User terminal access network security authentication method, device and electronic equipment
By introducing the SANF network element, differentiated security configuration files are generated based on information from user terminals and access networks, solving the problem that the 5G security authentication process cannot meet the personalized needs of various business scenarios, and realizing flexible security authentication configuration.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- ZTE CORP
- Filing Date
- 2022-07-29
- Publication Date
- 2026-05-29
AI Technical Summary
The existing 5G security authentication process uses the same level of security authentication and key negotiation process, which cannot meet the personalized security needs of various different business scenarios.
The SANF network element, which introduces a security algorithm negotiation function, generates differentiated security configuration files based on the user terminal's terminal type, user subscription identifier, and access network type, and then transmits these files to the user terminal to complete the security authentication process.
It enables differentiated security authentication for different business scenarios, supports flexible configuration of multiple authentication modes, key derivation algorithms and key lengths, and improves the flexibility and adaptability of security authentication.
Smart Images

Figure CN117527280B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of mobile communication technology, and in particular to a secure authentication method, apparatus and electronic device for user terminal accessing a network. Background Technology
[0002] The 5G network introduces three major service scenarios, each with different security requirements based on its own characteristics. The subsequent evolution to the 6G network will further expand the application scenarios, thus further increasing the personalized security requirements.
[0003] Currently, existing 5G security authentication processes employ the same level of security authentication and key negotiation, which is insufficient to address the personalized security needs of various business scenarios. Therefore, how to negotiate differentiated security authentication based on the capabilities and security requirements of user terminals and access networks has become a pressing technical challenge. Summary of the Invention
[0004] This application provides a secure authentication method, apparatus, and electronic device for user terminal access to a network, in order to address the problem that the existing 5G security authentication process uses the same level of security authentication and key negotiation process, which is not flexible enough to meet the personalized security needs of various different business scenarios.
[0005] Firstly, this application provides a security authentication method for user terminal accessing a network, applied to a Security Algorithm Negotiation (SANF) network element, the method comprising:
[0006] When a user terminal accesses a network, security information about the user terminal and the access network is obtained. The security information includes the terminal type of the user terminal, the user subscription identifier of the user terminal, and the type of the access network.
[0007] Based on the terminal type, the user subscription identifier, and the access network type, determine the configuration parameters used to generate the security configuration file;
[0008] The security configuration file is generated based on the configuration parameters and then transmitted to the user terminal so that the user terminal can complete the security authentication process for accessing the network based on the security configuration file.
[0009] Optionally, determining the configuration parameters for generating the security configuration file based on the terminal type, the user subscription identifier, and the access network type includes:
[0010] The system receives user subscription messages sent by the Unified Data Management (UDM) network element, as well as the authentication mode types supported by the user terminal and the access network. The user subscription message is obtained by the UDM network element based on the user subscription identifier, and the authentication mode types supported by the user terminal and the access network are obtained by the UDM network element from the Authentication Credentials Store (ARPF) network element based on the user subscription identifier.
[0011] Based on the user subscription message, the authentication mode types supported by the user terminal and the access network, and the obtained terminal type and access network type, the configuration parameters used to generate the security configuration file are determined.
[0012] Optionally, if the user subscription identifier is a hidden subscription identifier type, the UDM network element needs to decrypt the user subscription identifier through the subscription identifier decryption function SIDF network element, and obtain the user subscription message, the user credential, and the authentication mode type supported by the user terminal and the access network based on the decrypted user subscription identifier. The SIDF network element decrypts the user subscription identifier based on the user credential, which is obtained by the UDM network element from the ARPF network element based on the user subscription identifier.
[0013] When the user subscription identifier is a permanent user subscription identifier, the UDM network element directly obtains the user subscription message, the user credentials, and the authentication mode types supported by the user terminal and the access network based on the user subscription identifier.
[0014] Optionally, transmitting the security configuration file to the user terminal includes:
[0015] The security configuration file is passed to the UDM network element, wherein the UDM network element is used to treat the security configuration file as a new information element field, and performs integrity protection processing on the new information element field. The information element field after integrity protection processing is then passed to the user terminal through the authentication server function AUSF network element and the security anchor function SEAF network element in sequence.
[0016] Optionally, the UDM network element is further configured to generate a home environment authentication vector according to the security configuration file, and transmit the authentication token in the home environment authentication vector and the information element field after integrity protection processing to the user terminal in sequence through the AUSF network element and the SEAF network element;
[0017] The AUSF network element is used to determine the service environment authentication vector based on the home environment authentication vector, and send the service environment authentication vector and the information element field after integrity protection processing to the SEAF network element; the SEAF network element is used to send the service environment authentication vector and the information element field after integrity protection processing to the user terminal; the service environment authentication vector includes the authentication token; the user terminal is used to perform timeliness verification based on the authentication token and integrity verification on the information element field after integrity protection processing, and if the timeliness verification is successful and the integrity verification is successful, the user terminal completes the security authentication process for accessing the network based on the information element field after successful integrity verification.
[0018] Optionally, when a user terminal accesses the network, obtaining the security information of the user terminal and the access network includes:
[0019] When the user terminal requests network access, the security information sent by the UDM network element is received. The UDM network element, upon receiving a first authentication request from the AUSF network element, parses the first authentication request to obtain the security information carried in the first authentication request and sends the security information to the SANF network element. The first authentication request is generated by the AUSF network element upon receiving a second authentication request from the SEAF network element, and the second authentication request is generated by the SEAF network element upon receiving a registration request from the user terminal. The second authentication request carries the terminal type, the user subscription identifier, and the type of network access. The registration request is generated when the user terminal accesses the network, and the registration request carries the terminal type and the user subscription identifier.
[0020] Optionally, the configuration parameters include parameters for characterizing the authentication mode type, parameters for characterizing the key derivation algorithm, and parameters for characterizing the key length.
[0021] Secondly, this application also provides a security authentication device for user terminal access to a network, applied to a Security Algorithm Negotiation (SANF) network element, the device comprising:
[0022] The acquisition module is used to acquire security information of the user terminal and the access network, the security information including the terminal type of the user terminal, the user subscription identifier of the user terminal, and the type of the access network;
[0023] The determining module is used to determine the configuration parameters for generating the security configuration file based on the terminal type, the user subscription identifier, and the type of the access network;
[0024] The transmission module is used to generate the security configuration file according to the configuration parameters and transmit the security configuration file to the user terminal so that the user terminal can complete the security authentication process for accessing the network according to the security configuration file.
[0025] Thirdly, this application also provides an electronic device, including a processor, a communication interface, a memory, and a communication bus, wherein the processor, the communication interface, and the memory communicate with each other through the communication bus;
[0026] Memory, used to store computer programs;
[0027] When a processor executes a program stored in a memory, it implements the steps of the secure authentication method for user terminal accessing a network as described in any embodiment of the first aspect.
[0028] Fourthly, this application also provides a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the steps of the security authentication method for user terminal accessing a network as described in any embodiment of the first aspect.
[0029] In this embodiment, when a user terminal accesses a network, security information about the user terminal and the access network is obtained. This security information includes the user terminal's terminal type, the user terminal's user subscription identifier, and the access network type. Based on the terminal type, user subscription identifier, and access network type, configuration parameters for generating a security configuration file are determined. The security configuration file is generated based on these parameters and transmitted to the user terminal, allowing the user terminal to complete the network access security authentication process. This approach allows for the addition of a Security Algorithm Negotiation Function (SANF) network element on the network side. The SANF network element generates a security configuration file that meets the capabilities and security requirements of the user terminal and the access network based on the user terminal's terminal type, user subscription identifier, and access network type. This security configuration file is then transmitted to the user terminal, enabling the user terminal to complete the network access security authentication process. This allows for the generation of differentiated security configuration files for different terminal types, access network types, and user subscription identifiers under different business scenarios, achieving differentiated security authentication. Attached Figure Description
[0030] The accompanying drawings, which are incorporated in and form part of this specification, illustrate embodiments consistent with the invention and, together with the description, serve to explain the principles of the invention.
[0031] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, for those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0032] Figure 1 A flowchart illustrating a security authentication method for a user terminal accessing a network, provided in an embodiment of this application;
[0033] Figure 2 A schematic diagram of the structure of a SANF network element for security algorithm negotiation function provided in an embodiment of this application;
[0034] Figure 3 A schematic diagram illustrating a process for generating a security configuration file, provided as an embodiment of this application;
[0035] Figure 4 A schematic diagram of a user terminal authentication response provided in an embodiment of this application;
[0036] Figure 5 This is a schematic diagram of a process for obtaining security information provided in an embodiment of this application;
[0037] Figure 6 This application provides a schematic diagram of the structure of a security authentication device for user terminal accessing a network.
[0038] Figure 7 This is a schematic diagram of the structure of an electronic device provided in an embodiment of this application. Detailed Implementation
[0039] To make the objectives, technical solutions, and advantages of the embodiments of this application clearer, the technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.
[0040] See Figure 1 , Figure 1 This is a flowchart illustrating a security authentication method for user terminal accessing a network, provided in an embodiment of this application. This security authentication method for user terminal accessing a network is applied to the Security Algorithm Negotiation Function (SANF) network element, and the method may include the following steps:
[0041] Step 101: When the user terminal accesses the network, obtain the security information of the user terminal and the access network. The security information includes the terminal type of the user terminal, the user subscription identifier of the user terminal, and the type of access network.
[0042] It should be noted that the security authentication method for user terminal access to the network is applied to the Security Algorithm Negotiation Function (SANF) network element. This SANF network element can be a logical function on the Unified Data Management (UDM) side of the home network, or a logical function independent of the UDM network element. The main functional modules of this SANF network element can include a user and network security information collection module, a security algorithm analysis and decision-making module, and a security differential configuration file transmission module. The user and network security information collection module collects information such as the user equipment (UE) terminal type, the type of network accessed, and the user subscription identifier of the user terminal. The security algorithm analysis and decision-making module analyzes and judges the collected user information and security capabilities, combined with network-related information, to select appropriate authentication modes, security algorithms, key lengths, and other security information data. The security differential configuration file transmission module generates a differential security configuration file from the selected security information data, providing guidance and configuration for subsequent authentication, key negotiation, and security algorithm negotiation for the user terminal. The internal structure of this SANF network element is as follows: Figure 2 As shown.
[0043] Specifically, when a user terminal accesses the network, this SANF network element can obtain security information about the user terminal and the access network. This security information may include, but is not limited to, the user terminal's terminal type, the user terminal's user subscription identifier, and the type of access network. It should be noted that the user terminal type can be categorized based on its capabilities into low-power, medium-power, and high-power terminals. The user terminal's user subscription identifier can include a Subscription Permanent Identifier (SUPI) and a Subscription Concealed Identifier (SUCI), where SUCI is the encrypted output of SUPI. Access networks can be categorized into 3GPP access networks and Non-3GPP access networks. 3GPP access networks refer to those defined by the 3GPP organization, such as Long Term Evolution (LTE), Wideband Code Division Multiple Access (WCDMA), Time Division-Synchronous Code Division Multiple Access (TD-SCDMA), and Global System for Mobile Communications (GSM). Non-3GPP access networks refer to those not defined by the 3GPP organization, such as Wireless Local Area Networks (WLAN) and High Rate Packet Data (HRPD).
[0044] Step 102: Determine the configuration parameters used to generate the security profile based on the terminal type, user subscription identifier, and access network type.
[0045] In this step, the SANF network element can determine the capabilities of the user terminal and access network, as well as the security requirements of the user terminal in the current business scenario, based on the terminal type, user subscription identifier, and access network type. Then, based on these capabilities, it determines the configuration parameters of the security profile corresponding to the user terminal. Specifically, the configuration parameters of the security profile may include, but are not limited to, parameters characterizing the authentication mode type, parameters characterizing the key derivation algorithm, and parameters characterizing the key length. It should be noted that the authentication mode type can include existing 5G-AKA and EAP-AKA', or other authentication modes such as EAP-TLS can be introduced. Even lightweight or heavyweight authentication modes can be introduced to adapt to different application scenarios and security requirements. The key derivation algorithm can include national cryptographic algorithms SM3 and SM4, as well as other key derivation algorithms required or specified by the enterprise or operator. The key length supports 128 bits, 256 bits, 512 bits, etc.
[0046] Step 103: Generate a security configuration file based on the configuration parameters and pass the security configuration file to the user terminal so that the user terminal can complete the security authentication process for accessing the network based on the security configuration file.
[0047] In this step, the SANF network element can generate a security profile (SP) based on the configuration parameters and pass the security profile to the user terminal. The user terminal performs security configuration production based on the security profile, generates its own security profile, and uses its own security profile to generate the parameters required for authentication and key deduction, thereby completing the security authentication process for accessing the network, as well as the subsequent security processing and security protection process, and realizing secure network access for the user terminal.
[0048] In this embodiment, a Security Algorithm Negotiation (SANF) network element can be added to the network side. The SANF network element generates a security configuration file that conforms to the capabilities and security requirements of the user terminal and the access network based on the user terminal's terminal type, user subscription identifier, and access network type. This security configuration file is then transmitted to the user terminal, enabling the user terminal to complete the security authentication process for accessing the network according to the configuration file. This allows for the generation of differentiated security configuration files for different terminal types, access network types, and user subscription identifiers under different service scenarios, achieving differentiated security authentication.
[0049] Further, step 102 above, based on the terminal type, user subscription identifier, and access network type, determines the configuration parameters used to generate the security configuration file, including:
[0050] It receives user subscription messages sent by the Unified Data Management (UDM) network element, as well as the authentication mode types supported by the user terminal and the access network. The user subscription message is obtained by the UDM network element based on the user subscription identifier, and the authentication mode types supported by the user terminal and the access network are obtained by the UDM network element from the Authentication Credentials Store (ARPF) network element based on the user subscription identifier.
[0051] Based on the user's subscription messages, the authentication mode types supported by the user's terminal and the access network, as well as the obtained terminal type and access network type, determine the configuration parameters used to generate the security configuration file.
[0052] In one embodiment, the SANF network element can interact with the Unified Data Management (UDM) network element to determine the configuration parameters used to generate the security profile. Specifically, the UDM network element can obtain user subscription messages based on the user subscription identifier. The UDM network element can also obtain the authentication mode types supported by the user terminal and access network from the Authentication Credential Repository and Processing Function (ARPF) network element based on the user subscription identifier. Then, the UDM network element can send the user subscription messages, the authentication mode types supported by the user terminal and access network, and the obtained terminal type and access network type to the SANF network element. The SANF network element determines the configuration parameters used to generate the security profile based on the user subscription messages, the authentication mode types supported by the user terminal and access network, and the obtained terminal type and access network type. Figure 3 As shown. It should be noted that the user subscription messages here include, but are not limited to, application-layer authentication and key management subscriptions (AMKA subscription), authentication subscriptions, key derivation algorithm subscriptions, and key length subscriptions.
[0053] Furthermore, when the user subscription identifier is a user-hidden subscription identifier type, the UDM network element needs to decrypt the user subscription identifier through the subscription identifier decryption function SIDF network element, and obtain the user subscription message, user credentials, and the authentication mode type supported by the user terminal and access network based on the decrypted user subscription identifier. Here, the SIDF network element decrypts the user subscription identifier based on the user credentials, and the user credentials are obtained by the UDM network element from the ARPF network element based on the user subscription identifier.
[0054] When the user subscription identifier is a permanent user subscription identifier, the UDM network element directly obtains the user subscription message, user credentials, and the authentication mode type supported by the user terminal and the access network based on the user subscription identifier.
[0055] See also Figure 3 When the user subscription identifier is a hidden subscription identifier type (SUCI), the UDM network element can also use fields such as the protection scheme ID and home network public key ID in the SUCI to obtain user credentials and the authentication mode types supported by the user terminal and the access network from the ARPF network element. The UDM network element can also decrypt the user subscription identifier from the Subscription Identifier De-concealing Function (SIDF) network element based on the user credentials, and then use the decrypted user subscription identifier to obtain the user subscription message.
[0056] When the user subscription identifier is a Permanent Subscription Identifier (SUPI), the UDM network element can also directly obtain user credentials and the authentication mode types supported by the user terminal and access network from the ARPF network element based on the SUPI. The UDM network element can also directly obtain user subscription messages based on the user subscription identifier.
[0057] Furthermore, step 103 above, transmitting the security configuration file to the user terminal, includes:
[0058] The security configuration file is passed to the UDM network element, which uses the security configuration file as a new information element field and performs integrity protection processing on the new information element field. The information element field after integrity protection processing is then passed to the user terminal through the authentication server function AUSF network element and the security anchor function SEAF network element in sequence.
[0059] In one embodiment, after the SANF network element generates a security configuration file, it can pass the security configuration file to the UDM network element. The UDM network element can then use the security configuration file as a newly added Information Element (SPIE) field, perform integrity protection processing on the newly added SPIE field, and then pass the integrity-protected SPIE field to the user terminal sequentially through the Authentication Server Function (AUSF) network element and the Security Anchor Function (SEAF) network element. Figure 4 As shown. In this way, the user terminal can generate the relevant security configuration file and subsequent key deduction according to the instructions of SP IE, and reply to the network side authentication response message.
[0060] Furthermore, the UDM network element is also used to generate a home environment authentication vector based on the security configuration file, and to transmit the authentication token and the information element field after integrity protection processing in the home environment authentication vector to the user terminal in sequence through the AUSF network element and the SEAF network element.
[0061] The AUSF network element determines the service environment authentication vector based on the home environment authentication vector and sends the service environment authentication vector and the information element fields after integrity protection processing to the SEAF network element. The SEAF network element sends the service environment authentication vector and the information element fields after integrity protection processing to the user terminal. The service environment authentication vector includes an authentication token. The user terminal performs timeliness verification based on the authentication token and integrity verification on the information element fields after integrity protection processing. If both timeliness and integrity verification are successful, the user terminal completes the security authentication process for accessing the network based on the information element fields that have successfully verified integrity.
[0062] See Figure 4 The UDM network element can also generate a 5G HomeEnvironment Authentication Vector (5G HEAV) based on this security configuration file, and use the authentication token (AUTN) in the 5G HEAV and the information element field after integrity protection processing as the authentication response message (i.e., Figure 4The Nudm_UEAuthentication_Get Response is passed to the AUSF network element. The AUSF network element can determine the 5G Service Environment Authentication Vector (5G SEAV) based on the home environment authentication vector, and use the authentication token and the information element field after integrity protection processing in the service environment authentication vector as the authentication response message (i.e., Figure 4 The Nausf_UEAuthentication_Authenticate Response is sent to the SEAF network element; the SEAF network element can use the service environment authentication vector and the information element field after integrity protection processing as the authentication request (i.e., Figure 4 The authentication request (ARequest) is sent to the user terminal. Finally, the user terminal verifies the validity of the authentication request message using the authentication token and performs integrity verification on the information element fields after integrity protection. Specifically, the network side uses the user terminal's private key to protect the SPIE's integrity. After receiving the authentication request from the network side, the user terminal verifies the validity of the authentication request message using the AUTN in the authentication request. After confirming that the validity of the authentication request message is acceptable, the user terminal verifies the integrity of the SPIE using the network side's public key. If the integrity verification fails, the user terminal replies with an authentication failure message to the network side; if the integrity verification succeeds, the user terminal generates a relevant security configuration file and subsequent key deduction based on the information element fields of the successful integrity verification and replies with an authentication response message to the network side (i.e., ...). Figure 4 The authentication response (in the configuration file) completes the secure authentication process for network access. This effectively prevents the SPIE from being tampered with during transmission, improving the security of the security configuration file transmission.
[0063] Furthermore, step 101 above, when the user terminal accesses the network, involves obtaining security information about the user terminal and the access network, including:
[0064] When a user terminal requests network access, it receives security information sent by a UDM network element. The UDM network element, upon receiving a first authentication request from an AUSF network element, parses the first authentication request to obtain the security information carried in it and sends the security information to the SANF network element. The first authentication request is generated by the AUSF network element upon receiving a second authentication request from a SEAF network element. The second authentication request is generated by the SEAF network element upon receiving a registration request from a user terminal. The second authentication request carries the terminal type, user subscription identifier, and network access type. The registration request is generated when the user terminal accesses the network and carries the terminal type and user subscription identifier.
[0065] In one embodiment, when a user terminal requests network access, the SANF network element can obtain security information from the UDM network element. Specifically, such as... Figure 5 As shown, the user terminal (UE) initiates a registration request in the access network (i.e. Figure 5 The Registration Request message carries the UE type, SUCI, or 5G Globally Unique Temporary UE Identity (5G-GUTI) and is sent to the Security Anchor Function (SEAF) network element of the serving network. The SEAF network element then sends a second authentication request (i.e., ... Figure 5 The AUSF network element sends a Nausf_UEAuthentication_Authenticate Request message to the AUSF network element to invoke the Nausf_UEAuthentication service. The second authentication request carries the SUCI or the SUPI mapped to 5G-GUTI, and the Serving Network Name (SNN). The SNN can include the Serving Network Identifier (SN ID) and the Access Network Type. Upon receiving the second authentication message, the AUSF network element compares the Serving Network Name carried in the second authentication request message with the Serving Network Name of the pre-defined user terminal's Serving Network. This verifies whether the SEAF network element of the Serving Network is authorized to use the Serving Network Name in the second authentication request message, and also verifies the corresponding Access Network Type. If the Serving Network is not authorized to use the Serving Network Name in the second authentication request message, it replies with "Serving Network Not Authorized." Otherwise, the AUSF network element considers the Serving Network to be authorized to use the Serving Network Name in the second authentication request message. At this point, the AUSF network element initiates the first authentication request (i.e., ... Figure 5 The UDM network element sends a Nudm_UEAuthentication_Get Request message to the SANF network element. This first authentication request carries either SUCI or SUPI, as well as the service network name. After receiving the Nudm_UEAuthentication_Get Request message, the UDM network element sends the security information carried in the message to the SANF network element, which then generates a security profile.
[0066] It should be noted that, Figure 5 This is an improvement to the existing 5G security authentication process. For example, a SANF network element has been added to the existing process. When a user terminal initiates a registration request to access the network, in addition to carrying SUCI or 5G-GUTI, it can also carry the UE type. When the SEAF network element sends a second authentication request to the AUSF network element and when the AUSF network element sends a first authentication request to the UDM network element, in addition to carrying SN ID, SUCI or SUPI, it can also carry the access network type.
[0067] Furthermore, the configuration parameters include parameters for characterizing the authentication mode type, parameters for characterizing the key derivation algorithm, and parameters for characterizing the key length.
[0068] The following explanation uses a dense mMTC (massive machine-type communication) access scenario as an example. In this scenario, 5G requires millions of access points per square kilometer, while 6G requires tens of millions per square kilometer. Such dense terminal access will have a significant impact on network access authentication. It is questionable whether the existing 5G unified authentication architecture can meet the capacity expansion needs of subsequent mobile networks. Introducing SANF network elements allows for flexible configuration of user security profiles, selecting appropriate authentication modes and security processing based on terminal type and user subscription data.
[0069] Specifically, when a UE accesses the network, it initiates a registration request, carrying the terminal type, which is a low-power terminal in mMTC. After receiving the UE's registration request, the network side selects a matching lightweight access authentication mode, a simplified key derivation algorithm, and a suitable key length, etc., as a Security Profile based on the UE's terminal type and subscribed data information. The network side generates a simplified 5G HE AV based on the generated Security Profile and instructs the SP information to the UE via SPIE. Finally, the UE completes the mutual security authentication process with the network side based on the SPIE instruction information and the authentication information from the network side.
[0070] In this application, the security capabilities of the UE and the network are negotiated and processed in a unified manner. The UE's own capabilities and subscription information are comprehensively considered, and differentiated automatic matching is formed based on the UE's capabilities, UE classification, and user subscription preferences. This approach achieves the following technical effects:
[0071] First, the authentication mode can be expanded to include multiple authentication modes, not only the existing 5G-AKA and EAP-AKA, but also other authentication modes such as EAP-TLS. In order to adapt to different application scenarios and different security requirements, lightweight or heavyweight authentication modes can be introduced.
[0072] Second, it supports flexible expansion of key deduction algorithms. Current key deduction algorithms are fixed; by expanding the key deduction algorithms, national cryptographic algorithms SM3 and SM4 can be introduced. Furthermore, to meet the specific needs of industry private networks, key deduction algorithms required or specified by enterprises or operators can be introduced.
[0073] Third, easy upward scaling of key length. Currently, 5G authentication and key negotiation use a 128-bit key length, which is a direct parameter reflecting security capabilities. This fixed-key-length encryption algorithm cannot reflect the differences in security requirements. For high-security scenarios, such as applications against quantum attacks, 128 bits is no longer sufficient, necessitating support for longer key lengths. Scalable key lengths do not mean arbitrarily specifying a key length; rather, they support multiple key lengths (such as 128 bits, 256 bits, etc.). Depending on the scenario and security requirements, the key length can be selected to meet current needs.
[0074] IV. Flexible Support for the Expansion of Other Security Capabilities. Security capability expansion includes, but is not limited to, the three parameters described above, and can be flexibly expanded according to subsequent needs. For this flexible expansion of security capabilities and support for multi-level security capabilities, it is essential to introduce an arbitration negotiation function to match and negotiate security capabilities based on security requirements, providing the optimal security combination for different application scenarios. The introduction of the full algorithm negotiation function (SANF) can automatically match the parameters described above based on the user's subscription mechanism, terminal type, or access network type.
[0075] Compared to existing technologies, this application is not simply a combination of technologies, but rather uses the concept of big data to collect data such as users' security capabilities and subscription information. Through comprehensive analysis and judgment algorithms, it can provide differentiated security matching for different terminals and different user preferences.
[0076] See Figure 6 , Figure 6A security authentication device for user terminal accessing a network, provided in this application embodiment, is applied to a Security Algorithm Negotiation (SANF) network element. The device 600 includes:
[0077] The acquisition module 601 is used to acquire security information of the user terminal and the access network. The security information includes the terminal type of the user terminal, the user subscription identifier of the user terminal, and the type of access network.
[0078] The determination module 602 is used to determine the configuration parameters for generating the security configuration file based on the terminal type, user subscription identifier, and access network type.
[0079] The transmission module 603 is used to generate a security configuration file according to the configuration parameters and transmit the security configuration file to the user terminal so that the user terminal can complete the security authentication process for accessing the network according to the security configuration file.
[0080] Furthermore, module 602 is determined to include:
[0081] The first receiving submodule is used to receive user subscription messages sent by the Unified Data Management (UDM) network element and the authentication mode types supported by the user terminal and the access network. The user subscription message is obtained by the UDM network element based on the user subscription identifier, and the authentication mode types supported by the user terminal and the access network are obtained by the UDM network element from the Authentication Credentials Store (ARPF) network element based on the user subscription identifier.
[0082] The determination submodule is used to determine the configuration parameters for generating the security configuration file based on the user subscription message, the authentication mode type supported by the user terminal and the access network, as well as the obtained terminal type and access network type.
[0083] Furthermore, when the user subscription identifier is a user-hidden subscription identifier type, the UDM network element needs to decrypt the user subscription identifier through the subscription identifier decryption function SIDF network element, and obtain the user subscription message, user credentials, and the authentication mode type supported by the user terminal and access network based on the decrypted user subscription identifier. Here, the SIDF network element decrypts the user subscription identifier based on the user credentials, and the user credentials are obtained by the UDM network element from the ARPF network element based on the user subscription identifier.
[0084] When the user subscription identifier is a permanent user subscription identifier, the UDM network element directly obtains the user subscription message, user credentials, and the authentication mode type supported by the user terminal and the access network based on the user subscription identifier.
[0085] Furthermore, the transmission module 603 includes:
[0086] The delivery submodule is used to pass the security configuration file to the UDM network element. The UDM network element uses the security configuration file as a new information element field and performs integrity protection processing on the new information element field. The integrity-protected information element field is then passed to the user terminal through the authentication server function AUSF network element and the security anchor point function SEAF network element in sequence.
[0087] Furthermore, the UDM network element is also used to generate a home environment authentication vector based on the security configuration file, and to transmit the authentication token and the information element field after integrity protection processing in the home environment authentication vector to the user terminal in sequence through the AUSF network element and the SEAF network element.
[0088] The AUSF network element determines the service environment authentication vector based on the home environment authentication vector and sends the service environment authentication vector and the information element fields after integrity protection processing to the SEAF network element. The SEAF network element sends the service environment authentication vector and the information element fields after integrity protection processing to the user terminal. The service environment authentication vector includes an authentication token. The user terminal performs timeliness verification based on the authentication token and integrity verification on the information element fields after integrity protection processing. If both timeliness and integrity verification are successful, the user terminal completes the security authentication process for accessing the network based on the information element fields that have successfully verified integrity.
[0089] Furthermore, the acquisition module 601 includes:
[0090] The second receiving submodule is used to receive security information sent by the UDM network element when a user terminal requests network access. The UDM network element, upon receiving a first authentication request from the AUSF network element, parses the first authentication request to obtain the security information carried in it and sends the security information to the SANF network element. The first authentication request is generated by the AUSF network element upon receiving a second authentication request from the SEAF network element, and the second authentication request is generated by the SEAF network element upon receiving a registration request from the user terminal. The second authentication request carries the terminal type, user subscription identifier, and network access type. The registration request is generated when the user terminal accesses the network and carries the terminal type and user subscription identifier.
[0091] Furthermore, the configuration parameters include parameters for characterizing the authentication mode type, parameters for characterizing the key derivation algorithm, and parameters for characterizing the key length.
[0092] It should be noted that the security authentication device 600 for user terminal access to the network can implement the steps of the security authentication method for user terminal access to the network provided in any of the aforementioned method embodiments, and can achieve the same technical effect, which will not be described in detail here.
[0093] like Figure 7 As shown in the figure, this application provides an electronic device, including a processor 711, a communication interface 712, a memory 713, and a communication bus 714, wherein the processor 711, the communication interface 712, and the memory 713 communicate with each other through the communication bus 714.
[0094] Memory 713 is used to store computer programs;
[0095] In one embodiment of this application, when the processor 711 executes the program stored in the memory 713, it implements the security authentication method for user terminal accessing the network provided in any of the foregoing method embodiments, including:
[0096] When a user terminal accesses the network, security information about the user terminal and the access network is obtained. The security information includes the terminal type of the user terminal, the user subscription identifier of the user terminal, and the type of access network.
[0097] Based on the terminal type, user subscription identifier, and access network type, determine the configuration parameters used to generate the security profile;
[0098] A security configuration file is generated based on the configuration parameters and then transmitted to the user terminal so that the user terminal can complete the security authentication process for accessing the network based on the security configuration file.
[0099] This application also provides a computer-readable storage medium storing a computer program thereon, which, when executed by a processor, implements the steps of the security authentication method for user terminal accessing the network provided in any of the foregoing method embodiments.
[0100] It should be noted that, in this document, relational terms such as "first" and "second" are used merely to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitations, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes said element.
[0101] The above description is merely a specific embodiment of the present invention, enabling those skilled in the art to understand or implement the invention. Various modifications to these embodiments will be readily apparent to those skilled in the art, and the general principles defined herein may be implemented in other embodiments without departing from the spirit or scope of the invention. Therefore, the present invention is not to be limited to the embodiments shown herein, but is to be accorded the widest scope consistent with the principles and novel features claimed herein.
Claims
1. A secure authentication method for user terminal accessing a network, characterized in that, The method, applied to the SANF network element for security algorithm negotiation, includes: When a user terminal accesses a network, security information about the user terminal and the access network is obtained. The security information includes the terminal type of the user terminal, the user subscription identifier of the user terminal, and the type of the access network. Based on the terminal type, the user subscription identifier, and the access network type, configuration parameters for generating the security configuration file are determined; the configuration parameters include parameters for characterizing the authentication mode type. The security configuration file is generated based on the configuration parameters and then transmitted to the user terminal so that the user terminal can complete the security authentication process for accessing the network based on the security configuration file.
2. The method according to claim 1, characterized in that, The step of determining the configuration parameters for generating the security configuration file based on the terminal type, the user subscription identifier, and the access network type includes: The system receives user subscription messages sent by the Unified Data Management (UDM) network element, as well as the authentication mode types supported by the user terminal and the access network. The user subscription message is obtained by the UDM network element based on the user subscription identifier, and the authentication mode types supported by the user terminal and the access network are obtained by the UDM network element from the Authentication Credentials Store (ARPF) network element based on the user subscription identifier. Based on the user subscription message, the authentication mode types supported by the user terminal and the access network, and the obtained terminal type and access network type, the configuration parameters used to generate the security configuration file are determined.
3. The method according to claim 2, characterized in that, When the user subscription identifier is of the hidden user subscription identifier type, the UDM network element needs to decrypt the user subscription identifier through the subscription identifier decryption function SIDF network element, and obtain the user subscription message, user credentials, and the authentication mode type supported by the user terminal and the access network based on the decrypted user subscription identifier. The SIDF network element decrypts the user subscription identifier based on the user credentials, and the user credentials are obtained by the UDM network element from the ARPF network element based on the user subscription identifier. When the user subscription identifier is a permanent user subscription identifier, the UDM network element directly obtains the user subscription message, the user credentials, and the authentication mode types supported by the user terminal and the access network based on the user subscription identifier.
4. The method according to claim 2, characterized in that, The step of transmitting the security configuration file to the user terminal includes: The security configuration file is passed to the UDM network element, wherein the UDM network element is used to treat the security configuration file as a new information element field, and performs integrity protection processing on the new information element field. The information element field after integrity protection processing is then passed to the user terminal through the authentication server function AUSF network element and the security anchor function SEAF network element in sequence.
5. The method according to claim 4, characterized in that, The UDM network element is also used to generate a home environment authentication vector according to the security configuration file, and to transmit the authentication token in the home environment authentication vector and the information element field after integrity protection processing to the user terminal in sequence through the AUSF network element and the SEAF network element. The AUSF network element is used to determine the service environment authentication vector based on the home environment authentication vector, and send the service environment authentication vector and the information element field after integrity protection processing to the SEAF network element; the SEAF network element is used to send the service environment authentication vector and the information element field after integrity protection processing to the user terminal; the service environment authentication vector includes the authentication token; the user terminal is used to perform timeliness verification based on the authentication token and integrity verification on the information element field after integrity protection processing, and if the timeliness verification is successful and the integrity verification is successful, the user terminal completes the security authentication process for accessing the network based on the information element field after successful integrity verification.
6. The method according to claim 4, characterized in that, When a user terminal accesses the network, obtaining the security information of the user terminal and the access network includes: When the user terminal requests network access, the security information sent by the UDM network element is received. The UDM network element, upon receiving a first authentication request from the AUSF network element, parses the first authentication request to obtain the security information carried in the first authentication request and sends the security information to the SANF network element. The first authentication request is generated by the AUSF network element upon receiving a second authentication request from the SEAF network element, and the second authentication request is generated by the SEAF network element upon receiving a registration request from the user terminal. The second authentication request carries the terminal type, the user subscription identifier, and the type of network access. The registration request is generated when the user terminal accesses the network, and the registration request carries the terminal type and the user subscription identifier.
7. The method according to claim 1, characterized in that, The configuration parameters also include parameters for characterizing the key deduction algorithm and parameters for characterizing the key length.
8. A security authentication device for user terminal accessing a network, characterized in that, The device, applied to the SANF network element for security algorithm negotiation, includes: The acquisition module is used to acquire security information of the user terminal and the access network, the security information including the terminal type of the user terminal, the user subscription identifier of the user terminal, and the type of the access network; The determining module is configured to determine configuration parameters for generating a security configuration file based on the terminal type, the user subscription identifier, and the access network type; the configuration parameters include parameters for characterizing the authentication mode type; The transmission module is used to generate the security configuration file according to the configuration parameters and transmit the security configuration file to the user terminal so that the user terminal can complete the security authentication process for accessing the network according to the security configuration file.
9. An electronic device, characterized in that, It includes a processor, a communication interface, a memory, and a communication bus, wherein the processor, the communication interface, and the memory communicate with each other through the communication bus; Memory, used to store computer programs; When a processor executes a program stored in a memory, it implements the steps of the secure authentication method for user terminal accessing a network as described in any one of claims 1-7.
10. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by the processor, it implements the steps of the security authentication method for user terminal accessing the network as described in any one of claims 1-7.