An authentication method and apparatus thereof
By receiving and verifying access requests from remote devices, determining their permissions and assigning network addresses, the problem of low network security under relay technology is solved, and more efficient network security management and resource utilization is achieved.
Patent Information
- Application Number
- CN202011070319.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2020-09-30
- Publication Date
- 2025-07-04
- Estimated Expiration
- 2040-09-30
AI Technical Summary
The development of relay technology has led to low network security. Remote devices may bypass verification when accessing the network through relay devices, and cannot effectively determine whether they have access permissions.
Receive a request from the second device through the first device, determine whether the target remote device has permission to access the network, and sends information to indicate its permission status, including an authentication process and a network address allocation mechanism, to ensure that only the device with permission can access the network.
Improve network security, prevent unauthorized remote devices from accessing, save resources and optimize network address allocation, and reduce unnecessary interactions.
Smart Images

Figure CN114339748B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of communication technologies, and in particular, to an authentication method and apparatus thereof. Background Art
[0002] Relay technology is one of the key technologies in modern wireless communication systems. Adopting relay technology is beneficial to improving system capacity. Figure 1a is a schematic diagram of a relay communication scenario. As Figure 1a can be seen, a device outside the network coverage area (referred to as a remote device) can access the network through a device within the network coverage area (referred to as a relay device). Further, the remote device can obtain various communication services. In Figure 1a , the dashed circle represents the coverage area of the base station.
[0003] However, with the continuous development of relay technology, more and more remote devices access the network through relay devices, which may result in low network security. For example: A remote device hopes to access a network service through a relay device. The network providing this service will verify whether all access devices have the permission to access. However, since the remote device accesses through the relay device, it can bypass the network verification. Summary of the Invention
[0004] Embodiments of this application provide an authentication method and apparatus thereof, which can determine whether a target remote device has the permission to access the network, and is beneficial to improving network security.
[0005] In a first aspect, embodiments of this application provide an authentication method. The method includes: A first device receives a first request from a second device. The first request includes an identifier of a target remote device. When the second device is a terminal device, the first request is for the target remote device to request access to the network; when the second device is a network element, the first request is for requesting to determine whether the target remote device has the permission to access the network; the first device sends first information to the second device, and the first information is used to indicate whether the target remote device has the permission to access the network.
[0006] In this technical solution, it can be determined whether a target remote device has the permission to access the network, so as to prevent remote devices that cannot access from accessing the network, thereby being beneficial to improving network security.
[0007] In an implementation, the method may further include: The first device determines whether the target remote device has the permission to access the network.
[0008] In one implementation, the specific implementation for the first device to determine whether the target remote device has the permission to access the network may be: If the identifier of the target remote device exists in the target identifier list, the first device determines that the target remote device has the permission to access the network; the target identifier list includes one or more target identifiers, and the target identifier is used to indicate the remote device that has the permission to access the network.
[0009] In one implementation, the first request further includes a network identifier, and the foregoing first information is specifically used to indicate whether the target remote device has the permission to access the network indicated by the network identifier; when the second device is a terminal device, the first request is specifically used for the target remote device to request access to the network indicated by the network identifier; when the second device is a network element, the first request is specifically used to request to determine whether the target remote device has the permission to access the network indicated by the network identifier.
[0010] In one implementation, the method may further include: The first device sends an authentication request to a third device, the authentication request includes the identifier of the target remote device, and the authentication request is used to request to determine whether the target remote device has the permission to access the network; the first device receives the authentication result information from the third device, and the authentication result information is used to indicate whether the target remote device has the permission to access the network.
[0011] In one implementation, when the identifier of the target remote device exists in the target identifier list, the authentication result information is used to indicate that the target remote device has the permission to access the network, the target identifier list includes one or more target identifiers, and the target identifier is used to indicate the remote device that has the permission to access the network.
[0012] In one implementation, the first request and the authentication request further include a network identifier, and the authentication request is specifically used to request to determine whether the target remote device has the permission to access the network indicated by the network identifier; the first information and the authentication result information are specifically used to indicate whether the target remote device has the permission to access the network indicated by the network identifier; when the second device is a terminal device, the first request is specifically used for the target remote device to request access to the network indicated by the network identifier; when the second device is a network element, the first request is specifically used to request to determine whether the target remote device has the permission to access the network indicated by the network identifier.
[0013] In one implementation, the first request is further used to request to allocate a network address for the target remote device; when the target remote device has the permission to access the network, the foregoing first information may include the target network address allocated for the target remote device.
[0014] In one implementation, the method may further include: the first device sending a network address allocation request to the fourth device, where the network address allocation request is used to request to obtain a first number of network addresses; the first device receiving the first number of network addresses from the fourth device; the first number of network addresses being sent when the first number is less than or equal to the second number; where the second number is the number of remote devices having the permission to access the network; and the first number of network addresses includes the aforementioned target network address.
[0015] In this technical solution, on the one hand, it is possible to avoid allocating more network addresses than the second number for relay access, that is, it is possible to avoid the situation where the number of allocated network addresses is greater than the required number of network addresses, which is beneficial to avoiding waste of network addresses. On the other hand, when the fourth device is the device responsible for allocating network addresses and the first number is multiple, the fourth device can avoid the following situation by allocating multiple network addresses at one time: when different remote devices initiate network access requests, the first device needs to re-request the fourth device to allocate network addresses for each remote device. Therefore, by allocating multiple network addresses at one time, it is beneficial to reduce unnecessary interactions between the first device and the fourth device, thereby facilitating resource saving.
[0016] Second, an authentication method provided by an embodiment of the present application includes: the second device sending a first request to the first device, where the first request includes an identifier of a target remote device, and when the second device is a terminal device, the first request is used for the target remote device to request access to the network; when the second device is a network element, the first request is used to request to determine whether the target remote device has the permission to access the network; and the second device receiving first information from the first device, where the first information is used to indicate whether the target remote device has the permission to access the network.
[0017] In this technical solution, it is possible to determine whether the target remote device has the permission to access the network, so as to prevent remote devices that cannot access from accessing the network, which is beneficial to improving network security.
[0018] In one implementation, the first request further includes an identifier of the network, and the aforementioned first information is specifically used to indicate whether the target remote device has the permission to access the network indicated by the network identifier; when the second device is a terminal device, the first request is specifically used for the target remote device to request access to the network indicated by the network identifier; and when the second device is a network element, the first request is specifically used to request to determine whether the target remote device has the permission to access the network indicated by the network identifier.
[0019] In one implementation, the first request is further used to request the allocation of a network address for the target remote device; when the target remote device has the permission to access the network, the first information includes the target network address allocated for the target remote device.
[0020] In a third aspect, embodiments of the present application provide a communication device, which has some or all of the functions of the first device in the method example described in the first aspect above. For example, the functions of the communication device can have some or all of the functions in the embodiments of the present application, or can have the functions of implementing any one of the embodiments of the present application alone. The functions can be implemented by hardware or by hardware executing corresponding software. The hardware or software includes one or more units or modules corresponding to the above functions.
[0021] In one implementation, the structure of the communication device may include a processing unit and a communication unit. The processing unit is configured to support the communication device to execute the corresponding functions in the above method. The communication unit is used to support the communication between the communication device and other devices. The communication device may further include a storage unit, which is used to be coupled with the processing unit and the sending unit, and stores the necessary computer programs and data of the communication device.
[0022] In one implementation, the communication device includes: a processing unit, configured to call the communication unit to receive a first request from a second device. The first request includes an identifier of a target remote device. When the second device is a terminal device, the first request is used for the target remote device to request access to the network; when the second device is a network element, the first request is used to request to determine whether the target remote device has the permission to access the network; the processing unit is further configured to call the communication unit to send first information to the second device, and the first information is used to indicate whether the target remote device has the permission to access the network.
[0023] As an example, the processing unit can be a processor, the communication unit can be a transceiver or a communication interface, and the storage unit can be a memory.
[0024] In one implementation, the communication device includes: a processor, configured to call a transceiver to receive a first request from a second device. The first request includes an identifier of a target remote device. When the second device is a terminal device, the first request is used for the target remote device to request access to the network; when the second device is a network element, the first request is used to request to determine whether the target remote device has the permission to access the network; the processor is further configured to call the transceiver to send first information to the second device, and the first information is used to indicate whether the target remote device has the permission to access the network.
[0025] Fourthly, an embodiment of the present application provides another communication device, which has some or all of the functions of the second device in the method example described in the second aspect above. For example, the functions of the communication device may have some or all of the functions in some or all of the embodiments of the present application, or may have the functions of any one embodiment of the present application implemented separately. The functions can be implemented by hardware or by hardware executing corresponding software. The hardware or software includes one or more units or modules corresponding to the above functions.
[0026] In one implementation, the structure of the communication device may include a processing unit and a communication unit. The processing unit is configured to support the communication device to execute the corresponding functions in the above method. The communication unit is used to support the communication between the communication device and other devices. The communication device may further include a storage unit, which is used to be coupled with the processing unit and the sending unit, and stores the necessary computer programs and data of the communication device.
[0027] In one implementation, the communication device includes: a processing unit, configured to call the communication unit to send a first request to a first device. The first request includes an identifier of a target remote device. When the communication device is a device in a terminal device, the first request is used to request the target remote device to access the network; when the communication device is a device in a network element, the first request is used to request to determine whether the target remote device has the permission to access the network; the processing unit is further configured to call the communication unit to receive a first piece of information from the first device, and the first piece of information is used to indicate whether the target remote device has the permission to access the network.
[0028] As an example, the processing unit may be a processor, the communication unit may be a transceiver or a communication interface, and the storage unit may be a memory.
[0029] In one implementation, the communication device includes: a processor, configured to call a transceiver to send a first request to a first device. The first request includes an identifier of a target remote device. When the communication device is a device in a terminal device, the first request is used to request the target remote device to access the network; when the communication device is a device in a network element, the first request is used to request to determine whether the target remote device has the permission to access the network; the processor is further configured to call the transceiver to receive a first piece of information from the first device, and the first piece of information is used to indicate whether the target remote device has the permission to access the network.
[0030] Fifthly, an embodiment of the present invention provides a computer-readable storage medium, which stores a computer program. The computer program includes program instructions. When the program instructions are executed by a communication device, the communication device is caused to execute the method in the first aspect above.
[0031] Sixth aspect, an embodiment of the present invention provides a computer-readable storage medium storing a computer program, where the computer program includes program instructions, and when the program instructions are executed by a communication device, the communication device is caused to execute the method in the second aspect above.
[0032] Seventh aspect, the present application further provides a computer program product including a computer program, which when running on a computer causes the computer to execute the method described in the first aspect above.
[0033] Eighth aspect, the present application further provides a computer program product including a computer program, which when running on a computer causes the computer to execute the method described in the second aspect above.
[0034] Ninth aspect, the present application provides a chip system including at least one processor and an interface, configured to support a first device to implement the functions involved in the first aspect, for example, determining or processing at least one of the data and information involved in the above method. In a possible design, the chip system further includes a memory for storing the necessary computer programs and data of the first device. The chip system may be composed of chips or may include chips and other discrete devices.
[0035] Tenth aspect, the present application provides a chip system including at least one processor and an interface, configured to support a second device to implement the functions involved in the second aspect, for example, determining or processing at least one of the data and information involved in the above method. In a possible design, the chip system further includes a memory for storing the necessary computer programs and data of the second device. The chip system may be composed of chips or may include chips and other discrete devices. BRIEF DESCRIPTION OF THE DRAWINGS
[0036] Figure 1a is a schematic diagram of a relay communication scenario provided by an embodiment of the present application;
[0037] Figure 1b is a schematic diagram of the architecture of a communication system provided by an embodiment of the present application;
[0038] Figure 2a is a schematic flowchart of an authentication method provided by an embodiment of the present application;
[0039] Figure 2b is a schematic diagram of a process in which a first device requests a fourth device to allocate an IP address provided by an embodiment of the present application;
[0040] Figure 2cIt is a schematic diagram of a process in which a first device requests a fifth device to allocate an IP address provided by an embodiment of the present application;
[0041] Figure 3a It is a schematic flowchart of another authentication method provided by an embodiment of the present application;
[0042] Figure 3b It is a schematic diagram of a scenario where an IP address is pre-allocated to a remote device (including a target remote device) provided by an embodiment of the present application;
[0043] Figure 4a It is a schematic flowchart of yet another authentication method provided by an embodiment of the present application;
[0044] Figure 4b It is a schematic diagram of a scenario where the device responsible for authentication and the device responsible for allocating an IP address to the target remote device are both the third device provided by an embodiment of the present application;
[0045] Figure 4c It is a schematic diagram of a scenario where the device responsible for authentication and the device responsible for allocating an IP address to the target remote device are different devices provided by an embodiment of the present application;
[0046] Figure 5 It is a schematic diagram of the structure of a communication device provided by an embodiment of the present application;
[0047] Figure 6 It is a schematic diagram of the structure of another communication device provided by an embodiment of the present application;
[0048] Figure 7 It is a schematic diagram of the structure of a chip provided by an embodiment of the present application. Detailed implementation manners
[0049] To better understand an authentication method disclosed in an embodiment of the present application, the communication system applicable to the embodiment of the present application will be described first below.
[0050] Please refer to Figure 1b , Figure 1b which is a schematic diagram of the architecture of a communication system provided by an embodiment of the present application. The communication system may include, but is not limited to, a network device, a first device, and a second device. Figure 1b The number and form of the devices shown are for illustration and do not constitute a limitation on the embodiments of the present application. In practical applications, there may be two or more network devices, two or more first devices, and two or more second devices. Figure 1b The communication system shown takes the example of including a network device, a first device, and a second device.
[0051] In the embodiments of the present application, the second device may be a terminal device or a network element. Among them, the terminal device may refer to a target remote device that hopes to access the network; or the terminal device may refer to a relay device, which is a relay device that receives the network access request of the target remote device. Among them, the network element may refer to a session management function (SMF) network element or other core network elements. The embodiments of the present application do not limit the specific technologies and specific device forms adopted by the network element. The SMF can be used to be responsible for session management in the mobile network, such as session establishment, modification, and release. Specifically, the SMF can be used to allocate Internet Protocol (IP) addresses for users, select user plane function (UPF) network elements that provide packet forwarding functions, and so on.
[0052] When the second device is the target remote device, the first device may be a relay device. At this time, the first request sent by the second device to the first device is used for the target remote device to request access to the network, that is, the first request sent by the target remote device to the relay device is used for the target remote device to request access to the network.
[0053] When the second device is a relay device, the first device may be a network element (such as an SMF) serving the relay device. At this time, the first request sent by the second device to the first device is used for the target remote device to request access to the network, that is, the first request sent by the relay device to the network element (such as an SMF) serving the relay device is used for the target remote device to request access to the network.
[0054] When the second device is a network element (such as an SMF) serving the relay device, the first device may be a permission management device. Among them, the permission management device can be used to record whether a certain remote device has the permission to access the network, or to record whether a certain remote device has the permission to access the network through a relay device. The permission management device may be an authentication, authorization, and accounting (AAA) server, simply referred to as a 3A server. Or, the permission management device may be an application function (AF) network element.
[0055] In the embodiments of the present application, the remote device is a terminal device outside the network coverage area, and the relay device is a terminal device within the network coverage area. Among them, the terminal device is an entity on the user side for receiving or transmitting signals, such as a mobile phone. The terminal device can also be referred to as a terminal, user equipment (UE), mobile station (MS), mobile terminal (MT), etc. The terminal device can be a mobile phone, wearable device, tablet computer (Pad), computer with wireless transceiver function, virtual reality (VR) terminal device, augmented reality (AR) terminal device, wireless terminal in industrial control, wireless terminal in self-driving, wireless terminal in remote medical surgery, wireless terminal in smart grid, wireless terminal in transportation safety, wireless terminal in smart city, wireless terminal in smart home, wireless terminal in the Internet of Things, and so on. The embodiments of the present application do not limit the specific technologies and specific device forms adopted by the terminal device. It should be noted that in the embodiments of the present application, the relay device can be only used to assist the remote device in accessing the network. Or, the relay device can also have the functions of an ordinary terminal device.
[0056] It should be noted that Figure 1b taking the first device as the relay device and the second device as the target remote device as an example for introduction does not constitute a limitation on the embodiments of the present application.
[0057] In Figure 1b , the first device can be used to receive a first request from the second device and send first information to the second device. Among them, the first request includes the identifier of the target remote device. When the second device is a terminal device (such as Figure 1b the target remote device in ), the first request is used for the target remote device to request access to the network; the first information is used to indicate whether the target remote device has the permission to access the network. The target remote device is a remote device that hopes to access the network. The identifier of the target remote device is used to uniquely identify the target remote device, and the present application does not limit the form of the identifier.
[0058] In Figure 1bAmong them, the circular area is the network coverage range of the network device. Applied to the embodiments of the present application, this circular area can be used to indicate the coverage range of the network that the target remote device hopes to access.
[0059] The first device receiving the first request indicates that the target remote device hopes to access the network. After receiving the first request, the first device can determine whether the target remote device has the permission to access the network and send the first information to the second device. By implementing the embodiments of the present application, it can be determined whether the target remote device has the permission to access the network, which is beneficial to improving network security.
[0060] The network involved in the embodiments of the present application (i.e., the network that the remote device (including the target remote device) hopes to access) can refer to a data network, a local area network (LAN), a core network (such as a 4G core network, a 5G core network, etc.) or other types of networks. The embodiments of the present application do not make any limitations in this regard.
[0061] In one implementation, if the target remote device has the permission to access the network and the target remote device has a network address (such as a target network address), the target remote device can send information to the network through the target network address to obtain network services. The target remote device sending information to the network through the target network address means that the target remote device sends information to a relay device through the target network address, and the relay device sends the information to the network. In another implementation, if the target remote device has the permission to access the network, the first device can also send the target network address assigned to the target remote device to the second device. In this way, when the target remote device has the permission to access the network, assigning a network address to the target remote device can prevent remote devices that cannot access from accessing the network, which is beneficial to improving network security.
[0062] It should be noted that the network address mentioned in the embodiments of the present application can refer to an Internet Protocol (IP) address or a Media Access Control (MAC) address. In the embodiments of the present application, the network address is taken as an IP address for introduction, which does not constitute a limitation on the embodiments of the present application. The content related to IP address allocation is also applicable to MAC address allocation.
[0063] It should be noted that, in the embodiments of the present application, the target remote device can access the network through a relay device. Correspondingly, the authentication request mentioned in the embodiments of the present application can be used to request to determine whether the target remote device has the permission to access the network through the relay device. Similarly, the authentication result information mentioned in the embodiments of the present application can be used to indicate whether the target remote device has the permission to access the network through the relay device. When the second device is a network element, the first request can be used to request to determine whether the target remote device has the permission to access the network, that is, the first request is used to request to authenticate the target remote device. In this case, optionally, the first request can specifically be used to request to determine whether the target remote device has the permission to access the network through the relay device. Similarly, the response information corresponding to the first request (i.e., the first information) can be used to indicate whether the target remote device has the permission to access the network through the relay device. In other words, the permission to access the network mentioned in the embodiments of the present application can refer to: the permission to access the network through the relay device. In addition, in the embodiments of the present application, the permission to access the network can be described as the access network permission.
[0064] It should also be noted that, in the embodiments of the present application, the remote device and the relay device can communicate through the proximity service (ProSe) communication technology. The proximity communication technology can include but is not limited to: device to device (D2D) communication, wireless fidelity (WiFi) communication, and Bluetooth communication.
[0065] It can be understood that when the second device is not the target remote device, after receiving the first information, the second device can also send the first information to the target remote device. For example, when the second device is a relay device and the first device is an SMF network element, after receiving the first information, the relay device can also send the first information to the target remote device. When the second device is not the target remote device, after receiving the target IP address, the second device can also send the target IP address to the target remote device.
[0066] The network device in the embodiments of this application is an entity on the network side for transmitting or receiving signals. For example, the network device may be an evolved NodeB (eNB), a transmission reception point (TRP), a next generation NodeB (gNB) in an NR system, a base station in other future mobile communication systems, or an access node in a wireless fidelity (WiFi) system, etc. The embodiments of this application do not limit the specific technologies and specific device forms adopted by the network device.
[0067] It should be noted that the technical solutions of the embodiments of this application can be applied to various communication systems. For example: Long Term Evolution (LTE) system, 5th generation (5G) mobile communication system, 5G New Radio (NR) system. Optionally, the methods of the embodiments of this application are also applicable to various future evolved communication systems.
[0068] It can be understood that the communication systems described in the embodiments of this application are for more clearly explaining the technical solutions of the embodiments of this application, and do not constitute a limitation on the technical solutions provided by the embodiments of this application. Those skilled in the art know that with the evolution of the system architecture and the emergence of new service scenarios, the technical solutions provided by the embodiments of this application are equally applicable to similar technical problems.
[0069] The authentication method and its device provided by this application will be introduced in detail below with reference to the accompanying drawings.
[0070] Please refer to Figure 2a , Figure 2a which is a schematic flowchart of an authentication method provided by the embodiments of this application. Among them, the execution subject of step S201 is the second device, or a chip in the second device, and the execution subject of step S202 is the first device, or a chip in the first device. The following takes the first device and the second device as the execution subjects of the authentication method as an example for illustration. As Figure 2a shown, the method may include but is not limited to the following steps:
[0071] Step S201: The second device sends a first request to the first device. The first request includes the identifier of the target remote device. When the second device is a terminal device, the first request is used to request access to the network for the target remote device; when the second device is a network element, the first request is used to request to determine whether the target remote device has the permission to access the network.
[0072] In an embodiment of the present application, when a target remote device needs to access the network (or when the target remote device needs to access the network through a relay device), it may send a request to the relay device to request access to the network. For this target remote device, the purpose of sending the request is to access the network, rather than actively requesting the network or other devices (such as the relay device) to authenticate the target remote device. It should be noted that in the embodiment of the present application, authenticating the target remote device refers to: requesting to determine whether the target remote device has the permission to access the network.
[0073] When the second device is a relay device and the first device is a network element (such as an SMF) serving the relay device, the purpose of the second device sending the first request may be to request to connect the target remote device to the network. For the first device, in order to improve network security, when receiving the first request, it may determine whether the target remote device has the permission to access the network, and then allow the target remote device to access only when it is determined that the target remote device has the network access permission.
[0074] When the second device is a network element (such as an SMF) serving the relay device and the first device may be a permission management device, the second device sends the first request to request to determine whether the target remote device has the permission to access the network. This can prevent remote devices without the permission to access the network from accessing the network, thereby facilitating the improvement of network security.
[0075] Step S202: The first device sends the first information to the second device, and the first information is used to indicate whether the target remote device has the permission to access the network.
[0076] In an embodiment of the present application, after receiving the first request, the first device may trigger an authentication process for the target remote device. The authentication process for the target remote device is used to determine whether the target remote device has the permission to access the network. If the target remote device has the permission to access the network, the first information sent by the first device to the second device is used to indicate that the target remote device has the permission to access the network. If the target remote device does not have the permission to access the network, the first information is used to indicate that the target remote device does not have the permission to access the network. In this way, the authentication mechanism for the target remote device to access the network (that is, to determine whether the target remote device has the permission to access the network) is added, which can prevent remote devices that cannot access from accessing the network, thereby facilitating the improvement of network security.
[0077] In one implementation, the foregoing first request may also be used to request the allocation of a network address for a target remote device; in the case where the target remote device has the permission to access the network, the first information may include the target network address allocated for the target remote device. In other words, if the target remote device has the permission to access the network, the first device may send the target network address allocated for the target remote device to the second device. Optionally, if the target remote device does not have the permission to access the network, the first device may not send the target network address to the second device. In this way, in the case where the target remote device has the permission to access the network, allocating a network address for the target remote device can prevent remote devices that cannot access from accessing the network, thereby contributing to improving network security.
[0078] In one implementation, in the case where the foregoing first request may also be used to request the allocation of a network address for a target remote device, the first information may include explicit indication information or implicit indication information, and the indication information is used to indicate whether the target remote device has the permission to access the network. For example, if the first information includes a target network address, after receiving the first information, the second device may determine that the target remote device has the permission to access the network. At this time, the indication information in the first information is implicit indication information. If the first information does not include a target network address, after receiving the first information, the second device may determine that the target remote device does not have the permission to access the network. At this time, the indication information in the first information is implicit indication information.
[0079] For another example, the indication information in the first information is a field or includes a 1-bit binary digit (represented as 0 or 1). When the value of the indication information is 1, the indication information is used to indicate that the target remote device has the permission to access the network; when the value of the indication information is 0, the second indication information is used to indicate that the target remote device does not have the permission to access the network. At this time, the indication information in the first information is explicit indication information. Or, when the value of the indication information is 0, the indication information is used to indicate that the target remote device has the permission to access the network; when the value of the indication information is 1, the second indication information is used to indicate that the target remote device does not have the permission to access the network. At this time, the indication information in the first information is explicit indication information.
[0080] In one implementation, the first device itself may authenticate the target remote device, and the specific authentication process may be referred to Figure 3a in the description in the embodiments. In another implementation, the first device may request a third device to authenticate the target remote device, and the specific authentication process may be referred to Figure 4a in the description in the embodiments.
[0081] In an embodiment of the present application, a remote device may access the network through a specified relay device, or may access the network through any one of multiple specified relay devices, or may access the network through any device that supports relay technology. In one implementation, the embodiment of the present application may not limit which relay device the target remote device specifically accesses the network through. At this time, the authentication process for the target remote device can be used to determine whether the target remote device has the permission to access the network through relay technology. In another implementation, the target remote device can only access the network through a certain or certain specified relay devices. At this time, the authentication process for the target remote device can be used to determine whether the relay device involved in the process of the target remote device requesting to access the network is the aforementioned specified relay device, and whether the target remote device has the permission to access the network through relay technology. If the relay device involved in the process of the target remote device requesting to access the network is the aforementioned specified relay device, and the target remote device has the permission to access the network through relay technology, it means that the authentication of the target remote device passes, that is, it means that the target remote device has the permission to access the network through the relay device. If the relay device involved in the process of the target remote device requesting to access the network is not the aforementioned specified relay device, and / or the target remote device does not have the permission to access the network through relay technology, it means that the authentication of the target remote device fails, that is, it means that the target remote device does not have the permission to access the network through the relay device.
[0082] In an embodiment of the present application, a relay device may assist one or more remote devices in accessing the network. Optionally, a relay device may assist a limited number of remote devices in accessing the network. In one implementation, the remote devices that a relay device can assist in accessing the network are some specified remote devices. The remote devices that different relay devices can assist in accessing the network may be the same or different. In this case, the authentication process for the target remote device can be used to determine whether the remote devices that the relay device involved in the process of the target remote device requesting to access the network can assist in accessing the network include the target remote device. If it includes, it means that the authentication of the target remote device passes, that is, it means that the target remote device has the permission to access the network through the relay device. If it does not include, it means that the authentication of the target remote device fails, that is, it means that the target remote device does not have the permission to access the network through the relay device.
[0083] In one implementation, the first device may allocate a target network address for the target remote device. For example, when the first device is an SMF or a 3A server, it may allocate a target network address for the target remote device. In another implementation, the first device may request other devices (such as a fourth device or a fifth device) to allocate a target network address for the target remote device. For example, when the first device is a relay device, it may request the SMF or the 3A server to allocate a target network address for the target remote device.
[0084] In one implementation, the device responsible for allocating network addresses (the first device, the fourth device, or the fifth device) may pre-allocate network addresses for each remote device with access network permissions. In other words, multiple network addresses can be allocated at one time. In this case, when allocating network addresses, all or some of the remote devices that may have access network permissions may not have initiated a network access request yet. In other words, even when the remote device does not have a need to access the network, a network address can still be allocated for the remote device. It should be noted that after the remote device initiates a network access request, it can successfully access the network to obtain network services only when the authentication of the remote device passes and the remote device has a network address. It should also be noted that whether the remote device has a network address can be decoupled (or independent) from whether the remote device's authentication passes. In another implementation, the device responsible for allocating network addresses (the first device, the fourth device, or the fifth device) may allocate a network address for a remote device that has access network permissions and has initiated a network access request. In other words, a network address can be allocated for the remote device when the remote device has a need to access the network. It should be noted that when the second device is the target remote device, the first request sent by the second device is the above-mentioned network access request. The network access request mentioned in the embodiments of the present application is used by the sender of the network access request to request access to the network.
[0085] In one implementation, the process of the first device allocating a network address is as follows: The first device allocates a target network address for the target remote device and sends the target network address to the second device. Correspondingly, after receiving the target network address, the second device may send the target network address to the target remote device. For example, when the first device is an SMF and the second device is a relay device, after receiving the target network address, the relay device may send the target network address to the target remote device. Another example is when the first device is a 3A server and the second device is an SMF. After receiving the target network address, the SMF may send the target network address to the relay device. Correspondingly, the relay device may send the target network address from the SMF to the target remote device.
[0086] In another implementation, the process of the first device allocating network addresses is as follows: The first device allocates network addresses (including the target network address) to multiple remote devices (including the target remote device) respectively, and sends the allocated network addresses to the second device. Correspondingly, the second device can, when a certain remote device among the multiple remote devices needs to access the network (for example, when the remote device initiates a network access request), send the received network address corresponding to the remote device to the remote device. For example, the first device allocates network address 1 to remote device 1, allocates network address 2 to remote device 2, allocates network address 3 to remote device 3, and sends the allocated network addresses (i.e., network address 1, network address 2, and network address 3) to the second device. Correspondingly, the second device can, when remote device 1 initiates a network access request, send network address 1 to remote device 1. Similarly, the second device can, when remote device 2 initiates a network access request, send network address 2 to remote device 2. The second device can, when remote device 3 initiates a network access request, send network address 3 to remote device 3. It should be noted that in the embodiments of the present application, the two devices can communicate directly or indirectly through other devices or network elements, and the embodiments of the present application do not limit the communication method between the two devices. For example, when the first device is an SMF and the second device is a relay device, after receiving the network address, the relay device can directly send the network address to the corresponding remote device. Another example is that when the first device is a 3A server and the second device is an SMF, after receiving the network address, the SMF can send the network address to the corresponding remote device through a relay device.
[0087] In one implementation, the process of the first device requesting the fourth device to allocate network addresses can be as Figure 2b shown, including but not limited to steps s1 to s2:
[0088] Step s1: The first device sends a network address allocation request (which can also be referred to as a first network address allocation request) to the fourth device, and this network address allocation request is used to request to obtain a first quantity of network addresses; where the first quantity can be one or more;
[0089] Step s2: When the first quantity is less than or equal to the second quantity, the fourth device sends the first quantity of network addresses to the first device; where the second quantity is the number of remote devices having the permission to access the network; the first quantity of network addresses includes the aforementioned target network address.
[0090] The second quantity is the number of remote devices having the permission to access the network, that is, at most the second quantity of remote devices can access the network. Alternatively, the second quantity is the number of remote devices having the permission to access the network through the relay device, that is, at most the second quantity of remote devices can access the network through the relay device. It should be noted that at this time, it is not limited which relay device each remote device specifically accesses the network through. When the first quantity is less than or equal to the second quantity, the fourth device sends the first quantity of network addresses to the first device. On the one hand, it can avoid allocating more than the second quantity of network addresses for relay access, that is, it can avoid the situation where the number of allocated network addresses is greater than the required number of network addresses, which is beneficial to avoiding waste of network addresses. On the other hand, when the fourth device is the device responsible for allocating network addresses and the first quantity is multiple, the fourth device allocates multiple network addresses at one time, which can avoid the following situation: when different remote devices initiate network access requests, the first device needs to re-request the fourth device to allocate network addresses for each remote device. Therefore, by allocating multiple network addresses at one time, it is beneficial to reduce unnecessary interactions between the first device and the fourth device, thereby saving resources.
[0091] In one implementation, the first quantity can be configured by the network (for example, sent in a system message or proprietary signaling), or can be agreed by the protocol, or can be default set by the first device, or can be set and changed by the user, and the embodiments of the present application do not limit this. In one implementation, the second quantity can be pre-informed to the fourth device by the sixth device, or the fourth device can request the sixth device to obtain it. The sixth device can be a unified data management (UDM) network element or the aforementioned permission management network element. In another implementation, the second quantity can be determined by the corresponding configuration information of the aforementioned network, or can be configured by the network (for example, sent in a system message or proprietary signaling), or can be agreed by the protocol, or can be default set by the fourth device, or can be set and changed by the user, and the embodiments of the present application do not limit this. The corresponding configuration information of the network can indicate the number of remote devices that can access the network (i.e., the second quantity).
[0092] In another implementation, the foregoing network address allocation request may include indication information for indicating a target relay device; the target relay device may be a relay device involved in the process of the foregoing target remote device requesting to access the network. At this time, the foregoing second quantity may specifically be the quantity of remote devices having the permission to access the network through the target relay device. In one implementation, the quantities of remote devices that different relay devices can assist in accessing the network may be the same or different. In other words, taking the relay devices including relay device 1 and relay device 2 as an example, the quantity of remote devices having the permission to access the network through relay device 1 and the quantity of remote devices having the permission to access the network through relay device 2 may be the same or different.
[0093] In one implementation, when the fourth device is an SMF, the network address allocation request may be included in a session establishment request, and the session establishment request may be used to request the creation of a session regarding the first device. The session regarding the first device may be used to transmit information sent by the first device. The session mentioned in the embodiments of the present application may refer to a protocol data unit (PDU) session.
[0094] It should be noted that the embodiments of the present application do not limit the order of the first device receiving the foregoing first request and executing step s1. For example, the first device may execute step s1 after receiving the first request; or, it may execute step s1 before receiving the first request; or, it may execute step s1 and receive the foregoing first quantity of network addresses before receiving the first request; or, it may execute step s1 and receive the first request simultaneously.
[0095] In one implementation, the process of the first device requesting the fifth device to allocate a network address may be as Figure 2c shown, including but not limited to steps s1' to step s2':
[0096] Step s1': The first device sends a second network address allocation request to the fifth device, and the second network address allocation request is used to request the allocation of a network address for the foregoing target remote device;
[0097] Step s2': The fifth device sends the target network address (such as the target IP address) allocated for the target remote device to the first device.
[0098] In one implementation, the first device may send a second network address allocation request to the fifth device when the target remote device has the permission to access the network. In this way, the following situation can be avoided: when the target remote device does not have the permission to access the network, the fifth device is requested to allocate the target network address. Even if the fifth device allocates the target network address, the first device will not send the target network address to the target remote device. Therefore, sending the second network address allocation request to the fifth device when the target remote device has the permission to access the network helps to avoid unnecessary communication processes between the first device and the fifth device, thus helping to avoid resource waste.
[0099] In one implementation, when the fifth device is an SMF, the second network address allocation request may be included in a session establishment request, and the session establishment request may be used to request the creation of a session regarding the first device. Alternatively, the second network address allocation request may be included in a session update request. In this case, a session regarding the first device has already been created in the network. Therefore, after receiving the second network address allocation request, the SMF does not need to create a new session regarding the first device. In the embodiments of the present application, the fourth device and the fifth device may be the same device or different devices.
[0100] In one implementation, if the first device is a relay device and the second device is the target remote device, when the first device receives a first data packet from the second device and the session establishment regarding the first device is successful, the first device may process the first data packet to obtain a second data packet; and transmit the second data packet through the session. The source IP address of the first data packet is the IP address previously allocated to the target remote device (i.e., the target IP address), and the source IP address of the second data packet is the IP address of the first device.
[0101] In one implementation, the specific implementation of how the first device processes the first data packet can be as follows: The first device changes the source IP address of the first data packet from the destination IP address to its own IP address. Alternatively, the first device performs encapsulation processing on the first data packet, and the source IP address added to the first data packet during the encapsulation processing is the IP address of the first device. At this time, the first data packet after encapsulation processing (i.e., the second data packet) carries two source IP addresses. Among them, the source IP address of the outer encapsulation is the IP address of the first device, and the source IP address of the inner encapsulation is the destination IP address. This facilitates, in the case of receiving a feedback data packet for the second data packet (carrying two destination IP addresses, the destination IP address of the outer encapsulation is the IP address of the first device, and the destination IP address of the inner encapsulation is the destination IP address), sending the feedback data packet to the remote device with the IP address of the destination IP address (i.e., the destination remote device) according to the destination IP address of the inner encapsulation. In the embodiments of this application, the first device transmitting the second data packet through this session means that the first device transmits the second data packet to a user plane function (UPF) network element through this session.
[0102] It should be noted that in the embodiments of this application, the IP address assigned to the remote device (including the destination IP address) can be a public network IP address or a private network IP address. The IP address assigned to the remote device (including the destination IP address) can be an IPv4 address or an IPv6 address. The embodiments of this application do not make any limitations in this regard.
[0103] In one implementation, after the device responsible for allocating network addresses (such as an SMF or a 3A server) allocates a network address to a remote device, it can also send the allocated network address of the remote device to the UPF. After receiving the network address, the UPF can configure the network address as the information for N6 interface message sending and receiving. This enables the N6 interface to successfully identify the information to be sent to the remote device, and then send the information to be sent to the remote device to the remote device. Among them, the N6 interface protocol in the 5G protocol corresponds to the interface protocol between the UPF and the data network (DN). In one implementation, the UPF can also store the correspondence between the network address of the remote device and the network address of the relay device (corresponding to the remote device). Among them, the relay device corresponding to the remote device can mean that the remote device accesses the network through this relay device. The UPF stores this correspondence so as to route the information to be sent to the remote device to the relay device corresponding to the remote device according to this correspondence, and then send the information to be sent to the remote device to the remote device through the relay device.
[0104] By implementing the embodiments of the present application, an authentication mechanism for a target remote device to access the network is added, which can determine whether the target remote device has the permission to access the network, so as to prevent remote devices that cannot access from accessing the network, thereby facilitating the improvement of network security.
[0105] Please refer to Figure 3a , Figure 3a which is a schematic flowchart of another authentication method provided by the embodiments of the present application. This method details how a first device authenticates a target remote device. Among them, the execution entity of step S301 is the second device, or a chip in the second device, and the execution entities of steps S302 to S303 are the first device, or a chip in the first device. The following takes the first device and the second device as the execution entities of the authentication method as an example for illustration. As Figure 3a shown, the method may include but is not limited to the following steps:
[0106] Step S301: The second device sends a first request to the first device. The first request includes the identifier of the target remote device. When the second device is a terminal device, the first request is used for the target remote device to request access to the network; when the second device is a network element, the first request is used to request to determine whether the target remote device has the permission to access the network.
[0107] It should be noted that the execution process of step S301 can refer to Figure 2a the specific description of step S201 in
[0108] and will not be elaborated here.
[0109] Step S302: If the identifier of the target remote device exists in the target identifier list, the first device determines that the target remote device has the permission to access the network; wherein, the target identifier list includes one or more target identifiers, and the target identifier is used to indicate a remote device with the permission to access the network.
[0109] In an embodiment of the present application, the authentication process for the target remote device can be completed locally on the first device. The specific authentication process is as follows: After receiving the first request, the first device determines whether the target remote device has the permission to access the network. In one implementation, the first device can determine whether the target remote device has the permission to access the network through, but not limited to, the following methods: (1) Determine whether the target remote device has the permission to access the network based on whether the current location of the target remote device is within the location area allowed to access the network. If it is, it can be determined that the target remote device has the permission to access the network; if not, it can be determined that the target remote device does not have the permission to access the network. Among them, the location area allowed to access the network can be the first tracking area, and the first tracking area can be determined by the tracking area code (TAC). When the target remote device is in the first tracking area, the target remote device can be allowed to access the network. When the target remote device is not in the first tracking area, the target remote device can be allowed to access the network. (2) Determine whether the target remote device has the permission to access the network based on the capabilities of the target remote device. Among them, the capabilities of the target remote device can include: whether it has Ethernet communication capabilities, whether it has switch capabilities, etc. If it has the capabilities, it can be determined that the target remote device has the permission to access the network; if it does not have the capabilities, it can be determined that the target remote device does not have the permission to access the network. (3) Determine whether the target remote device has the permission to access the network based on whether the subscription of the network to the target remote device is valid. Among them, whether the subscription of the network to the target remote device is valid can indicate whether the target remote device is allowed to access the network. If the subscription of the network to the target remote device is valid, it can be determined that the target remote device has the permission to access the network; if the subscription of the network to the target remote device is invalid, it can be determined that the target remote device does not have the permission to access the network. (4) Determine whether the target remote device has the permission to access the network based on whether the identifier of the target remote device exists in the target identifier list. If it exists, it indicates that the target remote device has the permission to access the network. If it does not exist, it indicates that the target remote device does not have the permission to access the network.
[0110] Among them, the target identifier list can be stored locally on the first device. In one implementation, the target identifier list in the first device can be pre-configured for the first device by the aforementioned permission management device (such as a 3A server, AF). Alternatively, the target identifier list can be pre-sent to the first device by the permission management device.
[0111] In one implementation, each network may correspond to a list of identifiers. For a certain network, the list of identifiers corresponding to the network can be used to indicate each remote device having the permission to access the network. The relay device stores list of identifiers 1 and list of identifiers 2. The list of identifiers 1 corresponds to network 1 and is used to indicate each remote device having the permission to access network 1. The list of identifiers 2 corresponds to network 2 and is used to indicate each remote device having the permission to access network 2. If remote device 1 requests to access network 1 and remote device 2 requests to access network 2, the authentication process of the relay device for remote device 1 is as follows: The relay device determines whether the identifier of remote device 1 exists in the list of identifiers 1. If it exists, it indicates that remote device 1 has the permission to access network 1. If it does not exist, it indicates that remote device 1 does not have the permission to access network 1. The authentication process of the relay device for remote device 2 is as follows: The relay device 1 determines whether the identifier of remote device 2 exists in the list of identifiers 2. If it exists, it indicates that remote device 2 has the permission to access network 2. If it does not exist, it indicates that remote device 2 does not have the permission to access network 2. In one implementation, for a certain network, the list of identifiers corresponding to the network can be used to indicate each remote device having the permission to access the network through the relay device. In one implementation, different remote devices may request to access different networks through the same relay device. For example, remote device 1 may request to access network 1 through relay device 1, and remote device 2 may request to access network 2 through relay device 1 or relay device 2.
[0112] In the embodiments of the present application, the aforementioned network (i.e., the network that the remote device (including the target remote device) hopes to access) may refer to a data network, a local area network (LAN), a core network (such as a 4G core network, a 5G core network, etc.) or other types of networks, and the embodiments of the present application do not make any limitations in this regard. It should be noted that the relay device may broadcast the network identifiers that the relay device can access on the sidelink (SL) interface, so that the remote device can initiate a network access request to the relay device that can access the network according to the network it hopes to access. The sidelink may also be referred to as a sidelink or a direct link.
[0113] In one implementation, the foregoing first request may further include a network identifier. In this case, the foregoing first information may specifically be used to indicate whether the target remote device has the permission to access the network indicated by the network identifier. When the second device is a terminal device (such as the target remote device or a terminal device), the first request is specifically used for the target remote device to request access to the network indicated by the network identifier. When the second device is a network element, the first request is specifically used to request to determine whether the target remote device has the permission to access the network indicated by the network identifier. Among them, the network identifier is used to uniquely identify a network. It can be understood that the network identifier may be an identifier of a data network, an identifier of a local area network (LAN), an identifier of a core network (such as a 4G core network, a 5G core network, etc.), or an identifier of other types of networks. The embodiments of the present application do not make any limitations thereto.
[0114] If the first device determines whether the target remote device has the permission to access the network based on whether the identifier of the target remote device exists in the target identifier list, then the target identifier list may be associated with the network identifier. In this case, the target identifier may specifically be used to indicate the remote device that has the permission to access the network indicated by the network identifier.
[0115] Combined with the foregoing content, it can be known that a network identifier may be associated with an identifier list. For a certain network, the identifier list associated with the network identifier may be used to indicate each remote device that has the permission to access the network indicated by the network identifier. Therefore, after receiving the first request, the authentication process of the first device for the target remote device is as follows: obtain the target identifier list associated with the network identifier in the first request, and determine whether the identifier of the target remote device exists in the target identifier list. If it exists, it indicates that the target remote device has the permission to access the network (indicated by the network identifier). If it does not exist, it indicates that the target remote device does not have the permission to access the network.
[0116] In this way, it is possible to prevent a device that does not have the permission to access the network from accessing the network. When the network identifier is the identifier of a LAN, it is possible to prevent a member who does not belong to the LAN from joining the LAN session.
[0117] Step S303: The first device sends the first information to the second device, and the first information is used to indicate that the target remote device has the permission to access the network.
[0118] Specifically, if the target remote device has the permission to access a network (such as a data network or a LAN), the first information that the first device can send to the second device is used to indicate that the target remote device has the permission to access the network. If the target remote device does not have the permission to access a network (such as a data network or a LAN), the first information that the first device sends to the second device is used to indicate that the target remote device does not have the permission to access the network. In one implementation, if the target remote device has the permission to access a network (such as a data network or a LAN), the first device can send the target network address assigned to the target remote device to the second device. If the target remote device does not have the permission to access a network (such as a data network or a LAN), the first device may not send the target network address to the second device. It should be noted that for the content on how the first device obtains the network address (including the target network address) assigned to the remote device, reference can be made to Figure 2a the relevant descriptions in the embodiments, which will not be elaborated here. It should also be noted that for the execution process of step S303, reference can be made to Figure 2a the specific description of step S202 in
[0119] In the embodiments of the present application, the device that assigns network addresses to remote devices can be the first device, or the first device can request other devices (such as the fourth device or the fifth device) to assign network addresses to remote devices.
[0120] In one implementation, the network addresses of remote devices can be pre-assigned and stored in the first device. After the remote device (such as the target remote device) passes authentication, the first device can send the network address (i.e., the target network address) assigned to the target remote device to the second device. It should be noted that in the embodiments of the present application, a certain device passing authentication means that it is determined that the device has the permission to access the network. Similarly, in the embodiments of the present application, a certain device failing authentication means that it is determined that the device does not have the permission to access the network.
[0121] Taking the first device as the relay device, the second device as the target remote device, the fourth device as the SMF, the sixth device as the UDM, and the first quantity being multiple as an example, the schematic diagram of the scenario of pre-assigning network addresses to remote devices (including the target remote device) can be as Figure 3b shown. Among them, the target remote device sends a first request to the relay device, indicating that the target remote device hopes to access the network. At this time, the first request is used for the target remote device to request access to the network and also for requesting the assignment of a network address for the target remote device. By Figure 3bIt can be known that before receiving the first request, the relay device can send a network address allocation request to the SMF to pre-request the SMF to allocate network addresses for multiple (i.e., the first quantity) remote devices (including the target remote device) respectively. After receiving the network address allocation request, the SMF can obtain the second quantity from the UDM, and when the first quantity is less than or equal to the second quantity, allocate network addresses for each of the foregoing multiple remote devices, and send the network addresses allocated for each remote device to the relay device. In this way, when the relay device receives the first request and the authentication for the target remote device passes (for example, the identifier of the target remote device exists in the target identifier list), it can obtain the target network address allocated by the SMF for the target remote device from the local memory, and carry the target network address in the first information (the first information is used to indicate that the target remote device has the permission to access the network) and send it to the target remote device.
[0122] In another implementation manner, the first device can trigger the process of allocating a network address for the target remote device after determining that the authentication of the target remote device passes. For example, when the device that allocates the network address for the remote device is the first device, the first device can allocate a network address for the target remote device after determining that the authentication of the target remote device passes. Another example is that when the first device requests other devices (such as the fourth device or the fifth device) to allocate network addresses for the remote device, the first device can request the other device (such as the fourth device or the fifth device) to allocate a network address for the remote device after determining that the authentication of the target remote device passes. In this way, it is possible to avoid the situation where the process of allocating a network address for the remote device is triggered, but the authentication result of the remote device is authentication failure, which is beneficial to avoiding resource waste.
[0123] By implementing the embodiments of the present application, an authentication mechanism for the target remote device to access the network is added, and it can be determined whether the target remote device has the permission to access the network, so as to prevent remote devices that cannot access from accessing the network, which is beneficial to improving network security.
[0124] Please refer to Figure 4a , Figure 4a FIG. is a schematic flowchart of another authentication method provided by the embodiments of the present application, which details how the third device authenticates the target remote device. Among them, the execution entity of step S401 is the second device, or a chip in the second device, the execution entities of step S402 and step S404 are the first device, or a chip in the first device, and the execution entity of step S403 is the third device, or a chip in the third device. The following takes the first device, the second device, and the third device as the execution entities of the authentication method as an example for illustration. As Figure 4a shown, the method may include but is not limited to the following steps:
[0125] Step S401: The second device sends a first request to the first device. The first request includes the identifier of the target remote device. When the second device is a terminal device, the first request is used for the target remote device to request access to the network. When the second device is a network element, the first request is used to request to determine whether the target remote device has the permission to access the network.
[0126] It should be noted that the execution process of step S401 can refer to Figure 2a the specific description of step S201 in
[0127] Step S402: The first device sends an authentication request to the third device. The authentication request includes the identifier of the target remote device. The authentication request is used to request to determine whether the target remote device has the permission to access the network.
[0128] In the embodiments of the present application, the first device can request the third device to authenticate the target remote device. The process (or method) of the third device authenticating the target remote device is the same as Figure 3a the process (or method) of the first device authenticating the target remote device in Figure 3a the embodiments. The difference is that Figure 4a in the embodiments, the first device is the authentication subject, while in Figure 3a the embodiments, the third device is the authentication subject. The execution process of step S402 can refer to
[0129] the relevant content where the first device is the authentication subject in
[0130] the embodiments. Here, it will not be elaborated. Figure 3a the specific description of step S302 in
[0131] It should be noted that when the third device serves as the authentication entity, in order to inform the first device whether the target remote device has passed the authentication, after the third device completes the authentication of the target remote device, it can send the authentication result information to the first device to indicate whether the target remote device has passed the authentication (that is, whether the target remote device has the permission to access the network). Specifically, if the target remote device passes the authentication, the authentication result information sent to the first device is used to indicate that the target remote device has the permission to access the network; if the target remote device fails the authentication, the authentication result information sent to the first device is used to indicate that the target remote device does not have the permission to access the network.
[0132] In the embodiments of the present application, the network that the remote device hopes to access can be a data network, a local area network, or other types of networks. In one implementation, the foregoing first request and authentication request may further include a network identifier, and the authentication request is specifically used to request to determine whether the target remote device has the permission to access the network indicated by the network identifier; the first information and the authentication result information are specifically used to indicate whether the target remote device has the permission to access the network indicated by the network identifier. When the second device is a terminal device (such as the target remote device or a relay device), the first request is specifically used for the target remote device to request access to the network indicated by the network identifier; when the second device is a network element (such as an SMF network element), the first request is specifically used to request to determine whether the target remote device has the permission to access the network indicated by the network identifier.
[0133] If the third device determines whether the target remote device has the permission to access the network according to whether the identifier of the target remote device exists in the target identifier list, then the target identifier list is associated with the network identifier. At this time, the target identifier in the target identifier list can specifically be used to indicate the remote device that has the permission to access the network indicated by the network identifier.
[0134] Step S404: The first device sends the first information to the second device, and the first information is used to indicate whether the target remote device has the permission to access the network.
[0135] Specifically, after receiving the authentication result information, the first device can send the first information to the second device. At this time, the content indicated by the authentication result information and the first information is the same, that is, both the authentication result information and the first information are used to indicate that the target remote device has the permission to access the network, or both the authentication result information and the first information are used to indicate that the target remote device does not have the permission to access the network.
[0136] In one implementation, if the authentication result information is used to indicate that the target remote device has the permission to access the network, the first device may also send the target network address assigned to the target remote device to the second device, so that the second device can send the target network address to the target remote device. Wherein, the target network address may be sent together with the first information (for example, the target network address is carried in the first information), or sent separately, and the embodiments of the present application do not limit this. If the authentication result information is used to indicate that the target remote device does not have the permission to access the network, the first device may not send the target network address to the second device, or may not trigger the process of allocating a network address for the target remote device.
[0137] In one implementation, the process of allocating a network address for the target remote device may be triggered after it is determined that the target remote device has passed authentication. In one implementation, the first device may trigger the process of allocating a network address for the target remote device; or, the device responsible for authentication (such as the third device) may trigger the process of allocating a network address for the target remote device. In one implementation, the device responsible for authentication and the device responsible for allocating a network address for the target remote device may be the same device; or, they may be different devices, and the embodiments of the present application do not limit this.
[0138] In one implementation, the authentication request sent by the first device to the third device may also be used to request the allocation of a network address for the target remote device; correspondingly, the foregoing authentication result information may include the target network address allocated for the target remote device. In other words, in addition to being used to authenticate the target remote device, the third device may also be used to allocate a network address for the target remote device.
[0139] See Figure 4b , which is a schematic diagram of the scenario where both the device responsible for authentication and the device responsible for allocating a network address for the target remote device are the third device. Figure 4b Taking the first device as the relay device, the second device as the target remote device, and the third device as the SMF as an example. Among them, the target remote device sends a first request to the relay device, indicating that the target remote device hopes to access the network. At this time, the first request is used for the target remote device to request access to the network and also for requesting the allocation of a network address for the target remote device. By Figure 4bIt can be seen that after receiving the first request, the relay device sends an authentication request to the SMF to request the SMF to authenticate the target remote device and, in the case of successful authentication, allocate a network address for the target remote device. Correspondingly, after the SMF successfully authenticates the target remote device (such as when the identifier of the target remote device exists in the target identifier list), it can allocate a target network address for the target remote device and carry the target network address in the authentication result information (the authentication result information is used to indicate that the target remote device has the permission to access the network) and send it to the first device. Then the first device can carry the target network address in the first information (the first information is used to indicate that the target remote device has the permission to access the network) and send it to the target remote device. In this process, the SMF is used not only to authenticate the target remote device but also to allocate a network address for the target remote device.
[0140] In another implementation, when the authentication request sent by the first device to the third device is also used to request the allocation of a network address for the target remote device, the authentication result information (the authentication result information is used to indicate that the target remote device has the permission to access the network) sent by the third device to the first device can also be used to instruct the first device to allocate a network address for the target remote device. Correspondingly, after receiving the authentication result information, the first device can allocate a network address for the remote device.
[0141] See Figure 4c , which is a schematic diagram of a scenario where the device responsible for authentication and the device responsible for allocating a network address for the target remote device are different devices. Figure 4c Taking the first device as the SMF, the second device as the relay device, and the third device as the permission management device as an example. Among them, the target remote device sends a network address allocation request 1 to the relay device. The network address allocation request 1 includes the identifier of the target remote device, and the network address allocation request 1 is used to request the allocation of a network address for the target remote device. That is, the target remote device sending the network address allocation request 1 to the relay device indicates that the target remote device hopes to access the network. By Figure 4cIt can be known that after receiving the network address allocation request 1, the relay device sends a first request (including the identifier of the target remote device) to the SMF to indicate that the target remote terminal requests to access the network and requests to allocate a network address for the target remote device. At this time, the SMF can send an authentication request to the permission management device to request the permission management device to authenticate the target remote device. After the authentication is passed, the authentication result information sent by the permission management device to the SMF can be used to indicate that the target remote device has passed the authentication and to indicate to the SMF to allocate a network address for the target remote device. It can be understood that once the SMF receives the authentication result information, it can allocate the target network address for the target remote device and carry the target network address in the first information (the first information is used to indicate that the target remote device has the permission to access the network) and feedback it to the relay device, and then the relay device feeds back the target network address to the target remote device.
[0142] In one implementation, Figure 4c the authentication request in can also be used to request the permission management device to allocate a network address for the remote device after authenticating the target remote device. After authenticating the target remote device, the permission management device can continue to allocate a network address for the target remote device, or it can also authorize or instruct the SMF to allocate a network address for the target remote device. In this process, the device that authenticates the target remote device is the permission management device, and the device that allocates a network address for the target remote device is the SMF.
[0143] It should be noted that for the remaining execution process of step S404, reference can be made to Figure 2a the specific description of step S202 in, which will not be elaborated here.
[0144] By implementing the embodiments of the present application, an authentication mechanism for the target remote device to access the network is added, and it can be determined whether the target remote device has the permission to access the network, so as to prevent remote devices that cannot access from accessing the network, which is beneficial to improving network security.
[0145] In the above embodiments provided by the present application, the methods provided by the embodiments of the present application are introduced from the perspectives of the first device and the second device respectively. To implement the various functions in the methods provided by the above embodiments of the present application, the first device and the second device may include a hardware structure and software modules, and implement the above various functions in the form of a hardware structure, a software module, or a combination of a hardware structure and a software module. A certain function among the above various functions can be executed in the form of a hardware structure, a software module, or a combination of a hardware structure and a software module.
[0146] Please refer to Figure 5 , which is a schematic structural diagram of a communication device 50 provided by an embodiment of the present application. Figure 5The communication device 50 shown may include a processing unit 501 and a communication unit 502. The communication unit 502 may include a sending unit and / or a receiving unit. The sending unit is used to implement the sending function, and the receiving unit is used to implement the receiving function. The communication unit 502 can implement the sending function and / or the receiving function. The communication unit can also be described as a transceiver unit.
[0147] The communication device 50 can be a first device, or a device in the first device, or a device that can be used in combination with the first device. Alternatively, the communication device 50 can be a second device, or a device in the second device, or a device that can be used in combination with the second device.
[0148] When the communication device 50 is a first device: The processing unit 501 is used to call the communication unit 502 to receive a first request from a second device. The first request includes the identifier of the target remote device. When the second device is a terminal device, the first request is for the target remote device to request access to the network; when the second device is a network element, the first request is for requesting to determine whether the target remote device has the permission to access the network. The processing unit 501 is further used to call the communication unit 502 to send first information to the second device, and the first information is used to indicate whether the target remote device has the permission to access the network.
[0149] In one implementation, the processing unit 501 can also be used to: determine whether the target remote device has the permission to access the network.
[0150] In one implementation, the processing unit 501 can also be used to: if the identifier of the target remote device exists in the target identifier list, determine that the target remote device has the permission to access the network; the target identifier list includes one or more target identifiers, and the target identifiers are used to indicate the remote devices that have the permission to access the network.
[0151] In one implementation, the first request further includes a network identifier, and the foregoing first information is specifically used to indicate whether the target remote device has the permission to access the network indicated by the network identifier; when the second device is a terminal device, the first request is specifically for the target remote device to request access to the network indicated by the network identifier; when the second device is a network element, the first request is specifically for requesting to determine whether the target remote device has the permission to access the network indicated by the network identifier.
[0152] In one implementation, the processing unit 501 is further configured to call the communication unit 502 to send an authentication request to a third device. The authentication request includes an identifier of a target remote device, and is used to request to determine whether the target remote device has the permission to access the network. The processing unit 501 is further configured to call the communication unit 502 to receive authentication result information from the third device, and the authentication result information is used to indicate whether the target remote device has the permission to access the network.
[0153] In one implementation, when the identifier of the target remote device exists in a target identifier list, the authentication result information is used to indicate that the target remote device has the permission to access the network. The target identifier list includes one or more target identifiers, and the target identifier is used to indicate a remote device having the permission to access the network.
[0154] In one implementation, the first request and the authentication request further include a network identifier. The authentication request is specifically used to request to determine whether the target remote device has the permission to access the network indicated by the network identifier. The first information and the authentication result information are specifically used to indicate whether the target remote device has the permission to access the network indicated by the network identifier. When the second device is a terminal device, the first request is specifically used for the target remote device to request to access the network indicated by the network identifier. When the second device is a network element, the first request is specifically used to request to determine whether the target remote device has the permission to access the network indicated by the network identifier.
[0155] In one implementation, the first request is further used to request to allocate a network address for the target remote device. When the target remote device has the permission to access the network, the foregoing first information may include the target network address allocated for the target remote device.
[0156] In one implementation, the processing unit 501 is further configured to call the communication unit 502 to send a network address allocation request to a fourth device. The network address allocation request is used to request to obtain a first quantity of network addresses. The processing unit 501 is further configured to call the communication unit 502 to receive the first quantity of network addresses from the fourth device. The first quantity of network addresses is sent when the first quantity is less than or equal to a second quantity, where the second quantity is the quantity of remote devices having the permission to access the network. The first quantity of network addresses includes the foregoing target network address.
[0157] The communication device 50 is a second device: A processing unit 501 is configured to call a communication unit 502 to send a first request to a first device. The first request includes an identifier of a target remote device. When the communication device 50 is a device in a terminal device, the first request is used for the target remote device to request access to a network. When the communication device 50 is a device in a network element, the first request is used to request to determine whether the target remote device has the permission to access the network. The processing unit 501 is further configured to call the communication unit 502 to receive first information from the first device, where the first information is used to indicate whether the target remote device has the permission to access the network.
[0158] In one implementation, the first request further includes a network identifier. The foregoing first information is specifically used to indicate whether the target remote device has the permission to access the network indicated by the network identifier. When the communication device 50 is a device in a terminal device, the first request is specifically used for the target remote device to request access to the network indicated by the network identifier. When the communication device 50 is a device in a network element, the first request is specifically used to request to determine whether the target remote device has the permission to access the network indicated by the network identifier.
[0159] In one implementation, the first request is further used to request to allocate a network address for the target remote device. When the target remote device has the permission to access the network, the first information includes the target network address allocated for the target remote device.
[0160] Please refer to Figure 6 , Figure 6 which is a schematic structural diagram of another communication device 60 provided in an embodiment of this application. The communication device 60 may be a first device or a second device, or may be a chip, a chip system, or a processor, etc., that supports the first device to implement the foregoing method, or may be a chip, a chip system, or a processor, etc., that supports the second device to implement the foregoing method. This device can be used to implement the method described in the foregoing method embodiment, and for specific details, please refer to the description in the foregoing method embodiment.
[0161] The communication device 60 may include one or more processors 601. The processor 601 may be a general-purpose processor or a dedicated processor, etc. For example, it may be a baseband processor or a central processing unit. The baseband processor may be used to process communication protocols and communication data, and the central processing unit may be used to control a communication device (such as a remote device, a remote device chip, a relay device, a relay device chip, an SMF, an SMF chip, a DU, or a CU, etc.), execute a computer program, and process data of the computer program.
[0162] The communication device 60 may further include a transceiver 602 and an antenna 603. The transceiver 602 may be referred to as a transceiver unit, a transceiver, or a transceiver circuit, etc., and is used to implement a transceiver function. The transceiver 603 may include a receiver and a transmitter, the receiver may be referred to as a receiver or a receiving circuit, etc., and is used to implement a receiving function; the transmitter may be referred to as a transmitter or a transmitting circuit, etc., and is used to implement a transmitting function.
[0163] Optionally, the communication device 60 may include one or more memories 604, on which a computer program 605 may be stored, and the computer program may be run on the communication device 60, so that the communication device 60 performs the method described in the above method embodiment. Optionally, data may also be stored in the memory 604. The communication device 60 and the memory 604 may be provided separately or integrated together.
[0164] The communication device 60 is a first device: the processor 601 is used to execute Figure 3a The transceiver 602 is used to perform Figure 2a or Figure 2b step s1 in; or Figure 2c or Figure 3a Step S303 in ; or Figure 4a Steps S402 and S404 in .
[0165] The communication device 60 is a second device: the transceiver 602 is used to perform Figure 2a or Figure 3a Step S301 in ; or Figure 4a Step S401 in .
[0166] In one implementation, the processor 601 may include a transceiver for implementing the receiving and sending functions. For example, the transceiver may be a transceiver circuit, an interface, or an interface circuit. The transceiver circuit, interface, or interface circuit for implementing the receiving and sending functions may be separate or integrated. The above-mentioned transceiver circuit, interface, or interface circuit may be used for reading and writing code / data, or the above-mentioned transceiver circuit, interface, or interface circuit may be used for transmitting or delivering signals.
[0167] In one implementation, the processor 601 may store a computer program 606, which runs on the processor 601 and enables the communication device 60 to perform the method described in the above method embodiment. The computer program 606 may be fixed in the processor 601, in which case the processor 601 may be implemented by hardware.
[0168] In one implementation, the communication device 60 may include circuitry that can implement the functions of transmitting, receiving, or communicating in the foregoing method embodiments. The processor and transceiver described in this application may be implemented on an integrated circuit (IC), analog IC, radio frequency integrated circuit (RFIC), mixed-signal IC, application specific integrated circuit (ASIC), printed circuit board (PCB), electronic device, etc. The processor and transceiver may also be fabricated using various IC process technologies, such as complementary metal oxide semiconductor (CMOS), N-type metal oxide semiconductor (NMOS), P-type metal oxide semiconductor (PMOS), bipolar junction transistor (BJT), BiCMOS, silicon germanium (SiGe), gallium arsenide (GaAs), etc.
[0169] The communication device described in the above embodiments may be the first device or the second device, but the scope of the communication device described in this application is not limited thereto, and the structure of the communication device may not be subject to Figure 6 restrictions. The communication device may be an independent device or may be a part of a larger device. For example, the communication device may be:
[0170] (1) An independent integrated circuit (IC), or chip, or chip system or subsystem;
[0171] (2) A set of one or more ICs, optionally, the IC set may also include storage components for storing data and computer programs;
[0172] (3) ASIC, such as a modem;
[0173] (4) A module that can be embedded in other devices;
[0174] (5) A receiver, terminal, smart terminal, cellular phone, wireless device, handset, mobile unit, vehicle-mounted device, network device, cloud device, artificial intelligence device, etc.;
[0175] (6) Others, etc.
[0176] For the case where the communication device may be a chip or a chip system, reference may be made toFigure 7 Schematic structural diagram of the chip shown Figure 7 The chip shown includes a processor 701 and an interface 702. Among them, the number of processors 701 can be one or more, and the number of interfaces 702 can be multiple.
[0177] For the case where the chip is used to implement the functions of the first device in the embodiments of the present application:
[0178] The processor 701 is used to call the interface 702 to receive a first request from a second device. The first request includes an identifier of a target remote device. When the second device is a terminal device, the first request is used for the target remote device to request access to the network; when the second device is a network element, the first request is used to request to determine whether the target remote device has the permission to access the network; the processor 701 is further used to call the interface 702 to send a first message to the second device, and the first message is used to indicate whether the target remote device has the permission to access the network.
[0179] In one implementation, the processor 701 can also be used to: determine whether the target remote device has the permission to access the network.
[0180] In one implementation, the processor 701 can also be used to: if the identifier of the target remote device exists in the target identifier list, determine that the target remote device has the permission to access the network; the target identifier list includes one or more target identifiers, and the target identifier is used to indicate a remote device with the permission to access the network.
[0181] In one implementation, the first request further includes a network identifier, and the foregoing first message is specifically used to indicate whether the target remote device has the permission to access the network indicated by the network identifier; when the second device is a terminal device, the first request is specifically used for the target remote device to request access to the network indicated by the network identifier; when the second device is a network element, the first request is specifically used to request to determine whether the target remote device has the permission to access the network indicated by the network identifier.
[0182] In one implementation, the processor 701 is further used to call the interface 702 to send an authentication request to a third device. The authentication request includes an identifier of a target remote device, and the authentication request is used to request to determine whether the target remote device has the permission to access the network; the processor 701 is further used to call the interface 702 to receive authentication result information from the third device, and the authentication result information is used to indicate whether the target remote device has the permission to access the network.
[0183] In one implementation, when the identifier of the target remote device exists in the target identifier list, the authentication result information is used to indicate that the target remote device has the permission to access the network. The target identifier list includes one or more target identifiers, and the target identifier is used to indicate the remote device that has the permission to access the network.
[0184] In one implementation, the first request and the authentication request further include a network identifier. The authentication request is specifically used to request to determine whether the target remote device has the permission to access the network indicated by the network identifier. The first information and the authentication result information are specifically used to indicate whether the target remote device has the permission to access the network indicated by the network identifier. When the second device is a terminal device, the first request is specifically used for the target remote device to request to access the network indicated by the network identifier. When the second device is a network element, the first request is specifically used to request to determine whether the target remote device has the permission to access the network indicated by the network identifier.
[0185] In one implementation, the first request is further used to request to allocate a network address for the target remote device. When the target remote device has the permission to access the network, the foregoing first information may include the target network address allocated for the target remote device.
[0186] In one implementation, the processor 701 is further used to call the interface 702 to send a network address allocation request to the fourth device. The network address allocation request is used to request to obtain a first quantity of network addresses. The processor 701 is further used to call the interface 702 to receive the first quantity of network addresses from the fourth device. The first quantity of network addresses is sent when the first quantity is less than or equal to the second quantity. Wherein, the second quantity is the quantity of remote devices that have the permission to access the network. The first quantity of network addresses includes the foregoing target network address.
[0187] For the case where the chip is used to implement the function of the second device in the embodiments of the present application:
[0188] The processor 701 is used to call the interface 702 to send a first request to the first device. The first request includes the identifier of the target remote device. When the second device is a terminal device, the first request is used for the target remote device to request to access the network. When the second device is a network element, the first request is used to request to determine whether the target remote device has the permission to access the network. The processor 701 is further used to call the interface 702 to receive the first information from the first device. The first information is used to indicate whether the target remote device has the permission to access the network.
[0189] In one implementation, the first request further includes the identifier of the network indicated by the local area network identifier, and the foregoing first information is specifically used to indicate whether the target remote device has the permission to access the network indicated by the network identifier; when the second device is a terminal device, the first request is specifically used for the target remote device to request access to the network indicated by the network identifier; when the second device is a network element, the first request is specifically used to request to determine whether the target remote device has the permission to access the network indicated by the network identifier.
[0190] In one implementation, the first request is further used to request to allocate a network address for the target remote device; when the target remote device has the permission to access the network, the first information includes the target network address allocated for the target remote device.
[0191] Optionally, the chip further includes a memory 703, and the memory 703 is used to store necessary computer programs and data.
[0192] Those skilled in the art can also understand that the various illustrative logical blocks and steps listed in the embodiments of the present application can be implemented by electronic hardware, computer software, or a combination of the two. Whether such a function is implemented by hardware or software depends on the specific application and the design requirements of the entire system. For each specific application, those skilled in the art can use various methods to implement the described function, but such implementation should not be construed as exceeding the scope protected by the embodiments of the present application.
[0193] The present application further provides a computer-readable storage medium, on which a computer program is stored, and the computer program includes program instructions, and when the program instructions are executed by a computer, the functions of any one of the foregoing method embodiments are implemented.
[0194] The foregoing computer-readable storage medium includes, but is not limited to, flash memory, hard disk, and solid-state drive.
[0195] The present application further provides a computer program product, and when the computer program product is executed by a computer, the functions of any one of the foregoing method embodiments are implemented.
[0196] In the above embodiments, it can be implemented in whole or in part by software, hardware, firmware, or any combination thereof. When implemented using software, it can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer programs. When the computer program is loaded and executed on a computer, the processes or functions described in the embodiments of the present application are generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable devices. The computer program can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, the computer program can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center by wire (such as coaxial cable, optical fiber, digital subscriber line (DSL)) or wirelessly (such as infrared, wireless, microwave, etc.). The computer-readable storage medium can be any available medium that the computer can access or a data storage device such as a server or data center that includes one or more integrated available media. The available medium can be a magnetic medium (such as a floppy disk, hard disk, magnetic tape), an optical medium (such as a high-density digital video disc (DVD)), or a semiconductor medium (such as a solid state disk (SSD)), etc.
[0197] Those of ordinary skill in the art can understand that the various digital numbers such as the first and second involved in this application are only for the convenience of description and are not used to limit the scope of the embodiments of this application, nor do they represent the order of precedence.
[0198] At least one in this application can also be described as one or more. The plurality can be two, three, four, or more, and this application does not make any restrictions. In the embodiments of this application, for a technical feature, the technical features in this technical feature are distinguished by "first", "second", "third", "A", "B", "C", and "D", etc. There is no order of precedence or size order among the technical features described by the "first", "second", "third", "A", "B", "C", and "D".
[0199] The corresponding relationships shown in each table in this application can be configured or predefined. The values of the information in each table are only examples and can be configured to other values, which are not limited in this application. When configuring the corresponding relationships between the configuration information and each parameter, it is not necessarily required to configure all the corresponding relationships shown in each table. For example, in the tables of this application, the corresponding relationships shown in some rows can also not be configured. Another example is that appropriate deformation adjustments can be made based on the above tables, such as splitting, merging, etc. The names of the parameters shown in the titles of the above tables can also use other names that can be understood by the communication device, and the values or representation methods of the parameters can also use other values or representation methods that can be understood by the communication device. When implementing the above tables, other data structures can also be used, such as arrays, queues, containers, stacks, linear lists, pointers, linked lists, trees, graphs, structures, classes, heaps, hash tables or hash maps, etc.
[0200] The predefined in this application can be understood as defining, pre - defining, storing, pre - storing, pre - negotiating, pre - configuring, solidifying, or pre - burning.
[0201] Those of ordinary skill in the art can realize that the units and algorithm steps of each example described in combination with the embodiments disclosed herein can be implemented by electronic hardware or a combination of computer software and electronic hardware. Whether these functions are executed in a hardware or software manner depends on the specific application and design constraints of the technical solution. Professional technicians can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of this application.
[0202] Those skilled in the art can clearly understand that for the convenience and brevity of description, the specific working processes of the systems, devices, and units described above can refer to the corresponding processes in the foregoing method embodiments and will not be elaborated herein.
[0203] As described above, it is only the specific implementation manner of this application, but the protection scope of this application is not limited thereto. Any person skilled in the art can easily think of changes or substitutions within the technical scope disclosed in this application and should be covered by the protection scope of this application. Therefore, the protection scope of this application should be subject to the protection scope of the claims.
Claims
1. An authentication method, characterized in that, The method includes: A first device receives a first request from a second device, where the first request includes an identifier of a target remote device and a network identifier; when the second device is a terminal device, the first request is for the target remote device to request access to the network indicated by the network identifier; when the second device is a network element, the first request is for requesting to determine whether the target remote device has the permission to access the network indicated by the network identifier; one network identifier is associated with one identifier list, and the one identifier list indicates each remote device having the permission to access the network indicated by the one network identifier; The first device obtains the target identifier list associated with the network identifier, and based on the target identifier list, sends first information to the second device, where the first information is used to indicate whether the target remote device has the permission to access the network indicated by the network identifier.
2. The method according to claim 1, wherein The method further includes: The first device sends an authentication request to a third device, where the authentication request includes the identifier of the target remote device, and the authentication request is for requesting to determine whether the target remote device has the permission to access the network. The first device receives authentication result information from the third device, where the authentication result information is used to indicate whether the target remote device has the permission to access the network.
3. The method according to claim 2, wherein When the identifier of the target remote device exists in the target identifier list, the authentication result information is used to indicate that the target remote device has the permission to access the network, where the target identifier list includes one or more target identifiers, and the target identifiers are used to indicate the remote devices having the permission to access the network.
4. The method according to claim 2, characterized in that The authentication request further includes the network identifier, and the authentication request is specifically for requesting to determine whether the target remote device has the permission to access the network indicated by the network identifier; the authentication result information is specifically for indicating whether the target remote device has the permission to access the network indicated by the network identifier.
5. The method according to any one of claims 1 to 4, characterized in that, The first request is further for requesting to allocate a network address for the target remote device; when the target remote device has the permission to access the network, the first information includes the target network address allocated for the target remote device.
6. The method according to claim 5, characterized in that The method further includes: The first device sends a network address allocation request to a fourth device, where the network address allocation request is for requesting to obtain a first quantity of network addresses. The first device receives the first quantity of network addresses from the fourth device; the first quantity of network addresses is sent when the first quantity is less than or equal to a second quantity; where the second quantity is the quantity of remote devices having the permission to access the network; the first quantity of network addresses includes the target network address.
7. An authentication method, characterized in that, The method includes: The second device sends a first request to the first device, and the first request includes the identifier of the target remote device and the network identifier; when the second device is a terminal device, the first request is for the target remote device to request access to the network indicated by the network identifier; when the second device is a network element, the first request is for requesting to determine whether the target remote device has the permission to access the network indicated by the network identifier; one network identifier is associated with an identifier list, and the one identifier list indicates each remote device having the permission to access the network indicated by the one network identifier. The second device receives first information from the first device, and the first information is used to indicate whether the target remote device has the permission to access the network; the first information is determined based on the target identifier list associated with the network identifier.
8. The method according to claim 7, wherein The first request is further used to request to allocate a network address for the target remote device; when the target remote device has the permission to access the network, the first information includes the target network address allocated for the target remote device.
9. A communication device, characterized in that, It includes a unit for executing the method according to any one of claims 1 to 6.
10. A communication device, characterized in that, It includes a unit for executing the method according to any one of claims 7 to 8.
11. A communication device, characterized in that, The device includes a processor and a memory, and program instructions are stored in the memory. The processor executes the program instructions stored in the memory to enable the device to execute the method according to any one of claims 1 to 6.
12. A communication device, characterized in that, The device includes a processor and a memory, and program instructions are stored in the memory. The processor executes the program instructions stored in the memory to enable the device to execute the method according to any one of claims 7 to 8.
13. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program, and the computer program includes program instructions. When the program instructions are executed by the communication device, the communication device is enabled to execute the method according to any one of claims 1 to 6 or 7 to 8.
Citation Information
Patent Citations
Network access method, near field communication server, relay terminal and terminal
CN104469695A
Cited By
Authentication method and apparatus thereof
WO2022068541A1