Authentication methods, devices, servers, and computer-readable storage media
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-03-09
- Publication Date
- 2026-08-14
AI Technical Summary
目前,待认证终端通过用户身份、或者使用场景等方法进行二次认证,通过待认证终端进行二次认证时,待认证终端存在造假的问题,降低了二次认证的安全性
[0039]本发明提供的一种认证方法、装置、服务器以及计算机可读存储介质,AAA-服务器在接收核心网转发的二次认证请求时,向核心网发送地理位置请求,接收核心网发送的地理位置请求对应的请求反馈,并根据请求反馈获取待认证终端的地理位置,向位置业务平台LSP发送包含地理位置的位置鉴权请求,其中,LSP根据位置鉴权请求获取地理位置,并根据地理位置与预设位置集之间的位置关系确定位置鉴权结果,接收LSP发送的位置鉴权结果,根据位置鉴权结果确定二次认证结果。AAA-服务器通过核心网确定终端的地理位置,能够避免根据接收待认证终端发送的地理位置进行二次认证时,待认证终端进行位置造假的问题。提高了二次认证结果的安全性。
Smart Images

Figure CN116782221B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of communication technology, and in particular to an authentication method, apparatus, server, and computer-readable storage medium. Background Technology
[0002] 5G technology represents the future direction of information and communication technology. It not only boasts enhanced performance but also offers a wider range of application scenarios, extending beyond traditional human-to-human communication to include intelligent interconnection between people and things, and between things themselves. It serves as a crucial infrastructure for the digital transformation of the future economy and society.
[0003] Building upon primary authentication, 5G technology can provide network slicing for various industries, avoiding the need to build a dedicated physical network for each service and thus saving deployment costs. On the other hand, because different industries have specific security requirements, to prevent unauthorized terminals from accessing industry-specific network slices, the 5G specification proposes secondary authentication for users accessing network slices. Currently, secondary authentication is performed on terminals using methods such as user identity or usage scenario. However, this secondary authentication process is vulnerable to forgery, reducing its security. Summary of the Invention
[0004] The main objective of this invention is to provide an authentication method, apparatus, server, and computer-readable storage medium, which aims to improve the security of secondary authentication.
[0005] To achieve the above objectives, the present invention provides an authentication method, which includes the following steps:
[0006] When receiving a secondary authentication request forwarded by the core network, a geolocation request is sent to the core network;
[0007] Receive the request feedback corresponding to the geolocation request sent by the core network, and obtain the geolocation of the terminal to be authenticated based on the request feedback;
[0008] A location authentication request containing the geographic location is sent to the location service platform (LSP), wherein the LSP obtains the geographic location based on the location authentication request and determines the location authentication result based on the location relationship between the geographic location and a preset location set;
[0009] Receive the location authentication result sent by LSP, and determine the secondary authentication result based on the location authentication result.
[0010] Optionally, before the step of receiving the location authentication result sent by the LSP and determining the secondary authentication result based on the location authentication result, the method further includes:
[0011] Determine the first authentication result corresponding to the communication identifier and the device identifier;
[0012] The step of receiving the location authentication result sent by the LSP and determining the secondary authentication result based on the location authentication result includes:
[0013] Receive the location authentication result sent by the LSP, and determine the second authentication result based on the location authentication result;
[0014] The secondary authentication result is determined based on the first authentication result and the second authentication result.
[0015] Optionally, after the step of receiving the location authentication result sent by the LSP and determining the secondary authentication result based on the location authentication result, the method includes:
[0016] Upon receiving the updated geographical location of the terminal to be authenticated from the core network, the system resends a location authentication request containing the geographical location to the LSP and receives the authentication result fed back by the LSP based on the authentication request.
[0017] Receive the location authentication result sent by LSP, and update the secondary authentication result based on the location authentication result.
[0018] Optionally, before the step of sending a geolocation request to the core network upon receiving a secondary authentication request forwarded by the core network, the following steps are included:
[0019] Receive a connection request for secondary authentication sent by the core network through the Extended Authentication Protocol (EAP) channel, and obtain the device identifier of the terminal to be authenticated carried in the connection request;
[0020] The terminal to be authenticated is identified based on the device identifier and the pre-stored identifier information;
[0021] When the authentication of the terminal to be authenticated is successful, a connection channel is established with the terminal to be authenticated.
[0022] Optionally, after the step of receiving the location authentication result sent by the LSP and determining the secondary authentication result based on the location authentication result, the method includes:
[0023] The secondary authentication result is forwarded to the terminal to be authenticated through the core network.
[0024] To achieve the above objectives, the present invention also provides an authentication method applied to a terminal to be authenticated, the authentication method comprising:
[0025] After the primary authentication is successful, a connection channel with the server is established;
[0026] A secondary authentication request is sent to the AAA server through the connection channel. The AAA server performs secondary authentication based on the secondary authentication request and the geographical location of the terminal to be authenticated, and sends the secondary authentication result back to the terminal to be authenticated.
[0027] Receive the secondary authentication result from the server, and generate a response identifier when the secondary authentication result is successful;
[0028] Send the response identifier to the core network to obtain service data.
[0029] To achieve the above objectives, the present invention also provides an authentication method applied to a core network, the authentication method comprising:
[0030] When receiving a geolocation request sent by the AAA server, the geolocation of the terminal to be confirmed corresponding to the geolocation request is determined according to the positioning technology;
[0031] The request corresponding to the geolocation request is sent to the AAA server.
[0032] To achieve the above objectives, the present invention also provides an authentication device, the authentication device comprising:
[0033] The sending module is used to send a geolocation request to the core network when receiving a secondary authentication request forwarded by the core network;
[0034] The receiving module is used to receive the request feedback corresponding to the geographical location request sent by the core network, and to obtain the geographical location of the terminal to be authenticated based on the request feedback;
[0035] The sending module is used to send a location authentication request containing the geographic location to the location service platform (LSP), wherein the LSP obtains the geographic location according to the location authentication request and determines the location authentication result according to the positional relationship between the geographic location and a preset graphic.
[0036] The determination module is used to receive the location authentication result sent by the LSP and determine the secondary authentication result based on the location authentication result.
[0037] To achieve the above objectives, the present invention also provides an authentication device, the authentication device including a memory, a processor, and an authentication program stored in the memory and executable on the processor, wherein the authentication program, when executed by the processor, implements the various steps of the authentication method as described above.
[0038] To achieve the above objectives, the present invention also provides a computer-readable storage medium storing an authentication program that, when executed by a processor, implements the various steps of the authentication method described above.
[0039] This invention provides an authentication method, apparatus, server, and computer-readable storage medium. When the AAA-server receives a secondary authentication request forwarded by the core network, it sends a geolocation request to the core network, receives the corresponding request feedback from the core network, obtains the geolocation of the terminal to be authenticated based on the request feedback, and sends a location authentication request containing the geolocation to the Location Service Platform (LSP). The LSP obtains the geolocation based on the location authentication request, determines the location authentication result based on the location relationship between the geolocation and a preset location set, receives the location authentication result from the LSP, and determines the secondary authentication result based on the location authentication result. The AAA-server determines the terminal's geolocation through the core network, avoiding the problem of the terminal spoofing its location when performing secondary authentication based on the geolocation sent by the terminal to be authenticated. This improves the security of the secondary authentication result. Attached Figure Description
[0040] Figure 1 This is a schematic diagram of the hardware structure of the authentication device involved in an embodiment of the present invention;
[0041] Figure 2 This is a flowchart illustrating the first embodiment of the authentication method of the present invention;
[0042] Figure 3 This is a schematic diagram illustrating the interaction between the terminal to be authenticated, the core network, and the AAA server in the authentication method of this invention.
[0043] Figure 4 This is a schematic diagram of the modules of the authentication method of the present invention.
[0044] The realization of the objective, functional features and advantages of the present invention will be further explained in conjunction with the embodiments and with reference to the accompanying drawings. Detailed Implementation
[0045] It should be understood that the specific embodiments described herein are merely illustrative of the invention and are not intended to limit the invention.
[0046] The main solution of this invention is:
[0047] When receiving a secondary authentication request forwarded by the core network, a geolocation request is sent to the core network;
[0048] Receive the request feedback corresponding to the geolocation request sent by the core network, and obtain the geolocation of the terminal to be authenticated based on the request feedback;
[0049] A location authentication request containing the geographic location is sent to the location service platform (LSP), wherein the LSP obtains the geographic location based on the location authentication request and determines the location authentication result based on the location relationship between the geographic location and a preset location set;
[0050] Receive the location authentication result sent by LSP, and determine the secondary authentication result based on the location authentication result.
[0051] As one implementation solution, authentication devices can be like Figure 1 As shown.
[0052] The embodiments of the present invention relate to an authentication device, which includes: a processor 101, such as a CPU, a memory 102, and a communication bus 103. The communication bus 103 is used to enable communication between these components.
[0053] Memory 102 can be high-speed RAM or stable memory (non-volatile memory), such as disk storage. Figure 1 As shown, the memory 102, which is a computer-readable storage medium, may include an authentication program; and the processor 101 may be used to invoke the authentication program stored in the memory 102 and perform the following operations:
[0054] When receiving a secondary authentication request forwarded by the core network, a geolocation request is sent to the core network;
[0055] Receive the request feedback corresponding to the geolocation request sent by the core network, and obtain the geolocation of the terminal to be authenticated based on the request feedback;
[0056] A location authentication request containing the geographic location is sent to the location service platform (LSP), wherein the LSP obtains the geographic location based on the location authentication request and determines the location authentication result based on the location relationship between the geographic location and a preset location set;
[0057] Receive the location authentication result sent by LSP, and determine the secondary authentication result based on the location authentication result.
[0058] In one embodiment, processor 101 can be used to invoke an authentication program stored in memory 102 and perform the following operations:
[0059] Determine the first authentication result corresponding to the communication identifier and the device identifier;
[0060] The step of receiving the location authentication result sent by the LSP and determining the secondary authentication result based on the location authentication result includes:
[0061] Receive the location authentication result sent by the LSP, and determine the second authentication result based on the location authentication result;
[0062] The secondary authentication result is determined based on the first authentication result and the second authentication result.
[0063] In one embodiment, processor 101 can be used to invoke an authentication program stored in memory 102 and perform the following operations:
[0064] Upon receiving the updated geographical location of the terminal to be authenticated from the core network, the system resends a location authentication request containing the geographical location to the LSP and receives the authentication result fed back by the LSP based on the authentication request.
[0065] Receive the location authentication result sent by LSP, and update the secondary authentication result based on the location authentication result.
[0066] In one embodiment, processor 101 can be used to invoke an authentication program stored in memory 102 and perform the following operations:
[0067] Receive a connection request for secondary authentication sent by the core network through the Extended Authentication Protocol (EAP) channel, and obtain the device identifier of the terminal to be authenticated carried in the connection request;
[0068] The terminal to be authenticated is identified based on the device identifier and the pre-stored identifier information;
[0069] When the authentication of the terminal to be authenticated is successful, a connection channel is established with the terminal to be authenticated.
[0070] In one embodiment, processor 101 can be used to invoke an authentication program stored in memory 102 and perform the following operations:
[0071] The secondary authentication result is forwarded to the terminal to be authenticated through the core network.
[0072] Based on the hardware architecture of the aforementioned authentication equipment, embodiments of the authentication method of the present invention are proposed.
[0073] Reference Figure 2 , Figure 2 This is a first embodiment of the authentication method of the present invention, the authentication method comprising the following steps:
[0074] Step S10: When receiving a secondary authentication request forwarded by the core network, send a geolocation request to the core network;
[0075] The execution entity in this embodiment is an AAA (Authentication, Authorization, Accounting) server.
[0076] When a terminal to be authenticated sends a data request to the 5G core network, the terminal needs to perform two authentications. The first authentication is the primary authentication, which refers to the authentication process for the terminal to access the core network. The second authentication is performed after the terminal completes the primary authentication. The terminal then accesses its home core network (5G core network) and sends a second authentication request to the core network, which in turn sends the second authentication request to the AAA server. The terminal to be authenticated can be a terminal that implements 5G mobile communication functions, including but not limited to mobile phones, tablets, and IoT terminal devices.
[0077] Two-factor authentication follows the Extensible Authentication Protocol (EAP) framework, with NAS signaling at the underlying level. The terminal to be authenticated acts as the peer, and the AAA acts as the authentication server. During the two-factor authentication process, the SMF extracts the EAP data packets from the terminal to be authenticated from the NAS signaling and forwards them to the AAA server. The AAA server receives the EAP data packets, processes them, encapsulates the results into EAP data packets, and returns them to the SMF. The SMF then forwards these packets to the terminal to be authenticated via NAS signaling.
[0078] In this embodiment, the AAA server determines the geographical location of the terminal to be authenticated through the core network. Specifically, when the AAA server receives a secondary authentication request forwarded by the core network, it sends a geographical location request to the core network. Optionally, the AAA server obtains the geographical location of the terminal to be authenticated from the core network through the MP1 interface. The MP1 interface is a standard API interface defined by ETSI, which enhances basic 5G positioning capabilities to meet the on-demand location service requirements of operators' 5G location service platforms.
[0079] Optionally, after receiving the geolocation request from the AAA server, the core network calculates the distance between different base stations and the terminal to be authenticated by measuring the arrival times of reference signals sent by multiple base stations. It then draws concentric circles with each distance as the radius and estimates the terminal's location using a positioning algorithm (trilateration algorithm, least squares algorithm). When using the 5G core network to locate the terminal to be authenticated, the horizontal positioning accuracy is better than 3 meters (indoor) and 10 meters (outdoor) for 80% of the terminals, and the vertical positioning accuracy is better than 3 meters (indoor and outdoor) for 80% of the terminals. That is, in this embodiment, determining the geolocation of the terminal to be authenticated through core network positioning improves the accuracy of obtaining the terminal's location.
[0080] Step S20: Receive the request feedback corresponding to the geolocation request sent by the core network, and obtain the geolocation of the terminal to be authenticated based on the request feedback;
[0081] After receiving the geolocation request, the core network determines the geolocation of the terminal to be authenticated and sends the corresponding request back to the AAA server.
[0082] Optionally, in this embodiment, in order to ensure the security of the geographical location of the terminal to be authenticated, the core network can encrypt the determined geographical location using a public key and send it to the AAA server. After the AAA server receives the request feedback from the core network, it decrypts the request feedback to obtain the geographical location of the terminal to be authenticated.
[0083] In this embodiment, the request feedback may include information such as the device identifier of the terminal to be authenticated. The AAA server determines the terminal to be authenticated corresponding to the location in the request feedback sent by the core network through the device identifier.
[0084] Step S30: Send a location authentication request containing the geographic location to the location service platform LSP, wherein the LSP obtains the geographic location according to the location authentication request and determines the location authentication result according to the location relationship between the geographic location and a preset location set;
[0085] Step S40: Receive the location authentication result sent by LSP, and determine the secondary authentication result based on the location authentication result.
[0086] After receiving the geographic location of the terminal to be authenticated, the AAA server sends a location authentication request containing the geographic location to the Location-based services platform (LSP).
[0087] Optionally, in this embodiment, the AAA server pre-stores at least one terminal to be authenticated and a preset location set corresponding to the terminal. It is understood that if the current location of the terminal to be authenticated is within the preset location set, the current location of the terminal to be authenticated can be authenticated through secondary authentication, thereby obtaining core network service data. In this application, when sending the geographical location of the terminal to be authenticated to the LSP, the preset location set of the terminal to be authenticated is also sent to the LSP. After receiving the geographical location and the preset location set, the LSP determines the positional relationship between the geographical location and the preset location set to determine the location authentication result.
[0088] Optionally, the authentication result can be determined by checking whether the geographical location is within the preset location set. For example, if the geographical location is within the preset location set, the geographical location authentication result is considered successful; if the geographical location is not within the preset location set, the geographical location authentication result is considered unsuccessful. The location authentication result is then fed back to the AAA server to determine whether secondary authentication has passed based on the location authentication result. Specifically, if the location authentication result is successful, it is determined that the location of the terminal to be authenticated has passed secondary authentication; if the location authentication result is unsuccessful, it is determined that the location of the terminal to be authenticated has failed secondary authentication, and a corresponding prompt message is sent to the terminal to be authenticated.
[0089] In this embodiment, after determining the secondary authentication result, the AAA server forwards the secondary authentication result to the terminal to be authenticated through the core network, so that the terminal to be authenticated can perform the next action based on the secondary authentication result.
[0090] In this embodiment, when the AAA server receives the updated geographical location of the terminal to be authenticated from the core network, it resends a location authentication request containing the geographical location to the LSP, receives the authentication result fed back by the LSP based on the authentication request, receives the location authentication result sent by the LSP, and updates the secondary authentication result according to the location authentication result. This allows for real-time updates of the secondary authentication result of the terminal to be authenticated based on its geographical location, improving the security of core network service data.
[0091] In this embodiment, when the AAA-server receives a secondary authentication request forwarded by the core network, it sends a geolocation request to the core network, receives the request feedback corresponding to the geolocation request sent by the core network, and obtains the geolocation of the terminal to be authenticated based on the request feedback. It then sends a location authentication request containing the geolocation to the Location Service Platform (LSP). The LSP obtains the geolocation based on the location authentication request, determines the location authentication result based on the location relationship between the geolocation and a preset location set, receives the location authentication result sent by the LSP, and determines the secondary authentication result based on the location authentication result. The AAA-server determines the terminal's geolocation through the core network, which avoids the problem of the terminal spoofing its location when performing secondary authentication based on the geolocation sent by the terminal to be authenticated. This improves the security of the secondary authentication result.
[0092] Based on the first embodiment, a second embodiment of the authentication method of this invention is proposed, wherein the method includes the following steps before step S30:
[0093] Step S01: Determine the first authentication result corresponding to the communication identifier and the device identifier;
[0094] The step of receiving the location authentication result sent by the LSP and determining the secondary authentication result based on the location authentication result includes:
[0095] Step S31: Receive the location authentication result sent by LSP, and determine the second authentication result based on the location authentication result;
[0096] Step S32: Determine the secondary authentication result based on the first authentication result and the second authentication result.
[0097] In this embodiment, the communication identifier includes information such as IMEI and IMSI, and the device identifier includes information such as the terminal ID to be authenticated and the password.
[0098] In this embodiment, when the terminal to be authenticated sends a secondary authentication request to the AAA server, it carries communication identifier and device identifier information in the secondary authentication request. The AAA server performs the first authentication on the terminal to be authenticated based on the received communication identifier and device identifier, and obtains the first authentication result.
[0099] Optionally, if the ID and password of the terminal to be authenticated in the device identifier are correct, the terminal to be authenticated is determined to have passed the first authentication; otherwise, the first authentication is not passed.
[0100] After receiving the location authentication result from the LSP, the AAA server determines the secondary authentication result based on the location authentication result and the first authentication result. Optionally, the secondary authentication result is determined to be successful if the terminal to be authenticated simultaneously satisfies both the first authentication result and the location authentication result. In this embodiment, dual verification is performed on the secondary authentication using the first authentication result and the second authentication result, thereby improving the security of the verification.
[0101] Based on the first embodiment, a third embodiment of the authentication method of the present invention is proposed. Based on the first embodiment, the method includes the following steps before step S10:
[0102] Step S02: Receive a connection request for secondary authentication sent by the core network through the Extended Authentication Protocol (EAP) channel, and obtain the device identifier of the terminal to be authenticated carried in the connection request;
[0103] Step S03: Verify the identity of the terminal to be authenticated based on the device identifier and the pre-stored identifier information;
[0104] Step S04: When the authentication of the terminal to be authenticated is successful, a connection channel is established with the terminal to be authenticated.
[0105] This embodiment describes the process of establishing a connection channel between the terminal to be authenticated and the AAA server.
[0106] After successful primary authentication, the terminal to be authenticated establishes a connection with the core network and sends a secondary authentication connection request to the core network. The core network then forwards the secondary authentication connection request to the AAA server via the Extended Authentication Protocol (EAP) channel. The AAA server obtains the terminal identification information carried in the secondary authentication connection request, as well as the shared key in the EAP-AKA authentication protocol. The AAA server verifies whether the local RES(RESponse) derived from the shared key is equal to the received RES(RESponse) to authenticate the terminal to be authenticated. When the terminal to be authenticated successfully completes authentication, a connection channel is established between the terminal to be authenticated and the AAA server, and the terminal to be authenticated sends a secondary authentication request to the AAA server.
[0107] In this embodiment, by verifying the identity of the terminal to be authenticated, the security of data transmission through the connection channel established between the terminal to be authenticated and the AAA server is improved.
[0108] Furthermore, this invention also proposes an authentication method applied to a terminal to be authenticated. The authentication method includes:
[0109] Step S1: After the primary authentication is successful, establish a connection channel with the server.
[0110] Step S2: Send a secondary authentication request to the AAA server through the connection channel. The AAA server performs secondary authentication based on the secondary authentication request and the geographical location of the terminal to be authenticated, and sends the secondary authentication result back to the terminal to be authenticated.
[0111] Step S3: Receive the secondary authentication result from the server. When the secondary authentication result is successful, generate a response identifier.
[0112] Step S4: Send the response identifier to the core network to obtain service data.
[0113] After the primary authentication is successful, the terminal to be authenticated establishes a connection channel with the server and sends a secondary authentication request to the AAA server through the connection channel. The AAA server performs secondary authentication based on the secondary authentication request and the location information of the terminal to be authenticated, and feeds back the secondary authentication result to the terminal to be authenticated. When the secondary authentication result is successful, the terminal generates a response identifier and sends the response identifier to the core network to obtain business data.
[0114] In this embodiment, the geographical location of the terminal to be authenticated is determined by the core network, which avoids the terminal to be authenticated from spoofing its location, improves the security of secondary authentication, and thus ensures the security of business data when the terminal to be authenticated obtains business data from the core network.
[0115] Furthermore, this invention also proposes an authentication method for use in a core network. The authentication method includes:
[0116] Step S100: When receiving a geolocation request sent by the AAA server, determine the geolocation of the terminal to be confirmed corresponding to the geolocation request based on the positioning technology.
[0117] Step S200: Send the request corresponding to the geographic location request to the AAA server.
[0118] After receiving a geolocation request from the AAA server, the core network calculates the distance between the terminal to be authenticated and different base stations by measuring the arrival times of reference signals transmitted by multiple base stations. It then draws concentric circles with each distance as the radius and estimates the terminal's location using positioning algorithms (trilateration and least squares). When using the 5G core network to locate the terminal to be authenticated, the horizontal positioning accuracy is better than 3 meters (indoor) and 10 meters (outdoor) for 80% of UEs, and the vertical positioning accuracy is better than 3 meters (indoor and outdoor) for 80% of UEs. In this embodiment, determining the geolocation of the terminal to be authenticated through core network positioning improves the accuracy of obtaining the terminal's location.
[0119] Reference Figure 3 , Figure 3 This is a schematic diagram illustrating the interaction between the terminal to be certified, the core network, and the AAA server in this application.
[0120] In this embodiment, after the terminal to be authenticated passes the primary authentication, it establishes a communication connection with the core network and sends a secondary authentication connection request to the core network to establish a connection channel with the AAA server. After confirming the establishment of the connection channel, the AAA server receives the data from the terminal to be authenticated. The terminal to be authenticated then sends a secondary authentication request to the core network. The core network forwards the secondary authentication request to the AAA server. After determining that the received request is a secondary authentication request, the AAA server sends a geolocation request to the core network and receives the request feedback corresponding to the geolocation request sent by the core network. Based on the request feedback, it obtains the geolocation of the terminal to be authenticated and sends a location authentication request containing the geolocation to the Location Service Platform (LSP). The LSP obtains the geolocation based on the location authentication request and determines the location authentication result based on the positional relationship between the geolocation and a preset graphic. The LSP receives the location authentication result sent by the LSP and determines the secondary authentication result based on the location authentication result.
[0121] Reference Figure 4 , Figure 4 This is a schematic diagram of the modules in this application. The authentication device includes:
[0122] The first sending module 10 is used to send a geolocation request to the core network when receiving a secondary authentication request forwarded by the core network;
[0123] The receiving module 20 is used to receive the request feedback corresponding to the geographical location request sent by the core network, and to obtain the geographical location of the terminal to be authenticated based on the request feedback;
[0124] The second sending module 30 is used to send a location authentication request containing the geographic location to the location service platform LSP, wherein the LSP obtains the geographic location according to the location authentication request and determines the location authentication result according to the positional relationship between the geographic location and a preset graphic.
[0125] The determination module 40 is used to receive the location authentication result sent by the LSP and determine the secondary authentication result based on the location authentication result.
[0126] In one embodiment, before receiving the location authentication result sent by the LSP and determining the secondary authentication result based on the location authentication result, the determining module 40 is specifically used for:
[0127] Determine the first authentication result corresponding to the communication identifier and the device identifier;
[0128] The step of receiving the location authentication result sent by the LSP and determining the secondary authentication result based on the location authentication result includes:
[0129] Receive the location authentication result sent by the LSP, and determine the second authentication result based on the location authentication result;
[0130] The secondary authentication result is determined based on the first authentication result and the second authentication result.
[0131] In one embodiment, after receiving the location authentication result sent by the LSP and determining the secondary authentication result based on the location authentication result, the determining module 40 is specifically used for:
[0132] Upon receiving the updated geographical location of the terminal to be authenticated from the core network, the system resends a location authentication request containing the geographical location to the LSP and receives the authentication result fed back by the LSP based on the authentication request.
[0133] Receive the location authentication result sent by LSP, and update the secondary authentication result based on the location authentication result.
[0134] In one embodiment, before sending a geolocation request to the core network upon receiving a secondary authentication request forwarded by the core network, the first sending module 10 is specifically used for:
[0135] Receive a connection request for secondary authentication sent by the core network through the Extended Authentication Protocol (EAP) channel, and obtain the device identifier of the terminal to be authenticated carried in the connection request;
[0136] The terminal to be authenticated is identified based on the device identifier and the pre-stored identifier information;
[0137] When the authentication of the terminal to be authenticated is successful, a connection channel is established with the terminal to be authenticated.
[0138] In one embodiment, after receiving the location authentication result sent by the LSP and determining the secondary authentication result based on the location authentication result, the determining module 40 is specifically used for:
[0139] The secondary authentication result is forwarded to the terminal to be authenticated through the core network.
[0140] The present invention also provides an authentication device, the authentication device including a memory, a processor, and an authentication program stored in the memory and executable on the processor, wherein the authentication program, when executed by the processor, implements the various steps of the authentication method as described in the above embodiments.
[0141] The present invention also provides a computer-readable storage medium storing an authentication program, which, when executed by a processor, implements the various steps of the authentication method described in the above embodiments.
[0142] The sequence numbers of the above embodiments of the present invention are for descriptive purposes only and do not represent the superiority or inferiority of the embodiments.
[0143] It should be noted that, in this document, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, system, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, system, article, or apparatus. Unless otherwise specified, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, system, article, or apparatus that includes that element.
[0144] Through the above description of the embodiments, those skilled in the art can clearly understand that the systems described in the above embodiments can be implemented using software plus necessary general-purpose hardware platforms. Of course, they can also be implemented using hardware, but in many cases, the former is a better implementation method. Based on this understanding, the technical solution of the present invention, or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product is stored in a computer-readable storage medium (such as ROM / RAM, magnetic disk, optical disk) as described above, and includes several instructions to cause a terminal device (which may be a mobile phone, computer, parking management device, air conditioner, or network device, etc.) to execute the systems described in the various embodiments of the present invention.
[0145] The above are merely preferred embodiments of the present invention and do not limit the scope of the patent. Any equivalent structural or procedural transformations made based on the description and drawings of the present invention, or direct or indirect applications in other related technical fields, are similarly included within the scope of patent protection of the present invention.
Claims
1. An authentication method, characterized in that, The authentication method, applied to an AAA server, includes: When receiving a secondary authentication request forwarded by the core network, a geolocation request is sent to the core network so that the core network can determine the geolocation of the terminal to be authenticated corresponding to the geolocation request based on positioning technology. Receive the request feedback corresponding to the geographical location request sent by the core network, and obtain the geographical location of the terminal to be authenticated based on the request feedback; A location authentication request containing the geographic location is sent to the location service platform (LSP), wherein the LSP obtains the geographic location based on the location authentication request and determines the location authentication result based on the location relationship between the geographic location and a preset location set; Receive the location authentication result sent by LSP, and determine the secondary authentication result based on the location authentication result.
2. The authentication method as described in claim 1, characterized in that, Before the step of receiving the location authentication result sent by the LSP and determining the secondary authentication result based on the location authentication result, the method further includes: Determine the first authentication result corresponding to the communication identifier and the device identifier; The step of receiving the location authentication result sent by the LSP and determining the secondary authentication result based on the location authentication result includes: Receive the location authentication result sent by the LSP, and determine the second authentication result based on the location authentication result; The secondary authentication result is determined based on the first authentication result and the second authentication result.
3. The authentication method as described in claim 1, characterized in that, After the step of receiving the location authentication result sent by the LSP and determining the secondary authentication result based on the location authentication result, the following steps are included: Upon receiving the updated geographical location of the terminal to be authenticated from the core network, the system resends a location authentication request containing the geographical location to the LSP and receives the authentication result fed back by the LSP based on the authentication request. Receive the location authentication result sent by LSP, and update the secondary authentication result based on the location authentication result.
4. The authentication method as described in claim 1, characterized in that, Before the step of sending a geolocation request to the core network when receiving a secondary authentication request forwarded by the core network, the following steps are included: Receive a connection request for secondary authentication sent by the core network through the Extended Authentication Protocol (EAP) channel, and obtain the device identifier of the terminal to be authenticated carried in the connection request; The terminal to be authenticated is identified based on the device identifier and the pre-stored identifier information; When the authentication of the terminal to be authenticated is successful, a connection channel is established with the terminal to be authenticated.
5. The authentication method as described in claim 1, characterized in that, After the step of receiving the location authentication result sent by the LSP and determining the secondary authentication result based on the location authentication result, the following steps are included: The secondary authentication result is forwarded to the terminal to be authenticated through the core network.
6. An authentication method, characterized in that, The authentication method, applied to the terminal to be authenticated, includes: After the primary authentication is successful, a connection channel with the server is established; A secondary authentication request is sent to the AAA server through the connection channel. The AAA server receives a request feedback corresponding to a geolocation request sent by the core network, obtains the geolocation of the terminal to be authenticated based on the request feedback, and sends a location authentication request containing the geolocation to the Location Service Platform (LSP). The LSP obtains the geolocation based on the location authentication request and determines the location authentication result based on the location relationship between the geolocation and a preset location set. The AAA server receives the location authentication result sent by the LSP, determines the secondary authentication result based on the location authentication result, and sends the secondary authentication result back to the terminal to be authenticated. When the core network receives the geolocation request sent by the AAA server, it determines the geolocation of the terminal to be authenticated corresponding to the geolocation request based on positioning technology. Receive the secondary authentication result from the AAA server, and generate a response identifier when the secondary authentication result is successful; Send the response identifier to the core network to obtain service data.
7. An authentication method, characterized in that, The authentication method, applied to the core network, includes: When receiving a geolocation request sent by the AAA server, the geolocation of the terminal to be authenticated corresponding to the geolocation request is determined according to the positioning technology; Send the request corresponding to the geolocation request to the AAA server; The AAA server receives the request feedback corresponding to the geographic location request sent by the core network, obtains the geographic location of the terminal to be authenticated based on the request feedback, and sends a location authentication request containing the geographic location to the Location Service Platform (LSP). The LSP obtains the geographic location based on the location authentication request and determines the location authentication result based on the location relationship between the geographic location and a preset location set. The AAA server receives the location authentication result sent by the LSP and determines the secondary authentication result based on the location authentication result.
8. An authentication device, characterized in that, The authentication device includes: The first sending module is used to send a geolocation request to the core network when receiving a secondary authentication request forwarded by the core network, so that the core network can determine the geolocation of the terminal to be authenticated corresponding to the geolocation request based on the positioning technology when receiving the geolocation request; The receiving module is used to receive the request feedback corresponding to the geographical location request sent by the core network, and to obtain the geographical location of the terminal to be authenticated based on the request feedback; The second sending module is used to send a location authentication request containing the geographic location to the location service platform LSP, wherein the LSP obtains the geographic location according to the location authentication request and determines the location authentication result according to the positional relationship between the geographic location and a preset graphic. The determination module is used to receive the location authentication result sent by the LSP and determine the secondary authentication result based on the location authentication result.
9. A server, characterized in that, The server includes a memory, a processor, and an authentication program stored in the memory and executable on the processor, wherein the authentication program, when executed by the processor, implements the steps of the authentication method as described in any one of claims 1-5.
10. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores an authentication program that, when executed by a processor, implements the steps of the authentication method as described in any one of claims 1-5.
Citation Information
Patent Citations
Session processing method and device
CN110199513A
User authentication method, core network side equipment and computer readable storage medium
CN113079505A