Method and device for processing authentication vector
By including valid time parameters in the first authentication token of the authentication vector, the security risks caused by the use of expired authentication vectors by IoT devices in the storage and forwarding satellite communication scenario are solved, and the effectiveness check of the authentication vector and the guarantee of communication performance are realized.
Patent Information
- Application Number
- CN202311450760.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2023-11-02
- Publication Date
- 2025-05-06
AI Technical Summary
In storage and forwarding satellite communication scenarios, IoT devices may not have connections with satellites for a long time, resulting in the unused authentication vector generated by the core network expires, and satellites or user terminals continue to use expired authentication vectors, causing security risks.
By including valid time parameters in the first authentication token of the authentication vector, the authentication vector is generated and constructed, the validity of the authentication vector is ensured and used within the valid time.
It effectively avoids the security risks caused by the use of failure authentication vectors, and eliminates the possible SQN synchronization operations, ensuring the communication performance between the terminal and the satellite.
Smart Images

Figure CN119945693A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of communication technology, and more particularly to a method and device for processing an authentication vector. Background Art
[0002] In the Store and Forward (S&F) satellite communication scenario, data is exchanged between the User Equipment (UE), the satellite and the core network equipment. When the UE is an IoT device, there is a scenario where the IoT device may not have a communication connection with the satellite for a long time, and the unused authentication vector generated by the core network for the UE may have expired. In this scenario, the satellite or UE will continue to use the expired or realized authentication vector, which will bring security risks. Summary of the invention
[0003] The purpose of the present application is to provide a method and device for processing an authentication vector to solve the problem that in an S&F satellite communication scenario, a satellite or UE may use an expired authentication vector, thereby causing security risks.
[0004] In order to achieve the above object, the present application provides a method for processing an authentication vector, which is performed by a first core network device, and the method includes:
[0005] generating a first authentication token of an authentication vector, wherein the first authentication token comprises a first parameter of the authentication vector, and the first parameter is used to indicate a validity period of the authentication vector;
[0006] constructing an authentication vector according to the first authentication token and the first parameter;
[0007] Send the authentication vector to the second core network device.
[0008] Optionally, generating a first authentication token of an authentication vector comprises:
[0009] Generate a first message authentication code according to the first parameter and the second parameter, wherein the second parameter includes at least one of a permanent key K, an authentication management domain AMF parameter, a sequence number SQN, and a random number;
[0010] The first authentication token is generated according to the first message authentication code, the first parameter and a third parameter, wherein the third parameter includes at least one of an SQN, an anonymous key AK and an AMF parameter.
[0011] Optionally, generating a first authentication token of an authentication vector comprises:
[0012] Generate a first message authentication code according to the target key, the second authentication token and the first parameter; wherein the target key is related to at least one of the encryption protection key CK, the integrity protection key IK and the terminal related information;
[0013] The first authentication token is generated according to the second authentication token, the first parameter and the first message authentication code.
[0014] Optionally, the terminal-related information includes at least one of the following:
[0015] The terminal's operator information;
[0016] Application service information of the terminal;
[0017] Terminal identification information.
[0018] Optionally, the first parameter includes at least one of the following:
[0019] The effective start time and effective end time of the authentication vector;
[0020] The effective start time and effective duration of the authentication vector;
[0021] The validity period of the authentication vector ends.
[0022] The embodiment of the present application further provides a method for processing an authentication vector, which is performed by a second core network device, and the method includes:
[0023] receiving an authentication vector sent by a first core network device, wherein the authentication vector includes a first parameter, and the first parameter is used to indicate a validity period of the authentication vector;
[0024] In a case where it is determined according to the first parameter that the authentication vector is within the valid time, an authentication request is sent to the terminal, the authentication request including a first authentication token and a random number, and the first authentication token includes the first parameter.
[0025] Optionally, the first parameter includes at least one of the following:
[0026] The effective start time and effective end time of the authentication vector;
[0027] The effective start time and effective duration of the authentication vector;
[0028] The validity period of the authentication vector ends.
[0029] The embodiment of the present application further provides a method for processing an authentication vector, which is executed by a terminal, and the method includes:
[0030] Obtaining an authentication request sent by a second core network device, the authentication request including a first authentication token of an authentication vector and a random number, the first authentication token including a first parameter, and the first parameter is used to indicate a valid time of the authentication vector;
[0031] verifying the first authentication token;
[0032] After the first authentication token is verified, if it is determined according to the first parameter in the first authentication token that the authentication vector is within the valid time, an authentication response message is sent to the second core network device.
[0033] Optionally, the verifying the first authentication token includes:
[0034] generating a second message authentication code;
[0035] comparing the second message authentication code with the first message authentication code in the first authentication token;
[0036] In the case where the second message authentication code is identical to the first message authentication code, it is determined that the first authentication token has been authenticated successfully; otherwise, it is determined that the first authentication token has not been authenticated successfully.
[0037] Optionally, generating a second message authentication code includes:
[0038] Generate a second message authentication code according to the first parameter and the second parameter, where the second parameter includes at least one of a permanent key K, an AMF parameter, a sequence number SQN, and a random number;
[0039] Alternatively, a second message authentication code is generated according to a target key, a second authentication token and a first parameter; wherein the target key is related to at least one of an encryption protection key CK, an integrity protection key IK and terminal related information.
[0040] Optionally, the terminal-related information includes at least one of the following:
[0041] The terminal's operator information;
[0042] Application service information of the terminal;
[0043] Terminal identification information.
[0044] Optionally, the first parameter includes at least one of the following:
[0045] The effective start time and effective end time of the authentication vector;
[0046] The effective start time and effective duration of the authentication vector;
[0047] The validity period of the authentication vector ends.
[0048] The embodiment of the present application also provides an authentication vector processing device, including a memory, a transceiver, and a processor;
[0049] A memory for storing a computer program; a transceiver for transmitting and receiving data under the control of the processor; and a processor for reading the computer program in the memory and performing the following operations:
[0050] generating a first authentication token of an authentication vector, wherein the first authentication token comprises a first parameter of the authentication vector, and the first parameter is used to indicate a validity period of the authentication vector;
[0051] constructing an authentication vector according to the first authentication token and the first parameter;
[0052] Send the authentication vector to the second core network device.
[0053] Optionally, the processor further performs the following operations:
[0054] Generate a first message authentication code according to the first parameter and the second parameter, wherein the second parameter includes at least one of a permanent key K, an authentication management domain AMF parameter, a sequence number SQN, and a random number;
[0055] The first authentication token is generated according to the first message authentication code, the first parameter and a third parameter, wherein the third parameter includes at least one of an SQN, an anonymous key AK and an AMF parameter.
[0056] Optionally, the processor further performs the following operations:
[0057] Generate a first message authentication code according to the target key, the second authentication token and the first parameter; wherein the target key is related to at least one of the encryption protection key CK, the integrity protection key IK and the terminal related information;
[0058] The first authentication token is generated according to the second authentication token, the first parameter and the first message authentication code.
[0059] Optionally, the terminal-related information includes at least one of the following:
[0060] The terminal's operator information;
[0061] Application service information of the terminal;
[0062] Terminal identification information.
[0063] Optionally, the first parameter includes at least one of the following:
[0064] The effective start time and effective end time of the authentication vector;
[0065] The effective start time and effective duration of the authentication vector;
[0066] The validity period of the authentication vector ends.
[0067] The embodiment of the present application also provides an authentication vector processing device, including a memory, a transceiver, and a processor;
[0068] A memory for storing a computer program; a transceiver for transmitting and receiving data under the control of the processor; and a processor for reading the computer program in the memory and performing the following operations:
[0069] receiving an authentication vector sent by a first core network device, wherein the authentication vector includes a first parameter, and the first parameter is used to indicate a validity period of the authentication vector;
[0070] In a case where it is determined according to the first parameter that the authentication vector is within the valid time, an authentication request is sent to the terminal, the authentication request including a first authentication token and a random number, and the first authentication token includes the first parameter.
[0071] Optionally, the first parameter includes at least one of the following:
[0072] The effective start time and effective end time of the authentication vector;
[0073] The effective start time and effective duration of the authentication vector;
[0074] The validity period of the authentication vector ends.
[0075] The embodiment of the present application also provides an authentication vector processing device, including a memory, a transceiver, and a processor;
[0076] A memory for storing a computer program; a transceiver for transmitting and receiving data under the control of the processor; and a processor for reading the computer program in the memory and performing the following operations:
[0077] Obtaining an authentication request sent by a second core network device, the authentication request including a first authentication token of an authentication vector and a random number, the first authentication token including a first parameter, and the first parameter is used to indicate a valid time of the authentication vector;
[0078] verifying the first authentication token;
[0079] After the first authentication token is verified, if it is determined according to the first parameter in the first authentication token that the authentication vector is within the valid time, an authentication response message is sent to the second core network device.
[0080] Optionally, the processor further performs the following operations:
[0081] generating a second message authentication code;
[0082] comparing the second message authentication code with the first message authentication code in the first authentication token;
[0083] In the case where the second message authentication code is identical to the first message authentication code, it is determined that the first authentication token has been authenticated successfully; otherwise, it is determined that the first authentication token has not been authenticated successfully.
[0084] Optionally, the processor further performs the following operations:
[0085] Generate a second message authentication code according to the first parameter and the second parameter, where the second parameter includes at least one of a permanent key K, an AMF parameter, a sequence number SQN, and a random number;
[0086] Alternatively, a second message authentication code is generated according to a target key, a second authentication token and a first parameter; wherein the target key is related to at least one of an encryption protection key CK, an integrity protection key IK and terminal related information.
[0087] Optionally, the terminal-related information includes at least one of the following:
[0088] The terminal's operator information;
[0089] Application service information of the terminal;
[0090] Terminal identification information.
[0091] Optionally, the first parameter includes at least one of the following:
[0092] The effective start time and effective end time of the authentication vector;
[0093] The effective start time and effective duration of the authentication vector;
[0094] The validity period of the authentication vector ends.
[0095] The embodiment of the present application further provides a device for processing an authentication vector, including:
[0096] A generating unit, configured to generate a first authentication token of an authentication vector, wherein the first authentication token includes a first parameter of the authentication vector, and the first parameter is used to indicate a valid time of the authentication vector;
[0097] a construction unit, configured to construct an authentication vector according to the first authentication token and the first parameter;
[0098] The first sending unit is configured to send the authentication vector to the second core network device.
[0099] The embodiment of the present application further provides a device for processing an authentication vector, including:
[0100] A receiving unit, configured to receive an authentication vector sent by a first core network device, wherein the authentication vector includes a first parameter, and the first parameter is used to indicate a valid time of the authentication vector;
[0101] The second sending unit is configured to send an authentication request to the terminal when it is determined according to the first parameter that the authentication vector is within the valid time, the authentication request including a first authentication token and a random number, and the first authentication token including the first parameter.
[0102] The embodiment of the present application further provides a device for processing an authentication vector, including:
[0103] An acquiring unit, configured to acquire an authentication request sent by a second core network device, wherein the authentication request includes a first authentication token of an authentication vector and a random number, wherein the first authentication token includes a first parameter, and the first parameter is used to indicate a valid time of the authentication vector;
[0104] a verification unit, configured to verify the first authentication token;
[0105] The third sending unit is used to send authentication response information to the second core network device after the first authentication token is verified and if it is determined according to the first parameter in the first authentication token that the authentication vector is within the valid time.
[0106] An embodiment of the present application further provides a processor-readable storage medium, wherein the processor-readable storage medium stores a computer program, and the computer program is used to enable the processor to execute the steps of the authentication vector processing method as described above.
[0107] The above technical solution of the present application has at least the following beneficial effects:
[0108] In an embodiment of the present application, a first core network device generates a first authentication token of an authentication vector, wherein the first authentication token includes a first parameter of the authentication vector, and the first parameter is used to indicate the validity period of the authentication vector; an authentication vector is constructed according to the first authentication token and the first parameter; and the authentication vector is sent to a second core network device. Through the above scheme, the second core network device and the terminal can determine whether the authentication vector is valid based on the first parameter in the authentication vector, thereby effectively avoiding the security risks caused by the use of an invalid authentication vector. BRIEF DESCRIPTION OF THE DRAWINGS
[0109] Figure 1 A structural diagram showing a network system to which the embodiments of the present application can be applied;
[0110] Figure 2 A schematic diagram showing a flow chart of a method for processing an authentication vector according to an embodiment of the present application;
[0111] Figure 3 One of the schematic diagrams showing the generation of MAC' in an embodiment of the present application;
[0112] Figure 4 The second schematic diagram showing the generation of MAC' in the embodiment of the present application;
[0113] Figure 5 A second flowchart of a method for processing an authentication vector according to an embodiment of the present application is shown;
[0114] Figure 6 A third flowchart of a method for processing an authentication vector according to an embodiment of the present application is shown;
[0115] Figure 7 An interactive schematic diagram showing a method for processing an authentication vector according to an embodiment of the present application;
[0116] Figure 8 One of the structural block diagrams of the authentication vector processing device according to an embodiment of the present application is shown;
[0117] Fig. 9 A second structural block diagram showing an authentication vector processing device according to an embodiment of the present application;
[0118] Fig.10 A schematic diagram showing a module of an authentication vector processing device according to an embodiment of the present application;
[0119] Fig.11 A second schematic diagram of a module showing an authentication vector processing device according to an embodiment of the present application;
[0120] Fig.12 A third schematic diagram of a module of an authentication vector processing device according to an embodiment of the present application. DETAILED DESCRIPTION
[0121] The following will be combined with the drawings in the embodiments of the present application to clearly and completely describe the technical solutions in the embodiments of the present application. Obviously, the described embodiments are part of the embodiments of the present application, not all of the embodiments. Based on the embodiments in the present application, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of this application.
[0122] The terms "first", "second", etc. in the specification and claims of the present application are used to distinguish similar objects, and are not necessarily used to describe a specific order or sequential order. It should be understood that the data used in this way can be interchanged where appropriate, so that the embodiments of the present application described herein, for example, are implemented in a sequence other than those illustrated or described herein. In addition, the terms "including" and "having" and any of their variations are intended to cover non-exclusive inclusions, for example, the process, method, system, product or equipment comprising a series of steps or units is not necessarily limited to those steps or units clearly listed, but may include other steps or units that are not clearly listed or inherent to these processes, methods, products or equipment.
[0123] In the embodiments of the present application, the term "and / or" describes the association relationship of associated objects, indicating that three relationships may exist. For example, A and / or B can represent three situations: A exists alone, A and B exist at the same time, and B exists alone. The character " / " generally indicates that the associated objects before and after are in an "or" relationship. In the embodiments of the present application, the term "plurality" refers to two or more than two, and other quantifiers are similar.
[0124] In the embodiments of the present application, words such as "exemplary" or "for example" are used to indicate examples, illustrations or descriptions. Any embodiment or design described as "exemplary" or "for example" in the embodiments of the present application should not be interpreted as being more preferred or more advantageous than other embodiments or designs. Specifically, the use of words such as "exemplary" or "for example" is intended to present related concepts in a specific way.
[0125] Figure 1 A block diagram of a wireless communication system applicable to an embodiment of the present application is shown. The wireless communication system includes a terminal device 11 and a network side device (or network device) 12. The terminal device 11 may also be referred to as a terminal or a user terminal (User Equipment, UE). It should be noted that the specific type of the terminal 11 is not limited in the embodiment of the present application. The network side device 12 may be a base station or a core network.
[0126] In order to enable those skilled in the art to better understand the embodiments of the present application, the following description is first made.
[0127] Satellite store-and-forward means that the user equipment (UE), satellite and core network perform a complete data transmission. The process is divided into two stages in time:
[0128] Phase 1: Service link between UE and satellite. In this phase, the UE exchanges data with the satellite, and then the satellite caches the received data and transmits the currently cached core network data to the UE.
[0129] Phase 2: Feeder link between the core network and the satellite. In this phase, the core network exchanges data with the satellite, and then the satellite caches the received data and transmits the currently cached UE data to the core network.
[0130] These two phases are executed at different times. The execution order of phase 1 and phase 2 is different based on whether the data interaction between the UE and the core network is upload or download. This means that when the UE is authenticated, the core network is offline or does not participate in the authentication process. The current authentication vector (3G, 4G, 5G) of the UE authenticated by the 3rd Generation Partnership Project (3GPP) contains a sequence number (SQN) generated by the core network based on rules. The UE will also maintain the SQN value synchronously. The 3GPP system allows the SQN value to be asynchronous within a certain range. However, when the SQN value exceeds the asynchronous range allowed by the system, both parties need to perform an SQN value synchronization process that must be participated by the core. In the S&F satellite communication scenario, this synchronization process cannot be completed in real time, thus affecting the access of the UE. In addition, the current authentication vector structure may cause the system to continue to use authentication vectors that have expired from the perspective of the core network, but the UE cannot make a judgment on this from the structure of the authentication vector, which will cause security risks.
[0131] The UE authentication vectors of 4G and 5G are both extensions of the UE authentication vectors of 3G, and the core part is still 3G content.
[0132] The 3G authentication vector structure is: (RAND, AUTN, XRES, CK, IK, AK).
[0133] Among them, RAND is a random number (Random challenge), AUTN is an authentication token (AuthenticationToken), XRES is an expected response (eXpected Response), CK is an encryption protection key, IK is an integrity protection key, and AK is an anonymous key;
[0134] The 4G authentication vector structure is: (K asme ,RAND,AUTN,XRES), where RAND, AUTN and XRES have the same meaning as the corresponding values in the 3G authentication vector, K asme It is the access security management entity key, which is generated based on CK and IK. The CK and IK are the same as the CK and IK in the 3G authentication vector.
[0135] The 5G authentication vector structure is: (RAND, AUTN, XRES*, K AUSF), where RAND, AUTN have the same meaning as the corresponding values in the 3G authentication vector, K AUSF It is the authentication server function key, which is generated based on CK and IK. The CK and IK are the same as the CK and IK in the 3G authentication vector. XRES* represents the expected authentication response value.
[0136] In the S&F scenario, when SQN synchronization is required, the UE and the core network cannot complete real-time SQN synchronization, so that the UE cannot access the satellite communication system this time. In addition, in the S&F scenario, the UE may be an IoT device. It may not be connected to the satellite for a long time, and the unused authentication vector generated by the core network for the UE may have expired, but neither the satellite nor the UE can judge this, which causes security risks.
[0137] like Figure 2 As shown, an embodiment of the present application provides a method for processing an authentication vector, which is executed by a first core network device, and the method includes:
[0138] Step 201: Generate a first authentication token of an authentication vector, wherein the first authentication token includes a first parameter of the authentication vector, and the first parameter is used to indicate a validity period of the authentication vector.
[0139] The above authentication vector is used to authenticate the terminal.
[0140] In the embodiment of the present application, the above-mentioned first core network device can be a home location register (Home Location Register, HLR), a home handover server (Home Handover Server, HHS), and a unified data management entity (Unified Data Management, UDM).
[0141] For example, when the above-mentioned authentication vector is a 3G authentication vector, the above-mentioned first core network device is HLR, when the above-mentioned authentication vector is a 4G authentication vector, the above-mentioned first core network device is HHS, and when the above-mentioned authentication vector is a 5G authentication vector, the above-mentioned first core network device is UDM.
[0142] Step 202: construct an authentication vector according to the first authentication token and the first parameter;
[0143] In the embodiment of the present application, the above-mentioned authentication vector includes the above-mentioned first authentication token and the first parameter. Of course, the authentication vector may also include other parameters.
[0144] Step 203: Send the authentication vector to the second core network device.
[0145] As an implementation method, the above-mentioned first core network device sends an authentication vector to the second core network device, and the second core network device can be a serving GPRS support node (Serving GPRS Support Node, SGSN), a mobility management entity (Mobility Management Entity, MME), an authentication service function (Authentication Server Function, AUSF) / security anchor function (Security Anchor Function, SEAF).
[0146] For example, when the above-mentioned authentication vector is a 3G authentication vector, the above-mentioned second core network device is SGSN, when the above-mentioned authentication vector is a 4G authentication vector, the above-mentioned first core network device is MME, and when the above-mentioned authentication vector is a 5G authentication vector, the above-mentioned first core network device is AUSF / SEAF.
[0147] In an embodiment of the present application, a first core network device generates a first authentication token of an authentication vector, wherein the first authentication token includes a first parameter of the authentication vector, and the first parameter is used to indicate the validity period of the authentication vector; an authentication vector is constructed according to the first authentication token and the first parameter; and the authentication vector is sent to a second core network device. Through the above scheme, the second core network device and the terminal can determine whether the authentication vector is valid based on the first parameter in the authentication vector, thereby effectively avoiding the security risks caused by the use of an invalid authentication vector.
[0148] Optionally, generating a first authentication token of an authentication vector comprises:
[0149] Generate a first message authentication code according to the first parameter and the second parameter, wherein the second parameter includes at least one of a permanent key K, an authentication management domain AMF parameter, a sequence number SQN, and a random number (RAND);
[0150] The first authentication token is generated according to the first message authentication code, the first parameter and a third parameter, wherein the third parameter includes at least one of an SQN, an anonymous key AK and an AMF parameter.
[0151] In this embodiment of the present application, the first message authentication code is used to verify the first authentication token.
[0152] As an optional implementation, the first message authentication code is calculated based on a message authentication code (MAC) calculation function, such as Figure 3As shown, the MAC calculation function obtains MAC' based on K, AMF parameter, SQN, RAND and the first parameter (which can also be described as a valid time parameter), and the MAC' is the first message authentication code.
[0153] The above-mentioned message authentication code calculation function can also describe a message verification function or a message verification function. As an optional implementation method, AMF, SQN, a random number and a first parameter are used as input parameters of the message verification function, K is used as an input key, and then a first message authentication code of a fixed length is obtained.
[0154] For example: MAC' = f1 K (SQN||RAND||AMF||first parameter), where f1 represents the above-mentioned message verification function, and “||” represents a connector.
[0155] As an optional implementation, the first authentication token AUTN' satisfies the following formula:
[0156]
[0157] in, Represents XOR operation, and “||” represents a connector.
[0158] Optionally, generating a first authentication token of an authentication vector comprises:
[0159] Generate a first message authentication code according to the target key, the second authentication token and the first parameter; wherein the target key is related to at least one of the encryption protection key CK, the integrity protection key IK and the terminal related information;
[0160] The first authentication token is generated according to the second authentication token, the first parameter and the first message authentication code.
[0161] Optionally, the terminal-related information includes at least one of the following:
[0162] The terminal's operator information;
[0163] Application service information of the terminal;
[0164] Terminal identification information.
[0165] In the embodiment of the present application, the above-mentioned second authentication token is an authentication token in an existing authentication vector, and its generation method is the same as the existing method of generating authentication tokens. The above-mentioned terminal-related information includes but is not limited to operator information, application service information, UE itself information, etc.
[0166] For example, the second authentication token AUTN mentioned above satisfies the following formula:
[0167]
[0168] Wherein, MAC is a message authentication code generated in an existing manner.
[0169] As an optional implementation, Figure 4 As shown, the above target key is obtained based on the key derivation function. Specifically, CK, IK and terminal related information are input as input parameters to the key derivation function, and then the target key MK is output. Then, the MAC calculation function obtains MAC' based on the second authentication token AUTN, the valid time and MK, and the MAC' is the first message authentication code. Finally, AUTN' is constructed based on AUTN, the valid time and MAC'.
[0170] Among them, obtaining the first message authentication code based on the key derivation function (or key derivation function or key generation function) includes taking the second authentication token and the first parameter as input parameters of the key derivation function, taking the target key as the input key of the key derivation function, and then obtaining a first message authentication code of a fixed length.
[0171] As an optional implementation, the first authentication token AUTN' satisfies the following formula:
[0172] AUTN':=AUTN||valid time||MAC'.
[0173] Optionally, the first parameter includes at least one of the following:
[0174] The effective start time and effective end time of the authentication vector;
[0175] The effective start time and effective duration of the authentication vector;
[0176] The validity period of the authentication vector ends.
[0177] In the embodiment of the present application, in addition to using at least one of the valid start time, valid end data and valid duration to indicate the valid time of the authentication vector, the valid time of the authentication vector may also be indicated in other ways, which are not specifically limited here.
[0178] In an embodiment of the present application, a first core network device generates a first authentication token of an authentication vector, wherein the first authentication token includes a first parameter of the authentication vector, and the first parameter is used to indicate the validity period of the authentication vector; constructs an authentication vector according to the first authentication token and the first parameter; and sends the authentication vector to a second core network device. Through the above scheme, the second core network device and the terminal can determine whether the authentication vector is valid based on the first parameter in the authentication vector, thereby effectively avoiding the security risks caused by the use of an invalid authentication vector. In addition, when the above-mentioned validity period is set reasonably, the SQN synchronization operation that may have been required can be omitted to ensure the communication performance between the terminal and the satellite.
[0179] like Figure 5 As shown, the embodiment of the present application also provides a method for processing an authentication vector, which is executed by a second core network device, and the method includes:
[0180] Step 501: Receive an authentication vector sent by a first core network device, wherein the authentication vector includes a first parameter, and the first parameter is used to indicate a validity period of the authentication vector.
[0181] The second core network device and the first core network device have been described in detail in the method embodiment on the first core network device side, and will not be repeated here.
[0182] Step 502: When it is determined according to the first parameter that the authentication vector is within the valid time, an authentication request is sent to a terminal, the authentication request including a first authentication token and a random number, and the first authentication token includes the first parameter.
[0183] Optionally, the first parameter includes at least one of the following:
[0184] The effective start time and effective end time of the authentication vector;
[0185] The effective start time and effective duration of the authentication vector;
[0186] The validity period of the authentication vector ends.
[0187] In an embodiment of the present application, an authentication vector is received, wherein the authentication vector includes a first parameter, and the first parameter is used to indicate the validity period of the authentication vector; when it is determined according to the first parameter that the authentication vector is within the validity period, an authentication request is sent to the terminal, and the authentication request includes a first authentication token and a random number, and the first authentication token includes the first parameter, so that the terminal can perform a subsequent authentication process when it is determined based on the first parameter that the authentication vector is within the validity period, thereby effectively avoiding the security risks caused by the use of an invalid authentication vector. In addition, when the above-mentioned validity period is set reasonably, the SQN synchronization operation that may be required can also be omitted to ensure the communication performance between the terminal and the satellite.
[0188] like Figure 6 As shown, the embodiment of the present application also provides a method for processing an authentication vector, which is executed by a terminal, and the method includes:
[0189] Step 601: Obtain an authentication request sent by a second core network device, wherein the authentication request includes a first authentication token of an authentication vector and a random number, wherein the first authentication token includes a first parameter, and the first parameter is used to indicate a valid time of the authentication vector.
[0190] Step 602: Verify the first authentication token.
[0191] Step 603: After the first authentication token is verified, if it is determined according to the first parameter in the first authentication token that the authentication vector is within the valid time, an authentication response message is sent to the second core network device.
[0192] In an embodiment of the present application, a terminal obtains an authentication request, the authentication request includes a first authentication token of an authentication vector and a random number, the first authentication token includes a first parameter, and the first parameter is used to indicate the validity period of the authentication vector; the first authentication token is verified; after the first authentication token is verified, if it is determined that the authentication vector is within the validity period according to the first parameter in the first authentication token, an authentication response message is sent. Through the above scheme, the terminal performs a subsequent authentication process when it is determined that the authentication vector is within the validity period based on the first parameter, thereby effectively avoiding the security risks caused by the use of an invalid authentication vector. In addition, when the above-mentioned validity period is set reasonably, the SQN synchronization operation that may be required can be omitted to ensure the communication performance between the terminal and the satellite.
[0193] Optionally, the verifying the first authentication token includes:
[0194] Generate a second message authentication code (XAMC');
[0195] comparing the second message authentication code with the first message authentication code (MAC') in the first authentication token;
[0196] In the case where the second message authentication code is identical to the first message authentication code, it is determined that the first authentication token has been authenticated successfully; otherwise, it is determined that the first authentication token has not been authenticated successfully.
[0197] Optionally, generating a second message authentication code includes:
[0198] Generate a second message authentication code according to the first parameter and the second parameter, where the second parameter includes at least one of a permanent key K, an AMF parameter, a sequence number SQN, and a random number;
[0199] Alternatively, a second message authentication code is generated according to a target key, a second authentication token and a first parameter; wherein the target key is related to at least one of an encryption protection key CK, an integrity protection key IK and terminal related information.
[0200] Optionally, the terminal-related information includes at least one of the following:
[0201] The terminal's operator information;
[0202] Application service information of the terminal;
[0203] Terminal identification information.
[0204] In the embodiment of the present application, the terminal generates the second message authentication code in the same manner as the first core network device generates the first message authentication code. For example, the first core network device generates the first message authentication code based on the first parameter and the second parameter, and the terminal also generates the first message authentication code based on the first parameter and the second parameter using the same algorithm. For another example, the first core network device generates the first message authentication code based on the target key, the second authentication token and the first parameter, and the terminal also generates the second message authentication code based on the target key, the second authentication token and the first parameter using the same algorithm.
[0205] Optionally, the first parameter includes at least one of the following:
[0206] The effective start time and effective end time of the authentication vector;
[0207] The effective start time and effective duration of the authentication vector;
[0208] The validity period of the authentication vector ends.
[0209] In the embodiment of the present application, the terminal performs a subsequent authentication process when the authentication vector is determined to be within the valid time based on the first parameter, thereby effectively avoiding the security risks caused by using an invalid authentication vector. In addition, if the above-mentioned valid time is set reasonably, the SQN synchronization operation that may be required can be omitted, thereby ensuring the communication performance between the terminal and the satellite.
[0210] The following is an explanation of the method for processing the authentication vector of the present application in conjunction with an embodiment.
[0211] Embodiment 1:
[0212] The authentication vector validity period is integrated into the existing authentication token (AUTN) to generate a new AUTN'. The new MAC value that verifies AUTN' is named MAC'.
[0213] The process includes:
[0214] Step 1: Calculate MAC' (message authentication code for verifying AUTN') using K, AMF, SQN, RAND and validity time.
[0215] Step 2: 'Construct AUTN' using SQN, AK, AMF, validity time and MAC:
[0216]
[0217] Step 3: Construct the authentication vector:
[0218] 3G authentication vector structure: AV:=RAND||XRES||CK||IK||AUTN'||valid time;
[0219] 4G authentication vector structure: AV:=K ASME ||RAND||XRES||AUTN'||Valid time;
[0220] 5G authentication vector structure: AV:=K AUSF ||RAND||XRES*||AUTN'||Valid time.
[0221] Among them, RAND in the 3G authentication vector structure is a random number, XRES is the expected response, CK is the encryption protection key, and IK is the integrity protection key;
[0222] RAND in the 4G authentication vector structure is a random number, K ASME For access security management entity key, XRES is the expected response;
[0223] RAND in the 5G authentication vector structure is a random number, KAUSF is the authentication server function key, and XRES* represents the expected authentication response value.
[0224] It should be noted that the message authentication code (MAC) is used to implement integrity protection for messages.
[0225] UE side verification process:
[0226] Using the SQN, RAND and validity time provided by AUTN', as well as the K and AMF provided locally, XAMC' is calculated using the same method as the core network to generate MAC'. If the two are the same, AUTN' is authenticated, thereby also proving the correctness of the validity time.
[0227] Embodiment 2:
[0228] The validity time is integrated into the existing authentication token (AUTN), and a new AUTN' is constructed using the existing AUTN and the validity time. The new MAC value that verifies AUTN' is named MAC'.
[0229] The process includes:
[0230] Step 1: Generate a key MK for calculating MAC' using CK, IK and information related to UE (optional), such as operator information, application service information, UE information or other information.
[0231] Step 2: Calculate AUTN (same as existing AUTN).
[0232] Step 3: Calculate MAC' using MK, AUTN and validity time.
[0233] Step 4: Build AUTN using AUTN, validity time and MAC:
[0234] AUTN':=AUTN||valid time||MAC';
[0235] Step 5: Construct the authentication vector: (AUTN' replaces the original AUTN in the authentication vector and increases the validity period):
[0236] 3G authentication vector structure: AV:=RAND||XRES||CK||IK||AUTN'||valid time;
[0237] 4G authentication vector structure: AV:=K ASME ||RAND||XRES||AUTN'||Valid time;
[0238] 5G authentication vector structure: AV:=K AUSF ||RAND||XRES*||AUTN'||Valid time.
[0239] Among them, RAND in the 3G authentication vector structure is a random number, XRES is the expected response, CK is the encryption protection key, and IK is the integrity protection key;
[0240] RAND in the 4G authentication vector structure is a random number, K ASME For access to the security management entity key, XRES is the expected response;
[0241] RAND in the 5G authentication vector structure is a random number, K AUSF is the authentication server function key, and XRES* represents the expected authentication response value.
[0242] UE side verification process:
[0243] Step 1: Use the existing method to verify AUTN in AUTN'. If the verification is successful, continue to calculate CK and IK.
[0244] Step 2: Using CK, IK and locally stored UE-related information, MK is calculated using the same algorithm as the core network.
[0245] Step 3: Calculate XMAC' using the same algorithm as the core network using the valid time provided in AUTN, MK and AUTN'. If the two are the same, AUTN' is authenticated, thus proving the correctness of the valid time.
[0246] Embodiment three:
[0247] like Figure 7 As shown, including:
[0248] Step 1: The first core network device generates an authentication vector.
[0249] The first core network device is a network element in the core network responsible for generating an authentication vector, such as the HLR of 3G, the HHS of 4G, and the UDM of 5G.
[0250] Specifically, the first core network device generates the above authentication vector using the method for generating an authentication vector described in Embodiment 1 or Embodiment 2.
[0251] Step 2: The first core network device provides the generated authentication vector to the second core network device.
[0252] The second core network device is a network element in the core network responsible for authenticating the UE, for example, SGSN of 3G, MME of 4G, AUSF / SEAF of 5G).
[0253] Step 3: The second core network device uses the "validity time" parameter in the UE authentication vector to determine whether the UE authentication vector is within the validity period. If it is within the validity period, continue to execute the following steps, otherwise stop the current operation.
[0254] Step 4: The second core network device sends RAND and AUTN' in the authentication vector to the UE.
[0255] Step 5: The UE calculates a new XMAC' using the MAC' calculation method described in Embodiment 1 or Embodiment 2, and compares whether the MAC' in AUTN' is the same as XMAC'. If they are the same, it proves that AUTN' is correct and continues with the following steps, otherwise the current operation is stopped.
[0256] Step 6: The UE uses the "valid time" parameter in AUTN' to determine whether the UE authentication vector is within the validity period. If it is within the validity period, continue to execute the following steps, otherwise stop the current operation.
[0257] Step 7: The UE continues to calculate the authentication response value using existing operations in existing 3G, 4G or 5G.
[0258] Step 8: The UE sends the calculated authentication response value to the network element in the core network responsible for authenticating the UE. The network element in the core network responsible for authenticating the UE continues to complete the subsequent UE authentication process based on the authentication response value returned by the UE.
[0259] In the embodiment of the present application, the terminal performs a subsequent authentication process when the authentication vector is determined to be within the valid time based on the first parameter, thereby effectively avoiding the security risks caused by using an invalid authentication vector. In addition, if the above-mentioned valid time is set reasonably, the SQN synchronization operation that may be required can be omitted, thereby ensuring the communication performance between the terminal and the satellite.
[0260] like Figure 8 As shown, the embodiment of the present application further provides an authentication vector processing device, including a memory 820, a transceiver 800, and a processor 810;
[0261] A memory 820, for storing computer programs; a transceiver 800, for transmitting and receiving data under the control of the processor;
[0262] In one embodiment of the present application, the processor 810 is configured to read the computer program in the memory and perform the following operations:
[0263] generating a first authentication token of an authentication vector, wherein the first authentication token comprises a first parameter of the authentication vector, and the first parameter is used to indicate a validity period of the authentication vector;
[0264] constructing an authentication vector according to the first authentication token and the first parameter;
[0265] Send the authentication vector to the second core network device.
[0266] In another embodiment of the present application, the processor 810 is configured to read the computer program in the memory and perform the following operations:
[0267] receiving an authentication vector sent by a first core network device, wherein the authentication vector includes a first parameter, and the first parameter is used to indicate a validity period of the authentication vector;
[0268] In a case where it is determined according to the first parameter that the authentication vector is within the valid time, an authentication request is sent to the terminal, the authentication request including a first authentication token and a random number, and the first authentication token includes the first parameter.
[0269] Among them, Figure 8 In the embodiment, the bus architecture may include any number of interconnected buses and bridges, specifically linking together various circuits of one or more processors represented by processor 810 and memory represented by memory 820. The bus architecture may also link together various other circuits such as peripherals, voltage regulators, and power management circuits, which are well known in the art and are therefore not further described herein. The bus interface provides an interface. The transceiver 800 may be a plurality of components, namely, a transmitter and a receiver, providing a unit for communicating with various other devices on a transmission medium, which transmission medium may include a wireless channel, a wired channel, an optical cable, and the like. The processor 810 is responsible for managing the bus architecture and general processing, and the memory 820 may store data used by the processor 810 when performing operations.
[0270] The processor 810 may be a central processing unit (CPU), an application specific integrated circuit (ASIC), a field programmable gate array (FPGA) or a complex programmable logic device (CPLD). The processor may also adopt a multi-core architecture.
[0271] It should be noted here that the above-mentioned device provided in the embodiment of the present application can implement all the method steps implemented in the above-mentioned authentication vector processing method embodiment applied to the first core network device or the second core network device, and can achieve the same technical effect. The parts and beneficial effects of this embodiment that are the same as the method embodiment will not be described in detail here.
[0272] like Fig. 9 As shown, an embodiment of the present application provides an authentication vector processing device, which is applied to a terminal, including a memory 920, a transceiver 900, and a processor 910;
[0273] The memory 920 is used to store computer programs; the transceiver 900 is used to send and receive data under the control of the processor 910; the processor 910 is used to read the computer program in the memory 920 and perform the following operations:
[0274] Obtaining an authentication request sent by a second core network device, the authentication request including a first authentication token of an authentication vector and a random number, the first authentication token including a first parameter, and the first parameter is used to indicate a valid time of the authentication vector;
[0275] verifying the first authentication token;
[0276] After the first authentication token is verified, if it is determined according to the first parameter in the first authentication token that the authentication vector is within the valid time, an authentication response message is sent to the second core network device.
[0277] Among them, Fig. 9 In the embodiment, the bus architecture may include any number of interconnected buses and bridges, specifically one or more processors represented by processor 910 and various circuits of memory represented by memory 920 are linked together. The bus architecture may also link together various other circuits such as peripheral devices, voltage regulators, and power management circuits, which are well known in the art and are therefore not further described herein. The bus interface provides an interface. The transceiver 900 may be a plurality of components, namely, a transmitter and a receiver, providing a unit for communicating with various other devices on a transmission medium, including transmission media such as wireless channels, wired channels, and optical cables. For different user devices, the user interface 930 may also be an interface capable of externally and internally connecting required devices, and the connected devices include but are not limited to a keypad, a display, a speaker, a microphone, a joystick, and the like.
[0278] The processor 910 is responsible for managing the bus architecture and general processing, and the memory 920 can store data used by the processor 910 when performing operations.
[0279] Optionally, the processor 910 may be a CPU (central processing unit), an ASIC (Application Specific Integrated Circuit), an FPGA (Field-Programmable Gate Array) or a CPLD (Complex Programmable Logic Device), and the processor may also adopt a multi-core architecture.
[0280] The processor calls the computer program stored in the memory to execute any of the methods provided in the embodiments of the present application according to the obtained executable instructions. The processor and the memory can also be arranged physically separately.
[0281] Optionally, the processor further performs the following operations:
[0282] generating a second message authentication code;
[0283] comparing the second message authentication code with the first message authentication code in the first authentication token;
[0284] In the case where the second message authentication code is identical to the first message authentication code, it is determined that the first authentication token has been authenticated successfully; otherwise, it is determined that the first authentication token has not been authenticated successfully.
[0285] Optionally, the processor further performs the following operations:
[0286] Generate a second message authentication code according to the first parameter and the second parameter, where the second parameter includes at least one of a permanent key K, an AMF parameter, a sequence number SQN, and a random number;
[0287] Alternatively, a second message authentication code is generated according to a target key, a second authentication token and a first parameter; wherein the target key is related to at least one of an encryption protection key CK, an integrity protection key IK and terminal related information.
[0288] Optionally, the terminal-related information includes at least one of the following:
[0289] The terminal's operator information;
[0290] Application service information of the terminal;
[0291] Terminal identification information.
[0292] Optionally, the first parameter includes at least one of the following:
[0293] The effective start time and effective end time of the authentication vector;
[0294] The effective start time and effective duration of the authentication vector;
[0295] The validity period of the authentication vector ends.
[0296] It should be noted here that the above-mentioned device provided in the embodiment of the present application can implement all the method steps implemented in the above-mentioned embodiment of the method for processing the authentication vector applied to the terminal, and can achieve the same technical effect. The parts and beneficial effects of this embodiment that are the same as those of the method embodiment will not be described in detail here.
[0297] like Fig.10 As shown, the embodiment of the present application also provides a device for processing an authentication vector, including:
[0298] A generating unit 1001 is configured to generate a first authentication token of an authentication vector, wherein the first authentication token includes a first parameter of the authentication vector, and the first parameter is used to indicate a validity period of the authentication vector;
[0299] A construction unit 1002, configured to construct an authentication vector according to the first authentication token and the first parameter;
[0300] The first sending unit 1003 is configured to send the authentication vector to the second core network device.
[0301] Optionally, the generating unit includes:
[0302] A first generating subunit, configured to generate a first message authentication code according to the first parameter and a second parameter, wherein the second parameter includes at least one of a permanent key K, an authentication management domain AMF parameter, a sequence number SQN, and a random number;
[0303] The second generating subunit is used to generate the first authentication token according to the first message authentication code, the first parameter and the third parameter, wherein the third parameter includes at least one of an SQN, an anonymous key AK and an AMF parameter.
[0304] Optionally, the generating unit includes:
[0305] A third generating subunit, configured to generate a first message authentication code according to a target key, a second authentication token and a first parameter; wherein the target key is related to at least one of an encryption protection key CK, an integrity protection key IK and terminal related information;
[0306] The fourth generating subunit is used to generate the first authentication token according to the second authentication token, the first parameter and the first message authentication code.
[0307] Optionally, the terminal-related information includes at least one of the following:
[0308] The terminal's operator information;
[0309] Application service information of the terminal;
[0310] Terminal identification information.
[0311] Optionally, the first parameter includes at least one of the following:
[0312] The effective start time and effective end time of the authentication vector;
[0313] The effective start time and effective duration of the authentication vector;
[0314] The validity period of the authentication vector ends.
[0315] It should be noted here that the above-mentioned device provided in the embodiment of the present application can implement all the method steps implemented in the above-mentioned authentication vector processing method embodiment applied to the first core network device, and can achieve the same technical effect. The parts and beneficial effects of this embodiment that are the same as the method embodiment will not be described in detail here.
[0316] like Fig.11 As shown, the embodiment of the present application also provides a device for processing an authentication vector, including:
[0317] The receiving unit 1101 is configured to receive an authentication vector sent by a first core network device, wherein the authentication vector includes a first parameter, and the first parameter is used to indicate a validity period of the authentication vector;
[0318] The second sending unit 1102 is used to send an authentication request to the terminal when it is determined according to the first parameter that the authentication vector is within the valid time, the authentication request including a first authentication token and a random number, and the first authentication token includes the first parameter.
[0319] Optionally, the first parameter includes at least one of the following:
[0320] The effective start time and effective end time of the authentication vector;
[0321] The effective start time and effective duration of the authentication vector;
[0322] The validity period of the authentication vector ends.
[0323] It should be noted here that the above-mentioned device provided in the embodiment of the present application can implement all the method steps implemented in the above-mentioned authentication vector processing method embodiment applied to the second core network device, and can achieve the same technical effect. The parts and beneficial effects of this embodiment that are the same as the method embodiment will not be described in detail here.
[0324] like Fig.12 As shown, the embodiment of the present application also provides a device for processing an authentication vector, including:
[0325] An acquiring unit 1201 is configured to acquire an authentication request sent by a second core network device, wherein the authentication request includes a first authentication token of an authentication vector and a random number, wherein the first authentication token includes a first parameter, and the first parameter is used to indicate a valid time of the authentication vector;
[0326] A verification unit 1202, configured to verify the first authentication token;
[0327] The third sending unit 1203 is used to send authentication response information to the second core network device after the first authentication token is verified and if it is determined according to the first parameter in the first authentication token that the authentication vector is within the valid time.
[0328] Optionally, the verification unit includes:
[0329] a fifth generating subunit, configured to generate a second message authentication code;
[0330] a comparing subunit, configured to compare the second message authentication code with the first message authentication code in the first authentication token;
[0331] The verification subunit is used to determine that the first authentication token has been verified successfully when the second message authentication code is the same as the first message authentication code; otherwise, determine that the first authentication token has not been verified successfully.
[0332] Optionally, the fifth generating subunit is used for:
[0333] Generate a second message authentication code according to the first parameter and the second parameter, where the second parameter includes at least one of a permanent key K, an AMF parameter, a sequence number SQN, and a random number;
[0334] Alternatively, a second message authentication code is generated according to a target key, a second authentication token and a first parameter; wherein the target key is related to at least one of an encryption protection key CK, an integrity protection key IK and terminal related information.
[0335] Optionally, the terminal-related information includes at least one of the following:
[0336] The terminal's operator information;
[0337] Application service information of the terminal;
[0338] Terminal identification information.
[0339] Optionally, the first parameter includes at least one of the following:
[0340] The effective start time and effective end time of the authentication vector;
[0341] The effective start time and effective duration of the authentication vector;
[0342] The validity period of the authentication vector ends.
[0343] It should be noted here that the above-mentioned device provided in the embodiment of the present application can implement all the method steps implemented in the above-mentioned embodiment of the method for processing the authentication vector applied to the terminal, and can achieve the same technical effect. The parts and beneficial effects of this embodiment that are the same as those of the method embodiment will not be described in detail here.
[0344] It should be noted that the division of units in the embodiments of the present application is schematic and is only a logical function division. There may be other division methods in actual implementation. In addition, each functional unit in each embodiment of the present application may be integrated into a processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit. The above-mentioned integrated unit may be implemented in the form of hardware or in the form of software functional units.
[0345] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a processor-readable storage medium. Based on this understanding, the technical solution of the present application is essentially or the part that contributes to the prior art or all or part of the technical solution can be embodied in the form of a software product, and the computer software product is stored in a storage medium, including a number of instructions to enable a computer device (which can be a personal computer, server, or network device, etc.) or a processor (processor) to perform all or part of the steps of the method described in each embodiment of the present application. The aforementioned storage medium includes: U disk, mobile hard disk, read-only memory (Read-Only Memory, ROM), random access memory (Random Access Memory, RAM), disk or optical disk and other media that can store program codes.
[0346] In some embodiments of the present application, a processor-readable storage medium is also provided, which stores program instructions, and the program instructions are used to enable the processor to execute all the steps implemented by the method embodiment executed by the above-mentioned terminal or all the steps implemented by the method embodiment executed by the first core network device or the second core network device, and can achieve the same technical effect. The parts and beneficial effects of this embodiment that are the same as the method embodiment will not be described in detail here.
[0347] The terminal device involved in the embodiment of the present application may be a device that provides voice and / or data connectivity to a user, a handheld device with a wireless connection function, or other processing devices connected to a wireless modem. In different systems, the name of the terminal device may also be different. For example, in a 5G system, the terminal device may be called a user equipment (UE). A wireless terminal device can communicate with one or more core networks (CN) via a radio access network (RAN). The wireless terminal device may be a mobile terminal device, such as a mobile phone (or a "cellular" phone) and a computer with a mobile terminal device. For example, it may be a portable, pocket-sized, handheld, computer-built-in or vehicle-mounted mobile device that exchanges language and / or data with a wireless access network. For example, personal communication service (PCS) phones, cordless phones, session initiation protocol (SIP) phones, wireless local loop (WLL) stations, personal digital assistants (PDAs) and other devices. The wireless terminal device may also be referred to as a system, a subscriber unit, a subscriber station, a mobile station, a mobile station, a remote station, an access point, a remote terminal device, an access terminal device, a user terminal device, a user agent, and a user device, but is not limited in the embodiments of the present application.
[0348] The network device (or network side device) involved in the embodiment of the present application may be a base station, which may include multiple cells providing services for the terminal. Depending on the specific application scenario, the base station may also be called an access point, or may be a device in the access network that communicates with the wireless terminal device through one or more sectors on the air interface, or other names. The network device may be used to interchange received air frames with Internet Protocol (IP) packets, and serve as a router between the wireless terminal device and the rest of the access network, wherein the rest of the access network may include an Internet Protocol (IP) communication network. The network device may also coordinate the attribute management of the air interface. For example, the network device involved in the embodiments of the present application may be a network device (Base TransceiverStation, BTS) in the Global System for Mobile communications (Global System for Mobile communications, GSM) or Code Division Multiple Access (Code Division Multiple Access, CDMA), or a network device (NodeB) in Wide-band Code Division Multiple Access (WCDMA), or an evolutionary network device (evolutional Node B, eNB or e-NodeB) in the Long Term Evolution (Long Term Evolution, LTE) system, a 5G base station (gNB) in the 5G network architecture (next generation system), or a home evolved Node B (Home evolved Node B, HeNB), a relay node, a home base station (femto), a pico base station (pico), etc., which is not limited in the embodiments of the present application. In some network structures, the network device may include a centralized unit (CU) node and a distributed unit (DU) node, and the centralized unit and the distributed unit may also be arranged geographically separately.
[0349] Network devices and terminal devices can each use one or more antennas for multiple-input multiple-output (MIMO) transmission. MIMO transmission can be single-user MIMO (SU-MIMO) or multi-user MIMO (MU-MIMO). Depending on the form and number of antenna combinations, MIMO transmission can be 2D-MIMO, 3D-MIMO, FD-MIMO or massive-MIMO, or it can be diversity transmission, precoded transmission or beamforming transmission, etc.
[0350] Those skilled in the art will appreciate that the embodiments of the present application may be provided as methods, systems, or computer program products. Therefore, the present application may adopt the form of a complete hardware embodiment, a complete software embodiment, or an embodiment in combination with software and hardware. Moreover, the present application may adopt the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage and optical storage, etc.) that contain computer-usable program code.
[0351] The present application is described with reference to the flowcharts and / or block diagrams of the methods, devices (systems), and computer program products according to the embodiments of the present application. It should be understood that each process and / or box in the flowchart and / or block diagram, as well as the combination of the processes and / or boxes in the flowchart and / or block diagram, can be implemented by computer executable instructions. These computer executable instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to generate a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowchart and / or block diagram. Figure 1 A process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.
[0352] These processor executable instructions may also be stored in a processor readable memory that can direct a computer or other programmable data processing device to operate in a specific manner, so that the instructions stored in the processor readable memory produce an article of manufacture including an instruction device, which implements the process Figure 1 A process or multiple processes and / or boxes Figure 1 A function specified in one or more boxes.
[0353] These processor-executable instructions may also be loaded onto a computer or other programmable data processing device so that a series of operational steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing instructions for executing on the computer or other programmable device to implement the process. Figure 1A process or multiple processes and / or boxes Figure 1 The steps for the functions specified in one or more boxes.
[0354] Obviously, those skilled in the art can make various changes and modifications to the present application without departing from the spirit and scope of the present application. Thus, if these modifications and variations of the present application fall within the scope of the claims of the present application and their equivalents, the present application is also intended to include these modifications and variations.
Claims
1. A method for processing an authentication vector, characterized in that: The method is performed by a first core network device and includes: generating a first authentication token of an authentication vector, wherein the first authentication token comprises a first parameter of the authentication vector, and the first parameter is used to indicate a validity period of the authentication vector; constructing an authentication vector according to the first authentication token and the first parameter; Send the authentication vector to the second core network device.
2. The method according to claim 1, characterized in that The generating of the first authentication token of the authentication vector comprises: Generate a first message authentication code according to the first parameter and the second parameter, wherein the second parameter includes at least one of a permanent key K, an authentication management domain AMF parameter, a sequence number SQN, and a random number; The first authentication token is generated according to the first message authentication code, the first parameter and a third parameter, wherein the third parameter includes at least one of an SQN, an anonymous key AK and an AMF parameter.
3. The method according to claim 1, characterized in that The generating of the first authentication token of the authentication vector comprises: Generate a first message authentication code according to the target key, the second authentication token and the first parameter; wherein the target key is related to at least one of the encryption protection key CK, the integrity protection key IK and the terminal related information; The first authentication token is generated according to the second authentication token, the first parameter and the first message authentication code.
4. The method according to claim 3, characterized in that The terminal related information includes at least one of the following: The terminal's operator information; Application service information of the terminal; Terminal identification information.
5. The method according to any one of claims 1 to 4, characterized in that: The first parameter includes at least one of the following: The effective start time and effective end time of the authentication vector; The effective start time and effective duration of the authentication vector; The validity period of the authentication vector ends.
6. A method for processing an authentication vector, characterized in that: The method is performed by a second core network device and includes: receiving an authentication vector sent by a first core network device, wherein the authentication vector includes a first parameter, and the first parameter is used to indicate a validity period of the authentication vector; In a case where it is determined according to the first parameter that the authentication vector is within the valid time, an authentication request is sent to the terminal, the authentication request including a first authentication token and a random number, and the first authentication token includes the first parameter.
7. The method according to claim 6, characterized in that The first parameter includes at least one of the following: The effective start time and effective end time of the authentication vector; The effective start time and effective duration of the authentication vector; The validity period of the authentication vector ends.
8. A method for processing an authentication vector, characterized in that: Executed by a terminal, the method includes: Obtaining an authentication request sent by a second core network device, the authentication request including a first authentication token of an authentication vector and a random number, the first authentication token including a first parameter, and the first parameter is used to indicate a valid time of the authentication vector; verifying the first authentication token; After the first authentication token is verified, if it is determined according to the first parameter in the first authentication token that the authentication vector is within the valid time, an authentication response message is sent to the second core network device.
9. The method according to claim 8, characterized in that The verifying the first authentication token comprises: generating a second message authentication code; comparing the second message authentication code with the first message authentication code in the first authentication token; In the case where the second message authentication code is identical to the first message authentication code, it is determined that the first authentication token has been authenticated successfully; otherwise, it is determined that the first authentication token has not been authenticated successfully.
10. The method according to claim 9, characterized in that The generating a second message authentication code comprises: Generate a second message authentication code according to the first parameter and the second parameter, where the second parameter includes at least one of a permanent key K, an AMF parameter, a sequence number SQN, and a random number; Alternatively, a second message authentication code is generated according to a target key, a second authentication token and a first parameter; wherein the target key is related to at least one of an encryption protection key CK, an integrity protection key IK and terminal related information.
11. The method according to claim 10, characterized in that The terminal related information includes at least one of the following: The terminal's operator information; Application service information of the terminal; Terminal identification information.
12. The method according to any one of claims 8 to 11, characterized in that The first parameter includes at least one of the following: The effective start time and effective end time of the authentication vector; The effective start time and effective duration of the authentication vector; The validity period of the authentication vector ends.
13. An authentication vector processing device, characterized in that: Including memory, transceiver, processor; Memory for storing computer programs; a transceiver, for transmitting and receiving data under the control of the processor; A processor is configured to read the computer program in the memory and perform the following operations: generating a first authentication token of an authentication vector, wherein the first authentication token comprises a first parameter of the authentication vector, and the first parameter is used to indicate a validity period of the authentication vector; constructing an authentication vector according to the first authentication token and the first parameter; Send the authentication vector to the second core network device.
14. The device according to claim 13, characterized in that The processor also performs the following operations: Generate a first message authentication code according to the first parameter and the second parameter, wherein the second parameter includes at least one of a permanent key K, an authentication management domain AMF parameter, a sequence number SQN, and a random number; The first authentication token is generated according to the first message authentication code, the first parameter and a third parameter, wherein the third parameter includes at least one of an SQN, an anonymous key AK and an AMF parameter.
15. The device according to claim 13, characterized in that The processor also performs the following operations: Generate a first message authentication code according to the target key, the second authentication token and the first parameter; wherein the target key is related to at least one of the encryption protection key CK, the integrity protection key IK and the terminal related information; The first authentication token is generated according to the second authentication token, the first parameter and the first message authentication code.
16. The device according to claim 15, characterized in that The terminal related information includes at least one of the following: The terminal's operator information; Application service information of the terminal; Terminal identification information.
17. The device according to any one of claims 13 to 16, characterized in that The first parameter includes at least one of the following: The effective start time and effective end time of the authentication vector; The effective start time and effective duration of the authentication vector; The validity period of the authentication vector ends.
18. An authentication vector processing device, characterized in that: Including memory, transceiver, processor; A memory for storing a computer program; a transceiver for transmitting and receiving data under the control of the processor; and a processor for reading the computer program in the memory and performing the following operations: receiving an authentication vector sent by a first core network device, wherein the authentication vector includes a first parameter, and the first parameter is used to indicate a validity period of the authentication vector; In a case where it is determined according to the first parameter that the authentication vector is within the valid time, an authentication request is sent to the terminal, the authentication request including a first authentication token and a random number, and the first authentication token includes the first parameter.
19. The device according to claim 18, characterized in that The first parameter includes at least one of the following: The effective start time and effective end time of the authentication vector; The effective start time and effective duration of the authentication vector; The validity period of the authentication vector ends.
20. An authentication vector processing device, characterized in that: Including memory, transceiver, processor; a memory for storing a computer program; a transceiver for transmitting and receiving data under the control of the processor; A processor is configured to read the computer program in the memory and perform the following operations: Obtaining an authentication request sent by a second core network device, the authentication request including a first authentication token of an authentication vector and a random number, the first authentication token including a first parameter, and the first parameter is used to indicate a valid time of the authentication vector; verifying the first authentication token; After the first authentication token is verified, if it is determined according to the first parameter in the first authentication token that the authentication vector is within the valid time, an authentication response message is sent to the second core network device.
21. The device according to claim 20, characterized in that The processor also performs the following operations: generating a second message authentication code; comparing the second message authentication code with the first message authentication code in the first authentication token; In the case where the second message authentication code is identical to the first message authentication code, it is determined that the first authentication token has been authenticated successfully; otherwise, it is determined that the first authentication token has not been authenticated successfully.
22. The device according to claim 21, characterized in that The processor also performs the following operations: Generate a second message authentication code according to the first parameter and the second parameter, where the second parameter includes at least one of a permanent key K, an AMF parameter, a sequence number SQN, and a random number; Alternatively, a second message authentication code is generated according to a target key, a second authentication token and a first parameter; wherein the target key is related to at least one of an encryption protection key CK, an integrity protection key IK and terminal related information.
23. The device according to claim 22, characterized in that The terminal related information includes at least one of the following: The terminal's operator information; Application service information of the terminal; Terminal identification information.
24. The device according to any one of claims 20 to 23, characterized in that The first parameter includes at least one of the following: The effective start time and effective end time of the authentication vector; The effective start time and effective duration of the authentication vector; The validity period of the authentication vector ends.
25. An authentication vector processing device, characterized in that: include: A generating unit, configured to generate a first authentication token of an authentication vector, wherein the first authentication token includes a first parameter of the authentication vector, and the first parameter is used to indicate a valid time of the authentication vector; a construction unit, configured to construct an authentication vector according to the first authentication token and the first parameter; The first sending unit is configured to send the authentication vector to the second core network device.
26. An authentication vector processing device, characterized in that: include: A receiving unit, configured to receive an authentication vector sent by a first core network device, wherein the authentication vector includes a first parameter, and the first parameter is used to indicate a valid time of the authentication vector; The second sending unit is configured to send an authentication request to the terminal when it is determined according to the first parameter that the authentication vector is within the valid time, the authentication request including a first authentication token and a random number, and the first authentication token including the first parameter.
27. An authentication vector processing device, characterized in that: include: An acquiring unit, configured to acquire an authentication request sent by a second core network device, wherein the authentication request includes a first authentication token of an authentication vector and a random number, wherein the first authentication token includes a first parameter, and the first parameter is used to indicate a valid time of the authentication vector; a verification unit, configured to verify the first authentication token; The third sending unit is used to send authentication response information to the second core network device after the first authentication token is verified and if it is determined according to the first parameter in the first authentication token that the authentication vector is within the valid time.
28. A processor-readable storage medium, characterized in that: The processor-readable storage medium stores a computer program, and the computer program is used to cause the processor to execute the steps of the authentication vector processing method as described in any one of claims 1 to 5, or to execute the steps of the authentication vector processing method as described in any one of claims 6 to 7, or to execute the steps of the authentication vector processing method as described in any one of claims 8 to 12.