A method and system for activating 5g mobile communication
By introducing a two-way authentication mechanism between 5G base stations and the core network, the compatibility and security issues of 5G base stations and core network equipment are resolved, ensuring system stability and security and improving customer experience.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- FUJIAN SUNNADA NETWORK TECH CO LTD
- Filing Date
- 2024-06-26
- Publication Date
- 2026-04-28
AI Technical Summary
There are issues with the compatibility, stability, and security of existing 5G base stations and core network equipment, which affect network security and customer experience.
A two-way authentication mechanism is introduced between 5G base stations and the core network. Two-way authentication is performed through a preset authentication protocol. The base station can only be activated after the two-way authentication is successful, ensuring equipment quality and compatibility.
It improves the compatibility, stability, and security of 5G mobile communication systems, ensures mutual recognition of equipment quality, quickly resolves potential problems, and enhances customer satisfaction.
Smart Images

Figure CN118890635B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of 5G mobile communication technology, and in particular to a method and system for activating 5G mobile communication. Background Technology
[0002] The stability, reliability, and security of communication systems are continued and enhanced in the 5G era. The three major application scenarios of 5G mobile communication systems—eMBB (enhanced Mobile Broadband), uRLLC (ultra-reliable low-latency communication), and mMTC (massive machine-type communication)—are widely used in smart homes, industrial control, vehicle-to-everything (V2X) systems, and telemedicine.
[0003] The expanding market demand has spurred numerous equipment manufacturers to enter the development of 5G base stations and 5G core networks. With a large number of brands of 5G base station and core network equipment entering the market, a wide range of product quality will emerge. Currently, both 5G base station and core network equipment only comply with 3GPP protocols (3rd Generation Partnership Project). As long as transmission and parameters are correct, an NGAP-activated communication system can be successfully established. This can easily lead to compatibility, stability, and security issues in 5G mobile communication systems built with substandard 5G base stations or core networks, seriously threatening network security, customer experience, and production efficiency. Summary of the Invention
[0004] The technical problem to be solved by the present invention is to provide a method and system for activating 5G mobile communication, so as to ensure the compatibility, stability and security of the 5G mobile communication system.
[0005] To solve the above-mentioned technical problems, the technical solution adopted by the present invention is as follows:
[0006] A method for activating 5G mobile communication includes the following steps:
[0007] In the process of establishing NGAP with the core network, S1 and 5G mobile communication base stations initiate identity authentication based on a preset authentication protocol.
[0008] S2. The core network responds to the identity authentication;
[0009] S3. After the base station successfully authenticates the identity of the core network, it returns a configuration information update request containing authentication information to the core network.
[0010] S4. The core network completes the identity authentication of the core network according to the authentication information in the configuration information update request, and responds to the configuration information update request when the identity authentication is successful.
[0011] S5. The base station activates the cell based on the response information from the core network.
[0012] To solve the above-mentioned technical problems, another technical solution adopted by the present invention is as follows:
[0013] A system for activating 5G mobile communication includes a 5G mobile communication base station and a core network, and the base station and core network jointly implement the following steps:
[0014] In the process of establishing NGAP with the core network, S1 and 5G mobile communication base stations initiate identity authentication based on a preset authentication protocol.
[0015] S2. The core network responds to the identity authentication;
[0016] S3. After the base station successfully authenticates the identity of the core network, it returns a configuration information update request containing authentication information to the core network.
[0017] S4. The core network completes the identity authentication of the core network according to the authentication information in the configuration information update request, and responds to the configuration information update request when the identity authentication is successful.
[0018] S5. The base station activates the cell based on the response information from the core network.
[0019] The beneficial effects of this invention are as follows: The method and system for activating 5G mobile communication of this invention add a two-way authentication mode to 5G base station equipment and 5G core network equipment. During the NGAP establishment process between the base station and the core network, two-way authentication is performed. Only after the two-way authentication is successful can the base station be successfully activated and the 5G mobile communication system be established. Since the authentication protocol needs to be determined by both parties in advance, it can ensure that the quality, compatibility, and stability of the 5G base station equipment and the 5G core network equipment are mutually recognized. Even if problems occur, both parties can quickly provide solutions due to prior understanding and communication, thus effectively ensuring the compatibility, stability, and security of the entire 5G mobile communication system. Attached Figure Description
[0020] Figure 1 This is a flowchart illustrating a method for activating 5G mobile communication according to an embodiment of the present invention.
[0021] Figure 2 This is a schematic diagram of the architecture of a system for activating 5G mobile communication according to an embodiment of the present invention;
[0022] Figure 3 This is a signaling flowchart for core network identity authentication failure in an embodiment of the present invention;
[0023] Figure 4 This is a flowchart of the base station authentication failure signaling in an embodiment of the present invention;
[0024] Figure 5 This is a flowchart of the bidirectional authentication success signaling process in an embodiment of the present invention. Detailed Implementation
[0025] To explain in detail the technical content, objectives, and effects of the present invention, the following description is provided in conjunction with the embodiments and accompanying drawings.
[0026] Please refer to Figure 1 A method for activating 5G mobile communication includes the following steps:
[0027] In the process of establishing NGAP with the core network, S1 and 5G mobile communication base stations initiate identity authentication based on a preset authentication protocol.
[0028] S2. The core network responds to the identity authentication;
[0029] S3. After the base station successfully authenticates the identity of the core network, it returns a configuration information update request containing authentication information to the core network.
[0030] S4. The core network completes the identity authentication of the core network according to the authentication information in the configuration information update request, and responds to the configuration information update request when the identity authentication is successful.
[0031] S5. The base station activates the cell based on the response information from the core network.
[0032] As can be seen from the above description, the beneficial effects of the present invention are as follows: The method and system for activating 5G mobile communication of the present invention adds a two-way authentication mode to the 5G base station equipment and the 5G core network equipment. During the NGAP establishment process between the base station and the core network, two-way authentication is performed. Only after the two-way authentication is passed can the base station be successfully activated and the 5G mobile communication system be established. Since the authentication protocol needs to be determined by both parties in advance, it can ensure that the quality, compatibility, and stability of the 5G base station equipment and the 5G core network equipment are mutually recognized by each other. Even if problems occur, both parties can quickly provide solutions due to prior understanding and communication, thus effectively ensuring the compatibility, stability, and security of the entire 5G mobile communication system.
[0033] Furthermore, step S1 specifically includes:
[0034] Based on a preset authentication protocol, the base station carries the first identity authentication value in the application protocol interface establishment request sent to the core network.
[0035] Step S2 includes the following steps:
[0036] S21. The core network verifies the first identity authentication value based on a preset authentication protocol, and after the verification is successful, carries the second identity authentication value in the response information to the application protocol interface establishment request.
[0037] The second identity authentication value is generated based on the first identity authentication value;
[0038] S22. The base station verifies the second identity authentication value based on the preset authentication protocol to complete the identity authentication of the core network.
[0039] As described above, the core network and base stations perform data interaction based on a preset authentication protocol to achieve mutual identity authentication.
[0040] Further, step S1 includes the following steps:
[0041] S11. The base station generates a first random value based on a preset authentication protocol, and generates a first key and a second key based on the first random value and the base station name.
[0042] S12. The base station carries a first identity authentication value in the application protocol interface establishment request sent to the core network. The first identity authentication value includes the base station name, the first random value and the first key.
[0043] Step S21 is as follows:
[0044] The core network generates a third key and a fourth key corresponding to the first key and the second key respectively, based on the base station name and the first random value according to the preset authentication protocol. The third key is matched and verified with the first key. After the verification is successful, the second identity authentication value is carried in the response information to the application protocol interface establishment request.
[0045] The second authentication value includes the core network name, the second random value, and the fourth key;
[0046] Step S22 is as follows:
[0047] The base station obtains the fourth key from the second authentication value, matches and verifies it with the second key, and completes the identity authentication of the core network.
[0048] As described above, the base station and the core network are based on the same authentication protocol. The core network uses the base station name and a random value generated by the base station to perform a preliminary verification of the base station's identity using the first key, while the base station can complete the identity authentication of the base station based on the fourth key returned by the core network.
[0049] Furthermore, step S3 specifically includes:
[0050] After the base station successfully authenticates the identity of the core network, it generates a fifth key based on the core network name and the second random value, according to a preset authentication protocol, and returns a configuration information update request containing the fifth key to the core network.
[0051] Step S4 is as follows:
[0052] The core network verifies whether the fifth key is correct according to the preset authentication protocol. If it is correct, the identity authentication of the base station is successful, and the configuration information update request is responded to.
[0053] As can be seen from the above description, based on the same principle, the base station and the core network can generate the same result through the core network name and the random value generated by the core network, and the core network can thus authenticate the base station.
[0054] Furthermore, step S5 specifically includes:
[0055] The base station receives the response information from the core network, completes the F1AP startup of the centralized unit and the distributed unit, and activates the cell.
[0056] As described above, the base station establishes the necessary communication connection and coordination mechanism between the centralized unit and the distributed unit to complete the F1AP startup, so as to ensure that they can work together and activate the cell.
[0057] Please refer to Figure 2 A system for activating 5G mobile communication includes a 5G mobile communication base station and a core network, and the base station and core network jointly implement the following steps:
[0058] In the process of establishing NGAP with the core network, S1 and 5G mobile communication base stations initiate identity authentication based on a preset authentication protocol.
[0059] S2. The core network responds to the identity authentication;
[0060] S3. After the base station successfully authenticates the identity of the core network, it returns a configuration information update request containing authentication information to the core network.
[0061] S4. The core network completes the identity authentication of the core network according to the authentication information in the configuration information update request, and responds to the configuration information update request when the identity authentication is successful.
[0062] S5. The base station activates the cell based on the response information from the core network.
[0063] As can be seen from the above description, the beneficial effects of the present invention are as follows: The method and system for activating 5G mobile communication of the present invention adds a two-way authentication mode to the 5G base station equipment and the 5G core network equipment. During the NGAP establishment process between the base station and the core network, two-way authentication is performed. Only after the two-way authentication is passed can the base station be successfully activated and the 5G mobile communication system be established. Since the authentication protocol needs to be determined by both parties in advance, it can ensure that the quality, compatibility, and stability of the 5G base station equipment and the 5G core network equipment are mutually recognized by each other. Even if problems occur, both parties can quickly provide solutions due to prior understanding and communication, thus effectively ensuring the compatibility, stability, and security of the entire 5G mobile communication system.
[0064] Furthermore, step S1 specifically includes:
[0065] Based on a preset authentication protocol, the base station carries the first identity authentication value in the application protocol interface establishment request sent to the core network.
[0066] Step S2 includes the following steps:
[0067] S21. The core network verifies the first identity authentication value based on a preset authentication protocol, and after the verification is successful, carries the second identity authentication value in the response information to the application protocol interface establishment request.
[0068] The second identity authentication value is generated based on the first identity authentication value;
[0069] S22. The base station verifies the second identity authentication value based on the preset authentication protocol to complete the identity authentication of the core network.
[0070] As described above, the core network and base stations perform data interaction based on a preset authentication protocol to achieve mutual identity authentication.
[0071] Further, step S1 includes the following steps:
[0072] S11. The base station generates a first random value based on a preset authentication protocol, and generates a first key and a second key based on the first random value and the base station name.
[0073] S12. The base station carries a first identity authentication value in the application protocol interface establishment request sent to the core network. The first identity authentication value includes the base station name, the first random value and the first key.
[0074] Step S21 is as follows:
[0075] The core network generates a third key and a fourth key corresponding to the first key and the second key respectively, based on the base station name and the first random value according to the preset authentication protocol. The third key is matched and verified with the first key. After the verification is successful, the second identity authentication value is carried in the response information to the application protocol interface establishment request.
[0076] The second authentication value includes the core network name, the second random value, and the fourth key;
[0077] Step S22 is as follows:
[0078] The base station obtains the fourth key from the second authentication value, matches and verifies it with the second key, and completes the identity authentication of the core network.
[0079] As described above, the base station and the core network are based on the same authentication protocol. The core network uses the base station name and a random value generated by the base station to perform a preliminary verification of the base station's identity using the first key, while the base station can complete the identity authentication of the base station based on the fourth key returned by the core network.
[0080] Furthermore, step S3 specifically includes:
[0081] After the base station successfully authenticates the identity of the core network, it generates a fifth key based on the core network name and the second random value, according to a preset authentication protocol, and returns a configuration information update request containing the fifth key to the core network.
[0082] Step S4 is as follows:
[0083] The core network verifies whether the fifth key is correct according to the preset authentication protocol. If it is correct, the identity authentication of the base station is successful, and the configuration information update request is responded to.
[0084] As can be seen from the above description, based on the same principle, the base station and the core network can generate the same result through the core network name and the random value generated by the core network, and the core network can thus authenticate the base station.
[0085] Furthermore, step S5 specifically includes:
[0086] The base station receives the response information from the core network, completes the F1AP startup of the centralized unit and the distributed unit, and activates the cell.
[0087] As described above, the base station establishes the necessary communication connection and coordination mechanism between the centralized unit and the distributed unit to complete the F1AP startup, so as to ensure that they can work together and activate the cell.
[0088] The present invention provides a method and system for activating 5G mobile communication, applicable to scenarios involving 5G mobile communication activation.
[0089] Please refer to Figure 1 and Figure 2 Embodiment 1 of the present invention is as follows:
[0090] A method for activating 5G mobile communication includes the following steps:
[0091] In the process of establishing NGAP with the core network, S1 and 5G mobile communication base stations initiate identity authentication based on a preset authentication protocol.
[0092] Step S1 is as follows:
[0093] Based on a preset authentication protocol, the base station carries the first identity authentication value in the application protocol interface establishment request sent to the core network.
[0094] Step S1 includes the following steps:
[0095] S11. The base station generates a first random value based on a preset authentication protocol, and generates a first key and a second key based on the first random value and the base station name.
[0096] S12. The base station carries a first identity authentication value in the application protocol interface establishment request sent to the core network. The first identity authentication value includes the base station name, the first random value, and the first key.
[0097] In this embodiment, the base station sends an NGSETUP REQUEST signaling message to the core network, which carries an authentication value in the "RANNodeName" field. The "RANNodeName" consists of three parts: ENB Name, RAND1, and MAC address. The specific definitions of each value are as follows:
[0098] ENB Name: Base station name, up to 8 bytes, transmitted in hexadecimal string format;
[0099] RAND1: When the base station authenticates the core network, it generates an 8-byte random value, which is transmitted in hexadecimal string format.
[0100] MAC: The base station uses the input ENB Name, the MAC value calculated from RAND1, and RES1. The MAC value is 8 bytes long, case-insensitive, and transmitted as a hexadecimal string. It is the first key used by the core network to verify the correctness of the authentication value initiated by the base station; i.e., the first key.
[0101] RES1: The base station transmits RES1, which consists of the input ENB Name, the MAC value calculated from RAND1, and RES1 (8 bytes in total, case-insensitive, in hexadecimal string format). The core network responds to the base station by initiating the second authentication key, i.e., the second key.
[0102] In this embodiment, the specific encryption algorithm for the pre-defined authentication protocol, i.e., two-way authentication, needs to be known by both the base station and the core network. In other words, the base station and the core network need to communicate in advance to determine the authentication protocol in order to successfully complete two-way authentication. The equipment manufacturers of the base station and the core network have a cooperative relationship and can, as needed, conduct mutual trials, tests, and matching in advance on quality, stability, and compatibility issues of mutual concern. Specific testing includes aspects such as radio frequency, system architecture, and functionalities.
[0103] S2. The core network responds to the identity authentication;
[0104] Step S2 includes the following steps:
[0105] S21. The core network verifies the first identity authentication value based on a preset authentication protocol, and after the verification is successful, carries the second identity authentication value in the response information to the application protocol interface establishment request.
[0106] The second identity authentication value is generated based on the first identity authentication value;
[0107] Step S21 is as follows:
[0108] The core network generates a third key and a fourth key corresponding to the first key and the second key respectively, based on the base station name and the first random value according to the preset authentication protocol. The third key is matched and verified with the first key. After the verification is successful, the second identity authentication value is carried in the response information to the application protocol interface establishment request.
[0109] The second authentication value includes the core network name, the second random value, and the fourth key.
[0110] In this embodiment, the core network responds to the NG SETUP REQUEST signaling message from the base station, calculating the corresponding MAC and RES1 based on the base station's RAND1. To distinguish them from the MAC and RES1 generated by the base station, they are referred to as the third key and the fourth key. If the core network verifies that the MAC is correct, it responds to the NG SETUP RESPONSE signaling message, establishing an NG connection with the base station. The response signaling includes an "AMFName" field, carrying the responding base station's authentication fourth key RES1 and the authentication base station's random value RAND2. "AMFName" consists of three parts: MME Name, RES1, and RAND2. The specific definitions of each value are as follows:
[0111] MME Name: Core network name, up to 8 bytes, transmitted in hexadecimal string format;
[0112] RES1: The result calculated by the core network based on the base station name and RAND1 according to the algorithm of the preset authentication protocol, totaling 8 bytes, case-insensitive, transmitted in hexadecimal string format. This is the second key used by the core network to respond to the base station's authentication request.
[0113] RAND2: When the core network authenticates the base station, it generates an 8-byte random value, which is transmitted in hexadecimal string format.
[0114] S22. The base station verifies the second identity authentication value based on a preset authentication protocol to complete the identity authentication of the core network.
[0115] Step S22 is as follows:
[0116] The base station obtains the fourth key from the second authentication value, matches and verifies it with the second key, and completes the identity authentication of the core network.
[0117] In this embodiment, the base station receives the NG SETUP RESPONSE signaling message from the core network and verifies whether the received RES1 is the correct second key of the authentication core network, that is, it compares and verifies the fourth key with the second key.
[0118] S3. After the base station successfully authenticates the identity of the core network, it returns a configuration information update request containing authentication information to the core network.
[0119] Step S3 is as follows:
[0120] After the base station successfully authenticates the identity of the core network, it generates a fifth key based on the core network name and a second random value, according to a preset authentication protocol, and returns a configuration information update request containing the fifth key to the core network.
[0121] In this embodiment, if RES1 is correct in the NG SETUP RESPONSE signaling message that verifies the core network's response, the base station calculates the key for responding to the core network's base station authentication, i.e., the fifth key RES2, based on the received RAND2, and sends a RAN CONFIGURATION UPDATE signaling message in response. The "RANNodeName" field in the signaling message consists of ENB Name and RES2. The specific definitions of each value are as follows:
[0122] ENB Name: Base station name, up to 8 bytes, transmitted in hexadecimal string format;
[0123] RES2: The base station calculates RES2 from the core network's RAND2 input. It consists of 8 bytes, is case-insensitive, and is transmitted as a hexadecimal string. The base station responds to the core network with the authentication key.
[0124] S4. The core network completes the identity authentication of the core network according to the authentication information in the configuration information update request, and responds to the configuration information update request when the identity authentication is successful.
[0125] Step S4 is as follows:
[0126] The core network verifies whether the fifth key is correct according to the preset authentication protocol. If it is correct, the identity authentication of the base station is successful, and the configuration information update request is responded to.
[0127] In this embodiment, the core network receives the RAN CONFIGURATION UPDATE signaling message from the base station, verifies whether the received RES2 is correct, and then responds to the RAN CONFIGURATION UPDATE signaling message by sending a RAN CONFIGURATION UPDATE ACKNOWLEDGE signaling message. At this point, the two-way authentication between the base station equipment and the core network equipment is successful.
[0128] S5. The base station activates the cell based on the response information from the core network;
[0129] Step S5 is as follows:
[0130] The base station receives the response information from the core network, completes the F1AP startup of the centralized unit and the distributed unit, and activates the cell.
[0131] In this embodiment, the base station receives the authentication feedback from the core network via the signaling RAN CONFIGURATION UPDATEACKNOWLEDG, and thus completes the F1AP startup of CU and DU, activating the cell.
[0132] Please refer to Figures 3-5 Embodiment two of the present invention is as follows:
[0133] A method for activating 5G mobile communication differs from Embodiment 1 in that this embodiment uses three scenarios as examples: "base station initiates authentication, core network identity authentication fails", "core network initiates authentication, base station identity authentication fails", and "base station and core network initiate authentication in both directions, and both-way authentication succeeds".
[0134] 1) Base station initiates authentication, core network identity authentication fails.
[0135] For reference Figure 3 The base station sends an NGSETUP REQUEST signaling message to the core network, which includes an authentication value in the "RANNodeName" field. The "RANNodeName" consists of three parts: ENB Name, an 8-byte random value RAND1, and an 8-byte MAC address.
[0136] The core network lacks authentication functionality. Upon receiving an NG SETUP REQUEST signaling message requesting the base station's application interface, it cannot calculate the corresponding MAC address and RES1 based on the base station's RAND1 using the provided algorithm. Instead, it can only respond to the NG SETUP RESPONSE signaling message according to the 3GPP (3rd Generation Partnership Project) protocol. However, the "AMFName" field in this signaling message does not carry the second authentication key RES1 for the base station; it only contains the MME Name.
[0137] The response information received by the base station did not include RES1 indicating that the authentication of the core network had failed, and the core network could not authenticate with the base station. Therefore, the F1AP startup of CU and DU was not performed, and the cell could not be activated.
[0138] 2) The core network initiates authentication, but the base station's identity authentication fails.
[0139] For reference Figure 4 The base station lacks an identity authentication function. According to the 3GPP protocol (3rd Generation Partnership Project), it sends an application protocol interface establishment request (NGSETUP REQUEST) signaling to the core network. The "RANNodeName" field contained therein does not carry the identity authentication value RAND1, nor an authentication key MAC, but only the ENB Name field.
[0140] The core network responds to the base station's NG SETUP REQUEST signaling message because the received signaling message lacks the authentication random value RAND1. Based on the 3GPP protocol (3rd Generation Partnership Project), the core network responds to the NG SETUP RESPONSE signaling message to establish an NG connection with the base station. The response signaling includes an "AMFName" field, carrying the authentication base station's random value RAND2. "AMFName" consists of two parts: MME Name and RAND2.
[0141] Upon receiving the NG SETUP RESPONSE signaling message, the base station, lacking authentication functionality, will not calculate the corresponding RES2 key based on the received RAND2 field and will not send a RAN CONFIGURATION UPDATE response to the authentication base station initiated by the core network. If the core network does not receive a RES2 authentication response for more than 3 seconds, it determines that the base station's authentication has failed and subsequently shuts down the SCTP link with the base station.
[0142] 3) The base station and the core network initiate bidirectional authentication, and bidirectional authentication is successful.
[0143] For reference Figure 5 The base station sends an NGSETUP REQUEST signaling message to the core network, which includes an authentication value in the "RANNodeName" field. The "RANNodeName" consists of three parts: ENB Name, an 8-byte random value RAND1, and an 8-byte MAC address.
[0144] The core network responds to the base station's NG SETUP REQUEST signaling message, calculating the response MAC and RES1 according to the provided algorithm based on the base station's RAND1. If the core network verifies the MAC is correct, it responds with an NG SETUP RESPONSE signaling message, establishing an NG connection with the base station. The response signaling includes an "AMFName" field, carrying the second authentication key RES1 for the responding base station and the random value RAND2 for authenticating the base station. "AMFName" consists of three parts: MME Name, 8 bytes of RES1, and 8 bytes of random value RAND2.
[0145] When the base station receives the NG SETUP RESPONSE signaling message from the core network, it verifies that the received RES1 is the correct second authentication key from the core network. Based on the received RAND2, it calculates the RES2 key for the core network to initiate base station authentication according to a specific algorithm, and sends a RAN CONFIGURATION UPDATE signaling message in response. The "RANNodeName" field in the signaling message consists of ENB Name and 8 bytes of RES2.
[0146] The core network receives the RAN CONFIGURATION UPDATE signaling from the base station, verifies that the received RES2 is the correct authentication base station key, and then initiates a RAN CONFIGURATION UPDATE ACKNOWLEDGE response. At this point, the two-way authentication between the base station equipment and the core network equipment is successful.
[0147] The base station receives the authentication signal RAN CONFIGURATION UPDATE ACKNOWLEDG from the core network, and then completes the F1AP startup of CU and DU, activating the cell.
[0148] Please refer to Figure 2 Embodiment 3 of the present invention is as follows:
[0149] A system for activating 5G mobile communication includes a 5G mobile communication base station and a core network, and the base station and the core network jointly implement the steps in the method for activating 5G mobile communication in Embodiment 1 or 2 above.
[0150] In summary, the method and system for activating 5G mobile communication provided by this invention adds a two-way authentication mode to 5G base station equipment and 5G core network equipment. During the NGAP establishment process between the base station and the core network, two-way authentication is performed. Only after successful two-way authentication can the base station be successfully activated and the 5G mobile communication system established. Because the authentication protocol needs to be determined through prior communication between the two parties, it ensures that the quality, compatibility, and stability of the 5G base station equipment and 5G core network equipment are mutually recognized. Even if problems arise, the prior understanding and communication between the two parties allows for quick solutions, effectively guaranteeing the compatibility, stability, and security of the entire 5G mobile communication system. Application scenarios relying on this 5G mobile communication system become more reliable, greatly improving customer satisfaction and experience.
[0151] The above description is merely an embodiment of the present invention and does not limit the patent scope of the present invention. Any equivalent modifications made based on the content of the present invention specification and drawings, or direct or indirect applications in related technical fields, are similarly included within the patent protection scope of the present invention.
Claims
1. A method for activating 5G mobile communication, characterized in that, Including the following steps: In the process of establishing NGAP with the core network, S1 and 5G mobile communication base stations initiate identity authentication based on a preset authentication protocol. S2. The core network responds to the identity authentication; S3. After the base station successfully authenticates the identity of the core network, it returns a configuration information update request containing authentication information to the core network. S4. The core network completes the identity authentication of the base station based on the authentication information in the configuration information update request, and responds to the configuration information update request when the identity authentication is successful. S5. The base station activates the cell based on the response information from the core network; Step S1 is as follows: Based on a preset authentication protocol, the base station carries the first identity authentication value in the application protocol interface establishment request sent to the core network. Step S2 includes the following steps: S21. The core network verifies the first identity authentication value based on a preset authentication protocol, and after the verification is successful, carries the second identity authentication value in the response information to the application protocol interface establishment request. The second identity authentication value is generated based on the first identity authentication value; S22. The base station verifies the second identity authentication value based on the preset authentication protocol to complete the identity authentication of the core network.
2. The method for activating 5G mobile communication according to claim 1, characterized in that, Step S1 includes the following steps: S11. The base station generates a first random value based on a preset authentication protocol, and generates a first key and a second key based on the first random value and the base station name. S12. The base station carries a first identity authentication value in the application protocol interface establishment request sent to the core network. The first identity authentication value includes the base station name, the first random value and the first key. Step S21 is as follows: The core network generates a third key and a fourth key corresponding to the first key and the second key respectively, based on the base station name and the first random value according to the preset authentication protocol. The third key is matched and verified with the first key. After the verification is successful, the second identity authentication value is carried in the response information to the application protocol interface establishment request. The second authentication value includes the core network name, the second random value, and the fourth key; Step S22 is as follows: The base station obtains the fourth key from the second identity authentication value, matches and verifies it with the second key, and completes the identity authentication of the core network.
3. The method for activating 5G mobile communication according to claim 2, characterized in that, Step S3 is as follows: After the base station successfully authenticates the identity of the core network, it generates a fifth key based on the core network name and the second random value, according to a preset authentication protocol, and returns a configuration information update request containing the fifth key to the core network. Step S4 is as follows: The core network verifies whether the fifth key is correct according to the preset authentication protocol. If it is correct, the identity authentication of the base station is successful, and the configuration information update request is responded to.
4. The method for activating 5G mobile communication according to claim 1, characterized in that, Step S5 is as follows: The base station receives the response information from the core network, completes the F1AP startup of the centralized unit and the distributed unit, and activates the cell.
5. A system for activating 5G mobile communication, characterized in that, This includes 5G mobile communication base stations and core networks, and the following steps are jointly implemented by the base stations and core networks: In the process of establishing NGAP with the core network, S1 and 5G mobile communication base stations initiate identity authentication based on a preset authentication protocol. S2. The core network responds to the identity authentication; S3. After the base station successfully authenticates the identity of the core network, it returns a configuration information update request containing authentication information to the core network. S4. The core network completes the identity authentication of the base station based on the authentication information in the configuration information update request, and responds to the configuration information update request when the identity authentication is successful. S5. The base station activates the cell based on the response information from the core network; Step S1 is as follows: Based on a preset authentication protocol, the base station carries the first identity authentication value in the application protocol interface establishment request sent to the core network. Step S2 includes the following steps: S21. The core network verifies the first identity authentication value based on a preset authentication protocol, and after the verification is successful, carries the second identity authentication value in the response information to the application protocol interface establishment request. The second identity authentication value is generated based on the first identity authentication value; S22. The base station verifies the second identity authentication value based on the preset authentication protocol to complete the identity authentication of the core network.
6. A system for activating 5G mobile communication according to claim 5, characterized in that, Step S1 includes the following steps: S11. The base station generates a first random value based on a preset authentication protocol, and generates a first key and a second key based on the first random value and the base station name. S12. The base station carries a first identity authentication value in the application protocol interface establishment request sent to the core network. The first identity authentication value includes the base station name, the first random value and the first key. Step S21 is as follows: The core network generates a third key and a fourth key corresponding to the first key and the second key respectively, based on the base station name and the first random value according to the preset authentication protocol. The third key is matched and verified with the first key. After the verification is successful, the second identity authentication value is carried in the response information to the application protocol interface establishment request. The second authentication value includes the core network name, the second random value, and the fourth key; Step S22 is as follows: The base station obtains the fourth key from the second identity authentication value, matches and verifies it with the second key, and completes the identity authentication of the core network.
7. A system for activating 5G mobile communication according to claim 6, characterized in that, Step S3 is as follows: After the base station successfully authenticates the identity of the core network, it generates a fifth key based on the core network name and the second random value, according to a preset authentication protocol, and returns a configuration information update request containing the fifth key to the core network. Step S4 is as follows: The core network verifies whether the fifth key is correct according to the preset authentication protocol. If it is correct, the identity authentication of the base station is successful, and the configuration information update request is responded to.
8. A system for activating 5G mobile communication according to claim 5, characterized in that, Step S5 is as follows: The base station receives the response information from the core network, completes the F1AP startup of the centralized unit and the distributed unit, and activates the cell.
Citation Information
Patent Citations
Base station identity authentication method, device and equipment
CN112105024A