A method and apparatus for identity authentication

CN114696999BActive Publication Date: 2026-09-11CHINA IWNCOMM
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202011569237.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2020-12-26
Publication Date
2026-09-11
Estimated Expiration
2040-12-26

AI Technical Summary

Technical Problem

[0004]若在请求设备与鉴别接入控制器的双向身份鉴别过程中,身份信息被攻击者截获用于非法用途,则会对鉴别接入控制器、请求设备及网络造成极大的安全隐患

Benefits of technology

[0038] As can be seen from the above technical solutions, keeping the identity information of the requesting device and the authentication access controller confidential can prevent their exposure during transmission, ensuring that attackers cannot obtain private and sensitive information. Furthermore, by introducing an authentication server, while ensuring the confidentiality of entity identity-related information, real-time two-way authentication between the requesting device and the authentication access controller is achieved, laying the foundation for ensuring that only legitimate users can communicate with legitimate networks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114696999B_ABST
    Figure CN114696999B_ABST
Patent Text Reader

Abstract

The embodiment of the application discloses an identity authentication method, which performs secret processing on identity information of a request device and an authentication access controller, prevents the identity information of the request device and the authentication access controller from being exposed in a transmission process, and ensures that an attacker cannot obtain the private and sensitive information. Moreover, by introducing an authentication server, real-time authentication of bidirectional identities between the request device and the authentication access controller is realized while ensuring the confidentiality of entity identity related information.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of network communication security technology, and in particular to an identity authentication method and apparatus. Background Technology

[0002] In communication networks, a requesting device can access the network through an authentication access controller. In situations with high security requirements, the authentication access controller needs to authenticate the requesting device, and the requesting device also needs to authenticate the authentication access controller to ensure that the requesting device is a legitimate user and that the network it is accessing is legitimate. Furthermore, peer-to-peer transmission in blockchain technology also requires establishing trust relationships between different nodes; therefore, node authentication is also crucial.

[0003] During the two-way authentication process between the requesting device and the authentication access controller, both parties must provide their own identity information for authentication. However, this identity information typically carries private and sensitive information, such as ID card numbers, home addresses, bank card information, geographical location information, and affiliated organization information. Furthermore, in practical applications, this identity information is usually contained within the entity's digital certificate, which serves as the entity's identity credential.

[0004] If the identity information is intercepted by an attacker and used for illegal purposes during the two-way authentication process between the requesting device and the authentication access controller, it will pose a significant security risk to the authentication access controller, the requesting device, and the network. Summary of the Invention

[0005] To address the aforementioned technical issues, this application provides an identity authentication method and apparatus. By introducing an authentication server, the confidentiality of entity identity-related information is ensured while enabling real-time bidirectional identity authentication between the requesting device and the authentication access controller.

[0006] In a first aspect, embodiments of this application provide an identity authentication method, including:

[0007] The authentication access controller obtains the identity encrypted message sent by the requesting device. The identity encrypted message includes the identity information encrypted of the requesting device. The identity information encrypted of the requesting device is generated by encrypting encrypted data, including the digital certificate of the requesting device, using a message encryption key.

[0008] The authentication access controller sends a first authentication request message to a first authentication server it trusts. The first authentication request message includes the ciphertext of the authentication access controller's identity information and the digital certificate of the requesting device. The ciphertext of the authentication access controller's identity information is generated by encrypting encrypted data, including the digital certificate of the authentication access controller, using the public key of the encryption certificate. The digital certificate of the requesting device is obtained by the authentication access controller by decrypting the ciphertext of the requesting device's identity information using the message encryption key.

[0009] The authentication access controller receives a first authentication response message sent by the first authentication server. The first authentication response message includes a first authentication result information ciphertext, a first digital signature, a second authentication result information, and a second digital signature. The first authentication result information ciphertext is obtained by encrypting information including the first authentication result information. The first authentication result information includes a first verification result of the digital certificate of the authentication access controller. The first digital signature is a digital signature calculated by the second authentication server trusted by the requesting device on signature data including the first authentication result information ciphertext. The second authentication result information includes a second verification result of the digital certificate of the requesting device. The second digital signature is a digital signature calculated by the first authentication server on signature data including the second authentication result information.

[0010] The authentication access controller verifies the second digital signature using the public key of the first authentication server. If the verification passes, the authentication access controller determines the authentication result of the requesting device based on the second verification result in the second authentication result information. When the authentication access controller determines that the authentication result of the requesting device is valid, it sends a third authentication response message to the requesting device; or...

[0011] The authentication access controller verifies the second digital signature using the public key of the first authentication server. If the verification passes, the authentication access controller sends a third authentication response message to the requesting device and determines the authentication result of the requesting device based on the second verification result in the second authentication result information; or,

[0012] The authentication access controller uses the public key of the first authentication server to verify the second digital signature; if the second digital signature is verified, the authentication access controller determines the identity authentication result of the requesting device based on the second verification result in the second authentication result information; the authentication access controller sends a third authentication response message to the requesting device.

[0013] The third authentication response message includes ciphertext of authentication result information, which is generated by encrypting encrypted data, including the first ciphertext of authentication result information and the first digital signature, using the message encryption key.

[0014] After receiving the third authentication response message, the requesting device decrypts the ciphertext of the authentication result information using the message encryption key to obtain the first ciphertext of the authentication result information and the first digital signature. The requesting device verifies the first digital signature using the public key of the second authentication server. If the verification is successful, the requesting device determines the identity authentication result of the authentication access controller based on the first verification result in the first authentication result information obtained by decrypting the first ciphertext of the authentication result information.

[0015] Secondly, embodiments of this application provide an authentication access controller, including:

[0016] The acquisition unit is used to acquire the identity ciphertext message sent by the requesting device. The identity ciphertext message includes the identity information ciphertext of the requesting device, which is generated by encrypting encrypted data, including the digital certificate of the requesting device, using a message encryption key.

[0017] The first sending unit is configured to send a first authentication request message to a first authentication server trusted by the authentication access controller. The first authentication request message includes the ciphertext of the authentication access controller's identity information and the digital certificate of the requesting device. The ciphertext of the authentication access controller's identity information is generated by encrypting encrypted data, including the digital certificate of the authentication access controller, using the public key of the encryption certificate. The digital certificate of the requesting device is obtained by the authentication access controller by decrypting the ciphertext of the requesting device's identity information using the message encryption key.

[0018] The first receiving unit is configured to receive a first authentication response message sent by the first authentication server. The first authentication response message includes first authentication result information ciphertext, a first digital signature, second authentication result information, and a second digital signature. Specifically, the first authentication result information ciphertext is obtained by encrypting information including the first authentication result information; the first authentication result information includes a first verification result of the digital certificate of the authentication access controller; the first digital signature is a digital signature calculated by the second authentication server trusted by the requesting device on signature data including the first authentication result information ciphertext; the second authentication result information includes a second verification result of the digital certificate of the requesting device; and the second digital signature is a digital signature calculated by the first authentication server on signature data including the second authentication result information.

[0019] A first verification unit is used to verify the second digital signature using the public key of the first authentication server. If the verification passes, a first determining unit determines the authentication result of the requesting device based on the second verification result in the second authentication result information. When the first determining unit determines that the authentication result of the requesting device is valid, a second sending unit sends a third authentication response message to the requesting device; or...

[0020] The second sending unit verifies the second digital signature using the public key of the first authentication server. If the verification passes, the second sending unit sends a third authentication response message to the requesting device, and the first determining unit determines the authentication result of the requesting device based on the second verification result in the second authentication result information; or...

[0021] The first unit is used to verify the second digital signature using the public key of the first authentication server; if the second digital signature is verified, the first determining unit determines the identity authentication result of the requesting device based on the second verification result in the second authentication result information; the second sending unit sends a third authentication response message to the requesting device.

[0022] The third authentication response message includes ciphertext of authentication result information, which is generated by encrypting encrypted data, including the first ciphertext of authentication result information and the first digital signature, using the message encryption key.

[0023] Thirdly, embodiments of this application provide a requesting device, including:

[0024] The sending unit is used to send an identity ciphertext message to the authentication access controller. The identity ciphertext message includes the identity information ciphertext of the requesting device. The identity information ciphertext of the requesting device is generated by encrypting encrypted data, including the digital certificate of the requesting device, using a message encryption key.

[0025] The first receiving unit is configured to receive a third authentication response message sent by the authentication access controller. The third authentication response message includes ciphertext of authentication result information, which is generated by encrypting encrypted data including the first authentication result information and the first digital signature using a message encryption key. The first authentication result information is obtained by encrypting information including the first authentication result information, which includes a first verification result of the digital certificate of the authentication access controller.

[0026] The first decryption unit is used to decrypt the ciphertext of the authentication result information using the message encryption key to obtain the first ciphertext of the authentication result information and the first digital signature;

[0027] The first verification unit is used to verify the first digital signature using the public key of the second authentication server;

[0028] The first determining unit is configured to determine the identity authentication result of the authentication access controller based on the first verification result in the first authentication result information obtained by decrypting the ciphertext of the first authentication result information when the first digital signature verification is successful.

[0029] Fourthly, embodiments of this application provide a first authentication server, which is an authentication server trusted by the authentication access controller, comprising:

[0030] The first receiving unit is configured to receive a first authentication request message sent by the authentication access controller. The first authentication request message includes the ciphertext of the authentication access controller's identity information and the digital certificate of the requesting device. The ciphertext of the authentication access controller's identity information is generated by encrypting encrypted data, including the digital certificate of the authentication access controller, using the public key of the encryption certificate.

[0031] A first sending unit is configured to send a first authentication response message to the authentication access controller. The first authentication response message includes a first authentication result information ciphertext, a first digital signature, a second authentication result information, and a second digital signature. The first authentication result information ciphertext is obtained by encrypting information including the first authentication result information. The first authentication result information includes a first verification result of the digital certificate of the authentication access controller. The first digital signature is a digital signature calculated by a second authentication server trusted by the requesting device on signature data including the first authentication result information ciphertext. The second authentication result information includes a second verification result of the digital certificate of the requesting device. The second digital signature is a digital signature calculated by the first authentication server on signature data including the second authentication result information.

[0032] Fifthly, embodiments of this application provide a second authentication server, which is an authentication server requesting device trust. If the first authentication server trusted by the authentication access controller and the second authentication server requesting device trust are two different authentication servers, then the second authentication server includes:

[0033] The receiving unit is configured to receive a second authentication request message sent by a first authentication server. The second authentication request message includes encrypted first authentication result information, the digital certificate of the requesting device, and a third digital signature of the first authentication server. The third digital signature is a digital signature calculated and generated by the first authentication server from signature data including the encrypted first authentication result information and the digital certificate of the requesting device.

[0034] The first verification unit is used to verify the third digital signature;

[0035] The second verification unit is used to verify the legality of the digital certificate of the requesting device and obtain a second verification result when the third digital signature verification is successful.

[0036] The generation unit is used to generate second authentication result information based on information including the second verification result.

[0037] The sending unit is configured to send a second authentication response message to the first authentication server. The second authentication response message includes the first authentication result information ciphertext, a first digital signature, the second authentication result information, and a fourth digital signature. The first digital signature is a digital signature calculated and generated by the second authentication server on the signature data including the first authentication result information ciphertext, and the fourth digital signature is a digital signature calculated and generated by the second authentication server on the signature data including the second authentication result information.

[0038] As can be seen from the above technical solutions, keeping the identity information of the requesting device and the authentication access controller confidential can prevent their exposure during transmission, ensuring that attackers cannot obtain private and sensitive information. Furthermore, by introducing an authentication server, while ensuring the confidentiality of entity identity-related information, real-time two-way authentication between the requesting device and the authentication access controller is achieved, laying the foundation for ensuring that only legitimate users can communicate with legitimate networks. Attached Figure Description

[0039] To more clearly illustrate the technical solutions in the embodiments of this application or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0040] Figure 1 A schematic diagram illustrating an identity authentication method provided in an embodiment of this application;

[0041] Figure 2A schematic diagram illustrating a method for requesting a device REQ and negotiating an encryption key for an access controller AAC, provided in an embodiment of this application;

[0042] Figure 3 A schematic diagram illustrating an identity authentication method in a non-roaming situation provided in an embodiment of this application;

[0043] Figure 4 A schematic diagram illustrating another identity authentication method in a non-roaming situation provided in an embodiment of this application;

[0044] Figure 5 A schematic diagram illustrating an identity authentication method in a roaming situation provided in an embodiment of this application;

[0045] Figure 6 A schematic diagram illustrating another identity authentication method in roaming situations provided in an embodiment of this application;

[0046] Figure 7 This is a schematic diagram illustrating another identity authentication method in a non-roaming situation provided in the embodiments of this application, wherein "*" represents an optional field or optional operation;

[0047] Figure 8 This is a schematic diagram illustrating another identity authentication method in a non-roaming situation provided in the embodiments of this application, wherein "*" represents an optional field or optional operation;

[0048] Figure 9 This is a schematic diagram illustrating another identity authentication method in roaming situations provided in the embodiments of this application, where "*" represents an optional field or optional operation;

[0049] Figure 10 This is a schematic diagram illustrating another identity authentication method in roaming situations provided in the embodiments of this application, where "*" represents an optional field or optional operation;

[0050] Figure 11 A structural block diagram of an authentication access controller (AAC) provided in this application embodiment;

[0051] Figure 12 A structural block diagram of a request device REQ provided in an embodiment of this application;

[0052] Figure 13 A structural block diagram of a first authentication server AS-AAC provided in an embodiment of this application;

[0053] Figure 14 This is a structural block diagram of a second authentication server AS-REQ provided in an embodiment of this application. Detailed Implementation

[0054] In a communication network, a requesting device can access the network through an authentication access controller. To ensure that legitimate users access legitimate networks, the authentication access controller needs to authenticate the requesting device, and the requesting device also needs to authenticate the authentication access controller.

[0055] Taking current wireless and mobile communication scenarios as examples, in scenarios where a requesting device accesses a wireless network through an authentication access controller, the requesting device can be a terminal device such as a mobile phone, a personal digital assistant (PDA), or a tablet computer, while the authentication access controller can be a network-side device such as a wireless access point or a wireless router. In scenarios where a requesting device accesses a wired network through an authentication access controller, the requesting device can be a terminal device such as a desktop computer or a laptop computer, while the authentication access controller can be a network-side device such as a switch or a router. In scenarios where a requesting device accesses a 4G / 5G network through an authentication access controller, the requesting device can be a terminal device such as a mobile phone or a tablet computer, while the authentication access controller can be a network-side device such as a base station. Of course, this application is also applicable to various data communication scenarios, including other wired networks and short-range communication networks.

[0056] However, during the two-way authentication process between the requesting device and the authentication access controller, both devices need to provide their own identity information. For example, the identity information of the requesting device can be contained in its digital certificate, and the identity information of the authentication access controller can be contained in its digital certificate. If an attacker intercepts such a digital certificate during the authentication process, they can obtain the private and sensitive information contained within and use it for illegal purposes, posing a significant security risk to the authentication access controller, the requesting device, and even the network.

[0057] To address the aforementioned technical problems, this application provides an identity authentication method. The authentication access controller acquires an identity ciphertext message sent by a requesting device. This ciphertext message includes ciphertext identity information of the requesting device, generated by encrypting encrypted data, including the requesting device's digital certificate, using a message encryption key. The authentication access controller then sends a first authentication request message to a trusted first authentication server. This first authentication request message includes the authentication access controller's ciphertext identity information and the requesting device's digital certificate. The ciphertext identity information of the authentication access controller is generated by encrypting encrypted data, including the authentication access controller's digital certificate, using the public key of the encryption certificate. The requesting device's digital certificate is obtained by decrypting the ciphertext identity information of the requesting device using the message encryption key. The authentication access controller receives a first authentication response message sent by the first authentication server. This first authentication response message includes ciphertext of a first authentication result, a first digital signature, second authentication result information, and a second digital signature. The ciphertext of the first authentication result information is obtained by encrypting information including the first authentication result information, which includes a first verification of the authentication access controller's digital certificate. The authentication result is as follows: the first digital signature is a digital signature calculated by the second authentication server trusted by the requesting device on signature data including the ciphertext of the first authentication result information. The second authentication result information includes a second verification result of the requesting device's digital certificate. The second digital signature is a digital signature calculated by the first authentication server on signature data including the second authentication result information. The authentication access controller uses the public key of the first authentication server to verify the second digital signature. After successful verification, it determines the authentication result of the requesting device based on the second verification result in the second authentication result information. When the authentication access controller determines that the requesting device is legitimate, it sends a third authentication response message to the requesting device. The third authentication response message includes ciphertext of the authentication result information, which is generated by encrypting encrypted data including the ciphertext of the first authentication result information and the first digital signature using a message encryption key. The requesting device uses the message encryption key to decrypt the ciphertext of the authentication result information to obtain the ciphertext of the first authentication result information and the first digital signature. It then uses the public key of the second authentication server to verify the first digital signature. After successful verification, it determines the authentication result of the authentication access controller based on the first verification result in the first authentication result information obtained by decrypting the ciphertext of the first authentication result information.

[0058] It is understood that the first authentication result information mentioned in the embodiments of this application is obtained by the first authentication server trusted by the authentication access controller verifying the legality of the digital certificate of the authentication access controller, and the second authentication result information is obtained by the second authentication server trusted by the requesting device verifying the legality of the digital certificate of the requesting device. The aforementioned first authentication server and second authentication server can be two independent servers used for identity authentication, or the same server used for identity authentication. The above are only some examples of the requesting device, authentication access controller, and authentication server, and should not be construed as limiting the requesting device, authentication access controller, and authentication server. In other possible implementations of the embodiments of this application, the requesting device, authentication access controller, and authentication server can also be other devices.

[0059] The identity authentication method provided in this application embodiment is used to implement two-way identity authentication (MIA) between the requesting device and the authentication access controller.

[0060] For ease of explanation, in this embodiment of the application, the identity authentication method of the present application will be described using the requesting device (REQuester, abbreviated as REQ), the authentication access controller (AAC, abbreviated as AAC), and the authentication server (AS, abbreviated as AS) as examples.

[0061] In this system, the AS trusted by AAC is called the first authentication server (AS-AAC), and the AS trusted by REQ is called the second authentication server (AS-REQ). AS-AAC has the ability to verify the legitimacy of AAC digital certificates and holds digital certificates conforming to ISO / IEC 9594-8 / ITU X.509, other standards, or other technical systems, along with their corresponding private keys. AS-REQ has the ability to verify the legitimacy of REQ digital certificates and also holds digital certificates conforming to ISO / IEC 9594-8 / ITU X.509, other standards, or other technical systems, along with their corresponding private keys. Both AS-AAC and AS-REQ have the ability to transmit digital certificates to other ASs for verification and to transmit verification results to other ASs. When AS-AAC and AS-REQ are different, they trust each other and are aware of each other's digital certificates or the public keys within those certificates. The Certificate Server-Decrypt (CS-DEC) holds encryption certificates and corresponding private keys that comply with ISO / IEC 9594-8 / ITU X.509, other standards, or other technical systems. The CS-DEC can be a standalone server or reside in AS-AAC.

[0062] REQ can be one endpoint participating in the authentication process, establishing a connection with AAC, accessing the services provided by AAC, and accessing AS through AAC. REQ holds a digital certificate conforming to ISO / IEC 9594-8 / ITU X.509, other standards, or other technical systems, along with the corresponding private key, and is aware of AS-REQ's digital certificate or the public key within the digital certificate. AAC can be another endpoint participating in the authentication process, establishing a connection with REQ, providing services, communicating with REQ, and directly accessing AS-AAC. AAC holds a digital certificate conforming to ISO / IEC 9594-8 / ITU X.509, other standards, or other technical systems, along with the corresponding private key, and is aware of AS-AAC's digital certificate or the public key within the digital certificate, as well as CS-DEC's encryption certificate or the public key within the encryption certificate.

[0063] The following is combined with Figure 1 This application provides an embodiment of an identity authentication method, which includes:

[0064] S101, AAC obtains the encrypted identity message REQInit sent by REQ.

[0065] The REQInit includes REQ's identity information encrypted EncData. REQAmong them, EncData REQ The REQ is encrypted using a symmetric encryption algorithm with the message encryption key, and the digital certificate Cert includes the REQ. REQ The encrypted data, including the encrypted data, is generated using encryption. During the transmission of identity information between REQ and AAC, REQ's identity information is kept confidential to prevent its exposure during transmission. The message encryption key can be negotiated between REQ and AAC, or it can be pre-shared between REQ and AAC. The implementation method for REQ and AAC to negotiate the message encryption key will be described later. In this application, the object to be encrypted is referred to as encrypted data.

[0066] S102, AAC sends a first authentication request message AACVeri to the AS-AAC it trusts.

[0067] The AACVeri includes the ciphertext EncPub, the identity information of AAC. AS and Cert REQ Among them, EncPub AS AAC uses the public key of the encryption certificate to access the digital certificate Cert, which includes AAC's own encryption key. AAC The encrypted data, including the data itself, is generated using encryption. Therefore, during the transmission of identity information between AAC and AS-AAC, the identity information of AAC is kept confidential, preventing its exposure during transmission. Cert REQ It is when the AAC receives the EncData sent by the REQ REQ Then, using the message encryption key, a symmetric encryption algorithm is employed to encrypt EncData. REQ Obtained through decryption.

[0068] It should be noted that for EncPub AS Decryption can be performed by AS-AAC using the private key corresponding to the encryption certificate, or AS-AAC can decrypt EncPub. AS The decryption is performed by the CS-DEC, which has an interaction and trust relationship with AS-AAC. The CS-DEC can be a standalone server dedicated to certificate decryption, or it can be integrated into the authentication server to perform the decryption function. For example, in this embodiment, the CS-DEC can be integrated into AS-AAC.

[0069] S103, AAC receives the first authentication response message ASVeri sent by AS-AAC.

[0070] The ASVeri includes a first authentication result information ciphertext, a first digital signature, a second authentication result information, and a second digital signature. The first authentication result information ciphertext is a ciphertext containing the first authentication result information Pub. AACThe information inside is encrypted, Pub AAC This includes Cert AAC The first verification result Res AAC The first digital signature is a digital signature calculated by the REQ-trusted AS-REQ on the signature data, including the ciphertext of the first authentication result information; the second authentication result information is Pub. REQ This includes Cert REQ The second verification result Res REQ The second digital signature is an AS-AAC pair including Pub. REQ The digital signature is generated by calculating the signature data, including the signature data.

[0071] It should be noted that when AS-REQ and AS-AAC share the same authentication server (i.e., both REQ and AAC trust the same authentication server (non-roaming), the authentication server jointly trusted by REQ and AAC can be represented by AS-AAC (or AS-REQ). In this case, AS-AAC (or AS-REQ) can be used to decrypt EncPub. AS The obtained Cert AAC The first verification result, Res, is obtained by performing a validity verification. AAC , for Cert REQ The second verification result, Res, is obtained by performing a validity verification. REQ According to Res AAC The information included generates the first identification result information Pub AAC Then for Pub AAC Encryption generates the first authentication result ciphertext, based on Res REQ The information included generates the second identification result information Pub REQ The first digital signature Sig is generated by calculating the signature data, including the encrypted information of the first authentication result. AS_AAC1 (can also be represented as Sig) AS_REQ1 ), including the second identification result information Pub REQ The second digital signature Sig is generated from the signature data. AS_AAC2 (can also be represented as Sig) AS_REQ2 According to the encrypted information including the first identification result and Sig AS_AAC1 (can also be represented as Sig) AS_REQ1 Second identification result information Pub REQ Sig AS_AAC2 (can also be represented as Sig) AS_REQ2 The information, including the first authentication response message ASVeri, is generated and sent to the AAC.

[0072] The encryption / decryption method for the first authentication result information ciphertext can be preset. For example, it can be pre-generated by AAC for Pub. AAC The encryption key, and then that key is transmitted through EncPub. AS If sent to AS-AAC, AS-AAC can then utilize the key pair, including Pub. AAC The information, including the first authentication result ciphertext, is generated by encrypting the information. As one implementation method, AAC generates ciphertext for encrypting Pub. AAC The key can be a second protection random number (Nonce). AACPub AS-AAC uses Nonce AACPub For including Pub AAC Information, including the Nonce, can be encrypted; for example, the Nonce can be encrypted. AACPub With Pub AAC Perform an XOR operation to obtain the first authentication result information ciphertext Pub. AAC ⊕Nonce AACPub .

[0073] When the AS-REQ trusted by REQ and the AS-AAC trusted by AAC are two different authentication servers (roaming), after AS-AAC receives the first authentication request message AACVeri, AS-AAC will decrypt EncPub. AS The obtained Cert AAC The first verification result, Res, is obtained by performing a validity verification. AAC According to Res AAC The information included generates the first identification result information Pub AAC Then for Pub AAC The first authentication result information ciphertext is generated by encryption, and then a second authentication request message AS-AACVeri is sent to AS-REQ. AS-AACVeri includes the first authentication result information ciphertext and Cert. REQ and third digital signature Sig AS_AAC3 Among them, Sig AS_AAC3 The AS-AAC to AS-AACVeri includes the encrypted first identification result information and Cert. REQ The digital signature is generated by calculating the signature data, including the signature data. AS-REQ uses the AS-AAC public key to verify the Sig. AS_AAC3 If the verification passes, then Cert... REQ The second verification result, Res, is obtained by performing a validity verification. REQ According to Res REQ The information included generates the second identification result information Pub REQIt also sends a second authentication response message AS-REQVeri to AS-AAC, wherein AS-REQVeri includes the encrypted first authentication result information and the first digital signature Sig. AS_REQ1 Pub REQ and the fourth digital signature Sig AS_REQ4 ;Sig AS_REQ4 AS-REQ includes Pub REQ The digital signature generated by calculating the signature data, including Sig AS_REQ1 The AS-REQ verifies the digital signature generated by AS-REQ on the signature data, including the ciphertext of the first authentication result. After receiving the AS-REQ Veri, AS-AAC verifies the Sig using the AS-REQ's public key. AS_REQ4 If the verification passes, AS-AAC will support the Pub account. REQ The second digital signature Sig is generated from the signature data. AS_AAC2 According to the encrypted information including the first authentication result information and the Sig AS_REQ1 The second identification result information Pub REQ and the Sig AS_AAC2 The information included in the message generates the first authentication response message ASVeri, which is then sent to the AAC.

[0074] S104. AAC uses the AS-AAC public key to verify the second digital signature.

[0075] S105, AAC, based on the second verification result Res in the second identification result information. REQ Determine the identity verification result of REQ.

[0076] Due to Res REQ This can reflect whether the REQ is valid, therefore AAC can use the Res information in the second authentication result to determine its validity. REQ Verifying the validity of the REQ lays the foundation for ensuring that only valid REQs can access the network.

[0077] S106. AAC sends a third authentication response message, AACAuth, to REQ.

[0078] The AACAuth includes the encrypted authentication result information EncData. AAC Among them, EncData AAC It is generated by AAC using the message encryption key to encrypt encrypted data including the first authentication result information ciphertext and the first digital signature.

[0079] It should be noted that the execution order of S104 to S106 does not affect the specific implementation of this application. In practical applications, the execution order of S104 to S106 can be set according to requirements. A preferred approach is to execute S104 first. If the AAC fails to verify the second digital signature, the ASVeri is discarded. If the AAC verifies the second digital signature successfully, S105 is executed. If the AAC determines that the REQ is valid, S106 is executed. If the AAC determines that the REQ is invalid, the AAC chooses whether to execute S106 according to its local policy. Considering efficiency, the preferred solution is not to execute S106 and end the current authentication process.

[0080] S107, REQ uses the message encryption key to ciphertext EncData, the authentication result information. AAC Decryption yields the first authentication result ciphertext and the first digital signature.

[0081] Since the message encryption key can be negotiated between REQ and AAC, or it can be pre-shared between REQ and AAC, REQ, upon receiving the AACAuth, can use the message encryption key to encrypt EncData. AAC Decryption yields the first authentication result ciphertext and the first digital signature.

[0082] S108 and REQ use AS-REQ's public key to verify the first digital signature.

[0083] Since the first digital signature is a digital signature generated by AS-REQ from signature data including the ciphertext of the first authentication result information, and REQ knows the public key of the AS-REQ it trusts, REQ can use the public key of AS-REQ to verify the first digital signature. If the verification is successful, S109 is executed; if the verification fails, the AACAuth is discarded.

[0084] S109, REQ obtains the first verification result Res from the first authentication result information based on the decrypted first authentication result information ciphertext. AAC Determine the identity verification result of AAC.

[0085] REQ can decrypt the ciphertext of the first authentication result information according to a pre-set encryption / decryption method. Alternatively, as shown in the example in S103, the ciphertext of the first authentication result information can be generated by AS-AAC encrypting the first authentication result information using a second protection random number. In this case, the EncData sent by AAC to REQ in S106... AAC The encrypted data also includes a second protection random number, then REQ uses the message encryption key to encrypt the EncData. AACThe decryption process yields a second protection random number, which is then used to decrypt the ciphertext of the first authentication result information to obtain the first authentication result information.

[0086] Due to Res AAC It can reflect whether AAC is valid, therefore REQ can be determined based on the Res information in the first authentication result obtained after decryption. AAC Determining whether an AAC is valid lays the foundation for ensuring that a REQ can access legitimate networks.

[0087] As can be seen from the above technical solutions, keeping the identity information of the requesting device and the authentication access controller confidential can prevent their exposure during network access, ensuring that attackers cannot obtain their private and sensitive information. Furthermore, by introducing an authentication server, while ensuring the confidentiality of entity identity-related information, real-time two-way authentication between the requesting device and the authentication access controller can be achieved, laying the foundation for ensuring that only legitimate users can communicate with the legitimate network.

[0088] In some embodiments, REQInit in S101 may also include the digital signature Sig of REQ. REQ Sig REQ The signature data includes the Sig in REQInit. REQ For the other fields mentioned earlier, AAC also needs to determine Sig before S105. REQ The verification process must pass before S105 can be executed. It should be noted that if AS-REQ and AS-AAC are the same authentication server, then the Sig... REQ Authentication can be performed by AS-AAC (also represented as AS-REQ) or by AAC; if AS-REQ and AS-AAC are two different authentication servers, then the Sig... REQ Verification can be performed using either AS-REQ or AAC. AAC determines Sig. REQ Whether the verification passes includes the following methods:

[0089] As a method for verifying the Sig by an authentication server REQ In an embodiment where AS-REQ and AS-AAC are the same authentication server (i.e., non-roaming), when AS-AAC (which can also be represented as AS-REQ) verifies the Sig... REQ At that time, Sig REQ It can be carried in the AACVeri of S102 and transmitted to AS-AAC (also represented as AS-REQ). AS-AAC (also represented as AS-REQ) utilizes the Cert in AACVeri.REQ Verify the Sig REQ If the verification passes, the process continues with steps such as generating and sending the first authentication response message ASVeri; if the verification fails, these steps are not executed. Therefore, AAC can determine Sig based on whether or not the first authentication response message ASVeri is received. REQ Whether the verification passes or not, if AAC can receive ASVeri, then AAC determines Sig. REQ Verification successful.

[0090] As a method for verifying the Sig by an authentication server REQ In another embodiment, where AS-REQ and AS-AAC are two different authentication servers (i.e., roaming), when AS-REQ verifies the Sig... REQ At that time, Sig REQ It can be carried in the AACVeri of S102 and transmitted to AS-REQ in the second authentication request message AS-AACVeri sent by AS-AAC to AS-REQ. AS-REQ uses the Cert in AS-AACVeri. REQ Verify the Sig REQ If the verification passes, the process continues with generating and sending the second authentication response message AS-REQVeri, as well as generating the subsequent first authentication response message ASVeri. If the verification fails, the processes of generating and sending the second authentication response message AS-REQVeri and generating the subsequent first authentication response message ASVeri will not be executed. Therefore, AAC can determine Sig based on whether or not the first authentication response message ASVeri can be received. REQ Whether the verification passes or not, if AAC can receive ASVeri, then AAC determines Sig. REQ Verification successful.

[0091] As a result of AAC verification of the Sig REQ In one embodiment, AAC can utilize the EncData in the decrypted REQInit of S101. REQ The obtained Cert REQ Sig REQ To verify, thus determining Sig REQ Has the verification passed?

[0092] As a result of AAC verification of the Sig REQ In another embodiment, the authentication server generates a second authentication result information Pub. REQ It can also include Cert REQThen, after receiving the ASVeri from S103, AAC uses the Pub... REQ Cert in REQ Verify the Sig REQ Thus determining Sig REQ Has the verification passed?

[0093] As a result of AAC verification of the Sig REQ In another embodiment, the authentication server generates a second authentication result information Pub. REQ It can also include Cert REQ After receiving ASVeri from S103, AAC first verifies the Pub. REQ Cert in REQ Decrypting EncData REQ The obtained Cert REQ If the consistency is consistent, then use Certification. REQ Verify the Sig REQ Thus determining Sig REQ Has the verification passed?

[0094] In some embodiments, the AAC digital signature Sig in S102 may also include the AAC digital signature. AAC Sig AAC The signature data includes Sig in AACeri. AAC For the other fields mentioned earlier, before S109, REQ also needs to determine Sig. AAC The verification process must pass before S109 can be executed. REQ determines Sig. AAC Whether the verification is successful includes the following methods: An AS-AAC trusted by the AAC uses the decrypted ciphertext EncPub containing the AAC's identity information in AACVeri. AS The obtained Cert AAC Sig AAC Verification is performed, and subsequent processes will only proceed after successful verification. Therefore, if REQ can receive the AACAuth from S106, REQ determines Sig. AAC Verified.

[0095] Similarly, S106's AACAuth can also include the AAC digital signature Sig. AAC Sig AAC The signature data includes the Sig in AACAuth. AAC The other fields mentioned earlier are the first authentication result information Pub generated by AS-AAC. AAC It also includes Cert AAC Correspondingly, prior to S109, REQ also needs to determine Sig.AAC The verification process must pass before S109 can be executed. REQ determines Sig. AAC Whether the verification is successful includes the following methods: REQ uses the Pub obtained by decrypting the ciphertext of the first authentication result information. AAC Cert in AAC Verify the Sig AAC Based on the verification results, determine Sig AAC Has the verification passed?

[0096] Please refer to Figure 1 The messages transmitted between REQ, AAC, and the authentication server may also include parameters such as random numbers and identity identifiers generated by AAC and / or REQ. Normally, these random numbers and / or identity identifiers should remain unchanged during the authentication process, transmitted through various messages. However, network fluctuations or attacks may cause the loss or alteration of these parameters. Therefore, during authentication, the consistency of the identity identifiers and / or random numbers in the messages can be verified to ensure the reliability and freshness of the authentication results.

[0097] For example, if the REQ identity information ciphertext EncData in REQInit of S101 REQ The encrypted data also includes the REQ's identity ID. REQ Correspondingly, S102's AACVeri also includes ID. REQ The S103 ASVeri also includes ID REQ The authentication result information EncData in S106's AACAuth is encrypted. AAC The encrypted data also includes ID REQ Therefore, REQ decrypts EncData. AAC Also got ID REQ Before executing S109, REQ also needs to decrypt the obtained ID. REQ With REQ's own identity ID REQ Perform a consistency verification, and execute S109 only after the verification is successful.

[0098] Similarly, if the ciphertext of AAC's identity information EncPub in S102's AACVeri... AS The encrypted data also includes AAC's identity ID. AAC and the first protected random number Nonce AACID Nonce AACID Used for ID AACEncryption is performed. Correspondingly, the ASVeri of S103 also includes the AAC's identity ciphertext, which is AS-AAC using a nonce. AACID For ID AAC Encrypted, for example, can be obtained using a nonce. AACID With ID AAC Perform an XOR operation to obtain the AAC's ciphertext ID. AAC ⊕Nonce AACID Therefore, prior to S105, AAC needed to rely on its own identity ID. AAC and the Nonce AACID Verification of AAC's identity ciphertext, specifically including: AAC using the Nonce... AACID For AAC's own identity ID AAC The information, including the ciphertext, is encrypted to generate the AAC's identity ciphertext, and the generated AAC identity ciphertext is then compared with the AAC identity ciphertext received in S103; alternatively, the AAC can utilize the Nonce... AACID Decrypt the AAC identity ciphertext and obtain the ID. AAC With AAC's own identity ID AAC Perform a consistency verification, and execute S105 only after the verification is successful.

[0099] Similar to identity verification, if REQInit in S101 also includes a second random number (Nonce) generated by REQ... REQ Then, the AACeri of S102 can also include Nonce. REQ The first random number (Nonce) generated by AAC AAC Correspondingly, the ASVeri of S103 can also include Nonce. REQ and Nonce AAC EncData in S106's AACAuth AAC The encrypted data may also include a nonce. REQ Therefore, before S105, AAC also needs to process the Nonce in ASVeri. AAC Nonce generated by AAC AAC Perform consistency verification; prior to S109, REQ also needs to decrypt EncData. AAC The Nonce obtained REQ Nonce generated by REQ REQ Perform consistency verification.

[0100] In addition, to ensure the reliability of the authentication results, the S106 AACAuth can also include a message integrity check code (MacTag). AAC MacTag AAC AAC uses message integrity verification key pairs, including those in AACAuth excluding MacTag. AAC Other fields besides the one mentioned above are used for calculation; therefore, after receiving AACAuth, REQ must also verify the MacTag. AAC After successful verification, proceed with S109. REQ verifies the MacTag. AAC When using the message integrity verification key pair, the key should include the key pair in AACAuth excluding the MacTag. AAC Other fields are used to calculate and generate MacTag. AAC and calculate MacTag AAC With the MacTag in the received AACAuth AAC The data is compared; if they match, the verification passes; otherwise, the verification fails. The method for generating the message integrity verification key will be described in the next embodiment.

[0101] The message encryption key in the above embodiments can be obtained through negotiation between REQ and AAC. Therefore, this embodiment also provides a method for negotiating the message encryption key using REQ and AAC. See [link to documentation]. Figure 2 The method includes:

[0102] S201, AAC sends a key request message AACInit to REQ.

[0103] The AACInit includes the AAC key exchange parameter KeyInfo. AAC KeyInfo AAC This includes the temporary public key of AAC. Key exchange refers to key exchange algorithms such as Diffie-Hellman (DH). The AACInit may also include the first random number (Nonce) generated by AAC. AAC .

[0104] The AACInit may also include security capabilities. AAC Security capabilities AAC This indicates the security capabilities supported by AAC, including the authentication suites (which contain one or more authentication methods), symmetric encryption algorithms, integrity verification algorithms, and / or key derivation algorithms supported by AAC. These parameters allow REQ to select specific security policies to use. REQ can then make decisions based on these security capabilities.AAC Select the specific security policy (Security capabilities) used by REQ. REQ Security capabilities REQ The REQ indicates the authentication method, symmetric encryption algorithm, integrity verification algorithm, and / or key derivation algorithm used.

[0105] S202, REQ is based on the key exchange parameter KeyInfo, which includes REQ. REQ The corresponding temporary private key and KeyInfo AAC The included temporary public key is used to perform key exchange calculation to generate a first key, and the message encryption key is calculated using a key derivation algorithm based on information including the first key.

[0106] If S201's AACInit also includes the Nonce generated by AAC... AAC Then REQ can be based on KeyInfo. REQ The corresponding temporary private key and KeyInfo AAC The included temporary public key is used for key exchange calculation to generate the first key K1, and K1 is combined with the Nonce. AAC The second random number Nonce generated by REQ REQ The information, including the message encryption key, is calculated using a negotiated or pre-defined key derivation algorithm. The negotiated key derivation algorithm can be based on the Security capabilities sent by the AAC according to the REQ. AAC The chosen key derivation algorithm. KeyInfo REQ This refers to the key exchange parameters generated by REQ, including REQ's temporary public key. KeyInfo REQ The corresponding temporary private key is the temporary private key generated by REQ that corresponds to the temporary public key of REQ, that is, the temporary public key and the temporary private key are a pair of temporary public-private keys.

[0107] S203, REQ sends the identity-encrypted message REQInit to AAC.

[0108] The REQInit includes KeyInfo. REQ So that AAC can be based on including KeyInfo AAC The corresponding temporary private key and KeyInfo REQ The message encryption key is calculated from the information including the temporary public key. Among them, KeyInfo... AAC The corresponding temporary private key is the temporary private key generated by AAC that corresponds to the temporary public key of AAC. That is, the temporary public key and the temporary private key are a pair of temporary public-private keys.

[0109] The REQInit may also include security capabilities. REQ The REQInit may also include a Nonce. REQ So that AAC can use the KeyInfo as a basis. AAC The corresponding temporary private key, the KeyInfo REQ The included temporary public key, the Nonce AAC and the Nonce REQ The encryption key for the message is calculated from the information included.

[0110] The REQInit may also include the Nonce. AAC Then AAC can check the Nonce in REQInit before calculating the message encryption key. AAC Nonce generated by AAC AAC Perform consistency verification to ensure that the REQInit received by AAC is a response message to AACInit.

[0111] S204, AAC based on including KeyInfo AAC The corresponding temporary private key and KeyInfo REQ The included temporary public key is used to perform key exchange calculations to generate the first key, and the message encryption key is calculated using the key derivation algorithm based on information including the first key.

[0112] If the REQInit also includes the Nonce REQ Then AAC can be based on the KeyInfo. AAC The corresponding temporary private key and the KeyInfo REQ The included temporary public key is used for key exchange calculation to generate the first key K1, and K1 is combined with the Nonce. AAC and the Nonce REQ The information, including the message key, is used to calculate the encryption key for the message through a negotiated or pre-defined key derivation algorithm. The negotiated key derivation algorithm can be the Security capabilities sent by AAC based on the REQ. REQ The key export algorithm to be used.

[0113] It should be noted that, in Figure 2 In this embodiment, REQ and AAC can also generate message integrity verification keys. The implementation methods for REQ and AAC to generate message integrity verification keys are the same as... Figure 2 The implementation methods for generating message encryption keys for REQ and AAC in the examples are the same. For example, AAC can be generated through... Figure 2 The embodiment uses a key derivation algorithm to derive a string of key data. This key data can be used as both a message encryption key and a message integrity verification key. Alternatively, a portion of the key data can be used as a message encryption key, and the other portion as a message integrity verification key. AAC can also... Figure 2 The implementation method utilizes a key derivation algorithm to derive two identical or different key data sequences in stages: one sequence serves as the message encryption key, and the other as the message integrity verification key. REQ can be... Figure 2 The embodiment uses a key derivation algorithm to derive a string of key data. This key data can be used as both a message encryption key and a message integrity verification key. Alternatively, a portion of the key data can be used as the message encryption key, and the other portion as the message integrity verification key. REQ can also be achieved through... Figure 2 The implementation method uses a key derivation algorithm to derive two strings of identical or different key data in stages. One string is used as the message encryption key, and the other string is used as the message integrity verification key.

[0114] This application also provides a method for determining the first authentication server and / or the second authentication server used in the current authentication process by utilizing information exchange between AAC and REQ:

[0115] Please refer to Figure 2 In S201's AACInit, AAC adds the identity ID of at least one authentication server trusted by AAC. AS_AAC Then REQ is based on the ID. AS_AAC Identify the identity ID of at least one authentication server that you trust. AS_REQ In practice, REQ is derived from ID. AS_AAC Select at least one authentication server that it trusts as its ID. AS_REQ If the selection fails, REQ will use the identity of at least one trusted authentication server as its ID. AS_REQ (Where, successful selection corresponds to a non-roaming situation, and failed selection corresponds to a roaming situation), and the ID... AS_REQ Add it to REQInit in S203 and send it to AAC. Then, AAC can use it based on the ID. AS_AAC and ID AS_REQ The primary authentication server, such as AAC, can be used to determine the ID. AS_REQ and ID AS_AACDoes the system contain at least one identical authentication server identifier? If so, it's a non-roaming scenario, and AAC determines the first authentication server to participate in authentication from among the at least one authentication server identifier trusted by both REQ and AAC. If not, it's a roaming scenario, and AAC needs to determine the first authentication server based on the ID. AS_AAC Determine the first authentication server AS-AAC involved in identity authentication and set the ID. AS_REQ Send to AS-AAC so that AS-AAC can process the data based on the ID. AS_REQ Determine the second authentication server AS-REQ.

[0116] As another implementation, AAC may not need to send ID to REQ. AS_AAC The REQ adds the identity ID of at least one trusted authentication server to the REQInit in S203. AS_REQ According to ID AS_REQ The identity ID of the authentication server trusted by AAC itself. AS_AAC The specific implementation of the first authentication server and / or the second authentication server participating in the identity authentication process is as described in the previous implementation.

[0117] Since the authentication servers for REQ and AAC trusts can be the same or different, when the authentication servers for REQ and AAC trusts are the same, it is a non-roaming situation; when the authentication servers for REQ and AAC trusts are different, it is a roaming situation.

[0118] See Figure 3 This is an embodiment of an identity authentication method in a non-roaming scenario, where AS-AAC (or AS-REQ) can be used to represent an authentication server mutually trusted by REQ and AAC. Before this embodiment is executed, both REQ and AAC already possess the message encryption key, which can be pre-shared by both parties or obtained through [other means]. Figure 2 The identity authentication method, obtained through negotiation as shown, includes:

[0119] S301, AAC obtains the encrypted identity message REQInit sent by REQ.

[0120] The REQInit includes REQ's identity information encrypted EncData. REQ and REQ's digital signature Sig REQ .

[0121] S302, AAC sends the first authentication request message AACVeri to AS-AAC.

[0122] The AACVeri includes the ciphertext EncPub, the identity information of AAC. ASand Cert REQ The Cert REQ AAC uses the message encryption key to encrypt the EncData. REQ Obtained through decryption.

[0123] S303 and AS-AAC decrypt EncPub using the private key corresponding to the encryption certificate. AS Get Cert AAC Second protection random number Nonce AACPub For Cert respectively AAC and Cert REQ The first verification result, Res, is obtained by performing a validity verification. AAC Second verification result Res REQ According to Cert AAC and Res AAC The first identification result information is generated based on information including Cert. REQ and Res REQ The information included generates the second identification result; using the Nonce AACPub The information, including the first authentication result information, is encrypted to obtain the ciphertext of the first authentication result information. The signature data, including the ciphertext of the first authentication result information, is then used to calculate and generate the first digital signature Sig. AS_AAC1 The second digital signature Sig is generated by calculating the signature data, including the second authentication result information. AS_AAC2 .

[0124] S304, AAC receives the first authentication response message ASVeri sent by AS-AAC.

[0125] The ASVeri includes the first authentication result information ciphertext, Sig AS_AAC1 Second identification result information and Sig AS_AAC2 .

[0126] S305 and AAC use AS-AAC public key verification Sig AS_AAC2 Using the Cert information in the second identification result REQ Verify Sig REQ If all verifications pass, then based on the Res information in the second identification result... REQ Determine the identity verification result of REQ.

[0127] When AAC determines that REQ's identity authentication result is valid, it executes S306; when AAC determines that REQ's identity authentication result is invalid, it terminates the current authentication process.

[0128] S306, AAC uses a message encryption key pair including the ciphertext of the first authentication result information and the SigAS_AAC1 and the Nonce AACPub EncData is used to encrypt the data and generate the authentication result information in ciphertext. AAC For EncData AAC The digital signature Sig of AAC is generated from the signature data, including the signature data. AAC .

[0129] S307, AAC sends a third authentication response message AACAuth to REQ.

[0130] The AACAuth includes the EncData. AAC and the Sig AAC .

[0131] S308, REQ uses the message encryption key to access the EncData. AAC Decryption yields the first authentication result ciphertext, Sig AS_AAC1 and Nonce AACPub .

[0132] S309, REQ uses Nonce AACPub The first authentication result information is obtained by decrypting the ciphertext of the first authentication result information.

[0133] S310, REQ utilizes the Cert information from the first authentication result. AAC Verify the Sig AAC And, using the AS-AAC public key to verify the Sig AS_AAC1 .

[0134] If all verifications pass, execute S311; if verification fails, discard AACAuth.

[0135] S311, REQ, based on Res in the first identification result information AAC Determine the identity verification result of AAC.

[0136] It should be noted that in S305, Sig... REQ The verification can also be performed first in S301, that is, after AAC obtains the REQInit, it uses the EncData in the decrypted REQInit. REQ The obtained Cert REQ Verify Sig REQ After successful verification, S302 is executed. In this case, the second authentication result information may not include Cert. REQ Alternatively, in S305, for Sig REQ The verification can also be performed first in S303. In this case, the Sig REQIt can be sent to AS-AAC via AACVeri on S302, and AS-AAC can then use Cert... REQ Verify Sig REQ After verification, proceed with the subsequent operations.

[0137] See Figure 4 This is another embodiment of the identity authentication method in non-roaming scenarios, where AS-AAC (or AS-REQ) can be used to represent the authentication server that REQ and AAC both trust. Before this embodiment is executed, both REQ and AAC already possess the message encryption key, which can be pre-shared by both parties or obtained through [other means]. Figure 2 The identity verification method is obtained through negotiation as shown. This method includes:

[0138] S401, AAC retrieves the encrypted identity message REQInit sent by REQ.

[0139] The REQInit includes REQ's identity information encrypted EncData. REQ and REQ's digital signature Sig REQ .

[0140] S402, AAC sends the first authentication request message AACVeri to AS-AAC.

[0141] The AACVeri includes the ciphertext EncPub, the identity information of AAC. AS Cert REQ and AAC's digital signature Sig AAC The Cert REQ AAC uses the message encryption key to encrypt the EncData. REQ Obtained through decryption.

[0142] S403, AS-AAC ciphertext of AAC's identity information EncPub AS Decryption yields Cert AAC Second protection random number Nonce AACPub and using Cert AAC Verify the Sig AAC .

[0143] If the verification passes, execute S404; if the verification fails, discard AACVeri.

[0144] S404 and AS-AAC respectively address Cert AAC and Cert REQ The first verification result, Res, is obtained by performing a validity verification. AAC Second verification result Res REQAccording to Res AAC The first identification result information is generated based on information including Cert. REQ and Res REQ The information included generates the second identification result; using the Nonce AACPub The information, including the first authentication result information, is encrypted to generate ciphertext of the first authentication result information. The signature data, including the ciphertext of the first authentication result information, is then used to calculate and generate the first digital signature Sig. AS_AAC1 The second digital signature Sig is generated by calculating the signature data, including the second authentication result information. AS_AAC2 .

[0145] S405, AAC receives the first authentication response message ASVeri sent by AS-AAC.

[0146] The ASVeri includes the first authentication result information ciphertext, Sig AS_AAC1 Second identification result information and Sig AS_AAC2 .

[0147] S406, AAC uses AS-AAC's public key to verify Sig. AS_AAC2 Using the Cert information in the second identification result REQ Verify Sig REQ If all verifications pass, then based on the Res information in the second identification result... REQ Determine the identity verification result of REQ.

[0148] When AAC determines that REQ's identity authentication result is valid, it executes S407; when AAC determines that REQ's identity authentication result is invalid, it terminates the current authentication process.

[0149] S407, AAC utilizes a message encryption key pair including the ciphertext of the first authentication result information, Sig AS_AAC1 and Nonce AACPub EncData is used to encrypt the data and generate the authentication result information in ciphertext. AAC .

[0150] S408, AAC sends a third authentication response message AACAuth to REQ.

[0151] The AACAuth includes the EncData. AAC .

[0152] S409, REQ uses the message encryption key to access the EncData. AAC Decryption yields the first authentication result ciphertext, Sig AS_AAC1 and Nonce AACPub .

[0153] S410 and REQ use AS-AAC public key verification Sig AS_AAC1 .

[0154] If the verification passes, execute S411; if the verification fails, discard AACAuth.

[0155] S411, REQ utilizes Nonce AACPub Decrypting the ciphertext of the first authentication result information yields the first authentication result information. Based on the Res in the first authentication result information... AAC Determine the identity verification result of AAC.

[0156] It should be noted that in S406, Sig... REQ The verification can also be performed first in S401, that is, after AAC obtains the REQInit, it uses the EncData in the decrypted REQInit. REQ The obtained Cert REQ Verify Sig REQ After successful verification, S402 is executed. In this case, the second authentication result information may not include Cert. REQ Alternatively, in S406, for Sig REQ The verification can also be performed first in S403. In this case, the Sig REQ It can be sent to AS-AAC via S402's AACVeri, and AS-AAC can then use Cert... REQ Verify Sig REQ After verification, proceed with the subsequent operations.

[0157] See Figure 5 This is an embodiment of an identity authentication method in roaming scenarios, where AS-AAC and AS-REQ trust each other and know each other's digital certificates or the public key within those certificates. Before this embodiment is executed, both REQ and AAC already possess the message encryption key, which can be pre-shared by both parties or obtained through [other means]. Figure 2 The identity verification method is obtained through negotiation as shown. This method includes:

[0158] S501, AAC obtains the encrypted identity message REQInit sent by REQ.

[0159] The REQInit includes REQ's identity information encrypted EncData. REQ REQ trusts at least one authentication server's identity ID. AS_REQ and REQ's digital signature Sig REQ .

[0160] S502, AAC sends the first authentication request message AACVeri to AS-AAC.

[0161] The AACVeri includes the ciphertext EncPub, the identity information of AAC. AS Cert REQ and ID AS_REQ AS-AAC can be based on ID. AS_REQ The second authentication server AS-REQ used in this authentication process was identified, and Cert was set. REQ Send to AS-REQ for verification. The Cert... REQ AAC uses the message encryption key to encrypt the EncData. REQ Obtained through decryption.

[0162] S503, AS-AAC decryption EncPub AS Get Cert AAC Second protection random number Nonce AACPub , for Cert AAC The first verification result, Res, is obtained by performing a validity verification. AAC According to Cert AAC and Res AAC The first identification result information is generated from the information included, using Nonce. AACPub The information, including the first authentication result information, is encrypted to obtain the ciphertext of the first authentication result information. The signature data, including the ciphertext of the first authentication result information, is then used to calculate and generate the third digital signature Sig. AS_AAC3 .

[0163] S504, AS-AAC sends a second authentication request message AS-AACVeri to AS-REQ.

[0164] The AS-AACVeri includes the encrypted first authentication result information and Cert. REQ and Sig AS_AAC3 .

[0165] S505 and AS-REQ use AS-AAC public keys to verify Sig. AS_AAC3 .

[0166] If the verification passes, proceed with S506; if the verification fails, discard AS-AACVeri.

[0167] S506, AS-REQ for Cert REQ The second verification result, Res, is obtained by performing a validity verification. REQ According to Cert REQ and Res REQThe information included in the first authentication result information is used to generate a second authentication result information. The signature data, including the ciphertext of the first authentication result information, is then used to calculate and generate a first digital signature Sig. AS_REQ1 The fourth digital signature Sig is generated by calculating the signature data, including the second authentication result information. AS_REQ4 .

[0168] S507, AS-REQ sends a second authentication response message AS-REQVeri to AS-AAC.

[0169] The AS-REQVeri includes the first authentication result information ciphertext and the first digital signature Sig. AS_REQ1 The second authentication result information and the fourth digital signature Sig AS_REQ4 .

[0170] S508 and AS-AAC use the public key of AS-REQ to verify Sig. AS_REQ4 .

[0171] If the verification passes, execute 509; if the verification fails, discard AS-REQVeri.

[0172] S509 and AS-AAC calculate and generate a second digital signature Sig from the signature data, including the second authentication result information. AS_AAC2 According to the encrypted information including the first identification result and Sig AS_REQ1 Second identification result information and Sig AS_AAC2 The information included generates the first authentication response message ASVeri.

[0173] S510 and AS-AAC send the first authentication response message ASVeri to AAC.

[0174] S511 and AAC use AS-AAC's public key to verify Sig. AS_AAC2 Using the Cert information in the second identification result REQ Verify the Sig REQ If all verifications pass, then based on the Res information in the second identification result... REQ Determine the identity verification result of REQ.

[0175] When AAC determines that REQ's identity authentication result is valid, it executes S512; when AAC determines that REQ's identity authentication result is invalid, it terminates the current authentication process.

[0176] S512, AAC uses a message encryption key pair including the ciphertext of the first authentication result information, Sig AS_REQ1 and Nonce AACPub EncData is used to encrypt the data and generate the authentication result information in ciphertext.AAC For EncData AAC The digital signature Sig of AAC is generated from the signature data, including the signature data. AAC .

[0177] S513, AAC sends a third authentication response message AACAuth to REQ.

[0178] The AACAuth includes EncData. AAC and Sig AAC .

[0179] S514 and REQ use the message encryption key to pair EncData AAC Decryption yields the first authentication result ciphertext, Sig AS_REQ1 and Nonce AACPub .

[0180] S515, REQ utilizes Nonce AACPub The first authentication result information is obtained by decrypting the ciphertext of the first authentication result information.

[0181] S516, REQ utilizes the Cert information in the first authentication result. AAC Verify the Sig AAC And, using the public key of AS-REQ to verify the Sig AS_REQ1 .

[0182] If all verifications pass, execute S517; if verification fails, discard AACAuth.

[0183] S517, REQ, based on Res in the first identification result information AAC Determine the identity verification result of AAC.

[0184] It should be noted that in S511, Sig... REQ The verification can also be performed first in S501, that is, after AAC obtains the REQInit, it uses the EncData in the decrypted REQInit. REQ The obtained Cert REQ Verify Sig REQ After successful verification, S502 is executed. In this case, the second authentication result information may not include Cert. REQ Alternatively, in S511, for Sig REQ The verification can also be performed first in S505. In this case, the Sig... REQ It can be sent to AS-REQ via AACVeri or AS-AACVeri, and AS-REQ can then use Cert... REQ Verify SigREQ After verification, proceed with the subsequent operations.

[0185] See Figure 6 This is another embodiment of the identity authentication method in roaming scenarios. In this case, AS-AAC and AS-REQ trust each other and know each other's digital certificates or the public key within those certificates. Before this embodiment is executed, both REQ and AAC already possess the message encryption key, which can be pre-shared by both parties or obtained through [other means]. Figure 2 The identity authentication method, obtained through negotiation as shown, includes:

[0186] S601, AAC obtains the encrypted identity message REQInit sent by REQ.

[0187] The REQInit includes REQ's identity information encrypted EncData. REQ REQ trusts at least one authentication server's identity ID. AS_REQ and REQ's digital signature Sig REQ .

[0188] S602, AAC sends the first authentication request message AACVeri to AS-AAC.

[0189] The AACVeri includes the ciphertext EncPub, the identity information of AAC. AS Cert REQ ID AS_REQ and AAC's digital signature Sig AAC The Cert REQ AAC uses the message encryption key to encrypt the EncData. REQ Obtained through decryption.

[0190] S603, AS-AAC decryption EncPub AS Get Cert AAC Second protection random number Nonce AACPub and using Cert AAC Verify Sig AAC .

[0191] If the verification passes, execute S604; if the verification fails, discard AACVeri.

[0192] S604, AS-AAC for Cert AAC The first verification result, Res, is obtained by performing a validity verification. AAC According to Res AAC The first identification result information is generated from the information included, using Nonce. AACPubThe information, including the first authentication result information, is encrypted to generate ciphertext of the first authentication result information. The signature data, including the ciphertext of the first authentication result information, is then used to calculate and generate a third digital signature, Sig. AS_AAC3 .

[0193] S605, AS-AAC sends a second authentication request message AS-AACVeri to AS-REQ.

[0194] The AS-AACVeri includes the encrypted first authentication result information and Cert. REQ and Sig AS_AAC3 .

[0195] S606 and AS-REQ use AS-AAC public keys to verify Sig. AS_AAC3 .

[0196] If the verification passes, proceed with S607; if the verification fails, discard AS-AACVeri.

[0197] S607, AS-REQ verification Cert REQ The legality of Res is verified by a second result. REQ According to Cert REQ and Res REQ The information included in the first authentication result information is used to generate a second authentication result information. The signature data, including the ciphertext of the first authentication result information, is then used to calculate and generate a first digital signature Sig. AS_REQ1 The fourth digital signature Sig is generated by calculating the signature data, including the second authentication result information. AS_REQ4 .

[0198] S608, AS-REQ sends a second authentication response message AS-REQVeri to AS-AAC.

[0199] The AS-REQVeri includes the first authentication result information ciphertext and the first digital signature Sig. AS_REQ1 The second authentication result information and the fourth digital signature Sig AS_REQ4 .

[0200] S609 and AS-AAC use the public key of AS-REQ to verify Sig. AS_REQ4 .

[0201] If the verification passes, proceed to step 610; if the verification fails, discard AS-REQVeri.

[0202] S610 and AS-AAC calculate and generate a second digital signature Sig from the signature data, including the second authentication result information. AS_AAC2 According to the encrypted information including the first identification result and Sig AS_REQ1Second identification result information and Sig AS_AAC2 The information included generates the first authentication response message ASVeri.

[0203] S611, AS-AAC sends the first authentication response message ASVeri to AAC.

[0204] S612, AAC uses AS-AAC's public key to verify Sig. AS_AAC2 Using the Cert information in the second identification result REQ Verify the Sig REQ If all verifications pass, then based on the Res information in the second identification result... REQ Determine the identity verification result of REQ.

[0205] When AAC determines that REQ's identity authentication result is valid, S613 is executed; when AAC determines that REQ's identity authentication result is invalid, the authentication process ends.

[0206] S613, AAC utilizes a message encryption key pair including the ciphertext of the first authentication result information, Sig AS_REQ1 and Nonce AACPub EncData is used to encrypt the data and generate the authentication result information in ciphertext. AAC .

[0207] S614, AAC sends a third authentication response message AACAuth to REQ.

[0208] The AACAuth includes the EncData. AAC .

[0209] S615 and REQ use message encryption keys to pair EncData AAC Decryption yields the first authentication result ciphertext, Sig AS_REQ1 and Nonce AACPub .

[0210] S616 and REQ use the AS-REQ public key to verify Sig. AS_REQ1 .

[0211] If the verification passes, execute S617; if the verification fails, discard AACAuth.

[0212] S617, REQ utilizes Nonce AACPub Decrypting the ciphertext of the first authentication result information yields the first authentication result information. Based on the Res in the first authentication result information... AAC Determine the identity verification result of AAC.

[0213] It should be noted that in S612, Sig...REQ The verification can also be performed first in S601, that is, after AAC obtains the REQInit, it uses the EncData in the decrypted REQInit. REQ The obtained Cert REQ Verify Sig REQ After successful verification, S602 is executed. In this case, the second authentication result information may not include Cert. REQ Alternatively, in S612, for Sig REQ The verification can also be performed first in S606. In this case, the Sig REQ It can be sent to AS-REQ via AACVeri or AS-AACVeri, and AS-REQ can then use Cert... REQ Verify Sig REQ After verification, proceed with the subsequent operations.

[0214] For the sake of simplicity, Figures 7-10 In this embodiment, the first identification result information is represented by Pub. AAC This indicates that the second identification result information is represented by Pub. REQ express.

[0215] See Figure 7 This is an embodiment of an identity authentication method in non-roaming scenarios, where AS-AAC (or AS-REQ) can be used to represent an authentication server mutually trusted by both REQ and AAC. In this embodiment, the message encryption key negotiation process between REQ and AAC is integrated into the identity authentication process in parallel, making it easier to implement in engineering. The digital signature Sig of AAC... AAC Verified by REQ, the method includes:

[0216] S701, AAC generates Nonce AAC and KeyInfo AAC Generate security capabilities as needed AAC .

[0217] S702, AAC sends a key request message AACInit to REQ.

[0218] The AACInit includes Nonce AAC KeyInfo AAC and security capabilities AAC Among them, security capabilities AACThis is an optional field that represents the security capabilities supported by AAC, including the authentication suites, symmetric encryption algorithms, integrity verification algorithms, and / or key derivation algorithms supported by AAC (the same applies below).

[0219] S703, REQ generates Nonce REQ and KeyInfo REQ Generate security capabilities as needed REQ According to including KeyInfo REQ The corresponding temporary private key and KeyInfo AAC The included temporary public key is used for key exchange calculation to generate the first key K1, and K1 is combined with the Nonce. AAC Nonce REQ Other information (the other information used by REQ and AAC is the same and optional, such as specific strings) is used to calculate the message encryption key and message integrity verification key using a negotiated or pre-defined key derivation algorithm; the EncData is then calculated using a symmetric encryption algorithm with the message encryption key. REQ ; Calculate Sig REQ .

[0220] Among them, security capabilities REQ REQ indicates that it is based on security capabilities AAC The selection of a specific security strategy, i.e., the authentication method, symmetric encryption algorithm, integrity verification algorithm, and / or key derivation algorithm to be used (hereinafter the same), as determined by the REQ. Whether the REQ generates security capabilities. REQ It depends on whether the AACInit sent by AAC to REQ includes security capabilities. AAC Calculating the message integrity verification key using REQ is an optional operation; this step can be performed later when the message integrity verification key is needed.

[0221] S704, REQ sends the identity-encrypted message REQInit to AAC.

[0222] The REQInit includes Nonce AAC Nonce REQ Security capabilities REQ KeyInfo REQ EncData REQ and Sig REQ Among them, Nonce AACThis is an optional field and should be equal to the corresponding field in AACInit; Securitycapabilities REQ This is an optional field. EncData REQ The encrypted data includes Cert REQ and ID REQ Sig REQ The signature data includes the Sig in REQInit. REQ Other fields mentioned earlier, such as Nonce, are included in REQInit sequentially. AAC Nonce REQ Security capabilities REQ KeyInfo REQ EncData REQ and Sig REQ At that time, Sig REQ The signature data includes the Nonce AAC Nonce REQ Security capabilities REQ KeyInfo REQ and EncData REQ When REQInit does not include Nonce AAC When using fields, Sig REQ The signature data also includes the Nonce from AACInit. AAC Fields. In this application, the object to be signed is referred to as signature data.

[0223] S705. After receiving the REQInit, AAC performs the following operations (unless otherwise specified or logically related, the actions numbered (1), (2), ... in this document do not necessarily have a sequential order due to their numbering. The same applies throughout the document), including:

[0224] (1) If a Nonce exists in REQInit AAC Then check the Nonce. AAC Is it related to the Nonce generated by AAC? AAC If they are the same, discard REQInit; if they are different, discard it.

[0225] (2) Based on the KeyInfo AAC The corresponding temporary private key and the KeyInfo REQ The included temporary public key is used for key exchange calculation to generate the first key K1, and K1 is combined with the Nonce. AAC Nonce REQOther information (the other information used by AAC and REQ is the same and optional, such as a specific string) is used to calculate the message encryption key and message integrity verification key using a negotiated or pre-defined key derivation algorithm; among them, the calculation of the message integrity verification key by AAC is an optional operation, and this step can be performed later when the message integrity verification key is needed.

[0226] (3) Using the message encryption key, a symmetric encryption algorithm is employed to encrypt the EncData. REQ Decryption yields Cert REQ and ID REQ ;

[0227] (4) Generate Nonce AACID and Nonce AACPub ;

[0228] (5) Calculate the ciphertext EncPub, the identity information of AAC, using the public key of the encryption certificate. AS .

[0229] S706, AAC sends the first authentication request message AACVeri to AS-AAC.

[0230] The AACeri includes ID REQ Cert REQ Nonce REQ Nonce AAC and EncPub AS Among them, ID REQ Cert REQ Nonce REQ It should equal the corresponding field in REQInit; Nonce AAC It should be equal to the Nonce generated by AAC. AAC EncPub AS The encrypted data includes ID AAC Cert AAC Nonce AACPub and Nonce AACID .

[0231] After receiving the AACVeri, S707 and AS-AAC perform the following operations, including:

[0232] (1) Decrypt the EncPub using the private key corresponding to the encryption certificate. AS Get ID AAC Cert AAC Nonce AACID and Nonce AACPub ;

[0233] (2) Verify Cert respectively AAC and Cert REQ The legitimacy of Res AAC and Res REQ According to Cert AAC and Res AAC Information generated in Pub AAC According to Cert REQ and Res REQ Information generated in Pub REQ ; For ID AAC and Nonce AACID Generate ID by performing an XOR operation AAC ⊕Nonce AACID For Pub AAC and Nonce AACPub Generate Pub by performing XOR operation AAC ⊕Nonce AACPub ;

[0234] (3) Calculate the first digital signature Sig AS_AAC1 Second digital signature Sig AS_AAC2 .

[0235] S708, AS-AAC sends the first authentication response message ASVeri to AAC.

[0236] The ASVeri includes ID REQ Nonce REQ Pub AAC ⊕Nonce AACPub Sig AS_AAC1 ID AAC ⊕Nonce AACID Nonce AAC Pub REQ and Sig AS_AAC2 Among them, ID REQ Nonce REQ Nonce AACPub ID AAC Nonce AACID Nonce AAC They should be equal to the corresponding fields in AACVeri; Sig AS_AAC1 The signature data includes ID REQ Nonce REQ and Pub AAC ⊕Nonce AACPub ;Sig AS_AAC2 The signature data includes ID AAC ⊕Nonce AACID NonceAAC and Pub REQ .

[0237] S709. After receiving the ASVeri, AAC performs the following operations, including:

[0238] (1) Using Nonce AACID With ID AAC ⊕Nonce AACID Perform an XOR operation to recover the ID AAC Check the ID AAC With AAC's own identity ID AAC Are they the same?

[0239] (2) Check the Nonce AAC Is it related to the Nonce generated by AAC? AAC same;

[0240] (3) Verify Sig using AS-AAC public key AS_AAC2 ;

[0241] (4) Check Pub REQ Cert in REQ Decrypting EncData REQ The obtained Cert REQ Are they the same?

[0242] (5) Using Cert REQ Verify Sig in REQInit REQ ;

[0243] (6) If any step of the above checks and verifications fails, ASVeri shall be discarded immediately; if all the above checks and verifications pass, the product shall be processed according to the Pub. REQ Res in REQ Determine the identity verification result of REQ; if REQ is determined to be illegitimate, end the current verification process.

[0244] (7) Using the message encryption key and a symmetric encryption algorithm, calculate the authentication result information ciphertext EncData. AAC ;

[0245] (8) Calculate the digital signature Sig of AAC AAC ;

[0246] (9) Calculate MacTag as needed AAC .

[0247] S710 and AAC send a third authentication response message AACAuth to REQ.

[0248] The AACAuth includes Nonce. REQ Nonce AAC EncData AAC Sig AAC and MacTag AAC Among them, Nonce REQ and Nonce AAC This is an optional field and should be equal to the Nonce in REQInit. REQ Nonce generated by AAC AAC EncData AAC The encrypted data includes ID REQ Nonce REQ Pub AAC ⊕Nonce AACPub Sig AS_AAC1 and Nonce AACPub Sig AAC The signature data includes the Sig in AACAuth. AAC Other fields mentioned earlier. MacTag AAC This is an optional field, and its calculation process is as follows: Using the message integrity verification key, an integrity verification algorithm is applied to all fields except MacTag in AACAuth. AAC MacTag is generated by calculating information including other fields. AAC .

[0249] S711. After receiving the AACAuth, REQ performs the following operations, including:

[0250] (1) If a Nonce exists in AACAuth REQ Then check the Nonce. REQ Nonce generated with REQ REQ Are they the same? If a Nonce exists in AACAuth... AAC Then check the Nonce. AAC Nonce in the received AACInit AAC Are they the same?

[0251] (2) If MacTag exists in AACAuth AAC Then verify MacTag AAC ;

[0252] The verification process is as follows: using the message integrity verification key, an integrity verification algorithm is employed to verify the integrity of all data in AACAuth except for the MacTag. AAC Information including other fields is calculated locally to generate the MacTag. AAC (This calculation method is the same as AAC's calculation of MacTag)AAC (In the same way), and calculate the MacTag AAC With the MacTag in the received AACAuth AAC Compare them.

[0253] (3) Decrypt the EncData using the message encryption key and a symmetric encryption algorithm. AAC Get ID REQ Nonce REQ Pub AAC ⊕Nonce AACPub Sig AS_AAC1 Nonce AACPub ;

[0254] (4) Check the ID obtained after decryption REQ Nonce REQ Are they respectively related to REQ's own identity ID? REQ Nonce generated by REQ REQ same;

[0255] (5) Decrypt the obtained Nonce AACPub With Pub AAC ⊕Nonce AACPub Perform an XOR operation to restore Pub AAC ;

[0256] (6) Using Pub AAC Cert in AAC Verify Sig AAC And, using AS-AAC public key verification Sig AS_AAC1 ;

[0257] (7) If all the above checks and verifications pass, then according to Pub AAC Res in AAC Determine the identity authentication result of AAC. If any step of the above checks and verifications fails, discard AACAuth immediately.

[0258] It should be noted that in S709, the Sig... REQ The verification can also be performed first in S705, that is, after AAC obtains the REQInit, it uses the EncData in the decrypted REQInit. REQ The obtained Cert REQ Verify Sig REQ After successful verification, S706 is executed. In this case, Figure 7 Pub in the embodiment REQ It can be replaced with Res REQ Alternatively, in S709, for SigREQ The verification can also be performed first in S707. In this case, the Sig... REQ It can be sent to AS-AAC via S706's AACVeri, and AS-AAC can then use Cert... REQ Verify Sig REQ After verification, proceed with the subsequent operations.

[0259] See Figure 8 This is another embodiment of the identity authentication method in non-roaming scenarios, where AS-AAC (or AS-REQ) can be used to represent the authentication server jointly trusted by REQ and AAC. In this embodiment, the message encryption key negotiation process between REQ and AAC is integrated into the identity authentication process in parallel, making it easier to implement in engineering. The digital signature Sig of AAC... AAC Verified by AS-AAC, the method includes:

[0260] S801, AAC generates Nonce AAC and KeyInfo AAC Generate security capabilities as needed AAC .

[0261] S802, AAC sends a key request message AACInit to REQ.

[0262] The AACInit includes Nonce AAC KeyInfo AAC and security capabilities AAC Among them, security capabilities AAC This is an optional field.

[0263] S803, REQ generates Nonce REQ and KeyInfo REQ Generate security capabilities as needed REQ According to including KeyInfo REQ The corresponding temporary private key and KeyInfo AAC The included temporary public key is used for key exchange calculation to generate the first key K1, and K1 is combined with the Nonce. AAC Nonce REQOther information (other information used by REQ and AAC is the same and optional, such as specific strings) is used to calculate the message encryption key and message integrity verification key using a negotiated or pre-defined key derivation algorithm; the ciphertext EncData of REQ's identity information is then calculated using a symmetric encryption algorithm with the message encryption key. REQ ; Calculate Sig REQ .

[0264] The REQ calculation of the message integrity verification key is an optional operation, and this step can be performed later when the message integrity verification key is needed.

[0265] S804, REQ sends the identity-encrypted message REQInit to AAC.

[0266] The REQInit includes Nonce AAC Nonce REQ Security capabilities REQ KeyInfo REQ EncData REQ and Sig REQ Among them, Nonce AAC and security capabilities REQ It is an optional field, and Nonce AAC It should be equal to the Nonce in AACInit. AAC EncData REQ The encrypted data includes ID REQ and Cert REQ Sig REQ The signature data includes the Sig in REQInit. REQ Other fields mentioned earlier.

[0267] After receiving the REQInit, S805 and AAC perform the following operations, including:

[0268] (1) If a Nonce exists in REQInit AAC Then check the Nonce. AAC Nonce generated by AAC AAC Check if they are the same; if they are different, discard REQInit.

[0269] (2) Based on the KeyInfo AAC The corresponding temporary private key and the KeyInfo REQ The included temporary public key is used for key exchange calculation to generate the first key K1, and K1 is combined with the Nonce. AAC Nonce REQOther information (the other information used by AAC and REQ is the same and optional, such as a specific string) is used to calculate the message encryption key and message integrity verification key using a negotiated or pre-defined key derivation algorithm; among them, the calculation of the message integrity verification key by AAC is an optional operation, and this step can be performed later when the message integrity verification key is needed.

[0270] (3) Using the message encryption key, a symmetric encryption algorithm is employed to encrypt the EncData. REQ Decryption yields Cert REQ and ID REQ ;

[0271] (4) Generate Nonce AACID and Nonce AACPub ;

[0272] (5) Calculate the ciphertext EncPub, the identity information of AAC, using the public key of the encryption certificate. AS ;

[0273] (6) Calculate the digital signature Sig of AAC AAC .

[0274] S806, AAC sends the first authentication request message AACVeri to AS-AAC.

[0275] The AACeri includes ID REQ Cert REQ Nonce REQ Nonce AAC EncPub AS and Sig AAC Among them, ID REQ Cert REQ Nonce REQ These should be equal to the corresponding fields in REQInit. (EncPub) AS The encrypted data includes ID AAC Cert AAC Nonce AACPub and Nonce AACID Sig AAC The signature data includes Sig in AACeri. AAC Other fields mentioned earlier.

[0276] After receiving the AACVeri, S807 and AS-AAC perform the following operations, including:

[0277] (1) Decrypt the EncPub AS Get ID AAC CertAAC Nonce AACID and Nonce AACPub ;

[0278] (2) Using Cert AAC Verify the Sig AAC ;

[0279] (3) Verify Cert respectively AAC and Cert REQ The legitimacy of Res AAC and Res REQ According to Res AAC Information generated in Pub AAC According to Cert REQ and Res REQ Information generated in Pub REQ ; For ID AAC and Nonce AACID Generate ID by performing an XOR operation AAC ⊕Nonce AACID For Pub AAC and Nonce AACPub Generate Pub by performing XOR operation AAC ⊕Nonce AACPub ;

[0280] (4) Calculate the first digital signature Sig AS_AAC1 Second digital signature Sig AS_AAC2 .

[0281] S808 and AS-AAC send the first authentication response message ASVeri to AAC.

[0282] The ASVeri includes ID REQ Nonce REQ Pub AAC ⊕Nonce AACPub Sig AS_AAC1 ID AAC ⊕Nonce AACID Nonce AAC Pub REQ and Sig AS_AAC2 Among them, ID REQ Nonce REQ Nonce AACPub ID AAC Nonce AACID Nonce AAC They should be equal to the corresponding fields in AACVeri; Sig AS_AAC1 The signature data includes IDREQ Nonce REQ Pub AAC ⊕Nonce AACPub Sig AS_AAC2 The signature number includes ID AAC ⊕Nonce AACID Nonce AAC Pub REQ .

[0283] S809. After receiving the ASVeri, AAC performs the following operations, including:

[0284] (1) Using Nonce AACID With ID AAC ⊕Nonce AACID Perform an XOR operation to recover the ID AAC Check the ID AAC Is it consistent with AAC's own identity ID? AAC same;

[0285] (2) Check the Nonce AAC Is it related to the Nonce generated by AAC? AAC same;

[0286] (3) Verify Sig using AS-AAC public key AS_AAC2 ;

[0287] (4) Check Pub REQ Cert in REQ Decrypting EncData REQ The obtained Cert REQ Are they the same?

[0288] (5) Using Cert REQ Verify Sig in REQInit REQ ;

[0289] (6) If any step of the above checks and verifications fails, ASVeri shall be discarded immediately; if all the above checks and verifications pass, the product shall be processed according to the Pub. REQ Res in REQ Determine the identity verification result of REQ. If REQ is determined to be illegitimate, then end the current verification process.

[0290] (7) Calculate EncData using a symmetric encryption algorithm with the message encryption key. AAC ;

[0291] (8) Calculate MacTag as needed AAC .

[0292] S810 and AAC send a third authentication response message AACAuth to REQ.

[0293] The AACAuth includes Nonce. REQ Nonce AAC EncData AAC and MacTag AAC Among them, Nonce REQ and Nonce AAC This is an optional field and should be equal to the Nonce in REQInit. REQ Nonce generated by AAC AAC EncData AAC The encrypted data includes ID REQ Nonce REQ Pub AAC ⊕Nonce AACPub Sig AS_AAC1 and Nonce AACPub And ID REQ Nonce REQ Pub AAC ⊕Nonce AACPub Sig AS_AAC1 They should be equal to the corresponding fields in ASVeri. MacTag AAC This is an optional field, and its calculation process is as follows: Figure 7 As described in the examples.

[0294] S811, after receiving the AACAuth, REQ performs the following operations, including:

[0295] (1) If a Nonce exists in AACAuth REQ Then check the Nonce. REQ Nonce generated with REQ REQ Are they the same? If a Nonce exists in AACAuth... AAC Then check the Nonce. AAC Nonce in the received AACInit AAC Are they the same?

[0296] (2) If MacTag exists in AACAuth AAC Then verify MacTag AAC The verification process is as follows: Figure 7 As described in the embodiments;

[0297] (3) Decrypt the EncData using the message encryption key and a symmetric encryption algorithm. AAC Get ID REQNonce REQ Pub AAC ⊕Nonce AACPub Sig AS_AAC1 Nonce AACPub ;

[0298] (4) Check the ID obtained after decryption REQ Nonce REQ Are they respectively related to REQ's own identity ID? REQ Nonce generated by REQ REQ same;

[0299] (5) Verify Sig using AS-AAC public key AS_AAC1 ;

[0300] (6) Decrypt the obtained Nonce AACPub With Pub AAC ⊕Nonce AACPub Perform an XOR operation to restore Pub AAC ;

[0301] (7) If all the above checks and verifications pass, then according to Pub AAC Res in AAC Determine the identity authentication result of AAC; if any step of the above checks and verifications fails, discard AACAuth immediately.

[0302] It should be noted that in S809, Sig... REQ The verification can also be performed first in S805, that is, after AAC obtains the REQInit, it uses the EncData in the decrypted REQInit. REQ The obtained Cert REQ Verify Sig REQ After successful verification, S806 is executed. In this case, Figure 8 Pub in the embodiment REQ It can be replaced with Res REQ Alternatively, in S809, for Sig... REQ The verification can also be performed first in S807. In this case, the Sig REQ It can be sent to AS-AAC via S806's AACVeri, and AS-AAC can then use Cert... REQ Verify Sig REQ After verification, proceed with the subsequent operations.

[0303] See Figure 9This is an embodiment of an identity authentication method in roaming scenarios. In this embodiment, the message encryption key negotiation process between REQ and AAC is integrated into the identity authentication process in parallel, making it easier to implement in engineering. Specifically, the digital signature Sig of AAC... AAC Verified by REQ, the method includes:

[0304] S901, AAC generates Nonce AAC and KeyInfo AAC Generate security capabilities as needed AAC .

[0305] S902, AAC sends a key request message AACInit to REQ.

[0306] The AACInit includes Nonce AAC KeyInfo AAC Security capabilities AAC and ID AS_AAC Among them, security capabilities AAC and ID AS_AAC Optional field; ID AS_AAC The identity identifier of at least one authentication server representing AAC trust is used to enable REQ to be based on ID. AS_AAC Determine if a mutually trusted authentication server exists (the same applies below).

[0307] S903, REQ generates Nonce REQ and KeyInfo REQ Generate ID as needed AS_REQ and Security capabilities REQ According to including KeyInfo REQ The corresponding temporary private key and KeyInfo AAC The included temporary public key is used for key exchange calculation to generate the first key K1, and K1 is combined with the Nonce. AAC Nonce REQ Other information (other information used by REQ and AAC is the same and optional, such as specific strings) is used to calculate the message encryption key and message integrity verification key using a negotiated or pre-defined key derivation algorithm; the ciphertext EncData of REQ's identity information is then calculated using a symmetric encryption algorithm with the message encryption key. REQ ; Calculate Sig REQ .

[0308] Among them, ID AS_REQand security capabilities REQ This is an optional field. ID AS_REQ The identity identifier of at least one authentication server representing REQ trust, when an ID exists in AACInit. AS_AAC At that time, REQ will try to select at least one authentication server from its trusted authentication servers that matches the ID. AS_AAC The same authentication server identity is used as ID AS_REQ If the choice fails, the identity of at least one trusted authentication server will be used as the ID. AS_REQ When the ID does not exist in AACInit AS_AAC At that time, REQ uses the identity of at least one trusted authentication server as its ID. AS_REQ (Same throughout). Calculating the message integrity verification key using REQ is an optional operation; this step can be performed only when the message integrity verification key is required.

[0309] S904, REQ sends the encrypted identity message REQInit to AAC.

[0310] The REQInit includes Nonce AAC Nonce REQ Security capabilities REQ ID AS_REQ KeyInfo REQ EncData REQ and Sig REQ Among them, Nonce AAC ID AS_REQ and security capabilities REQ It is an optional field, and Nonce AAC It should equal the corresponding field in AACInit; EncData REQ The encrypted data includes ID REQ and Cert REQ Sig REQ The signature data includes the Sig in REQInit. REQ Other fields mentioned earlier, when Nonce is not included in REQInit. AAC When using fields, Sig REQ The signature data also includes the Nonce from AACInit. AAC Field.

[0311] S905. After receiving the REQInit, AAC performs the following operations, including:

[0312] (1) If a Nonce exists in REQInit AAC Then check the Nonce. AAC Is it related to the Nonce generated by AAC? AAC If they are the same, discard REQInit; if they are different, discard it.

[0313] (2) Based on the KeyInfo AAC The corresponding temporary private key and the KeyInfo REQ The included temporary public key is used for key exchange calculation to generate the first key K1, and K1 is combined with the Nonce. AAC Nonce REQ Other information (the other information used by AAC and REQ is the same and optional, such as a specific string) is used to calculate the message encryption key and message integrity verification key using a negotiated or pre-defined key derivation algorithm; the calculation of the message integrity verification key by AAC is an optional operation, and this step can be performed later when the message integrity verification key is needed.

[0314] (3) Using the message encryption key, a symmetric encryption algorithm is employed to encrypt the EncData. REQ Decryption yields Cert REQ and ID REQ ;

[0315] (4) Generate Nonce AACID and Nonce AACPub ;

[0316] (5) If REQInit carries ID AS_REQ And AACInit carries an ID AS_AAC Then AAC determines ID AS_REQ and ID AS_AAC If at least one identical authentication server identity exists, it indicates a non-roaming scenario. AAC determines the first authentication server to participate in authentication from among the identity identifiers of at least one authentication server commonly trusted by both REQ and AAC. If no such server exists, it indicates a roaming scenario, and AAC needs to determine the first authentication server based on the ID. AS_AAC Determine the first authentication server AS-AAC involved in identity authentication and set the ID. AS_REQ Send to AS-AAC so that AS-AAC can process the data based on the ID. AS_REQ Determine the second authentication server AS-REQ; or,

[0317] If REQInit carries an ID AS_REQ However, AACInit does not carry an ID. AS_AAC Then AAC determines ID AS_REQIf at least one authentication server with the same identity identifier exists as the authentication server trusted by AAC, then in a non-roaming scenario, AAC determines the first authentication server to participate in identity authentication from among the identity identifiers of at least one authentication server commonly trusted by both REQ and AAC. If none exists, then in a roaming scenario, AAC needs to determine the first authentication server AS-AAC to participate in identity authentication based on its own trusted authentication servers, and then record the ID. AS_REQ Send to AS-AAC so that AS-AAC can process the data based on the ID. AS_REQ Determine the second authentication server AS-REQ;

[0318] It should be noted that the result determined in this embodiment is the roaming status.

[0319] (6) Calculate the ciphertext EncPub, the identity information of AAC, using the public key of the encryption certificate. AS .

[0320] S906, AAC sends the first authentication request message AACVeri to AS-AAC.

[0321] The AACeri includes ID REQ Cert REQ Nonce REQ Nonce AAC EncPub AS and ID AS_REQ Among them, ID AS_REQ It is an optional field, and Nonce REQ ID AS_REQ ID REQ and Cert REQ They should be equal to the corresponding fields in REQInit; Nonce AAC It should be equal to the Nonce generated by AAC. AAC EncPub AS The encrypted data includes ID AAC Cert AAC Nonce AACPub and Nonce AACID .

[0322] After receiving the AACVeri, S907 and AS-AAC send a decryption request message AS-AACReq to the certificate decryption server CS-DEC.

[0323] The AS-AACReq includes EncPub in the AACVeri. AS .

[0324] After receiving the AS-AACReq, S908 and CS-DEC decrypt the EncPub using the private key corresponding to the encryption certificate. AS Get ID AAC Cert AAC Nonce AACID Nonce AACPub .

[0325] S909 and CS-DEC send a decryption response message CS-DECRep to AS-AAC.

[0326] The CS-DECRep includes the decrypted ID. AAC Cert AAC Nonce AACID Nonce AACPub .

[0327] After receiving the CS-DECRep, S910 and AS-AAC perform the following operations, including:

[0328] (1) Verify Cert AAC The legitimacy of Res AAC According to Cert AAC and Res AAC Information generated in Pub AAC ;

[0329] (2) For ID AAC and Nonce AACID Generate ID by performing an XOR operation AAC ⊕Nonce AACID For Pub AAC and Nonce AACPub Generate Pub by performing XOR operation AAC ⊕Nonce AACPub ;

[0330] (3) If ID exists in AACVeri AS_REQ Then AS-AAC is based on ID AS_REQ Determine the second authentication server AS-REQ. If it does not exist, it means that AS-AAC has already confirmed AS-REQ.

[0331] (4) Calculate the third digital signature Sig AS_AAC3 .

[0332] S911, AS-AAC sends a second authentication request message AS-AACVeri to AS-REQ.

[0333] The AS-AACVeri includes ID REQ NonceREQ Pub AAC ⊕Nonce AACPub ID AAC ⊕Nonce AACID Nonce AAC Cert REQ and Sig AS_AAC3 Among them, ID REQ Nonce REQ Cert REQ Nonce AACPub ID AAC Nonce AACID Nonce AAC They should be equal to the corresponding fields in AACVeri, Sig AS_AAC3 The signature data includes Sig in AS-AACVeri. AS_AAC3 Other fields mentioned earlier.

[0334] S912, after receiving the AS-AACVeri, AS-REQ performs the following operations, including:

[0335] (1) Verify the Sig using the AS-AAC public key. AS_AAC3 If the verification fails, discard AS-AACVeri.

[0336] (2) Verify Cert REQ The legitimacy of Res REQ According to Cert REQ and Res REQ Information generated in Pub REQ ;

[0337] (3) Calculate the first digital signature Sig AS_REQ1 and the fourth digital signature Sig AS_REQ4 .

[0338] S913, AS-REQ sends a second authentication response message AS-REQVeri to AS-AAC.

[0339] The AS-REQVeri includes ID REQ Nonce REQ Pub AAC ⊕Nonce AACPub Sig AS_REQ1 ID AAC ⊕Nonce AACID Nonce AAC Pub REQ and Sig AS_REQ4 Among them, ID REQNonce REQ Pub AAC ⊕Nonce AACPub ID AAC ⊕Nonce AACID Nonce AAC These should be equal to the corresponding fields in AS-AACVeri. Sig AS_REQ1 The signature data includes ID REQ Nonce REQ Pub AAC ⊕Nonce AACPub ;Sig AS_REQ4 The signature data includes ID AAC ⊕Nonce AACID Nonce AAC Pub REQ .

[0340] S914. After receiving the AS-REQVeri, AS-AAC performs the following operations, including:

[0341] (1) Verify the Sig using the public key of AS-REQ. AS_REQ4 If the verification fails, the AS-REQVeri will be discarded.

[0342] (2) Calculate and generate the second digital signature Sig AS_AAC2 .

[0343] S915, AS-AAC sends the first authentication response message ASVeri to AAC.

[0344] The ASVeri includes ID REQ Nonce REQ Pub AAC ⊕Nonce AACPub Sig AS_REQ1 ID AAC ⊕Nonce AACID Nonce AAC Pub REQ and Sig AS_AAC2 Among them, ID REQ Nonce REQ Pub AAC ⊕Nonce AACPub Sig AS_REQ1 ID AAC ⊕Nonce AACID Nonce AAC Pub REQ These should be equal to the corresponding fields in AS-REQVeri. Sig AS_AAC2 The signature data includes IDAAC ⊕Nonce AACID Nonce AAC Pub REQ .

[0345] S916. After receiving the ASVeri, the AAC performs the following operations, including:

[0346] (1) Using Nonce AACID For ID AAC ⊕Nonce AACID Perform an XOR operation to recover the ID AAC Check the ID AAC With AAC's own identity ID AAC Are they the same?

[0347] (2) Check the Nonce AAC Nonce generated by AAC AAC Are they the same?

[0348] (3) Verify Sig using AS-AAC public key AS_AAC2 ;

[0349] (4) Check Pub REQ Cert in REQ Decrypting EncData REQ The obtained Cert REQ Are they the same?

[0350] (5) Using Cert REQ Verify Sig in REQInit REQ ;

[0351] (6) If any step of the above checks and verifications fails, ASVeri shall be discarded immediately. If all the above checks and verifications pass, the ASVeri shall be discarded according to the Pub. REQ Res in REQ Determine the identity verification result of REQ; if REQ is determined to be illegitimate, end the current verification process.

[0352] (7) Using the message encryption key and a symmetric encryption algorithm, calculate the authentication result information ciphertext EncData. AAC ;

[0353] (8) Calculate Sig AAC ;

[0354] (9) Calculate MacTag as needed AAC .

[0355] S917, AAC sends a third authentication response message AACAuth to REQ.

[0356] The AACAuth includes Nonce. REQ Nonce AAC EncData AAC Sig AAC and MacTag AAC Among them, Nonce REQ and Nonce AAC This is an optional field and should be equal to the Nonce in REQInit. REQ Nonce generated by AAC AAC MacTag AAC This is an optional field, and its calculation process is as follows: Figure 7 As described in the embodiments. EncData AAC The encrypted data includes ID REQ Nonce REQ Pub AAC ⊕Nonce AACPub Sig AS_REQ1 and Nonce AACPub And ID REQ Nonce REQ Pub AAC ⊕Nonce AACPub Sig AS_REQ1 These should be equal to the corresponding fields in ASVeri. Sig AAC The signature data includes the Sig in AACAuth. AAC Other fields mentioned earlier.

[0357] After receiving the AACAuth, S918 and REQ perform the following operations, including:

[0358] (1) If a Nonce exists in AACAuth REQ Then check the Nonce. REQ Nonce generated with REQ REQ Are they the same? If a Nonce exists in AACAuth... AAC Then check the Nonce. AAC Nonce in the received AACInit AAC Are they the same?

[0359] (2) If MacTag exists in AACAuth AAC Then verify MacTag AAC The verification process is as follows: Figure 7 As described in the embodiments;

[0360] (3) Decrypt the EncData using the message encryption key and a symmetric encryption algorithm. AAC Get ID REQ Nonce REQ Pub AAC ⊕Nonce AACPub Sig AS_REQ1 Nonce AACPub ;

[0361] (4) Check the ID obtained after decryption REQ Nonce REQ Are they respectively related to REQ's own identity ID? REQ Nonce generated by REQ REQ same;

[0362] (5) Decrypt the obtained Nonce AACPub With Pub AAC ⊕Nonce AACPub Perform an XOR operation to restore Pub AAC ;

[0363] (6) Using Pub AAC Cert in AAC Verify Sig AAC Verify Sig using the public key of AS-REQ AS_REQ1 ;

[0364] (7) If all the above checks and verifications pass, then according to Pub AAC Res in AAC Determine the identity authentication result of AAC. If any step of the above checks and verifications fails, discard AACAuth immediately.

[0365] It should be noted that in S916, Sig... REQ The verification can also be performed first in S905, that is, after AAC obtains the REQInit, it uses the EncData in the decrypted REQInit. REQ The obtained Cert REQ Verify Sig REQ After successful verification, S906 is executed. In this case, Figure 9 Pub in the embodiment REQ It can be replaced with Res REQ Alternatively, in S916, for Sig REQ The verification can also be performed first in S912. In this case, the Sig REQ It can be sent to AS-REQ via S906's AACVeri or S911's AS-AACVeri, and then AS-REQ uses Cert...REQ Verify Sig REQ After verification, proceed with the subsequent operations.

[0366] See Figure 10 This is another embodiment of the identity authentication method in roaming scenarios. In this embodiment, the message encryption key negotiation process between REQ and AAC is integrated into the identity authentication process in parallel, which is easier to implement in engineering. Specifically, the digital signature Sig of AAC... AAC Verified by AS-AAC, the method includes:

[0367] S1001, AAC generates Nonce AAC and KeyInfo AAC Generate security capabilities as needed AAC .

[0368] S1002, AAC sends a key request message AACInit to REQ.

[0369] The AACInit includes Nonce AAC KeyInfo AAC Security capabilities AAC and ID AS_AAC Among them, security capabilities AAC and ID AS_AAC This is an optional field.

[0370] S1003, REQ generates Nonce REQ and KeyInfo REQ Generate ID as needed AS_REQ and Security capabilities REQ According to including KeyInfo REQ The corresponding temporary private key and KeyInfo AAC The included temporary public key is used for key exchange calculation to generate the first key K1, and K1 is combined with the Nonce. AAC Nonce REQ Other information (other information used by REQ and AAC is the same and optional, such as specific strings) is used to calculate the message encryption key and message integrity verification key using a negotiated or pre-defined key derivation algorithm; the ciphertext EncData of REQ's identity information is then calculated using a symmetric encryption algorithm with the message encryption key. REQ ; Calculate Sig REQ .

[0371] Among them, ID AS_REQand security capabilities REQ This is an optional field. Calculating the message integrity verification key using REQ is an optional operation; this step can be performed later when the message integrity verification key is needed.

[0372] S1004, REQ sends the identity-encrypted message REQInit to AAC.

[0373] The REQInit includes Nonce AAC Nonce REQ Security capabilities REQ ID AS_REQ KeyInfo REQ EncData REQ and Sig REQ Among them, Nonce AAC ID AS_REQ and security capabilities REQ It is an optional field, and Nonce AAC It should equal the corresponding field in AACInit. EncData REQ The encrypted data includes Cert REQ and ID REQ Sig REQ The signature data includes the Sig in REQInit. REQ Other fields mentioned earlier.

[0374] S1005. After receiving the REQInit, AAC performs the following operations, including:

[0375] (1) If a Nonce exists in REQInit AAC Then check the Nonce. AAC Is it related to the Nonce generated by AAC? AAC If they are the same, discard REQInit; if they are different, discard it.

[0376] (2) Based on the KeyInfo AAC The corresponding temporary private key and the KeyInfo REQ The included temporary public key is used for key exchange calculation to generate the first key K1, and K1 is combined with the Nonce. AAC Nonce REQOther information (the other information used by AAC and REQ is the same and optional, such as a specific string) is used to calculate the message encryption key and message integrity verification key using a negotiated or pre-defined key derivation algorithm; the calculation of the message integrity verification key by AAC is an optional operation, and this step can be performed later when the message integrity verification key is needed.

[0377] (3) Using the message encryption key, a symmetric encryption algorithm is employed to encrypt the EncData. REQ Decryption yields Cert REQ and ID REQ ;

[0378] (4) Generate Nonce AACID and Nonce AACPub ;

[0379] (5) Calculate the ciphertext EncPub, the identity information of AAC, using the public key of the encryption certificate. AS ;

[0380] (6) If REQInit carries ID AS_REQ And AACInit carries an ID AS_AAC Then AAC determines ID AS_REQ and ID AS_AAC If at least one identical authentication server identity exists, it indicates a non-roaming scenario. AAC determines the first authentication server to participate in authentication from among the identity identifiers of at least one authentication server commonly trusted by both REQ and AAC. If no such server exists, it indicates a roaming scenario, and AAC needs to determine the first authentication server based on the ID. AS_AAC Determine the first authentication server AS-AAC involved in identity authentication and set the ID. AS_REQ Send to AS-AAC so that AS-AAC can process the data based on the ID. AS_REQ Determine the second authentication server AS-REQ; or,

[0381] If REQInit carries an ID AS_REQ However, AACInit does not carry an ID. AS_AAC Then AAC determines ID AS_REQ If at least one authentication server with the same identity identifier exists as the authentication server trusted by AAC, then in a non-roaming scenario, AAC determines the first authentication server to participate in identity authentication from among the identity identifiers of at least one authentication server commonly trusted by both REQ and AAC. If none exists, then in a roaming scenario, AAC needs to determine the first authentication server AS-AAC to participate in identity authentication based on its own trusted authentication servers, and then record the ID. AS_REQ Send to AS-AAC so that AS-AAC can process the data based on the ID. AS_REQDetermine the second authentication server AS-REQ;

[0382] It should be noted that the result determined in this embodiment is the roaming status.

[0383] (7) Calculate the digital signature Sig of AAC AAC .

[0384] S1006, AAC sends the first authentication request message AACVeri to AS-AAC.

[0385] The AACVeri may include an ID. REQ Cert REQ Nonce REQ Nonce AAC ID AS_REQ EncPub AS and Sig AAC Among them, Nonce REQ ID AS_REQ ID REQ Cert REQ They should be equal to the corresponding fields in REQInit, Nonce AAC It should be equal to the Nonce generated by AAC. AAC ID AS_REQ This is an optional field. (EncPub) AS The encrypted data includes ID AAC Cert AAC Nonce AACPub and Nonce AACID ;Sig AAC The signature data includes Sig in AACeri. AAC Other fields mentioned earlier.

[0386] S1007. After receiving the AACVeri, AS-AAC sends a decryption request message AS-AACReq to CS-DEC.

[0387] The AS-AACReq includes EncPub in the AACVeri. AS .

[0388] After receiving the AS-AACReq, S1008 and CS-DEC decrypt the EncPub using the private key corresponding to the encryption certificate. AS Get ID AAC Cert AAC Nonce AACID Nonce AACPub .

[0389] S1009, CS-DEC sends a decryption response message CS-DECRep to AS-AAC.

[0390] The CS-DECRep includes the decrypted ID. AAC Cert AAC Nonce AACID Nonce AACPub .

[0391] After receiving the CS-DECRep, S1010 and AS-AAC perform the following operations, including:

[0392] (1) Using the Cert AAC Sig AAC Verification is required;

[0393] (2) If Sig AAC If the verification passes, then verify the Cert. AAC The legitimacy of Res AAC According to Res AAC Information generated in Pub AAC ;

[0394] (3) ID AAC and Nonce AACID Generate ID by performing an XOR operation AAC ⊕Nonce AACID For Pub AAC and Nonce AACPub Generate Pub by performing XOR operation AAC ⊕Nonce AACPub ;

[0395] (4) If ID exists in AACVeri AS_REQ Then AS-AAC is based on ID AS_REQ Determine the second authentication server AS-REQ. If it does not exist, it means that AS-AAC has already confirmed AS-REQ.

[0396] (5) Calculate the third digital signature Sig AS_AAC3 .

[0397] S1011, AS-AAC sends a second authentication request message AS-AACVeri to AS-REQ.

[0398] The AS-AACVeri includes ID REQ Nonce REQ Pub AAC ⊕Nonce AACPub ID AAC ⊕NonceAACID Nonce AAC Cert REQ and Sig AS_AAC3 Among them, ID REQ Nonce REQ Cert REQ Nonce AACPub ID AAC Nonce AACID Nonce AAC These should be equal to the corresponding fields in AACVeri. Sig AS_AAC3 The signature data includes Sig in AS-AACVeri. AS_AAC3 Other fields mentioned earlier.

[0399] S1012. After receiving the AS-AACVeri, AS-REQ performs the following operations, including:

[0400] (1) Verify the Sig using the AS-AAC public key. AS_AAC3 If the verification fails, the message AS-AACVeri is discarded.

[0401] (2) Verify Cert in AS-AACVeri REQ The legality of generating Res REQ According to Cert REQ and Res REQ Information generated in Pub REQ ;

[0402] (3) Calculate the first digital signature Sig AS_REQ1 and the fourth digital signature Sig AS_REQ4 .

[0403] S1013, AS-REQ sends a second authentication response message AS-REQVeri to AS-AAC.

[0404] The AS-REQVeri includes ID REQ Nonce REQ Pub AAC ⊕Nonce AACPub Sig AS_REQ1 ID AAC ⊕Nonce AACID Nonce AAC Pub REQ and Sig AS_REQ4 Among them, ID REQ Nonce REQ Pub AAC ⊕Nonce AACPubID AAC ⊕Nonce AACID Nonce AAC They should be equal to the corresponding fields in AS-AACVeri respectively; Sig AS_REQ1 The signature data includes ID REQ Nonce REQ Pub AAC ⊕Nonce AACPub ;Sig AS_REQ4 The signature data includes ID AAC ⊕Nonce AACID Nonce AAC Pub REQ .

[0405] S1014. After receiving the AS-REQVeri, AS-AAC performs the following operations, including:

[0406] (1) Verify the Sig using the public key of AS-REQ. AS_REQ4 If the verification fails, the AS-REQVeri will be discarded.

[0407] (2) Calculate and generate the second digital signature Sig AS_AAC2 .

[0408] S1015, AS-AAC sends the first authentication response message ASVeri to AAC.

[0409] The ASVeri includes ID REQ Nonce REQ Pub AAC ⊕Nonce AACPub Sig AS_REQ1 ID AAC ⊕Nonce AACID Nonce AAC Pub REQ and Sig AS_AAC2 Among them, ID REQ Nonce REQ Pub AAC ⊕Nonce AACPub Sig AS_REQ1 ID AAC ⊕Nonce AACID Nonce AAC Pub REQ They should be equal to the corresponding fields in AS-REQVeri; Sig AS_AAC2 The signature data includes ID AAC ⊕Nonce AACID Nonce AACPub REQ .

[0410] S1016. After receiving the ASVeri, the AAC performs the following operations, including:

[0411] (1) Using Nonce AACID For ID AAC ⊕Nonce AACID Perform an XOR operation to recover the ID AAC Check the ID AAC With AAC's own identity ID AAC Are they the same?

[0412] (2) Check the Nonce AAC Nonce generated by AAC AAC Are they the same?

[0413] (3) Verify Sig using AS-AAC public key AS_AAC2 ;

[0414] (4) Check Pub REQ Cert in REQ Decrypting EncData REQ The obtained Cert REQ Are they the same?

[0415] (5) Using Cert REQ Verify Sig in REQInit REQ ;

[0416] (6) If any step of the above checks and verifications fails, ASVeri shall be discarded immediately. If all the above checks and verifications pass, the ASVeri shall be discarded according to the Pub. REQ Res in REQ Determine the identity verification result of REQ; if the identity verification result of REQ is determined to be invalid, then end this verification process;

[0417] (7) Calculate EncData using a symmetric encryption algorithm with the message encryption key. AAC ;

[0418] (8) Calculate MacTag as needed AAC .

[0419] S1017, AAC sends a third authentication response message AACAuth to REQ.

[0420] The AACAuth includes Nonce. REQ Nonce AAC EncData AAC and MacTagAAC Among them, Nonce REQ and Nonce AAC This is an optional field and should be equal to the Nonce in REQInit. REQ Nonce generated by AAC AAC MacTag AAC This is an optional field, and its calculation process is as follows: Figure 7 As described in the embodiments. EncData AAC The encrypted data includes ID REQ Nonce REQ Pub AAC ⊕Nonce AACPub Sig AS_REQ1 and Nonce AACPub , where ID REQ Nonce REQ Pub AAC ⊕Nonce AACPub Sig AS_REQ1 They should be equal to the corresponding fields in ASVeri.

[0421] S1018. After receiving the AACAuth, REQ performs the following operations, including:

[0422] (1) If a Nonce exists in AACAuth REQ Then check the Nonce. REQ Nonce generated with REQ REQ Are they the same? If a Nonce exists in AACAuth... AAC Then check the Nonce. AAC Nonce in the received AACInit AAC Are they the same?

[0423] (2) If MacTag exists in AACAuth AAC Then verify MacTag AAC The verification process is as follows: Figure 7 As described in the embodiments;

[0424] (3) Decrypt the EncData using the message encryption key and a symmetric encryption algorithm. AAC Get ID REQ Nonce REQ Pub AAC ⊕Nonce AACPub Sig AS_REQ1 Nonce AACPub ;

[0425] (4) Check the ID obtained after decryptionREQ Nonce REQ Are they respectively related to REQ's own identity ID? REQ Nonce generated by REQ REQ same;

[0426] (5) Verify Sig using the public key of AS-REQ AS_REQ1 ;

[0427] (6) Decrypt the obtained Nonce AACPub With Pub AAC ⊕Nonce AACPub Perform an XOR operation to restore Pub AAC ;

[0428] (7) If all the above checks and verifications pass, then according to Pub AAC Res in AAC Determine the identity authentication result of AAC. If any step of the above checks and verifications fails, discard AACAuth immediately.

[0429] It should be noted that in S1016, Sig... REQ The verification can also be performed first in S1005, that is, after AAC obtains the REQInit, it uses the EncData in the decrypted REQInit. REQ The obtained Cert REQ Verify Sig REQ After successful verification, execute S1006. In this case, Figure 10 Pub in the embodiment REQ It can be replaced with Res REQ Alternatively, in S1016, for Sig REQ The verification can also be performed first in S1012. In this case, the Sig REQ It can be sent to AS-REQ via AACVeri of S1006 or AS-AACVeri of S1011, and AS-REQ will then use Cert... REQ Verify Sig REQ After verification, proceed with the subsequent operations.

[0430] In the above embodiments, each message may also carry a hash value. X_Y The hash value X_Y This is calculated by the sending entity X using a hash algorithm on the latest preceding message received from the peer entity Y. It is used by the peer entity Y to verify whether entity X has received the complete latest preceding message. Here, HASH... REQ_AACThis represents the hash value calculated by REQ for the latest preceding message sent by AAC. AAC_REQ HASH represents the hash value calculated by AAC for the latest preceding message sent by the received REQ. AAC_AS-AAC HASH represents the hash value calculated by AAC for the latest preceding message received from AS-AAC. AS-AAC_AAC HASH represents the hash value calculated by AS-AAC for the latest preceding message sent by AAC. AS-AAC_AS-REQ HASH represents the hash value calculated by AS-AAC for the latest preceding message sent by AS-REQ. AS-REQ_AS-AAC This represents the hash value calculated by AS-REQ for the latest preceding message received from AS-AAC. If the message currently sent by sender entity X is the first message exchanged between entity X and entity Y, meaning that entity X has not received any preceding messages from peer entity Y, then the hash value in this message... X_Y It may not exist or be meaningless.

[0431] Correspondingly, after the peer entity Y receives a message sent by entity X, if the message contains a hash... X_Y If entity Y has not sent a preceding message to entity X, then entity Y ignores the hash. X_Y When entity Y has previously sent a preceding message to entity X, entity Y uses a hash algorithm to calculate a hash value locally for the latest preceding message previously sent to entity X, and then hashes it with the hash value carried in the received message. X_Y If they match, proceed with the next steps; otherwise, discard or end the identification process.

[0432] In this invention, for entity X, the preceding message sent by peer entity Y to entity X refers to any message received by entity X from peer entity Y before entity X sends message M to peer entity Y; the latest preceding message sent by peer entity Y to entity X refers to the latest message received by entity X from peer entity Y before entity X sends message M to peer entity Y. If message M sent by entity X to its peer entity Y is the first message exchanged between entity X and entity Y, then there are no preceding messages sent by peer entity Y to entity X before entity X sends message M to its peer entity Y.

[0433] It should be noted that the above Figure 7 , Figure 8 , Figure 9 and Figure 10 The optional fields and optional operations in the corresponding embodiments are shown in the accompanying drawings. Figure 7 , Figure 8 , Figure 9 and Figure 10The asterisk (*) indicates the content. The order of the various contents included in the messages in all the above embodiments is not limited, and unless otherwise specified, the order in which the message recipient operates on the relevant messages and processes the contents included in the messages is not limited.

[0434] based on Figures 1 to 10 For a corresponding embodiment, see Figure 11 This application provides an authentication access controller (AAC) including:

[0435] The acquisition unit 1101 is used to acquire the identity ciphertext message sent by the requesting device. The identity ciphertext message includes the identity information ciphertext of the requesting device. The identity information ciphertext of the requesting device is generated by encrypting encrypted data, including the digital certificate of the requesting device, using a message encryption key.

[0436] The first sending unit 1102 is configured to send a first authentication request message to a first authentication server trusted by the authentication access controller. The first authentication request message includes ciphertext of the authentication access controller's identity information and the digital certificate of the requesting device. The ciphertext of the authentication access controller's identity information is generated by encrypting encrypted data, including the digital certificate of the authentication access controller, using the public key of the encryption certificate. The digital certificate of the requesting device is obtained by the authentication access controller by decrypting the ciphertext of the requesting device's identity information using the message encryption key.

[0437] The first receiving unit 1103 is configured to receive a first authentication response message sent by the first authentication server. The first authentication response message includes a first authentication result information ciphertext, a first digital signature, a second authentication result information, and a second digital signature. The first authentication result information ciphertext is obtained by encrypting information including the first authentication result information. The first authentication result information includes a first verification result of the digital certificate of the authentication access controller. The first digital signature is a digital signature calculated by the second authentication server trusted by the requesting device on signature data including the first authentication result information ciphertext. The second authentication result information includes a second verification result of the digital certificate of the requesting device. The second digital signature is a digital signature calculated by the first authentication server on signature data including the second authentication result information.

[0438] The first verification unit 1104 is used to verify the second digital signature using the public key of the first authentication server. If the verification passes, the first determining unit 1105 determines the identity authentication result of the requesting device based on the second verification result in the second authentication result information. When the first determining unit 1105 determines that the identity authentication result of the requesting device is valid, the second sending unit 1106 sends a third authentication response message to the requesting device; or...

[0439] The first verification unit 1104 is used to verify the second digital signature using the public key of the first authentication server. If the verification is successful, the second sending unit 1106 sends a third authentication response message to the requesting device, and the first determining unit 1105 determines the identity authentication result of the requesting device based on the second verification result in the second authentication result information; or...

[0440] The first verification unit 1104 is used to verify the second digital signature using the public key of the first authentication server; if the second digital signature is verified, the first determination unit 1105 determines the identity authentication result of the requesting device based on the second verification result in the second authentication result information; the second sending unit 1106 sends a third authentication response message to the requesting device.

[0441] The third authentication response message includes ciphertext of authentication result information, which is generated by encrypting encrypted data, including the first ciphertext of authentication result information and the first digital signature, using the message encryption key.

[0442] Optionally, the authentication access controller further includes:

[0443] The third sending unit is used to send a key request message to the requesting device, the key request message including the key exchange parameters of the authentication access controller; the identity ciphertext message obtained by the acquisition unit 1101 also includes the key exchange parameters of the requesting device.

[0444] The calculation unit is configured to perform key exchange calculations to generate a first key based on the temporary private key corresponding to the key exchange parameters of the authentication access controller and the temporary public key included in the key exchange parameters of the requesting device, and to calculate the message encryption key using a key derivation algorithm based on information including the first key.

[0445] Optionally, the key request message sent by the third sending unit further includes a first random number generated by the authentication access controller; the identity ciphertext message acquired by the acquisition unit 1101 further includes a second random number generated by the requesting device.

[0446] The calculation unit is specifically used to calculate the message encryption key based on information including the first key, the first random number, and the second random number.

[0447] Optionally, the identity encrypted message acquired by the acquisition unit 1101 further includes the first random number; then the authentication access controller further includes:

[0448] The second verification unit is used to verify the consistency between the first random number in the identity encrypted message and the first random number generated by the authentication access controller.

[0449] Optionally, if the key request message sent by the third sending unit also includes security capability parameter information supported by the authentication access controller, then the identity ciphertext message obtained by the obtaining unit 1101 also includes a specific security policy, which is determined by the requesting device based on the security capability parameter information supported by the authentication access controller.

[0450] Optionally, the key request message sent by the third sending unit may also include the identity identifier of at least one authentication server trusted by the authentication access controller; the identity ciphertext message obtained by the obtaining unit 1101 may also include the identity identifier of at least one authentication server trusted by the requesting device.

[0451] The authentication access controller further includes:

[0452] The second determining unit is configured to determine the first authentication server based on the identity identifier of at least one authentication server trusted by the requesting device in the identity encrypted message and the identity identifier of at least one authentication server trusted by the authentication access controller in the key request message.

[0453] Optionally, the identity encrypted message acquired by the acquisition unit 1101 may further include the identity identifier of at least one authentication server that the requesting device trusts; the authentication access controller may further include:

[0454] The third determining unit is used to determine the first authentication server based on the identity identifier of at least one authentication server trusted by the requesting device and the identity identifier of the authentication server trusted by the authentication access controller.

[0455] Optionally, the encrypted data of the authentication access controller's identity information ciphertext further includes the authentication access controller's identity identifier and a first protection random number;

[0456] Correspondingly, the first authentication response message also includes the encrypted identity of the authentication access controller, which is generated by encrypting information including the identity of the authentication access controller using the first protection random number;

[0457] The authentication access controller further includes:

[0458] The third verification unit is used to verify the encrypted identity of the authentication access controller based on the first protected random number of the authentication access controller's own identity identifier.

[0459] Optionally, the encrypted data of the authentication access controller's identity information ciphertext further includes a second protection random number; correspondingly, the first authentication result information ciphertext is obtained by encrypting information including the first authentication result information using the second protection random number;

[0460] The encrypted data of the authentication result information ciphertext in the third authentication response message sent by the second sending unit 1106 also includes the second protective random number.

[0461] Optionally, if the identity encrypted message acquired by the acquisition unit 1101 also includes the digital signature of the requesting device, then the first determining unit 1105 is further used to determine whether the digital signature of the requesting device has been verified. If the digital signature of the requesting device has been verified, then the identity authentication result of the requesting device is determined based on the second verification result.

[0462] Optionally, the first determining unit 1105 is specifically used for:

[0463] The digital signature of the requesting device is verified using the digital certificate of the requesting device obtained by decrypting the ciphertext of the requesting device's identity information, and the verification result determines whether the digital signature of the requesting device has passed verification; or...

[0464] When the second authentication server verifies the digital signature of the requesting device using the digital certificate of the requesting device, if the first receiving unit 1103 receives the first authentication response message, then the first determining unit 1105 determines that the digital signature of the requesting device has been verified successfully; or...

[0465] When the second authentication result information also includes the digital certificate of the requesting device, after the first receiving unit 1103 receives the first authentication response message, the first determining unit 1105 uses the digital certificate of the requesting device in the second authentication result information to verify the digital signature of the requesting device, and determines whether the digital signature of the requesting device has passed verification based on the verification result; or...

[0466] If the second authentication result information also includes the digital certificate of the requesting device, the first determining unit 1105 first determines the consistency between the digital certificate of the requesting device in the second authentication result information and the digital certificate of the requesting device obtained by decrypting the ciphertext of the identity information of the requesting device; if they are consistent, the first determining unit 1105 then uses the digital certificate of the requesting device to verify the digital signature of the requesting device, and determines whether the digital signature of the requesting device has been verified based on the verification result.

[0467] Optionally, the third authentication response message sent by the second sending unit 1106 also includes a message integrity check code. The message integrity check code is generated by the calculation unit using a message integrity check key to calculate other fields in the third authentication response message besides the message integrity check code. The message integrity check key is generated in the same way as the message encryption key.

[0468] Optionally, the message sent by the authentication access controller to the requesting device may further include a hash value calculated by the authentication access controller for the latest preamble message received from the requesting device; the message sent by the authentication access controller to the first authentication server may further include a hash value calculated by the authentication access controller for the latest preamble message received from the first authentication server.

[0469] based on Figures 1 to 10 For a corresponding embodiment, see Figure 12 This application provides a request device REQ, including:

[0470] The sending unit 1201 is used to send an identity encrypted message to the authentication access controller. The identity encrypted message includes the identity information encrypted message of the requesting device. The identity information encrypted message of the requesting device is generated by encrypting encrypted data, including the digital certificate of the requesting device, using a message encryption key.

[0471] The first receiving unit 1202 is configured to receive a third authentication response message sent by the authentication access controller. The third authentication response message includes ciphertext of authentication result information, which is generated by encrypting encrypted data including the first authentication result information and the first digital signature using a message encryption key. The first authentication result information is obtained by encrypting information including the first authentication result information, which includes a first verification result of the digital certificate of the authentication access controller.

[0472] The first decryption unit 1203 is used to decrypt the authentication result information ciphertext using the message encryption key to obtain the first authentication result information ciphertext and the first digital signature;

[0473] The first verification unit 1204 is used to verify the first digital signature using the public key of the second authentication server;

[0474] The first determining unit 1205 is used to determine the identity authentication result of the authentication access controller based on the first verification result in the first authentication result information obtained by decrypting the first authentication result information ciphertext when the first digital signature verification is successful.

[0475] Optionally, the requesting device further includes:

[0476] The second receiving unit is configured to receive a key request message sent by the authentication access controller, wherein the key request message includes key exchange parameters of the authentication access controller;

[0477] The calculation unit is configured to perform key exchange calculation to generate a first key based on the temporary private key corresponding to the key exchange parameters of the requesting device and the temporary public key included in the key exchange parameters of the authentication access controller, and to calculate the message encryption key using a key derivation algorithm based on information including the first key.

[0478] The encrypted identity message sent by the sending unit 1201 also includes the key exchange parameters of the requesting device.

[0479] Optionally, the key request message received by the second receiving unit may also include a first random number generated by the authentication access controller;

[0480] The calculation unit is specifically used to calculate the message encryption key based on information including the first key, the first random number, and the second random number generated by the requesting device;

[0481] Correspondingly, the identity encrypted message sent by the sending unit 1201 also includes the second random number.

[0482] Optionally, the encrypted identity message sent by the sending unit 1201 may also include the first random number.

[0483] Optionally, the key request message received by the second receiving unit further includes security capability parameter information supported by the authentication access controller, and the requesting device further includes:

[0484] The second determining unit is used to determine the specific security policy used by the requesting device based on the security capability parameter information supported by the authentication access controller; then the identity encrypted message sent by the sending unit 1201 also includes the specific security policy used by the requesting device.

[0485] Optionally, the key request message received by the second receiving unit further includes the identity identifier of at least one authentication server trusted by the authentication access controller; then the requesting device further includes:

[0486] The third determining unit is used to determine the identity identifier of at least one authentication server trusted by the requesting device based on the identity identifier of at least one authentication server trusted by the authentication access controller.

[0487] The encrypted identity message sent by the sending unit 1201 also includes the identity identifier of at least one authentication server trusted by the requesting device.

[0488] Optionally, the encrypted identity message sent by the sending unit 1201 may also include the identity identifier of at least one authentication server trusted by the requesting device.

[0489] Optionally, the encrypted data of the encrypted identity information of the requesting device sent by the sending unit 1201 further includes the identity identifier of the requesting device; correspondingly, the encrypted data of the encrypted authentication result information in the third authentication response message received by the first receiving unit 1202 further includes the identity identifier of the requesting device; then the requesting device further includes:

[0490] The second verification unit is used to verify the consistency between the identity identifier of the requesting device obtained by decrypting the ciphertext of the authentication result information and the identity identifier of the requesting device itself.

[0491] Optionally, the encrypted data of the authentication result information ciphertext in the third authentication response message received by the first receiving unit 1202 may further include a second protection random number;

[0492] The first decryption unit 1203 uses the message encryption key to decrypt the ciphertext of the authentication result information to obtain the second protection random number, and uses the second protection random number to decrypt the ciphertext of the first authentication result information to obtain the first authentication result information.

[0493] Optionally, before determining the identity authentication result of the authentication access controller, the first determining unit 1205 is further configured to determine whether the digital signature of the authentication access controller has been verified. If the digital signature of the authentication access controller has been verified, the identity authentication result of the authentication access controller is then determined based on the first verification result.

[0494] Optionally, the first determining unit 1205 is specifically used for:

[0495] When the authentication access controller sends a first authentication request message to its trusted first authentication server, including the digital signature of the authentication access controller, the first authentication server verifies the digital signature of the authentication access controller using the digital certificate of the authentication access controller obtained by decrypting the ciphertext of the authentication access controller's identity information. If the first receiving unit 1202 receives the third authentication response message, the first determining unit 1205 determines that the digital signature of the authentication access controller has been verified successfully; or...

[0496] When the third authentication response message also includes the digital signature of the authentication access controller, the first authentication result information obtained by decrypting the encrypted first authentication result information also includes the digital certificate of the authentication access controller; then the first determining unit 1205 uses the digital certificate of the authentication access controller to verify the digital signature of the authentication access controller, and determines whether the digital signature of the authentication access controller has been verified based on the verification result.

[0497] Optionally, the third authentication response message received by the first receiving unit 1202 further includes a message integrity check code; the requesting device further includes:

[0498] The third verification unit is used to verify the message integrity verification code using the message integrity verification key; the message integrity verification key is generated in the same way as the message encryption key.

[0499] Optionally, the message sent by the requesting device to the authentication access controller may also include a hash value calculated by the requesting device for the latest preceding message sent by the authentication access controller.

[0500] based on Figures 1 to 10 For a corresponding embodiment, see Figure 13 This application provides a first authentication server AS-AAC, which is an authentication server trusted by the authentication access controller, including:

[0501] The first receiving unit 1301 is used to receive a first authentication request message sent by the authentication access controller. The first authentication request message includes the ciphertext of the authentication access controller's identity information and the digital certificate of the requesting device. The ciphertext of the authentication access controller's identity information is generated by encrypting encrypted data, including the digital certificate of the authentication access controller, using the public key of the encryption certificate.

[0502] The first sending unit 1302 is configured to send a first authentication response message to the authentication access controller. The first authentication response message includes a first authentication result information ciphertext, a first digital signature, a second authentication result information, and a second digital signature. The first authentication result information ciphertext is obtained by encrypting information including the first authentication result information. The first authentication result information includes a first verification result of the digital certificate of the authentication access controller. The first digital signature is a digital signature calculated by a second authentication server trusted by the requesting device on signature data including the first authentication result information ciphertext. The second authentication result information includes a second verification result of the digital certificate of the requesting device. The second digital signature is a digital signature calculated by the first authentication server on signature data including the second authentication result information.

[0503] Optionally, if the first authentication request message received by the first receiving unit 1301 further includes the digital signature of the authentication access controller, then the first authentication server further includes:

[0504] The first verification unit is used to verify the digital signature of the authentication access controller by using the digital certificate of the authentication access controller obtained by decrypting the ciphertext of the identity information of the authentication access controller.

[0505] Optionally, if the first authentication server trusted by the authentication access controller and the second authentication server trusted by the requesting device are the same authentication server, then the first authentication server further includes:

[0506] The first decryption unit is used to decrypt the ciphertext of the identity information of the authentication access controller using the private key corresponding to the encryption certificate to obtain the digital certificate of the authentication access controller.

[0507] The second verification unit is used to verify the legitimacy of the digital certificate of the authentication access controller obtained by decryption to obtain a first verification result, and to verify the legitimacy of the digital certificate of the requesting device to obtain a second verification result.

[0508] The first generation unit is configured to generate first authentication result information based on information including the first verification result, generate ciphertext of the first authentication result information, generate second authentication result information based on information including the second verification result, calculate and generate a first digital signature on signature data including the ciphertext of the first authentication result information, calculate and generate a second digital signature on signature data including the second authentication result information, and generate the first authentication response message based on information including the ciphertext of the first authentication result information, the first digital signature, the second authentication result information, and the second digital signature.

[0509] Optionally, if the first authentication server trusted by the authentication access controller and the second authentication server trusted by the requesting device are two different authentication servers, then the first authentication server further includes:

[0510] The third verification unit is used to decrypt the ciphertext of the identity information of the authentication access controller using the private key corresponding to the encryption certificate to obtain the digital certificate of the authentication access controller, and to verify the legality of the digital certificate of the authentication access controller to obtain the first verification result.

[0511] The second generation unit is used to generate first authentication result information based on information including the first verification result, and then generate encrypted first authentication result information.

[0512] The second sending unit is configured to send a second authentication request message to the second authentication server. The second authentication request message includes the first authentication result information ciphertext, the digital certificate of the requesting device, and the third digital signature of the first authentication server. The third digital signature is a digital signature calculated and generated by the first authentication server from the signature data including the first authentication result information ciphertext and the digital certificate of the requesting device.

[0513] The second receiving unit is configured to receive a second authentication response message sent by the second authentication server. The second authentication response message includes the first authentication result information ciphertext, the first digital signature, the second authentication result information, and a fourth digital signature. The first digital signature is a digital signature calculated and generated by the second authentication server on the signature data including the first authentication result information ciphertext, and the fourth digital signature is a digital signature calculated and generated by the second authentication server on the signature data including the second authentication result information.

[0514] The fourth verification unit is used to verify the fourth digital signature using the public key of the second authentication server;

[0515] The third generation unit is used to calculate and generate a second digital signature from the signature data, including the second authentication result information, when the fourth digital signature verification is successful, and to generate the first authentication response message based on the information including the first authentication result information ciphertext, the first digital signature, the second authentication result information, and the second digital signature.

[0516] Optionally, the message sent by the first authentication server to the authentication access controller may also include a hash value calculated by the first authentication server for the latest preceding message received from the authentication access controller; the message sent by the first authentication server to the second authentication server may also include a hash value calculated by the first authentication server for the latest preceding message received from the second authentication server.

[0517] based on Figures 1 to 10 For a corresponding embodiment, see Figure 14 This application provides a second authentication server AS-REQ, which is an authentication server requesting device trust. If the first authentication server trusted by the authentication access controller and the second authentication server requesting device trust are two different authentication servers, then the second authentication server includes:

[0518] The receiving unit 1401 is configured to receive a second authentication request message sent by the first authentication server. The second authentication request message includes encrypted first authentication result information, the digital certificate of the requesting device, and a third digital signature of the first authentication server. The third digital signature is a digital signature calculated and generated by the first authentication server on signature data including the encrypted first authentication result information and the digital certificate of the requesting device.

[0519] The first verification unit 1402 is used to verify the third digital signature;

[0520] The second verification unit 1403 is used to verify the legality of the digital certificate of the requesting device to obtain a second verification result when the third digital signature verification is passed.

[0521] The generation unit 1404 is used to generate second authentication result information based on information including the second verification result.

[0522] The sending unit 1405 is used to send a second authentication response message to the first authentication server. The second authentication response message includes the first authentication result information ciphertext, a first digital signature, the second authentication result information, and a fourth digital signature. The first digital signature is a digital signature calculated and generated by the second authentication server on the signature data including the first authentication result information ciphertext. The fourth digital signature is a digital signature calculated and generated by the second authentication server on the signature data including the second authentication result information.

[0523] Optionally, the message sent by the second authentication server to the first authentication server may also include a hash value calculated by the second authentication server for the latest preceding message received from the first authentication server.

[0524] Those skilled in the art will understand that all or part of the steps of the above method embodiments can be implemented by hardware related to program instructions. The aforementioned program can be stored in a computer-readable storage medium. When the program is executed, it performs the steps of the above method embodiments. The aforementioned storage medium can be at least one of the following media: read-only memory (ROM), RAM, magnetic disk, or optical disk, etc., and other media capable of storing program code.

[0525] It should be noted that the various embodiments in this specification are described in a progressive manner, and the same or similar parts between the various embodiments can be referred to mutually. Each embodiment focuses on describing the differences from other embodiments. In particular, for the device and system embodiments, since they are consistent with and correspond to the method embodiments, the description is relatively simple, and relevant parts can be referred to the description of the method embodiments. The device and system embodiments described above are merely illustrative, and the units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of the modules can be selected to achieve the purpose of this embodiment according to actual needs. Those skilled in the art can understand and implement this without creative effort.

[0526] The above description is merely one specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the technical scope disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.

Claims

1. A method for identity verification, characterized in that, The method includes: The authentication access controller obtains the identity encrypted message sent by the requesting device. The identity encrypted message includes the identity information encrypted of the requesting device. The identity information encrypted of the requesting device is generated by encrypting encrypted data, including the digital certificate of the requesting device, using a message encryption key. The authentication access controller sends a first authentication request message to a first authentication server it trusts. The first authentication request message includes the ciphertext of the authentication access controller's identity information and the digital certificate of the requesting device. The ciphertext of the authentication access controller's identity information is generated by encrypting encrypted data, including the digital certificate of the authentication access controller, using the public key of the encryption certificate. The digital certificate of the requesting device is obtained by the authentication access controller by decrypting the ciphertext of the requesting device's identity information using the message encryption key. The authentication access controller receives a first authentication response message sent by the first authentication server. The first authentication response message includes a first authentication result information ciphertext, a first digital signature, a second authentication result information, and a second digital signature. The first authentication result information ciphertext is obtained by encrypting information including the first authentication result information. The first authentication result information includes a first verification result of the digital certificate of the authentication access controller. The first digital signature is a digital signature calculated by the second authentication server trusted by the requesting device on signature data including the first authentication result information ciphertext. The second authentication result information includes a second verification result of the digital certificate of the requesting device. The second digital signature is a digital signature calculated by the first authentication server on signature data including the second authentication result information. The authentication access controller verifies the second digital signature using the public key of the first authentication server. If the verification passes, the authentication access controller determines the authentication result of the requesting device based on the second verification result in the second authentication result information. When the authentication access controller determines that the authentication result of the requesting device is valid, it sends a third authentication response message to the requesting device; or... The authentication access controller verifies the second digital signature using the public key of the first authentication server. If the verification passes, the authentication access controller sends a third authentication response message to the requesting device and determines the authentication result of the requesting device based on the second verification result in the second authentication result information; or, The authentication access controller uses the public key of the first authentication server to verify the second digital signature; if the second digital signature is verified, the authentication access controller determines the identity authentication result of the requesting device based on the second verification result in the second authentication result information; the authentication access controller sends a third authentication response message to the requesting device. The third authentication response message includes ciphertext of authentication result information, which is generated by encrypting encrypted data, including the first ciphertext of authentication result information and the first digital signature, using the message encryption key. After receiving the third authentication response message, the requesting device decrypts the ciphertext of the authentication result information using the message encryption key to obtain the first ciphertext of the authentication result information and the first digital signature. The requesting device verifies the first digital signature using the public key of the second authentication server. If the verification is successful, the requesting device determines the identity authentication result of the authentication access controller based on the first verification result in the first authentication result information obtained by decrypting the first ciphertext of the authentication result information.

2. The method according to claim 1, characterized in that, Before the authentication access controller obtains the encrypted identity message sent by the requesting device, the method further includes: The authentication access controller sends a key request message to the requesting device, the key request message including the key exchange parameters of the authentication access controller; The requesting device generates a first key by performing a key exchange calculation based on the temporary private key corresponding to the key exchange parameters of the requesting device and the temporary public key included in the key exchange parameters of the authentication access controller, and calculates the message encryption key using a key derivation algorithm based on information including the first key. Correspondingly, the identity encrypted message also includes the key exchange parameters of the requesting device; The authentication access controller generates the first key by performing key exchange calculation based on the temporary private key corresponding to the key exchange parameters of the authentication access controller and the temporary public key included in the key exchange parameters of the requesting device, and calculates the message encryption key using the key derivation algorithm based on information including the first key.

3. The method according to claim 2, characterized in that, The key request message also includes a first random number generated by the authentication access controller; The requesting device further includes calculating the message encryption key as follows: The requesting device calculates the message encryption key based on information including the first key, the first random number, and the second random number generated by the requesting device. Correspondingly, the encrypted identity message also includes the second random number; The authentication access controller further includes the following steps in calculating the message encryption key: The authentication access controller calculates the message encryption key based on information including the first key, the first random number, and the second random number.

4. The method according to claim 3, characterized in that, The encrypted identity message also includes the first random number; Before the authentication access controller calculates the message encryption key, the method further includes: The authentication access controller verifies the consistency between the first random number in the identity encrypted message and the first random number generated by the authentication access controller. If the verification passes, the authentication access controller then calculates the message encryption key.

5. The method according to claim 2, characterized in that, The key request message also includes security capability parameter information supported by the authentication access controller, and the method further includes: The requesting device determines the specific security policy used by the requesting device based on the security capability parameter information; then the identity encrypted message also includes the specific security policy.

6. The method according to claim 2, characterized in that, The key request message also includes the identity identifier of at least one authentication server trusted by the authentication access controller; The method further includes: The requesting device determines the identity of at least one authentication server trusted by the authentication access controller based on the identity of at least one authentication server trusted by the requesting device. The encrypted identity message also includes the identity identifier of at least one authentication server trusted by the requesting device; The method further includes: The authentication access controller determines the first authentication server based on the identity identifier of at least one authentication server trusted by the requesting device in the identity ciphertext message and the identity identifier of at least one authentication server trusted by the authentication access controller in the key request message.

7. The method according to claim 1, characterized in that, The encrypted identity message also includes the identity identifier of at least one authentication server that the requesting device trusts; The method further includes: The authentication access controller determines the first authentication server based on the identity identifier of at least one authentication server trusted by the requesting device and the identity identifier of the authentication server trusted by the authentication access controller.

8. The method according to claim 1, characterized in that, The encrypted data of the requested device's identity information ciphertext also includes the identity identifier of the requested device; The encrypted data of the authentication access controller's identity information ciphertext also includes the authentication access controller's identity identifier and a first protection random number; The first authentication request message also includes the identity identifier of the requesting device, wherein the identity identifier of the requesting device is obtained by the authentication access controller decrypting the ciphertext of the identity information of the requesting device using the message encryption key; Correspondingly, the first authentication response message also includes the identity identifier of the requesting device and the encrypted identity identifier of the authentication access controller. The encrypted identity identifier of the authentication access controller is generated by encrypting information including the identity identifier of the authentication access controller using the first protection random number. Before the authentication access controller determines the authentication result of the requesting device, the method further includes: The authentication access controller verifies the encrypted identity of the authentication access controller based on its own identity identifier and the first protection random number. After the verification is successful, the authentication access controller then determines the identity authentication result of the requesting device. Correspondingly, the encrypted data of the authentication result information ciphertext in the third authentication response message also includes the identity identifier of the requesting device; therefore, before the requesting device determines the identity authentication result of the authentication access controller, the method further includes: The requesting device decrypts the ciphertext of the authentication result information to obtain the identity identifier of the requesting device, and performs consistency verification with the identity identifier of the requesting device itself. After the verification is successful, the requesting device then determines the identity authentication result of the authentication access controller.

9. The method according to claim 1, characterized in that, The encrypted data of the authentication access controller's identity information ciphertext also includes a second protection random number. Correspondingly, the first authentication result information ciphertext is obtained by encrypting information including the first authentication result information using the second protection random number. The encrypted data of the authentication result information ciphertext in the third authentication response message also includes the second protective random number; The requesting device then uses the message encryption key to decrypt the ciphertext of the authentication result information to obtain the second protection random number, and uses the second protection random number to decrypt the ciphertext of the first authentication result information to obtain the first authentication result information.

10. The method according to claim 1, characterized in that, Before the requesting device determines the authentication result of the authentication access controller, the method further includes: The requesting device determines whether the digital signature of the authentication access controller has been verified. If the digital signature of the authentication access controller has been verified, the requesting device then determines the identity authentication result of the authentication access controller.

11. The method according to claim 10, characterized in that, The requesting device determines whether the digital signature of the authentication access controller has been verified, specifically including: If the first authentication request message also includes the digital signature of the authentication access controller, then the first authentication server uses the digital certificate of the authentication access controller obtained by decrypting the ciphertext of the authentication access controller's identity information to verify the digital signature of the authentication access controller. If the requesting device receives the third authentication response message, then the requesting device determines that the digital signature of the authentication access controller has been verified successfully; or... If the third authentication response message also includes the digital signature of the authentication access controller, then the first authentication result information obtained by the requesting device after decrypting the encrypted first authentication result information also includes the digital certificate of the authentication access controller. The requesting device uses the decrypted digital certificate of the authentication access controller to verify the digital signature of the authentication access controller, and determines whether the digital signature of the authentication access controller has been verified based on the verification result.

12. The method according to claim 1, characterized in that, If the encrypted identity message also includes the digital signature of the requesting device, then before the authentication access controller determines the identity authentication result of the requesting device, the method further includes: The authentication access controller determines whether the digital signature of the requesting device has been verified. If the digital signature of the requesting device has been verified, the authentication access controller then determines the identity authentication result of the requesting device.

13. The method according to claim 12, characterized in that, The authentication access controller determines whether the digital signature of the requesting device has been verified, specifically including: The authentication access controller verifies the digital signature of the requesting device using the digital certificate obtained by decrypting the ciphertext of the requesting device's identity information, and determines whether the digital signature of the requesting device has passed verification based on the verification result; or... The second authentication server verifies the digital signature of the requesting device using the requesting device's digital certificate. If the authentication access controller receives the first authentication response message, it determines that the digital signature of the requesting device has been verified successfully; or... If the second authentication result information also includes the digital certificate of the requesting device, then after receiving the first authentication response message, the authentication access controller uses the digital certificate of the requesting device in the second authentication result information to verify the digital signature of the requesting device, and determines whether the digital signature of the requesting device has passed verification based on the verification result; or... If the second authentication result information also includes the digital certificate of the requesting device, then the authentication access controller verifies the consistency between the digital certificate of the requesting device in the second authentication result information and the digital certificate of the requesting device obtained by decrypting the ciphertext of the identity information of the requesting device; if they are consistent, then the authentication access controller uses the digital certificate of the requesting device to verify the digital signature of the requesting device, and determines whether the digital signature of the requesting device has been verified based on the verification result.

14. The method according to claim 2, characterized in that, The method further includes: The third authentication response message also includes a message integrity check code, which is generated by the authentication access controller using a message integrity check key to calculate other fields in the third authentication response message besides the message integrity check code; the message integrity check key of the authentication access controller is generated in the same way as the message encryption key of the authentication access controller. The requesting device uses the message integrity verification key to verify the message integrity verification code; if the verification is successful, the requesting device then executes the step of determining the authentication result of the authentication access controller; the message integrity verification key of the requesting device is generated in the same way as the message encryption key of the requesting device.

15. The method according to any one of claims 1 to 14, characterized in that, If the first authentication server trusted by the authentication access controller and the second authentication server trusted by the requesting device are the same authentication server, then before the first authentication server sends the first authentication response message, the method further includes: The first authentication server verifies the legitimacy of the digital certificate of the authentication access controller obtained by decrypting the ciphertext of the identity information of the authentication access controller using the private key corresponding to the encryption certificate, and obtains a first verification result. It then verifies the legitimacy of the digital certificate of the requesting device, and obtains a second verification result. Based on the information including the first verification result, it generates the first authentication result information, generates the ciphertext of the first authentication result information, and generates the second authentication result information based on the information including the second verification result. It calculates and generates a first digital signature on the signature data including the ciphertext of the first authentication result information, calculates and generates a second digital signature on the signature data including the second authentication result information, and generates the first authentication response message based on the information including the ciphertext of the first authentication result information, the first digital signature, the second authentication result information, and the second digital signature.

16. The method according to any one of claims 1 to 14, characterized in that, The first authentication server trusted by the authentication access controller and the second authentication server trusted by the requesting device are two different authentication servers; Before the first authentication server sends the first authentication response message, the method further includes: The first authentication server performs a legality verification on the digital certificate of the authentication access controller obtained by decrypting the ciphertext of the identity information of the authentication access controller using the private key corresponding to the encryption certificate, and obtains a first verification result. Based on the information including the first verification result, it generates first authentication result information and then generates the ciphertext of the first authentication result information. The first authentication server sends a second authentication request message to the second authentication server. The second authentication request message includes the encrypted first authentication result information, the digital certificate of the requesting device, and a third digital signature. The third digital signature is a digital signature calculated and generated by the first authentication server on the signature data including the encrypted first authentication result information and the digital certificate of the requesting device. The second authentication server verifies the third digital signature. After successful verification, it verifies the legality of the digital certificate of the requesting device to obtain a second verification result. Based on the information including the second verification result, it generates second authentication result information and sends a second authentication response message to the first authentication server. The second authentication response message includes the encrypted first authentication result information, the first digital signature, the second authentication result information, and a fourth digital signature. The fourth digital signature is a digital signature calculated and generated by the second authentication server based on the signature data including the second authentication result information. The first authentication server receives the second authentication response message and verifies the fourth digital signature using the public key of the second authentication server. If the verification is successful, the first authentication server calculates and generates a second digital signature based on the signature data including the second authentication result information, and generates the first authentication response message based on the information including the first authentication result information ciphertext, the first digital signature, the second authentication result information, and the second digital signature.

17. The method according to any one of claims 1 to 14, characterized in that, The message sent by the requesting device to the authentication access controller also includes a hash value calculated by the requesting device for the latest preceding message received from the authentication access controller; When the authentication access controller receives a message from the requesting device, it first verifies the hash value in the received message, and then performs subsequent operations after the verification is successful. The message sent by the authentication access controller to the requesting device also includes a hash value calculated by the authentication access controller for the latest preceding message sent by the requesting device. When the requesting device receives a message from the authentication access controller, it first verifies the hash value in the received message, and then performs subsequent operations after the verification is successful. The message sent by the authentication access controller to the first authentication server also includes a hash value calculated by the authentication access controller for the latest preceding message received from the first authentication server; When the first authentication server receives a message from the authentication access controller, it first verifies the hash value in the received message, and then performs subsequent operations after the verification is successful. The message sent by the first authentication server to the authentication access controller also includes a hash value calculated by the first authentication server for the latest preceding message sent by the authentication access controller. When the authentication access controller receives a message from the first authentication server, it first verifies the hash value in the received message, and then performs subsequent operations after the verification is successful. The message sent by the first authentication server to the second authentication server also includes a hash value calculated by the first authentication server for the latest preceding message received from the second authentication server; When the second authentication server receives a message from the first authentication server, it first verifies the hash value in the received message, and then performs subsequent operations after the verification is successful. The message sent by the second authentication server to the first authentication server also includes a hash value calculated by the second authentication server for the latest preceding message sent by the first authentication server. When the first authentication server receives a message from the second authentication server, it first verifies the hash value in the received message, and then performs subsequent operations after the verification is successful.

18. An authentication access controller, characterized in that, The authentication access controller includes: The acquisition unit is used to acquire the identity ciphertext message sent by the requesting device. The identity ciphertext message includes the identity information ciphertext of the requesting device, which is generated by encrypting encrypted data, including the digital certificate of the requesting device, using a message encryption key. The first sending unit is configured to send a first authentication request message to a first authentication server trusted by the authentication access controller. The first authentication request message includes the ciphertext of the authentication access controller's identity information and the digital certificate of the requesting device. The ciphertext of the authentication access controller's identity information is generated by encrypting encrypted data, including the digital certificate of the authentication access controller, using the public key of the encryption certificate. The digital certificate of the requesting device is obtained by the authentication access controller by decrypting the ciphertext of the requesting device's identity information using the message encryption key. The first receiving unit is configured to receive a first authentication response message sent by the first authentication server. The first authentication response message includes first authentication result information ciphertext, a first digital signature, second authentication result information, and a second digital signature. Specifically, the first authentication result information ciphertext is obtained by encrypting information including the first authentication result information; the first authentication result information includes a first verification result of the digital certificate of the authentication access controller; the first digital signature is a digital signature calculated by the second authentication server trusted by the requesting device on signature data including the first authentication result information ciphertext; the second authentication result information includes a second verification result of the digital certificate of the requesting device; and the second digital signature is a digital signature calculated by the first authentication server on signature data including the second authentication result information. A first verification unit is used to verify the second digital signature using the public key of the first authentication server. If the verification passes, a first determining unit determines the authentication result of the requesting device based on the second verification result in the second authentication result information. When the first determining unit determines that the authentication result of the requesting device is valid, a second sending unit sends a third authentication response message to the requesting device; or... The second sending unit verifies the second digital signature using the public key of the first authentication server. If the verification passes, the second sending unit sends a third authentication response message to the requesting device, and the first determining unit determines the authentication result of the requesting device based on the second verification result in the second authentication result information; or... The first unit is used to verify the second digital signature using the public key of the first authentication server; if the second digital signature is verified, the first determining unit determines the identity authentication result of the requesting device based on the second verification result in the second authentication result information; the second sending unit sends a third authentication response message to the requesting device. The third authentication response message includes ciphertext of authentication result information, which is generated by encrypting encrypted data, including the first ciphertext of authentication result information and the first digital signature, using the message encryption key.

19. The authentication access controller according to claim 18, characterized in that, The authentication access controller further includes: The third sending unit is used to send a key request message to the requesting device, the key request message including the key exchange parameters of the authentication access controller; the identity ciphertext message obtained by the acquisition unit also includes the key exchange parameters of the requesting device. The calculation unit is configured to perform key exchange calculations to generate a first key based on the temporary private key corresponding to the key exchange parameters of the authentication access controller and the temporary public key included in the key exchange parameters of the requesting device, and to calculate the message encryption key using a key derivation algorithm based on information including the first key.

20. The authentication access controller according to claim 19, characterized in that, The key request message sent by the third sending unit also includes a first random number generated by the authentication access controller; the identity ciphertext message acquired by the acquisition unit also includes a second random number generated by the requesting device. The calculation unit is specifically used to calculate the message encryption key based on information including the first key, the first random number, and the second random number.

21. The authentication access controller according to claim 20, characterized in that, The identity encrypted message acquired by the acquisition unit also includes the first random number; therefore, the authentication access controller further includes: The second verification unit is used to verify the consistency between the first random number in the identity encrypted message and the first random number generated by the authentication access controller.

22. The authentication access controller according to claim 19, characterized in that, The key request message sent by the third sending unit also includes security capability parameter information supported by the authentication access controller. Therefore, the identity ciphertext message obtained by the obtaining unit also includes a specific security policy, which is determined by the requesting device based on the security capability parameter information supported by the authentication access controller.

23. The authentication access controller according to claim 19, characterized in that, The key request message sent by the third sending unit also includes the identity identifier of at least one authentication server trusted by the authentication access controller; the identity ciphertext message obtained by the obtaining unit also includes the identity identifier of at least one authentication server trusted by the requesting device. The authentication access controller further includes: The second determining unit is configured to determine the first authentication server based on the identity identifier of at least one authentication server trusted by the requesting device in the identity encrypted message and the identity identifier of at least one authentication server trusted by the authentication access controller in the key request message.

24. The authentication access controller according to claim 18, characterized in that, The encrypted identity message acquired by the acquisition unit also includes the identity identifier of at least one authentication server trusted by the requesting device; The authentication access controller further includes: The third determining unit is used to determine the first authentication server based on the identity identifier of at least one authentication server trusted by the requesting device and the identity identifier of the authentication server trusted by the authentication access controller.

25. The authentication access controller according to claim 18, characterized in that, The encrypted data of the authentication access controller's identity information ciphertext also includes the authentication access controller's identity identifier and a first protection random number; Correspondingly, the first authentication response message also includes the encrypted identity of the authentication access controller, which is generated by encrypting information including the identity of the authentication access controller using the first protection random number; The authentication access controller further includes: The third verification unit is used to verify the encrypted identity of the authentication access controller based on the authentication access controller's own identity identifier and the first protection random number.

26. The authentication access controller according to claim 18, characterized in that, The encrypted data of the authentication access controller's identity information ciphertext also includes a second protection random number; correspondingly, the first authentication result information ciphertext is obtained by encrypting information including the first authentication result information using the second protection random number. The encrypted data of the authentication result information ciphertext in the third authentication response message sent by the second sending unit also includes the second protective random number.

27. The authentication access controller according to claim 18, characterized in that, The identity encrypted message obtained by the acquisition unit also includes the digital signature of the requesting device. The first determining unit is further used to determine whether the digital signature of the requesting device has been verified. If the digital signature of the requesting device has been verified, the identity authentication result of the requesting device is determined according to the second verification result.

28. The authentication access controller according to claim 27, characterized in that, The first determining unit is specifically used for: The digital signature of the requesting device is verified using the digital certificate of the requesting device obtained by decrypting the ciphertext of the identity information of the requesting device, and the verification result is used to determine whether the digital signature of the requesting device has passed the verification. or, When the second authentication server verifies the digital signature of the requesting device using the requesting device's digital certificate, if the first receiving unit receives the first authentication response message, then the first determining unit determines that the digital signature of the requesting device has been verified successfully; or... When the second authentication result information also includes the digital certificate of the requesting device, after the first receiving unit receives the first authentication response message, the first determining unit uses the digital certificate of the requesting device in the second authentication result information to verify the digital signature of the requesting device, and determines whether the digital signature of the requesting device has passed verification based on the verification result; or... If the second authentication result information also includes the digital certificate of the requesting device, then the first determining unit first determines the consistency between the digital certificate of the requesting device in the second authentication result information and the digital certificate of the requesting device obtained by decrypting the ciphertext of the identity information of the requesting device; If they match, the first determining unit then uses the digital certificate of the requesting device to verify the digital signature of the requesting device, and determines whether the digital signature of the requesting device has passed verification based on the verification result.

29. The authentication access controller according to claim 19, characterized in that, The third authentication response message sent by the second sending unit also includes a message integrity check code. The message integrity check code is generated by the calculation unit using a message integrity check key to calculate other fields in the third authentication response message besides the message integrity check code. The message integrity check key is generated in the same way as the message encryption key.

30. The authentication access controller according to any one of claims 18 to 29, characterized in that, The message sent by the authentication access controller to the requesting device also includes a hash value calculated by the authentication access controller for the latest preamble message received from the requesting device; the message sent by the authentication access controller to the first authentication server also includes a hash value calculated by the authentication access controller for the latest preamble message received from the first authentication server.

31. A requesting device, characterized in that, The requesting device includes: The sending unit is used to send an identity ciphertext message to the authentication access controller. The identity ciphertext message includes the identity information ciphertext of the requesting device. The identity information ciphertext of the requesting device is generated by encrypting encrypted data, including the digital certificate of the requesting device, using a message encryption key. The first receiving unit is configured to receive a third authentication response message sent by the authentication access controller. The third authentication response message includes ciphertext of authentication result information, which is generated by encrypting encrypted data including ciphertext of the first authentication result information and a first digital signature using a message encryption key. The first ciphertext of the first authentication result information is obtained by encrypting information including the first authentication result information, which includes a first verification result of the digital certificate of the authentication access controller. The first digital signature is a digital signature calculated by the second authentication server trusted by the requesting device on signature data including the ciphertext of the first authentication result information. The first decryption unit is used to decrypt the ciphertext of the authentication result information using the message encryption key to obtain the first ciphertext of the authentication result information and the first digital signature; The first verification unit is used to verify the first digital signature using the public key of the second authentication server; The first determining unit is configured to determine the identity authentication result of the authentication access controller based on the first verification result in the first authentication result information obtained by decrypting the ciphertext of the first authentication result information when the first digital signature verification is successful.

32. The requesting device according to claim 31, characterized in that, The requesting device also includes: The second receiving unit is configured to receive a key request message sent by the authentication access controller, wherein the key request message includes key exchange parameters of the authentication access controller; The calculation unit is configured to perform key exchange calculation to generate a first key based on the temporary private key corresponding to the key exchange parameters of the requesting device and the temporary public key included in the key exchange parameters of the authentication access controller, and to calculate the message encryption key using a key derivation algorithm based on information including the first key. The encrypted identity message sent by the sending unit also includes the key exchange parameters of the requesting device.

33. The requesting device according to claim 32, characterized in that, The key request message received by the second receiving unit also includes a first random number generated by the authentication access controller; The calculation unit is specifically used to calculate the message encryption key based on information including the first key, the first random number, and the second random number generated by the requesting device; Correspondingly, the encrypted identity message sent by the sending unit also includes the second random number.

34. The requesting device according to claim 33, characterized in that, The encrypted identity message sent by the sending unit also includes the first random number.

35. The requesting device according to claim 32, characterized in that, The key request message received by the second receiving unit also includes security capability parameter information supported by the authentication access controller, and the requesting device further includes: The second determining unit is used to determine the specific security policy used by the requesting device based on the security capability parameter information supported by the authentication access controller; then the identity encrypted message sent by the sending unit also includes the specific security policy used by the requesting device.

36. The requesting device according to claim 32, characterized in that, The key request message received by the second receiving unit also includes the identity identifier of at least one authentication server trusted by the authentication access controller; The requesting device further includes: The third determining unit is used to determine the identity identifier of at least one authentication server trusted by the requesting device based on the identity identifier of at least one authentication server trusted by the authentication access controller. The encrypted identity message sent by the sending unit also includes the identity identifier of at least one authentication server trusted by the requesting device.

37. The requesting device according to claim 32, characterized in that, The encrypted identity message sent by the sending unit also includes the identity identifier of at least one authentication server trusted by the requesting device.

38. The requesting device according to claim 31, characterized in that, The encrypted data of the ciphertext of the identity information of the requesting device sent by the sending unit also includes the identity identifier of the requesting device; correspondingly, the encrypted data of the ciphertext of the authentication result information in the third authentication response message received by the first receiving unit also includes the identity identifier of the requesting device. The requesting device further includes: The second verification unit is used to verify the consistency between the identity identifier of the requesting device obtained by decrypting the ciphertext of the authentication result information and the identity identifier of the requesting device itself.

39. The requesting device according to claim 31, characterized in that, The encrypted data of the authentication result information ciphertext in the third authentication response message received by the first receiving unit also includes a second protection random number; The first decryption unit uses the message encryption key to decrypt the ciphertext of the authentication result information to obtain the second protection random number, and uses the second protection random number to decrypt the ciphertext of the first authentication result information to obtain the first authentication result information.

40. The requesting device according to claim 31, characterized in that, Before determining the identity authentication result of the authentication access controller, the first determining unit is also used to determine whether the digital signature of the authentication access controller has been verified. If the digital signature of the authentication access controller has been verified, the first determining unit then determines the identity authentication result of the authentication access controller based on the first verification result.

41. The requesting device according to claim 40, characterized in that, The first determining unit is specifically used for: When the authentication access controller sends a first authentication request message to its trusted first authentication server, including the authentication access controller's digital signature, the first authentication server verifies the authentication access controller's digital signature using the digital certificate obtained by decrypting the authentication access controller's ciphertext identity information. If the first receiving unit receives the third authentication response message, the first determining unit determines that the authentication access controller's digital signature has been verified successfully; or... When the third authentication response message also includes the digital signature of the authentication access controller, the first authentication result information obtained by decrypting the first authentication result information ciphertext also includes the digital certificate of the authentication access controller. The first determining unit then uses the digital certificate of the authentication access controller to verify the digital signature of the authentication access controller, and determines whether the digital signature of the authentication access controller has passed the verification based on the verification result.

42. The requesting device according to claim 32, characterized in that, The third authentication response message received by the first receiving unit also includes a message integrity check code; The requesting device also includes: The third verification unit is used to verify the message integrity verification code using the message integrity verification key; The message integrity verification key is generated in the same way as the message encryption key.

43. The requesting device according to any one of claims 31 to 42, characterized in that, The message sent by the requesting device to the authentication access controller also includes a hash value calculated by the requesting device for the latest preceding message received from the authentication access controller.

44. A first authentication server, characterized in that, The first authentication server is an authentication server trusted by the authentication access controller, including: The first receiving unit is configured to receive a first authentication request message sent by the authentication access controller. The first authentication request message includes the ciphertext of the authentication access controller's identity information and the digital certificate of the requesting device. The ciphertext of the authentication access controller's identity information is generated by encrypting encrypted data, including the digital certificate of the authentication access controller, using the public key of the encryption certificate. A first sending unit is configured to send a first authentication response message to the authentication access controller. The first authentication response message includes a first authentication result information ciphertext, a first digital signature, a second authentication result information, and a second digital signature. The first authentication result information ciphertext is obtained by encrypting information including the first authentication result information. The first authentication result information includes a first verification result of the digital certificate of the authentication access controller. The first digital signature is a digital signature calculated by a second authentication server trusted by the requesting device on signature data including the first authentication result information ciphertext. The second authentication result information includes a second verification result of the digital certificate of the requesting device. The second digital signature is a digital signature calculated by the first authentication server on signature data including the second authentication result information.

45. The first authentication server according to claim 44, characterized in that, If the first authentication request message received by the first receiving unit also includes the digital signature of the authentication access controller, then the first authentication server further includes: The first verification unit is used to verify the digital signature of the authentication access controller by using the digital certificate of the authentication access controller obtained by decrypting the ciphertext of the identity information of the authentication access controller.

46. ​​The first authentication server according to claim 44, characterized in that, The first authentication server trusted by the authentication access controller and the second authentication server trusted by the requesting device are the same authentication server; The first authentication server further includes: The first decryption unit is used to decrypt the ciphertext of the identity information of the authentication access controller using the private key corresponding to the encryption certificate to obtain the digital certificate of the authentication access controller. The second verification unit is used to verify the legitimacy of the digital certificate of the authentication access controller obtained by decryption to obtain a first verification result, and to verify the legitimacy of the digital certificate of the requesting device to obtain a second verification result. The first generation unit is configured to generate first authentication result information based on information including the first verification result, generate ciphertext of the first authentication result information, generate second authentication result information based on information including the second verification result, calculate and generate a first digital signature on signature data including the ciphertext of the first authentication result information, calculate and generate a second digital signature on signature data including the second authentication result information, and generate the first authentication response message based on information including the ciphertext of the first authentication result information, the first digital signature, the second authentication result information, and the second digital signature.

47. The first authentication server according to claim 44, characterized in that, The first authentication server trusted by the authentication access controller and the second authentication server trusted by the requesting device are two different authentication servers; The first authentication server further includes: The third verification unit is used to decrypt the ciphertext of the identity information of the authentication access controller using the private key corresponding to the encryption certificate to obtain the digital certificate of the authentication access controller, and to verify the legality of the digital certificate of the authentication access controller to obtain the first verification result. The second generation unit is used to generate first authentication result information based on information including the first verification result, and then generate encrypted first authentication result information. The second sending unit is configured to send a second authentication request message to the second authentication server. The second authentication request message includes the first authentication result information ciphertext, the digital certificate of the requesting device, and the third digital signature of the first authentication server. The third digital signature is a digital signature calculated and generated by the first authentication server from the signature data including the first authentication result information ciphertext and the digital certificate of the requesting device. The second receiving unit is configured to receive a second authentication response message sent by the second authentication server. The second authentication response message includes the first authentication result information ciphertext, the first digital signature, the second authentication result information, and a fourth digital signature. The first digital signature is a digital signature calculated and generated by the second authentication server on the signature data including the first authentication result information ciphertext, and the fourth digital signature is a digital signature calculated and generated by the second authentication server on the signature data including the second authentication result information. The fourth verification unit is used to verify the fourth digital signature using the public key of the second authentication server; The third generation unit is used to calculate and generate a second digital signature from the signature data, including the second authentication result information, when the fourth digital signature verification is successful, and to generate the first authentication response message based on the information including the first authentication result information ciphertext, the first digital signature, the second authentication result information, and the second digital signature.

48. The first authentication server according to any one of claims 44 to 47, characterized in that, The message sent by the first authentication server to the authentication access controller also includes a hash value calculated by the first authentication server for the latest preamble message received from the authentication access controller; the message sent by the first authentication server to the second authentication server also includes a hash value calculated by the first authentication server for the latest preamble message received from the second authentication server.

49. A second authentication server, characterized in that, The second authentication server is the authentication server that requests the device to trust. If the first authentication server trusted by the authentication access controller and the second authentication server that requests the device to trust are two different authentication servers; The second authentication server includes: The receiving unit is configured to receive a second authentication request message sent by a first authentication server. The second authentication request message includes encrypted first authentication result information, the digital certificate of the requesting device, and a third digital signature of the first authentication server. The third digital signature is a digital signature calculated and generated by the first authentication server from signature data including the encrypted first authentication result information and the digital certificate of the requesting device. The first verification unit is used to verify the third digital signature; The second verification unit is used to verify the legality of the digital certificate of the requesting device and obtain a second verification result when the third digital signature verification is successful. The generation unit is used to generate second authentication result information based on information including the second verification result. The sending unit is configured to send a second authentication response message to the first authentication server. The second authentication response message includes the first authentication result information ciphertext, a first digital signature, the second authentication result information, and a fourth digital signature. The first digital signature is a digital signature calculated and generated by the second authentication server on the signature data including the first authentication result information ciphertext, and the fourth digital signature is a digital signature calculated and generated by the second authentication server on the signature data including the second authentication result information.

50. The second authentication server according to claim 49, characterized in that, The message sent by the second authentication server to the first authentication server also includes a hash value calculated by the second authentication server for the latest preceding message received from the first authentication server.

Citation Information

Patent Citations

  • Enhanced WLAN certificate authentication method, device and system

    CN105578464A

  • Identity authentication method and device for asymmetric cipher, computer equipment and storage medium

    CN107948189A