在 open模式 下, UE和 WLAN节点之间不建立安全连接, UE和 WLAN节点之间的数据以明文 方式传输, 导致 UE与 WLAN节点之间通信的安全性能较差的缺陷, 采用本实施 例的技术方案, 能够在 UE和 WLAN节点之间建立安全连接, 提高 UE与 WLAN节 点之间通信的安全性。
可选地, 在上述图 10所示实施例的基础上, 接收模块 20具体用于接收网元 设备发送的 UE的身份标识符对应的第二密钥,该第二密钥为网元设备根据 UE的 身份标识符以及网元设备中存储的 UE的身份标识符与第二密钥之间的对应关系 获取的; 该第二密钥为网元设备根据第一密钥和推演参数进行推演得到; 本实 施例中推演密钥为第二密钥。 建立模块 22具体用于基于接收模块 20接收的第二 密钥与 UE之间建立安全连接.
或者可选地, 在上述图 8所示实施例的基础上, 发送模块 21具体用于向网元
设备发送携带接收模块 20接收的 UE的身份标识符和 WLAN节点的身份标识符的 密钥请求消息; 接收模块 20具体用于接收网元设备发送的第三密钥, 该第三密 钥为网元设备根据第二密钥与 WLAN节点的身份标识符推演得到的; 该第二密 钥为网元设备根据 UE的身份标识符以及网元设备中存储的 UE的身份标识符与 第二密钥之间的对应关系获取的; 该第二密钥为网元设备根据第一密钥和推演 参数进行推演得到, 本实施例中, 推演密钥为第三密钥。 建立模块 22具体用于 基于接收模块 20接收的第三密钥与 UE之间建立安全连接。
可选地, 在上述图 10所示实施例的基础上, UE的身份标识符为 UE的 MAC 地址、 UE的 IMSI、 UE的 TMSI、 UE的 P-TMSI、 UE的 GUTI、 UE的 S-TMSI、 UE 的 RNTI或者 UE的 MSISDN。
可选地, 在上述图 10所示实施例的基础上, 移动通信网络可以为 GSM网络、 UMTS、 LTE系统、 CDMA网络或 GPRS网络; 网元设备可以为 GSM 网络的 BSC、 UMTS的 RNC、 GPRS 网络的 SGSN、 LTE系统的 MME或者 LTE系统中的 eNB。
上述实施例的 WLAN节点设备, 通过采用上述模块实现 WLAN的安全建立 与上述相关方法实施例的实现机制相同, 详细可以参考上述相关方法实施例的 记载, 在此不再赘述,
上述实施例的 WLAN节点设备, 通过采用上述模块能够实现 UE与 WLAN节 点之间基于推演密钥建立安全连接, 能够克服现有技术中 WLAN工作在 open模 式下, UE和 WLAN节点之间不建立安全连接, UE和 WLAN节点之间的数据以明 文方式传输, 导致 UE与 WLAN节点之间通信的安全性能较差的缺陷, 采用本实 施例的技术方案, 能够在 UE和 WLAN节点之间建立安全连接, 提高 UE与 WLAN 节点之间通信的安全性。
图 11为本发明一实施例提供的网元设备的结构示意图。 本实施例的网元设 备位于 UE接入的移动通信网络中。 如图 11所示, 本实施例的网元设备具体可以 包括: 接收模块 30、 获取模块 31和发送模块 32。
其中接收模块 30用于接收 WLAN节点发送的密钥请求消息, 该密钥请求消 息中携带有 UE的身份标识符; 获取模块 31与接收模块 30连接, 获取模块 31用于 根据接收模块 30接收的密钥请求消息中的 UE的身份标识符, 获取对应的推演密 钥; 该推演密钥为网元设备根据第一密钥和推演参数进行推演得到; 第一密钥 为网元设备与 UE在执行空口安全时的共享密钥, 或者第一密钥为根据网元设备 与 UE在执行空口安全时的共享密钥推演得出的;该推演参数为网元设备与 UE协
商确定的;发送模块 32与获取模块 31连接, 发送模块 32用于向 WLAN节点发送获 取模块 31获取的推演密钥, 以供 WLAN节点基于推演密钥与获取到推演密钥的 UE之间建立安全连接。 其中 UE 获取到的推演密钥与 WLAN节点接收网元设备 发送的推演密钥相同。
本实施例的网元设备, 通过采用上述模块实现 WLAN的安全建立与上述相 关方法实施例的实现机制相同, 详细可以参考上述相关方法实施例的记载, 在 此不再赘述,
本实施例的网元设备, 通过采用上述模块能够实现 UE与 WLAN节点之间基 于推演密钥建立安全连接, 能够克服现有技术中 WLAN工作在 open模式下, UE 和 WLAN节点之间不建立安全连接, UE和 WLAN节点之间的数据以明文方式传 输, 导致 UE与 WLAN节点之间通信的安全性能较差的缺陷, 采用本实施例的技 术方案, 能够在 UE和 WLAN节点之间建立安全连接, 提高 UE与 WLAN节点之间 通信的安全性。
图 12为本发明另一实施例提供的网元设备的结构示意图。 如图 12所示, 本 实施例的网元设备, 在上述图 10所示实施例的基础上, 还可以包括如下技术方 案。
本实施例的网元设备中, 获取模块 31还用于根据密钥请求消息中的 UE的身 份标识符, 获取对应的推演密钥之前, 获取第一密钥。
本实施例的网元设备中, 还包括推演模块 33和建立模块 34。 其中推演模块 33与获取模块 31连接, 用于在获取模块 31获取第一密钥之后, 根据密钥请求消 息中的 UE的身份标识符, 获取对应的推演密钥之前, 根据获取模块 31获取的第 一密钥和推演参数进行推演得到第二密钥; 建立模块 34与推演模块 33连接, 建 立模块 34用于建立推演模块 33推演得到的第二密钥与 UE的身份标识符之间的对 应关系。 此时对应的获取模块 31还与建立模块 34连接, 具体用于根据建立模块 34建立的第二密钥与 UE的身份标识符之间的对应关系、 以及密钥请求消息中的 UE的身份标识符, 获取第二密钥; 即该技术方案中推演密钥为第二密钥。 此时 对应的发送模块 32具体用于向 WLAN节点发送获取模块 31获取的第二密钥, 以 供 WLAN节点基于第二密钥与 UE之间建立安全连接。
或者可选地, 本实施例的网元设备中, 推演模块 33也用于在获取模块 31获 取第一密钥之后, 根据密钥请求消息中的 UE的身份标识符, 获取对应的推演密 钥之前, 根据获取模块 31获取的第一密钥和推演参数进行推演得到第二密钥;
建立模块 34也用于建立获取模块 31获取的第二密钥与 UE的身份标识符之间的对 应关系时, 接收模块 30具体用于接收 WLAN节点发送的携带 UE的身份标识符和 WLAN节点的身份标识符的密钥请求消息; 获取模块 31具体用于根据建立模块 34建立的第二密钥与 UE的身份标识符之间的对应关系、 以及接收模块 30接收的 密钥请求消息中的 UE的身份标识符, 获取第二密钥; 并根据第二密钥与密钥请 求消息中的 WLAN节点的身份标识符推演得到第三密钥; 发送模块 32具体用于 向 WLAN节点发送获取模块 31获取的第三密钥, 以供 WLAN节点基于第三密钥 与 UE之间建立安全连接。 即该技术方案中推演密钥为第三密钥。
可选地, 本实施例的网元设备中, UE的身份标识符为 UE的 MAC地址、 UE 的 IMSI、 UE的 TMSI、 UE的 P-TMSI、 UE的 GUTI、 UE的 S-TMSI、 UE的 RNTI或 者 UE的 MSISDN。
可选地, 本实施例的网元设备中, 接收模块 30还用于当 UE的身份标识符为 UE的 WLAN接口的 MAC地址时, 接收 UE发送的 UE的身份标识符。 例如接收模 块 30还用于当 UE的身份标识符为 UE的 WLAN接口的 MAC地址时, 接收 UE采用 加密的方式发送的 UE的身份标识符。
可选地, 本实施例的网元设备中, 移动通信网络可以为 GSM网络、 UMTS、 LTE 系统、 CDMA网络或 GPRS网络; 网元 i殳备可以为 GSM 网络的 BSC、 UMTS的 RNC、 GPRS 网络的 SGSN、 LTE系统的 MME或者 LTE系统中的 eNB。
本实施例的网元设备, 通过采用上述模块实现 WLAN的安全建立与上述相 关方法实施例的实现机制相同, 详细可以参考上述相关方法实施例的记载, 在 此不再赘述,
本实施例的网元设备, 通过采用上述模块能够实现 UE与 WLAN节点之间基 于推演密钥建立安全连接, 能够克服现有技术中 WLAN工作在 open模式下, UE 和 WLAN节点之间不建立安全连接, UE和 WLAN节点之间的数据以明文方式传 输, 导致 UE与 WLAN节点之间通信的安全性能较差的缺陷, 采用本实施例的技 术方案, 能够在 UE和 WLAN节点之间建立安全连接, 提高 UE与 WLAN节点之间 通信的安全性。
图 13为本发明再一实施例提供的 UE的结构示意图。 如图 13所示, 本实施例 的 IE, 具体可以包括获取模块 40、 生成模块 41、 认证模块 42和建立模块 43。
其中获取模块 40用于获取第一密钥; 该第一密钥为 UE与接入的移动通信网 络中的第一网元设备在执行空口安全时的共享密钥, 或者根据 UE与接入的移动
通信网络中的第一网元设备在执行空口安全时的共享密钥推演得出的; 生成模 块 41根据 UE的身份标识符和获取模块 40获取的第一密钥推演生成认证用户名和 认证信任状; 认证模块 42与生成模块 41连接, 认证模块 42用于根据生成模块 41 生成的认证用户名和认证信任状与第一网元设备或者第二网元设备进行 EAP认 证; 第二网元设备为移动通信网络中的所述第一网元设备之外的其他网元设备; 第二网元设备从第一网元设备处获取认证用户名和认证信任状; 或者第二网元 设备从第一网元设备处获取 UE的身份标识符和第一密钥,并根据 UE的身份标识 符和第一密钥推演生成认证用户名和认证信任状。 建立模块 43与认证模块 42连 接,建立模块 43用于在认证模块 42进行 EAP认证完成后与 WLAN节点之间建立安 全连接。
本实施例的 UE, 通过采用上述模块实现 WLAN的安全建立与上述相关方法 实施例的实现机制相同, 详细可以参考上述相关方法实施例的记载, 在此不再 赘述,
本实施例的 UE, 通过采用上述模块 UE能够根据 UE的身份标识符和第一密 钥推演生成认证用户名和认证密码; 并由 UE根据认证用户名和认证密码与 UE接 入的移动通信网络中的网元设备进行 EAP认证, 并在认证完成后 UE与 WLAN节 点之间建立安全连接; 其中第一密钥为用户设备与接入的移动通信网络中的网 元设备在执行空口安全时的共享密钥或者根据共享密钥推演得出的。 采用本实 施例的上述技术方案, 能够克服现有技术中 WLAN工作在 open模式下, UE和 WLAN节点之间不建立安全连接, UE和 WLAN节点之间的数据以明文方式传输, 导致 UE与 WLAN节点之间通信的安全性能较差的缺陷, 采用本发明实施例的技 术方案, 能够在 UE和 WLAN节点之间建立安全连接, 提高 UE与 WLAN节点之间 通信的安全性。
可选地, 上述图 13所示实施例的 UE中, UE的身份标识符为 UE的 MAC地址、 UE的 IMSI、 UE的 TMSI、 UE的 P-TMSI、 UE的 GUTI、 UE的 S-TMSI、 UE的 RNTI 或者 UE的 MSISDN。
可选地, 上述图 13所示实施例的 UE中, 移动通信网络可以为 GSM网络、 UMTS、 LTE系统、 CDMA网络或 GPRS网络; 网元设备可以为 GSM 网络的 BSC、 UMTS的 RNC、 GPRS 网络的 SGSN、 LTE系统的 MME或者 LTE系统中的 eNB。
图 14为本发明再一实施例提供的网元设备的结构示意图。 本实施例的网元 设备位于 UE接入的移动通信网络中。 如图 14所示, 本实施例的网元设备包括获
取模块 50、 认证模块 51和发送模块 52。
其中获取模块 50用于获取 UE的认证用户名和认证信任状; 该认证用户名和 认证信任状为根据 UE的身份标识符和第一密钥推演生成的; 第一密钥为 UE与网 元设备或者第二网元设备在执行空口安全时的共享密钥, 或者第一密钥为根据 UE与网元设备或者第二网元设备在执行空口安全时的共享密钥推演得出的。 认 证模块 51与获取模块 50连接, 认证模块 51用于根据认证用户名和认证信任状与 UE进行 EAP认证, 发送模块 52与认证模块 51连接, 发送模块 52用于在认证模块 51进行 EAP认证成功后, 向 WLAN节点发送认证完成, 以指示 WLAN节点与 UE 之间建立安全连接。
本实施例的网元设备, 通过采用上述模块实现 WLAN的安全建立与上述相 关方法实施例的实现机制相同, 详细可以参考上述相关方法实施例的记载, 在 此不再赘述,
本实施例的网元设备, 通过采用上述模块能够获取 UE的认证用户名和认证 信任状, 并根据认证用户名和认证密码与 UE进行 EAP认证, 并在认证完成后, 使得 UE与 WLAN节点之间建立安全连接; 其中认证用户名和认证信任状为根据 UE的身份标识符和第一密钥推演生成的; 第一密钥为 UE与接入的移动通信网络 中的第一网元设备或者第二网元设备在执行空口安全时的共享密钥或者根据共 享密钥推演得出的。采用本实施例的上述技术方案,能够克服现有技术中 WLAN 工作在 open模式下, UE和 WLAN节点之间不建立安全连接, UE和 WLAN节点之 间的数据以明文方式传输, 导致 UE与 WLAN节点之间通信的安全性能较差的缺 陷,采用本发明实施例的技术方案, 能够在 UE和 WLAN节点之间建立安全连接, 提高 UE与 WLAN节点之间通信的安全性。
可选地, 上述图 14所示实施例的网元设备中, 获取模块 50具体用于接收第 二网元设备发送的 UE的 UE的身份标识符和第一密钥, 该第一密钥为 UE与第二 网元设备在执行空口安全时的共享密钥或者根据 UE与第二网元设备在执行空口 安全时的共享密钥推演得出的; 并根据 UE的身份标识符和第一密钥推演生成认 证用户名和认证信任状。
或者可选地, 上述图 14所示实施例的网元设备中, 获取模块 50具体用于接 收第二网元设备发送的认证用户名和认证信任状, 认证用户名和认证信任状为 第二网元设备根据 UE的身份标识符和第一密钥推演生成的,第一密钥为 UE与第 二网元设备在执行空口安全时的共享密钥或者根据 UE与第二网元设备在执行空
口安全时的共享密钥推演得出的。
或者可选地, 上述图 14所示实施例的网元设备中, 获取模块 50具体用于获 取第一密钥; 第一密钥为第一网元设备与 UE在执行空口安全时的共享密钥或者 根据第一网元设备与 UE在执行空口安全时的共享密钥推演得出的; 并根据 UE的 身份标识符和第一密钥推演生成认证用户名和认证信任状。
可选地, 上述实施例的 UE中, UE的身份标识符为 UE的 MAC地址、 UE的 IMSL UE的 TMSI、 UE的 P-TMSI、 UE的 GUTI、 UE的 S-TMSI、 UE的 RNTI或者 UE的 MSISDN。
可选地,上述实施例的 UE中,移动通信网络可以为 GSM网络、 UMTS、 LTE系统、 CDMA网络或 GPRS网络;网元设备可以为 GSM 网络的 BSC、 UMTS的 RNC、 GPRS 网 络的 SGSN、 LTE系统的 MME或者 LTE系统中的 eNB。
上述实施例的网元设备, 通过采用上述模块实现 WLAN的安全建立与上述 相关方法实施例的实现机制相同, 详细可以参考上述相关方法实施例的记载, 在此不再赘述,
上述实施例的网元设备, 通过采用上述模块能够获取 UE的认证用户名和认 证信任状, 并根据认证用户名和认证密码与 UE进行 EAP认证, 并在认证完成后, 使得 UE与 WLAN节点之间建立安全连接; 其中认证用户名和认证信任状为根据 UE的身份标识符和第一密钥推演生成的; 第一密钥为 UE与网元设备或者第二网 元设备在执行空口安全时的共享密钥或者根据 UE与网元设备或者第二网元设备 的共享密钥推演得出的。 采用本实施例的上述技术方案, 能够克服现有技术中 WLAN工作在 open模式下, UE和 WLAN节点之间不建立安全连接, UE和 WLAN 节点之间的数据以明文方式传输, 导致 UE与 WLAN节点之间通信的安全性能较 差的缺陷, 采用本发明实施例的技术方案, 能够在 UE和 WLAN节点之间建立安 全连接, 提高 UE与 WLAN节点之间通信的安全性。
图 15为本发明一实施例提供的 WLAN的安全建立系统的结构示意图。 如图 15所 示,本实施例的 WLAN的安全建立系统包括: UE60、 WLAN节点设 ^61和网元设^ 62。 UE60、 WLAN节点设名 1和网元设^ 62两两互相通信。
UE60用于获取第一密钥;该第一密钥为 UE60与接入的移动通信网络中的网 元设备 62在执行空口安全时的共享密钥或者根据 UE60与网元设备 62在执行空口 安全时的共享密钥推演得出的。 UE60根据第一密钥和推演参数进行推演得到推 演密钥。 推演参数为 UE60和网元设备 62协商确定的。 UE60还用于向 WLAN节点
设备 61发送 UE的身份标识符。
WLAN节点设备 61接收 UE60发送 UE的身份标识符; 向网元设备 62发送携带 UE的身份标识符的密钥请求消息。
网元设备 62接收 WLAN节点设备 61发送的携带 UE的身份标识符的密钥请求 消息; 根据密钥请求消息中的 UE的身份标识符, 获取对应的推演密钥; 该推演 密钥为网元设备 62根据第一密钥和推演参数进行推演得到; 网元设备 62向 WLAN节点设备 61发送获取的推演密钥。
WLAN节点设备 61接收网元设备 62发送的 UE的身份标识符对应的推演密 钥, 这样, UE60和 WLAN节点设备 61都获取到推演密钥, 则 UE60和 WLAN节点 设备 61根据推演密钥建立安全连接。
可选地, 本实施例中的 UE60具体可以采用上述图 8或者图 9所示实施例的 UE, 本实施例中的 WLAN节点设备 61具体可以采用图 8及后续可选实施例中的 WLAN节点设备, 本实施例中的网元设备 62具体可以采用上述图 11或者图 12所 示实施例的网元设备, 并可以采用上述图 1-图 3所示实施例及相应的后续可选实 施例的技术方案实现 WLAN的安全建立, 详细可以参考上述相关实施例的记载, 在此不再赘述。
本实施例的 WLAN的安全建立系统, 通过采用上述 UE、 WLAN节点设备和 网元设备, UE与 WLAN节点之间能够基于推演密钥建立安全连接, 能够克服现 有技术中 WLAN工作在 open模式下, UE和 WLAN节点之间不建立安全连接, UE 和 WLAN节点之间的数据以明文方式传输, 导致 UE与 WLAN节点之间通信的安 全性能较差的缺陷, 采用本实施例的技术方案, 能够在 UE和 WLAN节点之间建 立安全连接, 提高 UE与 WLAN节点之间通信的安全性。
图 16为本发明另一实施例提供的 WLAN的安全建立系统的结构示意图。 如 图 16所示, 本实施例的 WLAN的安全建立系统包括: UE70和第一网元设备 71和 WLAN节点设备 72。 UE70和第一网元设备 71和 WLAN节点设备 72两两互相通信。
UE70用于获取第一密钥;该第一密钥为 UE70与接入的移动通信网络中的第 一网元设备 71或者第二网元设备(图中未示出 )在执行空口安全时的共享密钥, 或者根据 UE70与第一网元设备 71或者第二网元设备在执行空口安全时的共享密 钥推演得出的; UE根据 UE的身份标识符和第一密钥推演生成认证用户名和认证 信任状; 第一网元设备 71也获取 UE的认证用户名和认证信任状。
例如当第一密钥为 UE70与接入的移动通信网络中的第一网元设备 71在执行
空口安全时的共享密钥或者根据共享密钥推演得出的, 第一网元设备 71也获取 第一密钥; 并根据 UE的身份标识符和第一密钥推演生成认证用户名和认证信任 状。
当第一密钥为 UE70与接入的移动通信网络中的第二网元设备在执行空口安 全时的共享密钥或者根据共享密钥推演得出的。 此时, 第一网元设备 71也从第 二网元设备处获取认证用户名和认证信任状; 认证用户名和认证信任状为第二 网元设备根据 UE的身份标识符和第一密钥推演生成。 或者第一网元设备 71也从 第二网元设备处获取 UE的身份标识符和第一密钥,而由第一网元设备根据 UE的 身份标识符和第一密钥推演生成认证用户名和认证信任状。 第一网元设备 71和 第二网元设备互相通信。
由上述方案, UE70和第一网元设备 71都获取到认证用户名和认证信任状, 然后由 UE70和第一网元设备 71根据认证用户名和认证信任状进行 EAP认证, 并 在认证完成后,第一网元设备 71向 WLAN节点设备 72发送认证完成,以指示 UE70 与 WLAN节点设备 72之间建立安全连接。 其中 UE70和第一网元设备 71在进行 EAP认证的时候, 由 WLAN节点设备 72转发认证消息, 具体地在 EAP认证时涉及 到的认证消息可以参考相关现有技术,
可选地, 本实施例中的 UE70具体可以采用上述图 11所示实施例的 UE, 本实 施例中的第一网元设备 71具体可以采用上述图 14所示实施例的网元设备, 并可 以采用上述图 6-图 7所示实施例及相应的后续可选实施例的技术方案实现 WLAN 的安全建立, 详细可以参考上述相关实施例的记载, 在此不再赘述。
本实施例的 WLAN的安全建立系统, 通过采用上述 UE、 WLAN节点设备和 网元设备, UE能够根据 UE的身份标识符和第一密钥推演生成认证用户名和认证 密码; 并由 UE根据认证用户名和认证密码与 UE接入的移动通信网络中的网元设 备进行 EAP认证, 并在认证完成后 UE与 WLAN节点之间建立安全连接; 其中第 一密钥为用户设备与接入的移动通信网络中的网元设备在执行空口安全时的共 享密钥或者根据共享密钥推演得出的。 采用本实施例的上述技术方案, 能够克 服现有技术中 WLAN工作在 open模式下, UE和 WLAN节点之间不建立安全连接, UE和 WLAN节点之间的数据以明文方式传输,导致 UE与 WLAN节点之间通信的 安全性能较差的缺陷, 采用本发明实施例的技术方案, 能够在 UE和 WLAN节点 之间建立安全连接, 提高 UE与 WLAN节点之间通信的安全性。
以上所描述的装置实施例仅仅是示意性的, 其中作为分离部件说明的单元
可以是或者也可以不是物理上分开的, 作为单元显示的部件可以是或者也可以 不是物理单元, 即可以位于一个地方, 或者也可以分布到至少两个网络单元上。 可以根据实际的需要选择其中的部分或者全部模块来实现本实施例方案的目 的。 本领域普通技术人员在不付出创造性的劳动的情况下, 即可以理解并实施。
最后应说明的是: 以上各实施例仅用以说明本发明的技术方案, 而非对其 限制; 尽管参照前述各实施例对本发明进行了详细的说明, 本领域的普通技术 人员应当理解: 其依然可以对前述各实施例所记载的技术方案进行修改, 或者 对其中部分或者全部技术特征进行等同替换; 而这些修改或者替换, 并不使相 应技术方案的本质脱离本发明各实施例技术方案的范围。
Claims
1、 一种无线局域网络的安全建立方法, 其特征在于, 包括:
用户设备获取第一密钥, 所述第一密钥为所述用户设备与接入的移动通 信网络中的网元设备在执行空口安全时的共享密钥或者根据所述用户设备与 接入的移动通信网络中的网元设备在执行空口安全时的共享密钥推演得出 的;
所述用户设备根据所述第一密钥和推演参数进行推演得到推演密钥, 所 述推演参数为所述用户设备与所述网元设备协商确定的;
所述用户设备根据所述推演密钥与获取到推演密钥的无线局域网络节点 之间建立安全连接, 所述无线局域网络节点获取到的推演密钥与所述用户设 备获取的所述推演密钥相同。
2、 根据权利要求 1所述的方法, 其特征在于, 所述用户设备根据所述推 演密钥与获取到推演密钥的无线局域网络节点之间建立安全连接之前, 所述 方法还包括:
所述用户设备向所述无线局域网络节点发送所述用户设备的身份标识 符, 以供所述无线局域网络节点根据所述用户设备的身份标识符, 向所述网 元设备请求获取所述用户设备对应的推演密钥。
3、 根据权利要求 1或 2所述的方法, 其特征在于,
所述用户设备根据所述第一密钥和推演参数进行推演得到推演密钥, 包 括:所述用户设备根据所述第一密钥和所述推演参数进行推演得到第二密钥; 所述用户设备根据所述推演密钥与无线局域网络节点之间建立安全连 接, 包括: 所述用户设备根据所述第二密钥与无线局域网络节点之间建立安 全连接。
4、 根据权利要求 1或 2所述的方法, 其特征在于,
所述用户设备根据所述第一密钥和推演参数进行推演得到推演密钥, 包 括:所述用户设备根据所述第一密钥和所述推演参数进行推演得到第二密钥; 所述用户设备根据所述第二密钥和所述无线局域网络节点的身份标识符推演 得到第三密钥;
所述用户设备根据所述推演密钥与无线局域网络节点之间建立安全连 接, 包括: 所述用户设备根据所述第三密钥与所述无线局域网络节点之间建
立安全连接。
5、 根据权利要求 1-4任一所述的方法, 其特征在于, 所述用户设备的身 份标识符为所述用户设备的无线局域网络接口的媒体访问控制地址、 所述用 户设备的国际移动用户识别码、 所述用户设备的临时移动用户识别码、 所述 用户设备的分组临时移动用户识别码、 所述用户设备的全球唯一临时身份、 所述用户设备的系统架构演进临时移动客户身份、 所述用户设备的无线网络 临时标识或者所述用户设备的移动台国际电话综合业务数字网号码。
6、 根据权利要求 5所述的方法, 其特征在于, 当所述用户设备的身份标 识符为所述用户设备的无线局域网络接口的媒体访问控制地址时, 所述方法 还包括:
所述用户设备向所述网元设备发送所述用户设备的身份标识符。
7、 根据权利要求 6所述的方法, 其特征在于, 所述用户设备向所述网元 设备发送所述用户设备的身份标识符, 包括:
所述用户设备采用加密的方式向所述网元设备发送所述用户设备的身份 标识符。
8、 根据权利要求 7所述的方法, 其特征在于, 所述用户设备采用加密的 方式向所述网元设备发送所述用户设备的身份标识符, 包括:
所述用户设备在附着完成消息、 路由区域更新消息、 跟踪区域更新完成 消息、 非接入层安全模式结束消息或者容量迁移消息中携带所述用户设备的 身份标识符; 并向所述网元设备发送携带所述用户设备的身份标识符的加密 的所述附着完成消息、 所述路由区域更新消息、 所述跟踪区域更新完成消息、 所述非接入层安全模式结束消息或者所述容量迁移消息。
9、 根据权利要求 1-8任一所述的方法, 其特征在于, 所述移动通信网络 为全球移动通信网络、 通用移动通讯系统、 长期演进系统、 码分多址网络或 通用分组无线服务网络;
所述网元设备为所述全球移动通信网络的基站控制器、 所述通用移动通 讯系统的无线网络控制器、 所述通用分组无线服务网络的服务通用分组无线 服务支持节点、 所述长期演进系统的移动管理实体或者所述长期演进系统的 基站。
10、 一种无线局域网络的安全建立方法, 其特征在于, 包括:
无线局域网络节点接收用户设备发送的所述用户设备的身份标识符; 所述无线局域网络节点向所述用户设备接入的移动通信网络中的网元设 备发送携带所述用户设备的身份标识符的密钥请求消息;
所述无线局域网络节点接收所述网元设备发送的所述用户设备的身份标 识符对应的推演密钥, 所述推演密钥为所述网元设备根据第一密钥和推演参 数进行推演得到, 所述第一密钥为所述用户设备与所述网元设备在执行空口 安全时的共享密钥或者根据所述用户设备与所述网元设备在执行空口安全时 的共享密钥推演得出的, 所述推演参数为所述用户设备与所述网元设备协商 确定的;
所述无线局域网络节点基于所述推演密钥与获取到推演密钥的所述用户 设备之间建立安全连接, 所述用户设备获取到的推演密钥与所述无线局域网 络节点获取的所述推演密钥相同。
11、 根据权利要求 10所述的方法, 其特征在于,
所述无线局域网络节点接收所述网元设备发送的所述用户设备的身份标 识符对应的推演密钥, 包括: 所述无线局域网络节点接收所述网元设备发送 的所述用户设备的身份标识符对应的第二密钥, 所述第二密钥为所述网元设 备根据所述用户设备的身份标识符以及所述网元设备中存储的所述用户设备 的身份标识符与所述第二密钥之间的对应关系获取的; 所述第二密钥为所述 网元设备根据第一密钥和与所述推演参数进行推演得到;
所述无线局域网络节点基于所述推演密钥与所述用户设备之间建立安全 连接, 包括: 所述无线局域网络节点基于所述第二密钥与所述用户设备之间 建立安全连接。
12、 根据权利要求 10所述的方法, 其特征在于,
所述无线局域网络节点接收所述网元设备发送的所述用户设备的身份标 识符对应的推演密钥, 包括: 所述无线局域网络节点接收所述网元设备发送 的第三密钥, 所述第三密钥为所述网元设备根据第二密钥与所述无线局域网 络节点的身份标识符推演得到的; 所述第二密钥为所述网元设备根据所述用 户设备的身份标识符以及所述网元设备中存储的所述用户设备的身份标识符 与所述第二密钥之间的对应关系获取的; 所述第二密钥为所述网元设备根据 第一密钥和推演参数进行推演得到;
所述无线局域网络节点基于所述推演密钥与所述用户设备之间建立安全 连接, 包括: 所述无线局域网络节点基于所述第三密钥与所述用户设备之间 建立安全连接。
13、 根据权利要求 12所述的方法, 其特征在于, 所述无线局域网络节点 向所述用户设备接入的移动通信网络中的网元设备发送携带所述用户设备的 身份标识符的密钥请求消息, 包括:
所述无线局域网络节点向所述网元设备发送携带所述用户设备的身份标 识符和所述无线局域网络节点的身份标识符的密钥请求消息。
14、 根据权利要求 10-13任一所述的方法, 其特征在于, 所述用户设备的 身份标识符为所述用户设备的无线局域网络接口的媒体访问控制地址、 所述 用户设备的国际移动用户识别码、 所述用户设备的临时移动用户识别码、 所 述用户设备的分组临时移动用户识别码、所述用户设备的全球唯一临时身份、 所述用户设备的系统架构演进临时移动客户身份、 所述用户设备的无线网络 临时标识或者所述用户设备的移动台国际电话综合业务数字网号码。
15、 根据权利要求 10-14任一所述的方法, 其特征在于, 所述移动通信网 络为全球移动通信网络、 通用移动通讯系统、 长期演进系统、 码分多址网络 或通用分组无线服务网络;
所述网元设备为所述全球移动通信网络的基站控制器、 所述通用移动通 讯系统的无线网络控制器、 所述通用分组无线服务网络的服务通用分组无线 服务支持节点、 所述长期演进系统的移动管理实体或所述长期演进系统的者 基站。
16、 一种无线局域网络的安全建立方法, 其特征在于, 包括:
用户设备接入的移动通信网络中的网元设备接收无线局域网络节点发送 的密钥请求消息, 所述密钥请求消息中携带有所述用户设备的身份标识符; 所述网元设备根据所述密钥请求消息中的所述用户设备的身份标识符, 获取对应的推演密钥, 所述推演密钥为所述网元设备根据第一密钥和推演参 数进行推演得到, 所述第一密钥为所述网元设备与所述用户设备在执行空口 安全时的共享密钥或者根据所述网元设备与所述用户设备在执行空口安全时 的共享密钥推演得出的, 所述推演参数为所述网元设备与所述用户设备协商 确定的;
所述网元设备向所述无线局域网络节点发送所述推演密钥, 以供所述无 线局域网络节点基于所述推演密钥与获取到推演密钥的所述用户设备之间建 立安全连接, 所述用户设备获取到的推演密钥与所述无线局域网络节点接收 所述网元设备发送的所述推演密钥相同。
17、 根据权利要求 16所述的方法, 其特征在于, 所述网元设备根据所述 密钥请求消息中的所述用户设备的身份标识符, 获取对应的推演密钥之前, 还包括: 所述网元设备获取所述第一密钥。
18、 根据权利要求 17所述的方法, 其特征在于, 所述网元设备获取所述 第一密钥之后, 所述网元设备根据所述密钥请求消息中的所述用户设备的身 份标识符, 获取对应的推演密钥之前, 所述方法还包括:
所述网元设备根据所述第一密钥和所述推演参数进行推演得到第二密 钥;
所述网元设备建立所述第二密钥与所述用户设备的身份标识符之间的对 应关系;
所述网元设备根据所述密钥请求消息中的所述用户设备的身份标识符, 获取对应的推演密钥, 包括:
所述网元设备根据所述第二密钥与所述用户设备的身份标识符之间的对 应关系、 以及所述密钥请求消息中的所述用户设备的身份标识符, 获取所述 第二密钥;
所述网元设备向所述无线局域网络节点发送所述推演密钥, 以供所述无 线局域网络节点基于所述推演密钥与所述用户设备之间建立安全连接, 包括: 所述网元设备向所述无线局域网络节点发送所述第二密钥, 以供所述无 线局域网络节点基于所述第二密钥与所述用户设备之间建立安全连接。
19、 根据权利要求 17所述的方法, 其特征在于, 所述网元设备获取所述 第一密钥之后, 所述网元设备根据所述密钥请求消息中的所述用户设备的身 份标识符, 获取对应的推演密钥之前, 所述方法还包括:
所述网元设备根据所述第一密钥和所述推演参数进行推演得到第二密 钥;
所述网元设备根据所述第二密钥与所述无线局域网络节点的身份标识符 推演得到所述第三密钥;
所述网元设备向所述无线局域网络节点发送所述推演密钥, 以供所述无 线局域网络节点基于所述推演密钥与所述用户设备之间建立安全连接, 包括: 所述网元设备向所述无线局域网络节点发送所述第三密钥, 以供所述无 线局域网络节点基于所述第三密钥与所述用户设备之间建立安全连接。
20、 根据权利要求 16-19任一所述的方法, 其特征在于, 所述用户设备的 身份标识符为所述用户设备的无线局域网络接口的媒体访问控制地址、 所述 用户设备的国际移动用户识别码、 所述用户设备的临时移动用户识别码、 所 述用户设备的分组临时移动用户识别码、所述用户设备的全球唯一临时身份、 所述用户设备的系统架构演进临时移动客户身份、 所述用户设备的无线网络 临时标识或者所述用户设备的移动台国际电话综合业务数字网号码。
21、 根据权利要求 20所述的方法, 其特征在于, 当所述用户设备的身份 标识符为所述用户设备的无线局域网络接口的媒体访问控制地址时, 所述网 元设备接收所述无线局域网络节点发送的携带所述用户设备的身份标识符的 密钥请求消息之前, 所述方法还包括:
所述网元设备接收所述用户设备发送的所述用户设备的身份标识符。
22、 根据权利要求 21所述的方法, 其特征在于, 所述网元设备接收所述 用户设备发送的所述用户设备的身份标识符, 包括: 所述网元设备接收所述 用户设备采用加密的方式发送的所述用户设备的身份标识符。
23、 根据权利要求 23所述的方法, 其特征在于, 所述网元设备接收所述 用户设备采用加密的方式发送的所述用户设备的身份标识符, 包括: 所述网 元设备接收所述用户设备发送的携带所述用户设备的身份标识符的加密的附 着完成消息、 路由区域更新消息、 跟踪区域更新完成消息、 非接入层安全模 式结束消息或者容量迁移消息。
24、 根据权利要求 16-23任一所述的方法, 其特征在于, 所述移动通信网 络为全球移动通信网络、 通用移动通讯系统、 长期演进系统、 码分多址网络 或通用分组无线服务网络;
所述网元设备为所述全球移动通信网络的基站控制器、 所述通用移动通 讯系统的无线网络控制器、 所述通用分组无线服务网络的服务通用分组无线 服务支持节点 、所述长期演进系统的移动管理实体或者所述长期演进系统的 基站。
25、 一种无线局域网络的安全建立方法, 其特征在于, 包括:
用户设备获取第一密钥, 所述第一密钥为所述用户设备与接入的移动通 信网络中的第一网元设备在执行空口安全时的共享密钥或者根据所述用户设 备与接入的移动通信网络中的第一网元设备在执行空口安全时的所述共享密 钥推演得出的;
所述用户设备根据所述用户设备的身份标识符和所述第一密钥推演生成 认证用户名和认证信任状;
所述用户设备根据所述认证用户名和所述认证信任状与所述第一网元设 备或者第二网元设备进行扩展认证协议认证, 所述第二网元设备为所述移动 通信网络中的所述第一网元设备之外的其他网元设备, 所述第二网元设备从 所述第一网元设备处获取所述认证用户名和所述认证信任状; 或者所述第二 网元设备从所述第一网元设备处获取所述用户设备的身份标识符和所述第一 密钥, 并根据所述用户设备的身份标识符和所述第一密钥推演生成所述认证 用户名和所述认证信任状;
所述用户设备在所述扩展认证协议认证完成后与所述无线局域网络节点 之间建立安全连接。
26、 根据权利要求 25所述的方法, 其特征在于, 所述用户设备的身份标 识符为所述用户设备的无线局域网络接口的媒体访问控制地址、 所述用户设 备的国际移动用户识别码、 所述用户设备的临时移动用户识别码、 所述用户 设备的分组临时移动用户识别码、 所述用户设备的全球唯一临时身份、 所述 用户设备的系统架构演进临时移动客户身份、 所述用户设备的无线网络临时 标识或者所述用户设备的移动台国际电话综合业务数字网号码。
27、 根据权利要求 25或者 26所述的方法, 其特征在于, 所述移动通信网 络为全球移动通信网络、 通用移动通讯系统、 长期演进系统、 码分多址网络 或通用分组无线服务网络;
所述网元设备为所述全球移动通信网络的基站控制器、 所述通用移动通 讯系统的无线网络控制器、 所述通用分组无线服务网络的服务通用分组无线 服务支持节点、 所述长期演进系统的移动管理实体或所述长期演进系统的者 基站。
28、 一种无线局域网络的安全建立方法, 其特征在于, 包括:
用户设备接入的移动通信网络中的第一网元设备获取所述用户设备的认 证用户名和认证信任状; 所述认证用户名和所述认证信任状为根据所述用户 设备的身份标识符和第一密钥生成的; 所述第一密钥为所述用户设备与所述 第一网元设备或者第二网元设备在执行空口安全时的共享密钥, 或者根据所 述用户设备与所述第一网元设备或者第二网元设备在执行空口安全时的共享 密钥推演得出的;
所述第一网元设备根据所述认证用户名和所述认证信任状与用户设备进 行扩展认证协议认证;
所述第一网元设备在所述扩展认证协议认证成功后, 向所述无线局域网 络节点发送认证完成, 以指示所述无线局域网络节点与所述用户设备之间建 立安全连接。
29、 根据权利要求 28所述的方法, 其特征在于, 用户设备接入的移动通 信网络中的第一网元设备获取所述用户设备的认证用户名和认证信任状, 包 括:
所述第一网元设备接收所述第二网元设备发送的所述用户设备的所述用 户设备的身份标识符和所述第一密钥, 所述第一密钥为所述用户设备与所述 第二网元设备在执行空口安全时的共享密钥或者根据所述用户设备与所述第 二网元设备在执行空口安全时的共享密钥推演得出的;
所述第一网元设备根据所述用户设备的身份标识符和所述第一密钥生成 所述认证用户名和所述认证信任状。
30、 根据权利要求 28所述的方法, 其特征在于, 用户设备接入的移动通 信网络中的第一网元设备获取所述用户设备的认证用户名和认证信任状, 包 括:
所述第一网元设备接收所述第二网元设备发送的所述认证用户名和所述 认证信任状, 所述认证用户名和所述认证信任状为所述第二网元设备根据所 述用户设备的身份标识符和所述第一密钥推演生成的, 所述第一密钥为所述 用户设备与所述第二网元设备在执行空口安全时的共享密钥或者根据所述用 户设备与所述第二网元设备在执行空口安全时的共享密钥推演得出的。
31、 根据权利要求 28所述的方法, 其特征在于, 用户设备接入的移动通 信网络中的第一网元设备获取所述用户设备的认证用户名和认证信任状, 包
括:
所述第一网元设备获取所述第一密钥; 所述述第一密钥为所述第一网元 设备与所述用户设备在执行空口安全时的共享密钥或者根据所述第一网元设 备与所述用户设备在执行空口安全时的共享密钥推演得出的;
所述第一网元设备根据所述用户设备的身份标识符和所述第一密钥推演 生成所述认证用户名和所述认证信任状。
32、 根据权利要求 28-31任一所述的方法, 其特征在于, 所述用户设备的 身份标识符为所述用户设备的无线局域网络接口的媒体访问控制地址、 所述 用户设备的国际移动用户识别码、 所述用户设备的临时移动用户识别码、 所 述用户设备的分组临时移动用户识别码、所述用户设备的全球唯一临时身份、 所述用户设备的系统架构演进临时移动客户身份、 所述用户设备的无线网络 临时标识或者所述用户设备的移动台国际电话综合业务数字网号码。
33、 根据权利要求 32所述的方法, 其特征在于, 所述移动通信网络为全 球移动通信网络、 通用移动通讯系统、 长期演进系统、 码分多址网络或通用 分组无线服务网络;
所述网元设备为所述全球移动通信网络的基站控制器、 所述通用移动通 讯系统的无线网络控制器、 所述通用分组无线服务网络的服务通用分组无线 服务支持节点、 所述长期演进系统的移动管理实体或所述长期演进系统的者 基站。
34、 一种用户设备, 其特征在于, 包括:
获取模块, 用于获取第一密钥, 所述第一密钥为与接入的移动通信网络 中的网元设备在执行空口安全时的共享密钥或者根据所述用户设备与接入的 移动通信网络中的网元设备在执行空口安全时的共享密钥推演得出的;
推演模块, 用于根据所述获取模块获取的所述第一密钥和推演参数进行 推演得到推演密钥; 所述推演参数为所述用户设备与所述网元设备协商确定 的;
建立模块, 用于根据所述推演模块推演得到的所述推演密钥与获取到推 演密钥的无线局域网络节点之间建立安全连接, 所述无线局域网络节点获取 到的推演密钥与所述用户设备获取的所述推演密钥相同。
35、 根据权利要求 34所述的设备, 其特征在于, 所述设备还包括:
发送模块, 用于向所述无线局域网络节点发送用户设备的身份标识符, 以供所述无线局域网络节点根据所述用户设备的身份标识符, 向所述网元设 备请求获取所述用户设备对应的推演密钥。
36、 根据权利要求 34所述的设备, 其特征在于:
所述推演模块, 具体用于根据所述获取模块获取的所述第一密钥和所述 推演参数进行推演得到第二密钥;
所述建立模块, 具体用于根据所述推演模块推演的所述第二密钥与无线 局域网络节点之间建立安全连接。
37、 根据权利要求 34所述的设备, 其特征在于:
所述推演模块, 具体用于根据所述获取模块获取的所述第一密钥和所述 推演参数进行推演得到第二密钥; 并根据所述第二密钥和所述无线局域网络 节点的身份标识符推演得到第三密钥;
所述建立模块, 具体用于根据所述推演模块推演的所述第三密钥与所述 无线局域网络节点之间建立安全连接。
38、 根据权利要求 34-37任一所述的设备, 其特征在于, 所述发送模块发 送的用户设备的身份标识符为所述用户设备的无线局域网络接口的媒体访问 控制地址、 所述用户设备的国际移动用户识别码、 所述用户设备的临时移动 用户识别码、 所述用户设备的分组临时移动用户识别码、 所述用户设备的全 球唯一临时身份、 所述用户设备的系统架构演进临时移动客户身份、 所述用 户设备的无线网络临时标识或者所述用户设备的移动台国际电话综合业务数 字网号码。
39、 根据权利要求 38所述的设备, 其特征在于:
所述发送模块, 还用于当所述用户设备的身份标识符为所述用户设备的 无线局域网络接口的媒体访问控制地址时, 向所述网元设备发送所述用户设 备的身份标识符。
40、 根据权利要求 39所述的设备, 其特征在于:
所述发送模块, 具体用于当所述用户设备的身份标识符为所述用户设备 的无线局域网络接口的媒体访问控制地址时, 采用加密的方式向所述网元设 备发送所述用户设备的身份标识符。
41、 根据权利要求 34-40任一所述的设备, 其特征在于, 所述移动通信网
络为全球移动通信网络、 通用移动通讯系统、 长期演进系统、 码分多址网络 或通用分组无线服务网络;
所述网元设备为所述全球移动通信网络的基站控制器、 所述通用移动通 讯系统的无线网络控制器、 所述通用分组无线服务网络的服务通用分组无线 服务支持节点 、所述长期演进系统的移动管理实体或者所述长期演进系统的 基站。
42、 一种无线局域网络节点设备, 其特征在于, 包括:
接收模块, 用于接收用户设备发送的所述用户设备的身份标识符; 发送模块, 用于向所述用户设备接入的移动通信网络中的网元设备发送 携带所述接收模块接收的所述用户设备的身份标识符的密钥请求消息;
所述接收模块, 还用于接收所述网元设备发送的所述用户设备的身份标 识符对应的推演密钥; 所述推演密钥为所述网元设备根据第一密钥和推演参 数进行推演得到, 所述第一密钥为所述用户设备与所述网元设备在执行空口 安全时的共享密钥或者根据所述用户设备与所述网元设备在执行空口安全时 的共享密钥推演得出的; 所述推演参数为所述用户设备与所述网元设备协商 确定的;
建立模块, 用于基于所述接收模块接收的所述推演密钥与获取到推演密 钥的所述用户设备之间建立安全连接, 所述用户设备获取到的推演密钥与无 线局域网络节点获取的所述推演密钥相同。
43、 根据权利要求 42所述的设备, 其特征在于:
所述接收模块, 具体用于接收所述网元设备发送的所述用户设备的身份 标识符对应的第二密钥, 所述第二密钥为所述网元设备根据所述用户设备的 身份标识符以及所述网元设备中存储的所述用户设备的身份标识符与所述第 二密钥之间的对应关系获取的; 所述第二密钥为所述网元设备根据第一密钥 和所述推演参数进行推演得到;
所述建立模块, 具体用于基于所述接收模块接收的第二密钥与所述用户 设备之间建立安全连接.
44、 根据权利要求 42所述的设备, 其特征在于:
所述接收模块, 具体用于接收所述网元设备发送的第三密钥, 所述第三 密钥为所述网元设备根据第二密钥与所述无线局域网络节点的身份标识符推
演得到的; 所述第二密钥为所述网元设备根据所述用户设备的身份标识符以 及所述网元设备中存储的所述用户设备的身份标识符与所述第二密钥之间的 对应关系获取的; 所述第二密钥为所述网元设备根据第一密钥和推演参数进 行推演得到;
所述建立模块, 具体用于基于所述接收模块接收的所述第三密钥与所述 用户设备之间建立安全连接。
45、 根据权利要求 44所述的设备, 其特征在于:
所述发送模块, 具体用于向所述网元设备发送携带所述接收模块接收的 用户设备的身份标识符和所述无线局域网络节点的身份标识符的密钥请求消 息。
46、 根据权利要求 42-45任一所述的设备, 其特征在于, 所述接收模块接 收的用户设备的身份标识符为所述用户设备的无线局域网络接口的媒体访问 控制地址、 所述用户设备的国际移动用户识别码、 所述用户设备的临时移动 用户识别码、 所述用户设备的分组临时移动用户识别码、 所述用户设备的全 球唯一临时身份、 所述用户设备的系统架构演进临时移动客户身份、 所述用 户设备的无线网络临时标识或者所述用户设备的移动台国际电话综合业务数 字网号码。
47、 根据权利要求 42-46任一所述的设备, 其特征在于, 所述移动通信网 络为全球移动通信网络、 通用移动通讯系统、 长期演进系统、 码分多址网络 或通用分组无线月良务网络;
所述网元设备为所述全球移动通信网络的基站控制器、 所述通用移动通 讯系统的无线网络控制器、 所述通用分组无线服务网络的服务通用分组无线 服务支持节点、 所述长期演进系统的移动管理实体或所述长期演进系统的者 基站。
48、 一种网元设备, 位于用户设备接入的移动通信网络中, 其特征在于, 所述网元设备包括:
接收模块, 用于接收无线局域网络节点发送的密钥请求消息, 所述密钥 请求消息中携带有所述用户设备的身份标识符;
获取模块, 用于根据所述接收模块接收的所述密钥请求消息中的所述用 户设备的身份标识符, 获取对应的推演密钥; 所述推演密钥为根据第一密钥
和推演参数进行推演得到; 所述第一密钥为与所述用户设备在执行空口安全 时的共享密钥或者根据与所述用户设备在执行空口安全时的共享密钥推演得 出的; 所述推演参数为与所述用户设备协商确定的;
发送模块, 用于向所述无线局域网络节点发送所述获取模块获取到的所 述推演密钥, 以供所述无线局域网络节点基于所述推演密钥与获取到推演密 钥的所述用户设备之间建立安全连接, 所述用户设备获取到的推演密钥与所 述无线局域网络节点接收所述网元设备发送的所述推演密钥相同。
49、 根据权利要求 48所述的设备, 其特征在于, 所述获取模块, 还用于 获取所述第一密钥。
50、 根据权利要求 49所述的设备, 其特征在于, 所述设备还包括推演模 块和建立模块:
所述推演模块, 用于在所述获取模块获取所述第一密钥之后, 根据所述 密钥请求消息中的所述用户设备的身份标识符, 获取对应的所述推演密钥之 前, 根据所述第一密钥和所述推演参数进行推演得到第二密钥;
所述建立模块, 用于建立所述推演模块推演的所述第二密钥与所述用户 设备的身份标识符之间的对应关系;
所述获取模块, 具体用于根据所述建立模块建立的所述第二密钥与所述 用户设备的身份标识符之间的对应关系、 以及所述密钥请求消息中的所述用 户设备的身份标识符, 获取所述第二密钥;
所述发送模块, 具体用于向所述无线局域网络节点发送所述获取模块获 取的所述第二密钥, 以供所述无线局域网络节点基于所述第二密钥与所述用 户设备之间建立安全连接。
51、 根据权利要求 49所述的设备, 其特征在于, 所述设备还包括推演模 块和建立模块:
所述推演模块, 用于在所述获取模块获取所述第一密钥之后, 根据所述 密钥请求消息中的所述用户设备的身份标识符, 获取对应的所述推演密钥之 前, 根据所述第一密钥和所述推演参数进行推演得到第二密钥;
所述建立模块, 用于建立所述推演模块推演的所述第二密钥与所述用户 设备的身份标识符之间的对应关系;
所述获取模块, 具体用于根据所述建立模块建立的所述第二密钥与所述
用户设备的身份标识符之间的对应关系、 以及所述密钥请求消息中的所述用 户设备的身份标识符, 获取所述第二密钥; 并根据所述第二密钥与所述密钥 请求消息中的所述无线局域网络节点的身份标识符推演得到所述第三密钥; 所述发送模块, 具体用于向所述无线局域网络节点发送所述获取模块获 取的所述第三密钥, 以供所述无线局域网络节点基于所述第三密钥与所述用 户设备之间建立安全连接。
52、 根据权利要求 48-51任一所述的设备, 其特征在于, 所述接收模块接 收的用户设备的身份标识符为所述用户设备的无线局域网络接口的媒体访问 控制地址、 所述用户设备的国际移动用户识别码、 所述用户设备的临时移动 用户识别码、 所述用户设备的分组临时移动用户识别码、 所述用户设备的全 球唯一临时身份、 所述用户设备的系统架构演进临时移动客户身份、 所述用 户设备的无线网络临时标识或者所述用户设备的移动台国际电话综合业务数 字网号码。
53、 根据权利要求 52所述的设备, 其特征在于:
所述接收模块, 还用于当所述用户设备的身份标识符为所述用户设备的 无线局域网络接口的媒体访问控制地址时, 接收所述用户设备发送的所述用 户设备的身份标识符。
54、 根据权利要求 53所述的设备, 其特征在于:
所述接收模块, 还用于当所述用户设备的身份标识符为所述用户设备的 无线局域网络接口的媒体访问控制地址时, 接收所述用户设备采用加密的方 式发送的所述用户设备的身份标识符。
55、 根据权利要求 48-54任一所述的设备, 其特征在于, 所述移动通信网 络为全球移动通信网络、 通用移动通讯系统、 长期演进系统、 码分多址网络 或通用分组无线服务网络;
所述网元设备为所述全球移动通信网络的基站控制器、 所述通用移动通 讯系统的无线网络控制器、 所述通用分组无线服务网络的服务通用分组无线 服务支持节点 、所述长期演进系统的移动管理实体或者所述长期演进系统的 基站。
56、 一种用户设备, 其特征在于, 包括:
获取模块, 用于获取第一密钥; 所述第一密钥为所述用户设备与接入的
移动通信网络中的第一网元设备在执行空口安全时的共享密钥或者根据所述 用户设备与接入的移动通信网络中的第一网元设备在执行空口安全时的共享 密钥推演得出的;
生成模块, 用于根据所述用户设备的身份标识符和所述获取模块的所述 第一密钥推演生成认证用户名和认证信任状;
认证模块, 用于根据所述生成模块生成的所述认证用户名和所述认证信 任状与所述第一网元设备或者第二网元设备进行扩展认证协议认证; 所述第 二网元设备为所述移动通信网络中的所述第一网元设备之外的其他网元设 备; 所述第二网元设备从所述第一网元设备处获取所述认证用户名和所述认 证信任状; 或者所述第二网元设备从所述第一网元设备处获取所述用户设备 的身份标识符和所述第一密钥, 并根据所述用户设备的身份标识符和所述第 一密钥推演生成所述认证用户名和所述认证信任状;
建立模块, 用于在所述认证模块进行扩展认证协议认证完成后与所述无 线局域网络节点之间建立安全连接。
57、 根据权利要求 56所述的设备, 其特征在于, 所述用户设备的身份标 识符为所述用户设备的无线局域网络接口的媒体访问控制地址、 所述用户设 备的国际移动用户识别码、 所述用户设备的临时移动用户识别码、 所述用户 设备的分组临时移动用户识别码、 所述用户设备的全球唯一临时身份、 所述 用户设备的系统架构演进临时移动客户身份、 所述用户设备的无线网络临时 标识或者所述用户设备的移动台国际电话综合业务数字网号码。
58、 根据权利要求 56或者 57所述的设备, 其特征在于, 所述移动通信网 络为全球移动通信网络、 通用移动通讯系统、 长期演进系统、 码分多址网络 或通用分组无线服务网络;
所述网元设备为所述全球移动通信网络的基站控制器、 所述通用移动通 讯系统的无线网络控制器、 所述通用分组无线服务网络的服务通用分组无线 服务支持节点、 所述长期演进系统的移动管理实体或所述长期演进系统的者 基站。
59、 一种网元设备, 位于用户设备接入的移动通信网络中, 其特征在于, 所述网元设备包括:
获取模块, 用于获取所述用户设备的认证用户名和认证信任状; 所述认
证用户名和所述认证信任状为根据所述用户设备的身份标识符和第一密钥推 演生成的; 所述第一密钥为所述用户设备与所述网元设备或者第二网元设备 在执行空口安全时的共享密钥或者根据所述用户设备与所述网元设备或者第 二网元设备在执行空口安全时的共享密钥推演得出的;
认证模块, 用于根据所述认证用户名和所述认证信任状与用户设备进行 扩展认证协议认证;
发送模块, 用于在所述扩展认证协议认证成功后, 向所述无线局域网络 节点发送认证完成, 以指示所述无线局域网络节点与所述用户设备之间建立 安全连接。
60、 根据权利要求 59所述的设备, 其特征在于, 所述获取模块, 具体用 于接收所述第二网元设备发送的所述用户设备的所述用户设备的身份标识符 和所述第一密钥, 所述第一密钥为所述用户设备与所述第二网元设备在执行 空口安全时的共享密钥或者根据所述用户设备与所述第二网元设备在执行空 口安全时的共享密钥推演得出的; 并根据所述用户设备的身份标识符和所述 第一密钥推演生成所述认证用户名和所述认证信任状。
61、 根据权利要求 59所述的设备, 其特征在于, 所述获取模块, 具体用 于接收所述第二网元设备发送的所述认证用户名和所述认证信任状, 所述认 证用户名和所述认证信任状为所述第二网元设备根据所述用户设备的身份标 识符和所述第一密钥推演生成的, 所述第一密钥为所述用户设备与所述第二 网元设备在执行空口安全时的共享密钥或者根据所述用户设备与所述第二网 元设备在执行空口安全时的共享密钥推演得出的。
62、 根据权利要求 59所述的设备, 其特征在于, 所述获取模块, 具体用 于获取所述第一密钥; 所述述第一密钥为所述第一网元设备与所述用户设备 在执行空口安全时的共享密钥或者根据所述第一网元设备与所述用户设备在 执行空口安全时的共享密钥推演得出的; 并根据所述用户设备的身份标识符 和所述第一密钥推演生成所述认证用户名和所述认证信任状。
63、 根据权利要求 59-62任一所述的设备, 其特征在于, 所述用户设备的 身份标识符为所述用户设备的无线局域网络接口的媒体访问控制地址、 所述 用户设备的国际移动用户识别码、 所述用户设备的临时移动用户识别码、 所 述用户设备的分组临时移动用户识别码、所述用户设备的全球唯一临时身份、
所述用户设备的系统架构演进临时移动客户身份、 所述用户设备的无线网络 临时标识或者所述用户设备的移动台国际电话综合业务数字网号码。
64、 根据权利要求 63所述的设备, 其特征在于, 所述移动通信网络为全 球移动通信网络、 通用移动通讯系统、 长期演进系统、 码分多址网络或通用 分组无线服务网络;
所述网元设备为所述全球移动通信网络的基站控制器、 所述通用移动通 讯系统的无线网络控制器、 所述通用分组无线服务网络的服务通用分组无线 服务支持节点、 所述长期演进系统的移动管理实体或所述长期演进系统的者 基站。
65、 一种无线局域网络的安全建立系统, 其特征在于, 包括: 如上权利 要求 34-41任一所述的用户设备、如上权利要求 42-47任一所述的无线局域网络 节点设备和如上权利要求 48-55任一所述的网元设备;
或者包括如上权利要求 56-58任一所述的用户设备和如上权利要求 59-64 任一所述的网元设备。
Priority Applications (4)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| EP18198578.9A EP3503496B1 (en) | 2012-05-23 | 2013-05-22 | Secure establishment method, system and decive of a wireless local area network |
| EP13794647.1A EP2854329B1 (en) | 2012-05-23 | 2013-05-22 | Method, system, and device for securely establishing wireless local area network |
| US14/550,629 US9826398B2 (en) | 2012-05-23 | 2014-11-21 | Secure establishment method, system and device of wireless local area network |
| US15/782,584 US10687213B2 (en) | 2012-05-23 | 2017-10-12 | Secure establishment method, system and device of wireless local area network |
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| CN201210161427.0 | 2012-05-23 | ||
| CN201210161427.0A CN103428690B (zh) | 2012-05-23 | 2012-05-23 | 无线局域网络的安全建立方法及系统、设备 |
Related Child Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| US14/550,629 Continuation US9826398B2 (en) | 2012-05-23 | 2014-11-21 | Secure establishment method, system and device of wireless local area network |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| WO2013174267A1 true WO2013174267A1 (zh) | 2013-11-28 |
Family
ID=49623129
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| PCT/CN2013/076088 Ceased WO2013174267A1 (zh) | 2012-05-23 | 2013-05-22 | 无线局域网络的安全建立方法及系统、设备 |
Country Status (4)
| Country | Link |
|---|---|
| US (2) | US9826398B2 (zh) |
| EP (2) | EP3503496B1 (zh) |
| CN (1) | CN103428690B (zh) |
| WO (1) | WO2013174267A1 (zh) |
Cited By (4)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| WO2016069638A3 (en) * | 2014-10-29 | 2016-06-23 | Qualcomm Incorporated | User-plane security for next generation cellular networks |
| EP3076710A4 (en) * | 2013-12-27 | 2016-12-14 | Huawei Tech Co Ltd | OFFLOAD PROCEDURE, USER DEVICE, BASE STATION AND ACCESS POINT |
| CN115348048A (zh) * | 2022-04-28 | 2022-11-15 | 青岛海尔科技有限公司 | 安全通信的建立方法和装置、存储介质及电子装置 |
| US12200495B2 (en) | 2022-11-18 | 2025-01-14 | T-Mobile Usa, Inc. | Integrating security and routing policies in wireless telecommunication networks |
Families Citing this family (10)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| EP3270655A1 (en) * | 2013-01-16 | 2018-01-17 | Alcatel Lucent | Wireless telecommunications method and user equipment |
| US9801099B2 (en) * | 2013-05-15 | 2017-10-24 | Blackberry Limited | Method and system for use of cellular infrastructure to manage small cell access |
| WO2016134536A1 (zh) * | 2015-02-28 | 2016-09-01 | 华为技术有限公司 | 密钥生成方法、设备及系统 |
| KR102022813B1 (ko) * | 2015-08-11 | 2019-09-18 | 후아웨이 테크놀러지 컴퍼니 리미티드 | 액세스 인증 방법 및 장치 |
| WO2017133021A1 (zh) * | 2016-02-06 | 2017-08-10 | 华为技术有限公司 | 一种安全处理方法及相关设备 |
| BR112019022934A2 (pt) * | 2017-05-04 | 2020-06-09 | Huawei Tech Co Ltd | método e aparelho de obtenção de chave, dispositivo terminal, mídia de armazenamento legível por computador, método para processamento de segurança em mobilidade de um dispositivo terminal e sistema de comunicações |
| CN109756451B (zh) * | 2017-11-03 | 2022-04-22 | 华为技术有限公司 | 一种信息交互方法及装置 |
| US12052358B2 (en) | 2018-01-12 | 2024-07-30 | Qualcomm Incorporated | Method and apparatus for multiple registrations |
| EP3884728A4 (en) * | 2018-11-19 | 2022-09-07 | Telefonaktiebolaget Lm Ericsson (Publ) | RADIO NETWORK NODE, NETWORK NODE AND METHODS FOR ESTABLISHING A SECURE CONNECTION WITH THE USER EQUIPMENT (UE) |
| US11004325B2 (en) * | 2019-09-26 | 2021-05-11 | International Business Machines Corporation | Smartphone based reminding system for forgotten objects |
Citations (4)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN1512708A (zh) * | 2002-12-27 | 2004-07-14 | �ձ�������ʽ���� | 无线通信系统、共享密钥管理服务器及终端 |
| US20060178131A1 (en) * | 2005-02-07 | 2006-08-10 | Huotari Allen J | Key distribution for wireless devices |
| US20080076392A1 (en) * | 2006-09-22 | 2008-03-27 | Amit Khetawat | Method and apparatus for securing a wireless air interface |
| US20100138661A1 (en) * | 2008-12-01 | 2010-06-03 | Institute For Information Industry | Mobile station, access point, gateway apparatus, base station, and handshake method thereof for use in a wireless network framework |
Family Cites Families (50)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US4918728A (en) * | 1989-08-30 | 1990-04-17 | International Business Machines Corporation | Data cryptography operations using control vectors |
| DE69330065T2 (de) * | 1993-12-08 | 2001-08-09 | International Business Machines Corp., Armonk | Verfahren und System zur Schlüsselverteilung und Authentifizierung in einem Datenübertragungssystem |
| CA2255285C (en) * | 1998-12-04 | 2009-10-13 | Certicom Corp. | Enhanced subscriber authentication protocol |
| US6957346B1 (en) * | 1999-06-15 | 2005-10-18 | Ssh Communications Security Ltd. | Method and arrangement for providing security through network address translations using tunneling and compensations |
| FI111208B (fi) * | 2000-06-30 | 2003-06-13 | Nokia Corp | Datan salauksen järjestäminen langattomassa tietoliikennejärjestelmässä |
| US20030093663A1 (en) * | 2001-11-09 | 2003-05-15 | Walker Jesse R. | Technique to bootstrap cryptographic keys between devices |
| US20030139180A1 (en) * | 2002-01-24 | 2003-07-24 | Mcintosh Chris P. | Private cellular network with a public network interface and a wireless local area network extension |
| US8184603B2 (en) * | 2002-01-31 | 2012-05-22 | Lgc Wireless, Llc | Communication system having a community wireless local area network for voice and high speed data communication |
| US20030235305A1 (en) * | 2002-06-20 | 2003-12-25 | Hsu Raymond T. | Key generation in a communication system |
| JP4695877B2 (ja) | 2002-08-14 | 2011-06-08 | トムソン ライセンシング | 多数のバーチャルオペレータを支援する公衆無線ローカルエリアネットワークのためのセッションキー管理 |
| US7593717B2 (en) * | 2003-09-12 | 2009-09-22 | Alcatel-Lucent Usa Inc. | Authenticating access to a wireless local area network based on security value(s) associated with a cellular system |
| DE102004009289A1 (de) * | 2004-02-26 | 2005-09-15 | Siemens Ag | Verfahren zur Steuerung und Auswertung eines Nachrichtenverkehrs einer Kummunikationseinheit durch eine erste Netzwerkeinheit innerhalb eines Mobilfunksystems, sowie dazugehörige Kommunikationseinheit und erste Netzwerkeinheit |
| US8094821B2 (en) | 2004-08-06 | 2012-01-10 | Qualcomm Incorporated | Key generation in a communication system |
| MX2007009705A (es) * | 2005-02-11 | 2007-10-04 | Nokia Corp | Metodo y aparato para proporcionar procedimientos de carga inicial en una red de comunicacion. |
| WO2006135217A1 (en) * | 2005-06-16 | 2006-12-21 | Samsung Electronics Co., Ltd. | System and method for otimizing tunnel authentication procedure over a 3g-wlan interworking system |
| US7813511B2 (en) * | 2005-07-01 | 2010-10-12 | Cisco Technology, Inc. | Facilitating mobility for a mobile station |
| US20070101122A1 (en) * | 2005-09-23 | 2007-05-03 | Yile Guo | Method and apparatus for securely generating application session keys |
| US7835528B2 (en) * | 2005-09-26 | 2010-11-16 | Nokia Corporation | Method and apparatus for refreshing keys within a bootstrapping architecture |
| US8229398B2 (en) * | 2006-01-30 | 2012-07-24 | Qualcomm Incorporated | GSM authentication in a CDMA network |
| CN101411105A (zh) * | 2006-02-01 | 2009-04-15 | 科科通信公司 | 协议链路层 |
| WO2007106620A2 (en) * | 2006-03-10 | 2007-09-20 | Motorola, Inc. | Method for authenticating a mobile node in a communication network |
| US8239671B2 (en) * | 2006-04-20 | 2012-08-07 | Toshiba America Research, Inc. | Channel binding mechanism based on parameter binding in key derivation |
| US9002018B2 (en) * | 2006-05-09 | 2015-04-07 | Sync Up Technologies Corporation | Encryption key exchange system and method |
| US20080101400A1 (en) | 2006-10-30 | 2008-05-01 | Nokia Corporation | Managing attachment of a wireless terminal to local area networks |
| US7801100B2 (en) * | 2007-06-04 | 2010-09-21 | Sony Ericsson Mobile Communications Ab | Operating ad-hoc wireless local area networks using network identifiers and application keys |
| US8667151B2 (en) * | 2007-08-09 | 2014-03-04 | Alcatel Lucent | Bootstrapping method for setting up a security association |
| US8452017B2 (en) * | 2007-12-21 | 2013-05-28 | Research In Motion Limited | Methods and systems for secure channel initialization transaction security based on a low entropy shared secret |
| KR101188511B1 (ko) * | 2008-04-07 | 2012-10-05 | 인터디지탈 패튼 홀딩스, 인크 | 보안 세션 키 발생 |
| US20090262684A1 (en) * | 2008-04-18 | 2009-10-22 | Amit Khetawat | Method and Apparatus for Home Node B Registration using HNBAP |
| ES2380200T3 (es) * | 2008-06-18 | 2012-05-09 | Research In Motion Limited | Método para la continuidad de la calidad de servicio entre múltiples redes 3GPP |
| US8195991B2 (en) * | 2008-06-20 | 2012-06-05 | Qualcomm Incorporated | Handling of integrity check failure in a wireless communication system |
| US8396037B2 (en) * | 2008-06-23 | 2013-03-12 | Htc Corporation | Method for synchronizing PDCP operations after RRC connection re-establishment in a wireless communication system and related apparatus thereof |
| CN101631290B (zh) | 2008-07-16 | 2012-09-19 | 鸿富锦精密工业(深圳)有限公司 | 移动通信系统及其密钥设置方法 |
| GB0822253D0 (en) * | 2008-12-05 | 2009-01-14 | Qinetiq Ltd | Method of establishing a quantum key for use between network nodes |
| US9015487B2 (en) * | 2009-03-31 | 2015-04-21 | Qualcomm Incorporated | Apparatus and method for virtual pairing using an existing wireless connection key |
| US8385549B2 (en) * | 2009-08-21 | 2013-02-26 | Industrial Technology Research Institute | Fast authentication between heterogeneous wireless networks |
| EP2309805B1 (en) * | 2009-10-11 | 2012-10-24 | Research In Motion Limited | Handling wrong WEP key and related battery drain and communication exchange failures |
| BR112012018268B1 (pt) * | 2010-03-17 | 2021-02-02 | Telefonaktiebolaget Lm Ericsson (Publ) | métodos, nó que serve um terminal móvel e terminal móvel |
| US8804957B2 (en) * | 2010-03-29 | 2014-08-12 | Nokia Corporation | Authentication key generation arrangement |
| US20120163336A1 (en) * | 2010-06-18 | 2012-06-28 | Interdigital Patent Holdings, Inc. | Distributed architecture for security keys derivation in support of non-involved core network handover |
| US8681740B2 (en) * | 2010-12-21 | 2014-03-25 | Tektronix, Inc. | LTE network call correlation during User Equipment mobility |
| US9094864B2 (en) * | 2011-03-02 | 2015-07-28 | Qualcomm Incorporated | Architecture for WLAN offload in a wireless device |
| EP2730112A4 (en) * | 2011-07-08 | 2015-05-06 | Nokia Corp | METHOD AND DEVICE FOR AUTHENTICATING PARTICIPANTS OF AN LTE COMMUNICATION NETWORK OR UNIVERSAL MOBILE TELECOMMUNICATIONS SYSTEM |
| US8594628B1 (en) * | 2011-09-28 | 2013-11-26 | Juniper Networks, Inc. | Credential generation for automatic authentication on wireless access network |
| GB2495550A (en) * | 2011-10-14 | 2013-04-17 | Ubiquisys Ltd | An access point that can be used to establish connections with UE devices using both cellular and wifi air interfaces |
| EP2777239A1 (en) * | 2011-11-07 | 2014-09-17 | Option | Establishing a communication session |
| CN102595405A (zh) | 2012-01-21 | 2012-07-18 | 华为技术有限公司 | 一种网络接入的认证方法、系统和设备 |
| US9247575B2 (en) * | 2012-03-27 | 2016-01-26 | Blackberry Limited | eNB storing RRC configuration information at another network component |
| TWI626855B (zh) * | 2012-04-27 | 2018-06-11 | 內數位專利控股公司 | 最佳化鄰近資料路徑設置方法及裝置 |
| US9806873B2 (en) * | 2012-05-09 | 2017-10-31 | Samsung Electronics Co., Ltd. | Method and apparatus for controlling discontinuous reception in mobile communication system |
-
2012
- 2012-05-23 CN CN201210161427.0A patent/CN103428690B/zh active Active
-
2013
- 2013-05-22 EP EP18198578.9A patent/EP3503496B1/en active Active
- 2013-05-22 WO PCT/CN2013/076088 patent/WO2013174267A1/zh not_active Ceased
- 2013-05-22 EP EP13794647.1A patent/EP2854329B1/en active Active
-
2014
- 2014-11-21 US US14/550,629 patent/US9826398B2/en active Active
-
2017
- 2017-10-12 US US15/782,584 patent/US10687213B2/en active Active
Patent Citations (4)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN1512708A (zh) * | 2002-12-27 | 2004-07-14 | �ձ�������ʽ���� | 无线通信系统、共享密钥管理服务器及终端 |
| US20060178131A1 (en) * | 2005-02-07 | 2006-08-10 | Huotari Allen J | Key distribution for wireless devices |
| US20080076392A1 (en) * | 2006-09-22 | 2008-03-27 | Amit Khetawat | Method and apparatus for securing a wireless air interface |
| US20100138661A1 (en) * | 2008-12-01 | 2010-06-03 | Institute For Information Industry | Mobile station, access point, gateway apparatus, base station, and handshake method thereof for use in a wireless network framework |
Cited By (7)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| EP3076710A4 (en) * | 2013-12-27 | 2016-12-14 | Huawei Tech Co Ltd | OFFLOAD PROCEDURE, USER DEVICE, BASE STATION AND ACCESS POINT |
| US10034215B2 (en) | 2013-12-27 | 2018-07-24 | Huawei Technologies Co., Ltd. | Offloading method, user equipment, base station, and access point |
| WO2016069638A3 (en) * | 2014-10-29 | 2016-06-23 | Qualcomm Incorporated | User-plane security for next generation cellular networks |
| EP3499840A1 (en) * | 2014-10-29 | 2019-06-19 | Qualcomm Incorporated | User-plane security for next generation cellular networks |
| US10455414B2 (en) | 2014-10-29 | 2019-10-22 | Qualcomm Incorporated | User-plane security for next generation cellular networks |
| CN115348048A (zh) * | 2022-04-28 | 2022-11-15 | 青岛海尔科技有限公司 | 安全通信的建立方法和装置、存储介质及电子装置 |
| US12200495B2 (en) | 2022-11-18 | 2025-01-14 | T-Mobile Usa, Inc. | Integrating security and routing policies in wireless telecommunication networks |
Also Published As
| Publication number | Publication date |
|---|---|
| CN103428690A (zh) | 2013-12-04 |
| EP2854329A1 (en) | 2015-04-01 |
| CN103428690B (zh) | 2016-09-07 |
| US20180035288A1 (en) | 2018-02-01 |
| EP3503496A1 (en) | 2019-06-26 |
| EP3503496B1 (en) | 2021-06-30 |
| US10687213B2 (en) | 2020-06-16 |
| EP2854329B1 (en) | 2019-01-09 |
| US9826398B2 (en) | 2017-11-21 |
| EP2854329A4 (en) | 2015-07-15 |
| US20150082393A1 (en) | 2015-03-19 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| KR102771844B1 (ko) | 다중 등록들을 위한 방법 및 장치 | |
| WO2013174267A1 (zh) | 无线局域网络的安全建立方法及系统、设备 | |
| CN109314638B (zh) | 密钥配置及安全策略确定方法、装置 | |
| KR102315881B1 (ko) | 사용자 단말과 진화된 패킷 코어 간의 상호 인증 | |
| CN107005927B (zh) | 用户设备ue的接入方法、设备及系统 | |
| CN102823280B (zh) | 认证密钥生成部署 | |
| WO2019019736A1 (zh) | 安全实现方法、相关装置以及系统 | |
| WO2013185735A2 (zh) | 一种加密实现方法及系统 | |
| WO2019096075A1 (zh) | 一种消息保护的方法及装置 | |
| WO2022147803A1 (zh) | 安全通信方法及设备 | |
| WO2013181847A1 (zh) | 一种无线局域网接入鉴权方法、设备及系统 | |
| WO2016134536A1 (zh) | 密钥生成方法、设备及系统 | |
| CN109391942A (zh) | 触发网络鉴权的方法及相关设备 | |
| WO2022237561A1 (zh) | 一种通信方法及装置 | |
| US12052358B2 (en) | Method and apparatus for multiple registrations | |
| WO2012083873A1 (zh) | 一种密钥生成方法、装置及系统 | |
| WO2013152740A1 (zh) | 用户设备的认证方法、装置及系统 | |
| JP2020505845A (ja) | 緊急アクセス中のパラメータ交換のための方法およびデバイス | |
| WO2011143977A1 (zh) | 终端移动到增强通用陆地无线接入网络(utran)时建立增强密钥的方法及系统 | |
| CN117203935A (zh) | 用于在按需网络中进行设置、认证、授权和用户设备(ue)密钥生成和分发的方法和装置 | |
| CN102378168B (zh) | 多系统核心网通知密钥的方法和多系统网络 | |
| JP2021524167A (ja) | 複数の登録のための方法および装置 | |
| US12621657B2 (en) | Secure communication method and device |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| 121 | Ep: the epo has been informed by wipo that ep was designated in this application |
Ref document number: 13794647 Country of ref document: EP Kind code of ref document: A1 |
|
| NENP | Non-entry into the national phase |
Ref country code: DE |
|
| WWE | Wipo information: entry into national phase |
Ref document number: 2013794647 Country of ref document: EP |