Communication method and device

By adopting a domain name-based authentication mechanism in the service-oriented architecture of 5G networks, the network element authentication process is simplified, the problems of authentication complexity and security risks in the existing technology are solved, and automated and efficient network element authentication and certificate issuance are realized.

CN119946632APending Publication Date: 2025-05-06HUAWEI TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202311447842.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2023-11-01
Publication Date
2025-05-06

AI Technical Summary

Technical Problem

Under the service-oriented architecture of 5G networks, the existing network element authentication and certificate issuance methods are complex, requiring multiple CA deployment and manual management, increasing costs and security risks.

Method used

The domain name-based authentication mechanism is adopted to verify the domain name of the network functional network element through the first authentication device, issue domain name certificates, simplify the authentication process and reduce the complexity of the system.

Benefits of technology

It realizes automation and efficiency of network element authentication, reduces manual management needs, reduces costs, and improves network security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119946632A_ABST
    Figure CN119946632A_ABST
Patent Text Reader

Abstract

The invention provides a communication method and device which can be applied to a service architecture network. According to the method, a network function network element obtains a domain name of the network function network element, and the network function network element is a network element in a service architecture network. And the network function network element sends the domain name of the network function network element to the first authentication device, wherein the domain name of the network function network element is used for verifying the network function network element. And the network function network element obtains a first domain name certificate issued by the first authentication device, wherein the first domain name certificate is used for indicating that the verification is passed. Therefore, the method provides a domain name-based network element verification scheme for reducing the complexity of a network function network element authentication mechanism and improving the network element authentication efficiency.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of mobile communication technology, and in particular to a communication method and device. Background Art

[0002] The core network of the fifth generation (5G) mobile communication network adopts the network function virtualization (NFV) technology, which subdivides the functions of network elements into different network functions (NF) and deploys them on the network platform in a virtualized form, thereby realizing the rapid deployment of network functions. In order to simplify the communication and access control between network elements, the 5G network adopts the service-based architecture (SBA), and the virtualized network elements interact through the service-based architecture.

[0003] Based on network security considerations, the interaction between different NF network elements is based on the authentication certificate of the NF network element. In the network element authentication scheme currently used in the service-oriented architecture network, a third-party certificate authority (CA) is required to issue the public key certificate of the network function network element. In the communication authority authentication process of the network function network element, the authenticity of the public key certificate of the network function network element is verified based on the public key infrastructure (PKI) technology. If the verification is true, communication is allowed.

[0004] However, the service-oriented architecture may involve the authentication of various types of network function elements in multiple networks, which requires the deployment of numerous CAs and the manual management of CA deployment, which not only increases costs but is also prone to errors and security incidents. Therefore, in the current 5G network with a service-oriented architecture, the authentication and certificate issuance methods of NF elements need to be optimized. Summary of the invention

[0005] The present application provides a communication method and device for providing an authentication and certificate issuance mechanism for network function network elements suitable for a service-oriented architecture, so as to reduce the complexity of the network function network element authentication mechanism and improve the authentication efficiency.

[0006] In a first aspect, a communication method is provided. The method may be implemented by a first communication device. The first communication device may be a network function network element, or a component in the network function network element. Among them, the component in the present application may include at least one of a chip, a chip system, a processor, a transceiver, a processing unit, or a transceiver unit. The network function network element may be a network element deployed in a core network with a service-oriented architecture.

[0007] Taking the execution subject as a network function network element as an example, the method can be implemented through the following steps: the network function network element obtains the domain name of the network function network element, and the network function network element is a network element in a service-oriented architecture network. The network function network element sends the domain name of the network function network element to the first authentication device, and the domain name of the network function network element is used to verify the network function network element. The network function network element obtains a first domain name certificate issued by the first authentication device, and the first domain name certificate is used to indicate that the verification is passed.

[0008] Based on the first aspect, the network function network element under the service-oriented architecture can obtain the domain name of the network function network element, and send the domain name of the network function network element to the first authentication device, so that the first authentication device verifies the network function network element according to the domain name. After the verification is passed, the first authentication device can issue a first domain name certificate to indicate that the network function network element has passed the verification. The above authentication mechanism of the first domain name certificate is based on the domain name of the network function network element of the service-oriented architecture, that is, the identity of the network function network element is verified according to the domain name of the network function network element. Therefore, there is no need to issue a public key certificate to the network function network element in advance, which can reduce the complexity of the authentication system and does not require the introduction of too many manual deployment operations. In addition, the above authentication process does not require verification of the public key certificate, which saves a lot of calculations in the public key certificate verification process, and thus can achieve efficient network element authentication.

[0009] In a possible implementation, the verification is based on an automatic certificate management environment (ACME) protocol, which can implement automatic authentication and certificate issuance of network elements in a service-oriented architecture.

[0010] In a possible implementation, the domain name of the network function network element is determined according to the type information of the network function network element. In other words, there is a corresponding relationship between the domain name of the network function network element and the type information of the network function network element, or the domain name of the network function network element and the type information of the network function network element can be converted to each other through the corresponding relationship. As an example, there is a corresponding relationship between the domain name of the network function network element and the type information of the network function network element, for example, the domain name of the network function network element contains the type information of the network function network element.

[0011] In a set of possible implementations, the network function network element also sends the type information of the network function network element to the first authentication device, and the type information can be used to verify the type information corresponding to the domain name of the network function network element. Based on this implementation, before the first authentication device issues the first domain name certificate, the first authentication device can determine the type information corresponding to the domain name based on the domain name provided by the network function network element. Further, the first authentication device can compare whether the type information corresponding to the domain name of the network function network element is consistent with the type information provided by the network function network element to verify whether the network function network element has impersonated the information of other network elements or devices. If the comparison is consistent, it means that there is no identity impersonation, and the first authentication device can verify the network function network element. If the comparison is inconsistent, it means that there is identity impersonation, and the first authentication device can refuse to verify the network function network element, or determine that the verification result is not passed. Therefore, based on this implementation, the authentication reliability of the network function network element can be further improved.

[0012] In a possible implementation, the network function network element may also receive DNS challenge information from the first authentication server. The network function network element may also generate a DNS challenge response based on the domain name service (DNS) challenge information. The network function network element requests the second device to write the DNS challenge response into the domain name record of the network function network element in the DNS server. The network function network element receives an indication of completion of domain name record modification from the second device. The network function network element notifies the first authentication device to obtain the DNS challenge response from the DNS server, and the DNS challenge response and the DNS challenge information obtained by the first authentication device from the DNS server are used to verify the network function network element. The network function network element receives information from the first authentication device indicating that the verification is successful.

[0013] Based on this implementation, when the DNS method is used for domain name challenge verification, the network function network element can request the second device to write the DNS challenge information to the DNS server. Wherein, the second device is a device configured to have the right to modify the domain name record in the DNS, and its authority includes: in the process of receiving the DNS challenge response from the network function network element, the domain name of the network function network element is determined according to the connection information (such as tunnel information) between the network function network element, and the second device can also trigger or request the DNS server to modify the record corresponding to the domain name according to the domain name of the network function network element. Wherein, the domain name determined by the second device is the domain name of the network function network element obtained in the process of establishing a connection with the network function network element, so it can only request the DNS server to write the DNS challenge response to the record of the domain name of the network function network element, and will not write the DNS challenge response to the corresponding record of the false domain name of the DNS server according to the false domain name provided by the network function network element when sending the DNS challenge response, which can avoid the network function network element from providing a false domain name when requesting the second device to write the DNS challenge response, and obtaining a domain name certificate according to the false domain name, which can reduce the risk of domain name impersonation. Exemplarily, the second device may be a management device or a network repository function (NRF) network element, and the management device may be, for example, an operation and maintenance (OAM) device.

[0014] In a possible implementation, the first authentication device is deployed in the first network, and the first domain name certificate is specifically used for the network function network element to communicate with the network elements in the first network. Based on this implementation, the first authentication device deployed in the same network as the network function network element can issue a first domain name certificate to the network function network element for the network function network element to communicate in the network. This architecture can achieve secure communication within the same network.

[0015] In a possible implementation, the network function network element sends a domain name certificate acquisition request to a certificate management network element in the first network according to the first domain name certificate, the domain name certificate acquisition request is used to request a certificate of the network function network element issued by a second authentication device in the second network, and the domain name certificate acquisition request includes the domain name of the network function network element. The network function network element receives the second domain name certificate from the certificate management network element, and the second domain name certificate is issued by the second authentication device.

[0016] Based on this implementation, a second authentication device deployed in the second network can issue a second domain name certificate to the network function network element, which is used for the network function network element to communicate with the network element or device in the second network. The network function network element can communicate with the certificate management network element deployed in the first network, and communicate with the second authentication device of the second network through the certificate management network element. For example, the domain name of the network function network element is provided to the second authentication device through the certificate management network element, and the second authentication device verifies the network function network element according to the domain name of the network function network element. If the verification is successful, the second authentication device can issue a second domain name certificate.

[0017] In a possible implementation, the second domain name certificate is used for the network function network element to communicate with the network element of the second network. Therefore, cross-network secure communication can be achieved based on the second domain name certificate.

[0018] In a possible implementation, the network function network element receives information about the second authentication device from the management device, and the domain name certificate acquisition request also includes information about the second authentication device. Based on this implementation, the management device can provide the network function network element with information about the second authentication device, so that the network function network element sends the domain name to the second authentication device through the certificate management device to achieve verification.

[0019] In a possible implementation, the network function network element sends a domain name certificate acquisition request to the certificate management network element in the first network based on the first domain name certificate, including: the network function network element sends the first domain name certificate to the certificate management network element; the network function network element receives a first indication from the certificate management network element, and the first indication indicates that the first domain name certificate is authenticated; the network function network element sends the domain name certificate acquisition request to the certificate management network element.

[0020] Based on this implementation method, the communication between the network function network element and the certificate management network element can be based on the first domain name certificate of the network function network element, avoiding the network function network element that does not have the communication authority within the first network requesting the second authentication device to obtain the domain name certificate through the certificate management network element, which can improve the security of the cross-network communication process.

[0021] In a possible implementation, the first domain name certificate includes the domain name and type information of the network function network element, and the type information in the first domain name certificate is used to verify the domain name of the network function network element. Accordingly, before establishing communication with other network elements, other network elements can verify whether the type information corresponding to the domain name in the first domain name certificate is consistent with the type information contained in the first domain name certificate. If the verification result is inconsistent, the request can be rejected. Therefore, it is possible to identify whether the domain name certificate is forged, which can further improve network security.

[0022] In a second aspect, a communication method is provided. The method may be implemented by a second communication device. In the present application, the second communication device may be a management device or a component in a management device. The management device is, for example, an OAM device. Taking the execution subject as an example, the method may be implemented by the following steps: the management device provides the domain name of the network function network element to the network function network element; the management device sends a registration message to the DNS server, and the registration message includes the domain name of the network function network element.

[0023] In a possible implementation, the management device may also send information of a second authentication device to the network function network element, where the second authentication device is used to issue a second domain name certificate to the network function network element.

[0024] For the beneficial effects of the above second aspect and its possible implementation methods, reference may be made to the description of the beneficial effects of the corresponding implementation methods in the first aspect.

[0025] In a third aspect, a communication method is provided. The method can be implemented by a third communication device. In the present application, the third communication device can be a second device or a component in the second device. The second device is, for example, an OAM device or an NRF network element, which is used to request a DNS server to modify a domain name record. Taking the execution subject as the second device as an example, the method can be implemented by the following steps: the second device receives a DNS challenge response from the network function network element; the second device determines the domain name of the network function network element based on the connection information between the second device and the network function network element; the second device writes the DNS challenge response into the domain name record of the network function network element in the DNS server based on the domain name of the network function network element.

[0026] For the beneficial effects of the third aspect and its possible implementations, refer to the description of the beneficial effects of the corresponding implementations in the first aspect.

[0027] In a fourth aspect, a communication method is provided. The method can be implemented by a fourth communication device. In the present application, the fourth communication device can be a first authentication device or a component in the first authentication device. The first authentication device is, for example, a CA. Taking the execution subject as the first authentication device as an example, the method can be implemented by the following steps: the first authentication device receives the domain name and type information of the network function network element from the network function network element; the first authentication device verifies the type information and the type information corresponding to the domain name of the network function network element; if the verification passes, for example, the two are consistent, the first authentication device issues the first domain name certificate.

[0028] In a possible implementation, the first authentication device obtains the DNS challenge response from the DNS server;

[0029] The first authentication device verifies the network function network element according to the DNS challenge response and the DNS challenge information;

[0030] In the case where the verification is successful, the first authentication device provides the information indicating that the verification is successful to the network function network element.

[0031] The beneficial effects of the fourth aspect and its possible implementation methods can refer to the description of the beneficial effects of the corresponding implementation methods in the first aspect.

[0032] In a fifth aspect, a communication method is provided. The method can be implemented by a fifth communication device. In the present application, the fifth communication device can be a certificate management network element or a component in the certificate management network element. Taking the execution subject as an example, the method can be implemented by the following steps: the certificate management network element receives a domain name certificate acquisition request from a network function network element, the domain name certificate acquisition request is used to request a certificate of the network function network element issued by a second authentication device in a second network, the domain name certificate acquisition request includes a domain name of the network function network element, the network function network element and the certificate management network element belong to a first network, and the first domain name certificate is used for the network function network element to communicate with the network element in the first network; the certificate management network element sends the domain name of the network function network element to the second authentication device, and the domain name of the network function network element is used to verify the network function network element; the certificate management network element obtains a second domain name certificate issued by the second authentication device, and the second domain name certificate is used to indicate that the verification is passed; the certificate management network element sends the second domain name certificate to the network function network element.

[0033] In a possible implementation, the certificate management network element may also obtain domain name service DNS challenge information from the second authentication device; the certificate management network element generates a DNS challenge response based on the DNS challenge information; the certificate management network element writes the DNS challenge response into the domain name record of the network function network element in the domain name service DNS server; or, the certificate management network element requests the second device to write the DNS challenge response into the domain name record of the network function network element in the DNS server; the certificate management network element receives an indication of completion of domain name record modification from the second device; the certificate management network element notifies the second authentication device to obtain the DNS challenge response from the DNS server, and the DNS challenge response and the DNS challenge information are used by the second authentication device to verify the network function network element; if the verification is successful, the certificate management network element obtains information provided by the second authentication device to indicate that the verification is successful.

[0034] In a possible implementation, the second device receives a DNS challenge response from the certificate management network element; and the second device writes the DNS challenge response into a domain name record of the network function network element in the DNS server.

[0035] In a possible implementation, the first authentication device may also obtain the DNS challenge response from the DNS server; the first authentication device verifies the network function network element based on the DNS challenge response and the DNS challenge information; if the verification passes, the first authentication device provides the network function network element with the information indicating that the verification passed.

[0036] In a possible implementation, the certificate management network element may also receive a first domain name certificate from the network function network element, where the first domain name certificate is used to indicate that the domain name of the network function network element has passed verification, and the first domain name certificate includes the domain name and type information of the network function network element; the certificate management network element verifies the type information and the type information corresponding to the domain name of the network function network element; if the verification passes, the certificate management network element sends a first indication to the network function network element, where the first indication indicates that the first domain name certificate authentication has passed.

[0037] In a possible implementation manner, the second domain name certificate is used for the network function network element to communicate with the network element of the second network.

[0038] The beneficial effects of the above fifth aspect and its possible implementation methods can refer to the description of the beneficial effects of the corresponding implementation methods in the first aspect.

[0039] In a sixth aspect, a communication device is provided. The device may implement the method described in any possible implementation of any aspect of the first to fifth aspects. The device has the functions of any one of the first to fifth communication devices. The device is, for example, a network function network element, a management device, a second device, a first authentication device, or a certificate management network element, or a component in a network function network element, a component in a management device, a component in a second device, a component in a first authentication device, or a component in a certificate management network element.

[0040] In an optional implementation, the device may include a module corresponding to the method / operation / step / action described in any possible implementation of any aspect from the first aspect to the fifth aspect, and the module may be a hardware circuit, or software, or a hardware circuit combined with software. In an optional implementation, the device includes a processing unit (sometimes also referred to as a processing module) and a communication unit (sometimes also referred to as a transceiver module, a communication module, etc.). The transceiver unit can implement a sending function and a receiving function. When the transceiver unit implements the sending function, it can be called a sending unit (sometimes also referred to as a sending module), and when the transceiver unit implements the receiving function, it can be called a receiving unit (sometimes also referred to as a receiving module). The sending unit and the receiving unit can be the same functional module, which is called a transceiver unit, and the functional module can implement the sending function and the receiving function; or, the sending unit and the receiving unit can be different functional modules, and the transceiver unit is a general term for these functional modules.

[0041] Exemplarily, when the device is used to execute the method described in any one of the first to fifth aspects, the device may include a communication unit and a processing unit.

[0042] In the seventh aspect, an embodiment of the present application also provides a communication device, comprising a processor for executing a computer program (or computer executable instructions) stored in a memory, so that when the computer program (or computer executable instructions) is executed, the device executes the method described in any possible implementation of any aspect from the first to the fifth aspects.

[0043] In one possible implementation, the processor and the memory are integrated together;

[0044] In another possible implementation, the memory is located outside the communication device.

[0045] The communication device also includes a communication interface, which is used for the communication device to communicate with other devices, such as sending or receiving data and / or signals. Exemplarily, the communication interface can be a transceiver, circuit, bus, module or other type of communication interface.

[0046] In an eighth aspect, a computer-readable storage medium is provided, wherein the computer-readable storage medium is used to store a computer program or instruction, which, when executed, enables the method described in any possible implementation of any aspect from the first to the fifth aspect and the method shown in any possible implementation thereof to be implemented.

[0047] In a ninth aspect, a computer program product comprising instructions is provided, which, when executed on a computer, enables the method described in any possible implementation of any one of the first to fifth aspects to be implemented.

[0048] In the tenth aspect, an embodiment of the present application further provides a communication device for executing the method described in any possible implementation method of any one of the first to fifth aspects above.

[0049] In the eleventh aspect, a chip system is provided, which includes a logic circuit (or understood as, the chip system includes a processor, the processor may include a logic circuit, etc.), and may also include an input and output interface. The input and output interface can be used to input messages, and may also be used to output messages. The input and output interfaces may be the same interface, that is, the same interface can realize both the sending function and the receiving function; or, the input and output interface includes an input interface and an output interface, the input interface is used to realize the receiving function, that is, for receiving messages; the output interface is used to realize the sending function, that is, for sending messages. The logic circuit can be used to perform operations other than the sending and receiving functions in the method described in any possible implementation of any aspect of the first to fifth aspects above; the logic circuit can also be used to transmit messages to the input and output interface, or receive messages from other communication devices from the input and output interface. The chip system can be used to implement the method described in any possible implementation of any aspect of the first to fifth aspects above. The chip system can be composed of chips, or it can include chips and other discrete devices.

[0050] Optionally, the chip system may further include a memory, which may be used to store instructions, and the logic circuit may call the instructions stored in the memory to implement corresponding functions.

[0051] In a twelfth aspect, a communication method is provided, and the communication system may include the method implemented by the first communication device as shown in the first aspect and any possible implementation thereof and the method implemented by the fifth communication device as shown in the fifth aspect and any possible implementation thereof. Optionally, the method may also be included as shown in the second to fourth aspects and any possible implementation thereof.

[0052] In a thirteenth aspect, a communication system is provided, which may include a first communication device and a fifth communication device, and may optionally include at least one of a second communication device to a fourth communication device. Among them, the first communication device can be used to implement the method shown in the first aspect and any possible implementation thereof. The fifth communication device can be used to implement the method shown in the fifth aspect and any possible implementation thereof. The second communication device can be used to implement the method shown in the second aspect and any possible implementation thereof. The third communication device can be used to implement the method shown in the third aspect and any possible implementation thereof. The fourth communication device can be used to implement the method shown in the fourth aspect and any possible implementation thereof.

[0053] The technical effects brought about by the sixth to thirteenth aspects above can be found in the description of the beneficial effects of the corresponding implementation methods in the first aspect above, and will not be repeated here. BRIEF DESCRIPTION OF THE DRAWINGS

[0054] Figure 1 A schematic diagram of the architecture of a wireless communication system provided in an embodiment of the present application;

[0055] Figure 2 This is a schematic diagram of the authentication system under the service-oriented architecture;

[0056] Figure 3 A flow chart of a communication method provided in an embodiment of the present application;

[0057] Figure 4 A schematic diagram of a domain name verification process based on the ACME protocol provided in an embodiment of the present application;

[0058] Figure 5 A schematic diagram of an authentication system based on the ACME protocol provided in an embodiment of the present application;

[0059] Figure 6 A flowchart of another communication method provided in an embodiment of the present application;

[0060] Figure 7 A flowchart of another communication method provided in an embodiment of the present application;

[0061] Figure 8 A schematic diagram of the structure of a communication device provided in an embodiment of the present application;

[0062] Fig. 9 A schematic diagram of the structure of another communication device provided in an embodiment of the present application. DETAILED DESCRIPTION

[0063] The embodiment of the present application provides a communication method and device. The method and device are based on the same inventive concept. Since the method and device solve the problem in a similar principle, the implementation of the device and the method can refer to each other, and the repeated parts will not be repeated.

[0064] In order to enhance the flexibility and agility of network deployment, NFV technology is used in the core network of mobile networks to subdivide the functions of network elements into different network functions, and deploy them on the network platform in a virtualized form to achieve rapid deployment of network functions. In order to simplify the communication and access control between network elements, a service-oriented architecture is beginning to be adopted in 5G networks. Different network elements in the service-oriented architecture can use the hypertext transfer protocol secure (HTTPS) to send service requests and obtain services.

[0065] Figure 1 This is a schematic diagram of a network architecture based on a service-oriented architecture, which may include a service-oriented architecture in 5G and future mobile communication systems. Figure 1 The network architecture shown may include terminal equipment, access network equipment and core network equipment. The terminal equipment accesses the data network (DN) through the access network equipment and the core network equipment. Among them, the core network equipment includes a variety of NF network elements. For example, the NF network element in the service-oriented network architecture includes some or all of the following network elements: unified data management (UDM) network element, unified data repository (UDR) network element, network exposure function (NEF) network element (not shown in the figure), application function (AF) network element, policy control function (PCF) network element, access and mobility management function (AMF) network element, session management function (SMF) network element, user plane function (UPF) network element, network data analysis function (NWDAF) network element, NRF (not shown in the figure), location management function (LMF) network element (not shown in the figure). The description and function description of the above network elements can be referred to the 5G related protocols and will not be expanded here.

[0066] The access network equipment may be a radio access network (RAN) equipment. For example: a base station, an evolved NodeB (eNodeB), a transmission reception point (TRP), a next generation NodeB (gNB) in a 5G mobile communication system, a future mobile communication system such as the 6th generation (6G), an open access network (O-RAN or ORAN) mobile communication system or a next generation base station in a cloud radio access network (CRAN) mobile communication system, a base station in a future mobile communication system or an access node in a wireless fidelity (WiFi) system, etc.; it may also be a module or unit that completes part of the functions of a base station, for example, a centralized unit (CU) or a distributed unit (DU). The access network equipment may be a macro base station, a micro base station or an indoor station, a relay node or a donor node, etc. The access network device may also be an open access network (open RAN, O-RAN or ORAN), a cloud radio access network (cloud radio access network, CRAN), or a wireless fidelity (wireless fidelity, WiFi) system. The access network device may also be a communication system that integrates two or more of the above systems. The embodiments of the present application do not limit the specific technology and specific device form adopted by the wireless access network device.

[0067] Terminal devices can be user equipment (UE), mobile stations, mobile terminals, etc. Terminal devices can be widely used in various scenarios, such as device-to-device (D2D), vehicle to everything (V2X) communication, machine-type communication (MTC), Internet of Things (IOT), virtual reality, augmented reality, industrial control, autonomous driving, telemedicine, smart grid, smart furniture, smart office, smart wearable, smart transportation, smart city, etc. Terminal devices can be mobile phones, tablet computers, computers with wireless transceiver functions, wearable devices, vehicles, urban air vehicles (such as drones, helicopters, etc.), ships, robots, robotic arms, smart home devices, etc.

[0068] The access network equipment and terminal equipment can be fixed or movable. The access network equipment and terminal equipment can be deployed on land, including indoors or outdoors, handheld or vehicle-mounted; they can also be deployed on the water surface; they can also be deployed on airplanes, balloons and artificial satellites in the air. The embodiments of the present application do not limit the application scenarios of the access network equipment and terminal equipment.

[0069] It can be understood that the above network elements and communication equipment are examples of an implementation method of a 5G network under a service-oriented architecture. This application does not exclude the existence of network elements or devices with the above network element functions in 6G or newer wireless communication systems that have other names or other forms.

[0070] Figure 1 Nudr, Npcf, Namf, Nudm, Nsmf, Naf, and Nnwdaf are service interfaces provided by the above-mentioned UDR, PCF, AMF, UDM, SMF, AF, and NWDAF, respectively, and are used to call corresponding service operations. N1, N2, N3, N4, and N6 are interface serial numbers, and the meanings of these interface serial numbers are as follows:

[0071] 1) N1: The interface between the AMF network element and the terminal device, which can be used to transmit non-access stratum (NAS) signaling (such as QoS rules from the AMF network element) to the terminal device.

[0072] 2) N2: The interface between the AMF network element and the access network equipment, which can be used to transmit wireless bearer control information from the core network side to the access network equipment.

[0073] 3) N3: The interface between the access network equipment and the UPF network element, mainly used to transmit uplink and downlink user plane data between the access network equipment and the UPF network element.

[0074] 4) N4: The interface between the SMF network element and the UPF network element can be used to transmit information between the control plane and the user plane, including controlling the issuance of forwarding rules, QoS rules, traffic statistics rules, etc. for the user plane and reporting of information on the user plane.

[0075] 5) N6: Interface between UPF network element and DN, used to transfer uplink and downlink user data flows between UP network element F and DN.

[0076] It is understandable that the above network element or function can be a network element in a hardware device, a software function running on dedicated hardware, or a virtualized function instantiated on a platform (e.g., a cloud platform). As a possible implementation method, the above network element or function can be implemented by one device, or by multiple devices together, or can be a functional module in one device, which is not specifically limited in the embodiments of the present application.

[0077] In addition, each of the above NF network elements can also be referred to as NF for short. For example, the AMF network element can be referred to as AMF for short.

[0078] Understandably, Figure 1 This is an example of a 5G service-oriented network architecture. This application can also be applied to Figure 1 In service-oriented architectures other than 5G or future mobile networks (such as 6G), it is used to implement certificate issuance for NF network elements in service-oriented network architectures.

[0079] At present, in the authentication of NF network elements under the service-oriented architecture, it is necessary to issue a public key certificate to the NF network element through a CA, and the effectiveness scope of a general CA is limited, so different CAs need to be deployed in different networks. In addition, in the communication authority authentication process of the network function network element, it is necessary to verify the public key certificate of the network function network element based on the PKI technology, and implement the authentication result of the NF network element based on the verification result of the public key certificate. This authentication process requires the participation of many CAs, and there is a lot of CA deployment work. In addition, manual management of CA deployment is required, which increases costs and is prone to errors, causing security incidents, and needs to be optimized.

[0080] For example Figure 2As shown, a framework for issuing NF certificates under a service-oriented architecture. Wherein, network A and network B represent different networks, for example, network A and network B represent different public land mobile networks (PLMNs). Alternatively, network A and network B represent different security domains or operator networks. Currently, when an NF network element needs to obtain services from another NF network element, a transport layer security (TLS) link is first established between the two NF network elements. According to the requirements of the technical specification (TS) 33.310 of the third generation partnership project (3GPP) system architecture group 3 (SA3), two NF network elements need to perform mutual authentication when establishing a secure link. The basis of mutual authentication is an X.509 public key certificate based on a public key infrastructure (PKI). However, since different NF network elements may be located in different network domains, the authentication between NF network elements involves cross-domain authentication. Therefore, 3GPP SA3 introduces a cross-domain certificate issuance architecture. Different networks need to deploy subordinate certificate authorities (CA) in each other's domains to issue X.509 certificates to each other's NFs to achieve trust transfer.

[0081] Due to the large number of NF network elements in the 5G network, and in order to achieve mutual trust between the core network NFs of different operators, different operators need to deploy a large number of subordinate CAs in other operators' networks. For example, network A and network B can deploy interconnection CA, TLS server CA and TLS client CA respectively. Specifically, it includes providing cross-licensed intermediate root certificates for the secondary or tertiary CAs of other operators. The cross-authorized subordinate CA certificates include TLS client CA certificates and TLS server CA certificates. The clients that need to establish TLS connections authenticate each other based on TLS client CA certificates and TLS server CA certificates and establish TLS connections. Since an operator needs to establish an interconnection relationship with multiple operators, each operator needs to authorize dozens or hundreds of other operators to deploy subordinate CAs. Each operator also needs to maintain the operation and maintenance of dozens or hundreds of subordinate CAs, which makes the entire certificate management system extremely complicated and requires manual management of CA deployment, which not only increases costs, but is also prone to errors and causes security incidents. Therefore, it is necessary to propose a NF network element certificate issuance scheme suitable for the 5G service-oriented architecture.

[0082] The present application provides a network element verification method, which is used to provide a NF network element verification method suitable for a service-oriented architecture network. In this method, the domain name (domain name) of the NF network element is verified (or authenticated) based on the authentication device, and a domain name certificate is issued to indicate that the NF network element has passed the verification. Among them, the authentication device can authenticate the domain name of the NF network element based on the ACME protocol, so that an automated and efficient NF network element verification and certificate management mechanism can be implemented. ACME is a certificate management challenge solution formulated by the Internet Engineering Task Force (IETF). The domain name challenge schemes supported by the ACME protocol include hypertext transfer protocol (HTTP)-01 method and -01 method.

[0083] In the specific working mode of HTTP-01, when the ACME client initiates a domain name certificate application to the server, ACME needs to first verify the control of the ACME client over the domain name. The specific method is that the ACME server sends an instruction to the ACME client, requiring the ACME client to put the challenge data provided by the ACME server in the specified directory on the Internet server (web server) corresponding to the domain name controlled by it. After obtaining the challenge data, the ACME client will generate corresponding challenge verification information based on the challenge data and store it in the specified directory. After that, the ACME client will notify the ACME server to obtain the challenge verification information from the specified directory. After receiving the instruction, the ACME server first resolves the above domain name from the DNS server, obtains the IP address corresponding to the domain name, and then uses the IP address to access the corresponding Internet server and download the challenge verification information from the specified directory. The ACME server compares the downloaded verification information with the challenge verification data stored by itself. If they are consistent, it means that the verification is passed, and the ACME server modifies the corresponding certificate verification status to pass. After detecting that the domain name verification has passed, the ACME client sends a certificate signing request (CSR) to the ACME server. After receiving the request, ACME forwards the certificate signing request to the backend CA. The CA generates the corresponding domain name certificate based on the certificate application request and returns it to the ACME server. The ACME server places the above certificate in the corresponding directory on the ACME server, and the ACME client downloads the above certificate and deploys it to the corresponding Internet server for use.

[0084] Similarly, the DNS-01 challenge verification method is mainly that the ACME client puts the challenge verification information provided by the ACME server into the corresponding domain name record on the target DNS server and notifies the ACME server to obtain the challenge verification information. After the ACME server obtains the instruction that the challenge verification is ready, it obtains the record of the domain name from the DNS server corresponding to the above domain name through the DNS resolution service, extracts the corresponding challenge verification information from the record, and completes the challenge verification. The subsequent steps are similar to HTTP-01, including the ACME client sending the CSR, the ACME server forwarding the request to the CA and obtaining the corresponding domain name certificate, and finally the ACME client downloads the above certificate from the ACME server.

[0085] The following describes the network elements and devices used in the method provided by the present application. The method can be implemented by the NF network element to be verified and the authentication device.

[0086] The NF network element may be a NF to be verified in a service-oriented architecture network. Specifically, the NF network element may be a network element such as an AMF or an SMF.

[0087] The authentication device may be a device for verifying a domain name, and after the domain name of the NF network element passes the verification, the authentication device may issue a domain name certificate. For example, the authentication device may be a CA.

[0088] In some embodiments, the method may also be performed by one or more devices of an OAM, a certificate management function (CMF) network element, and a DNS server.

[0089] Among them, the OAM device can be an operation and maintenance network entity within the operator's network, which can be used to be responsible for the creation of NF network elements and / or CMF network elements, etc. For example, it can provide the initialization configuration of NF network elements and / or CMF network elements, and register domain names for NF network elements and / or CMF network elements.

[0090] The CMF network element can be used as a NF network element of the core network to provide a certificate management agent function. In some embodiments of the present application, the CMF can help the NF network element to perform domain name verification in some cases.

[0091] The DNS server can be used to implement the domain name registration function and the domain name and Internet Protocol (IP) address resolution function. In addition, when the domain name verification scheme based on the ACME protocol is adopted, the DNS server can help the authentication device to perform the domain name verification function based on the DNS-01 method, which will be described in conjunction with the embodiments below.

[0092] like Figure 3As shown, a network element verification method provided in an embodiment of the present application may include the following steps shown in S101 to S104:

[0093] S101: The NF network element obtains the domain name of the NF network element.

[0094] The domain name of the NF network element is explained below.

[0095] The domain name of the NF network element may be a name consisting of a string of characters separated by ".", which may be used to represent a device for communication. The domain name of the NF network element and the IP address of the NF may be registered in a DNS server, so that the DNS server supports resolution of the domain name and IP address of the NF network element.

[0096] In this application, the domain name of the NF network element can be used by the first authentication device to verify the identity of the NF network element. Therefore, based on S101, the NF network element can send the domain name of the NF network element to the first authentication device, so that the first authentication device can authenticate the identity of the NF network element. Specifically, the first authentication device can verify the identity of the NF network element based on the domain name.

[0097] Optionally, in this application, the OAM device may allocate a domain name for the NF network element, so in S101, the NF network element may obtain the domain name allocated by the OAM. In addition, the domain name of the NF network element may also be allocated by other devices, or may be stored in a local configuration such as a factory configuration of the NF network element.

[0098] Exemplarily, the NF network element may execute S101 after startup (such as instantiation) to request domain name verification, so as to obtain a domain name certificate after the domain name verification is passed, which is used as a trust certificate for communication between NFs. In addition, the NF network element may also execute S101 to initiate domain name verification when it needs to communicate with other NFs.

[0099] Optionally, the NF network element also obtains information of the first authentication device.

[0100] The information of the first authentication device is described below.

[0101] It can be understood that the information of the first authentication device in S101 can be used for the NF network element to send information or messages to the first authentication device. For example, the NF network element can send a domain name verification request to the first authentication device based on the information of the first authentication device. The information of the first authentication device may include the identification or address information of the first authentication device. The address information may include the domain name or IP address of the first authentication device, or may include a combination of an IP address and a port.

[0102] Optionally, the first authentication device may be deployed in the same network as the NF network element. In this application, the network may refer to a PLMN, a security domain, an operator network, etc., without specific limitation.

[0103] S102: The NF network element sends the domain name of the NF network element to the first authentication device, where the domain name of the NF network element is used to verify the NF network element.

[0104] Optionally, the NF network element may initiate domain name verification to the first authentication device based on the ACME protocol. The domain name verification method required by the ACME protocol will be described below in conjunction with an embodiment, which will not be expanded here.

[0105] As an example of S102, after the NF network element is started and / or before the NF network element communicates with other network elements, the NF network element can execute S102 to obtain the certificate required for communication.

[0106] S103: The first authentication device verifies the NF network element according to the domain name of the NF network element.

[0107] In S103, the verification of the NF network element by the first authentication device includes the identity verification of the NF network element, specifically, it can be the verification of the ownership or possession of the domain name provided by the NF network element.

[0108] The first authentication device can perform domain name verification on the NF network element based on the ACME protocol to implement the verification of the NF network element. As described above, based on the ACME protocol, the first authentication device can use HTTP-01 and / or DNS-01 to perform domain name verification. Figure 4 and Figure 5 The domain name verification method based on the ACME protocol is explained here, which is not expanded here.

[0109] S104: The NF network element obtains the first domain name certificate issued by the first authentication device.

[0110] In a possible embodiment of S104, the first authentication device may send the first domain name certificate to the NF network element according to the certificate issuance request of the NF network element. In another possible embodiment of S104, the first authentication device may submit (or publish) the first domain name certificate to the CA or ACME server, so in S104, the NF network element may obtain (e.g., download) the first domain name certificate from the CA or ACME server.

[0111] Exemplarily, the first domain name certificate may include the domain name of the NF network element. Later, when the NF network element needs to obtain services from the NF service provider (NF producer, NFp), or needs to communicate with other network elements, it can send a message carrying the first domain name certificate. The network element receiving the message can confirm that the NF network element has passed the verification based on the first domain name certificate, so that it can further communicate with the NF network element.

[0112] Based on the above Figure 3 According to the process shown, the NF network element under the service-oriented architecture can obtain its own domain name and the information of the first authentication device, and provide the domain name to the first authentication device according to the information of the first authentication device. The first authentication device can further verify the NF network element according to the domain name and issue a first domain name certificate. Accordingly, the NF network element can obtain the certificate issued by the first authentication device. Therefore, the present application provides a NF network element authentication method suitable for the server-oriented architecture, which can improve the efficient authentication and certificate issuance of the NF network element under the service-oriented architecture.

[0113] based on Figure 3 The process shown in the figure can also further improve the authentication reliability of the NF network element according to the type information of the NF network element in the present application.

[0114] In a possible embodiment, the domain name of the NF network element in the present application has a corresponding relationship with the type information of the NF network element and / or the identifier (ID) of the NF network element. Among them, the type information of the NF network element can be used to indicate the function or type of the NF network element. For example, when the type of the NF network element is AMF, the type information of the NF network element can be used to indicate that the NF network element is AMF. The type information of the NF network element can be "AMF", or it can be an index used to indicate that the type of the NF network element is AMF. In addition, the identifier of the NF network element can be a device identifier of the NF network element.

[0115] As an example of the above correspondence, the domain name of the NF network element may include the type information of the NF network element, that is, the type information of the NF network element may be used as part of its domain name. In addition, a domain name may be allocated to the NF network element according to the type information of the NF network element, and accordingly, the domain name may be used to identify the type information of the NF network element. For example, the domain name of the NF network element itself does not include the type information of the NF network element, but includes information corresponding to the type information.

[0116] Optionally, the domain name of the NF network element also has a corresponding relationship with the identifier (ID) of the NF network element. For example, the domain name of the NF network element includes the identifier of the NF network element.

[0117] As an example, the domain name of the AMF network element identified as "1234" can be "1234.AMF.aaa.bbb". "aaa" can be a specific business entity, such as the name or abbreviation of an operator, and "bbb" can represent the top-level domain name registered by the business entity, such as com or org, or a country domain name code, such as cn.

[0118] In this embodiment, optionally, the NF network element may also send the type information of the NF network element to the first authentication device, so that the first authentication device can verify the type information sent by the NF network element and the type information corresponding to the domain name of the NF network element. If the two types of information are consistent, S103 can be further executed, that is, the NF network element can be verified according to the domain name. Optionally, the domain name and type information of the NF network element can be carried in the same information or message sent by the NF network element to the first authentication device, or can be carried in different information or messages. For example, in S102, the NF network element can send the domain name and type information of the NF network element to the first authentication device, wherein the domain name has a corresponding relationship with the type information of the NF network element. Accordingly, before S103, the first authentication device can determine the corresponding type information according to the domain name provided by the NF network element, and verify the type information provided by the NF network element and the type information corresponding to the domain name, so as to verify whether the NF network element impersonates the domain name of other network elements or devices. Among them, the association between the domain name and type information of the NF network element may be known to the first authentication device. For example, the management device used to allocate the domain name of the NF network element may provide the corresponding relationship to the first authentication device, or the management device and the first authentication device may obtain the corresponding relationship based on the same configuration.

[0119] If the comparison result of the first authentication device is that the two types of information are consistent, it means that the domain name and the type information provided by the NF network element match, and the ownership of the domain name by the NF network element can be further verified. Otherwise, if the comparison result of the first authentication device is that the two types of information are inconsistent, it means that the domain name and the type information provided by the NF network element do not match, and there may be domain name impersonation. At this time, further verification is rejected, or it is determined that the NF network element has not passed the verification. In other words, the first authentication device can execute S103 when it is determined that the type information provided by the NF network element is consistent with the type information determined based on the domain name of the NF network element, thereby preventing the NF network element that impersonates the identity information of other network elements or devices from obtaining a domain name certificate. In the present application, the identity information may include one or more of the domain name, type information, or domain name certificate.

[0120] In addition, optionally, the first authentication device may add the type information of the NF network element in the extension domain and other fields of the first domain name certificate when issuing the first domain name certificate to indicate that the type information of the NF network element has passed the verification. In addition, the domain name included in the first domain name certificate may also be used to determine the verified type information of the NF network element, for example, the domain name of the NF network element in the first domain name certificate includes the type information, or the domain name of the NF network element in the first domain name certificate has a corresponding relationship with the type information.

[0121] In addition, in this embodiment, when the NF network element needs to communicate with other network elements (such as obtaining services from NFp), the NF network element can carry the first domain name certificate and type information in the communication request sent to other network elements, and the first domain name certificate can contain the domain name of NF. Among them, the domain name of the NF network element corresponds to the type information of the NF network element, and / or, the extended domain or other fields in the first domain name certificate contain type information. Accordingly, before establishing communication with the NF network element, other network elements can check the received first domain name certificate, and the content of the check may include: according to the type information provided by the NF network element in the communication request, compare or verify the type information determined according to the first domain name certificate. If the comparison result is inconsistent, the service request can be rejected, and there may be fraudulent use of the domain name certificate at this time; if the comparison result is consistent, the service request of the NF network element can be further processed, such as identifying whether the domain name certificate is legal. Among them, the type information determined according to the first domain name certificate can be specifically the type information corresponding to the domain name determined according to the domain name of the NF network element in the first domain name certificate, or it can be the type information contained in the extended domain and other fields of the first domain name certificate.

[0122] In addition, the type information corresponding to the domain name in the first domain name certificate can also be compared with the type information contained in the extension domain or other fields in the first domain name certificate to verify whether the first domain name certificate is forged, and further improve the reliability of communication. For example, if the type information corresponding to the domain name in the first domain name certificate is inconsistent with the type information carried in the extension domain of the first domain name certificate, it means that the first domain name certificate may be forged. At this time, the network element that receives the first domain name certificate can refuse to establish a connection with the NF network element that provides the first domain name certificate.

[0123] The following describes how the NF network element obtains the domain name of the NF network element.

[0124] As a possible way, the NF network element can obtain the domain name of the NF network element from the local configuration information. For example, before the NF network element is started, the NF network element creation and configuration device (or management device) can provide the NF network element with the domain name of the NF network element and / or the information of the first authentication device during the configuration process of the NF network element; for example, the domain name of the NF network element and / or the information of the first authentication device can be included in the initialization information configured by the NF network element creation and configuration device to the NF network element, and the NF network element can be configured according to the initialization information during the startup process. Among them, the initialization information can also include the type information and / or identification of the NF network element. In addition, the domain name of the NF network element and / or the information of the first authentication device can also be included in the local configuration information such as the factory configuration of the NF network element. The NF network element creation and configuration device can be, for example, an OAM device or an NRF network element, or can be other network elements or devices for providing NF network element creation and / or configuration functions.

[0125] Taking the OAM device as an example of a device for creating and configuring NF network elements, the OAM device can configure a domain name and an IP address for the NF network element according to the configuration policy of the NF network element after determining to start the NF network element. Among them, the OAM device can determine to start the NF network element according to the startup instruction of the NF network element, and the instruction can be sent by other network elements or devices, or can be triggered manually. Optionally, the startup instruction can include the type information and / or identification of the NF network element, so that the OAM device configures the domain name of the NF network element according to the type information and / or identification of the NF network element. The OAM device can send the domain name of the NF network element to the NF network element. In addition, the OAM device can also send a registration message to the DNS server, which includes the domain name and IP address of the NF network element, so that the domain name and IP address of the NF network element can be registered with the DNS server. In addition, the OAM device can also send a startup message to the NF network element to start the NF network element.

[0126] As another possible way, the NF network element may receive the domain name of the NF network element from a NF network element creation and configuration device such as an OAM device. For example, the NF network element may send a domain name request or a registration request to the OAM device after startup, or when there is a need to communicate with other NF network elements, and the OAM device may provide the NF network element with the domain name of the NF network element and / or the information of the first authentication device based on the request of the NF network element. Among them, the OAM device may configure the domain name and IP address of the NF network element after determining to start the NF network element, and / or after sending a startup message for starting the NF network element to the NF network element, and send the domain name and IP address to the NF network element. The OAM network element may also send the domain name of the NF network element to the NF network element after receiving a domain name request or a registration request from the NF network element, and / or send a registration message containing the domain name and IP address of the NF network element to the DNS server. It can be understood that the communication method between the NF network element and the NF network element creation and configuration device such as the OAM device does not fall within the scope of limitation of this application.

[0127] Optionally, the NF network element may also obtain type information from a creation and configuration device of the NF network element. For example, the type information may be included in the configuration information provided by the creation and configuration device of the NF network element to the NF network element, or the NF network element may receive the type information from the creation and configuration device of the NF network element. The type information of the NF network element may be carried in a system or a different message or information with the domain name of the NF network element.

[0128] It can be understood that, similar to the way in which the NF network element obtains the domain name, the NF network element can obtain the information of the first authentication device from the local configuration information, or receive the information of the first authentication device from the NF network element creation and configuration device such as the OAM device. If the NF network element obtains the domain name and the information of the first authentication device from the local configuration information, the domain name and the information of the first authentication device can both be configuration information in the factory configuration, and both are configuration information from the NF network element creation and configuration device, or, any one of the domain name and the information of the first authentication device can be configuration information in the factory configuration, and the other can be configuration information from the NF network element creation and configuration device. If the NF network element receives the domain name of the NF network element and the information of the first authentication device from the NF network element creation and configuration device, the domain name of the NF network element and the information of the first authentication device can come from the same device, such as both from the OAM device; in addition, the domain name of the NF network element and the information of the first authentication device can be carried in the same or different messages. For example, the OAM device can carry the domain name of the NF network element and the information of the first authentication device through the same message.

[0129] In addition, optionally, the NF network element may also obtain the root certificate and / or domain name verification method configuration and other information required for domain name verification of the first authentication device from the local configuration information. The root certificate can be used to verify the certificate provided by the first authentication device during the certificate application process, and the verification indicates that the first authentication device is a trusted entity. The domain name verification method configuration can be used to configure the challenge type for the NF network element to perform domain name verification, where the challenge type can be HTTP-01 method or DNS-01 method. Optionally, the root certificate and other information required for domain name verification of the first authentication device can be carried in the same local configuration information of the NF network element as the domain name of the NF network element and / or the information of the first authentication device.

[0130] Alternatively, the NF network element may also receive information required for domain name verification of the first authentication device, such as a root certificate and / or a domain name verification method configuration, from a creation and configuration device of the NF network element. Optionally, the root certificate and other information required for domain name verification of the first authentication device may be carried in the same configuration information or configuration message sent by the creation and configuration device of the NF network element to the NF network element together with the domain name of the NF network element and / or the information of the first authentication device. For example, the initialization information sent by the OAM device to the NF network element includes the domain name of the NF network element, the information of the first authentication device, and the root certificate and other information required for domain name verification of the first authentication device.

[0131] Combine the following Figure 4 and Figure 5 The verification process in S103 is described.

[0132] like Figure 4As shown in FIG. 1 , the domain name verification process based on the ACME protocol can be performed by the ACME client and the ACME server. Figure 5 As shown, the ACME client can be deployed in the NF network element, for example, the ACME client can be a functional module in the NF network element. The ACME server can be deployed in the authentication device, for example, the ACME server can be a functional module in the authentication device.

[0133] like Figure 4 As shown, the domain name verification based on the ACME protocol can be initiated by the NF network element. For example, in S102, the NF network element can request domain name verification based on the following process after startup: obtain a public-private key pair according to the root certificate, and send an account registration request to the ACME server to register the public-private key pair and the account. Among them, the public-private key pair can be used for encrypted communication between the ACME client and the ACME server. The account can be used to manage metadata related to domain name verification. After completing the registration, the ACME client can apply to the ACME server to create a certificate order, such as sending a verification request containing a domain name. The ACME server can send a token and a challenge type supported by the domain name to the ACME client in response to the verification request. Among them, the challenge type may include HTTP-01 and / or DNS-01. Thereafter, the ACME client can select the challenge type and deploy key authorization. The ACME client can also write a challenge response to the device, function or service request corresponding to the challenge type according to the selected challenge type. Among them, the challenge response can be generated based on the challenge information provided by the ACME server, and the challenge information can be a random number generated by the ACME server, and the ACME client can download the random number from the server. The challenge response can be generated by concatenating the random number provided by the ACME server and the account public key of the ACME client, as well as a challenge verification method such as HTTP-01, into a string of characters and inputting the string into a hash function to obtain a hash value, which is used as the challenge response.

[0134] Among them, if the challenge type selected by the ACME client is HTTP-01 challenge, the function or service corresponding to the challenge type may include an Internet (web) server. In this application, the web server can be a functional module in the NF network element. Among them, the web server in the ACME client can be used to provide domain name verification based on HTTP-01 challenge. Specifically, the ACME client can request the web server to write a challenge response in a specified directory and return the above challenge response content to the ACME server through the HTTPS protocol when receiving an access request from the ACME server. The ACME server can verify whether the challenge response returned through the HTTPS protocol is consistent with the challenge response generated based on a random number to verify whether the challenge is passed.

[0135] In addition, if the challenge type selected by the ACME client is a DNS-01 challenge, the device corresponding to the challenge type may be a DNS server. In the present application, the ACME client may be used to request that a challenge response (herein referred to as a DNS challenge response) be written to a DNS server. Specifically, the DNS challenge response may be written into the record of the NF network element domain name in the DNS server, that is, the DNS server may write the DNS challenge response into the record of the corresponding domain name according to the domain name of the NF network element.

[0136] Optionally, in the process of the ACME client requesting the DNS server to write the DNS challenge response into the record of the NF network element domain name, the NF network element may send a DNS challenge response to the second device to request the second device to write the DNS challenge response into the record of the NF network element domain name in the DNS server. Accordingly, the ACME server may be used to read the DNS challenge response from the record related to the domain name to be verified in the DNS server after receiving the notification sent by the ACME client indicating that the DNS challenge response has been written into the DNS server. If the DNS challenge response and the characteristic information are verified, it can be determined that the NF network element has passed the verification. Among them, the verification method is, for example, linking the corresponding random number stored on the ACME server with the key of the ACME client and the challenge verification method DNS-01 mentioned above and inputting them into a hash function to obtain a hash value, and then verifying the hash value with the DNS challenge response extracted from the DNS record. If the verification result is that the hash value DNS challenge response is the same, the ACME server determines that the NF network element has passed the verification. If the verification result is that the hash value DNS challenge response is different, the ACME server determines that the verification has failed.

[0137] Exemplarily, the second device may be a DNS challenge response writing device, used to write the DNS challenge response of the NF to be verified to the DNS server. The second device may specifically be an OAM device or an NRF. The second device may have the authority to modify the domain name record of the DNS server, and may be used to filter illegal DNS notification message write requests.

[0138] For example, when the NF network element requests the second device to modify the domain name in the DNS server, the second device only supports modifying the record associated with the domain name of the NF network element. Among them, the second device can obtain and store the domain name of the NF network element during the connection establishment process with the NF network element, for example, store the association relationship between the domain name of the NF network element and the connection information (such as tunnel information). When the second device receives the DNS challenge response from the NF network element, it can query the domain name of the NF network element according to the connection information of the received DNS challenge response to determine the domain name of the NF network element, and modify the record with the corresponding domain name in the DNS server, so as to write the DNS challenge response to the record of the corresponding domain name in the DNS server. Therefore, the second device can only request the DNS server to write the DNS challenge response to the record corresponding to the domain name of the NF network element, which can avoid the NF network element from providing a false domain name when requesting the second device to write the DNS challenge response. That is to say, even if the NF network element provides a false domain name when requesting to write the DNS challenge response, the second device can refuse to modify the domain name record of the DNS server when determining that the domain name of the NF network element is inconsistent with the false domain name when establishing a connection with the NF network element, thereby avoiding the network security risks caused by the impersonation of the domain name. In addition, if the ACME server determines that the HTTP-01 challenge passes or the DNS-01 challenge passes, information indicating that the verification passes may be provided to the ACME client.

[0139] Optionally, the ACME client may send a CSR to the ACME server after receiving information from the ACME server indicating that the verification is successful. Accordingly, the ACME server may request the CA module of the first authentication device to issue a first domain name certificate in response to the CSR. The first domain name certificate may indicate that the verification of the NF network element is successful, that is, the NF network element obtains communication authority.

[0140] It can be understood that the communication authority of the NF network element represented by the first domain name certificate is related to the effective scope or authority scope of the first authentication device. For example, if the first authentication device only has the authority to verify the NF network element in the network where the authentication device is located, then correspondingly, the first domain name certificate only indicates that the NF network element obtains communication authority within the network. Among them, the first authentication device and the NF network element can belong to the same or different networks. For another example, if the first authentication device has the authority to verify the NF network elements of multiple networks, the first domain name certificate can indicate the authority of the NF network element to communicate between multiple networks.

[0141] It can also be understood that the above actions performed by the ACME client can be replaced by being performed by the NF network element, and the above actions performed by the ACME server can be replaced by being performed by the first authentication device.

[0142] In one embodiment of the present application, if the OAM device is used as a management device for providing a domain name to the NF network element, a network element verification method provided in the embodiment of the present application may include: Figure 6 Steps shown:

[0143] S201: After obtaining the startup instruction of the NF network element, the OAM device allocates a domain name and an IP address to the NF network element according to the domain name generation strategy. The OAM device can generate a domain name according to the domain name generation strategy, the type information and the identifier of the NF network element.

[0144] Among them, the NF network element startup instruction can be used to trigger the OAM device configuration and / or start the NF network element. The NF network element startup can include the type information and / or identification of the NF network element. The NF network element startup instruction can be manually triggered on the OAM device, or it can be triggered by other network elements or control devices to the OAM device.

[0145] In addition, S201 can also be replaced by: after obtaining the NF startup instruction, the OAM device provides the type information and identification of the NF network element to the domain name issuance function. At this time, the domain name issuance function can generate a domain name according to the domain name generation strategy, the type information and identification of the NF network element. For example, the domain name may include the identification and type information of the NF network element. The domain name issuance function can also provide the domain name of the NF network element to OAM. Optionally, the domain name issuance function can be a part of the OAM device, for example, the domain name issuance function is a functional module deployed in the OAM device. In addition, the domain name issuance function can also be an entity independent of the OAM device. At this time, the domain name issuance function as an entity can have a communication interface with the OAM device.

[0146] S202: The OAM device sends a registration message to the DNS server to register the domain name and IP address of the NF network element with the DNS server. The registration message may include the domain name and IP address of the NF network element.

[0147] S203: The OAM device sends initialization information to the NF network element before starting the NF network element, which includes the domain name, IP address, information of the first authentication device, and the root certificate of the first authentication device of the NF network element. The initialization information may also include type information and / or identification of the NF network element. The initialization information may also include configuration information for performing ACME protocol-based authentication, such as HTTP-01 and / or DNS-01 challenge related information.

[0148] The first authentication device may deploy an ACME server, and the first authentication server may be a CA or other network element or device.

[0149] It can be understood that the step in S203 where the OAM device provides the domain name to the NF network element can be considered as an example of an implementation of S101.

[0150] S204: Optionally, the OAM starts the NF network element.

[0151] S205: After the NF network element is started, it obtains the domain name, IP address, address of the first authentication device and root certificate of the NF network element from the initialization information.

[0152] S206: The NF network element starts the ACME client.

[0153] Optionally, the NF network element may also start a web server. Alternatively, the NF network element may start the web server after deciding to adopt the HTTP-01 challenge.

[0154] S207: The ACME client of the NF network element requests the ACME server of the first authentication device to create an ACME account according to the configuration information.

[0155] S208: The ACME client of the NF network element requests the ACME server to create a certificate order for initiating a challenge verification based on the ACME protocol. The challenge verification process can be referred to Figure 4 .

[0156] It can be understood that in the challenge based on the ACME protocol, the NF network element can send the domain name of the NF network element to the first authentication device. For example, the domain name can be included in the request for the certificate order. This action can be considered as an example of an implementation of S102. In addition, the challenge based on the ACME protocol can be considered as an example of an implementation of S103.

[0157] Figure 6 The DNS-01 challenge is used as an example to illustrate.

[0158] Optionally, if the DNS-01 method is used for domain name challenge, the NF network element may request the second device to write the DNS challenge response to the DNS server. For example, in S209, the NF network element may send the DNS challenge response to the second device. It is understandable that Figure 6 The second device is described as an OAM identification as an example, which should not be construed as being limited to this. Optionally, the second device may send the domain name of the NF network element to the DNS server.

[0159] S210: The second device may determine the domain name of the NF network element according to the connection information of the received DNS challenge response.

[0160] Among them, the second device can obtain and store the domain name of the NF network element during the process of establishing a connection with the NF network element. Therefore, after receiving the DNS challenge response through the connection, the second device can determine the domain name of the NF network element according to the connection information of the connection receiving the DNS challenge response, and modify the DNS challenge response to the domain name record in the DNS server according to the domain name. Therefore, even if the NF network element impersonates other domain names and requests the second device to modify the record of the impersonated domain name, the second device can refuse to modify the domain name record of the DNS server when it determines that the domain name of the NF network element is inconsistent with the impersonated domain name when the second device establishes a connection with the NF network element, thereby avoiding network security risks caused by the impersonated domain name.

[0161] S211: The second device sends a DNS challenge response to the DNS server. The DNS challenge response may be generated by the ACME client of the NF network element according to the DNS challenge information obtained from the ACME server. Optionally, the second device may provide the domain name of the NF network element to the DNS server for the DNS server to modify the record of the domain name.

[0162] S212: The DNS server writes the DNS challenge response into the record of the domain name of the NF network element in the DNS server.

[0163] S213: The DNS server indicates to the second device that the modification of the domain name record of the DNS server is completed, such as sending an indication of the completion of the modification of the domain name record.

[0164] S214: The second device indicates to the ACME client of the NF network element that the modification of the domain name record of the DNS server is completed.

[0165] S215: The ACME client of the NF network element sends a message to the ACME server indicating that the modification of the domain name record of the DNS server is complete.

[0166] S216: The ACME server obtains the DNS challenge response from the domain name record of the NF network element in the DNS server. Subsequent verification can be performed based on the DNS challenge response and DNS challenge information, as shown in Figure 4 Instructions in .

[0167] S217: If the ACME server determines that the DNS challenge response obtained from the DNS server matches the DNS feature information provided to the ACME client, it confirms that the DNS-01 challenge is passed.

[0168] S218: If the ACME server determines that the DNS-01 challenge is passed, the ACME client is provided with information indicating that the verification is passed. Alternatively, the ACME client may send an access request to the ACME server, and the ACME server may provide the ACME client with information indicating that the verification is passed based on the access request.

[0169] S219: The ACME client sends the CSR to the ACME server.

[0170] S220: The ACME server provides the first domain name certificate to the ACME client.

[0171] S220 may be considered as an example of an implementation of S104. For example, in S220, the ACME server may store the issued first domain name certificate in a designated directory of the ACME server, and the ACME client may download the first domain name certificate from the designated directory.

[0172] Understandably, the above Figure 6 In the process shown, the ACME client refers to the ACME client deployed in the NF network element, and the ACME server refers to the ACME server deployed in the first authentication device.

[0173] In a possible embodiment of the present application, when the NF network element has not yet obtained a certificate supporting communication with network elements or devices in other networks other than the network (such as the first network) where the NF network element is located, the NF network element can obtain the certificate from an authentication device in other networks (such as the second network) through a CMF network element. It can be understood that the first network and the second network can be different PLMNs or operator networks, respectively. For the convenience of explanation, the authentication device in the second network can be referred to as a second authentication device.

[0174] It is understandable that the second authentication device can be understood as belonging to a different network from the NF network element. For example, the first authentication device and the second authentication device are authentication devices deployed in different networks.

[0175] In this embodiment, the NF network element may send a domain name certificate acquisition request to the CMF network element. The domain name certificate acquisition request may be used to request a certificate of the NF network element issued by the second authentication device. The domain name certificate acquisition request may include the domain name of the NF network element.

[0176] Optionally, the domain name certificate acquisition request may also include information about a second authentication device. The information about the second authentication device may include, for example, identification or address information of the second authentication device. The information about the second authentication device may be provided by the management device to the NF network element, for example, with reference to the manner in which the information about the first authentication device is provided. In addition, the information about the second authentication device may also be configured in the CMF network element, for example, the management device provides the information about the second authentication device to the CMF network element, in which case the NF network element may not need to obtain and provide the information about the second authentication device to the CMF network element.

[0177] Correspondingly, after receiving the domain name certificate acquisition request, the CMF network element can send the domain name of the NF network element to the second authentication device to trigger the second authentication device to verify the NF network element. For example, referring to the ACME protocol, the CMF network element can apply to the second authentication device to create a certificate order, such as sending a verification request containing the domain name.

[0178] Among them, the second authentication network element can adopt a domain name verification method based on the ACME protocol to perform verification according to the domain name of the NF network element. For example, the verification method of the second authentication device can refer to the instructions of the first authentication network element to verify the NF network element according to the domain name. After determining that the domain name of the NF network element passes the HTTP-01 challenge or DNS-01 challenge, the second authentication device determines that the NF network element has passed the authentication. Among them, the CMF network element can obtain the modification authority of the domain name record of the web server or DNS server. Therefore, during the HTTP-01 challenge process, the CMF network element can write the challenge response to the web server; during the DNS-01 challenge process, the CMF network element can write the DNS challenge response to the DNS server. The verification process of the second authentication network element can refer to Figure 7 Introduction in the process shown.

[0179] Optionally, the communication between NF and CMF can be carried out based on the first domain name certificate issued by the first authentication device to the NF network element. In other words, the NF network element may need to establish communication with the CMF network element based on the first domain name certificate before sending a domain name certificate acquisition request to the CMF. The CMF network element can determine that the NF network element has passed the verification of the first authentication device based on the first domain name certificate, or determine that the NF network element obtains communication authority based on the first domain name certificate. For example, the CMF network element can parse the first domain name certificate, obtain the domain name of the NF network element, and compare it with the domain name provided by the NF network element to determine whether the NF network element has impersonated the domain name certificate of other network elements, thereby avoiding providing the certificate issued by the second authentication device to the NF network element that impersonated the domain name certificate of other network elements.

[0180] If the CMF network element determines that the first domain name certificate has passed the authentication, that is, the first domain name certificate of the NF network element is a qualified domain name certificate, an indication (such as referred to as a first indication) indicating that the first domain name certificate has passed the authentication can be sent to the NF network element. The function of the first indication can also be described as: used to indicate that the NF network element is allowed to request a domain name certificate issued by a second authentication device.

[0181] In addition, when the domain name of the NF network element contains the type information of the NF network element, or the domain name of the NF network element has a corresponding relationship with the type information of the NF network element, the CMF network element can also determine the type information of the NG network element based on the first domain name certificate, and compare whether the type information determined according to the first domain name certificate is consistent with the type information provided by the NF network element in the connection request. The CMF network element can establish a connection with the NF network element and / or send a first indication only when the type information determined according to the first domain name certificate is consistent with the type information provided by the NF network element. If the type information determined by the first domain name certificate is inconsistent with the type information provided by the NF network element, the CMF network element can refuse to establish a connection with the NF network element, so that the NF network element cannot obtain the domain name certificate issued by the second authentication device, thereby preventing the NF network element that impersonates the identity information of other network elements from obtaining the certificate issued by the second authentication device.

[0182] Among them, the CMF network element can obtain the authority to communicate with the NF network element. For example, the CMF and the NF network element can be located in the same network, and the CMF can obtain a domain name certificate (for example, called a third domain name certificate) issued by the first authentication device to indicate that the CMF has passed the verification.

[0183] In addition, the CMF network element can also obtain the authority to communicate with the network element in the second network (such as including the second authentication device). For example, the CMF network element can also obtain a domain name certificate (such as a fourth domain name certificate) issued by the second authentication device, that is, the certificate can be used for the CMF to communicate with the network element in the second network. For another example, the CMF network element is configured to have the authority to communicate with the second authentication device, such as a connection has been established between the CMF network element and the second authentication device.

[0184] As an example, the CMF network element may be deployed with an ACME client, for example, the ACME client is an internal module of the CMF network element. Accordingly, the second authentication device may be deployed with an ACME server for performing domain name authentication based on the ACME protocol with the ACME client of the CMF network element (or other network elements). In addition, a web server may be deployed in the CMF network element to support challenges based on HTTP-01.

[0185] Optionally, the CMF network element may also deploy a certificate proxy module, and accordingly, the NF network element may deploy a certificate proxy module. The certificate proxy module of the NF network element may be used to request the certificate proxy module of the CMF network element to obtain the domain name certificate issued by the second authentication device. For example, the certificate proxy module of the NF network element may be used to send a domain name certificate acquisition request to the certificate proxy module of the CMF network element. In addition, the first indication and / or the second domain name certificate may also be transmitted between the certificate proxy module of the NF network element and the certificate proxy module of the CMF network element.

[0186] like Figure 7 As shown, when the NF network element requests the domain name certificate issued by the second authentication device through the CMF network element, the process may include the following steps:

[0187] S301: The NF network element sends the first domain name certificate of the NF network element to the CMF network element to request to establish a TLS connection with the CMF.

[0188] The first domain name certificate can be used to indicate that the NF network element has passed the verification of the first authentication device. The first domain name certificate can include the domain name of the NF network element.

[0189] It is understandable that before S301, NF network elements can refer to Figure 6 The process shown is to obtain the first domain name certificate.

[0190] S302: The CMF network element determines whether the first domain name certificate meets the requirements.

[0191] For example, the NF network element may provide a domain name to the CMF network element in S301, and the CMF network element may determine whether the domain name contained in the first domain name certificate is consistent with the domain name provided by the NF network element. If they are consistent, subsequent steps may be executed.

[0192] For example, the NF network element can also provide type information to the CMF network element in S301. In S302, the CMF network element can verify whether the type information provided by the NF network element is consistent with the type information determined according to the domain name in the first domain name certificate (or the type information contained in the first domain name certificate). If they are consistent, subsequent steps can be executed.

[0193] In addition, the CMF network element can also compare whether the type information corresponding to the domain name in the first domain name certificate is consistent with the type information contained in the extended domain and other fields in the first domain name certificate. If they are consistent, the subsequent steps can be executed.

[0194] S303: Optionally, the CMF network element may determine whether the NF network element has the authority to obtain the certificate issued by the second authentication device.

[0195] For example, the management device or NRF network element may provide permission configuration to the CMF network element. The permission configuration may be used to indicate the type information and / or identification of the NF network element that is allowed and / or not allowed to obtain the certificate issued by the second authentication device. If the NF network element does not belong to the NF network element that is not allowed to obtain the certificate issued by the second authentication device, S304 may be executed.

[0196] S304: The CMF network element sends a first indication to the NF network element indicating that the first domain name certificate authentication has passed.

[0197] S305: The NF network element sends a domain name certificate acquisition request to the CMF network element, which includes the domain name of the NF network element.

[0198] S306: The ACME client of the CMF network element requests the ACME server of the second authentication device to create a certificate order for initiating a domain name challenge verification based on the ACME protocol, wherein the ACME client needs to send the domain name of the NF network element to the ACME server to implement a challenge verification of the domain name.

[0199] It is understood that the process of domain name challenge initiated by CMF can refer to Figure 4 The difference is that the domain name to be verified is not the domain name of the CMF network element itself, but the domain name of the NF network element. In addition, the CMF network element can obtain the modification authority of the domain name record of the web server or DNS server. Therefore, in the domain name challenge, the CMF network element can modify the domain name record of the NF network element through the web server or DNS server.

[0200] S307: After determining that the domain name of the NF network element has passed the verification, the ACME server of the second authentication device sends information indicating that the verification has passed to the CMF network element, so as to indicate that the NF network element has passed the verification of the second authentication device.

[0201] S308: The ACME client of the CMF network element sends a CSR to the ACME server of the second authentication device to request the second authentication device to issue a second domain name certificate of the NF network element.

[0202] S309: The ACME client of the CMF network element obtains the second domain name certificate provided by the second authentication device.

[0203] For example, in S309, the ACME server in the second authentication device may store the issued first domain name certificate in a designated directory of the ACME server, and the ACME client downloads the first domain name certificate from the designated directory.

[0204] S310: The CMF network element sends the second domain name certificate to the NF network element.

[0205] For example, the CMF network element sends the second domain name certificate to the NF network element through the certificate proxy module.

[0206] based on Figure 7 In the process shown, the NF network element can request the second domain name certificate from the second authentication device through the CMF network element. The second authentication device can be deployed in a different network from the NF network element. At this time, the second domain name certificate can represent the NF network element to obtain communication rights in other networks outside the network, thereby providing security authentication for cross-network communication of the NF network element.

[0207] Based on the various embodiments shown in the present application, the trusted authentication of the NF network element is performed based on the domain name of the NF network element. There is no need to allocate a public key certificate for the NF network element in advance, and there is no need to deploy a complex CA authentication system to verify the public key certificate of the NF network element. A relatively simple authentication system deployment can be achieved under a service-oriented architecture, and a more efficient certificate issuance mechanism can be provided.

[0208] It is understandable that, in order to implement the functions in the above embodiments, the base station and the terminal include hardware structures and / or software modules corresponding to the execution of each function. It should be easily appreciated by those skilled in the art that, in combination with the units and method steps of each example described in the embodiments disclosed in this application, the present application can be implemented in the form of hardware or a combination of hardware and computer software. Whether a function is executed in the form of hardware or computer software driving hardware depends on the specific application scenario and design constraints of the technical solution.

[0209] Figure 8 and Fig. 9 A schematic diagram of the structure of a possible communication device provided for an embodiment of the present application. These communication devices can be used to implement the functions of the terminal device or base station in the above method embodiment, and thus can also achieve the beneficial effects possessed by the above method embodiment. In an embodiment of the present application, the communication device can be a NF network element, a management device, a first authentication device, a second device or a CMF network element, and can also be a component applied to the above modules or network elements, such as a functional module or a chip.

[0210] like Figure 8 As shown, the communication device 800 includes a processing unit 810 and a transceiver unit 820. The communication device 800 is used to implement the above Figure 3 , Figure 6 or Figure 7 The functions of the NF network element, management device, first authentication device, second device or CMF network element in the method embodiment shown in .

[0211] When the communication device 800 is used to implement Figure 3The functions of the NF network element in the method embodiment shown are: the processing unit 810 can be used to obtain the domain name of the NG network element. The transceiver unit 820 can be used to send the domain name of the NF network element to the first authentication device and obtain the first domain name certificate issued by the first authentication device.

[0212] When the communication device 800 is used to implement Figure 3 The function of the first authentication device in the method embodiment shown is: the transceiver unit 820 can be used to receive the domain name of the NF network element. The processing unit 810 can be used to verify the NF network element according to the domain name of the NF network element and issue a first domain name certificate.

[0213] For more detailed description of the processing unit 810 and the transceiver unit 820, please refer to Figure 3 The method embodiment shown is described in detail.

[0214] like Fig. 9 As shown, the communication device 900 includes a processor 910 and an interface circuit 920. The processor 910 and the interface circuit 920 are coupled to each other. It is understood that the interface circuit 920 can be a transceiver or an input / output interface. Optionally, the communication device 900 can also include a memory 930 for storing instructions executed by the processor 910 or storing input data required by the processor 910 to execute instructions or storing data generated after the processor 910 executes instructions. When the communication device 900 is used to implement Figure 4 When the method is shown, the processor 910 is used to implement the function of the above-mentioned processing unit 810, and the interface circuit 920 is used to implement the function of the above-mentioned transceiver unit 820.

[0215] When the above-mentioned communication device is a chip applied to a NF network element, a management device, a first authentication device, a second device or a CMF network element, the chip implements the functions of the NF network element, the management device, the first authentication device, the second device or the CMF network element in the above-mentioned method embodiment. The chip can receive information sent by other network elements or devices to the NF network element, the management device, the first authentication device, the second device or the CMF network element through other modules (such as communication interfaces) in the NF network element, the management device, the first authentication device, the second device or the CMF network element, or the chip sends information to other modules (such as communication interfaces) in the NF network element, the management device, the first authentication device, the second device or the CMF network element. Among them, the information is sent by the NF network element, the management device, the first authentication device, the second device or the CMF network element to other network elements or devices.

[0216] It is understood that the processor in the embodiments of the present application may be a central processing unit (CPU), or other general-purpose processors, digital signal processors (DSP), application specific integrated circuits (ASIC), field programmable gate arrays (FPGA) or other programmable logic devices, transistor logic devices, hardware components or any combination thereof. The general-purpose processor may be a microprocessor or any conventional processor.

[0217] The method steps in the embodiments of the present application can be implemented in hardware or in software instructions that can be executed by a processor. The software instructions can be composed of corresponding software modules, and the software modules can be stored in random access memory, flash memory, read-only memory, programmable read-only memory, erasable programmable read-only memory, electrically erasable programmable read-only memory, registers, hard disks, mobile hard disks, CD-ROMs, or any other form of storage medium known in the art. An exemplary storage medium is coupled to the processor so that the processor can read information from the storage medium and write information to the storage medium. The storage medium can also be a component of the processor. The processor and the storage medium can be located in an ASIC. In addition, the ASIC can be located in a NF network element, a management device, a first authentication device, a second device, or a CMF network element. The processor and the storage medium can also exist as discrete components in a NF network element, a management device, a first authentication device, a second device, or a CMF network element.

[0218] An embodiment of the present application also provides a communication system, including one or more network elements or devices in a NF network element, a management device, a first authentication device, a second device or a CMF network element for implementing the above-mentioned method embodiment.

[0219] An embodiment of the present application also provides a computer-readable storage medium, which is used to store computer programs or instructions. When the computer-readable storage medium is executed, the method shown in the above method embodiment is implemented.

[0220] The embodiment of the present application also provides a computer program product, which, when executed on a computer, enables the method shown in the method embodiment to be implemented.

[0221] In the above embodiments, it can be implemented in whole or in part by software, hardware, firmware or any combination thereof. When implemented by software, it can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer programs or instructions. When the computer program or instruction is loaded and executed on a computer, the process or function described in the embodiment of the present application is executed in whole or in part. The computer may be a general-purpose computer, a special-purpose computer, a computer network, a network device, a user device or other programmable device. The computer program or instruction may be stored in a computer-readable storage medium, or transmitted from one computer-readable storage medium to another computer-readable storage medium, for example, the computer program or instruction may be transmitted from one website site, computer, server or data center to another website site, computer, server or data center by wired or wireless means. The computer-readable storage medium may be any available medium that a computer can access or a data storage device such as a server, data center, etc. that integrates one or more available media. The available medium may be a magnetic medium, for example, a floppy disk, a hard disk, a tape; it may also be an optical medium, for example, a digital video disc; it may also be a semiconductor medium, for example, a solid-state hard disk. The computer-readable storage medium may be a volatile or nonvolatile storage medium, or may include both volatile and nonvolatile types of storage media.

[0222] In the various embodiments of the present application, unless otherwise specified or provided for in any logical conflict, the terms and / or descriptions between the different embodiments are consistent and may be referenced to each other, and the technical features in the different embodiments may be combined to form new embodiments according to their inherent logical relationships.

[0223] In the present application, "at least one" means one or more, and "more than one" means two or more. "And / or" describes the association relationship of associated objects, indicating that three relationships may exist. For example, A and / or B can mean: A exists alone, A and B exist at the same time, and B exists alone, where A and B can be singular or plural. In the text description of the present application, the character " / " generally indicates that the previous and next associated objects are in an "or" relationship; in the formula of the present application, the character " / " indicates that the previous and next associated objects are in a "division" relationship. "Including at least one of A, B and C" can mean: including A; including B; including C; including A and B; including A and C; including B and C; including A, B and C.

[0224] It is understood that the various numbers involved in the embodiments of the present application are only for the convenience of description and are not used to limit the scope of the embodiments of the present application. The size of the sequence number of the above-mentioned processes does not mean the order of execution, and the execution order of each process should be determined by its function and internal logic.

Claims

1. A network element verification method, characterized in that: include: The network function network element obtains the domain name of the network function network element, and the network function network element is a network element in the service-oriented architecture network; The network function network element sends the domain name of the network function network element to the first authentication device, where the domain name of the network function network element is used to verify the network function network element; The network function network element obtains a first domain name certificate issued by the first authentication device, and the first domain name certificate is used to indicate that the verification is passed.

2. The method according to claim 1, characterized in that The verification is based on the automated certificate management environment ACME protocol.

3. The method according to claim 1 or 2, characterized in that The domain name of the network function network element is determined according to the type information of the network function network element.

4. The method according to any one of claims 1 to 3, characterized in that: The method further comprises: The network function network element sends type information of the network function network element to the first authentication device, where the type information of the network function network element is used to compare type information corresponding to the domain name of the network function network element.

5. The method according to any one of claims 1 to 4, characterized in that: The method further comprises: The network function network element receives domain name service DNS challenge information from the first authentication server; The network function network element generates a DNS challenge response according to the DNS challenge information; The network function network element requests the second device to write the DNS challenge response into the domain name record of the network function network element in the DNS server; The network function network element receives a domain name record modification completion indication from the second device; The network function network element notifies the first authentication device to obtain the DNS challenge response from the DNS server, where the DNS challenge response and the DNS challenge information are used to verify the network function network element; The network function network element receives information indicating that the verification is successful from the first authentication device.

6. The method according to claim 5, characterized in that The method further comprises: The second device receives a DNS challenge response from the network function network element; The second device determines the domain name of the network function network element according to the connection information between the second device and the network function network element; The second device writes the DNS challenge response into the domain name record of the network function network element in the DNS server according to the domain name of the network function network element.

7. The method according to claim 4 or 5, characterized in that The method further comprises: The first authentication device obtains the DNS challenge response from the DNS server; The first authentication device verifies the network function network element according to the DNS challenge response and the DNS challenge information; In the case where the verification is successful, the first authentication device provides the information indicating that the verification is successful to the network function network element.

8. The method according to any one of claims 1 to 7, characterized in that: The first authentication device is deployed in a first network, and the first domain name certificate is specifically used for the network function network element to communicate with the network element in the first network.

9. The method according to claim 8, characterized in that The method further comprises: The network function network element sends a domain name certificate acquisition request to the certificate management network element in the first network according to the first domain name certificate, wherein the domain name certificate acquisition request is used to request a certificate of the network function network element issued by a second authentication device in the second network, and the domain name certificate acquisition request includes the domain name of the network function network element; The network function network element receives a second domain name certificate from the certificate management network element, where the second domain name certificate is issued by the second authentication device.

10. The method according to claim 9, characterized in that The second domain name certificate is used for the network function network element to communicate with the network elements in the second network.

11. The method according to claim 9 or 10, characterized in that The method further comprises: The network function network element receives the information of the second authentication device from the management device, and the domain name certificate acquisition request also includes the information of the second authentication device.

12. The method according to any one of claims 9 to 11, characterized in that: The network function network element sends a domain name certificate acquisition request to a certificate management network element in the first network according to the first domain name certificate, including: The network function network element sends the first domain name certificate to the certificate management network element; The network function network element receives a first indication from the certificate management network element, where the first indication indicates that the first domain name certificate is authenticated; The network function network element sends the domain name certificate acquisition request to the certificate management network element.

13. The method according to claim 12, characterized in that The first domain name certificate includes the domain name and type information of the network function network element, and the type information of the network function network element is used to verify the type information corresponding to the domain name of the network function network element.

14. The method according to any one of claims 1 to 13, characterized in that: The method further comprises: The management device provides the domain name of the network function network element to the network function network element; The management device sends a registration message to the DNS server, where the registration message includes the domain name of the network function network element.

15. The method according to claim 14, characterized in that The method further comprises: The management device sends information of a second authentication device to the network function network element, where the second authentication device is used to issue a second domain name certificate to the network function network element.

16. The method according to any one of claims 1 to 15, characterized in that: The method further comprises: The first authentication device receives the domain name and type information of the network function network element from the network function network element; The first authentication device verifies the type information and type information corresponding to the domain name of the network function network element; If the verification passes, the first authentication device issues the first domain name certificate.

17. The method according to any one of claims 1 to 16, characterized in that: The first domain name certificate includes the domain name and type information of the network function network element, and the type information in the first domain name certificate is used to verify the domain name of the network function network element.

18. A network element verification method, characterized in that: include: The certificate management network element receives a domain name certificate acquisition request from a network function network element, the domain name certificate acquisition request is used to request a certificate of the network function network element issued by a second authentication device in a second network, the domain name certificate acquisition request includes a domain name of the network function network element, the network function network element and the certificate management network element belong to a first network, and the first domain name certificate is used for the network function network element to communicate with a network element in the first network; The certificate management network element sends the domain name of the network function network element to the second authentication device, where the domain name of the network function network element is used to verify the network function network element; The certificate management network element obtains a second domain name certificate issued by the second authentication device, where the second domain name certificate is used to indicate that the verification is successful; The certificate management network element sends the second domain name certificate to the network function network element.

19. The method according to claim 18, characterized in that The method further comprises: The certificate management network element obtains domain name service DNS challenge information from the second authentication device; The certificate management network element generates a DNS challenge response according to the DNS challenge information; The certificate management network element writes the DNS challenge response into the domain name record of the network function network element in the domain name service DNS server; or, the certificate management network element requests the second device to write the DNS challenge response into the domain name record of the network function network element in the DNS server; the certificate management network element receives a domain name record modification completion indication from the second device; The certificate management network element notifies the second authentication device to obtain the DNS challenge response from the DNS server, where the DNS challenge response and the DNS challenge information are used by the second authentication device to verify the network function network element; In the case where the verification is successful, the certificate management network element obtains information provided by the second authentication device indicating that the verification is successful.

20. The method of claim 19, wherein: The method further comprises: The second device receives a DNS challenge response from the certificate management network element; The second device writes the DNS challenge response into the domain name record of the network function network element in the DNS server.

21. The method according to claim 19 or 20, characterized in that The method further comprises: The first authentication device obtains the DNS challenge response from the DNS server; The first authentication device verifies the network function network element according to the DNS challenge response and the DNS challenge information; In the case where the verification is successful, the first authentication device provides the information indicating that the verification is successful to the network function network element.

22. The method according to any one of claims 18 to 21, characterized in that: The method further comprises: The certificate management network element receives a first domain name certificate from the network function network element, where the first domain name certificate is used to indicate that the domain name of the network function network element has passed verification, and the first domain name certificate includes the domain name and type information of the network function network element; The certificate management network element verifies the type information and the type information corresponding to the domain name of the network function network element; If the verification passes, the certificate management network element sends a first indication to the network function network element, where the first indication indicates that the first domain name certificate authentication passes.

23. The method according to any one of claims 18 to 22, characterized in that: The second domain name certificate is used for the network function network element to communicate with the network element of the second network.

24. A communication device, characterized in that: The method comprises a unit or module for executing the method according to any one of claims 1 to 17, or comprises a unit or module for executing the method according to any one of claims 18 to 23.

25. A communication device, characterized in that: The method comprises a processor configured to execute a computer program or an instruction to implement the method according to any one of claims 1 to 17, or to implement the method according to any one of claims 18 to 23.

26. A computer-readable storage medium, characterized in that: The storage medium stores a computer program or an instruction. When the computer program or the instruction is executed by the communication device, the method according to any one of claims 1 to 23 is implemented.