Communication method and apparatus, related device, and storage medium
Patent Information
- Application Number
- CN202210803855.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-07-07
- Publication Date
- 2026-09-11
- Estimated Expiration
- 2042-07-07
AI Technical Summary
[0003]然而,相关技术中,对终端进行认证时,资源部署难度较大,且存在安全性不强的问题
[0027]The communication method, apparatus, related devices, and storage medium provided in this application embodiment have the following functions: First, when a first terminal passes initial authentication, a first request is sent to an AAA server via a second function. This first request requests secondary authentication for the first terminal. The second function is used for at least user plane processing. The method receives authentication results sent by the AAA server via the second function. If the authentication result indicates that the first terminal has passed secondary authentication, a session is established between the first terminal and a first device. First information is obtained, including session-related information between the first terminal and the first device. This first information is then sent to a first management platform via the second function. The first information is used by the first management platform to audit the services of the first terminal. The solution provided in this application embodiment utilizes the second function to forward secondary authentication information, enabling terminal authentication in application scenarios without dedicated line resources. Since a dedicated line does not need to be deployed between the core network and the AAA server, the difficulty of resource deployment is reduced, thereby shortening the dedicated network deployment cycle and improving the replicability of the dedicated network deployment. Simultaneously, sending session-related information between the terminal and the service-providing device to the first management platform allows the first management platform to audit the terminal's service status during the session, thereby strengthening service security management during the session.
Smart Images

Figure CN117412288B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of wireless communication, and more particularly to a communication method, apparatus, related equipment, and storage medium. Background Technology
[0002] When a terminal accesses a 5G private network, the 5G core network (5GC) will perform an identity authentication on the terminal. After the first identity authentication is successful, the terminal's authentication information will be sent to the Authentication, Authorization, Accounting (AAA) server in the 5G private network via a dedicated line. The AAA server will then perform a second identity authentication on the terminal.
[0003] However, in related technologies, authenticating terminals is difficult due to resource deployment challenges and lacks security. Summary of the Invention
[0004] To address the related technical problems, embodiments of the present invention provide a communication method, apparatus, related devices, and storage medium.
[0005] The technical solution of this invention is implemented as follows: This application provides a communication method applied to a first function, including: If the first terminal successfully authenticates once, a first request is sent to the AAA server through the second function. The first request is used to request a second authentication for the first terminal. The second function is used at least for user plane processing. Receive the authentication result sent by the AAA server through the second function; If the authentication result indicates that the second authentication of the first terminal has passed, a session is established between the first terminal and the first device. Obtain first information, which includes session-related information between the first terminal and the first device, and send the first information to the first management platform through the second function. The first information is used by the first management platform to audit the business of the first terminal.
[0006] In the above scheme, when receiving the authentication result sent by the AAA server through the second function, the method further includes: Receive second information sent by the AAA server through the second function, the second information indicating whether to verify the location of the first terminal; If the second information indicates that the location of the first terminal is to be verified, a second request is sent to the third function. The second request is used to request the access policy of the first terminal at the first location to access the private network. The third function receives the access policy returned based on the second request, the access policy including rules to allow access or rules to block access; If the received access policy contains access permission rules and the secondary authentication is successful, a session is established between the first terminal and the first device.
[0007] In the above scheme, when receiving the authentication result sent by the AAA server through the second function, the method further includes: Receive third information sent by the AAA server through the second function, the third information indicating whether to audit the services of the first terminal; When the third information indicates that the business of the first terminal is to be audited, the first information is obtained and sent to the first management platform through the second function.
[0008] This application also provides a communication method applied to an AAA server, including: The first function receives a first request sent by the second function, the first request being used to request secondary authentication of the first terminal, and the second function being used at least to perform user plane processing. In response to the first request, the first terminal is subjected to secondary authentication to obtain the authentication result; The authentication result is sent to the first function through the second function.
[0009] In the above scheme, the secondary authentication of the first terminal includes: The first terminal is subjected to secondary authentication based on the configured fourth information, wherein the fourth information includes at least one of the following: User information of the first terminal; Network-related information corresponding to the first terminal.
[0010] In the above scheme, the fourth information also includes a fifth information, which indicates whether to perform resource management verification on the first terminal; When the fifth information indicates that resource management verification should be performed on the first terminal, the method further includes the following when authenticating the first terminal: The resource management verification of the first terminal is performed through the second management platform.
[0011] In the above scheme, the fourth information also includes a sixth information, which indicates whether to execute a location locking strategy on the first terminal; When the authentication result is sent to the first function through the second function, second information is sent to the first function through the second function, and the second information indicates whether the location of the first terminal should be verified.
[0012] In the above scheme, the fourth information also includes a seventh information, which indicates whether to audit the session information of the first terminal; When the authentication result is sent to the first function through the second function, third information is sent to the first function through the second function, and the third information indicates whether to audit the business of the first terminal.
[0013] The method in the above scheme further includes: Receive the fourth message sent by the first management platform.
[0014] This application also provides a communication method applied to a first management platform, including: Receive first information sent by the first function through the second function, wherein the second function is at least used for user plane processing, and the first information contains session-related information between the first terminal and the first device; Based on the first information, the business of the first terminal is audited, and the audit results are obtained.
[0015] In the above scheme, the auditing of the first terminal's services based on the first information includes: Based on the first information and the fourth information configured for the AAA server, the services of the first terminal are audited, and the fourth information is used to perform secondary authentication on the first terminal.
[0016] The method in the above scheme further includes: Send the access policy for the private network associated with the terminal location to the third function.
[0017] This application also provides a communication device, including: The first sending unit is configured to send a first request to the AAA server via a second function when the first terminal passes the first authentication, the first request being used to request a second authentication of the first terminal; the second function is at least used for user plane processing; and to send first information to the first management platform via the second function, the first information containing session-related information between the first terminal and the first device, the first information being used by the first management platform to audit the services of the first terminal. The first receiving unit is used to receive the authentication result sent by the AAA server through the second function; The processing unit is configured to establish a session between the first terminal and the first device when the authentication result indicates that the second authentication of the first terminal has passed; and to obtain the first information.
[0018] This application also provides a communication device, including: The second receiving unit is used to receive a first request sent by the first function through the second function. The first request is used to request secondary authentication of the first terminal. The second function is used to perform user plane processing at least. The authentication unit is used to respond to the first request, perform secondary authentication on the first terminal, and obtain an authentication result; The second sending unit sends the authentication result to the first function through the second function.
[0019] This application also provides a communication device, including: The third receiving unit is used to receive first information sent by the first function through the second function, the second function being used at least for user plane processing, and the first information includes session-related information between the first terminal and the first device. The auditing unit is used to audit the business of the first terminal based on the first information and obtain the audit results.
[0020] This application embodiment also provides a first function, including: a first communication interface and a first processor; wherein, The first communication interface is used to send a first request to the AAA server through a second function when the first terminal passes the first authentication. The first request is used to request a second authentication for the first terminal. The second function is used to perform user plane processing at least. The interface is also used to receive the authentication result sent by the AAA server through the second function. The interface is also used to send first information to the first management platform through the second function. The first information contains session-related information between the first terminal and the first device. The first information is used by the first management platform to audit the services of the first terminal. The first processor is configured to establish a session between the first terminal and the first device when the authentication result indicates that the second authentication of the first terminal has passed; and to obtain first information through the first communication interface.
[0021] This application also provides an AAA server, including: a second communication interface and a second processor; wherein, The second communication interface is used to receive a first request sent by the first function through the second function, the first request being used to request secondary authentication of the first terminal, the second function being used at least to perform user plane processing; and to send authentication results to the first function through the second function. The second processor is configured to respond to the first request, perform secondary authentication on the first terminal, and obtain the authentication result.
[0022] This application embodiment also provides a first management platform, including: a third communication interface and a third processor; wherein, The third communication interface is used to receive first information sent by the first function through the second function, the second function being used at least for user plane processing, and the first information includes session-related information between the first terminal and the first device; The third processor is used to audit the services of the first terminal based on the first information and obtain the audit results.
[0023] This application embodiment also provides a first function, including: a first processor and a first memory for storing a computer program capable of running on the processor; Wherein, when the first processor is used to run the computer program, it executes the steps of any of the methods of the first functional side described above.
[0024] This application also provides an AAA server, including: a second processor and a second memory for storing computer programs capable of running on the processor; Wherein, when the second processor is used to run the computer program, it executes the steps of any of the methods described above on the AAA server side.
[0025] This application also provides a first management platform, including: a third processor and a third memory for storing computer programs that can run on the processor; When the third processor runs the computer program, it executes any of the steps of the first management platform method described above.
[0026] This application embodiment also provides a storage medium storing a computer program thereon, wherein when the computer program is executed by a processor, it implements the steps of any of the methods described above on the first functional side, or implements the steps of any of the methods described above on the AAA server side, or implements the steps of any of the methods described above on the first management platform side.
[0027] The communication method, apparatus, related devices, and storage medium provided in this application embodiment have the following functions: First, when a first terminal passes initial authentication, a first request is sent to an AAA server via a second function. This first request requests secondary authentication for the first terminal. The second function is used for at least user plane processing. The method receives authentication results sent by the AAA server via the second function. If the authentication result indicates that the first terminal has passed secondary authentication, a session is established between the first terminal and a first device. First information is obtained, including session-related information between the first terminal and the first device. This first information is then sent to a first management platform via the second function. The first information is used by the first management platform to audit the services of the first terminal. The solution provided in this application embodiment utilizes the second function to forward secondary authentication information, enabling terminal authentication in application scenarios without dedicated line resources. Since a dedicated line does not need to be deployed between the core network and the AAA server, the difficulty of resource deployment is reduced, thereby shortening the dedicated network deployment cycle and improving the replicability of the dedicated network deployment. Simultaneously, sending session-related information between the terminal and the service-providing device to the first management platform allows the first management platform to audit the terminal's service status during the session, thereby strengthening service security management during the session. Attached Figure Description
[0028] Figure 1 This is a diagram illustrating the architecture of a private network communication system for an enterprise campus in related technologies. Figure 2 This is a schematic flowchart of the first communication method according to an embodiment of this application; Figure 3 This is a schematic flowchart of the second communication method according to an embodiment of this application; Figure 4 This is a schematic flowchart of the third communication method according to an embodiment of this application; Figure 5 This is a schematic diagram of a dedicated network authentication system architecture used in this application. Figure 6 This is a flowchart illustrating a method for application-specific network communication in this application. Figure 7 This is a flowchart illustrating the asset management verification process in the application example network communication method of this application. Figure 8 This is a schematic diagram of the structure of a first type of communication device according to an embodiment of this application; Figure 9 This is a schematic diagram of the structure of a second type of communication device according to an embodiment of this application; Figure 10 This is a schematic diagram of the third type of communication device structure according to an embodiment of this application; Figure 11This is a schematic diagram of the first functional structure of an embodiment of this application; Figure 12 This is a schematic diagram of the AAA server structure according to an embodiment of this application; Figure 13 This is a schematic diagram of the first management platform structure according to an embodiment of this application; Figure 14 This is a schematic diagram of the communication system structure according to an embodiment of this application. Detailed Implementation
[0029] The present application will now be described in further detail with reference to the accompanying drawings and embodiments.
[0030] In related technologies, when a terminal accesses a 5G private network, such as a smart factory or an enterprise intranet, in order to strengthen the authentication of the access terminal, in addition to the 5GC performing the initial authentication on the terminal, a secondary authentication is also required through an AAA server. Figure 1 This is an architecture diagram of a private network communication system for enterprise campuses in related technologies, such as... Figure 1As shown, the terminal sends a session establishment request to the 5GC via the base station to request the establishment of a session between the terminal and the enterprise server. The session establishment request carries the terminal's identity information. After receiving the session establishment request, the 5GC performs an initial authentication of the terminal based on the 5G Authentication Key Agreement (5G-AKA) protocol. After successful initial authentication, the Session Management Function (SMF) in the 5GC triggers the Challenge Handshake Authentication Protocol (CHAP) for authentication and forwards the terminal's identity information, such as the International Mobile Subscriber Identity (IMSI), International Mobile Equipment Identity (IMEI), Mobile Station International ISDN number (MSISDN), and Data Network Name (DNN), to the AAA server, enabling the AAA server to perform a secondary authentication of the terminal. After successful secondary authentication, the AAA server forwards the request to the Multi-Service Control Gateway (MSCG). The gateway requests network access, which means requesting the MSCG to allocate an access interface for the terminal to access the enterprise server. After the MSCG grants network access to the terminal, a Protocol Data Unit (PDU) session is established between the terminal and the enterprise server, enabling the terminal to access the resources of the enterprise campus private network. During the secondary authentication process, because the identity information involves sensitive data, the SMF needs to send the terminal's identity information via a dedicated line to ensure data security during transmission. This can be done through a Virtual Private Network (VPN) such as Multi-protocol Label Switching (MPLS) or Internet Protocol Security (IPSec).
[0031] However, in application scenarios without dedicated lines, especially those lacking the ability to quickly build dedicated lines, constructing new dedicated lines not only requires additional resource deployment, but also involves significant deployment difficulties and a long deployment cycle. This increases the difficulty and time required for 5G private network deployment, hindering the rapid deployment and implementation of private network services and consequently impacting the large-scale replication of these services. Furthermore, simply authenticating the accessing terminal before establishing a session does not provide comprehensive security protection for the communication process.
[0032] Based on this, in various embodiments of this application, the second function is used to forward the secondary authentication information, which enables terminal authentication in application scenarios without dedicated line resources. Since it is not necessary to deploy a dedicated line between the core network and the AAA server, the difficulty of resource deployment is reduced, the private network deployment cycle is shortened, and the replicability of the private network deployment is improved. At the same time, sending the session-related information between the terminal and the device providing the service (i.e., the enterprise server) to the management platform enables the management platform to audit the terminal's service status during the session, thereby strengthening the service security management during the session.
[0033] This application provides a communication method applied to a first function, such as... Figure 2 As shown, the method includes: Step 201: If the first terminal passes the authentication once, send a first request to the AAA server through the second function. The first request is used to request a second authentication for the first terminal. The second function is used at least for user plane processing. Step 202: Receive the authentication result sent by the AAA server through the second function; Step 203: If the authentication result indicates that the second authentication of the first terminal has passed, establish a session between the first terminal and the first device; Step 204: Obtain first information, which includes session-related information between the first terminal and the first device, and send the first information to the first management platform through the second function. The first information is used by the first management platform to audit the business of the first terminal.
[0034] In practical applications, the terminal can be called a user equipment (UE) or a user, etc.; authentication can also be understood as authorization.
[0035] In a 5G scenario, the first function may include an SMF, which may also be referred to as a first functional entity. This application embodiment does not limit this, as long as its function is implemented. Correspondingly, in a 5G scenario, the second function may include a User Plane Function (UPF), which may also be referred to as a second functional entity. This application embodiment does not limit this, as long as its function is implemented.
[0036] In practical applications, in order to enable low-latency, high-bandwidth, and high-reliability edge applications in vertical industries, the second function can be deployed in the campus network, that is, close to the Mobile Edge Computing (MEC) edge server.
[0037] In step 201, after the first authentication is successful, the first function can first obtain the subscription information of the private network that the first terminal requests to access. The subscription information indicates whether to perform secondary authentication on the terminal accessing the private network. If the obtained subscription information indicates that the terminal accessing the private network should be subject to secondary authentication, the first function sends a first request to the AAA server.
[0038] In practical applications, the first function can obtain the subscription information of the dedicated network to which the first final request for access is made through the configuration method of the first management platform before sending the first request. Here, the dedicated network can also be understood as a private network.
[0039] In practical applications, the first request may carry the identity information of the first terminal, such as the IMSI, IMEI, MSISDN, DNN and other information of the first terminal.
[0040] In step 202, the first function receives the authentication result sent by the AAA server through the second function. This can be understood as the first function receiving the authentication result sent by the AAA server through the second function. In other words, the AAA server sends the authentication result to the second function, and the second function sends the received authentication result back to the first function. The authentication result indicates whether the first terminal has passed the two-factor authentication.
[0041] In practical applications, to further enhance the security authentication of the first terminal, the location of the first terminal can also be authenticated during the authentication process, so that the designated terminal can only access the designated private network, while the unauthorized terminal cannot access the private network.
[0042] Based on this, in one embodiment, when receiving the authentication result sent by the AAA server through the second function, the method may further include: Receive second information sent by the AAA server through the second function, the second information indicating whether to verify the location of the first terminal; If the second information indicates that the location of the first terminal is verified, a second request is sent to the third function. The second request is used to request the access policy of the first terminal at the first location to access the private network. The third function receives the access policy returned based on the second request, the access policy including rules to allow access or rules to block access; If the received access policy contains access permission rules and the secondary authentication is successful, a session is established between the first terminal and the first device.
[0043] The first function receiving the second information sent by the AAA server through the second function can be understood as the first function receiving the second information sent by the AAA server through the second function. In other words, the AAA server sends the second information to the second function, and the second function sends the received second information back to the first function.
[0044] In practical applications, the second request may carry the location information of the first terminal (such as the cell where the terminal is located).
[0045] In a 5G scenario, the third function may include a policy control function (PCF). The third function may also be referred to as a third function entity. This application embodiment does not limit this, as long as its function is implemented.
[0046] Regarding the access policy in the third function, it can be configured by the first management platform before the first terminal performs secondary authentication. Specifically, when the second information indicates that the location of the first terminal needs to be verified, the first management platform configures an access policy for the third function that is associated with the location of the dedicated network. Correspondingly, when the second information indicates that the location of the first terminal does not need to be verified, the first management platform does not configure an access policy for the PCF. The specific content of the second information can be determined by the first management platform. Specifically, the first management platform can send a sixth message to the AAA server, indicating whether to execute a location locking policy on the first terminal. The AAA server generates the second message based on the sixth message sent by the first management platform. In practical applications, the specific content of the sixth message and the second message can be determined according to the actual security authentication requirements of the dedicated network. This embodiment does not limit this; for example, the sixth message can be defaulted to executing a location locking policy on the first terminal, and the second message can be defaulted to verifying the location of the first terminal.
[0047] Specifically, when the first management platform configures the access policy for the third function, it subscribes the terminal information and the location information allowed for terminal access (such as the cell where the terminal is located) to the third function. This can be understood as associating the terminal with the location information allowed for terminal access and sending the association relationship to the third function. This allows the third function to determine whether the first terminal in the first location can access the dedicated network. If the determination result indicates that access is possible, it issues an access permission rule; or if the determination result indicates that access is not possible, it issues an access blocking rule.
[0048] In practical applications, the first function can determine whether to audit the business of the first terminal based on the configuration information of the AAA server, thereby deciding whether to obtain the first information during the session and send the first information to the first management platform.
[0049] Based on this, in one embodiment, when receiving the authentication result sent by the AAA server through the second function, the method may further include: Receive third information sent by the AAA server through the second function, the third information indicating whether to audit the services of the first terminal; When the third information indicates that the business of the first terminal is to be audited, the first information is obtained and sent to the first management platform through the second function.
[0050] The first function receiving the third information sent by the AAA server through the second function can be understood as the first function receiving the third information sent by the AAA server through the second function. In other words, the AAA server sends the third information to the second function, and the second function sends the received third information back to the first function.
[0051] In practical applications, after successful secondary authentication, the AAA server will request network access from the gateway of the dedicated network (such as MSCG), thereby enabling the gateway to allocate an access interface to the first terminal. After the gateway grants network access to the first terminal, the first function will send the acquired first information to the second function, the second function will send the first information to the first device through the gateway, and the first device will send the received first information to the first management platform.
[0052] In practical applications, the first information may include information related to the services of the first terminal, such as device information of the first terminal, network-related information corresponding to the first terminal, traffic-related information of the session, and session time-related information. The device information may include IMSI, ISDN, and IMEI; the network-related information may include slice ID and data network identifier, where the slice ID indicates which network slice the first terminal accesses the dedicated network through; the session traffic-related information may include session traffic, uplink traffic, and downlink traffic; and the session time-related information may include a start timestamp, PDU session start time, and PDU session end time.
[0053] After receiving the first information, the first management platform can use the first information to audit the business of the first terminal.
[0054] Accordingly, embodiments of this application also provide a communication method applied to an AAA server, such as... Figure 3 As shown, it includes: Step 301: Receive a first request sent by the first function through the second function, wherein the first request is used to request secondary authentication of the first terminal, and the second function is used at least for user plane processing; Step 302: In response to the first request, perform secondary authentication on the first terminal to obtain the authentication result; Step 303: Send the authentication result to the first function through the second function.
[0055] In practical applications, the first management platform can configure the AAA server with the information it uses to authenticate the first terminal.
[0056] Based on this, in one embodiment, the secondary authentication of the first terminal includes: The first terminal is then subjected to secondary authentication based on the configured fourth information. Specifically, the secondary authentication of the first terminal may be performed based on the fourth information configured by the management platform, wherein the fourth information includes at least one of the following: User information of the first terminal; Network-related information corresponding to the first terminal.
[0057] In practical applications, the user information of the first terminal may include: User ID, User Password, Integrated Circuit Card Identity (ICCID), IMSI, MSISDN, Start Time, and End Time. The network-related information corresponding to the first terminal may include: DNN and Single Network Slice Selection Assistance Information (S-NSSAI).
[0058] In practical applications, when the AAA server performs secondary authentication on the first terminal, it can also perform asset management authentication on the first terminal.
[0059] Based on this, in one embodiment, the fourth information further includes a fifth information, the fifth information indicating whether to perform resource management verification on the first terminal; When the fifth information indicates that resource management verification should be performed on the first terminal, the method for authenticating the first terminal may further include: The resource management verification of the first terminal is performed through the second management platform.
[0060] In practical applications, the second management platform can also be called an asset management platform or an asset management system. This application embodiment does not limit this, as long as its functions are implemented.
[0061] In practical applications, the first request received by the AAA server may carry the identity information of the first terminal. When the AAA server verifies the resource management of the first terminal through the second management platform, it compares whether the registration information of the first terminal exists in the second management platform and whether the registration information matches the identity information of the first terminal, thereby determining whether the first terminal passes the asset management verification. Specifically, if the registration information of the first terminal exists in the second management platform and the registration information matches the identity information of the first terminal, the verification of the first terminal is determined to be successful. If the registration information of the first terminal does not exist in the second management platform, and / or the registration information does not match the identity information of the first terminal, the verification of the first terminal is determined to be unsuccessful.
[0062] For example, the registration information in the second management platform may include the following interface protocol fields: entry time, IMEI device code, user ID, whether IP range is restricted, and IP range address; when performing asset management verification, the verification result is determined based on the following two conditions: The first condition is that the entry time is earlier than or equal to the start timestamp of the first terminal, and the IP address requested by the first terminal is within the IP address range, and the IMEI of the first terminal is consistent with the IMEI device code; wherein, the entry time can be understood as the time when the first terminal registers on the second management platform, that is, the time when the first terminal registers on the asset management platform, and the start timestamp can be understood as the start time of the session; The second condition is that all interface protocol fields contained in the first terminal and the asset management platform are identical.
[0063] If both conditions are met, the first terminal is determined to have passed verification; if neither condition is met, the first terminal is determined to have failed verification.
[0064] In practical applications, the content indicated by the fifth information can be configured by the first management platform according to the actual security authentication requirements of the dedicated network. This application embodiment does not limit this; for example, the fifth information can be defaulted to not performing resource management verification on the first terminal.
[0065] In practical applications, when performing secondary authentication on the first terminal, the AAA server can also determine whether the location of the first terminal needs to be verified based on the information configured on the first management platform, and notify the first function to verify the location of the first terminal.
[0066] Based on this, in one embodiment, the fourth information further includes a sixth information, the sixth information indicating whether a location locking strategy is executed on the first terminal; When the authentication result is sent to the first function through the second function, second information is sent to the first function through the second function, and the second information indicates whether the location of the first terminal should be verified.
[0067] In practical applications, the AAA server can determine whether it is necessary to audit the business of the first terminal based on the information configured in the first management platform, and notify the first function.
[0068] Based on this, in one embodiment, the fourth information further includes a seventh information, the seventh information indicating whether to audit the session information of the first terminal; When the authentication result of successful authentication is sent to the first function through the second function, the third information is sent to the first function through the second function, and the third information indicates whether to audit the business of the first terminal.
[0069] In practical applications, the first management platform can configure the specific content of the sixth information indication according to the actual security authentication requirements of the dedicated network. This application embodiment does not limit this; for example, it can be set by default to the sixth information indication to execute a location lock policy on the first terminal.
[0070] Accordingly, embodiments of this application also provide a communication method applied to a first management platform, such as... Figure 4 As shown, the method includes: Step 401: Receive first information sent by the first function through the second function, wherein the second function is at least used for user plane processing, and the first information contains session-related information between the first terminal and the first device; Step 402: Based on the first information, audit the business of the first terminal to obtain the audit results.
[0071] In practical applications, the first management platform can also be referred to as the management platform of a dedicated network. This application embodiment does not limit this, as long as its functions are implemented.
[0072] In practical applications, before the first terminal and the first device can have a session, the AAA server needs to be configured with fourth information so that the AAA server can perform secondary authentication on the first terminal.
[0073] Based on this, in one embodiment, the method may further include: Configure a fourth piece of information for the AAA server, which is used to perform secondary authentication on the first terminal.
[0074] The fourth information configured for the AAA server may include at least one of the following: User information of the first terminal; Network-related information corresponding to the first terminal.
[0075] In practical applications, before the AAA server performs secondary authentication on the first terminal, the first management platform can configure fourth information for the AAA server. That is, before receiving the first message sent by the first function through the second function, the first management platform configures fourth information for the AAA server.
[0076] In practical applications, the first management platform can use the fourth information to determine whether the business status of the first terminal is normal during the session.
[0077] Based on this, in one embodiment, the auditing of the services of the first terminal based on the first information includes: Based on the first information and the fourth information configured for the AAA server, the business of the first terminal is audited.
[0078] In practical applications, the first information may include information related to the services of the first terminal, such as user information of the first terminal, network-related information corresponding to the first terminal, traffic-related information of the session, and time-related information of the session.
[0079] In practical applications, when auditing the services of the first terminal, the user information and network-related information of the first terminal are verified by comparing the first information and the fourth information, and abnormal situations in the first terminal session are detected.
[0080] For example, when verifying the user information and network-related information of the first terminal, the user information of the first terminal in the first information and the fourth information can be compared to see if they are consistent, such as DNN, ICCID, slice ID, etc.; when detecting abnormal situations of the first terminal session, the session time-related information contained in the first information can be used to determine whether there is still session access when the expiration time is reached, and the session traffic-related information contained in the fourth information can be used to determine whether the traffic to access the private network is too large.
[0081] In this embodiment of the application, by auditing the services of the first terminal, abnormal situations in the session can be detected in a timely manner, thereby improving the security of the communication process.
[0082] In practical applications, the first management platform can instruct the AAA server whether it needs to perform asset management verification on the first terminal during secondary authentication by configuring information for the AAA server.
[0083] Based on this, in one embodiment, the fourth information configured for the AAA server may include a fifth information, which indicates whether to perform resource management verification on the first terminal.
[0084] In practical applications, the first management platform can also instruct the AAA server whether it needs to implement a location lock policy for the first terminal by configuring information for the AAA server. This allows the AAA server to send the authentication result to the first function through the second function, and send second information to the first function through the second function, indicating whether to verify the location of the first terminal.
[0085] Based on this, in one embodiment, the fourth information configured for the AAA server may include a sixth information, which indicates whether a location locking policy is executed on the first terminal.
[0086] In practical applications, when the sixth information indicates that a location lock policy needs to be executed on the first terminal, the first management platform also needs to configure an access policy for the third function that is associated with the terminal's location to access the dedicated network.
[0087] Based on this, in one embodiment, the method may further include: Send the access policy for the private network associated with the terminal location to the third function.
[0088] In practical applications, the first management platform can send location lock policies to the third function through the operator's management system, such as the Business Support System (BSS).
[0089] In practical applications, the first management platform can instruct the AAA server whether it needs to audit the session information of the first terminal by configuring information for the AAA server. This allows the AAA server to determine whether to instruct the first function to send the session-related information of the first terminal and the first device to the first management platform when sending the authentication result to the first function.
[0090] Based on this, in one embodiment, the fourth information configured for the AAA server may include a seventh information, which is used to indicate whether to audit the session information of the first terminal.
[0091] In practical applications, after receiving the information to be audited, the information can be stored in a cache. Specifically, the information to be audited can be put into a message queue. When auditing the information, one piece of information is retrieved from the message queue in sequence, and the retrieved information is audited.
[0092] In practical applications, after obtaining the audit results, the audit results can also be output.
[0093] Based on this, in one embodiment, the method may further include: Output the audit results.
[0094] In practical applications, when the first terminal experiences service anomalies, administrators need to conduct offline investigations based on the audit results to locate the fault. Therefore, the audit results can be sent to the terminals associated with the first management platform so that administrators can promptly detect service anomalies.
[0095] Therefore, in one embodiment, outputting the audit result includes: The audit results are sent to the terminal associated with the first management platform.
[0096] In practical applications, the terminals managed by the first management platform can be mobile phones, computers, wearable electronic devices, and other terminal devices.
[0097] The communication method provided in this application embodiment includes the following functions: First, when a first terminal passes initial authentication, a first request is sent to an AAA server via a second function. This first request requests secondary authentication for the first terminal. The second function is used for at least user plane processing. The method receives the authentication result sent by the AAA server via the second function. If the authentication result indicates that the second authentication of the first terminal has passed, a session is established between the first terminal and a first device. First information is obtained, including session-related information between the first terminal and the first device. This first information is then sent to a first management platform via the second function. The first information is used by the first management platform to audit the services of the first terminal. The solution provided in this application embodiment utilizes the second function to forward secondary authentication information, enabling terminal authentication in application scenarios without dedicated line resources. Since a dedicated line does not need to be deployed between the core network and the AAA server, the difficulty of resource deployment is reduced, thereby shortening the dedicated network deployment cycle and improving the replicability of the dedicated network deployment. Simultaneously, sending the session information between the terminal and the service-providing device to the first management platform (i.e., the enterprise server) allows the first management platform to audit the terminal's service status during the session, thereby strengthening service security management during the session.
[0098] The following section provides a more detailed description of this application with reference to application examples.
[0099] Figure 5 This is a schematic diagram of the architecture of the application example dedicated network authentication system of this application, where dashed lines represent nodes communicating via direct connection, and solid lines represent nodes communicating via UPF; as shown... Figure 5 As shown, the architecture of the application example dedicated network authentication system of this application mainly includes: base station (i.e., gNodeB), access and mobility management function (AMF), SMF, UPF, data network AAA (DN-AAA) server (i.e., the above-mentioned AAA server), MSCG and private network server.
[0100] The AMF and SMF are deployed in the 5GC, and the UE connects to the AMF via the gNodeB. The SMF is used for user plane processing, such as sending requests to the DN-AAA server via the UPF to request the DN-AAA server to perform secondary authentication for the UE, and sending the UE's session-related information to the enterprise private network server via the UPF.
[0101] The UPF, DN-AAA server, and private network server are deployed in a dedicated network. The UPF is deployed close to the MEC server. The SMF communicates with the UPF, and the UPF communicates with the DN-AAA server. This allows the UPF to receive requests from the SMF and forward them to the DN-AAA server, receive authentication results from the DN-AAA server and forward them to the SMF, and receive UE session-related information from the SMF and forward it to the enterprise private network server. The DN-AAA server receives requests from the SMF via the UPF, performs secondary authentication on the UE based on the received requests, generates authentication results, and forwards them to the SMF via the UPF. The private network server establishes sessions with the UE and provides the UE with access to the dedicated network resources.
[0102] Based on the above architecture, such as Figure 6 As shown, the dedicated network communication methods provided in this application example include: Step 1: The enterprise private network operation platform configures authentication information for the DN-AAA server, that is, the first management platform configures the fourth information; In practical applications, enterprise administrators or employees can enter usernames / passwords, device card numbers, authentication expiration times, slice ID information, auxiliary verification information, and other authentication information on the enterprise private network operation platform and submit them to the enterprise DN-AAA server. Here, the enterprise private network operation platform can also be called the enterprise private network operation self-service platform, which can be understood as a self-service channel, that is, enterprise administrators or employees can independently enter authentication information on it.
[0103] For example, the main authentication information configured in the enterprise private network operation platform is shown in Table 1:
[0104] Table 1 Step 2: The enterprise private network operation platform synchronizes the authentication information to the enterprise private network server, and when a dynamic location locking policy needs to be executed, it configures the access policy for the PCF through the BSS, that is, sends the access policy associated with the terminal location to the third function to access the private network. Here, the enterprise private network operation platform can also synchronize the UE's subscription information to the PCF through the BSS. The subscription information indicates whether a secondary audit is required when the UE accesses the private network.
[0105] Step 3: If the UE authentication is successful on the first attempt, the SMF forwards the UE's identity information to the DN-AAA server via the UPF; Here, an N4 tunnel is established between the SMF and the UPF. The N4 tunnel is based on the GPRS User Plane Part (GTP-U) tunnel and can be used to transfer the secondary authentication information between the SMF and the DN-AAA server. The UPF uses the existing device-level N4 tunnel and N6 leased line interface to forward the authentication information to the private network edge service secondary authentication gateway (i.e., the DN-AAA server) for secondary authentication.
[0106] In practical applications, the SMF can obtain the UE's subscription information from the PCF to determine whether secondary authentication of the UE is required. Specifically, it can determine the private network to be accessed based on the UE's DNN information, and then determine whether secondary authentication of the UE accessing the network is required based on the information associated with the private network in the subscription information.
[0107] Step 4: The DN-AAA server performs secondary authentication on the UE and obtains the authentication result; Here, the DN-AAA server compares the UE's authentication information with the authentication information configured on the enterprise private network operation platform, and determines whether the secondary authentication passes based on the comparison result. For example, it verifies the UE's username, password, SIM code, and IMEI number. If all verifications pass, the secondary authentication is successful; otherwise, it fails.
[0108] In practical applications, when performing secondary authentication, the DN-AAA server can follow the Extensible Authentication Protocol (EAP). The authentication information is carried by Non-Access Stratum (NAS) signaling, where the UE acts as the peer, the SMF acts as the authenticator, and the DN-AAA acts as the server. The authentication information is forwarded through the independently deployed secondary authentication gateway (i.e., the DN-AAA server) / EAP interface, and follows the secondary authentication architecture and standard protocols in relevant technologies. The 5GC performs secondary authentication through the interface between itself and the secondary authentication gateway device.
[0109] Meanwhile, during secondary authentication, the SMF sends an authentication start message to the DN-AAA server through the UPF and establishes an authentication channel between the UE and the DN-AAA server. After several EAP-Request / EAP-Response information exchanges between the SMF and the DN-AAA server through the UPF, the DN-AAA server sends the authentication result to the SMF through the UPF. During this process, the SMF and UPF, and the UPF and DN-AAA server, can use public protocols such as Password Authentication Protocol (PAP), CHAP, AKA, and Transport Layer Security (TLS) to exchange information.
[0110] During the secondary authentication process, the DN-AAA server determines whether to perform asset management verification based on user-defined configuration parameters. That is, the fourth information contains the fifth information, which indicates whether to perform asset management verification on the first terminal. When asset management verification is required, the DN-AAA server performs asset management verification through the asset management system.
[0111] Specifically, such as Figure 7As shown, during asset management verification, the DN-AAA server sends a request to the asset management system through the northbound interface, requesting the asset management system to query the UE's registration information and send the UE's authentication information to the asset management system for asset information comparison, such as entry time, IMEI, UserID, IP, etc. When the UE's registration information exists in the asset management system and the registration information is strongly consistent, the asset management system returns a successful verification result; otherwise, it returns a failed verification result.
[0112] For example, the verification rules of the asset management system are as follows: The main interface protocol fields included in the UE registration information in the asset management system are shown in Table 2:
[0113] Table 2 The verification conditions are: starttime≤triggerTimeStamp &UE request IP in (ipadress)&userEquipmentInfo=pei; that is, the entry time is earlier than or equal to the UE's start timestamp, the IP address requested by the UE is within the IP address range, and the UE's IMEI and IMEI device code in the authentication information are consistent.
[0114] The verification is successful if all the main interface protocol fields in Table 2 match and the verification conditions are met; otherwise, the verification fails.
[0115] When the DN-AAA server passes the secondary authentication and the asset management system returns a successful verification result, the DN-AAA will confirm the successful authentication and generate an authentication result. The generated authentication result will then be sent to the SMF, which will establish a connection between the UE and the data network, i.e., establish a session between the UE and the enterprise private network server.
[0116] Step 5: The DN-AAA server requests network access from the MSCG of the enterprise private network. After the MSCG grants network access, it sends a response to the DN-AAA server. Here, requesting network access from the MSCG of the enterprise private network can also be understood as requesting the MSCG to allocate an interface for the UE to access the enterprise private network server; after the MSCG grants network access to the UE, it sends a response to the DN-AAA server, and the DN-AAA server feeds back the response to the SMF through the UPF, so that the UE can conduct PDU sessions with the enterprise private network server through the allocated interface.
[0117] Step 6: The DN-AAA server sends the authentication result to the SMF; It should be noted that when the DN-AAA server returns the authentication result, it can also return configuration information for the authentication or audit process, that is, auxiliary verification information, such as whether to audit the UE's services or whether to dynamically lock the location policy.
[0118] When the auxiliary verification information includes configuration information for the dynamic lock location policy, that is, the fourth information includes the sixth information, and the sixth information indicates whether to execute the location lock policy on the first terminal, the SMF will verify the location of the UE before the session is established.
[0119] The process by which the SMF verifies the location of the UE is as follows: The enterprise private network operation platform configures the location locking policy to the PCF through the BSS, associating the UE's user number with the list of cells that allow user access and configuring it in the PCF. When the UE accesses the enterprise private network, the SMF automatically reports the cell where the UE is located. This allows the PCF to automatically record the UE's location when it goes online or changes location while online, and determine whether the user is in the configured cell list based on the UE's location. If it is, a permit rule is issued, allowing access; otherwise, a block rule is issued, blocking access. When the SMF receives the successful authentication result and the permit rule issued by the PCF, a PDU session is established between the UE and the enterprise private network server. When the SMF receives the block rule issued by the PCF, the UE cannot access the enterprise private network regardless of whether authentication is successful, thus preventing unauthorized terminals from accessing the enterprise private network.
[0120] Step 7: SMF establishes a PDU session between the UE and the enterprise private network service, and forwards the session information to the enterprise private network operation platform; Specifically, the SMF obtains the UE's session information, or first information, based on the PDU session between the UE and the enterprise private network server. This session information is then forwarded to the MSCG via the UPF, and subsequently forwarded by the MSCG to the enterprise private network server, which then sends it to the enterprise private network operation platform. This session information includes the UE's access records, application records, etc., and may specifically include the UE's device-related information, access traffic information, and PDU session time information.
[0121] For example, the main content of the session information is shown in Table 3:
[0122] Table 3 In practical applications, during the PDU session between the UE and the enterprise private network server, the PDU session data is also sent from the SMF to the UPF, and then forwarded by the UPF to the MSCG before reaching the enterprise private network server.
[0123] In practical applications, the SMF can determine whether to audit the session information between the UE and the enterprise private network server based on the configuration of the enterprise private network operation platform. That is, whether the auxiliary verification information is configured to require service auditing of the UE. In other words, the fourth information includes the seventh information, which indicates whether to audit the session information of the first terminal. When it is necessary to audit the session information between the UE and the enterprise private network server, the SMF will forward the session information between the UE and the enterprise private network server to the enterprise private network operation platform after the session is established. Of course, it can also be assumed that service auditing is mandatory.
[0124] Step 8: The enterprise private network operation platform audits the UE's services based on the received session information and obtains the audit results; Here, when receiving session information, the enterprise private network operation platform compares the session information online and dynamically refreshes the session information. This can also be understood as the SMF sending session information to the enterprise private network operation platform in real time, such as DNN, ICCID, MSISDN, IMSI, slice ID, start time, traffic, and other information. The enterprise private network operation platform compares the received session information with the authentication information configured for the DN-AAA server to audit the UE's services.
[0125] For example, the enterprise private network operation platform compares the end time of the PDU session with the expiration time in the authentication information to determine whether there is still session access information when the expiration time is reached. Based on the traffic information in the session information, it determines whether the access traffic of the private network has reached the limit. By comparing key information such as slice ID with the authentication information, it determines whether these key information are consistent.
[0126] Here, the enterprise private network operation platform can also synchronize the authentication information to the enterprise private network server when configuring authentication information for the DN-AAA server. This allows the enterprise private network server to send the authentication information to the enterprise private network operation platform when forwarding session information, so that the enterprise private network operation platform can compare the configured authentication information with the session information.
[0127] During the audit process, received session information can be placed into a message queue in the cache. When auditing session information, information can be retrieved one by one from the message queue and audited.
[0128] Step 9: Send the audit results to the terminals associated with the enterprise private network operation platform; Here, when an anomaly is detected during the audit, it is necessary to promptly notify the management personnel to conduct offline investigations in order to locate the fault. Therefore, the audit results can be sent to the terminals associated with the first management platform through notification methods such as SMS and email, so that the management personnel can be informed of the business anomaly in a timely manner.
[0129] The application example provided in this application demonstrates that the SMF determines whether secondary authentication of the UE is required, and then routes the traffic to the UPF to access the DN-AAA server for secondary authentication via a relay method. This provides an enterprise-controlled 5G private network authentication method in scenarios where MPLS or IPSec VPN leased lines are not available.
[0130] Meanwhile, during secondary authentication, asset comparison verification and location locking strategies are implemented to enhance UE security authentication. In normal business operations after successful secondary authentication, the authentication information configured on the enterprise private network operation platform is compared with the UE session information to audit the UE's business, preventing session data overreach caused by session data not meeting preset conditions (such as session time exceeding validity period or session traffic exceeding threshold). This strengthens the ability to detect business anomalies after secondary authentication and ensures communication security during the session.
[0131] To implement the method of the first functional side of the embodiments of this application, the embodiments of this application also provide a communication device, which is configured for the first function, such as... Figure 8 As shown, the device includes: The first sending unit 801 is configured to send a first request to the AAA server through a second function when the first terminal passes the first authentication, the first request being used to request a second authentication of the first terminal; the second function is at least used for user plane processing; and to send first information to the first management platform through the second function, the first information containing session-related information between the first terminal and the first device, the first information being used by the first management platform to audit the services of the first terminal. The first receiving unit 802 is used to receive the authentication result sent by the AAA server through the second function; The processing unit 803 is configured to establish a session between the first terminal and the first device when the authentication result indicates that the second authentication of the first terminal has passed; and to obtain the first information.
[0132] In one embodiment, the first receiving unit 802 is further configured to receive second information sent by the AAA server through the second function, wherein the second information indicates whether the location of the first terminal is verified. The first sending unit 801 is further configured to send a second request to the third function when the second information indicates that the location of the first terminal is to be verified. The second request is used to request the access policy of the first terminal at the first location to access the private network. The first receiving unit 802 is configured to receive the access policy returned by the third function based on the second request, wherein the access policy includes an access permission rule or an access blocking rule; The processing unit 803 establishes a session between the first terminal and the first device when the received access policy includes an access permission rule and the secondary authentication is successful.
[0133] In one embodiment, the first receiving unit 802 is further configured to receive third information sent by the AAA server through the second function, the third information indicating whether to audit the services of the first terminal; The processing unit 803 is used to obtain the first information when the third information indicates that the business of the first terminal is to be audited. The first sending unit 801 is used to send the first information to the first management platform through the second function.
[0134] In practical applications, the first sending unit 801 and the first receiving unit 802 can be implemented by the communication interface in the communication device, and the processing unit 803 can be implemented by the processor in the communication device.
[0135] To implement the AAA server-side method of this application embodiment, this application embodiment also provides a communication device, which is set on the AAA server, such as... Figure 9 As shown, the device includes: The second receiving unit 901 is used to receive a first request sent by the first function through the second function, the first request being used to request secondary authentication of the first terminal, and the second function being used at least to perform user plane processing. The authentication unit 902 is used to respond to the first request, perform secondary authentication on the first terminal, and obtain an authentication result; The second sending unit 903 sends the authentication result to the first function through the second function.
[0136] In one embodiment, the authentication unit 902 is used to perform secondary authentication on the first terminal based on configured fourth information; the fourth information includes at least one of the following: User information of the first terminal; Network-related information corresponding to the first terminal.
[0137] In one embodiment, the fourth information further includes a fifth information, the fifth information indicating whether resource management verification is performed on the first terminal; When the fifth information indicates that resource management verification should be performed on the first terminal, the authentication unit 902 is further configured to: The resource management verification of the first terminal is performed through the second management platform.
[0138] In one embodiment, the fourth information further includes a sixth information, the sixth information indicating whether a location locking strategy is executed on the first terminal; The second sending unit 903 is further configured to send second information to the first function through the second function when sending the authentication result to the first function through the second function, wherein the second information indicates whether to verify the location of the first terminal.
[0139] In one embodiment, the fourth information further includes a seventh information, the seventh information indicating whether to audit the session information of the first terminal; The second sending unit 903 is further configured to send third information to the first function through the second function when sending the authentication result to the first function through the second function, wherein the third information indicates whether to audit the services of the first terminal.
[0140] In one embodiment, the second receiving unit 901 is further configured to receive fourth information sent by the first management platform.
[0141] In practical applications, the second receiving unit 901 and the second sending unit 903 can be implemented by the communication interface in the communication device, and the authentication unit 902 can be implemented by the processor in the communication device.
[0142] To implement the platform-side method of this application embodiment, this application embodiment also provides a communication device, configured on the first management platform, such as... Figure 10 As shown, the device includes: The third receiving unit 1001 is used to receive first information sent by the first function through the second function, the second function being used at least for user plane processing, and the first information includes session-related information between the first terminal and the first device. Audit unit 1002 is used to audit the business of the first terminal based on the first information and obtain audit results.
[0143] In one embodiment, the auditing unit 1002 is used to audit the services of the first terminal based on the first information and the fourth information configured for the AAA server, wherein the fourth information is used to perform secondary authentication on the first terminal.
[0144] In one embodiment, the apparatus further includes a third transmitting unit for transmitting an access policy for accessing a private network associated with the terminal location to a third function.
[0145] In practical applications, the third receiving unit 1001 and the third transmitting unit can be implemented by the communication interface in the communication device, and the auditing unit 1002 can be implemented by the processor in the communication device.
[0146] It should be noted that the communication device provided in the above embodiments is only illustrated by the division of the above program modules. In actual applications, the above processing can be assigned to different program modules as needed, that is, the internal structure of the device can be divided into different program modules to complete all or part of the processing described above. In addition, the communication device and communication method embodiments provided in the above embodiments belong to the same concept, and their specific implementation process can be found in the method embodiments, which will not be repeated here.
[0147] Based on the hardware implementation of the above program modules, and in order to implement the method of the first functional side of the embodiments of this application, the embodiments of this application also provide a first function, such as... Figure 11 As shown, the first function 1100 includes: The first communication interface 1101 is capable of exchanging information with the AAA server and the first management platform; for example, it can send a first request to the AAA server through the second function, receive the authentication result sent by the AAA server through the second function, and send first information to the first management platform through the second function. The first processor 1102 is connected to the first communication interface 1101 to enable information interaction with the AAA and the first management platform, and to execute the methods provided by one or more of the above-mentioned first functional side technical solutions when running a computer program; The computer program is stored in the first memory 1103.
[0148] Specifically, the first communication interface 1101 is used to send a first request to the AAA server through a second function when the first terminal passes the first authentication, the first request being used to request a second authentication for the first terminal; the second function is used at least for user plane processing; and to receive the authentication result sent by the AAA server through the second function; and to send first information to the first management platform through the second function, the first information containing session-related information between the first terminal and the first device, the first information being used by the first management platform to audit the services of the first terminal; The first processor 1102 is configured to establish a session between the first terminal and the first device when the authentication result indicates that the second authentication of the first terminal has passed; and to obtain first information through the first communication interface 1101.
[0149] In one embodiment, the first communication interface 1101 is further configured to: Receive second information sent by the AAA server through the second function, the second information indicating whether to verify the location of the first terminal; If the second information indicates that the location of the first terminal is verified, a second request is sent to the third function. The second request is used to request the access policy of the first terminal at the first location to access the private network. The third function receives the access policy returned based on the second request, the access policy including rules to allow access or rules to block access; The first processor 1102 is configured to establish a session between the first terminal and the first device when the received access policy contains an access permission rule and the secondary authentication is successful.
[0150] In one embodiment, the first communication interface 1101 is further configured to receive third information sent by the AAA server through the second function, wherein the third information indicates whether to audit the services of the first terminal. The first processor 1102 is configured to, when the third information indicates that the business of the first terminal is to be audited, obtain the first information and send the first information to the first management platform through the second function using the first communication interface 1101.
[0151] It should be noted that the specific processing procedures of the first processor 1102 and the first communication interface 1101 can be understood by referring to the above method.
[0152] Of course, in practical applications, the various components in the first function 1100 are coupled together through the bus system 1104. It can be understood that the bus system 1104 is used to implement communication between these components. In addition to the data bus, the bus system 1104 also includes a power bus, a control bus, and a status signal bus. However, for clarity, in... Figure 11 The general designated all buses as Bus System 1104.
[0153] The first memory 1103 in this embodiment is used to store various types of data to support the operation of the first function 1100. Examples of such data include any computer program used to operate on the first function 1100.
[0154] The methods disclosed in the above embodiments of this application can be applied to the first processor 1102, or implemented by the first processor 1102. The first processor 1102 may be an integrated circuit chip with signal processing capabilities. In the implementation process, each step of the above method can be completed by the integrated logic circuit of the hardware or by instructions in the form of software in the first processor 1102. The first processor 1102 may be a general-purpose processor, a digital signal processor (DSP), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The first processor 1102 can implement or execute the methods, steps and logic block diagrams disclosed in the embodiments of this application. The general-purpose processor may be a microprocessor or any conventional processor, etc. The steps of the methods disclosed in the embodiments of this application can be directly reflected as being executed by a hardware decoding processor, or being executed by a combination of hardware and software modules in the decoding processor. The software modules may be located in a storage medium, which is located in the first memory 1103. The first processor 1102 reads the information in the first memory 103 and completes the steps of the aforementioned method in combination with its hardware.
[0155] In an exemplary embodiment, the first function 1100 may be implemented by one or more application-specific integrated circuits (ASICs), DSPs, programmable logic devices (PLDs), complex programmable logic devices (CPLDs), field-programmable gate arrays (FPGAs), general-purpose processors, controllers, microcontrollers (MCUs), microprocessors, or other electronic components to perform the aforementioned method.
[0156] Based on the hardware implementation of the above program modules, and in order to implement the AAA server-side method of the embodiments of this application, the embodiments of this application also provide an AAA server; such as Figure 12 As shown, the AAA server 1200 includes: The second communication interface 1201 is capable of exchanging information with the first function; for example, receiving a first request sent by the first function through the second function. The second processor 1202 is connected to the second communication interface 1201 to enable information interaction with the first function, and to execute the methods provided by one or more technical solutions on the AAA server side when running a computer program; The computer program is stored in the second memory 1203.
[0157] Specifically, the second communication interface 1201 is used to receive a first request sent by the first function through the second function, the first request being used to request secondary authentication of the first terminal, the second function being used at least to perform user plane processing; and to send an authentication result to the first function through the second function. The second processor 1202 is used to respond to the first request, perform secondary authentication on the first terminal, and obtain the authentication result.
[0158] In one embodiment, the second processor 1202 is configured to perform secondary authentication on the first terminal based on configured fourth information; the fourth information includes at least one of the following: User information of the first terminal; Network-related information corresponding to the first terminal.
[0159] In one embodiment, the fourth information further includes a fifth information, the fifth information indicating whether resource management verification is performed on the first terminal; When the fifth information indicates that resource management verification should be performed on the first terminal, the second processor 1202 is further configured to: The resource management verification of the first terminal is performed through the second management platform.
[0160] In one embodiment, the fourth information further includes a sixth information, the sixth information indicating whether a location locking strategy is executed on the first terminal; The second processor 1202 is further configured to, when sending the authentication result to the first function through the second function, use the second communication interface 1201 to send second information to the first function through the second function, the second information indicating whether to verify the location of the first terminal.
[0161] In one embodiment, the fourth information further includes a seventh information, which indicates whether to audit the session information of the first terminal; The second processor 1202 is further configured to, when sending the authentication result to the first function through the second function, use the second communication interface 1201 to send third information to the first function through the second function, wherein the third information indicates whether to audit the services of the first terminal.
[0162] In one embodiment, the second communication interface 1201 is also used to receive fourth information sent by the first management platform.
[0163] It should be noted that the specific processing procedures of the second processor 1202 and the second communication interface 1201 can be understood by referring to the above method.
[0164] Of course, in practical applications, the various components in the AAA server 1200 are coupled together through the bus system 1204. It can be understood that the bus system 1204 is used to implement communication between these components. In addition to the data bus, the bus system 1204 also includes a power bus, a control bus, and a status signal bus. However, for clarity, in... Figure 12 The general labeled all buses as Bus System 1204.
[0165] The second memory 1203 in this embodiment is used to store various types of data to support the operation of the AAA server 1200. Examples of such data include any computer program used to operate on the AAA server 1200.
[0166] The methods disclosed in the embodiments of this application can be applied to the second processor 1202, or implemented by the second processor 1202. The second processor 1202 may be an integrated circuit chip with signal processing capabilities. In the implementation process, each step of the above method can be completed by the integrated logic circuit of the hardware or by instructions in the form of software in the second processor 1202. The second processor 1202 may be a general-purpose processor, a DSP, or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The second processor 1202 can implement or execute the methods, steps, and logic block diagrams disclosed in the embodiments of this application. The general-purpose processor may be a microprocessor or any conventional processor, etc. The steps of the methods disclosed in the embodiments of this application can be directly manifested as being executed by a hardware decoding processor, or being executed by a combination of hardware and software modules in the decoding processor. The software modules may be located in a storage medium, which is located in the second memory 1203. The second processor 1202 reads the information in the second memory 1203 and completes the steps of the aforementioned method in conjunction with its hardware.
[0167] In an exemplary embodiment, the AAA server 1200 may be implemented by one or more ASICs, DSPs, PLDs, CPLDs, FPGAs, general-purpose processors, controllers, MCUs, microprocessors, or other electronic components to perform the aforementioned method.
[0168] Based on the hardware implementation of the above program modules, and in order to implement the method on the first management platform side of the embodiments of this application, the embodiments of this application also provide a first management platform; such as Figure 13 As shown, the first management platform 1300 includes: The third communication interface 1301 is capable of exchanging information with the first function; for example, receiving the first information sent by the first function through the second function. The third processor 1302 is connected to the third communication interface 1301 to enable information interaction with the first function, and is used to execute the methods provided by one or more technical solutions on the first management platform side when running a computer program; The computer program is stored in the third memory 1303.
[0169] Specifically, the third communication interface 1301 is used to receive first information sent by the first function through the second function, the second function being used at least for user plane processing, and the first information includes session-related information between the first terminal and the first device; The third processor 1302 is used to audit the services of the first terminal based on the first information and obtain the audit results.
[0170] In one embodiment, the third processor 1302 is used to audit the services of the first terminal based on the first information and the fourth information configured for the AAA server, wherein the fourth information is used to perform secondary authentication on the first terminal.
[0171] In one embodiment, the third communication interface 1301 is further configured to send an access policy for accessing a private network associated with the terminal location to the third function.
[0172] It should be noted that the specific processing procedures of the third processor 1302 and the third communication interface 1301 can be understood by referring to the above method.
[0173] Of course, in practical applications, the various components in the first management platform 1300 are coupled together through the bus system 1304. It can be understood that the bus system 1304 is used to realize the connection and communication between these components. In addition to the data bus, the bus system 1304 also includes a power bus, a control bus, and a status signal bus. However, for the sake of clarity, in... Figure 13The general designated all buses as Bus System 1304.
[0174] The third memory 1303 in this embodiment is used to store various types of data to support the operation of the first management platform 1300. Examples of such data include any computer program used to operate on the first management platform 1300.
[0175] The methods disclosed in the embodiments of this application can be applied to, or implemented by, the third processor 1302. The third processor 1302 may be an integrated circuit chip with signal processing capabilities. During implementation, each step of the above method can be completed by the integrated logic circuitry of the hardware or by instructions in the software form of the third processor 1302. The third processor 1302 may be a general-purpose processor, a DSP, or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The third processor 1302 can implement or execute the methods, steps, and logic block diagrams disclosed in the embodiments of this application. The general-purpose processor may be a microprocessor or any conventional processor, etc. The steps of the methods disclosed in the embodiments of this application can be directly manifested as execution by a hardware decoding processor, or execution by a combination of hardware and software modules in the decoding processor. The software modules may be located in a storage medium, specifically a third memory 1303. The third processor 1302 reads information from the third memory 1303 and, in conjunction with its hardware, completes the steps of the aforementioned method.
[0176] In an exemplary embodiment, the first management platform 1300 may be implemented by one or more ASICs, DSPs, PLDs, CPLDs, FPGAs, general-purpose processors, controllers, MCUs, microprocessors, or other electronic components to perform the aforementioned method.
[0177] It is understood that the memories (first memory 1103, second memory 1203, and third memory 1303) in the embodiments of this application can be volatile memory or non-volatile memory, or both. Non-volatile memory can be read-only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), magnetic random access memory (FRAM), flash memory, magnetic surface memory, optical disc, or compact disc read-only memory (CD-ROM); magnetic surface memory can be disk storage or magnetic tape storage. Volatile memory can be random access memory (RAM), which is used as an external cache.By way of example, but not limitation, many forms of RAM are available, such as Static Random Access Memory (SRAM), Synchronous Static Random Access Memory (SSRAM), Dynamic Random Access Memory (DRAM), Synchronous Dynamic Random Access Memory (SDRAM), Double Data Rate Synchronous Dynamic Random Access Memory (DDRSDRAM), Enhanced Synchronous Dynamic Random Access Memory (ESDRAM), SyncLink Dynamic Random Access Memory (SLDRAM), and Direct Rambus Random Access Memory (DRRAM). The memories described in the embodiments of this application are intended to include, but are not limited to, these and any other suitable types of memory.
[0178] To implement the methods of the embodiments of this application, the embodiments of this application also provide a communication system, such as... Figure 14 As shown, the system includes: a first function 1401, an AAA server 1402, and a first management platform 1403.
[0179] It should be noted that the specific processing procedures of the first function 1401, AAA server 1402 and first management platform 1403 have been detailed above and will not be repeated here.
[0180] In an exemplary embodiment, this application also provides a storage medium, namely a computer storage medium, specifically a computer-readable storage medium. For example, it may include a first memory 1103 storing a computer program, which can be executed by a first processor 1102 of a first function 1100 to complete the steps described in the aforementioned first function-side method. Another example is a second memory 1203 storing a computer program, which can be executed by a second processor 1202 of an AAA server 1200 to complete the steps described in the aforementioned AAA server-side method. Yet another example is a third memory 1303 storing a computer program, which can be executed by a third processor 1302 of a first management platform 1300 to complete the steps described in the aforementioned first management platform-side method. The computer-readable storage medium may be a memory such as FRAM, ROM, PROM, EPROM, EEPROM, Flash Memory, magnetic surface memory, optical disc, or CD-ROM.
[0181] It should be noted that terms such as "first" and "second" are used to distinguish similar objects, and are not necessarily used to describe a specific order or sequence.
[0182] Furthermore, the technical solutions described in the embodiments of this application can be combined arbitrarily without conflict.
[0183] The above description is merely a preferred embodiment of the present invention and is not intended to limit the scope of protection of the present invention.
Claims
1. A communication method, characterized in that, Applied to the first function, including: If the first terminal successfully authenticates once, a first request is sent to the Authentication, Authorization and Accounting (AAA) server through the second function. The first request is used to request a second authentication for the first terminal. The second function is at least used for user plane processing. Receive the authentication result sent by the AAA server through the second function, and receive the third information sent by the AAA server through the second function, wherein the third information indicates whether to audit the service of the first terminal; If the authentication result indicates that the second authentication of the first terminal is successful, a session is established between the first terminal and the first device; When the third information indicates that the service of the first terminal is to be audited, the first information is obtained. The first information includes session-related information between the first terminal and the first device. The first information includes at least one of the following: device information of the first terminal, network-related information corresponding to the first terminal, traffic-related information of the session, and time-related information of the session. The first information is sent to the first management platform through the second function. The first information is used by the first management platform to audit the service of the first terminal.
2. The method according to claim 1, characterized in that, The method further includes: Receive second information sent by the AAA server through the second function, the second information indicating whether to verify the location of the first terminal; If the second information indicates that the location of the first terminal is to be verified, a second request is sent to the third function. The second request is used to request the access policy of the first terminal at the first location to access the private network. The third function receives the access policy returned based on the second request, the access policy including rules to allow access or rules to block access; If the received access policy contains access permission rules and the secondary authentication is successful, a session is established between the first terminal and the first device.
3. A communication method, characterized in that, Applied to Authentication, Authorization, and Accounting (AAA) servers, including: Receive a first request sent by the first function through the second function, wherein the first request is used to request secondary authentication of the first terminal, and the second function is at least used to perform user plane processing; In response to the first request, the first terminal is subjected to secondary authentication to obtain the authentication result; The authentication result is sent to the first function through the second function, and third information is sent to the first function through the second function, wherein the third information indicates whether to audit the business of the first terminal.
4. The method according to claim 3, characterized in that, The secondary authentication of the first terminal includes: The first terminal is subjected to secondary authentication based on the configured fourth information, wherein the fourth information includes at least one of the following: User information of the first terminal; Network-related information corresponding to the first terminal.
5. The method according to claim 4, characterized in that, The fourth information also includes a fifth information, which indicates whether to perform resource management verification on the first terminal; When the fifth information indicates that resource management verification should be performed on the first terminal, the method further includes the following when authenticating the first terminal: The resource management verification of the first terminal is performed through the second management platform.
6. The method according to claim 4, characterized in that, The fourth information also includes a sixth information, which indicates whether to execute a location locking strategy on the first terminal; When the authentication result is sent to the first function through the second function, second information is sent to the first function through the second function, and the second information indicates whether the location of the first terminal should be verified.
7. The method according to claim 4, characterized in that, The fourth information also includes a seventh information, which indicates whether to audit the session information of the first terminal; When the authentication result is sent to the first function through the second function, third information is sent to the first function through the second function, and the third information indicates whether to audit the business of the first terminal.
8. The method according to any one of claims 4 to 7, characterized in that, The method further includes: Receive the fourth message sent by the first management platform.
9. A communication method, characterized in that, Applied to the first management platform, including: The system receives first information sent by a first function through a second function, the second function being used at least for user plane processing. The first information includes information related to a session between a first terminal and a first device. The first information includes at least one of the following: device information of the first terminal, network-related information corresponding to the first terminal, traffic-related information of the session, and time-related information of the session. Based on the first information, the services of the first terminal are audited to obtain the audit results. The first information is sent by the first function when the third information indicates that the services of the first terminal should be audited. The third information is sent by the Authentication, Authorization and Accounting (AAA) server to the first function through the second function, and the third information indicates whether the services of the first terminal should be audited.
10. The method according to claim 9, characterized in that, The auditing of the services of the first terminal based on the first information includes: Based on the first information and the fourth information configured for the AAA server, the services of the first terminal are audited, and the fourth information is used to perform secondary authentication on the first terminal.
11. The method according to claim 10, characterized in that, The method further includes: Send the access policy for the private network associated with the terminal location to the third function.
12. A communication device, characterized in that, include: The first sending unit is configured to send a first request to the Authentication, Authorization and Accounting (AAA) server via a second function when the first terminal passes the first authentication. The first request is used to request a second authentication for the first terminal. The second function is used to perform user plane processing at least. And send first information to the first management platform through the second function. The first information includes session-related information between the first terminal and the first device. The first information includes at least one of the device information of the first terminal, network-related information corresponding to the first terminal, traffic-related information of the session, and time-related information of the session. The first information is used by the first management platform to audit the services of the first terminal. The first receiving unit is configured to receive the authentication result sent by the AAA server through the second function, and to receive the third information sent by the AAA server through the second function, wherein the third information indicates whether to audit the service of the first terminal. The processing unit is configured to establish a session between the first terminal and the first device when the authentication result indicates that the second authentication of the first terminal has passed. And, if the third information indicates that the services of the first terminal are to be audited, the first information is obtained.
13. A communication device, characterized in that, include: The second receiving unit is used to receive a first request sent by the first function through the second function. The first request is used to request secondary authentication of the first terminal. The second function is used to perform user plane processing at least. The authentication unit is used to respond to the first request, perform secondary authentication on the first terminal, and obtain an authentication result; The second sending unit sends the authentication result to the first function through the second function, and sends third information to the first function through the second function, wherein the third information indicates whether to audit the services of the first terminal.
14. A communication device, characterized in that, include: The third receiving unit is configured to receive first information sent by the first function through the second function, wherein the second function is at least used for user plane processing, and the first information includes session-related information between the first terminal and the first device, wherein the first information includes at least one of the following: device information of the first terminal, network-related information corresponding to the first terminal, traffic-related information of the session, and time-related information of the session. An auditing unit is used to audit the services of the first terminal based on the first information and obtain an audit result. The first information is sent by the first function when the third information indicates that the services of the first terminal should be audited. The third information is sent by the Authentication, Authorization and Accounting (AAA) server to the first function through the second function, and the third information indicates whether the services of the first terminal should be audited.
15. A first function, characterized in that, include: A first communication interface and a first processor; wherein... The first communication interface is configured to, upon successful initial authentication of the first terminal, send a first request to the Authentication, Authorization, and Accounting (AAA) server via a second function, the first request being used to request secondary authentication of the first terminal; the second function is at least used for user plane processing; and to receive authentication results sent by the AAA server via the second function, and to receive third information sent by the AAA server via the second function, the third information indicating whether to audit the services of the first terminal; and to send first information to the first management platform via the second function, the first information containing session-related information between the first terminal and the first device, the first information including at least one of the following: device information of the first terminal, network-related information corresponding to the first terminal, traffic-related information of the session, and time-related information of the session, the first information being used by the first management platform to audit the services of the first terminal; The first processor is configured to establish a session between the first terminal and the first device when the authentication result indicates that the second authentication of the first terminal has passed; and to obtain the first information through the first communication interface when the third information indicates that the service of the first terminal is to be audited.
16. An Authentication, Authorization, and Accounting (AAA) server, characterized in that, include: A second communication interface and a second processor; wherein... The second communication interface is used to receive a first request sent by the first function through the second function, the first request being used to request secondary authentication of the first terminal, the second function being used at least for user plane processing; and to send an authentication result to the first function through the second function, and to send third information to the first function through the second function, the third information indicating whether to audit the services of the first terminal; The second processor is configured to respond to the first request, perform secondary authentication on the first terminal, and obtain the authentication result.
17. A first management platform, characterized in that, include: A third communication interface and a third processor; wherein... The third communication interface is used to receive first information sent by the first function through the second function. The second function is at least used for user plane processing. The first information includes session-related information between the first terminal and the first device. The first information includes at least one of the following: device information of the first terminal, network-related information corresponding to the first terminal, traffic-related information of the session, and time-related information of the session. The third processor is used to audit the services of the first terminal based on the first information and obtain an audit result. The first information is sent by the first function when the third information indicates that the services of the first terminal should be audited. The third information is sent by the Authentication, Authorization and Accounting (AAA) server to the first function through the second function, and the third information indicates whether the services of the first terminal should be audited.
18. A first function, characterized in that, include: A first processor and a first memory for storing computer programs capable of running on the processor; Wherein, when the first processor is used to run the computer program, it performs the steps of the method according to any one of claims 1 to 2.
19. An Authentication, Authorization, and Accounting (AAA) server, characterized in that, include: A second processor and a second memory for storing computer programs capable of running on the processor; Wherein, when the second processor is used to run the computer program, it performs the steps of the method according to any one of claims 3 to 8.
20. A first management platform, characterized in that, include: A third processor and a third memory for storing computer programs that can run on the processor; When the third processor runs the computer program, it performs the steps of the method according to any one of claims 9 to 11.
21. A storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, it implements the steps of the method according to any one of claims 1 to 2, or the steps of the method according to any one of claims 3 to 8, or the steps of the method according to any one of claims 9 to 11.
Citation Information
Patent Citations
Authentication method and device, session management function entity, server and terminal
CN114024693A
MBMS informaiton acquisition and transmission method, terminal device and network element device
WO2021109134A1