A method and apparatus for identity authentication
Patent Information
- Application Number
- CN202011569199.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2020-12-26
- Publication Date
- 2026-09-11
- Estimated Expiration
- 2040-12-26
AI Technical Summary
[0002]目前,通信网络通常要求在用户和网络接入点之间执行双向身份鉴别,确保合法用户能够与合法网络通信,在已有的实体鉴别方案中,通常不能保护用户的隐私信息,且会存在网络接入点进行恶意计费,给用户造成异常收费的问题
[0037]此外,请求设备确定鉴别接入控制器的身份合法后,还向鉴别接入控制器发送包括请求设备的数字签名的第二验证消息,请求设备的数字签名是对包括第一鉴别服务器的存证随机数在内的信息进行签名计算生成的;鉴别接入控制器根据请求设备的鉴权结果中携带的请求设备的公钥验证请求设备的数字签名以及根据所述请求设备的鉴权结果确定所述请求设备的身份合法性,在验证通过且确定所述请求设备的身份合法后为请求设备分配新临时身份标识,再生成鉴别完成消息和第一存证消息,并将鉴别完成消息发送给请求设备,将第一存证消息发送给第一鉴别服务器;相应的,请求设备使用鉴别完成消息中的新临时身份标识更新请求设备的临时身份标识,第一鉴别服务器验证第一存证消息中的请求设备的数字签名,并在验证通过后生成并保存请求设备的请求通过记录,证明请求设备在特定时间有请求访问网络的行为,为后续收费提供证据避免恶意收费。如此实现请求设备和鉴别接入控制器的双向身份鉴别;并且实体采用临时身份标识作为身份凭证,其真实身份不会被泄露,保障了用户隐私。
Smart Images

Figure CN114760032B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of network communication security technology, and in particular to an identity authentication method and apparatus. Background Technology
[0002] Currently, communication networks typically require two-way authentication between users and network access points to ensure that legitimate users can communicate with legitimate networks. Existing entity authentication schemes often fail to protect users' privacy information and may result in network access points engaging in malicious billing, causing users to be charged abnormally. Summary of the Invention
[0003] To address the aforementioned technical issues, this application provides an identity authentication method and apparatus that enables bidirectional identity authentication between the requesting device and the authentication access controller, protects user privacy information, and provides a basis for subsequent charging, access tracing, or prevention of malicious billing.
[0004] In view of the above, the first aspect of this application provides an identity authentication method, comprising:
[0005] The requesting device sends an authentication request message to the authentication access controller, the authentication request message including the temporary identity identifier of the requesting device;
[0006] The authentication access controller sends a first authentication request message to a second authentication server it trusts. The first authentication request message includes the temporary identity of the requesting device and the public key of the authentication access controller. The controller also receives a first authentication response message from the second authentication server. The first authentication response message includes the authentication result of the authentication access controller, the first digital signature of the first authentication server trusted by the requesting device, the authentication result of the requesting device, the evidence-stored random number generated by the first authentication server, and the second digital signature of the second authentication server.
[0007] The authentication access controller verifies the second digital signature of the second authentication server. After successful verification, it sends a first verification message to the requesting device. The first verification message includes the authentication result of the authentication access controller, the first digital signature of the first authentication server, the evidence storage random number generated by the first authentication server, and the first digital signature of the authentication access controller.
[0008] The requesting device verifies the first digital signature of the first authentication server and verifies the first digital signature of the authentication access controller based on the public key of the authentication access controller carried in the authentication result of the authentication access controller. After successful verification, the device obtains the authentication legitimacy result of the authentication access controller based on the authentication result of the authentication access controller. After determining that the authentication access controller is legitimate, the device sends a second verification message to the authentication access controller. The second verification message includes the digital signature of the requesting device. The digital signature of the requesting device is generated by signing information including the stored random number of the first authentication server.
[0009] The authentication access controller uses the public key of the requesting device carried in the authentication result of the requesting device to verify the digital signature of the requesting device and obtains the authentication result of the legality of the requesting device's identity based on the authentication result of the requesting device. After the verification is successful and the legality of the requesting device is determined, a new temporary identity identifier of the requesting device is generated, and then an authentication completion message and a first evidence storage message are generated; wherein, the authentication completion message includes the new temporary identity identifier of the requesting device; the first evidence storage message includes the new temporary identity identifier of the requesting device and the digital signature of the requesting device;
[0010] The requesting device replaces its temporary identity with the new temporary identity of the requesting device in the authentication completion message;
[0011] The first authentication server uses the public key of the requesting device to verify the digital signature of the requesting device in the first evidence storage message. After the verification is successful, it generates and saves the request approval record of the requesting device, and replaces the temporary identity of the requesting device with the new temporary identity of the requesting device in the first evidence storage message.
[0012] A second aspect of this application provides a requesting device, comprising:
[0013] The sending module is used to send an authentication request message to the authentication access controller, wherein the authentication request message includes a temporary identity identifier of the requesting device;
[0014] The receiving module is configured to receive a first verification message sent by the authentication access controller, wherein the first verification message includes the authentication result of the authentication access controller, the first digital signature of the first authentication server, the evidence storage random number generated by the first authentication server, and the first digital signature of the authentication access controller.
[0015] The verification module is used to verify the first digital signature of the first authentication server and the first digital signature of the authentication access controller carried in the authentication result of the authentication access controller. After the verification is successful, the authentication access controller's identity legitimacy authentication result is obtained based on the authentication result of the authentication access controller.
[0016] The sending module is further configured to send a second verification message to the authentication access controller after determining that the identity of the authentication access controller is legitimate. The second verification message includes the digital signature of the requesting device. The digital signature of the requesting device is generated by signing information including the stored random number of the first authentication server.
[0017] The receiving module is further configured to receive an authentication completion message sent by the authentication access controller. The authentication completion message includes a new temporary identity identifier for the requesting device. The new temporary identity identifier is generated by the authentication access controller after the digital signature of the requesting device is verified by the authentication access controller based on the public key of the requesting device carried in the authentication result of the requesting device.
[0018] An update module is used to replace the temporary identity of the requesting device with the new temporary identity of the requesting device in the authentication completion message.
[0019] A third aspect of this application provides an authentication access controller, comprising:
[0020] The receiving module is used to receive an authentication request message sent by the requesting device, wherein the authentication request message includes a temporary identity identifier of the requesting device;
[0021] The sending module is configured to send a first authentication request message to a second authentication server trusted by the authentication access controller. The first authentication request message includes a temporary identity identifier of the requesting device and the public key of the authentication access controller.
[0022] The receiving module is further configured to receive a first authentication response message sent by the second authentication server. The first authentication response message includes the authentication result of the authentication access controller, the first digital signature of the first authentication server trusted by the requesting device, the authentication result of the requesting device, the evidence storage random number generated by the first authentication server, and the second digital signature of the second authentication server.
[0023] The verification module is used to verify the second digital signature of the second authentication server;
[0024] The sending module is further configured to send a first verification message to the requesting device after the second digital signature of the second authentication server has been verified. The first verification message includes the authentication result of the authentication access controller, the first digital signature of the first authentication server, the evidence storage random number generated by the first authentication server, and the first digital signature of the authentication access controller.
[0025] The receiving module is further configured to receive a second verification message sent by the requesting device, the second verification message including the digital signature of the requesting device; the digital signature of the requesting device is generated by signing information including the stored random number of the first authentication server;
[0026] The verification module is further configured to verify the digital signature of the requesting device based on the public key of the requesting device carried in the authentication result of the requesting device;
[0027] The generation module is configured to obtain the identity legitimacy authentication result of the requesting device based on the authentication result of the requesting device, generate a new temporary identity identifier for the requesting device after the digital signature of the requesting device passes the verification and the identity of the requesting device is determined to be legitimate, and then generate an authentication completion message and a first evidence storage message; wherein, the authentication completion message includes the new temporary identity identifier of the requesting device; the first evidence storage message includes the new temporary identity identifier of the requesting device and the digital signature of the requesting device;
[0028] The sending module is further configured to send the first evidence storage message to the first authentication server trusted by the requesting device through the second authentication server, and to send the authentication completion message to the requesting device.
[0029] A fourth aspect of this application provides a second authentication server, comprising:
[0030] The receiving module is configured to receive a first authentication request message sent by the authentication access controller, wherein the first authentication request message includes a temporary identity identifier of the requesting device and the public key of the authentication access controller;
[0031] The sending module is used to send a first authentication response message to the authentication access controller. The first authentication response message includes the authentication result of the authentication access controller, the first digital signature of the first authentication server trusted by the requesting device, the authentication result of the requesting device, the evidence storage random number generated by the first authentication server, and the second digital signature of the second authentication server.
[0032] The receiving module is further configured to receive a first evidence storage message generated by the authentication access controller, the first evidence storage message including a new temporary identity identifier of the requesting device and a digital signature of the requesting device; the digital signature of the requesting device is generated by the requesting device signing information including the evidence storage random number of the first authentication server.
[0033] The fifth aspect of this application provides a first authentication server, comprising:
[0034] The verification module is used to verify the digital signature of the requesting device in the first evidence storage message using the public key of the requesting device. The first evidence storage message includes a new temporary identity of the requesting device and the digital signature of the requesting device. The digital signature of the requesting device is generated by the requesting device by signing information including the evidence storage random number of the first authentication server.
[0035] The replacement module is used to generate and save the request pass record of the requesting device after the digital signature verification of the requesting device is passed, and replace the temporary identity of the requesting device with the new temporary identity of the requesting device in the first evidence storage message.
[0036] As can be seen from the above technical solution, the requesting device uses a temporary identity as its identity credential, and the authentication access controller uses a public key as its identity credential. During the authentication process, the requesting device sends an authentication request message including its temporary identity to the authentication access controller. Then, the authentication access controller sends a first authentication request message to its trusted second authentication server. This first authentication request message includes the requesting device's temporary identity and the authentication access controller's public key. Thus, the second authentication server can check the validity of the authentication access controller's public key, thereby generating the authentication result of the authentication access controller and generating a second digital signature for the second authentication server. The first authentication server, trusted by the requesting device, can find the requesting device's public key based on its temporary identity and check its validity, thereby generating the authentication result of the requesting device and generating a first digital signature for the first authentication server. Furthermore, the first authentication... The second authentication server also generates a storage random number to provide evidence for subsequent charging. The second authentication server generates a first authentication response message based on the authentication result of the authentication access controller, the first digital signature of the first authentication server, the authentication result of the requesting device, the storage random number, and the second digital signature of the second authentication server, and returns the first authentication response message to the authentication access controller. The authentication access controller verifies the second digital signature of the second authentication server. If the verification is successful, it sends a first verification message to the requesting device. The first verification message includes the authentication result of the authentication access controller, the first digital signature of the first authentication server, the storage random number generated by the first authentication server, and the first digital signature of the authentication access controller. After the first digital signature of the first authentication server and the first digital signature of the authentication access controller are verified, the requesting device determines the legitimacy of the authentication access controller's identity based on the authentication result of the authentication access controller.
[0037] Furthermore, after verifying the legitimacy of the authentication access controller, the requesting device sends a second verification message to the authentication access controller, including the requesting device's digital signature. The digital signature of the requesting device is generated by signing and calculating information including the stored random number from the first authentication server. The authentication access controller verifies the requesting device's digital signature based on the public key carried in the authentication result of the requesting device, and determines the legitimacy of the requesting device's identity based on the authentication result. After successful verification and confirmation of the requesting device's legitimacy, a new temporary identity identifier is assigned to the requesting device. An authentication completion message and a first storage message are then generated, and the authentication completion message is sent to the requesting device, while the first storage message is sent to the first authentication server. Correspondingly, the requesting device updates its temporary identity identifier using the new temporary identity identifier in the authentication completion message. The first authentication server verifies the requesting device's digital signature in the first storage message, and after successful verification, generates and saves the requesting device's request approval record, proving that the requesting device requested network access at a specific time, providing evidence for subsequent charging and preventing malicious charging. This achieves two-way identity authentication between the requesting device and the authentication access controller; and since the entity uses a temporary identity identifier as identity credential, its true identity will not be disclosed, protecting user privacy. Attached Figure Description
[0038] To more clearly illustrate the technical solutions in the embodiments of this application or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0039] Figure 1 A schematic diagram illustrating an identity authentication method provided in an embodiment of this application;
[0040] Figure 2 A schematic diagram illustrating a method for requesting a device REQ and authenticating an access controller AAC negotiation message integrity verification key, provided as an embodiment of this application;
[0041] Figure 3 This is a schematic diagram of an identity authentication method provided in an embodiment of this application, where "*" represents an optional field or optional operation;
[0042] Figure 4 This is a schematic diagram of an identity authentication method provided in an embodiment of this application, where "*" represents an optional field or optional operation;
[0043] Figure 5 A structural block diagram of a request device REQ provided in an embodiment of this application;
[0044] Figure 6 A structural block diagram of an authentication access controller (AAC) provided in this application embodiment;
[0045] Figure 7 A structural block diagram of a second authentication server AS-AAC provided in this application embodiment;
[0046] Figure 8 This is a structural block diagram of a first authentication server AS-REQ provided in an embodiment of this application. Detailed Implementation
[0047] In a communication network, a requesting device can access the network through an authentication access controller. To ensure that the requesting device is a legitimate user and that the network accessed by the requesting device is a legitimate network, mutual identity authentication (MIA) is usually required between the authentication access controller and the requesting device.
[0048] Taking current wireless and mobile communication scenarios as examples, in scenarios where a requesting device accesses a wireless network through an authentication access controller, the requesting device can be a terminal device such as a mobile phone, a personal digital assistant (PDA), or a tablet computer, while the authentication access controller can be a network-side device such as a wireless access point or a wireless router. In scenarios where a requesting device accesses a wired network through an authentication access controller, the requesting device can be a terminal device such as a desktop computer or a laptop computer, while the authentication access controller can be a network-side device such as a switch or a router. In scenarios where a requesting device accesses a 4G / 5G network through an authentication access controller, the requesting device can be a terminal device such as a mobile phone or a tablet computer, while the authentication access controller can be a network-side device such as a base station. Of course, this application is also applicable to various data communication scenarios, including other wired networks and short-range communication networks.
[0049] However, existing entity authentication schemes typically fail to protect user privacy and can lead to malicious billing by network access points, resulting in abnormal charges for users. To address these issues, this application provides an identity authentication method. In this method, an authentication access controller assigns a temporary identity identifier to a requesting device as its identity credential. The authentication access controller itself uses a public key as its identity credential. When the requesting device accesses the network, it sends an authentication request message to the authentication access controller. The authentication access controller then sends a first authentication request message to a trusted second authentication server. This first authentication request message includes the requesting device's temporary identity identifier and the authentication access controller's public key. The trusted first authentication server generates an authentication result for the requesting device based on its temporary identity identifier. The trusted second authentication server verifies the authentication access controller's public key to generate its own authentication result. The second authentication server then sends a first authentication response message to the authentication access controller, carrying the authentication results of both the requesting device and the authentication access controller, along with relevant signatures. Both the requesting device and the authentication access controller obtain each other's authentication results, achieving bidirectional identity authentication. Because the requesting device uses a temporary identity identifier for authentication, the transmission of its real identity information is avoided, ensuring the security of its real identity information. In addition, after verifying the legitimacy of the authentication access controller, the requesting device sends a second verification message to the authentication access controller so that the authentication access controller can assign a new temporary identity to the requesting device and send a storage message to the first authentication server to store the requesting device's network access behavior, providing evidence for subsequent billing and preventing malicious billing.
[0050] For ease of explanation, this application embodiment will use a requesting device (REQuester, REQ), an authentication access controller (AAC), and an authentication server (AS) as examples to describe an identity authentication method.
[0051] In this system, the AS trusted by AAC is called the second authentication server AS-AAC, and the AS trusted by REQ is called the first authentication server AS-REQ. AS-AAC and AS-REQ each hold a digital certificate and its corresponding private key conforming to ISO / IEC 9594-8 / ITU X.509, other standards, or other technical systems. AS-REQ is aware of REQ's ID or TID and its corresponding REQ public key PUB. REQAdditionally, the system may also contain a Certificate Server-Decrypt (CS-DEC). The CS-DEC holds encryption certificates and corresponding private keys that conform to ISO / IEC 9594-8 / ITU X.509, other standards, or other technical systems. The CS-DEC can be a standalone server or reside within the AS-REQ.
[0052] AS-AAC and AS-REQ can be the same AS or different ASs. When AS-AAC and AS-REQ are the same, it is a non-roaming situation. When AS-AAC and AS-REQ are different, it is a roaming situation. In this case, AS-AAC and AS-REQ know each other's signing certificate or the public key in the signing certificate.
[0053] REQ and AAC are endpoints involved in the identity authentication process. REQ establishes a connection with AAC, accesses the services provided by AAC, and accesses AS through AAC; AAC establishes a connection with REQ, provides services, communicates with REQ, and can directly access AS-AAC. Both REQ and AAC have an ID that identifies their identities, and REQ also has a temporary identity identifier (TID). REQ and AAC each hold a pair of public and private keys (where REQ's public key and AAC's public key are denoted as PUB). REQ and PUB AAC The REQ and AAC know the digital certificates of the authentication servers they trust, or the public keys corresponding to those certificates. The REQ also knows the AS-REQ signing certificate or the public key within it. In some applications, the REQ also knows the CS-DEC encryption certificate or the public key within it. AS-AAC can then determine the appropriate encryption key based on the PUB. AAC By verifying the legitimacy of the AAC's identity, AS-REQ can locate the corresponding PUB based on the REQ's ID or TID. REQ And according to PUB REQ Verify the legitimacy of REQ's identity.
[0054] The following is combined with Figure 1 This application provides an embodiment of an identity authentication method, which includes:
[0055] S101, REQ sends an authentication request message ATTACH to AAC.
[0056] The ATTACH includes the REQ's temporary identity identifier (TID). REQ Among them, TID REQ TID is assigned by AAC for REQ, and in practical applications... REQIt is unique, meaning that when multiple REQs request access to the network, the AAC assigns a different TID to each REQ. REQ This is to distinguish REQs.
[0057] On the one hand, temporary identity identifiers can be used for identity verification, preventing the leakage of real identity information; on the other hand, TID... REQ It has an expiration date, which allows for lifecycle management.
[0058] S102, AAC sends the first authentication request message AACVeri to the AS-AAC it trusts.
[0059] The AACVeri includes the AAC public key PUB. AAC and the TID REQ .
[0060] S103, AAC receives the first authentication response message ASVeri sent by AS-AAC.
[0061] The ASVeri includes the authentication result Res from AAC. AAC The first digital signature of AS-REQ trusted by REQ, Sig AS_REQ1 The authentication result Res of REQ REQ Nonce generated by AS-REQ for evidence storage AS_REQ And AS-AAC's second digital signature Sig AS_AAC2 .
[0062] It should be noted that when AS-AAC and AS-REQ are the same authentication server, the authentication server commonly trusted by both REQ and AAC can be represented by AS-AAC (or AS-REQ). In this case, AS-AAC (which can also be represented as AS-REQ) is responsible for the authentication of the TID. REQ and the PUB AAC Perform verification. For example, determine the TID using AS-AAC (which can also be represented as AS-REQ). REQ Is it valid? If valid, then find the TID. REQ The corresponding REQ public key PUB REQ And check PUB REQ The legality, according to including PUB REQ Res is generated, including information such as the results of its inspection. REQ And generate a nonce for evidence storage. AS_AAC (can also be represented as Nonce) AS_REQ This is to provide evidence for billing and to inspect the PUB. AAC The legality, according to including PUB AACRes is generated, including information such as the results of its inspection. AAC and for Res AAC The signature calculation is performed on the information including the Sig to generate the Sig. AS_REQ1 It indicates that, including Res REQ and Nonce AS_REQ The signature calculation is performed on the information including the Sig to generate the Sig. AS_AAC2 According to Res AAC Sig AS_REQ1 Res REQ Nonce AS_REQ and Sig AS_AAC2 The information generated by ASVeri includes...
[0063] When the AS-AAC trusted by AAC and the AS-REQ trusted by REQ are different authentication servers, in this case, the PUB is verified by AS-AAC. AAC Specifically, to inspect PUB AAC The legality, according to including PUB AAC Res is generated, including information such as the results of its inspection. AAC Then according to Res AAC TID in AACVeri REQ The information included in the message generates a second authentication request message AS-AACVeri, which is then sent to AS-REQ.
[0064] AS-REQ based on TID REQ Find the corresponding PUB REQ And check PUB REQ The legality, according to including PUB REQ Res is generated, including information such as the results of its inspection. REQ And generate a nonce for evidence storage. AS_REQ This is to provide evidence for billing. Next, AS-REQ will include Res... AAC The signature calculation is performed on the information including the Sig to generate the Sig. AS_REQ1 For Res REQ and Nonce AS_REQ The information, including the signature calculation, generates the second digital signature Sig of the AS-REQ. AS_REQ2 According to Res AAC Sig AS_REQ1 Res REQ Nonce AS_REQ and Sig AS_REQ2 The information included in the message generates a second authentication response message AS-REQVeri, which is then sent to AS-AAC.
[0065] AS-AAC verification of the Sig AS_REQ2 After verification, for Res REQ and Nonce AS_REQ The signature calculation is performed on the information including the Sig to generate the Sig. AS_AAC2 According to Res AAC Sig AS_REQ1 Res REQ Nonce AS_REQ and Sig AS_AAC2 The information generated by ASVeri includes...
[0066] It should be noted that, considering the time-limited nature of temporary identity identifiers, AS-REQ generates a Nonce. AS-REQ Previously, it was also possible to determine the TID. REQ Does it meet the timeliness requirement? If so, then AS-REQ will generate a new nonce for evidence storage. AS_REQ This prevents criminals from exploiting expired TIDs. REQ It impersonates the current user to initiate a request to access the network.
[0067] S104, AAC verification of the Sig AS_AAC2 .
[0068] Specifically, AAC knows the public key of AS-AAC, and uses the public key of AS-AAC to access Sig. AS_AAC2 Perform verification; if the verification passes, it indicates that Res in ASVeri... REQ and Nonce AS_REQ It has not been tampered with, and you can continue with the subsequent operations.
[0069] S105, AAC sends the first authentication message AACAuth to REQ.
[0070] The AACAuth includes the Res AAC The Sig AS_REQ1 The Nonce AS_REQ And AAC's first digital signature Sig AAC1 .
[0071] S106, REQ verifies the Sig AS_REQ1 And according to the Res AAC PUB carried in AAC Verify the Sig AAC1 After verification, according to the Res AAC Obtain the identity verification result from AAC.
[0072] Specifically, REQ knows the public key of AS-REQ, and uses the public key of AS-REQ to access the Sig. AS_REQ1 Perform verification; and, REQ based on Res AAC PUB carried in AAC Verify Sig AAC1 If the Sig AAC1 and the Sig AS_REQ1 If all verifications pass, then REQ can be based on Res AAC Verify the legitimacy of AAC's identity to perform identity authentication. If at least one verification fails, stop proceeding to the next step. If AAC's identity is determined to be legitimate, proceed to step S107.
[0073] S107, REQ sends the second verification message REQAuth to AAC.
[0074] The REQAuth includes the digital signature Sig of REQ. REQ Sig REQ The REQ includes the Nonce. AS_REQ The signature is generated by performing signature calculations on the information included.
[0075] Optionally, REQAuth may also include the first message integrity check code MacTag generated by REQ. REQ Before executing S108, AAC also needs to verify the MacTag. REQ After successful verification, proceed with subsequent operations. (MacTag) REQ REQ utilizes its message integrity verification key pair with AAC, including the one in REQAuth excluding MacTag. REQ Other fields besides the one used are calculated and generated. Then AAC verifies the MacTag. REQ When using this method, the message integrity verification key pair between the REQ and REQ should be utilized, including the REQAuth key except for the MacTag. REQ Other fields are used to calculate and generate MacTag. REQ and calculate MacTag REQ MacTag in REQAuth REQ The comparison is performed; if they match, the verification passes; otherwise, the verification fails.
[0076] S108, AAC according to the Res REQ The public key PUB of REQ carried in REQ Verify the Sig REQ And according to the Res REQOnce the identity verification result of REQ is obtained and the identity of REQ is confirmed to be legitimate, a new temporary identity identifier (TID) is generated for REQ. REQnew Then, the authentication completion message AACFinish and the first evidence storage message AACUpdate are generated.
[0077] S109. AAC sends an authentication completion message AACFinish to REQ.
[0078] The AACFinish includes the TID. REQnew .
[0079] S110, REQ uses the TID in AACFinish. REQnew Replace the TID REQ .
[0080] Optionally, the AACFinish of S109 may also include a second message integrity checksum MacTag generated by AAC. AAC MacTag AAC AAC uses its message integrity verification key pair with REQ, including the MacTag in AACFinish. AAC Other fields besides the one used for calculation are also included. Accordingly, REQ must verify the MacTag before executing S110. AAC After successful verification, proceed with subsequent operations. REQ verifies the MacTag. AAC When using this method, the message integrity verification key pair between the device and AAC should be utilized, including the key pair in AACFinish excluding the MacTag. AAC Other fields are used to calculate and generate MacTag. AAC and calculate MacTag AAC MacTag in AACFinish AAC The comparison is performed; if they match, the verification passes; otherwise, the verification fails.
[0081] If MacTag AAC If the verification passes, it indicates that the interaction between REQ and AAC is complete, AACFinish is trustworthy, and REQ can use the TIDs in AACFinish. REQnew Replace TID REQ This allows for the updating of temporary identity identifiers. If MacTag... AAC If the verification fails, it indicates that the interaction between REQ and AAC is incomplete, AACFinish is untrusted, and REQ should immediately discard AACFinish.
[0082] S111, AAC sends the first evidence storage message AACUpdate to AS-AAC.
[0083] The AACUpdate includes the TID. REQnew and the Sig REQ .
[0084] Optionally, the AACUpdate also includes a second digital signature Sig of the AAC. AAC2 The Sig AAC2 It is AAC to AACUpdate in Sig AAC2 The signature is generated by performing signature calculations on other prior information. Thus, AS-AAC can be generated by performing signature calculations on the aforementioned Sig. AAC2 Verification is performed to determine whether AACUpdate has been tampered with during transmission.
[0085] S112, AS-REQ uses PUB REQ For Sig in the AACUpdate REQ Upon successful verification, a request pass record for REQ is generated and saved, using the TID from AACUpdate. REQnew Replace TID REQ .
[0086] When AS-AAC and AS-REQ are the same authentication server, AAC directly sends AACUpdate to AS-AAC (which can also be represented as AS-REQ), and AS-AAC (which can also be represented as AS-REQ) uses PUB... REQ Sig in AACUpdate REQ Verification is performed. If the verification passes, it indicates that the REQ initiated a network access request and successfully accessed the network during that time period. Based on this, AS-AAC (also represented as AS-REQ) generates a request pass record for the REQ and saves the request pass record locally or remotely, providing evidence for subsequent billing. In addition, AS-AAC (also represented as AS-REQ) also uses the TID in AACUpdate. REQnew Replace TID REQ To achieve TID REQ Update.
[0087] When AS-AAC and AS-REQ are different authentication servers, AAC sends AACUpdate to AS-AAC, and AS-AAC returns the TID. REQnew and the Sig REQ The information included in the calculation generates the third digital signature Sig of AS-AAC. AS_AAC3 Then, based on including TID REQnew SigREQ and Sig AS_AAC3 The information included generates a second evidence message, ASUpdate. AS-AAC sends ASUpdate to AS-REQ, and AS-REQ verifies the Sig based on AS-AAC's public key. AS_AAC3 If the verification passes, then proceed with the subsequent related steps, including verifying Sig. REQ And after successful verification, it generates and saves the REQ request pass record, as well as the execution TID. REQnew Replace TID REQ The steps.
[0088] In practical applications, the execution order of S109 and S111 is not limited. S109 can be executed first and then S111, or S111 can be executed first and then S109, or S109 and S111 can be executed simultaneously.
[0089] Optionally, AAC can first execute S111, i.e., send the first evidence storage message AACUpdate, and in S112, modify the Sig in the AACUpdate message. REQ After successful verification, a first evidence confirmation message is generated. Upon receiving the first evidence confirmation message, AAC executes S109, which sends the authentication completion message AACFinish to REQ.
[0090] As can be seen from the above, the identity authentication method provided in this application adopts TID. REQ As the identity credential for REQ, it adopts PUB AAC As an identity credential of AAC, REQ sends an authentication request message to AS-AAC when accessing the network, requesting two-way identity authentication. AS-AAC then verifies the PUB. AAC The legality of generating Res AAC AS-REQ verification TID REQ Generate Res REQ Then AS-AAC returns ASVeri to AAC, and AAC retrieves Res from ASVeri. REQ This verifies the legitimacy of REQ's identity. Once REQ's identity is confirmed, AAC sends REQ a message carrying Res. AAC AACAuth, REQ based on Res AAC By verifying the legitimacy of the AAC's identity, both two-way identity authentication between the REQ and the AAC is achieved, while also protecting the privacy of the entity's information.
[0091] Please refer to Figure 1 The Res in S103's ASVeri REQ This can indicate that the identity verification result of REQ is valid, invalid, or empty (i.e., Res).REQ The value is null, therefore the AACAuth of S105 also includes the AAC-generated indicator flag. AAC Flag AAC Used to indicate whether REQ needs to send its real identity ID. REQ For example, if the Res in ASVeri REQ This indicates that the REQ's identity verification result is empty (i.e., Res). REQ If the value is Null, then Flag AAC The flag can be 1, indicating that REQ needs to send its real ID. REQ In order to re-verify the identity of REQ; if the Res in ASVeri REQ The Flag indicates whether the REQ's identity verification result is valid or invalid. AAC The flag can be 0, indicating that REQ does not need to send its real ID. REQ When REQ needs to send its real ID. REQ In order to protect the privacy and security of REQ, REQ can use the public key of the encryption certificate to include the ID. REQ The information, including the REQ, is encrypted to generate the ciphertext EncPub, which is the identity identifier. AS Therefore, when REQ sends REQAuth to AAC, it can also carry EncPub. AS .
[0092] Accordingly, AAC also sends a third authentication request message AACReVeri to AS-AAC, wherein AACReVeri includes the EncPub. AS If AS-AAC and AS-REQ are the same authentication server, then AS-AAC (which can also be represented as AS-REQ) can decrypt EncPub using the private key of the encryption certificate. AS Get ID REQ According to ID REQ Search PUB REQ Check PUB REQ The legality of generating Res REQ And according to Res REQ A third authentication response message ASReVeri is generated. The AAC receives the ASReVeri and, based on the Res in the ASReVeri... REQ The legitimacy of REQ's identity needs to be reassessed.
[0093] If AS-AAC and AS-REQ are different authentication servers, then after AS-AAC receives the AACReVeri, it must also send the EncPub to AS-REQ. ASIf the fourth authentication request message AS-AACReVeri is received, then AS-REQ can decrypt EncPub using the private key of the encryption certificate. AS Get ID REQ According to ID REQ Search PUB REQ Check PUB REQ The legality of generating Res REQ And according to Res REQ A fourth authentication response message, AS-REQReVeri, is generated. After receiving AS-REQReVeri, AS-AAC determines the authentication response based on the Res value in AS-REQReVeri. REQ Generate a third authentication response message ASReVeri; AAC receives the ASReVeri and, based on the Res in the ASReVeri... REQ The legitimacy of REQ's identity needs to be reassessed.
[0094] In the above embodiments, the message integrity verification key used by REQ and AAC can be pre-shared between REQ and AAC, or it can be negotiated between the two. Therefore, this embodiment also provides a method for REQ and AAC to negotiate the message integrity verification key, see [link to documentation]. Figure 2 The method includes:
[0095] S201, REQ sends an authentication request message ATTACH to AAC.
[0096] ATTACH also includes the first key exchange parameter KeyInfo generated by REQ. REQ The KeyInfo REQ This includes the temporary public key for REQ, where key exchange refers to key exchange algorithms such as Diffie-Hellman (DH). The ATTACH may also include security capabilities. REQ Security capabilities REQ This indicates the security capability parameters supported by REQ, including the authentication suites supported by REQ (which contain one or more authentication methods), key exchange algorithms, and / or key derivation algorithms, so that AAC can select the specific security policy to use.
[0097] S202, AAC exchanges the second key parameter KeyInfo generated by AAC. AAC The corresponding temporary private key and the KeyInfo REQThe temporary public key is used to perform key exchange calculations to generate a first key. Based on the calculation data including the first key, a key derivation algorithm is used to calculate the message integrity verification key.
[0098] If the ATTACH in S201 also includes the first random number Nonce generated by REQ. REQ Then AAC can be based on KeyInfo. AAC The corresponding temporary private key and KeyInfo REQ The first key is generated by key exchange calculation using the temporary public key, and then combined with the Nonce. REQ The second random number Nonce generated by AAC AAC The computational data, including the data itself, is used to calculate the message integrity verification key using a negotiated or pre-defined key derivation algorithm. In this application, the computational object used in the algorithm operation is referred to as the computational data. The negotiated key derivation algorithm can be the Securitycapabilities sent by AAC based on the REQ. REQ The chosen key derivation algorithm. KeyInfo AAC This refers to the key exchange parameters generated by AAC, including the AAC's temporary public key. KeyInfo AAC The corresponding temporary private key is the temporary private key generated by AAC that corresponds to the temporary public key of AAC. That is, the temporary public key and the temporary private key are a pair of temporary public-private keys.
[0099] S203, AAC sends the first authentication message AACAuth to REQ.
[0100] AACAuth also includes KeyInfo generated by AAC. AAC .
[0101] When ATTACH in S201 also includes Nonce REQ In this case, the AACAuth may also include a second random number (Nonce) generated by AAC. AAC .
[0102] S204, REQ based on the KeyInfo REQ The corresponding temporary private key and the KeyInfo AAC The first key is generated by key exchange calculation using the temporary public key, and the message integrity verification key is calculated using the key derivation algorithm based on the calculation data including the first key.
[0103] If AACAuth includes Nonce AAC Then REQ is based on KeyInfo REQThe corresponding temporary private key and KeyInfo AAC The first key is generated by key exchange calculation using the temporary public key, and then the first key is combined with the Nonce. REQ and Nonce AAC The computational data, including the data itself, is used to calculate the message integrity verification key using a negotiated or pre-defined key derivation algorithm. The negotiated key derivation algorithm can be REQ based on the security capabilities sent by AAC. AAC The chosen key derivation algorithm. KeyInfo REQ The corresponding temporary private key is the temporary private key generated by REQ that corresponds to the temporary public key of REQ, that is, the temporary public key and the temporary private key are a pair of temporary public-private keys.
[0104] In practical applications, to achieve secure communication, REQ and AAC can also negotiate a session key for encrypting session content. Specifically, AACAuth can also include the AAC's identity ID. AAC AAC combines the first key with the TID REQ and ID AAC The session key (including the data encryption key and / or data integrity verification key) is calculated from the computational data, including the TID; correspondingly, REQ combines the first key with the TID. REQ and the ID AAC The session key (including the data encryption key and / or data integrity verification key) is calculated from the computational data.
[0105] When AAC calculates the session key using the above method, it can combine the first key with the TID. REQ and the ID AAC The computational data, including the TID, is used to calculate a key data string. This key data can be used as a data encryption key and / or a data integrity verification key. Alternatively, a portion of the key data can be used as a data encryption key, and another portion as a data integrity verification key. When REQ calculates the session key using the above method, it can combine the first key with the TID. REQ and the ID AAC The computational data includes a string of key data, which can be used as a data encryption key and / or a data integrity verification key. Alternatively, a portion of the key data can be used as a data encryption key and another portion as a data integrity verification key.
[0106] It should be noted that the random numbers and identity identifiers generated by REQ and / or AAC can be transmitted in the messages exchanged during the identity authentication process. Normally, the random numbers and / or identity identifiers carried in the received message should be the same as those carried in the sent message. However, in situations such as network jitter or attacks, the parameter information in the messages may be lost or tampered with. Therefore, in some embodiments of this application, the reliability of the authentication result can also be ensured by comparing whether the random numbers and / or identity identifiers in the sent and received messages are consistent.
[0107] In some embodiments, when the ATTACH of S101 also includes a Nonce REQ At that time, S102's AACeri also included Nonce REQ and Nonce AAC Correspondingly, S103's ASVeri also includes Nonce. REQ and Nonce AAC S105's AACAuth also includes a Nonce. REQ and Nonce AAC S107's REQAuth also includes a Nonce. AAC Thus, before AAC sends AACAuth to REQ, AAC can first verify the Nonce in ASVeri. AAC Nonce generated by AAC AAC (That is, the Nonce sent by AAC through AACCVeri) AAC The consistency of the REQ is ensured; similarly, before sending REQAuth to AAC, REQ can also verify the Nonce in AACAuth. REQ Nonce generated by REQ REQ (That is, the nonce sent by REQ via ATTACH) REQ Consistency of ); further, in S108, AAC generates TID REQnew Previously, AAC could also handle the Nonce in REQAuth. AAC Nonce generated by AAC AAC The consistency is verified, and if the verification passes, the subsequent steps are executed.
[0108] In other embodiments, the AACVeri of S102 also includes the AAC's identity ID. AAC Correspondingly, S103's ASVeri also includes ID. AAC Then AAC also needs to verify the ID in ASVeri. AAC With AAC's own ID AAC Consistency.
[0109] Considering that in practical applications, there might be situations where REQ maliciously sends incorrect digital signatures to evade billing, when AS-AAC and AS-REQ are the same authentication server, AAC can first send AACUpdate to AS-AAC (which can also be represented as AS-REQ), and AS-AAC (which can also be represented as AS-REQ) will then verify the digital signature Sig of REQ in AACUpdate. REQ Verification is performed. Once the verification is successful, the first evidence confirmation message AS-AACAck is generated. If AAC receives AS-AACAck, it indicates that AS-AAC (which can also be represented as AS-REQ) has generated and saved the REQ's request pass record. AAC then sends AACFinish to REQ.
[0110] When AS-AAC and AS-REQ are different authentication servers, AAC can first send AACUpdate to AS-AAC. AS-AAC then generates a second evidence storage message, AS-AACUpdate, based on AACUpdate and sends it to AS-REQ. AS-REQ verifies the digital signature Sig of REQ in the AS-AACUpdate. REQ Verification is performed. If the verification is successful, a second evidence confirmation message AS-REQAck is generated and sent to AS-AAC. AS-AAC generates a first evidence confirmation message AS-AACAck based on AS-REQAck and sends it to AAC. If AAC receives AS-AACAck, it indicates that AS-REQ has generated and saved the REQ's request approval record. AAC then sends AACFinish to REQ. If AAC does not receive AS-AACAck within the specified time, the authentication process ends.
[0111] Furthermore, embodiments of this application also provide a method for determining the first authentication server and / or the second authentication server used in this authentication process by utilizing information exchange between AAC and REQ:
[0112] Please refer to Figure 1 In S101, REQ proactively identifies the Route of at least one trusted authentication server. AS Add to ATTACH so that AAC can use the routes in ATTACH. AS The identity ID of at least one authentication server trusted by AAC itself. AS_AAC This identifies the second authentication server (AS-AAC) involved in identity verification. For example, AAC can determine the route... AS and IDAS_AAC If at least one identical authentication server identity exists, it indicates a non-roaming situation, and AAC determines the second authentication server AS-AAC from the identity identifiers of at least one authentication server commonly trusted by both REQ and AAC. If not, it indicates a roaming situation, and AAC needs to determine the second authentication server AS-AAC based on the ID. AS_AAC Identify the second authentication server AS-AAC involved in identity authentication and route AS Send to AS-AAC so that AS-AAC can adjust the route accordingly. AS Determine the first authentication server AS-REQ.
[0113] Since the authentication servers for REQ and AAC trusts can be the same or different, when the authentication servers for REQ and AAC trusts are the same, it is a non-roaming situation; when the authentication servers for REQ and AAC trusts are different, it is a roaming situation. Based on the aforementioned embodiments, the identity authentication method provided in this application embodiment will be introduced below in conjunction with non-roaming and roaming application scenarios. Among them, the following two situations will be mainly introduced: (1) the identity authentication method protected by REQ identity in the non-roaming situation; (2) the identity authentication method protected by REQ identity in the roaming situation.
[0114] See Figure 3 This is an embodiment of an identity authentication method under the above (1) scenario. In this case, AS-AAC (or AS-REQ) can be used to represent the authentication server jointly trusted by REQ and AAC. In this embodiment, the negotiation process of the message integrity verification key between REQ and AAC is integrated into the identity authentication process in parallel, which is more convenient for engineering implementation. The identity authentication method includes:
[0115] S301, REQ generates KeyInfo REQ and Nonce REQ Generate security capabilities as needed REQ .
[0116] S302, REQ sends an authentication request message ATTACH to AAC.
[0117] The ATTACH includes security capabilities. REQ KeyInfo REQ TID REQ Nonce REQ and Route AS Among them, security capabilities REQThis is an optional field that represents the security capabilities supported by REQ, including the authentication suites, key exchange algorithms, and / or key derivation algorithms supported by REQ (hereinafter the same); KeyInfo REQ It is the first key exchange parameter generated by REQ, including the temporary public key generated by REQ; TID REQ Nonce represents a temporary identity identifier for REQ. REQ The first random number generated for REQ, Route AS This indicates the identity of the authentication server trusted by REQ.
[0118] S303. After receiving ATTACH, AAC performs the following operations (unless otherwise specified or logically related, the numbered actions (1), (2)... do not necessarily have a sequential order due to their numbering, and the same applies throughout the text), including:
[0119] (1) Generate Nonce AAC ;
[0120] (2) Determine Route AS If the identity identifier is the same as that of the authentication server it trusts, then it is determined to be a non-roaming situation.
[0121] It should be noted that the judgment result in this embodiment is for the non-roaming case.
[0122] S304, AAC sends the first authentication request message AACVeri to AS-AAC.
[0123] The AACeri includes TID REQ Nonce REQ ID AAC Nonce AAC and PUB AAC Among them, ID AAC TID is an optional field. REQ and Nonce REQ It should be equal to the corresponding field in ATTACH, Nonce AAC The second random number generated for AAC, ID AAC For AAC's identity identifier, PUB AAC This is the public key for AAC.
[0124] After receiving the AACVeri, S305 and AS-AAC perform the following operations, including:
[0125] (1) Check PUB AAC The legality of the PUB depends on the inspection results. AAC Generate Res AAC ;
[0126] (2) According to TID REQ Search PUB REQ And check PUB REQ The legality of the PUB depends on the inspection results. REQ Generate Res REQ Among them, Res REQ The possible values of can be divided into the following three categories:
[0127] A. If the check result is valid, Res REQ Including inspection results and PUB REQ ;
[0128] B. When the check result is invalid, Res REQ This includes the inspection results, and depending on the application scenario, it may also include PUB (Public Internet Utilities). REQ ;
[0129] C. When TID REQ Invalid, or if AS-AAC requires, according to local policy, to check the validity of the REQ's identity based on the REQ's real identity identifier, then Res REQ The value can be null or other specific values; in this application, the value is null as an example.
[0130] (3) Generate a nonce for evidence storage AS_AAC When the check result is invalid, a nonce may not be generated. AS_AAC In subsequent steps, ASVeri will not include Nonce. AS_AAC .
[0131] (4) Calculate the first and second digital signatures Sig of AS-AAC. AS_AAC1 and Sig AS_AAC2 .
[0132] S306, AS-AAC sends the first authentication response message ASVeri to AAC.
[0133] The ASVeri includes TID REQ Nonce REQ Res AAC Sig AS_AAC1 ID AAC Nonce AAC Res REQ Nonce AS_AAC and Sig AS_AAC2 Among them, TID REQ Nonce REQ ID AAC Nonce AACThey should be equal to the corresponding fields in AACVeri; Sig AS_AAC1 The signature data includes TID REQ Nonce REQ and Res AAC ;Sig AS_AAC2 The signature data includes the Nonce AAC Res REQ and Nonce AS_AAC ID AAC This is an optional field; if an ID exists... AAC Then Sig AS_AAC2 The signature data also includes ID AAC .
[0134] S307. After receiving ASVeri, AAC performs the following operations, including:
[0135] (1) Generate Security capabilities as needed AAC ;
[0136] (2) If an ID exists in ASVeri AAC Then check ID AAC Is it related to AAC's own ID? AAC Same; check Nonce AAC Is it related to the Nonce generated by AAC? AAC same;
[0137] (3) Verify Sig AS_AAC2 ;
[0138] (4) If any step of the above checks and verifications fails, ASVeri shall be discarded immediately; if the above checks and verifications pass, the results shall be processed according to Res. REQ Generate Flag AAC Alternatively, if Res passes the above checks and verifications, REQ If REQ is invalid, the ASVeri can be discarded or the authentication process can be terminated according to the local policy; otherwise, the authentication process can be terminated according to Res. REQ Generate Flag AAC ;
[0139] (5) Generate KeyInfo AAC ;
[0140] (6) Calculate the first digital signature Sig of AAC. AAC1 .
[0141] Among them, Flag AAC Used to indicate whether a real ID is required from the REQ. REQ If Res REQIf the value is Null, then Flag AAC A value of 1 (this is just an example) indicates that the REQ requires a real ID. REQ This is to allow for re-verification of REQ's identity; if Res REQ If the value is not null, then Flag AAC A value of 0 (this is just an example) indicates that the REQ does not require a real ID. REQ .
[0142] S308, AAC sends the first authentication message AACAuth to REQ.
[0143] The AACAuth includes security capabilities. AAC KeyInfo AAC TID REQ Nonce REQ Res AAC Sig AS_AAC1 ID AAC Nonce AAC Nonce AS_AAC Flag AAC and Sig AAC1 Among them, security capabilities AAC This is an optional field, indicating that AAC is based on security capabilities. REQ The selection of a specific security strategy, i.e., the identity authentication method, key exchange algorithm, and / or key derivation algorithm determined by the AAC (hereinafter the same); KeyInfo AAC It is the second key exchange parameter generated by AAC, including the temporary public key generated by AAC; TID REQ Nonce REQ Res AAC Sig AS_AAC1 Nonce AAC Nonce AS_AAC They should be equal to the corresponding fields in ASVeri; Sig AAC1 The signature data includes the Sig in AACAuth. AAC1 Other fields mentioned earlier.
[0144] S309. After receiving AACAuth, REQ performs the following operations, including:
[0145] (1) Check TID REQ and Nonce REQ Are they respectively related to REQ's own TID? REQNonce generated by REQ REQ same;
[0146] (2) Obtain Res AAC PUB in AAC Using PUB AAC Verify Sig AAC1 ;
[0147] (3) Verify Sig AS_AAC1 ;
[0148] (4) After the above checks and verifications are passed, according to the Res in AACAuth AAC Obtain the AAC identity verification result;
[0149] (5) Based on KeyInfo REQ The corresponding temporary private key and KeyInfo AAC The first key K is obtained by key exchange calculation using the temporary public key, and then K is combined with the Nonce. AAC Nonce REQ Other information (the other information used by REQ and AAC is the same and optional, such as a specific string) is used to calculate the message integrity verification key using a negotiated or pre-defined key derivation algorithm; of course, this step can also be moved to be performed when the message integrity verification key is needed.
[0150] (6) If Flag AAC If the identifier is 1, then EncPub is calculated. AS ;
[0151] (7) Calculate the digital signature Sig of REQ REQ ;
[0152] (8) Calculate MacTag REQ .
[0153] S310, REQ sends a second authentication message REQAuth to AAC.
[0154] The REQAuth includes a Nonce. AAC EncPub AS Sig REQ and MacTag REQ Among them, Nonce AAC It should equal the corresponding field in AACAuth; EncPub AS This is the encrypted identity of the REQ, which is the public key pair of the REQ's encryption certificate containing the ID. REQ The information, including Sig, is generated using encryption. REQ It is REQ including Nonce AS_AACThe signature is generated by calculating the information included in EncPub. AS This is an optional field; if Flag... AAC If the flag is 0, REQAuth does not need to carry EncPub. AS MacTag REQ The calculation process is as follows: using the message integrity verification key, an integrity verification algorithm is applied to all messages in REQAuth except for the MacTag. REQ MacTag is generated by calculating information including other fields. REQ .
[0155] S311. After receiving REQAuth, AAC performs the following operations, including:
[0156] (1) Check Nonce AAC Is it related to the Nonce generated by AAC? AAC If they are the same, then discard the REQAuth immediately;
[0157] (2) Based on KeyInfo AAC The corresponding temporary private key and KeyInfo REQ The first key K is obtained by key exchange calculation using the temporary public key, and then K is combined with the Nonce. AAC Nonce REQ Other information (the other information used by AAC and REQ is the same and optional, such as a specific string) is used to calculate the message integrity verification key using a negotiated or pre-defined key derivation algorithm;
[0158] (3) Verify MacTag REQ ;
[0159] AAC uses a message integrity verification key and an integrity verification algorithm to verify the integrity of messages, excluding the MacTag, in REQAuth. REQ Information including other fields is calculated locally in the MacTag. REQ (This calculation method is the same as REQ calculation of MacTag) REQ (In the same way), calculate the MacTag REQ With the received MacTag REQ The comparison is performed; if they match, the verification passes; otherwise, the verification fails.
[0160] (4) If any step of the above checks and verifications fails, the REQAuth will be discarded immediately; if the above checks and verifications pass, the results will be processed according to the Flag. AAC Perform the following operations if Flag AAC If the identifier is 0, then verify Sig. REQ If FlagAAC If the identifier is 1, then AAC sends a third authentication request message AACReVeri to AS-AAC.
[0161] S312, AAC sends a third authentication request message AACReVeri to AS-AAC.
[0162] The AACReVeri includes EncPub AS ID AAC and Nonce AAC Among them, EncPub AS It should be equal to EncPub in REQAuth AS ID AAC This is an optional field.
[0163] S313. After receiving AACReVeri, AS-AAC performs the following operations, including:
[0164] (1) Decrypting EncPub AS Get ID REQ ;
[0165] (2) Based on ID REQ Find the corresponding PUB REQ ;
[0166] (3) Check PUB REQ The legality of generating Res REQ ;
[0167] (4) Calculate Sig as needed AS_AAC4 .
[0168] S314, AS-AAC sends a third authentication response message ASReVeri to AAC.
[0169] The ASReVeri includes ID AAC Nonce AAC Res REQ and Sig AS_AAC4 Among them, ID AAC This is an optional field; AS-AAC determines whether the ID is carried in AACReVeri. AAC Determine whether the ID is carried in ASReVeri AAC Sig AS_AAC4 This is an optional field, and its signature data includes the Nonce. AAC and Res REQ When an ID exists in ASReVeri AAC At that time, Sig AS_AAC4 The signature data also includes ID AAC .
[0170] S315. After receiving ASReVeri, AAC performs the following operations, including:
[0171] (1) If an ID exists in ASReVeri AAC Then check ID AAC Is it related to AAC's own ID? AAC Same; check Nonce in ASReVeri AAC Is it related to the Nonce generated by AAC? AAC same;
[0172] (2) If Sig exists in ASReVeri AS_AAC4 Then verify Sig AS_AAC4 ;
[0173] (3) According to Res REQ PUB in REQ Verify Sig REQ ;
[0174] (4) After the above checks and verifications are passed, according to Res in ASReVeri REQ Obtain the REQ's identity verification result; if any step of the above checks and verifications fails, discard ASReVeri immediately.
[0175] It should be noted that if the Flag AAC A value of 1 indicates that the REQ requires a real ID. REQ At this time, the REQAuth sent by REQ to AAC in S310 carries EncPub. AS AAC needs to send EncPub to AS-AAC. AS AACReVeri, so that AS-AAC is compatible with EncPub AS Decrypt to get ID REQ Then based on ID REQ Search PUB REQ And check PUB REQ The legitimacy of the result, thus generating Res REQ That is, S312 to S315 need to be executed; if Flag AAC A value of 0 indicates that the REQ does not require a real ID. REQ At this time, the REQAuth sent from REQ to AAC in S310 does not carry EncPub. AS That is, AAC does not need to execute S312 to S315. After the checks and verifications in S311 are passed, it can directly execute S316 and subsequent steps.
[0176] S316. After AAC confirms the validity of REQ's identity, it generates TID.REQnew Calculate the second digital signature Sig of AAC as needed. AAC2 .
[0177] S317. AAC sends the first evidence storage message AACUpdate to AS-AAC.
[0178] The AACUpdate includes TID REQ TID REQnew ID AAC Nonce AAC Sig REQ and Sig AAC2 Among them, ID AAC Sig AAC2 TID is an optional field. REQ It should be equal to TID in ATTACH. REQ ;Sig REQ It should be equal to Sig in REQAuth REQ ;Sig AAC2 The signature data includes Sig in AACUpdate. AAC2 Other fields mentioned earlier.
[0179] S318. After receiving AACUpdate, AS-AAC performs the following operations, including:
[0180] (1) If Sig exists in AACUpdate AAC2 Then verify Sig AAC2 ;
[0181] (2) Verify Sig REQ ;
[0182] (3) After the above verification is passed, save the TID. REQnew and replace TID REQ If any step in the above verification fails, AACUpdate is immediately discarded.
[0183] (4) Calculate Sig as needed AS_AAC5 .
[0184] S319, AS-AAC sends the first evidence confirmation message ASAck to AAC.
[0185] The ASAck includes ID AAC Nonce AAC and Sig AS_AAC5 Among them, ID AAC Sig AS_AAC5 Sig is an optional field. AS_AAC5 The signature data includes Sig from ASAck.AS_AAC5 Other fields mentioned earlier.
[0186] After receiving ASAck, S320 and AAC perform the following operations, including:
[0187] (1) If an ID exists in ASAck AAC Then check ID AAC Is it related to AAC's own ID? AAC Same; check Nonce AAC Is it related to the Nonce generated by AAC? AAC same;
[0188] (2) If Sig exists in ASAck AS_AAC5 Then verify Sig AS_AAC5 ;
[0189] (3) After the above checks and verifications are passed, calculate MacTag. AAC If any step in the above checks and verifications fails, the ASAck must be discarded immediately.
[0190] (4) Calculate the session key.
[0191] AAC combines K calculated in S311 with Nonce AAC Nonce REQ ID AAC TID REQnew Other information (the other information used by AAC and REQ is the same and optional, such as a specific string) is used to calculate a session key (including a data encryption key and / or a data integrity verification key) using a key derivation algorithm, which is used for subsequent secure communication between REQ and AAC.
[0192] S321, AAC sends an authentication completion message AACFinish to REQ.
[0193] The AACFinish includes TID REQnew and MacTag AAC Among them, TID REQnew It should be equal to the TID in AACUpdate. REQnew MacTag AAC The calculation process is as follows: using the message integrity verification key, an integrity verification algorithm is applied to all messages in AACFInsh except for the MacTag. AAC MacTag is generated by calculating information including other fields. REQ .
[0194] S322. After receiving AACFinish, REQ performs the following operations, including:
[0195] (1) Verify MacTag AAC ;
[0196] REQ uses a message integrity verification key and an integrity verification algorithm to verify the integrity of messages including MACTag in AACFIinsh. AAC Information including other fields is calculated locally in the MacTag. AAC (This calculation method is the same as AAC's calculation of MacTag) AAC (In the same way), calculate the MacTag AAC With the received MacTag AAC The comparison is performed; if they match, the verification passes; otherwise, the verification fails.
[0197] (2) Save TID REQnew and replace TID REQ ;
[0198] (3) Calculate the session key.
[0199] REQ combines K calculated in S309 with Nonce AAC Nonce REQ ID AAC TID REQnew Other information (the other information used by REQ and AAC is the same and optional, such as a specific string) is used to calculate a session key (including a data encryption key and / or a data integrity verification key) using a key derivation algorithm, which is used for subsequent secure communication between REQ and AAC.
[0200] This achieves two-way identity authentication between REQ and AAC. In this authentication process, REQ uses TID. REQ As an identity credential, it prevents the leakage of real identity information and protects privacy and security. In addition, S316 to S318 realize the notarization of REQ network access behavior, providing a basis for subsequent charging, access tracing, or prevention of malicious billing.
[0201] See Figure 4 This is an embodiment of an identity authentication method under the above (2) scenario. In this embodiment, the negotiation process of the message integrity verification key between REQ and AAC is integrated into the identity authentication process in parallel, which is more convenient for engineering implementation. The identity authentication method includes:
[0202] S401, REQ generates KeyInfo REQ and Nonce REQ Generate security capabilities as needed REQ .
[0203] S402, REQ sends an authentication request message ATTACH to AAC.
[0204] The ATTACH includes security capabilities. REQ KeyInfo REQ TID REQ Nonce REQ and Route AS Among them, security capabilities REQ TID is an optional field. REQ Nonce represents a temporary identity identifier for REQ. REQ The first random number generated for REQ, Route AS This indicates the identity of the authentication server trusted by REQ.
[0205] S403. After receiving ATTACH, AAC performs the following operations, including:
[0206] (1) Generate Nonce AAC ;
[0207] (2) Determine Route AS If the identity identifier is different from that of a trusted authentication server, it is determined to be a roaming situation. The AS-AAC can be determined from at least one trusted authentication server, based on the Route. AS Determine AS-REQ.
[0208] It should be noted that the judgment result in this embodiment is the roaming situation.
[0209] S404, AAC sends the first authentication request message AACVeri to AS-AAC.
[0210] The AACeri includes TID REQ Nonce REQ ID AAC Nonce AAC and PUB AAC Among them, ID AAC TID is an optional field. REQ and Nonce REQ It should be equal to the corresponding field in ATTACH, Nonce AAC The second random number generated for AAC, ID AAC For AAC's identity identifier, PUB AAC This is the public key for AAC.
[0211] After receiving the AACVeri, S405 and AS-AAC perform the following operations, including:
[0212] (1) Check PUB AAC The legality of the PUB depends on the inspection results. AAC Generate Res AAC ;
[0213] (2) Calculate Sig as needed AS_AAC4 .
[0214] S406, AS-AAC sends a second authentication request message AS-AACVeri to AS-REQ.
[0215] The AS-AACVeri includes TID REQ Nonce REQ Res AAC ID AAC Nonce AAC and Sig AS_AAC4 Among them, TID REQ Nonce REQ Nonce AAC These should be equal to the corresponding fields in AACVeri. Sig AS_AAC4 The signature data includes TID REQ Nonce REQ Res AAC ID AAC and Nonce AAC .
[0216] After receiving AS-AACVeri, S407 and AS-REQ perform the following operations, including:
[0217] (1) If Sig exists in AS-AACVeri AS_AAC4 Then verify Sig AS_AAC4 ;
[0218] (2) After successful verification, according to TID REQ Search PUB REQ And check PUB REQ The legality of the PUB depends on the inspection results and PUB. REQ Generate Res REQ Among them, Res REQ The possible values of can be divided into the following three categories:
[0219] A. If the check result is valid, Res REQ Including inspection results and PUB REQ ;
[0220] B. When the check result is invalid, Res REQ This includes the inspection results, and depending on the application scenario, it may also include PUB (Public Internet Utilities). REQ ;
[0221] C. When TID REQ Invalid, or if AS-REQ requires verification of REQ's identity based on the REQ's real identity identifier according to local policies, then Res REQ The value can be null or other specific values; in this application, the value is null as an example.
[0222] (3) Generate a nonce for evidence storage AS_REQ When the check result is invalid, a nonce may not be generated. AS_REQ In subsequent steps, AS-REQVeri will not include Nonce. AS_REQ .
[0223] (4) Calculate the first and second digital signatures Sig of AS-REQ. AS_REQ1 and Sig AS_REQ2 .
[0224] S408, AS-REQ sends a second authentication response message AS-REQVeri to AS-AAC.
[0225] The AS-REQVeri includes TID REQ Nonce REQ Res AAC Sig AS_REQ1 ID AAC Nonce AAC Res REQ Nonce AS_REQ Sig AS_REQ2 Among them, TID REQ Nonce REQ Res AAC ID AAC Nonce AAC They should be equal to the corresponding fields in AS-AACVeri respectively; Sig AS_REQ1 The signature data includes TID REQ Nonce REQ and Res AAC Sig AS_REQ2 The signature data includes ID AAC Nonce AAC Res REQ and Nonce AS_REQ .
[0226] S409. After receiving AS-REQVeri, AS-AAC performs the following operations, including:
[0227] (1) Verify Sig AS_REQ2 ;
[0228] (2) After successful verification, calculate the second digital signature Sig of AS-AAC. AS_AAC2 .
[0229] S410, AS-AAC sends the first authentication response message ASVeri to AAC.
[0230] The ASVeri includes TID REQ Nonce REQ Res AAC Sig AS_REQ1 ID AAC Nonce AAC Res REQ Nonce AS_REQ and Sig AS_AAC2 Among them, ID AAC This is an optional field. Sig AS_AAC2 The signature data includes the Nonce AAC Res REQ and Nonce AS_REQ ID AAC This is an optional field; if an ID exists... AAC Then Sig AS_AAC2 The signature data also includes ID AAC .
[0231] S411. After receiving ASVeri, AAC performs the following operations, including:
[0232] (1) Generate Security capabilities as needed AAC ;
[0233] (2) If an ID exists in ASVeri AAC Then check ID AAC Is it related to AAC's own ID? AAC Same; check Nonce AAC Is it related to the Nonce generated by AAC? AAC same;
[0234] (3) Verify Sig AS_AAC2 ;
[0235] (4) If any step of the above checks and verifications fails, ASVeri shall be discarded immediately; if the above checks and verifications pass, the results shall be processed according to Res. REQ Generate FlagAAC Alternatively, if Res passes the above checks and verifications, REQ If REQ is invalid, the ASVeri can be discarded or the authentication process can be terminated according to the local policy; otherwise, the authentication process can be terminated according to Res. REQ Generate Flag AAC ;
[0236] (5) Generate KeyInfo AAC ;
[0237] (6) Calculate the first digital signature Sig of AAC. AAC1 .
[0238] Among them, Flag AAC Used to indicate whether a real ID is required from the REQ. REQ If Res REQ If the value is Null, then Flag AAC A value of 1 (this is just an example) indicates that the REQ requires a real ID. REQ This is to allow for re-verification of REQ's identity; if Res REQ If the value is not null, then Flag AAC A value of 0 (this is just an example) indicates that the REQ does not require a real ID. REQ .
[0239] S412, AAC sends the first authentication message AACAuth to REQ.
[0240] The AACAuth includes security capabilities. AAC KeyInfo AAC TID REQ Nonce REQ Res AAC Sig AS_REQ1 ID AAC Nonce AAC Nonce AS_REQ Flag AAC and Sig AAC1 Among them, Security capabilities AAC TID is an optional field. REQ Nonce REQ Res AAC Sig AS_REQ1 Nonce AAC Nonce AS_REQ They should be equal to the corresponding fields in ASVeri, Sig AAC1The signature data includes the Sig in AACAuth. AAC1 Other fields mentioned earlier.
[0241] S413. After receiving AACAuth, REQ performs the following operations, including:
[0242] (1) Check TID REQ and Nonce REQ Are they respectively related to REQ's own TID? REQ Nonce generated by REQ REQ same;
[0243] (2) Obtain Res AAC PUB in AAC Using PUB AAC Verify Sig AAC1 ;
[0244] (3) Verify Sig AS_REQ1 ;
[0245] (4) After the above checks and verifications are passed, according to the Res in AACAuth AAC Obtain the AAC identity verification result;
[0246] (5) Based on KeyInfo REQ The corresponding temporary private key and KeyInfo AAC The first key K is obtained by key exchange calculation using the temporary public key, and then K is combined with the Nonce. AAC Nonce REQ Other information (the other information used by REQ and AAC is the same and optional, such as a specific string) is used to calculate the message integrity verification key using a negotiated or pre-defined key derivation algorithm; of course, this step can also be moved to be performed when the message integrity verification key is needed.
[0247] (6) If Flag AAC If the identifier is 1, then EncPub is calculated. AS ;
[0248] (7) Calculate the digital signature Sig of REQ REQ ;
[0249] (8) Calculate MacTag REQ .
[0250] S414, REQ sends a second authentication message REQAuth to AAC.
[0251] The REQAuth includes a Nonce. AAC EncPub ASSig REQ and MacTag REQ Among them, Nonce AAC It should be equal to the Nonce in AACAuth. AAC EncPub AS REQ utilizes the public key pair of the encryption certificate, including the ID. REQ The information, including the ciphertext, is generated using encryption; Sig REQ It is REQ including Nonce AS_REQ The signature is generated by calculating the information included in EncPub. AS This is an optional field; if Flag... AAC If the flag is 0, REQAuth does not need to carry EncPub. AS MacTag REQ The calculation process is as follows Figure 3 As described in the embodiments.
[0252] S415. After receiving REQAuth, AAC performs the following operations, including:
[0253] (1) Check Nonce AAC Is it related to the Nonce generated by AAC? AAC same;
[0254] (2) Based on KeyInfo AAC The corresponding temporary private key and KeyInfo REQ The first key K is obtained by key exchange calculation using the temporary public key, and then K is combined with the Nonce. AAC Nonce REQ Other information (the other information used by AAC and REQ is the same and optional, such as a specific string) is used to calculate the message integrity verification key using a negotiated or pre-defined key derivation algorithm;
[0255] (3) Verify MacTag REQ The verification process is as follows: Figure 3 As described in the embodiments;
[0256] (4) If any step of the above checks and verifications fails, the REQAuth will be discarded immediately; if the above checks and verifications pass, the results will be processed according to the Flag. AAC Perform the following operations if Flag AAC If the identifier is 0, then verify Sig. REQ If Flag AAC If the identifier is 1, then AAC sends a third authentication request message AACReVeri to AS-AAC.
[0257] S416, AAC sends a third authentication request message AACReVeri to AS-AAC.
[0258] The AACReVeri includes EncPub AS ID AAC and Nonce AAC Among them, EncPub AS It should be equal to EncPub in REQAuth AS ID AAC This is an optional field.
[0259] S417, AS-AAC sends the fourth authentication request message AS-AACReVeri to AS-REQ.
[0260] The AS-AACReVeri is generated by AS-AAC based on AACReVeri, and the AS-AACReVeri includes EncPub. AS ID AAC and Nonce AAC .
[0261] S418. After receiving AS-AACReVeri, AS-REQ performs the following operations, including:
[0262] (1) Decrypting EncPub AS Get ID REQ ;
[0263] (2) Based on the ID obtained from decryption REQ Find the corresponding PUB REQ ;
[0264] (3) Check PUB REQ The legality of the data is verified, and a Res is generated based on the inspection results. REQ ;
[0265] (4) Calculate Sig as needed AS_REQ3 .
[0266] S419, AS-REQ sends the fourth authentication response message AS-REQReVeri to AS-AAC.
[0267] The AS-REQReVeri includes ID AAC Nonce AAC Res REQ and Sig AS_REQ3 Among them, ID AAC Nonce AAC They should be equal to the corresponding fields in AS-AACReVeri; Sig AS_REQ3Sig is an optional field. AS_REQ3 The signature data includes Sig in AS-REQReVeri. AS_REQ3 Other fields mentioned earlier.
[0268] After receiving AS-REQReVeri, S420 and AS-AAC perform the following operations, including:
[0269] (1) If Sig exists in AS-REQReVeri AS_REQ3 Then verify Sig AS_REQ3 ;
[0270] (2) After verification, calculate Sig as needed. AS_AAC5 .
[0271] S421, AS-AAC sends a third authentication response message ASReVeri to AAC.
[0272] The ASReVeri includes ID AAC Nonce AAC Res REQ and Sig AS_AAC5 Among them, ID AAC This is an optional field; Sig AS_AAC5 This is an optional field, and its signature data includes the Nonce. AAC and Res REQ When ASReVeri carries an ID AAC When, then Sig AS_AAC5 The signature data also includes ID AAC .
[0273] S422. After receiving ASReVeri, AAC performs the following operations, including:
[0274] (1) If an ID exists in ASReVeri AAC Then check ID AAC Is it related to AAC's own ID? AAC Same; check Nonce in ASReVeri AAC Is it related to the Nonce generated by AAC? AAC same;
[0275] (2) If Sig exists in ASReVeri AS_AAC5 Then verify Sig AS_AAC5 ;
[0276] (3) According to Res REQ PUB in REQ Verify Sig REQ ;
[0277] (4) After the above checks and verifications are passed, according to Res in ASReVeri REQ Obtain the REQ's identity verification result; if any step of the above checks and verifications fails, discard ASReVeri immediately.
[0278] It should be noted that if the Flag AAC A value of 1 indicates that the REQ requires a real ID. REQ At this point, the REQAuth sent by REQ to AAC in S414 carries EncPub. AS And it is necessary to execute S416 to S422 so that AS-REQ can be applied to EncPub. AS Decrypt to get ID REQ Then based on ID REQ Search PUB REQ And check PUB REQ The legitimacy of the result, thus generating Res REQ If Flag AAC A value of 0 indicates that the REQ does not require a real ID. REQ At this point, the REQAuth sent by REQ to AAC in S414 does not carry EncPub. AS That is, AAC does not need to execute S416 to S422. After the checks and verifications in S415 are passed, it can directly execute S423 and subsequent steps.
[0279] S423. After AAC confirms the validity of REQ's identity, it generates TID. REQnew Calculate the second digital signature Sig of AAC as needed. AAC2 .
[0280] S424, AAC sends the first evidence storage message AACUpdate to AS-AAC.
[0281] The AACUpdate includes TID REQ TID REQnew ID AAC Nonce AAC Sig REQ and Sig AAC2 Among them, ID AAC Sig AAC2 This is an optional field; Sig REQ It should be equal to Sig in REQAuth REQ .
[0282] S425, after receiving AACUpdate, AS-AAC performs the following operations, including:
[0283] (1) If Sig exists in AACUpdate AAC2 Then verify Sig AAC2 ;
[0284] (2) Calculate the third digital signature Sig of AS-AAC as needed. AS_AAC3 .
[0285] S426, AS-AAC sends a second evidence storage message ASUpdate to AS-REQ.
[0286] The ASUpdate is generated based on AACUpdate, and the ASUpdate includes TID. REQ TID REQnew ID AAC Sig REQ and Sig AS_AAC3 Among them, TID REQ TID REQnew Sig REQ They should be equal to the corresponding fields in AACUpdate; Sig AS_AAC3 This is an optional field, and its signature data includes Sig from ASUpdate. AS_AAC3 Other fields mentioned earlier.
[0287] S427. After receiving ASUpdate, AS-REQ performs the following operations, including:
[0288] (1) If Sig exists in ASUpdate AS_AAC3 Then verify Sig AS_AAC3 ;
[0289] (2) Verify Sig REQ ;
[0290] (3) After successful verification, save the TID. REQnew and replace TID REQ ;
[0291] (4) Calculate Sig as needed AS_REQ4 .
[0292] S428, AS-REQ sends a second evidence confirmation message AS-REQAck to AS-AAC.
[0293] The AS-REQAck includes ID AAC and Sig AS_REQ4 Among them, Sig AS_REQ4 This is an optional field, and its signature data includes ID. AAC .
[0294] S429. After receiving AS-REQAck, AS-AAC performs the following operations, including:
[0295] (1) If Sig exists in AS-REQAck AS_REQ4 Then verify Sig AS_REQ4 ;
[0296] (2) Calculate Sig as needed AS_AAC6 .
[0297] S430, AS-AAC sends the first evidence confirmation message AS-AACAck to AAC.
[0298] The AS-AACAck includes ID. AAC Nonce AAC and Sig AS_AAC6 Among them, Sig AS_AAC6 This is an optional field, and its signature data includes the Nonce. AAC ID AAC This is an optional field; if an ID exists in AS-AACAck... AAC Sig AS_AAC6 The signature data also includes ID AAC .
[0299] S431. Upon receiving AS-AACAck, AAC performs the following operations, including:
[0300] (1) If an ID exists in AS-AACAck AAC Then check ID AAC Is it related to AAC's own ID? AAC Same; check Nonce AAC Is it related to the Nonce generated by AAC? AAC same;
[0301] (2) If Sig exists in AS-AACAck AS_AAC6 Then verify Sig AS_AAC6 ;
[0302] (3) After the above checks and verifications are passed, calculate MacTag. AAC If any step in the above checks and verifications fails, the AS-AACAck must be discarded immediately.
[0303] (4) Calculate the session key.
[0304] AAC combines the K calculated in S415 with the Nonce. AAC Nonce REQ ID AAC TID REQnewOther information (the other information used by AAC and REQ is the same and optional, such as a specific string) is used to calculate a session key (including a data encryption key and / or a data integrity verification key) using a key derivation algorithm, which is used for subsequent secure communication between REQ and AAC.
[0305] S432, AAC sends an authentication completion message AACFinish to REQ.
[0306] The AACFinish includes TID REQnew and MacTag AAC Among them, TID REQnew It should be equal to the TID in AACUpdate. REQnew MacTag AAC The calculation is as follows Figure 3 As described in the embodiments.
[0307] S433, REQ, upon receiving AACFinish, performs the following operations, including:
[0308] (1) Verify MacTag AAC The verification process is as follows: Figure 3 As described in the embodiments;
[0309] (2) Save TID REQnew and replace TID REQ ;
[0310] (3) Calculate the session key.
[0311] In this context, REQ combines K calculated in S413 with Nonce. AAC Nonce REQ ID AAC TID REQnew Other information (the other information used by REQ and AAC is the same and optional, such as a specific string) is used to calculate a session key (including a data encryption key and / or a data integrity verification key) using a key derivation algorithm, which is used for subsequent secure communication between REQ and AAC.
[0312] This achieves two-way identity authentication between REQ and AAC. During this authentication process, REQ's real identity is not directly transmitted, preventing the leakage of REQ's true identity information and ensuring privacy and security. Furthermore, S424 to S430 implement evidence storage of REQ's network access behavior, providing evidence for subsequent billing and preventing malicious billing.
[0313] In the above embodiments, each message may also carry a hash value. X_Y The hash value X_YThis is calculated by the sending entity X using a hash algorithm on the latest preceding message received from the peer entity Y. It is used by the peer entity Y to verify whether entity X has received the complete latest preceding message. Here, HASH... REQ_AAC This represents the hash value calculated by REQ for the latest preceding message sent by AAC. AAC_REQ HASH represents the hash value calculated by AAC for the latest preceding message sent by the received REQ. AAC_AS-AAC HASH represents the hash value calculated by AAC for the latest preceding message received from AS-AAC. AS-AAC_AAC HASH represents the hash value calculated by AS-AAC for the latest preceding message sent by AAC. AS-AAC_AS-REQ HASH represents the hash value calculated by AS-AAC for the latest preceding message sent by AS-REQ. AS-REQ_AS-AAC This represents the hash value calculated by AS-REQ for the latest preceding message received from AS-AAC. If the message currently sent by sender entity X is the first message exchanged between entity X and entity Y, meaning that entity X has not received any preceding messages from peer entity Y, then the hash value in this message... X_Y It may not exist or be meaningless.
[0314] Correspondingly, after the peer entity Y receives a message sent by entity X, if the message contains a hash... X_Y If entity Y has not sent a preceding message to entity X, then entity Y ignores the hash. X_Y When entity Y has previously sent a preceding message to entity X, entity Y uses a hash algorithm to calculate a hash value locally for the latest preceding message previously sent to entity X, and then hashes it with the hash value carried in the received message. X_Y If they match, proceed with the next steps; otherwise, discard or end the identification process.
[0315] In this invention, for entity X, the preceding message sent by peer entity Y to entity X refers to any message received by entity X from peer entity Y before entity X sends message M to peer entity Y; the latest preceding message sent by peer entity Y to entity X refers to the latest message received by entity X from peer entity Y before entity X sends message M to peer entity Y. If message M sent by entity X to its peer entity Y is the first message exchanged between entity X and entity Y, then there are no preceding messages sent by peer entity Y to entity X before entity X sends message M to its peer entity Y.
[0316] The above Figures 3 to 4 The optional fields and optional operations in the corresponding embodiments are shown in the accompanying drawings. Figures 3 to 4The asterisk (*) indicates the content. The order of the various contents included in the messages in all the above embodiments is not limited, and unless otherwise specified, the order in which the message receiver operates on the relevant messages and processes the contents included in the messages is not limited.
[0317] based on Figures 1 to 4 For the corresponding method implementation examples, please refer to... Figure 5 This application embodiment also provides a request device REQ, including:
[0318] Sending module 510 is used to send an authentication request message to the authentication access controller, wherein the authentication request message includes a temporary identity identifier of the requesting device;
[0319] The receiving module 520 is used to receive a first verification message sent by the authentication access controller. The first verification message includes the authentication result of the authentication access controller, the first digital signature of the first authentication server, the evidence storage random number generated by the first authentication server, and the first digital signature of the authentication access controller.
[0320] The verification module 530 is used to verify the first digital signature of the first authentication server and the public key of the authentication access controller carried in the authentication result of the authentication access controller, and to verify the first digital signature of the authentication access controller. After the verification is successful, the authentication module 530 obtains the authentication result of the authentication access controller based on the authentication result of the authentication access controller.
[0321] The sending module 510 is further configured to send a second verification message to the authentication access controller after determining that the identity of the authentication access controller is legitimate. The second verification message includes the digital signature of the requesting device. The digital signature of the requesting device is generated by signing information including the stored random number of the first authentication server.
[0322] The receiving module 520 is also configured to receive an authentication completion message sent by the authentication access controller. The authentication completion message includes a new temporary identity identifier of the requesting device. The new temporary identity identifier is generated by the authentication access controller after the digital signature of the requesting device is verified by the authentication access controller based on the public key of the requesting device carried in the authentication result of the requesting device.
[0323] The update module 540 is used to replace the temporary identity of the requesting device with the new temporary identity of the requesting device in the authentication completion message.
[0324] Optionally, the authentication completion message may also include a second message integrity check code generated by the authentication access controller. The second message integrity check code is calculated by the authentication access controller using the message integrity check key between itself and the requesting device, including other fields in the authentication completion message besides the second message integrity check code. In this case, the verification module 530 is further used to verify the second message integrity check code in the authentication completion message.
[0325] Optionally, the authentication request message further includes a first key exchange parameter generated by the requesting device, and the first verification message further includes a second key exchange parameter generated by the authentication access controller; the requesting device further includes:
[0326] The first calculation module is used to generate a first key by performing key exchange calculations based on the temporary private key corresponding to the first key exchange parameters and the temporary public key included in the second key exchange parameters, and to calculate the message integrity verification key using a key derivation algorithm based on the calculation data including the first key.
[0327] Optionally, the authentication request message further includes a first random number generated by the requesting device, and the first verification message further includes the first random number and a second random number generated by the authentication access controller; the verification module 530 is also used to verify the consistency between the first random number in the first verification message and the first random number generated by the requesting device.
[0328] The calculation data for the first calculation module to calculate the message integrity verification key also includes the first random number and the second random number.
[0329] Optionally, the first verification message may also include the identity identifier of the authentication access controller;
[0330] The requesting device also includes:
[0331] The second calculation module is used to calculate a session key for subsequent secure communication based on information including the first key, the temporary identity identifier of the requesting device, and the identity identifier of the authentication access controller.
[0332] Optionally, the message sent by the requesting device to the authentication access controller may also include a hash value calculated by the requesting device for the latest preceding message sent by the authentication access controller.
[0333] See Figure 6 This application also provides an authentication access controller (AAC), including:
[0334] The receiving module 610 is used to receive an authentication request message sent by the requesting device, wherein the authentication request message includes a temporary identity identifier of the requesting device;
[0335] The sending module 620 is used to send a first authentication request message to a second authentication server trusted by the authentication access controller. The first authentication request message includes a temporary identity identifier of the requesting device and the public key of the authentication access controller.
[0336] The receiving module 610 is further configured to receive a first authentication response message sent by the second authentication server. The first authentication response message includes the authentication result of the authentication access controller, the first digital signature of the first authentication server trusted by the requesting device, the authentication result of the requesting device, the evidence storage random number generated by the first authentication server, and the second digital signature of the second authentication server.
[0337] Verification module 630 is used to verify the second digital signature of the second authentication server;
[0338] The sending module 620 is further configured to send a first verification message to the requesting device after the second digital signature of the second authentication server has been verified. The first verification message includes the authentication result of the authentication access controller, the first digital signature of the first authentication server, the evidence storage random number generated by the first authentication server, and the first digital signature of the authentication access controller.
[0339] The receiving module 610 is further configured to receive a second verification message sent by the requesting device, the second verification message including the digital signature of the requesting device; the digital signature of the requesting device is generated by signing information including the evidence-stored random number of the first authentication server.
[0340] The verification module 630 is also used to verify the digital signature of the requesting device based on the public key of the requesting device carried in the authentication result of the requesting device;
[0341] The generation module 640 is configured to obtain the identity legitimacy authentication result of the requesting device based on the authentication result of the requesting device, generate a new temporary identity identifier for the requesting device after the digital signature of the requesting device passes the verification and the identity of the requesting device is determined to be legitimate, and then generate an authentication completion message and a first evidence storage message; wherein, the authentication completion message includes the new temporary identity identifier of the requesting device; the first evidence storage message includes the new temporary identity identifier of the requesting device and the digital signature of the requesting device;
[0342] The sending module 620 is also configured to send the first evidence storage message to the first authentication server trusted by the requesting device through the second authentication server, and to send the authentication completion message to the requesting device.
[0343] Optionally, the sending module 620 first sends the first evidence storage message, and after the receiving module 610 receives the first evidence storage confirmation message, it sends the authentication completion message to the requesting device. The first evidence storage confirmation message is generated by the first authentication server after verifying the digital signature of the requesting device in the first evidence storage message.
[0344] Optionally, the authentication completion message sent by the sending module 620 may also include a second message integrity check code generated by the authentication access controller. The second message integrity check code is calculated by the authentication access controller using the message integrity check key between itself and the requesting device, including other fields in the authentication completion message besides the second message integrity check code.
[0345] Optionally, the authentication request message further includes a first key exchange parameter generated by the requesting device, and the first verification message further includes a second key exchange parameter generated by the authentication access controller; the authentication access controller further includes:
[0346] The first calculation module is used to generate a first key by performing key exchange calculations based on the temporary private key corresponding to the second key exchange parameters and the temporary public key included in the first key exchange parameters, and to calculate the message integrity verification key using a key derivation algorithm based on the calculation data including the first key.
[0347] Optionally, the authentication request message further includes a first random number generated by the requesting device, the first authentication request message further includes the first random number and a second random number generated by the authentication access controller, and correspondingly, the first authentication response message further includes the first random number and the second random number, the first verification message further includes the first random number and the second random number, and the second verification message further includes the second random number.
[0348] The verification module 630 is further configured to verify the consistency between the second random number in the first authentication response message and the second random number generated by the authentication access controller before sending the first verification message to the requesting device; and to verify the consistency between the second random number in the second verification message and the second random number generated by the authentication access controller before generating a new temporary identity for the requesting device.
[0349] The calculation data for the first calculation module to calculate the message integrity verification key also includes the first random number and the second random number.
[0350] Optionally, the authentication request message may also include security capability parameter information supported by the requesting device, and the authentication access controller may further include:
[0351] The first determining module is used to determine the specific security policy used by the authentication access controller based on the security capability parameter information, and the first verification message further includes the specific security policy.
[0352] Optionally, the authentication request message further includes the identity identifier of at least one authentication server trusted by the requesting device, and the authentication access controller further includes:
[0353] The second determining module is used to determine the second authentication server based on the identity identifier of at least one authentication server trusted by the requesting device in the request message and the identity identifier of the authentication server trusted by the authentication access controller.
[0354] Optionally, the second verification message also includes a first message integrity check code generated by the requesting device. The first message integrity check code is calculated by the requesting device using the message integrity check key between itself and the authentication access controller, including other fields in the second verification message besides the first message integrity check code.
[0355] The verification module 630 is further configured to verify the first message integrity check code before the authentication access controller generates a new temporary identity for the requesting device.
[0356] Optionally, when the authentication result of the requesting device indicates that the requesting device needs to send its real identity identifier, the first verification message generated by the authentication access controller further includes an indication identifier, which is used to instruct the requesting device to send its real identity identifier.
[0357] The second verification message also includes the encrypted identity of the requesting device, which is generated by the requesting device encrypting its identity using the public key of the encryption certificate.
[0358] Then the sending module 620 is further configured to send a third authentication request message to the second authentication server, wherein the third authentication request message includes the encrypted identity identifier of the requesting device;
[0359] The receiving module 610 is further configured to receive a third authentication response message sent by the second authentication server, wherein the third authentication response message includes the authentication result of the requesting device;
[0360] The verification module 630 is further configured to re-determine the legitimacy of the requesting device based on the authentication result of the requesting device carried in the third authentication response message.
[0361] Optionally, the first authentication request message may further include the identity identifier of the authentication access controller; then the first authentication response message may further include the identity identifier of the authentication access controller.
[0362] The verification module 630 is further configured to verify the consistency between the identity identifier of the authentication access controller in the first authentication response message and the identity identifier of the authentication access controller itself before sending the first verification message to the requesting device.
[0363] Optionally, the first verification message may also include the identity identifier of the authentication access controller;
[0364] The authentication access controller further includes:
[0365] The second calculation module is used to calculate a session key for subsequent secure communication based on information including the first key, the temporary identity identifier of the requesting device, and the identity identifier of the authentication access controller.
[0366] Optionally, the message sent by the authentication access controller to the requesting device may also include a hash value calculated by the authentication access controller for the latest preamble message received from the requesting device; the message sent by the authentication access controller to the second authentication server may also include a hash value calculated by the authentication access controller for the latest preamble message received from the second authentication server.
[0367] See Figure 7 This application also provides a second authentication server AS-AAC, which is an authentication server trusted by the authentication access controller, including:
[0368] The receiving module 710 is configured to receive a first authentication request message sent by the authentication access controller, wherein the first authentication request message includes a temporary identity identifier of the requesting device and the public key of the authentication access controller;
[0369] The sending module 720 is used to send a first authentication response message to the authentication access controller. The first authentication response message includes the authentication result of the authentication access controller, the first digital signature of the first authentication server trusted by the requesting device, the authentication result of the requesting device, the evidence storage random number generated by the first authentication server, and the second digital signature of the second authentication server.
[0370] The receiving module 710 is further configured to receive a first evidence storage message generated by the authentication access controller, wherein the first evidence storage message includes a new temporary identity identifier of the requesting device and a digital signature of the requesting device; the digital signature of the requesting device is generated by the requesting device performing signature calculation on information including the evidence storage random number of the first authentication server.
[0371] Optionally, the first evidence storage message may also include a second digital signature of the authentication access controller, wherein the second digital signature of the authentication access controller is generated by signing other information preceding the second digital signature of the authentication access controller in the first evidence storage message;
[0372] The second authentication server further includes:
[0373] The verification module is used to verify the second digital signature of the authentication access controller.
[0374] Optionally, when the first authentication server and the second authentication server are the same, the second authentication server further includes:
[0375] The first processing module is used to check the validity of the public key of the authentication access controller and generate the authentication result of the authentication access controller; to find and check the validity of the public key of the requesting device based on the temporary identity of the requesting device, generate the authentication result of the requesting device, and generate a storage random number.
[0376] The first generation module is used to calculate the first digital signature of the first authentication server based on information including the authentication result of the authentication access controller, and to calculate the second digital signature of the second authentication server based on information including the authentication result of the requesting device and the evidence storage random number.
[0377] Optionally, if the first authentication server and the second authentication server are different, then the second authentication server further includes:
[0378] The second processing module is used to check the validity of the public key of the authentication access controller and generate the authentication result of the authentication access controller;
[0379] The second generation module is used to generate a second authentication request message based on the first authentication request message. The second authentication request message includes the temporary identity identifier of the requesting device and the authentication result of the authentication access controller.
[0380] The sending module 720 is also used to send the second authentication request message to the first authentication server;
[0381] The receiving module 710 is further configured to receive a second authentication response message sent by the first authentication server. The second authentication response message includes the authentication result of the authentication access controller, the first digital signature of the first authentication server, the authentication result of the requesting device, the evidence storage random number, and the second digital signature of the first authentication server. The first digital signature of the first authentication server is calculated and generated based on information including the authentication result of the authentication access controller, and the second digital signature of the first authentication server is calculated and generated based on information including the authentication result of the requesting device and the evidence storage random number.
[0382] The second processing module is further configured to verify the second digital signature of the first authentication server. After the verification is successful, the second generation module is further configured to calculate the second digital signature of the second authentication server based on information including the authentication result of the requesting device and the evidence storage random number, and generate the first authentication response message.
[0383] The second generation module is further configured to generate a second evidence storage message based on the first evidence storage message, and send the second evidence storage message to the first authentication server through the sending module. The second evidence storage message includes a new temporary identity of the requesting device, a digital signature of the requesting device, and a third digital signature of the second authentication server. The third digital signature of the second authentication server is calculated and generated by the second authentication server based on information including the new temporary identity of the requesting device and the digital signature of the requesting device.
[0384] Optionally, the receiving module 710 is further configured to receive a second evidence confirmation message generated and sent by the first authentication server after the third digital signature verification of the second authentication server in the second evidence storage message is passed;
[0385] The second processing module is also used to verify the third digital signature of the first authentication server in the second evidence confirmation message;
[0386] The second generation module is also used to generate a first evidence confirmation message after the third digital signature verification of the first authentication server is passed;
[0387] The sending module 720 is also used to send the first evidence confirmation message to the authentication access controller.
[0388] Optionally, the message sent by the second authentication server to the authentication access controller may also include a hash value calculated by the second authentication server for the latest preamble message received from the authentication access controller; the message sent by the second authentication server to the first authentication server may also include a hash value calculated by the second authentication server for the latest preamble message received from the first authentication server.
[0389] See Figure 8 This application embodiment also provides a first authentication server AS-REQ, which is an authentication server requesting device trust, including:
[0390] The verification module 810 is used to verify the digital signature of the requesting device in the first evidence storage message using the public key of the requesting device. The first evidence storage message includes a new temporary identity of the requesting device and the digital signature of the requesting device. The digital signature of the requesting device is generated by the requesting device by signing information including the evidence storage random number of the first authentication server.
[0391] The replacement module 820 is used to generate and save the request pass record of the requesting device after the digital signature verification of the requesting device is passed, and replace the temporary identity of the requesting device with the new temporary identity of the requesting device in the first evidence storage message.
[0392] Optionally, the first authentication server further includes:
[0393] The judgment module is used to determine whether the temporary identity of the requesting device meets the time limit before generating the evidence storage random number. If so, the replacement module 820 generates the evidence storage random number.
[0394] Optionally, when the first authentication server and the second authentication server trusted by the authentication access controller are different, the first authentication server further includes:
[0395] The receiving module is configured to receive a second authentication request message sent by the second authentication server, wherein the second authentication request message includes the temporary identity identifier of the requesting device and the authentication result of the authentication access controller;
[0396] The verification module 810 is also used to find and check the legality of the public key of the requesting device based on the temporary identity of the requesting device, generate the authentication result of the requesting device, and generate a random number for evidence storage.
[0397] The calculation module is used to calculate the first digital signature of the first authentication server based on information including the authentication result of the authentication access controller, and to calculate the second digital signature of the first authentication server based on information including the authentication result of the requesting device and the evidence storage random number.
[0398] The sending module is used to send a second authentication response message to the second authentication server. The second authentication response message includes the authentication result of the authentication access controller, the first digital signature of the first authentication server, the authentication result of the requesting device, the evidence storage random number, and the second digital signature of the first authentication server.
[0399] The receiving module is further configured to receive a second evidence storage message sent by the second authentication server. The second evidence storage message includes a new temporary identity of the requesting device, a digital signature of the requesting device, and a third digital signature of the second authentication server. The third digital signature of the second authentication server is calculated and generated by the second authentication server based on information including the new temporary identity of the requesting device and the digital signature of the requesting device.
[0400] The verification module 810 is also used to verify the third digital signature of the second authentication server, and to perform subsequent related steps after the verification is successful.
[0401] Optionally, the message sent by the first authentication server to the second authentication server may also include a hash value calculated by the first authentication server for the latest preceding message received from the second authentication server.
[0402] Those skilled in the art will understand that all or part of the steps of the above method embodiments can be implemented by hardware related to program instructions. The aforementioned program can be stored in a computer-readable storage medium. When the program is executed, it performs the steps of the above method embodiments. The aforementioned storage medium can be at least one of the following media: read-only memory (ROM), RAM, magnetic disk, or optical disk, etc., and other media capable of storing program code.
[0403] It should be noted that the various embodiments in this specification are described in a progressive manner, and the same or similar parts between the various embodiments can be referred to mutually. Each embodiment focuses on describing the differences from other embodiments. In particular, for the device and system embodiments, since they are consistent with and correspond to the method embodiments, the description is relatively simple, and relevant parts can be referred to the description of the method embodiments. The device and system embodiments described above are merely illustrative. The modules described as separate components may or may not be physically separate, and the components shown as modules may or may not be physical modules, that is, they may be located in one place or distributed across multiple network units. Some or all of the modules can be selected to achieve the purpose of this embodiment solution according to actual needs. Those skilled in the art can understand and implement this without creative effort.
[0404] The above description is merely one specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the technical scope disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.
Claims
1. A method for identity verification, characterized in that, The method includes: The requesting device sends an authentication request message to the authentication access controller, the authentication request message including the temporary identity identifier of the requesting device; The authentication access controller sends a first authentication request message to a second authentication server it trusts. The first authentication request message includes the temporary identity of the requesting device and the public key of the authentication access controller. The controller also receives a first authentication response message from the second authentication server. The first authentication response message includes the authentication result of the authentication access controller, the first digital signature of the first authentication server trusted by the requesting device, the authentication result of the requesting device, the evidence-stored random number generated by the first authentication server, and the second digital signature of the second authentication server. The authentication access controller verifies the second digital signature of the second authentication server. After successful verification, it sends a first verification message to the requesting device. The first verification message includes the authentication result of the authentication access controller, the first digital signature of the first authentication server, the evidence storage random number generated by the first authentication server, and the first digital signature of the authentication access controller. The requesting device verifies the first digital signature of the first authentication server and verifies the first digital signature of the authentication access controller based on the public key of the authentication access controller carried in the authentication result of the authentication access controller. After successful verification, the device obtains the authentication legitimacy result of the authentication access controller based on the authentication result of the authentication access controller. After determining that the authentication access controller is legitimate, the device sends a second verification message to the authentication access controller. The second verification message includes the digital signature of the requesting device. The digital signature of the requesting device is generated by signing information including the stored random number of the first authentication server. The authentication access controller uses the public key of the requesting device carried in the authentication result of the requesting device to verify the digital signature of the requesting device and obtains the authentication result of the legality of the requesting device's identity based on the authentication result of the requesting device. After the verification is successful and the legality of the requesting device is determined, a new temporary identity identifier of the requesting device is generated, and then an authentication completion message and a first evidence storage message are generated; wherein, the authentication completion message includes the new temporary identity identifier of the requesting device; the first evidence storage message includes the new temporary identity identifier of the requesting device and the digital signature of the requesting device; The requesting device replaces its temporary identity with the new temporary identity of the requesting device in the authentication completion message; The first authentication server uses the public key of the requesting device to verify the digital signature of the requesting device in the first evidence storage message. After the verification is successful, it generates and saves the request approval record of the requesting device, and replaces the temporary identity of the requesting device with the new temporary identity of the requesting device in the first evidence storage message.
2. The method according to claim 1, characterized in that, The authentication access controller first sends the first evidence storage message. After the first authentication server verifies the digital signature of the requesting device in the first evidence storage message, it generates a first evidence storage confirmation message. After receiving the first evidence confirmation message, the authentication access controller sends the authentication completion message to the requesting device.
3. The method according to claim 1, characterized in that, The authentication completion message also includes a second message integrity check code generated by the authentication access controller. The second message integrity check code is calculated and generated by the authentication access controller using the message integrity check key between itself and the requesting device, including other fields in the authentication completion message besides the second message integrity check code. Before the requesting device replaces its temporary identity with the new temporary identity in the authentication completion message, the method further includes: the requesting device verifying the second message integrity check code in the authentication completion message.
4. The method according to claim 3, characterized in that, The authentication request message further includes a first key exchange parameter generated by the requesting device, and the first verification message further includes a second key exchange parameter generated by the authentication access controller; therefore, the method further includes: The requesting device generates a first key by performing key exchange calculations based on the temporary private key corresponding to the first key exchange parameters and the temporary public key included in the second key exchange parameters, and calculates the message integrity verification key using a key derivation algorithm based on the calculation data including the first key. The authentication access controller generates the first key by performing key exchange calculations based on the temporary private key corresponding to the second key exchange parameters and the temporary public key included in the first key exchange parameters, and calculates the message integrity verification key using the key derivation algorithm based on the calculation data including the first key.
5. The method according to claim 4, characterized in that, The authentication request message also includes a first random number generated by the requesting device. The first authentication request message also includes the first random number and a second random number generated by the authentication access controller. Correspondingly... The first authentication response message also includes the first random number and the second random number, the first verification message also includes the first random number and the second random number, and the second verification message also includes the second random number; Before the authentication access controller sends the first authentication message to the requesting device, it further includes: The authentication access controller verifies the consistency between the second random number in the first authentication response message and the second random number generated by the authentication access controller. Before the requesting device sends the second authentication message to the authentication access controller, the method further includes: The requesting device verifies the consistency between the first random number in the first verification message and the first random number generated by the requesting device; Before the authentication access controller generates a new temporary identity for the requesting device, the method further includes: The authentication access controller verifies the consistency between the second random number in the second verification message and the second random number generated by the authentication access controller. The calculation data for the authentication access controller and the requesting device to calculate the message integrity verification key also includes the first random number and the second random number.
6. The method according to claim 1, characterized in that, If the authentication request message also includes security capability parameter information supported by the requesting device, then the method further includes: If the authentication access controller determines the security policy used by the authentication access controller based on the security capability parameter information, then the first verification message also includes the security policy.
7. The method according to claim 1, characterized in that, If the authentication request message also includes the identity identifier of at least one authentication server trusted by the requesting device, then the method further includes: The authentication access controller determines the second authentication server based on the identity identifier of at least one authentication server trusted by the requesting device in the authentication request message and the identity identifier of the authentication server trusted by the authentication access controller.
8. The method according to claim 1, characterized in that, If the first authentication server and the second authentication server are the same, then the method further includes: After receiving the first authentication request message, the first authentication server checks the validity of the public key of the authentication access controller and generates the authentication result of the authentication access controller; it searches for and checks the validity of the public key of the requesting device based on the temporary identity of the requesting device, generates the authentication result of the requesting device, and generates a storage random number; it calculates the first digital signature of the first authentication server based on information including the authentication result of the authentication access controller, calculates the second digital signature of the second authentication server based on information including the authentication result of the requesting device and the storage random number, and sends a first authentication response message to the authentication access controller. The first authentication response message includes the authentication result of the authentication access controller, the first digital signature of the first authentication server, the authentication result of the requesting device, the storage random number generated by the first authentication server, and the second digital signature of the second authentication server.
9. The method according to claim 1, characterized in that, The first evidence storage message also includes the second digital signature of the authentication access controller, wherein the second digital signature of the authentication access controller is generated by signing other information preceding the second digital signature of the authentication access controller in the first evidence storage message; The method further includes: The second authentication server verifies the second digital signature of the authentication access controller.
10. The method according to claim 3, characterized in that, The second verification message also includes a first message integrity check code generated by the requesting device. The first message integrity check code is calculated by the requesting device using the message integrity check key between itself and the authentication access controller, including other fields in the second verification message besides the first message integrity check code. Before the authentication access controller generates a new temporary identity for the requesting device, the method further includes: The authentication access controller verifies the first message integrity check code.
11. The method according to claim 1, characterized in that, When the authentication result of the requesting device indicates that the requesting device needs to send its real identity identifier, the first verification message generated by the authentication access controller further includes an indication identifier, which is used to instruct the requesting device to send its real identity identifier. The second verification message further includes the encrypted identity of the requesting device, which is generated by the requesting device encrypting its identity using the public key of its encryption certificate; the method further includes: The authentication access controller sends a third authentication request message to the second authentication server, the third authentication request message including the encrypted identity of the requesting device; The authentication access controller receives a third authentication response message sent by the second authentication server, the third authentication response message including the authentication result of the requesting device; The authentication access controller then re-determines the legitimacy of the requesting device based on the authentication result of the requesting device carried in the third authentication response message.
12. The method according to claim 1, characterized in that, The first authentication request message also includes the identity identifier of the authentication access controller; The first authentication response message further includes the identity identifier of the authentication access controller. Before the authentication access controller sends the first verification message to the requesting device, it also includes: The authentication access controller verifies the consistency between the authentication access controller's identity identifier in the first authentication response message and the authentication access controller's own identity identifier.
13. The method according to claim 4, characterized in that, The first verification message also includes the identity identifier of the authentication access controller, and the method further includes: The authentication access controller calculates a session key for subsequent secure communication based on information including the first key, the temporary identity of the requesting device, and the identity of the authentication access controller. The requesting device calculates a session key for subsequent secure communication based on information including the first key, the temporary identity of the requesting device, and the identity of the authentication access controller.
14. The method according to claim 1, characterized in that, If the first authentication server and the second authentication server are different, the method further includes: The second authentication server receives the first authentication request message sent by the authentication access controller, checks the validity of the public key of the authentication access controller, generates the authentication result of the authentication access controller, and sends a second authentication request message to the first authentication server; the second authentication request message includes the temporary identity of the requesting device and the authentication result of the authentication access controller; The first authentication server searches for and checks the validity of the public key of the requesting device based on the temporary identity of the requesting device, generates the authentication result of the requesting device and generates a storage random number, calculates the first digital signature of the first authentication server based on information including the authentication result of the authentication access controller, calculates the second digital signature of the first authentication server based on information including the authentication result of the requesting device and the storage random number, and sends a second authentication response message to the second authentication server. The second authentication response message includes the authentication result of the authentication access controller, the first digital signature of the first authentication server, the authentication result of the requesting device, the storage random number, and the second digital signature of the first authentication server. The second authentication server verifies the second digital signature of the first authentication server. After successful verification, the second authentication server calculates the second digital signature of the second authentication server based on information including the authentication result of the requesting device and the stored random number, and generates the first authentication response message. The authentication access controller sends the first evidence storage message to the second authentication server; the second authentication server generates a second evidence storage message based on the first evidence storage message and sends the second evidence storage message to the first authentication server. The second evidence storage message includes the new temporary identity of the requesting device, the digital signature of the requesting device, and the third digital signature of the second authentication server; wherein, the third digital signature of the second authentication server is calculated and generated by the second authentication server based on information including the new temporary identity of the requesting device and the digital signature of the requesting device; the first authentication server verifies the third digital signature of the second authentication server, and performs subsequent related steps after successful verification.
15. The method according to claim 14, characterized in that, The first authentication server verifies the third digital signature of the second authentication server in the second evidence storage message. After successful verification, it generates and sends a second evidence storage confirmation message to the second authentication server. The second authentication server receives the second evidence confirmation message, verifies the third digital signature of the first authentication server in the second evidence confirmation message, and after successful verification, generates and sends the first evidence confirmation message to the authentication access controller. After receiving the first evidence confirmation message, the authentication access controller sends the authentication completion message to the requesting device.
16. The method according to any one of claims 1 to 15, characterized in that, The message sent by the requesting device to the authentication access controller also includes a hash value calculated by the requesting device for the latest preceding message received from the authentication access controller; When the authentication access controller receives a message from the requesting device, it first verifies the hash value in the received message, and then performs subsequent operations after the verification is successful. The message sent by the authentication access controller to the requesting device also includes a hash value calculated by the authentication access controller for the latest preceding message sent by the requesting device. When the requesting device receives a message from the authentication access controller, it first verifies the hash value in the received message, and then performs subsequent operations after the verification is successful. The message sent by the authentication access controller to the second authentication server also includes a hash value calculated by the authentication access controller for the latest preceding message received from the second authentication server; When the second authentication server receives a message from the authentication access controller, it first verifies the hash value in the received message, and then performs subsequent operations after the verification is successful. The message sent by the second authentication server to the authentication access controller also includes a hash value calculated by the second authentication server for the latest preceding message sent by the authentication access controller. When the authentication access controller receives a message from the second authentication server, it first verifies the hash value in the received message, and then performs subsequent operations after the verification is successful. The message sent by the first authentication server to the second authentication server also includes a hash value calculated by the first authentication server for the latest preceding message received from the second authentication server; When the second authentication server receives a message from the first authentication server, it first verifies the hash value in the received message, and then performs subsequent operations after the verification is successful. The message sent by the second authentication server to the first authentication server also includes a hash value calculated by the second authentication server for the latest preceding message sent by the first authentication server. When the first authentication server receives a message from the second authentication server, it first verifies the hash value in the received message, and then performs subsequent operations after the verification is successful.
17. A requesting device, characterized in that, include: The sending module is used to send an authentication request message to the authentication access controller, wherein the authentication request message includes a temporary identity identifier of the requesting device; The receiving module is configured to receive a first verification message sent by the authentication access controller, wherein the first verification message includes the authentication result of the authentication access controller, the first digital signature of the first authentication server, the evidence storage random number generated by the first authentication server, and the first digital signature of the authentication access controller. The verification module is used to verify the first digital signature of the first authentication server and the first digital signature of the authentication access controller carried in the authentication result of the authentication access controller. After the verification is successful, the authentication access controller's identity legitimacy authentication result is obtained based on the authentication result of the authentication access controller. The sending module is further configured to send a second verification message to the authentication access controller after determining that the identity of the authentication access controller is legitimate. The second verification message includes the digital signature of the requesting device. The digital signature of the requesting device is generated by signing information including the stored random number of the first authentication server. The receiving module is further configured to receive an authentication completion message sent by the authentication access controller. The authentication completion message includes a new temporary identity identifier for the requesting device. The new temporary identity identifier is generated by the authentication access controller after the digital signature of the requesting device is verified by the authentication access controller based on the public key of the requesting device carried in the authentication result of the requesting device. An update module is used to replace the temporary identity of the requesting device with the new temporary identity of the requesting device in the authentication completion message.
18. The requesting device according to claim 17, characterized in that, The authentication completion message also includes a second message integrity check code generated by the authentication access controller. The second message integrity check code is calculated and generated by the authentication access controller using the message integrity check key between itself and the requesting device, including other fields in the authentication completion message besides the second message integrity check code. The verification module is further configured to verify the second message integrity check code in the authentication completion message.
19. The requesting device according to claim 18, characterized in that, The authentication request message further includes a first key exchange parameter generated by the requesting device, and the first verification message further includes a second key exchange parameter generated by the authentication access controller; the requesting device further includes: The first calculation module is used to generate a first key by performing key exchange calculations based on the temporary private key corresponding to the first key exchange parameters and the temporary public key included in the second key exchange parameters, and to calculate the message integrity verification key using a key derivation algorithm based on the calculation data including the first key.
20. The requesting device according to claim 19, characterized in that, The authentication request message also includes a first random number generated by the requesting device, and the first verification message also includes the first random number and a second random number generated by the authentication access controller; The verification module is also used to verify the consistency between the first random number in the first verification message and the first random number generated by the requesting device; The calculation data for the first calculation module to calculate the message integrity verification key also includes the first random number and the second random number.
21. The requesting device according to claim 19, characterized in that, The first verification message also includes the identity identifier of the authentication access controller; the requesting device further includes: The second calculation module is used to calculate a session key for subsequent secure communication based on information including the first key, the temporary identity identifier of the requesting device, and the identity identifier of the authentication access controller.
22. The requesting device according to any one of claims 17 to 21, characterized in that, The message sent by the requesting device to the authentication access controller also includes a hash value calculated by the requesting device for the latest preceding message received from the authentication access controller.
23. An authentication access controller, characterized in that, include: The receiving module is used to receive an authentication request message sent by the requesting device, wherein the authentication request message includes a temporary identity identifier of the requesting device; The sending module is configured to send a first authentication request message to a second authentication server trusted by the authentication access controller. The first authentication request message includes a temporary identity identifier of the requesting device and the public key of the authentication access controller. The receiving module is further configured to receive a first authentication response message sent by the second authentication server. The first authentication response message includes the authentication result of the authentication access controller, the first digital signature of the first authentication server trusted by the requesting device, the authentication result of the requesting device, the evidence storage random number generated by the first authentication server, and the second digital signature of the second authentication server. The verification module is used to verify the second digital signature of the second authentication server; The sending module is further configured to send a first verification message to the requesting device after the second digital signature of the second authentication server has been verified. The first verification message includes the authentication result of the authentication access controller, the first digital signature of the first authentication server, the evidence storage random number generated by the first authentication server, and the first digital signature of the authentication access controller. The receiving module is further configured to receive a second verification message sent by the requesting device, the second verification message including the digital signature of the requesting device; the digital signature of the requesting device is generated by signing information including the stored random number of the first authentication server; The verification module is further configured to verify the digital signature of the requesting device based on the public key of the requesting device carried in the authentication result of the requesting device; The generation module is configured to obtain the identity legitimacy authentication result of the requesting device based on the authentication result of the requesting device, generate a new temporary identity identifier for the requesting device after the digital signature of the requesting device passes the verification and the identity of the requesting device is determined to be legitimate, and then generate an authentication completion message and a first evidence storage message; wherein, the authentication completion message includes the new temporary identity identifier of the requesting device; the first evidence storage message includes the new temporary identity identifier of the requesting device and the digital signature of the requesting device; The sending module is further configured to send the first evidence storage message to the first authentication server trusted by the requesting device through the second authentication server, and to send the authentication completion message to the requesting device.
24. The authentication access controller according to claim 23, characterized in that, The sending module first sends the first evidence storage message, and after the receiving module receives the first evidence storage confirmation message, it sends the authentication completion message to the requesting device. The first evidence storage confirmation message is generated by the first authentication server after verifying the digital signature of the requesting device in the first evidence storage message.
25. The authentication access controller according to claim 23, characterized in that, The authentication completion message sent by the sending module also includes a second message integrity check code generated by the authentication access controller. The second message integrity check code is calculated by the authentication access controller using the message integrity check key between itself and the requesting device, including other fields in the authentication completion message besides the second message integrity check code.
26. The authentication access controller according to claim 25, characterized in that, The authentication request message further includes a first key exchange parameter generated by the requesting device, and the first verification message further includes a second key exchange parameter generated by the authentication access controller; the authentication access controller further includes: The first calculation module is used to generate a first key by performing key exchange calculations based on the temporary private key corresponding to the second key exchange parameters and the temporary public key included in the first key exchange parameters, and to calculate the message integrity verification key using a key derivation algorithm based on the calculation data including the first key.
27. The authentication access controller according to claim 26, characterized in that, The authentication request message also includes a first random number generated by the requesting device. The first authentication request message also includes the first random number and a second random number generated by the authentication access controller. Correspondingly... The first authentication response message also includes the first random number and the second random number, the first verification message also includes the first random number and the second random number, and the second verification message also includes the second random number; The verification module is further configured to verify the consistency between the second random number in the first authentication response message and the second random number generated by the authentication access controller before sending the first verification message to the requesting device; And before generating a new temporary identity for the requesting device, the consistency between the second random number in the second verification message and the second random number generated by the authentication access controller is verified; The calculation data for the first calculation module to calculate the message integrity verification key also includes the first random number and the second random number.
28. The authentication access controller according to claim 23, characterized in that, The authentication request message also includes security capability parameter information supported by the requesting device, and the authentication access controller further includes: The first determining module is used to determine the security policy used by the authentication access controller based on the security capability parameter information, and the first verification message further includes the security policy.
29. The authentication access controller according to claim 23, characterized in that, The authentication request message also includes the identity identifier of at least one authentication server trusted by the requesting device, and the authentication access controller further includes: The second determining module is used to determine the second authentication server based on the identity identifier of at least one authentication server trusted by the requesting device and the identity identifier of the authentication server trusted by the authentication access controller in the authentication request message.
30. The authentication access controller according to claim 23, characterized in that, The second verification message also includes a first message integrity check code generated by the requesting device. The first message integrity check code is calculated by the requesting device using the message integrity check key between itself and the authentication access controller, including other fields in the second verification message besides the first message integrity check code. The verification module is further configured to verify the first message integrity check code before the authentication access controller generates a new temporary identity for the requesting device.
31. The authentication access controller according to claim 23, characterized in that, When the authentication result of the requesting device indicates that the requesting device needs to send its real identity identifier, the first verification message generated by the authentication access controller further includes an indication identifier, which is used to instruct the requesting device to send its real identity identifier. The second verification message also includes the encrypted identity of the requesting device, which is generated by the requesting device encrypting its identity using the public key of the encryption certificate. The sending module is further configured to send a third authentication request message to the second authentication server, the third authentication request message including the encrypted identity identifier of the requesting device; The receiving module is further configured to receive a third authentication response message sent by the second authentication server, wherein the third authentication response message includes the authentication result of the requesting device; The verification module is further configured to re-determine the legitimacy of the requesting device based on the authentication result of the requesting device carried in the third authentication response message.
32. The authentication access controller according to claim 23, characterized in that, The first authentication request message also includes the identity identifier of the authentication access controller; therefore, the first authentication response message also includes the identity identifier of the authentication access controller. The verification module is further configured to verify the consistency between the identity identifier of the authentication access controller in the first authentication response message and the identity identifier of the authentication access controller itself before sending the first verification message to the requesting device.
33. The authentication access controller according to claim 26, characterized in that, The first verification message also includes the identity identifier of the authentication access controller; the authentication access controller further includes: The second calculation module is used to calculate a session key for subsequent secure communication based on information including the first key, the temporary identity identifier of the requesting device, and the identity identifier of the authentication access controller.
34. The authentication access controller according to any one of claims 23 to 33, characterized in that, The message sent by the authentication access controller to the requesting device also includes a hash value calculated by the authentication access controller for the latest preamble message received from the requesting device; the message sent by the authentication access controller to the second authentication server also includes a hash value calculated by the authentication access controller for the latest preamble message received from the second authentication server.
35. A second authentication server, characterized in that, include: The receiving module is configured to receive a first authentication request message sent by the authentication access controller, wherein the first authentication request message includes a temporary identity identifier of the requesting device and the public key of the authentication access controller; The sending module is used to send a first authentication response message to the authentication access controller. The first authentication response message includes the authentication result of the authentication access controller, the first digital signature of the first authentication server trusted by the requesting device, the authentication result of the requesting device, the evidence storage random number generated by the first authentication server, and the second digital signature of the second authentication server. The first authentication server and the second authentication server are the same. The receiving module is further configured to receive a first evidence storage message generated by the authentication access controller, the first evidence storage message including a new temporary identity identifier of the requesting device and a digital signature of the requesting device; the digital signature of the requesting device is generated by the requesting device performing signature calculation on information including the evidence storage random number of the first authentication server; The first processing module is used to check the validity of the public key of the authentication access controller and generate the authentication result of the authentication access controller; to find and check the validity of the public key of the requesting device based on the temporary identity of the requesting device, generate the authentication result of the requesting device, and generate a storage random number. The first generation module is used to calculate the first digital signature of the first authentication server based on information including the authentication result of the authentication access controller, and to calculate the second digital signature of the second authentication server based on information including the authentication result of the requesting device and the evidence storage random number.
36. A second authentication server, characterized in that, include: The receiving module is configured to receive a first authentication request message sent by the authentication access controller, wherein the first authentication request message includes a temporary identity identifier of the requesting device and the public key of the authentication access controller; The sending module is used to send a first authentication response message to the authentication access controller. The first authentication response message includes the authentication result of the authentication access controller, the first digital signature of the first authentication server trusted by the requesting device, the authentication result of the requesting device, the evidence storage random number generated by the first authentication server, and the second digital signature of the second authentication server. The first authentication server is different from the second authentication server. The second processing module is used to check the validity of the public key of the authentication access controller and generate the authentication result of the authentication access controller; The second generation module is used to generate a second authentication request message based on the first authentication request message. The second authentication request message includes the temporary identity identifier of the requesting device and the authentication result of the authentication access controller. The sending module is also used to send the second authentication request message to the first authentication server; The receiving module is further configured to receive a second authentication response message sent by the first authentication server. The second authentication response message includes the authentication result of the authentication access controller, the first digital signature of the first authentication server, the authentication result of the requesting device, the evidence storage random number, and the second digital signature of the first authentication server. The first digital signature of the first authentication server is calculated and generated based on information including the authentication result of the authentication access controller, and the second digital signature of the first authentication server is calculated and generated based on information including the authentication result of the requesting device and the evidence storage random number. The second processing module is further configured to verify the second digital signature of the first authentication server. After the verification is successful, the second generation module is further configured to calculate the second digital signature of the second authentication server based on information including the authentication result of the requesting device and the evidence storage random number, and generate the first authentication response message. The second generation module is further configured to generate a second evidence storage message based on the first evidence storage message, and send the second evidence storage message to the first authentication server through the sending module. The second evidence storage message includes a new temporary identity of the requesting device, a digital signature of the requesting device, and a third digital signature of the second authentication server. The third digital signature of the second authentication server is calculated and generated by the second authentication server based on information including the new temporary identity of the requesting device and the digital signature of the requesting device.
37. The second authentication server according to claim 35 or 36, characterized in that, The first evidence storage message also includes the second digital signature of the authentication access controller, which is generated by signing other information preceding the second digital signature of the authentication access controller in the first evidence storage message; The second authentication server further includes: The verification module is used to verify the second digital signature of the authentication access controller.
38. The second authentication server according to claim 36, characterized in that, The receiving module is also used to receive the second evidence confirmation message generated and sent by the first authentication server after the third digital signature verification of the second authentication server in the second evidence storage message is passed. The second processing module is also used to verify the third digital signature of the first authentication server in the second evidence confirmation message; The second generation module is also used to generate a first evidence confirmation message after the third digital signature verification of the first authentication server is passed; The sending module is also used to send the first evidence confirmation message to the authentication access controller.
39. The second authentication server according to claim 35 or 36, characterized in that, The message sent by the second authentication server to the authentication access controller also includes a hash value calculated by the second authentication server for the latest preamble message received from the authentication access controller; the message sent by the second authentication server to the first authentication server also includes a hash value calculated by the second authentication server for the latest preamble message received from the first authentication server.
40. A first authentication server, characterized in that, include: The verification module is used to verify the digital signature of the requesting device in the first evidence storage message using the public key of the requesting device. The first evidence storage message includes a new temporary identity of the requesting device and the digital signature of the requesting device. The digital signature of the requesting device is generated by the requesting device by signing information including the evidence storage random number of the first authentication server. The replacement module is used to generate and save the request pass record of the requesting device after the digital signature verification of the requesting device is passed, and replace the temporary identity of the requesting device with the new temporary identity of the requesting device in the first evidence storage message; The receiving module is configured to receive a second authentication request message sent by a second authentication server trusted by the authentication access controller, wherein the second authentication request message includes a temporary identity identifier of the requesting device and the authentication result of the authentication access controller, and the second authentication server is different from the first authentication server; The verification module is also used to find and check the legality of the public key of the requesting device based on the temporary identity of the requesting device, generate the authentication result of the requesting device, and generate a random number for evidence storage. The calculation module is used to calculate the first digital signature of the first authentication server based on information including the authentication result of the authentication access controller, and to calculate the second digital signature of the first authentication server based on information including the authentication result of the requesting device and the evidence storage random number. The sending module is used to send a second authentication response message to the second authentication server. The second authentication response message includes the authentication result of the authentication access controller, the first digital signature of the first authentication server, the authentication result of the requesting device, the evidence storage random number, and the second digital signature of the first authentication server. The receiving module is further configured to receive a second evidence storage message sent by the second authentication server. The second evidence storage message includes a new temporary identity of the requesting device, a digital signature of the requesting device, and a third digital signature of the second authentication server. The third digital signature of the second authentication server is calculated and generated by the second authentication server based on information including the new temporary identity of the requesting device and the digital signature of the requesting device. The verification module is also used to verify the third digital signature of the second authentication server, and to perform subsequent related steps after the verification is successful.
41. The first authentication server according to claim 40, characterized in that, Also includes: The judgment module is used to determine whether the temporary identity of the requesting device meets the time limit before generating the evidence storage random number. If so, the replacement module generates the evidence storage random number.
42. The first authentication server according to claim 40 or 41, characterized in that, The message sent by the first authentication server to the second authentication server also includes a hash value calculated by the first authentication server for the latest preceding message received from the second authentication server.
Citation Information
Patent Citations
An access authentication method suitable for wired and wireless network
CN1668005A
Handset identifier verification
US20190289464A1