Authentication method and apparatus

Through the collaboration between UDM, AUSF, and AMF network elements, the network authentication process for UEs was triggered from the network side, which solved the problem of network service interruption and improved the continuity and security of network services.

CN117546500BActive Publication Date: 2026-03-27BEIJING XIAOMI MOBILE SOFTWARE CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-04-14
Publication Date
2026-03-27

AI Technical Summary

Technical Problem

In mobile network communication systems, the lack of a mechanism on the network side to trigger the user equipment (UE) network authentication process may lead to network service interruption when security information is updated.

Method used

A mechanism is provided to trigger the UE network authentication process from the network side. This mechanism involves collaboration between UDM, AUSF, and AMF network elements, including sending authentication notification messages and authentication requests, to trigger the UE's network authentication process.

Benefits of technology

It improves the continuity and security of network services, preventing service interruptions and security threats caused by key expiration.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN117546500B_ABST
    Figure CN117546500B_ABST
Patent Text Reader

Abstract

The present disclosure provides an authentication method and device, and relates to the field of communication. The technical scheme of the present application is that a UDM network element receives a network authentication process trigger indication from an AUSF network element, and sends an authentication notification message to an AMF network element in response to the network authentication process trigger indication, thereby realizing a mechanism of triggering a network authentication process of a UE from the network side, and greatly improving the continuity and security of network services.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present disclosure relates to the technical field of mobile communication, and particularly relates to an authentication method and device. BACKGROUND

[0002] In a mobile network communication system, a user equipment (UE) can initiate a network authentication procedure to achieve bidirectional authentication between the UE side and the network side and provide information required for subsequent security procedures, such as an authentication server function (AUSF) network element key. However, in the current mobile network communication system, the network side does not have a mechanism to trigger a network authentication procedure for a UE, and therefore, in the case that information required for security procedures needs to be updated, network service interruption can occur due to the UE failing to initiate a network authentication procedure in time. SUMMARY

[0003] The present disclosure provides an authentication method and device, and provides a mechanism for the network side to trigger a network authentication procedure for a UE, thereby greatly improving the continuity and security of network service.

[0004] The first aspect embodiment of the present disclosure provides an authentication method, executed by a UDM network element, the method comprising: receiving a network authentication procedure trigger indication from an authentication server function (AUSF) network element, wherein the network authentication procedure trigger indication comprises an identity of a user equipment (UE) corresponding to the AUSF network element, and the network authentication procedure trigger indication is used to instruct the UDM network element to trigger a network authentication procedure for the UE; and sending an authentication notification message to an access and mobility management function (AMF) network element, wherein the identity of the UE is included in the authentication notification message, and the authentication notification message is used to notify the AMF network element to perform a network authentication procedure for the UE.

[0005] Optionally, the authentication notification message further comprises access type information, the access type information being used to indicate an access type to which the initiated network authentication procedure is applicable, and the access type comprising a 3rd Generation Partnership Project (3GPP) access and / or a non-3GPP access.

[0006] Optionally, the network authentication procedure trigger indication and the authentication notification message further comprise an authentication cause for which the AUSF network element requests triggering the network authentication procedure, the authentication cause comprising at least one of: a roaming steering count reaching an upper limit value; and a UE parameter update count reaching an upper limit value.

[0007] Optionally, the authentication notification message further comprises a confirmation request indication for requesting an authentication notification confirmation message from the AMF network element, the authentication notification confirmation message being used to indicate that the AMF network element has requested the UE to perform the network authentication procedure.

[0008] The second aspect embodiment of the present disclosure provides an authentication method, the method being performed by an AUSF network element, and the method comprising: sending a network authentication procedure trigger indication to a unified data management (UDM) network element, wherein the network authentication procedure trigger indication comprises an identity of a user equipment (UE) corresponding to the AUSF network element, and the network authentication procedure trigger indication is used to instruct the UDM network element to trigger a network authentication procedure for the UE.

[0009] Optionally, the network authentication procedure trigger indication further comprises an authentication cause for which the AUSF network element requests triggering the network authentication procedure, the authentication cause comprising at least one of: a roaming steering count reaching an upper limit value; and a UE parameter update count reaching an upper limit value.

[0010] Optionally, the method further comprises generating a new AUSF network element key and resetting values of the roaming steering count and the UE parameter update count after confirming completion of the network authentication procedure.

[0011] The third aspect embodiment of the present disclosure provides an authentication method, the method being performed by an AMF network element, and the method comprising: receiving an authentication notification message from a UDM network element, wherein the authentication notification message comprises an identity of a UE, and the authentication notification message is used to instruct the AMF network element to perform a network authentication procedure for the UE; sending an authentication request to the UE through a non-access (NAS) connection between the AMF network element and the UE, wherein the authentication request is used to request the UE to perform the network authentication procedure; and receiving an authentication response fed back by the UE, wherein the authentication response comprises information required for performing the network authentication procedure.

[0012] Optionally, the method further comprises: sending a paging message to the UE to create the NAS connection.

[0013] Optionally, the authentication notification message further comprises an acknowledgement request indication for requesting an authentication notification acknowledgement message from the AMF network element, and the method further comprises: sending the authentication notification acknowledgement message to the UDM network element, wherein the authentication notification acknowledgement message is used to indicate that the AMF network element has requested the UE to perform the network authentication procedure.

[0014] Optionally, the method further comprises: performing security protection on the authentication request according to the locally stored NAS security context.

[0015] Optionally, the method further comprises: updating the locally stored NAS security context after the network authentication procedure is completed.

[0016] A fourth aspect embodiment of the present disclosure provides an authentication method, comprising: an AUSF network element sending a network authentication procedure trigger indication to a UDM network element, wherein the network authentication procedure trigger indication comprises an identifier of a user equipment (UE) corresponding to the AUSF network element, and the network authentication procedure trigger indication is used to instruct the UDM network element to trigger a network authentication procedure for the UE; the UDM network element sending an authentication notification message to an AMF network element in response to the authentication procedure trigger indication, wherein the authentication notification message comprises the identifier of the UE and is used to notify the AMF network element to perform the network authentication procedure for the UE; the AMF network element sending an authentication request to the UE, wherein the authentication request is used to request the UE to perform the network authentication procedure; and the AMF network element receiving an authentication response fed back by the UE, wherein the authentication response comprises information required for performing the network authentication procedure.

[0017] Optionally, the authentication notification message comprises an acknowledgement request indication for requesting an authentication notification acknowledgement message from the AMF network element, and the method further comprises: the AMF network element sending the authentication notification acknowledgement message to the UDM network element, wherein the authentication notification acknowledgement message is used to indicate that the AMF network element has requested the UE to perform the network authentication procedure.

[0018] Optionally, the method further comprises: after the network authentication procedure is completed, the AUSF network element generates a new AUSF network element key, and resets a roaming steering count and a UE parameter update count.

[0019] Optionally, access type information is further comprised in the authentication notification message and the authentication request, and the access type information is used to indicate an access type to which the initiated network authentication procedure is applicable, and the access type comprises a third generation partnership project (3GPP) access and / or a non-3GPP access.

[0020] Optionally, the network authentication procedure trigger indication and the authentication notification message further comprise an authentication cause for which the AUSF network element requests triggering the network authentication procedure, the authentication cause comprising at least one of: a roaming steering count reaching an upper limit value; and a UE parameter update count reaching an upper limit value.

[0021] A fifth aspect of the present disclosure provides an authentication apparatus for a UDM network element, comprising: a transceiver configured to receive, from an Authentication Sever Function (AUSF) network element, a network authentication procedure trigger indication, wherein the network authentication procedure trigger indication comprises an identity of a User Equipment (UE) corresponding to the AUSF network element, and the network authentication procedure trigger indication is used to instruct the UDM network element to trigger a network authentication procedure for the UE; and transmit, to an Access and Mobility Mangement Function (AMF) network element, an authentication notification message, wherein the authentication notification message comprises the identity of the UE, and the authentication notification message is used to notify the AMF network element to perform the network authentication procedure for the UE.

[0022] A sixth aspect of the present disclosure provides an authentication apparatus for an AUSF network element, comprising: a transceiver configured to transmit, to a Unified Data Management (UDM) network element, a network authentication procedure trigger indication, wherein the network authentication procedure trigger indication comprises an identity of a User Equipment (UE) corresponding to the AUSF network element, and the network authentication procedure trigger indication is used to instruct the UDM network element to trigger a network authentication procedure for the UE.

[0023] A seventh aspect of the present disclosure provides an authentication apparatus for an AMF network element, comprising: a transceiver configured to receive, from a UDM network element, an authentication notification message, wherein the authentication notification message comprises an identity of a UE, and the authentication notification message is used to notify the AMF network element to perform a network authentication procedure for the UE; transmit, to the UE via a Non Access Stratum (NAS) connection between the AMF network element and the UE, an authentication request, wherein the authentication request is used to request the UE to perform the network authentication procedure; and receive an authentication response fed back by the UE, wherein the authentication response comprises information required for performing the network authentication procedure.

[0024] An authentication system is provided in an eighth aspect of the present disclosure, comprising: an AUSF network element, a UDM network element, and an AMF network element, wherein the AUSF network element is configured to send an authentication procedure trigger indication to the UDM network element, wherein the network authentication procedure trigger indication comprises an identifier of a user equipment (UE) corresponding to the AUSF network element, and the network authentication procedure trigger indication is configured to instruct the UDM network element to trigger a network authentication procedure for the UE; the UDM network element is configured to receive the network authentication procedure trigger indication sent from the AUSF network element, and send an authentication notification message to the AMF network element in response to the network authentication procedure trigger indication, wherein the authentication notification message comprises the identifier of the UE and is configured to notify the AMF network element to perform the network authentication procedure for the UE; and the AMF network element is configured to send an authentication request to the UE and receive an authentication response from the UE, wherein the authentication request is configured to request the UE to perform the network authentication procedure, and the authentication response comprises information required for performing the network authentication procedure.

[0025] A communication device is provided in a ninth aspect of the present disclosure, comprising: a transceiver; a memory; and a processor connected with the transceiver and the memory respectively, configured to control wireless signal transceiving of the transceiver by executing computer executable instructions on the memory, and enable the authentication method of the first aspect or the second aspect or the third aspect.

[0026] A computer storage medium is provided in a tenth aspect of the present disclosure, wherein the computer storage medium stores computer executable instructions; and the computer executable instructions are executed by a processor to enable the authentication method of the first aspect or the second aspect or the third aspect.

[0027] The authentication method and device provided in the present disclosure enable the network side to trigger a network authentication procedure for a UE, and greatly improve the continuity and security of network services.

[0028] Additional aspects and advantages of the present disclosure will be made apparent from the following description of embodiments, which will be given with reference to the attached drawings. BRIEF DESCRIPTION OF DRAWINGS

[0029] The above and / or additional aspects and advantages of the present disclosure will become apparent and be readily appreciated from the following description of embodiments, taken in conjunction with the accompanying drawings, in which:

[0030] Figure 1Flowchart of an authentication method according to an embodiment of the present disclosure;

[0031] Figure 2 Flowchart of an authentication method according to an embodiment of the present disclosure;

[0032] Figure 3 Flowchart of an authentication method according to an embodiment of the present disclosure;

[0033] Figure 4 Flowchart of an authentication method according to an embodiment of the present disclosure;

[0034] Figure 5 Flowchart of an authentication method according to an embodiment of the present disclosure;

[0035] Figure 6 Flowchart of an authentication method according to an embodiment of the present disclosure;

[0036] Figure 7 Flowchart of an authentication method according to an embodiment of the present disclosure;

[0037] Figure 8 Flowchart of an authentication method according to an embodiment of the present disclosure;

[0038] Figure 9 Flowchart of an authentication method according to an embodiment of the present disclosure;

[0039] Figure 10 Flowchart of an authentication method according to an embodiment of the present disclosure;

[0040] Figure 11 Flowchart of an authentication method according to an embodiment of the present disclosure;

[0041] Figure 12 Flowchart of an authentication method according to an embodiment of the present disclosure;

[0042] Figure 13 Flowchart of an authentication method according to an embodiment of the present disclosure;

[0043] Figure 14 Flowchart of an authentication method according to an embodiment of the present disclosure;

[0044] Figure 15 Block diagram of an authentication apparatus according to an embodiment of the present disclosure;

[0045] Figure 16 Block diagram of an authentication apparatus according to an embodiment of the present disclosure;

[0046] Figure 17A block diagram of an authentication apparatus according to an embodiment of the present disclosure;

[0047] Figure 18 A block diagram of an authentication apparatus according to an embodiment of the present disclosure;

[0048] Figure 19 A block diagram of an authentication apparatus according to an embodiment of the present disclosure;

[0049] Figure 20 A block diagram of an authentication apparatus according to an embodiment of the present disclosure;

[0050] Figure 21 A block diagram of an authentication apparatus according to an embodiment of the present disclosure;

[0051] Figure 22 A structural schematic diagram of a communication apparatus provided by an embodiment of the present disclosure;

[0052] Figure 23 A structural schematic diagram of a chip provided by an embodiment of the present disclosure. DETAILED DESCRIPTION

[0053] Embodiments of the present disclosure are described in detail below with reference to the accompanying drawings, examples of which are shown in the drawings, wherein the same or similar notations represent the same or similar elements or elements having the same or similar functions throughout. The embodiments described below with reference to the accompanying drawings are exemplary and are intended to explain the present disclosure, and cannot be understood as a limitation of the present disclosure.

[0054] In order to protect the Steering of Roaming (SoR) / UE Parameter Update (UPU) service, the Authentication Sever Function (AUSF) network element and the UE need to maintain the Steering of Roaming Counter AUSF / UE Parameter Update Counter SoR / Counter UPU within the lifetime of the AUSF network element key K AUSF When the newly generated K SoR is stored, the Counter UPU is set to 0x00 0x01, the Counter AUSF is set to 0x00 0x01, and will be incremented with each calculation of the hash value of the AUSF network element side SoR message SoR-MAC-I AUSF / UPU message UPU-MAC-I AUSF Once the Counter SoR / Counter UPUWhen the upper limit value is reached, the AUSF network element will not be able to provide the SoR / UPU protection service for the UE. Only when a new K AUSF is regenerated for the UE, the Counter SoR / Counter UPU is reset, and the AUSF network element can resume the SoR / UPU protection service for the UE. Therefore, it is necessary to refresh K AUSF in time before it becomes invalid. AUSF

[0055] The network authentication procedure can achieve mutual authentication between the UE side and the network side and provide information required for subsequent security procedures. After the network authentication procedure is successfully completed, a new K AUSF may be generated. In the current mobile communication network, the network side does not have a mechanism to trigger the network authentication procedure for the UE, and the UE can use the same K AUSF attached to the network for a long time without refreshing K AUSF , which will cause interruption of the SoR / UPU protection service and even network service. For security, it is urgently needed to enable a mechanism for the network side to trigger the network authentication procedure for the UE to address the introduced security threat. The network side triggering the network authentication procedure for the UE can greatly improve the continuity and security of network service.

[0056] When the Counter SoR / Counter UPU reaches the upper limit value, the network function (Network Function, NF) of the core network side (such as the AUSF network, the UDM network element, the AMF network element, etc.) can detect the unavailability of K AUSF and notify the UE to run the network authentication procedure without suspending the SoR / UPU protection service for the UE. However, in the current mobile communication network system, the network authentication procedure is mainly initiated by the UE by sending a registration request to the Access and Mobility Mangement Function (AMF) network element. The NF of the core network side does not have a mechanism to trigger the network authentication procedure for the UE, so it is possible to introduce additional security threats and reduce service quality.

[0057] Therefore, the present disclosure provides an authentication method and device, which provides a mechanism for the network side to trigger the network authentication procedure for the UE, thereby greatly improving the continuity and security of network service.

[0058] The authentication method and device provided by the present disclosure will be described in detail below with reference to the accompanying drawings.

[0059] Figure 1 ​A flowchart illustrating an authentication method according to an embodiment of this disclosure is shown. Figure 1 As shown, this method can be executed by a UDM network element and includes the following steps.

[0060] S101, Receive network authentication process trigger instruction from AUSF network element.

[0061] The network authentication process triggering indication includes the identifier of the user equipment (UE) corresponding to the AUSF network element, and the network authentication process triggering indication is used to instruct the UDM network element to trigger the network authentication process for the UE.

[0062] S102, send an authentication notification message to the AMF network element.

[0063] The authentication notification message includes the UE's identifier and is used to notify the AMF network element to perform the network authentication process for the UE.

[0064] In this embodiment, the UDM network element can receive a network authentication process triggering instruction carrying the identifier of the UE corresponding to the AMF network element from the AMF network element. After receiving the network authentication process triggering instruction, the UDM network element can send an authentication notification message to the AMF network element in response to the network authentication process triggering instruction to notify the AMF network element to perform the network authentication process for the UE.

[0065] For example, when an AUSF network element determines that it needs to regenerate the AUSF network element key K. AUSF In cases such as the current K AUSF In the event of an invalid authentication process, the AUSF network element can send a network authentication process trigger indication to the UDM network element.

[0066] The UE's identifier can be either a Generic Public Subscription Identifier (GPSI) or a Subscription Permanent Identifier (SUPI).

[0067] The specific implementation of the UE's network authentication process can refer to existing network authentication processes. For example, the specific implementation of the network authentication process shown in this application is similar to the implementation of the network authentication process initiated by the UE by sending a registration request to the AMF network element, and will not be described in detail here.

[0068] According to the authentication method of the embodiment of the present disclosure, the UDM network element receives a network authentication process trigger indication from the AUSF network element, and sends an authentication notification message to the AMF network element in response to the network authentication process trigger indication, thereby realizing a mechanism of triggering a network authentication process of the UE from the network side, and greatly improving the continuity and security of network services.

[0069] In some embodiments, the authentication notification message sent by the UDM network element to the AMF network element can further include access type information, which is used to indicate an access type to which the initiated network authentication process is applicable, and the access type includes 3rd Generation Partnership Project (3GPP) access and / or non-3GPP access.

[0070] For example, if the access type information in the authentication notification message received by the AMF network element indicates 3GPP access, the AMF network element can confirm that the initiated network authentication process is only for 3GPP access.

[0071] For another example, if the access type information in the authentication notification message received by the AMF network element indicates non-3GPP access, the AMF network element can confirm that the initiated network authentication process is only for non-3GPP access.

[0072] For another example, if the access type information in the authentication notification message received by the AMF network element indicates 3GPP access and non-3GPP access, the AMF network element can confirm that the initiated network authentication process is for both 3GPP access and non-3GPP access.

[0073] In some embodiments, the network authentication process trigger indication and the authentication notification message can further include an authentication reason for which the AUSF network element requests to trigger the network authentication process, and the authentication reason includes at least one of the following: a roaming steering count reaching an upper limit value; and a UE parameter update count reaching an upper limit value.

[0074] The AUSF network element can request the UDM network element to trigger the network authentication process due to K AUSF invalidity. The K AUSF invalidity can be caused by the roaming steering count reaching the upper limit value and / or the UE parameter update count reaching the upper limit value. Therefore, the reason for which the AUSF network element requests the UDM network element to trigger the network authentication process can be the roaming steering count reaching the upper limit value and / or the UE parameter update count reaching the upper limit value. The AUSF network element can carry an indication of the reason in the network authentication process trigger indication sent to the UDM network element. After receiving the network authentication process trigger indication carrying the authentication reason, the UDM network element can send the authentication notification message carrying the authentication reason to the AMF network element.

[0075] In some embodiments, the authentication notification message sent by the UDM network element to the AMF network element may further include a confirmation request indication for requesting an authentication notification confirmation message from the AMF network element, wherein the authentication notification confirmation message is used to indicate that the AMF network element has requested the UE to perform the network authentication process.

[0076] The authentication notification message sent by the UDM network element to the AMF network element may also include a confirmation request indication. This confirmation request indication is used to request an authentication notification confirmation message from the AMF network element, indicating that the AMF network element has requested the UE to perform the network authentication process. Thus, after receiving the authentication notification confirmation message, the UDM network element can confirm that the AMF network element has requested the UE to perform the network authentication process, that is, the UDM network element can know whether the current triggering of the UE's network authentication process has been implemented.

[0077] For example, if the authentication notification message includes a confirmation request instruction, and the UDM network element does not receive an authentication notification confirmation message from the AMF network element within a preset time period after sending the authentication notification message, then the UDM network element can confirm that this triggering of the network authentication process for the UE has failed.

[0078] Figure 2 A flowchart illustrating an authentication method according to an embodiment of this disclosure is shown. Figure 2 As shown, this method can be executed by an AUSF network element, and the authentication method may include the following steps.

[0079] S201, send a network authentication process trigger instruction to the UDM network element.

[0080] The network authentication process triggering indication includes the identifier of the user equipment (UE) corresponding to the AUSF network element, and the network authentication process triggering indication is used to instruct the UDM network element to trigger the network authentication process for the UE.

[0081] The UE identifier can be either GPSI or SUPI.

[0082] In this implementation, the AMF network element can send a network authentication process trigger indication to the UDM network element, and the UDM network element can respond to the network authentication trigger indication by sending an authentication notification message to the AMF network element, thereby realizing a mechanism for the network side to trigger the network authentication process for the UE.

[0083] For example, when an AUSF network element determines that it needs to regenerate the AUSF network element key K. AUSF In cases such as the current K AUSF In the event of an invalid network, the AUSF network element can send a network authentication process trigger indication to the UDM network element, which carries the identifier of the UE corresponding to the AUSF network element.

[0084] According to the authentication method of this disclosure embodiment, the AMF network element sends a network authentication process triggering instruction to the UDM network element, and the UDM network element can respond to the network authentication triggering instruction by sending an authentication notification message to the AMF network element. This enables a mechanism for triggering the network authentication process for the UE from the network side, which can greatly improve the continuity and security of network services.

[0085] In some embodiments, the network authentication process triggering indication sent by the AUSF network element to the UDM network element may also include the authentication reason for the AUSF network element to request the triggering of the network authentication process, and the authentication reason may include at least one of the following: the roaming manipulation count has reached the upper limit; and the UE parameter update count has reached the upper limit.

[0086] AUSF network elements can be due to K AUSF Invalid and requesting the UDM network element to trigger the network authentication process, K AUSF Invalidity may be due to the roaming manipulation count reaching its upper limit and / or the UE parameter update count reaching its upper limit. Therefore, the reason for the AUSF network element to request the UDM network element to trigger the network authentication process could be that the roaming manipulation count has reached its upper limit and / or the UE parameter update count has reached its upper limit. The network authentication process triggering instruction sent by the AUSF network element to the UDM network element can carry an authentication reason indicating this reason.

[0087] Figure 3 A flowchart illustrating an authentication method according to an embodiment of this disclosure is shown. This method can be executed by an AUSF network element and is based on... Figure 2 The illustrated embodiments, such as Figure 3 As shown, the authentication method may include the following steps.

[0088] S301 sends a network authentication process trigger instruction to the UDM network element.

[0089] The network authentication process triggering indication includes the identifier of the user equipment (UE) corresponding to the AUSF network element, and the network authentication process triggering indication is used to instruct the UDM network element to trigger the network authentication process for the UE.

[0090] For a description and specific details of step S301 above, please refer to the relevant description and details of step S201 above.

[0091] S302 After confirming the completion of the network authentication process, a new AUSF network element key is generated, and the roaming manipulation count and UE parameter update count are reset.

[0092] After confirming the completion of the network authentication process, the AUSF network element can generate a new AUSF network element key K. AUSF And reset the roaming manipulation count and UE parameter update count, i.e., CounterSoR set to 0x00 0x01, Counter UPU set to 0x00 0x01.

[0093] According to the authentication method, the AUSF network element sends a network authentication process trigger indication to the UDM network element, and the UDM network element can send an authentication notification message to the AMF network element in response to the network authentication trigger indication, and a new AUSF network element key can be generated and the roaming manipulation count and the UE parameter update count can be reset after the network authentication process is completed, so that the mechanism of triggering the network authentication process of the UE from the network side can be realized, and the continuity and security of network services can be greatly improved.

[0094] In some embodiments, the network authentication process trigger indication sent by the AUSF network element to the UDM network element can further include an authentication reason for which the AUSF network element requests to trigger the network authentication process, and the authentication reason includes at least one of the following: the roaming manipulation count reaches an upper limit value; and the UE parameter update count reaches an upper limit value.

[0095] The application further provides an authentication method, which is executed by an AMF network element and includes: receiving an authentication notification message from a UDM network element, wherein the authentication notification message includes an identifier of a UE, and the authentication notification message is used to notify the AMF network element to perform a network authentication process of the UE; sending an authentication request to the UE through a Non Access Stratum (NAS) connection between the AMF network element and the UE, wherein the authentication request is used to request the UE to perform the network authentication process; and receiving an authentication response fed back by the UE, wherein the authentication response includes information required for performing the network authentication process.

[0096] In some embodiments, the method further includes: sending a paging message to the UE to create the NAS connection.

[0097] In some embodiments, the authentication notification message further includes an acknowledgement request indication used to request the AMF network element to send an authentication notification acknowledgement message, and the method further includes: sending the authentication notification acknowledgement message to the UDM network element, wherein the authentication notification acknowledgement message is used to indicate that the AMF network element has requested the UE to perform the network authentication process.

[0098] In some embodiments, the method further includes: performing security protection on the authentication request according to a locally stored NAS security context.

[0099] In some embodiments, the method further includes: updating the locally stored NAS security context after the network authentication process is completed. In some embodiments, the method further includes: updating the locally stored NAS security context after the network authentication process is completed.

[0100] In some embodiments, the authentication request and the authentication notification message further comprise access type information, the access type information being used to indicate an access type to which the initiated network authentication procedure is applicable, the access type comprising a 3GPP access and / or a non-3GPP access.

[0101] In some embodiments, the authentication notification message further comprises an authentication cause for which the UDM network element sends the authentication notification message, the authentication cause comprising at least one of: a roaming steering count reaching an upper limit value; and a UE parameter update count reaching an upper limit value.

[0102] Figure 4 A flowchart of an authentication method according to an embodiment of the present disclosure is shown, as shown in Figure 4 The method can be performed by an AMF network element, and can comprise the following steps.

[0103] S401, receiving an authentication notification message from a UDM network element.

[0104] The authentication notification message comprises an identity of a UE, and the authentication notification message is used to notify the AMF network element to perform a network authentication procedure for the UE.

[0105] In the embodiment, the AMF network element can receive the authentication notification message carrying the identity of the UE from the UDM network element, so as to trigger the network authentication procedure for the UE by the UDM network element.

[0106] The identity of the UE can be a GPSI or a SUPI.

[0107] S402, sending an authentication request to the UE through a NAS connection between the AMF network element and the UE.

[0108] The authentication request is used to request the UE to perform the network authentication procedure.

[0109] After receiving the authentication notification message, the AMF network element can send the authentication request to the UE through the NAS connection between the AMF network element and the UE, so as to request the UE to perform the network authentication procedure.

[0110] S403, receiving an authentication response fed back by the UE.

[0111] The authentication response comprises information required for performing the network authentication procedure.

[0112] After receiving the authentication request from the AMF network element, the UE can feed back the authentication response to the AMF network element, so as to provide the AMF network element with the information required for performing the network authentication procedure.

[0113] The network devices involved in the network authentication procedure, such as the AMF network element, the AUSF network element, and the UDM network element, can interact with each other so that each of the network devices involved can obtain the information required for the network authentication procedure, thereby enabling the network authentication procedure for the UE.

[0114] The specific implementation of the network authentication procedure for the UE can refer to the network authentication procedure in the prior art. For example, the specific implementation of the network authentication procedure shown in the present application is similar to the implementation of the network authentication procedure initiated by the UE by sending a registration request to the AMF network element, and details are not repeated here.

[0115] According to the authentication method of the embodiments of the present disclosure, the AMF network element can receive the authentication notification message from the UDM network element, send the authentication request to the UE and obtain the authentication response including the information required for the network authentication procedure from the UE, to trigger the network authentication procedure for the UE, thereby enabling the mechanism of triggering the network authentication procedure for the UE from the network side, and greatly improving the continuity and security of network services.

[0116] In some embodiments, the authentication notification message received from the UDM network element can further include an authentication reason for the UDM network element to send the authentication notification message, and the authentication reason includes at least one of the following: a roaming manipulation count reaches an upper limit value; and a UE parameter update count reaches an upper limit value.

[0117] The UDM network element can send the authentication notification message to the AMF network element in response to the network authentication procedure trigger indication received from the AUSF network element. When the AUSF network element determines that the AUSF network element key K AUSF is invalid, such as the current K AUSF is invalid, the AUSF network element can send the network authentication procedure trigger indication to the UDM network element.

[0118] The K AUSF may be invalid due to the roaming manipulation count reaching the upper limit value and / or the UE parameter update count reaching the upper limit value, and therefore, the reason for the UDM network element to send the authentication notification message to trigger the network authentication procedure for the UE can be the roaming manipulation count reaching the upper limit value and / or the UE parameter update count reaching the upper limit value.

[0119] In some embodiments, the authentication notification message received from the UDM network element and the authentication request sent to the UE can further include access type information, which is used to indicate the access type to which the initiated network authentication procedure is applicable, and the access type includes 3rd Generation Partnership Project (3GPP) access and / or non-3GPP access.

[0120] For example, if the access type information in the authentication notification message received by the AMF network element indicates 3GPP access, the AMF network element can confirm that the initiated network authentication procedure is only for 3GPP access, and the AMF network element carries the access type information in the authentication request sent to the UE, so that the UE can confirm that the network authentication procedure is only for 3GPP access.

[0121] For another example, if the access type information in the authentication notification message received by the AMF network element indicates non-3GPP access, the AMF network element can confirm that the initiated network authentication procedure is only for non-3GPP access, and the AMF network element carries the access type information in the authentication request sent to the UE, so that the UE can confirm that the network authentication procedure is only for non-3GPP access.

[0122] For another example, if the access type information in the authentication notification message received by the AMF network element indicates non-3GPP access, the AMF network element can confirm that the initiated network authentication procedure is only for non-3GPP access, and the AMF network element carries the access type information in the authentication request sent to the UE, so that the UE can confirm that the network authentication procedure is only for non-3GPP access.

[0123] Figure 5 A flowchart of an authentication method according to an embodiment of the present disclosure is shown. The method can be performed by an AMF network element, based on Figure 4 The embodiment shown, as Figure 5 As shown, and the method can include the following steps.

[0124] S501, receiving an authentication notification message from a UDM network element.

[0125] The authentication notification message includes the identity of the UE, and the authentication notification message is used to inform the AMF network element to perform a network authentication procedure for the UE.

[0126] For the description and specific details of step S501, please refer to the related description and details of step S401.

[0127] S502, sending a paging message to the UE to create a NAS connection.

[0128] After receiving the authentication communication message carrying the identity of the UE, if the AMF network element finds that there is no NAS connection between the UE and the AMF network element, the 5G core network pages the UE, and if the UE is in a registered (RM-REGISTERED) and CM idle (CM-IDLE) state, the AMF can send a paging message to the UE via a 5G radio access network (NG-RAN) node to create a NAS connection with the UE. If the UE is in a CM connected (CM-CONNECTED) state, it indicates that the NAS connection between the UE and the AMF network element already exists, and step S502 can be omitted.

[0129] S503, sending an authentication request to the UE through the NAS connection between the AMF network element and the UE.

[0130] The authentication request is used to request the UE to perform a network authentication process.

[0131] S504, receiving an authentication response fed back by the UE.

[0132] The authentication response includes information required for the network authentication process.

[0133] For the description and specific details of steps S503-S504, please refer to the related description and details of steps S402-S403.

[0134] According to the authentication method of the embodiments of the present disclosure, the AMF network element can receive an authentication notification message from the UDM network element, send an authentication request to the UE and obtain an authentication response including information required for the network authentication process from the UE, to trigger the network authentication process of the UE. Thus, the mechanism of triggering the network authentication process of the UE from the network side can be realized, and the continuity and security of network services can be greatly improved.

[0135] In some embodiments, the authentication notification message received from the UDM network element can also include an authentication reason for the UDM network element to issue the authentication notification message, and the authentication reason includes at least one of the following: the roaming manipulation count reaches an upper limit value; and the UE parameter update count reaches an upper limit value.

[0136] In some embodiments, the authentication notification message received from the UDM network element and the authentication request sent to the UE can also include access type information, which is used to indicate the access type to which the initiated network authentication process is applicable, and the access type includes 3GPP access and / or non-3GPP access.

[0137] Figure 6 A flowchart of an authentication method according to an embodiment of the present disclosure is shown. The method can be performed by an AMF network element, based on Figure 4 As shown in the embodiment,Figure 6 As shown, and the method can include the following steps.

[0138] S601, receiving an authentication notification message from a UDM network element.

[0139] The authentication notification message includes an identity of the UE, and the authentication notification message is used to notify the AMF network element to perform a network authentication process for the UE.

[0140] S602, sending an authentication request to the UE through a NAS connection between the AMF network element and the UE.

[0141] The authentication request is used to request the UE to perform a network authentication process.

[0142] For the description and specific details of the above steps S601-S602, please refer to the related description and details of the above steps S401-S402.

[0143] S603, sending an authentication notification confirmation message to the UDM network element.

[0144] The authentication notification confirmation message is used to indicate that the AMF network element has requested the UE to perform a network authentication process.

[0145] The authentication notification message received from the UDM network element can also include a confirmation request indication for requesting the AMF network element to send the authentication notification confirmation message. If the authentication notification message includes the confirmation request indication, the AMF network element can send the authentication notification confirmation message to the UDM network element to notify the UDM network element that the network authentication process for the UE has been triggered after sending the authentication request to the UE. If the AMF network element fails to send the authentication request to the UE, the authentication notification confirmation message will not be sent to the UDM network element, and the UDM network element can confirm that the triggering of the network authentication process for the UE has failed to implement within a preset time period.

[0146] S604, receiving an authentication response fed back by the UE.

[0147] The authentication response includes information required for performing a network authentication process.

[0148] For the description and specific details of the above step S604, please refer to the related description and details of the above step S403.

[0149] According to the authentication method of the embodiments of the present disclosure, the AMF network element can receive an authentication notification message from the UDM network element, send an authentication request to the UE and obtain an authentication response including information required for performing a network authentication process from the UE, to trigger a network authentication process for the UE, thereby realizing a mechanism for triggering a network authentication process for the UE from the network side, and greatly improving the continuity and security of network services.

[0150] It should be noted that, although Figure 6 the embodiments shown are described only in Figure 4 the context of the embodiments shown, similarly, the Figure 6 embodiments shown can also be based on Figure 5 the embodiments shown, for example, Figure 6 the step S603 can also be combined with Figure 5 the steps S501-S504, and here will not be described in detail.

[0151] In some embodiments, the authentication notification message received from the UDM network element can also include an authentication reason for the UDM network element to issue the authentication notification message, and the authentication reason includes at least one of the following: the roaming steering count reaches an upper limit value; and the UE parameter update count reaches an upper limit value.

[0152] In some embodiments, the authentication notification message received from the UDM network element and the authentication request sent to the UE can also include access type information, which is used to indicate the access type to which the initiated network authentication process is applicable, and the access type includes 3GPP access and / or non-3GPP access.

[0153] Figure 7 A flowchart of an authentication method according to an embodiment of the present disclosure is shown. The method can be performed by an AMF network element, based on Figure 4 the embodiments shown, as Figure 7 shown, and the method can include the following steps.

[0154] S701, receiving an authentication notification message from a UDM network element.

[0155] Among them, the authentication notification message includes the identity of the UE, and the authentication notification message is used to notify the AMF network element to perform a network authentication process about the UE.

[0156] For the description and specific details of the above step S701, please refer to the related description and details of the above step S401.

[0157] S702, according to the locally stored NAS security context, the authentication request is secured.

[0158] After receiving the authentication notification message, the AMF network element can send an authentication request to the UE through the NAS connection between the AMF network element and the UE to request the UE to perform a network authentication process.

[0159] For safety, the AMF network element can protect the authentication request according to the locally stored NAS security context, for example, encrypt, and then send the security-protected authentication request to the UE. After receiving the security-protected authentication request, the UE can parse the security-protected authentication request according to the locally stored NAS security context of the UE to obtain the content of the authentication request.

[0160] S703, sending the security-protected authentication request to the UE through the NAS connection between the AMF network element and the UE.

[0161] The authentication request is used to request the UE to perform a network authentication process.

[0162] S704, receiving the authentication response fed back by the UE.

[0163] The authentication response includes information required for the network authentication process.

[0164] For the description and specific details of the above steps S703-S704, please refer to the related description and details of the above steps S402-S403.

[0165] According to the authentication method of the embodiments of the present disclosure, the AMF network element can receive the authentication notification message from the UDM network element, send the authentication request to the UE and obtain the authentication response including the information required for the network authentication process from the UE, to trigger the network authentication process of the UE, thereby realizing the mechanism of triggering the network authentication process of the UE from the network side, and greatly improving the continuity and security of network services.

[0166] It should be noted that, although Figure 7 the embodiments shown are only described on the basis of Figure 4 the embodiments shown, similarly, the Figure 7 the embodiments shown can also be based on Figure 5 and Figure 6 the embodiments shown, for example, Figure 7 the step S702 of Figure 5 the steps S501-S504 of Figure 6 the steps S601-S604 of

[0167] In some embodiments, the authentication notification message received from the UDM network element can also include the authentication reason for the UDM network element to issue the authentication notification message, and the authentication reason includes at least one of the following: the roaming manipulation count reaches the upper limit value; and the UE parameter update count reaches the upper limit value.

[0168] In some embodiments, the authentication notification message received from the UDM network element and the authentication request sent to the UE can further include access type information, which is used to indicate the access type to which the initiated network authentication procedure is applicable, and the access type includes 3GPP access and / or non-3GPP access.

[0169] Figure 8 A flowchart of an authentication method according to an embodiment of the disclosure is shown. The method can be performed by an AMF network element, based on Figure 7 The embodiment shown, as Figure 8 is shown, and the method can include the following steps.

[0170] S801, receiving an authentication notification message from a UDM network element.

[0171] Among them, the authentication notification message includes the identity of the UE, and the authentication notification message is used to notify the AMF network element to perform a network authentication procedure on the UE.

[0172] S802, security protection is performed on the authentication request according to the locally stored NAS security context.

[0173] S803, sending the security-protected authentication request to the UE through the NAS connection between the AMF network element and the UE.

[0174] Among them, the authentication request is used to request the UE to perform a network authentication procedure.

[0175] S804, receiving the authentication response fed back by the UE.

[0176] Among them, the authentication response includes the information required for the network authentication procedure.

[0177] For the description and specific details of the above steps S801-S804, please refer to the related description and details of the above steps S701-S704.

[0178] S805, updating the locally stored NAS security context after the network authentication procedure is completed.

[0179] After confirming that the network authentication procedure is completed, the AMF network element can update the locally stored NAS security context, so that the updated NAS security context can be used to protect the specified message after completing the NAS security model command flow to activate the updated NAS security context.

[0180] According to the authentication method of the embodiments of the present disclosure, the AMF network element can receive an authentication notification message from the UDM network element, send an authentication request to the UE and obtain an authentication response including information required for the network authentication process from the UE to trigger the network authentication process of the UE, thereby realizing the mechanism of triggering the network authentication process of the UE from the network side and greatly improving the continuity and security of network services.

[0181] In some embodiments, the authentication notification message received from the UDM network element can further include an authentication reason for the UDM network element to send the authentication notification message, and the authentication reason includes at least one of the following: a roaming steering count reaching an upper limit value; and a UE parameter update count reaching an upper limit value.

[0182] In some embodiments, the authentication notification message received from the UDM network element and the authentication request sent to the UE can further include access type information, which is used to indicate an access type to which the initiated network authentication process is applicable, and the access type includes 3GPP access and / or non-3GPP access.

[0183] The embodiments of the present disclosure provide an authentication method, which is performed by a UE, and the method comprises: receiving an authentication request from an AMF network element, wherein the authentication request is used to request the UE to perform a network authentication process; and feeding back an authentication response to the AMF network element, wherein the authentication response includes information required for the network authentication process.

[0184] In some embodiments, the method further comprises: receiving a paging message from the AMF network element to create a NAS connection with the AMF network element.

[0185] In some embodiments, the method further comprises: performing security protection on the authentication response according to a locally stored NAS security context.

[0186] In some embodiments, the method further comprises: updating the locally stored NAS security context after the network authentication process is completed.

[0187] In some embodiments, the authentication request includes access type information, which is used to indicate an access type to which the initiated network authentication process is applicable, and the access type includes 3GPP access and / or non-3GPP access.

[0188] Figure 9 A flowchart of an authentication method according to an embodiment of the present disclosure is shown. As shown in the figure, the method can be performed by a UE and can include the following steps. Figure 9

[0189] S901, receiving an authentication request from an AMF network element. ​

[0190] The authentication request is used to request the UE to perform the network authentication procedure.

[0191] In this embodiment, the UE can receive the authentication request for requesting the UE to perform the network authentication procedure from the AMF network element.

[0192] For example, the AMF network element can send the authentication request to the UE after receiving the authentication notification message for notifying the AMF network element to perform the network authentication procedure about the UE from the AUSF network element.

[0193] S902, feedback the authentication response to the AMF network element.

[0194] The authentication response includes information required for performing the network authentication procedure.

[0195] After receiving the authentication request from the AMF network element, the UE can feedback the authentication response to the AMF network element to provide the AMF network element with information required for performing the network authentication procedure.

[0196] The network devices involved in the network authentication procedure, such as the AMF network element, the AUSF network element, and the UDM network element, can interact with each other so that the network devices involved can obtain information required for performing the network authentication procedure, thereby being able to perform the network authentication procedure about the UE.

[0197] The specific implementation of the network authentication procedure about the UE can refer to the network authentication procedure in the prior art. For example, the specific implementation of the network authentication procedure shown in this application is similar to the implementation of the network authentication procedure initiated by the UE by sending a registration request to the AMF network element, which will not be described here.

[0198] According to the authentication method of the embodiments of the present disclosure, the UE can receive the authentication request from the AMF network element and feedback the authentication response including information required for performing the network authentication procedure to the AMF network element, thereby triggering the network authentication procedure about the UE, which can greatly improve the continuity and security of network services.

[0199] In some embodiments, the authentication request received from the AMF network element can include access type information, which is used to indicate the access type to which the initiated network authentication procedure is applicable, and the access type includes 3GPP access and / or non-3GPP access.

[0200] For example, if the access type information in the authentication request received by the UE indicates 3GPP access, the UE can confirm that the network authentication procedure is only performed for 3GPP access.

[0201] For another example, if the access type information in the authentication request received by the UE indicates a non-3GPP access, the UE can confirm that the network authentication procedure is only for the non-3GPP access.

[0202] For another example, if the access type information in the authentication request received by the UE indicates a non-3GPP access, the UE can confirm that the network authentication procedure is only for the non-3GPP access.

[0203] Figure 10 A flowchart of an authentication method according to an embodiment of the disclosure is shown. The method can be performed by a UE, based on Figure 9 As shown in the embodiment shown, the method can include the following steps. Figure 10

[0204] S1001, receiving a paging message from an AMF network element to create a NAS connection with the AMF network element.

[0205] The AMF network element can interact with the UE through the NAS connection. If there is no NAS connection between the UE and the AMF network element, the 5G core network pages the UE. If the UE is in the registered (RM-REGISTERED) and CM idle (CM-IDLE) state, the AMF can send a paging message to the UE via a 5G radio access network (NG-RAN) node to create a NAS connection with the UE. If the UE is in the CM connected (CM-CONNECTED) state, it indicates that the NAS connection between the UE and the AMF network element already exists, and this step S1001 can be omitted.

[0206] S1002, receiving an authentication request from the AMF network element through the NAS connection.

[0207] The authentication request is used to request the UE to perform a network authentication procedure.

[0208] S1003, feeding back an authentication response to the AMF network element.

[0209] The authentication response includes information required for the network authentication procedure.

[0210] For the description and specific details of the above steps S1002-S1003, please refer to the related description and details of the above steps S901-S902.

[0211] ​According to the authentication method of this disclosure, the UE can receive an authentication request from the AMF network element and send an authentication response to the AMF network element, including the information required for the network authentication process, to trigger the network authentication process for the UE. This enables a mechanism for triggering the network authentication process for the UE from the network side, which can greatly improve the continuity and security of network services.

[0212] In some embodiments, the authentication request received from the AMF network element may include access type information, which indicates the access type that can be applied to the initiated network authentication process, including 3GPP access and / or non-3GPP access.

[0213] Figure 11 A schematic flowchart of an authentication method according to an embodiment of this disclosure is shown. This method can be executed by a UE, based on... Figure 9 The illustrated embodiments, such as Figure 11 As shown, the method may include the following steps.

[0214] S1101 receives authentication requests from AMF network elements.

[0215] The authentication request is used to request the UE to perform the network authentication process.

[0216] For a description and specific details of step S1101 above, please refer to the relevant description and details of step S901 above.

[0217] S1102 provides security protection for authentication responses based on the NAS security context of local storage.

[0218] After receiving an authentication request, the UE can send an authentication response to the AMF network element through the NAS connection between the UE and the AMF network element to provide the information required for the network authentication process.

[0219] For security reasons, the UE can protect the authentication response based on the locally stored NAS security context, for example, by encrypting it, before sending the protected authentication response to the AMF network element. Upon receiving the protected authentication response, the AMF network element can parse it using the locally stored NAS security context to obtain the content of the authentication response.

[0220] S1103 sends a secure authentication response back to the AMF network element.

[0221] The authentication response includes the information required for the network authentication process.

[0222] For a description and specific details of step S1103 above, please refer to the relevant description and details of step S902 above.

[0223] According to the authentication method of this disclosure, the UE can receive an authentication request from the AMF network element and send an authentication response to the AMF network element, including the information required for the network authentication process, to trigger the network authentication process for the UE. This enables a mechanism for triggering the network authentication process for the UE from the network side, which can greatly improve the continuity and security of network services.

[0224] It should be noted that, although Figure 11 The illustrated embodiments are only in Figure 9 The description is based on the illustrated embodiment; similarly, the Figure 11 The illustrated embodiments can also be based on Figure 10 The illustrated embodiment, for example, Figure 11 Step S1102 can also be combined with Figure 10 The steps S1001-S1003 are combined, and will not be repeated here.

[0225] In some embodiments, the authentication request received from the AMF network element may include access type information, which indicates the access type that can be applied to the initiated network authentication process, including 3GPP access and / or non-3GPP access.

[0226] Figure 12 A schematic flowchart of an authentication method according to an embodiment of this disclosure is shown. This method can be executed by a UE, based on... Figure 9 The illustrated embodiments, such as Figure 12 As shown, the method may include the following steps.

[0227] S1201 receives authentication requests from AMF network elements.

[0228] The authentication request is used to request the UE to perform the network authentication process.

[0229] S1202 provides security protection for authentication responses based on the NAS security context of local storage.

[0230] S1203 sends a secure authentication response back to the AMF network element.

[0231] The authentication response includes the information required for the network authentication process.

[0232] For a description and specific details of steps S1201-S1203 above, please refer to the relevant description and details of steps S1101-S1103 above.

[0233] S1204 updates the NAS security context of the local storage after the network authentication process is completed.

[0234] After confirming the completion of the network authentication process, the UE can update the NAS security context stored locally. After completing the NAS security model command flow to activate the updated NAS security context, the UE can use the updated NAS security context to protect the specified message.

[0235] According to the authentication method of this disclosure, the UE can receive an authentication request from the AMF network element and send an authentication response to the AMF network element, including the information required for the network authentication process, to trigger the network authentication process for the UE. This enables a mechanism for triggering the network authentication process for the UE from the network side, which can greatly improve the continuity and security of network services.

[0236] In some embodiments, the authentication request received from the AMF network element may include access type information, which indicates the access type that can be applied to the initiated network authentication process, including 3GPP access and / or non-3GPP access.

[0237] Figure 13 A flowchart illustrating an authentication method according to an embodiment of this disclosure is shown. This method can be executed by interaction between the UE, AMF network element, AUSF network element, and UDM network element, such as... Figure 13 As shown, the method may include the following steps.

[0238] S1301, the AUSF network element sends a network authentication process trigger instruction to the UDM network element.

[0239] The network authentication process triggering indication includes the identifier of the user equipment (UE) corresponding to the AUSF network element, and the network authentication process triggering indication is used to instruct the UDM network element to trigger the network authentication process for the UE.

[0240] The UE's identifier can be either a Generic Public Subscription Identifier (GPSI) or a Subscription Permanent Identifier (SUPI).

[0241] For example, when an AUSF network element determines that it needs to regenerate the AUSF network element key K. AUSF In cases such as the current K AUSF In the event of an invalid network, the AUSF network element can send a network authentication process trigger indication to the UDM network element, which carries the identifier of the UE corresponding to the AUSF network element.

[0242] S1302, the UDM network element sends an authentication notification message to the AMF network element.

[0243] The authentication notification message includes the UE's identifier and is used to notify the AMF network element to perform the network authentication process for the UE.

[0244] After receiving a network authentication process trigger instruction, the UDM network element can send an authentication notification message to the AMF network element in response to the network authentication process trigger instruction, so as to notify the AMF network element to perform a network authentication process for the UE.

[0245] The specific implementation of the UE's network authentication process can refer to existing network authentication processes. For example, the specific implementation of the network authentication process shown in this application is similar to the implementation of the network authentication process initiated by the UE by sending a registration request to the AMF network element, and will not be described in detail here.

[0246] S1303, the AMF network element sends an authentication request to the UE.

[0247] The authentication request is used to request the UE to perform the network authentication process.

[0248] After receiving the authentication notification message, the AMF network element can send an authentication request to the UE through the Non-Access Stratum (NAS) connection between the AMF network element and the UE to request the UE to perform the network authentication process.

[0249] Upon receiving an authentication communication message carrying the UE's identifier, if the MF network element finds that no NAS connection exists between the UE and the AMF network element, the 5G core network will page the UE. If the UE is in a registered (RM-REGISTERED) or CM-idle state, the AMF can send a paging message to the UE via a 5G radio access network (NG-RAN) node to establish a NAS connection with the UE. If the UE is in a connected (CM-CONNECTED) state, it indicates that a NAS connection already exists between the UE and the AMF network element. The AMF network element then communicates with the UE through this NAS connection.

[0250] S1304, the AMF network element receives the authentication response from the UE.

[0251] The authentication response includes the information required for the network authentication process.

[0252] After receiving an authentication request from an AMF network element, the UE can send an authentication response back to the AMF network element to provide the AMF network element with the information required for the network authentication process.

[0253] According to the authentication method of this disclosure embodiment, the AUSF network element sends a network authentication process triggering instruction to the UDM network element. In response to the network authentication process triggering instruction, the UDM network element sends an authentication notification message to the AMF network element to notify the AMF network element to perform a network authentication process for the UE. After receiving the authentication notification message from the AUSF network element, the AMF network element sends an authentication request to the UE and obtains an authentication response from the UE including the information required for the network authentication process, thereby triggering the network authentication process for the UE. This realizes a mechanism for triggering the network authentication process for the UE from the network side, which can greatly improve the continuity and security of network services.

[0254] In some embodiments, the network authentication process trigger indication and authentication notification message may further include an authentication reason for the AUSF network element request to trigger the network authentication process, and the authentication reason may include at least one of the following: the roaming manipulation count has reached the upper limit; and the UE parameter update count has reached the upper limit.

[0255] When an AUSF network element determines that it needs to regenerate the AUSF network element key K AUSF In cases such as the current K AUSF In the event of an invalid authentication process, the AUSF network element can send a network authentication process trigger indication to the UDM network element.

[0256] K AUSF Invalidity may be due to the roaming manipulation count reaching the upper limit and / or the UE parameter update count reaching the upper limit. Therefore, the reason why the UDM network element sends an authentication notification message to trigger the network authentication process for the UE may be that the roaming manipulation count has reached the upper limit and / or the UE parameter update count has reached the upper limit.

[0257] In some embodiments, the authentication notification message sent by the UDM network element and the authentication request sent by the AMF network element to the UE may also include access type information, which is used to indicate the access type that can be applied to the initiated network authentication process. The access type includes 3rd Generation Partnership Project (3GPP) access and / or non-3GPP access.

[0258] For example, if the access type information in the authentication notification message received by the AMF network element indicates 3GPP access, the AMF network element can confirm that the initiated network authentication process is only for 3GPP access, and the authentication request sent by the AMF network element to the UE carries the access type information so that the UE can confirm that the network authentication process is only for 3GPP access.

[0259] For example, if the access type information in the authentication notification message received by the AMF network element indicates non-3GPP access, the AMF network element can confirm that the initiated network authentication process is only for non-3GPP access, and the authentication request sent by the AMF network element to the UE carries the access type information so that the UE can confirm that the network authentication process is only for non-3GPP access.

[0260] For example, if the access type information in the authentication notification message received by the AMF network element indicates 3GPP access and non-3GPP access, the AMF network element can confirm that the initiated network authentication process is for both 3GPP access and non-3GPP access, and the authentication request sent by the AMF network element to the UE carries the access type information so that the UE can confirm that the network authentication process is for both 3GPP access and non-3GPP access.

[0261] In some embodiments, the authentication notification message includes a confirmation request indication for requesting an authentication notification confirmation message from the AMF network element. The authentication method may also include the AMF network element sending an authentication notification confirmation message to the UDM network element, wherein the authentication notification confirmation message is used to indicate that the AMF network element has requested the UE to perform the network authentication process.

[0262] The authentication notification message sent by the UDM network element may also include a confirmation request indication for requesting an authentication notification confirmation message from the AMF network element. If the authentication notification message includes a confirmation request indication, the AMF network element can send an authentication notification confirmation message to the UDM network element after sending an authentication request to the UE to notify the UDM network element that the network authentication process for the UE has been triggered. If the AMF network element fails to send an authentication request to the UE, it will not send an authentication notification confirmation message to the UDM network element. If the UDM network element does not receive the authentication notification confirmation message within a preset time period, it can confirm that the triggering of the network authentication process for the UE has failed.

[0263] In some embodiments, the authentication method may further include, after the network authentication process is completed, the AUSF network element generating a new AUSF network element key and resetting the roaming manipulation count and UE parameter update count.

[0264] After confirming the completion of the network authentication process, the AUSF network element can generate a new AUSF network element key K. AUSF And reset the roaming manipulation count and UE parameter update count, i.e., Counter SoR Set to 0x00 0x01, and set Counter UPU Set to 0x00 0x01.

[0265] Figure 14A flowchart illustrating an authentication method according to an embodiment of this disclosure is shown. This method can be implemented through interaction between the UE, AMF network element, AUSF network element, and UDM network element, such as... Figure 14 As shown, the method may include the following steps.

[0266] S1401, the AUSF network element sends a network authentication process trigger indication to the UDM network element. This network authentication process trigger indication can be a Nausf_SoRProtection Response and / or a Nausf_UPUPtrotection Response. The Nausf_SoRProtection Response can indicate the process triggering the network authentication process with the K network element. AUSF Related Counter SoR Upon reaching the limit, the Nasuf_UPUPtrotection Response can indicate the relationship with K. AUSF Related Counter UPU The limit has been reached.

[0267] S1402, the UDM network element sends an Authentication Notification message (e.g., Nausf_UECM_AuthenticationNotification) to the AMF network element. This authentication notification message may include SUPI, access type, authentication reason, etc. The authentication reason can be a Counter. SoR Reaching the limit and / or Counter UPU The limit has been reached. The access type indicates whether the authentication process uses 3GPP access, non-3GPP access, or both.

[0268] S1403, considering that the UE may not have a NAS connection with the AMF network element, the 5G core network can page the UE. If the UE is in a registered (RM-REGISTERED) or CM-idle state (i.e., reachable via 3GPP access), the AMF can send a paging message to the UE via the 5G Radio Access Network (NG-RAN) node to establish a NAS connection with the UE. If the UE is in a connected (CM-CONNECTED) state, this step can be omitted.

[0269] S1404 Once the NAS connection between the UE and the AMF network element is established, the AMF network element can send an HN-triggered Authentication Request to the UE. This request may include the access type and may be protected by the NAS security context.

[0270] S1405, if the UDM network element has requested authentication notification confirmation from the AMF network element, then the AMF network element sends an authentication notification confirmation message ACK to the UDM network element.

[0271] S1406, the UE sends an HN-triggered Authentication Response to the AMF network element. This response may include information required for the network authentication process, such as the UE's own capability information.

[0272] S1407, The Security Anchor Function (SEAF) network element triggers the authentication service by sending an authentication request message Nausf_UEAuthentication_Authenticate Request to the AUSF network element. This message may include information such as SUCI or SUPI and the service network name.

[0273] S1408, the AUSF network element sends an authentication acquisition request message Nudm_UEAuthentication_GetRequest to the UDM network element. This message may include information such as SUPI and service network name. The UDM network element can select the authentication method based on SUPI.

[0274] S1409, based on the authentication method selected by the UDM network element, performs an improved extensible authentication protocol-authentication and key agreement (EAP-AKA) or 5G-AKA process.

[0275] S1410, the AUSF network element generates and stores a new K AUSF The authentication result confirmation request (Nudm_UEAuthentication_ResultConfirmation Request) is used to notify the UDM network element of the result and time of the network authentication process. Additionally, the AUSF network element checks the Counter... SoR and Counter UPU Reset.

[0276] S1411, the UDM network element stores the UE's authentication status information, including SUPI, authentication result indicating authentication success or failure, timestamp indicating the time of execution of the network authentication process, and service network name, etc.

[0277] S1412, the UDM network element sends an authentication result confirmation response, Nudm_UEAuthentication_ResultConfirmation Response, to the AUSF network element to indicate that the authentication result confirmation request has been received.

[0278] In the embodiments provided above, the methods provided by the embodiments of this application have been described from the perspectives of network devices and user equipment, respectively. To implement the functions of the methods provided in the embodiments of this application, the network device and the user equipment may include hardware structures and software modules, and may implement the above functions in the form of hardware structures, software modules, or a combination of hardware structures and software modules. One of the above functions may be executed in the form of hardware structures, software modules, or a combination of hardware structures and software modules.

[0279] Corresponding to the authentication methods provided in the above embodiments, this disclosure also provides an authentication device. Since the authentication device provided in this disclosure corresponds to the authentication methods provided in the above embodiments, the implementation methods of the authentication methods are also applicable to the authentication device provided in this embodiment, and will not be described in detail in this embodiment.

[0280] Figure 15 This is a schematic diagram of the structure of an authentication device 1500 provided in an embodiment of the present disclosure. This device can be used in UDM network elements.

[0281] like Figure 15 As shown, the device 1500 may include a transceiver module 1501.

[0282] The transceiver module 1501 is configured to receive a network authentication process trigger indication from an authentication server function (AUSF) network element, wherein the network authentication process trigger indication includes an identifier of a user equipment (UE) corresponding to the AUSF network element, and the network authentication process trigger indication is used to instruct the UDM network element to trigger a network authentication process for the UE; and to send an authentication notification message to an access and mobility management function (AMF) network element, wherein the authentication notification message includes an identifier of the UE, and the authentication notification message is used to notify the AMF network element to perform a network authentication process for the UE.

[0283] According to the authentication apparatus of this disclosure, the UDM network element receives a network authentication process triggering instruction from the AMF network element and sends an authentication notification message to the AMF network element in response to the network authentication process triggering instruction, thereby realizing a mechanism for triggering the network authentication process for the UE by the network side, which can greatly improve the continuity and security of network services.

[0284] In some embodiments, the authentication notification message further includes access type information, which indicates the access type that can be applied to the initiated network authentication process, including 3GPP access and / or non-3GPP access.

[0285] In some embodiments, the network authentication process triggering indication and the authentication notification message further include the authentication reason for the AUSF network element requesting to trigger the network authentication process, the authentication reason including at least one of the following: the roaming manipulation count has reached the upper limit; and the UE parameter update count has reached the upper limit.

[0286] In some embodiments, the authentication notification message further includes a confirmation request indication for requesting an authentication notification confirmation message from the AMF network element, wherein the authentication notification confirmation message is used to indicate that the AMF network element has requested the UE to perform the network authentication process.

[0287] Figure 16 This is a schematic diagram of the structure of an authentication device 1600 provided in an embodiment of the present disclosure. This device can be used in AUSF network elements.

[0288] like Figure 16 As shown, the device 1600 may include a transceiver module 1601.

[0289] The transceiver module 1601 is used to send a network authentication process triggering indication to the Unified Data Management (UDM) network element, wherein the network authentication process triggering indication includes the identifier of the user equipment (UE) corresponding to the AUSF network element, and the network authentication process triggering indication is used to instruct the UDM network element to trigger a network authentication process for the UE.

[0290] According to the authentication apparatus of this disclosure, the AMF network element sends a network authentication process triggering instruction to the UDM network element, and the UDM network element can respond to the network authentication triggering instruction by sending an authentication notification message to the AMF network element. This enables a mechanism for triggering the network authentication process for the UE from the network side, which can greatly improve the continuity and security of network services.

[0291] In some embodiments, the network authentication process triggering indication further includes the authentication reason requested by the AUSF network element to trigger the network authentication process, the authentication reason including at least one of the following: the roaming manipulation count has reached the upper limit; and the UE parameter update count has reached the upper limit.

[0292] In some embodiments, such as Figure 17 As shown, the device 1600 also includes a processing module 1602, which is used to generate a new AUSF network element key and reset the values ​​of roaming manipulation count and UE parameter update count after confirming that the network authentication process is completed.

[0293] Figure 18 This is a schematic diagram of the structure of an authentication device 1800 provided in an embodiment of this disclosure. The authentication device 1800 can be used in AMF network elements.

[0294] like Figure 18 As shown, the device 1800 may include a transceiver module 1801.

[0295] The transceiver module 1801 is configured to receive an authentication notification message from a UDM network element, wherein the authentication notification message includes a UE identifier and is used to notify the AMF network element to perform a network authentication process for the UE; send an authentication request to the UE through a NAS connection between the AMF network element and the UE, wherein the authentication request is used to request the UE to perform the network authentication process; and receive an authentication response from the UE, wherein the authentication response includes information required to perform the network authentication process.

[0296] According to the authentication apparatus of the present disclosure, the AMF network element can receive an authentication notification message from the UDM network element, send an authentication request to the UE, and obtain an authentication response from the UE including information required for the network authentication process, so as to trigger the network authentication process for the UE. This enables a mechanism for triggering the network authentication process for the UE from the network side, which can greatly improve the continuity and security of network services.

[0297] In some embodiments, the transceiver module 1801 is further configured to: send a paging message to the UE to create the NAS connection.

[0298] In some embodiments, the authentication notification message further includes a confirmation request indication for requesting an authentication notification confirmation message from the AMF network element, and the transceiver module 1801 is further configured to: send the authentication notification confirmation message to the UDM network element, wherein the authentication notification confirmation message is used to indicate that the AMF network element has requested the UE to perform the network authentication process.

[0299] In some embodiments, such as Figure 19 As shown, the device 1800 further includes a processing module 1802, which is used to: provide security protection for the authentication request based on the NAS security context of the local storage.

[0300] In some embodiments, the processing module 1802 is further configured to: update the NAS security context of the local storage after the network authentication process is completed.

[0301] In some embodiments, the authentication request and the authentication notification message further include access type information, which indicates the access type that can be applied to the initiated network authentication process, including 3GPP access and / or non-3GPP access.

[0302] In some embodiments, the authentication notification message may further include the authentication reason for the UDM network element to send the authentication notification message, and the authentication reason may include at least one of the following: the roaming manipulation count has reached the upper limit; and the UE parameter update count has reached the upper limit.

[0303] Figure 20 This is a schematic diagram of the structure of an authentication device 2000 provided in an embodiment of this disclosure. The authentication device 2000 can be used in a UE.

[0304] like Figure 20 As shown, the device 2000 may include a transceiver module 2001.

[0305] The transceiver module 2001 is used to receive an authentication request from the AMF network element, wherein the authentication request is used to request the UE to perform a network authentication process; and to send an authentication response back to the AMF network element, wherein the authentication response includes information required to perform the network authentication process.

[0306] According to the authentication apparatus of this disclosure, the UE can receive an authentication request from the AMF network element and send an authentication response to the AMF network element, including information required for the network authentication process, to trigger the network authentication process for the UE. This enables a mechanism for triggering the network authentication process for the UE from the network side, which can greatly improve the continuity and security of network services.

[0307] In some embodiments, the transceiver module 2001 is further configured to: receive a paging message from the AMF network element to establish a NAS connection with the AMF network element.

[0308] In some embodiments, such as Figure 21 As shown, the device 2000 further includes a processing module 2002, which is used to: perform security protection on the authentication response according to the NAS security context of the local storage.

[0309] In some embodiments, the processing module 2002 is further configured to: update the NAS security context of the local storage after the network authentication process is completed.

[0310] In some embodiments, the authentication request includes access type information, which indicates the access type that can be applied to the initiated network authentication process, including 3GPP access and / or non-3GPP access.

[0311] This application also provides an authentication system, which includes the aforementioned... Figure 15 The UDM network element described in the embodiment Figure 16-17 The AUSF network element described in the embodiment Figure 18-19 The AMF network element described in the embodiment.

[0312] Please see Figure 22 , Figure 22 This is a schematic diagram of the structure of a communication device 2200 provided in an embodiment of this application. The communication device 2200 can be a network device, a user device, a chip, chip system, or processor that supports the network device in implementing the above methods, or a chip, chip system, or processor that supports the user device in implementing the above methods. This device can be used to implement the methods described in the above method embodiments; for details, please refer to the descriptions in the above method embodiments.

[0313] The communication device 2200 may include one or more processors 2201. The processor 2201 may be a general-purpose processor or a dedicated processor, such as a baseband processor or a central processing unit (CPU). The baseband processor can be used to process communication protocols and communication data, while the CPU can be used to control the communication device (e.g., base station, baseband chip, terminal equipment, terminal equipment chip, DU or CU, etc.), execute computer programs, and process data from the computer programs.

[0314] Optionally, the communication device 2200 may further include one or more memories 2202, which may store a computer program 2204. The processor 2201 executes the computer program 2204 to cause the communication device 2200 to perform the method described in the above method embodiments. Optionally, the memory 2202 may also store data. The communication device 2200 and the memory 2202 may be provided separately or integrated together.

[0315] Optionally, the communication device 2200 may also include a transceiver 2205 and an antenna 2206. The transceiver 2205 may be referred to as a transceiver unit, transceiver, or transceiver circuit, etc., and is used to implement the transmission and reception functions. The transceiver 2205 may include a receiver and a transmitter. The receiver may be referred to as a receiver or receiving circuit, etc., and is used to implement the receiving function; the transmitter may be referred to as a transmitter or transmitting circuit, etc., and is used to implement the transmitting function.

[0316] Optionally, the communication device 2200 may further include one or more interface circuits 2207. The interface circuits 2207 are used to receive code instructions and transmit them to the processor 2201. The processor 2201 executes the code instructions to cause the communication device 2200 to perform the methods described in the above method embodiments.

[0317] In one implementation, the processor 2201 may include a transceiver for implementing receiving and transmitting functions. For example, the transceiver may be a transceiver circuit, an interface, or an interface circuit. The transceiver circuit, interface, or interface circuit for implementing receiving and transmitting functions may be separate or integrated. The aforementioned transceiver circuit, interface, or interface circuit can be used for reading and writing code / data, or it can be used for transmitting or relaying signals.

[0318] In one implementation, processor 2201 may store computer program 2203, which runs on processor 2201 and enables communication device 2200 to execute the methods described in the above method embodiments. Computer program 2203 may be embedded in processor 2201; in this case, processor 2201 may be implemented in hardware.

[0319] In one implementation, the communication device 2200 may include circuitry capable of performing the functions of transmitting, receiving, or communicating as described in the foregoing method embodiments. The processor and transceiver described in this application can be implemented on integrated circuits (ICs), analog ICs, radio frequency integrated circuits (RFICs), mixed-signal ICs, application-specific integrated circuits (ASICs), printed circuit boards (PCBs), electronic devices, etc. The processor and transceiver can also be manufactured using various IC process technologies, such as complementary metal-oxide-semiconductor (CMOS), n-metal-oxide-semiconductor (NMOS), positive-channel metal-oxide-semiconductor (PMOS), bipolar junction transistors (BJTs), bipolar CMOS (BiCMOS), silicon-germanium (SiGe), gallium arsenide (GaAs), etc.

[0320] The communication device described in the above embodiments may be a network device or a user equipment, but the scope of the communication device described in this application is not limited thereto, and the structure of the communication device may vary. Figure 22 The communication device may be a standalone device or part of a larger device. For example, the communication device may be:

[0321] (1) Independent integrated circuit IC, or chip, or chip system or subsystem;

[0322] (2) A collection of one or more ICs, optionally including storage components for storing data and computer programs;

[0323] (3) ASIC, such as modem;

[0324] (4) Modules that can be embedded in other devices;

[0325] (5) Receivers, terminal equipment, smart terminal equipment, cellular phones, wireless equipment, handheld devices, mobile units, vehicle-mounted equipment, network equipment, cloud equipment, artificial intelligence equipment, etc.

[0326] (6) Others, etc.

[0327] For cases where the communication device can be a chip or a chip system, please refer to [link / reference]. Figure 23 The diagram shows the structure of the chip. Figure 23 The chip shown includes a processor 2301 and an interface 2302. There can be one or more processors 2301, and multiple interfaces 2302.

[0328] Optionally, the chip also includes a memory 2303, which is used to store necessary computer programs and data.

[0329] Those skilled in the art will also understand that the various illustrative logical blocks and steps listed in the embodiments of this application can be implemented by electronic hardware, computer software, or a combination of both. Whether such functionality is implemented through hardware or software depends on the specific application and the overall system design requirements. Those skilled in the art can implement the described functionality using various methods for each specific application, but such implementation should not be construed as exceeding the scope of protection of the embodiments of this application.

[0330] This application also provides a readable storage medium having instructions stored thereon that, when executed by a computer, implement the functions of any of the above method embodiments.

[0331] This application also provides a computer program product that, when executed by a computer, implements the functions of any of the above method embodiments.

[0332] In the above embodiments, implementation can be achieved, in whole or in part, through software, hardware, firmware, or any combination thereof. When implemented using software, it can be implemented, in whole or in part, as a computer program product. The computer program product includes one or more computer programs. When the computer program is loaded and executed on a computer, all or part of the processes or functions described in the embodiments of this application are generated. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer program can be stored in a computer-readable storage medium or transferred from one computer-readable storage medium to another. For example, the computer program can be transferred from one website, computer, server, or data center to another via wired (e.g., coaxial cable, fiber optic, digital subscriber line (DSL)) or wireless (e.g., infrared, wireless, microwave, etc.) means. The computer-readable storage medium can be any available medium accessible to a computer or a data storage device such as a server or data center that integrates one or more available media. The available media may be magnetic media (e.g., floppy disks, hard disks, magnetic tapes), optical media (e.g., high-density digital video discs (DVDs)), or semiconductor media (e.g., solid-state disks (SSDs)).

[0333] Those skilled in the art will understand that the various numerical designations such as "first," "second," etc., involved in this application are merely for the convenience of description and are not intended to limit the scope of the embodiments of this application, nor do they indicate the order of sequence.

[0334] At least one in this application can also be described as one or more, and multiple can be two, three, four or more, and this application does not impose any limitation. In the embodiments of this application, for a technical feature, the technical features in that technical feature are distinguished by "first", "second", "third", "A", "B", "C" and "D", and there is no order or size among the technical features described by "first", "second", "third", "A", "B", "C" and "D".

[0335] As used herein, the terms "machine-readable medium" and "computer-readable medium" refer to any computer program product, device, and / or apparatus (e.g., disk, optical disk, memory, programmable logic device (PLD)) used to provide machine instructions and / or data to a programmable processor, including machine-readable media that receive machine instructions as machine-readable signals. The term "machine-readable signal" refers to any signal used to provide machine instructions and / or data to a programmable processor.

[0336] The systems and technologies described herein can be implemented in computing systems that include backend components (e.g., as a data server), or computing systems that include middleware components (e.g., an application server), or computing systems that include frontend components (e.g., a user computer with a graphical user interface or web browser through which a user can interact with embodiments of the systems and technologies described herein), or any combination of such backend, middleware, or frontend components. The components of the system can be interconnected via digital data communication of any form or medium (e.g., a communication network). Examples of communication networks include local area networks (LANs), wide area networks (WANs), and the Internet.

[0337] Computer systems can include clients and servers. Clients and servers are generally located far apart and typically interact through communication networks. Client-server relationships are created by computer programs running on the respective computers and having a client-server relationship with each other.

[0338] It should be understood that the various forms of processes shown above can be used to rearrange, add, or delete steps. For example, the steps described in this disclosure can be executed in parallel, sequentially, or in different orders, as long as the desired result of the technical solution disclosed in this disclosure can be achieved, and this is not limited herein.

[0339] Furthermore, it should be understood that the various embodiments described in this application can be implemented individually or in combination with other embodiments, where the scheme allows.

[0340] Those skilled in the art will recognize that the units and algorithm steps of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.

[0341] Those skilled in the art will understand that, for the sake of convenience and brevity, the specific working processes of the systems, devices, and units described above can be referred to the corresponding processes in the foregoing method embodiments, and will not be repeated here.

[0342] The above description is merely a specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.

Claims

1. An authentication method, characterized in that, The method is executed by a unified data management (UDM) network element, and the method includes: The network authentication process triggering indication is received from the authentication server (AUSF) network element, wherein the network authentication process triggering indication includes the identifier of the user equipment (UE) corresponding to the AUSF network element, and the network authentication process triggering indication is used to instruct the UDM network element to trigger a network authentication process for the UE; and Send an authentication notification message to the Access and Mobility Management Function (AMF) network element, wherein the authentication notification message includes the identifier of the UE, and the authentication notification message is used to notify the AMF network element to perform a network authentication process for the UE; The reason why the UDM network element sends the authentication notification message to trigger the network authentication process for the UE includes at least one of the following: the roaming manipulation count reaches the upper limit; and the UE parameter update count reaches the upper limit.

2. The method as described in claim 1, characterized in that, The system receives an authentication notification confirmation message sent by the AMF, which indicates that the AMF network element has successfully requested the UE to perform the network authentication process.

3. The method as described in any one of claims 1 or 2, characterized in that, The network authentication process trigger indication is sent to the UDM when the AUSF network element determines that it needs to regenerate the AUSF network element key corresponding to the user equipment (UE).

4. The method as described in claim 1, characterized in that, The authentication notification message also includes access type information, which indicates the access type that can be applied to the initiated network authentication process. The access type includes 3GPP access and / or non-3GPP access.

5. The method as described in claim 1 or 2, characterized in that, The network authentication process triggering indication and the authentication notification message also include the authentication reason for the AUSF network element request to trigger the network authentication process, and the authentication reason includes at least one of the following: The roaming manipulation count has reached its maximum value; as well as The UE parameter update count has reached its upper limit.

6. The method as described in claim 2, characterized in that, The authentication notification message also includes a confirmation request indication for requesting an authentication notification confirmation message from the AMF network element.

7. An authentication method, characterized in that, The method is executed by the authentication server function AUSF network element, and the method includes: A network authentication process triggering indication is sent to the Unified Data Management (UDM) network element. The network authentication process triggering indication includes the identifier of the User Equipment (UE) corresponding to the AUSF network element, and the network authentication process triggering indication is used to instruct the UDM network element to trigger a network authentication process for the UE. The identifier of the UE is also carried in an authentication notification message, which is a message sent by the UDM network element to the Access and Mobility Management Function (AMF) network element to notify the AMF network element to perform a network authentication process for the UE. The reasons for the UDM network element to trigger the network authentication process for the UE include at least one of the following: the roaming manipulation count reaches the upper limit; and the UE parameter update count reaches the upper limit.

8. The method as described in claim 7, characterized in that, The network authentication process triggering indication also includes the authentication reason requested by the AUSF network element to trigger the network authentication process, and the authentication reason includes at least one of the following: The roaming manipulation count has reached its maximum value; as well as The UE parameter update count has reached its upper limit.

9. The method as described in claim 7, characterized in that, Sending a network authentication process trigger instruction to the Unified Data Management (UDM) network element includes: determining that the AUSF network element key corresponding to the User Equipment (UE) needs to be regenerated, and sending the network authentication process trigger instruction to the UDM.

10. The method according to any one of claims 7-9, characterized in that, Also includes: After confirming the completion of the network authentication process, a new AUSF network element key corresponding to the user equipment (UE) is generated, and the values ​​of the roaming manipulation count and UE parameter update count are reset.

11. An authentication method, characterized in that, The method is executed by an Access and Mobility Management Function (AMF) network element, and the method includes: The system receives an authentication notification message from a Unified Data Management (UDM) network element, wherein the authentication notification message includes the UE's identifier and is used to notify the AMF network element to perform a network authentication process for the UE; and The system receives an authentication response sent by the UE in response to an authentication request. The authentication response includes information required to perform the network authentication process. The authentication request is sent by the AMF network element to the UE to request the UE to perform the network authentication process. The reason why the UDM network element sends the authentication notification message to trigger the network authentication process for the UE includes at least one of the following: the roaming manipulation count reaches the upper limit; and the UE parameter update count reaches the upper limit.

12. The method as described in claim 11, characterized in that, Also includes: A paging message is sent to the UE to establish a NAS connection between the AMF network element and the UE, and an authentication request is sent to the UE through the NAS connection.

13. The method as described in claim 11, characterized in that, Send an authentication notification confirmation message to the UDM network element, wherein the authentication notification confirmation message is used to indicate that the AMF network element has successfully requested the UE to perform the network authentication process.

14. The method as described in claim 13, characterized in that, The authentication notification message also includes a confirmation request indication for requesting an authentication notification confirmation message from the AMF network element.

15. The method according to any one of claims 11-14, characterized in that, Also includes: The authentication request is protected by the NAS security context of the local storage.

16. The method as described in claim 15, characterized in that, Also includes: After the network authentication process is completed, the NAS security context of the local storage is updated.

17. An authentication method, characterized in that, The authentication method is applied to communication equipment, which includes a terminal and network equipment. The network equipment includes an Authentication Server Function (AUSF) network element, a Unified Data Management (UDM) network element, and an Access and Mobility Management Function (AMF) network element. The method includes: The authentication server function AUSF network element sends a network authentication process triggering instruction to the unified data management UDM network element. The network authentication process triggering instruction includes the identifier of the user equipment (UE) corresponding to the AUSF network element, and the network authentication process triggering instruction is used to instruct the UDM network element to trigger a network authentication process for the UE. In response to the authentication process trigger indication, the UDM network element sends an authentication notification message to the AMF network element, wherein the authentication notification message includes the UE's identifier and is used to notify the AMF network element to perform a network authentication process for the UE; The reason why the UDM network element sends the authentication notification message to trigger the network authentication process for the UE includes at least one of the following: the roaming manipulation count reaches the upper limit; and the UE parameter update count reaches the upper limit.

18. The method as described in claim 17, characterized in that, The AMF network element sends an authentication request to the UE, wherein the authentication request is used to request the UE to perform the network authentication process; and The AMF network element receives the authentication response from the UE, wherein the authentication response includes information required for the network authentication process.

19. The method as described in claim 18, characterized in that, The AMF network element sends an authentication notification confirmation message to the UDM network element, wherein the authentication notification confirmation message is used to indicate that the AMF network element has successfully requested the UE to perform the network authentication process.

20. The method as described in claim 19, characterized in that, The authentication notification message includes a confirmation request indication for requesting an authentication notification confirmation message from the AMF network element.

21. The method according to any one of claims 17-19, characterized in that, Also includes: After the network authentication process is completed, the AUSF network element generates a new AUSF network element key corresponding to the user equipment (UE) and resets the roaming manipulation count and UE parameter update count.

22. The method according to any one of claims 17-19, characterized in that, Sending a network authentication process trigger instruction to the Unified Data Management (UDM) network element includes: the AUSF network element determining that it needs to regenerate the AUSF network element key corresponding to the User Equipment (UE), and sending the network authentication process trigger instruction to the UDM.

23. The method according to any one of claims 18-19, characterized in that, The authentication notification message and the authentication request also include access type information, which indicates the access type that can be applied to the initiated network authentication process. The access type includes 3GPP access and / or non-3GPP access.

24. The method according to any one of claims 17-19, characterized in that, The network authentication process triggering indication and the authentication notification message also include the authentication reason for the AUSF network element request to trigger the network authentication process, and the authentication reason includes at least one of the following: The roaming manipulation count has reached its maximum value; as well as The UE parameter update count has reached its upper limit.

25. An authentication device, characterized in that, Unified Data Management (UDM) network elements, including a transceiver module, are used for: The network authentication process triggering indication is received from the authentication server (AUSF) network element, wherein the network authentication process triggering indication includes the identifier of the user equipment (UE) corresponding to the AUSF network element, and the network authentication process triggering indication is used to instruct the UDM network element to trigger a network authentication process for the UE; and Send an authentication notification message to the Access and Mobility Management Function (AMF) network element, wherein the authentication notification message includes the identifier of the UE, and the authentication notification message is used to notify the AMF network element to perform a network authentication process for the UE; The reason why the UDM network element sends the authentication notification message to trigger the network authentication process for the UE includes at least one of the following: the roaming manipulation count reaches the upper limit; and the UE parameter update count reaches the upper limit.

26. The apparatus as claimed in claim 25, characterized in that, The system receives an authentication notification confirmation message sent by the AMF, which indicates that the AMF network element has successfully requested the UE to perform the network authentication process.

27. The apparatus as claimed in claim 25 or 26, characterized in that, The network authentication process trigger indication is sent to the UDM when the AUSF network element determines that it needs to regenerate the AUSF network element key corresponding to the user equipment (UE).

28. An authentication device, characterized in that, AUSF network elements for network authentication server functions include a transceiver module, which is used for: A network authentication process triggering indication is sent to the Unified Data Management (UDM) network element. The network authentication process triggering indication includes the identifier of the User Equipment (UE) corresponding to the AUSF network element, and the network authentication process triggering indication is used to instruct the UDM network element to trigger a network authentication process for the UE. The identifier of the UE is also carried in an authentication notification message, which is a message sent by the UDM network element to the Access and Mobility Management Function (AMF) network element to notify the AMF network element to perform a network authentication process for the UE. The reasons for the UDM network element to trigger the network authentication process for the UE include at least one of the following: the roaming manipulation count reaches the upper limit; and the UE parameter update count reaches the upper limit.

29. The apparatus as claimed in claim 28, characterized in that, The device is also used for: After confirming the completion of the network authentication process, a new AUSF network element key corresponding to the user equipment (UE) is generated, and the values ​​of the roaming manipulation count and UE parameter update count are reset.

30. An authentication device, characterized in that, A network element for Access and Mobility Management Functions (AMF) includes a transceiver module, which is used for: The system receives an authentication notification message from a Unified Data Management (UDM) network element, wherein the authentication notification message includes the UE's identifier and is used to notify the AMF network element to perform a network authentication process for the UE; and The system receives an authentication response sent by the UE in response to an authentication request. The authentication response includes information required to perform the network authentication process. The authentication request is sent by the AMF network element to the UE and is used to request the UE to perform the network authentication process. The reasons for the UDM network element to send the authentication notification message include at least one of the following: the roaming manipulation count has reached the upper limit; and the UE parameter update count has reached the upper limit.

31. The apparatus as claimed in claim 30, characterized in that, The transceiver module is further configured to send an authentication notification confirmation message to the UDM network element, wherein the authentication notification confirmation message is used to instruct the AMF network element to successfully request the UE to perform the network authentication process.

32. An authentication system, comprising an authentication server (AUSF) network element, a unified data management (UDM) network element, and an access and mobility management (AMF) network element, wherein, The AUSF network element is used to send a network authentication process triggering indication to the UDM network element, wherein the network authentication process triggering indication includes the identifier of the user equipment (UE) corresponding to the AUSF network element, and the network authentication process triggering indication is used to instruct the UDM network element to trigger a network authentication process for the UE; The UDM network element is used to receive the network authentication process trigger indication sent from the AMF network element, and in response to the network authentication process trigger indication, send an authentication notification message to the AMF network element, wherein the authentication notification message includes the UE's identifier and is used to notify the AMF network element to perform a network authentication process for the UE; The reason why the UDM network element sends the authentication notification message to trigger the network authentication process for the UE includes at least one of the following: the roaming manipulation count reaches the upper limit; and the UE parameter update count reaches the upper limit.

33. The system as described in claim 32, characterized in that, The AMF network element sends an authentication request to the UE and receives an authentication response from the UE, wherein the authentication request is used to request the UE to perform the network authentication process and the authentication response includes the information required to perform the network authentication process.

34. The system as described in claim 32 or 33, characterized in that, The UDM is also used to receive an authentication notification confirmation message sent by the AMF, which is used to indicate that the AMF network element has successfully requested the UE to perform the network authentication process.

35. The system as described in claim 32 or 33, characterized in that, After confirming the completion of the network authentication process, the AUSF network element regenerates the AUSF network element key corresponding to the user equipment (UE) and resets the values ​​of the roaming manipulation count and the UE parameter update count.

36. A communication device, wherein, include: transceiver; Memory; A processor, connected to both the transceiver and the memory, is configured to control the wireless signal transmission and reception of the transceiver by executing computer-executable instructions on the memory, and to implement the method described in any one of claims 1-24.

37. A computer storage medium, wherein, The computer storage medium stores computer-executable instructions; when executed by a processor, the computer-executable instructions can implement the method described in any one of claims 1-24.

38. A computer program product, wherein, When the computer program product is executed by a computer, it can implement the method described in any one of claims 1-24.

Citation Information

Patent Citations

  • Authentication Result Update Method and Communications Apparatus

    US20210400482A1

  • Home network initiated primary authentication / reauthentication

    WO2021094109A1