Boot authentication method, system, electronic device and readable storage medium

By introducing the first and second identifiers to the GBA network to distinguish service challenges and reboot responses, the boot authentication process between UE and BSF network elements is reduced, and the signaling increase caused by frequent rebooting in the GBA network is solved, and the reliability of the network is improved.

CN113840283BActive Publication Date: 2025-07-08ZTE CORP
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202010580221.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2020-06-23
Publication Date
2025-07-08
Estimated Expiration
2040-06-23

AI Technical Summary

Technical Problem

In GBA network, when UE interacts with multiple NAF/AP network elements, frequent rebooting processes lead to a sudden increase in signaling, causing network storms and reducing network reliability.

Method used

By introducing the first and second identifiers into the response information, the UE can distinguish between service challenges and reboot responses, thereby reducing the boot authentication process with the BSF network element, using B-TID for two-way authentication, and reducing signaling interaction.

Benefits of technology

Effectively reduce signaling interaction between UE and BSF network elements, reduce network storm risks, and improve the reliability of GBA network.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN113840283B_ABST
    Figure CN113840283B_ABST
Patent Text Reader

Abstract

An embodiment of the present invention relates to the field of communication technologies, and discloses a bootstrapping authentication method, system, electronic device, and readable storage medium. In the present invention, the above-mentioned bootstrapping authentication method includes: receiving response information sent by a Network Application Function / Authentication Proxy (NAF / AP) network element; if a preset first identifier is recognized from the response information and it is determined that a Bootstrapping Transaction Identifier (B-TID) is locally stored in the User Equipment (UE), performing mutual authentication with the NAF / AP network element according to the B-TID; wherein, the first identifier is an identifier carried in the response information when the NAF / AP network element determines to execute a service challenge. This is beneficial for reducing the number of times of the bootstrapping authentication process between the UE and the Bootstrapping Server Function (BSF) network element, thereby effectively reducing the signaling interaction between the UE and the BSF network element, reducing the risk of causing a network storm, and improving the reliability of the Generic Bootstrapping Architecture (GBA) network.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of communication technologies, and particularly to a bootstrapping authentication method, system, electronic device, and readable storage medium. Background Art

[0002] The Generic Bootstrapping Architecture (GBA) is a general bootstrapping architecture defined by the Third Generation Partnership Project (3GPP). With the development of numerous communication services, both operators and users require a reliable authentication mechanism to ensure the legitimate use of services. Especially in 3G / 4G services, many applications need to interact between the User Equipment (UE) and the Application Server (AS), such as service activation, service setting, service access, etc. To ensure the security of service applications, mutual authentication between the UE and the AS is required. If the UE and the AS directly interact, there are two serious problems: independent authentication needs to be performed between the UE and each AS, including the negotiation of the authentication mechanism and the management of keys; every time the UE logs in to a different AS, the user needs to input the key, resulting in a poor user experience. Therefore, the 3GPP standard organization proposed the concept of a general authentication architecture, and GBA is a general authentication architecture based on a shared key. GBA uses the Authentication and Key Agreement (AKA) protocol of the third-generation mobile communication network to provide a mechanism for key sharing, mutual authentication, and service protection between the UE and the network, with high security and generality.

[0003] Currently, in the typical GBA service process, the Network Application Function / Authentication Proxy (NAF / AP) network element initiates a challenge response and a re-bootstrapping response, which are the same response message (401 response) in the protocol. Therefore, as long as the UE receives a 401 response, it will immediately initiate a four-step bootstrapping process, that is, the bootstrapping authentication process between the Bootstrapping Server Function (BSF) and the UE. In a multi-NAF / AP application scenario, frequent re-bootstrapping may occur, resulting in a sudden increase in signaling and easily causing a network storm, and the reliability of the GBA network is relatively low. Summary of the Invention

[0004] The main objective of the embodiments of the present invention is to propose a bootstrapping authentication method, system, electronic device, and readable storage medium, which can effectively reduce the signaling interaction between the UE and the BSF network element, reduce the risk of causing network storms, and improve the reliability of the GBA network.

[0005] To achieve the above objective, an embodiment of the present invention provides a bootstrapping authentication method applied to a user equipment UE, including: receiving response information sent by a network application function / authentication proxy NAF / AP network element; if a preset first identifier is identified from the response information and it is determined that the UE locally stores a bootstrapping transaction identifier B-TID, performing mutual authentication with the NAF / AP network element according to the B-TID; where; the first identifier is an identifier carried in the response information when the NAF / AP network element determines to perform a service challenge.

[0006] To achieve the above objective, an embodiment of the present invention provides a bootstrapping authentication method applied to a network application function / authentication proxy NAF / AP network element, including: if it is determined to perform a service challenge, sending response information carrying a preset first identifier to a user equipment UE, so that when the UE identifies the first identifier and determines that the UE locally stores a bootstrapping transaction identifier B-TID, mutual authentication is performed with the NAF / AP network element according to the B-TID.

[0007] To achieve the above objective, an embodiment of the present invention provides a bootstrapping authentication system, including: a network application function / authentication proxy NAF / AP network element and a user equipment UE; the NAF / AP network element is configured to, if it is determined to perform a service challenge, send response information carrying a preset first identifier to the user equipment UE; the UE is configured to receive the response information sent by the NAF / AP network element, and if the first identifier is identified from the response information and it is determined that the UE locally stores a bootstrapping transaction identifier B-TID, perform mutual authentication with the NAF / AP network element according to the B-TID.

[0008] To achieve the above objective, an embodiment of the present invention provides an electronic device, including: at least one processor; and a memory communicatively connected to the at least one processor; where the memory stores instructions executable by the at least one processor, and when the instructions are executed by the at least one processor, when the electronic device is a network application function / authentication proxy network element, the at least one processor is capable of executing the bootstrapping authentication method applied to the NAF / AP network element as described above; when the electronic device is a user equipment, the at least one processor is capable of executing the bootstrapping authentication method applied to the UE as described above.

[0009] To achieve the above object, an embodiment of the present invention provides a computer-readable storage medium storing a computer program, which when executed by a processor implements the above-mentioned boot authentication method applied to a NAF / AP network element, or implements the above-mentioned boot authentication method applied to a UE.

[0010] Compared with the prior art, according to the first identifier, a UE can conveniently identify that the response information is the response information sent by the NAF / AP network element when determining to execute a service challenge. If the UE identifies the first identifier from the response information, the UE can determine that the received response information is a service challenge response. If it is determined at this time that the B-TID is locally stored, the UE can directly use the B-TID to perform mutual authentication with the NAF / AP without having to execute the boot authentication process between the UE and the BSF network element, which helps to reduce the number of times the UE initiates the boot authentication process with the BSF network element, thereby effectively reducing the signaling interaction between the UE and the BSF network element, reducing the risk of causing a network storm, and improving the reliability of the GBA network. BRIEF DESCRIPTION OF THE DRAWINGS

[0011] Figure 1 is a schematic diagram of the GBA architecture mentioned in the first embodiment of the present invention;

[0012] Figure 2 is a typical service flow chart of GBA in the prior art mentioned in the first embodiment of the present invention;

[0013] Figure 3 is the GBA re-boot service process in the prior art mentioned in the first embodiment of the present invention;

[0014] Figure 4 is a service flow chart in the prior art mentioned in the first embodiment of the present invention, where frequent re-boots may occur in the application scenario of multiple NAF / AP network elements, causing a network storm;

[0015] Figure 5 is a flow chart of the boot authentication method mentioned in the first embodiment of the present invention;

[0016] Figure 6 is a service flow chart of the UE receiving response information carrying the first identifier mentioned in the first embodiment of the present invention;

[0017] Figure 7 is a service flow chart of the UE receiving response information carrying the second identifier mentioned in the first embodiment of the present invention;

[0018] Figure 8 is a schematic diagram of the process of the UE performing mutual authentication with the NAF / AP network element according to the B-TID mentioned in the second embodiment of the present invention;

[0019] Figure 9 It is a flowchart of a UE accessing multiple NAF / AP network elements mentioned in the second embodiment of the present invention;

[0020] Figure 10 It is a flowchart of a bootstrapping authentication method mentioned in the third embodiment of the present invention;

[0021] Figure 11 It is a schematic diagram of a GBA networking design for disaster recovery scenarios in the prior art mentioned in the fourth embodiment of the present invention;

[0022] Figure 12 It is a disaster recovery flowchart in the prior art mentioned in the fourth embodiment of the present invention;

[0023] Figure 13 It is a flowchart of backing up disaster recovery data mentioned in the fourth embodiment of the present invention;

[0024] Figure 14 It is a flowchart of refreshing bootstrapping authentication mentioned in the fourth embodiment of the present invention;

[0025] Figure 15 It is a service flowchart from detecting a BSF network element failure to downloading disaster recovery data through a takeover-capable BSF network element mentioned in the fourth embodiment of the present invention;

[0026] Figure 16 It is a schematic diagram of a bootstrapping authentication system mentioned in the fifth embodiment of the present invention;

[0027] Figure 17 It is a schematic diagram of the structure of an electronic device mentioned in the sixth embodiment of the present invention. Detailed implementation manners

[0028] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the following will elaborate on each implementation manner of the present invention in conjunction with the accompanying drawings. However, those of ordinary skill in the art can understand that in each implementation manner of the present invention, many technical details are proposed to help readers better understand the present application. However, even without these technical details and various changes and modifications based on the following implementation manners, the technical solutions claimed in the present application can still be implemented. The division of the following embodiments is for convenience of description and should not constitute any limitation to the specific implementation manners of the present invention. The various embodiments can be combined and cross-referenced with each other on the premise of no contradiction.

[0029] The first embodiment of the present invention relates to a bootstrapping authentication method applied to a user equipment UE, where the UE is distributed in a GBA architecture. For ease of understanding, the following first briefly describes the GBA architecture:

[0030] In one example, the schematic diagram of the GBA architecture can be referred to Figure 1, the logical entities in the GBA architecture may include: Bootstrapping Server Function (BSF) network element, Network Application Function (NAF) / Authentication Proxy (NAF / AP) network element, Home Subscribe Server (HSS), User Equipment (UE), etc. The functions of each logical entity may be as follows:

[0031] The BSF network element is in the user's home network. The BSF network element obtains the user security settings and AKA authentication vectors of GBA from the HSS through the Zh interface, and completes the authentication of the UE to establish the shared key Ks.

[0032] The NAF network element is equivalent to the Application Server (AS). After receiving the service request from the UE, the NAF network element can obtain the key information negotiated during the bootstrapping authentication process of the UE and the BSF network element through the Zn interface, and complete the authentication of the UE.

[0033] The AP network element is generally deployed between the UE and the AS. The AP network element can proxy the AS to complete the authentication of the UE, and then the AP network element can forward the service request of the UE to the AS for the AS to process the service request.

[0034] The HSS stores the user security settings, private user identifiers, and authentication vectors. The HSS supports returning the authentication vectors to the BSF network element through the Zh interface.

[0035] The UE supports the AKA protocol / Hyper Text Transfer Protocol (HTTP) Digest protocol, and can perform two-way authentication with the BSF network element to generate Ks. Furthermore, based on Ks, a derived key Ks_NAF is generated, which can be used for the two-way authentication between the UE and the NAF / AP.

[0036] The inventor of the present application analyzed the typical GBA service process in the prior art and found that in the typical GBA service process, the NAF / AP initiates a service challenge ( Figure 2 steps 1-2) and the NAF / AP initiates a re-bootstrapping ( Figure 3Steps 3-4) are the same response message (401 Unauthorized) in the protocol, and the signaling is exactly the same, making it impossible to distinguish. Therefore, as long as the UE receives a 401 response, unable to tell whether it is a challenge or a re-boot, it needs to immediately initiate the four-step bootstrapping process. In the multi-NAF / AP application scenario ( Figure 4 ) frequent re-boots may occur, causing a network storm. The following briefly explains Figure 2 , Figure 3 , Figure 4 mentioned in this paragraph:

[0037] Figure 2 is a typical service flow chart of GBA in the prior art, including:

[0038] Steps 1-1 to 1-2, the UE sends an initial service request (HTTP GET, without B-TID) to the NAF / AP network element, and the NAF / AP network element initiates a service challenge to the UE.

[0039] Steps 1-3 to 1-9, after receiving the service challenge initiated by the NAF / AP network element, the UE executes the four-step bootstrapping process (i.e., bootstrapping initiation, bootstrapping challenge, bootstrapping challenge response, bootstrapping success). Steps 1-3 to 1-9 are as follows:

[0040] Step 1-3, the UE sends an HTTP request to the BSF network element to indicate bootstrapping initiation. The HTTP request may carry the user's private user identifier (IMPI).

[0041] Step 1-4, the BSF network element sends a user authentication request (Multimedia Authentication Request, abbreviated as: MAR) to the HSS. IMPI may be carried in the MAR.

[0042] Step 1-5, the HSS sends a user authentication response (Multimedia Authentication Answer, abbreviated as: MAA) to the BSF network element.

[0043] Among them, after receiving the MAR message, the HSS runs the AKA algorithm to calculate the authentication vector for the user, and the authentication vector is carried in the MAA, such as the five-element vector of AKA authentication: random number RAND, network authentication token AUTN, expected authentication reply XRES, confidentiality key CK, integrity key IK.

[0044] Step 1-6, the BSF network element sends a bootstrapping challenge to the UE.

[0045] Among them, the BSF network element can construct a 401 Unauthorized message to be sent to the UE based on the authentication vectors carried in the MAA, which means that the BSF network element sends a bootstrapping challenge to the UE. The 401 Unauthorized message can contain RAND and AUTN, and does not carry IK, CK, and XRES.

[0046] Step 1-7, the UE sends a bootstrapping challenge response to the BSF network element.

[0047] Among them, the UE authenticates the network by checking the AUTN, including checking for out-of-order. The UE calculates CK, IK, and RES based on its own key information, so that both the BSF and the UE have the shared key Ks = CK || IK. The UE sends an HTTP GET to the BSF, which contains the AKA response value (RES) calculated by the UE, that is, the UE sends a bootstrapping challenge response (HTTP GET) to the BSF network element.

[0048] Step 1-8, the BSF network element authenticates the UE and generates the shared key Ks and the B-TID.

[0049] Among them, the BSF can complete the authentication of the UE by calculating RES based on its own key information.

[0050] Step 1-9, the BSF network element sends a bootstrapping success (200 OK) message to the UE.

[0051] Among them, it is generated after the BSF network element successfully authenticates the UE. The BSF network element sends a 200 OK message to the UE to notify successful authentication, and this message contains the B-TID. In a specific implementation, the 200 OK message can also contain the lifetime of the shared key Ks.

[0052] So far, the above steps 1-3 to 1-9 implement the bootstrapping authentication between the BSF and the UE through the AKA protocol. After successful authentication, the UE and the BSF have the B-TID and Ks.

[0053] Step 1-10, after the UE's bootstrapping is successful, it sends a service challenge response carrying the B-TID to the NAF / AP network element.

[0054] Step 1-11, the NAF / AP network element goes to the BSF network element to look up the user authentication data.

[0055] Step 1-12, the BSF network element returns the user authentication data to the NAF / AP network element.

[0056] Step 1-13, perform service authentication and save (B-TID, Ks_NAF)

[0057] Among them, the NAF / AP network element and the UE complete mutual authentication through the derived key Ks_NAF derived from Ks.

[0058] In steps 1-14 to 1-16, the NAF / AP network element forwards the service request to the AS, receives the service response from the AS, and returns it to the UE.

[0059] In steps 1-17 to 1-19, the UE initiates a service request again, and the NAF / AP network element authenticates the UE based on the B-TID and Ks_NAF saved last time. After the authentication is passed, the service request is forwarded to the AS, thereby quickly completing the service access process.

[0060] Figure 3 In the prior art, the GBA redirects the service process, including:

[0061] Steps 3-1 to 3-2: The UE sends an initial service request to the NAF / AP network element, and the NAF / AP network element initiates a service challenge to the UE.

[0062] Step 3-3: After receiving the challenge, the UE executes the four-step bootstrap process. The bootstrap authentication between the BSF and the UE is implemented through the AKA protocol. When the authentication is successful, the UE and the BSF have B-TID1, Ks and IMPI. Figure 2 The description of the four-step guidance process will not be repeated here.

[0063] Steps 3-4 to 3-7, after the UE is successfully bootstrapped, it sends a service challenge response carrying B-TID1. The NAF / AP network element queries the BSF for user authentication data based on the B-TID1 in the challenge response, but the BSF returns a failure response (in abnormal scenarios such as BSF sending a restart, the user subscription data is lost). The NAF / AP network element fails to query and replies with a 401 response to the UE, instructing the UE to initiate the reboot process.

[0064] Step 3-8: After receiving the redirection response, the UE performs a four-step bootstrapping process. The two-way authentication between the BSF and the UE is implemented through the AKA protocol. When the authentication is successful, the UE and the BSF have B-TID2, Ks and IMPI.

[0065] Steps 3-9 to 3-15, after the redirection is successful, the UE executes the service access process. The UE and NAF / AP complete the two-way authentication through Ks_NAF generated by Ks.

[0066] Figure 4 This is a service flow chart of the frequent reboots that may cause network storms in the application scenario of multiple NAF / AP network elements in the prior art, including:

[0067] Steps 4-1 to 4-6, the UE initiates a service request to the NAF1 / AP1 network element. After four-step bootstrapping, the UE and the BSF network element obtain B-TID1 and Ks. After the NAF1 / AP1 network element performs service authentication, it locally stores B-TID1 and Ks_NAF1, and forwards the service request to the AS.

[0068] Steps 4-7 to 4-13, the UE initiates a service request to the NAF2 / AP2 network element. After another four-step bootstrapping, the UE and the BSF network element obtain a new B-TID2 and Ks. After the NAF2 / AP2 network element performs service authentication, it locally stores B-TID2 and Ks_NAF2, and forwards the service request to the AS.

[0069] Steps 4-14 to 4-16, when the UE accesses the NAF1 / AP1 network element again, because the re-bootstrapping process was executed when accessing the NAF2 / AP2 network element, and it carries B-TID2. The NAF1 / AP1 network element checks that it does not have B-TID2 locally and returns a 401 to instruct the UE to re-bootstrap.

[0070] Step 4-17, the UE initiates a re-bootstrapping to the BSF network element again and generates B-TID3.

[0071] Next, the NAF1 / AP1 network element queries B-TID3 and Ks_NAF from the BSF network element to authenticate the UE. The NAF1 / AP1 network element locally stores the B-TID3 and Ks_NAF data. At the same time, the NAF1 / AP1 network element also has unexpired B-TID1 and Ks_NAF garbage data locally.

[0072] And so on, when the UE accesses the NAF2 / AP2 network element again, it will initiate a four-step bootstrapping process and generate B-TID4, then the originally stored B-TID1, B-TID2, and B-TID3 all become garbage data.

[0073] This scenario will cause the NAF / AP network element to store a large amount of garbage data, resulting in a sharp increase in signaling to the NAF / AP network element and the BSF network element, which may cause a network storm and reduce the network reliability of GBA.

[0074] The bootstrapping authentication method proposed in the first embodiment of this application can effectively reduce the signaling interaction between the UE and the BSF network element, reduce the risk of causing a network storm, and improve the network reliability of GBA. The implementation details of the bootstrapping authentication method in this embodiment are described below. The following content is only provided for convenience of understanding and is not necessary for implementing this solution.

[0075] The flowchart of the bootstrapping authentication method in this embodiment can refer to Figure 5 , including:

[0076] Step 501: Receive the response information sent by the Network Application Function / Authentication Proxy (NAF / AP) network element.

[0077] Specifically, the UE can receive the response information sent by the NAF / AP network element, and the response information can be a 401 response.

[0078] In one example, if the NAF / AP network element determines to perform a service challenge, it can send the response information carrying a preset first identifier to the UE, so that the UE can receive the response information carrying the first identifier. Among them, the NAF / AP network element can determine to perform a service challenge in the following situations: the NAF / AP network element receives a service request (HTTP GET) sent by the UE, and the service request does not carry a B-TID. At this time, the NAF / AP network element can determine to perform a service challenge.

[0079] In another example, if the NAF / AP network element determines to perform a re-boot, it can send the response information carrying a preset second identifier to the UE, so that the UE can receive the response information carrying the second identifier. Among them, the NAF / AP network element can determine to perform a re-boot in the following situations: the NAF / AP network element receives a service request (HTTP GET) sent by the UE, and the service request carries a B-TID, but the NAF / AP network element detects that the B-TID is not stored locally and cannot be found in the BSF network element either, indicating that the B-TID carried in the service request received by the NAF / AP network element has expired or is illegal. At this time, the NAF / AP network element can determine to perform a re-boot. Or, when the NAF / AP network element detects a BSF network element failure, it can determine to perform a re-boot.

[0080] In one example, the first identifier and the second identifier are different parameter values of the Reason-Phrase parameter. Herein, the parameter values of the Reason-Phrase parameter can be customized. For example, if the first identifier is "unauthorized" and the second identifier is "renegotiation", the response message carrying the first identifier can be expressed as "401 unauthorized", i.e., a challenge response; the response message carrying the second identifier can be expressed as "401 renegotiation", i.e., a re-direction response. Herein, both "unauthorized" and "renegotiation" can be understood as the parameter values customized for the Reason-Phrase parameter. It should be noted that in this embodiment, only the above two customized parameter values are taken as examples, and the specific implementation is not limited thereto. Those skilled in the art can customize the parameter values of the Reason-Phrase parameter according to actual needs to distinguish the first identifier and the second identifier. By defining different parameter values for the Reason-Phrase parameter, it is convenient to distinguish whether the received response message is a service challenge response (the response message sent when the NAF / AP network element determines to perform a service challenge) or a re-direction response (the response message sent when the NAF / AP network element determines to perform a re-direction).

[0081] In the specific implementation, the first identifier and the second identifier can be different numbers, letters, symbols, etc. However, the specific forms of the first identifier and the second identifier are not specifically limited in this embodiment.

[0082] In one example, the first identifier and the second identifier are located in the header of the response message. Being located in the header of the response message facilitates the UE to quickly identify which identifier the received response message carries after receiving the response message.

[0083] In one example, if the NAF / AP network element determines to perform a service challenge, it can send a response message carrying a preset first identifier to the UE. If the NAF / AP network element determines to perform a re-direction, it can send a response message without adding an identifier to the UE. With such a setting, after receiving the response message, if the UE identifies the first identifier from the response message, it can determine that the received response message is actually a service challenge response; if the UE does not identify any preset identifier from the response message, it can determine that the received response message is actually a re-direction response, that is, the UE can also distinguish between a service challenge response and a re-direction response. The purpose of this embodiment is to enable the UE to distinguish between a service challenge response and a re-direction response, and the specific manner of distinction is not specifically limited.

[0084] Step 502: Determine whether the first identifier is identified from the response message; if so, execute Step 503, otherwise execute Step 504.

[0085] That is to say, the UE can determine whether it can recognize the first identifier from the response information. If the first identifier is recognized, step 503 can be executed. If the first identifier is not recognized, step 504 can be executed.

[0086] Step 503: If it is determined that the UE locally stores the Boot Transaction Identifier B-TID, perform mutual authentication with the NAF / AP network element according to the B-TID.

[0087] Specifically, if the UE recognizes a preset first identifier from the response information, it can be determined that the response information sent by the NAF / AP network element is actually a service challenge response. At this time, the UE can determine whether the Boot Transaction Identifier B-TID is locally stored. If the UE determines that the B-TID is locally stored, it indicates that the locally stored B-TID is valid, and the UE can perform mutual authentication with the NAF / AP network element according to the B-TID.

[0088] In one example, the process of the UE performing mutual authentication with the NAF / AP network element according to the B-TID can be as follows:

[0089] The UE sends a service challenge response carrying the B-TID to the NAF / AP network element. After receiving the service challenge response, the NAF / AP network element queries the UE's authentication data from the BSF network element. The NAF / AP locally stores data such as the B-TID and the derived key Ks_NAF. Mutual authentication is performed between the NAF / AP and the UE through the derived key. After the authentication is passed, the service request is forwarded to the AS, and the AS processes the service request. Since how the NAF / AP and the UE perform mutual authentication through the derived key belongs to the scope of the prior art, the implementation manner of how to perform mutual authentication through the derived key is not described in detail in this embodiment.

[0090] In one example, if the UE recognizes a preset first identifier from the response information but determines that the B-TID is not locally stored, the UE can initiate a boot authentication process with the BSF network element. Among them, the process of the UE initiating the boot authentication process with the BSF network element can refer to Figure 2 the four-step boot process shown in, and details are not repeated here to avoid redundancy. Recognizing the first identifier and determining that the UE does not locally store the B-TID indicates that the boot authentication has not been performed between the UE and the BSF network element, or the B-TID obtained after the UE and the BSF network element perform boot authentication has become invalid. At this time, initiating the boot authentication process with the BSF network element is beneficial to ensuring the normal progress of the boot authentication process when necessary.

[0091] Step 504: Initiate a boot authentication process with the Boot Service Function BSF network element.

[0092] In one example, if the UE does not recognize the first identifier from the response information but recognizes a preset second identifier, it can be determined that the response information sent by the NAF / AP network element is actually a re - boot response. At this time, the UE can directly initiate a boot authentication process with the BSF network element. The implementation process of the UE initiating the boot authentication process with the BSF network element can refer to Figure 2 the four - step boot process shown in

[0093] and will not be elaborated here to avoid repetition.

[0094] For the convenience of understanding this embodiment, the following briefly describes the service process in which the UE receives the response information carrying the first identifier, which can be referred to Figure 6 , including:

[0095] Step 6 - 1, the UE initiates a four - step boot authentication process to the BSF network element and obtains the B - TID and Ks from the BSF network element. The specific implementation method of the four - step boot authentication process can refer to Figure 2 and will not be elaborated here.

[0096] Step 6 - 2, the UE initiates a service request (HTTP GET) to the NAF / AP network element.

[0097] Step 6 - 3, the NAF / AP network element determines that the received is a primary service request and performs a service challenge.

[0098] Step 6 - 4, the NAF / AP network element sends the response information carrying the first identifier to the UE.

[0099] Step 6 - 5, the UE recognizes the first identifier and already has the B - TID locally, and does not initiate a re - boot process. When the UE recognizes the first identifier, it can determine that the received response information is a service challenge response.

[0100] Step 6 - 6, the UE sends a service challenge response to the NAF / AP network element. The UE derives a derived secret key based on the B - TID and Ks of the previous boot, calculates the response value response according to the derived secret key, and the UE carries the response value response in the service challenge response replied to the NAF / AP network element.

[0101] Steps 6 - 7 to 6 - 10, the NAF / AP network element queries the UE authentication data, that is, the user authentication data, from the BSF network element, locally saves data such as B - TID and Ks_NAF, and authenticates the UE. After successful authentication, it forwards the service request to the AS(Figure 6 (not shown in the figure).

[0102] For the convenience of understanding this embodiment, the following briefly describes the service process in which the UE receives the response message carrying the second identifier, which can be referred to Figure 7 , including:

[0103] Step 7-1, the UE initiates a four-step bootstrapping authentication process to obtain the B-TID and Ks from the BSF network element. Among them, the specific implementation method of the four-step bootstrapping authentication process can be referred to Figure 2 , which will not be elaborated here.

[0104] Step 7-2, the UE initiates an initial service request to the NAF / AP network element; among them, the B-TID may not be carried in the initial service request.

[0105] Step 7-3, the NAF / AP network element determines that the received is an initial service request and executes a service challenge.

[0106] Step 7-4, the NAF / AP network element sends a response message carrying the first identifier to the UE, such as a service challenge (401 unauthorized).

[0107] Step 7-5, the UE derives a derived secret key based on B-TID1 and Ks, calculates the response value response, and sends a challenge response to the NAF / AP network element. The challenge response carries B-TID1 and response, etc.

[0108] Step 7-6, the NAF / AP network element fails to obtain B-TID1 or detects BSF disaster recovery and determines to perform re-bootstrapping. Among them, when the NAF / AP network element does not detect B-TID1 locally or in the BSF network element, it can be considered that the NAF / AP network element fails to obtain B-TID1.

[0109] Step 7-7, the NAF / AP network element sends a response message carrying the second identifier to the UE, such as 401 renegotiation.

[0110] Step 7-8, the UE receives the re-bootstrapping response and re-initiates the four-step bootstrapping process to the BSF network element to obtain a new Ks and B-TID2.

[0111] Step 7-9, the UE sends a service challenge response to the NAF / AP network element. Among them, the UE derives a derived secret key based on B-TID2 and Ks, calculates the response value response, and sends a service challenge response carrying the response value response to the NAF / AP network element. The service challenge response also carries B-TID2.

[0112] Steps 7-10 to 7-13, the NAF / AP network element queries the UE authentication data, i.e., the user authentication data, from the BSF network element, locally saves data such as B-TID2 and Ks_NAF, and authenticates the UE. If the authentication is successful, it forwards the service request to the AS ( Figure 7 not shown in

[0113] It should be noted that the above examples in this embodiment are all illustrative examples for easy understanding and do not limit the technical solutions of the present invention.

[0114] Compared with the prior art, in this embodiment, the UE can easily identify, according to the first identifier, that the response information is the response information sent by the NAF / AP network element when determining to execute a service challenge. If the UE identifies the first identifier from the response information, the UE can determine that the received response information is a service challenge response. If it is determined at this time that B-TID has been locally stored, the UE can directly use this B-TID for mutual authentication with the NAF / AP without having to execute the bootstrapping authentication process between the UE and the BSF network element, which helps to reduce the number of times of the bootstrapping authentication process initiated by the UE between the UE and the BSF network element, thereby effectively reducing the signaling interaction between the UE and the BSF network element, reducing the risk of causing a network storm, and improving the reliability of the GBA network. In addition, the UE can easily identify, according to the second identifier, that the response information is the response information sent by the NAF / AP network element when determining to execute re-bootstrapping. If the UE identifies the second identifier from the response information, the UE can determine that the received response information is a re-bootstrapping response, and then the UE can initiate the bootstrapping authentication process with the BSF network element. Moreover, since the probability of the NAF / AP network element initiating re-bootstrapping information in the typical GBA service process is small, the probability that the UE initiates the bootstrapping authentication process with the BSF network element because it receives a re-bootstrapping response is also small. The UE can clearly distinguish whether the received response information is a service challenge response or a re-bootstrapping response through the first identifier and the second identifier, which helps to reduce the number of times of the bootstrapping authentication process initiated by the UE between the UE and the BSF network element, thereby effectively reducing the signaling interaction between the UE and the BSF network element, reducing the risk of causing a network storm, and improving the reliability of the GBA network.

[0115] The second embodiment of the present invention relates to a bootstrapping authentication method. After the UE executes the bootstrapping process with the BSF network element in this embodiment, it can use the B-TID and the shared key obtained after a successful authentication to access multiple NAF / APs simultaneously, which helps to reduce the number of times of the bootstrapping authentication process initiated by the UE between the UE and the BSF network element, thereby effectively reducing the signaling interaction between the UE and the BSF network element, reducing the risk of causing a network storm, and improving the reliability of the GBA network. The implementation details of the bootstrapping authentication method in this embodiment are described below. The following content is only the implementation details provided for easy understanding and is not necessary for implementing this solution.

[0116] Before receiving the response information sent by the NAF / AP network element in this embodiment, it further includes: The UE initiates a bootstrapping authentication process with the BSF network element, and obtains the B-TID and the shared key corresponding to the B-TID after the bootstrapping authentication is successful.

[0117] In one example, the process of the UE performing mutual authentication with the NAF / AP network element based on the B-TID can refer to Figure 8 , including:

[0118] Step 801: Determine the encryption information corresponding to the NAF / AP network element that sends the response information.

[0119] Among them, different NAF / AP network elements correspond to different encryption information. The encryption information may include: a random number RAND, a NAF_Id, etc. The NAF_Id may be composed of the host name of the AS and the security identifier Ua.

[0120] Step 802: Generate a derived key according to the shared key corresponding to the B-TID and the encryption information corresponding to the NAF / AP network element.

[0121] In one example, the authentication function between the UE and the NAF / AP is integrated in the mobile phone. The derived key may be represented as Ks_NAF, and the acquisition method of Ks_NAF may be: Ks_NAF = KDF(Ks, gba-me, RAND, IMPI, NAF_Id), where me in gba-me refers to mobile equipment, corresponding to the mobile phone, and gba-me can be understood as the identification information of the mobile phone.

[0122] In another example, the authentication function between the UE and the NAF / AP is integrated in the SIM card. The derived key may be represented as Ks_int_NAF, and the acquisition method of Ks_int_NAF may be: Ks_int_NAF = KDF(Ks, gba-u, RAND, IMPI, NAF_Id), where u in gba-u refers to Universal Integrated Circuit Card, abbreviated as uicc, corresponding to the SIM card, and gba-u can be understood as the identification information of the SIM card.

[0123] It can be understood that for different NAF / AP network elements, due to different encryption information, the finally generated derived keys are also different.

[0124] Step 803: Perform mutual authentication with the NAF / AP network element according to the derived key.

[0125] For the convenience of understanding this embodiment, the following briefly describes the process of a UE accessing multiple NAF / AP network elements, which can be referred to Figure 9 , including:

[0126] Step 9-1, the UE initiates a four-step bootstrapping authentication process to obtain the B-TID and Ks from the BSF network element.

[0127] Step 9-2, the UE initiates a service request to the NAF1 / AP1 network element.

[0128] Step 9-3, the NAF1 / AP1 network element sends response information carrying the first identifier to the UE, such as a service challenge (401 unauthorized).

[0129] Step 9-4, the UE returns a service challenge response to the NAF1 / AP1 network element. Among them, if the UE recognizes the first identifier and confirms that the B-TID already exists locally, it does not initiate a re-bootstrapping process. The UE generates a derived secret key Ks_int_NAF1 based on the previously bootstrapped B-TID, Ks, and the encryption information corresponding to the NAF1 / AP1 network element. The UE uses the derived secret key Ks_int_NAF1 to calculate the response value response and returns a service challenge response to the NAF1 / AP1.

[0130] Steps 9-5 to 9-7, after the NAF1 / AP1 queries the UE authentication data, i.e., the user authentication data, from the BSF, locally saves data such as the B-TID and Ks_NAF1, and authenticates the UE. If the authentication is successful, it forwards the service request to the AS ( Figure 9 not shown in the figure).

[0131] Step 9-8, the UE initiates a service request to the NAF2 / AP2 network element.

[0132] Step 9-9, the NAF2 / AP2 network element sends response information carrying the first identifier to the UE, such as a service challenge (401 unauthorized).

[0133] Step 9-10, the UE returns a service challenge response to the NAF2 / AP2 network element. Among them, if the UE recognizes the first identifier and confirms that the B-TID already exists locally, it does not initiate a re-bootstrapping process. The UE generates a derived secret key Ks_int_NAF2 based on the previously bootstrapped B-TID, Ks, and the encryption information corresponding to the NAF2 / AP2 network element. The UE uses the derived secret key Ks_int_NAF2 to calculate the response value response and returns a service challenge response to the NAF2 / AP2.

[0134] Steps 9-11 to 9-13, the NAF2 / AP2 network element queries the UE authentication data from the BSF network element, that is, after the user authentication data, locally saves data such as B-TID and Ks_NAF2, and authenticates the UE. After successful authentication, forwards the service request to the AS.

[0135] Steps 9-14 to 9-16, the UE initiates a service request to the NAF1 / AP1 network element. The NAF1 / AP1 network element executes a service challenge and sends a service challenge (401 unauthorized) to the UE. The UE and the NAF1 / AP1 network element still perform mutual authentication based on the previous derived key Ks_NAF.

[0136] Pass Figure 9 It can be seen that the UE accesses multiple NAF / AP network elements simultaneously, such as the above-mentioned NAF1 / AP1 network element and NAF2 / AP2 network element. When the UE receives a service challenge response (for example, 401 unauthorized), the UE can check whether the locally stored B-TID is valid (not timed out). If the locally stored B-TID is valid, the UE can generate a derived key according to the already bootstrapped B-TID and Ks, and directly use it for authentication without re-bootstrapping, so as to realize accessing multiple ASs with one B-TID. Among them, the UE can check whether the locally stored B-TID is valid, which can be understood as: the UE checks whether the B-TID is stored locally. If the B-TID is invalid, the UE checks and deletes the B-TID and will not save it.

[0137] It should be noted that the above examples in this embodiment are all illustrative examples for easy understanding and do not limit the technical solutions of the present invention.

[0138] Compared with the prior art, in this embodiment, for different NAF / APs, a derived key can be generated according to the B-TID, shared key, and encryption information corresponding to the NAF / AP network element after successful bootstrapping authentication, so that the NAF / AP network element can complete mutual authentication with the UE based on this derived key. That is, after the UE executes the bootstrapping process with the BSF network element, it can use the B-TID and shared key obtained after a successful authentication to access multiple NAF / APs simultaneously, which is beneficial to reducing the number of bootstrapping authentication processes initiated between the UE and the BSF network element, thereby effectively reducing the signaling interaction between the UE and the BSF network element, reducing the risk of causing network storms, and improving the reliability of the GBA network.

[0139] The third embodiment of the present invention relates to a bootstrapping authentication method applied to the NAF / AP network element. The implementation details of the bootstrapping authentication method in this embodiment are described below. The following content is only the implementation details provided for easy understanding and is not necessary for implementing the solution.

[0140] In this embodiment, the flowchart of the bootstrapping authentication method can be referred to Figure 10 , including:

[0141] Step 1001: Determine whether to perform a service challenge; if yes, perform Step 1002, otherwise perform Step 1003.

[0142] That is to say, the NAF / AP network element can determine whether to perform a service challenge. In one example, the NAF / AP network element can determine to perform a service challenge in the following cases: The NAF / AP network element receives a service request (HTTP GET) sent by the UE, and the B-TID is not carried in the service request. At this time, the NAF / AP network element can determine to perform a service challenge.

[0143] Step 1002: Send response information carrying a preset first identifier to the UE, so that when the UE recognizes the first identifier and determines that the B-TID is locally stored in the UE, two-way authentication is performed with the NAF / AP network element according to the B-TID.

[0144] Step 1003: If it is determined to perform a reboot, send response information carrying a preset second identifier to the UE, so that when the UE recognizes the second identifier, a bootstrapping authentication process is initiated with the BSF network element.

[0145] Since the bootstrapping authentication method of this embodiment is applied to the NAF / AP network element, and the bootstrapping authentication methods in the first and second embodiments are applied to the UE, and this embodiment corresponds to the first and second embodiments, this embodiment can be implemented in cooperation with the first and second embodiments. The relevant technical details mentioned in the first and second embodiments are still valid in this embodiment, and the technical effects achievable in the first and second embodiments can also be achieved in this embodiment. To avoid repetition, they are not elaborated here. Correspondingly, the relevant technical details mentioned in this embodiment can also be applied in the first and second embodiments.

[0146] The fourth embodiment of the present invention relates to a bootstrapping authentication method. The implementation details of the bootstrapping authentication method in this embodiment will be described below. The following content is only the implementation details provided for convenience of understanding and is not necessary for implementing this solution.

[0147] In this embodiment, the bootstrapping authentication in the disaster recovery scenario is mainly considered. The disaster recovery scenario may also cause a sudden increase in signaling, reducing the network reliability of GBA. Disaster recovery is also known as off-site disaster recovery or geographical disaster recovery, referring to two sites located in different geographical locations. When one site cannot provide services due to uncontrollable factors such as natural disasters, wars, and power failures, the other site can take over its business. In the prior art, for the disaster recovery scenario, the designed GBA network architecture is as Figure 11As shown in the figure, load sharing disaster recovery networking is adopted. Multiple BSF network elements share services, but do not share disaster recovery data or synchronize disaster recovery data. When a device fails, the remaining BSF devices can quickly take over. However, for a certain user, after the BSF device fails, the boot authentication process needs to be re-executed to restore the service. The disaster recovery process in the prior art can be as follows: Figure 12 As shown, including:

[0148] Steps 12-1 to 12-4, the UE initiates a service request to the NAF / AP network element, and after four steps of guidance, the UE obtains B-TID1 and Ks with the BSF1 network element. The UE sends a service challenge response based on B-TID1.

[0149] Steps 12-5 to 12-7, NAF / AP detects BSF1 failure and executes disaster recovery process. NAF / AP returns 401Unauthorized to instruct UE to reboot. UE then executes four-step reboot process to obtain B-TID2 and Ks from BSF2.

[0150] In steps 12-8 to 12-12, the UE returns a challenge response based on B-TID2, the NAF / AP network element queries the BSF2 network element for user authentication data, authenticates the UE, and then saves B-TID2 and Ks_NAF locally. After authentication, the service request is forwarded to the AS.

[0151] The above disaster recovery process will, to a certain extent, increase the boot process of BSF2 and may cause network storms, thereby reducing the network reliability of GBA.

[0152] In this embodiment, considering the risk of causing network storms in the existing disaster recovery process, the following solution is proposed: after the UE and the BSF network element are successfully bootstrapped and authenticated, the BSF network element will back up the disaster recovery data to the preset backup network element, and the backup network element will back up and share the disaster recovery data. When a BSF network element fails, the remaining BSF network elements can quickly take over and download the disaster recovery data from the backup network element, and can process the business without rebooting, that is, there is no need to execute the boot authentication process between the UE and the BSF network element again. Among them, the backup network element can be set as the HSS or the newly deployed central data node CDB according to actual needs, and this embodiment does not specifically limit this.

[0153] The disaster recovery data may be data backed up by the BSF network element and the UE after successful bootstrapping authentication, for example, the BSF network element uploads the disaster recovery data to the backup network element.

[0154] In one example, after the UE and the BSF network element complete the initial boot authentication, the BSF network element can back up the disaster recovery data to the backup network element. When the boot authentication between the UE and the BSF network element is refreshed, the BSF network element refreshes the disaster recovery data backed up on the backup network element. When the survival duration of the disaster recovery data exceeds its preset lifecycle, the BSF network element deletes the disaster recovery data backed up on the backup network element.

[0155] In one example, the disaster recovery data may include: B-TID and the shared key corresponding to the B-TID. The B-TID is generated after the initial boot authentication between the BSF network element and the UE is successful and is updated during the refreshed boot authentication. The shared key is the key negotiated between the BSF network element and the UE during the boot authentication process, which is valid within its lifecycle and is updated during the refreshed boot authentication. In a specific implementation, the disaster recovery data may further include information such as the temporary user identifier TMPI, the name of the BSF network element, and the security settings subscribed by the user.

[0156] To further facilitate the understanding of this embodiment, the process of backing up the disaster recovery data is briefly described below, which can be referred to Figure 13 , including:

[0157] Step 13-1, the UE initiates an initial boot authentication process and sends an initial boot request to the BSF network element.

[0158] Among them, the initial boot request indicates that the UE is not currently authenticated in the GBA network and needs to execute the initial boot authentication process before initiating a service.

[0159] Step 13-2, the BSF network element sends a user authentication request to the HSS. Among them, when the BSF network element sends a user authentication request to the HSS, it means that the BSF network element queries the user authentication data from the HSS.

[0160] Step 13-3, the HSS returns a user authentication response carrying an authentication vector. Among them, the authentication response can be understood as the user authentication data returned by the HSS.

[0161] Step 13-4, the BSF network element constructs a challenge request 401 Unauthorized based on the authentication vector and sends it to the UE.

[0162] Step 13-5, the UE replies with a boot challenge response to the BSF network element.

[0163] Step 13-6, the BSF network element sends an initial boot success response (200 OK) to the UE. Among them, after receiving the challenge response sent by the UE, the BSF network element authenticates the UE using the authentication vector saved locally. After successful authentication, the BSF network element generates a user boot authentication identifier B-TID and calculates the lifecycle of the shared key Ks, and the BSF network element carries the B-TID and the lifecycle of Ks in the 200 OK and returns them to the UE.

[0164] Step 13-7, the BSF network element backs up the disaster recovery data to the backup network element. Among them, the disaster recovery data includes information such as the Temporary Mobile Subscriber Identity (TMPI), the Bootstrapping Authentication Identity (B-TID), the shared key Ks, the life cycle of Ks, and the name of the BSF network element.

[0165] Step 13-8, the backup network element returns a backup response. After storing the disaster recovery data, the backup network element can return a backup response to the BSF network element.

[0166] To further facilitate the understanding of this embodiment, the process of refreshing the bootstrapping authentication is briefly described below. You can refer to Figure 14 , including:

[0167] Step 14-1, the UE initiates a process of refreshing the bootstrapping authentication and sends a refresh bootstrapping request to the BSF network element. For example, the UE has previously been successfully authenticated in the GBA network and initiates a process of refreshing the bootstrapping authentication before the life cycle expires.

[0168] Step 14-2, the BSF network element sends a user authentication request to the HSS

[0169] Step 14-3, the HSS returns a user authentication response, carrying an authentication vector.

[0170] Step 14-4, the BSF network element constructs a challenge request 401 Unauthorized according to the authentication vector and sends it to the UE.

[0171] Step 14-5, the UE replies with a bootstrapping challenge response to the BSF network element.

[0172] Step 14-6, the BSF network element sends a refresh bootstrapping success response (200 OK) to the UE. After receiving the challenge response sent by the UE, the BSF network element authenticates the UE through the authentication vector saved locally. After successful authentication, a new B-TID is generated, and the life cycle of the new shared key Ks is calculated. The BSF network element carries the new B-TID and the life cycle of the new Ks in 200 OK and returns them to the UE.

[0173] Step 14-7, the BSF network element refreshes the backed-up disaster recovery data.

[0174] Step 14-8, the backup network element returns a refresh response. After refreshing the backed-up disaster recovery data, the backup network element can return a refresh response to the BSF network element.

[0175] In an example, if the UE does not initiate a process of refreshing the bootstrapping authentication before the life cycle of the shared key Ks times out, the BSF network element deletes the UE-related data saved locally. When the BSF network element deletes the UE-related data locally, it notifies the backup network element to delete the disaster recovery data corresponding to the UE.

[0176] In this embodiment, during the two-way authentication process between the NAF / AP network element and the UE, when the NAF / AP network element determines that it needs to obtain a derived key from the BSF network element and detects a failure of the BSF network element, the NAF / AP network element obtains a derived key generated from disaster recovery data based on the backup from a preset takeover BSF network element; the NAF / AP network element performs two-way authentication with the UE according to the derived key obtained from the takeover BSF network element. For example, the takeover BSF network element can download disaster recovery data from the backup network element and generate a derived key based on the downloaded disaster recovery data. For example, the service flow chart from detecting the failure of the BSF network element to downloading disaster recovery data through the takeover BSF network element can be referred to Figure 15 , including:

[0177] Step 15-1, the UE initiates a four-step boot authentication process to obtain the B-TID and Ks from the BSF1 network element.

[0178] Step 15-2, the BSF1 network element backs up the disaster recovery data (B-TID, Ks) to the backup network element.

[0179] Step 15-3, the UE initiates a service request to the NAF / AP network element.

[0180] Step 15-4, the NAF / AP network element returns a service challenge (401 unauthorized) to the UE.

[0181] Step 15-5, the UE returns a service challenge response to the NAF1 / AP network element, and the service challenge response carries the B-TID.

[0182] Step 15-6, the NAF / AP network element determines that the BSF1 network element that boots the UE fails according to the B-TID, and performs disaster recovery to other takeover network elements, such as the BSF2 network element. In a specific implementation, the NAF / AP network element can derive the BSF network element host name from the service challenge response sent by the UE, and then determine whether the BSF network element corresponding to the BSF network element host name fails.

[0183] Step 15-7, the NAF / AP network element sends a user authentication request to the BSF2 network element, and the authentication request carries the B-TID.

[0184] Step 15-8, the BSF2 network element sends a request for querying disaster recovery data to the backup network element, and the request for querying disaster recovery data carries the B-TID.

[0185] Step 15-9, the backup network element returns the disaster recovery data. Among them, after receiving the disaster recovery data request, the backup network element queries the disaster recovery data corresponding to the B-TID according to the B-TID carried in it, such as the shared key. That is, it can be understood that the BSF2 network element downloads the disaster recovery data from the backup network element.

[0186] Step 15-10, the BSF2 network element returns an authentication response to the NAF / AP network element. Among them, the BSF2 network element can generate a derived key based on the disaster recovery data and carry the derived key in the authentication response to return to the NAF / AP network element.

[0187] Steps 15-11 to 15-12, the NAF / AP network element authenticates the UE based on the derived key. If the authentication is passed, the service request is forwarded to the AS.

[0188] It should be noted that the above examples in this embodiment are all illustrative examples for easy understanding and do not limit the technical solution of the present invention.

[0189] Compared with the prior art, in this embodiment, when a BSF network element fails, the remaining BSF network elements can quickly take over. The NAF / AP network element can obtain the derived key generated based on the backup disaster recovery data from the preset BSF network elements that can be taken over, and there is no need to re-perform the boot authentication between the BSF network elements that can be taken over and the UE, which is beneficial to reducing the number of reboots, reducing signaling interaction, reducing the risk of network storms, and improving the reliability of the GBA network.

[0190] Since the boot authentication method in this embodiment is applied to the NAF / AP network element, and the boot authentication methods in the first and second embodiments are applied to the UE, this embodiment corresponds to the first and second embodiments, so this embodiment can be implemented in cooperation with the first and second embodiments. The relevant technical details mentioned in the first and second embodiments are still valid in this embodiment. To avoid repetition, they are not elaborated here. Correspondingly, the relevant technical details mentioned in this embodiment can also be applied in the first and second embodiments.

[0191] In addition, those skilled in the art can understand that the step division of the above various methods is only for clear description. When implemented, they can be combined into one step or some steps can be split into multiple steps. As long as the same logical relationship is included, they are all within the protection scope of this patent; adding insignificant modifications to the algorithm or process or introducing insignificant designs, but not changing the core design of the algorithm and process are all within the protection scope of this patent.

[0192] The fifth embodiment of the present invention relates to a boot authentication system, as Figure 16As shown in the figure, it includes: a Network Application Function / Authentication Proxy (NAF / AP) network element 1601 and a User Equipment (UE) 1602; the NAF / AP network element 1601 is configured to send response information carrying a preset first identifier to the UE 1602 if it is determined that a service challenge needs to be executed; the UE 1602 is configured to receive the response information sent by the NAF / AP network element 1601, and if the first identifier is recognized from the response information and it is determined that the Boot Transaction Identifier (B-TID) is locally stored in the UE, perform two-way authentication with the NAF / AP network element 1601 based on the B-TID.

[0193] It should be noted that, in order to highlight the innovative part of the present invention, network elements that are not closely related to solving the technical problems proposed by the present invention are not introduced in this embodiment, but this does not mean that there are no other network elements in this embodiment.

[0194] It is not difficult to find that this embodiment is a system embodiment corresponding to the first to fourth embodiments, and this embodiment can be implemented in cooperation with the first to fourth embodiments. The relevant technical details and technical effects mentioned in the first to fourth embodiments are still valid in this embodiment, and for the sake of reducing repetition, they will not be elaborated here. Correspondingly, the relevant technical details mentioned in this embodiment can also be applied to the first to fourth embodiments.

[0195] The sixth embodiment of the present invention relates to an electronic device, as Figure 17 shown in the figure, it includes: at least one processor 1701; and a memory 1702 communicatively connected to the at least one processor 1701; wherein, the memory 1702 stores instructions executable by the at least one processor 1701, and the instructions are executed by the at least one processor 1701.

[0196] When the electronic device is a user equipment, the at least one processor is capable of executing the boot authentication method in the first or second embodiment.

[0197] When the electronic device is a Network Application Function / Authentication Proxy network element, the at least one processor is capable of executing the boot authentication method in the third or fourth embodiment.

[0198] Among them, the memory 1702 and the processor 1701 are connected in a bus manner. The bus may include any number of interconnected buses and bridges, and the bus connects various circuits of one or more processors 1701 and the memory 1702 together. The bus can also connect various other circuits such as peripheral devices, voltage regulators, and power management circuits, which are well known in the art, and thus will not be further described herein. The bus interface provides an interface between the bus and the transceiver. The transceiver can be a single component or multiple components, such as multiple receivers and transmitters, and provides a unit for communicating with various other devices over a transmission medium. The data processed by the processor 1701 is transmitted over a wireless medium via an antenna. Further, the antenna also receives data and transmits the data to the processor 1701.

[0199] The processor 1701 is responsible for managing the bus and general processing, and can also provide various functions, including timing, peripheral interface, voltage regulation, power management, and other control functions. The memory 1702 can be used to store data used by the processor 1701 when performing operations.

[0200] The seventh embodiment of the present invention relates to a computer-readable storage medium storing a computer program. When the computer program is executed by a processor, the method embodiments described above are implemented.

[0201] That is, those skilled in the art can understand that all or part of the steps of implementing the methods in the above embodiments can be completed by instructing relevant hardware through a program. The program is stored in a storage medium and includes several instructions for causing a device (which can be a single-chip microcomputer, a chip, etc.) or a processor to execute all or part of the steps of the methods described in various embodiments of the present application. The aforementioned storage medium includes: various media such as USB flash drives, mobile hard disks, read-only memories (ROMs), random access memories (RAMs), magnetic disks, or optical discs that can store program codes.

[0202] Those of ordinary skill in the art can understand that the above embodiments are specific embodiments for implementing the present invention, and in practical applications, various changes can be made in form and details without departing from the spirit and scope of the present invention.

Claims

1. A guiding authentication method, characterized in that, Applied to a user equipment UE, including: Receiving response information sent by a network application function / authentication proxy NAF / AP network element; If a preset first identifier is recognized from the response information and it is determined that the UE locally stores a boot transaction identifier B-TID, performing mutual authentication with the NAF / AP network element according to the B-TID; wherein, the first identifier is an identifier carried in the response information when the NAF / AP network element determines to execute a service challenge; Wherein, if a preset second identifier is recognized from the response information, initiating a boot authentication process with a boot service function BSF network element; wherein, the second identifier is an identifier carried in the response information when the NAF / AP network element determines to perform a reboot; 2. The guiding authentication method according to claim 1, wherein The first identifier and the second identifier are different parameter values of a Reason-Phrase parameter.

3. The guiding authentication method according to claim 1, characterized in that, The first identifier and the second identifier are located in the header of the response information.

4. The guided authentication method according to claim 1, characterized in that After receiving the response information sent by the network application function / authentication proxy NAF / AP network element, it further includes: If the first identifier is recognized from the response information and it is determined that the UE does not locally store the B-TID, initiating a boot authentication process with the BSF network element.

5. The guided authentication method according to claim 1, characterized in that Before receiving the response information sent by the network application function / authentication proxy NAF / AP network element, it further includes: Initiating a boot authentication process with the BSF network element, and obtaining the B-TID and a shared key corresponding to the B-TID after successful boot authentication; The performing mutual authentication with the NAF / AP network element according to the B-TID includes: Determining encryption information corresponding to the NAF / AP network element that sends the response information; wherein, different NAF / AP network elements correspond to different encryption information; Generating a derived key according to the shared key corresponding to the B-TID and the encryption information corresponding to the NAF / AP network element; Performing mutual authentication with the NAF / AP network element according to the derived key.

6. A guiding authentication method, characterized in that, Applied to a network application function / authentication proxy NAF / AP network element, including: If it is determined to execute a service challenge, sending response information carrying a preset first identifier to the user equipment UE, so that when the UE recognizes the first identifier and determines that the UE locally stores a boot transaction identifier B-TID, performing mutual authentication with the NAF / AP network element according to the B-TID; The method further includes: if the UE recognizes a preset second identifier from the response information, the UE initiates a boot authentication process with a boot service function BSF network element; wherein, the second identifier is an identifier carried in the response information when the NAF / AP network element determines to perform a reboot.

7. The guiding authentication method according to claim 6, wherein The method further includes: If it is determined to perform a reboot, sending response information carrying a preset second identifier to the UE, so that when the UE recognizes the second identifier, initiating a boot authentication process with a boot service function BSF network element.

8. The boot authentication method according to claim 6, wherein During the process of performing mutual authentication, it includes: When it is determined that a derived key needs to be obtained from the BSF network element and the BSF network element failure is detected, obtain the derived key generated from the disaster recovery data based on the backup from a preset takeover BSF network element; Perform mutual authentication with the UE according to the derived key obtained from the takeover BSF network element.

9. The guided authentication method according to claim 8, wherein The disaster recovery data is the data backed up by the BSF network element and the UE after successful bootstrapping authentication.

10. The boot authentication method according to claim 8 or 9, characterized in that, The disaster recovery data at least includes: the B-TID and the shared key corresponding to the B-TID.

11. A guiding authentication system, characterized in that, Includes: Network Application Function / Authentication Proxy NAF / AP network element and User Equipment UE; The NAF / AP network element is configured to send response information carrying a preset first identifier to the user equipment UE if it is determined to perform a service challenge; The UE is configured to receive the response information sent by the NAF / AP network element. If the first identifier is recognized from the response information and it is determined that the bootstrapping transaction identifier B-TID is locally stored in the UE, perform mutual authentication with the NAF / AP network element according to the B-TID; Wherein; The first identifier is the identifier carried in the response information when the NAF / AP network element determines to perform a service challenge; Wherein, if a preset second identifier is recognized from the response information, initiate a bootstrapping authentication process with the Bootstrapping Service Function BSF network element; wherein, the second identifier is the identifier carried in the response information when the NAF / AP network element determines to perform re-bootstrapping.

12. An electronic device, characterized in that, Includes: At least one processor; And, A memory communicatively connected to the at least one processor; wherein, The memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor, When the electronic device is a user equipment, the at least one processor is capable of executing the bootstrapping authentication method according to any one of claims 1 to 5; When the electronic device is a Network Application Function / Authentication Proxy network element, the at least one processor is capable of executing the bootstrapping authentication method according to any one of claims 6 to 10.

13. A computer-readable storage medium storing a computer program, characterized in that, The computer program, when executed by a processor, implements the bootstrapping authentication method according to any one of claims 1 to 5, or implements the bootstrapping authentication method according to any one of claims 6 to 10.

Citation Information

Patent Citations

  • Combined right-discriminating construction and realizing method thereof

    CN101022651A