Terminal access authentication method and system
By introducing security domains for network management servers and AAA servers in 5G networks, the problems of poor compatibility and high deployment costs of 802.1x authentication are resolved, and low-threshold, highly compatible terminal access authentication is achieved in multiple SNPN scenarios, reducing user operations and AAA server load.
Patent Information
- Application Number
- CN202510982334.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-16
- Publication Date
- 2025-09-12
AI Technical Summary
The existing 802.1x authentication in 5G networks has poor compatibility and high deployment costs during terminal access. In addition, authentication is complex in multi-SNPN scenarios, increasing user operation complexity and AAA server load.
By first establishing a PDU session and making an EAP request in the security domain of the network management server, AAA server and the first SNPN, the network management server obtains the UE's SUPI and synchronizes the contract data to the UDM of the target SNPN, reducing repeated authentication and reducing the load on the AAA server.
It achieves a one-time 802.1x authentication with low deployment threshold and high compatibility, reduces user operations, reduces the processing load of AAA servers, and supports terminal access in multiple SNPN scenarios.
Smart Images

Figure CN120640283A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of communication technology, and in particular to a terminal access authentication method and system. Background Art
[0002] In the field of enterprise network security, the access authentication requirements for wired / wireless LANs are becoming increasingly stringent. In traditional solutions, 802.1x authentication technology uses a "client-authenticator-authentication server" architecture combined with the Extensible Authentication Protocol (EAP) to achieve refined access control, such as using the EAP-TLS digital certificate mechanism to enhance security. This technology centrally manages user credentials and configures access rights for each client individually, and has become a standard solution for enterprise intranet security. However, with the advent of fifth-generation mobile communication technology (5G), the th The deployment of 5G (5th Generation Mobile Communication Technology) technology in enterprise private networks requires that terminals access through 5G and integrate the 5G native security mechanism with the traditional 802.1x authentication to meet the high security requirements of scenarios such as industrial control and campus networks.
[0003] In existing technologies, authentication is performed using the following two methods: The first method introduces 802.1x authentication logic into the 5G core network, encapsulating EAP messages within Stand-alone Non-Public Network (SNPN) signaling for transmission. This allows 5G terminals to trigger secondary authentication on the data network after accessing the core network. The second method implements terminal access authentication in the SNPN through collaboration between the User Plane Function (UPF) and the Session Management Function (SMF). The UPF forwards the EAP request to the enterprise Authentication, Authorization, and Accounting (AAA) server based on the SMF's initial forwarding rules, generates security rules based on the authentication results, and the SMF is responsible for generating and updating forwarding rules to control user plane traffic.
[0004] However, in the first method of existing technologies, 802.1x authentication in existing 5G networks requires the transmission of EAP messages in NAS messages, requiring the terminal protocol stack to support the encapsulation and parsing of EAP messages. However, current 5G terminals do not have built-in related functions, and the protocol stack code needs to be modified, resulting in poor terminal compatibility and high deployment costs. The second method does not consider the scenario where the terminal switches between multiple SNPNs. When the terminal switches across SNPNs, 802.1x authentication must be repeated, which not only increases the complexity of user operations, but also causes a surge in the processing load of the AAA server, affecting network efficiency and stability. Summary of the Invention
[0005] The purpose of this application is to address the deficiencies in the above-mentioned prior art and provide a terminal access authentication method and system to solve the problems of high deployment threshold and complex authentication in multiple SNPN scenarios in the prior art.
[0006] To achieve the above objectives, the technical solutions adopted in this application are as follows: In a first aspect, the present application provides a terminal access authentication method, which is applied to a terminal access authentication system, wherein the terminal access authentication system includes: a network management server, an authentication, authorization, and accounting AAA server, a first independent non-public network SNPN, and at least one second SNPN, wherein the network management server, the AAA server, and the first SNPN are deployed in the same security domain; the method includes: The user equipment UE in the first SNPN sends an access request to the first SNPN, and the first SNPN determines the subscription data of the UE according to the access request, and establishes a PDU session in the first SNPN according to the subscription data of the UE, wherein the access request includes the user identity SUPI of the UE; The UE sends an Extensible Authentication Protocol (EAP) request message to the first SNPN; the first SNPN creates a local data record based on the EAP request message, and sends the EAP request message of the UE to the network management server, where the local data record includes the media access control (MAC) address of the UE and the PDU session identifier of the UE; The network management server forwards the EAP request message of the UE to the AAA server, and the AAA server determines whether the EAP request is valid. If so, the network management server creates context information of the UE, where the context information of the UE includes a MAC address of the UE; The network management server obtains the SUPI of the UE from the first SNPN based on the MAC address of the UE, and determines the identifier of the target SNPN according to the SUPI of the UE, where the target SNPN is an SNPN that the UE can access, and the target SNPN is one of the second SNPNs. The network management server writes the contract data of the UE into the data table corresponding to the target SNPN in the network management server, and synchronizes the data table corresponding to the target SNPN in the network management server to the unified data management function UDM in the target SNPN.
[0007] Optionally, before the terminal UE in the first SNPN sends the access request to the first SNPN, the method further includes: The network management server receives subscription data of multiple UEs input by a user; The network management server writes the contract data of multiple UEs into the data table corresponding to the first SNPN in the network management server, synchronizes the data table corresponding to the first SNPN in the network management server to the UDM in the first SNPN, and synchronizes the data tables corresponding to each second SNPN in the network management server to the UDM in each second SNPN.
[0008] Optionally, the first SNPN determines the subscription data of the UE according to the access request, and establishes a PDU session in the first SNPN according to the subscription data of the UE, including: The SMF in the first SNPN generates a first subscription data query request according to the SUPI, sends the first subscription data query request to the UDM in the first SNPN, and receives the subscription data of the UE returned by the UDM in the first SNPN; The SMF determines the target data forwarding engine UPF according to the subscription data of the UE; The SMF establishes a PDU session for the UE in the first SNPN based on the target UPF.
[0009] Optionally, the first SNPN creates a local data record according to the EAP request message, including: The target UPF in the first SNPN determines whether the EAP request message includes a target field; If so, the target UPF creates a local data record based on the EAP request message.
[0010] Optionally, the network management server forwards the EAP request message of the UE to the AAA server, and the AAA server determines whether the EAP request is valid. If so, the network management server creates context information of the UE, including: The network management server determines whether a target field exists in the EAP request message, and if so, the authenticator in the network management server sends the EAP request message to the AAA server; The AAA server determines whether the EAP request is valid based on the EAP request message, and if so, generates an EAP response message and sends the EAP response message to the authenticator; The authenticator creates context information of the UE according to the EAP response message.
[0011] Optionally, the network management server acquiring the SUPI of the UE from the first SNPN based on the MAC address of the UE includes: The network management server reads the MAC address from the authenticator, generates a first query request, and sends the first query request to the NEF in the first SNPN, wherein the first query request includes the MAC address; The NEF in the first SNPN forwards the first query request to the target UPF, so that the target UPF retrieves the corresponding PDU session identifier in the local data record based on the MAC address; The target UPF sends the PDU session identifier to the network management server through the NEF; The network management server generates a second query request and sends the second query request to the SMF through the NEF, where the second query request includes the PDU session identifier; The SMF determines the SUPI corresponding to the PDU session identifier according to the PDU session identifier, and sends the SUPI to the network management server through the NEF.
[0012] Optionally, the method further includes: The UE initiates an access request in the SNPN to be accessed, and establishes a PDU session in the SNPN to be accessed according to a response result of the access request, where the SNPN to be accessed is one of the second SNPNs.
[0013] Optionally, the UE initiates an access request in the SNPN to be accessed, and establishes a PDU session in the target SNPN according to a response result of the access request, including: The UE initiates an access request to the SMF in the SNPN to be accessed, where the access request includes the SUPI of the UE; The SMF determines whether the UE's subscription data exists in the UDM in the SNPN to be accessed according to the SUPI. If so, it determines the target UPF of the UE in the SNPN to be accessed and establishes a PDU session for the UE in the SNPN to be accessed.
[0014] Optionally, the determining an identifier of a target SNPN according to the SUPI of the UE includes: The network management server uses the SUPI as an index to search a data table corresponding to a first SNPN in the network management server to determine whether subscription data of the UE corresponding to the SUPI is present; If so, the identifier of the accessible network in the subscription data of the UE is used as the identifier of the target SNPN.
[0015] In the second aspect, the present application provides a terminal access authentication system, which includes: a network management server, an AAA server, a first SNPN and at least one second SNPN, wherein the network management server, the AAA server and the first SNPN are deployed in the same security domain, and the terminal access authentication system is used to execute the terminal access authentication method described in the first aspect.
[0016] The beneficial effects of the present application are as follows: the first SNPN first determines the UE's subscription data based on the access request sent by the UE, and establishes a PDU session in the first SNPN based on the UE's subscription data. The first SNPN then creates a local data record based on the EAP request message sent by the UE, and sends the UE's EAP request message to the network management server. The network management server forwards the EAP request message to the AAA server. After the AAA server feedback confirms that the EAP request is legal, the network management server creates the UE's context information and obtains the UE's SUPI from the first SNPN based on the UE's MAC address. The identifier of the target SNPN is determined based on the UE's SUPI, and then the UE's subscription data is written into the data table corresponding to the target SNPN in the network management server, and the data table corresponding to the target SNPN in the network management server is synchronized to the UDM in the target SNPN. In the present application, the UE enters the security domain where the first SNPN is located in advance and completes authentication. After entering the security domain where the target SNPN is located, it does not need the AAA server to authenticate again, which reduces the UE's operations and reduces the processing load of the AAA server. In addition, this application can implement authentication based on the 802.1x protocol without modifying the UE's 5G protocol stack, with a low deployment threshold and high compatibility. BRIEF DESCRIPTION OF THE DRAWINGS
[0017] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the following is a brief introduction to the drawings required for use in the embodiments. It should be understood that the following drawings only show certain embodiments of the present application and therefore should not be regarded as limiting the scope. For ordinary technicians in this field, other relevant drawings can be obtained based on these drawings without creative work.
[0018] Figure 1 This is a schematic diagram of the architecture of a terminal access authentication system provided by an embodiment of the present application; Figure 2 This is a flow chart of a terminal access authentication method provided in an embodiment of the present application; Figure 3 1 is a flow chart of establishing a PDU session in a first SNPN according to an embodiment of the present application; Figure 4 This is a flow chart of a network management server creating UE context information according to an embodiment of the present application; Figure 5 This is a schematic diagram of a process for obtaining the SUPI of a UE provided in an embodiment of the present application; Figure 6 This is a flow chart of another terminal access authentication method provided in an embodiment of the present application. DETAILED DESCRIPTION
[0019] In order to make the purpose, technical solutions and advantages of the embodiments of the present application clearer, the technical solutions in the embodiments of the present application will be clearly and completely described below in conjunction with the drawings in the embodiments of the present application. It should be understood that the drawings in the present application only serve the purpose of illustration and description and are not used to limit the scope of protection of the present application. In addition, it should be understood that the schematic drawings are not drawn to scale. The flowcharts used in this application illustrate the operations implemented according to some embodiments of the present application. It should be understood that the operations of the flowcharts can be implemented out of sequence, and steps without logical context can be reversed or implemented simultaneously. In addition, those skilled in the art, under the guidance of the contents of this application, can add one or more other operations to the flowchart, or remove one or more operations from the flowchart.
[0020] In addition, the described embodiments are only a part of the embodiments of the present application, rather than all of the embodiments. The components of the embodiments of the present application generally described and shown in the drawings here can be arranged and designed in various configurations. Therefore, the following detailed description of the embodiments of the present application provided in the drawings is not intended to limit the scope of the claimed application, but merely represents selected embodiments of the present application. Based on the embodiments of the present application, all other embodiments obtained by those skilled in the art without making creative work are within the scope of protection of the present application.
[0021] It should be noted that the term "comprising" will be used in the embodiments of the present application to indicate the existence of the features declared thereafter, but does not exclude the addition of other features.
[0022] In the existing technology, by encapsulating EAP messages in SNPN signaling for transmission, the 5G terminal triggers secondary authentication for the data network after accessing the core network. This requires the terminal protocol stack to support the encapsulation and parsing of EAP messages. However, current 5G terminals do not have built-in related functions, and the protocol stack code needs to be modified, resulting in poor terminal compatibility and high deployment costs.
[0023] The method of implementing terminal access authentication in SNPN through the collaboration of UPF and SMF does not consider the scenario where the terminal switches between multiple SNPNs. When the terminal switches between SNPNs, 802.1x authentication must be repeated, which not only increases the complexity of user operations but also increases the processing load of AAA servers, affecting network efficiency and stability.
[0024] Based on this, the present application proposes a terminal access authentication method. In a security domain where a network management server, an AAA server, and a SNPN are deployed, the user device initiates an EAP request after establishing a PDU session. After the network management server confirms the legitimacy of the EAP request through the AAA server, it retrieves the subscription data corresponding to the user device from the UDM corresponding to the SNPN, and uses the SNPN that the user device can access in the subscription data as the target SNPN. The subscription data of the user device is filled into the UDM corresponding to the target SNPN, and the data table corresponding to the target SNPN is synchronized to the UDM in the target SNPN, so that the user device initiates an access request in the target SNPN without having to authenticate again through the AAA server. A PDU session in the target SNPN can be established. This method does not require changes to the 5G protocol stack of the user device, so it has high compatibility and low deployment cost. In addition, this method supports the coexistence of multiple SNPNs. The user device only needs to perform 802.1x authentication once, and does not need to perform 802.1x authentication again when accessing other SNPNs, reducing user device operations and reducing the processing load of the AAA server.
[0025] Before introducing the terminal access authentication method proposed in this application, a brief explanation of several terms designed in this application is first given.
[0026] 802.1x is a framework for centrally configuring, managing, and controlling access rights to wired and wireless local area networks (LANs), as well as providing network services and applications. 802.1x allows for individual access credentials to be set for each client. Specifically, 802.1x authentication utilizes the EAP framework of the Internet Engineering Task Force (IETF), which defines four main functional components: the client, the authenticator, the authentication server, and the user directory. The client can be a user device or terminal attempting to access the network. The authenticator can be a network access point, such as the Access and Mobility Management Function (AMF). The authentication server can be an AAA server. The user directory can be a database or table associated with the network. When a client wishes to access the network, it sends its user credentials to the authenticator, which forwards them to the authentication server. The authentication server then queries the user directory to verify the validity of the credentials forwarded by the authenticator and, based on the user's verification, determines whether to grant network access to the client.
[0027] User Equipment (UE) is a terminal device in a mobile communication system, including mobile phones, tablets, laptops, PDAs, IoT devices, smart home devices, self-driving cars, etc. UE can communicate with industrial equipment.
[0028] SNPN is a network type in the 5G system. SNPN does not rely on the network functions provided by the public land mobile network. During the terminal access process, only the SNPN is selected and registered.
[0029] AAA servers perform authentication, authorization, and accounting. Authentication verifies the identity of a terminal through methods such as usernames and passwords, digital certificates, and two-factor authentication, ensuring that only authorized users or devices can access network resources. Authorization determines the resources a terminal can access and the operations it can perform based on its identity and permissions, such as restricting access to specific files or applications. Accounting records the terminal's use of network resources.
[0030] A security domain is a logical area and collection of IT elements composed of systems with the same security protection requirements and mutual trust. As a special type of network, SNPN can be defined and managed according to its own security requirements and access control policies in the security domain division. For example, it can be isolated from other network domains and information flow in and out can be controlled by setting up firewalls and other means to ensure its security and independence.
[0031] Next, refer to Figure 1 The architecture of the terminal access authentication system used in the terminal access authentication method is introduced. Figure 1 This is a schematic diagram of the architecture of a terminal access authentication system provided in an embodiment of the present application.
[0032] Optionally, the terminal access authentication system includes: a network management server, an AAA server, a first SNPN, and at least one second SNPN, wherein the network management server, the AAA server, and the first SNPN are deployed in the same security domain. Figure 1 , the second SNPN-1, the second SNPN-2 and the second SNPN-n are used as examples of multiple second SNPNs.
[0033] Optionally, the network management server maintains a data table corresponding to the first SNPN and a data table corresponding to each second SNPN, and deploys an authenticator. The authenticator is an 802.1x authenticator. The network management server is connected to the AAA server and the first SNPN, and to each second SNPN. The data table corresponding to the first SNPN is synchronized with the Unified Data Management (UDM) function in the first SNPN, and the data table corresponding to each second SNPN is synchronized with the UDM in the corresponding second SNPN. A data table can be maintained in the UDM, and the data table can store the subscription data of the user device.
[0034] Optionally, the first SNPN and each second SNPN can be used in vertical industries such as industry, including an access layer, a control layer, a user plane, and supporting functions. The access layer includes the UE and the (Radio) Access Network (R)AN), wherein the (R)AN is used to provide a wireless connection between the UE and the core network. The control layer includes the AMF, SMF, the Policy Control Function (PCF), and the Authentication Server Function (AUSF), and the user plane includes the UPF for forwarding service data. Support functions include the Network Repository Function (NRF), the Network Exposure Function (NEF), and the Unified Data Management (UDM).
[0035] Figure 1 The interfaces marked with "N+ network element" are in compliance with the 3GPP 5G standard. Specifically, in the control plane interface, the interfaces between AMF and SMF are Namf and Nsmf respectively, the interaction interface between PCF and SMF is Npcf, and in the user plane interface, N1 is the interaction interface between UE and AMF, N2 is the interaction interface between (R)AN and AMF, N3 is the interaction interface between (R)AN and UPF, N4 is the interaction interface between SMF and UPF, and N6 is the interaction interface between UPF and the external data network (DN). DN is not shown in the figure.
[0036] Optionally, each second SNPN may be deployed in a security domain, such as Figure 1 As shown in . The range of the security domain where the first SNPN is located can cover the security domain where the second SNPN is located.
[0037] After introducing the terminal access authentication system, refer to Figure 2 , introduces the specific steps of the terminal access authentication method. Figure 2 This is a flow chart of a terminal access authentication method provided in an embodiment of the present application.
[0038] S201. The UE in the first SNPN sends an access request to the first SNPN. The first SNPN determines the subscription data of the UE according to the access request and establishes a PDU session in the first SNPN according to the subscription data of the UE. The access request includes the SUPI of the UE.
[0039] Optionally, when the UE enters a security domain for the first time, it needs to first enter the security domain where the first SNPN is located and complete authentication. In this case, the first SNPN serves as a bootstrap network.
[0040] Optionally, the subscription data of the UE includes the UE's Subscription Permanent Identifier (SUPI) and identifiers of networks accessible to the UE. For example, the subscription data of the UE includes the SUPI of the UE, an identifier of a first SNPN accessible to the UE, and an identifier of a second SNPN-1.
[0041] Optionally, in the data table corresponding to the first SNPN maintained by the network management server, the subscription data of multiple UEs may be pre-stored, and the data table corresponding to the first SNPN may be synchronized to the UDM in the first SNPN, such as Figure 1 The multiple UEs may be input by a user and may be connected to UEs in various SUPIs.
[0042] Optionally, the user can send an access request to the (R)AN and the SMF.
[0043] Optionally, the first SNPN may be searched in the data table according to the SUPI in the access request of the UE. If the SUPI in the access request exists in the pre-stored subscription data, the subscription data corresponding to the SUPI is used as the subscription data of the UE.
[0044] Optionally, the first SNPN selects a target UPF based on the UE's subscription data and basic information of each candidate UPF, and establishes an Ethernet-type PDU session based on the target UPF. The candidate UPF is the UPF in the first SNPN, and its basic information includes location information, current load, and other information.
[0045] Optionally, after the PDU session in the first SNPN is established, the access rights of the UE are authenticated.
[0046] S202: The UE sends an EAP request message to the first SNPN. The first SNPN creates a local data record according to the EAP request message and sends the UE's EAP request message to the network management server. The local data record includes the UE's MAC address and the UE's PDU session identifier.
[0047] Optionally, the EAP request message may be encapsulated by the Extensible Authentication Protocol over LAN (EAPoL) protocol. The EAP request message may include an 802.1x authentication frame, in which the value of the EAEEthernet Type field is 0x888E.
[0048] Optionally, local data records can be<MAC, PDU Session ID> , where MAC is the MAC address of the UE, which may be the source MAC address of the EAP request message, and PDU Session ID may be the PDU session identifier established between the UE and the UPF.
[0049] S203: The network management server forwards the EAP request message of the UE to the AAA server. The AAA server determines whether the EAP request is valid. If so, the network management server creates context information of the UE. The context information of the UE includes the MAC address of the UE.
[0050] Optionally, the network management server receives the EAP request message sent by the first SNPN. As an optional implementation, the network management server can determine whether the message contains an 802.1x authentication frame by detecting whether the value of the PAE Ethernet Type field in the received message is 0x888E. If so, the network management server forwards the EAP request message to the AAA server.
[0051] As an optional implementation, the EAP request message may also include a username and password, which may be encrypted. After receiving the EAP request message, the AAA server decrypts the username and password and searches a pre-stored database based on the decrypted username and password. If the username and password are found, the UE's EAP request is valid. If not, the UE's EAP request is invalid.
[0052] Optionally, the AAA server may generate an EAP response message according to the validity of the EAP request, and send the EAP response message to the network management server.
[0053] S204. The network management server obtains the UE's SUPI from the first SNPN based on the UE's MAC address, and determines the identifier of the target SNPN according to the UE's SUPI. The target SNPN is an SNPN that the UE can access, and the target SNPN is a second SNPN. The network management server writes the UE's contract data into the data table corresponding to the target SNPN in the network management server, and synchronizes the data table corresponding to the target SNPN in the network management server to the UDM in the target SNPN.
[0054] Optionally, after synchronizing the target SNPN data table to the UDM in the target SNPN, the UE may initiate an access request in the target SNPN and establish a PDU session in the target SNPN.
[0055] Optionally, the data table corresponding to the target SNPN in the network management server can be synchronized to the UDM in the target SNPN through a data synchronization mechanism, wherein the data synchronization mechanism can be a replica set mechanism.
[0056] As an optional implementation manner, the network management server may first obtain the PDU session identifier corresponding to the MAC address from the first SNPN based on the MAC address of the UE, and then obtain the SUPI corresponding to the PDU session identifier based on the PDU session identifier of the UE.
[0057] As an optional implementation manner, the network management server may search the first SNPN based on the acquired SUPI, and use the retrieved identifier of the network corresponding to the SUPI as the identifier of the target SNPN.
[0058] Optionally, after the target SNPN is determined, the UE's contract data is written into the data table corresponding to the target SNPN in the network management server, and the data table corresponding to the target SNPN in the network management server is synchronized to the UDM in the target SNPN. Since the UE has completed 802.1x authentication at this time, the UDM in the target SNPN in the network management server is synchronized to the UDM in the target SNPN, so that when the UE enters the security domain where the target SNPN is located, the SNPN will store the UE's contract data, so that there is no need to perform 802.1x authentication again, and a PDU session can be established and the target SNPN can be accessed.
[0059] In this embodiment, the first SNPN first determines the UE's subscription data based on the access request sent by the UE and establishes a PDU session in the first SNPN based on the UE's subscription data. The first SNPN then creates a local data record based on the EAP request message sent by the UE and sends the UE's EAP request message to the network management server. The network management server forwards the EAP request message to the AAA server. After the AAA server confirms that the EAP request is valid, the network management server creates UE context information and obtains the UE's SUPI from the first SNPN based on the UE's MAC address. It determines the identifier of the target SNPN based on the UE's SUPI, then writes the UE's subscription data into the data table corresponding to the target SNPN in the network management server and synchronizes the data table corresponding to the target SNPN in the network management server to the UDM in the target SNPN. In this embodiment, the UE pre-enters the security domain where the first SNPN is located and completes authentication. When it subsequently enters the security domain where the target SNPN is located, it does not require re-authentication by the AAA server. This method reduces UE operations and reduces the processing load on the AAA server. In addition, this embodiment can implement authentication based on the 802.1x protocol without modifying the UE's 5G protocol stack, with a low deployment threshold and high compatibility.
[0060] Next, methods that can be executed before step S201 are introduced.
[0061] Optionally, the network management server receives subscription data of multiple UEs input by a user.
[0062] Optionally, the network management server writes the contract data of multiple UEs into the data table corresponding to the first SNPN in the network management server, synchronizes the data table corresponding to the first SNPN in the network management server to the UDM in the first SNPN, and synchronizes the data tables corresponding to each second SNPN in the network management server to the UDM in each second SNPN.
[0063] Optionally, before the network management server authenticates the UE, the subscription data of the UE is not stored in the data table corresponding to each second SNPN in the network management server.
[0064] Optionally, in the data table corresponding to the first SNPN in the network management server, the UE's subscription data includes, in addition to the UE's SUPI, the identifier of the first SNPN, and the identifier of the second SNPN that the UE can access, a second SNPN to be authenticated identifier. The second SNPN to be authenticated identifier is used to indicate that the UE needs to perform 802.1x authentication to enter the security domain where the second SNPN is located.
[0065] Optionally, the data table corresponding to the first SNPN in the network management server and the data tables corresponding to each second SNPN in the network management server can serve as the master node, and the UDM in the first SNPN and the UDM in each second SNPN can serve as the slave node. The master node and the slave node establish a data synchronization relationship.
[0066] In this embodiment, the subscription data of multiple UEs are written in advance into a data table corresponding to the first SNPN in the network management server, so that the UE can complete 802.1x authentication when accessing the first SNPN.
[0067] Next, refer to Figure 3 The specific steps of determining the subscription data of the UE according to the access request and establishing the PDU session in the first SNPN according to the subscription data of the UE in S201 are introduced. Figure 3 This is a flow chart of establishing a PDU session in a first SNPN provided by an embodiment of the present application.
[0068] S301. The SMF in the first SNPN generates a first subscription data query request according to the SUPI, sends the first subscription data query request to the UDM in the first SNPN, and receives the subscription data of the UE returned by the UDM in the first SNPN.
[0069] Optionally, after entering the security domain where the first SNPN is located, the UE sends an access request to the first SNPN and sends the SUPI to the SMF of the first SNPN.
[0070] Optionally, the first subscription data query request includes the SUPI of the UE.
[0071] Optionally, the UDM in the first SNPN searches the data table according to the SUPI. If the subscription data corresponding to the SUPI can be retrieved, the subscription data is returned to the SMF as the subscription data of the UE.
[0072] S302. SMF determines the target UPF based on the UE's subscription data.
[0073] Specifically, the UE's subscription data may also include information such as service attributes, network policies, and geographical restrictions. The SMF determines the local target UPF based on the service attributes, network policies, and geographical restrictions in the UE's subscription data, combined with the network topology and load conditions.
[0074] As an optional implementation method, SMF can generate a list of qualified UPFs based on the contract data and network status, and then select the optimal UPF from the UPF list based on strategies such as capability matching, topology optimization, and load balancing, and use the optimal UPF as the target UPF.
[0075] S303. The SMF establishes a PDU session for the UE in the first SNPN based on the target UPF.
[0076] Optionally, the SMF establishes a connection with the target UPF through the N4 interface to implement user plane path configuration.
[0077] In this embodiment, the SMF sends a first contract data query request to the UDM in the first SNPN, and receives the contract data of the UE returned by the UDM, thereby determining the target UPF and establishing a PDU session for the UE in the first SNPN. The process of determining the target UPF has flexible scheduling resources and a high degree of customization.
[0078] Next, the specific process of the first SNPN creating the local data record according to the EAP request message in the above step S202 is introduced.
[0079] Optionally, the target UPF in the first SNPN determines whether the EAP request message contains a target field.
[0080] Specifically, the target UPF in the first SNPN determines whether the "EtherType" field in the EAP request message is 0x888E.
[0081] Optionally, if so, the target UPF creates a local data record based on the EAP request message.
[0082] If yes, the EAP request message contains an 802.1x authentication frame, and the target UPF creates a local data record.
[0083] If not, the EAP request message does not include an 802.1x authentication frame, and the UE will not be authenticated using 802.1x.
[0084] In this embodiment, the target UPF in the first SNPN determines whether the EAP request message contains a target field. If so, the target UPF creates a local data record based on the EAP request message, thereby facilitating the network management server to retrieve the PDU session identifier.
[0085] Next, refer to Figure 4 The specific steps of the network management server creating the UE context information in step S203 are introduced. Figure 4 This is a flow chart of a network management server creating UE context information provided by an embodiment of the present application.
[0086] S401: The network management server determines whether a target field exists in the EAP request message. If so, the authenticator in the network management server sends the EAP request message to the AAA server.
[0087] Specifically, after receiving the EAP request message, the network management server determines whether the "EtherType" field in the EAP request message is 0x888E. If so, the EAP request message contains an 802.1x authentication frame. The authenticator in the network management server then sends the EAP request message to the AAA server.
[0088] S402: The AAA server determines whether the EAP request is valid based on the EAP request message. If so, it generates an EAP response message and sends the EAP response message to the authenticator.
[0089] Optionally, the AAA server can first check whether the format of the EAP request message is legal, then query the locally stored database for the username and password, and determine whether the password in the EAP request message matches the password obtained from the query. If so, the EAP request is legal. If the EAP request is legal, the server generates an EAP response message and sends it to the authenticator in the network management server.
[0090] Optionally, the AAA server may encrypt the EAP response message, and the authenticator in the network management server decrypts the encrypted message after receiving it, thereby obtaining the legitimacy of the EAP request.
[0091] S403: The authenticator creates UE context information according to the EAP response message.
[0092] Optionally, after the context information of the UE is created, a port may be developed according to the context information to allow the UE to access the first SNPN.
[0093] Optionally, the UE context information may further include authentication time and authorization policy, wherein the authorization policy may include bandwidth limitation and the like.
[0094] Optionally, the UE's context information records the UE's MAC address. Even if the UE changes its IP address, the MAC address is always used as a physical layer identifier to ensure that the context is strongly bound to the device.
[0095] In this embodiment, the AAA server determines whether the EAP request is valid according to the EAP request message. If so, the authenticator creates context information of the UE, thereby completing 802.1x authentication of the UE, so that the UE can access the first SNPN.
[0096] Next, refer to Figure 5 The specific process of the network management server obtaining the UE's SUPI from the first SNPN based on the UE's MAC address in step S204 is introduced. Figure 5 This is a flowchart of obtaining the SUPI of a UE provided in an embodiment of the present application.
[0097] S501. The network management server reads the MAC address from the authenticator, generates a first query request, and sends the first query request to the NEF in the first SNPN. The first query request includes the MAC address.
[0098] Specifically, the network management server reads the MAC address from the context information of the UE in the authenticator and generates a first query request.
[0099] S502. The NEF in the first SNPN forwards the first query request to the target UPF, so that the target UPF retrieves the corresponding PDU session identifier in the local data record based on the MAC address.
[0100] Optionally, the NEF in the first SNPN receives the first query request from the network management server and forwards the first query request to the target UPF.
[0101] The target UPF is determined in the above step S302.
[0102] Specifically, the target UPF traverses the local data record based on the MAC address, and uses the PDU session identifier corresponding to the same MAC address in the local data record as the PDU session identifier of the UE.
[0103] S503: The target UPF sends the PDU session identifier to the network management server via the NEF.
[0104] Optionally, the target UPF sends the PDU session identifier to the NEF, and after receiving the PDU session identifier, the NEF sends the PDU session identifier to the first SNPN.
[0105] S504: The network management server generates a second query request and sends the second query request to the SMF through the NEF. The second query request includes a PDU session identifier.
[0106] Optionally, after receiving the PDU session identifier of the UE, the network management server generates a second query request based on the PDU session identifier and sends the second query request to the NEF in the first SNPN. After receiving the second query request, the NEF forwards the second query request to the SMF.
[0107] Optionally, the second query request is used to request to obtain the SUPI of the UE corresponding to the PDU session identifier.
[0108] S505. The SMF determines the SUPI corresponding to the PDU session identifier according to the PDU session identifier, and sends the SUPI to the network management server through the NEF.
[0109] Optionally, when creating a PDU session for the UE, the SMF may record the UE's SUPI and the PDU session identifier as a corresponding record. In step S505, the SMF may search based on the PDU session identifier to determine the correspondence between the PDU session identifier and the SUPI, determine the SUPI corresponding to the PDU session identifier, and send the SUPI to the NEF.
[0110] Optionally, after receiving the SUPI sent by the SMF, the NEF forwards the SUPI to the network management server.
[0111] In this embodiment, the network management server sequentially obtains the PDU session identifier and SUPI of the UE in the first SNPN, thereby determining the subscription data of the UE based on the SUPI and enabling the user to directly access the second SNPN.
[0112] Next, a process of the UE accessing a second SNPN is introduced, wherein the second SNPN is used as the SNPN to be accessed.
[0113] Optionally, the UE initiates an access request in the SNPN to be accessed, and establishes a PDU session in the SNPN to be accessed according to a response result of the access request, where the SNPN to be accessed is one of the second SNPNs.
[0114] Optionally, the access request initiated by the UE in the SNPN to be accessed may be the same as the access request initiated by the UE in the first SNPN. The access request initiated in the SNPN to be accessed includes the SUPI of the UE.
[0115] Optionally, the UE initiates an access request in the SNPN to be accessed. After receiving the access request, the SNPN to be accessed determines whether the UE's subscription data exists in the UDM according to the SUPI. If so, a PDU session of the SNPN to be accessed can be established, and the UE is allowed to access the SNPN to be accessed.
[0116] In this embodiment, after the network management server synchronizes the UE's subscription data with the UDM in the UE's target SNPN, the UE does not need to be authenticated again by the AAA server when accessing the SNPN to be accessed, thereby reducing the workload of the AAA server.
[0117] Next, the process of the UE accessing the SNPN to be accessed is discussed in different situations.
[0118] Optionally, the UE initiates an access request to the SMF in the SNPN to be accessed, where the access request includes the SUPI of the UE.
[0119] Optionally, the SMF determines whether the UE's subscription data exists in the UDM in the SNPN to be accessed based on the SUPI. If so, it determines the target UPF of the UE in the SNPN to be accessed and establishes a PDU session for the UE in the SNPN to be accessed.
[0120] Optionally, when the UDM in the SNPN to be accessed contains the subscription data of the UE, it means that the UE has already performed 802.1x authentication when accessing the first SNPN, and therefore can access the SNPN to be accessed without re-authentication.
[0121] Specifically, the SMF generates a second subscription data query request based on the SUPI and sends it to the UDM. The UDM retrieves the subscription data for each UE from the data table based on the SUPI in the second subscription data query request. If a corresponding SUPI is found, the subscription data corresponding to that SUPI is used as the UE's subscription data. The UDM sends this subscription data to the SMF. After receiving this subscription data, the SMF determines the target UPF in the SNPN to be accessed based on the subscription data and establishes a PDU session for the UE in the SNPN to be accessed based on the target UPF.
[0122] Optionally, if the UDM cannot retrieve the subscription data corresponding to the UE's SUPI in the data table, indicating that the UE has not passed the 802.1x authentication, a retrieval response is returned to the SMF, so that the SMF receives the retrieval response and denies the UE access to the SNPN to be accessed.
[0123] In this embodiment, the UE's subscription data is determined by the UDM in the SNPN to be accessed, so that the SMF establishes the UE's PDU session so that the UE can access the SNPN to be accessed without re-authentication.
[0124] As an optional implementation manner, the specific steps of determining the identifier of the target SNPN according to the SUPI of the UE in the above step S204 are described below.
[0125] Optionally, the network management server uses the SUPI as an index to search whether there is subscription data of the UE corresponding to the SUPI in a data table corresponding to the first SNPN in the network management server.
[0126] As an optional implementation manner, the network management server traverses the SUPI in each subscription data in the data table corresponding to the first SNPN, and for the traversed current SUPI, if the current SUPI is the same as the SUPI of the UE, the subscription data corresponding to the current SUPI is used as the subscription data of the UE.
[0127] Optionally, if so, the identifier of the accessible network in the UE's subscription data is used as the identifier of the target SNPN.
[0128] Optionally, if the data table corresponding to the first SNPN in the network management server contains subscription data of the UE corresponding to the SUPI, the network accessible to the UE in the subscription data of the UE is used as the target SNPN, and the identifier of the target SNPN is used as the identifier of the target SNPN.
[0129] In this embodiment, the identifier of the UE's network accessibility in the UE's contract data in the data table corresponding to the first SNPN in the network management server is used as the identifier of the target SNPN, thereby synchronizing the contract data to the UDM in the target SNPN, so that the UE does not need to be authenticated again when accessing the target SNPN.
[0130] Next, refer to Figure 6 This section introduces the overall process of the terminal access authentication method. Figure 6 This is a flow chart of another terminal access authentication method provided in an embodiment of the present application.
[0131] S601. Receive subscription data of multiple UEs.
[0132] Optionally, the network management server receives subscription data of multiple UEs.
[0133] S602. Write the subscription data of each UE into the data table corresponding to the first SNPN.
[0134] Optionally, the network management server writes the subscription data of each UE into the data table corresponding to the first SNPN.
[0135] S603: Synchronize the data table corresponding to the first SNPN to the UDM.
[0136] Optionally, the network management server synchronizes the data table corresponding to the first SNPN to the UDM in the first SNPN.
[0137] S604: The UE enters the security domain where the first SNPN is located.
[0138] S605: Send an access request.
[0139] Optionally, the UE sends an access request to the SMF in the first SNPN.
[0140] S606: Send a first contract data query request.
[0141] Optionally, the SMF sends a first contract data query request to the UDM.
[0142] S607: Retrieve the UE's subscription data.
[0143] Optionally, the UDM retrieves the UE's subscription data according to the SUPI in the first subscription data query request.
[0144] S608: Send the UE's subscription data.
[0145] Optionally, UDM sends the UE's subscription data to SMF.
[0146] S609: Determine the target UPF and establish a PDF session.
[0147] Optionally, the SMF determines the target UPF based on the UE's subscription data and establishes a PDF session based on the UPF.
[0148] S610: Send an EAP request message.
[0149] Optionally, the UE sends an EAP request message to the target UPF.
[0150] S611. Detect the target field.
[0151] Optionally, the target UPF detects whether the EAP request message includes a target field, and if so, executes S613.
[0152] S612: Create a local data record.
[0153] Optionally, the target UPF creates a local data record according to the EAP request message.
[0154] S613: Send an EAP request message.
[0155] Optionally, the target UPF sends the EAP request message to the network management server.
[0156] S614: Detect the target field.
[0157] Optionally, the network management server detects whether the EAP request message includes a target field, and if so, executes S615.
[0158] S615: Send an EAP request message.
[0159] Optionally, the network management server sends an EAP request message to the authenticator.
[0160] S616: Confirm whether the EAP request is legal.
[0161] Optionally, the AAA server confirms whether the EAP request is valid according to the EAP request message, and if so, executes S617.
[0162] S617: Generate an EAP response message and send it.
[0163] Optionally, the AAA server generates an EAP response message and sends the EAP response message to the authenticator.
[0164] S618: Create UE context information.
[0165] Optionally, the authenticator creates context information of the UE.
[0166] S619: Read the MAC address from the authenticator, generate and send a first query request through the NEF.
[0167] Optionally, the network management server reads the MAC address from the authenticator, generates a first query request, and sends the first query request to the NEF in the first SNPN. The NEF forwards the first query request to the target UPF.
[0168] S620: Determine a PDU session identifier according to the MAC address, and send the PDU session identifier.
[0169] Optionally, the target UPF retrieves from the local data record according to the MAC address, determines the PDU session identifier corresponding to the MAC address, and sends the PDU session identifier to the NEF.
[0170] S621: Generate a second query request according to the PDU session identifier and send it through the NEF.
[0171] Optionally, the network management server generates a second query request according to the PDU session identifier and sends it to the NEF, and the NEF sends the second query request to the SMF.
[0172] S622: Retrieve and send SUPI.
[0173] Optionally, the SMF retrieves the corresponding SUPI according to the PDU session identifier in the second query request, and sends the SUPI to the NEF.
[0174] S623. Retrieve the data table corresponding to the SNPN according to the SUPI to determine the subscription data of the UE.
[0175] Optionally, the network management server retrieves a data table corresponding to the SNPN according to the SUPI to determine the subscription data of the UE.
[0176] S624. Determine the identifier of the target SNPN, write the subscription data of the UE into the data table corresponding to the target SNPN, and synchronize the data table corresponding to the target SNPN to the UDM in the target SNPN.
[0177] S625. The UE enters the security domain where the SNPN to be accessed is located.
[0178] S626: Send an access request.
[0179] Optionally, the UE sends an access request to the base station and the SMF.
[0180] S627. Send a second contract data query request.
[0181] Optionally, the SMF sends a second contract data query request to the UDM.
[0182] S628. Query the UE's subscription data.
[0183] Optionally, if the UDM finds the subscription data corresponding to the SUPI, S629 is executed; if the UDM fails to find the subscription data corresponding to the SUPI, S631 is executed.
[0184] S629: Send the UE's subscription data.
[0185] Optionally, UDM sends the UE's subscription data to SMF.
[0186] S630: Determine the target UPF and establish a PDU session.
[0187] Optionally, the SMF determines the target UPF and establishes a PDU session.
[0188] S631: Send a no result response.
[0189] Optionally, the UDM sends a no result response to the SMF.
[0190] S632: Deny UE access.
[0191] Optionally, the SMF denies UE access.
[0192] An embodiment of the present application also provides a terminal access authentication system, which includes: a network management server, an AAA server, a first SNPN and at least one second SNPN, wherein the network management server, the AAA server and the first SNPN are deployed in the same security domain, and the terminal access authentication system is used to execute the above-mentioned terminal access authentication method.
[0193] The above is only a specific implementation method of the present application, but the protection scope of the present application is not limited thereto. Any technician familiar with this technical field can easily think of changes or replacements within the technical scope disclosed in this application, which should be covered by the protection scope of the present application.
Claims
1. A terminal access authentication method, characterized in that: Applied to a terminal access authentication system, the terminal access authentication system includes: a network management server, an authentication, authorization and accounting AAA server, a first independent non-public network SNPN and at least one second SNPN, wherein the network management server, the AAA server and the first SNPN are deployed in the same security domain; the method includes: The user equipment UE in the first SNPN sends an access request to the first SNPN, and the first SNPN determines the subscription data of the UE according to the access request, and establishes a PDU session in the first SNPN according to the subscription data of the UE, wherein the access request includes the user identity SUPI of the UE; The UE sends an Extensible Authentication Protocol (EAP) request message to the first SNPN; the first SNPN creates a local data record based on the EAP request message, and sends the EAP request message of the UE to the network management server, where the local data record includes the media access control (MAC) address of the UE and the PDU session identifier of the UE; The network management server forwards the EAP request message of the UE to the AAA server, and the AAA server determines whether the EAP request is valid. If so, the network management server creates context information of the UE, where the context information of the UE includes a MAC address of the UE; The network management server obtains the SUPI of the UE from the first SNPN based on the MAC address of the UE, and determines the identifier of the target SNPN according to the SUPI of the UE, where the target SNPN is an SNPN that the UE can access, and the target SNPN is one of the second SNPNs. The network management server writes the contract data of the UE into the data table corresponding to the target SNPN in the network management server, and synchronizes the data table corresponding to the target SNPN in the network management server to the unified data management function UDM in the target SNPN.
2. The terminal access authentication method according to claim 1, wherein: Before the terminal UE in the first SNPN sends the access request to the first SNPN, the method further includes: The network management server receives subscription data of multiple UEs input by a user; The network management server writes the contract data of multiple UEs into the data table corresponding to the first SNPN in the network management server, synchronizes the data table corresponding to the first SNPN in the network management server to the UDM in the first SNPN, and synchronizes the data tables corresponding to each second SNPN in the network management server to the UDM in each second SNPN.
3. The terminal access authentication method according to claim 1, wherein: The first SNPN determines, according to the access request, the subscription data of the UE, and establishes a PDU session in the first SNPN according to the subscription data of the UE, including: The SMF in the first SNPN generates a first subscription data query request according to the SUPI, sends the first subscription data query request to the UDM in the first SNPN, and receives the subscription data of the UE returned by the UDM in the first SNPN; The SMF determines the target data forwarding engine UPF according to the subscription data of the UE; The SMF establishes a PDU session for the UE in the first SNPN based on the target UPF.
4. The terminal access authentication method according to claim 3, wherein: The first SNPN creates a local data record according to the EAP request message, including: The target UPF in the first SNPN determines whether the EAP request message includes a target field; If so, the target UPF creates a local data record based on the EAP request message.
5. The terminal access authentication method according to claim 1, wherein: The network management server forwards the EAP request message of the UE to the AAA server, and the AAA server determines whether the EAP request is valid. If so, the network management server creates context information of the UE, including: The network management server determines whether a target field exists in the EAP request message, and if so, the authenticator in the network management server sends the EAP request message to the AAA server; The AAA server determines whether the EAP request is valid based on the EAP request message, and if so, generates an EAP response message and sends the EAP response message to the authenticator; The authenticator creates context information of the UE according to the EAP response message.
6. The terminal access authentication method according to claim 5, characterized in that: The network management server obtains the SUPI of the UE from the first SNPN based on the MAC address of the UE, including: The network management server reads the MAC address from the authenticator, generates a first query request, and sends the first query request to the NEF in the first SNPN, wherein the first query request includes the MAC address; The NEF in the first SNPN forwards the first query request to the target UPF, so that the target UPF retrieves the corresponding PDU session identifier in the local data record based on the MAC address; The target UPF sends the PDU session identifier to the network management server through the NEF; The network management server generates a second query request and sends the second query request to the SMF through the NEF, where the second query request includes the PDU session identifier; The SMF determines the SUPI corresponding to the PDU session identifier according to the PDU session identifier, and sends the SUPI to the network management server through the NEF.
7. The terminal access authentication method according to claim 1, wherein: The method further comprises: The UE initiates an access request in the SNPN to be accessed, and establishes a PDU session in the SNPN to be accessed according to a response result of the access request, where the SNPN to be accessed is one of the second SNPNs.
8. The terminal access authentication method according to claim 7, wherein: The UE initiates an access request in the SNPN to be accessed, and establishes a PDU session in the SNPN to be accessed according to a response result of the access request, including: The UE initiates an access request to the SMF in the SNPN to be accessed, where the access request includes the SUPI of the UE; The SMF determines whether the UE's subscription data exists in the UDM in the SNPN to be accessed according to the SUPI. If so, it determines the target UPF of the UE in the SNPN to be accessed and establishes a PDU session for the UE in the SNPN to be accessed.
9. The terminal access authentication method according to claim 2, wherein: The determining the identifier of the target SNPN according to the SUPI of the UE includes: The network management server uses the SUPI as an index to search a data table corresponding to a first SNPN in the network management server to determine whether subscription data of the UE corresponding to the SUPI is present; If so, the identifier of the accessible network in the subscription data of the UE is used as the identifier of the target SNPN.
10. A terminal access authentication system, characterized in that: The terminal access authentication system includes: a network management server, an AAA server, a first SNPN and at least one second SNPN, wherein the network management server, the AAA server and the first SNPN are deployed in the same security domain, and the terminal access authentication system is used to execute the terminal access authentication method as described in any one of claims 1-9.