User identity authentication system, method, device, network equipment and storage medium
By forwarding service requests to the target network in the 6G network and using the network registry center for cross-network authentication, the problem of identity verification for user terminals when accessing functional networks is solved, and secure and efficient identity verification between different networks is achieved.
Patent Information
- Application Number
- CN202311080918.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-08-25
- Publication Date
- 2026-01-13
- Estimated Expiration
- 2043-08-25
AI Technical Summary
In 6G networks, how to verify the identity of user terminals when accessing functional networks has become an urgent problem to be solved, especially when the network is deployed in a layered and distributed manner and provides multiple services. When the services that the visited network cannot provide need to be provided by other networks, how to ensure the identity verification of user terminals is a key issue.
When the visited network is unable to provide services, the service request is forwarded to the target network. The target network interacts with the user terminal to obtain the terminal's digital certificate and performs identity verification based on the certificate. The network registry center stores information about each network and terminal to achieve cross-network identity verification.
Before providing services across different networks, user terminal identity verification is implemented to ensure the security and legitimacy of the service, and to improve the efficiency and accuracy of identity verification.
Smart Images

Figure CN117135635B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of communication technology, and in particular to a user authentication system, method, apparatus, network device, and storage medium. Background Technology
[0002] In communication systems, when a user terminal accesses a visited network that is not part of its home network, the visited network needs to authenticate the user terminal. In current 5G (5th Generation Mobile Communication Technology) networks, the visited network and the home network work together to complete mutual authentication with the terminal, and the network does not perform further identity verification on the terminal in subsequent service provision.
[0003] However, in future 6G (6th generation mobile networks) networks, the network will exhibit a trend towards layered and distributed deployment. In addition to providing traditional connectivity services, the network will also offer data services, intelligent services, and sensing services. Furthermore, the specific network providing these services (referred to here as the functional network) may not be the user's visited or home network. In this case, the functional network providing the service needs to further verify the user terminal's identity. Therefore, how to verify the user terminal's identity when it accesses the functional network has become an urgent problem to be solved. Summary of the Invention
[0004] Therefore, it is necessary to provide a user authentication system, method, apparatus, network device, and storage medium to address the aforementioned technical problems.
[0005] In a first aspect, this application provides a user authentication system. The system includes at least one network, which comprises a distributed network and a functional network, wherein the distributed network includes a visitor network, wherein...
[0006] The visited network is used to receive service requests sent by user terminals, and if the visited network cannot provide the target service corresponding to the service request, it forwards the service request to the target network corresponding to the target service.
[0007] The target network is used to send a verification request to the user terminal according to the service request;
[0008] The target network is further configured to receive the terminal digital certificate sent by the user terminal in response to the verification request, verify the terminal digital certificate, and provide the target service to the user terminal if the terminal digital certificate verification is successful.
[0009] In one embodiment, the system further includes a network registration center, and the distributed network further includes a home network; the home network is the network used when the user terminal opens an account, and the network registration center is used to store network information of each of the distributed networks, network information of each of the functional networks, and terminal information of each of the user terminals.
[0010] In one embodiment, the visited network is further configured to send a target network query request to the network registry based on the target service;
[0011] The network registry is also used to return the target network to the visited network in response to the target network query request.
[0012] In one embodiment, the target network is further configured to send a first home network information query request to the network registration center based on the service request;
[0013] The network registration center is also used to respond to the first home network information query request, determine the target home network corresponding to the user terminal, and return the home network digital certificate of the target home network to the target home network;
[0014] The target network is also used to verify the terminal digital certificate based on the home network digital certificate.
[0015] In one embodiment, the visited network is further configured to receive a registration request sent by the user terminal, and based on the registration request, forward the registration request to the target home network corresponding to the user terminal;
[0016] The target home network is also used to authenticate the user terminal based on the registration request, and send the terminal digital certificate to the user terminal if the user terminal is successfully authenticated.
[0017] In one embodiment, the target home network is further configured to receive a temporary public key generated by the user terminal, encrypt the terminal digital certificate based on the temporary public key, and send the encrypted terminal digital certificate to the user terminal.
[0018] In one embodiment, the registration request is generated based on the temporary public key.
[0019] In one embodiment, the visited network is further configured to send a second home network information query request to the network registry center based on the registration request;
[0020] The network registration center is also configured to, in response to the second home network information query request, determine the target home network corresponding to the user terminal, and return the target home network to the visited network.
[0021] In one embodiment, the target home network is further configured to send a temporary identity identifier to the user terminal if the user terminal is successfully authenticated.
[0022] The target home network is also used to generate a user information update request based on the temporary identity identifier, and send the user information update request to the network registration center;
[0023] The network registration center is also used to update the terminal information of the user terminal in response to the user information update request.
[0024] In one embodiment, the home network is further configured to receive user terminal account opening information from the account opening system when the user terminal opens an account, and in response to the user terminal account opening information, send the terminal information of the user terminal to the network registration center.
[0025] The network registration center is used to store the terminal information of the user terminal and record the correspondence between the user terminal and the home network;
[0026] The network registration center is also used to send registration response information to the home network, the registration response information being used to indicate that the user terminal has successfully opened an account.
[0027] In one embodiment, the user terminal is further configured to send a digital certificate update request to the visited network;
[0028] The visited network is also used to forward the digital certificate update request to the target home network corresponding to the user terminal;
[0029] The target home network is also used to authenticate the user terminal based on the digital certificate update request, and send the updated terminal digital certificate to the user terminal if the user terminal is successfully authenticated.
[0030] Secondly, this application provides a user authentication method, the method comprising:
[0031] The system receives service requests sent by the visited network, which are forwarded to the network when the visited network receives the service request sent by the user terminal and is unable to provide the target service corresponding to the service request.
[0032] Based on the service request, a verification request is sent to the user terminal;
[0033] The system receives the terminal digital certificate sent by the user terminal in response to the verification request, verifies the terminal digital certificate, and provides the target service to the user terminal if the terminal digital certificate verification is successful.
[0034] Thirdly, this application provides a user authentication device, the device comprising:
[0035] The first receiving module is used to receive a service request sent by the visited network. The service request is forwarded to the network when the visited network receives the service request sent by the user terminal and is unable to provide the target service corresponding to the service request.
[0036] The sending module is used to send a verification request to the user terminal according to the service request;
[0037] The second receiving module is configured to receive the terminal digital certificate sent by the user terminal in response to the verification request, verify the terminal digital certificate, and provide the target service to the user terminal if the terminal digital certificate verification is successful.
[0038] Fourthly, this application provides a network device, including a transmitter, a processor, and a receiver;
[0039] The receiver is used to receive service requests sent by the visited network. The service request is forwarded to the network when the visited network receives the service request sent by the user terminal and is unable to provide the target service corresponding to the service request.
[0040] The transmitter is used to send a verification request to the user terminal according to the service request;
[0041] The receiver is also configured to receive the terminal digital certificate sent by the user terminal in response to the verification request;
[0042] The processor is used to verify the terminal digital certificate and, if the terminal digital certificate is verified, to provide the target service to the user terminal.
[0043] Fifthly, this application provides a computer-readable storage medium. The computer-readable storage medium stores a computer program thereon, which, when executed by a processor, implements any of the methods described above.
[0044] Sixthly, this application also provides a computer program product. The computer program product includes a computer program that, when executed by a processor, implements any of the methods described above.
[0045] The aforementioned user authentication system, method, apparatus, network device, and storage medium, when the visited network cannot provide the service required by the user terminal, forward the user terminal's service request to the corresponding functional network or distributed network. The functional network or distributed network then interacts with the user terminal to obtain the user terminal's digital certificate, and verifies the user terminal's identity based on the terminal digital certificate. If the verification is successful, the system provides the user terminal with the required service. This application embodiment establishes a system for authenticating a user terminal when the network providing the target service and the visited network are not the same network, allowing the network to verify the user terminal's identity before providing the service. Attached Figure Description
[0046] Figure 1 This is a schematic diagram of a user authentication system in one embodiment;
[0047] Figure 2 This is a schematic diagram of a user terminal requesting a target service in one embodiment;
[0048] Figure 3 This is a schematic diagram of a user authentication system in one embodiment;
[0049] Figure 4 This is a flowchart illustrating the process of querying the target's network in one embodiment;
[0050] Figure 5 This is a schematic diagram of the user terminal authentication process in one embodiment;
[0051] Figure 6 This is a schematic diagram of the process of a user terminal transmitting a temporary public key in one embodiment;
[0052] Figure 7 This is a schematic diagram of the process of updating terminal information by the target home network in one embodiment;
[0053] Figure 8 This is a schematic diagram of the user terminal account opening process in one embodiment;
[0054] Figure 9 This is a schematic diagram of the process for updating a terminal digital certificate in one embodiment;
[0055] Figure 10 This is a flowchart illustrating a user authentication method in one embodiment;
[0056] Figure 11This is a structural block diagram of a user authentication device in one embodiment;
[0057] Figure 12 This is a diagram of the internal structure of a network device in one embodiment. Detailed Implementation
[0058] To make the objectives, technical solutions, and advantages of this application clearer, the following detailed description is provided in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative and not intended to limit the scope of this application.
[0059] In one embodiment, such as Figure 1 As shown, a user authentication system is provided. The system includes at least one network 10, which includes a distributed network 100 and a functional network 200. The distributed network 100 includes a visited network 110. The visited network 110 receives service requests sent by user terminals and, if the visited network 110 cannot provide the target service corresponding to the service request, forwards the service request to the target network 10 corresponding to the target service. The target network 10 sends an authentication request to the user terminal according to the service request. The target network 10 also receives the terminal digital certificate sent by the user terminal in response to the authentication request, verifies the terminal digital certificate, and provides the target service to the user terminal if the terminal digital certificate verification is successful.
[0060] In this embodiment, the 6G network architecture includes multiple networks 10. Each network 10 may include a distributed network 100 (e.g., a sinking edge network, a dedicated network, etc.) for user access to the 6G network, and functional networks 200 (e.g., a connectivity communication network, a holographic communication network, a sensing service private network, an intelligent service network, etc.) for providing users with the services they require. Each distributed network 100 and functional network 200 may belong to different operators, and one functional network 200 may simultaneously provide services to the distributed networks 100 of multiple operators.
[0061] Visited network 110 is the network 10 currently accessed by the user. It can be the same as the user terminal's home network. When a user terminal accesses visited network 110, which is not its home network, visited network 110 can interact with the user terminal's home network to verify the user terminal's identity. Afterward, visited network 110 does not need to authenticate the user terminal again when providing services. However, if the user terminal needs to access other networks 10 through visited network 110, those other networks 10 will need to re-authenticate the user terminal.
[0062] like Figure 2As shown, when a user terminal needs a specific service from the visited network 110, it can send a service request to the visited network 110. Upon receiving the service request, if the visited network 110 can provide the target service (for example, if the visited network 110 is a private communication network within an enterprise, and the user terminal needs to communicate with another user terminal within the private network), it can directly provide the target service to the user terminal. If the visited network 110 cannot provide the target service (for example, if the user terminal needs to communicate with another user terminal outside the private network, or if the user terminal needs value-added services such as sensing services), the visited network 110 can forward the user terminal's service request to a target network 10 (which could be another distributed network 100 or a functional network 200) that can provide the target service.
[0063] The visiting network 110 can determine the target network 10 in several ways. For example, the visiting network 110 can record information about all networks 10 that provide services to it, and then select the network that can provide the target service from all networks 10 as the target network 10 based on the target service. Alternatively, the visiting network 110 can also search for the corresponding target network 10 on the network based on the target service: for example, a network relay node can be set up to record information about each network 10. The visiting network 110 sends a functional network query request to this network relay node based on the target service, and the network relay node returns the target network 10 to it. In this case, the visiting network 110 can also store the correspondence between the target service and the target network 10 after each time the target network 10 is found, so that when other user terminals also need the visiting network 110 to provide the same target service, the visiting network 110 can directly determine that the target network 10 can provide the target service without having to query the network relay node again, which can improve the efficiency of returning the target network 10.
[0064] After receiving a service request, the target network 10 needs to send an authentication request to the user terminal to re-verify the user terminal's identity. The target network 10 can forward the authentication request to the user terminal through the visited network 110, or the visited network 110 can establish a signaling transparent transmission channel, data transmission channel, or service transmission channel between the user terminal and the target network 10 to enable communication between them. Upon receiving the authentication request, the user terminal sends its own terminal digital certificate to the target network 10. The target network 10 can authenticate the user terminal based on the terminal digital certificate (the authentication process can refer to existing industry processes for authentication based on digital certificates, which will not be elaborated here). If the authentication fails, the target network 10 can refuse to provide the target service to the user terminal; if the authentication succeeds, the target network 10 can provide the target service to the user terminal. For example, if the target service is a sensing service, the target function network can collect the sensing data required by the user terminal and return the sensing data to the user terminal through the data transmission channel established by the visited network 110.
[0065] The user authentication system provided in this application provides a method for authenticating a user terminal when the visited network cannot provide the service required by the user terminal. The visited network forwards the user terminal's service request to the corresponding functional network or distributed network. The functional network or distributed network then interacts with the user terminal to obtain the user terminal's digital certificate and verifies the user terminal's identity based on the digital certificate. If the verification is successful, the system provides the user terminal with the required service. This application establishes a system for authenticating a user terminal when the network providing the target service and the visited network are not the same network, allowing the network to verify the user terminal's identity before providing the service.
[0066] In one embodiment, refer to Figure 3 As shown, the system also includes a network registration center 400, and the distributed network 100 includes a home network 120. The home network 120 is the network used when a user terminal opens an account, and the network registration center 400 is used to store network information of each network 10 and terminal information of each user terminal.
[0067] In this embodiment, the 6G network also includes a home network 120 used when a user terminal opens an account, and a network registration center 400 for storing information about each distributed network 100, functional network 200, and user terminal. The network registration center 400 can be a centralized network registration center, or it can be a network registration center composed of multiple distributed nodes, or it can be a network registration center implemented using blockchain technology and composed of multiple distributed blockchain nodes. This embodiment does not specifically limit this. The network information stored in the network registration center 400 may include service information of each network 10 (e.g., network identifier, access method, network location information, network coverage, network operator, etc.) and identity information of each network 10 (e.g., network identifier, network public key, etc.); the stored terminal information may include the terminal's identity identifier (an identity identifier generated by the home network 120), temporary identity identifier (an identity identifier generated by the visited network 110), user public key, etc.
[0068] Within each distributed network 100 and functional network 200, an NF (Network Function) service management element can be configured to manage network information for that network. This NF service management element can manage network function registration within its network and communicate with the network registration center 400 to update network information and query functional networks. The NF service management element can also communicate with other networks. For example, the NF service management element of visited network 110 can establish a data transmission channel between visited network 110 and target network 10, enabling user terminals to communicate with target network 10 through visited network 110.
[0069] The user authentication system provided in this application embodiment sets up a network registration center to manage network information of each network and terminal information of each terminal, which facilitates the management of each network under the 6G architecture where different networks are independent of each other.
[0070] In one embodiment, the visiting network 110 is further configured to send a target network query request to the network registry 400 based on the target service. The network registry 400 is further configured to return the target network 10 to the visiting network 110 in response to the target network query request.
[0071] In this embodiment, the visited network 110 can obtain a target network 10 that can provide the target service by sending a target network query request to the network registration center 400. The visited network 110 can generate a target network query request based on the target service; after receiving the target network query request, the network registration center 400 matches the network 10 that can provide the target service based on the network information of each functional network 200 stored in the database, and selects a target network 10 to return to the visited network 110. For example, the network 10 that is currently closest to the user terminal can be selected as the target network 10, or the network 10 whose operator is the same as the operator corresponding to the user terminal can be selected as the target network 10. This embodiment does not specifically limit this.
[0072] The user authentication system provided in this application embodiment enables the visited network to obtain the target network that can provide the target service by sending a target network query request to the network registry center, and can obtain the target network even when the visited network does not cache the information of each network.
[0073] In one embodiment, the target network 10 is further configured to send a first home network information query request to the network registration center 400 based on a service request. The network registration center 400 is further configured to, in response to the first home network information query request, determine the target home network 120 corresponding to the user terminal and return the home network digital certificate of the target home network to the target functional network. The target network 10 is further configured to verify the terminal digital certificate based on the home network digital certificate.
[0074] In the embodiments of this application, such as Figure 4 As shown, the target network 10 can verify the user terminal's digital certificate based on the home network digital certificate of the target home network 120 to which the user terminal belongs. The target network 10 can send a first home network information query request to the network registration center 400 based on information in the service request that indicates the user terminal's identity (e.g., the service request can carry the user terminal's identity identifier or temporary identity identifier). The network registration center 400 can store the correspondence between each terminal and each home network. It can find the target home network 120 corresponding to the user terminal based on the user terminal's identity identifier, obtain the home network digital certificate corresponding to the target home network 120, and send the home network digital certificate to the target network 10. The target network 10 can then verify the authenticity of the terminal digital certificate based on the home network digital certificate to determine whether the terminal digital certificate has passed verification.
[0075] The user authentication system provided in this application embodiment enables the target functional network to request a home network digital certificate from the network registration center based on a service request, and to verify the terminal digital certificate through the home network digital certificate, thereby enabling the target functional network to verify the identity of the user terminal through the home network digital certificate.
[0076] In one embodiment, the visited network 110 is further configured to receive a registration request sent by a user terminal, and based on the registration request, forward the registration request to the target home network 120 corresponding to the user terminal. The target home network 120 is further configured to authenticate the user terminal based on the registration request, and if the user terminal is successfully authenticated, send a terminal digital certificate to the user terminal.
[0077] In this embodiment, when a user terminal initially accesses a 6G network, it needs to obtain a terminal digital certificate from its corresponding target home network 120. Since the network the user terminal initially accesses (visited network 110) may not be the target home network 120, the visited network 110 can forward the registration request sent by the user terminal to the target home network 120, causing the target home network 120 to generate a terminal digital certificate for the user terminal. The visited network 110 can obtain the target home network 120 corresponding to the user terminal locally (for example, if the user terminal is a telephone, it can be determined based on the number segment of the user terminal's phone number), or it can obtain the target home network 120 by interacting with the network registration center 400.
[0078] After receiving a registration request forwarded by the visited network 110, the target home network 120 can authenticate the user terminal based on the registration request. Upon successful authentication, the target home network 120 sends the generated terminal digital certificate to the user terminal. In addition, the target home network 120 can also generate a temporary identity for the user terminal to use on the visited network 110, and send the temporary identity to the user terminal through the same process. Figure 4 As shown.
[0079] The authentication process can refer to the two-way authentication and authorization process in 5G networks, such as 5G-AKA (5G Authentication and Key Agreement) or EAP-AKA (Extensible Authentication Protocol Authentication and Key Agreement). Figure 5The diagram illustrates the 5G-AKA authentication process for user terminals: The user terminal's registration request is first sent to the Security Anchor Function (SEAF) network element in the visited network 110. The registration request carries the user terminal's SUPI (SUbscription Permanent Identifier), SUCI (SUbscription Concealed Identifier, i.e., an identifier obtained by encrypting the permanent identifier), or 5G-GUTI (5G Globally Unique Temporary Identifier). The SEAF network element generates an authentication request based on the registration request and sends it to the Authentication Server Function (AUSF) network element in the target home network 120. The authentication service function (AUSF) network element forwards the authentication request to the Unified Data Management (UDM) network element / Authentication Credential Repository and Processing Function (ARPF) network element. The UDM / ARPF network element decrypts the SUCI into a SUPI (if the user terminal sent a SUCI), selects the authentication mode, and generates the Home Authentication Vector (5G HE AV, including the expected user response HRES*) and the terminal's digital certificate. The UDM network element then sends the authentication vector and the terminal's digital certificate back to the Authentication Service Function (AUSF) network element. The authentication service function (AUSF) network element stores HRES*, calculates the hash of the expected user response HXRES*, replaces HRES* in 5G HE AV with HXRES* to obtain the network element authentication vector 5G SE AV, and sends 5G SE AV to the security anchor function (SEAF) network element in the visited network 110. The security anchor function (SEAF) network element generates an authentication request based on 5G SE AV and sends it to the user terminal. The user terminal calculates the user response (RES*) and generates an authentication response based on RES* and returns it to the security anchor function (SEAF) network element.The Security Anchor Function (SEAF) network element calculates the hash of the user response HRES* based on RES*, compares HRES* with HXRES*, and if they are the same, the user terminal successfully authenticates on the visited network (110). The SEAF network element then sends RES* to the Authentication Service Function (AUSF) network element, which compares RES* with XRES*. If they are the same, the user terminal successfully authenticates on the home network (120). The AUSF network element then sends the stored terminal digital certificate back to the user terminal via the SEAF network element.
[0080] The user authentication system provided in this application embodiment enables a user terminal to initiate a registration request to the visited network, which then forwards the registration request to the target home network. The target home network authenticates the registration request and, if authentication is successful, generates a terminal digital certificate and sends it to the user terminal. This allows for the generation of a terminal digital certificate for the user terminal when it first accesses a 6G network.
[0081] In one embodiment, the target home network 120 is further configured to receive a temporary public key generated by the user terminal, encrypt the terminal digital certificate based on the temporary public key, and send the encrypted terminal digital certificate to the user terminal.
[0082] In the embodiments of this application, reference is made to Figure 6 As shown, to ensure transmission security, the user terminal can also generate a temporary public key and a temporary private key, and send the temporary public key to the target home network 120 (which can be sent to the target home network 120 via the visited network 110). This allows the target home network 120 to encrypt the generated terminal digital certificate. Then, if the user terminal is successfully authenticated, the encrypted terminal digital certificate is sent to the user terminal. The user terminal can then use the temporary private key to decrypt the encrypted terminal digital certificate and store the decrypted terminal digital certificate in the user terminal.
[0083] The user authentication system provided in this application embodiment enables the user terminal to generate a temporary public key and a temporary private key pair, and send the temporary public key to the target home network. This allows the target home network to use the temporary public key to encrypt the terminal's digital certificate, thereby improving the security of transmitting the terminal's digital certificate.
[0084] In one embodiment, the registration request is generated based on the temporary public key.
[0085] In this embodiment, the user terminal can generate a temporary public key and a temporary private key when generating a registration request, and send the temporary public key along with the registration request to the visited network 110. The visited network 110 forwards the registration request carrying the temporary public key to the target home network 120, which then receives the temporary public key and encrypts the terminal's digital certificate based on it.
[0086] The user authentication system provided in this application embodiment enables the user terminal to carry a temporary public key in the registration request, so that the user terminal does not need to send the temporary public key to the target home network separately, thereby reducing the number of interactions between the user terminal and the target home network and improving the efficiency of the user terminal in obtaining the terminal digital certificate.
[0087] In one embodiment, the visited network 110 is further configured to send a second home network information query request to the network registration center 400 based on the registration request. The network registration center 400 is further configured to, in response to the second home network information query request, determine the target home network 120 corresponding to the user terminal and return the target home network 120 to the visited network 110.
[0088] In this embodiment, when the visited network 110 cannot obtain the target home network 120 of the user terminal locally, it can generate a second home network information query request using the identity identifier carried in the registration request and send the second home network information query request to the network registration center 400. After receiving the second home network information query request, the network registration center 400 queries the home network that corresponds to the identity identifier of the user terminal, and returns the home network as the target home network 120 to the visited network 110. The visited network 110 can then forward the registration request to the target home network 120 to complete the authentication of the user terminal.
[0089] The user authentication system provided in this application embodiment enables the visiting network to request the target home network from the network registry center based on the registration request. This allows the visiting network to obtain the target home network through the network registry center when it cannot determine the target home network corresponding to the user terminal locally.
[0090] In one embodiment, the target home network 120 is further configured to send a temporary identity identifier to the user terminal upon successful authentication. The target home network 120 is also configured to generate a user information update request based on the temporary identity identifier and send the user information update request to the network registration center 400. The network registration center 400 is further configured to update the terminal information of the user terminal in response to the user information update request.
[0091] In this embodiment, to ensure that the user terminal's true identity identifier (SUPI) is not leaked, the target home network 120 can generate a temporary identity identifier for the user terminal to use in the visited network 110. After generating the temporary identity identifier and sending it to the user terminal, the target home network 120 also needs to update the user terminal's terminal information stored in the network registration center 400 based on the temporary identity identifier, so that the network registration center 400 can subsequently determine the user terminal's identity and obtain the target home network 120 corresponding to the user terminal based on the user terminal's temporary identity identifier.
[0092] Reference Figure 7 As shown, the target home network 120 can send a temporary identity to the user terminal, generate a user information update request based on the temporary identity, and send the user information update request to the network registration center 400. The network registration center 400 obtains the temporary identity of the user terminal based on the user information update request, and updates the terminal information stored in the network registration center 400 when the user terminal opened the account based on the temporary identity.
[0093] The user authentication system provided in this application embodiment enables the target home network to generate a temporary identity identifier for the user terminal and update the terminal information stored in the network registration center based on the temporary identity identifier. This allows the network registration center to obtain the temporary identity identifier and subsequently identify the user terminal based on the temporary identity identifier.
[0094] In one embodiment, the home network 120 is further configured to receive user terminal account opening information from the account opening system when a user terminal opens an account, and in response to the user terminal account opening information, send the user terminal's terminal information to the network registration center 400. The network registration center is configured to store the user terminal's terminal information and record the correspondence between the user terminal and the home network 120. The network registration center 400 is further configured to send registration response information to the home network 300, the registration response information indicating that the user terminal account opening was successful.
[0095] In the embodiments of this application, reference is made to Figure 8As shown, when a user terminal opens an account through the account opening system, the system determines the home network 120 corresponding to the user terminal and generates user terminal account opening information, which is then sent to the home network 120. The user terminal account opening information may include the user terminal's identity identifier and information such as the services authorized for use by the user terminal. The home network 120 can generate terminal information (e.g., the user terminal's identity identifier) based on the user terminal account opening information and send the terminal information to the network registration center 400. The network registration center 400 can determine the sender of the terminal information, designate the sender as the home network 120 corresponding to the user terminal, and record the correspondence between the user terminal and the home network 120. Alternatively, the home network 120 can also send its own network identifier (or the address of the NF service management function network element of the home network 120) along with the terminal information to the network registration center 400, which then records the correspondence between the user terminal's identity identifier and the home network 120.
[0096] After completing the above steps, the network registration center 400 replies with a registration response to the home network 120, indicating that the user terminal has successfully opened an account. The home network 120 can also send its own home network digital certificate to the account opening system, which then sends the home network 120's home network digital certificate to the user terminal for storage. This allows the user terminal to subsequently verify the identity of the home network 120 based on the home network 120's home network digital certificate.
[0097] The user authentication system provided in this application embodiment enables the user terminal's home network to send the terminal information to the network registration center when the user terminal opens an account. This allows the network registration center to record the correspondence between the home network and the user terminal. Subsequently, the network registration center can return the home network corresponding to the user terminal to other networks based on the correspondence it stores.
[0098] In one embodiment, the user terminal is further configured to send a digital certificate update request to the visited network 110. The visited network 110 is further configured to forward the digital certificate update request to the target home network 120 corresponding to the user terminal. The target home network 120 is further configured to authenticate the user terminal based on the digital certificate update request, and if the user terminal is successfully authenticated, send the updated terminal digital certificate to the user terminal.
[0099] In the embodiments of this application, see Figure 9As shown, when a terminal digital certificate expires, the user terminal needs to obtain a new terminal digital certificate by sending a terminal digital certificate update request to the visited network 110. The digital certificate update request may include the user terminal's identity identifier or temporary identity identifier. The visited network 110 forwards the digital certificate update request to the target home network 120 corresponding to the user terminal (the visited network 110 can obtain the target home network 120 locally, or it can obtain the target home network 120 by initiating a query request to the network registration center 400; see the relevant description in the foregoing embodiments for details, and this application embodiment does not specifically limit this). The target home network 120 authenticates the user terminal based on the digital certificate update request (refer to the foregoing embodiments, authentication can be performed based on 5G-AKA or EAP-AKA'), generates an updated terminal digital certificate for the user terminal, and sends the updated terminal digital certificate to the user terminal if the authentication is successful.
[0100] like Figure 9 As shown, the user terminal can also generate a temporary public key and a temporary private key, and send the temporary public key to the target home network 120, so that the target home network 120 can use the temporary public key to encrypt the updated terminal digital certificate before sending the encrypted terminal digital certificate to the user terminal. Alternatively, the user terminal can also send the temporary public key in the digital certificate update request to the target home network 120, which is not specifically limited in this embodiment.
[0101] The user authentication system provided in this application embodiment enables the user terminal to obtain an updated digital certificate issued by the target home network when the user terminal's digital certificate expires, by sending a digital certificate update request to the visited network. This solves the problem of expired user terminal digital certificates.
[0102] In one embodiment, such as Figure 10 As shown, a user authentication method is provided. This application embodiment uses the application of this method to a network in the user authentication system of any of the above embodiments as an example for illustration, including the following steps:
[0103] Step 1002: Receive a service request sent by the visited network. The service request is forwarded to the network when the visited network receives a service request sent by the user terminal but is unable to provide the target service corresponding to the service request.
[0104] In this embodiment, when a user terminal needs a visited network to provide a specific service, it can send a service request to the visited network. If the visited network cannot provide the specific service, it can determine a network that can provide the specific service and forward the service request to that network. The method by which the visited network determines a network that can provide the specific service can be referred to the relevant description in the foregoing embodiments, and will not be repeated here.
[0105] Step 1004: Send a verification request to the user terminal according to the service request.
[0106] In this embodiment, after receiving a service request, the network needs to verify the identity of the user terminal. The network can send a verification request to the user terminal indicated in the service request, instructing the user terminal to send its digital certificate. The specific process of communication between the network and the user terminal can be referred to the description in the foregoing embodiments, and will not be repeated here.
[0107] Step 1006: Receive the terminal digital certificate sent by the user terminal in response to the verification request, verify the terminal digital certificate, and provide the target service to the user terminal if the terminal digital certificate verification is successful.
[0108] In this embodiment, after receiving the terminal digital certificate, the network verifies its authenticity. If the terminal digital certificate is determined to be valid, the network can continue to provide the target service indicated in the service request to the user terminal. The specific method for verifying the terminal digital certificate can be found in the descriptions of the foregoing embodiments, and will not be repeated here.
[0109] The user authentication method provided in this application, when the visited network cannot provide the service required by the user terminal, forwards the user terminal's service request to the corresponding functional network or distributed network. The functional network or distributed network then interacts with the user terminal to obtain the user terminal's digital certificate, and verifies the user terminal's identity based on the terminal digital certificate. If the verification is successful, the user terminal is provided with the required service. This application establishes a system for authenticating a user terminal when the network providing the target service and the visited network are not the same network, allowing the network to verify the user terminal's identity before providing the service.
[0110] It should be understood that although the steps in the flowcharts of the embodiments described above are shown sequentially according to the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless explicitly stated herein, there is no strict order restriction on the execution of these steps, and they can be executed in other orders. Moreover, at least some steps in the flowcharts of the embodiments described above may include multiple steps or multiple stages. These steps or stages are not necessarily completed at the same time, but can be executed at different times. The execution order of these steps or stages is not necessarily sequential, but can be performed alternately or in turn with other steps or at least some of the steps or stages of other steps.
[0111] Based on the same inventive concept, this application also provides a sensory information opening device for implementing the above-described sensory information opening method. The solution provided by this device is similar to the solution described in the above method; therefore, the specific limitations in one or more sensory information opening device embodiments provided below can be found in the limitations of the sensory information opening method described above, and will not be repeated here.
[0112] In one embodiment, such as Figure 11 As shown, a user authentication device 1100 is provided, including: a first receiving module 1102, a sending module 1104, and a second receiving module 1106, wherein:
[0113] The first receiving module 1102 is used to receive a service request sent by the visited network. The service request is forwarded to the network when the visited network receives the service request sent by the user terminal and is unable to provide the target service corresponding to the service request.
[0114] The sending module 1104 is used to send a verification request to the user terminal according to the service request;
[0115] The second receiving module 1106 is configured to receive the terminal digital certificate sent by the user terminal in response to the verification request, verify the terminal digital certificate, and provide the target service to the user terminal if the terminal digital certificate verification is successful.
[0116] The user authentication device provided in this application provides a system for authenticating user terminals when the visited network cannot provide the services required by the user terminal. The visited network forwards the user terminal's service request to the corresponding functional network or distributed network. The functional network or distributed network then interacts with the user terminal to obtain the user terminal's digital certificate and verifies the user terminal's identity based on the certificate. If the verification is successful, the system provides the required services to the user terminal. This application establishes a system for authenticating user terminals when the network providing the target service and the visited network are not the same network, allowing the network to verify the user terminal's identity before providing services.
[0117] Each module in the aforementioned user authentication device can be implemented entirely or partially through software, hardware, or a combination thereof. These modules can be embedded in or independent of the processor in a computer device, or stored in the memory of a computer device as software, so that the processor can invoke and execute the operations corresponding to each module.
[0118] In one embodiment, a network device is provided, such as Figure 12 The diagram shows the structure of a network device provided in an embodiment of this application. The network device may include a receiver 1202, a memory 1204, a processor 1206, at least one communication bus 1208, and a transmitter 1210. The communication bus 1208 is used to establish communication connections between components. The memory 1204 may include high-speed RAM or non-volatile memory (NVM), such as at least one disk storage device. The memory 1204 can store various programs to perform various processing functions and implement the method steps of this embodiment. In this embodiment, the transmitter 1210 can be a radio frequency processing module or a baseband processing module in a communication device, and the receiver 1202 can also be a radio frequency processing module or a baseband processing module in a communication device. The transmitter 1208 and receiver 1202 can be integrated to form a transceiver. Both the transmitter 1210 and receiver 1202 can be coupled to the processor 1206, and can perform receiving or transmitting actions under the instruction or control of the processor 1206.
[0119] In this embodiment, receiver 1202 is used to receive service requests sent by the visited network. The service request is forwarded to the network when the visited network receives the service request sent by the user terminal and is unable to provide the target service corresponding to the service request.
[0120] The transmitter 1210 is used to send a verification request to the user terminal according to the service request;
[0121] Receiver 1202 is also used to receive the terminal digital certificate sent by the user terminal in response to the verification request;
[0122] The processor 1206 is used to verify the terminal digital certificate and, if the terminal digital certificate is verified, to provide the target service to the user terminal.
[0123] Those skilled in the art will understand that Figure 12 The structure shown is merely a block diagram of a portion of the structure related to the present application and does not constitute a limitation on the communication device to which the present application is applied. Specific communication devices may include more or fewer components than those shown in the figure, or combine certain components, or have different component arrangements.
[0124] In one embodiment, a computer-readable storage medium is provided having a computer program stored thereon that, when executed by a processor, implements the steps in the above method embodiments.
[0125] In one embodiment, a computer program product is provided, including a computer program that, when executed by a processor, implements the steps in the above method embodiments.
[0126] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, data stored, data displayed, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties.
[0127] Those skilled in the art will understand that all or part of the processes in the methods of the above embodiments can be implemented by a computer program instructing related hardware. The computer program can be stored in a non-volatile computer-readable storage medium, and when executed, it can include the processes of the embodiments of the above methods. Any references to memory, databases, or other media used in the embodiments provided in this application can include at least one of non-volatile and volatile memory. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetic random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory can include random access memory (RAM) or external cache memory, etc. By way of illustration and not limitation, RAM can take many forms, such as Static Random Access Memory (SRAM) or Dynamic Random Access Memory (DRAM). The databases involved in the embodiments provided in this application may include at least one type of relational database and non-relational database. Non-relational databases may include, but are not limited to, blockchain-based distributed databases. The processors involved in the embodiments provided in this application may be general-purpose processors, central processing units, graphics processing units, digital signal processors, programmable logic devices, quantum computing-based data processing logic devices, etc., and are not limited to these.
[0128] The technical features of the above embodiments can be combined in any way. For the sake of brevity, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.
[0129] The embodiments described above are merely illustrative of several implementation methods of this application, and while the descriptions are specific and detailed, they should not be construed as limiting the scope of this patent application. It should be noted that those skilled in the art can make various modifications and improvements without departing from the concept of this application, and these all fall within the protection scope of this application. Therefore, the protection scope of this application should be determined by the appended claims.
Claims
1. A user authentication system, characterized in that, The system includes a network registration center and at least one network. The network includes a distributed network and a functional network. The distributed network includes a visited network and a home network. The network registration center stores network information for each network and terminal information for each user terminal. The home network is the network used when a user terminal registers an account. The visited network is used to receive service requests sent by the user terminal, and if the visited network cannot provide the target service corresponding to the service request, forward the service request to the target network corresponding to the target service, and establish a data transmission channel between the user terminal and the target network; the target network is any network capable of providing the target service; The target network is configured to send a verification request to the user terminal based on the service request, and to send a first home network information query request to the network registration center based on the service request. The network registration center is also used to respond to the first home network information query request, determine the target home network corresponding to the user terminal, and return the home network digital certificate of the target home network to the target home network; The target network is further configured to receive the terminal digital certificate sent by the user terminal in response to the verification request, verify the terminal digital certificate according to the home network digital certificate, and provide the target service to the user terminal through the data transmission channel if the terminal digital certificate verification is successful.
2. The system according to claim 1, characterized in that, The visited network is also used to send a target network query request to the network registry center based on the target service; The network registry is also used to return the target network to the visited network in response to the target network query request.
3. The system according to claim 1, characterized in that, The visited network is also used to receive the registration request sent by the user terminal, and based on the registration request, forward the registration request to the target home network corresponding to the user terminal; The target home network is also used to authenticate the user terminal based on the registration request, and send the terminal digital certificate to the user terminal if the user terminal is successfully authenticated.
4. The system according to claim 3, characterized in that, The target home network is also configured to receive a temporary public key generated by the user terminal, encrypt the terminal digital certificate based on the temporary public key, and send the encrypted terminal digital certificate to the user terminal.
5. The system according to claim 4, characterized in that, The registration request is generated based on the temporary public key.
6. The system according to claim 3, characterized in that, The visited network is also used to send a second home network information query request to the network registration center based on the registration request; The network registration center is also configured to, in response to the second home network information query request, determine the target home network corresponding to the user terminal, and return the target home network to the visited network.
7. The system according to claim 3, characterized in that, The target home network is also used to send a temporary identity identifier to the user terminal when the user terminal is successfully authenticated. The target home network is also used to generate a user information update request based on the temporary identity identifier, and send the user information update request to the network registration center; The network registration center is also used to update the terminal information of the user terminal in response to the user information update request.
8. The system according to claim 1, characterized in that, The home network is also used to receive user terminal account opening information from the account opening system when the user terminal opens an account, and in response to the user terminal account opening information, send the terminal information of the user terminal to the network registration center. The network registration center is used to store the terminal information of the user terminal and record the correspondence between the user terminal and the home network; The network registration center is also used to send registration response information to the home network, the registration response information being used to indicate that the user terminal has successfully opened an account.
9. The system according to claim 1, characterized in that, The visited network is also used to receive a digital certificate update request sent by the user terminal and forward the digital certificate update request to the target home network corresponding to the user terminal; The target home network is also used to authenticate the user terminal based on the digital certificate update request, and send the updated terminal digital certificate to the user terminal if the user terminal is successfully authenticated.
10. A user authentication method, characterized in that, The method is applied to any network in the user authentication system as described in any one of claims 1-9, comprising: The system receives service requests sent by the visited network, which are forwarded to the network when the visited network receives the service request sent by the user terminal and is unable to provide the target service corresponding to the service request. Based on the service request, a verification request is sent to the user terminal, and based on the service request, a first home network information query request is sent to the network registration center; The system receives a home network digital certificate sent by the network registration center in response to the first home network information query request. The home network digital certificate belongs to the target home network, and the target home network is the home network of the user terminal. The system receives the terminal digital certificate sent by the user terminal in response to the verification request, verifies the terminal digital certificate according to the home network digital certificate, and provides the target service to the user terminal if the terminal digital certificate verification is successful.
11. A user authentication device, characterized in that, The device is applied to any network in the user authentication system as described in any one of claims 1-9, comprising: The first receiving module is used to receive a service request sent by the visited network. The service request is forwarded to the network when the visited network receives the service request sent by the user terminal and is unable to provide the target service corresponding to the service request. The sending module is used to send a verification request to the user terminal according to the service request, and to send a first home network information query request to the network registration center based on the service request; The second receiving module is configured to receive a home network digital certificate sent by the network registration center in response to the first home network information query request, wherein the home network digital certificate belongs to the target home network, and the target home network is the home network of the user terminal; and to receive a terminal digital certificate sent by the user terminal in response to the verification request, verify the terminal digital certificate according to the home network digital certificate, and provide the target service to the user terminal if the terminal digital certificate verification passes.
12. A network device, characterized in that, Applied to any one of the user authentication systems as described in any one of claims 1-9, comprising a transmitter, a processor, and a receiver; The receiver is used to receive service requests sent by the visited network. The service request is forwarded to the network when the visited network receives the service request sent by the user terminal and is unable to provide the target service corresponding to the service request. The transmitter is configured to send a verification request to the user terminal according to the service request, and to send a first home network information query request to the network registration center based on the service request. The receiver is also configured to receive a home network digital certificate sent by the network registration center in response to the first home network information query request, wherein the home network digital certificate belongs to the target home network, and the target home network is the home network of the user terminal, and to receive a terminal digital certificate sent by the user terminal in response to the verification request. The processor is configured to verify the terminal digital certificate based on the home network digital certificate, and provide the target service to the user terminal if the terminal digital certificate verification is successful.
13. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, it implements the steps of the method of claim 10.
14. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by a processor, it implements the steps of the method of claim 10.
Citation Information
Patent Citations
A method, a client and a server for network security
CN102984115A
VoLTE international roam system and method for loopback
CN104363573A