Network access method, device and storage medium

By setting the threshold of authentication failures in the terminal device and switching to low-level network standard access, the problem that terminal devices cannot be stationed due to authentication rejection in the 5G independent network scenario is solved, and the success rate of stationing is improved.

CN118474807BActive Publication Date: 2025-05-13HONOR DEVICE CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202311348809.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-10-17
Publication Date
2025-05-13
Estimated Expiration
2043-10-17

AI Technical Summary

Technical Problem

In the 5G independent networking scenario, if the terminal device receives an authentication rejection message from the network during network access, the SIM card may be set to an invalid state, resulting in the terminal device being unable to stay on the network.

Method used

A network access method is proposed. If the terminal device fails to authentication within the first preset period, it will switch to the second network standard for access, and the level of the second network standard is lower than the first network standard. At the same time, the terminal device can disable the first network standard before the timer timed out to avoid being unable to stay in the network.

Benefits of technology

By switching the network standard and disabling the first network standard, the terminal equipment is avoided from being unable to stay in the network for a certain period of time, and the success rate of staying in the network is improved.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118474807B_ABST
    Figure CN118474807B_ABST
Patent Text Reader

Abstract

The present application provides a network access method, device and storage medium, the method comprising: in the process of a terminal device accessing the network in a first network standard, if the number of authentication failure messages sent by the terminal device to the network device within a first preset time period reaches a first threshold, the terminal device accesses the network in a second network standard, and the level of the second network standard is lower than the level of the first network standard. The above method is configured with a first threshold, the first threshold is the maximum number of authentication failures of the terminal device within the first preset time period, and when the first threshold is reached, if the terminal device still has not accessed the first network, it can try to access the second network, so as to avoid the terminal being unable to stay on the network within a certain period of time and improve the success rate of staying on the network.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of communication technology, and in particular to a network access method, device and storage medium. Background Art

[0002] In the standalone (SA) scenario of the fifth generation mobile communication technology (5G), if the terminal device receives an authentication reject message from the network side during network access, in one example, the subscriber identity module (SIM) card of the terminal device is directly set to an invalid state. In one example, if integrity protection is indicated in the authentication reject message, the SIM card will be set to an invalid state; or, if integrity protection is not indicated in the authentication reject message, the terminal device can change the tracking area (TA) and re-register, and can try a preset number of times. If the terminal device still fails to register after trying the preset number of times, the SIM card will be set to an invalid state. The above examples all result in the terminal device being unable to stay on the network. Summary of the invention

[0003] The embodiments of the present application provide a network access method, device and storage medium to prevent a terminal from being unable to access the network within a certain period of time and to improve the success rate of accessing the network.

[0004] In a first aspect, an embodiment of the present application proposes a network access method, comprising: in a process in which a terminal device accesses the network in a first network standard, if the number of authentication failure messages sent by the terminal device to the network device within a first preset time period is equal to a first threshold, the terminal device accesses the network in a second network standard, wherein the level of the second network standard is lower than the level of the first network standard.

[0005] Exemplarily, the first network standard is a 5G network, and the second network standard is a 4G network, a long term evolution (LTE) network, a 3G network, etc. The first network standard is a network above 5G, and the second network standard is a 5G network.

[0006] The above method configures a first threshold, which is the maximum number of terminal device authentication failures within a first preset time period. When the first threshold is reached, if the terminal device has not yet accessed the first network, it can try to access the second network to avoid the terminal being unable to stay on the network for a certain period of time and improve the success rate of staying on the network.

[0007] In an optional embodiment of the first aspect of the present application, the terminal device accesses the network in the second network standard, including: the terminal device starts a timer; before the timer times out, the terminal device accesses the network in the second network standard.

[0008] In the above method, the terminal device attempts to access the second network within the timer duration, that is, the terminal device disables the first network within the timer duration, which can avoid the terminal device being unable to stay on the network within the timer duration.

[0009] In an optional embodiment of the first aspect of the present application, the method further includes: after the timer times out, the terminal device accesses the network in the first network standard.

[0010] In the above method, the terminal device may try to access the first network again after the timer expires, and accessing the first network may increase the Internet access speed of the terminal device.

[0011] In an optional embodiment of the first aspect of the present application, the method also includes: when the status of the user identity card of the terminal device is set to an invalid state, if the number of times the terminal device sends an authentication failure message within a first preset time period is less than a first threshold, the terminal device sets the status of the user identity card from an invalid state to a valid state.

[0012] It should be understood that if the user identity card SIM is set to invalid, the terminal device will not be able to connect to the network. In the above method, as long as the number of authentication failures does not reach the first threshold within the first preset period, the SIM card can be set to be restored to valid after being set to invalid, so that the terminal device can continue to try to access the network.

[0013] In an optional embodiment of the first aspect of the present application, the method further includes: after the terminal device sets the state of the user identity card from an invalid state to a valid state, the terminal device accesses the network in the first network standard.

[0014] In an optional embodiment of the first aspect of the present application, the state of the user identity card of the terminal device is set to an invalid state, including: when a preset condition is met, the state of the user identity card of the terminal device is set to an invalid state;

[0015] Pre-conditions include any of the following:

[0016] The terminal device receives a first-type authentication rejection message from the network device; or

[0017] The terminal device receives a second-type authentication rejection message from the network device, and the second-type authentication rejection message indicates integrity protection; or

[0018] The terminal device receives a second-type authentication rejection message, in which integrity protection is not indicated, and the number of times the tracking area TA is changed is equal to the second threshold.

[0019] In an optional embodiment of the first aspect of the present application, the method also includes: the terminal device receives a second-type authentication rejection message from the network device; if integrity protection is not indicated in the second-type authentication rejection message, and the number of times the TA is changed is less than a second threshold, the terminal device changes the TA and accesses the network using the first network standard.

[0020] In a second aspect, an embodiment of the present application provides a network access device, comprising: a processing module and a sending module. In the process of the processing module performing network access in a first network standard, if the number of authentication failure messages sent by the sending module to the network device within a first preset time period is equal to a first threshold, the processing module performs network access in a second network standard; the level of the second network standard is lower than the level of the first network standard.

[0021] In a third aspect, an embodiment of the present application provides a terminal device, comprising: a processor and a memory; the memory stores computer execution instructions; the processor executes the computer execution instructions stored in the memory, so that the terminal device executes a method as described in any one of the first aspects of the present application.

[0022] In a fourth aspect, an embodiment of the present application provides a computer-readable storage medium, wherein the computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the method described in any one of the first aspects of the present application is implemented.

[0023] In a fifth aspect, an embodiment of the present application provides a computer program product, including a computer program, which, when executed, enables a computer to execute a method as described in any one of the first aspects of the present application.

[0024] It should be understood that the second to fifth aspects of the present application correspond to the technical solutions of the first aspect of the present application, and the beneficial effects achieved by each aspect and the corresponding optional implementation methods are similar and will not be repeated here. BRIEF DESCRIPTION OF THE DRAWINGS

[0025] Figure 1 A communication system architecture diagram provided for an embodiment of the present application;

[0026] Figure 2 The process of the network access method provided in the embodiment of the present application Figure 1 ;

[0027] Figure 3 The process of the network access method provided in the embodiment of the present application Figure 2 ;

[0028] Figure 4 The process of the network access method provided in the embodiment of the present application Figure 3 ;

[0029] Figure 5 The process of the network access method provided in the embodiment of the present application Figure 4 ;

[0030] Figure 6 The process of the network access method provided in the embodiment of the present application Figure 5 ;

[0031] Figure 7 The process of the network access method provided in the embodiment of the present application Figure 6 ;

[0032] Figure 8 The process of the network access method provided in the embodiment of the present application Figure 7 ;

[0033] Fig. 9 The process of the network access method provided in the embodiment of the present application Figure 8 ;

[0034] Fig.10 The process of the network access method provided in the embodiment of the present application Figure 9 ;

[0035] Fig.11 A schematic diagram of the structure of a network access device provided in an embodiment of the present application;

[0036] Fig.12 A schematic diagram of the hardware structure of a terminal device provided in an embodiment of the present application. DETAILED DESCRIPTION

[0037] In order to better understand the network access method provided in the embodiment of the present application, the communication system architecture of the embodiment of the present application is first described below.

[0038] For example, Figure 1 This is a communication system architecture diagram provided in the embodiment of the present application. Figure 1As shown, the communication system 100 includes a terminal device 101, an access network device 102 and a core network device 103, wherein the terminal device 101 is connected to the access network device 102, and the access network device 102 is connected to the core network device 103. The terminal device 101 communicates with the core network device 103 through the access network device 102. In the new radio (NR) network access process, the terminal device 101 can send a registration request to the core network device 103 through the access network device 102, and the core network device 103 sends an authentication request to the terminal device 101 through the access network device 102. Usually, network authentication adopts two-way authentication, that is, the core network device 103 needs to authenticate the terminal device 101, and the terminal device 101 also needs to authenticate the core network device 103. After the two-way authentication is successful, the terminal device 101 and the core network device 103 exchange information.

[0039] The terminal device involved in this application can also be called a terminal, which can be a device with wireless transceiver function, which can be deployed on land, including indoors or outdoors, handheld or vehicle-mounted; it can also be deployed on the water (such as ships, etc.); it can also be deployed in the air (such as airplanes, balloons and satellites, etc.). The terminal device can be a user equipment (UE), wherein the UE includes a handheld device, a vehicle-mounted device, a wearable device or a computing device with a wireless communication function. Exemplarily, the UE can be a mobile phone, a tablet computer or a computer with a wireless transceiver function. The terminal device can also be a virtual reality (VR) terminal device, an augmented reality (AR) terminal device, a wireless terminal in industrial control, a wireless terminal in unmanned driving, a wireless terminal in telemedicine, a wireless terminal in a smart grid, a wireless terminal in a smart city, a wireless terminal in a smart home, etc. In the embodiment of the present application, the device for realizing the function of the terminal can be a terminal; it can also be a device that can support the terminal to realize the function, such as a chip system, which can be installed in the terminal.

[0040] The network equipment involved in this application includes access network equipment and core network equipment. Access network equipment can be a base station, an evolved NodeB (eNodeB), a transmission reception point (TRP), a next generation NodeB (gNB) in a 5G mobile communication system, a next generation base station in a 6G mobile communication system, a base station in a future mobile communication system, or an access node in a WiFi system, etc.; it can also be a module or unit that completes part of the functions of a base station, for example, it can be a centralized unit (CU) or a distributed unit (DU). Core network equipment includes user plane function (UPF) network elements, access and mobility management function (AMF) network elements, session management function (SMF) network elements, policy control function (PCF) network elements, etc. In the embodiments of this application, unless otherwise specified, network equipment refers to core network equipment.

[0041] In an embodiment of the present application, the device for implementing the function of the network device may be a network device, or may be a device that can support the network device to implement the function, such as a chip system, which may be installed in the network device.

[0042] The technical solution provided in the embodiments of the present application can be applied to the Long Term Evolution (LTE) architecture, and can also be applied to the Universal Mobile Telecommunications System (UMTS) Terrestrial Radio Access Network (UTRAN) architecture, or the Global System for Mobile Communication (GSM) / Enhanced Data Rate for GSM Evolution (EDGE) system radio access network (GSM EDGE Radio Access Network, GERAN) architecture. In addition, the technical solution provided in the embodiments of the present application can also be applied to any other wireless communication system with similar structure and function, such as a Public Land Mobile Network (PLMN) system, a 5G communication system or a communication system after 5G, etc., and the embodiments of the present application do not impose any limitation on this.

[0043] Wireless communication between communication devices may include: wireless communication between network devices and terminal devices, wireless communication between network devices and network devices, and wireless communication between terminal devices and terminal devices. In the embodiments of the present application, the term "wireless communication" may also be referred to as "communication", and the term "communication" may also be described as "data transmission", "information transmission" or "transmission". Those skilled in the art may use the technical solution provided in the embodiments of the present application for wireless communication between network devices and terminal devices, for example, wireless communication between core network devices and terminal devices.

[0044] In the NR SA scenario, if the terminal device receives an authentication rejection message from the network device during the network access process, the terminal device may set the SIM card to an invalid state, causing the terminal device to be unable to access the network for a period of time. For more information, refer to Figure 2 or Figure 3 The process shown.

[0045] Figure 2 The process of the network access method provided in the embodiment of the present application Figure 1 .like Figure 2 As shown, the network access method includes the following steps:

[0046] S201. The terminal device sends a registration request to the network device.

[0047] In some embodiments, the registration request includes identification information of the terminal device, such as an international mobile subscriber identity (IMSI) of the terminal device. The registration request is used to request access to a network.

[0048] S202: The network device sends an authentication request to the terminal device.

[0049] In some embodiments, the network device verifies the legitimacy of the terminal device based on the registration request, and if the verification is successful, the network device sends an authentication request to the terminal device. The authentication request includes data such as a random challenge (RAND) and an authentication token (AUTN).

[0050] S203: The terminal device sends an authentication failure message to the network device.

[0051] In some embodiments, the terminal device extracts and calculates the media access control (MAC) and other information in AUTN, calculates XMAC, compares whether XMAC and MAC are equal, and verifies whether the sequence number (SQN) is within the normal range to authenticate the network to which it is connected. Among them, XMAC is generated by the terminal device, and MAC is generated by the network device and sent to the terminal device.

[0052] In some embodiments, if XMAC and MAC are equal, SQN is within a normal range, the terminal device successfully authenticates the network, and the terminal device sends an authentication response message to the network device.

[0053] In some embodiments, if XMAC and MAC are not equal, the terminal device sends an authentication failure message to the network device, where the authentication failure message is used to indicate a MAC failure (#20).

[0054] In some embodiments, if the separation bit of the AMF field in AUTN is 0, the terminal device sends an authentication failure message to the network device, and the authentication failure message is used to indicate that non-5G authentication is unacceptable (#26).

[0055] S204: The network device sends an authentication rejection message to the terminal device.

[0056] In some embodiments, after receiving the authentication failure message, the network device sends an authentication rejection message to the terminal device.

[0057] S205: The terminal device sets the SIM card to an invalid state.

[0058] The authentication rejection message includes a first type of authentication rejection message and a second type of authentication rejection message.

[0059] In some embodiments, after receiving the first type of authentication rejection message, the terminal device sets the SIM card to an invalid state.

[0060] In some embodiments, when the terminal device receives the second type of authentication rejection message, if the second type of authentication rejection message indicates integrity protection, the terminal device sets the SIM card to an invalid state.

[0061] It should be noted that, in the embodiment of the present application, the first type of authentication rejection message does not distinguish whether there is an indication of integrity protection, and the terminal device directly sets the SIM card to an invalid state after receiving the first type of authentication rejection message. The second type of authentication rejection message is an indication to distinguish whether there is integrity protection, and the second type of authentication rejection message indicates integrity protection or does not indicate integrity protection, and the corresponding terminal device performs different actions.

[0062] In summary, when the preset conditions are met, the status of the SIM of the terminal device is set to an invalid state, and the preset conditions include: the terminal device receives a first type of authentication rejection message from the network device; or the terminal device receives a second type of authentication rejection message from the network device, and the second type of authentication rejection message indicates integrity protection.

[0063] The SIM card is set to an invalid state, and the terminal device cannot communicate normally with the network device for a period of time, which may result in the inability to receive downlink data (such as called calls, text messages, etc.) and the inability to initiate uplink services (such as calling calls, sending text messages, etc.).

[0064] In the network access method shown in this embodiment, after the terminal device sends an authentication failure message (#20 or #26, indicating MAC failure or non-5G authentication is not accepted) to the network device, the terminal device receives a first type of authentication rejection message sent by the network device, or receives a second type of authentication rejection message indicating integrity protection sent by the network device. The terminal device then sets the SIM card to invalid, causing the terminal device to be unable to stay on the network for a period of time, affecting the normal communication of the terminal device.

[0065] In other embodiments, if the authentication failure message is used to indicate synchronization failure (synch failure) (#21), after the terminal device sends the authentication failure message to the network device, the network device may send an authentication request again, and the terminal device may perform network authentication again based on the second authentication request, thereby improving the success rate of the terminal device staying on the network. This process can be seen in Figure 3 The process shown.

[0066] Figure 3 The process of the network access method provided in the embodiment of the present application Figure 2 .like Figure 3 As shown, the network access method includes the following steps:

[0067] S301. The terminal device sends a registration request to the network device.

[0068] S302: The network device sends an authentication request to the terminal device.

[0069] S303: The terminal device sends an authentication failure message to the network device.

[0070] In some embodiments, the terminal device checks whether the SQN in the AUTN is within a normal range. If the SQN is not within a normal range, the terminal device sends an authentication failure message to the network device. The authentication failure message is used to indicate a synchronization failure (Synchfailure) (#21).

[0071] S304: The network device sends an authentication request to the terminal device.

[0072] In this embodiment, after receiving the authentication failure message indicating the synchronization failure, the network device may send an authentication request to the terminal device again. This step is similar to Figure 2 The processes shown are different.

[0073] S305: The terminal device sends an authentication failure message to the network device.

[0074] In this embodiment, the content indicated by the authentication failure message in S305 and S303 is consistent, and reference may be made to S303.

[0075] S306: The network device sends an authentication rejection message to the terminal device.

[0076] and Figure 2 The difference in the process shown is that after the network device sends two authentication requests to the terminal device, it still receives an authentication failure message from the terminal device, and the network device sends an authentication rejection message to the terminal device.

[0077] S307: The terminal device sets the SIM card to an invalid state.

[0078] S301, S302 and S307 can refer to Figure 2 S201, S202 and S205 of the illustrated embodiment are not described in detail here.

[0079] In the network access method shown in this embodiment, the authentication failure message sent by the terminal device to the network device indicates a synchronization failure (#21), and the network device can send an authentication request to the terminal device again. After the terminal device fails to authenticate the network side twice, the network device sends an authentication rejection message, and the terminal device sets the SIM card to an invalid state, causing the terminal device to be unable to stay on the network for a period of time, affecting the normal communication of the terminal device.

[0080] Based on the various network access methods shown above, after the terminal device receives an authentication rejection message from the network device, the SIM card of the terminal device will be set to an invalid state, affecting the normal communication of the terminal device.

[0081] In view of this, the present application proposes a network access method, which sets a threshold for the number of terminal device authentication failures (i.e., the first threshold in the embodiment below). When the threshold is reached within a first preset time period, the terminal device switches the network standard (such as switching from a 5G network to a 4G network, etc.) to continue network access, thereby avoiding the terminal device from being unable to access the network for a certain period of time, affecting the normal communication of the terminal device, and improving the success rate of network access.

[0082] The above scheme is described in detail below through specific embodiments. It should be noted that the following embodiments can exist alone or in combination with each other. For the same or similar contents, for example, explanations of terms or nouns, and explanations of steps, etc., they can be referenced to each other in different embodiments and will not be repeated.

[0083] Figure 4 The process of the network access method provided in the embodiment of the present application Figure 3 .like Figure 4 As shown, Figure 4 As shown, the network access method includes the following steps:

[0084] S401. A terminal device sends a registration request to a network device in a first network standard.

[0085] S402: The network device sends an authentication request to the terminal device.

[0086] S403. The terminal device sends an authentication failure message to the network device. The authentication failure message is used to indicate a MAC failure (#20) or non-5G authentication is not accepted (#26).

[0087] In this embodiment, after the terminal device sends an authentication failure message to the network device, the terminal device may start a counter to record the number of times the authentication failure message is sent. Each time the terminal device sends an authentication failure message, the counter increases by one.

[0088] S404: The network device sends an authentication rejection message to the terminal device.

[0089] S405: The terminal device sets the SIM card to an invalid state.

[0090] The authentication rejection message includes a first type of authentication rejection message and a second type of authentication rejection message.

[0091] In some embodiments, after receiving the first type of authentication rejection message, the terminal device sets the SIM card to an invalid state.

[0092] In some embodiments, when the terminal device receives the second type of authentication rejection message, if the second type of authentication rejection message indicates integrity protection, the terminal device sets the SIM card to an invalid state.

[0093] In some embodiments, if the number of times the terminal device sends authentication failure messages within the first preset time period is less than the first threshold, S406 is executed.

[0094] S406: The terminal device changes the state of the SIM card from an invalid state to a valid state.

[0095] S407: The terminal device sends a registration request to the network device in the first network standard.

[0096] S408: The network device sends an authentication request to the terminal device.

[0097] S409. The terminal device sends an authentication failure message to the network device. The authentication failure message is used to indicate a MAC failure (#20) or non-5G authentication is not accepted (#26).

[0098] In some embodiments, if the number of times the terminal device sends authentication failure messages to the network device within a first preset time period is equal to a first threshold, S410 is executed.

[0099] S410: The terminal device sends a registration request to the network device in the second network standard.

[0100] In some embodiments, if the number of times a terminal device sends authentication failure messages to a network device within a first preset time period is equal to a first threshold, the terminal device starts a timer, and before the timer expires, the terminal device accesses the network in a second network standard; after the timer expires, the terminal device sends a registration request to the network device in the second network standard.

[0101] That is to say, if the number of authentication failures reaches the first threshold within the first preset period, the terminal device will prohibit the terminal device from sending a registration request to the network device in the first network format within the second preset period (within the timer duration), that is, prohibit the terminal device from accessing the first network. Within the second preset period, the terminal device is allowed to send a registration request to the network device in the second network format, that is, allow the terminal device to access the second network.

[0102] In this embodiment, the level of the second network standard is lower than the level of the first network standard. Exemplarily, the first network standard is a 5G network, and the second network standard is a 4G network, an LTE network, a 3G network, etc. The first network standard is a 5G or higher network, and the second network standard is a 5G network. The 5G network may also be referred to as an NR network.

[0103] Exemplarily, the first threshold is 2, the first network standard is the NR network, and the second network standard is the LTE network. Figure 4 After the terminal device fails to authenticate twice, within the second preset time period, the terminal device does not register for the NR network but registers for the LTE network.

[0104] It should be noted that, considering the device's network time, the first threshold value is usually no more than 5. The network time may correspond to the duration of the first preset period. Exemplarily, the network time is set to 5 minutes, the first threshold value is 5, and if the terminal fails to authenticate 5 times within 5 minutes, the terminal disables the NR network and attempts to access the LTE network.

[0105] The network access method shown in this embodiment is Figure 2 An improvement to the process shown is that, during the process of the terminal device accessing the network in the first network standard, the reason for the terminal device authentication failure is MAC failure or non-5G authentication is not accepted. If the number of authentication failure messages sent by the terminal device to the network device within the first preset time period does not reach the first threshold (such as the first threshold is 2), the terminal device can continue to access the network in the first network standard; if the number of authentication failure messages sent by the terminal device to the network device within the first preset time period reaches the first threshold, the terminal device can access the network based on the second network standard, which can avoid the terminal device being unable to stay on the network due to multiple authentication failures, thereby improving the success rate of staying on the network.

[0106] In some embodiments, the maximum number of times that the terminal device configures the SIM card to be changed from an invalid state to a valid state is a third threshold.

[0107] In some embodiments, the third threshold may be set to the first threshold minus 1. For example, the first threshold is 2, and the third threshold is 1. For another example, the first threshold is 3, and the third threshold is 2.

[0108] In some embodiments, continue to refer to Figure 4 After S409, the method further includes:

[0109] S411. The terminal device sends an authentication rejection message to the network device.

[0110] After S411, jump to S405.

[0111] S411 is an optional step. If the number of authentication failure messages sent within the first preset time period is equal to the first threshold, the terminal device directly executes S410.

[0112] In this embodiment, after the terminal device receives the authentication rejection message from the network device for the first time, the SIM status is set to an invalid state. After the SIM status is restored once, the network access continues to be performed with the first network standard. After receiving the authentication rejection message for the second time, the SIM status is set to invalid again. If the number of authentication failures within the first preset time period still does not reach the first threshold (such as the first threshold is 3), the terminal device can restore the SIM status again and continue to access the network with the first network standard until the number of authentication failures reaches the first threshold. The terminal device can access the network based on the second network standard.

[0113] In the network access method shown in this embodiment, during the process of network access in the first network standard, the terminal device can restore the SIM card state to a valid state after receiving an authentication rejection message and setting the SIM card to an invalid state, and continue to access the network in the first network standard to improve the success rate of network access. If the number of times the SIM card state is restored reaches a third threshold (such as the third threshold is 2), the authentication still fails, and the number of authentication failures within the first preset time period reaches the first threshold (such as the first threshold is 3), the first network (such as the NR network) can be disabled within the second preset time period, and the second network (such as the LTE network) can be attempted to be accessed within the second preset time period to improve the success rate of network access.

[0114] Figure 5 The process of the network access method provided in the embodiment of the present application Figure 4 .like Figure 5 As shown, based on Figure 4 In the process shown, S403 is replaced by the following steps:

[0115] S412. The terminal device sends an authentication failure message to the network device, where the authentication failure message is used to indicate a synchronization failure (#21).

[0116] S413: The network device sends an authentication request to the terminal device.

[0117] S414. The terminal device sends an authentication failure message to the network device, where the authentication failure message is used to indicate a synchronization failure (#21).

[0118] And, replace S409 with the following steps:

[0119] S415. The terminal device sends an authentication failure message to the network device, where the authentication failure message is used to indicate a synchronization failure (#21).

[0120] S416: The network device sends an authentication request to the terminal device.

[0121] S417. The terminal device sends an authentication failure message to the network device, where the authentication failure message is used to indicate a synchronization failure (#21).

[0122] Figure 5 The other steps in Figure 4 , I will not go into details here.

[0123] In some embodiments, the first threshold is an even number greater than or equal to 4, and the third threshold may be set to be the ratio of the first threshold to 2 minus one. Figure 5 For example, the first threshold is 4, and the third threshold is 4 / 2-1=1; for another example, the first threshold is 6, and the third threshold is 6 / 2-1=2.

[0124] In some embodiments, the first threshold is an odd number greater than or equal to 3, and the third threshold can be set to a quotient of the first threshold and 2.

[0125] The network access method shown in this embodiment is Figure 3 The improvement of the process shown is that during the process of the terminal device accessing the network in the first network standard, the reason for the terminal device authentication failure is synchronization failure. The network device can send an authentication request again. If both authentications fail, as long as the number of authentication failures within the first preset time period does not reach the first threshold (such as 4), the terminal device can continue to access the network in the first network standard; if the number of authentication failures within the first preset time period reaches the first threshold, the terminal device can access the network based on the second network standard, which can avoid the terminal device being unable to stay on the network due to multiple authentication failures, and can improve the success rate of staying on the network.

[0126] In the network access method shown in this embodiment, in each network access process, the reason for authentication failure is #21, and the network device can send two authentication requests; the first threshold is configured as an even number greater than or equal to 4, and the third threshold is the ratio of the first threshold to 2 minus one. After receiving the authentication rejection message and setting the SIM card to an invalid state, the terminal device restores the SIM card state to a valid state and continues to access the network with the first network standard, which can improve the success rate of network access; if the number of times the SIM card state is restored reaches the third threshold, the authentication still fails, and the number of authentication failures within the first preset time period reaches the first threshold, the terminal device can disable the first network (such as the NR network) within the second preset time period, and access the second network (such as the LTE network) during the preset time period to improve the success rate of network access.

[0127] In the NR SA scenario, when a terminal device is accessing a network, if it receives a second-type authentication rejection message sent by a network device, and integrity protection is not indicated in the second-type authentication rejection message, the terminal device can change the tracking area TA and re-access the network. However, if the number of times the TA is changed reaches a preset threshold, the SIM card of the terminal device will be set to an invalid state, causing the terminal device to be unable to access the network for a period of time. For more information, refer to Figure 6 The process shown.

[0128] Figure 6 The process of the network access method provided in the embodiment of the present application Figure 5 .like Figure 6 As shown, the network access method includes the following steps:

[0129] S601. A terminal device sends a registration request to a network device in a first network standard.

[0130] In some embodiments, the first network standard is a 5G network (or NR network).

[0131] S602: The network device sends an authentication request to the terminal device.

[0132] S603. The terminal device sends an authentication failure message to the network device. The authentication failure message is used to indicate a MAC failure (#20) or non-5G authentication is not accepted (#26).

[0133] S604: The network device sends an authentication rejection message to the terminal device, and the authentication rejection message does not indicate integrity protection.

[0134] In some embodiments, after S604, if the number of times the TA is replaced is less than the second threshold, S605 is executed.

[0135] S605. The terminal device replaces the TA.

[0136] S606: The terminal device sends a registration request to the network device in the first network standard.

[0137] In summary, the terminal device receives a second-type authentication rejection message from a network device. If integrity protection is not indicated in the second-type authentication rejection message and the number of times the TA is changed is less than the second threshold, the terminal device changes the TA and accesses the network using the first network standard.

[0138] S607: The network device sends an authentication request to the terminal device.

[0139] S608. The terminal device sends an authentication failure message to the network device. The authentication failure message is used to indicate a MAC failure (#20) or non-5G authentication is not accepted (#26).

[0140] In some embodiments, after S608, the method further includes:

[0141] S610: The network device sends an authentication rejection message to the terminal device, and the authentication rejection message does not indicate integrity protection.

[0142] In some embodiments, after S610, if the number of times the TA is replaced is equal to the second threshold, S609 is executed.

[0143] S609: The terminal device sets the SIM card to an invalid state.

[0144] In summary, when the preset conditions are met, the status of the SIM of the terminal device is set to an invalid state. The preset conditions include: the terminal device receives a second-type authentication rejection message, the second-type authentication rejection message does not indicate integrity protection, and the number of times the tracking area TA is changed is equal to the second threshold.

[0145] In some embodiments, after S610, if the number of times the TA is replaced is less than the second threshold, the process jumps to S605.

[0146] In this embodiment, the second threshold is the maximum number of times the TA is changed, the second threshold is a positive integer, and the terminal device can configure the second threshold by itself.

[0147] In the network access method shown in this embodiment, after the terminal device sends an authentication failure message (#20 or #26, indicating MAC failure or non-5G authentication is not accepted) to the network device, it receives an authentication rejection message sent by the network device. If the authentication rejection message does not indicate integrity protection, the terminal device can replace the TA to re-access the network, which can improve the success rate of staying on the network. However, if the number of times the TA is replaced reaches the second threshold, the SIM card of the terminal device will be invalidated, which will also cause the terminal device to be unable to stay on the network for a certain period of time, affecting the normal communication of the terminal device.

[0148] In view of this, the present application also proposes a network access method. Considering that the number of times the TA is replaced is limited, after reaching the threshold of the number of times the TA is replaced, the SIM card will be set to invalid. In this regard, after the SIM card is set to invalid, its status can be restored to valid to continue network access. In addition, by adding a threshold for the number of authentication failures, if the terminal device replaces the TA for network access and still fails to authenticate, and the number of authentication failures reaches the threshold for the number of authentication failures, the network standard can be switched (such as switching from a 5G network to a 4G network, etc.) to continue network access, thereby avoiding the terminal device from being unable to stay on the network for a certain period of time, affecting the normal communication of the terminal device, and improving the success rate of staying on the network.

[0149] The above scheme is described in detail below through specific embodiments. It should be noted that the following embodiments can exist alone or in combination with each other. For the same or similar contents, for example, explanations of terms or nouns, and explanations of steps, etc., they can be referenced to each other in different embodiments and will not be repeated.

[0150] Figure 7 The process of the network access method provided in the embodiment of the present application Figure 6 .like Figure 7 As shown, the network access method includes the following steps:

[0151] S601 to S608;

[0152] After S608, if the number of times the terminal device sends authentication failure messages within the first preset time period is equal to the first threshold, execute:

[0153] S611. The terminal device sends a registration request to the network device in the second network standard.

[0154] In some embodiments, after S608, the method further includes:

[0155] S610: The network device sends an authentication rejection message to the terminal device, and the authentication rejection message does not indicate integrity protection.

[0156] In some embodiments, after S610, if the number of times the TA is replaced is less than the second threshold, the process jumps to S605.

[0157] S610 is an optional step. If the number of authentication failure messages sent within the first preset time period is equal to the first threshold, the terminal device directly executes S611.

[0158] Figure 7 The relevant steps in Figure 6 , I will not go into details here.

[0159] Exemplarily, the second threshold is greater than or equal to the first threshold, for example, the second threshold is 3 and the first threshold is 2. Figure 7 In the process, if the terminal device sends an authentication failure message again after changing the TA for the first time, since the terminal device has sent the authentication failure message twice, the terminal device will disable the first network for a period of time and try to access the second network during this period. In this example, if the second threshold is greater than or equal to the first threshold, the terminal device will try to access the first network by changing the TA before disabling the first network, and will not invalidate the SIM card.

[0160] Exemplarily, the second threshold is less than the first threshold, for example, the second threshold is 2 and the first threshold is 3. Figure 7Process: If the terminal device sends an authentication failure message again after changing the TA for the second time, since the terminal device has sent the authentication failure message three times, the terminal device will disable the first network for a period of time and try to access the second network during this period.

[0161] In the network access method shown in this embodiment, after the terminal device changes the TA to access the network with the first network standard, if the authentication still fails, if the number of authentication failures does not reach the first threshold within the first preset time period, the terminal device can continue to change the TA to access the network with the first network standard until the number of authentication failures reaches the first threshold. The terminal device can access the network based on the second network standard, thereby avoiding the terminal device from being unable to access the network for a period of time and improving the success rate of network access.

[0162] In some embodiments, during the process of the terminal device accessing the network in the first network standard, if the reason for the terminal device authentication failure is synchronization failure (#21), based on Figure 7 The present application also provides a network access method, such as Fig. 9 As shown, replace S603 with the following steps:

[0163] S617. The terminal device sends an authentication failure message to the network device, where the authentication failure message is used to indicate a synchronization failure (#21).

[0164] S618: The network device sends an authentication request to the terminal device.

[0165] S619. The terminal device sends an authentication failure message to the network device, where the authentication failure message is used to indicate a synchronization failure (#21).

[0166] And, replace S608 with the following steps:

[0167] S620. The terminal device sends an authentication failure message to the network device, where the authentication failure message is used to indicate a synchronization failure (#21).

[0168] S621. The network device sends an authentication request to the terminal device.

[0169] S622. The terminal device sends an authentication failure message to the network device, where the authentication failure message is used to indicate a synchronization failure (#21).

[0170] Fig. 9 The other steps in Figure 7 , I will not go into details here.

[0171] In the network access method shown in this embodiment, during each network access process, if the authentication failure reason is #21, the network device may send two authentication requests; after receiving the authentication rejection message (without indicating integrity protection), the terminal device may replace the TA and access the network using the first network standard, thereby improving the success rate of network access; if the number of times the TA is replaced reaches a second threshold and the authentication still fails, and the number of authentication failures within a first preset time period reaches the first threshold, the terminal device may disable the first network within a second preset time period and access the second network within the preset time period, thereby improving the success rate of network access.

[0172] Figure 8 The process of the network access method provided in the embodiment of the present application Figure 7 .like Figure 8 As shown, based on Figure 6 In the process shown, after S611, the network access method further includes the following steps:

[0173] S612: The terminal device changes the SIM card from an invalid state to a valid state.

[0174] S613: The terminal device sends a registration request to the network device in the first network standard.

[0175] S614: The network device sends an authentication request to the terminal device.

[0176] S615. The terminal device sends an authentication failure message to the network device. The authentication failure message is used to indicate a MAC failure (#20) or non-5G authentication is not accepted (#26).

[0177] In some embodiments, if the number of times the terminal device sends authentication failure messages to the network device within the first preset time period is equal to the first threshold, executing:

[0178] S616: The terminal device sends a registration request to the network device in the second network standard.

[0179] Exemplarily, the second threshold is less than the first threshold, for example, the second threshold is 1 and the first threshold is 3. Figure 8 In the process, if the terminal device sends an authentication failure message again after changing the TA for the first time, and receives an authentication rejection message from the network device, the terminal device sets the SIM card to an invalid state because the number of TA changes has reached the second threshold. Since the current number of authentication failures is 2, which does not reach the first threshold, the terminal device sets the SIM card from an invalid state to a valid state. Subsequently, if the terminal device sends an authentication failure message again, since the number of authentication failures reaches the first threshold, the terminal device will disable the first network for a period of time and try to access the second network during this period of time.

[0180] The network access method shown in this embodiment is Figure 6 The improvement of the process shown is that when the terminal device is accessing the network in the first network standard, if the number of times the TA is changed reaches the second threshold (such as the second threshold is 1), and the network is still not connected, the SIM card will be set to invalid, and the terminal device can restore its status to valid and continue to access the network in the first network standard, which can improve the success rate of network access. If the SIM card still fails to authenticate after being restored to validity, and the number of authentication failures reaches the first threshold (such as the first threshold is 3) within the first preset time period, the first network can be disabled within the second preset time period, and an attempt can be made to access the second network to improve the success rate of network access.

[0181] In some embodiments, during the process of the terminal device accessing the network in the first network standard, if the reason for the terminal device authentication failure is synchronization failure (#21), based on Figure 8 The present application also provides a network access method, such as Fig.10 As shown, S603 is replaced by S617 to S619, and S608 is replaced by S620 to S622, and S615 is replaced by the following steps:

[0182] S623. The terminal device sends an authentication failure message to the network device, where the authentication failure message is used to indicate a synchronization failure (#21).

[0183] S624: The network device sends an authentication request to the terminal device.

[0184] S625. The terminal device sends an authentication failure message to the network device, where the authentication failure message is used to indicate a synchronization failure (#21).

[0185] In the network access method shown in this embodiment, during each network access process, if the reason for authentication failure is #21, the network device may send two authentication requests; after receiving an authentication rejection message (without indicating integrity protection), the TA may be replaced to access the network using the first network standard, thereby improving the success rate of network access; if the number of times the TA is replaced reaches a second threshold and authentication rejection is still received (without indicating integrity protection), after the SIM card is invalidated, its status may be restored to valid, and network access may continue to be performed using the first network standard; if the number of authentication failures within a first preset time period reaches a first threshold, the first network may be disabled within a second preset time period, and an attempt may be made to access the second network, thereby improving the success rate of network access.

[0186] Fig.11 This is a schematic diagram of the structure of the network access device provided in the embodiment of the present application. Fig.11 As shown, the network access device 1100 includes: a processing module 1101 and a sending module 1102 .

[0187] In the process of the processing module 1101 performing network access in the first network standard, if the number of authentication failure messages sent by the sending module 1102 to the network device within the first preset time period is equal to the first threshold, the processing module 1101 performs network access in the second network standard;

[0188] The level of the second network standard is lower than the level of the first network standard.

[0189] In an optional embodiment, the processing module 1101 is used to start a timer; before the timer times out, network access is performed using the second network standard.

[0190] In an optional embodiment, the processing module 1101 is used to access the network using the first network standard after the timer times out.

[0191] In an optional embodiment, when the status of the user identity card is set to an invalid state, if the number of times the sending module 1102 sends the authentication failure message within a first preset time period is less than the first threshold, the processing module 1101 is used to set the status of the user identity card from the invalid state to a valid state.

[0192] In an optional embodiment, after the processing module 1101 sets the state of the user identification card from the invalid state to the valid state, the processing module 1101 is further configured to access the network using the first network standard.

[0193] In an optional embodiment, the network access device 1100 further includes: a receiving module 1103 .

[0194] The processing module 1101 is used to set the state of the user identity card to the invalid state when a preset condition is met; the preset condition includes any one of the following:

[0195] The receiving module 1103 receives a first type of authentication rejection message from the network device; or

[0196] The receiving module 1103 receives a second type of authentication rejection message from the network device, where the second type of authentication rejection message indicates integrity protection; or

[0197] The receiving module 1103 receives a second-type authentication rejection message, in which integrity protection is not indicated, and the number of times the tracking area TA is changed is equal to the second threshold.

[0198] In an optional embodiment, the receiving module 1103 is used to receive a second type of authentication rejection message from the network device;

[0199] If integrity protection is not indicated in the second-type authentication rejection message, and the number of times the TA is changed is less than the second threshold, the processing module 1101 is used to change the TA and access the network using the first network standard.

[0200] The network access device provided in this embodiment is used to implement the technical solution of the terminal device in the aforementioned method embodiment. Its implementation principle and technical effect are similar and will not be repeated here.

[0201] Fig.12 This is a schematic diagram of the hardware structure of the terminal device provided in the embodiment of the present application. Fig.12 As shown, the terminal device 1200 includes: a processor 1201 and a memory 1202; the memory 1202 stores computer execution instructions; the processor 1201 executes the computer execution instructions stored in the memory 1202, so that the terminal device executes the technical solution of the terminal device in the aforementioned method embodiment, and its implementation principle and technical effect are similar, which will not be repeated here.

[0202] An embodiment of the present application further provides a computer-readable storage medium, which stores a computer program. When the computer program is executed by a processor, the method steps performed by the terminal device in the aforementioned method embodiment are implemented.

[0203] An embodiment of the present application provides a computer program product, including a computer program. When the computer program is executed, a computer executes the method steps executed by a terminal device in the aforementioned method embodiment.

[0204] The methods described in the above embodiments may be implemented in whole or in part by software, hardware, firmware, or any combination thereof. If implemented in software, the functions may be stored as one or more instructions or codes on a computer-readable medium or transmitted on a computer-readable medium. Computer-readable media may include computer storage media and communication media, and may also include any medium that can transfer a computer program from one place to another. The storage medium may be any target medium that can be accessed by a computer.

[0205] In one possible implementation, a computer-readable medium may include RAM, ROM, compact disc read-only memory (CD-ROM) or other optical disk storage, disk storage or other magnetic storage devices, or any other medium that is intended to carry or store the required program code in the form of instructions or data structures and can be accessed by a computer. Moreover, any connection is appropriately referred to as a computer-readable medium. For example, if a coaxial cable, fiber optic cable, twisted pair, digital subscriber line (DSL) or wireless technology (such as infrared, radio and microwave) is used to transmit software from a website, server or other remote source, the coaxial cable, fiber optic cable, twisted pair, DSL or wireless technology such as infrared, radio and microwave are included in the definition of medium. Disks and optical disks as used herein include optical disks, laser disks, optical disks, digital versatile disks (DVD), floppy disks and Blu-ray disks, where disks usually reproduce data magnetically, while optical disks reproduce data optically using lasers. Combinations of the above should also be included in the scope of computer-readable media.

[0206] The embodiments of the present application are described with reference to the flowcharts and / or block diagrams of the methods, devices (systems) according to the embodiments of the present application. It should be understood that each process and / or box in the flowchart and / or block diagram, as well as the combination of the processes and / or boxes in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processing unit of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable device to generate a machine, so that the instructions executed by the processing unit of the computer or other programmable data processing device generate instructions for implementing the processes in the flowchart and / or block diagram. Figure 1 A process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.

[0207] The above specific implementation methods further illustrate the purpose, technical solutions and beneficial effects of the present invention in detail. It should be understood that the above are only specific implementation methods of the present invention and are not intended to limit the scope of protection of the present invention. Any modifications, equivalent substitutions, improvements, etc. made on the basis of the technical solutions of the present invention should be included in the scope of protection of the present invention.

Claims

1. A network access method, characterized in that: include: During the process of the terminal device accessing the network in the first network standard, if the terminal device receives a second type of authentication rejection message from the network device, the second type of authentication rejection message does not indicate integrity protection, and the number of times the tracking area TA is changed is equal to the second threshold, the terminal device sets the state of the user identity card to an invalid state; If the number of authentication failure messages sent by the terminal device to the network device within a first preset time period is equal to a first threshold, the terminal device accesses the network in a second network standard; the level of the second network standard is lower than the level of the first network standard.

2. The method according to claim 1, characterized in that The terminal device accesses the network using the second network standard, including: The terminal device starts a timer; Before the timer times out, the terminal device accesses the network using the second network standard.

3. The method according to claim 2, characterized in that The method further comprises: After the timer times out, the terminal device accesses the network using the first network standard.

4. The method according to any one of claims 1 to 3, characterized in that: The method further comprises: When the status of the user identity card of the terminal device is set to an invalid state, if the number of times the terminal device sends the authentication failure message within the first preset time period is less than the first threshold, the terminal device sets the status of the user identity card from the invalid state to a valid state.

5. The method according to claim 4, characterized in that The method further comprises: After the terminal device changes the state of the user identity card from the invalid state to the valid state, the terminal device accesses the network in the first network standard.

6. The method according to claim 4, characterized in that The state of the user identity card of the terminal device is set to an invalid state, including: When a preset condition is met, the state of the user identity card of the terminal device is set to the invalid state; The preset condition includes any of the following: The terminal device receives a first type of authentication rejection message from the network device; or The terminal device receives a second-type authentication rejection message from the network device, where the second-type authentication rejection message indicates integrity protection; or The terminal device receives the second-type authentication rejection message, in which integrity protection is not indicated, and the number of times the tracking area TA is changed is equal to a second threshold.

7. The method according to any one of claims 1 to 6, characterized in that: The method further comprises: The terminal device receives a second type of authentication rejection message from the network device; If integrity protection is not indicated in the second type of authentication rejection message, and the number of times the TA is changed is less than a second threshold, the terminal device changes the TA and accesses the network using the first network standard.

8. A network access device, characterized in that: include: Processing module, receiving module and sending module; During the process of the processing module performing network access in the first network standard, if the receiving module receives a second type of authentication rejection message from the network device, the second type of authentication rejection message does not indicate integrity protection, and the number of times the tracking area TA is changed is equal to the second threshold, the processing module sets the user identity card to an invalid state; if the number of authentication failure messages sent by the sending module to the network device within a first preset time period is equal to the first threshold, the processing module performs network access in the second network standard; the level of the second network standard is lower than the level of the first network standard.

9. A terminal device, characterized in that: include: Processor and memory; The memory stores computer-executable instructions; The processor executes the computer-executable instructions stored in the memory, so that the terminal device performs the method according to any one of claims 1 to 7.

10. A computer-readable storage medium storing a computer program, characterized in that: When the computer program is executed by a processor, the method according to any one of claims 1 to 7 is implemented.

11. A computer program product, comprising a computer program, characterized in that When the computer program is executed by a processor, the method according to any one of claims 1 to 7 is implemented.

Citation Information

Patent Citations

  • Method and device for network stationing after authentication failure

    CN107454660A

  • Terminal access authentication method and system as well as authentication server

    CN108024241A