Terminal authentication method and device based on secure resource pool, communication device and medium
By separating security capabilities from the network elements of the 5G communication network, forming a secure resource pool, and using the authentication encryption function to generate an authentication identifier AutID during the terminal authentication process, the problem of the inability to form a secure resource pool in the existing technology is solved, and a more efficient and secure terminal authentication process is achieved.
Patent Information
- Application Number
- CN202311788746.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2023-12-22
- Publication Date
- 2025-06-24
AI Technical Summary
The existing 5G design security mechanism fails to consider the security needs of different services, the security needs of different users in the same service, and the security needs of each network element in the communication network in different services, resulting in the inability to separate different security capabilities and services from the network elements of the communication network and the inability to form a security resource pool.
By separating the security capabilities from the network elements, forming a secure resource pool, and providing authentication encryption functions, using the security capabilities provided by the security resource pool, the authentication identifier AutID corresponding to the authentication vector is generated during the terminal authentication process, so that the terminal authentication process different network elements work as a whole.
It improves the security and efficiency of terminal authentication, and facilitates the scheduling of different security capabilities according to different security needs to meet the security needs in different services.
Smart Images

Figure CN120201427A_ABST
Abstract
Description
Technical Field
[0001] Embodiments of the present disclosure relate to the field of communication technologies, and in particular, to a terminal authentication method, apparatus, communication device, and medium based on a security resource pool. Background Art
[0002] With the development of communication technologies, according to the security requirements of different services, a communication network needs to provide different security capabilities and services. Therefore, different security capabilities need to be used as schedulable and manageable security resources to form a security resource pool.
[0003] However, when designing the security mechanism for existing 5G, the security requirements of different services, the security requirements of different users in the same service, and the security requirements of each network element in the communication network for different services are not considered. Therefore, different security capabilities and services cannot be separated from each network element of the communication network, and thus a security resource pool cannot be formed.
[0004] Therefore, there is an urgent need to provide a terminal authentication solution based on a security resource pool to improve the authentication efficiency and security. Summary of the Invention
[0005] At least one embodiment of the present disclosure provides a terminal authentication method, apparatus, communication device, and medium based on a security resource pool.
[0006] In a first aspect, an embodiment of the present disclosure provides a terminal authentication method based on a security resource pool. The security resource pool corresponds to the security resource pool layer of the security capability architecture, and the network elements of the security resource pool layer include: an authentication and encryption function. The method includes:
[0007] The authentication and encryption function receives the service type and the terminal identifier of the terminal to be authenticated sent by the Unified Data Management (UDM) network element.
[0008] The authentication and encryption function selects an authentication method based on the service type.
[0009] If the selected authentication method is the terminal authentication method based on the security resource pool, the authentication and encryption function generates an authentication vector and an authentication identifier (AutID) corresponding to the authentication vector based on the terminal identifier. The authentication vector includes an expected response.
[0010] The authentication and encryption function sends the elements of the authentication vector and the AutID to the UDM network element, and the elements of the authentication vector and the AutID are sent by the UDM network element to the Authentication Server Function (AUSF).
[0011] The authentication and encryption function receives the terminal response and the AutID sent by the AUSF.
[0012] The authentication and encryption function looks up the corresponding authentication vector based on the AutID, and compares the terminal response with the expected response in the found authentication vector. If they are the same, it is confirmed that the terminal to be authenticated passes the authentication.
[0013] In some embodiments, if the terminal identifier is the subscriber concealed identifier (SUCI), before the authentication and encryption function generates the authentication vector and the corresponding authentication identifier (AutID) based on the terminal identifier, the terminal authentication method based on the security resource pool further includes:
[0014] The authentication and encryption function receives the SUCI decryption request sent by the UDM network element;
[0015] The authentication and encryption function decrypts the SUCI of the terminal to be authenticated in response to the SUCI decryption request, and obtains the subscriber permanent identifier (SUPI) of the terminal to be authenticated.
[0016] Correspondingly, the authentication and encryption function generates the authentication vector and the corresponding authentication identifier (AutID) based on the terminal identifier, including:
[0017] The authentication and encryption function generates the authentication vector and the corresponding authentication identifier (AutID) based on the SUPI.
[0018] In some embodiments, the authentication vector includes a random number (RAND) and an authentication token (AUTH);
[0019] The authentication and encryption function sends the elements in the authentication vector and the AutID to the UDM network element, and the elements in the authentication vector and the AutID are sent by the UDM network element to the authentication service function (AUSF), including:
[0020] The authentication and encryption function sends the RAND, AUTH, and AutID to the UDM network element, and the RAND, AUTH, and AutID are sent by the UDM network element to the AUSF;
[0021] Correspondingly, the terminal response is: after the terminal verifies that the AUTH passes, the terminal response calculated by the terminal based on the RAND and the terminal's authentication root key.
[0022] In some embodiments, the network element in the security resource pool layer further includes: a communication encryption function, and the terminal authentication method based on the security resource pool further includes:
[0023] After the authentication and encryption function confirms that the terminal to be authenticated passes the authentication, it generates an anchor key Kseaf;
[0024] The authentication and encryption function sends the authentication security context to the communication encryption function. The authentication security context includes: the terminal identifier, Kseaf, and AutID, and the authentication security context is used for the communication encryption function to encrypt the communication data of the terminal that has passed the authentication.
[0025] In some embodiments, the terminal authentication method based on the security resource pool further includes:
[0026] After the authentication encryption function confirms that the terminal to be authenticated has passed the authentication, it sends the authentication result to the AUSF. The AutID is sent by the AUSF to the security anchoring function SEAF, and the AutID and the user permanent identifier SUPI of the authenticated terminal are sent by the SEAF to the access and mobility management function AMF.
[0027] In some embodiments, the service type and the terminal identifier of the terminal to be authenticated are information carried in the terminal authentication request. The terminal authentication request is the terminal authentication request sent by the SEAF to the AUSF after the terminal to be authenticated sends a registration request to the SEAF, and the AUSF sends the terminal authentication request to the UDM network element.
[0028] In some embodiments, the terminal authentication method based on the security resource pool further includes:
[0029] The authentication encryption function receives the terminal authentication request sent by the network function NF;
[0030] Based on the terminal authentication request, the authentication encryption function sends a terminal authentication notification to the UDM network element. The terminal authentication notification is used for: the UDM network element checks whether a terminal authentication process is in progress. If not, the UDM network element determines the security anchoring function SEAF corresponding to the terminal to be authenticated; the UDM sends a notification message to the SEAF, and the notification message carries the terminal identifier of the terminal to be authenticated.
[0031] The authentication encryption function receives the determination result sent by the SEAF. The determination result is used to determine whether to authenticate the terminal to be authenticated, and the determination result is: after the SEAF receives the notification message, the SEAF determines whether to authenticate the terminal to be authenticated based on the local authentication policy.
[0032] In some embodiments, after the authentication encryption function receives the determination result sent by the SEAF, the terminal authentication method based on the security resource pool further includes:
[0033] If the determination result is to authenticate the terminal to be authenticated, the authentication encryption function receives the service type and the terminal identifier of the terminal to be authenticated sent by the unified data management UDM network element, and subsequent steps.
[0034] In some embodiments, the communication encryption function and the authentication encryption function are deployed on the same physical device.
[0035] In some embodiments, the security capability architecture further includes: a security controller layer and a security service layer. Among them, the security service layer is used to provide an external security service interface;
[0036] The network element corresponding to the security controller layer receives a security service request sent by a terminal or a network function NF through a security service interface;
[0037] Based on the security requirement information carried in the security service request, the network element corresponding to the security controller layer schedules at least one network element among multiple network elements corresponding to the security resource pool layer to provide security capabilities for the security requirement information;
[0038] After obtaining the security service result fed back by the scheduled network element, the network element corresponding to the security controller layer sends the security service result to the terminal or the network function NF.
[0039] In a second aspect, an embodiment of the present disclosure further provides a terminal authentication device based on a security resource pool. The security resource pool corresponds to the security resource pool layer of the security capability architecture. The network elements of the security resource pool layer include: an authentication and encryption function; this device is applied to the authentication and encryption function, and this device includes:
[0040] A first unit, configured to receive a service type and a terminal identifier of a terminal to be authenticated sent by a unified data management UDM network element;
[0041] A second unit, configured to select an authentication method based on the service type;
[0042] A third unit, configured to, if the authentication method selected by the second unit is a terminal authentication method based on a security resource pool, generate an authentication vector and an authentication identifier AutID corresponding to the authentication vector based on the terminal identifier, where the authentication vector includes an expected response;
[0043] A fourth unit, configured to send elements in the authentication vector and the AutID to the UDM network element, and the elements in the authentication vector and the AutID are sent by the UDM network element to an authentication service function AUSF;
[0044] A fifth unit, configured to receive a terminal response and the AutID sent by the AUSF;
[0045] A sixth unit, configured to look up the corresponding authentication vector based on the AutID, and compare the terminal response with the expected response in the found authentication vector. If they are the same, it is confirmed that the terminal to be authenticated passes the authentication.
[0046] In a third aspect, an embodiment of the present disclosure further provides a communication device. The communication device includes a memory, a transceiver, and a processor:
[0047] The memory is used to store a computer program; the transceiver is used to send and receive data under the control of the processor; the processor is used to read the computer program in the memory and execute:
[0048] Receive a service type and a terminal identifier of a terminal to be authenticated sent by a unified data management UDM network element;
[0049] Select an authentication method based on the service type;
[0050] If the selected authentication method is the terminal authentication method based on the security resource pool, then based on the terminal identifier, an authentication vector and an authentication identifier AutID corresponding to the authentication vector are generated, and the authentication vector includes an expected response;
[0051] Send the elements in the authentication vector and AutID to the UDM network element, and the elements in the authentication vector and AutID are sent by the UDM network element to the authentication service function AUSF;
[0052] Receive the terminal response and AutID sent by the AUSF;
[0053] Search for the corresponding authentication vector based on AutID, and compare the terminal response with the expected response in the found authentication vector. If they are the same, confirm that the terminal to be authenticated passes the authentication.
[0054] In some embodiments, if the terminal identifier is the user hidden identifier SUCI, before generating the authentication vector and the authentication identifier AutID corresponding to the authentication vector based on the terminal identifier, the processor is further configured to:
[0055] Receive the SUCI decryption request sent by the UDM network element;
[0056] Respond to the SUCI decryption request to decrypt the SUCI of the terminal to be authenticated, and obtain the user permanent identifier SUPI of the terminal to be authenticated;
[0057] Correspondingly, generating the authentication vector and the authentication identifier AutID corresponding to the authentication vector based on the terminal identifier includes:
[0058] Generate the authentication vector and the authentication identifier AutID corresponding to the authentication vector based on the SUPI.
[0059] In some embodiments, the authentication vector includes a random number RAND and an authentication token AUTH;
[0060] Sending the elements in the authentication vector and AutID to the UDM network element, and the elements in the authentication vector and AutID are sent by the UDM network element to the authentication service function AUSF, includes:
[0061] Send RAND, AUTH, and AutID to the UDM network element, and RAND, AUTH, and AutID are sent by the UDM network element to the AUSF;
[0062] Correspondingly, the terminal response is: after the terminal verifies that AUTH passes, the terminal response calculated by the terminal based on RAND and the authentication root key of the terminal.
[0063] In some embodiments, the processor is further configured to:
[0064] After confirming that the terminal to be authenticated passes the authentication, generate an anchor key Kseaf;
[0065] Send the authentication security context to the communication encryption function. The authentication security context includes: the terminal identifier, Kseaf, and AutID. The authentication security context is used for the communication encryption function to encrypt the communication data of the authenticated terminal.
[0066] In some embodiments, the processor is further configured to:
[0067] After confirming that the terminal to be authenticated passes the authentication, send the authentication result to the AUSF. The AutID is sent by the AUSF to the security anchor function SEAF, and the AutID and the user permanent identifier SUPI of the authenticated terminal are sent by the SEAF to the access and mobility management function AMF.
[0068] In some embodiments, the service type and the terminal identifier of the terminal to be authenticated are information carried in the terminal authentication request. The terminal authentication request is the terminal authentication request sent by the security anchor function SEAF to the AUSF after the terminal to be authenticated sends a registration request to the SEAF, and the AUSF sends the terminal authentication request to the UDM network element.
[0069] In some embodiments, the processor is further configured to:
[0070] Receive the terminal authentication request sent by the network function NF;
[0071] Based on the terminal authentication request, send a terminal authentication notification to the UDM network element. The terminal authentication notification is used for: the UDM network element checks whether a terminal authentication process is in progress. If not, the UDM network element determines the security anchor function SEAF corresponding to the terminal to be authenticated; the UDM sends a notification message to the SEAF, and the terminal identifier of the terminal to be authenticated is carried in the notification message;
[0072] Receive the determination result sent by the SEAF. The determination result is used to determine whether to authenticate the terminal to be authenticated, and the determination result is: after the SEAF receives the notification message, the SEAF determines whether to authenticate the terminal to be authenticated based on the local authentication policy.
[0073] In some embodiments, the processor is further configured to:
[0074] After receiving the determination result sent by the SEAF, if the determination result is to authenticate the terminal to be authenticated, then receive the service type and the terminal identifier of the terminal to be authenticated sent by the unified data management UDM network element, and subsequent steps.
[0075] In some embodiments, the communication encryption function and the authentication encryption function are deployed on the same physical device.
[0076] In a fourth aspect, embodiments of the present disclosure further provide a processor-readable storage medium storing a program for causing a processor to execute the terminal authentication method based on a security resource pool according to any one of the embodiments in the first aspect.
[0077] It can be seen that in at least one embodiment of the present disclosure, by separating the security capabilities from the network elements to form a security resource pool, and providing a new network function: the authentication encryption function, using the security capabilities provided by the security resource pool, during the terminal authentication process, an authentication identifier AutID corresponding to the authentication vector is generated, enabling different network elements to work as a whole in the terminal authentication process, improving security, and the security capabilities are mainly used by the authentication encryption function, further improving security and authentication efficiency. In addition, since the security capabilities are separated from the network elements to form a security resource pool, it is convenient to schedule different security capabilities according to different security requirements to meet the security requirements in different services. BRIEF DESCRIPTION OF THE DRAWINGS
[0078] To more clearly illustrate the technical solutions of the embodiments of the present disclosure, the following will briefly introduce the drawings required for use in the embodiments or the description of the prior art. Obviously, the following drawings are only some embodiments of the present disclosure, and those of ordinary skill in the art can also obtain other drawings based on these drawings.
[0079] Figure 1 It is a schematic flowchart of a terminal authentication method based on a security resource pool provided by an embodiment of the present disclosure;
[0080] Figure 2 It is an interaction schematic diagram of a terminal authentication based on a security resource pool provided by an embodiment of the present disclosure;
[0081] Figure 3 It is another interaction schematic diagram of a terminal authentication based on a security resource pool provided by an embodiment of the present disclosure;
[0082] Figure 4 It is a schematic diagram of a security capability architecture provided by an embodiment of the present disclosure;
[0083] Figure 5 It is a schematic diagram of a terminal authentication device based on a security resource pool provided by an embodiment of the present disclosure;
[0084] Figure 6 It is a schematic diagram of a communication device provided by an embodiment of the present disclosure. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0085] In order to more clearly understand the above-mentioned objects, features, and advantages of the present disclosure, the present disclosure will be further described in detail below with reference to the accompanying drawings and embodiments. It can be understood that the described embodiments are part of the embodiments of the present disclosure, rather than all of the embodiments. The specific embodiments described herein are only used to explain the present disclosure, rather than limiting the present disclosure. All other embodiments obtained by those of ordinary skill in the art based on the described embodiments of the present disclosure fall within the scope of protection of the present disclosure.
[0086] It should be noted that, in this document, relational terms such as "first" and "second" are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations.
[0087] Currently, in the 5G communication system, the fifth-generation authentication and key agreement (5G AKA) is used for terminal authentication. Network elements related to terminal authentication and non-access stratum (NAS) security in 5G AKA include, but are not limited to: access and mobility management function (AMF), security anchor function (SEAF), authentication server function (AUSF), authentication credential repository and processing function (ARPF) and subscription identifier de-concealing function (SIDF) in the unified data management (UDM) network element.
[0088] It can be seen that in the 5G communication system, security capabilities such as key management and cryptographic operations are bound to the above-mentioned network elements, and different security capabilities cannot be separated from the above-mentioned network elements, so a security resource pool cannot be formed.
[0089] To this end, embodiments of the present disclosure separate the security capabilities from the network elements to form a security resource pool. The security capabilities in the security resource pool include, but are not limited to: security encryption algorithms, access authentication protocols, NAS security protocols, integrity algorithms, asymmetric keys, key derivation, etc. After forming the security resource pool, embodiments of the present disclosure provide a terminal authentication method, device, communication device or medium based on the security resource pool. By separating the security capabilities from the network elements to form a security resource pool and providing a new network function: authentication encryption function, using the security capabilities provided by the security resource pool, during the terminal authentication process, an authentication identifier AutID corresponding to the authentication vector is generated, so that the terminal authentication process works as a whole with different network elements, improving security, and the security capabilities are mainly used by the authentication encryption function, further improving security and authentication efficiency. In addition, since the security capabilities are separated from the network elements to form a security resource pool, it is convenient to schedule different security capabilities according to different security requirements to meet the security requirements in different services.
[0090] Figure 1 FIG. is a schematic flowchart of a terminal authentication method based on a security resource pool provided by an embodiment of the present disclosure. The security resource pool corresponds to the security resource pool layer of the security capability architecture. Among them, the security capability architecture will be described in detail below. The security capability architecture is a multi-layer architecture (including the security resource pool layer). The network elements in the security resource pool layer include: authentication encryption function. As Figure 1 shown, the terminal authentication method based on the security resource pool may include, but is not limited to, the following steps 101 to 106:
[0091] In step 101, the authentication encryption function receives the service type and the terminal identifier of the terminal to be authenticated sent by the unified data management UDM network element.
[0092] In this embodiment, the service type and the terminal identifier of the terminal to be authenticated are the information carried in the terminal authentication request. The terminal authentication request is the terminal authentication request sent by the security anchor function SEAF to the AUSF after the terminal to be authenticated sends a registration request to the SEAF, and the AUSF sends the terminal authentication request to the UDM network element.
[0093] In step 102, the authentication encryption function selects an authentication method based on the service type.
[0094] In this embodiment, the service type corresponds to the authentication method. For example, if the traditional authentication method (such as 5G AKA method) is adopted, the value of the service type is set to 0. If the terminal authentication method based on the security resource pool is adopted, the value of the service type is set to 1. The authentication encryption function selects the authentication method based on the service type sent by the UDM network element. For example, if the value of the service type is 1, the terminal authentication method based on the security resource pool is selected; if the value of the service type is 0, the traditional authentication method is selected.
[0095] In step 103, if the selected authentication method is the terminal authentication method based on the security resource pool, the authentication and encryption function generates an authentication vector and an authentication identifier AutID corresponding to the authentication vector based on the terminal identifier, and the authentication vector includes an expected response.
[0096] In this embodiment, the authentication and encryption function uses the security capability provided in the security resource pool to generate the authentication vector. The difference from the prior art is that in this embodiment, the authentication and encryption function generates the authentication identifier AutID corresponding to the authentication vector, and AutID enables different network elements in the terminal authentication process to work as a whole, improving security.
[0097] In step 104, the authentication and encryption function sends the elements in the authentication vector and AutID to the UDM network element, and the elements in the authentication vector and AutID are sent by the UDM network element to the authentication service function AUSF.
[0098] In this embodiment, the authentication vector includes a random number RAND and an authentication token AUTH. The authentication and encryption function sends RAND, AUTH, and AutID to the UDM network element, and RAND, AUTH, and AutID are sent by the UDM network element to AUSF.
[0099] In step 105, the authentication and encryption function receives the terminal response and AutID sent by AUSF.
[0100] In this embodiment, the terminal response is: after the terminal verifies that AUTH passes, the terminal response calculated by the terminal based on RAND and the authentication root key of the terminal.
[0101] In step 106, the authentication and encryption function looks up the corresponding authentication vector based on AutID, and compares the terminal response with the expected response in the found authentication vector. If they are the same, it is confirmed that the terminal to be authenticated passes the authentication.
[0102] In this embodiment, the authentication and encryption function stores the correspondence between AutID and the authentication vector. When the authentication and encryption function receives AutID, by looking up this correspondence, the authentication vector corresponding to AutID can be obtained. It can be seen that the authentication vector can be matched through AutID, preventing the incorrect use of the authentication vector and improving authentication security.
[0103] In some embodiments, if the terminal identifier is a subscriber concealed identifier (SUCI), before "the authentication and encryption function generates an authentication vector and an authentication identifier AutID corresponding to the authentication vector based on the terminal identifier" in step 103, the terminal authentication method based on the security resource pool further includes the following steps 1 and 2:
[0104] 1. The authentication and encryption function receives the SUCI decryption request sent by the UDM network element.
[0105] 2. In response to the SUCI decryption request, the authentication and encryption function decrypts the SUCI of the terminal to be authenticated, and obtains the Subscription Permanent Identifier (SUPI) of the terminal to be authenticated.
[0106] In this embodiment, the authentication and encryption function uses the security capability in the security resource pool: the SUCI decryption algorithm, to decrypt the SUCI of the terminal to be authenticated, and obtains the SUPI of the terminal to be authenticated.
[0107] Correspondingly, step 103 "The authentication and encryption function generates an authentication vector and an authentication identifier AutID corresponding to the authentication vector based on the terminal identifier" is specifically: The authentication and encryption function generates an authentication vector and an authentication identifier AutID corresponding to the authentication vector based on the SUPI.
[0108] In some embodiments, the network elements in the security resource pool layer further include: a communication encryption function, and the terminal authentication method based on the security resource pool further includes:
[0109] After the authentication and encryption function confirms that the terminal to be authenticated passes the authentication, it generates an anchor key Kseaf; the authentication and encryption function sends the authentication security context to the communication encryption function, and the authentication security context includes: the terminal identifier, Kseaf, and AutID. The authentication security context is used for the communication encryption function to encrypt the communication data of the terminal that has passed the authentication.
[0110] Among them, the authentication and encryption function uses the security capability provided in the security resource pool to generate the anchor key Kseaf, and uses the key Kausf of the AUSF to generate Kseaf. In this embodiment, the authentication and encryption function, the communication encryption function, the UDM network element, the AUSF, and the SEAF use the authentication security context constructed by the authentication vector identified by AutID, and AutID is used as the keyword for the security context interaction and data security processing between network elements, so that the security capabilities distributed in different network elements work as a whole, improving the authentication security.
[0111] In some embodiments, the terminal authentication method based on the security resource pool further includes:
[0112] After the authentication and encryption function confirms that the terminal to be authenticated passes the authentication, it sends the authentication result to the AUSF. The AutID is sent by the AUSF to the security anchoring function SEAF, and the AutID and the Subscription Permanent Identifier SUPI of the terminal that has passed the authentication are sent by the SEAF to the access and mobility management function AMF.
[0113] In some embodiments, the terminal authentication process based on the security resource pool can also be triggered by a Network Function (NF). For example, it includes but is not limited to the following steps 1 to 3:
[0114] 1. The authentication and encryption function receives a terminal authentication request sent by the network function NF.
[0115] 2. Based on the terminal authentication request, the authentication and encryption function sends a terminal authentication notification to the UDM network element. The terminal authentication notification is used for: the UDM network element checks whether a terminal authentication process is in progress. If not, the UDM network element determines the Security Anchor Function (SEAF) corresponding to the terminal to be authenticated; the UDM sends a notification message to the SEAF, and the terminal identifier of the terminal to be authenticated is carried in the notification message.
[0116] 3. The authentication and encryption function receives the determination result sent by the SEAF. The determination result is used to determine whether to authenticate the terminal to be authenticated, and the determination result is: after receiving the notification message, the SEAF determines whether to authenticate the terminal to be authenticated based on the local authentication policy.
[0117] In some embodiments, after the authentication and encryption function receives the determination result sent by the SEAF in step 3, if the determination result is to authenticate the terminal to be authenticated, the authentication and encryption function receives the service type sent by the Unified Data Management (UDM) network element and the terminal identifier of the terminal to be authenticated, as well as the subsequent steps.
[0118] In some embodiments, the communication encryption function and the authentication and encryption function are deployed on the same physical device. The communication encryption function and the authentication and encryption function are logically separated. However, when physically deployed, when the two are deployed on a physical device, there is no need for data exchange between them, and they can share data.
[0119] Figure 2 FIG. is an interaction schematic diagram of a terminal authentication based on a security resource pool provided by an embodiment of the present disclosure. Figure 2 For the interaction process triggered by the terminal for authentication, it includes the following steps 1 to 22:
[0120] 1. The terminal sends a registration request to the Security Anchor Function (SEAF).
[0121] In this embodiment, the information items carried in the registration request include: the terminal identifier and the service type. Among them, the terminal identifier is the Subscriber Concealed Identifier (SUCI). The service type corresponds to the authentication method. For example, if the traditional authentication method (such as the 5G AKA method) is adopted, the value of the service type is set to 0; if the terminal authentication method based on the security resource pool is adopted, the value of the service type is set to 1.
[0122] 2. The SEAF sends a terminal authentication request to the authentication service function AUSF.
[0123] In this embodiment, the information items carried in the terminal authentication request include: the terminal identifier and the service type. The terminal identifier and the service type are derived from the registration request. This terminal authentication request is, for example, an Nausf_UE authentication request.
[0124] 3. The AUSF sends a terminal authentication request to the unified data management UDM network element.
[0125] In this embodiment, the information items carried in the terminal authentication request include: the terminal identifier and the service type. This terminal authentication request is, for example, a Nudm_UE authentication request.
[0126] 4. The UDM network element sends a SUCI decryption request to the authentication and encryption function.
[0127] In this embodiment, the UDM network element hides the subscriber identifier SUCI for the user based on the terminal identifier carried in the terminal authentication request. The UDM network element sends a SUCI decryption request to the authentication and encryption function, and the SUCI carried in the terminal is included in the SUCI decryption request. The UDM network element also sends the service type to the authentication and encryption function. The service type can be carried in the SUCI decryption request, or the UDM network element can also send the service type to the authentication and encryption function through other signaling.
[0128] It should be noted that if the terminal identifier is the subscriber permanent identifier SUPI, the UDM network element does not need to send a SUCI decryption request to the authentication and encryption function, but sends the service type and SUPI to the authentication and encryption function.
[0129] 5. The authentication and encryption function decrypts the SUCI of the terminal.
[0130] In this embodiment, the authentication and encryption function decrypts the SUCI of the terminal to obtain the subscriber permanent identifier SUPI of the terminal.
[0131] 6. The authentication and encryption function selects an authentication method.
[0132] In this embodiment, the authentication and encryption function selects an authentication method based on the service type sent by the UDM network element. For example, if the value of the service type is 1, the terminal authentication method based on the security resource pool is selected; if the value of the service type is 0, the traditional authentication method is selected.
[0133] 7. The authentication and encryption function generates an authentication vector.
[0134] In this embodiment, the authentication and encryption function is based on the selected authentication method, which is the terminal authentication method based on the security resource pool. The authentication and encryption function determines the authentication root key of the terminal based on the SUPI, generates an authentication vector, and the authentication vector includes the expected response XRES*, a random number RAND, and an authentication token AUTH.
[0135] 8. The authentication and encryption function generates an authentication identifier AutID corresponding to the authentication vector.
[0136] 9. The authentication and encryption function sends RAND, AUTH, AutID, and SUPI to the UDM network element.
[0137] In this embodiment, if the terminal identifier in step 1 is the SUPI, the authentication and encryption function does not need to send the SUPI to the UDM network element.
[0138] 10. The UDM network element sends RAND, AUTH, AutID, and SUPI to the AUSF.
[0139] In this embodiment, the UDM network element sends a terminal authentication response to the AUSF, and the terminal authentication response carries RAND, AUTH, AutID, and SUPI. Among them, the terminal authentication response is, for example: Nudm_UE authentication response, corresponding to the Nudm_UE authentication request in step 3.
[0140] It should be noted that if the terminal identifier in step 1 is the SUPI, the UDM network element does not need to send the SUPI to the AUSF.
[0141] 11. The AUSF sends RAND and AUTH to the SEAF.
[0142] In this embodiment, the AUSF sends a terminal authentication response to the SEAF, and the terminal authentication response carries RAND and AUTH. Among them, the terminal authentication response is, for example: Nausf_UE authentication response, corresponding to the Nausf_UE authentication request in step 2.
[0143] 12. The SEAF generates a key identifier ngKSI and sends ngKSI, RAND, and AUTH to the terminal.
[0144] In this embodiment, the SEAF sends an authentication request to the terminal, and the authentication request carries ngKSI, RAND, and AUTH.
[0145] 13. The terminal verifies AUTH.
[0146] In this embodiment, the terminal verifies AUTH. After the verification passes, the terminal calculates the terminal response RES* based on RAND and the authentication root key of the terminal.
[0147] 14. The terminal sends RES* to SEAF.
[0148] In this embodiment, the terminal sends an Authentication response to SEAF, and the Authentication response carries RES*.
[0149] 15. SEAF sends RES* to AUSF.
[0150] In this embodiment, SEAF sends a terminal authentication request to AUSF, and the terminal authentication request carries RES*. The terminal authentication request is, for example: Nausf_UE Authentication Request.
[0151] 16. AUSF sends RES* and AutID to the authentication and encryption function.
[0152] In this embodiment, AUSF sends a terminal verification request to the authentication and encryption function, and the terminal verification request carries RES* and AutID.
[0153] 17. The authentication and encryption function authenticates RES*.
[0154] In this embodiment, after receiving the terminal verification request sent by AUSF, the authentication and encryption function looks up the corresponding authentication vector based on the AutID carried in the terminal verification request, and compares the RES* carried in the terminal verification request with the XRES* in the found authentication vector. If they are the same, it is confirmed that the terminal passes the authentication.
[0155] 18. After the authentication and encryption function confirms that the terminal passes the authentication, it generates the anchor key Kseaf.
[0156] In this embodiment, the authentication and encryption function calculates the anchor key Kseaf using the key Kausf of AUSF.
[0157] 19. The authentication and encryption function sends the authentication security context to the communication encryption function, and the authentication security context includes: SUPI, Kseaf, and AutID.
[0158] In this embodiment, the authentication and encryption function, the communication encryption function, the UDM network element, AUSF, and SEAF use the authentication security context constructed by the authentication vector identified by AutID, and AutID serves as the keyword for the security context interaction and data security processing between each network element, so that the security capabilities distributed in different network elements work as a whole, improving the authentication security.
[0159] In this embodiment, after the authentication and encryption function generates the anchor key Kseaf, it sends an authentication security context to the communication encryption function. The authentication security context includes: SUPI, Kseaf, and AutID.
[0160] 20. The authentication and encryption function sends the authentication result to the AUSF.
[0161] In this embodiment, after the authentication and encryption function confirms that the terminal passes the authentication or the terminal fails the authentication, it sends a terminal verification response to the AUSF. The terminal verification response carries the authentication result, and the authentication result is that the terminal passes the authentication or the terminal fails the authentication. Among them, the terminal verification response corresponds to the terminal verification request in step 16.
[0162] 21. The AUSF sends AutID and SUPI to the SEAF.
[0163] In this embodiment, after the AUSF confirms that the terminal passes the authentication, it sends a terminal authentication response to the SEAF. The terminal authentication response carries AutID and SUPI. Among them, the terminal authentication response is, for example: Nausf_UE authentication response, corresponding to the Nausf_UE authentication request in step 15.
[0164] It should be noted that if the terminal identifier in step 1 is the user permanent identifier SUPI, the AUSF does not need to send the SUPI to the SEAF.
[0165] 22. The SEAF provides AutID and SUPI to the authentication management function AMF.
[0166] In this embodiment, if the terminal identifier in step 1 is the user permanent identifier SUPI, the SEAF does not need to provide the SUPI to the AMF.
[0167] Figure 3 This is another interaction schematic diagram of terminal authentication based on a security resource pool provided by the embodiments of the present disclosure. Figure 3 For the interaction process of network function-triggered authentication, it includes the following steps 1 to step 6:
[0168] 1. The authentication and encryption function receives an authentication request sent by the network function NF.
[0169] In this embodiment, the NF triggers the authentication. According to different authentication policies and events, the parameters in the authentication request may include User Plane Update (UPU) or Authentication and Key Management Akma Anchor Function (AAnF).
[0170] 2. Based on the authentication request, the authentication and encryption function sends an authentication notice to the unified data management UDM network element.
[0171] 3. The UDM network element checks whether the authentication process is in progress. If not, the UDM network element determines the SEAF corresponding to the terminal to be authenticated.
[0172] 4. The UDM sends a notification message to the SEAF, and the SUPI of the terminal to be authenticated is carried in the notification message.
[0173] 5. After receiving the notification message, the SEAF determines whether to authenticate the terminal to be authenticated based on the local authentication policy and returns the result to the authentication and encryption function.
[0174] 6. The AMF performs the primary authentication process.
[0175] In this embodiment, if the result returned by the SEAF to the AMF is to perform authentication, the AMF performs authentication according to the authentication process after steps 1 and 2 of the interactive process of triggering authentication by the terminal as shown in Figure 2 shown.
[0176] Figure 4 is a schematic diagram of a security capability architecture provided by an embodiment of the present disclosure. As shown in Figure 4 shown, the security capability architecture includes: a security resource pool layer, a security controller layer, and a security service layer.
[0177] The security capabilities in the security resource pool layer include but are not limited to: security encryption algorithms, access authentication protocols, NAS security protocols, integrity algorithms, asymmetric keys, key derivation, etc. In this embodiment, by abstracting and pooling the security capabilities in the multi-mode heterogeneous network system, and using virtualization technology and software-defined technology, the differentiated security network elements are abstracted into multiple unified resource pools with different security capabilities.
[0178] The security service layer is used to provide an external security service interface.
[0179] The multiple network elements corresponding to the security resource pool layer include but are not limited to: AMF, SEAF, AUSF, UDM network element, authentication and encryption function, communication encryption function, etc. The authentication and encryption function and the communication encryption function are independent network functions of the core network proposed in this embodiment. The authentication and encryption function can use multiple security capabilities of the security resource pool to perform password operations related to authentication, store the authentication keys of subscribed users, store various keys and related data generated during the authentication process, etc.
[0180] Figure 4 In, the network element corresponding to the security controller layer receives a security service request sent by the terminal or the network function NF through the security service interface.
[0181] Figure 4Among them, the network element corresponding to the security controller layer schedules at least one of the multiple network elements corresponding to the security resource pool layer to provide security capabilities for the security requirement information carried in the security service request. Among them, the security requirement information includes, but is not limited to: authentication service requirements, integrity service requirements, security situation detection requirements, and digital signatures. If the security requirement information is an authentication service requirement, it can be in accordance with Figure 2 and Figure 3 The interaction process shown schedules at least one of the multiple network elements corresponding to the security resource pool layer to complete the authentication interaction. Other security requirement information is not the focus of this article and will not be described in detail.
[0182] Figure 4 Among them, after the network element corresponding to the security controller layer obtains the security service result fed back by the scheduled network element, it sends the security service result to the terminal or the network function NF.
[0183] In some embodiments, the network element corresponding to the security controller layer implements multiple functions. For example, it includes, but is not limited to, security situation analysis, policy conflict detection, policy distribution, and priority definition. These functions are not in this article and will not be described in detail.
[0184] In summary, the network element corresponding to the security controller layer can perform situation analysis of network security, and through programmable unified management and control, realize dynamic security policy generation, dynamically deploy network element security functions, and achieve coordinated orchestration of network security resources for the dynamic orchestration and management of network element security functions, and complete the dynamic configuration and orchestration of on-demand network security functions.
[0185] It should be noted that for the foregoing method embodiments, for the sake of simple description, they are all expressed as a series of action combinations. However, those skilled in the art can understand that the embodiments of the present disclosure are not limited by the described action sequence, because according to the embodiments of the present disclosure, certain steps can be performed in other sequences or simultaneously. In addition, those skilled in the art can understand that the embodiments described in the specification are all optional embodiments.
[0186] Figure 5 It is a schematic diagram of a terminal authentication device based on a security resource pool provided by an embodiment of the present disclosure. Among them, the security resource pool corresponds to the security resource pool layer of the security capability architecture, and the network elements of the security resource pool layer include: authentication and encryption functions; this device is applied to the authentication and encryption functions. As Figure 5 shown, the terminal authentication device based on the security resource pool includes, but is not limited to: a first unit 51, a second unit 52, a third unit 53, a fourth unit 54, a fifth unit 55, and a sixth unit 56. The function descriptions of each unit are as follows:
[0187] The first unit 51 is used to receive the service type sent by the Unified Data Management (UDM) network element and the terminal identifier of the terminal to be authenticated;
[0188] The second unit 52 is used to select an authentication method based on the service type;
[0189] The third unit 53 is used to, if the authentication method selected by the second unit is the terminal authentication method based on the security resource pool, generate an authentication vector and the authentication identifier AutID corresponding to the authentication vector based on the terminal identifier, and the authentication vector includes an expected response;
[0190] The fourth unit 54 is used to send the elements in the authentication vector and AutID to the UDM network element, and the elements in the authentication vector and AutID are sent by the UDM network element to the Authentication Server Function (AUSF);
[0191] The fifth unit 55 is used to receive the terminal response and AutID sent by the AUSF;
[0192] The sixth unit 56 is used to find the corresponding authentication vector based on AutID and compare the terminal response with the expected response in the found authentication vector. If they are the same, it is confirmed that the terminal to be authenticated passes the authentication.
[0193] In some embodiments, the third unit 53 is further used to:
[0194] If the terminal identifier is the Subscriber Concealed Identifier (SUCI), before generating the authentication vector and the authentication identifier AutID corresponding to the authentication vector based on the terminal identifier, receive the SUCI decryption request sent by the UDM network element; decrypt the SUCI of the terminal to be authenticated in response to the SUCI decryption request to obtain the Subscriber Permanent Identifier (SUPI) of the terminal to be authenticated;
[0195] Correspondingly, the third unit 53 generates the authentication vector and the authentication identifier AutID corresponding to the authentication vector based on the terminal identifier, including: generating the authentication vector and the authentication identifier AutID corresponding to the authentication vector based on the SUPI.
[0196] In some embodiments, the authentication vector includes a random number RAND and an authentication token AUTH;
[0197] The fourth unit 54 is used to send RAND, AUTH, and AutID to the UDM network element, and RAND, AUTH, and AutID are sent by the UDM network element to the AUSF;
[0198] Correspondingly, the terminal response is: after the terminal verifies that AUTH passes, the terminal response calculated by the terminal based on RAND and the terminal's authentication root key.
[0199] In some embodiments, the network element in the security resource pool layer further includes: a communication encryption function. The terminal authentication device based on the security resource pool further includes:
[0200] A seventh unit, configured to generate an anchor key Kseaf after confirming that the terminal to be authenticated passes the authentication; and send the authentication security context to the communication encryption function. The authentication security context includes: a terminal identifier, Kseaf, and AutID, and is used for the communication encryption function to encrypt the communication data of the terminal that passes the authentication.
[0201] In some embodiments, the terminal authentication device based on the security resource pool further includes:
[0202] An eighth unit, configured to send the authentication result to the AUSF after confirming that the terminal to be authenticated passes the authentication. The AutID is sent by the AUSF to the security anchoring function SEAF, and the AutID and the permanent user identifier SUPI of the terminal that passes the authentication are sent by the SEAF to the access and mobility management function AMF.
[0203] In some embodiments, the service type and the terminal identifier of the terminal to be authenticated are information carried in the terminal authentication request. The terminal authentication request is sent by the security anchoring function SEAF to the AUSF after the terminal to be authenticated sends a registration request to the SEAF, and the AUSF sends the terminal authentication request to the UDM network element.
[0204] In some embodiments, the terminal authentication device based on the security resource pool further includes a ninth unit, configured to:
[0205] Receive a terminal authentication request sent by a network function NF;
[0206] Based on the terminal authentication request, send a terminal authentication notification to the UDM network element. The terminal authentication notification is used for: the UDM network element checks whether a terminal authentication process is in progress. If not, the UDM network element determines the security anchoring function SEAF corresponding to the terminal to be authenticated; the UDM sends a notification message to the SEAF, and the notification message carries the terminal identifier of the terminal to be authenticated;
[0207] Receive a determination result sent by the SEAF. The determination result is used to determine whether to authenticate the terminal to be authenticated, and the determination result is: after receiving the notification message, the SEAF determines whether to authenticate the terminal to be authenticated based on the local authentication policy.
[0208] In some embodiments, the first unit 51 is further configured to, after the ninth unit receives the determination result sent by the SEAF, if the determination result is to authenticate the terminal to be authenticated, receive the service type and the terminal identifier of the terminal to be authenticated sent by the unified data management UDM network element.
[0209] In some embodiments, the communication encryption function and the authentication encryption function are deployed on the same physical device.
[0210] Figure 5 For the details of each embodiment of the terminal authentication device based on the security resource pool shown, refer to Figure 1 For the details of each embodiment of the terminal authentication method based on the security resource pool shown, they will not be elaborated here.
[0211] The embodiments of the present disclosure also provide a processor-readable storage medium. The processor-readable storage medium stores a program, and the program is used to cause the processor to execute Figure 1 the steps of each embodiment of the terminal authentication method based on the security resource pool shown. The processor-readable storage medium may be a non-transitory computer-readable storage medium.
[0212] The processor-readable storage medium may be any available medium or data storage device that the processor can access, including but not limited to magnetic memories (such as floppy disks, hard disks, magnetic tapes, magneto-optical discs (MO), etc.), optical memories (such as CDs, DVDs, BDs, HVDs, etc.), and semiconductor memories (such as ROMs, EPROMs, EEPROMs, non-volatile memories (NANDFLASH), solid-state drives (SSD), etc.).
[0213] Figure 6 The following is a schematic diagram of a communication device provided by an embodiment of the present disclosure. As Figure 6 shown, the communication device provided by the embodiment of the present disclosure includes a memory 61, a transceiver 62, and a processor 63:
[0214] The memory 61 is used to store computer programs; the transceiver 62 is used to send and receive data under the control of the processor 63; the processor 63 is used to read the computer programs in the memory 61 and execute:
[0215] Receive the service type and the terminal identifier of the terminal to be authenticated sent by the unified data management UDM network element;
[0216] Select an authentication method based on the service type;
[0217] If the selected authentication method is the terminal authentication method based on the security resource pool, then generate an authentication vector and an authentication identifier AutID corresponding to the authentication vector based on the terminal identifier. The authentication vector includes an expected response;
[0218] Send the elements in the authentication vector and AutID to the UDM network element, and the elements in the authentication vector and AutID are sent by the UDM network element to the authentication service function AUSF;
[0219] Receive the terminal response and AutID sent by the AUSF;
[0220] Find the corresponding authentication vector based on the AutID, and compare the terminal response with the expected response in the found authentication vector. If they are the same, confirm that the terminal to be authenticated passes the authentication.
[0221] In some embodiments, if the terminal identifier is the subscriber-concealed identifier SUCI, before generating the authentication vector and the corresponding authentication identifier AutID based on the terminal identifier, the processor 63 is further configured to:
[0222] Receive the SUCI decryption request sent by the UDM network element;
[0223] In response to the SUCI decryption request, decrypt the SUCI of the terminal to be authenticated to obtain the subscriber permanent identifier SUPI of the terminal to be authenticated;
[0224] Accordingly, generating the authentication vector and the corresponding authentication identifier AutID based on the terminal identifier includes:
[0225] Generate the authentication vector and the corresponding authentication identifier AutID based on the SUPI.
[0226] In some embodiments, the authentication vector includes a random number RAND and an authentication token AUTH;
[0227] Send the elements in the authentication vector and the AutID to the UDM network element, and the elements in the authentication vector and the AutID are sent by the UDM network element to the authentication service function AUSF, including:
[0228] Send the RAND, AUTH, and AutID to the UDM network element, and the RAND, AUTH, and AutID are sent by the UDM network element to the AUSF;
[0229] Accordingly, the terminal response is: after the terminal verifies that the AUTH passes, the terminal response calculated by the terminal based on the RAND and the authentication root key of the terminal.
[0230] In some embodiments, the processor 63 is further configured to:
[0231] After confirming that the terminal to be authenticated passes the authentication, generate an anchor key Kseaf;
[0232] Send the authentication security context to the communication encryption function. The authentication security context includes: the terminal identifier, the Kseaf, and the AutID, and the authentication security context is used by the communication encryption function to encrypt the communication data of the authenticated terminal.
[0233] In some embodiments, the processor 63 is further configured to:
[0234] After confirming that the terminal to be authenticated has passed the authentication, the authentication result is sent to the AUSF. The AutID is sent by the AUSF to the Security Anchor Function (SEAF), and the AutID and the Subscriber Permanent Identifier (SUPI) of the authenticated terminal are sent by the SEAF to the Access and Mobility Management Function (AMF).
[0235] In some embodiments, the service type and the terminal identifier of the terminal to be authenticated are information carried in the terminal authentication request. The terminal authentication request is the terminal authentication request sent by the Security Anchor Function (SEAF) to the AUSF after the terminal to be authenticated sends a registration request to the SEAF, and the AUSF sends the terminal authentication request to the UDM network element.
[0236] In some embodiments, the processor 63 is further configured to:
[0237] Receive the terminal authentication request sent by the Network Function (NF);
[0238] Based on the terminal authentication request, send a terminal authentication notification to the UDM network element. The terminal authentication notification is used for: the UDM network element checks whether a terminal authentication process is in progress. If not, the UDM network element determines the Security Anchor Function (SEAF) corresponding to the terminal to be authenticated; the UDM sends a notification message to the SEAF, and the notification message carries the terminal identifier of the terminal to be authenticated;
[0239] Receive the determination result sent by the SEAF. The determination result is used to determine whether to authenticate the terminal to be authenticated, and the determination result is: after the SEAF receives the notification message, the SEAF determines whether to authenticate the terminal to be authenticated based on the local authentication policy.
[0240] In some embodiments, the processor 63 is further configured to:
[0241] After receiving the determination result sent by the SEAF, if the determination result is to authenticate the terminal to be authenticated, then receive the service type and the terminal identifier of the terminal to be authenticated sent by the Unified Data Management (UDM) network element, and subsequent steps.
[0242] In some embodiments, the communication encryption function and the authentication encryption function are deployed on the same physical device.
[0243] Figure 6Among them, the transceiver 62 is used to receive and send data under the control of the processor 63. The bus architecture may include any number of interconnected buses and bridges, specifically, various circuits represented by one or more processors represented by the processor 63 and the memory represented by the memory 61 are linked together. The bus architecture can also link together various other circuits such as peripheral devices, voltage regulators, and power management circuits, which are well known in the art, and thus will not be further described herein. The bus interface provides an interface. The transceiver 62 can be multiple components, that is, including a transmitter and a receiver, and provides a unit for communicating with various other devices on a transmission medium, and these transmission media include wireless channels, wired channels, optical fiber cables, and other transmission media. The processor 63 is responsible for managing the bus architecture and general processing, and the memory 61 can store the data used by the processor 63 when executing operations.
[0244] Figure 6 Among them, the processor 63 can be an integrated circuit chip with the ability to process signals. In the implementation process, each step of the above method can be completed by the integrated logic circuit in the hardware of the processor 63 or the instructions in the form of software. The processor 63 can be a general-purpose processor, a digital signal processor (DSP), an application specific integrated circuit (ASIC), a field programmable gate array (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components. The general-purpose processor can be a microprocessor or the processor can also be any conventional processor, etc.
[0245] It should be noted that in this article, the term "including", "comprising" or any other variant thereof is intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements not only includes those elements, but also includes other elements not explicitly listed, or also includes elements inherent to such process, method, article or device. Without further limitation, the element defined by the statement "including..." does not exclude the existence of additional identical elements in the process, method, article or device including the element.
[0246] Those skilled in the art can understand that although some of the embodiments described herein include certain features included in other embodiments rather than other features, the combination of the features of different embodiments means that it is within the scope of the present disclosure and forms different embodiments.
[0247] Those skilled in the art can understand that the descriptions of the respective embodiments have their own emphases. For parts not detailed in a certain embodiment, reference can be made to the relevant descriptions of other embodiments.
[0248] Although the embodiments of the present disclosure have been described in conjunction with the accompanying drawings, those skilled in the art can make various modifications and variations without departing from the spirit and scope of the present disclosure, and such modifications and variations fall within the scope defined by the appended claims.
Claims
1. A terminal authentication method based on a security resource pool, where the security resource pool corresponds to the security resource pool layer of a security capability architecture, and the network elements of the security resource pool layer include: Authentication and encryption function; The method includes: The authentication and encryption function receives the service type and the terminal identifier of the terminal to be authenticated sent by the Unified Data Management (UDM) network element; The authentication and encryption function selects an authentication method based on the service type; If the selected authentication method is the terminal authentication method based on the security resource pool, the authentication and encryption function generates an authentication vector and an authentication identifier AutID corresponding to the authentication vector based on the terminal identifier, and the authentication vector includes an expected response; The authentication and encryption function sends the elements in the authentication vector and the AutID to the UDM network element; The authentication and encryption function receives the terminal response and the AutID sent by the Authentication Service Function (AUSF); The authentication and encryption function looks up the corresponding authentication vector based on the AutID, and compares the terminal response with the expected response in the found authentication vector. If they are the same, it is confirmed that the terminal to be authenticated passes the authentication.
2. The method according to claim 1, wherein If the terminal identifier is the Subscriber Concealed Identifier (SUCI), before the authentication and encryption function generates an authentication vector and an authentication identifier AutID corresponding to the authentication vector based on the terminal identifier, the method further includes: The authentication and encryption function receives the SUCI decryption request sent by the UDM network element; The authentication and encryption function decrypts the SUCI of the terminal to be authenticated in response to the SUCI decryption request to obtain the Subscriber Permanent Identifier (SUPI) of the terminal to be authenticated; Correspondingly, the authentication and encryption function generating an authentication vector and an authentication identifier AutID corresponding to the authentication vector based on the terminal identifier includes: The authentication and encryption function generates an authentication vector and an authentication identifier AutID corresponding to the authentication vector based on the SUPI.
3. The method according to claim 1, wherein, The authentication vector includes a random number RAND and an authentication token AUTH.
4. The method according to claim 1, wherein, The network element in the security resource pool layer further includes: a communication encryption function, and the method further includes: After the authentication and encryption function confirms that the terminal to be authenticated passes the authentication, it generates an anchor key Kseaf; The authentication and encryption function sends the authentication security context to the communication encryption function, and the authentication security context includes: the terminal identifier, the Kseaf, and the AutID, and the authentication security context is used for the communication encryption function to encrypt the communication data of the terminal that passes the authentication.
5. The method according to claim 1, wherein, The method further includes: After the authentication and encryption function confirms that the terminal to be authenticated passes the authentication, it sends the authentication result to the AUSF.
6. The method according to claim 1, wherein, The service type and the terminal identifier of the terminal to be authenticated are the information carried in the terminal authentication request.
7. The method according to claim 1, wherein, The method further includes: The authentication and encryption function receives the terminal authentication request sent by the Network Function (NF); The authentication and encryption function sends a terminal authentication notice to the UDM network element based on the terminal authentication request; The authentication and encryption function receives the determination result sent by the Security Anchor Function (SEAF), and the determination result is used to determine whether to authenticate the terminal to be authenticated.
8. The method according to claim 7, wherein After the authentication and encryption function receives the determination result sent by the SEAF, the method further includes: If the determination result is to authenticate the terminal to be authenticated, the authentication encryption function receives the service type and the terminal identifier of the terminal to be authenticated sent by the Unified Data Management (UDM) network element, as well as the subsequent steps.
9. The method according to claim 4, wherein The communication encryption function and the authentication encryption function are deployed on the same physical device.
10. A terminal authentication device based on a security resource pool, where the security resource pool corresponds to the security resource pool layer of the security capability architecture, and the network elements of the security resource pool layer include: Authentication encryption function; The apparatus is applied to the authentication encryption function, and the apparatus includes: A first unit, configured to receive the service type and the terminal identifier of the terminal to be authenticated sent by the Unified Data Management (UDM) network element; A second unit, configured to select an authentication method based on the service type; A third unit, configured to, if the authentication method selected by the second unit is the terminal authentication method based on the security resource pool, generate an authentication vector and an authentication identifier (AutID) corresponding to the authentication vector based on the terminal identifier, where the authentication vector includes an expected response; A fourth unit, configured to send the elements in the authentication vector and the AutID to the UDM network element; A fifth unit, configured to receive the terminal response and the AutID sent by the Authentication Server Function (AUSF); A sixth unit, configured to look up the corresponding authentication vector based on the AutID, and compare the terminal response with the expected response in the found authentication vector. If they are the same, it is confirmed that the terminal to be authenticated passes the authentication.
11. A communication device, the communication device includes a memory, a transceiver, and a processor: A memory for storing a computer program; The transceiver is configured to transmit and receive data under the control of the processor; The processor is configured to read the computer program in the memory and execute: Receive the service type and the terminal identifier of the terminal to be authenticated sent by the Unified Data Management (UDM) network element; Select an authentication method based on the service type; If the selected authentication method is the terminal authentication method based on the security resource pool, generate an authentication vector and an authentication identifier (AutID) corresponding to the authentication vector based on the terminal identifier, where the authentication vector includes an expected response; Send the elements in the authentication vector and the AutID to the UDM network element; Receive the terminal response and the AutID sent by the Authentication Server Function (AUSF); Look up the corresponding authentication vector based on the AutID, and compare the terminal response with the expected response in the found authentication vector. If they are the same, it is confirmed that the terminal to be authenticated passes the authentication.
12. The communication device according to claim 11, wherein, If the terminal identifier is the Subscriber Concealed Identifier (SUCI), before generating the authentication vector and the authentication identifier (AutID) corresponding to the authentication vector based on the terminal identifier, the processor is further configured to: Receive the SUCI decryption request sent by the UDM network element; In response to the SUCI decryption request, decrypt the SUCI of the terminal to be authenticated to obtain the Subscriber Permanent Identifier (SUPI) of the terminal to be authenticated; Accordingly, generating the authentication vector and the authentication identifier (AutID) corresponding to the authentication vector based on the terminal identifier includes: Generating the authentication vector and the authentication identifier (AutID) corresponding to the authentication vector based on the SUPI.
13. The communication device according to claim 11, wherein, The authentication vector includes a random number (RAND) and an authentication token (AUTH).
14. The communication device according to claim 11, wherein, The processor is further configured to: After confirming that the terminal to be authenticated passes the authentication, generate an anchor key Kseaf; Send the authentication security context to the communication encryption function. The authentication security context includes: the terminal identifier, the Kseaf, and the AutID. The authentication security context is used by the communication encryption function to encrypt the communication data of the terminal that has passed the authentication.
15. The communication device according to claim 11, wherein, The processor is further configured to: After confirming that the terminal to be authenticated passes the authentication, send the authentication result to the AUSF.
16. The communication device according to claim 11, wherein, The service type and the terminal identifier of the terminal to be authenticated are the information carried in the terminal authentication request.
17. The communication device according to claim 11, wherein, The processor is further configured to: Receive a terminal authentication request sent by a network function NF; Based on the terminal authentication request, send a terminal authentication notification to the UDM network element; Receive a determination result sent by the security anchoring function SEAF, where the determination result is used to determine whether to authenticate the terminal to be authenticated.
18. The communication device according to claim 17, wherein, The processor is further configured to: After receiving the determination result sent by the SEAF, if the determination result is to authenticate the terminal to be authenticated, then receive the service type and the terminal identifier of the terminal to be authenticated sent by the unified data management UDM network element, and subsequent steps.
19. The communication device according to claim 14, wherein, The communication encryption function and the authentication encryption function are deployed on the same physical device.
20. A processor-readable storage medium, characterized in that, The processor-readable storage medium stores a program, and the program is used to cause the processor to execute the terminal authentication method based on a security resource pool according to any one of claims 1 to 9.