IP Library › Granted Patent US 10,582,378
Granted Patent B2
US 10,582,378 · App. 16/520,833 · Granted Mar 3, 2020

Message protection method, user equipment, and core network device

Inventors: Jing Chen (Shanghai, CN); Li Hu (Shanghai, CN)
Assignee: HUAWEI TECHNOLOGIES CO., LTD.
H04W12/003H04L9/0643H04L9/0869H04L9/3247H04W4/14H04W12/001H04W12/04071H04W12/1008
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,582,378
App. No.
16/520,833
Granted
Mar 3, 2020
Kind
B2
Abstract

A message protection method, user equipment, and a core network device are disclosed. The method includes: sending a request message on which no security protection is performed to the core network device, where the request message includes a first random number; receiving an abnormal response message, where the abnormal response message includes a third random number and a signature; and determining, based on the third random number, the signature, and an obtained credential, whether the abnormal response message is a valid message. According to the message protection method provided in the embodiments of the disclosure, security protection can be performed on a message transmitted before a security context is established between the user equipment and the core network device, so as to improve network communication security.

Claims (55)

1. A message protection method, comprising:

sending a request message on which no security protection is performed to a core network device, wherein the request message comprises a first random number;

receiving an abnormal response message, wherein the abnormal response message comprises a third random number and a signature; and

determining, based on the third random number, the signature, and an obtained credential, whether the abnormal response message is a valid message.

2. The method according to claim 1 , wherein the determining, based on the third random number, the signature, and an obtained credential, whether the abnormal response message is a valid message comprises:

if the first random number is the same as the third random number, and signature verification succeeds, determining that the abnormal response message is a valid message, wherein that signature verification succeeds comprises: signature verification performed on the abnormal response message based on the third random number, the signature, and the credential succeeds.

3. The method according to claim 1 , wherein the abnormal response message further comprises a second random number, and the determining, based on the third random number, the signature, and an obtained credential, whether the abnormal response message is a valid message comprises:

if the first random number is the same as the third random number, and signature verification succeeds, determining that the abnormal response message is a valid message, wherein that signature verification succeeds comprises: signature verification performed on the abnormal response message based on the third random number, the second random number, the signature, and the credential succeeds.

4. The method according to claim 1 , wherein the method further comprises: determining a second hash value based on the request message; and

the determining, based on the third random number, the signature, and an obtained credential, whether the abnormal response message is a valid message comprises:

if the first random number is the same as the third random number, and signature verification succeeds, determining that the abnormal response message is a valid message, wherein that signature verification succeeds comprises: signature verification performed on the abnormal response message based on the third random number, the second hash value, the signature, and the credential succeeds.

5. The method according to claim 1 , wherein the method further comprises: determining a second hash value based on the request message, wherein

the abnormal response message further comprises a first hash value, and the first hash value is determined by the core network device based on the request message; and

the determining, based on the third random number, the signature, and an obtained credential, whether the abnormal response message is a valid message comprises:

if the first random number is the same as the third random number, the first hash value is the same as the second hash value, and signature verification succeeds, determining that the abnormal response message is a valid message, wherein that signature verification succeeds comprises: signature verification performed on the abnormal response message based on the third random number, the first hash value, the signature, and the credential succeeds.

6. The method according to claim 1 , wherein the method further comprises: determining a second hash value based on the request message, wherein

the abnormal response message further comprises a second random number; and

the determining, based on the third random number, the signature, and an obtained credential, whether the abnormal response message is a valid message comprises:

if the first random number is the same as the third random number, and signature verification succeeds, determining that the abnormal response message is a valid message, wherein that signature verification succeeds comprises: signature verification performed on the abnormal response message based on the third random number, the second random number, the second hash value, the signature, and the credential succeeds.

7. The method according to claim 1 , wherein the method further comprises: determining a second hash value based on the request message, wherein

the abnormal response message further comprises a second random number and a first hash value, and the first hash value is determined by the core network device based on the request message; and

the determining, based on the third random number, the signature, and an obtained credential, whether the abnormal response message is a valid message comprises:

if the first random number is the same as the third random number, the first hash value is the same as the second hash value, and signature verification succeeds, determining that the abnormal response message is a valid message, wherein that signature verification succeeds comprises: signature verification performed on the abnormal response message based on the third random number, the second random number, the first hash value, the signature, and the credential succeeds.

8. The method according to claim 1 , wherein the request message comprises an attach request message or a tracking area update request message.

9. The method according to claim 1 , wherein the abnormal response message comprises an attach reject message, a tracking area update reject message, or an identity request message.

10. The method according to claim 1 , wherein the abnormal response message further comprises the credential, and the credential is used to verify the signature.

11. The method according to claim 1 , wherein the method further comprises:

if the abnormal response message is an invalid message, changing an accessed access network device, and resending the request message to the core network device by using a changed access network device.

12. User equipment, comprising:

a transceiver, configured to: send a request message on which no security protection is performed to a core network device, wherein the request message comprises a first random number; and receive an abnormal response message, wherein the abnormal response message comprises a third random number and a signature; and

a processor, configured to determine, based on the third random number, the signature, and an obtained credential, whether the abnormal response message is a valid message.

13. The user equipment according to claim 12 , wherein the processor is specifically configured to:

if the first random number is the same as the third random number, and signature verification succeeds, determine that the abnormal response message is a valid message, wherein that signature verification succeeds comprises: signature verification performed on the abnormal response message based on the third random number, the signature, and the credential succeeds.

14. The user equipment according to claim 12 , wherein the abnormal response message further comprises a second random number, and the processor is specifically configured to:

if the first random number is the same as the third random number, and signature verification succeeds, determine that the abnormal response message is a valid message, wherein that signature verification succeeds comprises: signature verification performed on the abnormal response message based on the third random number, the second random number, the signature, and the credential succeeds.

15. The user equipment according to claim 12 , wherein the processor is further configured to determine a second hash value based on the request message; and

the processor is specifically configured to:

if the first random number is the same as the third random number, and signature verification succeeds, determine that the abnormal response message is a valid message, wherein that signature verification succeeds comprises: signature verification performed on the abnormal response message based on the third random number, the second hash value, the signature, and the credential succeeds.

16. The user equipment according to claim 12 , wherein the processor is further configured to determine a second hash value based on the request message, wherein

the abnormal response message further comprises a first hash value, and the first hash value is determined by the core network device based on the request message; and

the processor is specifically configured to:

if the first random number is the same as the third random number, the first hash value is the same as the second hash value, and signature verification succeeds, determine that the abnormal response message is a valid message, wherein that signature verification succeeds comprises: signature verification performed on the abnormal response message based on the third random number, the first hash value, the signature, and the credential succeeds.

17. The user equipment according to claim 12 , wherein the processor is further configured to determine a second hash value based on the request message, wherein

the abnormal response message further comprises a second random number; and

the processor is specifically configured to:

if the first random number is the same as the third random number, and signature verification succeeds, determine that the abnormal response message is a valid message, wherein that signature verification succeeds comprises: signature verification performed on the abnormal response message based on the third random number, the second random number, the second hash value, the signature, and the credential succeeds.

18. The user equipment according to claim 12 , wherein the processor is further configured to determine a second hash value based on the request message, wherein

the abnormal response message further comprises a second random number and a first hash value, and the first hash value is determined by the core network device based on the request message; and

the processor is specifically configured to:

if the first random number is the same as the third random number, the first hash value is the same as the second hash value, and signature verification succeeds, determine that the abnormal response message is a valid message, wherein that signature verification succeeds comprises: signature verification performed on the abnormal response message based on the third random number, the second random number, the first hash value, the signature, and the credential succeeds.

19. The user equipment according to claim 12 , wherein the request message comprises an attach request message or a tracking area update request message.

20. A computer program product stored in a non-transitory medium, comprising instructions which, when executed by a computer, cause the computer to:

send a request message on which no security protection is performed to a core network device, wherein the request message comprises a first random number;

receive an abnormal response message, wherein the abnormal response message comprises a third random number and a signature; and

determine, based on the third random number, the signature, and an obtained credential, whether the abnormal response message is a valid message.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 14, 2019
From: CHEN, JING; HU, LI
To: HUAWEI TECHNOLOGIES CO., LTD.
Reel/Frame 051011/0949 →
Continuity (2)
Continuation PCTCN2017072665 · Jan 25, 2017
Related Publication 20190349753A1 · Nov 14, 2019