Network authentication method and device, communication device and computer readable storage medium

By working together with the core network and relay equipment, authentication requests and responses are generated and processed, solving the problem of low authentication efficiency between terminals and the network and achieving efficient terminal and network authentication.

CN116709322BActive Publication Date: 2026-01-13CHINA TELECOM CORP LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202310774069.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-06-27
Publication Date
2026-01-13
Estimated Expiration
2043-06-27

AI Technical Summary

Technical Problem

In existing technologies, network authentication between terminals and between terminals and networks is inefficient and complex, requiring additional device-to-device authentication mechanisms.

Method used

The authentication request and response are generated by the first and second network devices in the core network working together. The authentication parameters and relay devices are used to process the intermediate authentication data to achieve authentication between user equipment and relay devices.

Benefits of technology

The authentication process can complete the authentication between user equipment and relay equipment, as well as the authentication between relay equipment and the network, reducing system complexity and improving network authentication efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116709322B_ABST
    Figure CN116709322B_ABST
Patent Text Reader

Abstract

The application relates to a network authentication method and device, communication equipment and a computer readable storage medium. The method comprises the following steps: a first network device generates an authentication request based on a user equipment identifier and a relay device identifier carried in a target registration request sent by a relay device and sends the authentication request to a second network device in response to receiving the target registration request; the second network device generates an authentication parameter response according to a corresponding authentication protocol according to the user equipment identifier in the received authentication request and sends the authentication parameter response to the first network device; the first network device generates authentication intermediate data based on target authentication parameters and sends the authentication intermediate data to the relay device; and the first network device receives a target authentication response fed back by the relay device, authenticates the user equipment and the relay device according to response parameters corresponding to the target authentication response, and sends an authentication result to the relay device. The method can effectively improve the network authentication efficiency between the user equipment, the relay device and the core network.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of network communication technology, and in particular to a network authentication method, apparatus, communication equipment, and computer-readable storage medium. Background Technology

[0002] With the development of network communication technology, when a terminal accesses the network through one or more relays, it is necessary to consider the mutual authentication issues between terminals and between terminals and the network.

[0003] Existing mechanisms generally employ additional mechanisms separate from cellular network access authentication to solve this problem independently. This requires enabling additional device-to-device authentication mechanisms, resulting in high system complexity and low network authentication efficiency. Summary of the Invention

[0004] Therefore, it is necessary to provide a network authentication method, apparatus, communication equipment, and computer-readable storage medium to address the aforementioned technical problems, which can effectively improve the network authentication efficiency between user equipment, relay equipment, and core network.

[0005] Firstly, this application provides a network authentication method applied to a core network, the core network including a first network device and a second network device, comprising:

[0006] In response to receiving the target registration request sent by the relay device, the first network device generates an authentication request based on the user equipment identifier and the relay device identifier carried in the target registration request, and sends it to the second network device.

[0007] The second network device obtains the corresponding subscription information based on the user equipment identifier in the received authentication request, determines the corresponding authentication protocol based on the subscription information, generates an authentication parameter response based on the authentication protocol, and sends it to the first network device.

[0008] The first network device determines the target authentication parameters from the authentication parameter response, generates intermediate authentication data based on the target authentication parameters, and sends it to the relay device so that the relay device selects target reference data from the intermediate authentication data, generates corresponding target reference authentication data, and generates the target authentication response based on the initial authentication response fed back by the user equipment based on the target reference authentication data, and generates the target authentication response according to the response parameters corresponding to the initial authentication response, and sends it to the core network.

[0009] Receive the target authentication response from the relay device, authenticate the user equipment and the relay device according to the response parameters corresponding to the target authentication response, and send the authentication result to the relay device.

[0010] In one embodiment, the second network device obtains the corresponding subscription information based on the user equipment identifier in the received authentication request, determines the corresponding authentication protocol based on the subscription information, generates an authentication parameter response according to the authentication protocol, and sends it to the first network device, including:

[0011] The second network device includes a first functional device and a second functional device;

[0012] The first functional device receives the authentication request and forwards it to the second functional device;

[0013] The second functional device obtains the corresponding subscription information based on the user equipment identifier in the authentication request, determines the corresponding authentication protocol based on the subscription information, and generates the first authentication vector according to the authentication protocol through a preset algorithm.

[0014] The second functional device sends the first authentication vector to the first functional device;

[0015] The first functional device determines the expected response parameters from the first authentication vector, and obtains the hash value of the expected response by fusing the expected response parameters with a random number, and constructs the second authentication vector based on the hash value;

[0016] An authentication parameter response is generated based on the second authentication vector and sent to the first network device.

[0017] In one embodiment, the second functional device obtains the corresponding subscription information based on the user equipment identifier in the authentication request, determines the corresponding authentication protocol based on the subscription information, and generates a first authentication vector according to the authentication protocol using a preset algorithm, including:

[0018] The authentication request includes the device location parameters corresponding to the relay device and the network identifier of the location corresponding to the relay device;

[0019] The network location parameters are obtained by logical operations based on the device location parameters and the local network identifier;

[0020] The first authentication vector is constructed based on the network location parameters.

[0021] In one embodiment, the first functional device determines the expected response parameters from the first authentication vector, obtains the hash value of the expected response by fusing the expected response parameters with a random number, and constructs a second authentication vector based on the hash value, including:

[0022] The authentication request includes the device location parameters corresponding to the relay device and the network identifier of the location corresponding to the relay device;

[0023] The network location parameters are obtained by logical operations based on the device location parameters and the local network identifier;

[0024] A second authentication vector is constructed based on the hash value and network location parameters.

[0025] In one embodiment, the above network authentication method further includes:

[0026] The first network device sends a query command to the second network device, so that the second network device can query the subscription information corresponding to the relay device identifier in the target registration request according to the query command;

[0027] Based on the query results, determine the relay service permissions of the relay device;

[0028] If the relay service permission is insufficient, the target registration request is rejected.

[0029] Secondly, this application also provides a network authentication method applied to a relay device, comprising:

[0030] Receive an initial registration request sent by a user equipment, the initial registration request including the user equipment identifier of the user equipment;

[0031] A target registration request is generated based on the initial registration request. The target registration request includes the user equipment identifier and the relay device identifier of the relay device.

[0032] The target registration request is sent to the core network, so that the core network determines the target authentication protocol based on the subscription information corresponding to the user equipment identifier, and generates corresponding authentication intermediate data according to the target authentication protocol through the user equipment identifier and the relay device identifier;

[0033] Receive intermediate authentication data from the core network, generate corresponding target reference authentication data based on the target reference data selected from the intermediate authentication data, and send the target reference authentication data to the user equipment.

[0034] The system receives the initial authentication response from the user equipment based on the target reference authentication data, generates the target authentication response according to the response parameters corresponding to the initial authentication response, and sends it to the core network. This enables the core network to generate the corresponding response parameters based on the target authentication response, authenticate the user equipment and the relay equipment based on the response parameters and the target parameters in the authentication intermediate data, and feeds back the authentication results to the relay equipment.

[0035] The authentication results fed back by the core network are sent to the user equipment to complete the network authentication between the user equipment and the relay equipment, as well as between the user equipment and the core network.

[0036] In one embodiment, receiving intermediate authentication data fed back from the core network, generating corresponding target reference authentication data based on target reference data selected from the intermediate authentication data, and sending the target reference authentication data to the user equipment includes:

[0037] The target reference data includes random parameters and authentication token parameters;

[0038] Generate corresponding target reference authentication data based on random parameters and authentication token parameters;

[0039] The target reference authentication data is sent to the user equipment so that the user equipment can verify the authentication token parameters carried in the target reference authentication data according to the 3GPP standard rules, generate an initial authentication response based on the verification result, and feed it back to the relay equipment.

[0040] In one embodiment, receiving an initial authentication response from a user equipment based on target reference authentication data, generating a target authentication response according to the response parameters corresponding to the initial authentication response, and sending it to the core network includes:

[0041] The response parameters and random numbers are used to calculate intermediate response parameters using a hash function.

[0042] The verification parameters are calculated using a hash function based on intermediate parameters and random numbers.

[0043] The verification parameters are compared with the target verification parameters corresponding to the intermediate authentication data, and the target authentication response is generated based on the response parameters and the comparison results.

[0044] Send the target authentication response to the core network.

[0045] Thirdly, this application also provides a network authentication device applied to a core network, the core network including a first network device and a second network device, comprising:

[0046] The verification module is used by the first network device to respond to the target registration request sent by the relay device, generate an authentication request based on the user equipment identifier and the relay device identifier carried in the target registration request, and send it to the second network device; the second network device obtains the corresponding subscription information according to the user equipment identifier in the received authentication request, determines the corresponding authentication protocol according to the subscription information, generates an authentication parameter response according to the authentication protocol, and sends it to the first network device.

[0047] The response module is used by the first network device to determine the target authentication parameters from the authentication parameter response, generate intermediate authentication data based on the target authentication parameters, and send it to the relay device. This enables the relay device to select target reference data from the intermediate authentication data, generate corresponding target reference authentication data, and generate a target authentication response based on the initial authentication response fed back by the user equipment based on the target reference authentication data, according to the response parameters corresponding to the initial authentication response, and send it to the core network. The module also receives the target authentication response fed back by the relay device, performs authentication between the user equipment and the relay device according to the response parameters corresponding to the target authentication response, and sends the authentication result to the relay device.

[0048] Fourthly, this application also provides a network authentication device for use in relay equipment, comprising:

[0049] The transceiver module is used to receive an initial registration request sent by a user equipment, which includes the user equipment identifier of the user equipment; generate a target registration request based on the initial registration request, which includes the user equipment identifier and the relay device identifier of the relay device; and send the target registration request to the core network so that the core network can determine the target authentication protocol based on the subscription information corresponding to the user equipment identifier, and generate corresponding authentication intermediate data according to the target authentication protocol through the user equipment identifier and the relay device identifier.

[0050] The verification module is used to receive intermediate authentication data fed back from the core network, generate corresponding target reference authentication data based on target reference data selected from the intermediate authentication data, and send the target reference authentication data to the user equipment; receive the initial authentication response fed back by the user equipment based on the target reference authentication data, generate a target authentication response according to the response parameters corresponding to the initial authentication response, and send it to the core network, so that the core network generates corresponding response parameters according to the target authentication response, authenticates the user equipment and the relay equipment based on the response parameters and the target parameters in the intermediate authentication data, and feeds back the authentication result to the relay equipment;

[0051] The authentication module is used to send the authentication results fed back by the core network to the user equipment, thereby completing network authentication between the user equipment and the relay equipment, as well as between the user equipment and the core network.

[0052] Fifthly, this application also provides a communication device. The communication device includes a memory and a processor, the memory storing a computer program, and the processor executing the computer program to perform the following steps:

[0053] In response to receiving the target registration request sent by the relay device, the first network device generates an authentication request based on the user equipment identifier and the relay device identifier carried in the target registration request, and sends it to the second network device.

[0054] The second network device obtains the corresponding subscription information based on the user equipment identifier in the received authentication request, determines the corresponding authentication protocol based on the subscription information, generates an authentication parameter response based on the authentication protocol, and sends it to the first network device.

[0055] The first network device determines the target authentication parameters from the authentication parameter response, generates intermediate authentication data based on the target authentication parameters, and sends it to the relay device so that the relay device selects target reference data from the intermediate authentication data, generates corresponding target reference authentication data, and generates the target authentication response based on the initial authentication response fed back by the user equipment based on the target reference authentication data, and generates the target authentication response according to the response parameters corresponding to the initial authentication response, and sends it to the core network.

[0056] Receive the target authentication response from the relay device, authenticate the user equipment and the relay device according to the response parameters corresponding to the target authentication response, and send the authentication result to the relay device.

[0057] Sixthly, this application also provides a communication device. The communication device includes a memory and a processor, the memory storing a computer program, and the processor executing the computer program to perform the following steps:

[0058] Receive an initial registration request sent by a user equipment, the initial registration request including the user equipment identifier of the user equipment;

[0059] A target registration request is generated based on the initial registration request. The target registration request includes the user equipment identifier and the relay device identifier of the relay device.

[0060] The target registration request is sent to the core network, so that the core network determines the target authentication protocol based on the subscription information corresponding to the user equipment identifier, and generates corresponding authentication intermediate data according to the target authentication protocol through the user equipment identifier and the relay device identifier;

[0061] Receive intermediate authentication data from the core network, generate corresponding target reference authentication data based on the target reference data selected from the intermediate authentication data, and send the target reference authentication data to the user equipment.

[0062] The system receives the initial authentication response from the user equipment based on the target reference authentication data, generates the target authentication response according to the response parameters corresponding to the initial authentication response, and sends it to the core network. This enables the core network to generate the corresponding response parameters based on the target authentication response, authenticate the user equipment and the relay equipment based on the response parameters and the target parameters in the authentication intermediate data, and feeds back the authentication results to the relay equipment.

[0063] The authentication results fed back by the core network are sent to the user equipment to complete the network authentication between the user equipment and the relay equipment, as well as between the user equipment and the core network.

[0064] Seventhly, this application also provides a computer-readable storage medium. The computer-readable storage medium stores a computer program thereon, which, when executed by a processor, performs the following steps:

[0065] In response to receiving the target registration request sent by the relay device, the first network device generates an authentication request based on the user equipment identifier and the relay device identifier carried in the target registration request, and sends it to the second network device.

[0066] The second network device obtains the corresponding subscription information based on the user equipment identifier in the received authentication request, determines the corresponding authentication protocol based on the subscription information, generates an authentication parameter response based on the authentication protocol, and sends it to the first network device.

[0067] The first network device determines the target authentication parameters from the authentication parameter response, generates intermediate authentication data based on the target authentication parameters, and sends it to the relay device so that the relay device selects target reference data from the intermediate authentication data, generates corresponding target reference authentication data, and generates the target authentication response based on the initial authentication response fed back by the user equipment based on the target reference authentication data, and generates the target authentication response according to the response parameters corresponding to the initial authentication response, and sends it to the core network.

[0068] Receive the target authentication response from the relay device, authenticate the user equipment and the relay device according to the response parameters corresponding to the target authentication response, and send the authentication result to the relay device.

[0069] Eighthly, this application also provides a computer-readable storage medium. The computer-readable storage medium stores a computer program thereon, which, when executed by a processor, performs the following steps:

[0070] Receive an initial registration request sent by a user equipment, the initial registration request including the user equipment identifier of the user equipment;

[0071] A target registration request is generated based on the initial registration request. The target registration request includes the user equipment identifier and the relay device identifier of the relay device.

[0072] The target registration request is sent to the core network, so that the core network determines the target authentication protocol based on the subscription information corresponding to the user equipment identifier, and generates corresponding authentication intermediate data according to the target authentication protocol through the user equipment identifier and the relay device identifier;

[0073] Receive intermediate authentication data from the core network, generate corresponding target reference authentication data based on the target reference data selected from the intermediate authentication data, and send the target reference authentication data to the user equipment.

[0074] The system receives the initial authentication response from the user equipment based on the target reference authentication data, generates the target authentication response according to the response parameters corresponding to the initial authentication response, and sends it to the core network. This enables the core network to generate the corresponding response parameters based on the target authentication response, authenticate the user equipment and the relay equipment based on the response parameters and the target parameters in the authentication intermediate data, and feeds back the authentication results to the relay equipment.

[0075] The authentication results fed back by the core network are sent to the user equipment to complete the network authentication between the user equipment and the relay equipment, as well as between the user equipment and the core network.

[0076] The aforementioned network authentication method, apparatus, communication equipment, and computer-readable storage medium, in response to a target registration request sent by a relay device, a first network device generates an authentication request based on the user equipment identifier and relay device identifier carried in the target registration request and sends it to a second network device. The second network device obtains the corresponding subscription information based on the user equipment identifier in the received authentication request, determines the corresponding authentication protocol based on the subscription information, generates an authentication parameter response based on the authentication protocol, and sends it to the first network device. The first network device determines the target authentication parameters from the authentication parameter response, generates authentication intermediate data based on the target authentication parameters, and sends it to the relay device. This allows the relay device to select target reference data from the authentication intermediate data, generate corresponding target reference authentication data, and, based on the initial authentication response received from the user equipment based on the target reference authentication data, generate a target authentication response based on the response parameters corresponding to the initial authentication response and send it to the core network. The core network device receives the target authentication response from the relay device, authenticates the user equipment and the relay device based on the response parameters corresponding to the target authentication response, and sends the authentication result to the relay device. This enables authentication between user equipment and relay equipment, as well as authentication between relay equipment and the network, to be completed in the same authentication process. Compared with existing technologies that use additional mechanisms different from cellular network access authentication and authenticate the process independently, the network verification method of this application can effectively reduce system complexity and improve network authentication efficiency. Attached Figure Description

[0077] Figure 1 This is a diagram illustrating the application environment of the core network participating in the network authentication method in one embodiment.

[0078] Figure 2 This is a flowchart illustrating a network authentication method in one embodiment;

[0079] Figure 3 This is a flowchart illustrating the step of generating the second authentication vector in one embodiment;

[0080] Figure 4 This is a flowchart illustrating a method for generating a first authentication vector in one embodiment;

[0081] Figure 5 This is a flowchart illustrating the step of generating the second authentication vector in one embodiment;

[0082] Figure 6 This is a flowchart illustrating the step of rejecting a target registration request in one embodiment;

[0083] Figure 7 This is a schematic diagram illustrating the process of a relay device participating in network authentication in one embodiment;

[0084] Figure 8 This is a schematic diagram of the process of generating target reference authentication data and feeding it back to the relay device in one embodiment;

[0085] Figure 9 This is a schematic diagram illustrating the process of generating a target authentication response and feeding it back to the core network in one embodiment;

[0086] Figure 10 This is a system architecture diagram of a network authentication method in one embodiment;

[0087] Figure 11 This is a flowchart illustrating a network authentication method in one embodiment;

[0088] Figure 12 This is a structural block diagram of a network authentication device in one embodiment;

[0089] Figure 13 This is a structural block diagram of a network authentication device in one embodiment;

[0090] Figure 14 This is an internal structure diagram of a communication device in one embodiment;

[0091] Figure 15 This is an internal structural diagram of a communication device in one embodiment. Detailed Implementation

[0092] To make the objectives, technical solutions, and advantages of this application clearer, the following detailed description is provided in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative and not intended to limit the scope of this application.

[0093] The network slice switching method provided in this application embodiment can be applied to, for example, Figure 1In the application environment shown, user equipment 102 communicates with relay equipment 104 through the network, and core network 106 communicates with relay equipment 104 through the network. Core network 106 includes a first network device and a second network device. The first network device, in response to receiving a target registration request from a relay device, generates an authentication request based on the user equipment identifier and relay device identifier carried in the target registration request and sends it to the second network device. The second network device obtains the corresponding subscription information based on the user equipment identifier in the received authentication request, determines the corresponding authentication protocol based on the subscription information, generates an authentication parameter response based on the authentication protocol, and sends it to the first network device. The first network device determines the target authentication parameters from the authentication parameter response, generates authentication intermediate data based on the target authentication parameters, and sends it to relay device 104, so that relay device 104 selects target reference data from the authentication intermediate data, generates corresponding target reference authentication data, and generates a target authentication response based on the initial authentication response fed back by user equipment 102 based on the target reference authentication data, according to the response parameters corresponding to the initial authentication response, and sends it to core network 106. The first network device receives the target authentication response fed back by relay device 104, authenticates user equipment 102 and relay device 104 according to the response parameters corresponding to the target authentication response, and sends the authentication result to relay device 104.

[0094] In one embodiment, such as Figure 2 As shown, a network slice switching method is provided, which is applied to... Figure 1 Taking the core network 106 as an example, the explanation includes the following steps:

[0095] In step S202, the first network device responds to receiving the target registration request sent by the relay device, generates an authentication request based on the user equipment identifier and the relay device identifier carried in the target registration request, and sends it to the second network device.

[0096] The target registration request includes a user equipment identifier and a relay device identifier. The target registration request is generated by the relay device based on the initial registration request sent by the user equipment. The initial registration request carries the user equipment identifier. The first network device can be a device in the core network responsible for the security anchor function. It can be a single device or a combination of multiple devices that jointly perform a specific function. The second network device includes a first functional device and a second functional device. The first functional device can be a device that undertakes the authentication service function, and the second functional device can be a device that undertakes the unified data management function.

[0097] Specifically, the first network device receives the target registration request sent by the relay device, and then generates an authentication request based on the user equipment identifier and relay device identifier carried in the target registration request, so that the authentication request carries the user equipment identifier and relay device identifier. Optionally, when generating the authentication request, the authentication request may also carry the service network name, and may also carry relay device location parameters, which may be the latitude and longitude parameters of the current relay device.

[0098] Optionally, when the first network device receives a target registration request, it verifies the permissions of the relay device identifier in the target registration request. If the device lacks the necessary permissions, it rejects the target registration request. The permission verification method includes the first network device querying the second functional device in the second network device to obtain the subscription information corresponding to the current relay device, and then determining whether the relay device has the permission to provide relay services based on the subscription information.

[0099] In step S204, the second network device obtains the corresponding subscription information based on the user equipment identifier in the received authentication request, determines the corresponding authentication protocol based on the subscription information, generates an authentication parameter response based on the authentication protocol, and sends it to the first network device.

[0100] Specifically, after receiving the authentication request, the first functional device in the second network device obtains the corresponding subscription information from the second functional device according to the user equipment identifier carried in the authentication request, determines the corresponding authentication protocol, generates a first authentication vector according to the authentication protocol, and sends the first authentication vector to the first functional device. The first functional device then generates a corresponding second authentication vector based on the first authentication vector, generates an authentication parameter response, so that the authentication parameter response carries the second authentication vector, and sends the first network device to the first network device.

[0101] In step S206, the first network device determines the target authentication parameters from the authentication parameter response, generates intermediate authentication data based on the target authentication parameters, and sends it to the relay device, so that the relay device selects target reference data from the intermediate authentication data, generates corresponding target reference authentication data, and generates a target authentication response based on the initial authentication response fed back by the user equipment based on the target reference authentication data, according to the response parameters corresponding to the initial authentication response, and sends it to the core network.

[0102] Specifically, the first network device receives the authentication parameter response sent back by the second network device, determines the target authentication parameter from the authentication parameter response, and then fuses the target authentication parameter with a random number to generate authentication intermediate data. This authentication intermediate data is then sent to the relay device. The fusion method can be any combination of operations such as addition, subtraction, multiplication, division, and square root extraction, so that the relay device can select target reference data from the authentication intermediate data, generate corresponding target reference authentication data, and, based on the initial authentication response fed back by the user equipment based on the target reference authentication data, generate a target authentication response according to the response parameters corresponding to the initial authentication response, and send it to the core network.

[0103] Step S208: Receive the target authentication response from the relay device, authenticate the user equipment and the relay device according to the response parameters corresponding to the target authentication response, and send the authentication result to the relay device.

[0104] Specifically, the relay device receives the initial authentication response sent by the user equipment, calculates the verification parameters based on the corresponding response parameters in the initial authentication response, and then compares the verification parameters with the corresponding standard parameters. If the two are consistent, the relay device generates the corresponding target authentication response and sends it to the core network.

[0105] Optionally, when calculating the verification parameters, the relay device can use a hash function to calculate the corresponding initial verification parameters by combining the response parameters and the random number, and then use the hash function to calculate the corresponding verification parameters by combining the initial verification parameters and the random number.

[0106] In this embodiment, the first network device responds to the target registration request sent by the relay device, generates an authentication request based on the user equipment identifier and relay device identifier carried in the target registration request, and sends it to the second network device. The second network device obtains the corresponding subscription information based on the user equipment identifier in the received authentication request, determines the corresponding authentication protocol based on the subscription information, generates an authentication parameter response based on the authentication protocol, and sends it to the first network device. The first network device determines the target authentication parameters from the authentication parameter response, generates authentication intermediate data based on the target authentication parameters, and sends it to the relay device, so that the relay device selects target reference data from the authentication intermediate data, generates corresponding target reference authentication data, and generates a target authentication response based on the initial authentication response fed back by the user equipment based on the target reference authentication data, according to the response parameters corresponding to the initial authentication response, and sends it to the core network. The core network receives the target authentication response fed back by the relay device, authenticates the user equipment and the relay device according to the response parameters corresponding to the target authentication response, and sends the authentication result to the relay device. This enables authentication between user equipment and relay equipment, as well as authentication between relay equipment and the network, to be completed in the same authentication process. Compared with existing technologies that use additional mechanisms different from cellular network access authentication and authenticate the process independently, the network verification method of this application can effectively reduce system complexity and improve network authentication efficiency.

[0107] In one embodiment, such as Figure 3 As shown, the second network device obtains the corresponding subscription information based on the user equipment identifier in the received authentication request, determines the corresponding authentication protocol based on the subscription information, generates an authentication parameter response according to the authentication protocol, and sends it to the first network device, including:

[0108] The second network device includes a first functional device and a second functional device. The first functional device may be a device in the core network that undertakes authentication service functions, and the second functional device may be a device in the core network that undertakes unified data management functions. The user equipment identifier is used to identify the identity of the corresponding user equipment in the network, and may be the user equipment's IP address, etc.

[0109] In step S302, the first functional device receives the authentication request and forwards the authentication request to the second functional device.

[0110] In step S304, the second functional device obtains the corresponding subscription information based on the user equipment identifier in the authentication request, determines the corresponding authentication protocol based on the subscription information, and generates a first authentication vector based on the authentication protocol using a preset algorithm.

[0111] Specifically, after receiving the authentication request, the second functional device searches for the pre-stored subscription information in the local database based on the user equipment identifier in the authentication request, determines the authentication protocol corresponding to the user equipment identifier based on the subscription information, and then generates the first authentication vector according to the category of the authentication protocol using the corresponding method / preset algorithm.

[0112] Optionally, the second functional device uses the Milenage algorithm set, as defined by the 3GPP standard, to generate the vector AV (RAND, AUTN, XRES, CK, IK), and then uses parameters CK, IK, and the serving network name SNN to generate the parameter K. AUSF And using parameters such as XRES, RAND, SNN, CK, and IK, the parameter XRES* is generated, and the first authentication vector HEAV(RAND, AUTN, XRES*, K) is generated. AUSF ).

[0113] In step S306, the second functional device sends the first authentication vector to the first functional device.

[0114] Specifically, the second functional device generates an intermediate authentication parameter response based on the first authentication vector, so that the intermediate authentication parameter response carries the first authentication vector, and then sends the intermediate authentication parameter response to the first functional device.

[0115] In step S308, the first functional device determines the expected response parameters from the first authentication vector, and obtains the hash value of the expected response by fusing the expected response parameters with a random number, and constructs the second authentication vector based on the hash value.

[0116] Specifically, after receiving the first authentication vector in the above steps, the first functional device determines the expected response parameters in the first authentication vector, and merges the preset response parameters with a random number to obtain the hash value of the expected response, and then constructs the second authentication vector based on the hash value.

[0117] Step S310: Generate an authentication parameter response based on the second authentication vector and send it to the first network device.

[0118] Specifically, the first functional device generates an authentication parameter response based on the second authentication vector, so that the authentication parameter response carries the second authentication vector.

[0119] In this embodiment, the first functional device receives an authentication request and forwards it to the second functional device. The second functional device obtains the corresponding subscription information based on the user equipment identifier in the authentication request, determines the corresponding authentication protocol based on the subscription information, generates a first authentication vector according to the authentication protocol using a preset algorithm, and sends the first authentication vector to the first functional device. The first functional device determines the expected response parameters from the first authentication vector, obtains the hash value of the expected response by fusing the expected response parameters with a random number, constructs a second authentication vector based on the hash value, generates an authentication parameter response based on the second authentication vector, and sends it to the first network device. Thus, through the process of mutual authentication and interaction of parameters between the first and second functional devices in the second network device, the parameter verification process of network authentication is realized, effectively improving the accuracy of verification during the network authentication process.

[0120] In one embodiment, such as Figure 4 As shown, the second functional device obtains the corresponding subscription information based on the user equipment identifier in the authentication request, determines the corresponding authentication protocol based on the subscription information, and generates a first authentication vector according to the authentication protocol using a preset algorithm, including:

[0121] The authentication request includes the device location parameters corresponding to the relay device and the network identifier of the location corresponding to the relay device.

[0122] Step S402: Obtain network location parameters based on logical operations of device location parameters and local network identifier.

[0123] Specifically, the second functional device performs an OR operation between the device location parameters corresponding to the relay device and the local network identifier to obtain the network location parameters.

[0124] Step S404: Based on the network location parameters, construct the first authentication vector.

[0125] Specifically, the second functional device generates a first authentication vector based on the network location parameters in the aforementioned steps, so that the first authentication vector carries the network location parameters.

[0126] In this embodiment, network location parameters are obtained by logical operations based on device location parameters and the local network identifier. Based on the network location parameters, a first authentication vector is constructed, thereby achieving accurate determination of the network location parameters, and thus improving the accuracy of the location dimension of the first authentication vector and enhancing the reliability of the first authentication vector.

[0127] In one embodiment, such as Figure 5As shown, the first functional device determines the expected response parameters from the first authentication vector, and obtains the hash value of the expected response by fusing the expected response parameters with a random number. Based on the hash value, it constructs a second authentication vector, including:

[0128] The authentication request includes the device location parameters corresponding to the relay device and the network identifier of the location corresponding to the relay device.

[0129] Step S502: Obtain network location parameters based on logical operations of device location parameters and local network identifier.

[0130] Specifically, the first functional device performs an OR operation between the device location parameters corresponding to the relay device and the local network identifier to obtain the network location parameters.

[0131] Step S504: Based on the hash value and network location parameters, a second authentication vector is constructed.

[0132] Specifically, the first functional device determines the expected response parameters from the first authentication vector, and obtains the hash value of the expected response by fusing the expected response parameters with a random number. Then, based on the combination of the hash value and the network location parameters, it obtains the second authentication vector.

[0133] In this embodiment, network location parameters are obtained by logical operations based on device location parameters and the local network identifier. A second authentication vector is constructed based on the hash value and the network location parameters, thereby achieving accurate determination of the network location parameters and improving the accuracy of the location dimension of the second authentication vector, thus enhancing the reliability of the second authentication vector.

[0134] In one embodiment, such as Figure 6 As shown, the above network authentication method also includes:

[0135] In step S602, the first network device sends a query instruction to the second network device, so that the second network device queries the subscription information corresponding to the relay device identifier in the target registration request according to the query instruction.

[0136] The query command corresponds to the relay device identifier currently being processed by the first network device, and is used to query the relay service permission status of the corresponding relay device.

[0137] Specifically, the first network device sends a query command to the second functional device of the second network device, so that the second functional device queries the subscription information corresponding to the relay device identifier in the target registration request according to the query command.

[0138] Step S604: Determine the relay service permissions of the relay device based on the query results.

[0139] In step S606, if the relay service permission is insufficient, the target registration request is rejected.

[0140] Specifically, when it is found that the corresponding relay device does not have the permission to provide relay services, the request result is rejected when the request is sent to the relay device.

[0141] In this embodiment, the first network device sends a query command to the second network device, so that the second network device queries the subscription information corresponding to the relay device identifier in the target registration request according to the query command. Based on the query result, the relay service permission of the relay device is determined. When the relay service permission is not granted, the target registration request is rejected, which effectively prevents the relay device without permission from performing network authentication and improves network security.

[0142] In one embodiment, such as Figure 7 As shown, a network slice switching method is provided, which is applied to... Figure 1 Taking relay device 104 as an example, the explanation includes the following steps:

[0143] Step S702: Receive the initial registration request sent by the user equipment.

[0144] The initial registration request includes the user equipment identifier of the user equipment, which can be various user terminals such as mobile phones, computers, wearable devices, etc.

[0145] Step S704: Generate a target registration request based on the initial registration request.

[0146] The target registration request includes the user equipment identifier and the relay device identifier of the relay device.

[0147] Step S706: Send the target registration request to the core network so that the core network can determine the target authentication protocol based on the subscription information corresponding to the user equipment identifier, and generate corresponding authentication intermediate data according to the target authentication protocol through the user equipment identifier and the relay device identifier.

[0148] The target registration request may include user equipment identifier, relay device identifier, relay device location parameters, and service network name.

[0149] Specifically, the relay device sends the target registration request to the core network. After receiving the target registration request, the first network device in the core network identifies the user equipment identifier in the target registration request. If it is a specific relay service representation allocated to the user equipment, it converts it into the remote user equipment identifier (such as SUPI) corresponding to the user equipment.

[0150] Step S708: Receive intermediate authentication data fed back from the core network, generate corresponding target reference authentication data based on the target reference data selected from the intermediate authentication data, and send the target reference authentication data to the user equipment.

[0151] Specifically, after receiving the authentication intermediate data, the relay device determines the target reference data in the authentication intermediate data according to the method defined by 3GPP, and generates corresponding target reference authentication data based on the target reference data, so that the target reference authentication data carries the target reference data, and sends the target reference authentication data to the user equipment.

[0152] Step S710: Receive the initial authentication response from the user equipment based on the target reference authentication data, generate a target authentication response according to the response parameters corresponding to the initial authentication response, and send it to the core network. This enables the core network to generate corresponding response parameters based on the target authentication response, authenticate the user equipment and the relay equipment based on the response parameters and the target parameters in the authentication intermediate data, and send the authentication result back to the relay equipment.

[0153] Specifically, the user equipment verifies the target reference data in the target reference authentication data received in the aforementioned steps according to the method defined by 3GPP, calculates the corresponding response parameters based on the target reference data, generates the corresponding initial authentication response, so that the initial authentication response carries the response parameters, and then sends the initial authentication response to the relay device. After receiving the initial authentication response, the relay device generates a target authentication response based on the response parameters corresponding to the initial authentication response and sends it to the core network, so that the core network generates the corresponding response parameters based on the target authentication response, authenticates the user equipment and the relay device based on the response parameters and the target parameters in the authentication intermediate data, and feeds back the authentication result to the relay device.

[0154] Step S712: Send the authentication result fed back by the core network to the user equipment to complete the network authentication between the user equipment and the relay equipment, as well as between the user equipment and the core network.

[0155] In this embodiment, by having a relay device participate in the two-way authentication between the remote user equipment and the core network, the authentication between the user equipment and the relay device and the network can be completed in the same authentication process. Compared with the existing technology that uses an additional mechanism different from cellular network access authentication and authenticates the process separately, the network verification method of this application can effectively reduce system complexity and improve network authentication efficiency.

[0156] In one embodiment, such as Figure 8As shown, the system receives intermediate authentication data from the core network, generates corresponding target reference authentication data based on target reference data selected from the intermediate authentication data, and sends the target reference authentication data to the user equipment, including:

[0157] The target reference data includes random parameters and authentication token parameters.

[0158] Step S802: Generate corresponding target reference authentication data based on random parameters and authentication token parameters.

[0159] Specifically, the relay device generates target reference authentication data from the target reference data in the authentication intermediate data received from the core network, so that the target reference data carries the random parameters and authentication token parameters in the target reference data.

[0160] Step S804: Send the target reference authentication data to the user equipment so that the user equipment can verify the authentication token parameters carried in the target reference authentication data according to the 3GPP standard rules, generate an initial authentication response based on the verification result, and feed it back to the relay device.

[0161] In this embodiment, target reference authentication data is generated based on random parameters and authentication token parameters. The target reference authentication data is then sent to the user equipment, so that the user equipment verifies the authentication token parameters carried in the target reference authentication data according to the 3GPP standard rules, generates an initial authentication response based on the verification result, and feeds it back to the relay device. This achieves effective verification of the authentication intermediate data fed back by the core network and improves the accuracy of network authentication.

[0162] In one embodiment, such as Figure 9 As shown, the process includes receiving the initial authentication response from the user equipment based on the target reference authentication data, generating a target authentication response according to the response parameters corresponding to the initial authentication response, and sending it to the core network.

[0163] Step S902: Calculate the intermediate response parameters by combining the response parameters and the random number using a hash function.

[0164] Step S904: Calculate the verification parameters using a hash function based on the intermediate parameters and the random number.

[0165] Step S906: Compare the verification parameters with the target verification parameters corresponding to the authentication intermediate data, and generate the target authentication response based on the response parameters and the comparison results.

[0166] Specifically, the relay device compares the verification parameters with the target verification parameters corresponding to the intermediate authentication data. If they match, the current authentication step is considered to have passed. Then, based on the response parameters and the comparison results, a target authentication response is generated so that the target authentication response carries the response parameters.

[0167] Step S908: Send the target authentication response to the core network.

[0168] In this embodiment, response parameters and random numbers are used to calculate intermediate response parameters using a hash function. Verification parameters are then calculated using the hash function based on the intermediate parameters and random numbers. The verification parameters are compared with the target verification parameters corresponding to the authentication intermediate data. Based on the response parameters and the comparison results, a target authentication response is generated and sent to the core network. This enables the user equipment to re-verify network authentication, thereby improving the efficiency of network authentication.

[0169] This application also provides an application scenario in which the above-described network authentication method is applied. This method is used in scenarios where a remote UE (User Equipment) accesses the network authentication process through a relay UE. Specifically, as follows... Figure 10 As shown, the application of this network authentication method in this scenario is as follows:

[0170] In this embodiment, the flowchart of the network authentication process for a remote UE accessing the network through a relay UE is shown below. Figure 11 As shown, the specific steps are as follows:

[0171] 1. The remote UE and the relay UE first establish a U2U connection. The remote UE initiates a registration request to the relay UE, and the message carries the network identifier of the remote UE. The connection method can be based on WiFi Direct or Sidelink, etc. The network identifier of the remote UE can be SUCI or SUPI in 5G, and other corresponding user identifiers in 6G networks. The network identifier of the remote UE can also be a specific identifier assigned to the relay UE.

[0172] 2. The relay UE forwards the registration request message of the remote UE to the core network. This message is forwarded to the security anchor function to request authentication of the remote UE. The registration request message carries the remote UE identifier and the relay UE identifier. The registration message carries specific fields. In one implementation, the registration message may optionally carry the relay UE location parameters. In another implementation, the relay UE location parameters may be the latitude and longitude parameters of the current relay UE.

[0173] 3. The security anchor function determines that the remote UE needs to be authenticated and sends an authentication request message to the authentication service function; the security anchor function needs to verify whether the relay UE has the authority to provide relay services. If it does not have the authority, the registration request is rejected.

[0174] Optionally, the security anchor function queries the unified data management function to obtain the subscription information of the relay UE, and obtains whether the relay UE has the authority to provide relay services based on the subscription information; wherein, the message carries the service network name SNN; the message carries the relay UE location parameters, and if the remote UE identifier received by the security anchor function is a specific relay service service identifier assigned to the UE, it needs to be converted into the remote UE network identifier (such as SUPI) corresponding to the UE.

[0175] 4. The authentication service function sends an authentication parameter request message to the unified data management function; the message carries the remote UE identifier, the service network name (SNN), and the relay UE location parameters.

[0176] 5. Upon receiving the request message, the unified data management function determines the corresponding authentication protocol based on the signed agreement, generates an authentication vector, and sends an authentication parameter response message to the authentication service function, carrying the generated authentication vector. Specifically, the unified data management function uses the 3GPP standard definition method and the Milenage algorithm set to generate vectors AV (RAND, AUTN, XRES, CK, IK), generating CK' and IK', and then uses CK, IK, SNN, etc., to generate K. AUSF XRES* is generated using XRES, RAND, SNN, CK, IK, etc., and the authentication vector HE AV(RAND, AUTN, XRES*, K) is used. AUSF Send to the authentication service function;

[0177] Wherein, RAND: random number, AUTN: authentication token, XRES: expected response, CK: cipher key, IK: integrity key, SNN: serving network name, Kausf: AUSF key, and Authentication Server Function.

[0178] Among them, in generating K AUSF When using XRES*, add the relay UE location parameter to the input parameters, and change the K parameter in the original 3GPP standard. AUSFReplace SNN in the generator function with "SNN||relay UE location parameters";

[0179] 6. After receiving the information, the authentication service function saves the XRES* parameter and calculates HXRES* using the XRES* and RAND parameters, and then uses K... AUSF and SNN generate K SEAF The parameters are then used to send the authentication vector SEAV(RAND, AUTN, HXRES*) to the security anchor function via an authentication response message.

[0180] Note: In one implementation, when generating K... SEAF At that time, the relay UE location parameter is added to the input parameters, and the K in the original 3GPP standard is changed. SEAF Replace SNN in the generator function with "SNN||relay UE location parameters";

[0181] 7. After receiving the message, the security anchor function saves the HXRES* parameter, calculates RXRES* using the HXRES* and RAND parameters, and then sends an authentication request message to the relay UE, carrying the authentication vector RE AV(RAND, AUTN, RXRES*).

[0182] 8. Upon receiving the message, the relay UE sends an authentication request message to the remote UE, which carries parameters such as RAND and AUTN.

[0183] 9. After receiving the authentication request message, the remote UE verifies the AUTN according to the method defined by 3GPP, completes the network authentication, and calculates and obtains CK, IK, and RES, as well as RES* and K. AUSF and K SEAF It also sends an authentication response message to the relay UE, which carries RES*.

[0184] 10. After receiving the response message, the relay UE calculates RRES* and compares it with RXRES*. If the two are consistent, the relay UE considers the authentication successful and sends an authentication response message to the security anchor function, carrying RES* in the message.

[0185] 11. After receiving the authentication response message, the security anchor function calculates HRES* using RES* and RAND, and compares it with HXRES*. If the two are consistent, the security anchor function considers the authentication successful and sends an authentication request message to the authentication service function, carrying RES* in the message.

[0186] 12. After receiving the message, the authentication service compares RES* with XRES*. If they match, the authentication service considers the authentication successful and sends an authentication response message to the security anchor function. This message contains K. SEAF ;

[0187] 13. After receiving the message, the security anchor point function sends an authentication success message to the relevant core network elements. After the relevant core network elements complete the relevant registration process, they send a registration response message to the relay UE, indicating that the registration and authentication were successful.

[0188] 14. After receiving the message, the relay UE sends a registration response message to the remote UE and assists the remote UE in completing subsequent user plane connection establishment and other business processes, thereby completing network authentication between the remote UE and the relay UE and between the remote UE and the core network.

[0189] In this embodiment, by having a relay UE participate in the bidirectional authentication between the remote UE and the core network, the authentication between the remote UE and the relay UE and the network can be completed in the same authentication process. Compared with the existing technology that uses additional mechanisms different from cellular network access authentication and authenticates the process separately, the network verification method of this application can effectively reduce system complexity and improve network authentication efficiency.

[0190] It should be understood that although the steps in the flowcharts of the embodiments described above are shown sequentially according to the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless explicitly stated herein, there is no strict order restriction on the execution of these steps, and they can be executed in other orders. Moreover, at least some steps in the flowcharts of the embodiments described above may include multiple steps or multiple stages. These steps or stages are not necessarily completed at the same time, but can be executed at different times. The execution order of these steps or stages is not necessarily sequential, but can be performed alternately or in turn with other steps or at least some of the steps or stages of other steps.

[0191] In one embodiment, such as Figure 12 As shown, a network authentication device is provided, applied to a core network. The core network includes a first network device and a second network device. The device can be a software module or a hardware module, or a combination of both, integrated into a communication device. Specifically, the device includes: a verification module 1202 and a response module 1204, wherein:

[0192] The verification module 1202 is used for the first network device to respond to the target registration request sent by the relay device, generate an authentication request based on the user equipment identifier and the relay device identifier carried in the target registration request, and send it to the second network device; the second network device obtains the corresponding subscription information according to the user equipment identifier in the received authentication request, determines the corresponding authentication protocol according to the subscription information, generates an authentication parameter response according to the authentication protocol, and sends it to the first network device.

[0193] The response module 1204 is used by the first network device to determine the target authentication parameters from the authentication parameter response, generate intermediate authentication data based on the target authentication parameters, and send it to the relay device. This enables the relay device to select target reference data from the intermediate authentication data, generate corresponding target reference authentication data, and generate a target authentication response based on the initial authentication response fed back by the user equipment based on the target reference authentication data, according to the response parameters corresponding to the initial authentication response, and send it to the core network. The module also receives the target authentication response fed back by the relay device, performs authentication between the user equipment and the relay device according to the response parameters corresponding to the target authentication response, and sends the authentication result to the relay device.

[0194] In one embodiment, the verification module 1202 is further configured to include a second network device comprising a first functional device and a second functional device; the first functional device receives an authentication request and forwards the authentication request to the second functional device; the second functional device obtains the corresponding subscription information based on the user equipment identifier in the authentication request, determines the corresponding authentication protocol based on the subscription information, and generates a first authentication vector according to the authentication protocol using a preset algorithm; the second functional device sends the first authentication vector to the first functional device; the first functional device determines the expected response parameters from the first authentication vector, and obtains the hash value of the expected response by fusing the expected response parameters with a random number, and constructs a second authentication vector based on the hash value; an authentication parameter response is generated based on the second authentication vector and sent to the first network device.

[0195] In one embodiment, the verification module 1202 is further configured to authenticate the request including the device location parameters corresponding to the relay device and the local network identifier corresponding to the relay device; obtain the network location parameters based on the logical operation of the device location parameters and the local network identifier; and construct the first authentication vector based on the network location parameters.

[0196] In one embodiment, the verification module 1202 is further configured to authenticate the request including the device location parameters corresponding to the relay device and the local network identifier corresponding to the relay device; obtain the network location parameters based on the logical operation of the device location parameters and the local network identifier; and construct a second authentication vector based on the hash value and the network location parameters.

[0197] In one embodiment, the response module 1204 is further configured to send a query instruction from the first network device to the second network device, so that the second network device queries the subscription information corresponding to the relay device identifier in the target registration request according to the query instruction; determines the relay service permission of the relay device according to the query result; and rejects the target registration request when the relay service permission is no permission.

[0198] The aforementioned network authentication device, in response to a target registration request sent by a relay device, generates an authentication request based on the user equipment identifier and relay device identifier carried in the target registration request and sends it to a second network device. The second network device obtains the corresponding subscription information based on the user equipment identifier in the received authentication request, determines the corresponding authentication protocol based on the subscription information, generates an authentication parameter response based on the authentication protocol, and sends it to the first network device. The first network device determines the target authentication parameters from the authentication parameter response, generates authentication intermediate data based on the target authentication parameters, and sends it to the relay device, enabling the relay device to select target reference data from the authentication intermediate data, generate corresponding target reference authentication data, and, based on the initial authentication response fed back by the user equipment based on the target reference authentication data, generates a target authentication response based on the response parameters corresponding to the initial authentication response and sends it to the core network. The core network device receives the target authentication response fed back by the relay device, authenticates the user equipment and the relay device based on the response parameters corresponding to the target authentication response, and sends the authentication result to the relay device. This enables authentication between user equipment and relay equipment, as well as authentication between relay equipment and the network, to be completed in the same authentication process. Compared with existing technologies that use additional mechanisms different from cellular network access authentication and authenticate the process independently, the network verification method of this application can effectively reduce system complexity and improve network authentication efficiency.

[0199] For specific limitations regarding the network authentication device, please refer to the limitations on the network authentication method above, which will not be repeated here. Each module in the aforementioned network authentication device can be implemented entirely or partially through software, hardware, or a combination thereof. These modules can be embedded in hardware or independently of the processor in the communication device, or stored in software in the memory of the communication device, so that the processor can call and execute the corresponding operations of each module.

[0200] In one embodiment, such as Figure 13 As shown, a network authentication device is provided, applied to a relay device. This device can be a software module, a hardware module, or a combination of both as part of a communication device. Specifically, the device includes: a transceiver module 1302, a verification module 1304, and an authentication module 1306, wherein:

[0201] The transceiver module 1302 is used to receive an initial registration request sent by a user equipment, the initial registration request including the user equipment identifier of the user equipment; generate a target registration request based on the initial registration request, the target registration request including the user equipment identifier and the relay device identifier of the relay device; send the target registration request to the core network, so that the core network determines the target authentication protocol based on the subscription information corresponding to the user equipment identifier, and generates corresponding authentication intermediate data according to the target authentication protocol through the user equipment identifier and the relay device identifier;

[0202] The verification module 1304 is used to receive authentication intermediate data fed back from the core network, generate corresponding target reference authentication data based on target reference data selected from the authentication intermediate data, and send the target reference authentication data to the user equipment; receive the initial authentication response fed back by the user equipment based on the target reference authentication data, generate a target authentication response according to the response parameters corresponding to the initial authentication response, and send it to the core network, so that the core network generates corresponding response parameters according to the target authentication response, authenticates the user equipment and the relay equipment based on the response parameters and the target parameters in the authentication intermediate data, and feeds back the authentication result to the relay equipment;

[0203] The authentication module 1306 is used to send the authentication results fed back by the core network to the user equipment, thereby completing the network authentication between the user equipment and the relay equipment, as well as between the user equipment and the core network.

[0204] In one embodiment, the verification module 1304 is further configured to: include random parameters and authentication token parameters in the target reference data; generate corresponding target reference authentication data based on the random parameters and authentication token parameters; send the target reference authentication data to the user equipment, so that the user equipment verifies the authentication token parameters carried in the target reference authentication data according to the 3GPP standard rules, generates an initial authentication response based on the verification result, and feeds it back to the relay device.

[0205] In one embodiment, the verification module 1304 is further configured to calculate the response intermediate parameters by hashing the response parameters and the random number using a hash function; calculate the verification parameters by hashing the intermediate parameters and the random number using a hash function; compare the verification parameters with the target verification parameters corresponding to the authentication intermediate data; generate the target authentication response based on the response parameters and the comparison result; and send the target authentication response to the core network.

[0206] For specific limitations regarding the network authentication device, please refer to the limitations on the network authentication method above, which will not be repeated here. Each module in the aforementioned network authentication device can be implemented entirely or partially through software, hardware, or a combination thereof. These modules can be embedded in hardware or independently of the processor in the communication device, or stored in software in the memory of the communication device, so that the processor can call and execute the corresponding operations of each module.

[0207] In one embodiment, a communication device is provided, which may be a server, and its internal structure diagram may be as follows: Figure 14As shown, the communication device includes a processor, memory, and a network interface connected via a system bus. The processor provides computing and control capabilities. The memory includes a non-volatile storage medium and internal memory. The non-volatile storage medium stores an operating system, computer programs, and a database. The internal memory provides an environment for the operation of the operating system and computer programs in the non-volatile storage medium. The database stores user equipment subscription information data. The network interface is used for communication with external terminals via a network connection. When executed by the processor, the computer program implements a network authentication method.

[0208] In one embodiment, a communication device is provided, which may be a terminal, and its internal structure diagram may be as follows: Figure 15 As shown, the communication device includes a processor, memory, communication interface, display screen, and input device connected via a system bus. The processor provides computing and control capabilities. The memory includes non-volatile storage media and internal memory. The non-volatile storage media stores the operating system and computer programs. The internal memory provides an environment for the operation of the operating system and computer programs stored in the non-volatile storage media. The communication interface is used for wired or wireless communication with external terminals; wireless communication can be achieved through Wi-Fi, mobile cellular networks, NFC (Near Field Communication), or other technologies. When the computer program is executed by the processor, it implements a network authentication method. The display screen can be an LCD screen or an e-ink screen. The input device can be a touch layer covering the display screen, buttons, a trackball, or a touchpad mounted on the device's casing, or an external keyboard, touchpad, or mouse.

[0209] Those skilled in the art will understand that Figure 14 and Figure 15 The structure shown is merely a block diagram of a portion of the structure related to the present application and does not constitute a limitation on the communication device to which the present application is applied. Specific communication devices may include more or fewer components than those shown in the figure, or combine certain components, or have different component arrangements.

[0210] In one embodiment, a communication device is provided, including a memory and a processor, wherein the memory stores a computer program, and the processor executes the computer program to implement the steps in the above-described method embodiments.

[0211] In one embodiment, a computer-readable storage medium is provided having a computer program stored thereon, which, when executed by a processor, implements the steps in the above method embodiments.

[0212] In one embodiment, a computer program product is provided, including a computer program that, when executed by a processor, implements the steps in the above method embodiments.

[0213] Those skilled in the art will understand that all or part of the processes in the above embodiments can be implemented by a computer program instructing related hardware. The computer program can be stored in a non-volatile computer-readable storage medium, and when executed, it can include the processes of the embodiments described above. Any references to memory, databases, or other media used in the embodiments provided in this application can include at least one of non-volatile and volatile memory. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetic random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory can include random access memory (RAM) or external cache memory, etc. By way of illustration and not limitation, RAM can take many forms, such as Static Random Access Memory (SRAM) or Dynamic Random Access Memory (DRAM). The databases involved in the embodiments provided in this application may include at least one type of relational database and non-relational database. Non-relational databases may include, but are not limited to, blockchain-based distributed databases. The processors involved in the embodiments provided in this application may be general-purpose processors, central processing units, graphics processing units, digital signal processors, programmable logic devices, quantum computing-based data processing logic devices, etc., and are not limited to these.

[0214] The technical features of the above embodiments can be combined in any way. For the sake of brevity, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.

[0215] The embodiments described above are merely illustrative of several implementation methods of this application, and while the descriptions are specific and detailed, they should not be construed as limiting the scope of this patent application. It should be noted that those skilled in the art can make various modifications and improvements without departing from the concept of this application, and these all fall within the protection scope of this application. Therefore, the protection scope of this application should be determined by the appended claims.

Claims

1. A network authentication method, characterized in that, Applied to a core network, the core network including a first network device and a second network device, the method includes: In response to receiving a target registration request sent by a relay device, the first network device generates an authentication request based on the user equipment identifier and relay device identifier carried in the target registration request, and sends it to the second network device. The second network device obtains the corresponding subscription information based on the user equipment identifier in the received authentication request, determines the corresponding authentication protocol based on the subscription information, generates an authentication parameter response based on the authentication protocol, and sends it to the first network device. The first network device determines the target authentication parameters from the authentication parameter response, generates intermediate authentication data based on the target authentication parameters, and sends it to the relay device, so that the relay device selects target reference data from the authentication intermediate data, generates corresponding target reference authentication data, and generates a target authentication response based on the initial authentication response fed back by the user equipment based on the target reference authentication data, according to the response parameters corresponding to the initial authentication response, and sends it to the core network. The system receives the target authentication response from the relay device, authenticates the user equipment with the relay device based on the response parameters corresponding to the target authentication response, and sends the authentication result to the relay device.

2. The method according to claim 1, characterized in that, The second network device obtains the corresponding subscription information based on the user equipment identifier in the received authentication request, determines the corresponding authentication protocol based on the subscription information, generates an authentication parameter response based on the authentication protocol, and sends it to the first network device, including: The second network device includes a first functional device and a second functional device; The first functional device receives the authentication request and forwards the authentication request to the second functional device; The second functional device obtains the corresponding subscription information based on the user equipment identifier in the authentication request, determines the corresponding authentication protocol based on the subscription information, and generates a first authentication vector based on the authentication protocol using a preset algorithm. The second functional device sends the first authentication vector to the first functional device; The first functional device determines the expected response parameters from the first authentication vector, and obtains the hash value of the expected response by fusing the expected response parameters with a random number, and constructs a second authentication vector based on the hash value; An authentication parameter response is generated based on the second authentication vector and sent to the first network device.

3. The method according to claim 2, characterized in that, The second functional device obtains the corresponding subscription information based on the user equipment identifier in the authentication request, determines the corresponding authentication protocol based on the subscription information, and generates a first authentication vector according to the authentication protocol using a preset algorithm, including: The authentication request includes the device location parameters corresponding to the relay device and the local network identifier corresponding to the relay device. The network location parameters are obtained by performing logical operations based on the device location parameters and the local network identifier. Based on the network location parameters, a first authentication vector is constructed.

4. The method according to claim 2, characterized in that, The first functional device determines the expected response parameters from the first authentication vector, and obtains the hash value of the expected response by fusing the expected response parameters with a random number, and constructs a second authentication vector based on the hash value, including: The authentication request includes the device location parameters corresponding to the relay device and the local network identifier corresponding to the relay device. The network location parameters are obtained by performing logical operations based on the device location parameters and the local network identifier. A second authentication vector is constructed based on the hash value and the network location parameters.

5. The method according to claim 1, characterized in that, The method further includes: The first network device sends a query command to the second network device, so that the second network device queries the subscription information corresponding to the relay device identifier in the target registration request according to the query command; Based on the query results, determine the relay service permissions of the relay device; If the relay service permission is insufficient, the target registration request is rejected.

6. A network authentication method, characterized in that, Applied to relay equipment, the method includes: Receive an initial registration request sent by a user equipment, wherein the initial registration request includes the user equipment identifier of the user equipment; A target registration request is generated based on the initial registration request, and the target registration request includes the user equipment identifier and the relay device identifier of the relay device; The target registration request is sent to the core network, so that the core network determines the target authentication protocol based on the subscription information corresponding to the user equipment identifier, and generates corresponding authentication intermediate data according to the target authentication protocol by using the user equipment identifier and the relay device identifier; The system receives intermediate authentication data from the core network, generates corresponding target reference authentication data based on target reference data selected from the intermediate authentication data, and sends the target reference authentication data to the user equipment. The system receives an initial authentication response from a user equipment based on the target reference authentication data, generates a target authentication response according to the response parameters corresponding to the initial authentication response, and sends it to the core network. This enables the core network to generate corresponding response parameters based on the target authentication response, authenticate the user equipment and the relay device based on the response parameters and the target parameters in the authentication intermediate data, and feeds back the authentication result to the relay device. The authentication result fed back by the core network is sent to the user equipment to complete the network authentication between the user equipment and the relay equipment, as well as between the user equipment and the core network.

7. The method according to claim 6, characterized in that, The step of receiving authentication intermediate data fed back from the core network, generating corresponding target reference authentication data based on target reference data selected from the authentication intermediate data, and sending the target reference authentication data to the user equipment includes: The target reference data includes random parameters and authentication token parameters; Generate corresponding target reference authentication data based on the random parameters and the authentication token parameters; The target reference authentication data is sent to the user equipment so that the user equipment verifies the authentication token parameters carried in the target reference authentication data according to the 3GPP standard rules, generates an initial authentication response based on the verification result, and feeds it back to the relay device.

8. The method according to claim 6, characterized in that, The step of receiving the initial authentication response from the user equipment based on the target reference authentication data, generating a target authentication response according to the response parameters corresponding to the initial authentication response, and sending it to the core network includes: The response parameters and random numbers are used to calculate intermediate response parameters using a hash function. The verification parameters are calculated using a hash function based on the intermediate parameters and the random number. The verification parameters are compared with the target verification parameters corresponding to the authentication intermediate data, and a target authentication response is generated based on the response parameters and the comparison results. The target authentication response is sent to the core network.

9. A network authentication device, characterized in that, Applied to a core network, the core network including a first network device and a second network device, the device includes: The verification module is used by the first network device to respond to a target registration request sent by a relay device, generate an authentication request based on the user equipment identifier and relay device identifier carried in the target registration request, and send it to the second network device; the second network device obtains the corresponding subscription information according to the user equipment identifier in the received authentication request, determines the corresponding authentication protocol according to the subscription information, generates an authentication parameter response according to the authentication protocol, and sends it to the first network device. The response module is configured to: First network device determine target authentication parameters from the authentication parameter response, generate intermediate authentication data based on the target authentication parameters, and send it to relay device; Relay device selects target reference data from the intermediate authentication data, generates corresponding target reference authentication data, and generates a target authentication response based on the initial authentication response received from user equipment using the target reference authentication data, according to the response parameters corresponding to the initial authentication response, and sends it to the core network; Receive the target authentication response from relay device, authenticate user equipment and relay device according to the response parameters corresponding to the target authentication response, and send the authentication result to relay device.

10. A network authentication device, characterized in that, Applied to relay equipment, the device includes: The transceiver module is configured to receive an initial registration request sent by a user equipment (UE), the initial registration request including the UE identifier; generate a target registration request based on the initial registration request, the target registration request including the UE identifier and the relay device identifier; and send the target registration request to the core network, so that the core network determines a target authentication protocol based on the subscription information corresponding to the UE identifier, and generates corresponding authentication intermediate data according to the target authentication protocol using the UE identifier and the relay device identifier. The verification module is used to receive authentication intermediate data fed back by the core network, generate corresponding target reference authentication data based on target reference data selected from the authentication intermediate data, and send the target reference authentication data to the user equipment; receive the initial authentication response fed back by the user equipment based on the target reference authentication data, generate a target authentication response according to the response parameters corresponding to the initial authentication response, and send it to the core network, so that the core network generates corresponding response parameters according to the target authentication response, authenticates the user equipment and the relay device based on the response parameters and the target parameters in the authentication intermediate data, and feeds back the authentication result to the relay device; The authentication module is used to send the authentication result fed back by the core network to the user equipment, thereby completing network authentication between the user equipment and the relay equipment, and between the user equipment and the core network.

11. A communication device comprising a memory and a processor, wherein the memory stores a computer program, characterized in that, When the processor executes the computer program, it implements the steps of the method according to any one of claims 1 to 8.

12. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, it implements the steps of the method according to any one of claims 1 to 8.

Citation Information

Patent Citations

  • Equipment access method, equipment and equipment access system

    CN112911583A

  • Authentication method, apparatus and system

    WO2012028010A1