Access authentication method and related device
By verifying the network element to obtain the terminal user identification file information and using public key authentication, the complexity and security problems of access authentication of multiple operators and one card are solved, and the effect of simplifying the process and improving security is achieved.
Patent Information
- Application Number
- CN202410095134.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-01-22
- Publication Date
- 2025-07-22
AI Technical Summary
In the prior art, user terminals need to be bound to the local operator, resulting in the inability to realize one card for multiple operators. Operators need to maintain a large amount of user information, there is a risk of single-point attack leakage, the access authentication process is complex and the security is low.
By verifying the network element, obtain the corresponding file information of the terminal's user ID, use the terminal's public key for authentication, simplify the authentication process, and improve security and flexibility.
There is no need to fall back to the home operator certification, which simplifies the authentication process, improves security and flexibility, and reduces operator management pressure and user experience improvement.
Smart Images

Figure CN120358494A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of communications, and in particular, to an access authentication method and related devices. Background Art
[0002] Currently, a user (or user card) needs to be bound to an operator, and it is impossible to achieve a one-card for multiple operators. That is to say, each operator independently manages its own user information, and even for the same type of operators in different regions, they independently manage their own user information. Operators need to maintain a large amount of user information, and there is a risk of leakage caused by a single-point attack. In addition, network access authentication is generally controlled by the home operator, where the home operator refers to the operator where the user signs the contract.
[0003] If a certain terminal is located in a region outside the home location, then the terminal needs to be access-authenticated by the home operator when accessing the network. Exemplarily, a user signs a contract with a mobile operator in region A, but the user is located in region B, so the user accesses the mobile operator in region B. The specific access authentication process includes: when the terminal accesses the network, it needs to send the user identifier to the serving network (the network in region B), and the serving network sends the user identifier to the home network, and the home network completes the access authentication of the terminal. That is to say, the serving network cannot perform access authentication on the terminal, and the whole process is relatively complex, resulting in a poor user experience. Summary of the Invention
[0004] This application provides an access authentication method and related devices, which can provide a secure and flexible authentication process, thereby improving the service experience.
[0005] In a first aspect, this application provides an access authentication method, which can be executed by an access authentication device. The access authentication device can be a verification network element, or a component (such as a chip, a chip system, etc.) configured in the verification network element, or, alternatively, a logic module or software that can implement all or part of the functions of the verification network element. This application does not make any limitations in this regard.
[0006] In this application, the verification network element is a network element of the target operator to which the terminal accesses. For example, the verification network element can be a core network element of the target operator to which the terminal accesses. For example, the verification network element can be an authentication server function (AUSF) network element, or an access and mobility management function (AMF) network element, or other core network elements. Also for example, the verification network element can also be an access network element of the target operator to which the terminal accesses, such as an access network node to which the terminal accesses. This application does not make any limitations in this regard.
[0007] Exemplarily, the method includes: receiving a user identifier from a terminal; obtaining file information corresponding to the user identifier from a storage network element, where the file information includes a public key of the terminal; and authenticating the terminal based on the file information.
[0008] In this application, the authentication network element and the storage network element may be the same network element or different network elements, and this application does not make any limitation in this regard. When the authentication network element and the storage network element are the same network element, the authentication network element obtaining the file information corresponding to the user identifier from the storage network element can be understood as the authentication network element obtaining the file information corresponding to the user identifier from the memory or local storage; when the authentication network element and the storage network element are different network elements, the authentication network element obtaining the file information corresponding to the user identifier from the storage network element can be understood as the authentication network element sending the user identifier to the storage network element and receiving the file information corresponding to the user identifier from the storage network element.
[0009] In the above technical solution, the authentication network element can obtain the file information corresponding to the user identifier from the storage network element according to the user identifier from the terminal, so as to complete the authentication of the terminal based on the file information. And the authentication network element can be a network element of the target operator accessed by the terminal. That is to say, even if the authentication network element is not a network element of the home operator, it can also obtain the file information corresponding to the user identifier to complete the authentication of the terminal, without having to fallback to the home operator for authentication, which is beneficial to simplifying the authentication process and thus reducing the latency. In addition, the above file information includes the public key of the terminal, and authenticating the terminal based on the public key of the terminal has higher security and flexibility compared to using symmetric keys.
[0010] In some possible implementation manners of the first aspect, the above authenticating the terminal based on the file information includes: receiving a first message from the terminal and a digital signature of the terminal, where the digital signature of the terminal is obtained by signing a second message or a hash value of the second message based on a private key of the terminal, and the second message is a message that has been interacted between the terminal and the authentication network element or the first message; and verifying the digital signature of the terminal based on the public key of the terminal.
[0011] Wherein, the above second message may be one or more of all the messages that have been interacted between the terminal and the authentication network element, and this application does not make any limitation in this regard.
[0012] The verification network element can verify the digital signature of the terminal based on the public key of the terminal in the file information, where the digital signature of the terminal is obtained by signing the second message or the hash value of the second message based on the private key of the terminal. If the verification network element passes the verification of the digital signature of the terminal, it is considered that the verification network element passes the authentication of the terminal. Correspondingly, if the verification network element fails to verify the digital signature of the terminal, it is considered that the verification network element fails to authenticate the terminal.
[0013] Verifying the digital signature of the terminal based on the public key of the terminal makes the selection of the verification network element relatively flexible. In other words, it is not limited that the verification network element is a certain specific network element, and any network element can complete the authentication of the terminal, with higher flexibility.
[0014] In some possible implementation manners of the first aspect, before verifying the digital signature of the terminal based on the public key of the terminal, the above method further includes: obtaining the authentication credential of the issuer from the storage network element, where the issuer is the issuer of the authentication credential of the terminal; verifying the authentication credential of the terminal based on the authentication credential of the issuer.
[0015] The issuer can be any one of an operator, a device manufacturer, a card manufacturer, etc. The verification network element can obtain the authentication credential of any issuer and verify the authentication credential of the terminal based on this credential, so that the flexibility of verification is higher.
[0016] In some possible implementation manners of the first aspect, the above method further includes: sending a third message and the digital signature of the verification network element to the terminal, where the digital signature of the verification network element is obtained by signing the fourth message or the hash value of the fourth message based on the private key of the verification network element, and the fourth message is the message interacted between the terminal and the verification network element or the above third message.
[0017] Among them, the fourth message can be one or more of all the messages interacted between the above terminal and the above verification network element. It can be understood that since the time when the verification network element receives the second message and sends the third message is different, the messages interacted between the terminal and the verification network element will also change. Therefore, the second message and the fourth message may be different.
[0018] The verification network element sends the digital signature of the verification network element to the terminal, so that the terminal can verify the digital signature of the verification network element based on the public key of the verification network element. And verifying the verification network element based on the public key of the verification network element enables the terminal to verify the verification network element corresponding to any operator. In this way, the terminal can access different operators with higher flexibility.
[0019] In addition, the authentication network element may receive the first message and the digital signature of the terminal before sending the third message and the digital signature of the authentication network element, or may receive the first message and the digital signature of the terminal after sending the third message and the digital signature of the authentication network element. This application does not make any restrictions in this regard. For example, the authentication network element may receive the first message and the digital signature of the terminal, and based on the public key of the terminal, verify the digital signature of the terminal. If the verification is successful, the authentication network element sends the third message and its own digital signature to the terminal.
[0020] In some possible implementations of the first aspect, the above method further includes: sending the certificate of the authentication network element to the terminal.
[0021] Among them, the certificate of the authentication network element may include, for example, the public key of the authentication network element, the issuer, the validity period, the signature of the issuer, the version number, the identifier of the authentication network element, the method for querying the certificate status (such as: revocation list information, online certificate status protocol (OCSP), etc.). When the certificate of the authentication network element is not pre-configured in the terminal, the terminal may pre-configure the certificate of the target operator, where the certificate of the target operator includes the public key of the operator. The terminal may verify the certificate of the authentication network element based on the certificate of the target operator, and then verify the digital signature of the authentication network element based on the public key of the authentication network element. The certificate of the authentication network element is issued by the operator, that is to say, the signature of the authentication network element certificate is generated using the private key of the operator. The terminal may use the public key in the operator's certificate to verify the signature of the authentication network element certificate; and use the public key of the authentication network element certificate to verify the digital signature of the authentication network element. If both of the above processes are successfully verified, it is considered that the terminal's authentication of the authentication network element is successful.
[0022] By sending the certificate of the authentication network element to the terminal through the authentication network element, the terminal does not need to pre-configure the certificate of the authentication network element. In the case of a large number of authentication network elements, the terminal does not need to pre-configure the certificates of each authentication network element, which helps to save the storage space of the terminal.
[0023] Optionally, the certificate of the authentication network element and the digital signature of the authentication network element may be carried in the same signaling or in different signaling. This application does not make any restrictions in this regard.
[0024] In some possible implementations of the first aspect, the above file information further includes at least one authentication credential and the algorithm corresponding to each authentication credential in the at least one authentication credential; and, the above method further includes: determining a target authentication credential from the at least one authentication credential; sending a first indication message to the terminal, where the first indication message is used to indicate the target authentication credential and / or the algorithm corresponding to the target authentication credential.
[0025] In this application, in one possible design, different authentication credentials can be understood as certificates with different format standards, such as certificates in X.509 format, lightweight certificates, certificates in a custom format defined by the operator, etc. The algorithms corresponding to each authentication credential can include the signature algorithm used in the certificate and the verification signature algorithm that needs to be used, etc. The algorithms corresponding to each authentication credential can be one or more, and this application does not make any restrictions in this regard. In another possible design, different authentication credentials may be multiple certificates with the same format standard. For example, a terminal may have 3 authentication credentials, and the formats of these 3 authentication credentials are all in X.509 format.
[0026] The authentication network element can indicate the target authentication credential and / or the algorithm corresponding to the target authentication credential to the terminal. For example, the above-mentioned target authentication credential and / or the algorithm corresponding to the target authentication credential can be determined according to the network status, security level, etc. That is to say, the target authentication credential and / or the algorithm corresponding to the target authentication credential can be flexibly selected, rather than always using a certain authentication credential and / or the algorithm corresponding to this authentication credential, and the flexibility of authentication is higher.
[0027] In a second aspect, this application provides an access authentication method. This method can be executed by an access authentication device. The access authentication device can be a terminal, or a component configured in the terminal (such as a chip, a chip system, etc.), or can also be a logical module or software that can implement all or part of the functions of the terminal. This application does not make any restrictions in this regard.
[0028] Exemplarily, the method includes: obtaining a user identifier; sending the above-mentioned user identifier to an authentication network element, where the authentication network element is a network element of the target operator to which the terminal is connected, and the above-mentioned user identifier corresponds to the file information stored in the storage network element. The file information includes the public key of the above-mentioned terminal, and the file information is used to authenticate the terminal.
[0029] In the above technical solution, the terminal can send the user identifier to the authentication network element, and the user identifier corresponds to the file information in the storage network element. In other words, after obtaining the user identifier, the authentication network element can obtain the corresponding file information according to the user identifier, and then complete the authentication of the terminal based on the above-mentioned file information. The authentication network element can be a network element of the target operator to which the terminal is connected. That is to say, even if the authentication network element is not a network element of the home operator, it can obtain the file information corresponding to the user identifier to complete the authentication of the terminal, without having to fall back to the home operator for authentication, which is beneficial to simplifying the authentication process. In addition, the above-mentioned file information includes the public key of the terminal. Authenticating the terminal based on the public key of the terminal is more secure and flexible than using a symmetric key.
[0030] In some possible implementations of the second aspect, the above method further includes: receiving a third message from a verification network element and a digital signature of the verification network element, where the digital signature of the verification network element is obtained by signing a fourth message or a hash value of the fourth message based on the private key of the verification network element, and the fourth message is a message exchanged between the terminal and the verification network element or the above third message; verifying the digital signature of the verification network element based on the public key of the verification network element.
[0031] Wherein, the fourth message may be one or more of all the messages exchanged between the terminal and the verification network element. The public key of the verification network element may be pre-set in the terminal, and the digital signature of the verification network element is verified based on the public key of the verification network element. If the terminal passes the verification of the digital signature of the verification network element, it is considered that the terminal passes the authentication of the verification network element. By using the method of verifying the signature with the public key for authentication, the authentication process is relatively simple.
[0032] The terminal verifies the digital signature of the verification network element based on the public key of the verification network element, so that the terminal can verify the verification network element corresponding to any operator. In this way, the terminal can access different operators with higher flexibility.
[0033] In some possible implementations of the second aspect, the above method further includes: sending a first message and a digital signature of the terminal to the verification network element, where the digital signature of the terminal is obtained by signing a second message or a hash value of the second message based on the private key of the terminal, and the second message is a message exchanged between the terminal and the verification network element or the above first message.
[0034] Wherein, the second message may be one or more of all the messages exchanged between the terminal and the verification network element, and the present application does not make any limitation thereto.
[0035] It can be understood that since the time when the verification network element receives the second message and sends the third message is different, the messages exchanged between the terminal and the verification network element will also change. Therefore, the second message and the fourth message may be different.
[0036] The terminal may send the digital signature of the terminal to the verification network element, so that the verification network element verifies the digital signature based on the public key of the terminal, and further completes the authentication of the terminal. By using the method of verifying the signature with the public key for authentication, the authentication process is relatively simple.
[0037] In addition, the terminal may receive the third message and the digital signature of the authentication network element before sending the first message and the digital signature of the terminal to the authentication network element, or may receive the third message and the digital signature of the authentication network element after sending the first message and the digital signature of the terminal to the authentication network element. This application does not make any restrictions in this regard. For example, the terminal may receive the third message and the digital signature of the authentication network element, and based on the public key of the authentication network element, verify the digital signature of the authentication network element. If the verification is passed, the terminal sends the first message and the digital signature of the terminal to the authentication network element.
[0038] The terminal sends the digital signature of the terminal so that the authentication network element can verify the digital signature of the terminal based on the public key of the terminal. Verifying the digital signature of the terminal based on the public key of the terminal makes the selection of the authentication network element relatively flexible. In other words, it is not limited that the authentication network element is a certain specific network element, and any network element can complete the authentication of the terminal, with higher flexibility.
[0039] In some possible implementation manners of the second aspect, the above method further includes: receiving the certificate of the authentication network element.
[0040] Among them, the certificate of the above authentication network element includes, for example, the public key of the authentication network element, the issuer, the validity period, the signature of the issuer, the version number, the identifier of the authentication network element, the method for querying the certificate status (such as: revocation list information, OCSP, etc.). When the certificate of the above authentication network element is not pre-configured in the terminal, the terminal may pre-configure the certificate of the target operator, where the certificate of the target operator includes the public key of the operator. The terminal may verify the certificate of the authentication network element based on the certificate of the target operator, and then verify the digital signature of the authentication network element based on the public key of the authentication network element. Among them, the certificate of the authentication network element is issued by the operator, that is to say, the signature of the authentication network element certificate is generated using the private key of the operator. The terminal may use the public key in the operator certificate to verify the signature of the authentication network element certificate; and use the public key of the authentication network element certificate to verify the digital signature of the authentication network element. If the above processes are all verified successfully, it is considered that the authentication of the terminal to the authentication network element is successful.
[0041] By receiving the certificate of the authentication network element, the terminal does not need to pre-configure the certificate of the authentication network element. It can be imagined that in the case of a large number of authentication network elements, the terminal does not need to pre-configure the certificates of each authentication network element, which is beneficial to saving the storage space of the terminal.
[0042] Optionally, the certificate of the authentication network element and the digital signature of the authentication network element may be carried in the same signaling or in different signaling. This application does not make any restrictions in this regard.
[0043] In some possible implementation manners of the second aspect, before obtaining the user identifier, the above method further includes: determining the target operator from multiple operators.
[0044] The terminal can determine a target operator from multiple operators. These multiple operators can be operators that have signed contracts with the user or operators that have not signed contracts with the user. This application does not make any restrictions in this regard. That is to say, each operator has the opportunity to be selected, which is conducive to improving the fairness of competition among operators.
[0045] In some possible implementation manners of the second aspect, determining the target operator from multiple operators includes: determining the target operator from multiple operators according to one or more of the user's location, the service quality (such as signal strength) of each operator among the multiple operators, the fees of each operator among the multiple operators, or the security of each operator among the multiple operators.
[0046] For example, the terminal can select the operator with the strongest signal strength, the lowest fee, and the highest security at the user's location among the multiple operators as the target operator to provide better services for the user, which is conducive to improving the user experience.
[0047] In some possible implementation manners of the second aspect, determining the target operator from multiple operators includes: in response to a user operation, determining the target operator from multiple operators, where the user operation is an operation in which the user selects a target operator from the multiple operators.
[0048] The terminal can display multiple operators available for the user to select through a user interface. In response to the user's operation of selecting a target operator from the multiple operators, the terminal determines the target operator, which is conducive to the user flexibly selecting the target operator to be accessed, thereby improving the user experience.
[0049] Combining the first aspect and the second aspect, in some possible implementation manners, the user identifier is carried in the first signaling, and the first signaling further includes the type of the user identifier and / or the identifier of the distributed storage system, and the identifier of the distributed storage system is used to identify the distributed storage system where the file information corresponding to the user identifier is located.
[0050] In a third aspect, this application provides an access authentication method, which can be executed by an access authentication device. The access authentication device can be a storage network element, a component (such as a chip, a chip system, etc.) configured in the storage network element, or, alternatively, a logic module or software capable of implementing all or part of the functions of the storage network element. This application does not make any restrictions in this regard.
[0051] Exemplarily, the method includes: receiving a user identifier of a terminal from an authentication network element, where the authentication network element is a network element of the target operator to which the terminal is connected; determining, based on the user identifier, file information corresponding to the user identifier, where the file information includes a public key of the terminal and is used to authenticate the terminal; and sending the file information to the authentication network element.
[0052] It can be understood that when the authentication network element and the storage network element are the same network element, the authentication network element (or the storage network element) directly receives the user identifier from the terminal, and then determines the corresponding file information according to the user identifier, without sending the above file information.
[0053] In the above technical solution, the storage network element can store the user identifier of the user and the corresponding file information, so that the authentication network element can query the corresponding file information based on the user identifier, and then complete the authentication of the terminal based on the above file information. The authentication network element can be a network element of the target operator to which the terminal is connected. That is to say, even if the authentication network element is not a network element of the home operator, it can obtain the file information corresponding to the user identifier to complete the authentication of the terminal, without falling back to the home operator for authentication, which is beneficial to simplifying the authentication process. In addition, the above file information includes the public key of the terminal. Authenticating the terminal based on the public key of the terminal is more secure and flexible than using a symmetric key.
[0054] Combining the first aspect to the third aspect, in some possible implementation manners, the above user identifier includes a decentralized root credential (DRC), a decentralized identity credential (DIC), a decentralized self-control credential (DSCC), or a self-control identity credential (SCIC).
[0055] Among them, the DRC is pre-set in the card by the card merchant / terminal manufacturer at the time of factory. The DIC is multiple temporary / derived identities derived from the DRC. The DSCC is generated by the user himself for the user's control of the identity information, independent of the DRC or the DIC. The SCIC is a derivative based on the DSCC. Each DRC, DIC, DSCC, or SCIC corresponds to file information.
[0056] Combined with the first aspect to the third aspect, in some possible implementation manners, the above user identifier includes a pseudo identifier (pseudo ID), and there is a corresponding relationship between the pseudo identifier and the real identity identifier. The real identity identifier and the corresponding file information are stored in the storage network element.
[0057] That is to say, what the terminal sends is a pseudo identifier, which is beneficial to improving security.
[0058] Combined with the first aspect to the third aspect, in some possible implementation manners, the above user identifier includes a transaction address, and the transaction address is used to indicate the location of the file information corresponding to the user identifier on the distributed storage system.
[0059] Combined with the first aspect to the third aspect, in some possible implementation manners, the above storage network element is a node on the distributed storage system, and at least one user identifier and the file information corresponding to each user identifier are stored in the node.
[0060] It can be understood that the distributed storage system may include one or more nodes. At least one user identifier and the file information corresponding to each user identifier may be stored in each node, and the above storage network element may be any one of the above one or more nodes.
[0061] Optionally, the above distributed storage system is a blockchain, a decentralized shared file information storage system, or an Inter Planetary File System (IPFS).
[0062] Fourth aspect, the present application provides an access authentication method, which can be executed by an access authentication device. The access authentication device may be a verification network element, or a component (such as a chip, a chip system, etc.) configured in the verification network element, or may also be a logic module or software capable of implementing all or part of the functions of the verification network element. The present application does not make any limitation in this regard.
[0063] In the present application, the verification network element is a network element of the target operator to which the terminal accesses. For example, the verification network element may be a core network element of the target operator to which the terminal accesses. For example, the verification network element may be an AUSF network element, or an AMF network element, or other core network elements. Again, for example, the verification network element may also be an access network element of the target operator to which the terminal accesses, such as an access network node to which the terminal accesses. The present application does not make any limitation in this regard. The verification network element will not be elaborated below.
[0064] Exemplarily, the method includes: receiving a user identifier from the terminal and the file information corresponding to the user identifier, where the file information includes the public key of the terminal; and authenticating the terminal based on the above file information.
[0065] Among them, the user identifier can be used to identify the authenticated terminal (or the universal integrated circuit card in the terminal).
[0066] In the above technical solution, the verification network element can directly complete the authentication of the terminal based on the obtained user identifier of the terminal and the file information corresponding to the user identifier. The verification network element can be a network element of the target operator to which the terminal is connected. That is to say, even if the verification network element is not a network element of the home operator, it can complete the authentication of the terminal without falling back to the home operator for authentication, which is beneficial to simplifying the authentication process.
[0067] In some possible implementation manners of the fourth aspect, the above authentication of the terminal based on the file information includes: receiving a first message from the terminal and a digital signature of the terminal, where the digital signature of the terminal is obtained by signing a second message or a hash value of the second message based on the private key of the terminal. The second message is a message interacted between the above terminal and the above verification network element or the above first message; verifying the digital signature of the terminal based on the public key of the terminal.
[0068] Among them, the above second message may be one or more of all the messages interacted between the above terminal and the above verification network element, and this application does not limit this.
[0069] The verification network element can verify the digital signature of the terminal based on the public key of the terminal in the file information, where the digital signature of the terminal is obtained by signing a second message or a hash value of the second message based on the private key of the terminal. If the verification network element passes the verification of the digital signature of the terminal, it is considered that the verification network element passes the authentication of the terminal. Correspondingly, if the verification network element fails to verify the digital signature of the terminal, it is considered that the verification network element fails the authentication of the terminal.
[0070] In some possible implementation manners of the fourth aspect, the above method further includes: sending a third message and a digital signature of the verification network element to the terminal, where the digital signature of the verification network element is obtained by signing a fourth message or a hash value of the fourth message based on the private key of the verification network element. The fourth message is a message interacted between the terminal and the verification network element or the above third message.
[0071] Among them, the fourth message may be one or more of all the messages interacted between the above terminal and the above verification network element. It can be understood that since the verification network element receives the second message and sends the third message at different times, the messages interacted between the terminal and the verification network element will also change. Therefore, the second message and the fourth message may be different.
[0072] In addition, the authentication network element may receive the first message and the digital signature of the terminal before sending the third message and the digital signature of the authentication network element, or may receive the first message and the digital signature of the terminal after sending the third message and the digital signature of the authentication network element. This application does not make any limitation in this regard. For example, the authentication network element may receive the first message and the digital signature of the terminal, and based on the public key of the terminal, verify the digital signature of the terminal. If the verification is passed, the authentication network element sends the third message and its own digital signature to the terminal.
[0073] In some possible implementations of the fourth aspect, the above method further includes: sending the certificate of the above authentication network element to the terminal.
[0074] Among them, the certificate of the above authentication network element may include, for example, the public key of the authentication network element, the issuer, the validity period, the signature of the issuer, the version number, the identifier of the authentication network element, the method for querying the certificate status (such as: revocation list information, OCSP, etc.). When the certificate of the above authentication network element is not pre-configured in the terminal, the terminal may pre-configure the certificate of the target operator, where the certificate of the target operator includes the public key of the operator. The terminal may verify the certificate of the authentication network element based on the certificate of the target operator, and then verify the digital signature of the authentication network element based on the public key of the authentication network element. The certificate of the authentication network element is issued by the operator, that is to say, the signature of the authentication network element certificate is generated using the private key of the operator. The terminal may use the public key in the operator certificate to verify the signature of the authentication network element certificate; and use the public key of the authentication network element certificate to verify the digital signature of the authentication network element. If the above processes are all verified successfully, it is considered that the terminal's authentication of the authentication network element is successful.
[0075] Optionally, the certificate of the authentication network element and the digital signature of the authentication network element may be carried in the same signaling, or may be carried in different signaling. This application does not make any limitation in this regard.
[0076] In some possible implementations of the fourth aspect, the above method further includes: obtaining the hash value of the file information corresponding to the user identifier from the storage network element based on the above user identifier; verifying the above file information based on the above hash value.
[0077] In a fifth aspect, this application provides an access authentication method, which may be executed by an access authentication device. The access authentication device may be a terminal, or a component (such as a chip, a chip system, etc.) configured in the terminal, or may also be a logical module or software capable of implementing all or part of the terminal functions. This application does not make any limitation in this regard.
[0078] Exemplarily, the method includes: obtaining a user identifier of a terminal and file information corresponding to the user identifier, where the file information includes a public key of the terminal; sending the user identifier and the file information corresponding to the user identifier to a verification network element, where the verification network element is a network element of a target operator to which the terminal is connected, and the file information is used to authenticate the terminal.
[0079] In the above technical solution, the terminal can send the user identifier and the file information corresponding to the user identifier to the verification network element, so that the verification network element can complete the authentication of the terminal according to the above file information, and the verification network element can be a network element of the target operator to which the terminal is connected. That is to say, even if the verification network element is not a network element of the home operator, it can obtain the file information corresponding to the user identifier to complete the authentication of the terminal, without having to fall back to the home operator for authentication, which is beneficial to simplifying the authentication process.
[0080] In some possible implementation manners of the fifth aspect, the above method further includes: receiving a third message from the verification network element and a digital signature of the verification network element, where the digital signature of the verification network element is obtained by signing a fourth message or a hash value of the fourth message based on a private key of the verification network element, where the fourth message is a message exchanged between the terminal and the verification network element or the above third message; verifying the digital signature of the verification network element based on the public key of the verification network element.
[0081] Among them, the fourth message may be one or more of all the messages exchanged between the above terminal and the above verification network element. The public key of the verification network element can be preset in the terminal, and the digital signature of the verification network element is verified based on the public key of the verification network element. If the terminal passes the verification of the digital signature of the verification network element, it is considered that the terminal has passed the authentication of the verification network element. By using the method of public key signature verification for authentication, the authentication process is relatively simple.
[0082] In some possible implementation manners of the fifth aspect, the above method further includes: sending a first message and a digital signature of the terminal to the verification network element, where the digital signature of the terminal is obtained by signing a second message or a hash value of the second message based on a private key of the terminal, where the second message is a message exchanged between the terminal and the verification network element or the above first message.
[0083] Among them, the above second message may be one or more of all the messages exchanged between the above terminal and the above verification network element, and this application does not make a limitation on this.
[0084] It can be understood that since the time when the verification network element receives the second message and sends the third message is different, the messages exchanged between the terminal and the verification network element will also change. Therefore, the second message and the fourth message may be different.
[0085] The terminal can send the digital signature of the terminal to the authentication network element, so that the authentication network element can verify the digital signature based on the public key of the terminal, and then complete the authentication of the terminal. By using the method of verifying the signature with the public key, the authentication process is relatively simple.
[0086] In addition, the terminal can receive the third message and the digital signature of the authentication network element before sending the first message and the digital signature of the terminal to the authentication network element, or can receive the third message and the digital signature of the authentication network element after sending the first message and the digital signature of the terminal to the authentication network element. This application does not make a limitation in this regard. For example, the terminal can receive the third message and the digital signature of the authentication network element, and verify the digital signature of the authentication network element based on the public key of the authentication network element. In the case of successful verification, the terminal sends the first message and the digital signature of the terminal to the authentication network element.
[0087] In some possible implementation manners of the fifth aspect, the above method further includes: receiving the certificate of the authentication network element.
[0088] In some possible implementation manners of the fifth aspect, before obtaining the user identifier and the file information corresponding to the user identifier, the above method further includes: determining a target operator from multiple operators.
[0089] The terminal can determine a target operator from multiple operators. The multiple operators can be operators that have signed a contract with the user, or can be operators that have not signed a contract with the user. This application does not make a limitation in this regard. That is to say, each operator has the opportunity to be selected, which is beneficial to improving the fairness of competition among operators.
[0090] In some possible implementation manners of the fifth aspect, the above determining a target operator from multiple operators includes: determining a target operator from multiple operators according to one or more of the location of the user, the service quality (such as signal strength) of each operator among the multiple operators, the fees of each operator among the multiple operators, or the security of each operator among the multiple operators.
[0091] For example, the terminal can select the operator with the strongest signal strength, the lowest fees, and the highest security in the location of the user among the multiple operators as the target operator, so as to provide better services for the user, which is beneficial to improving the user experience.
[0092] In some possible implementation manners of the fifth aspect, the above determining a target operator from multiple operators includes: determining a target operator from multiple operators in response to a user operation, where the user operation is an operation in which the user selects a target operator from the multiple operators.
[0093] The terminal can display multiple operators available for the user to select through the user interface. In response to the user's operation of selecting a target operator from the multiple operators, the terminal determines the target operator, which is beneficial for the user to flexibly select the target operator to be accessed, thereby improving the user experience.
[0094] Combining the fourth aspect and the fifth aspect, in some possible implementation manners, the above user identifier is carried in the first signaling, and the first signaling further includes the type of the user identifier and / or the identifier of the distributed storage system, and the identifier of the distributed storage system is used to identify the distributed storage system where the file information corresponding to the user identifier is located.
[0095] In a sixth aspect, the present application provides an access authentication method, which can be executed by an access authentication device. The access authentication device can be a storage network element, or a component (such as a chip, a chip system, etc.) configured in the storage network element, or can also be a logical module or software capable of implementing all or part of the functions of the storage network element. The present application does not make any limitation in this regard.
[0096] Exemplarily, the method includes: receiving the user identifier of the terminal from a verification network element, where the verification network element is a network element of the target operator to which the terminal accesses; determining the hash value of the file information corresponding to the user identifier based on the above user identifier, where the file information includes the public key of the terminal; and sending the hash value of the file information to the verification network element.
[0097] It can be understood that when the verification network element and the storage network element are the same network element, the verification network element (or the storage network element) directly receives the user identifier from the terminal, and then determines the hash value of the corresponding file information according to the user identifier, without sending / receiving the hash value of the above file information.
[0098] In the above technical solution, the storage network element can store the user identifier of the user and the hash value of the corresponding file information, so as to facilitate the verification network element to query the hash value of the corresponding file information based on the user identifier, and then verify the file information obtained from the terminal, which is beneficial to improving the accuracy of the file information.
[0099] Combining the fourth aspect to the sixth aspect, in some possible implementation manners, the above user identifier includes DRC, DIC, DSCC or SCIC.
[0100] Combining the fourth aspect to the sixth aspect, in some possible implementation manners, the above user identifier includes a false identity identifier, and there is a corresponding relationship between the false identity identifier and the real identity identifier, and the real identity identifier and the hash value of the corresponding file information are stored in the storage network element.
[0101] That is to say, the terminal sends a false identity identifier, which is beneficial to improving security.
[0102] Combined with the fourth to sixth aspects, in some possible implementation manners, the above user identifier includes a transaction address, and the transaction address is used to indicate the position of the hash value of the file information corresponding to the user identifier on the distributed storage system.
[0103] Combined with the fourth to sixth aspects, in some possible implementation manners, the above storage network element is a node on the distributed storage system, and at least one user identifier and the hash value of the file information corresponding to each user identifier are stored in the node.
[0104] Optionally, the above distributed storage system is a blockchain, a decentralized shared file information storage system, or an InterPlanetary File System.
[0105] In a seventh aspect, the present application provides an access authentication device, which can implement the methods described in the first to sixth aspects and any possible implementation manner of the first to sixth aspects. The device includes corresponding modules for executing the above methods. The modules included in the device can be implemented by software and / or hardware.
[0106] In an eighth aspect, the present application provides an access authentication device, which includes a processor, and the processor can be used to execute a computer program in a memory to implement the methods described in the first to sixth aspects and any possible implementation manner of the first to sixth aspects.
[0107] Optionally, the device further includes a communication interface, and the processor is coupled to the communication interface. The communication interface is used to receive signals from other communication devices outside the device and transmit them to the processor, or send signals from the processor to other communication devices outside the device. Exemplarily, the communication interface can be a transceiver, a circuit, a bus, a module, a pin, or other types of communication interfaces.
[0108] Optionally, the device further includes a memory, and the processor is coupled to the memory. The memory is used to store program instructions and data. The memory is coupled to the processor, and when the processor executes the instructions stored in the memory, the methods described in the above aspects can be implemented.
[0109] In a ninth aspect, the present application provides an access authentication device, including a processor and a communication interface. The communication interface is configured to receive signals from other communication devices outside the communication device and transmit them to the processor, or send signals from the processor to other communication devices outside the communication device. The processor, through logic circuits or by executing code instructions, implements the methods described in the first aspect to the sixth aspect and any possible implementation manner of the first aspect to the sixth aspect. Exemplarily, the communication interface may be a transceiver, a circuit, a bus, a module, a pin, or other types of communication interfaces.
[0110] Optionally, the device further includes a memory for storing instructions and / or data. The memory may be coupled to the processor. When the processor executes the instructions stored in the memory, the methods described in the first aspect to the sixth aspect and any possible implementation manner of the first aspect to the sixth aspect are implemented.
[0111] In a tenth aspect, the present application provides an access authentication device, including a processor and a memory. The memory is used for storing instructions and data. When the processor executes the instructions stored in the memory, the methods described in the first aspect to the sixth aspect and any possible implementation manner of the first aspect to the sixth aspect can be implemented.
[0112] Optionally, the device further includes a communication interface for the device to communicate with other communication devices. Exemplarily, the communication interface may be a transceiver, a circuit, a bus, a module, a pin, or other types of communication interfaces.
[0113] In an eleventh aspect, the present application provides a computer-readable storage medium storing a computer program or instructions. When the computer program or instructions are executed, the methods described in the first aspect to the sixth aspect and any possible implementation manner of the first aspect to the sixth aspect are implemented.
[0114] In a twelfth aspect, the present application provides a computer program product including instructions. When the instructions are run, the methods described in the first aspect to the sixth aspect and any possible implementation manner of the first aspect to the sixth aspect are implemented.
[0115] In a thirteenth aspect, the present application provides a chip system including at least one processor for supporting the implementation of the functions involved in the first aspect to the sixth aspect and any possible implementation manner of the first aspect to the sixth aspect. For example, receiving or processing the data involved in the above methods, etc.
[0116] In a possible design, the chip system further includes a memory for storing program instructions and data, and the memory is located inside or outside the processor.
[0117] The chip system may be composed of chips or may include chips and other discrete devices.
[0118] In a fourteenth aspect, the present application provides a communication system, which includes an authentication network element and a storage network element. The authentication network element is used to implement the method described in the first aspect and any possible implementation manner of the first aspect, and the storage network element is used to implement the method described in the third aspect and any possible implementation manner of the third aspect.
[0119] Optionally, the above communication system further includes a terminal, which is used to implement the method described in the second aspect and any possible implementation manner of the second aspect.
[0120] In a fifteenth aspect, the present application provides a communication system, which includes an authentication network element and a storage network element. The authentication network element is used to implement the method described in the fourth aspect and any possible implementation manner of the fourth aspect, and the storage network element is used to implement the method described in the sixth aspect and any possible implementation manner of the sixth aspect.
[0121] Optionally, the above communication system further includes a terminal, which is used to implement the method described in the fifth aspect and any possible implementation manner of the fifth aspect.
[0122] It should be understood that the technical solutions of the fourth aspect to the fifteenth aspect of the present application correspond to those of the first aspect to the third aspect of the present application, and the beneficial effects obtained by each aspect and the corresponding feasible implementation manners are similar and will not be elaborated here. Description of the Drawings
[0123] Figure 1 is a schematic diagram of a possible access authentication process;
[0124] Figure 2A is a schematic diagram of the architecture of a communication system applicable to the access authentication method provided by the present application;
[0125] Figure 2B is a schematic diagram of the blockchain provided by the embodiments of the present application;
[0126] Figure 3 is a schematic flowchart of the access authentication method provided by the embodiments of the present application;
[0127] Figure 4 is a schematic diagram of the subscription methods of multiple operators provided by the embodiments of the present application;
[0128] Figure 5It is a schematic diagram of the format of the first signaling provided by an embodiment of the present application;
[0129] Figure 6 It is a schematic diagram of the access authentication process provided by an embodiment of the present application;
[0130] Figure 7 It is another schematic diagram of the access authentication process provided by an embodiment of the present application;
[0131] Figure 8 It is yet another schematic diagram of the access authentication process provided by an embodiment of the present application;
[0132] Figure 9 It is a schematic flowchart of another access authentication method provided by an embodiment of the present application;
[0133] Figure 10 It is yet another schematic diagram of the access authentication process provided by an embodiment of the present application;
[0134] Figure 11 It is a schematic block diagram of the access authentication device provided by an embodiment of the present application;
[0135] Figure 12 It is another schematic block diagram of the access authentication device provided by an embodiment of the present application. Detailed implementation manners
[0136] Next, the technical solutions in the present application will be described in conjunction with the accompanying drawings.
[0137] Before introducing the method provided by the embodiment of the present application, the following points are explained first.
[0138] First, in the present application, indication includes explicit indication (also known as direct indication) and implicit indication (also known as indirect indication). Among them, explicitly indicating information A means including the information A; implicitly indicating information A means indicating information A through the correspondence between information A and information B and directly indicating information B. The correspondence between information A and information B can be predefined, pre-stored, pre-burned, or pre-configured; or, it can also mean indicating information A through information B and a preset rule.
[0139] Second, in the present application, information C is used for the determination of information D, which includes both the case where information D is determined only based on information C and the case where it is determined based on information C and other information. In addition, the situation where information C is used for the determination of information D can also be an indirect determination. For example, information D is determined based on information E, and information E is determined based on information C.
[0140] Third, in this application, "at least one" means one or more, and "a plurality" means two or more. "And / or" describes the association relationship between associated objects and indicates that there can be three relationships. For example, A and / or B can represent: A exists alone, A and B exist simultaneously, and B exists alone, where A and B can be singular or plural. The character " / " generally indicates that the associated objects before and after are in an "or" relationship, but it does not exclude the case where the associated objects before and after are in a "and" relationship. The specific meaning can be understood in combination with the context. "At least one (item)" or its similar expressions refer to any combination of these items, including any combination of single item or plural items. For example, at least one (item) of a, b, or c can represent: a, b, c; a and b; a and c; b and c; or a, b, and c. Where a, b, and c can be single or multiple.
[0141] Fourth, in this application, the use of prefix words such as "first" and "second" is only for the convenience of distinguishing and describing different things belonging to the same name category, and does not restrict the order, size, or quantity of things. For example, "the first message" and "the second message" can be different messages or the same message, and this application does not make any restrictions on this.
[0142] Fifth, "send" and "receive" in this application represent the direction of signal transmission. For example, "sending information to the authentication network element" can be understood as the destination of this information being the authentication network element, which can include directly sending through the air interface and also include indirectly sending through the air interface by other units or modules. "Receiving information from the terminal" can be understood as the source of this information being the terminal, which can include directly receiving from the terminal through the air interface and also include indirectly receiving from the terminal through the air interface by other units or modules. "Send" can also be understood as the "output" of the chip interface, and "receive" can also be understood as the "input" of the chip interface.
[0143] In other words, sending and receiving can be carried out between devices. For example, between the terminal and the authentication network element; it can also be carried out within a device. For example, sending or receiving between components, modules, chips, software modules, or hardware modules within a device through a bus, trace, or interface.
[0144] Sixth, in this application, "when...", "if", and "in case" all refer to the device making corresponding processing under certain objective circumstances, not limiting time, and do not require the device to have a judgment action when implemented, nor does it mean there are other limitations.
[0145] Seventh, in this application, words such as "example", "exemplarily", "for example", or "such as" are used to give examples, illustrations, or explanations. Any embodiment or design described as an "example", "exemplarily", "for example", or "such as" in this application should not be construed as being more preferred or having more advantages than other embodiments or design solutions. Rather, the use of words such as "example", "exemplarily", "for example", or "such as" is intended to present the relevant concepts in a specific manner.
[0146] Currently, the user (or the user card) needs to be bound to the operator, and it is impossible to achieve a one-card for multiple operators. That is to say, each operator independently manages its own user information, and even for the same type of operators in different regions, they independently manage their own user information. Operators need to maintain a large amount of user information, and there is a risk of leakage caused by a single-point attack. In addition, the access authentication of the network is generally controlled by the home operator, where the home operator refers to the operator where the user signs the contract.
[0147] If a certain terminal is located in a region outside the home location, then the terminal needs the home operator to perform access authentication on it when accessing the network. Exemplarily, a user signs a contract with a mobile operator in region A, but the user is located in region B, so the user accesses the mobile operator in region B. The specific access authentication process includes: when the terminal accesses the network, it needs to send the user identifier to the serving network (the network in region B), and the serving network sends the user identifier to the home network, and the home network completes the access authentication of the terminal. The following will be combined with Figure 1 to describe the existing access authentication process in detail.
[0148] Figure 1 is a schematic diagram of a possible access authentication process. Figure 1 a) in Figure 1 shows the registration stage,
[0149] In step 101, the terminal encrypts the subscription permanent identifier (SUPI) through the elliptic curve integrate encrypt scheme (ECIES) to obtain the subscription concealed identifier (SUCI).
[0150] The terminal encrypts the SUPI through the ECIES, which solves the problem of potential security risks in transmitting in plaintext and improves the security.
[0151] In step 102, the terminal sends the SUCI and the home network (HN) identifier to the serving network (SN). Correspondingly, the serving network receives the SUCI and the home network identifier from the terminal.
[0152] Among them, the serving network refers to the network accessed by the terminal, and the home network refers to the network where the user subscribes. For example, if the user subscribes with a mobile operator in Beijing, then the mobile operator in Beijing is the home network. After the user arrives in Guangzhou and accesses the mobile operator in Guangzhou, then the mobile operator in Guangzhou is the serving network.
[0153] The home network identifier is used to identify the home network. After the terminal encrypts the SUPI to obtain the SUCI, it sends the SUCI and the home network identifier to the serving network. The serving network can determine the corresponding home network based on the home network identifier.
[0154] In step 103, the serving network sends the above-mentioned SUCI, home network identifier, and serving network identifier to the home network. Correspondingly, the home network receives the SUCI, home network identifier, and serving network identifier from the serving network.
[0155] In step 104, the home network decrypts the SUCI through ECIES to obtain the SUPI.
[0156] After receiving the SUCI, the home network decrypts it through ECIES to obtain the SUPI. Since the information required for terminal authentication is stored in the home network, the home network can determine the information required for authentication, such as the authentication credentials used, based on the above-mentioned SUPI.
[0157] It can be understood that Figure 1 The authentication process shown in b) in
[0158] is illustrated by taking the authentication and key agreement (AKA) protocol as an example. For the authentication based on AKA, the specific principle is as follows: The home network and the terminal hold the same key, which corresponds to the SUPI. During the authentication process, both parties calculate based on the challenge value and the key. If the calculation results are the same, it proves that they hold the same key and the authentication passes. Figure 1 The process of authenticating the terminal through AKA will be explained in detail below in combination with b) in
[0159] In step 105, the home network generates an authentication quadruple.
[0160] The above authentication quadruple is (random number (RAND), authentication token (AUTN), hash of the expected response value (HXRES), key of the security anchor function (KSEAF)). The specific calculation process can refer to known technologies and will not be elaborated here.
[0161] Among them, RAND is a 128-bit random number. AUTN is an authentication token, which includes the exclusive OR value of AK and the home network sequence number (SQNHN) (denoted as C) and the message authentication code (MAC) value. HXRES is the hash value of RAND and the expected response value (XRES). KSEAF is the anchor key established with the serving network.
[0162] In step 106, the home network sends the above authentication quadruple (RAND, AUTN, HXRES, KSEAF) to the serving network. Correspondingly, the serving network receives the above authentication quadruple (RAND, AUTN, HXRES, KSEAF).
[0163] In step 107, the serving network sends (RAND, AUTN) to the terminal. Correspondingly, the terminal receives (RAND, AUTN).
[0164] After receiving the authentication quadruple, the serving network sends (RAND, AUTN) in the authentication quadruple to the terminal.
[0165] In step 108, the terminal calculates the MAC value based on (RAND, AUTN).
[0166] Exemplarily, the terminal splits AUTN into C and MAC, calculates AK through the shared key k and RAND (here the role of AK is to hide the sequence number (SQN) in the message), then performs an exclusive OR operation with C to obtain SQNHN, and finally calculates the MAC value based on this SQNHN and compares it with the received MAC value. Among them, the sequence number on the home network side is used when calculating the MAC value, rather than the sequence number on the terminal side.
[0167] If the MAC values are the same and the serial number on the terminal side is less than the serial number on the home network side, the authentication of the HN is passed, and the terminal executes steps 109 to 113; if the MAC values are the same, but the serial number on the terminal side is greater than the serial number on the home network side, the terminal executes step 114; if the MAC values are different, the authentication fails, and the terminal executes step 115.
[0168] The terminal will think that there is a problem of serial number out-of-sync and will perform re-synchronization. On the terminal side, this is also a main reason for introducing link attacks;
[0169] In step 109, the terminal generates a response value (response, RES) and KSEAF.
[0170] In step 110, the terminal sends RES to the serving network. Correspondingly, the serving network receives the above RES.
[0171] In step 111, the serving network hashes RES to obtain the hash of the response value (hash response, HRES), and compares it with the hash value sent by the home network.
[0172] If they are the same, step 112 is executed; if they are different, the authentication fails.
[0173] In step 112, the serving network sends HRES to the home network. Correspondingly, the home network receives the above HRES.
[0174] In step 113, the home network compares HRES with HXRES.
[0175] If they are the same, the home network returns SUPI to the serving network and completes the authentication of the terminal. If they are different, the authentication of the terminal fails.
[0176] In step 114, the terminal sends a data packet to the home network through the serving network. The data packet includes a message indicating synchronization failure.
[0177] In step 115, the terminal sends a MAC failure message to the serving network. Correspondingly, the serving network receives the above MAC failure message.
[0178] By Figure 1It can be seen that during the authentication process, since the home network stores the information required for authentication while the serving network does not have the above information, the serving network cannot perform access authentication on the terminal. Instead, the home network needs to complete the authentication, making the entire authentication process relatively complex. On the other hand, the operator needs to maintain a large amount of user information, which poses a risk of leakage due to a single-point attack and has low security. Additionally, the home network and the terminal authenticate based on a symmetric key. If either party is attacked, the key will be leaked, resulting in low security. For example, if the home network side is attacked, the key will be leaked, leading to low security.
[0179] To solve the above problems, the present application provides an access authentication method. The network element of the target operator to which the terminal is currently accessing (denoted as the verification network element) can obtain the file information corresponding to the user identifier from the storage network element according to the user identifier from the terminal, so as to complete the authentication of the terminal based on the above file information. That is to say, even if the verification network element is not a network element of the home operator, it can obtain the file information corresponding to the user identifier to complete the authentication of the terminal, without having to fall back to the home operator for authentication, which is beneficial to simplifying the authentication process. The above file information includes the public key of the terminal. Authenticating the terminal based on the public key of the terminal is more secure and flexible than using a symmetric key.
[0180] The access authentication method provided by the embodiments of the present application can be applied to the fourth-generation (4G) communication system, such as the long term evolution (LTE) communication system, and can also be applied to the fifth-generation (5G) communication system, such as the 5G new radio (NR) communication system, or to various communication systems evolved after 5G, such as the sixth-generation (6G) communication system. The method provided by the embodiments of the present application can also be applied to a Bluetooth system, a wireless fidelity (Wi-Fi) system, a long range (LoRa) system, or a vehicle-to-everything (V2X) system. The method provided by the embodiments of the present application can also be applied to a satellite communication system, where the satellite communication system can be integrated with the above communication systems.
[0181] For the convenience of understanding the embodiments of the present application, Figure 2A the application scenario applicable to the present application will be described by taking the Figure 2A shown communication system architecture as an example. Figure 2AAs shown, the communication system 1000 includes a radio access network (RAN) 100 and a core network (CN) 200. The RAN 100 includes at least one network device (such as 110a and 110b in Figure 2A , collectively referred to as 110) and at least one terminal (such as 120a - 120j in Figure 2A , collectively referred to as 120). Other RAN nodes may also be included in the RAN 100, for example, wireless relay devices and / or wireless backhaul devices ( Figure 2A not shown in the figure), etc. The terminal 120 is connected to the network device 110 wirelessly. The network device 110 is connected to the core network 200 wirelessly or by wire. The core network devices in the core network 200 and the network devices 110 in the RAN 100 may be different physical devices respectively, or may be the same physical device integrating the core network logic function and the radio access network logic function.
[0182] The RAN 100 may be a cellular system related to the 3rd generation partnership project (3GPP), for example, a 4G or 5G mobile communication system, or an evolved system after 5G (such as a 6G mobile communication system). The RAN 100 may also be an open RAN (O-RAN or ORAN), a cloud radio access network (CRAN), or a Wi-Fi system. The RAN 100 may also be a communication system integrating two or more of the above systems.
[0183] In this application, the terminal may be, for example, the terminal 120 in Figure 2A ; the authentication network element may be, for example, the network element in the core network 200 shown in Figure 2A , or may also be the network device 110 shown in Figure 2A ; the storage network element may be, for example, the network element in the core network 200 shown in Figure 2A , or may also be the network device 110 shown in Figure 2A . This application does not limit the specific types of the terminal, the authentication network element, and the storage network element. It can be understood that Figure 2A only shows a possible communication system architecture to which the embodiments of this application can be applied. In other possible scenarios, other devices may also be included in the communication system architecture.
[0184] The network device 110 is a node in a radio access network (RAN), also known as an access network device or a RAN node (or device). The network device 110 is used to assist the terminal in achieving wireless access. Multiple network devices 110 in the communication system 1000 can be of the same type of node or different types of nodes. In some scenarios, the roles of the network device 110 and the terminal 120 are relative. For example, Figure 2A the network element 120i can be a helicopter or a drone, which can be configured as a mobile base station. For the terminal 120j accessing the RAN 100 through the network element 120i, the network element 120i is a base station; but for the base station 110a, the network element 120i is a terminal. The network device 110 and the terminal 120 are sometimes both referred to as communication devices. For example, Figure 2A the network elements 110a and 110b in the figure can be understood as communication devices with base station functions, and the network elements 120a - 120j can be understood as communication devices with terminal functions.
[0185] In a possible scenario, the network device can be a base station, an evolved NodeB (eNodeB), a transmitting and receiving point (TRP), a transmitting point (TP), a next generation NodeB (gNB), a next generation base station in a 6G mobile communication system, a base station in a future mobile communication system, a satellite, or an access point (AP) in a Wi-Fi system, an integrated access and backhaul (IAB) node, a network device in a mobile switching center non-terrestrial network (NTN) communication system, that is, it can be deployed on a high-altitude platform or a satellite, etc. The network device can be a macro base station (such as Figure 2A 110a in the figure), a micro base station or an indoor station (such as Figure 2A 110b in the figure), a relay node or a donor node, or a radio controller in a CRAN scenario. The network device can also be a device serving as a base station function in device-to-device (D2D) communication, vehicle-to-everything (V2X) communication, drone communication, or machine communication. Optionally, the network device can also be a server, a wearable device, a vehicle or an in-vehicle device, etc. For example, the access network device in vehicle-to-everything (V2X) technology can be a road side unit (RSU).
[0186] In another possible scenario, multiple network devices cooperate to assist a terminal in achieving wireless access, and different network devices respectively implement some functions of a base station. For example, the network device can be a central unit (CU), a distributed unit (DU), a CU-control plane (CP), a CU-user plane (UP), or a radio unit (RU), etc. The CU and the DU can be set separately, or can also be included in the same network element, such as a baseband unit (BBU). The RU can be included in a radio frequency device or a radio frequency unit, such as included in a remote radio unit (RRU), an active antenna unit (AAU), or a remote radio head (RRH). It can be understood that the network device can be a CU node, or a DU node, or a device including a CU node and a DU node. In addition, the CU can be classified as a network device in the radio access network (RAN), or the CU can be classified as a network device in the core network (CN), which is not limited here.
[0187] In different systems, the CU (or CU-CP and CU-UP), DU, or RU may also have different names, but those skilled in the art can understand their meanings. For example, in the ORAN system, the CU can also be called an O-CU (open CU), the DU can also be called an O-DU, the CU-CP can also be called an O-CU-CP, the CU-UP can also be called an O-CU-UP, and the RU can also be called an O-RU. For the convenience of description, in this application, the CU, CU-CP, CU-UP, DU, and RU are used as examples for description. Any one of the CU (or CU-CP, CU-UP), DU, and RU in this application can be implemented by a software module, a hardware module, or a combination of a software module and a hardware module.
[0188] In the embodiments of this application, the form of the network device is not limited. The device for implementing the functions of the network device can be the network device; it can also be a device capable of supporting the network device to implement this function, such as a chip system. This device can be installed in the network device or used in combination with the network device.
[0189] A terminal can also be referred to as a terminal device, user equipment (UE), mobile station (MS), mobile terminal (MT), etc., or a device used to provide voice or data connectivity to users, and can also be an Internet of Things device. For example, terminal devices include handheld devices with wireless connection capabilities, vehicle-mounted devices, etc. Currently, terminals can be, for example: mobile phones, tablet computers, laptop computers, palmtop computers, mobile Internet devices (MID), wearable devices (such as smart watches, smart bracelets, pedometers, smart glasses, etc.), vehicle-mounted devices (such as cars, bicycles, electric vehicles, airplanes, ships, trains, high-speed trains, etc.), satellite terminals, virtual reality (VR) devices, augmented reality (AR) devices, intelligent point of sale (POS) machines, customer-premises equipment (CPE), wireless terminals in industrial control, smart home devices (such as refrigerators, TVs, air conditioners, electricity meters, etc.), intelligent robots, robotic arms, workshop equipment, wireless terminals in unmanned driving, wireless terminals in intelligent healthcare, wireless terminals in smart grid, wireless terminals in transportation safety, wireless terminals in smart cities, or wireless terminals in smart homes, flying devices (such as intelligent robots, hot air balloons, drones, airplanes), etc. The terminal device can also be a vehicle device, such as a vehicle device, in-vehicle module, in-vehicle chip, on-board unit (OBU), or telematics box (T-BOX), etc. The terminal device can also be other devices with terminal functions. For example, the terminal device can also be a device that serves as a terminal function in D2D communication.
[0190] The embodiments of the present application do not limit the device form of the terminal. The device for implementing the functions of the terminal can be the terminal; it can also be a device capable of supporting the terminal to implement this function, such as a chip system. This device can be installed in the terminal or used in matching with the terminal. In the embodiments of the present application, the chip system can be composed of chips or can also include chips and other discrete devices.
[0191] Before describing in detail the access authentication method provided by the present application, first, the blockchain is Figure 2B explained in detail below.
[0192] Figure 2BIt is a schematic diagram of the blockchain provided by an embodiment of the present application. It should be understood that in the present application, the blockchain is an example of a distributed storage system, and should not impose any limitations on the present application. For example, nodes on other types of distributed storage systems can also store user identities and corresponding file information.
[0193] As Figure 2B shown, multiple parties such as card merchants (such as universal integrated circuit cards (UICCs), which can be referred to as blockchain-UICCs (B-UICCs) in the present application), terminal manufacturers, operators, social authoritative institutions, and third-party institutions jointly construct (or maintain) the blockchain and publish their respective identities and the file information corresponding to the identities on the blockchain. In other words, the various nodes in at least one node on the blockchain can share identities and the corresponding file information. Therefore, in the present application, when a certain terminal accesses the network in a different location (non-home location), it can be authenticated by the accessed network, without the need to return to the home network for authentication. Additionally, in Figure 2B it, the over-the-air card writing server can be used to write the relevant information of the user's contract with the operator into the file information. The over-the-air card writing server can be jointly deployed with the operator or the card merchant.
[0194] It should be noted that in the present application, the identity can specifically be a self-control identity (scID), and several types of scID will be introduced in detail below.
[0195] For an institution (such as a card merchant, terminal device manufacturer, operator, social authoritative institution, or third-party institution), the scID includes a decentralized root credential (DRC) or a decentralized identity credential (DIC). Among them, the DRC is the trust root of the institution, and the DIC is derived based on the DRC. For example, China Mobile is the DRC, and Beijing Mobile is the DIC 1, and Shanghai Mobile is the DIC 2. Each DRC or DIC corresponds to a file information (profile). The authentication credential in the DIC file is signed and endorsed by the private key corresponding to the DRC, and the file information includes the service information that can be provided.
[0196] For a user (such as a terminal or B-UICC), the scID may include a DRC, a DIC, decentralized self-control credentials (DSCC), or self-control identity credentials (SCIC). Among them, the DRC is pre-set in the card by the card merchant / terminal device manufacturer at the time of factory shipment. The credential information (or authentication credential) in the file information corresponding to the DRC is endorsed by the card merchant / terminal manufacturer. For example, it is signed by the private key of the card merchant / terminal manufacturer. The DIC is one or more temporary / derived identities derived from the DRC. The credential information in the file information corresponding to the DIC can be endorsed by the DRC, such as being signed by the private key of the DRC, or can be endorsed by the operator, such as being signed by the private key of the operator. The DSCC is generated by the user himself / herself for the user's control of identity information, independent of the DRC or DIC. The credential information in the file information corresponding to the DSCC is self-signed by the terminal / card, or can be endorsed by the subscribing operator after subscription, such as being signed by the private key of the operator. The SCIC is a derivative based on the DSCC. The credential information in the file information corresponding to the SCIC can be endorsed by the DSCC, such as being signed by the private key of the DSCC, or can be endorsed by the operator, that is, being signed by the private key of the operator. Each DRC, DIC, DSCC, or SCIC corresponds to file information, and the file information includes information required for authenticating the terminal. For example, the file information includes, but is not limited to, information such as the public key of the terminal, the subscribing party, and the validity period. The file information may also include at least one authentication credential available for authenticating the terminal and / or the algorithm corresponding to each authentication credential. From Figure 2B It can be seen that the verification network element can obtain the information required for authenticating the terminal from the blockchain.
[0197] Next, the access authentication method provided by this application will be described in detail with reference to the accompanying drawings.
[0198] Figure 3 It is a schematic flowchart of the access authentication method 300 provided by an embodiment of this application. Figure 3 This method is only described from the perspective of the interaction among the terminal, the verification network element, and the storage network element, and should not constitute any limitation to this application. Figure 3The terminal in [description] can be replaced by components configured in the terminal (such as chips, chip systems, processors, etc.), or logical modules or software that can implement all or part of the functions of the terminal; the verification network element can be replaced by components configured in the verification network element (such as chips, chip systems, processors, etc.), or logical modules or software that can implement all or part of the functions of the verification network element; the storage network element can be replaced by components configured in the storage network element (such as chips, chip systems, processors, etc.), or logical modules or software that can implement all or part of the functions of the storage network element.
[0199] Figure 3 The method 300 shown includes steps 310 to 340. Each step in method 300 will be described in detail below.
[0200] In step 310, the terminal obtains a user identifier.
[0201] Among them, the user identifier is used to identify the terminal, or rather, the user identifier is used to identify the UICC in the terminal. The UICC can be a physical card, an embedded card embedded in hardware, or a software card, etc., and this application does not make any limitations in this regard. The above user identifier corresponds to the file information in the storage network element.
[0202] In this application, the terminal may include one or more user identifiers, and each user identifier corresponds to a file information, and the file information includes the credential information required for authenticating the terminal. For example, the file information includes the public key of the terminal, the validity period of the authentication credential, the issuer of the authentication credential, etc. Among them, the authentication credential can be a certificate, for example (this application does not limit the format standard of the certificate, such as a certificate in X.509 format, a lightweight certificate, or a certificate in a format customized by the operator, etc.).
[0203] Exemplarily, the terminal obtains the user identifier required for this access to the operator. The user identifier can be the user identifier used when the user signs a contract with the operator for this access. For example, the terminal completes the signing with operator 1 based on user identifier 1, and the signing-related information is written into the file information corresponding to user identifier 1. When the terminal accesses operator 1, it can obtain user identifier 1 for authentication.
[0204] It can be understood that the terminal may sign contracts with multiple operators, or rather, even when the terminal has not signed a contract with an operator, it may also be preconfigured with user identifiers and file information corresponding to multiple operators. In a possible implementation, before obtaining the user identifier, the terminal can determine the target operator to which the terminal connects from multiple operators.
[0205] In a first possible implementation, the terminal determines a target operator from multiple operators based on one or more of the user's location, the service quality (such as signal strength) of each operator among the multiple operators, the cost of each operator among the multiple operators, or the security of each operator among the multiple operators. By way of example and not limitation, the terminal may select the operator where the user is located as the target operator, or may select the operator with the strongest signal strength among the multiple operators as the target operator, or may select the operator with the lowest cost among the multiple operators as the target operator.
[0206] Exemplarily, in response to the user's operation of selecting one or more of the following conditions, the terminal determines the target operator according to the conditions selected by the user: the target operator is the operator where the user is located among the multiple operators; the target operator is the operator with the strongest signal strength among the multiple operators; or, the target operator is the operator with the lowest cost among the multiple operators, or, the target operator is the operator with the highest security among the multiple operators.
[0207] In a second possible implementation, the terminal determines a target operator from multiple operators in response to a user operation, where the user operation is an operation of the user selecting a target operator from the multiple operators.
[0208] Exemplarily, in response to the user's operation of selecting a target operator from the multiple operators, the terminal determines the target operator. For example, the terminal displays Operator 1, Operator 2, Operator 3, and Operator 4 through a user interface, and each operator is associated with signal strength, location, or cost, etc. In response to the user's operation of selecting Operator 1, the terminal determines that the target operator is Operator 1. In other words, the terminal selects Operator 1 for access authentication.
[0209] In a third possible implementation, the terminal randomly selects any one of the multiple operators as the target operator.
[0210] It should be noted that the above-mentioned multiple operators can be operators on a distributed storage system (such as a blockchain), or they can not be operators on a distributed storage system. This application does not make any restrictions in this regard. For example, when the above-mentioned multiple operators are not operators on a distributed storage system, taking operator A and operator B as examples of the above-mentioned multiple operators, operator A and operator B have signed a mutually trustworthy certificate, that is, both parties can obtain the information required for the other party to authenticate the terminal. In the first case, both operator A and B have pre-installed the certificate of the other party as a trusted certificate; or, in the second case, operator A and operator B have signed cross-certified certificates with each other; or, in the third case, operator A and operator B have established trust through a bridge. Then operator A and B are not on the blockchain. When a terminal holding a certificate issued by operator A accesses the network of operator B, in the first case, operator B has pre-installed the certificate of operator A as the trust root, and operator B can directly authenticate the terminal (verify the certificate of the terminal based on the certificate of operator A); in the second case, verify the cross-certificate issued by operator B to operator A based on the certificate of operator B, and further verify the certificate of the terminal; in the third case, verify the certificate of operator A based on the certificate of the bridge, and further verify the certificate of the terminal based on the certificate of operator A. It can be understood that if operator A and operator B are neither operators on a distributed storage system nor have signed mutually trustworthy certificates, it may return to the home operator to authenticate the terminal. However, in this application, each operator on the distributed storage system can be used as the home operator to authenticate the terminal, providing more options and higher flexibility.
[0211] Figure 4 It is a schematic diagram of various signing methods of operators provided by an embodiment of the present application.
[0212] Such as Figure 4As shown in the figure, multiple user identifiers are pre - installed in the terminal, such as DSCC, DRC, SCIC 1 to SCIC m derived from DSCC, and DIC 1 to DIC p derived from DRC. Each user identifier corresponds to file information, where m and p are positive integers greater than or equal to 1. The user can complete a contract signing with Operator 1 based on DIC 1, and the relevant information of the contract signing (such as the signatory, validity period, public key of the terminal, etc.) is written into the file information corresponding to DIC 1. When the user accesses the network of Operator 1, the terminal can use DIC 1 for access authentication. The user can also complete a contract signing with Operator 2 based on DIC 2, and the relevant contract - signing information is written into the file information corresponding to DIC 2. When the user accesses the network of Operator 2, the terminal uses DIC 2 for access authentication. The user can also complete a contract signing with Operator 3 based on DRC, and the operator issues SUPI and its corresponding file information. When the user accesses the network of Operator 3, the terminal uses SUPI for access authentication.
[0213] Optionally, the information required for access authentication of the terminal (or the file information corresponding to the user identifier) can be obtained from the blockchain. It can be understood that the above - mentioned blockchain is only an example and should not constitute any limitation to the embodiments of the present application. Exemplarily, other types of distributed storage systems, such as a decentralized shared file information storage system, or IPFS, etc., can also store file information, and the present application does not make any limitations in this regard. The nodes of these distributed storage systems can be network elements of the core network. In addition, there can also be a network element inside the core network as an agent of the distributed storage system to regularly synchronize the file information on the distributed storage system to provide it to the verification network element for authentication.
[0214] In step 320, the terminal sends a user identifier to the verification network element, and the verification network element receives the user identifier.
[0215] Among them, the verification network element is a network element of the target operator accessed by the terminal. For example, the verification network element can be a core network element of the target operator accessed by the terminal. For example, the verification network element can be an AUSF network element, or an AMF network element, or any other core network element. Another example is that the verification network element can also be an access network element of the target operator accessed by the terminal. For example, the verification network element can be an access network node accessed by the terminal, and the present application does not make any limitations in this regard.
[0216] The above - mentioned user identifier can be encrypted with a session key. Among them, the session key can be generated based on the temporary private key of the terminal and the public key of the verification network element, for example. In other words, the terminal can generate a session key based on the temporary private key of the terminal and the public key of the verification network element, and encrypt information such as the user identifier based on the session key, and send the encrypted user identifier to the verification network element.
[0217] In a possible implementation, the above user identifier includes DRC, DIC, DSCC, or SCIC. As described above, each DRC, DIC, DSCC, or SCIC corresponds to file information. After the operator completes the initial signing authentication using other endorsement voucher information of DRC, DIC, DSCC, or SCIC, it can issue a voucher endorsed by the operator for access identity authentication, or directly use other endorsement vouchers for initial authentication for subsequent access identity authentication.
[0218] That is to say, the terminal can send DRC, DIC, DSCC, or SCIC to the verification network element. Correspondingly, the verification network element can receive the above user identifier to obtain the file information corresponding to the user identifier, and then authenticate the terminal.
[0219] The file information may include an authentication voucher (such as a certificate), and the authentication voucher may include one or more of the following information: public key, issuer, validity period, signature of the issuer, version number, identifier of the terminal, certificate status query method (such as: revocation list information, OCSP, etc.). Among them, the issuer indicates the identifier of the endorser who endorses the authentication voucher. For example, DIC has two authentication vouchers. One authentication voucher is derived from DRC, then the issuer of this authentication voucher is DRC; the other authentication voucher is signed by the operator, then the issuer of this authentication voucher is the operator's scID. Another example is that DSCC is self-generated, then the issuer of this authentication voucher is the terminal.
[0220] In a possible implementation, the above user identifier includes a false identity identifier, and there is a corresponding relationship between the false identity identifier and the real identity identifier. The real identity identifier and the corresponding file information are stored in the storage network element.
[0221] It can be understood that the terminal sending a false identity identifier is beneficial to improving security. The real identity identifier (or the identity identifier at the time of signing) and the corresponding file information can be stored in the storage network element, and there is a corresponding relationship between the false identity identifier and the real identity identifier. The storage network element can determine the real identity identifier according to the false identity identifier and the above corresponding relationship, and then determine the corresponding file information according to the real identity identifier.
[0222] Among them, the above real identity identifier can be, for example, DRC, DIC, DSCC, or SCIC described above, and the present application does not limit this.
[0223] In a possible implementation, the above user identifier includes a transaction address, and the transaction address is used to indicate the location of the file information corresponding to the user identifier on the distributed storage system.
[0224] The above user identifier may include a transaction address, that is, the location of the file information used for authenticating the terminal on the distributed storage system.
[0225] Optionally, there may be one or more transaction addresses, and this application does not limit this. When there are multiple transaction addresses, it means that the file information used for authenticating the terminal is split into multiple parts and stored at multiple locations on the distributed storage system. The storage unit may determine the partial file information stored at each location based on the transaction address, and then synthesize the entire file information, and the entire file information may correspond to a DRC, DIC, DSCC, or SCIC.
[0226] In one possible case, the terminal may send the transaction address to the verification network element, and the verification network element obtains the corresponding file information from the storage network element based on the transaction address. Correspondingly, the storage network element determines the corresponding file information based on the transaction address.
[0227] In another possible case, the terminal may send the transaction address and one of the DRC, DIC, DSCC, SCIC, or false identity identifier to the verification network element. Exemplarily, one of the DRC, DIC, DSCC, SCIC, or false identity identifier may be used to query the corresponding file information. Assuming that the file information includes multiple authentication credentials and the algorithm corresponding to each authentication credential, the above transaction address may be used to determine the target authentication credential from the multiple authentication credentials. That is, the terminal may indicate which authentication credential to select through the transaction address. Among them, in one possible implementation, the authentication credential may be understood as a certificate, and different authentication credentials may be understood as certificates with different format standards, such as X.509 format certificates, lightweight certificates, etc. The algorithm corresponding to each authentication credential may include the signature algorithm used in the certificate and the verification signature algorithm that needs to be used, etc. The algorithm corresponding to each authentication credential may be one or more, and this application does not limit this. In another possible implementation, different authentication credentials may be multiple certificates of the same format standard. For example, the terminal may have 3 authentication credentials, and the formats of the 3 authentication credentials are all in X.509 format.
[0228] In one possible implementation, in addition to the public key, issuer, etc. information listed above in the file information, it may also include the transaction address of the issuer's information on the blockchain, and there may be one or more of these transaction addresses, and this application does not limit this.
[0229] In one possible implementation, the user identifier is carried in the first signaling, and the first signaling also includes the type of the user identifier and / or the identifier of the distributed storage system, and the identifier of the distributed storage system is used to identify the distributed storage system where the file information corresponding to the user identifier is located.
[0230] Among them, the type of user identifier is used to indicate the format of the above-mentioned first signaling of the authentication network element. For example, if the type of user identifier indicates that the user identifier carried in the first signaling is SUCI, the authentication network element parses the signaling based on the format of the signaling carrying SUCI. If the type of user identifier indicates that the user identifier carried in the first signaling is not SUCI, or indicates that the user identifier carried in the first signaling is any of the above scIDs, transaction address, or false identity identifier, the authentication network element can parse the signaling based on Figure 5 the format of the signaling shown. Optionally, the type of user identifier can also notify the authentication network element of the type of user identifier carried in the first signaling. For example, the type of user identifier is DRC, DIC, DSCC, SCIC, transaction address, or false identity identifier.
[0231] The identifier of the distributed storage system is used to identify the distributed storage system where the file information corresponding to the user identifier is located. Taking the blockchain as an example for the distributed storage system, the identifier of the blockchain is used to identify the blockchain to which the identity information belongs, or to identify the blockchain where the file information corresponding to the current user identifier is located. It can be understood that when there are multiple blockchains, this blockchain identifier facilitates the authentication network element to determine the blockchain where the file information corresponding to the user identifier is located, and then obtain the file information corresponding to the user identifier on the corresponding blockchain.
[0232] It should be understood that the information carried in the above-mentioned first signaling is only an example and should not constitute any limitation to this application. For example, the first signaling may further include a network identifier, a network public key (PK), a terminal temporary public key, etc. Among them, the network PK is used to identify the network public key used to encrypt the user identifier. For example, the network may have multiple public keys. Therefore, the terminal needs to indicate which public key to use when calculating the session key, so that the network can determine which private key corresponding to the public key to use when calculating the session key.
[0233] Next, an example of the signaling format for the interaction between the terminal and the authentication network element will be given in combination with Figure 5 Figure [Figure number] shows an example of the signaling format of the first signaling provided by an embodiment of the present application. As Figure 5 shown in Figure 5 Figure [Figure number], the first signaling includes a plaintext part and a ciphertext part. Among them, the plaintext part includes the type of user identifier, network identifier, network PK, and terminal temporary public key. Optionally, the plaintext part further includes the identifier of the blockchain. The ciphertext part includes encrypted data, which is ciphertext data obtained by encrypting the user identifier, random number, session identifier, etc. based on the session key. Among them, the session key can be a symmetric secret key generated based on the temporary private key of the terminal and the network public key.
[0234] In step 330, the verification network element obtains the file information corresponding to the above user identifier from the storage network element. The file information includes the public key of the terminal. Step 330 may specifically include step 331 and step 332, for example.
[0235] In step 331, the verification network element sends the user identifier to the storage network element.
[0236] In step 332, the storage network element sends the file information corresponding to the above user identifier to the verification network element.
[0237] After receiving the user identifier from the verification network element, the storage network element determines the file information corresponding to the user identifier, and then sends the file information corresponding to the above user identifier to the verification network element.
[0238] In one example, the user identifier is DRC, DIC, DSCC or SCIC. The storage network element determines the file information corresponding to the user identifier according to the above user identifier, and sends the file information corresponding to the above user identifier to the verification network element.
[0239] In another example, the user identifier is a false identity identifier. The storage network element can determine the real identity identifier according to the false identity identifier and the above corresponding relationship, and then determine the corresponding file information according to the real identity identifier, and send the above file information to the verification network element.
[0240] In yet another example, the user identifier is a trading address. The storage network element can determine one or more locations on the distributed storage system where the file information is stored according to the trading address, and then obtain the file information at the corresponding location, and send the file information corresponding to the above trading address to the verification network element after obtaining the file information.
[0241] In a possible implementation, the above storage network element is a node on the distributed storage system, and at least one user identifier and the file information corresponding to each user identifier are stored in the node.
[0242] In this application, the distributed storage system may include one or more nodes. At least one user identifier and the file information corresponding to each user identifier may be stored in each node. The above storage network element may be any one of the above one or more nodes.
[0243] It should be noted that the above storage network element being a node on the distributed storage system is only an example and should not impose any limitation on this application. For example, in actual applications, the storage network element may also be other management network elements. For example, it may be a network element inside the core network, and this network element can act as an agent of the distributed storage system to periodically synchronize the file information on the distributed storage system for the verification network element to perform authentication.
[0244] In addition, in this application, the verification network element and the storage network element may be the same network element or different network elements, and this application does not limit this. When the verification network element and the storage network element are the same network element, the verification network element obtains the file information corresponding to the user identifier from the storage network element, which can be understood as the verification network element obtains the file information corresponding to the user identifier from the memory or local storage; when the verification network element and the storage network element are different network elements, the verification network element obtains the file information corresponding to the user identifier from the storage network element, which can be understood as the verification network element sends the user identifier to the storage network element and receives the file information corresponding to the above user identifier from the storage network element.
[0245] In a possible implementation, the above distributed storage system is a blockchain, a decentralized shared file information storage system, or an InterPlanetary File System. Among them, for the blockchain, reference can be made to Figure 2B the relevant description.
[0246] In step 340, the verification network element authenticates the terminal based on the above file information.
[0247] After the verification network element obtains the file information corresponding to the user identifier from the storage network element, it authenticates the terminal based on this file information. Among them, the above file information includes the information required for authenticating the terminal, for example, the public key of the terminal.
[0248] A possible implementation manner is that the verification network element can verify the digital signature of the terminal based on the public key of the terminal. If the verification network element passes the verification of the digital signature of the terminal, it is considered that the verification network element passes the authentication of the terminal. Correspondingly, if the verification network element fails to verify the digital signature of the terminal, it is considered that the verification network element fails to authenticate the terminal.
[0249] Exemplarily, the verification network element receives a first message from the terminal and the digital signature of the terminal. The digital signature of the terminal is obtained by signing the second message or the hash value of the second message based on the private key of the terminal, where the second message is the message interacted between the above terminal and the above verification network element or the above first message; based on the public key of the terminal, the digital signature of the terminal is verified. Among them, the above second message may be one or more of all the messages interacted between the above terminal and the above verification network element, and this application does not limit this.
[0250] For example, before the terminal sends the first message, the messages exchanged between the terminal and the authentication network element include Message 1 (which can be, for example, a message sent by the terminal to the authentication network element), Message 2 (which can be, for example, a message sent by the authentication network element to the terminal), and Message 3 (which can be, for example, a message sent by the authentication network element to the terminal). The terminal can sign the hash values of Message 1, Message 2, and Message 3 based on the private key of the terminal to obtain the digital signature of the terminal, and send the first message and the digital signature of the terminal to the authentication network element. Among them, Message 1, Message 2, and Message 3 are examples of the second message. After receiving the first message and the digital signature of the terminal, the authentication network element verifies the digital signature of the terminal based on the public key of the terminal.
[0251] Optionally, before verifying the digital signature of the terminal based on the public key of the terminal, the above method further includes: obtaining the authentication credential of the issuer from the storage network element, where the issuer is the issuer of the authentication credential of the terminal; verifying the authentication credential of the terminal based on the authentication credential of the issuer.
[0252] It can be understood that the authentication network element can obtain the corresponding file information according to the user identifier of the terminal and verify the signature of the terminal based on the public key. Before that, the authentication network element can also verify the authentication credential of the terminal according to the issuer information of the authentication credential of the terminal. For example: taking the authentication credential as a certificate, when the authentication network element verifies the signature of the terminal, it first obtains the certificate of the terminal according to the user identifier, and obtains the certificate of the issuer from the blockchain or the storage network element according to the issuer information (or transaction address information) in the certificate. For example, a certain operator / card issuer, then first verifies the certificate of the terminal with the public key of the operator / card issuer, and further verifies the digital signature of the terminal with the public key in the terminal certificate. Among them, the verification chain may be longer (indicating that the user can derive more identities). For example: verifying the certificate of the DRC with the public key in the certificate of the card issuer, then verifying the certificate of the DIC with the public key of the DRC, and then verifying the digital signature of the above terminal with the public key of the DIC; or, verifying the certificate of the DIC with the public key of the operator, and then verifying the digital signature of the above terminal with the public key of the DIC. Optionally, the above method 300 further includes: the authentication network element sends a third message and the digital signature of the authentication network element to the terminal, and the digital signature of the authentication network element is obtained by signing the fourth message or the hash value of the fourth message based on the private key of the authentication network element, where the fourth message is a message exchanged between the terminal and the authentication network element or the above third message.
[0253] The authentication network element sends the digital signature of the authentication network element to the terminal, so that the terminal can verify the digital signature of the authentication network element based on the public key of the authentication network element. By verifying the authentication network element based on the public key of the authentication network element, the terminal can verify the authentication network element corresponding to any operator. In this way, the terminal can access different operators with higher flexibility.
[0254] Among them, the fourth message may be one or more of all the messages exchanged between the above terminal and the above authentication network element. It can be understood that since the time when the authentication network element receives the second message and sends the third message is different, the messages exchanged between the terminal and the authentication network element will also change. Therefore, the second message and the fourth message may be different.
[0255] Exemplarily, before sending the third message, the messages exchanged between the terminal and the authentication network element include message 1 (for example, it may be a message sent by the terminal to the authentication network element) and message 2 (for example, it may be a message sent by the authentication network element to the terminal). The authentication network element may sign the hash value of message 1 and the hash value of message 2 based on the private key of the authentication network element to obtain the digital signature of the authentication network element, and send the third message and the digital signature of the authentication network element to the terminal. Among them, message 1 and message 2 are examples of the second message. After receiving the third message and the digital signature of the authentication network element, the terminal verifies the digital signature of the authentication network element based on the public key of the authentication network element.
[0256] It should be noted that the authentication network element may receive the first message and the digital signature of the terminal before sending the third message and the digital signature of the authentication network element, or may receive the first message and the digital signature of the terminal after sending the third message and the digital signature of the authentication network element. This application does not make any limitations in this regard. For example, the authentication network element may receive the first message and the digital signature of the terminal, verify the digital signature of the terminal based on the public key of the terminal, and send the third message and the digital signature of the authentication network element to the terminal when the verification is passed.
[0257] Optionally, the above method 300 further includes: the authentication network element sends the certificate of the authentication network element to the terminal.
[0258] By the authentication network element sending the certificate of the authentication network element to the terminal, the terminal does not need to pre-store the certificate of the authentication network element. In the case where the number of authentication network elements is large, the terminal does not need to pre-store the certificates of each authentication network element, which is beneficial to saving the storage space of the terminal.
[0259] Among them, the certificate of the above verification network element includes, for example, the public key of the verification network element, the issuer, the validity period, the signature of the issuer, the version number, the identifier of the verification network element, the method for querying the certificate status (such as: revocation list information, OCSP, etc.). When the certificate of the above verification network element is not pre-configured in the terminal, the terminal can pre-configure the certificate of the target operator, where the certificate of the target operator includes the public key of the operator. The terminal can verify the certificate of the verification network element based on the certificate of the target operator, and then verify the digital signature of the verification network element based on the public key of the verification network element. Among them, the certificate of the verification network element is issued by the operator, that is to say, the signature of the verification network element certificate is generated using the private key of the operator. The terminal can use the public key in the operator certificate to verify the signature of the verification network element certificate; and use the public key of the verification network element certificate to verify the digital signature of the verification network element. If both of the above processes are successfully verified, the authentication of the authentication terminal for the verification network element is successful.
[0260] Optionally, the certificate of the verification network element and the digital signature of the verification network element may be carried in the same signaling or in different signaling. This application does not make any limitation in this regard.
[0261] Optionally, the above file information further includes at least one authentication credential and the algorithm corresponding to each authentication credential in the at least one authentication credential; and, the above method 300 further includes: the verification network element determines a target authentication credential from the at least one authentication credential; and sends a first indication message to the terminal, where the first indication message is used to indicate the target authentication credential and / or the algorithm corresponding to the target authentication credential.
[0262] In this application, a possible design is that different authentication credentials can be understood as certificates with different format standards, such as certificates in X.509 format, lightweight certificates, certificates in the custom format of the operator, etc. The algorithm corresponding to each authentication credential may include the signature algorithm used in the certificate and the verification signature algorithm that needs to be used, etc. The algorithm corresponding to each authentication credential may be one or more. This application does not make any limitation in this regard. Another possible design is that different authentication credentials may be multiple certificates with the same format standard. For example, the terminal may have 3 authentication credentials, and the formats of the 3 authentication credentials are all in X.509 format.
[0263] Exemplarily, after the authentication network element obtains the file information corresponding to the above file identifier, it can determine the target authentication credential from at least one authentication credential included in the file information, and indicate the target authentication credential and / or the algorithm corresponding to the target authentication credential to the terminal. For example, the above file information includes Certificate 1, Certificate 2, and Certificate 3. Each certificate includes the public key of the terminal, the issuer, the validity period, etc. The above Certificate 1, Certificate 2, and Certificate 3 can be certificates with different format standards. The authentication network element can determine that the target authentication credential is Certificate 1, and then indicate Certificate 1 and the corresponding algorithm (such as the signature algorithm used in the certificate and the verification signature algorithm that needs to be used, etc.) to the terminal.
[0264] The following will be combined with Figures 6 to 8 to Figure 3 The access authentication process shown is described in detail. Among them, in the Figure 6 shown embodiment, the user identifier sent by the terminal to the authentication network element includes DRC, DIC, DSCC, or SCIC. The above DRC, DIC, DSCC, or SCIC can be collectively referred to as scID. In the Figure 7 shown embodiment, the user identifier sent by the terminal to the authentication network element includes the transaction address. In the Figure 8 shown embodiment, the user identifier sent by the terminal to the authentication network element includes a false identity identifier.
[0265] Figure 6 is a schematic diagram of the access authentication process provided by the embodiments of the present application.
[0266] In step 601, the terminal generates a first ciphertext, which includes the encrypted scID, random number 1, and session identifier.
[0267] Among them, the first ciphertext can be obtained by encrypting scID, random number 1, and session identifier based on the session key. The session key can be generated based on the temporary private key of the terminal and the public key of the authentication network element. The session identifier is used to identify this session. The above random number 1 can be used to prevent replay attacks. For example, if the random number 1 is included in the message sent by the terminal to the authentication network element, then the digital signature of the authentication network element sent includes the above random number 1 to prevent third parties from replaying attacks on the terminal.
[0268] Exemplarily, the terminal generates a temporary public-private key pair used for accessing the network this time, and generates a session key based on the temporary private key of the terminal and the public key of the authentication network element (the public key of the authentication network element can be pre-set), and uses the session key to encrypt scID, random number 1, and session identifier, etc.
[0269] Optionally, the public key of the above authentication network element can also be replaced with the public key of the operator. In this case, the authentication network element needs to have the private key of the operator, and the operator and the authentication network element can be a set of public-private keys.
[0270] In step 602, the terminal sends the first ciphertext and the plaintext part to the verification network element. Correspondingly, the verification network element receives the first ciphertext and the plaintext part.
[0271] The plaintext part refers to the part that does not need to be encrypted. The plaintext part includes, for example, but is not limited to: the type of user identification, network identification, network public key, terminal temporary public key, and the identification of the distributed storage system, etc.
[0272] Exemplarily, after generating the first ciphertext, the terminal sends the above-mentioned first ciphertext and plaintext part to the verification network element. Correspondingly, the verification network element receives the above-mentioned first ciphertext and plaintext part.
[0273] In step 603, the verification network element decrypts to obtain the scID, random number 1, and session identification.
[0274] Exemplarily, the verification network element can use the private key of the verification network element and the temporary public key of the terminal to generate the above-mentioned session key, and decrypt the first ciphertext based on the above-mentioned session key to obtain the scID, random number 1, and session identification.
[0275] In step 604, the verification network element obtains the file information corresponding to the scID from the storage network element based on the scID.
[0276] Exemplarily, the verification network element sends the above-mentioned scID to the storage network element. Correspondingly, the storage network element receives the above-mentioned scID. Further, the storage network element determines the file information corresponding to the scID according to the above-mentioned scID, and sends the above-mentioned file information to the verification network element. Correspondingly, the verification network element receives the above-mentioned file information.
[0277] Optionally, the file information may include at least one authentication credential and the algorithm corresponding to each authentication credential in the at least one authentication credential. For the explanation of the above-mentioned at least one authentication credential and the algorithm corresponding to each authentication credential in the at least one authentication credential, reference can be made to Figure 3 the corresponding method, which will not be elaborated here.
[0278] In step 605, the verification network element generates random number 2 and signs the fourth message based on the private key of the verification network element. The fourth message may be one or more of all the messages exchanged between the above-mentioned terminal and the above-mentioned verification network element.
[0279] The above-mentioned random number 2 can be used to prevent replay attacks. For example, when the verification network element sends a message to the terminal, the message includes random number 2, then the digital signature sent by the terminal includes the above-mentioned random number 2 to prevent third parties from launching replay attacks on the verification network element.
[0280] The fourth message may be the message sent by the terminal to the authentication network element in step 602, or may be the third message sent by the authentication network element to the terminal in step 606. This application does not make any limitations in this regard.
[0281] It can be understood that the authentication network element may also sign the hash value of the fourth message based on the private key of the authentication network element. This application does not make any limitations in this regard.
[0282] In step 606, the authentication network element sends the digital signature of the authentication network element and the third message to the terminal. The third message includes the identifier of the authentication network element, random number 1, and random number 2. Correspondingly, the terminal receives the digital signature of the authentication network element and the third message.
[0283] Among them, the above third message may be encrypted, for example, it may be encrypted based on the session key generated by the authentication network element.
[0284] Optionally, the third message may further include the certificate of the authentication network element. If it is the certificate of the authentication network element, then it depends on what certificate is pre-set in the terminal. If the terminal pre-sets the certificate of the authentication network element, it can be directly verified. If the terminal pre-sets the certificate of the operator, then first use the certificate of the operator to verify the certificate of the authentication network element, and then use the public key of the authentication network element to verify the digital signature of the authentication network element. The specific process can refer to Figure 3 the relevant description.
[0285] In step 607, the terminal verifies the digital signature of the authentication network element based on the public key of the authentication network element. And signs the second message based on the private key of the terminal.
[0286] Among them, the second message may be one or more of all the messages exchanged between the above terminal and the above authentication network element. For example, the second message may be the message sent by the terminal to the authentication network element in step 602 and the third message sent by the authentication network element to the terminal in step 606, or may be the first message sent by the terminal to the authentication network element in step 608. This application does not make any limitations in this regard.
[0287] It can be understood that the terminal may also sign the hash value of the second message based on the private key of the terminal. This application does not make any limitations in this regard.
[0288] If the terminal's verification of the digital signature of the authentication network element passes, then step 608 is executed; if the terminal's verification of the digital signature of the authentication network element fails, then the terminal access fails. For example, the terminal can try to re-access. In other words, the terminal can restart the execution of step 601.
[0289] In step 608, the terminal sends the digital signature of the terminal and a first message to the authentication network element. The first message includes the scID, random number 1, and random number 2. Correspondingly, the authentication network element receives the digital signature of the terminal and the first message above.
[0290] Among them, the first message above can be encrypted. For example, it can be encrypted based on the session key generated by the terminal.
[0291] Optionally, the terminal can also send the digital signature of the terminal in step 602. In other words, the terminal can send the digital signature of the terminal, the first ciphertext, and the plaintext part in step 602. Among them, the digital signature of the terminal can be obtained, for example, by signing the first ciphertext and the plaintext part based on the private key of the terminal. In this case, after step 604, the authentication network element can execute step 609, that is, verify the digital signature of the terminal based on the public key of the terminal. And the terminal can not execute step 608.
[0292] In step 609, the authentication network element verifies the digital signature of the terminal according to the public key of the terminal obtained in step 604.
[0293] After receiving the digital signature of the terminal and the first message above, the authentication network element verifies the digital signature of the terminal according to the public key of the terminal in the file information in step 604. If the authentication network element passes the verification of the digital signature of the terminal, it is considered that the authentication network element passes the authentication of the terminal. Correspondingly, if the authentication network element fails to verify the digital signature of the terminal, it is considered that the authentication network element fails to authenticate the terminal.
[0294] In step 610, the authentication network element sends an indication message of successful network registration and access to the terminal. Correspondingly, the terminal receives the indication message above.
[0295] Figure 7 It is another schematic diagram of the access authentication process provided by the embodiments of the present application.
[0296] In step 701, the terminal generates a first ciphertext, which includes encrypted transaction address information, random number 1, and a session identifier.
[0297] Among them, the first ciphertext can be obtained, for example, by encrypting the transaction address information, random number 1, and the session identifier based on the session key. The session key can be generated based on the temporary private key of the terminal and the public key of the authentication network element. The session identifier is used to identify this session.
[0298] In a possible implementation, the transaction address information may include a transaction address list and a quantity. Wherein, the above quantity refers to the number of transaction addresses in the transaction address list. The transaction address list includes one or more transaction addresses, and the one or more transaction addresses are used to indicate the location of the file information on the distributed storage system. For a more detailed description of the transaction address, reference can be made to Figure 3 , which will not be elaborated here.
[0299] Exemplarily, the terminal generates a temporary public-private key pair used for this network access, and based on the temporary private key and the public key of the authentication network element (the public key of the authentication network element can be pre-set), generates a session key, and uses the session key to encrypt the transaction address list and quantity, random number 1, and session identifier, etc.
[0300] In step 702, the terminal sends the first ciphertext and the plaintext part to the authentication network element. Correspondingly, the authentication network element receives the first ciphertext and the plaintext part.
[0301] For the description of step 702, reference can be made to step 602.
[0302] In step 703, the authentication network element decrypts to obtain the transaction address information, random number 1, and session identifier.
[0303] Exemplarily, the authentication network element can use the private key of the authentication network element and the temporary public key of the terminal to generate the above session key, and based on the above session key, decrypt the first ciphertext to obtain the transaction address list and quantity, random number 1, and session identifier.
[0304] In step 704, the authentication network element obtains the corresponding file information from the storage network element based on the transaction address information.
[0305] Exemplarily, the authentication network element sends the above transaction address information to the storage network element. The transaction address information includes the transaction address list and the number of transaction addresses in the transaction address list. Correspondingly, the storage network element receives the above transaction address information. Further, the storage network element determines each location of the file information on the distributed storage system according to the transaction addresses in the above transaction address list, and obtains the file information. Further, the storage network element sends the above file information to the authentication network element. Correspondingly, the authentication network element receives the above file information.
[0306] Optionally, the file information may include at least one authentication credential and the algorithm corresponding to each authentication credential in the at least one authentication credential. For the explanation of the above at least one authentication credential and the algorithm corresponding to each authentication credential in the at least one authentication credential, reference can be made to Figure 3 , which will not be elaborated here.
[0307] In step 705, the authentication network element generates a random number 2 and signs the fourth message based on the private key of the authentication network element. The fourth message may be one or more of all the messages exchanged between the above terminal and the above authentication network element.
[0308] For example, the fourth message may be the message sent by the terminal to the authentication network element in step 702, or may be the third message sent by the authentication network element to the terminal in step 706. This application does not make any limitation in this regard.
[0309] It can be understood that the authentication network element may also sign the hash value of the fourth message based on the private key of the authentication network element. This application does not make any limitation in this regard.
[0310] In step 706, the authentication network element sends the digital signature of the authentication network element and the third message to the terminal. The third message includes the identifier of the authentication network element, random number 1, and random number 2. Correspondingly, the terminal receives the digital signature of the above authentication network element and the third message.
[0311] Among them, the above third message may be encrypted. For example, it may be encrypted based on the session key generated by the authentication network element.
[0312] In step 707, the terminal verifies the digital signature of the authentication network element based on the public key of the authentication network element. And signs the second message based on the private key of the terminal.
[0313] The second message may be one or more of all the messages exchanged between the above terminal and the above authentication network element. For example, the second message may be the message sent by the terminal to the authentication network element in step 702 and the third message sent by the authentication network element to the terminal in step 706, or may be the first message sent by the terminal to the authentication network element in step 708. This application does not make any limitation in this regard.
[0314] It can be understood that the terminal may also sign the hash value of the second message based on the private key of the terminal. This application does not make any limitation in this regard.
[0315] In step 708, the terminal sends the digital signature of the terminal and the first message to the authentication network element. The first message includes transaction address information, random number 1, and random number 2. Correspondingly, the authentication network element receives the digital signature of the above terminal and the first message.
[0316] Among them, the above first message may be encrypted. For example, it may be encrypted based on the session key generated by the terminal.
[0317] In step 709, the authentication network element verifies the digital signature of the terminal according to the public key of the terminal obtained in step 704.
[0318] After the authentication network element receives the digital signature and the first message of the above terminal, it verifies the digital signature of the terminal according to the public key of the terminal in the file information in step 704. If the authentication network element passes the verification of the digital signature of the terminal, it is considered that the authentication network element passes the authentication of the terminal. Correspondingly, if the authentication network element fails to verify the digital signature of the terminal, it is considered that the authentication network element fails to authenticate the terminal.
[0319] In step 710, the authentication network element sends an indication message of successful network registration and access to the terminal. Correspondingly, the terminal receives the above indication message.
[0320] Regarding Figure 7 For a more detailed description, reference can be made to Figure 6 , which will not be elaborated here.
[0321] Figure 8 is another schematic diagram of the access authentication process provided by the embodiments of the present application.
[0322] In step 801, the terminal generates a first ciphertext, which includes an encrypted false identity identifier, a random number 1, and a session identifier.
[0323] Among them, the first ciphertext can be obtained by encrypting the false identity identifier, the random number 1, and the session identifier based on the session key. The session key can be generated based on the temporary private key of the terminal and the public key of the authentication network element. The session identifier is used to identify the current session.
[0324] Exemplarily, the terminal generates a temporary public-private key pair for the current network access, and generates a session key based on the temporary private key of the terminal and the public key of the authentication network element (the public key of the authentication network element can be pre-set), and uses the session key to encrypt the false identity identifier, the random number 1, and the session identifier, etc.
[0325] In step 802, the terminal sends the first ciphertext and the plaintext part to the authentication network element. Correspondingly, the authentication network element receives the first ciphertext and the plaintext part.
[0326] For the description of step 802, reference can be made to step 602.
[0327] In step 803, the authentication network element decrypts to obtain the false identity identifier, the random number 1, and the session identifier.
[0328] Exemplarily, the authentication network element can use the private key of the authentication network element and the temporary public key of the terminal to generate the above session key, and decrypt the first ciphertext based on the above session key to obtain the false identity identifier, the random number 1, and the session identifier.
[0329] In step 804, the authentication network element obtains the corresponding file information from the storage network element based on the false identity identifier.
[0330] Exemplarily, the authentication network element sends the above-mentioned false identity identifier to the storage network element. Correspondingly, the storage network element receives the above-mentioned false identity identifier. Further, the storage network element determines the true identity identifier according to the above-mentioned false identity identifier and the corresponding relationship (the corresponding relationship between the false identity identifier and the true identity identifier), and further obtains the file information corresponding to the true identity identifier. Further, the storage network element sends the above-mentioned file information to the authentication network element. Correspondingly, the authentication network element receives the above-mentioned file information. For the relevant explanations of the false identity identifier, reference can be made to Figure 3 , which will not be elaborated here.
[0331] In step 805, the authentication network element generates a random number 2 and signs the fourth message based on the private key of the authentication network element. Among them, the fourth message can be one or more of all the messages exchanged between the above-mentioned terminal and the above-mentioned authentication network element.
[0332] For example, the fourth message can be the message sent by the terminal to the authentication network element in step 802, or the third message sent by the authentication network element to the terminal in step 806. This application does not make any limitations in this regard.
[0333] It can be understood that the authentication network element can also sign the hash value of the fourth message based on the private key of the authentication network element. This application does not make any limitations in this regard.
[0334] In step 806, the authentication network element sends the digital signature of the authentication network element and the third message to the terminal. The third message includes the identifier of the authentication network element, random number 1, and random number 2. Correspondingly, the terminal receives the above-mentioned digital signature of the authentication network element and the third message.
[0335] Among them, the above-mentioned third message can be encrypted, for example, it can be encrypted based on the session key generated by the authentication network element.
[0336] In step 807, the terminal verifies the digital signature of the authentication network element based on the public key of the authentication network element. And signs the second message based on the private key of the terminal.
[0337] Among them, the second message can be one or more of all the messages exchanged between the above-mentioned terminal and the above-mentioned authentication network element. For example, the second message can be the message sent by the terminal to the authentication network element in step 802 and the third message sent by the authentication network element to the terminal in step 806, or the first message sent by the terminal to the authentication network element in step 808. This application does not make any limitations in this regard.
[0338] It can be understood that the terminal can also sign the hash value of the second message based on the private key of the terminal. This application does not make any limitations in this regard.
[0339] In step 808, the terminal sends the digital signature of the terminal and a first message to the verification network element. The first message includes a false identity identifier, a random number 1, and a random number 2. Correspondingly, the verification network element receives the digital signature of the terminal and the first message above.
[0340] Among them, the first message above can be encrypted. For example, it can be encrypted based on the session key generated by the terminal.
[0341] In step 809, the verification network element verifies the digital signature of the terminal according to the public key of the terminal obtained in step 804.
[0342] After receiving the digital signature of the terminal and the first message above, the verification network element verifies the digital signature of the terminal according to the public key of the terminal in the file information in step 804. If the verification network element passes the verification of the digital signature of the terminal, it is considered that the verification network element passes the authentication of the terminal. Correspondingly, if the verification network element fails to verify the digital signature of the terminal, it is considered that the verification network element fails to authenticate the terminal.
[0343] In step 810, the verification network element sends an indication message indicating successful network registration and access to the terminal. Correspondingly, the terminal receives the indication message above.
[0344] Based on the above technical solution, the verification network element can obtain the file information corresponding to the user identifier from the storage network element according to the obtained user identifier of the terminal, so as to complete the authentication of the terminal based on the above file information. And the verification network element can be a network element of the target operator accessed by the terminal. That is to say, even if the verification network element is not a network element of the home operator, it can obtain the file information corresponding to the user identifier to complete the authentication of the terminal, without falling back to the home operator for authentication, which is beneficial to simplifying the authentication process.
[0345] Regarding Figure 8 For a more detailed description, reference can be made to Figure 6 , which will not be elaborated here.
[0346] Figure 9 is a schematic flowchart of the access authentication method 900 provided by an embodiment of the present application. Figure 9 This method is only described from the perspective of the interaction between the terminal, the verification network element, and the storage network element, and should not constitute any limitation to the present application. Figure 9The terminal in [it] can be replaced by components configured in the terminal (such as chips, chip systems, processors, etc.), or logical modules or software that can implement all or part of the functions of the terminal; the authentication network element can be replaced by components configured in the authentication network element (such as chips, chip systems, processors, etc.), or logical modules or software that can implement all or part of the functions of the authentication network element; the storage network element can be replaced by components configured in the storage network element (such as chips, chip systems, processors, etc.), or logical modules or software that can implement all or part of the functions of the storage network element.
[0347] Figure 9 The method 900 shown includes steps 910 to 930. Each step in method 900 is described in detail below.
[0348] In step 910, the terminal obtains a user identifier and file information corresponding to the user identifier.
[0349] Among them, the user identifier is used to identify the terminal, or rather, the user identifier is used to identify the UICC in the terminal. Here, the UICC can be a physical card, an embedded card embedded in hardware, or a software card, etc., and the present application does not limit this. The authentication network element can determine which terminal (or rather, UICC) to authenticate based on the user identifier.
[0350] In the present application, the terminal may include one or more user identifiers, and each user identifier corresponds to a piece of file information. The file information includes information required for authenticating the terminal. For example, the file information includes the public key of the terminal, the validity period of the authentication credential, the issuer of the authentication credential, etc. Among them, the authentication credential can be a certificate for example (the present application does not limit the format standard of the certificate, such as a certificate in X.509 format, a lightweight certificate, a certificate in a format customized by the operator, etc.).
[0351] Exemplarily, the terminal obtains the user identifier required for the terminal to access the operator this time and the file information corresponding to the user identifier. It can be understood that the terminal may store user identifiers and file information corresponding to multiple operators. Therefore, the terminal can determine the target operator to which the terminal accesses this time from multiple operators. For the relevant descriptions of the above multiple operators and the implementation manner of the terminal to determine the target operator, reference can be made to Figure 3 , which will not be elaborated here.
[0352] In step 920, the terminal sends the user identifier and the file information corresponding to the user identifier to the authentication network element.
[0353] Among them, the verification network element is a network element of the target operator to which the terminal is connected. For example, the verification network element may be a core network element of the target operator to which the terminal is connected. For example, the verification network element may be an AUSF network element, an AMF network element, or any other core network element. Another example is that the verification network element may also be an access network element of the target operator to which the terminal is connected. For example, the verification network element may be an access network node to which the terminal is connected, and this application does not limit this.
[0354] The above user identifier and file information may be encrypted with a session key. Among them, the session key may be generated based on the temporary private key of the terminal and the public key of the verification network element, for example. In other words, the terminal may generate a session key based on the temporary private key of the terminal and the public key of the verification network element, and encrypt the user identifier and the file information corresponding to the user identifier based on the session key, and send the encrypted user identifier and file information to the verification network element.
[0355] Optionally, the above user identifier includes DRC, DIC, DSCC, SCIC, transaction address, or false identity identifier. For the relevant explanations of the above user identifier, reference can be made to Figure 3 , which will not be elaborated here.
[0356] In step 930, the verification network element authenticates the terminal based on the above file information.
[0357] For the specific process of the verification network element authenticating the terminal, reference can be made to Figure 3 's description, which will not be elaborated here.
[0358] Optionally, before or after step 930, the above method 900 further includes: the verification network element sends a third message and a digital signature of the verification network element to the terminal. The digital signature of the verification network element is obtained by signing the fourth message or the hash value of the fourth message based on the private key of the verification network element, where the fourth message is a message interacted between the terminal and the verification network element or the above third message. Further, the terminal verifies the digital signature of the verification network element based on the public key of the verification network element.
[0359] For the process of the terminal receiving the third message and the digital signature of the verification network element and verifying them, reference can be made to Figure 3 , which will not be elaborated here.
[0360] In a possible implementation, the above method 900 further includes step 925, where the verification network element obtains the hash value of the file information corresponding to the above user identifier from the storage network element based on the user identifier.
[0361] Among them, the hash value of the file information may be the hash value corresponding to each authentication credential in the file information. Each authentication credential may correspond to a hash value, and the hash values may be stored at the same location or different locations in the distributed storage system. This application does not make any limitation in this regard.
[0362] Among them, the public key of the terminal is included in the file information. Step 925 may specifically include step 9251 and step 9252, for example.
[0363] In step 9251, the verification network element sends the user identifier to the storage network element.
[0364] In step 9252, the storage network element sends the hash value of the file information corresponding to the above user identifier to the verification network element.
[0365] After receiving the user identifier from the verification network element, the storage network element determines the hash value of the file information corresponding to the user identifier, and then sends the hash value of the file information corresponding to the above user identifier to the verification network element. For the process of obtaining the hash value of the file information for different user identifiers, reference can be made to the relevant explanation in step 332, as long as the file information is replaced with the hash value of the file information. Details are not described here again.
[0366] After obtaining the hash value of the file information corresponding to the above user identifier, the storage network element can verify the file information obtained from the terminal based on the hash value of the file information. If the verification passes, the terminal is authenticated based on the above file information.
[0367] The verification network element obtains the hash value of the file information corresponding to the above user identifier from the storage network element based on the user identifier. That is to say, what is stored in the storage network element is the hash value of the file information, rather than the file information itself. On the one hand, this can save the storage space of the storage network element, and on the other hand, it is beneficial to protect the privacy of users. It should be understood that for the relevant explanation of the storage network element, reference can be made to Figure 3 , which is not described here again.
[0368] The following will be combined with Figure 10 to Figure 9 introduce the access authentication method shown in detail.
[0369] Figure 10 is another schematic diagram of the access authentication process provided by an embodiment of this application.
[0370] In step 1001, the terminal generates a first ciphertext, which includes an encrypted user identifier, file information, random number 1, and session identifier.
[0371] Among them, the first ciphertext can be obtained by encrypting the user identification, file information, random number 1, and session identification based on a session key, and the session key can be generated based on the temporary private key of the terminal and the public key of the authentication network element. The session identification is used to identify the current session.
[0372] Exemplarily, the terminal generates a temporary public-private key pair for the current network access, and generates a session key based on the temporary private key of the terminal and the public key of the authentication network element (the public key of the authentication network element can be pre-set), and uses the session key to encrypt the user identification, the file information corresponding to the user identification, random number 1, and session identification, etc. Among them, the present application does not limit the type of user identification.
[0373] In step 1002, the terminal sends the first ciphertext and the plaintext part to the authentication network element. Correspondingly, the authentication network element receives the first ciphertext and the plaintext part.
[0374] The description of step 1002 can refer to step 602.
[0375] In step 1003, the authentication network element decrypts to obtain the user identification, file information, random number 1, and session identification.
[0376] Exemplarily, the authentication network element can generate the above session key using the private key of the authentication network element and the temporary public key of the terminal, and decrypt the first ciphertext based on the above session key to obtain the user identification, file information, random number 1, and session identification.
[0377] In step 1004, the authentication network element obtains the hash value of the corresponding file information from the storage network element based on the user identification.
[0378] Exemplarily, the authentication network element sends the above user identification to the storage network element. Correspondingly, the storage network element receives the above user identification. Further, the storage network element obtains the hash value of the corresponding file information according to the above user identification. Further, the storage network element sends the above hash value of the file information to the authentication network element. Correspondingly, the authentication network element receives the above hash value of the file information.
[0379] In step 1005, the authentication network element verifies the file information from the terminal based on the hash value of the file information.
[0380] If the verification is passed, step 1006 is continued.
[0381] In step 1006, the authentication network element generates random number 2 and signs the fourth message based on the private key of the authentication network element. Among them, the fourth message can be one or more of all the messages interacted between the above terminal and the above authentication network element.
[0382] For example, the fourth message may be the message sent by the terminal to the authentication network element in step 1002, or may be the third message sent by the authentication network element to the terminal in step 1007. This application does not make any limitations in this regard.
[0383] It can be understood that the authentication network element may also sign the hash value of the fourth message based on the private key of the authentication network element. This application does not make any limitations in this regard.
[0384] In step 1007, the authentication network element sends the digital signature of the authentication network element and the third message to the terminal. The third message includes the identifier of the authentication network element, random number 1, and random number 2. Correspondingly, the terminal receives the digital signature of the authentication network element and the third message.
[0385] Among them, the above third message may be encrypted. For example, it may be encrypted based on the session key generated by the authentication network element.
[0386] In step 1008, the terminal verifies the digital signature of the authentication network element based on the public key of the authentication network element. And signs the second message based on the private key of the terminal.
[0387] Among them, the second message may be one or more of all the messages exchanged between the above terminal and the above authentication network element. For example, the second message may be the message sent by the terminal to the authentication network element in step 1002 and the third message sent by the authentication network element to the terminal in step 1007, or may be the first message sent by the terminal to the authentication network element in step 1009. This application does not make any limitations in this regard.
[0388] It can be understood that the terminal may also sign the hash value of the second message based on the private key of the terminal. This application does not make any limitations in this regard.
[0389] In step 1009, the terminal sends the digital signature of the terminal and the first message to the authentication network element. The first message includes the user identifier, file information, random number 1, and random number 2. Correspondingly, the authentication network element receives the digital signature of the terminal and the first message.
[0390] Among them, the above first message may be encrypted. For example, it may be encrypted based on the session key generated by the terminal.
[0391] In step 1010, the authentication network element verifies the digital signature of the terminal according to the public key of the terminal.
[0392] After receiving the digital signature of the terminal and the first message, the authentication network element verifies the digital signature of the terminal according to the public key of the terminal in the file information. If the authentication network element passes the verification of the digital signature of the terminal, it is considered that the authentication network element passes the authentication of the terminal. Correspondingly, if the authentication network element fails to verify the digital signature of the terminal, it is considered that the authentication network element fails to authenticate the terminal.
[0393] In step 1011, the authentication network element sends an indication message of successful network registration and access to the terminal. Correspondingly, the terminal receives the above indication message.
[0394] Regarding Figure 10 For a more detailed description, reference can be made to Figure 6 , which will not be elaborated here.
[0395] Based on the above technical solution, the terminal can send the user identifier and the file information corresponding to the user identifier to the authentication network element, so that the authentication network element can complete the authentication of the terminal according to the above file information. The authentication network element can be a network element of the target operator to which the terminal is connected. That is to say, even if the authentication network element is not a network element of the home operator, it can obtain the file information corresponding to the user identifier to complete the authentication of the terminal, without having to fall back to the home operator for authentication, which is beneficial to simplifying the authentication process.
[0396] Above, the method provided by the embodiments of the present application has been described in detail in conjunction with the accompanying drawings. Below, the device provided by the embodiments of the present application will be described in detail in conjunction with the accompanying drawings.
[0397] It should be understood that Figure 11 and Figure 12 the device shown can be used to implement the functions of the terminal, authentication network element or storage network element in the above method embodiments, and thus can also achieve the beneficial effects possessed by the above method embodiments.
[0398] Figure 11 is a schematic block diagram of the access authentication device 1100 provided by the embodiments of the present application.
[0399] As Figure 11 shown, the device 1100 includes a transceiver module 1110 and a processing module 1120. The device 1100 can be used to implement the functions of the terminal, authentication network element or storage network element in any of the above Figures 3 to 10 shown method embodiments.
[0400] When the device 1100 is used to implement Figure 3 the function of the authentication network element in the method embodiment shown, the transceiver module 1110 can be used to receive the user identifier from the terminal; the processing module 1120 can be used to obtain the file information corresponding to the user identifier from the storage network element, and the file information includes the public key of the terminal; based on the file information, authenticate the terminal.
[0401] In a possible implementation, the processing module 1120 is specifically configured to receive a first message from the terminal and a digital signature of the terminal, where the digital signature of the terminal is obtained by signing a second message or a hash value of the second message based on a private key of the terminal, and where the second message is a message exchanged between the terminal and the verification network element or the first message; and verify the digital signature of the terminal based on a public key of the terminal.
[0402] In a possible implementation, the processing module 1120 is further configured to obtain an authentication credential of an issuer from a storage network element, where the issuer is an issuer of an authentication credential of the terminal; and verify the authentication credential of the terminal based on the authentication credential of the issuer.
[0403] In a possible implementation, the transceiver module 1110 may further be configured to: send a third message and a digital signature of the verification network element to the terminal, where the digital signature of the verification network element is obtained by signing a fourth message or a hash value of the fourth message based on a private key of the verification network element, and where the fourth message is a message exchanged between the terminal and the verification network element or the third message.
[0404] In a possible implementation, the transceiver module 1110 may further be configured to: send a certificate of the verification network element to the terminal.
[0405] In a possible implementation, the file information further includes at least one authentication credential and an algorithm corresponding to each authentication credential in the at least one authentication credential; and the processing module 1120 may further be configured to determine a target authentication credential from the at least one authentication credential; and the transceiver module 1110 may further be configured to send first indication information to the terminal, where the first indication information is used to indicate the target authentication credential and / or the algorithm corresponding to the target authentication credential.
[0406] When the apparatus 1100 is used to implement Figure 3 the functions of the terminal in the method embodiment shown, the processing module 1120 may be configured to obtain a user identifier; and the transceiver module 1110 may be configured to send the user identifier to a verification network element, where the verification network element is a network element of a target operator to which the terminal is connected, the user identifier corresponds to file information stored in a storage network element, and the file information includes a public key of the terminal, and the file information is used to authenticate the terminal.
[0407] In a possible implementation, the transceiver module 1110 may also be configured to receive a third message from the authentication network element and a digital signature of the authentication network element, where the digital signature of the authentication network element is obtained by signing a fourth message or a hash value of the fourth message based on a private key of the authentication network element, and the fourth message is a message exchanged between the terminal and the authentication network element or the third message; the processing module 1120 may also be configured to verify the digital signature of the authentication network element based on a public key of the authentication network element.
[0408] In a possible implementation, the transceiver module 1110 may also be configured to send a first message and a digital signature of the terminal to the authentication network element, where the digital signature of the terminal is obtained by signing a second message or a hash value of the second message based on a private key of the terminal, and the second message is a message exchanged between the terminal and the authentication network element or the first message.
[0409] In a possible implementation, the transceiver module 1110 may also be configured to receive a certificate of the authentication network element.
[0410] In a possible implementation, the processing module 1120 may also be configured to determine the target operator from multiple operators.
[0411] In a possible implementation, the processing module 1120 is specifically configured to determine the target operator from the multiple operators according to one or more of the user's location, the service quality of each operator among the multiple operators, the cost of each operator among the multiple operators, or the security of each operator among the multiple operators.
[0412] In a possible implementation, the processing module 1120 is specifically configured to determine the target operator from the multiple operators in response to a user operation, where the user operation is an operation in which the user selects the target operator from the multiple operators.
[0413] In a possible implementation, the user identifier is carried in a first signaling, and the first signaling further includes a type of the user identifier and / or an identifier of a distributed storage system, where the identifier of the distributed storage system is used to identify the distributed storage system where the file information corresponding to the user identifier is located.
[0414] When the apparatus 1100 is used to implement Figure 3When implementing the functions of the storage network element in the method embodiment shown, the transceiver module 1110 can be used to receive the user identifier of the terminal from the authentication network element, where the authentication network element is the network element of the target operator to which the terminal is connected; the processing module 1120 can be used to determine the file information corresponding to the user identifier based on the user identifier, where the file information includes the public key of the terminal, and the file information is used to authenticate the terminal; the transceiver module 1110 can also be used to send the file information to the authentication network element.
[0415] In a possible implementation, the user identifier includes a decentralized user root credential, a decentralized user identity credential, a decentralized self-controlled identity credential, or a self-controlled identity credential.
[0416] In a possible implementation, the user identifier includes a false identity identifier, and there is a corresponding relationship between the false identity identifier and the real identity identifier, and the real identity identifier and the corresponding file information are stored in the storage network element.
[0417] In a possible implementation, the user identifier includes a transaction address, and the transaction address is used to indicate the location of the file information corresponding to the user identifier or the hash value of the file information on the distributed storage system.
[0418] In a possible implementation, the storage network element is a node on the distributed storage system, and at least one user identifier and the file information corresponding to each user identifier are stored in the node.
[0419] In a possible implementation, the distributed storage system is a blockchain, a decentralized shared file information storage system, or an InterPlanetary File System.
[0420] For a more detailed description of each of the above modules, reference can be directly made to Figure 3 the relevant description in the method embodiment shown, which will not be elaborated here.
[0421] It should be understood that the division of the modules in the embodiments of the present application is illustrative, only a logical function division, and there may be other division methods in actual implementation. In addition, in each embodiment of the present application, the functional modules can be integrated in one processor, or can exist separately physically, or two or more modules can be integrated in one module. The above integrated modules can be implemented in the form of hardware or in the form of software functional modules.
[0422] Figure 12 is another schematic block diagram of the access authentication device 1200 provided by the embodiments of the present application.
[0423] The device 1200 may be a chip system, or alternatively, may be a device configured with a chip system for implementing the methods described in the above method embodiments. In the embodiments of the present application, the chip system may be composed of chips, or may include chips and other discrete devices.
[0424] As Figure 12 shown, the device 1200 may include a processor 1210, which may be used to execute computer programs or instructions in a memory to implement Figures 3 to 10 the steps executed by a terminal, an authentication network element, or a storage network element in any one of the embodiments shown.
[0425] Optionally, the device 1200 further includes a communication interface 1220. Among them, the communication interface 1220 can be used to communicate with other devices through a transmission medium, so that the device 1200 can communicate with other devices. The communication interface 1220 may be, for example, a transceiver, an interface, a bus, a circuit, or a device capable of implementing a transceiver function. The processor 1210 can use the communication interface 1220 to input and output data and is used to implement Figures 3 to 10 the steps executed by a terminal, an authentication network element, or a storage network element in any one of the embodiments shown.
[0426] Optionally, the device 1200 further includes at least one memory 1230 for storing program instructions and / or data. The memory 1230 is coupled to the processor 1210. The coupling in the embodiments of the present application is an indirect coupling or communication connection between devices, units, or modules, which may be electrical, mechanical, or other forms for information interaction between devices, units, or modules. The processor 1210 may cooperate with the memory 1230. The processor 1210 may execute the program instructions stored in the memory 1230. At least one of the at least one memory may be included in the processor.
[0427] It should be understood that the coupling in the embodiments of the present application is an indirect coupling or communication connection between devices, units, or modules, which may be electrical, mechanical, or other forms for information interaction between devices, units, or modules. The processor 1210 may cooperate with the memory 1230. In the embodiments of the present application, the specific connection medium between the above-mentioned processor 1210, communication interface 1220, and memory 1230 is not limited. Optionally, the processor 1210, communication interface 1220, and memory 1230 are connected through a bus 1240. The bus 1240 is in Figure 12The connection between the central part is represented by a thick line, and the connection manners between other components are only for illustrative purposes and are not restrictive. The bus can be a peripheral component interconnect (PCI) bus, an extended industry standard architecture (EISA) bus, or the like. The bus can be divided into an address bus, a data bus, a control bus, etc. For ease of representation, Figure 12 only a thick line is used to represent it in the figure, but it does not mean that there is only one bus or one type of bus.
[0428] In a possible implementation, the device 1200 is a System-On-a-Chip (SoC). Alternatively, the processor 1210 is an SoC.
[0429] This application also provides a computer program product, which includes: a computer program (which can also be referred to as code or instruction), and when the computer program is run, it can implement Figures 3 to 10 the steps executed by the terminal, the authentication network element, or the storage network element in any one of the illustrated embodiments.
[0430] This application also provides a computer-readable storage medium, which stores a computer program (which can also be referred to as code or instruction). When the computer program is run, it can implement Figures 3 to 10 the steps executed by the terminal, the authentication network element, or the storage network element in any one of the illustrated embodiments.
[0431] The embodiments of this application provide an access authentication system, which includes the terminal, the authentication network element, and the storage network element as described above.
[0432] It should be understood that the processor in the embodiments of the present application may be an integrated circuit chip with the ability to process signals. In the implementation process, each step of the above method embodiments may be completed by the integrated logic circuit in the hardware of the processor or instructions in the form of software. The above processor may be a general-purpose processor, a digital signal processor (DSP), an application specific integrated circuit (ASIC), a field programmable gate array (FPGA) or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components. It can implement or execute the various methods, steps and logic block diagrams disclosed in the embodiments of the present application. The general-purpose processor may be a microprocessor or the processor may also be any conventional processor, etc. The steps of the method disclosed in combination with the embodiments of the present application may be directly embodied as being executed by a hardware decoding processor, or executed by a combination of hardware and software modules in the decoding processor. The software module may be located in a mature storage medium in the art such as a random access memory, a flash memory, a read-only memory, a programmable read-only memory or an electrically erasable programmable memory, a register, etc. The storage medium is located in the memory, and the processor reads the information in the memory and combines its hardware to complete the steps of the above method.
[0433] It should also be understood that the memory in the embodiments of the present application may be a volatile memory or a non-volatile memory, or may include both volatile and non-volatile memories. Among them, the non-volatile memory may be a read-only memory (ROM), a programmable ROM (PROM), an erasable programmable ROM (EPROM), an electrically erasable programmable ROM (EEPROM), or a flash memory. The volatile memory may be a random access memory (RAM), which is used as an external cache. By way of example but not limitation, many forms of RAM are available, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), double data rate SDRAM (DDR SDRAM), enhanced SDRAM (ESDRAM), synchlink DRAM (SLDRAM), and direct rambus RAM (DR RAM). It should be noted that the memory of the systems and methods described herein is intended to include, but is not limited to, these and any other suitable types of memory.
[0434] The terms "unit", "module", etc. used in this specification may be used to represent computer-related entities, hardware, firmware, combinations of hardware and software, software, or software in execution. The units and modules in the embodiments of the present application have the same meaning and may be used interchangeably.
[0435] Those of ordinary skill in the art can realize that the various illustrative logical blocks and steps described in combination with the embodiments disclosed herein can be implemented by electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are executed in a hardware or software manner depends on the specific application and design constraints of the technical solution. Professional technicians can use different methods for each specific application to implement the described functions, but such implementation should not be considered to exceed the scope of this application. In several embodiments provided in this application, it should be understood that the disclosed devices, equipment, and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the division of the units is only a logical function division, and there can be other division methods in actual implementation. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed coupling, direct coupling, or communication connection to each other can be through some interfaces. The indirect coupling or communication connection of the devices or units can be in an electrical, mechanical, or other form.
[0436] The units described as separate components may or may not be physically separated. The components displayed as units may or may not be physical units, that is, they can be located in one place, or they can be distributed to multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0437] In addition, in each embodiment of this application, the functional units can be integrated in a processing unit, or each unit can exist physically alone, or two or more units can be integrated in one unit.
[0438] In the above embodiments, the functions of each functional unit can be implemented in whole or in part by software, hardware, firmware, or any combination thereof. When implemented using software, it can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions (programs). When the computer program instructions (programs) are loaded and executed on a computer, the processes or functions described in the embodiments of the present application are generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable devices. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, the computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center by wire (such as coaxial cable, optical fiber, digital subscriber line (DSL)) or wirelessly (such as infrared, wireless, microwave, etc.). The computer-readable storage medium can be any available medium that can be accessed by a computer or a data storage device such as a server or a data center that includes one or more integrated available media. The available medium can be a magnetic medium (for example, a floppy disk, a hard disk, a magnetic tape), an optical medium (for example, a digital video disc (DVD)), or a semiconductor medium (for example, a solid state disk (SSD)), etc.
[0439] If the function is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application, in essence, or the part that contributes to the technology, or a part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to enable a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of the present application. The foregoing storage medium includes: various media such as USB flash drives, mobile hard disks, ROM, RAM, magnetic disks, or optical discs that can store program codes.
[0440] As described above, the above are only the specific implementation manners of the present application, but the protection scope of the present application is not limited thereto. Any person skilled in the art can easily think of changes or substitutions within the technical scope disclosed in the present application, and all of them should be covered by the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.
Claims
1. An access authentication method, characterized in that Applied to an authentication network element, which is a network element of the target operator accessed by a terminal, the method includes: Receiving a user identifier from the terminal; Obtaining, from a storage network element, file information corresponding to the user identifier, where the file information includes a public key of the terminal; Authenticating the terminal based on the file information.
2. The method according to claim 1, characterized in that, The authenticating the terminal based on the file information includes: Receiving a first message from the terminal and a digital signature of the terminal, where the digital signature of the terminal is obtained by signing a second message or a hash value of the second message based on a private key of the terminal, and where the second message is a message exchanged between the terminal and the authentication network element or the first message; Verifying the digital signature of the terminal based on the public key of the terminal.
3. The method according to claim 2, wherein Before verifying the digital signature of the terminal based on the public key of the terminal, the method further includes: Obtaining an authentication credential of an issuer from a storage network element, where the issuer is the issuer of the authentication credential of the terminal; Verifying the authentication credential of the terminal based on the authentication credential of the issuer.
4. The method according to any one of claims 1 to 3, characterized in that, The method further includes: Sending a third message and a digital signature of the authentication network element to the terminal, where the digital signature of the authentication network element is obtained by signing a fourth message or a hash value of the fourth message based on a private key of the authentication network element, and where the fourth message is a message exchanged between the terminal and the authentication network element or the third message.
5. The method according to claim 4, characterized in that, The method further includes: Sending a certificate of the authentication network element to the terminal.
6. The method according to any one of claims 1 to 5, characterized in that, The file information further includes at least one authentication credential and an algorithm corresponding to each authentication credential in the at least one authentication credential; and the method further includes: Determining a target authentication credential from the at least one authentication credential; Sending first indication information to the terminal, where the first indication information is used to indicate the target authentication credential and / or the algorithm corresponding to the target authentication credential.
7. An access authentication method, characterized in that, Applied to a terminal, the method includes: Obtaining a user identifier; Sending the user identifier to an authentication network element, where the authentication network element is a network element of the target operator accessed by the terminal, the user identifier corresponds to file information stored in a storage network element, the file information includes a public key of the terminal, and the file information is used to authenticate the terminal.
8. The method according to claim 7, characterized in that, The method further includes: Receiving a third message and a digital signature of the authentication network element from the authentication network element, where the digital signature of the authentication network element is obtained by signing a fourth message or a hash value of the fourth message based on a private key of the authentication network element, and where the fourth message is a message exchanged between the terminal and the authentication network element or the third message; Verifying the digital signature of the authentication network element based on the public key of the authentication network element.
9. The method according to claim 7 or 8, characterized in that, The method further includes: Sending a first message and a digital signature of the terminal to the authentication network element, where the digital signature of the terminal is obtained by signing a second message or a hash value of the second message based on a private key of the terminal, and where the second message is a message exchanged between the terminal and the authentication network element or the first message.
10. The method according to claim 9, characterized in that, The method further includes: Receiving a certificate of the authentication network element.
11. The method according to any one of claims 7 to 10, characterized in that Before obtaining the user identifier, the method further includes: Determining the target operator from multiple operators.
12. The method according to claim 11, wherein The determining the target operator from multiple operators includes: Determining the target operator from the multiple operators according to one or more of the user's location, the service quality of each operator among the multiple operators, the cost of each operator among the multiple operators, or the security of each operator among the multiple operators.
13. The method according to claim 11, wherein, The determining the target operator from multiple operators includes: In response to a user operation, determining the target operator from the multiple operators, where the user operation is an operation in which the user selects the target operator from the multiple operators.
14. The method according to any one of claims 1 to 13, characterized in that, The user identifier is carried in a first signaling, and the first signaling further includes the type of the user identifier and / or the identifier of the distributed storage system, and the identifier of the distributed storage system is used to identify the distributed storage system where the file information corresponding to the user identifier is located.
15. An access authentication method, characterized in that, Applied to a storage network element, the method includes: Receiving a user identifier of a terminal from an authentication network element, where the authentication network element is a network element of the target operator to which the terminal is connected; Based on the user identifier, determining file information corresponding to the user identifier, where the file information includes a public key of the terminal, and the file information is used to authenticate the terminal; Sending the file information to the authentication network element.
16. The method according to any one of claims 1 to 15, characterized in that, The user identifier includes a decentralized user root credential, a decentralized user identity credential, a decentralized self-controlled identity credential, or a self-controlled identity credential.
17. The method according to any one of claims 1 to 15, characterized in that, The user identifier includes a false identity identifier, and there is a corresponding relationship between the false identity identifier and a real identity identifier, and the real identity identifier and the corresponding file information are stored in the storage network element.
18. The method according to any one of claims 1 to 17, characterized in that The user identifier includes a transaction address, and the transaction address is used to indicate the location of the file information corresponding to the user identifier or the hash value of the file information on the distributed storage system.
19. The method according to any one of claims 1 to 18, characterized in that, The storage network element is a node on a distributed storage system, and at least one user identifier and file information corresponding to each user identifier are stored in the node.
20. The method according to claim 19, wherein The distributed storage system is a blockchain, a decentralized shared file information storage system, or an InterPlanetary File System.
21. An access authentication device, characterized in that, Including a module for implementing the method according to any one of claims 1 to 6, 14, 16 to 20; or, including a module for implementing the method according to any one of claims 7 to 14, 16 to 20; or including a module for implementing the method according to any one of claims 15 to 20.
22. An access authentication device, characterized in that, Including a processor, the processor is coupled to a memory, where The memory is used to store a computer program; The processor is used to call the computer program so that the device implements the method according to any one of claims 1 to 6, 14, 16 to 20; or, implements the method according to any one of claims 7 to 14, 16 to 20; or, implements the method according to any one of claims 15 to 20.
23. A computer-readable storage medium, characterized in that, A computer program or instruction is stored in the storage medium, and when the computer program or instruction is executed by a computer, the method according to any one of claims 1 to 20 is implemented.
24. A computer program product, characterized in that, The computer program product includes instructions, and when the instructions are run by a computer, the method according to any one of claims 1 to 20 is implemented.
25. A communication system, characterized in that, Comprising: A verification network element and a storage network element, the verification network element being configured to implement the method according to any one of claims 1 to 6, 14, 16 to 20; The storage network element is configured to implement the method according to any one of claims 15 to 20.
26. The communication system according to claim 25, wherein, It further includes a terminal, the terminal being configured to implement the method according to any one of claims 7 to 14, 16 to 20.
Citation Information
Cited By
Access authentication method and related apparatus
WO2025157074A1