A method and apparatus for identity authentication

CN114760029BActive Publication Date: 2026-09-11CHINA IWNCOMM
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202011569190.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2020-12-26
Publication Date
2026-09-11
Estimated Expiration
2040-12-26

AI Technical Summary

Technical Problem

但在已有的实体鉴别方案中,通常不能保护用户的隐私信息,且会存在网络接入点恶意计费,给用户造成异常收费的问题

Benefits of technology

[0034] As can be seen from the above technical solution, when the requesting device and the authentication access controller use a symmetric key entity authentication protocol for bidirectional identity authentication, the requesting device's identity information is transmitted in encrypted form during message transmission, thereby ensuring the security of the requesting device's true identity information during the authentication process. Furthermore, after verifying the legitimacy of the requesting device's identity, the authentication access controller sends a first evidence storage message to a first authentication server trusted by the requesting device. This first authentication server records the requesting device's network access request behavior, providing objective evidence for subsequent network access point billing and effectively preventing network access points from maliciously billing users who did not attempt to access the network within their service area.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114760029B_ABST
    Figure CN114760029B_ABST
Patent Text Reader

Abstract

The embodiment of the present application discloses an identity authentication method, when a request device and an authentication access controller adopt a symmetric key entity authentication protocol to perform bidirectional identity authentication, identity information of the request device is transmitted in the form of cipher text in the process of transmitting messages, so as to ensure the security of the real identity information of the request device in the identity authentication process. In addition, after verifying the legal identity of the request device, the authentication access controller will correspondingly send a first evidence storage message to a first authentication server trusted by the request device, so as to record the behavior of the request device for requesting to access the network by using the first authentication server, to provide objective evidence for subsequent network access point charging, and effectively prevent the network access point from maliciously charging the user who does not attempt to access the network in the service area of the network access point.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of network communication security technology, and in particular to an identity authentication method and apparatus. Background Technology

[0002] Currently, communication networks typically require two-way authentication between users and network access points to ensure that legitimate users can communicate with legitimate networks. However, existing entity authentication schemes often fail to protect user privacy and can lead to malicious billing by network access points, resulting in abnormal charges for users. Summary of the Invention

[0003] To address the aforementioned technical problems, this application provides an identity authentication method and apparatus. Employing a symmetric-key entity authentication protocol, it ensures the confidentiality of entity identity and related information while achieving bidirectional identity authentication between the requesting device and the authentication access controller, ensuring legitimate users access legitimate networks. Furthermore, it prevents network access points from maliciously charging users who are not within their service area. Simultaneously, by employing key exchange computation and through ingenious details and process design, the protocol's resistance to quantum computing attacks or dictionary brute-force attacks is enhanced.

[0004] The embodiments of this application disclose the following technical solutions:

[0005] In a first aspect, embodiments of this application provide an identity authentication method, including:

[0006] The requesting device sends an authentication request message to the authentication access controller, the authentication request message including the encrypted identity information of the requesting device; the encrypted identity information of the requesting device is obtained by the requesting device encrypting encrypted data including the identity identifier of the requesting device using the public key of the encryption certificate;

[0007] The authentication access controller sends a first authentication request message carrying encrypted identity information of the requesting device to a trusted second authentication server, receives a first authentication response message from the second authentication server, and obtains from the first authentication response message a stored random number generated by the trusted first authentication server and an identity authentication key generated by the first authentication server. The stored random number and the identity authentication key are generated by the first authentication server after decrypting the encrypted identity information of the requesting device and determining the legitimacy of the requesting device's identity based on the decrypted identity identifier. The identity authentication key is calculated based on computational data including a pre-shared encryption key between the first authentication server and the requesting device.

[0008] The requesting device receives a first verification message sent by the authentication access controller and sends a second verification message to the authentication access controller. The first verification message includes the stored random number, and the second verification message includes a first identity authentication code and a first message integrity verification code. The first identity authentication code is generated by the requesting device using its pre-shared storage verification key with the first authentication server, along with information including the stored random number. The first message integrity verification code is generated by the requesting device using its message integrity verification key with the authentication access controller, along with other fields in the second verification message except for the first message integrity verification code. The message integrity verification key is calculated based on information including the identity authentication key.

[0009] The authentication access controller verifies the integrity check code of the first message. If the verification is successful, it determines that the identity of the requesting device is legitimate and generates an authentication completion message and a first evidence storage message.

[0010] The requesting device verifies the second message integrity check code in the authentication completion message. If the verification is successful, the identity of the authentication access controller is determined to be legitimate. The second message integrity check code is generated by the authentication access controller using the message integrity check key to calculate other fields in the authentication completion message, excluding the second message integrity check code.

[0011] The first authentication server verifies the first identity authentication code in the first evidence storage message. After successful verification, it generates and stores the request pass record of the requesting device.

[0012] Secondly, embodiments of this application provide an authentication access controller, including:

[0013] The receiving unit is configured to receive an authentication request message sent by the requesting device, wherein the authentication request message includes encrypted identity information of the requesting device; the encrypted identity information of the requesting device is obtained by the requesting device encrypting encrypted data, including the identity identifier of the requesting device, using the public key of the encryption certificate;

[0014] The sending unit is configured to send a first authentication request message carrying encrypted identity information of the requesting device to a second authentication server trusted by the authentication access controller;

[0015] The receiving unit is further configured to receive a first authentication response message sent by the second authentication server, and obtain from the first authentication response message a stored random number generated by the first authentication server trusted by the requesting device and an identity authentication key generated by the first authentication server; the identity authentication key is calculated based on computational data including a pre-shared encryption key between the first authentication server and the requesting device.

[0016] The sending unit is further configured to send a first verification message to the requesting device, wherein the first verification message includes the evidence storage random number;

[0017] The receiving unit is further configured to receive a second verification message sent by the requesting device, the second verification message including a first identity authentication code and a first message integrity verification code; the first message integrity verification code is generated by the requesting device using a message integrity verification key between itself and the authentication access controller to calculate other fields in the second verification message except for the first message integrity verification code; wherein, the message integrity verification key is calculated based on information including the identity authentication key;

[0018] The processing unit is used to verify the integrity check code of the first message. After the verification is successful, the identity of the requesting device is determined to be legitimate, and an authentication completion message and a first evidence storage message are generated.

[0019] The sending unit is further configured to send the authentication completion message to the requesting device and the first evidence storage message to the second authentication server.

[0020] Thirdly, embodiments of this application provide a requesting device, including:

[0021] The sending unit is configured to send an authentication request message to the authentication access controller, wherein the authentication request message includes encrypted identity information of the requesting device; the encrypted identity information of the requesting device is obtained by the requesting device encrypting encrypted data, including the identity identifier of the requesting device, using the public key of the encryption certificate;

[0022] The receiving unit is configured to receive a first verification message sent by the authentication access controller, wherein the first verification message includes a stored random number;

[0023] The processing unit is configured to: calculate and generate a first identity authentication code using a pre-shared evidence verification key between the requesting device and its trusted first authentication server, including the evidence-stored random number; and calculate and generate a first message integrity verification code using a message integrity verification key between the requesting device and the authentication access controller, including fields in the second verification message other than the first message integrity verification code; wherein the message integrity verification key is calculated based on information including an identity authentication key, and the identity authentication key is calculated based on computational data including a pre-shared encryption key between the requesting device and the first authentication server.

[0024] The sending unit is further configured to send the second verification message to the authentication access controller, the second verification message including the first identity authentication code and the first message integrity verification code;

[0025] The receiving unit is also configured to receive an authentication completion message sent by the authentication access controller;

[0026] The processing unit is further configured to verify the second message integrity check code in the authentication completion message. After successful verification, the identity of the authentication access controller is determined to be legitimate. The second message integrity check code is generated by the authentication access controller using the message integrity check key to calculate other fields in the authentication completion message, excluding the second message integrity check code.

[0027] Fourthly, embodiments of this application provide a first authentication server, which is an authentication server requesting device trust, comprising:

[0028] The processing unit is used to decrypt the encrypted identity information of the requesting device using the private key corresponding to the encryption certificate to obtain the identity identifier of the requesting device, determine the legitimacy of the requesting device based on the identity identifier of the requesting device, and generate a storage random number and an identity authentication key after determining that the identity of the requesting device is legitimate. The identity authentication key is calculated based on computational data including the pre-shared encryption key between the first authentication server and the requesting device.

[0029] The processing unit is also used to verify the first identity authentication code in the first evidence storage message, and after the verification is successful, generate and store the request pass record of the requesting device.

[0030] Fifthly, embodiments of this application provide a second authentication server, which is an authentication server trusted by the authentication access controller, comprising:

[0031] The receiving unit is configured to receive a first authentication request message sent by the authentication access controller, which carries encrypted identity information of the requesting device.

[0032] The sending unit is configured to send a first authentication response message to the authentication access controller, wherein the first authentication response message includes a stored random number generated by the first authentication server trusted by the requesting device and an identity authentication key generated by the first authentication server.

[0033] The receiving unit is further configured to receive a first evidence storage message sent by the authentication access controller, wherein the first evidence storage message includes a first identity authentication code.

[0034] As can be seen from the above technical solution, when the requesting device and the authentication access controller use a symmetric key entity authentication protocol for bidirectional identity authentication, the requesting device's identity information is transmitted in encrypted form during message transmission, thereby ensuring the security of the requesting device's true identity information during the authentication process. Furthermore, after verifying the legitimacy of the requesting device's identity, the authentication access controller sends a first evidence storage message to a first authentication server trusted by the requesting device. This first authentication server records the requesting device's network access request behavior, providing objective evidence for subsequent network access point billing and effectively preventing network access points from maliciously billing users who did not attempt to access the network within their service area. Attached Figure Description

[0035] To more clearly illustrate the technical solutions in the embodiments of this application or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0036] Figure 1 A schematic diagram illustrating an identity authentication method provided in an embodiment of this application;

[0037] Figure 2 This is a schematic diagram of an identity authentication method in a non-roaming situation provided in an embodiment of this application, where "*" represents an optional field or optional operation;

[0038] Figure 3 This is a schematic diagram of an identity authentication method in a roaming situation provided in an embodiment of this application, wherein "*" represents an optional field or optional operation;

[0039] Figure 4 A structural block diagram of an authentication access controller (AAC) provided in this application embodiment;

[0040] Figure 5A structural block diagram of a request device REQ provided in an embodiment of this application;

[0041] Figure 6 A structural block diagram of a first authentication server AS-REQ provided in an embodiment of this application;

[0042] Figure 7 This is a structural block diagram of a second authentication server AS-AAC provided in an embodiment of this application. Detailed Implementation

[0043] In a communication network, a requesting device can access the network through an authentication access controller. To ensure that the requesting device is a legitimate device and that the network requested by the user is a legitimate network, two-way authentication is usually required between the authentication access controller and the requesting device.

[0044] For example, in scenarios where a requesting device accesses a wireless network through an authentication access controller, the requesting device can be a mobile phone, a personal digital assistant (PDA), a tablet computer, or other terminal device, and the authentication access controller can be a wireless access point. In scenarios where a requesting device accesses a wired network through an authentication access controller, the requesting device can be a desktop computer, a laptop computer, or other terminal device, and the authentication access controller can be a switch or a router. In scenarios where a requesting device accesses a 4G / 5G network through an authentication access controller, the requesting device can be a mobile phone, and the authentication access controller can be a base station. Of course, this application is also applicable to various data communication scenarios, including other wired networks and short-range communication networks.

[0045] During the authentication process, the requesting device needs to provide its own real identity information so that the authentication access controller can authenticate the requesting device. For example, this identity information can be the identity identifier of the requesting device. The identity identifier may carry private and sensitive information such as ID card number, home address, bank card information, and geographical location. If it is intercepted by attackers during the authentication process and used for illegal purposes, it will cause great security risks to the authentication access controller, the requesting device, and even the network.

[0046] To address the aforementioned technical problems, embodiments of this application provide an identity authentication method. In this method, a requesting device sends an authentication request message to an authentication access controller. The authentication request message includes encrypted identity information of the requesting device, which is obtained by encrypting encrypted data, including the requesting device's identity identifier, using the public key of an encryption certificate. The authentication access controller sends a first authentication request message carrying the encrypted identity information of the requesting device to a trusted second authentication server and receives a first authentication response message from the second authentication server. From the first authentication response message, the controller obtains a stored random number generated by the trusted first authentication server after determining the legitimacy of the requesting device's identity and an identity authentication key generated by the first authentication server. The identity authentication key is calculated based on computational data including a pre-shared encryption key between the first authentication server and the requesting device. The requesting device receives a first verification message from the authentication access controller, which includes the stored random number, and sends a second verification message to the authentication access controller. The second verification message contains... The system includes a first identity authentication code and a first message integrity verification code. The first identity authentication code is generated by the requesting device using its pre-shared evidence storage verification key with the first authentication server, along with information including a storage random number. The first message integrity verification code is generated by the requesting device using its message integrity verification key with the authentication access controller, along with other fields in the second verification message besides the first message integrity verification code. The authentication access controller verifies the first message integrity verification code. If the verification is successful, it determines that the requesting device's identity is legitimate and generates an authentication completion message and a first evidence storage message. The requesting device verifies the second message integrity verification code in the authentication completion message. If the verification is successful, it determines that the authentication access controller's identity is legitimate. The second message integrity verification code is generated by the authentication access controller using the message integrity verification key, along with other fields in the authentication completion message besides the second message integrity verification code. The first authentication server verifies the first identity authentication code in the first evidence storage message. If the verification is successful, it generates and stores the requesting device's request approval record.

[0047] Therefore, when the requesting device and the authentication access controller perform bidirectional identity authentication using a symmetric key entity authentication protocol, the requesting device's identity information is transmitted in encrypted form, thus ensuring the security of the requesting device's true identity information during the authentication process. Furthermore, after verifying the legitimacy of the requesting device's identity, the authentication access controller sends a first evidence storage message, including a first identity authentication code generated by the requesting device, to a first authentication server trusted by the requesting device. This allows the first authentication server to generate and store a record of the requesting device's network access request based on the first identity authentication code, providing objective evidence for subsequent network access point billing and effectively preventing network access points from maliciously billing users who did not attempt to access the network within their service area.

[0048] It should be noted that the identity authentication method provided in this application embodiment is used to implement two-way identity authentication (MIA) between the access controller and the requesting device.

[0049] For ease of explanation, this application embodiment will use a requesting device (REQuester, REQ), an authentication access controller (AAC), and an authentication server (AS) as examples to describe an identity authentication method.

[0050] In this system, the AS trusted by REQ is called the first authentication server AS-REQ, and the AS trusted by AAC is called the second authentication server AS-AAC. REQ can be one endpoint participating in the authentication process, establishing a connection with AAC, accessing the services provided by AAC, and accessing the AS through AAC. AAC can be another endpoint participating in the authentication process, establishing a connection with REQ, providing services, and directly accessing AS-AAC; AS-AAC can directly access AS-REQ. When REQ and the AS trusted by AAC are the same, AS-AAC and AS-REQ can be the same AS; when REQ and the AS trusted by AAC are different, AS-AAC and AS-REQ are different ASs, and roaming occurs.

[0051] Before implementing bidirectional identity authentication between REQ and AAC using a symmetric key entity authentication protocol, REQ and AS-REQ have a pre-shared evidence storage and verification key K. REQ_AS K REQ_AS The same static key is pre-configured or distributed for both REQ and AS-REQ, and both REQ and AAC have an ID that identifies themselves. The Certificate Server-Decrypt (CS-DEC) holds encryption certificates and corresponding private keys that conform to ISO / IEC 9594-8 / ITU X.509, other standards, or other technical systems. The CS-DEC can be a standalone server or reside within the AS-REQ; and the REQ is aware of the encryption certificate or the public key within it.

[0052] The following is about Figure 1 An identity authentication method is described below, which includes:

[0053] S101, REQ sends an authentication request message ATTACH to AAC.

[0054] The ATTACH contains REQ's identity information ciphertext EncPub. AS EncPub AS REQ uses the public key of the encryption certificate to pair with its own identity ID. REQ The encrypted data is obtained by encrypting the data. This prevents unauthorized individuals from obtaining the real identity of the REQ during message transmission, ensuring the security of the REQ's real identity. In this application, the object to be encrypted is referred to as encrypted data.

[0055] Optional, REQ calculates EncPub AS The encrypted data may also include the Nonce key, an identity encryption key generated by REQ. REQID In other words, REQ can also utilize the public key pair of the encryption certificate, including the ID. REQ and Nonce REQID Encrypted data, including the encrypted data, yields the ciphertext EncPub containing the identity information. AS .

[0056] Optionally, ATTACH may also include security capabilities parameter information supported by REQ. REQ Security capabilities REQ This includes REQ-supported authentication suites (which contain one or more authentication methods), integrity verification algorithms, hash algorithms, key exchange algorithms, and / or key derivation algorithms, allowing AAC to select specific security capabilities to use. AAC .

[0057] Optionally, ATTACH may also include the identity of at least one authentication server Route trusted by REQ. AS So that AAC can be based on Route AS The system identifies the second authentication server AS-AAC by using the identity identifier of the authentication server it trusts.

[0058] Optionally, ATTACH may also include the first random number (Nonce) generated by REQ. REQ .

[0059] S102, AAC sends the first authentication request message AACVeri to the AS-AAC it trusts.

[0060] The AAC Veri contains the encrypted identity information EncPub carried in ATTACH for the REQ. AS .

[0061] Optionally, if ATTACH includes the identity identifier of at least one authentication server Route trusted by REQ. AS Therefore, before sending AACVeri, AAC needs to first determine the Route in ATTACH. AS The system identifies the second authentication server AS-AAC based on the identity of the authentication server it trusts. Specifically, if REQ and AAC share a common trusted authentication server, it can be determined that this is a non-roaming situation, meaning AS-AAC and AS-REQ are the same authentication server; if REQ and AAC do not share a common trusted authentication server, it can be determined that this is a roaming situation, meaning AS-AAC and AS-REQ are two independent authentication servers.

[0062] Optionally, AACVeri may also include the AAC's identity ID. AAC and / or the second random number Nonce generated by AAC AAC If the ATTACH sent by REQ to AAC includes a Nonce REQ Then the AACCVeri sent by AAC to AS-AAC can also include this Nonce. REQ .

[0063] S103, AAC receives the first authentication response message ASVeri sent by AS-AAC.

[0064] The ASVeri includes a storage random number and an identity authentication key IAK generated by AS-REQ after verifying the legitimacy of REQ's identity.

[0065] It should be noted that if AS-REQ and AS-AAC are the same authentication server, i.e., in a non-roaming scenario, AS-AAC (or AS-REQ) can be used to represent the authentication server that both REQ and AAC trust. In this case, AAC sends an EncPub to AS-AAC (which can also be represented as AS-REQ). AS After receiving AACVeri, AS-AAC (which can also be represented as AS-REQ) obtains and decrypts EncPub using the private key corresponding to the encryption certificate. AS The ID obtained REQ and according to ID REQ Determine if the REQ's identity is valid. If valid, generate a nonce for evidence storage. AS_AAC (can also be represented as Nonce) AS_REQ ) and the identity authentication key IAK, and will include the Nonce AS_AAC (can also be represented as Nonce) AS_REQThe ASVeri of IAK is sent to AAC. Among them, the above is for EncPub. AS Decryption can be performed by CS-DEC, which has an interactive and trust relationship with AS-AAC (also represented as AS-REQ), or by AS-AAC (also represented as AS-REQ). Here, IAK is the pre-shared encryption key K, including itself and REQ, derived by AS-AAC (also represented as AS-REQ) using the key derivation algorithm agreed upon with REQ. REQ_AS The computational data is obtained from the calculations. In this application, the computational objects used in the algorithm operation are referred to as computational data.

[0066] If AS-REQ and AS-AAC are different authentication servers, i.e., in a roaming situation, AAC first sends an EncPub to AS-AAC. AS AS-AAC generates a second authentication request message AS-AACVeri based on AACVeri and sends AS-AACVeri to AS-REQ. AS-AACVeri carries EncPub. AS AS-REQ obtains and decrypts EncPub using the private key corresponding to the encryption certificate. AS The ID obtained REQ According to ID REQ Determine if the REQ's identity is valid. If valid, generate a nonce for evidence storage. AS_REQ And the identity authentication key IAK will include Nonce AS_REQ The second authentication response message, AS-REQVeri, including IAK, is sent to AS-AAC. AS-AAC then generates an ASVeri based on the AS-REQVeri and includes the Nonce. AS_REQ And IAK's ASVeri is sent to AAC. Among them, the above is for EncPub AS Decryption can be performed by CS-DEC, which has an interaction and trust relationship with AS-REQ, or by AS-REQ itself. IAK is a key derivation algorithm agreed upon by AS-REQ and REQ, used by AS-REQ to encrypt a pre-shared encryption key K containing both itself and REQ. REQ_AS The calculations were performed using data including those included in the calculations.

[0067] Optionally, when Nonce is included in AACVeri REQ and Nonce AAC At the same time, the data used by the authentication server to calculate IAK also includes the Nonce. REQ and Nonce AAC .

[0068] Optionally, when the REQ's identity information is encrypted with EncPubAS The encrypted data also includes the identity encryption key Nonce. REQID In non-roaming situations, AS-AAC (which can also be represented as AS-REQ) can also be used to decrypt EncPub. AS The Nonce obtained REQID For ID REQ Encryption yields the REQ's ciphertext, which can then be included in the ASVeri. In roaming situations, AS-REQ can also utilize the decryption of EncPub. AS The Nonce obtained REQID For ID REQ Encryption yields the REQ's ciphertext, and AS-REQVeri and ASVeri can also contain the REQ's ciphertext; the REQ's ciphertext can be obtained using Nonce. REQID For ID REQ The result of the XOR operation, i.e.

[0069] Optionally, when AACVeri includes ID AAC and / or Nonce AAC In this case, ASVeri can also include ID. AAC and / or Nonce AAC Accordingly, after receiving the ASVeri, AAC can determine the ID in the ASVeri. AAC With its own identity ID AAC Whether they match, and / or, determine the Nonce in ASVeri. AAC Nonce generated by itself AAC If they match, proceed with the subsequent operations; otherwise, discard ASVeri.

[0070] Optionally, a pre-shared encryption key EK exists between AAC and AS-AAC. AAC_AS AS-AAC can utilize EK AAC_AS Information including IAK is encrypted to obtain the authentication key ciphertext EncData. AS_AAC , using EncData AS_AAC Replace IAK in ASVeri.

[0071] S104. AAC sends the first authentication message AACAuth to REQ.

[0072] The AACAuth includes a stored random number.

[0073] Optionally, AACAuth may also include the first key exchange parameter KeyInfo.AAC KeyInfo AAC The result is obtained by AAC using the identity authentication key IAK and a symmetric encryption algorithm to encrypt information, including its own generated temporary public key. AAC calculates KeyInfo. AAC First, the hash value of IAK, HASH(IAK), can be calculated. Then, a cross-OR operation is performed on HASH(IAK) and information including the temporary public key generated by AAC to generate KeyInfo. AAC Alternatively, AAC calculates KeyInfo. AAC In this case, the extended identity authentication key EIAK can be calculated first, and then a keyInfo can be generated by XORing EIAK with information including the temporary public key generated by AAC. AAC EIAK is generated by AAC using a key derivation algorithm, based on the IAK and other information (the other information used by AAC and REQ is the same and optional, such as a specific string). The temporary public key generated by AAC is the temporary public key in the temporary public-private key pair generated by AAC.

[0074] Optionally, if ASVeri carries the authentication key ciphertext EncData AS_AAC Then AAC needs to use its pre-shared encryption key EK with AS-AAC. AAC_AS Decrypting EncData AS_AAC IAK was obtained.

[0075] Optionally, if ATTACH includes security capabilities REQ Then AAC can be based on Security capabilities REQ Determine the specific security policies and capabilities you use. AAC and Security capabilities AAC Add to AACAuth and send to REQ. Security capabilities AAC This indicates that AAC determines the authentication method, integrity verification algorithm, hash algorithm, key exchange algorithm, and / or key derivation algorithm used.

[0076] Optionally, when ASVeri also includes the encrypted identity of REQ, AAC can add the encrypted identity of REQ to AACAuth and send it to REQ. That is, AACAuth can also include...

[0077] Optionally, AAC can also include the ID. AACNonce AAC and Nonce REQ Add any one or more of these to AACAuth and send it to REQ.

[0078] S105 and REQ utilize their pre-shared evidence verification key IK with AS-REQ. REQ_AS The first identity authentication code (MIC) is generated from the computational data, including the stored random number. REQ The message integrity verification key between the device and the AAC is used to calculate and generate the first message integrity verification code MacTag, which includes all fields in the second verification message except the first message integrity verification code. REQ .

[0079] Optionally, REQ can generate a second key exchange parameter, KeyInfo. REQ For example, after receiving AACAuth, REQ can use the authentication key IAK and a symmetric encryption algorithm to encrypt and calculate information including the temporary public key generated by REQ to generate KeyInfo. REQ Simply put, REQ calculates the hash value of IAK, i.e., HASH(IAK), and performs an XOR operation on HASH(IAK) and information including the temporary public key generated by REQ to generate KeyInfo. REQ Alternatively, REQ first calculates the extended authentication key EIAK, then performs an XOR operation on EIAK and information including the temporary public key generated by REQ to generate KeyInfo. REQ EIAK is generated by REQ using a key derivation algorithm, based on the IAK and other information (the other information used by AAC and REQ is the same and optional, such as a specific string). The IAK used by REQ is derived by REQ using a key derivation algorithm agreed upon with AS-REQ, based on its own and AS-REQ's pre-shared encryption key K. REQ_AS The calculations were performed using data including those included in the calculations.

[0080] Optionally, when AACAuth includes a Nonce REQ and Nonce AAC When calculating IAK using REQ, the calculation data may also include the nonce. REQ and Nonce AAC .

[0081] The message integrity verification key between REQ and AAC can be pre-shared between REQ and AAC, or it can be negotiated and generated by REQ and AAC. Methods for REQ and AAC to negotiate and generate the message integrity verification key include: REQ can use the key information (including KeyInfo) to... REQThe corresponding temporary private key and KeyInfo AAC The recovered temporary public key is used for key exchange calculation to obtain the first key K1, and K1 is combined with the Nonce. AAC Nonce REQ Other information (the other information used by REQ and AAC is the same and optional, such as specific strings) is used to calculate the message integrity verification key using a key derivation algorithm. Key exchange refers to key exchange algorithms such as the Diffie-Hellman (DH) algorithm. REQ The corresponding temporary private key is the temporary private key in the temporary public-private key pair generated by REQ.

[0082] Optionally, when AACAuth includes a Nonce REQ At that time, REQ can verify the Nonce in AACAuth. REQ Nonce generated with REQ REQ If the results are consistent, the subsequent operations will continue; otherwise, the AACAuth will be discarded.

[0083] Optionally, when AACAuth includes At that time, calculate MIC REQ The computational data used may also include That is, REQ can use its own message integrity verification algorithm agreed upon with AS-REQ, utilizing IK REQ_AS For including MIC is generated from computational data including stored random numbers. REQ .

[0084] Optionally, when AACAuth includes At that time, REQ can be based on Nonce REQID and one's own identity ID REQ In AACAuth Verification can be performed; one approach is that REQ can utilize Nonce. REQID and Perform an XOR operation to recover the ID REQ Then compare with the recovered ID REQ With REQ's own ID REQ To determine if they are consistent, another way is to check if the REQ uses the Nonce. REQID and one's own ID REQ Perform an XOR operation and compare the result with the values ​​in AACAuth. Check if they match; if they match, continue with subsequent operations; if they do not match, discard AACAuth.

[0085] S106, REQ sends the second authentication message REQAuth to AAC.

[0086] The REQAuth includes MIC REQ and MacTag REQ .

[0087] Optionally, REQAuth may also include KeyInfo. REQ Optionally, when AACAuth includes a Nonce AAC At that time, REQ can be used to express nonce. AAC Add it to REQAuth.

[0088] S107, AAC vs MacTag REQ The verification process is completed. Once the verification is successful, the authentication completion message AACFinish and the first evidence storage message AACUpdate are generated.

[0089] MacTag REQ The verification process includes: if MacTag REQ REQ utilizes its message integrity verification key pair with AAC, including the one in REQAuth excluding MacTag. REQ If the MacTag is generated from other fields besides the calculated value, then AAC verification will be performed. REQ When using this method, the message integrity verification key pair between the REQ and REQ should be utilized, including the REQAuth key except for the MacTag. REQ Other fields are used to calculate and generate MacTag. REQ The calculated MacTag REQ MacTag in REQAuth REQ The comparison is performed. If they match, the verification passes and the REQ's identity is deemed legitimate. If they do not match, the following actions are taken according to the local policy: either discarding the REQAuth or determining that the REQ's identity is illegitimate.

[0090] The message integrity verification key between AAC and REQ can be pre-shared between AAC and REQ, or it can be negotiated and generated by AAC and REQ. Methods for AAC and REQ to negotiate and generate the message integrity verification key include: AAC can use the key information (including KeyInfo) to... AAC The corresponding temporary private key and KeyInfo REQ The recovered temporary public key is used for key exchange calculation to obtain the first key K1, and K1 is combined with the Nonce. AAC Nonce REQOther information (the other information used by AAC and REQ is the same and optional, such as a specific string), is used to calculate the message integrity verification key using a key derivation algorithm. KeyInfo AAC The corresponding temporary private key is the temporary private key in the temporary public-private key pair generated by AAC, as defined by KeyInfo. REQ The recovered temporary public key is the temporary public key in the temporary public-private key pair generated by REQ.

[0091] Optionally, when REQAuth includes a Nonce AAC When AAC verifies MacTag REQ Previously, you could also verify the Nonce in REQAuth first. AAC Nonce generated by itself AAC If they match, proceed with the subsequent operations; otherwise, discard the REQAuth.

[0092] Optionally, AAC can also assign a temporary identity (TID) to the REQ. REQnew Used to transfer TID REQnew Add to AACFinish and AACUpdate.

[0093] In addition, in order for REQ to authenticate AAC, AAC also needs to generate a second message integrity check code, MacTag. AAC and the MacTag AAC Add to AACFinish. MacTag AAC AAC can utilize its message integrity verification key pair with REQ, including the authentication completion message AACFinish, excluding the MacTag. AAC Other fields besides those are calculated and generated.

[0094] Optionally, after verifying REQ's identity, AAC can also calculate a session key to ensure confidential communication between REQ and AAC. Specifically, AAC can calculate this key based on information including KeyInfo. AAC The corresponding temporary private key and KeyInfo REQ The recovered temporary public key is used for key exchange calculation to obtain the first key K1, and K1 is combined with... ID AAC Other information (the other information used by AAC and REQ is the same and optional, such as a specific string) is used to calculate the session key (including the data encryption key and / or data integrity verification key) using a key derivation algorithm.

[0095] In this method, when calculating the session key, AAC can use a key derivation algorithm to calculate a string of key data. This key data can be used as a data encryption key and / or a data integrity verification key. Alternatively, a portion of the key data can be used as a data encryption key, and another portion can be used as a data integrity verification key.

[0096] S108, AAC sends an authentication completion message AACFinish to REQ.

[0097] The AACFinish includes MacTag. AAC If AAC assigns a temporary identity TID to REQ. REQnew AACFinish also includes TID REQnew .

[0098] S109, REQ for MacTag in AACFinish AAC The verification process is completed, and once successful, AAC's identity is confirmed as legitimate.

[0099] MacTag AAC The verification process includes: if MacTag AAC AAC utilizes its message integrity verification key pair with REQ, including the MacTag in AACFinish. AAC If the calculation is generated from other fields besides the 'Matag', then REQ will verify the MacTag. AAC When using this method, the message integrity verification key pair between the device and AAC should be utilized, including the key pair in AACFinish excluding the MacTag. AAC Other fields are used to calculate and generate MacTag. AAC The calculated MacTag AAC MacTag in AACFinish AAC The comparison is performed. If they match, the verification passes and the AAC's identity is confirmed to be legitimate. If they do not match, the following actions are taken according to the local policy, including discarding AACFinish or determining that the AAC's identity is illegitimate.

[0100] Optionally, after REQ confirms the legitimacy of AAC's identity, it can also save the TID. REQnew So that the TID can be used in subsequent identity verification processes. REQnew It replaces one's true identity.

[0101] Optionally, after verifying the legitimacy of the AAC, the REQ can also calculate a session key to ensure confidential communication between the REQ and the AAC. Specifically, the REQ can calculate this key based on information including KeyInfo. REQ The corresponding temporary private key and KeyInfoAAC The recovered temporary public key is used for key exchange calculation to obtain the first key K1, and K1 is combined with... ID AAC Other information (the other information used by REQ and AAC is the same and optional, such as specific strings, etc.) is used to calculate the session key (including the data encryption key and / or data integrity verification key) using a key derivation algorithm. This is derived from KeyInfo. AAC The recovered temporary public key is the temporary public key in the temporary public-private key pair generated by AAC.

[0102] In the process of calculating the session key, REQ can use a key derivation algorithm to calculate a string of key data. This key data can be used as a data encryption key and / or a data integrity verification key. Alternatively, a portion of the key data can be used as a data encryption key, and another portion can be used as a data integrity verification key.

[0103] S110, AAC sends the first evidence storage message AACUpdate to AS-REQ.

[0104] The AACUpdate includes the MIC carried in REQAuth. REQ .

[0105] In non-roaming situations, AAC can directly send AACUpdate to AS-AAC (which can also be represented as AS-REQ).

[0106] In roaming situations, after AAC generates AACUpdate, it first sends AACUpdate to AS-AAC; then AS-AAC generates a second evidence storage message ASUpdate based on AACUpdate, and ASUpdate includes MIC. REQ And send ASUpdate to AS-REQ.

[0107] The AACUpdate may also include the temporary identity (TID) assigned by the AAC to the REQ. REQnew .

[0108] Optionally, AACUpdate may also include a second authentication code (MIC). AAC MIC AAC AAC utilizes the pre-shared verification key IK with AS-AAC. AAC_AS A pre-shared message integrity verification algorithm is used to verify the MIC in AACUpdate. AAC This was generated from calculations performed on other fields previously.

[0109] S111, AS-REQ vs MIC REQThe verification is performed, and once the verification is successful, a record of the REQ request is generated and stored.

[0110] AS-REQ can also save TIDs when generating and storing REQ requests via records. REQnew .

[0111] If AACUpdate also includes MIC AAC In non-roaming situations, AS-AAC (which can also be represented as AS-REQ) controls MIC. REQ and MIC AAC Verification is performed, i.e., AS-AAC (which can also be represented as AS-REQ) uses its pre-shared verification key IK with AAC. AAC_AS MIC calculated locally AAC And the pre-shared evidence verification key IK used with REQ REQ_AS MIC calculated locally REQ Then calculate the MIC AAC With MIC in AACUpdate AAC Compare and calculate the MIC. REQ With MIC in AACUpdate REQ Compare the results; if they match, the verification is successful.

[0112] If AACUpdate also includes MIC AAC In roaming situations, AS-AAC will first check the MIC. AAC Verification is performed, meaning AS-AAC first uses its pre-shared verification key IK with AAC. AAC_AS MIC calculated locally AAC The calculated MIC AAC With MIC in AACUpdate AAC The comparison is performed; if they match, the verification passes. After successful verification, AS-AAC generates ASUpdate and sends it to AS-REQ. Then, AS-REQ processes the MIC in ASUpdate. REQ Verification is performed by AS-REQ using its pre-shared evidence verification key IK with REQ. REQ_AS MIC calculated locally REQ The calculated MIC REQ MIC in ASUpdate REQ The comparison is performed. If they match, the verification is successful, and the REQ request pass record can be generated and saved.

[0113] It should be noted that in practical applications, S108 can be executed first and then S110, or S110 can be executed first and then S108, or S108 and S110 can be executed simultaneously.

[0114] Optionally, AAC can first execute S110, i.e., send the first evidence storage message, and in S111, verify the first identity authentication code MIC in the first evidence storage message. REQ Upon successful verification, a first evidence confirmation message is generated to prevent REQ from intentionally sending an incorrect first identity authentication code (MIC). REQ This is done to evade billing. After receiving the first evidence confirmation message, AAC executes S108, which sends the authentication completion message to REQ.

[0115] As can be seen from the above technical solution, when the requesting device and the authentication access controller perform bidirectional identity authentication using a symmetric key entity authentication protocol, the requesting device's identity information is transmitted in encrypted form, thereby ensuring the security of the requesting device's true identity information during the identity authentication process. Furthermore, after verifying the legitimacy of the requesting device's identity, the authentication access controller sends a first evidence storage message to a first authentication server trusted by the requesting device. This first authentication server records the requesting device's network access request behavior, providing objective evidence for subsequent network access point billing and effectively preventing network access points from maliciously billing users who did not attempt to access the network within their service area.

[0116] Based on the foregoing embodiments, the identity authentication method provided by the embodiments of this application will be described below for both non-roaming and roaming scenarios.

[0117] See Figure 2 This is an example of an identity authentication method in a non-roaming scenario. In this case, AS-AAC (or AS-REQ) can be used to represent an authentication server that is trusted by both AAC and REQ. The identity authentication method includes:

[0118] S201, REQ generates Nonce REQ Nonce REQID and EncPub AS Generate Security capabilities as needed. REQ .

[0119] S202, REQ sends an authentication request message ATTACH to AAC.

[0120] This ATTACH includes security capabilities. REQ EncPub AS Route AS and NonceREQ Among them, EncPub AS REQ utilizes the public key pair of the encryption certificate, including the ID. REQ Nonce REQID The encrypted identity information of REQ is obtained by calculating the encrypted data, including Route. AS The identifier of the authentication server indicating REQ trust; Security capabilities REQ This is an optional field that represents the security capability parameters supported by REQ, including the authentication suites, integrity verification algorithms, hash algorithms, key exchange algorithms, and / or key derivation algorithms supported by REQ (the same applies below).

[0121] S203, AAC generates Nonce AAC .

[0122] AAC according to Route AS Determine whether the authentication server trusted by REQ is the same as the authentication server trusted by itself. If they are the same, it is determined to be a non-roaming situation. In this embodiment, REQ and AAC have a common trusted authentication server.

[0123] S204, AAC sends the first authentication request message AACVeri to AS-AAC.

[0124] The AAC Veri includes EncPub AS Nonce REQ ID AAC and Nonce AAC Among them, EncPub AS and Nonce REQ They should be equal to the corresponding fields in ATTACH; ID AAC This is an optional field.

[0125] S205. After receiving AACVeri, AS-AAC performs the following operations (unless otherwise specified or logically related, the actions numbered (1), (2)... below do not necessarily have a sequential order due to their numbering. The same applies throughout the text), including:

[0126] (1) Decrypt EncPub using the private key of the encryption certificate AS Get ID REQ and Nonce REQID According to ID REQ Determine if the REQ's identity is valid. If valid, continue with subsequent operations; otherwise, discard AACVeri.

[0127] (2) Calculate and generate IAK;

[0128] AS-AAC utilizes its pre-shared encryption key K with REQ REQ_AS Combined with ID REQ Nonce REQ ID AAC Nonce AAC The computational data, including the key derivation algorithm pre-agreed with REQ, is used to calculate IAK.

[0129] (3) Generate a nonce for evidence storage AS_AAC ;

[0130] (4) For ID REQ and Nonce REQID Generate by performing XOR operation

[0131] (5) Optionally, AS-AAC utilizes its pre-shared encryption key EK with AAC. AAC_AS EncData is generated by encrypting information including IAK. AS_AAC .

[0132] S206, AS-AAC sends the first authentication response message ASVeri to AAC.

[0133] The ASVeri includes Nonce REQ ID AAC Nonce AAC Nonce AS_AAC and IAK. Among them, ID AAC This is an optional field if and only if the ID in AACVeri is... AAC Existence exists; ID AAC Nonce AAC They should be equal to the corresponding fields in AACVeri; if EncData exists. AS_AAC At that time, AS-AAC utilizes EncData AS_AAC Replace IAK in ASVeri.

[0134] S207. After receiving ASVeri, AAC performs the following operations, including:

[0135] (1) Check the Nonce in ASVeri AAC Nonce generated by AAC AAC Whether they match, if an ID exists in ASVeri AAC Then check the ID in ASVeri. AAC With AAC's own identity ID AACCheck if they match; if any item does not match, discard ASVeri.

[0136] (2) Obtain IAK;

[0137] EncData is included in ASVeri. AS_AAC In this case, the pre-shared encryption key EK between it and AS-AAC is used. AAC_AS Decrypting EncData AS_AAC IAK was obtained;

[0138] (3) Based on the IAK and other information (the other information used by AAC and REQ is the same and optional, such as a specific string, etc.), the EIAK is calculated and generated using the key derivation algorithm;

[0139] (4) Calculate and generate KeyInfo AAC ;

[0140] AAC performs an XOR operation on EIAK and information including the temporary public key generated by AAC to generate KeyInfo. AAC .

[0141] S208, AAC sends the first authentication message AACAuth to REQ.

[0142] The AACAuth includes security capabilities. AAC KeyInfo AAC , Nonce REQ ID AAC Nonce AAC and Nonce AS_AAC .in, Nonce REQ Nonce AAC Nonce AS_AAC These should be equal to the corresponding fields in ASVeri. Security capabilities AAC This is an optional field, indicating that AAC is based on security capabilities. REQ The choice of a specific security strategy, i.e., the identity authentication method, integrity verification algorithm, hash algorithm, key exchange algorithm, and / or key derivation algorithm (hereinafter the same) determined by the AAC, is made if and only if security capabilities exist in the ATTACH. REQ Security capabilities only exist at that time AAC .

[0143] S209. After receiving AACAuth, REQ performs the following operations, including:

[0144] (1) Using Nonce REQID and Perform an XOR operation to recover the ID REQ ;

[0145] (2) Check the recovered ID REQ With REQ's own identity ID REQ To check for consistency, examine the Nonce in AACAuth. REQ Nonce generated with REQ REQ Check if they match; if any item does not match, discard AACAuth.

[0146] (3) Calculate IAK;

[0147] REQ utilizes a pre-shared encryption key K with AS-AAC. REQ_AS Combined with ID REQ Nonce REQ ID AAC Nonce AAC The computational data, including the key derivation algorithm agreed upon with AS-AAC beforehand, is used to calculate IAK. The computational data used by REQ to calculate IAK is the same as that used by AS-AAC to calculate IAK in S205.

[0148] (4) Based on the IAK and other information (the other information used by AAC and REQ is the same and optional, such as a specific string, etc.), the EIAK is calculated and generated using the key derivation algorithm;

[0149] (5) Calculate and generate KeyInfo REQ ;

[0150] REQ performs an XOR operation on EIAK and information including the temporary public key generated by REQ to generate KeyInfo. REQ .

[0151] (6) Calculate the message integrity verification key;

[0152] REQ is based on including KeyInfo REQ The corresponding temporary private key and KeyInfo AAC The recovered temporary public key is used for key exchange calculation to obtain the first key K1, and K1 is combined with the Nonce. REQ Nonce AACIn addition to other information (the other information used by REQ and AAC is the same and optional, such as a specific string), the message integrity verification key is calculated using a key derivation algorithm.

[0153] (7) Calculate MIC REQ ;

[0154] (8) Calculate MacTag REQ .

[0155] S210, REQ sends a second authentication message REQAuth to AAC.

[0156] The REQAuth includes a Nonce. AAC KeyInfo REQ MIC REQ and MacTag REQ Among them, Nonce AAC It should be equal to the Nonce in AACAuth. AAC ;MIC REQ REQ utilizes its pre-shared evidence verification key IK with AS-AAC. REQ_AS The message integrity verification algorithm, which is pre-shared with AS-AAC, is used to verify the integrity of messages including Nonce. AS_AAC The calculations were performed using the included data. MacTag REQ REQ uses message integrity verification key pairs, including those in REQAuth excluding MacTag. REQ The information is calculated from other fields besides the main data.

[0157] S211. After receiving the REQAuth, AAC performs the following operations, including:

[0158] (1) Check the Nonce in REQAuth AAC Nonce generated by AAC AAC Check if they match; if not, discard the REQAuth.

[0159] (2) Calculate the message integrity verification key;

[0160] AAC is based on including KeyInfo AAC The corresponding temporary private key and KeyInfo REQ The recovered temporary public key is used for key exchange calculation to obtain the first key K1, and K1 is combined with the Nonce. REQ Nonce AAC In addition to other information (the other information used by AAC and REQ is the same and optional, such as a specific string), the message integrity verification key is calculated using a key derivation algorithm.

[0161] (3) Verify MacTag REQ ;

[0162] AAC uses message integrity verification key pairs, including those in REQAuth excluding the MacTag. REQ Information including other fields is calculated locally to obtain the MacTag. REQ (This calculation method is the same as REQ calculation of MacTag) REQ (Using the same method), compare the calculated MacTag REQ MacTag in REQAuth REQ If they match, the REQ's identity is deemed legitimate; otherwise, the REQAuth is discarded.

[0163] (4) Assigning a temporary identity identifier (TID) to REQ REQnew ;

[0164] (5) Optional, calculate MIC AAC .

[0165] S212, AAC sends the first evidence storage message AACUpdate to AS-AAC.

[0166] The AACUpdate includes ID AAC Nonce AAC TID REQnew MIC REQ and MIC AAC Among them, ID AAC MIC AAC MIC is an optional field. AAC AAC utilizes the pre-shared verification key IK between itself and AS-AAC. AAC_AS The message integrity verification algorithm pre-shared with AS-AAC is used to verify the MIC in AACUpdate. AAC The results are calculated from other fields previously used. For example, when AACUpdate includes, in sequence... ID AAC Nonce AAC TID REQnew MIC REQ and MIC AAC At that time, MIC AAC AAC utilizes the aforementioned IK AAC_AS The message integrity verification algorithm is used to check the fields in AACUpdate. ID AAC Nonce AAC TID REQnewand MIC REQ Calculated.

[0167] S213. After receiving AACUpdate, AS-AAC performs the following operations, including:

[0168] (1) If MIC exists in AACUpdate AAC Then verify MIC AAC ;

[0169] AS-AAC utilizes a pre-shared verification key IK with AAC. AAC_AS The message integrity verification algorithm pre-shared with AAC is used to verify the MIC in AACUpdate. AAC The MIC is calculated from the other fields previously. AAC Compare the calculated MIC AAC With MIC in AACUpdate AAC Check if they match; if not, discard AACUpdate.

[0170] (2) Verify MIC REQ ;

[0171] AS-AAC utilizes the pre-shared evidence verification key IK between AS-AAC and REQ. REQ_AS A pre-shared message integrity verification algorithm is used to verify the integrity of messages including Nonce. AS_AAC The MIC is obtained from the calculation data. REQ Compare the calculated MIC REQ With MIC in AACUpdate REQ Check if they match; if not, discard AACUpdate.

[0172] (3) Generate and save the REQ request through the record, and save the TID. REQnew ;

[0173] (4) Optional, calculate MIC AS_AAC .

[0174] S214, AS-AAC sends the first evidence confirmation message ASAck to AAC.

[0175] The ASAck includes ID AAC Nonce AAC and MIC AS_AAC Among them, ID AAC MIC AS_AAC MIC is an optional field. AS_AAC AS-AAC utilizes the pre-shared verification key IK between itself and AAC. AAC_ASThe message integrity verification algorithm pre-shared with AAC is used to verify the MIC in ASAck. AS_AAC The results were obtained from calculations performed on other fields previously.

[0176] S215. After receiving ASAck, AAC performs the following operations, including:

[0177] (1) If an ID exists in ASAck AAC Then check ID AAC Is it consistent with AAC's own identity ID? AAC same;

[0178] (2) Check the Nonce AAC Is it related to the Nonce generated by AAC? AAC same;

[0179] (3) If MIC exists in ASAck AS_AAC Then verify MIC AS_AAC ;

[0180] AAC utilizes a pre-shared verification key IK with AS-AAC. AAC_AS The message integrity verification algorithm pre-shared with AS-AAC is used to verify the MIC in ASAck. AS_AAC The MIC is calculated from the other fields previously. AS_AAC Compare the calculated MIC AS_AAC MIC in ASAck AS_AAC Are they consistent?

[0181] (4) After the above checks and verifications are passed, calculate MacTag. AAC If any step in the above checks and verifications fails, the ASAck must be discarded immediately.

[0182] (5) Calculate the session key;

[0183] AAC combines K1 calculated in S211. Nonce REQ ID AAC Nonce AAC Other information (the other information used by AAC and REQ is the same and optional, such as a specific string) is used to calculate the session key using a key derivation algorithm, which is used for subsequent secure communication between REQ and AAC.

[0184] S216. AAC sends an authentication completion message AACFinish to REQ.

[0185] The AACFinish includes TID REQnew and MacTag AACAmong them, MacTag AAC AAC uses message integrity verification key pairs, including those in AACFinish except for MacTag. AAC Information, including other fields, is calculated locally; TID REQnew Should be consistent with the TID in AACUpdate REQnew same.

[0186] S217. After receiving AACFinish, REQ performs the following operations, including:

[0187] (1) Verify MacTag AAC ;

[0188] REQ utilizes message integrity verification key pairs, including those in AACFinish except for MacTag. AAC Information including other fields is calculated locally to obtain the MacTag. AAC (This calculation method is the same as AAC's calculation of MacTag) AAC (Using the same method), compare the calculated MacTag AAC MacTag in AACFinish AAC If they match, the AAC identity is considered valid; otherwise, AACFinish is discarded.

[0189] (2) Save TID REQnew ;

[0190] (3) Calculate the session key;

[0191] REQ will combine with K1 calculated in S209. Nonce REQ ID AAC Nonce AAC Other information (the other information used by REQ and AAC is the same and optional, such as a specific string) is used to calculate the session key using a key derivation algorithm, which is used for subsequent secure communication between REQ and AAC.

[0192] Therefore, in S211 and S217, identity authentication for REQ and AAC is realized respectively, that is, bidirectional identity authentication for REQ and AAC is realized.

[0193] See Figure 3 This is an embodiment of an identity authentication method in roaming situations, the identity authentication method including:

[0194] S301, REQ generates Nonce REQ Nonce REQID and EncPub ASGenerate Security capabilities as needed. REQ .

[0195] S302, REQ sends an authentication request message ATTACH to AAC.

[0196] This ATTACH includes security capabilities. REQ EncPub AS Route AS and Nonce REQ Among them, EncPub AS REQ utilizes the public key pair of the encryption certificate, including the ID. REQ Nonce REQID The encrypted identity information of REQ is calculated from the encrypted data, including Route. AS The identifier of the authentication server indicating REQ trust; Security capabilities REQ This is an optional field.

[0197] S303, AAC generates Nonce AAC .

[0198] AAC according to Route AS It is determined whether the authentication server trusted by REQ is the same as the authentication server trusted by itself. If they are different, it is determined to be a roaming situation. In this embodiment, the AS-REQ trusted by REQ and the AS-AAC trusted by AAC are two independent authentication servers.

[0199] S304, AAC sends the first authentication request message AACVeri to AS-AAC.

[0200] The AAC Veri includes EncPub AS Nonce REQ ID AAC Nonce AAC and Route AS Among them, EncPub AS Nonce REQ and Route AS They should be equal to the corresponding fields in ATTACH; ID AAC This is an optional field.

[0201] After S305 and AS-AAC receive AACVeri, according to Rout AS Determine AS-REQ and send a second authentication request message AS-AACVeri to AS-REQ.

[0202] AS-AACVeri is generated based on AACVeri, and AS-AACVeri includes EncPub. AS Nonce REQ ID AAC and Nonce AAC EncPub AS Nonce REQ ID AAC and Nonce AAC They should be equal to the corresponding fields in AACVeri.

[0203] S306. After receiving AS-AACVeri, AS-REQ performs the following operations, including:

[0204] (1) Decrypt EncPub using the private key of the encryption certificate AS Get ID REQ and Nonce REQID According to ID REQ Determine if the REQ's identity is valid. If valid, continue with subsequent operations; otherwise, discard AAC-ASVeri.

[0205] (2) Generate a nonce for evidence storage AS_REQ .

[0206] (3) ID REQ and Nonce REQID Perform an XOR operation to obtain

[0207] (4) Calculate IAK;

[0208] AS-REQ utilizes its pre-shared encryption key K with REQ. REQ_AS Combined with ID REQ Nonce REQ ID AAC Nonce AAC The computational data, including the key derivation algorithm pre-agreed with REQ, is used to calculate IAK.

[0209] (5) Optionally, AS-REQ utilizes its pre-shared encryption key EK with AS-AAC. AS EncData is generated by encrypting information including IAK. AS_REQ .

[0210] S307, AS-REQ sends a second authentication response message AS-REQVeri to AS-AAC.

[0211] The AS-REQVeri includes ID AAC Nonce AAC Nonce AS_REQ and IAK. Among them, ID AAC Nonce AAC They should be equal to the corresponding fields in AS-AACVeri; if EncData exists. AS_REQ At that time, AS-REQ utilizes EncData AS_REQ Replace IAK in AS-REQVeri.

[0212] After receiving AS-REQVeri, S308 and AS-AAC perform the following operations, including:

[0213] (1) Obtain IAK; when EncData exists in AS-REQVeri AS_REQ At that time, it utilizes the pre-shared encryption key EK between itself and AS-REQ. AS For EncData AS_REQ Decryption yields IAK;

[0214] (2) Optionally, AS-AAC utilizes its pre-shared encryption key EK with AAC. AAC_AS EncData is generated by encrypting information including IAK. AS_AAC .

[0215] S309, AS-AAC sends the first authentication response message ASVeri to AAC.

[0216] The ASVeri includes Nonce REQ ID AAC Nonce AAC Nonce AS_REQ and IAK. Among them, ID AAC It is an optional field, and Nonce REQ ID AAC and Nonce AAC They should be equal to the corresponding fields in AACVeri; if EncData exists. AS_AAC At that time, AS-AAC will utilize EncData AS_AAC Replace IAK in ASVeri.

[0217] After receiving ASVeri, S310 and AAC perform the following operations, including:

[0218] (1) Check the Nonce in ASVeri AAC Nonce generated by AAC AAC Whether they match, if an ID exists in ASVeriAAC Then check the ID in ASVeri. AAC With AAC's own identity ID AAC Check if they match; if any item does not match, discard ASVeri.

[0219] (2) Obtain IAK;

[0220] EncData is included in ASVeri. AS_AAC In this case, the pre-shared encryption key EK between it and AS-AAC is used. AAC_AS Decrypting EncData AS_AAC IAK was obtained;

[0221] (3) Based on the IAK and other information (the other information used by AAC and REQ is the same and optional, such as a specific string, etc.), the EIAK is calculated and generated using the key derivation algorithm;

[0222] (4) Calculate KeyInfo AAC ;

[0223] AAC performs an XOR operation on EIAK and information including the temporary public key generated by AAC to generate KeyInfo. AAC .

[0224] S311, AAC sends the first authentication message AACAuth to REQ.

[0225] The AACAuth includes security capabilities. AAC KeyInfo AAC , Nonce REQ ID AAC Nonce AAC and Nonce AS_REQ .in, Nonce REQ ID AAC Nonce AAC Nonce AS_REQ They should be equal to the corresponding fields in ASVeri; Security capabilities AAC This is an optional field if and only if security capabilities exist in ATTACH. REQ Security capabilities only exist at that time AAC .

[0226] S312. After receiving AACAuth, REQ performs the following operations, including:

[0227] (1) Using Nonce REQID and Perform an XOR operation to recover the ID REQ ;

[0228] (2) Check the recovered ID REQ With REQ's own identity ID REQ To check for consistency, examine the Nonce in AACAuth. REQ Nonce generated with REQ REQ Check if they match; if any item does not match, discard AACAuth.

[0229] (3) Calculate IAK;

[0230] REQ utilizes a pre-shared encryption key K with AS-REQ. REQ_AS Combined with ID REQ Nonce REQ ID AAC Nonce AAC The computational data, including the key derivation algorithm agreed upon with AS-REQ beforehand, is used to calculate IAK. The computational data used by REQ to calculate IAK is the same as that used by AS-REQ to calculate IAK in S306.

[0231] (4) Based on the IAK and other information (the other information used by AAC and REQ is the same and optional, such as a specific string, etc.), the EIAK is calculated and generated using the key derivation algorithm;

[0232] (5) Calculate KeyInfo REQ Its calculation method is the same as Figure 2 The relevant descriptions in the embodiments are the same;

[0233] (6) Calculate the message integrity verification key;

[0234] REQ is based on including KeyInfo REQ The corresponding temporary private key and KeyInfo AAC The recovered temporary public key is used for key exchange calculation to obtain the first key K1, and K1 is combined with the Nonce. REQ Nonce AAC In addition to other information (the other information used by REQ and AAC is the same and optional, such as a specific string), the message integrity verification key is calculated using a key derivation algorithm.

[0235] (7) Calculate MIC REQ ;

[0236] (8) Calculate MacTag REQ .

[0237] S313, REQ sends a second authentication message REQAuth to AAC.

[0238] The REQAuth includes a Nonce. AAC KeyInfo REQ MIC REQ and MacTag REQ Among them, Nonce AAC It should be equal to the Nonce in AACAuth. AAC ;MIC REQ REQ utilizes its pre-shared evidence verification key IK with AS-REQ. REQ_AS The message integrity verification algorithm, which is pre-shared with AS-REQ, is used to verify the integrity of messages including Nonce. AS_REQ The calculations were performed using the included data. MacTag REQ REQ uses message integrity verification key pairs, including those in REQAuth excluding MacTag. REQ Information, including other fields, is calculated locally.

[0239] S314. After receiving the REQAuth, AAC performs the following operations, including:

[0240] (1) Check the Nonce in REQAuth AAC Nonce generated by AAC AAC Check if they match; if not, discard the REQAuth.

[0241] (2) Calculate the message integrity verification key;

[0242] AAC is based on including KeyInfo AAC The corresponding temporary private key and KeyInfo REQ The recovered temporary public key is used for key exchange calculation to obtain the first key K1, and K1 is combined with the Nonce. REQ Nonce AAC In addition to other information (the other information used by AAC and REQ is the same and optional, such as a specific string), the message integrity verification key is calculated using a key derivation algorithm.

[0243] (3) Verify MacTag REQ ;

[0244] AAC uses message integrity verification key pairs, including those in REQAuth excluding the MacTag. REQInformation including other fields is calculated locally to obtain the MacTag. REQ Compare the calculated MacTag REQ MacTag in REQAuth REQ If they match, the REQ's identity is deemed legitimate; otherwise, the REQAuth is discarded.

[0245] (4) Assigning a temporary identity identifier (TID) to REQ REQnew ;

[0246] (5) Optional, AAC calculation generates MIC AAC .

[0247] S315, AAC sends the first evidence storage message AACUpdate to AS-AAC.

[0248] The AACUpdate includes ID AAC Nonce AAC TID REQnew MIC REQ and MIC AAC Among them, ID AAC This is an optional field; It should be equal to the corresponding field in ASVeri; MIC REQ It should equal the corresponding field in REQAuth; MIC AAC MIC is an optional field. AAC AAC utilizes the pre-shared verification key IK between itself and AS-AAC. AAC_AS The message integrity verification algorithm pre-shared with AS-AAC is used to verify the MIC in AACUpdate. AAC The results were obtained from calculations performed on other fields previously.

[0249] S316. After receiving AACUpdate, AS-AAC performs the following operations, including:

[0250] (1) When MIC exists in AACUpdate AAC At that time, verify the MIC AAC ;

[0251] AS-AAC utilizes a pre-shared verification key IK with AAC. AAC_AS The message integrity verification algorithm pre-shared with AAC is used to verify the MIC in AACUpdate. AAC The MIC is calculated from the other fields previously. AAC Calculate the MIC AAC With MIC in AACUpdateAAC The comparison is performed, and if they are inconsistent, AACUpdate is discarded.

[0252] (2) Optional, AS-AAC calculation generates MIC AS_AAC .

[0253] S317, AS-AAC sends the second evidence storage message ASUpdate to AS-REQ.

[0254] This ASUpdate includes ID AAC TID REQnew MIC REQ and MIC AS_AAC .in, ID AAC TID REQnew MIC REQ They should be equal to the corresponding fields in AACUpdate; MIC AS_AAC MIC is an optional field. AS_AAC AS-AAC utilizes the pre-shared verification key IK between itself and AS-REQ. AS MIC in ASUpdate AS_AAC The other fields were calculated locally.

[0255] After receiving ASUpdate, S318 and AS-REQ perform the following operations, including:

[0256] (1) When MIC exists in ASUpdate AS At that time, verify the MIC AS_AAC ;

[0257] AS-REQ utilizes a pre-shared verification key IK with AS-AAC. AS MIC in ASUpdate AS_AAC The MIC is calculated locally from the other fields previously used. AS_AAC Compare the calculated MIC AS_AAC With MIC in ASUpdate AS_AAC Check if they match; if not, discard ASUpdate.

[0258] (2) Verify MIC REQ ;

[0259] AS-REQ utilizes the pre-shared evidence verification key IK between itself and REQ. REQ_AS A pre-shared message integrity verification algorithm is used to verify the integrity of messages including Nonce. AS_REQ The MIC is obtained from the calculation data. REQCompare the calculated MIC REQ MIC in ASUpdate REQ Check if they match; if not, discard ASUpdate.

[0260] (3) Generate and save the REQ request through the record, and save the TID in ASUpdate. REQnew ;

[0261] (4) Optional, calculate MIC AS_REQ .

[0262] S319, AS-REQ sends a second evidence confirmation message AS-REQAck to AS-AAC.

[0263] The AS-REQAck includes ID AAC and MIC AS_REQ Among them, ID AAC It should equal the corresponding field in ASUpdate; MIC AS_REQ This is an optional field, which is the pre-shared verification key IK between AS-REQ and AS-AAC. AS The message integrity verification algorithm pre-shared between AS-AAC and AS-REQAck is used to verify the MIC in AS-REQAck. AS_REQ The results were obtained from calculations performed on other fields previously.

[0264] After receiving the AS-REQAck, S320 and AS-AAC perform the following operations, including:

[0265] (1) If MIC exists in AS-REQAck AS_REQ Then verify MIC AS_REQ ;

[0266] AS-AAC utilizes the pre-shared evidence verification key IK between AS-REQ and AS-REQ. AS The message integrity verification algorithm pre-shared with AS-REQ is used to verify the MIC in AS-REQAck. AS_REQ The MIC is calculated from the other fields previously. AS_REQ Compare the calculated MIC AS_REQ MIC in AS-REQAck AS_REQ Check if they match; if not, discard the AS-REQAck.

[0267] (2) Optional, calculate MIC AS .

[0268] S321, AS-AAC sends the first presence confirmation message AS-AACAck to AAC.

[0269] The AS-AACAck includes ID AAC Nonce AAC and MIC AS Among them, ID AAC MIC AS MIC is an optional field. AS AS-AAC utilizes the pre-shared verification key IK between itself and AAC. AAC_AS The message integrity verification algorithm pre-shared with AAC is used to verify the MIC in AS-AACAck. AS The results were obtained from calculations performed on other fields previously.

[0270] S322. After receiving AS-AACAck, AAC performs the following operations, including:

[0271] (1) If an ID exists in AS-AACAck AAC Then check ID AAC Is it consistent with AAC's own identity ID? AAC same;

[0272] (2) Check the Nonce AAC Is it related to the Nonce generated by AAC? AAC same;

[0273] (3) If MIC exists in AS-AACAck AS Then verify MIC AS ;

[0274] AAC utilizes a pre-shared verification key IK with AS-AAC. AAC_AS The message integrity verification algorithm pre-shared with AS-AAC is used to verify the MIC in AS-AAC. AS The MIC is calculated from the other fields previously. AS Compare the calculated MIC AS MIC in AS-AACAck AS Are they consistent?

[0275] (4) After the above checks and verifications are passed, calculate MacTag. AAC If any step in the above checks and verifications fails, the AS-AACAck must be discarded immediately.

[0276] (5) Calculate the session key;

[0277] AAC combines K1 calculated in S314. Nonce REQ ID AAC Nonce AACOther information (the other information used by AAC and REQ is the same and optional, such as a specific string) is used to calculate the session key using a key derivation algorithm, which is used for subsequent secure communication between REQ and AAC.

[0278] S323, AAC sends an authentication completion message AACFinish to REQ.

[0279] The AACFinish includes TID REQnew and MacTag AAC Among them, TID REQnew Should be consistent with the TID in AACUpdate REQnew Same; MacTag AAC AAC uses message integrity verification key pairs, including those in AACFinish except for MacTag. AAC Information, including other fields, is calculated locally.

[0280] S324. After receiving AACFinish, REQ performs the following operations, including:

[0281] (1) Verify MacTag AAC ;

[0282] REQ utilizes message integrity verification key pairs, including those in AACFinish except for MacTag. AAC Information including other fields is calculated locally to obtain the MacTag. AAC Compare the calculated MacTag AAC MacTag in AACFinish AAC If they match, the AAC identity is considered valid; otherwise, AACFinish is discarded.

[0283] (2) Save TID REQnew ;

[0284] (3) Calculate the session key;

[0285] REQ will combine with K1 calculated in S312. Nonce REQ ID AAC Nonce AAC Other information (the other information used by REQ and AAC is the same and optional, such as a specific string) is used to calculate the session key using a key derivation algorithm, which is used for subsequent secure communication between REQ and AAC.

[0286] Therefore, in S314 and S324, identity authentication for REQ and AAC is implemented respectively, that is, bidirectional identity authentication for REQ and AAC is achieved.

[0287] In the above embodiments, each message may also carry a hash value. X_Y The hash value X_Y This is calculated by the sending entity X using a hash algorithm on the latest preceding message received from the peer entity Y. It is used by the peer entity Y to verify whether entity X has received the complete latest preceding message. Here, HASH... REQ_AAC This represents the hash value calculated by REQ for the latest preceding message sent by AAC. AAC_REQ HASH represents the hash value calculated by AAC for the latest preceding message sent by the received REQ. AAC_AS-AAC HASH represents the hash value calculated by AAC for the latest preceding message received from AS-AAC. AS-AAC_AAC HASH represents the hash value calculated by AS-AAC for the latest preceding message sent by AAC. AS-AAC_AS-REQ HASH represents the hash value calculated by AS-AAC for the latest preceding message sent by AS-REQ. AS-REQ_AS-AAC This represents the hash value calculated by AS-REQ for the latest preceding message received from AS-AAC. If the message currently sent by sender entity X is the first message exchanged between entity X and entity Y, meaning that entity X has not received any preceding messages from peer entity Y, then the hash value in this message... X_Y It may not exist or be meaningless.

[0288] Correspondingly, after the peer entity Y receives a message sent by entity X, if the message contains a hash... X_Y If entity Y has not sent a preceding message to entity X, then entity Y ignores the hash. X_Y When entity Y has previously sent a preceding message to entity X, entity Y uses a hash algorithm to calculate a hash value locally for the latest preceding message previously sent to entity X, and then hashes it with the hash value carried in the received message. X_Y If they match, proceed with the next steps; otherwise, discard or end the identification process.

[0289] In this invention, for entity X, the preceding message sent by peer entity Y to entity X refers to any message received by entity X from peer entity Y before entity X sends message M to peer entity Y; the latest preceding message sent by peer entity Y to entity X refers to the latest message received by entity X from peer entity Y before entity X sends message M to peer entity Y. If message M sent by entity X to its peer entity Y is the first message exchanged between entity X and entity Y, then there are no preceding messages sent by peer entity Y to entity X before entity X sends message M to its peer entity Y.

[0290] The above Figure 2 and Figure 3 The optional fields and optional operations in the corresponding embodiments are shown in the accompanying drawings. Figure 2 and Figure 3 The asterisk (*) indicates the content. The order of the various contents included in the messages in all the above embodiments is not limited, and unless otherwise specified, the order in which the message receiver operates on the relevant messages and processes the contents included in the messages is not limited.

[0291] based on Figures 1 to 3 For the corresponding method implementation, please refer to [link / reference]. Figure 4 This application provides an authentication access controller, which includes:

[0292] The receiving unit 401 is configured to receive an authentication request message sent by the requesting device, wherein the authentication request message includes encrypted identity information of the requesting device; the encrypted identity information of the requesting device is obtained by the requesting device encrypting encrypted data, including the identity identifier of the requesting device, using the public key of the encryption certificate;

[0293] Sending unit 402 is used to send a first authentication request message carrying encrypted identity information of the requesting device to a second authentication server trusted by the authentication access controller;

[0294] The receiving unit 401 is further configured to receive a first authentication response message sent by the second authentication server, and obtain from the first authentication response message a stored random number generated by the first authentication server trusted by the requesting device and an identity authentication key generated by the first authentication server; the identity authentication key is calculated based on computational data including a pre-shared encryption key between the first authentication server and the requesting device.

[0295] The sending unit 402 is further configured to send a first verification message to the requesting device, wherein the first verification message includes the evidence storage random number;

[0296] The receiving unit 401 is further configured to receive a second verification message sent by the requesting device, the second verification message including a first identity authentication code and a first message integrity verification code; the first message integrity verification code is generated by the requesting device using a message integrity verification key between itself and the authentication access controller to calculate other fields in the second verification message except for the first message integrity verification code; wherein, the message integrity verification key is calculated based on information including the identity authentication key;

[0297] The processing unit 403 is used to verify the integrity check code of the first message. After the verification is successful, the identity of the requesting device is determined to be legitimate, and an authentication completion message and a first evidence storage message are generated.

[0298] The sending unit 402 is also configured to send the authentication completion message to the requesting device and the first evidence storage message to the second authentication server.

[0299] Optionally, the sending unit 402 first sends the first evidence storage message, and after the receiving unit 401 receives the first evidence storage confirmation message, the sending unit 402 then sends the authentication completion message to the requesting device.

[0300] Optionally, if the first verification message further includes a first key exchange parameter generated by the authentication access controller based on the identity authentication key, and the second verification message further includes a second key exchange parameter generated by the requesting device based on the identity authentication key, then the processing unit 403 is further configured to: perform key exchange calculation to generate a first key based on the temporary private key corresponding to the first key exchange parameter and the temporary public key included in the second key exchange parameter, and calculate the message integrity verification key using a key derivation algorithm based on information including the first key.

[0301] Optionally, the processing unit 403 is further configured to: use the identity authentication key to encrypt information including the temporary public key generated by the authentication access controller using a symmetric encryption algorithm to generate the first key exchange parameters; the second key exchange parameters in the second verification message received by the receiving unit 401 are generated by the requesting device using the identity authentication key to encrypt information including the temporary public key generated by the requesting device using a symmetric encryption algorithm.

[0302] The processing unit 403 calculates the message integrity verification key by performing a key exchange calculation based on the temporary private key corresponding to the first key exchange parameter and the temporary public key recovered from the second key exchange parameter to generate the first key, and then calculating the message integrity verification key using the key derivation algorithm based on information including the first key.

[0303] Optionally, the processing unit 403 is specifically used to: calculate the hash value of the identity authentication key, and perform an XOR operation on the hash value and information including the temporary public key generated by the authentication access controller to generate the first key exchange parameters.

[0304] Optionally, the authentication request message received by the receiving unit 401 further includes a first random number generated by the requesting device; the first authentication request message sent by the sending unit 402 further includes the first random number and a second random number generated by the authentication access controller.

[0305] The first authentication response message received by the receiving unit 401 also includes the first random number and the second random number; the first verification message sent by the sending unit 402 also includes the first random number and the second random number, the calculation data of the identity authentication key also includes the first random number and the second random number, and the second verification message received by the receiving unit 401 also includes the second random number;

[0306] The processing unit 403 is further configured to: verify the consistency between the second random number in the first authentication response message and the second random number generated by the authentication access controller; and verify the consistency between the second random number in the second verification message and the second random number generated by the authentication access controller.

[0307] Optionally, if the authentication request message received by the receiving unit 401 further includes security capability parameter information supported by the requesting device, then the processing unit 403 is further configured to: determine the specific security policy used by the authentication access controller based on the security capability parameter information, and the first verification message further includes the specific security policy.

[0308] Optionally, if the authentication request message received by the receiving unit 401 further includes the identity identifier of at least one authentication server trusted by the requesting device, then the processing unit 403 is further configured to: determine the second authentication server based on the identity identifier of the at least one authentication server trusted by the requesting device and the identity identifier of the authentication server trusted by the authentication access controller in the authentication request message.

[0309] Optionally, the processing unit 403 is further configured to: assign a temporary identity identifier to the requesting device; then the authentication completion message and the first evidence storage message sent by the sending unit 402 also include the temporary identity identifier of the requesting device.

[0310] Optionally, the receiving unit 401 obtains the identity authentication key in the following manner:

[0311] The identity authentication key is obtained by decrypting the ciphertext of the identity authentication key using a pre-shared encryption key with the second authentication server; the ciphertext of the identity authentication key is generated by the second authentication server encrypting information including the identity authentication key using a pre-shared encryption key with the authentication access controller.

[0312] Optionally, the first authentication request message sent by the sending unit 402 may further include the identity identifier of the authentication access controller; the first authentication response message received by the receiving unit 401 may further include the identity identifier of the authentication access controller.

[0313] The processing unit 403 is further configured to: verify the consistency between the identity identifier of the authentication access controller in the first authentication response message and the identity identifier of the authentication access controller itself.

[0314] Optionally, if the first authentication response message received by the receiving unit 401 further includes the encrypted identity of the requesting device, and the first verification message sent by the sending unit 402 further includes the identity of the authentication access controller, then the processing unit 403 is further configured to: when it is determined that the identity of the requesting device is legitimate, calculate and generate a session key for subsequent secure communication based on information including the first key, the encrypted identity of the requesting device, and the identity of the authentication access controller.

[0315] Optionally, the first message integrity check code in the second verification message received by the receiving unit 401 is generated by the requesting device using the message integrity check key to calculate other fields in the second verification message besides the first message integrity check code.

[0316] Optionally, the message sent by the authentication access controller to the requesting device may also include a hash value calculated by the authentication access controller for the latest preamble message received from the requesting device; the message sent by the authentication access controller to the second authentication server may also include a hash value calculated by the authentication access controller for the latest preamble message received from the second authentication server.

[0317] See Figure 5 This application embodiment also provides a requesting device, the requesting device comprising:

[0318] The sending unit 501 is configured to send an authentication request message to the authentication access controller, wherein the authentication request message includes encrypted identity information of the requesting device; the encrypted identity information of the requesting device is obtained by the requesting device encrypting encrypted data, including the identity identifier of the requesting device, using the public key of the encryption certificate;

[0319] The receiving unit 502 is configured to receive a first verification message sent by the authentication access controller, wherein the first verification message includes a stored random number;

[0320] Processing unit 503 is configured to: calculate and generate a first identity authentication code using a pre-shared evidence verification key between the requesting device and its trusted first authentication server, including the evidence-stored random number; and calculate and generate a first message integrity verification code using a message integrity verification key between the requesting device and the authentication access controller, including fields in the second verification message other than the first message integrity verification code; wherein the message integrity verification key is calculated based on information including an identity authentication key, and the identity authentication key is calculated based on computational data including a pre-shared encryption key between the requesting device and the first authentication server.

[0321] The sending unit 501 is further configured to send the second verification message to the authentication access controller, wherein the second verification message includes the first identity authentication code and the first message integrity verification code;

[0322] The receiving unit 502 is also used to receive the authentication completion message sent by the authentication access controller;

[0323] The processing unit 503 is also used to verify the second message integrity check code in the authentication completion message. After the verification is successful, the identity of the authentication access controller is determined to be legitimate. The second message integrity check code is generated by the authentication access controller using the message integrity check key to calculate other fields in the authentication completion message, excluding the second message integrity check code.

[0324] Optionally, if the first verification message further includes a first key exchange parameter generated by the authentication access controller based on the identity authentication key; and the second verification message further includes a second key exchange parameter generated by the requesting device based on the identity authentication key, then the processing unit 503 is further configured to: perform key exchange calculation to generate a first key based on the temporary private key corresponding to the second key exchange parameter and the temporary public key included in the first key exchange parameter, and calculate the message integrity verification key using a key derivation algorithm based on information including the first key.

[0325] Optionally, the first key exchange parameter in the first verification message received by the receiving unit 502 is generated by the authentication access controller using the identity authentication key and employing a symmetric encryption algorithm to encrypt information including the temporary public key generated by the authentication access controller; the processing unit 503 is further configured to: use the identity authentication key and employ a symmetric encryption algorithm to encrypt information including the temporary public key generated by the requesting device to generate the second key exchange parameter.

[0326] The processing unit 503 calculates the message integrity verification key by performing a key exchange calculation based on the temporary private key corresponding to the second key exchange parameter and the temporary public key recovered from the first key exchange parameter to generate the first key, and then calculating the message integrity verification key using the key derivation algorithm based on information including the first key.

[0327] Optionally, the processing unit 503 is specifically used to: calculate the hash value of the identity authentication key, and perform an XOR operation on the hash value and information including the temporary public key generated by the requesting device to generate the second key exchange parameters.

[0328] Optionally, the authentication request message sent by the sending unit 501 further includes a first random number generated by the requesting device; the first verification message received by the receiving unit 502 further includes the first random number and a second random number generated by the authentication access controller, the calculation data of the identity authentication key further includes the first random number and the second random number, and the second verification message sent by the sending unit 501 further includes the second random number;

[0329] The processing unit 503 is further configured to: verify the consistency between the first random number in the first verification message and the first random number generated by the requesting device.

[0330] Optionally, the encrypted data of the encrypted identity information of the requesting device further includes the identity identifier encryption key generated by the requesting device; then the first verification message received by the receiving unit 502 also includes the encrypted identity identifier of the requesting device; the encrypted identity identifier of the requesting device is obtained by the first authentication server encrypting the identity identifier of the requesting device using the identity identifier encryption key obtained by decrypting the encrypted identity information of the requesting device.

[0331] The processing unit 503 is further configured to: verify the encrypted identity of the requesting device in the first verification message based on its own identity identifier and the identity identifier encryption key.

[0332] Optionally, the authentication completion message received by the receiving unit 502 may also include a temporary identity identifier assigned to the requesting device by the authentication access controller; then the processing unit 503 may further be used to save the temporary identity identifier of the requesting device when it determines that the identity of the authentication access controller is legitimate.

[0333] Optionally, if the first verification message received by the receiving unit 502 further includes the identity identifier of the authentication access controller, then the processing unit 503 is further configured to: when it is determined that the identity of the authentication access controller is legitimate, calculate and generate a session key for subsequent secure communication based on information including the first key, the encrypted identity identifier of the requesting device, and the identity identifier of the authentication access controller.

[0334] Optionally, the processing unit 503 is further configured to use the message integrity verification key to calculate and generate a first message integrity verification code from the fields in the second verification message other than the first message integrity verification code.

[0335] The second message integrity check code in the authentication completion message received by the receiving unit 502 is generated by the authentication access controller using the message integrity check key to calculate other fields in the authentication completion message besides the second message integrity check code.

[0336] Optionally, the message sent by the requesting device to the authentication access controller may also include a hash value calculated by the requesting device for the latest preceding message sent by the authentication access controller.

[0337] See Figure 6 This application embodiment also provides a first authentication server, which is an authentication server requesting device trust, including:

[0338] The processing unit 601 is used to decrypt the ciphertext of the identity information of the requesting device using the private key corresponding to the encryption certificate to obtain the identity identifier of the requesting device, determine the legitimacy of the requesting device based on the identity identifier of the requesting device, and generate a storage random number and an identity authentication key after determining that the identity of the requesting device is legitimate; the identity authentication key is calculated based on computational data including the pre-shared encryption key between the first authentication server and the requesting device.

[0339] The processing unit 601 is also used to verify the first identity authentication code in the first evidence storage message, and after the verification is successful, to generate and store the request pass record of the requesting device.

[0340] Optionally, the processing unit 601 is further configured to generate a first evidence confirmation message after verifying the first identity authentication code in the first evidence storage message.

[0341] Optionally, the processing unit 601 is further configured to: when generating and storing the request pass record of the requesting device, save the temporary identity identifier assigned to the requesting device by the authentication access controller.

[0342] Optionally, when the first authentication server is different from the second authentication server trusted by the authentication access controller, the first authentication server further includes:

[0343] The receiving unit is configured to receive a second authentication request message sent by the second authentication server; the second authentication request message includes encrypted identity information of the requesting device.

[0344] The sending unit is configured to send a second authentication response message to the second authentication server, wherein the second authentication response message includes the identity authentication key and the evidence storage random number.

[0345] The receiving unit is further configured to receive a second evidence storage message sent by the second authentication server, wherein the second evidence storage message includes the first identity authentication code.

[0346] The processing unit 601 is specifically used to verify the first identity authentication code in the second evidence storage message.

[0347] Optionally, the processing unit 601 is further configured to generate a second evidence storage confirmation message after the first identity authentication code in the second evidence storage message has been verified; the sending unit is further configured to send the second evidence storage confirmation message to the second authentication server.

[0348] Optionally, the message sent by the first authentication server to the second authentication server may also include a hash value calculated by the first authentication server for the latest preceding message received from the second authentication server.

[0349] See Figure 7 This application embodiment also provides a second authentication server, which is an authentication server trusted by the authentication access controller, including:

[0350] The receiving unit 701 is used to receive a first authentication request message sent by the authentication access controller, which carries encrypted identity information of the requesting device.

[0351] Sending unit 702 is used to send a first authentication response message to the authentication access controller. The first authentication response message includes a stored random number generated by the first authentication server trusted by the requesting device and an identity authentication key generated by the first authentication server.

[0352] The receiving unit 701 is further configured to receive a first evidence storage message sent by the authentication access controller, wherein the first evidence storage message includes a first identity authentication code.

[0353] Optionally, the first evidence storage message received by the receiving unit 701 further includes a second identity authentication code, which is generated by the authentication access controller using its pre-shared verification key with the second authentication server to calculate other fields preceding the second identity authentication code in the first evidence storage message; then the second authentication server further includes:

[0354] The verification unit is used to verify the correctness of the second identity authentication code using a pre-shared verification key with the authentication access controller.

[0355] Optionally, when the second authentication server is different from the first authentication server trusted by the requesting device, the second authentication server further includes:

[0356] The processing unit is configured to generate a second authentication request message based on the first authentication request message, wherein the second authentication request message includes encrypted identity information of the requesting device;

[0357] The sending unit 702 is also configured to send the second authentication request message to the first authentication server;

[0358] The receiving unit 701 is further configured to receive a second authentication response message sent by the first authentication server, wherein the second authentication response message includes the identity authentication key and the evidence storage random number;

[0359] The processing unit is further configured to generate the first authentication response message based on the second authentication response message;

[0360] The processing unit is further configured to generate a second evidence storage message based on the first evidence storage message, wherein the second evidence storage message includes the first identity authentication code;

[0361] The sending unit 702 is also used to send the second evidence storage message to the first authentication server.

[0362] Optionally, the receiving unit 701 is further configured to receive the second evidence confirmation message generated by the first authentication server; the processing unit is further configured to generate a first evidence confirmation message after the receiving unit 701 receives the second evidence confirmation message; and the sending unit 702 is further configured to send the first evidence confirmation message to the authentication access controller.

[0363] Optionally, the message sent by the second authentication server to the authentication access controller may also include a hash value calculated by the second authentication server for the latest preamble message received from the authentication access controller; the message sent by the second authentication server to the first authentication server may also include a hash value calculated by the second authentication server for the latest preamble message received from the first authentication server.

[0364] When the requesting device and the authentication access controller perform bidirectional identity authentication using a symmetric key entity authentication protocol, the requesting device's identity information is transmitted in encrypted form, thereby ensuring the security of the requesting device's true identity information during the authentication process. Furthermore, after verifying the legitimacy of the requesting device's identity, the authentication access controller sends a first evidence storage message to a first authentication server trusted by the requesting device. This first authentication server records the requesting device's network access request behavior, providing objective evidence for subsequent network access point billing and effectively preventing network access points from maliciously billing users who did not attempt to access the network within their service area.

[0365] Those skilled in the art will understand that all or part of the steps of the above method embodiments can be implemented by hardware related to program instructions. The aforementioned program can be stored in a computer-readable storage medium. When the program is executed, it performs the steps of the above method embodiments. The aforementioned storage medium can be at least one of the following media: read-only memory (ROM), RAM, magnetic disk, or optical disk, etc., and other media capable of storing program code.

[0366] It should be noted that the various embodiments in this specification are described in a progressive manner, and the same or similar parts between the various embodiments can be referred to mutually. Each embodiment focuses on describing the differences from other embodiments. In particular, for the device and system embodiments, since they are consistent with and correspond to the method embodiments, the description is relatively simple, and relevant parts can be referred to the description of the method embodiments. The device and system embodiments described above are merely illustrative, and the units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of the modules can be selected to achieve the purpose of this embodiment solution according to actual needs. Those skilled in the art can understand and implement this without creative effort.

[0367] The above description is merely one specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the technical scope disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.

Claims

1. An identity authentication method, characterized by, The method includes: The requesting device sends an authentication request message to the authentication access controller, the authentication request message including the encrypted identity information of the requesting device; the encrypted identity information of the requesting device is obtained by the requesting device encrypting encrypted data including the identity identifier of the requesting device using the public key of the encryption certificate; The authentication access controller sends a first authentication request message carrying encrypted identity information of the requesting device to a trusted second authentication server, receives a first authentication response message from the second authentication server, and obtains from the first authentication response message a stored random number generated by the trusted first authentication server and an identity authentication key generated by the first authentication server. The stored random number and the identity authentication key are generated by the first authentication server after decrypting the encrypted identity information of the requesting device and determining the legitimacy of the requesting device's identity based on the decrypted identity identifier. The identity authentication key is calculated based on computational data including a pre-shared encryption key between the first authentication server and the requesting device. The requesting device receives a first verification message sent by the authentication access controller and sends a second verification message to the authentication access controller. The first verification message includes the stored random number, and the second verification message includes a first identity authentication code and a first message integrity verification code. The first identity authentication code is calculated by the requesting device using its pre-shared storage verification key with the first authentication server, along with information including the stored random number. The first message integrity verification code is calculated by the requesting device using its message integrity verification key with the authentication access controller, along with other fields in the second verification message except for the first message integrity verification code. The message integrity verification key is calculated based on information including the identity authentication key. The authentication access controller verifies the integrity check code of the first message. If the verification is successful, it determines that the identity of the requesting device is legitimate and generates an authentication completion message and a first evidence storage message. The requesting device verifies the second message integrity check code in the authentication completion message. If the verification is successful, the identity of the authentication access controller is determined to be legitimate. The second message integrity check code is generated by the authentication access controller using the message integrity check key to calculate other fields in the authentication completion message, excluding the second message integrity check code. The first authentication server verifies the first identity authentication code in the first evidence storage message. After successful verification, it generates and stores the request pass record of the requesting device.

2. The method of claim 1, wherein, The authentication access controller first sends the first evidence storage message. After the first authentication server verifies the first identity authentication code in the first evidence storage message, it generates a first evidence storage confirmation message. After receiving the first evidence confirmation message, the authentication access controller sends the authentication completion message to the requesting device.

3. The method of claim 1, wherein, The message integrity verification key is generated through negotiation between the requesting device and the authentication access controller, and includes: The first verification message also includes a first key exchange parameter generated by the authentication access controller based on the identity authentication key; The second verification message also includes a second key exchange parameter generated by the requesting device based on the identity authentication key; The requesting device generates a first key by performing a key exchange calculation based on the temporary private key corresponding to the second key exchange parameter and the temporary public key included in the first key exchange parameter, and calculates the message integrity verification key using a key derivation algorithm based on information including the first key; the authentication access controller generates the first key by performing a key exchange calculation based on the temporary private key corresponding to the first key exchange parameter and the temporary public key included in the second key exchange parameter, and calculates the message integrity verification key using the key derivation algorithm based on information including the first key.

4. The method of claim 3, wherein, The authentication access controller uses the identity authentication key and a symmetric encryption algorithm to encrypt information, including the temporary public key generated by the authentication access controller, to generate the first key exchange parameters. The requesting device uses the identity authentication key and a symmetric encryption algorithm to encrypt information, including the temporary public key generated by the requesting device, to generate the second key exchange parameters. The requesting device calculates the message integrity verification key by performing a key exchange calculation based on the temporary private key corresponding to the second key exchange parameters and the temporary public key recovered from the first key exchange parameters to generate the first key, and then calculating the message integrity verification key using a key derivation algorithm based on information including the first key. The authentication access controller calculates the message integrity verification key by performing a key exchange calculation based on the temporary private key corresponding to the first key exchange parameter and the temporary public key recovered from the second key exchange parameter to generate the first key, and then using the key derivation algorithm to calculate the message integrity verification key based on information including the first key.

5. The method of claim 4, wherein, The authentication access controller calculates the hash value of the identity authentication key, and performs an XOR operation on the hash value and information including the temporary public key generated by the authentication access controller to generate the first key exchange parameters; The requesting device calculates the hash value of the identity authentication key, and performs an XOR operation on the hash value and information including the temporary public key generated by the requesting device to generate the second key exchange parameters.

6. The method of claim 1, wherein, The authentication request message also includes a first random number generated by the requesting device; the first authentication request message also includes the first random number and a second random number generated by the authentication access controller; The first authentication response message further includes the first random number and the second random number; the first verification message further includes the first random number and the second random number, the calculation data of the identity authentication key further includes the first random number and the second random number, and the second verification message further includes the second random number; Before the authentication access controller sends the first authentication message to the requesting device, the method further includes: The authentication access controller verifies the consistency between the second random number in the first authentication response message and the second random number generated by the authentication access controller. Before the requesting device sends the second authentication message to the authentication access controller, the method further includes: The requesting device verifies the consistency between the first random number in the first verification message and the first random number generated by the requesting device; Before the authentication access controller determines that the identity of the requesting device is legitimate, the method further includes: The authentication access controller verifies the consistency between the second random number in the second verification message and the second random number generated by the authentication access controller.

7. The method of claim 1, wherein, If the authentication request message also includes security capability parameter information supported by the requesting device, then the method further includes: If the authentication access controller determines the security policy used by the authentication access controller based on the security capability parameter information, then the first verification message also includes the security policy.

8. The method according to claim 1, characterized in that, If the authentication request message also includes the identity identifier of at least one authentication server trusted by the requesting device, then the method further includes: The authentication access controller determines the second authentication server based on the identity identifier of at least one authentication server trusted by the requesting device in the authentication request message and the identity identifier of the authentication server trusted by the authentication access controller.

9. The method according to claim 3, characterized in that, The encrypted data of the requested device's identity information ciphertext also includes the identity identifier encryption key generated by the requested device; The first authentication response message also includes the encrypted identity of the requesting device, which is obtained by the first authentication server encrypting the identity of the requesting device using the identity encryption key obtained by decrypting the encrypted identity information of the requesting device. The first verification message also includes the encrypted identity of the requesting device; Before the requesting device sends the second authentication message to the authentication access controller, the method further includes: The requesting device verifies the encrypted identity of the requesting device in the first verification message based on its own identity identifier and the identity identifier encryption key.

10. The method according to claim 1, characterized in that, Before generating the authentication completion message and the first evidence storage message, the method further includes: If the authentication access controller assigns a temporary identity identifier to the requesting device, then the authentication completion message and the first evidence storage message also include the temporary identity identifier of the requesting device; When the requesting device determines that the identity of the authentication access controller is legitimate, it also saves the temporary identity identifier of the requesting device. When the first authentication server generates and stores the request access record of the requesting device, it also saves the temporary identity identifier of the requesting device.

11. The method according to claim 1, characterized in that, The authentication access controller obtains the identity authentication key by: the authentication access controller decrypting the ciphertext of the identity authentication key using a pre-shared encryption key with the second authentication server to obtain the identity authentication key; the ciphertext of the identity authentication key is generated by the second authentication server encrypting information including the identity authentication key using a pre-shared encryption key with the authentication access controller.

12. The method according to claim 1, characterized in that, The first evidence storage message also includes a second identity authentication code, which is generated by the authentication access controller using a pre-shared verification key with the second authentication server to calculate other fields preceding the second identity authentication code in the first evidence storage message. Therefore, before the first authentication server generates and stores the request pass record of the requesting device, the method further includes: The second authentication server uses a pre-shared verification key with the authentication access controller to verify the correctness of the second identity authentication code.

13. The method according to claim 1, characterized in that, The first authentication request message also includes the identity identifier of the authentication access controller; therefore, the first authentication response message also includes the identity identifier of the authentication access controller, and before the authentication access controller sends the first verification message to the requesting device, it further includes: The authentication access controller verifies the consistency between the authentication access controller's identity identifier in the first authentication response message and the authentication access controller's own identity identifier.

14. The method according to claim 9, characterized in that, The first verification message also includes the identity identifier of the authentication access controller, and the method further includes: When the identity of the requesting device is determined to be legitimate, the authentication access controller calculates and generates a session key for subsequent secure communication based on information including the first key, the encrypted identity of the requesting device, and the identity of the authentication access controller. When the identity of the authentication access controller is determined to be legitimate, the requesting device calculates and generates a session key for subsequent secure communication based on information including the first key, the encrypted identity of the requesting device, and the identity of the authentication access controller.

15. The method according to claim 1, characterized in that, If the first authentication server and the second authentication server are different, the method further includes: The second authentication server receives the first authentication request message sent by the authentication access controller, generates a second authentication request message based on the first authentication request message, and sends the second authentication request message to the first authentication server; the second authentication request message includes encrypted identity information of the requesting device; The first authentication server generates a storage random number, generates and sends a second authentication response message to the second authentication server; the second authentication response message includes the identity authentication key and the storage random number. The second authentication server generates the first authentication response message based on the second authentication response message, the first authentication response message including the identity authentication key and the evidence storage random number; After generating the first evidence storage message, the authentication access controller sends the first evidence storage message to the second authentication server; The second authentication server generates a second evidence storage message based on the first evidence storage message and sends the second evidence storage message to the first authentication server; the second evidence storage message includes the first identity authentication code; The first authentication server then verifies the first identity authentication code, specifically by verifying the first identity authentication code in the second evidence storage message.

16. The method according to claim 15, characterized in that, The authentication access controller first sends the first evidence storage message to the second authentication server. The second authentication server generates a second evidence storage message based on the first evidence storage message and sends the second evidence storage message to the first authentication server. The first authentication server verifies the first identity authentication code in the second evidence storage message. After successful verification, it generates a second evidence storage confirmation message. After receiving the second evidence confirmation message, the second authentication server generates a first evidence confirmation message and sends the first evidence confirmation message to the authentication access controller. After receiving the first evidence confirmation message, the authentication access controller sends the authentication completion message to the requesting device.

17. The method according to any one of claims 1 to 16, characterized in that, The first message integrity check code is generated by the requesting device using the message integrity check key to calculate other fields in the second verification message besides the first message integrity check code; The second message integrity check code is generated by the authentication access controller using the message integrity check key to calculate other fields in the authentication completion message besides the second message integrity check code.

18. The method according to any one of claims 1 to 16, characterized in that, The message sent by the requesting device to the authentication access controller also includes a hash value calculated by the requesting device for the latest preceding message received from the authentication access controller; When the authentication access controller receives a message from the requesting device, it first verifies the hash value in the received message, and then performs subsequent operations after the verification is successful. The message sent by the authentication access controller to the requesting device also includes a hash value calculated by the authentication access controller for the latest preceding message sent by the requesting device. When the requesting device receives a message from the authentication access controller, it first verifies the hash value in the received message, and then performs subsequent operations after the verification is successful. The message sent by the authentication access controller to the second authentication server also includes a hash value calculated by the authentication access controller for the latest preceding message received from the second authentication server; When the second authentication server receives a message from the authentication access controller, it first verifies the hash value in the received message, and then performs subsequent operations after the verification is successful. The message sent by the second authentication server to the authentication access controller also includes a hash value calculated by the second authentication server for the latest preceding message sent by the authentication access controller. When the authentication access controller receives a message from the second authentication server, it first verifies the hash value in the received message, and then performs subsequent operations after the verification is successful. The message sent by the first authentication server to the second authentication server also includes a hash value calculated by the first authentication server for the latest preceding message received from the second authentication server; When the second authentication server receives a message from the first authentication server, it first verifies the hash value in the received message, and then performs subsequent operations after the verification is successful. The message sent by the second authentication server to the first authentication server also includes a hash value calculated by the second authentication server for the latest preceding message sent by the first authentication server. When the first authentication server receives a message from the second authentication server, it first verifies the hash value in the received message, and then performs subsequent operations after the verification is successful.

19. An authentication access controller, characterized in that, The authentication access controller includes: The receiving unit is configured to receive an authentication request message sent by the requesting device, wherein the authentication request message includes encrypted identity information of the requesting device; the encrypted identity information of the requesting device is obtained by the requesting device encrypting encrypted data, including the identity identifier of the requesting device, using the public key of the encryption certificate; The sending unit is configured to send a first authentication request message carrying encrypted identity information of the requesting device to a second authentication server trusted by the authentication access controller; The receiving unit is further configured to receive a first authentication response message sent by the second authentication server, and obtain from the first authentication response message a stored random number generated by the first authentication server trusted by the requesting device and an identity authentication key generated by the first authentication server; the identity authentication key is calculated based on computational data including a pre-shared encryption key between the first authentication server and the requesting device. The sending unit is further configured to send a first verification message to the requesting device, wherein the first verification message includes the evidence storage random number; The receiving unit is further configured to receive a second verification message sent by the requesting device, the second verification message including a first identity authentication code and a first message integrity verification code; the first message integrity verification code is generated by the requesting device using a message integrity verification key between itself and the authentication access controller to calculate other fields in the second verification message except for the first message integrity verification code; wherein, the message integrity verification key is calculated based on information including the identity authentication key; The processing unit is used to verify the integrity check code of the first message. After the verification is successful, the identity of the requesting device is determined to be legitimate, and an authentication completion message and a first evidence storage message are generated. The sending unit is further configured to send the authentication completion message to the requesting device and the first evidence storage message to the second authentication server.

20. The authentication access controller according to claim 19, characterized in that, The sending unit first sends the first evidence storage message. After the receiving unit receives the first evidence storage confirmation message, the sending unit then sends the authentication completion message to the requesting device.

21. The authentication access controller according to claim 19, characterized in that, The first verification message also includes a first key exchange parameter generated by the authentication access controller based on the identity authentication key, and the second verification message also includes a second key exchange parameter generated by the requesting device based on the identity authentication key. Then the processing unit is further configured to: perform key exchange calculation to generate a first key based on the temporary private key corresponding to the first key exchange parameter and the temporary public key included in the second key exchange parameter, and calculate the message integrity verification key using a key derivation algorithm based on information including the first key.

22. The authentication access controller according to claim 21, characterized in that, The processing unit is further configured to: use the identity authentication key to encrypt information including the temporary public key generated by the authentication access controller using a symmetric encryption algorithm to generate the first key exchange parameter; the second key exchange parameter in the second verification message received by the receiving unit is generated by the requesting device using the identity authentication key to encrypt information including the temporary public key generated by the requesting device using a symmetric encryption algorithm. The processing unit calculates the message integrity verification key by performing a key exchange calculation based on the temporary private key corresponding to the first key exchange parameter and the temporary public key recovered from the second key exchange parameter to generate the first key, and then using the key derivation algorithm to calculate the message integrity verification key based on information including the first key.

23. The authentication access controller according to claim 22, characterized in that, The processing unit is specifically used to: calculate the hash value of the identity authentication key, and perform an XOR operation on the hash value and information including the temporary public key generated by the authentication access controller to generate the first key exchange parameters.

24. The authentication access controller according to claim 19, characterized in that, The authentication request message received by the receiving unit also includes a first random number generated by the requesting device; the first authentication request message sent by the sending unit also includes the first random number and a second random number generated by the authentication access controller; The first authentication response message received by the receiving unit also includes the first random number and the second random number; the first verification message sent by the sending unit also includes the first random number and the second random number; the calculation data of the identity authentication key also includes the first random number and the second random number; and the second verification message received by the receiving unit also includes the second random number. The processing unit is further configured to: verify the consistency between the second random number in the first authentication response message and the second random number generated by the authentication access controller; and verify the consistency between the second random number in the second verification message and the second random number generated by the authentication access controller.

25. The authentication access controller according to claim 19, characterized in that, The authentication request message received by the receiving unit also includes security capability parameter information supported by the requesting device; then the processing unit is further configured to: determine the security policy used by the authentication access controller based on the security capability parameter information, and the first verification message also includes the security policy.

26. The authentication access controller according to claim 19, characterized in that, The authentication request message received by the receiving unit also includes the identity identifier of at least one authentication server trusted by the requesting device; then the processing unit is further configured to: determine the second authentication server based on the identity identifier of the at least one authentication server trusted by the requesting device and the identity identifier of the authentication server trusted by the authentication access controller in the authentication request message.

27. The authentication access controller according to claim 19, characterized in that, The processing unit is further configured to: assign a temporary identity identifier to the requesting device; then the authentication completion message and the first evidence storage message sent by the sending unit also include the temporary identity identifier of the requesting device.

28. The authentication access controller according to claim 19, characterized in that, The receiving unit obtains the identity authentication key in the following manner: it decrypts the ciphertext of the identity authentication key using a pre-shared encryption key with the second authentication server to obtain the identity authentication key; the ciphertext of the identity authentication key is generated by the second authentication server encrypting information including the identity authentication key using a pre-shared encryption key with the authentication access controller.

29. The authentication access controller according to claim 19, characterized in that, The first authentication request message sent by the sending unit also includes the identity identifier of the authentication access controller; the first authentication response message received by the receiving unit also includes the identity identifier of the authentication access controller. The processing unit is further configured to: verify the consistency between the identity identifier of the authentication access controller in the first authentication response message and the identity identifier of the authentication access controller itself.

30. The authentication access controller according to claim 21, characterized in that, The first authentication response message received by the receiving unit also includes the encrypted identity of the requesting device, and the first verification message sent by the sending unit also includes the identity of the authentication access controller; then the processing unit is further configured to: when it is determined that the identity of the requesting device is legitimate, calculate and generate a session key for subsequent secure communication based on information including the first key, the encrypted identity of the requesting device, and the identity of the authentication access controller.

31. The authentication access controller according to any one of claims 19 to 30, characterized in that, The first message integrity check code in the second verification message received by the receiving unit is generated by the requesting device using the message integrity check key to calculate other fields in the second verification message besides the first message integrity check code.

32. The authentication access controller according to any one of claims 19 to 30, characterized in that, The message sent by the authentication access controller to the requesting device also includes a hash value calculated by the authentication access controller for the latest preamble message received from the requesting device; the message sent by the authentication access controller to the second authentication server also includes a hash value calculated by the authentication access controller for the latest preamble message received from the second authentication server.

33. A requesting device, characterized in that, The requesting device includes: The sending unit is configured to send an authentication request message to the authentication access controller, wherein the authentication request message includes encrypted identity information of the requesting device; the encrypted identity information of the requesting device is obtained by the requesting device encrypting encrypted data, including the identity identifier of the requesting device, using the public key of the encryption certificate; The receiving unit is configured to receive a first verification message sent by the authentication access controller, wherein the first verification message includes a stored random number; The processing unit is configured to: calculate and generate a first identity authentication code using a pre-shared evidence verification key between the requesting device and its trusted first authentication server, including the evidence-stored random number; and calculate and generate a first message integrity verification code using a message integrity verification key between the requesting device and the authentication access controller, including fields in the second verification message other than the first message integrity verification code; wherein the message integrity verification key is calculated based on information including an identity authentication key, and the identity authentication key is calculated based on computational data including a pre-shared encryption key between the requesting device and the first authentication server. The sending unit is further configured to send the second verification message to the authentication access controller, the second verification message including the first identity authentication code and the first message integrity verification code; The receiving unit is also configured to receive an authentication completion message sent by the authentication access controller; The processing unit is further configured to verify the second message integrity check code in the authentication completion message. After successful verification, the identity of the authentication access controller is determined to be legitimate. The second message integrity check code is generated by the authentication access controller using the message integrity check key to calculate other fields in the authentication completion message, excluding the second message integrity check code.

34. The requesting device according to claim 33, characterized in that, The first verification message also includes a first key exchange parameter generated by the authentication access controller based on the identity authentication key; the second verification message also includes a second key exchange parameter generated by the requesting device based on the identity authentication key. Then the processing unit is further configured to: perform key exchange calculation to generate a first key based on the temporary private key corresponding to the second key exchange parameter and the temporary public key included in the first key exchange parameter, and calculate the message integrity verification key using a key derivation algorithm based on information including the first key.

35. The requesting device according to claim 34, characterized in that, The first key exchange parameter in the first verification message received by the receiving unit is generated by the authentication access controller using the identity authentication key and employing a symmetric encryption algorithm to encrypt information including the temporary public key generated by the authentication access controller; the processing unit is further configured to: use the identity authentication key and employ a symmetric encryption algorithm to encrypt information including the temporary public key generated by the requesting device to generate the second key exchange parameter. The processing unit calculates the message integrity verification key by performing a key exchange calculation based on the temporary private key corresponding to the second key exchange parameters and the temporary public key recovered from the first key exchange parameters to generate the first key, and then using the key derivation algorithm to calculate the message integrity verification key based on information including the first key.

36. The requesting device according to claim 35, characterized in that, The processing unit is specifically used to: calculate the hash value of the identity authentication key, and perform an XOR operation on the hash value and information including the temporary public key generated by the requesting device to generate the second key exchange parameters.

37. The requesting device according to claim 34, characterized in that, The authentication request message sent by the sending unit also includes a first random number generated by the requesting device; the first verification message received by the receiving unit also includes the first random number and a second random number generated by the authentication access controller, and the calculation data of the identity authentication key also includes the first random number and the second random number, and the second verification message sent by the sending unit also includes the second random number; then the processing unit is further configured to: verify the consistency between the first random number in the first verification message and the first random number generated by the requesting device.

38. The requesting device according to claim 34, characterized in that, The encrypted data of the requested device's identity information ciphertext also includes the identity identifier encryption key generated by the requested device; The first verification message received by the receiving unit further includes the encrypted identity of the requesting device; the encrypted identity of the requesting device is obtained by the first authentication server encrypting the identity of the requesting device using the identity encryption key obtained by decrypting the encrypted identity information of the requesting device. The processing unit is further configured to: verify the encrypted identity of the requesting device in the first verification message based on its own identity identifier and the identity identifier encryption key.

39. The requesting device according to claim 33, characterized in that, The authentication completion message received by the receiving unit also includes a temporary identity identifier assigned to the requesting device by the authentication access controller; then the processing unit is further configured to save the temporary identity identifier of the requesting device when it determines that the identity of the authentication access controller is valid.

40. The requesting device according to claim 38, characterized in that, If the first verification message received by the receiving unit also includes the identity identifier of the authentication access controller, then the processing unit is further configured to: when it is determined that the identity of the authentication access controller is legitimate, calculate and generate a session key for subsequent secure communication based on information including the first key, the encrypted identity identifier of the requesting device, and the identity identifier of the authentication access controller.

41. The requesting device according to any one of claims 33 to 40, characterized in that, The processing unit is also configured to use the message integrity verification key to calculate and generate the first message integrity verification code for other fields in the second verification message, excluding the first message integrity verification code. The second message integrity check code in the authentication completion message received by the receiving unit is calculated and generated by the authentication access controller using the message integrity check key on all fields in the authentication completion message except for the second message integrity check code.

42. The requesting device according to any one of claims 33 to 40, characterized in that, The message sent by the requesting device to the authentication access controller also includes a hash value calculated by the requesting device for the latest preceding message received from the authentication access controller.

43. A first authentication server, characterized in that, The first authentication server is an authentication server that requests device trust, and the first authentication server includes: The processing unit is used to decrypt the encrypted identity information of the requesting device using the private key corresponding to the encryption certificate to obtain the identity identifier of the requesting device, determine the legitimacy of the requesting device based on the identity identifier of the requesting device, and generate a storage random number and an identity authentication key after determining that the identity of the requesting device is legitimate. The identity authentication key is calculated based on computational data including the pre-shared encryption key between the first authentication server and the requesting device. The processing unit is further configured to verify the first identity authentication code in the first evidence storage message, and after successful verification, generate and store the request pass record of the requesting device; the first evidence storage message is generated by the authentication access controller after verifying the first message integrity check code in the second verification message sent by the requesting device, and after successful verification, the identity of the requesting device is determined to be legitimate; the second verification message includes the first identity authentication code and the first message integrity check code; the first identity authentication code is calculated by the requesting device using its pre-shared evidence storage verification key with the first authentication server, including the evidence storage random number; the first message integrity check code is calculated by the requesting device using its message integrity verification key with the authentication access controller, including other fields in the second verification message except for the first message integrity check code; wherein, the message integrity verification key is calculated based on information including the identity authentication key.

44. The first authentication server according to claim 43, characterized in that, The processing unit is further configured to generate a first evidence confirmation message after verifying the first identity authentication code in the first evidence storage message.

45. The first authentication server according to claim 43, characterized in that, The processing unit is also configured to save the temporary identity identifier assigned to the requesting device by the authentication access controller when generating and storing the request access record of the requesting device.

46. ​​The first authentication server according to claim 43, characterized in that, When the first authentication server is different from the second authentication server trusted by the authentication access controller, the first authentication server further includes: The receiving unit is configured to receive a second authentication request message sent by the second authentication server, wherein the second authentication request message includes encrypted identity information of the requesting device; The sending unit is configured to send a second authentication response message to the second authentication server, wherein the second authentication response message includes the identity authentication key and the evidence storage random number. The receiving unit is further configured to receive a second evidence storage message sent by the second authentication server, wherein the second evidence storage message includes the first identity authentication code. The processing unit is specifically used to verify the first identity authentication code in the second evidence storage message.

47. The first authentication server according to claim 46, characterized in that, The processing unit is further configured to generate a second evidence storage confirmation message after the first identity authentication code in the second evidence storage message has been verified; the sending unit is further configured to send the second evidence storage confirmation message to the second authentication server.

48. The first authentication server according to claim 46 or 47, characterized in that, The message sent by the first authentication server to the second authentication server also includes a hash value calculated by the first authentication server for the latest preceding message received from the second authentication server.

49. A second authentication server, characterized in that, The second authentication server is an authentication server trusted by the authentication access controller, and the second authentication server includes: The receiving unit is configured to receive a first authentication request message sent by the authentication access controller, which carries encrypted identity information of the requesting device. The sending unit is configured to send a first authentication response message to the authentication access controller, wherein the first authentication response message includes a stored random number generated by the first authentication server trusted by the requesting device and an identity authentication key generated by the first authentication server. The receiving unit is further configured to receive a first evidence storage message sent by the authentication access controller, the first evidence storage message including a first identity authentication code; the first evidence storage message is generated by the authentication access controller after verifying the first message integrity check code in the second verification message sent by the requesting device, and determining that the identity of the requesting device is legitimate after the verification is successful; the second verification message includes the first identity authentication code and the first message integrity check code; the first identity authentication code is calculated by the requesting device using its pre-shared evidence storage verification key with the first authentication server, including information including the evidence storage random number; the first message integrity check code is calculated by the requesting device using its message integrity verification key with the authentication access controller, including other fields in the second verification message except for the first message integrity check code; wherein, the message integrity verification key is calculated based on information including the identity authentication key.

50. The second authentication server according to claim 49, characterized in that, The first evidence storage message received by the receiving unit also includes a second identity authentication code. The second identity authentication code is generated by the authentication access controller using its pre-shared verification key with the second authentication server to calculate other fields before the second identity authentication code in the first evidence storage message. The second authentication server further includes: The verification unit is used to verify the correctness of the second identity authentication code using a pre-shared verification key with the authentication access controller.

51. The second authentication server according to claim 49, characterized in that, When the second authentication server is different from the first authentication server trusted by the requesting device, the second authentication server further includes: The processing unit is configured to generate a second authentication request message based on the first authentication request message, wherein the second authentication request message includes encrypted identity information of the requesting device; The sending unit is also used to send the second authentication request message to the first authentication server; The receiving unit is further configured to receive a second authentication response message sent by the first authentication server, wherein the second authentication response message includes the identity authentication key and the evidence storage random number; The processing unit is further configured to generate the first authentication response message based on the second authentication response message; The processing unit is further configured to generate a second evidence storage message based on the first evidence storage message, wherein the second evidence storage message includes the first identity authentication code; The sending unit is also used to send the second evidence storage message to the first authentication server.

52. The second authentication server according to claim 51, characterized in that, The receiving unit is further configured to receive a second evidence confirmation message generated by the first authentication server; the processing unit is further configured to generate a first evidence confirmation message after the receiving unit receives the second evidence confirmation message; the sending unit is further configured to send the first evidence confirmation message to the authentication access controller.

53. The second authentication server according to any one of claims 49 to 52, characterized in that, The message sent by the second authentication server to the authentication access controller also includes a hash value calculated by the second authentication server for the latest preamble message received from the authentication access controller; the message sent by the second authentication server to the first authentication server also includes a hash value calculated by the second authentication server for the latest preamble message received from the first authentication server.

Citation Information

Patent Citations

  • An access authentication method suitable for wired and wireless network

    CN1668005A

  • Handset identifier verification

    US20190289464A1