Method and apparatus for establishing end-to-end security in wireless communication system
The disclosure relates to a 5G or 6G communication system for supporting a higher data transmission rate. Disclosed is a method of a first terminal in a wireless communication system including transmitting a first request message for information required for establishing security between terminals to a first entity, receiving a first response message including the information required for establishing security between terminals from the first entity in response to the first request message, generating security information for the first terminal, based on the response message, transmitting a second request message including the security information for the first terminal to a relay terminal, establishing security with the relay terminal, receiving a second response message including security information for a second terminal from the relay terminal in response to the second request message, and generating an end-to-end session key between terminals, based on the received security information for the second terminal.
1 . A method of a first terminal in a wireless communication system, the method comprising:
transmitting, to a first entity, a first request message for information required for establishing security between the first terminal and a second terminal;
in response to transmitting the first request message, receiving, from the first entity, a first response message including the information required for establishing the security between the first terminal and the second terminal;
generating, based on the first response message, first security information for the first terminal, wherein the first security information includes an identifier (ID) of the first terminal, a public key of the first terminal, and security information related to a digital signature of the first terminal;
transmitting, to a relay terminal, a second request message including the generated first security information for the first terminal;
establishing security with the relay terminal, after transmitting the second request message;
in response to transmitting the second request message, receiving, from the relay terminal, a second response message including second security information for a second terminal, after establishing the security with the relay terminal, wherein the second security information for the second terminal includes an ID of the second terminal, a public key of the second terminal, and security information related to a digital signature of the second terminal; and
generating an end-to-end session key (E2E session key) between the first terminal and the second terminal based on the received second security information for the second terminal.
2 . The method of claim 1 , wherein the security information related to the digital signature of the first terminal, the security information related to the digital signature of the second terminal, and the security information related to the digital signature of the relay terminal comprise a combination of values for verifying the digital signature of the first terminal, the digital signature of the second terminal, and the digital signature of the relay terminal.
3 . The method of claim 1 , further comprising:
transmitting, to the first entity, a message including a public key of the first terminal in case that information required for establishing the security between the first terminal and the second terminal included in a first message comprises information indicating a certificate-based approach; and
transmitting, to the first entity, a message including an ID of the first terminal and information on an expiration date of the ID of the first terminal in case that information required for establishing the security between the first terminal and the second terminal included in the first message comprises information indicating an identity-based approach.
4 . The method of claim 3 , wherein the first entity is configured to, in case that the message comprising the ID of the first terminal and the information on the expiration date of the ID of the first terminal is received and the expiration date is coming soon, newly generate a certificate for the first terminal or transmit, to the first terminal, a message comprising an indication of a conventional certificate.
5 . A method of a relay terminal in a wireless communication system, the method comprising:
receiving, from a first terminal, a first request message including first security information for the first terminal, wherein the first security information includes an identifier (ID) of the first terminal, a public key of the first terminal, and security information related to a digital signature of the first terminal;
transmitting a second request message to a second terminal based on the received first request message;
establishing security with the second terminal, after transmitting the second request message;
in response to transmitting the second request message, receiving a first response message including second security information for the second terminal, wherein the second security information for the second terminal includes an ID of the second terminal, a public key of the second terminal, and security information related to a digital signature of the second terminal;
establishing security with the first terminal after receiving the first response message; and
in response to receiving the first request message, transmitting, to the first terminal, a second response message including the second security information for the second terminal, after establishing the security with the first terminal.
6 . The method of claim 5 , wherein the security information related to a digital signature of the first terminal, the security information related to the digital signature of the second terminal, and security information related to the digital signature of the relay terminal comprise a combination of values for verifying the digital signature of the first terminal, the digital signature of the second terminal, and the digital signature of the relay terminal.
7 . The method of claim 5 , further comprising, in case that information required for establishing hop security between the first terminal and the relay terminal included in the first request message includes information indicating a certificate-based approach, transmitting, to a first entity, a message including a public key of the relay terminal; and
In case that the information required for establishing hop security between the first terminal and the relay terminal included in the first request message includes information indicating an identity-based approach, transmitting, to the first entity, a message including information on an ID of the relay terminal and an expiration date of the ID of the relay terminal.
8 . The method of claim 7 , wherein, in case that the first entity receives the message including the information on the ID of the relay terminal and the expiration date of the ID of the relay terminal, the first entity is configured to newly generate a certificate for the relay terminal or transmit, to the relay terminal, a message including an indication indicating to use the certificate in case that the ID expires soon.
9 . A first terminal in a wireless communication system, the first terminal comprising:
a transceiver; and
a controller connected to the transceiver, the controller configured to:
transmit, to a first entity, a first request message for information required for establishing security between the first terminal and a second terminal,
in response to transmitting the first request message, receive, from the first entity, a first response message including the information required for establishing the security between the first terminal and the second terminal,
generate, based on the first response message, first security information for the first terminal, wherein the first security information includes an identifier (ID) of the first terminal, a public key of the first terminal, and security information related to a digital signature of the first terminal,
transmit, to a relay terminal, a second request message including the generated first security information for the first terminal,
establish security with the relay terminal, after transmitting the second request message,
in response to transmitting the second request message, receive, from the relay terminal, a second response message including second security information for a second terminal, after establishing the security with the relay terminal, wherein the second security information for the second terminal includes n ID of the second terminal, a public key of the second terminal, and security information related to a digital signature of the second terminal, and
generate an end-to-end session key (E2E session key) between the first terminal and the second terminal based on the received second security information for the second terminal.
10 . The first terminal of claim 9 , wherein the security information related to a digital signature of the first terminal, the security information related to the digital signature of the second terminal, and the security information related to the digital signature of the relay terminal comprise a combination of values for verifying the digital signature of the first terminal, the digital signature of the second terminal, and the digital signature of the relay terminal.
11 . The first terminal of claim 9 , wherein the controller is further configured to:
transmit, to the first entity, a message including a public key of the first terminal in case that information required for establishing the security between the first terminal and the second terminal included in a first message comprises information indicating a certificate-based approach, and
transmit, to the first entity, a message including an ID of the first terminal and information on an expiration date of the ID of the first terminal in case that information required for establishing the security between the first terminal and the second terminal included in the first message comprises information indicating an identity-based approach.
12 . The first terminal of claim 11 , wherein the first entity is configured to, in case that the message comprising the ID of the first terminal and the information on the expiration date of the ID of the first terminal is received and the expiration date is coming soon, newly generate a certificate for the first terminal or transmit, to the first terminal, a message comprising an indication of a conventional certificate.
13 . A relay terminal in a wireless communication system, the relay terminal comprising:
a transceiver; and
a controller connected to the transceiver, the controller configured to:
receive, from a first terminal, a first request message including first security information for the first terminal, wherein the first security information includes an identifier (ID) of the first terminal, a public key of the first terminal, and security information related to a digital signature of the first terminal,
transmit a second request message to a second terminal based on the received first request message,
establish security with the second terminal, after transmitting the second request message,
in response to transmitting the second request message, receive a first response message including second security information for the second terminal, wherein the second security information for the second terminal includes an ID of the second terminal, a public key of the second terminal, and security information related to a digital signature of the second terminal,
establish security with the first terminal, after receiving the first response message, and
in response to receiving the first request message transmit, to the first terminal, a second response message including the second security information for the second terminal, after establishing the security with the first terminal.
14 . The relay terminal of claim 13 , wherein the security information related to a digital signature of the first terminal, the security information related to the digital signature of the second terminal, and the security information related to the digital signature of the relay terminal comprise a combination of value for verifying the digital signature of the first terminal, the digital signature of the second terminal, and the digital signature of the relay terminal.
15 . The relay terminal of claim 13 , wherein the controller is configured to:
in case that information required for establishing hop security between the first terminal and the relay terminal included in the first request message includes information indicating a certificate-based approach, transmit, to a first entity, a message including a public key of the relay terminal; and
in case that the information required for establishing hop security between the first terminal and the relay terminal included in the first request message includes information indicating an identity-based approach, transmit, to the first entity, a message including information on an ID of the relay terminal and an expiration date of the ID of the relay terminal.
16 . The relay terminal of claim 15 , wherein, in case that the first entity receives the message including the information on the ID of the relay terminal and the expiration date of the ID of the relay terminal, the first entity is configured to newly generate a certificate for the relay terminal or transmit, to the relay terminal, a message including an indication indicating to use the certificate in case that the ID expires soon.