User authentication method, communication device and storage medium

CN121128202APending Publication Date: 2025-12-12BEIJING XIAOMI MOBILE SOFTWARE CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202480006437.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-04-10
Publication Date
2025-12-12

AI Technical Summary

Technical Problem

In existing mobile networks, user equipment access and legal authentication are mainly based on contract information, which lacks flexibility and security, making it difficult to achieve separate authentication for different devices using the same user equipment.

Method used

A first network function is introduced to perform user authentication. By determining whether to authenticate the first user, a user authentication process is initiated, and the user configuration information and capability information are used to determine the authentication method, signaling overhead is reduced and security is improved.

Benefits of technology

It enables separate authentication of different devices using the same user device within the mobile network, improving user security and authentication efficiency, and reducing the risk of illegal use.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121128202A_ABST
    Figure CN121128202A_ABST
Patent Text Reader

Abstract

The embodiment of the invention provides a user authentication method, communication equipment and a storage medium. A user authentication method performed by a first network function may include: determining whether to perform user authentication on a first user; and determining to perform user authentication on the first user, and initiating a user authentication process of the first user.
Need to check novelty before this filing date? Find Prior Art

Description

User authentication method, communication device and storage medium TECHNICAL FIELD

[0001] The present disclosure relates to the technical field of communication, and in particular to a user authentication method, a communication device and a storage medium. BACKGROUND

[0002] Current mobile networks are based on user subscription, which enables communication operators to perform network access and / or legal authentication of user equipment (UE) based on subscription information.

[0003] SUMMARY

[0004] Embodiments of the present disclosure provide a user authentication method, a communication device and a storage medium.

[0005] According to a first aspect of embodiments of the present disclosure, a user authentication method is provided, wherein the method is performed by a first network function, and the method comprises: determining whether to perform user authentication on a first user; and determining to perform user authentication on the first user, initiating a user authentication procedure of the first user.

[0006] According to a second aspect of embodiments of the present disclosure, a user authentication method is provided, wherein the method is performed by a first UE, and the method comprises: sending a first request to a first network function; the first request at least comprising user identity information of a first user using the first UE; and determining whether to perform user authentication on the first user after the first request is received by the first network function.

[0007] According to a third aspect of embodiments of the present disclosure, a user authentication method is provided, wherein the method is performed by a second network function, and the method comprises: sending user configuration information of a first user to a first network function; the user configuration information being used by the first network function to determine whether to perform user authentication on the first user and / or an authentication manner of the user authentication.

[0008] According to a fourth aspect of embodiments of the present disclosure, a user authentication method is provided, wherein the method is performed by a third network function, and the method comprises: receiving a second indication sent by a first network function; the second indication being used to request to perform user authentication on a first user;

[0009] Performing user authentication on the first user according to the second indication.

[0010] According to a fifth aspect of embodiments of the present disclosure, a first network function is provided, and the first network function comprises:

[0011] a processing module configured to determine whether to perform user authentication on a first user, and determine to perform user authentication on the first user, and initiate a user authentication procedure of the first user.

[0012] According to a sixth aspect of the embodiments of the present disclosure, a first user equipment (UE) is provided, and the first UE comprises:

[0013] a sending module configured to send a first request to a first network function, wherein the first request comprises at least user identity information of a first user of the first UE, and the first request is used to determine whether to perform user authentication on the first user after the first request is received by the first network function.

[0014] According to a seventh aspect of the embodiments of the present disclosure, a second network function is provided, and the second network function comprises:

[0015] a receiving module configured to receive a first indication sent by the first network function, wherein the first indication is used to indicate that the first UE performs user authentication on the first user with a third network function.

[0016] According to an eighth aspect of the embodiments of the present disclosure, a third network function is provided, and the third network function comprises:

[0017] a receiving module configured to receive a second indication sent by the first network function, wherein the second indication is used to request to perform user authentication on the first user.

[0018] a processing module configured to perform user authentication on the first user according to the second indication.

[0019] According to a ninth aspect of the embodiments of the present disclosure, a communication device is provided, and the communication device comprises one or more processors, wherein the processors are used to invoke instructions to enable the communication device to perform the user authentication method provided in any of the first aspect to the fourth aspect.

[0020] According to a tenth aspect of the embodiments of the present disclosure, a storage medium is provided, and the storage medium stores instructions, when the instructions are run on a communication device, the communication device is enabled to perform the user authentication method provided in any of the first aspect to the fourth aspect.

[0021] According to an eleventh aspect of the embodiments of the present disclosure, a communication system is provided, and the communication system comprises: a first network function configured to perform the user authentication method provided in any of the first aspect; a first user equipment (UE) configured to perform the user authentication method provided in any of the second aspect; a second network function configured to perform the user authentication method provided in any of the third aspect; and a third network function configured to perform the user authentication method provided in any of the fourth aspect.

[0022] According to a twelfth aspect of the embodiments of the present disclosure, a program product is provided, including a computer program, which, when executed by a communication device, causes the communication device to perform the user authentication method provided in any of the first aspect to the fourth aspect.

[0023] The technical means provided by the embodiments of the present disclosure is that the first network function performs user authentication, so that user authentication is introduced into the mobile network, different devices use the same UE for separate authentication, and the security of the first user is improved.

[0024] It should be understood that the foregoing general description and the following detailed description are only exemplary and explanatory, and cannot limit the embodiments of the present disclosure. BRIEF DESCRIPTION OF DRAWINGS

[0025] The accompanying drawings, which are incorporated into the specification and constitute a part of the specification, illustrate the embodiments consistent with the present disclosure, and together with the specification, serve to explain the principles of the embodiments of the present disclosure.

[0026] FIG. 1 is a schematic diagram of an architecture of a communication system according to an exemplary embodiment;

[0027] FIG. 2 is a schematic diagram of a user authentication method according to an exemplary embodiment;

[0028] FIG. 3 is a schematic diagram of a user authentication method according to an exemplary embodiment;

[0029] FIG. 4 is a schematic diagram of a user authentication method according to an exemplary embodiment;

[0030] FIG. 5 is a schematic diagram of a user authentication method according to an exemplary embodiment;

[0031] FIG. 6 is a schematic diagram of a user authentication method according to an exemplary embodiment;

[0032] FIG. 7A is a schematic diagram of a user authentication method according to an exemplary embodiment;

[0033] FIG. 7B is a schematic diagram of a user authentication method according to an exemplary embodiment;

[0034] FIG. 8A is a schematic diagram of a structure of a first network function according to an exemplary embodiment;

[0035] FIG. 8B is a schematic diagram of a structure of a first UE according to an exemplary embodiment;

[0036] FIG. 8C is a schematic diagram of a structure of a second network function according to an exemplary embodiment;

[0037] FIG. 8D is a schematic diagram of a third network function according to an example embodiment;

[0038] FIG. 9A is a schematic diagram of a communication device according to an example embodiment;

[0039] FIG. 9B is a schematic diagram of a chip according to an example embodiment. DETAILED DESCRIPTION

[0040] A first aspect of the embodiments of the present disclosure provides a user authentication method, wherein the method is performed by a first network function, and the method comprises:

[0041] determining whether to perform user authentication on a first user;

[0042] determining to perform user authentication on the first user, and initiating a user authentication procedure of the first user.

[0043] According to the above scheme, the first network function performs user authentication, so that user authentication is introduced in the mobile network, different devices using the same UE are authenticated respectively, and the security of the first user is improved.

[0044] In some embodiments of the first aspect, the method further comprises:

[0045] receiving a first request sent by a first user equipment (UE) used by the first user, wherein the first request at least comprises user identity information of the first user; and determining whether to perform user authentication on the first user comprises:

[0046] receiving the first request, and determining whether to perform user authentication on the first user.

[0047] According to the above scheme, the first network function performs authentication based on the first request sent by the first UE, so that the first UE can trigger authentication based on the first request.

[0048] In some embodiments of the first aspect, the first request is a registration request of the first UE and / or a first device; the first UE is a UE used by the first user; and the first device is a device associated with the first UE; and the method further comprises at least one of the following:

[0049] determining not to perform user authentication on the first user and / or that user authentication of the first user fails, and sending a first response to the first UE, wherein the first response indicates that the first request is rejected;

[0050] determining that user authentication of the first user is passed and that network access authentication of the first UE and / or the first device is passed, and sending a second response to the first UE, wherein the second response indicates that the first request is accepted.

[0051] Based on the above scheme, the first request is a registration request, so that in the process of network access authentication of the first user using the first UE, the user authentication is triggered by the registration request, the signaling overhead is reduced, and if the user authentication of the first user is not performed and / or the authentication of the first user fails, the network access of the first UE is rejected, so that the illegal use of the first UE by the first user can be reduced from the beginning of the network access of the first UE.

[0052] In some embodiments of the first aspect, the first response comprises a failure cause.

[0053] Based on the above scheme, the first response comprises a failure cause, which facilitates the first UE to know the reason why the first request is rejected, thereby improving user experience.

[0054] In some embodiments of the first aspect, the failure cause comprises at least one of:

[0055] The user authentication of the first user is not supported;

[0056] The reason why the user authentication of the first user is not supported;

[0057] The user authentication of the first user fails;

[0058] The reason why the user authentication of the first user fails.

[0059] In some embodiments of the first aspect, the first request comprises at least one of:

[0060] A first subscription identifier, the first subscription identifier being used to identify the first UE;

[0061] A first device identifier, the first device identifier being used to identify a first device used by the first user;

[0062] Capability information; the capability information is used to indicate to the first network function whether the first UE and / or the first device supports user authentication;

[0063] The first UE is a UE used by the first user; and the first device is a device associated with the first UE.

[0064] In some embodiments of the first aspect, determining whether to perform user authentication on the first user comprises:

[0065] Determining whether to perform user authentication on the first user according to user configuration information of the first user.

[0066] In some embodiments of the first aspect, determining whether to perform user authentication on the first user according to user configuration information of the first user comprises at least one of:

[0067] Whether the user configuration information of the first user is activated, determining whether to perform user authentication on the first user;

[0068] determining whether to perform user authentication on the first user according to whether the first subscription identifier can identify the second device; the first subscription identifier being used to identify a first UE used by the first user; and the second subscription identifier of the second device or a second device identifier being recorded in the user configuration information;

[0069] determining whether to perform user authentication on the first user according to whether the first device identifier can identify the third device; the device identifier of the third device being recorded in the user configuration information; and determining whether to perform user authentication on the first user according to whether the user configuration information records an authentication policy used for user authentication;

[0070] determining whether to perform user authentication on the first user according to whether the first UE and / or the first device supports user authentication;

[0071] wherein the first UE is a UE used by the first user; and the first device is a device associated with the first UE.

[0072] Based on the above scheme, various optional ways of determining whether to perform authentication on the first user are provided, and in the specific implementation process, the optional ways can be flexibly selected as needed.

[0073] In some embodiments of the first aspect, whether the user configuration information of the first user is activated determines whether to perform user authentication on the first user, including at least one of the following:

[0074] when the user configuration information of the first user is not activated, it is determined that the user authentication on the first user is not performed;

[0075] when the user configuration information of the first user is activated, it is determined that the user authentication on the first user is performed.

[0076] In some embodiments of the first aspect, whether the first subscription identifier matches the second subscription identifier recorded in the user configuration information determines whether to perform user authentication on the first user, including at least one of the following:

[0077] when the first subscription identifier matches the second subscription identifier, it is determined that the user authentication on the first user is performed;

[0078] when the first subscription identifier does not match the second subscription identifier, it is determined that the user authentication on the first user is not performed.

[0079] In some embodiments of the first aspect, determining whether to perform user authentication on the first user according to whether the first device identifier can identify the third device comprises at least one of: determining to perform user authentication on the first user according to that the first device identifier can identify the third device; determining not to perform user authentication on the first user according to that the first device identifier cannot identify the third device.

[0080] determining to perform user authentication on the first user according to that the user configuration information records the authentication policy for user authentication;

[0081] determining not to perform user authentication on the first user according to that the user configuration information does not record the authentication policy for user authentication.

[0082] In some embodiments of the first aspect, determining whether to perform user authentication on the first user according to whether the first UE and / or the first device supports user authentication comprises at least one of:

[0083] determining to perform user authentication on the first user according to that the first UE and / or the first device supports user authentication;

[0084] determining not to perform user authentication on the first user according to that the first UE and / or the first device does not support user authentication.

[0085] In some embodiments of the first aspect, the method further comprises at least one of:

[0086] determining whether the first UE and / or the first device supports user authentication according to first information sent by the first UE; the first information comprising capability information of the first UE and / or capability information of the first device;

[0087] determining whether the first UE and / or the first device supports user authentication according to second information in the user configuration information; the second information being used to indicate capability of the first UE and / or the first device;

[0088] determining whether the first UE and / or the first device supports user authentication according to the first information when the first information is acquired and the user configuration information records the second information.

[0089] In some embodiments of the first aspect, the method further comprises:

[0090] determining to perform user authentication on the first user, and determining the authentication manner for the first user.

[0091] Based on the above solution, the first network function also determines the authentication method, so that the first network function can simply control the third network function to authenticate the first user and / or the authentication method.

[0092] In some embodiments of the first aspect, determining to perform user authentication on a first user and determining an authentication method for the first user include:

[0093] Determine to perform user authentication on the first user, and determine an authentication method for the first user according to the user configuration information of the first user.

[0094] Based on the above solution, the user configuration information is used to determine whether to perform user authentication for the first user and also to determine the authentication method for performing user authentication on the first user. This is equivalent to one user configuration information being able to realize multiple functions and being easy to implement.

[0095] In some embodiments of the first aspect, the method further includes: receiving user configuration information sent by the second network function.

[0096] In some embodiments of the first aspect, the method further comprises:

[0097] A second request is sent to the second network function; the second request is used to request user configuration information of the first user.

[0098] In some embodiments of the first aspect, the second request includes:

[0099] The user identity information and / or first subscription identifier of the first user, where the first subscription identifier is used to identify the first UE; the first UE is a UE first device identifier used by the first user and is used to identify the first device.

[0100] In some embodiments of the first aspect, the second network function includes: a user profile information server.

[0101] In some embodiments of the first aspect, initiating a user authentication process for the first user includes at least one of the following:

[0102] Sending a first instruction to the first UE; the first instruction is used to instruct the first UE and the third network function to perform user authentication of the first user;

[0103] A second indication is sent to the third network function; the second indication is used to request user authentication for the first user.

[0104] In some embodiments of the first aspect, the first indication or the second indication includes: indication information of an authentication method used for user authentication.

[0105] In some embodiments of the first aspect, the first network function includes at least one of the following:

[0106] an access management function AMF;

[0107] a security anchor function SEAF;

[0108] a user management function UDM.

[0109] The second aspect provides a user authentication method, wherein the method is performed by a first UE, and the method comprises:

[0110] sending a first request to a first network function; the first request comprises at least user identity information of a first user of the first UE; and determining whether to perform user authentication on the first user after the first request is received by the first network function.

[0111] In some embodiments of the second aspect, the first request comprises at least one of:

[0112] a first subscription identifier, the first subscription identifier being used to identify the first UE;

[0113] a first device identifier, the first device identifier being used to identify a first device used by the first user;

[0114] capability information, the capability information being used by the first network function to determine whether the first UE and / or the first device supports user authentication;

[0115] the first UE is a UE used by the first user; and the first device is a device associated with the first UE.

[0116] In some embodiments of the second aspect, the first request is a registration request of the first UE and / or the first device.

[0117] In some embodiments of the second aspect, the method further comprises:

[0118] receiving a first response or a second response; the first response indicates that the first request is rejected; and the second response indicates that the first request is accepted.

[0119] In some embodiments of the second aspect, the first response comprises a failure cause.

[0120] In some embodiments of the second aspect, the failure cause indicates at least one of:

[0121] user authentication of the first user is not supported;

[0122] a reason why user authentication of the first user is not supported;

[0123] user authentication of the first user fails;

[0124] a reason why user authentication of the first user fails.

[0125] In some embodiments of the second aspect, the method further includes:

[0126] receiving a first indication sent by the first network function; the first indication is used to indicate that the first UE performs user authentication of the first user with the third network function.

[0127] In some embodiments of the second aspect, the first indication includes indication information of an authentication mode used by the user authentication.

[0128] The third aspect provides a user authentication method, wherein the method is performed by a second network function, and the method includes:

[0129] sending, to the first network function, user configuration information of the first user; the user configuration information is used by the first network function to determine whether to perform user authentication of the first user and / or an authentication mode of the user authentication.

[0130] In some embodiments of the third aspect, the method further includes:

[0131] receiving a second request sent by the first network function, the second request is used by the first network function to request the user configuration information of the first user.

[0132] In some embodiments of the third aspect, the second request includes at least one of:

[0133] a user identity of the first user and / or a first subscription identifier, the first subscription identifier is used to identify the first UE; the first UE is a UE device identifier of the first device used by the first user.

[0134] The fourth aspect provides a user authentication method, wherein the method is performed by a third network function, and the method includes:

[0135] receiving a second indication sent by the first network function; the second indication is used to request to perform user authentication of the first user;

[0136] performing user authentication of the first user according to the second indication.

[0137] In some embodiments of the third aspect, the second indication includes indication information of an authentication mode used by the user authentication.

[0138] The fifth aspect provides a first network function, which includes:

[0139] a processing module configured to determine whether to perform user authentication of the first user; and determine to perform user authentication of the first user, and initiate a user authentication process of the first user.

[0140] The sixth aspect provides a first user equipment (UE), which includes:

[0141] The sending module is configured to send a first request to the first network function; the request at least includes user identity information of a first user using the first UE; and the first request is used to determine whether to perform user authentication on the first user after the first request is received by the first network function.

[0142] The seventh aspect provides a second network function, and the second network function comprises:

[0143] The receiving module is configured to receive a first indication sent by the first network function; the first indication is used to indicate that the first UE performs user authentication of the first user with the third network function.

[0144] The eighth aspect provides a third network function, and the third network function comprises:

[0145] The receiving module is configured to receive a second indication sent by the first network function; the second indication is used to request to perform user authentication on the first user.

[0146] The processing module is configured to perform user authentication on the first user according to the second indication.

[0147] The ninth aspect provides a communication device, and the communication device comprises one or more processors.

[0148] The processor is used to invoke instructions to enable the communication device to perform the user authentication method described in the optional implementation manners of the first aspect to the fourth aspect.

[0149] The tenth aspect provides a storage medium, and the storage medium stores instructions, when the instructions are executed on the communication device, the instructions enable the communication device to perform the user authentication method described in the optional implementation manners of the first aspect to the fourth aspect.

[0150] The eleventh aspect provides a program product, and the program product comprises a computer program, when the computer program is executed on the communication device, the computer program enables the communication device to perform the user authentication method described in the optional implementation manners of the first aspect to the fourth aspect.

[0151] The twelfth aspect provides a computer program, when the computer program is executed on the computer, the computer program enables the computer to perform the user authentication method described in the optional implementation manners of the first aspect to the fifth aspect.

[0152] It can be understood that the terminal, the network device, the communication system, the program product, and the computer program are all used to execute the method provided in the embodiments of the present disclosure. Therefore, the beneficial effects that can be achieved by the terminal, the network device, the communication system, the program product, and the computer program can refer to the beneficial effects in the corresponding method, and will not be described here again.

[0153] The embodiments of the present disclosure provide a user authentication method, a communication device, a communication system and a storage medium. The embodiments of the present disclosure are not exhaustive, but only illustrate some embodiments, and are not specific limitations on the protection scope of the present disclosure. In the case of no contradiction, each step in an embodiment can be implemented as an independent embodiment, and the steps can be combined arbitrarily, for example, the mode after removing some steps in an embodiment can also be implemented as an independent embodiment, and the order of the steps in an embodiment can be exchanged arbitrarily, in addition, the optional implementation mode in an embodiment can be combined arbitrarily; in addition, the embodiments can be combined arbitrarily, for example, the steps of different embodiments can be combined arbitrarily, an embodiment can be combined with the optional implementation mode of other embodiments.

[0154] In the embodiments of the present disclosure, the terms and / or descriptions between the embodiments are consistent and can be referred to each other if there is no special description and logical conflict, and the technical features in different embodiments can be combined to form new embodiments according to their inherent logical relationship.

[0155] The terms used in the embodiments of the present disclosure are only for the purpose of describing the specific embodiments, and not as a limitation on the present disclosure.

[0156] In the embodiments of the present disclosure, unless otherwise specified, the elements expressed in singular form, such as "one", "a", "the", "above", "preceding", "this", etc., can represent "one and only one", or "one or more", "at least one", etc. For example, in the case of using articles such as "a", "an", "the" in English, the noun after the article can be understood as singular expression, or as plural expression.

[0157] In the embodiments of the present disclosure, "a plurality of" means two or more.

[0158] In some embodiments, the terms "at least one of", "one or more", "a plurality of", "multiple", and the like can be replaced with each other.

[0159] In some embodiments, the description of "at least one of A, B", "A and / or B", "A or B in one case, A or B in another case", "one of A or B", and the like, can include the following technical manners according to the case: in some embodiments, A is executed (A is executed regardless of B); in some embodiments, B is executed (B is executed regardless of A); in some embodiments, A and B are selectively executed (A and B are selectively executed); in some embodiments, A and B are executed (A and B are executed). When there are more branches such as A, B, C, and the like, the above description is similar.

[0160] In some embodiments, the description of "A or B", and the like, can include the following technical manners according to the case: in some embodiments, A is executed (A is executed regardless of B); in some embodiments, B is executed (B is executed regardless of A); in some embodiments, A and B are selectively executed (A and B are selectively executed). When there are more branches such as A, B, C, and the like, the above description is similar.

[0161] The prefix words "first", "second", and the like in the embodiments of the present disclosure are only used to distinguish different description objects, and do not constitute a limitation on the position, order, priority, quantity, or content of the description objects. The description of the description objects should refer to the description in the context of the claims or embodiments, and should not constitute an additional limitation because of the use of the prefix words. For example, the description objects are "fields", and the ordinal words before "fields" in "first field" and "second field" do not limit the position or order between "fields". "First" and "second" do not limit whether the "fields" modified thereby are in the same message, nor do they limit the order of "first field" and "second field". For another example, the description objects are "levels", and the ordinal words before "levels" in "first level" and "second level" do not limit the priority between "levels". For another example, the quantity of the description objects is not limited by the ordinal words, and can be one or more. For example, "first device", wherein the quantity of "devices" can be one or more. In addition, the objects modified by different prefix words can be the same or different, for example, the description objects are "devices", and "first device" and "second device" can be the same device or different devices, and the types thereof can be the same or different. For another example, the description objects are "information", and "first type of information" and "second type of information" can be the same information or different information, and the content thereof can be the same or different.

[0162] In some embodiments, "including A", "containing A", "for indicating A", "carrying A", can be interpreted as directly carrying A, or indirectly indicating A.

[0163] In some embodiments, the terms "…", "determining …", "in the case of …", "when …", "if …", and the like can be replaced with each other.

[0164] In some embodiments, the terms “greater than”, “greater than or equal to”, “not less than”, “more than”, “more than or equal to”, “not less than”, “higher than”, “higher than or equal to”, “not lower than”, “above”, and the like can be replaced with each other, and the terms “less than”, “less than or equal to”, “not greater than”, “fewer than”, “fewer than or equal to”, “not more than”, “lower than”, “lower than or equal to”, “not higher than”, “below”, and the like can be replaced with each other.

[0165] In some embodiments, an apparatus and the like can be interpreted as an entity, and can also be interpreted as virtual, and the name thereof is not limited to the name described in the embodiments. The terms “apparatus”, “equipment”, “device”, “circuitry”, “network element”, “node”, “function”, “unit”, “section”, “system”, “network”, “chip”, “chip system”, “entity”, “subject”, and the like can be replaced with each other.

[0166] In some embodiments, “network” can be interpreted as an apparatus (for example, an access network device, a core network device, and the like) included in the network.

[0167] In some embodiments, the terms “access network device (AN device)”, “radio access network device (RAN device)”, “base station (BS)”, “radio base station”, “fixed station”, “node”, “access point”, “transmission point (TP)”, “reception point (RP)”, “transmission / reception point (TRP)”, “panel”, “antenna panel”, “antenna array”, “cell”, “macro cell”, “small cell”, “femto cell”, “pico cell”, “sector”, “cell group”, “serving cell”, “carrier”, “component carrier”, “bandwidth part (BWP)”, and the like can be replaced with each other.

[0168] In some embodiments, the terms "terminal", "terminal device", "user equipment (UE)", "user terminal", "mobile station (MS)", "mobile terminal (MT)", "subscriber station", "mobile unit", "subscriber unit", "wireless unit", "remote unit", "mobile device", "wireless device", "wireless communication device", "remote device", "mobile subscriber station", "access terminal", "mobile terminal", "wireless terminal", "remote terminal", "handset", "user agent", "mobile client", "client", and so on can be replaced with each other.

[0169] In some embodiments, the access network device, the core network device, or the network device can be replaced with a terminal. For example, the embodiments of the present disclosure can also be applied to a structure in which communication between the access network device, the core network device, or the network device and the terminal is replaced with communication between a plurality of terminals (e.g., device-to-device (D2D), vehicle-to-everything (V2X), or the like). In this case, the terminal can also be configured to have all or part of the functions of the access network device. In addition, the terms "uplink", "downlink", and the like can also be replaced with terms corresponding to the inter-terminal communication (e.g., "side"). For example, the uplink channel, the downlink channel, and the like can be replaced with the side channel, and the uplink, the downlink, and the like can be replaced with the sidelink.

[0170] In some embodiments, the terminal can be replaced with the access network device, the core network device, or the network device. In this case, the access network device, the core network device, or the network device can also be configured to have all or part of the functions of the terminal.

[0171] In some embodiments, the data, information, etc. can be obtained in compliance with the laws and regulations of the country in which the location is situated.

[0172] In some embodiments, the data, information, etc. can be obtained after obtaining the consent of the user.

[0173] In addition, each element, each row, or each column in the table of the embodiments of the present disclosure can be implemented as an independent embodiment, and any combination of any element, any row, or any column can also be implemented as an independent embodiment.

[0174] FIG. 1 is an architecture schematic diagram of a communication system according to an embodiment of the present disclosure.

[0175] As shown in FIG. 1, the communication system 100 includes a terminal 101 and a network device 102. The network device 102 can include an access network device and / or a core network device.

[0176] In some embodiments, the terminal 101 includes at least one of a mobile phone, a wearable device, an Internet of Things device, a communication-capable automobile, a smart automobile, a Pad, a computer with wireless transceiver function, a virtual reality (VR) terminal device, an augmented reality (AR) terminal device, a wireless terminal device in industrial control, a wireless terminal device in self-driving, a wireless terminal device in remote medical surgery, a wireless terminal device in smart grid, a wireless terminal device in transportation safety, a wireless terminal device in smart city, a wireless terminal device in smart home, etc., but is not limited thereto.

[0177] In some embodiments, the terminal is also referred to as a user equipment (UE).

[0178] In some embodiments, the access network device may, for example, be at least one of a node or a device that accesses a terminal to a wireless network, and the access network device may, for example, include at least one of an evolved node B (eNB) in a 5G communication system, a next generation eNB (ng-eNB), a next generation node B (gNB), a node B (NB), a home node B (HNB), a home evolved node B (HeNB), a wireless backhaul device, a radio network controller (RNC), a base station controller (BSC), a base transceiver station (BTS), a base band unit (BBU), a mobile switching center, a base station in a 6G communication system, an open base station (Open RAN), a cloud base station (Cloud RAN), a base station in other communication systems, an access node in a Wi-Fi system, but is not limited thereto.

[0179] In some embodiments, the technical means of the present disclosure can be applicable to an Open RAN architecture, at which time the interfaces between or within the access network devices involved in the embodiments of the present disclosure can become internal interfaces of the Open RAN, and the processes and information interactions between these internal interfaces can be implemented through software or programs.

[0180] In some embodiments, the access network device can be composed of a central unit (CU) and a distributed unit (DU), where the CU can also be referred to as a control unit. The CU-DU structure can split the protocol layers of the access network device, and some of the protocol layers can be controlled by the CU, and the rest or all of the protocol layers can be distributed in the DU and controlled by the CU, but is not limited thereto.

[0181] In some embodiments, the core network device can be one device including the first network element, etc., or can be multiple devices or device groups, each including the first network element. The network element can be virtual or physical. The core network may, for example, include at least one of an evolved packet core (EPC), a 5G core network (5GCN), and a next generation core (NGC).

[0182] It can be understood that the communication system described in the embodiments of the present disclosure is for more clearly illustrating the technical means of the embodiments of the present disclosure, and does not constitute a limitation on the technical means provided by the embodiments of the present disclosure. It can be known by those skilled in the art that, as the system architecture evolves and new service scenarios appear, the technical means provided by the embodiments of the present disclosure are also applicable to similar technical problems.

[0183] The following embodiments of the present disclosure can be applied to the communication system 100 shown in FIG. 1 or part of the subject, but are not limited thereto. The subjects shown in FIG. 1 are illustrative, and the communication system can include all or part of the subjects in FIG. 1, or other subjects other than FIG. 1. The number and form of each subject is arbitrary, and the connection relationship between the subjects is illustrative. The subjects can be connected or not connected, and the connection can be in any way, can be direct connection or indirect connection, can be wired connection or wireless connection.

[0184] Embodiments of the present disclosure can be applied to Long Term Evolution (LTE), LTE-Advanced (LTE-A), LTE-Beyond (LTE-B), SUPER 3G, IMT-Advanced, 4th generation mobile communication system (4G), 5th generation mobile communication system (5G), 5G new radio (NR), Future Radio Access (FRA), New-Radio Access Technology (RAT), New Radio (NR), New radio access (NX), Future generation radio access (FX), Global System for Mobile communications (GSM (registered trademark)), CDMA2000, Ultra Mobile Broadband (UMB), IEEE 802.11 (Wi-Fi (registered trademark)), IEEE 802.16 (WiMAX (registered trademark)), IEEE 802.20, Ultra-WideBand (UWB), Bluetooth (Bluetooth (registered trademark)), Public Land Mobile Network (PLMN) network, Device-to-Device (D2D) system, Machine to Machine (M2M) system, Internet of Things (IoT) system, Vehicle-to-Everything (V2X), system using other resources, next-generation system extended based thereon, and the like. In addition, a plurality of systems can be combined (for example, combination of LTE and NR).

[0185] As shown in FIG. 2, the present embodiment provides a user authentication method, which is performed by the communication system as shown in FIG. 1. The method can include, but is not limited to, at least one of the following:

[0186] S2101: The first UE sends a first request to the first network function.

[0187] In some embodiments, the first UE can be any UE accessing to a mobile network.

[0188] In some embodiments, the first network function can be various types of core network functions.

[0189] In some embodiments, the first request can be used to request or trigger user authentication of the first user.

[0190] In some embodiments, the first request comprises at least user identity information of the first user.

[0191] In some embodiments, the user identity information can comprise, but not limited to, a user identifier. The user identifier can comprise, but not limited to, a user level identifier, a government department assigned user identity information, and / or a device identifier of a non-subscribed device, etc. The non-subscribed device is a device that has not subscribed a contract with the communication operator shown in FIG. 1.

[0192] In some embodiments, the first request comprises at least one of:

[0193] a first subscription identifier, the first subscription identifier being used to identify the first UE;

[0194] a first device identifier, the first device identifier being used to identify a first device used by the first user; capability information; the UE capability information being used to indicate whether the first UE and / or the first device supports user authentication to the first network function;

[0195] the first UE is a UE used by the first user; the first device is a device associated with the first UE.

[0196] In some embodiments, the first subscription identifier can be an identifier assigned by the communication operator when the first UE or the first device subscribes to the communication operator, or an identifier derived from the identifier assigned by the communication operator. In some embodiments, the first subscription identifier can comprise, but not limited to, a Subscription Concealed Identifier (SUCI) or a Subscription Permanent Identifier (SUPI).

[0197] In some embodiments, the capability information can be at least a capability possessed by the first UE and / or the first device. In some embodiments, the capability information can be at least a subscribed capability of the first UE and / or the first device.

[0198] In some embodiments, the capability information can indicate whether the first UE and / or the first device supports user authentication.

[0199] In some embodiments, the association relationship between the first UE and the first device can be embodied in at least one of:

[0200] The first UE can be a gateway UE of the first device; for example, the first UE can be a home gateway UE of the first device, or the first UE can be a hotspot device of the first device.

[0201] The first UE and the first device can be bound, for example, a smart watch and / or a mobile phone of the same user are bound.

[0202] In some embodiments, the first user can be a user currently using the first device or using the first UE, in which case the first user can be the device or the user using the first device, and in this case the first user is equivalent to a user currently indirectly using the first UE.

[0203] In some embodiments, the first user can be a user currently directly using the first UE. For example, the first UE is a shared device, and the first UE can be used by multiple users (persons), and in this case the first user corresponds to a person.

[0204] In some embodiments, the first device can be a non-subscribed device or a non-3GPP device.

[0205] In some embodiments, the first UE can send the first request to the first network function through a non-access layer message, or can send the first request to the first network function based on a manner of invoking a standardized service.

[0206] In some embodiments, the first network function can include but is not limited to a core network function. In some embodiments, the core network function includes but is not limited to an access management function, a mobility management entity, a security anchor function (SEAF), and / or user data management.

[0207] S2102: The first network function determines whether and / or how to perform user authentication of the first user.

[0208] In some embodiments, whether and / or how to perform user authentication of the first user is determined according to user configuration information and / or local information.

[0209] In some embodiments, the user configuration information can include but is not limited to at least one of the following:

[0210] User identity information of the first user;

[0211] A first subscription identifier, the first subscription identifier being used to identify the first UE;

[0212] State information indicating whether the configuration information is activated;

[0213] A second subscription identifier;

[0214] information of the third device;

[0215] authentication policy indicating an optional authentication manner for identity authentication of the first user;

[0216] second information indicating whether the first UE and / or the first device supports user authentication;

[0217] user authentication condition indicating a condition for identity authentication of the first user;

[0218] first device identifier for identifying the first device.

[0219] The above is of course only an example of the user configuration information.

[0220] In some embodiments, if the SUCI of the first UE and / or the first device is carried in the first request, the first network function can convert the SUCI into the SUPI.

[0221] In some embodiments, the local information can include, but is not limited to, a local configuration policy and / or a network planning parameter of the first network function and / or a historical authentication record of the first user cached by the first network function. In some embodiments, the local configuration policy can be a rule and / or a policy configured by an operation management and maintenance server of a communication operator on the first network function. The network planning parameter can be a parameter configured by the network when deployed.

[0222] In some embodiments, if the user configuration information is used to determine whether and / or how to perform user authentication of the first user, the method can include:

[0223] The second network function sends the user configuration information.

[0224] In some embodiments, the second network function actively pushes the updated user configuration information to the third network function when detecting that the user configuration information of at least one user is updated.

[0225] In some embodiments, the first network function sends a second request to the second network function and receives the user configuration information sent by the second network function based on the second request.

[0226] In some embodiments, the second request is used for the first network function to request the user configuration of the first user.

[0227] In some embodiments, if the first network function locally stores the user configuration information of the first user, the first network function also does not need to temporarily request the user configuration information from the second network function.

[0228] In some embodiments, the second request can include, but is not limited to, at least one of the following:

[0229] user identity information of the first user;

[0230] the first subscription identifier.

[0231] In some embodiments, there are multiple optional ways to determine whether to perform user authentication on the first user according to the user configuration information, which can specifically include but are not limited to any one of the following:

[0232] Way 1:

[0233] whether the user configuration information of the first user is activated, to determine whether to perform user authentication on the first user.

[0234] In some embodiments, when the user configuration information of the first user is not activated, it is determined not to perform user authentication on the first user; and / or, when the user configuration information of the first user is activated, it is determined to perform user authentication on the first user.

[0235] For example, the user configuration information is configured with a state and is at least the state of the user configuration information by the state information, so that the second network device can provide the user configuration information of any state to the first network device and the user configuration information includes the state information, so that the first network device will receive the user configuration information and the state information from the second network device, and determine whether the corresponding user configuration information is activated according to the state information.

[0236] For another example, the user configuration information is configured with a state and is at least its state by the state information, so that the second network device can only provide the user configuration information of the activated state to the first network function. If a certain user configuration information is not activated, the first network function cannot receive the corresponding user configuration information from the second network function, at this time the first network function can determine whether the corresponding user configuration information is activated according to whether the corresponding user configuration information is successfully received.

[0237] It is worth noting that: in some cases, the first network function can also determine whether to perform user authentication on the first user according to whether the first user has user configuration information. For example, the first network function fails to obtain the user configuration information of the first user or the user configuration information is incorrect, then it can be considered that the corresponding user is not authenticated. For another example, the first network function successfully obtains the user configuration information of the first user, then performs user authentication on the first user according to the obtained user configuration information. In this way, it can reduce the illegal use of the first UE by illegal users who do not submit user information and / or submit incorrect user information, and improve the use security of the first UE.

[0238] Way 2:

[0239] whether the first subscription identifier can identify the second device, to determine whether to perform user authentication on the first user.

[0240] In some embodiments, the first subscription identity identifies a first UE used by the first user.

[0241] In some embodiments, the first subscription identity can include, but is not limited to, SUCI and / or SUPI. The second subscription identity can include, but is not limited to, SUPI.

[0242] In some embodiments, a second subscription identity of the second device or a second device identity is recorded in the user configuration information;

[0243] In some embodiments, the second subscription identity is a subscription identity of the second device that the first user has subscribed to use, and / or the second subscription identity is a subscription identity of the second device corresponding to the first user and has passed network access verification.

[0244] Exemplarily, whether to perform user authentication on the first user is determined according to whether the first subscription identity matches the second subscription identity recorded in the user configuration information. In this way, the UE or device identified by the second subscription identity can be a device that the first user has subscribed to use in advance. The second subscription identity can also be an identity of a UE and / or device that the network actively collects according to the historical use and / or historical user authentication of the mobile network by the first user.

[0245] In some embodiments, when the first subscription identity matches the second subscription identity, it is determined to perform user authentication on the first user; and / or when the first subscription identity does not match the second subscription identity, it is determined not to perform user authentication on the first user.

[0246] In some embodiments, the first subscription identity can include, but is not limited to, SUCI and / or SUPI. The second subscription identity can include, but is not limited to, SUPI.

[0247] Method 3:

[0248] Whether to perform user authentication on the first user is determined according to whether the first device identity can identify the third device.

[0249] In some embodiments, a device identity of the third device is recorded in the user configuration information.

[0250] In some embodiments, the third device can be a device allowed to be used by the first user.

[0251] In some embodiments, the third device can be a device determined to be allowed to be used by the first user according to subscription information and / or device use policy.

[0252] In some embodiments, the third device can be one or more. In some embodiments, the third device can also be a set of devices. The device identities in the set of devices can be consecutively arranged, and the user configuration information can record two specific device identities in the set of devices, e.g., the minimum device identity and / or the maximum device identity. In this way, the third device identity can be the minimum device identity, the maximum device identity, or any one identity between the minimum device identity and the maximum device identity. For example, in an office scenario, a company or a group can sign a contract with a communication operator for multiple office UEs, which have consecutively numbered device identities. Employees can use their employee numbers as user identity information to use these office devices. In this way, authentication of the employee number of an employee is one of the user authentication in the embodiments of the present disclosure.

[0253] In this scenario, if the number of third devices that the first user can use is zero, it can be considered that it is determined not to perform user authentication on the first user. If the number of third devices that the first user can use is greater than zero, it is determined whether and / or how to perform user authentication on the first user according to whether the first device identity matches the third device identity.

[0254] In some embodiments, determining whether to perform user authentication on the first user according to whether the first device identity can identify the third device includes at least one of the following: determining to perform user authentication on the first user according to that the first device identity can identify the third device; determining not to perform user authentication on the first user according to that the first device identity cannot identify the third device.

[0255] Method 4:

[0256] Determining whether to perform user authentication on the first user according to whether the user configuration information records an authentication policy for user authentication.

[0257] In some embodiments, the authentication policy can be configured by a core network function, an operation management and maintenance server, and / or a service server.

[0258] In some embodiments, the authentication policy can be used by the first network function to determine whether to perform user authentication on the first user, and / or the authentication manner for authenticating the first user.

[0259] In some embodiments, it is determined to perform user authentication on the first user according to that the user configuration information records an authentication policy for user authentication; and / or, it is determined not to perform user authentication on the first user according to that the user configuration information does not record an authentication policy for user authentication.

[0260] In some embodiments, it is determined to perform user authentication on the first user according to that the authentication policy indicates to perform user authentication on the first user; and / or, it is determined not to perform user authentication on the first user according to that the authentication policy indicates not to perform user authentication on the first user.

[0261] Method 5:

[0262] According to whether the first UE and / or the first device support user authentication, it is determined whether to perform user authentication on the first user.

[0263] In some embodiments, the first UE and / or the first device support user authentication, and it is determined to perform user authentication on the first user; and / or, the first UE and the first device do not support user authentication, and it is determined not to perform user authentication on the first user.

[0264] In some embodiments, according to the first information sent by the first UE, it is determined whether the first UE and / or the first device support user authentication; the first information includes capability information of the first UE and / or capability information of the first device.

[0265] For example, in the case of receiving the first information, the second information of the user profile record is ignored, and it is directly determined according to the first information whether the first UE and / or the first device support user authentication.

[0266] In some embodiments, in the case of not receiving the first information, according to the second information of the user configuration information, it is determined whether the first UE and / or the first device support user authentication; the second information is used to indicate the capability of the first UE and / or the first device.

[0267] In some embodiments, regardless of whether the first information is received, it is directly determined according to the second information in the user configuration information whether the first UE and / or the first device support user authentication.

[0268] In some embodiments, in the case of obtaining the first information and the user configuration information recording the second information, it is determined according to the first information whether the first UE and / or the first device support user authentication. Here, the first information can be the first information sent by the first UE and / or the first device according to the local device setting, or can be dynamically generated according to the user interface detection of the user operation. In one case of the embodiments of the present disclosure, the priority of the first information is higher than that of the second information. In other embodiments, in the case of obtaining the first information and the user configuration information recording the second information, in the case that the first information and the second information both indicate that at least one of the first UE and the first device supports user authentication, it is determined that the first UE and / or the first device support user authentication, otherwise it is determined that the first UE and the first device do not support user authentication. In some embodiments, in the case that the second information of the user configuration information indicates that at least one of the first UE and the first device supports user authentication, it is finally determined according to the first information whether the first UE and / or the first device support user authentication.

[0269] In some embodiments, the first information can be information temporarily obtained by the first network function from the first UE after receiving the first request, or can be information carried in the first request.

[0270] The above is merely an example of whether the first network function performs user authentication on the first user, and the implementation is not limited to the above example.

[0271] There are various ways to determine the authentication mode of the first user after determining that the first user is authenticated, and the implementation is not limited to any of the above.

[0272] For example, determining that the first user is authenticated and determining the authentication mode of the first user can include, but is not limited to, at least one of the following:

[0273] According to the user configuration information, the authentication mode of the first user is determined;

[0274] According to the local information of the first network function, the authentication mode of the first user is determined.

[0275] In some embodiments, the authentication mode can be any of the extended authentication protocol (EAP) authentication. For example, the alternative authentication mode of user authentication can include, but is not limited to: Extented Authentication Protocol-Message Digest Algorithm 5 (EAP-MD5), Extented Authentication Protocol-Pre-shared key (EAP-PSK), Extented Authentication Protocol-Transport Layer Security (EAP-TLS), Extented Authentication Protocol-Lightweight Extensible Authentication (EAP-LEAP), Extented Authentication Protocol-Protected Extensible Authentication (EAP-PEAP). The above is merely an example of EAP authentication, and the implementation is not limited to any of the above examples.

[0276] Exemplarily, the authentication manner of the user authentication can also be distinguished according to whether the authentication device needs to request third-party authentication. For example, when third-party authentication is needed, the third network function needs to interact with the server of the third-party authentication to obtain the user authentication result. If the third party does not need to participate in the authentication, the third network function can complete the user authentication of the first user by itself. Exemplarily, the server of the third-party authentication can include but is not limited to an Authentication Authorization Accounting (AAA) server.

[0277] In some embodiments, the third network function can be various core network functions capable of identity authentication. Exemplarily, the core network function can include but is not limited to an Authentication Server Function (AUSF), a UDM, a User Authentication and Authorization Function (UAAF), and / or a User Information Management Function (UIMF).

[0278] In some embodiments, it is determined to perform user authentication on the first user, and the authentication manner of the first user is determined according to the user configuration information of the first user.

[0279] In some embodiments, it is determined not to perform user authentication on the first user, and there is no need to determine the authentication manner of the user authentication on the first user.

[0280] In some embodiments, the first user is authenticated by default. In this case, it can be directly determined whether the first user needs to be authenticated, and the authentication manner of the user authentication is directly determined.

[0281] In some embodiments, the above-mentioned manners 1 to 5 can be used alone or in combination.

[0282] Exemplarily, when each of the determination results obtained according to the manners 1 to 5 determines to perform user authentication on the first user, it is determined to perform user authentication on the first user. Otherwise, when any one of the manners 1 to 5 determines not to perform user authentication, it is determined not to perform user authentication on the first user.

[0283] Exemplarily, when each of the determination results of the manner 1 and the manner 5 determines to perform the user authentication on the first user, and when any one of the determination results of the manner 2 to the manner 4 indicates that the user authentication on the first user is needed, it is determined to perform the user authentication on the first user. And / or, when each of the determination results of the manner 1 and the manner 5 determines to perform the user authentication on the first user, and when none of the determination results of the manner 2 to the manner 4 indicates that the user authentication on the first user is needed, it is determined not to perform the user authentication on the first user.

[0284] In some embodiments, according to the user configuration information, it is determined how to perform the user authentication on the first user.

[0285] S2103: The first network function sends the first indication to the first UE.

[0286] In some embodiments, the first indication is used to instruct the first UE to perform the user authentication on the first user with the third network function.

[0287] In some embodiments, the first indication can include: indication information of an authentication manner used by the user authentication, and / or, authentication information.

[0288] The authentication manner indicated by the indication information can be the authentication manner determined in the foregoing S2102.

[0289] If the first indication does not include the indication information, the first UE can select any authentication manner supported by the first UE, and carry an indicator of the authentication manner selected by the first UE in an authentication request sent to the third network function when performing the user authentication with the third network function. Or, if the first indication does not include the indication information, the first UE selects a default authentication manner agreed by the protocol or the like, and the third network function is also aware of the default authentication manner.

[0290] The authentication information can be used by the first UE and the third network function in the user authentication.

[0291] In some embodiments, the authentication information can be protected by a local credential (for example, a first credential) used by the first UE in the user authentication. For example, the authentication information is integrity protected, confidentiality protected, scrambled, and the like by using the first credential. After the authentication information protected by the first credential is transmitted to the third network function, the third network function can verify the authentication information by using a second credential stored in the network. If the verification is successful, it is considered that the user authentication on the first user is passed, otherwise, it is considered that the user authentication on the first user is failed.

[0292] The first credential can be a key and / or a digital certificate of the first user when the first user subscribes. It is worth noting that the first user can be any user or device that does not distribute a subscription key when subscribing.

[0293] In some embodiments, the authentication information can be a random number randomly generated by the first network function or a specific authentication symbol.

[0294] S2104: The first network function sends a second indication to the third network function.

[0295] In some embodiments, the third network function can be various core network functions. Illustratively, the third network function can be various authentication functions capable of identity authentication. Illustratively, the third network function can include, but is not limited to, AUSF, UDM, UIMF, and / or UAAF, etc.

[0296] In some embodiments, the second indication is used to request user authentication for the first user.

[0297] In some embodiments, the second indication can include at least one of the following:

[0298] indication information of an authentication method used by the user authentication;

[0299] authentication information.

[0300] It is worth noting that the first network function can perform either S2103 or S2104. For example, the first network function sends the first indication to the first UE, and then the first UE initiates information interaction with the third network function to perform user authentication after receiving the first indication. At this time, S2104 is an optional step. For example, the first network function sends the second indication to the third network function, and then the third network function initiates information interaction with the first UE to perform user authentication after receiving the second indication. At this time, S2103 is an optional step.

[0301] In some embodiments, both S2103 and S2104 need to be performed, and after the third network function and the first network function each receive the first indication and the second indication, it can be determined whether the user authentication for the first user is needed according to the first indication and / or the second indication, reducing the fake authentication caused by the interception of the first indication and / or the second indication, and again improving the security of user authentication.

[0302] S2105: The third network function sends a user authentication result of the first user to the first network function.

[0303] In some embodiments, the user authentication result can at least indicate whether the first user passes the user authentication.

[0304] S2106: The first network function sends a response to the first request to the first UE.

[0305] In some embodiments, the third network function sends a success response or a failure response to the first network function.

[0306] In some embodiments, the response is sent to the first UE according to a user authentication result received from the third network function, and / or the response is sent to the first UE according to a determination of whether the first user is authenticated.

[0307] In some embodiments, the successful response is sent to the first network function according to a user authentication result received from the third network function that the user authentication is passed.

[0308] In some embodiments, the failure response is sent to the first network function according to a user authentication result received from the third network function that the user authentication is failed. Further exemplarily, the failure response can comprise a failure cause.

[0309] In some embodiments, the first request can be any request for authenticating the first user. For example, the request can be any one request after the first UE registers to the network. For example, the first request can also be an update request when the first UE performs tracking area update and / or radio notification area update. For another example, the first request can be a user authentication request specially for authenticating the first user.

[0310] In some embodiments, the first request can be a registration request of the first UE. The registration request can be used for the first UE to request to register to the network.

[0311] In some embodiments, the first response is sent to the first UE according to a determination that the first user is not authenticated and / or the user authentication of the first user is failed; the first response indicates that the first request is rejected.

[0312] In some embodiments, the second response is sent to the first UE according to a determination that the user authentication of the first user is passed and the onboarding authentication of the first UE is passed; the second response indicates that the first request is accepted.

[0313] In some embodiments, the first response comprises a failure cause.

[0314] In some embodiments, any one of the foregoing failure causes can comprise at least one of:

[0315] The user authentication of the first user is not supported;

[0316] A reason that the user authentication of the first user is not supported;

[0317] The user authentication of the first user is failed;

[0318] A reason that the user authentication of the first user is failed.

[0319] In some embodiments, S2101 is an optional step. The first network function can actively perform user authentication on a possible user of the first UE (e.g., the possible user can include the first user) according to the updated user configuration information provided by the second network function. In this case, S2101 is an optional step.

[0320] As shown in FIG. 3, the embodiments of the present disclosure provide a user authentication method, which is performed by a first network function. The method can include:

[0321] S3101: receiving a first request.

[0322] In some embodiments, the first request is sent by a first UE.

[0323] In some embodiments, the related description of the first request can refer to FIG. 2. For example, the first request can include at least user identity information of the first user. Of course, the identity information of the first user can not be limited to the user identity information of the first user.

[0324] S3102: determining whether and / or how to perform user authentication on the first user.

[0325] In some embodiments, whether and / or how to perform user authentication on the first user is determined according to the user configuration information and / or the local information.

[0326] In some embodiments, the optional manner of S3102 can refer to S2102 of FIG. 2, which will not be repeated here.

[0327] S3103: sending a first indication and / or a second indication.

[0328] In some embodiments, the first indication is sent to the first UE and / or the second indication is sent to a third network function.

[0329] In some embodiments, the optional manner of S3102 can refer to S2103 and / or S2104 of FIG. 2, which will not be repeated here.

[0330] S3104: receiving a user authentication result of the first user.

[0331] In some embodiments, the first network function receives the user authentication result from the third network function.

[0332] In some embodiments, the user authentication result can be used to indicate that the first user passes or fails the user authentication.

[0333] S3105: sending a response to the first request.

[0334] In some embodiments, the response to the first request can correspond to S2106 of the embodiments of FIG. 2, which will not be repeated here.

[0335] As shown in FIG. 4, the embodiments of the present disclosure provide a user authentication method, which is performed by a first UE, and can include:

[0336] S4101: sending a first request.

[0337] In some embodiments, the first request can be used to request or trigger user authentication of a first user.

[0338] In some embodiments, the first request can be a registration request for the first UE to request network access.

[0339] In some embodiments, the first request includes at least user identity information of the first user.

[0340] In some embodiments, the first request includes at least one of the following:

[0341] a first subscription identifier, the first subscription identifier being used to identify the first UE;

[0342] a first device identifier, the first device identifier being used to identify a first device used by the first user;

[0343] capability information, the capability information being used for a first network function to determine whether the first UE and / or the first device supports user authentication;

[0344] the first UE is a UE used by the first user, and the first device is a device associated with the first UE.

[0345] In some embodiments, the first request can further include first information, which can be an indication dynamically determined by the first UE that whether the first UE and / or the first device currently supports user authentication.

[0346] For example, the description of the first request can correspond to the embodiments of FIG. 2.

[0347] S4102: receiving a first indication.

[0348] In some embodiments, the first indication is received from a first network function.

[0349] In some embodiments, the first indication is used to indicate that the first UE performs user authentication of the first user with a third network function.

[0350] In some embodiments, the first indication further includes at least one of the following:

[0351] authentication information of the first user for user authentication;

[0352] indication information of an authentication manner used by the user authentication.

[0353] It is worth noting that the step of receiving the first indication by the first UE can be an optional step. For example, the first request triggers the user authentication of the first user at the network side, and the user authentication process of the first user can complete the interaction between multiple network functions of the network, and the first UE no longer needs to participate again. At this time, the first UE can not receive the first indication.

[0354] S4103: sending a third request.

[0355] In some embodiments, the third request is sent according to the first indication. In some embodiments, the third request is sent to the third network function according to the first indication.

[0356] In some embodiments, the third request is used to request the third network to perform the user authentication of the first user.

[0357] In some embodiments, the third request can include but is not limited to the aforementioned authentication information and / or indication information.

[0358] In some embodiments, the third request can include authentication information protected by a first credential. The first credential can be a credential locally stored by the first UE. For example, the first credential can be a first credential determined when the third network function, the service server, or the first UE and / or the first user is subscribed.

[0359] In some embodiments, the first credential can include but is not limited to a pre-configured key and / or a number of digital frames. Protecting the authentication information using the first credential can include performing integrity protection, confidentiality protection, and / or scrambling protection on the authentication information based on the first credential or a key derived based on the first credential.

[0360] It is worth noting that the step of sending the third request by the first UE can be an optional step. For example, the first request triggers the user authentication of the first user at the network side, and the user authentication process of the first user can complete the interaction between multiple network functions of the network, and the first UE no longer needs to participate again. For example, in some embodiments, performing the user authentication based on the first credential is only one way to perform the user authentication of the first user, and in actual implementation, the user authentication can be performed based on the user configuration information of the first user by the first network function and / or the third network function without being related to the first credential.

[0361] S4104: receiving a response to the first request.

[0362] In some embodiments, a success response or a failure response sent by the first network function is received. Exemplarily, the success response and / or the failure response can refer to the corresponding embodiments of FIG. 2. Exemplarily, the success response can include the second response described above. The failure response can include the first response.

[0363] In some embodiments, the first response can include a failure cause.

[0364] In some embodiments, the failure cause indicates at least one of:

[0365] User authentication of the first user is not supported;

[0366] A reason why the user authentication of the first user is not supported;

[0367] User authentication of the first user fails;

[0368] A reason why the user authentication of the first user fails.

[0369] In some embodiments, S4101 and S4104 can constitute embodiments, and other steps are optional steps. S4101, S4102 and S4104 constitute embodiments, that is, the first indication is information that notifies the first UE to some extent that the user authentication of the first user is being or will be performed on the network side.

[0370] As shown in FIG. 5, the embodiments of the present disclosure provide a user authentication method, which is performed by a second network function, and the method can include:

[0371] S5101: receiving a second request.

[0372] In some embodiments, the second request sent by the first network function is received.

[0373] In some embodiments, the second request sent by the first network function is received, and the second request is used for the first network function to request user configuration information of the first user.

[0374] In some embodiments, the second request is sent by the first network function based on a first request such as a registration request of the first UE for network access.

[0375] In some embodiments, the second request at least includes user identity information of the first user.

[0376] In some embodiments, the second request includes at least one of:

[0377] A first subscription identifier, the first subscription identifier being used for identifying the first UE

[0378] A first device identifier, the first device identifier being used for identifying the first device. Exemplarily, the first UE can be a network gateway of the first device.

[0379] Exemplarily, the related description of the second request can refer to the corresponding embodiment of FIG. 2.

[0380] S5102: sending the user configuration information of the first user.

[0381] In some embodiments, the user configuration information of the first user is sent to the first network function.

[0382] In some embodiments, the user configuration information of the first user is sent according to the second request.

[0383] In some embodiments, the user configuration information of the first user is sent when the user configuration information of the first user is updated.

[0384] In some embodiments, the user configuration information can be used for user authentication of the first user.

[0385] Exemplarily, the user configuration information can be used by the first network function to determine whether user authentication of the first user is needed and / or how to perform the user authentication. Specifically, the content contained in the user configuration information can refer to the corresponding embodiment of FIG. 2.

[0386] In some embodiments, the second network function can be various core network functions. Exemplarily, the second network function can be any core network function that stores user information, for example, the second network function can include but is not limited to UDM and / or user profile server (UPS).

[0387] In some embodiments, the S5101 is an optional step, for example, the second network function can actively provide the user configuration information of the first user to the first network function without the need for the first network function to actively request to obtain the user configuration information. That is, the S5102 is a step that can be executed independently.

[0388] As shown in FIG. 6, the embodiments of the present disclosure provide a user authentication method, which is performed by a third network function, and the method can include:

[0389] S6101: receiving a second indication.

[0390] In some embodiments, the second indication is used to request user authentication of the first user.

[0391] In some embodiments, the second indication can include but is not limited to at least one of the following:

[0392] user identity information of the first user;

[0393] a first subscription identifier of the first UE;

[0394] authentication information;

[0395] indication information of an authentication manner used by the user authentication.

[0396] S6102: Perform user authentication on the first user.

[0397] In some embodiments, the user authentication on the first user is performed based on the second indication.

[0398] In some embodiments, the user authentication on the first user comprises at least one of the following:

[0399] Performing the user authentication on the first user based on the user identity information of the first user contained in the second indication, to obtain an authentication result;

[0400] Based on the user identity information of the first user contained in the second indication, instructing a third-party authentication server to perform the user authentication on the first user, and receiving an authentication result sent by the third-party authentication server.

[0401] The specific authentication result can be referred to the corresponding embodiments in FIG. 2.

[0402] In some embodiments, the user authentication on the first user can comprise:

[0403] Receiving a third request sent by the first UE, and at least part of information of the third request is protected by the first credential;

[0404] Verifying the third request using the second credential stored locally by the third network function;

[0405] If the third request passes the verification, it is considered that the first user passes the user authentication;

[0406] If the third request fails to pass the verification, it is considered that the first user fails to pass the user authentication.

[0407] In some embodiments, the user identity information and / or authentication information in the third request is protected by the first credential, and the user identity information and / or the first subscription identifier of the first user in the third request can be carried in plaintext.

[0408] In some embodiments, the user authentication on the first user is performed according to the authentication manner indicated by the second indication and / or the third request.

[0409] In some embodiments, the EAP authentication is performed on the first user by using the EAP framework. The specific authentication process can involve multiple information interactions between multiple network functions, which will not be repeated here.

[0410] S6103: Send the authentication result of the first user.

[0411] In some embodiments, the S6101 is an optional step, the first UE receives the first indication sent by the first network function, and the first UE initiates user authentication of the first user by the third network function based on the first indication.

[0412] Current mobile networks are user-centric, and in general, a user usually has only one mobile phone and has one subscription with an operator, and uses some services of the operator, such as a call service and / or a short message service (SMS).

[0413] However, nowadays, a user can have different kinds of devices, such as a mobile phone, a tablet computer, and / or a notebook computer. Some devices are owned by only one user, and can also be shared by multiple users. These devices can need to access operator services and / or non-operator services. With the rise of the Internet of Things technology, there are more and more kinds of Internet of Things devices, such as smart sensors, gateway devices, smart switches, actuators, and the like. There are various relationships between the owners of these devices, the holders of the subscriptions, and the actual users of the things.

[0414] Currently, before a device accesses a service, user authentication is usually performed. For example, user authentication based on a username and / or a password. However, with the increasing number of services, there are more and more credentials for user authentication, and therefore, it is more and more troublesome for a user to manage different credentials. Before a device accesses a service, an identity information provider performs user authentication by providing identity information to a network function or an application server.

[0415] An operator can provide enhanced services through a 3GPP network or a non-3GPP to improve user experience and optimize the network, for example, the network operator can adjust the network settings and customize services according to the needs of the user, without relying on the subscription data of the established connection. As an identity provider, the operator can consider additional information from the network, charge and provide differentiated services according to the user identification.

[0416] A user of a certain device can be identified based on subscription personal information, a UE connected by the device, or a gateway device connected by the device.

[0417] In some embodiments, the security architecture only supports authentication and / or authentication based on subscription personal information, but does not support authentication and / or authentication based on a UE connected by the device and / or a gateway device connected by the device.

[0418] Embodiments of the present disclosure provide a user authentication method to solve the above problems, which can specifically include: enabling a 3GPP system to enable a UE that performs user authentication based on subscription data to access operator or non-operator services.

[0419] In some embodiments, user authentication (VI-a) is part of the study of user identity security (V). User authentication (VI-a) is required between users through a user identification module (e.g., Universal Subscriber Identity Module (USIM)) and a user authentication and authorization function (UAAF).

[0420] Embodiments of the present disclosure provide a related solution for user authentication after the UE is authenticated by the access network for network access, for example, based on the identity information of the other UE connected by the UE or based on the identity information of the gateway connected by the UE.

[0421] Specifically, after receiving a registration request containing a user identifier for requesting registration to the network, the AMF can determine whether and how to initiate user authentication between the UE and the home network. The determination can involve user authentication initiated based on user profile information received from a user profile server (UPF). Such user authentication can also be supported by a user authentication and authorization function (UAAF) of the operator of the home network. The registration request will be accepted after the user authentication is passed.

[0422] Embodiment 1:

[0423] As shown in FIG. 7A, a user authentication method provided by embodiments of the present disclosure can include:

[0424] 1. When a user logs in a UE, the UE sends a registration request. The registration request can contain a UE subscription identifier (e.g., Subscription Concealed Identifier (SUCI)), a user identifier used by the UE, a user identifier of the other UE connected by the UE, identity information of the gateway connected by the UE, etc. The registration request can also include UE capability information, which can indicate the capabilities of the UE, for example, the UE capability information indicates whether the UE supports user authentication.

[0425] 2. For the initial registration request, the AMF should call the primary authentication service (primary authentication) based on the received SUCI. For subsequent registration requests, if the UE has undergone user authentication of primary authentication and the AMF has a valid security context, the primary authentication can be skipped.

[0426] 3. When the AMF receives the user identity in the registration request from the UE, it obtains the user configuration information related to the user identity from the UPS. Exemplarily, the user configuration information contains at least the following information:

[0427] The status of the user configuration, for example, the status of the user configuration can include but is not limited to: activated, inactivated, suspended, or suspended recovery, etc.

[0428] The SUbscription Permanent Identifier (SUPI) of the user, which is the 3GPP subscription identity of the UE;

[0429] The used device, for example, the used device can be identified by its subscription data or device identity;

[0430] The authentication policy, which can be used for user authentication of the UE to access the network, services and / or slices; and the authentication capability supported by the used device.

[0431] Other information.

[0432] 4. The AMF determines whether and how to trigger user authentication according to any of the following:

[0433] If the status of the user configuration information is activated, the AMF determines to trigger user authentication, otherwise the AMF can determine not to trigger user authentication, and if the user authentication is not triggered, the registration request can be rejected.

[0434] If the SUPI of the 3GPP subscription in the user configuration information is the same as the SUPI received from the UE, the AMF can determine to trigger user authentication, otherwise the AMF determines not to trigger user authentication and rejects the registration request.

[0435] If the user configuration information contains the device information of the used device, the AMF obtains the device identity by invoking the N5g-eir_MEIdentityCheck_Get service operation to start the UE identity check process. Then the AMF checks whether the device identity provided by the UE is the device identity of the used device recorded in the user configuration information. If yes, the AMF can determine to trigger user authentication. If not, the AMF determines not to trigger user authentication and rejects the registration request.

[0436] The AMF determines whether to trigger user authentication according to the authentication policy obtained from the user configuration information.

[0437] Exemplarily, if the UE does not send the UE capability supporting user authentication, the AMF obtains the authentication capability of the UE from the user configuration information. If the UE sends the capability information, it is determined whether the UE supports user authentication based on non-contract data according to the capability information sent by the UE.

[0438] 5a. Based on the identity verification in step 4, if one of the checks fails, the AMF sends a registration reject message to the UE, which can include a failure cause. For example, the failure cause can indicate that the user configuration information is not activated, there is no connected 3GPP contract, the device location, the user authentication function is not supported, and the like.

[0439] 5b. Based on the checks in step 4, if all the checks support user authentication, the AMF triggers user authentication between the UE and the UAAF according to the user authentication capability of the UE.

[0440] 6. The AMF sends a registration accept message to the UE. Optionally, the UE sends a registration complete.

[0441] Exemplarily, step 6 can include:

[0442] 6a. Registration accept related information transmission.

[0443] 6b. Registration complete related information transmission.

[0444] Embodiment 2:

[0445] After the primary user authentication, the AMF forwards the user identity contained in the registration request to the UDM. According to the user related information provided by the AMF, the UDM determines whether to initiate user authentication between the UE and the home network, and how to initiate user authentication, and returns the user authentication method to the AMF.

[0446] As shown in FIG. 7B, the user authentication method provided by the embodiment of the present disclosure can include:

[0447] 1. When a user logs in the UE or a user account, the UE sends a registration request. The registration request can contain a UE contract identifier (for example, a user contract identifier (SUCI)), a user identity used by the UE, a user identity of the UE connected to the UE, and identification information of the gateway connected to the UE. The registration request can also include UE capability information, which can indicate the capability of the UE.

[0448] 2. For the initial registration request, the AMF should call the primary authentication service based on the received SUCI. For subsequent registration requests, if the UE has undergone primary user authentication and the AMF has a valid security context, the primary user authentication can be skipped.

[0449] 3. The AMF can request the UDM to determine whether to allow the UE to register by invoking the Nudm_UECM_Registration / Nudm_User_Registration service operation. The information sent by the AMF to the UDM can include, but is not limited to, the UE identity (e.g., SUPI), the user identity currently used by the UE, the identity of other UEs associated with the UE, the identity of the network device to which the UE is connected, and / or the authentication capability supported by the UE.

[0450] 4. When the UDM receives the user identity from the AMF, the UDM obtains the user configuration information related to the user identity from the UPS. Exemplarily, the user configuration information at least contains the following information:

[0451] The status of the user configuration, for example, the status of the user configuration can include, but is not limited to, activated, inactivated, suspended, or suspended recovery, etc.

[0452] The subscription permanent identifier (SUbscription Permanent Identifier, SUPI), which is the 3GPP subscription identity of the UE;

[0453] The used device, for example, the used device can be identified by its subscription data or device identity;

[0454] The authentication policy, which can be used for user authentication, for example, the authentication policy can provide the way of user authentication, or allow the service and / or slice user authentication of user authentication;

[0455] The authentication capability supported by the used device;

[0456] Other information.

[0457] 5. The UDM determines whether to trigger user authentication and how to trigger user authentication according to the following principles:

[0458] If the status of the user configuration information is activated, the UDM can determine to trigger user authentication, otherwise the UDM determines not to trigger user authentication.

[0459] If the SUPI of the 3GPP subscription in the user configuration information is the same as the SUPI received from the UE, the UDM can determine to trigger user authentication, otherwise the UDM determines not to trigger user authentication.

[0460] If the user configuration information contains the used device information, the UDM initiates the UE identity check procedure by invoking the N5g-eir_MEIdentityCheck_Get service operation to obtain the device identity. Then the UDM checks whether the device identity provided by the UE is the used device identity recorded in the user configuration information. If yes, the UDM can determine to trigger the user authentication. If not, the AMF determines not to trigger the user authentication and rejects the registration request. The UDM determines whether to trigger the user authentication according to the authentication policy retrieved from the user configuration information.

[0461] If the UE has no UE capability information, the UDM checks the authentication capability supported by the used device retrieved from the user configuration information. If the UE has sent the UE capability information, the UDM determines whether the UE supports the user authentication according to the non-subscription number according to the UE capability information. That is, the capability information sent by the UE can override the capability information queried from the user configuration information. The UDM determines how to trigger the user authentication (user authentication method) according to the capability of the UE to support the user authentication.

[0462] 6. Based on the determination result of step 5, the UDM returns the Nudm_UECM_Registration / Nudm_User_Registration response to the AMF.

[0463] If all the checks support the user authentication, the user authentication method is included in the response.

[0464] If one of the checks fails, the response includes a failure cause. For example, the failure cause can indicate that the user configuration information is not activated, there is no connected 3GPP subscription, the device location, the user authentication function is not supported, etc.

[0465] 7a. If the received response includes a failure cause, the AMF UE sends a registration reject message. The registration reject message includes the failure cause.

[0466] 7b. If the received response includes the user authentication method, the AMF triggers the user authentication between the UE and the UAAF accordingly.

[0467] 8. The AMF sends a registration accept message to the UE. Optionally, the UE sends a registration complete message to the network side.

[0468] Exemplarily, step 8 can include:

[0469] 8a. Transmission of registration accept related information.

[0470] 8b. Transmission of registration complete related information.

[0471] The AMF can perform at least one of the following functions:

[0472] The AMF should be able to identify (understand) the user identity and / or UE capability, and the AMF can identify the user identity and / or UE capability according to the information sent by the UE to be authenticated.

[0473] The AMF should be able to obtain the user configuration information from the UPF based on the user identity.

[0474] The AMF should be able to determine whether and how to perform user authentication based on the information received from the UE.

[0475] The AMF should be able to determine whether and how to perform user authentication based on the information obtained from the user profile file.

[0476] If the AMF obtains information from the user profile file and information received from the UE used by the user, the information received from the UE used by the user is preferred to determine whether and how to perform user authentication.

[0477] The AMF should be able to trigger user authentication between the UE and the UAAF according to the authentication capability of the UE.

[0478] The AMF should be able to send a registration rejection message to the UE, which can be used to indicate the failure reason of user authentication.

[0479] The AMF should be able to use the Nudm-User-Registration service to call the UDM for user authentication.

[0480] The AMF should be able to receive and understand the authentication response of the UDM to the user. The AMF should be able to trigger user authentication between the UE and the UAAF based on the indication information of the authentication method received from the UDM.

[0481] If the registration response received from the UDM includes a failure reason, the AMF can send a registration rejection message to the UE.

[0482] Exemplarily, in some embodiments, the first network function can be an AMF, and the third network function can be a UDM or an AUSF. In some embodiments, the first network function can be a UDM, and the third network function can be a UAAF or a UIMF, etc.

[0483] The UDM can perform at least one of the following functions:

[0484] The UDM should be able to identify the UE identity and / or whether the UE supports user authentication capability based on the registration request sent by the AMF.

[0485] The UDM should be able to obtain the user configuration information from the UPF using the user identity.

[0486] The UDM should be able to determine whether and / or how to perform user authentication, e.g., based on user configuration information obtained from the UPS, determine whether and / or how to perform user authentication.

[0487] The UDM should send a registration response to the AMF, which can include a failure cause that can indicate that user authentication failed, user authentication cannot be performed, and / or a reason why user authentication cannot be performed.

[0488] The UPS can perform at least one of the following functions:

[0489] The UPS should be able to provide user configuration information associated with a user identity to the AMF based on a request from the AMF;

[0490] The UPS should be able to provide user configuration information associated with a user identity to the UDM based on a request from the UDM.

[0491] The UE can perform at least one of the following functions:

[0492] The UE should be able to send a registration request containing a user identity and / or capability information;

[0493] The UE should be able to perform user authentication triggered by the AMF.

[0494] In the embodiments of the present disclosure, part or all of the steps, and optional implementation manners thereof, can be combined with part or all of the steps in other embodiments, or can be combined with optional implementation manners of other embodiments.

[0495] In the embodiments of the present disclosure, part or all of the steps, and optional implementation manners thereof, can be combined with part or all of the steps in other embodiments, or can be combined with optional implementation manners of other embodiments.

[0496] The embodiments of the present disclosure also provide a device for implementing any of the above methods, for example, providing a device, the above device includes units or modules for implementing each step performed by the terminal in any of the above methods. For another example, another device is also provided, which includes units or modules for implementing each step performed by the network device (for example, an access network device, or a core network device, etc.) in any of the above methods.

[0497] It should be understood that the division of each unit or module in the above apparatus is only a logical function division, and all or part of them can be integrated into a physical entity or physically separated in actual implementation. In addition, the units or modules in the apparatus can be implemented in the form of processor calling software: for example, the apparatus includes a processor connected with a memory, the memory stores instructions, and the processor calls the instructions stored in the memory to implement any of the above methods or realize the functions of each unit or module of the above apparatus, wherein the processor is, for example, a general processor such as a central processing unit (CPU) or a microprocessor, and the memory is a memory in the apparatus or a memory outside the apparatus. Alternatively, the units or modules in the apparatus can be implemented in the form of hardware circuit, and the functions of part or all of the units or modules can be realized by the design of hardware circuit. The above hardware circuit can be understood as one or more processors; for example, in one implementation, the above hardware circuit is an application-specific integrated circuit (ASIC), and the functions of part or all of the above units or modules are realized by the design of the logical relationship of elements in the circuit; for example, in another implementation, the above hardware circuit is a programmable logic device (PLD), and a field programmable gate array (FPGA) is taken as an example, which can include a large number of logic gate circuits, and the connection relationship between the logic gate circuits is configured by a configuration file, so as to realize the functions of part or all of the above units or modules. All units or modules of the above apparatus can be implemented in the form of processor calling software, or all units or modules can be implemented in the form of hardware circuit, or part of the units or modules are implemented in the form of processor calling software, and the remaining part is implemented in the form of hardware circuit.

[0498] In the embodiments of the present disclosure, the processor is a circuit with signal processing capability. In one implementation, the processor can be a circuit with instruction reading and running capability, such as a central processing unit (CPU), a microprocessor, a graphics processing unit (GPU) (which can be understood as a microprocessor), a digital signal processor (DSP), and the like. In another implementation, the processor can implement certain functions through a logical relationship of a hardware circuit, and the logical relationship of the hardware circuit is fixed or reconfigurable. For example, the processor is a hardware circuit implemented by an application-specific integrated circuit (ASIC) or a programmable logic device (PLD), such as an FPGA. In the reconfigurable hardware circuit, the processor loads a configuration document to implement the configuration of the hardware circuit. It can be understood that the processor loads an instruction to implement the functions of the above part or all units or modules. In addition, the hardware circuit can also be designed for artificial intelligence, which can be understood as an ASIC, such as a neural network processing unit (NPU), a tensor processing unit (TPU), a deep learning processing unit (DPU), and the like.

[0499] As shown in FIG. 8A, the embodiments of the present disclosure provide a first network function, which can include:

[0500] The processing module 7101 is configured to determine whether to perform user authentication on the first user, and determine to perform user authentication on the first user, and initiate a user authentication process of the first user.

[0501] In some embodiments, the processing module can be configured to perform information processing related steps in any one of the user authentication methods by the first network function.

[0502] In some embodiments, the terminal can further include a sending module and / or a receiving module.

[0503] In some embodiments, the sending module and / or the receiving module can correspond to a network interface and / or a transceiving antenna of the first network function.

[0504] In some embodiments, the sending module can be configured to perform information sending related steps in any one of the user authentication methods by the first network function.

[0505] In some embodiments, the receiving module may be used by the first network function to perform steps related to information sending in any user authentication method.

[0506] The receiving module is configured to receive a first request sent by a first user equipment UE used by a first user; the first request includes at least user identity information of the first user; the processing module is configured to receive the first request and determine whether to perform user authentication on the first user.

[0507] In some embodiments, the first request is a registration request for a first UE and / or a first device; the first UE is a UE used by a first user; the first device is a device associated with the first UE; and the sending module is configured to perform at least one of the following:

[0508] determining not to perform user authentication on the first user and / or that user authentication on the first user fails, and sending a first response to the first UE; the first response indicating that the first request is rejected;

[0509] The user authentication of the first user is passed and the network access authentication of the first UE and / or the first device is passed, and a second response is sent to the first UE; the second response indicates that the first request is accepted.

[0510] In some embodiments, the first response includes a reason for the failure.

[0511] In some embodiments, the failure reason includes at least one of the following:

[0512] User authentication for the first user is not supported;

[0513] The reason why user authentication of the first user is not supported;

[0514] User authentication of the first user fails;

[0515] The reason why user authentication failed for the first user.

[0516] In some embodiments, the first request includes at least one of the following:

[0517] A first subscription identifier, where the first subscription identifier is used to identify the first UE;

[0518] a first device identifier, where the first device identifier is used to identify a first device used by the first user;

[0519] Capability information; UE capability information is used to indicate to the first network function whether the first UE and / or the first device supports user authentication;

[0520] The first UE is a UE used by a first user; the first device is a device associated with the first UE.

[0521] In some embodiments, the processing module is configured to determine whether to perform user authentication for the first user according to user configuration information of the first user.

[0522] In some embodiments, the processing module is configured to perform at least one of the following:

[0523] whether the user configuration information of the first user is activated, determining whether to perform user authentication for the first user;

[0524] whether the first subscription identifier can identify the second device, determining whether to perform user authentication for the first user; the first subscription identifier identifies a first UE used by the first user; a second subscription identifier or a second device identifier of the second device is recorded in the user configuration information;

[0525] whether the first device identifier can identify a third device, determining whether to perform user authentication for the first user; a device identifier of the third device is recorded in the user configuration information; whether an authentication policy for user authentication is recorded in the user configuration information, determining whether to perform user authentication for the first user;

[0526] whether the first UE and / or the first device support user authentication, determining whether to perform user authentication for the first user;

[0527] wherein the first UE is a UE used by the first user; and the first device is a device associated with the first UE.

[0528] In some embodiments, the processing module is configured to perform at least one of the following:

[0529] when the user configuration information of the first user is not activated, determining not to perform user authentication for the first user;

[0530] when the user configuration information of the first user is activated, determining to perform user authentication for the first user.

[0531] In some embodiments, the processing module is configured to perform at least one of the following:

[0532] when the first subscription identifier matches the second subscription identifier, determining to perform user authentication for the first user;

[0533] when the first subscription identifier does not match the second subscription identifier, determining not to perform user authentication for the first user.

[0534] In some embodiments, the processing module is configured to perform at least one of the following: determining whether to perform user authentication on the first user according to whether the first device identifier can identify the third device includes at least one of the following: determining to perform user authentication on the first user according to that the first device identifier can identify the third device; determining not to perform user authentication on the first user according to that the first device identifier cannot identify the third device. In some embodiments, the processing module is configured to perform at least one of the following:

[0535] The user configuration information records an authentication policy for user authentication, and it is determined to perform user authentication on the first user.

[0536] The user configuration information does not record an authentication policy for user authentication, and it is determined not to perform user authentication on the first user.

[0537] In some embodiments, the processing module is configured to perform at least one of the following:

[0538] The first UE and / or the first device support user authentication, and it is determined to perform user authentication on the first user.

[0539] The first UE and the first device do not support user authentication, and it is determined not to perform user authentication on the first user.

[0540] In some embodiments, the processing module is configured to perform at least one of the following:

[0541] According to the first information sent by the first UE, it is determined whether the first UE and / or the first device support user authentication; the first information includes capability information of the first UE and / or capability information of the first device.

[0542] According to the second information in the user configuration information, it is determined whether the first UE and / or the first device support user authentication; the second information is used to indicate the capability of the first UE and / or the first device.

[0543] In a case where the first information is obtained and the user configuration information records the second information, it is determined whether the first UE and / or the first device support user authentication according to the first information.

[0544] In some embodiments, the processing module is configured to perform at least one of the following:

[0545] It is determined to perform user authentication on the first user, and the authentication manner for the first user is determined.

[0546] In some embodiments, the processing module is configured to perform at least one of the following:

[0547] It is determined to perform user authentication on the first user, and the authentication manner for the first user is determined according to the user configuration information of the first user.

[0548] In some embodiments, the receiving module is configured to receive the user configuration information sent by the second network function.

[0549] In some embodiments, the sending module is configured to send a second request to the second network function; the second request is used to request the user configuration information of the first user.

[0550] In some embodiments, the second request comprises:

[0551] user identity information of the first user and / or a first subscription identifier, the first subscription identifier being used to identify the first UE and / or a first device; the first UE is a UE used by the first user; the first device identifier is used to identify the first device.

[0552] In some embodiments, the second network function comprises: a user configuration information server.

[0553] In some embodiments, the sending module is configured to perform at least one of the following:

[0554] sending a first indication to the first UE; the first indication is used to instruct the first UE to perform user authentication of the first user with a third network function;

[0555] sending a second indication to the third network function; the second indication is used to request user authentication of the first user.

[0556] In some embodiments, the first indication or the second indication comprises: indication information of an authentication mode used by the user authentication.

[0557] In some embodiments, the first network function comprises at least one of the following:

[0558] an access management function AMF;

[0559] a security anchor function SEAF;

[0560] a user management function UDM.

[0561] As shown in FIG. 8B, the embodiments of the present disclosure provide a first UE, wherein the first UE comprises:

[0562] a sending module 7201 configured to send a first request to a first network function; the first request comprises at least user identity information of a first user using the first UE; after the first request is received by the first network function, it is determined whether to perform user authentication of the first user.

[0563] In some embodiments, the first request comprises at least one of the following:

[0564] a first subscription identifier, the first subscription identifier being used to identify the first UE;

[0565] a first device identifier, the first device identifier being used to identify a first device used by the first user;

[0566] capability information; the capability information being used by the first network function to determine whether the first UE and / or the first device supports user authentication of the first user;

[0567] the first UE is a UE used by the first user; and the first device is a device associated with the first UE.

[0568] In some embodiments, the first request is a registration request of the first UE and / or the first device.

[0569] In some embodiments, the receiving module is configured to receive a first response or a second response; the first response indicates that the first request is rejected; and the second response indicates that the first request is accepted.

[0570] In some embodiments, the first response includes a failure cause.

[0571] In some embodiments, the failure cause indicates at least one of:

[0572] user authentication of the first user is not supported;

[0573] a reason why user authentication of the first user is not supported;

[0574] user authentication of the first user fails;

[0575] a reason why user authentication of the first user fails.

[0576] In some embodiments, the receiving module is configured to receive a first indication sent by the first network function; the first indication is used to indicate that the first UE performs user authentication of the first user with a third network function.

[0577] In some embodiments, the first indication includes indication information of an authentication mode used for user authentication.

[0578] As shown in FIG. 8C, the embodiments of the present disclosure provide a second network function, wherein the second network function includes:

[0579] a sending module 7301 configured to send user configuration information of the first user to the first network function; the user configuration information is used by the first network function to determine whether to perform user authentication of the first user and / or an authentication mode of the user authentication.

[0580] In some embodiments, the second network function can comprise a processing module and / or a receiving module. The processing module is configured to perform steps related to information processing in the user authentication method. The sending module is configured to perform steps related to information sending in the user authentication method. The receiving module is configured to perform steps related to information receiving in the user authentication method.

[0581] In some embodiments, the receiving module is configured to receive a second request sent by the first network function, the second request being used for the first network function to request the user configuration information of the first user.

[0582] In some embodiments, the second request comprises at least one of:

[0583] a user identity of the first user and / or a first UE device identifier, the first UE device identifier being used to identify the first UE; the first UE being a UE used by the first user; the first UE device identifier being used to identify the first UE.

[0584] As shown in FIG. 8D, the embodiments of the present disclosure provide a third network function, the third network function comprising:

[0585] a receiving module 7401 configured to receive a second indication sent by the first network function, the second indication being used to request user authentication of the first user;

[0586] a processing module 7402 configured to perform user authentication of the first user according to the second indication.

[0587] In some embodiments, the third network function can comprise a processing module and / or a receiving module. The processing module is configured to perform steps related to information processing in the user authentication method. The sending module is configured to perform steps related to information sending in the user authentication method. The receiving module is configured to perform steps related to information receiving in the user authentication method.

[0588] In some embodiments, the second indication comprises indication information of an authentication mode used for user authentication.

[0589] The embodiments of the present disclosure also provide a communication device, which can comprise: one or more processors; wherein the processor is configured to invoke instructions to enable the communication device to perform the user authentication method implemented by any one of the preceding embodiments.

[0590] In some embodiments, as shown in FIG. 9A and / or FIG. 9B, the communication device 8100 further comprises one or more memories 8102 configured to store instructions. Optionally, all or part of the memory 8102 can also be located outside the communication device 8100.

[0591] The communication device can be the terminal and the network device described above. In some embodiments, the network device can be a master node and / or a secondary node.

[0592] In some embodiments, the communication device 8100 further includes one or more transceivers 8103. When the communication device 8100 includes one or more transceivers 8103, the communication steps such as sending and receiving in the above method are performed by the transceiver 8103, and other steps are performed by the processor 8101.

[0593] In some embodiments, the transceiver can include a receiver and a transmitter, which can be separate or integrated together. Optionally, the terms transceiver, transceiving unit, transceiver, transceiving circuit, etc. can be replaced with each other, the terms transmitter, transmitting unit, transmitter, transmitting circuit, etc. can be replaced with each other, and the terms receiver, receiving unit, receiver, receiving circuit, etc. can be replaced with each other.

[0594] Optionally, the communication device 8100 further includes one or more interface circuits 8104, which are connected with the memory 8102, and can be used to receive signals from the memory 8102 or other devices, and can be used to send signals to the memory 8102 or other devices. For example, the interface circuit 8104 can read the instructions stored in the memory 8102 and send the instructions to the processor 8101.

[0595] The communication device 8100 described in the above embodiments can be a network device or a terminal, but the scope of the communication device 8100 described in the present disclosure is not limited to this, and the structure of the communication device 8100 can not be limited to the structure shown in FIG. 9A. The communication device can be a standalone device or can be part of a larger device. For example, the communication device can be: (1) a standalone integrated circuit (IC), or a chip, or a chip system or subsystem; (2) a set of one or more ICs, which can optionally also include storage components for storing data, programs; (3) an ASIC, such as a Modem; (4) a module that can be embedded in other devices; (5) a receiver, a terminal device, a smart terminal device, a cellular phone, a wireless device, a handset, a mobile unit, a vehicle-mounted device, a network device, a cloud device, an artificial intelligence device, etc.; (6) other devices, etc.

[0596] FIG. 9B is a structural schematic diagram of a chip 8200 according to an embodiment of the present disclosure. For the case where the communication device 8100 is a chip or a chip system, the structural schematic diagram of the chip 8200 shown in FIG. 9B can be referred to, but is not limited to this.

[0597] The chip 8200 comprises one or more processors 8201 configured to invoke instructions to cause the chip 8200 to perform any of the above user authentication methods.

[0598] In some embodiments, the chip 8200 further comprises one or more interface circuits 8202 connected with the memory 8203, which can be configured to receive signals from the memory 8203 or other devices, and can be configured to send signals to the memory 8203 or other devices. For example, the interface circuit 8202 can read instructions stored in the memory 8203 and send the instructions to the processor 8201. Alternatively, the terms interface circuit, interface, transceiver pin, transceiver, etc. can be replaced by each other.

[0599] In some embodiments, the chip 8200 further comprises one or more memories 8203 configured to store instructions. Alternatively, all or part of the memory 8203 can be outside the chip 8200.

[0600] The present disclosure also provides a storage medium having instructions stored thereon, which, when executed on the communication device 8100, cause the communication device 8100 to perform any of the above methods. Alternatively, the storage medium is an electronic storage medium. Alternatively, the storage medium is a computer readable storage medium, but can also be a storage medium readable by other devices. Alternatively, the storage medium can be a non-transitory storage medium, but can also be a transitory storage medium.

[0601] The present disclosure also provides a program product, which, when executed by the communication device 8100, causes the communication device 8100 to perform any of the above user authentication methods. Alternatively, the program product is a computer program product.

[0602] The present disclosure also provides a computer program, which, when executed on a computer, causes the computer to perform any of the above user authentication methods.

[0603] Other embodiments of the present disclosure will be apparent to those skilled in the art from consideration of the specification and practice of the features disclosed herein. The present disclosure is intended to cover any variations, uses, or adaptations of the present disclosure embodiments following, in general, the principles of the present disclosure and including such features to the present disclosure as come within the true spirit and scope of the present disclosure. The specification and examples are to be regarded as illustrative only, and the true scope and spirit of the present disclosure are indicated by the following claims.

[0604] It should be understood that the embodiments of the present disclosure are not limited to the precise construction that has been described above and shown in the accompanying drawings and that various modifications and changes can be made without departing from the scope thereof. The scope of the present disclosure is limited only by the appended claims.

Claims

1. A user authentication method, wherein: Executed by a first network function, the method includes: determining whether to perform user authentication on the first user; Determine to perform user authentication on the first user and initiate a user authentication process for the first user.

2. The method according to claim 1, wherein The method further comprises: Receiving a first request sent by a first user equipment UE used by the first user; the first request includes at least user identity information of the first user; and determining whether to perform user authentication on the first user includes: Upon receiving the first request, determining whether to perform user authentication on the first user.

3. The method according to claim 2, wherein: The first request is a registration request for a first UE and / or a first device; the first UE is a UE used by the first user; the first device is a device associated with the first UE; and the method further includes at least one of the following: determining not to perform user authentication on the first user and / or that user authentication on the first user fails, and sending a first response to the first UE, wherein the first response indicates that the first request is rejected; The user authentication of the first user is passed and the network access authentication of the first UE and / or the first device is passed, and a second response is sent to the first UE; the second response indicates that the first request is accepted.

4. The method according to claim 3, wherein: The first response includes a reason for the failure.

5. The method according to claim 4, wherein The failure reasons include at least one of the following: User authentication of the first user is not supported; the reason why user authentication of the first user is not supported; User authentication of the first user fails; The reason why the user authentication of the first user failed.

6. The method according to any one of claims 1 to 5, wherein: The first request includes at least one of the following: A first subscription identifier, where the first subscription identifier is used to identify the first UE; a first device identifier, where the first device identifier is used to identify a first device used by the first user; capability information; The UE capability information is used to indicate to the first network function whether the first UE and / or the first device supports user authentication; The first UE is a UE used by the first user; the first device is a device associated with the first UE.

7. The method according to any one of claims 1 to 6, wherein: The determining whether to perform user authentication on the first user includes: Determine whether to perform user authentication on the first user according to the user configuration information of the first user.

8. The method according to claim 7, wherein: The determining, based on the user configuration information of the first user, whether to perform user authentication on the first user includes at least one of the following: Whether the user configuration information of the first user is activated, determining whether to perform user authentication on the first user; determining whether to perform user authentication on the first user based on whether the first subscription identifier can identify the second device; The first subscription identifier identifies a first UE used by the first user; The second subscription identifier or the second device identifier of the second device is recorded in the user configuration information; determining whether to perform user authentication on the first user based on whether the first device identifier can identify the third device; The device identification of the third device is recorded in the user configuration information; determining whether to perform user authentication on the first user according to whether the user configuration information records an authentication policy for user authentication; determining whether to perform user authentication on the first user according to whether the first UE and / or the first device supports user authentication; The first UE is a UE used by the first user; and the first device is a device associated with the first UE.

9. The method according to claim 8, wherein Whether the user configuration information of the first user is activated determines whether to perform user authentication on the first user, including at least one of the following: The user configuration information of the first user is not activated, and it is determined not to perform user authentication on the first user; The user configuration information of the first user is activated, and user authentication is performed on the first user.

10. The method according to claim 8 or 9, wherein: The determining whether to perform user authentication on the first user based on whether the first contract identifier matches the second contract identifier recorded in the user configuration information includes at least one of the following: The first contract identification matches the second contract identification, and user authentication is performed on the first user; The first contract identification does not match the second contract identification, and it is determined not to perform user authentication on the first user.

11. The method according to any one of claims 8 to 10, wherein: Determining whether to perform user authentication on the first user according to whether the first device identifier can identify the third device includes at least one of the following: determining to perform user authentication on the first user based on that the first device identifier can identify the third device; The first device identifier cannot identify the third device, and it is determined that user authentication is not performed on the first user.

12. The method according to any one of claims 8 to 11, wherein: Determining whether and / or how to perform user authentication on the first user, based on whether the user configuration information records an authentication policy for user authentication, includes at least one of the following: The user configuration information records an authentication policy for user authentication, and determines to perform user authentication on the first user; The user configuration information does not record the authentication policy for user authentication, and it is determined not to perform user authentication on the first user.

13. The method according to any one of claims 8 to 12, wherein: Determining whether to perform user authentication on the first user according to whether the first UE and / or the first device supports user authentication includes at least one of the following: The first UE and / or the first device supports user authentication, and determines to perform user authentication on the first user; The first UE and the first device do not support user authentication, and determine not to perform user authentication on the first user.

14. The method according to any one of claims 8 to 13, wherein: The method further comprises at least one of the following: determining, based on first information sent by the first UE, whether the first UE and / or the first device supports user authentication; the first information including capability information of the first UE and / or capability information of the first device; determining, according to the second information in the user configuration information, whether the first UE and / or the first device supports user authentication; The second information is used to indicate the capability of the first UE and / or the first device; When the first information is obtained and the user configuration information records the second information, it is determined whether the first UE and / or the first device supports user authentication based on the first information.

15. The method according to any one of claims 1 to 14, wherein: The method further comprises: Determine to perform user authentication on the first user and determine an authentication method for the first user.

16. The method according to claim 15, wherein The determining to perform user authentication on the first user and determining an authentication method for the first user includes: Determine to perform user authentication on the first user, and determine an authentication method for the first user according to the user configuration information of the first user.

17. The method according to any one of claims 7 to 14 or 16, wherein: The method further includes: receiving the user configuration information sent by the second network function.

18. The method according to claim 17, wherein The method further comprises: Send a second request to the second network function; the second request is used to request user configuration information of the first user.

19. The method according to claim 18, wherein The second request includes: The user identity information and / or first device identifier of the first user, the first subscription identifier is used to identify the first UE; the first UE is the UE used by the first user; the first device identifier is used for the first device.

20. The method according to any one of claims 17 to 19, wherein: The second network function includes: a user configuration information server.

21. The method according to any one of claims 1 to 20, wherein: The initiating the user authentication process of the first user includes at least one of the following: Sending a first instruction to the first UE; the first instruction is used to instruct the first UE and the third network function to perform user authentication of the first user; Send a second indication to the third network function; the second indication is used to request user authentication for the first user.

22. The method according to claim 21, wherein The first indication or the second indication includes: indication information of the authentication method used for the user authentication.

23. The method according to any one of claims 1 to 22, wherein: The first network function includes at least one of the following: Access Management Function AMF; Security Anchor Function SEAF; User management function UDM.

24. A user authentication method, wherein: The method is performed by a first UE and includes: Sending a first request to a first network function; the first request includes at least user identity information of a first user using the first UE; after the first network function receives the first request, determining whether to perform user authentication on the first user.

25. The method according to claim 24, wherein The first request includes at least one of the following: A first subscription identifier, where the first subscription identifier is used to identify the first UE; a first device identifier, where the first device identifier is used to identify a first device used by the first user; Capability information; The capability information is used by the first network function to determine whether the first UE and / or the first device supports user authentication; The first UE is a UE used by the first user; the first device is a device associated with the first UE.

26. The method according to claim 24 or 25, wherein The first request is a registration request of the first UE and / or first device.

27. The method according to claim 26, wherein The method further comprises: A first response or a second response is received; the first response indicates that the first request is rejected; the second response indicates that the first request is accepted.

28. The method according to claim 27, wherein The first response includes a reason for the failure.

29. The method according to claim 28, wherein The failure reason indicates at least one of the following: User authentication of the first user is not supported; the reason why user authentication of the first user is not supported; User authentication of the first user fails; The reason why the user authentication of the first user failed.

30. The method according to any one of claims 24 to 29, wherein The method further comprises: Receive a first indication sent by the first network function; the first indication is used for the first indication, which is used to instruct the first UE and the third network function to perform user authentication of the first user.

31. The method according to claim 30, wherein The first indication includes: indication information of the authentication method used for the user authentication.

32. A user authentication method, wherein: Executed by a second network function, the method includes: Sending user configuration information of the first user to the first network function; the user configuration information is used by the first network function to determine whether to perform user authentication on the first user and / or the authentication method for performing the user authentication.

33. The method according to claim 32, wherein The method further comprises: A second request sent by the first network function is received, where the second request is used by the first network function to request user configuration information of the first user.

34. The method according to claim 32 or 33, wherein The second request includes at least one of the following: The user identity identifier and / or first UE device identifier of the first user, the first UE device identifier is used to identify the first UE; the first UE is the UE used by the first user; the first UE device identifier, the first UE device identifier is used to identify the first UE.

35. A user authentication method, wherein: Executed by a third network function, the method includes: receiving a second indication sent by the first network function, wherein the second indication is used to request user authentication for the first user; Perform user authentication on the first user according to the second instruction.

36. The method according to claim 35, wherein The second indication includes indication information of the authentication method used for the user authentication.

37. A first network function, wherein: include: a processing module configured to determine whether to perform user authentication on the first user; Determine to perform user authentication on the first user and initiate a user authentication process for the first user.

38. A first user equipment UE, wherein: include: a sending module, configured to send a first request to the first network function; The first request includes at least user identity information of a first user using the first UE; After receiving the first request, the first network function determines whether to perform user authentication on the first user.

39. A second network function, wherein: include: a receiving module, configured to receive a first indication sent by the first network function; The first indication is used for the first indication, and is used to instruct the first UE and the third network function to perform user authentication of the first user.

40. A third network function, wherein: include: a receiving module, configured to receive a second indication sent by the first network function; The second indication is used to request user authentication for the first user; The processing module is configured to perform user authentication on the first user according to the second indication.

41. A communication system, wherein: include: a first network function, configured to perform the method according to any one of claims 1 to 23; A first user equipment UE, configured to perform the method according to any one of claims 24 to 34; The third network function is configured to execute the method according to claim 35 or 36.

42. A communication device, wherein: The communication device comprises: one or more processors; The processor is configured to call instructions to enable the communication device to execute the user authentication method according to any one of claims 1 to 23, 24 to 34, and / or 35 to 36.

43. A storage medium, wherein The storage medium stores instructions, which, when executed on a communication device, enable the communication device to execute the user authentication method according to any one of claims 1 to 23, 24 to 34, and / or 35 to 36.

44. A program product comprising a computer program, which, when executed by a communication device, causes the communication device to execute the user authentication method according to any one of claims 1 to 23, 24 to 34, and / or 35 to 36.