Security Authentication Method, Apparatus, Device, and Storage Medium

The sending identifiers and negotiation keys to the terminal device through the core network device solves the problem of secure sending of MBS service information, realizes security authentication between the terminal device and the service docking server, improves the security and correctness of information transmission, and reduces processing overhead.

CN115244892BActive Publication Date: 2025-07-25GUANGDONG OPPO MOBILE TELECOMMUNICATIONS CORP LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202080098244.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2020-04-24
Publication Date
2025-07-25
Estimated Expiration
2040-04-24

AI Technical Summary

Technical Problem

In the prior art, the problem of information security transmission of MBS services has not been effectively solved, especially in LTE and 5GS systems. The GBA mechanism requires additional server BSF, which increases costs and poses security risks.

Method used

The core network device sends identifiers and negotiation keys to the terminal device to ensure secure authentication between the terminal device and the service docking server, avoid leakage of security information of the core network device, and directly use the keys between the terminal device and the core network device for negotiation, reducing processing overhead.

Benefits of technology

It improves the security and correctness of information transmission, saves information transmission resources, avoids security threats from core network equipment, and reduces processing overhead.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115244892B_ABST
    Figure CN115244892B_ABST
Patent Text Reader

Abstract

The present application discloses a security authentication method, apparatus, device and storage medium, belonging to the field of communication technologies. The method includes: a first core network device sends a first identifier to a terminal device, where the first identifier is used to identify the identity of the terminal device between the terminal device and a first server; the terminal device and the first core network device negotiate to determine a first key, where the first key is used for security authentication between the terminal device and the first server. In the embodiments of the present application, by sending an identifier and negotiating a key from the core network device to the terminal device, the security between the terminal device and the server to which the service that the terminal device needs to enable is docked can be guaranteed. Through this identifier, the server for service docking can clarify the information source; the key derived from this key can determine an encryption key to encrypt the information transmitted between the terminal device and the server for service docking, improving the security of the transmitted information.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] Embodiments of the present application relate to the field of communication technologies, and particularly to a security authentication method, apparatus, device, and storage medium. Background Art

[0002] With the rapid development of network communication technologies, people's demands for mobile communications are no longer limited to just telephone and message sending and receiving services, and a large number of multimedia service requirements have continuously emerged.

[0003] Among them, some multimedia services require multiple UEs (User Equipment) to be able to receive the same data simultaneously, such as video on demand, television broadcasting, online education, vehicle-mounted communication, etc. Compared with general data, these multimedia services have characteristics such as large data volume and long duration. In order to effectively utilize mobile network resources and better provide services for UEs, the MBS (Multicast Broadcast Service) service has emerged. The MBS service refers to the wireless network sending the same information content from point to multipoint over the air interface to multiple (i.e., multicast) or all (i.e., broadcast) UEs. It can achieve network resource sharing, improve the utilization rate of network resources, especially air interface resources, and efficiently provide users with high-speed and stable multimedia services.

[0004] However, how to securely send information related to the MBS service to users still needs further discussion and research. Summary of the Invention

[0005] Embodiments of the present application provide a security authentication method, apparatus, device, and storage medium. The technical solutions are as follows:

[0006] On the one hand, embodiments of the present application provide a security authentication method applied to a terminal device. The method includes:

[0007] Receiving a first identifier from a first core network device, where the first identifier is used to identify the identity of the terminal device between the terminal device and a first server, and the first server refers to the server for which the terminal device needs to initiate a first service connection;

[0008] Negotiating with the first core network device to determine a first key, where the first key is used for security authentication between the terminal device and the first server.

[0009] On the other hand, embodiments of the present application provide a security authentication method applied to a first core network device. The method includes:

[0010] Send a first identifier to the terminal device, where the first identifier is used to identify the identity of the terminal device between the terminal device and a first server, and the first server refers to the server for the first service connection that the terminal device needs to initiate;

[0011] Negotiate with the terminal device to determine a first key, where the first key is used for security authentication between the terminal device and the first server.

[0012] In another aspect, an embodiment of the present application provides a security authentication device disposed in a terminal device. The device includes:

[0013] An identifier receiving module, configured to receive a first identifier from a first core network device, where the first identifier is used to identify the identity of the terminal device between the terminal device and a first server, and the first server refers to the server for the first service connection that the terminal device needs to initiate;

[0014] A key determining module, configured to negotiate with the first core network device to determine a first key, where the first key is used for security authentication between the terminal device and the first server.

[0015] In yet another aspect, an embodiment of the present application provides a security authentication device disposed in a first core network device. The device includes:

[0016] An identifier sending module, configured to send a first identifier to the terminal device, where the first identifier is used to identify the identity of the terminal device between the terminal device and a first server, and the first server refers to the server for the first service connection that the terminal device needs to initiate;

[0017] A key determining module, configured to negotiate with the terminal device to determine a first key, where the first key is used for security authentication between the terminal device and the first server.

[0018] In still another aspect, an embodiment of the present application provides a terminal device, which includes: a processor and a transceiver connected to the processor; where:

[0019] The transceiver is configured to receive a first identifier from a first core network device, where the first identifier is used to identify the identity of the terminal device between the terminal device and a first server, and the first server refers to the server for the first service connection that the terminal device needs to initiate;

[0020] The processor is configured to negotiate with the first core network device to determine a first key, where the first key is used for security authentication between the terminal device and the first server.

[0021] On the other hand, an embodiment of the present application provides a core network device, where the core network device includes: a processor and a transceiver connected to the processor; where:

[0022] The transceiver is configured to send a first identifier to a terminal device, where the first identifier is used to identify the identity of the terminal device between the terminal device and a first server, and the first server refers to a server to which the first service that the terminal device needs to enable is docked;

[0023] The processor is configured to negotiate with the terminal device to determine a first key, where the first key is used for security authentication between the terminal device and the first server.

[0024] On the other hand, an embodiment of the present application provides a computer-readable storage medium, where a computer program is stored in the storage medium, and the computer program is configured to be executed by a processor of a terminal device to implement the above-mentioned security authentication method on the terminal device side.

[0025] On the other hand, an embodiment of the present application provides a computer-readable storage medium, where a computer program is stored in the storage medium, and the computer program is configured to be executed by a processor of a core network device to implement the above-mentioned security authentication method on the first core network device side.

[0026] On the other hand, an embodiment of the present application provides a chip, where the chip includes a programmable logic circuit and / or program instructions, and when the chip runs on a terminal device, it is configured to implement the security authentication method on the terminal device side as described above.

[0027] On the other hand, an embodiment of the present application provides a chip, where the chip includes a programmable logic circuit and / or program instructions, and when the chip runs on a core network device, it is configured to implement the security authentication method on the first core network device side as described above.

[0028] The technical solution provided by the embodiment of the present application may include the following beneficial effects:

[0029] By sending an identifier and a negotiation key to a terminal device through a core network device, the security between the terminal device and the server to which the service that the terminal device needs to activate is connected can be ensured. Moreover, since this identifier is used to identify the identity of the terminal device between the terminal device and the server to which the service is connected, the server to which the service is connected can clarify the information source when there is information exchange with the terminal device, and clarify the terminal device with this service requirement, so as to facilitate subsequent sending of service-related information to this terminal device, avoid the server to which the service is connected from sending service-related information to a terminal device without this service requirement, save information transmission resources, and ensure the correctness of information transmission. In addition, since this key is used for security authentication between the terminal device and the server to which the service is connected, the key derived from this key can be used to determine the encryption key between the terminal device and the server to which the service is connected. When there is information exchange between the terminal device and the server to which the service is connected, the terminal device and the server to which the service is connected can encrypt the transmitted information based on this encryption key, improving the security of the transmitted information. BRIEF DESCRIPTION OF THE DRAWINGS

[0030] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the following will briefly introduce the drawings required for description in the embodiments. Obviously, the following-described drawings are only some embodiments of the present application. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.

[0031] Figure 1 is a schematic diagram of the system architecture provided by an embodiment of the present application;

[0032] Figure 2 is a schematic diagram of the LTE system architecture provided by an embodiment of the present application;

[0033] Figure 3 is a schematic diagram of the 5GS system architecture provided by an embodiment of the present application;

[0034] Figure 4 is a schematic diagram of the 5GS system architecture provided by another embodiment of the present application;

[0035] Figure 5 is a flowchart of the negotiation key provided by an embodiment of the present application;

[0036] Figure 6 is a flowchart of the security authentication method provided by an embodiment of the present application;

[0037] Figure 7 is a flowchart of the AKA mechanism provided by an embodiment of the present application;

[0038] Figure 8It is a schematic diagram showing the relationship between the GBA mechanism and the AKA mechanism provided by an embodiment of the present application;

[0039] Figure 9 It is a flowchart showing the integration of the AKA mechanism into the GBA mechanism provided by an embodiment of the present application;

[0040] Figure 10 It is a flowchart showing the GBA mechanism used as secondary authentication provided by an embodiment of the present application;

[0041] Figure 11 It is a flowchart showing the limitation of keys provided by an embodiment of the present application;

[0042] Figure 12 It is a block diagram of a security authentication device provided by an embodiment of the present application;

[0043] Figure 13 It is a block diagram of a security authentication device provided by another embodiment of the present application;

[0044] Figure 14 It is a block diagram of a security authentication device provided by still another embodiment of the present application;

[0045] Figure 15 It is a block diagram of a security authentication device provided by yet another embodiment of the present application;

[0046] Figure 16 It is a structural block diagram of a terminal device provided by an embodiment of the present application;

[0047] Figure 17 It is a structural block diagram of a core network device provided by an embodiment of the present application. Detailed implementation manners

[0048] To make the objectives, technical solutions and advantages of the present application clearer, the following will further describe the embodiments of the present application in detail with reference to the accompanying drawings.

[0049] The network architecture and service scenarios described in the embodiments of the present application are for more clearly illustrating the technical solutions of the embodiments of the present application, and do not constitute a limitation to the technical solutions provided by the embodiments of the present application. Those of ordinary skill in the art can understand that with the evolution of the network architecture and the emergence of new service scenarios, the technical solutions provided by the embodiments of the present application are equally applicable to similar technical problems.

[0050] The technical solutions provided by the embodiments of the present application can be applied to various communication systems, such as: GSM (Global System of Mobile Communication) system, CDMA (Code Division Multiple Access) system, ECDMA (Wideband Code Division Multiple Access) system, GPRS (General Packet Radio Service), LTE (Long Term Evolution) system, FDD (Frequency Division Duplex, LTE frequency division duplex) system, TDD (Time Division Duplex, LTE time division duplex) system, UMTS (Universal Mobile Telecommunication System), WiMAX (Worldwide Interoperability for Microwave Access) communication system, 5GS or New Radio (NR), etc.

[0051] Please refer to Figure 1 , which shows a schematic diagram of the system architecture of a communication system provided by the embodiments of the present application. As Figure 1 shown, the system architecture 100 may include: a terminal device 10, an access network device 20, and a core network device 30.

[0052] The terminal device 10 may refer to a UE, an access terminal, a user unit, a user station, a mobile station, a mobile device, a remote station, a remote terminal, a mobile device, a wireless communication device, a user agent, or a user device. Optionally, the terminal device may also be a cellular phone, a cordless phone, a SIP (Session Initiation Protocol) phone, a WLL (Wireless Local Loop) station, a PDA (Personal Digital Assistant), a handheld device with wireless communication function, a computing device, or other processing devices connected to a wireless modem, a vehicle-mounted device, a wearable device, a terminal device in 5GS, or a terminal device in a future evolved PLMN (Public Land Mobile Network), etc. The embodiments of the present application do not limit this.

[0053] The access network device 20 is a device deployed in the access network to provide wireless communication functions for the terminal device 10. The access network device 20 may include various forms of macro base stations, micro base stations, relay stations, access points, etc. In systems adopting different radio access technologies, the names of the devices with the functions of access network devices may be different. For example, in the 5G NR system, it is called gNodeB or gNB. With the evolution of communication technologies, the name of the "access network device" may change. For the convenience of description, in the embodiments of this application, the above-mentioned device that provides wireless communication functions for the terminal device 10 is collectively referred to as the access network device. Optionally, through the access network device 20, a communication relationship can be established between the terminal device 10 and the core network device 30. Exemplarily, in the LTE system, the access network device 20 may be the EUTRAN (Evolved Universal Terrestrial Radio Access Network) or one or more eNodeBs in the EUTRAN; in the 5GS system, the access network device 20 may be the RAN (Radio Access Network) or one or more gNBs in the RAN.

[0054] The core network device 30 refers to a device that can provide functions such as session management, mobility relationship, policy management, and security authentication for the terminal device 10. In one example, when information needs to be transmitted between the terminal device 10 and the application server, in order to ensure the accuracy of the transmitted information, it is necessary to encrypt the transmitted information, thus introducing the GBA (General Bootstrapping Architecture) mechanism. Through the GBA mechanism, the key Ks between the terminal device and the device carrying the GBA mechanism can be negotiated, and the key Ks is used to derive the key Ks_xx_NAF between the terminal device and the application server. Optionally, the core network device 30 may participate in the negotiation process of the key Ks.

[0055] Among them, the application server refers to the server corresponding to the service that the terminal device needs to establish, such as the server corresponding to the MBS (Multicast Broadcast Service) service. Exemplarily, in the LTE (Long Term Evolution) system, the server corresponding to the MBS service can be the BM-SC; in the 5GS system, the servers corresponding to the MBS service can be the MBSF (Multimedia Broadcast Service Function) and the MBSU (Multimedia Broadcast Service User plane).

[0056] Figure 2 shows a schematic diagram of the system architecture of the LTE system provided by the embodiments of the present application. As Figure 2 shown, the system architecture 200 may include the following network entities:

[0057] 1. EUTRAN: A network composed of multiple eNodeBs (Evolved NodeBs), which implements radio physical layer functions, resource scheduling and radio resource management, radio access control, and mobility management functions. The eNodeBs can be connected through the X2 interface, which can be used to transmit data during the X2-based handover process. The eNodeB is connected to the SGW (Serving Gateway) through the user plane interface SI-U and uses GTP-U (General Packet Radio System General Tunneling Protocol User Plane) to transmit user data; it is connected to the MME (Mobility Management Entity) through the control plane interface SI-E and uses the SI-AP protocol to implement functions such as radio access bearer control.

[0058] 2. MME: It is mainly responsible for all control plane functions of user and session management, including NAS (Non-Access-Stratum) signaling and security, management of the tracking area list (Tracking Area List), selection of the P-GW (Packet Date Network Gateway) and the SGW, etc.

[0059] 3. SGW: It is mainly responsible for data transmission, forwarding, and routing switching of user equipment, and serves as the local mobility anchor point when the user equipment switches between eNodeBs (for each user equipment, there is only one SGW serving it at each moment).

[0060] 4. P-GW: As the anchor point of the PDN (Packet Date Network) connection, it is responsible for IP address allocation of user equipment, data packet filtering, rate control, and generation of charging information for user equipment.

[0061] 5. SGSN (Serving GPR Supporting Node): It is the access node between the 2G access network GERAN (GSM / EDGE Radio Access Network), the 3G access network UTRAN (Universal Terrestrial Radio Access Network), and the EPS core network EPC, and is responsible for the establishment of the bearer from GERAN and UTRAN to EPC and the forwarding of data.

[0062] 6. HSS (Home Subscriber Server): It stores the subscription data of mobile users.

[0063] 7. PCRF (Policy and Charging Rules Function): It is responsible for charging management and policy control, including PCC (Policy and Charging Control) rules and QoS (Quality of Service) rules.

[0064] Figure 3 The schematic diagram of the system architecture of the 5GS system provided by the embodiment of the present application is shown. As Figure 3 shown, the system architecture 300 may include: UE, RAN (Radio Access Network), Core, and DN (Data Network). Among them, UE, RAN, and Core are the main components of the architecture. Logically, they can be divided into two parts: the user plane and the control plane. The control plane is responsible for the management of the mobile network, and the user plane is responsible for the transmission of service data. In the figure, the NG2 reference point is located between the RAN control plane and the Core control plane, the NG3 reference point is located between the RAN user plane and the Core user plane, and the NG6 reference point is located between the Core user plane and the data network.

[0065] UE: It is the entry point for mobile users to interact with the network, capable of providing basic computing and storage capabilities, displaying service windows to users, and accepting user operation inputs. The UE will adopt the next-generation air interface technology to establish signal and data connections with the RAN, thereby transmitting control signals and service data to the mobile network.

[0066] RAN: Similar to the base station in a traditional network, it is deployed close to the UE, provides network access functions for authorized users in a specific area, and can use transmission tunnels of different qualities to transmit user data according to the user level, service requirements, etc. The RAN can manage its own resources, utilize them reasonably, provide access services to the UE on demand, and forward control signals and user data between the UE and the core network.

[0067] Core: Responsible for maintaining the subscription data of the mobile network, managing the network elements of the mobile network, and providing functions such as session management, mobility management, policy management, and security authentication for the UE. When the UE attaches, it provides network access authentication for the UE; when the UE has a service request, it allocates network resources for the UE; when the UE moves, it updates network resources for the UE; when the UE is idle, it provides a fast recovery mechanism: when the UE detaches, it releases network resources for the UE; when the UE has service data, it provides a data routing function for the UE, such as forwarding uplink data to the DN: or receiving UE downlink data from the DN and forwarding it to the RAN, and then sending it to the UE.

[0068] DN: It is a data network that provides service to users. Generally, the client is located at the UE and the server is located in the data network. The data network can be a private network, such as a local area network, or an external network not controlled by the operator, such as the Internet, or a proprietary network jointly deployed by operators, such as for configuring IMS (IP Multimedia Core Network Subsystem) services.

[0069] Figure 4 is at Figure 3The detailed architecture is determined based on this, where the user plane of the core network includes UPF (User Plane Function); the control plane of the core network includes AUSF, AMF, SMF (Session Management Function), NSSF (Network Slice Selection Function), NEF (Network Exposure Function), NRF (NF Repository Function), UDM, PCF (Policy Control Function), and AF (Application Function). The functions of these functional entities are as follows:

[0070] UPF: Forward user data packets according to the routing rules of the SMF;

[0071] AUSF: Perform security authentication of the UE;

[0072] AMF: UE access management and mobility management;

[0073] SMF: UE session management;

[0074] NSSF: Select a network slice for the UE;

[0075] NEF: Open network functions to third parties in the form of northbound API interfaces;

[0076] NRF: Provide storage functions and selection functions for network function entity information for other network elements;

[0077] UDM: User subscription context management;

[0078] PCF: User policy management;

[0079] AF: User application management.

[0080] Optionally, in the 5GS system architecture shown in the embodiments of this application, SEAF (Safety Anchor Function) and AMF are deployed together, and ARPF (Authentication credential Repository and Processing Function) and UDM are deployed together. That is, SEAF is deployed in AMF to perform security-related functions; ARPF is deployed in UDM to perform authentication and management-related functions.

[0081] In Figure 4 In the architecture shown, the N1 interface is the reference point between the UE and the AMF; the N2 interface is the reference point between the RAN and the AMF, used for sending NAS messages, etc.; the N3 interface is the reference point between the RAN and the UPF, used for transmitting user plane data, etc.; the N4 interface is the reference point between the SMF and the UPF, used for transmitting information such as tunnel identification information of the N3 connection, data caching indication information, and downlink data notification messages; the N6 interface is the reference point between the UPF and the DN, used for transmitting user plane data, etc.

[0082] It should be noted that Figure 3 and Figure 4 The interface names between the various network elements in are only examples. In specific implementations, the interface names may be other names, and the embodiments of the present application do not make specific limitations in this regard. Figure 3 and Figure 4 The names of the various network elements (such as UDM, AMF, AUSF, etc.) included in are also only examples and do not limit the functions of the network elements themselves. In 5GS and other future networks, the above-mentioned various network elements may also have other names, and the embodiments of the present application do not make specific limitations in this regard. For example, in a 6G network, some or all of the above-mentioned network elements may continue to use the terms in 5G, or may use other names, etc. A unified description is made here and will not be repeated below. In addition, it should be understood that the names of the messages (or signaling) transmitted between the above-mentioned various network elements are also only examples and do not limit the functions of the messages themselves.

[0083] In the LTE system, the GBA mechanism is jointly completed by the following functional entities: the terminal device, the BSF (Bootstrapping Server Function), and the HSS (Home Subscriber Server). For example, as Figure 5 shown, the process of negotiating the key Ks between the terminal device and the BSF carrying the GBA mechanism through the GBA mechanism may include the following steps:

[0084] Step 510, the terminal device sends an authentication request to the BSF, and the authentication request includes the identity identifier of the terminal device.

[0085] Step 520, the BSF forwards the authentication request to the HSS, and the authentication request includes the identity identifier of the terminal device.

[0086] Step 530, the HSS generates an AV (Authentication Vector) vector and a user key file.

[0087] Step 540, the HSS sends the AV vector and the user key file to the BSF.

[0088] Step 550, the BSF sends the RAND (Random) and AUTN (Authentication Token) in the AV vector to the terminal device.

[0089] Step 560, the terminal device authenticates the identity of the BSF based on the AUTN and calculates the RES (Response) based on the RAND.

[0090] Step 570, the terminal device sends the RES to the BSF.

[0091] Step 580, the BSF authenticates the identity of the terminal device based on the RES. If the authentication is successful, the CK (Encryption Key) and IK (Integrity Key) are concatenated as the key Ks, and this key Ks is used to derive the key Ks_xx_NAF between the terminal device and the application server. Here, the CK and IK are included in the AV vector.

[0092] Step 590, the terminal device concatenates the CK and IK as the key Ks.

[0093] In the above Steps 580 and 590, since the terminal device and the BSF use the same key calculation parameters CK and IK and the same key calculation method, that is, concatenating the CK and IK, the terminal device and the BSF can calculate the same key Ks, thus achieving the purpose of negotiating the key Ks. Subsequently, when the terminal device needs to establish a communication relationship with the application server, the terminal device can initiate a connection establishment request to the application server. After receiving the connection establishment request, the application server obtains the key Ks_xx_NAF derived from the key Ks from the BSF. The application server obtains the key Ks from the BSF and then derives the key Ks_xx_NAF based on the key Ks; the terminal device also derives the key Ks_xx_NAF based on the key Ks, so that the terminal device and the application server perform security authentication based on this key Ks_xx_NAF.

[0094] However, the above GBA mechanism is applied to the LTE system. From Figure 2 and Figure 4From the comparison and description above, it can be seen that the system architectures of the LTE system and the 5GS system are different, and the functional entities they contain are also different. Therefore, the above GBA mechanism cannot be directly applied to the 5GS system. Moreover, since the above GBA mechanism requires the deployment of a separate server BSF, additional costs are incurred to implement the GBA mechanism. Additionally, in the above GBA mechanism, the generation process of the key Ks requires the root keys CK and IK between the terminal device and the core network device to be leaked to the BSF so that the BSF can negotiate the key Ks with the terminal device, which poses a threat to the security of the core network and has security risks.

[0095] Based on this, the embodiments of the present application provide a security authentication method, which can be used to solve the above technical problems.

[0096] By sending an identifier and a negotiation key from the core network device to the terminal device, the security between the terminal device and the server to which the service that the terminal device needs to enable is docked can be guaranteed. Moreover, since this identifier is used to identify the identity of the terminal device between the terminal device and the server to which the service is docked, the server to which the service is docked can clarify the information source when there is information exchange with the terminal device, and clarify the terminal device with this service requirement, so as to facilitate subsequent sending of service-related information to this terminal device, avoiding the server to which the service is docked from sending service-related information to terminal devices without this service requirement, saving information transmission resources and ensuring the correctness of information transmission. Additionally, since this key is used for security authentication between the terminal device and the server to which the service is docked, the key derived from this key can be used to determine the encryption key between the terminal device and the server to which the service is docked. When there is information exchange between the terminal device and the server to which the service is docked, the terminal device and the server to which the service is docked can encrypt the transmitted information based on this encryption key, enhancing the security of the transmitted information.

[0097] Furthermore, for the technical solution provided by the embodiments of the present application, this identifier is different from another identifier used to identify the identity of the terminal device between the terminal device and the core network device. By setting up this identifier different from the other identifier, the leakage of the other identifier to the server to which the service is docked can be avoided, thereby avoiding threatening the security of the core network device and the core network system, and ensuring the security of communication between the terminal device and the core network device while enabling the server to which the service is docked to identify the identity of the terminal device.

[0098] In addition, for the technical solution provided in the embodiment of the present application, by directly using the key for security authentication between the terminal device and the core network device as the key for security authentication between the terminal device and the server for business docking, it is possible to avoid generating multiple keys, avoid multiple negotiations between the terminal device and the core network device for key generation, and reduce the processing overhead of the terminal device and the core network device.

[0099] In addition, for the technical solution provided in the embodiment of the present application, by separately calculating, by the terminal device and the core network device, the key for security authentication between the terminal device and the server for business docking, and this key is different from the key for security authentication between the terminal device and the core network device, it is possible to avoid leaking the root key for deriving the encryption key between the terminal device and the core network device to the server for business docking. Thus, while implementing the security authentication between the terminal device and the server for business docking and ensuring the security of information transmission between the terminal device and the server for business docking, the security of information transmission between the terminal device and the core network device is also ensured.

[0100] Next, several exemplary embodiments will be combined to introduce and illustrate the technical solution of the present application.

[0101] Please refer to Figure 6 , which shows a flowchart of a security authentication method provided in the embodiment of the present application. This method can be applied to Figure 1 , Figure 3 and Figure 4 shown in the system architecture. This method may include the following steps:

[0102] Step 610, the first core network device sends a first identifier to the terminal device, and the first identifier is used to identify the identity of the terminal device between the terminal device and the first server.

[0103] The first core network device may send a first identifier to the terminal device. Optionally, the first identifier may be referred to as B-TID (Bootstrapping Transaction Identification). In the embodiments of the present application, the first core network device is used for access management and mobility management of the terminal device. Optionally, a functional unit for performing security-related functions is deployed in the first core network device, and this functional unit is used to send the first identifier to the terminal device. Exemplarily, in the 5GS system, the first core network device may be an AMF, and a SEAF for performing security-related functions is deployed in the AMF, and the first identifier is sent to the terminal device by the SEAF. The embodiments of the present application do not limit the entity that determines the first identifier. Optionally, the first identifier is determined by the first core network device; or, the first identifier is determined by the functional unit in the first core network for performing security-related functions; or, the first identifier is determined by other functional entities outside the first core network device, and then sent by the other functional entities to the first core network device, and then sent by the first core network device to the terminal device. Exemplarily, in the 5GS system, the first identifier is determined by the SEAF in the AMF and then sent by the SEAF to the terminal device; or, the first identifier is determined by the AUSF, then sent by the AUSF to the SEAF in the AMF, and then sent by the SEAF to the terminal device.

[0104] The first identifier can be used to identify the identity of the terminal device between the terminal device and the first server, and the first server refers to the server to which the first service that the terminal device needs to enable is docked. The embodiments of the present application do not limit the types of the first server and the first service. Optionally, when the first service is an MBS service, the first server may be an MBSF and an MBSU; or, when the first service is other services, such as an emergency service, a multimedia telephone service, etc., the first server is the server docked for these services respectively, such as the server docked for the emergency service, the server docked for the multimedia telephone service, etc.

[0105] By sending the first identifier to the terminal device through the first core network device, when the terminal device performs information transmission or establishes a communication relationship with the first server subsequently, the terminal device can use this first identifier to identify its own identity. Optionally, the first identifier is different from the second identifier used to identify the identity of the terminal device between the terminal device and the core network device. By setting up a first identifier different from the second identifier, it is possible to avoid leaking the second identifier to the first server, thereby avoiding threatening the security of the core network device and the core network system, and ensuring the security of the communication between the terminal device and the core network device while enabling the terminal device to be identified between the terminal device and the first server.

[0106] Step 620: The terminal device negotiates with the first core network device to determine a first key, which is used for security authentication between the terminal device and the first server.

[0107] If security authentication between the terminal device and the first server is to be implemented and the information transmitted between the terminal device and the first server is to be encrypted, then the information needs to be encrypted, and an encryption key is required during the encryption process. In the embodiments of the present application, the terminal device can negotiate with the first core network device to determine the first key, and this first key can be used for security authentication between the terminal device and the first server. Optionally, this first key can be referred to as Ks. Optionally, the above method further includes: the terminal device and / or the first core network device derive a third key according to the first key, and this third key is used for security authentication between the terminal device and the first server. That is to say, the first key is the key between the terminal device and the first core network device, which is used for GBA authentication, and the third key is the key between the terminal device and the first server, which is used for security authentication between the terminal device and the first server. Optionally, this third key can be referred to as Ks_xx_NAF.

[0108] Compared with the case where the first core network device determines the first key and then sends the first key to the terminal device, which may cause leakage during the key transmission process, in the embodiments of the present application, the terminal device negotiates with the first core network device to determine the first key, thereby avoiding leakage during the key transmission process and improving the security of the first key.

[0109] The embodiments of the present application do not limit the specific manner of negotiating and determining the first key. Optionally, the terminal device and the first core network device respectively determine the first key based on the same key generation parameters and key generation algorithm; or, the terminal device and the first core network device determine a certain common key as the first key. Below, the above two ways of generating the first key are introduced and described.

[0110] In one example, the first key is the same as the second key, and this second key is used to derive the encryption key corresponding to the information transmitted between the terminal device and the first core network device. Optionally, the second key is related to the functional entity carrying the GBA mechanism, and different functional entities carrying the GBA mechanism result in different second keys. Exemplarily, in 5GS, when the functional entity carrying the GBA mechanism is implemented as the AMF deployed with SEAF, that is, the second key is referred to as Kseaf; or, when the functional entity carrying the GBA mechanism is implemented as the AUSF, that is, the second key is referred to as Kausf.

[0111] By directly using the second key between the terminal device and the first core network device as the first key between the terminal device and the first server, multiple key generations can be avoided, multiple negotiations on key generation between the terminal device and the first core network device can be avoided, and the processing overheads of the terminal device and the first core network device can be reduced.

[0112] In another example, the terminal device negotiates with the first core network device to determine the first key based on key generation parameters. That is, the terminal device and the core network device calculate and store the first key respectively based on the same key generation parameters and using the same key generation algorithm. Optionally, the key generation parameters include at least one of the following: the second key, RAND, the second identifier, and the key identification parameter. Among them, the second key is used to derive the encryption key corresponding to the information transmitted between the terminal device and the first core network device. Optionally, the second key is related to the functional entity carrying the GBA mechanism. Different functional entities carrying the GBA mechanism result in different second keys. Exemplarily, in 5GS, when the functional entity carrying the GBA mechanism is implemented as the AMF deployed with SEAF, the second key is called Kseaf; or when the functional entity carrying the GBA mechanism is implemented as AUSF, the second key is called Kausf; RAND can be sent by the first core network device to the terminal device during other authentication processes between the first core network device and the terminal device. For example, when the first core network device and the terminal device perform the AKA (Authentication and Key Agreement) authentication mechanism, after receiving the AV vector, the first core network device sends the RAND in the AV vector to the terminal device; the second identifier is used to identify the identity of the terminal device between the terminal device and the first core network device. When the terminal device transmits information to the first core network device, it needs to indicate its own identity. Optionally, the second identifier can be called SUPI (Subscription Permanent Identifier); the key identification parameter is used to identify the first key. Optionally, the key identification parameter can be represented as "5g_gba".

[0113] By calculating the first key different from the second key by the terminal device and the first core network device respectively, the root key used to derive the encryption key between the terminal device and the first core network device can be prevented from being leaked to the first server, thereby ensuring the security of information transmission between the terminal device and the first server while also ensuring the security of information transmission between the terminal device and the first core network device.

[0114] In a possible implementation manner, the above method further includes step 630: The terminal device performs information transmission with the first server based on the first identifier and the first key.

[0115] After receiving the first identifier and the first key, the terminal device can perform information transmission with the first server based on the first identifier and the first key. Exemplarily, the terminal device carries the first identifier in the information transmitted to the first server to identify the identity of the terminal device, and the terminal device uses the key derived from the first key to determine the encryption key to encrypt the information transmitted to the first server. Since the first server also stores the first key or the encryption key derived from the first key, when the first server receives the encrypted information from the terminal device, it can use the key derived from the first key to determine the encryption key to decrypt the encrypted information to obtain the information content. Exemplarily, assume that the first key is the key Ks and the key derived from the first key is the key Ks_xx_NAF. When the first server stores the key Ks, the first server derives the key Ks_xx_NAF using the key Ks, and then uses the key Ks_xx_NAF to determine the encryption key to process the encrypted information; when the first server stores the key Ks_xx_NAF, the first server uses the key Ks_xx_NAF to determine the encryption key to process the encrypted information.

[0116] The embodiments of the present application do not limit the manner and timing of the first server obtaining the first key or the key derived from the first key. Optionally, when the first server receives the information from the terminal device, it sends a key acquisition request to the functional entity carrying the GBA mechanism to obtain the first key or the key derived from the first key; or, when the first server has the need to send information to the terminal device, it sends a key acquisition request to the functional entity carrying the GBA mechanism to obtain the first key or the key derived from the first key, that is, the functional entity carrying the GBA mechanism can either directly send the first key to the first server or send the key derived from the first key to the first server. Exemplarily, in the 5GS system, when the functional entity carrying the GBA mechanism is the AMF deployed with SEAF, the first server sends a key acquisition request to the AMF to obtain the first key or the key derived from the first key, and when the functional entity carrying the GBA mechanism is the AUSF, the first server sends a key acquisition request to the AUSF to obtain the first key or the key derived from the first key.

[0117] It should be noted that the embodiments of the present application do not limit the execution order of steps 610 and 620. Optionally, step 610 is executed before step 620, that is, the first identifier is determined before the first key; or, steps 610 and 620 are executed after, that is, the first identifier is determined after the first key; or steps 610 and 620 are executed simultaneously, that is, the first identifier and the first key are determined simultaneously.Figure 6 For example, only step 610 is executed before step 620, but this does not limit the technical solution of the embodiments of the present application.

[0118] In summary, for the technical solution provided by the embodiments of the present application, by sending an identifier and a negotiation key from the core network device to the terminal device, the security between the terminal device and the server to which the service that the terminal device needs to enable is docked can be guaranteed. Moreover, since this identifier is used to identify the identity of the terminal device between the terminal device and the server to which the service is docked, the server to which the service is docked can clarify the information source when there is information interaction with the terminal device, and clarify the terminal device with this service requirement, so as to facilitate sending information related to this service to the terminal device subsequently, and avoid the server to which the service is docked from sending information related to this service to the terminal device without this service requirement, saving information transmission resources and ensuring the correctness of information transmission. In addition, since this key is used for security authentication between the terminal device and the server to which the service is docked, the key derived from this key can be used to determine the encryption key between the terminal device and the server to which the service is docked. When there is information interaction between the terminal device and the server to which the service is docked, the terminal device and the server to which the service is docked can encrypt the transmitted information based on this encryption key, improving the security of the transmitted information.

[0119] In addition, for the technical solution provided by the embodiments of the present application, this identifier is different from another identifier used to identify the identity of the terminal device between the terminal device and the core network device. By setting up this identifier different from the other identifier, it is possible to avoid leaking the other identifier to the server to which the service is docked, thereby avoiding threatening the security of the core network device and the core network system, and ensuring the security of communication between the terminal device and the core network device while enabling the server to which the service is docked to identify the identity of the terminal device.

[0120] Furthermore, for the technical solution provided by the embodiments of the present application, by directly using the key for security authentication between the terminal device and the core network device as the key for security authentication between the terminal device and the server to which the service is docked, it is possible to avoid generating multiple keys, avoid multiple negotiations between the terminal device and the core network device for key generation, and reduce the processing overhead of the terminal device and the core network device.

[0121] In addition, for the technical solution provided in the embodiments of the present application, the terminal device and the core network device respectively calculate the key for security authentication between the terminal device and the server docked with the service. This key is different from the key for security authentication between the terminal device and the core network device, which can avoid leaking the root key for deriving the encryption key between the terminal device and the core network device to the server docked with the service. Therefore, while realizing the security authentication between the terminal device and the server docked with the service and ensuring the security of information transmission between the terminal device and the server docked with the service, the security of information transmission between the terminal device and the core network device is also ensured.

[0122] In the embodiments of the present application, there are two methods for carrying the GBA mechanism, that is, there are two entities for determining the first identifier. One is to integrate the GBA mechanism with the AKA mechanism, that is, the GBA mechanism is carried by other core network devices outside the first core network device; the other is to use the GBA mechanism as a secondary authentication after the system registration process or the AKA mechanism, that is, the GBA mechanism is carried by the first core network device. The following will introduce and illustrate these two methods for carrying the GBA mechanism through several embodiments.

[0123] First, a brief introduction to the AKA mechanism is given.

[0124] Please refer to Figure 7 , which shows a flowchart of an AKA mechanism provided in the embodiments of the present application. This mechanism may include the following steps:

[0125] Step 701, the UDM generates an AV vector.

[0126] Step 702, the UDM sends a first AKA authentication response to the AUSF; the first AKA authentication response includes the AV vector and the SUPI.

[0127] Step 703, the AUSF stores the XRES; the XRES is included in the AV vector.

[0128] Step 704, the AUSF calculates the HXRES; the AUSF can calculate the HXRES according to the RAND in the AV vector.

[0129] Step 705, the AUSF sends a second AKA authentication response to the SEAF in the AMF; the second AKA authentication response includes the AV vector.

[0130] Step 706, the SEAF in the AMF sends a first identity authentication request to the terminal device; the first identity authentication request includes the RAND and the AUTN.

[0131] Step 707, the terminal device authenticates the identity of the core network according to the AUTN and calculates the identity authentication response RES according to the RAND.

[0132] Step 708, the terminal device sends a first authentication response to the SEAF in the AMF.

[0133] Step 709, the SEAF in the AMF calculates HRES and compares it with HXRES; the SEAF in the AMF can calculate HRES based on the RES in the first authentication response and compare it with HXRES. If they are the same, it is determined that the identity authentication of the terminal device is passed.

[0134] Step 710, the SEAF in the AMF sends a second authentication request to the AUSF; the second authentication request includes the RES of the first authentication response.

[0135] Step 711, the AUSF authenticates the identity of the terminal device according to the RES of the first authentication response.

[0136] Step 712, the AUSF sends a second authentication response to the SEAF in the AMF; the second authentication response includes the authentication result, SUPI, and Kseaf.

[0137] Please refer to Figure 8 , which shows a schematic diagram of the GBA mechanism carried in the 5GS system provided by the embodiments of the present application. It can be seen from Figure 8 that in the 5GS system, the GBA mechanism can either be integrated with the AKA mechanism or be used as a secondary authentication mechanism after the AKA mechanism. It should be noted that these two methods of carrying the GBA mechanism can be combined and used to promote each other. The following introduces and explains these two methods of carrying the GBA mechanism.

[0138] In a possible implementation manner, please refer to Figure 8 , before the above step 610, it further includes: Step 601, the terminal device sends a registration request to the first core network device, and the registration request includes first indication information, where the first indication information is used to indicate that the terminal device needs to enable the first service.

[0139] In the 5GS system, the first core network device can be implemented as an AMF. The terminal device can send a registration request to the AMF to access the core network. In order to enable the core network device to clearly know that the terminal device has a need to activate the first service, the terminal device can carry first indication information in the registration request sent to the first core network device. This first indication information is used to indicate to the core network device that the terminal device has a need to activate the first service, so that the subsequent core network device can implement the GBA mechanism based on this first indication information. Optionally, the terminal device may not carry the first indication information in the registration request, but in the case where the first core network device subsequently exchanges information with other core network devices, the core network device adds the first indication information to the exchanged information, that is, the core network device can determine that the terminal device needs to activate the first service. Exemplarily, as Figure 8 shown, the core network device can carry the first indication information in its stored subscription information or policy information.

[0140] The following introduces and explains the GBA mechanism carried in the AKA mechanism.

[0141] In one example, please refer to Figure 9 , before the above step 610, it further includes: step 910, the second core network device sends an AKA authentication response to the first core network device, and the AKA authentication response includes a first identifier.

[0142] In the embodiments of the present application, the second core network device is the core network device for carrying the GBA mechanism. Exemplarily, in the 5GS system, the second core network device can be an AUSF. In the above Figure 7 shown embodiment, the AMF including the SEAF is the first core network device, and the AUSF is the second core network device. Through Figure 7 the steps 701 to 711 of the embodiment shown, the identity authentication between the terminal device and the second core network device is completed, so step 712 is that the second core network device sends an AKA authentication response to the first core network device to indicate that the AKA authentication mechanism process is completed. In the embodiments of the present application, the Figure 7 step 712 of the AKA authentication mechanism shown is modified to step 910 of the GBA mechanism here. The second core network device still sends an AKA authentication response to the first core network device, but in Figure 9 the embodiment shown, the AKA authentication response includes a first identifier, and this first identifier is used to identify the identity of the terminal device between the terminal device and the first server, thus realizing the integration of the GBA mechanism into the AKA mechanism. Optionally, the AKA authentication response in step 910 may further include an AKA authentication result, a SUPI, and a Kseaf. The embodiments of the present application do not limit this.

[0143] Optionally, as Figure 9 shown, before step 910 above, the method further includes: step 901, the second core network device calculates a first identifier. That is, after the authentication between the second core network device and the terminal device ends, the second core network device can calculate the first identifier to execute the GBA mechanism, and include the first identifier in the AKA authentication response sent to the terminal device.

[0144] Optionally, as Figure 9 shown, before step 610 above, the method further includes: the first core network device encrypts the first identifier with an encryption key derived from a second key, to obtain an encrypted first identifier. That is, after receiving the first identifier from the second core network device, to ensure that the first identifier is securely sent to the terminal device, the first core network device can send the first identifier to the terminal device through a secure channel. That is, the first core network device can encrypt the first identifier. The first core network device can encrypt the first identifier with an encryption key derived from a second key, where the second key is used to derive an encryption key corresponding to information transmitted between the terminal device and the first core network device. The encrypted first identifier can be sent by the first core network device to the terminal device.

[0145] By carrying the GBA mechanism in the AKA mechanism, the authentication result between the terminal device and the core network in the AKA mechanism can be borrowed, avoiding re - executing the authentication between the terminal device and the core network for the GBA mechanism, reducing the processing overhead of the terminal device and the core network device, also avoiding excessive information exchange due to re - executing the authentication, reducing the signaling overhead between the terminal device and the core network device, and saving information transmission resources.

[0146] The following introduces and explains the GBA mechanism as a system registration process or a secondary authentication after the AKA mechanism.

[0147] In one example, please refer to Figure 10 , before step 610 above, the method further includes the following steps:

[0148] Step 1010, the first core network device sends an authentication request to the terminal device, and the authentication request is used to indicate to the terminal device to authenticate the core network.

[0149] In the embodiments of the present application, the first core network device is used to carry the GBA mechanism. Exemplarily, in the 5GS system, the first core network device can be implemented as an AMF deployed with SEAF. Before calculating the first identifier and sending the first identifier to the terminal device, the first core network device needs to perform identity authentication with the terminal device to ensure the identity security of the terminal device and the core network and improve the security of the system. The embodiments of the present application do not limit the content of the identity authentication request. Optionally, the identity authentication request includes AUTN and RAND. The AUTN is used to indicate the identity of the core network, and the RAND is used to determine the identity of the core network and / or the identity authentication response.

[0150] The embodiments of the present application provide three methods for triggering the GBA mechanism, namely triggering by the terminal device, triggering by the first core network device, and triggering by the third core network device. The following describes these three methods for triggering the GBA mechanism.

[0151] Method 1: The GBA mechanism is triggered by the terminal device.

[0152] As Figure 10 shown, before step 1010, the following steps are further included:

[0153] Step 1001: The terminal device sends a GBA authentication request to the first core network device.

[0154] The embodiments of the present application do not limit the content of the GBA authentication request. Optionally, the GBA authentication request includes a second identifier, such as SUPI, which is used to identify the identity of the terminal device between the terminal device and the first core network device.

[0155] Step 1002: In response to receiving the GBA authentication request, the first core network device forwards the GBA authentication request to the third core network device.

[0156] After receiving the GBA authentication request, the first core network device can directly forward the GBA authentication request to the third core network device, or send another GBA authentication request to the third core network device. The content of the another GBA authentication request can be the same as the content of the GBA authentication request. The embodiments of the present application do not limit this.

[0157] Step 1003: The third core network device sends an AV vector to the first core network device.

[0158] The third core network device can be used for subscription management of terminal devices. Exemplarily, in a 5GS system, the third core network device can be implemented as a UDM. After receiving a GBA authentication request, the third core network device can calculate an AV vector. The embodiments of the present application do not limit the specific content included in the AV vector. Optionally, the AV vector includes AUTN and RAND; or, the AV vector further includes XRES. The embodiments of the present application do not limit the calculation method of the AV vector. Optionally, the calculation method of the AV vector is to concatenate the content it includes. For example, when the AV vector includes AUTN, RAND, and XRES, since the content included in the AV vector can be represented in the form of a string, the calculation method of the AV vector is: AV = AUTN||RAND||XRES.

[0159] Method 2: The GBA mechanism is triggered by the first core network device.

[0160] As Figure 10 shown, before the above step 1010, the following steps are further included:

[0161] Step 1004: The first core network device sends a GBA authentication request to the third core network device.

[0162] The embodiments of the present application do not limit the content of the GBA authentication request. Optionally, the GBA authentication request includes a second identifier, such as SUPI, which is used to identify the identity of the terminal device between the terminal device and the first core network device.

[0163] Step 1005: The third core network device sends the AV vector to the second core network device.

[0164] Based on the description of the above step 1003, the description of step 1005 here can be obtained. For the description of step 1005, please refer to the above step 1003 and will not be repeated here.

[0165] Method 3: The GBA mechanism is triggered by the third core network device.

[0166] As Figure 10 shown, before the above step 1010, the following steps are further included:

[0167] Step 1006: The third core network device sends the AV vector to the second core network device.

[0168] Based on the description of the above step 1003, the description of step 1006 here can be obtained. For the description of step 1006, please refer to the above step 1003 and will not be repeated here.

[0169] Step 1020: In response to successful authentication of the first core network device, the terminal device sends an authentication response to the first core network device, and this authentication response is used to indicate to the first core network device that the terminal device has been authenticated.

[0170] After receiving the authentication request from the first core network device, the terminal device can authenticate the first core network device according to the content of this authentication request.

[0171] Optionally, when the authentication request includes RAND and AUTN, as Figure 10 shown, the above step 1020 includes: The terminal device determines the identity of the core network according to RAND and the root key of the terminal device; in response to the identity corresponding to AUTN, it is determined that the core network authentication is successful. After receiving the authentication request from the first core network device, the terminal device can determine the identity of the core network according to RAND and the root key of the terminal device, that is, the terminal device can calculate AUTN according to RAND and the root key, and then the terminal device can compare the calculated AUTN with the AUTN included in the authentication request. If they are the same, it is determined that the core network authentication is successful.

[0172] When the core network authentication is successful, the terminal device can send an authentication response to the first core network device, and this authentication response includes RES. Optionally, when the authentication request includes RAND, the terminal device can calculate RES according to this RAND and the second key, and this second key is used to derive the encryption key corresponding to the information transmitted between the terminal device and the first core network device. After calculating RES, the terminal device sends the authentication response including RES to the first core network device, and this authentication response can be used for the first core network device to authenticate the terminal device.

[0173] Step 1030: In response to successful authentication of the terminal device, the first core network device calculates a first identifier.

[0174] After receiving the authentication response, the first core network device can authenticate the terminal device according to the content of this authentication response.

[0175] Optionally, when the authentication response includes RES and the AV vector includes XRES, the above step 1030 includes: In response to XRES corresponding to RES in the authentication response, it is determined that the terminal device authentication is successful. After receiving the authentication response, the first core network device compares RES with XRES in the AV vector. If they are the same, it is determined that the terminal device authentication is successful and calculates a first identifier.

[0176] In the case where the GBA mechanism is integrated into the AKA mechanism, if the terminal device has a GBA security authentication requirement and starts the GBA mechanism, the AKA mechanism integrated with the GBA mechanism needs to be restarted. Repeatedly executing the AKA mechanism will waste the processing overhead of the terminal device and the core network device. Based on this, the embodiments of the present application provide a secondary authentication mechanism that is executed after the GBA mechanism is used as the AKA mechanism, so that the GBA mechanism and the AKA mechanism can be separated. When the terminal device has a GBA security authentication requirement and starts the GBA mechanism, there is no need to restart the AKA mechanism, saving the processing overhead of the terminal device and the core network device. Moreover, in the embodiments of the present application, the GBA mechanism can be triggered either by the terminal device or by the core network device, providing multiple ways to trigger the GBA mechanism and improving the flexibility of triggering the GBA mechanism.

[0177] In another possible implementation manner, in each of the above embodiments, the information exchanged between the terminal device and the first core network device is a NAS message. For example, in the above embodiment, the GBA authentication request sent by the terminal device to the first core network device in step 1001 belongs to the NAS message.

[0178] In still another possible implementation manner, as Figure 11 shown, the above method further includes: step 1140, the third core network device sends a user key file to the first core network device, and the user key file is used to define the attributes of the first key. Optionally, the user key file includes at least one of the following: the type of the UICC (Universal Integrated Circuit Card) of the terminal device, the key lifetime of the first key, and the candidate timestamp of the first key. Through the user key file, the attributes of the first key, such as the key lifetime, the optional timestamp of the key, and the UICC type of the terminal device corresponding to the key, can be defined.

[0179] It should be noted that the embodiments of the present application do not limit the execution order of step 1140 and steps 610 and 620. Optionally, step 1140 is executed before steps 610 and 620; or, step 1140 is executed after steps 610 and 620; or, step 1140 and steps 610 and 620 are executed simultaneously. In Figure 11 this, only step 1140 being before steps 610 and 620 is taken as an example for illustration, but it does not constitute a limitation to the present application.

[0180] In summary, the technical solution provided by the embodiment of the present application realizes the integration of the GBA mechanism and the AKA mechanism by carrying the first identifier in the AKA authentication response. Since the GBA mechanism is integrated into the AKA mechanism, the GBA mechanism can borrow the identity authentication result between the terminal device and the core network device in the AKA mechanism, avoiding the need to perform the identity authentication between the terminal device and the core network device again for the GBA mechanism, reducing the processing overhead of the terminal device and the core network device, and also avoiding excessive information exchanges caused by performing the identity authentication again, reducing the signaling overhead between the terminal device and the core network device, and saving information transmission resources.

[0181] In addition, the technical solution provided by the embodiment of the present application realizes the secondary authentication after the AKA mechanism by using the GBA mechanism. When the identity authentication between the terminal device and the core network device is passed, the core network device calculates the first identifier and sends the first identifier to the terminal device. By performing the secondary authentication using the GBA mechanism after the AKA mechanism, the GBA mechanism and the AKA mechanism can be separated. When the GBA security authentication requirement is triggered in the terminal device to start the GBA mechanism, it is not necessary to restart the AKA mechanism, saving the processing overhead of the terminal device and the core network device. Moreover, in the embodiment of the present application, the GBA mechanism can be triggered either by the terminal device or by the core network device, providing multiple ways to trigger the GBA mechanism and improving the flexibility of triggering the GBA mechanism.

[0182] It should be noted that in the above method embodiment, the technical solution of the present application is mainly introduced from the perspective of the interaction between the terminal device and the first core network device. The steps performed by the terminal device described above can be separately implemented as a security authentication method on the terminal device side; the steps performed by the first core network device described above can be separately implemented as a security authentication method on the first core network device side.

[0183] The following is the device embodiment of the present application, which can be used to execute the method embodiment of the present application. For the details not disclosed in the device embodiment of the present application, please refer to the method embodiment of the present application.

[0184] Please refer to Figure 12 , which shows a block diagram of a security authentication device provided by an embodiment of the present application. The device has the function of implementing the method example on the terminal device side described above. The function can be implemented by hardware or by hardware executing corresponding software. The device can be the terminal device described above or can be set in the terminal device. As Figure 12 shown, the device 1200 may include: an identifier receiving module 1210 and a key determination module 1220.

[0185] An identifier receiving module 1210, configured to receive a first identifier from a first core network device, where the first identifier is used to identify the identity of the terminal device between the terminal device and a first server, and the first server refers to the server for the first service docking that the terminal device needs to initiate.

[0186] A key determining module 1220, configured to negotiate with the first core network device to determine a first key, where the first key is used for security authentication between the terminal device and the first server.

[0187] In one example, the first identifier is carried in an Authentication and Key Agreement (AKA) authentication response sent by a second core network device to the first core network device, and the second core network device is used to carry a Generic Bootstrapping Architecture (GBA) mechanism.

[0188] In one example, the first core network device is used to carry the GBA mechanism; as Figure 13 shown, the apparatus 1200 further includes: a first request receiving module 1230, configured to receive an identity authentication request from the first core network device, where the identity authentication request is used to indicate to the terminal device to perform identity authentication on the core network; a second response sending module 1240, configured to, in response to the core network identity authentication being passed, send an identity authentication response to the first core network device, where the identity authentication response is used to indicate to the first core network device to perform identity authentication on the terminal device.

[0189] In one example, as Figure 13 shown, the apparatus 1200 further includes: a second request sending module 1250, configured to send a GBA authentication request to the first core network device, where the GBA authentication request includes a second identifier, and the second identifier is used to identify the identity of the terminal device between the terminal device and the first core network device.

[0190] In one example, the identity authentication request includes a random number RAND and an authentication token AUTN, where the RAND is used to determine the identity of the core network and / or the identity authentication response, and the AUTN is used to indicate the identity of the core network.

[0191] In one example, as Figure 13 shown, the apparatus 1200 further includes: an information determining module 1260, configured to determine the identity of the core network according to the RAND and the root key of the terminal device; an authentication passing module 1270, configured to, in response to the identity corresponding to the AUTN, determine that the core network identity authentication is passed.

[0192] In one example, as Figure 13As shown, the device 1200 further includes: a response determination module 1280, configured to determine the authentication response according to the RAND and a second key, where the second key is used to derive an encryption key corresponding to information transmitted between the terminal device and the first core network device.

[0193] In one example, as Figure 13 As shown, the device 1200 further includes: a fourth request sending module 1290, configured to send a registration request to the first core network device, where the registration request includes first indication information, and the first indication information is used to indicate that the terminal device needs to enable the first service.

[0194] In one example, the key determination module 1220 is configured to: negotiate and determine the first key with the first core network device based on key generation parameters, where the key generation parameters include at least one of the following: a second key, RAND, a second identifier, and a key identification parameter; where the second key is used to derive an encryption key corresponding to information transmitted between the terminal device and the first core network device, the second identifier is used to identify the identity of the terminal device between the terminal device and the first core network device, and the key identification parameter is used to identify the first key.

[0195] In one example, the first key is the same as the second key, and the second key is used to derive an encryption key corresponding to information transmitted between the terminal device and the first core network device.

[0196] In one example, as Figure 13 As shown, the device 1200 further includes: a key derivation module 1201, configured to derive a third key according to the first key, where the third key is used for security authentication between the terminal device and the first server.

[0197] In one example, the information exchanged between the terminal device and the first core network device belongs to non-access stratum (NAS) messages.

[0198] In summary, the technical solution provided by the embodiments of the present application can ensure the security between the terminal device and the server to which the service that the terminal device needs to activate is docked by sending an identifier and a negotiation key from the core network device to the terminal device. Moreover, since this identifier is used to identify the identity of the terminal device between the terminal device and the server to which the service is docked, the server to which the service is docked can clarify the information source when there is information interaction with the terminal device, and clarify the terminal device with this service requirement, so as to facilitate sending information related to this service to the terminal device subsequently, avoiding the server to which the service is docked from sending information related to this service to a terminal device without this service requirement, saving information transmission resources, and ensuring the correctness of information transmission. In addition, since this key is used for security authentication between the terminal device and the server to which the service is docked, the key derived from this key can be used to determine the encryption key between the terminal device and the server to which the service is docked. When there is information interaction between the terminal device and the server to which the service is docked, the terminal device and the server to which the service is docked can encrypt the transmitted information based on this encryption key, improving the security of the transmitted information.

[0199] Please refer to Figure 14 , which shows a block diagram of a security authentication device provided by an embodiment of the present application. This device has the function of implementing the method example on the first core network device side described above, and this function can be implemented by hardware or by hardware executing corresponding software. This device can be the first core network device described above or can be arranged in the first core network device. As Figure 14 shown, this device 1400 may include: an identifier sending module 1410 and a key determination module 1420.

[0200] The identifier sending module 1410 is configured to send a first identifier to the terminal device, and the first identifier is used to identify the identity of the terminal device between the terminal device and the first server, and the first server refers to the server to which the first service that the terminal device needs to activate is docked.

[0201] The key determination module 1420 is configured to negotiate and determine a first key with the terminal device, and the first key is used for security authentication between the terminal device and the first server.

[0202] In one example, as Figure 15 shown, the device 1400 further includes: a first response receiving module 1430, configured to receive an AKA authentication response from the second core network device, and the AKA authentication response includes the first identifier, and the second core network device is used to carry the GBA mechanism.

[0203] In one example, as Figure 15As shown, the device 1400 further includes: an identifier acquisition module 1440, configured to encrypt the first identifier with an encryption key derived from a second key to obtain an encrypted first identifier, where the encrypted first identifier is used to be sent to the terminal device, and the second key is used to derive an encryption key corresponding to information transmitted between the terminal device and the first core network device.

[0204] In one example, the first core network device is used to carry the GBA mechanism; as Figure 15 As shown, the device 1400 further includes: a first request sending module 1452, configured to send an authentication request to the terminal device, where the authentication request is used to indicate to the terminal device to authenticate the core network; a second response receiving module 1454, configured to receive an authentication response from the terminal device, where the authentication response is used to indicate to the first core network device to authenticate the terminal device; an identifier determination module 1450, configured to calculate the first identifier in response to the terminal device passing the authentication.

[0205] In one example, as Figure 15 As shown, the device 1400 further includes: a vector receiving module 1460, configured to receive an AV vector from the third core network device, where the AV vector includes RAND and AUTN.

[0206] In one example, as Figure 15 As shown, the device 1400 further includes: a second request receiving module 1472, configured to receive a GBA authentication request from the terminal device, where the GBA authentication request includes a second identifier, and the second identifier is used to identify the identity of the terminal device between the terminal device and the first core network device; a second request forwarding module 1474, configured to forward the GBA authentication request to the third core network device in response to receiving the GBA authentication request.

[0207] In one example, as Figure 15 As shown, the device 1400 further includes: a third request sending module 1476, configured to send a GBA authentication request to the third core network device, where the GBA authentication request includes a second identifier, and the second identifier is used to identify the identity of the terminal device between the terminal device and the first core network device.

[0208] In one example, the authentication request includes RAND and AUTN, where RAND is used to determine the identity of the core network and / or the authentication response, and AUTN is used to indicate the identity of the core network.

[0209] In one example, XRES is further included in the AV vector; as Figure 15 shown, the apparatus 1400 further includes: an authentication passed module 1456, configured to determine that the identity authentication of the terminal device is passed in response to the XRES corresponding to the RES in the identity authentication response.

[0210] In one example, as Figure 15 shown, the apparatus 1400 further includes: a fourth request receiving module 1480, configured to receive a registration request from the terminal device, where the registration request includes first indication information for indicating that the terminal device needs to activate the first service.

[0211] In one example, the key determination module 1420 is configured to: negotiate and determine the first key based on key generation parameters and the terminal device, where the key generation parameters include at least one of the following: a second key, RAND, a second identifier, and a key identification parameter; where the second key is used to derive an encryption key corresponding to information transmitted between the terminal device and the first core network device, the second identifier is used to identify the identity of the terminal device between the terminal device and the first core network device, and the key identification parameter is used to identify the first key.

[0212] In one example, the first key is the same as the second key, and the second key is used to derive an encryption key corresponding to information transmitted between the terminal device and the first core network device.

[0213] In one example, as Figure 15 shown, the apparatus 1400 further includes: a file receiving module 1490, configured to receive a user key file from a third core network device, where the user key file is used to define the attributes of the first key.

[0214] In one example, the user key file includes at least one of the following: the type of the UICC of the terminal device, the key lifetime of the first key, and the candidate timestamp of the first key.

[0215] In one example, as Figure 15 shown, the apparatus 1400 further includes: a key derivation module 1401, configured to derive a third key according to the first key, where the third key is used for security authentication between the terminal device and the first server.

[0216] In one example, the information exchanged between the terminal device and the first core network device belongs to NAS messages.

[0217] In summary, the technical solution provided by the embodiments of the present application can ensure the security between the terminal device and the server to which the service that the terminal device needs to enable is docked by sending an identifier and a negotiation key from the core network device to the terminal device. Moreover, since the identifier is used to identify the identity of the terminal device between the terminal device and the server to which the service is docked, the server to which the service is docked can clarify the information source when there is information exchange with the terminal device, and clarify the terminal device with the service requirement, so as to facilitate subsequent sending of service-related information to the terminal device, avoid the server to which the service is docked from sending service-related information to the terminal device without the service requirement, save information transmission resources, and ensure the correctness of information transmission. In addition, since the key is used for security authentication between the terminal device and the server to which the service is docked, the key derived from the key can be used to determine the encryption key between the terminal device and the server to which the service is docked. When there is information exchange between the terminal device and the server to which the service is docked, the terminal device and the server to which the service is docked can encrypt the transmitted information based on the encryption key, improving the security of the transmitted information.

[0218] It should be noted that when the device provided in the above embodiment realizes its functions, only the division of the above-mentioned various functional modules is used for illustration. In practical applications, the above functions can be allocated to different functional modules according to actual needs, that is, the content structure of the device is divided into different functional modules to complete all or part of the functions described above.

[0219] Regarding the device in the above embodiment, the specific manners in which each module performs operations have been described in detail in the embodiments related to the method, and will not be elaborated herein.

[0220] Please refer to Figure 16 , which shows a schematic structural diagram of a terminal device 160 provided by an embodiment of the present application. For example, the terminal device can be used to execute the security authentication method on the terminal device side. Specifically: The terminal device 160 may include: a processor 161, a receiver 162, a transmitter 163, a memory 164, and a bus 165.

[0221] The processor 161 includes one or more processing cores. The processor 161 executes various functional applications and information processing by running software programs and modules.

[0222] The receiver 162 and the transmitter 163 can be implemented as a transceiver 166, and the transceiver 166 can be a communication chip.

[0223] The memory 164 is connected to the processor 161 through the bus 165.

[0224] The memory 164 can be used to store a computer program, and the processor 161 is used to execute the computer program to implement the various steps performed by the terminal device in the above method embodiments.

[0225] In addition, the memory 164 can be implemented by any type of volatile or non-volatile storage device or a combination thereof. The volatile or non-volatile storage devices include but are not limited to: RAM (Random-Access Memory), ROM (Read-Only Memory), EPROM (Erasable Programmable Read-Only Memory), EEPROM (Electrically Erasable Programmable Read-Only Memory), flash memory or other solid-state storage technologies, CD-ROM (Compact Disc Read-Only Memory), DVD (Digital Video Disc) or other optical storage, cassette tapes, magnetic tapes, disk storage or other magnetic storage devices. Among them:

[0226] The transceiver 166 is used to receive a first identifier from a first core network device. The first identifier is used to identify the identity of the terminal device between the terminal device and a first server, and the first server refers to the server for the first service docking that the terminal device needs to initiate.

[0227] The processor 161 is used to negotiate with the first core network device to determine a first key, and the first key is used for security authentication between the terminal device and the first server.

[0228] In one example, the first identifier is carried in an AKA authentication response sent by a second core network device to the first core network device, and the second core network device is used to carry the GBA mechanism.

[0229] In one example, the first core network device is used to carry the GBA mechanism; the transceiver 166 is further used to receive an identity authentication request from the first core network device, and the identity authentication request is used to indicate to the terminal device to perform identity authentication on the core network; the transceiver 166 is further used to, in response to the core network identity authentication being passed, send an identity authentication response to the first core network device, and the identity authentication response is used to indicate to the first core network device to perform identity authentication on the terminal device.

[0230] In one example, the transceiver 166 is further configured to send a GBA authentication request to the first core network device, where the GBA authentication request includes a second identifier, and the second identifier is used to identify the identity of the terminal device between the terminal device and the first core network device.

[0231] In one example, the identity authentication request includes RAND and AUTN, where RAND is used to determine the identity of the core network and / or the identity authentication response, and AUTN is used to indicate the identity of the core network.

[0232] In one example, the processor 161 is further configured to determine the identity of the core network according to the RAND and the root key of the terminal device; the processor 161 is further configured to determine that the core network identity authentication is passed in response to the identity corresponding to the AUTN.

[0233] In one example, the processor 161 is further configured to determine the identity authentication response according to the RAND and a second key, where the second key is used to derive an encryption key corresponding to the information transmitted between the terminal device and the first core network device.

[0234] In one example, the transceiver 166 is further configured to send a registration request to the first core network device, where the registration request includes first indication information, and the first indication information is used to indicate that the terminal device needs to activate the first service.

[0235] In one example, the processor 161 is configured to negotiate with the first core network device to determine the first key based on key generation parameters, where the key generation parameters include at least one of the following: a second key, RAND, a second identifier, a key identification parameter; where the second key is used to derive an encryption key corresponding to the information transmitted between the terminal device and the first core network device, the second identifier is used to identify the identity of the terminal device between the terminal device and the first core network device, and the key identification parameter is used to identify the first key.

[0236] In one example, the first key is the same as the second key, and the second key is used to derive an encryption key corresponding to the information transmitted between the terminal device and the first core network device.

[0237] In one example, the processor 161 is further configured to derive a third key according to the first key, and the third key is used for security authentication between the terminal device and the first server.

[0238] In one example, the information exchanged between the terminal device and the first core network device belongs to NAS messages.

[0239] Please refer to Figure 17 which shows a schematic structural diagram of the core network device 170 provided in an embodiment of the present application. For example, the core network device can be used to execute the security authentication method on the first core network device side described above. Specifically: The core network device 170 may include: a processor 171, a receiver 172, a transmitter 173, a memory 174, and a bus 175.

[0240] The processor 171 includes one or more processing cores. The processor 171 executes various functional applications and information processing by running software programs and modules.

[0241] The receiver 172 and the transmitter 173 can be implemented as a transceiver 176, and the transceiver 176 can be a communication chip.

[0242] The memory 174 is connected to the processor 171 through the bus 175.

[0243] The memory 174 can be used to store computer programs, and the processor 171 is used to execute the computer programs to implement each step executed by the first core network device in the above method embodiments.

[0244] In addition, the memory 174 can be implemented by any type of volatile or non-volatile storage device or a combination thereof. The volatile or non-volatile storage device includes but is not limited to: RAM and ROM, EPROM, EEPROM, flash memory or other solid-state storage technologies, CD-ROM, DVD or other optical storage, tape cassette, tape, magnetic disk storage or other magnetic storage devices. Among them:

[0245] The transceiver 176 is used to send a first identifier to the terminal device, and the first identifier is used to identify the identity of the terminal device between the terminal device and the first server, and the first server refers to the server for the first service docking that the terminal device needs to initiate.

[0246] The processor 171 is used to negotiate with the terminal device to determine a first key, and the first key is used for security authentication between the terminal device and the first server.

[0247] In one example, the transceiver 176 is further used to receive an AKA authentication response from the second core network device, and the AKA authentication response includes the first identifier, and the second core network device is used to carry the GBA mechanism.

[0248] In one example, the processor 171 is further configured to encrypt the first identifier with an encryption key derived from a second key to obtain an encrypted first identifier, where the encrypted first identifier is used to be sent to the terminal device, and the second key is used to derive an encryption key corresponding to information transmitted between the terminal device and the first core network device.

[0249] In one example, the first core network device is configured to carry the GBA mechanism; the transceiver 176 is further configured to send an authentication request to the terminal device, where the authentication request is used to indicate to the terminal device to authenticate the core network; the transceiver 176 is further configured to receive an authentication response from the terminal device, where the authentication response is used to indicate to the first core network device to authenticate the terminal device; the processor 171 is further configured to calculate the first identifier in response to the terminal device passing the authentication.

[0250] In one example, the transceiver 176 is further configured to receive an AV vector from the third core network device, where the AV vector includes RAND and AUTN.

[0251] In one example, the transceiver 176 is further configured to receive a GBA authentication request from the terminal device, where the GBA authentication request includes a second identifier, and the second identifier is used to identify the identity of the terminal device between the terminal device and the first core network device; the transceiver 176 is further configured to forward the GBA authentication request to the third core network device in response to receiving the GBA authentication request.

[0252] In one example, the transceiver is further configured to send a GBA authentication request to the third core network device, where the GBA authentication request includes a second identifier, and the second identifier is used to identify the identity of the terminal device between the terminal device and the first core network device.

[0253] In one example, the authentication request includes RAND and AUTN, where RAND is used to determine the identity of the core network and / or the authentication response, and AUTN is used to indicate the identity of the core network.

[0254] In one example, the processor 171 is further configured to determine that the terminal device passes the authentication in response to the XRES corresponding to the RES in the authentication response.

[0255] In one example, the transceiver 176 is further configured to receive a registration request from the terminal device, where the registration request includes first indication information, and the first indication information is used to indicate that the terminal device needs to enable the first service.

[0256] In one example, the processor 171 is configured to negotiate and determine the first key with the terminal device based on key generation parameters, where the key generation parameters include at least one of the following: a second key, RAND, a second identifier, and a key identification parameter; wherein, the second key is used to derive an encryption key corresponding to information transmitted between the terminal device and the first core network device, the second identifier is used to identify the identity of the terminal device between the terminal device and the first core network device, and the key identification parameter is used to identify the first key.

[0257] In one example, the first key is the same as the second key, and the second key is used to derive an encryption key corresponding to information transmitted between the terminal device and the first core network device.

[0258] In one example, the transceiver 176 is further configured to receive a user key file from a third core network device, where the user key file is used to define the attributes of the first key.

[0259] In one example, the user key file includes at least one of the following: the type of the UICC of the terminal device, the key lifetime of the first key, and the candidate timestamp of the first key.

[0260] In one example, the processor 171 is further configured to derive a third key according to the first key, where the third key is used for security authentication between the terminal device and the first server.

[0261] In one example, the information exchanged between the terminal device and the first core network device belongs to NAS messages.

[0262] The embodiment of the present application further provides a computer-readable storage medium, in which a computer program is stored, and the computer program is used to be executed by a processor of a terminal device to implement the above-mentioned security authentication method on the terminal device side.

[0263] The embodiment of the present application further provides a computer-readable storage medium, in which a computer program is stored, and the computer program is used to be executed by a processor of a core network device to implement the above-mentioned security authentication method on the first core network device side.

[0264] The embodiment of the present application further provides a chip, which includes programmable logic circuits and / or program instructions, and when the chip runs on a terminal device, it is used to implement the security authentication method on the terminal device side as described above.

[0265] The embodiments of the present application further provide a chip, which includes a programmable logic circuit and / or program instructions, and is used to implement the security authentication method on the first core network device side as described above when the chip runs on a core network device.

[0266] The present application also provides a computer program product, which causes a computer to execute the security authentication method on the terminal device side when the computer program product runs on a terminal device.

[0267] The present application also provides a computer program product, which causes a computer to execute the security authentication method on the first core network device side when the computer program product runs on a core network device.

[0268] Those skilled in the art should be able to realize that in one or more of the above examples, the functions described in the embodiments of the present application can be implemented by hardware, software, firmware, or any combination thereof. When implemented using software, these functions can be stored in a computer-readable medium or transmitted as one or more instructions or codes on a computer-readable medium. The computer-readable medium includes computer storage media and communication media, where the communication media includes any medium that facilitates the transfer of a computer program from one place to another. The storage media can be any available medium accessible by a general-purpose or special-purpose computer.

[0269] The above are only exemplary embodiments of the present application, and are not intended to limit the present application. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principle of the present application shall be included in the protection scope of the present application.

Claims

1. A security authentication method, characterized in that, Applied to a terminal device, the method includes: Receiving a first identifier from a first core network device, where the first identifier is used to identify the identity of the terminal device between the terminal device and a first server, and the first server refers to the server for the first service docking that the terminal device needs to initiate, and the first core network device is the Access and Mobility Management Function (AMF); Negotiating with the first core network device to determine a first key, where the first key is used for security authentication between the terminal device and the first server, wherein, negotiating with the first core network device to determine a first key includes: Negotiating with the first core network device to determine the first key based on key generation parameters, where the key generation parameters include at least one of the following: a second key, a random number RAND, a second identifier, and a key identification parameter; wherein, the second key is used to derive the encryption key corresponding to the information transmitted between the terminal device and the first core network device, the second identifier is used to identify the identity of the terminal device between the terminal device and the first core network device, and the key identification parameter is used to identify the first key.

2. The method according to claim 1, wherein The first identifier is carried in the Authentication and Key Agreement (AKA) authentication response sent by a second core network device to the first core network device, and the second core network device is used to carry the Generic Bootstrapping Architecture (GBA) mechanism.

3. The method according to claim 1, wherein The first core network device is used to carry the GBA mechanism; before receiving the first identifier from the first core network device, it further includes: Receiving an identity authentication request from the first core network device, where the identity authentication request is used to indicate to the terminal device to authenticate the core network; Responding to the successful core network identity authentication, sending an identity authentication response to the first core network device, where the identity authentication response is used to indicate to the first core network device to authenticate the terminal device.

4. The method according to claim 3, characterized in that, Before receiving the identity authentication request from the first core network device, it further includes: Sending a GBA authentication request to the first core network device, where the GBA authentication request includes a second identifier, and the second identifier is used to identify the identity of the terminal device between the terminal device and the first core network device.

5. The method according to claim 3, wherein The identity authentication request includes a random number RAND and an authentication token AUTN, where the RAND is used to determine the identity of the core network and / or the identity authentication response, and the AUTN is used to indicate the identity of the core network.

6. The method according to claim 5, characterized in that The method further includes: Determining the identity of the core network according to the RAND and the root key of the terminal device; Responding to the identity corresponding to the AUTN, determining that the core network identity authentication is successful.

7. The method according to claim 5, wherein The method further includes: Determining the identity authentication response according to the RAND and the second key, where the second key is used to derive the encryption key corresponding to the information transmitted between the terminal device and the first core network device.

8. The method according to any one of claims 1 to 7, characterized in that, Before receiving the first identifier from the first core network device, it further includes: Send a registration request to the first core network device, where the registration request includes first indication information for indicating that the terminal device needs to enable the first service.

9. The method according to any one of claims 1 to 7, characterized in that, The method further includes: Derive a third key according to the first key, where the third key is used for security authentication between the terminal device and the first server.

10. The method according to any one of claims 1 to 7, characterized in that, The information exchanged between the terminal device and the first core network device belongs to non-access stratum (NAS) messages.

11. A security authentication method, characterized in that, Applied to a first core network device, where the first core network device is an access and mobility management function (AMF), the method includes: Send a first identifier to the terminal device, where the first identifier is used to identify the identity of the terminal device between the terminal device and the first server, and the first server is the server to which the first service that the terminal device needs to enable is docked; Negotiate with the terminal device to determine a first key, where the first key is used for security authentication between the terminal device and the first server, where negotiating with the terminal device to determine the first key includes: Negotiate with the terminal device to determine the first key based on key generation parameters, where the key generation parameters include at least one of the following: a second key, a random number RAND, a second identifier, and a key identification parameter; where the second key is used to derive the encryption key corresponding to the information transmitted between the terminal device and the first core network device, the second identifier is used to identify the identity of the terminal device between the terminal device and the first core network device, and the key identification parameter is used to identify the first key.

12. The method according to claim 11, wherein Before sending the first identifier to the terminal device, it further includes: Receive an authentication and key agreement (AKA) authentication response from a second core network device, where the AKA authentication response includes the first identifier, and the second core network device is used to carry the generic bootstrapping architecture (GBA) mechanism.

13. The method according to claim 12, wherein Before sending the first identifier to the terminal device, it further includes: Encrypt the first identifier with the encryption key derived from the second key to obtain an encrypted first identifier for sending to the terminal device, and the second key is used to derive the encryption key corresponding to the information transmitted between the terminal device and the first core network device.

14. The method according to claim 11, wherein The first core network device is used to carry the GBA mechanism; before sending the first identifier to the terminal device, it further includes: Send an identity authentication request to the terminal device, where the identity authentication request is used to indicate to the terminal device to perform identity authentication on the core network; Receive an identity authentication response from the terminal device, where the identity authentication response is used to indicate to the first core network device to perform identity authentication on the terminal device; In response to the terminal device's successful identity authentication, calculate the first identifier.

15. The method according to claim 14, wherein Before sending the identity authentication request to the terminal device, it further includes: Receive an authentication vector (AV) from a third core network device, where the AV includes a random number RAND and an authentication token AUTN.

16. The method according to claim 15, characterized in that Before receiving the AV from the third core network device, it further includes: Receive a GBA authentication request from the terminal device, where the GBA authentication request includes a second identifier for identifying the identity of the terminal device between the terminal device and the first core network device; In response to receiving the GBA authentication request, forward the GBA authentication request to a third core network device.

17. The method according to claim 15, wherein Before receiving the AV vector from the third core network device, further include: Send a GBA authentication request to the third core network device, where the GBA authentication request includes a second identifier for identifying the identity of the terminal device between the terminal device and the first core network device.

18. The method according to claim 15, wherein The identity authentication request includes RAND and AUTN, where RAND is used to determine the identity of the core network and / or the identity authentication response, and AUTN is used to indicate the identity of the core network.

19. The method according to claim 15, characterized in that, The AV vector further includes XRES; after receiving the identity authentication response from the terminal device, further include: In response to XRES corresponding to RES in the identity authentication response, determine that the identity authentication of the terminal device is passed.

20. The method according to any one of claims 11 to 19, characterized in that Before sending the first identifier to the terminal device, further include: Receive a registration request from the terminal device, where the registration request includes first indication information for indicating that the terminal device needs to enable the first service.

21. The method according to any one of claims 11 to 19, characterized in that, The method further includes: Receive a user key file from the third core network device, where the user key file is used to define the attributes of the first key.

22. The method according to claim 21, wherein The user key file includes at least one of the following: the type of the universal integrated circuit card (UICC) of the terminal device, the key lifetime of the first key, and the candidate timestamp of the first key.

23. The method according to any one of claims 11 to 19, characterized in that, The method further includes: Derive a third key according to the first key, where the third key is used for security authentication between the terminal device and the first server.

24. The method according to any one of claims 11 to 19, characterized in that, The information exchanged between the terminal device and the first core network device belongs to non-access stratum (NAS) messages.

25. A security authentication device, characterized in that, Set in the terminal device, the apparatus includes: An identifier receiving module, configured to receive a first identifier from a first core network device, where the first identifier is used to identify the identity of the terminal device between the terminal device and a first server, and the first server refers to the server to which the first service that the terminal device needs to enable is docked, and the first core network device is the access and mobility management function (AMF); A key determination module, configured to negotiate with the first core network device to determine a first key for security authentication between the terminal device and the first server, where the key determination module is configured to: Negotiate with the first core network device to determine the first key based on key generation parameters, where the key generation parameters include at least one of the following: a second key, a random number RAND, a second identifier, and a key identification parameter; Wherein, the second key is used to derive an encryption key corresponding to the information transmitted between the terminal device and the first core network device, the second identifier is used to identify the identity of the terminal device between the terminal device and the first core network device, and the key identification parameter is used to identify the first key.

26. The device according to claim 25, characterized in that, The first identifier is carried in an Authentication and Key Agreement (AKA) authentication response sent by a second core network device to the first core network device, and the second core network device is used to carry a Generic Bootstrapping Architecture (GBA) mechanism.

27. The device according to claim 25, characterized in that, The apparatus further includes: A first request receiving module, configured to receive an identity authentication request from the first core network device, where the identity authentication request is used to instruct the terminal device to perform identity authentication on the core network; A second response sending module, configured to send an identity authentication response to the first core network device in response to the core network identity authentication being passed, where the identity authentication response is used to instruct the first core network device to perform identity authentication on the terminal device.

28. The device according to claim 27, characterized in that, The apparatus further includes: A second request sending module, configured to send a GBA authentication request to the first core network device, where the GBA authentication request includes a second identifier, and the second identifier is used to identify the identity of the terminal device between the terminal device and the first core network device.

29. The device according to claim 27, wherein The identity authentication request includes a random number RAND and an authentication token AUTN, where the RAND is used to determine the identity of the core network and / or the identity authentication response, and the AUTN is used to indicate the identity of the core network.

30. The device according to claim 29, wherein The apparatus further includes: An information determination module, configured to determine the identity of the core network according to the RAND and the root key of the terminal device; An authentication passed module, configured to determine that the core network identity authentication is passed in response to the identity corresponding to the AUTN.

31. The device according to claim 29, characterized in that, The apparatus further includes: A response determination module, configured to determine the identity authentication response according to the RAND and the second key, where the second key is used to derive an encryption key corresponding to the information transmitted between the terminal device and the first core network device.

32. The device according to any one of claims 25 to 31, characterized in that, The apparatus further includes: A fourth request sending module, configured to send a registration request to the first core network device, where the registration request includes first indication information, and the first indication information is used to indicate that the terminal device needs to activate the first service.

33. The device according to any one of claims 25 to 31, characterized in that, The apparatus further includes: A key derivation module, configured to derive a third key according to the first key, where the third key is used for security authentication between the terminal device and the first server.

34. The device according to any one of claims 25 to 31, characterized in that, The information exchanged between the terminal device and the first core network device belongs to a Non-Access Stratum (NAS) message.

35. A security authentication device, characterized in that, It is disposed in a first core network device, and the first core network device is an Access and Mobility Management Function (AMF). The apparatus includes: An identifier sending module, configured to send a first identifier to the terminal device, where the first identifier is used to identify the identity of the terminal device between the terminal device and a first server, and the first server refers to the server to which the first service that the terminal device needs to activate is docked; A key determination module, configured to negotiate with the terminal device to determine a first key, where the first key is used for security authentication between the terminal device and the first server. Wherein, the key determination module is configured to: Negotiate with the terminal device to determine the first key based on key generation parameters, where the key generation parameters include at least one of the following: a second key, a random number RAND, a second identifier, and a key identification parameter. Wherein, the second key is used to derive an encryption key corresponding to information transmitted between the terminal device and the first core network device, the second identifier is used to identify the identity of the terminal device between the terminal device and the first core network device, and the key identification parameter is used to identify the first key.

36. The device according to claim 35, characterized in that, The apparatus further includes: A first response receiving module, configured to receive an Authentication and Key Agreement (AKA) authentication response from a second core network device, where the AKA authentication response includes the first identifier, and the second core network device is used to carry a Generic Bootstrapping Architecture (GBA) mechanism.

37. The device according to claim 36, characterized in that, The apparatus further includes: An identifier obtaining module, configured to encrypt the first identifier with an encryption key derived from the second key to obtain an encrypted first identifier, where the encrypted first identifier is used to be sent to the terminal device, and the second key is used to derive an encryption key corresponding to information transmitted between the terminal device and the first core network device.

38. The device according to claim 35, wherein The first core network device is used to carry the GBA mechanism; the apparatus further includes: A first request sending module, configured to send an identity authentication request to the terminal device, where the identity authentication request is used to instruct the terminal device to perform identity authentication on the core network. A second response receiving module, configured to receive an identity authentication response from the terminal device, where the identity authentication response is used to instruct the first core network device to perform identity authentication on the terminal device. An identifier determination module, configured to calculate the first identifier in response to the terminal device passing the identity authentication.

39. The apparatus according to claim 38, wherein The apparatus further includes: A vector receiving module, configured to receive an Authentication Vector (AV) from a third core network device, where the AV includes a random number RAND and an Authentication Token (AUTN).

40. The device according to claim 39, wherein, The apparatus further includes: A second request receiving module, configured to receive a GBA authentication request from the terminal device, where the GBA authentication request includes a second identifier, and the second identifier is used to identify the identity of the terminal device between the terminal device and the first core network device. A second request forwarding module, configured to forward the GBA authentication request to the third core network device in response to receiving the GBA authentication request.

41. The device according to claim 39, characterized in that, The apparatus further includes: A third request sending module, configured to send a GBA authentication request to the third core network device, where the GBA authentication request includes a second identifier, and the second identifier is used to identify the identity of the terminal device between the terminal device and the first core network device.

42. The device according to claim 39, characterized in that, The identity authentication request includes RAND and AUTN, where RAND is used to determine the identity of the core network and / or the identity authentication response, and AUTN is used to indicate the identity of the core network.

43. The device according to claim 39, characterized in that, The AV vector further includes XRES; the device further includes: An authentication passed module, configured to determine that the terminal device passes the identity authentication in response to the XRES corresponding to the RES in the identity authentication response.

44. The device according to any one of claims 35 to 43, characterized in that, The device further includes: A fourth request receiving module, configured to receive a registration request from the terminal device, where the registration request includes first indication information for indicating that the terminal device needs to activate the first service.

45. The device according to any one of claims 35 to 43, characterized in that The device further includes: A file receiving module, configured to receive a user key file from a third core network device, where the user key file is used to define the attributes of the first key.

46. The device according to claim 45, characterized in that, The user key file includes at least one of the following: the type of the universal integrated circuit card (UICC) of the terminal device, the key lifetime of the first key, and the candidate timestamp of the first key.

47. The device according to any one of claims 35 to 43, characterized in that, The device further includes: A key derivation module, configured to derive a third key according to the first key, where the third key is used for security authentication between the terminal device and the first server.

48. The device according to any one of claims 35 to 43, characterized in that, The information exchanged between the terminal device and the first core network device belongs to non-access stratum (NAS) messages.

49. A terminal device, characterized in that, The terminal device includes: a processor and a transceiver connected to the processor; where: The transceiver is configured to receive a first identifier from a first core network device, where the first identifier is used to identify the identity of the terminal device between the terminal device and a first server, and the first server is the server to which the first service that the terminal device needs to activate is docked, and the first core network device is the access and mobility management function (AMF); The processor is configured to negotiate with the first core network device to determine a first key, where the first key is used for security authentication between the terminal device and the first server, wherein, the processor is configured to: Negotiate with the first core network device to determine the first key based on key generation parameters, where the key generation parameters include at least one of the following: a second key, a random number RAND, a second identifier, and a key identification parameter; wherein, the second key is used to derive the encryption key corresponding to the information transmitted between the terminal device and the first core network device, the second identifier is used to identify the identity of the terminal device between the terminal device and the first core network device, and the key identification parameter is used to identify the first key.

50. A core network device, characterized in that, The core network device is the access and mobility management function (AMF), and the core network device includes: a processor and a transceiver connected to the processor; where: The transceiver is configured to send a first identifier to the terminal device, where the first identifier is used to identify the identity of the terminal device between the terminal device and a first server, and the first server is the server to which the first service that the terminal device needs to activate is docked; The processor is configured to negotiate with the terminal device to determine a first key, which is used for secure authentication between the terminal device and the first server. Wherein, the processor is configured to: Negotiate with the terminal device to determine the first key based on key generation parameters, where the key generation parameters include at least one of the following: a second key, a random number RAND, a second identifier, and a key identification parameter. Wherein, the second key is used to derive an encryption key corresponding to information transmitted between the terminal device and the core network device, the second identifier is used to identify the identity of the terminal device between the terminal device and the core network device, and the key identification parameter is used to identify the first key.

51. A computer-readable storage medium, characterized in that, A computer program is stored in the storage medium, and the computer program is configured to be executed by a processor of the terminal device to implement the secure authentication method according to any one of claims 1 to 10.

52. A computer-readable storage medium, characterized in that, A computer program is stored in the storage medium, and the computer program is configured to be executed by a processor of the core network device to implement the secure authentication method according to any one of claims 11 to 24.

Citation Information

Patent Citations

  • Extended universal bootstrap architecture authentication method and device and storage medium

    CN110831002A