User access authentication system

By introducing enhanced passwords and authentication enhanced verification mechanisms in the user access authentication system, the poor security problem of VPDN authentication method in 5G network is solved, and high security and stability of user access authentication is achieved.

CN120074903APending Publication Date: 2025-05-30XINGTANG TELECOMM TECH CO LTD +2
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510200141.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-21
Publication Date
2025-05-30

AI Technical Summary

Technical Problem

The existing VPDN authentication methods have poor security problems in 5G networks, especially after user sensitive data is leaked, attackers can pretend to be real users to attack the user's dedicated network, resulting in user intranet security risks.

Method used

It provides a user access authentication system, generates enhanced passwords through a dedicated terminal, and establishes an L2TP tunnel between the operator network and the enhanced LNS AAA terminal to perform authentication enhanced verification. The system includes message type, message length and message body. The message body includes a dedicated identifier, communication identity, fresh factor and authentication code. The authentication code is generated using the SM-HMAC algorithm to perform point-to-point access authentication.

Benefits of technology

By enhancing the use of passwords, users' private network security risks caused by user sensitive data leakage are avoided, ensuring that attackers cannot access the attack through user identity, and improving the security and stability of user access authentication.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120074903A_ABST
    Figure CN120074903A_ABST
Patent Text Reader

Abstract

The invention relates to a user access authentication system, belongs to the technical field of network security, and solves the problem of poor user access authentication security in a VPDN service in the prior art. Comprising a special terminal, an operator network end, an enhanced LNS AAA end and a special network end, wherein the special terminal is used for generating an enhanced password, and sending a user activation request to the operator network side based on the enhanced password; the operator network end establishes an L2TP tunnel with the enhanced LNS AAA end based on the user activation request, and sends the enhanced password to the enhanced LNS AAA end; and the enhanced LNS AAA end performs authentication enhanced verification based on the enhanced password, and if the authentication enhanced verification is passed, the special terminal performs service data interaction with the special network end. The user access authentication system is high in safety and good in stability.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of network security technology, and in particular, to a user access authentication system. Background Art

[0002] VPDN (Virtual Private Dial-up Network) is a technology that provides a secure connection for remote users through a public network (such as the Internet or a telephone network). It allows remote users to securely access a private network through a public network (such as the Internet), and transmits private data over the public network by encapsulating and encrypting network data to achieve the security level of the private network. Its working process is as follows: The client initiates a dial-up request; the request reaches the LAC through the network; the LAC and the LNS establish an L2TP tunnel; the client and the LNS establish a PPP connection through the tunnel; the LNS accesses the AAA server for user authentication; after the authentication is passed, the client can access the internal network.

[0003] Currently, the VPDN authentication of each operator mainly uses PAP and CHAP. With the application of VPDN technology in the 5G network, the VPDN authentication method develops from traditional PAP and CHAP authentication to authentication with a more extensive scalability EAP technology framework. After 5G extends the use of EAP, it provides session-based secondary authentication capabilities, which can perform authentication and authorization on users according to their own needs before the user establishes a session, and block illegal user requests before the user's private network; the secondary authentication is implemented based on the EAP framework, which provides a standardized authentication architecture for third parties. Therefore, attackers will carry attack information during the secondary authentication process based on the standardized architecture and the flexibility of the EAP framework to attack the user's private network. In addition, during the authentication process, the user name and password are generally transmitted in plain text, and the AAA server uses the user name and password as authentication credentials to implement access authentication. And plain text transmission means that the data is not encrypted during the transmission process, and it is easy to be intercepted and read by attackers, resulting in data leakage. Once the user name and password are leaked, attackers will disguise themselves as real users to attack the user's private network, resulting in security risks for the user's internal network.

[0004] Therefore, it is necessary to provide a user access authentication system with high security and good stability. Summary of the Invention

[0005] In view of the above analysis, embodiments of the present invention aim to provide a user access authentication system to solve the problem of poor security of user access authentication in the VPDN service in the prior art.

[0006] An embodiment of the present invention provides a user access authentication system, which includes: a dedicated terminal, a carrier network side, an enhanced LNS AAA side, and a dedicated network side;

[0007] Among them, the dedicated terminal is used to generate an enhanced password and send a user activation request to the carrier network side based on the enhanced password; the carrier network side establishes an L2TP tunnel with the enhanced LNS AAA side based on the user activation request and sends the enhanced password to the enhanced LNS AAA side; the enhanced LNS AAA side performs enhanced authentication verification based on the enhanced password. If the enhanced authentication verification passes, the dedicated terminal and the dedicated network side perform service data interaction.

[0008] Based on a further improvement of the above system, the enhanced password includes: a message type, a message length, and a message body; among them, the message type is used to distinguish the importance level of the enhanced password, and the message length is used to represent the length of the message body.

[0009] Based on a further improvement of the above system, the message body includes: a dedicated identifier, a communication identity, a freshness factor, and an authentication code; among them, the dedicated identifier is used to distinguish each dedicated terminal in the system, the communication identity is used to represent the communication number, the freshness factor is used to represent the generation time of the enhanced password, and the authentication code is used for enhanced authentication verification.

[0010] Based on a further improvement of the above system, the message type includes: primary enhancement, where neither the dedicated identifier nor the communication identity in the message body of the enhanced password can be empty; secondary enhancement, where the dedicated identifier in the message body of the enhanced password cannot be empty and the communication identity is empty.

[0011] Based on a further improvement of the above system, the sending of the enhanced password to the enhanced LNS AAA side includes: the carrier network side sets the AVPType value in the Proxy Authen Response to 33 based on the RFC2661 L2TP protocol standard, sets the value of the Proxy Authen Response to the enhanced password, and sends the updated Proxy Authen Response to the enhanced LNS AAA side.

[0012] Based on a further improvement of the above system, the dedicated terminal and the enhanced LNS AAA side pre-set an identifier-identity relationship, and the identifier-identity relationship refers to the corresponding relationship between the dedicated identifier and the communication identity.

[0013] Based on further improvements to the above system, the dedicated terminal is used to generate an enhanced password, including: determining the message type based on service requirements, obtaining the dedicated identifier and communication identity of the current dedicated terminal based on the message type, generating a freshness factor based on the system time, generating an authentication code using the SM-HMAC algorithm based on the freshness factor, dedicated identifier, and communication identity, and calculating the length of the message body as the message length; generating an enhanced password based on the message type, message length, dedicated identifier, communication identity, freshness factor, and authentication code.

[0014] Based on further improvements to the above system, the enhanced LNS AAA end performs enhanced authentication verification based on the enhanced password, including: the enhanced LNS AAA end parses the received enhanced password to obtain the first message type, first message length, first dedicated identifier, first communication identity, first freshness factor, and first authentication code; if the data types of the first dedicated identifier and the first communication identity conform to the first message type, and the relationship between the first dedicated identifier and the first communication identity conforms to the identifier-identity relationship, then calculate the second message length of the first dedicated identifier, first communication identity, first freshness factor, and first authentication code. If the first message length is consistent with the second message length, then generate a second authentication code using the SM-HMAC algorithm based on the first dedicated identifier, first communication identity, and first freshness factor, and compare whether the first authentication code and the second authentication code are consistent. If they are consistent, the verification is successful.

[0015] Based on further improvements to the above system, when the dedicated terminal re-enters the network for access authentication, it updates the freshness factor to prevent network replay attacks.

[0016] Based on further improvements to the above system, sending a user activation request to the operator network end based on the enhanced password includes: obtaining subscription information, where the subscription information includes APN / DNN, QoS, TEID; obtaining negotiation information, where the negotiation information refers to the information negotiated between the user equipment UE and the mobility management entity MME or the access and mobility management function AMF; sending a user activation request to the operator network end based on the enhanced password, subscription information, and / or negotiation information.

[0017] Compared with the prior art, the present invention can at least achieve one of the following beneficial effects:

[0018] The present invention provides a user access authentication system. By customizing and enhancing the capabilities of commercial LNS AAA devices, a point-to-point access based on enhanced passwords is constructed between dedicated terminals and enhanced LNS AAA devices without the awareness of the mobile operator network, thereby avoiding the security risks of the user's private network caused by the leakage of user sensitive data. In addition, by analyzing the service characteristics of the operator's VPDN and based on the standard L2TP / PPP protocol, without modifying the standard authentication process, specific fields of the communication standard protocol are used to carry enhanced passwords to cover information such as user passwords, thereby realizing the enhanced function of user access authentication and ensuring that attackers cannot conduct access attacks through user identities.

[0019] In the present invention, the above technical solutions can also be combined with each other to achieve more preferred combination solutions. Other features and advantages of the present invention will be described in the subsequent specification, and some advantages can be made obvious from the specification or understood by implementing the present invention. The objectives and other advantages of the present invention can be realized and obtained through the content specifically pointed out in the specification and the drawings. BRIEF DESCRIPTION OF THE DRAWINGS

[0020] The drawings are only for the purpose of showing specific embodiments and are not considered as limiting the present invention. Throughout the drawings, the same reference signs denote the same components;

[0021] Figure 1 It is an example diagram of a user access authentication system in an embodiment of the present invention;

[0022] Figure 2 It is an example diagram of the enhanced password format in an embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0023] The following will specifically describe the preferred embodiments of the present invention in conjunction with the drawings. The drawings form a part of this application and are used together with the embodiments of the present invention to explain the principles of the present invention, rather than to limit the scope of the present invention.

[0024] UPF (User Plane Function) is a key component in the 5G Core (5GC) architecture, responsible for processing the transmission and related control of user data. Its main functions include: data forwarding and routing, policy implementation, QoS guarantee, traffic aggregation and control, security and encryption, network slice support, etc.

[0025] The PGW (PDN Gateway) is an important network element in the 4G core network (EPC, Evolved Packet Core), mainly responsible for the processing and control of user data. Its main functions include: user session management, data forwarding and anchoring, IP address allocation, charging and policy control, and lawful interception.

[0026] APN / DNN (Access Point Name / Data Network Name) is the name used to identify the external data network to which a user equipment (UE) in a mobile network is to connect. It consists of two parts: the network ID, which represents an external network, and the operator ID, which indicates which operator it belongs to.

[0027] QoS (Quality of Service) refers to the quality of network service. It is a mechanism used to manage and optimize network resources to ensure that different types of network traffic (such as voice, video, data, etc.) can obtain the corresponding quality of service according to their requirements. QoS usually involves the following aspects: bandwidth management, delay control, and packet loss rate control. In the 5G network, QoS is crucial for supporting various different types of applications (such as the Internet of Things, autonomous driving, etc.).

[0028] TEID (Tunnel Endpoint Identifier) is the tunnel endpoint identifier. It is an important field in the GTP (GPRS Tunnelling Protocol) protocol and is used to identify the tunnel endpoints in the GTP-U or GTP-C protocol.

[0029] A specific embodiment of the present invention discloses a user access authentication system, which includes: a dedicated terminal, an operator network side, an enhanced LNS AAA side, and a dedicated network side;

[0030] Among them, the dedicated terminal is used to generate an enhanced password and send a user activation request to the operator network side based on the enhanced password; the operator network side establishes an L2TP tunnel with the enhanced LNS AAA side based on the user activation request and sends the enhanced password to the enhanced LNS AAA side; the enhanced LNS AAA side performs enhanced authentication verification based on the enhanced password. If the enhanced authentication verification passes, the dedicated terminal and the dedicated network side perform service data interaction, as Figure 1 shown.

[0031] Exemplarily, the dedicated terminal is the user terminal, and its devices are handheld terminals, computer terminals, etc. that have the VPDN service enabled. The operator network side is the operator's 4G / 5G core network, such as the UPF and PGW that are docked with the enhanced LNS AAA and establish an L2TP tunnel. The enhanced LNS AAA side refers to the device that has undergone customized enhancement transformation of the functions of the commercial LNS AAA device to support enhanced password verification. The dedicated network side refers to the target network of the user terminal, that is, the private network, such as office automation systems, mail systems, remote medical systems, government affairs office systems, educational administration systems, etc.

[0032] Among them, the enhanced LNS AAA is docked with the operator network through the standard L2TP / PPP protocol, and a certification enhancement service based on SM-HMAC is customized on the basis of the standard VPDN access commercial process, so as to realize the point-to-point certification enhancement ability from the dedicated terminal to the enhanced LNS AAA and meet the high-security access requirements of the user's dedicated network. The certification enhancement between the enhanced LNS AAA and the dedicated terminal follows the standard RFC 1334 PAP protocol and RFC RFC2661 L2TP protocol. Based on multiple factors such as the communication identities of the terminal IMSI, MSISDN, etc. and the dedicated identifier of the terminal, the dedicated terminal and the enhanced LNS AAA customize the certification enhancement service, enhance and replace the user password field in the standard certification protocol, without modifying the protocol itself. The specific definition of the enhanced password field can be formulated and adjusted according to the actual security protection design. The enhanced LNS AAA establishes an L2TP tunnel with the LAC side of the operator network (for example, UPF or PGW), supports the establishment of a PPP session with the LAC to complete the user's VPDN network access, and the dedicated terminal and the enhanced LNS AAA perform enhanced authentication transformation and are embedded in the standard process of VPDN access authentication.

[0033] Among them, the enhanced password includes: message type, message length, and message body. For the message type, it is used to distinguish the importance level of the enhanced password. In different application scenarios, technicians can design different message types. For example, for level 1 enhancement, 0x01, both the dedicated identifier and the communication identity in the message body of the enhanced password cannot be empty; for level 2 enhancement, 0x02, the dedicated identifier in the message body of the enhanced password cannot be empty, and the communication identity is empty; for level 3 enhancement, 0x03, the dedicated identifier in the message body of the enhanced password is empty, and the communication identity cannot be empty; for level 4 enhancement, 0x04, both the dedicated identifier and the communication identity in the message body of the enhanced password are empty. For the message length, it is used to represent the length of the message body. For the message body, it includes: dedicated identifier, communication identity, freshness factor, and authentication code. Among them, the dedicated identifier is used to distinguish each dedicated terminal in the system. The system administrator or technician needs to pre-assign a unique number to each dedicated terminal to implement the subsequent user access authentication process. Here, no specific form of the number is limited, as long as it can distinguish the user terminals in the system. The communication identity is used to represent the communication number, such as IMSI, MSISDN, etc. The freshness factor is used to represent the generation time of the enhanced password, and the authentication code is used for enhanced verification authentication. An example diagram of the enhanced password is as shown in Figure 2 shown.

[0034] Exemplarily, in the authentication enhancement scheme, based on the PAP authentication process, the user's enhanced password is replaced, and the password field is securely enhanced according to the principle of "changing once per use". Each time the dedicated terminal restarts, enters flight mode, or is triggered to re-authenticate for network access in other ways, the freshness factor will be changed to prevent network replay attacks. Therefore, when the dedicated terminal re-authenticates for network access, it will update the freshness factor.

[0035] Exemplarily, the message type and message length occupy 4 bytes, and the message body occupies 4*n bytes, where n = 1, 2, 3,..., N. It can be understood that the system management user or technician can set the corresponding relationship between the dedicated identifier and the communication identity based on business requirements, and pre-store the record of the corresponding relationship (such as a relationship mapping table, etc.) in the dedicated terminal and the enhanced LNS AAA end to meet the subsequent user access authentication process. Among them, the corresponding relationship is a 1:N (that is, 1 dedicated terminal identifier corresponds to multiple communication identities) relationship.

[0036] The dedicated terminal is used to generate the enhanced password, including:

[0037] Determine the message type based on business requirements, obtain the dedicated identifier and communication identity of the current dedicated terminal based on the message type, generate a freshness factor based on the system time, generate an authentication code using the SM-HMAC algorithm based on the freshness factor, dedicated identifier, and communication identity, and calculate the length of the message body as the message length; generate an enhanced password based on the message type, message length, dedicated identifier, communication identity, freshness factor, and authentication code. Among them, the business requirements are used to specify the importance level of the message type.

[0038] Sending a user activation request to the operator network side based on the enhanced password includes:

[0039] A1: Obtain subscription information, where the subscription information includes APN / DNN, QoS, TEID.

[0040] A2: Obtain negotiation information, where the negotiation information refers to the information after negotiation between the user equipment UE and the mobility management entity MME or the access and mobility management function AMF.

[0041] Specifically, in the 4G LTE network, the negotiation process between the UE (user equipment) and the MME (mobility management entity, Mobile Management Entity) mainly involves the following steps:

[0042] Initial attachment: After the UE is powered on, it first performs the initial attachment process. The UE will send an AttachRequest message to the eNodeB (base station), and the eNodeB will forward the message to the MME. After receiving the Attach Request message, the MME will perform a series of authentication and authorization processes, including interacting with the HSS (home subscriber server) to verify the user's identity and subscription information. The MME will allocate a temporary mobile subscriber identification number (TMSI) for the UE and include it in the Attach Accept message and send it to the UE.

[0043] Security mode control: The MME will send a Security Mode Command message to the UE to start the security mode control process. After receiving the Security Mode Command message, the UE will execute the corresponding security algorithm and include the result in the Security Mode Complete message and return it to the MME.

[0044] Session establishment: The UE sends a Service Request message to the MME to request the establishment of a data session. After receiving the Service Request message, the MME interacts with the SGW (Serving Gateway) and the PGW (Packet Data Network Gateway) to establish a data tunnel. The MME sends a ServiceAccept message to the UE to notify the UE that the data session has been successfully established.

[0045] Mobility management: When the UE moves within the LTE network, the eNodeB detects the UE's movement and sends a Handover Required message to the MME. The MME coordinates the handover process between the target eNodeB and the source eNodeB, including data forwarding and path switching. After the handover is completed, the MME sends a Handover Command message to the UE to notify the UE that the handover was successful.

[0046] Detachment process: When the UE powers off or leaves the LTE network, it sends a Detach Request message to the MME. After receiving the Detach Request message, the MME interacts with the SGW and the PGW to release the relevant resources and sends a DetachAccept message to the UE. During the entire negotiation process, the MME plays a core control role, responsible for managing functions such as the UE's mobility, session establishment, and security authentication. The communication between the UE and the MME is forwarded through the eNodeB, which plays a role in wireless access.

[0047] Specifically, in a 5G network, the negotiation process between the UE (User Equipment) and the AMF (Access and Mobility Management Function) involves multiple steps, including registration requests, authentication, and security context establishment. The following is the main information after the UE and the AMF have negotiated:

[0048] Registration request: The UE sends a registration request to the AMF. The main parameters included are: Message type: Registration request, indicating that this is a registration request; 5GS registration type: initial registration, indicating that this is an initial registration; Security header type has a value of 0, indicating an unencrypted plaintext NAS message; NAS keyset identifier: used for the identification of the security context; 5GS mobile identity: 5G user identity, which can be 5G-GUTI or SUCI; UE security capability: the encryption and integrity protection algorithms supported by the UE.

[0049] Authentication process: The AMF queries the NRF based on the Routing Indicator provided in the UE registration request to obtain the home AUSF, and then performs authentication with the AUSF to obtain authentication parameters. The authentication process includes sub-processes such as obtaining authentication data, two-way authentication between the UE and the serving network, and authentication confirmation by the home network.

[0050] Security context establishment: After the UE and the 5G network complete the authentication process, they negotiate the security algorithms and keys used for signaling encryption and integrity protection in the subsequent communication process through the NAS signaling encryption and integrity protection processes. The AMF combines the configured algorithm priorities and the security capabilities reported by the UE in the initial NAS message, selects the protection algorithm, calculates the key, and starts encryption and integrity protection.

[0051] Registration acceptance: The AMF sends a registration acceptance request to the UE, which contains the following information: the allocated temporary identifier (such as 5G-GUTI); PDU session status indication; allowed NSSAI (Network Slice Selection Assistance Information); configured NSSAI; LADN (Local Area Data Network) list information, etc.

[0052] RM status: Two RM states (RM-DEREGISTERED and RM-REGISTERED) are used in the UE and the AMF to reflect the registration status of the UE in the selected PLMN. In the RM-REGISTERED state, the UE can perform mobility registration update processes, periodic registration update processes, or perform a deregistration process when it is no longer necessary to register with the PLMN.

[0053] Security algorithms and keys: After the security algorithm negotiation between the UE and the AMF is completed, NAS messages between them are encrypted and integrity protected to improve the security of the network. In the 5G key architecture, the root key K is stored in the UDM and the USIM card, and keys such as KAUSF, KSEAF, and KAMF are derived layer by layer from the root key K.

[0054] A3: Send a user activation request to the operator network side based on the enhanced password, subscription information, and / or negotiation information.

[0055] Exemplarily, the dedicated terminal sends a user activation request to the operator network through a wireless interface (such as LTE / NR), and the request contains information such as the enhanced password, subscription information, and / or negotiation information.

[0056] The sending of the enhanced password to the enhanced LNS AAA side includes:

[0057] The operator network side sets the AVPType value in the Proxy AuthenResponse to 33 based on the RFC2661 L2TP protocol standard, sets the value of the Proxy Authen Response to the enhanced password, and sends the updated ProxyAuthen Response to the enhanced LNS AAA side. Preferably, in the present invention, the AVP Type value of the ProxyAuthenResponse in the ICCN control message in the L2TP session is set to 33, and the value of the Proxy Authen Response is set to the enhanced password.

[0058] The enhanced LNS AAA side performs enhanced authentication verification based on the enhanced password, including:

[0059] B1: The enhanced LNS AAA side parses the received enhanced password to obtain the first message type, the first message length, the first dedicated identifier, the first communication identity, the first freshness factor, and the first authentication code.

[0060] The present invention does not make specific limitations on the form of the enhanced password. It can adopt any one of the forms such as plain text, byte stream, binary encoding, JSON, XML, etc. And the methods for parsing each form are also common knowledge in the art, and the present invention does not make specific limitations on this. Preferably, when the enhanced password is a string, the enhanced LNS AAA side can use template parsing method, DOM parsing method, etc. to parse the enhanced password.

[0061] B2: If the data types of the first dedicated identifier and the first communication identity conform to the first message type, and the relationship between the first dedicated identifier and the first communication identity conforms to the identifier-identity relationship, then calculate the second message length of the first dedicated identifier, the first communication identity, the first freshness factor, and the first authentication code. If the first message length is consistent with the second message length, then generate the second authentication code based on the first dedicated identifier, the first communication identity, and the first freshness factor using the SM-HMAC algorithm, and compare whether the first authentication code and the second authentication code are consistent. If they are consistent, the verification is successful. Further, if the data types of the first dedicated identifier and the first communication identity conform to the first message type, but the relationship between the first dedicated identifier and the first communication identity does not conform to the identifier-identity relationship, the verification fails; if the data types of the first dedicated identifier and the first communication identity do not conform to the first message type, the verification fails; if the data types of the first dedicated identifier and the first communication identity conform to the first message type, but the relationship between the first dedicated identifier and the first communication identity does not conform to the identifier-identity relationship, the verification fails.

[0062] A specific embodiment of the present invention discloses an authentication process for a user access authentication system. Taking 5G as an example, it specifically includes:

[0063] After the dedicated terminal is powered on and for the first time when accessing the VPDN, when the user accesses the external PDN network service, set the APN, username, and enhanced password according to the activated VPDN service, select the authentication method as PAP. When the dedicated terminal is issued, initialize relevant resources (including information data such as dedicated identifiers for dedicated terminal initialization), and obtain the communication identity of the terminal (IMSI, MSISDN, etc.). Calculate the authentication code based on the parameter fields of the enhanced password using SM-HMAC, generate the enhanced password, and carry subscription information such as APN / DNN, QoS, TEID, etc. or information negotiated between the UE and the AMF, and initiate an activation request.

[0064] L2TP tunnel establishment: After the UPF receives the PFCP message, it confirms through AAA issuance or local configuration that it is an L2TP user and initiates the L2TP tunnel establishment.

[0065] L2TP session establishment: After the L2TP tunnel is established, the UPF initiates the L2TP session establishment process, establishes a user session with the enhanced LNS AAA, and the enhanced LNS AAA obtains the enhanced password for authentication verification during user authentication.

[0066] LCP negotiation: After the L2TP session is established, LCP negotiation is carried out. LCP negotiation is mainly used for link creation.

[0067] User authentication: After the LCP link negotiation is completed, according to the authentication type obtained from the LCP negotiation, the UPF initiates user authentication to the LNS, and performs the user authentication process with different authentication methods according to the negotiated authentication type. At the same time, the enhanced LNS AAA compares according to the enhanced password obtained during session establishment in the manner described in step B2 above. If the comparison is successful, it indicates that the enhanced password is legal and the user access authentication is successful. If the comparison fails, it indicates a risk of illegal tampering, etc., and the user access authentication fails, and subsequent user service data access will not be allowed.

[0068] IPCP negotiation: After the LCP link negotiation and authentication negotiation are completed, it enters the network negotiation stage. The UPF initiates IPCP negotiation according to the address type requested by the user during access, and can obtain information such as the UE IP address, DNS address, NBNS address, etc., and carry them to the SMF in the activation response message.

[0069] User activation response: After the IPCP negotiation ends, the operator network returns a user activation success response to the terminal.

[0070] Service access: After access authentication is completed, the user conducts service access, and realizes service data transmission through the L2TP tunnel to achieve intranet service access.

[0071] The present invention provides a user access authentication system. By customizing and enhancing the capabilities of commercial LNS AAA devices, a point-to-point access based on enhanced passwords between dedicated terminals and enhanced LNS AAA devices is constructed without the awareness of the mobile operator network, thereby avoiding the security risks of the user's private network caused by the leakage of user sensitive data. In addition, by analyzing the service characteristics of the operator's VPDN, based on the standard L2TP / PPP protocol, without modifying the standard authentication process, the enhanced password is carried in specific fields of the communication standard protocol to cover information such as the user password, and then the enhanced function of user access authentication is realized, ensuring that attackers cannot conduct access attacks through the user identity.

[0072] Those skilled in the art can understand that all or part of the processes of implementing the methods in the above embodiments can be completed by instructing relevant hardware through a computer program, and the program can be stored in a computer-readable storage medium. Among them, the computer-readable storage medium is a magnetic disk, an optical disc, a read-only memory or a random access memory, etc.

[0073] The above is only a preferred specific implementation manner of the present invention, but the protection scope of the present invention is not limited thereto. Any changes or substitutions that can be easily thought of by those skilled in the art within the technical scope disclosed by the present invention should be covered by the protection scope of the present invention.

Claims

1. A user access authentication system, characterized in that: The system includes: a dedicated terminal, an operator network terminal, an enhanced LNS AAA terminal, and a dedicated network terminal; The dedicated terminal is used to generate an enhanced password and send a user activation request to the operator network end based on the enhanced password; the operator network end establishes an L2TP tunnel with the enhanced LNS AAA end based on the user activation request and sends the enhanced password to the enhanced LNS AAA end; the enhanced LNS AAA end performs authentication enhancement verification based on the enhanced password, and if the authentication enhancement verification passes, the dedicated terminal interacts with the dedicated network end for service data.

2. A user access authentication system according to claim 1, characterized in that: The enhanced password includes: message type, message length and message body; The message type is used to distinguish the importance of the enhanced password, and the message length is used to indicate the length of the message body.

3. A user access authentication system according to claim 2, characterized in that: The message body includes: a dedicated identifier, a communication identity, a freshness factor and an authentication code; Among them, the dedicated identifier is used to distinguish each dedicated terminal in the system, the communication identity is used to indicate the communication number, the freshness factor is used to indicate the generation time of the enhanced password, and the authentication code is used for authentication enhancement verification.

4. A user access authentication system according to claim 3, characterized in that: The message types include: first-level enhancement, the dedicated identifier and the communication identity in the message body of the enhanced password cannot be empty; second-level enhancement, the dedicated identifier in the message body of the enhanced password cannot be empty, and the communication identity is empty.

5. A user access authentication system according to claim 4, characterized in that: The step of sending the enhanced password to the enhanced LNS AAA terminal comprises: The operator network end sets the AVP Type value in the Proxy Authen Response to 33 based on the RFC2661 L2TP protocol standard, sets the value of the Proxy Authen Response to the enhanced password, and sends the updated Proxy Authen Response to the enhanced LNS AAA end.

6. A user access authentication system according to claim 5, characterized in that: The dedicated terminal and the enhanced LNS AAA terminal preset an identifier-identity relationship, and the identifier-identity relationship refers to the corresponding relationship between the dedicated identifier and the communication identity.

7. A user access authentication system according to claim 6, characterized in that: The dedicated terminal is used to generate an enhanced password, including: Determine the message type based on the business requirements, obtain the dedicated identifier and communication identity of the current dedicated terminal based on the message type, generate a freshness factor based on the system time, generate an authentication code using the SM-HMAC algorithm based on the freshness factor, the dedicated identifier and the communication identity, and calculate the length of the message body as the message length; Generates an enhanced password based on the message type, message length, private identifier, communication identity, freshness factor, and authentication code.

8. A user access authentication system according to claim 7, characterized in that: The enhanced LNS AAA end performs enhanced authentication verification based on the enhanced password, including: The enhanced LNS AAA end parses the received enhanced password to obtain a first message type, a first message length, a first dedicated identifier, a first communication identity, a first freshness factor, and a first authentication code; If the data types of the first dedicated identifier and the first communication identity conform to the first message type, and the relationship between the first dedicated identifier and the first communication identity conforms to the identifier-identity relationship, then the second message length of the first dedicated identifier, the first communication identity, the first freshness factor and the first authentication code is calculated. If the first message length is consistent with the second message length, then the second authentication code is generated based on the first dedicated identifier, the first communication identity and the first freshness factor using the SM-HMAC algorithm. The first authentication code is compared with the second authentication code to see if they are consistent. If they are consistent, the verification is successful.

9. A user access authentication system according to claim 8, characterized in that: When the dedicated terminal re-enters the network for authentication, the freshness factor will be updated to prevent network replay attacks.

10. A user access authentication system according to claim 9, characterized in that: The sending a user activation request to the operator network terminal based on the enhanced password includes: Obtaining contract information, including APN / DNN, QoS, and TEID; Acquire negotiation information, where the negotiation information refers to information negotiated between the user equipment UE and the mobility management entity MME or the access and mobility management function AMF; A user activation request is sent to the operator network end based on the enhanced password, contract information and / or negotiation information.