Terminal network access method and device, computer equipment and storage medium

By using hidden identification and authentication vectors in the integrated air-space and earth network, the identity security risks during user terminal access are solved, communication security and authentication accuracy are improved, information leakage is avoided and the authentication burden of the ground network is shared.

CN120264276APending Publication Date: 2025-07-04CHINA TELECOM CORP LTD TECHNOLOGY INNOVATION CENTER +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510335590.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-20
Publication Date
2025-07-04

AI Technical Summary

Technical Problem

In the integrated air-space and earth network, when user terminals access the network, communication is easily interfered with, and there are identity security risks such as counterfeiting, deception, and tracking, which affects communication security.

Method used

By receiving an authentication request with a hidden identifier initiated by the user terminal, a first authentication response message is generated, and the authentication result is obtained based on the authentication related network elements of the satellite network, and the authentication result is sent to the ground network to determine whether the user terminal is allowed to access the ground network, and the authentication accuracy and security are improved using the hidden identifier and authentication vector.

Benefits of technology

Effectively avoid attackers stealing user information, increase the security of terminals when entering the network, and share the authentication pressure of ground networks, and improve the authentication capabilities of satellite networks for user terminals.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120264276A_ABST
    Figure CN120264276A_ABST
Patent Text Reader

Abstract

The invention discloses a terminal network access method and device, computer equipment and a storage medium. Belongs to the technical field of satellite communication. The method specifically comprises the following steps: receiving a first authentication request which is initiated by a user terminal and carries a hidden identifier; wherein the hidden identifier is obtained by encrypting a user identifier of the user terminal based on the encryption key by the user terminal. Generating a first authentication response message based on the hidden identifier; and obtaining an authentication result based on the first authentication response message, the user terminal and an authentication association network element of the satellite network. And sending the authentication result to the ground network, so that the ground network determines whether to allow the user terminal to access the ground network through the satellite network based on the authentication result. According to the invention, the situation that an attacker steals the user information can be effectively avoided, the security of the terminal in network access is improved, the authentication of the user terminal based on the satellite network is realized, and the authentication pressure of a ground network is shared.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of satellite communication technology, and particularly to a method and apparatus for terminal network access, a computer device, and a storage medium. Background Art

[0002] Ubiquitous connection means that seamless, high-speed, and reliable communication connections can be achieved at any time and any place. Ubiquitous connection is a new scenario in the 6G network of the sixth-generation mobile communication technology, including connections with heterogeneous networks such as satellite networks, industrial networks, and body area networks, such as the space-air-ground integrated network. The space-air-ground integrated network is a network of integrated cooperation relying on the ground network and expanding with the space-based network and the air-based network, covering scenarios such as cross-domain deployment of network elements and remote operation and maintenance.

[0003] However, the network topology of the space-air-ground integrated network is dynamically changeable and has a complex structure. The wireless link is highly exposed in the open space, and the transmission channel is open and has a large distance span. Therefore, during communication, especially when a user terminal accesses the network, the communication is easily interfered, and there are identity security risks such as impersonation, deception, and tracking. Summary of the Invention

[0004] Based on this, it is necessary to provide a method and apparatus for terminal network access, a computer device, and a storage medium that can improve the security of network access for the above technical problems.

[0005] In a first aspect, this application provides a method for terminal network access, which is applied to the UDM network element of a satellite network and includes:

[0006] Receiving a first authentication request carrying a hidden identifier initiated by a user terminal; wherein, the hidden identifier is obtained by the user terminal encrypting the user identifier of the user terminal based on an encryption key;

[0007] Generating a first authentication response message based on the hidden identifier;

[0008] Obtaining an authentication result based on the first authentication response message, the user terminal, and the authentication-related network element of the satellite network;

[0009] Sending the authentication result to the ground network so that the ground network determines whether to allow the user terminal to access the ground network through the satellite network based on the authentication result.

[0010] In one embodiment, generating a first authentication response message based on the hidden identifier includes:

[0011] Performing decryption processing on the hidden identifier to obtain the user identifier;

[0012] Generating an authentication vector based on the user identifier;

[0013] Generate a first authentication response message based on the authentication vector.

[0014] In one embodiment, based on the first authentication response message, the user terminal, and the authentication-related network element of the satellite network, obtain the authentication result, including:

[0015] Based on the first authentication response message and the authentication-related network element of the satellite network, initiate a second authentication request to the user terminal; wherein, the second authentication request is used to instruct the user terminal to feedback a second authentication response message to the authentication-related network element based on the second authentication request; the second authentication response message is used to instruct the authentication-related network element to feedback the authentication result to the UDM network element of the satellite network based on the second authentication response message;

[0016] Receive the authentication result feedback by the authentication-related network element.

[0017] In one embodiment, the authentication-related network element includes an AUSF network element and a SEAF network element;

[0018] Based on the first authentication response message and the authentication-related network element of the satellite network, initiate a second authentication request to the user terminal, including:

[0019] Send the first authentication response message to the AUSF network element; wherein, the first authentication response message is used to instruct the AUSF network element to forward the first authentication response message to the SEAF network element; the first authentication response message is used to instruct the SEAF network element to send a second authentication request to the user terminal based on the first authentication response message.

[0020] In one embodiment, the authentication-related network element includes an AUSF network element and a SEAF network element;

[0021] The second authentication request is specifically used to instruct the user terminal to send a second authentication response message to the SEAF network element based on the second authentication request; the second authentication response message is used to instruct the SEAF network element to forward the second authentication response message to the AUSF network element.

[0022] In one embodiment, the second authentication response message is specifically used to instruct the AUSF network element to feedback the authentication result to the UDM network element of the satellite network based on the second authentication response message.

[0023] In one embodiment, send the authentication result to the terrestrial network so that the terrestrial network determines whether to allow the user terminal to access the terrestrial network through the satellite network based on the authentication result, including:

[0024] Perform signature processing on the authentication result based on the signature algorithm, and send the signed authentication result to the UDM network element of the terrestrial network, so that the UDM network element of the terrestrial network verifies the signature of the signed authentication result and determines whether to allow the user terminal to access the terrestrial network through the satellite network based on the verification result.

[0025] In a second aspect, the present application provides a terminal network access device, which includes:

[0026] A receiving module, configured to receive a first authentication request carrying a hidden identifier initiated by a user terminal; wherein, the hidden identifier is obtained by the user terminal encrypting the user identifier of the user terminal based on an encryption key;

[0027] A generating module, configured to generate a first authentication response message based on the hidden identifier;

[0028] An obtaining module, configured to obtain an authentication result based on the first authentication response message, the user terminal, and an authentication related network element of the satellite network;

[0029] A sending module, configured to send the authentication result to the terrestrial network, so that the terrestrial network determines whether to allow the user terminal to access the terrestrial network through the satellite network based on the authentication result.

[0030] In a third aspect, the present application further provides a computer device, which includes a memory and a processor. The memory stores a computer program, and when the processor executes the computer program, the following steps are implemented:

[0031] Receive a first authentication request carrying a hidden identifier initiated by a user terminal; wherein, the hidden identifier is obtained by the user terminal encrypting the user identifier of the user terminal based on an encryption key;

[0032] Generate a first authentication response message based on the hidden identifier;

[0033] Obtain an authentication result based on the first authentication response message, the user terminal, and an authentication related network element of the satellite network;

[0034] Send the authentication result to the terrestrial network, so that the terrestrial network determines whether to allow the user terminal to access the terrestrial network through the satellite network based on the authentication result.

[0035] In a fourth aspect, the present application further provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the following steps are implemented:

[0036] Receive a first authentication request carrying a hidden identifier initiated by a user terminal; wherein, the hidden identifier is obtained by the user terminal encrypting the user identifier of the user terminal based on an encryption key;

[0037] Generate a first authentication response message based on the hidden identifier;

[0038] Obtain an authentication result based on the first authentication response message, the user terminal, and an authentication related network element of the satellite network;

[0039] Send the authentication result to the terrestrial network so that the terrestrial network can determine whether to allow the user terminal to access the terrestrial network through the satellite network based on the authentication result.

[0040] In a fifth aspect, the present application also provides a computer program product, which includes a computer program. When the computer program is executed by a processor, the following steps are implemented:

[0041] Receive a first authentication request carrying a hidden identifier initiated by the user terminal; wherein, the hidden identifier is obtained by the user terminal encrypting the user identifier of the user terminal based on an encryption key;

[0042] Generate a first authentication response message based on the hidden identifier;

[0043] Obtain an authentication result based on the first authentication response message, the authentication related network element of the user terminal and the satellite network;

[0044] Send the authentication result to the terrestrial network so that the terrestrial network can determine whether to allow the user terminal to access the terrestrial network through the satellite network based on the authentication result.

[0045] For the above terminal network access method, device, computer device and storage medium, receive a first authentication request carrying a hidden identifier initiated by the user terminal; wherein, the hidden identifier is obtained by the user terminal encrypting the user identifier of the user terminal based on an encryption key. Generate a first authentication response message based on the hidden identifier; and obtain an authentication result based on the first authentication response message, the authentication related network element of the user terminal and the satellite network. Send the authentication result to the terrestrial network so that the terrestrial network can determine whether to allow the user terminal to access the terrestrial network through the satellite network. In the present application, initiating a first authentication request to the satellite network based on the hidden identifier can effectively avoid the situation where an attacker steals user information, not only increasing the security during terminal network access, but also realizing the authentication of the user terminal based on the satellite network and sharing the authentication pressure of the terrestrial network. Description of the Drawings

[0046] Figure 1 It is an application environment diagram of a terminal network access method provided in this embodiment;

[0047] Figure 2 It is a flowchart of the first terminal network access method provided in this embodiment;

[0048] Figure 3 It is a flowchart of generating the first authentication response message provided in this embodiment;

[0049] Figure 4 It is a flowchart of receiving the authentication result fed back by the authentication related network element provided in this embodiment;

[0050] Figure 5 It is a schematic flowchart of the second terminal network access method provided in this embodiment;

[0051] Figure 6 It is a structural block diagram of a terminal network access device provided in this embodiment;

[0052] Figure 7 It is an internal structure diagram of a computer device provided in this embodiment. Detailed implementation manners

[0053] In order to make the objectives, technical solutions and advantages of this application clearer, the following further describes this application in detail with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain this application and are not used to limit this application.

[0054] The terminal network access method provided in the embodiments of this application is mainly applied to an application environment as Figure 1 shown. Among them, the UMD network element in the satellite network receives a first authentication request carrying a hidden identifier initiated by a user terminal. The UMD network element in the satellite network generates a first authentication response message based on the hidden identifier; and obtains an authentication result based on the first authentication response message, the user terminal, and the authentication-related network element of the satellite network; the UMD network element in the satellite network sends the authentication result to the terrestrial network, so that the terrestrial network determines whether to allow the user terminal to access the terrestrial network through the satellite network based on the authentication result. Among them, the hidden identifier is obtained by the user terminal encrypting the user identifier of the user terminal based on an encryption key.

[0055] Among them, the satellite network refers to a network composed of a series of communication satellites distributed in the earth's orbit for providing global communication services. The satellite network of this application mainly refers to the space-based network in the 5G / 6G space-air-ground integrated security network.

[0056] The UMD network element (Unified Data Management) is responsible for the management of user identifiers, subscribed data, authentication data, and the registration management of the user's serving network elements.

[0057] The terrestrial network refers to a mobile communication network configured on land, which can be a 5G communication network or a 6G communication network.

[0058] The user terminal refers to a terminal device on the user side, including but not limited to intelligent terminals such as mobile phones and computers, and can also be intelligent wearable devices such as smart watches and smart bracelets.

[0059] In one embodiment, Figure 2 is a schematic flowchart of a terminal network access method provided in the embodiments of this application, where this method is applied toFigure 1 Taking the UDM network element in the satellite network in

[0060] S201, receiving a first authentication request carrying a hidden identifier initiated by a user terminal.

[0061] Among them, the hidden identifier is obtained by the user terminal encrypting the user identifier of the user terminal based on an encryption key. The hidden identifier refers to the identifier obtained after encrypting the user identifier. The user identifier refers to the unique identifier used to represent the user identity.

[0062] Optionally, in this embodiment, the user identifier may be SUPI (Subscription Permanent Identifier).

[0063] Optionally, in this embodiment, the hidden identifier may be SUCI (Subscription Concealed Identifier).

[0064] As an alternative implementation manner of the embodiment of the present application, receiving a first authentication request initiated by the user terminal through the authentication-related network element in the satellite network. Optionally, the authentication-related network element includes an AUSF (Authentication Server Function) network element and a SEAF (Security Anchor Function) network element. Specifically, when the user terminal has a communication requirement, the user terminal sends an initial registration request carrying a hidden identifier to the SEAF network element. The SEAF network element generates a first authentication request carrying a hidden identifier based on the initial registration request and the standard authentication process (i.e., the 3GPP (3rd Generation Partnership Project) standard authentication process), and sends the first authentication request to the AUSF network element. The AUSF network element forwards the first authentication request to the UDM network element.

[0065] As another alternative implementation manner of the embodiment of the present application, the user terminal directly sends a first authentication request carrying a hidden identifier to the UDM network element.

[0066] Optionally, in this embodiment, the user terminal encrypts the user identifier based on the ECIES mechanism to obtain a hidden identifier. Among them, the ECIES mechanism can be an encryption mechanism corresponding to the key encapsulation algorithm of PQC (Post-Quantum Cryptography) (such as ML-KEM (Module Learning with Errors Key Encapsulation Mechanism)), or an encryption mechanism corresponding to the hybrid key encapsulation algorithm. The hybrid key encapsulation algorithm can be an encryption method that mixes the PQC key encapsulation and the classical DH key negotiation algorithm. It should be noted that the public keys corresponding to the encryption keys or encryption mechanisms need to be pre-configured in the satellite network and the terrestrial network for decrypting the encrypted messages.

[0067] S202. Generate a first authentication response message based on the hidden identifier.

[0068] Among them, the first authentication response message refers to the response message corresponding to the first authentication request generated by the UDM network element based on the hidden identifier.

[0069] Optionally, in this embodiment, the hidden identifier is decrypted, and a first authentication response message is generated based on the decryption result.

[0070] S203. Obtain an authentication result based on the first authentication response message, the user terminal, and the authentication-related network element of the satellite network.

[0071] Among them, the authentication result refers to the result of the registration authentication of the user terminal.

[0072] As an alternative implementation manner of this embodiment of the present application, an authentication request is generated based on the first authentication response message. An authentication result is obtained according to the user terminal, the authentication request, and the authentication-related network element of the satellite network.

[0073] S204. Send the authentication result to the terrestrial network so that the terrestrial network determines whether to allow the user terminal to access the terrestrial network through the satellite network based on the authentication result.

[0074] As an alternative implementation manner of this embodiment of the present application, the authentication result is sent to the terrestrial network so that the terrestrial network determines whether to allow the user terminal to access the terrestrial network through the satellite network based on the authentication result. For example, if the authentication result is authentication passed, it is determined that the user terminal is allowed to access the terrestrial network through the satellite network. If the authentication result is authentication failed, it is determined that the user terminal is not allowed to access the terrestrial network through the satellite network.

[0075] As another alternative implementation manner of the embodiment of the present application, the authentication result is signed based on a signature algorithm, and the signed authentication result is sent to the UDM network element of the terrestrial network, so that the UDM network element of the terrestrial network verifies the signature of the signed authentication result, and determines whether to allow the user terminal to access the terrestrial network through the satellite network based on the signature verification result. Optionally, the signature algorithm may be but is not limited to a PQC digital signature algorithm (for example, Dilithium). The UDM network element of the terrestrial network has a public key corresponding to the PQC digital signature algorithm, so that the UDM network element of the terrestrial network verifies the signature of the authenticated result after signature processing, obtains the validity of the authentication result according to the signature verification result, and determines whether to allow the user terminal to access the terrestrial network through the satellite network based on the authentication result when the validity is valid.

[0076] As yet another alternative implementation manner of the embodiment of the present application, the available situation of the feeder link between the satellite network and the terrestrial network is obtained. When the available situation is available, the authentication result is sent to the terrestrial network, so that the terrestrial network determines whether to allow the user terminal to access the terrestrial network through the satellite network based on the authentication result. That is to say, only when the available situation of the feeder link is available, the UDM network element of the satellite network synchronizes the authentication result with the UDM network element of the terrestrial network, solving the problem of terminal network access failure caused by the interruption of the feeder link.

[0077] For the above terminal network access method, a first authentication request carrying a hidden identifier is received; wherein, the hidden identifier is obtained by the user terminal encrypting the user identifier of the user terminal based on an encryption key. A first authentication response message is generated based on the hidden identifier; and an authentication result is obtained based on the first authentication response message, the user terminal, and the authentication related network element of the satellite network. The authentication result is sent to the terrestrial network, so that the terrestrial network determines whether to allow the user terminal to access the terrestrial network through the satellite network based on the authentication result. In the present application, the first authentication request is initiated to the satellite network based on the hidden identifier, which can effectively avoid the situation where an attacker steals user information, not only increases the security during terminal network access, but also realizes the authentication of the user terminal based on the satellite network, sharing the authentication pressure of the terrestrial network.

[0078] In one embodiment, in order to generate the first authentication response message more accurately, as Figure 3 shown, an alternative implementation manner in S202 includes:

[0079] S301, decrypt the hidden identifier to obtain the user identifier.

[0080] Optionally, in this embodiment, the UDM network element of the satellite network is preconfigured with a public key corresponding to the encryption key or encryption mechanism of the user terminal, and the hidden identifier is decrypted based on the preconfigured public key to obtain the user identifier.

[0081] S302. Generate an authentication vector based on the user identifier.

[0082] Among them, the authentication vector (abbreviated as AV) is a set of data used for user authentication in a communication system. These data are usually generated by a network operator or an authentication center and are used to ensure that only legitimate users can access the network.

[0083] Optionally, in this embodiment, based on the user identifier, target information is obtained; an authentication and authorization vector is generated based on the target information and the MILINAGE algorithm. An optional implementation manner of obtaining target information based on the user identifier in this embodiment is to determine the user identity based on the user identifier; obtain user information based on the user identity; and obtain target information from the user information based on the standard authentication process. It should be noted that the standard authentication process refers to the standard authentication process specified by 3GPP, and the specific content will not be elaborated here.

[0084] S303. Generate a first authentication response message based on the authentication vector.

[0085] Optionally, in this embodiment, a first authentication response message is generated based on the authentication vector and the standard authentication process. Exemplarily, based on the authentication vector and the standard authentication process, a target vector is obtained from the authentication vector; a first authentication response message is generated based on the target vector.

[0086] In this embodiment, the hidden identifier is decrypted to obtain the user identifier. An authentication vector is generated based on the user identifier. A first authentication response message is generated based on the authentication vector, so that the obtained first authentication response message is more accurate and more in line with the requirements of the standard authentication process.

[0087] In one of the embodiments, the authentication-related network element includes an AUSF network element and a SEAF network element. In order to obtain the authentication result more accurately, as Figure 4 shown, an optional implementation manner of S203 includes:

[0088] S401. Initiate a second authentication request to the user terminal based on the first authentication response message and the authentication-related network element of the satellite network.

[0089] Among them, the second authentication request is used to instruct the user terminal to feedback a second authentication response message to the authentication-related network element based on the second authentication request; the second authentication response message is used to instruct the authentication-related network element to feedback an authentication result to the UDM network element of the satellite network based on the second authentication response message. The second authentication request refers to a request message for requesting the user terminal to perform authentication.

[0090] Optionally, in this embodiment, a first authentication response message is sent to the AUSF network element; among them, the first authentication response message is used to instruct the AUSF network element to forward the first authentication response message to the SEAF network element; the first authentication response message is used to instruct the SEAF network element to send a second authentication request to the user terminal based on the first authentication response message. An optional implementation manner in which the SEAF network element sends a second authentication request to the user terminal based on the first authentication response message in this embodiment is to generate a second authentication request based on the first authentication response message; and send the second authentication request to the user terminal.

[0091] S402, receive the authentication result feedback by the authentication-related network element.

[0092] Optionally, the second authentication request in this embodiment is specifically used to instruct the user terminal to send a second authentication response message to the SEAF network element based on the second authentication request; the second authentication response message is used to instruct the SEAF network element to forward the second authentication response message to the AUSF network element. That is to say, after receiving the second authentication request, the user terminal will generate a second authentication response message according to the authentication standard process. And send the second authentication response message to the SEAF network element. The SEAF network element forwards the second authentication response message to the AUSF network element. The AUSF network element performs authentication on the user terminal based on the second authentication response message, obtains the authentication result, and sends the authentication result to the UDM network element of the satellite network.

[0093] In this embodiment, a second authentication request is initiated to the user terminal based on the first authentication response message and the authentication-related network element of the satellite network; among them, the second authentication request is used to instruct the user terminal to feedback a second authentication response message to the authentication-related network element based on the second authentication request; the second authentication response message is used to instruct the authentication-related network element to feedback an authentication result to the UDM network element of the satellite network based on the second authentication response message. Receiving the authentication result feedback by the authentication-related network element not only realizes the process of authenticating and authorizing the user terminal based on the satellite network, sharing the burden of ground network authentication and authorization, but also improves the accuracy of the authentication result.

[0094] In one of the embodiments, as Figure 5 shown, an optional implementation manner of a terminal access method includes:

[0095] S501, when there is a communication requirement, the user terminal encrypts the user identifier to obtain a hidden identifier.

[0096] S502, The user terminal sends an initial registration request carrying a hidden identifier to the SEAF network element of the satellite network.

[0097] S503, Based on the initial registration request, the SEAF network element sends a first authentication request carrying a hidden identifier to the AUSF network element of the satellite network.

[0098] S504, The AUSF network element forwards the first authentication request to the UMD network element of the satellite network.

[0099] S505, The UMD network element of the satellite network decrypts the hidden identifier to obtain the user identifier.

[0100] S506, Based on the user identifier, the UMD network element of the satellite network generates an authentication vector.

[0101] S507, Based on the authentication vector, the UMD network element of the satellite network generates a first authentication response message.

[0102] S508, The UMD network element of the satellite network sends the first authentication response message to the AUSF network element.

[0103] S509, The AUSF network element forwards the first authentication response message to the SEAF network element.

[0104] S510, Based on the first authentication response message, the SEAF network element sends a second authentication request to the user terminal.

[0105] S511, Based on the second authentication request, the user terminal sends a second authentication response message to the SEAF network element.

[0106] S512, The SEAF network element forwards the second authentication response message to the AUSF network element.

[0107] S513, Based on the second authentication response message, the AUSF network element feeds back the authentication result to the UDM network element of the satellite network.

[0108] S514, The UDM network element of the satellite network receives the authentication result fed back by the authentication-related network element.

[0109] S515, The UDM network element of the satellite network signs the authentication result based on the signature algorithm and, when the availability of the feeder link is available, sends the signed authentication result to the UDM network element of the terrestrial network.

[0110] S516, The UDM network element of the terrestrial network verifies the signature of the signed authentication result and, based on the verification result, determines whether to allow the user terminal to access the terrestrial network through the satellite network.

[0111] In this embodiment, a first authentication request carrying a hidden identifier is received from a user terminal; the hidden identifier is obtained by the user terminal encrypting the user identifier of the user terminal based on an encryption key. Based on the hidden identifier, a first authentication response message is generated; and based on the first authentication response message, the user terminal, and the authentication-related network element of the satellite network, an authentication result is obtained. The authentication result is sent to the terrestrial network so that the terrestrial network can determine whether to allow the user terminal to access the terrestrial network through the satellite network based on the authentication result. In this application, initiating the first authentication request to the satellite network based on the hidden identifier can effectively prevent attackers from stealing user information, not only enhancing the security when the terminal accesses the network but also implementing the authentication of the user terminal based on the satellite network and sharing the authentication pressure of the terrestrial network.

[0112] It should be understood that although the steps in the flowcharts involved in the above embodiments are shown in sequence according to the arrows, these steps do not necessarily need to be executed in the order indicated by the arrows. Unless there is a clear description in this article, the execution of these steps has no strict order limit, and these steps can be executed in other orders. Moreover, at least some of the steps in the flowcharts involved in the above embodiments may include multiple steps or multiple stages. These steps or stages do not necessarily need to be executed at the same time but can be executed at different times. The execution order of these steps or stages does not necessarily need to be sequential, but can be executed alternately or in turn with at least some of the steps or stages in other steps or other steps.

[0113] Based on the same inventive concept, an embodiment of this application also provides a terminal network access device for implementing the above-mentioned terminal network access method. The solution provided by this device to solve the problem is similar to the solution described in the above method. Therefore, the specific limitations in one or more embodiments of the terminal network access device provided below can refer to the limitations on the terminal network access method in the above text and will not be repeated here.

[0114] In one embodiment, through Figure 6 The structural block diagram of the terminal network access device in one embodiment is shown. As Figure 6 shown, a terminal network access device 1 is provided, which includes: a receiving module 10, a generating module 20, an obtaining module 30, and a sending module 40, where:

[0115] The receiving module 10 is configured to receive a first authentication request carrying a hidden identifier from a user terminal; the hidden identifier is obtained by the user terminal encrypting the user identifier of the user terminal based on an encryption key;

[0116] The generating module 20 is configured to generate a first authentication response message based on the hidden identifier;

[0117] An obtaining module 30, configured to obtain an authentication result based on a first authentication response message, a user terminal, and an authentication related network element of a satellite network;

[0118] A sending module 40, configured to send the authentication result to a terrestrial network, so that the terrestrial network determines whether to allow the user terminal to access the terrestrial network through the satellite network based on the authentication result.

[0119] In one embodiment, the Figure 6 above-mentioned generating module 20 is further specifically configured to:

[0120] Decrypt the hidden identifier to obtain a user identifier;

[0121] Generate an authentication vector based on the user identifier;

[0122] Generate a first authentication response message based on the authentication vector.

[0123] In one embodiment, the Figure 6 above-mentioned obtaining module 30 is further specifically configured to:

[0124] Initiate a second authentication request to the user terminal based on the first authentication response message and the authentication related network element of the satellite network; wherein, the second authentication request is used to instruct the user terminal to feedback a second authentication response message to the authentication related network element based on the second authentication request; the second authentication response message is used to instruct the authentication related network element to feedback the authentication result to the UDM network element of the satellite network based on the second authentication response message;

[0125] Receive the authentication result feedback by the authentication related network element.

[0126] In one embodiment, the authentication related network element includes an AUSF network element and a SEAF network element; on this basis, the Figure 6 above-mentioned obtaining module 30 is further specifically configured to:

[0127] Send the first authentication response message to the AUSF network element; wherein, the first authentication response message is used to instruct the AUSF network element to forward the first authentication response message to the SEAF network element; the first authentication response message is used to instruct the SEAF network element to send a second authentication request to the user terminal based on the first authentication response message.

[0128] In one embodiment, the authentication related network element includes an AUSF network element and a SEAF network element;

[0129] The second authentication request is specifically used to instruct the user terminal to send a second authentication response message to the SEAF network element based on the second authentication request; the second authentication response message is used to instruct the SEAF network element to forward the second authentication response message to the AUSF network element.

[0130] In one embodiment, the two - authentication response message is specifically used to instruct the AUSF network element to feedback the authentication result to the UDM network element of the satellite network based on the second - authentication response message.

[0131] In one embodiment, the Figure 6 sending module 40 in the above also specifically is used for:

[0132] Perform signature processing on the authentication result based on the signature algorithm, and send the signed authentication result to the UDM network element of the terrestrial network, so that the UDM network element of the terrestrial network verifies the signature of the signed authentication result, and based on the verification result, determines whether to allow the user terminal to access the terrestrial network through the satellite network.

[0133] Each module in the above - mentioned terminal network - access device can be implemented in whole or in part by software, hardware, and their combination. The above - mentioned modules can be embedded in the processor of the computer device in hardware form or be independent of it, or be stored in the memory of the computer device in software form, so that the processor can call and execute the operations corresponding to the above - mentioned modules.

[0134] In one embodiment, a computer device is provided. The computer device can be on the platform side, and its internal structure diagram can be as Figure 7 shown. The computer device includes a processor, a memory, and a network interface connected through a system bus. Among them, the processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non - volatile storage medium and an internal memory. The non - volatile storage medium stores an operating system, a computer program, and a database. The internal memory provides an environment for the operation of the operating system and the computer program in the non - volatile storage medium. The database of the computer device is used to store relevant information of the terminal network - access method. The network interface of the computer device is used to communicate with the external user side through a network connection. When the computer program is executed by the processor, it implements a terminal network - access method.

[0135] Those skilled in the art can understand that Figure 7 the structure shown in

[0136] In one embodiment, a computer device is provided, including a memory and a processor. A computer program is stored in the memory. When the processor executes the computer program, the following steps are implemented:

[0137] Receive a first authentication request carrying a hidden identifier initiated by a user terminal; wherein the hidden identifier is obtained by the user terminal encrypting the user identifier of the user terminal based on an encryption key;

[0138] Generate a first authentication response message based on the hidden identifier;

[0139] Obtain an authentication result based on the first authentication response message, the user terminal, and the authentication related network element of the satellite network;

[0140] Send the authentication result to the terrestrial network so that the terrestrial network determines whether to allow the user terminal to access the terrestrial network through the satellite network based on the authentication result.

[0141] In one embodiment, when the processor executes the computer program, the following steps are further implemented: generating a first authentication response message based on the hidden identifier, including:

[0142] Perform decryption processing on the hidden identifier to obtain the user identifier;

[0143] Generate an authentication vector based on the user identifier;

[0144] Generate a first authentication response message based on the authentication vector.

[0145] In one embodiment, when the processor executes the computer program, the following steps are further implemented: obtaining an authentication result based on the first authentication response message, the user terminal, and the authentication related network element of the satellite network, including:

[0146] Initiate a second authentication request to the user terminal based on the first authentication response message and the authentication related network element of the satellite network; wherein the second authentication request is used to instruct the user terminal to feedback a second authentication response message to the authentication related network element based on the second authentication request; the second authentication response message is used to instruct the authentication related network element to feedback the authentication result to the UDM network element of the satellite network based on the second authentication response message;

[0147] Receive the authentication result feedback by the authentication related network element.

[0148] In one embodiment, when the processor executes the computer program, the following steps are further implemented: the authentication related network element includes an AUSF network element and a SEAF network element;

[0149] Initiate a second authentication request to the user terminal based on the first authentication response message and the authentication related network element of the satellite network, including:

[0150] Send the first authentication response message to the AUSF network element; wherein the first authentication response message is used to instruct the AUSF network element to forward the first authentication response message to the SEAF network element; the first authentication response message is used to instruct the SEAF network element to send a second authentication request to the user terminal based on the first authentication response message.

[0151] In one embodiment, when the processor executes the computer program, the following steps are further implemented: authenticating the associated network elements includes an AUSF network element and a SEAF network element;

[0152] The second authentication request is specifically used to instruct the user equipment to send a second authentication response message to the SEAF network element based on the second authentication request; the second authentication response message is used to instruct the SEAF network element to forward the second authentication response message to the AUSF network element.

[0153] In one embodiment, when the processor executes the computer program, the following steps are further implemented: the second authentication response message is specifically used to instruct the AUSF network element to feedback the authentication result to the UDM network element of the satellite network based on the second authentication response message.

[0154] In one embodiment, when the processor executes the computer program, the following steps are further implemented: sending the authentication result to the terrestrial network so that the terrestrial network determines whether to allow the user equipment to access the terrestrial network through the satellite network based on the authentication result, including:

[0155] Performing signature processing on the authentication result based on the signature algorithm, and sending the signed authentication result to the UDM network element of the terrestrial network, so that the UDM network element of the terrestrial network verifies the signature of the signed authentication result, and determines whether to allow the user equipment to access the terrestrial network through the satellite network based on the verification result.

[0156] In one of the embodiments, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by a processor, the following steps are implemented:

[0157] Receiving a first authentication request carried with a hidden identifier initiated by the user equipment; wherein, the hidden identifier is obtained by the user equipment encrypting the user identifier of the user equipment based on an encryption key;

[0158] Generating a first authentication response message based on the hidden identifier;

[0159] Obtaining an authentication result based on the first authentication response message, the user equipment and the authentication associated network elements of the satellite network;

[0160] Sending the authentication result to the terrestrial network so that the terrestrial network determines whether to allow the user equipment to access the terrestrial network through the satellite network based on the authentication result.

[0161] In one embodiment, when the computer program is executed by the processor, the following steps are further implemented: generating a first authentication response message based on the hidden identifier, including:

[0162] Performing decryption processing on the hidden identifier to obtain the user identifier;

[0163] Generate an authentication vector based on the user identifier;

[0164] Generate a first authentication response message based on the authentication vector.

[0165] In one embodiment, when the computer program is executed by a processor, the following steps are further implemented: Obtain an authentication result based on the first authentication response message, the user terminal, and the authentication-related network element of the satellite network, including:

[0166] Initiate a second authentication request to the user terminal based on the first authentication response message and the authentication-related network element of the satellite network; wherein, the second authentication request is used to instruct the user terminal to feedback a second authentication response message to the authentication-related network element based on the second authentication request; the second authentication response message is used to instruct the authentication-related network element to feedback the authentication result to the UDM network element of the satellite network based on the second authentication response message;

[0167] Receive the authentication result feedback by the authentication-related network element.

[0168] In one embodiment, when the computer program is executed by a processor, the following steps are further implemented: The authentication-related network element includes an AUSF network element and a SEAF network element;

[0169] Initiate a second authentication request to the user terminal based on the first authentication response message and the authentication-related network element of the satellite network, including:

[0170] Send the first authentication response message to the AUSF network element; wherein, the first authentication response message is used to instruct the AUSF network element to forward the first authentication response message to the SEAF network element; the first authentication response message is used to instruct the SEAF network element to send a second authentication request to the user terminal based on the first authentication response message.

[0171] In one embodiment, when the computer program is executed by a processor, the following steps are further implemented: The authentication-related network element includes an AUSF network element and a SEAF network element;

[0172] The second authentication request is specifically used to instruct the user terminal to send a second authentication response message to the SEAF network element based on the second authentication request; the second authentication response message is used to instruct the SEAF network element to forward the second authentication response message to the AUSF network element.

[0173] In one embodiment, when the computer program is executed by a processor, the following steps are further implemented: The second authentication response message is specifically used to instruct the AUSF network element to feedback the authentication result to the UDM network element of the satellite network based on the second authentication response message.

[0174] In one embodiment, when the computer program is executed by a processor, the following steps are further implemented: Send the authentication result to the terrestrial network so that the terrestrial network determines whether to allow the user terminal to access the terrestrial network through the satellite network based on the authentication result, including:

[0175] Perform signature processing on the authentication result based on the signature algorithm, and send the signed authentication result to the UDM network element of the terrestrial network, so that the UDM network element of the terrestrial network verifies the signature of the signed authentication result, and determines whether to allow the user terminal to access the terrestrial network through the satellite network based on the signature verification result.

[0176] In one embodiment, a computer program product is provided, including a computer program, which when executed by a processor implements the following steps:

[0177] Receive a first authentication request carrying a hidden identifier initiated by the user terminal; wherein, the hidden identifier is obtained by the user terminal encrypting the user identifier of the user terminal based on an encryption key;

[0178] Generate a first authentication response message based on the hidden identifier;

[0179] Obtain an authentication result based on the first authentication response message, the user terminal, and the authentication-related network element of the satellite network;

[0180] Send the authentication result to the terrestrial network, so that the terrestrial network determines whether to allow the user terminal to access the terrestrial network through the satellite network based on the authentication result.

[0181] In one embodiment, when the computer program is executed by the processor, the following steps are further implemented: generating a first authentication response message based on the hidden identifier, including:

[0182] Perform decryption processing on the hidden identifier to obtain the user identifier;

[0183] Generate an authentication vector based on the user identifier;

[0184] Generate a first authentication response message based on the authentication vector.

[0185] In one embodiment, when the computer program is executed by the processor, the following steps are further implemented: obtaining an authentication result based on the first authentication response message, the user terminal, and the authentication-related network element of the satellite network, including:

[0186] Initiate a second authentication request to the user terminal based on the first authentication response message and the authentication-related network element of the satellite network; wherein, the second authentication request is used to instruct the user terminal to feedback a second authentication response message to the authentication-related network element based on the second authentication request; the second authentication response message is used to instruct the authentication-related network element to feedback the authentication result to the UDM network element of the satellite network based on the second authentication response message;

[0187] Receive the authentication result feedback by the authentication-related network element.

[0188] In one embodiment, when the computer program is executed by a processor, the following steps are further implemented: The authentication-related network elements include an AUSF network element and a SEAF network element;

[0189] Based on the first authentication response message and the authentication-related network elements of the satellite network, initiate a second authentication request to the user terminal, including:

[0190] Send the first authentication response message to the AUSF network element; wherein, the first authentication response message is used to instruct the AUSF network element to forward the first authentication response message to the SEAF network element; the first authentication response message is used to instruct the SEAF network element to send a second authentication request to the user terminal based on the first authentication response message.

[0191] In one embodiment, when the computer program is executed by a processor, the following steps are further implemented: The authentication-related network elements include an AUSF network element and a SEAF network element;

[0192] The second authentication request is specifically used to instruct the user terminal to send a second authentication response message to the SEAF network element based on the second authentication request; the second authentication response message is used to instruct the SEAF network element to forward the second authentication response message to the AUSF network element.

[0193] In one embodiment, when the computer program is executed by a processor, the following steps are further implemented: The second authentication response message is specifically used to instruct the AUSF network element to feedback the authentication result to the UDM network element of the satellite network based on the second authentication response message.

[0194] In one embodiment, when the computer program is executed by a processor, the following steps are further implemented: Send the authentication result to the terrestrial network so that the terrestrial network determines whether to allow the user terminal to access the terrestrial network through the satellite network based on the authentication result, including:

[0195] Perform signature processing on the authentication result based on the signature algorithm and send the signed authentication result to the UDM network element of the terrestrial network, so that the UDM network element of the terrestrial network verifies the signature of the signed authentication result and determines whether to allow the user terminal to access the terrestrial network through the satellite network based on the verification result.

[0196] Those of ordinary skill in the art can understand that all or part of the processes in the methods of the above embodiments can be completed by instructing relevant hardware through a computer program. The computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above methods. Among them, any reference to a memory, database, or other medium used in the embodiments provided in the present application can include at least one of non-volatile and volatile memories. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetoresistive random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory can include random access memory (RAM) or external cache memory, etc. By way of illustration and not limitation, RAM can be in various forms, such as static random access memory (SRAM) or dynamic random access memory (DRAM), etc. The databases involved in the embodiments provided in the present application can include at least one of relational databases and non-relational databases. Non-relational databases can include distributed databases based on blockchain, etc., without limitation. The processors involved in the embodiments provided in the present application can be general-purpose processors, central processing units, graphics processing units, digital signal processors, programmable logic devices, terminal access logics based on quantum computing, etc., without limitation.

[0197] The technical features of the above embodiments can be combined arbitrarily. For the sake of concise description, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, it should be considered as the scope described in this specification.

[0198] The above embodiments only represent several implementation manners of the present application. The description is relatively specific and detailed, but it should not be construed as a limitation on the patent scope of the present application. It should be noted that for those of ordinary skill in the art, without departing from the concept of the present application, several modifications and improvements can still be made, and these all belong to the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the appended claims.

Claims

1. A terminal network access method, characterized in that, The unified data management function UDM network element applied to the satellite network includes: Receiving a first authentication request carrying a hidden identifier initiated by a user terminal; wherein, the hidden identifier is obtained by the user terminal encrypting the user identifier of the user terminal based on an encryption key; Generating a first authentication response message based on the hidden identifier; Obtaining an authentication result based on the first authentication response message, the user terminal, and the authentication related network element of the satellite network; Sending the authentication result to the terrestrial network, so that the terrestrial network determines whether to allow the user terminal to access the terrestrial network through the satellite network based on the authentication result.

2. The method according to claim 1, wherein The generating the first authentication response message based on the hidden identifier includes: Performing decryption processing on the hidden identifier to obtain the user identifier; Generating an authentication vector based on the user identifier; Generating the first authentication response message based on the authentication vector.

3. The method according to claim 2, characterized in that, The obtaining the authentication result based on the first authentication response message, the user terminal, and the authentication related network element of the satellite network includes: Initiating a second authentication request to the user terminal based on the first authentication response message and the authentication related network element of the satellite network; wherein, the second authentication request is used to instruct the user terminal to feedback a second authentication response message to the authentication related network element; the second authentication response message is used to instruct the authentication related network element to feedback the authentication result to the UDM network element of the satellite network based on the second authentication response message; Receiving the authentication result feedback by the authentication related network element.

4. The method according to claim 3, wherein The authentication related network element includes an authentication service function AUSF network element and a security anchor point function SEAF network element; The initiating the second authentication request to the user terminal based on the first authentication response message and the authentication related network element of the satellite network includes: Sending the first authentication response message to the AUSF network element; wherein, the first authentication response message is used to instruct the AUSF network element to forward the first authentication response message to the SEAF network element; the first authentication response message is used to instruct the SEAF network element to send the second authentication request to the user terminal based on the first authentication response message.

5. The method according to claim 3, wherein The authentication related network element includes an AUSF network element and a SEAF network element; The second authentication request is specifically used to instruct the user terminal to send the second authentication response message to the SEAF network element; the second authentication response message is used to instruct the SEAF network element to forward the second authentication response message to the AUSF network element.

6. The method according to claim 5, wherein: The second authentication response message is specifically used to instruct the AUSF network element to feedback the authentication result to the UDM network element of the satellite network based on the second authentication response message.

7. The method according to claim 1, wherein The sending the authentication result to the terrestrial network, so that the terrestrial network determines whether to allow the user terminal to access the terrestrial network through the satellite network based on the authentication result includes: Sign the authentication result based on the signature algorithm, and send the signed authentication result to the UDM network element of the terrestrial network, so that the UDM network element of the terrestrial network verifies the signature of the signed authentication result, and determines whether to allow the user terminal to access the terrestrial network through the satellite network based on the signature verification result.

8. A terminal network access device, characterized in that, Configured in the UDM network element of the satellite network, including: A receiving module, configured to receive a first authentication request carried with a hidden identifier initiated by a user terminal; wherein, the hidden identifier is obtained by the user terminal encrypting the user identifier of the user terminal based on an encryption key; A generating module, configured to generate a first authentication response message based on the hidden identifier; An obtaining module, configured to obtain an authentication result based on the first authentication response message, the user terminal, and the authentication related network element of the satellite network; A sending module, configured to send the authentication result to the terrestrial network, so that the terrestrial network determines whether to allow the user terminal to access the terrestrial network through the satellite network based on the authentication result.

9. A computer device, comprising a memory and a processor, the memory storing a computer program, characterized in that, When the processor executes the computer program, the steps of the method according to any one of claims 1 to 7 are implemented.

10. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 7 are implemented.

11. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 7 are implemented.