WO2021129012A1 - 隐私信息传输方法、装置、计算机设备及计算机可读介质 - Google Patents

隐私信息传输方法、装置、计算机设备及计算机可读介质 Download PDF

Info

Publication number
WO2021129012A1
WO2021129012A1 PCT/CN2020/118111 CN2020118111W WO2021129012A1 WO 2021129012 A1 WO2021129012 A1 WO 2021129012A1 CN 2020118111 W CN2020118111 W CN 2020118111W WO 2021129012 A1 WO2021129012 A1 WO 2021129012A1
Authority
WO
WIPO (PCT)
Prior art keywords
identity recognition
request message
authentication information
terminal device
private
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Ceased
Application number
PCT/CN2020/118111
Other languages
English (en)
French (fr)
Inventor
陆海涛
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
ZTE Corp
Original Assignee
ZTE Corp
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by ZTE Corp filed Critical ZTE Corp
Priority to US17/784,808 priority Critical patent/US12225373B2/en
Priority to JP2022535853A priority patent/JP7404540B2/ja
Priority to EP20906846.9A priority patent/EP4061037B1/en
Publication of WO2021129012A1 publication Critical patent/WO2021129012A1/zh
Anticipated expiration legal-status Critical
Ceased legal-status Critical Current

Links

Images

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/02Protecting privacy or anonymity, e.g. protecting personally identifiable information [PII]
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/04Network architectures or network communication protocols for network security for providing a confidential data exchange among entities communicating through data packet networks
    • H04L63/0428Network architectures or network communication protocols for network security for providing a confidential data exchange among entities communicating through data packet networks wherein the data content is protected, e.g. by encrypting or encapsulating the payload
    • H04L63/0442Network architectures or network communication protocols for network security for providing a confidential data exchange among entities communicating through data packet networks wherein the data content is protected, e.g. by encrypting or encapsulating the payload wherein the sending and receiving network entities apply asymmetric encryption, i.e. different keys for encryption and decryption
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/08Network architectures or network communication protocols for network security for authentication of entities
    • H04L63/083Network architectures or network communication protocols for network security for authentication of entities using passwords
    • H04L63/0846Network architectures or network communication protocols for network security for authentication of entities using passwords using time-dependent-passwords, e.g. periodically changing passwords
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/14Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols using a plurality of keys or algorithms
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/32Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials
    • H04L9/3297Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials involving time stamps, e.g. generation of time stamps
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/03Protecting confidentiality, e.g. by encryption
    • H04W12/033Protecting confidentiality, e.g. by encryption of the user plane, e.g. user's traffic
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/06Authentication
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/12Detection or prevention of fraud
    • H04W12/121Wireless intrusion detection systems [WIDS]; Wireless intrusion prevention systems [WIPS]
    • H04W12/122Counter-measures against attacks; Protection against rogue devices
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/14Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic
    • H04L63/1441Countermeasures against malicious traffic
    • H04L63/1466Active attacks involving interception, injection, modification, spoofing of data unit addresses, e.g. hijacking, packet injection or TCP sequence number attacks
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/03Protecting confidentiality, e.g. by encryption
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W60/00Affiliation to network, e.g. registration; Terminating affiliation with the network, e.g. de-registration
    • H04W60/04Affiliation to network, e.g. registration; Terminating affiliation with the network, e.g. de-registration using triggered events

Definitions

  • the embodiments of the present disclosure relate to the field of communication technology, and in particular to a method, device, computer equipment, and computer-readable medium for transmitting private information.
  • IMSI International Mobile Subscriber Identity
  • IMSI International Mobile Subscriber Identity
  • 3GPP R15 the standard protocol of 5G mobile communications (5-Generation, fifth-generation mobile communications technology), has considered the protection of user IMSI.
  • 3GPP 3rd Generation Partnership Project, the third-generation partnership project
  • terminal equipment terminal equipment and The interaction of the network is NAS (Non-Access Stratum, Non-Access Stratum) signaling.
  • the NAS protocol fully considers security measures.
  • the IMSI is protected by encryption.
  • TMSI Temporal Mobile Subscriber Identity
  • TMSI Temporal Mobile Subscriber Identity
  • the present disclosure provides a method, device, computer equipment, and computer-readable medium for transmitting private information.
  • embodiments of the present disclosure provide a method for transmitting private information, including: when an identity registration request message is received, generating authentication information, and encrypting the authentication information with a first private key, the identity registration request The message is sent by the terminal device through the base station; the first identity recognition request message is sent to the terminal device, and the first identity recognition request message carries the encrypted authentication information; the identity recognition response message returned by the terminal device is received, and the The privacy information in the identity recognition response message.
  • embodiments of the present disclosure provide a method for transmitting private information, including: sending an identity registration request message; receiving a first identity recognition request message sent by a network device, and obtaining encrypted authentication in the first identity recognition request message Information; use the first public key to decrypt the encrypted authentication information to obtain authentication information; when the authentication information is valid, send an identity recognition response message to the network device, the identity recognition response message carries Private information.
  • embodiments of the present disclosure provide a network device, including: a generating module, configured to generate authentication information when an identity registration request message is received, the identity registration request message being sent by a terminal device through a base station; and encryption; A module for encrypting the authentication information by using a first private key; a sending module for sending a first identity recognition request message to the terminal device, the first identity recognition request message carrying encrypted authentication information; The obtaining module is used to receive the identity recognition response message returned by the terminal device, and obtain the privacy information in the identity recognition response message.
  • an embodiment of the present disclosure provides a terminal device, including: a receiving module, configured to receive a first identity recognition request message sent by a network device; and an acquiring module, configured to obtain the encrypted first identity recognition request message
  • the decryption module is used to decrypt the encrypted authentication information using the first public key to obtain the authentication information
  • the sending module is used to send the identity registration request message; when the authentication information is valid, to the
  • the network device sends an identity recognition response message, and the identity recognition response message carries privacy information.
  • embodiments of the present disclosure provide a computer device, including: one or more processors; a storage device, wherein one or more programs are stored thereon; when the one or more programs are used by the one When executed by the or multiple processors, the one or more processors implement the method for transmitting private information as described above.
  • embodiments of the present disclosure provide a computer-readable medium on which a computer program is stored, wherein the program is executed to implement the above-mentioned private information transmission method.
  • FIG. 1 is a flowchart of a method for transmitting private information provided by an embodiment of the disclosure
  • FIG. 2 is another flowchart of the privacy information transmission method provided by an embodiment of the present disclosure
  • FIG. 3 is another flowchart of the privacy information transmission method provided by the embodiments of the present disclosure.
  • FIG. 4 is another flowchart of the privacy information transmission method provided by the embodiments of the disclosure.
  • FIG. 5 is a signaling flowchart of a method for transmitting private information provided by an embodiment of the disclosure
  • FIG. 6 is another signaling flowchart of the privacy information transmission method provided by the embodiments of the disclosure.
  • FIG. 7a and 7b are schematic diagrams of functions for preventing private information from being stolen by an attacker provided by an embodiment of the present disclosure
  • FIG. 8 is a schematic structural diagram of a network device provided by an embodiment of the disclosure.
  • FIG. 9 is a schematic structural diagram of a terminal device provided by an embodiment of the disclosure.
  • FIG. 10 is a schematic diagram of a computer device provided by an embodiment of the disclosure.
  • an attacker can use an active way to capture the private information (such as IMSI) of the initial NAS signaling.
  • the active method is that the attacker pretends to be a communication base station and sends an identification request message to the terminal device, and the terminal device leaks private information after responding.
  • embodiments of the present disclosure provide a method for transmitting private information.
  • the privacy information transmission method of the embodiments of the present disclosure is applied to a system including terminal equipment and network equipment.
  • the terminal equipment and network equipment in the embodiments of the present disclosure include but are not limited to 5G equipment.
  • the network device may be a 5G core network device.
  • the network equipment of the network operator generates the first public key and the first private key, the first public key is used for data encryption, the first private key is used for data decryption, the first private key is stored inside the network device, and the first public key is issued To the terminal equipment.
  • the terminal device enters the network and opens an account
  • the network operator allocates private information (ie IMSI) and the first public key (ie, the public key generated by the network operator).
  • the terminal device also generates a second public key and a second private key and stores them locally.
  • the IMSI and the first public key of the terminal device are stored on a USIM (Universal Subscriber Identity Module, Global Subscriber Identity Module) card of the terminal device.
  • USIM Universal Subscriber
  • the embodiments of the present disclosure provide a method for transmitting private information, which is applied to a network device. As shown in FIG. 1 and FIG. 5, the method for transmitting private information includes the following steps:
  • Step 101 When an identity registration request message is received, authentication information is generated.
  • the terminal device accesses the network for the first time or is turned off after a long period of time, the terminal device sends an identity registration request message to the base station (step 100 in FIG. 5), and the identity registration request message carries the temporary identity of the terminal device. Identify the GUTI, and the base station forwards the identity registration request message to the network device of the core network (step 100' in FIG. 5).
  • the network device of the core network cannot query the true identity of the terminal device through the GUTI. In order to verify the true identity of the terminal device, the network device generates authentication information.
  • Step 102 Use the first private key to encrypt the authentication information.
  • the network device uses the pre-stored first private key to encrypt the authentication information to generate encrypted authentication information.
  • Step 103 Send a first identity recognition request message to the terminal device.
  • the network device sends a first identity recognition request message to the terminal device, where the first identity recognition request message carries encrypted authentication information.
  • the terminal device uses the pre-stored first public key to decrypt and verify whether the authentication information is valid.
  • Step 104 Receive the identity recognition response message returned by the terminal device, and obtain the privacy information in the identity recognition response message.
  • the terminal device when the terminal device decrypts the encrypted authentication information carried in the first identity recognition request message and verifies that the authentication information is valid, it returns an identity recognition response message carrying private information to the network device.
  • the network device obtains the privacy information in the identity recognition response message.
  • the network device determines that the privacy information is correct, it determines that the identity of the terminal device is true and allows the terminal device to access the network.
  • the private information here may include encrypted private data or unencrypted private data.
  • the embodiment of the present disclosure generates and encrypts authentication information through a network device, so that the terminal device authenticates the authentication information, prevents the pseudo base station from acquiring the privacy information of the terminal device, and ensures that the terminal device is turned on again when the terminal device is connected for the first time or is turned off for a long time.
  • the initial NAS signaling of equipment and network equipment can safely transmit private information, avoid leakage of private information, and improve the security and reliability of data transmission.
  • the private information includes unencrypted private data.
  • the terminal device decrypts the encrypted authentication information carried in the first identity recognition request message and verifies that the authentication information is valid, it returns an identity recognition response message carrying unencrypted private data to the network device.
  • the network device obtains the unencrypted private data in the identity recognition response message, and when it is determined that the unencrypted private data is correct, it determines that the identity of the terminal device is true and allows the terminal device to access the network.
  • the attacker uses an active method to capture private information, that is, the attacker uses a pseudo base station device to simulate a real base station to the terminal
  • the device sends an identification request message to obtain the user's private information. Since the pseudo base station cannot simulate the network device of the real core network to issue and carry the authentication information encrypted with the first private key, when the terminal device uses the first public key to decrypt, the authentication information cannot be obtained, or the obtained authentication information is invalid. Therefore, the terminal device will not respond to the identity recognition request message sent by the pseudo base station, and will not leak the user's private information to the pseudo base station.
  • the attacker can also passively capture the private information of the initial NAS signaling.
  • the passive way is to obtain private information through data analysis by monitoring the signaling messages between the terminal equipment and the network. For this way of stealing private information, in some embodiments, as shown in FIG. 2 and FIG. 6, the private information includes encrypted private data.
  • Step 201 Receive the identity recognition response message returned by the terminal device, and obtain the second public key in the identity recognition response message.
  • the terminal device decrypts the encrypted authentication information carried in the first identity recognition request message and verifies that the authentication information is valid
  • the second public key is carried in the identity recognition response message and sent to the network device.
  • the network device receives the identity recognition response message and obtains the second public key therein.
  • Step 202 Generate a temporary key, encrypt the temporary key with the second public key, and generate a second identity recognition request message according to the encrypted temporary key.
  • the network device In this step, the network device generates a temporary key, encrypts the temporary key with the second public key, and generates a second identity recognition request message carrying the encrypted temporary key.
  • Step 203 Send a second identity recognition request message to the terminal device.
  • the network device sends the second identity recognition request message to the terminal device, so that the terminal device can obtain the temporary key and encrypt it with the temporary key.
  • obtaining the private information in the identity recognition response message includes: obtaining the encrypted private data carried in the identity recognition response message. After step 104, it further includes: decrypting the encrypted private data by using the temporary key to obtain the private data.
  • the network device determines that the decrypted private data is correct, it determines that the identity of the terminal is true and allows the terminal to access the network.
  • the attacker uses a passive method to capture private information, that is, the attacker uses a listener to monitor the identity sent by the terminal device. In response to the air interface wireless signal of the message, perform wireless communication protocol analysis to capture private information.
  • the terminal device since the terminal device uses the temporary key to encrypt the private data in the carried private information, the attacker cannot obtain the plaintext content of the private data.
  • the temporary key is replaced each time the private information is transmitted, the ciphertext of the private data transmitted each time is different, making it impossible for an attacker to use the ciphertext of the private data and the user binding for tracking.
  • the authentication information is a timestamp
  • the encrypted authentication information is the encrypted timestamp
  • the attacker uses the pseudo base station to actively capture the private information of the initial NAS signaling.
  • the embodiment of the present disclosure also provides a method for transmitting private information. The method is applied to a terminal device. As shown in FIG. 3 and FIG. 5, the privacy information transmission method includes the following steps:
  • Step 301 Send an identity registration request message.
  • the terminal device when the terminal device accesses the network for the first time or is turned off after a long period of time, the terminal device sends an identity registration request message to the base station (that is, step 100 in FIG. 5), and the identity registration request message carries the terminal device temporary Identity GUTI.
  • the base station forwards the identity registration request message to the network device of the core network (step 100' in Fig. 5).
  • Step 302 Receive a first identity recognition request message sent by a network device, and obtain encrypted authentication information in the first identity recognition request message.
  • the network device After the network device receives the identity registration request message forwarded by the base station, it generates authentication information, uses the locally stored first public key to encrypt the authentication information, generates encrypted authentication information, and sends the encrypted authentication information to the terminal device The first identification request message. The terminal device obtains the encrypted authentication information in the first identity recognition request message.
  • Step 303 Use the first public key to decrypt the encrypted authentication information to obtain the authentication information.
  • the terminal device uses the pre-stored first public key to decrypt the encrypted authentication information to obtain the authentication information.
  • Step 304 When the authentication information is valid, send an identity recognition response message to the network device.
  • the identity recognition response message carrying privacy information is sent to the network device for the network device to obtain the identity recognition response Private information in the message. If the network device can determine that the private information is correct, the terminal device is considered to be authentic and the terminal device is allowed to access the network. It should be noted that the private information here may be encrypted private data or unencrypted private data.
  • the embodiment of the present disclosure generates and encrypts authentication information through a network device, so that the terminal device authenticates the authentication information, prevents the pseudo base station from acquiring the privacy information of the terminal device, and ensures that the terminal device is turned on again when the terminal device is connected for the first time or is turned off for a long time.
  • the initial NAS signaling of equipment and network equipment can safely transmit private information, avoid leakage of private information, and improve the security and reliability of data transmission.
  • the private information includes unencrypted private data.
  • the terminal device sends an identity recognition response message carrying unencrypted private data to the network device, so that the terminal device can obtain the unencrypted private data.
  • the network device determines that the private data is correct, it determines that the identity of the terminal device is true and allows the terminal device to access the network.
  • the attacker uses an active method to capture private information, that is, the attacker uses a pseudo base station to simulate a real base station to the terminal device. Send an identification request message to obtain the user's private information. Since the pseudo base station cannot simulate the network device of the real core network to issue and carry the authentication information encrypted with the first private key, when the terminal device uses the first public key to decrypt, the authentication information cannot be obtained, or the obtained authentication information is invalid. Therefore, the terminal device will not respond to the identity recognition request message sent by the pseudo base station, and will not leak the user's private information to the pseudo base station.
  • the attacker uses the listener to passively obtain the private information of the initial NAS signaling.
  • the private information includes encrypted private data, and before sending the identification response message to the network device (ie, step 304), it also includes:
  • Step 401 When the authentication information is valid, send an identity recognition response message to the network device.
  • the terminal device decrypts the encrypted authentication information carried in the first identity recognition request message and verifies that the authentication information is valid, it returns an identity recognition response message carrying the second public key to the network device.
  • Step 402 Receive the second identity recognition request message sent by the network device, obtain the encrypted temporary key carried therein, and decrypt the encrypted temporary key with the second private key to obtain the temporary key.
  • the encrypted temporary key is obtained after the network device generates the temporary key and encrypts it with the second public key.
  • the terminal device decrypts the encrypted temporary key according to the second private key stored locally to obtain the temporary key.
  • Step 403 Use the temporary key to encrypt the private data to obtain the encrypted private data.
  • the terminal device uses the temporary key to encrypt the private data to obtain the encrypted private data, that is, the encrypted IMSI.
  • sending an identity recognition response message to the network device includes: sending an identity recognition response message carrying encrypted private data to the network device.
  • the terminal device sends an identity recognition response message carrying the encrypted private data to the network device, so that the network device uses the temporary key to decrypt and obtain the private data. If the network device determines that the decrypted private data is correct and considers the identity of the terminal device to be true, the terminal device is allowed to access the network.
  • the attacker uses a passive method to capture private information, that is, the attacker uses a listener to monitor the identity sent by the terminal device. In response to the air interface wireless signal of the message, perform wireless communication protocol analysis to capture private information.
  • the terminal device since the terminal device uses the temporary key to encrypt the private data in the carried private information, the attacker cannot obtain the plaintext content of the private data.
  • the temporary key is replaced each time the private information is transmitted, the ciphertext of the private data transmitted each time is different, making it impossible for an attacker to use the ciphertext of the private data and the user binding for tracking.
  • the valid authentication information includes: the timestamp is consistent with the current time. If it is verified that the time stamp is consistent with the current time, the authentication information is valid. Conversely, if the time stamp is not decrypted, or the time stamp is inconsistent with the current time, the authentication information is invalid.
  • an embodiment of the present disclosure also provides a network device, including:
  • the generating module 11 is configured to generate authentication information when an identity registration request message is received; the identity registration request message is sent by the terminal device through the base station.
  • the encryption module 12 is configured to encrypt the authentication information by using the first private key.
  • the sending module 13 is configured to send a first identity recognition request message to the sending terminal device, where the first identity recognition request message carries encrypted authentication information.
  • the first obtaining module 14 is configured to receive the identity recognition response message returned by the terminal device, and obtain the privacy information in the identity recognition response message.
  • the device further includes:
  • the second obtaining module is configured to receive the identity recognition response message returned by the terminal device, and obtain the second public key in the identity recognition response message.
  • the encryption module is used for generating a temporary key, and encrypting the temporary key by using the second public key.
  • the sending module 13 is further configured to generate a second identity recognition request message according to the encrypted temporary key, and send the second identity recognition request message to the terminal device.
  • the first obtaining module 14 is further configured to obtain the encrypted private data carried in the identity recognition response message, and decrypt the encrypted private data using the temporary key to obtain the private data.
  • the private information includes unencrypted private data.
  • the authentication information includes a time stamp.
  • an embodiment of the present disclosure further provides a terminal device, including:
  • the receiving module 21 is configured to receive the first identity recognition request message sent by the network device.
  • the obtaining module 22 is configured to obtain the encrypted authentication information in the first identity recognition request message.
  • the first decryption module 23 is configured to use the first public key to decrypt the encrypted authentication information to obtain the authentication information.
  • the sending module 24 is configured to send an identity registration request message; when the authentication information is valid, send an identity recognition response message to the network device, and the identity recognition response message carries privacy information.
  • the private information includes encrypted private data
  • the device further includes:
  • the sending module is further configured to send an identity recognition response message to the network device, where the identity recognition response message carries the second public key.
  • the second decryption module is configured to receive the second identity recognition request message sent by the network device, obtain the encrypted temporary key carried therein, and decrypt the encrypted temporary key using the second private key, A temporary key is obtained, and the encrypted temporary key is obtained after the network device generates the temporary key and encrypts it with the second public key.
  • the encryption module is used to encrypt private data by using the temporary key to obtain encrypted private data.
  • the sending module 24 is further configured to send an identity recognition response message carrying the encrypted private data to the network device.
  • the private information includes unencrypted private data.
  • the authentication information includes a time stamp
  • the valid authentication information includes: the time stamp is consistent with the current time.
  • an embodiment of the present disclosure also provides a computer device, the computer device includes: one or more processors 1001 and a storage device 1002; wherein, the storage device 1002 stores one or more programs, when the above one When one or more programs are executed by the above-mentioned one or more processors 1001, the above-mentioned one or more processors 1001 implement the privacy information transmission method as provided in the foregoing embodiments.
  • the embodiments of the present disclosure also provide a computer-readable medium on which a computer program is stored, wherein the computer program implements the privacy information transmission method provided in the foregoing embodiments when the computer program is executed.
  • the private information transmission method, device, computer equipment, and computer readable medium provided by the embodiments of the present disclosure generate authentication information when receiving an identity registration request message, and encrypt the authentication information with the first private key;
  • the device sends a first identity recognition request message, where the first identity recognition request message carries encrypted authentication information; receives the identity recognition response message returned by the terminal device, and obtains the privacy information in the identity recognition response message.
  • the embodiment of the present disclosure generates and encrypts authentication information through a network device, so that the terminal device authenticates the authentication information, prevents the pseudo base station from acquiring the privacy information of the terminal device, and ensures that the terminal device is turned on again when the terminal device is connected for the first time or is turned off for a long time. Devices and network devices can safely transmit private information, avoid leakage of private information, and improve the security and reliability of data transmission.
  • the functional modules/units in the device can be implemented as software, firmware, hardware, and appropriate combinations thereof.
  • the division between functional modules/units mentioned in the above description does not necessarily correspond to the division of physical components; for example, a physical component may have multiple functions, or a function or step may consist of several physical components.
  • the components are executed cooperatively.
  • Some physical components or all physical components can be implemented as software executed by a processor, such as a central processing unit, a digital signal processor, or a microprocessor, or as hardware, or as an integrated circuit, such as an application specific integrated circuit .
  • Such software may be distributed on a computer-readable medium
  • the computer-readable medium may include a computer storage medium (or non-transitory medium) and a communication medium (or transitory medium).
  • the term computer storage medium includes volatile and non-volatile data implemented in any method or technology for storing information (such as computer-readable instructions, data structures, program modules, or other data).
  • Information such as computer-readable instructions, data structures, program modules, or other data.
  • Computer storage media include but are not limited to RAM, ROM, EEPROM, flash memory or other memory technologies, CD-ROM, digital versatile disk (DVD) or other optical disk storage, magnetic cassettes, magnetic tapes, magnetic disk storage or other magnetic storage devices, or Any other medium used to store desired information and that can be accessed by a computer.
  • communication media usually contain computer-readable instructions, data structures, program modules, or other data in a modulated data signal such as carrier waves or other transmission mechanisms, and may include any information delivery media. .

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Computer Hardware Design (AREA)
  • Computing Systems (AREA)
  • General Engineering & Computer Science (AREA)
  • Mobile Radio Communication Systems (AREA)

Abstract

一种隐私信息传输方法、装置、计算机设备及计算机可读介质。所述方法包括:当接收到身份注册请求消息时,生成认证信息,并利用第一私钥对认证信息进行加密,身份注册请求消息是终端设备通过基站发送的;向终端设备发送第一身份识别请求消息,第一身份识别请求消息携带加密后的认证信息;接收终端设备返回的身份识别响应消息,获取身份识别响应消息中的隐私信息。

Description

隐私信息传输方法、装置、计算机设备及计算机可读介质
相关申请的交叉引用
本申请基于申请号为201911358121.2、申请日为2019年12月25日的中国专利申请提出,并要求该中国专利申请的优先权,该中国专利申请的全部内容在此引入本申请作为参考。
技术领域
本公开实施例涉及通信技术领域,具体涉及一种隐私信息传输方法、装置、计算机设备及计算机可读介质。
背景技术
现在社会对个人隐私信息保护越来越重视。在移动通信过程中,使用大量的终端设备,每个终端设备都有全球唯一的IMSI(International Mobile Subscriber Identity,国际移动用户识别码)。IMSI由一串十进制数字组成,最大长度为15位,是用于区分移动通信网络中不同用户的、在所有移动通信网络中不重复的识别码。因此IMSI就是用户的隐私信息,如何防止IMSI泄露,是移动通信过程中保护用户隐私的主要内容。
5G移动通信(5-Generation,第五代移动通信技术)的标准协议3GPP R15已经考虑到了对用户IMSI的保护,3GPP(3rd Generation Partnership Project,第三代合作伙伴计划)的设计中,终端设备与网络的交互是NAS(Non-Access Stratum,非接入层)信令。NAS协议充分考虑了安全性措施,在通信过程中通过加密方式保护IMSI,除了信令的加密和安保以外,还有用临时的TMSI(Temporary Mobile Subscriber Identity,临时移动用户标识)代替IMSI,防止IMSI暴露导致用户信息泄露。但是,终端设备首次接入或长时间关机后再开机时,网络会要求识别终端设备身份,这不可避免的会携带隐私信息,导致这部分信令存在隐私信息泄露风险。
发明内容
有鉴于此,本公开提供一种隐私信息传输方法、装置、计算机设备及计算机可读介质。
第一方面,本公开实施例提供一种隐私信息传输方法,包括:当接收到身份注册请求消息时,生成认证信息,并利用第一私钥对所述认证信息进行加密,所述身份注册请求消息是终端设备通过基站发送的;向所述终端设备发送第一身份识别请求消息,所述第一身份识别请求消息携带加密后的认证信息;接收所述终端设备返回的身份识别响应消息,获取所述身份识别响应消息中的隐私信息。
第二方面,本公开实施例提供一种隐私信息传输方法,包括:发送身份注册请求消息;接收网络设备发送的第一身份识别请求消息,获取所述第一身份识别请求消息中加密后的认证信息;利用第一公钥对所述加密后的认证信息进行解密,得到认证信息;当所述认证信息有效时,向所述网络设备发送身份识别响应消息,所述身份识别响应消息中携带有隐私信息。
第三方面,本公开实施例提供一种网路设备,包括:生成模块,用于当接收到身份注册请求消息时,生成认证信息,所述身份注册请求消息是终端设备通过基站发送的;加密模块,用于利用第一私钥对所述认证信息进行加密;发送模块,用于向所述终端设备发送第一身份识别请求消息,所述第一身份识别请求消息携带加密后的认证信息;获取模块,用于接收所述终端设备返回的身份识别响应消息,获取所述身份识别响应消息中的隐私信息。
第四方面,本公开实施例提供一种终端设备,包括:接收模块,用于接收网络设备发送的第一身份识别请求消息;获取模块,用于获取所述第一身份识别请求消息中加密后的认证信息;解密模块,用于利用第一公钥对所述加密后的认证信息进行解密,得到认证信息;发送模块,用于发送身份注册请求消息;当所述认证信息有效时,向所述网络设备发送身份识别响应消息,所述身份识别响应消息携带隐私信息。
第五方面,本公开实施例提供一种计算机设备,包括:一个或多个处理器;存储装置,其中,其上存储有一个或多个程序;当所述一个或多个程序被所述一个或多个处理器执行时,使得所述一个或多个处理器实现如上述的隐私信息传输方法。
第六方面,本公开实施例提供一种计算机可读介质,其上存储有计算机程序,其中,所述程序被执行时实现如上述的隐私信息传输方法。
附图说明
图1为本公开实施例提供的隐私信息传输方法的流程图;
图2为本公开实施例提供的隐私信息传输方法的又一流程图;
图3为本公开实施例提供的隐私信息传输方法的又一流程图;
图4为本公开实施例提供的隐私信息传输方法的又一流程图;
图5为本公开实施例提供的隐私信息传输方法的信令流程图;
图6为本公开实施例提供的隐私信息传输方法的又一信令流程图;
图7a和图7b为本公开实施例提供的防止隐私信息被攻击者窃取的功能示意图;
图8为本公开实施例提供的网络设备的结构示意图;
图9为本公开实施例提供的终端设备的结构示意图;
图10为本公开实施例提供的计算机设备的示意图。
具体实施方式
在下文中将参考附图更充分地描述示例实施例,但是所述示例实施例可以以不同形式来体现且不应当被解释为限于本文阐述的实施例。反之,提供这些实施例的目的在于使本公开透彻和完整,并将使本领域技术人员充分理解本公开的范围。
如本文所使用的,术语“和/或”包括一个或多个相关列举条目的任何和所有组合。
本文所使用的术语仅用于描述特定实施例,且不意欲限制本公开。如本文所使用的,单数形式“一个”和“该”也意欲包括复数形式,除非上下文另外清楚指出。还将理解的是,当本说明书中使用术语“包括”和/或“由……制成”时,指定存在所述特征、整体、步骤、操作、元件和/或组件,但不排除存在或添加一个或多个其他特征、整体、步骤、操作、元件、组件和/或其群组。
本文所述实施例可借助本公开的理想示意图而参考平面图和/或截面图进行描述。因此,可根据制造技术和/或容限来修改示例图示。因此,实施例不限于附图中所示的实施例,而是包括基于制造工艺而形成的配置的修改。因此,附图中例示的区具有示意性属性,并且图中所示区的形状例示了元件的区的具体形状,但并不旨在是限制性的。
除非另外限定,否则本文所用的所有术语(包括技术和科学术语)的含义与本领域普通技术人员通常理解的含义相同。还将理解,诸如那些在常用字典中限定的那些术语应当被解释为具有与其在相关技术以及本公开的背景下的含义一致的含义,且将不解释为具有理想化或过度形式上的含义,除非本文明确如此限定。
终端设备首次接入或长时间关机后再开机时,攻击者可以使用主动方式捕获初始NAS信令的隐私信息(例如IMSI)。主动方式是攻击者伪装成通信基站,向终端设备发送身份识别请求消息,终端设备响应后泄露隐私信息。针对这种窃取隐私信息的方式,本公开实施例提供一种隐私信息传输方法。
本公开实施例的隐私信息传输方法应用于包括终端设备设备和网络设备的系统,在一些情况下,本公开实施例中的终端设备与网络设备包括但不限于5G设备。网络设备可以为5G核心网设备。网络运营商的网络设备生成第一公钥和第一私钥,第一公钥用于数据加密,第一私钥用于数据解密,第一私钥保存在网络设备内部,第一公钥发布给终端设备。终端设备在入网开户时由网络运营商分配隐私信息(即IMSI)、第一公钥(即网络运营商产生的公钥)。终端设备还生成第二公钥和第二私钥并存储在本地,终端设备所述IMSI和第一公钥存储在终端设备的USIM(Universal Subscriber Identity Module,全球用户识别卡)卡上。
本公开实施例提供一种隐私信息传输方法,所述方法应用于网络设备,结合图1和图5所示,所述隐私信息传输方法包括以下步骤:
步骤101,当接收到身份注册请求消息时,生成认证信息。
在本步骤之前,终端设备首次接入网络或长时间关机后再开机时,终端设备向基站发送身份注册请求消息(如图5中的步骤100),所述身份注册请求消息携带终端设备临时身份标识GUTI,基站将身份注册请求消息转发给核心网的网络设备(如图5中的步骤100’)。
由于终端设备是首次接入或长时间关机后再开机,核心网的网络设备通过所述GUTI无法查询到终端设备的真实身份,为核实终端设备的真实身份,网络设备生成认证信息。
步骤102,利用第一私钥对认证信息进行加密。
在该步骤中,网络设备利用预先存储的第一私钥对认证信息进行加密,生成加密后的认证信息。
步骤103,向终端设备发送第一身份识别请求消息。
在该步骤中,网络设备向终端设备发送第一身份识别请求消息,所述第一身份识别请求消息携带加密后的认证信息。以供终端设备接收到该加密后的认证信息之后,利用预先存储的第一公钥进行解密,并验证认证信息是否有效。
步骤104,接收终端设备返回的身份识别响应消息,获取身份识别响应消息中的隐私信息。
在该步骤中,当终端设备对第一身份识别请求消息中携带的加密后的认证信息进行解密,并且验证认证信息有效时,向网络设备返回携带有隐私信息的身份识别响应消息。网络设备获取身份识别响应消息中的隐私信息,当网络设备确定隐私信息正确时,则确定终端设备的身份真实,允许终端设备接入网络。需要说明的是,此处的隐私信息可以包括加密的隐私数据,也可以包括未加密的隐私数据。
本公开实施例通过网络设备生成并加密认证信息,以便终端设备对该认证信息进行认证,防止伪基站获取终端设备的隐私信息,确保在终端设备首次接入或长时间关机后再开机时,终端设备和网络设备的初始NAS信令能够安全地传输隐私信息,避免隐私信息泄露,提高数据传输的安全性和可靠性。
在一些实施例中,隐私信息包括未加密的隐私数据。当终端设备对第一身份识别请求消息中携带的加密后的认证信息进行解密,并且验证认证信息有效时,向网络设备返回携带有未加密的隐私数据的身份识别响应消息。网络设备获取身份识别响应消息中的未加密的隐私数据,当确定未加密的隐私数据正确时,则确定终端设备的身份真实,允许终端设备接入网络。
本公开实施例中,如图7a所示,针对终端设备首次接入网络或长时间关机后再开机时,攻击者使用主动方式捕获隐私信息,即攻击者使用伪基站设备,模拟真实基站向终端设备发送身份识别请求消息,来获取用户的隐私信息。由于伪基站无法模拟真实核心网的网络设备下发携带有使用第一私钥加密的认证信息,这样终端设备使用第一公钥解密时,不能获得认证信息,或者获得的认证信息无效。因此终端设备将不会响应伪基站发送的身份识别请求消息,也就不会向伪基站泄露用户的隐私信息。
终端设备首次接入或长时间关机后再开机时,攻击者还可以使用被动方式捕获初始NAS信令的隐私信息。被动方式是通过监听终端设备和网络间的信令消息,通过数据分析来获取隐私信息。针对这种窃取隐私信息的方式,在一些实施例中,结合图2和图6所示,隐私信息包括加密后的隐私数据,向终端设备发送第一身份识别请求消息(即步骤103)之后,还包括:
步骤201,接收终端设备返回的身份识别应答消息,获取身份识别应答消息中的第二公钥。
当终端设备对第一身份识别请求消息中携带的加密后的认证信息进行解密,并且验证认证信息有效时,将第二公钥携带在身份识别应答消息中发送给网络设备,在本步骤中,网络设备接收身份识别应答消息,获取其中的第二公钥。
步骤202,生成临时密钥,利用第二公钥对临时密钥加密,根据加密后的临时密钥生成第二身份识别请求消息。
在该步骤中,网络设备生成临时密钥,利用第二公钥对临时密钥加密,生成携带加密后的临时密钥的第二身份识别请求消息。
步骤203,向终端设备发送第二身份识别请求消息。
在该步骤中,网络设备将第二身份识别请求消息发送至终端设备,以供终端设备获取该临时密钥,并利用临时密钥加密。
相应的,获取身份识别响应消息中的隐私信息(即步骤104)包括:获取身份识别响应消息中携带的加密后的隐私数据。步骤104之后,还包括:利用临时密钥对加密后的隐私数据进行解密,得到隐私数据。当网络设备确定解密出的隐私数据正确时,则确定终端的身份真实,允许终端接入网络。
本公开实施例中,如图7b所示,针对终端设备首次接入网络或长时间关机后再开机时,攻击者使用被动方式捕获隐私信息,即攻击者使用监听器监听终端设备发送的身份识别响应消息的空口无线信号,进行无线通信协议分析捕获隐私信息。在本公开实施例中,由于终端设备对携带的隐私信息中隐私数据都使用临时密钥进行加密,因此攻击者无法获 得隐私数据的明文内容。而且,由于每次隐私信息传输都更换临时密钥,因此每次所传输的隐私数据的密文都不同,使得攻击者无法使用隐私数据的密文和用户绑定进行追踪。
在一些实施例中,所述认证信息为时间戳,所述加密后的认证信息即为加密后的时间戳。
针对终端设备首次接入或长时间关机后再开机时,攻击者使用伪基站主动捕获初始NAS信令的隐私信息的情况。本公开实施例还提供一种隐私信息传输方法。所述方法应用于终端设备,结合图3和图5所示,所述隐私信息传输方法包括以下步骤:
步骤301,发送身份注册请求消息。
在本步骤中,终端设备首次接入网络或长时间关机后再开机时,终端设备向基站发送身份注册请求消息(即图5中的步骤100),所述身份注册请求消息携带有终端设备临时身份标识GUTI。本步骤之后,基站将所述身份注册请求消息转发给核心网的网络设备(如图5中的步骤100’)。
步骤302,接收网络设备发送的第一身份识别请求消息,获取所述第一身份识别请求消息中加密后的认证信息。
网络设备接收到基站转发的身份注册请求消息之后,生成认证信息,并利用本地存储的第一公钥对认证信息加密,生成加密后的认证信息,并向终端设备发送携带加密后的认证信息的第一身份识别请求消息。终端设备获取第一身份识别请求消息中加密后的认证信息。
步骤303,利用第一公钥对所述加密后的认证信息进行解密,得到认证信息。
在该步骤中,终端设备利用预先存储的第一公钥对加密后的认证信息进行解密,得到认证信息。
步骤304,当所述认证信息有效时,向网络设备发送身份识别响应消息。
若终端设备验证出认证信息有效,说明所述第一身份识别请求消息是由真实的网络设备发出的,则将携带隐私信息的身份识别响应消息发送到网络设备,以供网络设备获取身份识别响应消息中的隐私信息。若能网络设备确定隐私信息正确,则认为终端设备的身份真实,允许终端设备接入网络。需要说明的是,此处的隐私信息可以是加密的隐私数据,也可以是未加密的隐私数据。
本公开实施例通过网络设备生成并加密认证信息,以便终端设备对该认证信息进行认证,防止伪基站获取终端设备的隐私信息,确保在终端设备首次接入或长时间关机后再开机时,终端设备和网络设备的初始NAS信令能够安全地传输隐私信息,避免隐私信息泄露,提高数据传输的安全性和可靠性。
在一些实施例中,隐私信息包括未加密的隐私数据。终端设备向网络设备发送携带未加密的隐私数据的身份识别响应消息,以供终端设备获取未加密的隐私数据。当网络设备确定隐私数据正确时,则确定终端设备的身份真实,允许终端设备接入网络。
本公开实施例中,如图7a所示,针对终端设备首次接入网络或长时间关机后再开机时,攻击者使用主动方式捕获隐私信息,即攻击者使用伪基站,模拟真实基站向终端设备发送身份识别请求消息,来获取用户的隐私信息。由于伪基站无法模拟真实核心网的网络设备下发携带有使用第一私钥加密的认证信息,这样终端设备使用第一公钥解密时,不能获得认证信息,或者获得的认证信息无效。因此终端设备将不会响应伪基站发送的身份识别请求消息,也就不会向伪基站泄露用户的隐私信息。
针对终端设备首次接入网络或长时间关机后再开机时,攻击者使用监听器被动获取初始NAS信令的隐私信息的情况。在一些实施例中,结合图4和图6,隐私信息包括加密后的隐私数据,向网络设备发送身份识别响应消息(即步骤304)之前,还包括:
步骤401,当认证信息有效时,向网络设备发送身份识别应答消息。
在该步骤中,当终端设备对第一身份识别请求消息中携带的加密后的认证信息进行解密,并且验证认证信息有效时,向网络设备返回携带第二公钥的身份识别应答消息。
步骤402,接收网络设备发送的第二身份识别请求消息,获取其中携带的加密后的临时密钥,并利用第二私钥对加密后的临时密钥进行解密,得到临时密钥。
在该步骤中,加密后的临时密钥是网络设备生成临时密钥之后,并利用第二公钥加密得到的。终端设备根据本地存储的第二私钥对加密后的临时密钥进行解密,得到临时密钥。
步骤403,利用临时密钥对隐私数据进行加密,得到加密后的隐私数据。
在该步骤中,终端设备利用临时密钥对隐私数据进行加密,得到加密后的隐私数据,即加密后的IMSI。
相应的,向网络设备发送身份识别响应消息(即步骤304),包括:向网络设备发送携带加密后的隐私数据的身份识别响应消息。
在该步骤中,终端设备向网络设备发送携带加密后的隐私数据的身份识别响应消息,以供网络设备利用临时密钥进行解密,获取隐私数据。若网络设备确定解密出的隐私数据正确,认为终端设备的身份真实,则允许终端设备接入网络。
本公开实施例中,如图7b所示,针对终端设备首次接入网络或长时间关机后再开机时,攻击者使用被动方式捕获隐私信息,即攻击者使用监听器监听终端设备发送的身份识别响应消息的空口无线信号,进行无线通信协议分析捕获隐私信息。在本公开实施例中,由于终端设备对携带的隐私信息中隐私数据都使用临时密钥进行加密,因此攻击者无法获 得隐私数据的明文内容。而且,由于每次隐私信息传输都更换临时密钥,因此每次所传输的隐私数据的密文都不同,使得攻击者无法使用隐私数据的密文和用户绑定进行追踪。
在一些实施例中,所述认证信息有效包括:所述时间戳与当前时间一致。若验证出时间戳与当前时间一致,则说明认证信息有效。反之,如果解密不出时间戳,或者解密出的时间戳与当前时间不一致,则说明认证信息无效。
基于与前述实施例相同的技术构思,如图8所示,本公开实施例还提供一种网络设备,包括:
生成模块11用于,当接收到身份注册请求消息时,生成认证信息;所述身份注册请求消息是终端设备通过基站发送的。
加密模块12用于,利用第一私钥对所述认证信息进行加密。
发送模块13用于,向发送所述终端设备发送第一身份识别请求消息,所述第一身份识别请求消息携带加密后的认证信息。
第一获取模块14用于,接收所述终端设备返回的身份识别响应消息,获取所述身份识别响应消息中的隐私信息。
在一些实施例中,所述装置还包括:
第二获取模块用于,接收所述终端设备返回的身份识别应答消息,获取所述身份识别应答消息中的第二公钥。
加密模块用于,生成临时密钥,利用所述第二公钥对所述临时密钥加密。
发送模块13还用于,根据加密后的临时密钥生成第二身份识别请求消息,并向所述终端设备发送所述第二身份识别请求消息。
所述第一获取模块14还用于,获取所述身份识别响应消息中携带的加密后的隐私数据,利用所述临时密钥对所述加密后的隐私数据进行解密,得到所述隐私数据。
在一些实施例中,所述隐私信息包括未加密的隐私数据。
在一些实施例中,所述认证信息包括时间戳。
基于与上述实施例相同的技术构思,如图9所示,本公开实施例还提供一种终端设备,包括:
接收模块21用于,接收网络设备发送的第一身份识别请求消息。
获取模块22用于,获取所述第一身份识别请求消息中加密后的认证信息。
第一解密模块23用于,利用第一公钥对所述加密后的认证信息进行解密,得到认证信息。
发送模块24用于,发送身份注册请求消息;当所述认证信息有效时,向所述网络设 备发送身份识别响应消息,所述身份识别响应消息中携带有隐私信息。
在一些实施例中,所述隐私信息包括加密后的隐私数据,所述装置还包括:
发送模块还用于,向所述网络设备发送身份识别应答消息,所述身份识别应答消息携带第二公钥。
第二解密模块用于,接收所述网络设备发送的第二身份识别请求消息,获取其中携带的加密后的临时密钥,并利用第二私钥对所述加密后的临时密钥进行解密,得到临时密钥,所述加密后的临时密钥是所述网络设备生成临时密钥之后,并利用第二公钥加密得到的。
加密模块用于,利用所述临时密钥对隐私数据进行加密,得到加密后的隐私数据。
所述发送模块24还用于,向所述网络设备发送携带所述加密后的隐私数据的身份识别响应消息。
在一些实施例中,所述隐私信息包括未加密的隐私数据。
在一些实施例中,所述认证信息包括时间戳,所述认证信息有效包括:所述时间戳与当前时间一致。
参照图10,本公开实施例还提供了一种计算机设备,该计算机设备包括:一个或多个处理器1001以及存储装置1002;其中,存储装置1002上存储有一个或多个程序,当上述一个或多个程序被上述一个或多个处理器1001执行时,使得上述一个或多个处理器1001实现如前述各实施例所提供的隐私信息传输方法。
本公开实施例还提供了一种计算机可读介质,其上存储有计算机程序,其中,该计算机程序被执行时实现如前述各实施例所提供的隐私信息传输方法。
本公开实施例提供的隐私信息传输方法、装置、计算机设备及计算机可读介质,当接收到身份注册请求消息时,生成认证信息,并利用第一私钥对所述认证信息进行加密;向终端设备发送第一身份识别请求消息,所述第一身份识别请求消息携带加密后的认证信息;接收所述终端设备返回的身份识别响应消息,获取所述身份识别响应消息中的隐私信息。本公开实施例通过网络设备生成并加密认证信息,以便终端设备对该认证信息进行认证,防止伪基站获取终端设备的隐私信息,确保在终端设备首次接入或长时间关机后再开机时,终端设备和网络设备能够安全地传输隐私信息,避免隐私信息泄露,提高数据传输的安全性和可靠性。
本领域普通技术人员可以理解,上文中所公开方法中的全部或某些步骤、装置中的功能模块/单元可以被实施为软件、固件、硬件及其适当的组合。在硬件实施方式中,在以上描述中提及的功能模块/单元之间的划分不一定对应于物理组件的划分;例如,一个物理组件可以具有多个功能,或者一个功能或步骤可以由若干物理组件合作执行。某些物理组件 或所有物理组件可以被实施为由处理器,如中央处理器、数字信号处理器或微处理器执行的软件,或者被实施为硬件,或者被实施为集成电路,如专用集成电路。这样的软件可以分布在计算机可读介质上,计算机可读介质可以包括计算机存储介质(或非暂时性介质)和通信介质(或暂时性介质)。如本领域普通技术人员公知的,术语计算机存储介质包括在用于存储信息(诸如计算机可读指令、数据结构、程序模块或其他数据)的任何方法或技术中实施的易失性和非易失性、可移除和不可移除介质。计算机存储介质包括但不限于RAM、ROM、EEPROM、闪存或其他存储器技术、CD-ROM、数字多功能盘(DVD)或其他光盘存储、磁盒、磁带、磁盘存储或其他磁存储装置、或者可以用于存储期望的信息并且可以被计算机访问的任何其他的介质。此外,本领域普通技术人员公知的是,通信介质通常包含计算机可读指令、数据结构、程序模块或者诸如载波或其他传输机制之类的调制数据信号中的其他数据,并且可包括任何信息递送介质。
本文已经公开了一些实施例,并且虽然采用了具体术语,但它们仅用于并仅应当被解释为一般说明性含义,并且不用于限制的目的。在一些实例中,对本领域技术人员显而易见的是,除非另外明确指出,否则可单独使用与特定实施例相结合描述的特征、特性和/或元素,或可与其他实施例相结合描述的特征、特性和/或元件组合使用。因此,本领域技术人员将理解,在不脱离由所附的权利要求阐明的本公开的范围的情况下,可进行各种形式和细节上的改变。

Claims (12)

  1. 一种隐私信息传输方法,包括:
    当接收到身份注册请求消息时,生成认证信息,并利用第一私钥对所述认证信息进行加密,所述身份注册请求消息是终端设备通过基站发送的;
    向所述终端设备发送第一身份识别请求消息,所述第一身份识别请求消息携带加密后的认证信息;
    接收所述终端设备返回的身份识别响应消息,获取所述身份识别响应消息中的隐私信息。
  2. 如权利要求1所述的方法,其中,所述隐私信息包括加密后的隐私数据,所述的向所述终端设备发送第一身份识别请求消息的步骤之后,还包括:
    接收所述终端设备返回的身份识别应答消息,获取所述身份识别应答消息中的第二公钥;
    生成临时密钥,利用所述第二公钥对所述临时密钥加密,根据加密后的临时密钥生成第二身份识别请求消息,并向所述终端设备发送所述第二身份识别请求消息;
    所述获取所述身份识别响应消息中的隐私信息包括:获取所述身份识别响应消息中携带的加密后的隐私数据;
    所述获取所述身份识别响应消息中的隐私信息之后,还包括:利用所述临时密钥对所述加密后的隐私数据进行解密,得到隐私数据。
  3. 如权利要求1所述的方法,其中,所述隐私信息包括未加密的隐私数据。
  4. 如权利要求1-3任一项所述的方法,其中,所述认证信息包括时间戳。
  5. 一种隐私信息传输方法,包括:
    发送身份注册请求消息;
    接收网络设备发送的第一身份识别请求消息,获取所述第一身份识别请求消息中加密后的认证信息;
    利用第一公钥对所述加密后的认证信息进行解密,得到认证信息;
    当所述认证信息有效时,向所述网络设备发送身份识别响应消息,所述身份识别响应消息携带隐私信息。
  6. 如权利要求5所述的方法,其中,所述隐私信息包括加密后的隐私数据,所述的向所述网络设备发送身份识别响应消息的步骤之前,还包括:
    向所述网络设备发送身份识别应答消息,所述身份识别应答消息携带第二公钥;
    接收所述网络设备发送的第二身份识别请求消息,获取其中携带的加密后的临时密钥, 并利用第二私钥对所述加密后的临时密钥进行解密,得到临时密钥,所述加密后的临时密钥是所述网络设备在生成临时密钥之后,利用第二公钥加密得到的;
    利用所述临时密钥对隐私数据进行加密,得到加密后的隐私数据;
    所述向所述网络设备发送身份识别响应消息,包括:向所述网络设备发送携带所述加密后的隐私数据的身份识别响应消息。
  7. 如权利要求5所述的方法,其中,所述隐私信息包括未加密的隐私数据。
  8. 如权利要求5-7任一项所述的方法,其中,所述认证信息包括时间戳,所述认证信息有效包括:所述时间戳与当前时间一致。
  9. 一种网络设备,包括:
    生成模块,用于当接收到身份注册请求消息时,生成认证信息;所述身份注册请求消息是终端设备通过基站发送的;
    加密模块,用于利用第一私钥对所述认证信息进行加密;
    发送模块,用于向所述终端设备发送第一身份识别请求消息,所述第一身份识别请求消息携带加密后的认证信息;
    获取模块,用于接收所述终端设备返回的身份识别响应消息,获取所述身份识别响应消息中的隐私信息。
  10. 一种终端设备,包括:
    接收模块,用于接收网络设备发送的第一身份识别请求消息;
    获取模块,用于获取所述第一身份识别请求消息中加密后的认证信息;
    解密模块,用于利用第一公钥对所述加密后的认证信息进行解密,得到认证信息;
    发送模块,用于发送身份注册请求消息;当所述认证信息有效时,向所述网络设备发送身份识别响应消息,所述身份识别响应消息携带隐私信息。
  11. 一种计算机设备,包括:
    一个或多个处理器;
    存储装置,其中,其上存储有一个或多个程序;
    当所述一个或多个程序被所述一个或多个处理器执行时,使得所述一个或多个处理器实现如权利要求1-8任一项所述的隐私信息传输方法。
  12. 一种计算机可读介质,其上存储有计算机程序,其中,所述程序被执行时实现如权利要求1-8任一项所述的隐私信息传输方法。
PCT/CN2020/118111 2019-12-25 2020-09-27 隐私信息传输方法、装置、计算机设备及计算机可读介质 Ceased WO2021129012A1 (zh)

Priority Applications (3)

Application Number Priority Date Filing Date Title
US17/784,808 US12225373B2 (en) 2019-12-25 2020-09-27 Privacy information transmission method, apparatus, computer device and computer-readable medium
JP2022535853A JP7404540B2 (ja) 2019-12-25 2020-09-27 プライバシー情報伝送方法、装置、コンピュータ機器及びコンピュータ読み取り可能な媒体
EP20906846.9A EP4061037B1 (en) 2019-12-25 2020-09-27 Privacy information transmission methods, computer device and computer-readable medium

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN201911358121.2 2019-12-25
CN201911358121.2A CN113038459A (zh) 2019-12-25 2019-12-25 隐私信息传输方法、装置、计算机设备及计算机可读介质

Publications (1)

Publication Number Publication Date
WO2021129012A1 true WO2021129012A1 (zh) 2021-07-01

Family

ID=76458378

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2020/118111 Ceased WO2021129012A1 (zh) 2019-12-25 2020-09-27 隐私信息传输方法、装置、计算机设备及计算机可读介质

Country Status (5)

Country Link
US (1) US12225373B2 (zh)
EP (1) EP4061037B1 (zh)
JP (1) JP7404540B2 (zh)
CN (1) CN113038459A (zh)
WO (1) WO2021129012A1 (zh)

Families Citing this family (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN115529127B (zh) * 2022-09-23 2023-10-03 中科海川(北京)科技有限公司 基于sd-wan场景的设备认证方法、装置、介质、设备
CN116226812A (zh) * 2023-02-28 2023-06-06 华能信息技术有限公司 一种用于终端身份认证及数据加解密的方法及系统
CN116170228B (zh) * 2023-02-28 2026-04-10 紫金山实验室 终端标识设备的认证方法、装置、存储介质及设备
CN119232416A (zh) * 2023-06-30 2024-12-31 中兴通讯股份有限公司 身份信息的校验方法和系统、存储介质及电子装置
CN118764855B (zh) * 2024-09-04 2024-12-24 中国电信股份有限公司 识别方法、装置、设备及存储介质

Citations (6)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN1790984A (zh) * 2004-12-14 2006-06-21 中兴通讯股份有限公司 一种通信系统中用户身份保密的方法
CN105101183A (zh) * 2014-05-07 2015-11-25 中国电信股份有限公司 对移动终端上隐私内容进行保护的方法和系统
US20150358820A1 (en) * 2013-05-07 2015-12-10 Huawei Device Co., Ltd. Method for Establishing Connection Between Devices, Configuration Device, and Wireless Device
CN105636037A (zh) * 2015-06-29 2016-06-01 宇龙计算机通信科技(深圳)有限公司 认证方法、装置及电子设备
CN108718323A (zh) * 2018-06-29 2018-10-30 北京东方英卡数字信息技术有限公司 一种身份认证方法和系统
CN110062383A (zh) * 2019-04-24 2019-07-26 中国联合网络通信集团有限公司 一种认证方法、终端、认证服务器、应用服务器

Family Cites Families (36)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US5864665A (en) * 1996-08-20 1999-01-26 International Business Machines Corporation Auditing login activity in a distributed computing environment
US7039392B2 (en) * 2000-10-10 2006-05-02 Freescale Semiconductor System and method for providing device authentication in a wireless network
FI115098B (fi) * 2000-12-27 2005-02-28 Nokia Corp Todentaminen dataviestinnässä
GB2401293B (en) * 2002-01-17 2004-12-22 Toshiba Res Europ Ltd Data transmission links
US7523490B2 (en) * 2002-05-15 2009-04-21 Microsoft Corporation Session key security protocol
JP2005295408A (ja) * 2004-04-02 2005-10-20 Tepco Uquest Ltd 暗号化装置,復号化装置,暗号化復号化システム,鍵情報更新システム
US7376972B2 (en) * 2004-04-14 2008-05-20 Microsoft Corporation Session key exchange key
US7715822B2 (en) * 2005-02-04 2010-05-11 Qualcomm Incorporated Secure bootstrapping for wireless communications
GB0517592D0 (en) * 2005-08-25 2005-10-05 Vodafone Plc Data transmission
EP1873998B1 (en) * 2006-06-27 2018-09-19 Vringo Infrastructure Inc. Identifiers in a communication system
CN101141251B (zh) * 2006-09-08 2012-05-23 华为技术有限公司 通信系统中消息加密签名的方法及系统和设备
JP2008079192A (ja) * 2006-09-25 2008-04-03 Hitachi Kokusai Electric Inc 無線基地局装置
US9055107B2 (en) * 2006-12-01 2015-06-09 Microsoft Technology Licensing, Llc Authentication delegation based on re-verification of cryptographic evidence
US8150037B2 (en) * 2007-02-20 2012-04-03 Carnegie Mellon University Apparatus and method for secure, user-friendly deployment of information
CN101442407B (zh) * 2007-11-22 2011-05-04 杭州中正生物认证技术有限公司 利用生物特征进行身份认证的方法及系统
CN101286844B (zh) * 2008-05-29 2010-05-12 西安西电捷通无线网络通信有限公司 一种支持快速切换的实体双向鉴别方法
US8965338B2 (en) * 2008-06-09 2015-02-24 Apple Inc Network access control methods and apparatus
US8467532B2 (en) * 2010-01-04 2013-06-18 Tata Consultancy Services Limited System and method for secure transaction of data between a wireless communication device and a server
US20110291803A1 (en) * 2010-05-27 2011-12-01 Zeljko Bajic Rfid security and mobility architecture
US9565558B2 (en) * 2011-10-21 2017-02-07 At&T Intellectual Property I, L.P. Securing communications of a wireless access point and a mobile device
CN102882685A (zh) * 2012-09-27 2013-01-16 东莞宇龙通信科技有限公司 身份认证系统及其方法
US9100175B2 (en) * 2013-11-19 2015-08-04 M2M And Iot Technologies, Llc Embedded universal integrated circuit card supporting two-factor authentication
JP6075885B2 (ja) * 2014-02-18 2017-02-08 日本電信電話株式会社 認証システム及びオンラインサインアップ制御方法
GB2535780B (en) * 2015-02-27 2018-04-11 Ip Access Ltd Obtaining permanent identity of a User Equipment in a small cell
US10050789B2 (en) * 2015-04-24 2018-08-14 Red Hat, Inc. Kerberos preauthentication with J-PAKE
US10931644B2 (en) * 2015-06-23 2021-02-23 Telefonaktiebolaget Lm Ericsson (Publ) Methods, network nodes, mobile entity, computer programs and computer program products for protecting privacy of a mobile entity
KR102088857B1 (ko) * 2016-04-06 2020-03-13 삼성전자 주식회사 기지국 및/또는 기지국으로부터 수신된 정보의 진정성을 검증하는 시스템 및 방법
CN107592281B (zh) * 2016-07-06 2022-04-05 华为技术有限公司 一种传输数据的保护系统、方法及装置
US10516994B2 (en) * 2016-07-17 2019-12-24 Qualcomm Incorporated Authentication with privacy identity
EP3488627B1 (en) * 2016-07-25 2023-09-06 Telefonaktiebolaget LM Ericsson (PUBL) Proof-of-presence indicator
EP3624476B1 (en) * 2017-05-08 2022-07-06 LG Electronics Inc. Method for securing connection identifier of user equipment in wireless communication system and apparatus therefor
WO2018208949A1 (en) * 2017-05-09 2018-11-15 Intel IP Corporation Privacy protection and extensible authentication protocol authentication and authorization in cellular networks
WO2018231426A1 (en) * 2017-06-16 2018-12-20 Motorola Mobility Llc Rogue unit detection information
US11463875B2 (en) * 2019-04-26 2022-10-04 Qualcomm Incorporated Detection of system information modification using access stratum security mode command
WO2020247043A1 (en) * 2019-06-07 2020-12-10 Convida Wireless, Llc Apparatus, system, method, and computer-readable medium for cellular system enhancements for the support of multi-sim user equipments
US12113790B2 (en) * 2019-07-12 2024-10-08 Lg Electronics Inc. Mutual authentication and re-authentication method between wireless power transmitting device and wireless power receiving device, and wireless power transmitting device and wireless power receiving device using same

Patent Citations (6)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN1790984A (zh) * 2004-12-14 2006-06-21 中兴通讯股份有限公司 一种通信系统中用户身份保密的方法
US20150358820A1 (en) * 2013-05-07 2015-12-10 Huawei Device Co., Ltd. Method for Establishing Connection Between Devices, Configuration Device, and Wireless Device
CN105101183A (zh) * 2014-05-07 2015-11-25 中国电信股份有限公司 对移动终端上隐私内容进行保护的方法和系统
CN105636037A (zh) * 2015-06-29 2016-06-01 宇龙计算机通信科技(深圳)有限公司 认证方法、装置及电子设备
CN108718323A (zh) * 2018-06-29 2018-10-30 北京东方英卡数字信息技术有限公司 一种身份认证方法和系统
CN110062383A (zh) * 2019-04-24 2019-07-26 中国联合网络通信集团有限公司 一种认证方法、终端、认证服务器、应用服务器

Non-Patent Citations (1)

* Cited by examiner, † Cited by third party
Title
See also references of EP4061037A4 *

Also Published As

Publication number Publication date
US12225373B2 (en) 2025-02-11
EP4061037A4 (en) 2023-01-04
CN113038459A (zh) 2021-06-25
JP7404540B2 (ja) 2023-12-25
US20230023665A1 (en) 2023-01-26
JP2023506791A (ja) 2023-02-20
EP4061037B1 (en) 2025-04-30
EP4061037A1 (en) 2022-09-21

Similar Documents

Publication Publication Date Title
US9253178B2 (en) Method and apparatus for authenticating a communication device
WO2021129012A1 (zh) 隐私信息传输方法、装置、计算机设备及计算机可读介质
WO2018050081A1 (zh) 设备身份认证的方法、装置、电子设备及存储介质
CN101917710A (zh) 移动互联网加密通讯的方法、系统及相关装置
US10484350B2 (en) Privacy-preserving location corroborations
CN103533539A (zh) 虚拟sim卡参数管理方法及装置
US11962692B2 (en) Encrypting data in a pre-associated state
CN111918289B (zh) 终端接入方法、装置和服务器
CN101895881A (zh) 一种实现gba密钥的方法及终端可插拔设备
CN114189343A (zh) 互相认证的方法和装置
CN111918283A (zh) 一种物联网设备的配网方法、装置、系统及存储介质
CN114258013A (zh) 数据加密方法、设备和存储介质
CN111901795A (zh) 接入方法及核心网设备、微基站管理服务器
CN115022850A (zh) 一种d2d通信的认证方法、装置、系统、电子设备及介质
WO2019024937A1 (zh) 密钥协商方法、装置及系统
CN110536289B (zh) 密钥发放方法及其装置、移动终端、通信设备和存储介质
KR101329789B1 (ko) 모바일 디바이스의 데이터베이스 암호화 방법
WO2021082558A1 (zh) 网络切片的访问控制方法、装置及存储介质
CN111885600B (zh) 双卡终端的接入方法、终端及服务器
KR20160146090A (ko) 스마트홈 시스템에서의 통신 방법 및 그 장치
CN110072232A (zh) 一种可信执行环境用户界面的防伪造方法和系统
CN111800791B (zh) 认证方法及核心网设备、终端
CN116528230A (zh) 验证码处理方法、移动终端及可信服务系统
KR101298216B1 (ko) 복수 카테고리 인증 시스템 및 방법
CN101034979B (zh) 一种用户身份的保护方法

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 20906846

Country of ref document: EP

Kind code of ref document: A1

ENP Entry into the national phase

Ref document number: 2022535853

Country of ref document: JP

Kind code of ref document: A

ENP Entry into the national phase

Ref document number: 2020906846

Country of ref document: EP

Effective date: 20220615

NENP Non-entry into the national phase

Ref country code: DE

WWG Wipo information: grant in national office

Ref document number: 2020906846

Country of ref document: EP