User authentication method, communication device and storage medium

CN121128203APending Publication Date: 2025-12-12BEIJING XIAOMI MOBILE SOFTWARE CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202480006452.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-04-10
Publication Date
2025-12-12

AI Technical Summary

Technical Problem

In wireless access backhaul base stations, how to securely authenticate user equipment shared by multiple users to ensure device security and user-based control and billing.

Method used

The first network function sends a request to the second network function to perform user authentication and receive a response indicating the authentication result. The second network function authenticates the user and sends a response. The third network function also participates in the authentication process. The user device also initiates an authentication request and receives a response. The credentials are used to protect the user identity and authentication information, ensuring the security and flexibility of the authentication process.

Benefits of technology

It realizes the authentication of specific users, ensures the security of user equipment usage and user-based control and billing, simplifies the authentication process, and improves the security and flexibility of authentication.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121128203A_ABST
    Figure CN121128203A_ABST
Patent Text Reader

Abstract

The invention provides a user authentication method, communication equipment and a storage medium. The user authentication method comprises the following steps: sending a first request to a second network function; the first request is used for requesting to perform user authentication on a first user using first user equipment (UE); receiving a first response sent by the second network function; the first response is used for indicating whether the user authentication of the first user is passed or not.
Need to check novelty before this filing date? Find Prior Art

Description

User authentication method, communication device and storage medium TECHNICAL FIELD

[0001] The present disclosure relates to the technical field of communication, and particularly relates to a user authentication method, a communication device and a storage medium. BACKGROUND

[0002] Mobile gNB with wireless access backhaul (MWAB) refers to that a user equipment (UE) or a mobile base station accesses as other user equipment (UE). For example, a UE which has camped on a cell can provide wireless access for other UEs to access the cell which the UE camps on.

[0003] SUMMARY

[0004] The present disclosure provides a user authentication method, a communication device and a storage medium.

[0005] According to a first aspect of the present disclosure, a user authentication method is provided, wherein the method is performed by a first network function, and the method comprises: sending a first request to a second network function; the first request is used to request user authentication of a first user using a first user equipment (UE); receiving a first response sent by the second network function; the first response is used to indicate whether the user authentication of the first user passes.

[0006] According to a second aspect of the present disclosure, a user authentication method is provided, wherein the method is performed by a second network function, and the method comprises: receiving a first request sent by a first network function; the first request is used to request user authentication of a first user of the first UE; performing user authentication on the first user; sending a first response to the first network function or the first UE according to a result of the user authentication.

[0007] According to a third aspect of the present disclosure, a user authentication method is provided, wherein the method is performed by a third network function, and the method comprises: receiving a fourth request sent by a second network function; the fourth request is used to request the third network function to perform user authentication on a first user using a first user equipment (UE); performing user authentication on the first user; sending a fourth response to the second network function according to a result of the user authentication; the fourth response is used to indicate whether the user authentication of the first user passes.

[0008] According to a third aspect of embodiments of the present disclosure, a user authentication method is provided, wherein the method is performed by a first user equipment (UE), and the method comprises: sending, to a first network function, a second request; the second request is used for the first UE to request user authentication of a first user; receiving a second response sent by the first network function; the second response is used to indicate whether the first user passes the user authentication.

[0009] According to a fifth aspect of embodiments of the present disclosure, a first network function is provided, wherein the first network function comprises:

[0010] a sending module configured to send, to a second network function, a first request; the first request is used to request user authentication of a first user using a first user equipment (UE); a receiving module configured to receive a first response sent by the second network function; the first response is used to indicate whether the first user passes the user authentication.

[0011] According to a sixth aspect of embodiments of the present disclosure, a second network function is provided, wherein the second network function comprises: a receiving module configured to receive a first request sent by a first network function; the first request is used to request user authentication of a first user of the first UE; a processing module configured to perform user authentication on the first user; and a sending module configured to send, to the first network function or the first UE, a first response according to a result of the user authentication.

[0012] According to a seventh aspect of embodiments of the present disclosure, a third network function is provided, wherein the third network function comprises: a receiving module configured to receive a fourth request sent by a second network function; the fourth request is used to request the third network function to perform user authentication on a first user using a first user equipment (UE); a processing module configured to perform user authentication on the first user; and a sending module configured to send, to the second network function, a fourth response according to a result of the user authentication; the fourth response is used to indicate whether the first user passes the user authentication.

[0013] According to an eighth aspect of embodiments of the present disclosure, a first user equipment (UE) is provided, wherein the first UE comprises: a sending module configured to send, to a first network function, a second request; the second request is used for the first UE to request user authentication of a first user; and a receiving module configured to receive a second response sent by the first network function; the second response is used to indicate whether the first user passes the user authentication.

[0014] According to a ninth aspect of embodiments of the present disclosure, a communication system is provided, wherein the communication system comprises:

[0015] The first network function is configured to perform the method provided in any of the technical solutions of the first aspect.

[0016] The second network function is configured to perform the method provided in any of the technical solutions of the second aspect.

[0017] The third network function is configured to perform the method provided in any of the technical solutions of the third aspect.

[0018] The first user equipment (UE) is configured to perform the method provided in any of the technical solutions of the fourth aspect.

[0019] According to a tenth aspect of the embodiments of the present disclosure, a communication device is provided, and the communication device comprises:

[0020] one or more processors;

[0021] The processor is configured to invoke instructions to cause the communication device to perform the user authentication method in any of the first aspect to the fourth aspect.

[0022] According to an eleventh aspect of the embodiments of the present disclosure, a storage medium is provided, and the storage medium stores instructions, when the instructions are executed on a communication device, causing the communication device to perform the user authentication method in any of the first aspect to the fourth aspect.

[0023] According to an eleventh aspect of the embodiments of the present disclosure, a program product is provided, and the program product comprises a computer program, when the computer program is executed on a communication device, causing the communication device to perform the user authentication method in any of the first aspect to the fourth aspect.

[0024] The technical solution provided by the embodiments of the present disclosure can perform user authentication for a first UE by a user (a first user) using the first UE, so that when one UE is used by multiple users, the specific user can be authenticated respectively, and the security of the first UE and / or the control and charging based on the user can be ensured.

[0025] It should be understood that the foregoing general description and the following detailed description are only exemplary and explanatory, and cannot limit the embodiments of the present disclosure. BRIEF DESCRIPTION OF DRAWINGS

[0026] The accompanying drawings, which are incorporated into the specification and constitute a part of the specification, illustrate the embodiments consistent with the present disclosure, and together with the specification, serve to explain the principles of the embodiments of the present disclosure.

[0027] FIG. 1 is a schematic diagram of an architecture of a communication system according to an exemplary embodiment;

[0028] FIG. 2 is a schematic diagram of a user authentication method according to an exemplary embodiment;

[0029] FIG. 3 is a flow diagram illustrating a user authentication method according to an example embodiment;

[0030] FIG. 4 is a flow diagram illustrating a user authentication method according to an example embodiment;

[0031] FIG. 5 is a flow diagram illustrating a user authentication method according to an example embodiment;

[0032] FIG. 6 is a flow diagram illustrating a user authentication method according to an example embodiment;

[0033] FIG. 7A is a flow diagram illustrating a user authentication method according to an example embodiment;

[0034] FIG. 7B is a flow diagram illustrating a user authentication method according to an example embodiment;

[0035] FIG. 8A is a structural diagram of a first network function according to an example embodiment;

[0036] FIG. 8B is a structural diagram of a second network function according to an example embodiment;

[0037] FIG. 8C is a structural diagram of a third network function according to an example embodiment;

[0038] FIG. 8D is a structural diagram of a first UE according to an example embodiment;

[0039] FIG. 9A is a structural diagram of a communication device according to an example embodiment;

[0040] FIG. 9B is a structural diagram of a chip according to an example embodiment. DETAILED DESCRIPTION

[0041] The present disclosure provides a user authentication method, a communication device, and a storage medium.

[0042] The first aspect provides a user authentication method, wherein the method is performed by a first network function, and the method comprises: sending a first request to a second network function; the first request is used to request user authentication of a first user using a first user equipment (UE); receiving a first response sent by the second network function; the first response is used to indicate whether the user authentication of the first user passes.

[0043] Based on the above scheme, the wireless communication network can perform user authentication of a user using a first UE (first user), so that when one UE is used by multiple users, the specific user can be authenticated respectively, and the security of the use of the first UE and / or the control and charging based on the user are ensured.

[0044] In some embodiments of the first aspect, the method further includes: receiving a second request sent by the first UE; the second request is used by the first UE to request user authentication of the first user; sending the first request to the second network function, including: sending the first request to the second network function according to the second request; sending a second response to the first UE according to the first response; the second response is used to indicate whether the first user passes the user authentication.

[0045] Based on the above solution, the first network function initiates user authentication for the first user after receiving the second request from the first UE. In this way, the first UE can trigger the second network function to perform user authentication by sending the second request.

[0046] In some embodiments of the first aspect, the second request includes first information; the first information includes at least one of the following: user identity information of the first user; first authentication information; first authentication information, used for user authentication of the first user; indication information of the authentication method; authentication method used for user authentication of the first user; first subscription identifier, the first subscription identifier is used to identify the first UE; service identifier, used to indicate the service accessed by the first user using the first UE; network slice information, used to indicate the network slice accessed by the first user using the first UE.

[0047] The above solution limits the information content of the second request, so that subsequent flexible selection can be made according to specific scenarios.

[0048] In some of the first aspect, at least a portion of the first information is protected by a first credential; and the second request includes the portion of the first information protected by the first credential.

[0049] The above solution uses the first credential to participate in the user authentication of the first user, and has the characteristic of being easy to implement.

[0050] In some embodiments of the first aspect, the user identity information and / or the first authentication information of the first user is protected by a first credential.

[0051] Based on the above solution, using the first credential to protect the user identity information and / or authentication information can ensure that certain information for user authentication is carried in plain text and protected, thereby simplifying the user authentication of the first user.

[0052] In some embodiments of the first aspect, the method further includes: sending a first indication to the first UE; the first indication is used to instruct the first UE to initiate user authentication for the first user.

[0053] Based on the above solution, by sending the first indication, the first network function can provide the first UE with authentication information for participating in the first user authentication, thereby improving the security of the user authentication of the first user itself.

[0054] In some embodiments of the first aspect, the first indication comprises at least one of:

[0055] indication information of an authentication manner, the authentication manner being used for user authentication of the first user;

[0056] a service identifier, used to indicate a service accessed by the first user using the first UE;

[0057] network slice information, used to indicate a network slice accessed by the first user using the first UE;

[0058] second authentication information, used to instruct the first UE to perform user authentication of the first user.

[0059] In some embodiments of the first aspect, the method further comprises:

[0060] receiving a third request sent by the first UE, the third request comprising user identity information of the first user;

[0061] determining, according to the third request, whether to perform user authentication of the first user;

[0062] sending, to the first UE, the first indication, comprising: sending, to the first UE, the first indication in response to performing user authentication of the first user.

[0063] Based on the above scheme, after receiving the first indication, the first UE can send a second request according to actual needs such as whether the first user continues to use the first UE, to formally trigger the network side to perform user authentication of the first user.

[0064] In some embodiments of the first aspect, the method further comprises:

[0065] sending, to the first UE, a third response according to whether to perform user authentication of the first user;

[0066] the third response indicates acceptance or rejection of the third request;

[0067] when the third response indicates rejection of the third request, it represents that user authentication of the first user fails or the first network function determines not to perform user authentication of the first user; and / or, when the third response indicates acceptance of the third request, it represents that the first network function determines to perform user authentication of the first user and the authentication of the first user passes; or,

[0068] the third response is irrelevant to user authentication of the first user.

[0069] Based on the above scheme, in some cases, the third response is related to user authentication of the first user, and in other cases, the third response is irrelevant to user authentication of the first user, which can be flexibly set according to user authentication scenarios in specific authentication processes.

[0070] In some embodiments of the first aspect, the method further comprises: the first response indicates that the first user passes the user authentication, and the user identity information of the first user is associated with the first subscription identifier of the first UE. Based on the above scheme, in the user authentication process, the user identity information of the first user is associated with the first subscription identifier, which facilitates subsequent user authentication of the first user.

[0071] The second aspect provides a user authentication method, wherein the method is performed by a second network function, and the method comprises: receiving a first request sent by a first network function; the first request is used to request user authentication of a first user of a first UE; performing user authentication on the first user; and sending a first response to the first network function or the first UE according to a result of the user authentication.

[0072] In some embodiments of the second aspect, the first request comprises at least one of: user identity information of the first user; first authentication information; the first authentication information is used for user authentication of the first user; indication information of an authentication manner; the authentication manner is used for user authentication of the first user; a first subscription identifier, the first subscription identifier is used to identify the first UE; a service identifier, the service identifier is used to indicate a service accessed by the first user using the first UE; and network slice information, the network slice information is used to indicate a network slice accessed by the first user using the first UE.

[0073] In some embodiments of the second aspect, at least part of the first request is protected by a first credential used by the first UE; the user authentication of the first user comprises: verifying the first request based on a second credential; and determining whether the user authentication of the first user passes based on whether the first request passes the verification.

[0074] In some embodiments of the second aspect, the user identity information of the first user and / or the first authentication information is protected by the first credential.

[0075] In some embodiments of the second aspect, the determining whether the user authentication of the first user passes based on whether the first request passes the verification comprises at least one of: when the first request does not pass the verification, determining that the user authentication of the first user does not pass; and when the first request passes the verification, determining that the user authentication of the first user passes.

[0076] In some embodiments of the second aspect, the method further comprises: determining the second credential based on the user identity information of the first user carried in the first request in plaintext.

[0077] In some embodiments of the second aspect, the performing user authentication on the first user comprises: sending a fourth request to a third network function; the fourth request is used to request the third network function to perform user authentication on the first user; receiving a fourth response sent by the third network function; and the fourth response is used to indicate whether the user authentication of the first user passes.

[0078] In some embodiments of the second aspect, the fourth request comprises second information; the second information comprises at least one of: user identity information of the first user; authentication information of the first user; authentication information used for user authentication of the first user; indication information of an authentication manner; the authentication manner used for user authentication of the first user; a first subscription identifier, the first subscription identifier used for identifying the first UE; a service identifier, the service identifier used for indicating a service accessed by the first user using the first UE; network slice information, the network slice information used for indicating a network slice accessed by the first user using the first UE.

[0079] In some embodiments of the second aspect, at least part of the second information is protected by the first credential.

[0080] In some embodiments of the second aspect, the user identity information of the first user and / or the first authentication information is protected by the first credential.

[0081] The third aspect provides a user authentication method, wherein the method is performed by a third network function, and the method comprises: receiving a fourth request sent by a second network function; the fourth request is used for requesting the third network function to perform user authentication on a first user using a first user equipment (UE); performing user authentication on the first user; and sending a fourth response to the second network function according to a result of the user authentication; the fourth response is used for indicating whether the user authentication of the first user passes.

[0082] In some embodiments of the third aspect, the fourth request comprises second information; the second information comprises at least one of: user identity information of the first user; authentication information of the first user; authentication information used for user authentication of the first user; indication information of an authentication manner; the authentication manner used for user authentication of the first user; a first subscription identifier, the first subscription identifier used for identifying the first UE; a service identifier, the service identifier used for indicating a service accessed by the first user using the first UE; network slice information, the network slice information used for indicating a network slice accessed by the first user using the first UE.

[0083] In some embodiments of the third aspect, at least part of the second information is protected by the first credential.

[0084] In some embodiments of the third aspect, the user identity information of the first user and / or the first authentication information is protected by the first credential.

[0085] In some embodiments of the third aspect, performing user authentication on the first user comprises: verifying the fourth request based on a second credential; and determining whether the user authentication of the first user passes according to whether the fourth request passes the verification.

[0086] In some embodiments of the third aspect, determining whether the user authentication of the first user passes or not is based on whether the fourth request passes or not the verification, including at least one of: the fourth request fails the verification, determining that the user authentication of the first user fails; the fourth request passes the verification, determining that the user authentication of the first user passes.

[0087] The fourth aspect provides a method for user authentication, wherein the method is performed by a first user equipment (UE), and the method comprises:

[0088] sending a second request to a first network function; the second request is used for the first UE to request the user authentication of the first user;

[0089] receiving a second response sent by the first network function; the second response is used for indicating whether the first user passes the user authentication or not.

[0090] In some embodiments of the fourth aspect, the method further comprises:

[0091] receiving a first indication sent by the first network function; the first indication is used for indicating that the first UE initiates the user authentication of the first user.

[0092] In some embodiments of the fourth aspect, the first indication comprises at least one of: indication information of an authentication manner, the authentication manner being used for the user authentication of the first user; a service identity, used for indicating a service accessed by the first user using the first UE; network slice information, used for indicating a network slice accessed by the first user using the first UE; and second authentication information, used for indicating that the first UE performs the user authentication of the first user.

[0093] In some embodiments of the fourth aspect, sending the second request to the first network function comprises: sending the second request to the first network function according to first information; at least part of the first information is protected by a first credential used by the first UE.

[0094] In some embodiments of the fourth aspect, the user identity information of the first user and / or the first authentication information in the first information are protected by the first credential.

[0095] In some embodiments of the fourth aspect, the method further comprises:

[0096] sending a third request to the first network function; the third request comprises user identity information of the first user; receiving a third response sent by the first network function; the third response is related to the user authentication of the first user, then: when the third response indicates rejecting the third request, it represents that the user authentication of the first user fails or the first network function determines not to perform the user authentication of the first user; and / or, when the third response indicates accepting the third request, it represents that the first network function determines to perform the user authentication of the first user and the user authentication of the first user passes; or, the third response is not related to the user authentication of the first user.

[0097] A fifth aspect provides a first network function, wherein the first network function comprises:

[0098] a sending module configured to send a first request to a second network function; the first request is used to request user authentication of a first user using a first user equipment (UE);

[0099] a receiving module configured to receive a first response sent by the second network function; the first response is used to indicate whether the user authentication of the first user is passed.

[0100] A sixth aspect provides a second network function, wherein the second network function comprises:

[0101] a receiving module configured to receive a first request sent by a first network function; the first request is used to request user authentication of a first user of a first UE;

[0102] a processing module configured to perform the user authentication of the first user;

[0103] a sending module configured to send a first response to the first network function or the first UE according to a result of the user authentication.

[0104] A seventh aspect provides a third network function, wherein the third network function comprises:

[0105] a receiving module configured to receive a fourth request sent by a second network function; the fourth request is used to request the third network function to perform user authentication of a first user using a first user equipment (UE);

[0106] a processing module configured to perform the user authentication of the first user;

[0107] a sending module configured to send a fourth response to the second network function according to a result of the user authentication; the fourth response is used to indicate whether the user authentication of the first user is passed.

[0108] An eighth aspect provides a first user equipment (UE), wherein the first UE comprises:

[0109] a sending module configured to send a second request to a first network function; the second request is used for the first user equipment (UE) to request user authentication of a first user;

[0110] a receiving module configured to receive a second response sent by the first network function; the second response is used to indicate whether the first user is passed the user authentication.

[0111] A ninth aspect provides a communication system, comprising:

[0112] The first network function is configured to perform the method provided in any of the technical solutions of the first aspect.

[0113] The second network function is configured to perform the method provided in any of the technical solutions of the second aspect.

[0114] The third network function is configured to perform the method provided in any of the technical solutions of the third aspect.

[0115] The first user equipment (UE) is configured to perform the method provided in any of the technical solutions of the fourth aspect.

[0116] In a tenth aspect, the present disclosure provides a communication device, comprising: one or more processors; wherein the processor is configured to invoke instructions to cause the communication device to perform the user authentication method described in the optional implementation manners of the first aspect to the fourth aspect.

[0117] In an eleventh aspect, the present disclosure provides a storage medium, wherein the storage medium stores instructions, when the instructions are executed on a communication device, causing the communication device to perform the user authentication method described in the optional implementation manners of the first aspect to the fourth aspect.

[0118] In a twelfth aspect, the present disclosure provides a program product, when executed by a communication device, causing the communication device to perform the user authentication method described in the optional implementation manners of the first aspect to the fourth aspect. Illustratively, according to an embodiment of the present disclosure, a program product is provided, comprising a computer program, when the computer program is executed by a communication device, causing the communication device to perform the user authentication method provided in any of the first aspect to the fourth aspect.

[0119] In a thirteenth aspect, the present disclosure provides a computer program, when executed on a computer, causing the computer to perform the user authentication method described in the optional implementation manners of the first aspect to the fourth aspect.

[0120] It can be understood that the terminal, network function, and communication system, program product, and computer program described above are all configured to perform the method provided by the present disclosure. Therefore, the beneficial effects that can be achieved thereby can refer to the beneficial effects in the corresponding method, which will not be described herein again.

[0121] The present disclosure proposes a user authentication method, a communication device, a communication system, and a storage medium. The present disclosure is not exhaustive and is only a partial illustration, and is not a specific limitation on the protection scope of the present disclosure. Each step in a certain embodiment can be implemented independently, and the steps can be combined arbitrarily, for example, a mode in which part of the steps is removed can also be implemented independently, and the order of the steps in a certain embodiment can be arbitrarily exchanged, in addition, the optional implementation mode in a certain embodiment can be arbitrarily combined; in addition, each of the embodiments can be combined arbitrarily, for example, different parts or all steps can be combined arbitrarily, and a certain embodiment can be combined with other optional implementation modes.

[0122] In each of the present disclosure, the terms and / or descriptions between each are consistent if there is no special description and logical conflict, and can be referred to each other, and the technical features in different embodiments can be combined to form new ones according to their inherent logical relationship.

[0123] The terms used in the present disclosure are only for the purpose of describing a specific purpose, and not as a limitation on the present disclosure.

[0124] In the present disclosure, unless otherwise specified, elements expressed in singular form, such as "one", "a", "the", "above", "preceding", "this", etc., can represent "one and only one", or "one or more", "at least one", etc. For example, in the case of using articles such as "a", "an", "the" in English, the noun after the article can be understood as singular expression, or as plural expression.

[0125] In the present disclosure, "plurality" means two or more.

[0126] In some embodiments, the terms "at least one of", "one or more", "a plurality of", "multiple", and the like can be replaced with each other.

[0127] In some embodiments, the writing manner of "at least one of A, B", "A and / or B", "A in one case and B in another case", "one case A and another case B", and the like can include the following technical manners according to the case: in some embodiments, A is executed independently of B; in some embodiments, B is executed independently of A; in some embodiments, A and B are selectively executed (A and B are selectively executed); in some embodiments, A and B are executed (A and B are executed). When there are more branches of A, B, C, etc., it is similar to the above.

[0128] In some embodiments, the expression "A or B" or the like can include the following technical manners according to the situation: in some embodiments, A is executed regardless of B; in some embodiments, B is executed regardless of A; in some embodiments, A and B are selectively executed. When there are more branches such as A, B, C, and the like, the above description is similar.

[0129] In the present disclosure, the prefix words "first", "second", and the like are only used to distinguish different description objects, and do not constitute limitations on the position, order, priority, quantity, or content of the description objects. The description of the description objects should be referred to the description in the claims or the context above and below, and should not be considered as redundant limitations because of the use of the prefix words. For example, the description object is "field", and the ordinal words before "field" in "first field" and "second field" do not limit the position or order between "fields". "First" and "second" do not limit whether the "fields" they modify are in the same message, nor do they limit the order of "first field" and "second field". For another example, the description object is "level", and the ordinal words before "level" in "first level" and "second level" do not limit the priority between "levels". For another example, the quantity of the description object is not limited by the ordinal words, and can be one or more. For example, "first device", where the quantity of "device" can be one or more. In addition, the objects modified by different prefix words can be the same or different. For example, the description object is "device", and "first device" and "second device" can be the same device or different devices, and their types can be the same or different. For another example, the description object is "information", and "first type of information" and "second type of information" can be the same information or different information, and their contents can be the same or different.

[0130] In some embodiments, "including A", "containing A", "for indicating A", "carrying A" can be interpreted as directly carrying A, or indirectly indicating A.

[0131] In some embodiments, the terms "…", "determining …", "in the case of …", "when …", "when …", "if …", and the like can be replaced with each other.

[0132] In some embodiments, the terms "greater than", "greater than or equal to", "not less than", "more than", "more than or equal to", "not less than", "higher than", "higher than or equal to", "not lower than", "above", and the like can be replaced with each other. The terms "less than", "less than or equal to", "not greater than", "less than", "less than or equal to", "not more than", "lower than", "lower than or equal to", "not higher than", "below", and the like can be replaced with each other.

[0133] In some embodiments, an apparatus or the like can be interpreted as an entity, and can also be interpreted as virtual, and the name thereof is not limited to the name recited in the specification, and the terms "apparatus", "equipment", "device", "circuit", "network element", "node", "function", "unit", "section", "system", "network", "chip", "chip system", "entity", "subject" and the like can be replaced with each other.

[0134] In some embodiments, a "network" can be interpreted as an apparatus (for example, an access network device, a core network device, and the like) included in the network.

[0135] In some embodiments, the terms "access network device (AN device)", "radio access network device (RAN device)", "base station (BS)", "radio base station", "fixed station", "node", "access point", "transmission point (TP)", "reception point (RP)", "transmission / reception point (TRP)", "panel", "antenna panel", "antenna array", "cell", "macro cell", "small cell", "femto cell", "pico cell", "sector", "cell group", "serving cell", "carrier", "component carrier", "bandwidth part (BWP)" and the like can be replaced with each other.

[0136] In some embodiments, the terms "terminal," "terminal device," "user equipment (UE)," "user terminal," "mobile station (MS)," "mobile terminal (MT)," "subscriber station," "mobile unit," "subscriber unit," "wireless unit," "remote unit," "mobile device," "wireless device," "wireless communication device," "remote device," "mobile subscriber station," "access terminal," "mobile terminal," "wireless terminal," "remote terminal," "handset," "user agent," "mobile client," "client," and so on can be replaced with each other.

[0137] In some embodiments, an access network device, a core network device, or a network device can be replaced with a terminal. For example, the structures of the present disclosure can also be applied to a structure in which communication between an access network device, a core network device, or a network device and a terminal is replaced with communication between a plurality of terminals (e.g., device-to-device (D2D), vehicle-to-everything (V2X), or the like). In this case, the terminal can also be configured to have all or part of the functions of the access network device. In addition, the terms "uplink," "downlink," and the like can also be replaced with terms corresponding to the inter-terminal communication (e.g., "side"). For example, an uplink channel, a downlink channel, and the like can be replaced with a side channel, and an uplink, a downlink, and the like can be replaced with a sidelink.

[0138] In some embodiments, a terminal can be replaced with an access network device, a core network device, or a network device. In this case, the access network device, the core network device, or the network device can also be configured to have all or part of the functions of the terminal.

[0139] In some embodiments, the data, information, etc. can be obtained in compliance with the laws and regulations of the country where the location is situated.

[0140] In some embodiments, the data, information, etc. can be obtained after obtaining the consent of the user.

[0141] In addition, each element, each row, or each column in the table of the present disclosure can be implemented independently, and any combination of any element, any row, or any column can also be implemented independently.

[0142] FIG. 1 is a schematic diagram of an architecture of a communication system according to the present disclosure.

[0143] As shown in FIG. 1, the communication system 100 includes a terminal 101 and a network device 102. The network device 102 can include an access network device and / or a core network device.

[0144] In some embodiments, the terminal 101 includes at least one of a mobile phone, a wearable device, an Internet of Things device, a communication-capable automobile, a smart automobile, a Pad, a computer with wireless transceiver function, a virtual reality (VR) terminal device, an augmented reality (AR) terminal device, a wireless terminal device in industrial control, a wireless terminal device in self-driving, a wireless terminal device in remote medical surgery, a wireless terminal device in a smart grid, a wireless terminal device in transportation safety, a wireless terminal device in a smart city, a wireless terminal device in a smart home, etc., but is not limited thereto.

[0145] In some embodiments, the terminal is also referred to as a user equipment (UE).

[0146] In some embodiments, the access network device may, for example, be at least one of a node or a device that accesses a terminal to a wireless network, and the access network device may include at least one of an evolved node B (eNB) in a 5G communication system, a next generation eNB (ng-eNB), a next generation node B (gNB), a node B (NB), a home node B (HNB), a home evolved node B (HeNB), a wireless backhaul device, a radio network controller (RNC), a base station controller (BSC), a base transceiver station (BTS), a base band unit (BBU), a mobile switching center, a base station in a 6G communication system, an open base station (Open RAN), a cloud base station (Cloud RAN), a base station in other communication systems, an access node in a Wi-Fi system, but is not limited thereto.

[0147] In some embodiments, the technical means of the present disclosure can be applicable to an Open RAN architecture, at which time the interfaces between or within the access network devices involved in the present disclosure can become internal interfaces of the Open RAN, and the processes and information interactions between these internal interfaces can be implemented through software or programs.

[0148] In some embodiments, the access network device can be composed of a central unit (CU) and a distributed unit (DU), where the CU can also be referred to as a control unit. The CU-DU structure can split the protocol layers of the access network device, and some of the protocol layers are controlled by the CU, and the rest or all of the protocol layers are distributed in the DU and controlled by the CU, but is not limited thereto.

[0149] In some embodiments, the core network device can be one device including the first network element, etc., or a plurality of devices or device groups each including the first network element. The network element can be virtual or physical. The core network may, for example, include at least one of an evolved packet core (EPC), a 5G core network (5GCN), and a next generation core (NGC).

[0150] It can be understood that the communication system described in the present disclosure is for more clearly illustrating the technical means of the present disclosure, and does not constitute a limitation on the technical means provided by the present disclosure. It can be known by those skilled in the art that, as the system architecture evolves and new business scenarios appear, the technical means provided by the present disclosure are also applicable to similar technical problems.

[0151] The following disclosure can be applied to the communication system 100 shown in FIG. 1 or part of the subject, but is not limited thereto. The subjects shown in FIG. 1 are illustrative, and the communication system can include all or part of the subjects in FIG. 1, or other subjects other than FIG. 1. The number and form of each subject is arbitrary, the connection relationship between each subject is illustrative, each subject can be connected or not connected, and the connection can be in any way, can be direct connection or indirect connection, can be wired connection or wireless connection.

[0152] Each of the present disclosure can be applied to Long Term Evolution (LTE), LTE-Advanced (LTE-A), LTE-Beyond (LTE-B), SUPER 3G, IMT-Advanced, 4th generation mobile communication system (4G), 5th generation mobile communication system (5G), 5G new radio (NR), Future Radio Access (FRA), New-Radio Access Technology (RAT), New Radio (NR), New radio access (NX), Future generation radio access (FX), Global System for Mobile communications (GSM (registered trademark)), CDMA2000, Ultra Mobile Broadband (UMB), IEEE 802.11 (Wi-Fi (registered trademark)), IEEE 802.16 (WiMAX (registered trademark)), IEEE 802.20, Ultra-WideBand (UWB), Bluetooth (Bluetooth (registered trademark)), Public Land Mobile Network (PLMN) network, Device-to-Device (D2D) system, Machine to Machine (M2M) system, Internet of Things (IoT) system, Vehicle-to-Everything (V2X), system using other resources, next-generation system extended based thereon, and the like. In addition, a plurality of systems can be combined (for example, combination of LTE and NR).

[0153] Previously, mobile networks were user-centric, one user could typically use one or more communication devices such as a mobile phone and sign up with a carrier and use some services of the carrier based on the subscription, for example, a call service and / or a Short Message Service (SMS).

[0154] Nowadays, a user can have different kinds of devices, such as a mobile phone, a tablet computer and / or a notebook computer. Some devices are owned by one user only, and some devices can be shared by multiple users. How to ensure the security of the use of these devices is a problem to be solved urgently. In view of this, as shown in FIG. 2, the present disclosure provides a user authentication method, wherein the method is performed by the communication system shown in FIG. 1. The method can include:

[0155] S2101: The first UE sends a third request to the first network function.

[0156] In some embodiments, the first UE can be any UE accessing to a mobile network.

[0157] In some embodiments, the first network function can include, but is not limited to, a core network function. Exemplarily, the core network function includes, but is not limited to, an access management function, a mobility management entity, a security anchor function (SEAF) and / or a user data management.

[0158] In some embodiments, the third request can be any request containing user identity information of the first user.

[0159] In some embodiments, the third request can be used to request or trigger user authentication of the first user.

[0160] In some embodiments, the third request at least includes user identity information of the first user.

[0161] In some embodiments, the user identity information can include, but is not limited to, a user identifier. The user identifier includes, but is not limited to, a user layer identifier, a user identity information distributed by a government department and / or a device identifier of a non-subscription device, etc. The non-subscription device is a device that has not signed a contract with the communication operator shown in FIG. 1.

[0162] In some embodiments, the third request can be a registration request of the first UE. The registration request can be used for the first UE to request registration to the network. In some embodiments, the third request can also include a request of tracking area update, radio notification area update of the first UE, or a user authentication request or a service request of the first user using the first UE.

[0163] In some embodiments, the third request includes at least one of the following:

[0164] a first subscription identifier, the first subscription identifier being used to identify the first UE;

[0165] capability information; the capability information being used to indicate to the first network function whether the first UE and / or the first device supports user authentication;

[0166] The first UE is a UE used by the first user; the first device is a device associated with the first UE.

[0167] In some embodiments, the first subscription identifier can be an identifier assigned by the communication operator when the first UE subscribes to the communication operator, or an identifier derived from the identifier assigned by the communication operator. In some embodiments, the first subscription identifier includes, but is not limited to, a subscriber concealed identifier (SUCI), a subscriber permanent identifier (SUPI), or a generic public subscription identifier (GPSI).

[0168] In some embodiments, the capability information can be at least a capability possessed by the first UE and / or the first device. In some embodiments, the capability information can be at least a capability subscribed by the first UE and / or the first device.

[0169] In some embodiments, the capability information can indicate whether the first UE and / or the first device supports user authentication and / or one or more user authentication methods that can be supported.

[0170] In some embodiments, the association relationship between the first UE and the first device can be embodied in at least one of the following:

[0171] The first UE can be a gateway UE of the first device; for example, the first UE can be a home gateway UE of the first device, or the first UE can be a hotspot device of the first device.

[0172] The first UE and the first device can have a binding relationship, for example, a smart watch and / or a mobile phone of the same user have a binding relationship.

[0173] In some embodiments, the first user can be a user currently using the first device and / or the first UE, in which case the first user can be a device or a user using the first device, and in this case the first user is equivalent to a user currently indirectly using the first UE.

[0174] In some embodiments, the first user can be a user currently directly using the first UE. For example, the first UE is a shared device, and the first UE can be used by multiple users (persons), and in this case the first user corresponds to a person.

[0175] In some embodiments, the first device can be a non-subscription device or a non-3GPP device, etc.

[0176] In some embodiments, the first UE can send the third request to the first network function through a non-access layer message, or can send the third request to the first network function based on a manner of calling a standardized service.

[0177] S2102: The first network function determines whether and / or how to perform the user authentication of the first user.

[0178] In some embodiments, the determination of whether and / or how to perform the user authentication of the first user is based on the user configuration information and / or the local information.

[0179] In some embodiments, the user configuration information can include, but is not limited to, at least one of the following:

[0180] User identity information of the first user;

[0181] A first subscription identifier, which is used to identify the first UE;

[0182] State information, which indicates whether the configuration information is activated;

[0183] A second subscription identifier;

[0184] Information of a third device;

[0185] An authentication policy, which indicates an optional authentication manner for identity authentication of the first user;

[0186] Second information, which indicates whether the first UE and / or the first device supports the user authentication;

[0187] User authentication conditions, which indicate conditions for identity authentication of the first user.

[0188] Of course, the above is only an example of the user configuration information.

[0189] In some embodiments, if the SUCI of the first UE is carried in the third request, the first network function can convert the SUCI into the SUPI.

[0190] In some embodiments, the local information can include, but is not limited to, a local configuration policy and / or a network planning parameter of the first network function and / or a historical authentication record of the first user cached by the first network function. In some embodiments, the local configuration policy can be a rule and / or a policy configured by an operation management and maintenance server of a communication operator on the first network function. The network planning parameter can be a parameter configured by the network when deployed.

[0191] In some embodiments, if the user configuration information is used to determine whether and / or how to perform the user authentication of the first user, the method can include:

[0192] The fourth network function sends the user configuration information.

[0193] In some embodiments, the fourth network function actively pushes the updated user configuration information to the first network function when it is detected that the user configuration information of at least one user is updated.

[0194] In some embodiments, the fourth network function sends a request for user configuration information to the first network function and receives the user configuration information sent by the fourth network function based on the request for user configuration information.

[0195] In some embodiments, the request for user configuration information is used for the first network function to request the user configuration of the first user.

[0196] In some embodiments, if the first network function locally stores the user configuration information of the first user, the first network function does not need to temporarily request the user configuration information from the fourth network function.

[0197] In some embodiments, the second request can include, but is not limited to, at least one of the following:

[0198] User identity information of the first user;

[0199] First subscription identifier.

[0200] In some embodiments, there are multiple optional ways to determine whether to perform user authentication on the first user according to the user configuration information, which can include, but are not limited to, any one of the following:

[0201] Way 1:

[0202] Whether the user configuration information of the first user is activated, determine whether to perform user authentication on the first user.

[0203] In some embodiments, if the user configuration information of the first user is not activated, it is determined not to perform user authentication on the first user; and / or, if the user configuration information of the first user is activated, it is determined to perform user authentication on the first user.

[0204] For example, the user configuration information is configured with a state and at least the state of the user configuration information by the state information, so that the fourth network function can provide the user configuration information of any state to the first network function and the user configuration information includes the state information, so that the first network function will receive the user configuration information and the state information from the fourth network function, and determine whether the corresponding user configuration information is activated according to the state information.

[0205] For another example, the user configuration information is configured with a state and at least its state by the state information, so that the fourth network function can only provide the user configuration information of the activated state to the first network function. If a certain user configuration information is not activated, the first network function cannot receive the corresponding user configuration information from the fourth network function, at this time the first network function can determine whether the corresponding user configuration information is activated according to whether the corresponding user configuration information is successfully received.

[0206] It is worth noting that in some cases, the first network function can also determine whether to perform user authentication on the first user according to whether the first user has user configuration information. For example, the first network function fails to obtain the user configuration information of the first user or the user configuration information is incorrect, and it can be considered that the corresponding user is not subjected to user authentication. For another example, the first network function successfully obtains the user configuration information of the first user, and performs user authentication on the first user according to the obtained user configuration information. In this way, the illegal use of the first UE by illegal users who do not submit user information and / or submit incorrect user information can be reduced, and the use security of the first UE can be improved.

[0207] Method 2:

[0208] According to whether the first subscription identifier can identify the second device, it is determined whether to perform user authentication on the first user.

[0209] In some embodiments, the first subscription identifier is used to identify a first UE used by the first user.

[0210] In some embodiments, the first subscription identifier can include but is not limited to SUCI and / or SUPI. The second subscription identifier can include but is not limited to SUPI.

[0211] In some embodiments, the second subscription identifier or the second device identifier of the second device is recorded in the user configuration information.

[0212] In some embodiments, the second subscription identifier is a subscription identifier for which the first user has subscribed to use the second device, and / or the second subscription identifier is a subscription identifier of the second device corresponding to the first user and having passed network access verification.

[0213] For example, according to whether the first subscription identifier matches the second subscription identifier recorded in the user configuration information, it is determined whether to perform user authentication on the first user. In this way, the UE or device identified by the second subscription identifier can be a device that the first user subscribes to use in advance. The second subscription identifier can also be a UE and / or device identifier actively collected by the network according to the historical use and / or historical user authentication of the first user to the mobile network.

[0214] In some embodiments, when the first subscription identifier matches the second subscription identifier, it is determined to perform user authentication on the first user; and / or when the first subscription identifier does not match the second subscription identifier, it is determined not to perform user authentication on the first user.

[0215] In some embodiments, the first subscription identifier can include but is not limited to SUCI and / or SUPI. The second subscription identifier can include but is not limited to SUPI.

[0216] Method 3:

[0217] determining whether to perform user authentication for the first user according to whether the first device identity can identify the third device.

[0218] In some embodiments, the device identity of the third device is recorded in the user configuration information.

[0219] In some embodiments, the third device can be a device that the first user is allowed to use.

[0220] In some embodiments, the third device can be a device that the first user is allowed to use according to the subscription information and / or the device usage policy.

[0221] In some embodiments, the third device can be one or more. In some embodiments, the third device can also be a set of devices. The device identities in the set of devices can be continuous. The user configuration information can record two specific device identities in the set of devices, for example, the minimum device identity and / or the maximum device identity. In this way, the third device identity can be the minimum device identity, the maximum device identity, or any device identity between the minimum device identity and the maximum device identity. For example, in an office scenario, a company or a group can sign a contract with a communication operator for multiple office UEs, which have continuous numbered device identities. Employees can use their employee numbers as user identity information to use these office devices. In this way, authentication of the employee number of the employee is one of the user authentication in the embodiments of the present disclosure.

[0222] In this scenario, if the number of third devices that the first user can use is zero, it can be considered that it is determined not to perform user authentication for the first user. If the number of third devices that the first user can use is greater than zero, it is determined whether and / or how to perform user authentication for the first user according to whether the first device identity and the third device identity match.

[0223] In some embodiments, determining whether to perform user authentication for the first user according to whether the first device identity can identify the third device comprises at least one of the following: determining to perform user authentication for the first user according to that the first device identity can identify the third device; determining not to perform user authentication for the first user according to that the first device identity cannot identify the third device.

[0224] Method 4:

[0225] determining whether to perform user authentication for the first user according to whether the user configuration information records an authentication policy for user authentication.

[0226] In some embodiments, the authentication policy can be configured by a core network function, an operation management and maintenance server, and / or a service server.

[0227] In some embodiments, the authentication policy is used by the first network function to determine whether to perform user authentication for the first user, and / or the manner of authentication for the first user.

[0228] In some embodiments, the user profile information records the authentication policy for user authentication, and it is determined to perform user authentication for the first user; and / or the user profile information does not record the authentication policy for user authentication, and it is determined not to perform user authentication for the first user.

[0229] In some embodiments, the authentication policy indicates to perform user authentication for the first user, and it is determined to perform user authentication for the first user; and / or the authentication policy indicates not to perform user authentication for the first user, and it is determined not to perform user authentication for the first user.

[0230] Option 5:

[0231] It is determined whether to perform user authentication for the first user according to whether the first UE and / or the first device supports user authentication.

[0232] In some embodiments, the first UE and / or the first device supports user authentication, and it is determined to perform user authentication for the first user; and / or the first UE and the first device do not support user authentication, and it is determined not to perform user authentication for the first user.

[0233] In some embodiments, it is determined whether the first UE and / or the first device supports user authentication according to the first information sent by the first UE; the first information includes capability information of the first UE and / or capability information of the first device.

[0234] For example, in the case of receiving the first information, the second information recorded in the user profile is ignored, and it is directly determined whether the first UE and / or the first device supports user authentication according to the first information.

[0235] In some embodiments, in the case of not receiving the first information, it is determined whether the first UE and / or the first device supports user authentication according to the second information of the user profile information; the second information is used to indicate the capability of the first UE and / or the first device.

[0236] In some embodiments, whether the first information is received or not, it is directly determined whether the first UE and / or the first device supports user authentication according to the second information in the user profile information.

[0237] In some embodiments, when the first information is obtained and the second information is recorded in the user configuration information, it is determined whether the first UE and / or the first device supports user authentication according to the first information. Here, the first information can be first information sent by the first UE and / or the first device according to local device settings, or can be dynamically generated according to user interface detection of user operation. In one case of the present disclosure, the priority of the first information is higher than that of the second information. In another case, when the first information is obtained and the second information is recorded in the user configuration information, if both the first information and the second information indicate that at least one of the first UE and the first device supports user authentication, it is determined that the first UE and / or the first device supports user authentication, otherwise it is determined that neither the first UE nor the first device supports user authentication. In some embodiments, when the second information of the user configuration information indicates that at least one of the first UE and the first device supports user authentication, it is finally determined whether the first UE and / or the first device supports user authentication according to the first information.

[0238] In some embodiments, the first information can be information temporarily obtained by the first network function from the first UE after receiving the third request, or can be information carried in the third request.

[0239] The above is only an example of whether the first network function performs user authentication on the first user, and the specific implementation is not limited to the above example.

[0240] There are various ways to determine the authentication mode of the first user when it is determined to perform user authentication on the first user, and the specific implementation is not limited to any of the above.

[0241] For example, determining to perform user authentication on the first user and determining the authentication mode of the first user can include, but is not limited to, at least one of the following:

[0242] Determining the authentication mode of the first user according to the user configuration information;

[0243] Determining the authentication mode of the first user according to local information of the first network function.

[0244] In some embodiments, the authentication manner can be one of any extended authentication protocol (EAP) authentication. For example, the alternative authentication manners of the user authentication can include, but are not limited to, Extented Authentication Protocol-Message Digest Algorithm 5 (EAP-MD5), Extented Authentication Protocol-Pre-shared key (EAP-PSK), Extented Authentication Protocol-Transport Layer Security (EAP-TLS), Extented Authentication Protocol-Lightweight Extensible Authentication (EAP-LEAP), and Extented Authentication Protocol-Protected Extensible Authentication (EAP-PEAP). The above are only examples of EAP authentication, and the specific implementation is not limited to any of the above examples.

[0245] For example, the authentication manner of the user authentication can also be distinguished according to whether the authentication device needs to request third-party authentication. For example, when the third-party authentication is needed, the second network function needs to interact with the server of the third-party authentication to obtain the user authentication result. If the third-party is not needed to participate in the authentication, the second network function can complete the user authentication of the first user by itself. For example, the server of the third-party authentication can include, but is not limited to, an authentication, authorization and accounting (AAA) server.

[0246] In some embodiments, the second network function can be various core network functions capable of identity authentication, exemplarily, the core network function can include but is not limited to an authentication server function (AUSF), a UDM, a user authentication and authorization function (UAAF), and / or a user information management function (UIMF).

[0247] In some embodiments, it is determined to perform user authentication on the first user, and the authentication manner for the first user is determined according to the user configuration information of the first user.

[0248] In some embodiments, it is determined not to perform user authentication on the first user, and there is no need to determine the authentication manner for the first user.

[0249] In some embodiments, the first user is authenticated by default, in which case, it can be directly determined whether the first user needs to be authenticated, and the authentication manner for the first user is directly determined.

[0250] In some embodiments, the above-mentioned manners 1 to 5 can be used alone or in combination.

[0251] Exemplarily, when each of the determination results obtained according to the manners 1 to 5 determines that the first user needs to be authenticated, it is determined that the first user needs to be authenticated, otherwise, when any one of the manners 1 to 5 determines that the first user does not need to be authenticated, it is determined that the first user does not need to be authenticated.

[0252] Exemplarily, when each of the determination results obtained according to the manners 1 and 5 determines that the first user needs to be authenticated, when any one of the determination results obtained according to the manners 2 to 4 determines that the first user needs to be authenticated, it is determined that the first user needs to be authenticated. And / or, when each of the determination results obtained according to the manners 1 and 5 determines that the first user needs to be authenticated, when none of the determination results obtained according to the manners 2 to 4 determines that the first user needs to be authenticated, it is determined that the first user does not need to be authenticated.

[0253] S2103: The first network function sends the first indication to the first UE.

[0254] In some embodiments, the first network function determines to perform user authentication for the first user, and sends the first indication to the first UE. In this case, the first indication is used to directly or indirectly instruct the first UE to initiate user authentication for the first user. In this way, the first UE, upon receiving the first indication, can be considered to need to initiate a second request for user authentication for the first UE.

[0255] In some embodiments, the first network function determines the indication content of the first indication according to whether to perform user authentication for the first user, and sends the first indication to the first UE. In this case, the first indication is used to directly or indirectly instruct the first UE whether to initiate user authentication for the first user.

[0256] In some embodiments, the first indication comprises at least one of:

[0257] indication information of an authentication manner used for user authentication of the first user;

[0258] a service identifier used to indicate a service accessed by the first user using the first UE;

[0259] network slice information used to indicate a network slice accessed by the first user using the first UE;

[0260] second authentication information used to instruct the first UE to perform user authentication for the first user.

[0261] In some embodiments, the first indication can comprise at least one of: indication information of an authentication manner used for user authentication, and / or the second authentication information, and / or a reason for not performing user authentication for the first user. For example, when the first network function determines to perform user authentication for the first user, the first indication can comprise at least one of: indication information of an authentication manner used for user authentication and / or the second authentication information. For another example, when the first network function determines not to perform user authentication for the first user, the first indication can comprise a reason for not performing user authentication for the first user. For example, the indication information of an authentication manner used for user authentication and / or the second authentication information in the first indication can be used to indirectly instruct to perform user authentication for the first user. The reason for not performing user authentication for the first user can be used to indirectly instruct not to perform user authentication for the first user.

[0262] In some embodiments, the second authentication information can comprise an authentication request (or an authentication instruction) used to instruct the first UE to perform user authentication for the first user, and / or an authentication instruction generated by the first network function to assist the first user to perform user authentication.

[0263] For example, in some embodiments, the second authentication information can be an EAP message such as an EAP request encapsulated in an EAP.

[0264] In some embodiments, the first indication can comprise an indicator specifically indicating whether the user authentication of the first user is required, which is different from the authentication information, the indication information of the authentication manner and / or the reason why the user authentication of the first user is not performed.

[0265] Exemplarily, the reason why the user authentication of the first user is not performed can comprise that the first UE does not support the user authentication, the user configuration information of the first user indicates that the user authentication of the first user is not required, etc.

[0266] In some embodiments, the authentication manner indicated by the indication information can be the authentication manner determined in the foregoing S2102.

[0267] In some embodiments, the second authentication information and / or the indication information of the authentication manner are optional. For example, if the first indication does not contain the indication information, the first UE can select any authentication manner supported by itself, and carry an indicator of the authentication manner selected by the first UE in an authentication request sent to the second network function when performing the user authentication with the third network function. Alternatively, if the first indication does not contain the indication information, the first UE selects a default authentication manner agreed by the protocol or the like, and the second network function is also aware of the default authentication manner. The authentication information can be used for the user authentication between the first UE and the second network function.

[0268] In some embodiments, the second authentication information can be verified by the first UE using the local credential (e.g., the first credential) for the user authentication. For example, the second authentication information is verified by the first credential for integrity protection verification, confidentiality protection verification, scrambling protection verification, etc. The second authentication information verified by the first credential will be known by the first UE. After the first UE successfully obtains the second authentication information, the first UE can obtain the first authentication information according to the second authentication information, and then transmits the first authentication information protected by the first credential to the second network function. After that, the second network function can use the network to store the second credential for authentication. If the authentication is successful, it can be considered that the user authentication of the first user is passed, otherwise, it can be considered that the user authentication is not passed.

[0269] Exemplarily, all or part of the second authentication information is taken as the second authentication information; or the first UE generates the second authentication information without referring to the second authentication information. Exemplarily, the second authentication information can be taken as a response message of the first authentication information. For example, the second authentication information can be taken as an EAP response.

[0270] The first credential can be a key and / or a digital certificate when the first user subscribes. It is worth noting that the first user can be any user or device that does not distribute a subscription key when subscribing.

[0271] In some embodiments, the second authentication information can be a random number randomly generated by the first network function or a specific authentication symbol; and / or, the first authentication information can be the second authentication information, or the first authentication information can be generated based on the second authentication information provided by the first network function, or the second authentication information can be user information of the first user. In summary, the second authentication information can be used to verify the identity of the first user.

[0272] In some embodiments, the first network function sending the first indication to the first UE is an optional step. For example, without performing S2103, directly enter the step of the first network function sending the first request to the second network function.

[0273] In some embodiments, the second network function can be various core network functions. Illustratively, the second network function can be various authentication functions capable of identity authentication. Illustratively, the second network function can include, but is not limited to, at least one of the following: an authentication server function (AUSF), a UDM, a user authentication and authorization function (UAAF).

[0274] In some embodiments, the first request is used to request user authentication for the first user.

[0275] In some embodiments, the first request can include at least one of the following:

[0276] indication information of an authentication method used for user authentication;

[0277] second authentication information.

[0278] It is worth noting that the first network function can send any one of the first indication and the first request. For example, the first network function sends the first indication to the first UE, and then the first UE actively interacts with the second network function to perform user authentication after receiving the first indication, and then the sending of the first request is an optional step. For example, the first network function sends the first request to the second network function, and then the second network function actively interacts with the first UE to perform user authentication after receiving the second indication, and then the first network function sending the first indication is an optional step.

[0279] In some embodiments, the first network function can simultaneously perform the sending of the first indication and the second indication, and after the second network function and the first network function each receive the first indication and the second indication, it can be determined whether user authentication is needed for the first user according to the first indication and / or the second indication, reducing the fake authentication caused by the interception of the first indication and / or the second indication, and again improving the security of user authentication.

[0280] S2104: The first UE sends a second request to the first network function.

[0281] In some embodiments, the second request is used for the first UE to request user authentication of the first user.

[0282] In some embodiments, the first UE sends the second request to the first network function based on the first request.

[0283] In some embodiments, the second request can carry more information for user authentication of the first user than the first request.

[0284] In some embodiments, the second request includes first information; the first information includes at least one of:

[0285] user identity information of the first user;

[0286] authentication information of the first user; the authentication information is used for user authentication of the first user;

[0287] indication information of an authentication mode; the authentication mode is used for user authentication of the first user;

[0288] a first subscription identifier, the first subscription identifier is used to identify the first UE;

[0289] a service identifier, the service identifier is used to indicate a service accessed by the first user using the first UE;

[0290] network slice information, the network slice information is used to indicate a network slice accessed by the first user using the first UE.

[0291] In some embodiments, the user identity information can include but is not limited to a user identifier. The user identifier includes but is not limited to a user layer identifier, user identity information distributed by a government department, and / or a device identifier of a non-subscription device, etc. The non-subscription device is a device that has not signed a contract with the communication operator shown in FIG. 1.

[0292] In some embodiments, part or all of the first information can come from or be determined according to the first indication.

[0293] For example, when the authentication mode indicated by the first indication is not supported by the first UE or is not preferred by the first UE, the authentication mode indicated by the second authentication information carried by the first information can be different from the authentication mode indicated by the first indication.

[0294] In some embodiments, if the first information carries the service identifier of the first service, the network side can perform user authentication of the first user using the first UE to obtain the service corresponding to the service identifier, so as to realize user authentication at the granularity of the service, rather than only at the granularity of the whole device of the first UE. For example, if the first information does not contain the first subscription identifier, the second network function of the network side can perform user authentication of whether the corresponding service is available to the first user without using the subscription identifier of the first user based on the service identifier.

[0295] In some embodiments, the network slice information can include, but is not limited to, at least one of the following:

[0296] Network slice selection assistance information (NSSAI);

[0297] Single network slice selection assistance information (S-NSSAI).

[0298] If the first information carries the network slice information, the network side can perform user authentication of the first user using the first UE to obtain the network slice corresponding to the network slice information, so as to realize user authentication at the granularity of the network slice, rather than only at the granularity of the whole device of the first UE. For example, if the first information does not contain the first subscription identifier, the second network function of the network side can perform user authentication of whether the corresponding service is available to the first user without using the subscription identifier of the first user based on the network slice information.

[0299] In some embodiments, the first authentication information and / or the second authentication information can be encapsulated into an extended authentication protocol (EAP) message. In this way, the user authentication of the first user can be performed using the EAP.

[0300] In some embodiments, the second authentication information can be any information used for user authentication of the first user. For example, the second authentication information can also be a password or a short message verification code used for user authentication.

[0301] In some embodiments, the second authentication information is optional information of the second request.

[0302] Of course, the above is only an example of the first information.

[0303] In some embodiments, at least part of the first information is protected by the first credential.

[0304] In some embodiments, the second authentication information and / or the user identity information of the first user can be guaranteed by the first credential. The protection can be in various manners including but not limited to integrity protection, confidentiality protection and / or scrambling protection.

[0305] If the first authentication information is protected by the first credential, since the second authentication information is provided by the first network function, this can reduce the UE from intercepting other UE's data protected by the first credential in the network for user authentication, and can improve security. For example, the second authentication information can be dynamically generated by the first network, or can be determined by the first network according to the user configuration information of the first user. For example, the user configuration information of the first user is pre-configured with authentication information. For another example, the user configuration information of the first user is configured with a rule for dynamically generating the second authentication information, so that the first network function can dynamically generate the second authentication information according to the user configuration information of the first user.

[0306] In some embodiments, any one of the first subscription identifier in the second request and the user identity information of the first user is carried in plaintext, facilitating subsequent retrieval of information required for user authentication of the first user.

[0307] In some embodiments, the first subscription identifier included in the second request and the first subscription identifier included in the third request can both point to the first UE, but the first subscription identifier included in the second request and the first subscription identifier included in the third request can be different subscription identifiers of the first UE. For example, the first subscription identifier included in the second request is GPSI, and the first subscription identifier included in the third request can be SUCI, etc.

[0308] S2105: The first network function sends a first request to the second network function.

[0309] In some embodiments, the first network function sends the first request to the second network function according to the second request. For example, the first network function sends the first request to the second network function after receiving the second request. The first request can include part or all of the information in the second request.

[0310] In some embodiments, the first network function sends the first request to the second network function according to the third request. For example, the first network function sends the first request to the second network function after receiving the third request. The first request can include part or all of the information in the third request. In this case, the first UE does not need to send the second request to the first network function, and the first network function also does not need to send the first indication to the first UE. Of course, the first network function can also send the first indication to the first network function, which is equivalent to informing the first UE that the network side will or is performing user authentication on the first user.

[0311] In some embodiments, the first request comprises first information. The first information comprises at least one of:

[0312] user identity information of the first user;

[0313] first authentication information; the first authentication information is used for user authentication of the first user;

[0314] indication information of an authentication manner; the authentication manner is used for user authentication of the first user;

[0315] a first subscription identifier, the first subscription identifier is used for identifying the first UE;

[0316] a service identifier, the service identifier is used for indicating a service accessed by the first user using the first UE;

[0317] network slice information, the network slice information is used for indicating a network slice accessed by the first user using the first UE.

[0318] In some other embodiments, the first request comprises at least one of:

[0319] user identity information of the first user;

[0320] first authentication information; the first authentication information is used for user authentication of the first user;

[0321] indication information of an authentication manner; the authentication manner is used for user authentication of the first user;

[0322] a first subscription identifier, the first subscription identifier is used for identifying the first UE;

[0323] a service identifier, the service identifier is used for indicating a service accessed by the first user using the first UE;

[0324] network slice information, the network slice information is used for indicating a network slice accessed by the first user using the first UE.

[0325] In some embodiments, part or all of the first request is protected by the first credential. For example, part or all of the first information in the first request is protected by the first credential.

[0326] In some embodiments, part of the first request, such as the authentication information and / or the indication information, is protected by the first credential.

[0327] S2106: The second network function sends a fourth request to a third network function.

[0328] In some embodiments, the third network function can be a core network function or a third-party authentication server. For example, the third network function can include, but is not limited to, a UIMF.

[0329] In some embodiments, the fourth request is for requesting the third network function to perform user authentication on the first user.

[0330] In some embodiments, the fourth request comprises second information; the second information comprises at least one of:

[0331] user identity information of the first user;

[0332] first authentication information; the first authentication information is indicative of a user authentication mode for the first user; the user authentication mode is used for user authentication of the first user;

[0333] a first subscription identifier, the first UE identifier is used for identifying the first UE;

[0334] a service identifier, the service identifier is used for indicating a service accessed by the first user using the first UE;

[0335] network slice information, the network slice information is used for indicating a network slice accessed by the first user using the first UE.

[0336] In some embodiments, at least part of the second information is protected by the first credential. Exemplarily, the user identity information of the first user and / or the first authentication information is protected by the first credential.

[0337] In some embodiments, the second network function sends the fourth request to the third network function based on the first request.

[0338] In some embodiments, if the second network function itself supports user authentication, the second network function can perform user authentication on the first user without sending the fourth request to the third network function, and the third network function completes the user authentication of the first user, i.e., S2104 and subsequent steps related to the user authentication of the first user triggered by S2104 can be omitted.

[0339] In some embodiments, the fourth request can comprise one or more information units or containers. At least part of the first request or at least part of the first information is carried in one information unit or container. For example, the fourth request can directly contain the first request.

[0340] S2107: The third network function performs user authentication on the first user.

[0341] In some embodiments, the third network function comprises but is not limited to a user information management function (UIMF) or a third-party authentication server. The third-party authentication server comprises but is not limited to an authentication, authorization and accounting (AAA) server.

[0342] In some embodiments, the third-party authentication server can include, but is not limited to:

[0343] In some embodiments, the third network function performs user authentication for the first user based on the fourth request.

[0344] In some embodiments, the third network function performs user authentication for the first user based on the second credential for the fourth request.

[0345] Exemplarily, the third network function determines the second credential according to the user identity information and / or the first subscription identifier of the first user carried in plaintext in the fourth request, verifies the fourth request based on the second credential, and determines whether the user authentication for the first user passes according to whether the fourth request passes the verification.

[0346] In some embodiments, the fourth request is authenticated by digital signature or integrity verification based on the second credential, and if the digital signature verification and / or integrity verification passes, it can be considered that the fourth request passes the verification.

[0347] In some embodiments, the fourth request is decrypted and / or descrambled based on the second credential, and if the decryption and / or descrambling is successful, it can be considered that the fourth request passes the verification. The decryption corresponds to the confidentiality protection, and a symmetric key or an asymmetric key can be used for the confidentiality protection.

[0348] In some embodiments, determining whether the user authentication for the first user passes according to whether the fourth request passes the verification includes at least one of the following:

[0349] If the fourth request does not pass the verification, it is determined that the user authentication for the first user does not pass.

[0350] If the fourth request passes the verification, it is determined that the user authentication for the first user passes.

[0351] In some embodiments, the user authentication for the first user can not be based on the second credential. Exemplarily, whether the fourth request passes the verification is determined according to whether two or more of the user identity information of the first user, the first subscription key, the service identifier and / or the network slice information have corresponding storage records in the third network function. Exemplarily, if two or more of the user identity information of the first user, the first subscription key, the service identifier and / or the network slice information have corresponding storage records in the third network function, it can be considered that the fourth request passes the verification, otherwise it can be considered that the fourth request does not pass the verification.

[0352] S2108: The third network function sends a fourth response to the second network function.

[0353] In some embodiments, the fourth response is for indicating whether the user authentication of the first user is passed.

[0354] In some embodiments, when the fourth response indicates that the user authentication of the first user is not passed, the fourth response can further comprise a failure cause.

[0355] S2109: The second network function sends a first response to the first network function.

[0356] In some embodiments, the first response is for indicating whether the first user is passed the user authentication.

[0357] In some embodiments, when the first response indicates that the user authentication of the first user is failed, the first response can comprise a failure cause.

[0358] S2110: The first network function sends a third response to the first UE. In some embodiments, the third response indicates to accept or reject the third request.

[0359] In some embodiments, the first network function sends the third response to the first UE according to the result of the user authentication of the first user.

[0360] In some embodiments, the first network function sends the third response to the first UE according to the result of the verification of the first UE (not the result of the user authentication of the first user).

[0361] In some embodiments, the third response is related to the user authentication of the first user, then when the third response indicates to reject the third request, it represents that the user authentication of the first user is failed or the first network function determines not to perform the user authentication for the first user; and / or, when the third response indicates to accept the third request, it represents that the first network function determines to perform the user authentication for the first user and the user authentication of the first user is passed. Exemplarily, the first network function sends the third response according to the first response.

[0362] In some other embodiments, the third response is not related to the user authentication of the first user.

[0363] Exemplarily, if the third request is a registration request for the first UE to enter the network. If the third response is related to the user authentication of the first user, then whether the third response indicates to accept the registration request of the first UE is related to whether the user authentication of the first user is passed.

[0364] If the third request is a registration request and the fourth response is related to the user authentication of the first user, then the registration of the first UE to enter the network needs to be completed after the user authentication.

[0365] If the third request is a registration request and the fourth response is irrelevant to the user authentication of the first user, the network access registration of the first UE can be completed at any time after S2101, for example, before, when or after obtaining the result of the user authentication of the first user. That is, the execution order of S2108 is not limited to after S2107.

[0366] Exemplarily, if the third request is a registration request for the network access of the first UE. If the third response is irrelevant to the user authentication of the first user, the third response indicates whether to accept the registration request of the first UE is not affected by whether the first user is authenticated. At this time, the network access authentication of the first UE can proceed as usual.

[0367] S2111: The first response indicates that the first user passes the user authentication, and the first network function associates the user identity information of the first user with the first subscription identifier of the first UE.

[0368] Exemplarily, according to the association relationship between the user identity information of the first user and the first subscription identifier, the user configuration information of the first user is updated.

[0369] In some embodiments, the first response indicates that the first user passes the user authentication, and the user configuration information of the first user is updated, for example, the user identity information of the first user is associated with the first subscription identifier of the first UE in the user configuration information. For another example, the device information of the first device is added in the user configuration information, etc.

[0370] As shown in FIG. 3, the present disclosure provides a user authentication method, which is executed by a first network function. The method can include:

[0371] S3101: receiving a third request.

[0372] In some embodiments, the third request is sent by the first UE.

[0373] In some embodiments, the related description of the first request can be referred to FIG. 2. Exemplarily, the third request can at least include the user identity information of the first user, etc. Of course, the identity information of the first user can not be limited to the user identity information of the first user.

[0374] S3102: determining whether and / or how to perform user authentication on the first user.

[0375] In some embodiments, according to the user configuration information and / or the local information, whether and / or how to perform user authentication on the first user is determined.

[0376] In some embodiments, the optional mode of S3102 can be referred to S2102 of FIG. 2, which will not be repeated here.

[0377] In addition, the S3102 can be an optional step. For example, in some cases, it can be considered that the user authentication of the first user is required by default and / or the user authentication of the first user is performed in a default authentication manner, and thus the step does not need to be performed.

[0378] S3103: sending a first indication.

[0379] In some embodiments, the first indication is sent to the first UE.

[0380] In some embodiments, the optional manner of S3103 can refer to S2103 of FIG. 2, which will not be repeated here.

[0381] It is worth noting that if the third request carries information required for the user authentication of the first user, the S3103 is an optional step.

[0382] S3104: receiving a second request.

[0383] In some embodiments, the second request is used by the first UE to request the user authentication of the first user.

[0384] In some embodiments, the first UE sends the second request to the first network function based on the first indication.

[0385] In some embodiments, the second request can carry more information for the user authentication of the first user relative to the first indication.

[0386] In some embodiments, the second request includes first information; the first information includes at least one of the following:

[0387] User identity information of the first user;

[0388] First authentication information; the first authentication information is indication information of an authentication manner for the user authentication of the first user; the authentication manner is used for the user authentication of the first user.

[0389] First subscription identifier, the first subscription identifier is used to identify the first UE;

[0390] Service identifier, used to indicate a service accessed by the first user using the first UE;

[0391] Network slice information, used to indicate a network slice accessed by the first user using the first UE.

[0392] S3105: sending a first request.

[0393] In some embodiments, the optional manner of S3105 can refer to S2105 of FIG. 2, which will not be repeated here.

[0394] S3106: receiving the first response.

[0395] In some embodiments, the first response is used to indicate whether the first user passes the user authentication.

[0396] In some embodiments, the first response indicates that the user authentication of the first user fails, and the first response can include a failure cause.

[0397] S3107: sending a third response.

[0398] In some embodiments, the optional manner of S3107 can refer to S2110 of FIG. 2, which will not be repeated here.

[0399] S3108: the first response indicates that the first user passes the user authentication, and the user identity information of the first user is associated with the first subscription identifier of the first UE.

[0400] In some embodiments, the optional manner of S3108 can refer to S2111 of FIG. 2, which will not be repeated here.

[0401] As shown in FIG. 4, the present disclosure provides a user authentication method, which is executed by a second network function. The method can include:

[0402] S4101: receiving a first request.

[0403] In some embodiments, the first request sent by the first network function is received.

[0404] In some embodiments, the first request sent by the first network function according to the third request or the second request is received.

[0405] In some embodiments, the related description of the first request can be referred to FIG. 2. Exemplarily, the first request includes at least one of the following;

[0406] The user identity information of the first user;

[0407] The first authentication information; the first authentication information is used for the indication information of the user authentication mode of the first user; the authentication mode is used for the user authentication of the first user;

[0408] The first subscription identifier, the first subscription identifier is used for identifying the first UE;

[0409] The service identifier, used for indicating the service accessed by the first user using the first UE;

[0410] The network slice information, used for indicating the network slice accessed by the first user using the first UE.

[0411] S4102: sending a fourth request.

[0412] In some embodiments, the fourth request is used to request the third network function to perform user authentication on the first user.

[0413] In some embodiments, the optional method of S4102 can be found in S2106 of Figure 2, which will not be repeated here.

[0414] S4103: Receive the fourth response.

[0415] In some embodiments, the second network function receives a fourth response from the third network function.

[0416] In some embodiments, the fourth response is used to indicate whether the user authentication of the first user is passed.

[0417] In some embodiments, when the fourth response indicates that the user authentication of the first user has failed, the fourth response may further include a reason for the failure.

[0418] In some embodiments, S4102 to S4103 are optional steps. For example, the second network function may perform local user authentication of the first user.

[0419] In some embodiments, the first network function performs user authentication on the first user based on the user configuration information and / or local information.

[0420] S4104: Send the first response.

[0421] In some embodiments, the first response is sent based on the user authentication result of the first user.

[0422] In some embodiments, a first response is sent to the first network function based on a user authentication result of the first user.

[0423] In some embodiments, sending a first response may be an optional step. For example, if the user authentication result is determined to be passed according to the protocol, the first response is not sent; if the user authentication result is failed, the first network function is notified within the agreed time. In this way, the first network function can determine whether the user authentication result of the first user is passed based on whether the first response is received within the predetermined time. Therefore, S4104 is an optional step.

[0424] As shown in FIG5 , the present disclosure provides a user authentication method, which is performed by a third network function. The method may include:

[0425] S5101: Receive the fourth request.

[0426] In some embodiments, a fourth request sent by the second network function is received.

[0427] In some embodiments, a fourth request sent by the second network function according to the first request is received.

[0428] In some embodiments, the fourth request can refer to the description shown in FIG. 2.

[0429] In some embodiments, the fourth request is used to request the third network function to perform user authentication on the first user using the first user equipment (UE).

[0430] In some embodiments, the fourth request includes second information; the second information includes at least one of the following:

[0431] User identity information of the first user;

[0432] First authentication information; the first authentication information is indication information of an authentication manner used for user authentication of the first user;

[0433] First subscription identifier, the first subscription identifier is used to identify the first UE;

[0434] Service identifier, used to indicate a service accessed by the first user using the first UE;

[0435] Network slice information, used to indicate a network slice accessed by the first user using the first UE.

[0436] S5102: Perform user authentication on the first user.

[0437] In some embodiments, the third network function performs user authentication on the first user according to the authentication manner indicated by the indication information.

[0438] In some embodiments, the first user is authenticated using an EAP authentication manner.

[0439] In some embodiments, the fourth request is verified based on the second credential; and whether the user authentication of the first user is passed is determined according to whether the fourth request is verified.

[0440] In some embodiments, when the fourth request is not verified, it is determined that the user authentication of the first user is not passed; and / or when the fourth request is verified, it is determined that the user authentication of the first user is passed.

[0441] S5103: Send a fourth response.

[0442] In some embodiments, the second network function receives the fourth response from the third network function.

[0443] In some embodiments, the fourth response is used to indicate whether the user authentication of the first user is passed.

[0444] In some embodiments, when the fourth response indicates that the user authentication of the first user is not passed, the fourth response can further include a failure reason.

[0445] In some embodiments, the first response is sent to the first network function according to a user authentication result of the first user.

[0446] In some embodiments, the information interaction between the first network function, the second network function and the third network function can be realized through message transmission of corresponding interfaces, or through calling of standardized service operations.

[0447] As shown in FIG. 6, the present disclosure provides a user authentication method, which is executed by a first UE. The method can include:

[0448] S6101: sending a third request.

[0449] In some embodiments, the first UE sends the third request to the first network function.

[0450] In some embodiments, the third request includes at least one of the following:

[0451] a first subscription identifier, the first subscription identifier being used to identify the first UE and / or a first device;

[0452] capability information, the UE capability information being used to indicate to the first network function whether the first UE and / or the first device supports user authentication;

[0453] the first UE is a UE used by the first user; and the first device is a device associated with the first UE.

[0454] In some embodiments, the first subscription identifier can be an identifier assigned by a communication operator when the first UE subscribes to the communication operator, or an identifier derived from the identifier assigned by the communication operator. In some embodiments, the first subscription identifier includes but is not limited to a subscriber concealed identity (SUCI) or a subscriber permanent identity (SUPI).

[0455] In some embodiments, the capability information can be at least a capability possessed by the first UE and / or the first device. In some embodiments, the capability information can be at least a capability subscribed by the first UE and / or the first device.

[0456] In some embodiments, the capability information can indicate whether the first UE and / or the first device supports user authentication and / or one or more authentication modes that can be supported.

[0457] In some embodiments, the association relationship between the first UE and the first device can be embodied in at least one of the following:

[0458] The first UE can be a gateway UE of the first device; for example, the first UE can be a home gateway UE of the first device, or the first UE can be a hotspot device of the first device.

[0459] The first UE and the first device can be in a binding relationship, for example, a smart watch and / or a mobile phone of the same user have a binding relationship.

[0460] In some embodiments, the first user can be a user currently using the first device or using the first device, in which case the first user can be the device or the user using the first device, and in this case the first user is equivalent to the current indirect use of the first UE.

[0461] In some embodiments, the first user can be a user currently directly using the first UE. For example, the first UE is a shared device, which can be used by multiple users (persons), and in this case the first user corresponds to the person.

[0462] In some embodiments, the first device can be a non-subscribed device or a non-3GPP device, etc.

[0463] In some embodiments, the first UE can send a third request to the first network function through a non-access layer message, or send the third request to the first network function based on a manner of calling a standardized service.

[0464] In some embodiments, the optional implementation of S6101 can refer to the corresponding S2101 of FIG. 2.

[0465] S6102: receiving a first indication.

[0466] In some embodiments, the first indication sent by the first network function is received.

[0467] In some embodiments, the related description of the first indication can refer to the corresponding S2103 of FIG. 2.

[0468] S6103: sending a second request.

[0469] In some embodiments, the related description of the second request can refer to the corresponding related description of FIG. 2.

[0470] In some embodiments, the optional implementation of S3103 can refer to the corresponding S2104 of FIG. 2.

[0471] S6104: receiving a third response.

[0472] In some embodiments, the related description of the third response can refer to the corresponding related description of FIG. 2.

[0473] In some embodiments, S6102 and S6103 are optional steps, that is, S6101 to S6104 can be executed alone.

[0474] Currently, a device usually performs user authentication before it acquires a service. For example, user authentication based on a username and / or a password. However, as the number of services increases, more and more credentials are required for user authentication, and thus it becomes more and more troublesome for a user to manage different credentials. Before a device acquires a service, an identity information provider performs user authentication by providing identity information to a network function or an application server.

[0475] An operator can provide enhanced services through a 3GPP network or a non-3GPP network to improve user experience and optimize the network. For example, the network operator can adjust network settings and customize services according to the needs of the user without relying on subscription data for establishing a connection. As an identity provider, the operator can consider additional information from the network to charge and provide differentiated services according to the user identity.

[0476] A user of a certain device can be identified based on subscription personal information, a UE to which the device is connected, or a gateway device to which the device is connected.

[0477] The security architecture in some embodiments only supports authentication and / or authorization based on subscription personal information, but does not support authentication and / or authorization based on a UE to which the device is connected and / or a gateway device to which the device is connected.

[0478] In some embodiments, user authentication (VI-a) is part of the study of user identity security (V). User authentication (VI-a) needs to be performed between users through a user identification module (for example, a universal subscriber identity module (USIM)) and a user authentication and authorization function (UAAF).

[0479] The present disclosure provides a related solution for user authentication after a UE performs network access authentication through an access network, for example, based on the identity information of another UE to which the UE is connected or based on the identity information of a gateway to which the UE is connected.

[0480] The present disclosure proposes that the user authentication is performed after the terminal performs the primary authentication with the network. The identity of the user who uses the subscription-based terminal to access the operator or non-operator deployment (i.e. external non-3GPP) services needs to be authenticated. Exemplarily, the user authentication is performed using the EAP framework. The user authentication is performed between the terminal and the UAAF (User authentication and Authorization Function) deployed by the terminal operator. The AMF communicates with the UAAF as an authenticator. The UAAF acts as an authentication server. The user authentication can need the support of the UIMF (User Information Management Function) to obtain more information related to the user.

[0481] As shown in FIG. 7A, the present disclosure provides a user authentication method which can include:

[0482] 1a-1. For the user who needs to authenticate the user identity, the UE needs to send the user identity to the network function (e.g. AMF). This step can include step 1a and step 1b.

[0483] 1a-2. The AMF receives the user identity from the UE in the UE registration procedure, for example, the AMF receives the registration request carried by the UE with the user identity.

[0484] 1b. After the UE registration is completed, the user registration request is sent, which includes the user identity. The user registration request can be a kind of non-access layer message. For example, the user identity is encapsulated into the format required by the non-access layer message.

[0485] 2. The AMF determines whether and / or how to perform the user authentication according to the information related to the identity authentication policy in the subscription information or the user profile. Exemplarily, the AMF determines whether the user authentication is performed by the UAAF or the AAA server. Exemplarily, the AMF can also determine the EAP authentication method used for the user authentication.

[0486] 3. The AMF sends the user authentication request to the UE through the NAS message, which can include the user ID to be authenticated (which can be referred to as EAP-ID) and / or the EAP request. Exemplarily, the user authentication request can optionally include the service ID or network slice information (i.e. S-NSSAI). The AMF also indicates the selected EAP method to the UE. Exemplarily, the EAP request can be one of the second authentication information mentioned above.

[0487] 4. The UE provides a user identity as EAP-ID, optionally with a traffic ID or network slice information (which can include but not limited to S-NSSAI). In some embodiments, the UE provides the EAP-ID in a message that can also include an EAP-Response (EAP-Response) in a user authentication response. The UE can send the above information to a core network function such as AMF, SEAF, or MME, through a non-access stratum message or by invoking a standardized service operation. In some embodiments, the EAP-Response can include information needed for user authentication, such as a random number, an indicator, a username and / or password of the user to be authenticated, and / or other EAP-Response that participates in user authentication. In some embodiments, the EAP-Response can be protected using a credential associated with the user identity (i.e., the first credential mentioned above). Exemplarily, the EAP-Response can be the first authentication information mentioned above.

[0488] 5. The AMF sends the EAP-Response to the UAAF by invoking a service Nuaaf_UsereAuth_Authenticate Request, and indicates the authentication method used for user authentication. The UAAF verifies the EAP-Response using a credential associated with the user identity used by the UE. The UAAF can interact with the UIMF to obtain more information needed for user authentication.

[0489] 7. One or more EAP message exchanges are performed between the UE and the UAAF.

[0490] 8. The EAP-ID authentication is completed. Exemplarily, the UAAF and the AMF invoke Nuaaf_UserAuth_AuthenticateResponse to transmit the result of authentication failure or authentication success, and optionally the UAAF provides the SUPI to the AMF.

[0491] 9. Optionally, the AMF associates the user identity with the SUPI if the authentication is successful.

[0492] 10. The AMF returns a user registration response to the UE through a NAS message according to the result of user authentication. If the user authentication is passed, the UE is successfully registered in the operator network, and subsequent service usage can be performed by the UE. If the user authentication fails, the UE is prompted with the reason for authentication failure, and subsequent service usage operation cannot be performed on the UE.

[0493] As shown in FIG. 7B, the present disclosure provides a user authentication method which can include:

[0494] User authentication can also be conducted between the UE and an authentication, authorization and accounting server (AAA-S) of the operator or an external third party. The AMF acts as an EAP authenticator and communicates with the AAA-S through a UAAF. The UAAF undertakes the interaction of AAA protocols with the AAA-s. Various EAP methods can be used for user identity authentication. If the AAA-S belongs to a third party, the UAAF goes through an authentication, authorization and accounting proxy (AAA-P). The AAA-P then interacts with the AAA-S.

[0495] 1a-1. For a user requiring user identity authentication, the UE needs to send the user identity to a network function (e.g. AMF). This step can include step 1a and step 1b.

[0496] 1a-2. The AMF receives the user identity from the UE in the UE registration procedure, for example, the AMF receives a registration request from the UE with the user identity.

[0497] 1b. After the UE registration is completed, a user registration request is sent, which includes the user identity. The user registration request can be a kind of non-access layer message. For example, the user identity is encapsulated into the format required by the non-access layer message.

[0498] 2. The AMF decides whether to start the user identity authentication procedure and how to start according to the information related to the identity authentication policy in the subscription information or user profile, or triggered by the UAAF.

[0499] 3. The AMF sends a user authentication request to the UE through a NAS message, requesting an EAP authentication user ID (EAP-ID), which can optionally include a service ID or network slice information (i.e. S-NSSAI). The AMF also indicates the selected EAP method to the UE.

[0500] 4. The UE provides the user identity as the EAP-ID, which can be optionally sent together with the service ID or network slice information (S-NSSAI) to the AMF through an EAP response in the user authentication response through a NAS message. The EAP response is protected using the credential associated with the user identity.

[0501] 5. The AMF sends the user identity to the UAAF providing the AAA interface through a Nuaaf_UserAuth_Authenticate Request (EAP response, EAP-ID, GPSI, S-NSSAI).

[0502] 6. If the AAA-P exists, the UAAF sends the EAP response and / or the user identity to the AAA-P, otherwise the UAAF forwards the message directly to the AAA-S. The UAAF forwards the EAP-ID together with the GPSI to the AAA-S. The AAA-S stores the GPSI to create an association with the user identity so that the AAA-S can use it later for user authentication.

[0503] 7-12. EAP messages related to EAP authentication are exchanged with the UE, which can be seen in more detail in Figure 7B. One or more of these steps can occur or be repeated, and one or more of these steps can be omitted, i.e. not performed.

[0504] 13. The EAP-ID authentication is completed. The result of the authentication, either success or failure, is sent to the UAAF together with the GPSI.

[0505] 14. The UAAF sends the response of the authentication to the AMF by invoking Nuaaf_UserAuth_Authenticate Response. For example, the response of the authentication can include the result of the authentication success or failure and / or the GPSI, etc.

[0506] 15. The AMF returns the user registration response to the UE through the NAS message according to the result of the user authentication (success or failure). If the user authentication is passed, the UE is successfully registered in the operator network and the subsequent service usage can be performed by the UE. If the user authentication fails, the user is prompted on the UE for the reason of the authentication failure and the subsequent service usage operation on the UE cannot be performed.

[0507] The AMF can perform at least one of the following functions:

[0508] The AMF should be able to send a user authentication request to the UE through the NAS message, requesting the user ID for EAP authentication and indicating the EAP method. Exemplarily, the user ID and the aforementioned EAP-ID are both a kind of the aforementioned user identity information.

[0509] The AMF should be able to receive the EAP response from the UE through the NAS message from the user authentication response.

[0510] The AMF should be able to forward the EAP response to the UAAF and indicate the authentication method used for the EAP authentication.

[0511] The AMF should be able to receive the result of the authentication success or failure sent by the UAAF, and optionally, the result of the authentication success or failure is received from the UAAF together with the SUPI.

[0512] The AMF should be able to associate the SUPI with the user identity.

[0513] The AMF shall be able to send the user authentication result (success / failure) to the UE in the user registration response.

[0514] The UAAF can perform at least one of the following functions:

[0515] The UAAF shall be able to receive the EAP response and the indication of the authentication method of the EAP authentication from the AMF by invoking Nuaaf_UserAuth_AuthenticateRequest.

[0516] The UAAF shall be able to authenticate the EAP response by using the same credential authentication associated with the user identity used by the UE.

[0517] The UAAF shall be able to interact with the UIMF to obtain more information required for the user authentication.

[0518] The UAAF shall be able to send the user authentication result to the AMF in Nuaaf_UserAuth_AuthenticateResponse, optionally together with the SUPI to the AMF.

[0519] The UAAF shall be able to route the user identity to the AAA-S.

[0520] The UAAF shall be able to forward the EAP-ID together with the GPSI to the AAA-S.

[0521] The UAAF shall be able to receive the user authentication result from the AAA-S.

[0522] The UIMF shall be able to interact with the UAAF for user authentication.

[0523] The UE shall be able to send the user registration request to the AMF, wherein the user registration request can contain the user identity and optionally the service ID or network slice information.

[0524] The UE shall be able to receive the result of the user identity authentication from the AMF in the user registration response.

[0525] The AAA-S shall be able to receive the EAP-ID and the GPSI from the UAAF.

[0526] The AAA-S shall be able to store the GPSI to create an association with the user identity so that it can be used later by the AAA-S to revoke authorization or trigger re-authentication.

[0527] The AAA-S shall be able to send the user authentication result from the UAAF.

[0528] In the present disclosure, part or all of the steps, and optional implementation manners thereof, can be combined with part or all of the steps in other, and can also be combined with optional implementation manners of other.

[0529] In the present disclosure, part or all of the steps, and optional implementation manners thereof, can be combined with part or all of the steps in other, and can also be combined with optional implementation manners of other.

[0530] The present disclosure also provides a device for implementing any of the above methods, for example, a device is provided, and the device includes units or modules for implementing the steps performed by the terminal in any of the above methods. For another example, another device is provided, and the device includes units or modules for implementing the steps performed by the network function (for example, an access network device, or a core network device, etc.) in any of the above methods.

[0531] It should be understood that the division of each unit or module in the above device is only a logical function division, and all or part of the units or modules can be integrated into one physical entity, or can be physically separated. In addition, the units or modules in the device can be implemented in the form of processor calling software: for example, the device includes a processor, the processor is connected with a memory, the memory stores instructions, and the processor calls the instructions stored in the memory to implement any of the above methods or to implement the functions of the units or modules of the device, wherein the processor is, for example, a general processor, such as a central processing unit (CPU) or a microprocessor, and the memory is a memory in the device or a memory outside the device. Alternatively, the units or modules in the device can be implemented in the form of hardware circuit, and the functions of part or all of the units or modules can be implemented by the design of hardware circuit, and the hardware circuit can be understood as one or more processors; for example, in one implementation, the hardware circuit is an application-specific integrated circuit (ASIC), and the functions of part or all of the units or modules are implemented by the design of the logical relationship of elements in the circuit; for another example, in another implementation, the hardware circuit is a programmable logic device (PLD), and a field programmable gate array (FPGA) is taken as an example, which can include a large number of logic gate circuits, and the connection relationship between the logic gate circuits is configured by a configuration file, so as to implement the functions of part or all of the units or modules. All units or modules of the above device can be implemented in the form of processor calling software, or all units or modules can be implemented in the form of hardware circuit, or part of the units or modules can be implemented in the form of processor calling software, and the remaining part can be implemented in the form of hardware circuit.

[0532] In the present disclosure, the processor is a circuit with signal processing capability. In one implementation, the processor can be a circuit with instruction reading and running capability, such as a central processing unit (CPU), a microprocessor, a graphics processing unit (GPU) (which can be understood as a microprocessor), a digital signal processor (DSP), etc. In another implementation, the processor can implement certain functions through a logical relationship of hardware circuit, which is fixed or reconfigurable. For example, the processor is a hardware circuit implemented by an application-specific integrated circuit (ASIC) or a programmable logic device (PLD), such as an FPGA. In the reconfigurable hardware circuit, the processor loads a configuration document to implement the hardware circuit configuration. It can be understood that the processor loads instructions to implement the functions of the above part or all units or modules. In addition, it can also be a hardware circuit designed for artificial intelligence, which can be understood as an ASIC, such as a neural network processing unit (NPU), a tensor processing unit (TPU), a deep learning processing unit (DPU), etc.

[0533] As shown in FIG. 8A, the present disclosure provides a first network function, which comprises:

[0534] The sending module 7101 is configured to send a first request to a second network function; the first request is used to request user authentication of a first user using a first user equipment (UE);

[0535] The receiving module 7102 is configured to receive a first response sent by the second network function; the first response is used to indicate whether the user authentication of the first user is passed.

[0536] In some embodiments, the sending module and / or the receiving module can correspond to a network interface and / or a transceiving antenna of the first network function.

[0537] In some embodiments, the sending module can be used by the first network function to perform information sending related steps in any one of the user authentication methods.

[0538] In some embodiments, the receiving module can be configured to receive the second request sent by the first UE; the second request is used for the first UE to request the user authentication of the first user.

[0539] In some embodiments, the terminal further comprises a processing module.

[0540] In some embodiments, the processing module can be configured to perform the information processing related steps in any one of the user authentication methods by the first network function.

[0541] In some embodiments, the receiving module is configured to receive a second request sent by the first UE; the second request is used for the first UE to request the user authentication of the first user.

[0542] The sending module is configured to send the first request to the second network function according to the second request; send a second response to the first UE according to the first response; the second response is used to indicate whether the first user passes the user authentication.

[0543] In some embodiments, the second request comprises first information; the first information comprises at least one of:

[0544] User identity information of the first user;

[0545] First authentication information; the first authentication information is used for the user authentication of the first user;

[0546] Indication information of an authentication method; the authentication method is used for the user authentication of the first user;

[0547] First subscription identifier; the first subscription identifier is used to identify the first UE;

[0548] Service identifier; the service identifier is used to indicate a service accessed by the first user using the first UE;

[0549] Network slice information; the network slice information is used to indicate a network slice accessed by the first user using the first UE.

[0550] In some embodiments, at least part of the first information is protected by a first credential;

[0551] The first request comprises the part of the first information protected by the first credential.

[0552] In some embodiments, the first authentication information is protected by the first credential.

[0553] In some embodiments, the sending module is configured to send a first indication to the first UE; the first indication is used to instruct the first UE to initiate the user authentication of the first user.

[0554] In some embodiments, the first indication comprises at least one of:

[0555] indication information of an authentication manner; the authentication manner is used for user authentication of the first user;

[0556] service identification, used for indicating a service accessed by the first user using the first UE;

[0557] network slice information, used for indicating a network slice accessed by the first user using the first UE;

[0558] second authentication information, used for indicating that the first UE performs user authentication of the first user.

[0559] In some embodiments, the receiving module is configured to receive a third request sent by the first UE based on the first indication; the third request comprises user identity information of the first user;

[0560] The processing module is configured to determine whether to perform user authentication of the first user according to the third request;

[0561] The sending module is configured to send the first indication to the first UE in response to performing user authentication of the first user.

[0562] In some embodiments, the sending module is configured to send a third response to the first UE according to whether to perform user authentication of the first user;

[0563] The third response indicates acceptance or rejection of the third request;

[0564] When the third response indicates rejection of the third request, it represents that the user authentication of the first user fails or the first network function determines not to perform user authentication of the first user; and / or, when the third response indicates acceptance of the third request, it represents that the first network function determines to perform user authentication of the first user and the authentication of the first user passes; or,

[0565] The third response is irrelevant to the user authentication of the first user.

[0566] In some embodiments, the processing module is configured to, when the first response indicates that the first user passes the user authentication, associate the user identity information of the first user with the first subscription identification of the first UE.

[0567] FIG. 8B is a second network function provided by the present disclosure, wherein the second network function comprises:

[0568] The receiving module 7201 is configured to receive a first request sent by the first network function; the first request is used for requesting to perform user authentication of a first user of a first UE;

[0569] The processing module 7202 is configured to perform user authentication of the first user;

[0570] The sending module 7203 is configured to send a first response to the first network function or the first UE according to a result of the user authentication.

[0571] In some embodiments, the processing module can be configured to perform any step related to information processing in the user authentication method performed by the second network function.

[0572] In some embodiments, the sending module and / or the receiving module can correspond to a network interface and / or a transceiving antenna of the second network function, for processing any step related to information processing in the user authentication method.

[0573] In some embodiments, the first request comprises at least one of:

[0574] user identity information of the first user;

[0575] first authentication information; the first authentication information is indication information of an authentication manner used for user authentication of the first user; the authentication manner is used for user authentication of the first user;

[0576] a first subscription identifier, the first subscription identifier being used for identifying the first UE;

[0577] a service identifier, the service identifier being used for indicating a service accessed by the first user using the first UE;

[0578] network slice information, the network slice information being used for indicating a network slice accessed by the first user using the first UE.

[0579] In some embodiments, at least part of the first request is protected by the first credential;

[0580] The processing module is configured to authenticate the first request based on the second credential; and determine whether the user authentication of the first user passes or not according to whether the first request passes the authentication or not.

[0581] In some embodiments, the first authentication information is protected by the first credential.

[0582] In some embodiments, the determining whether the user authentication of the first user passes or not according to whether the first request passes the authentication or not comprises at least one of:

[0583] when the first request fails the authentication, determining that the user authentication of the first user fails;

[0584] when the first request passes the authentication, determining that the user authentication of the first user passes.

[0585] In some embodiments, the processing module is configured to determine the second credential according to user identity information of the first user carried in the first request in plaintext.

[0586] In some embodiments, the sending module is configured to send a fourth request to the third network function; the fourth request is used to request the third network function to perform user authentication on the first user.

[0587] The receiving module is configured to receive a fourth response sent by the third network function; the fourth response is used to indicate whether the user authentication of the first user is passed.

[0588] In some embodiments, the fourth request includes second information; the second information includes at least one of the following:

[0589] User identity information of the first user;

[0590] First authentication information; the first authentication information is used for user authentication of the first user;

[0591] Indication information of an authentication mode; the authentication mode is used for user authentication of the first user;

[0592] First subscription identifier, the first UE identifier is used to identify the first UE;

[0593] Service identifier, used to indicate a service accessed by the first user using the first UE;

[0594] Network slice information, used to indicate a network slice accessed by the first user using the first UE;

[0595] Second authentication information, used to indicate that the first UE performs user authentication of the first user.

[0596] In some embodiments, at least part of the second information is protected by the first credential.

[0597] In some embodiments, the first authentication information is protected by the first credential.

[0598] As shown in FIG. 8C, the present disclosure provides a third network function, wherein the third network function includes:

[0599] The receiving module 7301 is configured to receive a fourth request sent by the second network function; the fourth request is used to request the third network function to perform user authentication on a first user using a first user equipment (UE);

[0600] The processing module 7302 is configured to perform user authentication on the first user;

[0601] The sending module 7303 is configured to send a fourth response to the second network function according to a result of the user authentication; the fourth response is used to indicate whether the user authentication of the first user is passed.

[0602] In some embodiments, the processing module can be configured to perform any step related to information processing in the user authentication method performed by the third network function.

[0603] In some embodiments, the sending module and / or the receiving module can correspond to a network interface and / or a transceiving antenna of the third network function, for processing any step related to information processing in the user authentication method.

[0604] In some embodiments, the fourth request includes second information; the second information includes at least one of:

[0605] user identity information of the first user;

[0606] authentication information of the first user; the authentication information is used for user authentication of the first user;

[0607] indication information of an authentication mode; the authentication mode is used for user authentication of the first user;

[0608] a first subscription identifier, the first subscription identifier being used for identifying the first UE;

[0609] a service identifier, the service identifier being used for indicating a service accessed by the first user using the first UE;

[0610] network slice information, the network slice information being used for indicating a network slice accessed by the first user using the first UE.

[0611] In some embodiments, at least part of the second information is protected by a first credential.

[0612] In some embodiments, the first authentication information is protected by the first credential.

[0613] In some embodiments, the processing module is configured to authenticate the fourth request based on a second credential; and determine whether the user authentication of the first user is passed based on whether the fourth request is verified.

[0614] In some embodiments, the processing module is configured to perform at least one of:

[0615] the fourth request is not verified, and it is determined that the user authentication of the first user is not passed;

[0616] the fourth request is verified, and it is determined that the user authentication of the first user is passed.

[0617] As shown in FIG. 8D, the present disclosure provides a first UE, wherein the first UE includes:

[0618] a sending module 7401 configured to send a second request to a first network function; the second request is used for a first user equipment (UE) to request user authentication of a first user;

[0619] The receiving module 7402 is configured to receive a second response sent by the first network function; the second response is used to indicate whether the first user passes the user authentication.

[0620] In some embodiments, the processing module can be configured to perform any step related to information processing in the user authentication method performed by the first UE.

[0621] In some embodiments, the sending module and / or the receiving module can correspond to a network interface and / or a transceiving antenna of the first UE, and be used to perform any step related to information processing in the user authentication method.

[0622] In some embodiments, the receiving module is configured to receive a first indication sent by the first network function; the first indication is used to indicate that the first UE initiates the user authentication for the first user.

[0623] In some embodiments, the first indication comprises at least one of:

[0624] indication information of an authentication manner, the authentication manner being used for the user authentication of the first user;

[0625] a service identifier, used to indicate a service accessed by the first user using the first UE;

[0626] network slice information, used to indicate a network slice accessed by the first user using the first UE.

[0627] In some embodiments, the sending module is configured to send a second request to the first network function according to first information; at least part of the first information is protected by the first credential.

[0628] In some embodiments, the first authentication information in the first information is protected by the first credential.

[0629] In some embodiments, the sending module is configured to send a third request to the first network function; the third request comprises user identity information of the first user.

[0630] The receiving module is configured to receive a third response sent by the first network function.

[0631] The third response is related to the user authentication of the first user, and when the third response indicates rejection of the third request, it represents that the user authentication of the first user fails or the first network function determines not to perform the user authentication for the first user; and / or, when the third response indicates acceptance of the third request, it represents that the first network function determines to perform the user authentication for the first user and the authentication of the first user passes; or,

[0632] The third response is not related to the user authentication of the first user.

[0633] The present disclosure also provides a communication device, which can include one or more processors; wherein the processor is configured to invoke instructions to cause the communication device to perform any one of the above-mentioned implementable user authentication methods.

[0634] In some embodiments, as shown in FIG. 9A and / or FIG. 9B, the communication device 8100 further includes one or more memories 8102 for storing instructions. Optionally, all or part of the memory 8102 can also be outside the communication device 8100.

[0635] The communication device can be the terminal and the network function mentioned above. In some embodiments, the network function can be a master node and / or a secondary node.

[0636] In some embodiments, the communication device 8100 further includes one or more transceivers 8103. When the communication device 8100 includes one or more transceivers 8103, the communication steps such as sending and receiving in the above-mentioned methods are performed by the transceiver 8103, and the other steps are performed by the processor 8101.

[0637] In some embodiments, the transceiver can include a receiver and a transmitter, which can be separate or integrated together. Optionally, the terms transceiver, transceiving unit, transceiver, transceiving circuit, etc. can be replaced by each other, the terms transmitter, transmitting unit, transmitter, transmitting circuit, etc. can be replaced by each other, and the terms receiver, receiving unit, receiver, receiving circuit, etc. can be replaced by each other.

[0638] Optionally, the communication device 8100 further includes one or more interface circuits 8104, which are connected with the memory 8102, and can be used to receive signals from the memory 8102 or other devices, and can be used to send signals to the memory 8102 or other devices. For example, the interface circuit 8104 can read the instructions stored in the memory 8102 and send the instructions to the processor 8101.

[0639] The communication device 8100 described above can be a network function or a terminal, but the range of the communication device 8100 described in the present disclosure is not limited thereto, and the structure of the communication device 8100 can not be limited by FIG. 9A. The communication device can be a standalone device or can be a part of a larger device. For example, the communication device can be: (1) a standalone integrated circuit (IC), or a chip, or a chip system or subsystem; (2) a set of one or more ICs, which can optionally also include storage components for storing data, programs; (3) an ASIC, such as a modem; (4) a module that can be embedded in other devices; (5) a receiver, a terminal device, a smart terminal device, a cellular phone, a wireless device, a handset, a mobile unit, a vehicle-mounted device, a network function, a cloud device, an artificial intelligence device, and the like; (6) other devices, and the like.

[0640] FIG. 9B is a structural schematic diagram of a chip 8200 provided by the present disclosure. For the case where the communication device 8100 can be a chip or a chip system, reference can be made to the structural schematic diagram of the chip 8200 shown in FIG. 9B, but not limited thereto.

[0641] The chip 8200 includes one or more processors 8201 for invoking instructions to cause the chip 8200 to perform any of the above user authentication methods.

[0642] In some embodiments, the chip 8200 further includes one or more interface circuits 8202 connected with the memory 8203, which can be used to receive signals from the memory 8203 or other devices, and can be used to send signals to the memory 8203 or other devices. For example, the interface circuit 8202 can read instructions stored in the memory 8203 and send the instructions to the processor 8201. Alternatively, the terms interface circuit, interface, transceiver pin, transceiver, and the like can be replaced with each other.

[0643] In some embodiments, the chip 8200 further includes one or more memories 8203 for storing instructions. Alternatively, all or part of the memory 8203 can be outside the chip 8200.

[0644] The present disclosure also provides a storage medium having instructions stored thereon, which, when executed on the communication device 8100, cause the communication device 8100 to perform any of the above methods. Alternatively, the storage medium is an electronic storage medium. Alternatively, the storage medium is a computer-readable storage medium, but can also be a storage medium readable by other devices. Alternatively, the storage medium can be a non-transitory storage medium, but can also be a transitory storage medium.

[0645] The present disclosure also provides a program product which, when executed by the communication device 8100, causes the communication device 8100 to perform any of the above user authentication methods. Optionally, the program product is a computer program product.

[0646] The present disclosure also provides a computer program which, when executed on a computer, causes the computer to perform any of the above user authentication methods.

[0647] Other embodiments of the present disclosure will be apparent to those skilled in the art from consideration of the specification and practice of the features disclosed herein. The present disclosure is intended to cover any variations, uses or adaptations of the present disclosure following, in general, the principles of the present disclosure and including such features to the extent that they are not disclosed in the prior art. The specification and examples are to be regarded as illustrative only, and the true scope and spirit of the present disclosure are indicated by the following claims.

[0648] It should be understood that the present disclosure is not limited to the precise structures herein described and illustrated in the drawings, and that various modifications and changes can be made without departing from its scope. The scope of the present disclosure is limited only by the claims that follow.

Claims

1. A user authentication method, wherein: Executed by a first network function, the method includes: Sending a first request to the second network function; the first request is used to request user authentication of a first user using a first user equipment UE; Receive a first response sent by the second network function; the first response is used to indicate whether the user authentication of the first user is passed.

2. The method according to claim 1, wherein The method further includes: receiving a second request sent by the first UE; the second request is used by the first UE to request user authentication of the first user; The sending the first request to the second network function includes: sending the first request to the second network function according to the second request; Based on the first response, a second response is sent to the first UE; the second response is used to indicate whether the first user passes the user authentication.

3. The method according to claim 1 or 2, wherein: The second request includes first information; the first information includes at least one of the following: user identity information of the first user; First authentication information; the first authentication information is used for user authentication of the first user; Instructions for authentication methods; The authentication method is used for user authentication of the first user; a first subscription identifier, where the first subscription identifier is used to identify the first UE; A service identifier, used to indicate a service accessed by the first user using the first UE; Network slice information, used to indicate the network slice accessed by the first user using the first UE.

4. The method according to claim 3, wherein: At least a portion of the first information is protected by a first credential; The first request includes a portion of the first information protected by the first credential.

5. The method according to claim 4, wherein The first authentication information is protected by the first credential.

6. The method according to any one of claims 2 to 5, wherein: The method further comprises: Send a first indication to the first UE; the first indication is used to instruct the first UE to initiate user authentication for the first user.

7. The method according to claim 6, wherein: The first instruction includes at least one of the following: Indication information of an authentication method; the authentication method is used for user authentication of the first user; A service identifier, used to indicate a service accessed by the first user using the first UE; Network slice information, used to indicate a network slice accessed by the first user using the first UE; The second authentication information is used to instruct the first UE to perform user authentication of the first user.

8. The method according to claim 6, wherein: The method further comprises: receiving a third request sent by the first UE based on the first indication; the third request including user identity information of the first user; determining, according to the third request, whether to perform user authentication of the first user; The sending the first indication to the first UE includes: sending the first indication to the first UE in response to performing user authentication of the first user.

9. The method according to claim 8, wherein The method further comprises: Sending a third response to the first UE according to whether user authentication of the first user is performed; The third response indicates acceptance or rejection of the third request; The third response is related to the user authentication of the first user. When the third response indicates that the third request is rejected, it represents that the user authentication of the first user has failed or the first network function has determined not to perform user authentication on the first user; and / or, when the third response indicates that the third request is accepted, it represents that the first network function has determined to perform user authentication on the first user and the authentication of the first user has passed; or The third response is unrelated to user authentication of the first user.

10. The method according to any one of claims 1 to 9, wherein: The method further comprises: The first response indicates that the first user passes user authentication, and associates the user identity information of the first user with the first subscription identifier of the first UE.

11. A user authentication method, wherein: Executed by a second network function, the method includes: Receive a first request sent by a first network function; the first request is used to request a first user of the first UE Perform user authentication; Performing user authentication on the first user; Send a first response to the first network function or the first UE according to a result of the user authentication.

12. The method according to claim 11, wherein The first request includes at least one of the following: user identity information of the first user; First authentication information; the first authentication information is used for user authentication of the first user; Instructions for authentication methods; The authentication method is used for user authentication of the first user; a first subscription identifier, where the first subscription identifier is used to identify the first UE; A service identifier, used to indicate a service accessed by the first user using the first UE; Network slice information, used to indicate the network slice accessed by the first user using the first UE.

13. The method according to claim 12, wherein: At least a portion of the first request is protected by the first UE using first credentials; The performing user authentication on the first user includes: authenticating the first request based on second credentials; Whether the user authentication of the first user passes is determined based on whether the first request passes verification.

14. The method according to claim 13, wherein The first authentication information is protected by the first credential.

15. The method according to claim 13 or 14, wherein: The determining whether the user authentication of the first user is passed according to whether the first request is verified includes at least one of the following: The first request fails verification, and it is determined that the user authentication of the first user fails; The first request passes verification, determining that the user authentication of the first user passes.

16. The method according to any one of claims 11 to 15, wherein: The method further comprises: The second credential is determined based on the user identity information of the first user carried in plain text in the first request.

17. The method according to claim 11, wherein The performing user authentication on the first user includes: Sending a fourth request to a third network function; the fourth request is used to request the third network function to perform user authentication on the first user; Receive a fourth response sent by the third network function; the fourth response is used to indicate whether the user authentication of the first user is passed.

18. The method according to claim 17, wherein The fourth request includes second information; the second information includes at least one of the following: user identity information of the first user; First authentication information of the first user; the first authentication information is used for user authentication of the first user; Instructions for authentication methods; The authentication method is used for user authentication of the first user; A first subscription identifier, where the first UE identifier is used to identify the first UE; A service identifier, used to indicate a service accessed by the first user using the first UE; Network slice information, used to indicate the network slice accessed by the first user using the first UE.

19. The method according to claim 18, wherein At least a portion of the second information is protected by a first credential.

20. The method according to claim 19, wherein The first authentication information is protected by the first credential.

21. A user authentication method, wherein: Executed by a third network function, the method includes: receiving a fourth request sent by the second network function, wherein the fourth request is used to request the third network function to perform user authentication on a first user using a first user equipment UE; Performing user authentication on the first user; A fourth response is sent to the second network function based on the result of the user authentication; the fourth response is used to indicate whether the user authentication of the first user is passed.

22. The method according to claim 21, wherein The fourth request includes second information; the second information includes at least one of the following: user identity information of the first user; First authentication information; the first authentication information is used for user authentication of the first user; Instructions for authentication methods; The authentication method is used for user authentication of the first user; a first subscription identifier, where the first subscription identifier is used to identify the first UE; A service identifier, used to indicate a service accessed by the first user using the first UE; Network slice information, used to indicate the network slice accessed by the first user using the first UE.

23. The method according to claim 22, wherein At least a portion of the second information is protected by a first credential.

24. The method according to claim 23, wherein The first authentication information is protected by the first credential.

25. The method according to any one of claims 21 to 24, wherein: The performing user authentication on the first user includes: authenticating the fourth request based on the second credential; Whether the user authentication of the first user is passed is determined based on whether the fourth request is verified.

26. The method according to claim 25, wherein The determining whether the user authentication of the first user is passed according to whether the fourth request is verified includes at least one of the following: The fourth request fails to pass the verification, and it is determined that the user authentication of the first user fails; The fourth request passes verification, and it is determined that the user authentication of the first user is successful.

27. A user authentication method, wherein: The method is performed by a first user equipment UE, and includes: Sending a second request to the first network function; the second request is used by the first user equipment UE to request user authentication of the first user; Receive a second response sent by the first network function; the second response is used to indicate whether the first user passes user authentication.

28. The method according to claim 27, wherein The method further comprises: Receive a first indication sent by the first network function; the first indication is used to instruct the first UE to initiate user authentication for the first user.

29. The method according to claim 28, wherein The first instruction includes at least one of the following: Indication information of an authentication method; the authentication method is used for user authentication of the first user; A service identifier, used to indicate a service accessed by the first user using the first UE; Network slice information, used to indicate a network slice accessed by the first user using the first UE; The second authentication information is used to instruct the first UE to perform user authentication of the first user.

30. The method according to any one of claims 27 to 29, wherein The sending the second request to the first network function includes: Sending a second request to a first network function based on first information; at least a portion of the first information is protected by the first UE using a first credential.

31. The method according to claim 30, wherein The first authentication information in the first information is protected by the first credential.

32. The method according to any one of claims 27 to 29, wherein: The method further comprises: Sending a third request to the first network function; the third request including user identity information of the first user; receiving a third response sent by the first network function; The third response is related to the user authentication of the first user. When the third response indicates that the third request is rejected, it represents that the user authentication of the first user has failed or the first network function has determined not to perform user authentication on the first user; and / or, when the third response indicates that the third request is accepted, it represents that the first network function has determined to perform user authentication on the first user and the authentication of the first user has passed; or The third response is unrelated to user authentication of the first user.

33. A first network function, wherein: include: a sending module, configured to send a first request to the second network function; The first request is used to request user authentication for a first user using a first user equipment UE; A receiving module, configured to receive a first response sent by the second network function; The first response is used to indicate whether the user authentication of the first user is passed.

34. A second network function, wherein: The second network function includes: a receiving module configured to receive a first request sent by a first network function, wherein the first request is used to request user authentication for a first user of the first UE; a processing module, configured to perform user authentication on the first user; A sending module is configured to send a first response to the first network function or the first UE according to a result of the user authentication.

35. A third network function, wherein: The third network function includes: The receiving module is configured to receive a fourth request sent by the second network function; the fourth request is used to request the The third network function performs user authentication on the first user using the first user equipment UE; a processing module, configured to perform user authentication on the first user; A sending module is configured to send a fourth response to the second network function according to the result of the user authentication; the fourth response is used to indicate whether the user authentication of the first user is passed.

36. A first user equipment UE, wherein: The first UE includes: a sending module configured to send a second request to the first network function; the second request is used by the first user equipment UE to request user authentication of the first user; The receiving module is configured to receive a second response sent by the first network function; the second response is used to indicate whether the first user passes the user authentication.

37. A communication system, wherein: include: a first network function, configured to perform the method according to any one of claims 1 to 10; a second network function, configured to perform the method according to any one of claims 11 to 20; a third network function, configured to perform the method according to any one of claims 21 or 26; The first user equipment UE is configured to execute the method according to any one of claims 27 to 32.

38. A communication device, wherein: The communication device comprises: one or more processors; The processor is configured to call instructions to enable the communication device to execute the user authentication method according to any one of claims 1 to 10, 11 to 20, 21 or 26, and / or 27 to 32.

39. A storage medium, wherein: The storage medium stores instructions, which, when executed on a communication device, enable the communication device to execute the user authentication method described in any one of claims 1 to 10, 11 to 20, 21 or 26, and / or 27 to 32.

40. A program product comprising a computer program, which, when executed by a communication device, causes the communication device to execute the user authentication method according to any one of claims 1 to 10, 11 to 20, 21 or 26, and / or 27 to 32.