CN111357308A - 一种安全保护的方法及装置 - Google Patents
一种安全保护的方法及装置 Download PDFInfo
- Publication number
- CN111357308A CN111357308A CN201880074395.6A CN201880074395A CN111357308A CN 111357308 A CN111357308 A CN 111357308A CN 201880074395 A CN201880074395 A CN 201880074395A CN 111357308 A CN111357308 A CN 111357308A
- Authority
- CN
- China
- Prior art keywords
- nas
- access technology
- message
- sequence number
- uplink
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Granted
Links
Images
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/04—Network architectures or network communication protocols for network security for providing a confidential data exchange among entities communicating through data packet networks
- H04L63/0428—Network architectures or network communication protocols for network security for providing a confidential data exchange among entities communicating through data packet networks wherein the data content is protected, e.g. by encrypting or encapsulating the payload
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W12/00—Security arrangements; Authentication; Protecting privacy or anonymity
- H04W12/03—Protecting confidentiality, e.g. by encryption
- H04W12/033—Protecting confidentiality, e.g. by encryption of the user plane, e.g. user's traffic
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W12/00—Security arrangements; Authentication; Protecting privacy or anonymity
- H04W12/08—Access security
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/12—Applying verification of the received information
- H04L63/123—Applying verification of the received information received data contents, e.g. message integrity
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W12/00—Security arrangements; Authentication; Protecting privacy or anonymity
- H04W12/04—Key management, e.g. using generic bootstrapping architecture [GBA]
- H04W12/043—Key management, e.g. using generic bootstrapping architecture [GBA] using a trusted network node as an anchor
- H04W12/0431—Key distribution or pre-distribution; Key agreement
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W12/00—Security arrangements; Authentication; Protecting privacy or anonymity
- H04W12/10—Integrity
- H04W12/106—Packet or message integrity
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W12/00—Security arrangements; Authentication; Protecting privacy or anonymity
- H04W12/10—Integrity
- H04W12/108—Source integrity
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W12/00—Security arrangements; Authentication; Protecting privacy or anonymity
- H04W12/12—Detection or prevention of fraud
- H04W12/121—Wireless intrusion detection systems [WIDS]; Wireless intrusion prevention systems [WIPS]
- H04W12/122—Counter-measures against attacks; Protection against rogue devices
Landscapes
- Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Computer Hardware Design (AREA)
- Computing Systems (AREA)
- General Engineering & Computer Science (AREA)
- Mobile Radio Communication Systems (AREA)
- Storage Device Security (AREA)
- Communication Control (AREA)
Abstract
本申请涉及无线通信技术领域。本申请的实施例提供一种安全保护的方法及装置,用以实现对多条NAS连接链路进行安全保护。本申请的方法包括:终端确定第一参数,第一参数用于表示传输非接入层NAS消息所使用的接入技术,其中,终端能够支持至少两种接入技术,且能够分别为至少两种接入技术中的每种接入技术维护对应的NAS序列号,然后终端根据第一参数、NAS密钥以及传输NAS消息所使用的接入技术对应的NAS序列号对NAS消息进行安全保护。本申请适用于对NAS消息进行安全保护的流程中。
Description
PCT国内申请,说明书已公开。
Claims (48)
- PCT国内申请,权利要求书已公开。
Applications Claiming Priority (3)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
CN201711148926.5A CN109803263A (zh) | 2017-11-17 | 2017-11-17 | 一种安全保护的方法及装置 |
CN2017111489265 | 2017-11-17 | ||
PCT/CN2018/112897 WO2019096002A1 (zh) | 2017-11-17 | 2018-10-31 | 一种安全保护的方法及装置 |
Publications (2)
Publication Number | Publication Date |
---|---|
CN111357308A true CN111357308A (zh) | 2020-06-30 |
CN111357308B CN111357308B (zh) | 2025-05-06 |
Family
ID=65351089
Family Applications (4)
Application Number | Title | Priority Date | Filing Date |
---|---|---|---|
CN202011569869.XA Active CN112738804B (zh) | 2017-11-17 | 2017-11-17 | 一种安全保护的方法及装置 |
CN201811088200.1A Active CN109361655B (zh) | 2017-11-17 | 2017-11-17 | 一种安全保护的方法及装置 |
CN201711148926.5A Pending CN109803263A (zh) | 2017-11-17 | 2017-11-17 | 一种安全保护的方法及装置 |
CN201880074395.6A Active CN111357308B (zh) | 2017-11-17 | 2018-10-31 | 一种安全保护的方法及装置 |
Family Applications Before (3)
Application Number | Title | Priority Date | Filing Date |
---|---|---|---|
CN202011569869.XA Active CN112738804B (zh) | 2017-11-17 | 2017-11-17 | 一种安全保护的方法及装置 |
CN201811088200.1A Active CN109361655B (zh) | 2017-11-17 | 2017-11-17 | 一种安全保护的方法及装置 |
CN201711148926.5A Pending CN109803263A (zh) | 2017-11-17 | 2017-11-17 | 一种安全保护的方法及装置 |
Country Status (11)
Country | Link |
---|---|
US (3) | US10681551B2 (zh) |
EP (3) | EP4114063B1 (zh) |
JP (1) | JP7101775B2 (zh) |
KR (1) | KR102354625B1 (zh) |
CN (4) | CN112738804B (zh) |
AU (1) | AU2018366571B2 (zh) |
BR (1) | BR112020009823B1 (zh) |
ES (1) | ES2882598T3 (zh) |
MX (1) | MX2020005132A (zh) |
SG (1) | SG11202004530SA (zh) |
WO (1) | WO2019096002A1 (zh) |
Families Citing this family (11)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN109246688B (zh) * | 2017-07-11 | 2021-02-23 | 华为技术有限公司 | 设备接入方法、设备及系统 |
CN112738804B (zh) * | 2017-11-17 | 2021-12-21 | 华为技术有限公司 | 一种安全保护的方法及装置 |
WO2019170104A1 (en) * | 2018-03-06 | 2019-09-12 | Mediatek Singapore Pte. Ltd. | Apparatuses and methods for protection of an intial non-access stratum (nas) message |
CN109862022B (zh) * | 2019-02-27 | 2021-06-18 | 中国电子科技集团公司第三十研究所 | 一种基于方向的协议新鲜性检查方法 |
CN112218285B (zh) * | 2019-07-11 | 2022-06-14 | 华为技术有限公司 | 上行用户数据传输的方法、设备及系统 |
WO2021051974A1 (zh) * | 2019-09-16 | 2021-03-25 | 华为技术有限公司 | 一种空口信息的安全保护方法及装置 |
CN113692777B (zh) * | 2019-09-30 | 2024-03-01 | Oppo广东移动通信有限公司 | 一种重定向方法及装置、终端设备、网络设备 |
CN113381966B (zh) * | 2020-03-09 | 2023-09-26 | 维沃移动通信有限公司 | 信息上报方法、信息接收方法、终端及网络侧设备 |
US12081982B2 (en) * | 2020-09-08 | 2024-09-03 | Qualcomm Incorporated | Optimization for an initial access stratum security mode command procedure |
CN113194097B (zh) * | 2021-04-30 | 2022-02-11 | 北京数盾信息科技有限公司 | 一种安全网关的数据处理方法、装置及安全网关 |
CN119729457A (zh) * | 2023-09-27 | 2025-03-28 | 大唐移动通信设备有限公司 | Nas消息的安全保护方法、装置及存储介质 |
Citations (3)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN101815296A (zh) * | 2009-02-23 | 2010-08-25 | 华为技术有限公司 | 一种进行接入认证的方法、装置及系统 |
CN103781069A (zh) * | 2012-10-19 | 2014-05-07 | 华为技术有限公司 | 一种双向认证的方法、设备及系统 |
CN109361655A (zh) * | 2017-11-17 | 2019-02-19 | 华为技术有限公司 | 一种安全保护的方法及装置 |
Family Cites Families (15)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN101309500B (zh) | 2007-05-15 | 2011-07-20 | 华为技术有限公司 | 不同无线接入技术间切换时安全协商的方法和装置 |
US8699711B2 (en) * | 2007-07-18 | 2014-04-15 | Interdigital Technology Corporation | Method and apparatus to implement security in a long term evolution wireless device |
CN101378591B (zh) | 2007-08-31 | 2010-10-27 | 华为技术有限公司 | 终端移动时安全能力协商的方法、系统及装置 |
GB2472580A (en) * | 2009-08-10 | 2011-02-16 | Nec Corp | A system to ensure that the input parameter to security and integrity keys is different for successive LTE to UMTS handovers |
US8730912B2 (en) | 2010-12-01 | 2014-05-20 | Qualcomm Incorporated | Determining a non-access stratum message count in handover |
EP4221458A1 (en) | 2010-12-03 | 2023-08-02 | InterDigital Patent Holdings, Inc. | Method and apparatus for performing multi-radio access technology carrier aggregation |
CN103002521B (zh) | 2011-09-08 | 2015-06-03 | 华为技术有限公司 | 传递上下文的方法及移动性管理实体 |
US10433161B2 (en) * | 2012-01-30 | 2019-10-01 | Telefonaktiebolaget Lm Ericsson (Publ) | Call handover between cellular communication system nodes that support different security contexts |
US9119062B2 (en) * | 2012-10-19 | 2015-08-25 | Qualcomm Incorporated | Methods and apparatus for providing additional security for communication of sensitive information |
GB2509937A (en) | 2013-01-17 | 2014-07-23 | Nec Corp | Providing security information to a mobile device in which user plane data and control plane signalling are communicated via different base stations |
CN104349317A (zh) * | 2013-07-31 | 2015-02-11 | 中兴通讯股份有限公司 | 一种移动网络的接入方法、ue、安全服务网关和系统 |
CN103607713A (zh) * | 2013-10-29 | 2014-02-26 | 小米科技有限责任公司 | 网络接入方法、装置、设备和系统 |
US10425448B2 (en) * | 2014-03-17 | 2019-09-24 | Telefonaktiebolaget Lm Ericsson (Publ) | End-to-end data protection |
EP3340690B1 (en) * | 2015-09-22 | 2019-11-13 | Huawei Technologies Co., Ltd. | Access method, device and system for user equipment (ue) |
KR102354093B1 (ko) | 2017-05-08 | 2022-01-20 | 텔레폰악티에볼라겟엘엠에릭슨(펍) | 분리된 카운트를 사용하여 다수의 nas 연결에 대한 보안을 제공하는 방법 및 관련된 네트워크 노드와 무선 터미널 |
-
2017
- 2017-11-17 CN CN202011569869.XA patent/CN112738804B/zh active Active
- 2017-11-17 CN CN201811088200.1A patent/CN109361655B/zh active Active
- 2017-11-17 CN CN201711148926.5A patent/CN109803263A/zh active Pending
-
2018
- 2018-10-31 BR BR112020009823-0A patent/BR112020009823B1/pt active IP Right Grant
- 2018-10-31 ES ES18877885T patent/ES2882598T3/es active Active
- 2018-10-31 MX MX2020005132A patent/MX2020005132A/es unknown
- 2018-10-31 EP EP22176791.6A patent/EP4114063B1/en active Active
- 2018-10-31 EP EP21162807.8A patent/EP3910977B1/en active Active
- 2018-10-31 AU AU2018366571A patent/AU2018366571B2/en active Active
- 2018-10-31 SG SG11202004530SA patent/SG11202004530SA/en unknown
- 2018-10-31 KR KR1020207017411A patent/KR102354625B1/ko active Active
- 2018-10-31 EP EP18877885.6A patent/EP3681186B1/en active Active
- 2018-10-31 JP JP2020527746A patent/JP7101775B2/ja active Active
- 2018-10-31 CN CN201880074395.6A patent/CN111357308B/zh active Active
- 2018-10-31 WO PCT/CN2018/112897 patent/WO2019096002A1/zh unknown
-
2019
- 2019-05-06 US US16/404,163 patent/US10681551B2/en active Active
-
2020
- 2020-05-14 US US16/874,306 patent/US10904764B2/en active Active
- 2020-12-31 US US17/139,235 patent/US11564100B2/en active Active
Patent Citations (4)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN101815296A (zh) * | 2009-02-23 | 2010-08-25 | 华为技术有限公司 | 一种进行接入认证的方法、装置及系统 |
CN103781069A (zh) * | 2012-10-19 | 2014-05-07 | 华为技术有限公司 | 一种双向认证的方法、设备及系统 |
CN109361655A (zh) * | 2017-11-17 | 2019-02-19 | 华为技术有限公司 | 一种安全保护的方法及装置 |
CN109803263A (zh) * | 2017-11-17 | 2019-05-24 | 华为技术有限公司 | 一种安全保护的方法及装置 |
Non-Patent Citations (1)
Title |
---|
ERICSSON: "Multiple registrations", 3GPP TSG SA WG3 (SECURITY) MEETING #88-BIS,S3-172491, 2 October 2017 (2017-10-02), pages 1 - 4 * |
Also Published As
Similar Documents
Publication | Publication Date | Title |
---|---|---|
CN111357308A (zh) | 一种安全保护的方法及装置 | |
CN106416121B (zh) | 用于签名产生和加密/解密的共模rsa密钥对 | |
CN105915502B (zh) | 利于网络加入的方法和系统 | |
CN108173644A (zh) | 数据传输加密方法、装置、存储介质、设备及服务器 | |
EP3768039B1 (en) | Key generation method, master enodeb, secondary enodeb and user equipment | |
EP1872513A1 (en) | Providing fresh session keys | |
CN114071459A (zh) | 一种rrc连接恢复方法及装置 | |
US20210250762A1 (en) | Key generation method, device, and system | |
CN103391540A (zh) | 密钥信息生成方法及系统、终端设备、接入网设备 | |
CN103581154A (zh) | 物联网系统中的鉴权方法和装置 | |
CN109756451B (zh) | 一种信息交互方法及装置 | |
CN106778285A (zh) | 用于对设备进行升级的方法、装置 | |
CN102685730A (zh) | 一种ue上下文信息发送方法及mme | |
CN101355507B (zh) | 更新跟踪区时的密钥生成方法及系统 | |
CN112400335B (zh) | 用于执行数据完整性保护的方法和计算设备 | |
CN104217171A (zh) | 一种密码破解方法、装置及系统 | |
CN114095277A (zh) | 配电网安全通信方法、安全接入设备及可读存储介质 | |
CN118694614A (zh) | 通信网络安全管理方法及系统 | |
CN107529159B (zh) | 宽带集群下行共享信道的接入层加密、解密、完整性保护方法和装置、安全实现方法 | |
CN120266432A (zh) | 在环境物联网网络中使用物理层共享安全密钥进行无线安全通信的方法及相关设备 | |
WO2019205895A1 (zh) | 寻呼方法、网络设备及终端 | |
CN108270560B (zh) | 一种密钥传输方法及装置 | |
WO2018076299A1 (zh) | 数据传输方法及装置 | |
CN106304054B (zh) | 一种lte系统中的保护数据完整性的方法及装置 | |
CN112154682A (zh) | 密钥更新方法、设备和存储介质 |
Legal Events
Date | Code | Title | Description |
---|---|---|---|
PB01 | Publication | ||
PB01 | Publication | ||
SE01 | Entry into force of request for substantive examination | ||
SE01 | Entry into force of request for substantive examination | ||
GR01 | Patent grant | ||
GR01 | Patent grant |