Device authentication method and apparatus, and communication device
By acquiring and sending the identification information of non-3GPP devices to trigger the authentication process, the problem of non-3GPP devices being unable to legally access the 3GPP core network is solved, and secure communication is realized in personal IoT and fixed-mobile convergence scenarios.
Patent Information
- Application Number
- CN202210102685.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-01-27
- Publication Date
- 2025-11-25
- Estimated Expiration
- 2042-01-27
AI Technical Summary
In existing technologies, non-3GPP devices cannot securely access the 3GPP core network, leading to security risks in communication networks. This is especially true in personal IoT and fixed-mobile convergence scenarios. How to enable non-3GPP devices to legally access the core network is an urgent problem to be solved.
The first terminal obtains the identification information of the second terminal and sends a message containing the identification information to the first network element to trigger the authentication process for the second terminal, thereby enabling legitimate access for non-3GPP devices.
In scenarios where non-3GPP devices access communication networks through personal IoT networks or home networks, the security of communication is effectively guaranteed, and legitimate access and secure authentication of non-3GPP devices are achieved.
Smart Images

Figure CN116567626B_ABST
Abstract
Description
Technical Field
[0001] This application belongs to the field of communication technology, specifically relating to a device authentication method, apparatus, and communication equipment. Background Technology
[0002] In related technologies, mobile phones can create WiFi hotspots for other devices, such as allowing laptops to access the internet via the phone. However, since laptops are not 3GPP (3rd Generation Partnership Project) devices, the communication network cannot detect that the laptop is online, thus failing to verify its legitimacy. If unauthorized devices access the network through a mobile phone, secure communication between the phone and the network is at risk. These technologies do not describe how non-3GPP devices can access the core network through a 3GPP device. In scenarios involving personal IoT and fixed-mobile convergence, how to securely allow non-3GPP devices to access the core network is a pressing issue that needs to be addressed. Summary of the Invention
[0003] This application provides a device authentication method, apparatus, and communication equipment that can solve the problem of how to securely allow non-3GPP devices to access the core network.
[0004] Firstly, a device authentication method is provided, including:
[0005] The first terminal obtains the identification information of the second terminal;
[0006] The first terminal sends a first message to the first network element. The first message includes the identification information of the second terminal and is used to trigger the authentication process for the second terminal.
[0007] Secondly, a device authentication method is provided, including:
[0008] The first network element receives a first message sent by the first terminal, the first message including the identification information of the second terminal;
[0009] The first network element triggers the authentication process for the second terminal based on the first message.
[0010] Thirdly, a device authentication device is provided, comprising:
[0011] The first acquisition module is used to acquire the identification information of the second terminal;
[0012] The first sending module is used to send a first message to the first network element. The first message includes the identification information of the second terminal and is used to trigger the authentication process for the second terminal.
[0013] Fourthly, a device authentication apparatus is provided, comprising:
[0014] The first receiving module is configured to receive a first message sent by the first terminal, wherein the first message includes the identification information of the second terminal;
[0015] The processing module is used to trigger the authentication process for the second terminal based on the first message.
[0016] Fifthly, a terminal is provided, the terminal including a processor and a memory, the memory storing a program or instructions executable on the processor, the program or instructions, when executed by the processor, implementing the steps of the method as described in the first aspect.
[0017] In a sixth aspect, a terminal is provided, including a processor and a communication interface, wherein the processor is used to acquire identification information of a second terminal, the communication interface is used to send a first message to a first network element, the first message including the identification information of the second terminal, and the first message is used to trigger an authentication process for the second terminal.
[0018] In a seventh aspect, a network-side device is provided, the network-side device including a processor and a memory, the memory storing a program or instructions executable on the processor, the program or instructions, when executed by the processor, implementing the steps of the method as described in the second aspect.
[0019] Eighthly, a network-side device is provided, including a processor and a communication interface, wherein the communication interface is used to receive a first message sent by a first terminal, the first message including identification information of a second terminal; the processor is used to trigger an authentication process for the second terminal based on the first message.
[0020] A ninth aspect provides a device authentication system, comprising: a terminal and a network-side device, wherein the terminal can be used to perform the steps of the device authentication method as described in the first aspect, and the network-side device can be used to perform the steps of the device authentication method as described in the second aspect.
[0021] In a tenth aspect, a readable storage medium is provided, on which a program or instructions are stored, which, when executed by a processor, implement the steps of the method described in the first aspect, or implement the steps of the method described in the second aspect.
[0022] Eleventhly, a chip is provided, the chip including a processor and a communication interface, the communication interface being coupled to the processor, the processor being used to run programs or instructions to implement the method as described in the first aspect, or to implement the method as described in the second aspect.
[0023] In a twelfth aspect, a computer program / program product is provided, which is stored in a storage medium and is executed by at least one processor to implement the steps of the method as described in the first aspect, or to implement the method as described in the second aspect.
[0024] In this embodiment, the first terminal obtains the identification information of the second terminal and sends a first message containing the identification information of the second terminal to the first network element. The first message triggers the authentication process for the second terminal, thereby achieving the purpose of using the first terminal (3GPP terminal) to assist the second terminal (non-3GPP terminal) in accessing the core network for authentication. In scenarios where non-3GPP devices access the communication network through personal IoT networks or home networks, the security of communication can be effectively guaranteed. Attached Figure Description
[0025] Figure 1 This diagram illustrates the structure of a communication system to which embodiments of this application can be applied.
[0026] Figure 2 One of the flowcharts illustrating the device authentication method according to an embodiment of this application;
[0027] Figure 3 A second schematic flowchart illustrating the device authentication method according to an embodiment of this application;
[0028] Figure 4 One of the interactive schematic diagrams illustrating the device authentication method of this application embodiment;
[0029] Figure 5 The second interactive schematic diagram illustrating the device authentication method of this application embodiment;
[0030] Figure 6 The third interactive schematic diagram illustrating the device authentication method of this application embodiment;
[0031] Figure 7 The fourth interactive schematic diagram illustrating the device authentication method of this application embodiment;
[0032] Figure 8 One of the schematic diagrams of the device authentication apparatus according to an embodiment of this application;
[0033] Figure 9 A structural block diagram illustrating a communication device according to an embodiment of this application;
[0034] Figure 10 A structural block diagram illustrating the terminal in an embodiment of this application;
[0035] Figure 11 A second schematic diagram illustrating the module of the device authentication apparatus according to an embodiment of this application;
[0036] Figure 12 This is a second structural block diagram illustrating an embodiment of the network-side device of this application. Detailed Implementation
[0037] The technical solutions of the embodiments of this application will be clearly described below with reference to the accompanying drawings. Obviously, the described embodiments are only some, not all, of the embodiments of this application. All other embodiments obtained by those skilled in the art based on the embodiments of this application are within the scope of protection of this application.
[0038] The terms "first," "second," etc., used in the specification and claims of this application are used to distinguish similar objects and not to describe a specific order or sequence. It should be understood that such terms can be used interchangeably where appropriate so that embodiments of this application can be implemented in orders other than those illustrated or described herein, and the objects distinguished by "first" and "second" are generally of the same class, not limited in number; for example, a first object can be one or more. Furthermore, in the specification and claims, "and / or" indicates at least one of the connected objects, and the character " / " generally indicates that the preceding and following objects are in an "or" relationship.
[0039] It is worth noting that the technologies described in this application are not limited to Long Term Evolution (LTE) / LTE-Advanced (LTE-A) systems, but can also be used in other wireless communication systems, such as Code Division Multiple Access (CDMA), Time Division Multiple Access (TDMA), Frequency Division Multiple Access (FDMA), Orthogonal Frequency Division Multiple Access (OFDMA), Single-carrier Frequency Division Multiple Access (SC-FDMA), and other systems. The terms "system" and "network" in this application are often used interchangeably, and the described technologies can be used with the systems and radio technologies mentioned above, as well as with other systems and radio technologies. The following description describes New Radio (NR) systems for illustrative purposes, and NR terminology is used in most of the following description; however, these technologies can also be applied to applications beyond NR systems, such as 6th generation (6G) radio systems. thGeneration 6G communication system.
[0040] Figure 1This diagram illustrates a block diagram of a wireless communication system applicable to embodiments of this application. The wireless communication system includes a terminal 11 and a network-side device 12. Terminal 11 can be a mobile phone, tablet computer, laptop computer, personal digital assistant (PDA), handheld computer, netbook, ultra-mobile personal computer (UMPC), mobile internet device (MID), augmented reality (AR) / virtual reality (VR) device, robot, wearable device, vehicle-mounted device (VUE), pedestrian terminal (PUE), smart home (home devices with wireless communication capabilities, such as refrigerators, televisions, washing machines, or furniture), game console, personal computer (PC), ATM, or self-service machine, etc. Wearable devices include: smartwatches, smart bracelets, smart headphones, smart glasses, smart jewelry (smart bracelets, smart chains, smart rings, smart necklaces, smart anklets, smart anklets, etc.), smart wristbands, smart clothing, etc. It should be noted that the specific type of terminal 11 is not limited in this embodiment. Network-side equipment 12 may include access network equipment or core network equipment. Access network equipment 12 may also be referred to as radio access network equipment, radio access network (RAN), radio access network function, or radio access network unit. Access network equipment 12 may include base stations, WLAN access points, or WiFi nodes, etc. Base stations may be referred to as Node B, evolved Node B (eNB), access point, base transceiver station (BTS), radio base station, radio transceiver, Basic Service Set (BSS), Extended Service Set (ESS), home B node, home evolved B node, Transmitting Receiving Point (TRP), or any other suitable term in the field, as long as the same technical effect is achieved. The base station is not limited to specific technical terms. It should be noted that in this application embodiment, only a base station in an NR system is used as an example for description, and the specific type of base station is not limited.Core network equipment may include, but is not limited to, at least one of the following: core network node, core network function, Mobility Management Entity (MME), Access and Mobility Management Function (AMF), Session Management Function (SMF), User Plane Function (UPF), Policy Control Function (PCF), Policy and Charging Rules Function (PCRF), Edge Application Server Discovery Function (EASDF), Unified Data Management (UDM), Unified Data Repository (UDR), Home Subscriber Server (HSS), Centralized network configuration (CNC), Network Repository Function (NRF), Network Exposure Function (NEF), Local NEF (or L-NEF), Binding Support Function (BSF), and Application Function. Functions (AF), etc. It should be noted that this application embodiment only uses core network devices in the NR system as an example for description, and does not limit the specific type of core network device. It is worth noting that the functions of the aforementioned core network devices can be implemented by multiple devices, or the functions of multiple core network devices can be implemented by one device; this application embodiment does not limit this. In this application embodiment, if the functions of multiple core network devices are implemented by one device, then the interaction between these multiple core network devices in this application embodiment is an internal operation of that device.
[0041] To enable those skilled in the art to better understand the embodiments of this application, the following description is provided first.
[0042] 1. Personal Internet of Things (PIN).
[0043] A PIN is a group consisting of at least one PIN element (PINE), where at least one PIN element is a terminal (User Equipment, UE). PIN elements communicate with each other. Two PIN elements can communicate through a direct connection between them or indirectly through a communication network.
[0044] A PIN element can be a UE or a non-3GPP device. A PIN element can also be a non-5G-Capable over WLAN (N5CW) device. A non-3GPP device refers to a device that does not use 3GPP-defined credentials, does not support 3GPP-defined NAS protocols, or does not support 3GPP access technologies (such as 3G / 4G / 5G air interface technologies) but only supports non-3GPP access technologies (such as WiFi, fixed network, Bluetooth, etc.). It is worth noting that when the PIN element is a UE, when it accesses the communication network through PEGC, it can also perform the procedures for non-3GPP devices or N5CW devices, for example, interacting with the communication network without using the UE's NAS. The scheme described in the embodiments of this application can also be used.
[0045] A PIN can contain one or more PIN Elements with Gateway Capability (PEGC). These PIN elements can communicate directly with each other or via PEGC. PEGCs can also facilitate communication between these PIN elements and other devices or application servers outside the PIN. A PEGC can be a gateway in a smart home scenario or a mobile phone in a wearable device scenario.
[0046] 2. Wireline Wireless Convergence (WWC).
[0047] The current 3GPP 5G core network supports fixed network access, including support for residential gateways (RGs) to access the 5G core network through fixed networks and 3GPP networks, as well as support for 3GPP terminal devices to access the 5G core network through residential gateways.
[0048] The device authentication method provided in this application will be described in detail below with reference to the accompanying drawings and through some embodiments and application scenarios.
[0049] like Figure 2 As shown in the figure, this application provides a device authentication method, including:
[0050] Step 201: The first terminal obtains the identification information of the second terminal.
[0051] In this embodiment, the first terminal is a personal IoT gateway, and the second terminal is a device that cannot use the NAS protocol. As an optional implementation, the second terminal may be a non-3GPP device or a personal IoT device. Alternatively, the second terminal may be a 3GPP device, and the connection between the second terminal and the first terminal may not support NAS protocol transmission.
[0052] Optionally, the first terminal can also be a home gateway. The first terminal and the second terminal can establish a connection via WiFi, Bluetooth, or passive IoT (e.g., Passive IoT) technology. It is worth noting that when the first terminal and the second terminal establish a connection via passive IoT, the second terminal can be a 3GPP device or a non-3GPP device, and the passive IoT technology can be either 3GPP access technology or a non-3GPP access technology.
[0053] Step 202: The first terminal sends a first message to the first network element. The first message includes the identification information of the second terminal, and the first information is used to trigger the authentication process for the second terminal.
[0054] Wherein, the first network element is a mobility management network element or a session management network element, such as the mobility management network element being an Access and Mobility Management Function (AMF) or the session management network element being a Session Management Function (SMF).
[0055] In this embodiment, the first terminal obtains the identification information of the second terminal and sends a first message containing the identification information of the second terminal to the first network element. The first message triggers the authentication process for the second terminal, thereby achieving the purpose of using the first terminal (3GPP terminal) to assist the second terminal (non-3GPP terminal) in accessing the core network for authentication. In scenarios where non-3GPP devices access the communication network through personal IoT networks or home networks, the security of communication can be effectively guaranteed.
[0056] Optionally, the first message instructs the second terminal to request access to the first network element, or the first message requests the establishment of a session for the second terminal.
[0057] Optionally, the first terminal sends a first request to the first network element, including:
[0058] The first terminal sends the first message through the Non-Access Stratum (NAS) connection between the first terminal and the first network element.
[0059] Optionally, the first message further includes at least one of the following:
[0060] The identification information of the first terminal;
[0061] Non-3GPP equipment indication information;
[0062] N5CW instructions;
[0063] Instructions for terminal requests to access that do not support NAS;
[0064] Personal IoT indicator information;
[0065] Passive Internet of Things (IoT) indication information.
[0066] Optionally, the non-3GPP device indication information is non-3GPP device registration type information.
[0067] Optionally, the personal IoT indication information is the personal IoT element (PINE) registration type information.
[0068] Optionally, the identification information of the second terminal includes at least one of the following:
[0069] The Media Access Control (MAC) address of the second terminal;
[0070] The device identifier of the second terminal;
[0071] The International Mobile Subscriber Identity (IMSI) of the second terminal;
[0072] The second terminal's subscription permanent identifier (SUPI);
[0073] The second terminal's subscription cipher (SUCI);
[0074] The second terminal's Generic Public Subscription Identifier (GPSI).
[0075] As a first optional implementation, the first terminal obtains the identification information of the second terminal, including:
[0076] During the process of establishing a connection (such as an L2 connection) with the second terminal, the first terminal obtains the identification information of the second terminal.
[0077] Alternatively, the first terminal obtains the identification information of the second terminal through an authentication process. Optionally, the second terminal is associated with or connected to the first terminal's Wireless Local Area Network (WLAN). For example, the first and second terminals use an EAP authentication process.
[0078] For example, the above authentication process may specifically include:
[0079] The first terminal sends an EAP-Req / Identity message to the second terminal, and the second terminal sends an EAP-Res / Identity message to the first terminal. This EAP-Res / Identity message contains the second terminal's identification information. The second terminal's identification information can be sent via a Network Access Identity (NAI). Optionally, the second terminal can indicate that it does not support NAS access to the core network, or that it wishes to access the core network without NAS. For example, the NAI could contain the field 5gc-nn to indicate that it does not support NAS access to 5GC, or that it wishes to access 5GC without NAS.
[0080] The identification information of the second terminal can be used to identify the second terminal in a PIN or 5G system.
[0081] As a second optional implementation, the first terminal obtains the identification information of the second terminal, including:
[0082] The first terminal receives a first target request message sent by the second terminal. The first target request message is used to establish a secure connection with the first terminal device. For example, the first target request message may be an Internet Key Exchange (IKE) AUTH request message, which includes the identification information of the second terminal.
[0083] In this implementation, before the first terminal obtains the first target request message sent by the second terminal, an L2 connection is established between the first terminal and the second terminal, the second terminal obtains an IP address, and the first terminal and the second terminal establish an IP security association (IPsec Security Association, IPSec SA).
[0084] For example, the second terminal associates with or connects to the first terminal's WLAN and obtains an IP address from the first terminal's WLAN. The second terminal can request the IP address using Dynamic Host Configuration Protocol (DHCP) or other request messages.
[0085] Optionally, the first terminal may first authenticate the second terminal, and then assign an IP address to the second terminal after authentication.
[0086] In this implementation, as one possible approach, the second terminal sends a second target request message to the first terminal. This second target request message may specifically be an IKE_AUTH request message, and it does not carry the AUTH parameter, indicating that EAP authentication is required. The first terminal sends a response message to the second terminal, such as an IKE_AUTH response message, which includes the EAP request message. The second terminal then sends an IKE_AUTH request message to the first terminal, which includes the EAP response message and the second terminal's identification information.
[0087] In this embodiment, the first terminal obtains the identification information of the second terminal and sends a first message containing the identification information of the second terminal to the first network element. The first message triggers the authentication process for the second terminal, thereby achieving the purpose of using the first terminal (3GPP terminal) to assist the second terminal (non-3GPP terminal) in accessing the core network for authentication. In scenarios where non-3GPP devices access the communication network through personal IoT networks or home networks, the security of communication can be effectively guaranteed.
[0088] like Figure 3 As shown in the embodiments of this application, a device authentication method is also provided, including:
[0089] Step 301: The first network element receives a first message sent by the first terminal, the first message including the identification information of the second terminal.
[0090] Wherein, the first network element is a mobility management network element or a session management network element, such as the mobility management network element being an Access and Mobility Management Function (AMF) or the session management network element being a Session Management Function (SMF).
[0091] Step 302: The first network element triggers the authentication process for the second terminal based on the first message.
[0092] For example, the first terminal is a personal IoT gateway, and the second terminal is a device that cannot use the NAS protocol. As an alternative implementation, the second terminal can be a non-3GPP device or a personal IoT device. Alternatively, the second terminal can be a 3GPP device, and the connection between the second terminal and the first terminal does not support NAS protocol transmission. The first terminal can also be a home gateway. The first and second terminals can establish a connection via WiFi, Bluetooth, or Passive IoT technology. It is worth noting that when the first and second terminals establish a connection via passive IoT, the second terminal can be a 3GPP device or a non-3GPP device, and the passive IoT technology can be either a 3GPP access technology or a non-3GPP access technology.
[0093] In this embodiment, the first network element receives a first message containing the identification information of the second terminal sent by the first terminal, and triggers an authentication process for the second terminal based on the first message, thereby achieving the purpose of assisting the second terminal (non-3GPP terminal) in accessing the core network for authentication through the first terminal (3GPP terminal). In scenarios where non-3GPP devices access the communication network through personal IoT networks or home networks, the security of communication can be effectively guaranteed.
[0094] Optionally, the first message instructs the second terminal to request access to the first network element, or the first message requests the establishment of a session for the second terminal.
[0095] Optionally, the first network element receives a first message sent by the first terminal, including:
[0096] The first network element receives the first message through the NAS connection between the first terminal and the first network element.
[0097] Optionally, the first message further includes at least one of the following:
[0098] The identification information of the first terminal;
[0099] Non-3GPP equipment indication information;
[0100] Personal IoT indicator information;
[0101] N5CW instructions;
[0102] Instructions for terminal requests to access that do not support NAS;
[0103] Passive Internet of Things (IoT) indication information.
[0104] Optionally, the non-3GPP device indication information is non-3GPP device registration type information.
[0105] Optionally, the personal IoT indication information is the personal IoT element (PINE) registration type information.
[0106] Optionally, the identification information of the second terminal includes at least one of the following:
[0107] The media access control MAC address of the second terminal;
[0108] The device identifier of the second terminal;
[0109] The International Mobile Subscriber Identity (IMSI) of the second terminal;
[0110] The permanent identifier for the second terminal is SUPI.
[0111] The second terminal's contract encryption identifier SUCI;
[0112] The second terminal's general public contract identifier is GPSI.
[0113] Optionally, the first network element triggers an authentication process for the second terminal based on the first message, including:
[0114] The first network element sends a second message to the second network element based on the first message. The second message is used to request authentication of the second terminal.
[0115] Optionally, the first network element is a mobility management network element, and the second network element is an authentication server network element;
[0116] Alternatively, the first network element may be a session management network element, and the second network element may be a mobility management network element.
[0117] In one embodiment of this application, it is assumed that the first terminal is PEGC and the second terminal is PINE, such as... Figure 4 As shown, the above-mentioned device authentication methods include:
[0118] Step 401: Establish an L2 connection between PINE and PEGC.
[0119] For example, PINE is associated with or connected to the WLAN of PEGC.
[0120] Step 402: PEGC initiates the authentication process to obtain PINE's identification information.
[0121] PINE sends its own identification information to PEGC.
[0122] For example, PEGC and PINE use the EAP authentication process. For instance, PEGC sends an EAP-Req / Identity message to PINE. PINE sends an EAP-Res / Identity message to PEGC, which includes its own identifier. PINE's identifier can be sent in the form of a Network Access Identity (NAI). Optionally, PINE can indicate that it does not support NAS access to 5GC, or that it wishes to avoid NAS access to 5GC. For example, the NAI may include the field 5gc-nn indicating that it does not support NAS access to 5GC, or that it wishes to avoid NAS access to 5GC.
[0123] For example, the NAI sent by PINE can be type1.rid678.schid0.useriduser17@nai.5gc-nn.mnc123.mcc45.3gppnetwork.org.
[0124] The identification information of the PINE is used to identify the PINE in the PIN or 5G system. For example, it can be the PINE's MAC address, PINE's device identifier, IMSI, SUPI, SUCI, or GPSI, etc.
[0125] Step 403: PEGC sends a NAS message to AMF, instructing PINE to be connected to the core network.
[0126] For example, PEGC sends a registration request message to AMF, which includes at least one of the following: registration type, PEGC identifier, and PINE identifier. The registration type can indicate PINE registration or non-3GPP device registration. The registration request message can also be a PINE registration request message or a non-3GPP device registration request message, indicating that the PINE needs to be connected to the core network. The PINE identifier itself can also indicate that the PINE needs to be connected to the core network. Alternatively, the NAS message can also carry an N5CW indicator or a passive IoT indicator, indicating that an N5CW device or a passive IoT device is requesting access. Alternatively, the NAS message can also include an indication that a terminal that does not support NAS is requesting access, indicating that a device that does not support NAS when accessing 5GC via PEGC is requesting access.
[0127] PEGC can send the aforementioned NAS messages through its NAS connection with the AMF. The AMF is the AMF that serves the PEGC.
[0128] Step 404: After receiving the NAS message in step 3, the AMF triggers the core network's authentication process for the PINE.
[0129] For example, the AMF sends an authentication request to the AUSF, including a PIN indication or a non-3GPP indication. The EAP authentication process is then performed between the PINE and the Authentication Server Function (AUSF). Upon successful authentication, the AUSF sends an EAP-Success message to the AMF.
[0130] Step 405: AMF sends a NAS message to PEGC to indicate that PINE has successfully accessed the core network.
[0131] In this embodiment of the application, the registration request message can also be other NAS messages, and no specific limitation is made here.
[0132] In this embodiment, the PEGC can be replaced with a Residential Gateway (RG), and the PINE can be replaced with other non-3GPP equipment. Additionally, in this embodiment, the core network is sometimes referred to as the 5G Core network (5GC) or the 5G System (5GS). The access core network can also be referred to as the access communication network.
[0133] It is worth noting that the authentication of the PINE by the communication system can also be optional. For example, if the communication system trusts the PEGC, it may not need to authenticate the PINE accessing through the PEGC. Therefore, step 404 is optional. Optionally, step 404 can be replaced by the AMF receiving the NAS message and determining, based on the instruction in the message to access the PINE to the core network, not performing authentication of the PINE. In the embodiments of this application, step 2 of the PEGC may only be used to obtain the PINE's identification information, rather than to initiate the authentication process for the PINE.
[0134] In another embodiment of this application, it is assumed that the first terminal is PEGC and the second terminal is PINE, such as... Figure 5 As shown, the above-mentioned device authentication methods include:
[0135] Step 501: PINE establishes a connection with PEGC and obtains an IP address.
[0136] For example, the PINE associates with or connects to the PEGC's WLAN and obtains an IP address from the PEGC's WLAN. The PINE can obtain an IP address using a DHCP request or other message requests, which is not specifically limited in this embodiment.
[0137] Optionally, PEGC can authenticate the PINE before assigning it an IP address. This application does not specifically limit what information PEGC uses for PINE authentication.
[0138] Step 502: PINE establishes a secure IP connection with PEGC.
[0139] For example, PINE and PEGC exchange IKE initial messages to establish a secure IP connection.
[0140] Step 503: PINE sends an IKE_AUTH request message to PEGC.
[0141] As one possible implementation, the IKE_AUTH request message includes the identification information of the PINE. The identification information of the PINE can be found in the description in step 402.
[0142] As another possible implementation, PINE sends an IKE_AUTH request message to PEGC, without carrying the AUTH parameter, indicating that EAP authentication is required. PEGC sends an IKE_AUTH response message to PINE, which includes the EAP request message. PINE then sends an IKE_AUTH request message to PEGC, which includes the EAP response message and PINE's identification information.
[0143] Step 504: PEGC sends a NAS message to AMF to connect PINE to the core network.
[0144] Please refer to the description of step 403 in the above embodiments for details.
[0145] Step 505: After receiving the NAS message, the AMF triggers the core network's authentication process for the PINE.
[0146] This step can be referred to the description of step 404 above. The difference is that PINE and PEGC use the IKE message passing authentication process to exchange information.
[0147] Step 506: AMF sends a NAS message to PEGC to indicate that PINE has successfully connected to the core network.
[0148] The registration request message in this embodiment can also be replaced with other NAS messages, and this embodiment does not specifically limit this.
[0149] It is worth noting that authentication of the PINE by the communication system can also be optional. For example, if the communication system trusts PEGC, it may not need to authenticate the PINE accessing through PEGC. Therefore, step 505 is optional. Optionally, step 404 can be replaced by the AMF receiving the NAS message and determining, based on the instruction in the message to access the PINE to the core network, not to perform authentication of the PINE.
[0150] In another embodiment of this application, it is assumed that the first terminal is PEGC and the second terminal is PINE, as follows: Figure 6 As shown, the above-mentioned device authentication methods include:
[0151] Step 601: Establish an L2 connection between PINE and PEGC.
[0152] Step 602: PEGC initiates the authentication process to obtain PINE's identification information.
[0153] Steps 601 and 602 can be referred to the descriptions of steps 401 and 402, and will not be repeated here.
[0154] Step 603: PEGC sends a NAS message to AMF to connect PINE to the core network.
[0155] The NAS message includes at least one of the following: registration type, PEGC identifier, and PINE identifier. The registration type can indicate PINE registration or registration for a non-3GPP device. The NAS message can also be a PINE registration request message or a non-3GPP device registration request message. The PINE identifier itself can also indicate that the PINE needs to be connected to the core network. Alternatively, the NAS message can also carry an N5CW indicator or a passive IoT indicator, indicating that an N5CW device or passive IoT device is requesting access. Alternatively, the NAS message can also include an indication that a terminal that does not support NAS is requesting access, indicating that a device that does not support NAS when accessing 5GC via PEGC is requesting access.
[0156] Optionally, the NAS message includes an N1 Session Management (SM) message, used to instruct the SMF to connect the PINE to the core network.
[0157] N1 SM messages can be PDU session establishment request messages or other N1 SM messages.
[0158] The above registration types, at least one of the PEGC identifier and the PINE identifier can be included in the N1 SM message.
[0159] PEGC can send the aforementioned NAS messages through its NAS connection with the AMF. The AMF is the AMF that serves the PEGC.
[0160] Step 604: The AMF sends an N11 message to the SMF to connect the PINE to the core network.
[0161] The N11 message includes at least one of the following: registration type, PEGC identifier, and PINE identifier.
[0162] If step 603 includes an N1 SM message, then the AMF sends an N1 SM message to the SMF.
[0163] For example, the N11 message can be a PINE session establishment request message.
[0164] The N11 message in this step can also be represented as PINE establishing a session channel or allocating network resources.
[0165] Step 605: SMF sends a response message to AMF for the N11 message to trigger the authentication process for PINE.
[0166] The response message to the N11 message may include an identifier for PINE. Optionally, it may also include an identifier for PEGC.
[0167] SMF can be a session management network element serving PEGC. The need for PINE authentication can be determined based on PEGC subscriptions, operator policies, etc.
[0168] For example, the response message to the N11 message can be a PINE authentication request message.
[0169] Step 606: AMF triggers the core network's authentication process for PINE.
[0170] Step 606 can be referred to the description of step 404.
[0171] Step 607: AMF sends an N11 message to SMF, indicating that PINE authentication was successful.
[0172] For example, the N11 message can be a PINE authentication response message.
[0173] In this embodiment of the application, steps 605 to 607 are optional steps.
[0174] Optionally, the SMF sends an N11 message to the AMF to indicate that the PINE session has been successfully established.
[0175] For example, the N11 message can be a response message for establishing a PINE session.
[0176] Optionally, AMF sends a NAS message to PEGC to indicate that PINE access was successful.
[0177] For example, the NAS message can be a PINE registration or a non-3GPP device registration request message.
[0178] Optionally, SMF allocates user plane resources or session resources to PINE. This scheme can simultaneously trigger authentication and session establishment with a single NAS message in step 603, saving network resources.
[0179] Through the above steps, PINE successfully connected to 5GC. This can also be considered as the PINE session channel being established or the network successfully allocating resources to PINE.
[0180] It is worth noting that the authentication of the PINE by the communication system can also be optional. For example, if the communication system trusts the PEGC, it may not need to authenticate the PINE accessing through the PEGC. Therefore, steps 605-607 can be omitted, or step 606 can be omitted. Optionally, step 605 can be replaced by the SMF receiving the N11 message and determining not to perform authentication of the PINE based on the instruction in the message to access the core network. Alternatively, step 606 can be replaced by the AMF receiving the response message of the N11 message and determining not to perform authentication of the PINE based on the PINE's identifier and / or the PEGC's identifier. In the embodiments of this application, the PEGC in step 602 may simply be used to obtain the PINE's identifier information, rather than to initiate the authentication process for the PINE.
[0181] In another embodiment of this application, it is assumed that the first terminal is PEGC and the second terminal is PINE, as follows: Figure 7 As shown, the above-mentioned device authentication methods include:
[0182] Step 701: PINE establishes a connection with PEGC and obtains an IP address.
[0183] For details, please refer to the description in step 501.
[0184] Step 702: PINE establishes a secure IP connection with PEGC.
[0185] For example, PINE and PEGC exchange IKE initial messages to establish a secure IP connection.
[0186] Step 703: PINE sends an IKE_AUTH request message to PEGC.
[0187] For details, please refer to the description in step 503.
[0188] Step 704: PEGC sends a NAS message to AMF to connect PINE to the core network.
[0189] Step 705: The AMF sends an N11 message to the SMF to connect the PINE to the core network.
[0190] Step 706: SMF sends a response message to AMF for the N11 message to trigger the authentication process for PINE.
[0191] Step 707: AMF triggers the core network's authentication process for PINE.
[0192] Step 708: AMF sends an N11 message to SMF, indicating that PINE authentication was successful.
[0193] In this embodiment of the application, steps 706 to 708 are optional steps.
[0194] Steps 704 to 708 above can be referred to the description of steps 603 to 607 above.
[0195] Optionally, the SMF sends an N11 message to the AMF to indicate that the PINE session has been successfully established.
[0196] For example, the N11 message can be a response message for establishing a PINE session.
[0197] Optionally, AMF sends a NAS message to PEGC to indicate that PINE access was successful.
[0198] For example, the NAS message can be a PINE registration or a non-3GPP device registration request message.
[0199] Optionally, SMF allocates user plane resources or session resources to PINE. This scheme can simultaneously trigger authentication and session establishment with a single NAS message in step 703, saving network resources.
[0200] Through the above steps, PINE successfully connected to 5GC. This can also be considered as the PINE session channel being established or the network successfully allocating resources to PINE.
[0201] In this embodiment, 3GPP terminal equipment assists non-3GPP equipment in accessing the 5G core network for authentication, thus ensuring communication security in scenarios where non-3GPP equipment accesses the communication network through personal IoT networks or home networks.
[0202] It is worth noting that the authentication of PINEs by the communication system can also be optional. For example, if the communication system trusts PEGC, it may not need to authenticate PINEs accessing through PEGC. Therefore, steps 706-708 can be omitted, or step 707 can be omitted. Optionally, step 706 can be replaced by the SMF, upon receiving the N11 message, determining not to perform authentication of the PINE based on the instruction in the message to access the core network. Alternatively, step 707 can be replaced by the AMF, upon receiving the response message to the N11 message, determining not to perform authentication of the PINE based on the PINE's identifier and / or the PEGC's identifier.
[0203] The device authentication method provided in this application can be executed by a device authentication device. This application uses the example of a device authentication device executing the device authentication method to illustrate the device authentication device provided in this application.
[0204] like Figure 8 As shown, this application embodiment provides a device authentication device 800, applied to a first terminal, the device comprising:
[0205] The first acquisition module 801 is used to acquire the identification information of the second terminal;
[0206] The first sending module 802 is used to send a first message to the first network element. The first message includes the identification information of the second terminal and is used to trigger the authentication process for the second terminal.
[0207] Optionally, the first message instructs the second terminal to request access to the first network element, or the first message requests the establishment of a session for the second terminal.
[0208] Optionally, the first sending module is used to send the first message through a non-access stratum (NAS) connection between the first terminal and the first network element.
[0209] Optionally, the first message further includes at least one of the following:
[0210] The identification information of the first terminal;
[0211] Non-3GPP equipment indication information;
[0212] Personal IoT indicator information;
[0213] N5CW instructions;
[0214] Instructions for terminal requests to access that do not support NAS;
[0215] Passive Internet of Things (IoT) indication information.
[0216] Optionally, the non-3GPP device indication information is non-3GPP device registration type information.
[0217] Optionally, the personal IoT indication information is the personal IoT element (PINE) registration type information.
[0218] Optionally, the identification information of the second terminal includes at least one of the following:
[0219] The media access control MAC address of the second terminal;
[0220] The device identifier of the second terminal;
[0221] The International Mobile Subscriber Identity (IMSI) of the second terminal;
[0222] The permanent identifier for the second terminal is SUPI.
[0223] The second terminal's contract encryption identifier SUCI;
[0224] The second terminal's general public contract identifier is GPSI.
[0225] Optionally, the first network element is a mobility management network element or a session management network element.
[0226] Optionally, the first terminal is a personal IoT gateway.
[0227] Optionally, the second terminal is a non-3GPP device or a personal IoT device.
[0228] In this embodiment, the first terminal obtains the identification information of the second terminal and sends a first message containing the identification information of the second terminal to the first network element. The first message triggers the authentication process for the second terminal, thereby achieving the purpose of using the first terminal (3GPP terminal) to assist the second terminal (non-3GPP terminal) in accessing the core network for authentication. In scenarios where non-3GPP devices access the communication network through personal IoT networks or home networks, the security of communication can be effectively guaranteed.
[0229] The device authentication device in this application embodiment can be an electronic device, such as an electronic device with an operating system, or a component in an electronic device, such as an integrated circuit or a chip. The electronic device can be a terminal, or other devices besides a terminal. For example, the terminal can include, but is not limited to, the type of terminal 11 listed above; other devices can be servers, network attached storage (NAS), etc., and this application embodiment does not specifically limit the type.
[0230] The device authentication device provided in this application embodiment can achieve... Figure 2 The various processes implemented in the method embodiments achieve the same technical effect, and will not be described again here to avoid repetition.
[0231] Optional, such as Figure 9As shown, this application embodiment also provides a communication device 900, including a processor 901 and a memory 902. The memory 902 stores a program or instructions that can run on the processor 901. For example, when the communication device 900 is a terminal, the program or instructions executed by the processor 901 implement the various steps of the device authentication method embodiment applied to the first terminal described above, and achieve the same technical effect. When the communication device 900 is a network-side device (such as a first network element), the program or instructions executed by the processor 901 implement the various steps of the device authentication method embodiment applied to the first network element described above, and achieve the same technical effect. To avoid repetition, further details are omitted here.
[0232] This application embodiment also provides a terminal, including a processor and a communication interface. The processor is used to acquire identification information of a second terminal; the communication interface is used to send a first message to a first network element, the first message including the identification information of the second terminal, and the first message is used to trigger an authentication process for the second terminal. This terminal embodiment corresponds to the above-described terminal-side method embodiment. All implementation processes and methods of the above-described method embodiments can be applied to this terminal embodiment and achieve the same technical effect. Specifically, Figure 10 A schematic diagram of the hardware structure of a terminal to implement an embodiment of this application.
[0233] The terminal 1000 includes, but is not limited to, at least some of the following components: radio frequency unit 1001, network module 1002, audio output unit 1003, input unit 1004, sensor 1005, display unit 1006, user input unit 1007, interface unit 1008, memory 1009, and processor 1010.
[0234] Those skilled in the art will understand that the terminal 1000 may also include a power supply (such as a battery) for supplying power to various components. The power supply may be logically connected to the processor 1010 through a power management system, thereby enabling functions such as managing charging, discharging, and power consumption through the power management system. Figure 10 The terminal structure shown does not constitute a limitation on the terminal. The terminal may include more or fewer components than shown, or combine certain components, or have different component arrangements, which will not be elaborated here.
[0235] It should be understood that, in this embodiment, the input unit 1004 may include a graphics processing unit (GPU) 10041 and a microphone 10042. The GPU 10041 processes image data of still images or videos obtained by an image capture device (such as a camera) in video capture mode or image capture mode. The display unit 1006 may include a display panel 10061, which may be configured in the form of a liquid crystal display, an organic light-emitting diode, etc. The user input unit 1007 includes a touch panel 10071 and at least one of other input devices 10072. The touch panel 10071 is also called a touch screen. The touch panel 10071 may include a touch detection device and a touch controller. Other input devices 10072 may include, but are not limited to, physical keyboards, function keys (such as volume control buttons, power buttons, etc.), trackballs, mice, joysticks, etc., which will not be described in detail here.
[0236] In this embodiment, after receiving downlink data from the network-side device, the radio frequency unit 1001 can transmit it to the processor 1010 for processing; in addition, the radio frequency unit 1001 can send uplink data to the network-side device. Typically, the radio frequency unit 1001 includes, but is not limited to, antennas, amplifiers, transceivers, couplers, low-noise amplifiers, duplexers, etc.
[0237] The memory 1009 can be used to store software programs or instructions and various data. The memory 1009 may primarily include a first storage area for storing programs or instructions and a second storage area for storing data. The first storage area may store the operating system, application programs or instructions required for at least one function (such as sound playback function, image playback function, etc.). Furthermore, the memory 1009 may include volatile memory or non-volatile memory, or both. The non-volatile memory may be read-only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), or flash memory. Volatile memory can be random access memory (RAM), static random access memory (SRAM), dynamic random access memory (DRAM), synchronous dynamic random access memory (SDRAM), double data rate synchronous dynamic random access memory (DDRSDRAM), enhanced synchronous dynamic random access memory (ESDRAM), synchronous link dynamic random access memory (SLDRAM), and direct memory bus RAM (DRRAM). The memory 1009 in this embodiment includes, but is not limited to, these and any other suitable types of memory.
[0238] The processor 1010 may include one or more processing units; optionally, the processor 1010 integrates an application processor and a modem processor, wherein the application processor mainly handles operations involving the operating system, user interface, and applications, and the modem processor mainly handles wireless communication signals, such as a baseband processor. It is understood that the aforementioned modem processor may also not be integrated into the processor 1010.
[0239] The processor 1010 is used to obtain the identification information of the second terminal;
[0240] The radio frequency unit 1001 is used to send a first message to the first network element. The first message includes the identification information of the second terminal and is used to trigger the authentication process for the second terminal.
[0241] Optionally, the first message instructs the second terminal to request access to the first network element, or the first message requests the establishment of a session for the second terminal.
[0242] Optionally, the radio frequency unit 1001 is used to send the first message through the non-access stratum (NAS) connection between the first terminal and the first network element.
[0243] Optionally, the first message further includes at least one of the following:
[0244] The identification information of the first terminal;
[0245] Non-3GPP equipment indication information;
[0246] Personal IoT indicator information;
[0247] N5CW instructions;
[0248] Instructions for terminal requests to access that do not support NAS;
[0249] Passive Internet of Things (IoT) indication information.
[0250] Optionally, the non-3GPP device indication information is non-3GPP device registration type information.
[0251] Optionally, the personal IoT indication information is the personal IoT element (PINE) registration type information.
[0252] Optionally, the identification information of the second terminal includes at least one of the following:
[0253] The media access control MAC address of the second terminal;
[0254] The device identifier of the second terminal;
[0255] The International Mobile Subscriber Identity (IMSI) of the second terminal;
[0256] The permanent identifier for the second terminal is SUPI.
[0257] The second terminal's contract encryption identifier SUCI;
[0258] The second terminal's general public contract identifier is GPSI.
[0259] Optionally, the first network element is a mobility management network element or a session management network element.
[0260] Optionally, the first terminal is a personal IoT gateway.
[0261] Optionally, the second terminal is a non-3GPP device or a personal IoT device.
[0262] In this embodiment, the first terminal obtains the identification information of the second terminal and sends a first message containing the identification information of the second terminal to the first network element. The first message triggers the authentication process for the second terminal, thereby achieving the purpose of using the first terminal (3GPP terminal) to assist the second terminal (non-3GPP terminal) in accessing the core network for authentication. In scenarios where non-3GPP devices access the communication network through personal IoT networks or home networks, the security of communication can be effectively guaranteed.
[0263] like Figure 11 As shown in the figure, this application embodiment also provides a device authentication device 1100, including:
[0264] The first receiving module 1101 is used to receive a first message sent by the first terminal, the first message including the identification information of the second terminal;
[0265] The processing module 1102 is used to trigger the authentication process for the second terminal based on the first message.
[0266] Optionally, the first message instructs the second terminal to request access to the first network element, or the first message requests the establishment of a session for the second terminal.
[0267] Optionally, the first receiving module is configured to receive the first message through a NAS connection between the first terminal and the first network element.
[0268] Optionally, the first message further includes at least one of the following:
[0269] The identification information of the first terminal;
[0270] Non-3GPP equipment indication information;
[0271] Personal IoT indicator information;
[0272] N5CW instructions;
[0273] Instructions for terminal requests to access that do not support NAS;
[0274] Passive Internet of Things (IoT) indication information.
[0275] Optionally, the non-3GPP device indication information is non-3GPP device registration type information.
[0276] Optionally, the personal IoT indication information is the personal IoT element (PINE) registration type information.
[0277] Optionally, the identification information of the second terminal includes at least one of the following:
[0278] The media access control MAC address of the second terminal;
[0279] The device identifier of the second terminal;
[0280] The International Mobile Subscriber Identity (IMSI) of the second terminal;
[0281] The permanent identifier for the second terminal is SUPI.
[0282] The second terminal's contract encryption identifier SUCI;
[0283] The second terminal's general public contract identifier is GPSI.
[0284] Optionally, the processing module is configured to send a second message to the second network element based on the first message, the second message being used to request authentication of the second terminal.
[0285] Optionally, the first network element is a mobility management network element, and the second network element is an authentication server network element;
[0286] Alternatively, the first network element may be a session management network element, and the second network element may be a mobility management network element.
[0287] Optionally, the first terminal is a personal IoT gateway.
[0288] Optionally, the second terminal is a non-3GPP device or a personal IoT device.
[0289] In this embodiment, the first terminal obtains the identification information of the second terminal and sends a first message containing the identification information of the second terminal to the first network element. The first message triggers the authentication process for the second terminal, thereby achieving the purpose of using the first terminal (3GPP terminal) to assist the second terminal (non-3GPP terminal) in accessing the core network for authentication. In scenarios where non-3GPP devices access the communication network through personal IoT networks or home networks, the security of communication can be effectively guaranteed.
[0290] This application embodiment also provides a network-side device (i.e., the first network element mentioned above), including a processor and a communication interface. The communication interface is used to receive a first message sent by a first terminal, the first message including the identification information of the second terminal; the processor is used to trigger an authentication process for the second terminal according to the first message.
[0291] This network-side device embodiment corresponds to the above-described network-side device method embodiment. All implementation processes and methods of the above-described method embodiment can be applied to this network-side device embodiment and can achieve the same technical effect.
[0292] Specifically, embodiments of this application also provide a network-side device (the aforementioned first network element). For example... Figure 12As shown, the network-side device 1300 includes a processor 1301, a network interface 1302, and a memory 1303. The network interface 1302 is, for example, a common public radio interface (CPRI).
[0293] Specifically, the network-side device 1300 of this embodiment further includes: instructions or programs stored in memory 1303 and executable on processor 1301, wherein processor 1301 calls the instructions or programs in memory 1303 to execute. Figure 11 The methods executed by each module shown achieve the same technical effect, and to avoid repetition, they will not be described in detail here.
[0294] This application also provides a readable storage medium storing a program or instructions. When the program or instructions are executed by a processor, they implement the various processes of the above-described device authentication method embodiments and achieve the same technical effect. To avoid repetition, they will not be described again here.
[0295] The processor is the processor in the terminal described in the above embodiments. The readable storage medium includes computer-readable storage media, such as computer read-only memory (ROM), random access memory (RAM), magnetic disk, or optical disk.
[0296] This application embodiment also provides a chip, which includes a processor and a communication interface. The communication interface is coupled to the processor. The processor is used to run programs or instructions to implement the various processes of the above-described device authentication method embodiments and can achieve the same technical effect. To avoid repetition, it will not be described again here.
[0297] It should be understood that the chip mentioned in the embodiments of this application may also be referred to as a system-on-a-chip, system chip, chip system, or system-on-a-chip, etc.
[0298] This application also provides a computer program / program product, which is stored in a storage medium and executed by at least one processor to implement the various processes of the above-described device authentication method embodiments, and can achieve the same technical effect. To avoid repetition, it will not be described again here.
[0299] This application embodiment also provides a device authentication system, including: a terminal and a network-side device, wherein the terminal can be used to execute the steps of the device authentication method applied to the first terminal as described above, and the network-side device can be used to execute the steps of the device authentication method applied to the first network element as described above.
[0300] It should be noted that, in this document, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitations, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes that element. Furthermore, it should be noted that the scope of the methods and apparatuses in the embodiments of this application is not limited to performing functions in the order shown or discussed, but may also include performing functions substantially simultaneously or in the reverse order, depending on the functions involved. For example, the described methods may be performed in a different order than described, and various steps may be added, omitted, or combined. Additionally, features described with reference to certain examples may be combined in other examples.
[0301] Through the above description of the embodiments, those skilled in the art can clearly understand that the methods of the above embodiments can be implemented by means of software plus necessary general-purpose hardware platforms. Of course, they can also be implemented by hardware, but in many cases the former is a better implementation method. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, can be embodied in the form of a computer software product. This computer software product is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk) and includes several instructions to cause a terminal (which may be a mobile phone, computer, server, air conditioner, or network device, etc.) to execute the methods described in the various embodiments of this application.
[0302] The embodiments of this application have been described above with reference to the accompanying drawings. However, this application is not limited to the specific embodiments described above. The specific embodiments described above are merely illustrative and not restrictive. Those skilled in the art can make many other forms under the guidance of this application without departing from the spirit and scope of the claims, and all of these forms are within the protection scope of this application.
Claims
1. A device authentication method, characterized in that, include: The first terminal obtains the identification information of the second terminal; wherein the second terminal is a device that does not support the NAS protocol; The first terminal sends a first message to the first network element. The first message includes the identification information of the second terminal and is used to trigger the authentication process for the second terminal. The first message further includes at least one of the following: The identification information of the first terminal; Non-3GPP equipment indication information; Personal IoT indicator information; The N5CW indicates that it lacks 5G capability on Wi-Fi. Instructions for terminal requests to access that do not support NAS; Passive Internet of Things (IoT) indication information.
2. The method according to claim 1, characterized in that, The first message instructs the second terminal to request access to the first network element, or the first message requests the establishment of a session for the second terminal.
3. The method according to claim 1, characterized in that, The first terminal sends a first request to the first network element, including: The first terminal sends the first message through the non-access stratum (NAS) connection between the first terminal and the first network element.
4. The method according to claim 1, characterized in that, The non-3GPP device indication information is the non-3GPP device registration type information.
5. The method according to claim 1, characterized in that, The Personal Internet of Things (IoT) indication information is the Personal Internet of Things (PINE) registration type information.
6. The method according to claim 1, characterized in that, The identification information of the second terminal includes at least one of the following: The media access control MAC address of the second terminal; The device identifier of the second terminal; The International Mobile Subscriber Identity (IMSI) of the second terminal; The permanent identifier for the second terminal is SUPI. The second terminal's contract encryption identifier SUCI; The second terminal's general public contract identifier is GPSI.
7. The method according to claim 1, characterized in that, The first network element is a mobility management network element or a session management network element.
8. The method according to claim 1, characterized in that, The first terminal is a personal IoT gateway.
9. The method according to claim 1, characterized in that, The second terminal is a non-3GPP device or a personal IoT device.
10. A device authentication method, characterized in that, include: The first network element receives a first message sent by the first terminal, the first message including the identification information of the second terminal; wherein the second terminal is a device that does not support the NAS protocol; The first network element triggers the authentication process for the second terminal based on the first message; The first message further includes at least one of the following: The identification information of the first terminal; Non-3GPP equipment indication information; Personal IoT indicator information; N5CW instructions; Instructions for terminal requests to access that do not support NAS; Passive Internet of Things (IoT) indication information.
11. The method according to claim 10, characterized in that, The first message instructs the second terminal to request access to the first network element, or the first message requests the establishment of a session for the second terminal.
12. The method according to claim 10, characterized in that, The first network element receives a first message sent by the first terminal, including: The first network element receives the first message through the NAS connection between the first terminal and the first network element.
13. The method according to claim 10, characterized in that, The non-3GPP device indication information is the non-3GPP device registration type information.
14. The method according to claim 10, characterized in that, The Personal Internet of Things (IoT) indication information is the Personal Internet of Things (PINE) registration type information.
15. The method according to claim 10, characterized in that, The identification information of the second terminal includes at least one of the following: The media access control MAC address of the second terminal; The device identifier of the second terminal; The International Mobile Subscriber Identity (IMSI) of the second terminal; The permanent identifier for the second terminal is SUPI. The second terminal's contract encryption identifier SUCI; The second terminal's general public contract identifier is GPSI.
16. The method according to claim 10, characterized in that, The first network element triggers an authentication process for the second terminal based on the first message, including: The first network element sends a second message to the second network element based on the first message. The second message is used to request authentication of the second terminal.
17. The method according to claim 16, characterized in that, The first network element is a mobility management network element, and the second network element is an authentication server network element; Alternatively, the first network element may be a session management network element, and the second network element may be a mobility management network element.
18. The method according to claim 10, characterized in that, The first terminal is a personal IoT gateway.
19. The method according to claim 10, characterized in that, The second terminal is a non-3GPP device or a personal IoT device.
20. A device authentication device, characterized in that, include: The first acquisition module is used to acquire the identification information of the second terminal; wherein the second terminal is a device that does not support the NAS protocol; The first sending module is used to send a first message to the first network element. The first message includes the identification information of the second terminal and is used to trigger the authentication process for the second terminal. The first message further includes at least one of the following: Identification information of the first terminal; Non-3GPP equipment indication information; Personal IoT indicator information; The N5CW indicates that it lacks 5G capability on Wi-Fi. Instructions for terminal requests to access that do not support NAS; Passive Internet of Things (IoT) indication information.
21. The apparatus according to claim 20, characterized in that, The first message instructs the second terminal to request access to the first network element, or the first message requests the establishment of a session for the second terminal.
22. The apparatus according to claim 20, characterized in that, The first sending module is used to send the first message through a non-access stratum (NAS) connection between the first terminal and the first network element.
23. The apparatus according to claim 20, characterized in that, The identification information of the second terminal includes at least one of the following: The media access control MAC address of the second terminal; The device identifier of the second terminal; The International Mobile Subscriber Identity (IMSI) of the second terminal; The permanent identifier for the second terminal is SUPI. The second terminal's contract encryption identifier SUCI; The second terminal's general public contract identifier is GPSI.
24. A device authentication device, applied to a first network element, characterized in that, include: The first receiving module is configured to receive a first message sent by a first terminal, the first message including the identification information of a second terminal; wherein the second terminal is a device that does not support the NAS protocol; The processing module is used to trigger the authentication process for the second terminal based on the first message; The first message further includes at least one of the following: The identification information of the first terminal; Non-3GPP equipment indication information; Personal IoT indicator information; N5CW instructions; Instructions for terminal requests to access that do not support NAS; Passive Internet of Things (IoT) indication information.
25. The apparatus according to claim 24, characterized in that, The first message instructs the second terminal to request access to the first network element, or the first message requests the establishment of a session for the second terminal.
26. The apparatus according to claim 24, characterized in that, The first receiving module is used to receive the first message through the NAS connection between the first terminal and the first network element.
27. The apparatus according to claim 24, characterized in that, The identification information of the second terminal includes at least one of the following: The media access control MAC address of the second terminal; The device identifier of the second terminal; The International Mobile Subscriber Identity (IMSI) of the second terminal; The permanent identifier for the second terminal is SUPI. The second terminal's contract encryption identifier SUCI; The second terminal's general public contract identifier is GPSI.
28. The apparatus according to claim 24, characterized in that, The processing module is used to send a second message to the second network element according to the first message, the second message being used to request authentication of the second terminal.
29. The apparatus according to claim 28, characterized in that, The first network element is a mobility management network element, and the second network element is an authentication server network element; Alternatively, the first network element may be a session management network element, and the second network element may be a mobility management network element.
30. A terminal, characterized in that, It includes a processor and a memory, the memory storing a program or instructions that can run on the processor, the program or instructions being executed by the processor to implement the steps of the device authentication method as described in any one of claims 1 to 9.
31. A network-side device, characterized in that, It includes a processor and a memory, the memory storing a program or instructions that can run on the processor, the program or instructions being executed by the processor to implement the steps of the device authentication method as described in any one of claims 10 to 19.
32. A readable storage medium, characterized in that, The readable storage medium stores a program or instructions that, when executed by a processor, implement the steps of the device authentication method as described in any one of claims 1 to 9, or implement the steps of the device authentication method as described in any one of claims 10 to 19.
Citation Information
Patent Citations
Authentication access method and device
CN109391941A