Core network IMS joint authentication access method and system
By generating joint authentication tokens on the core network, the authentication process of the core network and IP multimedia subsystem in the 5G network is simplified, signaling redundancy and resource waste problems are solved, network load and delay are reduced, and network stability and resource utilization are improved in high concurrency scenarios.
Patent Information
- Application Number
- CN202510439688.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-09
- Publication Date
- 2025-07-11
AI Technical Summary
In the prior art, the dual authentication of the core network and IP multimedia subsystem in the 5G network leads to signaling redundancy, signaling storm risks and resource waste, especially in high concurrency scenarios, increasing network load and delay.
By generating joint authentication tokens in the core network, it is simplified into a single token verification, cross-system mutual recognition, reduce the number of signaling interactions, and use dynamically generated joint authentication tokens to achieve cross-system mutual recognition, reducing network load and delay.
Significantly reduce network load and delay, improve network resource utilization and response speed, enhance network stability in high concurrency scenarios, simplify key management, and avoid chain leakage risks.
Smart Images

Figure CN120302289A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of communications, and in particular to a core network IMS joint authentication access method. Background Art
[0002] In modern communication networks, user equipment (UE) needs to complete identity authentication through a USIM card to ensure the security of network access. In 5G and the IP Multimedia Subsystem, the authentication process involves the following steps:
[0003] Core network authentication: The UE sends an authentication request to the core network, and the HSS / UDM verifies the user identity and generates a key. The 5G authentication mechanism is based on SUPI (Subscription Permanent Identifier) and SUCI (encrypted SUPI), and realizes user identity protection through public key encryption.
[0004] IMS authentication: The UE needs to send the same authentication request to the IP Multimedia Subsystem again. The IMS obtains the authentication vector through the HSS and completes two-way authentication. The IMS authentication mechanism is based on the AKA (Authentication and Key Agreement) protocol, and completes two-way authentication by sharing a key between the ISIM card and the HSS.
[0005] However, the existing technologies have the following problems:
[0006] 1. Dual authentication leads to signaling redundancy: The IMS and the core network need to process the same authentication request separately, and the HSS / UDM needs to calculate the authentication vector repeatedly, increasing the signaling load.
[0007] 2. Risk of signaling storm: When the number of users surges, the dual authentication process exacerbates network congestion and prolongs the fault recovery time.
[0008] 3. Resource waste: The two authentications consume computing resources and bandwidth, reducing network efficiency.
[0009] Therefore, there is an urgent need for a core network IMS joint authentication access method that can solve the above problems. Summary of the Invention
[0010] The object of the present invention is to provide a core network IMS joint authentication access method and system, which can significantly reduce network load and latency.
[0011] To achieve the above object, the present invention provides a method for core network IMS joint authentication access. The core network receives an initial registration request from a UE, and the initial registration request includes a user permanent identifier and a request identifier for joint authentication; the core network triggers a joint authentication process based on the request identifier for joint authentication: randomly generates a joint authentication token according to the user permanent identifier, synchronously pushes the joint authentication token and user context information to the IP multimedia subsystem, and adds the joint authentication token to the authentication success response and returns it to the UE, so that the UE can successfully access the 5G core network. The user context information includes the user permanent identifier; the IP multimedia subsystem binds the joint authentication token with the user permanent identifier of the UE and marks the UE registration status as pre-authentication completed, so that when the user subsequently initiates a registration to the IP multimedia subsystem, the user identity of the UE can be directly verified based on the joint authentication token for registration.
[0012] Preferably, before randomly generating a joint authentication token according to the user permanent identifier, the core network also generates an authentication vector to obtain a shared key, and derives a service key and an access layer key based on the shared key, and transfers the service key and the access layer key to the AMF network element of the core network for subsequent air interface encryption and communication security protection. This solution enables the service password and the access layer password to be uniformly derived from the shared key by the core network, simplifying the complex process of key management. Moreover, the shared key is uniformly derived by the core network and is independent of the encryption key in the IMS, avoiding the risk of chain leakage.
[0013] Preferably, the core network randomly generates a joint authentication token according to the user permanent identifier and the shared key. The joint authentication token includes a JAT value, a JAT validity period, and an integrity check code, and the JAT validity period is bound to the validity period of the shared key. The present invention binds the life cycles of the shared key and the JAT validity period. Based on the integrity check code of timeliness, the core network synchronously updates the joint authentication token to the IMS, ensuring that the joint authentication token cannot be forged and is valid only once. Moreover, the dynamic JAT mechanism is based on the integrity check code verification of timeliness and key isolation technology, which reduces redundant calculations while effectively resisting replay attacks and man-in-the-middle threats, and the security is significantly improved compared with traditional dual authentication.
[0014] Specifically, the core network randomly generates a joint authentication token according to the user permanent identifier, a time stamp, a random number, and the shared key, further increasing the security of the joint authentication token.
[0015] More specifically, the joint authentication token is obtained by substituting the user permanent identifier, timestamp, random number, and shared key into the HMAC algorithm. The three data items of the timestamp, random number, and shared key are encrypted through a single HMAC algorithm, enabling a single HMAC calculation to replace multiple encryptions and reducing the computational resource consumption by 30%.
[0016] Specifically, after receiving the authentication success response, the UE also monitors the validity period of the JAT. When the joint authentication token is approaching expiration, the UE sends a token update request to the core network. The core network regenerates the joint authentication token based on the token update request and synchronizes the joint authentication token to the IP multimedia subsystem.
[0017] Specifically, when the IP multimedia subsystem receives the SIP registration request carrying the JAT value sent by the UE, it verifies the validity of the joint authentication token corresponding to the JAT value. If the joint authentication token is valid, the registration information of the UE is marked as registered, the IP address and JAT validity period of the UE are recorded, and a request permission response is returned to the UE to enable the UE to successfully access the IP multimedia subsystem. If the validity of the joint authentication token is invalid, a rejection permission response is returned to the UE, and the standard IMS AKA process is executed for SIP registration verification. During the registration of the joint authentication token, the original SIP registration process can be automatically transferred to ensure service continuity.
[0018] More specifically, the user context information further includes the JAT valid value and the IP address of the UE. The IP address of the UE is assigned by the core network. After the joint authentication token is valid, the IP multimedia subsystem also determines whether the user context information corresponding to the JAT value is consistent. If it is consistent, the registration information of the UE is marked as registered, and a request permission response is returned to the UE. If it is inconsistent, the context synchronization mechanism between the core network and the IP multimedia subsystem is triggered to synchronize and update the JATT joint authentication token and user context information from the core network, and the consistency verification of the user context information is performed again.
[0019] Preferably, the user permanent identifier in the initial registration request is the user permanent identifier encrypted by the UE using the public key. After receiving the initial registration request, the core network decrypts the user permanent identifier using the private key and verifies the user's legality. When the UE is legal, the next step is executed to continue the joint authentication process.
[0020] The present invention also provides a core network IMS joint authentication access system, including a core network and an IP multimedia subsystem; the core network includes an interface module for communicating with the UE, an authentication management module, and a communication module for communicating with the IP multimedia subsystem, the interface module receives an initial registration request sent by the UE, and parses the user permanent identifier and the joint authentication request identifier in the initial registration request to trigger the joint authentication procedure; the authentication management module generates a joint authentication token based on the user permanent identifier after triggering the joint authentication procedure, and synchronously pushes the joint authentication token and user context information to the IP multimedia subsystem through the communication module, and returns the joint authentication token to the authentication success response to the UE through the interface module, wherein the user context information includes the user permanent identifier; the IP multimedia subsystem receives the joint authentication token and the user permanent identifier, binds the joint authentication token to the user permanent identifier of the UE, and marks the UE registration status as pre-authentication completed, so that when the user subsequently initiates registration to the IP multimedia subsystem, the user identity of the UE can be directly verified based on the joint authentication token for registration.
[0021] Preferably, the interface module is an AMF network element, the communication module is an NEF network element, and the authentication management module includes an AUSF network element and an UDM network element, the AMF network element sends the user permanent identifier to the AUSF network element and triggers a joint authentication procedure; the AUSF network element requests the UDM network element to decrypt the user permanent identifier; the UDM network element decrypts the user permanent identifier, generates a joint authentication token based on the user permanent identifier, and returns the user permanent identifier and the joint authentication token to the AUSF network element; the UDM network element also synchronously pushes the joint authentication token and user context information to the IP multimedia subsystem through the NEF network element; the AUSF network element adds the joint authentication token to the authentication success response, and sends the authentication success response to the UE through the AMF network element.
[0022] Compared with the traditional IMS, which needs to independently initiate AKA recognition and requires two HSS interactions, the present invention simplifies IMS recognition into a single token verification, and uses dynamically generated joint authentication tokens to achieve cross-system mutual recognition, reducing repeated authentication requests between the core network and IMS (IP Multimedia Subsystem), reducing the number of signaling interactions by more than 50%, significantly reducing network load and latency, improving network resource utilization and response speed, and enhancing network stability in high-concurrency scenarios. Moreover, the core network of the present invention automatically pushes the joint authentication token to the IMS terminal each time it generates it, ensuring that the IMS obtains the latest joint authentication token in real time. BRIEF DESCRIPTION OF THE DRAWINGS
[0023] Figure 1 It is a flow chart of the core network IMS joint authentication access method of the present invention.
[0024] Figure 2 It is the structural diagram of the core network IMS joint authentication access method of the present invention. Specific implementation manner
[0025] To describe in detail the technical content, structural features, achieved objectives and effects of the present invention, the following will be described in detail in conjunction with the implementation manners and with reference to the accompanying drawings.
[0026] Refer to Figure 1 and Figure 2 , the present invention discloses a core network IMS joint authentication access system including a core network and an IP multimedia subsystem (IMS), and this core network IMS joint authentication access system is used to execute the core network IMS joint authentication access method. The core network IMS joint authentication access method includes steps S1 to S8.
[0027] S1, the UE sends an initial registration request (NAS information) to the 5G core network through the gnb (base station), and the initial registration request includes a user permanent identifier and a request identifier for joint authentication. The core network in this embodiment is a 5G core network, and this core network can be used to form a 6G network, so that the core network IMS joint authentication access method and system of the present invention are the core network IMS joint authentication access method and system of the 6G network.
[0028] Among them, the user permanent identifier is an encrypted user permanent identifier. Specifically, the UE uses the public key of the 5G core network to encrypt the user permanent identifier SUPI to generate an encrypted user permanent identifier SUPI, and the encrypted user permanent identifier can also be called an encrypted temporary identifier SUCI. This temporary identifier SUCI follows the 3GPP TS 33.501 specification.
[0029] The UE establishes a connection with the base station through RRC (Radio Resource Control) and sends an initial registration request (NAS message, Non-Access Stratum). The request identifier for joint authentication in the initial registration request is the request type for joint authentication, which is an identifier for joint authentication.
[0030] Among them, the initial registration request further includes the UE's security function type (UE Security Capabilities).
[0031] S2, the 5G core network receives the initial registration request of the UE and generates a joint authentication token (JAT, Jointauthentication token).
[0032] Specifically, the 5G core network receives the initial registration request (NAS information) sent by the base station, parses the initial registration information, obtains the encrypted subscriber permanent identifier (SUCI) and the request identifier for joint authentication therein, and triggers the joint authentication process based on the request identifier for joint authentication: The 5G core network randomly generates a joint authentication token (JAT, Joint authentication token) based on the subscriber permanent identifier, assigns an IE address to the UE, synchronously pushes the joint authentication token and user context information to the IP multimedia subsystem, and adds the joint authentication token and associated parameters to the authentication success response and sends it to the UE, so that the UE can successfully access the 5G core network. The user context information includes the UE's IP address and subscriber permanent identifier, and the associated parameters include the token type.
[0033] Preferably, the 5G core network randomly generates a joint authentication token based on the subscriber permanent identifier, timestamp, random number, and shared key. The user context information and associated parameters further include the JAT validity period, and the JAT validity period is bound to the validity period of the shared key.
[0034] Specifically, the 5G core network includes an AMF network element, an AUSF network element, a SEAF network element, a UDM network element, and a NEF network element. Step S2 specifically includes steps S21 to S26.
[0035] S21. The AMF network element receives the initial registration request of the UE sent by the base station, parses the encrypted subscriber permanent identifier (SUCI) and the request identifier for joint authentication, triggers the joint authentication process based on this, and sends the encrypted subscriber permanent identifier (SUCI) to the AUSF network element.
[0036] S22. The AUSF network element sends a request to decrypt the subscriber permanent identifier (SUCI) to the UDM network element, requesting to decrypt the SUCI to obtain the subscriber permanent identifier SUPI.
[0037] S23. The UDM network element decrypts the subscriber permanent identifier (SUCI) to obtain the decrypted subscriber permanent identifier SUPI, and generates a joint authentication token based on the subscriber permanent identifier SUPI. Specifically, step S23 includes:
[0038] S231. The UDM network element uses the private key to decrypt the encrypted subscriber permanent identifier (SUCI) to obtain the restored subscriber permanent identifier SUPI, and verifies the user's legality (such as subscription status, service permissions) based on the subscriber permanent identifier SUPI. If legal, proceed to the next step; if not legal, reject the current initial registration request and return a rejection request response to the UE.
[0039] S232. The UDM network element generates an authentication vector (RAND, AUTN, XRES*, KAUSF) according to the 5G AKA protocol to generate a shared key, and derives a service key (such as the SEAF key) based on the shared key.
[0040] S233. The UDM network element generates a joint authentication token based on the user permanent identifier SUPI, timestamp (Timestamp), nonce (Nonce), and shared key (such as KAUSF). Subsequently, the UDM network element associates and stores the joint authentication token with the user context information, which includes the JAT validity period (such as 3600 seconds), IP address, service type (such as VoLTE), and QoS policy. The joint authentication token includes the JAT value, JAT validity period, and integrity check code. The JAT validity period is bound to the validity period of the shared password.
[0041] Among them, the user permanent identifier SUPI, timestamp (Timestamp), nonce (Nonce), and shared key (such as KAUSF) are substituted into the SHA256 function in the HMAC algorithm to calculate the JAT value, and then a joint authentication token containing the JAT value, JAT validity period, and integrity check code is obtained.
[0042] Specifically, the specific algorithm for the JAT value is as follows:
[0043] Input: user permanent identifier SUPI, timestamp (Timestamp), nonce (Nonce), shared key (such as KAUSF);
[0044] Calculation: JAT = HMAC-SHA256(SUPI||Timestamp||Nonce, KAUSF);
[0045] Data encapsulation: Associate and store the JAT with the user context information (such as IP address, QoS policy).
[0046] The following is the calculation and acquisition process of the joint authentication token:
[0047]
[0048] In summary, the joint authentication token of the present invention includes the JAT value (jat Value), JAT validity period (expiry Time), and integrity check code (hmac or hmac parameter).
[0049] S234. The UDM network element returns the decrypted user permanent identifier SUPI, authentication vector, and joint authentication token to the AUSF network element.
[0050] S235, The UDM network element triggers the NEF network element synchronization: The UDM network element sends a synchronization notification containing the joint authentication token and user context information to the NEF network element through the internal service interface of the 5G core network (such as the Nudm_DataManagement service).
[0051] S24, The NEF network element verifies the legitimacy of the UDM network element (such as OAuth 2.0 token or mutual TLS certificate), checks the HMAC signature (integrity check code) in the joint authentication token, and confirms that the data has not been tampered with.
[0052] S25, After receiving the user permanent identifier SUPI, authentication vector, and joint authentication token returned by the UDM network element, the AUSF network element returns the authentication vector (5G AKA challenge, RAND / AUTN) and joint authentication token to the AMF network element. At the same time, the AUSF network element passes the shared key (KAUSF) and joint authentication token to the SEAF network element (Security Anchor Function).
[0053] S26, The SEAF network element generates a service key (such as Kseaf) and an access layer key (such as KgNB) based on the shared key (KAUSF) and the joint authentication token, and passes the service key (such as Kseaf) and the access layer key (such as KgNB) to the AMF network element for subsequent air interface encryption and integrity protection. The service key (such as Kseaf) is used for the communication security between the SEAF network element and the AUSF network element within the 5G core network. The access layer key (such as KgNB) is used to protect the communication security between the 5G core network, the base station, and the UE.
[0054] S3, The NEF network element synchronously pushes the joint authentication token and user context information to the HSS network element of the IP Multimedia Subsystem. The user context information includes the UE's IP address and user permanent identifier, and the associated parameter includes the token type.
[0055] Among them, the NEF network element pushes a synchronization authentication request (POST / sync-jat request) to the HSS network element of the IP Multimedia Subsystem through the Nnef_DataSync service, and the message body is the joint authentication token and user context information in JSON or Protobuf format.
[0056] S4, The HSS network element of the IP Multimedia Subsystem stores the joint authentication token, binds the joint authentication token to the user permanent identifier of the UE (which can also be the IP Multimedia Private Identity, IMPI), records the user context information, and marks the registration status of the UE as pre-authentication completed, so as to skip the AKA authentication process when the user subsequently initiates registration to the IP Multimedia Subsystem.
[0057] Among them, the IP multimedia subsystem includes P-CSCF network elements, I-CSCF network elements, S-CSCF network elements, and HSS network elements.
[0058] S5. The AUSF network element sends the joint authentication token and associated parameters to the UE in the authentication success response through the AMF network element, so that the UE can successfully access the 5G core network.
[0059] Among them, the AUSF network element takes the joint authentication token as part of the authentication success response, adds a new "JAT-ontainer" field in the authentication success response (5G NAS (Non-Access Stratum) message), which contains the JAT value and associated parameters (such as JAT validity period, token type), and sends it to the UE through the AMF network element. Thus, the UE successfully accesses the 5G core network.
[0060] S6. After receiving the authentication success response, the UE extracts the joint authentication token and associated parameters, stores the joint authentication token, and binds the joint authentication token to the IMS service identifier.
[0061] Specifically, after receiving the authentication success response, the security module (USIM or terminal TEE) of the UE extracts the JAT value and JAT validity period in the authentication success response, and uses the derived key derived from the shared key to verify the legality of the HMAC in the joint authentication token (uses the KAUSF derived key to verify the HMAC parameter in the joint authentication token). If the verification is successful, the UE stores the joint authentication token in the secure storage area (such as the USIM card or the terminal security chip), and binds it to the IMS service identifier (such as IMPI).
[0062] If the verification of the joint authentication token fails (such as the HMAC verification fails), the UE triggers a fallback process, and the UE reinitiates an independent IMS authentication request (traditional registration authentication process): the UE sends authentication requests to the 5G core network and the IP multimedia subsystem respectively. The UDM network element of the 5G core network verifies the user identity and generates a key, and verifies the UE's identity based on the key. The UE sends the same authentication request to the IP multimedia subsystem again. The IP multimedia subsystem obtains the authentication vector through the HSS network element and completes mutual authentication. Based on the AKA (Authentication and Key Agreement) protocol, mutual authentication is completed by sharing the key between the ISIM card and the HSS.
[0063] After receiving the successful authentication response, the UE sends a token update request to the 5G core network based on the monitored JAT validity period when the joint authentication token is about to expire; the 5G core network regenerates the joint authentication token based on the token update request, and synchronizes the joint authentication token to the IP multimedia subsystem, so that the IP multimedia subsystem stores the updated joint authentication token and binds the updated joint authentication token to the UE's user permanent identifier.
[0064] There is no specific order between step S3 and step S5, and they can be performed simultaneously or one after the other.
[0065] S7: When IMS service is needed, the UE initiates a SIP registration request to the IMS network element carrying the JAT value.
[0066] Specifically, the UE adds a custom field JAT value in a SIP registration request, and sends the SIP registration request carrying the JAT value to a P-CSCF network element (proxy CSCF) of the IP multimedia subsystem.
[0067] S8, after receiving the SIP registration request, the P-CSCF network element of the IP multimedia subsystem forwards the SIP registration request to the I-CSCF network element, and then forwards it to the S-CSCF network element. The S-CSCF network element sends a MAR (Multimedia-Auth-Request) message to the HSS network element, and carries the JAT value. The HSS network element obtains the stored joint authentication token based on the JAT value, verifies the validity of the corresponding joint authentication token (whether the timestamp is expired or whether the hash value matches). If the verification is successful, the UE's user registration information is updated through the S-CSCF network element, and the UE's registration information is marked as registered, and the UE's IP address and JAT validity period are recorded, and the request permission response is returned to the UE in the original path, so that the UE can successfully access the IP multimedia subsystem. The request permission response is a MAA (Multimedia-Auth-Answer) message. Among them, the SIP registration request also carries the UE's user permanent identifier.
[0068] If the validity verification of the joint authentication token fails, the HSS network element returns a rejection response to the UE and executes a standard IMS AKA process to perform SIP registration verification.
[0069] Specifically, the HSS network element of the IP multimedia subsystem also obtains the user context information corresponding to the associated authentication token where it is located based on the JAT value. After verifying the validity of the associated authentication token, it also verifies whether the user context information corresponding to the associated authentication token is consistent (including whether it is within the JAT validity period, whether the IP addresses are the same, etc.). If so, it returns the determination result to the S-CSCF network element along the original path, updates the user registration information of the UE in the S-CSCF network element, marks the registration information of the UE as registered, records the IP address and JAT validity period of the UE, and returns a request permission response to the UE along the original path, so that the UE can successfully access the IP multimedia subsystem. If the HSS network element determines that the user context information is inconsistent, it triggers the context synchronization mechanism between the 5G core network and the IP multimedia subsystem, synchronizes and updates the associated authentication token and user context information stored therein from the 5G core network through the subscription / notification function of the NEF network, and then verifies again whether the user context information corresponding to the associated authentication token is consistent. If it is inconsistent for a preset number of times, it returns a rejection permission response to the UE along the original path and executes the standard IMS AKA process for SIP registration verification. Among them, the SIP registration request is sent from the user's IP address and can be recognized and obtained by the IP multimedia subsystem.
[0070] Among them, in the present invention, in the 5G core network, the UDM network element and the NEF network element communicate and interact based on the 3GPP SBI (service-based interface) using the HTTP / 2 protocol. Between the 5G core network and the IP multimedia subsystem: between the NEF network element and the HSS network element, they communicate and interact using the extended Nnef interface (3GPP TS29.503) and support the JAT_Update operation type. Therefore, the HSS network element of the IP multimedia subsystem of the present invention supports both the associated authentication token and the traditional authentication vector storage, allows both registration modes and registration processes at the same time, can support the coexistence of new and old systems, and allows the operator to upgrade the network in phases.
[0071] UE (User Equipment): User equipment, such as devices that access the communication network, like smartphones and Internet of Things terminals. USIM (Universal Subscriber Identity Module): Universal Subscriber Identity Module, which stores user identity information and keys and is used for network authentication and secure communication. IMS (IP Multimedia Subsystem): IP Multimedia Subsystem, the core network architecture that supports multimedia services such as voice and video. 5G Core Network: 5G Core Network, which provides efficient data transmission and network slicing functions. HSS / UDM (Home Subscriber Server / Unified Data Management): Home Subscriber Server / Unified Data Management, which stores user subscription data and processes authentication requests. gNB (Next Generation Node B): 5G base station, responsible for wireless access between the UE and the 5G core network and handling physical layer and RRC layer signaling. AMF (Access and Mobility Management Function): Access and Mobility Management Function, responsible for UE access control, mobility management (such as handover), registration, and connection status management. AUSF (Authentication Server Function): Authentication Server Function, which processes user authentication requests and interacts with the UDM / HSS to complete the generation of authentication vectors. UDM (Unified Data Management) / HSS (Home Subscriber Server): Stores user subscription data (such as SUPI, service permissions) and generates authentication vectors (such as 5G AKA parameters). SEAF (Security Anchor Function): Security Anchor Function, which manages the security context between the UE and the 5G core network and derives access layer keys (such as KgNB). NEF (Network Exposure Function): Network Exposure Function, which provides network capability open interfaces and allows external systems (such as IMS) to access 5G core network data. SMF (Session Management Function): Session Management Function, which manages the establishment, modification, and release of user sessions and allocates IP addresses. P-CSCF (Proxy-Call Session Control Function): Proxy-Call Session Control Function, the entry node of the IMS network, responsible for receiving SIP requests from the UE and forwarding them to the I-CSCF / S-CSCF.I-CSCF (Interrogating-CSCF): Interrogating Session Control Function, which queries the HSS according to the user identifier (such as IMPI) to determine the S-CSCF to which the user belongs. S-CSCF (Serving-CSCF): Serving Session Control Function, a core network element of IMS, which performs user authentication, session control, and service triggering. Signaling Storm: Network congestion or paralysis caused by signaling requests exceeding the network processing capacity.
[0072] The above-disclosed are only the preferred embodiments of the present invention. Of course, the scope of rights of the present invention cannot be limited thereby. Therefore, equivalent changes made according to the scope of the patent application of the present invention still fall within the scope covered by the present invention.
Claims
1. A core network IMS joint authentication and access method, characterized in that: Including: The core network receives an initial registration request from the UE, and the initial registration request includes a user permanent identifier and a request identifier for joint authentication; The core network triggers a joint authentication process based on the request identifier for joint authentication: randomly generates a joint authentication token according to the user permanent identifier, synchronously pushes the joint authentication token and user context information to the IP multimedia subsystem, and adds the joint authentication token to the authentication success response and returns it to the UE, so that the UE can successfully access the 5G core network, and the user context information includes the user permanent identifier; The IP multimedia subsystem receives the joint authentication token and the user permanent identifier, binds the joint authentication token to the user permanent identifier of the UE, and marks the UE registration status as pre-authentication completed, so that when the user subsequently initiates registration to the IP multimedia subsystem, the user identity of the UE can be directly verified based on the joint authentication token for registration.
2. The core network IMS joint authentication access method according to claim 1, wherein: Before randomly generating a joint authentication token according to the user permanent identifier, the core network also generates an authentication vector to obtain a shared key, and derives a service key and an access layer key according to the shared key, and transfers the service key and the access layer key to the AMF network element of the core network.
3. The core network IMS joint authentication access method according to claim 1, characterized in that: The core network randomly generates a joint authentication token according to the user permanent identifier and the shared key, and the joint authentication token includes a JAT value, a JAT validity period, and an integrity check code, and the JAT validity period is bound to the validity period of the shared key.
4. The core network IMS joint authentication access method according to claim 3, wherein: The core network randomly generates a joint authentication token according to the user permanent identifier, a time stamp, a random number, and the shared key.
5. The core network IMS joint authentication access method according to claim 4, characterized in that: The joint authentication token is obtained by substituting the user permanent identifier, the time stamp, the random number, and the shared key into the HMAC algorithm.
6. The core network IMS joint authentication access method according to claim 3, characterized in that: After receiving the authentication success response, the UE also monitors the JAT validity period, and when the joint authentication token is approaching expiration, sends a token update request to the core network; The core network regenerates a joint authentication token according to the token update request, and synchronizes the joint authentication token to the IP multimedia subsystem.
7. The core network IMS joint authentication access method according to claim 3, characterized in that: When receiving a SIP registration request carrying a JAT value sent by the UE, the IP multimedia subsystem verifies the validity of the joint authentication token corresponding to the JAT value. If the joint authentication token is valid, it marks the registration information of the UE as registered and returns a request permission response to the UE, so that the UE can successfully access the IP multimedia subsystem; If the joint authentication token is invalid, it returns a rejection permission response to the UE and executes the standard IMS AKA process for SIP registration verification.
8. The core network IMS joint authentication access method according to claim 7, characterized in that: The user context information further includes a JAT valid value and the IP address of the UE, which is assigned by the core network. After the joint authentication token is valid, the IP multimedia subsystem further determines whether the user context information corresponding to the JAT value is consistent. If it is consistent, the registration information of the UE is marked as registered, and a request permission response is returned to the UE; if it is inconsistent, the context synchronization mechanism of the core network and the IP multimedia subsystem is triggered to synchronize and update the JATT joint authentication token and user context information from the core network, and the consistency verification of the user context information is performed again.
9. The core network IMS joint authentication access method according to claim 1, characterized in that: The user permanent identifier in the initial registration request is the user permanent identifier encrypted by the UE using the public key; after receiving the initial registration request, the core network decrypts the user permanent identifier using the private key and verifies the user's legality. When the UE is legal, the next step is executed to continue the joint authentication process.
10. A core network IMS joint authentication and access system, characterized in that: It includes a core network and an IP multimedia subsystem; the core network includes an interface module for communicating with the UE, an authentication management module, and a communication module for communicating with the IP multimedia subsystem. The interface module receives the initial registration request sent by the UE, parses the user permanent identifier and the request identifier for joint authentication in the initial registration request to trigger the joint authentication process; After triggering the joint authentication process, the authentication management module generates a joint authentication token according to the user permanent identifier, synchronously pushes the joint authentication token and user context information to the IP multimedia subsystem through the communication module, and adds the joint authentication token to the authentication success response through the interface module and returns it to the UE. The user context information includes the user permanent identifier; The IP multimedia subsystem receives the joint authentication token and the user permanent identifier, binds the joint authentication token to the user permanent identifier of the UE, and marks the UE registration status as pre-authentication completed, so that when the user subsequently initiates a registration to the IP multimedia subsystem, the user identity of the UE can be directly verified based on the joint authentication token for registration.