Authentication method and device

CN121128204APending Publication Date: 2025-12-12GUANGDONG OPPO MOBILE TELECOMMUNICATIONS CORP LTD
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
CN202480029499.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Priority Date
2023-05-06
Filing Date
2024-05-06
Publication Date
2025-12-12

AI Technical Summary

Technical Problem

In the prior art, when the zero-power consumption device (A-IoT device) is authenticated with the network side, the computing complexity is high, making it difficult to realize an effective authentication process, especially during the access process of the core network.

Method used

The first device sends a response message to the core network side device, uses the shared key to calculate the target verification code, and authenticates with the target device, reducing the computing burden of the second device and realizing proxy authentication.

Benefits of technology

It effectively reduces the computing complexity of A-IoT devices, simplifies the authentication process with the network side, and ensures that the core network side devices can perform effective device authentication.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121128204A_ABST
    Figure CN121128204A_ABST
Patent Text Reader

Abstract

The invention relates to an authentication method and device, a computer readable storage medium, a computer program product and a computer program. The method comprises the steps that a first device sends a first message to a core network side device, the first message carries a first response, and the first response is used for the core network side device to execute authentication related to one or more second devices.
Need to check novelty before this filing date? Find Prior Art

Description

Authentication methods and equipment

[0001] This application is based on PCT application No. PCT / CN2023 / 092600 and filed on May 6, 2023, and claims the priority of that PCT application. The entire contents of that PCT application are hereby incorporated into this application by reference in their entirety. Technical Field

[0002] The present application relates to the field of communications, and more particularly, to an authentication method, device, computer-readable storage medium, computer program product, and computer program. Background Art

[0003] In related technologies, the authentication and key negotiation processes between UE (User Equipment) and the core network use highly complex computational functions and key architectures. However, zero-power devices, such as A-IoT devices, also need to access networks such as the core network. Therefore, how to enable A-IoT devices to authenticate with the network while reducing their computational complexity becomes a challenge.

[0004] Summary of the Invention

[0005] Embodiments of the present application provide an authentication method, device, computer-readable storage medium, computer program product, and computer program.

[0006] This embodiment of the present application provides an authentication method, including:

[0007] The first device sends a first message to the core network side device, wherein the first message carries a first response, and the first response is used by the core network side device to perform authentication related to one or more second devices.

[0008] This embodiment of the present application provides an authentication method, including:

[0009] A core network side device receives a first message from a first device, wherein the first message carries a first response, and the first response is used by the core network side device to perform authentication related to one or more second devices.

[0010] This embodiment of the present application provides an authentication method, including:

[0011] The first device receives a second message from a core network side device, wherein the second message carries one or more first message authentication codes for authenticating the core network side device.

[0012] This embodiment of the present application provides an authentication method, including:

[0013] The core network side device sends a second message to the first device, wherein the second message carries one or more first message authentication codes for authenticating the core network side device.

[0014] This embodiment of the present application provides an authentication method, including:

[0015] The first device calculates a target verification code for authenticating the first device based on a third shared key shared with the target second device;

[0016] The first device sends a third message to the target second device, wherein the third message carries the target verification code.

[0017] This embodiment of the present application provides an authentication method, including:

[0018] The target second device receives a third message from the first device, wherein the third message carries a target verification code for authenticating the first device, and the target verification code is related to a third shared key shared by the target second device and the first device;

[0019] The target second device authenticates the first device based on the target check code and the target verification code.

[0020] This embodiment of the present application provides an authentication method, including:

[0021] The first device receives a fourth message from the target second device, wherein the fourth message carries a third response for authenticating the target second device, and the third response is related to a third shared key shared by the target second device and the first device;

[0022] The first device authenticates the target second device based on the third response and a third expected response.

[0023] This embodiment of the present application provides an authentication method, including:

[0024] The target second device sends a fourth message to the first device, wherein the fourth message carries a third response for authenticating the target second device, and the third response is related to a third shared key shared by the target second device and the first device.

[0025] An embodiment of the present application provides a first device, including:

[0026] The first communication unit is used to send a first message to a core network side device, wherein the first message carries a first response, and the first response is used by the core network side device to perform authentication related to one or more second devices.

[0027] An embodiment of the present application provides a core network side device, including:

[0028] The second communication unit is used to receive a first message from a first device, wherein the first message carries a first response, and the first response is used by the core network side device to perform authentication related to one or more second devices.

[0029] An embodiment of the present application provides a first device, including:

[0030] The first communication unit is used to receive a second message from a core network side device, wherein the second message carries one or more first message authentication codes for authenticating the core network side device.

[0031] An embodiment of the present application provides a core network side device, including:

[0032] The second communication unit is used to send a second message to the first device, wherein the second message carries one or more first message authentication codes for authenticating the core network side device.

[0033] An embodiment of the present application provides a first device, including:

[0034] a first processing unit, configured to calculate a target verification code for authenticating the first device based on a third shared key shared with a target second device;

[0035] The first communication unit is configured to send a third message to the target second device, wherein the third message carries the target verification code.

[0036] An embodiment of the present application provides a target second device, including:

[0037] a third communication unit, configured to receive a third message from the first device, wherein the third message carries a target verification code for authenticating the first device, and the target verification code is related to a third shared key shared by the target second device and the first device;

[0038] The third processing unit is configured to authenticate the first device based on a target check code and the target verification code.

[0039] An embodiment of the present application provides a first device, including:

[0040] a first communication unit, configured to receive a fourth message from a target second device, wherein the fourth message carries a third response for authenticating the target second device, and the third response is related to a third shared key shared by the target second device and the first device;

[0041] The first processing unit is configured to authenticate the target second device based on the third response and a third expected response.

[0042] An embodiment of the present application provides a target second device, including:

[0043] The third communication unit is configured to send a fourth message to the first device, wherein the fourth message carries a third response for authenticating the target second device, and the third response is related to a third shared key shared by the target second device and the first device.

[0044] By adopting the solution provided in this embodiment, the first device can send a first response to cause the core network device to perform authentication related to each second device. In this way, the first device can authenticate the second device with the network on behalf of the second device. While ensuring that the core network device can authenticate the second device, it avoids performing complex calculations on the second device, reducing the computational burden on the second device. BRIEF DESCRIPTION OF THE DRAWINGS

[0045] FIG1 is a schematic diagram of an application scenario according to an embodiment of the present application.

[0046] FIG2 is a schematic flowchart of an authentication method according to an embodiment of the present application.

[0047] FIG3 is a schematic flowchart of an authentication method according to another embodiment of the present application.

[0048] FIG4 is a schematic diagram of a scenario architecture of an authentication method according to an embodiment of the present application.

[0049] FIG5a, FIG5b to FIG11 are schematic diagrams of various example processes of an authentication method according to an embodiment of the present application.

[0050] FIG12 is a schematic flowchart of an authentication method according to an embodiment of the present application.

[0051] FIG13 is a schematic flowchart of an authentication method according to another embodiment of the present application.

[0052] FIG14 is a schematic flowchart of yet another authentication method according to an embodiment of the present application.

[0053] FIG15 is a schematic flowchart of an authentication method according to another embodiment of the present application.

[0054] FIG16 is a schematic flowchart of another authentication method according to an embodiment of the present application.

[0055] FIG17 is a schematic flowchart of yet another authentication method according to another embodiment of the present application.

[0056] FIG18 is a schematic block diagram of a first device according to an embodiment of the present application.

[0057] Figure 19 is a schematic block diagram of a core network side device according to an embodiment of the present application.

[0058] FIG20 is a schematic block diagram of a target second device according to an embodiment of the present application. DETAILED DESCRIPTION

[0059] The technical solutions of the embodiments of the present application can be applied to various communication systems, such as: GSM, CDMA, WCDMA, GPRS, LTE, LTE-A, NR, NR evolution, WLAN, WiFi, or other communication systems.

[0060] The embodiments of the present application describe various embodiments in conjunction with network devices and terminals. The terminals can be mobile or fixed, and can also be referred to as mobile stations, user units, etc. The terminal can be a site in a WLAN, and can be a smart terminal, wireless modem, laptop computer, tablet computer, or other terminal. In the embodiments of the present application, the terminal can be a VR terminal / AR terminal, an industrial control terminal, an unmanned driving terminal, a telemedicine terminal, a smart grid terminal, a transportation safety terminal, a smart city terminal, or a wireless terminal for a smart home, etc. As an example and not a limitation, in the embodiments of the present application, the terminal can also be a wearable device.

[0061] In the embodiment of the present application, the network device may be a device for communicating with a terminal, and the network device may be an access point in WLAN, a base station in GSM, CDMA, or WCDMA, an evolved base station in LTE, or a relay station, or a network device (gNB) in an in-vehicle device, a wearable device, and an NR network, or a network device in a future evolved PLMN network, or a network device in a non-terrestrial network, etc. As an example and not a limitation, in the embodiment of the present application, the network device may have a mobile feature, for example, the network device may be a mobile device.

[0062] To facilitate understanding of the technical solutions of the embodiments of the present application, the relevant technologies of the embodiments of the present application are described below. The following relevant technologies can be arbitrarily combined with the technical solutions of the embodiments of the present application as optional solutions, and they all fall within the protection scope of the embodiments of the present application.

[0063] Figure 1 exemplarily illustrates a communication system 100. The communication system includes a network device 110 and two terminals 120. In one possible implementation, the communication system 100 may include multiple network devices 110, and each network device 110 may include a different number of terminals 120 within its coverage area, although this embodiment of the present application does not limit this. In one possible implementation, the communication system 100 may also include a mobility management entity, access and mobility management functions, and other network entities, although this embodiment of the present application does not limit this. The network devices may include access network devices and core network devices. That is, the communication system may also include multiple core networks for communicating with the access network devices. The access network devices may be base stations of LTE, LTE-A, or NR systems. Taking the communication system shown in Figure 1 as an example, the communication devices may include network devices and terminals with communication functions. The communication devices may also include other devices in the communication system, such as network controllers, mobility management entities, and other network entities, although this embodiment of the present application does not limit this.

[0064] Figure 2 is a schematic flow chart of an authentication method according to an embodiment of the present application. The method includes at least part of the following contents.

[0065] S210. The first device sends a first message to the core network side device, wherein the first message carries a first response, and the first response is used by the core network side device to perform authentication related to one or more second devices.

[0066] Figure 3 is a schematic flow chart of an authentication method according to another embodiment of the present application. The method includes at least part of the following contents.

[0067] S310. A core network side device receives a first message from a first device, where the first message carries a first response, and the first response is used by the core network side device to perform authentication related to one or more second devices.

[0068] The first device includes at least one of the following: a terminal device, a first access network device. The second device is an ambient IoT (AIoT) device. In some possible examples, any second device can also be a zero-power device, for example, an active zero-power device, a passive zero-power device, a semi-passive zero-power device, etc. Optionally, the second device can be called a tag. In other possible examples, the second device can be a terminal with lower computing power. All possible names or possible devices of the second device are not exhaustively listed here.

[0069] Exemplarily, the one or more second devices may be connected to the core network through an indirect mode. In this mode, one or more second devices are connected to the core network through a terminal device and a first access network device corresponding to the terminal device. In this case, the first device is the terminal device, or the first device may be the first access network device corresponding to the terminal device. Exemplarily, the one or more second devices may be connected to the core network through a direct mode. In this mode, one or more second devices are connected to the core network through a corresponding first access network device. In this case, the first device is the first access network device. In addition, when the first device is a terminal device, the first device may be a proxy UE or a relay UE, etc.

[0070] The core network side device may include one or more core network devices; the one or more core network devices may include at least one of the following: AUSF, UDM (Unified Data Management Function), ARPF (Authentication Credential Repository and Processing Function), AMF, UPF, SEAF, and AIOT network element. It should be understood that this is only an example. In actual processing, the one or more core network devices may also include other core network devices, but this is not an exhaustive list.

[0071] In some possible embodiments, on the first device side, the method further includes: the first device calculates the first response based on at least one shared key, wherein the at least one shared key includes at least one of the following: one or more first shared keys, a second shared key, different first shared keys among the one or more first shared keys are shared by different second devices with the first device and the core network side device, and the second shared key is shared by the first device and the core network side device.

[0072] Furthermore, the first device calculating the first response based on at least one shared key may include: the first device calculating the first response based on identifications of one or more second devices and at least one shared key.

[0073] Optionally, the first device may further calculate the first response based on the identifiers of one or more second devices, at least one shared key, and at least one of the following parameters: an identifier of the first device, an identifier of the first network device, and at least one random number. This is not intended to limit or exhaustively list all possible parameters that may be used to calculate the first response.

[0074] Here, the first response may be a first RES (Response).

[0075] Different second devices in the one or more second devices correspond to different first shared keys in the one or more first shared keys. The different first shared keys in the one or more first shared keys are shared by different second devices in the one or more second devices, the first device, and the core network side device. Here, each second device, the first device, and the core network side device may have already stored the corresponding first shared key before performing the authentication process (i.e., S201 and S301).

[0076] Exemplarily, the first shared key corresponding to any second device is shared by the second device, the first device, and the core network side device. The first shared key corresponding to any second device can be at least one of a pre-shared key, a pre-distributed key, a private network key, an application layer key, a physical layer key, and a physical unclonable function (PUF) key.

[0077] For example, the first shared key corresponding to any second device can be the root key corresponding to that second device. The above root key is for illustrative purposes only. In actual processing, as long as the same key is shared by any second device, the first device, and the core network device, it is protected by this embodiment. This example does not limit the specific generation, distribution, or configuration method of the root key.

[0078] For example, any first shared key is not a root key of the second device, and the any first shared key may be an intermediate shared key corresponding to any second device. In this case, the processing of the first device may further include: the first device receiving one or more first shared keys.

[0079] For example, the intermediate shared key corresponding to any second device can be obtained through negotiation between any second device and the core network device. The core network device then uses the intermediate shared key as the first shared key and sends the first shared key corresponding to the second device to the first device via the first network device, which then stores the key. In other words, the first device receives one or more first shared keys from the first network device. Correspondingly, the first network device sends the one or more first shared keys to the first device.

[0080] Taking any second device as the i-th second device (i is a positive integer) as an example, the i-th second device shares a root key with the core network side device, and the first device does not share the root key. The i-th second device and the core network side device can derive the intermediate shared key of the i-th second device based on the root key of the i-th second device. The core network side uses the intermediate shared key of the i-th second device as the first shared key of the i-th second device and sends the first shared key of the i-th second device to the first device through the first network device. Correspondingly, the first device can receive the first shared key of the i-th second device from the first network device. In this way, the first shared key of the i-th second device is a key shared by the i-th second device, the core network side device, and the first device.

[0081] Among them, the first network device includes one of the following: AUSF, authentication device, and the authentication device includes one of the following: second access network device, AMF, SEAF, UPF, service server, AIoT network element.

[0082] In some possible examples, the first network device may be a first core network device in a core network-side device. For example, the first core network device may be any one of an AUSF, an AMF, an UPF, a SEAF, an AIOT network element, and the like. For another example, the first core network device may be an authentication device deployed in the core network. In this case, the authentication device may be an AIoT network element deployed in the core network and / or a service server deployed in the core network. The service server may be a server serving AIoT services, and the service server may be deployed on the core network side as a core network element. The AIOT network element may refer to any one of a core network element with AIOT service functions, a core network element with AIOT functions, or a core network element serving AIOT functions. It should be understood that the AIOT network element may be a separate core network element specifically configured to serve AIOT functions, or an existing core network element with AIOT functions added. This embodiment does not exhaustively enumerate all possible scenarios.

[0083] In some possible examples, the first network device is an authentication device, which may be a device with AIOT functionality, or a device dedicated to AIOT authentication functionality, or a device dedicated to AIOT certification functionality. For example, the authentication device is an Authenticator, or an AIOT authentication device (i.e., A-IoT Authenticator). The authentication device may be deployed in the core network, that is, the first network device may be the first core network device in the core network side device, or the first network device may be an authentication device not deployed in the core network. Alternatively, the first network device may be a second access network device, and the second access network device may be an access network device with AIoT authentication functionality. Alternatively, the first network device may be a service server, which is not deployed in the core network, but is a server that can access the core network and serves AIOT services, or is called an AIoT server.

[0084] In the above example, this embodiment does not limit the method for generating the intermediate shared key. It can be calculated using a specified key calculation method based on a random number and the root key of the second device, or it can be obtained using other methods. As long as the i-th second device and the core network side device can obtain the same intermediate shared key, it is within the scope of protection of this embodiment. It should also be understood that the parameters for deriving the intermediate shared key do not need to use the root key. As long as the process of deriving the intermediate shared key uses a key that is shared only by the i-th second device and the core network side device and not shared by the first device, it is within the scope of protection of this embodiment.

[0085] The second shared key may be at least one of a pre-assigned second shared key, a private network second shared key, an application layer second shared key, a physical layer second shared key, a PUF second shared key, a root key of the first device, and other keys derived from the root key of the first device. This embodiment does not limit the method for obtaining, generating, or obtaining the second shared key. As long as the second shared key can be stored in both the first device and the core network side device before executing the authentication method provided by this embodiment, it is within the scope of protection of this embodiment.

[0086] In some possible implementations, the first device calculates the first response based on at least one shared key, including: the first device calculates the first response based on the identifiers of the one or more second devices and the one or more first shared keys, wherein the first response is used by the core network side device to authenticate the one or more second devices.

[0087] Optionally, in addition to being used by the core network side device to authenticate the one or more second devices, the first response can also be used by the core network side device to authenticate the first device as an intermediate node for one or more second devices. The first device as an intermediate node for one or more second devices can also be alternatively referred to as the first device being a proxy device for one or more second devices, or the first device (such as UE) being a service binding device for one or more second devices, etc., which are not exhaustive here.

[0088] Optionally, the parameters used to calculate the first response may include, but are not limited to, the identifiers of one or more second devices and the one or more first shared keys. Exemplarily, the first device calculating the first response based on the identifiers of the one or more second devices and the one or more first shared keys may include: the first device calculating the first response based on the identifiers of the one or more second devices, the one or more first shared keys, and at least one of the following parameters: the identifier of the first device, the identifier of the first network device, and the second shared key.

[0089] This is only an example. In actual processing, more types of parameters can be used to calculate the first response. For example, one or more random numbers can be added. The function of the one or more random numbers can be to prevent replay attacks. The one or more random numbers may include: one or more first random numbers, one or more second random numbers, a third random number, one or more fourth random numbers, and so on. The specific usage or specific allocation method of the above types of random numbers are described below and are not exhaustive or limited here.

[0090] Exemplarily, in the process of calculating the first response, the first device may first calculate one or more intermediate keys, and then calculate the first response based on the one or more intermediate keys.

[0091] For example, the first device calculates one or more first intermediate keys based on one or more first shared keys, and calculates the first response based on the one or more first intermediate keys, the identification of one or more second devices and at least one of the following parameters: the identification of the first device, the identification of the first network device, the second shared key, one or more first random numbers, and a third random number.

[0092] For example, the first device calculates one or more second intermediate keys based on one or more first shared keys and at least one of the following parameters: the identification of the first network device, one or more fourth random numbers, and the second shared key; and calculates the first response based on one or more second intermediate keys, the identification of one or more second devices and at least one of the following parameters: the identification of the first device, the one or more first random numbers.

[0093] For example, the first device calculates a third intermediate key based on the second shared key, the identifier of the first network device and at least one of a third random number, and uses the first calculation method to calculate the first response based on the third intermediate key, the identifier of the one or more second devices, the one or more first shared keys and at least one of the following: the identifier of the first device, the one or more first random numbers.

[0094] For another example, the first device obtains a third intermediate key based on the second shared key, the identifier of the first network device, and at least one of a third random number, obtains one or more first intermediate keys based on one or more first shared keys, and calculates the first response based on the third intermediate key, the identifier of the one or more second devices, the one or more first intermediate keys, and at least one of the following: the identifier of the first device, the one or more first random numbers.

[0095] Exemplarily, in the process of calculating the first response by the first device, the first device may also first calculate one or more second responses, and then use the first calculation method to calculate the first response based on the one or more second responses, the identification of the one or more second devices, the one or more first shared keys and at least one of the following: the identification of the first device, the one or more first random numbers, the identification of the first network device, and the second shared key.

[0096] Exemplarily, in the process of calculating the first response by the first device, one or more first intermediate responses may be calculated first, and then the first response may be calculated based on the one or more first intermediate responses. For example, the first device calculates one or more first intermediate responses based on the identification of the one or more second devices, the one or more first shared keys, and at least one of the following: the identification of the first device, the second shared key, the one or more first random numbers, one or more second responses; and calculates the first response based on the one or more first intermediate responses. Calculating the first response based on the one or more first intermediate responses may be: calculating the first response based on the one or more first intermediate responses and at least one of the following: a third random number, the identification of the first network device. In this example, the first response may also be referred to as a group response.

[0097] In some embodiments, the first device calculates a first response based on the identification of the one or more second devices and the one or more first shared keys, including: the first device calculates the first response based on the identification of the one or more second devices, the one or more first shared keys, the identification of the first device, and one or more first random numbers.

[0098] The first device calculates the first response based on the identifiers of the one or more second devices, the one or more first shared keys, the identifier of the first device, and the one or more first random numbers, including one of the following: the first device calculates the first response based on the identifiers of the one or more second devices, the one or more first shared keys, the identifier of the first device, and the one or more first random numbers using a first calculation method; the first device obtains one or more intermediate keys based on the one or more first shared keys, and calculates the first response based on the identifiers of the one or more second devices, the one or more intermediate keys, the identifier of the first device, and the one or more first random numbers using the first calculation method; the first device calculates one or more first intermediate responses based on the identifiers of the one or more second devices, the one or more first shared keys, the identifier of the first device, and the one or more first random numbers, and calculates the first response based on the one or more first intermediate responses.

[0099] In some possible examples, the first device may directly use the first shared key to calculate the first response.

[0100] The first device calculates the first response based on the identifiers of the one or more second devices, the one or more first shared keys, the identifier of the first device, and the one or more first random numbers using a first calculation method, including one of the following: the first device calculates the first response based on the one or more second responses, the identifiers of the one or more second devices, the one or more first shared keys, the identifier of the first device, and the one or more first random numbers using a first calculation method, and the one or more second responses are obtained based on the one or more second random numbers; the first device calculates the first response based on the second shared key, the identifiers of the one or more second devices, the one or more first shared keys, the identifier of the first device, and the one or more first random numbers using the first calculation method; the first device calculates the third intermediate key based on the second shared key, the identifier of the first network device, and the third random number, and calculates the first response based on the third intermediate key, the identifiers of the one or more second devices, the one or more first shared keys, the identifier of the first device, and the one or more first random numbers using the first calculation method.

[0101] The above-mentioned identification may include an ID and / or a network identification. For example, the ID may include but is not limited to at least one of the following: SUPI, 5G-GUTI, GPSI, Index (number), etc. For another example, the above-mentioned network identification may include at least one of: IP address, MAC (Media Access Control, Media Access Control) address, etc. It should be pointed out that for the sake of brevity, the ID is used as the identification for exemplary explanation below. The IDs involved below can be replaced with network identifications (IP addresses and / or MAC addresses), but they are not listed one by one.

[0102] The above-mentioned first calculation method may include at least one of the following: a first authentication function, a second authentication function, a third authentication function, a hash algorithm, Advanced Encryption Standard (AES), ACSON, SNOW 3G (Snow Third Generation, third generation mobile communication snow), ZUC (ZUChongzhi, Zu Chongzhi), XOR calculation, direct connection calculation, KDF. Among them, the first authentication function can be expressed as f1(), and the second authentication function can be expressed as f2(); the hash algorithm can be expressed as HASH(), and the hash algorithm can include HMAC-SHA-256 (Hash based Message Authentication Code-Secure Hash Algorithm-256, hash-based message authentication code secure hash algorithm 256), or other hash algorithms can also be used, which are not exhaustive in this embodiment. It should be understood that this is only an exemplary explanation. In actual processing, the first calculation method may also include more possibilities, such as a third key generation function (for example, it can be expressed as f3), a fourth key generation function (for example, it can be expressed as f4), a fifth key generation function (for example, it can be expressed as f5), etc. At least one, all possible calculation functions (or algorithms) of the first calculation method are not enumerated here.

[0103] In one example, when the number of second devices is one, the first device calculates the first response based on the identifier of the second device, the first shared key, the identifier of the first device, and the first random number using a first calculation method.

[0104] Taking the first shared key as the root key, the first calculation method as the hash algorithm, and the first device as the UE as an example, the above-mentioned calculation of the first response can be expressed by the following formula: RES'=HASH(Kr,AIoT ID,UE ID,NONCE1), wherein RES' represents the first response, HASH represents the hash algorithm, Kr is the first shared key, i.e., the root key, AIoT ID is the identifier of the second device, and UE ID is

[0105] The identifier of the first device, NONCE1 is the first random number. The above-mentioned hash algorithm can also be replaced by other algorithms or functions in the above-mentioned first calculation method, such as being replaced by the second authentication function. The above-mentioned processing can be calculated using the following formula: RES'=f2(Kr,AIoT ID,UE ID,NONCE1), where f2 represents the second authentication function. The meanings of other parameters in the formula are the same as those described above and will not be repeated here. The above-mentioned first shared key can also be any one of K, PSK (pre-shared key), PMK (Pairwise Master Key), etc., and the corresponding Kr in each formula example provided in this embodiment (including the following) can also be replaced by K, PSK, PMK, etc., which are not exhaustive here.

[0106] Taking the case where the first shared key is KAUSF-A (that is, the intermediate shared key KAUSF-A is used as the first shared key), the first calculation method is a hash algorithm, and the first device is a terminal device (such as UE) as an example, the processing of the first device calculating the first response can be expressed by the following formula: RES'=HASH(KAUSF-A, AIoT ID, UE ID, NONCE1), wherein KAUSF-A is the first shared key, and the meanings of other parameters in the formula are the same as those described above, so they will not be repeated. The above hash algorithm can also be replaced by the second authentication function in the above-mentioned first calculation method. For example, the following formula can be used for calculation: RES'=f2(KAUSF-A, AIoT ID, UE ID, NONCE1). The meanings of each content or parameter in the formula are the same as those described in the above example, so they will not be repeated. Specific examples of other calculation methods in the first calculation method that can also be replaced by the above HASH are not listed here one by one. In addition, in some possible examples, the above-mentioned first shared key can also be expressed as K AUSF-A , unless otherwise specified, KAUSF-A and K AUSF-A The meanings are the same and will not be repeated.

[0107] It should be understood that the above is a relevant explanation of the calculation formula for the first device being a UE as an example, and the above-mentioned first device can be not only a UE but also a first access network device. For example, taking the first device as an example of a gNB, the above-mentioned calculation of the first response can also be replaced by using any one of the following formulas for calculation: RES'=HASH(Kr,AIoT ID,gNB ID,NONCE1), RES'=f2(Kr,AIoT ID,gNB ID,NONCE1), RES'=HASH(KAUSF-A,AIoT ID,gNB ID,NONCE1), RES'=f2(KAUSF-A,AIoT ID,gNB ID,NONCE1).

[0108] The following examples involve the identification of the first device. If the UE ID is used as an example, the UE ID can be replaced with the identification of the first access network device, such as eNB ID, gNB ID, etc. For the sake of brevity, they are not described one by one.

[0109] When there are multiple second devices, the first device calculates the first response using a first calculation method based on the identifiers of the multiple second devices, the multiple first shared keys, the identifier of the first device, and the multiple first random numbers. When there are multiple second devices, the multiple second devices may belong to the same device group.

[0110] If there are multiple second devices, the device group consisting of these multiple second devices may share a common first random number. In this case, the first device calculates the first response using a first calculation method based on the identifiers of the multiple second devices, the multiple first shared keys, the identifier of the first device, and the first random number. For example, where each first shared key is a root key corresponding to each second device and the first calculation method includes a hash algorithm and an exclusive-OR algorithm, the first device calculates the first response using the first calculation method based on the identifiers of the multiple second devices, the multiple first random numbers, the multiple first shared keys, and the identifier of the first device. This can be expressed using the following formula:

[0111] RES' represents a first response, which may also be referred to as a first group response. In some possible examples, RES' may be represented as RES'-Group. N is an integer greater than or equal to 2, which may represent the total number of second devices included in a device group. Kr1 to Kr N Any Kr iIt can be the root key corresponding to the i-th second device, where i is an integer greater than or equal to 1 and less than or equal to N; AIoT ID-1 to AIoT ID-N are the identifiers of each second device in the N second devices, and UE ID represents the identifier when the first device is a terminal device. The meanings of other parameters in the formula are the same as those described above and are not repeated here. If the first device is a first access network device, such as a gNB, the above formula can also be expressed alternatively as:

[0112] The above AIoT ID-1 to AIoT ID-N can also be calculated using XOR or direct connection, for example:

[0113] (AIoT ID-1,…,AIoT ID-N)=(AIoT ID-1||AIoTID-2||…||AIoT ID-N), or,

[0114] In some other examples, any of the above Kr can also be replaced by any of the KAUSF-A, for example, the above formula is replaced by In the above formula, KAUSF-A1~KAUSF-A N Any KAUSF-A i It can be the first shared key corresponding to the i-th second device. The meaning of other contents in this formula is the same as in the previous example and is not repeated here. If the first device is a first access network device, such as a gNB, the above formula can also be expressed as:

[0115] It should be noted that when there are multiple second devices, different first random numbers among the one or more first random numbers may correspond to different second devices. That is, each second device in the device group consisting of the multiple second devices has its own corresponding first random number. In this case, the first device uses a first calculation method based on the identifiers of the multiple second devices, the multiple first shared keys, the identifier of the first device, and the multiple first random numbers to calculate the first response. Taking the example of each first shared key being the root key corresponding to each second device and the first calculation method including a hash algorithm and an XOR algorithm, the process of calculating the first response can be expressed using the following formula:

[0116] Among them, NONCE11...NONCE1 N The XOR calculation or direct connection calculation can be used between them, both of which are within the protection scope of this embodiment. NONCE11 to NONCE1 Nare the first random numbers corresponding to the N second devices. If it is a first access network device, such as a gNB, the above formula can also be expressed alternatively as:

[0117] The above are only possible examples in the scenario of multiple second devices. The algorithm shown in the above formula can also be replaced by other algorithms or functions in the aforementioned first calculation method, and they are not listed here exhaustively.

[0118] In one example, when the number of second devices is one, the first device calculates the first response based on the second response, the identifier of the second device, the first shared key, the identifier of the first device, and the first random number using a first calculation method.

[0119] The second response can be calculated based on a second random number, which can be sent by the core network device to the first device. For example, the second response can be represented as RES, and the calculation method for obtaining the second response can be: RES = f2(RAND), where RAND is the second random number. This is for illustrative purposes only. In actual processing, in addition to using the second random number, the second response can also be calculated using other shared keys between the first device and the core network device and the second random number. For example, it can be expressed as RES = f2(RAND, K), where K can be other shared keys between the first device and the core network device. This embodiment does not limit the method for obtaining or generating these other shared keys. In addition to the second authentication function shown in the example, the calculation method for the second response can also use other algorithms or functions, such as a hash algorithm, etc. The various possible generation algorithms or generation parameters for the second response are not exhaustively listed here. It should be noted that when the core network device sends the second random number to the first device, the first network device can send the second random number to the first device when the first network device is a core network device.

[0120] Taking the first shared key as the root key and the first calculation method as the hash algorithm as an example, the processing of the first device calculating the first response can be expressed by the following formula: RES'=HASH(Kr,AIoT ID,UE ID,RES,NONCE1), where RES is the aforementioned second response, and the meanings of other parameters in the formula are the same as those described above, so they will not be elaborated on. The above hash algorithm can also be replaced by other algorithms or functions in the first calculation method. For example, the hash algorithm can be replaced by the second authentication function, and the calculation formula can be replaced by: RES'=f2(Kr,AIoT ID,UE ID,RES,NONCE1), where f2() represents the second authentication function, and the meanings of other parameters in the formula are the same as those described above, so they will not be elaborated on. Specific examples of how the above hash algorithm can also be replaced by other algorithms or functions in the first calculation method are not listed here one by one.

[0121] Taking the first shared key as KAUSF-A and the first calculation method as a hash algorithm as an example, the first device can calculate the first response using the following formula: RES' = HASH(KAUSF-A, AIoT ID, UE ID, RES, NONCE1). The meaning of each element in the formula is the same as in the previous embodiment and is not repeated here. The above is only an example. In some more examples, the hash algorithm can also be replaced by the second authentication function or other algorithms or functions in the first calculation method, which are not described in detail in this embodiment.

[0122] When there are multiple second devices, the first device uses a first calculation method to calculate the first response based on multiple second responses, the identifiers of the multiple second devices, the multiple first shared keys, the identifier of the first device, and the one or more first random numbers.

[0123] The above-mentioned multiple second responses can be calculated based on the second random numbers corresponding to the multiple second devices respectively. Any second random number can be sent by the core network side device to the first device. The method of obtaining any second random number and the method of calculating any second response are the same as those in the previous embodiment and will not be repeated here.

[0124] Taking as an example a case where each first shared key is a root key corresponding to each second device, the first calculation method is a hash algorithm, and multiple second devices correspond to the same first random number, the first device calculates the first response, which can be expressed using the following formula:

[0125] Among them, RES1~RES NThe N second responses corresponding to the N second devices are the aforementioned second responses. The meanings of other contents in the formula are the same as those in the aforementioned embodiment and are not elaborated on.

[0126] The above-mentioned hash algorithm can also be replaced by other algorithms or functions in the first calculation method, such as the hash algorithm can be replaced by the second authentication function, etc., which are not listed here one by one, or the XOR calculation can be replaced by a direct calculation. The Kr of each second device in the above formula can also be replaced by the KAUSF-A of each second device. This embodiment does not elaborate on the possible replacement methods of the above formula one by one. In addition, a first random number in this example can also be replaced by a first random number corresponding to each second device, that is, the first device uses the first calculation method to calculate the first response based on multiple second responses, the identifiers of the multiple second devices, the multiple first random numbers, the multiple first shared keys, and the identifier of the first device, and will not be described in detail.

[0127] In one example, when the number of second devices is one, the first device calculates the first response based on the second shared key, the identifier of the second device, the first shared key, the identifier of the first device, and the first random number using the first calculation method.

[0128] Taking the first shared key as the root key and the first calculation method including the second authentication function and direct calculation as an example, the first device can calculate the first response using the following formula: RES'=f2(KAUSF-UE||Kr,AIoT ID,UE ID,NONCE1), where "||" represents direct calculation, KAUSF-UE is the second shared key taking the first device as UE as an example, and the remaining parameters are the same as those described in the above example and will not be repeated. The first calculation method can also be replaced by a hash function and direct calculation, for example, it can be expressed as: RES'=HASH(KAUSF-UE||Kr,AIoT ID,UE ID,NONCE1), and the various parameters in the formula are the same as those described in the above example and will not be repeated. Alternatively, the first calculation method can also be replaced by a hash function and XOR calculation, for example, it can be expressed as: in, Indicates exclusive OR calculation. The parameters in the formula are the same as those in the previous example and are not repeated here.

[0129] The first shared key in the above example can also be replaced by KAUSF-A. The above process can be expressed by the following formula: RES'=f2(KAUSF-UE||KAUSF-A, AIoT ID, UE ID, NONCE1), where "||" represents direct calculation. The parameters in the formula are the same as those in the above example and are not repeated here. The first calculation method in the above example can also be replaced by a hash function and XOR calculation, for example, it can be expressed as: The parameters in the formula are the same as those in the previous example and will not be repeated here.

[0130] In the above example, the second shared key KAUSF-UE, taking the first device as UE, can also be expressed as K AUSF-UE , unless otherwise specified, KAUSF-UE and K AUSF-UE In addition, the second shared key can also be replaced by the root key of the UE, such as Kr-UE, KrUE, or Kr UE Alternatively, the second shared key may be replaced by another key derived from the UE's root key, such as the CK (Ciphering Key) corresponding to the UE, or the IK (Integrity Key) corresponding to the UE, or KSEAF (which may be represented by K SEAF , or expressed as K SEAF-UE )etc.

[0131] If the first device is a first access network device, the corresponding second shared key may be KAUSF-gNB (or KAUSF-eNB, etc.). In addition, the second shared key may also be replaced by the root key of the first access network device, such as Kr-gNB, KrgNB, or Kr gNB Alternatively, the second shared key may be replaced by another key derived from the root key of the first access network device, such as the CK corresponding to the first access network device, or the IK corresponding to the first access network device, or KSEAF (which may be represented as K SEAF , or expressed as K SEAF -gNB) and so on.

[0132] For example, in the above examples, KAUSF-UE can be replaced by KAUSF-gNB, and UEID can be replaced by gNB ID. For example, RES'=f2(KAUSF-gNB||KAUSF-A,AIoT ID,gNB ID,NONCE1). RES' = HASH(KAUSF-gNB||Kr, AIoT ID, gNB ID, NONCE1), RES' = f2(KAUSF-gNB||Kr, AIoT ID, gNB ID, NONCE1). The UE ID mentioned in each of the following examples can be replaced with the gNB ID (or an identifier of the access network device such as the eNB ID) when the first device is the first access network device. The KAUSF-UE mentioned in each of the following examples can be replaced with the KAUSF-gNB (or the second shared key between the access network device such as the KAUSF-eNB and the core network) when the first device is the first access network device. For the sake of brevity, this description is not repeated below.

[0133] On the basis of the above example, the aforementioned second response can also be added, that is, the first device can use the first calculation method to calculate the first response based on the second shared key, the identifier of the first device, the identifier of the second device, the first random number, the second response and the first shared key. For example, the first calculation method includes a hash function and a direct calculation. The above processing can be expressed as RES'=HASH(KAUSF-UE||KAUSF-A,AIoT ID,UE ID,RES,NONCE1). The meaning of each parameter in the formula is the same as in the above example and is not repeated here. In each formula in the above example, KAUSF-UE can be replaced with KAUSF-gNB, and UEID can be replaced with gNB ID, and no repetition is given.

[0134] When there are multiple second devices, the first device uses the first calculation method to calculate the first response based on the second shared key, the identifiers of the multiple second devices, the multiple first shared keys, the identifier of the first device, and the one or more first random numbers.

[0135] Taking each first shared key as the root key corresponding to each second device, the first calculation method including the second authentication function and direct calculation, and multiple second devices corresponding to the same first random number as an example, the first device calculates the first response, which can be expressed by the following formula: RES'=f2(KAUSF-UE||Kr1||…||Kr N ,AIoT ID-1…AIoT ID-N,UE ID,NONCE1), where each parameter is the same as that in the previous example and will not be repeated. The first calculation method can also be replaced by a hash function and XOR calculation, for example, it can be expressed as:

[0136] in, = represents XOR calculation, and the parameters in the formula are the same as those in the previous example, and are not repeated here. The first shared keys in the above example can also be replaced by KAUSF-A, and are not repeated here.

[0137] On the basis of the above example, multiple second responses can be added. For example, if the first calculation method includes a hash function and a direct calculation, the above process can be expressed as RES'=f2(KAUSF-UE||Kr1||…||Kr N ,AIoT ID-1…AIoT ID-N,UE ID,RES1||…||RES N ,NONCE1), the meaning of each parameter in the formula is the same as that in the previous example and will not be repeated here.

[0138] It should be understood that the above is merely an exemplary description and does not exhaustively enumerate all possible combinations of the aforementioned first calculation method. As long as one or more algorithms or functions in the first calculation method can be used to calculate the first response, it is within the scope of protection of this embodiment.

[0139] In one example, when the number of second devices is one, the first device obtains a third intermediate key based on the second shared key, the identifier of the first network device, and a third random number, and calculates the first response based on the third intermediate key, the identifier of the second device, the first shared key, the identifier of the first device, and the first random number using the first calculation method.

[0140] The first device obtaining the third intermediate key based on the second shared key, the identifier of the first network device, and the third random number may include: the first device using a second calculation method to calculate the third intermediate key from the second shared key, the identifier of the first network device, and the third random number. The second calculation method may include a KDF; in some possible examples, the second calculation method may also include other calculation functions, such as any one of f3 (third key generation function), f4 (fourth key generation function), f5 (fifth key generation function), etc. This embodiment does not exhaustively enumerate all possible calculation functions of the second calculation method.

[0141] For example, the first device can calculate the third intermediate key using the following formula: KUE = KDF (KAUSF-UE, A-IoT authenticator ID, NONCE2), where KUE is the third intermediate key when the first device is a terminal device, KDF() is a KDF function or a KDF calculation function, KAUSF-UE is the second shared key, A-IoT Authenticator ID is the identifier of the aforementioned first network device, and NONCE2 is a third random number (the third random number can also be replaced by RAND). The above-mentioned KAUSF-UE can also be expressed as K AUSF-UE , the above KUE can also be expressed as K UE , unless otherwise specified, KAUSF-UE and K AUSF- UE Same meaning, KUE and K UE The meanings are the same and no repetition is given.

[0142] The first network device may specifically refer to an authentication device, such as an AIOT authentication device (i.e., A-IoT Authenticator). It should be understood that the first network device may also be an AUSF, and the A-IoT Authenticator ID may be replaced with the AUSF ID. Accordingly, the formula may be replaced with KUE=KDF(KAUSF-UE, AUSF ID, NONCE2), all within the scope of protection of this embodiment.

[0143] The third random number may be sent by the first network device to the first device. As long as the timing of sending the third random number occurs before executing S201 and S301, it is within the scope of protection of this embodiment. It should be noted that when the first network device sends the third random number to the first device, if the first network device is a core network device, the core network device may send the third random number to the first device. If the first network device is not a core network device, the first network device performs the process of sending the third random number.

[0144] Taking the first shared key as the root key and the first calculation method including the second authentication function and direct connection calculation as an example, the calculation of the first response by the above-mentioned first device can be expressed as: RES'=HASH(KUE||Kr,AIoT ID,UE ID,NONCE1), wherein KUE is the aforementioned third intermediate key, Kr represents the root key, and the meanings of the other parameters in this formula are the same as those in the aforementioned embodiment, and are not repeated here. Taking the first shared key as KAUSF-A and the first calculation method including the second authentication function and direct connection calculation as an example, the calculation formula for calculating the first response can be expressed as RES'=f2(KUE||KAUSF-A,AIoT ID,UE ID,NONCE1), wherein KAUSF-A is the first shared key, and the meanings of the other parameters are the same as those in the aforementioned other embodiments, and are not repeated here.

[0145] In the above examples, HASH and f2 can be replaced by any other algorithm or function in the first calculation method, and the direct connection algorithm can also be replaced by any other algorithm or function in the first calculation method, such as In addition, in the above example, a second response can also be added, for example, This is not an exhaustive list of all possible situations and combinations.

[0146] If the first device is the first access network device, the corresponding second shared key can be expressed as KAUSF-gNB (or KAUSF-eNB, etc.). In the above examples, KAUSF-UE in each formula can be replaced by KAUSF-gNB, UEID can be replaced by gNB ID, and each third intermediate key KUE can also be replaced by KgNB, or KeNB, etc. to represent the third intermediate key of the first access network device. For example, KgNB=KDF(KAUSF-gNB, A-IoT authenticator ID, NONCE2), KgNB=KDF(KAUSF-gNB, AUSF ID, NONCE2), etc.; accordingly, the formula for calculating the first response can also be replaced by RES'=HASH(KgNB||Kr,AIoT ID,gNB ID,NONCE1), RES'=f2(KgNB||KAUSF-A,AIoT ID,gNB ID,NONCE1), Any one of the above. The UE ID involved in each example below can be replaced by gNB ID (or identification of access network device such as eNB ID) when the first device is the first access network device. The KAUSF-UE involved in each example below can be replaced by KAUSF-gNB (or the second shared key between access network device such as KAUSF-eNB and core network) when the first device is the first access network device. In addition, the KUE involved in the following can be replaced by KgNB (or KeNB, etc.) when the first device is the first access network device. For the sake of brevity, no repeated explanation will be given below.

[0147] When there are multiple second devices, the first device obtains a third intermediate key based on the second shared key, the identifier of the first network device, and the third random number, and calculates the first response using the first calculation method based on the third intermediate key, the identifiers of the multiple second devices, the multiple first shared keys, the identifier of the first device, and the one or more first random numbers. The method by which the first device obtains the third intermediate key based on the second shared key, the identifier of the first network device, and the third random number is the same as in the previous embodiment and is not further described.

[0148] Taking the case where each first shared key is a root key corresponding to each second device, the first calculation method includes a second authentication function and direct calculation, and multiple second devices correspond to the same first random number, the first device calculates the first response, which can be expressed as: RES'=HASH(KUE||Kr1...||Kr N , AIoT ID-1…AIoT ID-N, UE ID, NONCE1), where KUE is the aforementioned third intermediate key. The meanings of other parameters in this formula are the same as those in the aforementioned embodiment and are not repeated here. In the above example, each root key can also be replaced by KAUSF-A, and the first calculation method includes the second authentication function and direct connection calculation as an example. The calculation formula of the above first response can be expressed as RES'=f2(KUE||KAUSF-A1…||KAUSF-A N ,AIoT ID-1…AIoT ID-N UE ID,NONCE1), the meanings of the parameters in the formula are the same as those in the other aforementioned embodiments and are not repeated here.

[0149] In each of the above examples, HASH and f2 can be replaced by any other algorithm or function in the first calculation method, and the direct connection algorithm can also be replaced by any other algorithm or function in the first calculation method. This does not exhaustively enumerate all possible situations and combinations. In addition, the first random number in this example can also be replaced by the first random number corresponding to each second device, and will not be further described.

[0150] In some possible examples, the first device may use the first shared key to calculate a first intermediate key, and then calculate the first response based on the first intermediate key.

[0151] The first device obtains one or more intermediate keys based on the one or more first shared keys, and calculates the first response using the first calculation method based on the identifiers of the one or more second devices, the one or more intermediate keys, the identifier of the first device, and the one or more first random numbers, including one of the following:

[0152] The first device obtains one or more first intermediate keys based on the one or more first shared keys, and calculates the first response using a first calculation method based on one or more second responses, the identifiers of the one or more second devices, the one or more first intermediate keys, the identifier of the first device, and the one or more first random numbers, wherein the one or more second responses are obtained based on the one or more second random numbers;

[0153] The first device obtains one or more first intermediate keys based on the one or more first shared keys, and calculates the first response using the first calculation method based on a second shared key, the identifiers of the one or more second devices, the one or more first intermediate keys, the identifier of the first device, and the one or more first random numbers, wherein the second shared key is shared by the first device and the core network side device;

[0154] The first device calculates one or more second intermediate keys based on the one or more first shared keys, the identifier of the first network device, and the one or more fourth random numbers; and calculates the first response based on the identifiers of the one or more second devices, the one or more second intermediate keys, the identifier of the first device, and the one or more first random numbers using the first calculation method;

[0155] The first device obtains a third intermediate key based on the second shared key, the identifier of the first network device, and a third random number, obtains one or more first intermediate keys based on one or more first shared keys, and calculates the first response based on the third intermediate key, the identifier of the one or more second devices, the one or more first intermediate keys, the identifier of the first device, and the one or more first random numbers using a first calculation method.

[0156] In one example, when the number of second devices is one, the first device obtains a first intermediate key based on the first shared key, and calculates the first response based on the second response, the identifier of the second device, the first intermediate key, the identifier of the first device, and the first random number using a first calculation method.

[0157] Here, the first device obtaining the first intermediate key based on the first shared key may include: if the first shared key is a root key, the first device calculating the first intermediate key based on the root key. In this case, the first shared key may be a root key, and the first intermediate key may be KAUSF-A'. The root key may be shared by the first device, the second device, and the core network device. Therefore, the first device and the core network device may obtain the same first intermediate key KAUSF-A' based on the root key using the same method. This example does not limit the calculation method for obtaining the first intermediate key based on the first shared key. For example, KAUSF-A' may be calculated using CK (encryption key) and IK (integrity key). The CK and IK may be derived from a root key shared by the core network device, the second device, and the first device. This embodiment does not limit the specific generation method of CK and IK. Alternatively, the first device obtaining the first intermediate key based on the first shared key may include: if the first shared key is not a root key, the first device calculating the first intermediate key based on the first shared key. In this case, the first shared key may be sent from the first network device to the first device, namely, the aforementioned KAUSF-A, and the first intermediate key may be KAUSF-A'. It should be noted that when the first network device sends the first shared key to the first device, if the first network device is a core network device, the first network device in the core network device may send the first shared key to the first device. If the first network device is not a core network device, the first network device performs the process of sending the first shared key.

[0158] For example, the above-mentioned process of obtaining the first intermediate key based on the first shared key can be expressed as KAUSF-A'=X(KAUSF-A), or KAUSF-A'=X(Kr), where X() can be a calculation function for obtaining the first intermediate key based on the first shared key. The calculation function can include but is not limited to at least one of KDF, f1, HASH, f2, f3, etc., and KAUSF-A' in the above formula can also be obtained in combination with other parameters, such as AK (anonymous key), other random numbers, other identifiers, etc. At least one, all possible parameters and algorithms (or functions) are not enumerated here.

[0159] Taking the first calculation method including a hash algorithm as an example, the first calculation method is used to calculate the first response based on the identifier of the first device, the first intermediate key, the identifier of the second device, and the first random number, which can be expressed as: RES'=HASH(KAUSF-A', A-IoT ID, UE ID, NONCE1).

[0160] If there are multiple second devices, the first device derives multiple first intermediate keys based on the multiple first shared keys and calculates the first responses using the first calculation method based on the multiple second responses, the identifiers of the multiple second devices, the multiple first intermediate keys, the identifier of the first device, and the one or more first random numbers. The process of deriving any first intermediate key based on any first shared key is the same as in the previous example and is not further described.

[0161] Taking the example where the first calculation method includes a hash algorithm and multiple second devices correspond to the same first random number, the calculation of the first response can be expressed as: In addition, the first random number in this example can also be replaced by the first random number corresponding to each second device, which will not be described in detail. It should also be noted that the calculation functions in each calculation formula in the above example can be replaced by other functions included in the first calculation method, and this embodiment does not list them one by one.

[0162] In one example, when there is only one second device, the first device derives a first intermediate key based on the first shared key, and calculates the first response using a first calculation method based on the second response, the identifier of the second device, the first intermediate key, the identifier of the first device, and the first random number. Derivation of the first intermediate key based on the first shared key may involve using a root key as the first shared key. The method for deriving the first intermediate key based on the first shared key is the same as in the previous embodiment and is not repeated here.

[0163] Taking the first calculation method as a hash algorithm as an example, the calculation of the first response can be expressed as: RES'=HASH(KAUSF-A', A-IoT ID, UE ID, RES, NONCE1), where KAUSF-A' is the first intermediate key. The meaning of the remaining contents in the formula is the same as that in the above embodiment, and the replaceable methods of the various contents in the formula are also the same as those in the above embodiment, and are not repeated here.

[0164] When there are multiple second devices, the first device obtains multiple first intermediate keys based on the multiple first shared keys, and calculates the first response based on multiple second responses, the identifiers of the multiple second devices, the multiple first intermediate keys, the identifier of the first device, and the one or more first random numbers using a first calculation method.

[0165] Taking the first calculation method as a hash algorithm and multiple second devices corresponding to the same first random number as an example, the calculation of the first response can be expressed as: The meaning of each content in the formula is the same as that in the above embodiment. In this example, a first random number can also be replaced by a first random number corresponding to each second device. The replacement method of each content in the formula is the same as that in the above embodiment and is not repeated here.

[0166] In one example, when the number of second devices is one, the first device obtains the first intermediate key based on the first shared key, and calculates the first response based on the second shared key, the identifier of the second device, the first intermediate key, the identifier of the first device, and the first random number using the first calculation method.

[0167] The specific description of how the first device obtains the first intermediate key based on the first shared key is the same as that in the above embodiment and is not repeated here.

[0168] Taking the first calculation method including the second authentication function and direct connection calculation as an example, the calculation of the first response can be expressed as: RES'=f2(KAUSF-UE||KAUSF-A', A-IoT ID, UE ID, NONCE1), where KAUSF-A' is the first intermediate key, and the meanings of the remaining parameters are the same as those in the aforementioned embodiment, and are not repeated; the f2() function in the above-mentioned first calculation method can also be replaced by HASH or other calculation methods in the first calculation method, and the above-mentioned direct connection calculation can also be replaced by XOR calculation, and all possible situations are not enumerated here. In the above example, a second response can also be added for calculation, such as RES'=f2(KAUSF-UE||KAUSF-A', A-IoT ID, UE ID, RES, NONCE1). The various possible combinations of this example are not enumerated here.

[0169] When there are multiple second devices, the first device obtains multiple first intermediate keys based on the multiple first shared keys, and uses the first calculation method to calculate the first response based on the second shared key, the identifiers of the multiple second devices, the multiple first intermediate keys, the identifier of the first device, and the one or more first random numbers.

[0170] Taking the first calculation method including the second authentication function and direct calculation, and multiple second devices corresponding to the same first random number as an example, the calculation of the first response can be expressed as: RES'=f2(KAUSF-UE||KAUSF-A'1...||KAUSF-A' N ,AIoT ID-1…AIoT ID-N,UE ID,NONCE1), in this formula, KAUSF-A' is the first intermediate key, and the meanings of the remaining parameters are the same as those in the aforementioned embodiment and are not repeated; the f2() function in the above-mentioned first calculation method can also be replaced by HASH or other calculation methods in the first calculation method, and the above-mentioned direct connection calculation can also be replaced by XOR calculation. All possible situations are not exhaustively listed here. In addition, a first random number in this example can also be replaced by the first random number corresponding to each second device; in the above example, a second response can also be added for calculation, such as RES'=f2(KAUSF-UE||KAUSF-A',A-IoT ID,UE ID,RES,NONCE1). The various possible combinations of this example are not exhaustively listed here.

[0171] In one example, when the number of second devices is one, the first device calculates a second intermediate key based on the first shared key, the identifier of the first network device and one or more fourth random numbers; and calculates the first response based on the identifier of the second device, the second intermediate key, the identifier of the first device and the first random number using the first calculation method.

[0172] For example, the first device calculates the second intermediate key based on the first shared key, the identifier of the first network device and the fourth random number, which may mean that the first device uses the second calculation method to calculate the second intermediate key based on the first shared key, the identifier of the first network device and the fourth random number.

[0173] Taking the above-mentioned first shared key as KAUSF-A and the second calculation method as KDF as an example, the first device calculates the second intermediate key, which can be expressed as KA-IoT=KDF(KAUSF-A, A-IoT authenticator ID, nonce3), where KA-IoT can represent the second intermediate key corresponding to the second device, KAUSF-A is the first shared key, and nonce3 is the fourth random number. The meaning of other contents in the formula is the same as that of the above embodiment and will not be repeated. For example, the above-mentioned KA-IoT can also be expressed as K A-IoTTaking the above-mentioned first shared key as the root key and the second calculation method as KDF as an example, the first device calculates the second intermediate key, which can be expressed as KA-IoT = KDF (Kr, A-IoT authenticator ID, nonce3). The meaning of other contents in the formula is the same as that of the previous embodiment and is not repeated here.

[0174] Taking the first calculation method, specifically f2, as an example, the above calculation of the first response can be expressed as: RES' = f2(KA-IoT, A-IoT ID, UE ID, NONCE1). The meaning of each content in this formula is the same as in the previous embodiment and is not repeated here. A second response can also be added to this calculation. For example, the above formula can be expressed as RES' = f2(KA-IoT, A-IoT ID, UE ID, RES, NONCE1), where RES represents the second response. The specific description is the same as in the previous embodiment and is not repeated here.

[0175] In addition, in addition to the above-mentioned A-IoT authenticator, the first network device can also be a core network device such as AUSF, AMF, SEAF, AIoT network element, UPF, etc. Therefore, the above-mentioned AIoT Authenticator ID can also be replaced by at least one of AUSF ID, AMFID, SEAF ID, AIoT network element ID, UPF ID, etc., for example, KA-IoT=KDF(Kr, AMF ID, nonce3), or, KA-IoT=KDF(KAUSF-A, AMF ID, nonce3), etc., and all possible situations are not enumerated here.

[0176] For example, the first device calculates the second intermediate key based on the first shared key, the identifier of the first network device and the fourth random number, which may refer to: the first device obtains the first intermediate key based on the first shared key, and calculates the second intermediate key based on the first intermediate key, the identifier of the first network device and the fourth random number using the second calculation method. Taking the above-mentioned first shared key as the root key as an example, the first device obtains the first intermediate key based on the first shared key, which may refer to obtaining KAUSF-A' based on Kr. The relevant examples are the same as those in the aforementioned embodiment and are not repeated. Alternatively, taking the first shared key as KAUSF-A as an example, the first device obtains the first intermediate key based on the first shared key, which may refer to obtaining KAUSF-A' based on KAUSF-A. The relevant examples are the same as those in the aforementioned embodiment and are not repeated. Correspondingly, taking the second calculation method as KDF as an example, the second intermediate key is calculated based on the first intermediate key, the identifier of the first network device and the fourth random number using the second calculation method, which can be expressed as KA-IoT = KDF (KAUSF-A', A-IoT authenticator ID, nonce3), where KAUSF-A' is the first intermediate key. The meaning of other contents in the formula is the same as in the previous embodiment and will not be repeated here.

[0177] When there are multiple second devices, the first device calculates multiple second intermediate keys based on the multiple first shared keys, the identifier of the first network device and multiple fourth random numbers; and calculates the first response using the first calculation method based on the identifiers of the multiple second devices, the multiple second intermediate keys, the identifier of the first device, and the one or more first random numbers.

[0178] For example, taking any one of the above-mentioned multiple second devices as the i-th second device, the first shared key of the i-th second device is KAUSF-Ai, and the second calculation method is KDF as an example, the first device uses the second calculation method to calculate the i-th second intermediate key (i.e., the second intermediate key of the i-th second device) based on the i-th first shared key, the identifier of the first network device and the i-th fourth random number, which can be expressed as KA-IoT-i = KDF (KAUSF-Ai, A-IoT authenticator ID, nonce3i), where KA-IoT-i can represent the i-th second intermediate key corresponding to the i-th second device, KAUSF-Ai is the i-th first shared key (i.e., the first shared key of the i-th second device), and nonce3i represents the fourth random number corresponding to the i-th second device. The meaning of other contents in the formula is the same as that in the previous embodiment and will not be repeated.

[0179] Taking any one of the above-mentioned multiple second devices as the i-th second device, the first shared key of the i-th second device is Kri, and the second calculation method is KDF as an example, the first device uses the second calculation method to calculate the i-th second intermediate key (i.e., the second intermediate key of the i-th second device) based on the i-th first shared key, the identifier of the first network device and the i-th fourth random number, which can be expressed as KA-IoTi=KDF(Kri, A-IoT authenticator ID, nonce3i), where the meaning of other contents in the formula is the same as in the previous embodiment and will not be repeated.

[0180] In addition, in addition to the above-mentioned A-IoT authenticator, the first network device can also be a core network device such as AUSF, AMF, SEAF, AIoT network element, UPF, etc. Therefore, the above-mentioned AIoT Authenticator ID can also be replaced by at least one of AUSF ID, AMFID, SEAF ID, AIoT network element ID, UPF ID, etc., for example, KA-IoT-i=KDF(Kri, AMF ID, nonce3i), or, KA-IoT-i=KDF(KAUSF-Ai, AMF ID, nonce3i), etc., and all possible situations are not enumerated here.

[0181] Taking the first calculation method as f2 and multiple second devices corresponding to the same first random number as an example, the calculation of the first response can be expressed as: Among them, KA-IoT-1 to KA-IoT-N are the second intermediate keys corresponding to the N second devices, respectively. The meaning of each content in this formula is the same as in the previous embodiment and is not repeated here. It should also be noted that multiple second responses can be added to this calculation, and / or a first random number can be replaced by the first random number corresponding to each second device. The replacement method of each content in this formula is the same as in the previous embodiment and is not repeated here.

[0182] In one example, when the number of second devices is one, the first device obtains a third intermediate key based on the second shared key, the identifier of the first network device, and a third random number, and obtains the first intermediate key based on the first shared key; and calculates the first response based on the third intermediate key, the identifier of the second device, the first intermediate key, the identifier of the first device, and the first random number using a first calculation method.

[0183] The manner in which the first device obtains the third intermediate key based on the second shared key, the identifier of the first network device, and the third random number has been described in detail in the previous embodiment and is not repeated here. The specific manner in which the first intermediate key is obtained based on the first shared key is the same as in the previous embodiment and is not repeated here.

[0184] Taking the first calculation method as f2 as an example, the calculation of the first response can be expressed as: RES'=f2(KUE||KAUSF-A', A-IoT ID, UE ID, NONCE1), where KAUSF-A' is the first intermediate key. The alternative methods of other contents in the formula are the same as those in the previous embodiment and are not repeated here.

[0185] When there are multiple second devices, the first device obtains a third intermediate key based on the second shared key, the identifier of the first network device, and a third random number, and obtains multiple first intermediate keys based on multiple first shared keys; and calculates the first response based on the third intermediate key, the identifiers of the multiple second devices, the multiple first intermediate keys, the identifier of the first device, and the one or more first random numbers using a first calculation method.

[0186] The manner in which the first device obtains the third intermediate key based on the second shared key, the identifier of the first network device, and the third random number has been described in detail in the previous embodiment and is not repeated here. The specific manner in which the multiple first intermediate keys are obtained based on the multiple first shared keys is the same as in the previous embodiment and is not repeated here.

[0187] Taking the first calculation method as f2 and multiple second devices corresponding to the same first random number as an example, the calculation of the first response can be expressed as: RES'=f2(KUE||KAUSF-A'1…||KAUSF-A'N,(AIoT ID-1…AIoT ID-N),UE ID,NONCE1), where KAUSF-A'1~KAUSF-A'N are the first intermediate keys corresponding to N second devices respectively, and KUE is the third intermediate key. The meanings of the remaining contents in the formula are the same as those in the previous embodiment, and the replaceable methods of the various contents in the formula are also the same as those in the previous embodiment, and they will not be repeated here.

[0188] It should be pointed out that in the above examples, the first calculation method is illustrated by taking at least one of HASH, f2, direct connection algorithm, and XOR algorithm as an example, and they can all be replaced by the other various functions or algorithms in the above-mentioned first calculation method. For the sake of brevity, they are not listed one by one.

[0189] In some possible examples, the first shared key is used to obtain a first intermediate response, and then the first response is calculated based on the first intermediate response.

[0190] For example, the first device calculates one or more first intermediate responses based on the identifiers of the one or more second devices, the one or more first random numbers, the one or more first shared keys, and the identifier of the first device, and the first device calculates the first response based on the one or more first intermediate responses using the first calculation method. Calculating the first response based on the one or more first intermediate responses includes: the first device calculating the first response based on the one or more first intermediate responses and at least one of the following: the identifier of the first network device and a third random number using the first calculation method.

[0191] The first device calculates one or more first intermediate responses based on the identifiers of the one or more second devices, the one or more first shared keys, the identifier of the first device, and the one or more first random numbers, including one of the following:

[0192] The first device calculates the one or more first intermediate responses, respectively, using a first calculation method, based on the one or more second responses, the identifiers of the one or more second devices, the one or more first shared keys, the identifier of the first device, and the one or more first random numbers, where the one or more second responses are obtained based on the one or more second random numbers;

[0193] The first device calculates the one or more first intermediate responses respectively using the first calculation method based on the second shared key, the identifiers of the one or more second devices, the one or more first shared keys, the identifier of the first device, and the one or more first random numbers, wherein the second shared key is shared by the first device and the core network side device;

[0194] The first device calculates a third intermediate key based on the second shared key, the identifier of the first network device, and the third random number, and calculates the one or more first intermediate responses based on the third intermediate key, the identifiers of the one or more second devices, the one or more first intermediate keys, the identifier of the first device, and the one or more first random numbers using the first calculation method;

[0195] The first device obtains one or more first intermediate keys based on the one or more first shared keys, and calculates the one or more first intermediate responses based on the one or more second responses, the identifiers of the one or more second devices, the one or more first intermediate keys, the identifier of the first device, and the one or more first random numbers using a first calculation method.

[0196] The first device obtains one or more first intermediate keys based on the one or more first shared keys, and calculates the one or more first intermediate responses based on the second shared key, the one or more identifiers of the second device, the one or more first intermediate keys, the identifier of the first device, and the one or more first random numbers using the first calculation method.

[0197] The first device calculates one or more second intermediate keys based on the one or more first shared keys, the identifier of the first network device, and the one or more fourth random numbers; and calculates the one or more first intermediate responses based on the identifiers of the one or more second devices, the one or more second intermediate keys, the identifier of the first device, and the one or more first random numbers using the first calculation method, respectively;

[0198] The first device obtains a third intermediate key based on the second shared key, the identifier of the first network device, and a third random number, obtains one or more first intermediate keys based on the one or more first shared keys, and calculates the one or more first intermediate responses based on the third intermediate key, the identifiers of the one or more second devices, the one or more first intermediate keys, the identifier of the first device, and the one or more first random numbers using a first calculation method.

[0199] For example, when the number of second devices is one, taking the first shared key as the root key and the first calculation method as the hash algorithm, the first device uses the first calculation method based on the identifier of the second device, the first shared key, the identifier of the first device, and the first random number to calculate the first intermediate response, which can be expressed by the following formula: RES" = HASH(Kr, AIoT ID, UE ID, NONCE1), where RES" represents the first intermediate response. The meanings of other parameters in the formula are the same as those in the previous embodiment and are not repeated here.

[0200] For example, when the number of second devices is one, taking the first shared key as the root key and the first calculation method as the hash algorithm, the above-mentioned first device uses the first calculation method based on the second response, the identifier of the second device, the first shared key, the identifier of the first device, and the first random number to calculate the first intermediate response, which can be expressed by the following formula: RES" = HASH(Kr, AIoT ID, UE ID, RES, NONCE1), where RES" represents the first intermediate response, and the meanings of other parameters in the formula are the same as those in the previous embodiment and are not repeated here.

[0201] In general, when the number of second devices is one, the difference between the processing of this scenario and the example in which the first device calculates the first response in the aforementioned embodiment is that the first device uses the first response of a second device obtained in the above examples as the first intermediate response rather than the final first response. In order to distinguish it from RES' (first response) in the aforementioned embodiment, this example uses RES" to represent the first intermediate response. Regarding the various calculation methods that may be used to calculate the first response in the process of the first device calculating the first response of a second device in the aforementioned embodiment, they are all used to generate a first intermediate response of a second device in this embodiment, but they are not listed one by one.

[0202] The calculating of the first response based on the one or more first intermediate responses includes one of the following: the first device calculates the first response based on the one or more first intermediate responses, the identifier of the first network device, and a third random number using the first calculation method; the first device calculates the first response based on the one or more first intermediate responses and the identifier of the first network device using the first calculation method; the first device calculates the first response based on the one or more first intermediate responses and the third random number using the first calculation method.

[0203] When the number of second devices is one, the first device uses the first calculation method to calculate the first response based on the one or more first intermediate responses, the identifier of the first network device, and the third random number. It can be that the first device uses the first calculation method to calculate the first response based on the first intermediate response, the identifier of the first network device and the third random number.

[0204] Taking the first calculation method as a hash algorithm as an example, the above processing can be expressed as: RES'=HASH(RES', A-IoT authenticator ID, nonce2), where RES' has the same meaning as in the previous example and represents the first response, RES' represents the aforementioned first intermediate response, and the meaning of the remaining contents in the formula is the same as in the previous embodiment and will not be repeated.

[0205] The first device calculating the first response based on the one or more first intermediate responses and the identifier of the first network device using the first calculation method may include: the first device calculating the first response based on the first intermediate response and the identifier of the first network device using the first calculation method. Taking the first calculation method as the second authentication function as an example, the above processing can be expressed as RES'=f2(RES", A-IoT authenticator ID). The meaning of each content in the formula is the same as in the previous embodiment and is not repeated here.

[0206] The first device calculating the first response based on the one or more first intermediate responses and the third random number using the first calculation method may include: the first device calculating the first response based on the first intermediate response and the third random number using the first calculation method. Taking the first calculation method as an example of a hash algorithm, the above processing can be expressed as: RES'=HASH(RES",nonce2). The meaning of each content in the formula is the same as in the previous embodiment and is not repeated here.

[0207] The above description is directed to the manner in which the first device generates the first intermediate response of the second device and calculates the first response based on the first intermediate response when there is only one second device.

[0208] Next, a method is described in which, for a case where there are multiple second devices, the first device generates a first intermediate response for each of the multiple second devices and calculates the first response based on the first intermediate response of each second device.

[0209] In this case, the method for calculating the first intermediate response of each second device among the multiple second devices is also the same as the method for calculating the first response of any second device in the aforementioned embodiment.

[0210] For example, taking the i-th first shared key (the first shared key of the i-th second device) as the i-th root key and the first calculation method as the hash algorithm, the first device calculates the i-th first intermediate response based on the identifier of the i-th second device, the i-th first random number, the i-th first shared key, and the identifier of the first device using the first calculation method, which can be expressed by the following formula: RES"i=HASH(Kr i,AIoT ID-i,UE ID,NONCE1i), where RES"i represents the i-th first intermediate response (i.e., the first intermediate response of the i-th second device), NONCE1i is the i-th first random number, i.e., the first random number corresponding to the i-th second device. The meanings of other parameters in this formula are the same as those in the previous embodiment and are not repeated here.

[0211] For example, taking the i-th first shared key (the first shared key of the i-th second device) as the i-th root key and the first calculation method as the hash algorithm, the first device uses the first calculation method based on the second shared key, the identifier of the first device, the identifier of the i-th second device, the i-th first random number and the i-th first shared key to calculate the i-th first intermediate response, which can be expressed by the following formula: RES"i=f2(KAUSF-UE||Kr i ,AIoT ID-i,UE ID,NONCE1i), where “||” indicates direct connection calculation, and the remaining parameters are the same as those in the previous example and will not be repeated.

[0212] In general, when there are multiple second devices, the difference between the process of calculating the first intermediate response of any second device and the example of the first device calculating the first response of the second device in the aforementioned embodiment is that the first device uses the method of calculating the first response of a second device in the above examples to calculate the first intermediate response of any second device rather than the final first response. In order to distinguish it from RES' (first response) and RES" in the aforementioned embodiment, this example uses RES"i to represent the first intermediate response of the i-th second device. Regarding the various calculation methods that may be used to calculate the first response in the process of the first device calculating the first response of the second device in the aforementioned embodiment, they are all used to generate the first intermediate response of any second device in this embodiment and are not listed one by one here.

[0213] Furthermore, in the case where there are multiple second devices, an exemplary description is given of a manner in which the first device calculates the first response based on the first intermediate response of each of the multiple second devices.

[0214] Optionally, calculating the first response based on the one or more first intermediate responses may include: calculating the first response based on the multiple first intermediate responses. For example, the multiple first intermediate responses may be subjected to an exclusive OR calculation or a direct connection calculation to calculate the first response, which may be expressed as: RES”1-RES”N is the first intermediate response of each second device in the N second devices. For example, a combination of multiple calculation functions can be used for calculation. For example, the first response can be calculated by combining an exclusive OR calculation and a hash algorithm, which is expressed as follows: It should be understood that this is merely an exemplary description, and the above specific method of directly calculating the first response based on multiple first intermediate responses can also be implemented using one or more other algorithms and / or function combinations, which are not exhaustively listed here.

[0215] Optionally, the first device calculates the first response using the first calculation method based on the multiple first intermediate responses, the identifier of the first network device, and one or more third random numbers. The number of the third random numbers may also be one or more. In a preferred example, the third random number is one. Taking the example of the first calculation method including an XOR algorithm and a hash algorithm, the above processing can be expressed as: RES' has the same meaning as in the above example and represents the first response, RES" represents the above first intermediate response, and the rest of the meanings in the formula are the same as in the above embodiment and will not be repeated.

[0216] Optionally, the first device calculates the first response based on the multiple first intermediate responses and the identifier of the first network device using the first calculation method. Taking the first calculation method as the second authentication function as an example, the above processing can be expressed as The meanings of the various contents in the formula are the same as those in the above embodiment and will not be repeated.

[0217] Optionally, the first device calculates the first response based on the multiple first intermediate responses and the third random number using the first calculation method. Taking the first calculation method including a direct connection algorithm and a hash algorithm as an example, the above processing can be expressed as: RES'=HASH(RES"1||…||RES"N, nonce2). The meaning of each content in the formula is the same as in the previous embodiment and is not repeated here.

[0218] It should be understood that the above is only an exemplary explanation. In actual processing, in addition to using one or more first shared keys to calculate the first response, one or more second device identifiers, the first device identifier, the first network device identifier, the second shared key, and at least one of the random numbers (such as the first random number, the second random number, the third random number, and the fourth random number) may be used. All of these are within the scope of protection of this embodiment, but are not limited or exhaustive. In addition, the parameters used to calculate the first response may include other types of parameters in addition to the above possible parameters, which are also not limited or exhaustive.

[0219] In some embodiments, the first device calculates the first response based on at least one shared key, including: the first device calculates the first response based on the second shared key and at least one of the following parameters: an identifier of the first device, an identifier of the one or more second devices, and an identifier of the first network device, wherein the first response is used by the core network side device to authenticate the first device as an intermediate node for the one or more second devices. In other words, in this embodiment, the first response is used by the core network side device to authenticate the first device, and further used by the core network side device to authenticate that the first device can serve as an intermediate node for one or more second devices.

[0220] The first device calculates the first response based on at least one shared key, including: the first device calculates the first response based on the second shared key, the identifiers of the one or more second devices, and at least one of the following parameters: the identifier of the first device and the identifier of the first network device. This is merely an example; more types of parameters may be used to calculate the first response, such as one or more random numbers. The description of the random numbers is similar to that in the previous embodiment and is not repeated here.

[0221] Exemplarily, the first device calculating the first response based on at least one shared key includes: the first device calculating the first response using a first calculation method based on the second shared key, the identifiers of the one or more second devices, the identifier of the first device, and a third random number. The description of the third random number is the same as in the previous embodiment and is not repeated here.

[0222] Taking the first device as UE, the first calculation method including the second authentication function, and a second device as an example, the calculation of the first response can be expressed by the following formula: RES'=f2(K AUSF-UE ,AIoT ID,UE ID,NONCE2), where K AUSF-UE The first calculation method can also be replaced by a hash function. For example, the calculation of the first response can be expressed as: RES'=HASH(K AUSF-UE , AIoT ID, UE ID, NONCE2); or, the first calculation method can also be replaced by KDF, for example, the calculation of the first response can be expressed as: RES'=KDF(K AUSF-UE , AIoT ID, UE ID, NONCE2), the parameters in the formula are the same as those in the previous example, and will not be repeated. AUSF-UE Can be replaced by the UE's root key (such as Kr UE), or other keys derived from the UE's root key (such as the UE's corresponding IK, or the UE's corresponding CK, or K SEAF-UE ) and so on, this is not an exhaustive list.

[0223] In the above example, the parameters for calculating the first response can also be increased to include the identifier of the first network device. For example, taking the first device as UE, the first calculation method including the second authentication function, and a second device as an example, the calculation of the first response can be expressed by the following formula: RES'=f2(K AUSF-UE , AIoT ID, UE ID, A-IoT authenticator ID, NONCE2), where A-IoT authenticator ID represents the identifier of the first network device (the AIoT Authenticator ID can also be replaced by at least one of AUSF ID, AMF ID, SEAF ID, AIoT network element ID, UPF ID, etc.), and the remaining parameters in the formula are the same as those in the above example and are not repeated. The first calculation method can also be replaced by a hash function, etc., without exhaustive enumeration, and the second shared key K AUSF-UE Possible replacement methods are the same as those in the aforementioned embodiment and are not described in detail. In addition, the first device can be replaced by a first access network device, and the description of the method for calculating the first response corresponding to the first access network device is also the same as that in the aforementioned embodiment and is not described in detail.

[0224] In the case where there are multiple second devices, the "AIoT ID" in each formula in the above examples can be replaced with "AIoT ID-1...AIoT ID-N"; or, "AIoT ID-1...AIoT ID-N" can also be calculated using direct calculation, XOR calculation, or other calculation methods to replace the "AIoT ID" in the above formulas. I will not go into details here.

[0225] The above is an exemplary description based on the example of the first device being a UE. The first device can be replaced by a first access network device. Accordingly, the "UE ID" in the above formulas can be replaced by "gNB ID", "K AUSF-UE " can be replaced by "K AUSF-gNB ", etc., no repetition is given here. The second shared key K AUSF-gNB It can be replaced by the root key of the first access network device (such as Kr gNB ), or other keys derived from the root key of the first access network device (such as IK, or CK, or K SEAF-gNB ) and so on, this is not an exhaustive list.

[0226] Illustratively, the first device may first calculate one or more second responses, and then calculate the first response using the first calculation method based on the one or more second responses, the identifiers of the one or more second devices, the second shared key, and at least one of the following: the identifier of the first device, the one or more first random numbers, and the identifier of the first network device. The description of the second response is the same as in the previous embodiment and is not repeated here.

[0227] Taking the first device as UE and the first calculation method as hash algorithm as an example, the process of calculating the first response can be expressed as: RES'=HASH(K AUSF-UE , AIoT ID, UE ID, RES, NONCE1), where RES is the second response, and RES can be equal to f2(RAND). The meanings of other parameters in the formula are the same as those described above and are not repeated here. The above-mentioned hash algorithm can also be replaced by other algorithms or functions in the first calculation method, which are not exhaustive here. The possible replacement forms of the second shared key, the first device can be replaced by the first access network device, the number of second devices can be multiple, and other replacement instructions are similar to the above-mentioned embodiments and are not repeated here.

[0228] Exemplarily, the first device calculates the first response based on at least one shared key, including: the first device calculates a third intermediate key based on the second shared key and at least one of the following: an identifier of the first network device and a third random number; and uses the first calculation method to calculate the first response based on the third intermediate key, the identifier of the one or more second devices, and at least one of the following: the identifier of the first device, the one or more first random numbers.

[0229] The calculation method of the third intermediate key is the same as that in the above embodiment and will not be described in detail.

[0230] Taking the first device as UE and the first calculation method as a hash algorithm as an example, the calculation of the first response can be expressed as: RES'=HASH(KUE,AIoT ID,UE ID,NONCE1), where KUE=KDF(KAUSF-UE,A-IoT authenticator ID,NONCE2), KUE represents the third intermediate key, and the meaning of other parameters is the same as that in the aforementioned embodiment and will not be repeated. Regarding the possible replacement forms of the second shared key, the first device can be replaced by the first access network device, the number of second devices can be multiple, etc., the replacement instructions are similar to the aforementioned embodiment and will not be repeated.

[0231] Exemplarily, in the process of calculating the first response by the first device, one or more first intermediate responses may be calculated first, and then the first response may be calculated based on the one or more first intermediate responses. For example, the first device calculates one or more first intermediate responses based on the identification of the one or more second devices, the second shared key and at least one of the following parameters: the identification of the first device, the one or more first random numbers, one or more second responses; and calculates the first response based on the one or more first intermediate responses. Calculating the first response based on the one or more first intermediate responses may be: calculating the first response based on the one or more first intermediate responses and at least one of the following: a third random number, the identification of the first network device. In this example, the relevant instructions for calculating the first intermediate response are similar to those in the aforementioned embodiment, and the only difference is that the first shared key in the aforementioned embodiment is replaced by only the second shared key in this example, so they are not repeated.

[0232] In this embodiment, the processing of calculating the first response based on one or more first intermediate responses and at least one of the following: a third random number, an identifier of the first network device is the same as that in the above embodiment and will not be repeated.

[0233] The above embodiments provide exemplary explanations of how the first device generates the first response in different scenarios where the number of the second devices is one or more.

[0234] In some possible implementations, in the core network side device, the method further includes: the core network side device performs authentication related to the one or more second devices based on the first expected response and the first response, wherein the first expected response is calculated based on at least one first shared key, and the at least one shared key includes at least one of the following: one or more first shared keys, a second shared key, different first shared keys among the one or more first shared keys are shared by different second devices and the first device and the core network side device, and the second shared key is shared by the first device and the core network side device. That is, the core network side device also needs to obtain a first expected response, which can be expressed as a first XRES (Expected Response).

[0235] In some possible implementations, the core network side device includes a first network device, and the first network device obtains a first expected response from another network device. The method further includes: the first network device receiving the first expected response from the second network device. In this case, the first network device performs authentication processing.

[0236] Alternatively, the core network side device may not include the first network device, and the core network side device receives the first expected response from the second network device.

[0237] In this implementation, the second network device may include at least one of the following: UDM, ARPF.

[0238] In some possible implementations, the method further includes: the core network side device calculating the first expected response based on the at least one shared key.

[0239] Further, the core network side device calculates the first expected response based on the at least one shared key, which may include: calculating the first expected response based on the identifiers of one or more second devices and the at least one shared key.

[0240] Optionally, the core network-side device may further calculate the first expected response based on identifiers of one or more second devices, at least one shared key, and at least one of the following parameters: an identifier of the first device, an identifier of the first network device, and at least one random number. This does not limit or exhaustively enumerate all possible parameters that may be used to calculate the first response.

[0241] In some embodiments, the core network side device calculates the first expected response based on the at least one shared key, including: the core network side device calculates the first expected response based on the identifiers of the one or more second devices and the one or more first shared keys. The core network side device performs authentication related to the one or more second devices based on the first expected response and the first response, including: the core network side device performs authentication on the one or more second devices based on the first expected response and the first response.

[0242] Wherein, performing authentication of the one or more second devices based on the first expected response and the first response may include: determining that authentication of the one or more second devices is successful or passed when the first expected response and the first response are the same; and / or determining that authentication of the one or more second devices is failed or not passed when the first expected response and the first response are different. Optionally, when the first expected response and the first response are the same, in addition to determining that authentication of the one or more second devices is successful, authentication of the first device as an intermediate node for the one or more second devices may also be determined to be successful or passed.

[0243] Optionally, the parameters used to calculate the first expected response may include but are not limited to the identifiers of one or more second devices and the one or more first shared keys. For example, when calculating the first expected response, in addition to using the identifiers of one or more second devices and the one or more first shared keys, other parameters may also be used. Exemplarily, the core network side device calculates the first expected response based on the identifiers of the one or more second devices and the one or more first shared keys, which may include: the core network side device calculates the first expected response based on the identifiers of the one or more second devices, the one or more first shared keys and at least one of the following parameters: the identifier of the first device, the identifier of the first network device, and the second shared key.

[0244] It should be pointed out that the calculation method used by the core network side device to calculate the first expected response is also the first calculation method. The parameters and related processing used by the core network side device to calculate the first expected response should be the same as the parameters and related processing used by the first device to calculate the first response.

[0245] For example, if the first device first calculates one or more intermediate keys and then calculates the first response based on the one or more intermediate keys, the core network side device also calculates one or more intermediate keys and then calculates the first expected response based on the one or more intermediate keys.

[0246] Exemplarily, if the first device first calculates one or more second responses, and then uses the first calculation method to calculate the first response based on the one or more second responses, the identifiers of the one or more second devices, the one or more first shared keys, and at least one of the following: the identifier of the first device, the one or more first random numbers, the identifier of the first network device, and the second shared key. Correspondingly, the core network side device first calculates one or more second expected responses, and then uses the first calculation method to calculate the first expected response based on the one or more second expected responses, the identifiers of the one or more second devices, the one or more first shared keys, and at least one of the following: the identifier of the first device, the one or more first random numbers, the identifier of the first network device, and the second shared key.

[0247] For example, if the first device first calculates one or more first intermediate responses and then calculates the first response based on the one or more first intermediate responses, the core network device first calculates one or more second intermediate responses and then calculates the first expected response based on the one or more second intermediate responses. The parameters and method used to calculate the second intermediate responses should be the same as the parameters and method used by the first device to calculate the first intermediate response.

[0248] In some embodiments, the core network side device calculates the first expected response based on the identifiers of the one or more second devices, the one or more first shared keys, the identifier of the first device, and one or more first random numbers.

[0249] The core network side device calculates the first expected response based on the identifiers of the one or more second devices, the one or more first shared keys, the identifier of the first device, and the one or more first random numbers, including one of the following: the core network side device adopts a first calculation method to calculate the first expected response based on the identifiers of the one or more second devices, the one or more first shared keys, the identifier of the first device, and the one or more first random numbers; the core network side device obtains one or more intermediate keys based on the one or more first shared keys, and adopts the first calculation method to calculate the first expected response based on the identifiers of the one or more second devices, the one or more intermediate keys, the identifier of the first device, and the one or more first random numbers; the core network side device calculates one or more second intermediate responses based on the identifiers of the one or more second devices, the one or more first shared keys, the identifier of the first device, and the one or more first random numbers, and calculates the first expected response based on the one or more second intermediate responses.

[0250] The core network side device calculates the first expected response based on the identifiers of the one or more second devices, the one or more first shared keys, the identifier of the first device, and the one or more first random numbers using a first calculation method, including one of the following: the core network side device calculates the first expected response based on the one or more second expected responses, the identifiers of the one or more second devices, the one or more first shared keys, the identifier of the first device, and the one or more first random numbers using the first calculation method, and the one or more second expected responses are obtained based on the one or more second random numbers; the core network side device calculates the first expected response based on the second shared key, the identifiers of the one or more second devices, the one or more first shared keys, the identifier of the first device, and the one or more first random numbers using the first calculation method, and the second shared key is shared by the first device and the core network side device; the core network side device calculates the third intermediate key based on the second shared key, the identifier of the first network device, and the third random number, and calculates the first expected response based on the third intermediate key, the identifiers of the one or more second devices, the one or more first shared keys, the identifier of the first device, and the one or more first random numbers using the first calculation method.

[0251] The core network side device obtains one or more intermediate keys based on the one or more first shared keys, and uses the first calculation method to calculate the first expected response based on the identification of the one or more second devices, the one or more intermediate keys, the identification of the first device, and the one or more first random numbers, including one of the following: the core network side device obtains one or more first intermediate keys based on the one or more first shared keys, and uses the first calculation method to calculate the first expected response based on one or more second responses, the identification of the one or more second devices, the one or more first intermediate keys, the identification of the first device, and the one or more first random numbers, wherein the one or more second expected responses are obtained based on one or more second random numbers; the core network side device obtains one or more first intermediate keys based on the one or more first shared keys, and uses the first calculation method to calculate the first expected response based on the second shared key, the identification of the one or more second devices, the one or more first intermediate keys, The first expected response is calculated using the identifier of the first device and the one or more first random numbers, wherein the second shared key is shared by the first device and the core network side device; the core network side device calculates one or more second intermediate keys based on the one or more first shared keys, the identifier of the first network device and one or more fourth random numbers; the first expected response is calculated using the first calculation method based on the identifiers of the one or more second devices, the one or more second intermediate keys, the identifier of the first device and the one or more first random numbers; the core network side device obtains a third intermediate key based on the second shared key, the identifier of the first network device and the third random number, obtains one or more first intermediate keys based on the one or more first shared keys, and calculates the first expected response using the first calculation method based on the third intermediate key, the identifiers of the one or more second devices, the one or more first intermediate keys, the identifier of the first device and the one or more first random numbers.

[0252] In which, the core network side device calculates one or more second intermediate responses based on the identifiers of the one or more second devices, the one or more first shared keys, the identifier of the first device, and the one or more first random numbers, including one of the following: the core network side device respectively adopts the first calculation method to calculate the one or more second expected responses, the identifiers of the one or more second devices, the one or more first shared keys, the identifier of the first device, and the one or more first random numbers, and the one or more second expected responses are obtained based on the one or more second random numbers; the core network side device respectively adopts the first calculation method to calculate the one or more second intermediate responses based on the second shared key, the identifiers of the one or more second devices, the one or more first shared keys, the identifier of the first device, and the one or more first random numbers, wherein the second shared key is shared by the first device and the core network side device; the core network side device calculates the third intermediate key based on the second shared key, the identifier of the first network device and the third random number, and respectively adopts the first calculation method to calculate the third intermediate key, the identifier of the one or more second devices, the one or more first intermediate keys , the identifier of the first device, and the one or more first random numbers, and calculate the one or more second intermediate responses; the core network side device obtains one or more first intermediate keys based on the one or more first shared keys, and respectively adopts the first calculation method to calculate the one or more second intermediate responses based on the one or more second expected responses, the identifiers of the one or more second devices, the one or more first intermediate keys, the identifier of the first device, and the one or more first random numbers; the core network side device obtains one or more first intermediate keys based on the one or more first shared keys, and respectively adopts the first calculation method to calculate the one or more second intermediate responses based on the second shared key, the identifiers of the one or more second devices, the one or more first intermediate keys, the identifier of the first device, and the one or more first random numbers; the core network side device calculates one or more second intermediate keys based on the one or more first shared keys, the identifier of the first network device, and the one or more fourth random numbers; and respectively adopts the first calculation method to calculate the one or more second intermediate responses based on the identifiers of the one or more second devices, the one or more second intermediate keys, the identifier of the first device, and the one or more first random numbers;The core network side device obtains a third intermediate key based on the second shared key, the identifier of the first network device, and a third random number, obtains one or more first intermediate keys based on the one or more first shared keys, and calculates the one or more second intermediate responses using the first calculation method based on the third intermediate key, the identifiers of the one or more second devices, the one or more first intermediate keys, the identifier of the first device, and the one or more first random numbers.

[0253] The calculating of the first expected response based on the one or more second intermediate responses includes one of the following: the core network side device adopts the first calculation method to calculate the first expected response based on the one or more second intermediate responses, the identifier of the first network device, and a third random number; the core network side device adopts the first calculation method to calculate the first expected response based on the one or more second intermediate responses and the identifier of the first network device; the core network side device adopts the first calculation method to calculate the first expected response based on the one or more second intermediate responses and the third random number.

[0254] In the above process, the descriptions of the first shared key, the first calculation method, and the second calculation method are the same as those in the previous embodiment and are not repeated here. The detailed process of the core network side device obtaining the first intermediate key, the second intermediate key, and the third intermediate key in the above process is also the same as the process of the first device obtaining the first intermediate key, the second intermediate key, and the third intermediate key in the previous embodiment and is not repeated here.

[0255] In this embodiment, the core network side device may include a first network device, and the processing of calculating the first expected response may be performed by the first network device; or, the core network side device does not include the first network device. In this case, the first expected response may also be calculated by the first network device, that is, the processing of the aforementioned core network side device may be replaced by the first network device, and no repetition is made. The first network device may be an AUSF or an authentication device, and the detailed description of the authentication device has been detailed in the aforementioned embodiment and will not be repeated here. In the following description, the core network side device is used as an example for description, which does not mean that other network side devices (such as the case where the first network device performs the processing and the first network device is not a core network side device) cannot perform the same processing, but it is just that no repetition is made.

[0256] In the process of calculating the first expected response of a second device by the core network side device, the specific method adopted should be the same as the process of calculating the first response of a second device by the first device in the aforementioned embodiment.

[0257] For example, when there is only one second device, the first device calculates the first response using the first calculation method based on the identifier of the second device, the first random number, the first shared key, and the identifier of the first device. Correspondingly, the core network side device also needs to calculate the first expected response using the first calculation method based on the identifier of the second device, the first random number, the first shared key, and the identifier of the first device.

[0258] Taking the first shared key as the root key and the first calculation method as the hash algorithm as an example, the above-mentioned core network side device uses the first calculation method to calculate the first expected response based on the identifier of the second device, the first random number, the first shared key and the identifier of the first device, which can be expressed by the following formula: XRES'=HASH(Kr,AIoT ID,UE ID,NONCE1), where XRES' represents the first expected response, HASH represents the hash algorithm, Kr is the first shared key, i.e., the root key, AIoT ID is the identifier of the second device, UE ID is the identifier of the first device, and NONCE1 is the first random number.

[0259] It can be seen from the above example that the core network side device calculates the first expected response. If the root key and hash function are used for calculation, the formula used is the same as the formula RES'=HASH(Kr,AIoT ID,UE ID,NONCE1) used by the first device to calculate the first response using the root key and hash function. The only difference is that in this example, the first expected response obtained by the core network side device is distinguished as XRES'. This is because the core network side device and the first device are different execution entities. XRES' and RES' are used to represent the results calculated by the core network side device and the first device based on the same formula, but in fact, the two need to use the same parameters and calculation methods to achieve the purpose of verification.

[0260] Regarding other possible examples in which the core network side device obtains the first expected response from one or more second devices, the same calculation formula is used as that for the other possible examples in which the first device obtains the first response from one or more second devices. Therefore, the calculation method of the core network side device will not be repeated.

[0261] In addition, the core network side device may also calculate a second intermediate response using the first shared key, and then calculate the first expected response based on the second intermediate response.

[0262] In the process of calculating the second intermediate response of one or more second devices by the core network side device, the specific method adopted should be the same as the process of calculating the first intermediate response of one or more second devices by the first device in the aforementioned embodiment.

[0263] For example, when there are multiple second devices, taking the i-th first shared key (the first shared key of the i-th second device) as the i-th root key and the first calculation method as the hash algorithm, the first device uses the first calculation method to calculate the i-th first intermediate response based on the identifier of the i-th second device, the i-th first random number, the i-th first shared key, and the identifier of the first device. Correspondingly, the core network side device also uses the first calculation method to calculate the i-th second intermediate response based on the identifier of the i-th second device, the i-th first random number, the i-th first shared key, and the identifier of the first device; for example, it can be expressed as XRES"i=HASH(Kr i ,AIoT ID-i,UE ID,NONCE1i).

[0264] That is, the core network side device calculates the second intermediate response in the same way as the first device calculates the first intermediate response. The only difference is that in this example, the second intermediate response obtained by the core network side device is distinguished as XRES". In addition, the second response on the first device side is replaced by the second expected response (for example, it can be expressed as XRES). This is because the core network side device and the first device are different execution entities. XRES" and RES" are used to represent the results calculated by the core network side device and the first device based on the same formula, but in fact, the two need to use the same parameters and calculation methods to achieve the purpose of verification. Regarding other possible examples of the core network side device obtaining a second intermediate response from a second device, the same calculation formula is used as the other possible examples of the first device obtaining a first intermediate response from a second device. Therefore, the calculation method of the core network side device will not be repeated.

[0265] In the process of the core network side device using the second intermediate response of one or more second devices to calculate the first expected response, the specific method used should be the same as the process of the first device using the first intermediate response of one or more second devices to calculate the first response in the aforementioned embodiment.

[0266] For example, taking the first calculation method including an XOR algorithm and a hash algorithm as an example, the process of the first device calculating the first response can be expressed as follows: Accordingly, the process of calculating the first expected response by the core network side device can be expressed as: Here, XRES' has the same meaning as in the above example, indicating the first expected response, XRES"1 to XRES"N respectively indicate the second intermediate responses of N second devices, and the rest of the meanings in the formula are the same as in the above embodiment and are not repeated here.

[0267] Regarding other possible examples in which the core network side device obtains the first expected response based on the second intermediate response of a second device, the same calculation formula is used as in the other possible examples in which the first device calculates the first response based on the first intermediate response of a second device. Therefore, the calculation method of the core network side device will not be repeated.

[0268] In some embodiments, the core network side device calculates the first expected response based on the at least one shared key, including: the core network side device calculates the first expected response based on the second shared key and at least one of the following parameters: an identifier of the first device, an identifier of the one or more second devices, and an identifier of the first network device. The core network side device performs authentication related to the one or more second devices based on the first expected response and the first response, including: the core network side device performs authentication of the first device as an intermediate node for the one or more second devices based on the first expected response and the first response.

[0269] Among them, based on the first expected response and the first response, performing authentication of the first device as an intermediate node of the one or more second devices may include: when the first expected response and the first response are the same, determining that the authentication of the first device as an intermediate node of the one or more second devices is successful or passed; and / or, when the first expected response and the first response are different, determining that the authentication of the first device as an intermediate node of the one or more second devices fails or does not pass.

[0270] The core network side device calculates the first expected response based on the at least one shared key, including: calculating the first expected response based on the second shared key, the identifier of the one or more second devices and at least one of the following parameters: the identifier of the first device, the identifier of the first network device.

[0271] Exemplarily, the core network side device calculates the first expected response based on at least one shared key, including: the core network side device uses a first calculation method to calculate the first expected response based on the second shared key, the identifiers of the one or more second devices, the identifier of the first device, and a third random number.

[0272] Exemplarily, the core network-side device may first calculate one or more second expected responses, and then calculate the first expected response using the first calculation method based on the one or more second expected responses, the identifiers of the one or more second devices, the second shared key, and at least one of the following: the identifier of the first device, the one or more first random numbers, and the identifier of the first network device. The description of the second expected response is the same as in the previous embodiment and is not repeated here.

[0273] Exemplarily, the core network side device calculates a third intermediate key based on the second shared key and at least one of the following: an identifier of the first network device and a third random number; and calculates the first expected response using the first calculation method based on the third intermediate key, the identifier of the one or more second devices and at least one of the following: the identifier of the first device, the one or more first random numbers.

[0274] Exemplarily, the core network side device calculates one or more second intermediate responses, and then calculates the first expected response based on the one or more second intermediate responses. For example, one or more second intermediate responses are calculated based on the identifier of the one or more second devices, the second shared key and at least one of the following parameters: the identifier of the first device, the one or more first random numbers, one or more second responses; the first expected response is calculated based on the one or more second intermediate responses. Calculating the first expected response based on the one or more second intermediate responses can be: calculating the first expected response based on the one or more second intermediate responses and at least one of the following: a third random number, the identifier of the first network device. In this embodiment, the processing of calculating the first expected response based on one or more second intermediate responses and at least one of the following: a third random number, the identifier of the first network device is also the same as in the aforementioned embodiment and will not be repeated.

[0275] This is only an example explanation. More types of parameters can be used to calculate the first expected response. The parameters and calculation method used to calculate the first expected response should be the same as the parameters and calculation method used to calculate the first response, so they are not repeated here.

[0276] The above embodiments describe in detail the detailed processing method of the first device calculating the first response and the core network side device calculating the first expected response in the scenario where there are one or more second devices. Next, the interaction process between the first device and the core network side device is described.

[0277] In some possible implementations, the second device may trigger the execution of the authentication method.

[0278] The processing by the first device may further include: the first device receiving an authentication request from each of the one or more second devices, wherein the authentication request of each second device carries an identifier of the second device. Furthermore, the processing by the first device may further include: the first device sending an authentication request to the core network side device, wherein the authentication request carries the identifiers of the one or more second devices. Accordingly, the core network side device receives the authentication request from the first device.

[0279] Furthermore, the processing by the core network device may further include: the core network device sending a second message to the first device, the second message carrying at least one of the following: an identifier of the one or more second devices, an identifier of a device group, the device group including multiple second devices. The second message may be a response message to the aforementioned authentication request. Exemplarily, the second message may be referred to as an authentication response.

[0280] Optionally, the second message may further carry one or more first random numbers. Optionally, the second message may further carry at least one of one or more second random numbers, one or more fourth random numbers, and a third random number.

[0281] Accordingly, the first device may perform the aforementioned process of calculating the first response after receiving the second message from the core network device; then the first device sends the first message to the core network device. The core network device receives the first message from the first device and, based on the first expected response and the first response, performs authentication associated with the one or more second devices.

[0282] Optionally, the method also includes at least one of the following: the first device receives binding information from a fourth network device, the binding information including one or more second devices with which the first device has a binding relationship; the first device determines one or more second devices with which the first device has a binding relationship based on preset binding information; the first device uses the one or more second devices that have passed authentication as one or more second devices with a binding relationship, and the authentication includes physical layer authentication and / or air interface authentication.

[0283] The first device may, upon receiving an authentication request from each of the second devices, first determine whether each second device is a device having a binding relationship with itself based on the binding information, and upon determining that each second device is a device having a binding relationship with itself, forward the authentication request from each second device to the core network side device.

[0284] The processing of the binding information received by the first device from the fourth network device may be before calculating the first response, or before the first device forwards the authentication request. The binding information may include one or more devices that have a binding relationship with the first device. For example, the binding information may include at least one of the following: an identifier of each device in the one or more devices that have a binding relationship with the first device, an identifier of each device group in the one or more device groups that have a binding relationship with the first device, and an identifier of each device included in each device group that has a binding relationship with the first device. The fourth network device may be the same as or different from the first network device, and this embodiment does not limit the fourth network device.

[0285] The preset binding information may be pre-configured directly in the first device. The content of the preset binding information may be the same as the aforementioned binding information, and will not be repeated here.

[0286] The specific processing flow of the physical layer authentication and / or air interface authentication is not limited in this embodiment. That is, as long as the first device performs physical layer authentication and / or air interface authentication with any second device, the identifier of the second device will be saved and the second device will be recorded as a device with which the first device has a binding relationship.

[0287] In some possible examples, the number of the second device is one.

[0288] The first device sends an authentication request before calculating the first response. The first device may also add an identifier of the first device to the authentication request sent to the core network side device.

[0289] Exemplarily, the core network side device may include a first network device, which may check whether the first device and the second device have a binding relationship, and forward the authentication request to the second network device when it is determined that there is a binding relationship. Correspondingly, the first network device receives the first expected response from the second network device. After receiving the authentication request forwarded by the first network device, the second network device calculates the first expected response corresponding to the second device (i.e., XRES' of the aforementioned embodiment); and sends the first expected response to the first network device. The second network device may include UDM and / or ARPF. The specific processing method for the second network device to obtain the first expected response should be the same as the method for calculating the first expected response in the aforementioned embodiment, so it will not be repeated. The above processing is particularly applicable to the case where the first network device is not an authentication device, for example, the first network device is a first core network device, such as AUSF.

[0290] Among them, the first network device checks whether the first device and the second device have a binding relationship, which can be based on the binding information corresponding to the first device stored by itself. For example, it checks whether the identifier of the second device is included in the identifier of one or more binding devices contained in the binding information corresponding to the first device. If so, it is determined that the first device and the second device have a binding relationship. Optionally, the first network device can further determine whether the first device can provide a wireless connection and / or a relay connection for the second device. For example, the first network device can determine whether the first device can provide a wireless connection and / or a relay connection for the second device based on relevant data of the first device. For example, the first network device can determine whether the first device can provide a wireless connection and / or a relay function based on the relevant data of the first device, to determine whether the first device can provide a wireless connection and / or a relay connection for the second device.

[0291] Optionally, the core network side device may include a first network device, which may also receive at least one of the following from the second network device: a first message authentication code (MAC), a second expected response (such as XRES in the aforementioned embodiment), KAUSF, etc. Optionally, the first network device may also receive at least one of the following from the second network device: a first random number, a second random number, a third random number, and a fourth random number. The above-mentioned first expected response, first message authentication code, second expected response, etc. may be carried in the 5G HEAV sent by the second network device to the first network device.

[0292] The first network device may include at least one of the first random number, the second random number, the third random number, and the fourth random number from the second network device in a second message and send the message to the first device. Accordingly, after receiving the second message, the first device may calculate a first response. The first device then sends the first response to the first network device. If the first expected response is identical to the first response, the first network device determines that authentication of the second device is successful.

[0293] Exemplarily, the first network device may check whether the first device and the second device have a binding relationship. If a binding relationship is determined, the first network device calculates the first expected response of the second device. The manner in which the first network device calculates the first expected response in this example has been described in detail in the aforementioned embodiment and is not further elaborated here.

[0294] When the first network device calculates the first expected response, it can also obtain any one of the first message authentication code, second expected response, KAUSF, and so on, of the second device. The first network device also generates at least one of the aforementioned first random number, second random number, third random number, and fourth random number. The first network device can then send a second message to the first device, carrying at least one of the aforementioned first message authentication code, second expected response, KAUSF, first random number, second random number, third random number, and fourth random number. The processing that the first device can perform, as well as the subsequent authentication processing performed by the first network device, are the same as those in the aforementioned example and are not further described.

[0295] In some possible examples, there are multiple second devices, and the multiple second devices may belong to the same device group.

[0296] The first device sends an authentication request before calculating the first response.

[0297] In this scenario, each of the multiple second devices can send an authentication request to the first device on the same time domain resource; for example, the time domain resource can be a time, and each second device sets the same time to trigger the authentication request. When the time to trigger the authentication request arrives, each second device sends an authentication request to the first device at the same time. Of course, the time domain resource can also be a time range, for example, each second device can send an authentication request to the first device at any time within a specified time range. The time range can be set according to actual conditions, for example, it can be within the range of 11 o'clock to 11:10, or longer or shorter, and is not limited here. Accordingly, if the time domain resource is a time, the first device can receive the authentication request sent by each second device at the same time, and different authentication requests carry different second device identifiers; if the time domain resource is a time range, the first device can send the authentication requests of each second device received within the time range to the core network side device at the end of the time range.

[0298] When the first device forwards the authentication request to the core network device, the first device may also add the first device identifier to the authentication request. In addition, the authentication request may also include identifiers of the device groups to which the multiple second devices belong.

[0299] Exemplarily, the core network side device may include a first network device, which may check whether the first device has a binding relationship with multiple second devices. If it is determined that a binding relationship exists, the authentication request of the multiple second devices is forwarded to the second network device. Accordingly, the first network device receives a first expected response from the second network device. In this case, the first expected response may be the group first expected response of the device group to which the multiple second devices belong. After receiving the authentication requests of the multiple second devices forwarded by the first network device, the second network device calculates the first expected responses corresponding to the multiple second devices (i.e., the XRES' in the aforementioned embodiment) and sends the first expected response to the first network device. The second network device may include UDM and / or ARPF. The specific processing method for the second network device to obtain the first expected response should be the same as the method for the first network device to calculate the first expected response in the aforementioned embodiment, and therefore will not be described in detail. The method for the first network device to check whether the first device has a binding relationship with each second device may include: the first network device determines whether the first device has a binding relationship with the device group through the identifier of the device group to which the multiple second devices belong, and if so, determines that the first device has a binding relationship with each second device.

[0300] Alternatively, the first network device may also receive at least one of the following from the second network device: one or more first random numbers, one or more second random numbers, a third random number, or one or more fourth random numbers. The first expected response, one or more random numbers, and other content may be carried in a 5G HEAV message sent by the second network device to the first network device. The first network device may include at least one of the one or more first random numbers, one or more second random numbers, third random number, or one or more fourth random numbers from the second network device in a second message and send it to the first device. Accordingly, after receiving the second message, the first device may perform a process of calculating a first response; then, the first device may send the first response to the first network device. If the first expected response is the same as the first response, the first network device determines that authentication of the second device is successful. Exemplarily, the first network device may check whether the first device has a binding relationship with each second device. If a binding relationship is determined, the first network device calculates a first expected response. When the first network device calculates the first expected response, it also generates at least one of the one or more first random numbers, one or more second random numbers, third random number, or one or more fourth random numbers. The first network device may then send a second message to the first device, where the second message carries at least one of the one or more first random numbers, the one or more second random numbers, the third random number, the one or more fourth random numbers, and so on. The processing that may be performed by the first device and the subsequent authentication processing performed by the first network device are the same as those in the above example and are not described in detail.

[0301] Optionally, the first message further carries one or more first random numbers. Optionally, the first message further carries at least one of one or more second random numbers, one or more fourth random numbers, and a third random number.

[0302] In this case, the processing of the first device further includes: the first device generating the one or more first random numbers. Then, the first device performs the aforementioned processing of calculating the first response. Correspondingly, the core network side device performs the processing of receiving the first message from the first device.

[0303] For example, a core network device includes a first network device. The first network device calculates a first expected response based on the one or more first random numbers, or sends the one or more first random numbers to a second network device and receives the first expected response from the second network device. The first network device then determines that authentication of the one or more second devices is successful if the first expected response is the same as the first response. In a scenario where there is only one second device, the first device forwards the authentication request from the second device to the first network device. Accordingly, the first network device receives the authentication request forwarded by the first device. During the forwarding of the authentication request by the first device to the first network device, the first device may also include an identifier of the first device in the authentication request. The first network device may check whether a binding relationship exists between the first device and the second device. If a binding relationship is determined, the first device sends a second message to the first device. Unlike the previous example, the second message is only used for authentication confirmation and does not carry information such as random numbers. After receiving the second message, the first device generates random numbers on its own, calculates a first response, and sends the first response and the random numbers along with the first message to the first network device. The first network device can calculate a first expected response based on the first random number corresponding to the second device sent by the first device, or send the first random number corresponding to the second device to the second network device, which will then calculate the 5G HE AV corresponding to the second device. The process of obtaining the 5G HE AV is the same as in the previous embodiment and will not be described in detail. In the scenario where there are multiple second devices, the first device simultaneously receives authentication requests from multiple second devices and forwards them to the first network device. Accordingly, the first network device receives the authentication requests from multiple second devices forwarded by the first device. In the process of forwarding the authentication requests to the first network device, the first device may also add the first device's identifier to the authentication request. The first network device may check whether the first device has a binding relationship with the multiple second devices. If a binding relationship is determined, it may send a second message to the first device. The second message is only used for authentication confirmation and does not carry information such as the random number. After receiving the second message, the first device generates a random number corresponding to each second device, calculates a first response, and sends the first response and each random number to the first network device in the first message. The first network device can calculate the first expected response based on the first random number corresponding to each second device sent by the first device, or send the first random number corresponding to each second device to the second network device, and the second network device still calculates the 5G HE AV corresponding to the second device; the process of obtaining the 5G HE AV is the same as that in the previous embodiment and will not be repeated.

[0304] In some possible implementations, the second device may trigger the execution of the authentication method.

[0305] The processing of the first device may also include: the first device receiving an authentication request from each of the one or more second devices, wherein the authentication request of each second device carries the identifier of the second device. After the first device receives the authentication request from each second device, it performs a process of calculating a first response. In the process of calculating the first response, the first device generates one or more first random numbers. In addition, the first device may also generate the aforementioned one or more second random numbers, a third random number, and one or more fourth random numbers. The first device then sends a first message, which, in addition to carrying the first response, may also carry at least one of the one or more first random numbers, one or more second random numbers, a third random number, and one or more fourth random numbers.

[0306] The processing by the core network side device may include: the core network side device receiving a first message from a first device.

[0307] Optionally, the core network side device includes a first network device, which can receive a first message from the first device, obtain each random number from the first message, send each random number to the second network device, and receive a first expected response from the second network device; if the first expected response is the same as the first response, the first network device can determine that the authentication of each second device is successful. Furthermore, the first network device can also send a notification message of successful authentication to the first device.

[0308] Alternatively, the first network device may receive a first message from the first device, obtain each random number from the first message, and calculate a first expected response based on each random number; if the first expected response is the same as the first response, the first network device may determine that authentication of each second device is successful. Furthermore, the first network device may send a notification message of successful authentication to the first device.

[0309] The above implementation is applied to the scenario where there is only one second device or multiple second devices. The processing of the first device calculating the first response and the processing of the first network device or the second network device generating the first expected response are the same as the above embodiments and will not be repeated.

[0310] In addition, regardless of the scenario of one or more second devices, the core network side device can verify whether there is a binding relationship between the first device and each second device after receiving the first message. The specific processing method is the same as the previous embodiment and will not be repeated.

[0311] In some possible implementations, the authentication may be triggered by the network side.

[0312] The second message is used to request authentication, and the core network side device includes a first network device; the method also includes: the first network device receives an authentication request from a third network device, and the authentication request carries at least one of the following: the identifier of the one or more second devices, the identifier of the device group, and the device group includes multiple second devices.

[0313] The third network device may be a server, for example, a server with AIOT service functions, etc., and all possible possibilities are not exhaustively enumerated here.

[0314] If there is only one second device, the authentication request may carry the identifier of the second device. If there are multiple second devices, the authentication request may carry the identifier of each second device; alternatively, the authentication request may carry the identifier of a device group. Furthermore, if the authentication request carries the identifier of the device group, the first network device may also determine the identifier of each of the multiple second devices included in the device group based on the identifier of the device group.

[0315] In some possible examples, the first network device may be a first core network device, such as AUSF, that is, the first core network device may obtain a first expected response from the second network device or calculate the first expected response itself after determining the identifiers of the above-mentioned respective second devices. The above-mentioned processing is the same as the aforementioned implementation method and will not be repeated. The first network device may then send a second message to the first device, where the second message is used to request authentication. The second message may carry one or more first random numbers; in addition, it may also carry the aforementioned other random numbers. The first device performs processing such as calculating the first response and sending the first message to the first network device. The specific processing method is the same as the aforementioned embodiment and will not be repeated.

[0316] In some possible examples, the first network device may be an authentication device. The first network device may receive an authentication request from a third network device via another core network device. The other core network device may include at least one of AUSF, UDM, and ARPF. The other core network device may first calculate the authentication information of each second device based on the authentication request from the third network device. The authentication information of each second device may include at least one of the following: a message authentication code of the second device, a second expected response of the second device, a second random number corresponding to the second device, and the like. Furthermore, in this case, the other core network device may carry the above authentication information in the authentication request and send it to the first network device. The first network device may perform the calculation of the first expected response and send the second message to the first device. The first device may perform the calculation of the first response and send the first message to the first network device. The specific processing method is the same as that in the previous embodiment and is not further described. In this example, the first network device may be any one of the core network side devices, such as AUSF; or the first network device may not be a core network side device, such as an authentication device.

[0317] The core network side device in each of the above embodiments may not include the first network device. In this case, the processing performed by the first network device in the above embodiments can be replaced by the core network side device and will not be repeated.

[0318] In some possible implementations, the first device may also verify or authenticate the core network side device. Specifically, the second message carries one or more first message authentication codes for authenticating the core network side device.

[0319] Here, the first message authentication code can be used by a first device that is an intermediate node for one or more second devices to authenticate the core network side device. That is to say, the first device is an intermediate node for one or more second devices, so the first device can replace one or more second devices to authenticate the core network side device by verifying the first message authentication code. The difference from the aforementioned embodiment is that, in addition to carrying the content involved in the aforementioned embodiment, the second message in this embodiment also carries one or more first message authentication codes. Other relevant descriptions of the second message (such as the timing of sending, etc.) are the same as those in the aforementioned embodiment and are not repeated here.

[0320] The method further includes: the core network side device calculating the one or more message authentication codes based on the at least one shared key.

[0321] Optionally, the core network side device calculates the one or more first message authentication codes based on the at least one shared key, including: the core network side device calculates a first message authentication code based on the at least one shared key and at least one of the following parameters: the identifier of the first network device, the identifier of the one or more second devices, and the identifier of the first device.

[0322] Correspondingly, on the first device side, the method also includes: the first device calculates a second message authentication code based on the at least one shared key; the first device authenticates the core network side device based on the second message authentication code and the one or more first message authentication codes.

[0323] In some embodiments, the core network side device calculates the one or more first message authentication codes based on the at least one shared key, including: the core network side device calculates a first message authentication code based on the at least one shared key and at least one of the following parameters: the identification of the first network device, the identification of the one or more second devices, and the identification of the first device.

[0324] The second message carries a first message authentication code; the first device calculates the second message authentication code based on the at least one shared key, including: the first device calculates the second message authentication code based on the at least one shared key and at least one of the following parameters: the identifier of the first network device, the identifier of the one or more second devices, and the identifier of the first device.

[0325] In this embodiment, the first device authenticates the core network side device based on the second message authentication code and the one or more first message authentication codes, which may include: when the second message authentication code and the first message authentication code are the same, determining that the authentication of the core network side device has passed or succeeded (or determining that the authentication of the core network side device has passed or succeeded instead of one or more second devices); and / or, when the second message authentication code and the first message authentication code are different, determining that the authentication of the core network side device has failed or failed (or determining that the authentication of the core network side device has succeeded instead of one or more second devices).

[0326] Furthermore, the parameters for calculating the first message authentication code may also include one or more random numbers.

[0327] In one example, the core network side device calculates the first message authentication code based on the one or more first shared keys.

[0328] The core network side device calculates the first message authentication code based on the one or more first shared keys, including one of the following:

[0329] The core network side device calculates one or more second intermediate keys based on the one or more first shared keys and at least one of the following: an identifier of the first network device and one or more fourth random numbers, and calculates the first message authentication code based on the one or more second intermediate keys, the identifiers of the one or more second devices, and the identifier of the first device using the third calculation method;

[0330] The core network side device calculates one or more intermediate verification codes based on the one or more first shared keys, and calculates the first message authentication code based on the one or more intermediate verification codes and the identifier of the first network device using a third calculation method.

[0331] The third calculation method can be at least one of the first authentication function, the second authentication function, the third authentication function, a hash algorithm, AES, ACSON, SNOW 3G, ZUC, XOR calculation, direct calculation, KDF, etc. The third calculation method may be the same as or different from the first calculation method. For example, the first calculation method may be a hash calculation, and the third calculation method may be the first authentication function, etc.

[0332] In the processing of the first device, the method also includes: the first device calculates a second message authentication code based on the one or more first shared keys, and when the second message authentication code is the same as the first message authentication code, the first device determines that the authentication of the core network side device is completed.

[0333] Among them, the first device calculates the second message authentication code based on the one or more first shared keys, including one of the following: the first device calculates one or more second intermediate keys based on the one or more first shared keys and at least one of the following: the identification of the first network device and one or more fourth random numbers, and uses the third calculation method to calculate the second message authentication code based on the one or more second intermediate keys, the identification of the one or more second devices and the identification of the first device; the first device calculates one or more intermediate verification codes based on the one or more first shared keys, and uses the third calculation method to calculate the second message authentication code based on the one or more intermediate verification codes and the identification of the first network device.

[0334] This example is particularly applicable to scenarios where there are multiple second devices. In this scenario, the first message authentication code can be a first group message authentication code. That is, when multiple second devices form a device group, a single overall first message authentication code is generated for the device group. However, this example can also be used in scenarios where there is only one second device, and its applicable scenarios are not limited here.

[0335] Optionally, the core network side device calculates one or more second intermediate keys based on the one or more first shared keys, the identifier of the first network device and one or more fourth random numbers, and uses the third calculation method to calculate the first message authentication code based on the one or more second intermediate keys, the identifier of the one or more second devices and the identifier of the first device.

[0336] The manner in which the core network side device calculates each second intermediate key is the same as the manner in which the aforementioned first device calculates each second intermediate key, and is not described again here.

[0337] In the process of calculating the first message authentication code based on the one or more second intermediate keys, the identification of the one or more second devices and the identification of the first device using the third calculation method, other parameters may be added, such as at least one of a sixth random number, a sequence number (SQN, Sequence number), etc. In addition to the above-mentioned sixth random number and sequence number SQN, other parameters may also be included, which are not exhaustive here.

[0338] Taking the third calculation method as the first authentication function as an example, the calculation of the first message authentication code can be expressed as: Wherein, MAC-Group is the first message authentication code, f1 is the first authentication function, KA-IoT-1 to KA-IoT-N are the second intermediate keys of the N second devices, Tag ID-1 to Tag ID-N are the identifiers of the N second devices, RAND' is the sixth random number, and SQN is the sequence number. The above Tag ID can be replaced with the A-IoT ID in the above embodiment. The above RAND' may be the same as the above second random number in some possible cases, and may be different from the above second random number in other possible cases.

[0339] Taking the third calculation method as a hash algorithm as an example, the first message authentication code calculated using the first calculation method based on the one or more second intermediate keys, the one or more identifiers of the second device, the identifier of the first device, and the sixth random number can be expressed as follows: The meanings of the various contents in the formula are the same as those in the above embodiment and are not described in detail.

[0340] Optionally, the core network side device calculates one or more intermediate verification codes based on the one or more first shared keys, and calculates the first message authentication code based on the one or more intermediate verification codes and the identifier of the first network device using a third calculation method.

[0341] Taking any second device as the i-th second device as an example, a MAC corresponding to the i-th second device is obtained based on at least one of the first shared key, serial number, sixth random number, AMF name, etc. of the i-th second device, and the MAC corresponding to the i-th second device is used as the i-th intermediate verification code. Taking the third calculation method as an example of a hash algorithm, the third calculation method is used to calculate the first message authentication code based on the one or more intermediate verification codes and the identifier of the first network device, which can be expressed as: Among them, MAC-1 to MAC-N are intermediate verification codes corresponding to the N second devices respectively. The meanings of other contents in the formula are the same as those in the above embodiment and are not repeated here.

[0342] It should be understood that the above is only an exemplary explanation. In actual processing, the algorithms or functions in the various formulas given in the above examples can also be replaced by one or more other algorithms or functions in the third calculation method. For example, XOR calculation can be replaced by direct connection calculation, f1 can be replaced by f3, HASH can be replaced by f2, and so on. The examples are not exhaustive here.

[0343] In this example, the processing of calculating the second message authentication code on the first device side should be the same as the parameters and algorithm (or function) used in the processing of calculating the first message authentication code by the core network side device. This embodiment is only used to distinguish the message authentication codes obtained by different subjects, so the first message authentication code and the second message authentication code are used to distinguish. The second message authentication code obtained on the first device side can be expressed as XMAC-Group, and the processing of the first device will not be repeated here.

[0344] It should also be noted that other parameters may also be used in the above calculation of the first message authentication code and the second message authentication code, such as the second shared key, etc., which are not exhaustively listed or limited here.

[0345] In one example, the core network side device calculates the first message authentication code based on the second shared key.

[0346] The core network side device calculates the first message authentication code based on the second shared key, including: the core network side device calculates a first message authentication code based on the second shared key and at least one of the following parameters: the identifier of the first network device, the identifier of the one or more second devices, and the identifier of the first device.

[0347] In the processing of the first device, the method also includes: the first device calculates a second message authentication code based on a second shared key and at least one of the following parameters: the identifier of the first network device, the identifier of the one or more second devices, and the identifier of the first device. When the second message authentication code is the same as the first message authentication code, the first device determines that the authentication of the core network side device is completed.

[0348] The parameters for calculating the first message authentication code and the second message authentication code may further include one or more random numbers, such as a sixth random number. It should be noted that the parameters for calculating the first message authentication code and the second message authentication code are the same and are calculated in the same manner.

[0349] For example, the calculation of the first message authentication code can be expressed as: MAC-1=f1(K AUSF-UE , Tag ID, UE ID, RAND'), where MAC-1 is the first message authentication code, f1 is the first authentication function, K AUSF-UE is the second shared key, Tag ID is the identifier of the second device, and RAND' is the sixth random number. The above Tag ID can be replaced by the A-IoT ID in the aforementioned embodiment. This is only a scenario involving one second device. In actual processing, multiple second devices may be included. The tag ID in the above formula can be replaced by (Tag ID-1,…,Tag ID-N). In addition, the replacement description of the second shared key and the replacement description of UE ID in the above formula are similar to those in the aforementioned embodiment and are not repeated here.

[0350] In the above embodiment, the processing of calculating the second message authentication code on the first device side should be the same as the parameters and algorithm (or function) used in the processing of calculating the first message authentication code by the core network side device. This embodiment is only for the purpose of distinguishing the message authentication codes obtained by different subjects. The second message authentication code obtained on the first device side can be expressed as XMAC-2, and the processing of the first device will not be repeated here.

[0351] In a possible example, the second message also carries one or more first message authentication codes; the core network side device calculates the one or more first message authentication codes based on the at least one shared key, including: the core network side device calculates the first message authentication code corresponding to each second device in the one or more second devices based on the one or more first shared keys.

[0352] In the processing by the first device, the first device calculating the second message authentication code based on the at least one shared key includes: the first device calculating the second message authentication code based on the first shared key corresponding to the target second device among the one or more second devices. The first device authenticating the core network side device based on the one or more second message authentication codes and the one or more first message authentication codes includes: authenticating the core network side device based on the target second message authentication code and a target first message authentication code among the one or more first message authentication codes, wherein the target first message authentication code is related to the target second device.

[0353] Among them, authenticating the core network side device based on the target second message authentication code and the target first message authentication code among the one or more first message authentication codes may include: determining that the authentication of the core network side device is successful or passed when the target second message authentication code and the target first message authentication code are the same; and / or determining that the authentication of the core network side device is not passed or failed when the target second message authentication code and the target first message authentication code are different.

[0354] This example differs from the previous example in that the core network side device in this example calculates the corresponding first message authentication code for each second device. This embodiment does not limit the method of calculating the first message authentication code of each second device and other parameters that may be used for the calculation. As long as they are related to the first shared key of each second device, they are within the protection scope of this embodiment.

[0355] In the case that the number of the second device is one, the first device side may use the second device as the aforementioned target second device and calculate the target second message authentication code of the target second device.

[0356] If there are multiple second devices, the first device may select any one of the multiple second devices as the target second device and calculate the target second message authentication code for the target second device. The first message authentication code corresponding to the target second device is then determined from the multiple first message authentication codes and used as the target first message authentication code. The specific method for calculating the target second message authentication code by the first device is not limited within the scope of this embodiment, as long as it is the same as the method for calculating the first message authentication code and is related to the first shared key.

[0357] In some other possible examples, the core network side device calculates the one or more first message authentication codes based on the at least one shared key, including: the core network side device calculates the first message authentication code corresponding to each second device in the one or more second devices based on the second shared key and the identifier of one or more second devices. This embodiment does not limit the method of calculating the first message authentication code of each second device and other parameters that may be used for calculation. As long as they are related to the identifier of each second device and the second shared key, they are within the protection scope of this embodiment. Accordingly, the processing of the first device calculating the target second message authentication code should be the same as the method of calculating the target first message authentication code. The processing of the first device authenticating the core network side device based on the target second message authentication code and the target first message authentication code in the one or more first message authentication codes is also the same as the above example, so it will not be repeated.

[0358] In some possible implementations, mutual authentication is also performed between the first device and the second device.

[0359] In some possible examples, the first device performs physical layer authentication with the second device, so that the second device authenticates the first device.

[0360] Optionally, the method further includes: the first device sends a third message to a target second device among the one or more second devices, the third message being used to instruct the target second device to authenticate the first device; the first device receives a pilot signal sent by the target second device; the first device calculates a target verification code corresponding to the target second device based on the pilot signal sent by the target second device; the first device sends the target verification code to the target second device; the first device receives a fourth message from the target second device, wherein the fourth message is used to indicate the authentication result of the target second device on the first device. The authentication result may include authentication passed (or verification or authentication of the first device passed), or authentication failed (or verification or authentication of the first device failed).

[0361] The third message may be a physical layer authentication request. The pilot signal sent by the target second device may be a secret pilot sent by the target second device. The secret pilot is calculated based on the first shared key (such as Kr) and the channel information between the first device (such as UE) and the second device (such as A-IoT device). It has confidentiality and privacy, and can only be verified by the first device.

[0362] Exemplarily, the first device calculates a target verification code corresponding to the target second device based on the first shared key of the target second device and the secret pilot of the target second device.

[0363] The target second device is any one of one or more second devices, and each second device performs the same processing as the target second device. For example, the first device sends a third message to each of the one or more second devices, and the third message is used to instruct each second device to authenticate the first device; the first device receives the pilot signal sent by each second device; the first device calculates the verification code corresponding to each second device based on the pilot signal sent by each second device; the first device sends the corresponding verification code to each second device; the first device receives a fourth message from each second device, wherein the fourth message of each second device is used to indicate whether each second device has successfully authenticated the first device. The processing of each second device will not be described here one by one.

[0364] Optionally, the method further includes: the first device calculating a target verification code for authenticating the first device based on a third shared key shared with a target second device among the one or more second devices; and the first device sending a third message to the target second device, wherein the third message carries the target verification code. The first device calculating the target verification code may specifically be calculating the target verification code based on the third shared key and at least one of: a fifth random number, an identifier of the target second device, and an identifier of the first device.

[0365] The processing on the target second device side may include: the target second device receives a third message from the first device, wherein the third message carries a target verification code for authenticating the first device, and the target verification code is related to a third shared key shared by the target second device and the first device; the target second device authenticates the first device based on the target verification code and the target verification code.

[0366] The method further includes: the target second device calculating the target verification code based on the third shared key and at least one of the following: a fifth random number, an identifier of the target second device, and an identifier of the first device.

[0367] In some possible examples, the third shared key is shared by the target second device and the first device. The third shared key corresponding to the target second device can be at least one of a pre-shared key (such as a root key), a pre-distributed key, a private network key, an application layer key, a physical layer key, a physical unclonable function (PUF) key, etc. In some possible examples, in addition to being shared by the target second device and the first device, the third shared key can also be shared with the core network side device, that is, the third shared key can also be a key shared by the target second device, the first device, and the core network side device. In this example, the third shared key can be the same as the first shared key in the aforementioned embodiment. In other words, as long as the third shared key is pre-saved between the target second device and the first device, regardless of whether the third shared key is shared by the target second device and the first device, or the third shared key is shared by the target second device, the first device, and the core network side device, it is within the protection scope of this embodiment.

[0368] The first device calculates a target verification code for authenticating the first device based on a third shared key shared with a target second device among the one or more second devices, including: the first device calculates a target verification code for authenticating the first device based on the third shared key shared with a target second device among the one or more second devices and at least one of the following: a fifth random number, an identifier of the target second device, and an identifier of the first device.

[0369] The fifth random number can be generated by the first device. And the fifth random number can be carried by the third message to be transmitted to the target second device. It should also be noted that different second devices can correspond to different fifth random numbers, and the configuration method of the fifth random number corresponding to each second device is not described here one by one. In addition, the calculation method of the target verification code corresponding to the target second device can be configured according to actual conditions, such as the first authentication function (such as f1), the second authentication function (such as f2), the third authentication function (such as f3), f4 (such as called IK derivation function), f5 (such as AK derivation function), hash algorithm, AES, ACSON, SNOW 3G, ZUC, XOR calculation, direct calculation, KDF, at least one of.

[0370] For example, the first device calculates the target verification code corresponding to the target second device, which can be expressed as: MAC'_A = f1(Kr, Tag ID, UE ID, nonce3), where Kr is the third shared key shared between the target second device and the UE, nonce3 represents the fifth random number, and the remaining parameters are the same as those described in the previous embodiment and are not repeated here. The replacement description of the UE ID is also the same as in the previous embodiment and is not repeated here.

[0371] The target second device calculates the target verification code in the same way as the first device calculates the target verification code corresponding to the target second device. For example, the target verification code calculated on the target second device side can be expressed as: XMAC'_A=f1(Kr, Tag ID, UE ID, nonce3).

[0372] The target second device authenticates the first device based on the target check code and the target verification code, which may include: if the target check code and the target verification code are the same, determining that the verification of the first device passes or succeeds; otherwise, determining that the verification of the first device fails.

[0373] Furthermore, the processing of the target second device may further include: sending a fourth message to the first device, wherein the fourth message carries an authentication result of the first device, where the authentication result may include authentication success or authentication failure. Correspondingly, the processing of the first device may include: receiving the fourth message from the target second device.

[0374] The target second device is any one of one or more second devices, and each second device performs the same processing as the target second device. The processing of each second device is not described in detail here. After the first device receives the fourth message from each second device, it can also include that when each second device indicates that the authentication of the first device is successful, the first device can complete all authentication processing. Alternatively, when each second device indicates that the authentication of the first device is successful, the first device performs the aforementioned calculation of the first response (or executes S210).

[0375] In some possible examples, the first device authenticates the second device.

[0376] Optionally, the first device can use the PUF principle to authenticate each second device. For example: taking any second device as the i-th second device as an example, the first device authenticates the i-th second device according to the PUF principle. After the authentication is passed, the first device sends a verification pass message to the i-th second device.

[0377] Optionally, the method further includes: the first device receiving a fourth message from a target second device among the one or more second devices, wherein the fourth message carries a third response for authenticating the target second device, the third response being related to a third shared key shared between the target second device and the first device; and the first device authenticating the target second device based on the third response and a third expected response. The first device calculates the third expected response based on the third shared key and at least one of: a fifth random number, an identifier of the target second device, and an identifier of the first device.

[0378] Accordingly, the processing of the target second device may include: the target second device sending a fourth message to the first device, wherein the fourth message carries a third response for authenticating the target second device, and the third response is related to a third shared key shared by the target second device and the first device. The method further includes: the target second device calculating the third response based on the third shared key and at least one of: a fifth random number, an identifier of the target second device, and an identifier of the first device.

[0379] Before receiving the fourth message, the first device may also send a third message to the target second device, where the third message carries the fifth random number. The relevant description of the fifth random number is the same as in the aforementioned embodiment. Alternatively, the third message may also carry a sixth random number, which is different from the fifth random number. Accordingly, the "fifth random number" in the parameters for calculating the third response and calculating the third expected response may be replaced with the "sixth random number."

[0380] The third message can be an authentication response corresponding to the target AIoT device or an authentication request corresponding to the target AIoT device; the fourth message can be an authentication confirmation corresponding to the target AIoT device or an authentication response corresponding to the target AIoT device.

[0381] The calculation method of the third expected response of the target second device can be configured according to actual conditions, for example, it can be at least one of the first authentication function (such as f1), the second authentication function (such as f2), the third authentication function (such as f3), f4 (such as called IK derivative function), f5 (such as AK derivative function), hash algorithm, AES, ACSON, SNOW 3G, ZUC, XOR calculation, direct calculation, and KDF. It should be pointed out that the calculation method used to calculate the third expected response or the third response is different from the calculation method used to calculate the target verification code or the target check code in the aforementioned embodiment; and / or, the parameters used to calculate the third expected response or the third response are different from the parameters used to calculate the target verification code or the target check code in the aforementioned embodiment. For example, the calculation method used to calculate the third expected response or the third response can be f1, and the calculation method used to calculate the target verification code or the target check code in the aforementioned embodiment can be f2 or a hash algorithm.

[0382] For example, taking the calculation of the third expected response based on the fifth random number and the third shared key corresponding to the target second device (the third shared key may be the same as the first shared key) as an example, the following calculation formula can be used to express it: XRES-AIOT-i = HASH (Kri, fifth random number), or XRES-AIOT-i = f2 (KAUSF-Ai, fifth random number), where XRES-AIOT-i represents the third expected response of the target second device, and the meaning of other contents in the formula is not repeated here.

[0383] For example, taking the calculation of the third expected response based on the fifth random number and the third shared key corresponding to the target second device (the third shared key is different from the first shared key), the first device uses any one of the following calculation formulas to calculate the third expected response: XRES'_A = KDF(Kr, Tag ID, UE ID, nonce3), or XRES'_A = HASH(Kr, Tag ID, UE ID, nonce3), or XRES'_A = f2(Kr, Tag ID, UE ID, nonce3). Among them, XRES'_A represents the third expected response of the target second device, and the meaning of other contents in the formula is not repeated. Kr is the third shared key of the target second device, nonce3 represents the fifth random number, and the remaining parameters are the same as those described in the previous embodiment and are not repeated. The replacement description of UE ID is also the same as that of the previous embodiment and is not repeated.

[0384] On the target second device side, the method of calculating the third response should be the same as the method in which the first device calculates the third expected response of the target second device. For example, the calculation of the third response on the target second device side can be expressed as any one of the following: RES'_A = KDF(Kr, Tag ID, UE ID, nonce3), or RES'_A = HASH(Kr, Tag ID, UE ID, nonce3), or RES'_A = f2(Kr, Tag ID, UE ID, nonce3).

[0385] The first device authenticates the target second device based on the third response and the third expected response. This may be: if the third response is the same as the third expected response, the first device determines that the authentication of the target second device is successful; otherwise, the first device determines that the authentication of the target second device has failed.

[0386] The processing of each second device is the same as that of the target second device, and the relevant processing of each second device will not be described here one by one.

[0387] After determining that the authentication of each of the second devices is successful, the first device may perform the processing of sending the first message, or the first device may perform the processing of calculating the first response, or the first device may perform the aforementioned processing of sending the third message to each of the one or more second devices. Various possible processing are not enumerated here.

[0388] For each example provided in the embodiments of the present application (including each example below), the first device can be a terminal device or a first access network device, so the UE ID involved in the above examples or formulas can be replaced by any one of gNB ID, eNB ID, etc., and the UE-related keys involved in each formula (such as shared keys or intermediate keys) can be replaced by keys related to the first access network device (for example, KUE can be replaced by KgNB, KAUSF-UE can be replaced by KAUSF-gNB, etc.); and, in addition to the above-mentioned A-IoT authenticator, the first network device can also be a core network device such as AUSF, AMF, SEAF, AIoT network element, UPF, etc., so the AIoT Authenticator ID involved in the above examples or formulas can also be replaced by at least one of AUSFID, AMF ID, SEAF ID, AIoT network element ID, UPF ID, etc., and all possible situations are not described here one by one.

[0389] In conjunction with the indirect mode processing architecture of the A-IoT device (i.e., any of the aforementioned second devices) provided in Figure 4, a possible exemplary illustration of the above-mentioned authentication method is provided: the UE / base station (i.e., the aforementioned first device) acts as an authentication agent to authenticate the A-IoT device, and the core network only authenticates the UE and does not authenticate the A-IoT device. Furthermore, the A-IoT device and the UE or base station (hereinafter only using the UE as an example) have a shared key, which can be the root key Kr of the A-IoT device shared with the core network. The A-IoT device authenticates the UE using physical layer authentication. The core network authenticates the A-IoT based on the A-IoT device root key Kr. However, since the UE possesses the A-IoT root key Kr, the authentication of the A-IoT can be completed on the UE proxy. The 5G AKA and the RES' (i.e., the aforementioned first response) that authenticates the A-IoT do not need to be calculated by the A-IoT, thereby reducing the computational burden of the A-IoT. In addition, authentication can also be performed between the core network and a server (e.g., a third-party server of an AIOT service), and this part of the processing is not limited in this embodiment.

[0390] In conjunction with Figure 5a, an exemplary explanation of the above authentication method is given. Taking the second device as A-IoT (i.e., A-IoT device), the first device as UE (as proxy authentication), and the core network side device as the core network side as an example, the above A-IoT, UE, and core network side can use the same first shared key and A-IoT ID to perform authentication processing. Specifically, after the UE receives the authentication request from the core network side (which can carry the A-IoT ID), the generation of RES' (i.e., the aforementioned first response) needs to include the Kr or shared key (i.e., the first shared key) of the A-IoT device to achieve the purpose of authentication; Figure 5a illustrates a possible calculation method for RES': RES' = HASH (Kue||Kr, A-IoT ID, UE ID, nonce1). The meaning of each parameter in this formula is the same as in the above embodiment and is not repeated. The core network uses the same method as the UE to generate XRES' (i.e., the aforementioned first expected response) and verifies that RES' = XRES' to complete the authentication of the IoT device. Before the UE calculates the first response, the A-IoT device can also authenticate the UE, such as physical layer authentication. The above-mentioned A-IoT device can also be replaced by a zero-power device, and the A-IoT ID in the above formula can also be replaced by a tag ID, which will not be repeated here. It should also be noted that in relation to Figure 5a, XRES' can be calculated on the core network side before sending the authentication request (such as shown in the first dotted box on the core network side in Figure 5a), or the core network side can calculate XRES' after receiving the confirmation (carrying RES') sent by the UE (as shown in the second dotted box on the core network side in Figure 5a). This example does not limit the specific execution timing of the calculation of XRES' on the core network side. In addition, the above-mentioned shared key can be a shared key derived from the root key Kr of the A-IoT device. In the process of the above-mentioned A-IoT device authenticating the UE using physical layer authentication, the A-IoT device may need to perform some authentication calculations.

[0391] The above authentication method is illustrated in conjunction with Figure 5b. For example, the second device is an A-IoT (i.e., an A-IoT device), the first device is a first access network device (e.g., the gNB in ​​Figure 5b), and the core network device is represented as the core network. The A-IoT, gNB, and core network can use the same first shared key and A-IoT ID to perform authentication. Specifically, after receiving the authentication request (which may include the A-IoT ID) from the core network, the gNB generates RES' (i.e., the aforementioned first response), which includes the A-IoT device's Kr or shared key (i.e., the first shared key) to achieve authentication. Figure 5b illustrates a possible calculation method for RES': RES' = HASH(Kue||Kr, A-IoT ID, gNB ID, nonce1). The meanings of the various parameters in this formula are the same as in the previous embodiment and are not repeated here. The core network generates XRES' (i.e., the aforementioned first expected response) using the same method as the gNB and verifies that RES' = XRES', completing authentication of the IoT device. Before the gNB calculates the first response, the A-IoT device can also authenticate the gNB. The aforementioned A-IoT device can also be replaced with a zero-power device, and the A-IoT ID in the above formula can also be replaced with a tag ID. This explanation is not repeated here. Regarding Figure 5b, it should also be noted that the core network can calculate XRES' before sending the authentication request to the gNB (as shown in the first dashed box on the core network side in Figure 5b), or the core network can calculate XRES' after receiving the confirmation (carrying RES') from the gNB (as shown in the second dashed box on the core network side in Figure 5b). This example does not limit the specific timing of calculating XRES' on the core network side. Furthermore, the aforementioned shared key can be a shared key derived from the A-IoT device's root key Kr. During the A-IoT device's authentication process with the gNB, the A-IoT device may need to perform some authentication calculations.

[0392] In conjunction with Figure 6, the authentication method provided in the aforementioned embodiment is exemplified. In Figure 6, taking a scenario of a second device as an example, the second device is represented as an A-IoT device, the first device is a terminal device or a first access network device, and the first device is represented as a UE / gNB (that is, the first device is a UE or a gNB) in Figure 6. The first shared key is the root key Kr. For simplicity, the core network side devices are merged into core network side network elements and represented as AUSF / UDM / ARPF in Figure 6. The authentication method of Figure 6 is that the UE authenticates the A-IoT device based on the root key. The processing flow of Figure 6 is summarized as follows: a pre-condition is adopted: the A-IoT device and the UE / gNB and the core network side network element share the root key Kr of the A-IoT device; the authentication method includes: the UE generates RES', and the generation of RES' needs to include the A-IoT Kr or the shared key to achieve the purpose of authentication, specifically in any of the following ways: RES' = HASH(Kr, Tag ID, UE ID, nonce1), RES' = f2(Kr, Tag ID, UE ID, nonce1), RES' = HASH(Kr, Tag ID, UE ID, RES, nonce1), where the tag ID can be replaced with the A-IoT ID. The core network side network element uses the same method to generate XRES' and verifies that RES' = XRES' to complete the authentication of the IoT device; or the authentication method includes: the gNB generates RES', and the generation of RES' needs to include the A-IoT Kr or the shared key to achieve the purpose of authentication, specifically in any of the following ways: RES' = HASH(Kr, Tag ID, gNB The core network side network element uses the same method to generate XRES' and verify that RES' = XRES' to complete the authentication of the IoT device.

[0393] The specific processing flow of Figure 6 includes:

[0394] In step S601, the A-IoT device sends an authentication request to the UE / gNB, carrying the A-IoT ID. The UE can be a relay UE or a proxy UE.

[0395] Optionally, S600 may be included before S601: the UE / gNB triggers the AIoT device. For example, the UE / gNB may send a trigger message to the AIoT device to trigger the AIoT device to send an authentication request.

[0396] S602: The UE / gNB forwards the authentication request to the AUSF, carrying the A-IoT ID and UE ID.

[0397] S603, AUSF / UDM / ARPF calculates XRES' (ie, the first expected response).

[0398] Specifically, the AUSF checks the whitelist to see if it includes the binding relationship between the UE / gNB and the A-IoT device, and whether the UE / gNB can provide a wireless or relay connection for the A-IoT device. If so, the process proceeds to the next step; otherwise, the process terminates. The AUSF sends an authentication request to the UDM / ARPF, carrying the A-IoT ID. The UDM / ARPF performs 5G AKA, calculates the A-IoT's 5G HEAV, including MAC, XRES, KAUSF, and RAND, and calculates XRES', which it sends to the AUSF.

[0399] Among them, if the first device is a UE, the calculation of XRES' may include XRES'=HASH(Kr,A-IoT ID,UE ID,nonce1); if the first device is a gNB, the calculation of XRES' may include XRES'=HASH(Kr,A-IoT ID,gNB ID,nonce1). Other possible calculation formulas are the same as those in the previous embodiment and are not repeated here.

[0400] S604: The AUSF sends an authentication response to the UE / gNB, carrying the A-IoT ID and MAC (i.e., the first message authentication code). This authentication response may be the second message in the aforementioned embodiment.

[0401] In S605, the UE / gNB calculates RES, MAC, and KAUSF based on Kr. The UE verifies MAC and successfully completes authentication on the core network side.

[0402] Optionally, the A-IoT device performs physical layer authentication with the UE based on Kr. At step S606, the UE / gNB sends a physical layer authentication request to the A-IoT device. At step S607, the A-IoT device sends a secret pilot to the UE. At step S608, the UE / gNB calculates a verification code based on Kr and the secret pilot and sends it to the A-IoT device. At step S609, the A-IoT device successfully authenticates the UE / gNB based on the verification code. At step S610, the A-IoT device sends an authentication success message to the UE / gNB.

[0403] Optionally, the UE / gNB authenticates the A-IoT device, for example, using a PUF principle. This includes the following steps: S611: The UE / gNB authenticates the A-IoT device based on the PUF principle. S612: After the UE / gNB authenticates the A-IoT device based on the PUF principle, it sends a verification success message.

[0404] Optionally, the UE / gNB can authenticate the AIoT device by calculating the third expected response (XRES-AIOT) of the AIoT device. For example, this may include: S611': The UE / gNB calculates XRES-AIOT based on Kr or KAUSF-A and sends the fifth random number used to calculate XRES-AIOT to the A-IoT device. The method for calculating XRES-AIOT in this step is the same as in the previous embodiment and is not repeated here. S612': The A-IoT device calculates RES-AIOT based on Kr and sends it to the UE / gNB. The UE / gNB verifies that XRES-AIOT = RES-AIOT, successfully authenticating the A-IoT device.

[0405] S613: The UE / gNB sends an authentication confirmation to the AUSF, carrying RSE'. The method for the UE / gNB to calculate RES' has been described in detail in the previous embodiment and is not repeated here.

[0406] S614, AUSF verifies RES'=XRES' and successfully verifies the A-IoT device.

[0407] It should be noted that the above S613 and S614 may be executed after S605 successfully completes the authentication on the core network side, and S606 to S612, and / or S611 to S612, and / or S611' to S612' may not be executed. Alternatively, the above S613 and S614 may be executed after S605 successfully completes the authentication on the core network side and after the above S610 is completed, that is, the above S611 to S612 and / or S611' to S612' may not be executed. Alternatively, the above S613 and S614 may be executed after S605 successfully completes the authentication on the core network side and after the above S610 is completed, and after S612 is further completed. In this case, the processing of S611' to S612' is not executed. Alternatively, the above S613 and S614 may be executed after the above S605 is successfully authenticated on the core network side, after the above S610 is completed, and after S612' is further completed. In this case, the processes of S611 to S612 are not executed.

[0408] It should also be noted that in the above process, the authentication response in S604 may carry various random numbers (such as the first random number, the second random number, and so on in the aforementioned embodiment, which are not exhaustive), and the corresponding authentication confirmation in S613 may only carry RES'. Alternatively, in the above process, the authentication response in S604 may not carry various random numbers, and the corresponding authentication confirmation in S613 may carry, in addition to RES', various random numbers used to calculate RES'.

[0409] Still in combination with the above Figure 6, another exemplary explanation of the authentication method is given. In another example, 5G AKA can be performed based on the UE's second shared key (for example, the UE's root key KAUSF-UE) to complete the authentication of the network.

[0410] In this example, S601 to S602 are the same as those in the previous example and are not described in detail.

[0411] The AUSF / UDM / ARPF calculation XRES' (i.e., the first expected response) processing in S603, in this example, is performed by the UE / gNB and the network based on the root key of the UE / gNB to obtain the UE's 5G HE AV and complete the authentication of the network. Specifically, the AUSF checks the whitelist to see whether it includes the binding relationship between the UE / gNB and the A-IoT device, and whether the UE / gNB can provide a wireless connection or relay connection for the A-IoT device. If the check result is yes, the AUSF sends an authentication request to the UDM / ARPF, carrying the UE ID (or gNB ID), and the UDM performs 5G AKA, calculates the UE's (or gNB's) 5G HE AV, including MAC, XRES, XRES'KAUSF-UE, RAND, and sends it to the AUSF. If the check result is otherwise, the process is terminated.

[0412] In addition, in this example, the root key of the UE / gNB is also added to the process of calculating XRES', which may include one of the following: XRES'=f2(KAUSF-UE||Kr,A-IoT ID,UE ID,nonce1), XRES'=HASH(KAUSF-UE||Kr,A-IoT ID,UE ID,nonce1), XRES'=f2(KAUSF-UE||KAUSF-A,A-IoT ID,UE ID,nonce1), XRES'=HASH(KAUSF-UE||KAUSF-A,A-IoT ID,gNB ID,nonce1), XRES'=f2(KAUSF-UE||Kr,A-IoT ID,gNB ID,nonce1). ID, nonce1), XRES'=HASH(KAUSF-UE||KAUSF-A, A-IoT ID, gNB ID, nonce1); the above || can be replaced by an XOR algorithm, etc. The meanings of the parameters in the above formulas are the same as those in the previous embodiment and are not repeated here.

[0413] The processing of S604 to S612 or S604 to S612' in this example is the same as that in the above example and will not be described in detail.

[0414] In the process of S613, the UE / gNB calculates RES' in the same manner as the aforementioned calculation of XRES', and no further explanation is given.

[0415] In conjunction with Figure 7, the aforementioned authentication method is further illustrated by taking a second device as an example. In the example of Figure 7, an authentication network element (i.e., authentication device) A-IoT authenticator is added. In Figure 7, the second device is an A-IoT device, the first device is a UE / gNB, the first network device is an A-IoT authenticator, and the core network side devices other than the first network device are represented as AUSF / UDM / ARPF. In the example of Figure 7, the random number nonce2 (i.e., the aforementioned third random number) is generated by the A-IoT authenticator, KA-IoT (i.e., the second intermediate key) is generated based on KAUSF-A (i.e., the first shared key), and XRES' is generated based on KA-IoT.

[0416] Optionally, at S700, the UE / gNB triggers the AIoT device. For example, the UE / gNB may send a trigger message to the AIoT device to trigger the AIoT device to send an authentication request.

[0417] In the specific processing flow, the processing of S701 to S702 is the same as that of the aforementioned S601 to S602 and will not be described in detail.

[0418] S703, AUSF / UDM / ARPF calculates 5G HE AV and sends it to the A-IoT authenticator. For example, AUSF sends 5G HE AV (including XRES, the aforementioned second expected response, including MAC) to the authentication network element A-IoT authenticator, which can be a base station, AMF, SEAF, UPF, service server, A-IoT network element, etc.

[0419] S704, the A-IoT authenticator calculates XRES' (ie, the first expected response).

[0420] Optionally, the A-IoT authenticator generates a random number nonce2, generates KA-IoT according to KAUSF-A, generates XRES' according to KA-IoT, and the A-IoT authenticator replaces the XRES in 5G HE AV with XRES' and stores it locally; or, the AUSF generates a random number nonce2, generates KA-IoT according to KAUSF-A, generates XRES' according to KA-IoT, and sends XRES' to the A-IoT authenticator. The calculation method of KA-IoT is the same as that in the aforementioned embodiment and will not be repeated. If the first device is a UE, the calculation of XRES' may include one of the following: XRES'=f2(KA-IoT, A-IoT ID, UE ID, nonce1), XRES'=HASH(KA-IoT, A-IoT ID, UE ID, nonce1). The above-mentioned various possible processing are the same as those in the aforementioned embodiment and will not be repeated. If the first device is a gNB, calculating XRES' may include one of the following: XRES' = f2(KA-IoT, A-IoT ID, gNB ID, nonce1), XRES' = HASH(KA-IoT, A-IoT ID, gNB ID, nonce1). The above possible processing is the same as in the previous embodiment and is not further described.

[0421] Optionally, the A-IoT authenticator performs 5G AKA based on the UE's root key (i.e., KAUSF-UE). For example, the A-IoT authenticator generates a random number nonce2, generates KUE (a third intermediate key) based on the UE's KAUSF-UE, and then calculates XRES' based on the third intermediate key. The method for calculating KUE is the same as in the previous embodiment and is not described in detail. Accordingly, the method for calculating XRES' based on KUE may include one of the following: XRES'=f2(KUE||Kr,A-IoT ID,UE ID,nonce1), XRES'=HASH(KUE||Kr,A-IoT ID,UE ID,nonce1), XRES'=f2(KUE||KAUSF-A,A-IoT ID,UE ID,nonce1), XRES'=HASH(KUE||KAUSF-A,A-IoT ID,UE ID,nonce1).

[0422] Optionally, the A-IoT authenticator performs 5G AKA based on the gNB's root key (i.e., KAUSF-gNB). For example, the A-IoT authenticator generates a random number, nonce2, generates KUE (a third intermediate key) based on the gNB's KAUSF-gNB, and then calculates XRES' based on the third intermediate key. The method for calculating KgNB is the same as in the previous embodiment and is not further described. Accordingly, the method for calculating XRES' based on KgNB may include one of the following: XRES' = f2(KgNB||Kr, A-IoT ID, gNB ID, nonce1), XRES' = HASH(KgNB||Kr, A-IoT ID, gNB ID, nonce1), XRES' = f2(KgNB||KAUSF-A, A-IoT ID, gNB ID, nonce1), XRES' = HASH(KgNB||KAUSF-A, A-IoT ID, gNB ID, nonce1).

[0423] In addition, the calculation method of the above XRES' can also be HASH (XRES, A-IoT authenticator ID, nonce1), which is not described here.

[0424] The specific processing of S705 to S715 is the same as the specific description of S604 to S614 in the above example. The only difference is that the method of calculating RES' is the same as the calculation of XRES' in S704, so it is not repeated here.

[0425] In conjunction with FIG8 , taking a plurality of second devices as an example to form a device group, another exemplary explanation of the aforementioned authentication method is given. The example in FIG8 also includes an authentication network element (i.e., authentication device) A-IoT authenticator. In FIG8 , for the sake of simplicity, only any one of the plurality of second devices is illustrated, and the arbitrary second device is represented as an A-IoT device. In addition, the example in FIG8 is illustrated by taking the first device as UE / gNB, the first network device as A-IoT authenticator, and the core network side devices other than the first network device as including AUSF / UDM / ARPF as an example.

[0426] S801: The server sends a trigger command, which carries multiple A-IoT IDs and / or Group-IDs associated with multiple A-IoT devices to be triggered.

[0427] S802, AUSF obtains 5G HE AV of each A-IoT.

[0428] For example, AUSF checks the whitelist to determine the binding relationship between Group-ID and A-IoT ID, and searches for the UE ID (or gNB ID) bound to them. These UE / gNBs can provide wireless or relay connections for A-IoT devices. It also searches for the A-IoT authenticator bound to them. Furthermore, AUSF sends an authentication request to UDM / ARPF, carrying the A-IoT ID, Group ID, authenticator ID, UE ID, and UDM / ARPF for 5G AKA. It calculates the 5G HE AV of A-IoT, including MAC, XRES, KAUSF, and RAND, and sends the 5G HE AC of each A-IoT device to AUSF.

[0429] S803: The AUSF sends an authentication request to the A-IoT authenticator. Because the network server triggers authentication, the AUSF sends the authentication request to the A-IoT authenticator, which carries 5G HEAV. The A-IoT authenticator can be a base station, AMF, SEAF, UPF, service server, A-IoT network element, etc.

[0430] S804: The A-IoT authenticator calculates XRES'_Group. For example, the A-IoT authenticator generates a random number, nonce-i, for each A-IoT device, generates KA-IoT-i based on KAUSF-i, and generates an XRES'_Group based on the KA-IoT-i of each A-IoT device. The method for calculating XRES'_Group is detailed in the previous embodiment and will not be repeated here.

[0431] S805: The A-IoT authenticator sends an authentication request to the UE / gNB. The authentication request carries the A-IoT ID, the MAC address of each A-IoT, the A-IoT authenticator ID, and so on.

[0432] Optionally, after S805 is completed, at least one of the following may also be performed: each A-IoT device performs physical layer authentication on the UE / gNB based on Kr; the UE / gNB authenticates each A-IoT device; or the UE / gNB authenticates each AIoT device. The aforementioned authentication processes between the UE / gNB and each A-IoT device, namely S806 to S810, S811 to S812, and S811' to S812', are identical to the aforementioned S606 to S610, S611 to S612, and S611' to S612', and are not repeated here.

[0433] At step S813, the UE / gNB sends an authentication response to the A-IoT authenticator, including the RSE'-Group. The UE calculates the RES'-Group in the same manner as the XRES'-Group.

[0434] S814, A-IoT Authenticator verifies RES'_Group = XRES'_Group, successfully authenticates group A-IoT, trusts A-IoT is not a malicious device, and also trusts the sent data.

[0435] Optionally, the authentication request in S803 may also carry the random numbers of each A-IoT device (for example, the first random number of the i-th A-IoT device is represented as NONCE1i) and XRES'_Group. That is, the AUSF generates a random number nonce1 for each A-IoT device, generates KA-IoT based on KAUSF-A, and generates an XRES'_Group based on the KA-IoT of each A-IoT device. The AUSF sends an authentication request, including the XRES'_Group, to the A-IoT authenticator; then executes S805, and the A-IoT authenticator forwards the authentication request to the UE, including MAC, A-IoT authenticator ID, A-IoT ID-1…A-IoT ID-I, nonce-1…nonce-i, RAND.

[0436] Optionally, before the processing of S813, for example, before S806, it may also include: the UE / gNB performs 5G AKA calculation RES, MAC, and KAUSF based on any Kr, the UE / gNB verifies the MAC, and successfully completes the authentication on the core network side.

[0437] Optionally, in S802 , the MAC calculation may be performed to generate a MAC_Group for the group of A-IoT devices, and the MAC_Group may be included in the authentication request in S805 . Accordingly, the UE-verified MAC mentioned above refers to the UE / gNB-verified MAC_Group. The MAC_Group calculation method is the same as in the previous embodiment and is not further described.

[0438] In conjunction with Figure 9, taking a second device as an example, the above-mentioned authentication method is further exemplified. In Figure 9, the second device is represented as an A-IoT device, the first device is represented as UE / gNB, and the core network side device is simplified as AUSF / UDM / ARPF.

[0439] S901: The A-IoT device sends an authentication request to the UE / gNB, carrying the A-IoT ID.

[0440] After completing S901, the A-IoT device and the UE / gNB may also perform at least one of the following: the A-IoT device performs physical layer authentication of the UE / gNB based on Kr; the UE / gNB authenticates the A-IoT device; or the UE / gNB authenticates the A-IoT device. The various authentication processes between the UE and the A-IoT device, namely S902-S906, S907-S908, and S907'-S908', are similar to S606-S610, S611-S612, and S611'-S612' described above and are not repeated here.

[0441] In step S909, the UE / gNB generates random numbers and calculates RES'. The calculation method of RES' is the same as in the previous embodiment and is not further described.

[0442] S910: The UE / gNB sends an authentication request to the AUSF. The authentication request carries RES'.

[0443] S911, AUSF calculates XRES' and verifies that RES'=XRES'. The calculation method of XRES' is the same as that in the above embodiment and will not be described in detail.

[0444] S912: If the AUSF verification is successful, an authentication success message is sent to the UE.

[0445] In conjunction with Figure 10, taking a second device as an AIoT device as an example, another exemplary explanation of the above authentication method is given.

[0446] S1001: The A-IoT device sends an authentication request to the UE, which carries the A-IoT ID. The UE here can be a relay UE or a proxy UE.

[0447] S1002, the UE initiates an authentication request to SEAF / AUSF / UDM / ARPF (core network side device), carrying the UE ID and AIoT ID.

[0448] In this example, the authentication request in S1002 may only carry one AIoT ID. In some possible examples, if multiple AIoT devices execute S1001, the authentication request in S1002 may carry multiple AIoT IDs. In addition, the core network side device that receives the authentication request may be AUSF, and of course, it may also be at least one of SEAF, UDM, and ARPF. The core network side device that receives the authentication request is not limited or exhaustive here.

[0449] S1003, SEAF / AUSF / UDM / ARPF (core network side device) calculates XRES' (ie, first expected response) and MAC' (ie, first message authentication code) based on the UE's root key (KAUSF shared by the UE and the core network side device).

[0450] For example, SEAF / AUSF / UDM / ARPF checks the whitelist or contract data to see if it includes the binding relationship between the UE and the A-IoT terminal, and whether the UE can provide a wireless connection or relay connection for the A-IoT terminal. If the check result is yes (for example, if the UE is an intermediate node of the A-IoT terminal, or a proxy device of the A-IoT terminal, or a service binding device of the A-IoT terminal), the process of obtaining XRES' and MAC' is executed; otherwise, the process is terminated.

[0451] Optionally, the above processing of checking the binding relationship can be performed by AUSF. If the check result is yes, the processing of obtaining XRES' and MAC' performed by AUSF may include: sending an authentication request to UDM / ARPF, carrying UE ID and AIoT ID; UDM / ARPF uses the UE's root key KAUSF-UE to perform a calculation similar to 5G AKA to obtain the UE's 5G HE AV, which includes MAC', XRES, XRES'KAUSF-UE, RAND, and sends the 5G HE AV to AUSF. The specific calculation method of XRES' and MAC' is the same as that in the previous embodiment and will not be repeated.

[0452] S1004, SEAF / AUSF / UDM / ARPF sends an authentication response (ie, the second message in the aforementioned embodiment) to the UE, which may include MAC'.

[0453] In step S1005, the UE calculates RES' (first response) and XMAC' (second message authentication code) based on the UE's root key (KAUSF shared by the UE and the core network device). The UE authenticates the core network (SEAF / AUSF / UDM / ARPF) based on XMAC' and MAC'. For example, if XMAC' is the same as MAC', authentication of the core network is successfully completed, and then step S1006 is executed. The specific calculation method of RES' and XMAC' is the same as in the previous embodiment and will not be repeated.

[0454] S1006: The UE sends RES' to SEAF / AUSF / UDM / ARPF. The RES' may be carried by the first message in the aforementioned embodiment.

[0455] S1007: SEAF / AUSF / UDM / ARPF authenticates the UE based on RES' and XRES'. Specifically, if RES' and XRES' are the same, it is determined that the UE is authenticated, authorizing the UE to provide a wireless connection or relay connection to the A-IoT terminal, or to establish a binding relationship between the UE and the AIoT terminal, or to connect the UE to the AIoT terminal for appropriate services.

[0456] S1008, SEAF / AUSF / UDM / ARPF sends an authentication success message to the UE.

[0457] After receiving the authentication success message, the UE starts authentication with the AIoT terminal.

[0458] Optionally, authentication may be performed using the authentication methods provided in the aforementioned examples.

[0459] Optionally, the root key Kr of the A-IoT device can be used for authentication, where the root key of the AIoT device is shared by the AIoT device and the UE.

[0460] S1009, UE can use Kr to generate MAC'_A (the verification code corresponding to the AIoT device) and XRES'_A (the third expected response of the AIoT device). The specific calculation method of MAC'_A and XRES'_A is the same as that in the previous embodiment and will not be repeated.

[0461] S1010: The UE sends an authentication response to the AIoT device, carrying the UE ID, AIoT ID, MAC'_A, and nonce3 (i.e., the fifth random number). This authentication response can be called the authentication response corresponding to the AIoT device.

[0462] In step S1011, the AIoT device uses Kr to generate XMAC'_A (the verification code corresponding to the AIoT device) and RES'_A (the third response), and authenticates the UE based on MAC'_A and XMAC'_A. Specifically, if MAC'_A and XMAC'_A are the same, the UE is successfully authenticated. The specific calculation method for XMAC'_A and RES'_A is the same as in the previous embodiment and is not further described.

[0463] S1012, the AIoT device sends an authentication confirmation to the UE, carrying RES'_A.

[0464] S1013: When RES'_A is the same as X RES'_A, the UE determines that the AIoT device has been successfully authenticated.

[0465] It should also be noted that the execution order of the above process can also be adjusted. For example, the above S1009 to S1012 can also be replaced and executed after S1001 and before S1002. Alternatively, the above S1009 to S1012 can also be replaced and executed in other steps. This is not limited or exhaustive.

[0466] Another exemplary description of the aforementioned authentication method is given with reference to FIG11 .

[0467] S1101, SEAF / AUSF / UDM / ARPF (core network side device) calculates XRES' (ie, first expected response) and MAC' (ie, first message authentication code) based on the UE's root key (KAUSF shared by the UE and the core network side device).

[0468] S1102, SEAF / AUSF / UDM / ARPF (core network side device) sends an authentication request (i.e., the second message of the aforementioned embodiment) to the UE, which may include UE ID, one or more AIoT IDs (IDs of one or more AIoT devices), and MAC'.

[0469] In step S1103, the UE calculates RES' (first response) and XMAC' (second message authentication code) based on the UE's root key (KAUSF shared by the UE and the core network device). The UE authenticates the core network (SEAF / AUSF / UDM / ARPF) based on XMAC' and MAC'. For example, if XMAC' and MAC' are the same, authentication of the core network is successful, and then step S1104 is executed.

[0470] S1104, the UE sends RES' to SEAF / AUSF / UDM / ARPF in an authentication response, where the authentication response may be the first message in the aforementioned embodiment.

[0471] S1105: SEAF / AUSF / UDM / ARPF authenticates the UE based on RES' and XRES'. Specifically, if RES' is the same as XRES', it determines that the UE is authenticated, authorizing the UE to provide a wireless connection or relay connection to the A-IoT terminal, or to establish a binding relationship between the UE and the AIoT terminal, or to connect the UE to the AIoT terminal for appropriate services.

[0472] S1106, SEAF / AUSF / UDM / ARPF sends an authentication confirmation message to the UE.

[0473] After receiving the authentication confirmation message, the UE starts authentication with the AIoT terminal.

[0474] S1107, UE can use Kr to generate MAC'_A (the verification code corresponding to the AIoT device) and XRES'_A (the third expected response of the AIoT device). The specific calculation method of MAC'_A and XRES'_A is the same as that in the previous embodiment and will not be repeated here.

[0475] S1108: The UE sends an authentication request to the AIoT device (e.g., each of one or more AIoT devices; FIG11 illustrates only one AIoT device for simplicity), carrying the UE ID, AIoT ID, MAC'_A, and nonce3 (i.e., the fifth random number). This authentication response may be referred to as the authentication response corresponding to the AIoT device.

[0476] In step S1109, the AIoT device uses Kr to generate XMAC'_A (the verification code corresponding to the AIoT device) and RES'_A (the third response), and authenticates the UE based on MAC'_A and XMAC'_A. Specifically, if MAC'_A and XMAC'_A are the same, the UE is successfully authenticated. The specific calculation method for XMAC'_A and RES'_A is the same as in the previous embodiment and is not further described.

[0477] S1110, the AIoT device sends an authentication response to the UE, carrying RES'_A.

[0478] S1111. When RES'_A is the same as X RES'_A, the UE determines that the AIoT device is successfully authenticated.

[0479] As can be seen, by adopting the above authentication method, the first device can send a first response to cause the core network device to perform authentication related to each second device. In this way, the first device can authenticate the second device with the network on behalf of the second device. While ensuring that the core network device can authenticate the second device, it avoids performing complex calculations on the second device, reducing the computational burden on the second device.

[0480] Figure 12 is a schematic flow chart of an authentication method according to an embodiment of the present application. The method includes at least part of the following contents.

[0481] S1210. The first device receives a second message from a core network side device, wherein the second message carries one or more first message authentication codes for authenticating the core network side device.

[0482] Figure 13 is a schematic flow chart of an authentication method according to another embodiment of the present application. The method includes at least part of the following contents.

[0483] S1310. The core network side device sends a second message to the first device, wherein the second message carries one or more first message authentication codes for authenticating the core network side device.

[0484] The method on the first device side also includes: the first device calculates a second message authentication code based on at least one shared key, wherein the at least one shared key includes at least one of the following: one or more first shared keys, a second shared key, different first shared keys among the one or more first shared keys are shared by different second devices with the first device and the core network side device, and the second shared key is shared by the first device and the core network side device; the first device authenticates the core network side device based on the second message authentication code and the one or more first message authentication codes.

[0485] The method on the core network side device also includes: the core network side device calculates the one or more first message authentication codes based on at least one shared key, wherein the at least one shared key includes at least one of the following: one or more first shared keys, a second shared key, different first shared keys among the one or more first shared keys are shared by different second devices with the first device and the core network side device, and the second shared key is shared by the first device and the core network side device.

[0486] Regarding this embodiment, the first message authentication code, the second message authentication code, the first shared key, the second shared key and related processing instructions are the same as those in the previous embodiment and will not be repeated.

[0487] It should be noted that the authentication method provided in this embodiment can only perform the processing of authenticating the core network side device, that is, in the simplest embodiment, only the first device can replace one or more second devices to authenticate the core network side device.

[0488] If one or more second devices trigger authentication, the first device can also receive authentication requests from one or more second devices, and send authentication requests to the core network side device; accordingly, the core network side device can send a second message after receiving the authentication request.

[0489] Taking Figure 10 as an example, only the processing of S1001 to S1005 can be executed, and the processing of calculating RES' and calculating XRES' can be not executed, so that the first device replaces one or more second devices (AIoT devices) to authenticate SEAF / AUSF / UDM / ARPF (core network side device); if the authentication is successful, the UE can also send an authentication confirmation to SEAF / AUSF / UDM / ARPF (core network side device) to indicate that the authentication is successful, and / or the UE can send an authentication response to the AIoT device to indicate that the authentication of the core network side device is completed.

[0490] If the core network side device triggers authentication, the core network side device may directly send a second message, and the second message may also be used to request authentication.

[0491] Taking Figure 11 as an example, only the processing of S1101 to S1103 may be performed, and the processing of calculating RES' and calculating XRES' may not be performed, so that the first device replaces one or more second devices to authenticate SEAF / AUSF / UDM / ARPF (core network side device). If the authentication is successful, the UE may also send an authentication response to SEAF / AUSF / UDM / ARPF (core network side device) to indicate that the authentication is successful. Optionally, if the authentication is successful, the UE may send an authentication response to the AIoT device to indicate that the authentication of the core network side device is completed.

[0492] In this embodiment, the first device may also perform authentication with each second device. The specific processing method is the same as that in the above embodiment and will not be repeated.

[0493] As can be seen, by adopting the above authentication method, the first device can authenticate the core network device by receiving one or more first message authentication codes from the core network device. In this way, the first device can authenticate the network side on behalf of the second device, and it can also avoid performing complex calculations on the second device, reducing the computational burden on the second device.

[0494] Figure 14 is a schematic flow chart of an authentication method according to an embodiment of the present application. The method includes at least part of the following contents.

[0495] S1410. The first device calculates a target verification code for authenticating the first device based on a third shared key shared with the target second device;

[0496] S1420. The first device sends a third message to the target second device, where the third message carries the target verification code.

[0497] Figure 15 is a schematic flow chart of an authentication method according to another embodiment of the present application. The method includes at least part of the following contents.

[0498] S1510. The target second device receives a third message from the first device, wherein the third message carries a target verification code for authenticating the first device, and the target verification code is related to a third shared key shared by the target second device and the first device.

[0499] S1520: The target second device authenticates the first device based on the target check code and the target verification code.

[0500] The method further includes: the target second device calculating the target verification code based on the third shared key and at least one of the following: a fifth random number, an identifier of the target second device, and an identifier of the first device.

[0501] In this embodiment, the first device and the target second device perform the calculation of the target verification code, the calculation of the target check code and other related instructions, the relevant instructions of the third shared key, the interaction process between the first device and the target second device and the related messages are the same as the previous embodiment, so they are not repeated.

[0502] By using this authentication method, the second device can authenticate the first device by verifying the target verification code of the first device, thereby accessing the core network through the first device. This eliminates the need for the second device to perform complex operations and achieve authentication, thus reducing the computational burden on the second device.

[0503] Figure 16 is a schematic flow chart of an authentication method according to an embodiment of the present application. The method includes at least part of the following contents.

[0504] S1610. The first device receives a fourth message from a target second device, where the fourth message carries a third response for authenticating the target second device, and the third response is related to a third shared key shared by the target second device and the first device.

[0505] S1620. The first device authenticates the target second device based on the third response and the third expected response.

[0506] Figure 17 is a schematic flow chart of an authentication method according to another embodiment of the present application. The method includes at least part of the following contents.

[0507] S1710. The target second device sends a fourth message to the first device, where the fourth message carries a third response for authenticating the target second device, and the third response is related to a third shared key shared by the target second device and the first device.

[0508] The method further includes: the target second device calculating the third response based on the third shared key and at least one of the following: a fifth random number, an identifier of the target second device, and an identifier of the first device.

[0509] In this embodiment, the first device and the target second device execute the third response, the calculation of the third expected response, and other related instructions, the third shared key, the interaction process between the first device and the target second device, and the related messages are the same as those in the previous embodiment, so they are not repeated here.

[0510] By adopting the above authentication method, the first device and the second device can authenticate the second device through an expected response. This eliminates the need for the second device to perform more complex interactions with the core network to achieve authentication, eliminating the need for complex calculations on the second device, and reducing the computational burden on the second device.

[0511] Finally, the beneficial effects of the solution provided by this embodiment are described in combination with relevant technologies.

[0512] Ambient IoT is a new type of IoT terminal being researched in 3GPP Release 19. It is a type of IoT device powered by energy harvesting, lacking batteries or with limited energy storage capacity. The devices are extremely low cost, but their computing power is extremely limited. Currently, there are two network architectures in the industry: direct mode and indirect mode.

[0513] In related technologies, a UE must undergo authentication and key negotiation before accessing the 5G network and using network resources. Based on the authentication results, the network authorizes the UE to use network resources and services. The 3GPP security standards define the 5G AKA process and the cryptographic algorithms used. The authentication and authorization credentials used in the UE's AKA process are based on the symmetric root key K, which is centrally stored on the network side by the core network's UDM / ARPF network elements. Each authorization requires the UDM to obtain the authorization credentials and the core network to perform the corresponding authentication calculations.

[0514] The above analysis shows that the functions used in the AKA authentication and key agreement processes in related technologies have high computational complexity and a complex key architecture, making them unsuitable for secure authentication of A-IoT devices. They also do not support authentication and key agreement between A-IoT devices and UEs / gNBs. Authentication and key agreement are performed between tags and readers, but cannot support authentication and key agreement between A-IoT devices and networks. Compared to the related technologies described above, the various embodiments provided in this application enable the A-IoT device to perform authentication calculations through a first device (which can be either a terminal or an access network device), allowing the network and A-IoT devices to complete bidirectional authentication through the first device. This advantage is that the A-IoT device does not need to perform complex authentication calculations. Furthermore, the first device can proxy the calculation of the authentication parameter RES' for a group of A-IoT devices, allowing the network to complete authentication for a group of A-IoT devices in a single process, improving the efficiency of group A-IoT device authentication. By proxying authentication with the first device, the first device is enabled to manage the security processes of the A-IoT device, enhancing the capabilities of the first device and increasing flexibility and security management efficiency.

[0515] FIG18 is a schematic diagram of the composition structure of a first device according to an embodiment of the present application, including:

[0516] The first communication unit 1801 is used to send a first message to a core network side device, wherein the first message carries a first response, and the first response is used by the core network side device to perform authentication related to one or more second devices.

[0517] The first device also includes: a first processing unit 1802, used to calculate the first response based on at least one shared key, wherein the at least one shared key includes at least one of the following: one or more first shared keys, a second shared key, different first shared keys among the one or more first shared keys are shared by different second devices with the first device and the core network side device, and the second shared key is shared by the first device and the core network side device.

[0518] The first processing unit is configured to calculate the first response based on the identifiers of the one or more second devices and the one or more first shared keys, wherein the first response is used by the core network side device to authenticate the one or more second devices.

[0519] The first processing unit is configured to calculate the first response based on the identifiers of the one or more second devices, the one or more first shared keys, the identifier of the first device, and one or more first random numbers.

[0520] The first processing unit is used to perform one of the following: using a first calculation method to calculate the first response based on the identification of the one or more second devices, the one or more first shared keys, the identification of the first device, and the one or more first random numbers; obtaining one or more intermediate keys based on the one or more first shared keys, and using the first calculation method to calculate the first response based on the identification of the one or more second devices, the one or more intermediate keys, the identification of the first device, and the one or more first random numbers; calculating one or more first intermediate responses based on the identification of the one or more second devices, the one or more first shared keys, the identification of the first device, and the one or more first random numbers, and calculating the first response based on the one or more first intermediate responses.

[0521] The first processing unit is used to perform one of the following: using the first calculation method to calculate the first response based on one or more second responses, the identification of the one or more second devices, the one or more first shared keys, the identification of the first device, and the one or more first random numbers, wherein the one or more second responses are obtained based on the one or more second random numbers; using the first calculation method to calculate the first response based on the second shared key, the identification of the one or more second devices, the one or more first shared keys, the identification of the first device, and the one or more first random numbers; calculating the third intermediate key based on the second shared key, the identification of the first network device and the third random number, and using the first calculation method to calculate the first response based on the third intermediate key, the identification of the one or more second devices, the one or more first shared keys, the identification of the first device, and the one or more first random numbers.

[0522] The first processing unit is configured to perform one of the following: obtaining one or more first intermediate keys based on the one or more first shared keys, and calculating the first response based on one or more second responses, the identification of the one or more second devices, the one or more first intermediate keys, the identification of the first device, and one or more first random numbers using a first calculation method, wherein the one or more second responses are obtained based on one or more second random numbers; obtaining one or more first intermediate keys based on the one or more first shared keys, and calculating the first response based on the second shared key, the identification of the one or more second devices, the one or more first intermediate keys, the identification of the first device, and the one or more first random numbers using the first calculation method, wherein the second shared key is the first device. The device is shared with the core network side device; one or more second intermediate keys are calculated based on the one or more first shared keys, the identification of the first network device and one or more fourth random numbers; the first response is calculated based on the identification of the one or more second devices, the one or more second intermediate keys, the identification of the first device and the one or more first random numbers using the first calculation method; the third intermediate key is obtained based on the second shared key, the identification of the first network device and the third random number, and one or more first intermediate keys are obtained based on the one or more first shared keys; the first response is calculated based on the third intermediate key, the identification of the one or more second devices, the one or more first intermediate keys, the identification of the first device and the one or more first random numbers using the first calculation method.

[0523] The first processing unit is used to perform one of the following: respectively using a first calculation method to calculate the one or more first intermediate responses based on one or more second responses, the identification of the one or more second devices, the one or more first shared keys, the identification of the first device, and one or more first random numbers, wherein the one or more second responses are obtained based on the one or more second random numbers; respectively using the first calculation method to calculate the one or more first intermediate responses based on the second shared key, the identification of the one or more second devices, the one or more first shared keys, the identification of the first device, and the one or more first random numbers; calculating a third intermediate key based on the second shared key, the identification of the first network device and a third random number, respectively using the first calculation method to calculate the one or more first intermediate responses based on the third intermediate key, the identification of the one or more second devices, the one or more first intermediate keys, the identification of the first device, and the one or more first random numbers; respectively obtaining one or more first intermediate keys based on the one or more first shared keys, respectively using the first calculation method to calculate the one or more second responses, the identification of the one or more second devices, the one or more first intermediate keys, the identification of the first device The method comprises the steps of: obtaining a first intermediate key based on the one or more first shared keys, and calculating the one or more first intermediate keys based on the second shared key, the identification of the one or more second devices, the one or more first intermediate keys, the identification of the first device, and the one or more first random numbers; calculating the one or more second intermediate keys based on the one or more first shared keys, the identification of the first network device, and the one or more fourth random numbers; calculating the one or more first intermediate responses based on the identification of the one or more second devices, the one or more second intermediate keys, the identification of the first device, and the one or more first random numbers based on the first calculation method; obtaining a third intermediate key based on the second shared key, the identification of the first network device, and the third random number, and obtaining one or more first intermediate keys based on the one or more first shared keys, and calculating the one or more first intermediate responses based on the third intermediate key, the identification of the one or more second devices, the one or more first intermediate keys, the identification of the first device, and the one or more first random numbers based on the first calculation method.

[0524] The first processing unit is configured to calculate the first response based on the one or more first intermediate responses and at least one of the following: an identifier of the first network device and a third random number by adopting the first calculation method.

[0525] The first communication unit is configured to receive the one or more first shared keys.

[0526] A first processing unit is used to calculate the first response based on the second shared key and at least one of the following parameters: the identifier of the first device, the identifier of the one or more second devices, and the identifier of the first network device, wherein the first response is used by the core network side device to authenticate the first device as an intermediate node of the one or more second devices.

[0527] The first communication unit is used to receive a second message from the core network side device, where the second message carries at least one of the following: an identifier of the one or more second devices, an identifier of a device group, and the device group includes multiple second devices.

[0528] The second message also carries one or more first message authentication codes for authenticating the core network side device; the first processing unit is used to calculate the second message authentication code based on the at least one shared key; and authenticate the core network side device based on the second message authentication code and the one or more first message authentication codes.

[0529] The second message carries a first message authentication code; the first processing unit 1602 is used to calculate the second message authentication code based on the at least one shared key and at least one of the following parameters: the identification of the first network device, the identification of the one or more second devices, and the identification of the first device.

[0530] The second message carries the one or more first message authentication codes; the first processing unit 1602 is used to calculate the second message authentication code based on the first shared key corresponding to the target second device among the one or more second devices; and authenticate the core network side device based on the target second message authentication code and the target first message authentication code among the one or more first message authentication codes, wherein the target first message authentication code is related to the target second device.

[0531] The first communication unit is configured to send an authentication request to the core network side device, where the authentication request carries the identifiers of the one or more second devices.

[0532] The second message is used to request authentication.

[0533] The first communication unit is configured to receive an authentication request from each of the one or more second devices, where the authentication request from each second device carries an identifier of the second device.

[0534] A first communication unit is configured to send a third message to a target second device among the one or more second devices, the third message being used to instruct the target second device to authenticate the first device; receive a pilot signal sent by the target second device; send the target verification code to the target second device; and receive a fourth message from the target second device, wherein the fourth message is used to indicate a result of the authentication of the first device by the target second device;

[0535] The first processing unit is configured to calculate a target verification code corresponding to the target second device based on the pilot signal sent by the target second device.

[0536] a first processing unit, configured to calculate a target verification code for authenticating the first device based on a third shared key shared with a target second device among the one or more second devices;

[0537] The first communication unit is configured to send a third message to the target second device, wherein the third message carries the target verification code.

[0538] The first processing unit is configured to calculate a target verification code for authenticating the first device based on a third shared key shared with a target second device among the one or more second devices and at least one of the following: a fifth random number, an identifier of the target second device, and an identifier of the first device.

[0539] a first communication unit, configured to receive a fourth message from a target second device among the one or more second devices, wherein the fourth message carries a third response for authenticating the target second device, and the third response is related to a third shared key shared by the target second device and the first device;

[0540] The first processing unit is configured to authenticate the target second device based on the third response and a third expected response.

[0541] The first processing unit is configured to calculate the third expected response based on the third shared key and at least one of the following parameters: a fifth random number, an identifier of the target second device, and an identifier of the first device.

[0542] The first communication unit is used to receive binding information from a fourth network device, wherein the binding information includes the one or more second devices with which the first device has a binding relationship; and / or, the first processing unit 1602 is used to determine the one or more second devices with which the binding relationship is established based on preset binding information, and / or, the first device authenticates the one or more second devices as the one or more second devices with which the binding relationship is established, wherein the authentication includes physical layer authentication and / or air interface authentication.

[0543] The first device includes at least one of the following: a terminal device, a first access network device; the second device is an environment-powered Internet of Things (AIoT) device; the first network device includes one of the following: AUSF, an authentication device, and the authentication device includes one of the following: a second access network device, AMF, SEAF, UPF, a service server, and an AIoT network element.

[0544] FIG19 is a schematic diagram of the structure of a core network side device according to an embodiment of the present application, including:

[0545] The second communication unit 1901 is used to receive a first message from a first device, wherein the first message carries a first response, and the first response is used by the core network side device to perform authentication related to one or more second devices.

[0546] The core network side device also includes: a second processing unit 1902, used to perform authentication related to the one or more second devices based on the first expected response and the first response, wherein the first expected response is calculated based on at least one first shared key, and the at least one shared key includes at least one of the following: one or more first shared keys, a second shared key, different first shared keys among the one or more first shared keys are shared by different second devices and the first device and the core network side device, and the second shared key is shared by the first device and the core network side device.

[0547] The second processing unit is configured to calculate the first expected response based on the at least one shared key.

[0548] The second processing unit is configured to calculate the first expected response based on the identifications of the one or more second devices and the one or more first shared keys; and perform authentication of the one or more second devices based on the first expected response and the first response.

[0549] The second processing unit is used to perform one of the following: using a first calculation method to calculate the first expected response based on the identification of the one or more second devices, the one or more first shared keys, the identification of the first device, and one or more first random numbers; obtaining one or more intermediate keys based on the one or more first shared keys, and using the first calculation method to calculate the first expected response based on the identification of the one or more second devices, the one or more intermediate keys, the identification of the first device, and the one or more first random numbers; calculating one or more second intermediate responses based on the identification of the one or more second devices, the one or more first shared keys, the identification of the first device, and the one or more first random numbers, and calculating the first expected response based on the one or more second intermediate responses.

[0550] The second processing unit is used to perform one of the following: using the first calculation method to calculate the first expected response based on one or more second expected responses, the identification of the one or more second devices, the one or more first shared keys, the identification of the first device, and the one or more first random numbers, wherein the one or more second expected responses are obtained based on the one or more second random numbers; using the first calculation method to calculate the first expected response based on the second shared key, the identification of the one or more second devices, the one or more first shared keys, the identification of the first device, and the one or more first random numbers; calculating the third intermediate key based on the second shared key, the identification of the first network device and the third random number, and using the first calculation method to calculate the first expected response based on the third intermediate key, the identification of the one or more second devices, the one or more first shared keys, the identification of the first device, and the one or more first random numbers.

[0551] a second processing unit, configured to perform one of the following: obtaining one or more first intermediate keys based on the one or more first shared keys, and calculating the first expected response based on one or more second responses, the identifiers of the one or more second devices, the one or more first intermediate keys, the identifier of the first device, and the one or more first random numbers using a first calculation method, wherein the one or more second expected responses are obtained based on the one or more second random numbers; obtaining one or more first intermediate keys based on the one or more first shared keys, and calculating the first expected response based on the second shared key, the identifiers of the one or more second devices, the one or more first intermediate keys, the identifier of the first device, and the one or more first random numbers using the first calculation method; calculating one or more second intermediate keys based on the one or more first shared keys, the identifier of the first network device, and one or more fourth random numbers; calculating the first expected response based on the identifiers of the one or more second devices, the one or more second intermediate keys, the identifier of the first device, and the one or more first random numbers using the first calculation method; obtaining a third intermediate key based on the second shared key, the identifier of the first network device, and a third random number; obtaining one or more first intermediate keys based on the one or more first shared keys, and calculating the first expected response based on the third intermediate key, the identifiers of the one or more second devices, the one or more first intermediate keys, the identifier of the first device, and the one or more first random numbers using the first calculation method.

[0552] The second processing unit is used to perform one of the following: respectively adopting the first calculation method to calculate the one or more second intermediate responses based on the one or more second expected responses, the identification of the one or more second devices, the one or more first shared keys, the identification of the first device, and the one or more first random numbers, wherein the one or more second expected responses are obtained based on the one or more second random numbers; respectively adopting the first calculation method to calculate the one or more second intermediate responses based on the second shared key, the identification of the one or more second devices, the one or more first shared keys, the identification of the first device, and the one or more first random numbers; respectively calculating the third intermediate key based on the second shared key, the identification of the first network device and the third random number, respectively adopting the first calculation method to calculate the one or more second intermediate responses based on the third intermediate key, the identification of the one or more second devices, the one or more first intermediate keys, the identification of the first device, and the one or more first random numbers; respectively obtaining one or more first intermediate keys based on the one or more first shared keys, respectively adopting the first calculation method to calculate the one or more second expected responses, the identification of the one or more second devices, the one or more first intermediate keys, the first random numbers The method comprises the steps of: calculating the one or more second intermediate responses based on the identification of the one or more second devices and the one or more first random numbers; obtaining one or more first intermediate keys based on the one or more first shared keys, and respectively using the first calculation method to calculate the one or more second intermediate responses based on the second shared key, the identification of the one or more second devices, the one or more first intermediate keys, the identification of the first device, and the one or more first random numbers; calculating one or more second intermediate keys based on the one or more first shared keys, the identification of the first network device, and the one or more fourth random numbers; respectively using the first calculation method to calculate the one or more second intermediate responses based on the identification of the one or more second devices, the one or more second intermediate keys, the identification of the first device, and the one or more first random numbers; obtaining a third intermediate key based on the second shared key, the identification of the first network device, and a third random number, and obtaining one or more first intermediate keys based on the one or more first shared keys, and respectively using the first calculation method to calculate the one or more second intermediate responses based on the third intermediate key, the identification of the one or more second devices, the one or more first intermediate keys, the identification of the first device, and the one or more first random numbers.

[0553] The second processing unit is configured to calculate the first expected response by adopting the first calculation method based on the one or more second intermediate responses and at least one of the following: an identifier of the first network device and the third random number.

[0554] The second communication unit is configured to send the one or more first shared keys to the first device.

[0555] A second processing unit is used to calculate the first expected response based on the second shared key and at least one of the following parameters: the identification of the first device, the identification of the one or more second devices, and the identification of the first network device; and based on the first expected response and the first response, perform authentication of the first device as an intermediate node of the one or more second devices.

[0556] The core network side device includes a first network device, and the first communication unit is set in the first network device; the first communication unit is used to receive the first expected response from the second network device.

[0557] The first communication unit is configured to send a second message to the first device, where the second message carries at least one of the following: an identifier of the one or more second devices, and an identifier of a device group, where the device group includes multiple second devices.

[0558] The second message also carries one or more first message authentication codes for authenticating the core network side device; the second processing unit is used to calculate the one or more first message authentication codes based on the at least one shared key.

[0559] The second processing unit is configured to calculate a first message authentication code based on the at least one shared key and at least one of the following parameters: an identifier of the first network device, identifiers of the one or more second devices, and an identifier of the first device.

[0560] The second processing unit is configured to calculate a first message authentication code corresponding to each second device in the one or more second devices based on the one or more first shared keys.

[0561] The second communication unit is configured to receive an authentication request from the first device, where the authentication request carries the identifiers of the one or more second devices.

[0562] The second message is used to request authentication, the core network side device includes a first network device, and the first communication unit is set in the first network device; the first communication unit is used to receive an authentication request from a third network device, and the authentication request carries at least one of the following: the identifier of the one or more second devices, the identifier of the device group, and the device group includes multiple second devices.

[0563] The first device includes at least one of the following: a terminal device, a first access network device; the second device is an environment-powered Internet of Things (AIoT) device; the first network device includes one of the following: AUSF, an authentication device, and the authentication device includes one of the following: a second access network device, AMF, SEAF, UPF, a service server, and an AIoT network element.

[0564] A first device according to an embodiment of the present application includes:

[0565] The first communication unit is used to receive a second message from a core network side device, wherein the second message carries one or more first message authentication codes for authenticating the core network side device.

[0566] A first processing unit is configured to calculate a second message authentication code based on at least one shared key, wherein the at least one shared key includes at least one of the following: one or more first shared keys and a second shared key, different first shared keys among the one or more first shared keys are shared by different second devices with the first device and the core network side device, and the second shared key is shared by the first device and the core network side device; and authenticate the core network side device based on the second message authentication code and the one or more first message authentication codes.

[0567] The core network side device of an embodiment of the present application includes:

[0568] The second communication unit is used to send a second message to the first device, wherein the second message carries one or more first message authentication codes for authenticating the core network side device.

[0569] A second processing unit is used to calculate the one or more first message authentication codes based on at least one shared key, wherein the at least one shared key includes at least one of the following: one or more first shared keys, and a second shared key. Different first shared keys among the one or more first shared keys are shared by different second devices with the first device and the core network side device, and the second shared key is shared by the first device and the core network side device.

[0570] A first device according to an embodiment of the present application includes:

[0571] a first processing unit, configured to calculate a target verification code for authenticating the first device based on a third shared key shared with a target second device;

[0572] The first communication unit is configured to send a third message to the target second device, wherein the third message carries the target verification code.

[0573] The target second device according to an embodiment of the present application, as shown in FIG20 , includes:

[0574] A third communication unit 2001 is configured to receive a third message from a first device, wherein the third message carries a target verification code for authenticating the first device, and the target verification code is related to a third shared key shared by the target second device and the first device;

[0575] The third processing unit 2002 is configured to authenticate the first device based on a target check code and the target verification code.

[0576] The third processing unit is configured to calculate the target verification code based on the third shared key and at least one of the following: a fifth random number, an identifier of the target second device, and an identifier of the first device.

[0577] A first device according to an embodiment of the present application includes:

[0578] a first communication unit, configured to receive a fourth message from a target second device, wherein the fourth message carries a third response for authenticating the target second device, and the third response is related to a third shared key shared by the target second device and the first device;

[0579] The first processing unit is configured to authenticate the target second device based on the third response and a third expected response.

[0580] The target second device according to an embodiment of the present application includes:

[0581] The third communication unit is configured to send a fourth message to the first device, wherein the fourth message carries a third response for authenticating the target second device, and the third response is related to a third shared key shared by the target second device and the first device.

[0582] The third processing unit is configured to calculate the third response based on the third shared key and at least one of the following: a fifth random number, an identifier of the target second device, and an identifier of the first device.

[0583] The device of the embodiment of the present application can realize the corresponding functions of each device in the aforementioned authentication method embodiment. The processes, functions, implementation methods and beneficial effects corresponding to each module (sub-module, unit or component, etc.) in the first device, or the core network side device, or the target second device can be found in the corresponding description in the above method embodiment, which will not be repeated here. It should be noted that the functions described in the first device, or the core network side device, or each module (sub-module, unit or component, etc.) in the embodiment of the application can be implemented by different modules (sub-modules, units or components, etc.), or by the same module (sub-module, unit or component, etc.).

[0584] It should be understood that in the various embodiments of the present application, the size of the sequence number of each process mentioned above does not mean the order of execution, and the execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiment of the present application. Those skilled in the art can clearly understand that, for the convenience and brevity of description, the specific working process of the system, device and unit described above can refer to the corresponding process in the aforementioned method embodiment, and will not be repeated here. The above is only a specific implementation method of the present application, but the scope of protection of the present application is not limited thereto. Any person skilled in the art who is familiar with the technical field can easily think of changes or replacements within the technical scope disclosed in the present application, which should be included in the scope of protection of the present application. Therefore, the scope of protection of the present application should be based on the scope of protection of the claim.

Claims

1. An authentication method, comprising: The first device sends a first message to a core network side device, wherein the first message carries a first response, and the first response is used by the core network side device to perform authentication related to one or more second devices.

2. The method according to claim 1, wherein: The method further comprises: The first device calculates the first response based on at least one shared key, wherein the at least one shared key includes at least one of the following: one or more first shared keys and a second shared key, different first shared keys among the one or more first shared keys are shared by different second devices with the first device and the core network side device, and the second shared key is shared by the first device and the core network side device.

3. The method according to claim 2, wherein: The first device calculates the first response based on at least one shared key, including: The first device calculates the first response based on the identifiers of the one or more second devices and the one or more first shared keys, wherein the first response is used by the core network side device to authenticate the one or more second devices.

4. The method according to claim 3, wherein: The first device calculates the first response based on the identifications of the one or more second devices and the one or more first shared keys, including: The first device calculates the first response based on the identification of the one or more second devices, the one or more first shared keys, the identification of the first device, and one or more first random numbers.

5. The method according to claim 4, wherein: The first device calculates the first response based on the identifications of the one or more second devices and the one or more first shared keys, including one of the following: The first device calculates the first response based on the identifiers of the one or more second devices, the one or more first shared keys, the identifier of the first device, and the one or more first random numbers in a first calculation manner; The first device obtains one or more intermediate keys based on the one or more first shared keys, and calculates the first response based on the identifiers of the one or more second devices, the one or more intermediate keys, the identifier of the first device, and the one or more first random numbers using the first calculation method; The first device calculates one or more first intermediate responses based on the identifications of the one or more second devices, the one or more first shared keys, the identification of the first device, and the one or more first random numbers, and calculates the first response based on the one or more first intermediate responses.

6. The method according to claim 5, wherein: The first device calculates the first response based on the identifiers of the one or more second devices, the one or more first shared keys, the identifier of the first device, and the one or more first random numbers in a first calculation manner, including one of the following: The first device calculates the first response in a first calculation manner based on one or more second responses, the identifiers of the one or more second devices, the one or more first shared keys, the identifier of the first device, and the one or more first random numbers, where the one or more second responses are obtained based on the one or more second random numbers; The first device calculates the first response based on the second shared key, the one or more identifiers of the second devices, the one or more first shared keys, the identifier of the first device, and the one or more first random numbers by using the first calculation method; The first device calculates a third intermediate key based on the second shared key, the identifier of the first network device and a third random number, and calculates the first response based on the third intermediate key, the identifiers of the one or more second devices, the one or more first shared keys, the identifier of the first device, and the one or more first random numbers using the first calculation method.

7. The method according to claim 5, wherein: The first device obtains one or more intermediate keys based on the one or more first shared keys, and calculates the first response based on the identifiers of the one or more second devices, the one or more intermediate keys, the identifier of the first device, and the one or more first random numbers using the first calculation method, including one of the following: The first device obtains one or more first intermediate keys based on the one or more first shared keys, and calculates the first response in a first calculation manner based on one or more second responses, the identification of the one or more second devices, the one or more first intermediate keys, the identification of the first device, and one or more first random numbers, wherein the one or more second responses are obtained based on the one or more second random numbers; The first device obtains one or more first intermediate keys based on the one or more first shared keys, and calculates the first response based on a second shared key, the one or more second device identifiers, the one or more first intermediate keys, the first device identifier, and the one or more first random numbers using the first calculation method, wherein the second shared key is shared by the first device and the core network side device; The first device calculates one or more second intermediate keys based on the one or more first shared keys, the identifier of the first network device and one or more fourth random numbers; and uses the first calculation method to calculate one or more second intermediate keys based on the identifiers of the one or more second devices, the one or more fourth random numbers. one or more second intermediate keys, an identifier of the first device, and the one or more first random numbers, to calculate the first response; The first device obtains a third intermediate key based on the second shared key, the identifier of the first network device, and a third random number, obtains one or more first intermediate keys based on one or more first shared keys, and calculates the first response based on the third intermediate key, the identifier of the one or more second devices, the one or more first intermediate keys, the identifier of the first device, and the one or more first random numbers using a first calculation method.

8. The method according to claim 5, wherein: The first device calculates one or more first intermediate responses based on the identifiers of the one or more second devices, the one or more first shared keys, the identifier of the first device, and the one or more first random numbers, including one of the following: The first device calculates the one or more first intermediate responses based on the one or more second responses, the identifiers of the one or more second devices, the one or more first shared keys, the identifier of the first device, and one or more first random numbers using a first calculation method, respectively, wherein the one or more second responses are obtained based on the one or more second random numbers; The first device calculates the one or more first intermediate responses based on the second shared key, the one or more identifiers of the second devices, the one or more first shared keys, the identifier of the first device, and the one or more first random numbers, respectively, by using the first calculation method; The first device calculates a third intermediate key based on the second shared key, the identifier of the first network device, and the third random number, and respectively calculates the one or more first intermediate responses based on the third intermediate key, the identifiers of the one or more second devices, the one or more first intermediate keys, the identifier of the first device, and the one or more first random numbers using the first calculation method; The first device obtains one or more first intermediate keys based on the one or more first shared keys, and calculates the one or more first intermediate responses based on one or more second responses, the identifiers of the one or more second devices, the one or more first intermediate keys, the identifier of the first device, and the one or more first random numbers using a first calculation method; The first device obtains one or more first intermediate keys based on the one or more first shared keys, and respectively calculates the one or more first intermediate responses based on the second shared key, the one or more identifiers of the second devices, the one or more first intermediate keys, the identifier of the first device, and the one or more first random numbers by using the first calculation method; The first device calculates one or more second intermediate keys based on the one or more first shared keys, the identification of the first network device, and one or more fourth random numbers; respectively calculating the one or more first intermediate responses based on the identifiers of the one or more second devices, the one or more second intermediate keys, the identifier of the first device, and the one or more first random numbers by using the first calculation method; The first device obtains a third intermediate key based on the second shared key, the identifier of the first network device, and a third random number, obtains one or more first intermediate keys based on one or more first shared keys, and calculates the one or more first intermediate responses based on the third intermediate key, the identifiers of the one or more second devices, the one or more first intermediate keys, the identifier of the first device, and the one or more first random numbers, respectively using a first calculation method.

9. The method according to claim 5 or 8, wherein: The calculating the first response based on the one or more first intermediate responses comprises: The first device calculates the first response based on the one or more first intermediate responses and at least one of the following: an identifier of the first network device and a third random number using the first calculation method.

10. The method according to any one of claims 2 to 9, wherein: The method further comprises: The first device receives the one or more first shared keys.

11. The method according to claim 2, wherein: The first device calculates the first response based on at least one shared key, including: The first device calculates the first response based on the second shared key and at least one of the following parameters: the identification of the first device, the identification of the one or more second devices, and the identification of the first network device, wherein the first response is used by the core network side device to authenticate the first device as an intermediate node of the one or more second devices.

12. The method according to any one of claims 2 to 11, wherein: The method further comprises: The first device receives a second message from the core network side device, where the second message carries at least one of the following: an identifier of the one or more second devices, an identifier of a device group, and the device group includes multiple second devices.

13. The method according to claim 12, wherein: The second message also carries one or more first message authentication codes for authenticating the core network side device; the method further includes: The first device calculates a second message authentication code based on the at least one shared key; The first device authenticates the core network side device based on the second message authentication code and the one or more first message authentication codes.

14. The method according to claim 13, wherein: The second message carries a first message authentication code; The first device calculates a second message authentication code based on the at least one shared key, including: The first device calculates the second message authentication code based on the at least one shared key and at least one of the following parameters: an identifier of the first network device, an identifier of the one or more second devices, and an identifier of the first device.

15. The method according to claim 13, wherein: The second message carries the one or more first message authentication codes; The first device calculating the second message authentication code based on the at least one shared key includes: the first device calculating the second message authentication code based on the first shared key corresponding to the target second device among the one or more second devices; The first device authenticates the core network side device based on the one or more second message authentication codes and the one or more first message authentication codes, including: authenticating the core network side device based on the target second message authentication code and a target first message authentication code among the one or more first message authentication codes, wherein the target first message authentication code is related to the target second device.

16. The method according to any one of claims 12 to 15, wherein: Also includes: The first device sends an authentication request to the core network side device, where the authentication request carries the identifiers of the one or more second devices.

17. The method according to any one of claims 12 to 15, wherein: The second message is used to request authentication.

18. The method according to any one of claims 1 to 16, wherein: The method further comprises: The first device receives an authentication request from each of the one or more second devices, where the authentication request of each second device carries an identifier of the second device.

19. The method according to any one of claims 1 to 18, wherein: The method further comprises: The first device sends a third message to a target second device among the one or more second devices, where the third message is used to instruct the target second device to authenticate the first device; The first device receives a pilot signal sent by the target second device; The first device calculates a target verification code corresponding to the target second device based on the pilot signal sent by the target second device; The first device sends the target verification code to the target second device; The first device receives a fourth message from the target second device, wherein the fourth message is used to indicate an authentication result of the target second device on the first device.

20. The method according to any one of claims 1 to 18, wherein: The method further comprises: The first device calculates a target verification code for authenticating the first device based on a third shared key shared with a target second device among the one or more second devices; The first device sends a third message to the target second device, wherein the third message carries the target verification code.

21. The method according to claim 20, wherein: The first device calculates a target verification code for authenticating the first device based on a third shared key shared with a target second device among the one or more second devices, including: The first device calculates a target verification code for authenticating the first device based on a third shared key shared with a target second device among the one or more second devices and at least one of the following: a fifth random number, an identifier of the target second device, and an identifier of the first device.

22. The method according to any one of claims 1 to 21, wherein: The method further comprises: The first device receives a fourth message from a target second device among the one or more second devices, wherein the fourth message carries a third response for authenticating the target second device, and the third response is related to a third shared key shared by the target second device and the first device; The first device authenticates the target second device based on the third response and a third expected response.

23. The method according to claim 22, wherein: The method further comprises: The first device calculates the third expected response based on the third shared key and at least one of the following parameters: a fifth random number, an identifier of the target second device, and an identifier of the first device.

24. The method according to any one of claims 1 to 23, wherein: The method further comprises at least one of the following: The first device receives binding information from a fourth network device, where the binding information includes the one or more second devices with which the first device has a binding relationship; The first device determines the one or more second devices having a binding relationship based on preset binding information; The first device uses the one or more second devices that have passed authentication as the one or more second devices with a binding relationship, and the authentication includes physical layer authentication and / or air interface authentication.

25. The method according to any one of claims 6-9, 11, and 14, wherein: The first device includes at least one of the following: a terminal device, a first access network device; the second device is an environment-powered Internet of Things (AIoT) device; the first network device includes one of the following: AUSF, an authentication device, and the authentication device includes one of the following: a second access network device, AMF, SEAF, UPF, a service server, and an AIoT network element.

26. An authentication method, comprising: A core network side device receives a first message from a first device, wherein the first message carries a first response, and the first response is used by the core network side device to perform authentication related to one or more second devices.

27. The method according to claim 26, wherein: The method further comprises: The core network side device performs authentication related to the one or more second devices based on the first expected response and the first response, wherein the first expected response is calculated based on at least one first shared key, and the at least one shared key includes at least one of the following: one or more first shared keys, and a second shared key, different first shared keys among the one or more first shared keys are shared by different second devices and the first device and the core network side device, and the second shared key is shared by the first device and the core network side device.

28. The method according to claim 27, wherein: The method further comprises: The core network side device calculates the first expected response based on the at least one shared key.

29. The method according to claim 28, wherein: The core network side device calculates the first expected response based on the at least one shared key, including: the core network side device calculates the first expected response based on the identifiers of the one or more second devices and the one or more first shared keys; The core network side device performs authentication related to the one or more second devices based on the first expected response and the first response, including: the core network side device performs authentication on the one or more second devices based on the first expected response and the first response.

30. The method of claim 29, wherein: The core network side device calculates the first expected response based on the identifiers of the one or more second devices and the one or more first shared keys, including one of the following: The core network side device calculates the first expected response based on the identifiers of the one or more second devices, the one or more first shared keys, the identifier of the first device, and one or more first random numbers in a first calculation manner; The core network side device obtains one or more intermediate keys based on the one or more first shared keys, and calculates the first expected response based on the identifiers of the one or more second devices, the one or more intermediate keys, the identifier of the first device, and the one or more first random numbers using the first calculation method; The core network side device calculates one or more second intermediate responses based on the identifiers of the one or more second devices, the one or more first shared keys, the identifier of the first device, and the one or more first random numbers, and calculates the first expected response based on the one or more second intermediate responses.

31. The method according to claim 30, wherein: The core network side device calculates the first expected response based on the identifiers of the one or more second devices, the one or more first shared keys, the identifier of the first device, and the one or more first random numbers in a first calculation manner, including one of the following: The core network side device calculates the first expected response by adopting a first calculation method based on one or more second expected responses, the identifiers of the one or more second devices, the one or more first shared keys, the identifier of the first device, and the one or more first random numbers, where the one or more second expected responses are obtained based on the one or more second random numbers; The core network side device calculates the first expected response based on the second shared key, the identifiers of the one or more second devices, the one or more first shared keys, the identifiers of the first device, and the one or more first random numbers by using the first calculation method; The core network side device calculates a third intermediate key based on the second shared key, the identifier of the first network device and a third random number, and calculates the first expected response based on the third intermediate key, the identifiers of the one or more second devices, the one or more first shared keys, the identifier of the first device, and the one or more first random numbers using the first calculation method.

32. The method of claim 30, wherein: The core network side device obtains one or more intermediate keys based on the one or more first shared keys, and calculates the first expected response based on the identifiers of the one or more second devices, the one or more intermediate keys, the identifier of the first device, and the one or more first random numbers using the first calculation method, including one of the following: The core network side device obtains one or more first intermediate keys based on the one or more first shared keys, and calculates the first expected response based on one or more second responses, the identifiers of the one or more second devices, the one or more first intermediate keys, the identifier of the first device, and the one or more first random numbers using a first calculation method, wherein the one or more second expected responses are obtained based on the one or more second random numbers; The core network side device obtains one or more first intermediate keys based on the one or more first shared keys, and calculates the first expected response based on the second shared key, the identifiers of the one or more second devices, the one or more first intermediate keys, the identifier of the first device, and the one or more first random numbers by using the first calculation method; The core network side device calculates one or more second intermediate keys based on the one or more first shared keys, the identifier of the first network device and one or more fourth random numbers; and adopts the first calculation method to calculate one or more second intermediate keys based on the identifier of the one or more second devices, the The one or more second intermediate keys, the identification of the first device, and the one or more first random numbers are used to calculate the first expected response; The core network side device obtains a third intermediate key based on the second shared key, the identifier of the first network device, and a third random number, obtains one or more first intermediate keys based on one or more first shared keys, and calculates the first expected response based on the third intermediate key, the identifier of the one or more second devices, the one or more first intermediate keys, the identifier of the first device, and the one or more first random numbers using a first calculation method.

33. The method of claim 30, wherein: The core network side device calculates one or more second intermediate responses based on the identifiers of the one or more second devices, the one or more first shared keys, the identifier of the first device, and the one or more first random numbers, including one of the following: The core network side device respectively calculates the one or more second intermediate responses based on the one or more second expected responses, the identifiers of the one or more second devices, the one or more first shared keys, the identifier of the first device, and the one or more first random numbers by using the first calculation method, wherein the one or more second expected responses are obtained based on the one or more second random numbers; The core network side device calculates the one or more second intermediate responses based on the second shared key, the identifiers of the one or more second devices, the one or more first shared keys, the identifiers of the first device, and the one or more first random numbers by using the first calculation method respectively; The core network side device calculates a third intermediate key based on the second shared key, the identifier of the first network device and the third random number, and respectively calculates the one or more second intermediate responses based on the third intermediate key, the identifiers of the one or more second devices, the one or more first intermediate keys, the identifier of the first device, and the one or more first random numbers using the first calculation method; The core network side device obtains one or more first intermediate keys based on the one or more first shared keys, and calculates the one or more second intermediate responses based on one or more second expected responses, the identifiers of the one or more second devices, the one or more first intermediate keys, the identifier of the first device, and the one or more first random numbers by using a first calculation method; The core network side device obtains one or more first intermediate keys based on the one or more first shared keys, and respectively calculates the one or more second intermediate responses based on the second shared key, the identifiers of the one or more second devices, the one or more first intermediate keys, the identifier of the first device, and the one or more first random numbers by using the first calculation method; The core network side device calculates one or more second intermediate keys based on the one or more first shared keys, the identifier of the first network device and one or more fourth random numbers; respectively calculating the one or more second intermediate responses based on the identifiers of the one or more second devices, the one or more second intermediate keys, the identifier of the first device, and the one or more first random numbers by using the first calculation method; The core network side device obtains a third intermediate key based on the second shared key, the identifier of the first network device, and a third random number, obtains one or more first intermediate keys based on one or more first shared keys, and calculates the one or more second intermediate responses based on the third intermediate key, the identifier of the one or more second devices, the one or more first intermediate keys, the identifier of the first device, and the one or more first random numbers, respectively using the first calculation method.

34. The method according to claim 30 or 33, wherein: The calculating the first expected response based on the one or more second intermediate responses comprises: The core network side device calculates the first expected response using the first calculation method based on the one or more second intermediate responses and at least one of the following: an identifier of the first network device and the third random number.

35. The method according to any one of claims 27 to 34, wherein: The method further comprises: The core network side device sends the one or more first shared keys to the first device.

36. The method of claim 28, wherein: The core network side device calculates the first expected response based on the at least one shared key, including: the core network side device calculates the first expected response based on the second shared key and at least one of the following parameters: an identifier of the first device, an identifier of the one or more second devices, and an identifier of the first network device; The core network side device performs authentication related to the one or more second devices based on the first expected response and the first response, including: the core network side device performs authentication of the first device as an intermediate node of the one or more second devices based on the first expected response and the first response.

37. The method of claim 27, wherein: The core network side device includes a first network device; the method further includes: The first network device receives the first expected response from the second network device.

38. The method according to any one of claims 27 to 37, wherein: The method further comprises: The core network side device sends a second message to the first device, where the second message carries at least one of the following: an identifier of the one or more second devices, an identifier of a device group, and the device group includes multiple second devices.

39. The method of claim 38, wherein: The second message also carries one or more first message authentication codes for authenticating the core network side device; the method further includes: The core network side device calculates the one or more first message authentication codes based on the at least one shared key.

40. The method of claim 39, wherein: The core network side device calculates the one or more first message authentication codes based on the at least one shared key, including: The core network side device calculates a first message authentication code based on the at least one shared key and at least one of the following parameters: an identifier of the first network device, an identifier of the one or more second devices, and an identifier of the first device.

41. The method of claim 39, wherein: The core network side device calculates the one or more first message authentication codes based on the at least one shared key, including: The core network side device calculates a first message authentication code corresponding to each second device in the one or more second devices based on the one or more first shared keys.

42. The method according to any one of claims 38 to 41, wherein: Also includes: The core network side device receives an authentication request from the first device, where the authentication request carries the identifiers of the one or more second devices.

43. The method according to any one of claims 38 to 41, wherein: The second message is used to request authentication, and the core network side device includes a first network device; the method further includes: The first network device receives an authentication request from a third network device, where the authentication request carries at least one of the following: an identifier of the one or more second devices, an identifier of a device group, and the device group includes a plurality of second devices.

44. The method according to any one of claims 31-34, 36, 37, 40, 43, wherein: The first device includes at least one of the following: a terminal device, a first access network device; the second device is an environment-powered Internet of Things (AIoT) device; the first network device includes one of the following: AUSF, an authentication device, and the authentication device includes one of the following: a second access network device, AMF, SEAF, UPF, a service server, and an AIoT network element.

45. An authentication method, comprising: The first device receives a second message from a core network side device, wherein the second message carries one or more first message authentication codes for authenticating the core network side device.

46. ​​The method of claim 45, wherein: The method further comprises: The first device calculates a second message authentication code based on at least one shared key, wherein the at least one shared key includes at least one of the following: one or more first shared keys and a second shared key, different first shared keys among the one or more first shared keys are shared by different second devices and the first device and the core network side device, and the second shared key is shared by the first device and the core network side device; The first device authenticates the core network side device based on the second message authentication code and the one or more first message authentication codes.

47. An authentication method, comprising: The core network side device sends a second message to the first device, wherein the second message carries one or more first message authentication codes for authenticating the core network side device.

48. The method of claim 47, wherein: The method further comprises: The core network side device calculates the one or more first message authentication codes based on at least one shared key, wherein the at least one shared key includes at least one of the following: one or more first shared keys and a second shared key, different first shared keys among the one or more first shared keys are shared by different second devices with the first device and the core network side device, and the second shared key is shared by the first device and the core network side device.

49. An authentication method, comprising: The first device calculates a target verification code for authenticating the first device based on a third shared key shared with the target second device; The first device sends a third message to the target second device, wherein the third message carries the target verification code.

50. An authentication method, comprising: The target second device receives a third message from the first device, wherein the third message carries a target verification code for authenticating the first device, and the target verification code is related to a third shared key shared by the target second device and the first device; The target second device authenticates the first device based on the target check code and the target verification code.

51. The method of claim 50, wherein: The method further comprises: The target second device calculates the target verification code based on the third shared key and at least one of the following: a fifth random number, an identifier of the target second device, and an identifier of the first device.

52. An authentication method, comprising: The first device receives a fourth message from a target second device, wherein the fourth message carries a message for authenticating the target second device. a third response from the target second device, the third response being related to a third shared key shared by the target second device and the first device; The first device authenticates the target second device based on the third response and a third expected response.

53. An authentication method, comprising: The target second device sends a fourth message to the first device, wherein the fourth message carries a third response for authenticating the target second device, and the third response is related to a third shared key shared by the target second device and the first device.

54. The method of claim 53, wherein: The method further comprises: The target second device calculates the third response based on the third shared key and at least one of: a fifth random number, an identification of the target second device, and an identification of the first device.

55. A first device, comprising: The first communication unit is used to send a first message to a core network side device, wherein the first message carries a first response, and the first response is used by the core network side device to perform authentication related to one or more second devices.

56. A core network side device, comprising: The second communication unit is used to receive a first message from a first device, wherein the first message carries a first response, and the first response is used by the core network side device to perform authentication related to one or more second devices.

57. A first device, comprising: The first communication unit is used to receive a second message from a core network side device, wherein the second message carries one or more first message authentication codes for authenticating the core network side device.

58. A core network side device, comprising: The second communication unit is used to send a second message to the first device, wherein the second message carries one or more first message authentication codes for authenticating the core network side device.

59. A first device, comprising: A first processing unit, configured to calculate a target verification code for authenticating the first device based on a third shared key shared with a target second device; The first communication unit is configured to send a third message to the target second device, wherein the third message carries the target verification code.

60. A target second device, comprising: a third communication unit, configured to receive a third message from the first device, wherein the third message carries a target verification code for authenticating the first device, and the target verification code is related to a third shared key shared by the target second device and the first device; The third processing unit is configured to authenticate the first device based on a target check code and the target verification code.

61. A first device, comprising: a first communication unit, configured to receive a fourth message from a target second device, wherein the fourth message carries a third response for authenticating the target second device, and the third response is related to a third shared key shared by the target second device and the first device; The first processing unit is configured to authenticate the target second device based on the third response and the third expected response.

62. A target second device, comprising: The third communication unit is used to send a fourth message to the first device, wherein the fourth message carries a third response for authenticating the target second device, and the third response is related to a third shared key shared by the target second device and the first device.

Citation Information

Patent Citations

  • Network authentication method, network device, terminal device and storage medium

    CN110495198A

  • Network authentication method, network device and core network device

    CN110583036A

  • Authentication method and device and equipment

    CN111818516A

  • Communication method and device

    CN111866871A

  • Authentication method, device and system

    CN112087753A