Authentication method, device and system

IAB host uses certificate authentication to authenticate IAB nodes, which solves the problem of USIM card and core network participation when 5G IAB nodes are connected to the network, and achieves the effect of reducing costs and simplifying the authentication process.

CN114830705BActive Publication Date: 2025-05-06HUAWEI TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN201980103050.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2019-12-31
Publication Date
2025-05-06
Estimated Expiration
2039-12-31

AI Technical Summary

Technical Problem

When 5G IAB nodes are connected to the network, the existing technology requires the configuration of USIM cards, which increases the cost of the nodes. The authentication process requires the participation of the core network, which affects the performance of the core network.

Method used

Through the IAB host, it uses certificate authentication to authenticate the IAB nodes based on the support certificate authentication capabilities reported by the IAB node, which avoids USIM card configuration and core network participation.

Benefits of technology

It realizes the secure authentication of IAB nodes when entering the network without configuring a USIM card, which reduces the cost of nodes, simplifies the authentication process, and reduces the impact on the core network.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114830705B_ABST
    Figure CN114830705B_ABST
Patent Text Reader

Abstract

The present application provides an authentication method, device and system, which can be used for security authentication between a relay node and a host node when the relay node joins the network. The host node determines that the authentication method of the relay node is certificate authentication based on the ability to support certificate authentication reported by the relay node. In this method, the relay node first indicates to the host node that the relay node supports certificate authentication; then the host node determines that the relay node uses certificate authentication; the host node sends a second message to the relay node, instructing the relay node to use certificate authentication. The scheme in this application can be used in communication systems, for example, it can be used in fifth-generation 5G networks.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of communication technology, and in particular to an authentication method, device and system. Background Art

[0002] An important technology in the deployment of the fifth-generation mobile communication technology (5th-Generation, 5G) network is the "integrated access backhaul" (IAB) technology. IAB technology integrates the wireless access link and the wireless backhaul link. It does not require a separate antenna (usually optical fiber) for the backhaul link, enabling operators to install 5G antennas in places where it is difficult to deploy optical fiber or the cost of deploying optical fiber is too high.

[0003] The R16 standard stipulates that when an IAB node joins the network, it can use the 5G-authentication and key agreement (5G-AKA) or extensible authentication protocol-AKA' (extensible authentication protocol-AKA', EAP-AKA') authentication method. The 5G-AKA or EAP-AKA' authentication method requires that the IAB node must be configured with a universal subscriber identity module (USIM) card, which increases the cost of the IAB node. Summary of the invention

[0004] The embodiments of the present application provide an authentication method, device and system. An IAB host (donor) can authenticate the IAB node by using certificate authentication based on the capability of supporting certificate authentication reported by the IAB node. Therefore, the IAB node can complete the security authentication when joining the network without configuring a USIM card, thereby reducing the cost of the IAB node.

[0005] To achieve the above-mentioned objectives, the embodiments of the present application adopt the following technical solutions. In the methods of the first aspect to the ninth aspect below, the IAB scenario is used as an example for explanation. It should be noted that the first aspect to the ninth aspect below are also applicable to relay scenarios other than the IAB scenario, wherein the IAB node can be replaced with a relay node, and the IAB host can be replaced with a host node.

[0006] In a first aspect, an authentication method and a corresponding authentication device are provided. In the scheme, an IAB host receives a first message from an IAB node, the first message includes first indication information, the first indication information is used to indicate an authentication method supported by the IAB node, and the authentication method supported by the IAB node includes certificate authentication; the IAB host determines that the IAB node uses certificate authentication according to the first indication information; the IAB host sends a second message to the IAB node, the second message includes second indication information used to indicate that the IAB node uses certificate authentication; wherein the IAB host is a parent node of the IAB node; or the IAB node is connected to the IAB host through one or more other IAB nodes.

[0007] The first message may be a radio resource control (RRC) connection setup request message (setup request); or the first message may be an RRC connection setup completion message (setup complete). If the first message is an RRC connection setup request message, the second message may be an RRC connection setup message (setup). If the first message is an RRC connection setup completion message, the second message may be an RRC message sent by the IAB host to the IAB node after the RRC connection setup completion message.

[0008] In this scheme, the IAB host can determine that the IAB node uses certificate authentication based on the capability of supporting certificate authentication reported by the IAB node, and send a second message to the IAB node to instruct the IAB node to use certificate authentication for security authentication, so that the IAB node can complete the security authentication when joining the network without configuring a USIM card, reducing the cost of the IAB node, and the authentication process only involves the interaction between the IAB host and the IAB node, without the involvement of the core network, reducing the impact on the core network.

[0009] In a possible design, before the IAB host receives the first message from the IAB node, the method further includes: the IAB host sends a system broadcast message, the system broadcast message includes third indication information, and the third indication information is used to indicate that the IAB host supports the certificate authentication mode.

[0010] That is, before the IAB host receives the first message from the IAB node, the IAB host may carry the third indication information in the system broadcast message to notify the IAB node that the IAB host supports the certificate authentication mode.

[0011] In one possible design, the authentication methods supported by the IAB node also include at least one of the following authentication methods: 5G-Authentication and Key Agreement AKA, Extensible Authentication Protocol EAP-AKA' or EAP-Transport Layer Security TLS.

[0012] In one possible design, after the IAB host sends the second message to the IAB node, the method further includes: the IAB host receives a third message from the IAB node; the IAB host authenticates the IAB node based on the third message; wherein the third message carries at least one of the following information: an electronic serial number ESN of the IAB node, a certificate of the IAB node, or a signature of the IAB node on the third message.

[0013] That is, after the IAB host sends the second message to the IAB node, the IAB host may authenticate the IAB node according to the third message from the IAB node including certificate-related information.

[0014] In a possible design, the third message includes a certificate of the IAB node, the certificate of the IAB node comes from a certificate issuing server CA; the certificate of the IAB node includes a CA signature, and the IAB host has a CA public key from the CA; the IAB host authenticates the IAB node according to the third message, including: the IAB host verifies the CA signature using the CA public key.

[0015] In one possible design, the third message also includes a signature of the IAB node on the third message, and the certificate of the IAB node also includes a public key of the IAB node; the IAB host authenticates the IAB node based on the third message, and also includes: if the IAB host passes the verification of the CA signature using the CA public key, the IAB host obtains the public key of the IAB node from the certificate of the IAB node, and uses the public key of the IAB node to verify the signature of the third message.

[0016] In one possible design, the third message also includes the ESN of the IAB node, and the IAB host has an ESN whitelist from the operation administration and maintenance server OAM; the IAB host authenticates the IAB node based on the third message, and also includes: if the IAB host uses the public key of the IAB node to verify the signature of the third message, the IAB host verifies the consistency of the ESN of the IAB node with the ESN included in the certificate of the IAB node; or, if the IAB host uses the public key of the IAB node to verify the signature of the third message, the IAB host uses the ESN whitelist to verify the ESN of the IAB node.

[0017] In a possible design, after the IAB host successfully authenticates the IAB node according to the third message, the method may further include: the IAB host sends a fourth message to the IAB node. The fourth message may carry at least one of the following information: an electronic serial number (ESN) of the IAB host, a certificate of the IAB host, or a signature of the IAB host on the fourth message.

[0018] That is, after the IAB host successfully authenticates the IAB node according to the third message, the IAB host may further send a fourth message to the IAB node, so that the IAB node may authenticate the IAB host according to the fourth message, thereby completing the two-way authentication process between the IAB host and the IAB node.

[0019] In one possible design, after the IAB host sends the second message to the IAB node, the method further includes: the IAB host receives request information from the IAB node, the request information is used to indicate obtaining the certificate of the IAB node; in response to the request information, the IAB host obtains the certificate of the IAB node from the operator CA through the core network; the IAB host sends the certificate of the IAB node to the IAB node. The signaling transmission involved in the above process can be carried on the signaling radio bearer SRB1 for transmission; or can be carried on the preconfigured data radio bearer DRB for transmission.

[0020] In a second aspect, an authentication method and a corresponding communication device are provided. In this scheme, an IAB node sends a first message to an IAB host, the first message includes first indication information, the first indication information is used to indicate an authentication method supported by the IAB node, and the authentication method supported by the IAB node includes certificate authentication; the IAB node receives a second message from the IAB host, the second message includes second indication information used to instruct the IAB node to use certificate authentication; wherein the IAB host is a parent node of the IAB node; or, the IAB node is connected to the IAB host through one or more other IAB nodes.

[0021] The first message may be an RRC connection establishment request message; or the first message may be an RRC connection establishment completion message. If the first message is an RRC connection establishment request message, the second message may be an RRC connection establishment message. If the first message is an RRC connection establishment completion message, the second message may be an RRC message sent by the IAB host to the IAB node after the RRC connection establishment completion message.

[0022] In this solution, the IAB node reports the capability of supporting certificate authentication to the IAB host, and receives a second message including second indication information for instructing the IAB node to use certificate authentication, so as to instruct the IAB node to use certificate authentication for security authentication, thereby enabling the IAB node to complete security authentication upon network access without configuring a USIM card, thereby reducing the cost of the IAB node, and enabling the authentication process to involve only the interaction between the IAB host and the IAB node, without the involvement of the core network, thereby reducing the impact on the core network.

[0023] In a possible design, before the IAB node sends the first message to the IAB host, the method further includes: the IAB node receiving a system broadcast message from the IAB host, the system broadcast message including third indication information, and the third indication information is used to indicate that the IAB host supports the certificate authentication mode.

[0024] In one possible design, the authentication methods supported by the IAB node also include at least one of the following authentication methods: 5G-Authentication and Key Agreement AKA, Extensible Authentication Protocol EAP-AKA' or EAP-Extensible Authentication Protocol TLS.

[0025] In one possible design, after the IAB node receives the second message from the IAB host, the method further includes: the IAB node sends a third message to the IAB host, the third message carrying at least one of the following information: an electronic serial number ESN of the IAB node, a certificate of the IAB node, and a signature of the IAB node on the third message.

[0026] In one possible design, after the IAB node sends the third message to the IAB host, the method may further include: the IAB node receives a fourth message from the IAB host, and authenticates the IAB host according to the fourth message. The fourth message may carry at least one of the following information: an electronic serial number (ESN) of the IAB host, a certificate of the IAB host, or a signature of the IAB host on the fourth message.

[0027] That is, after the IAB node sends the third message to the IAB host, the IAB node receives the fourth message from the IAB host, so that the IAB node can authenticate the IAB host according to the fourth message, thereby completing the two-way authentication process between the IAB host and the IAB node.

[0028] In one possible design, after the IAB node receives the second message from the IAB host, the method further includes: the IAB node sends a request message to the IAB host, the request message is used to instruct to obtain the certificate of the IAB node; the IAB node receives the certificate of the IAB node from the IAB host. The signaling transmission involved in the above process can be carried on a signaling radio bearer SRB1; or, it can be carried on a preconfigured data radio bearer DRB.

[0029] In a third aspect, a communication device is provided for implementing the above-mentioned various methods. The communication device may be the IAB host in the above-mentioned first aspect, or a device including the above-mentioned IAB host; or, the communication device may be the IAB node in the above-mentioned second aspect, or a device including the above-mentioned IAB node. The communication device includes a module, unit, or means corresponding to the implementation of the above-mentioned method, and the module, unit, or means may be implemented by hardware, software, or by executing the corresponding software implementation by hardware. The hardware or software includes one or more modules or units corresponding to the above-mentioned functions.

[0030] In a fourth aspect, a communication device is provided, comprising: a processor and a memory; the memory is used to store computer instructions, and when the processor executes the instructions, the communication device executes the method described in any one of the above aspects. The communication device can be the IAB host in the above first aspect or a device including the above IAB host; or the communication device can be the IAB node in the above second aspect or a device including the above IAB node.

[0031] In a fifth aspect, a communication device is provided, comprising: a processor; the processor is coupled to a memory, and after reading instructions in the memory, executes the method as described in any of the above aspects according to the instructions. The communication device may be the IAB host in the above first aspect or a device including the above IAB host; or the communication device may be the IAB node in the above second aspect or a device including the above IAB node.

[0032] In a sixth aspect, a computer-readable storage medium is provided, wherein instructions are stored in the computer-readable storage medium, and when the computer-readable storage medium is run on a computer, the computer can execute the method described in any of the above aspects.

[0033] In a seventh aspect, a computer program product comprising instructions is provided, which, when executed on a computer, enables the computer to execute the method described in any one of the above aspects.

[0034] In an eighth aspect, a communication device is provided (for example, the communication device may be a chip or a chip system), the communication device including a processor for implementing the functions involved in any of the above aspects. In one possible design, the communication device also includes a memory for storing necessary program instructions and data. When the communication device is a chip system, it may be composed of a chip, or may include a chip and other discrete devices.

[0035] Among them, the technical effects brought about by any design method in the third to eighth aspects can refer to the technical effects brought about by different design methods in the above-mentioned first or second aspects, and will not be repeated here.

[0036] According to a ninth aspect, a communication system is provided, the communication system comprising the IAB host described in the above aspect and the IAB node described in the above aspect. BRIEF DESCRIPTION OF THE DRAWINGS

[0037] Figure 1 A structural diagram of an IAB network provided in an embodiment of the present application;

[0038] Figure 2 A flowchart of an IAB node / IAB host applying to a CA for a certificate provided in an embodiment of the present application;

[0039] Figure 3 A schematic diagram of the hardware structure of a communication device provided in an embodiment of the present application;

[0040] Figure 4 A flowchart of an authentication method provided in an embodiment of the present application;

[0041] Figure 5 A flowchart of another authentication method provided in an embodiment of the present application;

[0042] Figure 6 A schematic diagram of an authentication method provided in an embodiment of the present application;

[0043] Figure 7 A schematic diagram of another authentication method provided in an embodiment of the present application;

[0044] Figure 8 A schematic diagram of another authentication method provided in an embodiment of the present application;

[0045] Fig. 9 A schematic diagram of an authentication method provided in an embodiment of the present application;

[0046] Fig.10 A flowchart of another authentication method provided in an embodiment of the present application;

[0047] Fig.11 A flowchart of another authentication method provided in an embodiment of the present application;

[0048] Fig.12 A flowchart of another authentication method provided in an embodiment of the present application;

[0049] Fig.13 A flowchart of another authentication method provided in an embodiment of the present application;

[0050] Fig.14 A flowchart of another authentication method provided in an embodiment of the present application;

[0051] Fig.15A structural diagram of an IAB node provided in an embodiment of the present application;

[0052] Fig.16 A structural diagram of an IAB host provided in an embodiment of the present application. DETAILED DESCRIPTION

[0053] The technical solutions in the embodiments of the present application will be described below in conjunction with the drawings in the embodiments of the present application. Among them, in the description of the present application, unless otherwise specified, " / " indicates that the objects associated before and after are in an "or" relationship, for example, A / B can represent A or B; "and / or" in the present application is only a kind of association relationship describing the associated objects, indicating that there can be three relationships, for example, A and / or B can represent: A exists alone, A and B exist at the same time, and B exists alone, where A and B can be singular or plural. And, in the description of the present application, unless otherwise specified, "multiple" refers to two or more than two. "At least one of the following" or its similar expressions refers to any combination of these items, including any combination of single items or plural items. For example, at least one of a, b, or c can represent: a, b, c, ab, ac, bc, or abc, where a, b, c can be single or multiple. In addition, in order to clearly describe the technical solutions of the embodiments of the present application, in the embodiments of the present application, words such as "first" and "second" are used to distinguish the same items or similar items with substantially the same functions and effects. Those skilled in the art can understand that words such as "first" and "second" do not limit the quantity and execution order, and words such as "first" and "second" do not necessarily limit the difference.

[0054] In addition, the network architecture and business scenarios described in the embodiments of the present application are intended to more clearly illustrate the technical solutions of the embodiments of the present application, and do not constitute a limitation on the technical solutions provided in the embodiments of the present application. Ordinary technicians in this field can know that with the evolution of network architecture and the emergence of new business scenarios, the technical solutions provided in the embodiments of the present application are also applicable to similar technical problems.

[0055] The authentication method provided in the embodiment of the present application can be applied to Figure 1 The communication system 100 shown in FIG. 1 may include an IAB host 20 and an IAB node 30, wherein the IAB host may also be referred to as a host IAB, or an IAB base station, etc., which is not limited in the present application.

[0056] Among them, the IAB node 30 can directly access the IAB host 20, that is, the IAB host is the parent node of the IAB node, and this scenario is called a single-hop access backhaul integration scenario. Alternatively, the IAB node 30 can access the IAB host 20 through other IAB nodes (for example, the IAB node 40), that is, the IAB node is connected to the IAB host through one or more other IAB nodes, and this scenario is called a multi-hop access backhaul integration scenario.

[0057] For example, Figure 1 As shown, the IAB network can adopt a centralized unit-distributed unit (CU-DU) separation architecture, that is, the IAB host 20 is composed of an IAB host DU (referred to as host DU) 21 and an IAB host CU (referred to as host CU) 22. The IAB node 30 is composed of an IAB node DU (referred to as node DU) 31 and an IAB node mobile terminal (mobile terminal, MT) (referred to as node MT) 32. Among them, IAB-MT can also be called IAB-UE, which is not limited in this application.

[0058] The host CU 22 is used to provide control functions and can send control signaling to the IAB node through the host DU 21. The host DU 21 can forward the signaling from the host CU 22 to the IAB node and can also control the signaling from its child nodes (i.e., Figure 1 30 or IAB node 40 or terminal device 50) is backhauled to host CU 22. Node DU 31 is used to provide access services for its child nodes and provide uplink and downlink data transmission between its child nodes and IAB node 30. The child nodes of node DU 31 can be terminal devices 50, or other IAB nodes, etc. Node MT 32 has a function similar to that of a terminal device, and can be used to backhaul data from its child nodes transmitted via node DU 31, for example, in a multi-hop scenario, backhaul the data to IAB node 40, or, in a single-hop scenario, directly backhaul the data to IAB host 20.

[0059] In the authentication method, device and system provided in the embodiment of the present application, when the IAB node enters the network, the IAB host can receive a first message including a first indication information from the IAB node, and the first indication information can indicate that the authentication method supported by the IAB node includes certificate authentication. Thus, the IAB host can determine that the IAB node uses certificate authentication based on the first indication information, and send a second message including a second indication information for indicating that the IAB node uses certificate authentication to the IAB node. In other words, the IAB host can determine that the IAB node uses certificate authentication based on the ability to support certificate authentication reported by the IAB node, and send a second message to the IAB node to instruct the IAB node to use the certificate authentication method for security authentication, so that the IAB node can complete the security authentication when entering the network without configuring a USIM card, reducing the cost of the IAB node, and the authentication process only involves the interaction between the IAB host and the IAB node, without the participation of the core network, reducing the impact on the core network.

[0060] The IAB node accessing the network may include the first access after the IAB node is powered on, or the re-access after the IAB node device is powered off, etc. The embodiment of the present application does not limit the specific scenario of the IAB accessing the network. In addition, the IAB host may be the parent node of the IAB node; or the IAB node may also be connected to the IAB host through one or more other IAB nodes.

[0061] Among them, the IAB node and the IAB host can be devices from the same manufacturer or from different manufacturers. When the IAB node uses the certificate authentication method for security authentication when joining the network, if the IAB node and the IAB host are both devices from the same manufacturer, the IAB node and the IAB host can respectively apply to the manufacturer's certificate authority (CA) to obtain a certificate (or digital certificate). Exemplarily, if the IAB node and the IAB host are both Huawei devices, the IAB node and the IAB host can respectively apply to the Huawei CA for a certificate. As a possibility, the IAB node and the IAB host can respectively apply to the Huawei CA for a certificate when the device leaves the factory. This application does not limit the time when the IAB node and the IAB host apply to the Huawei CA for a certificate.

[0062] For example, the process of the IAB node and the IAB host applying to the CA for a certificate can be as follows: Figure 2As shown. First, the IAB node / IAB host sends a certificate request message to the CA, and the certificate request message may include the identity information of the IAB node / IAB host. Then, the CA may generate a corresponding certificate for the IAB node / IAB host according to the certificate request message from the IAB node / IAB host, and send a certificate response message to the IAB node / IAB host, and the certificate response message includes the certificate generated by the CA for the IAB node / IAB host.

[0063] Exemplarily, the certificate generated by the CA for the IAB node / IAB host may include one or more of the following information:

[0064] (1) The device serial number assigned by the CA to the IAB node / IAB host;

[0065] (2) Information about the organization that issued the certificate, such as Huawei CA information;

[0066] (3) Validity period of the certificate;

[0067] (4) the public key corresponding to the certificate; or

[0068] (5) CA signature (i.e., the CA signs the certificate of the IAB host / IAB node using its own private key).

[0069] It is understandable that the information included in the certificate of the IAB node / IAB host is not limited to the above examples, and the certificate of the IAB node / IAB host may also include other information, which is not limited in this application.

[0070] In addition, the CA may also send the CA's public key information to the IAB node / IAB host. Exemplarily, the CA may carry the CA's public key information in the certificate response message; further exemplary, the CA may also send the CA's public key information to the IAB node / IAB host through other messages. The embodiment of the present application does not limit the manner in which the CA sends the CA's public key information to the IAB node / IAB host.

[0071] When the IAB node and the IAB host are devices from the same manufacturer, the IAB node and the IAB host can obtain their respective certificates from the CA through the above process, so that the IAB node and the IAB host can use the obtained certificates, and the certificate authentication can be completed through the interaction between the IAB node and the IAB host. The entire authentication process is completed on the air interface side without the participation of the core network. Such certificate authentication can also be called private authentication between the IAB node and the IAB host. Compared with the authentication method in the prior art that requires the participation of the core network, it can speed up the IAB node authentication process and shorten the delay of the IAB node network access process.

[0072] For example, the IAB host or IAB node may be Figure 3 This is achieved by the communication equipment (also referred to as communication means) in the communication device. Figure 3 FIG. 3 is a schematic diagram of the hardware structure of a communication device provided in an embodiment of the present application. The communication device 300 includes a processor 301, a communication line 302, a memory 303, and at least one communication interface ( Figure 3 The communication interface 304 is used as an example for illustration only).

[0073] The processor 301 may be a general-purpose central processing unit (CPU), a microprocessor, an application-specific integrated circuit (ASIC), or one or more integrated circuits for controlling the execution of the program of the present application.

[0074] The communication link 302 may include a pathway to transmit information between the above-mentioned components.

[0075] The communication interface 304 uses any transceiver or other device for communicating with other devices or communication networks, such as Ethernet, radio access network (RAN), wireless local area networks (WLAN), etc.

[0076] The memory 303 may be a read-only memory (ROM) or other types of static storage devices that can store static information and instructions, a random access memory (RAM) or other types of dynamic storage devices that can store information and instructions, or an electrically erasable programmable read-only memory (EEPROM), a compact disc read-only memory (CD-ROM) or other optical disc storage, optical disc storage (including compressed optical disc, laser disc, optical disc, digital versatile disc, Blu-ray disc, etc.), a magnetic disk storage medium or other magnetic storage device, or any other medium that can be used to carry or store the desired program code in the form of instructions or data structures and can be accessed by a computer, but is not limited thereto. The memory may exist independently and be connected to the processor via a communication line 302. The memory may also be integrated with the processor.

[0077] The memory 303 is used to store computer-executable instructions for executing the solution of the present application, and the execution is controlled by the processor 301. The processor 301 is used to execute the computer-executable instructions stored in the memory 303, thereby realizing the token acquisition and sending method provided in the following embodiments of the present application.

[0078] Optionally, the computer-executable instructions in the embodiments of the present application may also be referred to as application code, which is not specifically limited in the embodiments of the present application.

[0079] In a specific implementation, as an embodiment, the processor 301 may include one or more CPUs, such as Figure 3 CPU0 and CPU1 in.

[0080] In a specific implementation, as an embodiment, the communication device 300 may include multiple processors, such as Figure 3 301 and processor 308 in the embodiment of the present invention. Each of these processors may be a single-CPU processor or a multi-CPU processor. The processor herein may refer to one or more devices, circuits, and / or processing cores for processing data (e.g., computer program instructions).

[0081] In a specific implementation, as an embodiment, the communication device 300 may also include an output device 305 and an input device 306. The output device 305 communicates with the processor 301 and can display information in a variety of ways. For example, the output device 305 may be a liquid crystal display (LCD), a light emitting diode (LED) display device, a cathode ray tube (CRT) display device, or a projector. The input device 306 communicates with the processor 301 and can receive user input in a variety of ways. For example, the input device 306 may be a mouse, a keyboard, a touch screen device, or a sensor device.

[0082] The communication device 300 may be a general purpose device or a dedicated device. In a specific implementation, the communication device 300 may be a desktop computer, a portable computer, a network server, a personal digital assistant (PDA), a mobile phone, a tablet computer, a wireless terminal device, an embedded device or a computer with a plurality of Figure 3 The embodiment of the present application does not limit the type of the communication device 300.

[0083] For the sake of convenience, the following will take a single-hop scenario as an example. Figures 1 to 3The authentication method provided in the embodiment of the present application is specifically described. It should be noted that in the following method, the IAB node can be replaced by a relay node, the IAB host can be replaced by a host node, the relay node and the host node are connected, and the connection can be a direct connection, for example, through a return link, that is, the host node is the parent node of the relay node; or, the connection can be an indirect connection, for example, through more than two return links, that is, the host node can be connected to the host node through one or more other relay nodes.

[0084] like Figure 4 As shown, an authentication method provided in an embodiment of the present application may include:

[0085] 401. An IAB node sends a first message to an IAB host. The first message includes first indication information. The first indication information is used to indicate an authentication method supported by the IAB node. The authentication method supported by the IAB node includes certificate authentication.

[0086] The IAB host may be the parent node of the IAB node, i.e., the IAB node is directly connected to the IAB host, corresponding to a single-hop scenario; or, the IAB node may be connected to the IAB host through one or more other IAB nodes, i.e., the IAB node accesses the IAB host through other IAB nodes, corresponding to a multi-hop scenario.

[0087] In some implementations, the authentication methods supported by the IAB node may also include at least one of the following authentication methods: 5G-AKA, EAP-AKA' or EAP-transport layer security (EAP-transport layer security, EAP-TLS), etc.

[0088] In some implementations, the first message may be a radio resource control (RRC) connection setup request message (setup request).

[0089] In some other implementations, the first message may be an RRC connection setup complete message (setup complete).

[0090] It is understandable that the first message may also be other types of messages, and the embodiment of the present application does not limit the type of the first message.

[0091] 402. The IAB host determines, according to the first instruction information, that the IAB node uses certificate authentication.

[0092] According to the above, the first message includes first indication information for indicating the authentication method supported by the IAB node, wherein the authentication method supported by the IAB node includes certificate authentication. Therefore, the IAB host can determine that the IAB node can use certificate authentication according to the first indication information in the first message indicating that the authentication method supported by the IAB node includes certificate authentication.

[0093] Wherein, step 402 is an optional step. That is, after step 401, step 403 is directly executed. That is, after the IAB host receives the first message from the IAB node, the IAB host can send a second message to the IAB node in response to the first message.

[0094] 403. The IAB host sends a second message to the IAB node, where the second message includes second instruction information for instructing the IAB node to use certificate authentication.

[0095] If the first message is an RRC connection establishment request message, the second message may be an RRC connection establishment message (setup). If the first message is an RRC connection establishment completion message, the second message may be an RRC message sent by the IAB host to the IAB node after the RRC connection establishment completion message, such as an RRC reconfiguration message, or an SMC (security mode command) message, or a newly defined RRC message.

[0096] In the scheme described in steps 401 to 403, the IAB host can determine that the IAB node uses certificate authentication based on the capability of supporting certificate authentication reported by the IAB node, and send a second message to the IAB node to instruct the IAB node to use certificate authentication for security authentication, so that the IAB node can complete the security authentication when joining the network without configuring a USIM card, thereby reducing the cost of the IAB node, and the authentication process only involves the interaction between the IAB host and the IAB node, without the participation of the core network, reducing the impact on the core network.

[0097] In some embodiments, see Figure 5 Before step 401, the method may further include:

[0098] 501. The IAB host sends a system broadcast message, where the system broadcast message includes third indication information, and the third indication information is used to indicate that the IAB host supports a certificate authentication mode.

[0099] That is, the IAB host may carry the third indication information in the system broadcast message to notify the IAB node that the IAB host supports the certificate authentication method. Exemplarily, the IAB host may send the third indication information through system information block 1 (SIB1). It is understandable that the IAB host may also send the third indication information through other SIBs, and the embodiment of the present application does not limit the form in which the IAB host sends the third indication information.

[0100] In addition, after the IAB host sends the second message to the IAB node to instruct the IAB node to use the certificate authentication mode, that is, after step 403, the method may further include:

[0101] 502. The IAB node sends a third message to the IAB host.

[0102] The third message may carry at least one of the following information: an electronic serial number (ESN) of the IAB node, a certificate of the IAB node, or a signature of the IAB node on the third message. Exemplarily, the third message may also carry a random number generated by the IAB node, which may be used for key derivation after the certificate authentication is passed. It is understandable that the third message may also carry other information associated with the certificate authentication of the IAB node, and the embodiment of the present application does not specifically limit the information carried in the third message.

[0103] If the first message is an RRC connection establishment request message, the third message may be an RRC connection establishment completion message. If the first message is an RRC connection establishment completion message, the third message may be an RRC message sent by the IAB host to the IAB node after the second message, for example, a security mode complete (SMC) message, or a newly defined RRC message.

[0104] According to the above, if the IAB host and the IAB node are devices from the same manufacturer, the IAB host and the IAB node can apply to the CA of the manufacturer for certificates respectively. That is, the certificates of the IAB host and the IAB node come from the certificate issuing server CA of the same manufacturer.

[0105] 503. The IAB host authenticates the IAB node according to the third message.

[0106] The third message may include the certificate of the IAB node and the signature of the IAB node on the third message, the certificate of the IAB node comes from the certificate issuing server CA; the certificate of the IAB node includes the CA signature and the public key of the IAB node, and the IAB host has the CA public key from the CA. Exemplarily, the CA may send the CA public key together with the certificate of the IAB host to the IAB host; further exemplarily, the CA may also send the CA public key of the CA to the IAB host through other messages. The embodiment of the present application does not limit the manner in which the IAB host receives the CA public key from the CA.

[0107] Among them, the way in which the IAB host authenticates the IAB node according to the third message may include at least one of the following ways: verification of the CA signature by the CA public key, verification of the signature of the third message by the public key of the IAB node, consistency verification of the ESN in the third message and the ESN in the certificate of the IAB node, or ESN whitelist verification of the ESN in the third message, etc. The above authentication methods can be used alone or in combination, that is, the IAB host can use one or more of the above authentication methods to authenticate the IAB node according to the third message, and the embodiments of the present application are not limited to this.

[0108] In some implementations, step 503 may include: the IAB host verifies the CA signature included in the certificate of the IAB node using the CA public key.

[0109] That is to say, the IAB host verifies the CA signature using the CA public key; if the IAB host passes the verification of the CA signature using the CA public key, it means that the certificate of the IAB node is legal, the IAB node is a legal node, and the IAB host passes the authentication of the IAB node.

[0110] The CA signature included in the certificate of the IAB node is the signature of the certificate by the CA using the CA private key. For example, the CA signature can be a verification value generated by the CA using the CA private key for the certificate. The IAB host verifies the CA signature using the CA public key, which may include: the IAB host generates another verification value for the certificate of the IAB node using the CA public key; and compares the generated verification value with the CA signature. If the generated verification value is consistent with the CA signature, it means that the verification has passed; if the generated verification value is inconsistent with the CA signature, it means that the verification has failed.

[0111] For example, see Figure 6 The third message may include the certificate of the IAB node, and the certificate of the IAB node includes the CA signature. Figure 6 The sending end shown in FIG. 4 sends the third message to the IAB host (ie, Figure 6After receiving the IAB node, the IAB host can use the CA public key to verify the CA signature. If the verification passes, it means that the certificate is legal, the IAB node is a legal node, and the IAB host succeeds in authenticating the IAB node.

[0112] In some other implementations, step 503 may include: the IAB host verifies the signature of the third message using the public key of the IAB node.

[0113] For example, see Figure 7 , the IAB host verifies the CA signature using the CA public key; if the IAB host passes the verification of the CA signature using the CA public key, the IAB host obtains the public key of the IAB node from the certificate of the IAB node, and uses the public key to verify the signature of the third message.

[0114] That is to say, first, the IAB host verifies the CA signature using the CA public key; if the IAB host passes the verification of the CA signature using the CA public key, it means that the certificate of the IAB node is legal. Then, the IAB host can use the public key of the IAB node contained in the certificate of the IAB node to verify the signature of the third message to verify that the third message has not been tampered with during the transmission process. Among them, the signature of the third message is the signature of the IAB node using the private key of the IAB node on the third message; the private key of the IAB node and the public key of the IAB node are a pair of matching authentication keys. If the IAB host passes the verification of the signature of the third message using the public key contained in the certificate of the IAB node, it means that the received third message has not been tampered with, and then the IAB host performs authentication on the IAB node according to the ESN of the IAB node carried in the third message.

[0115] In some other implementations, the third message may also include an ESN of the IAB node, which may be referred to as ESN1; the certificate of the IAB node may include another ESN, which may be referred to as ESN2. Step 503 may include: the IAB host verifies the consistency of ESN1 with ESN2 included in the certificate of the IAB node.

[0116] For example, see Figure 8 ,exist Figure 7 After the verification of the signature of the third message using the public key of the IAB node is passed, the IAB host can further verify the consistency of ESN1 and ESN2 included in the certificate of the IAB node. If ESN1 is consistent with ESN2, the IAB node is a legal node, and the IAB host succeeds in authenticating the IAB node.

[0117] In some other implementations, the IAB host may also have an ESN whitelist from an operation administration and maintenance (OAM) server, and step 503 may include: the IAB host uses the ESN whitelist to verify the ESN1 of the IAB node included in the third message.

[0118] For example, see Fig. 9 ,exist Figure 7 After the verification of the signature of the third message using the public key of the IAB node is passed, the IAB host can also use the ESN whitelist to verify ESN1 of the IAB node included in the third message. Specifically, the IAB host can verify whether ESN1 is included in the ESN whitelist. If ESN1 is included in the ESN whitelist, the IAB node is a legitimate node, and the IAB host passes the authentication of the IAB node.

[0119] It is understandable that the manner in which the IAB host authenticates the IAB node according to the third message is not limited to the above example, and the IAB host may also authenticate the IAB node in other manners, which is not limited in the embodiment of the present application.

[0120] In some other embodiments, after the IAB host authenticates the IAB node according to the third message, the method may further include:

[0121] 504. The IAB host sends a fourth message to the IAB node.

[0122] The fourth message may carry at least one of the following information: an electronic serial number (ESN) of the IAB host, a certificate of the IAB host, or a signature of the IAB host on the fourth message. Exemplarily, the fourth message may also carry a random number generated by the IAB host, which may be used for key derivation after the certificate authentication is passed. It is understandable that the fourth message may also carry other information associated with the certificate authentication of the IAB host, and the embodiment of the present application does not specifically limit the information carried in the fourth message.

[0123] 505. The IAB node authenticates the IAB host according to the fourth message.

[0124] The way in which the IAB node authenticates the IAB host according to the fourth message may be similar to the way in which the IAB host authenticates the IAB node according to the third message described in step 503. The way in which the IAB node authenticates the IAB host according to the fourth message may include at least one of the following ways: verification of the CA signature by the CA public key, verification of the signature of the fourth message by the public key of the IAB host, consistency verification of the ESN in the fourth message and the ESN in the certificate of the IAB host, or ESN whitelist verification of the ESN in the fourth message, etc. The above authentication methods may be used alone or in combination, that is, the IAB node may use one or more of the above authentication methods to authenticate the IAB host according to the fourth message, and the specific details may refer to the description in step 503, which will not be repeated here.

[0125] That is, after the IAB host successfully authenticates the IAB node according to the third message, the IAB host may further send a fourth message to the IAB node, so that the IAB node may authenticate the IAB host according to the fourth message, thereby completing the two-way authentication process between the IAB host and the IAB node.

[0126] For example, as mentioned above, when the access backhaul integrated network adopts the CU-DU separation architecture, the IAB host may include an IAB host DU and an IAB host CU. The IAB node may include an IAB node MT and an IAB node DU. Fig.10 , the above Figure 4 and Figure 5 The authentication method shown can be performed between the IAB host DU, the IAB host CU and the IAB node MT. Figure 4 and Figure 5 The interaction between the IAB host and the IAB node in the authentication method shown mainly involves the direct interaction between the IAB host DU and the IAB node MT and the message transfer between the IAB host DU and the IAB host CU. That is, Fig.10 The messages transmitted in steps 1005, 1006, 1009, 1011, 1014 and 1016 are respectively the forwarding of the messages in steps 1004, 1007, 1008, 1012, 1013 and 1017.

[0127] Specifically, Fig.10 As shown, another authentication method provided in an embodiment of the present application may include:

[0128] 1001. The IAB host DU sends a system broadcast message. The system broadcast message may include third indication information. The third indication information is used to indicate that the IAB host supports the certificate authentication mode.

[0129] In some implementations, the IAB host supports the certificate authentication mode determined by the IAB host CU. The IAB host CU may send indication information of supporting the certificate authentication mode to the IAB host DU. For example, the IAB host DU and the IAB host CU may be connected via an F1 interface, and therefore, the IAB host CU may send indication information of supporting the certificate authentication mode to the IAB host DU via an F1 connection setup response message.

[0130] In some other implementations, the IAB host supports the certificate authentication mode determined by the IAB host DU. The IAB host DU may send indication information of supporting the certificate authentication mode to the IAB host CU. For example, the IAB host DU may send indication information of supporting the certificate authentication mode to the IAB host CU via an F1 connection setup request message (setup request).

[0131] That is, the IAB host DU may carry the third indication information in the system broadcast message to notify the IAB node MT that the IAB host supports the certificate authentication method. Exemplarily, the IAB host DU may send the third indication information through system information block 1 (SIB1). It is understandable that the IAB host DU may also send the third indication information through other SIBs, and the embodiment of the present application does not limit the form in which the IAB host DU sends the third indication information.

[0132] For example, the system broadcast message may be Figure 5 The system broadcast message described in step 501, that is, step 1001 may correspond to Figure 5 Step 501 in .

[0133] 1002. After receiving the system broadcast message from the IAB host DU, the IAB node MT sends MSG1 to the IAB host DU.

[0134] MSG1 is used for preamble transmission in the random access process. The MSG1 is the first message in the random access process, and may also be referred to as a preamble message, which is described uniformly here and will not be described in detail below.

[0135] 1003. After receiving MSG1, the IAB host DU sends MSG2 to the IAB node MT.

[0136] MSG2 is a random access response message, wherein MSG2 is a response message to the above MSG1.

[0137] like Fig.10As shown, step 1002 and step 1003 together constitute a random access (RA) process. After step 1003, the method may further include:

[0138] 1004. The IAB node MT sends an RRC connection establishment request message (RRC setup request) to the IAB host DU.

[0139] Among them, the RRC connection establishment request message can also be called MSG3.

[0140] 1005. The IAB host DU sends a first F1 application layer protocol (F1application protocol, F1AP) message carrying an RRC connection establishment request message to the IAB host CU.

[0141] That is, after receiving the RRC connection establishment request message from the IAB node MT, the IAB host DU encapsulates the RRC connection establishment request message into a first F1AP message and sends it to the IAB host CU through the F1 interface. The first F1AP message may be an initial UL RRC message transfer message.

[0142] 1006. The IAB host CU sends a second F1AP message carrying an RRC connection establishment message to the IAB host DU in response to the RRC connection establishment request message. The second F1AP message may be a downlink RRC message transfer message (DL RRC MessageTransfer).

[0143] 1007. The IAB host DU sends the RRC connection establishment message to the IAB node MT.

[0144] That is, after receiving the second F1AP message carrying the RRC connection establishment message from the IAB host CU, the IAB host DU may send the RRC connection establishment message to the IAB node MT.

[0145] Among them, the RRC connection establishment message may also be referred to as MSG4. The RRC connection establishment message may include air interface configuration information, so that the IAB node MT can establish an RRC connection according to the air interface configuration information after receiving the RRC connection establishment message. Usually, when establishing an RRC connection, the IAB node will establish a signaling radio bearer 1 (signalling radiobearer 1, SRB1). SRB1 can be used to transmit RRC messages. After SRB1 is established at step 1007, the RRC messages between the IAB node MT and the IAB host DU involved in the steps after step 1007 can all be carried on the SRB1 for transmission.

[0146] 1008. The IAB node MT sends an RRC connection establishment completion message to the IAB host DU. The RRC connection establishment completion message may include the first indication information.

[0147] The RRC connection establishment completion message may also be referred to as MSG5, which is used to notify the IAB host that the RRC connection has been established. The first indication information is used to indicate the authentication method supported by the IAB node, and the authentication method supported by the IAB node includes certificate authentication. The authentication method supported by the IAB node may also include at least one of the following authentication methods: 5G-AKA, EAP-AKA or EAP-TLS, etc. The RRC connection establishment completion message may also include IAB node indication information to indicate that the IAB node is currently accessing the network.

[0148] Exemplarily, the RRC connection establishment complete message may be: Figure 4 The first message described in step 401, that is, step 1008 may correspond to Figure 4 Step 401 in .

[0149] 1009. The IAB host DU sends a third F1AP message carrying an RRC connection establishment completion message to the IAB host CU.

[0150] That is, after receiving the RRC connection establishment completion message from the IAB node MT, the IAB host DU encapsulates the RRC connection establishment completion message in a third F1AP message and sends it to the IAB host CU through the F1 interface. The third F1AP message may be a UL RRC Message Transfer message.

[0151] like Fig.10 As shown, steps 1004 to 1009 together constitute an RRC setup process. After step 1009, the method may further include:

[0152] 1010. The IAB host CU determines that the IAB node uses certificate authentication according to the RRC connection establishment completion message carried in the third F1AP message.

[0153] According to the above, the third F1AP message carries an RRC connection establishment completion message, and the RRC connection establishment completion message includes first indication information for indicating the authentication method supported by the IAB node, wherein the authentication method supported by the IAB node includes certificate authentication. Therefore, the IAB host CU can determine that the IAB node can use certificate authentication according to the first indication information carried in the RRC connection establishment completion message indicating that the authentication method supported by the IAB node includes certificate authentication.

[0154] Exemplarily, step 1010 may correspond to Figure 4 Step 402 in .

[0155] 1011. The IAB host CU sends a fourth F1AP message carrying an RRC message X to the IAB host DU, where the RRC message X includes second indication information for instructing the IAB node to use certificate authentication. The fourth F1AP message may be a DL RRC MessageTransfer message.

[0156] Exemplarily, the RRC message X may be an existing RRC message, such as an RRC reconfiguration message, or a security mode command (SMC) message. Again exemplarily, the RRC message X may also be a newly defined RRC message. In some implementations, the second indication information may be indication information for instructing the IAB node to report a certificate. It is understood that the IAB host CU may also instruct the IAB node to use certificate authentication through other types of second indication information, which is not limited in the embodiments of the present application.

[0157] 1012. The IAB host DU sends an RRC message X to the IAB node MT.

[0158] That is, the IAB host CU carries the information of the IAB node using the certificate for authentication in the RRC message, and sends it to the IAB node MT through the relay of the IAB host DU.

[0159] Exemplarily, the RRC message X may be Figure 4 The second message described in step 403, that is, step 1012 may correspond to Figure 4 Step 403 in .

[0160] 1013. The IAB node MT sends an RRC message Y to the IAB host DU.

[0161] The RRC message Y may be an existing RRC message, such as a security mode complete (SMC) message, or the RRC message Y may be a newly defined RRC message. The type of the RRC message Y is not limited in the embodiment of the present application.

[0162] The RRC message Y may include certificate related information of the IAB node, so that the IAB node MT may report the certificate to the IAB host DU through the RRC message Y.

[0163] Among them, the RRC message Y may carry at least one of the following information: the electronic serial number ESN of the IAB node, the certificate of the IAB node, or the signature of the IAB node on the third message, etc. As another example, the RRC message Y may also carry a random number generated by the IAB node, which may be used for key derivation after the certificate authentication is passed. It is understandable that the RRC message Y may also carry other information associated with the certificate authentication of the IAB node, and the embodiment of the present application does not specifically limit the information carried in the RRC message Y.

[0164] Exemplarily, the RRC message Y may be Figure 5 502 described in step 1013; that is, step 1013 may correspond to Figure 5 Step 502 in .

[0165] 1014. The IAB host DU sends the fifth F1AP message carrying the RRC message Y to the IAB host CU.

[0166] That is, after receiving the RRC message Y from the IAB node MT, the IAB host DU encapsulates the RRC message Y in the fifth F1AP message and sends it to the IAB host CU through the F1 interface. The fifth F1AP message may be a UL RRC MessageTransfer message.

[0167] 1015. The IAB host CU authenticates the IAB node according to the RRC message Y.

[0168] According to the above, the IAB host CU may have a CA public key from the CA. The RRC message Y may include a certificate of the IAB node, and the certificate of the IAB node includes a CA signature.

[0169] In some embodiments, the IAB host CU can verify the CA signature using the CA public key. If the IAB host CU passes the verification of the CA signature using the CA public key, it means that the certificate of the IAB node is legal and the IAB node is a legal node, so the IAB host CU passes the authentication of the IAB node.

[0170] In other embodiments, the IAB host CU uses the CA public key to verify the CA signature; if the IAB host CU passes the verification of the CA signature using the CA public key, it means that the certificate of the IAB node is legal. Then, the IAB host CU can also use the public key contained in the certificate of the IAB node to verify the message signature of the RRC message Y to verify that the RRC message Y has not been tampered with during the transmission process; wherein the message signature of the RRC message Y is the signature of the RRC message Y by the IAB node using the private key of the IAB node. If the IAB host CU passes the verification of the message signature of the RRC message Y using the public key contained in the certificate of the IAB node, it means that the received RRC message Y has not been tampered with, and the IAB host CU further authenticates the IAB node based on the RRC message Y.

[0171] In some other embodiments, the RRC message Y may also include an electronic serial number (ESN) of the IAB node, which may be referred to as ESN1; the certificate of the IAB node may include ESN2. The IAB host CU may verify the consistency of ESN1 and ESN2 included in the certificate of the IAB node. Specifically, the IAB host may verify the consistency of the above ESN1 and ESN2. If ESN1 is consistent with ESN2, the IAB node is a legitimate node, and the IAB host CU passes the authentication of the IAB node.

[0172] In some other embodiments, the IAB host CU also has an ESN whitelist obtained from the CA, and the IAB host CU can use the ESN whitelist to verify ESN1 of the IAB node included in the RRC message Y. Specifically, the IAB host can verify whether ESN1 is included in the ESN whitelist. If ESN1 is included in the ESN whitelist, the IAB node is a legitimate node, and the IAB host CU passes the authentication of the IAB node.

[0173] It is understandable that the way in which the IAB host CU authenticates the IAB node according to the RRC message Y is not limited to the above example, and the IAB host CU may also authenticate the IAB node in other ways. The embodiment of the present application does not limit the way in which the IAB host CU authenticates the IAB node according to the RRC message Y.

[0174] Exemplarily, step 1015 may correspond to Figure 5 Step 503 in .

[0175] After the IAB host CU authenticates the IAB node according to the RRC message Y, the method may further include:

[0176] 1016. The IAB host CU sends the sixth F1AP message carrying the RRC message Z to the IAB host DU.

[0177] The RRC message Z may be an existing RRC message; or, the RRC message Z may also be a newly defined RRC message. The type of the RRC message Z is not limited in the embodiment of the present application.

[0178] RRC message Z includes certificate-related information of the IAB host. Exemplarily, RRC message Z may carry at least one of the following information: the electronic serial number ESN of the IAB host, the certificate of the IAB host, or the signature of the IAB host on the third message, etc. Exemplarily, RRC message Z may also carry a random number generated by the IAB host, which may be used for key derivation after the certificate authentication is passed. It is understandable that RRC message Z may also carry other information associated with the certificate authentication of the IAB host, and the embodiments of the present application do not specifically limit the information carried in RRC message Z.

[0179] Among them, the sixth F1AP message may be a DL RRC Message Transfer message.

[0180] 1017. The IAB host DU sends an RRC message Z to the IAB node MT.

[0181] That is, after receiving the sixth F1AP message carrying the RRC message Z from the IAB host CU, the IAB host CU may send the RRC message Z to the IAB node MT.

[0182] Exemplarily, the RRC message Z may be Figure 5 504 described in step 1017; that is, step 1017 may correspond to Figure 5 Step 504 in .

[0183] 1018. The IAB node MT authenticates the IAB host according to the RRC message Z.

[0184] The manner in which the IAB node MT authenticates the IAB host according to the RRC message Z may be similar to the manner described in step 1015, which will not be described in detail herein.

[0185] Exemplarily, step 1018 may correspond to Figure 5 Step 505 in .

[0186] according to Fig.10It can be seen from the above description that in step 1008, the IAB node MT sends an RRC connection establishment completion message to the IAB host DU, and the RRC connection establishment completion message carries the first indication information that the authentication method supported by the IAB node includes certificate authentication. Then, in step 1010, the IAB host CU determines that the IAB node uses certificate authentication based on the first indication information. And through steps 1011 and 1012, the IAB host CU sends the second indication information for indicating that the IAB node uses certificate authentication to the IAB node MT via the IAB host DU. Afterwards, through steps 1013 and 1014, the IAB node MT sends an RRC message Y carrying certificate-related information to the IAB host CU via the IAB host DU, so that the IAB host CU authenticates the IAB node according to the RRC message Y in step 1015.

[0187] In some embodiments, if the first indication information in step 1008 indicates that the only authentication method supported by the IAB node is certificate authentication, then the authentication method may not be performed. Fig.10 The process in which the IAB host determines the certificate authentication and notifies the IAB node that the determined authentication method is the certificate authentication as shown in steps 1010 to 1012 in the above description, that is, directly executing step 1013 after step 1009. That is, if the first indication information indicates that the only authentication method supported by the IAB node is the certificate authentication, the IAB node does not need to send the RRC message Y including the certificate related information to the IAB host after receiving the second indication information from the IAB host indicating that the IAB node uses the certificate authentication; instead, the IAB node can directly send the RRC message Y including the certificate related information to the IAB host.

[0188] In some other embodiments, Fig.10 In the authentication process in advance, such as Fig.11 As shown, another authentication method provided in an embodiment of the present application may include:

[0189] 1101. The IAB host DU sends a system broadcast message. The system broadcast message may include third indication information. The third indication information is used to indicate that the IAB host supports the certificate authentication mode.

[0190] 1102. After receiving the system broadcast message from the IAB host DU, the IAB node MT sends MSG1 to the IAB host DU.

[0191] 1103. After receiving MSG1, the IAB host DU sends MSG2 to the IAB node MT.

[0192] MSG2 is a random access response message, wherein MSG2 is a response message to the above MSG1.

[0193] Among them, steps 1101 to 1103 correspond to Fig.10 For details of steps 1001 to 1003, see Fig.10 The description is not repeated here.

[0194] 1104. The IAB node MT sends an RRC connection establishment request message (RRC setup request) to the IAB host DU. The RRC connection establishment request message may include first indication information.

[0195] Among them, the RRC connection establishment request message may also be referred to as MSG3. The first indication information is used to indicate the authentication method supported by the IAB node, and the authentication method supported by the IAB node includes certificate authentication. The authentication method supported by the IAB node may also include at least one of the following authentication methods: 5G-AKA, EAP-AKA or EAP-TLS, etc. The RRC connection establishment completion message may also include IAB node indication information to indicate that the IAB node is currently accessing the network.

[0196] Exemplarily, the RRC connection establishment request message may be: Figure 4 401 described in step 1104; that is, step 1104 may correspond to Figure 4 Step 401 in .

[0197] 1105. The IAB host DU sends a first F1AP message carrying an RRC connection establishment request message to the IAB host CU.

[0198] That is, after receiving the RRC connection establishment request message from the IAB node MT, the IAB host DU encapsulates the RRC connection establishment request message in the first F1AP message, and sends it to the IAB host CU through the F1 interface.

[0199] 1106. The IAB host CU determines that the IAB node uses certificate authentication according to the RRC connection establishment request message.

[0200] According to the above, the first F1AP message carries an RRC connection establishment request message, and the RRC connection establishment request message includes first indication information for indicating the authentication method supported by the IAB node, wherein the authentication method supported by the IAB node includes certificate authentication. Therefore, the IAB host CU can determine that the IAB node can use certificate authentication according to the first indication information carried in the RRC connection establishment request message indicating that the authentication method supported by the IAB node includes certificate authentication.

[0201] Exemplarily, step 1106 may correspond to Figure 4 Step 402 in .

[0202] 1107. The IAB host CU sends a second F1AP message carrying an RRC connection establishment message to the IAB host DU in response to the RRC connection establishment request message, where the RRC connection establishment message includes second indication information for instructing the IAB node to use certificate authentication.

[0203] In some implementations, the second indication information may be indication information for instructing the IAB node to report a certificate. It is understandable that the IAB host CU may also instruct the IAB node to use certificate authentication through other types of second indication information, which is not limited in the present embodiment.

[0204] 1108. The IAB host DU sends the RRC connection establishment message to the IAB node MT.

[0205] That is, after receiving the second F1AP message carrying the RRC connection establishment message from the IAB host CU, the IAB host DU may send the RRC connection establishment message to the IAB node MT.

[0206] Among them, the RRC connection establishment message may also be referred to as MSG4. The RRC connection establishment message may include air interface configuration information, so that the IAB node MT can establish an RRC connection according to the air interface configuration information after receiving the RRC connection establishment message. Usually, when establishing an RRC connection, the IAB node will establish SRB1. SRB1 can be used to transmit RRC messages. After SRB1 is established at step 1108, the RRC messages between the IAB node MT and the IAB host DU involved in the steps after step 1108 can be carried on the SRB1 for transmission.

[0207] Exemplarily, the RRC connection establishment message may be: Figure 4 403 described in step 1108; that is, step 1108 may correspond to Figure 4 Step 403 in .

[0208] 1109. The IAB node MT sends an RRC connection establishment completion message to the IAB host DU.

[0209] The RRC connection establishment complete message may also be referred to as MSG5, and is used to notify the IAB host that the RRC connection has been established. The RRC connection establishment complete message may include certificate related information of the IAB node, so that the IAB node MT reports the certificate to the IAB host DU through the RRC connection establishment complete message.

[0210] Among them, the RRC connection establishment completion message may carry at least one of the following information: the electronic serial number ESN of the IAB node, the certificate of the IAB node, or the signature of the IAB node on the third message, etc. As another example, the RRC message Y may also carry a random number generated by the IAB node, which may be used for key derivation after the certificate authentication is passed. It is understandable that the RRC connection establishment completion message may also carry other information associated with the certificate authentication of the IAB node, and the embodiment of the present application does not specifically limit the information carried in the RRC connection establishment completion message.

[0211] Exemplarily, the RRC connection establishment complete message may be: Figure 5 502 described in step 1109; that is, step 1109 may correspond to Figure 5 Step 502 in .

[0212] 1110. The IAB host DU sends a third F1AP message carrying an RRC connection establishment completion message to the IAB host CU.

[0213] That is, after receiving the RRC connection establishment completion message from the IAB node MT, the IAB host DU encapsulates the RRC connection establishment completion message in the third F1AP message, and sends it to the IAB host CU through the F1 interface.

[0214] 1111. The IAB host CU authenticates the IAB node according to the RRC connection establishment completion message.

[0215] The manner in which the IAB host CU authenticates the IAB node according to the RRC connection establishment completion message may be similar to the manner described in step 1015, which will not be repeated here.

[0216] Exemplarily, step 1111 may correspond to Figure 5 Step 503 in .

[0217] 1112. The IAB host CU sends the sixth F1AP message carrying the RRC message Z to the IAB host DU.

[0218] RRC message Z includes certificate-related information of the IAB host. Exemplarily, RRC message Z may carry at least one of the following information: the electronic serial number ESN of the IAB host, the certificate of the IAB host, or the signature of the IAB host on the third message, etc. Exemplarily, RRC message Z may also carry a random number generated by the IAB host, which may be used for key derivation after the certificate authentication is passed. It is understandable that RRC message Z may also carry other information associated with the certificate authentication of the IAB host, and the embodiments of the present application do not specifically limit the information carried in RRC message Z.

[0219] 1113. The IAB host DU sends an RRC message Z to the IAB node MT.

[0220] Exemplarily, the RRC message Z may be Figure 5 ; that is, step 1113 may correspond to Figure 5 Step 504 in .

[0221] 1114. The IAB node MT authenticates the IAB host according to the RRC message Z.

[0222] Exemplarily, step 1114 may correspond to Figure 5 Step 505 in .

[0223] Among them, steps 1112 to 1114 correspond to Fig.10 For details of steps 1016 to 1018, see Fig.10 The description is not repeated here.

[0224] according to Fig.11 It can be seen from the above description that in step 1104, the IAB node MT sends an RRC connection establishment request message (MSG3) to the IAB host DU, and the RRC connection establishment request message carries the first indication information that the authentication method supported by the IAB node includes certificate authentication. Then, in step 1106, the IAB host CU determines that the IAB node uses certificate authentication based on the first indication information. And in steps 1107 and 1108, the IAB host CU sends the second indication information for indicating that the IAB node uses certificate authentication to the IAB node MT via the IAB host DU through the RRC connection establishment message (MSG4). Afterwards, in steps 1109 and 1110, the IAB node MT sends an RRC connection establishment completion message (MSG5) carrying certificate-related information to the IAB host CU via the IAB host DU, so that the IAB host CU authenticates the IAB node according to the RRC connection establishment completion message in step 1111.

[0225] contrast Fig.10 and Fig.11 It is known that in Fig.10 In the illustrated embodiment, after the MSG5 message, the IAB host sends the instruction information for determining that the IAB node uses certificate authentication to the IAB node through the RRC message. Moreover, after the MSG5 message, after the IAB node receives the instruction information for using certificate authentication from the IAB host, the IAB node sends its certificate and other information to the IAB host, and the IAB host completes the authentication of the IAB node.

[0226] And in Fig.11In the embodiment shown, the IAB host sends the instruction information of confirming that the IAB node uses the certificate authentication to the IAB node through the MSG4 message. The IAB node sends its certificate and other information to the IAB host in the MSG5 message. Fig.11 The embodiment shown is compared to Fig.10 In the illustrated embodiment, the IAB authentication process is advanced to the start of the RRC establishment process, thereby further shortening the delay of the IAB node network access process.

[0227] The above embodiment mainly describes that when the IAB node and the IAB host are devices of the same manufacturer, the IAB node and the IAB host can respectively obtain the certificates issued for them from the CA of the manufacturer in advance, so that when the IAB node enters the network, the IAB node and the IAB host use the obtained certificates, and the certificate authentication can be completed through the interaction between the IAB node and the IAB host. The entire authentication process is completed on the air interface side without the participation of the core network.

[0228] However, the IAB node and the IAB host may also be devices of different manufacturers. When the IAB node is switched / reestablished / moved, the IAB node may be connected to the IAB host of a different manufacturer. For example, when the link quality between the IAB node and the IAB host deteriorates and data transmission between the two cannot be guaranteed, the IAB node may switch to another IAB host of a different manufacturer. For another example, when the IAB node is moving, it may move to the coverage area of ​​another IAB host of a different manufacturer, and the IAB node needs to switch to another IAB host of a different manufacturer.

[0229] When the IAB node and the IAB host are devices from different manufacturers, the IAB node and the IAB host cannot obtain certificates through the CA of the same manufacturer, and the solution of the above embodiment may no longer apply. In order to support authentication between devices from different manufacturers, the IAB node and the IAB host need to obtain the certificate issued by the operator from the operator CA. After the IAB node and the IAB host obtain the certificates from the operator CA server respectively, two-way authentication and key negotiation can be performed.

[0230] Specifically, Fig.12 As shown, another authentication method provided in an embodiment of the present application is provided. Fig.12 Can include Fig.11 Steps 1101 to 1108 are shown. After step 1108, the method may further include:

[0231] 1201. The IAB node MT sends an RRC connection establishment completion message to the IAB host DU.

[0232] The RRC connection establishment complete message may also be referred to as MSG5, and is used to notify the IAB host that the RRC connection has been established. The RRC connection establishment complete message may include IAB node indication information to indicate that the IAB node currently accessing the network is.

[0233] After step 1201, the IAB node can obtain the certificate of the IAB node from the operator CA through the core network via the IAB host. For example, the specific process of the IAB node applying for the operator certificate is as follows:

[0234] 1202. The IAB host sends the relevant information of the operator CA to the IAB node. For example, the relevant information of the operator CA may include: CA name and / or CA uniform resource locator (URL), etc. It is understandable that the relevant information of the operator CA may also include other information, which is not limited in the embodiment of the present application.

[0235] 1203. In response to the relevant information of the operator CA, the IAB node sends a certificate management protocol version 2 (CMPV2) initial request message to the IAB host.

[0236] The CMPV2 initial request is used to request the CA obtained in step 1202 to obtain a certificate.

[0237] 1204. The IAB host forwards the CMPV2 initial request to the operator CA through the core network server.

[0238] 1205. In response to the CMPV2 initial request, the operator CA sends a CMPV2 initial response message (initial response) to the IAB host through the core network server.

[0239] The CMPV2 initial response is used to respond to the request message of the IAB node and may include the certificate of the IAB node.

[0240] 1206. The IAB host forwards the CMPV2 initial response to the IAB node.

[0241] 1207. In response to the CMPV2 initial response, the IAB node sends a CMPV2 certification confirm message to the IAB host.

[0242] The CMPV2 certification confirm is used to indicate to the CA that the certificate of the IAB node has been received.

[0243] 1208. The IAB host forwards the CMPV2 certificationconfirm to the operator CA through the core network server.

[0244] 1209. In response to CMPV2 certification confirm, the operator CA sends a CMPV2 public key infrastructure (PKI) confirmation message (confirm) to the IAB host through the core network server.

[0245] The CMPV2 PKI confirm is used to confirm the receipt of the CMPV2 certification confirm message.

[0246] 1210. The IAB host forwards the CMPV2 PKI confirm to the operator CA through the core network server.

[0247] Through step 1202 to step 1210, the IAB node obtains the certificate of the IAB node from the operator CA through the core network server via the IAB host.

[0248] In addition, the IAB host can obtain the certificate of the IAB host from the operator CA in advance. For example, the IAB host can obtain its own certificate from the operator CA when the IAB host accesses the core network. It is understandable that the IAB host can also obtain the certificate of the IAB host from the operator CA in other ways, for example: in the process of the IAB node requesting to obtain a certificate, the IAB host also requests to obtain its own certificate, and the embodiment of the present application is not limited to this. Then, the IAB node and the IAB host can use the obtained certificate to perform two-way authentication and key negotiation. Exemplarily, the IAB node and the IAB host use the obtained certificate to perform two-way authentication and key negotiation through the EAP-TLS process, and the specific process is as follows:

[0249] 1211. The IAB host sends an EAP request (request) TLS start message (start) to the IAB node.

[0250] The EAP request TLS start is used to instruct the IAB node to perform EAP-TLS authentication.

[0251] 1212. In response to EAP request TLS start, the IAB node sends an EAP response client hello message to the IAB host.

[0252] The EAP response client hello message is used to confirm the receipt of the EAP request TLS start message.

[0253] 1213. The IAB host sends an EAP request server hello, certificate, certificate request message to the IAB node.

[0254] The EAP request server hello, certificate, certificate request message is used to request the IAB node to provide certificate information. At the same time, the message also carries the certificate information related to the IAB host so that the IAB node can perform authentication on the IAB host.

[0255] 1214. The IAB node sends an EAP response certificate, client key exchange, change cipher spec, finished message to the IAB host.

[0256] Once the IAB node completes the authentication of the IAB host, the IAB node sends an EAP response certificate, client key exchange, change cipher spec, finished message to the IAB host. The EAP response certificate, client key exchange, change cipher spec, finished message is used for the IAB node to report the certificate information obtained from the operator CA to the IAB host, so that the IAB host can perform authentication on the IAB node.

[0257] 1215. The IAB host sends an EAP request change cipher spec, finished message to the IAB node.

[0258] Once the IAB host completes the authentication of the IAB node, the IAB host sends an EAP request change cipher spec, finished message to the IAB node. The EAP request change cipher spec, finished message is used to indicate that the IAB host has completed the authentication of the IAB node. At the same time, the message also carries information such as the encryption algorithm specified by the IAB host to be used by the IAB node.

[0259] 1216. The IAB node sends an EAP response message (response) to the IAB host.

[0260] The EAP response message is used to respond to the receipt of the EAP request change cipher spec, finished message.

[0261] 1217. In response to the EAP response, the IAB host sends an EAP success message (success) to the IAB node.

[0262] The EAP success message is used to indicate the completion of the EAP-TLS authentication process.

[0263] Through the above steps 1211 to 1217, the IAB node and the IAB host complete the two-way authentication and key negotiation. After this, the IAB host can obtain the capabilities of the IAB node. Exemplarily, the specific process of the IAB host obtaining the capabilities of the IAB node is as follows:

[0264] 1218. The IAB host sends a capability enquiry message (capability enquiry) to the IAB node.

[0265] The capability enquiry message is used to instruct the IAB to report the air interface capability information it supports in an energy-saving manner.

[0266] 1219. In response to the capability enquiry, the IAB node sends capability information (capabilityinformation) to the IAB host.

[0267] The capability information message includes various capability information of the IAB node, such as whether the IAB node supports multi-input multi-output (MIM0) capability, whether it supports dual connection function, security algorithms supported by the IAB node, etc.

[0268] After the IAB host acquires the capabilities of the IAB node, the security mode between the IAB host and the IAB node can be activated. For example, the specific process of activating the security mode between the IAB host and the IAB node is as follows:

[0269] 1220. The IAB host sends a security mode command message (security mode command) to the IAB node.

[0270] The security mode command message is used to indicate the security algorithm used by the IAB node air interface, including: encryption algorithm and integrity protection algorithm.

[0271] 1221. In response to the security mode command, the IAB node sends a security mode complete message (security mode complete) to the IAB host.

[0272] The security mode complete message is used to confirm the receipt of the security mode command message.

[0273] After the key and algorithm negotiation between the IAB host and the IAB node is completed, the IAB node can establish SRB2 and a data radio bearer (DRB). Exemplarily, the specific process of the IAB node establishing SRB2 and DRB can be as follows:

[0274] 1222. The IAB host sends an RRC reconfiguration message (reconfiguration) to the IAB node.

[0275] The RRC reconfiguration message is used to instruct the IAB node to establish corresponding SRB2 and DRB according to the configuration information of the IAB host.

[0276] Among them, SRB2 can be used to transmit non-access stratum (NAS) messages, has a lower priority than SRB1, and is always configured after the security mode is activated. DRB can be used to transmit user plane data.

[0277] 1223. In response to the RRC reconfiguration, the IAB node sends an RRC reconfiguration complete message (reconfiguration complete) to the IAB host.

[0278] The RRC reconfiguration complete message is used to indicate that the RRC reconfiguration is complete and SRB2 and DRB have been established.

[0279] As can be seen from the above, SRB1 is established in step 1108, and the above-mentioned process of applying for operator certificates and the process of two-way authentication and key negotiation occur after the establishment of SRB1 and before the establishment of SRB2 and DRB. Since SRB1 is mainly used to transmit RRC messages, and the messages in the above-mentioned process of applying for operator certificates and the process of two-way authentication and key negotiation are application layer messages, not RRC messages, it is necessary to consider how the messages in the process of applying for operator certificates and the process of two-way authentication and key negotiation are transmitted between the IAB node and the IAB host.

[0280] In a possible implementation, all messages in the above-mentioned operator certificate application process and the two-way authentication and key negotiation process are carried on SRB1 for transmission on the air interface between the IAB node and the IAB host.

[0281] In another possible implementation, all messages in the above-mentioned process of applying for operator certificate and the process of two-way authentication and key negotiation can be transmitted on a default DRB or a pre-configured DRB. The default DRB or pre-configured DRB is pre-established before the process of applying for operator certificate. For example, the IAB host can carry the configuration information of the default DRB in MSG4, and pre-establish an initial DRB according to the configuration information when establishing the RRC connection. Since the default DRB or pre-configured DRB is established before the security mode activation process shown in steps 1220 to 1221, the default DRB or pre-configured DRB has no security protection and is only used to transmit messages in the above-mentioned process of applying for operator certificate and the process of two-way authentication and key negotiation.

[0282] exist Fig.12 In the illustrated embodiment, bidirectional authentication between devices of different manufacturers during access is achieved by obtaining a certificate issued by the operator CA from the operator CA, and there is no need to configure the IAB node with a USIM card, thus saving the cost of the IAB node.

[0283] According to the above, for convenience, Figures 4 to 12 The illustrated embodiments are all described by taking a single-hop scenario where the IAB host is the parent node of the IAB node as an example, and the authentication method provided by the present invention can also be used in a multi-hop scenario where the IAB node is connected to the IAB host through other IAB nodes. In the multi-hop scenario, similar to the single-hop scenario, the IAB host completes the authentication of the IAB node, and the IAB node completes the authentication of the IAB host. The other IAB nodes between the IAB node and the IAB host are only used for routing and forwarding of signaling.

[0284] In summary, therefore, the present application embodiment discloses an authentication method, which is applied to an IAB host, such as Fig.13 As shown, the method may include the following steps 1301 to 1303:

[0285] 1301. An IAB host receives a first message from an IAB node. The first message includes first indication information. The first indication information is used to indicate an authentication method supported by the IAB node. The authentication method supported by the IAB node includes certificate authentication.

[0286] 1302. The IAB host determines, according to the first indication information, that the IAB node uses certificate authentication.

[0287] 1303. The IAB host sends a second message to the IAB node, where the second message includes second instruction information for instructing the IAB node to use certificate authentication.

[0288] The IAB host may be a parent node of the IAB node; or the IAB node may be connected to the IAB host through one or more other IAB nodes.

[0289] In the above authentication method, for example, the operation of the IAB host can refer to Figure 4 The operation of the IAB host in the illustrated embodiment and the above-mentioned related textual descriptions are not repeated here.

[0290] In addition, the present application also discloses an authentication method, which is applied to an IAB node, such as Fig.14 As shown, the method includes the following steps 1401-1402:

[0291] 1401. An IAB node sends a first message to an IAB host. The first message includes first indication information. The first indication information is used to indicate an authentication method supported by the IAB node. The authentication method supported by the IAB node includes certificate authentication.

[0292] 1402. The IAB node receives a second message from the IAB host, where the second message includes second instruction information for instructing the IAB node to use certificate authentication.

[0293] The IAB host may be a parent node of the IAB node; or the IAB node is connected to the IAB host through one or more other IAB nodes.

[0294] In the above authentication method, for example, the operation of the IAB node can refer to Figure 4 The operation of the IAB node in the illustrated embodiment and the above-mentioned related textual descriptions are not repeated here.

[0295] The above mainly introduces the solution provided by the embodiment of the present application from the perspective of the interaction between various network elements. It can be understood that in order to realize the above functions, the above-mentioned IAB node or IAB host includes hardware structures and / or software modules corresponding to the execution of each function. Those skilled in the art should easily realize that, in combination with the units and algorithm steps of each example described in the embodiments disclosed in this document, the present application can be implemented in the form of hardware or a combination of hardware and computer software. Whether a function is executed in the form of hardware or computer software driving hardware depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of this application.

[0296] The embodiment of the present application can divide the IAB node or IAB host into functional modules according to the above method example. For example, each functional module can be divided according to each function, or two or more functions can be integrated into one processing module. The above integrated module can be implemented in the form of hardware or in the form of software functional modules. It should be noted that the division of modules in the embodiment of the present application is schematic and is only a logical functional division. There may be other division methods in actual implementation.

[0297] For example, when the functional modules are divided in an integrated manner, Fig.15 A possible composition diagram of the IAB node 1500 involved in the above embodiment is shown. Fig.15 As shown, the IAB node 1500 may include a processing unit 1501 and a transceiver unit 1502 .

[0298] The processing unit 1501 may be used to support the IAB node 1500 to execute the above step 505 and / or other processes of the technology described herein.

[0299] The transceiver unit 1502 may be used to support the IAB node 1500 to execute step 401 , step 403 , step 501 , step 502 , step 504 , etc., and / or other processes for the technology described herein.

[0300] For example, when the functional modules are divided in an integrated manner, Fig.16 A possible composition diagram of the IAB host 1600 involved in the above embodiment is shown. Fig.16 As shown, the IAB host 1600 may include a processing unit 1601 and a transceiver unit 1602 .

[0301] The processing unit 1601 may be used to support the IAB host 1600 to execute the above steps 402 and 503, etc., and / or other processes of the technology described herein.

[0302] The transceiver unit 1602 may be used to support the IAB host 1600 to execute step 401 , step 403 , step 501 , step 502 , step 504 , etc., and / or other processes for the technology described herein.

[0303] It should be noted that all relevant contents of each step involved in the above method embodiment can be referred to the functional description of the corresponding functional module and will not be repeated here.

[0304] Optionally, an embodiment of the present application further provides an authentication device (for example, the authentication device may be a chip or a chip system), which includes a processor for implementing the method in any of the above method embodiments. In one possible design, the authentication device also includes a memory. The memory is used to store necessary program instructions and data, and the processor can call the program code stored in the memory to instruct the authentication device to execute the method in any of the above method embodiments. Of course, the memory may not be in the authentication device. When the authentication device is a chip system, it may be composed of a chip, or it may include a chip and other discrete devices, which is not specifically limited in the embodiment of the present application.

[0305] In the above embodiments, it can be implemented in whole or in part by software, hardware, firmware or any combination thereof. When implemented using a software program, it can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, the process or function described in the embodiment of the present application is generated in whole or in part. The computer may be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions may be stored in a computer-readable storage medium, or transmitted from one computer-readable storage medium to another computer-readable storage medium, for example, the computer instructions may be transmitted from a website site, computer, server or data center by wired (e.g., coaxial cable, optical fiber, digital subscriber line (digital subscriber line, DSL)) or wireless (e.g., infrared, wireless, microwave, etc.) mode to another website site, computer, server or data center. The computer-readable storage medium may be any available medium that a computer can access or may contain one or more servers, data centers and other data storage devices that can be integrated with the medium. The available medium may be a magnetic medium (eg, a floppy disk, a hard disk, a magnetic tape), an optical medium (eg, a DVD), or a semiconductor medium (eg, a solid state disk (SSD)), etc. In the embodiment of the present application, the computer may include the aforementioned device.

[0306] Although the present application is described herein in conjunction with various embodiments, in the process of implementing the claimed application, those skilled in the art may understand and implement other variations of the disclosed embodiments by viewing the drawings, the disclosure, and the appended claims. In the claims, the word "comprising" does not exclude other components or steps, and "one" or "an" does not exclude multiple situations. A single processor or other unit may implement several functions listed in a claim. Certain measures are recorded in different dependent claims, but this does not mean that these measures cannot be combined to produce good results.

[0307] Although the present application has been described in conjunction with specific features and embodiments thereof, it is obvious that various modifications and combinations may be made thereto without departing from the spirit and scope of the present application. Accordingly, this specification and the drawings are merely exemplary illustrations of the present application as defined by the appended claims, and are deemed to have covered any and all modifications, variations, combinations or equivalents within the scope of the present application. Obviously, those skilled in the art may make various modifications and variations to the present application without departing from the spirit and scope of the present application. Thus, if these modifications and variations of the present application fall within the scope of the claims of the present application and their equivalents, the present application is also intended to include these modifications and variations.

Claims

1. An authentication method, characterized in that: include: The host node receives a first message from the relay node, where the first message includes first indication information, where the first indication information is used to indicate an authentication method supported by the relay node, where the authentication method supported by the relay node includes certificate authentication; The host node sends a second message to the relay node, where the second message includes second indication information for instructing the relay node to use certificate authentication; The host node receives request information from the relay node, the request information is used to instruct to obtain the certificate of the relay node; in response to the request information, the host node obtains the certificate of the relay node from the certificate issuing server CA through the core network; the host node sends the certificate of the relay node to the relay node; The host node receives a third message from the relay node; the third message carries the certificate of the relay node and the signature of the relay node on the third message; The certificate of the relay node comes from the certificate issuing server CA, and the certificate of the relay node includes the CA signature and the public key of the relay node; The host node has a CA public key from the CA; The host node verifies the CA signature using the CA public key; If the host node passes the verification of the CA signature using the CA public key, the host node obtains the public key of the relay node from the certificate of the relay node, and uses the public key of the relay node to verify the signature of the third message; Wherein, the relay node is connected to the host node.

2. The method according to claim 1, characterized in that Before the donor node receives the first message from the relay node, the method further includes: The host node sends a system broadcast message, where the system broadcast message includes third indication information, and the third indication information is used to indicate that the host node supports a certificate authentication method.

3. The method according to claim 1 or 2, characterized in that: The authentication methods supported by the relay node also include at least one of the following authentication methods: 5G-Authentication and Key Agreement AKA, Extensible Authentication Protocol EAP-AKA' or EAP-Transport Layer Security TLS.

4. The method according to claim 1 or 2, characterized in that: The third message also includes the ESN of the relay node, and the host node has an ESN whitelist from the operation administration and maintenance server OAM; The authentication method further comprises: If the host node passes the signature verification of the third message using the public key of the relay node, the host node verifies the consistency between the ESN of the relay node and the ESN included in the certificate of the relay node; or, If the host node passes the signature verification of the third message using the public key of the relay node, the host node verifies the ESN of the relay node using the ESN whitelist.

5. The method according to claim 1 or 2, characterized in that: The first message is a radio resource control RRC connection establishment request message; or, The first message is an RRC connection establishment completion message.

6. An authentication method, characterized in that: include: The access backhaul integrated relay node sends a first message to the host node, where the first message includes first indication information, where the first indication information is used to indicate an authentication method supported by the relay node, where the authentication method supported by the relay node includes certificate authentication; The relay node receives a second message from the host node, where the second message includes second indication information for instructing the relay node to use certificate authentication; The relay node sends a request message to the host node, where the request message is used to instruct to obtain a certificate of the relay node; The relay node receives a certificate of the relay node from the host node; The relay node sends a third message to the host node; the third message carries the certificate of the relay node and the signature of the relay node on the third message; The certificate of the relay node comes from a certificate issuing server CA, and the certificate of the relay node includes a CA signature and a public key of the relay node; The host node has a CA public key from the CA; The third message is used by the host node to authenticate the relay node; The authentication includes: verifying the CA signature using the CA public key, and verifying the signature of the third message using the public key of the relay node; The host node is a parent node of the relay node; or the relay node is connected to the host node through one or more other relay nodes.

7. The method according to claim 6, characterized in that Before the relay node sends the first message to the host node, the method further includes: The relay node receives a system broadcast message from the host node, where the system broadcast message includes third indication information, and the third indication information is used to indicate that the host node supports a certificate authentication method.

8. The method according to claim 6 or 7, characterized in that: The authentication methods supported by the relay node also include at least one of the following authentication methods: 5G-Authentication and Key Agreement AKA, Extensible Authentication Protocol EAP-AKA' or EAP-Extensible Authentication Protocol TLS.

9. The method according to claim 6 or 7, characterized in that: The third message also carries the electronic serial number ESN of the relay node; the host node has an ESN whitelist from the operation administration and maintenance server OAM; The authentication further includes: verifying the consistency of the ESN of the relay node with the ESN included in the certificate of the relay node, or verifying the ESN of the relay node using the ESN whitelist.

10. The method according to claim 6 or 7, characterized in that: The first message is a radio resource control RRC connection establishment request message; or, The first message is an RRC connection establishment completion message.

11. A communication device, characterized in that: include: Processor and memory; The memory is used to store computer instructions. When the processor executes the computer instructions, the communication device executes the method according to any one of claims 1 to 5.

12. A communication device, characterized in that: include: Processor and memory; The memory is used to store computer instructions. When the processor executes the computer instructions, the communication device executes the method according to any one of claims 6 to 10.

13. A communication device, characterized in that: The method comprises means for performing the method as claimed in any one of claims 1 to 5.

14. A communication device, characterized in that: Comprising means for performing the method as claimed in any one of claims 6 to 10.

15. A communication system, characterized in that: It comprises a host node and a relay node, wherein the relay node is connected to the host node, the host node is used to execute the method as described in any one of claims 1-5, and the relay node is used to execute the method as described in any one of claims 6-10.

16. A computer-readable storage medium, characterized in that: The method comprises instructions, which, when executed on a computer, enable the computer to execute the method according to any one of claims 1 to 5, or enable the computer to execute the method according to any one of claims 6 to 10.

17. A computer program product, characterized in that When the computer program product is executed on a computer, the computer is enabled to execute the method according to any one of claims 1 to 5, or the computer is enabled to execute the method according to any one of claims 6 to 10.

Citation Information

Patent Citations

  • Authentication method, re-authentication method and communication device

    CN101640886A

  • Certificate-based authentication

    CN107079007A