Authentication synchronization method, communication system and network device
By standardizing the generation rules of sequence numbers and the distributed use of subscript indices in 5G networks, the problem of frequent triggering of authentication weight synchronization between the PS domain and IMS domain is solved, signaling overhead is reduced, and network efficiency is improved.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-22
- Publication Date
- 2026-04-07
AI Technical Summary
In 5G networks, the authentication weight synchronization process between the PS domain and IMS domain is frequently triggered, leading to increased signaling overhead, which existing technologies have not been able to effectively address.
By standardizing the generation rules of serial numbers, using different subscript indices distributed across the PS and IMS domains, and updating the serial numbers according to different incrementing strategies during the authentication process, it is ensured that there is no interference between different domains.
This reduces the frequency of authentication weight synchronization, decreases signaling overhead, and improves network efficiency.
Smart Images

Figure CN119967413B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the field of communication technology, in particular to an authentication synchronization method and a communication system and a network device. BACKGROUND
[0002] In a mobile communication system, in order to enhance the security of the mobile communication system, a mechanism of bidirectional authentication between a terminal and a core network is introduced, in which process, SQN (Sequence Number) is a very important parameter, which ensures that each authentication request is fresh. The SQN is composed of two parts of SEQ (Sequence) and IND (Index), wherein the SEQ is used to ensure the uniqueness and freshness of the message sequence, and the IND is used to select a specific element in the SQN array.
[0003] Specifically, under a voice scheme such as VoNR (Voice over New Radio) in a 5G network, when the terminal is switched on, the alternate authentication between the PS (Packet Switched) domain and the IMS (IP Multimedia Subsystem) domain will be performed again. In this process, if the PS domain directly uses the SQN previously fetched from the UDM (Unified Data Management) to generate an authentication vector, and after the PS domain fetches the SQN, the IMS domain generates its own authentication vector using the same SQN, then the SEQ value stored at the USIM (Universal Subscriber Identity Module) side will be greater than the SEQ value used in the PS domain authentication, that is, the authentication fails, at this time, the authentication heavy synchronization process will be triggered alternately between the PS domain and the IMS domain, which greatly increases the signaling overhead.
[0004] At present, no effective solution has been proposed for the above problems. SUMMARY
[0005] Embodiments of the present application provide an authentication synchronization method and a communication system and a network device, to at least solve the technical problem that related technologies do not standardize and unify the generation rule of the sequence number, which causes the authentication heavy synchronization process to be frequently triggered between network devices, and increases the signaling overhead.
[0006] According to an aspect of the embodiments of the present application, a method for authenticating synchronization is provided. The method comprises: receiving a first authentication request initiated by a target terminal, and generating a first authentication vector according to the first authentication request; sending a first authentication synchronization request carrying the first authentication vector to the target terminal; wherein the first authentication vector comprises at least a first serial number, and the first serial number is composed of a first serial number and a corresponding first index, and the first index is used to reflect the type of the first authentication request; in the case that the result of authenticating the first authentication vector by the target terminal is authentication success, receiving a second authentication request initiated by the target terminal again, and generating a second authentication vector according to the second authentication request; sending a second authentication synchronization request carrying the second authentication vector to the target terminal; wherein the second authentication vector comprises at least a second serial number obtained by updating the first serial number according to a preset first updating rule; in the case that the result of authenticating the first authentication vector by the target terminal is authentication failure, receiving an authentication heavy synchronization request initiated by the target terminal, and the authentication heavy synchronization request carries at least a maximum serial number stored in a USIM of the target terminal; generating a third authentication vector according to the authentication heavy synchronization request; and sending a third authentication synchronization request carrying the third authentication vector to the target terminal; wherein the third authentication vector comprises at least a second serial number obtained by updating the maximum serial number and the first index according to a preset second updating rule.
[0007] Optionally, the receiving the first authentication request initiated by the target terminal, and generating the first authentication vector according to the first authentication request, and sending the first authentication synchronization request carrying the first authentication vector to the target terminal comprises: receiving the first authentication request initiated by the target terminal, wherein the first authentication request carries at least identity information of the target terminal, and the type of the first authentication request comprises a network access request or an IP multimedia subsystem service request; determining a target authentication method corresponding to the identity information in the first authentication request from a preset authentication method list, and determining target authentication data corresponding to the target authentication method and the identity information in the first authentication request, wherein the authentication method list comprises a corresponding relationship between the identity information of a plurality of users and the authentication method, and the target authentication data comprises at least one of an authentication key, the first serial number, and the first index; generating the first authentication vector according to the target authentication data, and sending the first authentication synchronization request carrying the first authentication vector to the target terminal.
[0008] Optionally, the generating the first authentication vector according to the target authentication data comprises: obtaining a random number, and determining an expected authentication response according to the random number and an authentication key in the target authentication data; obtaining a first serial number and a corresponding first index, and composing the first serial number from the first serial number and the corresponding first index, wherein the first index comprises an even value or an odd value; and composing the first authentication vector from the random number, the authentication key, the expected authentication response, and the first serial number.
[0009] Optionally, the sending the first authentication synchronization request carrying the first authentication vector to the target terminal comprises: in a case that the first authentication request is a network access request, sending the first authentication synchronization request carrying the first authentication vector to the target terminal through an N2 interface; and in a case that the first authentication request is an IP multimedia subsystem service request, sending the first authentication synchronization request carrying the first authentication vector to the target terminal through an interface of an IP multimedia subsystem trust domain via an entity network element of the IP multimedia subsystem.
[0010] Optionally, the sending the first authentication synchronization request carrying the first authentication vector to the target terminal comprises: sending the first authentication synchronization request carrying the first authentication vector to the target terminal, wherein the target terminal is configured to parse the first authentication vector in the first authentication synchronization request to obtain the first serial number; determining whether the first serial number in the first authentication vector satisfies a preset condition, wherein the preset condition comprises: a difference between the first serial number and a maximum serial number in a plurality of second serial numbers stored in a USIM of the target terminal is not greater than a first preset threshold, a difference between the maximum serial number and the first serial number is not greater than a second preset threshold, and the first serial number is greater than a second target serial number stored in the USIM of the target terminal and having the same index; in a case that the first serial number satisfies the preset condition, determining that a result of authenticating the first authentication vector is authentication success, sending an authentication synchronization success response corresponding to the first authentication vector to the core network, and updating the maximum serial number in the plurality of second serial numbers stored in the USIM according to the first serial number in the first authentication vector; and in a case that the difference between the maximum serial number and the first serial number is greater than the second threshold, determining that the result of authenticating the first authentication vector is authentication failure, and sending an authentication re-synchronization request to the core network, wherein the authentication re-synchronization request carries at least the maximum serial number.
[0011] Optionally, the receiving the authentication re-synchronization request initiated by the target terminal and carrying at least the maximum sequence number in the plurality of second sequence numbers stored in the USIM of the target terminal, and generating the third authentication vector according to the authentication re-synchronization request, and sending the third authentication synchronization request carrying the third authentication vector to the target terminal comprises: in the case that the result of the authentication of the target terminal to the first authentication vector is authentication failure, and the difference between the maximum sequence number in the plurality of second sequence numbers stored in the USIM of the target terminal and the first sequence number is greater than the second threshold, receiving the authentication re-synchronization request initiated by the target terminal, wherein the authentication re-synchronization request carries at least the maximum sequence number; updating the maximum sequence number and the first index in the authentication re-synchronization request according to the second update rule to obtain the third sequence number, and sending the third authentication synchronization request carrying the third authentication vector including the third sequence number to the target terminal.
[0012] Optionally, the first update rule comprises: incrementing the sequence number by 2, adding 2 to the index, and then performing a modulo operation on a preset value; and the second update rule comprises: incrementing the sequence number by 1, incrementing the index by 1, or performing a modulo operation on the index with respect to a preset value; and the preset value is the number of the second sequence numbers stored in the USIM of the target terminal.
[0013] According to another aspect of the embodiments of the present application, a communication system is further provided, which comprises: a target terminal and a core network. The target terminal is configured to send a first authentication request to the core network. The core network is configured to receive the first authentication request initiated by the target terminal, generate a first authentication vector according to the first authentication request, and send a first authentication synchronization request carrying the first authentication vector to the target terminal. The first authentication vector includes at least a first sequence number, and the first sequence number is composed of the first sequence number and a corresponding first index, and the first index is used to reflect the type of the first authentication request. In the case that the result of the authentication of the target terminal to the first authentication vector is authentication success, the core network receives a second authentication request initiated by the target terminal again, generates a second authentication vector according to the second authentication request, and sends a second authentication synchronization request carrying the second authentication vector to the target terminal. The second authentication vector includes at least a second sequence number obtained by updating the first sequence number according to a preset first update rule. In the case that the result of the authentication of the target terminal to the first authentication vector is authentication failure, the core network receives an authentication re-synchronization request initiated by the target terminal and carrying at least a maximum sequence number in a plurality of second sequence numbers stored in a USIM of the target terminal, generates a third authentication vector according to the authentication re-synchronization request, and sends a third authentication synchronization request carrying the third authentication vector to the target terminal. The third authentication vector includes at least a second sequence number obtained by updating the maximum sequence number and the first index according to a preset second update rule.
[0014] According to another aspect of the embodiments of the present application, a computer program product is also provided, which comprises a computer program, wherein the computer program, when executed by a processor, implements the authentication synchronization method described above.
[0015] According to another aspect of the embodiments of the present application, a network device is also provided, which comprises a memory and a processor, wherein the memory stores a computer program, and the processor is configured to execute the authentication synchronization method described above by using the computer program.
[0016] In the embodiments of the present application, the core network receives a first authentication request initiated by a target terminal, generates a first authentication vector according to the first authentication request, and sends a first authentication synchronization request carrying the first authentication vector to the target terminal. The first authentication vector at least comprises a first serial number, which is composed of a first serial number and a corresponding first index. The first index is used to reflect the type of the first authentication request. In the case that the result of the authentication of the first authentication vector by the target terminal is successful, the core network receives a second authentication request initiated by the target terminal, generates a second authentication vector according to the second authentication request, and sends a second authentication synchronization request carrying the second authentication vector to the target terminal. The second authentication vector at least comprises a second serial number obtained by updating the first serial number according to a preset first updating rule. In the case that the result of the authentication of the first authentication vector by the target terminal is unsuccessful, the core network receives an authentication heavy synchronization request initiated by the target terminal, which at least carries a maximum serial number in a plurality of second serial numbers stored in a Universal Subscriber Identity Module (USIM) of the target terminal, generates a third authentication vector according to the authentication heavy synchronization request, and sends a third authentication synchronization request carrying the third authentication vector to the target terminal. The third authentication vector at least comprises a second serial number obtained by updating the maximum serial number and the first index according to a preset second updating rule. In the above authentication process, the index is used to ensure that the different domains do not interfere with each other in the authentication synchronization process, and the serial number is updated according to different increment strategies in the authentication synchronization process and the authentication heavy synchronization process, so as to reduce the frequency of authentication heavy synchronization to the greatest extent. Thus, the technical problem that the generation rule of the serial number is not standardized in the related art, which causes the authentication heavy synchronization process to be frequently triggered between the network devices and increases the signaling overhead is solved. BRIEF DESCRIPTION OF DRAWINGS
[0017] The accompanying drawings, which are included to provide a further understanding of the application and are incorporated in and constitute a part of this application, illustrate embodiments of the application and serve to explain the principles of the application. In the drawings:
[0018] Figure 1is a structural schematic diagram of an optional communication system according to an embodiment of the application;
[0019] Figure 2 is a flow schematic diagram of an optional authentication synchronization method according to an embodiment of the application;
[0020] Figure 3 is a structural schematic diagram of an optional network device according to an embodiment of the application. DETAILED DESCRIPTION
[0021] In order to make the personnel in the art better understand the scheme of the present application, the technical scheme in the embodiments of the present application will be clearly and completely described below in conjunction with the drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative labor should belong to the scope of protection of the present application.
[0022] It should be noted that the terms "first", "second", and the like in the specification and claims of the present application and the drawings are used to distinguish similar objects, and do not necessarily have to describe a specific order or sequence. It should be understood that the data thus used can be interchanged under appropriate circumstances, so that the embodiments of the present application described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "include" and "have" and any variations thereof are intended to cover non-exclusive inclusion, for example, a process, method, system, product or device that includes a series of steps or units does not have to be limited to those steps or units clearly listed, but can include other steps or units that are not clearly listed or inherent to these processes, methods, products or devices.
[0023] In order to better understand the embodiments of the present application, first, the part of the nouns or terms appearing in the description of the embodiments of the present application are translated and explained as follows:
[0024] SQN (Sequence Number): In 3GPP protocol, in order to resist replay attack, UE (User Equipment) and HSS (Home Subscriber Server) on the core network side each maintain a sequence number counter SQN, HSS maintains SQN HSS, which is responsible for generating a new sequence number for each generated AV (Authentication Vector); and UE maintains SQN UE to save the maximum SQN value in the received AV. In addition, SQN includes two parts: SEQ and IND, that is, SQN = SEQ || IND, wherein SEQ occupies 43 bits, and IND occupies 5 bits, therefore, SQN occupies 48 bits in total, that is, 6 bytes.
[0025] USIM (Universal Subscriber Identity Module): also known as upgraded SIM, is a component of UMTS (Universal Mobile Telecommunication System) 3G network. In addition to being able to support multiple applications, the USIM card also upgrades the algorithm in terms of security, and adds the function of card authentication to the network. This two-way authentication can effectively prevent hackers from attacking the card. Generally, the IC chip of USIM has a storage capacity of 128 KB, which can store the following information: 500 sets of phone numbers and corresponding names, 50 sets of short messages, 4-bit USIM password (PIN), and more than 5 sets of recently dialed numbers.
[0026] IMS (IP Multimedia Subsystem): is a new form of multimedia service, which can meet the needs of terminal customers for more novel and diversified multimedia services. Therefore, IMS is considered as the core technology of the next generation network, and is also an important way to solve the integration of mobile and fixed networks, and to introduce voice, data, and video triple convergence and other differentiated services.
[0027] Authentication is a crucial concept in information science, involving verifying whether a user has the necessary permissions to access a system. Traditional authentication methods typically rely on passwords, where each user who obtains the password is considered authorized. However, this approach is problematic if a password is stolen or lost, requiring administrators to reset it, necessitating manual verification of the user's identity beforehand. To overcome these drawbacks, alternative authentication methods have been proposed, such as a two-way authentication mechanism called AKA (Authentication and Key Agreement), which involves both user authentication (network authentication to prevent unauthorized access to network resources) and network authentication (user authentication to prevent unauthorized network access). In addition, other authentication methods can be used, such as HTTP digest authentication under specific conditions (e.g., accessing IMS via ADSL in a fixed network).
[0028] Example 1
[0029] Currently, the 3GPP protocol specification defines three methods for calculating SQN: time-based, partially time-based, and non-time-based. The non-time-based method for calculating SEQ and IND is as follows: The network maintains a counter for each terminal, with SEQ incrementing by 1 each time; the index of the next authentication vector is (IND+1) modulo 'a', where 'a' is the size of the SEQ number stored in the terminal's USIM, typically 32. Therefore, the index IND is generally retrieved cyclically from 0 to 31.
[0030] In addition, during the authentication and synchronization process, the SEQ of the serial number stored in the terminal's USIM needs to be compared with the SEQ sent to the terminal by the core network. net A comparison is then performed. Furthermore, the terminal's USIM must meet the following three conditions to successfully authenticate with the core network in order to confirm successful authentication and synchronization:
[0031] (1)SEQ net -SEQ ms ≦Δ, and Δ is generally set to 2. 28 ;
[0032] (2)SEQ ms -SEQ net ≦L, and L is generally set to 32;
[0033] (3)SEQ net >SEQ k
[0034] Among them, SEQ ms SEQ is the largest value stored in the terminal USIM. k It is the SEQ stored in the terminal USIM and issued by the core network. net SEQ with the same subscript index.
[0035] Based on the above SQN calculation method and authentication mechanism, it can be seen that the SEQ in the authentication request issued later must be larger than the SEQ in the authentication request issued earlier. Even if the latest issued SEQ is smaller than the maximum SEQ stored in USIM, it cannot be much smaller, at most smaller by L (usually taken as 32).
[0036] Assuming the initial value of SEQ is 100, the PS field calculates SEQ and IND according to a non-time-based mechanism as shown in Table 1 below.
[0037] Table 1
[0038] IND #0 #1 #2 #3 SEQ 101 102 103 104
[0039] The IMS domain will resynchronize during the first authentication. The resynchronization process will bring the maximum SEQ value stored on the USIM card to the IMS, i.e., the SEQ value. ms =101, IND=0. Therefore, the IMS domain calculates SEQ and IND according to the non-time-based mechanism as shown in Table 2 below.
[0040] Table 2
[0041] IND #1 #2 #3 #4 SEQ 102 103 104 105
[0042] However, in practice, after authentication in the IMS domain, the PS domain will synchronize the authentication weight during the second authentication because SEQ net >SEQ k If this judgment condition is not met, the authentication weight synchronization will be triggered alternately, greatly increasing the frequency of authentication weight synchronization and increasing signaling overhead.
[0043] To address the aforementioned problems, this application provides a communication system 10. Figure 1 This is a schematic diagram of the structure of an optional communication system 10 according to an embodiment of this application, as shown below. Figure 1 As shown. The communication system 10 includes: a target terminal 11 and a core network 12, wherein:
[0044] The target terminal 11 is used to send the first authentication request to the core network 12.
[0045] Core network 12 is used to implement the authentication process of target terminal 11 according to the following terminal authentication management method, so as to reduce the frequency of re-authentication synchronization.
[0046] It should be noted that the steps shown in the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions, and although a logical order is shown in the flowchart, in some cases, the steps shown or described herein can be executed in an order different from that shown.
[0047] Figure 2 is a flowchart of a method of authenticating and synchronizing according to an embodiment of the present application, as shown in the figure, the method comprises the following steps S202-S208, wherein: Figure 2
[0048] Step S202, receiving a first authentication request initiated by a target terminal, and generating a first authentication vector according to the first authentication request, and sending a first authentication synchronization request carrying the first authentication vector to the target terminal.
[0049] Among them, the above-mentioned first authentication vector at least includes: a first sequence number (SQN net ), and the first sequence number (SQN net ) is composed of a first sequence number (SEQ net ) and a corresponding first index (IND), and the first index (IND) is used to reflect the type of the first authentication request.
[0050] Specifically, in the technical solution provided in the above step S202, the interaction process between the target terminal and the core network is as follows:
[0051] First, the core network receives a first authentication request initiated by a target terminal. Among them, the first authentication request at least carries the identity information of the target terminal, such as IMSI (International Mobile Subscriber Identity, International Mobile Subscriber Identity), and the type of the first authentication request includes: network access request or IP multimedia subsystem service request, wherein:
[0052] In the case where the type of the first authentication request is a network access request, it means that the target terminal is authenticated in the PS domain, which is mainly used for the target terminal to access the 5G network or when the network needs to confirm the terminal identity, such as terminal boot, location update, service request, etc. Therefore, the first authentication request sent by the target terminal to the access and mobility management function AMF network element of the core network can at least include the type of the request service and the identity information, etc., wherein the identity information can be SUCI (Subscription Concealed Identifier, Secure User Context Identifier) or 5G-GUTI (5G Globally Unique Temporary Identifier, 5G Temporary Global User Identifier), etc.
[0053] In the case that the type of the first authentication request is an IMS service request, it is explained that the target terminal is authenticated in the IMS domain, which is mainly used in the scenario that the target terminal requests to use IMS services, such as initiating or receiving voice calls, video calls or message services, etc. Therefore, the first authentication request sent by the target terminal to the access and mobility management function (AMF) network element of the core network can at least include its IMS identity, such as IMPI (IMS Private Identity) or IMPU (IMS Public Identity).
[0054] Second step: The core network determines the target authentication method corresponding to the identity information in the first authentication request from the preset authentication method list, and determines the corresponding target authentication data according to the target authentication method and the identity information in the first authentication request.
[0055] Among them, for different types of first authentication requests, the core network processes the above first authentication request in different ways, as follows:
[0056] In the case that the type of the first authentication request is a network access request, after the AMF network element of the core network receives the first authentication request initiated by the target terminal, it can determine the target authentication method supported by the target terminal from the preset authentication method list according to the network policy and the identity information of the target terminal, wherein the above authentication method list includes the corresponding relationship between the identity information of multiple users and the authentication method. In the 5G network, the authentication method is usually EAP-AKA' (Extensible Authentication Protocol-AKA') or 5G-AKA authentication method, etc. The AMF network element sends the selected target authentication method and the identity information in the first authentication request to the UDM (Unified Data Management) network element in the core network, wherein the UDM is responsible for storing and managing the authentication data of the user, including the key (K), the first serial number (i.e. the initial SEQ value) in the first authentication vector and the first subscript index.
[0057] In the case that the type of the first authentication request is an IP multimedia subsystem service request, the AMF network element of the core network, after receiving the first authentication request initiated by the target terminal, first forwards the request to the P-CSCF (Proxy-Call Session Control Function) network element in the IMS domain; the P-CSCF network element forwards the request to the I-CSCF (Inquiry-Call Session Control Function) network element, so as to reach the S-CSCF (Service-Call Session Control Function) network element. Then, the S-CSCF network element sends the request to the AMF network element to perform subsequent related procedures of determining the target authentication data. For details, reference can be made to the above network access request, and no more description is made herein.
[0058] Step 3: The core network generates a first authentication vector according to the target authentication data, and sends a first authentication synchronization request carrying the first authentication vector to the target terminal.
[0059] Specifically, the UDM network element of the core network can generate the first authentication vector according to the following rules, including:
[0060] First, a random number (Rand) is obtained, and an expected authentication response (XRES) is determined according to the random number and an authentication key (K) in the target authentication data.
[0061] Then, a first serial number (SEQ net ) and a corresponding first index (IND) are obtained, and a first sequence number (SQN net ) is composed of the first serial number (SEQ net ) and the corresponding first index (IND). The first index is planned to be used in the PS domain and the IMS domain, for example, even IND is used in the PS domain and odd IND is used in the IMS domain, so that in multiple authentication requests, the two domains can independently perform authentication without frequently triggering the authentication synchronization process. Even if the authentication frequency of the PS domain is higher than that of the IMS domain, the differentiated use of the IND value can reduce the frequency of sequence number synchronization, thereby reducing the network signaling overhead and improving the network efficiency.
[0062] Finally, the first authentication vector is composed of the random number (Rand), the authentication key (K), the expected authentication response (XRES), and the first sequence number (SQN net ).
[0063] Further, after the UDM network element of the core network feeds back the generated first authentication vector to the AMF network element, the AMF network element can feed back the corresponding first authentication synchronization request to the target terminal according to the following rules, including:
[0064] In the case that the first authentication request is a network access request, that is, the target terminal performs authentication in the PS domain. In this case, the AMF network element in the PS domain receives the first authentication request sent by the target terminal through the N1 interface (that is, the control plane signaling interface) for interaction; and the AMF network element in the core network can send the first authentication request to the target terminal through the N2 interface (that is, the interface between the radio access network and the AMF network element).
[0065] In the case that the first authentication request is an IP multimedia subsystem service request, that is, the target terminal performs authentication in the IMS domain. In this case, the S-CSCF network element in the IMS domain sends the first authentication request to the entity network element (that is, the proxy call session control function P-CSCF network element, the interrogating call session control function I-CSCF network element, and the service call session control function S-CSCF network element) in the IMS domain through the interface of the IP multimedia subsystem trust domain (that is, N3IWF), and then the entity network element in the IMS domain sends the first authentication request to the target terminal.
[0066] Fifth step: The target terminal parses the first authentication vector in the first authentication synchronization request to obtain the first sequence number (SQN net ).
[0067] Sixth step: The target terminal judges whether the first sequence number (SEQ net ) in the first sequence number (SQN net ) satisfies the preset condition. The preset condition includes that the difference between the first sequence number (SEQ net ) and the maximum sequence number (SEQ ms ) stored in the USIM of the target terminal is not greater than a preset first threshold value (generally set to 2 28 ), the difference between the maximum sequence number (SEQ ms ) and the first sequence number (SEQ net ) is not greater than a preset second threshold value (generally set to 32), and the first sequence number (SEQ net ) is greater than the second target sequence number (SEQ k ) with the same index stored in the USIM of the target terminal. In addition, if the first sequence number (SEQ net ) satisfies the preset condition, the seventh step is executed; otherwise, the eighth step is executed.
[0068] Step 7: If the target terminal determines that the result of the authentication of the first authentication vector is successful, the target terminal sends an authentication synchronization success response to the core network, and the target terminal updates the maximum sequence number in the plurality of second sequence numbers stored in the USIM according to the first sequence number in the first authentication vector.
[0069] Step 8: If the target terminal determines that the result of the authentication of the first authentication vector is unsuccessful, the target terminal sends an authentication weight synchronization request to the core network to trigger an authentication weight synchronization process, wherein the authentication weight synchronization request carries at least the maximum sequence number.
[0070] Step S204: If the result of the authentication of the first authentication vector by the target terminal is successful, the second authentication request initiated by the target terminal is received again, and a second authentication vector is generated according to the first authentication request, and a second authentication synchronization request carrying the second authentication vector is sent to the target terminal.
[0071] Specifically, the process of the terminal performing the alternating authentication in the PS domain and the IMS domain can be that the terminal performs one or more authentications in the PS domain and then performs one or more authentications in the IMS domain, which mainly depends on the network configuration and user activity. Therefore, when the result of the authentication of the first authentication vector by the target terminal is successful (i.e., the first sequence number in the first authentication synchronization request satisfies the three constraint conditions), the target terminal can first feed back an authentication synchronization success response corresponding to the first authentication synchronization request to the core network, and the core network can perform a subsequent processing process. In addition, the core network can continue to receive the second authentication request initiated by the target terminal according to actual needs (such as data service needs, real-time call service needs), and then generate a second authentication vector according to the second authentication request, wherein the second authentication vector at least includes a second sequence number obtained by updating the first sequence number according to a preset first updating rule; finally, a second authentication synchronization request carrying the second authentication vector is sent to the target terminal.
[0072] Optionally, the first updating rule includes: incrementing the sequence number by 2, adding 2 to the index and then performing a modulo operation on a preset value (i.e., IND+2 modulo a), wherein the preset value is the number of second sequence numbers stored in the USIM of the target terminal.
[0073] It should be noted that the process of the core network processing the second authentication request is the same as the process of processing the first authentication request in step S202, and therefore the process is not described in detail here.
[0074] Step S206, in case that the result of the authentication of the target terminal to the first authentication vector is authentication failure, receiving the authentication weight synchronization request initiated by the target terminal and carrying at least the maximum serial number in the plurality of second serial numbers stored in the USIM of the target terminal, and generating the third authentication vector according to the authentication weight synchronization request, and sending the third authentication synchronization request carrying the third authentication vector to the target terminal.
[0075] Specifically, in case that the result of the authentication of the target terminal to the first authentication vector is authentication failure (i.e. the first serial number in the first authentication synchronization request does not satisfy at least one of the three preset conditions), it means that the SQN states between the target terminal and the core network side can be out of synchronization, which means that the second SQN value stored in the USIM of the target terminal cannot reflect the latest state of the core network side. Therefore, in order to restore the synchronization state with the network side and ensure the safety of subsequent communication, the target terminal can trigger the authentication weight synchronization process. Specifically as follows:
[0076] Firstly, in case that the difference between the maximum serial number (SEQ ms ) and the first serial number (SEQ net ) is greater than a preset second threshold value (generally set to 32), the target terminal sends an authentication weight synchronization request to the core network, wherein the authentication weight synchronization request carries at least the maximum serial number.
[0077] Then, the core network updates the maximum serial number and the first index in the authentication weight synchronization request according to a second update rule to obtain a third serial number.
[0078] The above-mentioned second update rule includes: incrementing the serial number by 1, incrementing the index by 1, or performing a modulo operation on the index with a preset value, wherein the preset value is the number of second serial numbers stored in the USIM of the target terminal.
[0079] Finally, the core network sends a third authentication synchronization request carrying a third authentication vector containing the third serial number to the target terminal.
[0080] Wherein, other parameters in the third authentication vector, such as random number (Rand), expected authentication response (XRES), authentication key, etc. are updated according to the parameter generation process in the first authentication vector in step S202. Therefore, the core network can generate the third authentication vector by using the third serial number, the updated random number (Rand), the expected authentication response (XRES), the authentication key, etc. and send the third authentication synchronization request carrying the third authentication vector to the target terminal, and the target terminal can continue to judge the third serial number (SEQ net ) in the third serial number (SEQ netwhether a preset condition is met, and sending a corresponding authentication resynchronization success response to the core network or an authentication heavy resynchronization process to the core network according to a judgment result.
[0081] Based on the terminal authentication management method defined in the steps S202 to S206, if the initial value of the SEQ is still 100, the PS domain calculates the SEQ and the IND according to the non-time-based mechanism as shown in Table 3.
[0082] Table 3
[0083] IND #0 #4 #6 #8 SEQ 102 104 106 108
[0084] The IMS domain will resynchronize in the first authentication, and the resynchronization process will bring the maximum SEQ value stored in the USIM card to the IMS, that is, SEQ ms = 101, IND = 0. Therefore, the IMS domain calculates the SEQ and the IND according to the non-time-based mechanism as shown in Table 4.
[0085] Table 4
[0086] IND #1 #3 #5 #7 SEQ 103 105 107 109
[0087] As can be seen from the above Tables 3 and 4, when the target terminal performs the alternating authentication in the PS / IMS domain, the authentication frequency of the PS domain is higher. Even so, the IMS domain authentication will trigger the authentication heavy resynchronization process only when the PS domain authentication reaches 16 times or more in succession, greatly reducing the authentication heavy resynchronization frequency and reducing the signaling overhead.
[0088] Embodiment 2
[0089] According to the embodiments of the present application, a computer program product is also provided, which includes a computer program. When the computer program is executed by a processor, the authentication resynchronization method in the embodiment 1 is implemented.
[0090] According to the embodiments of the present application, a non-volatile storage medium is also provided, which includes a stored computer program. A device in which the non-volatile storage medium is located executes the authentication resynchronization method in the embodiment 1 by running the computer program.
[0091] According to the embodiments of the present application, a processor is also provided, which is used to run a computer program. When the computer program is run, the authentication resynchronization method in the embodiment 1 is executed.
[0092] According to the embodiments of the present application, an electronic device is also provided, which includes a memory and a processor. The memory stores a computer program, and the processor is configured to execute the authentication resynchronization method in the embodiment 1 by the computer program.
[0093] Specifically, the computer program runs to implement the following steps: receiving a first authentication request initiated by a target terminal, and generating a first authentication vector according to the first authentication request, and sending a first authentication synchronization request carrying the first authentication vector to the target terminal, wherein the first authentication vector at least includes a first serial number, and the first serial number is composed of a first serial number and a corresponding first subscript index, and the first subscript index is used to reflect the type of the first authentication request; in the case that the result of authenticating the first authentication vector at the target terminal is authentication success, receiving a second authentication request initiated by the target terminal again, and generating a second authentication vector according to the second authentication request, and sending a second authentication synchronization request carrying the second authentication vector to the target terminal, wherein the second authentication vector at least includes a second serial number obtained by updating the first serial number according to a preset first updating rule; in the case that the result of authenticating the first authentication vector at the target terminal is authentication failure, receiving an authentication heavy synchronization request initiated by the target terminal and carrying a maximum serial number in a plurality of second serial numbers stored in a global user identity card (USIM) of the target terminal, and generating a third authentication vector according to the authentication heavy synchronization request, and sending a third authentication synchronization request carrying the third authentication vector to the target terminal, wherein the third authentication vector at least includes a second serial number obtained by updating the maximum serial number and the first subscript index according to a preset second updating rule.
[0094] As an optional implementation, the network device can exist in the form of a mobile terminal, a computer terminal or a similar computing device. Figure 3 A hardware structure block diagram of a network device for implementing the authentication synchronization method is shown. As shown in the figure, Figure 3 the network device 30 can include one or more (in the figure, 302a, 302b, …, 302n are shown) processors 302 (the processor 302 can include but is not limited to a processing device such as a microprocessor MCU or a programmable logic device FPGA), a memory 304 for storing data, and a transmission device 306 for communication function. In addition, it can also include a display, an input / output interface (I / O interface), a universal serial bus (USB) port (which can be included as one of the ports of the BUS bus), a network interface, a power supply and / or a camera. Those skilled in the art can understand, Figure 3 the structure shown in the figure is only schematic, and it does not limit the structure of the network device described above. For example, the network device 30 can also include more or fewer components than those Figure 3 shown in the figure, or have a different configuration from that Figure 3 shown in the figure.
[0095] It should be noted that the one or more processors 302 and / or other data processing circuitry described above can be referred to herein generically as "data processing circuitry". The data processing circuitry can be embodied in whole or in part as software, hardware, firmware, or any combination thereof. In addition, the data processing circuitry can be a single standalone processing module, or incorporated in whole or in part within any one of the other elements of network device 30. As referred to in the embodiments herein, the data processing circuitry acts as a processor to control, for example, the selection of the variable resistance terminal path connected to the interface.
[0096] Memory 304 can be used to store software programs of application software and modules, such as program instructions / data storage means corresponding to the authentication synchronization method of the embodiments herein, and the processor 302 can execute various functional applications and data processing by running the software programs and modules stored in the memory 304, i.e. implement the vulnerability detection method of the application program described above. The memory 304 can include a high-speed random access memory, and can also include a non-volatile memory, such as one or more magnetic storage devices, flash memories, or other non-volatile solid-state memories. In some examples, the memory 304 can further include a memory disposed remotely with respect to the processor 302, which can be connected to the network device 30 through a network. Examples of the above-mentioned network include but are not limited to the Internet, an intranet, a local area network, a mobile communication network, and combinations thereof.
[0097] The transmission device 306 is used to receive or send data via a network. Specific examples of the above-mentioned network can include a wireless network provided by a communication provider of the network device 30. In one example, the transmission device 306 includes a network adapter (Network Interface Controller, NIC), which can be connected to other network devices through a base station so as to communicate with the Internet. In one example, the transmission device 306 can be a radio frequency (Radio Frequency, RF) module, which is used to communicate with the Internet in a wireless manner.
[0098] The display can be, for example, a touch screen type liquid crystal display (LCD), which can enable a user to interact with the user interface of the network device 30.
[0099] The above-mentioned embodiment numbers are only for description, and do not represent the advantages and disadvantages of the embodiments.
[0100] In the above-described embodiments of the present application, the description of each embodiment has its own emphasis, and the parts not described in detail in a certain embodiment can be referred to the related description of other embodiments.
[0101] In several embodiments provided in the present application, it should be understood that the disclosed technology can be implemented by other ways. Among them, the above-described device embodiments are only schematic, for example, the division of units can be a logical function division, and actual implementation can have another division manner, for example, a plurality of units or components can be combined or integrated into another system, or some features can be ignored or not executed. In addition, the coupling or direct coupling or communication connection between the displayed or discussed units can be indirect coupling or communication connection through some interfaces, units or modules, which can be electrical or other forms.
[0102] The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, i.e. they can be located in one place or distributed to multiple units. Part or all of the units can be selected according to actual needs to achieve the purpose of the embodiment.
[0103] In addition, the functional units in each embodiment of the present application can be integrated in one processing unit, or each unit can be physically present separately, or two or more units can be integrated in one unit. The integrated unit can be realized in the form of hardware or in the form of a software functional unit.
[0104] If the integrated unit is realized in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer readable storage medium. Based on this understanding, the technical solutions of the present application essentially or the part of the prior art that contributes to the technical solutions or the whole or part of the technical solutions can be embodied in the form of a software product. The computer software product is stored in a storage medium, including a plurality of instructions for causing a computer device (which can be a personal computer, a server or a network device, etc.) to execute all or part of the steps of the embodiments of the present application. The aforementioned storage medium includes: a U disk, a read-only memory (ROM, Read-Only Memory), a random access memory (RAM, Random Access Memory), a mobile hard disk, a magnetic disk or an optical disk, and various media that can store program codes.
[0105] The above is only the preferred embodiment of the present application, and it should be pointed out that for ordinary skilled in the art, without departing from the principles of the present application, a number of improvements and refinements can be made, which should be considered as the protection scope of the present application.
Claims
1. An authentication and synchronization method, characterized in that, include: The system receives a first authentication request initiated by the target terminal, generates a first authentication vector based on the first authentication request, and sends a first authentication synchronization request carrying the first authentication vector to the target terminal. The first authentication vector includes at least a first sequence number, and the first sequence number consists of a first sequence number and a corresponding first subscript index. The first subscript index is used to reflect the type of the first authentication request. If the authentication result obtained by the target terminal through the first authentication vector is successful, a second authentication request initiated by the target terminal is received again, and a second authentication vector is generated according to the second authentication request. A second authentication synchronization request carrying the second authentication vector is sent to the target terminal. The second authentication vector includes at least a second serial number obtained by updating the first serial number according to a preset first update rule. The first update rule includes: incrementing the serial number by 2, adding 2 to the subscript index, and then performing a modulo operation on a preset value. The preset value is the number of second serial numbers stored in the target terminal's Global Subscriber Identity Module (USIM). If the authentication result obtained by the target terminal through the first authentication vector is authentication failure, the system receives an authentication weight synchronization request initiated by the target terminal, which carries at least the largest sequence number among multiple second sequence numbers stored in the target terminal's USIM. The system generates a third authentication vector based on the authentication weight synchronization request and sends a third authentication synchronization request carrying the third authentication vector to the target terminal. The third authentication vector includes at least a second sequence number obtained by updating the largest sequence number and the first subscript index according to a preset second update rule. The second update rule includes incrementing the sequence number by 1, incrementing the subscript index by 1, or performing a modulo operation on the subscript index with the preset value.
2. The method according to claim 1, characterized in that, Receiving a first authentication request initiated by a target terminal, generating a first authentication vector based on the first authentication request, and sending a first authentication synchronization request carrying the first authentication vector to the target terminal, including: The system receives a first authentication request initiated by the target terminal, wherein the first authentication request carries at least the identity information of the target terminal, and the type of the first authentication request includes: a network access request or an IP Multimedia Subsystem Service request. The target authentication method corresponding to the identity information in the first authentication request is determined from the preset authentication method list, and the corresponding target authentication data is determined based on the target authentication method and the identity information in the first authentication request. The authentication method list includes the correspondence between the identity information of multiple users and the authentication methods, and the target authentication data includes at least one of the following: authentication key, first sequence number, and first subscript index. The first authentication vector is generated based on the target authentication data, and a first authentication synchronization request carrying the first authentication vector is sent to the target terminal.
3. The method according to claim 2, characterized in that, Generating the first authentication vector based on the target authentication data includes: Obtain a random number, and determine the desired authentication response based on the random number and the authentication key in the target authentication data; Obtain the first sequence number and the corresponding first subscript index, and compose the first sequence number by the first sequence number and the corresponding first subscript index, wherein the value type of the first subscript index includes: even number or odd number; The first authentication vector is composed of the random number, the authentication key, the expected authentication response, and the first sequence number.
4. The method according to claim 2, characterized in that, Sending a first authentication synchronization request carrying the first authentication vector to the target terminal includes: If the first authentication request is the network access request, the first authentication synchronization request carrying the first authentication vector is sent to the target terminal through the N2 interface. If the first authentication request is a service request for the IP Multimedia Subsystem, the first authentication synchronization request carrying the first authentication vector is sent to the target terminal through the interface of the IP Multimedia Subsystem Trust Domain via the entity network element of the IP Multimedia Subsystem.
5. The method according to claim 2, characterized in that, Sending a first authentication synchronization request carrying the first authentication vector to the target terminal includes: A first authentication synchronization request carrying the first authentication vector is sent to the target terminal. The target terminal parses the first authentication vector within the first authentication synchronization request to obtain the first sequence number. It then determines whether the first sequence number satisfies preset conditions, including: the difference between the first sequence number and the largest sequence number among multiple second sequence numbers stored in the target terminal's USIM is not greater than a preset first threshold; the difference between the largest sequence number and the first sequence number is not greater than a preset second threshold; and the first sequence number is greater than the same index stored in the target terminal's USIM. The second target sequence number; if the first sequence number satisfies the preset condition, the authentication result obtained by the first authentication vector is determined to be successful, and a corresponding authentication synchronization success response is sent to the core network, and the maximum sequence number among the multiple second sequence numbers stored in the USIM is updated according to the first sequence number in the first authentication vector; if the difference between the maximum sequence number and the first sequence number is greater than the second threshold, the authentication result obtained by the first authentication vector is determined to be unsuccessful, and the authentication weight synchronization request is sent to the core network, wherein the authentication weight synchronization request carries at least the maximum sequence number.
6. The method according to claim 1, characterized in that, Receiving an authentication weight synchronization request initiated by the target terminal, which carries at least the largest sequence number among multiple second sequence numbers stored in the target terminal's USIM, generating a third authentication vector based on the authentication weight synchronization request, and sending a third authentication synchronization request carrying the third authentication vector to the target terminal, including: If the authentication result obtained by the target terminal for the first authentication vector is authentication failure, and the difference between the largest sequence number among the multiple second sequence numbers stored in the target terminal's USIM and the first sequence number is greater than a second threshold, an authentication weight synchronization request initiated by the target terminal is received, wherein the authentication weight synchronization request carries at least the largest sequence number. The maximum sequence number and the first index in the authentication weight synchronization request are updated according to the second update rule to obtain the third sequence number, and the third authentication synchronization request carrying the third authentication vector containing the third sequence number is sent to the target terminal.
7. A communication system, characterized in that, The communication system includes: a target terminal and a core network, wherein... The target terminal is used to send a first authentication request to the core network; The core network is configured to receive a first authentication request initiated by the target terminal, generate a first authentication vector based on the first authentication request, and send a first authentication synchronization request carrying the first authentication vector to the target terminal. The first authentication vector includes at least a first sequence number, which is composed of a first sequence number and a corresponding first subscript index, the first subscript index reflecting the type of the first authentication request. If the target terminal successfully authenticates the first authentication vector, the core network receives a second authentication request initiated by the target terminal, generates a second authentication vector based on the second authentication request, and sends a second authentication synchronization request carrying the second authentication vector to the target terminal. The second authentication vector includes at least a second sequence number obtained by updating the first sequence number according to a preset first update rule. The first update rule includes: updating the sequence number... The number is incremented by 2, the index is incremented by 2, and then modulo is performed on a preset value, where the preset value is the number of second serial numbers stored in the target terminal's Global Subscriber Identity Module (USIM). If the target terminal fails to authenticate the first authentication vector, an authentication weight synchronization request initiated by the target terminal is received, which carries at least the largest serial number among the multiple second serial numbers stored in the target terminal's USIM. A third authentication vector is generated based on the authentication weight synchronization request, and a third authentication synchronization request carrying the third authentication vector is sent to the target terminal. The third authentication vector includes at least a second serial number obtained by updating the largest serial number and the first index according to a preset second update rule. The second update rule includes: incrementing the serial number by 1, incrementing the index by 1, or performing a modulo operation on the index with the preset value.
8. A computer program product, characterized in that, include: A computer program, wherein when executed by a processor, the computer program implements the authentication synchronization method according to any one of claims 1 to 6.
9. A network device, characterized in that, include: A memory and a processor, wherein the memory stores a computer program, and the processor is configured to execute the authentication synchronization method according to any one of claims 1 to 6 through the computer program.
Citation Information
Patent Citations
Resynchronization method, authentication method and device
CN101399603A
Authentication vector acquisition method, home server and network system
CN101998395A