Authentication filtering method, system and device and storage medium
In the satellite communication cruise scenario, AMF configures black and white list parameters and directly rejects non-white list users' requests or forwards to AUSF for verification based on the authentication filtering strategy, solving the problem of network load and resource waste in the traditional authentication process, and achieving improvement in communication efficiency.
Patent Information
- Application Number
- CN202510880678.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-27
- Publication Date
- 2025-08-26
AI Technical Summary
In a cruise ship scenario based on satellite communications, the traditional authentication process requires forwarding all requests to AUSF verification of the core network, resulting in increased network load and waste of resources, affecting communication efficiency.
Provide an authentication filtering method, which determines the authentication mode through the access and mobility management functions (AMF), configures black and white list parameters, and directly rejects non-white list users' requests or forwards to AUSF for verification based on the authentication filtering strategy, and combines a multi-source synchronization mechanism to ensure the accuracy and timeliness of black and white list information.
It reduces the authentication workload of authentication server functions, reduces signaling interaction, optimizes the collaboration efficiency of the core network and satellite communication resources, and improves communication efficiency.
Smart Images

Figure CN120547556A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of wireless communication technology, and in particular to an authentication filtering method, system, device and storage medium. Background Art
[0002] In satellite-based cruise ship scenarios, user access control and blacklist and whitelist management are crucial for efficient utilization of network resources. Satellite communication resources are limited and signaling costs are high. Traditional authentication processes require forwarding all requests to the core network's AUSF for verification, which not only increases network load but also wastes resources and affects communication efficiency. Summary of the Invention
[0003] The purpose of the present invention is to solve one of the technical problems existing in the prior art to at least a certain extent.
[0004] To this end, the object of the present invention is to provide an efficient authentication filtering method, system, device and storage medium.
[0005] In order to achieve the above technical objectives, one aspect of an embodiment of the present invention provides an authentication filtering method, comprising the following steps: determining an authentication mode for an access and mobility management function; configuring blacklist and whitelist parameters required for authentication according to the authentication mode; receiving an authentication request from a target object; the authentication request carrying a user identification code and a user address; and determining, based on the blacklist and whitelist parameters and the authentication request and an authentication filtering policy, whether to reject the authentication request or to send the authentication request to an authentication server function. This application reduces the authentication workload of the authentication server function through authentication filtering, which is beneficial to reducing network load and improving communication efficiency.
[0006] In some embodiments, the determining, based on the blacklist and whitelist parameters and the authentication request and an authentication filtering policy, to reject the authentication request or to send the authentication request to an authentication server function includes:
[0007] Obtain the whitelist area configuration and whitelist number configuration in the blacklist and whitelist parameters;
[0008] If the whitelist number configuration includes the user identification code and the whitelist area configuration includes the user address, sending the authentication request to the authentication server function to cooperate with the authentication server function to complete the authentication;
[0009] Alternatively, if the whitelist number configuration does not include the user identification code or the whitelist area configuration does not include the user address, the authentication request is rejected.
[0010] In some embodiments, the determining, based on the blacklist and whitelist parameters and the authentication request and an authentication filtering policy, to reject the authentication request or to send the authentication request to an authentication server function includes:
[0011] Obtain the blacklist area configuration and blacklist number configuration in the blacklist and whitelist parameters;
[0012] If the blacklist number configuration does not include the user identification code and the blacklist area configuration does not include the user address, sending the authentication request to the authentication server function to cooperate with the authentication server function to complete the authentication;
[0013] Alternatively, if the blacklist number configuration includes the user identification code or the blacklist area configuration includes the user address, the authentication request is rejected.
[0014] In some embodiments, the determining, based on the blacklist and whitelist parameters and the authentication request and an authentication filtering policy, to reject the authentication request or to send the authentication request to an authentication server function includes:
[0015] Obtain the whitelist number configuration and blacklist number configuration in the blacklist and whitelist parameters;
[0016] If the blacklist number configuration includes the user identification code and the whitelist number configuration includes the user identification code, determining a first priority of the user identification code in the whitelist number configuration and a second priority of the user identification code in the blacklist number configuration;
[0017] If the first priority is greater than the second priority, authentication filtering is performed through a whitelist;
[0018] If the first priority is less than or equal to the second priority, authentication filtering is performed using a blacklist.
[0019] In some embodiments, configuring the blacklist and whitelist parameters required for authentication according to the authentication mode includes:
[0020] If the authentication mode is multi-source mode, turn on the authentication filtering switch and authentication filtering policy switch of the access and mobility management function;
[0021] The address of a unified data repository is set, and the blacklist and whitelist parameters of the unified data repository are obtained through the address and saved in a local cache; wherein the unified data repository synchronizes the blacklist and whitelist parameters from multiple sources.
[0022] In some embodiments, the method further comprises:
[0023] If the access and mobility management function successfully obtains the blacklist and whitelist parameters of the unified data repository, initiating a parameter subscription request to the unified data repository to subscribe to the blacklist and whitelist parameters;
[0024] If the target object updates the blacklist and whitelist parameters, it receives the notification body sent by the unified data repository, reads the subscription number and operation type of the notification body, and updates the blacklist and whitelist parameters cached locally.
[0025] In some embodiments, configuring the blacklist and whitelist parameters required for authentication according to the authentication mode includes:
[0026] If the authentication mode is local mode, turn on the authentication filtering switch of the access and mobility management function and turn off the authentication filtering policy switch;
[0027] Clear the locally saved blacklist and whitelist parameters, obtain new blacklist and whitelist parameters from the local configuration, and save them to the local cache.
[0028] On the other hand, an embodiment of the present invention provides an authentication and filtering system, including:
[0029] The first module is used to determine the authentication mode of the access and mobility management function;
[0030] The second module is used to configure the blacklist and whitelist parameters required for authentication according to the authentication mode;
[0031] The third module is used to receive an authentication request from a target object; the authentication request carries a user identification code and a user address;
[0032] The fourth module is used to determine whether to reject the authentication request or send the authentication request to an authentication server function based on the blacklist and whitelist parameters and the authentication request and an authentication filtering policy.
[0033] On the other hand, an embodiment of the present invention provides an authentication filtering device, comprising:
[0034] at least one processor;
[0035] at least one memory for storing at least one program;
[0036] When the at least one program is executed by the at least one processor, the at least one processor implements the above-mentioned authentication filtering method.
[0037] On the other hand, an embodiment of the present invention provides a storage medium storing a program executable by a processor. When the program is executed by the processor, it is used to implement the above-mentioned authentication and filtering method.
[0038] The embodiments of the present application include at least the following beneficial effects: The method provided by the embodiments of the present invention includes: determining an authentication mode for an access and mobility management function; configuring blacklist and whitelist parameters required for authentication based on the authentication mode; receiving an authentication request from a target object; the authentication request carrying a user identification code and a user address; and determining, based on an authentication filtering policy and the blacklist and whitelist parameters and the authentication request, whether to reject the authentication request or to send the authentication request to an authentication server function. Through authentication filtering, the present application reduces the authentication workload of the authentication server function, which helps reduce network load and improve communication efficiency. BRIEF DESCRIPTION OF THE DRAWINGS
[0039] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the following introduction is made to the drawings of the embodiments of the present invention or the related technical solutions in the prior art. It should be understood that the drawings introduced below are only for the convenience of clearly describing some embodiments of the technical solutions of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without any creative work.
[0040] Figure 1 A schematic diagram of a flow chart of an embodiment of the authentication and filtering method provided by the present invention;
[0041] Figure 2 A flowchart of another embodiment of the authentication and filtering method provided by the present invention;
[0042] Figure 3 A schematic structural diagram of an embodiment of the authentication and filtering system provided by the present invention;
[0043] Figure 4 This is a structural diagram of an embodiment of the authentication filtering device provided by the present invention. DETAILED DESCRIPTION
[0044] The embodiments of the present invention are described in detail below, examples of which are shown in the accompanying drawings, wherein the same or similar reference numerals throughout represent the same or similar elements or elements having the same or similar functions. The embodiments described below with reference to the accompanying drawings are exemplary and are only used to explain the present invention and are not to be construed as limiting the present invention. The step numbers in the following embodiments are provided for ease of explanation only and do not limit the order of the steps. The order of execution of the steps in the embodiments can be adaptively adjusted according to the understanding of those skilled in the art.
[0045] First, the terms used in this application are explained:
[0046] IMSI: International Mobile Subscriber Identity;
[0047] PLMN: Public Land Mobile Network;
[0048] TAC: Tracking Area Code;
[0049] AMF: Access and Mobility Management Function;
[0050] AUSF: Authentication Server Function;
[0051] UE: User Equipment;
[0052] UDR: Unified Data Repository.
[0053] In satellite-based cruise ship scenarios, user access control and blacklist and whitelist management are crucial for efficient utilization of network resources. Satellite communication resources are limited and signaling costs are high. Traditional authentication processes require forwarding all requests to the core network's AUSF for verification, which not only increases network load but also potentially wastes resources. Furthermore, cruise ship users come from a variety of sources, including temporary visitors and regular subscribers. Their blacklist and whitelist information needs to be dynamically and synchronously updated from multiple sources (such as QR code registration systems or corporate CRM systems).
[0054] This application proposes a blacklist and whitelist authentication filtering and multi-source synchronization mechanism, combined with a lightweight authentication filtering strategy, which only forwards authentication requests to AUSF for whitelist users. At the same time, it ensures the accuracy and timeliness of blacklist and whitelist information through real-time multi-source data synchronization, thereby reducing unnecessary signaling interactions and optimizing the collaborative efficiency of core network and satellite communication resources.
[0055] The authentication filtering method and system proposed in the embodiments of the present invention are described in detail below with reference to the accompanying drawings. First, the authentication filtering method proposed in the embodiments of the present invention will be described with reference to the accompanying drawings.
[0056] Reference Figure 1, an authentication filtering method is provided in an embodiment of the present invention. The authentication filtering method in the embodiment of the present invention can be applied to a terminal, a server, or software running in a terminal or a server. The terminal can be a tablet computer, a laptop computer, a desktop computer, etc., but is not limited to this. The server can be an independent physical server, or a server cluster or distributed system composed of multiple physical servers, or a cloud server that provides basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communications, middleware services, domain name services, security services, CDN, and big data and artificial intelligence platforms. The authentication filtering method in the embodiment of the present invention mainly includes the following steps:
[0057] S100: Determine the authentication mode for access and mobility management functions;
[0058] S200: Configure the blacklist and whitelist parameters required for authentication according to the authentication mode;
[0059] S300: Receive an authentication request from the target object; the authentication request carries a user identification code and a user address;
[0060] S400: According to the blacklist and whitelist parameters and the authentication request, based on the authentication filtering policy, determine whether to reject the authentication request or send the authentication request to the authentication server function.
[0061] In some possible implementations, the authentication filtering policy determines whether the authentication request belongs to a whitelist based on the matching result of the blacklist and whitelist parameters and the authentication request. If it belongs to the whitelist, the authentication request is sent to the authentication server function; if it belongs to the non-whitelist, the authentication request is rejected. The target object in this application can be a user.
[0062] In some embodiments, based on the blacklist and whitelist parameters and the authentication request, determining to reject the authentication request or to send the authentication request to the authentication server function based on the authentication filtering policy includes:
[0063] Get the whitelist area configuration and whitelist number configuration in the blacklist and whitelist parameters;
[0064] If the whitelist number configuration includes a user identification code and the whitelist area configuration includes a user address, the authentication request is sent to the authentication server function to cooperate with the authentication server function to complete the authentication;
[0065] Alternatively, if the whitelist number configuration does not include the user identification code or the whitelist area configuration does not include the user address, the authentication request is rejected.
[0066] This application can be authenticated and filtered through a whitelist.
[0067] In some embodiments, based on the blacklist and whitelist parameters and the authentication request, determining to reject the authentication request or to send the authentication request to the authentication server function based on the authentication filtering policy includes:
[0068] Get the blacklist area configuration and blacklist number configuration in the blacklist and whitelist parameters;
[0069] If the blacklist number configuration does not include the user identification code and the blacklist area configuration does not include the user address, the authentication request is sent to the authentication server function to cooperate with the authentication server function to complete the authentication;
[0070] Alternatively, if the blacklist number configuration includes a user identification code or the blacklist area configuration includes a user address, the authentication request is rejected.
[0071] This application can be authenticated and filtered using a blacklist.
[0072] In some embodiments, based on the blacklist and whitelist parameters and the authentication request, determining to reject the authentication request or to send the authentication request to the authentication server function based on the authentication filtering policy includes:
[0073] Get the whitelist and blacklist number configurations in the blacklist and whitelist parameters;
[0074] If the blacklist number configuration includes a user identification code and the whitelist number configuration includes a user identification code, determining a first priority of the user identification code in the whitelist number configuration and a second priority of the user identification code in the blacklist number configuration;
[0075] If the first priority is greater than the second priority, authentication filtering is performed through the whitelist method;
[0076] If the first priority is less than or equal to the second priority, authentication filtering is performed using a blacklist.
[0077] In some embodiments, according to the authentication mode, the blacklist and whitelist parameters required for authentication are configured, including:
[0078] If the authentication mode is multi-source mode, turn on the authentication filtering switch and authentication filtering policy switch for the access and mobility management function;
[0079] Set the address of the unified data repository, and obtain the blacklist and whitelist parameters of the unified data repository through the address and save them to the local cache; the unified data repository synchronizes the blacklist and whitelist parameters from multiple sources.
[0080] The authentication filter switch enables the authentication filter function for access and mobility management. The authentication filter policy switch enables the AMF to request the UDR to obtain authentication blacklist and whitelist parameters. The local cache is the local cache for access and mobility management.
[0081] In some embodiments, the method further comprises:
[0082] If the access and mobility management function successfully obtains the blacklist and whitelist parameters of the unified data repository, it initiates a parameter subscription request to the unified data repository to subscribe to the blacklist and whitelist parameters;
[0083] If the target object updates the blacklist and whitelist parameters, it receives the notification body sent by the unified data repository, reads the subscription number and operation type of the notification body, and updates the blacklist and whitelist parameters in the local cache.
[0084] In some embodiments, according to the authentication mode, the blacklist and whitelist parameters required for authentication are configured, including:
[0085] If the authentication mode is local, turn on the authentication filtering switch for the access and mobility management function and turn off the authentication filtering policy switch;
[0086] Clear the locally saved blacklist and whitelist parameters, obtain new blacklist and whitelist parameters from the local configuration, and save them to the local cache.
[0087] The AMF administrator selects the local configuration mode or the multi-source dynamic policy mode based on the actual scenario.
[0088] The following is a detailed description of the authentication filtering method provided by this application using a specific embodiment:
[0089] 1. The overall process of the AMF authentication and filtering mechanism.
[0090] Reference Figure 2 As shown, the overall process is:
[0091] Sub-process: Global configuration
[0092] A[Start]-->B{Operation mode selection}
[0093] B-->|Local Configuration Mode|C[AMF Local Configuration]
[0094] B-->|Multi-source dynamic mode|E[UDR centralized configuration]
[0095] Sub-process C: Local configuration process
[0096] C-->C1[1. Enable authentication filter switch 2. Disable policy switch]
[0097] C1-->C2[3.Configure blacklist and whitelist (IMSI+region)]
[0098] C2-->C3 [Trigger AMF: a. Clear the old cache b. Load the new configuration into memory]
[0099] C3-->C4 [AMF cache data]
[0100] C4-->|Local Update|C
[0101] C4-->|Authentication Decision|G
[0102] Sub-process D: Local update
[0103] D-->D1[local update]
[0104] D1-->D2 [AMF cache data]
[0105] Sub-process E: Dynamic Strategy Process
[0106] E->E1 [UDR pre-configuration: multi-source data synchronization (CRM / code scanning) and storage of multiple policy entries]
[0107] E1-->E2 [AMF configuration: a. Set UDR address b. Enable dual switch c. Optional local list (low priority)]
[0108] E2-->E3 [First synchronization: AMF pulls full data]
[0109] E3-->E4[AMF cache data]
[0110] E4-->|Real-time update linkage|F
[0111] E5-->|Authentication Decision|G
[0112] Sub-process F: Real-time update linkage
[0113] F-->F1 [Subscription mechanism: Generate subscription ID, UDR records subscription relationship]
[0114] F1-->F2 [Data change source: Enterprise CRM update or QR code scanning system operation]
[0115] F2-->F3 [UDR detects changes: increments the version number and generates a change log]
[0116] F3-->F4 [Push notification: send subscription ID and incremental data (add / delete)]
[0117] F4-->F5 [AMF Update: Atomic Update Cache]
[0118] Sub-process G: Authentication decision engine
[0119] G-->G1 [User authentication request: IMSI and location information]
[0120] G1-->G2 {Execute policy check: 1. Blacklist match or 2. Whitelist match}
[0121] G2-->|match blacklist|H[immediate rejection]
[0122] G2-->|Match Whitelist|I[Quick Release to AUSF Deep Authentication]
[0123] G2-->|Not matched|J[Immediately rejected]
[0124] 2. Description of AMF authentication filtering mode.
[0125] After AMF enables authentication filtering, there are two authentication modes: multi-source dynamic mode and local configuration mode.
[0126] 1. Key comparison of the two authentication filtering modes is shown in Table 1:
[0127] Dimensions Local configuration mode Multi-source dynamic strategy mode Data Source AMF local static configuration UDR dynamic acquisition (supports multi-source synchronization: CRM / code scanning system, etc.) Real-time AMF configuration needs to be updated manually Support real-time updates (via subscription / notification mechanism) Priority Only local configuration takes effect UDR data takes precedence, AMF local configuration is optional (lowest priority) Applicable Scenarios Small network or fixed user group Large-scale dynamic networks (such as enterprise IoT and guest access)
[0128] Table 1
[0129] 3. Authentication filtering mode process.
[0130] 1. AMF implements the authentication and filtering process based on local configuration.
[0131] Configuration steps:
[0132] Step S311: Turn on the AMF authentication filter switch and turn off the authentication filter policy switch. For a description of the switch parameters, see Section 1 of Point 6.
[0133] Step S312: The AMF configures authentication blacklist and whitelist parameters. If the whitelist method is used, the whitelist area range, whitelist numbers, and whitelist priority are configured; if the blacklist method is used, the blacklist area range, blacklist numbers, and blacklist priority are configured. For parameter descriptions, see Section 1 of Point 6.
[0134] process:
[0135] Step S321: After the authentication filtering policy switch is successfully turned off, the AMF is triggered to clear all locally saved authentication blacklist and whitelist parameters.
[0136] Step S322: After the AMF successfully configures the authentication blacklist and whitelist parameters, it triggers the AMF to obtain the authentication blacklist and whitelist from the local configuration and save the obtained authentication blacklist in the AMF cache.
[0137] Step S323: The user initiates an authentication request to AMF with IMSI and TAC information. AMF decides to directly reject the user authentication request or forward the authentication request to AUSF to complete the authentication process based on the lightweight authentication filtering mechanism of the blacklist and whitelist in point 5.
[0138] 2. AMF implements the overall authentication and filtering process based on multi-source dynamic strategies.
[0139] Configuration steps:
[0140] About UDR:
[0141] Authentication blacklist and whitelist parameters have been synchronized to the UDR: If using the whitelist method, configure the whitelist region range, whitelist numbers, and whitelist priority; if using the blacklist method, configure the blacklist region range, blacklist numbers, and blacklist priority. Parameter descriptions are in Section 1 of Point 6.
[0142] UDR blacklist and whitelist data source description: supports synchronization of authentication blacklist and whitelist parameters from multiple sources (code scanning system, enterprise CRM) to UDR. UDR supports storage of multiple authentication blacklist and whitelist parameter information.
[0143] About AMF:
[0144] AMF configures the peer UDR address;
[0145] Turn on the authentication filtering switch of AMF and turn on the authentication filtering policy switch. For the switch parameter description, see Section 1 of Point 6. AMF configures the authentication blacklist and whitelist parameters (optional): If the whitelist method is configured, configure the whitelist area range, whitelist number and whitelist priority; if the blacklist method is configured, configure the blacklist area range, blacklist number and blacklist priority. AMF configuration of authentication blacklist and whitelist parameters is an optional step. If AMF configures authentication blacklist and whitelist parameters, the authentication blacklist and whitelist parameters configured by AMF have the lowest priority. For parameter description, see Section 1 of Point 6. It should be noted that in the case of multiple sources, both AMF and UDR can configure blacklist and whitelist parameters, and AMF can also not configure blacklist and whitelist parameters. The UDR blacklist and whitelist parameters have a higher priority than the AMF local configuration. After receiving the UDR blacklist and whitelist parameters, AMF will merge the locally configured blacklist and whitelist parameters with the UDR blacklist and whitelist parameters. AMF performs authentication filtering based on the blacklist and whitelist parameters.
[0146] process:
[0147] Step S331: After the authentication filtering policy switch is successfully turned on, the AMF requests the UDR to obtain the authentication blacklist and whitelist parameters;
[0148] Step S332: AMF saves the obtained authentication blacklist and whitelist parameters in the AMF cache.
[0149] Step S333: The user initiates an authentication request to AMF with IMSI and TAC information. AMF decides to directly reject the user authentication request or forward the authentication request to AUSF to complete the authentication process based on the lightweight authentication filtering mechanism of the blacklist and whitelist in point 5.
[0150] 4. Real-time blacklist and whitelist updates are linked with user authentication.
[0151] Significance: Real-time blacklist and whitelist updates and user authentication linkage: It can achieve real-time updates of blacklist and whitelist information and link it with the user authentication process to ensure that newly added legitimate users can access the network immediately and immediately prohibit illegal users from accessing the network.
[0152] Prerequisite: The AMF has enabled the authentication filtering and authentication filtering policy switches. For a description of the switch parameters, see Section 1 of Point 6. The AMF configures the peer UDR address.
[0153] process:
[0154] Step S411: After the AMF successfully obtains the authentication blacklist and whitelist parameters from the UDR for the first time, it initiates a parameter subscription request for the authentication blacklist and whitelist parameters to the UDR.
[0155] Step S412: The UDR responds successfully and returns the subscription ID.
[0156] Step S413: After the UDR obtains the subscription ID, it uses the subscription ID as the primary key to save the authentication blacklist and whitelist parameters of the subscription.
[0157] In step S414, the user updates the blacklist and whitelist information to the UDR through the QR code scanning system or the enterprise CRM. Upon detecting the change, the UDR proactively sends a notification to the AMF subscribed to in step 1. The notification body contains the subscription ID, the operation type (add or delete), and the blacklist and whitelist information added or deleted. For a description of the notification parameters, see Section 3 of Point 6.
[0158] Step S415: The AMF receives the authentication blacklist and whitelist parameter change notification, matches the locally cached blacklist and whitelist according to the subscription ID, and adds or deletes the locally cached blacklist and whitelist according to the operation type and the blacklist and whitelist.
[0159] 5. Lightweight authentication and filtering mechanism based on blacklist and whitelist.
[0160] 1. There are two ways for AMF to control authentication filtering: authentication filtering mechanism based on whitelist and authentication filtering mechanism based on blacklist.
[0161] Method 1: Authentication filtering based on whitelist:
[0162] The AMF checks the whitelist area range configuration and whitelist number configuration. If the PLMN.TAC and IMSI carried in the authentication request meet the configured whitelist area range configuration and whitelist number, the AMF forwards the authentication request to the AUSF and cooperates with the AUSF to complete the authentication process. If one of the items is not met, the AMF rejects the authentication request initiated by the terminal.
[0163] Method 2: Blacklist-based authentication filtering:
[0164] The AMF checks the blacklist area range configuration and blacklist number configuration. If the PLMN.TAC and IMSI carried in the authentication request meet the configured blacklist area range configuration or blacklist number, the AMF rejects the authentication request initiated by the terminal. If the PLMN.TAC and IMSI carried in the authentication request do not meet the configured blacklist area range configuration and blacklist number, the AMF forwards the authentication request to the AUSF and cooperates with the AUSF to complete the authentication process.
[0165] 2. Priority-based multi-source blacklist and whitelist conflict resolution method:
[0166] Background: Because AMF blacklists and whitelists can be obtained from multiple sources, blacklist and whitelist conflicts can arise. For example, whitelist numbers in blacklist A and blacklist B may overlap. For example, AMF blacklist and whitelist parameters can be obtained from multiple sources: locally configured by the AMF and obtained from the UDR. Therefore, in some embodiments, blacklist and whitelist conflicts may arise.
[0167] For example, the AMF locally configures whitelist number 100 and blacklist number 101. The UDR sends the configuration to the AMF: whitelist number 102 and blacklist number 100. Number 100 is both on the blacklist and the whitelist. When the AMF receives an authentication request from number 100, it cannot determine whether to allow or deny authentication. This is where priority comes in.
[0168] In other embodiments, the UDR supports synchronizing authentication blacklist and whitelist parameters from multiple sources (such as code scanning systems and enterprise CRM) to the UDR. The UDR supports storing multiple authentication blacklist and whitelist parameter information. This can also lead to blacklist and whitelist conflicts.
[0169] For example, the QR code scanning system receives: whitelist number: 100, blacklist number: 101. The enterprise CRM receives: whitelist number: 102, blacklist number: 100. The UDR sends both blacklist and whitelist information to the AMF. Because number 100 is on both the blacklist and the whitelist, when the AMF receives an authentication request from number 100, it cannot determine whether to allow or deny authentication. This is where priority comes in.
[0170] This application proposes a solution that introduces a priority-based multi-source blacklist and whitelist conflict resolution mechanism. When AMF detects a blacklist and whitelist conflict, it compares the priorities of the conflicting blacklists. If the priorities differ, the higher-priority blacklist is used for authentication filtering. If the priorities are the same, the blacklist is used for authentication filtering.
[0171] 6. Parameter analysis and explanation.
[0172] 1. AMF authentication filter switch parameter table.
[0173]
[0174]
[0175] Table 2
[0176] Referring to Table 2, this application designs authentication filter switch parameters, and implements blacklist and whitelist parameter configuration under different modules by designing authentication filter switches and authentication filter policy switches for access and mobility management functions.
[0177] 2. Authentication blacklist and whitelist parameter table.
[0178]
[0179]
[0180] Table 3
[0181] See Table 3. This application filters authentication requests and reduces network load by designing authentication blacklist and whitelist parameters / blacklist and whitelist parameters. Both the UDR and AMF can configure the authentication blacklist and whitelist parameters in the table. If the multi-source dynamic policy is enabled, the AMF will request the UDR to obtain the authentication blacklist and whitelist parameters stored by the UDR; the AMF stores both the blacklist and whitelist parameters configured locally by the AMF and the blacklist and whitelist parameters obtained from the UDR in the AMF cache. When an authentication request is subsequently encountered, the AMF directly performs authentication filtering based on the cached blacklist and whitelist parameters.
[0182] PLMN: Public Land Mobile Network. For example, a network operator may have four PLMNs in a certain area: XX001, XX006, XX009, and XX010. TAC: Tracking Area Code. For example, 111111 is a park, and 222222 is an amusement park. PLMN represents a large area, while TAC represents a smaller area.
[0183] PLMN example:
[0184] 1.XX001.*: Indicates that all areas under XX001 are allowed to request AUSF to complete the authentication process.
[0185] *.11111: Parks of any PLMN are allowed to request AUSF to complete the authentication process.
[0186] 3. UDR push notification parameter table, see Table 4.
[0187]
[0188]
[0189] Table 4
[0190] This application proposes a lightweight authentication and filtering mechanism based on dynamic black and white lists: user authentication requests are pre-filtered through dynamic black and white lists, and only the authentication requests of white-listed users are forwarded to AUSF, directly rejecting non-white-listed users, thereby reducing signaling interaction and resource consumption. This application proposes a multi-source black and white list data synchronization mechanism: supports synchronization of black and white list data from multiple sources (such as code scanning systems, enterprise CRMs), and ensures the accuracy and reliability of white list information. This application proposes a real-time black and white list update and user authentication linkage mechanism: realizes real-time update of black and white list information, and links with the user authentication process to ensure that newly added legal users can access the network immediately, thereby improving service response efficiency. This application proposes a cache-driven black and white list user rejection optimization strategy: by caching the authentication information of black and white list users, direct rejection is made in subsequent access attempts to avoid repeated verification and reduce the load on core network and satellite communication resources. This application proposes a priority-based multi-source white list update conflict resolution mechanism: introduces a priority strategy in multi-source black and white list data synchronization to resolve conflicting data from different sources. This application proposes a dynamic blacklist and whitelist authentication filtering and regional restriction linkage mechanism: combining the dual restrictions of region and user number to achieve the coordinated management of dynamic blacklist and whitelist filtering and regional access control, improving access accuracy and resource utilization. This application also proposes an AMF local configuration disaster recovery mechanism: when the UDR is unreachable, local configuration mode is allowed to ensure basic authentication functions.
[0191] This application proposes a blacklist and whitelist authentication filtering and multi-source synchronization mechanism, combined with a lightweight authentication filtering strategy, which only forwards authentication requests to AUSF for whitelist users. At the same time, it ensures the accuracy and timeliness of blacklist and whitelist information through real-time multi-source data synchronization, thereby reducing unnecessary signaling interactions and optimizing the collaborative efficiency of core network and satellite communication resources.
[0192] In summary, the method provided by the embodiment of the present application includes: determining an authentication mode for an access and mobility management function; configuring blacklist and whitelist parameters required for authentication based on the authentication mode; receiving an authentication request from a target object; the authentication request carrying a user identification code and user address; and determining, based on an authentication filtering policy and the blacklist and whitelist parameters and the authentication request, whether to reject the authentication request or to send the authentication request to an authentication server function. Through authentication filtering, the present application reduces the authentication workload of the authentication server function, thereby reducing network load and improving communication efficiency.
[0193] Secondly, refer to the attached Figure 3An authentication and filtering system according to an embodiment of the present invention is described. The system specifically includes:
[0194] A first module 310 is configured to determine an authentication mode for an access and mobility management function;
[0195] The second module 320 is used to configure the blacklist and whitelist parameters required for authentication according to the authentication mode;
[0196] The third module 330 is configured to receive an authentication request from a target object; the authentication request carries a user identification code and a user address;
[0197] The fourth module 340 is configured to determine whether to reject the authentication request or send the authentication request to the authentication server function based on the blacklist and whitelist parameters and the authentication request and the authentication filtering policy.
[0198] It can be seen that the contents of the above method embodiments are all applicable to the present system embodiments. The functions specifically implemented by the present system embodiments are the same as those of the above method embodiments, and the beneficial effects achieved are also the same as those achieved by the above method embodiments.
[0199] Reference Figure 4 , an embodiment of the present invention provides an authentication filtering device, comprising:
[0200] at least one processor 410;
[0201] at least one memory 420, for storing at least one program;
[0202] When the at least one program is executed by the at least one processor 410 , the at least one processor 410 implements the authentication filtering method.
[0203] Similarly, the contents of the above method embodiments are applicable to the present device embodiments. The functions specifically implemented by the present device embodiments are the same as those of the above method embodiments, and the beneficial effects achieved are also the same as those achieved by the above method embodiments.
[0204] An embodiment of the present invention further provides a computer-readable storage medium storing a program executable by a processor. The program executable by the processor is used to execute the above-mentioned authentication and filtering method when executed by the processor.
[0205] Similarly, the contents of the above method embodiments are applicable to the present storage medium embodiment. The functions specifically implemented by the present storage medium embodiment are the same as those of the above method embodiments, and the beneficial effects achieved are also the same as those achieved by the above method embodiments.
[0206] In some optional embodiments, the function / operation mentioned in the block diagram may not occur in the order mentioned in the operation diagram. For example, depending on the function / operation involved, the two boxes shown in succession can actually be executed substantially simultaneously or the boxes can sometimes be executed in reverse order. In addition, the embodiment presented and described in the flow chart of the present invention is provided in an exemplary manner for the purpose of providing a more comprehensive understanding of the technology. The disclosed method is not limited to the operation and logic flow presented herein. Optional embodiments are contemplated in which the order of the various operations is changed and the sub-operations described as a part of a larger operation are performed independently.
[0207] In addition, although the present invention is described in the context of functional modules, it should be understood that, unless otherwise stated, one or more of the functions and / or features may be integrated into a single physical device and / or software module, or one or more functions and / or features may be implemented in separate physical devices or software modules. It is also understood that a detailed discussion of the actual implementation of each module is not necessary for understanding the present invention. More specifically, given the properties, functions, and internal relationships of the various functional modules in the devices disclosed herein, the actual implementation of the module will be understood within the ordinary skill of an engineer. Therefore, a person skilled in the art will be able to implement the present invention set forth in the claims using ordinary skill without undue experimentation. It is also understood that the specific concepts disclosed are merely illustrative and are not intended to limit the scope of the present invention, which is determined by the full scope of the appended claims and their equivalents.
[0208] If the functions are implemented in the form of software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, or the part that contributes to the prior art, or the part of the technical solution, can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several programs for enabling a computer device (which can be a personal computer, server, or network device, etc.) to perform all or part of the steps of the method described in each embodiment of the present invention. The aforementioned storage medium includes various media that can store program codes, such as a USB flash drive, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk, or an optical disk.
[0209] The logic and / or steps represented in a flowchart or otherwise described herein, for example, may be considered as an ordered list of executable programs for implementing the logical functions, and may be embodied in any computer-readable medium for use by, or in conjunction with, a program execution system, apparatus, or device (e.g., a computer-based system, a system including a processor, or other system that can retrieve and execute a program from a program execution system, apparatus, or device). For purposes of this specification, a "computer-readable medium" may be any device that can contain, store, communicate, propagate, or transport a program for use by, or in conjunction with, a program execution system, apparatus, or device.
[0210] More specific examples (a non-exhaustive list) of computer-readable media include the following: an electrical connection with one or more wires (electronic devices), a portable computer disk cartridge (magnetic devices), a random access memory (RAM), a read-only memory (ROM), an erasable and programmable read-only memory (EPROM or flash memory), a fiber optic device, and a portable compact disc read-only memory (CDROM). In addition, the computer-readable medium may even be paper or other suitable medium on which the program is printed, since the program may be obtained electronically, for example, by optically scanning the paper or other medium, followed by editing, deciphering, or processing in another suitable manner as necessary, and then stored in a computer memory.
[0211] It should be understood that various parts of the present invention can be implemented using hardware, software, firmware, or a combination thereof. In the above-described embodiments, multiple steps or methods can be implemented using software or firmware stored in a memory and executed by a suitable program execution system. For example, if implemented using hardware, as in another embodiment, any one of the following technologies known in the art or a combination thereof can be used: a discrete logic circuit having a logic gate circuit for implementing a logic function on a data signal, an application-specific integrated circuit having a suitable combination of logic gate circuits, a programmable gate array (PGA), a field programmable gate array (FPGA), etc.
[0212] In the above description of this specification, reference to the terms "one embodiment / example," "another embodiment / example," or "certain embodiments / examples" means that the specific features, structures, materials, or characteristics described in conjunction with the embodiment or example are included in at least one embodiment or example of the present invention. In this specification, the schematic representation of the above terms does not necessarily refer to the same embodiment or example. Moreover, the specific features, structures, materials, or characteristics described may be combined in any suitable manner in any one or more embodiments or examples.
[0213] While embodiments of the present invention have been shown and described, it will be appreciated by those skilled in the art that various changes, modifications, substitutions, and variations may be made to the embodiments without departing from the principles and spirit of the invention, and that the scope of the invention is defined by the claims and their equivalents.
[0214] The above is a specific description of the preferred implementation of the present invention, but the present invention is not limited to the embodiments. Those skilled in the art can make various equivalent modifications or substitutions without violating the spirit of the present invention. These equivalent modifications or substitutions are all included in the scope defined by the claims of the present invention.
Claims
1. An authentication filtering method, characterized in that: The method comprises the following steps: Determine the authentication mode for access and mobility management functions; According to the authentication mode, configure the blacklist and whitelist parameters required for authentication; Receive an authentication request from a target object; the authentication request carries a user identification code and a user address; According to the blacklist and whitelist parameters and the authentication request, based on the authentication filtering policy, it is determined whether to reject the authentication request or send the authentication request to the authentication server function.
2. The authentication filtering method according to claim 1, characterized in that: The determining, based on the blacklist and whitelist parameters and the authentication request and an authentication filtering policy, to reject the authentication request or to send the authentication request to an authentication server function includes: Obtain the whitelist area configuration and whitelist number configuration in the blacklist and whitelist parameters; If the whitelist number configuration includes the user identification code and the whitelist area configuration includes the user address, sending the authentication request to the authentication server function to cooperate with the authentication server function to complete the authentication; Alternatively, if the whitelist number configuration does not include the user identification code or the whitelist area configuration does not include the user address, the authentication request is rejected.
3. The authentication filtering method according to claim 2, characterized in that: The determining, based on the blacklist and whitelist parameters and the authentication request and an authentication filtering policy, to reject the authentication request or to send the authentication request to an authentication server function includes: Obtain the blacklist area configuration and blacklist number configuration in the blacklist and whitelist parameters; If the blacklist number configuration does not include the user identification code and the blacklist area configuration does not include the user address, sending the authentication request to the authentication server function to cooperate with the authentication server function to complete the authentication; Alternatively, if the blacklist number configuration includes the user identification code or the blacklist area configuration includes the user address, the authentication request is rejected.
4. The authentication filtering method according to claim 1, wherein: The determining, based on the blacklist and whitelist parameters and the authentication request and an authentication filtering policy, to reject the authentication request or to send the authentication request to an authentication server function includes: Obtain the whitelist number configuration and blacklist number configuration in the blacklist and whitelist parameters; If the blacklist number configuration includes the user identification code and the whitelist number configuration includes the user identification code, determining a first priority of the user identification code in the whitelist number configuration and a second priority of the user identification code in the blacklist number configuration; If the first priority is greater than the second priority, authentication filtering is performed through a whitelist; If the first priority is less than or equal to the second priority, authentication filtering is performed using a blacklist.
5. The authentication filtering method according to claim 1, characterized in that: The configuration of the blacklist and whitelist parameters required for authentication according to the authentication mode includes: If the authentication mode is multi-source mode, turn on the authentication filtering switch and authentication filtering policy switch of the access and mobility management function; The address of a unified data repository is set, and the blacklist and whitelist parameters of the unified data repository are obtained through the address and saved in a local cache; wherein the unified data repository synchronizes the blacklist and whitelist parameters from multiple sources.
6. The authentication filtering method according to claim 5, characterized in that: The method further comprises: If the access and mobility management function successfully obtains the blacklist and whitelist parameters of the unified data repository, initiating a parameter subscription request to the unified data repository to subscribe to the blacklist and whitelist parameters; If the target object updates the blacklist and whitelist parameters, it receives the notification body sent by the unified data repository, reads the subscription number and operation type of the notification body, and updates the blacklist and whitelist parameters cached locally.
7. The authentication filtering method according to claim 1, characterized in that: The configuration of the blacklist and whitelist parameters required for authentication according to the authentication mode includes: If the authentication mode is local mode, turn on the authentication filtering switch of the access and mobility management function and turn off the authentication filtering policy switch; Clear the locally saved blacklist and whitelist parameters, obtain new blacklist and whitelist parameters from the local configuration, and save them to the local cache.
8. An authentication and filtering system, characterized in that: include: The first module is used to determine the authentication mode of the access and mobility management function; The second module is used to configure the blacklist and whitelist parameters required for authentication according to the authentication mode; The third module is used to receive an authentication request from a target object; the authentication request carries a user identification code and a user address; The fourth module is used to determine whether to reject the authentication request or send the authentication request to an authentication server function based on the blacklist and whitelist parameters and the authentication request and an authentication filtering policy.
9. An authentication filtering device, characterized in that: include: at least one processor; at least one memory for storing at least one program; When the at least one program is executed by the at least one processor, the at least one processor implements the authentication filtering method according to any one of claims 1 to 7.
10. A computer-readable storage medium storing a program executable by a processor, characterized in that: The processor-executable program is used to implement the authentication filtering method according to any one of claims 1 to 7 when executed by the processor.
Citation Information
Cited By
Cross-private network communication method and system
CN122248562A