WO2020207156A1 - 认证方法、装置及设备 - Google Patents
认证方法、装置及设备 Download PDFInfo
- Publication number
- WO2020207156A1 WO2020207156A1 PCT/CN2020/077791 CN2020077791W WO2020207156A1 WO 2020207156 A1 WO2020207156 A1 WO 2020207156A1 CN 2020077791 W CN2020077791 W CN 2020077791W WO 2020207156 A1 WO2020207156 A1 WO 2020207156A1
- Authority
- WO
- WIPO (PCT)
- Prior art keywords
- information
- network device
- authentication
- request message
- user
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Ceased
Links
Images
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W12/00—Security arrangements; Authentication; Protecting privacy or anonymity
- H04W12/009—Security arrangements; Authentication; Protecting privacy or anonymity specially adapted for networks, e.g. wireless sensor networks, ad-hoc networks, RFID networks or cloud networks
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W12/00—Security arrangements; Authentication; Protecting privacy or anonymity
- H04W12/06—Authentication
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/04—Network architectures or network communication protocols for network security for providing a confidential data exchange among entities communicating through data packet networks
- H04L63/0428—Network architectures or network communication protocols for network security for providing a confidential data exchange among entities communicating through data packet networks wherein the data content is protected, e.g. by encrypting or encapsulating the payload
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/08—Network architectures or network communication protocols for network security for authentication of entities
- H04L63/0892—Network architectures or network communication protocols for network security for authentication of entities by using authentication-authorization-accounting [AAA] servers or protocols
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W12/00—Security arrangements; Authentication; Protecting privacy or anonymity
- H04W12/02—Protecting privacy or anonymity, e.g. protecting personally identifiable information [PII]
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W12/00—Security arrangements; Authentication; Protecting privacy or anonymity
- H04W12/03—Protecting confidentiality, e.g. by encryption
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W12/00—Security arrangements; Authentication; Protecting privacy or anonymity
- H04W12/08—Access security
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W4/00—Services specially adapted for wireless communication networks; Facilities therefor
- H04W4/12—Messaging; Mailboxes; Announcements
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W60/00—Affiliation to network, e.g. registration; Terminating affiliation with the network, e.g. de-registration
- H04W60/04—Affiliation to network, e.g. registration; Terminating affiliation with the network, e.g. de-registration using triggered events
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W8/00—Network data management
- H04W8/18—Processing of user or subscriber data, e.g. subscribed services, user preferences or user profiles; Transfer of user or subscriber data
- H04W8/20—Transfer of user or subscriber data
Definitions
- This application relates to the field of communication technology, and in particular to an authentication method, device and equipment.
- the network slice is a virtual private network. Before the terminal device accesses the network slice, the data network device needs to authenticate the identity of the user who uses the terminal device.
- the data network device may be a third-party network device, for example, the third-party network device may be a game platform.
- the terminal device can request the third-party network device to authenticate the user's identity through the core network device (device of the operator's network).
- the terminal device may send the user identity information of the user to the core network device, and the core network device requests the data network device to authenticate the user's identity according to the user identity information.
- the user's identity information is the user's private data. In the above process, the user's identity information may be leaked, resulting in poor user privacy security.
- This application provides an authentication method, device and equipment. Improve the security of user privacy.
- the embodiments of this application provide an authentication method.
- the core network device sends a user authentication request message to the data network device.
- the authentication request message is used to request the data network device to authenticate the user, and the core network device receives the data network device.
- the sent authentication response message includes the first information, and the first information is used to indicate the user identity information of the user.
- the user's DUI is invisible to other devices (core network device and access network device, or access network device), so that DUI will not leak to these devices, and it will not make DUI in the process of transmission.
- core network device and access network device or access network device
- the transmission between the terminal equipment and the access network equipment, the transmission between the access network equipment and the core network equipment, the transmission between the core network equipment and the data network equipment which improves the security of user privacy Sex.
- the authentication request message includes the first information.
- the data network device may determine the user to be authenticated according to the first information of the authentication request message terminal, and then perform identity authentication on the user to be authenticated.
- the authentication request message includes less content, which saves signaling overhead.
- the authentication request message further includes user identity information
- the user identity information is located in the container of the authentication request message
- the first information is located outside the container of the authentication request message.
- the data network device can obtain the user identity information in the container, and obtain the first information corresponding to the user identity information, and determine whether the first information corresponding to the user identity information is in the authentication request message Whether the included first information is the same, when it is determined that it is the same, the identity authentication of the user indicated by the user identity information is performed to avoid the user identity authentication error when the information in the authentication request message is maliciously changed during the data transmission process
- the problem has improved the security of authentication.
- the core network device receives the registration request message sent by the terminal device.
- the registration request message includes the first information and the user identity information.
- the user identity information Located in the container of the registration request message, the first information is located outside the container of the registration request message.
- the core network device can obtain the first information and the user identity information through the registration request message, and does not need to obtain the first information and the user identity information through additional other signaling, which saves signaling overhead.
- the core network device before the core network device sends the authentication request message to the data network device, the core network device sends a user identity request message to the terminal device; the core network device receives the user identity response message sent by the terminal device, and the user identity response The message includes the first information and user identity information.
- the core network device can obtain the first information and the user identity information through the registration request message, and does not need to obtain the first information and the user identity information through additional other signaling, which saves signaling overhead.
- the core network device obtains the identification of the terminal device, and the core network device stores the corresponding relationship between the identification of the terminal device and the first information. In this way, the core network device can determine the corresponding relationship between the user and the terminal device. Correspondingly, after the core network device receives the authentication response message, the core network device can obtain the corresponding determination according to the user indicated by the first information in the authentication response message. Terminal device, and perform corresponding processing operations on the terminal device (for example, sending a registration response message, etc.).
- the identification of the terminal device includes the terminal permanent identifier SUPI and/or the hidden terminal subscription identifier SUCI.
- the core network device sending a user authentication request message to the data network device includes: the core network device obtains the first information; the core network device determines the address information of the data network device according to the first information; the core The network device sends an authentication request message to the data network device according to the address information.
- the core network device can obtain the address information of the data network device according to the first information, so that the core network device can quickly obtain the address information of the data network device.
- the slice information is network slice selection assistance information NSSAI.
- the core network device receives a first status update request message sent by the data network device, and the first status update request message includes the first information;
- the core network device updates the status of the user corresponding to the first information according to the first status update request message
- the core network device sends a first status update response message to the data network device, where the first status update response message includes the first information.
- the data network device after the data network device updates the status of the user, the data network device sends a first status update request message to the core network device, and carries the first information in the first status update request message. In this way, the core network The device can identify the corresponding user according to the first information, and update the status of the identified user.
- the DUI of the user is invisible to the core network device during the communication with the core network device. DUI is leaked, and user privacy is protected.
- the core network device sends a second status update request message to the data network device, the second status update request message includes the first information; the core network device receives the second status update response message sent by the data network device , The second status update response message includes the first information.
- the core network device can request the data network device to update the user's status, and the information exchanged between the data network device and the core network device includes the first information, so that the core network device can identify according to the first information
- the corresponding user realizes the update operation of the user's status with the data network device.
- the user's DUI is transmitted between the core network device, the UE and the data network.
- Other devices are invisible, which avoids the leakage of DUI and protects the privacy of users.
- the core network device sends a notification message to the terminal device, the notification message includes the first information, and the notification message is used to indicate that the status of the user corresponding to the first information is updated.
- the embodiments of the present application provide an authentication method.
- the data network device receives the authentication request message of the user sent by the core network device; the data network device authenticates the user according to the authentication request message, and sends an authentication response to the core network device
- the authentication response message includes the first information, and the first information is used to indicate the user's data network user identity information user identity information.
- the user's DUI is invisible to other devices (core network device and access network device, or access network device), so that DUI will not leak to these devices, and it will not make DUI in the process of transmission.
- core network device and access network device or access network device
- the transmission between the terminal equipment and the access network equipment, the transmission between the access network equipment and the core network equipment, the transmission between the core network equipment and the data network equipment which improves the security of user privacy Sex.
- the authentication request message includes the first information.
- the data network device may determine the user to be authenticated according to the first information of the authentication request message terminal, and then perform identity authentication on the user to be authenticated.
- the authentication request message includes less content, which saves signaling overhead.
- the authentication request message further includes user identity information
- the user identity information is located in the container of the authentication request message
- the first information is located outside the container of the authentication request message.
- the data network device can obtain the user identity information in the container, and obtain the first information corresponding to the user identity information, and determine whether the first information corresponding to the user identity information is in the authentication request message Whether the included first information is the same, when it is determined that it is the same, the identity authentication of the user indicated by the user identity information is performed to avoid the user identity authentication error when the information in the authentication request message is maliciously changed during the data transmission process
- the problem has improved the security of authentication.
- the authentication request message includes the first information; the data network device can determine the user identity information according to the first information; the data network device performs identity authentication on the user according to the user identity information.
- the authentication request message includes the first information; the data network device may perform identity authentication on the user according to the first information.
- the authentication request message includes user identity information; before the data network device sends the authentication response message to the core network device, the data network device determines the first information according to the user identity information.
- the data network device sends a first status update request message to the core network device, the first status update request message includes first information, and the first status update request message is used to request the core network device to check the first status update request message.
- the status of the user indicated by the information is updated; the data network device receives the first status update response message sent by the core network device, and the first status update response message includes the first information.
- the data network device after the data network device updates the status of the user, the data network device sends a first status update request message to the core network device, and carries the first information in the first status update request message. In this way, the core network The device can identify the corresponding user according to the first information, and update the status of the identified user.
- the DUI of the user is invisible to the core network device during the communication with the core network device. DUI is leaked, and user privacy is protected.
- the data network device receives a second status update request message sent by the core network device, the second status update request message includes the first information; the data network device determines the user identity information according to the first information, and The user identity information updates the status of the user; the data network device sends a second status update response message to the core network device, and the second status update response message includes the first information.
- the core network device can request the data network device to update the user's status, and the information exchanged between the data network device and the core network device includes the first information, so that the core network device can identify according to the first information
- the corresponding user realizes the update operation of the user's status with the data network device.
- the user's DUI is transmitted between the core network device, the UE and the data network.
- Other devices are invisible, which avoids the leakage of DUI and protects the privacy of users.
- an embodiment of the present application provides an authentication device, including a sending module and a receiving module, where:
- the sending module is configured to send a user authentication request message to a data network device, where the authentication request message is used to request the data network device to perform identity authentication on the user;
- the receiving module is configured to receive an authentication response message sent by the data network device by the device, where the authentication response message includes first information, and the first information is used to indicate user identity information of the user.
- the authentication request message includes the first information.
- the authentication request message further includes the user identity information, the user identity information is located in a container of the authentication request message, and the first information is located in a container of the authentication request message. Outside.
- the receiving module is further configured to receive a registration request message sent by the terminal device before the sending module sends an authentication request message to the data network device, where the registration request message includes the The first information and the user identity information, the user identity information is located in the container of the registration request message, and the first information is located outside the container of the registration request message.
- the sending module is further configured to send a user identity request message to the terminal device before the sending module sends the authentication request message to the data network device;
- the receiving module is further configured to receive a user identity response message sent by the terminal device, where the user identity response message includes the first information and the user identity information.
- the device further includes a processing module, wherein the processing module is configured to:
- the corresponding relationship between the identifier of the terminal device and the first information is stored.
- the identifier of the terminal device includes the terminal permanent identifier SUPI and/or the hidden terminal subscription identifier SUCI.
- the processing module is further configured to obtain the first information, and determine the address information of the data network device according to the first information;
- the sending module is specifically configured to send the authentication request message to the data network device according to the address information.
- the slice information is network slice selection assistance information NSSAI.
- the receiving module is further configured to receive a first status update request message sent by the data network device, where the first status update request message includes the first information;
- the processing module is further configured to update the status of the user corresponding to the first information according to the first status update request message;
- the sending module is further configured to send a first status update response message to the data network device, where the first status update response message includes the first information.
- the sending module is further configured to send a second status update request message to the data network device, where the second status update request message includes the first information
- the receiving module is further configured to receive a second status update response message sent by the data network device, where the second status update response message includes the first information.
- the sending module is further configured to send a notification message to the terminal device, the notification message including the first information, and the notification message is used to indicate that the first information corresponds to The status of users is updated.
- an embodiment of the present application provides an authentication method, including a receiving module, a processing module, and a sending module, where:
- the receiving module is configured to receive a user authentication request message sent by a core network device
- the processing module is configured to perform identity authentication on the user according to the authentication request message
- the sending module is configured to send an authentication response message to the core network device, the authentication response message including first information, and the first information is used to indicate data network user identity information of the user.
- the authentication request message includes the first information.
- the authentication request message further includes the user identity information, the user identity information is located in a container of the authentication request message, and the first information is located in a container of the authentication request message. Outside the container.
- the authentication request message includes the first information; the processing module is specifically configured to:
- the authentication request message includes the first information; the processing module is specifically configured to:
- the data network device performs identity authentication on the user according to the first information.
- the authentication request message includes the user identity information; the processing module is further configured to: before the sending module sends the authentication response message to the core network device, according to the user The identity information determines the first information.
- the sending module is further configured to send a first status update request message to the core network device, where the first status update request message includes the first information, and the first The status update request message is used to request the core network device to update the status of the user indicated by the first information;
- the receiving module is further configured to receive a first status update response message sent by the core network device, where the first status update response message includes the first information.
- the receiving module is further configured to receive a second status update request message sent by the core network device, where the second status update request message includes the first information;
- the processing module is further configured to determine the user identity information according to the first information, and update the user status according to the user identity information;
- the sending module is further configured to send a second status update response message to the core network device, where the second status update response message includes the first information.
- an embodiment of the present application provides an authentication device, including a memory and a processor, and the processor executes program instructions in the memory to implement the authentication method described in any one of the first aspect.
- an embodiment of the present application provides an authentication device, including a memory and a processor, and the processor executes program instructions in the memory to implement the authentication method described in any one of the second aspect.
- an embodiment of the present application provides a storage medium, where the storage medium is used to store a computer program that is used to implement the authentication method described in any one of the first aspect when the computer program is executed by a computer or a processor.
- an embodiment of the present application provides a storage medium for storing a computer program, and the computer program is used to implement the authentication method described in any one of the second aspect when the computer program is executed by a computer or a processor.
- the core network device sends the user’s authentication request message to the data network device, and the data network device can check the user’s identity Perform authentication and send an authentication response message to the core network device.
- the authentication response message includes first information.
- the first information may indicate the user's DUI so that the core network device can determine the identity authentication result of the user according to the authentication response message.
- the user's DUI is invisible to other devices (core network device and access network device, or access network device), so that DUI will not leak to these devices, and it will not make DUI in the process of transmission. (For example, the transmission between the terminal equipment and the access network equipment, the transmission between the access network equipment and the core network equipment, the transmission between the core network equipment and the data network equipment), which improves the security of user privacy Sex.
- Figure 1A is a 5G network architecture diagram provided by an embodiment of the application.
- FIG. 1B is a schematic diagram of the authentication architecture provided by an embodiment of the application.
- FIG. 2 is a schematic flowchart of an authentication method provided by an embodiment of the application
- FIG. 3 is a schematic flowchart of another authentication method provided by an embodiment of the application.
- FIG. 5 is a schematic flowchart of yet another authentication method provided by an embodiment of this application.
- FIG. 6 is a schematic flowchart of another authentication method provided by an embodiment of this application.
- FIG. 7 is a schematic flowchart of yet another authentication method provided by an embodiment of the application.
- FIG. 8 is a schematic structural diagram of an authentication device provided by an embodiment of this application.
- FIG. 9 is a schematic structural diagram of another authentication device provided by an embodiment of this application.
- FIG. 10 is a schematic structural diagram of another authentication device provided by an embodiment of this application.
- FIG. 11 is a schematic diagram of the hardware structure of an authentication device provided by an embodiment of the application.
- FIG. 12 is a schematic diagram of the hardware structure of another authentication device provided by an embodiment of the application.
- the operator network may also be referred to as a mobile communication network, and is mainly a network through which mobile network operators (mobile network operators, MNOs) provide users with mobile broadband access services.
- the operator network described in the embodiment of this application may specifically be a network that meets the requirements of the 3rd generation partnership project (3rd generation partnership project, 3GPP) standard, referred to as the 3GPP network.
- 3GPP networks are operated by operators, including but not limited to 5G networks, 4G networks, 3rd-Generation (3G) networks and second-generation wireless telephone technology (2-Generation wireless telephone technology, 2G) Network etc.
- 3G networks 3rd-Generation (3G) networks
- 2G second-generation wireless telephone technology
- next-generation network ie, 5G network
- 5G network has also made network architecture adjustments relative to 4G networks.
- the 5G network splits the mobility management entity (MME) in the 4G network, and splits it into access and mobility management functions (AMF) and session management functions (session management). function, SMF) and other network elements.
- MME mobility management entity
- AMF access and mobility management functions
- SMF session management functions
- the 3GPP standardization process also defines a 5G network architecture based on a service-oriented architecture, as shown in Figure 1A.
- Fig. 1A is a 5G network architecture diagram provided by an embodiment of the application.
- the 5G network architecture may include terminal equipment, data network (DN), and operator network.
- DN data network
- operator network operator network
- the operator's network may include network exposure function (NEF) network elements, network storage function (network function repository function, NRF) network elements, policy control function (PCF) network elements, and unified data management (unified data management, UDM) network elements, application function (AF) network elements, authentication server function (authentication server function, AUSF) network elements, access and mobility management function (access and mobility management function, AMF) Network element, session management function (SMF) network element, (radio) access network ((radio) access network, (R)AN), user plane function (UPF) network element, etc.
- NEF network exposure function
- NRF network storage function repository function
- PCF policy control function
- UDM unified data management
- AF application function
- authentication server function authentication server function
- AUSF access and mobility management function
- AMF Access and mobility management function
- SMF session management function
- R radio access network
- R user plane function
- UPF user plane function
- the terminal device also referred to as user equipment (UE) shown in the embodiment of the present application is a device with a wireless transceiver function.
- Terminal devices can be deployed on land, including indoor or outdoor, handheld or vehicle-mounted.
- Terminal equipment can also be deployed on the water (such as ships, etc.), and can also be deployed in the air (such as airplanes, balloons, satellites, etc.).
- the terminal may be a mobile phone (mobile phone), a tablet computer (pad), a computer with wireless transceiver function, a virtual reality (VR) terminal, an augmented reality (AR) terminal, and an industrial control (industrial control) Wireless terminals in, self-driving (self-driving) wireless terminals, remote medical (remote medical) wireless terminals, smart grid (smart grid) wireless terminals, transportation safety (transportation safety) wireless terminals , Wireless terminals in smart cities, wireless terminals in smart homes, etc.
- the above-mentioned terminal equipment can establish a connection with the operator's network through an interface (such as N1, etc.) provided by the operator's network, and use services such as data and/or voice provided by the operator's network.
- the terminal device can also access the DN through the operator's network, and use the operator's service deployed on the DN and/or the service provided by a third party.
- the aforementioned third party may be a service party other than the operator's network and terminal equipment, and may provide other services such as data and/or voice for the terminal equipment.
- the specific form of expression of the aforementioned third party can be determined according to actual application scenarios, and is not limited here.
- the RAN is a sub-network of an operator's network, and an implementation system between service nodes and terminal equipment in the operator's network.
- the terminal device To access the operator's network, the terminal device first passes through the RAN, and then can be connected to the service node of the operator's network through the RAN.
- the RAN equipment in this application is a type of equipment that provides wireless communication functions for terminal equipment.
- the access network equipment includes but is not limited to: next generation nodeB (gNB) and evolved node B (evolved node) in 5G.
- B eNB
- radio network controller RNC
- node B node B
- BSC base station controller
- BTS base transceiver station
- home base station Form example, home evolved nodeB, or home node B, HNB
- BBU baseband unit
- TRP transmission point
- TP transmission point
- mobile switching center etc.
- the AMF network element is a control plane network element provided by the operator's network. It is responsible for the access control and mobility management of terminal equipment accessing the operator's network. For example, it includes functions such as mobile status management, allocation of temporary user identities, authentication and authorization of users, etc. .
- the SMF network element is a control plane network element provided by the operator's network, and is responsible for managing the protocol data unit (protocol data unit, PDU) session of the terminal device.
- a PDU session is a channel used to transmit PDUs, and terminal devices need to transmit PDUs to each other through the PDU session and DN.
- the PDU session is established, maintained, and deleted by the SMF network element.
- SMF network elements include session management (such as session establishment, modification and release, including tunnel maintenance between UPF and AN), UPF network element selection and control, service and session continuity (SSC) mode selection, Session-related functions such as roaming.
- session management such as session establishment, modification and release, including tunnel maintenance between UPF and AN
- UPF network element selection and control including tunnel maintenance between UPF and AN
- SSC service and session continuity
- the UPF network element is a gateway provided by the operator and a gateway for the communication between the operator's network and the DN.
- UPF network elements include user plane-related functions such as packet routing and transmission, packet inspection, service usage reporting, quality of service (QoS) processing, lawful monitoring, uplink packet inspection, and downlink packet storage.
- QoS quality of service
- DN can also be called packet data network (packet data network, PDN), which is a network located outside the operator's network.
- the operator's network can be connected to multiple DNs, and multiple services can be deployed on the DN to provide data for terminal devices. And/or voice services.
- DN is the private network of a smart factory.
- the sensors installed in the workshop of the smart factory can be terminal devices.
- the control server of the sensor is deployed in the DN, and the control server can provide services for the sensors.
- the sensor can communicate with the control server, obtain instructions from the control server, and transmit the collected sensor data to the control server according to the instructions.
- a DN is an internal office network of a company.
- the mobile phones or computers of employees of the company can be terminal devices, and the mobile phones or computers of employees can access information and data resources on the company's internal office network.
- UDM network element is a control plane network element provided by the operator, responsible for storing the subscriber permanent identifier (SUPI), credential, security context, and subscription data of subscribers in the operator’s network And other information.
- SUPI will be encrypted first during transmission, and the encrypted SUPI is called a hidden user subscription identifier (SUCI).
- the information stored in UDM network elements can be used for authentication and authorization of terminal equipment accessing the operator's network.
- the contracted users of the above-mentioned operator's network may specifically be users who use the services provided by the operator's network, such as users who use China Telecom's mobile phone core card, or users who use China Mobile's mobile phone core card.
- the permanent contract identifier SUPI of the aforementioned subscriber may be the number of the mobile phone core card, etc.
- the credential and security context of the aforementioned subscriber may be a small file stored such as the encryption key of the mobile phone core card or information related to the encryption of the mobile phone core card for authentication and/or authorization.
- the aforementioned security context may be data (cookie) or token (token) stored on the user's local terminal (for example, mobile phone).
- the contract data of the aforementioned subscriber may be the supporting service of the mobile phone core card, such as the data package of the mobile phone core card or the use of the network. It should be noted that permanent identifiers, credentials, security contexts, authentication data (cookies), and tokens are equivalent to information related to authentication and authorization.
- the AUSF network element is a control plane network element provided by the operator, and is usually used for first-level authentication, that is, the authentication between the terminal device (subscriber) and the operator's network. After the AUSF network element receives the authentication request initiated by the subscriber, it can authenticate and/or authorize the subscriber through the authentication information and/or authorization information stored in the UDM network element, or generate the authentication and/or authorization of the subscriber through the UDM network element. Or authorization information. The AUSF network element can feed back authentication information and/or authorization information to the subscriber.
- NEF network elements are control plane network elements provided by operators. NEF network elements open the external interface of the operator's network to third parties in a safe manner. When the SMF network element needs to communicate with a third-party network element, the NEF network element can serve as a relay for the communication between the SMF network element and the third-party network element. When the NEF network element is used as a relay, it can be used as the translation of the identification information of the subscriber and the translation of the identification information of the third-party network element. For example, when NEF sends the SUPI of the subscriber from the operator network to the third party, it can translate the SUPI into its corresponding external identity (identity, ID). Conversely, when the NEF network element sends the external ID (third-party network element ID) to the operator's network, it can be translated into SUPI.
- ID external identity
- the PCF network element is a control plane function provided by the operator to provide the SMF network element with a PDU session strategy.
- Policies can include charging-related policies, QoS-related policies, and authorization-related policies.
- Network slice selection function (Network Slice Selection Function, NSSF) network elements (not shown in the figure) are responsible for determining network slice instances, selecting AMF network elements, and so on.
- NSSF Network Slice Selection Function
- Nnef, Nausf, Nnrf, Npcf, Nudm, Naf, Namf, Nsmf, N1, N2, N3, N4, and N6 are interface serial numbers.
- the meaning of these interface serial numbers can refer to the meaning defined in the 3GPP standard protocol, which is not limited here.
- the mobility management network element in this application may be the AMF network element shown in FIG. 1A, or may be a network element having the function of the aforementioned AMF network element in a future communication system.
- the mobility management network element in this application may also be a mobility management entity (MME) in long term evolution (LTE).
- MME mobility management entity
- the mobility management network element As an AMF network element as an example.
- the AMF network element is referred to as AMF for short, and the terminal device is referred to as UE. That is, the AMF described later in this application can be replaced with a mobility management network element, and the UE can be replaced with a terminal device.
- 3GPP emphasizes that network slices do not affect each other. For example, a large number of sudden meter reading services should not affect normal mobile broadband services.
- 3GPP In order to meet diverse needs and isolation between slices, relatively independent management and operation and maintenance between businesses are required, and tailor-made business functions and analysis capabilities are provided. Instances of different types of services are deployed on different network slices, and different instances of the same service type can also be deployed on different network slices.
- the "slice” in this application may also be referred to as “network slicing” or “network slicing instance”, and the three have the same meaning, which are explained here in a unified manner and will not be repeated in the following.
- the slice in the 5G network is a virtual private network, which is composed of a set of network functions and sub-networks.
- the RAN, AMF, SMF, and UPF in Figure 1A can form a slice.
- Each network function in Fig. 1A only schematically shows one, but in actual network deployment, there may be multiple, tens or hundreds of each network function or sub-network.
- Many network slices can be deployed in an operator's network, and each slice can have different performance to meet the needs of different applications and different vertical industries. Operators can tailor a slice according to the needs of customers in different vertical industries. Operators can also allow some industry customers to enjoy greater autonomy and participate in part of the management and control functions of slicing.
- slice-level authentication is a network control function participated by industry customers, that is, authentication and authorization of end users to access slices.
- the selection process of the network slice will be triggered.
- the slice selection process depends on the user's subscription data, local configuration information, roaming agreement, operator's strategy, and so on. In the selection process of the network slice, the above parameters need to be considered comprehensively to select the best slice type for the UE.
- the UE may provide the requested network slice to the core network for the core network to select a network slice instance for the UE.
- the network slice requested by the UE may be represented by a requested network slice set, or may also be represented as requested network slice selection assistance information (requested NSSAI).
- the requested NSSAI is composed of one or more single network slice selection assistance information (S-NSSAI).
- S-NSSAI single network slice selection assistance information
- Each S-NSSAI is used to identify a network slice type, which can also be understood as S- NSSAI is used to identify network slices, or can be understood as S-NSSAI is identification information of network slices.
- S-NSSAI is identification information of network slices.
- the core network element (such as AMF or NSSF) comprehensively judges based on the UE's subscription data, the UE's requested NSSAI, roaming agreement, and local configuration information, and selects the set of network slices that the UE is allowed to access.
- the set of network slices allowed to be accessed can be represented by allowed NSSAI, and the S-NSSAI included in the allowed NSSAI are all S-NSSAIs allowed to be accessed by the current operator network.
- the UE Before accessing the network or network slice, the UE needs to perform mutual authentication with the network slice and obtain authorization from the network.
- the authentication and authorization of the UE by the network is directly performed by the operator network.
- This type of authentication and authorization method is called Primary Authentication.
- DNs outside of the operator's network such as DNs that serve vertical industries
- a commercial company provides a game platform to provide game players with game services through the operator's network.
- the operator's network needs to authenticate and authorize the UE, that is, level 1 authentication.
- the game player is a customer of a commercial company, and the commercial company also needs to authenticate and authorize game players. If this authentication is based on network slicing, or its granularity is based on slices, the authentication can be It is called slice authentication (slice authentication) or secondary authentication (secondary authentication), or slice-specific secondary authentication (slice-specific secondary authentication).
- first-level authentication it is for the authentication between the UE (or a certain user using the UE) and the network (operator network or third-party network).
- the first-level authentication it refers to the authentication between the UE and the operator network.
- the operator network performs the first-level authentication on the UE during the registration process of the UE. If the first-level authentication is passed, the security context of the UE can be established .
- secondary authentication it refers to the authentication between the UE (or the user using the UE) and the network outside the operator's network (that is, the third-party network), and the third-party network will notify the operator of the result of the secondary authentication Provider network so that the operator’s network can authorize or deny the UE to access the operator’s network that serves the third-party network.
- the second-level authentication can also be referred to as the second-level authentication of the slice, or the slice authentication, or the identity authentication of the user (user who uses the UE), which actually means: UE (or The second level authentication performed between the user using the UE and the third-party network will determine whether the operator network authorizes the UE to access the slice.
- FIG. 1B is a schematic diagram of an authentication architecture provided by an embodiment of the application. Please refer to Figure 1B, including terminal equipment, core network equipment and data network equipment.
- the terminal device requests the data network device to perform secondary authentication (identify the user) through the core network device.
- the message transmitted between the terminal device and the core network device and between the core network device and the data network device includes
- the information indicating the user identity information is the first information, and the first information does not include the privacy information in the user identity information.
- the first information does not include the user name in the user identity information, which can avoid the leakage of user identity information. Improve the security of authentication.
- the core network device involved in the embodiment of the present application may be an AMF, a proxy server, or a proxy authentication function network.
- the data network equipment may be an authentication, authorization, and accounting (Authentication, Authorization, Accounting, AAA) server, etc.
- the user identity information involved in the embodiments of this application is used to identify the identity of the user.
- the user involved in this application is different from the user equipment (UE).
- the user may refer to an individual (such as a person or through a UE) who uses the user equipment (UE). Other devices connected to the network).
- the user identity information may be data network user identity (DUI).
- the user identity information is DUI as an example for description.
- FIG. 2 is a schematic flowchart of an authentication method provided by an embodiment of the application. See Figure 2.
- the method can include:
- the core network device sends a user's authentication request (slice authentication request) message to the data network device, where the authentication request message is used to request the data network device to authenticate the user.
- a user's authentication request slice authentication request
- the authentication request message may include at least one of the following information: the first information of the user or the DUI of the user.
- the first information may indicate the DUI, that is, there is a correspondence between the first information and the DUI.
- the first information and the DUI may have a one-to-one correspondence, or a one-to-many, many-to-one, or many-to-many relationship.
- the first information may be information obtained after privacy protection processing (for example, randomization processing, number processing, mapping processing, encryption processing, etc.) is performed on user privacy information in the DUI.
- privacy protection processing for example, randomization processing, number processing, mapping processing, encryption processing, etc.
- the first information obtained in this way is called data network user conceived identity information (DUC).
- DUC data network user conceived identity information
- the user privacy information in the DUI may be the user name.
- the first information may also be an identifier of the terminal device.
- the identification of the terminal device may also be referred to as a terminal identifier (or an identifier of the UE).
- the identification of the terminal device may be a non-confidential subscription identifier (generic public subscription identifier, GPSI).
- the DUI includes routing information, which is used to indicate the address of the data network device.
- the core network device may forward information (for example, authentication request information, or other information sent to the data network device) to the data network device according to the routing information.
- the routing information may be private information, or it may not be private information. If the routing information is private information, privacy protection processing (for example, randomization, numbering, mapping, encryption, etc.) can be performed on the routing information. In the actual application process, the first information corresponding to the DUI can be updated.
- the DUI is located in a container of the authentication request message.
- the container may be an EAP message container used for extensible authentication protocol (EAP) authentication.
- EAP extensible authentication protocol
- the core network device may only transparently transmit the information in the container without processing the information in the container, that is, the information in the container is invisible to the core network device. In this way, for the core network device that transparently transmits information, since the DUI is not interpreted, the DUI can be prevented from leaking to the core network device, and the DUI can also be prevented from leaking to the core network device in the process of transmitting the DUI.
- the first information may be located in the container in the authentication request message or outside the container. Since the first information has undergone privacy protection processing, even if the first information is visible to other devices (for example, core network equipment, air interface, or core network eavesdropping equipment), it will not cause the leakage of DUI privacy.
- the authentication request message may also include an identifier of the UE, such as SUPI or GPSI, which is used to indicate the UE through which the user performs user authentication.
- an identifier of the UE such as SUPI or GPSI, which is used to indicate the UE through which the user performs user authentication.
- the user can be identified by the UE, and on the other hand, authorization can also be performed by the binding relationship between the UE and the user.
- the core network device may receive a registration request (registration request) message sent by the terminal device, and when it is determined according to the registration request message that the user needs to be authenticated, the embodiment shown in FIG. 2 is executed.
- registration request registration request
- the data network device performs identity authentication on the user according to the authentication request message.
- the data network device can perform identity authentication on the user according to the DUI.
- the data network device may determine the DUI corresponding to the first information according to the correspondence between the first information and the DUI, and perform identity authentication on the user according to the determined DUI.
- the data network device may determine the DUI corresponding to the first information according to the corresponding relationship between the first information and the DUI, and determine the DUI and the authentication request message obtained Whether the DUI is the same, if so, the user will be authenticated according to the DUI. In this way, it is possible to avoid the problem that the authentication request message is tampered with during the transmission process, which causes incorrect identity authentication of the user.
- the data network device may also authenticate the corresponding relationship between the identifier of the UE and the user. For example, if the authentication policy only allows the user to use a specific UE to access, when the identifier of the UE included in the authentication request message does not correspond to the DUI, the identity authentication of the user fails.
- the process of performing identity authentication on a user according to the DUI will vary depending on the specific authentication protocol used.
- the authentication request message is the beginning of the authentication process.
- the next step can include authentication method negotiation, key algorithm negotiation, two-way authentication authorization and other steps.
- Each step requires corresponding actions between UE, core network, and data network equipment.
- the specific process can refer to the existing process, which will not be repeated here.
- the data network device sends an authentication response message to the core network device.
- the authentication response message may be an authentication success response message or an authentication failure response message.
- the data network device successfully authenticates the user's identity, the data network device sends an authentication success response message to the core network device.
- the data network device fails to authenticate the user's identity, the data network device sends an authentication failure response message to the core network device.
- the authentication response message includes the first information.
- the authentication response message may also include DUI.
- the DUI can be located in a container of the authentication response message to avoid leakage of the DUI.
- the core network device may determine the authentication result (for example, authentication success or authentication failure) of the user indicated by the DUC by the data network device.
- the DUI will not be leaked to the core network equipment and the access network equipment, nor will the DUI be in the transmission process (for example, terminal equipment). Leakage occurs in the transmission between the access network equipment, the transmission between the access network equipment and the core network equipment, and the transmission between the core network equipment and the data network equipment.
- the core network device may obtain the DUI of the user according to the identification of the terminal device, and determine the authentication result of the user indicated by the DUI (for example, authentication success or authentication failure).
- the DUI will not leak to the access network device, and it will not cause the DUI to be transmitted during the transmission (for example, the transmission between the terminal device and the access network device).
- the core network device may allow the user (or the UE used by the user) corresponding to the first information to access the corresponding slice according to the first information in the authentication response message. Or deny the user (or UE used by the user) corresponding to the first information to access the corresponding slice.
- the authentication response message is an authentication success response message
- the core network device allows the user (or the UE used by the user) corresponding to the first information to access the corresponding slice.
- the core network device rejects the user (or the UE used by the user) corresponding to the first information to access the corresponding slice.
- the core network device when the user needs to be authenticated (secondary authentication), the core network device sends the user's authentication request message to the data network device, and the data network device can authenticate the user's identity, and An authentication response message is sent to the core network device, and the authentication response message includes first information.
- the first information may indicate the user's DUI so that the core network device can determine the identity authentication result of the user according to the authentication response message.
- the user's DUI is invisible to other devices (core network device and access network device, or access network device), so that DUI will not leak to these devices, and it will not make DUI in the process of transmission. (For example, the transmission between the terminal equipment and the access network equipment, the transmission between the access network equipment and the core network equipment, the transmission between the core network equipment and the data network equipment), which improves the security of user privacy Sex.
- FIG. 3 is a schematic flowchart of another authentication method provided by an embodiment of the application. See Figure 3.
- the method can include:
- the terminal device sends a registration request message to the core network device.
- the registration request message includes the first information and/or DUI.
- the DUI is located in a container of the registration request message.
- the registration request message includes the first information
- the first information is located inside or outside the container of the registration request message.
- the registration request message may also include the identification and slice information of the terminal device.
- the identification of the terminal device may include SUPI and/or SUCI.
- the slice information can be NSSAI.
- the identification and slice information of the terminal device are used to perform primary authentication on the terminal device.
- the content (one or more of the first information, DUI, terminal device identification, and slice information) included in the registration request message may be processed information.
- the content in the registration request message may be encrypted.
- the registration request message is a part of a NAS (Non Access Stratum) message and is encrypted by a NAS key.
- the terminal device may store the corresponding relationship between the first information and the DUI. Accordingly, the terminal device may determine the corresponding first information according to the DUI, and carry the first information in the registration request message.
- the core network equipment performs first-level authentication on the terminal equipment.
- S302 is an optional step. That is, after S301 is executed, S302 may be executed, or S302 may not be executed.
- the core network device may perform primary authentication on the terminal device according to the identification and slice information of the terminal device, and after the core network device passes the primary authentication of the terminal device, the terminal device may be authorized.
- the core network device determines that the user needs to perform secondary authentication, the core network device obtains address information of the data network device.
- the core network device may determine whether the user needs to perform secondary authentication through the following feasible implementations: the core network device obtains the user (the user indicated by the first information and/or the DUI) and/or the subscription data corresponding to the UE , And determine whether the user purchases the corresponding service (the service provided by the requested slice) according to the contract data, if yes, determine that the user needs to be authenticated at the second level, if not, then determine that the user does not need to be authenticated at the second level .
- SUPI is included in the registration request message
- the UE subscription data corresponding to SUPI can be obtained in the database according to SUPI, and the subscription data may also include the subscription data corresponding to the user.
- S303 will be executed after the core network device has passed the primary authentication on the terminal device. If the core network device fails to perform the first level authentication on the terminal device, the core network device may not perform S303-S304.
- the core network device may obtain the address information of the data network device through the following feasible implementation methods: the core network device obtains at least one of the first information, DUI, or slice information; the core network device obtains at least one of the first information, DUI, or slice information; At least one of the slice information determines the address information of the data network device.
- the address information of the data network device may be the domain name, internet protocol (IP) address, media access control (MAC) address, etc. of the data network device.
- the core network device can obtain the DUI.
- the core network device can be equipped to obtain the container
- the DUI functions so that the core network device can obtain the address information of the data network device according to the DUI.
- the DUI is not safe for the core network device, that is, the DUI obtained by the core network device may leak DUI, and the core network device cannot obtain the DUI.
- the core network device may not have the function of obtaining the DUI in the container. That is, the core network device cannot obtain the DUI in the container, thereby making the DUI invisible to the core network device.
- the first information may include address information of the data network device, and correspondingly, the core network device may obtain the address information of the data network device in the first information.
- the corresponding relationship between the first information and the data network device may also be stored, and correspondingly, the address information of the data network device may be obtained according to the first information and the corresponding relationship.
- the DUI may include the address information of the data network device.
- the core network device can obtain the DUI, the core network device can obtain the address information of the data network device in the DUI.
- the address information of the data network device can be obtained according to the slice information and the correspondence relationship.
- the address information obtained according to the first information and/or DUI may be intersected with the address information obtained according to the slice information, and Determine the address information in the intersection as the address information of the data network device.
- the core network device may also store the correspondence between the first information and the identification of the terminal device.
- the core network device may store the correspondence between the first information and the SUPI, or store the correspondence between the first information and the non-confidential subscription identifier (generic public subscription identifier, GPSI).
- the core network device can determine the corresponding terminal device according to the first information, and can also determine the first information according to the identification of the terminal device.
- the core network device may also store the corresponding relationship between the DUI and the identification of the terminal device.
- the core network device sends an authentication request message to the data network device according to the address information of the data network device.
- the authentication request message may include at least one of the following information: the first information of the user or the DUI of the user.
- the core network device encapsulates the container in the registration request message in the authentication request message when sending the authentication request message.
- the data network device obtains the user's DUI in the authentication request message.
- the corresponding relationship between the DUI and the first information is stored in the data network device.
- the data network device obtains the DUI in the container of the authentication request message.
- the data network device may obtain the DUI corresponding to the first information according to the corresponding relationship between the first information and the DUI.
- the data network device can obtain the DUI corresponding to the first information according to the correspondence between the first information and the DUI, and obtain the DUI in the container of the authentication request message, and determine the first information Whether the corresponding DUI is the same as the DUI obtained in the authentication request message, if so, the DUI corresponding to the first information or the DUI in the authentication request message is determined as the user's DUI.
- the data network device authenticates the user according to the user's DUI.
- the data network device may determine the corresponding user according to the user's DUI, and perform identity authentication on the determined user.
- the data network device sends an authentication response message to the core network device.
- the authentication response message includes the first information.
- the authentication response message may also include DUI.
- the DUI can be located in a container of the authentication response message to avoid leakage of the DUI.
- the data network device when the data network device successfully authenticates the user's identity, the data network device sends an authentication success response message to the core network device.
- the data network device fails to authenticate the user's identity, the data network device sends an authentication failure response message to the core network device.
- the core network device sends a registration response message to the terminal device.
- the core network device may determine the authentication result (for example, authentication success or authentication failure) of the user indicated by the DUC by the data network device.
- the DUI will not be leaked to the core network equipment and the access network equipment, nor will the DUI be in the transmission process (for example, terminal equipment). Leakage occurs in the transmission between the access network equipment, the transmission between the access network equipment and the core network equipment, and the transmission between the core network equipment and the data network equipment.
- the core network device may be based on the authentication result of the user indicated by the identification of the terminal device (for example, authentication success or authentication failure).
- the access network device cannot obtain the DUI, the DUI will not leak to the access network device, and it will not cause the DUI to be transmitted during the transmission (for example, the transmission between the terminal device and the access network device).
- the transmission between the access network equipment and the core network equipment, the transmission between the core network equipment and the data network equipment) leaks.
- the registration response message is a registration success response message.
- the registration response message is a registration failure response message.
- the core network device may store the first information after receiving the registration request message.
- the data network device receives the authentication response message, it can determine whether the stored first information is the same as the first information included in the authentication response message. If so, the core network device sends a registration success response message to the terminal device.
- the core network device sends the user authentication request message to the data network device, and the data network device can The user’s identity is authenticated, and an authentication response message is sent to the core network device.
- the authentication response message includes first information.
- the first information can indicate the user’s DUI so that the core network device can determine the identity authentication of the user according to the authentication response message. result.
- the user's DUI is invisible to other devices (core network device and access network device, or access network device), so that DUI will not leak these devices, nor will DUI be in the process of transmission. (For example, the transmission between the terminal equipment and the access network equipment, the transmission between the access network equipment and the core network equipment, the transmission between the core network equipment and the data network equipment), which improves the security of user privacy Sex.
- FIG. 4 is a schematic flowchart of another authentication method provided by an embodiment of the application. Referring to Figure 4, the method may include:
- the terminal device sends a registration request message to the core network device.
- the registration request message includes the identification and slice information of the terminal device.
- the identification of the terminal device may include SUPI and/or SUCI.
- the slice information can be NSSAI.
- the identification and slice information of the terminal device are used to perform primary authentication on the terminal device.
- the core network equipment performs first-level authentication on the terminal equipment.
- the core network device determines that the user needs to perform secondary authentication, the core network device sends a user identity request (ID request) message to the terminal device.
- ID request user identity request
- the user identity request message is used to request the user's identity information.
- S404 The terminal device sends a user identity response (ID response) message to the core network device.
- ID response user identity response
- the user identity response message includes the first information and/or DUI.
- the DUI is located in the container of the user identity response message.
- the user identity response message includes the first information
- the first information is located inside or outside the container of the user identity response message.
- the user identity response message includes the first information and/or the DUI may be processed information.
- the first information and /DUI may be encrypted.
- the first information and/or DUI may be encrypted by a non-access stratum (NAS) key.
- NAS non-access stratum
- the corresponding relationship between the first information and the DUI is stored in the terminal device.
- the core network device obtains address information of the data network device according to the user identity response message.
- the process of obtaining the address information of the data network device by the core network device may refer to the process of obtaining the address information of the data network device in S303, which will not be repeated here.
- the core network device sends an authentication request message to the data network device according to the address information of the data network device.
- the authentication request message may include at least one of the following information: the first information of the user or the DUI of the user.
- it may also include the identifier of the UE, such as GPSI
- the data network device obtains the DUI of the user in the authentication request message.
- S408 The data network device authenticates the user according to the user's DUI.
- the data network device sends an authentication response message to the core network device.
- the authentication response message includes the first information.
- the authentication response message may also include DUI.
- the core network device sends a registration response message to the terminal device.
- execution process of S406-S410 can refer to the execution process of S304-S308, which will not be repeated here.
- the core network device sends the user authentication request message to the data network device, and the data network device can The user’s identity is authenticated, and an authentication response message is sent to the core network device.
- the authentication response message includes first information.
- the first information can indicate the user’s DUI so that the core network device can determine the identity authentication of the user according to the authentication response message. result.
- the user's DUI is invisible to other devices (core network device and access network device, or access network device), so that DUI will not leak these devices, nor will DUI be in the process of transmission. (For example, the transmission between the terminal equipment and the access network equipment, the transmission between the access network equipment and the core network equipment, the transmission between the core network equipment and the data network equipment), which improves the security of user privacy Sex.
- FIG. 5 is a schematic flowchart of yet another authentication method provided by an embodiment of the application. Referring to Figure 5, the method may include:
- S501 The terminal device sends a registration request message to the core network device.
- the registration request message includes the identification and slice information of the terminal device.
- the core network equipment performs first-level authentication on the terminal equipment.
- the core network device determines that the user needs to perform secondary authentication, the core network device sends a user identity request (ID request) message to the terminal device.
- ID request user identity request
- S504 The terminal device sends a user identity response (ID response) message to the core network device.
- ID response user identity response
- the user identity response message includes the first information.
- the user identity response message does not include the container.
- the user identity response message includes a container, and the first information is located inside or outside the container.
- the terminal device determines the user's DUI according to the user identity request message, and performs preset processing (such as randomization processing, mapping processing, etc.) on the DUI to obtain the first information, and carries the first information in the user identity response message .
- preset processing such as randomization processing, mapping processing, etc.
- the core network device obtains address information of the data network device according to the user identity response message.
- the process of obtaining the address information of the data network device by the core network device may refer to the process of obtaining the address information of the data network device in S303, which will not be repeated here.
- the address information of the data network device can also be obtained in the manner shown in S301-S303. That is, the process of S501-S505 can also be replaced with the process of S301-S303.
- the core network device sends an authentication request message to the data network device according to the address information of the data network device.
- the authentication request message includes the first information.
- the authentication request message includes a container, and the first information is located inside or outside the container.
- the core network device may obtain the first information in the user identity response message, and carry the first information in the authentication request message.
- the data network device performs identity authentication on the user according to the first information.
- the data network device may store the first information corresponding to each DUI. Accordingly, the data network device may determine the corresponding user according to the first information, and perform identity authentication on the corresponding user.
- the data network device stores the first information obtained after randomizing each DUI, or the data network device can perform randomization processing
- the inverse operation of the first information can obtain each DUI in reverse.
- the data network device may also authenticate the corresponding relationship between the identifier of the UE and the user. For example, if the authentication policy only allows the user to use a specific UE to access, when the identifier of the UE included in the authentication request message does not correspond to the DUI, the identity authentication of the user fails.
- the data network device sends an authentication response message to the core network device.
- the authentication response message includes the first information.
- the core network device sends a registration response message to the terminal device.
- execution process of S508-S509 can refer to the execution process of S307-S308, which will not be repeated here.
- the core network device sends the user authentication request message to the data network device, and the data network device
- the data network device sends an authentication response message to the core network device.
- the authentication response message includes first information.
- the first information can indicate the user’s DUI so that the core network device can determine the user’s The identity authentication result.
- the user's DUI is invisible to other devices (core network device and access network device, or access network device), so that DUI will not leak these devices, nor will DUI be in the process of transmission.
- the transmission between the terminal equipment and the access network equipment, the transmission between the access network equipment and the core network equipment, the transmission between the core network equipment and the data network equipment which improves the security of user privacy Sex. Further, there is no need to store the corresponding relationship between the DUI and the first information in the data network device and the terminal device, which reduces the occupation of storage space.
- FIG. 6 is a schematic flowchart of another authentication method provided by an embodiment of the application. Referring to Figure 6, the method may include:
- the data network device sends a first status update request message to the core network device.
- the first status update request message includes first information.
- the first status update request message is used to request to update the status of the user indicated by the first information.
- the first status update request message may be used to request an update operation (modification, revocation operation, etc.) of the user's authority.
- the data network device may first update the user's authority in the data network device, and then request the core network device to update the user's authority.
- the data network device when the data network device determines to update the user's status, the data network device first obtains the user's DUI, and according to the correspondence between the DUI and the first information, obtains the first information corresponding to the DUI, and sends it to the core The network device sends a first status update request message including the first information.
- the first status update request message may also include the identification of the terminal device.
- the identification of the terminal device may be GPSI.
- the core network device updates the status of the user corresponding to the first information according to the first status update request message.
- the core network device may identify the corresponding user according to the first information in the first status update request message, and update the status of the user.
- the core network device stores the authentication result of the user corresponding to the first information, and the authentication result may include the status of the user.
- the core network device can identify the corresponding user according to the first information in the first status update request message, and update the status of the corresponding user.
- the core network device sends a first status update response message to the data network device.
- the first status update response message includes the first information.
- the data network device may determine the latest status of the user indicated by the first information according to the first status update response message.
- the core network device sends a notification message to the terminal device.
- the notification message includes the first information.
- the notification message is used to indicate that the status of the user corresponding to the first information is updated.
- the core network device may obtain the identification of the terminal device in the first status update request message, and send a notification message to the terminal device according to the identification of the terminal device.
- the corresponding relationship between the DUI and the first information is stored in the terminal device.
- One terminal device can correspond to one or more users. Therefore, after the terminal device receives the notification message, the corresponding user can be determined according to the first information in the notification message and the corresponding relationship.
- the data network device after the data network device updates the status of the user, the data network device sends a first status update request message to the core network device, and the first status update request message carries the first information
- the core network device can identify the corresponding user according to the first information, and update the status of the identified user.
- the user in the process of communicating with the core network device, the user’s DUI is Invisible, avoiding the leakage of DUI and protecting user privacy.
- FIG. 7 is a schematic flowchart of yet another authentication method provided by an embodiment of the application. Referring to Figure 7, the method may include:
- the core network device sends a second status update request message to the data network device, where the second status update request message includes the first information.
- the core network device may detect the state of the user.
- the core network device may send a second state update request message to the data network device.
- the second status update request may be used to request the data network device to re-authenticate the user, update the user's authority (modify, revoke, etc.), and so on.
- the data network device determines the DUI according to the first information, and updates the state of the user according to the DUI.
- the data network device stores the corresponding relationship between the DUI and the first information, and the data network device may determine to obtain the DUI according to the first information and the corresponding relationship.
- the data network device when the second status update request message is used to request the data network device to re-authenticate the user, the data network device re-authenticates the user’s identity.
- the process of authenticating the user’s identity can be seen in Figure 2-5 The illustrated embodiment will not be repeated here.
- the data network device verifies the user's authority, and agrees or rejects the update operation of the user's authority.
- the data network device sends a second status update response message to the core network device.
- the second status update response message includes the first information.
- the core network device may determine the latest status of the user indicated by the first information according to the second status update response message.
- the core network device sends a notification message to the terminal device.
- the notification message includes the first information.
- the notification message is used to indicate that the status of the user corresponding to the first information is updated.
- the core network device may obtain the identification of the terminal device in the first status update request message, and send a notification message to the terminal device according to the identification of the terminal device.
- the corresponding relationship between the DUI and the first information is stored in the terminal device.
- One terminal device can correspond to one or more users. Therefore, after the terminal device receives the notification message, the corresponding user can be determined according to the first information in the notification message and the corresponding relationship.
- the core network device can request the data network device to update the status of the user, and the information exchanged between the data network device and the core network device includes the first information, so that the core network device can The corresponding user is identified according to the first information, and the data network equipment is used to update the user’s status.
- the user’s DUI affects the core network equipment, UE, and data network equipment. Other devices in the transmission are invisible, which avoids the leakage of DUI and protects the privacy of users.
- FIG. 8 is a schematic structural diagram of an authentication device provided by an embodiment of this application.
- the authentication device 10 can be applied to core network equipment 10.
- the authentication device 10 may include a sending module 11 and a receiving module 12, where:
- the sending module 11 is configured to send a user authentication request message to a data network device, where the authentication request message is used to request the data network device to perform identity authentication on the user;
- the receiving module 12 is configured to receive an authentication response message sent by the data network device by the device, where the authentication response message includes first information, and the first information is used to indicate user identity information of the user.
- the sending module 11 may execute steps related to the sending function of the core network device in the foregoing method embodiment.
- the sending module 11 may execute S201 in the embodiment of FIG. 2 and S304 and S308 in the embodiment of FIG. 3, S403, S406, and S410 in the embodiment of FIG. 4, S503, S506, and S509 in the embodiment of FIG. 5, S604 in the embodiment of FIG. 6, and S701 and S704 in the embodiment of FIG.
- the receiving module 12 may perform steps related to the sending function of the core network device in the foregoing method embodiment.
- the sending module 11 may perform S203 in the embodiment of FIG. 2 and S301 and S307 in the embodiment of FIG. 3, S401, S404, and S409 in the embodiment of Fig. 4, S501, S504, and S508 in the embodiment of Fig. 5, S601 and S603 in the embodiment of Fig. 6, and S703 in the embodiment of Fig. 7.
- the authentication device 10 shown in the embodiment of the present application can execute the technical solutions shown in the foregoing method embodiments, and its implementation principles and beneficial effects are similar, and details are not described herein again.
- the authentication request message includes the first information.
- the authentication request message further includes the user identity information, the user identity information is located in a container of the authentication request message, and the first information is located in a container of the authentication request message. Outside.
- the receiving module 12 is further configured to receive a registration request message sent by the terminal device before the sending module 11 sends an authentication request message to the data network device, where the registration request message includes The first information and the user identity information, the user identity information is located in the container of the registration request message, and the first information is located outside the container of the registration request message.
- the sending module 11 is further configured to send a user identity request message to a terminal device before the sending module 11 sends an authentication request message to the data network device;
- the receiving module 12 is further configured to receive a user identity response message sent by the terminal device, where the user identity response message includes the first information and the user identity information.
- FIG. 9 is a schematic structural diagram of another authentication device provided by an embodiment of the application.
- the authentication device 10 may further include a processing module 13, wherein the processing module 13 is used for:
- the corresponding relationship between the identifier of the terminal device and the first information is stored.
- the identifier of the terminal device includes the terminal permanent identifier SUPI and/or the hidden terminal subscription identifier SUCI.
- the processing module 13 is further configured to obtain the first information, and determine the address information of the data network device according to the first information;
- the sending module 11 is specifically configured to send the authentication request message to the data network device according to the address information.
- the slice information is network slice selection assistance information NSSAI.
- the receiving module 12 is further configured to receive a first status update request message sent by the data network device, where the first status update request message includes the first information;
- the processing module 13 is further configured to update the status of the user corresponding to the first information according to the first status update request message;
- the sending module 11 is further configured to send a first status update response message to the data network device, where the first status update response message includes the first information.
- the sending module 11 is further configured to send a second status update request message to the data network device, where the second status update request message includes the first information;
- the receiving module 12 is further configured to receive a second status update response message sent by the data network device, where the second status update response message includes the first information.
- the sending module 11 is further configured to send a notification message to the terminal device, the notification message includes the first information, and the notification message is used to indicate the first information The status of the corresponding user is updated.
- the authentication device 10 shown in the embodiment of the present application can execute the technical solutions shown in the foregoing method embodiments, and its implementation principles and beneficial effects are similar, and details are not described herein again.
- FIG. 10 is a schematic structural diagram of another authentication device provided by an embodiment of the application.
- the authentication device 20 can be applied to data network equipment.
- the authentication device 20 may include a receiving module 21, a processing module 22, and a sending module 23, where:
- the receiving module 21 is configured to receive a user authentication request message sent by a core network device
- the processing module 22 is configured to perform identity authentication on the user according to the authentication request message
- the sending module 23 is configured to send an authentication response message to the core network device, where the authentication response message includes first information, and the first information is used to indicate data network user identity information of the user.
- the receiving module 21 may execute steps related to the sending function of the core network device in the above method embodiment.
- the sending module 11 may execute S201 in the embodiment of FIG. 2, S304 in the embodiment of FIG. 3, and FIG. 4 S406 in the embodiment, S506 in the embodiment in FIG. 5, S604 in the embodiment in FIG. 6, and S704 in the embodiment in FIG.
- the processing module 22 may perform steps related to the sending function of the core network device in the above method embodiment.
- the sending module 11 may perform S202 in the embodiment of FIG. 2 and S305-S306 in the embodiment of FIG. 3, S407-S408 in the embodiment of Fig. 4, S507 in the embodiment of Fig. 5, S602 in the embodiment of Fig. 6, and S702 in the embodiment of Fig. 7.
- the sending module 23 may execute steps related to the sending function of the core network device in the foregoing method embodiment.
- the sending module 11 may execute S203 in the embodiment of FIG. 2, S307 in the embodiment of FIG. 3, and FIG. S409 in the embodiment, S508 in the embodiment in FIG. 5, S601 and S603 in the embodiment in FIG. 6, and S703 in the embodiment in FIG.
- the authentication device 20 shown in the embodiment of the present application can execute the technical solution shown in the foregoing method embodiment, and its implementation principles and beneficial effects are similar, and will not be repeated here.
- the authentication request message includes the first information.
- the authentication request message further includes the user identity information, the user identity information is located in a container of the authentication request message, and the first information is located in a container of the authentication request message. Outside.
- the authentication request message includes the first information; the processing module 22 is specifically configured to:
- the authentication request message includes the first information; the processing module 22 is specifically configured to:
- the data network device performs identity authentication on the user according to the first information.
- the authentication request message includes the user identity information; the processing module 22 is further configured to, before the sending module 23 sends the authentication response message to the core network device, according to all The user identity information determines the first information.
- the sending module 23 is further configured to send a first status update request message to the core network device, where the first status update request message includes the first information, A status update request message is used to request the core network device to update the status of the user indicated by the first information;
- the receiving module 21 is further configured to receive a first status update response message sent by the core network device, where the first status update response message includes the first information.
- the receiving module 21 is further configured to receive a second status update request message sent by the core network device, where the second status update request message includes the first information;
- the processing module 22 is further configured to determine the user identity information according to the first information, and update the status of the user according to the user identity information;
- the sending module 23 is further configured to send a second status update response message to the core network device, where the second status update response message includes the first information.
- the authentication device 10 shown in the embodiment of the present application can execute the technical solutions shown in the foregoing method embodiments, and its implementation principles and beneficial effects are similar, and will not be repeated here.
- FIG. 11 is a schematic diagram of the hardware structure of an authentication device provided by an embodiment of the application.
- the authentication device 30 includes: a memory 31, a processor 32, a receiver 33, and a transmitter 34, where the memory 31 communicates with the processor 32; for example, the memory 31, the processor 32, and the receiver 33 It can communicate with the transmitter 34 through a communication bus 35, the memory 31 is used to store a computer program, and the processor 32 executes the computer program to implement the above authentication method.
- the processor 32 shown in the present application may implement the functions of the processing module 13 in the embodiment of FIG. 9, the receiver 33 may implement the functions of the receiving module 12 in the embodiment of FIG. 8-9, and the transmitter 34 may implement the function of FIG. 8- The function of the sending module 11 in the 9th embodiment will not be repeated here.
- the aforementioned processor 32 may be a central processing unit (Central Processing Unit, CPU), or other general-purpose processors, digital signal processors (Digital Signal Processor, DSP), and application specific integrated circuits (Application Specific Integrated Circuits), ASIC) etc.
- the general-purpose processor may be a microprocessor or the processor may also be any conventional processor or the like.
- the steps in the embodiment of the authentication method disclosed in this application may be directly embodied as being executed and completed by a hardware processor, or executed and completed by a combination of hardware and software modules in the processor.
- FIG. 12 is a schematic diagram of the hardware structure of another authentication device provided by an embodiment of the application.
- the authentication device 40 includes: a memory 41, a processor 42, a receiver 43, and a transmitter 44, where the memory 41 communicates with the processor 42; for example, the memory 41, the processor 42, and the receiver 43 It can communicate with the transmitter 44 through a communication bus 45, the memory 41 is used to store a computer program, and the processor 42 executes the computer program to implement the above authentication method.
- the processor 42 shown in the present application can implement the functions of the processing module 22 in the embodiment in FIG. 10
- the receiver 43 can implement the functions of the receiving module 21 in the embodiment in FIG. 10
- the transmitter 44 can implement the implementation in FIG. The function of the sending module 23 in the example will not be repeated here.
- the foregoing processor may be a CPU, or other general-purpose processors, DSPs, ASICs, and so on.
- the general-purpose processor may be a microprocessor or the processor may also be any conventional processor or the like.
- the steps in the embodiment of the authentication method disclosed in this application may be directly embodied as being executed and completed by a hardware processor, or executed and completed by a combination of hardware and software modules in the processor.
- the present application provides a storage medium, the storage medium is used to store a computer program, and the computer program is used to implement the authentication method described in the foregoing embodiment.
- All or part of the steps in the foregoing method embodiments can be implemented by a program instructing relevant hardware.
- the aforementioned program can be stored in a readable memory.
- the program executes the steps that include the foregoing method embodiments; and the foregoing memory (storage medium) includes: read-only memory (English: read-only memory, abbreviation: ROM), RAM, flash memory, hard disk, Solid state drives, magnetic tapes (English: magnetic tape), floppy disks (English: floppy disk), optical discs (English: optical disc) and any combination thereof.
- These computer program instructions can be provided to the processing unit of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing equipment to generate a machine, so that the instructions executed by the processing unit of the computer or other programmable data processing equipment are generated for use It is a device that realizes the functions specified in one process or multiple processes in the flowchart and/or one block or multiple blocks in the block diagram.
- These computer program instructions can also be stored in a computer-readable memory that can guide a computer or other programmable data processing equipment to work in a specific manner, so that the instructions stored in the computer-readable memory produce an article of manufacture including the instruction device.
- the device implements the functions specified in one process or multiple processes in the flowchart and/or one block or multiple blocks in the block diagram.
- These computer program instructions can also be loaded on a computer or other programmable data processing equipment, so that a series of operation steps are executed on the computer or other programmable equipment to produce computer-implemented processing, so as to execute on the computer or other programmable equipment.
- the instructions provide steps for implementing functions specified in a flow or multiple flows in the flowchart and/or a block or multiple blocks in the block diagram.
- the term “including” and its variations may refer to non-limiting inclusion; the term “or” and its variations may refer to “and/or”.
- the terms “first”, “second”, etc. in the present application are used to distinguish similar objects, and are not necessarily used to describe a specific order or sequence.
- “plurality” means two or more.
- “And/or” describes the association relationship of the associated objects, indicating that there can be three types of relationships, for example, A and/or B, which can mean: A alone exists, both A and B exist, and B alone exists.
- the character “/” generally indicates that the associated objects are in an "or” relationship.
Landscapes
- Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Computer Hardware Design (AREA)
- Computing Systems (AREA)
- General Engineering & Computer Science (AREA)
- Business, Economics & Management (AREA)
- Accounting & Taxation (AREA)
- Mobile Radio Communication Systems (AREA)
- Telephonic Communication Services (AREA)
Abstract
本申请实施例提供一种认证方法、装置及设备,该方法包括:核心网设备向数据网设备发送用户的认证请求消息,所述认证请求消息用于请求所述数据网设备对所述用户进行身份认证;所述核心网设备接收所述数据网设备发送的认证响应消息,所述认证响应消息包括第一信息,所述第一信息用于指示所述用户的用户身份信息。提高了用户隐私的安全性。
Description
本申请要求于2019年04月12日提交中国专利局、申请号为2019102924399、申请名称为“认证方法、装置及设备”的中国专利申请的优先权,其全部内容通过引用结合在本申请中。
本申请涉及通信技术领域,尤其涉及一种认证方法、装置及设备。
网络切片为虚拟的专用网络,在终端设备接入网络切片之前,需要由数据网设备对使用终端设备的用户的身份进行认证。数据网设备可以为第三方网络设备,例如,第三方网络设备可以为游戏平台等。
在现有技术中,终端设备可以通过核心网设备(运营商网络的设备)请求第三方网络设备对用户的身份进行认证。例如,终端设备可以向核心网设备发送用户的用户身份信息,核心网设备根据用户身份信息请求数据网设备对用户的身份进行认证。然而,用户身份信息为用户的隐私数据,在上述过程中,用户身份信息可能被泄露,导致用户隐私的安全性较差。
发明内容
本申请提供一种认证方法、装置及设备。提高了用户隐私的安全性。
第一方面,本申请实施例提供一种认证方法,核心网设备向数据网设备发送用户的认证请求消息,认证请求消息用于请求数据网设备对用户进行身份认证,核心网设备接收数据网设备发送的认证响应消息,认证响应消息包括第一信息,第一信息用于指示用户的用户身份信息。
在上述过程中,用户的DUI对其它设备(核心网设备和接入网设备,或者接入网设备)为不可见的,使得DUI不会泄露到这些设备,也不会使得DUI在传输的过程(例如,终端设备与接入网设备之间的传输、接入网设备与核心网设备之间的传输、核心网设备与数据网设备之间的传输)中发生泄漏,提高了用户隐私的安全性。
在一种可能的实施方式中,认证请求消息中包括第一信息。
在上述过程中,数据网设备可以根据认证请求消息终端的第一信息确定待认证的用户,进而对待认证的用户进行身份认证。认证请求消息中包括的内容较少,节省了信令开销。
在一种可能的实施方式中,认证请求消息还包括用户身份信息,用户身份信息位于认证请求消息的容器中,第一信息位于认证请求消息的容器之外。
在上述过程中,数据网设备在接收到认证请求消息之后,可以在容器中获取用户身份信息,并获取用户身份信息对应的第一信息,判断用户身份信息对应的第一信息与认证请 求消息中包括的第一信息是否相同,在确定相同时,再对用户身份信息所指示的用户进行身份认证,避免了在数据传输过程中对认证请求消息中的信息被恶意更改时,对用户身份认证错误的问题,提高了认证的安全性。
在一种可能的实施方式中,核心网设备向数据网设备发送认证请求消息之前,核心网设备接收终端设备发送的注册请求消息,注册请求消息中包括第一信息和用户身份信息,用户身份信息位于注册请求消息的容器中,第一信息位于注册请求消息的容器之外。
在上述过程中,核心网设备可以通过注册请求消息获取得到第一信息和用户身份信息,无需通过额外的其它信令获取第一信息和用户身份信息,节省了信令开销。
在一种可能的实施方式中,核心网设备向数据网设备发送认证请求消息之前,核心网设备向终端设备发送用户身份请求消息;核心网设备接收终端设备发送的用户身份响应消息,用户身份响应消息包括第一信息和用户身份信息。
在上述过程中,核心网设备可以通过注册请求消息获取得到第一信息和用户身份信息,无需通过额外的其它信令获取第一信息和用户身份信息,节省了信令开销。
在一种可能的实施方式中,核心网设备获取终端设备的标识,并核心网设备存储终端设备的标识和第一信息之间的对应关系。这样,核心网设备可以确定得到用户与终端设备之间的对应关系,相应的,在核心网设备接收到认证响应消息之后,可以根据认证响应消息中的第一信息所指示的用户确定得到对应的终端设备,并对该终端设备执行相应的处理操作(例如发送注册响应消息等)。
在一种可能的实施方式中,终端设备的标识包括终端永久标识符SUPI和/或隐藏的终端签约标识符SUCI。
在一种可能的实施方式中,核心网设备向数据网设备发送用户的认证请求消息,包括:核心网设备获取第一信息;核心网设备根据第一信息,确定数据网设备的地址信息;核心网设备根据地址信息向数据网设备发送认证请求消息。
在上述过程中,核心网设备根据第一信息即可获取得到数据网设备的地址信息,使得核心网设备可以快速获取得到数据网设备的地址信息。
在一种可能的实施方式中,切片信息为网络切片选择辅助信息NSSAI。
在一种可能的实施方式中,核心网设备接收数据网设备发送的第一状态更新请求消息,第一状态更新请求消息包括第一信息;
核心网设备根据第一状态更新请求消息更新第一信息对应的用户的状态;
核心网设备向数据网设备发送第一状态更新响应消息,第一状态更新响应消息包括第一信息。
在上述过程中,在数据网设备对用户的状态进行更新之后,数据网设备向核心网设备发送第一状态更新请求消息,并在第一状态更新请求消息中携带第一信息,这样,核心网设备可以根据第一信息识别对应的用户,并对识别得到的用户的状态进行更新,在上述过程中,在与核心网设备通信的过程中,用户的DUI对核心网设备为不可见的,避免了DUI的泄露,保障了用户隐私。
在一种可能的实施方式中,核心网设备向数据网设备发送第二状态更新请求消息,第二状态更新请求消息包括第一信息;核心网设备接收数据网设备发送的第二状态更新响应消息,第二状态更新响应消息中包括第一信息。
在上述过程中,核心网设备可以请求数据网设备对用户的状态进行更新操作,数据网设备与核心网设备之间交互的信息中包括第一信息,这样,核心网设备可以根据第一信息识别对应的用户,以和数据网设备实现对用户的状态的更新操作,在上述过程中,在与核心网设备通信的过程中,用户的DUI对核心网设备、UE和数据网之间的传输中的其他设备为不可见的,避免了DUI的泄露,保障了用户的隐私。
在一种可能的实施方式中,核心网设备向终端设备发送通知消息,通知消息包括第一信息,通知消息用于指示第一信息对应的用户的状态发生更新。
第二方面,本申请实施例提供一种认证方法,数据网设备接收核心网设备发送的用户的认证请求消息;数据网设备根据认证请求消息对用户进行身份认证,并向核心网设备发送认证响应消息,认证响应消息包括第一信息,第一信息用于指示用户的数据网用户身份信息用户身份信息。
在上述过程中,用户的DUI对其它设备(核心网设备和接入网设备,或者接入网设备)为不可见的,使得DUI不会泄露到这些设备,也不会使得DUI在传输的过程(例如,终端设备与接入网设备之间的传输、接入网设备与核心网设备之间的传输、核心网设备与数据网设备之间的传输)中发生泄漏,提高了用户隐私的安全性。
在一种可能的实施方式中,认证请求消息中包括第一信息。
在上述过程中,数据网设备可以根据认证请求消息终端的第一信息确定待认证的用户,进而对待认证的用户进行身份认证。认证请求消息中包括的内容较少,节省了信令开销。
在一种可能的实施方式中,认证请求消息还包括用户身份信息,用户身份信息位于认证请求消息的容器中,第一信息位于认证请求消息的容器之外。
在上述过程中,数据网设备在接收到认证请求消息之后,可以在容器中获取用户身份信息,并获取用户身份信息对应的第一信息,判断用户身份信息对应的第一信息与认证请求消息中包括的第一信息是否相同,在确定相同时,再对用户身份信息所指示的用户进行身份认证,避免了在数据传输过程中对认证请求消息中的信息被恶意更改时,对用户身份认证错误的问题,提高了认证的安全性。
在一种可能的实施方式中,认证请求消息包括第一信息;数据网设备可以根据第一信息确定用户身份信息;数据网设备根据用户身份信息,对用户进行身份认证。
在一种可能的实施方式中,认证请求消息包括第一信息;数据网设备可以根据第一信息对用户进行身份认证。
在一种可能的实施方式中,认证请求消息包括用户身份信息;数据网设备向核心网设备发送认证响应消息之前,数据网设备根据用户身份信息确定第一信息。
在一种可能的实施方式中,数据网设备向核心网设备发送第一状态更新请求消息,第一状态更新请求消息包括第一信息,第一状态更新请求消息用于请求核心网设备对第一信息所指示的用户的状态进行更新;数据网设备接收核心网设备发送的第一状态更新响应消息,第一状态更新响应消息包括第一信息。
在上述过程中,在数据网设备对用户的状态进行更新之后,数据网设备向核心网设备发送第一状态更新请求消息,并在第一状态更新请求消息中携带第一信息,这样,核心网设备可以根据第一信息识别对应的用户,并对识别得到的用户的状态进行更新,在上述过 程中,在与核心网设备通信的过程中,用户的DUI对核心网设备为不可见的,避免了DUI的泄露,保障了用户隐私。
在一种可能的实施方式中,数据网设备接收核心网设备发送的第二状态更新请求消息,第二状态更新请求消息包括第一信息;数据网设备根据第一信息确定用户身份信息,并根据用户身份信息更新用户的状态;数据网设备向核心网设备发送第二状态更新响应消息,第二状态更新响应消息中包括第一信息。
在上述过程中,核心网设备可以请求数据网设备对用户的状态进行更新操作,数据网设备与核心网设备之间交互的信息中包括第一信息,这样,核心网设备可以根据第一信息识别对应的用户,以和数据网设备实现对用户的状态的更新操作,在上述过程中,在与核心网设备通信的过程中,用户的DUI对核心网设备、UE和数据网之间的传输中的其他设备为不可见的,避免了DUI的泄露,保障了用户的隐私。
第三方面,本申请实施例提供一种认证装置,包括发送模块和接收模块,其中,
所述发送模块用于,向数据网设备发送用户的认证请求消息,所述认证请求消息用于请求所述数据网设备对所述用户进行身份认证;
所述接收模块用于,设备接收所述数据网设备发送的认证响应消息,所述认证响应消息包括第一信息,所述第一信息用于指示所述用户的用户身份信息。
在一种可能的实施方式中,所述认证请求消息中包括所述第一信息。
在一种可能的实施方式中,所述认证请求消息还包括所述用户身份信息,所述用户身份信息位于所述认证请求消息的容器中,所述第一信息位于所述认证请求消息的容器之外。
在一种可能的实施方式中,所述接收模块还用于,在所述发送模块向数据网设备发送认证请求消息之前,接收终端设备发送的注册请求消息,所述注册请求消息中包括所述第一信息和所述用户身份信息,所述用户身份信息位于所述注册请求消息的容器中,所述第一信息位于所述注册请求消息的容器之外。
在一种可能的实施方式中,所述发送模块还用于,在所述发送模块向数据网设备发送认证请求消息之前,向终端设备发送用户身份请求消息;
所述接收模块还用于,接收所述终端设备发送的用户身份响应消息,所述用户身份响应消息包括所述第一信息和所述用户身份信息。
在一种可能的实施方式中,所述装置还包括处理模块,其中,所述处理模块用于:
获取所述终端设备的标识;
存储所述终端设备的标识和所述第一信息之间的对应关系。
在一种可能的实施方式中,所述终端设备的标识包括终端永久标识符SUPI和/或隐藏的终端签约标识符SUCI。
在一种可能的实施方式中,所述处理模块还用于,获取所述第一信息,并根据所述第一信息,确定所述数据网设备的地址信息;
所述发送模块具体用于,根据所述地址信息向所述数据网设备发送所述认证请求消息。
在一种可能的实施方式中,所述切片信息为网络切片选择辅助信息NSSAI。
在一种可能的实施方式中,所述接收模块还用于,接收所述数据网设备发送的第一状 态更新请求消息,所述第一状态更新请求消息包括所述第一信息;
所述处理模块还用于,根据所述第一状态更新请求消息更新所述第一信息对应的用户的状态;
所述发送模块还用于,向所述数据网设备发送第一状态更新响应消息,所述第一状态更新响应消息包括所述第一信息。
在一种可能的实施方式中,所述发送模块还用于,向所述数据网设备发送第二状态更新请求消息,所述第二状态更新请求消息包括所述第一信息;
所述接收模块还用于,接收所述数据网设备发送的第二状态更新响应消息,所述第二状态更新响应消息中包括所述第一信息。
在一种可能的实施方式中,所述发送模块还用于,向所述终端设备发送通知消息,所述通知消息包括所述第一信息,所述通知消息用于指示所述第一信息对应的用户的状态发生更新。
第三方面,本申请实施例提供一种认证方法,包括接收模块、处理模块和发送模块,其中,
所述接收模块用于,接收核心网设备发送的用户的认证请求消息;
所述处理模块用于,根据所述认证请求消息对所述用户进行身份认证;
所述发送模块用于,向所述核心网设备发送认证响应消息,所述认证响应消息包括第一信息,所述第一信息用于指示所述用户的数据网用户身份信息用户身份信息。
在一种可能的实施方式中,所述认证请求消息中包括所述第一信息。
在另一种可能的实施方式中,所述认证请求消息还包括所述用户身份信息,所述用户身份信息位于所述认证请求消息的容器中,所述第一信息位于所述认证请求消息的容器之外。
在一种可能的实施方式中,所述认证请求消息包括所述第一信息;所述处理模块具体用于:
根据所述第一信息确定所述用户身份信息;
根据所述用户身份信息,对所述用户进行身份认证。
在一种可能的实施方式中,所述认证请求消息包括所述第一信息;所述处理模块具体用于:
所述数据网设备根据所述第一信息对所述用户进行身份认证。
在一种可能的实施方式中,所述认证请求消息包括所述用户身份信息;所述处理模块还用于,在所述发送模块向所述核心网设备发送认证响应消息之前,根据所述用户身份信息确定所述第一信息。
在一种可能的实施方式中,所述发送模块还用于,向所述核心网设备发送第一状态更新请求消息,所述第一状态更新请求消息包括所述第一信息,所述第一状态更新请求消息用于请求所述核心网设备对所述第一信息所指示的用户的状态进行更新;
所述接收模块还用于,接收所述核心网设备发送的第一状态更新响应消息,所述第一状态更新响应消息包括所述第一信息。
在一种可能的实施方式中,所述接收模块还用于,接收所述核心网设备发送的第二状态更新请求消息,所述第二状态更新请求消息包括所述第一信息;
所述处理模块还用于,根据所述第一信息确定所述用户身份信息,并根据所述用户身份信息更新所述用户的状态;
所述发送模块还用于,向所述核心网设备发送第二状态更新响应消息,第二所述状态更新响应消息中包括所述第一信息。
第五方面,本申请实施例提供一种认证装置,包括存储器和处理器,所述处理器执行所述存储器中的程序指令,用于实现第一方面任一项所述的认证方法。
第六方面,本申请实施例提供一种认证装置,包括存储器和处理器,所述处理器执行所述存储器中的程序指令,用于实现第二方面任一项所述的认证方法。
第七方面,本申请实施例提供一种存储介质,所述存储介质用于存储计算机程序,所述计算机程序被计算机或处理器执行时用于实现第一方面任一项所述的认证方法。
第八方面,本申请实施例提供一种存储介质,所述存储介质用于存储计算机程序,所述计算机程序被计算机或处理器执行时用于实现第二方面任一项所述的认证方法。
本申请实施例提供的认证方法、装置及设备,当需要对用户进行身份认证(二级认证)时,核心网设备向数据网设备发送用户的认证请求消息,在数据网设备可以对用户的身份进行认证,并向核心网设备发送认证响应消息,认证响应消息中包括第一信息,该第一信息可以指示用户的DUI,使得核心网设备可以根据认证响应消息确定对用户的身份认证结果。在上述过程中,用户的DUI对其它设备(核心网设备和接入网设备,或者接入网设备)为不可见的,使得DUI不会泄露到这些设备,也不会使得DUI在传输的过程(例如,终端设备与接入网设备之间的传输、接入网设备与核心网设备之间的传输、核心网设备与数据网设备之间的传输)中发生泄漏,提高了用户隐私的安全性。
图1A为本申请实施例提供的5G网络架构图;
图1B为本申请实施例提供的认证架构示意图;
图2为本申请实施例提供的认证方法的流程示意图;
图3为本申请实施例提供的另一种认证方法的流程示意图;
图4为本申请实施例提供的又一种认证方法的流程示意图;
图5为本申请实施例提供的再一种认证方法的流程示意图;
图6为本申请实施例提供的另一种认证方法的流程示意图;
图7为本申请实施例提供的又一种认证方法的流程示意图;
图8为本申请实施例提供的一种认证装置的结构示意图;
图9为本申请实施例提供的另一种认证装置的结构示意图;
图10为本申请实施例提供的又一种认证装置的结构示意图;
图11为本申请实施例提供的一种认证装置的硬件结构示意图;
图12为本申请实施例提供的另一种认证装置的硬件结构示意图。
运营商网络也可称为移动通信网络,主要是移动网络运营商(mobile network operator, MNO)为用户提供移动宽带接入服务的网络。本申请实施例所描述的运营商网络具体可为符合第三代合作伙伴项目(3rd generation partnership project,3GPP)标准要求的网络,简称3GPP网络。通常3GPP网络由运营商来运营,包括但不限于5G网络、4G网络、第三代移动通信技术(3rd-Generation,3G)网络和第二代无线电话技术(2-Generation wireless telephone technology,2G)网络等。为了方便描述,后续描述将以运营商网络为例进行说明
随着移动带宽接入服务的扩展,MNO的网络也会随之发展以便更好地支持多样化的商业模式,满足更加多样化的应用业务以及更多行业的需求。为了给更多的行业提供更好、更完善的服务,下一代网络(即5G网络)相对于4G网络也做了网络架构调整。例如,5G网络将4G网络中的移动管理实体(mobility management entity,MME)进行拆分,拆分为包括接入与移动性管理功能(access and mobility management function,AMF)和会话管理功能(session management function,SMF)等多个网元。3GPP标准化过程中还定义了基于服务化架构的5G网络架构,如图1A所示。
图1A为本申请实施例提供的5G网络架构图。请参见图1A,5G网络架构中可以包括终端设备、数据网络(data network,DN)和运营商网络。
其中,运营商网络可包括网络开放功能(network exposure function,NEF)网元、网络存储功能(network function repository function,NRF)网元、策略控制功能(policy control function,PCF)网元、统一数据管理(unified data management,UDM)网元、应用功能(application function,AF)网元、认证服务器功能(authentication server function,AUSF)网元、接入与移动性管理功能(access and mobility management function,AMF)网元、会话管理功能(session management function,SMF)网元、(无线)接入网((radio)access network,(R)AN)以及用户面功能(user plane function,UPF)网元等。上述运营商网络中,除(无线)接入网部分之外部分,称为核心网络部分。为方便说明,后续以(R)AN称为RAN为例进行说明。
本申请实施例所示的终端设备(也可以称为用户设备(user equipment,UE))是一种具有无线收发功能的设备。终端设备可以部署在陆地上,包括室内或室外、手持或车载。终端设备也可以部署在水面上(如轮船等),还可以部署在空中(例如飞机、气球和卫星上等)。所述终端可以是手机(mobile phone)、平板电脑(pad)、带无线收发功能的电脑、虚拟现实(virtual reality,VR)终端、增强现实(augmented reality,AR)终端、工业控制(industrial control)中的无线终端、无人驾驶(self-driving)中的无线终端、远程医疗(remote medical)中的无线终端、智能电网(smart grid)中的无线终端、运输安全(transportation safety)中的无线终端、智慧城市(smart city)中的无线终端、智慧家庭(smart home)中的无线终端等。
上述终端设备可通过运营商网络提供的接口(例如N1等)与运营商网络建立连接,使用运营商网络提供的数据和/或语音等服务。终端设备还可通过运营商网络访问DN,使用DN上部署的运营商业务,和/或第三方提供的业务。其中,上述第三方可为运营商网络和终端设备之外的服务方,可为终端设备提供他数据和/或语音等服务。其中,上述第三方的具体表现形式,具体可根据实际应用场景确定,在此不做限制。
RAN是运营商网络的子网络,是运营商网络中业务节点与终端设备之间的实施系统。 终端设备要接入运营商网络,首先是经过RAN,进而可通过RAN与运营商网络的业务节点连接。本申请中的RAN设备,是一种为终端设备提供无线通信功能的设备,接入网设备包括但不限于:5G中的下一代基站(next generation nodeB,gNB)、演进型节点B(evolved node B,eNB)、无线网络控制器(radio network controller,RNC)、节点B(node B,NB)、基站控制器(base station controller,BSC)、基站收发台(base transceiver station,BTS)、家庭基站(例如,home evolved nodeB,或home node B,HNB)、基带单元(baseband unit,BBU)、传输点(transmitting and receiving point,TRP)、发射点(transmitting point,TP)、移动交换中心等。
AMF网元是由运营商网络提供的控制面网元,负责终端设备接入运营商网络的接入控制和移动性管理,例如包括移动状态管理,分配用户临时身份标识,认证和授权用户等功能。
SMF网元是由运营商网络提供的控制面网元,负责管理终端设备的协议数据单元(protocol data unit,PDU)会话。PDU会话是一个用于传输PDU的通道,终端设备需要通过PDU会话与DN互相传送PDU。PDU会话由SMF网元负责建立、维护和删除等。SMF网元包括会话管理(如会话建立、修改和释放,包含UPF和AN之间的隧道维护)、UPF网元的选择和控制、业务和会话连续性(service and session continuity,SSC)模式选择、漫游等会话相关的功能。
UPF网元是由运营商提供的网关,是运营商网络与DN通信的网关。UPF网元包括数据包路由和传输、包检测、业务用量上报、服务质量(quality of service,QoS)处理、合法监听、上行包检测、下行数据包存储等用户面相关的功能。
DN也可以称为分组数据网络(packet data network,PDN),是位于运营商网络之外的网络,运营商网络可以接入多个DN,DN上可部署多种业务,可为终端设备提供数据和/或语音等服务。例如,DN是某智能工厂的私有网络,智能工厂安装在车间的传感器可为终端设备,DN中部署了传感器的控制服务器,控制服务器可为传感器提供服务。传感器可与控制服务器通信,获取控制服务器的指令,根据指令将采集的传感器数据传送给控制服务器等。又例如,DN是某公司的内部办公网络,该公司员工的手机或者电脑可为终端设备,员工的手机或者电脑可以访问公司内部办公网络上的信息、数据资源等。
UDM网元是由运营商提供的控制面网元,负责存储运营商网络中签约用户的用户永久标识符(SUbscriber Permanent Identifier,SUPI)、信任状(credential)、安全上下文(security context)、签约数据等信息。其中SUPI在传输过程中会先进行加密,加密后的SUPI被称为隐藏的用户签约标识符(SUbscription Concealed Identifier,SUCI)。UDM网元所存储的这些信息可用于终端设备接入运营商网络的认证和授权。其中,上述运营商网络的签约用户具体可为使用运营商网络提供的业务的用户,例如使用中国电信的手机芯卡的用户,或者使用中国移动的手机芯卡的用户等。上述签约用户的永久签约标识SUPI可为该手机芯卡的号码等。上述签约用户的信任状、安全上下文可为该手机芯卡的加密密钥或者跟该手机芯卡加密相关的信息等存储的小文件,用于认证和/或授权。上述安全上下文可为存储在用户本地终端(例如手机)上的数据(cookie)或者令牌(token)等。上述签约用户的签约数据可为该手机芯卡的配套业务,例如该手机芯卡的流量套餐或者使用网络等。需要说明的是,永久标识符、信任状、安全上下文、认证数据(cookie)、以及令牌等同认证、授 权相关的信息,在本发明本申请文件中,为了描述方便起见不做区分、限制。如果不做特殊说明,本申请实施例将以用安全上下文为例进行来描述,但本申请实施例同样适用于其他表述方式的认证、和/或授权信息。
AUSF网元是由运营商提供的控制面网元,通常用于一级认证,即终端设备(签约用户)与运营商网络之间的认证。AUSF网元接收到签约用户发起的认证请求之后,可通过UDM网元中存储的认证信息和/或授权信息对签约用户进行认证和/或授权,或者通过UDM网元生成签约用户的认证和/或授权信息。AUSF网元可向签约用户反馈认证信息和/或授权信息。
NEF网元是由运营商提供控制面网元。NEF网元以安全的方式对第三方开放运营商网络的对外接口。在SMF网元需要与第三方的网元通信时,NEF网元可作为SMF网元与第三方的网元通信的中继。NEF网元作为中继时,可作为签约用户的标识信息的翻译,以及第三方的网元的标识信息的翻译。比如,NEF将签约用户的SUPI从运营商网络发送到第三方时,可以将SUPI翻译成其对应的外部身份标识(identity,ID)。反之,NEF网元将外部ID(第三方的网元ID)发送到运营商网络时,可将其翻译成SUPI。
PCF网元是由运营商提供的控制面功能,用于向SMF网元提供PDU会话的策略。策略可以包括计费相关策略、QoS相关策略和授权相关策略等。
网络切片选择功能(Network Slice Selection Function,NSSF)网元(图中未示出),负责确定网络切片实例,选择AMF网元等。
图1A中Nnef、Nausf、Nnrf、Npcf、Nudm、Naf、Namf、Nsmf、N1、N2、N3、N4,以及N6为接口序列号。这些接口序列号的含义可参见3GPP标准协议中定义的含义,在此不做限制。
本申请中的移动性管理网元可以是图1A所示的AMF网元,也可以是未来通信系统中的具有上述AMF网元的功能的网元。或者,本申请中的移动性管理网元还可以是长期演进(long term evolution,LTE)中的移动性管理实体(mobility management entity,MME)等。
为方便说明,本申请后续,以移动性管理网元为AMF网元为例进行说明。进一步地,将AMF网元简称为AMF,将终端设备称为UE,即本申请后续所描述的AMF均可替换为移动性管理网元,UE均可替换为终端设备。
目前,多种多样的场景对3GPP生态系统提出了不同的需求,如计费、策略、安全、移动性等需求。3GPP强调了网络切片之间不相互影响,例如突发的大量的抄表业务不应该影响正常的移动宽带业务。为了满足多样性需求和切片间的隔离,需要业务间相对独立的管理和运维,并提供量身定做的业务功能和分析能力。不同类型业务的实例部署在不同的网络切片上,相同业务类型的不同实例也可部署在不同的网络切片上。其中,本申请中的“切片”也可以称为“网络切片”,或称为“网络切片实例”,三者具有相同的含义,这里统一说明,后续不再赘述。
5G网络中的切片是一个虚拟的专用网络,它是由一组网络功能、子网络所构成。比如,图1A中的RAN、AMF、SMF、UPF可以组成一个切片。图1A中的每种网络功能只示意性地画出了一个,而在实际网络部署中,每种网络功能或子网络可以有多个、数十个或上百个。运营商网络中可以部署很多网络切片,每个切片可以有不同的性能来满足不同应用、 不同垂直行业的需求。运营商可以根据不同垂直行业客户的需求,“量身定做”一个切片。运营商也可以允许一些行业客户享有较大的自主权,参与切片的部分管理、控制功能。其中,切片级的认证就是由行业客户参与的一种网络控制功能,即对终端用户接入切片进行认证和授权。
当核心网部署了网络切片,用户初始附着(或称为注册)到网络时,会触发网络切片的选择过程。切片的选择过程取决于用户的签约数据,本地配置信息,漫游协议,运营商的策略等等。在网络切片的选择过程中,需要综合考虑以上参数,才能为UE选择最佳的切片类型。
当UE需要接入到某个网络切片时,UE可以提供请求的网络切片给核心网,用于核心网为UE选择网络切片实例。其中,UE请求的网络切片,可以用请求的网络切片集合来表示,或者也可以表示为请求的网络切片选择辅助信息(requested network slice selection assistance information,requested NSSAI)。requested NSSAI是由一个或多个单网络切片选择辅助信息(single network slice selection assistance information,S-NSSAI)来表示构成,每个S-NSSAI用于标识一个网络切片类型,也可以理解为,S-NSSAI用于标识网络切片,或者可以理解为S-NSSAI是网络切片的标识信息。为了简单起见,在以下的描述中,对“网络切片”或是“S-NSSAI”不做严格区分,可以同样适用。
UE注册到网络之后,核心网网元(如AMF或NSSF)根据UE的签约数据、UE的requested NSSAI、漫游协议以及本地配置等信息综合判断,为UE选择允许接入的网络切片集合。其中,允许接入的网络切片集合可以用允许的(allowed)NSSAI来表示,allowed NSSAI包含的S-NSSAI均为当前运营商网络允许接入的S-NSSAI。
UE在接入网络或网络切片之前,需要同网络切片进行双向认证并得到网络的授权。目前,在5G标准中,网络对UE的认证与授权都是由运营商网络直接进行,这类认证授权方法被称为Primary Authentication(一级认证)。随着垂直行业和物联网的发展,可以预见,运营商网络之外的DN(如服务于垂直行业的DN),对于接入到该DN的UE同样有认证与授权的需求。比如,某商业公司提供了游戏平台,通过运营商网络,为游戏玩家提供游戏服务。一方面,由于玩家使用的UE是通过运营商网络接入游戏平台,运营商网络需要对该UE进行认证和授权,即一级认证。游戏玩家是商业公司的客户,该商业公司也需要对游戏玩家进行认证、授权,这种认证如果是基于网络切片的,或者它的颗粒度(granularity)是以切片为单位的,则该认证可以称为切片认证(slice authentication)或称为二级认证(secondary authentication),或称为基于切片的二级认证(slice-specific secondary authentication)。
需要说明的是,不管是上述一级认证,还是二级认证,都是针对UE(或使用该UE的某个用户)与网络(运营商网络或第三方网络)之间的认证。比如,针对一级认证,指的是UE与运营商网络之间的认证,如在UE的注册流程中运营商网络对UE执行一级认证,若一级认证通过则可以建立该UE的安全上下文。再比如,针对二级认证,指的是UE(或使用该UE的用户)与运营商网络之外的网络(即第三方网络)之间的认证,第三方网络会将二级认证结果通知运营商网络,以便运营商网络授权或拒绝该UE接入为第三方网络服务的运营商网络。
需要说明的是,本申请后续也可以将二级认证称为对切片的二级认证,或切片认证, 或对用户(使用UE的用户)进行身份认证,其具有的含义实际是:UE(或使用该UE的用户)与第三方网络之间执行的二级认证,其认证结果,将会决定运营商网络是否授权UE接入该切片。
图1B为本申请实施例提供的认证架构示意图。请参见图1B,包括终端设备、核心网设备和数据网设备。终端设备通过核心网设备请求数据网设备进行二级认证(对用户进行身份认证),其中,终端设备与核心网设备之间、以及核心网设备与数据网设备之间传输的消息中包括用于指示用户身份信息的信息为第一信息,第一信息中不包括用户身份信息中的隐私信息,例如,第一信息中不包括用户身份信息中的用户名,这样可以避免用户身份信息的泄露,提高了认证的安全性。
其中,本申请实施例所涉及的核心网设备可以为AMF、代理服务器或代理认证功能网等。数据网设备可以为认证、授权和计费(Authentication、Authorization、Accounting,AAA)服务器等。本申请实施例所涉及的用户身份信息用于标识用户的身份,本申请所涉及的用户与用户设备(UE)不同,用户可以是指使用用户设备(UE)的个体(例如人、或通过UE接入网络的其他设备)。用户身份信息可以为数据网用户身份信息(data network user identity,DUI),下面,以用户身份信息为DUI为例进行说明。
下面,通过具体实施例对本申请所示的技术方案进行详细说明。需要说明的是,下面几个具体实施例可以相互结合,对于相同或相似的内容,在不同的实施例中不再重复说明。
图2为本申请实施例提供的认证方法的流程示意图。请参见图2,该方法可以包括:
S201、核心网设备向数据网设备发送用户的认证请求(slice authentication request)消息,认证请求消息用于请求数据网设备对用户进行身份认证。
其中,认证请求消息中可以包括如下信息中的至少一种:用户的第一信息或用户的DUI。
其中,第一信息可以指示DUI,即,第一信息和DUI之间具有对应关系。第一信息和DUI之间可以为一一对应的关系,也可以为一对多、多对一、多对多的关系。
可选的,第一信息可以为对DUI中的用户隐私信息进行了隐私保护处理(例如,随机化处理、编号处理、映射处理、加密处理等)后得到的信息,为了便于描述,将提供该种方式获取得到的第一信息称为隐藏的数据网用户身份信息(data network user conceived identity,DUC)。例如,DUI中的用户隐私信息可以为用户名。
可选的,当使用终端设备的用户的个数为一个时,第一信息还可以为终端设备的标识。终端设备的标识还可以称为终端识别符(或者UE的识别符),例如,终端设备的标识可以为非保密的签约用户识别符(generic public subscription identifier,GPSI)。
可选的,DUI中包括路由信息,该路由信息用于指示数据网设备的地址。核心网设备可以根据路由信息将信息(例如,认证请求信息、或发给数据网设备的其它信息)转发给数据网设备。该路由信息有可能是隐私信息,也有可能不是隐私信息。若路由信息为隐私信息,则可以对路由信息进行隐私保护处理(例如、随机化处理、编号处理、映射处理、加密处理等)。在实际应用过程中,可以对DUI对应的第一信息进行更新。
当认证请求消息中包括DUI时,则DUI位于认证请求消息的容器(container)中,例如,容器可以为用于可扩展的认证协议(extensible authentication protocol,EAP)认证的EAP消息容器。其中,核心网设备可以仅对该容器中的信息进行透传,而不对容器中的信 息进行处理,即,容器中的信息对核心网设备为不可见的。这样,对于信息透传的核心网设备,由于不对DUI解读,可以避免DUI泄露给核心网设备,也可以避免核心网设备传输DUI的过程中对DUI造成泄露。
当认证请求消息中包括第一信息时,则第一信息可以位于认证请求消息中的容器之内,也可以位于容器之外。由于第一信息经过了隐私保护处理,因此,即使第一信息对其他设备(例如,核心网设备、空口或核心网窃听设备)可见,也不会造成DUI隐私的泄露。
可选的,认证请求消息还可以包括UE的识别符,如SUPI或者GPSI,用于指示用户是通过哪个UE进行的用户认证。一方面可以通过UE识别用户,另一方面,也可以通过UE和用户的绑定关系来进行授权。
可选的,在S201之前,核心网设备可以接收终端设备发送的注册请求(registration request)消息,并根据注册请求消息判断需要对用户进行身份认证时,再执行图2所示的实施例。
S202、数据网设备根据认证请求消息对用户进行身份认证。
可选的,当认证请求消息中包括DUI时,数据网设备可以根据DUI对用户进行身份认证。
可选的,当认证请求消息中包括第一信息时,数据网设备可以根据第一信息和DUI的对应关系,确定第一信息对应的DUI,并根据确定得到的DUI对用户进行身份认证。
可选的,当认证请求消息中包括DUI和第一信息时,数据网设备可以根据第一信息和DUI的对应关系,确定第一信息对应的DUI,并判断确定得到的DUI和认证请求消息中的DUI是否相同,若是,则根据DUI对用户进行身份认证。这样,可以避免认证请求消息在传输的过程中被篡改而导致对用户进行身份认证有误的问题。
可选的,当认证请求消息中包括UE的识别符时,数据网设备还可以对UE的识别符与用户之间的对应关系进行认证。例如,如果认证策略仅允许用户使用特定UE接入,则当认证请求消息中包括的UE的识别符与DUI不对应时,则对用户的身份认证失败。
需要说明的是,根据DUI对用户进行身份认证的流程,会因为采用的具体认证协议的不同而不同。一般上,认证请求消息是认证流程的开始,接下来可以包括认证方法的协商、密钥算法协商、双向认证授权等步骤,每个步骤都需要UE、核心网、数据网设备之间进行相应的信息交互。具体流程可以参见现有的过程,此处不再进行赘述。
S203、数据网设备向核心网设备发送认证响应消息。
可选的,认证响应消息可以为认证成功响应消息或者认证失败响应消息。当数据网设备对用户的身份认证成功时,则数据网设备向核心网设备发送认证成功响应消息。当数据网设备对用户的身份认证失败时,则数据网设备向核心网设备发送认证失败响应消息。
可选的,认证响应消息包括第一信息。
可选的,认证响应消息还可以包括DUI。DUI可以位于认证响应消息的一个容器中,以避免DUI发生泄漏。
可选的,当第一信息为DUC时,在核心网设备接收到认证响应消息之后,核心网设备可以确定数据网设备对DUC所指示的用户的认证结果(例如,认证成功或者认证失败)。在该种情况下,由于核心网设备、接入网设备均无法获取得到DUI,使得DUI不会泄露至核心网设备、接入网设备,也不会使得DUI在传输的过程(例如,终端设备与接入网设备 之间的传输、接入网设备与核心网设备之间的传输、核心网设备与数据网设备之间的传输)中发生泄漏。
可选的,当第一信息为终端设备的标识时,核心网设备可以根据终端设备的标识获取用户的DUI,并确定DUI所指示的用户的认证结果(例如,认证成功或者认证失败)。在该种情况下,由于接入网设备无法获取得到DUI,使得DUI不会泄露至接入网设备,也不会使得DUI在传输的过程(例如,终端设备与接入网设备之间的传输、接入网设备与核心网设备之间的传输、核心网设备与数据网设备之间的传输)中发生泄漏。
可选的,在核心网设备接收到认证响应消息之后,核心网设备可以根据认证响应消息中的第一信息,允许第一信息对应的用户(或者用户所使用的UE)接入对应的切片,或者拒绝第一信息对应的用户(或者用户所使用的UE)接入对应的切片。当认证响应消息为认证成功响应消息时,则核心网设备允许第一信息对应的用户(或者用户所使用的UE)接入对应的切片。当认证响应消息为认证失败响应消息时,则核心网设备拒绝第一信息对应的用户(或者用户所使用的UE)接入对应的切片。
本申请实施例提供的认证方法,当需要对用户进行身份认证(二级认证)时,核心网设备向数据网设备发送用户的认证请求消息,在数据网设备可以对用户的身份进行认证,并向核心网设备发送认证响应消息,认证响应消息中包括第一信息,该第一信息可以指示用户的DUI,使得核心网设备可以根据认证响应消息确定对用户的身份认证结果。在上述过程中,用户的DUI对其它设备(核心网设备和接入网设备,或者接入网设备)为不可见的,使得DUI不会泄露到这些设备,也不会使得DUI在传输的过程(例如,终端设备与接入网设备之间的传输、接入网设备与核心网设备之间的传输、核心网设备与数据网设备之间的传输)中发生泄漏,提高了用户隐私的安全性。
在上述任意一个实施例的基础上,下面,结合图3-图7,对认证方法进行详细说明。
图3为本申请实施例提供的另一种认证方法的流程示意图。请参见图3,该方法可以包括:
S301、终端设备向核心网设备发送注册请求消息。
其中,注册请求消息中包括第一信息和/或DUI。
当注册请求消息中包括DUI时,DUI位于注册请求消息的一个容器中。当注册请求消息中包括第一信息时,第一信息位于注册请求消息的容器之内或者之外。
可选的,注册请求消息中还可以包括终端设备的标识和切片信息。终端设备的标识可以包括SUPI和/或SUCI。切片信息可以为NSSAI。终端设备的标识和切片信息用于对终端设备进行一级认证。
可选的,注册请求消息中包括的内容(第一信息、DUI、终端设备的标识、切片信息中的一种或多种)可以为被处理过的信息。例如,注册请求消息中的内容可以为被加密处理过的,如注册请求消息为NAS(Non Access Stratum,非接入层)消息的一部分,由NAS密钥加密。
可选的,终端设备中可以存储第一信息和DUI的对应关系,相应的,终端设备可以根据DUI确定对应的第一信息,并在注册请求消息中携带第一信息。
S302、核心网设备对终端设备进行一级认证。
需要说明的是,S302为可选的步骤。即,在执行完S301之后,可以执行S302,也可 以不执行S302。
可选的,核心网设备可以根据终端设备的标识和切片信息对终端设备进行一级认证,在核心网设备对终端设备一级认证通过之后,可以对终端设备授权。
S303、核心网设备在确定需要对用户进行二级认证时,核心网设备获取数据网设备的地址信息。
可选的,核心网设备可以通过如下可行的实现方式判断是否需要对用户进行二级认证:核心网设备获取用户(第一信息和/或DUI所指示的用户)和/或UE对应的签约数据,并根据签约数据判断该用户是否购买对应的服务(请求接入的切片所提供的服务),若是,则确定需要对用户进行二级认证,若否,则确定不需要对用户进行二级认证。当注册请求消息中包括SUPI时,可以根据SUPI在数据库中获取SUPI对应的UE签约数据,该签约数据也可以包括用户对应的签约数据。
例如,若核心网设备执行S302,则在核心网设备对终端设备进行一级认证通过之后,再执行S303。若核心网设备对终端设备进行一级认证失败,则核心网设备可以不执行S303-S304。
需要说明的是,当核心网设备确定不需要对用户进行二级认证时,则不执行S303-S304。
可选的,核心网设备可以通过如下可行的实现方法获取数据网设备的地址信息:核心网设备获取第一信息、DUI或切片信息中的至少一种;核心网设备根据第一信息、DUI或切片信息中的至少一种,确定数据网设备的地址信息。数据网设备的地址信息可以为数据网设备的域名、互联网协议(internet protocol,IP)地址、媒体访问控制(media access control,MAC)地址等。
需要说明的是,若DUI对核心网设备为安全的,即,核心网设备获取DUI不会对DUI造成泄露,则核心网设备可以获取得到DUI,例如,可以使得核心网设备具备获取容器内的DUI的功能,以使得核心网设备可以根据DUI获取数据网设备的地址信息。若DUI对核心网设备为不安全的,即,核心网设备获取DUI可能会对DUI造成泄露,则核心网设备无法获取得到DUI,例如,可以使得核心网设备不具备获取容器内的DUI的功能,即,核心网设备无法获取容器中的DUI,进而使得DUI对核心网设备不可见。
第一信息中可以包括数据网设备的地址信息,相应的,核心网设备可以在第一信息中获取数据网设备的地址信息。或者,还可以存储第一信息与数据网设备之间的对应关系,相应的,可以根据第一信息和该对应关系获取数据网设备的地址信息。
DUI中可以包括数据网设备的地址信息,相应的,若核心网设备可以获取得到DUI,则核心网设备可以在DUI中获取数据网设备的地址信息。
切片信息和数据网设备之间具有预设的对应关系,相应的,可以根据切片信息和该对应关系获取数据网设备的地址信息。
可选的,当根据第一信息和/或DUI、以及切片信息获取地址信息时,可以将根据第一信息和/或DUI获取得到的地址信息与根据切片信息获取到的地址信息去交集,并将交集中的地址信息确定为数据网设备的地址信息。
可选的,若注册请求消息中包括第一信息和终端设备的标识,则核心网设备还可以存储第一信息和终端设备的标识之间的对应关系。例如,核心网设备可以存储第一信息和 SUPI之间的对应关系,或者存储第一信息和非保密的签约用户识别符(generic public subscription identifier,GPSI)之间的对应关系。这样,核心网设备可以根据第一信息确定得到对应的终端设备,也可以根据终端设备的标识确定得到第一信息。当然,若核心网设备可以获取得到DUI,核心网设备还可以存储DUI于终端设备的标识之间的对应关系。
S304、核心网设备根据数据网设备的地址信息,向数据网设备发送认证请求消息。
其中,认证请求消息中可以包括如下信息中的至少一种:用户的第一信息或用户的DUI。
可选的,当终端设备向核心网设备发送的注册请求消息中包括容器,则核心网设备在发送认证请求消息时,将注册请求消息中的容器封装在认证请求消息中。
需要说明的是,S304的执行过程可以参见S201的执行过程,此处不再进行赘述。
S305、数据网设备在认证请求消息中获取用户的DUI。
其中,数据网设备中存储有DUI和第一信息的对应关系。
若认证请求消息的容器中包括DUI,则数据网设备在认证请求消息的容器中获取DUI。
若认证请求消息中包括第一信息,则数据网设备可以根据第一信息和DUI的对应关系,获取第一信息对应的DUI。
若认证请求消息中包括第一信息和DUI,则数据网设备可以根据第一信息和DUI的对应关系获取第一信息对应的DUI、以及在认证请求消息的容器中获取DUI,并判断第一信息对应的DUI和在认证请求消息中获取DUI是否相同,若是,将第一信息对应的DUI或者认证请求消息中的DUI确定为用户的DUI。
S306、数据网设备根据用户的DUI对用户进行身份认证。
例如,数据网设备可以根据用户的DUI确定对应的用户,并对确定得到的用户进行身份认证。
需要说明的是,S306的执行过程可以参见S202的执行过程,此处不再进行赘述。
S307、数据网设备向核心网设备发送认证响应消息。
其中,认证响应消息包括第一信息。
可选的,认证响应消息中还可以包括DUI。DUI可以位于认证响应消息的一个容器中,以避免DUI发生泄漏。
其中,当数据网设备对用户的身份认证成功时,则数据网设备向核心网设备发送认证成功响应消息。当数据网设备对用户的身份认证失败时,则数据网设备向核心网设备发送认证失败响应消息。
S308、核心网设备向终端设备发送注册响应消息。
可选的,当第一信息为DUC时,在核心网设备接收到认证响应消息之后,核心网设备可以确定数据网设备对DUC所指示的用户的认证结果(例如,认证成功或者认证失败)。在该种情况下,由于核心网设备、接入网设备均无法获取得到DUI,使得DUI不会泄露至核心网设备、接入网设备,也不会使得DUI在传输的过程(例如,终端设备与接入网设备之间的传输、接入网设备与核心网设备之间的传输、核心网设备与数据网设备之间的传输)中发生泄漏。
可选的,当第一信息为终端设备的标识时,核心网设备可以根据终端设备的标识所指示的用户的认证结果(例如,认证成功或者认证失败)。在该种情况下,由于接入网设备 无法获取得到DUI,使得DUI不会泄露至接入网设备,也不会使得DUI在传输的过程(例如,终端设备与接入网设备之间的传输、接入网设备与核心网设备之间的传输、核心网设备与数据网设备之间的传输)中发生泄漏。
可选的,当认证响应消息为认证成功响应消息时,则注册响应消息为注册成功响应消息。当认证响应消息为认证失败响应消息时,则注册响应消息为注册失败响应消息。
可选的,若注册请求消息中包括第一信息,则核心网设备在接收到注册请求消息之后,可以存储第一信息。相应的,在数据网设备接收到认证响应消息之后,可以判断存储的第一信息与认证响应消息中包括的第一信息是否相同,若是,核心网设备再向终端设备发送注册成功响应消息。
在图3所示的实施例中,在网络注册的过程中,当需要对用户进行身份认证(二级认证)时,核心网设备向数据网设备发送用户的认证请求消息,数据网设备可以对用户的身份进行认证,并向核心网设备发送认证响应消息,认证响应消息中包括第一信息,该第一信息可以指示用户的DUI,使得核心网设备可以根据认证响应消息确定对用户的身份认证结果。在上述过程中,用户的DUI对其它设备(核心网设备和接入网设备,或者接入网设备)为不可见的,使得DUI不会泄露这这些设备,也不会使得DUI在传输的过程(例如,终端设备与接入网设备之间的传输、接入网设备与核心网设备之间的传输、核心网设备与数据网设备之间的传输)中发生泄漏,提高了用户隐私的安全性。
图4为本申请实施例提供的又一种认证方法的流程示意图。请参见图4,该方法可以包括:
S401、终端设备向核心网设备发送注册请求消息。
其中,注册请求消息中包括终端设备的标识和切片信息。
可选的,终端设备的标识可以包括SUPI和/或SUCI。切片信息可以为NSSAI。终端设备的标识和切片信息用于对终端设备进行一级认证。
S402、核心网设备对终端设备进行一级认证。
需要说明的是,S402的执行过程可以参见S302的执行过程,此处不再进行赘述。
S403、核心网设备在确定需要对用户进行二级认证时,核心网设备向终端设备发送用户身份请求(ID request)消息。
其中,用户身份请求消息用于请求用户的身份信息。
S404、终端设备向核心网设备发送用户身份响应(ID response)消息。
其中,用户身份响应消息中包括第一信息和/或DUI。当用户身份响应消息中包括DUI时,则DUI位于用户身份响应消息的容器中。当用户身份响应消息中包括第一信息时,则第一信息位于用户身份响应消息的容器之内或之外。
可选的,用户身份响应消息中包括第一信息和/或DUI可以为被处理过的信息。例如,第一信息和/DUI可以为被加密处理过的。例如,第一信息和/或DUI可以为经过非接入层(non access stratum,NAS)秘钥加密处理过的。
可选的,终端设备中存储有第一信息和DUI之间的对应关系。
S405、核心网设备根据用户身份响应消息,获取数据网设备的地址信息。
需要说明的是,核心网设备获取数据网设备的地址信息的过程可以参见S303中获取数据网设备的地址信息的过程,此处不再进行赘述。
S406、核心网设备根据数据网设备的地址信息,向数据网设备发送认证请求消息。
其中,认证请求消息中可以包括如下信息中的至少一种:用户的第一信息或用户的DUI。可选的,还可以包括UE的识别符,如GPSI
S407、数据网设备在认证请求消息中获取用户的DUI。
S408、数据网设备根据用户的DUI对用户进行身份认证。
S409、数据网设备向核心网设备发送认证响应消息。
其中,认证响应消息包括第一信息。
可选的,认证响应消息还可以包括DUI。
S410、核心网设备向终端设备发送注册响应消息。
需要说明的是,S406-S410的执行过程可以参见S304-S308的执行过程,此处不再进行赘述。
在图4所示的实施例中,在网络注册的过程中,当需要对用户进行身份认证(二级认证)时,核心网设备向数据网设备发送用户的认证请求消息,数据网设备可以对用户的身份进行认证,并向核心网设备发送认证响应消息,认证响应消息中包括第一信息,该第一信息可以指示用户的DUI,使得核心网设备可以根据认证响应消息确定对用户的身份认证结果。在上述过程中,用户的DUI对其它设备(核心网设备和接入网设备,或者接入网设备)为不可见的,使得DUI不会泄露这这些设备,也不会使得DUI在传输的过程(例如,终端设备与接入网设备之间的传输、接入网设备与核心网设备之间的传输、核心网设备与数据网设备之间的传输)中发生泄漏,提高了用户隐私的安全性。
图5为本申请实施例提供的再一种认证方法的流程示意图。请参见图5,该方法可以包括:
S501、终端设备向核心网设备发送注册请求消息。
其中,注册请求消息中包括终端设备的标识和切片信息。
S502、核心网设备对终端设备进行一级认证。
S503、核心网设备在确定需要对用户进行二级认证时,核心网设备向终端设备发送用户身份请求(ID request)消息。
需要说明的是,S501-S503的执行过程可以参见S401-S403的执行过程,此处不再进行赘述。
S504、终端设备向核心网设备发送用户身份响应(ID response)消息。
其中,用户身份响应消息中包括第一信息。
可选的,用户身份响应消息中不包括容器。或者,用户身份响应消息中包括容器,第一信息位于容器之内或之外。
可选的,终端设备根据用户身份请求消息确定用户的DUI,并对DUI进行预设处理(例如随机化处理、映射处理等),得到第一信息,并在用户身份响应消息中携带第一信息。
S505、核心网设备根据用户身份响应消息,获取数据网设备的地址信息。
需要说明的是,核心网设备获取数据网设备的地址信息的过程可以参见S303中获取数据网设备的地址信息的过程,此处不再进行赘述。
需要说明的是,在图5所示的实施例中,还可以通过S301-S303所示的方式获取数据网设备的地址信息。即,S501-S505的过程还可以替换为S301-S303的过程。
S506、核心网设备根据数据网设备的地址信息,向数据网设备发送认证请求消息。
其中,认证请求消息中包括第一信息。
可选的,认证请求消息中不包括容器。或者,认证请求消息中包括容器,第一信息位于容器之内或之外。
可选的,核心网设备可以在用户身份响应消息中获取第一信息,并在认证请求消息中携带第一信息。
S507、数据网设备根据第一信息,对用户进行身份认证。
可选的,数据网设备中可以存储每个DUI对应的第一信息,相应的,数据网设备可以根据第一信息确定对应的用户,并对相应的用户进行身份认证。
例如,假设第一信息为对DUI进行随机化处理得到的,相应的,数据网设备中存储有对每个DUI进行随机化处理后得到的第一信息,或者数据网设备中可以进行随机化处理的逆操作,针对第一信息可以逆向获得每个DUI。
可选的,当认证请求消息中包括UE的识别符时,数据网设备还可以对UE的识别符与用户之间的对应关系进行认证。例如,如果认证策略仅允许用户使用特定UE接入,则当认证请求消息中包括的UE的识别符与DUI不对应时,则对用户的身份认证失败。
S508、数据网设备向核心网设备发送认证响应消息。
其中,认证响应消息包括第一信息。
S509、核心网设备向终端设备发送注册响应消息。
需要说明的是,S508-S509的执行过程可以参见S307-S308的执行过程,此处不再进行赘述。
在图5所示的实施例中,在网络注册的过程中,当需要对用户进行身份认证(二级认证)时,核心网设备向数据网设备发送用户的认证请求消息,在数据网设备对用户的身份进行完成时,数据网设备向核心网设备发送认证响应消息,认证响应消息中包括第一信息,该第一信息可以指示用户的DUI,使得核心网设备可以根据认证响应消息确定对用户的身份认证结果。在上述过程中,用户的DUI对其它设备(核心网设备和接入网设备,或者接入网设备)为不可见的,使得DUI不会泄露这这些设备,也不会使得DUI在传输的过程(例如,终端设备与接入网设备之间的传输、接入网设备与核心网设备之间的传输、核心网设备与数据网设备之间的传输)中发生泄漏,提高了用户隐私的安全性。进一步的,数据网设备和终端设备中无需存储DUI和第一信息的对应关系,减少了对存储空间的占用。
图6为本申请实施例提供的另一种认证方法的流程示意图。请参见图6,该方法可以包括:
S601、数据网设备向核心网设备发送第一状态更新请求消息。
其中,第一状态更新请求消息包括第一信息。第一状态更新请求消息用于请求对第一信息所指示的用户的状态进行更新。
可选的,第一状态更新请求消息可以用于请求对用户的权限进行更新操作(修改、吊销操作等)。当第一状态更新请求消息用于请求对用户的权限进行更新操作时,数据网设备可以先在数据网设备中对用户的权限进行更新操作,再请求核心网设备对用户的权限进行更新操作。
可选的,在数据网设备确定对用户的状态进行更新时,数据网设备先获取用户的DUI, 并根据DUI和第一信息之间的对应关系,获取DUI对应的第一信息,并向核心网设备发送包括第一信息的第一状态更新请求消息。
可选的,第一状态更新请求消息中还可以包括终端设备的标识。例如,终端设备的标识可以为GPSI。
S602、核心网设备根据第一状态更新请求消息更新第一信息对应的用户的状态。
可选的,核心网设备可以根据第一状态更新请求消息中的第一信息识别对应的用户,并对用户的状态进行更新。
需要说明的是,在图2-图5所示的实施例中,核心网设备中存储了第一信息对应的用户的认证结果,认证结果中可以包括用户的状态。相应的,核心网设备可以根据第一状态更新请求消息中的第一信息识别对应的用户,并对对应的用户的状态进行更新。
S603、核心网设备向数据网设备发送第一状态更新响应消息。
其中,第一状态更新响应消息包括第一信息。
数据网设备可以根据第一状态更新响应消息确定第一信息所指示的用户的最新状态。
S604、核心网设备向终端设备发送通知消息。
其中,通知消息中包括第一信息。通知消息用于指示第一信息对应的用户的状态发生更新。
可选的,核心网设备可以在第一状态更新请求消息中获取终端设备的标识,并根据终端设备的标识向终端设备发送通知消息。
其中,终端设备中存储有DUI和第一信息的对应关系。一个终端设备可以对应一个或多个用户,因此,在终端设备接收到通知消息后,可以根据通知消息中的第一信息和该对应关系确定对应的用户。
在图6所示的实施例中,在数据网设备对用户的状态进行更新之后,数据网设备向核心网设备发送第一状态更新请求消息,并在第一状态更新请求消息中携带第一信息,这样,核心网设备可以根据第一信息识别对应的用户,并对识别得到的用户的状态进行更新,在上述过程中,在与核心网设备通信的过程中,用户的DUI对核心网设备为不可见的,避免了DUI的泄露,保障了用户隐私。
图7为本申请实施例提供的又一种认证方法的流程示意图。请参见图7,该方法可以包括:
S701、核心网设备向数据网设备发送第二状态更新请求消息,第二状态更新请求消息包括第一信息。
可选的,核心网设备可以对用户的状态进行检测,在核心网设备检测到用户的状态异常时,核心网设备可以向数据网设备发送第二状态更新请求消息。
例如,第二状态更新请求可以用于请求数据网设备对用户进行重新身份认证、对用户的权限进行更新操作(修改、吊销操作等)等。
S702、数据网设备根据第一信息确定DUI,并根据DUI更新用户的状态。
其中,数据网设备中存储有DUI和第一信息之间的对应关系,数据网设备可以根据第一信息和该对应关系,确定得到DUI。
例如,当第二状态更新请求消息用于请求数据网设备对用户进行重新身份认证时,则数据网设备对用户的身份进行重新认证,对用户的身份进行认证的过程可以参见图2-图5 所示的实施例,此处不再进行赘述。当第二状态更新请求消息用于请求对用户的权限进行更新时,则数据网设备核实该用户的权限,同意或拒绝对用户的权限进行更新操作。
S703、数据网设备向核心网设备发送第二状态更新响应消息。
其中,第二状态更新响应消息中包括第一信息。
核心网设备可以根据第二状态更新响应消息确定第一信息所指示的用户的最新状态。
S704、核心网设备向终端设备发送通知消息。
其中,通知消息中包括第一信息。通知消息用于指示第一信息对应的用户的状态发生更新。
可选的,核心网设备可以在第一状态更新请求消息中获取终端设备的标识,并根据终端设备的标识向终端设备发送通知消息。
其中,终端设备中存储有DUI和第一信息的对应关系。一个终端设备可以对应一个或多个用户,因此,在终端设备接收到通知消息后,可以根据通知消息中的第一信息和该对应关系确定对应的用户。
在图7所示的实施例中,核心网设备可以请求数据网设备对用户的状态进行更新操作,数据网设备与核心网设备之间交互的信息中包括第一信息,这样,核心网设备可以根据第一信息识别对应的用户,以和数据网设备实现对用户的状态的更新操作,在上述过程中,在与核心网设备通信的过程中,用户的DUI对核心网设备、UE和数据网之间的传输中的其他设备为不可见的,避免了DUI的泄露,保障了用户的隐私。
图8为本申请实施例提供的一种认证装置的结构示意图。该认证装置10可以应用于核心网设备10。请参见图8,该认证装置10可以包括发送模块11和接收模块12,其中,
所述发送模块11用于,向数据网设备发送用户的认证请求消息,所述认证请求消息用于请求所述数据网设备对所述用户进行身份认证;
所述接收模块12用于,设备接收所述数据网设备发送的认证响应消息,所述认证响应消息包括第一信息,所述第一信息用于指示所述用户的用户身份信息。
可选的,发送模块11可以执行上述方法实施例中与核心网设备的发送功能相关的步骤,例如,发送模块11可以执行图2实施例中的S201,图3实施例中的S304和S308,图4实施例中的S403、S406和S410,图5实施例中的S503、S506和S509,图6实施例中的S604,图7实施例中的S701和S704。
可选的,接收模块12可以执行上述方法实施例中与核心网设备的发送功能相关的步骤,例如,发送模块11可以执行图2实施例中的S203,图3实施例中的S301和S307,图4实施例中的S401、S404和S409,图5实施例中的S501、S504和S508,图6实施例中的S601和S603,图7实施例中的S703。
本申请实施例所示的认证装置10可以执行上述方法实施例所示的技术方案,其实现原理以及有益效果类似,此处不再进行赘述。
在一种可能的实施方式中,所述认证请求消息中包括所述第一信息。
在一种可能的实施方式中,所述认证请求消息还包括所述用户身份信息,所述用户身份信息位于所述认证请求消息的容器中,所述第一信息位于所述认证请求消息的容器之外。
在一种可能的实施方式中,所述接收模块12还用于,在所述发送模块11向数据网设 备发送认证请求消息之前,接收终端设备发送的注册请求消息,所述注册请求消息中包括所述第一信息和所述用户身份信息,所述用户身份信息位于所述注册请求消息的容器中,所述第一信息位于所述注册请求消息的容器之外。
在一种可能的实施方式中,所述发送模块11还用于,在所述发送模块11向数据网设备发送认证请求消息之前,向终端设备发送用户身份请求消息;
所述接收模块12还用于,接收所述终端设备发送的用户身份响应消息,所述用户身份响应消息包括所述第一信息和所述用户身份信息。
图9为本申请实施例提供的另一种认证装置的结构示意图。在图8所示实施例的基础上,请参见图9,认证装置10还可以包括处理模块13,其中,所述处理模块13用于:
获取所述终端设备的标识;
存储所述终端设备的标识和所述第一信息之间的对应关系。
在一种可能的实施方式中,所述终端设备的标识包括终端永久标识符SUPI和/或隐藏的终端签约标识符SUCI。
在一种可能的实施方式中,所述处理模块13还用于,获取所述第一信息,并根据所述第一信息,确定所述数据网设备的地址信息;
所述发送模块11具体用于,根据所述地址信息向所述数据网设备发送所述认证请求消息。
在一种可能的实施方式中,所述切片信息为网络切片选择辅助信息NSSAI。
在一种可能的实施方式中,所述接收模块12还用于,接收所述数据网设备发送的第一状态更新请求消息,所述第一状态更新请求消息包括所述第一信息;
所述处理模块13还用于,根据所述第一状态更新请求消息更新所述第一信息对应的用户的状态;
所述发送模块11还用于,向所述数据网设备发送第一状态更新响应消息,所述第一状态更新响应消息包括所述第一信息。
在一种可能的实施方式中,所述发送模块11还用于,向所述数据网设备发送第二状态更新请求消息,所述第二状态更新请求消息包括所述第一信息;
所述接收模块12还用于,接收所述数据网设备发送的第二状态更新响应消息,所述第二状态更新响应消息中包括所述第一信息。
在一种可能的实施方式中,所述发送模块11还用于,向所述终端设备发送通知消息,所述通知消息包括所述第一信息,所述通知消息用于指示所述第一信息对应的用户的状态发生更新。
本申请实施例所示的认证装置10可以执行上述方法实施例所示的技术方案,其实现原理以及有益效果类似,此处不再进行赘述。
图10为本申请实施例提供的又一种认证装置的结构示意图。该认证装置20可以应用于数据网设备。请参见图10,该认证装置20可以包括接收模块21、处理模块22和发送模块23,其中,
所述接收模块21用于,接收核心网设备发送的用户的认证请求消息;
所述处理模块22用于,根据所述认证请求消息对所述用户进行身份认证;
所述发送模块23用于,向所述核心网设备发送认证响应消息,所述认证响应消息包 括第一信息,所述第一信息用于指示所述用户的数据网用户身份信息用户身份信息。
可选的,接收模块21可以执行上述方法实施例中与核心网设备的发送功能相关的步骤,例如,发送模块11可以执行图2实施例中的S201,图3实施例中的S304,图4实施例中的S406,图5实施例中的S506,图6实施例中的S604,图7实施例中的S704。
可选的,处理模块22可以执行上述方法实施例中与核心网设备的发送功能相关的步骤,例如,发送模块11可以执行图2实施例中的S202,图3实施例中的S305-S306,图4实施例中的S407-S408,图5实施例中的S507,图6实施例中的S602,图7实施例中的S702。
可选的,发送模块23可以执行上述方法实施例中与核心网设备的发送功能相关的步骤,例如,发送模块11可以执行图2实施例中的S203,图3实施例中的S307,图4实施例中的S409,图5实施例中的S508,图6实施例中的S601和S603,图7实施例中的S703。
本申请实施例所示的认证装置20可以执行上述方法实施例所示的技术方案,其实现原理以及有益效果类似,此处不再进行赘述。
在一种可能的实施方式中,所述认证请求消息中包括所述第一信息。
在一种可能的实施方式中,所述认证请求消息还包括所述用户身份信息,所述用户身份信息位于所述认证请求消息的容器中,所述第一信息位于所述认证请求消息的容器之外。
在一种可能的实施方式中,所述认证请求消息包括所述第一信息;所述处理模块22具体用于:
根据所述第一信息确定所述用户身份信息;
根据所述用户身份信息,对所述用户进行身份认证。
在一种可能的实施方式中,所述认证请求消息包括所述第一信息;所述处理模块22具体用于:
所述数据网设备根据所述第一信息对所述用户进行身份认证。
在一种可能的实施方式中,所述认证请求消息包括所述用户身份信息;所述处理模块22还用于,在所述发送模块23向所述核心网设备发送认证响应消息之前,根据所述用户身份信息确定所述第一信息。
在一种可能的实施方式中,所述发送模块23还用于,向所述核心网设备发送第一状态更新请求消息,所述第一状态更新请求消息包括所述第一信息,所述第一状态更新请求消息用于请求所述核心网设备对所述第一信息所指示的用户的状态进行更新;
所述接收模块21还用于,接收所述核心网设备发送的第一状态更新响应消息,所述第一状态更新响应消息包括所述第一信息。
在一种可能的实施方式中,所述接收模块21还用于,接收所述核心网设备发送的第二状态更新请求消息,所述第二状态更新请求消息包括所述第一信息;
所述处理模块22还用于,根据所述第一信息确定所述用户身份信息,并根据所述用户身份信息更新所述用户的状态;
所述发送模块23还用于,向所述核心网设备发送第二状态更新响应消息,第二所述状态更新响应消息中包括所述第一信息。
本申请实施例所示的认证装置10可以执行上述方法实施例所示的技术方案,其实现 原理以及有益效果类似,此处不再进行赘述。
图11为本申请实施例提供的一种认证装置的硬件结构示意图。请参见图11,该认证装置30包括:存储器31、处理器32、接收器33和发送器34,其中,存储器31和处理器32通信;示例性的,存储器31、处理器32、接收器33和发送器34可以通过通信总线35通信,所述存储器31用于存储计算机程序,所述处理器32执行所述计算机程序实现上述认证方法。
可选的,本申请所示处理器32可以实现图9实施例中处理模块13的功能,接收器33可以实现图8-9实施例中接收模块12的功能,发送器34可以实现图8-9实施例中发送模块11的功能,此处不再进行赘述。
可选的,上述处理器32可以是中央处理单元(Central Processing Unit,CPU),还可以是其他通用处理器、数字信号处理器(Digital Signal Processor,DSP)、专用集成电路(Application Specific Integrated Circuit,ASIC)等。通用处理器可以是微处理器或者该处理器也可以是任何常规的处理器等。结合本申请所公开的认证方法实施例中的步骤可以直接体现为硬件处理器执行完成,或者用处理器中的硬件及软件模块组合执行完成。
图12为本申请实施例提供的另一种认证装置的硬件结构示意图。请参见图12,该认证装置40包括:存储器41、处理器42、接收器43和发送器44,其中,存储器41和处理器42通信;示例性的,存储器41、处理器42、接收器43和发送器44可以通过通信总线45通信,所述存储器41用于存储计算机程序,所述处理器42执行所述计算机程序实现上述认证方法。
可选的,本申请所示的处理器42可以实现图10实施例中的处理模块22的功能,接收器43可以实现图10实施例中接收模块21的功能,发送器44可以实现图10实施例中发送模块23的功能,此处不再进行赘述。
可选的,上述处理器可以是CPU,还可以是其他通用处理器、DSP、ASIC等。通用处理器可以是微处理器或者该处理器也可以是任何常规的处理器等。结合本申请所公开的认证方法实施例中的步骤可以直接体现为硬件处理器执行完成,或者用处理器中的硬件及软件模块组合执行完成。
本申请提供一种存储介质,所述存储介质用于存储计算机程序,所述计算机程序用于实现上述实施例所述的认证方法。
实现上述各方法实施例的全部或部分步骤可以通过程序指令相关的硬件来完成。前述的程序可以存储于一可读取存储器中。该程序在执行时,执行包括上述各方法实施例的步骤;而前述的存储器(存储介质)包括:只读存储器(英文:read-only memory,缩写:ROM)、RAM、快闪存储器、硬盘、固态硬盘、磁带(英文:magnetic tape)、软盘(英文:floppy disk)、光盘(英文:optical disc)及其任意组合。
本申请实施例是参照根据本申请实施例的方法、设备(系统)、和计算机程序产品的流程图和/或方框图来描述的。应理解可由计算机程序指令实现流程图和/或方框图中的每一流程和/或方框、以及流程图和/或方框图中的流程和/或方框的结合。可提供这些计算机程序指令到通用计算机、专用计算机、嵌入式处理机或其他可编程数据处理设备的处理单元以产生一个机器,使得通过计算机或其他可编程数据处理设备的处理单元执行的指令产生用于实现在流程图一个流程或多个流程和/或方框图一个方框或多个方框中指 定的功能的装置。
这些计算机程序指令也可存储在能引导计算机或其他可编程数据处理设备以特定方式工作的计算机可读存储器中,使得存储在该计算机可读存储器中的指令产生包括指令装置的制造品,该指令装置实现在流程图一个流程或多个流程和/或方框图一个方框或多个方框中指定的功能。
这些计算机程序指令也可装载到计算机或其他可编程数据处理设备上,使得在计算机或其他可编程设备上执行一系列操作步骤以产生计算机实现的处理,从而在计算机或其他可编程设备上执行的指令提供用于实现在流程图一个流程或多个流程和/或方框图一个方框或多个方框中指定的功能的步骤。
显然,本领域的技术人员可以对本申请实施例进行各种改动和变型而不脱离本申请的精神和范围。这样,倘若本申请实施例的这些修改和变型属于本申请权利要求及其等同技术的范围之内,则本申请也意图包含这些改动和变型在内。
在本申请中,术语“包括”及其变形可以指非限制性的包括;术语“或”及其变形可以指“和/或”。本本申请中术语“第一”、“第二”等是用于区别类似的对象,而不必用于描述特定的顺序或先后次序。本申请中,“多个”是指两个或两个以上。“和/或”,描述关联对象的关联关系,表示可以存在三种关系,例如,A和/或B,可以表示:单独存在A,同时存在A和B,单独存在B这三种情况。字符“/”一般表示前后关联对象是一种“或”的关系。
Claims (16)
- 一种认证方法,其特征在于,包括:核心网设备向数据网设备发送用户的认证请求消息,所述认证请求消息用于请求所述数据网设备对所述用户进行身份认证;所述核心网设备接收所述数据网设备发送的认证响应消息,所述认证响应消息包括第一信息,所述第一信息用于指示所述用户的用户身份信息。
- 根据权利要求1所述的方法,其特征在于,所述认证请求消息中包括所述第一信息。
- 根据权利要求2所述的方法,其特征在于,所述认证请求消息还包括所述用户身份信息,所述用户身份信息位于所述认证请求消息的容器中,所述第一信息位于所述认证请求消息的容器之外。
- 根据权利要求3所述的方法,其特征在于,所述核心网设备向数据网设备发送认证请求消息之前,还包括:所述核心网设备接收终端设备发送的注册请求消息,所述注册请求消息中包括所述第一信息和所述用户身份信息,所述用户身份信息位于所述注册请求消息的容器中,所述第一信息位于所述注册请求消息的容器之外。
- 根据权利要求3所述的方法,其特征在于,所述核心网设备向数据网设备发送认证请求消息之前,还包括:所述核心网设备向终端设备发送用户身份请求消息;所述核心网设备接收所述终端设备发送的用户身份响应消息,所述用户身份响应消息包括所述第一信息和所述用户身份信息。
- 根据权利要求1-5任一项所述的方法,其特征在于,所述方法还包括:所述核心网设备获取终端设备的标识;所述核心网设备存储所述终端设备的标识和所述第一信息之间的对应关系。
- 根据权利要求1-6任一项所述的方法,其特征在于,所述核心网设备向数据网设备发送用户的认证请求消息,包括:所述核心网设备获取所述第一信息;所述核心网设备根据所述第一信息,确定所述数据网设备的地址信息;所述核心网设备根据所述地址信息向所述数据网设备发送所述认证请求消息。
- 一种认证装置,其特征在于,包括发送模块和接收模块,其中,所述发送模块用于,向数据网设备发送用户的认证请求消息,所述认证请求消息用于请求所述数据网设备对所述用户进行身份认证;所述接收模块用于,设备接收所述数据网设备发送的认证响应消息,所述认证响应消息包括第一信息,所述第一信息用于指示所述用户的用户身份信息。
- 根据权利要求8所述的装置,其特征在于,所述认证请求消息中包括所述第一信息。
- 根据权利要求9所述的装置,其特征在于,所述认证请求消息还包括所述用户身份信息,所述用户身份信息位于所述认证请求消息的容器中,所述第一信息位于所述认证 请求消息的容器之外。
- 根据权利要求10所述的装置,其特征在于,所述接收模块还用于,在所述发送模块向数据网设备发送认证请求消息之前,接收终端设备发送的注册请求消息,所述注册请求消息中包括所述第一信息和所述用户身份信息,所述用户身份信息位于所述注册请求消息的容器中,所述第一信息位于所述注册请求消息的容器之外。
- 根据权利要求10所述的装置,其特征在于,所述发送模块还用于,在所述发送模块向数据网设备发送认证请求消息之前,向终端设备发送用户身份请求消息;所述接收模块还用于,接收所述终端设备发送的用户身份响应消息,所述用户身份响应消息包括所述第一信息和所述用户身份信息。
- 根据权利要求8-12任一项所述的装置,其特征在于,所述装置还包括处理模块,其中,所述处理模块用于:获取终端设备的标识;存储所述终端设备的标识和所述第一信息之间的对应关系。
- 根据权利要求8-13任一项所述的装置,其特征在于,处理模块还用于,获取所述第一信息,并根据所述第一信息,确定所述数据网设备的地址信息;所述发送模块具体用于,根据所述地址信息向所述数据网设备发送所述认证请求消息。
- 一种认证装置,其特征在于,包括存储器和处理器,所述处理器执行所述存储器中的程序指令,用于实现权利要求1-7任一项所述的认证方法。
- 一种存储介质,其特征在于,所述存储介质用于存储计算机程序,所述计算机程序被计算机或处理器执行时用于实现权利要求1-7任一项所述的认证方法。
Priority Applications (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| EP20787999.0A EP3944649A4 (en) | 2019-04-12 | 2020-03-04 | VERIFICATION METHOD, DEVICE AND DEVICE |
| US17/498,175 US11871223B2 (en) | 2019-04-12 | 2021-10-11 | Authentication method and apparatus and device |
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| CN201910292439.9 | 2019-04-12 | ||
| CN201910292439.9A CN111818516B (zh) | 2019-04-12 | 2019-04-12 | 认证方法、装置及设备 |
Related Child Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| US17/498,175 Continuation US11871223B2 (en) | 2019-04-12 | 2021-10-11 | Authentication method and apparatus and device |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| WO2020207156A1 true WO2020207156A1 (zh) | 2020-10-15 |
Family
ID=72750844
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| PCT/CN2020/077791 Ceased WO2020207156A1 (zh) | 2019-04-12 | 2020-03-04 | 认证方法、装置及设备 |
Country Status (4)
| Country | Link |
|---|---|
| US (1) | US11871223B2 (zh) |
| EP (1) | EP3944649A4 (zh) |
| CN (1) | CN111818516B (zh) |
| WO (1) | WO2020207156A1 (zh) |
Cited By (3)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN114531254A (zh) * | 2020-10-30 | 2022-05-24 | 中国移动通信有限公司研究院 | 一种认证信息获取方法、装置、相关设备和存储介质 |
| WO2022233534A1 (en) * | 2021-05-06 | 2022-11-10 | Telefonaktiebolaget Lm Ericsson (Publ) | Application-specific gpsi retrieval |
| WO2024213133A1 (zh) * | 2023-04-12 | 2024-10-17 | 中国移动通信有限公司研究院 | 终端认证验证方法及终端认证验证装置 |
Families Citing this family (11)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US12238076B2 (en) * | 2018-10-02 | 2025-02-25 | Arista Networks, Inc. | In-line encryption of network data |
| CN112105015B (zh) * | 2019-06-17 | 2022-08-26 | 华为技术有限公司 | 二级认证的方法和装置 |
| US12342214B2 (en) * | 2019-09-30 | 2025-06-24 | Telefonaktiebolaget Lm Ericsson (Publ) | Terminal device, application server, network exposure function node and methods therein |
| EP3993477A4 (en) * | 2020-04-02 | 2022-10-05 | NEC Corporation | Wireless access network node device, amf device, and method for same |
| CN112423301B (zh) * | 2020-11-02 | 2023-12-22 | 中国联合网络通信集团有限公司 | 专网注册管理方法和amf网元 |
| CN114615665B (zh) * | 2020-12-04 | 2024-10-29 | 中国电信股份有限公司 | 终端认证方法、装置和存储介质 |
| CN115190649A (zh) * | 2021-04-02 | 2022-10-14 | 华为技术有限公司 | 一种会话控制的方法、装置和系统 |
| CN115913584B (zh) * | 2021-08-10 | 2025-04-15 | 中国电信股份有限公司 | 鉴权方法、装置、电子设备和计算机可读存储介质 |
| CN118139047A (zh) * | 2022-11-28 | 2024-06-04 | 大唐移动通信设备有限公司 | 一种接入点认证方法、装置及可读存储介质 |
| CN120186595A (zh) * | 2023-12-19 | 2025-06-20 | 维沃移动通信有限公司 | 通信方法、终端及网络侧设备 |
| CN120456019A (zh) * | 2024-02-08 | 2025-08-08 | 华为技术有限公司 | 一种通信方法和通信装置 |
Citations (4)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| WO2018077232A1 (zh) * | 2016-10-31 | 2018-05-03 | 华为技术有限公司 | 一种网络认证方法、相关设备及系统 |
| CN108513289A (zh) * | 2017-02-27 | 2018-09-07 | 中兴通讯股份有限公司 | 一种终端标识的处理方法、装置及相关设备 |
| US20180317086A1 (en) * | 2017-01-27 | 2018-11-01 | Telefonaktiebolaget Lm Ericsson (Publ) | Secondary Authentication of a User Equipment |
| WO2018208949A1 (en) * | 2017-05-09 | 2018-11-15 | Intel IP Corporation | Privacy protection and extensible authentication protocol authentication and authorization in cellular networks |
Family Cites Families (10)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US9716996B2 (en) * | 2013-05-21 | 2017-07-25 | Brocade Communications Systems, Inc. | Method and system for selective and secure interaction of BYOD (bring your own device) with enterprise network through mobile wireless networks |
| CN104618891B (zh) * | 2013-11-04 | 2018-10-19 | 华为终端(东莞)有限公司 | 一种通信方法、终端及核心网实体 |
| US10136315B2 (en) * | 2014-04-17 | 2018-11-20 | Guang Gong | Password-less authentication system, method and device |
| CN104899497B (zh) * | 2015-05-20 | 2018-03-20 | 李明 | 不具有sam模块的身份证阅读装置、sam装置及系统 |
| CN107026823B (zh) * | 2016-02-02 | 2020-08-28 | 普天信息技术有限公司 | 应用于无线局域网wlan中的接入认证方法和终端 |
| CN110166246B (zh) * | 2016-03-30 | 2022-07-08 | 创新先进技术有限公司 | 基于生物特征的身份注册、认证的方法和装置 |
| JP2018056896A (ja) * | 2016-09-30 | 2018-04-05 | 日本電気株式会社 | 基地局、無線端末、サーバ、基地局の制御方法 |
| JP2019004409A (ja) * | 2017-06-19 | 2019-01-10 | シャープ株式会社 | 端末装置、コアネットワーク内の装置、データネットワーク内の装置、及び通信制御方法 |
| US10631224B2 (en) * | 2017-10-05 | 2020-04-21 | Blackberry Limited | Authenticating user equipments through relay user equipments |
| EP3909277A1 (en) * | 2019-01-10 | 2021-11-17 | Convida Wireless, LLC | Apparatus, system, method, and computer-readable medium for performing a message service and identity service in a 5g network |
-
2019
- 2019-04-12 CN CN201910292439.9A patent/CN111818516B/zh active Active
-
2020
- 2020-03-04 EP EP20787999.0A patent/EP3944649A4/en active Pending
- 2020-03-04 WO PCT/CN2020/077791 patent/WO2020207156A1/zh not_active Ceased
-
2021
- 2021-10-11 US US17/498,175 patent/US11871223B2/en active Active
Patent Citations (4)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| WO2018077232A1 (zh) * | 2016-10-31 | 2018-05-03 | 华为技术有限公司 | 一种网络认证方法、相关设备及系统 |
| US20180317086A1 (en) * | 2017-01-27 | 2018-11-01 | Telefonaktiebolaget Lm Ericsson (Publ) | Secondary Authentication of a User Equipment |
| CN108513289A (zh) * | 2017-02-27 | 2018-09-07 | 中兴通讯股份有限公司 | 一种终端标识的处理方法、装置及相关设备 |
| WO2018208949A1 (en) * | 2017-05-09 | 2018-11-15 | Intel IP Corporation | Privacy protection and extensible authentication protocol authentication and authorization in cellular networks |
Non-Patent Citations (2)
| Title |
|---|
| HUAWEI ET AL.: "Update of Solution #2.14 with EAP-PSK Authentication Method", 3GPP TSG SA WG3 (SECURITY) MEETING #86 S3-170436, 10 February 2017 (2017-02-10), XP051217784, DOI: 20200521161424A * |
| See also references of EP3944649A4 |
Cited By (4)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN114531254A (zh) * | 2020-10-30 | 2022-05-24 | 中国移动通信有限公司研究院 | 一种认证信息获取方法、装置、相关设备和存储介质 |
| CN114531254B (zh) * | 2020-10-30 | 2023-03-31 | 中国移动通信有限公司研究院 | 一种认证信息获取方法、装置、相关设备和存储介质 |
| WO2022233534A1 (en) * | 2021-05-06 | 2022-11-10 | Telefonaktiebolaget Lm Ericsson (Publ) | Application-specific gpsi retrieval |
| WO2024213133A1 (zh) * | 2023-04-12 | 2024-10-17 | 中国移动通信有限公司研究院 | 终端认证验证方法及终端认证验证装置 |
Also Published As
| Publication number | Publication date |
|---|---|
| US11871223B2 (en) | 2024-01-09 |
| US20220030429A1 (en) | 2022-01-27 |
| EP3944649A4 (en) | 2022-04-27 |
| CN111818516A (zh) | 2020-10-23 |
| CN111818516B (zh) | 2022-10-18 |
| EP3944649A1 (en) | 2022-01-26 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| WO2020207156A1 (zh) | 认证方法、装置及设备 | |
| US20250350946A1 (en) | Communication method, communication apparatus, and communication system | |
| US12356199B2 (en) | Communication method, apparatus, and system for verifying identity of user equipment by network device | |
| WO2021017550A1 (zh) | 一种事件报告的发送方法、装置及系统 | |
| WO2020253408A1 (zh) | 二级认证的方法和装置 | |
| US20250184731A1 (en) | Communication method and communication apparatus | |
| US20250063364A1 (en) | Communication method and network element device | |
| WO2021063298A1 (zh) | 实现外部认证的方法、通信装置及通信系统 | |
| US12581309B2 (en) | Slice service verification method and apparatus | |
| US20250279901A1 (en) | Communication method and communication apparatus | |
| WO2023016160A1 (zh) | 一种会话建立方法和相关装置 | |
| US20250227465A1 (en) | Communication method and communication apparatus | |
| CN113645621B (zh) | 一种安全通信方法及装置 | |
| EP4135376A1 (en) | Method and device for secure communication | |
| WO2021253859A1 (zh) | 切片认证方法及系统 | |
| US20250126476A1 (en) | Security decision negotiation method and network element | |
| EP2378802B1 (en) | A wireless telecommunications network, and a method of authenticating a message | |
| WO2020215272A1 (zh) | 通信方法、通信装置和通信系统 | |
| CN104735749B (zh) | 一种接入网络的方法及无线路由器、门户平台服务器 | |
| US20250392582A1 (en) | Communication method and communication apparatus | |
| US20250330795A1 (en) | Communication method and communication apparatus | |
| US20260089499A1 (en) | Systems and methods for managing network security keys between a home network and a visited network | |
| WO2025031156A1 (zh) | 通信方法和通信装置 | |
| CN119450433A (zh) | 通信方法和通信装置 |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| 121 | Ep: the epo has been informed by wipo that ep was designated in this application |
Ref document number: 20787999 Country of ref document: EP Kind code of ref document: A1 |
|
| NENP | Non-entry into the national phase |
Ref country code: DE |
|
| ENP | Entry into the national phase |
Ref document number: 2020787999 Country of ref document: EP Effective date: 20211020 |