Network access authentication method, device, equipment and medium

Through three interactions between the terminal device and the access device, network access authentication and key negotiation are completed, and the problem of low authentication efficiency in the prior art is solved, and security and efficiency are improved.

CN120128923APending Publication Date: 2025-06-10CHENGDU TD TECH LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202311680941.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2023-12-07
Publication Date
2025-06-10

AI Technical Summary

Technical Problem

The existing network access authentication method requires the terminal device to interact with the access device multiple times, resulting in low authentication efficiency.

Method used

The terminal device sends an authentication request to the access device, the access device generates a second authentication result and generates a unicast key, the terminal device generates a unicast key and a multicast key, and sends an authentication confirmation message to the access device, and the access device generates a multicast key and a third authentication result, completing the authentication process.

Benefits of technology

Through three interactions, authentication and key negotiation are completed, authentication efficiency is improved and the security of terminal equipment access to the network is enhanced.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120128923A_ABST
    Figure CN120128923A_ABST
Patent Text Reader

Abstract

The invention provides a network access authentication method and device, equipment and a medium, which can be applied to the technical field of communication. In the method, after a terminal device sends an authentication request to an access device, the access device generates a second authentication result, after the second authentication result indicates that authentication is passed, a unicast key is generated, and then an authentication response message is sent to the terminal device. And the terminal equipment generates a unicast key and a first authentication result, generates a multicast key when the first authentication result indicates that the authentication is passed, and then sends an authentication confirmation message to the access equipment. And the access device generates a multicast key and a third authentication result to complete the authentication process. According to the scheme, the authentication process is completed through three times of interaction between the terminal equipment and the access equipment, and the authentication efficiency is effectively improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of communication technologies, and in particular, to an access authentication method, apparatus, device, and medium. Background Art

[0002] Compared with the Ethernet environment that uses network interfaces and network cables as propagation media, the wireless network uses air as the propagation media, and all terminals can obtain the surrounding wireless communication data. Since the wireless network does not support the Ethernet physical isolation method, identity authentication and access control are particularly important in wireless network security.

[0003] In the prior art, when a terminal device wants to access the network, it needs to perform identity authentication. The authentication process requires the participation of an access device in the network. The access device sends a unicast key negotiation request packet to the terminal device, and the terminal device returns a unicast key negotiation response packet. Then, the access device sends a unicast key negotiation confirmation packet to the terminal device to complete the negotiation of the unicast key. The access device then sends a multicast key announcement packet to the terminal device, and the terminal device returns a multicast key response packet to complete the negotiation of the multicast key. After the negotiation of the unicast key and the multicast key is completed, it indicates that the terminal device authentication is successful, and the terminal device can access the network.

[0004] In summary, the existing access authentication method requires multiple interactions between the terminal device and the access device, resulting in low authentication efficiency. Summary of the Invention

[0005] Embodiments of this application provide an access authentication method, apparatus, device, and medium, which are used to solve the problem that the existing access authentication method requires multiple interactions between the terminal device and the access device, resulting in low authentication efficiency.

[0006] In a first aspect, an embodiment of this application provides an access authentication method applied to a terminal device. The method includes:

[0007] Sending an authentication request to an access device, where the authentication request includes first encrypted data and an obtained device identifier to be verified of the access device, and the first encrypted data is data obtained by encrypting a first random number generated using a pre-shared key;

[0008] Receiving an authentication response message sent by the access device, where the authentication response message includes second encrypted data and first verification data;

[0009] Generating a unicast key and a first authentication result according to the pre-shared key, the second encrypted data, the first random number, the device identifier to be verified, and the first verification data, where the first authentication result is used to indicate whether the access device authentication is passed or not;

[0010] If the first authentication result indicates that the access device passes the authentication, generate a multicast key and second verification data according to the unicast key, the second encrypted data, and the device identifier to be verified;

[0011] Send an authentication confirmation message to the access device, where the authentication confirmation message includes the second verification data.

[0012] In a specific implementation manner, the generating the unicast key and the first authentication result according to the pre-shared key, the second encrypted data, the first random number, the device identifier to be verified, and the first verification data includes:

[0013] Decrypt the second encrypted data according to the pre-shared key to obtain a second random number;

[0014] Generate the unicast key according to the pre-shared key, the first random number, and the second random number;

[0015] Generate third verification data according to the unicast key, the second encrypted data, and the device identifier to be verified;

[0016] If the third verification data is the same as the first verification data, generate a first authentication result indicating that the access device passes the authentication;

[0017] If the third verification data is different from the first verification data, generate a first authentication result indicating that the access device fails the authentication.

[0018] In a specific implementation manner, the generating the multicast key and the second verification data according to the unicast key, the second encrypted data, and the device identifier to be verified includes:

[0019] Generate the multicast key using a preset key generation algorithm and the unicast key;

[0020] Generate the second verification data according to the multicast key, the second encrypted data, and the device identifier to be verified.

[0021] In a second aspect, an embodiment of the present application provides an access network authentication method applied to an access device, and the method includes:

[0022] Receive an authentication request sent by a terminal device, where the authentication request includes first encrypted data and a device identifier to be verified;

[0023] Generate a second authentication result according to the device identifier to be verified and the target device identifier of the access device, where the second authentication result is used to indicate whether the terminal device passes the preliminary authentication or not;

[0024] If the second authentication result indicates that the preliminary authentication of the terminal device is passed, generate a unicast key, second encrypted data, and first verification data according to the pre-shared key, the first encrypted data, the generated second random number, and the target device identifier;

[0025] Send an authentication response message to the terminal device, where the authentication response message includes the second encrypted data and the first verification data;

[0026] Receive an authentication confirmation message sent by the terminal device, where the authentication confirmation message includes second verification data;

[0027] Generate a multicast key and a third authentication result according to the unicast key, the second encrypted data, the target device identifier, and the second verification data to complete the authentication process, and the third authentication result is used to indicate whether the secondary authentication of the terminal device is passed or not passed.

[0028] In a specific embodiment, the generating the second authentication result according to the device identifier to be verified and the target device identifier of the access device includes:

[0029] If the device identifier to be verified is the same as the target device identifier, generate a second authentication result indicating that the preliminary authentication of the terminal device is passed;

[0030] If the device identifier to be verified is different from the target device identifier, generate a second authentication result indicating that the preliminary authentication of the terminal device fails.

[0031] In a specific embodiment, the generating the unicast key, the second encrypted data, and the first verification data according to the pre-shared key, the first encrypted data, the generated second random number, and the target device identifier includes:

[0032] Decrypt the first encrypted data according to the pre-shared key to obtain a first random number;

[0033] Generate the unicast key according to the pre-shared key, the first random number, and the second random number;

[0034] Encrypt the second random number with the pre-shared key to obtain the second encrypted data;

[0035] Generate the first verification data according to the unicast key, the second encrypted data, and the target device identifier.

[0036] In a specific embodiment, the generating the multicast key and the third authentication result according to the unicast key, the second encrypted data, the target device identifier, and the second verification data includes:

[0037] Generate the multicast key by using a preset key generation algorithm and the unicast key;

[0038] Generate fourth verification data according to the multicast key, the second encrypted data, and the target device identifier;

[0039] If the fourth verification data is the same as the second verification data, generate a third authentication result indicating that the secondary authentication of the terminal device has passed;

[0040] If the fourth verification data is different from the second verification data, generate a third authentication result indicating that the secondary authentication of the terminal device has not passed.

[0041] In a third aspect, an embodiment of the present application provides an access authentication device, including:

[0042] A sending module, configured to send an authentication request to an access device, where the authentication request includes first encrypted data and the to-be-verified device identifier of the obtained access device, and the first encrypted data is data obtained by encrypting a first random number generated by using a pre-shared key;

[0043] A receiving module, configured to receive an authentication response message sent by the access device, where the authentication response message includes second encrypted data and first verification data;

[0044] A security module, configured to:

[0045] Generate a unicast key and a first authentication result according to the pre-shared key, the second encrypted data, the first random number, the to-be-verified device identifier, and the first verification data, where the first authentication result is used to indicate whether the access device authentication has passed or not;

[0046] If the first authentication result indicates that the access device authentication has passed, generate a multicast key and second verification data according to the unicast key, the second encrypted data, and the to-be-verified device identifier;

[0047] The sending module is further configured to send an authentication confirmation message to the access device, where the authentication confirmation message includes the second verification data.

[0048] In a fourth aspect, an embodiment of the present application provides an access authentication device, including:

[0049] A receiving module, configured to receive an authentication request sent by a terminal device, where the authentication request includes first encrypted data and a to-be-verified device identifier;

[0050] A security module, configured to:

[0051] Generate a second authentication result based on the device identifier to be verified and the target device identifier of the access device, where the second authentication result is used to indicate whether the preliminary authentication of the terminal device is passed or not;

[0052] If the second authentication result indicates that the preliminary authentication of the terminal device is passed, generate a unicast key, second encrypted data, and first verification data based on the pre-shared key, the first encrypted data, the generated second random number, and the target device identifier;

[0053] A sending module, configured to send an authentication response message to the terminal device, where the authentication response message includes the second encrypted data and the first verification data;

[0054] The receiving module is further configured to receive an authentication confirmation message sent by the terminal device, where the authentication confirmation message includes second verification data;

[0055] The security module is further configured to generate a multicast key and a third authentication result based on the unicast key, the second encrypted data, the target device identifier, and the second verification data, to complete the authentication process, where the third authentication result is used to indicate whether the secondary authentication of the terminal device is passed or not.

[0056] In a fifth aspect, an embodiment of the present application provides an electronic device, including:

[0057] A processor, a memory, and a communication interface;

[0058] The memory is used to store executable instructions of the processor;

[0059] Wherein, the processor is configured to execute the network access authentication method according to any one of the first aspect via executing the executable instructions.

[0060] In a sixth aspect, an embodiment of the present application provides an electronic device, including:

[0061] A processor, a memory, and a communication interface;

[0062] The memory is used to store executable instructions of the processor;

[0063] Wherein, the processor is configured to execute the network access authentication method according to any one of the second aspect via executing the executable instructions.

[0064] In a seventh aspect, an embodiment of the present application provides a readable storage medium, on which a computer program is stored, and when the computer program is executed by a processor, it implements the network access authentication method according to any one of the first aspect or the second aspect.

[0065] In an eighth aspect, an embodiment of the present application provides a computer program product, including a computer program, which when executed by a processor is used to implement the network access authentication method described in any one of the first aspect or the second aspect.

[0066] In the network access authentication method, device, equipment and medium provided by the embodiments of the present application, after the terminal device sends an authentication request to the access device, the access device generates a second authentication result. After the second authentication result indicates that the authentication is passed, a unicast key is generated, and then an authentication response message is sent to the terminal device. The terminal device generates a unicast key and a first authentication result. When the first authentication result indicates that the authentication is passed, a multicast key is generated, and then an authentication confirmation message is sent to the access device. The access device generates a multicast key and a third authentication result to complete the authentication process. This solution completes the authentication process through three interactions between the terminal device and the access device, effectively improving the authentication efficiency. BRIEF DESCRIPTION OF THE DRAWINGS

[0067] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the drawings in the following description are some embodiments of the present application. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.

[0068] Figure 1 It is a schematic diagram of the application scenario of the network access authentication method provided by the present application;

[0069] Figure 2 It is a schematic flowchart of the first embodiment of the network access authentication method provided by the present application;

[0070] Figure 3 It is a schematic flowchart of the second embodiment of the network access authentication method provided by the present application;

[0071] Figure 4 It is a schematic flowchart of the third embodiment of the network access authentication method provided by the present application;

[0072] Figure 5 It is a schematic flowchart of the fourth embodiment of the network access authentication method provided by the present application;

[0073] Figure 6 It is a schematic structural diagram of the first embodiment of the network access authentication device provided by the present application;

[0074] Figure 7 It is a schematic structural diagram of the second embodiment of the network access authentication device provided by the present application;

[0075] Figure 8 It is a schematic structural diagram of an electronic device provided by the present application Figure 1 ;

[0076] Figure 9 Structural schematic diagram of an electronic device provided for this application Figure 2 。 Specific implementation manners

[0077] To make the objectives, technical solutions and advantages of the embodiments of this application clearer, the technical solutions in the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings in the embodiments of this application. Obviously, the described embodiments are some but not all of the embodiments of this application. Based on the embodiments in this application, all other embodiments obtained by those of ordinary skill in the art under the inspiration of this embodiment belong to the scope protected by this application.

[0078] The terms "first", "second", "third", "fourth", etc. (if any) in the specification and claims of this application and the above-mentioned accompanying drawings are used to distinguish similar objects and do not necessarily need to be used to describe a specific order or sequence. It should be understood that such used data may be interchanged under appropriate circumstances so that the embodiments of this application described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "include" and "have" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product or device that includes a series of steps or units does not necessarily need to be limited to those steps or units clearly listed, but may include other steps or units not clearly listed or inherent to these processes, methods, products or devices.

[0079] With the development of technology, wireless networks use air as the propagation medium, and all terminals can obtain the surrounding wireless communication data. Since wireless networks do not support the physical isolation method of Ethernet, authentication and access control are particularly important in wireless network security.

[0080] In the prior art, when a terminal device wants to access the network, it needs to perform identity authentication. The authentication process requires the participation of an access device in the network. The access device sends a unicast key negotiation request packet to the terminal device, and the terminal device returns a unicast key negotiation response packet. Then, the access device sends a unicast key negotiation confirmation packet to the terminal device to complete the negotiation of the unicast key. The access device then sends a multicast key announcement packet to the terminal device, and the terminal device returns a multicast key response packet to complete the negotiation of the multicast key. After the negotiation of the unicast key and the multicast key is completed, it indicates that the terminal device authentication is successful, and the terminal device can access the network. The identity authentication process requires five interactions between the terminal device and the access device, which may lead to the problem of low authentication efficiency.

[0081] In view of the problems existing in the prior art, the inventors found during the research on the network access authentication method that during the network access authentication process, not only the terminal device and the access device need to be authenticated, but also the unicast key and the multicast key need to be negotiated during this process. Therefore, as long as the authentication and key negotiation can be completed, the network access authentication can be achieved. Therefore, the interaction process between the terminal device and the access device can be reduced to three times, enabling the authentication and key negotiation to be completed through three interactions, thereby improving the authentication efficiency. After the terminal device sends an authentication request to the access device, the access device generates a second authentication result. After the second authentication result indicates that the authentication is passed, a unicast key is generated, and then an authentication response message is sent to the terminal device. The terminal device generates a unicast key and a first authentication result. When the first authentication result indicates that the authentication is passed, a multicast key is generated, and then an authentication confirmation message is sent to the access device. The access device generates a multicast key and a third authentication result, completing the authentication process. Based on the above inventive concept, the network access authentication scheme in this application is designed.

[0082] Exemplarily, Figure 1 FIG. is a schematic diagram of an application scenario of the network access authentication method provided by this application. As Figure 1 shown, this application scenario may include: a terminal device 11 and an access device 12.

[0083] Exemplarily, in Figure 1 the application scenario shown, the access device 12 is located in a wireless network. At this time, the terminal device 11 has not yet accessed the wireless network. The terminal device 11 needs to access the wireless network to perform access, and the terminal device 11 sends an authentication request to the access device 12 in the network.

[0084] The access device 12 performs a preliminary authentication on the terminal device 11 according to the to-be-verified identifier in the authentication request and its own target device identifier, and generates a second authentication result. After the second authentication result indicates that the preliminary authentication of the terminal device is passed, a unicast key is generated, and then an authentication response message is sent to the terminal device 11.

[0085] After receiving the authentication response message, the terminal device 11 generates a unicast key, and authenticates the access device 12 according to the second encrypted data and the first check data in the authentication response message, generating a first authentication result. When the first authentication result indicates that the authentication of the access device is passed, a multicast key is generated, and then an authentication confirmation message is sent to the access device 12.

[0086] After receiving the authentication confirmation message, the access device 12 generates a multicast key, and performs a secondary authentication on the terminal device 11 according to the second check data in the authentication confirmation message, generating a third authentication result, completing the authentication process.

[0087] When the third authentication result indicates that the secondary authentication of the terminal device is passed, the terminal device 11 is allowed to access the network.

[0088] It should be noted that Figure 1 This is only a schematic diagram of an application scenario provided by the embodiments of the present application. The embodiments of the present application do not limit Figure 1 the actual forms of various devices included therein, nor do they limit Figure 1 the interaction methods between the devices therein. In the specific application of the solution, it can be set according to actual needs.

[0089] Next, the technical solution of the present application will be described in detail through specific embodiments. It should be noted that the following several specific embodiments can be combined with each other, and the same or similar concepts or processes may not be repeated in some embodiments.

[0090] Figure 2 FIG. is a schematic flowchart of the first embodiment of the network access authentication method provided by the present application. The embodiments of the present application will describe the situation where the terminal device and the access device perform three interactions to complete the network access authentication. The method in this embodiment can be implemented by software, hardware, or a combination of software and hardware. As Figure 2 shown, the network access authentication method specifically includes the following steps:

[0091] S201: The terminal device sends an authentication request to the access device.

[0092] In this step, when the terminal device wants to access the network, it needs to obtain the to-be-verified identifier of the access device in the network, and encrypt the first random number generated by using the pre-shared key to obtain the first encrypted data, and then send an authentication request to the access device in the network. The authentication request includes the first encrypted data and the to-be-verified device identifier.

[0093] S202: After receiving the authentication request sent by the terminal device, the access device generates a second authentication result according to the to-be-verified device identifier and the target device identifier of the access device.

[0094] In this step, after the terminal device sends an authentication request to the access device, the access device can receive the authentication request, and then perform a preliminary authentication on the terminal device according to the to-be-verified device identifier and the target device identifier in the authentication request, and generate a second authentication result. The second authentication result is used to indicate whether the preliminary authentication of the terminal device passes or fails.

[0095] Specifically, the authentication can be performed according to whether the to-be-verified device identifier is the same as the target device identifier, because if there is no problem with the terminal device and the wireless network, the two identifiers should be the same.

[0096] If the to-be-verified device identifier is the same as the target device identifier, a second authentication result indicating that the preliminary authentication of the terminal device passes is generated;

[0097] If the device identifier to be verified is different from the target device identifier, a second authentication result indicating that the preliminary authentication of the terminal device fails is generated.

[0098] S203: If the second authentication result indicates that the preliminary authentication of the terminal device passes, the access device generates a unicast key, second encrypted data, and first verification data according to the pre-shared key, first encrypted data, generated second random number, and target device identifier.

[0099] In this step, after the access device generates the second authentication result, if the second authentication result indicates that the preliminary authentication of the terminal device passes, the access device generates a second random number, and then generates a unicast key, second encrypted data, and first verification data according to the pre-shared key, first encrypted data in the authentication request, second random number, and target device identifier.

[0100] The unicast key can be generated according to the pre-shared key, first encrypted data, and second random number, the second encrypted data can be generated according to the pre-shared key and second random number, and the first verification data can be generated according to the unicast key, second encrypted data, and target device identifier.

[0101] It should be noted that if the second authentication result indicates that the preliminary authentication of the terminal device fails, it means that the terminal device is not secure, then this terminal device is not allowed to access the network and access the network, and the authentication process ends.

[0102] It should be noted that if the second authentication result indicates that the preliminary authentication of the terminal device fails, the access device can send the second authentication result to the terminal device.

[0103] S204: The access device sends an authentication response message to the terminal device.

[0104] In this step, after the access device generates the unicast key, second encrypted data, and first verification data, in order to enable the terminal device to know that the preliminary verification passes, and for the subsequent terminal device to authenticate the access device, generate a unicast key and a multicast key, the access device needs to send an authentication response message to the terminal device, and the authentication response message includes the second encrypted data and the first verification data.

[0105] It should be noted that the authentication response message may also include the second authentication result.

[0106] S205: After receiving the authentication response message sent by the access device, the terminal device generates a unicast key and a first authentication result according to the pre-shared key, second encrypted data, first random number, device identifier to be verified, and first verification data.

[0107] In this step, after the access device sends an authentication response message to the terminal device, the terminal device can receive the authentication response message, learn that the preliminary authentication is passed, and needs to generate a unicast key and authenticate the access device. According to the pre-shared key, the first random number, the device identifier to be verified, and the second encrypted data and the first verification data in the authentication response message, a unicast key and a first authentication result are generated. The first authentication result is used to indicate whether the access device is authenticated successfully or not.

[0108] A unicast key can be generated according to the pre-shared key, the second encrypted data, and the first random number, and then a first authentication result is generated according to the unicast key, the second encrypted data, the device identifier to be verified, and the first verification data.

[0109] S206: If the first authentication result indicates that the access device is authenticated successfully, the terminal device generates a multicast key and a second verification data according to the unicast key, the second encrypted data, and the device identifier to be verified.

[0110] In this step, after the terminal device generates the first authentication result, if the first authentication result indicates that the access device is authenticated successfully, the terminal device generates a multicast key and a second verification data according to the unicast key, the second encrypted data, and the device identifier to be verified.

[0111] Specifically, a preset key generation algorithm and the unicast key are used to generate the multicast key.

[0112] Furthermore, according to the multicast key, the second encrypted data, and the device identifier to be verified, a second verification data is generated by using a hash algorithm.

[0113] It should be noted that if the first authentication result indicates that the access device is not authenticated successfully, it means that the access device is not secure. Then the terminal device will not access the network and end the authentication process.

[0114] It should be noted that if the first authentication result indicates that the access device is not authenticated successfully, the terminal device can send the first authentication result to the access device.

[0115] S207: The terminal device sends an authentication confirmation message to the access device.

[0116] In this step, after the terminal device generates the multicast key and the second verification data, in order to let the access device know that the authentication is passed and for the subsequent secondary authentication of the terminal device by the access device and the generation of the multicast key, the terminal device needs to send an authentication confirmation message to the access device. The authentication confirmation message includes the second verification data.

[0117] S208: After the access device receives the authentication confirmation message sent by the terminal device, it generates a multicast key and a third authentication result according to the unicast key, the second encrypted data, the target device identifier, and the second verification data, thus completing the authentication process.

[0118] In this step, after the terminal device sends the authentication confirmation message to the access device, the access device can receive this authentication confirmation message, and can know that its own authentication is passed. It is necessary to generate a multicast key and perform secondary authentication on the terminal device. According to the unicast key, the second encrypted data, the target device identifier, and the second verification data in the authentication confirmation message, it generates a multicast key and a third authentication result, completing the authentication process. The third authentication result is used to indicate whether the secondary authentication of the terminal device is passed or not.

[0119] When the third authentication result indicates that the secondary authentication of the terminal device is passed, the terminal device is allowed to access the network and access the network. When the third authentication result indicates that the secondary authentication of the terminal device fails, the terminal device is not allowed to access the network and access the network.

[0120] It should be noted that after the access device generates the third authentication result, it can also send the third authentication result to the terminal device.

[0121] For the network access authentication method provided in this embodiment, after the terminal device sends an authentication request to the access device, the access device generates a second authentication result. After the second authentication result indicates that the authentication is passed, it generates a unicast key, and then sends an authentication response message to the terminal device. The terminal device generates a unicast key and a first authentication result. When the first authentication result indicates that the authentication is passed, it generates a multicast key, and then sends an authentication confirmation message to the access device. The access device generates a multicast key and a third authentication result, completing the authentication process. Compared with the prior art that requires five interactions to complete the authentication, this solution completes the authentication process through three interactions between the terminal device and the access device, effectively improving the authentication efficiency. And the terminal device is authenticated twice and the access device is authenticated once, improving the security of the terminal device accessing the network.

[0122] Figure 3 It is a schematic flowchart of the second embodiment of the network access authentication method provided by this application. On the basis of the above embodiment, this application embodiment describes the situation where the access device generates a unicast key, second encrypted data, and first verification data according to a pre-shared key, first encrypted data, second random number, and target device identifier. As Figure 3 shown, this network access authentication method specifically includes the following steps:

[0123] S301: Decrypt the first encrypted data according to the pre-shared key to obtain the first random number.

[0124] In this step, after the access device determines that the second authentication result indicates that the terminal device has passed the preliminary authentication, since the same pre-shared key is stored in the access device and the terminal device, the first encrypted data is decrypted according to the pre-shared key to obtain the first random number.

[0125] S302: Generate a unicast key according to the pre-shared key, the first random number, and the second random number.

[0126] In this step, after the access device obtains the first random number, it can combine the pre-shared key, the first random number, and the second random number, and use a key derivation algorithm to generate a unicast key.

[0127] S303: Encrypt the second random number with the pre-shared key to obtain the second encrypted data.

[0128] In this step, after the access device determines that the second authentication result indicates that the terminal device has passed the preliminary authentication, it encrypts the second random number with the pre-shared key to obtain the second encrypted data.

[0129] It should be noted that the execution order of steps S301 - S302 and step S303 can be: first execute steps S301 - S302, and then execute step S303; it can also be: first execute step S303, and then execute steps S301 - S302; it can also be: steps S301 - S302 and step S303 are executed simultaneously. The embodiments of the present application do not limit the execution order of steps S301 - S302 and step S303, and can be determined according to the actual situation.

[0130] S304: Generate the first verification data according to the unicast key, the second encrypted data, and the target device identifier.

[0131] In this step, after the access device encrypts the second encrypted data and the unicast key, and then combines the target device identifier, and uses a hash algorithm, the first verification data can be obtained.

[0132] The network access authentication method provided in this embodiment makes the unicast key more secure by generating a unicast key according to the pre-shared key, the first random number, and the second random number; and it is more difficult to be cracked by using a hash algorithm to generate the first verification data, thereby improving the security.

[0133] Figure 4 This is a schematic flowchart of the third embodiment of the network access authentication method provided by the present application. On the basis of the above embodiments, the embodiments of the present application illustrate the situation where the terminal device generates a unicast key and the first authentication result according to the pre-shared key, the second encrypted data, the first random number, the device identifier to be verified, and the first verification data. As Figure 4 shown, the network access authentication method specifically includes the following steps:

[0134] S401: Decrypt the second encrypted data according to the pre-shared key to obtain the second random number.

[0135] In this step, after the terminal device receives the authentication response message sent by the access device, since the same pre-shared key is stored in the access device and the terminal device, the second encrypted data is decrypted according to the pre-shared key to obtain the second random number.

[0136] S402: Generate a unicast key according to the pre-shared key, the first random number, and the second random number.

[0137] In this step, after the terminal device obtains the second random number, it can combine the first random number and the pre-shared key and use a key derivation algorithm to generate a unicast key.

[0138] It should be noted that the key derivation algorithm used by the terminal device and the access device when generating the unicast key is the same.

[0139] S403: Generate third verification data according to the unicast key, the second encrypted data, and the device identifier to be verified.

[0140] In this step, after the terminal device generates the unicast key, it can combine the second encrypted data and the device identifier to be verified and use a hash algorithm to generate third verification data.

[0141] It should be noted that the hash algorithm used by the access device to generate the first verification data is the same as the hash algorithm used by the terminal device to generate the third verification data.

[0142] S404: Determine whether the third verification data is the same as the first verification data; if the third verification data is the same as the first verification data, execute step S405; if the third verification data is different from the first verification data, execute step S406.

[0143] S405: Generate a first authentication result indicating that the access device is authenticated.

[0144] S406: Generate a first authentication result indicating that the access device is not authenticated.

[0145] In the above steps, the terminal device can authenticate the access device after generating the third verification data. Since the third verification data is generated by the terminal device according to the unicast key, the second encrypted data, and the device identifier to be verified, and the first verification data is generated by the access device according to the unicast key, the second encrypted data, and the target device identifier. If there is no problem with the terminal device and the wireless network, the two verification data should be the same. Therefore, it can be determined whether the third verification data is the same as the first verification data to authenticate the access device.

[0146] If the third verification data is the same as the first verification data, a first authentication result indicating that the access device is authenticated successfully is generated.

[0147] If the third verification data is different from the first verification data, a first authentication result indicating that the access device is not authenticated successfully is generated.

[0148] The network access authentication method provided in this embodiment generates a unicast key by using a pre-shared key, a first random number, and a second random number, which can ensure that the unicast keys generated by the terminal device and the access device are the same, and complete the negotiation of the unicast key. Furthermore, the access device is verified according to whether the third verification data is the same as the first verification data, improving the verification accuracy.

[0149] Figure 5 FIG. 4 is a schematic flowchart of Embodiment 4 of the network access authentication method provided in this application. On the basis of the above embodiments, this embodiment of the application describes the case where the access device generates a multicast key and a third authentication result according to the unicast key, the second encrypted data, the target device identifier, and the second verification data.

[0150] As Figure 5 shown, the network access authentication method specifically includes the following steps:

[0151] S501: Generate a multicast key by using a preset key generation algorithm and the unicast key.

[0152] In this step, after receiving the authentication confirmation message sent by the terminal device, the access device generates a multicast key by using a preset key generation algorithm and the unicast key, and completes the negotiation of the multicast key.

[0153] It should be noted that the preset key generation algorithm used by the terminal device to generate the multicast key is the same as the preset key generation algorithm used by the access device to generate the multicast key.

[0154] S502: Generate fourth verification data according to the multicast key, the second encrypted data, and the target device identifier.

[0155] In this step, after generating the multicast key, the access device combines the second encrypted data and the target device identifier, and uses a hash algorithm to generate the fourth verification data.

[0156] It should be noted that the hash algorithm used by the terminal device to generate the second verification data is the same as the hash algorithm used by the access device to generate the fourth verification data.

[0157] S503: Determine whether the fourth verification data is the same as the second verification data; if the fourth verification data is the same as the second verification data, execute step S504; if the fourth verification data is different from the second verification data, execute step S505.

[0158] S504: Generate a third authentication result indicating that the secondary authentication of the terminal device has passed.

[0159] S505: Generate a third authentication result indicating that the secondary authentication of the terminal device has failed.

[0160] In the above steps, after the access device generates the fourth verification data, it can perform secondary authentication on the terminal device. Since the second verification data is generated by the terminal device based on the multicast key, the second encrypted data, and the device identifier to be verified, and the fourth verification data is generated by the access device based on the multicast key, the second encrypted data, and the target device identifier. If there is no problem with the terminal device and the wireless network, the two verification data should be the same. Therefore, it can be determined whether the second verification data is the same as the fourth verification data to perform secondary authentication on the terminal device.

[0161] If the fourth verification data is the same as the second verification data, generate a third authentication result indicating that the secondary authentication of the terminal device has passed.

[0162] If the fourth verification data is different from the second verification data, generate a third authentication result indicating that the secondary authentication of the terminal device has failed.

[0163] The network access authentication method provided in this embodiment can generate a multicast key by using a preset key generation algorithm and a unicast key, ensuring that the multicast keys generated by the terminal device and the access device are the same, and completing the negotiation of the multicast key. Furthermore, according to whether the fourth verification data is the same as the second verification data, secondary verification is performed on the terminal device, improving the verification accuracy and ensuring the security of the terminal device.

[0164] The following is an embodiment of the apparatus of the present application, which can be used to execute the method embodiment of the present application. For details not disclosed in the embodiment of the apparatus of the present application, please refer to the method embodiment of the present application.

[0165] Figure 6 It is a schematic structural diagram of the first embodiment of the network access authentication apparatus provided by the present application; this apparatus can be integrated into the terminal device in the above method embodiment, or can be implemented by the terminal device in the above method embodiment. As Figure 6 shown, the network access authentication apparatus 60 includes:

[0166] A sending module 61, configured to send an authentication request to an access device, where the authentication request includes first encrypted data and the device identifier to be verified of the obtained access device, and the first encrypted data is data obtained by encrypting a first random number generated by using a pre-shared key pair;

[0167] A receiving module 62, configured to receive an authentication response message sent by the access device, where the authentication response message includes second encrypted data and first verification data;

[0168] The safety module 63 is used for:

[0169] Generate a unicast key and a first authentication result according to the pre-shared key, the second encrypted data, the first random number, the device identifier to be authenticated, and the first verification data, where the first authentication result is used to indicate whether the access device authentication has passed or failed;

[0170] If the first authentication result indicates that the access device has passed authentication, generating a multicast key and second verification data according to the unicast key, the second encrypted data and the identification of the device to be verified;

[0171] The sending module 61 is further configured to send an authentication confirmation message to the access device, where the authentication confirmation message includes the second verification data.

[0172] Furthermore, the security module 63 is specifically used for:

[0173] Decrypting the second encrypted data according to the pre-shared key to obtain a second random number;

[0174] Generate the unicast key according to the pre-shared key, the first random number and the second random number;

[0175] generating third verification data according to the unicast key, the second encrypted data and the identification of the device to be verified;

[0176] If the third verification data is the same as the first verification data, generating a first authentication result indicating that the access device has passed authentication;

[0177] If the third verification data is different from the first verification data, a first authentication result indicating that the access device authentication has failed is generated.

[0178] Furthermore, the security module 63 is specifically used for:

[0179] Generate the multicast key using a preset key generation algorithm and the unicast key;

[0180] The second verification data is generated according to the multicast key, the second encrypted data and the identification of the device to be verified.

[0181] The network access authentication device provided in this embodiment is used to execute the technical solution of the terminal device in any of the aforementioned method embodiments. Its implementation principle and technical effects are similar and will not be repeated here.

[0182] Figure 7This is a schematic diagram of the structure of the second embodiment of the network access authentication device provided by this application; the device can be integrated into the access device in the above method embodiment, and can also be implemented by the access device in the above method embodiment. Figure 7 As shown, the network access authentication device 70 includes:

[0183] The receiving module 71 is used to receive an authentication request sent by a terminal device, wherein the authentication request includes the first encrypted data and an identification of a device to be verified;

[0184] The security module 72 is used for:

[0185] Generate a second authentication result according to the device identifier to be verified and the target device identifier of the access device, wherein the second authentication result is used to indicate whether the terminal device has passed or failed the preliminary authentication;

[0186] If the second authentication result indicates that the terminal device has passed the preliminary authentication, generating a unicast key, second encrypted data and first verification data according to the pre-shared key, the first encrypted data, the generated second random number and the target device identifier;

[0187] A sending module 73, configured to send an authentication response message to the terminal device, wherein the authentication response message includes the second encrypted data and the first verification data;

[0188] The receiving module 71 is further configured to receive an authentication confirmation message sent by the terminal device, wherein the authentication confirmation message includes second verification data;

[0189] The security module 72 is also used to generate a multicast key and a third authentication result based on the unicast key, the second encrypted data, the target device identifier and the second verification data to complete the authentication process. The third authentication result is used to indicate whether the secondary authentication of the terminal device has passed or failed.

[0190] Furthermore, the security module 72 is specifically used for:

[0191] If the identification of the device to be verified is the same as the identification of the target device, generating a second authentication result indicating that the terminal device has passed the preliminary authentication;

[0192] If the to-be-verified device identifier is different from the target device identifier, a second authentication result indicating that the terminal device has failed the preliminary authentication is generated.

[0193] Furthermore, the security module 72 is specifically used for:

[0194] Decrypting the first encrypted data according to the pre-shared key to obtain a first random number;

[0195] Generate the unicast key according to the pre-shared key, the first random number and the second random number;

[0196] Encrypting the second random number using the pre-shared key to obtain the second encrypted data;

[0197] The first verification data is generated according to the unicast key, the second encrypted data and the target device identifier.

[0198] Furthermore, the security module 72 is specifically used for:

[0199] Generate the multicast key using a preset key generation algorithm and the unicast key;

[0200] generating fourth verification data according to the multicast key, the second encrypted data and the target device identifier;

[0201] If the fourth verification data is the same as the second verification data, generating a third authentication result indicating that the secondary authentication of the terminal device has passed;

[0202] If the fourth verification data is different from the second verification data, a third authentication result is generated indicating that the secondary authentication of the terminal device has not passed.

[0203] The network access authentication device provided in this embodiment is used to execute the technical solution of the access device in any of the aforementioned method embodiments. Its implementation principle and technical effect are similar and will not be repeated here.

[0204] Figure 8 A schematic diagram of the structure of an electronic device provided in this application Figure 1 .like Figure 8 As shown, the electronic device 80 includes:

[0205] Processor 81, memory 82, and communication interface 83;

[0206] The memory 82 is used to store executable instructions of the processor 81;

[0207] The processor 81 is configured to execute the technical solution of the terminal device in any of the aforementioned method embodiments by executing the executable instructions.

[0208] Optionally, the memory 82 can be independent or integrated with the processor 81.

[0209] Optionally, when the memory 82 is a device independent of the processor 81, the electronic device 80 may further include:

[0210] The bus 84 , the memory 82 and the communication interface 83 are connected to the processor 81 via the bus 84 and communicate with each other. The communication interface 83 is used to communicate with other devices.

[0211] Optionally, the communication interface 83 may be implemented by a transceiver. The communication interface is used to implement communication between the database access device and other devices (such as a client, a read-write library, and a read-only library). The memory may include a random access memory (RAM) and may also include a non-volatile memory (non-volatile memory), such as at least one disk storage.

[0212] The bus 84 may be a peripheral component interconnect (PCI) bus or an extended industry standard architecture (EISA) bus, etc. The bus may be divided into an address bus, a data bus, a control bus, etc. For ease of representation, only one thick line is used in the figure, but it does not mean that there is only one bus or one type of bus.

[0213] The above-mentioned processor can be a general-purpose processor, including a central processing unit CPU, a network processor (NP), etc.; it can also be a digital signal processor DSP, an application-specific integrated circuit ASIC, a field programmable gate array FPGA or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components.

[0214] The electronic device is used to execute the technical solution of the terminal device in any of the aforementioned method embodiments, and its implementation principle and technical effect are similar and will not be repeated here.

[0215] Figure 9 A schematic diagram of the structure of an electronic device provided in this application Figure 2 .like Figure 9 As shown, the electronic device 90 includes:

[0216] Processor 91, memory 92, and communication interface 93;

[0217] The memory 92 is used to store executable instructions of the processor 91;

[0218] The processor 91 is configured to execute the technical solution of accessing the device in any of the aforementioned method embodiments by executing the executable instructions.

[0219] Optionally, the memory 92 can be independent or integrated with the processor 91.

[0220] Optionally, when the memory 92 is a device independent of the processor 91, the electronic device 90 may further include:

[0221] The bus 94 , the memory 92 and the communication interface 93 are connected to the processor 91 via the bus 94 and communicate with each other. The communication interface 93 is used to communicate with other devices.

[0222] Optionally, the communication interface 93 may be implemented by a transceiver. The communication interface is used to implement communication between the database access device and other devices (such as a client, a read-write library, and a read-only library). The memory may include a random access memory (RAM) and may also include a non-volatile memory (non-volatile memory), such as at least one disk storage.

[0223] The bus 94 may be a peripheral component interconnect (PCI) bus or an extended industry standard architecture (EISA) bus, etc. The bus may be divided into an address bus, a data bus, a control bus, etc. For ease of representation, only one thick line is used in the figure, but it does not mean that there is only one bus or one type of bus.

[0224] The above-mentioned processor can be a general-purpose processor, including a central processing unit CPU, a network processor (NP), etc.; it can also be a digital signal processor DSP, an application-specific integrated circuit ASIC, a field programmable gate array FPGA or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components.

[0225] The electronic device is used to execute the technical solution of accessing the device in any of the aforementioned method embodiments, and its implementation principle and technical effect are similar and will not be repeated here.

[0226] An embodiment of the present application also provides a readable storage medium having a computer program stored thereon, and when the computer program is executed by a processor, the technical solution provided by any of the aforementioned method embodiments is implemented.

[0227] An embodiment of the present application also provides a computer program product, including a computer program, which is used to implement the technical solution provided by any of the aforementioned method embodiments when executed by a processor.

[0228] Those skilled in the art can understand that all or part of the steps of implementing the above-mentioned method embodiments can be completed by hardware related to program instructions. The aforementioned program can be stored in a computer-readable storage medium. When the program is executed, the steps of the above-mentioned method embodiments are executed; and the aforementioned storage medium includes: ROM, RAM, disk or optical disk and other media that can store program codes.

[0229] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present application, rather than to limit it. Although the present application has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or replace some or all of the technical features therein with equivalents. However, these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the scope of the technical solutions of the embodiments of the present application.

Claims

1. An access authentication method, characterized in that, applied to a terminal device, the method includes: sending an authentication request to an access device, the authentication request including first encrypted data and the device identifier to be verified of the access device obtained, the first encrypted data being data obtained by encrypting a first random number generated using a pre-shared key; receiving an authentication response message sent by the access device, the authentication response message including second encrypted data and first verification data; generating a unicast key and a first authentication result according to the pre-shared key, the second encrypted data, the first random number, the device identifier to be verified, and the first verification data, the first authentication result being used to indicate whether the access device is authenticated or not; if the first authentication result indicates that the access device is authenticated, then generating a multicast key and second verification data according to the unicast key, the second encrypted data, and the device identifier to be verified; sending an authentication confirmation message to the access device, the authentication confirmation message including the second verification data.

2. The method according to claim 1, characterized in that, the generating a unicast key and a first authentication result according to the pre-shared key, the second encrypted data, the first random number, the device identifier to be verified, and the first verification data includes: decrypting the second encrypted data according to the pre-shared key to obtain a second random number; generating the unicast key according to the pre-shared key, the first random number, and the second random number; generating third verification data according to the unicast key, the second encrypted data, and the device identifier to be verified; if the third verification data is the same as the first verification data, then generating a first authentication result indicating that the access device is authenticated; if the third verification data is different from the first verification data, then generating a first authentication result indicating that the access device is not authenticated.

3. The method according to claim 1, characterized in that, the generating a multicast key and second verification data according to the unicast key, the second encrypted data, and the device identifier to be verified includes: generating the multicast key using a preset key generation algorithm and the unicast key; generating the second verification data according to the multicast key, the second encrypted data, and the device identifier to be verified.

4. An access authentication method, characterized in that, applied to an access device, the method includes: receiving an authentication request sent by a terminal device, the authentication request including first encrypted data and a device identifier to be verified; generating a second authentication result according to the device identifier to be verified and the target device identifier of the access device, the second authentication result being used to indicate whether the terminal device is preliminarily authenticated or not; if the second authentication result indicates that the terminal device is preliminarily authenticated, then generating a unicast key, second encrypted data, and first verification data according to a pre-shared key, the first encrypted data, the generated second random number, and the target device identifier; Send an authentication response message to the terminal device, where the authentication response message includes the second encrypted data and the first verification data; Receive an authentication confirmation message sent by the terminal device, where the authentication confirmation message includes second verification data; Generate a multicast key and a third authentication result according to the unicast key, the second encrypted data, the target device identifier, and the second verification data, and complete the authentication process, where the third authentication result is used to indicate whether the secondary authentication of the terminal device passes or fails.

5. The method according to claim 4, wherein, The generating a second authentication result according to the device identifier to be verified and the target device identifier of the access device includes: If the device identifier to be verified is the same as the target device identifier, generate a second authentication result indicating that the preliminary authentication of the terminal device passes; If the device identifier to be verified is different from the target device identifier, generate a second authentication result indicating that the preliminary authentication of the terminal device fails.

6. The method according to claim 4, wherein, The generating a unicast key, second encrypted data, and first verification data according to the pre-shared key, the first encrypted data, the generated second random number, and the target device identifier includes: Decrypt the first encrypted data according to the pre-shared key to obtain a first random number; Generate the unicast key according to the pre-shared key, the first random number, and the second random number; Encrypt the second random number with the pre-shared key to obtain the second encrypted data; Generate the first verification data according to the unicast key, the second encrypted data, and the target device identifier.

7. The method according to claim 4, wherein, The generating a multicast key and a third authentication result according to the unicast key, the second encrypted data, the target device identifier, and the second verification data includes: Generate the multicast key using a preset key generation algorithm and the unicast key; Generate fourth verification data according to the multicast key, the second encrypted data, and the target device identifier; If the fourth verification data is the same as the second verification data, generate a third authentication result indicating that the secondary authentication of the terminal device passes; If the fourth verification data is different from the second verification data, generate a third authentication result indicating that the secondary authentication of the terminal device fails.

8. An access network authentication device, wherein, Comprising: A sending module, configured to send an authentication request to an access device, where the authentication request includes first encrypted data and the device identifier to be verified of the access device obtained, and the first encrypted data is data obtained by encrypting a generated first random number with a pre-shared key; A receiving module, configured to receive an authentication response message sent by the access device, where the authentication response message includes second encrypted data and first verification data; A security module, configured to: Generate a unicast key and a first authentication result based on the pre-shared key, the second encrypted data, the first random number, the device identifier to be verified, and the first verification data, where the first authentication result is used to indicate whether the access device is authenticated successfully or not; If the first authentication result indicates that the access device is authenticated successfully, generate a multicast key and a second verification data based on the unicast key, the second encrypted data, and the device identifier to be verified; The sending module is further configured to send an authentication confirmation message to the access device, where the authentication confirmation message includes the second verification data.

9. An access network authentication device, characterized in that, comprising: a receiving module, configured to receive an authentication request sent by a terminal device, where the authentication request includes first encrypted data and a device identifier to be verified; a security module, configured to: generate a second authentication result based on the device identifier to be verified and the target device identifier of the access device, where the second authentication result is used to indicate whether the terminal device is preliminarily authenticated successfully or not; if the second authentication result indicates that the terminal device is preliminarily authenticated successfully, generate a unicast key, second encrypted data, and first verification data based on a pre-shared key, the first encrypted data, a generated second random number, and the target device identifier; a sending module, configured to send an authentication response message to the terminal device, where the authentication response message includes the second encrypted data and the first verification data; the receiving module is further configured to receive an authentication confirmation message sent by the terminal device, where the authentication confirmation message includes second verification data; the security module is further configured to generate a multicast key and a third authentication result based on the unicast key, the second encrypted data, the target device identifier, and the second verification data to complete the authentication process, where the third authentication result is used to indicate whether the terminal device is authenticated successfully in the second authentication or not.

10. An electronic device, characterized in that, comprising: a processor, a memory, and a communication interface; the memory is used to store executable instructions of the processor; wherein, the processor is configured to execute the access network authentication method according to any one of claims 1 to 3 by executing the executable instructions.

11. An electronic device, characterized in that, comprising: a processor, a memory, and a communication interface; the memory is used to store executable instructions of the processor; wherein, the processor is configured to execute the access network authentication method according to any one of claims 4 to 7 by executing the executable instructions.

12. A readable storage medium, on which a computer program is stored, characterized in that, the computer program, when executed by a processor, implements the access network authentication method according to any one of claims 1 to 3, or any one of claims 4 to 7.

13. A computer program product, characterized in that, comprising a computer program, where the computer program, when executed by a processor, is used to implement the access network authentication method according to any one of claims 1 to 3, or any one of claims 4 to 7.