Authentication and Security Methods, Devices, and Storage Media

By separating and concentrating the security functions of the 5G core network, the number of software and hardware systems that need to pass security level certification is reduced, the problem of high system complexity is solved, and high security level authentication and data transmission security is achieved.

CN116419218BActive Publication Date: 2025-07-25DATANG MOBILE COMM EQUIP CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202210006344.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-01-05
Publication Date
2025-07-25
Estimated Expiration
2042-01-05

AI Technical Summary

Technical Problem

The existing 5G core network system is highly complex in high security applications, resulting in increased system costs.

Method used

By separating the security functions of the core network system, the security capabilities of the 5G core network are concentrated in a limited computing system. The network element calls related security functions through the security system interface, reducing the number of software and hardware systems that need to pass security level certification.

Benefits of technology

Reduces system complexity and cost while maintaining high security levels of authentication and data transmission security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116419218B_ABST
    Figure CN116419218B_ABST
Patent Text Reader

Abstract

The embodiments of the present application provide an authentication and security method, apparatus, and storage medium. The method includes: determining an authentication root key of a UE according to the SUPI, generating an authentication vector according to the root key and a serving network name, and using a unique identifier AuthID to identify the authentication vector, this UE authentication process, and a first authentication instance. The first authentication instance is created in the authentication server function AUSF functional area, the first authentication instance is created for this UE authentication process, and the authentication vector is included in the first authentication instance. The authentication and security method, apparatus, and storage medium provided by the embodiments of the present application separate the security functions of the core network system, concentrate the 5G core network security capabilities in a limited computing system, and network elements that require security services call relevant security functions through the interfaces of the security system, thereby greatly reducing the number of software and hardware systems that need to pass the security level authentication.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of communication technologies, and in particular, to an authentication and security method, apparatus, and storage medium. Background Art

[0002] The 5th generation mobile communication (5G) system can be applied not only to ordinary commercial applications, but also to dedicated systems with high security requirements as dedicated systems. In high-security application fields, there are specific security standards for both system software and hardware.

[0003] In existing solutions, key management and cryptographic operations are each processed by individual network elements.

[0004] The 5G core network consists of many network elements (servers) that implement various functions. When the system requires a high security level, all software and hardware in the core network need to meet the corresponding security standards. Adopting the existing solution will greatly increase the system complexity and thus increase the system cost. Summary of the Invention

[0005] Embodiments of this application provide an authentication and security method, apparatus, and storage medium to solve the technical problem of high system complexity in the prior art.

[0006] In a first aspect, embodiments of this application provide an authentication and security method applied to an authentication and encryption system, including:

[0007] Receiving a first request message sent by a Unified Data Management (UDM) network element, where the first request message contains a Subscriber Concealed Identifier (SUCI) of a target User Equipment (UE), and the first request message is used to request the authentication and encryption system to decrypt the SUCI;

[0008] Decrypting the SUCI to obtain a Subscriber Permanent Identifier (SUPI);

[0009] Sending the SUPI to the UDM network element;

[0010] Receiving a second request message sent by the UDM network element, where the second request message contains the SUPI and a service network name, and the second request message is sent after the UDM network element checks the subscription information of the target UE according to the SUPI;

[0011] Determine the authentication root key of the target UE according to the SUPI, generate an authentication vector according to the root key and the serving network name, and use the unique identifier AuthID to identify the authentication vector, this UE authentication process, and the first authentication instance, where the first authentication instance is created in the Authentication Server Function (AUSF) function area for this UE authentication process, and the authentication vector is included in the first authentication instance;

[0012] Send the part of the authentication vector that needs to be provided to the target UE to the UDM network element;

[0013] Receive a third request message sent by the AUSF network element, where the third request message includes an authentication response RES* and the AuthID;

[0014] Authenticate the target UE according to the RES* and the AuthID included in the third request message.

[0015] In some embodiments, it further includes:

[0016] Send the authentication result to the AUSF network element;

[0017] When the target UE is authenticated successfully, receive a fourth request message sent by the AUSF network element, where the fourth request message includes the SUPI or the AuthID;

[0018] Determine the first authentication instance using the SUPI or the AuthID, and calculate the key Kseaf using the key Kausf and the serving network name in the authentication vector; and use the SUPI to identify the second authentication instance, where the second authentication instance is created in the Security Anchor Function (SEAF) function area for this UE authentication process, and the key Kseaf is included in the second authentication instance;

[0019] Send the result of whether the key Kseaf is successfully generated to the AUSF network element.

[0020] In some embodiments, it further includes:

[0021] When the target UE is authenticated successfully, receive a fifth request message sent by the SEAF network element, where the fifth request message includes the SUPI and the Anti-Dimensionality Attack (ABBA);

[0022] Find the second authentication instance using the SUPI, and calculate the key Kamf using the key Kseaf, the SUPI, and the ABBA.

[0023] In some embodiments, it further includes:

[0024] The third authentication instance is identified by the SUPI, and the third authentication instance is created in the access and mobility management function (AMF) functional area for this UE authentication process. The key Kamf is included in the third authentication instance.

[0025] In some embodiments, it further includes:

[0026] Send the result of whether the key Kamf is successfully generated to the SEAF network element.

[0027] In some embodiments, it further includes:

[0028] Generate an AuthID for this UE authentication process.

[0029] In some embodiments, the second request message further includes an AuthID, and the AuthID is a unique identifier generated by the UDM network element for this UE authentication process.

[0030] In some embodiments, it further includes:

[0031] Receive a sixth request message sent by the AMF network element. The sixth request message includes the SUPI and is used to request the establishment of a security context.

[0032] Locate the third authentication instance in the AMF functional area using the SUPI, and establish a first non-access stratum (NAS) security context using the key Kamf. The first NAS security context includes the keys KNASenc and KNASint.

[0033] Send the SUPI, the key KNASenc, and the key KNASint to the communication cipher system.

[0034] In some embodiments, the sixth request message further includes a 5G key set identifier ngKSI; the ngKSI is used to identify the first NAS security context.

[0035] In some embodiments, the SUPI, the ngKSI, the key KNASenc, and the key KNASint are used for the communication cipher system to establish a second NAS security context, and the second NAS security context includes the SUPI, the ngKSI, the key KNASenc, and the key KNASint.

[0036] In some embodiments, the SUPI, the key KNASenc, and the key KNASint are used for the communication cipher system to establish a second NAS security context, and the second NAS security context includes the SUPI, the key KNASenc, and the key KNASint.

[0037] In some embodiments, it further includes:

[0038] Receiving the result of establishing the second NAS security context sent by the communication cipher system;

[0039] Sending the result of establishing the second NAS security context to the AMF network element.

[0040] In a second aspect, an embodiment of the present application provides a network device, including a memory, a transceiver, and a processor;

[0041] The memory is used for storing a computer program; the transceiver is used for transmitting and receiving data under the control of the processor; the processor is used for reading the computer program in the memory and performing the following operations:

[0042] Receiving a first request message sent by a unified data management UDM network element, where the first request message includes a user hidden identifier SUCI of a target terminal UE, and the first request message is used to request the authentication cipher system to decrypt the SUCI;

[0043] Decrypting the SUCI to obtain a user permanent identifier SUPI;

[0044] Sending the SUPI to the UDM network element;

[0045] Receiving a second request message sent by the UDM network element, where the second request message includes the SUPI and a service network name, and the second request message is sent after the UDM network element checks the subscription information of the target UE according to the SUPI;

[0046] Determining an authentication root key of the target UE according to the SUPI, generating an authentication vector according to the root key and the service network name, and using a unique identifier AuthID to identify the authentication vector, this UE authentication process, and a first authentication instance, where the first authentication instance is created for this UE authentication process in the authentication server function AUSF functional area, and the first authentication instance includes the authentication vector;

[0047] Sending the part of the authentication vector that needs to be provided to the target UE to the UDM network element;

[0048] Receive a third request message sent by the AUSF network element, where the third request message contains an authentication response RES* and the AuthID;

[0049] Authenticate the target UE based on the RES* and the AuthID included in the third request message.

[0050] In some embodiments, it further includes:

[0051] Send the authentication result to the AUSF network element;

[0052] When the target UE is authenticated successfully, receive a fourth request message sent by the AUSF network element, where the fourth request message contains the SUPI or the AuthID;

[0053] Determine the first authentication instance using the SUPI or the AuthID, and calculate the key Kseaf using the key Kausf and the serving network name in the authentication vector; and identify the second authentication instance using the SUPI, where the second authentication instance is created for this UE authentication process in the security anchor function (SEAF) functional area, and the second authentication instance contains the key Kseaf;

[0054] Send the result of whether the key Kseaf is successfully generated to the AUSF network element.

[0055] In some embodiments, it further includes:

[0056] When the target UE is authenticated successfully, receive a fifth request message sent by the SEAF network element, where the fifth request message contains the SUPI and anti-dimension reduction attack (ABBA);

[0057] Find the second authentication instance using the SUPI, and calculate the key Kamf using the key Kseaf, the SUPI, and the ABBA.

[0058] In some embodiments, it further includes:

[0059] Identify the third authentication instance using the SUPI, where the third authentication instance is created for this UE authentication process in the access and mobility management function (AMF) functional area, and the third authentication instance contains the key Kamf.

[0060] In some embodiments, it further includes:

[0061] Send the result of whether the key Kamf is successfully generated to the SEAF network element.

[0062] In some embodiments, it further includes:

[0063] Generate an AuthID for this UE authentication process.

[0064] In some embodiments, the second request message further includes an AuthID, which is a unique identifier generated by the UDM network element for this UE authentication process.

[0065] In some embodiments, it further includes:

[0066] Receive a sixth request message sent by the AMF network element, where the sixth request message includes the SUPI and is used to request the establishment of a security context;

[0067] Use the SUPI to find the third authentication instance in the AMF functional area, and establish a first non-access stratum NAS security context using the key Kamf. The first NAS security context includes the keys KNASenc and KNASint;

[0068] Send the SUPI, the key KNASenc, and the key KNASint to the communication cipher system.

[0069] In some embodiments, the sixth request message further includes a 5G key set identifier ngKSI; the ngKSI is used to identify the first NAS security context.

[0070] In some embodiments, the SUPI, the ngKSI, the key KNASenc, and the key KNASint are used by the communication cipher system to establish a second NAS security context, and the second NAS security context includes the SUPI, the ngKSI, the key KNASenc, and the key KNASint.

[0071] In some embodiments, the SUPI, the key KNASenc, and the key KNASint are used by the communication cipher system to establish a second NAS security context, and the second NAS security context includes the SUPI, the key KNASenc, and the key KNASint.

[0072] In some embodiments, it further includes:

[0073] Receive the result of establishing the second NAS security context sent by the communication cipher system;

[0074] Send the result of establishing the second NAS security context to the AMF network element.

[0075] In a third aspect, an embodiment of the present application provides a communication device system, including an authentication cipher system and a communication cipher system;

[0076] The authentication cipher system sends the SUPI, the key KNASenc, and the key KNASint to the communication cipher system;

[0077] The communication cipher system performs the NAS security process according to the SUPI, the key KNASenc, and the key KNASint.

[0078] Fourthly, an authentication and security device provided by an embodiment of the present application includes:

[0079] A first receiving module, configured to receive a first request message sent by a unified data management UDM network element, where the first request message includes a user hidden identifier SUCI of a target terminal UE, and the first request message is used to request the authentication cipher system to decrypt the SUCI;

[0080] A decryption module, configured to decrypt the SUCI to obtain a user permanent identifier SUPI;

[0081] A first sending module, configured to send the SUPI to the UDM network element;

[0082] A second receiving module, configured to receive a second request message sent by the UDM network element, where the second request message includes the SUPI and a serving network name, and the second request message is sent after the UDM network element checks the subscription information of the target UE according to the SUPI;

[0083] A determination module, configured to determine an authentication root key of the target UE according to the SUPI, generate an authentication vector according to the root key and the serving network name, and use a unique identifier AuthID to identify the authentication vector, this UE authentication process, and a first authentication instance, where the first authentication instance is created in an authentication server function AUSF functional area for this UE authentication process, and the first authentication instance includes the authentication vector;

[0084] A second sending module, configured to send a part of the authentication vector that needs to be provided to the target UE to the UDM network element;

[0085] A third receiving module, configured to receive a third request message sent by an AUSF network element, where the third request message includes an authentication response RES* and the AuthID;

[0086] An authentication module, configured to authenticate the target UE according to the RES* and the AuthID included in the third request message.

[0087] Fifth aspect, an embodiment of the present application further provides a processor-readable storage medium, which stores a computer program for causing the processor to execute the steps of the authentication and security method described in the first aspect above.

[0088] Sixth aspect, an embodiment of the present application further provides a computer-readable storage medium, which stores a computer program for causing a computer to execute the steps of the authentication and security method described in the first aspect above.

[0089] Seventh aspect, an embodiment of the present application further provides a communication device-readable storage medium, which stores a computer program for causing a communication device to execute the steps of the authentication and security method described in the first aspect above.

[0090] Eighth aspect, an embodiment of the present application further provides a chip product-readable storage medium, which stores a computer program for causing a chip product to execute the steps of the authentication and security method described in the first aspect above.

[0091] The authentication and security method, device and storage medium provided by the embodiments of the present application separate the security functions of the core network system, centralize the 5G core network security capabilities in a limited computing system, and network elements that require security services call relevant security functions through the interfaces of the security system, thereby greatly reducing the number of software and hardware systems that need to pass the security level authentication. BRIEF DESCRIPTION OF THE DRAWINGS

[0092] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the drawings in the following description are some embodiments of the present application. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.

[0093] Figure 1 It is a schematic diagram of the core network high-security system architecture provided by the embodiments of the present application;

[0094] Figure 2 It is a schematic flowchart of the authentication and security method provided by the embodiments of the present application;

[0095] Figure 3 It is a schematic diagram of the signaling interaction of the UE authentication process provided by the embodiments of the present application;

[0096] Figure 4 It is a schematic diagram of the signaling interaction of the NAS security process provided by the embodiments of the present application;

[0097] Figure 5 It is a schematic structural diagram of a network device provided by an embodiment of the present application;

[0098] Figure 6 It is a schematic structural diagram of an authentication and security device provided by an embodiment of the present application. Specific Embodiments

[0099] To make the objectives, technical solutions, and advantages of the embodiments of the present application clearer, the technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present application. Apparently, the described embodiments are only a part rather than all of the embodiments of the present application. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present application without creative efforts shall fall within the protection scope of the present application.

[0100] Figure 1 It is a schematic diagram of the core network high-security system architecture provided by an embodiment of the present application. As Figure 1 shown, an embodiment of the present application provides a communication device system (high-security level password system), including an authentication password system and a communication password system.

[0101] The authentication password system sends the SUPI, the key KNASenc, and the key KNASint to the communication password system.

[0102] The communication password system performs the NAS security process based on the SUPI, the key KNASenc, and the key KNASint.

[0103] Specifically, the authentication password system is a network element in the high-security level password system and is used for operations related to password operations during the user authentication process.

[0104] The operations related to password operations specifically include: storing the authentication key of the subscribed user, performing relevant password operations, storing the key and relevant data generated during the authentication process, and providing the key and relevant parameters generated during the authentication process to other password calculation devices. Other password calculation devices include the communication password system.

[0105] The communication password system is also a network element in the high-security level password system and is used to achieve data transmission security. For example, it stores the key for achieving data communication security and performs relevant password operations to achieve confidentiality and integrity protection of data communication.

[0106] In the embodiments of the present application, the authentication password system and the communication password system are newly added network elements. These two newly added network elements are network elements with a high security level, which are used to separate the capabilities related to password operations from the 5G core network elements, so as to avoid turning the entire core network into a high security level network. Therefore, the complexity and cost of the entire system can be reduced.

[0107] The authentication password system consists of the following functional areas:

[0108] Unified Data Management (UDM) functional area: The UDM network element in the 5G core network can access the functions and data in the UDM functional area of the authentication password system through the interface of the authentication password system, but cannot access the functions and data in other functional areas. The UDM functional area can write the security information required by the Authentication Server Function (AUSF) network element during the terminal / User Equipment (UE) authentication process into the AUSF functional area.

[0109] AUSF functional area: The AUSF network element in the 5G core network can access the functions and data in the AUSF functional area of the authentication password system through the interface of the authentication password system, but cannot access the functions and data in other functional areas. The AUSF functional area can write the security information required by the SEcurity Anchor Function (SEAF) network element during the UE authentication process into the SEAF functional area.

[0110] SEAF functional area: The SEAF network element in the 5G core network can access the functions and data in the SEAF functional area of the authentication password system through the interface of the authentication password system, but cannot access the functions and data in other functional areas. The SEAF functional area can write the security information required by the Access and Mobility Management Function (AMF) network element during the UE authentication process into the AMF functional area.

[0111] AMF functional area: The AMF network element in the 5G core network can access the functions and data in the AMF functional area of the authentication password system through the interface of the authentication password system, but cannot access the functions and data in other functional areas. The AMF functional area can provide the security information for realizing the security of UE data communication to the communication password system.

[0112] Figure 2 It is a schematic flowchart of the authentication and security method provided by the embodiments of the present application. As Figure 2 shown, the embodiments of the present application provide an authentication and security method, and its execution subject can be an authentication password system. The method includes:

[0113] Step 201: Receive a first request message sent by a UDM network element. The first request message contains a Subscription Concealed Identifier (SUCI) of a target UE, and the first request message is used to request the authentication password system to decrypt the SUCI.

[0114] Step 202: Decrypt the SUCI to obtain a Subscription Permanent Identifier (SUPI).

[0115] Step 203: Send the SUPI to the UDM network element.

[0116] Step 204: Receive a second request message sent by the UDM network element. The second request message contains the SUPI and a serving network name (SN name). The second request message is sent after the UDM network element checks the subscription information of the target UE according to the SUPI.

[0117] Step 205: Determine an authentication root key of the target UE according to the SUPI, generate an authentication vector according to the root key and the serving network name, and use a unique identifier AuthID to identify the authentication vector, this UE authentication process, and a first authentication instance. The first authentication instance is created in the Authentication Server Function (AUSF) functional area, the first authentication instance is created for this UE authentication process, and the first authentication instance contains the authentication vector.

[0118] Step 206: Send the part of the authentication vector that needs to be provided to the target UE to the UDM network element.

[0119] Step 207: Receive a third request message sent by the AUSF network element. The third request message contains an authentication response (RESponse, RES*) and the AuthID.

[0120] Step 208: Authenticate the target UE according to the RES* and the AuthID included in the third request message.

[0121] In some embodiments, it further includes:

[0122] Send the authentication result to the AUSF network element;

[0123] In the case where the target UE is authenticated successfully, receive a fourth request message sent by the AUSF network element. The fourth request message contains the SUPI or the AuthID.

[0124] Determine the first authentication instance using the SUPI or the AuthID, and calculate the key Kseaf using the key Kausf and the serving network name in the authentication vector; and identify a second authentication instance using the SUPI, where the second authentication instance is created in the security anchor function (SEAF) functional area, the second authentication instance is created for this UE authentication process, and the second authentication instance contains the key Kseaf;

[0125] Send the result of whether the key Kseaf is successfully generated to the AUSF network element.

[0126] In some embodiments, it further includes:

[0127] In the case where the target UE is authenticated successfully, receive a fifth request message sent by the SEAF network element, where the fifth request message contains the SUPI and Anti-Bidding down Between Architectures (ABBA);

[0128] Locate the second authentication instance using the SUPI, and calculate the key Kamf using the key Kseaf, the SUPI, and the ABBA.

[0129] In some embodiments, it further includes:

[0130] Identify a third authentication instance using the SUPI, where the third authentication instance is created in the access and mobility management function (AMF) functional area, the third authentication instance is created for this UE authentication process, and the third authentication instance contains the key Kamf.

[0131] In some embodiments, it further includes:

[0132] Send the result of whether the key Kamf is successfully generated to the SEAF network element.

[0133] In some embodiments, it further includes:

[0134] Generate an AuthID for this UE authentication process.

[0135] In some embodiments, the second request message further contains an AuthID, which is a unique identifier generated by the UDM network element for this UE authentication process.

[0136] In some embodiments, it further includes:

[0137] Receive a sixth request message sent by the AMF network element, where the sixth request message contains the SUPI, and the sixth request message is used to request the establishment of a security context;

[0138] Use the SUPI to find the third authentication instance in the AMF functional area, and establish a first Non-Access Stratum (NAS) security context using the key Kamf. The first NAS security context contains the key KNASenc and the key KNASint;

[0139] Send the SUPI, the key KNASenc, and the key KNASint to the communication cipher system.

[0140] In some embodiments, the SUPI, the key KNASenc, and the key KNASint are used for the communication cipher system to establish a second NAS security context, and the second NAS security context contains the SUPI, the key KNASenc, and the key KNASint.

[0141] In some embodiments, the sixth request message further includes a 5G key set identifier ngKSI; the ngKSI is used to identify the first NAS security context.

[0142] In some embodiments, the SUPI, the ngKSI, the key KNASenc, and the key KNASint are used for the communication cipher system to establish a second NAS security context, and the second NAS security context contains the SUPI, the ngKSI, the key KNASenc, and the key KNASint.

[0143] In some embodiments, it further includes:

[0144] Receive the result of establishing the second NAS security context sent by the communication cipher system;

[0145] Send the result of establishing the second NAS security context to the AMF network element.

[0146] Specifically, Figure 3 is a signaling interaction schematic diagram of the UE authentication process provided by the embodiments of the present application. As Figure 3 shown, the UE authentication process provided by the embodiments of the present application includes the following steps:

[0147] 1. The UE sends a registration request to the SEAF network element, and the request contains the UE's SUCI or 5G Globally Unique Temporary UE Identity (GUTI).

[0148] 2. The SEAF network element sends a UE authentication request to the AUSF network element. The request contains the UE's SUCI or SUPI, and the serving network name (SN name).

[0149] 3. The AUSF network element sends a UE authentication request to the UDM network element. The request contains the UE's SUCI or SUPI, and the serving network name.

[0150] 4. When the request contains the UE's SUCI, the UDM network element sends a SUCI decryption request (the first request) to the authentication password system. The request contains the UE's SUCI.

[0151] 5. The authentication password system decrypts the UE's SUCI to obtain the UE's SUPI.

[0152] 6. The authentication password system returns the UE's SUPI to the UDM network element.

[0153] 7. The UDM network element checks the UE's subscription information using the UE's SUPI. If the UE authentication can continue, the UDM network element sends a request (the second request) to the authentication password system to generate a UE authentication vector. The request contains the SUPI and the serving network name.

[0154] Optionally, the UDM network element can provide a unique identifier AuthID (Authentication ID) for this UE authentication process.

[0155] Optionally, the authentication password system can also provide a unique identifier AuthID for this UE authentication process.

[0156] If the UDM network element provides the AuthID, the request should also contain the AuthID.

[0157] Before the UE is actually authenticated successfully, the UDM network element and the AUSF network element interact with the authentication password system using the AuthID, so that the security capabilities distributed in different entities work as a whole. The authentication password system stores the generated authentication vector, and the authentication vector uses the AuthID as an identifier.

[0158] 8. The authentication and ciphering system determines the authentication root key of the UE based on the UE's SUPI. The authentication and ciphering system generates an authentication vector for authenticating the UE by using the UE's root key and information such as the serving network name. The format of the 5G authentication vector is: (RAND, AUTN, XRES*, key Kausf). Among them, RAND (Random challenge) is a random challenge, AUTN (AUthentication TokeN) is an authentication token, XRES* (eXpected RESponse) is an expected response, and the key Kausf is a key.

[0159] Optionally, if the authentication and ciphering system provides the AuthID, the authentication and ciphering system generates an AuthID; otherwise, it uses the AuthID provided by the UDM network element.

[0160] The authentication and ciphering system uses the AuthID to identify the generated authentication vector and the UE authentication process this time.

[0161] The authentication and ciphering system uses the UE's SUPI as an identifier to create an authentication instance (the first authentication instance) for the UE authentication process in the AUSF functional area. This authentication instance contains the UE authentication vector identified by the AuthID.

[0162] 9. The authentication and ciphering system only returns the part of the authentication vector that needs to be provided to the UE to the UDM network element, that is, (RAND, AUTN). If the AuthID is provided by the authentication and ciphering system, the AuthID should also be returned to the UDM network element.

[0163] 10. The UDM network element returns (RAND, AUTN) and the AuthID to the AUSF network element.

[0164] When the AUSF network element provides the UE's SUCI to the UDM network element, the UDM network element also needs to return the SUPI.

[0165] 11. The AUSF network element sends (RAND, AUTN) to the SEAF network element.

[0166] 12. The SEAF network element generates a 5G key set identifier (Key Set Identifier in 5G, ngKSI), and then sends (RAND, AUTN), ngKSI, and ABBA to the UE.

[0167] 13. The UE verifies the AUTN, confirms that the authentication vector is correct, and then calculates RES* by using the UE's root key and RAND.

[0168] 14. The UE sends RES* to the SEAF network element.

[0169] 15. The SEAF network element sends RES* to the AUSF network element.

[0170] 16. The AUSF network element sends a UE authentication request (the third request) to the authentication password system. The request contains AuthID and RES*, and may also contain the UE's SUPI.

[0171] 17. The authentication password system locates the authentication vector in the AUSF functional area using the SUPI and AuthID, and then verifies whether RES* is the same as XRES* in the authentication vector.

[0172] If the authentication is successful, the authentication password system marks the UE as authenticated in this UE authentication instance and stores the key Kausf.

[0173] 18. The authentication password system returns the authentication result (success / failure) to the AUSF network element.

[0174] 19. If the UE is authenticated, the AUSF network element requests the authentication password system to calculate the key Kseaf. This request (the fourth request) contains: SUPI or AuthID, and may also contain: serving network name.

[0175] 20. The authentication password system determines the UE's authentication instance using the SUPI, and then calculates the key Kseaf using the key Kausf and SN.

[0176] The authentication password system creates an authentication instance (the second authentication instance) for this UE authentication process in the SEAF functional area using the UE's SUPI as an identifier. This authentication instance contains the information: the key Kseaf.

[0177] 21. The authentication password system returns the result (success / failure) of whether the key is generated successfully to the AUSF network element.

[0178] 22. The AUSF network element returns the authentication result to the SEAF network element.

[0179] If the authentication is successful, if the authentication request sent by the SEAF network element contains the SUCI, the AUSF network element should also send the SUPI to the SEAF network element.

[0180] 23. If the authentication is successful, the SEAF network element requests the authentication authorization system to generate the key Kamf. This request (the fifth request) contains: SUPI and ABBA.

[0181] 24. The authentication and authorization system locates the UE authentication instance in the SEAF functional area using the SUPI, and then calculates the key Kamf using the key Kseaf and related parameters.

[0182] The authentication password system uses the SUPI of the UE as an identifier to create an authentication instance (the third authentication instance) for this UE authentication process in the AMF functional area. This authentication instance contains the information: the key Kamf.

[0183] 25. The authentication password system returns the result (success / failure) of whether the key is successfully generated to the SEAF network element.

[0184] 26. The SEAF network element returns the authentication result to the AMF network element.

[0185] If the authentication is successful, the SEAF network element provides the ngKSI and SUPI to the AMF network element.

[0186] Specifically, Figure 4 is a signaling interaction schematic diagram of the NAS security process provided by the embodiments of the present application. As Figure 4 shown, the NAS security process provided by the embodiments of the present application includes the following steps:

[0187] 1. When the AMF network element has not yet established the NAS security context of the UE, the AMF network element sends a request to establish a security context (the sixth request) to the authentication password system. This request contains: SUPI, and this request may also contain: ngKSI.

[0188] 2. The authentication password system locates the UE authentication security context in the AMF functional area using the SUPI, and then uses the Kamf to establish the UE NAS security context (the first NAS security context). This NAS security context has the keys for implementing NAS security: KNASenc and KNASint.

[0189] In the case where the ngKSI is also included in the above security context request, the UE NAS security context is established using the Kamf in the UE security context with the ngKSI as an identifier. This NAS security context has the keys for implementing NAS security: KNASenc and KNASint.

[0190] 3. The authentication password system sends the key material for implementing NAS security to the communication password system through a message. This message contains: SUPI, the key KNASenc, and the key KNASint.

[0191] In the case where the ngKSI is also included in the above security context request, this message may also contain: ngKSI.

[0192] 4. The communication cipher system uses the SUPI as an identifier to establish the NAS security context (the second NAS security context) of the UE, and the NAS security context includes: SUPI, the key KNASenc, and the key KNASint.

[0193] When the ngKSI is also included in the above security context request, the communication cipher system uses the SUPI and the ngKSI as identifiers to establish the NAS security context of the UE, and the NAS security context may also include: ngKSI.

[0194] 5. The communication cipher system returns the result (Success / Failure) of establishing the UE NAS security context to the authentication cipher system.

[0195] 6. The authentication cipher system returns the result (Success / Failure) of the communication cipher system establishing the NAS security context to the AMF network element.

[0196] 7. When the AMF network element needs to send a NAS message to the UE, the AMF network element generates a NAS plaintext message.

[0197] 8. The AMF network element sends a NAS message cipher operation request to the communication cipher system, and the request includes: SUPI, the message plaintext, and the parameters required for security calculation, such as the algorithm identifier, COUNT, BEARER, DIRECTION, and LENGTH, etc.

[0198] When the ngKSI is also included in the above security context request, the ngKSI may also be included in the NAS message cipher operation request.

[0199] 9. The communication cipher system uses the SUPI to obtain the security context of the UE, calculates the NAS ciphertext, and then returns the NAS ciphertext to the AMF network element.

[0200] 10. The AMF network element sends a NAS message to the UE.

[0201] 11. The UE sends a NAS message to the AMF network element.

[0202] 12. The AMF network element sends a NAS message cipher operation request to the communication cipher system, and the request includes: SUPI, the message ciphertext, and the parameters required for security calculation, such as the algorithm identifier, COUNT, BEARER, DIRECTION, and LENGTH, etc.

[0203] When the ngKSI is also included in the above security context request, the ngKSI may also be included in the NAS message cipher operation request.

[0204] 13. The communication cipher system decrypts and verifies the NAS ciphertext, and then returns the message plaintext to the AMF network element.

[0205] The authentication and security method provided by the embodiments of the present application separates the security functions of the core network system, concentrates the 5G core network security capabilities in a limited computing system, and network elements that require security services call relevant security functions through the interfaces of the security system, thereby greatly reducing the number of software and hardware systems that need to pass the security level authentication.

[0206] Figure 5 It is a schematic structural diagram of a network device provided by the embodiments of the present application, as Figure 5 shown, the network device includes a memory 520, a transceiver 500, and a processor 510, where:

[0207] The memory 520 is used to store computer programs; the transceiver 500 is used to send and receive data under the control of the processor 510; the processor 510 is used to read the computer programs in the memory 520 and perform the following operations:

[0208] Receive a first request message sent by a unified data management UDM network element, where the first request message contains a user hidden identifier SUCI of a target terminal UE, and the first request message is used to request the authentication cipher system to decrypt the SUCI;

[0209] Decrypt the SUCI to obtain a user permanent identifier SUPI;

[0210] Send the SUPI to the UDM network element;

[0211] Receive a second request message sent by the UDM network element, where the second request message contains the SUPI and a service network name, and the second request message is sent after the UDM network element checks the subscription information of the target UE according to the SUPI;

[0212] Determine an authentication root key of the target UE according to the SUPI, generate an authentication vector according to the root key and the service network name, and use a unique identifier AuthID to identify the authentication vector, this UE authentication process, and a first authentication instance, where the first authentication instance is created in the authentication server function AUSF function area, the first authentication instance is created for this UE authentication process, and the first authentication instance contains the authentication vector;

[0213] Send the part of the authentication vector that needs to be provided to the target UE to the UDM network element;

[0214] Receive a third request message sent by the AUSF network element, where the third request message contains an authentication response RES* and the AuthID;

[0215] Authenticate the target UE according to the RES* and the AuthID included in the third request message.

[0216] Specifically, the transceiver 500 is used to receive and send data under the control of the processor 510.

[0217] Among them, in Figure 5 The bus architecture may include any number of interconnected buses and bridges, specifically, various circuits of one or more processors represented by the processor 510 and the memory represented by the memory 520 are linked together. The bus architecture can also link together various other circuits such as peripheral devices, voltage regulators, and power management circuits, which are well known in the art, so they will not be further described herein. The bus interface provides an interface. The transceiver 500 may be multiple components, that is, including a transmitter and a receiver, and provides a unit for communicating with various other devices on a transmission medium, and these transmission mediums include wireless channels, wired channels, optical fiber cables, and other transmission mediums. The processor 510 is responsible for managing the bus architecture and general processing, and the memory 520 can store the data used by the processor 510 when performing operations.

[0218] The processor 510 may be a central processing unit (CPU), an application specific integrated circuit (ASIC), a field-programmable gate array (FPGA), or a complex programmable logic device (CPLD), and the processor may also adopt a multi-core architecture.

[0219] In some embodiments, it further includes:

[0220] Send the authentication result to the AUSF network element;

[0221] When the target UE is authenticated successfully, receive a fourth request message sent by the AUSF network element, where the fourth request message contains the SUPI or the AuthID;

[0222] Determine the first authentication instance using the SUPI or the AuthID, and calculate the key Kseaf using the key Kausf and the serving network name in the authentication vector; and identify the second authentication instance using the SUPI, where the second authentication instance is created in the security anchor function (SEAF) functional area, the second authentication instance is created for this UE authentication process, and the key Kseaf is included in the second authentication instance;

[0223] Send the result of whether the key Kseaf is successfully generated to the AUSF network element.

[0224] In some embodiments, it further includes:

[0225] In the case where the target UE is authenticated successfully, receive a fifth request message sent by the SEAF network element, where the fifth request message includes the SUPI and the anti-dimensionality reduction attack (ABBA);

[0226] Locate the second authentication instance using the SUPI, and calculate the key Kamf using the key Kseaf, the SUPI, and the ABBA.

[0227] In some embodiments, it further includes:

[0228] Identify a third authentication instance using the SUPI, where the third authentication instance is created in the access and mobility management function (AMF) functional area, the third authentication instance is created for this UE authentication process, and the key Kamf is included in the third authentication instance.

[0229] In some embodiments, it further includes:

[0230] Send the result of whether the key Kamf is successfully generated to the SEAF network element.

[0231] In some embodiments, it further includes:

[0232] Generate an AuthID for this UE authentication process.

[0233] In some embodiments, the second request message further includes an AuthID, where the AuthID is a unique identifier generated by the UDM network element for this UE authentication process.

[0234] In some embodiments, it further includes:

[0235] Receive a sixth request message sent by the AMF network element, where the sixth request message includes the SUPI, and the sixth request message is used to request the establishment of a security context;

[0236] Use the SUPI to find the third authentication instance in the AMF functional area, and establish a first non-access stratum (NAS) security context using the key Kamf. The first NAS security context includes the key KNASenc and the key KNASint;

[0237] Send the SUPI, the key KNASenc, and the key KNASint to the communication cipher system.

[0238] In some embodiments, the sixth request message further includes a 5G key set identifier ngKSI; the ngKSI is used to identify the first NAS security context.

[0239] In some embodiments, the SUPI, the ngKSI, the key KNASenc, and the key KNASint are used for the communication cipher system to establish a second NAS security context, and the second NAS security context includes the SUPI, the ngKSI, the key KNASenc, and the key KNASint.

[0240] In some embodiments, the SUPI, the key KNASenc, and the key KNASint are used for the communication cipher system to establish a second NAS security context, and the second NAS security context includes the SUPI, the key KNASenc, and the key KNASint.

[0241] In some embodiments, it further includes:

[0242] Receive the result of establishing the second NAS security context sent by the communication cipher system;

[0243] Send the result of establishing the second NAS security context to the AMF network element.

[0244] Specifically, the above network device provided by the embodiments of the present application can implement all the method steps implemented by the method embodiments with the authentication cipher system as the execution subject, and can achieve the same technical effects. The same parts and beneficial effects as those in the method embodiments will not be specifically described herein.

[0245] Figure 6 It is a schematic structural diagram of an authentication and security device provided by the embodiments of the present application, as Figure 6 shown. The embodiments of the present application provide an authentication and security device, including

[0246] The first receiving module 601, the decryption module 602, the first sending module 603, the second receiving module 604, the determination module 605, the second sending module 606, the third receiving module 607, and the authentication module 608, where:

[0247] The first receiving module 601 is configured to receive a first request message sent by a unified data management UDM network element. The first request message includes a user hidden identifier SUCI of a target user equipment UE, and the first request message is used to request the authentication password system to decrypt the SUCI.

[0248] The decryption module 602 is configured to decrypt the SUCI to obtain a user permanent identifier SUPI.

[0249] The first sending module 603 is configured to send the SUPI to the UDM network element.

[0250] The second receiving module 604 is configured to receive a second request message sent by the UDM network element. The second request message includes the SUPI and a service network name, and the second request message is sent after the UDM network element checks the subscription information of the target UE according to the SUPI.

[0251] The determination module 605 is configured to determine an authentication root key of the target UE according to the SUPI, generate an authentication vector according to the root key and the service network name, and use a unique identifier AuthID to identify the authentication vector, this UE authentication process, and a first authentication instance. The first authentication instance is created in an authentication server function AUSF function area, the first authentication instance is created for this UE authentication process, and the first authentication instance includes the authentication vector.

[0252] The second sending module 606 is configured to send a part of the authentication vector that needs to be provided to the target UE to the UDM network element.

[0253] The third receiving module 607 is configured to receive a third request message sent by an AUSF network element. The third request message includes an authentication response RES* and the AuthID.

[0254] The authentication module 608 is configured to authenticate the target UE according to the RES* and the AuthID included in the third request message.

[0255] In some embodiments, it further includes:

[0256] Sending the authentication result to the AUSF network element;

[0257] When the target UE is successfully authenticated, receive a fourth request message sent by the AUSF network element, where the fourth request message contains the SUPI or the AuthID;

[0258] Use the SUPI or the AuthID to determine the first authentication instance, and calculate the key Kseaf using the key Kausf and the serving network name in the authentication vector; and use the SUPI to identify the second authentication instance, which is created in the security anchor function (SEAF) functional area and is created for this UE authentication process, and the second authentication instance contains the key Kseaf;

[0259] Send the result of whether the key Kseaf is successfully generated to the AUSF network element.

[0260] In some embodiments, it further includes a fourth receiving module and a first searching module;

[0261] When the target UE is successfully authenticated, the fourth receiving module is used to receive a fifth request message sent by the SEAF network element, where the fifth request message contains the SUPI and the anti-dimensionality reduction attack (ABBA);

[0262] The first searching module is used to find the second authentication instance using the SUPI, and calculate the key Kamf using the key Kseaf, the SUPI, and the ABBA.

[0263] In some embodiments, it further includes an identification module;

[0264] The identification module is used to identify a third authentication instance using the SUPI, which is created in the access and mobility management function (AMF) functional area and is created for this UE authentication process, and the third authentication instance contains the key Kamf.

[0265] In some embodiments, it further includes a third sending module;

[0266] The third sending module is used to send the result of whether the key Kamf is successfully generated to the SEAF network element.

[0267] In some embodiments, it further includes a generation module;

[0268] The generation module is used to generate an AuthID for this UE authentication process.

[0269] In some embodiments, the second request message further contains an AuthID, which is a unique identifier generated by the UDM network element for this UE authentication process.

[0270] In some embodiments, it further includes a fifth receiving module, a second searching module, and a fourth sending module;

[0271] The fifth receiving module is configured to receive a sixth request message sent by an AMF network element, where the sixth request message includes the SUPI, and the sixth request message is used to request the establishment of a security context;

[0272] The second searching module is configured to search for the third authentication instance in the AMF functional area by using the SUPI, and establish a first non-access stratum (NAS) security context by using the key Kamf, where the first NAS security context includes a key KNASenc and a key KNASint;

[0273] The fourth sending module is configured to send the SUPI, the key KNASenc, and the key KNASint to a communication cipher system.

[0274] In some embodiments, the sixth request message further includes a 5G key set identifier ngKSI; the ngKSI is used to identify the first NAS security context.

[0275] In some embodiments, the SUPI, the ngKSI, the key KNASenc, and the key KNASint are used for the communication cipher system to establish a second NAS security context, where the second NAS security context includes the SUPI, the ngKSI, the key KNASenc, and the key KNASint.

[0276] In some embodiments, the SUPI, the key KNASenc, and the key KNASint are used for the communication cipher system to establish a second NAS security context, where the second NAS security context includes the SUPI, the key KNASenc, and the key KNASint.

[0277] In some embodiments, it further includes a sixth receiving module and a fifth sending module;

[0278] The sixth receiving module is configured to receive the result of establishing the second NAS security context sent by the communication cipher system;

[0279] The fifth sending module is configured to send the result of establishing the second NAS security context to the AMF network element.

[0280] Specifically, the above authentication and security device provided by the embodiments of the present application can implement all the method steps implemented by the method embodiments with the above execution subject being an authentication password system, and can achieve the same technical effects. Here, the same parts and beneficial effects as those in the method embodiments in this embodiment will not be specifically described again.

[0281] It should be noted that the division of units / modules in the above embodiments of the present application is illustrative. It is only a logical function division, and there may be other division methods in actual implementation. In addition, in each embodiment of the present application, each functional unit may be integrated in a processing unit, or each unit may exist physically alone, or two or more units may be integrated in one unit. The above integrated unit can be implemented in the form of hardware or in the form of a software functional unit.

[0282] If the above integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a processor-readable storage medium. Based on such an understanding, the technical solution of the present application, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions for causing a computer device (which may be a personal computer, a server, or a network device, etc.) or a processor to execute all or part of the steps of the methods described in the various embodiments of the present application. The foregoing storage medium includes: various media such as a USB flash drive, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk, or an optical disc that can store program codes.

[0283] In some embodiments, a computer-readable storage medium is further provided. The computer-readable storage medium stores a computer program, and the computer program is used to cause a computer to execute the steps of the authentication and security methods provided in the above method embodiments.

[0284] Specifically, the above computer-readable storage medium provided by the embodiments of the present application can implement all the method steps implemented by the above method embodiments, and can achieve the same technical effects. Here, the same parts and beneficial effects as those in the method embodiments in this embodiment will not be specifically described again.

[0285] It should be noted that: The computer-readable storage medium can be any available medium or data storage device accessible by the processor, including but not limited to magnetic memories (such as floppy disks, hard disks, magnetic tapes, magneto-optical disks (MO), etc.), optical memories (such as CDs, DVDs, BDs, HVDs, etc.), and semiconductor memories (such as ROMs, EPROMs, EEPROMs, non-volatile memories (NAND FLASH), solid state drives (SSD), etc.).

[0286] In addition, it should be noted that: In the embodiments of the present application, terms such as "first" and "second" are used to distinguish similar objects, rather than to describe a specific order or sequence. It should be understood that such terms can be interchanged under appropriate circumstances, so that the embodiments of the present application can be implemented in an order other than those illustrated or described herein, and the objects distinguished by "first" and "second" are generally of the same category, and do not limit the number of objects. For example, the first object can be one or more.

[0287] In the embodiments of the present application, the term "and / or" describes the association relationship of associated objects, indicating that three relationships can exist. For example, A and / or B can represent: A exists alone, A and B exist simultaneously, and B exists alone. The character " / " generally represents an "or" relationship between the associated objects before and after.

[0288] In the embodiments of the present application, the term "a plurality of" means two or more, and other quantifiers are similar thereto.

[0289] The technical solutions provided by the embodiments of this application can be applicable to multiple systems, especially 5G systems. For example, the applicable systems can be Global System of Mobile Communication (GSM) systems, Code Division Multiple Access (CDMA) systems, Wideband Code Division Multiple Access (WCDMA) General Packet Radio Service (GPRS) systems, Long Term Evolution (LTE) systems, LTE Frequency Division Duplex (FDD) systems, LTE Time Division Duplex (TDD) systems, Long Term Evolution Advanced (LTE-A) systems, Universal Mobile Telecommunication System (UMTS), Worldwide Interoperability for Microwave Access (WiMAX) systems, 5G New Radio (NR) systems, etc. Both terminal devices and network devices are included in these multiple systems. The system may also include a core network part, such as an Evolved Packet System (EPS), a 5G System (5GS), etc.

[0290] The terminal device involved in the embodiments of the present application may be a device that provides voice and / or data connectivity to users, such as a handheld device with wireless connection capabilities, or other processing devices connected to a wireless modem, etc. In different systems, the name of the terminal device may also be different. For example, in a 5G system, the terminal device may be referred to as a user equipment (UE). The wireless terminal device can communicate with one or more core networks (CN) via a radio access network (RAN). The wireless terminal device can be a mobile terminal device, such as a mobile phone (or a "cellular" phone) and a computer with a mobile terminal device. For example, it can be a portable, pocket-sized, handheld, computer-integrated, or vehicle-mounted mobile device that exchanges language and / or data with the radio access network. For example, devices such as personal communication service (PCS) phones, cordless phones, session initiated protocol (SIP) phones, wireless local loop (WLL) stations, personal digital assistants (PDAs), etc. The wireless terminal device can also be referred to as a system, a subscriber unit, a subscriber station, a mobile station, a mobile, a remote station, an access point, a remote terminal device, an access terminal device, a user terminal device, a user agent, a user device, which is not limited in the embodiments of the present application.

[0291] The network device involved in the embodiments of this application can be a base station, which may include multiple cells that provide services to terminals. Depending on specific application scenarios, the base station can also be referred to as an access point, or it can be a device in the access network that communicates with wireless terminal devices through one or more sectors over the air interface, or have other names. The network device can be used to mutually replace the received air frames and Internet Protocol (IP) packets, acting as a router between the wireless terminal device and the rest of the access network, where the rest of the access network may include an Internet Protocol (IP) communication network. The network device can also coordinate the management of the attributes of the air interface. For example, the network device involved in the embodiments of this application can be a network device (Base Transceiver Station, BTS) in a Global System for Mobile communications (GSM) or Code Division Multiple Access (CDMA), or it can be a network device (NodeB) in a Wide-band Code Division Multiple Access (WCDMA), or it can also be an evolved network device (evolutional Node B, eNB or e-NodeB) in a Long Term Evolution (LTE) system, a 5G base station (gNB) in a 5G network architecture (next generation system), or it can be a Home evolved Node B (HeNB), a relay node, a femto, a pico, etc. This is not limited in the embodiments of this application. In some network architectures, the network device can include a centralized unit (centralized unit, CU) node and a distributed unit (distributed unit, DU) node, and the centralized unit and the distributed unit can also be geographically separated.

[0292] A network device and a terminal device can each use one or more antennas for multi-input multi-output (MIMO) transmission. The MIMO transmission can be single-user MIMO (SU-MIMO) or multi-user MIMO (MU-MIMO). According to the form and number of antenna combinations, the MIMO transmission can be 2D-MIMO, 3D-MIMO, FD-MIMO, or massive-MIMO, or it can be diversity transmission, precoding transmission, beamforming transmission, etc.

[0293] Those skilled in the art should understand that the embodiments of the present application can be provided as a method, a system, or a computer program product. Therefore, the present application can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present application can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage and optical storage, etc.) that contain computer-usable program code.

[0294] The present application is described with reference to the flowcharts and / or block diagrams of methods, devices (systems), and computer program products according to the embodiments of the present application. It should be understood that each process and / or block in the flowchart and / or block diagram, as well as the combination of processes and / or blocks in the flowchart and / or block diagram, can be implemented by computer-executable instructions. These computer-executable instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing devices to generate a machine, such that the instructions executed by the processor of the computer or other programmable data processing devices generate a device for implementing the functions specified in Figure 1 one process or multiple processes and / or blocks Figure 1 one block or multiple blocks.

[0295] These processor-executable instructions can also be stored in a processor-readable memory that can direct a computer or other programmable data processing device to work in a specific manner, such that the instructions stored in the processor-readable memory generate a manufactured article including an instruction device that implements the functions specified in Figure 1 one process or multiple processes and / or blocks Figure 1 one block or multiple blocks.

[0296] These processor-executable instructions can also be loaded onto a computer or other programmable data processing device, such that a series of operation steps are executed on the computer or other programmable device to generate a computer-implemented process. Thus, the instructions executed on the computer or other programmable device provide for implementing the functions specified in Figure 1One or more processes and / or boxes Figure 1 Steps of the functions specified in one box or more boxes.

[0297] Obviously, those skilled in the art can make various changes and modifications to this application without departing from the spirit and scope of this application. Thus, if these modifications and variations of this application fall within the scope of the claims of this application and their equivalent technologies, this application is also intended to include these modifications and variations.

Claims

1. A method for authentication and security, characterized in that, Applied to an authentication and ciphering system, including: Receiving a first request message sent by a Unified Data Management (UDM) network element, where the first request message contains a Subscriber Concealed Identifier (SUCI) of a target User Equipment (UE), and the first request message is used to request the authentication and ciphering system to decrypt the SUCI; Decrypting the SUCI to obtain a Subscriber Permanent Identifier (SUPI); Sending the SUPI to the UDM network element; Receiving a second request message sent by the UDM network element, where the second request message contains the SUPI and a serving network name, and the second request message is sent after the UDM network element checks the subscription information of the target UE according to the SUPI; Determining an authentication root key of the target UE according to the SUPI, generating an authentication vector according to the root key and the serving network name, and using a unique identifier AuthID to identify the authentication vector, this UE authentication process, and a first authentication instance, where the first authentication instance is created for this UE authentication process in the Authentication Server Function (AUSF) functional area, and the first authentication instance contains the authentication vector; Sending the part of the authentication vector that needs to be provided to the target UE to the UDM network element; Receiving a third request message sent by the AUSF network element, where the third request message contains an authentication response RES* and the AuthID; Authenticating the target UE according to the RES* and the AuthID contained in the third request message.

2. The authentication and security method according to claim 1, wherein It further includes: Sending the authentication result to the AUSF network element; When the target UE passes the authentication, receiving a fourth request message sent by the AUSF network element, where the fourth request message contains the SUPI or the AuthID; Determining the first authentication instance using the SUPI or the AuthID, calculating a key Kseaf using the key Kausf in the authentication vector and the serving network name; and using the SUPI to identify a second authentication instance, where the second authentication instance is created for this UE authentication process in the Security Anchor Function (SEAF) functional area, and the second authentication instance contains the key Kseaf; Sending the result of whether the key Kseaf is successfully generated to the AUSF network element.

3. The authentication and security method according to claim 2, wherein It further includes: When the target UE passes the authentication, receiving a fifth request message sent by the SEAF network element, where the fifth request message contains the SUPI and Anti-Dimensionality Attack (ABBA); Finding the second authentication instance using the SUPI, and calculating a key Kamf using the key Kseaf, the SUPI, and the ABBA.

4. The authentication and security method according to claim 3, wherein It further includes: Using the SUPI to identify a third authentication instance, where the third authentication instance is created for this UE authentication process in the Access and Mobility Management Function (AMF) functional area, and the third authentication instance contains the key Kamf.

5. The authentication and security method according to claim 4, wherein It further includes: Sending the result of whether the key Kamf is successfully generated to the SEAF network element.

6. The authentication and security method according to claim 1, wherein It further includes: Generate an AuthID for this UE authentication process.

7. The authentication and security method according to claim 1, characterized in that The second request message also contains the AuthID, which is a unique identifier generated by the UDM network element for this UE authentication process.

8. The authentication and security method according to claim 4, wherein It further includes: Receive a sixth request message sent by the AMF network element, where the sixth request message contains the SUPI and is used to request the establishment of a security context. Use the SUPI to find the third authentication instance in the AMF functional area and establish a first non-access stratum (NAS) security context using the key Kamf. The first NAS security context contains the keys KNASenc and KNASint. Send the SUPI, the key KNASenc, and the key KNASint to the communication cipher system.

9. The authentication and security method according to claim 8, wherein, The sixth request message also contains the 5G key set identifier ngKSI, which is used to identify the first NAS security context.

10. The authentication and security method according to claim 9, characterized in that, The SUPI, the ngKSI, the key KNASenc, and the key KNASint are used for the communication cipher system to establish a second NAS security context, which contains the SUPI, the ngKSI, the key KNASenc, and the key KNASint.

11. The authentication and security method according to claim 8, wherein The SUPI, the key KNASenc, and the key KNASint are used for the communication cipher system to establish a second NAS security context, which contains the SUPI, the key KNASenc, and the key KNASint.

12. The authentication and security method according to claim 11, characterized in that, It further includes: Receive the result of establishing the second NAS security context sent by the communication cipher system. Send the result of establishing the second NAS security context to the AMF network element.

13. A network device, characterized in that, It includes a memory, a transceiver, and a processor. The memory is used to store computer programs; the transceiver is used to send and receive data under the control of the processor; the processor is used to read the computer programs in the memory and perform the following operations: Receive a first request message sent by the unified data management (UDM) network element. The first request message contains the user concealed identifier (SUCI) of the target terminal UE and is used to request the authentication cipher system to decrypt the SUCI. Decrypt the SUCI to obtain the subscriber permanent identifier (SUPI). Send the SUPI to the UDM network element. Receive a second request message sent by the UDM network element. The second request message contains the SUPI and the service network name, and the second request message is sent after the UDM network element checks the subscription information of the target UE according to the SUPI. Determine the authentication root key of the target UE according to the SUPI, generate an authentication vector according to the root key and the service network name, and use the unique identifier AuthID to identify the authentication vector, this UE authentication process, and the first authentication instance. The first authentication instance is created in the authentication server function AUSF functional area for this UE authentication process, and the authentication vector is included in the first authentication instance; Send the part of the authentication vector that needs to be provided to the target UE to the UDM network element; Receive a third request message sent by the AUSF network element. The third request message includes an authentication response RES* and the AuthID; Authenticate the target UE according to the RES* and the AuthID included in the third request message.

14. The network device according to claim 13, characterized in that, It further includes: Send the authentication result to the AUSF network element; When the target UE authentication is passed, receive a fourth request message sent by the AUSF network element. The fourth request message includes the SUPI or the AuthID; Use the SUPI or the AuthID to determine the first authentication instance, and calculate the key Kseaf using the key Kausf and the service network name in the authentication vector; and use the SUPI to identify the second authentication instance. The second authentication instance is created in the security anchor function SEAF functional area for this UE authentication process, and the key Kseaf is included in the second authentication instance; Send the result of whether the key Kseaf is successfully generated to the AUSF network element.

15. The network device according to claim 14, characterized in that, It further includes: When the target UE authentication is passed, receive a fifth request message sent by the SEAF network element. The fifth request message includes the SUPI and anti-dimensionality reduction attack ABBA; Use the SUPI to find the second authentication instance, and calculate the key Kamf using the key Kseaf, the SUPI, and the ABBA.

16. The network device according to claim 15, wherein It further includes: Use the SUPI to identify the third authentication instance. The third authentication instance is created in the access and mobility management function AMF functional area for this UE authentication process, and the key Kamf is included in the third authentication instance.

17. The network device according to claim 16, wherein, It further includes: Send the result of whether the key Kamf is successfully generated to the SEAF network element.

18. The network device according to claim 13, wherein It further includes: Generate an AuthID for this UE authentication process.

19. The network device according to claim 13, characterized in that, The second request message further includes an AuthID, which is a unique identifier generated by the UDM network element for this UE authentication process.

20. The network device according to claim 16, wherein It further includes: Receive a sixth request message sent by the AMF network element. The sixth request message includes the SUPI, and the sixth request message is used to request the establishment of a security context; Use the SUPI to find the third authentication instance in the AMF functional area, and establish a first non-access stratum NAS security context using the key Kamf. The first NAS security context includes the key KNASenc and the key KNASint; Send the SUPI, the key KNASenc, and the key KNASint to the communication cipher system.

21. The network device according to claim 20, wherein The sixth request message further includes a 5G key set identifier ngKSI; the ngKSI is used to identify the first NAS security context.

22. The network device according to claim 21, characterized in that, The SUPI, the ngKSI, the key KNASenc, and the key KNASint are used for the communication cipher system to establish a second NAS security context, and the second NAS security context includes the SUPI, the ngKSI, the key KNASenc, and the key KNASint.

23. The network device according to claim 20, wherein The SUPI, the key KNASenc, and the key KNASint are used for the communication cipher system to establish a second NAS security context, and the second NAS security context includes the SUPI, the key KNASenc, and the key KNASint.

24. The network device according to claim 23, wherein Further included: Receive the result of establishing the second NAS security context sent by the communication cipher system; Send the result of establishing the second NAS security context to the AMF network element.

25. An authentication and security device, characterized in that, Included: A first receiving module, configured to receive a first request message sent by a unified data management UDM network element, where the first request message includes a user hidden identifier SUCI of a target terminal UE, and the first request message is used to request the authentication cipher system to decrypt the SUCI; A decryption module, configured to decrypt the SUCI to obtain a user permanent identifier SUPI; A first sending module, configured to send the SUPI to the UDM network element; A second receiving module, configured to receive a second request message sent by the UDM network element, where the second request message includes the SUPI and a service network name, and the second request message is sent after the UDM network element checks the subscription information of the target UE according to the SUPI; A determination module, configured to determine an authentication root key of the target UE according to the SUPI, generate an authentication vector according to the root key and the service network name, and use a unique identifier AuthID to identify the authentication vector, this UE authentication process, and a first authentication instance, where the first authentication instance is created in an authentication server function AUSF functional area for this UE authentication process, and the first authentication instance includes the authentication vector; A second sending module, configured to send a part of the authentication vector that needs to be provided to the target UE to the UDM network element; A third receiving module, configured to receive a third request message sent by an AUSF network element, where the third request message includes an authentication response RES* and the AuthID; An authentication module, configured to authenticate the target UE according to the RES* and the AuthID included in the third request message.

26. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program, and the computer program is used to cause a computer to execute the authentication and security method according to any one of claims 1 to 12.