Authentication method and related device
By interacting with the authentication server through the SMF, the system uses the UE's common public user identifier and location information to determine whether an unsigned terminal should perform secondary authentication. This solves the problem that unsigned terminals cannot perform secondary authentication in existing technologies and enables a more flexible authentication process.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- CHINA MOBILE COMM LTD RES INST
- Filing Date
- 2022-03-09
- Publication Date
- 2026-04-17
AI Technical Summary
The existing two-factor authentication is only triggered by the session management function or the authentication server. Unsigned terminals cannot perform two-factor authentication, resulting in poor triggering flexibility.
The SMF sends a request message carrying the UE's general public user identifier to the authentication server, receives an indication message to determine whether to trigger secondary authentication for unsigned terminals, and determines whether to perform secondary authentication based on location and the number of session requests.
It improves the flexibility of secondary authentication for uncontracted terminals, enriches the application scenarios of secondary authentication, and enables secure access for uncontracted terminals.
Smart Images

Figure CN116782214B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of communication technology, and in particular to an authentication method and related equipment. Background Technology
[0002] To meet the diverse network and communication capabilities required by vertical industry applications, 5G networks not only authenticate terminal access but also provide authentication capabilities for terminals accessing data networks within those industries—a process known as secondary authentication. Secondary authentication leverages the underlying authentication channel provided by the 5G network, allowing vertical industries to select or customize specific authentication algorithms and protocols, ensuring autonomy and control over authentication and providing effective security for 5G applications in vertical industries. Simultaneously, secondary authentication helps reduce new security risks arising between users and external data networks when accessing them via 5G.
[0003] 5G two-factor authentication enables authentication between a terminal and an external data network. However, currently, two-factor authentication is only triggered by the Session Management Function (SMF) or an authentication server, and only terminals that have signed up for two-factor authentication can perform it. In real-world applications, such as a company's 5G smart park, there may be situations where unsigned employees enter the park and their terminals need to access the data network (e.g., access intranet services). In such cases, two-factor authentication cannot be performed, thus limiting the flexibility of triggering two-factor authentication. Summary of the Invention
[0004] This invention provides an authentication method and related equipment to solve the problem that in existing secondary authentication methods, only terminals that have signed up for secondary authentication can perform secondary authentication, resulting in poor flexibility in triggering terminals to perform secondary authentication.
[0005] To solve the above-mentioned technical problems, the present invention is implemented as follows:
[0006] In a first aspect, embodiments of the present invention provide an authentication method applied to a Session Management Function (SMF), the method comprising:
[0007] If it is determined that the user equipment (UE) has not signed up for secondary authentication, a first request message is sent to the authentication server. The first request message carries the General Public User Identifier (GPSI) corresponding to the UE. The first request message is used to request confirmation on whether to perform secondary authentication on the UE.
[0008] The system receives a first indication message sent by the authentication server, which is used to determine whether to trigger secondary authentication for the UE.
[0009] Optionally, after receiving the first indication information sent by the authentication server, the method further includes:
[0010] If the first indication information indicates that the UE should be triggered for secondary authentication, then the UE shall be triggered for secondary authentication.
[0011] Optionally, sending the first request information to the authentication server includes:
[0012] When the user location information of the UE indicates that the UE is in a location area where secondary authentication is permitted, the UE sends a first request to the authentication server.
[0013] Optionally, sending the first request information to the authentication server includes:
[0014] If the number of Protocol Data Unit (PDU) session requests initiated by the UE is less than a preset threshold, a first request message is sent to the authentication server.
[0015] Optionally, before sending the first request information to the authentication server, the method further includes:
[0016] The Globally Unique Permanent User Identifier (SUPI) and Data Network Name (DNN) of the UE are used to obtain the General Public User Identifier (GPSI) corresponding to the UE.
[0017] Optionally, sending the first request information to the authentication server includes:
[0018] Establish an N4 session with the User Plane Function (UPF), wherein N4 is the interface between the SMF and the UPF;
[0019] The first request information is sent to the authentication server through the UPF.
[0020] Secondly, embodiments of the present invention provide an authentication method applied to an authentication server, the method comprising:
[0021] If the user equipment (UE) has not signed up for secondary authentication, the system receives a first request message sent by the session management function (SMF). The first request message carries the General Public User Identifier (GPSI) corresponding to the UE and is used to request confirmation on whether to perform secondary authentication on the UE.
[0022] Send a first indication message to the SMF, the first indication message being used to determine whether to trigger secondary authentication of the UE.
[0023] Optionally, after sending the first indication information to the SMF, the method further includes:
[0024] If the first indication information indicates that the UE should be triggered for secondary authentication, then the UE shall be subjected to secondary authentication.
[0025] Optionally, after performing secondary authentication on the UE, the method further includes:
[0026] If the UE successfully performs secondary authentication, update information is sent to the Network Open Element (NEF). The update information is used to instruct the UE's corresponding GPSI to be added to the user's subscription data.
[0027] Optionally, receiving the first request information sent by the SMF includes:
[0028] When the user location information of the UE indicates that the UE is in a location area where secondary authentication is permitted, the UE receives the first request information sent by the SMF.
[0029] Optionally, receiving the first request information sent by the SMF includes:
[0030] If the number of Protocol Data Unit (PDU) session requests initiated by the UE is less than a preset threshold, the first request information sent by the SMF is received.
[0031] Optionally, the General Public Subscriber Identity (GPSI) corresponding to the UE is obtained based on the UE's Globally Unique Permanent Subscriber Identity (SUPI) and Data Network Name (DNN).
[0032] Thirdly, embodiments of the present invention provide an SMF, the SMF comprising:
[0033] The sending module is used to send a first request message to the authentication server when it is determined that the user equipment (UE) has not signed up for secondary authentication. The first request message carries the General Public User Identifier (GPSI) corresponding to the UE and is used to request confirmation on whether to perform secondary authentication on the UE.
[0034] The receiving module is used to receive first indication information sent by the authentication server, the first indication information being used to determine whether to trigger secondary authentication of the UE.
[0035] Optionally, the SMF further includes:
[0036] The triggering module is used to trigger the secondary authentication of the UE when the first indication information indicates that the secondary authentication of the UE should be triggered.
[0037] Optionally, the sending module is specifically used for:
[0038] If it is determined that the user equipment (UE) has not signed up for secondary authentication, and the user location information of the UE indicates that the UE is in a location area where secondary authentication is permitted, a first request message is sent to the authentication server.
[0039] Optionally, the sending module is specifically used for:
[0040] If it is determined that the user equipment (UE) has not signed up for secondary authentication, and the number of Protocol Data Unit (PDU) session requests initiated by the UE is less than a preset threshold, a first request message is sent to the authentication server.
[0041] Optionally, the SMF further includes:
[0042] The acquisition module is used to obtain the Universal Public User Identifier (GPSI) corresponding to the UE based on the UE's Globally Unique Permanent User Identifier (SUPI) and Data Network Name (DNN).
[0043] Optionally, the sending module is specifically used for:
[0044] If it is determined that the user equipment (UE) has not signed up for secondary authentication, an N4 session is established with the user plane function (UPF), wherein N4 is the interface between the SMF and the UPF;
[0045] The first request information is sent to the authentication server through the UPF.
[0046] Fourthly, embodiments of the present invention provide an authentication server, the authentication server comprising:
[0047] The receiving module is used to receive a first request message sent by the Session Management Function (SMF) when the User Equipment (UE) has not signed up for secondary authentication. The first request message carries the General Public User Identifier (GPSI) corresponding to the UE and is used to request confirmation on whether to perform secondary authentication on the UE.
[0048] The first sending module is used to send first indication information to the SMF, the first indication information being used to determine whether to trigger secondary authentication of the UE.
[0049] Optionally, the authentication server further includes:
[0050] The authentication module is used to perform secondary authentication on the UE when the first indication information indicates that secondary authentication of the UE is triggered.
[0051] Optionally, the authentication server further includes:
[0052] The second sending module is used to send update information to the Network Open Element (NEF) when the UE successfully performs secondary authentication. The update information is used to instruct the UE's corresponding GPSI to be added to the user's subscription data.
[0053] Optionally, the receiving module is specifically used for:
[0054] If the user equipment (UE) has not signed up for secondary authentication, and the user location information of the UE indicates that the UE is in a location area where secondary authentication is permitted, the UE receives the first request information sent by the SMF.
[0055] Optionally, the receiving module is specifically used for:
[0056] If the user equipment (UE) has not signed up for secondary authentication, and the number of Protocol Data Unit (PDU) session requests initiated by the UE is less than a preset threshold, the first request information sent by the SMF will be received.
[0057] Optionally, the General Public Subscriber Identity (GPSI) corresponding to the UE is obtained based on the UE's Globally Unique Permanent Subscriber Identity (SUPI) and Data Network Name (DNN).
[0058] Fifthly, embodiments of the present invention provide an SMF, including a transceiver and a processor.
[0059] The transceiver is configured to send a first request message to the authentication server when it is determined that the user equipment (UE) has not signed up for secondary authentication. The first request message carries the General Public User Identifier (GPSI) corresponding to the UE and is used to request confirmation on whether to perform secondary authentication on the UE.
[0060] The transceiver is also used to receive first indication information sent by the authentication server, the first indication information being used to determine whether to trigger secondary authentication of the UE.
[0061] Optionally, the processor is configured to trigger secondary authentication of the UE when the first indication information indicates that secondary authentication of the UE should be triggered.
[0062] Optionally, the transceiver is further configured to send a first request message to the authentication server when the user location information of the UE indicates that the UE is within a location area where secondary authentication is permitted.
[0063] Optionally, the transceiver is further configured to send a first request message to the authentication server when the number of Protocol Data Unit (PDU) session requests initiated by the UE is less than a preset threshold.
[0064] Optionally, the processor is further configured to obtain the General Public User Identifier (GPSI) corresponding to the UE based on the UE's Globally Unique Permanent User Identifier (SUPI) and Data Network Name (DNN).
[0065] Optionally, the processor is further configured to establish an N4 session with the User Plane Function (UPF), wherein the N4 is the interface between the SMF and the UPF;
[0066] The transceiver is also used to send a first request message to the authentication server via the UPF.
[0067] Sixthly, embodiments of the present invention provide an authentication server, including a transceiver and a processor.
[0068] The transceiver is used to receive a first request message sent by the Session Management Function (SMF) when the User Equipment (UE) has not signed up for secondary authentication. The first request message carries the General Public User Identifier (GPSI) corresponding to the UE and is used to request confirmation on whether to perform secondary authentication on the UE.
[0069] The transceiver is also used to send a first indication message to the SMF, the first indication message being used to determine whether to trigger secondary authentication of the UE.
[0070] Optionally, the processor is configured to perform secondary authentication on the UE when the first indication information indicates that secondary authentication of the UE is triggered.
[0071] Optionally, the transceiver is further configured to send update information to the Network Open Element (NEF) when the UE successfully performs secondary authentication. The update information is used to instruct the UE's corresponding GPSI to be added to the user's subscription data.
[0072] Optionally, the transceiver is further configured to receive a first request message sent by the SMF when the user location information of the UE indicates that the UE is within a location area where secondary authentication is permitted.
[0073] Optionally, the transceiver is further configured to receive first request information sent by the SMF when the number of Protocol Data Unit (PDU) session requests initiated by the UE is less than a preset threshold.
[0074] Optionally, the General Public Subscriber Identity (GPSI) corresponding to the UE is obtained based on the UE's Globally Unique Permanent Subscriber Identity (SUPI) and Data Network Name (DNN).
[0075] In a seventh aspect, embodiments of the present invention provide an SMF, comprising: a processor, a memory, and a program stored in the memory and executable on the processor, wherein the program, when executed by the processor, implements the steps of the authentication method described in the first aspect.
[0076] Eighthly, embodiments of the present invention provide an authentication server, comprising: a processor, a memory, and a program stored in the memory and executable on the processor, wherein the program, when executed by the processor, implements the steps of the authentication method described in the second aspect above.
[0077] Ninthly, embodiments of the present invention provide a computer-readable storage medium storing a computer program, wherein when the computer program is executed by a processor, it implements the steps of the authentication method described in the first aspect; or when the computer program is executed by a processor, it implements the steps of the authentication method described in the second aspect.
[0078] In this embodiment of the invention, when it is determined that the User Equipment (UE) has not subscribed to secondary authentication, a first request message is sent to the authentication server. This first request message carries the General Public Subscriber Identity (GPSI) corresponding to the UE and is used to request confirmation on whether to perform secondary authentication on the UE. A first indication message is received from the authentication server, which is used to determine whether to trigger secondary authentication for the UE. Thus, for UEs that have not subscribed to secondary authentication, the interaction between the SMF and the authentication server can determine whether to trigger secondary authentication, improving the flexibility of triggering secondary authentication and enriching the use cases for secondary authentication. Attached Figure Description
[0079] To more clearly illustrate the technical solutions of the embodiments of the present invention, the drawings used in the description of the embodiments of the present invention will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0080] Figure 1 This is a flowchart of an authentication method provided in an embodiment of the present invention;
[0081] Figure 2 This is a schematic diagram of a UE accessing a campus network according to an embodiment of the present invention;
[0082] Figure 3 This is a flowchart of another authentication method provided in an embodiment of the present invention;
[0083] Figure 4This is a flowchart of another authentication method provided in an embodiment of the present invention;
[0084] Figure 5 This is a schematic diagram of an SMF structure provided in an embodiment of the present invention;
[0085] Figure 6 This is a schematic diagram of the structure of an authentication server provided in an embodiment of the present invention;
[0086] Figure 7 This is a schematic diagram of another SMF structure provided in an embodiment of the present invention;
[0087] Figure 8 This is a schematic diagram of another authentication server provided in an embodiment of the present invention. Detailed Implementation
[0088] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some, not all, of the embodiments of the present invention. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0089] In this embodiment of the invention, an authentication method and related equipment are proposed to solve the problem that in existing secondary authentication, only terminals that have signed up for secondary authentication can perform secondary authentication, resulting in poor flexibility in triggering terminals to perform secondary authentication.
[0090] See Figure 1 , Figure 1 This is a flowchart of an authentication method provided in an embodiment of the present invention, used in the Session Management Function (SMF), such as... Figure 1 As shown, the method includes the following steps:
[0091] Step 101: If it is determined that the User Equipment (UE) has not signed up for secondary authentication, a first request message is sent to the authentication server. The first request message carries the Generic Public Subscription Identifier (GPSI) corresponding to the UE. The first request message is used to request confirmation on whether to perform secondary authentication on the UE.
[0092] The authentication server can be a third-party data network server used for authentication, authorization, and accounting, or a carrier data network server used for authentication, authorization, and accounting, etc. For example, the authentication server can be a Data Network Authentication, Authorization, Accounting (DN-AAA) server. Sending the first request information to the authentication server can be done when the UE's user location information indicates that the UE is within a location area where secondary authentication is permitted; or it can be done when the number of Protocol Data Unit (PDU) session requests initiated by the UE is less than a preset threshold; or it can be done when the UE's user location information indicates that the UE is within a location area where secondary authentication is permitted and the number of PDU session requests initiated by the UE is less than a preset threshold; etc., this embodiment does not limit this.
[0093] In one implementation, if it is determined that the user equipment (UE) has not signed up for secondary authentication, and if the user location information of the UE indicates that the UE is in a location area where secondary authentication is allowed and the number of Protocol Data Unit (PDU) session requests initiated by the UE is less than a preset threshold, then a first request message is sent to the authentication server.
[0094] Step 102: Receive the first indication information sent by the authentication server. The first indication information is used to determine whether to trigger the secondary authentication of the UE.
[0095] The secondary authentication can be used to indicate that the UE and the authentication server authenticate each other through an extensible authentication protocol. If the first indication information indicates that the UE's secondary authentication should be triggered, then the UE's secondary authentication can be triggered; if the first indication information indicates that the UE's secondary authentication should not be triggered, then the UE's secondary authentication can be left untried, i.e., the action of triggering the UE's secondary authentication is not performed.
[0096] In one implementation, if the UE successfully performs secondary authentication, the authentication server can send update information to the Network Exposure Function (NEF). This update information instructs that the GPSI corresponding to the UE be added to the user's subscription data. Thus, for UEs that have not yet subscribed, successful secondary authentication enables automatic subscription, thereby dynamically updating the user's subscription data.
[0097] It should be noted that for UEs with subscribed secondary authentication, the secondary authentication process can be as follows: The UE first establishes a Network Attached Storage (NAS) security context through the Primary Authentication and Access and Mobility Management Function (AMF). The AMF is responsible for terminal access and handover. Then, the UE initiates a PDU session establishment request. The Session Management Function (SMF) obtains subscription data from the Unified Data Management Function (UDM) based on the globally unique Subscription Permanent Identifier (SUPI) obtained from the AMF. The SMF is used to provide service continuity and uninterrupted user experience, while the UDM is responsible for generating authentication vectors. The SMF checks whether the UE request conforms to the user subscription data and local policies. If it does not conform, the UE request is rejected. If it does conform, the Extensible Authentication Protocol (EAP) authentication process is triggered. The DNAAA server and the UE exchange the EAP messages required for EAP, completing authentication, and subsequently establishing a PDU session.
[0098] In this embodiment of the invention, when it is determined that the User Equipment (UE) has not subscribed to secondary authentication, a first request message is sent to the authentication server. This first request message carries the General Public Subscriber Identity (GPSI) corresponding to the UE and is used to request confirmation on whether to perform secondary authentication on the UE. A first indication message is received from the authentication server, which is used to determine whether to trigger secondary authentication for the UE. Thus, for UEs that have not subscribed to secondary authentication, the interaction between the SMF and the authentication server can determine whether to trigger secondary authentication, improving the flexibility of triggering secondary authentication and enriching the use cases for secondary authentication.
[0099] Optionally, after receiving the first indication information sent by the authentication server, the method further includes:
[0100] If the first indication information indicates that the UE should be triggered for secondary authentication, then the UE shall be triggered for secondary authentication.
[0101] In the case where the UE is triggered to perform secondary authentication by the SMF, the UE and the authentication server exchange EAP authentication messages to perform secondary authentication.
[0102] In this embodiment, when the first indication information indicates that the UE should be triggered for secondary authentication, the UE is triggered for secondary authentication. This allows the UE to determine the triggering of secondary authentication by sending the first indication information from the authentication server to the SMF, enabling UEs that have not signed up for secondary authentication to perform secondary authentication after accessing the network and securely access the data network.
[0103] Optionally, sending the first request information to the authentication server includes:
[0104] When the user location information of the UE indicates that the UE is in a location area where secondary authentication is permitted, the UE sends a first request to the authentication server.
[0105] The UE's user location information can be carried in the UE's ULI parameter. This user location information indicates that the UE is within a location area where secondary authentication is permitted; it can be represented by the UE's ULI parameter. This permitted location area can be preset, and different location areas can be set for different use cases. For example, such as... Figure 2 As shown, for a UE that needs to access a company's intranet services, the location area that allows secondary authentication can be a company's 5G smart park.
[0106] In addition, when the user location information of the UE indicates that the UE is in a location area where secondary authentication is allowed, the SMF can obtain the general public user identifier (GPSI) corresponding to the UE based on the UE's globally unique permanent user identifier (SUPI) and data network name (DNN), and send a first request message to the authentication server, which carries the GPSI corresponding to the UE.
[0107] In this embodiment, when the user location information of the UE indicates that the UE is in a location area where secondary authentication is permitted, a first request message is sent to the authentication server. In this way, secondary authentication can be performed for UEs that have not signed up but need to access a specific network in a specific area, thus enriching the use cases for secondary authentication of UEs.
[0108] Optionally, sending the first request information to the authentication server includes:
[0109] If the number of Protocol Data Unit (PDU) session requests initiated by the UE is less than a preset threshold, a first request message is sent to the authentication server.
[0110] The preset threshold can be pre-set, for example, to 100, 1000, 10000, etc., and can be set according to the SMF's capabilities to ensure that the number of PDU session requests initiated by the UE is within the SMF's overload control range. Sending a first request message to the authentication server when the number of PDU session requests initiated by the UE is less than the preset threshold can be done when the UE's user location information indicates that the UE is within a location area where secondary authentication is permitted, and the number of PDU session requests initiated by the UE is less than the preset threshold.
[0111] In this embodiment, if the number of Protocol Data Unit (PDU) session requests initiated by the UE is less than a preset threshold, a first request message is sent to the authentication server. This can reduce the possibility of DoS attacks launched by malicious UEs against the authentication server and improve network security.
[0112] Optionally, before sending the first request information to the authentication server, the method further includes:
[0113] The Globally Unique Permanent User Identifier (SUPI) and Data Network Name (DNN) of the UE are used to obtain the General Public User Identifier (GPSI) corresponding to the UE.
[0114] The SMF can send a request message to the UDM, which carries the UE's SUPI and DNN. The UDM then returns the GPSI corresponding to the UE to the SMF. Thus, the SMF can obtain the GPSI corresponding to the UE from the UDM based on the UE's SUPI and DNN.
[0115] In this implementation, the Globally Unique Permanent User Identifier (SUPI) and Data Network Name (DNN) of the UE are used to obtain the General Public User Identifier (GPSI) corresponding to the UE. In this way, the UE's GPSI can be used to request confirmation from the authentication server whether to perform secondary authentication on the UE.
[0116] Optionally, sending the first request information to the authentication server includes:
[0117] Establish an N4 session with the User Plane Function (UPF), wherein N4 is the interface between the SMF and the UPF;
[0118] The first request information is sent to the authentication server through the UPF.
[0119] The ID of the N4 session can be assigned by the SMF to uniquely identify an N4 session.
[0120] In this embodiment, an N4 session is established with the User Plane Function (UPF), and a first request message is sent to the authentication server through the UPF. This allows the UPF to transmit a first request message to the authentication server requesting confirmation on whether to perform secondary authentication on the UE.
[0121] As a specific embodiment, such as Figure 3 As shown, the authentication method includes the following process:
[0122] (1) The UE sends an authentication request (Registration request) to the AMF;
[0123] (2) Primary authentication is performed between the UE and the Authentication Server Function (AUSF);
[0124] (3) NAS security is established between UE and AMF;
[0125] (4) The UE sends a PDU session establishment request (NAS security established) to the AMF;
[0126] (5a) The AMF sends a NAS security context establishment request (Nsmf_PDUSession_CreateSMContextRequest) to the V-SMF;
[0127] (5b) The V-SMF returns a NAS security context establishment request response (Nsmf_PDUSession_CreateSMContext Response) to the AMF.
[0128] (6) The V-SMF continues the PDU session establishment request process and sends a PDU session creation request (Nsmf_PDUSession_Create Request) to the H-SMF;
[0129] (7) The SMF obtains subscription information from the UDM and verifies whether the UE request is legitimate;
[0130] (8) The SMF obtains the GPSI corresponding to the UE from the UDM based on the SUPI and DNN;
[0131] If the UE has not signed up for secondary authentication, but the UE's ULI parameters indicate that the UE is within a location area where secondary authentication is permitted and the number of PDU requests initiated by the UE is within the SMF overload control range, then the SMF obtains the UE's corresponding GPSI from the UDM based on the SUPI and DNN. The SMF overload control range is set to reduce potential DoS attacks that malicious UEs may launch against DN AAA.
[0132] (9) SMF establishes an N4 session with H-UPF;
[0133] (10) The SMF requests the DN-AAA via the H-UPF whether to perform secondary authentication on the UE, and the request carries the UE's GPSI.
[0134] (11) DN-AAA determines whether to trigger secondary authentication based on the UE's GPSI;
[0135] DN-AAA queries the authentication database based on GPSI to determine whether secondary authentication needs to be triggered. If it does not need to be executed, it skips all subsequent processes. If it needs to be executed, it instructs SMF to trigger secondary authentication.
[0136] (12) Does DN-AAA respond to SMF to trigger secondary authentication?
[0137] (13) The UE performs EAP authentication;
[0138] If DN-AAA responds to SMF to trigger secondary authentication, then SMF triggers secondary authentication, and UE and DN-AAA exchange EAP authentication messages.
[0139] (14) The UE continues the PDU session establishment process and indicates that the EAP authentication is successful.
[0140] (15) DN-AAA updates UDM contract data.
[0141] After the UE successfully completes EAP authentication, DN-AAA sends update information (Nnef_parameterProvision_update) to NEF, adding the UE's GPSI to the user's subscription data.
[0142] It should be noted that the UE and DN-AAA support EAP authentication based on 3GPP credentials or online credential applications, such as EAP-TLS, EAP-MD5, EAP-AKA, etc.
[0143] In this embodiment, SMF provides a method for UEs that do not have a secondary authentication subscription but actually need to perform secondary authentication. This allows DN-AAA to determine whether to perform secondary authentication based on the UE's GPSI information. Furthermore, for UEs that successfully perform secondary authentication, it can automatically trigger an update of the user's subscription data. For UEs that need secondary authentication but have not signed up, this method can trigger the UE's secondary authentication, enabling DN-AAA to have more autonomous and refined control over the UE's secondary authentication. It also allows for dynamic updates of user subscription data, improving the flexibility of secondary authentication and enriching its application scenarios.
[0144] See Figure 4 , Figure 4 This is a flowchart of an authentication method provided in an embodiment of the present invention, used for an authentication server, such as... Figure 4 As shown, the method includes the following steps:
[0145] Step 201: If the user equipment (UE) has not signed up for secondary authentication, receive a first request message sent by the session management function (SMF). The first request message carries the general public user identifier (GPSI) corresponding to the UE. The first request message is used to request confirmation on whether to perform secondary authentication on the UE.
[0146] Step 202: Send a first indication message to the SMF. The first indication message is used to determine whether to trigger the UE's secondary authentication.
[0147] Optionally, after sending the first indication information to the SMF, the method further includes:
[0148] If the first indication information indicates that the UE should be triggered for secondary authentication, then the UE shall be subjected to secondary authentication.
[0149] Optionally, after performing secondary authentication on the UE, the method further includes:
[0150] If the UE successfully performs secondary authentication, update information is sent to the Network Open Element (NEF). The update information is used to instruct the UE's corresponding GPSI to be added to the user's subscription data.
[0151] Optionally, receiving the first request information sent by the SMF includes:
[0152] When the user location information of the UE indicates that the UE is in a location area where secondary authentication is permitted, the UE receives the first request information sent by the SMF.
[0153] Optionally, receiving the first request information sent by the SMF includes:
[0154] If the number of Protocol Data Unit (PDU) session requests initiated by the UE is less than a preset threshold, the first request information sent by the SMF is received.
[0155] Optionally, the General Public Subscriber Identity (GPSI) corresponding to the UE is obtained based on the UE's Globally Unique Permanent Subscriber Identity (SUPI) and Data Network Name (DNN).
[0156] It should be noted that this embodiment is as a comparison with... Figure 4 The implementation method of the authentication server in the illustrated embodiment can be found in [reference needed]. Figure 4 The related descriptions of the embodiments shown will not be repeated in this embodiment to avoid repetition, and can achieve the same beneficial effects.
[0157] See Figure 5 , Figure 5 This is a schematic diagram of an SMF structure provided in an embodiment of the present invention, as shown below. Figure 5 As shown, the SMF300 includes:
[0158] The sending module 301 is used to send a first request message to the authentication server when it is determined that the user equipment UE has not signed up for secondary authentication. The first request message carries the general public user identifier (GPSI) corresponding to the UE and is used to request confirmation on whether to perform secondary authentication on the UE.
[0159] The receiving module 302 is used to receive first indication information sent by the authentication server, the first indication information being used to determine whether to trigger secondary authentication of the UE.
[0160] Optionally, the SMF further includes:
[0161] The triggering module is used to trigger the secondary authentication of the UE when the first indication information indicates that the secondary authentication of the UE should be triggered.
[0162] Optionally, the sending module is specifically used for:
[0163] If it is determined that the user equipment (UE) has not signed up for secondary authentication, and the user location information of the UE indicates that the UE is in a location area where secondary authentication is permitted, a first request message is sent to the authentication server.
[0164] Optionally, the sending module is specifically used for:
[0165] If it is determined that the user equipment (UE) has not signed up for secondary authentication, and the number of Protocol Data Unit (PDU) session requests initiated by the UE is less than a preset threshold, a first request message is sent to the authentication server.
[0166] Optionally, the SMF further includes:
[0167] The acquisition module is used to obtain the Universal Public User Identifier (GPSI) corresponding to the UE based on the UE's Globally Unique Permanent User Identifier (SUPI) and Data Network Name (DNN).
[0168] Optionally, the sending module is specifically used for:
[0169] If it is determined that the user equipment (UE) has not signed up for secondary authentication, an N4 session is established with the user plane function (UPF), wherein N4 is the interface between the SMF and the UPF;
[0170] The first request information is sent to the authentication server through the UPF.
[0171] SMF300 can achieve Figure 1 The various processes implemented by SMF in the illustrated method embodiment will not be described again here to avoid repetition. For UEs that have not signed up for secondary authentication, the interaction between SMF and the authentication server can determine whether to trigger secondary authentication for the UE, which can improve the flexibility of triggering secondary authentication for the UE and enrich the use cases for secondary authentication.
[0172] See Figure 6 , Figure 6 This is a schematic diagram of the structure of an authentication server provided in an embodiment of the present invention, as shown below. Figure 6 As shown, the authentication server 400 includes:
[0173] The receiving module 401 is configured to receive a first request message sent by the Session Management Function (SMF) when the User Equipment (UE) has not signed up for secondary authentication. The first request message carries the General Public User Identifier (GPSI) corresponding to the UE and is used to request confirmation on whether to perform secondary authentication on the UE.
[0174] The first sending module 402 is used to send first indication information to the SMF, the first indication information being used to determine whether to trigger secondary authentication of the UE.
[0175] Optionally, the authentication server further includes:
[0176] The authentication module is used to perform secondary authentication on the UE when the first indication information indicates that secondary authentication of the UE is triggered.
[0177] Optionally, the authentication server further includes:
[0178] The second sending module is used to send update information to the Network Open Element (NEF) when the UE successfully performs secondary authentication. The update information is used to instruct the UE's corresponding GPSI to be added to the user's subscription data.
[0179] Optionally, the receiving module is specifically used for:
[0180] If the user equipment (UE) has not signed up for secondary authentication, and the user location information of the UE indicates that the UE is in a location area where secondary authentication is permitted, the UE receives the first request information sent by the SMF.
[0181] Optionally, the receiving module is specifically used for:
[0182] If the user equipment (UE) has not signed up for secondary authentication, and the number of Protocol Data Unit (PDU) session requests initiated by the UE is less than a preset threshold, the first request information sent by the SMF will be received.
[0183] Optionally, the General Public Subscriber Identity (GPSI) corresponding to the UE is obtained based on the UE's Globally Unique Permanent Subscriber Identity (SUPI) and Data Network Name (DNN).
[0184] Authentication server 400 can achieve Figure 4 The various processes implemented by the authentication server in the illustrated method embodiment will not be described again here to avoid repetition. For UEs that have not signed up for secondary authentication, the interaction between the SMF and the authentication server can determine whether to trigger secondary authentication for the UE, which can improve the flexibility of triggering secondary authentication for the UE and enrich the use cases for secondary authentication.
[0185] This invention also provides an SMF, including: a processor, a memory, and a program stored in the memory and executable on the processor. When the program is executed by the processor, it implements the various processes of the above-described authentication method embodiments and achieves the same technical effect. To avoid repetition, it will not be described again here.
[0186] For details, see Figure 7 As shown, this embodiment of the invention also provides an SMF, including a bus 501, a transceiver 502, an antenna 503, a bus interface 504, a processor 505, and a memory 506.
[0187] The transceiver 502 is used to send a first request message to the authentication server when it is determined that the user equipment UE has not signed up for secondary authentication. The first request message carries the General Public User Identifier (GPSI) corresponding to the UE and is used to request confirmation on whether to perform secondary authentication on the UE.
[0188] The transceiver 502 is also used to receive first indication information sent by the authentication server, the first indication information being used to determine whether to trigger secondary authentication of the UE.
[0189] Optionally, the processor 505 is configured to trigger secondary authentication of the UE when the first indication information indicates that secondary authentication of the UE should be triggered.
[0190] Optionally, the transceiver 502 is further configured to send a first request message to the authentication server when the user location information of the UE indicates that the UE is in a location area where secondary authentication is permitted.
[0191] Optionally, the transceiver 502 is further configured to send a first request message to the authentication server when the number of Protocol Data Unit (PDU) session requests initiated by the UE is less than a preset threshold.
[0192] Optionally, the processor 505 is further configured to obtain the General Public User Identifier (GPSI) corresponding to the UE based on the UE's Globally Unique Permanent User Identifier (SUPI) and Data Network Name (DNN).
[0193] Optionally, the processor 505 is further configured to establish an N4 session with the User Plane Function (UPF), wherein the N4 is the interface between the SMF and the UPF;
[0194] The transceiver 502 is also used to send a first request message to the authentication server through the UPF.
[0195] exist Figure 7 In this document, a bus architecture (represented by bus 501) is used. Bus 501 can include any number of interconnected buses and bridges, linking various circuits including one or more processors represented by processor 505 and memory represented by memory 506. Bus 501 can also link various other circuits such as peripheral devices, voltage regulators, and power management circuits, which are well known in the art and therefore will not be described further herein. Bus interface 504 provides an interface between bus 501 and transceiver 502. Transceiver 502 can be a single element or multiple elements, such as multiple receivers and transmitters, providing a unit for communicating with various other devices over a transmission medium. Data processed by processor 505 is transmitted over a wireless medium via antenna 503, which further receives data and transmits it to processor 505.
[0196] Processor 505 manages bus 501 and general processing, and also provides various functions, including timing, peripheral interfaces, voltage regulation, power management, and other control functions. Memory 506 can be used to store data used by processor 505 during operation.
[0197] Optionally, the processor 505 can be a CPU, ASIC, FPGA, or CPLD.
[0198] This invention also provides an authentication server, including: a processor, a memory, and a program stored in the memory and executable on the processor. When the program is executed by the processor, it implements the various processes of the above-described authentication method embodiments and achieves the same technical effect. To avoid repetition, it will not be described again here.
[0199] For details, see Figure 8 As shown, this embodiment of the invention also provides an authentication server, including a bus 601, a transceiver 602, an antenna 603, a bus interface 604, a processor 605, and a memory 606.
[0200] The transceiver 602 is used to receive a first request message sent by the Session Management Function (SMF) when the User Equipment (UE) has not signed up for secondary authentication. The first request message carries the General Public User Identifier (GPSI) corresponding to the UE and is used to request confirmation on whether to perform secondary authentication on the UE.
[0201] The transceiver 602 is also used to send first indication information to the SMF, the first indication information being used to determine whether to trigger secondary authentication of the UE.
[0202] Optionally, the processor 605 is configured to perform secondary authentication on the UE when the first indication information indicates that secondary authentication of the UE is triggered.
[0203] Optionally, the transceiver 602 is further configured to send update information to the Network Open Element (NEF) when the UE successfully performs secondary authentication. The update information is used to instruct the UE's corresponding GPSI to be added to the user's subscription data.
[0204] Optionally, the transceiver 602 is further configured to receive a first request message sent by the SMF when the user location information of the UE indicates that the UE is in a location area where secondary authentication is permitted.
[0205] Optionally, the transceiver 602 is further configured to receive first request information sent by the SMF when the number of Protocol Data Unit (PDU) session requests initiated by the UE is less than a preset threshold.
[0206] Optionally, the General Public Subscriber Identity (GPSI) corresponding to the UE is obtained based on the UE's Globally Unique Permanent Subscriber Identity (SUPI) and Data Network Name (DNN).
[0207] exist Figure 8 In this document, a bus architecture (represented by bus 601) is used. Bus 601 can include any number of interconnected buses and bridges, linking various circuits including one or more processors represented by processor 605 and memory represented by memory 606. Bus 601 can also link various other circuits such as peripheral devices, voltage regulators, and power management circuits, which are well known in the art and therefore will not be described further herein. Bus interface 604 provides an interface between bus 601 and transceiver 602. Transceiver 602 can be a single element or multiple elements, such as multiple receivers and transmitters, providing a unit for communicating with various other devices over a transmission medium. Data processed by processor 605 is transmitted over a wireless medium via antenna 603, which further receives data and transmits data to processor 605.
[0208] Processor 605 manages bus 601 and general processing, and also provides various functions, including timing, peripheral interface, voltage regulation, power management, and other control functions. Memory 606 can be used to store data used by processor 605 during operation.
[0209] Optionally, the processor 605 can be a CPU, ASIC, FPGA, or CPLD.
[0210] This invention also provides a computer-readable storage medium storing a computer program. When executed by a processor, this computer program implements the various processes of the above-described authentication method embodiments and achieves the same technical effects. To avoid repetition, it will not be described again here. The computer-readable storage medium may be a read-only memory (ROM), a random access memory (RAM), a magnetic disk, or an optical disk, etc.
[0211] It should be noted that, in this document, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Unless otherwise specified, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes that element.
[0212] Through the above description of the embodiments, those skilled in the art can clearly understand that the methods of the above embodiments can be implemented by means of software plus necessary general-purpose hardware platforms. Of course, they can also be implemented by hardware, but in many cases the former is a better implementation method. Based on this understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk), and includes several instructions to cause a terminal (which may be a mobile phone, computer, server, air conditioner, or network device, etc.) to execute the methods described in the various embodiments of the present invention.
[0213] The embodiments of the present invention have been described above with reference to the accompanying drawings. However, the present invention is not limited to the specific embodiments described above. The specific embodiments described above are merely illustrative and not restrictive. Those skilled in the art can make many other forms under the guidance of the present invention without departing from the spirit and scope of the claims, and all of these forms are within the protection scope of the present invention.
Claims
1. An authentication method characterized by, Applied to the Session Management Function (SMF), the method includes: If it is determined that the user equipment (UE) has not signed up for secondary authentication, a first request message is sent to the authentication server. The first request message carries the General Public User Identifier (GPSI) corresponding to the UE. The first request message is used to request confirmation on whether to perform secondary authentication on the UE. The system receives a first indication message sent by the authentication server, which is used to determine whether to trigger secondary authentication for the UE.
2. The method according to claim 1, characterized in that, After receiving the first indication information sent by the authentication server, the method further includes: If the first indication information indicates that the UE should be triggered for secondary authentication, then the UE shall be triggered for secondary authentication.
3. The method according to claim 1, characterized in that, Sending the first request information to the authentication server includes: When the user location information of the UE indicates that the UE is in a location area where secondary authentication is permitted, the UE sends a first request to the authentication server.
4. The method according to claim 1, characterized in that, Sending the first request information to the authentication server includes: If the number of Protocol Data Unit (PDU) session requests initiated by the UE is less than a preset threshold, a first request message is sent to the authentication server.
5. The method according to claim 1, characterized in that, Before sending the first request information to the authentication server, the method further includes: The Globally Unique Permanent User Identifier (SUPI) and Data Network Name (DNN) of the UE are used to obtain the General Public User Identifier (GPSI) corresponding to the UE.
6. The method according to claim 1, characterized in that, Sending the first request information to the authentication server includes: Establish an N4 session with the User Plane Function (UPF), wherein N4 is the interface between the SMF and the UPF; The first request information is sent to the authentication server through the UPF.
7. An authentication method, characterized in that, Applied to an authentication server, the method includes: If the user equipment (UE) has not signed up for secondary authentication, the system receives a first request message sent by the session management function (SMF). The first request message carries the General Public User Identifier (GPSI) corresponding to the UE and is used to request confirmation on whether to perform secondary authentication on the UE. Send a first indication message to the SMF, the first indication message being used to determine whether to trigger secondary authentication of the UE.
8. The method according to claim 7, characterized in that, After sending the first indication information to the SMF, the method further includes: If the first indication information indicates that the UE should be triggered for secondary authentication, then the UE shall be subjected to secondary authentication.
9. The method according to claim 7, characterized in that, After performing secondary authentication on the UE, the method further includes: If the UE successfully performs secondary authentication, update information is sent to the Network Open Element (NEF). The update information is used to instruct the UE's corresponding GPSI to be added to the user's subscription data.
10. The method according to claim 7, characterized in that, The first request information sent by the SMF includes: When the user location information of the UE indicates that the UE is in a location area where secondary authentication is permitted, the UE receives the first request information sent by the SMF.
11. The method according to claim 7, characterized in that, The first request information sent by the SMF includes: If the number of Protocol Data Unit (PDU) session requests initiated by the UE is less than a preset threshold, the UE receives the first request information sent by the SMF.
12. The method according to claim 7, characterized in that, The General Public User Identifier (GPSI) corresponding to the UE is obtained based on the UE's Globally Unique Permanent User Identifier (SUPI) and Data Network Name (DNN).
13. An SMF, characterized in that, The SMF includes: The sending module is used to send a first request message to the authentication server when it is determined that the user equipment (UE) has not signed up for secondary authentication. The first request message carries the General Public User Identifier (GPSI) corresponding to the UE and is used to request confirmation on whether to perform secondary authentication on the UE. The receiving module is used to receive first indication information sent by the authentication server, the first indication information being used to determine whether to trigger secondary authentication of the UE.
14. An authentication server, characterized in that, The authentication server includes: The receiving module is used to receive a first request message sent by the Session Management Function (SMF) when the User Equipment (UE) has not signed up for secondary authentication. The first request message carries the General Public User Identifier (GPSI) corresponding to the UE and is used to request confirmation on whether to perform secondary authentication on the UE. The first sending module is used to send first indication information to the SMF, the first indication information being used to determine whether to trigger secondary authentication of the UE.
15. An SMF, characterized in that, Including transceivers and processors, The transceiver is configured to send a first request message to the authentication server when it is determined that the user equipment (UE) has not signed up for secondary authentication. The first request message carries the General Public User Identifier (GPSI) corresponding to the UE and is used to request confirmation on whether to perform secondary authentication on the UE. The transceiver is also used to receive first indication information sent by the authentication server, the first indication information being used to determine whether to trigger secondary authentication of the UE.
16. An authentication server, characterized in that, Including transceivers and processors, The transceiver is used to receive a first request message sent by the Session Management Function (SMF) when the User Equipment (UE) has not signed up for secondary authentication. The first request message carries the General Public User Identifier (GPSI) corresponding to the UE and is used to request confirmation on whether to perform secondary authentication on the UE. The transceiver is also used to send a first indication message to the SMF, the first indication message being used to determine whether to trigger secondary authentication of the UE.
17. An SMF, characterized in that, include: A processor, a memory, and a program stored in the memory and executable on the processor, wherein the program, when executed by the processor, implements the steps of the authentication method as described in any one of claims 1 to 6.
18. An authentication server, characterized in that, include: A processor, a memory, and a program stored in the memory and executable on the processor, wherein the program, when executed by the processor, implements the steps of the authentication method as described in any one of claims 7 to 12.
19. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program that, when executed by a processor, implements the steps of the authentication method as described in any one of claims 1 to 6; or, when executed by a processor, the computer program implements the steps of the authentication method as described in any one of claims 7 to 12.
Citation Information
Patent Citations
Information verification method, system and device
CN110177111A
Authentication and authorization method and device
CN113784346A