An authentication method and related equipment

By using common channels to transmit authentication information in 5G networks, two-step or four-step authentication methods are used to solve the problem of terminal equipment and network equipment authentication in the scenario without RRC connection, and a low-power authentication process is realized.

CN114554489BActive Publication Date: 2025-08-08SHANGHAI HUAWEI TECH CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202011354045.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2020-11-26
Publication Date
2025-08-08
Estimated Expiration
2040-11-26

AI Technical Summary

Technical Problem

In 5G networks, authentication cannot be performed in scenarios where there is no RRC connection between the terminal device, resulting in an increase in power consumption of the terminal device.

Method used

By passing the information required for authentication on the common channel between the terminal device and the network device, a two-step or four-step authentication method is used to complete the authentication process using session requests and response messages, embedded in the session establishment process, and simplifying information interaction.

Benefits of technology

It realizes authentication between terminal devices and network devices without RRC connection, reduces information interaction, reduces power consumption of terminal devices, and simplifies authentication process.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114554489B_ABST
    Figure CN114554489B_ABST
Patent Text Reader

Abstract

The present application provides an authentication method and related devices. First, a network device receives a session request sent by a terminal device on an uplink common channel. The network device can confirm that the terminal device has passed authentication based on the session request. Then, the network device sends a session response to the terminal device on a downlink common channel. The session response is used to instruct the terminal device to authenticate the network device. In a scenario where no RRC connection is established between the terminal device and the network device, the terminal device and the network device can transmit the information required for authentication through a common channel, thereby achieving authentication between the terminal device and the network device.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The embodiments of the present application relate to the field of communications, and in particular to an authentication method and related equipment. Background Art

[0002] The 3rd Generation Partnership Project (3GPP) standards organization developed the protocol standard for the fifth-generation cellular mobile communication system. Compared with the long-term evolution (LTE) system, the New Radio (NR) system supports a larger transmission bandwidth, more transmit and receive antenna arrays, a higher transmission rate, and a more flexible and fine-grained scheduling mechanism. These features of the NR system provide a wider range of applications.

[0003] Network security is a critical feature of fifth-generation mobile communications (5G). 5G defines a unique authentication and key agreement (AKA) protocol for radio resource control (RRC) connections in 2C scenarios. 5G AKA provides bidirectional authentication and data encryption. Bidirectional authentication involves both the network device authenticating the terminal device and the terminal device authenticating the network device.

[0004] However, in some scenarios, such as 2B scenarios, in order to reduce power consumption on the terminal device side, an RRC connection is usually not required between the terminal device and the network device. For scenarios without an RRC connection, authentication cannot be performed between the terminal device and the network device. Summary of the Invention

[0005] The present application provides an authentication method and related equipment. In a scenario where no RRC connection is established between a terminal device and a network device, the terminal device and the network device can transmit the information required for authentication through a public channel, thereby realizing authentication between the terminal device and the network device.

[0006] The first aspect of the present application provides an authentication method, in which: a network device receives a session request sent by a terminal device on an uplink common channel, wherein the session request is used to request the network device to authenticate the terminal device; the network device confirms that the terminal device has passed the authentication based on the session request; the network device sends a session response to the terminal device on a downlink common channel, wherein the session response is used to instruct the terminal device to authenticate the network device.

[0007] The present application provides an authentication method. First, a network device receives a session request sent by a terminal device on an uplink common channel. The network device can confirm that the terminal device has passed authentication based on the session request. Then, the network device sends a session response to the terminal device on a downlink common channel. The session response is used to instruct the terminal device to authenticate the network device. In a scenario where an RRC connection is not established between the terminal device and the network device, the terminal device and the network device can transmit the information required for authentication through a common channel, thereby achieving authentication between the terminal device and the network device.

[0008] In a possible implementation manner of the first aspect, the session request includes a hidden user identity (SUCI) and a first response parameter.

[0009] In this possible implementation, the types of parameters that may be included in the session request are provided, thereby improving the feasibility of the solution.

[0010] In a possible implementation of the first aspect, the network device includes an access and mobility management function AMF and an authentication service function AUSF; the network device confirms, according to the session request, that the terminal device is authenticated, including: the AMF sends a first authentication request to the AUSF, where the first authentication request includes the SUCI, the first response parameter, and the first random parameter received by the terminal device; the AUSF confirms, according to the first authentication request, that the terminal device is authenticated; the AUSF sends a first authentication response to the AMF, where the first authentication response includes a second random parameter, a second response parameter, an authentication token AUTN, and a security anchor function key Kseaf; and the AMF confirms, according to the first authentication response, that the terminal device is authenticated.

[0011] In this possible implementation, the network device uses a two-step method to authenticate the terminal device, embeds the authentication process into the session establishment process, and completes the authentication using a pair of messages used by the session establishment on the air interface. This method requires less information exchange, simplifies the authentication process, and is more conducive to power saving for the terminal device.

[0012] In a possible implementation of the first aspect, the network device includes a unified data management function UDM, and the AUSF confirms that the terminal device has passed authentication based on the first authentication request, including: the AUSF sends a first request message to the UDM based on the first authentication request, the first request message includes a first random parameter and SUCI, and the first request message is used to instruct the UDM to send an authentication vector to the AUSF; the AUSF receives the authentication vector sent by the UDM, the authentication vector includes the second random parameter, a third response parameter, an encryption key CK, an integrity key IK and the AUTN; the AUSF determines that the terminal device has passed authentication based on the authentication vector.

[0013] In this possible implementation, the network device uses a two-step method to authenticate the terminal device, embeds the authentication process into the session establishment process, and completes the authentication using a pair of messages used by the session establishment on the air interface. This method requires less information exchange, simplifies the authentication process, and is more conducive to power saving for the terminal device.

[0014] In a possible implementation manner of the first aspect, the session response includes the second random parameter, AUTN, and configuration information, where the configuration information is used to indicate the terminal device configuration and the session between the terminal device and the network device.

[0015] In this possible implementation, the types of parameters that may be included in the session response are provided, thereby improving the feasibility of the solution.

[0016] In a possible implementation manner of the first aspect, the session request includes the SUCI.

[0017] In this possible implementation, the types of parameters that may be included in the session request are provided, thereby improving the feasibility of the solution.

[0018] In a possible implementation of the first aspect, the network device confirms that the terminal device has passed authentication based on the session request, including: the network device sends a second authentication request to the terminal device based on the session request, and the second authentication request is used to instruct the terminal device to authenticate the network device; the network device receives a second authentication response sent by the terminal device; and the network device confirms that the terminal device has passed authentication based on the second authentication response.

[0019] In this possible implementation, the authentication process between the terminal device and the network device can be realized by simply modifying or not modifying the existing UDM and AUSF algorithms or processes. The modification of the existing network equipment is small and the impact on the 2C network is relatively small.

[0020] The second aspect of the present application provides an authentication method, in which: a terminal device sends a session request to a network device on an uplink common channel, wherein the session request is used to request the network device to authenticate the terminal device; the terminal device receives a session response sent by the network device on a downlink common channel, wherein the session response is used to instruct the terminal device to authenticate the network device.

[0021] The present application provides an authentication method. In a scenario where no RRC connection is established between a terminal device and a network device, the terminal device and the network device can transmit the information required for authentication through a public channel, thereby realizing authentication between the terminal device and the network device.

[0022] In a possible implementation manner of the second aspect, the session response includes configuration information, where the configuration information is used to instruct the terminal device to configure a session with the network device.

[0023] In a possible implementation manner of the second aspect, the session response further includes an authentication parameter, and the method further includes: the terminal device authenticating the network device according to the authentication parameter.

[0024] A third aspect of the present application provides a network device, which includes a processor, the processor is coupled to a memory, the memory is used to store computer programs or instructions, and the processor is used to execute the computer programs or instructions in the memory, so that the method in the first aspect or any possible implementation of the first aspect is executed.

[0025] In a fourth aspect, the present application provides a terminal device, which includes a processor coupled to a memory, the memory being used to store computer programs or instructions, and the processor being used to execute the computer programs or instructions in the memory, so that the method in the second aspect or any possible implementation of the second aspect is executed.

[0026] In a fifth aspect, the present application provides a computer-readable storage medium storing a program, which enables the method in the above-mentioned first aspect or any possible implementation of the first aspect to be executed.

[0027] In a sixth aspect, the present application provides a computer-readable storage medium storing a program, which enables the method in the above-mentioned second aspect or any possible implementation of the second aspect to be executed.

[0028] In a seventh aspect, the present application provides a computer program product storing one or more computer-executable instructions. When the computer-executable instructions are executed by the processor, the method of the above-mentioned first aspect or any possible implementation of the first aspect is executed.

[0029] In an eighth aspect, the present application provides a computer program product storing one or more computer-executable instructions. When the computer-executable instructions are executed by the processor, the method of the above-mentioned second aspect or any possible implementation of the second aspect is executed.

[0030] In a ninth aspect of the present application, a chip system is provided, which includes a processor for supporting a terminal device or a network device to implement the functions involved in the above aspects, such as sending or processing the data and / or information involved in the above methods. In one possible design, the chip system also includes a memory, which is used to store necessary program instructions and data. The chip system can be composed of a chip or a chip and other discrete devices.

[0031] It can be seen from the above technical solutions that the embodiments of the present application have the following advantages:

[0032] The present application provides an authentication method and related devices. First, a network device receives a session request sent by a terminal device on an uplink common channel. The network device can confirm that the terminal device has passed authentication based on the session request. Then, the network device sends a session response to the terminal device on a downlink common channel. The session response is used to instruct the terminal device to authenticate the network device. In a scenario where no RRC connection is established between the terminal device and the network device, the terminal device and the network device can transmit the information required for authentication through a common channel, thereby achieving authentication between the terminal device and the network device. BRIEF DESCRIPTION OF THE DRAWINGS

[0033] Figure 1 A schematic diagram of an embodiment of an RRC connection-based authentication method provided in this application;

[0034] Figure 2 Schematic diagram of the application scenario of the authentication system provided for this application;

[0035] Figure 3 A schematic diagram of an embodiment of the authentication method provided by this application;

[0036] Figure 4 A schematic diagram of another embodiment of the authentication method provided by this application;

[0037] Figure 5 A schematic diagram of another embodiment of the authentication method provided by this application;

[0038] Figure 6 A schematic diagram of the structure of the network device provided in this application;

[0039] Figure 7 A schematic diagram of the structure of the terminal device provided in this application;

[0040] Figure 8 A schematic diagram of the structure of the communication device provided in this application;

[0041] Figure 9 This is another structural diagram of the communication device provided in this application. DETAILED DESCRIPTION

[0042] The following will be combined with the accompanying drawings in the embodiments of the present invention to clearly and completely describe the technical solutions in the embodiments of the present invention. Obviously, the embodiments described are only part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art are within the scope of protection of the present invention.

[0043] The terms "first," "second," "third," "fourth," and so forth (if any) in the description and claims of the present invention and the accompanying drawings are used to distinguish similar objects and are not necessarily used to describe a particular order or sequential sequence. It should be understood that the terms used in this manner are interchangeable where appropriate, so that the embodiments described herein can be implemented in an order other than that shown or described herein.

[0044] In the embodiments of this application, words such as "exemplary" or "for example" are used to indicate examples, illustrations, or descriptions. Any embodiment or design described as "exemplary" or "for example" in the embodiments of this application should not be construed as being preferred or advantageous over other embodiments or designs. Rather, the use of words such as "exemplary" or "for example" is intended to present the relevant concepts in a concrete manner to facilitate understanding.

[0045] “And / or” in this application is only a description of the association relationship of associated objects, indicating that there can be three relationships. For example, A and / or B can mean: A exists alone, A and B exist at the same time, and B exists alone, where A and B can be singular or plural. Moreover, in the description of this application, unless otherwise specified, “multiple” means two or more than two. “At least one of the following items” or similar expressions refers to any combination of these items, including any combination of single items or plural items. For example, at least one of a, b, or c can mean: a, b, c, ab, ac, bc, or abc, where a, b, c can be single or multiple.

[0046] The technical solutions of the embodiments of the present application can be applied to various communication systems, such as: long term evolution (LTE) system, LTE frequency division duplex (FDD) system, LTE time division duplex (TDD) system, fifth generation (5G) system, namely new radio (NR) and future mobile communication systems.

[0047] The 3rd Generation Partnership Project (3GPP) standards organization developed the protocol standard for the fifth-generation cellular mobile communication system. Compared with the long-term evolution (LTE) system, the New Radio (NR) system supports a larger transmission bandwidth, more transmit and receive antenna arrays, a higher transmission rate, and a more flexible and fine-grained scheduling mechanism. These features of the NR system provide a wider range of applications.

[0048] Network security is a critical feature of 5G. For radio resource control (RRC) connections in 2C scenarios, 5G defines a unique authentication and key agreement (AKA) protocol. 5G AKA provides bidirectional authentication and data encryption. Bidirectional authentication involves both the network device authenticating the terminal device and the terminal device authenticating the network device.

[0049] Figure 1 This is a schematic diagram of an embodiment of an authentication method based on RRC connection provided by this application.

[0050] In the embodiment of the present application, the process for establishing communication between a terminal device and a network device consists of three parts: the RACH access process, the RRC establishment process, and the 5G AKA authentication process. First, the terminal device initiates a random access request to the access network device, and the terminal device receives a random access response from the access network device. After the terminal device confirms that the random access is successful based on the random access response, the terminal device sends an RRC establishment request to the access network device. After the terminal device receives the RRC establishment response from the access network device and confirms that the RRC establishment is successful based on the RRC establishment response, it begins the 5G AKA authentication process. The 5G AKA authentication process is described in detail below.

[0051] In this application, after the RRC connection is established between the terminal device and the access network device, subsequent air interface information is transmitted through the uplink physical uplink shared channel (PUSCH) and the downlink physical downlink shared channel (PDSCH). Here we only describe the authentication process.

[0052] In the present application, the network device may be a core network device, and the network device may include an access and mobility management function (AMF), an authentication server function (AUSF) and a unified data management function (UDM). The terminal device initiates a registration request to the AMF through the access network device. The registration request includes a subscription concealed identifier (SUCI). After the AMF finds that the registration request is an initial registration request, the AMF requests authentication from the AUSF. After receiving the authentication request, the AUSF requests an authentication vector from the UDM. The UDM generates an authentication vector and returns it to the AUSF. The AUSF converts the 5-tuple authentication vector into a 4-tuple authentication vector and sends it to the AMF. The AMF generates a random number (RAND number, RAND) and an authentication token (AUthentication TokeN, AUTN) based on the 4-tuple authentication vector, and sends the generated RAND and AUTN to the terminal device, where the AUTN includes MAC data. The terminal device obtains MAC data based on AUTN and calculates whether the XMAC data is consistent with the MAC data. If they are consistent, the network device is considered to have passed the authentication. If they are inconsistent, the network device is considered to have failed the authentication. After the authentication is passed, the response parameter (RES*) is calculated and the response parameter (RES*) is sent to the AMF in the authentication response. The AMF calculates the hash response parameter (HRES*) based on RES* and determines whether HRES* is consistent with the expected hash response parameter (HXRES*) to authenticate the terminal device. If they are consistent, the authentication is passed. If they are inconsistent, the authentication fails. After the AMF successfully authenticates the terminal device, the AMF sends the authentication information including RES* to the AUSF for secondary authentication. The AUSF compares whether RES* is consistent with the expected response (XRES*) to authenticate the terminal device for the second time. If they are consistent, the authentication is passed. If they are inconsistent, the authentication fails. After the AUSF successfully authenticates the terminal device, the AUSF returns the authentication success information to the AMF.

[0053] However, in some scenarios, such as 2B scenarios, in order to reduce power consumption on the terminal device side, an RRC connection is usually not required between the terminal device and the network device. For scenarios without an RRC connection, authentication cannot be performed between the terminal device and the network device.

[0054] In a scenario where there is no RRC connection between a terminal device and a network device, the present application provides an authentication method and related devices. First, the network device receives a session request sent by the terminal device on an uplink common channel. The network device can confirm that the terminal device has passed authentication based on the session request. Then, the network device sends a session response to the terminal device on a downlink common channel. The session response is used to instruct the terminal device to authenticate the network device. In a scenario where there is no RRC connection established between the terminal device and the network device, the terminal device and the network device can transmit the information required for authentication through a common channel, thereby achieving authentication between the terminal device and the network device.

[0055] Figure 2 Schematic diagram of the application scenario of the authentication system provided in this application.

[0056] See also Figure 2 In the embodiment of the present application, the network device, the wireless access network and the terminal device constitute an authentication system.

[0057] The authentication system provided by the present application includes: a network device 101, a radio access network (RAN) 102, RAN 103 and RAN 104, and terminal devices 105, 106, 107 and 108. Among them, the network device 101 includes AMF 109, AUSF 110 and UDM 111,

[0058] Among them, terminal device 105 and terminal device 106 interact with AMF109 included in network device 101 through RAN102, terminal device 107 interacts with AMF109 included in network device 101 through RAN103, terminal device 108 interacts with AMF109 included in network device 101 through RAN104, AMF109 interacts with AUSF110, and AUSF110 interacts with UDM111.

[0059] In the embodiment of the present application, only one network device, three RANs and four terminal devices are used as an example for schematic illustration. In actual application, the application scenario of the embodiment of the present application may optionally include more than Figure 2 The embodiments shown provide more or fewer RANs and terminal devices. The embodiments of the present application do not limit the number of network devices, RANs, and terminal devices.

[0060] The network device 101 in the embodiment of the present application can be a core network device. Optionally, AMF, AUSF and UDM can be integrated on the same device, or AMF, AUSF and UDM can be integrated on different devices. The specific details are not limited here.

[0061] In this application, RAN is used to transmit information exchanged between network devices and terminal devices, and its role in the authentication process is basically to transparently transmit information.

[0062] In this application, AMF is used to initiate the authentication process inside the network device, process the authentication message of the terminal device, obtain the authentication vector from AUSF, authenticate the terminal device, and generate the encryption key.

[0063] In this application, AUSF is used to communicate with UDM, obtain the authentication vector from UDM, process the authentication vector and pass it to AMF to authenticate the terminal device.

[0064] In this application, UDM is used to store account opening information and user keys, and generate authentication vectors.

[0065] The terminal device in the embodiments of the present application can be a device that provides voice and / or data connectivity to a user, a handheld device with wireless connection function, or other processing equipment connected to a wireless modem. The terminal device can be a mobile terminal, such as a mobile phone (or "cellular" phone) and a computer with a mobile terminal, for example, a portable, pocket-sized, handheld, computer-built-in or vehicle-mounted mobile device that exchanges language and / or data with a network device. For example, personal communication service (PCS) phones, cordless phones, session initiation protocol (SIP) phones, wireless local loop (WLL) stations, personal digital assistants (PDAs), and other devices. The terminal device may also be referred to as a system, a subscriber unit, a subscriber station, a mobile station, a mobile station, a remote station, an access point, a remote terminal, an access terminal, a user agent, a user device, or user equipment, a user station, a remote station, a user terminal (TE), a terminal, a wireless communication device, and a user agent or user equipment. In addition, the terminal device may also be a chip system for implementing UE functions. Specific limitations are not made here.

[0066] based on Figure 2 The authentication system described describes the authentication method provided by this application.

[0067] Figure 3 This is a schematic diagram of an embodiment of the authentication method provided by this application. Figure 3 , the authentication method includes steps 201 to 203.

[0068] 201. The network device receives a session request sent by the terminal device on an uplink common channel. Correspondingly, the terminal device sends a session request to the network device on the uplink common channel.

[0069] In this application, there is no RRC connection established between the terminal device and the network device, and the terminal device and the network device cannot exchange information through a dedicated channel. Therefore, the terminal device sends a session request to the network device through an uplink public channel. The session request is used to request the network device to authenticate the terminal device.

[0070] 202. The network device confirms that the terminal device has passed authentication according to the session request.

[0071] In the present application, the session request includes authentication parameters, and the network device can authenticate the terminal device based on the authentication parameters included in the session request.

[0072] 203. The network device sends a session response to the terminal device on the downlink common channel. Correspondingly, the terminal device receives the session response sent by the network device on the downlink common channel.

[0073] In this application, no RRC connection is established between the terminal device and the network device, and information exchange between the terminal device and the network device cannot be achieved through a dedicated channel. Therefore, the network device sends a session response to the terminal device through a downlink public channel, and the session response is used to instruct the terminal device to authenticate the network device.

[0074] In this application, the above Figure 3 In the embodiment shown, step 202 has a specific implementation method, which will be described in detail below.

[0075] Method 1: Two-step authentication

[0076] Figure 4 This is a schematic diagram of another embodiment of the authentication method provided by this application. Figure 4 In this embodiment, the network device may be a core network device, the network device includes AMF, AUSF and UDM, and the session request includes SUCI and a first response parameter (RES*).

[0077] The AMF sends the first authentication request to the AUSF.

[0078] In this embodiment, the first authentication request includes the SUCI, RES*, and the R0 received by the terminal device. R0 is generated by the network device and periodically updated by the network device. After receiving R0, the terminal device can calculate RES* based on R0 and the account opening key, and then include RES* and SUCI in a session request, which is sent to the AMF via the RAN.

[0079] The AUSF sends first request information to the UDM according to the first authentication request.

[0080] In this embodiment, the first request information includes R0 and SUCI, and the first request information is used to instruct the UDM to send an authentication vector to the AUSF.

[0081] The AUSF receives the authentication vector sent by the UDM.

[0082] In this application, the authentication vector includes a second random parameter (R1), an expected response (eXpected RESponse, XRES), an encryption key (encryption key, CK), an integrity key (integrity key, IK) and an authentication token (aUthentication TokeN, AUTN). The UDM receives a first request message, which includes R0 and SUCI. The UDM generates an authentication vector based on R0, R1 and the key for opening an account for the terminal, and sends the authentication vector to the AUSF. The algorithm is similar to that of 5G AKA. When the terminal device calculates relevant parameters such as RES*, it uses R0 to perform the calculation. The UDM uses R0 to calculate XRES, and uses R1 to calculate CK, IK, and AUTN.

[0083] The AUSF determines that the terminal device has passed authentication based on the authentication vector.

[0084] In this application, the AUSF determines the consistency of RES* and XRES to authenticate the terminal device. If RES* and XRES are consistent, the AUSF confirms that the terminal device has passed authentication. If RES* and XRES are inconsistent, the terminal device is confirmed to have failed authentication. After confirming that the terminal device has passed authentication, the AUSF sends a first authentication response to the AMF.

[0085] The AUSF sends a first authentication response to the AMF.

[0086] In the present application, the first authentication response includes a second random parameter (R1), a hashed expected response (hash eXpectedRESponse, HXRES*), AUTN and a security anchor function key (key for SEAF, Kseaf).

[0087] The AMF confirms that the terminal device has passed the authentication based on the first authentication response.

[0088] In this application, AMF calculates HRES* through RES*, determines whether HRES* is consistent with HXRES*, and authenticates the terminal device. If AMF confirms that HRES* is consistent with HXRES*, AMF confirms that the terminal device has passed the authentication. If AMF confirms that HRES* is inconsistent with HXRES*, AMF confirms that the terminal device has not passed the authentication. After the authentication is passed, AMF allocates a session ID, allocates uplink service channel resources, and calculates the NAS encryption key (key for NAS encryption, Knasenc) and NAS integrity key (keyfor NAS integrity, Knasint). The allocated session ID and uplink service channel resource data are encrypted and integrity protected using the key, and the encrypted data (session ID and service channel resources) and R1, AUTN are sent to the terminal device through RAN.

[0089] In this application, after the network device confirms that the terminal device has passed authentication, the network device uses a session ID (Session Id) to identify the user during the process of conducting business with the terminal device, rather than a subscription permanent identifier (SUPI).

[0090] In this application, the encrypted data of the service includes a message sequence number. The AMF needs to determine whether the message sequence number is incremented to prevent service data replay attacks. To prevent session request replay attacks, in addition to the periodic update of R0, the AMF also needs to save the assigned Session ID and SUCI, as well as the corresponding RES* and key information. If the SUCI has already been assigned a Session ID, the process of requesting the authentication vector from the UDM will not be triggered again. Instead, the previously assigned data will be directly encrypted and sent to the terminal.

[0091] In this application, in order to avoid the Session ID not being updated for a long time and thus reducing system security, a field can be added to the broadcast system message to indicate whether the terminal should re-authenticate and establish a session.

[0092] In this application, if a network device fails during the authentication process, the subsequent process is terminated. The network elements included in the network device can send failure notification messages to each other, but the air interface does not send messages and does not notify the terminal. Similarly, if the terminal device fails to authenticate, it does not notify the core network.

[0093] Method 2: Four-step authentication method

[0094] Figure 5 This is another example of the authentication method provided by this application. Figure 5 In this embodiment, the session request includes SUCI. The network devices include AMF, AUSF and UDM.

[0095] The network device sends a second authentication request to the terminal device according to the session request.

[0096] In this application, after the AMF included in the network device receives a session request, the AMF requests authentication from the AUSF. After receiving the authentication request, the AUSF requests an authentication vector from the UDM. The UDM generates an authentication vector and returns it to the AUSF. The AMF generates a random number (RAND) and an authentication token (AUTN) based on the 4-tuple authentication vector, and carries the generated RAND and AUTN in a second authentication request and sends it to the terminal device. The second authentication request is used to instruct the terminal device to authenticate the network device.

[0097] The network device receives the second authentication response sent by the terminal device.

[0098] In this application, the terminal device obtains AUTN based on the second authentication request, which includes MAC data. The terminal device obtains the MAC data based on the AUTN and calculates whether the XMAC data is consistent with the MAC data. If they are consistent, the network device is considered to have passed authentication. If they are inconsistent, the network device is considered to have failed authentication. After authentication is successful, the terminal device calculates the response parameter (RES*) and sends it to the AMF in the second authentication response.

[0099] The network device confirms that the terminal device has passed the authentication based on the second authentication response.

[0100] In this application, the network device obtains the response parameter (RES*) based on the second authentication response, and the AMF calculates the hash response parameter (HRES*) through RES*, and determines whether HRES* is consistent with the expected hash response parameter (HXRES*) to authenticate the terminal device. If they are consistent, the authentication is passed; if they are inconsistent, the authentication fails. After the AMF successfully authenticates the terminal device, the AMF sends the authentication information including RES* to the AUSF for secondary authentication. The AUSF compares whether RES* is consistent with the expected response (XRES*) to authenticate the terminal device for the second time. If they are consistent, the authentication is passed; if they are inconsistent, the authentication fails. After the AUSF successfully authenticates the terminal device, the AUSF replies with the authentication success information to the AMF.

[0101] In this embodiment, in a scenario where there is no RRC connection between the terminal device and the network device, the information exchanged between the terminal device and the network device is not transmitted through the physical uplink shared channel (PUSCH) and the physical downlink shared channel (PDSCH), but through the uplink access channel and the downlink common control channel.

[0102] The present application provides an authentication method and related devices. First, a network device receives a session request sent by a terminal device on an uplink common channel. The network device can confirm that the terminal device has passed authentication based on the session request. Then, the network device sends a session response to the terminal device on a downlink common channel. The session response is used to instruct the terminal device to authenticate the network device. In a scenario where no RRC connection is established between the terminal device and the network device, the terminal device and the network device can transmit the information required for authentication through a common channel, thereby achieving authentication between the terminal device and the network device.

[0103] The above embodiment provides a different implementation method of an authentication method. The following provides a network device 30, such as Figure 6 As shown, the network device 30 is used to execute the steps executed by the network device in the above embodiment. The execution steps and corresponding beneficial effects are specifically understood with reference to the above corresponding embodiments, and will not be repeated here. The network device 30 includes:

[0104] The receiving unit 301 is configured to receive a session request sent by a terminal device on an uplink common channel, wherein the session request is used to request the network device to authenticate the terminal device;

[0105] A processing unit 302 is configured to confirm that the terminal device is authenticated according to the session request;

[0106] The sending unit 303 is used to send a session response to the terminal device on a downlink common channel, where the session response is used to instruct the terminal device to authenticate the network device.

[0107] In a possible implementation, the session request includes a hidden user identifier SUCI and a first response parameter.

[0108] In one possible implementation, the network device includes an access and mobility management function AMF and an authentication service function AUSF;

[0109] The AMF sends a first authentication request to the AUSF, where the first authentication request includes the SUCI, the first response parameter, and the first random parameter received by the terminal device;

[0110] The AUSF confirms that the terminal device is authenticated according to the first authentication request;

[0111] The AUSF sends a first authentication response to the AMF, where the first authentication response includes a second random parameter, a second response parameter, an authentication token AUTN, and a security anchor function key Kseaf;

[0112] The AMF confirms that the terminal device has passed authentication based on the first authentication response.

[0113] In one possible implementation, the network device includes a unified data management function UDM;

[0114] The AUSF sends a first request message to the UDM according to the first authentication request, where the first request message includes a first random parameter and a SUCI, and the first request message is used to instruct the UDM to send an authentication vector to the AUSF;

[0115] The AUSF receives the authentication vector sent by the UDM, where the authentication vector includes the second random parameter, the third response parameter, the encryption key CK, the integrity key IK, and the AUTN;

[0116] The AUSF determines that the terminal device passes authentication based on the authentication vector.

[0117] In a possible implementation, the session response includes the second random parameter, AUTN, and configuration information, where the configuration information is used to indicate the configuration of the session between the terminal device and the network device.

[0118] In a possible implementation manner, the session request includes the SUCI.

[0119] In one possible implementation,

[0120] The sending unit 303 is further configured to send a second authentication request to the terminal device according to the session request, where the second authentication request is used to instruct the terminal device to authenticate the network device;

[0121] The receiving unit 301 is further configured to receive a second authentication response sent by the terminal device;

[0122] The processing unit 302 is further configured to confirm that the terminal device has passed authentication according to the second authentication response.

[0123] It should be noted that the information interaction, execution process, etc. between the modules of the above-mentioned network device 30 are based on the same concept as the method embodiment of the present application, and the technical effects they bring are the same as those of the method embodiment of the present invention. For specific contents, please refer to the description in the method embodiment shown above in this application, and no further details will be given here.

[0124] The above embodiment provides a different implementation of a network device 30. The following provides a terminal device 40, such as Figure 7 As shown, the terminal device 40 is used to execute the steps executed by the terminal device in the above embodiment. The execution steps and corresponding beneficial effects are specifically understood with reference to the above corresponding embodiments, and are not repeated here. The terminal device 40 includes:

[0125] A sending unit 401 is configured to send a session request to a network device on an uplink common channel, wherein the session request is used to request the network device to authenticate the terminal device;

[0126] The receiving unit 402 is configured to receive a session response sent by the network device on a downlink common channel, where the session response is used to instruct the terminal device to authenticate the network device.

[0127] In a possible implementation, the session response includes configuration information, where the configuration information is used to indicate the configuration of the session between the terminal device and the network device.

[0128] In a possible implementation, the session response further includes an authentication parameter; and the processing unit is configured to authenticate the network device according to the authentication parameter.

[0129] It should be noted that the information interaction, execution process, etc. between the modules of the above-mentioned terminal device 40 are based on the same concept as the method embodiment of the present application, and the technical effects they bring are the same as those of the method embodiment of the present invention. For specific contents, please refer to the description in the method embodiment shown above in this application, and no further details will be given here.

[0130] See Figure 8As shown, a schematic diagram of the structure of a communication device 50 is provided in an embodiment of the present application. The communication device 50 includes: a processor 502, a communication interface 503, a memory 501 and a bus 504. The communication interface 503, the processor 502 and the memory 501 are interconnected via a bus 504; the bus 504 can be a Peripheral Component Interconnect (PCI) bus or an Extended Industry Standard Architecture (EISA) bus. The bus can be divided into an address bus, a data bus, a control bus, etc. For ease of representation, Figure 8 The communication device 50 can be implemented by using only one thick line. Figure 6 The functions of the network devices in the embodiment shown or Figure 7 Functions of the terminal device in the illustrated embodiment. The communication interface 503 can perform the corresponding functions of the receiving unit and the sending unit in the network device or terminal device in the above method example, and the processor 502 can perform the functions performed by the processing unit included in the network device or terminal device in the above method embodiment.

[0131] The following combination Figure 7 The components of the communication device 50 are described in detail.

[0132] The processor 502 is the control center of the controller, which can be a central processing unit (CPU), an application specific integrated circuit (ASIC), or one or more integrated circuits configured to implement the embodiments of the present application, such as one or more digital signal processors (DSPs), or one or more field programmable gate arrays (FPGAs).

[0133] The communication interface 503 is used to communicate with other devices.

[0134] The processor 502 may execute the aforementioned Figure 6 The operations performed by the network device 30 in the embodiment shown in the figure may be performed by the processor 502. Figure 7 The operations performed by the terminal device 40 in the illustrated embodiment will not be described in detail here.

[0135] The embodiment of the present application further provides a communication device 60, which can be a terminal device or a chip. The communication device 60 can be used to perform the operations performed by the terminal device in the above method embodiment. When the communication device 60 is a terminal device, Figure 9 The following is a simplified schematic diagram of the terminal device. Figure 9 In this article, the terminal device is a mobile phone. Figure 9 As shown, the terminal device includes a processor, a memory, a radio frequency circuit, an antenna, and input and output devices. The processor is mainly used to process communication protocols and communication data, as well as to control the terminal device, execute software programs, process software program data, etc. The memory is mainly used to store software programs and data. The radio frequency circuit is mainly used to convert baseband signals into radio frequency signals and process radio frequency signals. The antenna is mainly used to transmit and receive radio frequency signals in the form of electromagnetic waves. Input and output devices, such as touch screens, displays, keyboards, etc., are mainly used to receive data input by users and output data to users. It should be noted that some types of terminal devices may not have input and output devices.

[0136] When data needs to be sent, the processor performs baseband processing on the data to be sent and outputs the baseband signal to the RF circuit. The RF circuit performs RF processing on the baseband signal and then transmits the RF signal to the outside in the form of electromagnetic waves through the antenna. When data is sent to the terminal device, the RF circuit receives the RF signal through the antenna, converts the RF signal into a baseband signal, and outputs the baseband signal to the processor. The processor converts the baseband signal into data and processes the data. For the sake of explanation, Figure 9 Only one memory and processor are shown. In actual terminal devices, one or more processors and one or more memories may exist. A memory may also be referred to as a storage medium or storage device. The memory may be independent of the processor or integrated with the processor, and this is not limited in the present embodiment.

[0137] In the embodiment of the present application, the antenna and radio frequency circuit with transceiver functions can be regarded as the transceiver unit of the terminal device, and the processor with processing function can be regarded as the processing unit of the terminal device.

[0138] The terminal device includes a transceiver unit 601 and a processing unit 602. The transceiver unit 601 may also be referred to as a transceiver, a transceiver, a transceiver device, etc. The processing unit 602 may also be referred to as a processor, a processing board, a processing module, a processing device, etc.

[0139] Alternatively, the device in transceiver unit 601 that implements the receiving function may be considered a receiving unit, and the device in transceiver unit 601 that implements the transmitting function may be considered a transmitting unit. That is, transceiver unit 601 includes a receiving unit and a transmitting unit. The transceiver unit may also be sometimes referred to as a transceiver, a transceiver, or a transceiver circuit. The receiving unit may also be sometimes referred to as a receiver, a receiver, or a receiving circuit. The transmitting unit may also be sometimes referred to as a transmitter, a transmitter, or a transmitting circuit.

[0140] For example, in one implementation, the transceiver unit 601 is used to perform a receiving operation of the terminal device, and the processing unit 602 is used to perform a processing action on the terminal device side.

[0141] It should be understood that Figure 9 This is only an example and not a limitation. The terminal device including the transceiver unit and the processing unit may not rely on Figure 9 The structure shown.

[0142] When the communication device 60 is a chip, the chip includes a transceiver unit and a processing unit. The transceiver unit may be an input / output circuit or a communication interface; the processing unit may be a processor, microprocessor, or integrated circuit integrated on the chip. The input circuit may be an input pin, the output circuit may be an output pin, and the processing circuit may be a transistor, a gate circuit, a trigger, or various logic circuits. The input signal received by the input circuit may be, for example, but not limited to, received and input by a receiver, and the signal output by the output circuit may be, for example, but not limited to, output to and transmitted by a transmitter. The input circuit and the output circuit may be different circuits or the same circuit. In this case, the circuit functions as an input circuit and an output circuit at different times.

[0143] It should be noted that the information interaction, execution process, etc. between the modules of the device 60 provided in the above embodiment are based on the same concept as the method embodiment of the present application, and the technical effects they bring are the same as those of the method embodiment of the present invention. For specific contents, please refer to the description in the method embodiment shown above in this application, and no further details will be given here.

[0144] Those skilled in the art will clearly understand that, for the convenience and brevity of description, the specific working processes of the systems, devices and units described above can refer to the corresponding processes in the aforementioned method embodiments and will not be repeated here.

[0145] In the several embodiments provided in this application, it should be understood that the disclosed systems, devices and methods can be implemented in other ways. For example, the device embodiments described above are merely schematic. For example, the division of the units is merely a logical function division. In actual implementation, there may be other division methods, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be an indirect coupling or communication connection through some interfaces, devices or units, which can be electrical, mechanical or other forms.

[0146] The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of these units may be selected to achieve the purpose of this embodiment according to actual needs.

[0147] In addition, the functional units in the various embodiments of the present application may be integrated into a single processing unit, or each unit may exist physically separately, or two or more units may be integrated into a single unit. The aforementioned integrated units may be implemented in the form of hardware or software functional units.

[0148] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application is essentially or the part that contributes to the prior art or all or part of the technical solution can be embodied in the form of a software product, and the computer software product is stored in a storage medium, including a number of instructions for enabling a computer device (which can be a personal computer, server, or network device, etc.) to execute all or part of the steps of the method described in each embodiment of the present application. The aforementioned storage medium includes: U disk, mobile hard disk, read-only memory (ROM, read-only memory), random access memory (RAM, random access memory), disk or optical disk, and other media that can store program code.

Claims

1. An authentication method, characterized in that: include: The network device receives a session request sent by the terminal device on an uplink common channel, wherein the session request is used to request the network device to authenticate the terminal device; The network device confirms that the terminal device is authenticated according to the session request; The network device sends a session response to the terminal device on a downlink common channel, where the session response is used to instruct the terminal device to authenticate the network device; The network device includes an access and mobility management function AMF and an authentication service function AUSF, and the network device confirms that the terminal device is authenticated according to the session request, including: the AMF sends a first authentication request to the AUSF, where the first authentication request is obtained based on the session request; the AUSF confirms that the terminal device is authenticated according to the first authentication request; the AUSF sends a first authentication response to the AMF; and the AMF confirms that the terminal device is authenticated according to the first authentication response. Alternatively, the network device confirms that the terminal device has passed authentication based on the session request, including: the network device sends a second authentication request to the terminal device based on the session request, and the second authentication request is used to instruct the terminal device to authenticate the network device; the network device receives a second authentication response sent by the terminal device; the network device confirms that the terminal device has passed authentication based on the second authentication response.

2. The authentication method according to claim 1, wherein: When the AMF confirms that the terminal device is authenticated according to the first authentication response, the session request includes a hidden user identity (SUCI) and a first response parameter.

3. The authentication method according to claim 2, wherein: The first authentication request includes the SUCI, the first response parameter, and the first random parameter received by the terminal device, and the first authentication response includes a second random parameter, a second response parameter, an authentication token AUTN, and a security anchor function key Kseaf.

4. The authentication method according to claim 3, wherein: The network device includes a unified data management function (UDM), and the AUSF confirms, according to the first authentication request, that the terminal device passes authentication, including: The AUSF sends a first request message to the UDM according to the first authentication request, where the first request message includes a first random parameter and a SUCI, and the first request message is used to instruct the UDM to send an authentication vector to the AUSF; The AUSF receives the authentication vector sent by the UDM, where the authentication vector includes the second random parameter, the third response parameter, the encryption key CK, the integrity key IK, and the AUTN; The AUSF determines that the terminal device passes authentication based on the authentication vector.

5. The authentication method according to any one of claims 3 to 4, characterized in that: The session response includes the second random parameter, AUTN and configuration information, and the configuration information is used to indicate the session between the terminal device and the network device.

6. The authentication method according to claim 1, wherein: When the network device confirms that the terminal device has passed the authentication according to the second authentication response, the session request includes a hidden user identity (SUCI).

7. An authentication method, characterized in that: include: The terminal device sends a session request to the network device on an uplink common channel, wherein the session request is used to request the network device to authenticate the terminal device; The terminal device receives a session response sent by the network device on a downlink common channel, where the session response is used to instruct the terminal device to authenticate the network device; The network device includes an access and mobility management function (AMF) and an authentication service function (AUSF), and the network device authenticates the terminal device by: the AMF sends a first authentication request to the AUSF, where the first authentication request is obtained based on the session request; the AUSF confirms that the terminal device is authenticated according to the first authentication request; the AUSF sends a first authentication response to the AMF; and the AMF confirms that the terminal device is authenticated according to the first authentication response. Alternatively, the network device authenticates the terminal device including: the network device sends a second authentication request to the terminal device according to the session request, the second authentication request being used to instruct the terminal device to authenticate the network device; the network device receives a second authentication response sent by the terminal device; the network device confirms that the terminal device has passed the authentication according to the second authentication response.

8. The authentication method according to claim 7, wherein: The session response includes configuration information, where the configuration information is used to indicate the configuration of the session between the terminal device and the network device.

9. The authentication method according to claim 7 or 8, characterized in that: The session response also includes authentication parameters, and the method further includes: The terminal device authenticates the network device according to the authentication parameters.

10. A network device, characterized in that: include: a receiving unit, configured to receive a session request sent by a terminal device on an uplink common channel, wherein the session request is used to request the network device to authenticate the terminal device; a processing unit, configured to confirm that the terminal device is authenticated according to the session request; a sending unit, configured to send a session response to the terminal device on a downlink common channel, wherein the session response is used to instruct the terminal device to authenticate the network device; The network device includes an access and mobility management function AMF and an authentication service function AUSF; the AMF sends a first authentication request to the AUSF, where the first authentication request is obtained based on the session request; The AUSF confirms that the terminal device is authenticated according to the first authentication request; the AUSF sends a first authentication response to the AMF; the AMF confirms that the terminal device is authenticated according to the first authentication response; Alternatively, the sending unit is further used to send a second authentication request to the terminal device according to the session request, and the second authentication request is used to instruct the terminal device to authenticate the network device; the receiving unit is further used to receive a second authentication response sent by the terminal device; the processing unit is further used to confirm that the terminal device has passed the authentication based on the second authentication response.

11. The network device according to claim 10, wherein: When the AMF confirms that the terminal device is authenticated according to the first authentication response, the session request includes a hidden user identity (SUCI) and a first response parameter.

12. The network device according to claim 11, wherein: The first authentication request includes the SUCI, the first response parameter, and the first random parameter received by the terminal device, and the first authentication response includes a second random parameter, a second response parameter, an authentication token AUTN, and a security anchor function key Kseaf.

13. The network device according to claim 12, wherein: The network device includes a unified data management function UDM; The AUSF sends a first request message to the UDM according to the first authentication request, where the first request message includes a first random parameter and a SUCI, and the first request message is used to instruct the UDM to send an authentication vector to the AUSF; The AUSF receives the authentication vector sent by the UDM, where the authentication vector includes the second random parameter, the third response parameter, the encryption key CK, the integrity key IK, and the AUTN; The AUSF determines that the terminal device passes authentication based on the authentication vector.

14. The network device according to any one of claims 12 to 13, characterized in that: The session response includes the second random parameter, AUTN and configuration information, and the configuration information is used to indicate the session between the terminal device and the network device.

15. The network device according to claim 10, wherein: When the network device confirms that the terminal device has passed the authentication according to the second authentication response, the session request includes a hidden user identity (SUCI).

16. A terminal device, characterized in that: include: a sending unit, configured to send a session request to a network device on an uplink common channel, wherein the session request is used to request the network device to authenticate the terminal device; a receiving unit, configured to receive a session response sent by the network device on a downlink common channel, wherein the session response is used to instruct the terminal device to authenticate the network device; The network device includes an access and mobility management function (AMF) and an authentication service function (AUSF), and the network device authenticates the terminal device by: the AMF sends a first authentication request to the AUSF, where the first authentication request is obtained based on the session request; the AUSF confirms that the terminal device is authenticated according to the first authentication request; the AUSF sends a first authentication response to the AMF; and the AMF confirms that the terminal device is authenticated according to the first authentication response. Alternatively, the network device authenticates the terminal device including: the network device sends a second authentication request to the terminal device according to the session request, the second authentication request being used to instruct the terminal device to authenticate the network device; the network device receives a second authentication response sent by the terminal device; the network device confirms that the terminal device has passed the authentication according to the second authentication response.

17. The terminal device according to claim 16, characterized in that The session response includes configuration information, where the configuration information is used to indicate the configuration of the session between the terminal device and the network device.

18. The terminal device according to claim 16 or 17, characterized in that: The session response also includes authentication parameters; A processing unit is used to authenticate the network device according to the authentication parameter.

19. A communication device, characterized in that: The invention comprises a processor coupled to a memory, wherein the memory is used to store a computer program or instructions, and the processor is used to execute the computer program or instructions in the memory, so that: The method of any one of claims 1 to 6 is performed; or The method of any one of claims 7 to 9 is performed.

20. A computer-readable storage medium, characterized in that The computer-readable storage medium stores instructions, which, when executed on a computer, cause: The method according to any one of claims 1 to 6 is performed; or The method according to any one of claims 7 to 9 is performed.

Citation Information

Patent Citations

  • GEO satellite Internet of Things authentication method and system

    CN111526503A