Authentication method and device and storage medium
Through the blockchain network distributed storage authentication and authentication vector, the security and performance bottleneck problems of the 5G AKA authentication and authentication mechanism when large-scale terminals are connected to the network are solved, and cross-domain authentication and stable acquisition of authentication and authentication vectors are realized. It is suitable for terminal devices and network devices of 5G and 6G systems.
Patent Information
- Application Number
- CN202410083775.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-01-19
- Publication Date
- 2025-07-22
AI Technical Summary
The existing 5G AKA authentication and authentication mechanism faces insufficient security, performance bottlenecks and throughput problems when large-scale terminals access the network, and cannot meet the concurrent access requests of massive devices in the Internet of Things scenarios, and the signaling interaction between heterogeneous networks is inefficient, which may cause terminals to fail to authenticate and authenticate.
The blockchain network distributed storage authentication and authentication vector is adopted, and the authentication and authentication vector associated with the terminal identification is queried in the blockchain network through a proxy server, and sent it to the mobility management function AMF entity for two-way authentication and authentication, realizing cross-domain authentication and authentication, avoiding single point of failure and network congestion.
It ensures stable acquisition of authentication and authentication vectors, shortens the authentication process, avoids network congestion and single point of failure, realizes cross-domain authentication and authentication, and meets the concurrent access requests of massive terminal devices.
Smart Images

Figure CN120358492A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of communication technologies, and in particular, to an authentication and authorization method, apparatus, and storage medium. Background Art
[0002] The 6G network composed of heterogeneous distributed networks aims to achieve global coverage and will connect a large number of Internet of Things (IoT) terminal devices. Mobile IoT terminal devices may need to obtain services from different networks during movement, and it is necessary to consider implementing authentication and authorization for terminals between different service networks.
[0003] Existing authentication and authorization mechanisms between service networks and terminals, such as 5G AKA (5G Authentication and Key Agreement), have many deficiencies in authentication and authorization when facing large-scale terminal access to the network. For example, in terms of security, the home network (HN) consists of a single node, resulting in insufficient fault tolerance of the system. Once the home network server fails or is attacked, such as a distributed denial-of-service attack, etc., it will be unable to connect to the service network and will be unable to provide secure authentication and authorization services; in terms of throughput and latency, a single home network server has performance bottlenecks and cannot meet the concurrent access requests of a large number of devices in the IoT scenario. Summary of the Invention
[0004] This application provides an authentication and authorization method, apparatus, and storage medium to improve the stability of obtaining authentication and authorization vectors and ensure mutual authentication and authorization between the terminal and the service network.
[0005] In a first aspect, this application provides an authentication and authorization method applied to a proxy server. The proxy server is a node in a blockchain network, and authentication and authorization vectors are stored in the blockchain network. The method includes:
[0006] Receiving an authentication and authorization request sent by an Access and Mobility Management Function (AMF) entity, where the authentication and authorization request includes a terminal identifier;
[0007] Querying, in the blockchain network, the authentication and authorization vectors associated with the terminal identifier. If one or more groups of authentication and authorization vectors associated with the terminal identifier are queried, obtaining a group of authentication and authorization vectors associated with the terminal identifier;
[0008] Sending the obtained authentication and authorization vectors to the AMF entity for mutual authentication and authorization between the AMF entity and the terminal.
[0009] Optionally, the authentication and authorization request further includes a service network identifier where the AMF entity is located; the querying for the authentication and authorization vectors associated with the terminal identifier in the blockchain network includes:
[0010] If it is determined according to the service network identifier that the corresponding service network has signed a roaming agreement, or it is determined that the AMF entity has the permission to use the authentication and authorization vectors associated with the terminal identifier in the blockchain network, then query for the authentication and authorization vectors associated with the terminal identifier in the blockchain network.
[0011] Optionally, when querying for the authentication and authorization vectors associated with the terminal identifier in the blockchain network, if one or more groups of authentication and authorization vectors associated with the terminal identifier are queried, obtaining one group of authentication and authorization vectors associated with the terminal identifier includes:
[0012] Query for the authentication and authorization vectors associated with the terminal identifier in the blockchain network through a preset smart contract. If one or more groups of authentication and authorization vectors associated with the terminal identifier are queried, then obtain one group of authentication and authorization vectors associated with the terminal identifier.
[0013] Optionally, after obtaining one group of authentication and authorization vectors associated with the terminal identifier, it further includes:
[0014] Mark the obtained authentication and authorization vectors as unavailable in the blockchain network.
[0015] Optionally, the method further includes:
[0016] After the initial mutual authentication and authorization between the terminal and the initial service network is completed, receive one or more groups of authentication and authorization vectors associated with the terminal identifier sent by the AMF entity; wherein, the one or more groups of authentication and authorization vectors associated with the terminal identifier are the remaining authentication and authorization vectors after removing the group of authentication and authorization vectors used during the initial mutual authentication and authorization from the multiple groups of authentication and authorization vectors generated by the unified data management UDM entity for the terminal;
[0017] Save the one or more groups of authentication and authorization vectors associated with the terminal identifier to the blockchain network.
[0018] Optionally, the method further includes:
[0019] If it is queried that all the authentication and authorization vectors associated with the terminal identifier have exceeded the preset time limit, or are all marked as unavailable, then send an authentication and authorization vector acquisition request to the AMF entity, so that the AMF entity requests new authentication and authorization vectors associated with the terminal identifier from the UDM entity;
[0020] Receive the new authentication and authorization vector associated with the terminal identifier sent by the AMF entity and save it in the blockchain network.
[0021] In a second aspect, the present application provides an authentication and authorization method applied to an AMF entity. The method includes:
[0022] Receive an authentication and authorization request sent by a terminal, where the authentication and authorization request includes a terminal identifier;
[0023] Forward the authentication and authorization request to a proxy server, where the proxy server is a node in the blockchain network, and a set or multiple sets of authentication and authorization vectors associated with the terminal identifier are stored in the blockchain network;
[0024] Receive a set of authentication and authorization vectors associated with the terminal identifier queried by the proxy server from the blockchain network;
[0025] Perform two-way authentication and authorization with the terminal according to the received authentication and authorization vectors.
[0026] Optionally, the forwarding of the authentication and authorization request to the proxy server includes:
[0027] Add the service network identifier where the AMF entity is located to the authentication and authorization request, and send the authentication and authorization request with the added service network identifier to the proxy server. The service network identifier is used to determine whether the corresponding service network has signed a roaming agreement or to determine whether the AMF entity has the permission to use the authentication and authorization vectors associated with the terminal identifier in the blockchain network.
[0028] Optionally, the performing two-way authentication and authorization with the terminal according to the received authentication and authorization vectors includes:
[0029] Send the random number and authentication token in the authentication and authorization vector to the terminal and receive the actual response generated by the terminal according to the random number and the authentication token;
[0030] Obtain the digest value of the actual response according to the actual response;
[0031] Compare the digest value of the actual response with the digest value of the expected response in the authentication and authorization vector. If they are the same, it is determined that the two-way authentication and authorization is successful.
[0032] Optionally, the method further includes:
[0033] After the authentication service function AUSF entity completes the initial two-way authentication and authorization for the terminal and the initial service network, it receives one or more sets of authentication and authorization vectors associated with the terminal identifier sent by the AUSF entity; wherein, the one or more sets of authentication and authorization vectors associated with the terminal identifier are the remaining authentication and authorization vectors after removing one set of authentication and authorization vectors used in the initial two-way authentication and authorization from multiple sets of authentication and authorization vectors generated by the UDM entity for the terminal.
[0034] Send one or more sets of authentication and authorization vectors associated with the terminal identifier to the proxy server, so that the proxy server saves them in the blockchain network.
[0035] Optionally, the method further includes:
[0036] Receive an authentication and authorization vector acquisition request sent by the proxy server after querying that all the authentication and authorization vectors associated with the terminal identifier have exceeded the preset time limit or are all marked as unavailable;
[0037] Request new authentication and authorization vectors associated with the terminal identifier from the UDM entity according to the authentication and authorization vector acquisition request;
[0038] Receive the new authentication and authorization vectors associated with the terminal identifier sent by the UDM entity and send them to the proxy server, so that the proxy server saves them in the blockchain network.
[0039] In a third aspect, the present application provides an authentication and authorization device, including:
[0040] A receiving unit, configured to receive an authentication and authorization request sent by an access and mobility management function AMF entity, where the authentication and authorization request includes a terminal identifier;
[0041] A processing unit, configured to query the authentication and authorization vectors associated with the terminal identifier in the blockchain network. If one or more sets of authentication and authorization vectors associated with the terminal identifier are queried, obtain one set of authentication and authorization vectors associated with the terminal identifier;
[0042] A sending unit, configured to send the obtained authentication and authorization vectors to the AMF entity for the AMF entity to perform two-way authentication and authorization with the terminal.
[0043] Optionally, the authentication and authorization request further includes a service network identifier where the AMF entity is located; when the processing unit queries the authentication and authorization vectors associated with the terminal identifier in the blockchain network, it is configured to:
[0044] If it is determined that the corresponding service network has signed a roaming agreement according to the service network identifier, or it is determined that the AMF entity has the permission to use the authentication and authorization vector associated with the terminal identifier in the blockchain network, then query the authentication and authorization vector associated with the terminal identifier in the blockchain network.
[0045] Optionally, when the processing unit queries the authentication and authorization vector associated with the terminal identifier in the blockchain network, if one or more groups of authentication and authorization vectors associated with the terminal identifier are queried, when obtaining a group of authentication and authorization vectors associated with the terminal identifier, it is used for:
[0046] Query the authentication and authorization vector associated with the terminal identifier in the blockchain network through a preset smart contract. If one or more groups of authentication and authorization vectors associated with the terminal identifier are queried, then obtain a group of authentication and authorization vectors associated with the terminal identifier.
[0047] Optionally, after the processing unit obtains a group of authentication and authorization vectors associated with the terminal identifier, it is further used for:
[0048] Mark the obtained authentication and authorization vector as unavailable in the blockchain network.
[0049] Optionally, the receiving unit is further used for, after the initial two-way authentication and authorization between the terminal and the initial service network is completed, receiving one or more groups of authentication and authorization vectors associated with the terminal identifier sent by the AMF entity; wherein, the one or more groups of authentication and authorization vectors associated with the terminal identifier are the remaining authentication and authorization vectors after removing the group of authentication and authorization vectors used in the initial two-way authentication and authorization from the multiple groups of authentication and authorization vectors generated by the unified data management UDM entity for the terminal;
[0050] The processing unit is further used for saving the one or more groups of authentication and authorization vectors associated with the terminal identifier to the blockchain network.
[0051] Optionally, the processing unit is further used for, if it is queried that all the authentication and authorization vectors associated with the terminal identifier have exceeded the preset time limit, or are all marked as unavailable, then sending an authentication and authorization vector acquisition request to the AMF entity through the sending unit, so that the AMF entity requests a new authentication and authorization vector associated with the terminal identifier from the UDM entity;
[0052] The receiving unit is further used for receiving the new authentication and authorization vector associated with the terminal identifier sent by the AMF entity and saving it to the blockchain network through the processing unit.
[0053] In a fourth aspect, the present application provides an authentication and authorization device, including:
[0054] A receiving unit, configured to receive an authentication and authorization request sent by a terminal, where the authentication and authorization request includes a terminal identifier;
[0055] A sending unit, configured to forward the authentication and authorization request to a proxy server, where the proxy server is a node in a blockchain network, and a set or multiple sets of authentication and authorization vectors associated with the terminal identifier are stored in the blockchain network;
[0056] The receiving unit is further configured to receive a set of authentication and authorization vectors associated with the terminal identifier, which are queried by the proxy server from the blockchain network;
[0057] An authentication and authorization unit, configured to perform two-way authentication and authorization with the terminal according to the received authentication and authorization vectors.
[0058] Optionally, when forwarding the authentication and authorization request to the proxy server, the sending unit is configured to:
[0059] Add the service network identifier where the AMF entity is located to the authentication and authorization request, and send the authentication and authorization request with the added service network identifier to the proxy server. The service network identifier is used to determine whether the corresponding service network has signed a roaming agreement or to determine whether the AMF entity has the permission to use the authentication and authorization vectors associated with the terminal identifier in the blockchain network.
[0060] Optionally, when performing two-way authentication and authorization with the terminal according to the received authentication and authorization vectors, the authentication and authorization unit is configured to:
[0061] Send the random number and the authentication token in the authentication and authorization vector to the terminal through the sending unit, and receive the actual response generated by the terminal according to the random number and the authentication token through the receiving unit;
[0062] Obtain the digest value of the actual response;
[0063] Compare the digest value of the actual response with the digest value of the expected response in the authentication and authorization vector. If they are consistent, it is determined that the two-way authentication and authorization is successful.
[0064] Optionally, the receiving unit is further configured to, after an authentication service function AUSF entity completes the initial two-way authentication and authorization for the terminal and the initial service network, receive a set or multiple sets of authentication and authorization vectors associated with the terminal identifier sent by the AUSF entity; where the set or multiple sets of authentication and authorization vectors associated with the terminal identifier are the remaining authentication and authorization vectors after removing a set of authentication and authorization vectors used in the initial two-way authentication and authorization from multiple sets of authentication and authorization vectors generated by a UDM entity for the terminal;
[0065] The sending unit is further configured to send one or more sets of authentication and authorization vectors associated with the terminal identifier to the proxy server, so that the proxy server saves them in the blockchain network.
[0066] Optionally, the receiving unit is further configured to receive an authentication and authorization vector acquisition request sent by the proxy server after querying that all the authentication and authorization vectors associated with the terminal identifier have exceeded a preset time limit or are all marked as unavailable;
[0067] The sending unit is further configured to request new authentication and authorization vectors associated with the terminal identifier from the UDM entity according to the authentication and authorization vector acquisition request;
[0068] The receiving unit is further configured to receive the new authentication and authorization vectors associated with the terminal identifier sent by the UDM entity and send them to the proxy server, so that the proxy server saves them in the blockchain network.
[0069] In a fifth aspect, the present application provides a proxy server, including a memory, a transceiver, and a processor; the proxy server is a node in the blockchain network, and authentication and authorization vectors are stored in the blockchain network;
[0070] The memory is used to store computer programs; the transceiver is used to send and receive data under the control of the processor; the processor is used to read the computer programs in the memory and perform the following operations:
[0071] Receive an authentication and authorization request sent by an access and mobility management function AMF entity, where the authentication and authorization request includes a terminal identifier;
[0072] Query the authentication and authorization vectors associated with the terminal identifier in the blockchain network. If one or more sets of authentication and authorization vectors associated with the terminal identifier are queried, obtain a set of authentication and authorization vectors associated with the terminal identifier;
[0073] Send the obtained authentication and authorization vectors to the AMF entity for the AMF entity to perform two-way authentication and authorization with the terminal.
[0074] Optionally, the authentication and authorization request further includes a service network identifier where the AMF entity is located; when the processor queries the authentication and authorization vectors associated with the terminal identifier in the blockchain network, it is used to:
[0075] If it is determined according to the service network identifier that the corresponding service network has signed a roaming agreement, or it is determined that the AMF entity has the right to use the authentication and authorization vectors associated with the terminal identifier in the blockchain network, query the authentication and authorization vectors associated with the terminal identifier in the blockchain network.
[0076] Optionally, the processor queries, in the blockchain network, authentication and authorization vectors associated with the terminal identifier. If one or more groups of authentication and authorization vectors associated with the terminal identifier are queried, when obtaining one group of authentication and authorization vectors associated with the terminal identifier, it is used for:
[0077] Query, in the blockchain network, authentication and authorization vectors associated with the terminal identifier through a preset smart contract. If one or more groups of authentication and authorization vectors associated with the terminal identifier are queried, obtain one group of authentication and authorization vectors associated with the terminal identifier.
[0078] Optionally, after the processor obtains one group of authentication and authorization vectors associated with the terminal identifier, it is further used for:
[0079] Mark the obtained authentication and authorization vectors as unavailable in the blockchain network.
[0080] Optionally, the processor is further used for:
[0081] After the terminal and the initial service network complete initial two-way authentication and authorization, receive one or more groups of authentication and authorization vectors associated with the terminal identifier sent by the AMF entity; wherein, one or more groups of authentication and authorization vectors associated with the terminal identifier are the remaining authentication and authorization vectors after removing one group of authentication and authorization vectors used in the initial two-way authentication and authorization from multiple groups of authentication and authorization vectors generated by the unified data management UDM entity for the terminal;
[0082] Save one or more groups of authentication and authorization vectors associated with the terminal identifier to the blockchain network.
[0083] Optionally, the processor is further used for:
[0084] If all the authentication and authorization vectors associated with the terminal identifier that are queried have exceeded a preset time limit or are all marked as unavailable, send an authentication and authorization vector acquisition request to the AMF entity, so that the AMF entity requests new authentication and authorization vectors associated with the terminal identifier from the UDM entity;
[0085] Receive the new authentication and authorization vectors associated with the terminal identifier sent by the AMF entity and save them to the blockchain network.
[0086] In a sixth aspect, the present application provides an AMF entity, including a memory, a transceiver, and a processor;
[0087] The memory is used for storing computer programs; the transceiver is used for transceiving data under the control of the processor; the processor is used for reading the computer programs in the memory and performing the following operations:
[0088] Receive the authentication and authorization request sent by the receiving terminal, where the authentication and authorization request includes a terminal identifier;
[0089] Forward the authentication and authorization request to a proxy server, where the proxy server is a node in the blockchain network, and a group or multiple groups of authentication and authorization vectors associated with the terminal identifier are stored in the blockchain network;
[0090] Receive a group of authentication and authorization vectors associated with the terminal identifier queried by the proxy server from the blockchain network;
[0091] Perform two-way authentication and authorization with the terminal according to the received authentication and authorization vectors.
[0092] Optionally, when the processor forwards the authentication and authorization request to the proxy server, it is used for:
[0093] Add the service network identifier where the AMF entity is located to the authentication and authorization request, and send the authentication and authorization request with the added service network identifier to the proxy server. The service network identifier is used to determine whether the corresponding service network has signed a roaming agreement, or to determine whether the AMF entity has the permission to use the authentication and authorization vectors associated with the terminal identifier in the blockchain network.
[0094] Optionally, when the processor performs two-way authentication and authorization with the terminal according to the received authentication and authorization vectors, it is used for:
[0095] Send the random number and authentication token in the authentication and authorization vector to the terminal, and receive the actual response generated by the terminal according to the random number and the authentication token;
[0096] Obtain the digest value of the actual response according to the actual response;
[0097] Compare the digest value of the actual response with the digest value of the expected response in the authentication and authorization vector. If they are the same, it is determined that the two-way authentication and authorization is successful.
[0098] Optionally, the processor is further used for:
[0099] After the authentication service function AUSF entity completes the initial two-way authentication and authorization for the terminal and the initial service network, receive a group or multiple groups of authentication and authorization vectors associated with the terminal identifier sent by the AUSF entity; among them, the group or multiple groups of authentication and authorization vectors associated with the terminal identifier are the remaining authentication and authorization vectors after removing the group of authentication and authorization vectors used in the initial two-way authentication and authorization from the multiple groups of authentication and authorization vectors generated by the UDM entity for the terminal;
[0100] Send one or more sets of authentication and authorization vectors associated with the terminal identifier to the proxy server, so that the proxy server saves them in the blockchain network.
[0101] Optionally, the processor is further configured to:
[0102] Receive an authentication and authorization vector acquisition request sent by the proxy server after querying that all the authentication and authorization vectors associated with the terminal identifier have exceeded a preset time limit or are all marked as unavailable;
[0103] Request new authentication and authorization vectors associated with the terminal identifier from the UDM entity according to the authentication and authorization vector acquisition request;
[0104] Receive the new authentication and authorization vectors associated with the terminal identifier sent by the UDM entity and send them to the proxy server, so that the proxy server saves them in the blockchain network.
[0105] In a seventh aspect, the present application provides a non-transitory readable storage medium storing a computer program for causing a processor to execute the method described in the first aspect or the second aspect.
[0106] In the authentication and authorization method, device and storage medium of the present application, when two-way authentication and authorization between a terminal and a service network is required, the terminal sends an authentication and authorization request to a mobility management function AMF entity, and the AMF entity forwards it to a proxy server. The authentication and authorization request includes a terminal identifier. The proxy server is a node in the blockchain network, and the blockchain network stores authentication and authorization vectors. The proxy server queries the authentication and authorization vectors associated with the terminal identifier in the blockchain network. If one or more sets of authentication and authorization vectors associated with the terminal identifier are queried, one set of authentication and authorization vectors associated with the terminal identifier is obtained; the obtained authentication and authorization vectors are sent to the AMF entity for two-way authentication and authorization between the AMF entity and the terminal. This embodiment uses the blockchain network to distributively store authentication and authorization vectors, which can ensure stable acquisition of authentication and authorization vectors, shorten the authentication and authorization process, avoid network congestion caused by a large number of terminals requesting authentication and authorization vectors from the home network at the same time, and avoid the occurrence of single-point failure problems or the situation where authentication and authorization vectors cannot be obtained due to the inability to connect to the home network server. In addition, cross-domain authentication and authorization can also be achieved.
[0107] It should be understood that the content described in the above-mentioned invention content part is not intended to limit the key or important features of the embodiments of the present invention, nor is it used to limit the scope of the present invention. Other features of the present invention will become easily understood through the following description. BRIEF DESCRIPTION OF THE DRAWINGS
[0108] To more clearly illustrate the technical solutions in the present application or the prior art, the following will briefly introduce the accompanying drawings required for the description of the embodiments or the prior art. Obviously, the accompanying drawings in the following description are some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other accompanying drawings can also be obtained based on these drawings.
[0109] Figure 1 It is the system architecture diagram of the authentication and authorization method provided by an embodiment of the present application;
[0110] Figure 2 It is the flowchart of the authentication and authorization method provided by an embodiment of the present application;
[0111] Figure 3 It is the flowchart of the authentication and authorization method provided by another embodiment of the present application;
[0112] Figure 4 It is the signaling diagram of the authentication and authorization method provided by an embodiment of the present application;
[0113] Figure 5 It is the signaling diagram of the authentication and authorization method provided by another embodiment of the present application;
[0114] Figure 6 It is the structure diagram of the proxy server provided by an embodiment of the present application;
[0115] Figure 7 It is the structure diagram of the AMF entity provided by an embodiment of the present application;
[0116] Figure 8 It is the structure diagram of the authentication and authorization device provided by an embodiment of the present application;
[0117] Figure 9 It is the structure diagram of the authentication and authorization device provided by another embodiment of the present application. Detailed implementation manners
[0118] In the embodiments of the present invention, the term "and / or" describes the association relationship of associated objects, indicating that there can be three relationships. For example, A and / or B can represent: A exists alone, A and B exist simultaneously, and B exists alone. The character " / " generally represents an "or" relationship between the associated objects before and after.
[0119] In the embodiments of the present application, the term "a plurality of" means two or more, and other quantifiers are similar.
[0120] The existing authentication and authorization mechanism between the service network and the terminal, such as 5G AKA (5G Authentication and Key Agreement). The authentication and authorization process of 5G AKA involves entities such as AUSF (Authentication Server Function), UDM (Unified Data Management), ARPF (Authentication credential Repository and Processing Function), AMF (Access and Mobility Management Function), SEAF (Security Anchor Function), etc. Among them, AUSF and UDM / ARPF belong to the home network, and AMF / SEAF belong to the service network (access network, core network);
[0121] When the terminal needs authentication and authorization, the terminal applies to the home network for an authentication and authorization vector through the service network, and realizes mutual authentication and authorization through the authentication and authorization vector. In the 5G AKA protocol, the AUSF entity applies to the UDM entity for an authentication and authorization vector. After receiving the authentication and authorization vector, the AUSF entity returns it to the AMF / SEAF entity. The AMF / SEAF entity returns the authentication and authorization vector to the terminal. The terminal uses the authentication and authorization vector to authenticate the service network and then sends RES* back to the service network. The service network uses RES* to authenticate the terminal. In the current 5G AKA process, the service network and the terminal need to perform multiple real-time interactions to complete the relevant security process.
[0122] There are many deficiencies in the authentication and authorization of 5G AKA when facing a large number of terminals accessing the network. For example, in terms of security, the home network (HN) consists of a single node, resulting in insufficient fault tolerance of the system. Once the home network server fails or is attacked, such as a distributed denial of service attack, etc., it will be unable to connect to the service network and will be unable to provide secure authentication and authorization services; in terms of throughput and latency, a single home network server has a performance bottleneck and cannot meet the concurrent access requests of a large number of devices in the Internet of Things scenario.
[0123] At the same time, for the 6G network, the number and types of 6G heterogeneous networks increase. If the spatial distance between heterogeneous networks is long, the efficiency of real-time signaling interaction using 5G AKA will be relatively slow. Even when two service networks cannot communicate, it may cause the terminal to be unable to perform authentication and authorization.
[0124] To solve the above technical problems, the embodiments of the present application provide an authentication and authorization method. Considering that the blockchain network has the characteristics of being distributed, immutable, and traceable, and using the storage characteristics of the distributed ledger of the blockchain network, the authentication and authorization vectors required in the authentication and authorization process can be uploaded and stored distributively in advance, avoiding the situation where the service network and the home network cannot be connected, avoiding single-point failure problems, meeting the concurrent access requests of a large number of terminal devices, and also realizing cross-domain authentication and authorization, without being affected by the network space distance. Even when the two service networks cannot be directly connected, the cross-domain authentication and authorization of the terminal can still be realized.
[0125] Specifically, for the authentication and authorization method provided by the embodiments of the present application, the authentication and authorization vectors can be uploaded to the blockchain network through a proxy server in advance, where the proxy server is a node in the blockchain network, and the blockchain network is used to store the authentication and authorization vectors; when two-way authentication and authorization between the terminal and the service network is required, the Mobility Management Function (AMF) entity sends an authentication and authorization request to the proxy server, and the authentication and authorization request includes the terminal identifier; the proxy server queries the authentication and authorization vectors associated with the terminal identifier in the blockchain network. If one or more groups of authentication and authorization vectors associated with the terminal identifier are found, a group of authentication and authorization vectors associated with the terminal identifier is obtained; the obtained authentication and authorization vectors are sent to the AMF entity for two-way authentication and authorization between the AMF entity and the terminal. The embodiments of the present application use the blockchain network to store the authentication and authorization vectors distributively, which can ensure the stable acquisition of the authentication and authorization vectors, shorten the authentication and authorization process, avoid network congestion caused by a large number of terminals requesting authentication and authorization vectors from the home network at the same time, and also avoid the situation where the authentication and authorization vectors cannot be obtained due to single-point failure problems or the inability to connect to the home network server. In addition, cross-domain authentication and authorization can also be realized.
[0126] The authentication and authorization method provided by the present application is applicable to, for example Figure 1In the system architecture shown, each AMF entity (or AMF / SEAF entity) of a service network (access network, core network) is connected to a proxy server. The proxy server acts as a node of the blockchain network and is connected to the blockchain network. Assume that the terminal UE is a device registered in core network A. During the initial authentication and authorization (initial registration) process between the UE and core network A, the UDM / ARPF entity generates multiple groups of authentication and authorization vectors for the UE and sends them to the AUSF entity. After processing, the AUSF entity can send the multiple groups of authentication and authorization vectors of the UE to the AMF / SEAF entity, and further upload them to the blockchain network through the proxy server. When the UE moves to core network B, an authentication and authorization process is required. The UE can send an authentication and authorization request to the AMF / SEAF entity, which is then forwarded by the AMF / SEAF entity to the proxy server. The proxy server obtains the authentication and authorization vectors of the UE from the blockchain network and sends them to the AMF / SEAF entity, and then a two-way authentication and authorization process is carried out with the UE.
[0127] The technical solutions provided by the embodiments of the present application can be applicable to multiple systems, especially 5G systems or 6G systems. Specifically, for example, the applicable systems can be Long Term Evolution (LTE) systems, LTE Frequency Division Duplex (FDD) systems, LTE Time Division Duplex (TDD) systems, Long Term Evolution Advanced (LTE-A) systems, Universal Mobile Telecommunication System (UMTS), Worldwide Interoperability for Microwave Access (WiMAX) systems, 5G New Radio (NR) systems and their evolved communication systems, etc. These multiple systems can include terminal devices and network devices. The system can also include a core network part, such as an Evolved Packet System (EPS), 5G System (5GS), etc.
[0128] The terminal device involved in the embodiments of the present application can be a device that provides voice and / or data connectivity to users, such as a handheld device with wireless connection capabilities, or other processing devices connected to a wireless modem, etc. In different systems, the name of the terminal device may also be different. For example, in a 5G system, the terminal device can be called a user equipment (UE). The wireless terminal device can be a USB storage device, other personal computer memory devices, and dongles. It can also communicate with one or more core networks (CNs) via a radio access network (RAN). The wireless terminal device can be a mobile terminal device, such as a mobile phone (or a "cellular" phone) and a computer with a mobile terminal device. For example, it can be a portable, pocket-sized, handheld, computer-integrated, or vehicle-mounted mobile device that exchanges voice and / or data with the radio access network. For example, devices such as personal communication service (PCS) phones, cordless phones, session initiated protocol (SIP) phones, wireless local loop (WLL) stations, personal digital assistants (PDAs), personal computers, tablets, machine-type communication (MTC) terminal devices, etc. The wireless terminal device can also be called a system, subscriber unit, subscriber station, mobile station, mobile, remote station, access point, remote terminal, access terminal, user terminal, user agent, user device, and wireless access points and routers / modems that meet the limitations of this definition, etc. This is not limited in the embodiments of the present application.
[0129] The network device involved in the embodiments of the present application may be a base station, which may include multiple cells that provide services to terminals. Depending on specific application scenarios, the base station may also be referred to as an access point, or may be a device in the access network that communicates with wireless terminal devices through one or more sectors over the air interface, or other names. The network device can be used to mutually replace the received air frames and Internet Protocol (IP) packets, and act as a router between the wireless terminal device and the rest of the access network, where the rest of the access network may include an Internet Protocol (IP) communication network. The network device can also coordinate the attribute management of the air interface. For example, the network device involved in the embodiments of the present application may be an evolved network device (eNB or e-NodeB) in a Long Term Evolution (LTE) system, a 5G base station (gNB) in a 5G network architecture (next generation system), etc., or may also be a Home evolved Node B (HeNB), a relay node, a femto, a pico, a network test device, etc. The embodiments of the present application do not limit this. In some network architectures, the network device may include a centralized unit (CU) node and a distributed unit (DU) node, and the centralized unit and the distributed unit may also be geographically separated.
[0130] Next, the technical solutions in the embodiments of the present application will be clearly and completely described with reference to the accompanying drawings in the embodiments of the present application. Apparently, the described embodiments are only a part of the embodiments of the present application, rather than all of the embodiments. Based on the embodiments of the present application, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present application.
[0131] Among them, the method and the device are based on the same inventive concept. Since the principles of the method and the device for solving problems are similar, the implementation of the device and the method can be referred to each other, and the repeated parts will not be elaborated.
[0132] Figure 2 It is a flowchart of an authentication and authorization method provided for this embodiment. As Figure 2 shown, this embodiment provides an authentication and authorization method, and the execution entity is a proxy server. The proxy server is a node in the blockchain network, and the authentication and authorization vectors are stored in the blockchain network. The specific steps of the authentication and authorization method provided in this embodiment are as follows:
[0133] S201. Receive an authentication and authorization request sent by an Access and Mobility Management Function (AMF) entity, where the authentication and authorization request includes a terminal identifier.
[0134] In this embodiment, when two-way authentication and authorization between a terminal and a serving network (access network) is required, the terminal may send an authentication and authorization request to the AMF entity (or AMF / SEAF entity), where the authentication and authorization request includes a terminal identifier, and then the AMF entity forwards the authentication and authorization request to the proxy server.
[0135] The scenario where two-way authentication and authorization between a terminal and a serving network (access network) is required may be that the terminal moves to another serving network (for example, the terminal moves from serving network A to serving network B and needs to perform two-way authentication and authorization with serving network B). Of course, it may also be any other possible scenario, which is not limited here.
[0136] S202. Query the authentication and authorization vectors associated with the terminal identifier in the blockchain network. If one or more groups of authentication and authorization vectors associated with the terminal identifier are queried, obtain a group of authentication and authorization vectors associated with the terminal identifier.
[0137] In this embodiment, the AMF entity of each serving network may be connected to a proxy server. As a node in the blockchain network, the proxy server may query and download the authentication and authorization vectors associated with the terminal identifier from the blockchain network according to the authentication and authorization request received from the AMF entity. The authentication and authorization vectors may specifically include, but are not limited to: RAND (Random Challenge), AUTN (Authentication Token), HXRES* (Hash Expected Response), and K SEAF (Security Anchor Function Key), etc.
[0138] Among them, if one or more groups of authentication and authorization vectors associated with the terminal identifier are stored in the blockchain network, since only one group of authentication and authorization vectors is required for each two-way authentication and authorization, the proxy server may only obtain a group of authentication and authorization vectors associated with the terminal identifier from the blockchain network.
[0139] In specific implementation, the proxy server can query the authentication and authorization vectors associated with the terminal identifier in the blockchain network through a preset smart contract. If one or more groups of authentication and authorization vectors associated with the terminal identifier are queried, a group of authentication and authorization vectors associated with the terminal identifier is obtained. Among them, a smart contract is a contract composed of program code that will be automatically executed when conditions are met. After all the contractors of the smart contract confirm the conditions, the smart contract will be deployed on the blockchain, and the blockchain is responsible for execution, transactions, and records. It allows for trusted transactions without a third party. These transactions are traceable and irreversible. In this embodiment, a smart contract for querying and downloading authentication and authorization vectors can be preset on the blockchain network, and query and download conditions can also be set. When it is verified that the query and download conditions are met, the authentication and authorization vectors associated with the terminal identifier can be automatically queried in the blockchain network. Of course, the proxy server can also use any other possible known methods to query and download the authentication and authorization vectors associated with the terminal identifier in the blockchain network, which will not be elaborated here.
[0140] In addition, since a group of authentication and authorization vectors is used for each two-way authentication and authorization, and the group of authentication and authorization vectors will not be used again after use, in this embodiment, after obtaining a group of authentication and authorization vectors associated with the terminal identifier, the obtained authentication and authorization vectors can be marked as unavailable in the blockchain network. In its specific implementation, the obtained authentication and authorization vectors can also be marked as unavailable through a preset smart contract; correspondingly, when obtaining a group of authentication and authorization vectors associated with the terminal identifier, a group of authentication and authorization vectors that have not been marked as unavailable can be selected for download.
[0141] Among them, one or more groups of authentication and authorization vectors associated with the terminal identifier in the blockchain network can be uploaded in advance. The specific process can be as follows:
[0142] When the terminal and the initial service network perform initial two-way authentication and authorization, for example, the terminal is a subscribed user on the initial service network. When the terminal performs initial registration on the initial service network, the terminal and the initial service network need to perform initial two-way authentication and authorization. For the detailed initial registration process, refer to the registration process in TS23.502 (but not limited to this registration process). During the initial two-way authentication and authorization process, the Unified Data Management (UDM) entity can calculate multiple groups of authentication and authorization vectors (AV(n)) based on parameters such as the key K shared with the terminal. Each group of authentication and authorization vectors in the multiple groups of authentication and authorization vectors includes RAND, AUTN, XRES* (Expected Response, expected response), and K. AUSF(Authentication service function key), and send multiple groups of authentication and authorization vectors to the Authentication Server Function (AUSF) entity. The AUSF entity can calculate HXRES* based on XRES* in each group of authentication and authorization vectors, and use the key K AUSF Replace it with the key K SEAF , to obtain the final multiple groups of authentication and authorization vectors. Each group of the final authentication and authorization vectors includes RAND, AUTN, HXRES*, and K SEAF , and the AUSF entity can use one group of authentication and authorization vectors to perform the initial two-way authentication and authorization process with the terminal; after the initial two-way authentication and authorization process is completed, the AUSF entity can send the remaining authentication and authorization vectors except the one group used in the initial two-way authentication and authorization to the AMF entity (or AMF / SEAF entity). Then, the AMF entity (or AMF / SEAF entity) can send the authentication and authorization vectors to the proxy server, and the proxy server uploads them to the blockchain network. Each group of the authentication and authorization vectors includes RAND, AUTN, HXRES*, and K SEAF , and is associated with the terminal identifier. In addition, the specific process of uploading to the blockchain network is not restricted here.
[0143] Optionally, the terminal identifier can be the terminal's Subscription Concealed Identifier (SUCI). Since it needs to be uploaded to the blockchain network, considering the protection of user privacy, the terminal identifier uses the terminal's SUCI.
[0144] S203. Send the obtained authentication and authorization vectors to the AMF entity for the AMF entity to perform two-way authentication and authorization with the terminal.
[0145] In this embodiment, the proxy server can send a group of authentication and authorization vectors associated with the obtained terminal identifier to the AMF entity (or AMF / SEAF entity), and then the AMF entity (or AMF / SEAF entity) performs two-way authentication and authorization with the terminal.
[0146] Among them, the specific two-way authentication and authorization process of the AMF entity (similar to the above initial two-way authentication and authorization process) can be as follows:
[0147] Send the random number RAND and the authentication token AUTN in the authentication and authorization vector to the terminal; temporarily store the digest value HXRES* of the expected response in the authentication and authorization vector, and use K SEAF Replace it with K AMF (AMF key);
[0148] Receive the actual response RES* generated by the terminal based on the random number and the authentication token;
[0149] Obtain the digest value HRES* of the actual response according to the actual response RES*;
[0150] Compare the digest value HRES* of the actual response with the digest value HXRES* of the expected response in the authentication and authorization vector. If they are the same, it is determined that the two-way authentication and authorization is successful.
[0151] Of course, the two-way authentication and authorization process may not be limited to the above example, and other feasible two-way authentication and authorization processes may also be adopted.
[0152] In the authentication and authorization method provided in this embodiment, when two-way authentication and authorization between the terminal and the service network is required, the terminal sends an authentication and authorization request to the Mobility Management Function (AMF) entity, and the AMF entity forwards it to the proxy server. The authentication and authorization request includes the terminal identifier. The proxy server is a node in the blockchain network, and the authentication and authorization vector is stored in the blockchain network; the proxy server queries the authentication and authorization vector associated with the terminal identifier in the blockchain network. If one or more groups of authentication and authorization vectors associated with the terminal identifier are queried, a group of authentication and authorization vectors associated with the terminal identifier is obtained; the obtained authentication and authorization vector is sent to the AMF entity for two-way authentication and authorization between the AMF entity and the terminal. This embodiment uses the blockchain network to distribute and store the authentication and authorization vector, which can ensure stable acquisition of the authentication and authorization vector, shorten the authentication and authorization process, avoid network congestion caused by a large number of terminals requesting the authentication and authorization vector from the home network at the same time, and also avoid the occurrence of single-point failure problems or the situation where the authentication and authorization vector cannot be obtained due to the inability to connect to the home network server. In addition, cross-domain authentication and authorization can also be achieved.
[0153] Based on any of the above embodiments, after receiving the authentication and authorization request sent by the terminal, the AMF entity can also add the service network identifier where the AMF entity is located, such as the service network name (ServiceNetwork ID, SN ID), to the authentication and authorization request, and then send the authentication and authorization request with the added service network identifier to the proxy server. When the proxy server queries the authentication and authorization vector associated with the terminal identifier in the blockchain network, it specifically includes:
[0154] If it is determined according to the service network identifier that the corresponding service network has signed a roaming agreement, or it is determined that the AMF entity has the permission to use the authentication and authorization vector associated with the terminal identifier in the blockchain network, then query the authentication and authorization vector associated with the terminal identifier in the blockchain network.
[0155] In this embodiment, the proxy server can determine whether the corresponding service network has signed a roaming agreement based on the service network identifier. Only the service network that has signed a roaming agreement has the right to use the authentication and authorization vectors associated with the terminal identifier. Alternatively, the proxy server can also determine whether the AMF entity has the right to use the authentication and authorization vectors associated with the terminal identifier in the blockchain network through other means based on the service network identifier. Only when it is determined that the service network corresponding to the service network identifier has signed a roaming agreement, or it is determined that the AMF entity has the right to use the authentication and authorization vectors associated with the terminal identifier in the blockchain network, can the proxy server query the authentication and authorization vectors associated with the terminal identifier in the blockchain network, obtain a set of authentication and authorization vectors associated with the terminal identifier, and return them to the AMF entity to ensure the security and privacy of the authentication and authorization vectors in the blockchain network. The specific judgment process can also be implemented through a preset smart contract or other means, which is not limited here. For example, in the above embodiment, a smart contract for querying and downloading authentication and authorization vectors is preset on the blockchain network. The querying and downloading conditions can be the verification of the service network identifier, and based on the service network identifier, it is determined whether the service network corresponding to the service network identifier has signed a roaming agreement, or it is determined whether the AMF entity has the right to use the authentication and authorization vectors associated with the terminal identifier in the blockchain network. If the verification passes, the authentication and authorization vectors associated with the terminal identifier can be automatically queried in the blockchain network.
[0156] Based on any of the above embodiments, when the proxy server queries the authentication and authorization vectors associated with the terminal identifier in the blockchain network, the authentication and authorization vectors associated with the terminal identifier have all exceeded the preset time limit (the authentication and authorization vectors are unavailable after exceeding the preset time limit), or are all marked as unavailable (for example, used up), indicating that the authentication and authorization vectors associated with the terminal identifier in the blockchain network are all unavailable. The proxy server can send an authentication and authorization vector acquisition request to the AMF entity, so that the AMF entity requests the UDM entity for new authentication and authorization vectors associated with the terminal identifier. The process of the UDM entity generating new authentication and authorization vectors can refer to the above embodiments (optionally, the AUSF entity can also participate in the process of generating new authentication and authorization vectors. For example, in the above embodiment, HXRES* is calculated based on XRES*, and the key K AUSF is replaced with the key K SEAF and so on). Then, the AMF entity can send the new authentication and authorization vectors to the proxy server, which uploads them to the blockchain network for subsequent use, ensuring the replenishment and update of the authentication and authorization vectors in the blockchain network.
[0157] Optionally, the UDM entity generates multiple groups of new authentication and authorization vectors associated with the terminal identifier. The AUSF entity can use one group of the new authentication and authorization vectors for the current two-way authentication and authorization, and send the remaining new authentication and authorization vectors to the AMF entity, which then sends them to the proxy server for uploading to the blockchain network.
[0158] Figure 3 It is a flowchart of an authentication and authorization method provided in this embodiment. As Figure 3 shown, this embodiment provides an authentication and authorization method, and the execution entity is the AMF entity. The specific steps of the authentication and authorization method provided in this embodiment are as follows:
[0159] S301. Receive an authentication and authorization request sent by the terminal, where the authentication and authorization request includes a terminal identifier;
[0160] S302. Forward the authentication and authorization request to the proxy server, where the proxy server is a node in the blockchain network, and one or more groups of authentication and authorization vectors associated with the terminal identifier are stored in the blockchain network;
[0161] S303. Receive a group of authentication and authorization vectors associated with the terminal identifier queried by the proxy server from the blockchain network;
[0162] S304. Perform two-way authentication and authorization with the terminal according to the received authentication and authorization vectors.
[0163] This embodiment is an embodiment of the authentication and authorization method on the AMF entity side. For its principle and technical effects, refer to the embodiment of the authentication and authorization method on the proxy server side above, and details are not described here again.
[0164] Based on the above embodiment, forwarding the authentication and authorization request to the proxy server includes:
[0165] Add the service network identifier where the AMF entity is located to the authentication and authorization request, and send the authentication and authorization request with the added service network identifier to the proxy server. The service network identifier is used to determine whether the corresponding service network has signed a roaming agreement, or to determine whether the AMF entity has the permission to use the authentication and authorization vectors associated with the terminal identifier in the blockchain network.
[0166] Based on any of the above embodiments, performing two-way authentication and authorization with the terminal according to the received authentication and authorization vectors includes:
[0167] Send the random number and authentication token in the authentication and authorization vector to the terminal, and receive the actual response generated by the terminal according to the random number and the authentication token;
[0168] Obtain the digest value of the actual response according to the actual response;
[0169] Compare the digest value of the actual response with the digest value of the expected response in the authentication and authorization vector. If they are the same, it is determined that the two-way authentication and authorization is successful.
[0170] Based on any of the above embodiments
[0171] The method further includes:
[0172] After the authentication service function AUSF entity completes the initial two-way authentication and authorization for the terminal and the initial service network, receive one or more sets of authentication and authorization vectors associated with the terminal identifier sent by the AUSF entity; wherein, one or more sets of authentication and authorization vectors associated with the terminal identifier are the remaining authentication and authorization vectors after removing one set of authentication and authorization vectors used in the initial two-way authentication and authorization from multiple sets of authentication and authorization vectors generated by the UDM entity for the terminal;
[0173] Send one or more sets of authentication and authorization vectors associated with the terminal identifier to the proxy server, so that the proxy server saves them to the blockchain network.
[0174] Based on any of the above embodiments, the method further includes:
[0175] Receive an authentication and authorization vector acquisition request sent by the proxy server after querying that all the authentication and authorization vectors associated with the terminal identifier have exceeded the preset time limit or are all marked as unavailable;
[0176] Request new authentication and authorization vectors associated with the terminal identifier from the UDM entity according to the authentication and authorization vector acquisition request;
[0177] Receive the new authentication and authorization vectors associated with the terminal identifier sent by the UDM entity, and send them to the proxy server, so that the proxy server saves them to the blockchain network.
[0178] The above process of the embodiments of the present application will be introduced in detail below with specific examples.
[0179] 1) Initial two-way authentication and authorization process
[0180] The terminal is initially registered on the initial service network A. When the terminal and the initial service network perform initial two-way authentication and authorization, the UDM entity can generate multiple sets of authentication and authorization vectors (AV(n)) associated with the terminal identifier. Each set of elements in the multiple sets of authentication and authorization vectors includes RAND, AUTN, XRES* (Expected Response, expected response), and K AUSF (Authentication service function key), and send the multiple sets of authentication and authorization vectors to the AUSF entity;
[0181] The AUSF entity can calculate HXRES* based on XRES* in each group of authentication and authorization vectors, and replace the key K AUSF with the key K SEAF to obtain the final multiple groups of authentication and authorization vectors. Each group of the final authentication and authorization vectors includes RAND, AUTN, HXRES*, and K SEAF The AUSF entity can use one group of authentication and authorization vectors to perform the initial two-way authentication and authorization process with the terminal;
[0182] After the initial two-way authentication and authorization process is completed, the AUSF entity can send the remaining authentication and authorization vectors except the group used in the initial two-way authentication and authorization to the AMF entity (or AMF / SEAF entity). Then, the AMF entity (or AMF / SEAF entity) can send the authentication and authorization vectors to the proxy server, and the proxy server uploads them to the blockchain network. Each group of the authentication and authorization vectors includes RAND, AUTN, HXRES*, and K SEAF and is associated with the terminal identifier.
[0183] 2) Repeated two-way authentication and authorization process
[0184] When the terminal moves to the serving network B and needs to re-register, or in other scenarios where two-way authentication and authorization between the terminal and the serving network is required, as Figure 4 shown, the two-way authentication and authorization process is as follows:
[0185] The terminal sends an authentication and authorization request to the AMF entity (or AMF / SEAF entity) of the serving network B, and the authentication and authorization request includes the terminal identifier;
[0186] The AMF entity (or AMF / SEAF entity) adds the serving network identifier where the AMF entity is located to the authentication and authorization request, and sends the authentication and authorization request with the added serving network identifier to the proxy server;
[0187] Based on the terminal identifier and the serving network identifier, the proxy server queries the authentication and authorization vectors associated with the terminal identifier in the blockchain network. If one or more groups of authentication and authorization vectors associated with the terminal identifier are found, one group of authentication and authorization vectors associated with the terminal identifier is obtained; where the serving network identifier is used to determine whether the corresponding serving network has signed a roaming agreement, or to determine whether the AMF entity has the permission to use the authentication and authorization vectors associated with the terminal identifier in the blockchain network;
[0188] The proxy server sends the obtained authentication and authorization vectors to the AMF entity, and performs two-way authentication and authorization with the terminal according to the received authentication and authorization vectors;
[0189] The two-way authentication and authorization process is asFigure 5 As shown in the figure, specifically including:
[0190] The AMF entity (or AMF / SEAF entity) sends the random number RAND and the authentication token AUTN in the authentication and authorization vector to the terminal; temporarily stores the digest value HXRES* of the expected response in the authentication and authorization vector, and replaces K SEAF with K AMF ;
[0191] The terminal verifies the service network based on the random number and the authentication token, generates the actual response RES*; and sends the actual response RES* to the AMF entity (or AMF / SEAF entity);
[0192] The AMF entity (or AMF / SEAF entity) obtains the digest value HRES* of the actual response according to the actual response RES*; compares the digest value HRES* of the actual response with the digest value HXRES* of the expected response in the authentication and authorization vector. If they are the same, it is determined that the two-way authentication and authorization is successful; if they are different, it is determined that the two-way authentication and authorization fails.
[0193] Figure 6 This is a structural diagram of a proxy server according to an embodiment of the present application. The proxy server can execute the processing flow provided by the method embodiment on the proxy server side, as Figure 6 shown, the proxy server 600 includes a memory 601, a transceiver 602, and a processor 603.
[0194] The transceiver 602 is used to receive and send data under the control of the processor 603.
[0195] Among them, in Figure 6 the bus architecture may include any number of interconnected buses and bridges, specifically various circuits of one or more processors 603 represented by the processor 603 and the memory 601 represented by the memory 601 are linked together. The bus architecture can also link various other circuits such as peripheral devices, voltage regulators, and power management circuits together, which are well known in the art, so they will not be further described herein. The bus interface provides an interface. The transceiver 602 can be multiple elements, that is, including a transmitter and a receiver, and provides a unit for communicating with various other devices on the transmission medium, and these transmission mediums include wireless channels, wired channels, optical fiber cables, etc. The processor 603 is responsible for managing the bus architecture and general processing, and the memory 601 can store the data used by the processor 603 when executing operations.
[0196] The processor 603 can be a central processing unit (CPU), an application specific integrated circuit (ASIC), a field-programmable gate array (FPGA), or a complex programmable logic device (CPLD). The processor 603 can also adopt a multi-core architecture.
[0197] The processor 603 is used to read the computer program in the memory 601 and perform the following operations:
[0198] Receive an authentication and authorization request sent by an access and mobility management function (AMF) entity, where the authentication and authorization request includes a terminal identifier;
[0199] Query the authentication and authorization vectors associated with the terminal identifier in the blockchain network. If one or more groups of authentication and authorization vectors associated with the terminal identifier are queried, obtain a group of authentication and authorization vectors associated with the terminal identifier;
[0200] Send the obtained authentication and authorization vectors to the AMF entity for the AMF entity to perform two-way authentication and authorization with the terminal.
[0201] Optionally, the authentication and authorization request further includes a service network identifier of the AMF entity. When the processor 603 queries the authentication and authorization vectors associated with the terminal identifier in the blockchain network, it is used for:
[0202] If it is determined that the corresponding service network has signed a roaming agreement according to the service network identifier, or it is determined that the AMF entity has the permission to use the authentication and authorization vectors associated with the terminal identifier in the blockchain network, query the authentication and authorization vectors associated with the terminal identifier in the blockchain network.
[0203] Optionally, when the processor 603 queries the authentication and authorization vectors associated with the terminal identifier in the blockchain network and, if one or more groups of authentication and authorization vectors associated with the terminal identifier are queried, obtains a group of authentication and authorization vectors associated with the terminal identifier, it is used for:
[0204] Query the authentication and authorization vectors associated with the terminal identifier in the blockchain network through a preset smart contract. If one or more groups of authentication and authorization vectors associated with the terminal identifier are queried, obtain a group of authentication and authorization vectors associated with the terminal identifier.
[0205] Optionally, after the processor 603 obtains a group of authentication and authorization vectors associated with the terminal identifier, it is further used for:
[0206] Mark the obtained authentication and authorization vectors as unavailable in the blockchain network.
[0207] Optionally, the processor 603 is further configured to:
[0208] After the initial two-way authentication and authorization between the terminal and the initial service network is completed, receive one or more sets of authentication and authorization vectors associated with the terminal identifier sent by the AMF entity; wherein, the one or more sets of authentication and authorization vectors associated with the terminal identifier are the remaining authentication and authorization vectors after removing the set of authentication and authorization vectors used in the initial two-way authentication and authorization from the multiple sets of authentication and authorization vectors generated by the unified data management UDM entity for the terminal;
[0209] Save the one or more sets of authentication and authorization vectors associated with the terminal identifier into the blockchain network.
[0210] Optionally, the processor 603 is further configured to:
[0211] If it is queried that all the authentication and authorization vectors associated with the terminal identifier have exceeded the preset time limit or are all marked as unavailable, send an authentication and authorization vector acquisition request to the AMF entity, so that the AMF entity requests new authentication and authorization vectors associated with the terminal identifier from the UDM entity;
[0212] Receive the new authentication and authorization vectors associated with the terminal identifier sent by the AMF entity and save them into the blockchain network.
[0213] It should be noted here that the above proxy server provided by the embodiments of the present invention can implement all the method steps implemented by the method embodiments on the proxy server side and can achieve the same technical effects. The same parts and beneficial effects as those in the method embodiments are not specifically described in this embodiment.
[0214] Figure 7 This is a structural diagram of an AMF entity according to an embodiment of the present application. The AMF entity can execute the processing flow provided by the method embodiment on the AMF entity side, such as Figure 7 As shown, the AMF entity 700 includes a memory 701, a transceiver 702, and a processor 703.
[0215] The transceiver 702 is configured to receive and send data under the control of the processor 703.
[0216] Among them, in Figure 7Among them, the bus architecture may include any number of interconnected buses and bridges, specifically, various circuits represented by one or more processors 703 represented by the processor 703 and the memory 701 represented by the memory 701 are linked together. The bus architecture can also link various other circuits such as peripheral devices, voltage regulators, and power management circuits, which are well known in the art, so they will not be further described herein. The bus interface provides an interface. The transceiver 702 can be multiple components, that is, including a transmitter and a receiver, and provides a unit for communicating with various other devices on a transmission medium, and these transmission mediums include wireless channels, wired channels, optical fiber cables and other transmission mediums. The processor 703 is responsible for managing the bus architecture and general processing, and the memory 701 can store the data used by the processor 703 when executing operations.
[0217] The processor 703 can be a central processing unit (CPU), an application specific integrated circuit (ASIC), a field-programmable gate array (FPGA), or a complex programmable logic device (CPLD). The processor 703 can also adopt a multi-core architecture.
[0218] The processor 703 is used to read the computer program in the memory 701 and perform the following operations:
[0219] Receive an authentication and authorization request sent by a terminal, and the authentication and authorization request includes a terminal identifier;
[0220] Forward the authentication and authorization request to a proxy server, where the proxy server is a node in a blockchain network, and a group or multiple groups of authentication and authorization vectors associated with the terminal identifier are stored in the blockchain network;
[0221] Receive a group of authentication and authorization vectors associated with the terminal identifier queried by the proxy server from the blockchain network;
[0222] Perform two-way authentication and authorization with the terminal according to the received authentication and authorization vectors.
[0223] Optionally, when the processor 703 forwards the authentication and authorization request to the proxy server, it is used for:
[0224] Add the service network identifier where the AMF entity is located to the authentication and authorization request, and send the authentication and authorization request with the added service network identifier to the proxy server. The service network identifier is used to determine whether the corresponding service network has signed a roaming agreement, or to determine whether the AMF entity has the permission to use the authentication and authorization vector associated with the terminal identifier in the blockchain network.
[0225] Optionally, when performing two-way authentication and authorization with the terminal according to the received authentication and authorization vector, the processor 703 is configured to:
[0226] Send the random number and authentication token in the authentication and authorization vector to the terminal, and receive the actual response generated by the terminal based on the random number and the authentication token;
[0227] Obtain the digest value of the actual response according to the actual response;
[0228] Compare the digest value of the actual response with the digest value of the expected response in the authentication and authorization vector. If they are the same, it is determined that the two-way authentication and authorization is successful.
[0229] Optionally, the processor 703 is further configured to:
[0230] After the authentication service function AUSF entity completes the initial two-way authentication and authorization for the terminal and the initial service network, receive a set or multiple sets of authentication and authorization vectors associated with the terminal identifier sent by the AUSF entity; wherein, the set or multiple sets of authentication and authorization vectors associated with the terminal identifier are the remaining authentication and authorization vectors after removing the set of authentication and authorization vectors used in the initial two-way authentication and authorization from the multiple sets of authentication and authorization vectors generated by the UDM entity for the terminal;
[0231] Send the set or multiple sets of authentication and authorization vectors associated with the terminal identifier to the proxy server, so that the proxy server saves them in the blockchain network.
[0232] Optionally, the processor 703 is further configured to:
[0233] Receive an authentication and authorization vector acquisition request sent by the proxy server after querying that all the authentication and authorization vectors associated with the terminal identifier have exceeded the preset time limit or are all marked as unavailable;
[0234] Request the UDM entity for new authentication and authorization vectors associated with the terminal identifier according to the authentication and authorization vector acquisition request;
[0235] Receive the new authentication and authorization vectors associated with the terminal identifier sent by the UDM entity, and send them to the proxy server, so that the proxy server saves them in the blockchain network.
[0236] It should be noted here that the above-mentioned AMF entity provided by the embodiment of the present invention can implement all the method steps implemented by the method embodiment on the AMF entity side, and can achieve the same technical effects. Therefore, the same parts and beneficial effects as those in the method embodiment will not be specifically described herein.
[0237] Figure 8 It is a structural diagram of the authentication and authorization device provided by the embodiment of the present application. The authentication and authorization device provided by this embodiment can execute the processing flow provided by the method embodiment on the proxy server side, such as Figure 8 As shown, the authentication and authorization device 800 includes: a receiving unit 801, a processing unit 802, and a sending unit 803.
[0238] The receiving unit 801 is configured to receive an authentication and authorization request sent by an access and mobility management function AMF entity, where the authentication and authorization request includes a terminal identifier;
[0239] The processing unit 802 is configured to query, in the blockchain network, an authentication and authorization vector associated with the terminal identifier. If one or more groups of authentication and authorization vectors associated with the terminal identifier are queried, then obtain a group of authentication and authorization vectors associated with the terminal identifier;
[0240] The sending unit 803 is configured to send the obtained authentication and authorization vector to the AMF entity for the AMF entity to perform two-way authentication and authorization with the terminal.
[0241] Optionally, the authentication and authorization request further includes a service network identifier where the AMF entity is located; when the processing unit 802 queries the authentication and authorization vector associated with the terminal identifier in the blockchain network, it is configured to:
[0242] If it is determined according to the service network identifier that the corresponding service network has signed a roaming agreement, or it is determined that the AMF entity has the permission to use the authentication and authorization vector associated with the terminal identifier in the blockchain network, then query the authentication and authorization vector associated with the terminal identifier in the blockchain network.
[0243] Optionally, when the processing unit 802 queries the authentication and authorization vector associated with the terminal identifier in the blockchain network, if one or more groups of authentication and authorization vectors associated with the terminal identifier are queried, and then obtain a group of authentication and authorization vectors associated with the terminal identifier, it is configured to:
[0244] Query, in the blockchain network, the authentication and authorization vector associated with the terminal identifier through a preset smart contract. If one or more groups of authentication and authorization vectors associated with the terminal identifier are queried, then obtain a group of authentication and authorization vectors associated with the terminal identifier.
[0245] Optionally, after obtaining a set of authentication and authorization vectors associated with the terminal identifier, the processing unit 802 is further configured to:
[0246] Mark the obtained authentication and authorization vectors as unavailable in the blockchain network.
[0247] Optionally, the receiving unit 801 is further configured to, after the terminal and the initial service network complete the initial two-way authentication and authorization, receive one or more sets of authentication and authorization vectors associated with the terminal identifier sent by the AMF entity; wherein, the one or more sets of authentication and authorization vectors associated with the terminal identifier are the remaining authentication and authorization vectors after removing one set of authentication and authorization vectors used in the initial two-way authentication and authorization from multiple sets of authentication and authorization vectors generated by the unified data management UDM entity for the terminal;
[0248] The processing unit 802 is further configured to save the one or more sets of authentication and authorization vectors associated with the terminal identifier to the blockchain network.
[0249] Optionally, the processing unit 802 is further configured to, if it is queried that all the authentication and authorization vectors associated with the terminal identifier have exceeded the preset time limit or are all marked as unavailable, send an authentication and authorization vector acquisition request to the AMF entity through the sending unit 803, so that the AMF entity requests new authentication and authorization vectors associated with the terminal identifier from the UDM entity;
[0250] The receiving unit 801 is further configured to receive the new authentication and authorization vectors associated with the terminal identifier sent by the AMF entity and save them to the blockchain network through the processing unit 802.
[0251] The authentication and authorization device provided by the embodiment of the present application can specifically be used to execute the method embodiment on the proxy server side, and the specific functions are not described herein again.
[0252] Figure 9 This is a structural diagram of the authentication and authorization device provided by the embodiment of the present application. The authentication and authorization device provided by this embodiment can execute the processing flow provided by the method embodiment on the AMF entity side, as Figure 9 shown. The authentication and authorization device 900 includes: a receiving unit 901, a sending unit 902, and an authentication and authorization unit 903.
[0253] The receiving unit 901 is configured to receive an authentication and authorization request sent by a terminal, where the authentication and authorization request includes a terminal identifier;
[0254] A sending unit 902, configured to forward the authentication and authorization request to a proxy server, where the proxy server is a node in a blockchain network, and a set or multiple sets of authentication and authorization vectors associated with the terminal identifier are stored in the blockchain network;
[0255] The receiving unit 901 is further configured to receive a set of authentication and authorization vectors associated with the terminal identifier, which are queried by the proxy server from the blockchain network;
[0256] An authentication and authorization unit 903, configured to perform two-way authentication and authorization with the terminal according to the received authentication and authorization vectors.
[0257] Optionally, when forwarding the authentication and authorization request to the proxy server, the sending unit 902 is configured to:
[0258] Add the service network identifier where the AMF entity is located to the authentication and authorization request, and send the authentication and authorization request with the added service network identifier to the proxy server, where the service network identifier is used to determine whether the corresponding service network has signed a roaming agreement, or to determine whether the AMF entity has the permission to use the authentication and authorization vectors associated with the terminal identifier in the blockchain network.
[0259] Optionally, when performing two-way authentication and authorization with the terminal according to the received authentication and authorization vectors, the authentication and authorization unit 903 is configured to:
[0260] Send the random number and the authentication token in the authentication and authorization vector to the terminal through the sending unit 902, and receive the actual response generated by the terminal according to the random number and the authentication token through the receiving unit 901;
[0261] Obtain the digest value of the actual response;
[0262] Compare the digest value of the actual response with the digest value of the expected response in the authentication and authorization vector. If they are the same, it is determined that the two-way authentication and authorization is successful.
[0263] Optionally, the receiving unit 901 is further configured to, after the authentication service function AUSF entity completes the initial two-way authentication and authorization for the terminal and the initial service network, receive a set or multiple sets of authentication and authorization vectors associated with the terminal identifier sent by the AUSF entity; where the set or multiple sets of authentication and authorization vectors associated with the terminal identifier are the remaining authentication and authorization vectors after removing the set of authentication and authorization vectors used in the initial two-way authentication and authorization from the multiple sets of authentication and authorization vectors generated by the UDM entity for the terminal;
[0264] The sending unit 902 is further configured to send one or more groups of authentication and authorization vectors associated with the terminal identifier to the proxy server, so that the proxy server saves them in the blockchain network.
[0265] Optionally, the receiving unit 901 is further configured to receive an authentication and authorization vector acquisition request sent by the proxy server after querying that all the authentication and authorization vectors associated with the terminal identifier have exceeded a preset time limit or are all marked as unavailable;
[0266] The sending unit 902 is further configured to request new authentication and authorization vectors associated with the terminal identifier from the UDM entity according to the authentication and authorization vector acquisition request;
[0267] The receiving unit 901 is further configured to receive the new authentication and authorization vectors associated with the terminal identifier sent by the UDM entity and send them to the proxy server, so that the proxy server saves them in the blockchain network.
[0268] The authentication and authorization device provided by the embodiment of the present application can specifically be used to execute the method embodiment on the side of the AMF entity, and the specific functions are not described in detail here.
[0269] It should be noted that the division of units in the embodiment of the present application is illustrative, and is only a logical function division. In actual implementation, there may be other division methods. In addition, in each embodiment of the present application, each functional unit may be integrated into one processing unit, or each unit may exist physically alone, or two or more units may be integrated into one unit. The above integrated unit can be implemented in the form of hardware or in the form of a software functional unit.
[0270] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a processor-readable storage medium. Based on such an understanding, the technical solution of the present application, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions for causing a computer device (which may be a personal computer, a server, or a network device, etc.) or a processor to execute all or part of the steps of the method described in each embodiment of the present application.
[0271] It should be noted here that the above device provided by the embodiment of the present invention can implement all the method steps implemented by the above method embodiment, and can achieve the same technical effect. The same parts and beneficial effects as those in the method embodiment are not specifically described in this embodiment.
[0272] In addition, an embodiment of the present application further provides a non-transitory readable storage medium storing a computer program for causing a processor to execute the method embodiments on the side of the proxy server or the AMF entity. The non-transitory readable storage medium may be any available medium or data storage device accessible by the processor, including but not limited to magnetic memories (such as floppy disks, hard disks, magnetic tapes, magneto-optical disks (MO), etc.), optical memories (such as CDs, DVDs, BDs, HVDs, etc.), and semiconductor memories (such as ROM, EPROM, EEPROM, non-volatile memories (NAND FLASH), solid state drives (SSD)), etc.
[0273] Those skilled in the art should understand that the embodiments of the present application may be provided as a method, a system, or a computer program product. Therefore, the present application may take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present application may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk memories and optical memories, etc.) containing computer-usable program code.
[0274] The present application is described with reference to the flowcharts and / or block diagrams of methods, apparatuses (systems), and computer program products according to the embodiments of the present application. It should be understood that each flow and / or block in the flowcharts and / or block diagrams, and the combination of flows and / or blocks in the flowcharts and / or block diagrams, can be implemented by computer-executable instructions. These computer-executable instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing devices to generate a machine, so that the instructions executed by the processor of the computer or other programmable data processing devices generate a device for implementing the functions specified in Figure 1 one or more of the flows Figure 1 or blocks or the combination of multiple flows and / or blocks.
[0275] These processor-executable instructions can also be stored in a processor-readable memory that can direct a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the processor-readable memory generate a manufactured article including an instruction device that implements the functions specified in Figure 1 one or more of the flows Figure 1 or blocks or the combination of multiple flows and / or blocks.
[0276] Obviously, those skilled in the art can make various modifications and variations to the present application without departing from the spirit and scope of the present application. Thus, if these modifications and variations of the present application fall within the scope of the claims of the present application and their equivalent technologies, the present application is also intended to include these modifications and variations.
Claims
1. A method for authentication and authorization, characterized in that, Applied to a proxy server, the proxy server being a node in a blockchain network, where authentication and authorization vectors are stored in the blockchain network, the method includes: Receiving an authentication and authorization request sent by an Access and Mobility Management Function (AMF) entity, the authentication and authorization request including a terminal identifier; Querying, in the blockchain network, the authentication and authorization vectors associated with the terminal identifier. If one or more groups of authentication and authorization vectors associated with the terminal identifier are queried, obtaining a group of authentication and authorization vectors associated with the terminal identifier; Sending the obtained authentication and authorization vectors to the AMF entity for the AMF entity to perform two-way authentication and authorization with the terminal.
2. The method according to claim 1, characterized in that, The authentication and authorization request further includes a service network identifier where the AMF entity is located. The querying, in the blockchain network, the authentication and authorization vectors associated with the terminal identifier includes: If it is determined that the corresponding service network has signed a roaming agreement according to the service network identifier, or it is determined that the AMF entity has the permission to use the authentication and authorization vectors associated with the terminal identifier in the blockchain network, querying the authentication and authorization vectors associated with the terminal identifier in the blockchain network.
3. The method according to claim 1 or 2, characterized in that, The querying, in the blockchain network, the authentication and authorization vectors associated with the terminal identifier. If one or more groups of authentication and authorization vectors associated with the terminal identifier are queried, obtaining a group of authentication and authorization vectors associated with the terminal identifier includes: Querying, in the blockchain network, the authentication and authorization vectors associated with the terminal identifier through a preset smart contract. If one or more groups of authentication and authorization vectors associated with the terminal identifier are queried, obtaining a group of authentication and authorization vectors associated with the terminal identifier.
4. The method according to claim 3, wherein After obtaining a group of authentication and authorization vectors associated with the terminal identifier, it further includes: Marking the obtained authentication and authorization vectors as unavailable in the blockchain network.
5. The method according to claim 1, wherein The method further includes: After the terminal and the initial service network complete the initial two-way authentication and authorization, receiving one or more groups of authentication and authorization vectors associated with the terminal identifier sent by the AMF entity; wherein, the one or more groups of authentication and authorization vectors associated with the terminal identifier are the remaining authentication and authorization vectors after removing the group of authentication and authorization vectors used during the initial two-way authentication and authorization from the multiple groups of authentication and authorization vectors generated by a Unified Data Management (UDM) entity for the terminal; Saving the one or more groups of authentication and authorization vectors associated with the terminal identifier to the blockchain network.
6. The method according to claim 1, characterized in that, The method further includes: If it is queried that all the authentication and authorization vectors associated with the terminal identifier have exceeded a preset time limit, or are all marked as unavailable, sending an authentication and authorization vector acquisition request to the AMF entity to enable the AMF entity to request new authentication and authorization vectors associated with the terminal identifier from the UDM entity; Receiving the new authentication and authorization vectors associated with the terminal identifier sent by the AMF entity and saving them to the blockchain network.
7. A method for authentication and authorization, characterized in that, Applied to an AMF entity, the method includes: Receiving an authentication and authorization request sent by a terminal, the authentication and authorization request including a terminal identifier; Forward the authentication and authorization request to a proxy server, where the proxy server is a node in a blockchain network, and one or more groups of authentication and authorization vectors associated with the terminal identifier are stored in the blockchain network; Receive a group of authentication and authorization vectors associated with the terminal identifier queried by the proxy server from the blockchain network; Perform two-way authentication and authorization with the terminal according to the received authentication and authorization vectors.
8. The method according to claim 7, characterized in that, The step of forwarding the authentication and authorization request to the proxy server includes: Adding the service network identifier where the AMF entity is located to the authentication and authorization request, and sending the authentication and authorization request with the added service network identifier to the proxy server. The service network identifier is used to determine whether the corresponding service network has signed a roaming agreement, or to determine whether the AMF entity has the permission to use the authentication and authorization vectors associated with the terminal identifier in the blockchain network.
9. The method according to claim 7, wherein The step of performing two-way authentication and authorization with the terminal according to the received authentication and authorization vectors includes: Sending the random number and authentication token in the authentication and authorization vector to the terminal, and receiving the actual response generated by the terminal according to the random number and the authentication token; Obtaining the digest value of the actual response according to the actual response; Comparing the digest value of the actual response with the digest value of the expected response in the authentication and authorization vector. If they are the same, it is determined that the two-way authentication and authorization is successful.
10. The method according to any one of claims 7-9, characterized in that, The method further includes: After the authentication service function AUSF entity completes the initial two-way authentication and authorization for the terminal and the initial service network, receiving one or more groups of authentication and authorization vectors associated with the terminal identifier sent by the AUSF entity; wherein, the one or more groups of authentication and authorization vectors associated with the terminal identifier are the remaining authentication and authorization vectors after removing the group of authentication and authorization vectors used in the initial two-way authentication and authorization from the multiple groups of authentication and authorization vectors generated by the UDM entity for the terminal; Sending the one or more groups of authentication and authorization vectors associated with the terminal identifier to the proxy server so that the proxy server saves them to the blockchain network.
11. The method according to any one of claims 7-9, characterized in that, The method further includes: Receiving an authentication and authorization vector acquisition request sent by the proxy server after querying that all the authentication and authorization vectors associated with the terminal identifier have exceeded the preset time limit or are all marked as unavailable; Requesting new authentication and authorization vectors associated with the terminal identifier from the UDM entity according to the authentication and authorization vector acquisition request; Receiving the new authentication and authorization vectors associated with the terminal identifier sent by the UDM entity and sending them to the proxy server so that the proxy server saves them to the blockchain network.
12. An authentication and authorization device, characterized in that, including: A receiving unit, configured to receive an authentication and authorization request sent by an access and mobility management function AMF entity, where the authentication and authorization request includes a terminal identifier; A processing unit, configured to query for authentication and authorization vectors associated with the terminal identifier in a blockchain network. If one or more groups of authentication and authorization vectors associated with the terminal identifier are queried, obtain a group of authentication and authorization vectors associated with the terminal identifier; A sending unit, configured to send the obtained authentication and authorization vector to the AMF entity for the AMF entity to perform two-way authentication and authorization with the terminal.
13. An authentication and authorization device, characterized in that, It includes: A receiving unit, configured to receive an authentication and authorization request sent by the terminal, where the authentication and authorization request includes a terminal identifier; A sending unit, configured to forward the authentication and authorization request to a proxy server, where the proxy server is a node in a blockchain network, and one or more groups of authentication and authorization vectors associated with the terminal identifier are stored in the blockchain network; The receiving unit is further configured to receive a group of authentication and authorization vectors associated with the terminal identifier queried by the proxy server from the blockchain network; An authentication and authorization unit, configured to perform two-way authentication and authorization with the terminal according to the received authentication and authorization vector.
14. A proxy server, characterized in that, It includes a memory, a transceiver, and a processor; the proxy server is a node in a blockchain network, and authentication and authorization vectors are stored in the blockchain network; The memory is configured to store a computer program; the transceiver is configured to send and receive data under the control of the processor; the processor is configured to read the computer program in the memory and perform the following operations: Receive an authentication and authorization request sent by an access and mobility management function AMF entity, where the authentication and authorization request includes a terminal identifier; Query the authentication and authorization vectors associated with the terminal identifier in the blockchain network. If one or more groups of authentication and authorization vectors associated with the terminal identifier are queried, obtain a group of authentication and authorization vectors associated with the terminal identifier; Send the obtained authentication and authorization vector to the AMF entity for the AMF entity to perform two-way authentication and authorization with the terminal.
15. The proxy server according to claim 14, wherein The authentication and authorization request further includes a service network identifier where the AMF entity is located; when the processor queries the authentication and authorization vectors associated with the terminal identifier in the blockchain network, it is configured to: If it is determined according to the service network identifier that the corresponding service network has signed a roaming agreement, or it is determined that the AMF entity has the right to use the authentication and authorization vectors associated with the terminal identifier in the blockchain network, query the authentication and authorization vectors associated with the terminal identifier in the blockchain network.
16. The proxy server according to claim 14 or 15, characterized in that, When the processor queries the authentication and authorization vectors associated with the terminal identifier in the blockchain network and, if one or more groups of authentication and authorization vectors associated with the terminal identifier are queried, obtains a group of authentication and authorization vectors associated with the terminal identifier, it is configured to: Query the authentication and authorization vectors associated with the terminal identifier in the blockchain network through a preset smart contract. If one or more groups of authentication and authorization vectors associated with the terminal identifier are queried, obtain a group of authentication and authorization vectors associated with the terminal identifier.
17. The proxy server according to claim 16, wherein After the processor obtains a group of authentication and authorization vectors associated with the terminal identifier, it is further configured to: Mark the obtained authentication and authorization vector as unavailable in the blockchain network.
18. The proxy server according to claim 14, wherein The processor is further configured to: After the initial two-way authentication and authorization are completed between the terminal and the initial service network, receive one or more sets of authentication and authorization vectors associated with the terminal identifier sent by the AMF entity; wherein, the one or more sets of authentication and authorization vectors associated with the terminal identifier are the remaining authentication and authorization vectors after removing one set of authentication and authorization vectors used in the initial two-way authentication and authorization from multiple sets of authentication and authorization vectors generated by the Unified Data Management (UDM) entity for the terminal. Save the one or more sets of authentication and authorization vectors associated with the terminal identifier to the blockchain network.
19. The proxy server according to claim 14, wherein The processor is further configured to: If it is queried that all the authentication and authorization vectors associated with the terminal identifier have exceeded the preset time limit, or are all marked as unavailable, send an authentication and authorization vector acquisition request to the AMF entity, so that the AMF entity requests new authentication and authorization vectors associated with the terminal identifier from the UDM entity. Receive the new authentication and authorization vectors associated with the terminal identifier sent by the AMF entity and save them to the blockchain network.
20. An AMF entity, characterized in that, Comprising a memory, a transceiver, and a processor; The memory is used to store computer programs; the transceiver is used to send and receive data under the control of the processor; the processor is used to read the computer programs in the memory and perform the following operations: Receive an authentication and authorization request sent by a terminal, where the authentication and authorization request includes a terminal identifier. Forward the authentication and authorization request to a proxy server, where the proxy server is a node in the blockchain network, and one or more sets of authentication and authorization vectors associated with the terminal identifier are stored in the blockchain network. Receive one set of authentication and authorization vectors associated with the terminal identifier queried by the proxy server from the blockchain network. Perform two-way authentication and authorization with the terminal according to the received authentication and authorization vectors.
21. The AMF entity according to claim 20, wherein, When forwarding the authentication and authorization request to the proxy server, the processor is configured to: Add the service network identifier where the AMF entity is located to the authentication and authorization request, and send the authentication and authorization request with the added service network identifier to the proxy server. The service network identifier is used to determine whether the corresponding service network has signed a roaming agreement, or to determine whether the AMF entity has the right to use the authentication and authorization vectors associated with the terminal identifier in the blockchain network.
22. The AMF entity according to claim 20, characterized in that, When performing two-way authentication and authorization with the terminal according to the received authentication and authorization vectors, the processor is configured to: Send the random number and the authentication token in the authentication and authorization vectors to the terminal, and receive the actual response generated by the terminal according to the random number and the authentication token. Obtain the digest value of the actual response according to the actual response. Compare the digest value of the actual response with the digest value of the expected response in the authentication and authorization vectors. If they are the same, determine that the two-way authentication and authorization are successful.
23. The AMF entity according to any one of claims 20-22, characterized in that, The processor is further configured to: After the authentication service function AUSF entity completes the initial two-way authentication and authorization for the terminal and the initial service network, it receives one or more sets of authentication and authorization vectors associated with the terminal identifier sent by the AUSF entity; wherein, the one or more sets of authentication and authorization vectors associated with the terminal identifier are the remaining authentication and authorization vectors after removing the set of authentication and authorization vectors used in the initial two-way authentication and authorization from the multiple sets of authentication and authorization vectors generated by the UDM entity for the terminal. Send the one or more sets of authentication and authorization vectors associated with the terminal identifier to the proxy server, so that the proxy server saves them in the blockchain network.
24. The AMF entity according to any one of claims 20-22, characterized in that, The processor is further configured to: Receive an authentication and authorization vector acquisition request sent by the proxy server after querying that all the authentication and authorization vectors associated with the terminal identifier have exceeded the preset time limit or are all marked as unavailable; Request the UDM entity for new authentication and authorization vectors associated with the terminal identifier according to the authentication and authorization vector acquisition request; Receive the new authentication and authorization vectors associated with the terminal identifier sent by the UDM entity and send them to the proxy server, so that the proxy server saves them in the blockchain network.
25. A non-transitory readable storage medium, characterized in that, The non-transitory readable storage medium stores a computer program, and the computer program is used to cause the processor to execute the method according to any one of claims 1-11.