WO2024092801A1 - 认证方法、装置、通信设备及存储介质 - Google Patents
认证方法、装置、通信设备及存储介质 Download PDFInfo
- Publication number
- WO2024092801A1 WO2024092801A1 PCT/CN2022/130092 CN2022130092W WO2024092801A1 WO 2024092801 A1 WO2024092801 A1 WO 2024092801A1 CN 2022130092 W CN2022130092 W CN 2022130092W WO 2024092801 A1 WO2024092801 A1 WO 2024092801A1
- Authority
- WO
- WIPO (PCT)
- Prior art keywords
- ees
- authentication
- eec
- information
- ecs
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Ceased
Links
Images
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W12/00—Security arrangements; Authentication; Protecting privacy or anonymity
- H04W12/06—Authentication
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/08—Network architectures or network communication protocols for network security for authentication of entities
- H04L63/0869—Network architectures or network communication protocols for network security for authentication of entities for achieving mutual authentication
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/20—Network architectures or network communication protocols for network security for managing network security; network security policies in general
- H04L63/205—Network architectures or network communication protocols for network security for managing network security; network security policies in general involving negotiation or determination of the one or more network security mechanisms to be used, e.g. by negotiation between the client and the server or between peers or by selection according to the capabilities of the entities involved
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/32—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials
- H04L9/3271—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials using challenge-response
- H04L9/3273—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials using challenge-response for mutual authentication
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L2209/00—Additional information or applications relating to cryptographic mechanisms or cryptographic arrangements for secret or secure communication H04L9/00
- H04L2209/80—Wireless
Definitions
- the present disclosure relates to the field of wireless communication technology but is not limited to the field of wireless communication technology, and in particular to an authentication method, apparatus, communication device and storage medium.
- edge enabler client EEC
- ECS edge configuration server
- EES edge enabler server
- TLS Transport Layer Security
- the TLS authentication method involves multiple authentication mechanisms. For these multiple authentication mechanisms, if the authentication mechanism adopted between EEC, ECS and/or EES cannot be determined, the authentication between EEC, ECS and/or EES cannot be synchronized, and low security and reliability problems may occur when performing authentication.
- the embodiments of the present disclosure disclose an authentication method, an apparatus, a communication device and a storage medium.
- an authentication method is provided, wherein the method is performed by an edge enabling client EEC, and the method includes:
- the service provision request information is used to request to obtain the security authentication method supported by the edge enabling server EES.
- an authentication method is provided, wherein the method is executed by an edge configuration client ECS, and the method includes:
- the service provision request information is used to request to obtain the security authentication method supported by the edge enabling server EES.
- an authentication method is provided, wherein the method is performed by an edge enabling server EES, and the method includes:
- the authentication capability request information is used to request the authentication capability information of the EES, wherein the authentication capability information of the EES indicates the security authentication method supported by the EES.
- an authentication device wherein the device includes:
- a sending module is configured to send service provision request information to the edge configuration server ECS;
- the service provision request information is used to request to obtain the security authentication method supported by the edge enabling server EES.
- an authentication device wherein the device includes:
- a receiving module configured to receive service provision request information sent by the EEC
- the service provision request information is used to request to obtain the security authentication method supported by the edge enabling server EES.
- an authentication device wherein the device comprises:
- a receiving module configured to receive authentication capability request information sent by the ECS
- the authentication capability request information is used to request the authentication capability information of the EES, wherein the authentication capability information of the EES indicates the security authentication method supported by the EES.
- an authentication system is provided, wherein the system includes EEC, ECS and EES, wherein the EEC is used to implement the method performed by the EEC as described in any embodiment of the present disclosure; the ECS is used to implement the method performed by the ECS as described in any embodiment of the present disclosure; and the EES is used to implement the method performed by the EES as described in any embodiment of the present disclosure.
- a communication device including:
- a memory for storing instructions executable by the processor
- the processor is configured to implement the method described in any embodiment of the present disclosure when running the executable instructions.
- a computer storage medium stores a computer executable program, and when the executable program is executed by a processor, the method described in any embodiment of the present disclosure is implemented.
- a service provision request message is sent to the edge configuration server ECS; wherein the service provision request message is used to request the security authentication method supported by the edge enabling server EES.
- the service provision request message sent to the edge configuration server ECS can request the security authentication method supported by the edge enabling server EES
- the authentication between the ECS and the EES can be performed based on the security authentication method supported by the EES indicated by the authentication capability information of the EES, so that the data transmission between the ECS and the EES is more secure and reliable, and the security and reliability of communication are improved.
- Fig. 1 is a schematic structural diagram of a wireless communication system according to an exemplary embodiment.
- Fig. 2 is a schematic flow chart of an authentication method according to an exemplary embodiment.
- Fig. 3 is a schematic flow chart of an authentication method according to an exemplary embodiment.
- Fig. 4 is a schematic flow chart showing an authentication method according to an exemplary embodiment.
- Fig. 5 is a schematic flow chart of an authentication method according to an exemplary embodiment.
- Fig. 6 is a schematic flow chart of an authentication method according to an exemplary embodiment.
- Fig. 7 is a schematic flow chart of an authentication method according to an exemplary embodiment.
- Fig. 8 is a schematic flow chart of an authentication method according to an exemplary embodiment.
- Fig. 9 is a schematic flow chart of an authentication method according to an exemplary embodiment.
- Fig. 10 is a schematic flow chart of an authentication method according to an exemplary embodiment.
- Fig. 11 is a schematic flow chart of an authentication method according to an exemplary embodiment.
- Fig. 12 is a schematic flow chart of an authentication method according to an exemplary embodiment.
- Fig. 13 is a schematic structural diagram of an authentication method according to an exemplary embodiment.
- Fig. 14 is a schematic structural diagram of an authentication method according to an exemplary embodiment.
- Fig. 15 is a schematic diagram showing the structure of an authentication device according to an exemplary embodiment.
- Fig. 16 is a schematic diagram showing the structure of an authentication device according to an exemplary embodiment.
- Fig. 17 is a schematic diagram showing the structure of an authentication device according to an exemplary embodiment.
- Fig. 18 is a schematic diagram showing the structure of an authentication system according to an exemplary embodiment.
- Fig. 19 is a schematic diagram showing the structure of a terminal according to an exemplary embodiment.
- Fig. 20 is a block diagram of a base station according to an exemplary embodiment.
- first, second, third, etc. may be used to describe various information in the disclosed embodiments, these information should not be limited to these terms. These terms are only used to distinguish the same type of information from each other.
- first information may also be referred to as the second information, and similarly, the second information may also be referred to as the first information.
- word "if” as used herein may be interpreted as "at the time of” or "when” or "in response to determining”.
- FIG1 shows a schematic diagram of the structure of a wireless communication system provided by an embodiment of the present disclosure.
- the wireless communication system is a communication system based on mobile communication technology, and the wireless communication system may include: a plurality of user equipments 110 and a plurality of base stations 120 .
- the user equipment 110 may be a device that provides voice and/or data connectivity to a user.
- the user equipment 110 may communicate with one or more core networks via a radio access network (RAN).
- RAN radio access network
- the user equipment 110 may be an IoT user equipment, such as a sensor device, a mobile phone, and a computer with an IoT user equipment.
- IoT user equipment such as a sensor device, a mobile phone, and a computer with an IoT user equipment.
- it may be a fixed, portable, pocket-sized, handheld, computer-built-in, or vehicle-mounted device.
- a station STA
- a subscriber unit a subscriber station, a mobile station, a mobile station, a remote station, an access point, a remote terminal, an access terminal, a user terminal, a user agent, a user device, or a user equipment.
- the user equipment 110 may also be a device of an unmanned aerial vehicle.
- the user device 110 may be a vehicle-mounted device, such as a driving computer with wireless communication function, or a wireless user device connected to a driving computer.
- the user device 110 may be a roadside device, such as a street lamp, a signal lamp, or other roadside device with wireless communication function.
- the base station 120 may be a network-side device in a wireless communication system.
- the wireless communication system may be a fourth generation mobile communication technology (4G) system, also known as a long term evolution (LTE) system; or, the wireless communication system may be a 5G system, also known as a new air interface system or a 5G NR system. Alternatively, the wireless communication system may be a next generation system of the 5G system.
- the access network in the 5G system may be called NG-RAN (New Generation-Radio Access Network).
- the base station 120 can be an evolved base station (eNB) adopted in the 4G system.
- the base station 120 can also be a base station (gNB) adopting a centralized distributed architecture in the 5G system.
- the base station 120 adopts a centralized distributed architecture it usually includes a centralized unit (central unit, CU) and at least two distributed units (distributed units, DU).
- the centralized unit is provided with a packet data convergence protocol (Packet Data Convergence Protocol, PDCP) layer, a radio link layer control protocol (Radio Link Control, RLC) layer, and a media access control (Media Access Control, MAC) layer protocol stack;
- the distributed unit is provided with a physical (Physical, PHY) layer protocol stack.
- the specific implementation method of the base station 120 is not limited in the embodiment of the present disclosure.
- a wireless connection may be established between the base station 120 and the user equipment 110 via a wireless air interface.
- the wireless air interface is a wireless air interface based on the fourth generation mobile communication network technology (4G) standard; or, the wireless air interface is a wireless air interface based on the fifth generation mobile communication network technology (5G) standard, for example, the wireless air interface is a new air interface; or, the wireless air interface may also be a wireless air interface based on the next generation mobile communication network technology standard of 5G.
- an E2E (End to End) connection may also be established between the user devices 110.
- V2X vehicle-to-everything
- V2V vehicle to vehicle
- V2I vehicle to Infrastructure
- V2P vehicle to pedestrian
- the above-mentioned user equipment can be considered as the terminal equipment of the following embodiments.
- the wireless communication system may further include a network management device 130 .
- the network management device 130 may be a core network device in a wireless communication system, for example, the network management device 130 may be a mobility management entity (MME) in an evolved packet core (EPC). Alternatively, the network management device may also be other core network devices, such as a serving gateway (SGW), a public data network gateway (PGW), a policy and charging rules function (PCRF), or a home subscriber server (HSS).
- SGW serving gateway
- PGW public data network gateway
- PCRF policy and charging rules function
- HSS home subscriber server
- the embodiments of the present disclosure list multiple implementation methods to clearly illustrate the technical solutions of the embodiments of the present disclosure.
- the multiple embodiments provided by the embodiments of the present disclosure can be executed separately, or can be executed together with the methods of other embodiments of the embodiments of the present disclosure, or can be executed together with some methods in other related technologies separately or in combination; the embodiments of the present disclosure do not limit this.
- an authentication method is provided in this embodiment, wherein the method is executed by an edge enabling client EEC, and the method includes:
- Step 21 Send service provision request information to the edge configuration server ECS;
- the service provision request information is used to request to obtain the security authentication method supported by the edge enabling server EES.
- the terminal involved in the present disclosure may be, but is not limited to, a mobile phone, a wearable device, a vehicle-mounted terminal, a road side unit (RSU, Road Side Unit), a smart home terminal, an industrial sensor device and/or a medical device, etc.
- the terminal may be a Redcap terminal or a predetermined version of a new air interface NR terminal (for example, an R17 NR terminal).
- the edge enabling client EEC may be an application program running on the terminal, for example, a WeChat application program and a Weibo application program, and the like.
- a service provision request message is sent to an edge configuration server ECS; wherein the service provision request message is used to request a security authentication method supported by an edge enabling server EES; and the service provision request message includes the home network information of the terminal corresponding to the EEC.
- the home network information includes at least one of the home network identifier, the Authentication and Key Management for Applications (AKMA) key identifier (A-KID, AKMA Key Identifier) and the session practice identifier (B-TID, Bootstrapping Transaction Identifier), which can be used to identify the home network of the terminal or EEC.
- AKMA Authentication and Key Management for Applications
- A-KID Authentication and Key Management for Applications
- B-TID Bootstrapping Transaction Identifier
- a service provision request message is sent to an edge configuration server ECS; wherein the service provision request message is used to request to obtain a security authentication method supported by an edge enabling server EES.
- Authentication capability information of the EES sent by the ECS is received; wherein the authentication capability information of the EES indicates a security authentication method supported by the EES.
- the location information and/or application client profile (AC Profile) of the terminal corresponding to the EEC is sent to the ECS; after receiving the location information and/or application client profile of the terminal corresponding to the EEC, the ECS stores them in the ECS; the location information and/or application client profile of the terminal corresponding to the EEC is used by the ECS to identify the ECS.
- AC Profile application client profile
- service provision request information is sent to the edge configuration server ECS; wherein the service provision request information is used to request to obtain the security authentication mode supported by the edge enabling server EES.
- a service provision request message is sent to an edge configuration server ECS; wherein the service provision request message is used to request to obtain a security authentication method supported by an edge enabling server EES.
- Authentication capability information of the EES sent by the ECS and information for establishing a connection between the ECS and the EES are received; wherein the authentication capability information of the EES indicates the security authentication method supported by the EES.
- the EEC is configured with authentication capability information of the ECS, and the authentication capability information of the ECS indicates the security authentication methods supported by the ECS.
- the authentication capability information of the ECS is pre-configured in the EEC; or, the authentication capability information of the ECS is configured in the EEC by an edge-aware application client (Edge-aware AC); or, the authentication capability information of the ECS is configured in the EEC by a user.
- an authentication method for performing mutual authentication between the EEC and the ECS is determined; wherein the first authentication capability information includes at least one of the following: a security authentication method supported by the EEC; a security authentication method supported by the edge configuration server ECS; a security authentication method supported by the home network; and a security authentication method supported by the access network.
- an authentication mode for performing mutual authentication between the EEC and the ECS is determined. Authentication between the EEC and the ECS is performed based on the authentication mode. In response to the mutual authentication between the EEC and the ECS being successful, a transport layer security TLS connection is established between the EEC and the ECS.
- an authentication method for performing mutual authentication between the EEC and the ECS is determined. Authentication between the EEC and the ECS is performed based on the authentication method.
- a transport layer security TLS connection is established between the EEC and the ECS. Based on the TLS connection, a service provision request message is sent to the edge configuration server ECS; wherein the service provision request message is used to request a security authentication method supported by the edge enabling server EES.
- an authentication method for performing mutual authentication between the EEC and the ECS is determined. Authentication between the EEC and the ECS is performed based on the authentication method.
- a transport layer security TLS connection is established between the EEC and the ECS. Based on the TLS connection, the authentication capability information of the EES sent by the ECS is received; wherein the authentication capability information of the EES indicates the security authentication method supported by the EES.
- a service provision request message is sent to an edge configuration server ECS; wherein the service provision request message is used to request a security authentication method supported by an edge enabling server EES.
- Authentication capability information of the EES sent by the ECS is received; wherein the authentication capability information of the EES indicates a security authentication method supported by the EES.
- Based on the second authentication capability information an authentication method for performing mutual authentication between the EEC and the EES is determined; wherein the second authentication capability information includes at least one of the following: a security authentication method supported by the EEC; a security authentication method supported by the edge enabling server EES; a security authentication method supported by the home network; and a security authentication method supported by the access network.
- a service provision request message is sent to the edge configuration server ECS; wherein the service provision request message is used to request the security authentication method supported by the edge enabling server EES.
- the service provision request message sent to the edge configuration server ECS can request the security authentication method supported by the edge enabling server EES
- the authentication between the ECS and the EES can be performed based on the security authentication method supported by the EES indicated by the authentication capability information of the EES, so that the data transmission between the ECS and the EES is more secure and reliable, and the security and reliability of communication are improved.
- an authentication method is provided in this embodiment, wherein the method is executed by an edge enabling client EEC, and the method includes:
- Step 31 Based on the first authentication capability information, determine an authentication method for performing mutual authentication between the EEC and the ECS;
- the first authentication capability information includes at least one of the following:
- the EEC is configured with authentication capability information of the ECS, and the authentication capability information of the ECS indicates a security authentication method supported by the ECS.
- the authentication capability information of the ECS is pre-configured in the EEC; or, the authentication capability information of the ECS is configured in the EEC by an edge-sensitive application client AC; or, the authentication capability information of the ECS is configured in the EEC by a user.
- an authentication method for performing mutual authentication between the EEC and the ECS is determined; wherein the first authentication capability information includes at least one of the following: an authentication method supported by the EEC; a security authentication method supported by the edge configuration server ECS; a security authentication method supported by the home network; and a security authentication method supported by the access network.
- Authentication between the EEC and the ECS is performed based on the authentication method.
- a transport layer security TLS connection is established between the EEC and the ECS.
- an authentication method for performing mutual authentication between the EEC and the ECS is determined; wherein the first authentication capability information includes at least one of the following: an authentication method supported by the EEC; a security authentication method supported by the edge configuration server ECS; a security authentication method supported by the home network; and a security authentication method supported by the access network.
- Authentication between the EEC and the ECS is performed based on the authentication method.
- a transport layer security TLS connection is established between the EEC and the ECS.
- a service provision request information is sent to the edge configuration server ECS; wherein the service provision request information is used to request the acquisition of the security authentication method supported by the edge enabling server EES.
- an authentication method for performing mutual authentication between the EEC and the ECS is determined; wherein the first authentication capability information includes at least one of the following: an authentication method supported by the EEC; a security authentication method supported by the edge configuration server ECS; a security authentication method supported by the home network; and a security authentication method supported by the access network.
- Authentication between the EEC and the ECS is performed based on the authentication method.
- a transport layer security TLS connection is established between the EEC and the ECS.
- a service provision request information is sent to the edge configuration server ECS; wherein the service provision request information is used to request the security authentication method supported by the edge enabling server EES.
- the authentication capability information of the EES sent by the ECS and/or the information for establishing a connection between the ECS and the EES is received; wherein the authentication capability information of the EES indicates the security authentication method supported by the EES.
- the authentication capability information of the EES in response to the EES not being authorized to use authentication and key management AKMA in the access network or home network of the EEC, does not include the authentication method of transport layer security TLS based on AKMA; and/or, in response to the EES not being authorized to use AKMA in the access network or home network of the terminal corresponding to the EEC, the authentication capability information of the EES does not include the authentication method of transport layer security TLS based on AKMA; and/or, in response to the EES not being authorized to use general bootstrapping framework GBA in the access network or home network of the EEC, the authentication capability information of the EES does not include the authentication method of transport layer security TLS based on GBA; and/or, in response to the EES not being authorized to use GBA in the access network or home network of the terminal corresponding to the EEC, the authentication capability information of the EES does not include the authentication method of transport layer security TLS based on GBA.
- an authentication method is provided in this embodiment, wherein the method is executed by an edge enabling client EEC, and the method includes:
- Step 41 Receive the authentication capability information of EES sent by ECS;
- the authentication capability information of the EES indicates the security authentication method supported by the EES.
- a service provision request message is sent to an edge configuration server ECS; wherein the service provision request message is used to request to obtain a security authentication method supported by an edge enabling server EES.
- Authentication capability information of the EES sent by the ECS is received; wherein the authentication capability information of the EES indicates the security authentication method supported by the EES.
- service provision request information is sent to the edge configuration server ECS; wherein the service provision request information is used to request to obtain the security authentication mode supported by the edge enabling server EES.
- a service provision request message is sent to an edge configuration server ECS, wherein the service provision request message is used to request to obtain a security authentication method supported by an edge enabling server EES.
- Authentication capability information of the EES sent by the ECS and information for establishing a connection between the ECS and the EES are received, wherein the authentication capability information of the EES indicates the security authentication method supported by the EES.
- an authentication method for performing mutual authentication between the EEC and the ECS is determined; wherein the first authentication capability information includes at least one of the following: an authentication method supported by the EEC; a security authentication method supported by the edge configuration server ECS; a security authentication method supported by the home network; and a security authentication method supported by the access network.
- Authentication between the EEC and the ECS is performed based on the authentication method.
- a transport layer security TLS connection is established between the EEC and the ECS.
- a service provision request information is sent to the edge configuration server ECS; wherein the service provision request information is used to request the security authentication method supported by the edge enabling server EES.
- the authentication capability information of the EES sent by the ECS and/or the information for establishing a connection between the ECS and the EES is received; wherein the authentication capability information of the EES indicates the security authentication method supported by the EES.
- an authentication method is provided in this embodiment, wherein the method is executed by an edge enabling client EEC, and the method includes:
- Step 51 Based on the second authentication capability information, determine an authentication method for performing mutual authentication between the EEC and the EES;
- the second authentication capability information includes at least one of the following:
- a service provision request message is sent to an edge configuration server ECS; wherein the service provision request message is used to request a security authentication method supported by an edge enabling server EES.
- Authentication capability information of the EES sent by the ECS is received; wherein the authentication capability information of the EES indicates a security authentication method supported by the EES.
- Based on the second authentication capability information an authentication method for performing mutual authentication between the EEC and the EES is determined; wherein the second authentication capability information includes at least one of the following: a security authentication method supported by the EEC; a security authentication method supported by the edge enabling server EES; a security authentication method supported by the home network; and a security authentication method supported by the access network.
- the authentication method for performing mutual authentication between the EEC and the ECS determines the authentication method for performing mutual authentication between the EEC and the ECS; wherein the first authentication capability information includes at least one of the following: an authentication method supported by the EEC; a security authentication method supported by the edge configuration server ECS; a security authentication method supported by the home network; and a security authentication method supported by the access network.
- the authentication capability information of the EES sent by the ECS wherein the authentication capability information of the EES indicates the security authentication method supported by the EES.
- the second authentication capability information determines the authentication method for performing mutual authentication between the EEC and the EES; wherein the second authentication capability information includes at least one of the following: a security authentication method supported by the EEC; a security authentication method supported by the edge enabling server EES; a security authentication method supported by the home network; and a security authentication method supported by the access network.
- this embodiment provides an authentication method, wherein the method is executed by an edge configuration client ECS, and the method includes:
- Step 61 receiving service provision request information sent by EEC
- the service provision request information is used to request to obtain the security authentication method supported by the edge enabling server EES.
- the terminal involved in the present disclosure may be, but is not limited to, a mobile phone, a wearable device, a vehicle-mounted terminal, a road side unit (RSU, Road Side Unit), a smart home terminal, an industrial sensor device and/or a medical device, etc.
- the terminal may be a Redcap terminal or a predetermined version of a new air interface NR terminal (for example, an R17 NR terminal).
- the edge enabling client EEC may be an application program running on the terminal, for example, a WeChat application program and a Weibo application program.
- a service provision request message sent by an EEC is received; wherein the service provision request message is used to request a security authentication method supported by an edge enabling server EES; and the service provision request message includes home network information of a terminal corresponding to the EEC.
- the home network information includes at least one of the home network identifier, the Authentication and Key Management for Applications (AKMA) key identifier (A-KID, AKMA Key Identifier) and the session practice identifier (B-TID, Bootstrapping Transaction Identifier), which can be used to identify the home network of the terminal or EEC.
- AKMA Authentication and Key Management for Applications
- A-KID Authentication and Key Management for Applications
- B-TID Bootstrapping Transaction Identifier
- a service provision request message sent by an EEC is received, wherein the service provision request message is used to request to obtain a security authentication method supported by an edge enabling server EES.
- Authentication capability information is sent to the EEC, wherein the authentication capability information of the EES indicates the security authentication method supported by the EES.
- service provision request information sent by the EEC is received; wherein the service provision request information is used to request to obtain a security authentication method supported by the edge enabling server EES.
- a service provision request message sent by an EEC is received; wherein the service provision request message is used to request to obtain a security authentication method supported by an edge enabling server EES.
- Authentication capability information of the EES and information for establishing a connection between the ECS and the EES are sent to the EEC; wherein the authentication capability information of the EES indicates the security authentication method supported by the EES.
- receiving authentication capability information of the EES sent by the EES wherein the authentication capability information of the EES indicates the security authentication method supported by the EES.
- Receive service provision request information sent by the EEC wherein the service provision request information is used to request to obtain the security authentication method supported by the edge enabling server EES.
- receiving authentication capability information of the EES sent by the EES wherein the authentication capability information of the EES indicates a security authentication method supported by the EES.
- Receive service provision request information sent by the EEC wherein the service provision request information is used to request to obtain a security authentication method supported by the edge enabling server EES.
- receiving the authentication capability information of the EES sent by the EES wherein the authentication capability information of the EES indicates the security authentication method supported by the EES.
- Receive service provision request information sent by the EEC wherein the service provision request information is used to request to obtain the security authentication method supported by the edge enabling server EES.
- authentication capability request information is sent to the identified EES; wherein the authentication capability request information is used to request the authentication capability information of the EES, wherein the authentication capability information of the EES indicates the security authentication method supported by the EES.
- Service provision request information sent by the EEC is received; wherein the service provision request information is used to request to obtain the security authentication method supported by the edge enabling server EES.
- the authentication capability information of the identified EES is sent to the EEC.
- the identified EES is the EES screened out by a predetermined condition.
- the authentication capability request information includes a visited network identifier and/or a home network identifier of the EEC, or the authentication capability request information includes a visited network identifier and/or a home network identifier of a terminal corresponding to the EEC.
- the authentication capability information of the EES in response to the EES not being authorized to use authentication and key management AKMA in the access network or home network of the EEC, does not include the authentication method of transport layer security TLS based on application authentication and key management AKMA; and/or, in response to the EES not being authorized to use AKMA in the access network or home network of the terminal corresponding to the EEC, the authentication capability information of the EES does not include the authentication method of transport layer security TLS based on AKMA; and/or, in response to the EES not being authorized to use general bootstrapping framework GBA in the access network or home network of the EEC, the authentication capability information of the EES does not include the authentication method of transport layer security TLS based on GBA; and/or, in response to the EES not being authorized to use GBA in the access network or home network of the terminal corresponding to the EEC, the authentication capability information of the EES does not include the authentication method of transport layer security TLS based on GBA.
- a TLS connection is established between the EES and the ECS. Based on the TLS connection, authentication capability request information is sent to the identified EES; wherein the authentication capability request information is used to request the authentication capability information of the EES.
- a TLS connection is established between the EES and the ECS. Based on the TLS connection, the authentication capability information of the EES sent by the EES is received; wherein the authentication capability information of the EES indicates a security authentication method supported by the EES.
- this embodiment provides an authentication method, wherein the method is executed by an edge configuration client ECS, and the method includes:
- Step 71 Receive the authentication capability information of the EES sent by the EES;
- the authentication capability information of the EES indicates the security authentication method supported by the EES.
- receiving authentication capability information of the EES sent by the EES wherein the authentication capability information of the EES indicates the security authentication method supported by the EES.
- Receive service provision request information sent by the EEC wherein the service provision request information is used to request to obtain the security authentication method supported by the edge enabling server EES.
- the authentication capability information of the EES is received from the EES, wherein the authentication capability information of the EES indicates the security authentication method supported by the EES.
- Service provision request information is received from the EEC, wherein the service provision request information is used to request the security authentication method supported by the edge enabling server EES.
- the identified authentication capability information of the EES is sent to the EEC.
- a service provision request message sent by an EEC is received; wherein the service provision request message is used to request a security authentication method supported by an edge enabling server EES.
- an authentication capability request message is sent to the identified EES; wherein the authentication capability request message is used to request the authentication capability information of the EES.
- the authentication capability information of the EES sent by the EES is received; wherein the authentication capability information of the EES indicates the security authentication method supported by the EES.
- the authentication capability request information includes a visited network identifier and/or a home network identifier of the EEC, or the authentication capability request information includes a visited network identifier and/or a home network identifier of a terminal corresponding to the EEC.
- the authentication capability request information includes at least one of the following:
- the home network information of the EEC corresponding terminal
- the EEC's visited network information The EEC's visited network information.
- the EEC corresponds to the visited network information of the terminal.
- the authentication capability information of the EES in response to the EES not being authorized to use authentication and key management AKMA in the access network or home network of the EEC, does not include the authentication method of transport layer security TLS based on AKMA; and/or, in response to the EES not being authorized to use AKMA in the access network or home network of the terminal corresponding to the EEC, the authentication capability information of the EES does not include the authentication method of transport layer security TLS based on AKMA; and/or, in response to the EES not being authorized to use general bootstrapping framework GBA in the access network or home network of the EEC, the authentication capability information of the EES does not include the authentication method of transport layer security TLS based on GBA; and/or, in response to the EES not being authorized to use GBA in the access network or home network of the terminal corresponding to the EEC, the authentication capability information of the EES does not include the authentication method of transport layer security TLS based on GBA.
- the authentication capability information of the EES is received from the EES, wherein the authentication capability information of the EES indicates the security authentication mode supported by the EES, and the identified authentication capability information of the EES is sent to the EEC.
- the authentication capability information of the EES is received from the EES, wherein the authentication capability information of the EES indicates the security authentication mode supported by the EES.
- the identified authentication capability information of the EES and information for establishing a connection between the ECS and the EES are sent to the EEC.
- this embodiment provides an authentication method, wherein the method is executed by an edge configuration client ECS, and the method includes:
- Step 81 In response to the ECS not having the authentication capability information of the identified EES, send authentication capability request information to the identified EES; wherein the authentication capability request information is used to request the authentication capability information of the EES.
- the identified EES is the EES screened out through specific information, wherein the specific information includes the location information of the terminal corresponding to the EEC, the application client profile (AC Profile) and/or the ECS provider policy (ECSP policy).
- specific information includes the location information of the terminal corresponding to the EEC, the application client profile (AC Profile) and/or the ECS provider policy (ECSP policy).
- a service provision request message sent by an EEC is received; wherein the service provision request message is used to request a security authentication method supported by an edge enabling server EES.
- an authentication capability request message is sent to the identified EES; wherein the authentication capability request message is used to request the authentication capability information of the EES.
- the authentication capability information of the EES sent by the EES is received; wherein the authentication capability information of the EES indicates the security authentication method supported by the EES.
- service provision request information sent by the EEC is received; wherein the service provision request information is used to request the secure authentication method supported by the edge enabling server EES.
- a TLS connection is established between the EES and the ECS.
- Authentication capability request information is sent to the identified EES based on the TLS connection; wherein the authentication capability request information is used to request the authentication capability information of the EES.
- Authentication capability information of the EES sent by the EES is received; wherein the authentication capability information of the EES indicates the secure authentication method supported by the EES.
- the authentication capability request information includes a visited network identifier and/or a home network identifier of the EEC, or the authentication capability request information includes a visited network identifier and/or a home network identifier of a terminal corresponding to the EEC.
- the authentication capability information of the EES in response to the EES not being authorized to use authentication and key management AKMA in the access network or home network of the EEC, does not include the authentication method of transport layer security TLS based on AKMA; and/or, in response to the EES not being authorized to use AKMA in the access network or home network of the terminal corresponding to the EEC, the authentication capability information of the EES does not include the authentication method of transport layer security TLS based on AKMA; and/or, in response to the EES not being authorized to use general bootstrapping framework GBA in the access network or home network of the EEC, the authentication capability information of the EES does not include the authentication method of transport layer security TLS based on GBA; and/or, in response to the EES not being authorized to use GBA in the access network or home network of the terminal corresponding to the EEC, the authentication capability information of the EES does not include the authentication method of transport layer security TLS based on GBA.
- a service provision request message sent by an EEC is received; wherein the service provision request message is used to request a security authentication method supported by an edge enabling server EES.
- an authentication capability request message is sent to the identified EES; wherein the authentication capability request message is used to request the authentication capability information of the EES.
- the authentication capability information of the EES sent by the EES is received; wherein the authentication capability information of the EES indicates a security authentication method supported by the EES.
- the authentication capability information of the identified EES is sent to the EEC.
- service provision request information sent by the EEC is received; wherein the service provision request information is used to request the secure authentication method supported by the edge enabling server EES.
- authentication capability request information is sent to the identified EES; wherein the authentication capability request information is used to request the authentication capability information of the EES.
- Authentication capability information of the EES sent by the EES is received; wherein the authentication capability information of the EES indicates the secure authentication method supported by the EES.
- the authentication capability information of the identified EES and information for establishing a connection between the ECS and the EES are sent to the EEC.
- this embodiment provides an authentication method, wherein the method is executed by an edge configuration client ECS, and the method includes:
- Step 91 Send the identified authentication capability information of the EES to the EEC.
- a service provision request message sent by an EEC is received, wherein the service provision request message is used to request to obtain a security authentication method supported by an edge enabling server EES, and the identified authentication capability information of the EES is sent to the EEC.
- a service provision request message sent by an EEC is received, wherein the service provision request message is used to request a security authentication method supported by an edge enabling server (EES).
- EES edge enabling server
- the identified authentication capability information of the EES and information for establishing a connection between the ECS and the EES are sent to the EEC.
- a service provision request message sent by an EEC is received; wherein the service provision request message is used to request a security authentication method supported by an edge enabling server EES.
- an authentication capability request message is sent to the identified EES; wherein the authentication capability request message is used to request the authentication capability information of the EES.
- the authentication capability information of the EES sent by the EES is received; wherein the authentication capability information of the EES indicates a security authentication method supported by the EES.
- the authentication capability information of the identified EES is sent to the EEC.
- this embodiment provides an authentication method, wherein the method is executed by an edge configuration server EES, and the method includes:
- Step 101 Receive authentication capability request information sent by ECS
- the authentication capability request information is used to request the authentication capability information of the EES, wherein the authentication capability information of the EES indicates the security authentication method supported by the EES.
- the terminal involved in the present disclosure may be, but is not limited to, a mobile phone, a wearable device, a vehicle-mounted terminal, a road side unit (RSU, Road Side Unit), a smart home terminal, an industrial sensor device and/or a medical device, etc.
- the terminal may be a Redcap terminal or a predetermined version of a new air interface NR terminal (for example, an R17 NR terminal).
- the edge enabling client EEC may be an application program running on the terminal, for example, a WeChat application program and a Weibo application program, and the like.
- authentication capability request information sent by ECS is received; wherein the authentication capability request information is used to request authentication capability information of the EES, wherein the authentication capability information of the EES indicates a security authentication method supported by the EES; the authentication capability request information includes an access network identifier and/or a home network identifier of the EEC, or the authentication capability request information includes an access network identifier and/or a home network identifier of a terminal corresponding to the EEC.
- an authentication capability request message sent by an ECS is received, wherein the authentication capability request message is used to request authentication capability information of the EES, wherein the authentication capability information of the EES indicates a security authentication method supported by the EES, and the authentication capability information of the EES is sent to the ECS.
- the authentication capability information of the EES in response to the EES not being authorized to use authentication and key management AKMA in the access network or home network of the EEC, does not include the authentication method of transport layer security TLS based on AKMA; and/or, in response to the EES not being authorized to use AKMA in the access network or home network of the terminal corresponding to the EEC, the authentication capability information of the EES does not include the authentication method of transport layer security TLS based on AKMA; and/or, in response to the EES not being authorized to use general bootstrapping framework GBA in the access network or home network of the EEC, the authentication capability information of the EES does not include the authentication method of transport layer security TLS based on GBA; and/or, in response to the EES not being authorized to use GBA in the access network or home network of the terminal corresponding to the EEC, the authentication capability information of the EES does not include the authentication method of transport layer security TLS based on GBA.
- an authentication capability request message sent by an ECS is received; wherein the authentication capability request message is used to request the authentication capability information of the EES, wherein the authentication capability information of the EES indicates the security authentication method supported by the EES.
- Authorization confirmation information is sent to the access network and/or home network of the EEC; authorization response information is received from the access network and/or home network, wherein the authorization response information indicates at least one of the following: the EEC is authorized to use AKMA; the EEC is not authorized to use AKMA; the EEC is authorized to use GBA; and the EEC is not authorized to use GBA.
- the access network and the home network determine the authorization response information based on the identifier sent by the ECS.
- this embodiment provides an authentication method, wherein the method is executed by an edge configuration server EES, and the method includes:
- Step 111 Send authorization confirmation information to the visited network and/or home network of the EEC;
- Step 112 Receive authorization response information sent by the visited network and/or the home network, wherein the authorization response information indicates at least one of the following:
- Said EES is authorized to use AKMA
- the said EES is not authorized to use AKMA;
- the EES is authorized to use GBA.
- the EES is not authorized to use GBA.
- an authorization confirmation message is sent to a visited network and/or a home network of the EEC; an authorization response message sent by the visited network and/or the home network is received, wherein the authorization response message indicates at least one of the following: the EES is authorized to use AKMA; the EES is not authorized to use AKMA; the EES is authorized to use GBA; and the EES is not authorized to use GBA.
- authentication capability information of the EES is sent to the ECS.
- the access network and/or home network of the EEC determines whether to authorize AKMA and/or GBA based on the identification information sent by the ECS, and obtains a determination result; based on the determination result, determines the authorization response information. It should be noted that as long as one of the access network and the home network of the EEC does not authorize AKMA, AKMA is not authorized; and/or, as long as one of the access network and the home network of the EEC does not authorize GBA, GBA is not authorized.
- this embodiment provides an authentication method, wherein the method is executed by an edge configuration server EES, and the method includes:
- Step 121 Based on the authorization response information, send the authentication capability information of the EES to the ECS.
- an authorization confirmation message is sent to a visited network and/or a home network of the EEC; an authorization response message sent by the visited network and/or the home network is received, wherein the authorization response message indicates at least one of the following: the EEC is authorized to use AKMA; the EEC is not authorized to use AKMA; the EEC is authorized to use GBA; and the EEC is not authorized to use GBA.
- the authentication capability information of the EES is sent to the ECS.
- the authentication capability information of the EES in response to the EES not being authorized to use authentication and key management AKMA in the access network or home network of the EEC, does not include the authentication method of transport layer security TLS based on AKMA; and/or, in response to the EES not being authorized to use AKMA in the access network or home network of the terminal corresponding to the EEC, the authentication capability information of the EES does not include the authentication method of transport layer security TLS based on AKMA; and/or, in response to the EES not being authorized to use general bootstrapping framework GBA in the access network or home network of the EEC, the authentication capability information of the EES does not include the authentication method of transport layer security TLS based on GBA; and/or, in response to the EES not being authorized to use GBA in the access network or home network of the terminal corresponding to the EEC, the authentication capability information of the EES does not include the authentication method of transport layer security TLS based on GBA.
- this embodiment provides an authentication method, wherein the method is executed by an edge configuration server EES, and the method includes:
- Step 131 receiving authentication capability request information sent by the ECS; wherein the authentication capability request information is used to request authentication capability information of the EES, wherein the authentication capability information of the EES indicates the security authentication method supported by the EES;
- Step 132 Send the authentication capability information of the EES to the ECS.
- EEC can be configured with the authentication capability of ECS.
- the authentication capability of ECS can be pre-configured with EEC through ECS configuration information; the edge-aware application client (AC, Application Client) can configure the authentication capability of ECS through ECS configuration information; users can configure the authentication capability of ECS through ECS configuration information.
- AC Application Client
- this embodiment provides an authentication method, including:
- Step 140 The edge enabling client EEC may obtain the authentication capabilities of the access network and the home network during the registration process.
- the authentication capabilities indicate the supported authentication mechanisms.
- the security authentication methods include at least one of the following: an authentication method based on transport layer security TLS of the general bootstrapping framework GBA; an authentication method based on TLS of the application authentication and key management AKMA; and an authentication method based on a certificate.
- the EES may send its authentication capabilities to the ECS during the EES registration process.
- Step 141 establish a TLS connection.
- the EEC selects a mutual authentication method used between the EEC and the ECS based on the authentication capability of the EEC, the authentication capability of the ECS, the authentication capability of the home network, and the authentication capability of the access network.
- a TLS connection is established between the EEC and the ECS.
- messages between the EEC and the ECS are protected.
- Step 142 send a service provision request.
- the EEC sends a service provision request to the ECS.
- the service provision request includes the security credentials of the EEC received during the EEC authorization process, and may include a UE identifier, such as a Generic Public Subscription Identifier (GPSI), connectivity information, UE location information, and AC configuration information.
- GPSI Generic Public Subscription Identifier
- the EEC may send its home network identifier to the ECS.
- Step 143 check the authentication mode of the EES. If the AC configuration information is provided by the EEC, the ECS identifies the EES based on the provided AC profile information and the UE location information. If no AC profile is provided, then: the ECS identifies the EES based on the UE-specific service information and the UE location information at the ECS; or, the ECS identifies the EES by applying the ECS provider policy (e.g., based only on the UE location information); the ECS checks whether it has the authentication capability for the identified EES.
- the ECS identifies the EES based on the provided AC profile information and the UE location information. If no AC profile is provided, then: the ECS identifies the EES based on the UE-specific service information and the UE location information at the ECS; or, the ECS identifies the EES by applying the ECS provider policy (e.g., based only on the UE location information); the ECS checks whether it has the authentication capability for the identified EES.
- Step 144 Send authentication capability information. If the ECS has authentication capability information of the identified EES, steps 145 to 148 should be skipped. The ECS sends the authentication capability of the identified EES to the EEC together with information for establishing a connection with the identified EES (e.g., a Uniform Resource Identifier (URI) and an IP address).
- URI Uniform Resource Identifier
- Step 145 TLS connection establishment. If the ECS does not have the authentication capability information of the identified EES, a TLS connection is established between the EES and the ECS. After step 145, the messages between the EES and the ECS are protected.
- Step 146 Send an EES authentication capability request.
- the ECS sends an EES authentication capability request to the EES.
- the ECS may send a visited network identifier and a home network identifier to the EES.
- Step 147 Send the authentication capability information of the EES. After receiving the authentication capability request, the EES sends its authentication capability information back to the ECS. If the EES is not authorized to use AKMA in the visited network and home network of the UE (EEC), the EES should not include TLS with AKMA in the authentication capability information. If the EES is not authorized to use GBA in the visited network and home network of the UE (EEC), the EES should not include TLS with GBA in the authentication capability information.
- Step 148 Send the authentication capability information of the EES.
- the ECS sends the authentication capability of the identified EES to the EEC together with the information (eg, URI and IP address) for establishing a connection to the identified EES.
- the information eg, URI and IP address
- Step 149 Select an authentication method.
- the EEC selects a security authentication method based on the authentication capability of the EEC, the authentication capability of the EES, the authentication capability of the home network, and the authentication function of the access network.
- Step 150 Perform mutual authentication based on the selected authentication method.
- the EEC triggers the authentication procedure according to the selected method.
- the EES may send a registration request message to the ECS, and the registration request message includes the authentication capability information of the EES.
- the ECS obtains the authentication capability information of the EES from the registration request message, and stores the authentication capability information of the EES and the identifier of the EES locally.
- an authentication device is provided in this embodiment, wherein the device includes:
- the sending module 151 is configured to send service provision request information to the edge configuration server ECS;
- the service provision request information is used to request to obtain the security authentication method supported by the edge enabling server EES.
- an authentication device is provided in this embodiment, wherein the device includes:
- the receiving module 161 is configured to receive the service provision request information sent by the EEC;
- the service provision request information is used to request to obtain the security authentication method supported by the edge enabling server EES.
- an authentication device is provided in this embodiment, wherein the device includes:
- the receiving module 171 is configured to receive the authentication capability request information sent by the ECS;
- the authentication capability request information is used to request the authentication capability information of the EES, wherein the authentication capability information of the EES indicates the security authentication method supported by the EES.
- an authentication system is provided in this embodiment, wherein the system includes EEC, ECS and EES, wherein the EEC is used to implement any method described in the present disclosure executed by the EEC; the ECS is used to implement any method described in the present disclosure executed by the ECS; and the EES is used to implement any method described in the present disclosure executed by the EES.
- the present disclosure provides a communication device, the communication device comprising:
- a memory for storing processor-executable instructions
- the processor is configured to implement the method applied to any embodiment of the present disclosure when running executable instructions.
- the processor may include various types of storage media, which are non-temporary computer storage media that can continue to memorize information stored thereon after the communication device loses power.
- the processor may be connected to the memory via a bus or the like to read the executable program stored in the memory.
- An embodiment of the present disclosure further provides a computer storage medium, wherein the computer storage medium stores a computer executable program, and when the executable program is executed by a processor, the method of any embodiment of the present disclosure is implemented.
- an embodiment of the present disclosure provides a structure of a terminal.
- this embodiment provides a terminal 800, which can be a mobile phone, a computer, a digital broadcast terminal, a message sending and receiving device, a game console, a tablet device, a medical device, a fitness device, a personal digital assistant, etc.
- terminal 800 may include one or more of the following components: a processing component 802 , a memory 804 , a power component 806 , a multimedia component 808 , an audio component 810 , an input/output (I/O) interface 812 , a sensor component 814 , and a communication component 816 .
- a processing component 802 may include one or more of the following components: a processing component 802 , a memory 804 , a power component 806 , a multimedia component 808 , an audio component 810 , an input/output (I/O) interface 812 , a sensor component 814 , and a communication component 816 .
- a processing component 802 may include one or more of the following components: a processing component 802 , a memory 804 , a power component 806 , a multimedia component 808 , an audio component 810 , an input/output (I/O) interface 812 , a sensor component 814 , and a communication component
- the processing component 802 generally controls the overall operation of the terminal 800, such as operations associated with display, phone calls, data communications, camera operations, and recording operations.
- the processing component 802 may include one or more processors 820 to execute instructions to complete all or part of the steps of the above-mentioned method.
- the processing component 802 may include one or more modules to facilitate the interaction between the processing component 802 and other components.
- the processing component 802 may include a multimedia module to facilitate the interaction between the multimedia component 808 and the processing component 802.
- the memory 804 is configured to store various types of data to support operations on the device 800. Examples of such data include instructions for any application or method operating on the terminal 800, contact data, phone book data, messages, pictures, videos, etc.
- the memory 804 can be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as static random access memory (SRAM), electrically erasable programmable read-only memory (EEPROM), erasable programmable read-only memory (EPROM), programmable read-only memory (PROM), read-only memory (ROM), magnetic memory, flash memory, magnetic disk or optical disk.
- SRAM static random access memory
- EEPROM electrically erasable programmable read-only memory
- EPROM erasable programmable read-only memory
- PROM programmable read-only memory
- ROM read-only memory
- magnetic memory flash memory
- flash memory magnetic disk or optical disk.
- Power component 806 provides power to various components of terminal 800.
- Power component 806 may include a power management system, one or more power supplies, and other components associated with generating, managing, and distributing power to terminal 800.
- the multimedia component 808 includes a screen that provides an output interface between the terminal 800 and the user.
- the screen may include a liquid crystal display (LCD) and a touch panel (TP). If the screen includes a touch panel, the screen may be implemented as a touch screen to receive input signals from the user.
- the touch panel includes one or more touch sensors to sense touch, slide, and gestures on the touch panel. The touch sensor may not only sense the boundaries of the touch or slide action, but also detect the duration and pressure associated with the touch or slide operation.
- the multimedia component 808 includes a front camera and/or a rear camera. When the device 800 is in an operating mode, such as a shooting mode or a video mode, the front camera and/or the rear camera may receive external multimedia data. Each front camera and rear camera may be a fixed optical lens system or have a focal length and optical zoom capability.
- the audio component 810 is configured to output and/or input audio signals.
- the audio component 810 includes a microphone (MIC), and when the terminal 800 is in an operation mode, such as a call mode, a recording mode, and a speech recognition mode, the microphone is configured to receive an external audio signal.
- the received audio signal can be further stored in the memory 804 or sent via the communication component 816.
- the audio component 810 also includes a speaker for outputting audio signals.
- I/O interface 812 provides an interface between processing component 802 and peripheral interface modules, such as keyboards, click wheels, buttons, etc. These buttons may include but are not limited to: home button, volume button, start button, and lock button.
- the sensor assembly 814 includes one or more sensors for providing various aspects of status assessment for the terminal 800.
- the sensor assembly 814 can detect the open/closed state of the device 800, the relative positioning of the components, such as the display and keypad of the terminal 800, and the sensor assembly 814 can also detect the position change of the terminal 800 or a component in the terminal 800, the presence or absence of contact between the user and the terminal 800, the orientation or acceleration/deceleration of the terminal 800, and the temperature change of the terminal 800.
- the sensor assembly 814 may include a proximity sensor configured to detect the presence of nearby objects without any physical contact.
- the sensor assembly 814 may also include an optical sensor, such as a CMOS or CCD image sensor, for use in imaging applications.
- the sensor assembly 814 may also include an acceleration sensor, a gyroscope sensor, a magnetic sensor, a pressure sensor, or a temperature sensor.
- the communication component 816 is configured to facilitate wired or wireless communication between the terminal 800 and other devices.
- the terminal 800 can access a wireless network based on a communication standard, such as Wi-Fi, 2G or 3G, or a combination thereof.
- the communication component 816 receives a broadcast signal or broadcast-related information from an external broadcast management system via a broadcast channel.
- the communication component 816 also includes a near field communication (NFC) module to facilitate short-range communication.
- the NFC module can be implemented based on radio frequency identification (RFID) technology, infrared data association (IrDA) technology, ultra-wideband (UWB) technology, Bluetooth (BT) technology and other technologies.
- RFID radio frequency identification
- IrDA infrared data association
- UWB ultra-wideband
- Bluetooth Bluetooth
- terminal 800 can be implemented by one or more application-specific integrated circuits (ASICs), digital signal processors (DSPs), digital signal processing devices (DSPDs), programmable logic devices (PLDs), field programmable gate arrays (FPGAs), controllers, microcontrollers, microprocessors or other electronic components to perform the above methods.
- ASICs application-specific integrated circuits
- DSPs digital signal processors
- DSPDs digital signal processing devices
- PLDs programmable logic devices
- FPGAs field programmable gate arrays
- controllers microcontrollers, microprocessors or other electronic components to perform the above methods.
- a non-transitory computer-readable storage medium including instructions is also provided, such as a memory 804 including instructions, and the instructions can be executed by the processor 820 of the terminal 800 to complete the above method.
- the non-transitory computer-readable storage medium can be a ROM, a random access memory (RAM), a CD-ROM, a magnetic tape, a floppy disk, an optical data storage device, etc.
- an embodiment of the present disclosure shows the structure of a base station.
- the base station 900 can be provided as a network side device.
- the base station 900 includes a processing component 922, which further includes one or more processors, and a memory resource represented by a memory 932 for storing instructions that can be executed by the processing component 922, such as an application.
- the application stored in the memory 932 may include one or more modules, each of which corresponds to a set of instructions.
- the processing component 922 is configured to execute instructions to execute any method of the aforementioned method applied to the base station.
- the base station 900 may also include a power supply component 926 configured to perform power management of the base station 900, a wired or wireless network interface 950 configured to connect the base station 900 to the network, and an input/output (I/O) interface 958.
- the base station 900 may operate based on an operating system stored in the memory 932, such as Windows Server TM, Mac OS XTM, UnixTM, LinuxTM, FreeBSDTM or the like.
Landscapes
- Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Computer Hardware Design (AREA)
- Computing Systems (AREA)
- General Engineering & Computer Science (AREA)
- Mobile Radio Communication Systems (AREA)
Abstract
Description
Claims (32)
- 一种认证方法,其中,所述方法由边缘使能客户端EEC执行,所述方法包括:向边缘配置服务器ECS发送服务提供请求信息;其中,所述服务提供请求信息用于请求获取边缘使能服务器EES支持的安全认证方式。
- 根据权利要求1所述的方法,其中,所述服务提供请求信息包含所述EEC所对应终端的归属网络信息。
- 根据权利要求1所述的方法,其中,所述EEC配置有所述ECS的认证能力信息,所述ECS的认证能力信息指示所述ECS支持的安全认证方式。
- 根据权利要求1所述的方法,其中,所述ECS的认证能力信息预先配置于所述EEC;或者,所述ECS的认证能力信息由边缘敏感的应用客户端AC配置于所述EEC;或者,所述ECS的认证能力信息由用户配置于所述EEC。
- 根据权利要求1所述的方法,其中,所述方法还包括:基于第一认证能力信息,确定在所述EEC和所述ECS之间执行相互认证的认证方式;其中,所述第一认证能力信息包括以下至少之一:EEC支持的认证方式;边缘配置服务器ECS支持的安全认证方式;归属网络支持的安全认证方式;和,访问网络支持的安全认证方式。
- 根据权利要求5所述的方法,其中,所述方法还包括:响应于所述EEC和所述ECS之间相互认证成功,在所述EEC和所述ECS之间建立传输层安全TLS连接。
- 根据权利要求1所述的方法,其中,所述方法还包括:接收所述ECS发送的EES的认证能力信息;其中,所述EES的认证能力信息指示所述EES支持的安全认证方式。
- 根据权利要求7所述的方法,其中,所述接收所述ECS发送的EES的认证能力信息,包括:接收所述ECS发送的EES的认证能力信息和用于建立所述ECS与所述EES之间的连接的信息。
- 根据权利要求7所述的方法,其中,响应于所述EES未被授权在EEC的访问网络或者归属网络使用认证和密钥管理AKMA,所述EES的认证能力信息中不包含基于应用的认证和密钥管理AKMA的传输层安全TLS的认证方式;和/或,响应于所述EES未被授权在EEC所对应终端的访问网络或者归属网络使用AKMA,所述EES的认证能力信息中不包含基于AKMA的传输层安全TLS的认证方式;和/或,响应于所述EES未被授权在EEC的访问网络或者归属网络使用通用引导框架GBA,所述EES的认证能力信息中不包含基于GBA的传输层安全TLS的认证方式;和/或,响应于所述EES未被授权在EEC所对应终端的访问网络或者归属网络使用GBA,所述EES的认证能力信息中不包含基于GBA的传输层安全TLS的认证方式。
- 根据权利要求7所述的方法,其中,所述方法还包括:基于第二认证能力信息,确定在所述EEC和所述EES之间执行相互认证的认证方式;其中,所述第二认证能力信息包括以下至少之一:EEC支持的安全认证方式;边缘使能服务器EES支持的安全认证方式;归属网络支持的安全认证方式;和,访问网络支持的安全认证方式。
- 一种认证方法,其中,所述方法由边缘配置客户端ECS执行,所述方法包括:接收EEC发送的服务提供请求信息;其中,所述服务提供请求信息用于请求获取边缘使能服务器EES支持的安全认证方式。
- 根据权利要求11所述的方法,其中,所述服务提供请求信息包含所述EEC所对应终端的归属网络信息。
- 根据权利要求11所述的方法,其中,所述方法还包括:接收所述EES发送的所述EES的认证能力信息;其中,所述EES的认证能力信息指示所述EES支持的安全认证方式。
- 根据权利要求13所述的方法,其中,所述接收所述EES发送的所述EES的认证能力信息,包括:在EES注册过程中,接收所述EES发送的所述EES的认证能力信息。
- 根据权利要求13所述的方法,其中,所述方法还包括:响应于所述ECS不具有识别的所述EES的认证能力信息,向识别的所述EES发送认证能力请求信息;其中,所述认证能力请求信息用于请求所述EES的认证能力信息。
- 根据权利要求15所述的方法,其中,所述认证能力请求信息包括EEC的访问网络标识符和/或归属网络标识符,或者,所述认证能力请求信息包括EEC所对应的终端的访问网络标识符和/或归属网络标识符。
- 根据权利要求13所述的方法,其中,所述方法还包括:响应于所述ECS不具有识别的所述EES的认证能力信息,向所述EES发送认证能力请求信息;其中,所述认证能力请求信息包含以下至少之一:所述EEC的归属网络信息;所述EEC对应终端的归属网络信息;所述EEC的拜访地网络信息;和,所述EEC对应终端的拜访地网络信息。
- 根据权利要求13所述的方法,其中,响应于所述EES未被授权在EEC的访问网络或者归属网络使用认证和密钥管理AKMA,所述EES的认证能力信息中不包含基于AKMA的传输层安全TLS的认证方式;和/或,响应于所述EES未被授权在EEC所对应终端的访问网络或者归属网络使用AKMA,所述EES的认证能力信息中不包含基于AKMA的传输层安全TLS的认证方式;和/或,响应于所述EES未被授权在EEC的访问网络或者归属网络使用通用引导框架GBA,所述EES的认证能力信息中不包含基于GBA的传输层安全TLS的认证方式;和/或,响应于所述EES未被授权在EEC所对应终端的访问网络或者归属网络使用GBA,所述EES的认证能力信息中不包含基于GBA的传输层安全TLS的认证方式。
- 根据权利要求18所述的方法,其中,所述方法还包括:向所述EEC发送识别的所述EES的认证能力信息。
- 根据权利要求19所述的方法,其中,所述向所述EEC发送识别的所述EES的认证能力信息,包括:向所述EEC发送识别的所述EES的认证能力信息和用于建立所述ECS和所述EES之间的连接的信息。
- 一种认证方法,其中,所述方法由边缘使能服务器EES执行,所述方法包括:接收ECS发送的认证能力请求信息;其中,所述认证能力请求信息用于请求所述EES的认证能力信息,其中,所述EES的认证能力信息指示所述EES支持的安全认证方式。
- 根据权利要求21所述的方法,其中,所述认证能力请求信息包括EEC的访问网络标识符和/或归属网络标识符,或者,所述认证能力请求信息包括EEC所对应的终端的访问网络标识符和/或归属网络标识符。
- 根据权利要求21所述的方法,其中,所述认证能力请求信息包含以下至少之一:所述EEC的归属网络信息;所述EEC对应终端的归属网络信息;所述EEC的拜访地网络信息;和,所述EEC对应终端的拜访地网络信息。
- 根据权要求21所述的方法,其中,所述方法还包括:向EEC的访问网络和/或归属网络发送授权确认信息;接收所述访问网络和/或归属网络发送的授权响应信息,其中,所述授权响应信息指示以下至少之一:所述EES被授权使用AKMA;所述EES未被授权使用AKMA;所述EES被授权使用GBA;以及所述EES未被授权使用GBA。
- 根据权利要求24所述的方法,其中,所述方法还包括:基于所述授权响应信息,向所述ECS发送所述EES的认证能力信息。
- 根据权利要求25所述的方法,其中,响应于所述EES未被授权在EEC的访问网络或者归属网络使用认证和密钥管理AKMA,所述EES的认证能力信息中不包含基于AKMA的传输层安全TLS的认证方式;和/或,响应于所述EES未被授权在EEC所对应终端的访问网络或者归属网络使用AKMA,所述EES的认证能力信息中不包含基于AKMA的传输层安全TLS的认证方式;和/或,响应于所述EES未被授权在EEC的访问网络或者归属网络使用通用引导框架GBA,所述EES的认证能力信息中不包含基于GBA的传输层安全TLS的认证方式;和/或,响应于所述EES未被授权在EEC所对应终端的访问网络或者归属网络使用GBA,所述EES的认证能力信息中不包含基于GBA的传输层安全TLS的认证方式。
- 一种认证装置,其中,所述装置包括:发送模块,被配置为向边缘配置服务器ECS发送服务提供请求信息;其中,所述服务提供请求信息用于请求获取边缘使能服务器EES支持的安全认证方式。
- 一种认证装置,其中,所述装置包括:接收模块,被配置为接收EEC发送的服务提供请求信息;其中,所述服务提供请求信息用于请求获取边缘使能服务器EES支持的安全认证方式。
- 一种认证装置,其中,所述装置包括:接收模块,被配置为接收ECS发送的认证能力请求信息;其中,所述认证能力请求信息用于请求所述EES的认证能力信息,其中,所述EES的认证能力信息指示所述EES支持的安全认证方式。
- 一种认证系统,其中,所述系统包括EEC、ECS和EES,其中,所述EEC用于实现所述EEC执行的如权利要求1至10任一所述的方法;所述ECS用于实现所述ECS执行的如权利要求11至20任一所述的方法;所述EES用于实现所述EES执行的如权利要求21至26任一所述的方法。
- 一种通信设备,其中,包括:存储器;处理器,与所述存储器连接,被配置为通过执行存储在所述存储器上的计算机可执行指令,并能够实现权利要求1至10、11至20或者21至26任一项所述的方法。
- 一种计算机存储介质,所述计算机存储介质存储有计算机可执行指令,所述计算机可执行指令被处理器执行后能够实现权利要求1至10、11至20或者21至26任一项所述的方法。
Priority Applications (3)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| CN202280004784.8A CN118302991A (zh) | 2022-11-04 | 2022-11-04 | 认证方法、装置、通信设备及存储介质 |
| PCT/CN2022/130092 WO2024092801A1 (zh) | 2022-11-04 | 2022-11-04 | 认证方法、装置、通信设备及存储介质 |
| EP22964103.0A EP4614872A4 (en) | 2022-11-04 | 2022-11-04 | AUTHENTICATION PROCEDURES AND DEVICES, COMMUNICATION DEVICE AND STORAGE MEDIUM |
Applications Claiming Priority (1)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| PCT/CN2022/130092 WO2024092801A1 (zh) | 2022-11-04 | 2022-11-04 | 认证方法、装置、通信设备及存储介质 |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| WO2024092801A1 true WO2024092801A1 (zh) | 2024-05-10 |
Family
ID=90929522
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| PCT/CN2022/130092 Ceased WO2024092801A1 (zh) | 2022-11-04 | 2022-11-04 | 认证方法、装置、通信设备及存储介质 |
Country Status (3)
| Country | Link |
|---|---|
| EP (1) | EP4614872A4 (zh) |
| CN (1) | CN118302991A (zh) |
| WO (1) | WO2024092801A1 (zh) |
Citations (3)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN104660614A (zh) * | 2015-03-16 | 2015-05-27 | 联想(北京)有限公司 | 认证方法、电子设备以及服务器 |
| CN106506439A (zh) * | 2015-11-30 | 2017-03-15 | 杭州华三通信技术有限公司 | 一种认证终端接入网络的方法和装置 |
| US20200359218A1 (en) * | 2019-05-09 | 2020-11-12 | Samsung Electronics Co., Ltd. | Apparatus and method for providing mobile edge computing services in wireless communication system |
Family Cites Families (1)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN115777193A (zh) * | 2020-08-04 | 2023-03-10 | 英特尔公司 | 用于边缘使能器服务器装载的边缘安全程序 |
-
2022
- 2022-11-04 EP EP22964103.0A patent/EP4614872A4/en active Pending
- 2022-11-04 CN CN202280004784.8A patent/CN118302991A/zh active Pending
- 2022-11-04 WO PCT/CN2022/130092 patent/WO2024092801A1/zh not_active Ceased
Patent Citations (3)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN104660614A (zh) * | 2015-03-16 | 2015-05-27 | 联想(北京)有限公司 | 认证方法、电子设备以及服务器 |
| CN106506439A (zh) * | 2015-11-30 | 2017-03-15 | 杭州华三通信技术有限公司 | 一种认证终端接入网络的方法和装置 |
| US20200359218A1 (en) * | 2019-05-09 | 2020-11-12 | Samsung Electronics Co., Ltd. | Apparatus and method for providing mobile edge computing services in wireless communication system |
Non-Patent Citations (4)
| Title |
|---|
| "3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; Study on Security Aspects of Enhancement of Support for Edge Computing in 5GC (Release 17)", 3GPP DRAFT; S3-202085, 3RD GENERATION PARTNERSHIP PROJECT (3GPP), MOBILE COMPETENCE CENTRE ; 650, ROUTE DES LUCIOLES ; F-06921 SOPHIA-ANTIPOLIS CEDEX ; FRANCE, 29 August 2020 (2020-08-29), Mobile Competence Centre ; 650, route des Lucioles ; F-06921 Sophia-Antipolis Cedex ; France , XP051922999 * |
| APPLE: "New solution for EEC authentication and authorization framework with ECS/EES based on GBA", 3GPP DRAFT; S3-213982, 3RD GENERATION PARTNERSHIP PROJECT (3GPP), MOBILE COMPETENCE CENTRE ; 650, ROUTE DES LUCIOLES ; F-06921 SOPHIA-ANTIPOLIS CEDEX ; FRANCE, vol. SA WG3, no. e-meeting; 20211108 - 20211119, 1 November 2021 (2021-11-01), Mobile Competence Centre ; 650, route des Lucioles ; F-06921 Sophia-Antipolis Cedex ; France, XP052073395 * |
| HUAWEI, HISILICON: "EC: New solution on authentication and authorization between EEC and ECS", 3GPP DRAFT; S3-202483, 3RD GENERATION PARTNERSHIP PROJECT (3GPP), MOBILE COMPETENCE CENTRE ; 650, ROUTE DES LUCIOLES ; F-06921 SOPHIA-ANTIPOLIS CEDEX ; FRANCE, vol. SA WG3, no. e-meeting; 20201012 - 20201016, 2 October 2020 (2020-10-02), Mobile Competence Centre ; 650, route des Lucioles ; F-06921 Sophia-Antipolis Cedex ; France , XP051937784 * |
| See also references of EP4614872A4 * |
Also Published As
| Publication number | Publication date |
|---|---|
| EP4614872A4 (en) | 2025-12-10 |
| CN118302991A (zh) | 2024-07-05 |
| EP4614872A1 (en) | 2025-09-10 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| WO2024197490A1 (zh) | 信息处理方法、系统及装置、通信设备及存储介质 | |
| WO2024164340A1 (zh) | Qos监控结果的订阅方法、装置、通信设备及存储介质 | |
| EP4429298A1 (en) | Relay communication method and apparatus, communication device, and storage medium | |
| WO2024164337A1 (zh) | 定位服务的授权方法、装置、通信设备及存储介质 | |
| CN116349267B (zh) | 密钥分发方法、装置、通信设备及存储介质 | |
| WO2024234179A1 (zh) | 信息处理方法、装置、通信设备及存储介质 | |
| WO2022236602A1 (zh) | 能力指示信息的传输方法、装置、通信设备及存储介质 | |
| EP4564757A1 (en) | Application program interface (api) authentication method and apparatus, and communication device and storage medium | |
| US20250374040A1 (en) | Information processing method and apparatus, communication device and storage medium | |
| US20230014016A1 (en) | Voice call method, terminal and storage medium | |
| WO2024145948A1 (zh) | 授权方法、装置、通信设备及存储介质 | |
| CN117678254A (zh) | Eap认证方法、装置、通信设备及存储介质 | |
| WO2024092801A1 (zh) | 认证方法、装置、通信设备及存储介质 | |
| US20250343695A1 (en) | Personal iot network (pin) primitive credential configuration method and apparatus, communication device, and storage medium | |
| US20260039644A1 (en) | Api invoker authentication method and apparatus, communication device, and storage medium | |
| WO2024092735A1 (zh) | 通信控制方法、系统及装置、通信设备及存储介质 | |
| CN117597958A (zh) | 认证与授权方法、装置、通信设备及存储介质 | |
| WO2023070560A1 (zh) | 信息传输方法、装置、通信设备和存储介质 | |
| CN117597959A (zh) | 认证与授权方法、装置、通信设备及存储介质 | |
| WO2024031399A1 (zh) | Ue加入pin的方法及装置、通信设备及存储介质 | |
| WO2024092467A1 (zh) | 信息传输方法、装置、通信设备和存储介质 | |
| WO2024138444A1 (zh) | 信息处理方法以及装置、通信设备及存储介质 | |
| WO2024164345A1 (zh) | 信息处理方法、系统及装置、通信设备及存储介质 | |
| WO2023164796A1 (zh) | 信息处理方法、装置、通信设备及存储介质 | |
| WO2024031391A1 (zh) | 测距或侧行链路定位方法、装置、通信设备及存储介质 |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| WWE | Wipo information: entry into national phase |
Ref document number: 202280004784.8 Country of ref document: CN |
|
| 121 | Ep: the epo has been informed by wipo that ep was designated in this application |
Ref document number: 22964103 Country of ref document: EP Kind code of ref document: A1 |
|
| WWE | Wipo information: entry into national phase |
Ref document number: 202527047834 Country of ref document: IN |
|
| WWE | Wipo information: entry into national phase |
Ref document number: 2022964103 Country of ref document: EP |
|
| NENP | Non-entry into the national phase |
Ref country code: DE |
|
| ENP | Entry into the national phase |
Ref document number: 2022964103 Country of ref document: EP Effective date: 20250604 |
|
| WWP | Wipo information: published in national office |
Ref document number: 202527047834 Country of ref document: IN |
|
| WWP | Wipo information: published in national office |
Ref document number: 2022964103 Country of ref document: EP |