Registration method, authentication method, device and computer readable storage medium

CN117641347BActive Publication Date: 2026-09-18ZTE CORP
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202311361858.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-01-28
Publication Date
2026-09-18
Estimated Expiration
2041-01-28

AI Technical Summary

Technical Problem

在此过程中,UE和AUSF实体都会根据路由指示(Routing Indicator,RID)生成AKMA锚定密钥的密钥标识以及相关的AKMA锚定密钥,但目前无法保证AUSF实体获得有效的RID,AUSF实体生成的A-KID与UE生成的A-KID也可能不一致,这种情况下,网络侧无法正确定位AAnF实体或UDM实体,导致无法判断用户是否进行了AMKA签约或无法找到用户的AKMA安全上下文,对用户的认证或注册失败,用户无法获得安全可靠的服务

Benefits of technology

[0005] This application provides a registration, authentication, and routing indication determination method, apparatus, entity, and terminal to ensure RID validity and improve the reliability of user registration and access.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN117641347B_ABST
    Figure CN117641347B_ABST
Patent Text Reader

Abstract

The application provides a registration method, an authentication method, a device and a computer readable storage medium. The method obtains authentication information of a unified data management function (UDM) entity, determines a routing indication (RID) according to the authentication information, and sends a registration request to a key anchor function entity according to the RID.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] This application is a divisional application of Chinese patent application No. 202110121462.9, filed on January 28, 2021, entitled “Registration, Authentication, Routing Instruction Determination Method, Apparatus, Entity and Terminal”. Technical Field

[0002] This application relates to wireless communication networks, including, for example, a registration, authentication, and routing indication determination method, apparatus, entity, and terminal. Background Technology

[0003] The fifth-generation (5G) mobile communication network architecture consists of several network functions (NFs). For example, the Unified Data Management (UDM) entity is the permanent storage location for user subscription data, residing in the user's home network; the Authentication Credential Repository and Processing Function (ARPF) entity stores long-term security credentials used for authentication and uses these credentials as input to perform key operations; the Authentication Server Function (AUSF) entity interacts with the ARPF entity and provides authentication services; and the Application Function (AF) entity manages the user equipment (UE) session. Furthermore, the 5G network architecture introduces the Authentication and Key Management for Applications (AKMA) Anchor Function (AAnF) entity. The AAnF entity resides in the home network and is primarily used to generate session keys between the user equipment (UE) and the AF entity, as well as maintain the security context between the UE and the AF. AKMA technology provides end-to-end security protection for the 5G network from the user to the application.

[0004] After the AUSF entity authenticates the UE, the UE can register with the AAnF entity to access the 5G network. During this process, both the UE and the AUSF entity generate a key identifier for the AKMA anchor key and the related AKMA anchor key based on the Routing Indicator (RID). However, currently, it cannot be guaranteed that the AUSF entity obtains a valid RID, and the A-KID generated by the AUSF entity may not be consistent with the A-KID generated by the UE. In this case, the network side cannot correctly locate the AAnF entity or the UDM entity, resulting in the inability to determine whether the user has subscribed to AMKA or to find the user's AKMA security context. Consequently, authentication or registration for the user fails, and the user cannot obtain secure and reliable services. Summary of the Invention

[0005] This application provides a registration, authentication, and routing indication determination method, apparatus, entity, and terminal to ensure RID validity and improve the reliability of user registration and access.

[0006] This application provides a registration method for AUSF entities, including:

[0007] Obtain the authentication information of the UDM entity;

[0008] Determine the RID based on the authentication information;

[0009] A registration request is sent to the key anchoring function entity based on the RID.

[0010] This application also provides an authentication method applied to a UDM entity, including:

[0011] The stored RID is checked based on the authentication request of the AUSF entity according to the authentication service function;

[0012] Authentication information is sent to the AUSF entity based on the inspection results.

[0013] This application also provides a routing indication determination method, applied to a UE, including:

[0014] Obtain the authentication information of the Unified Data Management (UDM) entity;

[0015] The routing indication (RID) is determined based on the authentication information.

[0016] This application embodiment also provides a registration device, including:

[0017] The first acquisition module is configured to acquire the authentication information of the UDM entity;

[0018] The first determining module is configured to determine the RID based on the authentication information;

[0019] The registration module is configured to send a registration request to the key anchoring function entity based on the RID.

[0020] This application also provides an authentication device, including:

[0021] The inspection module is configured to inspect the stored RID based on the authentication request from the AUSF entity of the authentication service function;

[0022] The authentication module is configured to send authentication information to the AUSF entity based on the inspection results.

[0023] This application also provides a route indication determination device, including:

[0024] The second acquisition module is configured to acquire the authentication information of the Unified Data Management (UDM) entity.

[0025] The second determining module is configured to determine the Routing Indicator (RID) based on the authentication information.

[0026] This application also provides a functional entity, including: a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the program to implement the above-described registration method, authentication method, or routing indication determination method.

[0027] This application also provides a terminal, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the program to implement the above-described routing indication determination method.

[0028] This application also provides a computer-readable storage medium storing a computer program that, when executed by a processor, implements the above-described registration method, authentication method, or routing indication determination method. Attached Figure Description

[0029] Figure 1 This is a schematic diagram of an application identity authentication and key management service architecture provided in one embodiment;

[0030] Figure 2 A flowchart of a registration method provided in one embodiment;

[0031] Figure 3 A flowchart illustrating the key identifier for generating the anchor key of KAMA, as provided in one embodiment;

[0032] Figure 4 A flowchart for generating a key identifier for an anchor key of KAMA, provided as another embodiment;

[0033] Figure 5 A flowchart of an authentication method provided in one embodiment;

[0034] Figure 6 A flowchart illustrating a route indication determination method provided in one embodiment;

[0035] Figure 7 A schematic diagram of a registration device provided in one embodiment;

[0036] Figure 8 A schematic diagram of the structure of an authentication device provided in one embodiment;

[0037] Figure 9 This is a schematic diagram of the structure of a route indication determination device provided in one embodiment;

[0038] Figure 10 A schematic diagram of the hardware structure of a functional entity provided in one embodiment;

[0039] Figure 11 This is a schematic diagram of the hardware structure of a terminal provided in one embodiment. Detailed Implementation

[0040] The present application will now be described in conjunction with the accompanying drawings and embodiments. It is to be understood that the specific embodiments described herein are merely illustrative of the application and not intended to limit it. It should be noted that, unless otherwise specified, the embodiments and features described herein can be arbitrarily combined with each other. Furthermore, it should be noted that, for ease of description, the accompanying drawings show only the parts relevant to the present application, not the entire structure.

[0041] Figure 1 This is a schematic diagram of an application identity authentication and key management service architecture provided in one embodiment. Figure 1As shown, the UE communicates with the Access Network (AN) or Radio Access Network (RAN) through various network functions. The Access Management Function (AMF) entity manages user network access requests, handling non-access stratum (NAS) signaling management and user mobility management. The AMF entity has a security anchor function, interacting with the AUSF entity and the UE, receiving intermediate keys established for the UE authentication process. For authentication methods based on the Universal Subscriber Identity Module (USIM), the AMF entity also obtains security-related data from the AUSF entity. The AF entity manages the user equipment (UE) session.

[0042] The UDM entity stores user subscription data and resides in the user's home network. The Authentication Credential Repository and Processing Function (ARPF) entity stores long-term security credentials used for authentication and performs key operations using these credentials as input. The AUSF entity interacts with the ARPF entity and provides authentication services. The AAnF entity resides in the home network and is primarily used to generate session keys between the UE and the AF entity, as well as maintain the security context between the UE and the AF entity. The AAnF entity is similar to the Bootstrapping Server Function (BSF) in the General Bootstrapping Architecture (GBA); the interface Ua* between the UE and the AF entity is similar to the Ua interface in GBA. Nnef, Nausf, Naanf, and Namf are service-based interfaces for the Network Exposure Function (NEF), AUSF, AAnF, and AMF entities, respectively. The NEF entity manages externally exposed network data; external applications can access core network data through the NEF.

[0043] Before accessing the network, the UE requests key negotiation authentication from the AUSF entity and the UDM entity. The AUSF entity generates the session key between the UE and the AF entity and maintains the security context between the UE and the AF entity. The UDM entity stores user subscription data and determines whether the user is an AKMA subscribed user, etc. After successful key negotiation authentication, the UE can generate the AKMA anchor key key identifier (AKMA-Key Identification, A-KID) and the related AKMA anchor key (denoted as K) based on the RID. AKMA ), and through the AF entity, A-KID and K AKMA Send to the AAnF entity. During this process, the AAnF entity also generates an A-KID using the RID, and sends the user's SUPI, the generated A-KID, and the K... AKMA The message is sent to the AAnF entity, which responds to the AUSF entity to complete the user's authentication and registration.

[0044] The AAnF entity obtains the A-KID and K generated by the UE from the AF entity. AKMA On the other hand, it also obtains the A-KID and K generated on the network side from the AUSF entity. AKMA However, the RID of the AUSF entity may be empty or invalid, and may also be inconsistent with the RID used by the UE. This can cause the network side to be unable to correctly locate the AAnF entity or UDM entity, unable to determine whether the user has signed up for AMKA or unable to find the user's AKMA security context, resulting in failure of user authentication or registration, and the user being unable to obtain secure and reliable services.

[0045] This application provides a registration method applicable to AUSF entities. The AUSF entity can determine a valid RID based on the authentication information of the UDM entity, providing valid information for the AAnF entity, thereby enabling user registration and providing users with safe and reliable services.

[0046] Figure 2 A flowchart of a registration method provided in one embodiment, such as Figure 2 As shown, the method provided in this embodiment includes steps 110 and 130.

[0047] In step 110, the authentication information of the Unified Data Management (UDM) entity is obtained.

[0048] In this embodiment, during the authentication process, the AUSF entity interacts with the UDM entity to obtain authentication information, the purpose of which is to determine a valid RID. The authentication information may or may not include the RID, and may also include indication information about the RID, used to instruct the AUSF entity on how to determine the RID.

[0049] In one embodiment, the authentication information may also include authentication credentials, such as the authentication vector (AV) of authentication and key agreement (AKA), and the authentication method may adopt the authentication response (Nudm_UE Authentication_Get Request) service operation.

[0050] In step 120, the routing indication RID is determined based on the authentication information.

[0051] RIDs can consist of 1 to 4 decimal digits. The RID combined with the Home Network Identifier (NRI) forms the A-KID, used to transmit user data or signaling to the AUSF and UDM entities within the specified network. If the RID is invalid, the A-KID is also invalid, and the network cannot correctly locate the UDM entity, thus failing to determine whether the user has an AMKA subscription; if the AAnF entity cannot be correctly located, the user's AKMA security context cannot be found.

[0052] In this embodiment, the AUSF entity can determine the RID based on the authentication information of the UDM entity. The authentication information may include the RID; in this case, the AUSF entity can directly send a registration request to the AAnF entity based on the RID obtained from the UDM entity. Alternatively, the authentication information may not include the RID; in this case, the AUSF entity can determine a valid RID based on a pre-configured policy or through negotiation with the UE. Or, the authentication information may contain indication information about the RID, and the AUSF entity determines the RID according to this indication information.

[0053] In one embodiment, the UDM entity can check whether it stores a RID. If it does, it sends the stored RID to the AUSF entity through authentication information. If it does not, it does not send information about the RID, or it can send indication information about the RID.

[0054] In step 130, a registration request is sent to the key anchoring function entity according to the RID.

[0055] In this embodiment, after determining a valid RID, the AUSF entity can include the user's SUPI, the valid A-KID generated based on the RID, and the K... AKMA Send a message to the AAnF entity to request the AAnF entity to complete the user's registration.

[0056] In one embodiment, the authentication information includes RID.

[0057] In this embodiment, the UDM entity checks whether it stores a RID. If so, it sends the RID to the AUSF entity using authentication information. The AUSF entity can directly determine the RID based on the authentication information and generate an A-KID and related KID based on the RID. AKMA .

[0058] In one embodiment, the authentication information does not include the RID; step 120 includes:

[0059] Based on a pre-configured strategy or the result of negotiation with the user terminal, a value of the appropriate number of digits is selected from the Mobile Subscriber Identity (MSIN) as the RID.

[0060] In this embodiment, the UDM entity did not detect the RID, therefore the authentication information does not include the RID. Since the AUSF entity did not obtain the RID from the authentication information, it can select specific bits from the MSIN as the RID to make the RID valid, thereby generating a valid A-KID and providing a reliable basis for user registration. The selected number of bits and their position in the MSIN (e.g., the first few bits, the last few bits, the middle few bits, or specific bits, etc.) can be determined according to a pre-configured policy, or through negotiation with the UE. In some embodiments, they can also be determined based on indication information regarding the RID.

[0061] It should be noted that the UE can also select the corresponding number of bits from the MSIN as the RID and generate the A-KID accordingly, and the value selected by the UE from the MSIN is consistent with the value selected by the AUSF entity from the MSIN.

[0062] In one embodiment, selecting a value with the appropriate number of bits from the MSIN as the RID includes one of the following:

[0063] 1) Select the value of the first digit of the MSIN as the RID. For example, if the RID has 4 digits, the AUSF entity selects the 1st to 4th digits of the MSIN as the RID.

[0064] 2) Select the value of the corresponding number of bits in the MSIN starting from the set position as the RID. For example, if the RID has 4 bits, the AUSF entity selects the 3rd to 6th bits in the MSIN as the RID.

[0065] 3) Select the value of the last digit of MSIN as RID. For example, if RID has 4 digits, then the AUSF entity selects the last 4 digits of MSIN as RID.

[0066] In one embodiment, the Home Location Register (HLR, corresponding to the UDM) can be identified using the first letter or the first few digits of the MSIN. Therefore, the RID can be filled in using the first letter or the first few digits of the MSIN. If the RID is 4 bits long and the MSIN is 0123456789, according to the pre-configuration strategy of selecting the first 4 bits, "0123" can be filled in the RID to obtain the updated A-KID. Alternatively, if the pre-configuration strategy is to select the 3rd to 6th bits of the MSIN, then "2345" would be filled in the RID.

[0067] In one embodiment, the authentication information includes RID indication information; the RID indication information is used to specify the value of the corresponding number of bits in the MSIN.

[0068] In this embodiment, the UDM entity does not detect the RID and sends RID indication information to the AUSF entity through the authentication information to instruct the AUSF entity to select the value of the corresponding number of bits from the MSIN as the RID.

[0069] In one embodiment, step 120 includes: using the value of the corresponding bit in the MSIN specified by the RID indication information as the RID.

[0070] In this embodiment, the UDM entity specifies the value of the corresponding number of digits in the MSIN in the RID indication information. For example, it specifies the value of the first, last, or corresponding number of digits in the MSIN from a set position as the RID.

[0071] In one embodiment, the authentication information includes the Home Network Public Key Identifier (HNPKI).

[0072] In this embodiment, the UDM entity can also indicate the home network public key identifier to the AUSF entity through authentication information, which represents the identifier of a public key provided by a home network to protect SUPI. In the absence of protection, the value of the home network public key identifier is 0.

[0073] In one embodiment, it further includes:

[0074] Step 100: Send an authentication request to the UDM entity, the authentication request containing a Subscription Concealed Identifier (SUCI) or a Subscription Permanent Identifier (SUPI).

[0075] In this embodiment, the AUS F entity sends an authentication request to the UDM entity. The authentication request includes a user identifier, which can be either SUCI or SUPI.

[0076] SUPI could be the International Mobile Subscriber Identification Number (IMSI) or the Network Access Identifier (NAI).

[0077] SUCI consists of six parts:

[0078] SUPI type, with values ​​from 0 to 7. A value of 0 indicates IMSI, and a value of 1 indicates NAI.

[0079] Home network identifier, used to identify home network users. When SUPI is IMSI, IMSI consists of Mobile Country Code (MCC), Mobile Network Code (MNC), and MSIN;

[0080] RID, assigned by the home network operator, together with the home network identifier, indicates the transmission of network signaling to the AUSF entity and UDM entity serving the user;

[0081] The Protection Scheme Identifier indicates whether there is no protection (Null-Scheme) or protection (Non-Null-Scheme).

[0082] The Home Network Public Key Identifier represents the identifier of a public key provided by a home network to protect SUPI. In the absence of protection, its value is 0.

[0083] The protection scheme output includes the MSIN or NAI of the IMSI in the unprotected case, and the MSIN and NAI values ​​encrypted using elliptic curve cryptography in the protected case.

[0084] In one embodiment, step 130 includes:

[0085] Step 131: Generate the key identifier A-KID for the AKMA anchor key based on the RID;

[0086] Step 132: Send a registration request to the key anchoring function entity based on the A-KID.

[0087] In this embodiment, the AUSF entity will include the user's SUPI, the valid A-KID generated based on the RID, and the K... AKMA Send a message to the AAnF entity to request the AAnF entity to complete the user's registration.

[0088] In this embodiment, the anchor key K AKMA The key identifier A-KID consists of two parts: username and realm. The username contains the RID and a temporary user identifier; the realm contains the home network identifier.

[0089] In this embodiment, the AUSF entity uses the Naanf_AKMA_KeyRegistration Request service operation to transfer the user's SUPI, the A-KID generated based on the RID, and the K... AKMA The message is sent to the AAnF entity, which then completes the user registration and uses the Naanf_AKMA_KeyRegistration Response service to send the response message to the AUSF entity.

[0090] In this embodiment, the key to generating A-KID lies in determining a valid RID, that is, replacing invalid RIDs in the Username with the corresponding digits from the MSIN. Based on a pre-configured strategy, specific digits can be selected from the MSIN to fill in the RID, thus making the RID valid and updating the A-KID.

[0091] The following example illustrates how to select the appropriate number of digits from MSIN and fill them into RID.

[0092] For example, the IMSI is 234150123456789, that is, MCC=234, MNC=15, MSIN=0123456789, RID is 000, the home network public key identifier is 27, the unprotected SUCI is 0, 234, 15, 000, 0, 0 and 0123456789, and the protected SUCI is 0, 234, 15, 000, 1, 27, <Elliptic Curve Cryptography EphemeralPublic Key Value>, <Encrypted 0123456789> and <Media AccessControl Tag Value>. In this case, RID is 000, which is an invalid RID with 3 bits. According to the pre-configured policy or the negotiation result with the UE, the 4th to 6th bits of MSIN are selected, "345" is filled into RID, and in the updated A-KID, RID is updated to 345.

[0093] For another example, the IMSI is 234150123456789, that is, MCC=234, MNC=15, MSIN=0123456789, RID is 9999, the home network public key identifier is 27, the unprotected SUCI is 0, 234, 15, 9999, 0, 0 and 0123456789, and the protected SUCI is 0, 234, 15, 9999, 1, 27, <Elliptic Curve Public Key Value>, <Encrypted 0123456789> and <MAC Tag Value>. In this case, RID is 9999. Assuming 9999 is a set default value or an invalid value, then RID is invalid and has 4 bits. According to the pre-configured policy, the first 4 bits of MSIN can be selected, "0123" is filled into RID, and in the updated A-KID, RID is 0123. If the pre-configured policy is to select the 3rd to 6th bits of MSIN, "2345" is filled into RID, and in the new A-KID, RID is 2345.

[0094] Figure 3 is a flowchart of generating a key identifier of an anchor key for KAMA according to an embodiment. In this embodiment, the user is an AKMA subscribed user, and both the UE and the AUSF entity can determine a valid RID. As Figure 3 shown, the specific process is as follows:

[0095] A. During the authentication process, the AUSF entity sends an authentication request to the UDM entity, where the authentication request includes the user's SUCI / SUPI.

[0096] B. The UDM entity checks whether the RID of the user is stored.

[0097] C. If the user's RID exists, the UDM entity sends the RID value to the AUSF entity via authentication information; if the user's RID does not exist, the authentication information sent by the UDM entity does not include the RID.

[0098] D. If the AUSF entity receives the RID from the UDM entity, it directly determines the RID; otherwise, it selects the value of the corresponding number of bits in the MSIN as the user's RID. The method by which the AUSF entity selects the value from the MSIN can be determined by a pre-configured policy or through negotiation between the network side and the UE. The actual number of bits selected is determined by the number of bits in the RID.

[0099] E. Generate A-KID based on RID.

[0100] Figure 4 A flowchart illustrating the key identifier for generating the anchor key for KAMA, provided as another embodiment. (See attached flowchart.) Figure 4 As shown, the specific process is as follows:

[0101] a. During the authentication process, the AUSF entity sends an authentication request to the UDM entity, which includes the user's SUCI / SUPI.

[0102] b. The UDM entity checks whether the user's RID is stored.

[0103] c. If the user's RID is not available, the UDM entity sends authentication information to the AUSF entity, which includes an RID indicator to specify which digits of the MSIN should be selected as the RID.

[0104] d. The UDM entity sends the RID indication to the UE, where the RID indication can be sent to the UE through the AMF entity.

[0105] e. The UE selects the value of the corresponding number of bits from the MSIN as the RID according to the RID instruction.

[0106] f.UE generates A-KID based on RID.

[0107] g. The AUSF entity selects the value of the corresponding number of bits from the MSIN as the RID according to the RID instruction of the UDM entity.

[0108] h.AUSF entities generate A-KIDs based on RIDs.

[0109] In one embodiment, the AUSF entity is based on K AKMA Determine the application key K AFBased on this, the network side can correctly locate the ANF entity and the UDM entity, thereby correctly initiating application layer encryption, realizing user registration and authentication, ensuring user access security, and providing secure and reliable services to the terminal based on the AKMA architecture.

[0110] This application also provides an authentication method applicable to UDM entities. The UDM entity checks whether it stores a RID and sends corresponding authentication information to an AUSF entity. The AUSF entity then determines a valid RID, providing valid information to the AUSF entity and thus authenticating the user and providing a secure and reliable service. It should be noted that technical details not described in detail in this embodiment can be found in any of the above embodiments.

[0111] Figure 5 A flowchart of an authentication method provided in one embodiment, such as Figure 5 As shown, the method provided in this embodiment includes steps 210 and 220.

[0112] In step 210, the stored routing indication RID is checked based on the authentication request of the Authentication Service Function (AUSF) entity.

[0113] In step 220, authentication information is sent to the AUSF entity based on the inspection results.

[0114] In this embodiment, the UDM entity can check whether it has stored a RID. If it does, it sends the stored RID to the AUSF entity through authentication information; if it does not, it does not send information about the RID, or it can send indication information about the RID.

[0115] In one embodiment, the authentication information includes the RID.

[0116] In this embodiment, the UDM entity checks whether it has stored an RID. If it does, it can send the RID to the AUSF entity through authentication information. The AUSF entity can directly determine the RID based on the authentication information.

[0117] In one embodiment, the authentication information does not include the RID.

[0118] In this embodiment, the UDM entity did not detect the RID, therefore the RID is not included in the authentication information. Since the AUSF entity did not obtain the RID from the authentication information, it can select specific bits from the MSIN as the RID.

[0119] In one embodiment, the authentication information includes a RID indication, which specifies the value of a corresponding number of bits in the MSIN.

[0120] In this embodiment, the UDM entity does not detect the RID and sends RID indication information to the AUSF entity through the authentication information to instruct the AUSF entity to select the value of the corresponding number of bits from the MSIN as the RID.

[0121] In one embodiment, the authentication information includes the home network public key identifier.

[0122] In one embodiment, it further includes:

[0123] Step 200: Receive an authentication request, which includes SUCI or SUPI.

[0124] This application also provides a routing indication determination method, which can be applied to a UE and an AUSF entity. The UE and / or the AUSF entity determine a valid RID based on the authentication information of the UDM entity, providing valid information to the AUSF entity, thereby enabling user registration and providing users with secure and reliable services. It should be noted that technical details not described in detail in this embodiment can be found in any of the above embodiments. For example, the process by which the UE determines the RID based on the authentication information of the UDM entity can be found in any of the above embodiments, specifically the process by which the AUSF entity determines the RID based on the authentication information of the UDM entity.

[0125] Figure 6 A flowchart of a route indication determination method provided in one embodiment is shown below. Figure 6 As shown, the method provided in this embodiment includes steps 310 and 320.

[0126] In step 310, the authentication information of the Unified Data Management (UDM) entity is obtained;

[0127] In step 320, the routing indication RID is determined based on the authentication information.

[0128] In this embodiment, the UE and / or the AUSF entity obtains the authentication information sent by the UDM entity. The UDM entity can check whether it has stored the RID. If it does, it sends the stored RID to the UE through the authentication information; if not, it does not send information about the RID, or it can send indication information about the RID.

[0129] In one embodiment, the authentication information includes RID indication information; the RID indication information is used to specify the value of the corresponding digit in the MSIN.

[0130] In this embodiment, the UE and / or AUSF entity obtains the authentication information sent by the UDM entity. The authentication information includes a RID indication. The UE and / or AUSF entity can select the value of the corresponding number of bits from the MSIN as the RID according to the RID indication.

[0131] In one embodiment, step 320 includes: using the value of the corresponding bit in the MSIN specified by the RID indication information as the RID.

[0132] In this embodiment, the UE and / or AUSF entity obtains authentication information sent by the UDM entity. This authentication information includes a RID indicator. The UE and / or AUSF entity can use the value of the corresponding bit in the MSIN as the RID based on the RID indicator. See details... Figure 4 .

[0133] This application also provides a registration device. Figure 7 This is a schematic diagram of a registration device provided in one embodiment. Figure 7 As shown, the registration device includes: a first acquisition module 410, a first determination module 420, and a registration module 430.

[0134] The first acquisition module 410 is configured to acquire the authentication information of the Unified Data Management (UDM) entity.

[0135] The first determining module 420 is configured to determine the RID based on the authentication information;

[0136] The registration module 430 is configured to send a registration request to the key anchoring function entity based on the RID.

[0137] The registration device in this embodiment determines the RID based on the authentication information of the UDM entity, provides valid information for the AAnF entity, thereby realizing user registration and providing users with safe and reliable services.

[0138] In one embodiment, the authentication information includes the RID.

[0139] In one embodiment, the authentication information does not include the RID; the first determining module 420 is configured to:

[0140] Based on the pre-configured strategy or the negotiation result with the user terminal, a value with the appropriate number of bits is selected from the MSIN as the RID.

[0141] In one embodiment, selecting a value with the appropriate number of bits from the MSIN as the RID includes one of the following:

[0142] Select the value of the first digit of the MSIN as the RID;

[0143] Select the value of the corresponding number of digits starting from the set position in the MSIN as the RID;

[0144] Select the value of the last corresponding digit in the MSIN as the RID.

[0145] In one embodiment, the authentication information includes RID indication information; the RID indication information is used to specify the value of the corresponding digit in the MSIN.

[0146] In one embodiment, the first determining module 420 is configured as follows:

[0147] The value of the corresponding bit in the MSIN specified by the RID indication information is used as the RID.

[0148] In one embodiment, the authentication information includes a home network common key identifier.

[0149] In one embodiment, it further includes:

[0150] The request module is configured to send an authentication request to the UDM entity, the authentication request containing either the hidden user identifier SUCI or the permanent user identifier SUPI.

[0151] In one embodiment, the registration module 430 includes:

[0152] The generation module is configured to generate a key identifier for the AKMA anchor key based on the RID;

[0153] The registration unit is configured to send a registration request to the key anchoring function entity based on the key identifier.

[0154] The registration device proposed in this embodiment belongs to the same inventive concept as the registration method proposed in the above embodiments. Technical details not described in detail in this embodiment can be found in any of the above embodiments. Furthermore, this embodiment has the same beneficial effects as the registration method.

[0155] This application also provides an authentication device. Figure 8 This is a schematic diagram of an authentication device provided in one embodiment. Figure 8 As shown, the authentication device includes an inspection module 510 and an authentication module 520.

[0156] The inspection module 510 is configured to inspect the stored RID based on the authentication request of the AUSF entity of the authentication service function;

[0157] The authentication module 520 is configured to send authentication information to the AUSF entity based on the inspection results.

[0158] The authentication device in this embodiment checks whether a RID is stored, sends authentication information to the AUSF entity, and allows the AUSF entity to determine the RID, providing valid information to the AUSF entity, thereby realizing user authentication and providing users with safe and reliable services.

[0159] In one embodiment, the authentication information includes the RID.

[0160] In one embodiment, the authentication information does not include the RID.

[0161] In one embodiment, the authentication information includes a RID indication, which specifies the value of a corresponding number of bits in the MSIN.

[0162] In one embodiment, the authentication information includes the home network public key identifier.

[0163] In one embodiment, it further includes:

[0164] The request receiving module is configured to receive authentication requests, which include the user's hidden identifier SUCI or the user's permanent identifier SUPI.

[0165] The authentication device proposed in this embodiment belongs to the same inventive concept as the authentication method proposed in the above embodiments. Technical details not described in detail in this embodiment can be found in any of the above embodiments. Furthermore, this embodiment has the same beneficial effects as the authentication method.

[0166] This application also provides a route indication determination device. Figure 9 This is a schematic diagram of a route indication determination device provided in one embodiment. Figure 9 As shown, the route indication determination device includes: a second acquisition module 610 and a second determination module 620.

[0167] The second acquisition module 610 is configured to acquire the authentication information of the Unified Data Management (UDM) entity.

[0168] The second determining module 620 is configured to determine the routing indication RID based on the authentication information.

[0169] The routing indication determination device in this embodiment determines a valid RID based on the authentication information of the UDM entity, provides valid information for the AAnF entity, thereby enabling user registration and providing users with safe and reliable services.

[0170] In one embodiment, the authentication information includes RID indication information; the RID indication information is used to specify the value of the corresponding digit in the MSIN.

[0171] In one embodiment, the second determining module 620 is configured to: use the value of the corresponding bit in the MSIN specified by the RID indication information as the RID.

[0172] The routing indication determination device proposed in this embodiment belongs to the same inventive concept as the routing indication determination method proposed in the above embodiments. Technical details not described in detail in this embodiment can be found in any of the above embodiments. Furthermore, this embodiment has the same beneficial effects as the routing indication determination method.

[0173] This application also provides a functional entity. The functional entity in this embodiment is an AUSF entity or a UDM entity. Figure 10 A schematic diagram of the hardware structure of a functional entity provided in one embodiment, such as... Figure 10 As shown, the functional entity provided in this application includes a memory 72, a processor 71, and a computer program stored in the memory and executable on the processor. When the processor 71 executes the program, it implements the above-described registration method, authentication method, or routing indication determination method.

[0174] The functional entity may also include a memory 72; the processor 71 in the functional entity may be one or more. Figure 10 Taking a processor 71 as an example; memory 72 is used to store one or more programs; the one or more programs are executed by the one or more processors 71, causing the one or more processors 71 to implement the registration method, authentication method, or routing indication determination method as described in the embodiments of this application.

[0175] The functional entities also include: communication device 73, input device 74 and output device 75.

[0176] The processor 71, memory 72, communication device 73, input device 74, and output device 75 in the functional entity can be connected via a bus or other means. Figure 10 Taking the bus connection between China and Israel as an example.

[0177] Input device 74 can be used to receive input digital or character information, and to generate key signal inputs related to user settings and function control of functional entities. Output device 75 may include display devices such as a display screen.

[0178] The communication device 73 may include a receiver and a transmitter. The communication device 73 is configured to perform information transmission and reception communication under the control of the processor 71.

[0179] The memory 72, as a computer-readable storage medium, can be configured to store software programs, computer-executable programs, and modules, such as program instructions / modules corresponding to the registration method described in the embodiments of this application (e.g., the first acquisition module 410, the first determination module 420, and the registration module 430 in the registration device). The memory 72 may include a program storage area and a data storage area, wherein the program storage area may store the operating system and at least one application program required for a function; the data storage area may store data created based on the use of the functional entity, etc. Furthermore, the memory 72 may include high-speed random access memory and may also include non-volatile memory, such as at least one disk storage device, flash memory device, or other non-volatile solid-state storage device. In some instances, the memory 72 may further include memory remotely located relative to the processor 71, and these remote memories can be connected to the functional entity via a network. Examples of such networks include, but are not limited to, the Internet, corporate intranets, local area networks, mobile communication networks, and combinations thereof.

[0180] This application also provides a terminal. Figure 11 This is a schematic diagram of the hardware structure of a terminal provided in one embodiment, such as... Figure 11 As shown, the terminal provided in this application includes a memory 82, a processor 81, and a computer program stored in the memory and executable on the processor. When the processor 81 executes the program, it implements the above-described routing indication determination method.

[0181] The terminal may also include a memory 82; the processor 81 in the terminal may be one or more. Figure 11 Taking a processor 81 as an example; memory 82 is used to store one or more programs; the one or more programs are executed by the one or more processors 81, so that the one or more processors 81 implement the routing indication determination method as described in the embodiments of this application.

[0182] The terminal also includes: a communication device 83, an input device 84, and an output device 85.

[0183] The processor 81, memory 82, communication device 83, input device 84, and output device 85 in the terminal can be connected via a bus or other means. Figure 11 Taking the bus connection between China and Israel as an example.

[0184] Input device 84 can be used to receive input digital or character information, and to generate key signal inputs related to user settings and function control of the terminal. Output device 85 may include display devices such as a display screen.

[0185] The communication device 83 may include a receiver and a transmitter. The communication device 83 is configured to perform information transmission and reception communication under the control of the processor 81.

[0186] The memory 82, as a computer-readable storage medium, can be configured to store software programs, computer-executable programs, and modules, such as program instructions / modules corresponding to the route indication determination method described in the embodiments of this application (e.g., the second acquisition module 610 and the second determination module 620 in the route indication determination device). The memory 82 may include a program storage area and a data storage area, wherein the program storage area may store the operating system and at least one application program required for a function; the data storage area may store data created based on the use of the terminal, etc. Furthermore, the memory 82 may include high-speed random access memory and may also include non-volatile memory, such as at least one disk storage device, flash memory device, or other non-volatile solid-state storage device. In some instances, the memory 82 may further include memory remotely located relative to the processor 81, and these remote memories can be connected to the terminal via a network. Examples of such networks include, but are not limited to, the Internet, corporate intranets, local area networks, mobile communication networks, and combinations thereof.

[0187] This application embodiment also provides a storage medium storing a computer program. When executed by a processor, the computer program implements any of the registration method, authentication method, or routing indication determination method described in this application embodiment. The registration method includes: obtaining authentication information of a UDM entity; determining a RID based on the authentication information; and sending a registration request to a key anchoring function entity based on the RID. The authentication method includes: checking the stored RID based on an authentication request from an Authentication Service Function (AUSF) entity; and sending authentication information to the AUSF entity based on the check result. The routing indication determination method includes: obtaining authentication information of a UDM entity; determining a RID based on the authentication information; and sending a registration request to a key anchoring function entity based on the RID.

[0188] The computer storage medium in this application embodiment can be any combination of one or more computer-readable media. The computer-readable medium can be a computer-readable signal medium or a computer-readable storage medium. For example, a computer-readable storage medium can be, but is not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination thereof. More specific examples of computer-readable storage media (a non-exhaustive list) include: an electrical connection having one or more wires, a portable computer disk, a hard disk, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM), flash memory, optical fiber, portable CD-ROM, optical storage device, magnetic storage device, or any suitable combination thereof. The computer-readable storage medium can be any tangible medium containing or storing a program that can be used by or in conjunction with an instruction execution system, apparatus, or device.

[0189] Computer-readable signal media may include data signals propagated in baseband or as part of a carrier wave, carrying computer-readable program code. Such propagated data signals may take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination thereof. Computer-readable signal media may also be any computer-readable medium other than computer-readable storage media, which can send, propagate, or transmit programs for use by or in connection with an instruction execution system, apparatus, or device.

[0190] Program code contained on a computer-readable medium may be transmitted using any suitable medium, including but not limited to: wireless, wire, optical fiber, radio frequency (RF), etc., or any suitable combination thereof.

[0191] Computer program code for performing the operations of this application can be written in one or more programming languages ​​or a combination thereof, including object-oriented programming languages ​​such as Java, Smalltalk, and C++, as well as conventional procedural programming languages ​​such as "C" or similar programming languages. The program code can be executed entirely on the user's computer, partially on the user's computer, as a standalone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In cases involving remote computers, the remote computer can be connected to the user's computer via any type of network, including a local area network (LAN) or a wide area network (WAN), or it can be connected to an external computer (e.g., via the Internet using an Internet service provider).

[0192] The above description is merely an exemplary embodiment of this application and is not intended to limit the scope of protection of this application.

[0193] Those skilled in the art will understand that the term user terminal encompasses any suitable type of wireless user equipment, such as mobile phones, portable data processing devices, portable web browsers, or vehicle-mounted mobile stations.

[0194] Generally, the various embodiments of this application can be implemented in hardware or dedicated circuitry, software, logic, or any combination thereof. For example, some aspects can be implemented in hardware, while others can be implemented in firmware or software that can be executed by a controller, microprocessor, or other computing device, although this application is not limited thereto.

[0195] Embodiments of this application can be implemented by executing computer program instructions through the data processor of a mobile device, for example, in a processor entity, or through hardware, or through a combination of software and hardware. The computer program instructions can be assembly instructions, Instruction Set Architecture (ISA) instructions, machine instructions, machine-dependent instructions, microcode, firmware instructions, status setting data, or source code or object code written in any combination of one or more programming languages.

[0196] Any block diagram of logical flow in the accompanying drawings of this application may represent program steps, or may represent interconnected logic circuits, modules, and functions, or may represent a combination of program steps and logic circuits, modules, and functions. The computer program may be stored on memory. Memory may be of any type suitable to the local technical environment and may be implemented using any suitable data storage technology, such as, but not limited to, read-only memory (ROM), random access memory (RAM), optical storage devices and systems (Digital Video Disc (DVD) or Compact Disk (CD)), etc. Computer-readable media may include non-transitory storage media. The data processor may be of any type suitable to the local technical environment, such as, but not limited to, general-purpose computers, special-purpose computers, microprocessors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), and processors based on multi-core processor architectures.

[0197] A detailed description of exemplary embodiments of this application has been provided above through exemplary and non-limiting examples. However, various modifications and adjustments to the above embodiments will be apparent to those skilled in the art when considered in conjunction with the accompanying drawings and claims, without departing from the scope of this application. Therefore, the proper scope of this application will be determined by the claims.

Claims

1. A registration method, characterized in that, The AUSF entities applied to the authentication service function include: Authentication information is received from the Unified Data Management Function (UDM) entity, which includes Routing Indication (RID) information for specifying the value of a corresponding bit in the Mobile Subscriber Identity (MSIN). Determine whether the authentication information includes an RID; In response to the authentication information not including the RID, the value of the corresponding number of bits in the MSIN specified in the RID indication information is used as the target RID; A registration request is sent to the key anchoring function entity based on the target RID.

2. The method according to claim 1, characterized in that, The authentication information includes authentication credentials.

3. The method according to claim 2, characterized in that, The authentication credential is the authentication vector AV of authentication and key negotiation AKA.

4. The method according to claim 1, characterized in that, The authentication information includes the Home Network Public Key Identifier (HNPKI).

5. The method according to claim 1, characterized in that, Also includes: Send an authentication request to the UDM entity, the authentication request containing either the hidden user identifier SUCI or the permanent user identifier SUPI.

6. The method according to claim 1, characterized in that, Sending a registration request to the key anchoring function entity based on the target RID includes: Generate a key identifier A-KID for the AKMA anchor key of the application identity authentication and key management service based on the target RID; The registration request is sent to the key anchoring function entity according to the A-KID.

7. An authentication service functional entity, characterized in that, include: Memory, used to store computer-readable instructions; and A processor is configured to read the computer-readable instructions, and when executing the computer-readable instructions, the processor performs the following operations: Authentication information is received from the Unified Data Management Function (UDM) entity, which includes Routing Indication (RID) information for specifying the value of a corresponding bit in the Mobile Subscriber Identity (MSIN). Determine whether the authentication information includes an RID; In response to the authentication information not including the RID, the value of the corresponding number of bits in the MSIN specified in the RID indication information is used as the target RID; A registration request is sent to the key anchoring function entity based on the target RID.

8. A computer-readable storage medium having a computer program stored thereon, the computer program performing the following operations when executed by a processor: Authentication information is received from the Unified Data Management Function (UDM) entity, which includes Routing Indication (RID) information for specifying the value of a corresponding bit in the Mobile Subscriber Identity (MSIN). Determine whether the authentication information includes a Routing Indicator (RID); In response to the authentication information not including the RID, the value of the corresponding number of bits in the MSIN specified in the RID indication information is used as the target RID; A registration request is sent to the key anchoring function entity based on the target RID.

Citation Information

Patent Citations

  • Key identifier generation method and related device

    CN116746181A

  • Methods and apparatuses for dynamically updating routing identifier(s)

    WO2020005925A1