Wireless device authentication indication method and device

By using random access process on the wireless side to authenticate and authenticate wireless devices, the problem of high cost of upgrading core networks in traditional methods is solved, and the rapid access and authentication of new wireless relay devices such as intelligent metasurfaces is realized, and the flexibility and efficiency of the communication network are improved.

CN115278664BActive Publication Date: 2025-09-02CHINA ACADEMY OF INFORMATION & COMM
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202210824539.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-07-14
Publication Date
2025-09-02
Estimated Expiration
2042-07-14

AI Technical Summary

Technical Problem

The authentication and authentication methods of traditional wireless relays and terminals require the participation of the core network side, resulting in high upgrade costs and high resource consumption, and it is impossible to adapt to the flexible authentication and authentication needs of new wireless relay devices such as smart metasurfaces.

Method used

By adopting a random access process on the wireless side, the first uplink signal includes a user ID, the first downlink signal calculates the authentication response, and the second uplink signal transmits the authentication result, fast authentication and authentication of the wireless device is realized.

Benefits of technology

Simplifies the authentication process, reduces the commercial costs of operators, and improves the flexibility and efficiency of wireless communication networks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115278664B_ABST
    Figure CN115278664B_ABST
Patent Text Reader

Abstract

The present application discloses a wireless device authentication indication method for use in an air interface of a mobile communication system, comprising the following steps: a first uplink signal for initiating an authentication process, comprising a user identifier; a first downlink signal in response to the first uplink signal, the first downlink signal being used to calculate an authentication response; and a second uplink signal comprising an authentication response in response to the first downlink signal. The present application also includes an apparatus for applying the method. The present application solves the problem of inconvenient access to wireless devices, and is particularly suitable for new types of wireless relay devices such as smart metasurfaces to access wireless communication networks through base stations, allowing for flexible and rapid adjustment of base station coverage.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of wireless communication technology, and in particular to a method and device for indicating wireless device authentication. Background Art

[0002] In traditional communications, wireless relay and terminal authentication and authorization are performed on the core network side, using 5G Authentication and Key Agreement (AKA). This process requires the participation of the user device (UE), including the Universal Subscriber Identity Module (USIM), the serving network (SN), and the home network (HN).

[0003] Considering that traditional wireless relays receive and regenerate data packets and send them to UEs, they are managed as network nodes and therefore utilize core network-based authentication and authorization. However, some intermediate wireless nodes, such as smart relays or smart metasurfaces, are transparent to data packets and content and cannot schedule UEs. In smart metasurfaces, the base station controls parameters such as the metasurface's phase to better control diffusely reflected incident signals, achieving controlled propagation of electromagnetic waves in the communication channel, thereby improving the coverage, capacity, and energy efficiency of the communication system. With new types of wireless relays, upgrading the core network is time-consuming and resource-intensive, reducing operators' commercial benefits. The cost and overhead of implementing core network authentication and authorization upgrades are significant. Therefore, compared to traditional wireless relays, new wireless relay types such as smart metasurfaces offer more flexible authentication and authorization methods, considering wireless-side authentication and authorization methods. Furthermore, with the rapid development of mobile communications, adopting wireless-side authentication and authorization methods for mobile terminals also facilitates the simplification and upgrade of the entire communication network. Summary of the Invention

[0004] This application proposes a wireless device authentication indication method and device to solve the technical problem of inconvenient wireless device access. It is particularly suitable for new types of wireless relay devices such as smart metasurfaces to access wireless communication networks through base stations, and flexibly and quickly adjust the base station coverage range.

[0005] In a first aspect, the present application proposes a wireless device authentication indication method for an air interface of a mobile communication system, comprising the following steps:

[0006] The first uplink signal used to start the authentication process includes a user identifier;

[0007] a first downlink signal in response to the first uplink signal, the first downlink signal being used to calculate an authentication response;

[0008] In response to the first downlink signal, the second uplink signal includes an authentication response or an authentication failure message.

[0009] In response to the second uplink signal, the second downlink signal includes information on authentication success or failure.

[0010] Preferably, the random access resources occupied by the first uplink signal or the random access sequence used is dedicated to the authentication procedure.

[0011] As an optional embodiment, the first downlink signal includes a random access response.

[0012] Preferably, the first uplink signal is scrambled using a user identifier encrypted with a public key; the public key has a one-to-one correspondence with the user identifier.

[0013] Preferably, the first downlink signal includes a challenge random number, a message authentication code, and an anonymous key. The message authentication code is a function of the challenge random number and a pre-stored sequence number. The anonymous key is a function of the challenge random number and a public key.

[0014] Preferably, the authentication response is a function of a public key, a challenge random number, and a sequence number.

[0015] Preferably, the serial number is pre-stored by the wireless device and the network device and is used to determine the validity of the challenge message.

[0016] Preferably, the MAC CE of the first downlink signal includes uplink grant information for scheduling uplink resources occupied by the second uplink signal.

[0017] Preferably, the MAC CE of the first downlink signal includes a wireless device identifier.

[0018] The method described in any embodiment of the first aspect of the present application, applied to a network device, comprises the following steps:

[0019] The network device receives the first uplink signal and identifies the user identifier and the public key;

[0020] The network device generates and sends the first downlink signal;

[0021] The network device receives the second uplink signal, compares the authentication response information with the locally stored authentication information, and determines whether the authentication is successful or terminated.

[0022] The method according to any one of the embodiments of the first aspect of the present application, used in a wireless device, comprises the following steps:

[0023] The wireless device sends the first uplink signal, which includes the user identification of the wireless device;

[0024] The wireless device receives the first downlink signal, and obtains the serial number according to a relationship between the set serial number and the message authentication code and the challenge random number in the first downlink signal;

[0025] If the serial number belongs to a pre-stored serial number range, the authentication response is generated; and the wireless device sends a second uplink signal including the authentication response.

[0026] In a second aspect, the present application further provides a network device for implementing the method described in any embodiment of the first aspect of the present application. At least one module in the network device is configured to implement at least one of the following functions: receiving the first uplink signal and identifying the user identifier and public key; generating and sending the first downlink signal; receiving the second uplink signal, comparing the authentication response information with the locally stored authentication information, and determining whether the authentication is successful or terminated.

[0027] In a third aspect, the present application further provides a wireless device for implementing the method described in any embodiment of the first aspect of the present application. At least one module in the wireless device is configured to implement at least one of the following functions: sending the first uplink signal containing the user identifier of the wireless device; receiving the first downlink signal, and deriving the sequence number based on a relationship between a set sequence number and a message authentication code and a challenge random number in the first downlink signal; and generating the authentication response if the sequence number falls within a pre-stored sequence number range.

[0028] In a fourth aspect, the present application also proposes a communication device, comprising: a memory, a processor, and a computer program stored on the memory and runnable on the processor, wherein the computer program, when executed by the processor, implements the steps of the method described in any one of the embodiments of the first aspect of the present application.

[0029] In a fifth aspect, the present application further proposes a computer-readable medium, on which a computer program is stored. When the computer program is executed by a processor, the steps of the method described in any embodiment of the first aspect of the present application are implemented.

[0030] In a sixth aspect, the present application also proposes a mobile communication system comprising at least one network device as described in any embodiment of the present application and / or at least one wireless device as described in any embodiment of the present application.

[0031] At least one of the above technical solutions adopted in the embodiments of the present application can achieve the following beneficial effects:

[0032] This patent proposes a wireless authentication method for intermediate wireless nodes, such as smart metasurfaces or wireless relays, and terminal devices. This method uses a random access process to initiate, execute, and confirm authentication. This method can be applied to intermediate wireless nodes, such as smart repeaters or smart metasurfaces, because the data packets and content of these intermediate wireless nodes are transparent. Considering wireless authentication methods solves the time-consuming and resource-intensive issue of core network upgrades, thereby improving the commercial interests of operators. BRIEF DESCRIPTION OF THE DRAWINGS

[0033] The drawings described herein are used to provide a further understanding of the present application and constitute a part of the present application. The illustrative embodiments of the present application and their descriptions are used to explain the present application and do not constitute an improper limitation on the present application. In the drawings:

[0034] Figure 1 This is a flow chart of an embodiment of the method of this application;

[0035] Figure 2 This is a flow chart of an embodiment of the method of the present application used in a network device;

[0036] Figure 3 This is a flow chart of an embodiment of the method of the present application used in a wireless device;

[0037] Figure 4 is a schematic diagram of an embodiment of a network device;

[0038] Figure 5 is a schematic diagram of an embodiment of a wireless device;

[0039] Figure 6 A schematic structural diagram of a network device according to another embodiment of the present invention;

[0040] Figure 7 is a block diagram of a wireless device according to another embodiment of the present invention. DETAILED DESCRIPTION

[0041] To make the purpose, technical solutions, and advantages of this application more clear, the technical solutions of this application will be clearly and completely described below in conjunction with the specific embodiments of this application and the corresponding drawings. Obviously, the embodiments described are only part of the embodiments of this application, not all of them. Based on the embodiments in this application, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of this application.

[0042] The following describes in detail the technical solutions provided by various embodiments of the present application in conjunction with the accompanying drawings.

[0043] Figure 1 This is a flow chart of an embodiment of the method of this application.

[0044] The present application proposes a wireless device authentication indication method, which is used in an air interface of a mobile communication system and includes the following steps 101 to 104 .

[0045] Step 101: A first uplink signal for starting an authentication process includes a user identifier.

[0046] The authentication and authorization process and the random access process are multiplexed. The multiplexing method is such that the first uplink signal is sent using random access resources and conforms to the random access signal structure. Alternatively, the first uplink signal itself is a random access signal. To ensure that the first uplink signal receives a response indicating that the authentication process has been initiated, the first uplink signal may include indication information for the authentication process, or the random access resources occupied by the first uplink signal may indicate that the first uplink signal is used for the authentication process.

[0047] Preferably, the first uplink signal is a random access sequence dedicated to the authentication procedure, and a portion of the random access sequence dedicated to the authentication procedure is selected. In particular, the first uplink signal for the wireless device (relay device or intermediate device with a smart metasurface) is specially configured compared to the random access signal of the terminal.

[0048] Preferably, the random access resources occupied by the first uplink signal are dedicated to the authentication procedure, that is, when the first uplink signal is sent in the random access resources dedicated to the authentication procedure, what is obtained is an authentication procedure response, not a random access response.

[0049] Preferably, the sequence of the first uplink signal is scrambled using a user identifier encrypted with a public key; the public key corresponds to the user identifier in a one-to-one manner. The user identifier may be a permanent identifier of a wireless device.

[0050] Preferably, the first uplink signal sends a user identity encrypted with a public key on the occupied time-frequency resources.

[0051] Step 101 is the authentication initiation phase. The wireless device transmits a first uplink signal, which includes, for example, an encrypted user identifier of the wireless device, over the air interface with the network device. The network device receives the first uplink signal and obtains the wireless device's user identifier and public key. The public key corresponds to the user identifier.

[0052] Step 102: A first downlink signal responds to the first uplink signal, where the first downlink signal is used to calculate an authentication response.

[0053] Preferably, the first downlink signal includes a challenge random number, a message authentication code, and an anonymous key. The message authentication code is a function of the challenge random number and a pre-stored sequence number. The anonymous key is a function of the challenge random number and a public key.

[0054] Preferably, the MAC CE of the first downlink signal includes uplink grant information for scheduling uplink resources occupied by the second uplink signal.

[0055] As an optional embodiment, the first downlink signal includes a random access response.

[0056] Step 102 is the authentication execution phase. The first downlink signal sent by the network device includes a challenge message, so that the wireless device can calculate an authentication response based on the received challenge message. Preferably, the first downlink signal includes indication information indicating an identifier for the wireless device; the first downlink signal also includes indication information indicating that the challenge message is used for authentication.

[0057] Preferably, the first downlink signal is carried by the MAC layer, and the MAC CE includes an identifier of the wireless device and the query message.

[0058] Preferably, the first downlink signal is scrambled with a new RNTI, and the new RNTI is related to the time-frequency resource where the first downlink signal is located.

[0059] For example, the challenge message includes a challenge random number and an authentication token; the authentication token includes at least a message authentication code and an anonymous key.

[0060] The message authentication code is a function of the wireless device's serial number and a random challenge number. The anonymous key is a function of a public key and the random challenge number. The public key is a key shared by the wireless device and the network node. The serial number is pre-stored by the wireless device and the network device and is used to determine the validity of the challenge message. The message authentication code is used by the wireless device to determine whether the challenge message has been tampered with.

[0061] Step 103: In response to the first downlink signal, the second uplink signal includes an authentication response.

[0062] After receiving the first downlink signal, the wireless device verifies the validity and authenticity of the message, then calculates an authentication response for authentication and authorization, and reports the authentication response.

[0063] The wireless device receives the first downlink signal, obtains a sequence number based on the relationship between the set sequence number and the message authentication code and the challenge random number in the first downlink signal, and verifies the validity and authenticity of the challenge message by comparing it with the pre-stored sequence number.

[0064] Preferably, the authentication response is a function of a public key, a challenge random number, and a sequence number.

[0065] Step 103 is the authentication execution phase. If the challenge message is valid, the wireless device sends an authentication response to the network device. If the wireless device fails to verify the message, it sends an authentication failure message to the network. The network then determines whether to re-initiate authentication with the wireless device.

[0066] Step 104: In response to the second uplink signal, the second downlink signal includes a message indicating success or failure of the authentication response.

[0067] Step 104 is the authentication confirmation phase. The network device compares the authentication response message from the wireless device with the locally stored authentication information to determine whether the authentication is successful or terminated.

[0068] In this step, the network device notifies the wireless device of the success or failure of the authentication based on the reported authentication response.

[0069] Figure 2 This is a flow chart of an embodiment of the method of the present application being applied to a network device.

[0070] The method described in any one of the embodiments of the first aspect of the present application is used for a network device and includes the following steps 201 to 204.

[0071] Step 201: The network device receives the first uplink signal and identifies the user identifier and public key.

[0072] The network device receives the first uplink signal, obtains the user identity of the wireless device, and finds the public key corresponding to the user identity.

[0073] Step 202: The network device generates and sends the first downlink signal.

[0074] The network device sends a first downlink signal including a challenge message. The challenge message includes a challenge random number RAND and an authentication token;

[0075] The authentication token AUTN is determined by at least a message authentication code MAC and an anonymous key AK;

[0076] Furthermore, define AUTN=f1(MAC, AK), where f1 is a function expression and the specific format is not limited.

[0077] A message authentication code, used by the wireless device to determine whether the challenge message has been tampered with, is determined by at least the sequence number SEQ corresponding to the wireless device and the challenge random number RAND;

[0078] Furthermore, MAC=f2(SEQ, RAND) is defined, where f2 is a function expression, and the specific format is not limited.

[0079] The serial number is pre-stored by the wireless device and the network device and is used to determine the validity of the challenge message;

[0080] The anonymous key is a function of a public key CK and a challenge random number, and the public key is a key shared by the wireless device and the network device;

[0081] Furthermore, an anonymous key AK=f3(RAND, CK) is defined, where f3 is a function expression, and the specific format is not limited.

[0082] Preferably, the first downlink signal is carried by the MAC layer. If the first uplink signal is a random access sequence, in order to distinguish it from the MAC RAR of the random access response, the MAC CE of the first downlink signal includes a signal identifier for the wireless device and indicates that the first downlink signal (challenge message) sent is used for authentication; if the first uplink signal is data information, the wireless device can decode it through new RNTI scrambling, for example, Auth_RNTI. The determination of Auth_RNTI is related to the time domain resources and frequency domain resources used by the wireless device to send the first uplink signal.

[0083] Step 203: The network device receives the second uplink signal, compares the authentication response information with the locally stored authentication information, and determines whether the authentication is successful or terminated.

[0084] The network device compares the authentication response reported by the wireless device with the authentication response information stored in itself to determine whether the authentication response is successful or failed.

[0085] The network device determines whether to re-initiate re-authentication with the wireless device based on the authentication failure message reported by the wireless device.

[0086] Step 204: The network device sends the second downlink signal, where the second downlink signal includes a message indicating success or failure of the authentication response.

[0087] Notify the wireless device of the success or failure of authentication and assign an identity to the wireless device.

[0088] Figure 3 This is a flow chart of an embodiment of the method of the present application used in a wireless device.

[0089] The method described in any one of the embodiments of the first aspect of the present application is used in a wireless device and includes the following steps 301 to 304.

[0090] Step 301: The wireless device sends the first uplink signal, which includes the user identification of the wireless device.

[0091] The wireless device sends a first uplink signal, where the first uplink signal includes an encrypted wireless device user identifier. The encryption is performed based on a public key, and the public key corresponds to the wireless device identifier in a one-to-one manner.

[0092] The first uplink signal is a data sequence or data information.

[0093] Preferably, the first uplink signal is a random access sequence. To distinguish it from the random access sequence of the random access process, a portion of the random access sequence dedicated to authentication can be selected. The random access sequence can be scrambled according to the encrypted user permanent identifier. Considering that the deployment location of the intermediate node type of the wireless device is usually close to the base station, the random access format can use a short sequence with a sequence length of L=139.

[0094] Preferably, the first uplink signal uses a random access time-frequency resource dedicated to authentication and authorization, and the wireless device sends user identification information on this resource. Furthermore, the data transmission method can be a non-orthogonal multiple access access method, where each wireless device has a dedicated multiple access identifier for identifying multiple wireless devices;

[0095] Preferably, the public key is sent by public signaling between the network device and the wireless device, such as broadcast signaling, or the public key is pre-configured by the network device to the wireless device.

[0096] The user identifier of the wireless device is identifiable by a network device. Preferably, the user identifier is a permanent user identifier. Currently, a permanent user identifier is a fixed identity identifier of a user on the network and does not change with changes in the network. Therefore, the permanent user identifier can uniquely correspond to a user at any time and in any scenario. For example, the permanent user identifier is the user's International Mobile Subscriber Identification Number (IMSI) or International Mobile Equipment Identification Number (IMEI).

[0097] Step 302: The wireless device receives the first downlink signal, and obtains a sequence number based on a relationship between a set sequence number and a message authentication code and a challenge random number in the first downlink signal.

[0098] If the sequence number falls within the pre-stored sequence number range, the authentication response is generated. The authentication response RES is at least a function of the public key CK, the challenge random number RAND, and the sequence number SEQ. Further, RES = f4(CK, RAND, SEQ), where f4 is a function expression whose specific format is not limited.

[0099] Step 303: The wireless device sends the second uplink signal, which includes the authentication response or a message indicating authentication failure.

[0100] The wireless device successfully verifies the validity and authenticity of the message, calculates an authentication response for authentication and authorization, and reports the authentication response.

[0101] Preferably, the authentication response is sent on the uplink resources scheduled by the uplink grant (UL grant) in the MAC CE of the first downlink signal.

[0102] The wireless device fails to authenticate the message, meaning the sequence number decoded from the received message authentication code is outside the range of sequence numbers stored by the wireless device. The wireless device detects that the challenge message has been tampered with and sends an authentication failure message to the network device. Furthermore, the sequence number stored by the wireless device is pre-stored or pre-configured by the network device and notified via public signaling (e.g., broadcast signaling).

[0103] Step 304: After sending the authentication response, the wireless device receives the second downlink signal and determines whether the authentication response is successful or failed.

[0104] Figure 4 Schematic diagram of a network device embodiment.

[0105] The present application also provides a network device for implementing the method described in any embodiment of the first aspect of the present application. At least one module in the network device is configured to implement at least one of the following functions: receiving the first uplink signal and identifying the user identifier and public key; generating and sending the first downlink signal; receiving the second uplink signal, comparing the authentication response information with the locally stored authentication information, and determining whether the authentication is successful or terminated.

[0106] To implement the above technical solution, the present application proposes a network device 400 comprising a network sending module 401 , a network determining module 402 , and a network receiving module 403 .

[0107] The network sending module is used to send the first downlink signal and the second downlink signal.

[0108] The network determination module is used to identify the user identifier and public key and generate the challenge message; it is also used to compare the authentication response reported by the wireless device with the authentication response information stored in the network to determine whether the authentication response is successful or failed.

[0109] The network receiving module is configured to receive the first uplink signal and the second uplink signal.

[0110] The specific methods for implementing the functions of the network sending module, network determination module, and network receiving module are as described in the various method embodiments of this application and will not be repeated here.

[0111] Figure 5 is a schematic diagram of an embodiment of a wireless device.

[0112] The present application also provides a wireless device for implementing the method described in any embodiment of the first aspect of the present application. At least one module in the wireless device is configured to implement at least one of the following functions: sending the first uplink signal containing the user identification of the wireless device; receiving the first downlink signal, and deriving the sequence number based on a relationship between a set sequence number, a message authentication code in the first downlink signal, and a challenge random number; and generating the authentication response if the sequence number falls within a pre-stored sequence number range, otherwise generating an authentication failure message.

[0113] To implement the above technical solution, the present application proposes a wireless device 500 , which includes a wireless sending module 501 , a wireless determination module 502 , and a wireless receiving module 503 .

[0114] The wireless receiving module is used to receive the first downlink information and the second downlink information.

[0115] The wireless determination module is configured to be triggered by the message authentication code and the challenge random number in the first downlink information, derive a sequence number based on a relationship between a set sequence number and the message authentication code and the challenge random number in the first downlink signal, and then determine whether the inquiry message is valid based on whether the derived sequence number falls within a pre-stored sequence number range. The wireless determination module is further configured to confirm the success or failure of the authentication response based on an indication in the second downlink information.

[0116] The wireless sending module is used to send the first uplink information and the second uplink information.

[0117] The specific methods for implementing the functions of the wireless sending module, wireless determination module, and wireless receiving module are as described in the various method embodiments of this application and will not be repeated here.

[0118] The wireless device described in this application may refer to a wireless relay device, an intermediate device with an intelligent metasurface, or a mobile terminal device.

[0119] Figure 6The schematic diagram of the structure of a network device according to another embodiment of the present invention is shown. As shown in the figure, the network device 600 includes a processor 601, a wireless interface 602, and a memory 603. The wireless interface can be a plurality of components, namely, a transmitter and a receiver, providing a unit for communicating with various other devices on a transmission medium. The wireless interface implements the communication function with the wireless device, processes wireless signals through receiving and transmitting devices, and the data carried by the signals is communicated with the memory or processor via an internal bus structure. The memory 603 contains a computer program for executing any one of the embodiments of the present application, and the computer program is run or changed on the processor 601. When the memory, processor, and wireless interface circuit are connected via a bus system. The bus system includes a data bus, a power bus, a control bus, and a status signal bus, which will not be described in detail here.

[0120] Figure 7 FIG2 is a block diagram of a wireless device according to another embodiment of the present invention. Wireless device 700 includes at least one processor 701, memory 702, a control interface 703, and at least one network interface 704. The various components in wireless device 700 are coupled together via a bus system. The bus system is used to enable communication between these components. The bus system includes a data bus, a power bus, a control bus, and a status signal bus.

[0121] The control interface 904 is used to connect to the phase conversion device of the intermediate device (such as a metasurface device) to convert the multiple sets of control parameters into drive signals for each surface unit, thereby adjusting the reflection (or refraction) signal of the intermediate device. Alternatively, the control interface is dedicated to end-user applications. The control interface 703 may include a display, keyboard, or pointing device, such as a mouse, trackball, touchpad, or touch screen.

[0122] Memory 702 stores executable modules or data structures. The memory may store an operating system and application programs. The operating system includes various system programs, such as a framework layer, a core library layer, and a driver layer, for implementing various basic services and processing hardware-based tasks. Application programs include various application programs, such as media players and browsers, for implementing various application services.

[0123] In an embodiment of the present invention, the memory 702 contains a computer program for executing any one of the embodiments of the present application, and the computer program is run or changed on the processor 701 .

[0124] Memory 702 includes a computer-readable storage medium. Processor 701 reads information from memory 702 and, in conjunction with its hardware, performs the steps of the above-described method. Specifically, the computer-readable storage medium stores a computer program that, when executed by processor 701, implements the steps of any of the above-described method embodiments.

[0125] The processor 701 may be an integrated circuit chip with signal processing capabilities. During implementation, each step of the method of the present application may be completed by hardware integrated logic circuits in the processor 701 or by instructions in the form of software. The processor 701 may be a general-purpose processor, a digital signal processor, an application-specific integrated circuit, an off-the-shelf programmable gate array or other programmable logic device, a discrete gate or transistor logic device, or a discrete hardware component. The various methods, steps, and logic block diagrams disclosed in the embodiments of the present invention may be implemented or executed. The general-purpose processor may be a microprocessor or any conventional processor. The steps of the method disclosed in conjunction with the embodiments of the present invention may be directly implemented as being executed by a hardware decoding processor, or may be executed by a combination of hardware and software modules in the decoding processor.

[0126] Those skilled in the art will appreciate that embodiments of the present invention may be provided as methods, systems, or computer program products. Therefore, the present invention may take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware. In a typical configuration, the device of the present application includes one or more processors (CPUs), an input / output user interface, a network interface, and a memory.

[0127] Furthermore, the present invention may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program codes.

[0128] Therefore, the present application also provides a computer-readable medium storing a computer program, wherein when the computer program is executed by a processor, the steps of the method described in any embodiment of the present application are implemented. For example, the memory 603, 702 of the present invention may include non-permanent memory, random access memory (RAM) and / or non-volatile memory in a computer-readable medium, such as read-only memory (ROM) or flash RAM.

[0129] Computer-readable media includes permanent and non-permanent, removable and non-removable media that can be implemented by any method or technology to store information. The information can be computer-readable instructions, data structures, program modules or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technology, compact disc read-only memory (CD-ROM), digital versatile disc (DVD) or other optical storage, magnetic cassettes, magnetic tape, magnetic disk storage or other magnetic storage devices or any other non-transmission media that can be used to store information that can be accessed by a computing device. As defined herein, computer-readable media does not include transitory computer-readable media (transitory media), such as modulated data signals and carrier waves.

[0130] based on Figures 4 to 7 In addition to the embodiments of the present application, the present application also proposes a mobile communication system, comprising at least one embodiment of any wireless device in the present application and / or at least one embodiment of any network device in the present application.

[0131] It should also be noted that the terms "comprises," "includes," or any other variations thereof are intended to encompass non-exclusive inclusion, such that a process, method, commodity, or apparatus that includes a series of elements includes not only those elements but also other elements not explicitly listed, or includes elements inherent to such process, method, commodity, or apparatus. In the absence of further limitations, an element defined by the phrase "comprises a ..." does not exclude the presence of other identical elements in the process, method, commodity, or apparatus that includes the element.

[0132] It should also be noted that the terms "first" and "second" in this application are used to distinguish multiple objects with the same name and have no other special meaning unless specifically stated.

[0133] The foregoing is merely an embodiment of the present application and is not intended to limit the present application. For those skilled in the art, the present application may have various changes and variations. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principles of the present application should all be included within the scope of the claims of the present application.

Claims

1. A wireless device authentication indication method for an air interface of a mobile communication system, wherein a wireless relay device with an intelligent metasurface accesses a wireless communication network through a base station, characterized in that: The following steps are involved: A first uplink signal used to initiate an authentication process includes a user identifier; the first uplink signal is sent using random access resources and conforms to a random access signal structure; the first uplink signal includes indication information for an authentication procedure, or the random access resources occupied by the first uplink signal indicate that the first uplink signal is used for an authentication procedure; The first downlink signal is in response to the first uplink signal, and the first downlink signal is used to calculate the authentication response; the challenge message in the first downlink signal includes a challenge random number and an authentication token, and the authentication token includes a message authentication code and an anonymous key; the message authentication code is a function of the challenge random number and a pre-stored sequence number; the anonymous key is a function of the challenge random number and a public key; wherein the sequence number is used to determine the validity of the challenge message; and the message authentication code is used by the wireless device to determine whether the challenge message has been tampered with; In response to the first downlink signal, the second uplink signal includes an authentication response or an authentication failure message; In response to the second uplink signal, the second downlink signal includes information on authentication success or failure.

2. The method according to claim 1, wherein: The random access resource or random access sequence occupied by the first uplink signal is dedicated to the authentication procedure.

3. The method according to claim 1, wherein: The first uplink signal is scrambled using a user identifier encrypted with a public key; the public key corresponds to the user identifier in a one-to-one manner.

4. The method according to claim 1, characterized in that The authentication response is a function of a public key, a challenge random number, and a sequence number.

5. The method according to claim 1, wherein: The MAC CE of the first downlink signal includes uplink grant information, which is used to schedule uplink resources occupied by the second uplink signal.

6. The method according to claim 1, wherein: The MAC CE of the first downlink signal includes a wireless device identifier.

7. The method according to any one of claims 1 to 6, used for a network device, characterized in that: The network device receives the first uplink signal and identifies the user identifier and the public key; The network device generates and sends the first downlink signal; The network device receives the second uplink signal, compares the authentication response information with the locally stored authentication information, and determines whether the authentication is successful or terminated.

8. The method according to any one of claims 1 to 6, used in a wireless device, characterized in that: The wireless device sends the first uplink signal, which includes the user identification of the wireless device; The wireless device receives the first downlink signal, and obtains the serial number according to a relationship between the set serial number and the message authentication code and the challenge random number in the first downlink signal; If the serial number falls within a pre-stored serial number range, generating the authentication response; The wireless device sends a second uplink signal including an authentication response.

9. A network device, used to implement the method according to any one of claims 1 to 7, characterized in that: At least one module in the network device is used to implement at least one of the following functions: receiving the first uplink signal, identifying the user identifier and public key; generating and sending the first downlink signal; receiving the second uplink signal, comparing the authentication response information with the locally stored authentication information, and determining whether the authentication is successful or terminated.

10. A wireless device, configured to implement the method according to any one of claims 1 to 6 and 8, characterized in that: At least one module in the wireless device is used to implement at least one of the following functions: sending the first uplink signal, which includes the user identification of the wireless device; receiving the first downlink signal, and deriving the serial number based on the relationship between the set serial number and the message authentication code and the challenge random number in the first downlink signal; and generating the authentication response if the serial number falls within a pre-stored serial number range.

11. A communication device, characterized in that: include: A memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the computer program, when executed by the processor, implements the steps of the method according to any one of claims 1 to 8.

12. A computer-readable medium storing a computer program, wherein the computer program, when executed by a processor, implements the steps of the method according to any one of claims 1 to 8.

13. A mobile communication system comprising at least one network device according to claim 9 and at least one wireless device according to claim 10.

Citation Information

Patent Citations

  • Terminal device, communication method, and integrated circuit

    CN107637139A

  • Wireless communication network optimization method and computer readable storage medium

    CN113179527A

  • A system and method of secure network authentication

    WO2009089764A1