Method and system for supporting unified and rapid authentication of 5G core network users

By introducing a unified and fast authentication method in the 5G core network and dynamically adjusting the security level and authentication strategy, the complexity caused by multiple authentications is solved, enabling terminals to access the 5G network quickly and securely, and improving authentication efficiency and trustworthiness.

CN121013079APending Publication Date: 2025-11-25DATA COMM SCI & TECH RES INST +2
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202410645170.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-05-23
Publication Date
2025-11-25

AI Technical Summary

Technical Problem

The existing multi-authentication mechanism in 5G mobile communication systems leads to complex processes, reduces the efficiency of users in executing business processes, and makes it impossible to perform differentiated authentication processing on terminal UEs.

Method used

A method for unified and rapid authentication of 5G core network users is introduced. By identifying the terminal security level, dynamically adjusting the authentication strategy, generating or querying the authentication vector, rapid authentication is achieved. The method also unifies the primary authentication, secondary authentication and slice authentication processes without changing the 5G core network framework.

Benefits of technology

Without altering the existing network framework, this approach reduces authentication time and costs, improves authentication efficiency, enables differentiated authentication processes, ensures secure, fast, and efficient terminal access to the core network, and strengthens the trust relationship between terminals and the core network.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121013079A_ABST
    Figure CN121013079A_ABST
Patent Text Reader

Abstract

The invention relates to a method and a system for supporting unified and rapid authentication of 5G core network users, belongs to the technical field of communication security, and solves the problems of complexity and low efficiency of multiple authentication in the prior art. Comprising the following steps: receiving a terminal authentication request sent by a core network element in a 5G core network authentication process; when the terminal is identified as a secure user according to the terminal authentication request, acquiring a security level of a current authentication environment; identifying whether rapid authentication is supported or not according to the security level, and if the rapid authentication is supported, querying or generating an authentication vector according to a 5G core network authentication type and a terminal identity identifier in the terminal authentication request; if the rapid authentication is not supported, discarding the terminal authentication request or generating an authentication vector according to the terminal identity identifier; and the core network element receives the authentication vector, sends the authentication vector to the terminal according to a 3GPP standard, and executes and completes a 5G core network authentication process. The differentiated rapid authentication processing flow is realized, and the multi-authentication efficiency is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of communication security technology, and in particular to a method and system for supporting unified and rapid authentication of 5G core network users. Background Technology

[0002] With the continuous development of mobile communication technology, 5G, as the latest mobile communication technology, is gradually changing our lifestyles with its advantages of high speed, low latency and large capacity. In 5G mobile communication systems, multiple authentication and authorization methods are one of the most critical processes for secure communication and are the foundation for establishing trust between the terminal side and the communication network side.

[0003] To protect legitimate users and secure network access, existing 3GPP standards propose various authentication methods based on application scenario requirements, including primary authentication, secondary authentication, and slice authentication, providing multiple security mechanisms for terminals to access different network resources.

[0004] However, current primary authentication, secondary authentication, and slice authentication mechanisms are all independently designed. While the superposition of multiple authentication mechanisms can improve secure access capabilities for high-security users, it also leads to increased complexity in process and resource management, reducing the efficiency of users executing business processes. Furthermore, it fails to provide differentiated authentication processing for terminal UEs accessing the network. Therefore, from a user security perspective, how to ensure the secure access of legitimate users to the network and provide fast and effective authentication services for terminal UEs during 5G service authentication and authorization processes is currently a key research focus. Summary of the Invention

[0005] Based on the above analysis, the embodiments of the present invention aim to provide a method and system for supporting unified and rapid authentication of 5G core network users, so as to solve the problems of complexity and low efficiency of existing multi-factor authentication.

[0006] On one hand, embodiments of the present invention provide a method for supporting unified and rapid authentication of 5G core network users, comprising the following steps:

[0007] Receive terminal authentication requests sent by core network elements during the 5G core network authentication process;

[0008] When a terminal is identified as a secure user based on the terminal authentication request, the security level of the current authentication environment is obtained; based on the security level, it is determined whether fast authentication is supported. If fast authentication is supported, the authentication vector is queried or generated based on the 5G core network authentication type and the terminal identity identifier in the terminal authentication request; if fast authentication is not supported, the terminal authentication request is discarded or an authentication vector is generated based on the terminal identity identifier.

[0009] The core network element receives the authentication vector and sends it to the terminal according to the 3GPP standard, thus completing the 5G core network authentication process.

[0010] Based on the further improvement of the above method, the terminal is identified as a secure user based on the terminal authentication request. This is done by obtaining the number of terminal authentication requests that have the same terminal identity and authentication type as the terminal authentication request, but different network service identifier or terminal device identifier within a preset time period before the current time. If the number does not exceed the security threshold, the terminal is considered a secure user.

[0011] Based on the further improvements to the above method, the security level includes the highest level and the normal level; the security level of the current authentication environment is obtained by periodically counting whether the number of received terminal authentication requests exceeds the total number threshold. If it exceeds, the security level is adjusted to the highest level; otherwise, the default security level is used.

[0012] Based on further improvements to the above method, when the security level is at its highest level, fast authentication is not supported; otherwise, fast authentication is supported.

[0013] Based on further improvements to the above methods, the 5G core network authentication types include: 5G primary authentication, secondary authentication, and slice authentication.

[0014] Based on the above method, the method further includes: storing the authentication algorithm and root key corresponding to each 5G core network authentication type; and pre-injecting terminal identity information into the database by calling the identity trust interface. The terminal identity information includes: terminal identity identifier, terminal device identifier, serving network identifier, authentication status, authentication time, aging time, and authentication vector.

[0015] Based on the further improvement of the above method, the authentication vector is generated according to the authentication algorithm and root key corresponding to the 5G core network authentication type; the authentication vector is a vector composed of random number RAND, terminal expected response XRES, encryption key CK, integrity key IK and authentication token AUTN.

[0016] Based on further improvements to the above method, if fast authentication is supported, the authentication vector can be queried or generated according to the 5G core network authentication type and the terminal identity identifier in the terminal authentication request, including:

[0017] Based on the terminal identity identifier in the terminal authentication request, query the pre-injected terminal identity information. If the terminal exists and the current time has not exceeded the aging time, obtain the authentication vector already stored for the terminal. If the terminal exists but the current time has exceeded the aging time, generate an authentication vector and update the corresponding authentication vector and aging time in the database. If the terminal does not exist, generate an authentication vector and then combine it with the terminal identity information to store it in the database.

[0018] Based on further improvements to the above method, if fast authentication is not supported, the authentication request can be discarded or an authentication vector can be generated based on the terminal identity, including:

[0019] Based on the terminal identity identifier in the terminal authentication request, query the pre-injected terminal identity information. If the terminal does not exist, discard the authentication request; if the terminal exists, generate an authentication vector and update the corresponding authentication vector and aging time in the database.

[0020] On the other hand, embodiments of the present invention provide a system supporting unified and rapid authentication for 5G core network users, comprising:

[0021] The authentication module is used to send the terminal authentication request received by the core network element to the data processing module according to the 3GPP standard, and to receive the authentication vector fed back by the data processing module through the core network element and send the authentication vector to the terminal to complete the 5G core network authentication process.

[0022] The data processing module is used to receive terminal authentication requests sent by core network elements in the authentication module through the data access interface, send them to the authentication control module, receive the authentication vector fed back by the authentication control module, and feed the authentication vector back to the authentication module.

[0023] The authentication control module is used to obtain the security level of the current authentication environment when the terminal is identified as a secure user based on the terminal authentication request; determine whether fast authentication is supported based on the security level; if fast authentication is supported, query or generate an authentication vector based on the 5G core network authentication type and the terminal identity identifier in the terminal authentication request; if fast authentication is not supported, discard the terminal authentication request or generate an authentication vector based on the terminal identity identifier; and send the authentication vector to the data processing module.

[0024] Compared with existing technologies, the present invention can achieve at least one of the following beneficial effects: without changing the 5G core network framework, it enables unified and rapid authentication of users in the authentication process of primary authentication, secondary authentication, and slice authentication of the terminal UE, reducing time costs, and dynamically adjusting the security level to achieve differentiated authentication processing procedures. This ensures that the terminal can securely, quickly, and effectively access the core network in various scenarios, enhances mutual trust between the terminal and the core network, reduces the complexity of multi-authentication, and improves the efficiency of multi-authentication.

[0025] In this invention, the above-described technical solutions can be combined with each other to achieve more preferred combinations. Other features and advantages of this invention will be set forth in the following description, and some advantages may become apparent from the description or be learned by practicing the invention. The objects and other advantages of this invention can be realized and obtained from what is particularly pointed out in the description and drawings. Attached Figure Description

[0026] The accompanying drawings are for illustrative purposes only and are not intended to limit the invention. Throughout the drawings, the same reference numerals denote the same parts.

[0027] Figure 1 This is a flowchart of a method for supporting unified and rapid authentication of 5G core network users in Embodiment 1 of the present invention;

[0028] Figure 2 This is a schematic diagram of a system structure that supports unified and rapid authentication for 5G core network users in Embodiment 1 of the present invention. Detailed Implementation

[0029] Preferred embodiments of the present invention will now be described in detail with reference to the accompanying drawings, which form part of this application and are used together with the embodiments of the present invention to illustrate the principles of the present invention, but are not intended to limit the scope of the present invention.

[0030] Example 1

[0031] One specific embodiment of the present invention discloses a method for supporting unified and rapid authentication of 5G core network users, such as... Figure 1 As shown, it includes the following steps:

[0032] S1. Receive terminal authentication requests sent by core network elements during the 5G core network authentication process;

[0033] S2. When the terminal is identified as a secure user based on the terminal authentication request, obtain the security level of the current authentication environment; determine whether fast authentication is supported based on the security level; if fast authentication is supported, query or generate the authentication vector based on the 5G core network authentication type and the terminal identity identifier in the terminal authentication request; if fast authentication is not supported, discard the terminal authentication request or generate the authentication vector based on the terminal identity identifier.

[0034] S3. The core network element receives the authentication vector and sends it to the terminal according to the 3GPP standard, thus completing the 5G core network authentication process.

[0035] It should be noted that this embodiment introduces the Extended Authentication and Authorization Protocol (EAP-AKA) into the 5G core network, making this method applicable to various 5G core network authentication processes: enabling secure access for terminal UE primary authentication, and applicable to secondary authentication and slice authentication, thereby improving the flexibility and scalability of the solution.

[0036] During implementation, without changing the 5G core network framework, the above steps replace the original authentication vector acquisition method in the authentication process. This reduces the time cost for the terminal UE under multiple authentication methods, allows for shared key data, and enables on-demand configuration of security policies. It enables the terminal to securely, quickly, and effectively access the 5G core network, and is an important solution to enhance mutual trust between the terminal and the core network.

[0037] It should be noted that in step S1, the data access interface receives the terminal authentication request sent by the core network element in the 5G core network authentication process and configures the core network element and corresponding authentication type for adaptive access through the interface policy. On the other hand, the authentication vector obtained in step S2 is fed back to the core network element and finally returned to the terminal. The terminal uses the received authentication vector to authenticate the network.

[0038] Specifically, in the main authentication process: the terminal UE (User Equipment) uses the encrypted user identity identifier SUCI (Subscription Concealed Identifier, SUPI-encrypted user identification code) and initiates registration with the visited network SEAF (Security Anchor Function); upon receiving the terminal's registration request, the SEAF sends an authentication request to the terminal user's home network AUSF (Authentication Server Function) according to the 3GPP standard (3rd Generation Partnership Project); the home network AUSF requests authentication information from the UDM (Unified Data Management) according to the 3GPP standard. At this time, in step S1, the terminal authentication request after the core network element UDM decrypts the SUCI is received.

[0039] In the secondary authentication process: the terminal UE requests to establish a PDU (Protocol Data Unit) session and completes the basic authentication process; after receiving the PDU session establishment request from the terminal UE, the SMF (Session Management Function) initiates an EAP (Extensible Authentication Protocol) authentication request (EAP-Request / Identity) to the terminal UE; upon receiving the EAP response (EAP-Response / Identity) from the terminal UE, the UDM initiates the secondary authentication process, and the UPF establishes a transparent channel between the terminal UE and the DN-AAA server (Data Network Authentication, Authorization, and Accounting server); the DN-AAA server sends EAP request data (EAP-Request / Message) to the terminal UE; after receiving the EAP-Request / Message from the DN-AAA server, the terminal UE generates EAP response data (EAP-Response / Message) and sends it to the DN-AAA server. At this time, in step S1, the core network element DN-AAA server sends an EAP authentication request.

[0040] In the slice authentication process: the terminal UE requests access to a specific slice network, and the AMF triggers the slice authentication process after receiving the UE's registration request; the AMF sends a slice authentication request to the NSSAAF, and the NSSAAF sends it to the AAA server (Authentication, Authorization, and Accounting). At this time, the slice authentication request sent by the core network element AAA server is received in step S1.

[0041] Further, in step S2, a security risk assessment is first performed based on the terminal identity identifier, terminal device identifier, network service identifier, and authentication type in the authentication request to identify whether the terminal is a secure user. Specifically, this is done by obtaining the number of terminal authentication requests within a preset time period prior to the current time that have the same terminal identity identifier and authentication type as the terminal authentication request, but different network service identifier or terminal device identifier. If the number does not exceed a security threshold, the terminal is considered a secure user.

[0042] For example, if the same terminal identity makes the same authentication type authentication request multiple times using different terminal devices within 1 second, and the number of times exceeds the security threshold, then the terminal is considered to be at risk, the authentication request is not responded to and is discarded; otherwise, the terminal is considered a safe user, and the next security level identification is performed.

[0043] It should be noted that security levels include the highest level and the normal level. The highest level corresponds to a high-risk security policy, prohibiting access to terminals that have not been pre-injected, and also prohibiting access to terminals that have been pre-injected via fast authentication methods. The normal level corresponds to a low-risk security policy, allowing access via fast authentication methods. By setting different security policies according to security levels, different user security needs can be met, enabling differentiated authentication processes for terminal access to the network.

[0044] Specifically, this embodiment initially configures a security level by default based on the actual situation. During the authentication process, it monitors the current authentication environment in real time. Once it determines that the authentication environment is at risk of being attacked by the network, it automatically switches the security level to the highest level. In other words, the security level of the current authentication environment is obtained by periodically counting whether the number of received terminal authentication requests exceeds a total threshold. If it does, the security level is adjusted to the highest level; otherwise, the default security level is used.

[0045] Preferably, a method for modifying the security level through the interface is provided, and a security level change log is recorded.

[0046] It should be noted that in this embodiment, the authentication algorithm and root key corresponding to each authentication type are pre-stored in the database. The authentication algorithm can be adjusted according to actual needs, including: various international standard authentication algorithms, such as the asymmetric encryption algorithm RSA and the symmetric encryption algorithm AES; commercial cryptographic algorithms, such as the symmetric encryption algorithm SM4, the cryptographic hash algorithm SM3, and the elliptic curve public-key cryptography algorithm SM2; and encryption algorithms recognized by the user terminal. In other words, in this embodiment, the authentication algorithm is loosely coupled with each authentication process, not only supporting multiple authentication algorithms but also enabling dynamic adjustment of the authentication algorithm, thus improving authentication security.

[0047] It should be noted that terminal identity information is pre-injected into the database by calling the identity trust interface. This terminal identity information includes: terminal identity identifier, terminal device identifier, service network identifier, authentication status, authentication time, aging time, and authentication vector. During pre-injection, the authentication status is always mutual trust.

[0048] Furthermore, ① when the security level is identified as normal, fast authentication is supported.

[0049] At this point, based on the 5G core network authentication type and the terminal identity identifier in the terminal authentication request, the authentication vector is retrieved or generated, including:

[0050] Based on the terminal identity identifier in the terminal authentication request, query the pre-injected terminal identity information. If the terminal exists and the current time has not exceeded the aging time, obtain the authentication vector already stored for the terminal. If the terminal exists but the current time has exceeded the aging time, generate an authentication vector and update the corresponding authentication vector and aging time in the database. If the terminal does not exist, generate an authentication vector and then combine it with the terminal identity information to store it in the database.

[0051] It should be noted that the authentication vector is generated based on the authentication algorithm and root key corresponding to the 5G core network authentication type; the authentication vector is a vector composed of a random number RAND, the terminal's expected response XRES, the encryption key CK, the integrity key IK, and the authentication token AUTN.

[0052] ② When the highest security level is identified, fast authentication is not supported.

[0053] At this point, based on the terminal's identity, the authentication request is discarded or an authentication vector is generated, including:

[0054] Based on the terminal identity identifier in the terminal authentication request, query the pre-injected terminal identity information. If the terminal does not exist, discard the authentication request; if the terminal exists, generate an authentication vector and update the corresponding authentication vector and aging time in the database.

[0055] In step S3, when the core network element in each authentication process receives the authentication vector, if it identifies the terminal as not a secure user in step S2, or if it identifies the security level as the highest and the terminal identity information has not been pre-injected, and has already discarded the authentication request, the core network element's timeout for receiving the authentication vector will occur, and the authentication process will automatically terminate. Otherwise, the corresponding core network element receives the authentication vector and sends it to the terminal according to the 3GPP standard, thus completing the 5G core network authentication process.

[0056] It should be noted that although this embodiment is a method for fast user authentication in 5G core networks, the method is also applicable to 4G mobile communication systems. Introducing the fast authentication method of this embodiment into the 4G user registration and authentication process ensures that terminal users can access the core network securely and efficiently.

[0057] Specifically, in the 4G mobile communication standard, when a terminal UE initiates a registration request, the core network element MME (Mobility Management Entity) receives the user registration and sends an authentication request message to the HSS (Home Subscriber Server). After receiving the authentication request message, the HSS on the core network side performs the user registration negotiation process. After successful authentication, it receives the authentication request sent by the core network element HSS in step S1, obtains the authentication vector in step S2, and feeds it back to the HSS. The HSS then sends the authentication message to the MME. The MME sends the authentication response to the user terminal according to the 3GPP standard process, ensuring that the terminal UE can access the core network securely and efficiently.

[0058] Compared with existing technologies, this embodiment provides a method for unified and rapid authentication of 5G core network users. Without changing the 4G / 5G core network framework, it enables unified and rapid authentication of users in the authentication process of primary authentication, secondary authentication, and slice authentication performed by the terminal UE, reducing time costs and dynamically adjusting the security level to achieve differentiated authentication processing. This ensures that the terminal can securely, quickly, and effectively access the core network in various scenarios, enhances mutual trust between the terminal and the core network, reduces the complexity of multi-authentication, and improves the efficiency of multi-authentication.

[0059] Example 2

[0060] Another embodiment of the present invention discloses a system supporting unified and rapid authentication for 5G core network users, thereby implementing the method for supporting unified and rapid authentication for 5G core network users in Embodiment 1. The specific implementation of each module is described in the corresponding description in Embodiment 1. Figure 2 As shown, the system includes:

[0061] The authentication module 101 is used to send the terminal authentication request received by the core network element to the data processing module according to the 3GPP standard, and to receive the authentication vector fed back by the data processing module through the core network element and send the authentication vector to the terminal to complete the 5G core network authentication process.

[0062] The data processing module 102 is used to receive terminal authentication requests sent by core network elements in the authentication module through the data access interface, send them to the authentication control module, receive the authentication vector fed back by the authentication control module, and feed back the authentication vector to the authentication module.

[0063] The authentication control module 103 is used to obtain the security level of the current authentication environment when the terminal is identified as a secure user based on the terminal authentication request; to identify whether fast authentication is supported based on the security level; if fast authentication is supported, to query or generate an authentication vector based on the 5G core network authentication type and the terminal identity identifier in the terminal authentication request; if fast authentication is not supported, to discard the terminal authentication request or generate an authentication vector based on the terminal identity identifier; and to send the authentication vector to the data processing module.

[0064] Furthermore, the data processing module also includes interface strategies for configuring core network elements for adaptive access and their corresponding authentication types.

[0065] Specifically, the authentication control module includes a risk assessment unit, a security management unit, an identity management unit, a key management unit, and an authentication processing unit. The identity management unit provides an identity trust interface for pre-injecting terminal identity information into the database; the key management unit sets the authentication algorithm and root key corresponding to each 5G core network authentication type, stores them in the database, and can adjust them according to actual conditions; the risk assessment unit identifies whether the terminal is a secure user based on the terminal authentication request; the security management unit initializes the security level and dynamically adjusts the security level according to the current authentication environment; and the authentication processing unit, in conjunction with the risk assessment unit, security management unit, identity management unit, and key management unit, obtains the authentication vector according to the method in Example 1.

[0066] Since the system for unified and rapid authentication of 5G core network users in this embodiment and the aforementioned method for unified and rapid authentication of 5G core network users are related and can be mutually referenced, this description is redundant and will not be repeated here. Because this system embodiment shares the same principle as the aforementioned method embodiment, it also possesses the corresponding technical effects of the aforementioned method embodiment.

[0067] Those skilled in the art will understand that all or part of the processes of the methods described in the above embodiments can be implemented by a computer program instructing related hardware, and the program can be stored in a computer-readable storage medium. The computer-readable storage medium may be a disk, optical disk, read-only memory, or random access memory, etc.

[0068] The above description is only a preferred embodiment of the present invention, but the scope of protection of the present invention is not limited thereto. Any changes or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in the present invention should be included within the scope of protection of the present invention.

Claims

1.A method for supporting unified fast authentication of a 5G core network user, characterized in that, The method comprises the following steps: receiving a terminal authentication request sent by a core network element in a 5G core network authentication process; when it is identified according to the terminal authentication request that the terminal is a secure user, obtaining a security level of a current authentication environment; according to the security level, identifying whether to support fast authentication, if supporting fast authentication, according to a 5G core network authentication type and a terminal identity in the terminal authentication request, querying or generating an authentication vector; if not supporting fast authentication, discarding the terminal authentication request or generating an authentication vector according to the terminal identity; the core network element receives the authentication vector, and sends the authentication vector to the terminal according to the 3GPP standard, and completes the 5G core network authentication process. 2.The method of claim 1, wherein, According to the terminal authentication request, it is identified that the terminal is a secure user, by obtaining the number of terminal authentication requests with the same terminal identity and authentication type as the terminal authentication request, but different network service identities or terminal device identities within a preset time period before the current time, if the number does not exceed a security number threshold, the terminal is a secure user. 3.The method of claim 1, wherein, The security level includes the highest level and the normal level; the security level of the current authentication environment is obtained by regularly counting whether the number of received terminal authentication requests exceeds a total number threshold, if it exceeds, the security level is adjusted to the highest level; otherwise, the security level is configured by default. 4.The method of claim 3, wherein, When the security level is the highest level, fast authentication is not supported; otherwise, fast authentication is supported. 5.The method of claim 1, wherein, The 5G core network authentication type includes: 5G primary authentication, secondary authentication and slice authentication. 6.The method of claim 5, wherein, The method further comprises: storing an authentication algorithm and a root key corresponding to each 5G core network authentication type; and pre-injecting terminal identity information in the database by calling an identity trust interface, the terminal identity information including: terminal identity, terminal device identity, service network identity, authentication state, authentication time, aging time and authentication vector. 7.The method of claim 6, wherein, The authentication vector is generated according to the authentication algorithm and the root key corresponding to the 5G core network authentication type; the authentication vector is a vector composed of random number RAND, terminal expected response XRES, encryption key CK, integrity key IK and authentication token AUTN. 8.The method of claim 7, wherein, If fast authentication is supported, according to the 5G core network authentication type and the terminal identity in the terminal authentication request, the authentication vector is queried or generated, comprising: According to the terminal identity in the terminal authentication request, query the pre-injected terminal identity information, if the terminal exists and the current time does not exceed the aging time, obtain the stored authentication vector of the terminal; if the terminal exists but the current time exceeds the aging time, generate an authentication vector and update the corresponding authentication vector and aging time in the database; if the terminal does not exist, generate an authentication vector and store the terminal identity information in the database. 9.The method of claim 7, wherein, If fast authentication is not supported, the authentication request is discarded or an authentication vector is generated according to the terminal identity, comprising: According to the terminal identity in the terminal authentication request, the pre-injected terminal identity information is queried, if the terminal does not exist, the authentication request is discarded; if the terminal exists, the authentication vector is generated, and the corresponding authentication vector and aging time in the database are updated. 10.A system for supporting unified fast authentication of a 5G core network user, characterized in that, Comprise: The authentication module is used for sending the terminal authentication request received by the core network element to the data processing module according to the 3GPP standard, receiving the authentication vector fed back by the data processing module through the core network element, and sending the authentication vector to the terminal, and executing the 5G core network authentication process; The data processing module is used for receiving the terminal authentication request sent by the core network element in the authentication module through the data access interface, sending to the authentication control module, and receiving the authentication vector fed back by the authentication control module, and feeding back the authentication vector to the authentication module; The authentication control module is used for identifying the terminal as a security user according to the terminal authentication request; According to the security level, it is identified whether to support fast authentication, if it supports fast authentication, according to the 5G core network authentication type and the terminal identity in the terminal authentication request, the authentication vector is queried or generated; If it does not support fast authentication, the terminal authentication request is discarded or the authentication vector is generated according to the terminal identity; the authentication vector is sent to the data processing module.