Authentication method and device, communication equipment, storage medium and computer program product
By receiving and verifying the target identifier through network element equipment and initiating the EAP authentication process, the authentication problem of non-3GPP equipment relay access to the network is solved, and secure and reliable network access is achieved.
Patent Information
- Application Number
- CN202410591110.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Priority Date
- 2024-05-09
- Filing Date
- 2024-05-13
- Publication Date
- 2025-11-11
AI Technical Summary
How to enable non-3GPP devices without USIM capabilities to access the network via smart terminal devices or gateway devices for authentication, thus meeting the connectivity requirements of the Internet of Things.
The network element receives the target request message sent by the terminal device, which includes the target identifier. Based on the identifier, it initiates the EAP authentication process, which includes the verification of the terminal device and the individual user or device. Successful EAP authentication is achieved through the authentication response message from the authentication server.
It enables relay access authentication for non-3GPP devices that lack USIM capabilities, ensuring network security and saving resources.
Smart Images

Figure CN120935566A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of communication technology, and in particular to an authentication method, apparatus, communication equipment, storage medium, and computer program product. Background Technology
[0002] With the rapid development of the information and digital age driven by mobile communication technology, the demand for network connectivity for the Internet of Everything is becoming increasingly strong. During the commercialization of 5G, certain individual users who use smart terminal devices to obtain specific network application services and non-3GPP devices that do not have USIM (Universal Subscriber Identity Module) capabilities also hope to access the network via relay through smart terminal devices or gateway devices. Therefore, how to achieve relay access authentication for such individual users or non-3GPP devices has become an urgent problem to be solved. Summary of the Invention
[0003] This application provides an authentication method, apparatus, communication device, storage medium, and computer program product that can achieve relay access authentication for individual users or non-3GPP devices.
[0004] In a first aspect, this application provides an authentication method, the method comprising: a network element receiving a target request message sent by a terminal device, wherein the target request message includes a target identifier, the target identifier being an identifier of an individual user using or accessing the network through the terminal device or an identifier of a device using or accessing the network through the terminal device; and the network element initiating an EAP authentication process based on the target identifier.
[0005] Secondly, this application provides an authentication method, the method comprising: a terminal device sending a target request message to a network element device, wherein the target request message includes a target identifier, the target identifier being the identifier of an individual user using or accessing the network through the terminal device or the identifier of a device using or accessing the network through the terminal device, so that the network element device initiates an EAP authentication process based on the target identifier.
[0006] Thirdly, this application provides an authentication method, the method comprising: an authentication server receiving a second authentication request message sent by a network element device, the second authentication request message including a target identifier, wherein the target identifier is obtained by the network element device from a target request message sent by a terminal device, the target identifier being an identifier of an individual user using or accessing the network through the terminal device or an identifier of a device using or accessing the network through the terminal device, for performing EAP authentication on the individual user or device corresponding to the target identifier; the authentication server sending a second authentication response message to the network element device, wherein, in the case of successful EAP authentication, the second authentication response message includes a first EAP authentication success message, the first EAP authentication success message being used to indicate that the individual user or device corresponding to the target identifier has successfully completed EAP authentication.
[0007] Fourthly, this application provides an authentication device, the device comprising: a receiving module, configured to receive a target request message sent by a terminal device, wherein the target request message includes a target identifier, the target identifier being an identifier of an individual user using or accessing the network through the terminal device or an identifier of a device using or accessing the network through the terminal device; and an execution module, configured to initiate an Extensible Authentication Protocol (EAP) authentication process based on the target identifier.
[0008] Fifthly, this application provides an authentication device, the device comprising: a sending module, used by a terminal device to send a target request message to a network element device, wherein the target request message includes a target identifier, the target identifier being an identifier of an individual user using or accessing the network through the terminal device or an identifier of a device using or accessing the network through the terminal device, so that the network element device initiates an EAP authentication process based on the target identifier.
[0009] Sixthly, this application provides an authentication apparatus, comprising: a receiving module, configured to receive a second authentication request message sent by a network element device, the second authentication request message including a target identifier, wherein the target identifier is obtained by the network element device from a target request message sent by a terminal device, and the target identifier is the identifier of an individual user using or accessing the network through the terminal device or the identifier of a device using or accessing the network through the terminal device, for performing EAP authentication on the individual user or device corresponding to the target identifier; and a sending module, configured to send a second authentication response message to the network element device, wherein, in the case of successful EAP authentication, the second authentication response message includes a first EAP authentication success message, the first EAP authentication success message being used to indicate that the individual user or device corresponding to the target identifier has successfully completed EAP authentication.
[0010] In a seventh aspect, this application provides a communication device, including: a transceiver, a memory, and a processor, wherein the memory stores a computer program, and the processor executes the computer program to control the transceiver to implement the steps of any one of the first, second, or third aspects described above.
[0011] Eighthly, this application provides a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the steps of the method described in any one of the first, second, or third aspects above.
[0012] Ninthly, this application provides a chip including programmable logic circuitry and / or program instructions, which, when the chip is running, can perform the steps of the method described in any one of the first, second, or third aspects above.
[0013] In a tenth aspect, this application provides a computer program product, including a computer program, characterized in that, when executed by a processor, the computer program implements the steps of the method described in any one of the first, second, or third aspects above.
[0014] The aforementioned authentication methods, devices, communication equipment, storage media, and computer program products involve network element devices receiving target request messages sent by terminal devices. These target request messages include target identifiers, which can be identifiers of individual users or devices using or accessing the network through the terminal devices. Subsequently, the network element devices initiate EAP authentication processes based on the target identifiers, thereby achieving relay access authentication for individual users or non-3GPP devices.
[0015] In the eleventh aspect, this application provides an authentication method, the method comprising: a network element receiving a target request message carrying a target identifier sent from a terminal device, or the network element receiving a target request message without a target identifier and a target identifier sent from a terminal device; wherein the target identifier is the identifier of an individual user or device using or accessing the network through the terminal device; and the network element initiating an Extensible Authentication Protocol (EAP) authentication process based on the target identifier.
[0016] In a twelfth aspect, this application provides an authentication method, the method comprising: a terminal device sending a target request message carrying a target identifier to a network element device, or the terminal device sending a target request message without carrying a target identifier and a target identifier to the network element device, so that the network element device initiates an EAP authentication process based on the target identifier; wherein, the target identifier is the identifier of an individual user or device using or accessing the network through the terminal device.
[0017] In a thirteenth aspect, this application provides an authentication method, the method comprising: an authentication server receiving a second authentication request message carrying a target identifier sent by a network element device, or the authentication server receiving a second authentication request message without carrying a target identifier and a target identifier sent by a network element device, for performing EAP authentication on an individual user or device corresponding to the target identifier; wherein, the target identifier is the identifier of an individual user or device using or accessing the network through a terminal device; the authentication server sending a second authentication response message carrying the target identifier to the network element device, or the authentication server sending a second authentication response message without carrying the target identifier and the target identifier to the network element device.
[0018] In a fourteenth aspect, this application provides an authentication device, the device comprising: a receiving module, configured to receive a target request message carrying a target identifier sent from a terminal device, or configured to receive a target request message without a target identifier and a target identifier sent from a terminal device; wherein the target identifier is an identifier of an individual user or device using or accessing the network through the terminal device; and an execution module, configured to initiate an EAP authentication process based on the target identifier.
[0019] In a fifteenth aspect, this application provides an authentication device, the device comprising: a sending module, configured to send a target request message carrying a target identifier to a network element device, or configured to send a target request message without a target identifier and a target identifier to a network element device, so that the network element device initiates an EAP authentication process based on the target identifier; wherein, the target identifier is the identifier of an individual user or device using or accessing the network through the terminal device.
[0020] In a sixteenth aspect, this application provides an authentication device, the device comprising: a receiving module, configured to receive a second authentication request message carrying a target identifier sent by a network element device, or, the authentication server receiving a second authentication request message without carrying a target identifier and a target identifier sent by a network element device, for performing EAP authentication on an individual user or device corresponding to the target identifier; the target identifier being an identifier of an individual user or device using or accessing the network through a terminal device; and a sending module, configured to send a second authentication response message carrying the target identifier to the network element device, or, the authentication server sending a second authentication response message without carrying the target identifier and the target identifier to the network element device.
[0021] In a seventeenth aspect, this application provides a communication device, comprising: a transceiver, a memory, and a processor, wherein the memory stores a computer program, and the processor executes the computer program to control the transceiver to implement the steps of any one of the eleventh, twelfth, or thirteenth aspects described above.
[0022] In an eighteenth aspect, this application provides a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the steps of the method described in any one of the eleventh, twelfth, or thirteenth aspects above.
[0023] In a nineteenth aspect, this application provides a chip including programmable logic circuitry and / or program instructions, which, when the chip is running, can perform the steps of the method described in any one of the eleventh, twelfth, or thirteenth aspects above.
[0024] In a twentieth aspect, this application provides a computer program product, including a computer program, characterized in that, when executed by a processor, the computer program implements the steps of the method described in any one of the eleventh, twelfth, or thirteenth aspects above.
[0025] The aforementioned authentication methods, devices, communication equipment, storage media, and computer program products involve a network element receiving a target request message carrying a target identifier from a terminal device, or receiving a target request message without a target identifier and a target identifier from a terminal device; wherein the target identifier is the identifier of an individual user or device using or accessing the network through the terminal device; and then the network element initiates an EAP authentication process based on the target identifier, thereby achieving relay access authentication for individual users or non-3GPP devices. Attached Figure Description
[0026] Figure 1 This is a schematic diagram of the ProSe relay communication architecture in related technologies;
[0027] Figure 2 This is a diagram illustrating the application environment of an authentication method in one embodiment.
[0028] Figure 3 This is a flowchart illustrating an authentication method in one embodiment;
[0029] Figure 4 This is a schematic diagram of the signaling interaction process of an authentication method in one embodiment;
[0030] Figure 5 This is a schematic diagram of the signaling interaction process of a re-authentication method in one embodiment;
[0031] Figure 6 This is a schematic diagram of the architecture of an authentication method in one embodiment;
[0032] Figure 7 This is a structural block diagram of an authentication device in one embodiment;
[0033] Figure 8 This is a structural block diagram of another authentication device in one embodiment;
[0034] Figure 9 This is a structural block diagram of another authentication device in one embodiment;
[0035] Figure 10 This is an internal structure diagram of a communication device in one embodiment;
[0036] Figure 11 This is a schematic structure of a chip in one embodiment;
[0037] Figure 12 A flowchart illustrating an authentication method in one embodiment;
[0038] Figure 13 A schematic diagram of the signaling interaction process of an authentication method in one embodiment;
[0039] Figure 14 A schematic diagram of the signaling interaction process of a re-authentication method in one embodiment;
[0040] Figure 15 This is a structural block diagram of an authentication device in one embodiment;
[0041] Figure 16 This is a structural block diagram of another authentication device in one embodiment;
[0042] Figure 17 This is a structural block diagram of another authentication device in one embodiment. Detailed Implementation
[0043] To make the objectives, technical solutions, and advantages of this application clearer, the following detailed description is provided in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative and not intended to limit the scope of this application.
[0044] Currently, 3GPP (3rd Generation Partnership Project) TS 33.503 (R17) defines the 5G ProSe (Proximity Services) relay communication scheme. This means that when a terminal is outside the network coverage area and cannot directly connect to the network, it can access the network through a terminal device with relay function. The terminal device outside the network coverage area is called the remote terminal device, and the terminal device with relay function is called the relay terminal device.
[0045] like Figure 1The diagram illustrates the ProSe relay communication architecture in related technologies. The remote terminal device establishes a connection with the relay terminal device via the PC5 interface. The relay terminal device establishes a connection with the base station via the Uu interface. The base station establishes a connection with the 5GC (5G Core, 5G core network). The 5GC establishes a connection with the data network via the N6 interface. An end-to-end security mechanism is implemented between the remote terminal device and the 5GC, and a PC5 link security mechanism is implemented between the remote terminal device and the relay terminal device.
[0046] However, for remote terminal devices to communicate with the network via relay terminal devices, the remote terminal devices must have USIM (Universal Subscriber Identity Module) capabilities. This is because 5GS (5G System) authentication for relay access of remote terminal devices is based on the unique USIM credentials between the remote terminal device and 5GS. In other words, Figure 1 The remote terminal equipment in the architecture has independent NAS (Non-Access Stratum) connectivity and PDU (Protocol Data Unit) sessions, equivalent to those of 3GPP equipment.
[0047] However, with the rapid development of the information and digital age driven by mobile communication technology, the demand for network connectivity for the Internet of Everything is becoming increasingly strong. During the commercialization of 5G, certain individual users who use smart terminal devices to obtain specific network application services and non-3GPP devices that do not have USIM capabilities also hope to be able to access the network through smart terminal devices or gateway devices. Therefore, how to achieve relay access authentication for such individual users or non-3GPP devices has become an urgent problem to be solved.
[0048] Therefore, it is necessary to propose effective technical means to solve the above problems. The technical solution of this application and how it solves the above technical problems will be described in detail below with specific embodiments. These specific embodiments can be combined with each other, and the same or similar concepts or processes may not be repeated in some embodiments. The embodiments of this application will be described below with reference to the accompanying drawings.
[0049] Figure 2 This is a schematic diagram illustrating an application scenario of an authentication method provided in an embodiment of this application. For example... Figure 2As shown, this scenario includes network element devices, terminal devices, authentication servers, subscription databases, PCF (Policy Control Function), and non-3GPP devices. Data transmission between network element devices, terminal devices, authentication servers, subscription databases, and PCF occurs via the network, as does data transmission between non-3GPP devices and terminal devices.
[0050] Among them, network element equipment refers to the network elements of the core network in the wireless communication network. It can be SMF (Session Management function) or AMF (Access and Mobility Management Function). The wireless communication network can be a Global System for Mobile communication (GSM) or Code Division Multiple Access (CDMA) network, or a Wideband Code Division Multiple Access (WCDMA) network, or a Long Term Evolution (LTE) network, or a 5G New Radio (NR) network. There are no restrictions here.
[0051] Terminal equipment can be a wireless terminal, which can be a device that provides voice and / or other service data connectivity to a user, a handheld device with wireless connectivity, or other processing devices connected to a wireless modem. Wireless terminals can communicate with one or more core networks via a Radio Access Network (RAN). Wireless terminals can be mobile terminals, such as mobile phones (or "cellular" phones) and computers with mobile terminals, for example, portable, pocket-sized, handheld, computer-embedded, or vehicle-mounted mobile devices that exchange voice and / or data with the RAN. Wireless terminals can also be referred to as systems, subscriber units, subscriber stations, mobile stations, mobile devices, remote stations, remote terminals, access terminals, user terminals, user agents, user devices, or user equipment, without limitation herein.
[0052] The authentication server can be a DN-AAA (Data Network-Authentication, Authorization, Accounting) server or an AUSF (Authentication Server Function).
[0053] The subscription database can be a UDM (Unified Data Management), a UDR (Unified Data Repository), or a specific network element with data storage capabilities, such as a DN-DB (Data Node-DataBase). This network element can be deployed inside the operator's network or deployed outside the operator's network by the operator in cooperation with a third party.
[0054] Non-3GPP equipment refers to equipment that does not have USIM capability, NAS connection, independent PDU session, and cannot directly interact with core network equipment.
[0055] In one embodiment, such as Figure 3 As shown, an authentication method is provided, which is applied to... Figure 2Taking network element devices as an example, the explanation includes the following steps:
[0056] Step 301: The network element device receives a target request message sent by the terminal device. The target request message includes a target identifier, which is the identifier of an individual user accessing the network through the terminal device or the identifier of a device accessing the network through the terminal device.
[0057] In this context, network element equipment can be either the SMF (Smart Component Provider) or the AMF (Agency Component Provider) within the 5GC. Terminal equipment refers to relay terminal equipment, i.e., smart terminal equipment or gateway equipment; gateway equipment can be a 5G home gateway device. Individual users accessing the network through terminal equipment are specific individual users using smart terminal equipment to obtain specific network application services. Devices accessing the network through terminal equipment are non-3GPP devices that obtain specific network application services through smart terminal equipment or gateway equipment. Non-3GPP devices refer to devices without USIM capabilities, and can be called remote terminal devices without USIM capabilities.
[0058] The identifier of an individual user accessing the network through a terminal device can be a user identifier or a temporary user identifier. The identifier of a device accessing the network through a terminal device can be a device identifier or a temporary device identifier. In other words, the target identifier can be a user identifier, a temporary user identifier, a device identifier, or a temporary device identifier.
[0059] User identifiers or device identifiers can be allocated, generated, and managed on the UDM side or the application service side of 5GC.
[0060] The target request message is either a PDU session establishment request message or a PDU session modification request message. The target request message may also include at least one of the following: a specific identifier, service information, and authentication server information. The specific identifier is used to instruct the network element to initiate an EAP authentication process based on the target identifier; the service information is the data network name related to the requested service; and the authentication server information is used by the network element to send an EAP authentication request message to the authentication server indicated by the authentication server information during the EAP authentication process.
[0061] Optionally, after obtaining the identifier of the individual user or the identifier of the device, the terminal device sends a PDU session establishment request message or a PDU session modification request message containing the target identifier to the network element device, so that the network element device can receive the PDU session establishment request message or PDU session modification request message containing the target identifier sent by the terminal device.
[0062] Step 302: The network element device initiates the EAP authentication process based on the target identifier.
[0063] EAP stands for Extensible Authentication Protocol.
[0064] Optionally, after receiving the target identifier, the network element can either directly initiate the EAP authentication process based on the target identifier, or verify the terminal device and the individual user or device corresponding to the target identifier before initiating the EAP authentication process based on the target identifier; this is not limited here. Preferably, verifying the terminal device and the individual user or device corresponding to the target identifier before initiating the EAP authentication process based on the target identifier ensures network security.
[0065] For example, a network element initiates an EAP authentication process based on a target identifier, including: the network element sending a second authentication request message to the authentication server, the second authentication request message including the target identifier; the network element receiving a second authentication response message sent by the authentication server; if the second authentication response message is a first EAP authentication success message, the network element sending a target response message to the terminal device, instructing the terminal device to forward the data between the individual user or device corresponding to the target identifier and the network side.
[0066] In the above authentication method, the network element receives a target request message sent by the terminal device. The target request message includes a target identifier, which is the identifier of an individual user accessing the network through the terminal device or the identifier of a device accessing the network through the terminal device. Then, the network element initiates the EAP authentication process based on the target identifier, thereby realizing the relay access authentication of individual users or non-3GPP devices.
[0067] In one embodiment, the network element initiates an Extensible Authentication Protocol (EAP) authentication process based on the target identifier, including: the network element verifies the terminal device and the individual user or device corresponding to the target identifier; if the verification is successful, the network element initiates the EAP authentication process based on the target identifier.
[0068] In an optional embodiment, if the target request message further includes a specific identifier, the network element verifies the terminal device and the individual user or device corresponding to the target identifier, including:
[0069] Network element devices determine whether a terminal device is authorized to provide network access services to an individual user or device corresponding to a target identifier by checking the terminal device's subscription data; network element devices also determine whether an individual user or device corresponding to a target identifier is authorized to use the network access services provided by the terminal device by checking whether the terminal device's subscription data is associated with the configuration data of the individual user or device corresponding to the target identifier.
[0070] If the terminal device is authorized to provide network access services to the individual user or device corresponding to the target identifier, and the individual user or device corresponding to the target identifier is authorized to use the network access services provided by the terminal device, then the verification is successful.
[0071] In another optional embodiment, if the target request message does not include a specific identifier, the network element verifies the terminal device and the individual user or device corresponding to the target identifier, including:
[0072] The network element device determines whether the terminal device is authorized to provide network access services to the individual user or device corresponding to the target identifier by checking the subscription data of the terminal device; the network element device determines whether the individual user or device corresponding to the target identifier is authorized to use the network access services provided by the terminal device by checking whether the subscription data of the terminal device is associated with the configuration data of the individual user or device corresponding to the target identifier; and the network element device determines whether the individual user or device corresponding to the target identifier has been authenticated within the validity period based on the authentication result of the individual user or device corresponding to the target identifier.
[0073] If the terminal device is authorized to provide network access services to the individual user or device corresponding to the target identifier, the individual user or device corresponding to the target identifier is authorized to use the network access services provided by the terminal device, and the individual user or device corresponding to the target identifier has not been authenticated within the validity period, then the verification is successful.
[0074] To avoid any misunderstanding regarding the statement "verification is successful if the individual user or device corresponding to the target identifier is not authenticated within the validity period," the verification process is further explained here. The network element device's actions of "determining whether the terminal device is authorized to provide network access services to the individual user or device corresponding to the target identifier" and "determining whether the individual user or device corresponding to the target identifier is authorized to use the network access services provided by the terminal device" aim to determine whether to accept the target request message sent by the terminal device. If the terminal device is authorized to provide network access services to the individual user or device corresponding to the target identifier, and the individual user or device corresponding to the target identifier is authorized to use the network access services provided by the terminal device, then the target request message sent by the terminal device needs to be accepted. Conversely, if not, then the target request message sent by the terminal device does not need to be accepted, and a target request rejection message is sent to the terminal device.
[0075] When it is necessary to accept target request messages sent by terminal devices, the network element device also needs to "determine whether the individual user or device corresponding to the target identifier has been authenticated within the validity period" to determine whether to initiate the EAP authentication process. If it has not been authenticated within the validity period, the EAP authentication process is initiated. If it has been authenticated within the validity period, the target request reception message is sent to the terminal device to avoid having to go through the authentication process every time it accesses in the short term, so as to save network resources.
[0076] The subscription data of the terminal device is stored in the UDM or locally on the network element. The configuration data of the individual user or device corresponding to the target identifier is stored in the subscription database, that is, in the UDM, UDR, or a specific network element with data storage function.
[0077] The network element determines whether a terminal device is authorized to provide network access services to an individual user or device corresponding to a target identifier by checking the terminal device's subscription data. This includes: the network element determining whether a terminal device is authorized to provide network access services to an individual user or device corresponding to a target identifier by checking the terminal device's subscription data stored locally; or, the network element sending a first verification request to the UDM, the first verification request instructing the UDM to determine whether the terminal device is authorized to provide network access services to an individual user or device corresponding to a target identifier based on the terminal device's subscription data, receiving a first verification result sent by the UDM, and determining whether the terminal device is authorized to provide network access services to an individual user or device corresponding to a target identifier based on the first verification result.
[0078] The network element determines whether the individual user or device corresponding to the target identifier is authorized to use the network access service provided by the terminal device by checking whether the subscription data of the terminal device is associated with the configuration data of the individual user or device corresponding to the target identifier. This includes: the network element checking whether the subscription data of the terminal device stored locally is associated with the configuration data of the individual user or device corresponding to the target identifier; if they are associated, the network element determines that the individual user or device corresponding to the target identifier is authorized to use the network access service provided by the terminal device; or, the network element sending a second verification request to the subscription database, the second verification request instructing the subscription database to check whether the subscription data of the terminal device is associated with the configuration data of the individual user or device corresponding to the target identifier; receiving the second verification result sent by the subscription database; and determining whether the individual user or device corresponding to the target identifier is authorized to use the network access service of the terminal device based on the second verification result.
[0079] It is understood that network element devices can also send a third verification request to the UDM. The third verification request is used to instruct the UDM to determine whether the terminal device is authorized to provide network access services based on the terminal device's subscription data, and to instruct the UDM to check whether the subscription data is associated with the configuration data of the individual user or device corresponding to the target identifier. The device receives the third verification result sent by the UDM and determines whether the terminal device is authorized to provide network access services and whether the subscription data is associated with the configuration data of the individual user or device corresponding to the target identifier based on the third verification result.
[0080] The authentication result includes either authentication success information or authentication failure information. Authentication success information includes the authentication success time parameter.
[0081] The network element determines whether the individual user or device corresponding to the target identifier has been authenticated within the validity period based on the authentication result of the individual user or device corresponding to the target identifier. This includes: if the authentication result includes authentication success information, determining whether the individual user or device corresponding to the target identifier has been authenticated within the validity period based on the authentication success time parameter in the authentication success information; if the authentication result includes authentication failure information, determining that the individual user or device corresponding to the target identifier has not been authenticated within the validity period.
[0082] It should be noted that if, during the verification process between the network element and the individual user or device corresponding to the target identifier, the network element discovers that the current request session requires secondary authentication of the terminal device, such as the terminal device triggering an EAP authentication process for the user identifier to the DN-AAA server through the network element, the DN-AAA server needs to perform secondary authentication on the terminal device first to determine whether the terminal device is authorized to access the current data network. If the terminal device is not authorized to access the current data network, the EAP authentication process initiated by the terminal device will not be accepted.
[0083] In this embodiment, by verifying the terminal device and the individual user or device corresponding to the target identifier, if the verification is successful, the network element device initiates the EAP authentication process based on the target identifier, which can ensure network security.
[0084] In one embodiment, the target identifier and the configuration data of the individual user or device corresponding to the target identifier are described in detail.
[0085] If the target identifier is the identifier of an individual user accessing the network through a terminal device, then the configuration data of the individual user corresponding to the target identifier includes at least one of the individual user's user identifier, temporary user identifier, and authentication result. The target identifier can be either a user identifier or a temporary user identifier.
[0086] The User Identity (UID) is used to identify the current user within the 5G system content. The Temporary User Identity (TUID) is a temporary identifier created by temporarily encrypting the User Identity. It has a certain validity period and is generated and stored in the individual user's configuration data after authentication to provide privacy protection for future access. The authentication result indicates whether the user has been authenticated within the validity period and also indicates whether the current User Identity has been activated.
[0087] The configuration data for individual users also includes at least one of the following: user application layer identifier, group identifier, service information, session policy, security policy, access policy, and security credentials.
[0088] The User Application Identity (UAID) is used to identify the current user at the application layer. It's important to note that there is a mapping relationship between the UAID and the UAID.
[0089] A group ID is used when an individual user corresponding to a target ID belongs to a certain group and differentiated processing needs to be performed based on group information. In such cases, an associated group ID needs to be added.
[0090] Service info limits the types of services that use individual user configuration data and stores network requirement information related to the service, such as QoS.
[0091] Session policies include QoS, traffic splitting rules, and access control policies.
[0092] Security policies include authentication methods and related key processing requirements.
[0093] Access policies include restrictions on the use of the current service, such as restricting the use of the current service to a specific geographical location or network.
[0094] Security credentials are pre-configured on both the network side and the user terminal side for two-way authentication between the network and the user. Security credentials can be generated, allocated, and managed by the operator's 5GC or by the application side. When generated by the application side, a trust relationship and a secure interaction environment are required between the operator and the application side.
[0095] If the target identifier is the identifier of a device accessing the network through a terminal device, then the configuration data of the device corresponding to the target identifier includes at least one of the device identifier, temporary device identifier, and authentication result; the target identifier is a device identifier or a temporary device identifier.
[0096] The device identifier is used to identify non-3GPP devices. The temporary device identifier is a temporary identifier formed by temporarily encrypting the device identifier; it has a certain validity period and is generated and stored in the device's configuration data after authentication to provide privacy protection for subsequent access. The authentication result indicates whether the device has been successfully authenticated.
[0097] The device's configuration data also includes at least one of the following: device group identifier, service information, session policy, security policy, access policy, and security credentials.
[0098] The group identifier, service information, session policy, security policy, and access policy are similar to those of the individual user in the configuration data of the individual user mentioned above, and will not be described again here.
[0099] Security credentials are pre-configured on the network side and non-3GPP equipment side for two-way authentication between network and non-3GPP equipment. Security credentials can be generated, allocated, and managed by the operator's 5GC or by the application side. When generated by the application side, a trust relationship and a secure interaction environment are required between the operator and the application side.
[0100] In one embodiment, after the above verification is successful, the method further includes the network element device generating a transaction identifier based on the target identifier; the transaction identifier is used by the network element device to identify and manage the EAP session of the individual user or device corresponding to the target identifier.
[0101] In one embodiment, after the above verification is successful, the network element initiates an EAP authentication process based on the target identifier, including one of the following two implementation methods:
[0102] In the first method, the network element sends a first authentication request message to the terminal device based on the target identifier; the network element receives a first authentication response message from the terminal device, the first authentication response message including the target identifier.
[0103] The network element sends a second authentication request message to the authentication server, the second authentication request message including the target identifier; the network element receives a second authentication response message sent by the authentication server.
[0104] If the second authentication response message is a first EAP authentication success message, which indicates that the personal user or device corresponding to the target identifier has successfully completed EAP authentication, then the network element sends a target response message to the terminal device. The target response message includes a second EAP authentication success message obtained by the network element based on the first EAP authentication success message. The second EAP authentication success message is used to instruct the terminal device to forward the data between the personal user or device corresponding to the target identifier and the network side. Both the first and second EAP authentication success messages include the target identifier.
[0105] In the second approach, the network element device no longer needs to send the first authentication request message to the terminal device, but instead directly sends the second authentication request message to the authentication server and receives the second authentication response message from the authentication server.
[0106] Specifically, when a network element sends a first authentication request message to the individual user or device corresponding to the target identifier via a terminal device, it can carry object indication information. This object indication information can be carried in the first authentication request message or in the NAS message carrying the first authentication request message. Similarly, when a network element sends a second authentication request message to the authentication server, it can also carry object indication information. The object indication information can be used to inform the recipient that the object currently undergoing EAP authentication is the individual user or device corresponding to the target identifier.
[0107] Before sending the second authentication request message to the authentication server, the network element device also needs to obtain the address information of the authentication server. Specifically, the network element device can obtain the address information from the authentication server information in the target request message, or it can determine the address information based on the type of the target identifier.
[0108] The specific implementation method for determining the address information based on the type of the target identifier by the network element device can be as follows: the authentication server includes an AUSF or a DN-AAA server, and the network element device sends a second authentication request message to the authentication server, including: if the target identifier is the identifier of an individual user accessing the network through a terminal device, the network element device sends a second authentication request message to the AUSF; if the target identifier is the identifier of a device accessing the network through a terminal device, the network element device sends a second authentication request message to the DN-AAA server.
[0109] After receiving the second authentication request message from the network element, the authentication server verifies whether the individual user or device corresponding to the target identifier is authorized to use the network access service. If so, the authentication server sends a second authentication response message to the network element, including the first EAP authentication success message; if not, the authentication server sends a second authentication response message to the network element, including the EAP authentication failure message. Upon receiving the second authentication response message including the first EAP authentication success message, the network element sends a target response message to the terminal device, including the second EAP authentication success message. The first and second EAP authentication success messages can be the same or different, and this is not limited here. In addition to the target identifier, the first and second EAP authentication success messages may also include a master key (MSK).
[0110] In one embodiment, after receiving a second authentication response message including a first EAP authentication success message, the network element performs at least one of the following:
[0111] Network element devices associate target identifiers with session context information of terminal devices to perform at least one of the following on network access traffic of individual users or devices corresponding to the target identifier: traffic identification, QoS management and security tracing.
[0112] Based on the first EAP authentication success message, the network element device stores the authentication result of the individual user or device corresponding to the target identifier. The authentication result includes information indicating that the authentication status of the individual user or device corresponding to the target identifier is successful.
[0113] The network element sends the authentication result of the individual user or device corresponding to the target identifier to the subscription database. The subscription database updates the authentication result in the configuration data of the individual user or device corresponding to the target identifier based on the received authentication result.
[0114] The network element sends a session policy information request to the PCF corresponding to the target identifier for the individual user or device, in order to obtain the session policy information of the individual user or device corresponding to the target identifier; wherein, the session policy information is used by the network element for subsequent PDU session management process.
[0115] In one embodiment, if the target request message is a PDU session establishment request message or a PDU session modification request message, the method further includes, before the network element sends the target response message to the terminal device, the network element establishing or modifying the PDU session of the terminal device. Therefore, the target response message is a PDU session establishment acceptance message or a PDU session modification acceptance message.
[0116] After receiving the target response message, the terminal device indicates that the individual user or device corresponding to the target identifier and the network have completed two-way authentication. Therefore, the terminal device can forward the data between the individual user or device corresponding to the target identifier and the network side.
[0117] In one embodiment, after two-way authentication is completed between the individual user or device corresponding to the target identifier and the network, the method further includes: when the individual user or device corresponding to the target identifier is triggered to re-authenticate, the network element device re-initiates the EAP authentication process based on the target identifier.
[0118] The specific triggering method can be triggered by network element devices or authentication servers. The triggering reason can be business policy, application service policy, etc., and there is no limitation on the triggering reason here.
[0119] Optionally, the network element device may re-initiate the EAP authentication process based on the target identifier, including: the network element device re-verifies the terminal device and the individual user or device corresponding to the target identifier; if the verification is successful, the network element device may re-initiate the EAP authentication process based on the target identifier.
[0120] The network element re-initiates the EAP authentication process based on the target identifier, including: the network element sending a third authentication request message to the terminal device based on the target identifier, the third authentication request message including the re-authentication identifier and the target identifier; the network element receiving a third authentication response message sent by the terminal device, the third authentication response message including the target identifier.
[0121] The re-authentication identifier is used to inform the terminal device that the individual user or device corresponding to the target identifier needs to be re-authenticated, and to instruct the terminal device to suspend forwarding data between the network element and the network side.
[0122] After receiving the third authentication response message sent by the terminal device, the network element sends a fourth EAP authentication request message to the authentication server. The fourth EAP authentication request message includes a re-authentication identifier and a target identifier. The network element then receives the fourth EAP authentication response message sent by the authentication server. The fourth EAP authentication response message includes the target identifier.
[0123] It should be noted that the process of network element devices re-initiating the EAP authentication process based on the target identifier is similar to the above-mentioned process of network element devices initiating the EAP authentication process based on the target identifier, and will not be described again here.
[0124] In one embodiment, another authentication method is provided, in which the method is applied to Figure 2 Taking a terminal device as an example, the explanation includes the following steps:
[0125] The terminal device sends a target request message to the network element device. The target request message includes a target identifier, which is the identifier of an individual user accessing the network through the terminal device or the identifier of a device accessing the network through the terminal device, so that the network element device can initiate the EAP authentication process based on the target identifier.
[0126] In one embodiment, the target request message also includes a specific identifier, which is used to instruct the network element to initiate an EAP authentication process based on the target identifier.
[0127] In one embodiment, if the target identifier is the identifier of an individual user accessing the network through a terminal device, then the configuration data of the individual user corresponding to the target identifier includes at least one of the individual user's user identifier, temporary user identifier, and authentication result; the target identifier is a user identifier or a temporary user identifier.
[0128] If the target identifier is the identifier of a device accessing the network through a terminal device, then the configuration data of the device corresponding to the target identifier includes at least one of the device identifier, temporary device identifier, and authentication result; the target identifier is a device identifier or a temporary device identifier.
[0129] In one embodiment, after the terminal device sends a target request message to the network element device, the method further includes: the terminal device receiving a target response message sent by the network element device, the target response message including a second EAP authentication success message obtained by the network element device based on a first EAP authentication success message; the first EAP authentication success message is used to indicate that the personal user or device corresponding to the target identifier has successfully completed EAP authentication; the second EAP authentication success message is used to instruct the terminal device to forward the data between the personal user or device corresponding to the target identifier and the network side; wherein both the first EAP authentication success message and the second EAP authentication success message include a target identifier.
[0130] The first and second EAP authentication success messages also include the master key.
[0131] In one embodiment, the method further includes: a terminal device receiving a third authentication request message sent by a network element device based on a target identifier, the third authentication request message including a re-authentication identifier and a target identifier; and the terminal device sending a third authentication response message to the network element device, the third authentication response message including the target identifier.
[0132] In one embodiment, after the terminal device receives a third authentication request message sent by the network element based on the target identifier, the method further includes: the terminal device suspending the forwarding of data between the individual user or device corresponding to the target identifier and the network side.
[0133] In one embodiment, after the terminal device receives the third authentication request message sent by the network element device based on the target identifier, the method further includes: the terminal device sending notification information to the individual user or device corresponding to the target identifier, the notification information being used to notify the individual user or device corresponding to the target identifier to suspend forwarding of data between the individual user or device corresponding to the target identifier and the network side.
[0134] In one embodiment, the terminal device is a smart terminal device or a gateway device, the individual user corresponding to the target identifier is a specific user who uses the smart terminal device to obtain a specific network application service, and the device corresponding to the target identifier is a non-3GPP device that obtains a specific network application service through the smart terminal device or the gateway device. Non-3GPP devices refer to devices that do not have USIM capabilities.
[0135] The authentication method embodiments on the terminal device side described above have been described in detail in the authentication method embodiments on the network device side described above, and will not be repeated here. The following only describes in detail the aspects of the terminal device side not mentioned in the network device side description.
[0136] In one embodiment, before the terminal device sends a target request message to the network element device, the method further includes: obtaining a target identifier; if the target identifier is the identifier of an individual user accessing the network through the terminal device, and the target identifier is a temporary user identifier, then determining whether the temporary user identifier is valid; if invalid, obtaining the user identifier of the individual user corresponding to the target identifier and using the user identifier as the target identifier; if the target identifier is the identifier of a device accessing the network through the terminal device, and the target identifier is a temporary device identifier, then determining whether the temporary device identifier is valid; if invalid, obtaining the device identifier of the device corresponding to the target identifier and using the device identifier as the target identifier.
[0137] In other words, if the obtained temporary user identifier or temporary device identifier is valid, then the temporary user identifier or temporary device identifier is used as the target identifier. If the obtained temporary user identifier or temporary device identifier is invalid, then the user identifier or device identifier is obtained and used as the target identifier.
[0138] Specifically, when a temporary user identifier or a temporary device identifier is invalid, the user identifier can be obtained from the network side based on the temporary user identifier, or the device identifier can be obtained from the network side based on the temporary device identifier.
[0139] To obtain the target identifier, specifically, if the target identifier is the identifier of a device accessing the network through a terminal device, the terminal needs to execute a D2D connection establishment process corresponding to the target identifier, and obtain the target identifier during this process. If the target identifier is the identifier of an individual user accessing the network through a terminal device, the target identifier is obtained directly from the local storage. The D2D connection can be, for example, WLAN or Bluetooth, and this D2D connection already has a security protection mechanism.
[0140] In one embodiment, after obtaining the target identifier, before the terminal device sends a target request message to the network element device, the method further includes: the terminal device determining whether the terminal device's subscription data is associated with the configuration data of the individual user or device corresponding to the target identifier; if so, the terminal device sends a target request message to the network element device.
[0141] Optionally, the terminal device determines whether the subscription data of the terminal device is associated with the configuration data of the individual user or device corresponding to the target identifier based on the target identifier. This includes: the terminal device sending a fourth verification request to the UDM through the AMF, the fourth verification request being used to instruct the UDM to check whether the subscription data is associated with the configuration data of the individual user or device corresponding to the target identifier; receiving the fourth verification result sent by the UDM; and determining whether the individual user or device corresponding to the target identifier is authorized to use the network access service of the terminal device based on the fourth verification result.
[0142] In one embodiment, after obtaining the target identifier but before the terminal device sends a target request message to the network element device, the method further includes:
[0143] The terminal device determines whether the individual user or device corresponding to the target identifier meets the authorization and authentication requirements; if the authorization and authentication requirements are met, the terminal device sends a target request message to the network element device.
[0144] Specifically, the terminal device determines whether the individual user or device corresponding to the target identifier meets the authorization and authentication requirements. If the authorization and authentication requirements are met, the terminal device determines whether the individual user or device corresponding to the target identifier has been authenticated within the validity period based on the authentication results stored locally or on the network side. If the authentication results of the individual user or device corresponding to the target identifier have not been authenticated within the validity period, then the authorization and authentication requirements are met. The network side can be, for example, an AMF (Automatic Familiarization Function).
[0145] The terminal device determines whether the individual user or device corresponding to the target identifier has been authenticated within the validity period based on the authentication result of the individual user or device corresponding to the target identifier stored on the network side. Specifically, the terminal device may send an authentication result request to the network side, which carries the target identifier. After receiving the authentication result request, the network side queries the authentication result of the individual user or device corresponding to the target identifier from the UDM and sends the query result to the network side. The network side then forwards the query result to the terminal device.
[0146] In one embodiment, after the terminal device sends a target request message to the network element device, during the process of the network element device initiating an EAP authentication process based on the target identifier, the method further includes: the terminal device receiving a first authentication request message sent by the network element device based on the target identifier; the terminal device forwarding the first authentication request message to the individual user or device corresponding to the target identifier; the terminal device receiving a first authentication response message sent by the individual user or device corresponding to the target identifier, and forwarding the first authentication response message to the network element device.
[0147] Optionally, the terminal device may forward the first authentication request message to the individual user or device corresponding to the target identifier, which can be implemented in the following two ways:
[0148] The first method involves the terminal device sending a first authentication request message to the individual user or device corresponding to the target identifier based on the target identifier.
[0149] In the second scenario, the terminal device also receives the object indication information mentioned above from the network device side, and the terminal device forwards the first authentication request message to the individual user or device corresponding to the target identifier based on the object indication information.
[0150] In one embodiment, after the terminal device receives the target response message sent by the network element device, the method further includes: the terminal device storing the authentication result of the individual user or device corresponding to the target identifier based on the second EAP authentication success message in the target response message, so as to determine whether the individual user or device corresponding to the target identifier meets the authorization authentication requirements based on the authentication result.
[0151] In one embodiment, after the terminal device receives the target response message sent by the network element device, the method further includes: the terminal device re-establishing the D2D connection based on the master key for security protection, which can further enhance the link security between the terminal device and the device corresponding to the target identifier.
[0152] In one embodiment, after the terminal device receives the target response message sent by the network element device, the method further includes: if the target identifier included in the second EAP authentication success message is a temporary user identifier of an individual user, then the terminal device sends the temporary user identifier to the individual user corresponding to the target identifier; if the target identifier included in the second EAP authentication success message is a temporary device identifier of a device, then the terminal device sends the temporary device identifier to the device corresponding to the target identifier.
[0153] The purpose of this embodiment is that if the individual user or device corresponding to the target identifier is authenticating for the first time, the target identifier included in the second authentication request message sent by the network element device to the authentication server must be a user identifier or a device identifier. In order to protect the privacy and security of the network and individual users / devices, the authentication server will generate a temporary user identifier or a temporary device identifier based on the target identifier and send the temporary user identifier or temporary device identifier to the network element device. The network element device will send the temporary user identifier or temporary device identifier to the terminal device, and the terminal device will then forward the temporary user identifier or temporary device identifier to the individual user or the device corresponding to the target identifier. In this way, the individual user or device corresponding to the target identifier can directly send the temporary user identifier or temporary device identifier to the terminal device in the next authentication process. After the terminal device sends the temporary user identifier or temporary device identifier to the network side, the network side can directly parse the user identifier or device identifier based on the temporary user identifier or temporary device identifier and then perform the EAP authentication process based on the user identifier or device identifier.
[0154] Additionally, it's worth noting that the authentication server generates a temporary user identifier or temporary device identifier based on the target identifier. Specifically, the authentication server can generate a temporary user identifier based on the master key and the user identifier, or a temporary device identifier based on the master key and the device identifier. Furthermore, the generated temporary user identifier or temporary device identifier is stored in the configuration data of the individual user or device. Specifically, the authentication server, network element device, or terminal device can send storage instruction information including the temporary user identifier or temporary device identifier to the subscription database. This storage instruction information instructs the subscription database to store the temporary user identifier or temporary device identifier in the configuration data of the individual user or device.
[0155] In one embodiment, yet another authentication method is provided, in which the method is applied to Figure 2 Taking the authentication server in the example, the following steps are included:
[0156] The authentication server receives a second authentication request message sent by the network element device. The second authentication request message includes a target identifier, wherein the target identifier is obtained by the network element device from the target request message sent by the terminal device. The target identifier is the identifier of the individual user accessing the network through the terminal device or the identifier of the device accessing the network through the terminal device, and EAP authentication is performed for the individual user or device corresponding to the target identifier.
[0157] The authentication server sends a second authentication response message to the network element device. If the EAP authentication is successful, the second authentication response message includes a first EAP authentication success message, which indicates that the personal user or device corresponding to the target identifier has successfully completed EAP authentication.
[0158] In one embodiment, the authentication server sends a second authentication response message to the network element device, including: the authentication server verifying whether the individual user or device corresponding to the target identifier is authorized to use the network access service; if so, the authentication server sends a second authentication response message to the network element device including a first EAP authentication success message.
[0159] In one embodiment, the first EAP authentication success message includes at least one of the following: target identifier; target identifier and master key.
[0160] In one embodiment, if the target identifier is the identifier of an individual user accessing the network through a terminal device, then the target identifier is a user identifier or a temporary user identifier; if the target identifier is the identifier of a device accessing the network through a terminal device, then the target identifier is a device identifier or a temporary device identifier.
[0161] In one embodiment, the terminal device is a smart terminal device or a gateway device, the individual user corresponding to the target identifier is a specific user who uses the smart terminal device to obtain a specific network application service, and the device corresponding to the target identifier is a non-3GPP device that obtains a specific network application service through the smart terminal device or the gateway device. Non-3GPP devices refer to devices that do not have USIM capabilities.
[0162] The authentication method embodiments on the authentication server side described above have been described in detail in the authentication method embodiments on the network device side described above, and will not be repeated here.
[0163] In one embodiment, yet another authentication method is provided, in which the method is applied to Figure 2 Taking UDM as an example, the explanation includes the following steps:
[0164] UDM associates the configuration data of the individual user or device corresponding to the target identifier with the subscription data of the terminal device. This is used by network element devices in the EAP authentication process to verify the terminal device and the individual user or device corresponding to the target identifier based on the subscription data.
[0165] Optionally, through pre-configuration, the network access service provider initiates the process, and the operator's UDM associates the configuration data of the target identifier of the network access service with the personal user or device in the subscription data of the terminal device that supports the network access service.
[0166] To facilitate understanding, the following diagram illustrates the signaling interaction process of an authentication method, combining the authentication methods described above for the network device side, terminal device side, and authentication server side. The authentication process is illustrated using a non-3GPP device without USIM capabilities as an example. Figure 4 As shown.
[0167] Step 401: The terminal device establishes a D2D connection with a non-3GPP device.
[0168] Step 402: The terminal device sends a target request message carrying the target identifier to the network element device (SMF), that is, it sends a PDU session establishment request message or a PDU session modification request message.
[0169] Step 403, SMF verifies the terminal device and non-3GPP devices, including interaction with the subscription database.
[0170] Step 404: If the verification is successful, the SMF generates a transaction identifier based on the target identifier. This transaction identifier is used by the SMF to identify and manage EAP sessions of non-3GPP devices.
[0171] Step 405: SMF sends a second authentication request message to the authentication server.
[0172] Step 406: Non-3GPP devices and the authentication server perform EAP two-way authentication based on application layer credentials, with the terminal device and 5GS responsible for EAP message pass-through.
[0173] Step 407: The authentication server verifies whether the non-3GPP device is authorized to use the network access service. If so, the authentication server sends a second authentication response message to the SMF, including a first EAP authentication success message; if not, the authentication server sends a second authentication response message to the SMF, including an EAP authentication failure message. Optionally, the first EAP authentication success message includes a master key and a temporary device identifier.
[0174] After SMF receives the second authentication response message, which includes the first EAP authentication success message,
[0175] Step 408a: SMF associates the target identifier with the session context information of the terminal device.
[0176] Step 408b: Based on the first EAP authentication success message, the SMF stores the authentication result of the non-3GPP device.
[0177] Optionally, in step 408c, the SMF sends the authentication results of non-3GPP devices to the subscription database.
[0178] Optionally, in step 408d, the SMF sends a session policy information request for non-3GPP devices to the PCF to obtain session policy information for non-3GPP devices.
[0179] Step 409: SMF establishes or modifies the PDU session of the terminal device.
[0180] Step 410: The SMF sends a target response message to the terminal device, which is either a PDU session establishment acceptance message or a PDU session modification acceptance message. The target response message includes a second EAP authentication success message. Optionally, the first EAP authentication success message includes the master key and the temporary device identifier.
[0181] Optionally, in step 411, the terminal device stores the authentication result of the non-3GPP device based on the second EAP authentication success message.
[0182] Optionally, in step 412a, the terminal device re-establishes security protection for the D2D connection based on the master key.
[0183] Optionally, in step 412b, the terminal device sends a temporary device identifier to a non-3GPP device.
[0184] Step 412c: The terminal device forwards data between the non-3GPP device and the network side.
[0185] When a non-3GPP device is triggered for re-authentication, the network element re-initiates the EAP authentication process based on the target identifier. A schematic diagram of the signaling interaction process for the re-authentication method is shown below. Figure 5 As shown.
[0186] Step 501: Two-way authentication is completed between non-3GPP devices and the network.
[0187] Step 502a, SMF triggers re-authentication.
[0188] Step 502b-1: The authentication server triggers re-authentication. Step 502b-2: The authentication server triggers the sending of a re-authentication request to the SMF.
[0189] Step 503: SMF sends a third authentication request message to the terminal device. The third authentication request message includes a re-authentication identifier and a target identifier.
[0190] Step 504: The terminal device suspends forwarding of data between non-3GPP devices and the network side.
[0191] Step 505: The terminal device sends a notification message to the non-3GPP device. The notification message is used to notify the non-3GPP device to suspend the forwarding of data between the non-3GPP device and the network side.
[0192] Step 506: The terminal device sends a third authentication response message to the SMF.
[0193] Step 507, execute with Figure 4 The same steps as steps 403-412.
[0194] It should be understood that, although Figure 3-5 The steps in the flowchart are shown sequentially as indicated by the arrows, but these steps are not necessarily executed in the order indicated by the arrows. Unless otherwise specified herein, there is no strict order in which these steps are executed, and they can be performed in other orders. Figure 3-5 At least some of the steps in the process may include multiple steps or multiple stages. These steps or stages are not necessarily completed at the same time, but may be executed at different times. The execution order of these steps or stages is not necessarily sequential, but may be executed in turn or alternately with other steps or at least some of the steps or stages in other steps.
[0195] Based on the above, the architecture diagram of the authentication method in this application is as follows: Figure 6As shown, a D2D connection is established between the non-3GPP device and the terminal device. The terminal device establishes a connection with the base station through the Uu interface. The base station establishes a connection with the 5GC. The 5GC establishes a connection with the data network through the N6 interface. The data network establishes a network connection with the authentication server. An end-to-end secure connection of the application layer control plane is established between the non-3GPP device and the authentication server.
[0196] In one embodiment, such as Figure 7 As shown, an authentication device 700 is provided, comprising: a receiving module 701 and an execution module 702, wherein the receiving module 701 and the execution module 702 are disposed in a network element device, wherein:
[0197] The receiving module 701 is used to receive a target request message sent by the terminal device, wherein the target request message includes a target identifier, which is the identifier of an individual user using or accessing the network through the terminal device or the identifier of a device using or accessing the network through the terminal device.
[0198] Execution module 702 is used to initiate an Extensible Authentication Protocol (EAP) authentication process based on the target identifier.
[0199] In one embodiment, the execution module 702 is specifically used to verify the terminal device and the individual user or device corresponding to the target identifier; if the verification is successful, the network element device initiates the EAP authentication process based on the target identifier.
[0200] In one embodiment, the execution module 702 is specifically configured to determine whether the terminal device is authorized to provide network access services to the individual user or device corresponding to the target identifier by checking the subscription data of the terminal device; and to determine whether the individual user or device corresponding to the target identifier is authorized to use the network access services provided by the terminal device by checking whether the subscription data of the terminal device is associated with the configuration data of the individual user or device corresponding to the target identifier; if the terminal device is authorized to provide network access services to the individual user or device corresponding to the target identifier, and the individual user or device corresponding to the target identifier is authorized to use the network access services provided by the terminal device, then the verification is successful.
[0201] In one embodiment, the execution module 702 is specifically used to determine whether the personal user or device corresponding to the target identifier has been authenticated within the validity period based on the authentication result of the personal user or device corresponding to the target identifier; if the terminal device is authorized to provide network access services to the personal user or device corresponding to the target identifier, the personal user or device corresponding to the target identifier is authorized to use the network access services provided by the terminal device, and the personal user or device corresponding to the target identifier has not been authenticated within the validity period; then the verification is successful.
[0202] In one embodiment, the target request message also includes a specific identifier, which is used to instruct the network element to initiate an EAP authentication process based on the target identifier.
[0203] In one embodiment, if the target identifier is the identifier of an individual user who uses or accesses the network through a terminal device, then the configuration data of the individual user corresponding to the target identifier includes at least one of the individual user's user identifier, temporary user identifier, and authentication result; the target identifier is a user identifier or a temporary user identifier. If the target identifier is the identifier of a device that uses or accesses the network through a terminal device, then the configuration data of the device corresponding to the target identifier includes at least one of the device's device identifier, temporary device identifier, and authentication result; the target identifier is a device identifier or a temporary device identifier.
[0204] In one embodiment, the execution module 702 is specifically configured to send a first authentication request message to the terminal device based on the target identifier; and receive a first authentication response message sent by the terminal device, wherein the first authentication response message includes the target identifier.
[0205] In one embodiment, the authentication device 700 further includes a generation module for generating a transaction identifier based on the target identifier; the transaction identifier is used by the network element device to identify and manage the EAP session of the individual user or device corresponding to the target identifier.
[0206] In one embodiment, the execution module 702 is specifically configured to send a second authentication request message to the authentication server, the second authentication request message including a target identifier; receive a second authentication response message sent by the authentication server; if the second authentication response message is a first EAP authentication success message, the first EAP authentication success message is used to indicate that the personal user or device corresponding to the target identifier has successfully completed EAP authentication; then send a target response message to the terminal device, the target response message including a second EAP authentication success message obtained by the network element device based on the first EAP authentication success message; the second EAP authentication success message is used to instruct the terminal device to forward the data between the personal user or device corresponding to the target identifier and the network side; wherein both the first EAP authentication success message and the second EAP authentication success message include the target identifier.
[0207] In one embodiment, the first EAP authentication success message and the second EAP authentication success message also include a master key.
[0208] In one embodiment, the authentication server includes an AUSF or a DN-AAA server, and the execution module 702 is specifically configured to send a second authentication request message to the AUSF if the target identifier is the identifier of an individual user using or accessing the network through a terminal device; and to send a second authentication request message to the DN-AAA server if the target identifier is the identifier of a device using or accessing the network through a terminal device.
[0209] In one embodiment, the authentication device 700 further includes an association module for associating the target identifier with the session context information of the terminal device, so as to perform at least one of the following on the network access traffic of the individual user or device corresponding to the target identifier: traffic identification, quality of service (QoS) management and security tracing.
[0210] In one embodiment, the authentication device 700 further includes a storage module for storing the authentication result of the individual user or device corresponding to the target identifier based on the first EAP authentication success message. The authentication result includes information indicating that the authentication status of the individual user or device corresponding to the target identifier is successful.
[0211] In one embodiment, the authentication device 700 further includes a re-authentication module, which is used to re-initiate the EAP authentication process based on the target identifier when the personal user or device corresponding to the target identifier is triggered for re-authentication.
[0212] In one embodiment, the re-authentication module is specifically used for the network element device to send a third authentication request message to the terminal device based on the target identifier, the third authentication request message including a re-authentication identifier and a target identifier; and to receive a third authentication response message sent by the terminal device, the third authentication response message including the target identifier.
[0213] In one embodiment, the re-authentication module is specifically used to send a fourth EAP authentication request message to the authentication server, the fourth EAP authentication request message including a re-authentication identifier and a target identifier; and to receive a fourth EAP authentication response message sent by the authentication server, the fourth EAP authentication response message including the target identifier.
[0214] In one embodiment, the terminal device is a smart terminal device or a gateway device, the individual user corresponding to the target identifier is a specific user who uses the smart terminal device to obtain a specific network application service, and the device corresponding to the target identifier is a non-3GPP device that obtains a specific network application service through the smart terminal device or the gateway device. Non-3GPP device refers to a device that does not have the Global Subscriber Identity Module (USIM) capability.
[0215] The aforementioned generation module, association module, storage module, and re-authentication module are all located in the network device.
[0216] In one embodiment, such as Figure 8 As shown, another authentication device is provided. The authentication device 800 includes: a sending module 801, which is disposed in the terminal device, wherein:
[0217] The sending module 801 is used to send a target request message to the network element device. The target request message includes a target identifier, which is the identifier of an individual user accessing the network through a terminal device or the identifier of a device accessing the network through a terminal device, so that the network element device can initiate an EAP authentication process based on the target identifier.
[0218] In one embodiment, the target request message also includes a specific identifier, which is used to instruct the network element to initiate an EAP authentication process based on the target identifier.
[0219] In one embodiment, the authentication device 800 further includes a first determining module, configured to determine whether the subscription data of the terminal device is associated with the configuration data of the individual user or device corresponding to the target identifier; if so, the terminal device sends a target request message to the network element device.
[0220] In one embodiment, if the target identifier is the identifier of an individual user accessing the network through a terminal device, then the configuration data of the individual user corresponding to the target identifier includes at least one of the individual user's user identifier, temporary user identifier, and authentication result; the target identifier is a user identifier or a temporary user identifier. If the target identifier is the identifier of a device accessing the network through a terminal device, then the configuration data of the device corresponding to the target identifier includes at least one of the device's device identifier, temporary device identifier, and authentication result; the target identifier is a device identifier or a temporary device identifier.
[0221] In one embodiment, the authentication device 800 further includes an acquisition module and a second determination module. The acquisition module is used to acquire a target identifier. The second determination module is used to determine whether a temporary user identifier is valid if the target identifier is an identifier of an individual user accessing the network through a terminal device, and if it is invalid, to acquire the user identifier of the individual user corresponding to the target identifier and use the user identifier as the target identifier. If the target identifier is an identifier of a device accessing the network through a terminal device, to determine whether a temporary device identifier is valid if the target identifier is invalid, to acquire the device identifier of the device corresponding to the target identifier and use the device identifier as the target identifier.
[0222] In one embodiment, if the target identifier is the identifier of a device that accesses the network through a terminal device, the acquisition module is specifically used to execute the point-to-point D2D connection establishment process of the device corresponding to the target identifier, and to acquire the target identifier during the execution of the D2D connection establishment process of the device corresponding to the target identifier.
[0223] In one embodiment, the authentication device 800 further includes a receiving module, configured to receive a first authentication request message sent by a network element device based on a target identifier; forward the first authentication request message to the individual user or device corresponding to the target identifier; and have the terminal device receive a first authentication response message sent by the individual user or device corresponding to the target identifier and forward the first authentication response message to the network element device.
[0224] In one embodiment, the receiving module is further configured to receive a target response message sent by a network element device, the target response message including a second EAP authentication success message obtained by the network element device based on a first EAP authentication success message; the first EAP authentication success message is used to indicate that the personal user or device corresponding to the target identifier has successfully completed EAP authentication; the second EAP authentication success message is used to instruct the terminal device to forward the data between the personal user or device corresponding to the target identifier and the network side; wherein both the first EAP authentication success message and the second EAP authentication success message include a target identifier.
[0225] In one embodiment, the first EAP authentication success message and the second EAP authentication success message also include a master key.
[0226] In one embodiment, the authentication device 800 further includes a storage module for storing the authentication result of the individual user or device corresponding to the target identifier based on the second EAP authentication success message.
[0227] In one embodiment, the authentication device 800 further includes a connection establishment module for security protection of re-establishing the D2D connection based on the master key.
[0228] In one embodiment, the sending module is further configured to send the temporary user identifier to the individual user corresponding to the target identifier if the target identifier included in the second EAP authentication success message is a temporary user identifier of an individual user; and to send the temporary device identifier to the device corresponding to the target identifier if the target identifier included in the second EAP authentication success message is a temporary device identifier of a device.
[0229] In one embodiment, the receiving module is further configured to receive a third authentication request message sent by the network element device based on the target identifier, the third authentication request message including a re-authentication identifier and a target identifier; the sending module is further configured to send a third authentication response message to the network element device, the third authentication response message including the target identifier.
[0230] In one embodiment, the authentication device 800 further includes a pause module for pausing the forwarding of data between the individual user or device corresponding to the target identifier and the network side.
[0231] In one embodiment, the sending module is further configured to send notification information to the individual user or device corresponding to the target identifier. The notification information is used to notify the terminal device to suspend forwarding of data between the individual user or device corresponding to the target identifier and the network side.
[0232] In one embodiment, the terminal device is a smart terminal device or a gateway device, the individual user corresponding to the target identifier is a specific user who uses the smart terminal device to obtain a specific network application service, and the device corresponding to the target identifier is a non-3GPP device that obtains a specific network application service through the smart terminal device or the gateway device. Non-3GPP devices refer to devices that do not have USIM capabilities.
[0233] The aforementioned first determining module, obtaining module, second determining module, receiving module, storage module, connection establishment module, and pause module are all located in the terminal device.
[0234] In one embodiment, such as Figure 9 As shown, another authentication device is provided. The authentication device 900 includes a receiving module 901 and a sending module 902, both of which are located on the authentication server.
[0235] The receiving module 901 is used to receive a second authentication request message sent by the network element device. The second authentication request message includes a target identifier, wherein the target identifier is obtained by the network element device from the target request message sent by the terminal device. The target identifier is the identifier of an individual user accessing the network through the terminal device or the identifier of a device accessing the network through the terminal device, so as to perform EAP authentication for the individual user or device corresponding to the target identifier.
[0236] The sending module 902 is used to send a second authentication response message to the network element device. In the case of successful EAP authentication, the second authentication response message includes a first EAP authentication success message, which is used to indicate that the personal user or device corresponding to the target identifier has successfully completed EAP authentication.
[0237] In one embodiment, the sending module 902 is specifically used to verify whether the individual user or device corresponding to the target identifier is authorized to use the network access service; if so, the authentication server sends a second authentication response message including the first EAP authentication success message to the network element device.
[0238] In one embodiment, the first EAP authentication success message includes at least one of the following: target identifier; target identifier and master key.
[0239] In one embodiment, if the target identifier is the identifier of an individual user accessing the network through a terminal device, then the target identifier is a user identifier or a temporary user identifier; if the target identifier is the identifier of a device accessing the network through a terminal device, then the target identifier is a device identifier or a temporary device identifier.
[0240] In one embodiment, the terminal device is a smart terminal device or a gateway device, the individual user corresponding to the target identifier is a specific user who uses the smart terminal device to obtain a specific network application service, and the device corresponding to the target identifier is a non-3GPP device that obtains a specific network application service through the smart terminal device or the gateway device. Non-3GPP devices refer to devices that do not have USIM capabilities.
[0241] For specific limitations regarding the authentication device, please refer to the limitations on the authentication method above, which will not be repeated here. Each module in the aforementioned authentication device can be implemented entirely or partially through software, hardware, or a combination thereof. These modules can be embedded in or independent of the processor in the computer device in hardware form, or stored in the memory of the computer device in software form, so that the processor can call and execute the operations corresponding to each module.
[0242] Figure 10 This is a schematic diagram of the structure of a communication device provided in an embodiment of this application. The communication device may include a transceiver 1001, a memory 1002, a processor 1003, and at least one communication bus 1004. The communication bus 1004 is used to realize communication connections between components. The memory 1002 may include a high-speed RAM memory, and may also include non-volatile memory (NVM), such as at least one disk storage device. The memory 1002 can store various programs for performing various processing functions and implementing the method steps of this embodiment. In this embodiment, the transceiver 1001 can be a radio frequency processing module or a baseband processing module in the communication device. The transceiver 1001 can be coupled to the processor 1003, and can perform receiving or transmitting actions under the instruction or control of the processor 1003.
[0243] In one embodiment, a communication device is provided in which the processor 1003 executes a computer program and controls the transceiver 1001 to implement the steps of the authentication method described in any one of the network element device side, terminal device side, or authentication server side.
[0244] In one embodiment, a computer-readable storage medium is provided, on which a computer program is stored, which, when executed by a processor, implements the steps of any one of the authentication methods described above on the network element side, terminal device side, or authentication server side.
[0245] In one embodiment, a computer program product containing instructions is also provided, which, when run on a computer, causes the computer to perform the steps of any one of the authentication methods described above on the network element side, terminal device side, or authentication server side.
[0246] In one embodiment, a chip is provided. Figure 11 This is a schematic structural diagram of the chip according to an embodiment of this application. Figure 11 The chip 1100 shown includes a processor 1101, which can call and run computer programs from memory to implement the methods in the embodiments of this application.
[0247] Optionally, such as Figure 11 As shown, chip 1100 may further include memory 1102. Processor 1101 can retrieve and run computer programs from memory 1102 to implement the methods described in this embodiment. Memory 1102 may be a separate device independent of processor 1101, or it may be integrated into processor 1101.
[0248] Optionally, the chip 1100 may further include an input interface 1103. The processor 1101 can control the input interface 1103 to communicate with other devices or chips; specifically, it can acquire information or data sent by other devices or chips. Optionally, the chip 1100 may further include an output interface 1104. The processor 1101 can control the output interface 1104 to communicate with other devices or chips; specifically, it can output information or data to other devices or chips.
[0249] Optionally, the chip 1100 can be applied to the communication device in the embodiments of this application, and the chip 1100 can implement the corresponding processes implemented by the communication device in the various methods of the embodiments of this application. For the sake of brevity, it will not be described in detail here.
[0250] It should be understood that the chip 1100 mentioned in the embodiments of this application can also be called a system-on-a-chip, system chip, chip system, or system-on-a-chip, etc. It should be understood that the processor in the embodiments of this application may be an integrated circuit chip with signal processing capabilities. In the implementation process, each step of the above method embodiments can be completed by the integrated logic circuit in the processor's hardware or by instructions in software form. The processor mentioned above can be a general-purpose processor, a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, or discrete hardware components. It can implement or execute the various methods, steps, and logic block diagrams disclosed in the embodiments of this application. The general-purpose processor can be a microprocessor or any conventional processor, etc. The steps of the methods disclosed in the embodiments of this application can be directly embodied as being executed by a hardware decoding processor, or executed by a combination of hardware and software modules in the decoding processor. The software module can reside in a mature storage medium in the field, such as random access memory, flash memory, read-only memory, programmable read-only memory, electrically erasable programmable memory, or registers. This storage medium is located in memory, and the processor reads information from the memory and, in conjunction with its hardware, completes the steps of the above method.
[0251] In one embodiment, such as Figure 12 As shown, an authentication method is provided, which is applied to... Figure 2 Taking network element devices as an example, the explanation includes the following steps:
[0252] Step 1201: The network element receives a target request message carrying a target identifier from the terminal device, or the network element receives a target request message without a target identifier and a target identifier from the terminal device; wherein, the target identifier is the identifier of an individual user or device that uses or accesses the network through the terminal device.
[0253] Among them, the network element device can be either SMF or AMF in 5GC. The interaction between the terminal device and the network element device can be direct or indirect (that is, the interaction method through intermediate devices, including sending and receiving).
[0254] For example, when the network element is an SMF, and the terminal device and the network element interact directly, the target request message can be a PDU session establishment request message or a PDU session modification request message. That is, the network element receives a PDU session establishment request message or a PDU session modification request message sent by the terminal device.
[0255] When the network element is an SMF (Small and Medium Function), in the case of indirect interaction between the terminal device and the network element, the terminal device sends a first NAS (Non-access stratum) message to the intermediate device AMF (Advanced Management Function). The first NAS message includes a target request message carrying a target identifier, or it includes a target request message without a target identifier and a target identifier. The target request message can be a PDU session establishment request message or a PDU session modification request message. If the target request message carries a target identifier, the intermediate device AMF sends the target request message to the network element; if the target request message does not carry a target identifier, the intermediate device AMF sends the target request message and the target identifier to the network element.
[0256] When the network element device is an AMF, the terminal device interacts directly with the network element device. That is, the terminal device sends a second NAS message to the network element device. The second NAS message includes a target request message carrying a target identifier, or the second NAS message includes a target request message without a target identifier and a target identifier.
[0257] The following embodiments all use the network element device as SMF and are examples of indirect interaction between the terminal device and the network element device. In the indirect interaction between the terminal device and the network element device, the intermediate device forwarding process is omitted.
[0258] The terminal device is a relay terminal device, also known as a smart terminal device or a gateway device. The gateway device can be a 5G home gateway device. The individual user who uses or accesses the network through the terminal device is a specific individual user who uses the smart terminal device to obtain specific network application services. The device that uses or accesses the network through the terminal device is a non-3GPP device that obtains specific network application services through the smart terminal device or gateway device. Non-3GPP devices refer to devices that do not have USIM capabilities and can be called remote terminal devices without USIM capabilities.
[0259] The identifier of an individual user using or accessing the network through a terminal device can be a user identifier or a temporary user identifier. The identifier of a device using or accessing the network through a terminal device can be a device identifier or a temporary device identifier. In other words, the target identifier can be a user identifier, a temporary user identifier, a device identifier, or a temporary device identifier. Among them, the user identifier or device identifier can be allocated, generated, and managed on the 5GC's UDM side or the application service side.
[0260] The target request message may also include at least one of a specific identifier, service information, and authentication server information. The specific identifier is used to instruct the network element to initiate the EAP authentication process based on the target identifier; the service information is the data network name information related to the requested service; and the authentication server information is used by the network element to send an authentication request message to the authentication server indicated by the authentication server information during the EAP authentication process.
[0261] Optionally, after obtaining the identifier of the individual user or the identifier of the device, the terminal device sends a PDU session establishment request message or a PDU session modification request message containing the target identifier to the network element device, so that the network element device can receive the PDU session establishment request message or PDU session modification request message containing the target identifier sent by the terminal device.
[0262] Step 1202: The network element device initiates the EAP authentication process based on the target identifier.
[0263] EAP stands for Extensible Authentication Protocol.
[0264] Optionally, after receiving the target identifier, the network element can either directly initiate the EAP authentication process based on the target identifier, or verify the terminal device and the individual user or device corresponding to the target identifier before initiating the EAP authentication process based on the target identifier; this is not limited here. Preferably, verifying the terminal device and the individual user or device corresponding to the target identifier before initiating the EAP authentication process based on the target identifier ensures network security.
[0265] For example, a network element initiates an EAP authentication process based on a target identifier, including: the network element sending a second authentication request message to an authentication server, the second authentication request message including the target identifier; the network element receiving a second authentication response message sent by the authentication server; if the second authentication response message is a first EAP authentication success message, the network element sending a target response message including the second EAP authentication success message to a terminal device, the second EAP authentication success message being used to instruct the terminal device to forward data between the individual user or device corresponding to the target identifier and the network side, wherein the first EAP authentication success message and the second EAP authentication success message may be the same or different.
[0266] In the above authentication method, the network element receives a target request message carrying a target identifier from the terminal device, or receives a target request message without a target identifier and a target identifier from the terminal device; wherein, the target identifier is the identifier of the individual user or device using or accessing the network through the terminal device; and then the network element initiates the EAP authentication process based on the target identifier, thereby realizing the relay access authentication of individual users or non-3GPP devices.
[0267] In one embodiment, before the network element initiates the EAP authentication process based on the target identifier, the method further includes: the network element verifying the terminal device and the individual user or device corresponding to the target identifier.
[0268] Optionally, the network element device verifies the terminal device and the individual user or device corresponding to the target identifier, including: the network element device verifies the terminal device and the individual user or device corresponding to the target identifier based on the subscription data of the terminal device and / or the configuration data of the individual user or device corresponding to the target identifier.
[0269] In other words, network element devices examine subscription data to determine whether the subscription data is associated with a target identifier, thereby determining whether the terminal device is authorized to provide network access services to the individual user or device corresponding to the target identifier, and whether the individual user or device corresponding to the target identifier is authorized to use the network access services provided by the terminal device; or,
[0270] The network element device checks the configuration data of the individual user or device corresponding to the target identifier. By determining whether the target identifier is associated with subscription data, it determines whether the terminal device is authorized to provide network access services to the individual user or device corresponding to the target identifier, and whether the individual user or device corresponding to the target identifier is authorized to use the network access services provided by the terminal device; or,
[0271] The network element device checks the subscription data and determines whether the terminal device is authorized to provide network access services to the individual user or device corresponding to the target identifier by determining whether the subscription data is associated with the target identifier; the network element device checks the configuration data of the individual user or device corresponding to the target identifier and determines whether the individual user or device corresponding to the target identifier is authorized to use the network access services provided by the terminal device by determining whether the target identifier is associated with the subscription data.
[0272] Correspondingly, if it is determined that the subscription data is associated with a target identifier, then it is determined that the terminal device is authorized to provide network access services to the individual user or device corresponding to the target identifier, and that the individual user or device corresponding to the target identifier is authorized to use the network access services provided by the terminal device; or,
[0273] If it is determined that the target identifier is associated with subscription data, then it is determined that the terminal device is authorized to provide network access services to the individual user or device corresponding to the target identifier, and that the individual user or device corresponding to the target identifier is authorized to use the network access services provided by the terminal device; or,
[0274] If it is determined that the subscription data is associated with the target identifier, then it is determined that the terminal device is authorized to provide network access services to the individual user or device corresponding to the target identifier; if it is determined that the target identifier is associated with the subscription data, then it is determined whether the individual user or device corresponding to the target identifier is authorized to use the network access services provided by the terminal device.
[0275] The subscription data of the terminal device is stored in the UDM or locally on the network element. The configuration data of the individual user or device corresponding to the target identifier is stored in the subscription database, that is, in the UDM, UDR, or a specific network element with data storage function.
[0276] The implementation of network element equipment checking subscription data can be as follows: the network element equipment uses locally stored subscription data of terminal devices to determine whether the subscription data is associated with a target identifier, thereby determining whether the terminal device is authorized to provide network access services to the individual user or device corresponding to the target identifier, and whether the individual user or device corresponding to the target identifier is authorized to use the network access services provided by the terminal device; or...
[0277] The network element sends a first authentication request to the UDM. This first authentication request instructs the UDM to determine, based on the terminal device's subscription data, whether the terminal device is authorized to provide network access services to the individual user or device corresponding to the target identifier, and whether the individual user or device corresponding to the target identifier is authorized to use the network access services provided by the terminal device. The UDM determines whether the terminal device is authorized to provide network access services to the individual user or device corresponding to the target identifier, and whether the individual user or device corresponding to the target identifier is authorized to use the network access services provided by the terminal device, by determining whether the subscription data is associated with the target identifier. The network element receives the first authentication result sent by the UDM and, based on the first authentication result, determines whether the terminal device is authorized to provide network access services to the individual user or device corresponding to the target identifier, and whether the individual user or device corresponding to the target identifier is authorized to use the network access services provided by the terminal device.
[0278] The implementation method for a network element device to check the configuration data of a personal user or device corresponding to a target identifier can be as follows: The network element device sends a second verification request to the subscription database. This second verification request instructs the subscription database to determine, based on the configuration data of the personal user or device corresponding to the target identifier, whether the terminal device is authorized to provide network access services to the personal user or device corresponding to the target identifier, and whether the personal user or device corresponding to the target identifier is authorized to use the network access services provided by the terminal device. The subscription database determines whether the terminal device is authorized to provide network access services to the personal user or device corresponding to the target identifier, and whether the personal user or device corresponding to the target identifier is authorized to use the network access services provided by the terminal device, by determining whether the configuration data of the personal user or device corresponding to the target identifier is associated with subscription data. The network element device receives the second verification result sent by the subscription database and determines, based on the second verification result, whether the terminal device is authorized to provide network access services to the personal user or device corresponding to the target identifier, and whether the personal user or device corresponding to the target identifier is authorized to use the network access services provided by the terminal device.
[0279] Specifically, determining whether the configuration data of the individual user or device corresponding to the target identifier is associated with the subscription data can be achieved by determining whether the configuration data of the individual user or device corresponding to the target identifier is associated with the subscription identifier corresponding to the subscription data.
[0280] Optionally, the network element device verifies the terminal device and the individual user or device corresponding to the target identifier based on the terminal device's subscription data and / or the configuration data of the individual user or device corresponding to the target identifier. This includes: the network element device checking the subscription data and the configuration data of the individual user or device corresponding to the target identifier to determine whether the terminal device is authorized to provide network access services to the individual user or device corresponding to the target identifier, thereby determining whether the individual user or device corresponding to the target identifier is authorized to use the network access services provided by the terminal device.
[0281] The implementation can be as follows: the network element sends a third authentication request to the UDM. This request instructs the UDM to determine whether the terminal device is authorized to provide network access services to the individual user or device corresponding to the target identifier, based on the subscription data and the configuration data of the individual user or device corresponding to the target identifier. The UDM determines whether the terminal device is authorized to provide network access services to the individual user or device corresponding to the target identifier by determining whether the subscription data is associated with the target identifier and whether the configuration data of the individual user or device corresponding to the target identifier is associated with the subscription data. The network element receives the third authentication result from the UDM and determines whether the terminal device is authorized to provide network access services to the individual user or device corresponding to the target identifier based on the result. If the third authentication result determines that the terminal device is authorized to provide network access services to the individual user or device corresponding to the target identifier, then the individual user or device corresponding to the target identifier is authorized to use the network access services provided by the terminal device.
[0282] If it is determined that the terminal device is authorized to provide network access services to the individual user or device corresponding to the target identifier, and that the individual user or device corresponding to the target identifier is authorized to use the network access services provided by the terminal device, then the target request message sent by the terminal device needs to be accepted. Otherwise, it means that the target request message sent by the terminal device does not need to be accepted, and a target request rejection message is sent to the terminal device.
[0283] In one embodiment, the method further includes: the network element receiving a specific identifier sent from the terminal device, the specific identifier being used to instruct the network element to initiate an EAP authentication process based on the target identifier.
[0284] The specific identifier can be sent in the target request message or sent together with the target request message.
[0285] If a network element receives a specific identifier sent from a terminal device, after determining that the terminal device is authorized to provide network access services to the individual user or device corresponding to the target identifier, and after determining that the individual user or device corresponding to the target identifier is authorized to use the network access services provided by the terminal device, the network element directly initiates the EAP authentication process based on the target identifier.
[0286] If the network element does not receive a specific identifier from the terminal device, the network element verifies the terminal device and the individual user or device corresponding to the target identifier. This verification also includes: the network element determining whether the individual user or device corresponding to the target identifier has been authenticated based on the configuration data of the individual user or device. In other words, after determining that the terminal device is authorized to provide network access services to the individual user or device corresponding to the target identifier, and that the individual user or device corresponding to the target identifier is authorized to use the network access services provided by the terminal device, and after determining that the individual user or device corresponding to the target identifier is not authenticated, the network element then initiates the EAP authentication process based on the target identifier.
[0287] The configuration data for individual users includes their authentication results, while the configuration data for devices includes their authentication results. Authentication results include either success or failure information; success information includes the authentication time parameter.
[0288] Optionally, based on the configuration data of the individual user or device corresponding to the target identifier, determine whether the individual user or device corresponding to the target identifier has been authenticated. This includes: if the authentication result of the individual user or device is authentication failure, then determine that the individual user or device corresponding to the target identifier is unauthenticated. If the authentication result is authentication success, further determine whether the individual user or device corresponding to the target identifier has been authenticated within the validity period based on the authentication success time parameter in the authentication success information. If it has not been authenticated within the validity period, then determine that the individual user or device corresponding to the target identifier is unauthenticated. If it has been authenticated within the validity period, then send a target request reception message to the terminal device to avoid performing the authentication process every time access is made in the short term, thereby saving network resources.
[0289] In addition, if the network element device discovers that the current request session requires secondary authentication of the terminal device during the verification process of the terminal device and the individual user or device corresponding to the target identifier, such as the terminal device triggering the EAP authentication process for the user identifier to the DN-AAA server through the network element device, the DN-AAA server needs to perform secondary authentication on the terminal device first to determine whether the terminal device is authorized to access the current data network. If the terminal device is not authorized to access the current data network, the EAP authentication process initiated by the terminal device will not be accepted.
[0290] In this embodiment, by verifying the terminal device and the individual user or device corresponding to the target identifier, if the verification is successful, the network element device initiates the EAP authentication process based on the target identifier, which can ensure network security.
[0291] In one embodiment, the target identifier and the configuration data of the individual user or device corresponding to the target identifier are described in detail.
[0292] If the target identifier is the identifier of an individual user using or accessing the network through a terminal device, then the configuration data of the individual user corresponding to the target identifier includes at least one of the individual user's user identifier, temporary user identifier, and authentication result. The target identifier can be either a user identifier or a temporary user identifier.
[0293] The User Identity (UID) is used to identify the current user within the 5G system content. The Temporary User Identity (TUID) is a temporary identifier created by temporarily encrypting the User Identity. It has a certain validity period and is generated and stored in the individual user's configuration data after authentication to provide privacy protection for future access. The authentication result indicates whether the user has been authenticated within the validity period and also indicates whether the current User Identity has been activated.
[0294] The configuration data for individual users also includes at least one of the following: user application layer identifier, group identifier, service information, session policy, security policy, access policy, and security credentials.
[0295] The User Application Identity (UAID) is used to identify the current user at the application layer. It's important to note that there is a mapping relationship between the UAID and the UAID.
[0296] A group ID is used when an individual user corresponding to a target ID belongs to a certain group and differentiated processing needs to be performed based on group information. In such cases, an associated group ID needs to be added.
[0297] Service info limits the types of services that use individual user configuration data and stores network requirement information related to the service, such as QoS.
[0298] Session policies include QoS, traffic splitting rules, and access control policies.
[0299] Security policies include authentication methods and related key processing requirements.
[0300] Access policies include restrictions on the use of the current service, such as restricting the use of the current service to a specific geographical location or network.
[0301] Security credentials are pre-configured on both the network side and the user terminal side for two-way authentication between the network and the user. Security credentials can be generated, allocated, and managed by the operator's 5GC or by the application side. When generated by the application side, a trust relationship and a secure interaction environment are required between the operator and the application side.
[0302] The security credentials associated with the user identifier are stored in the individual user's configuration data. These security credentials are pre-configured or pre-provided to the network device storing the configuration data and the terminal device used by the individual user. The security credentials are derived from a long-term key K in the terminal device's USIM, and include, but are not limited to:
[0303] Using the GBA (Generic Bootstrapping Architecture) scheme, the terminal device and the network side provide the network functions of the current application to run the GBA process (as defined in 3GPP TS 33.220), and obtain K based on the long-term key K. s(_ext)_NAF And based on personal user identifiers and K s(_ext)_NAF The security credentials for the individual user are derived. The update mechanism for these credentials is based on the key K in the GBA scheme. s(_ext)_NAF Update mechanism, when key K s(_ext)_NAF After the update is complete, proceed with the security credential update process.
[0304] Using the AKMA (Authentication and Key Management for Applications) scheme, the terminal device and the network side provide the network functions of the current application to run the AKMA process (such as 3GPP TS33.535), and obtain K based on the long-term key K. AF And based on personal user identifiers and K AF The security credentials for the individual user are derived. The credential update mechanism is based on the key K in the AKMA scheme. AF Update mechanism, when key K AF After the update is complete, proceed with the security credential update process.
[0305] The identity authentication service function AUSF executes an authentication process with the terminal device. AUSF requests the security credentials of the individual user from the network function that stores the individual user's configuration data, and authenticates the individual user using the terminal device based on the security credentials.
[0306] If the target identifier is the identifier of a device used or accessing the network through a terminal device, then the configuration data of the device corresponding to the target identifier includes at least one of the device identifier, temporary device identifier, and authentication result; the target identifier is a device identifier or a temporary device identifier.
[0307] The device identifier is used to identify non-3GPP devices. The temporary device identifier is a temporary identifier formed by temporarily encrypting the device identifier; it has a certain validity period and is generated and stored in the device's configuration data after authentication to provide privacy protection for subsequent access. The authentication result indicates whether the device has been successfully authenticated.
[0308] The device's configuration data also includes at least one of the following: device group identifier, service information, session policy, security policy, access policy, and security credentials.
[0309] The group identifier, service information, session policy, security policy, and access policy are similar to those of the individual user in the configuration data of the individual user mentioned above, and will not be described again here.
[0310] Security credentials are pre-configured on the network side and non-3GPP equipment side for two-way authentication between network and non-3GPP equipment. Security credentials can be generated, allocated, and managed by the operator's 5GC or by the application side. When generated by the application side, a trust relationship and a secure interaction environment are required between the operator and the application side.
[0311] The security credentials associated with the device identifier are stored in the device's configuration data. These credentials are pre-configured or pre-provided to the network device or DN-AAA server storing the configuration data, and in non-3GPP devices. The security credentials are obtained based on the long-term key K in the terminal device's USIM, including but not limited to:
[0312] Using the GBA scheme, the terminal device and the network side provide the network functions of the current application to run the GBA process (as defined in 3GPP TS 33.220), and obtain K based on the long-term key K. s(_ext)_NAF And based on device identifier and K s(_ext)_NAF The security credentials for device identification are derived. The security credential update mechanism is based on the key K in the GBA scheme. s(_ext)_NAF Update mechanism, when key K s(_ext)_NAF After the update is complete, proceed with the security credential update process.
[0313] Using the AKMA scheme, the terminal device and the network side provide the network functions of the current application to run the AKMA process (such as 3GPP TS 33.535), and obtain K based on the long-term key K. AF And based on device identifier and K AF The security credentials for device identification are derived. The security credential update mechanism is based on the K key in the AKMA scheme. AF Update mechanism, when key K AF After the update is complete, proceed with the security credential update process.
[0314] The DN-AAA server performs an authentication process with non-3GPP devices. The DN-AAA server requests the security credentials of the non-3GPP devices from the network function that stores the configuration data of the non-3GPP devices (if the DN-AAA does not store the security credentials of the non-3GPP devices), and authenticates the non-3GPP devices using the terminal devices based on the security credentials.
[0315] In one embodiment, after the above verification is successful, the method further includes the network element device generating a transaction identifier based on the target identifier; the transaction identifier is used by the network element device to identify and forward EAP session messages of the individual user or device corresponding to the target identifier.
[0316] In one embodiment, after the above verification is successful, the network element initiates an EAP authentication process based on the target identifier, including one of the following two implementation methods:
[0317] In the first scenario, the network element sends a first authentication request message carrying a target identifier to the terminal device, or the network element sends a first authentication request message without carrying a target identifier and a target identifier to the terminal device; the network element receives a first authentication response message carrying a target identifier from the terminal device, or the network element receives a first authentication response message without carrying a target identifier and a target identifier from the terminal device.
[0318] The network element sends a second authentication request message carrying the target identifier to the authentication server, or the network element sends a second authentication request message without carrying the target identifier and the target identifier to the authentication server; the network element receives a second authentication response message carrying the target identifier from the authentication server, or the network element receives a second authentication request message without carrying the target identifier and the target identifier from the authentication server.
[0319] The network element sends a target response message carrying the target identifier to the terminal device, or the network element sends a target response message without carrying the target identifier and the target identifier to the terminal device.
[0320] In the second scenario, the network element device no longer needs to send the first authentication request message to the terminal device. Instead, it directly sends the second authentication request message to the authentication server, receives the second authentication response message from the authentication server, and then sends a target response message carrying the target identifier to the terminal device. Alternatively, it can send a target response message without the target identifier and the target identifier to the terminal device.
[0321] Optionally, if the second authentication response message includes the first EAP authentication success message, which indicates that the personal user or device corresponding to the target identifier has successfully completed EAP authentication, then the network element device sends a target response message including the second EAP authentication success message to the terminal device. The second EAP authentication success message is obtained by the network element device based on the first EAP authentication success message, and the second EAP authentication success message is used to instruct the terminal device to forward the data between the personal user or device corresponding to the target identifier and the network side.
[0322] Specifically, when a network element sends a first authentication request message to the individual user or device corresponding to the target identifier via a terminal device, it can carry object indication information. This object indication information can be carried in the first authentication request message or in the NAS message carrying the first authentication request message. Similarly, when a network element sends a second authentication request message to the authentication server, it can also carry object indication information. The object indication information can be used to inform the recipient that the object currently undergoing EAP authentication is the individual user or device corresponding to the target identifier.
[0323] Before sending the second authentication request message to the authentication server, the network element device also needs to obtain the address information of the authentication server. Specifically, the network element device can obtain the address information from the authentication server information in the target request message, or it can determine the address information based on the type of the target identifier.
[0324] The specific implementation method for determining the address information based on the type of the target identifier by the network element device can be as follows: the authentication server includes an AUSF or a DN-AAA server, and the network element device sends a second authentication request message to the authentication server, including: if the target identifier is the identifier of an individual user using or accessing the network through a terminal device, the network element device sends a second authentication request message to the AUSF; if the target identifier is the identifier of a device using or accessing the network through a terminal device, the network element device sends a second authentication request message to the DN-AAA server.
[0325] After receiving the second authentication request message from the network element device, the authentication server verifies whether the individual user or device corresponding to the target identifier is authorized to use the network access service. If so, the authentication server sends a second authentication response message to the network element device, including the first EAP authentication success message; if not, the authentication server sends a second authentication response message to the network element device, including the EAP authentication failure message. Upon receiving the second authentication response message including the first EAP authentication success message, the network element device sends a target response message including the second EAP authentication success message to the terminal device. The first and second EAP authentication success messages can be the same or different; this is not limited here.
[0326] The second authentication response message may also include a master key (MSK). The network element sends the master key to the terminal device along with the target response message carrying the target identifier or without the target identifier. This master key can be sent within the target response message or together with it; specifically, sending the master key within the target response message can be done by sending it along with the first EAP authentication success message.
[0327] In one embodiment, after receiving a second authentication response message including a first EAP authentication success message, the network element performs at least one of the following:
[0328] The network element device associates the target identifier with the session context information of the terminal device, or adds the target identifier to the session context of the terminal device, in order to perform at least one of the following on the network access traffic of the individual user or device corresponding to the target identifier: traffic identification, quality of service (QoS) management and security tracing.
[0329] The network element stores the authentication result of the individual user or device corresponding to the target identifier based on the second authentication response message. If the second authentication response message includes a first EAP authentication success message, the authentication result is authentication success information; if the second authentication response message includes an EAP authentication failure message, the authentication result is authentication failure information. Authentication success information indicates that the authentication status of the individual user or device corresponding to the target identifier is successful. Authentication failure information indicates that the authentication status of the individual user or device corresponding to the target identifier is failed.
[0330] The network element sends the authentication result of the individual user or device corresponding to the target identifier to the subscription database. The subscription database updates the authentication result in the configuration data of the individual user or device corresponding to the target identifier based on the received authentication result.
[0331] The network element sends a session policy information request to the PCF corresponding to the target identifier for the individual user or device, in order to obtain the session policy information of the individual user or device corresponding to the target identifier; wherein, the session policy information is used by the network element for subsequent PDU session management process.
[0332] In one embodiment, if the target request message is a PDU session establishment request message or a PDU session modification request message, the method further includes, before the network element sends the target response message to the terminal device, the network element establishing or modifying the PDU session of the terminal device. Therefore, the target response message is a PDU session establishment acceptance message or a PDU session modification acceptance message.
[0333] After receiving the target response message, the terminal device indicates that the individual user or device corresponding to the target identifier and the network have completed two-way authentication. Therefore, the terminal device can forward the data between the individual user or device corresponding to the target identifier and the network side.
[0334] In one embodiment, after two-way authentication is completed between the individual user or device corresponding to the target identifier and the network, the method further includes: the network element device deciding to initiate re-authentication for the individual user or device corresponding to the target identifier, and the network element device initiating an EAP authentication process based on the target identifier; or, the authentication server deciding to initiate re-authentication for the individual user or device corresponding to the target identifier, the network element device receiving a re-authentication request containing the target identifier sent by the authentication server, and the network element device initiating an EAP authentication process based on the target identifier.
[0335] In other words, the specific triggering method can be triggered by network element devices or authentication servers, and the triggering reason can be business strategy, application service strategy, etc. There is no limitation on the triggering reason here.
[0336] In one embodiment, before the network element initiates the EAP authentication process based on the target identifier, the method further includes: the network element sending a third authentication request message carrying the target identifier to the terminal device, or the network element sending a third authentication request message without carrying the target identifier and the target identifier to the terminal device; the network element receiving a third authentication response message carrying the target identifier sent by the terminal device, or the network element receiving a third authentication response message without carrying the target identifier and the target identifier sent by the terminal device.
[0337] The network element also sends a re-authentication identifier to the terminal device. This re-authentication identifier is carried in the third authentication request message, or it is sent together with the third authentication request message. The re-authentication identifier is used to inform the terminal device that the individual user or device corresponding to the target identifier needs to be re-authenticated, and instructs the terminal device to suspend forwarding data between the network element and the network side.
[0338] After receiving the third authentication response message sent by the terminal device, the network element device initiates the EAP authentication process based on the target identifier. During the process of initiating the EAP authentication process based on the target identifier, the interaction between devices may or may not carry the re-authentication identifier, which is not limited here.
[0339] In one embodiment, another authentication method is provided, in which the method is applied to Figure 2 Taking a terminal device as an example, the explanation includes the following steps:
[0340] The terminal device sends a target request message carrying a target identifier to the network element device, or the terminal device sends a target request message without a target identifier and a target identifier to the network element device, so that the network element device can initiate an EAP authentication process based on the target identifier; wherein, the target identifier is the identifier of the individual user or device that uses or accesses the network through the terminal device.
[0341] In one embodiment, the method further includes: the terminal device sending a specific identifier to the network element device, the specific identifier being used to instruct the network element device to initiate an EAP authentication process based on the target identifier.
[0342] In one embodiment, the target identifier is the identifier of an individual user who uses or accesses the network through a terminal device, and the configuration data of the individual user corresponding to the target identifier includes at least one of the individual user's user identifier, temporary user identifier, and authentication result; the target identifier is a user identifier or a temporary user identifier.
[0343] The target identifier is the identifier of the device used or accessing the network through the terminal device. The configuration data of the device corresponding to the target identifier includes at least one of the device identifier, temporary device identifier and authentication result; the target identifier is a device identifier or a temporary device identifier.
[0344] In one embodiment, after the terminal device sends a target request message to the network element device, the method further includes: the terminal device receiving a target response message carrying a target identifier sent by the network element device, or the terminal device receiving a target response message without carrying the target identifier and a target identifier sent by the network element device.
[0345] In one embodiment, the method further includes: the terminal device receiving the master key sent by the network element device.
[0346] In one embodiment, the target response message includes a second EAP authentication success message, which instructs the terminal device to forward data between the individual user or device corresponding to the target identifier and the network side.
[0347] In one embodiment, the target response message includes a second EAP authentication success message or an authentication failure message, and the method further includes: the terminal device sending the second EAP authentication success message or EAP authentication failure message to the individual user or device corresponding to the target identifier.
[0348] In one embodiment, the method further includes: the terminal device receiving a third authentication request message carrying a target identifier sent by a network element device, or the terminal device receiving a third authentication request message without a target identifier and a target identifier sent by a network element device; the terminal device sending a third authentication response message carrying a target identifier to the network element device, or the terminal device sending a third authentication response message without a target identifier and a target identifier to the network element device.
[0349] In one embodiment, the method further includes: the terminal device sending a re-authentication identifier to the network element device, the re-authentication identifier being carried in a third authentication response message, or the re-authentication identifier being sent together with the third authentication response message.
[0350] In one embodiment, after the terminal device receives the third authentication request message sent by the network element device, the method further includes: the terminal device suspending the forwarding of data between the individual user or device corresponding to the target identifier and the network side.
[0351] In one embodiment, the method further includes: the terminal device sending a notification message to the individual user or device corresponding to the target identifier, the notification message being used to notify the individual user or device corresponding to the target identifier to suspend forwarding of data between the individual user or device corresponding to the target identifier and the network side.
[0352] In one embodiment, the terminal device is a smart terminal device or a gateway device, the individual user corresponding to the target identifier is a specific user who uses the smart terminal device to obtain a specific network application service, and the device corresponding to the target identifier is a non-3GPP device that obtains a specific network application service through the smart terminal device or the gateway device. Non-3GPP devices refer to devices that do not have USIM capabilities.
[0353] The authentication method embodiments on the terminal device side described above have been described in detail in the authentication method embodiments on the network device side described above, and will not be repeated here. The following only describes in detail the aspects of the terminal device side not mentioned in the network device side description.
[0354] In one embodiment, before the terminal device sends a target request message to the network element device, the method further includes: the terminal device obtaining a target identifier; if the target identifier is the identifier of an individual user using or accessing the network through the terminal device, the target identifier is a temporary user identifier, and the terminal device determines whether the temporary user identifier is valid; if invalid, the terminal device obtains the user identifier of the individual user corresponding to the target identifier and uses the user identifier as the target identifier; if the target identifier is the identifier of a device using or accessing the network through the terminal device, the target identifier is a temporary device identifier, and the terminal device determines whether the temporary device identifier is valid; if invalid, the terminal device obtains the device identifier of the device corresponding to the target identifier and uses the device identifier as the target identifier.
[0355] In other words, if the temporary user identifier or temporary device identifier obtained by the terminal device is valid, then the temporary user identifier or temporary device identifier will be used as the target identifier. If the obtained temporary user identifier or temporary device identifier is invalid, then the user identifier or device identifier will be obtained and used as the target identifier.
[0356] Specifically, when a temporary user identifier or a temporary device identifier is invalid, the user identifier can be obtained from the network side based on the temporary user identifier, or the device identifier can be obtained from the network side based on the temporary device identifier.
[0357] To obtain the target identifier, specifically, if the target identifier is the identifier of a device used or accessing the network through the terminal device, the terminal needs to execute the D2D connection establishment process corresponding to the target identifier, and obtain the target identifier during the D2D connection establishment process. If the target identifier is the identifier of an individual user used or accessing the network through the terminal device, the target identifier is obtained directly from the local machine. The D2D connection can be, for example, WLAN or Bluetooth, and the D2D connection already has a security protection mechanism.
[0358] In one embodiment, after obtaining the target identifier but before the terminal device sends a target request message to the network element device, the method further includes: the terminal device verifying the individual user or device corresponding to the target identifier.
[0359] Optionally, the terminal device verifies the individual user or device corresponding to the target identifier based on the terminal device's subscription data.
[0360] In other words, the terminal device checks the subscription data and determines whether the subscription data is associated with a target identifier in order to determine whether the individual user or device corresponding to the target identifier is authorized to use the network access service provided by the terminal device.
[0361] The implementation method can be as follows: the terminal device sends a fourth authentication request to the UDM through the AMF. The fourth authentication request is used to instruct the UDM to check whether the subscription data is associated with the target identifier. The terminal device receives the fourth authentication result sent by the UDM and determines whether the individual user or device corresponding to the target identifier is authorized to use the network access service of the terminal device based on the fourth authentication result.
[0362] In one embodiment, before the terminal device sends a target request message to the network element device, the method further includes: the terminal device determining whether the individual user or device corresponding to the target identifier has been authenticated based on the configuration data of the individual user or device corresponding to the target identifier.
[0363] The configuration data for individual users includes their authentication results, while the configuration data for devices includes their authentication results. Authentication results include either success or failure information; success information includes the authentication time parameter.
[0364] The configuration data of the individual user or device corresponding to the target identifier can be stored locally on the terminal device or stored on the network side, such as AMF.
[0365] Optionally, if the authentication result for an individual user or device is an authentication failure message, then it is determined that the individual user or device corresponding to the target identifier is unauthenticated. If the authentication result is an authentication success message, then it is further determined whether the individual user or device corresponding to the target identifier has been authenticated within the validity period based on the authentication success time parameter in the authentication success message. If it has not been authenticated within the validity period, then it is determined that the individual user or device corresponding to the target identifier is unauthenticated.
[0366] In one embodiment, after the terminal device sends a target request message to the network element device, during the process of the network element device initiating an EAP authentication process based on the target identifier, the method further includes: the terminal device receiving a first authentication request message carrying the target identifier sent by the network element device, or the terminal device receiving a first authentication request message without the target identifier and the target identifier sent by the network element device. The terminal device forwards the first authentication request message carrying the target identifier, or the first authentication request message without the target identifier and the target identifier, to the individual user or device corresponding to the target identifier. The terminal device receives a first authentication response message carrying the target identifier sent by the individual user or device corresponding to the target identifier, or the terminal device receives a first authentication response message without the target identifier and the target identifier sent by the individual user or device corresponding to the target identifier. The terminal device forwards the first authentication response message carrying the target identifier, or the first authentication response message without the target identifier and the target identifier, to the network element device.
[0367] Optionally, the terminal device may forward the first authentication request message to the individual user or device corresponding to the target identifier, which can be implemented in the following two ways:
[0368] The first method involves the terminal device sending a first authentication request message to the individual user or device corresponding to the target identifier based on the target identifier.
[0369] In the second scenario, the terminal device also receives the object indication information mentioned above from the network device side, and the terminal device forwards the first authentication request message to the individual user or device corresponding to the target identifier based on the object indication information.
[0370] In one embodiment, after the terminal device receives the target response message sent by the network element device, the method further includes: the terminal device storing the authentication result of the individual user or device corresponding to the target identifier based on the target response message.
[0371] The purpose of this embodiment is to store the authentication result of the individual user or device corresponding to the target identifier, so that the terminal device can determine whether the individual user or device corresponding to the target identifier has been authenticated based on the authentication result.
[0372] In one embodiment, after the terminal device receives the master key sent by the network element device, the method further includes: the terminal device establishing a D2D connection based on the master key for security protection, which can further enhance the link security between the terminal device and the device corresponding to the target identifier.
[0373] In one embodiment, after the terminal device receives the target response message sent by the network element device, the method further includes: if the target identifier is a temporary user identifier of an individual user, the terminal device sends the temporary user identifier to the individual user corresponding to the target identifier; if the target identifier is a temporary device identifier of a device, the terminal device sends the temporary device identifier to the device corresponding to the target identifier.
[0374] The purpose of this embodiment is that if the individual user or device corresponding to the target identifier is authenticating for the first time, the target identifier included in the second authentication request message sent by the network element device to the authentication server must be a user identifier or a device identifier. In order to protect the privacy and security of the network and individual users / devices, the authentication server will generate a temporary user identifier or a temporary device identifier based on the target identifier and send the temporary user identifier or temporary device identifier to the network element device. The network element device will send the temporary user identifier or temporary device identifier to the terminal device, and the terminal device will then forward the temporary user identifier or temporary device identifier to the individual user or the device corresponding to the target identifier. In this way, the individual user or device corresponding to the target identifier can directly send the temporary user identifier or temporary device identifier to the terminal device in the next authentication process. After the terminal device sends the temporary user identifier or temporary device identifier to the network side, the network side can directly parse the user identifier or device identifier based on the temporary user identifier or temporary device identifier and then perform the EAP authentication process based on the user identifier or device identifier.
[0375] Additionally, it's worth noting that the authentication server generates a temporary user identifier or temporary device identifier based on the target identifier. Specifically, the authentication server can generate a temporary user identifier based on the master key and the user identifier, or a temporary device identifier based on the master key and the device identifier. Furthermore, the generated temporary user identifier or temporary device identifier is stored in the configuration data of the individual user or device. Specifically, the authentication server, network element device, or terminal device can send storage instruction information including the temporary user identifier or temporary device identifier to the subscription database. This storage instruction information instructs the subscription database to store the temporary user identifier or temporary device identifier in the configuration data of the individual user or device.
[0376] In one embodiment, yet another authentication method is provided, in which the method is applied to Figure 2 Taking the authentication server in the example, the following steps are included:
[0377] The authentication server receives a second authentication request message carrying a target identifier from a network element device, or the authentication server receives a second authentication request message without a target identifier and a target identifier from a network element device, in order to perform EAP authentication on the individual user or device corresponding to the target identifier; the target identifier is the identifier of the individual user or device that uses or accesses the network through a terminal device.
[0378] The authentication server sends a second authentication response message carrying the target identifier to the network element device; alternatively, the authentication server sends a second authentication response message without carrying the target identifier and the target identifier to the network element device.
[0379] In one embodiment, the method further includes: an authentication server verifying whether the individual user or device corresponding to the target identifier is authorized to use the network access service.
[0380] In one embodiment, the second authentication response message includes the master key.
[0381] In one embodiment, the second authentication response message is a first EAP authentication success message, which is used to indicate that the personal user or device corresponding to the target identifier has successfully completed EAP authentication.
[0382] In one embodiment, the target identifier is the identifier of an individual user who uses or accesses the network through a terminal device, and the target identifier is either the user identifier of the individual user or the temporary user identifier.
[0383] In one embodiment, the target identifier is the identifier of a device that uses or accesses the network through a terminal device, and the target identifier is either a device identifier or a temporary device identifier.
[0384] In one embodiment, the target identifier is the identifier of an individual user who uses or accesses the network through a terminal device, and the authentication server is AUSF.
[0385] In one embodiment, the target identifier is the identifier of the device that uses or accesses the network through the terminal device, and the authentication server is a DN-AAA server.
[0386] In one embodiment, the terminal device is a smart terminal device or a gateway device, the individual user corresponding to the target identifier is a specific user who uses the smart terminal device to obtain a specific network application service, and the device corresponding to the target identifier is a non-3GPP device that obtains a specific network application service through the smart terminal device or the gateway device. Non-3GPP devices refer to devices that do not have USIM capabilities.
[0387] The authentication method embodiments on the authentication server side described above have been described in detail in the authentication method embodiments on the network device side described above, and will not be repeated here.
[0388] In one embodiment, yet another authentication method is provided, in which the method is applied to Figure 2 Taking UDM as an example, the explanation includes the following steps:
[0389] UDM associates the configuration data of the individual user or device corresponding to the target identifier with the subscription data of the terminal device. This allows network element devices to verify the terminal device and the individual user or device corresponding to the target identifier based on the subscription data of the terminal device and / or the configuration data of the individual user or device corresponding to the target identifier.
[0390] Optionally, through pre-configuration, the network access service provider initiates the process, and the operator's UDM associates the configuration data of the target identifier of the network access service with the personal user or device in the subscription data of the terminal device that supports the network access service.
[0391] To facilitate understanding, the following diagram illustrates the signaling interaction process of an authentication method, combining the authentication methods described above for the network device side, terminal device side, and authentication server side. The authentication process is illustrated using a non-3GPP device without USIM capabilities as an example. Figure 13 As shown.
[0392] Step 1301: The terminal device establishes a D2D connection with a non-3GPP device.
[0393] Step 1302: The terminal device sends a target request message including the target identifier to the SMF, that is, it sends a PDU session establishment request message or a PDU session modification request message including the target identifier.
[0394] Step 1303: SMF verifies the terminal device and non-3GPP devices, including interaction with the subscription database.
[0395] Step 1304: If the verification is successful, the SMF generates a transaction identifier based on the target identifier. This transaction identifier is used by the SMF to identify and forward EAP session messages of non-3GPP devices.
[0396] Step 1305: SMF sends a second authentication request message to the authentication server.
[0397] Step 1306: Non-3GPP devices and the authentication server perform EAP two-way authentication based on application layer credentials, with the terminal device and 5GS responsible for EAP message pass-through.
[0398] Step 1307: The authentication server verifies whether the non-3GPP device is authorized to use the network access service. If so, the authentication server sends a second authentication response message to the SMF, including a first EAP authentication success message; if not, the authentication server sends a second authentication response message to the SMF, including an EAP authentication failure message. Optionally, the second authentication response message includes a master key and a temporary device identifier.
[0399] After SMF receives the second authentication response message, which includes the first EAP authentication success message,
[0400] Step 1308a: The SMF associates the target identifier with the session context information of the terminal device.
[0401] Step 1308b: Based on the second authentication response message, the SMF stores the authentication result of the non-3GPP device.
[0402] Optionally, in step 1308c, the SMF sends the authentication results of non-3GPP devices to the subscription database.
[0403] Optionally, in step 1308d, the SMF sends a session policy information request for non-3GPP devices to the PCF to obtain session policy information for non-3GPP devices.
[0404] Step 1309: SMF establishes or modifies the PDU session of the terminal device.
[0405] Step 1310: The SMF sends a target response message to the terminal device, which is either a PDU session establishment acceptance message or a PDU session modification acceptance message. The target response message includes a second EAP authentication success message. Optionally, the target response message includes the master key and a temporary device identifier.
[0406] Optionally, in step 1311, the terminal device stores the authentication result of the non-3GPP device based on the target response message.
[0407] Optionally, in step 1312a, the terminal device establishes security protection for the D2D connection based on the master key.
[0408] Optionally, in step 1312b, the terminal device sends a temporary device identifier to a non-3GPP device.
[0409] Step 1312c: The terminal device forwards data between the non-3GPP device and the network side.
[0410] The SMF (Service Provider Function) decides to initiate re-authentication for the individual user or device corresponding to the target identifier. The SMF initiates the EAP (Electronic Access Authentication) process based on the target identifier. The authentication server also decides to initiate re-authentication for the individual user or device corresponding to the target identifier. The SMF receives a re-authentication request containing the target identifier from the authentication server and initiates the EAP authentication process based on the target identifier. A schematic diagram of the signaling interaction process for the re-authentication method is shown below. Figure 14 As shown.
[0411] Step 1401: Complete two-way authentication between non-3GPP devices and the network.
[0412] Step 1402a, SMF triggers re-authentication.
[0413] Step 1402b-1: The authentication server triggers re-authentication. Step 1402b-2: The authentication server triggers the sending of a re-authentication request to the SMF.
[0414] Step 1403: SMF sends a third authentication request message to the terminal device. The third authentication request message includes a re-authentication identifier and a target identifier.
[0415] Step 1404: The terminal device suspends forwarding of data between non-3GPP devices and the network side.
[0416] Step 1405: The terminal device sends a notification message to the non-3GPP device. The notification message is used to notify the non-3GPP device to suspend the forwarding of data between the non-3GPP device and the network side.
[0417] Step 1406: The terminal device sends a third authentication response message to the SMF.
[0418] Step 1407, execute with Figure 13 The same steps as steps 1305-1312.
[0419] It should be understood that, although Figure 12-14The steps in the flowchart are shown sequentially as indicated by the arrows, but these steps are not necessarily executed in the order indicated by the arrows. Unless otherwise specified herein, there is no strict order in which these steps are executed, and they can be performed in other orders. Figure 12-14 At least some of the steps in the process may include multiple steps or multiple stages. These steps or stages are not necessarily completed at the same time, but may be executed at different times. The execution order of these steps or stages is not necessarily sequential, but may be executed in turn or alternately with other steps or at least some of the steps or stages in other steps.
[0420] In one embodiment, such as Figure 15 As shown, an authentication device is provided. The authentication device 1500 includes: a receiving module 1501 and an execution module 1502, which are disposed in a network element device, wherein:
[0421] The receiving module 1501 is configured to receive a target request message carrying a target identifier sent from a terminal device, or to receive a target request message without a target identifier and a target identifier sent from a terminal device; wherein the target identifier is the identifier of an individual user using or accessing the network through the terminal device or the identifier of a device using or accessing the network through the terminal device.
[0422] Execution module 1502 is used to initiate the EAP authentication process based on the target identifier.
[0423] In one embodiment, the authentication device 1500 further includes a first verification module for verifying the terminal device and the individual user or device corresponding to the target identifier.
[0424] In one embodiment, the first verification module is specifically used to verify the terminal device and the individual user or device corresponding to the target identifier based on the subscription data of the terminal device and / or the configuration data of the individual user or device corresponding to the target identifier.
[0425] In one embodiment, the first verification module is specifically configured to: examine subscription data; determine whether the subscription data is associated with a target identifier to determine whether the terminal device is authorized to provide network access services to the individual user or device corresponding to the target identifier, and to determine whether the individual user or device corresponding to the target identifier is authorized to use the network access services provided by the terminal device; or examine the configuration data of the individual user or device corresponding to the target identifier; determine whether the target identifier is associated with subscription data to determine whether the terminal device is authorized to provide network access services to the individual user or device corresponding to the target identifier, and to determine whether the individual user or device corresponding to the target identifier is authorized to use the network access services provided by the terminal device; or examine the configuration data of the individual user or device corresponding to the target identifier; determine whether the target identifier is associated with subscription data to determine whether the individual user or device corresponding to the target identifier is authorized to use the network access services provided by the terminal device.
[0426] In one embodiment, the first verification module is specifically used to check the subscription data and the configuration data of the individual user or device corresponding to the target identifier, to determine whether the terminal device is authorized to provide network access services to the individual user or device corresponding to the target identifier, so as to determine whether the individual user or device corresponding to the target identifier is authorized to use the network access services provided by the terminal device.
[0427] In one embodiment, the first verification module is specifically used to determine whether the personal user or device corresponding to the target identifier has been authenticated based on the configuration data of the personal user or device corresponding to the target identifier.
[0428] In one embodiment, the receiving module 1501 is further configured to receive a specific identifier sent from the terminal device, the specific identifier being used to instruct the network element device to initiate an EAP authentication process based on the target identifier.
[0429] In one embodiment, the target identifier is the identifier of an individual user who uses or accesses the network through a terminal device, and the configuration data of the individual user corresponding to the target identifier includes at least one of the individual user's user identifier, temporary user identifier, and authentication result.
[0430] In one embodiment, the target identifier is the identifier of a device that uses or accesses the network through a terminal device, and the configuration data of the device corresponding to the target identifier includes at least one of the device identifier, temporary device identifier, and authentication result.
[0431] In one embodiment, the authentication device 1500 further includes a generation module for generating a transaction identifier based on the target identifier; the transaction identifier is used by the network element device to identify and forward the EAP session messages of the individual user or device corresponding to the target identifier.
[0432] In one embodiment, the execution module 1502 is specifically configured to send a second authentication request message carrying a target identifier to the authentication server, or send a second authentication request message without a target identifier and a target identifier to the authentication server; receive a second authentication response message carrying a target identifier sent by the authentication server, or receive a second authentication request message without a target identifier and a target identifier sent by the authentication server; send a target response message carrying a target identifier to the terminal device, or send a target response message without a target identifier and a target identifier to the terminal device.
[0433] In one embodiment, the second authentication response message includes the master key.
[0434] In one embodiment, the execution module 1502 is further configured to send a master key to the terminal device.
[0435] In one embodiment, the second authentication response message is a first EAP authentication success message, which is used to indicate that the personal user or device corresponding to the target identifier has successfully completed EAP authentication.
[0436] In one embodiment, the target response message includes a second EAP authentication success message, which instructs the terminal device to forward data between the individual user or device corresponding to the target identifier and the network side.
[0437] In one embodiment, the target identifier is the identifier of an individual user who uses or accesses the network through a terminal device, and the authentication server is AUSF.
[0438] In one embodiment, the target identifier is the identifier of the device that uses or accesses the network through the terminal device, and the authentication server is a DN-AAA server.
[0439] In one embodiment, the authentication device 1500 further includes an association module for associating the target identifier with the session context information of the terminal device, or adding the target identifier to the session context of the terminal device.
[0440] In one embodiment, the authentication device 1500 further includes a first storage module for storing the authentication result of the individual user or device corresponding to the target identifier based on the second authentication response message.
[0441] In one embodiment, the authentication device 1500 further includes a re-authentication module, used by the network element device to decide to initiate re-authentication for the individual user or device corresponding to the target identifier, and to initiate an EAP authentication process based on the target identifier; or, the authentication server decides to initiate re-authentication for the individual user or device corresponding to the target identifier, receives a re-authentication request containing the target identifier sent by the authentication server, and initiates an EAP authentication process based on the target identifier.
[0442] In one embodiment, the re-authentication module is specifically used for the network element device to send a third authentication request message to the terminal device based on the target identifier, the third authentication request message including a re-authentication identifier and a target identifier; and to receive a third authentication response message sent by the terminal device, the third authentication response message including the target identifier.
[0443] In one embodiment, the re-authentication module is further configured to send a third authentication request message carrying a target identifier to the terminal device, or send a third authentication request message without carrying a target identifier and a target identifier to the terminal device; receive a third authentication response message carrying a target identifier sent by the terminal device, or receive a third authentication response message without carrying a target identifier and a target identifier sent by the terminal device.
[0444] In one embodiment, the re-authentication module is also used to send a re-authentication identifier to the terminal device.
[0445] In one embodiment, the terminal device is a smart terminal device or a gateway device, the individual user corresponding to the target identifier is a specific user who uses the smart terminal device to obtain a specific network application service, and the device corresponding to the target identifier is a non-3GPP device that obtains a specific network application service through the smart terminal device or the gateway device. Non-3GPP device refers to a device that does not have the Global Subscriber Identity Module (USIM) capability.
[0446] The aforementioned first verification module, generation module, association module, first storage module, and re-authentication module are all located in the network device.
[0447] In one embodiment, such as Figure 16 As shown, another authentication device is provided. The authentication device 1600 includes: a sending module 1601, which is disposed in the terminal device, wherein:
[0448] The sending module 801 is used to send a target request message carrying a target identifier to the network element device, or to send a target request message without a target identifier and a target identifier to the network element device, so that the network element device can initiate an EAP authentication process based on the target identifier;
[0449] The target identifier is the identifier of an individual user or device that uses or accesses the network through a terminal device.
[0450] In one embodiment, the sending module 801 is further configured to send a specific identifier to the network element device, the specific identifier being used to instruct the network element device to initiate an EAP authentication process based on the target identifier.
[0451] In one embodiment, the authentication device 1600 further includes a second verification module for verifying the individual user or device corresponding to the target identifier.
[0452] In one embodiment, the second verification module is specifically used by the terminal device to verify the individual user or device corresponding to the target identifier based on the terminal device's subscription data.
[0453] In one embodiment, the second verification module is specifically used to check the subscription data and determine whether the individual user or device corresponding to the target identifier is authorized to use the network access service provided by the terminal device by determining whether the subscription data is associated with the target identifier.
[0454] In one embodiment, the target identifier is the identifier of an individual user who uses or accesses the network through a terminal device, and the configuration data of the individual user corresponding to the target identifier includes at least one of the individual user's user identifier, temporary user identifier, and authentication result; the target identifier is a user identifier or a temporary user identifier.
[0455] In one embodiment, the target identifier is the identifier of a device that uses or accesses the network through a terminal device, and the configuration data of the device corresponding to the target identifier includes at least one of the device identifier, temporary device identifier, and authentication result; the target identifier is a device identifier or a temporary device identifier.
[0456] In one embodiment, the authentication device 1600 further includes an acquisition module and a determination module. The acquisition module is used to acquire a target identifier. The determination module is used to determine whether the temporary user identifier is valid if the target identifier is a temporary user identifier of an individual user. If invalid, the module acquires the user identifier of the individual user corresponding to the target identifier and uses the user identifier as the target identifier. Alternatively, if the target identifier is a temporary device identifier of a device, the module determines whether the temporary device identifier is valid. If invalid, the module acquires the device identifier of the device corresponding to the target identifier and uses the device identifier as the target identifier.
[0457] In one embodiment, when the target identifier is the identifier of a device that uses or accesses the network through a terminal device, the acquisition module is specifically used to execute the D2D connection establishment process of the device corresponding to the target identifier, and to acquire the target identifier during the execution of the D2D connection establishment process of the device corresponding to the target identifier.
[0458] In one embodiment, the authentication device 1600 further includes a receiving module, configured to receive a target response message carrying a target identifier sent by a network element device, or to receive a target response message without a target identifier and a target identifier sent by a network element device.
[0459] In one embodiment, the receiving module is further configured to receive the master key sent by the network element device.
[0460] In one embodiment, the target response message includes a second EAP authentication success message, which instructs the terminal device to forward data between the individual user or device corresponding to the target identifier and the network side.
[0461] In one embodiment, the target response message includes a second EAP authentication success message or an authentication failure message, and the sending module 801 is further configured to send the second EAP authentication success message or EAP authentication failure message to the individual user or device corresponding to the target identifier.
[0462] In one embodiment, the authentication device 1600 further includes a second storage module for storing the authentication result of the individual user or device corresponding to the target identifier based on the target response message.
[0463] In one embodiment, the authentication device 1600 further includes a connection establishment module for security protection of establishing D2D connections based on a master key.
[0464] In one embodiment, the sending module is further configured to send the temporary user identifier to the individual user corresponding to the target identifier if the target identifier is a temporary user identifier of an individual user; or send the temporary device identifier to the device corresponding to the target identifier if the target identifier is a temporary device identifier of a device.
[0465] In one embodiment, the receiving module is further configured to receive a third authentication request message carrying a target identifier sent by a network element device, or receive a third authentication request message without a target identifier and a target identifier sent by a network element device; send a third authentication response message carrying a target identifier to the network element device, or send a third authentication response message without a target identifier and a target identifier to the network element device.
[0466] In one embodiment, the receiving module is further configured to send a re-authentication identifier to the network element device.
[0467] In one embodiment, the authentication device 1600 further includes a pause module for pausing the forwarding of data between the individual user or device corresponding to the target identifier and the network side.
[0468] In one embodiment, the sending module is further configured to send notification information to the individual user or device corresponding to the target identifier. The notification information is used to notify the terminal device to suspend forwarding of data between the individual user or device corresponding to the target identifier and the network side.
[0469] In one embodiment, the terminal device is a smart terminal device or a gateway device, the individual user corresponding to the target identifier is a specific user who uses the smart terminal device to obtain a specific network application service, and the device corresponding to the target identifier is a non-3GPP device that obtains a specific network application service through the smart terminal device or the gateway device. Non-3GPP devices refer to devices that do not have USIM capabilities.
[0470] The aforementioned second verification module, determination module, acquisition module, receiving module, storage module, connection establishment module, and pause module are all located on the terminal device.
[0471] In one embodiment, such as Figure 17 As shown, another authentication device is provided. The authentication device 1700 includes a receiving module 1701 and a sending module 1702, both of which are located on the authentication server.
[0472] The receiving module 1701 is used to receive a second authentication request message carrying a target identifier sent by a network element device, or to receive a second authentication request message without a target identifier and a target identifier sent by a network element device, so as to perform EAP authentication for the individual user or device corresponding to the target identifier; wherein, the target identifier is obtained by the network element device from the first NAS message sent by the terminal device, and the target identifier is the identifier of the individual user or device that uses or accesses the network through the terminal device.
[0473] The sending module 1702 is used to send a second authentication response message carrying a target identifier to the network element device, or to send a second authentication response message without carrying a target identifier and a target identifier to the network element device.
[0474] In one embodiment, the authentication device 1700 further includes a third verification module for verifying whether the individual user or device corresponding to the target identifier is authorized to use the network access service.
[0475] In one embodiment, the second authentication response message includes the master key.
[0476] In one embodiment, the second authentication response message is a first EAP authentication success message, which is used to indicate that the personal user or device corresponding to the target identifier has successfully completed EAP authentication.
[0477] In one embodiment, the target identifier is the identifier of an individual user who uses or accesses the network through a terminal device, and the authentication server is AUSF.
[0478] In one embodiment, the target identifier is the identifier of the device that uses or accesses the network through the terminal device, and the authentication server is a DN-AAA server.
[0479] In one embodiment, the terminal device is a smart terminal device or a gateway device, the individual user corresponding to the target identifier is a specific user who uses the smart terminal device to obtain a specific network application service, and the device corresponding to the target identifier is a non-3GPP device that obtains a specific network application service through the smart terminal device or the gateway device. Non-3GPP devices refer to devices that do not have USIM capabilities.
[0480] The aforementioned third verification module is set up in the authentication server.
[0481] For specific limitations regarding the authentication device, please refer to the limitations on the authentication method above, which will not be repeated here. Each module in the aforementioned authentication device can be implemented entirely or partially through software, hardware, or a combination thereof. These modules can be embedded in or independent of the processor in the computer device in hardware form, or stored in the memory of the computer device in software form, so that the processor can call and execute the operations corresponding to each module.
[0482] Those skilled in the art will understand that all or part of the processes in the methods of the above embodiments can be implemented by a computer program instructing related hardware. The computer program can be stored in a non-volatile computer-readable storage medium, and when executed, it can include the processes of the embodiments of the methods described above. Any references to memory, storage, databases, or other media used in the embodiments provided in this application can include at least one of non-volatile and volatile memory. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, or optical storage, etc. Volatile memory can include random access memory (RAM) or external cache memory. By way of illustration and not limitation, RAM can be in various forms, such as static random access memory (SRAM) or dynamic random access memory (DRAM), etc.
[0483] The technical features of the above embodiments can be combined in any way. For the sake of brevity, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.
[0484] The embodiments described above are merely illustrative of several implementation methods of this application, and while the descriptions are relatively specific and detailed, they should not be construed as limiting the scope of the invention patent. It should be noted that those skilled in the art can make various modifications and improvements without departing from the concept of this application, and these all fall within the protection scope of this application. Therefore, the protection scope of this patent application should be determined by the appended claims.
Claims
1. An authentication method, characterized in that, The method includes: The network element receives a target request message carrying a target identifier from a terminal device, or the network element receives the target request message without carrying the target identifier and the target identifier from the terminal device; wherein, the target identifier is the identifier of an individual user or device that uses or accesses the network through the terminal device; The network element initiates an Extensible Authentication Protocol (EAP) authentication process based on the target identifier.
2. The method according to claim 1, characterized in that, Before the network element initiates the Extensible Authentication Protocol (EAP) authentication process based on the target identifier, the method further includes: The network element device verifies the terminal device and the individual user or device corresponding to the target identifier.
3. The method according to claim 2, characterized in that, The network element device verifies the terminal device and the individual user or device corresponding to the target identifier, including: The network element device verifies the terminal device and the individual user or device corresponding to the target identifier based on the subscription data of the terminal device and / or the configuration data of the individual user or device corresponding to the target identifier.
4. The method according to claim 3, characterized in that, The network element device verifies the terminal device and the individual user or device corresponding to the target identifier based on the subscription data of the terminal device and / or the configuration data of the individual user or device corresponding to the target identifier, including: The network element device checks the subscription data and determines whether the subscription data is associated with the target identifier, thereby determining whether the terminal device is authorized to provide network access services to the individual user or device corresponding to the target identifier, and whether the individual user or device corresponding to the target identifier is authorized to use the network access services provided by the terminal device; or... The network element device checks the configuration data of the individual user or device corresponding to the target identifier. By determining whether the target identifier is associated with the subscription data, it determines whether the terminal device is authorized to provide network access services to the individual user or device corresponding to the target identifier, and whether the individual user or device corresponding to the target identifier is authorized to use the network access services provided by the terminal device; or... The network element device checks the subscription data and determines whether the terminal device is authorized to provide network access services to the individual user or device corresponding to the target identifier by determining whether the subscription data is associated with the target identifier. The network element device checks the configuration data of the individual user or device corresponding to the target identifier, and determines whether the individual user or device corresponding to the target identifier is authorized to use the network access service provided by the terminal device by determining whether the target identifier is associated with the subscription data.
5. The method according to claim 3, characterized in that, The network element device verifies the terminal device and the individual user or device corresponding to the target identifier based on the subscription data of the terminal device and / or the configuration data of the individual user or device corresponding to the target identifier, including: The network element device checks the subscription data and the configuration data of the individual user or device corresponding to the target identifier to determine whether the terminal device is authorized to provide network access services to the individual user or device corresponding to the target identifier, so as to determine whether the individual user or device corresponding to the target identifier is authorized to use the network access services provided by the terminal device.
6. The method according to claim 2, characterized in that, The network element device verifies the terminal device and the individual user or device corresponding to the target identifier, and further includes: The network element device determines whether the individual user or device corresponding to the target identifier has been authenticated based on the configuration data of the individual user or device corresponding to the target identifier.
7. The method according to claim 1, characterized in that, The method further includes: The network element receives a specific identifier sent from the terminal device, and the specific identifier is used to instruct the network element to initiate the EAP authentication process based on the target identifier.
8. The method according to claim 1, characterized in that, The target identifier is the identifier of an individual user who uses or accesses the network through the terminal device, and the configuration data of the individual user corresponding to the target identifier includes at least one of the individual user's user identifier, temporary user identifier, and authentication result.
9. The method according to claim 1, characterized in that, The target identifier is the identifier of a device that uses or accesses the network through the terminal device, and the configuration data of the device corresponding to the target identifier includes at least one of the device identifier, temporary device identifier, and authentication result.
10. The method according to claim 1, characterized in that, The method further includes: The network element device generates a transaction identifier based on the target identifier; The transaction identifier is used by the network element device to identify and forward EAP session messages of the individual user or device corresponding to the target identifier.
11. The method according to claim 1, characterized in that, The network element initiates the EAP authentication process based on the target identifier, including: The network element device sends a second authentication request message carrying the target identifier to the authentication server, or the network element device sends a second authentication request message without carrying the target identifier and the target identifier to the authentication server; The network element device receives a second authentication response message carrying the target identifier sent by the authentication server, or the network element device receives a second authentication response message without carrying the target identifier and the target identifier sent by the authentication server; The network element device sends a target response message carrying the target identifier to the terminal device, or the network element device sends the target response message without carrying the target identifier and the target identifier to the terminal device.
12. The method according to claim 11, characterized in that, The second authentication response message includes the master key.
13. The method according to claim 11, characterized in that, The method further includes: The network element sends the master key to the terminal device.
14. The method according to claim 11, characterized in that, The second authentication response message is a first EAP authentication success message, which indicates that the personal user or device corresponding to the target identifier has successfully completed EAP authentication.
15. The method according to claim 11, characterized in that, The target response message includes a second EAP authentication success message, which instructs the terminal device to forward data between the individual user or device corresponding to the target identifier and the network side.
16. The method according to claim 11, characterized in that, The target identifier is the identifier of an individual user who uses or accesses the network through the terminal device, and the authentication server is an authentication server function (AUSF).
17. The method according to claim 11, characterized in that, The target identifier is the identifier of the device that uses or accesses the network through the terminal device, and the authentication server is a data network authorization, authentication, and accounting (DN-AAA) server.
18. The method according to claim 14, characterized in that, The method further includes: The network element device associates the target identifier with the session context information of the terminal device, or adds the target identifier to the session context of the terminal device.
19. The method according to claim 11, characterized in that, The method further includes: The network element device stores the authentication result of the individual user or device corresponding to the target identifier based on the second authentication response message.
20. The method according to claim 1, characterized in that, The method further includes: The network element device decides to initiate re-authentication for the individual user or device corresponding to the target identifier, and the network element device initiates the EAP authentication process based on the target identifier; or... The authentication server decides to initiate re-authentication for the individual user or device corresponding to the target identifier. The network element receives the re-authentication request containing the target identifier sent by the authentication server, and the network element initiates the EAP authentication process based on the target identifier.
21. The method according to claim 20, characterized in that, Before the network element initiates the EAP authentication process based on the target identifier, the method further includes: The network element sends a third authentication request message carrying the target identifier to the terminal device, or the network element sends the third authentication request message without carrying the target identifier and the target identifier to the terminal device; The network element receives a third authentication response message carrying the target identifier sent by the terminal device, or the network element receives a third authentication response message without carrying the target identifier and the target identifier sent by the terminal device.
22. The method according to claim 21, characterized in that, The method further includes: The network element sends a re-authentication identifier to the terminal device.
23. The method according to claim 1, characterized in that, The terminal device is a smart terminal device or a gateway device. The individual user corresponding to the target identifier is a specific user who uses the smart terminal device to obtain a specific network application service. The device corresponding to the target identifier is a non-3GPP device that obtains a specific network application service through the smart terminal device or the gateway device. The non-3GPP device refers to a device that does not have the Global Subscriber Identity Module (USIM) capability.
24. An authentication method, characterized in that, The method includes: The terminal device sends a target request message carrying a target identifier to the network element device, or the terminal device sends the target request message without carrying the target identifier and the target identifier to the network element device, so that the network element device initiates the EAP authentication process based on the target identifier; The target identifier is the identifier of an individual user or device that uses or accesses the network through the terminal device.
25. The method according to claim 24, characterized in that, The method further includes: The terminal device sends a specific identifier to the network element device, and the specific identifier is used to instruct the network element device to initiate the EAP authentication process based on the target identifier.
26. The method according to claim 24, characterized in that, The method further includes: The terminal device verifies the individual user or device corresponding to the target identifier.
27. The method according to claim 26, characterized in that, The terminal device verifies the individual user or device corresponding to the target identifier, including: The terminal device verifies the individual user or device corresponding to the target identifier based on the subscription data of the terminal device.
28. The method according to claim 27, characterized in that, The terminal device verifies the individual user or device corresponding to the target identifier based on its subscription data, including: The terminal device checks the subscription data and determines whether the subscription data is associated with the target identifier in order to determine whether the individual user or device corresponding to the target identifier is authorized to use the network access service provided by the terminal device.
29. The method according to claim 24, characterized in that, The target identifier is the identifier of an individual user who uses or accesses the network through the terminal device, and the configuration data of the individual user corresponding to the target identifier includes at least one of the individual user's user identifier, temporary user identifier, and authentication result.
30. The method according to claim 24, characterized in that, The target identifier is the identifier of a device that uses or accesses the network through the terminal device, and the configuration data of the device corresponding to the target identifier includes at least one of the device identifier, temporary device identifier, and authentication result.
31. The method according to claim 24, characterized in that, The method further includes: The terminal device acquires the target identifier; The target identifier is a temporary user identifier for an individual user. The terminal device determines whether the temporary user identifier is valid; if invalid, it obtains the user identifier of the individual user corresponding to the target identifier and uses that user identifier as the target identifier; or... The target identifier is a temporary device identifier of the device. The terminal device determines whether the temporary device identifier is valid; if invalid, it obtains the device identifier of the device corresponding to the target identifier and uses the device identifier as the target identifier.
32. The method according to claim 31, characterized in that, When the target identifier is the identifier of a device that uses or accesses the network through the terminal device, obtaining the target identifier includes: The terminal device executes a point-to-point D2D connection establishment process with the device corresponding to the target identifier, and obtains the target identifier during the D2D connection establishment process with the device corresponding to the target identifier.
33. The method according to claim 24, characterized in that, The method further includes: The terminal device receives a target response message carrying the target identifier sent by the network element device, or the terminal device receives the target response message without carrying the target identifier and the target identifier sent by the network element device.
34. The method according to claim 33, characterized in that, The method further includes: The terminal device receives the master key sent by the network element device.
35. The method according to claim 33, characterized in that, The target response message includes a second EAP authentication success message, which instructs the terminal device to forward data between the individual user or device corresponding to the target identifier and the network side.
36. The method according to claim 33, characterized in that, The target response message includes a second EAP authentication success message or an authentication failure message, and the method further includes: The terminal device sends the second EAP authentication success message or EAP authentication failure message to the individual user or device corresponding to the target identifier.
37. The method according to claim 33, characterized in that, The method further includes: The terminal device stores the authentication result of the individual user or device corresponding to the target identifier based on the target response message.
38. The method according to claim 34, characterized in that, The method further includes: The terminal device establishes security protection for the D2D connection based on the master key.
39. The method according to claim 34, characterized in that, The method further includes: The target identifier is a temporary user identifier for an individual user, and the terminal device sends the temporary user identifier to the individual user corresponding to the target identifier. The target identifier is a temporary device identifier of the device, and the terminal device sends the temporary device identifier to the device corresponding to the target identifier.
40. The method according to claim 24, characterized in that, The method further includes: The terminal device receives a third authentication request message carrying the target identifier sent by the network element device, or the terminal device receives the third authentication request message without carrying the target identifier and the target identifier sent by the network element device; The terminal device sends a third authentication response message carrying the target identifier to the network element device, or the terminal device sends a third authentication response message without carrying the target identifier and the target identifier to the network element device.
41. The method according to claim 39, characterized in that, The method further includes: The terminal device sends a re-authentication identifier to the network element device.
42. The method according to claim 40, characterized in that, The method further includes: The terminal device suspends forwarding of data between the individual user or device corresponding to the target identifier and the network side.
43. The method according to claim 40, characterized in that, The method further includes: The terminal device sends a notification message to the individual user or device corresponding to the target identifier. The notification message is used to notify the individual user or device corresponding to the target identifier to suspend the forwarding of data between the individual user or device corresponding to the target identifier and the network side.
44. The method according to claim 24, characterized in that, The terminal device is a smart terminal device or a gateway device. The individual user corresponding to the target identifier is a specific user who uses the smart terminal device to obtain a specific network application service. The device corresponding to the target identifier is a non-3GPP device that obtains a specific network application service through the smart terminal device or the gateway device. The non-3GPP device refers to a device that does not have USIM capability.
45. An authentication method, characterized in that, The method includes: The authentication server receives a second authentication request message carrying a target identifier from a network element device, or the authentication server receives a second authentication request message without the target identifier and the target identifier from the network element device, in order to perform EAP authentication for the individual user or device corresponding to the target identifier; wherein, the target identifier is the identifier of the individual user or device that uses or accesses the network through a terminal device. The authentication server sends a second authentication response message carrying the target identifier to the network element device, or the authentication server sends a second authentication response message without carrying the target identifier and the target identifier to the network element device.
46. The method according to claim 45, characterized in that, The method further includes: The authentication server verifies whether the individual user or device corresponding to the target identifier is authorized to use the network access service.
47. The method according to claim 45, characterized in that, The second authentication response message includes the master key.
48. The method according to claim 45, characterized in that, The second authentication response message is a first EAP authentication success message, which indicates that the personal user or device corresponding to the target identifier has successfully completed EAP authentication.
49. The method according to claim 45, characterized in that, The target identifier is the identifier of an individual user who uses or accesses the network through the terminal device, and the authentication server is AUSF.
50. The method according to claim 45, characterized in that, The target identifier is the identifier of the device used or accessing the network through the terminal device, and the authentication server is a DN-AAA server.
51. The method according to claim 45, characterized in that, The terminal device is a smart terminal device or a gateway device. The individual user corresponding to the target identifier is a specific user who uses the smart terminal device to obtain a specific network application service. The device corresponding to the target identifier is a non-3GPP device that obtains a specific network application service through the smart terminal device or the gateway device. The non-3GPP device refers to a device that does not have USIM capability.
52. An authentication device, characterized in that, The device includes: A receiving module is configured to receive a target request message carrying a target identifier from a terminal device, or to receive the target request message without carrying the target identifier and the target identifier from the terminal device; wherein the target identifier is the identifier of an individual user or device using or accessing the network through the terminal device. The execution module is used by the network element device to initiate the EAP authentication process based on the target identifier.
53. An authentication device, characterized in that, The device includes: The sending module is used for the terminal device to send a target request message carrying a target identifier to the network element device, or for the terminal device to send the target request message without carrying the target identifier and the target identifier to the network element device, so that the network element device initiates the EAP authentication process based on the target identifier; The target identifier is the identifier of an individual user or device that uses or accesses the network through the terminal device.
54. An authentication device, characterized in that, The device includes: The receiving module is used for the authentication server to receive a second authentication request message carrying a target identifier sent by a network element device, or for the authentication server to receive a second authentication request message without carrying the target identifier and the target identifier sent by the network element device, so as to perform EAP authentication for the individual user or device corresponding to the target identifier; the target identifier is the identifier of the individual user or device that uses or accesses the network through a terminal device. The sending module is used for the authentication server to send a second authentication response message carrying the target identifier to the network element device, or for the authentication server to send a second authentication response message without carrying the target identifier and the target identifier to the network element device.
55. A communication device, comprising: A transceiver, a memory, and a processor, the memory storing a computer program, characterized in that, when the processor executes the computer program, it controls the transceiver to implement the steps of any one of claims 1 to 23, or 24 to 44, or 45 to 51.
56. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, it implements the steps of the method according to any one of claims 1 to 23, or 24 to 44, or 45 to 51.
57. A computer program product, comprising a computer program, characterized in that, When executed by a processor, the computer program implements the steps of the method according to any one of claims 1 to 23, or 24 to 44, or 45 to 51.