Authentication method, device, communication equipment and readable storage medium

By authorizing and authenticating the administrator before sending the policy, and using the GBA authentication process and session key encryption, the security issue of sending policies from the physical network to the twin network is resolved, achieving higher policy transmission security and reliability.

CN116232620BActive Publication Date: 2025-10-03CHINA MOBILE COMM LTD RES INST +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202111477116.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-12-06
Publication Date
2025-10-03
Estimated Expiration
2041-12-06

AI Technical Summary

Technical Problem

In the existing technology, the security of the physical network when sending policies to the twin network is low.

Method used

Before the policy is sent, the administrator is authorized and the legitimacy is authenticated. The general authentication mechanism GBA authentication process is used to ensure the legitimacy of the administrator. The session key is used for encryption and decryption to improve the security of policy sending.

Benefits of technology

Through the authorization and authentication of policies, the security and reliability of policy transmission are improved, and illegal or unauthorized policy transmission is prevented.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116232620B_ABST
    Figure CN116232620B_ABST
Patent Text Reader

Abstract

The present application provides an authentication method, apparatus, communication equipment and readable storage medium. The method includes: receiving a policy request message sent by a second network side device in a physical network, the policy request message is used to request the first network side device to send a policy to the second network side device; calling a core network device to send a notification message to a target terminal, the notification message is used to notify the authorization of the target policy, and the target terminal is determined based on the administrator information corresponding to the target policy; receiving a target authorization authentication request message sent by the target terminal when receiving an authorization confirmation for the target policy; and when the authorization authentication passes, sending a target policy generated based on the policy request message to the second network side device. The present application can improve the security of policy transmission.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The embodiments of the present application relate to the field of communication technology, and in particular to an authentication method, apparatus, communication device, and readable storage medium. Background Art

[0002] A Digital Twin Network (DTN) is a network system that consists of a physical network entity and a virtual twin, with the two interacting and mapping in real time. When the physical network and the twin interact, the physical network applies a policy to the twin network, and the twin network generates the corresponding policy and then sends it to the physical network. This makes policy transmission less secure. Summary of the Invention

[0003] The embodiments of the present application provide an authentication method, apparatus, communication device, and readable storage medium to solve the problem of low security in existing policy sending.

[0004] To solve the above problems, this application is implemented as follows:

[0005] In a first aspect, an embodiment of the present application provides an authentication method, which is applied to a first network-side device in a twin network, including:

[0006] In a second aspect, an embodiment of the present application provides an authentication method, applied to a target terminal, comprising:

[0007] In a third aspect, an embodiment of the present application further provides an authentication device, which is applied to a first network-side device in a twin network, including:

[0008] In a fourth aspect, an embodiment of the present application further provides an authentication device, applied to a target terminal, comprising:

[0009] In the fifth aspect, an embodiment of the present application also provides a communication device, comprising: a transceiver, a memory, a processor, and a program stored in the memory and runnable on the processor; the processor is used to read the program in the memory to implement the steps in the method described in the first aspect above; or, the steps in the method described in the second aspect above.

[0010] In a sixth aspect, an embodiment of the present application further provides a readable storage medium for storing a program, which, when executed by a processor, implements the steps of the method described in the first aspect, or implements the steps of the method described in the second aspect.

[0011] In an embodiment of the present application, before the twin network sends its requested policy to the physical network, the policy will be authorized and the legitimacy of the authorization will be authenticated. The twin network will only send the policy if the authorization and authentication are passed, thereby improving the security of policy sending. BRIEF DESCRIPTION OF THE DRAWINGS

[0012] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the following briefly introduces the drawings required for use in the description of the embodiments of the present application. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without any creative work.

[0013] Figure 1 This is one of the structural diagrams of the network system to which the embodiments of the present application can be applied;

[0014] Figure 2 This is the second structural diagram of a network system applicable to the embodiments of the present application;

[0015] Figure 3 This is one of the flow charts of the authentication method provided in the embodiment of the present application;

[0016] Figure 4 This is the second flow chart of the authentication method provided in the embodiment of the present application;

[0017] Figure 5 This is the third flow chart of the authentication method provided in the embodiment of the present application;

[0018] Figure 6 This is a schematic diagram of the GBA authentication process provided in an embodiment of the present application;

[0019] Figure 7 This is one of the structural diagrams of the authentication device provided by the implementation of this application;

[0020] Figure 8 This is the second structural diagram of the authentication device provided by the present application;

[0021] Figure 9 It is a structural diagram of the communication equipment provided by the implementation of this application. DETAILED DESCRIPTION

[0022] The following will be combined with the drawings in the embodiments of this application to clearly and completely describe the technical solutions in the embodiments of this application. Obviously, the embodiments described are part of the embodiments of this application, not all of them. Based on the embodiments in this application, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of this application.

[0023] The terms "first", "second" etc. in the embodiments of the present application are used to distinguish similar objects, and are not necessarily used to describe a specific order or sequential order. In addition, the terms "comprise" and "have" and any deformation thereof are intended to cover non-exclusive inclusions, such as, the process, method, system, product or equipment comprising a series of steps or units need not be limited to those steps or units clearly listed, but may include other steps or units that are not clearly listed or that are intrinsic to these processes, methods, products or equipment. In addition, "and / or" is used in the present application to represent at least one of connected objects, such as A and / or B and / or C, and represents comprising independent A, independent B, independent C, and A and B all exist, B and C all exist, A and C all exist, and 7 situations that A, B and C all exist.

[0024] See Figure 1 , Figure 1 This is a structural diagram of a network system to which the embodiments of the present application can be applied, such as Figure 1 As shown, it includes a first network side device 11 in a twin network (also called a digital twin network), a second network side device 12 in a physical network, a terminal 13 and a core network device 14.

[0025] In a specific implementation, the second network-side device 12 may send a policy application to the first network-side device 11. The first network-side device 11 may generate a corresponding policy in response to the policy application.

[0026] Before the first network-side device 11 sends a policy to the second network-side device 12, the administrator corresponding to the policy may first authorize the policy through the terminal 13. If the administrator's authorization is successful, that is, the administrator has authorized the policy to be sent, the first network-side device 11 may authenticate the legitimacy of the administrator's authorization. If the authentication is successful, that is, the first network-side device 11 authenticates the legitimacy of the administrator's authorization, the first network-side device 11 may send the generated corresponding policy to the second network-side device. Otherwise, the first network-side device 11 may not send the corresponding policy, thereby improving the reliability of policy transmission.

[0027] During implementation, the first network side device 11 and the terminal 13 can authenticate the legitimacy of the administrator's authorization through a generic authentication mechanism (Generic Bootstrapping Architecture, GBA) authentication process, and the authentication process may involve interaction between the first network side device 11, the terminal 13 and the core network device 14.

[0028] In one embodiment, Figure 2As shown, the first network-side device 11 may be a Policy Distribution Entity (PDF). The second network-side device 12 may be a Physical Network Element (PNE). The core network device 14 may be an Evolved Packet Core (EPC), which may include a Bootstrapping Server Function (BSF), a Short Message Service Center (SMSC), and a Home Subscriber Server (HSS).

[0029] exist Figure 2 In the Authentication and Authorization Security Tunnel (AAT), an authentication and authorization security tunnel is established between the PDE and an administrator group, including at least one terminal. This tunnel enables policy authorization and authentication. Once authorization and authentication are successful, the PDE sends the policy to the PNE via the Distribute Entity (DE). During the policy transmission process, the PDE and DE can encrypt and decrypt the policy via the Key Distribution Center (KDC), further enhancing the security of policy transmission.

[0030] It should be noted that, in other implementations, the first network-side device 11, the second network-side device 12, and the core network device 14 may also be in other forms, which is not limited in the embodiments of the present application.

[0031] The following describes the authentication method provided in the embodiments of the present application.

[0032] See also Figure 3 , Figure 3 This is one of the flow charts of the authentication method provided in the embodiment of the present application. Figure 3 The authentication method shown can be applied to the first network-side device in a twin network.

[0033] like Figure 3 As shown, the authentication method may include the following steps:

[0034] Step 301: Receive a policy request message sent by a second network-side device in a physical network, where the policy request message is used to request the first network-side device to send a policy to the second network-side device.

[0035] In a specific implementation, the policy request message may include identification information (Element ID) of the second network side device, so that the first network side device can know the device requesting the policy.

[0036] After receiving the policy request message, the first network-side device may generate a target policy and determine the administrator corresponding to the target policy, that is, the administrator who authorizes the target policy, and then obtain administrator information corresponding to the target policy, where the administrator information may include at least one of the following: an international mobile subscriber identity (IMSI) corresponding to the administrator; and an international mobile equipment identity (IMEI) corresponding to the administrator.

[0037] During implementation, the first network side device can determine the administrator corresponding to the target policy through the target identification information, wherein the target identification information includes at least one of the following: the identification information of the second network side device carried in the policy request message; the identification information of the target policy.

[0038] When the target identification information includes the identification information of the second network-side device, a first correspondence between each network-side device or each network-side device type in the physical network and the administrator can be preset. Therefore, in this case, different administrators can only authorize policies requested by specified network-side devices or network-side device types (i.e., their corresponding network-side devices or network-side device types), thereby further improving the reliability of policy transmission.

[0039] In the case where the target identification information includes identification information of the target policy, a second correspondence between each policy or policy type and an administrator can be preset. Thus, in this case, different administrators can only authorize specified policies or policy types (i.e., their corresponding policies or policy types), thereby further improving the reliability of policy transmission.

[0040] When the target identification information includes the identification information of the second network-side device and the identification information of the target policy, a third correspondence between each network-side device (or each network-side device type), each policy (or each policy type), and the administrator in the physical network can be preset. In this case, different administrators can only authorize network-side devices in a specific physical network, specific policies, or policy types, thereby further improving the reliability of policy transmission.

[0041] Step 302: Invoke the core network device to send a notification message to the target terminal, where the notification message is used to notify authorization of the target policy. The target terminal is determined based on administrator information corresponding to the target policy.

[0042] In a specific implementation, if the administrator information includes IMSI, the terminal with the target card installed can be determined as the target terminal, and the identification information of the target card is the IMSI. If the administrator information includes IMEI, the terminal with the identification information being IMEI can be determined as the target terminal.

[0043] The first network side device may call a target core network function and send a notification message to the target terminal through the entity where the target core network function is located, so as to notify the administrator corresponding to the target policy to authorize the target policy.

[0044] After receiving the notification message, the target terminal may output authorization information, where the authorization information may include at least one of the following: identification information of the second network-side device and identification information of the target policy. This allows an administrator using the target terminal to authorize the target policy based on the authorization information, i.e., to confirm whether to allow the first network-side device to send the target policy to the second network-side device.

[0045] If the second condition is met, the administrator using the target terminal can authorize and confirm, i.e., authorize and approve, that is, allow the first network side device to send the target policy to the second network side device; otherwise, the administrator can deny authorization, i.e., authorize and reject, that is, not allow the first network side device to send the target policy to the second network side device. The second condition may include at least one of the following:

[0046] Allowing the second network side device or the network side device type to which the second network side device belongs to request a policy;

[0047] The security level of the target policy or the policy type to which the target policy belongs is low;

[0048] The second network-side device or the network-side device type to which the second network-side device belongs is allowed to request the target policy or the policy type to which the target policy belongs.

[0049] Step 303: Receive a target authorization authentication request message sent by the target terminal after receiving authorization confirmation of the target policy.

[0050] When the administrator corresponding to the target policy approves the authorization of the target policy, the target terminal can send an authorization authentication request message to the first network side device so that the first network side device can authenticate the legitimacy of the administrator's authorization, thereby improving the security of policy sending.

[0051] During implementation, the target authorization and authentication request message can be an ordinary authorization and authentication request message without confidentiality protection and integrity protection, or it can be an authorization and authentication request message with confidentiality protection and / or integrity protection. The specific details can be determined based on actual conditions, and the embodiments of the present application do not limit this.

[0052] Step 304: If the authorization authentication is passed, send the target policy generated based on the policy request message to the second network side device.

[0053] After receiving the target authorization authentication request message, the first network side device may authenticate the legitimacy of the authorization in any manner.

[0054] If the authorization is determined to be legitimate, the authorization authentication may be determined to be successful, and the target policy may be sent to the second network-side device. If the authorization is determined to be invalid, the authorization authentication may be determined to be unsuccessful, and the target policy may not be sent to the second network-side device. This improves the security of policy transmission.

[0055] The authentication method of the embodiment of the present application authorizes the policy and authenticates the legitimacy of the authorization before the twin network sends the requested policy to the physical network. The twin network will only send the policy if the authorization and authentication are passed, thereby improving the security of policy sending.

[0056] Optionally, the target authorization authentication message is a first authorization authentication request message, and the first authorization authentication request message includes first encrypted information and second encrypted information, wherein the first encrypted information is obtained by the target terminal encrypting first information using a first session key, and the first information includes the second authorization authentication request message; the second encrypted information is obtained by the target terminal encrypting second information using a second session key, and the second information is obtained by digesting the second authorization authentication request message;

[0057] The sending the target policy to the second network side device when the authorization authentication is passed includes:

[0058] Decrypting the first encrypted information and the second encrypted information respectively using the session key obtained from the core network device;

[0059] If the first encrypted information and the second encrypted information are successfully decrypted, determining that the first authorization and authentication request message is sent by the terminal with the target IMSI installed, and sending the target policy to the second network-side device;

[0060] The target IMSI is the IMSI corresponding to the target policy.

[0061] In this optional implementation manner, the second authorization and authentication request message is a common authorization and authentication request message, and the first authorization and authentication request message is an authorization and authentication request message that has been subjected to confidentiality protection and integrity protection.

[0062] In a specific implementation, the target terminal encrypts the second authorization and authentication request message using the first session key to obtain first encrypted information, thereby protecting the confidentiality of the second authorization and authentication request message. The target terminal digests the second authorization and authentication request message, then encrypts the digested request message using the second session key to obtain second encrypted information, thereby protecting the integrity of the second authorization and authentication request message, thereby improving the reliability of authorization and authentication.

[0063] The first network-side device can obtain a session key from the core network device and then use the obtained session key to decrypt the first encrypted information and the second encrypted information. If the decryption of the first encrypted information and the second encrypted information is successful, it indicates that the first network-side device has obtained the first session key and the second session key from the core network device, and the first authorization authentication request message is sent by the IMSI corresponding to the installed target policy. Therefore, authentication is successful, and the target policy is sent to the second network-side device.

[0064] Through the above method, the first network side device can use the session key from the core network device to decrypt the first authorization and authentication request message that has been confidentiality protected and integrity protected, and after successful decryption, send the target policy to the second network side device, thereby improving the reliability of authorization and authentication, and further improving the security of policy sending.

[0065] Optionally, after calling the core network device to send a notification message to the target terminal and before receiving a target authorization authentication request message sent by the target terminal when the target terminal receives authorization confirmation of the target policy, the method further includes:

[0066] Receiving the first authorization and authentication request message sent by the target terminal;

[0067] Sending first indication information to the target terminal, where the first indication information is used to instruct to initiate a general authentication mechanism GBA authentication process;

[0068] receiving a second service request message corresponding to the GBA authentication process sent by the target terminal, where the second service request message includes third identification information corresponding to the GBA authentication process;

[0069] Obtaining a session key from the core network device using the third identification information;

[0070] In the case where the session key is successfully obtained, second indication information is sent to the target terminal, where the second indication information is used to indicate the completion of the GBA authentication process.

[0071] In this optional implementation, authentication of authorization legitimacy is achieved through the GBA authentication process.

[0072] In a specific implementation, after authorization confirmation, the administrator using the target terminal may send the first authorization authentication request message to the first network side device, so that the first network side device authenticates the legitimacy of the authorization.

[0073] After receiving the first authorization and authentication request message, the first network-side device may instruct the terminal to initiate a GBA process to achieve session key sharing and establish a secure channel between the target terminal and the first network-side device through the GBA process. This can improve the security of the authorization and authentication request message and the security of authorization and authentication.

[0074] After the target terminal initiates the GBA authentication process, an Authentication and Key Agreement (AKA) challenge can be performed between the target terminal and the core network device to complete the target terminal's authentication of the network layer and the network layer's authentication of the UE. The UE and BSF both generate a target key, denoted as the Ks key. The target terminal can obtain third identification information corresponding to the GBA authentication process, such as the session-transaction identifier (B-TID). It is understood that different session keys are generated for different GBA authentication processes, thereby further ensuring the security of authorization and authentication.

[0075] After executing the AKA challenge, both the target terminal and the core network device can derive the first session key and the second session key based on the target key.

[0076] Because the GBA authentication process has not yet been completed, the target terminal can send the third identification information to the first network-side device, so that the first network-side device can obtain the first session identifier and the second session identifier from the core network device using the third identification information, thereby completing the GBA authentication process. This can improve the security of the first network-side device in obtaining the session key, thereby improving the reliability of authorization and authentication.

[0077] Optionally, the first information may further include at least one of the following: the International Mobile Equipment Identity (IMEI) of the target terminal; facial information f1 collected by a camera of the target terminal;

[0078] The sending the target policy to the second network-side device includes:

[0079] When the first condition is met, sending the target policy to the second network-side device;

[0080] The first condition includes at least one of the following:

[0081] The IMEI is the IMSI bound to the target IMSI;

[0082] The facial information matches the facial information of the administrator corresponding to the target policy.

[0083] In this optional embodiment, the target terminal may encrypt the IMEI, f1, and the authorization request authentication message using the first session key to obtain the first encrypted information. After successfully decrypting the first encrypted information, the second network-side device may determine that the second authorization authentication request message is sent by the target IMSI corresponding to the target policy and obtain the IMEI and f1.

[0084] Afterwards, the first network side device can verify the binding relationship between IMSI and IMEI. If the IMEI obtained by decrypting the first encrypted information is the IMEI bound to the target IMSI, it can be determined that the second authorization authentication request message is sent by the target terminal corresponding to the target policy.

[0085] The first network side device can match the facial information obtained by decrypting the first encrypted information with the facial information of the administrator corresponding to the target policy collected in advance. If they match, it can be determined that the second authorization authentication request message is sent by the administrator corresponding to the target policy.

[0086] In this way, the user card, terminal and administrator that send the authorization authentication request message can be authenticated. If the authentication is successful, it means that the authorization of the target policy is legal, so the target policy can be sent, improving the security of policy sending.

[0087] See also Figure 4 , Figure 4 This is the second flow chart of the authentication method provided in the embodiment of the present application. The authentication method in the embodiment of the present application can be applied to the target terminal.

[0088] like Figure 4 As shown, the authentication method may include the following steps:

[0089] Step 401: Receive a notification message sent by a core network device, where the notification message is used to notify authorization of a target policy, where the target policy is a policy requested by a second network-side device in the physical network to be sent to a first network-side device in the twin network.

[0090] Step 402: Output the authorization information of the target policy;

[0091] Step 403: Upon receiving authorization confirmation of the target policy, send a target authorization authentication request message to the first network-side device.

[0092] In the authentication method of this embodiment, the target terminal can authorize the sending of the policy and can send an authorization authentication request to the first network side device so that the first network side device authenticates the legitimacy of the above authorization, thereby improving the security of policy sending.

[0093] Optionally, the sending a target authorization authentication request message to the first network-side device includes:

[0094] Encrypting first information using a first session key to generate first encrypted information, where the first information includes a first authorization and authentication request message;

[0095] Encrypting second information using a second session key to generate second encrypted information, where the second information is obtained by summarizing the first authorization authentication message;

[0096] A second authorization and authentication request message is sent to the first network-side device, where the second authorization and authentication request message includes the first encryption information and the second encryption information.

[0097] Optionally, upon receiving the authorization confirmation of the target policy, before encrypting the first information using the first session key, the method further includes:

[0098] Sending the first authorization and authentication request message to the first network side device;

[0099] Receiving first indication information sent by a core network device, where the first indication information is used to instruct initiation of a general authentication mechanism GBA authentication process;

[0100] A first service request message corresponding to the GBA authentication process is sent to the core network device, wherein the first service request includes an Internet Protocol Multimedia System Private User Identity (IMS Private User Identity, IMPI) of the target terminal;

[0101] Obtaining the target key and third identification information corresponding to the GBA authentication process;

[0102] generating the first session key and the second session key using the target key;

[0103] Sending a second service request message corresponding to the GBA authentication process to the first network side device, where the second service request message includes the third identification information;

[0104] Receive second indication information sent by the first network side device, where the second indication information is used to indicate completion of the GBA authentication process.

[0105] In this optional embodiment, the target terminal carries the IMPI in the service request of the GBA process to complete the sharing of the session key between the target terminal and the first network-side device. In this way, the first network-side device can confirm the IMSI in the target terminal and prevent other IMSIs from sending authorization and authentication request messages.

[0106] Optionally, the first information further includes at least one of the following: the International Mobile Equipment Identity (IMEI) of the target terminal; and facial information collected by a camera of the target terminal.

[0107] It should be noted that this embodiment is an implementation of the network side device corresponding to the above method embodiment, so reference may be made to the relevant description in the above method embodiment, and the same beneficial effects can be achieved. To avoid repetition, no further description will be given here.

[0108] The various optional implementation methods introduced in the embodiments of the present application can be implemented in combination with each other or separately if they do not conflict with each other, and the embodiments of the present application do not limit this.

[0109] For easier understanding, the following examples are provided:

[0110] In this embodiment of the present application, the physical network applies a policy to the twin network. After the application, the twin network generates the corresponding policy and then issues it to the physical network device. Before the policy is issued, the PDE can notify the relevant operators (or administrators), and the relevant operators can authenticate the relevant policies. An authentication and authorization security tunnel is established between the PDE and the operators.

[0111] The embodiment of the present application can achieve: operator authentication; authorization for policy issuance, and ultimately achieve secure policy issuance through DE.

[0112] The embodiment of the present application may include the following steps:

[0113] The physical device makes a security policy request to the twin network;

[0114] The twin network generates corresponding strategies and sends reminder information to relevant operators based on the device type and strategy type;

[0115] The operator initiates the authentication process and completes identity authentication with the PDE platform, and generates a session key with the platform;

[0116] The operation uses the session key to protect the confidentiality and integrity of the password and sends it to the PDE platform;

[0117] The platform completes password authentication, identity authentication and password authorization, and issues policies to physical devices.

[0118] like Figure 5 As shown, the authentication method of the embodiment of the present application may include the following steps:

[0119] Step 1: The physical network device (Network Element) initiates a network policy request to the PDE (twin network).

[0120] The network policy request may include an identifier (ElementID) of the physical device.

[0121] Step 2: PDE obtains administrator information of relevant policies.

[0122] During implementation, the twin network requires the policy administrator to authenticate and authorize the request, so the administrator information (such as IMSI) is obtained through the network device ID (Element ID) or other identification.

[0123] Step 3: PDE calls the core network function (such as SMSC).

[0124] Step 4: The EPC sends a notification message (eg, SMS) to the UE specified by the policy administrator.

[0125] Step 5: If the policy administrator determines that authorization is possible, the UE initiates a second authorization and authentication request to the PDE.

[0126] Step 6: The PDE instructs the UE to initiate the GBA authentication process.

[0127] Step 7: The UE initiates the GBA authentication process with the EPC, carrying the IMS Private User Identity (IMPI). The authentication and key agreement protocol (AKA) challenge is executed, completing the UE-to-network authentication and the network-to-UE authentication. Both the UE and the BSF generate the Ks key and save the B-TID.

[0128] Step 8: The UE derives session keys Ks_1 and Ks_2 using the Ks key.

[0129] Step 9: The UE initiates a service request to the PDE and carries the B-TID.

[0130] Step 10: PDE obtains session keys Ks_1 and Ks_2 from EPC through B-TID.

[0131] Step 11: The PDE responds to complete the GBA authentication process.

[0132] Step 12: The UE initiates an identification process to obtain the administrator's facial information f1.

[0133] Step 13: The UE uses Ks_1 to encrypt f1 and IMEI to generate ciphertext information S1 to protect the confidentiality of the message.

[0134] Step 14: The UE digests the request message and encrypts it with Ks_2 to generate D1, thus protecting the integrity of the message.

[0135] Step 15: The UE carries S1 and D1 and initiates a second authorization and authentication request to the PDE.

[0136] Step 16. PDE first uses Ks_2 to decrypt and verify D1 to ensure the integrity of the message. Then, it uses Ks_1 to decrypt and obtain f1 and IMEI to confirm that the message is sent by the specified IMSI. Then, it verifies the binding relationship between IMSI and IMEI to confirm that it is sent by the specified terminal UE. Finally, it uses f1 to verify the facial information to confirm that the policy administrator himself sent the message.

[0137] Step 17: PDE returns the configuration policy to the physical network.

[0138] In addition, the specific process of GBA between UE and PDE can be found in Figure 6 .exist Figure 6 In the PDE, the functions of the network application function entity (NAF) are integrated. The specific GBA process between the UE and the PDE can be found in the implementation of the GBA process in the relevant technology, which will not be repeated here.

[0139] The embodiments of this application include the following:

[0140] The PNE makes a policy request to the PDE. The PDE uses the administrator's UE to authorize the policy and uses the GBA method / process to protect the confidentiality and integrity of the information generated by the administrator's UE during the authorization process, and performs a verification process for the device-card binding.

[0141] The UE uses session keys Ks_1 and Ks_2 to protect the confidentiality and integrity of the authorization request message.

[0142] In the GBA process, since the UE requests the EPC to carry the IMPI and finally completes the sharing of the session key between the UE and the PDE, the PDE can confirm the IMSI in the UE and prevent other IMSIs from sending authorization request messages.

[0143] PDE analyzes IMSI and IMEI to ensure the binding of the phone and card.

[0144] PDE uses facial recognition information to ensure that the message is confirmed by the policy administrator himself.

[0145] The embodiment of the present application can issue network policies for digital twin networks through remote authentication and policy authorization by the administrator. Compared with the existing technology, the embodiment of the present application has the following beneficial effects:

[0146] Initiated by the platform, it can authenticate and authorize different policy administrators, that is, different administrators can manage different policies and authorize them;

[0147] The method of automatically generating session keys between the terminal and the network is used to protect the confidentiality and integrity of messages;

[0148] A new session key is generated during each authorization process, which effectively ensures the security of the authentication and authorization process.

[0149] Policy administrators and user terminals can be confirmed through machine-card binding information confirmation and face recognition confirmation to better protect security.

[0150] See also Figure 7 , Figure 7 This is one of the structural diagrams of the authentication device provided in the embodiment of this application. Figure 7 As shown, the authentication device 700 includes:

[0151] A first transceiver is configured to:

[0152] receiving a policy request message sent by a second network-side device in the physical network, wherein the policy request message is used to request the first network-side device to send a policy to the second network-side device;

[0153] Invoking a core network device to send a notification message to a target terminal, where the notification message is used to notify authorization of the target policy, and the target terminal is determined based on administrator information corresponding to the target policy;

[0154] receiving a target authorization authentication request message sent by the target terminal upon receiving authorization confirmation of the target policy;

[0155] If the authorization and authentication are successful, the target policy generated based on the policy request message is sent to the second network side device.

[0156] Optionally, the target authorization authentication message is a first authorization authentication request message, and the first authorization authentication request message includes first encrypted information and second encrypted information, wherein the first encrypted information is obtained by the target terminal encrypting first information using a first session key, and the first information includes the second authorization authentication request message; the second encrypted information is obtained by the target terminal encrypting second information using a second session key, and the second information is obtained by digesting the second authorization authentication request message;

[0157] The device further comprises:

[0158] A first processor is configured to:

[0159] Decrypting the first encrypted information and the second encrypted information respectively using the session key obtained from the core network device;

[0160] If the first encrypted information and the second encrypted information are successfully decrypted, determining that the first authorization and authentication request message is sent by the terminal with the target IMSI installed, and sending the target policy to the second network-side device through the first transceiver;

[0161] The target IMSI is the IMSI corresponding to the target policy.

[0162] Optionally, the first transceiver is further configured to:

[0163] Receiving the first authorization and authentication request message sent by the target terminal;

[0164] Sending first indication information to the target terminal, where the first indication information is used to instruct to initiate a general authentication mechanism GBA authentication process;

[0165] receiving a second service request message corresponding to the GBA authentication process sent by the target terminal, where the second service request message includes third identification information corresponding to the GBA authentication process;

[0166] Obtaining a session key from the core network device using the third identification information;

[0167] In the case where the session key is successfully obtained, second indication information is sent to the target terminal, where the second indication information is used to indicate the completion of the GBA authentication process.

[0168] Optionally, the first information further includes at least one of the following: the International Mobile Equipment Identity (IMEI) of the target terminal; facial information collected by a camera of the target terminal;

[0169] The first transceiver is configured to:

[0170] When the first condition is met, sending the target policy to the second network-side device;

[0171] The first condition includes at least one of the following:

[0172] The IMEI is the IMSI bound to the target IMSI;

[0173] The facial information matches the facial information of the administrator corresponding to the target policy.

[0174] The authentication device 700 can realize the embodiment of the present application Figure 3 The various processes of the method embodiment and the achievement of the same beneficial effects are not described again here to avoid repetition.

[0175] See also Figure 8 , Figure 8 This is the second structural diagram of the authentication device provided in the embodiment of this application. Figure 8 As shown, the authentication device 800 includes:

[0176] A second transceiver is used to receive a notification message sent by a core network device, where the notification message is used to notify the authorization of a target policy, where the target policy is a policy requested to be sent by the second network-side device in the physical network to the first network-side device in the twin network;

[0177] a second processor, configured to output authorization information of the target policy;

[0178] The second transceiver is further configured to send a target authorization authentication request message to the first network side device upon receiving authorization confirmation of the target policy.

[0179] Optionally, the second processor is further configured to:

[0180] Encrypting first information using a first session key to generate first encrypted information, where the first information includes a first authorization and authentication request message;

[0181] Encrypting second information using a second session key to generate second encrypted information, where the second information is obtained by summarizing the first authorization authentication message;

[0182] The second transceiver is further configured to send a second authorization and authentication request message to the first network-side device, where the second authorization and authentication request message includes the first encryption information and the second encryption information.

[0183] Optionally, the second transceiver is further configured to:

[0184] Sending the first authorization and authentication request message to the first network side device;

[0185] Receiving first indication information sent by a core network device, where the first indication information is used to instruct initiation of a general authentication mechanism GBA authentication process;

[0186] A first service request message corresponding to the GBA authentication process is sent to the core network device, wherein the first service request includes an Internet Protocol Multimedia System Private User Identity (IMPI) of the target terminal;

[0187] Obtaining the target key and third identification information corresponding to the GBA authentication process;

[0188] The second processor is further configured to generate the first session key and the second session key using the target key;

[0189] The second transceiver is further configured to:

[0190] Sending a second service request message corresponding to the GBA authentication process to the first network side device, where the second service request message includes the third identification information;

[0191] Receive second indication information sent by the first network side device, where the second indication information is used to indicate completion of the GBA authentication process.

[0192] Optionally, the first information further includes at least one of the following: the International Mobile Equipment Identity (IMEI) of the target terminal; and facial information collected by a camera of the target terminal.

[0193] The authentication device 800 can realize the embodiment of the present application Figure 4The various processes of the method embodiment and the achievement of the same beneficial effects are not described again here to avoid repetition.

[0194] The present application also provides a communication device. Figure 9 The communication device may include a processor 901, a memory 902, and a program 9021 stored in the memory 902 and executable on the processor 901.

[0195] When the communication device is a terminal, the program 9021 can be executed by the processor 901 to achieve Figure 3 Any steps in the corresponding method embodiments and achieving the same beneficial effects will not be repeated here.

[0196] When the communication device is a network side device, the program 9021 can be executed by the processor 901 to achieve Figure 4 Any steps in the corresponding method embodiments and achieving the same beneficial effects will not be repeated here.

[0197] A person skilled in the art will understand that all or part of the steps of the above-mentioned embodiment method can be completed by hardware related to program instructions, and the program can be stored in a readable medium. The embodiment of the present application also provides a readable storage medium on which a computer program is stored, and when the computer program is executed by a processor, the above-mentioned method can be implemented. Figure 3 or Figure 4 Any steps in the corresponding method embodiments can achieve the same technical effects and will not be described again here to avoid repetition.

[0198] The storage medium may be a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk.

[0199] The above is a preferred implementation of the embodiment of the present application. It should be pointed out that for ordinary technicians in this technical field, several improvements and modifications can be made without departing from the principles described in the present application. These improvements and modifications should also be regarded as the scope of protection of the present application.

Claims

1. An authentication method, characterized in that: The first network-side device used in the twin network includes: receiving a policy request message sent by a second network-side device in the physical network, wherein the policy request message is used to request the first network-side device to send a policy to the second network-side device; Invoking a core network device to send a notification message to a target terminal, wherein the notification message is used to notify authorization of a target policy, and the target terminal is determined based on administrator information corresponding to the target policy; receiving a target authorization authentication request message sent by the target terminal upon receiving authorization confirmation of the target policy; If the authorization and authentication are successful, the target policy generated based on the policy request message is sent to the second network side device.

2. The method according to claim 1, characterized in that The target authorization and authentication message is a first authorization and authentication request message, the first authorization and authentication request message including first encrypted information and second encrypted information, wherein the first encrypted information is obtained by the target terminal encrypting first information using a first session key, the first information including the second authorization and authentication request message; the second encrypted information is obtained by the target terminal encrypting second information using a second session key, the second information being obtained by digesting the second authorization and authentication request message; The sending the target policy to the second network side device when the authorization authentication is passed includes: Decrypting the first encrypted information and the second encrypted information respectively using the session key obtained from the core network device; If the first encrypted information and the second encrypted information are successfully decrypted, determining that the first authorization and authentication request message is sent by the terminal with the target IMSI installed, and sending the target policy to the second network-side device; The target IMSI is the IMSI corresponding to the target policy.

3. The method according to claim 2, characterized in that After the invoking the core network device to send a notification message to the target terminal, and before the receiving the target authorization authentication request message sent by the target terminal when the authorization confirmation of the target policy is received, the method further includes: Receiving the first authorization and authentication request message sent by the target terminal; Sending first indication information to the target terminal, where the first indication information is used to instruct to initiate a general authentication mechanism GBA authentication process; receiving a second service request message corresponding to the GBA authentication process sent by the target terminal, where the second service request message includes third identification information corresponding to the GBA authentication process; Obtaining a session key from the core network device using the third identification information; In the case where the session key is successfully obtained, second indication information is sent to the target terminal, where the second indication information is used to indicate the completion of the GBA authentication process.

4. The method according to claim 2 or 3, characterized in that The first information further includes at least one of the following: the International Mobile Equipment Identity (IMEI) of the target terminal; facial information collected by a camera of the target terminal; The sending the target policy to the second network-side device includes: When the first condition is met, sending the target policy to the second network-side device; The first condition includes at least one of the following: The IMEI is the IMSI bound to the target IMSI; The facial information matches the facial information of the administrator corresponding to the target policy.

5. An authentication method, characterized in that: Applied to target terminals, including: Receive a notification message sent by a core network device, where the notification message is used to notify authorization of a target policy, where the target policy is a policy requested by a second network-side device in the physical network to be sent to a first network-side device in the twin network; Outputting authorization information of the target policy; When the authorization confirmation of the target policy is received, a target authorization authentication request message is sent to the first network side device.

6. The method according to claim 5, characterized in that The sending a target authorization authentication request message to the first network side device includes: Encrypting first information using a first session key to generate first encrypted information, where the first information includes a first authorization and authentication request message; Encrypting second information using a second session key to generate second encrypted information, where the second information is obtained by summarizing the first authorization authentication message; A second authorization and authentication request message is sent to the first network-side device, where the second authorization and authentication request message includes the first encryption information and the second encryption information.

7. The method according to claim 6, characterized in that Upon receiving the authorization confirmation of the target policy, before encrypting the first information using the first session key, the method further includes: Sending the first authorization and authentication request message to the first network side device; Receiving first indication information sent by a core network device, where the first indication information is used to instruct initiation of a general authentication mechanism GBA authentication process; A first service request message corresponding to the GBA authentication process is sent to the core network device, wherein the first service request includes an Internet Protocol Multimedia System Private User Identity (IMPI) of the target terminal; Obtaining the target key and third identification information corresponding to the GBA authentication process; generating the first session key and the second session key using the target key; Sending a second service request message corresponding to the GBA authentication process to the first network side device, where the second service request message includes the third identification information; Receive second indication information sent by the first network side device, where the second indication information is used to indicate completion of the GBA authentication process.

8. The method according to claim 6, characterized in that The first information also includes at least one of the following: the International Mobile Equipment Identity (IMEI) of the target terminal; and facial information collected by the camera of the target terminal.

9. An authentication device, characterized in that: The first network-side device used in the twin network includes: A first transceiver is configured to: receiving a policy request message sent by a second network-side device in the physical network, wherein the policy request message is used to request the first network-side device to send a policy to the second network-side device; Invoking a core network device to send a notification message to a target terminal, wherein the notification message is used to notify authorization of a target policy, and the target terminal is determined based on administrator information corresponding to the target policy; receiving a target authorization authentication request message sent by the target terminal upon receiving authorization confirmation of the target policy; If the authorization and authentication are successful, the target policy generated based on the policy request message is sent to the second network side device.

10. An authentication device, characterized in that: Applied to target terminals, including: A second transceiver is used to receive a notification message sent by a core network device, where the notification message is used to notify the authorization of a target policy, where the target policy is a policy requested to be sent by the second network-side device in the physical network to the first network-side device in the twin network; a second processor, configured to output authorization information of the target policy; The second transceiver is further configured to send a target authorization authentication request message to the first network side device upon receiving authorization confirmation of the target policy.

11. A communication device comprising: A transceiver, a memory, a processor, and a program stored in the memory and executable on the processor; wherein the processor is configured to read the program in the memory to implement the steps of the authentication method according to any one of claims 1 to 4; or the steps of the authentication method according to any one of claims 6 to 8.

12. A readable storage medium for storing a program, characterized in that: When the program is executed by a processor, the steps of the authentication method according to any one of claims 1 to 4 are implemented; Or, the steps in the authentication method as claimed in any one of claims 6 to 8.

Citation Information

Patent Citations

  • Initial security configuration method, security module and terminal

    CN113015159A

  • Authentication information processing method, and terminal and network device

    WO2020215958A1