Authentication method and system

By deploying the ATLF module on the core network side, matching user terminal information to determine whether secondary authentication is exempted, the problem of excessive network response time caused by secondary authentication in the prior art is solved, and more efficient data service network response and resource conservation are achieved.

CN115835202BActive Publication Date: 2025-05-13ZHONGRUI COMM PLANNING & DESIGN
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202211235243.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-10-10
Publication Date
2025-05-13
Estimated Expiration
2042-10-10

AI Technical Summary

Technical Problem

In the prior art, the secondary authentication mechanism causes the network response time to be too long in certain special application scenarios, affecting the response speed of the emergency network.

Method used

By deploying the ATLF module on the core network side, the user terminal's TAC and DNN information are obtained, and matching them with the pre-planned access resource information, it is determined whether secondary authentication is exempted. When the user terminal is recognized as trustworthy, skip the secondary authentication and communicate directly with the data service dedicated network.

Benefits of technology

On the premise of ensuring the security of data service network communication, the overall response efficiency of the data service network is improved, network resources are saved, and the rationality of the secondary authentication type selection of user terminals is improved.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115835202B_ABST
    Figure CN115835202B_ABST
Patent Text Reader

Abstract

The present invention discloses an authentication method and system, and relates to the field of mobile communication technology. The authentication method includes that after the core network side receives the request of the user terminal to access the data service private network and completes the primary authentication, a user plane data channel is established between the user terminal side and the core network side; the core network side obtains the user terminal information, matches the user terminal information with the pre-planned access resource information, and confirms whether to exempt the user terminal from secondary authentication according to the matching result. In the authentication system, the core network side includes AUSF network element, SMF network element (including ATLF module), UPF network element and AAA network element. Compared with the prior art, the authentication method of the present invention improves the rationality of the selection of secondary authentication type of the user terminal under the premise of ensuring the security of data service network communication by exempting the secondary authentication of the credit user terminal, forcing the secondary authentication of the user terminal with insufficient credit conditions or directly refusing access.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of mobile communication technology, and more specifically, to an authentication method and system. Background Art

[0002] To prevent illegal network attacks, user terminals (User Equipment, UE) accessing the 5G network need to be authenticated through the access network. Compared with ordinary public users, vertical industries have higher requirements for business confidentiality and security. Therefore, vertical industry terminals need to undergo another identity authentication before accessing the data service private network through the 5G network, i.e., secondary authentication.

[0003] The user terminal first completes the primary authentication between the UDM (Unified Data Management) network element and the AUSF (Authentication Server Function) network element, and then initiates a request to access the data service network. The SMF (Session Management Function) network element first determines whether the terminal needs to be authenticated based on the DNN (Data Network Name). After confirming that the terminal needs secondary authentication, it sends an authentication request message to the UPF (User Plane Function). The UPF forwards the authentication request to the AAA (Authentication; Authorization; Accounting) network element. After the AAA network element completes the secondary authentication, the SMF sends a notification of establishing a session to the UPF. Terminals that fail the secondary authentication will be denied access to the data service network.

[0004] The secondary authentication mechanism effectively improves the security of the business, but it also has the disadvantages of being too fixed and inflexible in some special application scenarios. For example, the cluster network is an important command and dispatch platform for handling public emergencies, emergency support, and urban management. It is widely used in government, public security, public utilities and other fields. When it is in emergency command and dispatch scenarios such as disaster relief, the secondary authentication mechanism affects the response speed of the entire emergency network.

[0005] The prior art has disclosed a secondary authentication method and system for a user terminal, and an access and mobility management device; wherein the secondary authentication method is to notify a third-party data network server to authenticate the user terminal after the 5G network completes the authentication of the user terminal when the user terminal is registered to the 5G network. In essence, when the 5G terminal registers with the network, the third-party platform is notified to perform authentication in advance. This technical means is still consistent with the mainstream authentication idea, and there is still the problem of long overall network response time. Summary of the invention

[0006] The present invention provides an authentication method and system to overcome the defect that the secondary authentication mechanism described in the prior art causes a long network response time.

[0007] In order to solve the above technical problems, the technical solution of the present invention is as follows:

[0008] In a first aspect, an authentication method is applied to a data service network, wherein the data service network is a data network dedicated network established, owned, managed and used by an enterprise, organization or department to meet its own needs, comprising:

[0009] After the core network side receives the user terminal's request to access the data service private network and completes one-time authentication, a user plane data channel is established between the user terminal side and the core network side; wherein the core network includes AUSF network elements, SMF network elements, UPF network elements and AAA network elements; the SMF network element includes an ATLF (Authentication Type Label Function, secondary authentication type of the terminal and registration) module;

[0010] The core network obtains user terminal information, matches the user terminal information with the pre-planned access resource information, and determines whether to exempt the user terminal from secondary authentication based on the matching result:

[0011] If the user terminal information belongs to the pre-planned access resource information, the core network side exempts the user terminal from performing secondary authentication and establishes a connection between the user terminal and the data service dedicated network;

[0012] If the user terminal information does not belong to the pre-planned access resource information, the core network side does not exempt the user terminal from performing secondary authentication; wherein the user terminal information includes the TAC (Tracking Area Code) subscribed by the user terminal and the carried DNN.

[0013] In this technical solution, after completing one authentication, the core network side matches the user terminal information with the pre-planned access resource information, and confirms whether to exempt the user terminal from secondary authentication based on the matching result; when the user terminal is exempted from secondary authentication, it can skip the secondary authentication and communicate directly with the data service private network, thereby improving the overall response efficiency of the data service network while ensuring the security of data service network communication, and saving network resources to a certain extent.

[0014] As a preferred solution, after the core network side does not exempt the user terminal from performing secondary authentication, any of the following steps is performed:

[0015] (1) The core network directly denies user terminals access to the data service network;

[0016] (2) The core network side performs one of the secondary authentications on the user terminal.

[0017] As a preferred solution, the pre-planned access resource information includes:

[0018] The dedicated DNN for the data service network signed by the SIM card of the credit communication terminal is denoted as DNN SP ;

[0019] A temporary TAC used to temporarily configure a data service private network base station, the number of which is denoted as w, and the temporary TAC is denoted as τ j ', j = [1, 2, ..., w], that is, τ j '∈T'={τ1',τ2',…,τ w '}.

[0020] As a possible design of the preferred solution, the core network side obtains user terminal information and matches the user terminal information with pre-planned access resource information, and the steps include:

[0021] The SMF network element instructs the UPF network element to send user terminal information to the ATLF module; the DNN signed by the user terminal in the user terminal information is recorded as DNN UE , the TAC carried by the user terminal is denoted as τ UE ;

[0022] ATLF module judges DNN UE With DNN SP Is it consistent and τ UE Belongs to T':

[0023] If DNN UE ≠DNN SP , output secondary authentication type S k To refuse authentication;

[0024] If DNNUE =DNN SP , and τ UE ∈T', output secondary authentication type S k It is exempt from authentication;

[0025] If DNN UE =DNN SP ,and Output secondary authentication type S k Authentication is required;

[0026] The ATLF module will output the secondary authentication type S k Sent to the SMF network element, the SMF network element according to the secondary authentication type S k Determine whether to exempt the user terminal from secondary authentication.

[0027] That is, in this possible design, the user terminal is allowed to skip the secondary authentication and directly access the data service private network only if the DNN signed by the user terminal is a DNN dedicated to the data service private network, and the TAC it carries is an element of the temporary TAC set T' of the temporarily configured data service private network base station.

[0028] Furthermore, if the user terminal information belongs to the pre-planned access resource information, the user terminal is exempted from performing secondary authentication and a connection between the user terminal and the data service private network is established, specifically:

[0029] If the SMF network element receives the secondary authentication type S k In order to avoid authentication, the SMF network element sends a request to the UPF network element to establish a connection for the user terminal to the data service private network; the UPF network element responds to the connection request and establishes a connection channel between the user terminal and the data service private network.

[0030] Furthermore, if the user terminal information does not belong to the pre-planned access resource information, the core network side does not exempt the user terminal from performing secondary authentication, including:

[0031] If the SMF network element receives the secondary authentication type S k To reject authentication, the SMF network element directly rejects the user terminal's access to the data service network;

[0032] If the SMF network element receives the secondary authentication type S k To ensure that authentication is required, the SMF network element forwards a secondary identity authentication message about the user terminal to the AAA network element and establishes an authentication channel between the user terminal and the AAA network element; the secondary identity authentication message includes DNN UE, and also includes one or more of the user terminal's IMSI (International Mobile Subscriber Identity), IMEI (International Mobile Equipment Identity), MSISDN (Mobile Subscriber Integrated Services Digital Number) and ULI (User Location Information).

[0033] Preferably, after the SMF network element forwards the secondary identity authentication message to the AAA network element and establishes an authentication channel between the user terminal and the AAA network element, the AAA network element performs secondary authentication on the user terminal according to the received secondary identity authentication message and outputs the secondary authentication result r p To the SMF network element; wherein the secondary authentication result r p This includes either passing the certification or failing the certification.

[0034] Optionally, the AAA network element performs secondary authentication on the user terminal and outputs the secondary authentication result r p After the SMF network element, it also includes:

[0035] When the SMF network element receives the secondary authentication result r p When the authentication is passed, the SMF network element sends a request to the UPF network element to establish a connection for the user terminal to the data service private network. The UPF network element responds to the connection request and establishes a connection channel between the user terminal and the data service private network.

[0036] When the SMF network element receives the secondary authentication result r p When the authentication fails, the SMF network element denies the user terminal access to the data service network.

[0037] In the second aspect, an authentication system is applied to the authentication method proposed in any technical solution of the first aspect, including a core network side and a data service private network, the core network side includes an AUSF network element, an SMF network element, a UPF network element and an AAA network element, the SMF network element includes an ATLF module, and the ATLF module is configured to match the acquired user terminal information with the pre-planned access resource information, judge, record and output the secondary authentication type S k; Wherein, the user terminal information includes the DNN signed by the user terminal requesting access to the data service private network and the TAC it carries, the pre-planned access resource information includes the dedicated DNN for the data service private network signed by the SIM card of the credit communication terminal and the temporary TAC used to temporarily configure the base station of the data service private network, and the output secondary authentication type S k It includes one of the following: authentication rejection, authentication exemption, and authentication required.

[0038] In this technical solution, the ATLF module is deployed on the core network side to obtain the TAC, DNN and other information of the user terminal, and the secondary authentication type of the terminal is registered and used as a condition for subsequent authentication type selection. The secondary authentication is exempted for trusted user terminals, which is beneficial to improving the response efficiency of the data service private network.

[0039] As a preferred solution, if the secondary authentication type S output by the ATLF module is k In order to exempt or refuse authentication, the SMF network element does not communicate with the AAA network element; if the secondary authentication type S output by the ATLF module k To ensure authentication, the SMF network element communicates with the AAA network element.

[0040] Compared with the prior art, the technical solution of the present invention has the following beneficial effects:

[0041] (1) The present invention proposes an authentication method that pre-plans a dedicated DNN for a data service private network and a temporary data service private network base station TAC as the basis for credit, i.e., access resource information. Only user terminals that have signed a contract for a data service private network and accessed a temporary data service private network base station are exempted from secondary authentication. For user terminals that do not meet the credit conditions, secondary authentication is still forced or access is directly denied. This improves the rationality of secondary authentication type selection for user terminals while ensuring the security of data service network communications.

[0042] (2) The present invention deploys an ATLF module on the core network side to obtain the TAC, DNN and other information of the user terminal, and registers the secondary authentication type of the terminal for use as a condition for subsequent authentication type selection. The secondary authentication is exempted for trusted user terminals, which is beneficial to improving the response efficiency of the data service private network.

[0043] (3) Compared with the prior art, the present invention reduces the communication frequency between the SMF network element and the AAA network element, which can save network resources to a certain extent. BRIEF DESCRIPTION OF THE DRAWINGS

[0044] Figure 1 is a flow chart of the authentication method;

[0045] Figure 2 A flow chart for requesting network access by a user terminal in a data service network;

[0046] Figure 3 A flow chart for requesting access to the network for a user terminal in an emergency network;

[0047] Figure 4 Establish a flow chart for user terminal and emergency private network conversation;

[0048] Figure 5 This is the architecture diagram of the authentication system. DETAILED DESCRIPTION

[0049] The drawings are for illustrative purposes only and should not be construed as limiting the present patent;

[0050] In order to better illustrate the present embodiment, some parts in the drawings may be omitted, enlarged or reduced, and do not represent the size of the actual product;

[0051] It is understandable to those skilled in the art that some well-known structures and their descriptions may be omitted in the drawings.

[0052] The technical solution of the present invention is further described below in conjunction with the accompanying drawings and embodiments.

[0053] Example 1

[0054] This embodiment proposes an authentication method, see Figure 1 , applied to data service networks, which are dedicated data networks established, owned, managed and used by enterprises, organizations or departments to meet their own needs, including:

[0055] After the core network side receives the user terminal's request to access the data service private network and completes an authentication, a user plane data channel is established between the user terminal side and the core network side; wherein the core network includes AUSF network elements, SMF network elements, UPF network elements and AAA network elements; the SMF network elements include ATLF modules;

[0056] The core network obtains user terminal information, matches the user terminal information with the pre-planned access resource information, and determines whether to exempt the user terminal from secondary authentication based on the matching result:

[0057] If the user terminal information belongs to the pre-planned access resource information, the core network side exempts the user terminal from performing secondary authentication and establishes a connection between the user terminal and the data service dedicated network;

[0058] If the user terminal information does not belong to the pre-planned access resource information, the core network side does not exempt the user terminal from secondary authentication; wherein the user terminal information includes the TAC subscribed by the user terminal and the DNN carried.

[0059] In this embodiment, matching user terminal information with pre-planned access resource information can be regarded as the core network side comparing user terminal information with its pre-stored credit information set to determine whether the user terminal is a trusted device and request access through the planned data service dedicated network.

[0060] In the specific implementation process, when the user terminal is identified as a trusted device by the core network side and requests to access the network through the planned data service private network, the core network side does not need to perform secondary authentication for the user terminal, and directly establishes a connection between the user terminal and the data service private network; when the user terminal does not meet the trust conditions, the core network side directly rejects the user terminal's request to access the data service private network or forces secondary authentication. Under the premise of ensuring the security of data service network communication, the overall response efficiency of the data service network is improved, and network resources are saved to a certain extent.

[0061] As a preferred embodiment, after the core network side confirms that the user terminal is not exempted from performing secondary authentication, the core network side directly denies the user terminal access to the data service network.

[0062] As another preferred embodiment, after the core network side confirms that the user terminal is not exempted from secondary authentication, the core network side performs secondary authentication on the user terminal.

[0063] As a preferred embodiment, the pre-planned access resource information includes:

[0064] The dedicated DNN for the data service network signed by the SIM card of the credit communication terminal is denoted as DNN SP ;

[0065] A temporary TAC used to temporarily configure a data service private network base station, the number of which is denoted as w, and the temporary TAC is denoted as τ j ', j = [1, 2, ..., w], that is, τ j '∈T'={τ1',τ2',…,τ w '}.

[0066] As a preferred embodiment, the user terminal information also includes but is not limited to IP address, IMEI, IMSI, MSISDN, and ULI.

[0067] As an alternative embodiment, see Figure 2 The core network side obtains user terminal information and matches the user terminal information with pre-planned access resource information, which is achieved through the following steps:

[0068] First, the SMF network element on the core network side instructs the UPF network element to send user terminal information to the ATLF module; the DNN signed by the user terminal in the user terminal information is recorded as DNN UE, the TAC carried by the user terminal is denoted as τ UE ;

[0069] Secondly, the ATLF module determines the DNN UE With DNN SP Is it consistent and τ UE Belongs to T':

[0070] If DNN UE ≠DNN SP , output secondary authentication type S k To refuse authentication;

[0071] If DNN UE =DNN SP , and τ UE ∈T', output secondary authentication type S k It is exempt from authentication;

[0072] If DNN UE =DNN SP ,and Output secondary authentication type S k Authentication is required;

[0073] Then, the ATLF module will output the secondary authentication type S k Sent to the SMF network element, the SMF network element according to the secondary authentication type S k Determine whether to exempt the user terminal from secondary authentication.

[0074] As a non-limiting example, the SMF network element on the core network side instructs the UPF network element to send user terminal information to the ATLF module, specifically: the SMF network element instructs the UPF network element to establish a user plane data channel for the user terminal, and sends the user terminal's IP address, TAC, DNN and other information to the ATLF module.

[0075] In the specific implementation process, when the ATLF module determines that DNN UE =DNN SP When the ATLF module τ UE ∈T', it is recognized that the user terminal requests access to the data service private network through the trusted base station; if and only if the DNN signed by the user terminal is a DNN dedicated to the data service private network, and the TAC it carries is an element of the temporary TAC set T' of the temporary configuration of the data service private network base station, the core network side exempts the user terminal from performing secondary authentication, that is, the SMF network element does not communicate with the AAA network element to perform secondary authentication for the user terminal.

[0076] Furthermore, if the user terminal information belongs to the pre-planned access resource information, the user terminal is exempted from performing secondary authentication and a connection between the user terminal and the data service private network is established, specifically:

[0077] If the SMF network element receives the secondary authentication type S k In order to avoid authentication, the SMF network element sends a request to the UPF network element to establish a connection for the user terminal to the data service private network; the UPF network element responds to the connection request and establishes a connection channel between the user terminal and the data service private network.

[0078] In particular, if the user terminal information does not belong to the pre-planned access resource information, the core network side does not exempt the user terminal from performing secondary authentication, including:

[0079] If the SMF network element receives the secondary authentication type S k To reject authentication, the SMF network element directly rejects the user terminal's access to the data service network;

[0080] If the SMF network element receives the secondary authentication type S k To ensure that authentication is required, the SMF network element forwards a secondary identity authentication message to the AAA network element and establishes an authentication channel between the user terminal and the AAA network element; the secondary identity authentication message includes DNN UE , and also includes one or more of IMSI (International Mobile Subscriber Identity), IMEI (International Mobile Equipment Identity), MSISDN (Mobile Subscriber Integrated Services Digital Number), and ULI (User Location Information) carried by the user terminal.

[0081] In a specific implementation process, when the ATLF module on the core network side outputs the secondary authentication type S to the SMF network element k After refusing authentication, the SMF network element directly denies the user terminal access to the data service network.

[0082] In another specific implementation process, when the ATLF module on the core network side outputs the secondary authentication type S to the SMF network element k After authentication is required, the SMF network element forwards the secondary identity authentication message to the AAA network element and establishes an authentication channel between the user terminal and the AAA network element.

[0083] Optionally, the AAA network element performs secondary authentication on the user terminal and outputs the secondary authentication result r p After the SMF network element, it also includes:

[0084] When the SMF network element receives the secondary authentication result r p When the authentication is passed, the SMF network element sends a request to the UPF network element to establish a connection for the user terminal to the data service private network. The UPF network element responds to the connection request and establishes a connection channel between the user terminal and the data service private network.

[0085] When the SMF network element receives the secondary authentication result r p When the authentication fails, the SMF network element denies the user terminal access to the data service network.

[0086] Example 2

[0087] This embodiment proposes an authentication method, see Figure 1 , Figure 3 , Figure 4 , applied to emergency dedicated networks, including:

[0088] TAC deployment and private network contract signing;

[0089] After the core network side receives the user terminal's request to access the emergency private network and completes an authentication, a user plane data channel is established between the user terminal side and the core network side; wherein the core network includes AUSF network elements, SMF network elements, UPF network elements and AAA network elements; the SMF network elements include ATLF modules;

[0090] The core network obtains user terminal information, matches the user terminal information with the pre-planned access resource information, and determines whether to exempt the user terminal from secondary authentication based on the matching result:

[0091] If the user terminal information belongs to the pre-planned access resource information, the core network side exempts the user terminal from performing secondary authentication and establishes a connection between the user terminal and the emergency private network;

[0092] If the user terminal information does not belong to the pre-planned access resource information, the core network side does not exempt the user terminal from secondary authentication; wherein the user terminal information includes the TAC subscribed by the user terminal and the DNN carried.

[0093] As a non-limiting example, the TAC deployment includes TAC pre-planning and emergency base station TAC configuration.

[0094] TAC pre-planning is to pre-plan n special TACs for temporary configuration of emergency base stations, and any special TAC is denoted as τ i ∈T={τ1, τ2, τ3,…,τn}, i∈{1, 2, 3,..., n}.

[0095] The TAC configuration of the emergency base station is specifically as follows: when an emergency such as a fire or air raid occurs, the area with emergency communication support requirements radiated by the emergency is denoted as A, and the m emergency base stations within the service range of area A are denoted as b. j ∈B={b1, b2, b3,…, b m According to the radiation range of the m emergency base stations, an appropriate number of currently available special TACs are selected from the pre-planned set T to configure the emergency base stations in the set B. The number of selected temporary TACs is denoted as w, and the w temporary TACs are denoted as τ j '∈T'={τ1',τ2',…,τ w '}.

[0096] As a non-limiting example, the private network contract is specifically a DNN dedicated to the emergency private network contract for the SIM card of the emergency communication terminal (ie, the credit terminal), recorded as DNN SP .

[0097] In a specific implementation process, after the core network side receives a request from a user terminal to access the emergency private network and completes an authentication, a user plane data channel is established between the user terminal side and the core network side, including:

[0098] S21. The user terminal initiates a network access request, triggering an authentication process; the DNN signed by the user terminal is recorded as DNN UE , the TAC it carries is denoted as τ UE ;

[0099] S22. The SMF network element instructs the UPF network element to establish a user plane data channel for the user terminal.

[0100] In a specific implementation process, the core network side obtains user terminal information, specifically: the SMF network element instructs the UPF network element to send the IP address, TAC, DNN and other information of the user terminal to the ATLF module.

[0101] As a non-limiting example, matching the user terminal information with the pre-planned access resource information, and determining whether to exempt the user terminal from secondary authentication according to the matching result, includes:

[0102] S23, ATLF module determines the secondary authentication type S of the user terminal according to the user terminal information k , S k ∈S={s1,s2,s3}, its expression is as follows:

[0103]

[0104] In a specific implementation process, S k The steps for determining the value of are as follows:

[0105] When DNN UE ≠DNN SP When k=3, the ATLF module outputs S k =S3=Authentication refused;

[0106] When DNN UE =DNN SP When further judgment: If τ UE ∈T', then let k = 1, then the ATLF module outputs S k =S1= authentication-free; if Then let k = 2, then the ATLF module outputs S k =S2=Authentication is required.

[0107] As a non-limiting example, the determining whether to exempt the user terminal from performing secondary authentication according to the matching result includes:

[0108] S24, ATLF module records S k , S k Send to SMF network element;

[0109] S25, SMF network element receives S k , initiate a secondary authentication request, skip the secondary authentication request, or deny the user terminal access to the emergency private network.

[0110] In a specific implementation process, the SMF network element receives the S sent by the ATLF module. k If the value is authentication-free, the SMF network element initiates a request to skip the secondary authentication and directly sends a request to the UPF network element to establish a connection for the user terminal to the emergency private network; the UPF network element responds to the connection request and establishes a connection channel between the user terminal and the emergency private network.

[0111] In another specific implementation process, the SMF network element receives the S sent by the ATLF module. k The value is required for authentication, the SMF network element forwards the secondary identity authentication message to the AAA network element, and establishes an authentication channel between the user terminal and the AAA network element. The secondary identity authentication message includes the DNN carried by the user terminal. UE , IMSI, IMEI, MSISDN and ULI.

[0112] Furthermore, the secondary identity authentication message also includes an IP address.

[0113] Further, the AAA network element performs secondary authentication on the user terminal according to the received secondary identity authentication message, and outputs the secondary authentication result r p To SMF network element; where r p ∈R={r1,r2}, the values ​​are as follows:

[0114]

[0115] In particular, when r p= r1 is r p When the value is passed, the SMF network element sends a request to the UPF network element to establish an emergency private network for the user terminal. The UPF network element responds to the connection request and establishes a connection channel between the user terminal and the emergency private network. p= r2 is r p When the value is authentication failure, the SMF network element denies the user terminal access to the emergency private network.

[0116] In another specific implementation process, the SMF network element receives the S sent by the ATLF module. k If the value is authentication rejection, the SMF network element directly rejects the user terminal's access to the emergency private network.

[0117] Example 3

[0118] This embodiment proposes an authentication system, see Figure 5 , applied to the authentication method proposed in Example 1 or Example 2.

[0119] An authentication system includes a core network side and a data service private network, wherein the core network side includes an AUSF network element, an SMF network element, an UPF network element and an AAA network element, and the SMF network element includes an ATLF module. The ATLF module is configured to match the acquired user terminal information with the pre-planned access resource information, determine, record and output the secondary authentication type S k ; Wherein, the user terminal information includes the DNN signed by the user terminal requesting access to the data service private network and the TAC it carries, the pre-planned access resource information includes the dedicated DNN for the data service private network signed by the SIM card of the credit communication terminal and the temporary TAC used to temporarily configure the base station of the data service private network, and the output secondary authentication type S k It includes one of the following: authentication rejection, authentication exemption, and authentication required.

[0120] like Figure 5As shown, it is an architecture diagram of the authentication system of this embodiment, which includes UE (User Equipment), RAN (Radio Access Network), AMF (Authentication Management Function) network element, AUSF (Authentication Server Function) network element, SMF (Session Management Function) network element, UDM (Unified Data Management) network element, UPF (User Plane Function) network element and AAA (Authentication Authorization Accounting) network element.

[0121] As a preferred embodiment, if the secondary authentication type S output by the ATLF module k In order to exempt or refuse authentication, the SMF network element does not communicate with the AAA network element; if the secondary authentication type S output by the ATLF module k To ensure authentication, the SMF network element communicates with the AAA network element.

[0122] The same or similar reference numerals correspond to the same or similar components;

[0123] The terms used in the drawings to describe positional relationships are only used for illustrative purposes and should not be construed as limiting this patent;

[0124] Obviously, the above embodiments of the present invention are merely examples for clearly illustrating the present invention, and are not intended to limit the embodiments of the present invention. For those skilled in the art, other different forms of changes or modifications can be made based on the above description. It is not necessary and impossible to list all the embodiments here. Any modifications, equivalent substitutions and improvements made within the spirit and principles of the present invention should be included in the protection scope of the claims of the present invention.

Claims

1. An authentication method, applied to a data service network, characterized in that: The method comprises: After the core network side receives the user terminal's request to access the data service private network and completes an authentication, a user plane data channel is established between the user terminal side and the core network side; wherein the core network includes AUSF network elements, SMF network elements, UPF network elements and AAA network elements; the SMF network elements include ATLF modules; The core network obtains user terminal information, matches the user terminal information with the pre-planned access resource information, and determines whether to exempt the user terminal from secondary authentication based on the matching result: If the user terminal information belongs to the pre-planned access resource information, the core network side exempts the user terminal from performing secondary authentication and establishes a connection between the user terminal and the data service dedicated network; If the user terminal information does not belong to the pre-planned access resource information, the core network side does not exempt the user terminal from performing secondary authentication; wherein the user terminal information includes the DNN subscribed by the user terminal and the carried TAC; After the core network side does not exempt the user terminal from performing secondary authentication, any of the following steps is performed: (1) The core network directly denies the user terminal access to the data service network; (2) The core network performs secondary authentication on the user terminal; The pre-planned access resource information includes: a dedicated DNN for a data service private network subscribed by a SIM card of a credit communication terminal, denoted as DNN SP ; and, a temporary TAC for temporarily configuring a data service private network base station, the number of which is denoted as w, and the temporary TAC is denoted as τ j ', j = [1, 2, ..., w], that is, τ j '∈T'={τ1',τ2',…,τ w '};as well as, The core network side obtains user terminal information and matches the user terminal information with pre-planned access resource information, the steps of which include: The SMF network element instructs the UPF network element to send user terminal information to the ATLF module; the DNN signed by the user terminal in the user terminal information is recorded as DNN UE , the TAC carried by the user terminal is denoted as τ UE ; ATLF module judges DNN UE With DNN SP Is it consistent and τ UE Whether it belongs to T': If DNN UE ≠DNN SP , output secondary authentication type S k To refuse authentication; if DNN UE =DNN SP , and τ UE ∈T', output secondary authentication type S k If DNN UE =DNN SP ,and Output secondary authentication type S k Authentication is required; The ATLF module will output the secondary authentication type S k Sent to the SMF network element, the SMF network element according to the secondary authentication type S k Determine whether to exempt the user terminal from performing secondary authentication; and If the user terminal information belongs to the pre-planned access resource information, exempting the user terminal from performing secondary authentication and establishing a connection between the user terminal and the data service private network includes: If the SMF network element receives the secondary authentication type S k In order to avoid authentication, the SMF network element sends a request to the UPF network element to establish a connection for the user terminal to the data service private network; the UPF network element responds to the connection request and establishes a connection channel between the user terminal and the data service private network; the SMF network element does not communicate with the AAA network element.

2. An authentication method according to claim 1, characterized in that: If the user terminal information does not belong to the pre-planned access resource information, the core network side does not exempt the user terminal from performing secondary authentication, including: If the SMF network element receives the secondary authentication type S k To reject authentication, the SMF network element directly rejects the user terminal's access to the data service private network; If the SMF network element receives the secondary authentication type S k To ensure that authentication is required, the SMF network element forwards a secondary identity authentication message about the user terminal to the AAA network element and establishes an authentication channel between the user terminal and the AAA network element; the secondary identity authentication message includes DNN UE , and also includes one or more of IMSI, IMEI, MSISDN, and ULI carried by the user terminal.

3. An authentication method according to claim 2, characterized in that: After the SMF network element forwards the secondary identity authentication message to the AAA network element and establishes an authentication channel between the user terminal and the AAA network element, the method further includes: According to the received secondary identity authentication message, the AAA network element performs secondary authentication on the user terminal and outputs the secondary authentication result r p To the SMF network element; wherein the secondary authentication result r p This includes either passing the certification or failing the certification.

4. An authentication method according to claim 3, characterized in that: The AAA network element performs secondary authentication on the user terminal and outputs the secondary authentication result r p After the SMF network element, it also includes: When the SMF network element receives the secondary authentication result r p When the authentication is passed, the SMF network element sends a request to the UPF network element to establish a connection to the data service private network for the user terminal. The UPF network element responds to the connection request and establishes a connection channel between the user terminal and the data service private network. When the SMF network element receives the secondary authentication result r p When the authentication fails, the SMF network element denies the user terminal access to the data service private network.

5. An authentication system, applied to an authentication method according to any one of claims 1 to 4, comprising a core network and a data service private network, wherein the core network side comprises an AUSF network element, an SMF network element, a UPF network element and an AAA network element, characterized in that: The SMF network element includes an ATLF module; The ATLF module is configured to match the acquired user terminal information with the pre-planned access resource information, determine, record and output the secondary authentication type S k ; Wherein, the user terminal information includes the DNN signed by the user terminal requesting access to the data service private network and the TAC it carries, the pre-planned access resource information includes the dedicated DNN for the data service private network signed by the SIM card of the credit communication terminal and the temporary TAC used to temporarily configure the data service private network base station, and the secondary authentication type S output by the ATLF module k It includes one of the following: authentication rejection, authentication exemption, and authentication required; wherein, If the secondary authentication type S output by the ATLF module k In order to exempt or refuse authentication, the SMF network element does not communicate with the AAA network element; if the secondary authentication type S output by the ATLF module k To ensure authentication, the SMF network element communicates with the AAA network element.

Citation Information

Patent Citations

  • Private network registration management method and AMF network element

    CN112423301A

  • Authentication and authorization method and device

    CN113784346A