Authentication vector generation method and key management unit, data management system

By deploying a key management unit on the user equipment side, the generation of authentication vectors solves the problem of network resource waste caused by user equipment's autonomous management of key data, and achieves an effective combination of autonomous management and network authentication, thus saving network resources.

CN121150979BActive Publication Date: 2026-08-04CHINA SATENT NETWORK APPLICATION RESEARCH INSTITUTE CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
CHINA SATENT NETWORK APPLICATION RESEARCH INSTITUTE CO LTD
Filing Date
2024-11-11
Publication Date
2026-08-04

AI Technical Summary

Technical Problem

Existing technologies lead to a waste of network resources when user equipment autonomously manages key data.

Method used

A key management unit is deployed on the user equipment side. By receiving authentication requests from the data management system, it queries the authentication data of the user equipment and generates an authentication vector, which is used to authenticate whether to allow connection to the target network.

Benefits of technology

It fulfills the user equipment's need for autonomous management of key data, while saving network resources and avoiding the waste of resources in deploying AUSF or UDM on the user equipment side.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121150979B_ABST
    Figure CN121150979B_ABST
Patent Text Reader

Abstract

The embodiment of the application provides a kind of authentication vector generation method and key management unit, data management system, wherein, the method comprises: receiving the authentication request sent by data management system, wherein, the first identification of user is included in authentication request, and authentication request is the request generated by data management system in the case where the management right of the authentication key of user equipment is determined to belong to user equipment, and data management system is deployed in target network;In response to the authentication request, the authentication data of the user equipment is queried based on the first identification of the user;First authentication vector of user equipment is generated using authentication data, wherein, first authentication vector is used to authenticate whether to allow user equipment to connect to target network. Through the present application, the problem of wasting network resources in the related art when implementing the demand of user equipment for autonomous management of key data is solved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of communication networks, and more specifically, to a method for generating authentication vectors, a key management unit, and a data management system. Background Technology

[0002] With the development of private network services, more and more private network users want to be able to independently control the key information of their user equipment. According to the solutions in related technologies, it is necessary to deploy an authentication server (AUSF) or a data management system (UDM) on the user equipment side and assign the user equipment with number ranges of 10,000 or even 100,000 to meet customer needs.

[0003] Furthermore, since operators need to centrally manage user equipment data such as numbers, UDM stores all the service data and number information of user equipment and is generally not allowed to be deployed on the user equipment side. Even if AUSF or UDM is allowed to be deployed on the customer side, with the existing operator number segment allocation scheme, when the total number of user equipment terminals of the user does not reach several thousand, it will result in a large waste of valuable number resources.

[0004] Therefore, it is evident that the above technical solutions, while fulfilling the user equipment's need for autonomous management of key data, will result in a waste of network resources.

[0005] No effective solutions have yet been proposed in the relevant technologies to address the aforementioned technical problems. Summary of the Invention

[0006] This application provides a method for generating authentication vectors, a key management unit, and a data management system to at least address the problem of wasted network resources when realizing the need for user equipment to autonomously manage key data in related technologies.

[0007] According to one embodiment of this application, a method for generating an authentication vector is provided, applied to a key management unit deployed in a user equipment. The method includes: receiving an authentication request sent by a data management system, wherein the authentication request includes a first user identifier, and the authentication request is generated by the data management system after determining that the management right of the authentication key of the user equipment belongs to the user equipment, the data management system being deployed in a target network; responding to the authentication request by querying the authentication data of the user equipment based on the first user identifier, wherein the authentication data includes the authentication key; and generating a first authentication vector of the user equipment using the authentication data, wherein the first authentication vector is used to authenticate whether the user equipment is allowed to connect to the target network.

[0008] In an exemplary embodiment, responding to the authentication request and querying the authentication data of the user equipment based on the first user identifier includes: parsing the first user identifier from the authentication request; and searching for the authentication data that matches the first user identifier, wherein the authentication data is pre-stored by the user equipment in the key management unit.

[0009] In an exemplary embodiment, generating a first authentication vector for the user equipment using the authentication data includes: obtaining a random number and an authentication token generated by the data management system included in the authentication data, wherein the authentication token is generated by the data management system based on the random number and a first key pre-shared with the user equipment; obtaining a response parameter and a second key included in the authentication data, wherein both the response parameter and the second key are generated by the user equipment using the random number and the authentication key; and determining a first authentication quadruple constructed using the random number, the authentication token, the response parameter, and the second key as the first authentication vector.

[0010] In an exemplary embodiment, after generating the first authentication vector of the user equipment using the authentication data, the method further includes: sending the first authentication vector to the data management system to instruct the data management system to encapsulate the first authentication vector into a first response message and send the first response message to an authentication server, wherein the authentication server is used to send a second response message obtained based on the first response message to a security anchoring service, the security anchoring service is used to send the second response message to the user equipment, and the user equipment is used to perform authentication interaction with the security anchoring service based on the second response message to determine whether the user equipment has passed the authentication of the target network, wherein both the authentication server and the security anchoring service are deployed in the target network.

[0011] In an exemplary embodiment, the value of the authentication management field of the user equipment is a first preset value, which indicates that the management right of the authentication key belongs to the user equipment, and the first preset value is a non-zero value.

[0012] In one exemplary embodiment, the method is applied to a data management system deployed in a target network. The method includes: upon determining that the management rights of the authentication key of a user equipment belong to the user equipment, generating an authentication request and sending the authentication request to a key management unit, wherein the authentication request includes a first user identifier, and the key management unit is deployed in the user equipment; receiving a first authentication vector of the user equipment sent by the key management unit, wherein the first authentication vector is generated by the key management unit in response to the authentication request, based on the first user identifier, and using the authentication data of the user equipment; the first authentication vector is used to authenticate whether the user equipment is allowed to connect to the target network, and the authentication data includes the authentication key.

[0013] In one exemplary embodiment, when it is determined that the management right of the authentication key of the user equipment belongs to the user equipment, generating an authentication request and sending the authentication request to the key management unit includes: receiving a first authentication request sent by an authentication server; parsing the value of the authentication management field included in the first authentication request; determining that the management right of the authentication key of the user equipment belongs to the user equipment when the value of the authentication management field is a first preset value, wherein the first preset value is a non-zero value; generating the authentication request using the user's first identifier; and sending the authentication request to the key management unit.

[0014] In one exemplary embodiment, the first authentication request is generated by the authentication server based on a second authentication request sent by the security anchoring service. The second authentication request includes the first user identifier, the network information of the target network, and the value of the authentication management domain. The second authentication request is generated by the security anchoring service based on a service request sent by the user equipment. The service request includes the second user identifier and the network information. The first user identifier is an identifier obtained by the security anchoring service after converting the second user identifier. Both the authentication server and the security anchoring service are deployed in the target network.

[0015] In an exemplary embodiment, after receiving the first authentication request sent by the authentication server, the method further includes: parsing the value of the authentication management field included in the first authentication request; determining that the management right of the authentication key of the user equipment belongs to the target network when the value of the authentication management field is a second preset value, wherein the second preset value is 0; generating a second authentication vector of the user equipment using the authentication key, wherein the second authentication vector is used to authenticate whether the user equipment is allowed to connect to the target network.

[0016] In an exemplary embodiment, after receiving the first authentication vector of the user equipment sent by the key management unit, the method further includes: encapsulating the first authentication vector into a first response message; and sending the first response message to an authentication server, wherein the authentication server is used to send a second response message converted based on the first response message to a security anchoring service, the security anchoring service is used to send the second response message to the user equipment, and the user equipment is used to perform authentication interaction with the security anchoring service based on the second response message to determine whether the user equipment has passed the authentication of the target network, wherein both the authentication server and the security anchoring service are deployed in the target network.

[0017] According to another embodiment of this application, a key management unit is provided, which is deployed in a user equipment and includes: a first receiving module, configured to receive an authentication request sent by a data management system, wherein the authentication request includes the first user identifier, and the authentication request is generated by the data management system after determining that the management right of the authentication key of the user equipment belongs to the user equipment, and the data management system is deployed in a target network; a first response module, configured to respond to the authentication request and query the authentication data of the user equipment based on the first user identifier, wherein the authentication data includes the authentication key; and a first generation module, configured to generate a first authentication vector of the user equipment using the authentication data, wherein the first authentication vector is used to authenticate whether the user equipment is allowed to connect to the target network.

[0018] According to another embodiment of this application, a data management system is provided, which is deployed in a target network, comprising: a second generation module, configured to generate an authentication request and send the authentication request to a key management unit when it is determined that the management right of the authentication key of a user equipment belongs to the user equipment, wherein the authentication request includes a first user identifier, and the key management unit is deployed in the user equipment; and a second receiving module, configured to receive a first authentication vector of the user equipment sent by the key management unit, wherein the first authentication vector is generated by the key management unit in response to the authentication request, based on the first user identifier, and using the authentication data of the user equipment, and the first authentication vector is used to authenticate whether the user equipment is allowed to connect to the target network, and the authentication data includes the authentication key.

[0019] According to another embodiment of this application, an authentication vector generation system is provided, comprising: the aforementioned key management unit, the aforementioned data management system, a security anchoring service, and an authentication server, wherein the security anchoring service, the aforementioned authentication server, the aforementioned data management system, and the aforementioned key management unit are sequentially connected, wherein the aforementioned security anchoring service, the aforementioned authentication server, and the aforementioned data management system are all deployed in a target network, and the aforementioned key management unit is deployed in a user equipment; the aforementioned security anchoring service is used to receive a service request sent by the aforementioned user equipment and generate a second authentication request based on the aforementioned service request, wherein the aforementioned service request includes the aforementioned second user identifier and the network information of the aforementioned target network; the aforementioned authentication server is used to receive the aforementioned second authentication request sent by the aforementioned security anchoring service and generate a first authentication request based on the aforementioned second authentication request, wherein the aforementioned first authentication request includes a value of an authentication management field and a first user identifier, wherein the aforementioned first user identifier is an identifier obtained by the aforementioned security anchoring service after converting the aforementioned second user identifier.

[0020] According to yet another embodiment of this application, a computer program product is also provided, including a computer program that, when executed by a processor, implements the steps in any of the above method embodiments.

[0021] According to yet another embodiment of this application, a computer-readable storage medium is also provided, wherein a computer program is stored therein, and the computer program is configured to perform the steps in any of the above method embodiments when it is run.

[0022] According to yet another embodiment of this application, an electronic device is also provided, including a memory and a processor, wherein the memory stores a computer program, and the processor is configured to run the computer program to perform the steps in any of the above method embodiments.

[0023] This application addresses the issue of the key management unit (KMU) being deployed on the user equipment (UE) side. Upon receiving an authentication request from the data management system, the KMU queries authentication data from the UE side based on the user's first identifier included in the authentication request. It then generates a first authentication vector for the UE using this data, thereby enabling authentication of whether the UE can connect to the target network. This eliminates the need to deploy AUSF or UDM on the UE side, allowing the UE to autonomously manage authentication keys and perform network authentication. Therefore, it solves the problem of wasted network resources in related technologies when implementing autonomous key data management by the UE, achieving network authentication and resource conservation while effectively fulfilling the UE's need for autonomous key data management. Attached Figure Description

[0024] Figure 1 This is a hardware structure block diagram of a server device for an authentication vector generation method according to an embodiment of this application.

[0025] Figure 2 This is a flowchart of the authentication vector generation method according to an embodiment of this application. Figure 1 ;

[0026] Figure 3 This is a schematic diagram illustrating the connection relationship between the user side and the network side according to an embodiment of this application;

[0027] Figure 4 This is a flowchart of the authentication vector generation method according to an embodiment of this application. Figure 2 ;

[0028] Figure 5 This is a flowchart illustrating the generation of authentication vectors according to a specific embodiment of this application;

[0029] Figure 6 This is a structural block diagram of a key management unit according to an embodiment of this application;

[0030] Figure 7 This is a structural block diagram of a data management system according to an embodiment of this application;

[0031] Figure 8 This is a structural block diagram of an authentication vector generation system according to an embodiment of this application. Detailed Implementation

[0032] The embodiments of this application will be described in detail below with reference to the accompanying drawings and examples.

[0033] It should be noted that the terms "first," "second," etc., in the specification, claims, and drawings of this application are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence.

[0034] The methods and embodiments provided in this application can be executed on a server device or a similar computing device. Taking running on a server device as an example, Figure 1 This is a hardware structure block diagram of a server device for an authentication vector generation method according to an embodiment of this application. For example... Figure 1 As shown, the server device may include one or more ( Figure 1 Only one is shown in the diagram. A processor 102 (which may include, but is not limited to, a microprocessor MCU or a programmable logic device FPGA, etc.) and a memory 104 for storing data are also shown. The server device may further include a transmission device 106 for communication functions and an input / output device 108. Those skilled in the art will understand that... Figure 1 The structure shown is for illustrative purposes only and does not limit the structure of the server equipment described above. For example, the server equipment may also include components that are more... Figure 1 The more or fewer components shown, or having the same Figure 1 The different configurations shown.

[0035] The memory 104 can be used to store computer programs, such as application software programs and modules, like the computer program corresponding to the authentication vector generation method in this embodiment. The processor 102 executes various functional applications and data processing by running the computer program stored in the memory 104, thus implementing the above-described method. The memory 104 may include high-speed random access memory and non-volatile memory, such as one or more magnetic storage devices, flash memory, or other non-volatile solid-state memory. In some instances, the memory 104 may further include memory remotely located relative to the processor 102, and these remote memories can be connected to server devices via a network. Examples of such networks include, but are not limited to, the Internet, corporate intranets, local area networks, mobile communication networks, and combinations thereof.

[0036] The transmission device 106 is used to receive or send data via a network. Specific examples of the network described above may include a wireless network provided by a communication provider for the server device. In one example, the transmission device 106 includes a Network Interface Controller (NIC), which can connect to other network devices via a base station to communicate with the Internet. In another example, the transmission device 106 may be a Radio Frequency (RF) module used for wireless communication with the Internet.

[0037] This embodiment provides a method for generating authentication vectors, applied to a key management unit deployed in a user equipment. Figure 2 This is a flowchart of the authentication vector generation method according to an embodiment of this application. Figure 1 ,like Figure 2 As shown, the process includes the following steps:

[0038] Step S202: Receive an authentication request sent by the data management system. The authentication request includes a first user identifier and is generated by the data management system after determining that the user equipment has the right to manage the authentication key. The data management system is deployed in the target network.

[0039] Step S204: In response to the authentication request, query the authentication data of the user equipment based on the user's first identifier, wherein the authentication data includes the authentication key;

[0040] Step S206: Generate a first authentication vector for the user equipment using the authentication data, wherein the first authentication vector is used to authenticate whether the user equipment is allowed to connect to the target network.

[0041] Optionally, the key management unit in this embodiment is a device or component deployed on the user equipment side that has network authentication function. For example, the key management unit is an authentication management system (AMS).

[0042] Optionally, the data management system in this embodiment is a device or component deployed on the network side, possessing network authentication functionality. For example, the data management system is a UDM (User Device Management System). The target network in this embodiment includes, but is not limited to, the network through which the user equipment will communicate. It can be, but is not limited to, next-generation mobile networks, such as 5G or 6G networks. In the 5G core network, the UDM manages user identity, user subscription data, authentication data, etc., and provides data access interfaces for other network functions, supporting data interaction and integration with external systems. The main functions of the UDM include: User subscription data management: storing and managing user subscription information; User authentication data management: processing user authentication data; User identification data management: managing user identification information; UE access authentication, authorization, and authorization based on subscription data: providing access authentication and authorization services based on user subscription data. The UDM ensures the security and privacy of user data while providing fast authentication and authorization services, ensuring the smooth operation of services.

[0043] Optionally, the user equipment includes, but is not limited to, terminals that require a private network, such as a user equipment (UE). The user's primary identifier is the identifier of the user equipment, including, but not limited to, information that can uniquely identify the user equipment, such as a subscription permanent identifier (SUPI).

[0044] In an exemplary embodiment, in a 5G network, the authentication vector is calculated by the AMS based on the SUPI provided by the UE, the locally stored authentication key, and authentication-related data.

[0045] Optionally, the authentication key is a key used to verify the identity of a user equipment and protect communication security. For example, in a mobile communication network, it is a key used to generate and verify authentication responses. In this embodiment, the authentication key is known only to the user equipment to ensure communication security. Key aspects of the authentication key include, but are not limited to: Authentication: The authentication key is used to verify whether the device is a legitimate user, preventing unauthorized access. Encrypted Communication: During inter-device communication, the authentication key can be used to encrypt and decrypt data, ensuring data confidentiality and integrity. Generation Method: The key can be randomly generated or generated using a secure algorithm. For example, a symmetric key algorithm (e.g., AES) or an asymmetric key algorithm (e.g., RSA) can be used.

[0046] Optionally, authentication-related data includes: SUPI, eK (Encryption Key): Encryption key used to protect the security of user data. OP (Operator Key): Operator key used to generate authentication vectors. OPc (Operator KeyCHAINing): Operator key chain used to maintain the integrity of the key chain during key updates. Kamf (Access and Mobility Management Function Key): AMF key used for secure communication between the AMF and the UE. Kseaf (Security Context for Access Type Full Key): Security context key for full access types. Ksea (Security Context for Access Type Authenticated Encryption): Security context key for authenticated encrypted access types. RAND (Random Number): Random number used to generate authentication challenges. AUTN (Authentication Token): Authentication token used to verify the network's authentication request to the UE. KDF (Key Derivation Function): Key derivation function used to derive other keys from the base key (such as OP). TAI (Tracking Area Identity): Identifies the tracking area where the UE is located. ECGI (E-UTRAN Cell Global Identifier): Identifies the cell the UE is connected to. MAC (Message Authentication Code): Verifies the integrity and origin of a message. These data and keys are used to generate an authentication vector during the authentication process. This vector is sent to the UE to complete the authentication and key negotiation process. This process ensures secure communication and authentication between the UE and the network.

[0047] In one exemplary embodiment, such as Figure 3 The diagram shown is a schematic of the connection between the user side and the network side in this embodiment. The AMS and UDM are connected. The AMS stores the SUPI, which requires the UE to manage the authentication key independently, as well as the Ki and OP or OPC authentication-related information corresponding to the SUPI. After receiving the authentication request, the AMS has the ability to query the locally stored authentication key and authentication-related data based on the SUPI, and to use it to calculate and generate the authentication vector.

[0048] In an exemplary embodiment, in a 5G network, the Access Management System (AMS) stores the User Independent Management Key (SUPI) and the corresponding authentication data (e.g., Ki, OP, or OPC). The AMS is connected to the User Device Management Module (UDM). When the AMS receives an authentication request, it queries the locally stored authentication key and authentication data based on the SUPI in the authentication request. An authentication vector is calculated based on the authentication key and authentication data, including: RAND: a random number used to generate the authentication response; AUTN: an authentication token containing an authentication challenge and sequence number; XRES: an encrypted response, representing the user equipment's response to RAND; and KAUSF: a security key between the user equipment and the core network. It should be noted that the AMS in this embodiment stores and manages the user's sensitive authentication information. Therefore, the AMS needs to have high security and must be able to resist various security threats, such as data leakage, tampering, and unauthorized access. To protect user privacy and data security, the AMS needs to comply with strict data protection policies and regulations, such as the EU's General Data Protection Regulation (GDPR). As the number of 5G users increases, Access Authentication Service (AMS) needs to be highly scalable to handle the ever-increasing data volume and requests. AMS needs to be high-performance to ensure rapid response and low latency in the authentication process. AMS needs to be compatible with different 5G devices and network components to ensure a seamless authentication process. To address evolving cybersecurity threats and technological advancements, AMS needs to be regularly maintained and updated. Through these measures, AMS can ensure the security and effectiveness of the user authentication process in 5G networks.

[0049] In one exemplary embodiment, in a 5G network, the UDM is connected to the AMS, and the UDM needs to be appropriately adapted. That is, for user equipment that needs to independently manage authentication keys, it is only necessary to store the user equipment's SUPI, user service subscription data, and the corresponding authentication management field (AMF) value of the authentication data, and no longer store the authentication key and other authentication-related information.

[0050] Through the above steps, since the key management unit is deployed on the user equipment side, when receiving an authentication request from the data management system, the key management unit queries authentication data from the user equipment side based on the user's first identifier included in the authentication request, and generates a first authentication vector for the user equipment using the authentication data. This first authentication vector can then be used to authenticate whether the user equipment is allowed to connect to the target network. Therefore, it is not necessary to deploy AUSF or UDM on the user equipment side to achieve the goal of user equipment autonomous management of authentication keys and network authentication. Thus, it can solve the problem of network resource waste caused when realizing the need for user equipment autonomous management of key data in related technologies, achieving the effect of network authentication and saving network resources while effectively realizing the need for user equipment autonomous management of key data.

[0051] In one exemplary embodiment, responding to an authentication request and querying authentication data of the user equipment based on a first user identifier includes: parsing the first user identifier from the authentication request; and searching for authentication data that matches the first user identifier, wherein the authentication data is pre-stored in the key management unit by the user equipment.

[0052] Optionally, in the authentication request, the user's first identifier refers to key information used to identify and verify the identity of the user equipment. Depending on the authentication scenario, the user's first identifier may take different forms. For example, when the authentication method is 5G network authentication, the user's first identifier may be the UE's SUPI. The authentication data corresponding to the SUPI is retrieved from the AMS database. Authentication data is typically pre-stored in the AMS, which protects the confidentiality, integrity, and availability of the key. During the authentication data retrieval process, various factors may also need to be considered, such as the user equipment ID, authentication function name, and signature information.

[0053] Optionally, when the authentication method is 5G network authentication, the process of generating an authentication request includes: the UE initiating a service request, carrying the Subscription Concealed Identifier (SUCI) or 5G-GUTI. The Security Anchor Function (SEAF) sends a Nausf_UEAuthentication_authenticate request message to the AUSF, which carries the SUPI and the Serving Network Name. The AUSF sends a Nudm_Authenticate_Get Request message to the UDM. The Nudm_Authenticate_Get Request message carries the AMF value of the user equipment. When the UDM determines from the AMF value that the UE is a UE that needs to independently manage the authentication key, it sets the SUPI value into the Nudm_Authenticate_Get Request message, generating an authentication request.

[0054] In this embodiment, the process by which the key management unit queries the authentication data of the user device using the user's first identifier involves parsing key authentication information from the authentication request and searching for matching pre-stored authentication data in the key management unit. This process ensures the accuracy and security of authentication.

[0055] In an exemplary embodiment, generating a first authentication vector for the user equipment using the authentication data includes: obtaining a random number and an authentication token generated by the data management system included in the authentication data, wherein the authentication token is generated by the data management system based on the random number and a first key pre-shared with the user equipment; obtaining a response parameter and a second key included in the authentication data, wherein both the response parameter and the second key are generated by the user equipment using the random number and the authentication key; and determining a first authentication quadruple constructed using the random number, the authentication token, the response parameter, and the second key as the first authentication vector.

[0056] Optionally, when the target network is a 5G network, the key management unit can generate random numbers through the following steps:

[0057] S1, Generate a random number: The data management system generates a random number, which is the basis for the authentication process. For example, the random number is RAND.

[0058] S2, Generate Authentication Token: Based on the aforementioned random number and the first key pre-shared with the user equipment, the data management system generates an authentication token. This authentication token is used to verify the identity of the user equipment; for example, the authentication token is AUTN.

[0059] S3, Generate Response Parameters and Second Key: The user equipment uses the received random number and authentication key to generate response parameters and a second key. These two elements are generated by the user equipment during the authentication process and are used to interact with the data management system. For example, the response parameter is XRES*, and the second key is KAUSF.

[0060] S4, Construct the authentication quadruple: Combine the random number, authentication token, response parameters, and second key to form an authentication quadruple. This quadruple will serve as the first authentication vector to complete the authentication process. For example, the authentication quadruple generated by AMS is {RAND, XRES*, AUTN, Kausf}. The specific calculation process for constructing the authentication quadruple may also include: First, the network generates RAND and uses RAND and a key pre-shared with the UE (such as OP or OPC) to generate AUTN. Then, the network sends RAND to the UE. After receiving RAND, the UE uses the locally stored eKi and RAND to calculate XRES* using a specific algorithm. Simultaneously, the UE also uses RAND and eKi (and possibly OP or OPC) to calculate KAUSF.

[0061] This embodiment uses random numbers and authentication tokens generated based on these random numbers, ensuring that each authentication process is unique. This increases system security and reduces the risk of replay and prediction attacks. The response parameters generated by the user device and the second key, combined with the random numbers and authentication tokens generated by the data management system, enable two-way authentication, ensuring the identity verification of both the user device and the data management system. Due to the one-time use nature of random numbers, even if an attacker intercepts data during one authentication process, they cannot reuse this data in another, effectively preventing replay attacks. The second key is dynamically generated based on random numbers and the authentication key, increasing key complexity and security, making key management more flexible and secure. The constructed authentication quadruple serves as the first authentication vector, simplifying the authentication process, making it more efficient, and reducing latency. This ensures the security and reliability of the authentication process, prevents unauthorized access, and improves system security and user trust.

[0062] In an exemplary embodiment, after generating a first authentication vector for a user equipment using authentication data, the method further includes: sending the first authentication vector to a data management system to instruct the data management system to encapsulate the first authentication vector into a first response message and send the first response message to an authentication server. The authentication server is used to send a second response message, converted from the first response message, to a security anchoring service. The security anchoring service is used to send the second response message to the user equipment. The user equipment is used to perform authentication interaction with the security anchoring service based on the second response message to determine whether the user equipment has passed the authentication of the target network. Both the authentication server and the security anchoring service are deployed in the target network.

[0063] Optionally, during the authentication process in the 5G network, after generating the first authentication vector, the AMS sends the first authentication vector to the UDM; the UDM encapsulates the first authentication vector into a first response message and sends the first response message to the AUSF; after receiving the first response message from the UDM, the AUSF uses the first authentication vector to authenticate the UE. If authentication is successful, the AUSF returns the authentication result to the SEAF. Based on the authentication result returned by the AUSF, the SEAF decides whether to allow the UE to access the network. If authentication is successful, the SEAF will allow the UE to access the network and allocate corresponding resources and services to the UE. If authentication fails, the SEAF will reject the UE's request and notify the UE of the reason for the authentication failure. Through the collaborative work between the AUSF, UDM, and SEAF, effective authentication of the UE can be achieved, ensuring that only legitimate users can access the network.

[0064] Optionally, the authentication process specifically includes: the UE sending XRES* back to the network side. The network side uses the same algorithm and key (OP or OPC) to calculate the expected XRES and compares it with the XRES* received from the UE. If the two match, the UE is considered to have successfully authenticated.

[0065] This embodiment, through the interaction of multiple steps and network components described above, ensures that only verified user devices can access the target network, significantly improving system security. Furthermore, this multi-layered, multi-component authentication process enables the target network to implement more robust and flexible security measures, protecting network resources from threats.

[0066] In an exemplary embodiment, the value of the authentication management field of the user equipment is a first preset value, which is used to indicate that the management right of the authentication key belongs to the user equipment, and the first preset value is a non-zero value.

[0067] Optionally, the authentication management field includes, but is not limited to, the AMF (Authentication Management Field). The AMF consists of 16 bits, with the highest bit being Bit 0 and the lowest bit being Bit 15. The highest bit, Bit 0, is called the AMF separator and should be set to 1, representing access authentication for both 4G and 5G networks. Bits 1 to 7 are reserved for future standardization and should always be kept at 0 until they have a defined purpose. Bits 8 to 15 can be explicitly used for proprietary purposes; in this embodiment, these 8 bits are used as labels for users of the self-managed key to implement user authentication classification processing. For example, when the UDM receives a Nudm_Authenticate_Get Request, it checks the AMF value of the requesting UE based on the SUPI and determines how to process it based on the values ​​of Bits 8 to 15 of the AMF. For example, if Bits 8 to 15 of the AMF are non-zero, then according to the UDM's configuration policy, a request to obtain the authentication vector carrying the SUPI will be sent to the corresponding AMS deployed on the client side. If bits 8 to 15 of the AMF are 0 (default value), the authentication vector is processed locally by the UDM according to the standard 3GPP system.

[0068] In addition, during the user service activation process, the user's service data and code information should be submitted to the UDM. The service activation system should check bits 8 to 15 of the AMF. If the value is all zeros, the system should submit the authentication data to the UDM. If the value is not all zeros, the system should submit the user's special AMF value to the UDM, and at the same time submit the SUPI and all authentication-related data to the AMS to ensure that the user data and authentication data meet the storage requirements of this embodiment.

[0069] This embodiment provides a method for generating authentication vectors, applied to a data management system deployed in a target network. Figure 4 This is a flowchart of the authentication vector generation method according to an embodiment of this application. Figure 2 ,like Figure 4 As shown, the process includes the following steps:

[0070] Step S402: If it is determined that the management right of the authentication key of the user equipment belongs to the user equipment, an authentication request is generated and sent to the key management unit. The authentication request includes the first user identifier. The key management unit is deployed in the user equipment.

[0071] Step S404: Receive the first authentication vector of the user equipment sent by the key management unit. The first authentication vector is generated by the key management unit in response to the authentication request and by querying the authentication data of the user equipment based on the user's first identifier. The first authentication vector is used to authenticate whether the user equipment is allowed to connect to the target network. The authentication data includes the authentication key.

[0072] Optionally, the key management unit in this embodiment is a device or component deployed on the user equipment side that has network authentication function. For example, the key management unit is an authentication management system (AMS).

[0073] Optionally, the data management system in this embodiment is a device or component deployed on the network side, possessing network authentication functionality. For example, the data management system is a UDM (User Device Management System). The target network in this embodiment includes, but is not limited to, the network through which the user equipment will communicate. It can be, but is not limited to, next-generation mobile networks, such as 5G or 6G networks. In the 5G core network, the UDM manages user identity, user subscription data, authentication data, etc., and provides data access interfaces for other network functions, supporting data interaction and integration with external systems. The main functions of the UDM include: User subscription data management: storing and managing user subscription information; User authentication data management: processing user authentication data; User identification data management: managing user identification information; UE access authentication, authorization, and authorization based on subscription data: providing access authentication and authorization services based on user subscription data. The UDM ensures the security and privacy of user data while providing fast authentication and authorization services, ensuring the smooth operation of services.

[0074] Optionally, the user equipment includes, but is not limited to, terminals that require a private network, such as a user equipment (UE). The user's primary identifier is the identifier of the user equipment, including, but not limited to, information that can uniquely identify the user equipment, such as a subscription permanent identifier (SUPI).

[0075] In an exemplary embodiment, in a 5G network, the authentication vector is calculated by the AMS based on the SUPI provided by the UE, the locally stored authentication key, and authentication-related data.

[0076] Optionally, the authentication key is a key used to verify the identity of a user equipment and protect communication security. For example, in a mobile communication network, it is a key used to generate and verify authentication responses. In this embodiment, the authentication key is known only to the user equipment to ensure communication security. Key aspects of the authentication key include, but are not limited to: Authentication: The authentication key is used to verify whether the device is a legitimate user, preventing unauthorized access. Encrypted Communication: During inter-device communication, the authentication key can be used to encrypt and decrypt data, ensuring data confidentiality and integrity. Generation Method: The key can be randomly generated or generated using a secure algorithm. For example, a symmetric key algorithm (e.g., AES) or an asymmetric key algorithm (e.g., RSA) can be used.

[0077] Optionally, authentication-related data includes: SUPI, eK (Encryption Key): Encryption key used to protect the security of user data. OP (Operator Key): Operator key used to generate authentication vectors. OPc (Operator KeyCHAINing): Operator key chain used to maintain the integrity of the key chain during key updates. Kamf (Access and Mobility Management Function Key): AMF key used for secure communication between the AMF and the UE. Kseaf (Security Context for Access Type Full Key): Security context key for full access types. Ksea (Security Context for Access Type Authenticated Encryption): Security context key for authenticated encrypted access types. RAND (Random Number): Random number used to generate authentication challenges. AUTN (Authentication Token): Authentication token used to verify the network's authentication request to the UE. KDF (Key Derivation Function): Key derivation function used to derive other keys from the base key (such as OP). TAI (Tracking Area Identity): Identifies the tracking area where the UE is located. ECGI (E-UTRAN Cell Global Identifier): Identifies the cell the UE is connected to. MAC (Message Authentication Code): Verifies the integrity and origin of a message. These data and keys are used to generate an authentication vector during the authentication process. This vector is sent to the UE to complete the authentication and key negotiation process. This process ensures secure communication and authentication between the UE and the network.

[0078] In one exemplary embodiment, such as Figure 3 The diagram shown is a schematic of the connection between the user side and the network side in this embodiment. The AMS and UDM are connected. The AMS stores the SUPI, which requires the UE to manage the authentication key independently, as well as the Ki and OP or OPC authentication-related information corresponding to the SUPI. After receiving the authentication request, the AMS has the ability to query the locally stored authentication key and authentication-related data based on the SUPI, and to use it to calculate and generate the authentication vector.

[0079] In an exemplary embodiment, in a 5G network, the Access Management System (AMS) stores the User Independent Management Key (SUPI) and the corresponding authentication data (e.g., Ki, OP, or OPC). The AMS is connected to the User Device Management Module (UDM). When the AMS receives an authentication request, it queries the locally stored authentication key and authentication data based on the SUPI in the request. An authentication vector is generated based on the authentication key and authentication data, including: RAND: a random number used to generate the authentication response; AUTN: an authentication token containing an authentication challenge and sequence number; XRES: an encrypted response, representing the user equipment's response to RAND; and KAUSF: a security key between the user equipment and the core network. It should be noted that the AMS in this embodiment stores and manages the user's sensitive authentication information. Therefore, the AMS needs to have high security and must be able to resist various security threats, such as data leakage, tampering, and unauthorized access. To protect user privacy and data security, the AMS needs to comply with strict data protection policies and regulations, such as the EU's General Data Protection Regulation (GDPR). As the number of 5G users increases, Access Authentication Service (AMS) needs to be highly scalable to handle the ever-increasing data volume and requests. AMS needs to be high-performance to ensure rapid response and low latency in the authentication process. AMS needs to be compatible with different 5G devices and network components to ensure a seamless authentication process. To address evolving cybersecurity threats and technological advancements, AMS needs to be regularly maintained and updated. Through these measures, AMS can ensure the security and effectiveness of the user authentication process in 5G networks.

[0080] In one exemplary embodiment, in a 5G network, the UDM is connected to the AMS, and the UDM needs to be appropriately adapted. That is, for user equipment that needs to independently manage authentication keys, it is only necessary to store the user equipment's SUPI, user service subscription data, and the corresponding authentication management field (AMF) value of the authentication data, and no longer store the authentication key and other authentication-related information.

[0081] Through the above steps, since the key management unit is deployed on the user equipment side, when receiving an authentication request from the data management system, the key management unit queries authentication data from the user equipment side based on the user's first identifier included in the authentication request, and generates a first authentication vector for the user equipment using the authentication data. This first authentication vector can then be used to authenticate whether the user equipment is allowed to connect to the target network. Therefore, it is not necessary to deploy AUSF or UDM on the user equipment side to achieve the goal of user equipment autonomous management of authentication keys and network authentication. Thus, it can solve the problem of network resource waste caused when realizing the need for user equipment autonomous management of key data in related technologies, achieving the effect of network authentication and saving network resources while effectively realizing the need for user equipment autonomous management of key data.

[0082] In one exemplary embodiment, when it is determined that the management right of the authentication key of the user equipment belongs to the user equipment, generating an authentication request and sending the authentication request to the key management unit includes: receiving a first authentication request sent by an authentication server; parsing the value of the authentication management field included in the first authentication request; determining that the management right of the authentication key of the user equipment belongs to the user equipment when the value of the authentication management field is a first preset value, wherein the first preset value is a non-zero value; generating an authentication request using the user's first identifier; and sending the authentication request to the key management unit.

[0083] Optionally, the first authentication request is generated by the authentication server based on the second authentication request sent by the security anchoring service. The second authentication request includes the user's first identifier, the network information of the target network, and the value of the authentication management domain. The second authentication request is generated by the security anchoring service based on the service request sent by the user equipment. The service request includes the user's second identifier and network information. The user's first identifier is the identifier obtained by the security anchoring service after converting the user's second identifier. Both the authentication server and the security anchoring service are deployed in the target network.

[0084] Optionally, the security anchoring service includes, but is not limited to, SEAF, SEAF, AUSF, UDM, AMS, and the connection relationships between UEs, such as... Figure 3As shown. The second user identifier is the identifier of the user equipment, including but not limited to information that can uniquely identify the user equipment. For example, the second user identifier can be a SUCI. For example, when the authentication method is 5G network authentication, the process of generating an authentication request includes: the UE initiates a service request, carrying a SUCI or 5G-GUTI. SEAF converts the SUCI to a SUPI through the communication protocol, sets the SUPI and the name of the 5G network in the Nausf_UEAuthentication_authenticate request message, and sends the Nausf_UEAuthentication_authenticate request message to AUSF. AUSF sends a Nudm_Authenticate_Get Request message (i.e., the first authentication request) to UDM. The Nudm_Authenticate_Get Request message carries the AMF value of the user equipment. When UDM determines from the AMF value that the UE is a UE that needs to independently manage the authentication key, it sets the value of the SUPI in the Nudm_Authenticate_Get Request message and generates an authentication request.

[0085] Optionally, the AMF consists of 16 bits, with the highest bit being Bit 0 and the lowest bit being Bit 15. The highest bit, Bit 0, is called the AMF separator and should be set to 1, representing its use for access authentication in both 4G and 5G networks. Bits 1 to 7 are reserved for future standardization and should always be kept at 0 until they have a defined purpose. Bits 8 to 15 can be explicitly used for proprietary purposes; in this embodiment, these 8 bits are used as tags for users of the self-managed key to implement user authentication classification processing. For example, when the UDM receives a Nudm_Authenticate_Get Request, it checks the AMF value of the requesting UE based on the SUPI and determines how to process it based on the values ​​of Bits 8 to 15 of the AMF. For example, if Bits 8 to 15 of the AMF are non-zero, then according to the UDM's configuration policy, a request to obtain the authentication vector carrying the SUPI will be sent to the corresponding AMS deployed on the client side. If bits 8 to 15 of the AMF are 0 (default value), the authentication vector is processed locally by the UDM according to the standard 3GPP system.

[0086] In addition, during the user service activation process, the user's service data and code information should be submitted to the UDM. The service activation system should check bits 8 to 15 of the AMF. If the value is all zeros, the system should submit the authentication data to the UDM. If the value is not all zeros, the system should submit the user's special AMF value to the UDM, and at the same time submit the SUPI and all authentication-related data to the AMS to ensure that the user data and authentication data meet the storage requirements of this embodiment.

[0087] This embodiment can determine whether a user equipment is an independent user equipment that manages the authentication key by parsing the authentication management domain. This can effectively realize the user equipment's need for autonomous management of key data, thereby achieving network authentication and saving network resources.

[0088] In an exemplary embodiment, after receiving the first authentication request sent by the authentication server, the method further includes: parsing the value of the authentication management field included in the first authentication request; determining that the management right of the authentication key of the user equipment belongs to the target network when the value of the authentication management field is a second preset value, wherein the second preset value is 0; and generating a second authentication vector of the user equipment using the authentication key, wherein the second authentication vector is used to authenticate whether the user equipment is allowed to connect to the target network.

[0089] Optionally, the data management system generates a second authentication vector for the user equipment using the authentication key, which is the same process as the key management unit generating the second authentication vector, and will not be described again here.

[0090] In an exemplary embodiment, after receiving the first authentication vector of the user equipment sent by the key management unit, the method further includes: encapsulating the first authentication vector into a first response message; and sending the first response message to an authentication server, wherein the authentication server is used to send a second response message transformed based on the first response message to a security anchoring service, the security anchoring service is used to send the second response message to the user equipment, and the user equipment is used to perform authentication interaction with the security anchoring service based on the second response message to determine whether the user equipment has passed the authentication of the target network, and both the authentication server and the security anchoring service are deployed in the target network.

[0091] Optionally, during the authentication process in the 5G network, after generating the first authentication vector, the AMS sends the first authentication vector to the UDM; the UDM encapsulates the first authentication vector into a first response message and sends the first response message to the AUSF; after receiving the first response message from the UDM, the AUSF uses the first authentication vector to authenticate the UE. If authentication is successful, the AUSF returns the authentication result to the SEAF. Based on the authentication result returned by the AUSF, the SEAF decides whether to allow the UE to access the network. If authentication is successful, the SEAF will allow the UE to access the network and allocate corresponding resources and services to the UE. If authentication fails, the SEAF will reject the UE's request and notify the UE of the reason for the authentication failure. Through the collaborative work between the AUSF, UDM, and SEAF, effective authentication of the UE can be achieved, ensuring that only legitimate users can access the network.

[0092] Optionally, the authentication process specifically includes: the UE sending XRES* back to the network side. The network side uses the same algorithm and key (OP or OPC) to calculate the expected XRES and compares it with the XRES* received from the UE. If the two match, the UE is considered to have successfully authenticated.

[0093] This embodiment, through the interaction of multiple steps and network components described above, ensures that only verified user devices can access the target network, significantly improving system security. Furthermore, this multi-layered, multi-component authentication process enables the target network to implement more robust and flexible security measures, protecting network resources from threats.

[0094] The present application will be described in detail below with reference to specific embodiments:

[0095] This specific embodiment addresses the scenario where UDM is not deployed on the user equipment side. It introduces an authentication data management system (AMS) deployed on the user equipment side to support autonomous authentication management for user equipment with non-sequential numbers, while reducing the waste of number resources.

[0096] like Figure 3 As shown, AMS and UDM are connected. AMS stores the SUPI that the user needs to manage independently, as well as the Ki and OP or OPC authentication-related information corresponding to the SUPI. After receiving an authentication vector request, it has the ability to query the locally stored key and authentication-related information based on the SUPI, and use it to calculate and generate the authentication vector (RAND, AUTN, XRES*, KAUSF).

[0097] The specific process is as follows: Figure 5 As shown, it includes the following steps:

[0098] S501, the UE initiates a service request, carrying SUCI or 5G-GUTI.

[0099] S502, SEAF sends a Nausf_UEAuthentication_authenticate request message to AUSF, carrying the user identifier (SUPI) and the serving network name.

[0100] S503, AUSF sends a Nudm_UEAuthenticate_Get request message to UDM to request the authentication vector.

[0101] S504, UDM checks the AMF value of the requesting user based on SUPI, finds that the user is a user who needs to manage the authentication key independently, and forwards the authentication vector request to AMS, carrying SUPI in the request.

[0102] S505, AMS calculates and generates an authentication vector (RAND, AUTN, XRES*, KAUSF) based on SUPI and locally stored keys such as eKi, OP or OPC, as well as authentication-related data, and returns it to UDM.

[0103] S506, UDM fills the generated authentication vector (RAND, AUTN, XRES*, and KAUSF) generated by AMS into Nudm_Authenticate_Get Response and returns it to AUSF.

[0104] In S507, AUSF calculates a new quadruple {RAND,HXRES*,AUTN,Kseaf}, deletes Kseaf, and then returns 5G SE AV(RAND,AUTN,HXRES*) to SEAF via the Nausf_UEAuthentication_authenticate response.

[0105] S508, SEAF sends RAND, AUTN to UE.

[0106] S509, the UE calculates RES* and MAC using the same algorithm. It compares its calculation with the one provided by SEAF. If they match, the UE successfully authenticates to the network.

[0107] S510, the UE reports its calculated RES* to the SEAF.

[0108] S511, SEAF uses the same algorithm to calculate HRES* and compares the consistency between HRES* and HXRES*. If they are consistent, the subsequent process continues.

[0109] S512, SEAF reports the RES* provided by UE to AUSF.

[0110] S513, AUSF compares the consistency of RES* and XRES*. If they match, AUSF successfully authenticates the UE and SEAF and returns an authentication success response.

[0111] This specific embodiment uses bits 8 to 15 of the Authentication Management Field (AMF) as user identifiers to differentiate user equipment authentication processes. It interfaces with an external Authentication Management System (AMS) and a User Device Memory (UDM) to provide a method for storing authentication keys and generating authentication vectors for user equipment authentication. 5G network user equipment supports external user equipment with non-sequential numbers, allowing them to independently manage authentication keys. Furthermore, by utilizing the dedicated purpose bits of the AMF in 3GPP standard information for user identification, it is fully compatible with the existing 5G network architecture and will not cause any systemic impact.

[0112] Through the above description of the embodiments, those skilled in the art can clearly understand that the methods according to the above embodiments can be implemented by means of software plus necessary general-purpose hardware platforms. Of course, they can also be implemented by hardware, but in many cases the former is a better implementation method. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk) and includes several instructions to cause a terminal device (which may be a mobile phone, computer, server, or network device, etc.) to execute the methods described in the various embodiments of this application.

[0113] This embodiment also provides a key management unit and a data management system, which are used to implement the above embodiments and preferred embodiments, respectively. Details already described will not be repeated. As used below, the term "module" can refer to a combination of software and / or hardware that performs a predetermined function. Although the apparatus described in the following embodiments is preferably implemented in software, hardware implementation, or a combination of software and hardware, is also possible and contemplated.

[0114] Figure 6 This is a structural block diagram of a key management unit according to an embodiment of this application. The key management unit is deployed in the user equipment, such as... Figure 6 As shown, the device includes:

[0115] The first receiving module 62 is used to receive an authentication request sent by the data management system, wherein the authentication request includes the first user identifier, and the authentication request is generated by the data management system after determining that the management right of the authentication key of the user equipment belongs to the user equipment. The data management system is deployed in the target network.

[0116] The first response module 64 is used to respond to the above authentication request and query the authentication data of the user equipment based on the above user first identifier, wherein the above authentication data includes the above authentication key.

[0117] The first generation module 66 is used to generate a first authentication vector for the user equipment using the authentication data, wherein the first authentication vector is used to authenticate whether the user equipment is allowed to connect to the target network.

[0118] In an exemplary embodiment, the first response module 64 includes: a first parsing unit, configured to parse a user first identifier from the authentication request; and a first lookup unit, configured to look up authentication data that matches the user first identifier, wherein the authentication data is pre-stored by the user equipment in the key management unit.

[0119] In an exemplary embodiment, the first generation module 66 includes: a first acquisition unit, configured to acquire a random number and an authentication token generated by a data management system included in the authentication data, wherein the authentication token is generated by the data management system based on the random number and a first key pre-shared with the user equipment; a second acquisition unit, configured to acquire a response parameter and a second key included in the authentication data, wherein both the response parameter and the second key are generated by the user equipment using the random number and the authentication key; and a first determination unit, configured to determine the first authentication quadruple constructed using the random number, the authentication token, the response parameter, and the second key as the first authentication vector.

[0120] In one exemplary embodiment, the apparatus further includes: a first sending module, configured to generate a first authentication vector for a user equipment using authentication data, and then send the first authentication vector to a data management system to instruct the data management system to encapsulate the first authentication vector into a first response message and send the first response message to an authentication server. The authentication server is configured to send a second response message, converted from the first response message, to a security anchoring service. The security anchoring service is configured to send the second response message to the user equipment. The user equipment is configured to perform authentication interaction with the security anchoring service based on the second response message to determine whether the user equipment has passed the authentication of the target network. Both the authentication server and the security anchoring service are deployed in the target network.

[0121] In an exemplary embodiment, the value of the authentication management field of the user equipment is a first preset value, which is used to indicate that the management right of the authentication key belongs to the user equipment, and the first preset value is a non-zero value.

[0122] Figure 7 This is a structural block diagram of a data management system according to an embodiment of this application. The data management system is deployed in a target network, such as... Figure 7 As shown, the device includes:

[0123] The second generation module 72 is used to generate an authentication request and send the authentication request to the key management unit when it is determined that the management right of the authentication key of the user equipment belongs to the user equipment. The authentication request includes a first user identifier and the key management unit is deployed in the user equipment.

[0124] The second receiving module 74 is used to receive the first authentication vector of the user equipment sent by the key management unit. The first authentication vector is generated by the key management unit in response to the authentication request and by querying the authentication data of the user equipment based on the first identifier of the user. The first authentication vector is used to authenticate whether the user equipment is allowed to connect to the target network. The authentication data includes the authentication key.

[0125] In one exemplary embodiment, the second generation module 72 includes: a first receiving unit for receiving a first authentication request sent by an authentication server; a first parsing unit for parsing the value of the authentication management field included in the first authentication request; a second determining unit for determining that the management right of the authentication key of the user equipment belongs to the user equipment when the value of the authentication management field is a first preset value, wherein the first preset value is a non-zero value; a first generation unit for generating the authentication request using the user's first identifier; and a first sending unit for sending the authentication request to the key management unit.

[0126] In one exemplary embodiment, the first authentication request is generated by the authentication server based on a second authentication request sent by the security anchoring service. The second authentication request includes the first user identifier, the network information of the target network, and the value of the authentication management domain. The second authentication request is generated by the security anchoring service based on a service request sent by the user equipment. The service request includes the second user identifier and the network information. The first user identifier is an identifier obtained by the security anchoring service after converting the second user identifier. Both the authentication server and the security anchoring service are deployed in the target network.

[0127] In one exemplary embodiment, the apparatus further includes: a first parsing module, configured to parse the value of the authentication management field included in the first authentication request after receiving the first authentication request sent by the authentication server; a first determining module, configured to determine that the management right of the authentication key of the user equipment belongs to the target network when the value of the authentication management field is a second preset value, wherein the second preset value is 0; and a third generating module, configured to generate a second authentication vector of the user equipment using the authentication key, wherein the second authentication vector is used to authenticate whether the user equipment is allowed to connect to the target network.

[0128] In one exemplary embodiment, the apparatus further includes: a first encapsulation module, configured to encapsulate the first authentication vector of the user equipment sent by the key management unit into a first response message; and a second sending module, configured to send the first response message to an authentication server, wherein the authentication server is configured to send a second response message converted based on the first response message to a security anchoring service, the security anchoring service is configured to send the second response message to the user equipment, and the user equipment is configured to perform authentication interaction with the security anchoring service based on the second response message to determine whether the user equipment has passed the authentication of the target network, wherein both the authentication server and the security anchoring service are deployed in the target network.

[0129] Figure 8 This is a structural block diagram of an authentication vector generation system according to an embodiment of this application. The data management system is deployed in the target network, such as... Figure 8 As shown, the device includes: a key management unit 82, a data management system 84, a security anchoring service 86, and an authentication server 88. The security anchoring service, the authentication server, the data management system, and the key management unit are connected sequentially. The security anchoring service, the authentication server, and the data management system are all deployed in the target network, while the key management unit is deployed in the user equipment. The security anchoring service receives service requests sent by the user equipment and generates a second authentication request based on the service requests. The service requests include the second user identifier and network information of the target network. The authentication server receives the second authentication request sent by the security anchoring service and generates a first authentication request based on the second authentication request. The first authentication request includes the value of an authentication management field and a first user identifier, which is an identifier obtained by the security anchoring service after converting the second user identifier.

[0130] It should be noted that the above modules can be implemented by software or hardware. For the latter, they can be implemented in the following ways, but are not limited to: all the above modules are located in the same processor; or, the above modules are located in different processors in any combination.

[0131] Embodiments of this application also provide a computer-readable storage medium storing a computer program, wherein the computer program is configured to perform the steps in any of the above method embodiments when it is run.

[0132] In one exemplary embodiment, the aforementioned computer-readable storage medium may include, but is not limited to, various media capable of storing computer programs, such as a USB flash drive, read-only memory (ROM), random access memory (RAM), portable hard disk, magnetic disk, or optical disk.

[0133] Embodiments of this application also provide an electronic device, including a memory and a processor, wherein the memory stores a computer program and the processor is configured to run the computer program to perform the steps in any of the above method embodiments.

[0134] In one exemplary embodiment, the electronic device may further include a transmission device and an input / output device, wherein the transmission device is connected to the processor and the input / output device is connected to the processor.

[0135] Embodiments of this application also provide a computer program product, which includes a computer program that, when executed by a processor, implements the steps in any of the above method embodiments.

[0136] Embodiments of this application also provide another computer program product, including a non-volatile computer-readable storage medium storing a computer program that, when executed by a processor, implements the steps in any of the above method embodiments.

[0137] The embodiments described herein also provide a computer program that includes computer instructions stored in a computer-readable storage medium; a processor of a computer device reads the computer instructions from the computer-readable storage medium and executes the computer instructions, causing the computer device to perform the steps in any of the above method embodiments.

[0138] Specific examples in this embodiment can be found in the examples described in the above embodiments and exemplary implementations, and will not be repeated here.

[0139] Obviously, those skilled in the art should understand that the modules or steps of this application described above can be implemented using general-purpose computing devices. They can be centralized on a single computing device or distributed across a network of multiple computing devices. They can be implemented using computer-executable program code, and thus can be stored in a storage device for execution by a computing device. In some cases, the steps shown or described can be performed in a different order than those presented here, or they can be fabricated as separate integrated circuit modules, or multiple modules or steps can be fabricated as a single integrated circuit module. Thus, this application is not limited to any particular combination of hardware and software.

[0140] The above description is merely a preferred embodiment of this application and is not intended to limit this application. Various modifications and variations can be made to this application by those skilled in the art. Any modifications, equivalent substitutions, improvements, etc., made within the principles of this application should be included within the protection scope of this application.

Claims

1. A method for generating an authentication vector, characterized in that, The method, applied to a key management unit deployed in a user equipment, includes: The system receives an authentication request sent by a data management system, wherein the authentication request includes a first user identifier, and the authentication request is generated by the data management system after determining that the user equipment has the right to manage the authentication key of the user equipment. The data management system is deployed in the target network. In response to the authentication request, the authentication data of the user equipment is queried based on the user's first identifier, wherein the authentication data includes the authentication key; The authentication data is used to generate a first authentication vector for the user equipment, wherein the first authentication vector is used to authenticate whether the user equipment is allowed to connect to the target network.

2. The method according to claim 1, characterized in that, In response to the authentication request, querying the authentication data of the user equipment based on the user's first identifier includes: Parse the user's first identifier from the authentication request; The authentication data that matches the user's first identifier is searched, wherein the authentication data is pre-stored by the user equipment in the key management unit.

3. The method according to claim 1, characterized in that, Generating the first authentication vector of the user equipment using the authentication data includes: The authentication data includes a random number and an authentication token generated by the data management system, wherein the authentication token is generated by the data management system based on the random number and a first key shared with the user equipment in advance. Obtain the response parameters and the second key included in the authentication data, wherein the response parameters and the second key are both generated by the user equipment using the random number and the authentication key; The first authentication quadruple constructed using the random number, the authentication token, the response parameter, and the second key is determined as the first authentication vector.

4. The method according to claim 1, characterized in that, After generating the first authentication vector of the user equipment using the authentication data, the method further includes: The first authentication vector is sent to the data management system to instruct the data management system to encapsulate the first authentication vector into a first response message and send the first response message to the authentication server. The authentication server is used to send a second response message, which is converted based on the first response message, to the security anchoring service. The security anchoring service is used to send the second response message to the user equipment. The user equipment is used to perform authentication interaction with the security anchoring service based on the second response message to determine whether the user equipment has passed the authentication of the target network. Both the authentication server and the security anchoring service are deployed in the target network.

5. The method according to claim 1, characterized in that, The value of the authentication management field of the user equipment is a first preset value, which indicates that the management right of the authentication key belongs to the user equipment, and the first preset value is a non-zero value.

6. A method for generating an authentication vector, characterized in that, Applied to a data management system deployed on a target network, the method includes: If it is determined that the user equipment has the right to manage the authentication key, an authentication request is generated and sent to the key management unit. The authentication request includes a first user identifier. The key management unit is deployed in the user equipment. The key management unit receives a first authentication vector from the user equipment, wherein the first authentication vector is generated by the key management unit in response to the authentication request, based on the authentication data of the user equipment queried according to the user's first identifier, using the authentication data. The first authentication vector is used to authenticate whether the user equipment is allowed to connect to the target network, and the authentication data includes the authentication key.

7. The method according to claim 6, characterized in that, If it is determined that the user equipment has the right to manage the authentication key, an authentication request is generated and sent to the key management unit, including: Receive the first authentication request sent by the authentication server; Parse the value of the authentication management field included in the first authentication request; When the value of the authentication management field is a first preset value, it is determined that the management right of the authentication key of the user equipment belongs to the user equipment, wherein the first preset value is a non-zero value; The authentication request is generated using the user's first identifier; The authentication request is sent to the key management unit.

8. The method according to claim 7, characterized in that, The first authentication request is generated by the authentication server based on the second authentication request sent by the security anchoring service. The second authentication request includes the user's first identifier, the network information of the target network, and the value of the authentication management domain. The second authentication request is generated by the security anchoring service based on the service request sent by the user equipment. The service request includes the user's second identifier and the network information. The user's first identifier is an identifier obtained by the security anchoring service after converting the user's second identifier. Both the authentication server and the security anchoring service are deployed in the target network.

9. The method according to claim 7, characterized in that, After receiving the first authentication request sent by the authentication server, the method further includes: Parse the value of the authentication management field included in the first authentication request; If the value of the authentication management domain is a second preset value, it is determined that the management right of the authentication key of the user equipment belongs to the target network, wherein the second preset value is 0; The authentication key is used to generate a second authentication vector for the user equipment, wherein the second authentication vector is used to authenticate whether the user equipment is allowed to connect to the target network.

10. The method according to claim 6, characterized in that, After receiving the first authentication vector of the user equipment sent by the key management unit, the method further includes: The first authentication vector is encapsulated into the first response message; The first response message is sent to the authentication server, wherein the authentication server is used to send a second response message transformed based on the first response message to the security anchoring service, the security anchoring service is used to send the second response message to the user equipment, and the user equipment is used to perform authentication interaction with the security anchoring service based on the second response message to determine whether the user equipment has passed the authentication of the target network, wherein both the authentication server and the security anchoring service are deployed in the target network.

11. A key management unit, characterized in that, The key management unit is deployed in the user equipment and includes: The first receiving module is used to receive an authentication request sent by the data management system. The authentication request includes a first user identifier and is generated by the data management system after determining that the user equipment has the right to manage the authentication key of the user equipment. The data management system is deployed in the target network. The first response module is used to respond to the authentication request and query the authentication data of the user equipment based on the user's first identifier, wherein the authentication data includes the authentication key; A first generation module is used to generate a first authentication vector for the user equipment using the authentication data, wherein the first authentication vector is used to authenticate whether the user equipment is allowed to connect to the target network.

12. A data management system, characterized in that, The data management system is deployed on the target network and includes: The second generation module is used to generate an authentication request and send the authentication request to the key management unit when it is determined that the management right of the authentication key of the user equipment belongs to the user equipment. The authentication request includes a first user identifier, and the key management unit is deployed in the user equipment. The second receiving module is configured to receive the first authentication vector of the user equipment sent by the key management unit, wherein the first authentication vector is generated by the key management unit in response to the authentication request and by querying the authentication data of the user equipment based on the user's first identifier, using the authentication data. The first authentication vector is used to authenticate whether the user equipment is allowed to connect to the target network, and the authentication data includes the authentication key.

13. A system for generating authentication vectors, characterized in that, include: The key management unit of claim 11, the data management system of claim 12, the security anchoring service, and the authentication server, wherein the security anchoring service, the authentication server, the data management system, and the key management unit are sequentially connected, wherein... The security anchoring service, the authentication server, and the data management system are all deployed in the target network, while the key management unit is deployed in the user equipment. The security anchoring service is used to receive a service request sent by the user equipment and generate a second authentication request based on the service request, wherein the service request includes a second user identifier and network information of the target network; The authentication server is configured to receive the second authentication request sent by the security anchoring service and generate a first authentication request based on the second authentication request. The first authentication request includes a value of the authentication management field and a first user identifier, wherein the first user identifier is an identifier obtained by the security anchoring service after converting the second user identifier.

14. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by a processor, it implements the steps of the method described in any one of claims 1 to 5, or the steps of the method described in any one of claims 6 to 10.

15. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program, wherein when the computer program is executed by a processor, it implements the steps of the method described in any one of claims 1 to 5, or implements the steps of the method described in any one of claims 6 to 10.

16. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, When the processor executes the computer program, it implements the steps of the method described in any one of claims 1 to 5, or the steps of the method described in any one of claims 6 to 10.