Access authentication method, device and equipment for heterogeneous convergence network

By using modular design on the access network side to decouple the access and authentication processes and intelligently select access and authentication schemes, the complexity and resource waste of access authentication in 6G heterogeneous converged networks are solved, achieving efficient and secure access and authentication.

CN121151884APending Publication Date: 2025-12-16CHINA MOBILE COMM LTD RES INST +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510628067.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-15
Publication Date
2025-12-16

AI Technical Summary

Technical Problem

The existing 5G AKA or EAP AKA access authentication process cannot meet the complex and ever-changing security access authentication requirements in 6G heterogeneous converged networks, and there is a problem of redundant authentication causing resource waste.

Method used

By deploying an access authentication management module, an access function module, and an authentication function module on the access network side, the access process and authentication process of the terminal device are decoupled, the access and authentication processes are executed separately, and the appropriate access and authentication schemes are intelligently selected for the terminal device.

Benefits of technology

It meets the complex and ever-changing security access authentication needs of terminal devices, reduces resource waste caused by redundant authentication, and improves authentication efficiency and access success rate.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121151884A_ABST
    Figure CN121151884A_ABST
Patent Text Reader

Abstract

The invention discloses an access authentication method, device and equipment oriented to a heterogeneous convergence network, an access authentication management module, an access function module and an authentication function module are deployed on an access network side of the heterogeneous convergence network, the access authentication management module receives a request sent by terminal equipment, and when the request is an access request, the authentication function module sends the request to the terminal equipment; selecting an access scheme for the terminal equipment when the request is a connection request or a service request, and selecting an authentication scheme for the terminal equipment when the request is a connection request or a service request and the terminal equipment needs to be authenticated; the access function module completes the access process of the terminal equipment according to the selected access scheme; and the authentication function module completes the authentication process of the terminal equipment according to the selected authentication scheme. According to the method, the access process and the authentication process are decoupled, and the adaptive access scheme and the adaptive authentication scheme are intelligently selected for the terminal equipment, so that the complex and variable security access authentication requirements of the terminal equipment can be met, and the resource waste caused by redundant authentication is effectively reduced.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of communication technology, and in particular to an access authentication method, apparatus, computer-readable storage medium, computer program product, and terminal equipment for heterogeneous converged networks. Background Technology

[0002] In 5G (5th Generation Mobile Communication Technology) networks, 5G AKA (5G Authentication and Key Agreement) or EAP AKA (Extensible Authentication Protocol-Authentication and Key Agreement Prime) are typically used as the terminal access authentication scheme. All terminals accessing the 5G network must follow the AKA access authentication process defined by 3GPP (3rd Generation Partnership Project).

[0003] However, in the future 6G era, there will be scenarios where heterogeneous terminals access the network across different converged networks such as satellite networks, mobile networks, the Internet, and the Internet of Things. The current 5G AKA or EAP AKA access authentication process in 5G networks will not be able to meet the complex and ever-changing security access authentication requirements of 6G, and there is also the problem of resource waste caused by redundant authentication. Summary of the Invention

[0004] The purpose of this invention is to provide an access authentication method, apparatus, computer-readable storage medium, computer program product, and terminal device for heterogeneous converged networks. Through a modular structure design on the access network side, the access process and authentication process of the terminal device can be decoupled, and the access process and authentication process can be executed separately. The appropriate access scheme and authentication scheme can be intelligently selected for the terminal device, thereby meeting the complex and ever-changing security access authentication needs of the terminal device. At the same time, the authentication process is only executed when the terminal device needs to be authenticated, thereby effectively reducing the resource waste caused by redundant authentication.

[0005] To achieve the above objectives, embodiments of the present invention provide an access authentication method for heterogeneous converged networks, applied to the access network side of the heterogeneous converged network. The access network side is equipped with an access authentication management module, an access function module, and an authentication function module. The method includes:

[0006] The access authentication management module receives requests sent by terminal devices, selects an access scheme for the terminal device when the request is an access request, and selects an authentication scheme for the terminal device when the request is a connection request or a service request and authentication of the terminal device is required.

[0007] The access function module completes the access process of the terminal device according to the access scheme selected by the access authentication management module.

[0008] The authentication function module completes the authentication process of the terminal device according to the authentication scheme selected by the access authentication management module.

[0009] Furthermore, the access request carries device information of the terminal device, including device type and identity identifier; before selecting an access scheme for the terminal device, it also includes:

[0010] The trust assessment status of the terminal device is obtained from the core network side based on the device information.

[0011] The trust assessment is performed on the terminal device based on the trust assessment status to determine whether to allow the access operation to be performed on the terminal device.

[0012] If the trust assessment result is satisfactory, it is determined that access operation is permitted for the terminal device; wherein, the access operation refers to selecting an access scheme for the terminal device;

[0013] If the trust assessment result is unqualified, it is determined to perform an access denial operation or an access restriction operation on the terminal device; wherein, the access restriction operation means allowing the terminal device to perform an access operation, but marking the terminal device and restricting the access permissions of the terminal device after access.

[0014] Furthermore, the access request also carries access point information; the step of selecting an access scheme for the terminal device specifically includes:

[0015] Based on the access point information, determine whether the current network status of the access point meets the access requirements of the terminal device;

[0016] If satisfied, an access method is selected for the terminal device based on the device information, and the access request and the selected access method are sent to the access function module of the access point.

[0017] The process of completing the access process of the terminal device through the access function module according to the access scheme selected by the access authentication management module specifically includes:

[0018] The access function module of the access point completes the access process of the terminal device according to the access request and the selected access method.

[0019] Furthermore, selecting an access scheme for the terminal device further includes:

[0020] If the requirements are not met, a new access point that meets the access requirements will be selected for the terminal device, and the new access point information will be sent to the terminal device.

[0021] Receive a new access request sent by the terminal device based on the new access point information, reselect an access method for the terminal device according to the device information carried in the new access request, and send the new access request and the newly selected access method to the access function module of the new access point;

[0022] The process of completing the access process of the terminal device through the access function module according to the access scheme selected by the access authentication management module specifically includes:

[0023] The access function module of the new access point completes the access process of the terminal device according to the new access request and the newly selected access method.

[0024] Furthermore, after the access function module completes the access process of the terminal device according to the access scheme selected by the access authentication management module, the process further includes:

[0025] The access function module sends the access status indication information to the access authentication management module.

[0026] The access authentication management module sends access request response information back to the terminal device based on the access status indication information.

[0027] Furthermore, the connection request or service request carries device information of the terminal device, including device type and identity identifier; before selecting an authentication scheme for the terminal device, the following is also included:

[0028] Determine whether authentication is required for the terminal device based on the device information;

[0029] If not required, the connection request or service request will be sent to the core network side for processing.

[0030] If necessary, an authentication operation is performed on the terminal device; wherein, the authentication operation refers to selecting an authentication scheme for the terminal device.

[0031] Furthermore, the connection request or service request also carries service information, including the service type and the service's QoS requirements for the network; the step of selecting an authentication scheme for the terminal device specifically includes:

[0032] Based on the device information, the service information, and the trust assessment result of the terminal device, an authentication method is selected for the terminal device, and the authentication request and the selected authentication method are sent to the authentication function module.

[0033] The authentication process of the terminal device, which is completed by the authentication function module according to the authentication scheme selected by the access authentication management module, specifically includes:

[0034] The authentication function module completes the authentication process of the terminal device based on the authentication request and the selected authentication method.

[0035] Furthermore, after the authentication process of the terminal device is completed by the authentication function module according to the authentication scheme selected by the access authentication management module, the process further includes:

[0036] The authentication result information is sent to the access authentication management module through the authentication function module.

[0037] The authentication result information is fed back to the terminal device through the access authentication management module.

[0038] To achieve the above objectives, embodiments of the present invention also provide an access authentication device for heterogeneous converged networks, deployed on the access network side of the heterogeneous converged network, the device comprising:

[0039] The access authentication management module is used to receive requests sent by terminal devices, and when the request is an access request, select an access scheme for the terminal device; when the request is a connection request or a service request and authentication of the terminal device is required, select an authentication scheme for the terminal device.

[0040] The access function module is used to complete the access process of the terminal device according to the access scheme selected by the access authentication management module.

[0041] The authentication function module is used to complete the authentication process of the terminal device according to the authentication scheme selected by the access authentication management module.

[0042] This invention also provides a computer-readable storage medium, including a stored computer program, which, when running, controls the device where the computer-readable storage medium is located to execute the access authentication method for heterogeneous converged networks described above.

[0043] This invention also provides a computer program product, including a computer program that, when executed by a processor, implements the access authentication method for heterogeneous converged networks as described above.

[0044] This invention also provides a terminal device, including a processor, a memory, and a computer program stored in the memory and configured to be executed by the processor. When the processor executes the computer program, it implements the access authentication method for heterogeneous converged networks described above.

[0045] Compared with existing technologies, this invention provides an access authentication method, apparatus, computer-readable storage medium, computer program product, and terminal device for heterogeneous converged networks. Applied to the access network side of a heterogeneous converged network, the access network side deploys an access authentication management module, an access function module, and an authentication function module. The access authentication management module receives requests from terminal devices and selects an access scheme for the terminal device when the request is an access request; when the request is a connection request or a service request requiring authentication, it selects an authentication scheme for the terminal device. The access function module completes the access process of the terminal device based on the access scheme selected by the access authentication management module. The authentication function module completes the authentication process of the terminal device based on the authentication scheme selected by the access authentication management module. This invention, through a modular structure design on the access network side, decouples the access and authentication processes of the terminal device, executing them separately and intelligently selecting appropriate access and authentication schemes for the terminal device. This meets the complex and ever-changing security access authentication needs of terminal devices. Furthermore, by executing the authentication process only when authentication is required, it effectively reduces resource waste caused by redundant authentication. Attached Figure Description

[0046] Figure 1 This is a flowchart of an access authentication method for heterogeneous converged networks provided in an embodiment of the present invention;

[0047] Figure 2 This is a network architecture diagram of an access authentication method for heterogeneous converged networks provided by an embodiment of the present invention;

[0048] Figure 3 This is an access flowchart of an access authentication method for heterogeneous converged networks provided by an embodiment of the present invention;

[0049] Figure 4 This is an authentication flowchart of an access authentication method for heterogeneous converged networks provided by an embodiment of the present invention;

[0050] Figure 5This is a structural block diagram of an access authentication device for heterogeneous converged networks provided in an embodiment of the present invention;

[0051] Figure 6 This is a structural block diagram of a terminal device provided in an embodiment of the present invention. Detailed Implementation

[0052] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0053] This invention provides an access authentication method for heterogeneous converged networks. The method is applied to the access network side of the heterogeneous converged network, which is equipped with an access authentication management module, an access function module, and an authentication function module. (See also...) Figure 1 The diagram shows a flowchart of an access authentication method for heterogeneous converged networks according to an embodiment of the present invention. The method includes steps S11 to S13:

[0054] Step S11: Receive a request sent by the terminal device through the access authentication management module, and select an access scheme for the terminal device if the request is an access request, and select an authentication scheme for the terminal device if the request is a connection request or a service request and authentication of the terminal device is required.

[0055] Step S12: The access function module completes the access process of the terminal device according to the access scheme selected by the access authentication management module;

[0056] Step S13: The authentication process of the terminal device is completed by the authentication function module according to the authentication scheme selected by the access authentication management module.

[0057] It should be noted that, based on new security access requirements, this embodiment of the invention provides an access authentication mechanism for heterogeneous converged networks (e.g., 6G heterogeneous converged networks). This mechanism mainly consists of three functional modules deployed on the access network side of the heterogeneous converged network and two functional modules deployed on the core network side of the heterogeneous converged network. See [link to relevant documentation]. Figure 2 The diagram shown is a network architecture diagram of an access authentication method for heterogeneous converged networks according to an embodiment of the present invention. The access network side deploys an access authentication management module, an access function module, and an authentication function module, while the core network side deploys an identity management module and an authentication management module; wherein:

[0058] The access authentication management module is used to uniformly manage the access and authentication requests of all terminal devices. During the access process of a terminal device, it selects an access scheme to choose the most suitable access scheme for the terminal device and notifies the access function module to execute the access process for the terminal device. During the authentication process of a terminal device, it first determines whether the terminal device needs to be authenticated. If authentication is required, it selects an authentication scheme to choose the most suitable authentication scheme for the terminal device and notifies the authentication function module to execute the authentication process for the terminal device.

[0059] The access function module is used to execute the corresponding access process according to the access scheme selected by the access authentication management module (in cooperation with the identity management module on the core network side to complete the access process of the terminal device).

[0060] The authentication function module is used to execute the corresponding authentication process according to the authentication scheme selected by the access authentication management module (in cooperation with the authentication management module on the core network side to complete the authentication process of the terminal device).

[0061] The identity management module is used to store and manage the identity information of terminal devices in cross-domain networks on the core network side. During the access and authentication process of terminal devices, this module is accessed to obtain or verify relevant information of the terminal devices.

[0062] The authentication management module is used to execute the access and authentication process of terminal devices on the core network side and generate corresponding credentials. For example, the authentication management module is used on the core network side to verify the identity of terminal devices.

[0063] Combination Figure 2 As shown, in a specific implementation of this embodiment of the invention, the terminal device initiates a request to the access network side of the heterogeneous converged network; the access authentication management module on the access network side receives the request sent by the terminal device; further, if the access authentication management module determines that the received request is an access request, it selects an appropriate access scheme for the terminal device according to the received access request, and notifies the access function module to execute the access process for the terminal device; if the access authentication management module determines that the received request is a connection request or a service request, it first determines whether the terminal device needs to be authenticated. If authentication is required, it then selects an appropriate authentication scheme for the terminal device according to the received connection request or service request, and notifies the authentication function module to execute the authentication process for the terminal device; correspondingly, the access function module completes the access process of the terminal device according to the access scheme selected by the access authentication management module; the authentication function module completes the authentication process of the terminal device according to the authentication scheme selected by the access authentication management module.

[0064] It should be noted that, taking a 6G heterogeneous converged network as an example, it may contain various networks such as satellite networks, mobile networks, fixed networks, and industrial IoT. These different networks can be seamlessly connected. However, different terminal devices accessing different networks within the 6G heterogeneous converged network may require different access and authentication methods. For example, when a mobile terminal accesses a base station located on a satellite, it can use either the satellite network's access authentication method or the mobile network's access authentication method. Similarly, when an IoT terminal accesses a mobile network, it may only be able to use the IoT's access authentication method. Therefore, in this embodiment of the invention, the access and authentication methods can be several methods recognized by the 6G heterogeneous converged network, and the access authentication management module can select appropriate authentication and access methods for the terminal devices according to their different needs.

[0065] It should be noted that the access process executed by the access function module and the authentication process executed by the authentication function module are similar to the current existing technology, and the embodiments of the present invention do not impose specific limitations.

[0066] The access authentication method for heterogeneous converged networks provided in this invention decouples the access process and authentication process of terminal devices through a modular structure design on the access network side and the core network side. The access process and authentication process are executed separately for the terminal devices, and the appropriate access scheme and authentication scheme are intelligently selected for the terminal devices. This can meet the complex and ever-changing security access authentication needs of terminal devices. At the same time, the authentication process is only executed when it is determined that the terminal device needs to be authenticated, thereby effectively reducing the resource waste caused by redundant authentication.

[0067] In one optional embodiment, the access request carries device information of the terminal device, including device type and identity identifier; before selecting an access scheme for the terminal device, the method further includes:

[0068] The trust assessment status of the terminal device is obtained from the core network side based on the device information.

[0069] The trust assessment is performed on the terminal device based on the trust assessment status to determine whether to allow the access operation to be performed on the terminal device.

[0070] If the trust assessment result is satisfactory, it is determined that access operation is permitted for the terminal device; wherein, the access operation refers to selecting an access scheme for the terminal device;

[0071] If the trust assessment result is unqualified, it is determined to perform an access denial operation or an access restriction operation on the terminal device; wherein, the access restriction operation means allowing the terminal device to perform an access operation, but marking the terminal device and restricting the access permissions of the terminal device after access.

[0072] Specifically, in conjunction with the above embodiments, the access request sent by the terminal device generally carries the terminal device's device information. This device information mainly includes the terminal device's device type (e.g., mobile phone, camera, satellite device, IoT device, etc.) and identity identifier (e.g., device ID, etc.). Correspondingly, after determining that the received request is an access request, before selecting an appropriate access scheme for the terminal device based on the received access request, the access authentication management module can first obtain the terminal device's trust assessment status from the core network side based on the terminal device's device information carried in the access request (i.e., the result obtained by the core network after performing a trust assessment on the terminal device's past network accesses). Then, based on... The obtained trust assessment status is used to perform a trust assessment on the terminal device to determine whether access operation is currently allowed. If the trust assessment result is qualified (i.e., the terminal device passes the trust assessment and is considered a trustworthy terminal), then access operation is currently allowed, and the access authentication management module can continue to process the terminal device's access request, that is, it can continue to select an appropriate access scheme for the terminal device. If the trust assessment result is unqualified (i.e., the terminal device fails the trust assessment and is considered a terminal with extremely high risk), then access operation is currently not allowed, but the access authentication management module can perform access denial or access restriction operations on the terminal device.

[0073] It should be noted that if the access authentication management module performs an access denial operation on the terminal device, the access authentication management module can directly send an access denial response to the terminal device and will no longer process any subsequent access requests sent by the terminal device.

[0074] It should be noted that if the access authentication management module performs an access restriction operation on the terminal device, the access authentication management module can continue to process the access request of the terminal device, but it needs to mark the terminal device and restrict the access permissions of the terminal device after it accesses the network.

[0075] In one optional embodiment, the access request also carries access point information; the step of selecting an access scheme for the terminal device specifically includes:

[0076] Based on the access point information, determine whether the current network status of the access point meets the access requirements of the terminal device;

[0077] If satisfied, an access method is selected for the terminal device based on the device information, and the access request and the selected access method are sent to the access function module of the access point.

[0078] The process of completing the access process of the terminal device through the access function module according to the access scheme selected by the access authentication management module specifically includes:

[0079] The access function module of the access point completes the access process of the terminal device according to the access request and the selected access method.

[0080] Specifically, in conjunction with the above embodiments, the access request sent by the terminal device generally also carries information about the access point that the terminal device wants to access (e.g., the access point identifier). Accordingly, when the access authentication management module selects an appropriate access scheme for the terminal device, it can first determine whether the current network status of the access point (i.e., the access point that the terminal device wants to access) meets the terminal device's access requirements based on the access point information carried in the access request. If it is determined that the current network status of the access point meets the terminal device's access requirements, it then selects an appropriate access method for the terminal device based on the device information (e.g., device type) carried in the access request, and sends the access request sent by the terminal device and the selected access method to the access function module of the access point. Accordingly, after receiving the access request and the access method selected by the access authentication management module, the access function module of the access point can complete the access process of the terminal device according to the access method selected by the access authentication management module.

[0081] It should be noted that each access point on the access network side is equipped with its own access function module. The access function module of the corresponding access point will execute the access process for the terminal device to access the access point.

[0082] In one optional embodiment, selecting an access scheme for the terminal device further includes:

[0083] If the requirements are not met, a new access point that meets the access requirements will be selected for the terminal device, and the new access point information will be sent to the terminal device.

[0084] Receive a new access request sent by the terminal device based on the new access point information, reselect an access method for the terminal device according to the device information carried in the new access request, and send the new access request and the newly selected access method to the access function module of the new access point;

[0085] The process of completing the access process of the terminal device through the access function module according to the access scheme selected by the access authentication management module specifically includes:

[0086] The access function module of the new access point completes the access process of the terminal device according to the new access request and the newly selected access method.

[0087] Specifically, in conjunction with the above embodiments, after the access authentication management module determines whether the current network status of the access point meets the access requirements of the terminal device based on the access point information carried in the access request, if it determines that the current network status of the access point does not meet the access requirements of the terminal device, it can reselect a new access point that meets the access requirements of the terminal device and send the new access point information to the terminal device. After receiving the new access point information sent by the access authentication management module, the terminal device can resend a new access request to the access authentication management module based on the received new access point information. After receiving the new access request sent by the terminal device, the access authentication management module can reselect an appropriate access method for the terminal device based on the device information (e.g., device type) carried in the received new access request, and send the new access request and the newly selected access method sent by the terminal device to the access function module of the new access point. Correspondingly, after receiving the new access request and the newly selected access method sent by the access authentication management module, the access function module of the new access point can complete the access process of the terminal device according to the newly selected access method.

[0088] For example, suppose a mobile terminal wants to access a terrestrial base station. If the access authentication management module determines that the capacity of the terrestrial base station is saturated and cannot meet the access needs of the mobile terminal, and detects that a satellite base station in the sky is available, then the satellite base station can be used as the new access point for the mobile terminal. The new access point information is forwarded to the mobile terminal, which then re-initiates a new access request to the new access point. After receiving the new access request from the mobile terminal, the access authentication management module will reselect an appropriate access scheme for the terminal device based on the received new access request and notify the access function module to execute the access process for the terminal device.

[0089] It should be noted that, in addition to sending new access requests and newly selected access methods from terminal devices to the access function module of the new access point, the access authentication management module can also send the trust assessment results of terminal devices to the new access point. This allows the new access point to conveniently and promptly know the trust assessment status of terminal devices, avoiding repeated trust assessments of terminal devices by the new access point and thus improving the processing efficiency of the new access point.

[0090] The access authentication method for heterogeneous converged networks provided in this invention can intelligently select a suitable access point for terminal devices based on the current network status, thereby improving the access success rate of terminal devices and effectively avoiding congestion.

[0091] In one optional embodiment, after the access function module completes the access process of the terminal device according to the access scheme selected by the access authentication management module, the method further includes:

[0092] The access function module sends the access status indication information to the access authentication management module.

[0093] The access authentication management module sends access request response information back to the terminal device based on the access status indication information.

[0094] Specifically, in conjunction with the above embodiments, after the access function module completes the access process of the terminal device according to the access scheme selected by the access authentication management module, it can send access status indication information (e.g., including the identity identifier and access status of the terminal device) to the access authentication management module; after receiving the access status indication information sent by the access function module, the access authentication management module can send access request response information back to the terminal device according to the received access status indication information to indicate whether the terminal device has successfully accessed the network.

[0095] For example, see Figure 3 The diagram shows an access flowchart for an access authentication method for heterogeneous converged networks according to an embodiment of the present invention. The UE (User Equipment) sends an access request to the access authentication management module on the access network side. This access request carries the UE's device type, identity identifier, and access point information that the UE wants to access. Upon receiving the access request from the UE, and if the UE's trust assessment result is deemed satisfactory... Figure 3After omitting the trust assessment process, the system selects a suitable access point for the UE based on the current network status (this could be the access point the UE wants to access, or a newly selected access point), and selects a suitable access method for the UE based on the UE's device type. Then, it sends the UE's access request and the selected access method to the access function module of the selected access point. Upon receiving the access request and selected access method from the access authentication management module, the access function module executes the access procedure corresponding to the selected access method (e.g., mobile terminal access procedure, satellite terminal access procedure, or various terminal access procedures supported by the network). This requires cooperation between the UE, the access authentication management module, the access function module, and the identity management module on the core network side to complete the access procedure. After the access procedure is completed, the access function module sends access status indication information to the access authentication management module. Upon receiving the access status indication information from the access function module, the access authentication management module sends access request response information back to the UE.

[0096] In one optional embodiment, the connection request or service request carries device information of the terminal device, the device information including device type and identity identifier; before selecting an authentication scheme for the terminal device, the method further includes:

[0097] Determine whether authentication is required for the terminal device based on the device information;

[0098] If not required, the connection request or service request will be sent to the core network side for processing.

[0099] If necessary, an authentication operation is performed on the terminal device; wherein, the authentication operation refers to selecting an authentication scheme for the terminal device.

[0100] Specifically, in conjunction with the above embodiments, the connection request or service request sent by the terminal device generally carries the terminal device's device information. This device information mainly includes the terminal device's device type (e.g., mobile phone, camera, satellite device, IoT device, etc.) and identity identifier (e.g., device ID, etc.). Correspondingly, after determining that the received request is a connection request or service request, before selecting an appropriate authentication scheme for the terminal device based on the received connection request or service request, the access authentication management module can first determine whether an authentication operation needs to be performed on the terminal device based on the device information carried in the connection request or service request. If it is determined that no authentication operation is needed, the access authentication management module can directly send the received connection request or service request to the core network side for corresponding processing. If it is determined that an authentication operation needs to be performed on the terminal device, the access authentication management module can perform the authentication operation, that is, it can continue to select an appropriate authentication scheme for the terminal device.

[0101] It should be noted that terminal devices generally fall into three categories: First, terminal devices with low network service demand and low security requirements do not need authentication. Second, terminal devices with infrequent or non-urgent network service demand can be temporarily exempted from authentication upon access, and authenticated when requesting service. Third, terminal devices with high network service demand and high security requirements can be authenticated upon access. Facing the complex access scenarios of 6G, this embodiment of the invention separates the access process from the authentication process, eliminating authentication of terminal devices upon access. This better meets the different access authentication needs of terminal devices. Therefore, based on the above classification of terminal devices, in this embodiment, the access network side will determine whether authentication is required after receiving a connection request or service request from the terminal device. Authentication will only be performed when it is determined that authentication is required, thus eliminating some authentication steps for terminal devices, effectively improving authentication efficiency, reducing resource waste caused by redundant authentication, and saving resources.

[0102] In one optional embodiment, the connection request or service request further carries service information, including the service type and the service's QoS requirements for the network; the step of selecting an authentication scheme for the terminal device specifically includes:

[0103] Based on the device information, the service information, and the trust assessment result of the terminal device, an authentication method is selected for the terminal device, and the authentication request and the selected authentication method are sent to the authentication function module.

[0104] The authentication process of the terminal device, which is completed by the authentication function module according to the authentication scheme selected by the access authentication management module, specifically includes:

[0105] The authentication function module completes the authentication process of the terminal device based on the authentication request and the selected authentication method.

[0106] It should be noted that when a terminal device sends a connection request, it needs to send its device information to the access network side. If it needs to further request services, it needs to send the service information to the access network side as well (it can be sent along with the connection request or sent separately in a service request). Therefore, the connection request or service request sent by the terminal device will carry not only the terminal device's device information but also the service information. The service information mainly includes the type of service requested (e.g., voice call, video call, file upload, file download, etc.) and the service's QoS (Quality of Service) requirements for the network (e.g., bandwidth requirements, latency requirements, etc.).

[0107] Specifically, in conjunction with the above embodiments, when the access authentication management module selects an appropriate authentication scheme for the terminal device, it can select an appropriate authentication method for the terminal device based on the device information (e.g., device type) and service information (e.g., service type and service QoS requirements for the network) carried in the connection request or service request, combined with the trust assessment result of the terminal device, and send the authentication request and the selected authentication method to the authentication function module; accordingly, after receiving the authentication request and the authentication method selected by the access authentication management module, the authentication function module can complete the authentication process of the terminal device according to the authentication method selected by the access authentication management module.

[0108] It should be noted that the authentication request sent by the access authentication management module to the authentication function module will also carry the device information of the terminal device. In addition, the authentication method selected by the access authentication management module can also be added to the authentication request and sent to the authentication function module together.

[0109] In one optional embodiment, after the authentication process of the terminal device is completed by the authentication function module according to the authentication scheme selected by the access authentication management module, the method further includes:

[0110] The authentication result information is sent to the access authentication management module through the authentication function module.

[0111] The authentication result information is fed back to the terminal device through the access authentication management module.

[0112] Specifically, in conjunction with the above embodiments, after the authentication function module completes the authentication process of the terminal device according to the authentication scheme selected by the access authentication management module, it can send the authentication result information (e.g., authentication success or authentication failure) to the access authentication management module; after receiving the authentication result information sent by the authentication function module, the access authentication management module can directly forward the received authentication result information to the terminal device to indicate whether the terminal device has successfully authenticated.

[0113] Understandably, after a connection is established and authentication is successful, if it is still necessary to execute business requests, the access authentication management module can send the business requests to the core network side for corresponding processing.

[0114] For example, see Figure 4 The diagram illustrates an authentication flowchart for an access authentication method for heterogeneous converged networks according to an embodiment of the present invention. Assuming the UE has successfully accessed the network, the UE sends a connection request or service request to the access authentication management module on the access network side. This connection request or service request carries the UE's device type, identity identifier, service type, and QoS requirements of the service to the network. Upon receiving the connection request or service request from the UE, the access authentication management module determines whether the UE needs to be authenticated. If not, it directly feeds back the authentication result information to the UE. If so, based on the UE's device information, trust assessment result, service type, and QoS requirements of the service to the network, it selects a suitable authentication method for the UE and sends the authentication request (carrying the UE's device information (e.g., identity identifier) ​​and the selected authentication method) to the authentication function module. Upon receiving the authentication request from the access authentication management module, the authentication function module executes the corresponding authentication protocol and authentication process (e.g., 6G AKA or EAP) according to the selected authentication method. The authentication process involves various authentication protocols supported by networks such as AKA, and requires cooperation between the UE, the access authentication management module, the authentication function module, and the authentication management module on the core network side to complete the authentication process. After the authentication process is completed, the authentication function module sends the authentication result information to the access authentication management module. After receiving the authentication result information sent by the authentication function module, the access authentication management module sends the authentication result information back to the UE.

[0115] This invention also provides an access authentication device for heterogeneous converged networks. The device is deployed on the access network side of the heterogeneous converged network and is used to implement the access authentication method for heterogeneous converged networks described in any of the above embodiments. See [link to relevant documentation]. Figure 5 The diagram shown is a structural block diagram of an access authentication device for heterogeneous converged networks according to an embodiment of the present invention. The device includes:

[0116] The access authentication management module 11 is used to receive requests sent by terminal devices, and when the request is an access request, select an access scheme for the terminal device; when the request is a connection request or a service request and authentication of the terminal device is required, select an authentication scheme for the terminal device.

[0117] Access function module 12 is used to complete the access process of the terminal device according to the access scheme selected by access authentication management module 11;

[0118] The authentication function module 13 is used to complete the authentication process of the terminal device according to the authentication scheme selected by the access authentication management module 11.

[0119] Preferably, the access request carries device information of the terminal device, including device type and identity identifier; before selecting an access scheme for the terminal device, the access authentication management module 11 is further configured to:

[0120] The trust assessment status of the terminal device is obtained from the core network side based on the device information.

[0121] The trust assessment is performed on the terminal device based on the trust assessment status to determine whether to allow the access operation to be performed on the terminal device.

[0122] If the trust assessment result is satisfactory, it is determined that access operation is permitted for the terminal device; wherein, the access operation refers to selecting an access scheme for the terminal device;

[0123] If the trust assessment result is unqualified, it is determined to perform an access denial operation or an access restriction operation on the terminal device; wherein, the access restriction operation means allowing the terminal device to perform an access operation, but marking the terminal device and restricting the access permissions of the terminal device after access.

[0124] Preferably, the access request also carries access point information; the access authentication management module 11 selects an access scheme for the terminal device, specifically including:

[0125] Based on the access point information, determine whether the current network status of the access point meets the access requirements of the terminal device;

[0126] If satisfied, an access method is selected for the terminal device based on the device information, and the access request and the selected access method are sent to the access function module 12 of the access point.

[0127] Then, the access function module 12 completes the access process of the terminal device according to the access scheme selected by the access authentication management module 11, specifically including:

[0128] The terminal device completes the access process based on the access request and the selected access method.

[0129] Preferably, the access authentication management module 11 selects an access scheme for the terminal device, and further includes:

[0130] If the requirements are not met, a new access point that meets the access requirements will be selected for the terminal device, and the new access point information will be sent to the terminal device.

[0131] The system receives a new access request sent by the terminal device based on the new access point information, reselects an access method for the terminal device according to the device information carried in the new access request, and sends the new access request and the newly selected access method to the access function module 12 of the new access point.

[0132] Then, the access function module 12 completes the access process of the terminal device according to the access scheme selected by the access authentication management module 11, specifically including:

[0133] The terminal device completes the access process based on the new access request and the newly selected access method.

[0134] Preferably, after completing the access process of the terminal device according to the access scheme selected by the access authentication management module 11, the access function module 12 is further configured to:

[0135] Send the access status indication information to the access authentication management module 11;

[0136] The access authentication management module 11 is also used for:

[0137] The system sends an access request response to the terminal device based on the access status indication information.

[0138] Preferably, the connection request or service request carries device information of the terminal device, the device information including device type and identity identifier; before selecting an authentication scheme for the terminal device, the access authentication management module 11 is further configured to:

[0139] Determine whether authentication is required for the terminal device based on the device information;

[0140] If not required, the connection request or service request will be sent to the core network side for processing.

[0141] If necessary, an authentication operation is performed on the terminal device; wherein, the authentication operation refers to selecting an authentication scheme for the terminal device.

[0142] Preferably, the connection request or service request also carries service information, including the service type and the service's QoS requirements for the network; the access authentication management module 11 selects an authentication scheme for the terminal device, specifically including:

[0143] Based on the device information, the service information, and the trust assessment result of the terminal device, an authentication method is selected for the terminal device, and the authentication request and the selected authentication method are sent to the authentication function module 13;

[0144] Then, the authentication function module 13 completes the authentication process of the terminal device according to the authentication scheme selected by the access authentication management module 11, specifically including:

[0145] The authentication process for the terminal device is completed based on the authentication request and the selected authentication method.

[0146] Preferably, after completing the authentication process of the terminal device according to the authentication scheme selected by the access authentication management module 11, the authentication function module 13 is further configured to:

[0147] The authentication result information is sent to the access authentication management module 11;

[0148] The access authentication management module 11 is also used for:

[0149] The authentication result information is fed back to the terminal device.

[0150] It should be noted that the access authentication device for heterogeneous converged networks provided in this embodiment of the invention can implement all the processes of the access authentication method for heterogeneous converged networks described in any of the above embodiments. The functions and technical effects of each module in the device are the same as those of the access authentication method for heterogeneous converged networks described in the above embodiments, and will not be repeated here.

[0151] This invention also provides a computer-readable storage medium, including a stored computer program, which, when running, controls the device where the computer-readable storage medium is located to execute the access authentication method for heterogeneous converged networks described in any of the above embodiments.

[0152] This invention also provides a computer program product, including a computer program that, when executed by a processor, implements the access authentication method for heterogeneous converged networks described in any of the above embodiments.

[0153] This invention also provides a terminal device, see [link to relevant documentation]. Figure 6 The diagram shown is a structural block diagram of a terminal device according to an embodiment of the present invention. The terminal device includes a processor 10, a memory 20, and a computer program stored in the memory 20 and configured to be executed by the processor 10. When the processor 10 executes the computer program, it implements the access authentication method for heterogeneous converged networks described in any of the above embodiments.

[0154] Preferably, the computer program can be divided into one or more modules / units (such as computer program 1, computer program 2, ...), and the one or more modules / units are stored in the memory 20 and executed by the processor 10 to complete the present invention. The one or more modules / units can be a series of computer program instruction segments capable of performing specific functions, and the instruction segments are used to describe the execution process of the computer program in the terminal device.

[0155] The processor 10 may be a central processing unit (CPU), or other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor may be a microprocessor, or the processor 10 may be any conventional processor. The processor 10 is the control center of the terminal device, connecting various parts of the terminal device through various interfaces and lines.

[0156] The memory 20 mainly includes a program storage area and a data storage area. The program storage area can store the operating system, applications required for at least one function, etc., while the data storage area can store related data, etc. Furthermore, the memory 20 can be a high-speed random access memory, or a non-volatile memory, such as a plug-in hard disk, a smart media card (SMC), a secure digital card (SD), and a flash card, or other volatile solid-state storage devices.

[0157] It should be noted that the aforementioned terminal devices may include, but are not limited to, processors and memory, as will be understood by those skilled in the art. Figure 6 The structural block diagram shown is merely a structural example of the terminal device described above and does not constitute a limitation on the structure of the terminal device. The terminal device may include more or fewer components than shown, or combine certain components, or use different components.

[0158] In summary, the access authentication method, apparatus, computer-readable storage medium, computer program product, and terminal device provided by the embodiments of the present invention for heterogeneous converged networks, through modular structural design on the access network side and the core network side, can decouple the access process and authentication process of the terminal device, execute the access process and authentication process separately for the terminal device, and intelligently select the appropriate access scheme and authentication scheme for the terminal device based on information such as device information, trust assessment status, access requirements, current network status, and service information, thereby meeting the complex and ever-changing security access authentication requirements of the terminal device. At the same time, it can also intelligently select a suitable access point for the terminal device based on the current network status, thereby improving the access success rate of the terminal device and effectively avoiding congestion. In addition, the authentication process is only executed when it is determined that the terminal device needs to be authenticated, which can eliminate part of the authentication process of the terminal device, thereby effectively improving the authentication efficiency of the terminal device and effectively reducing the resource waste caused by redundant authentication, saving resources.

[0159] The above description is only a preferred embodiment of the present invention. It should be noted that for those skilled in the art, several improvements and modifications can be made without departing from the technical principles of the present invention, and these improvements and modifications should also be considered within the scope of protection of the present invention.

Claims

1. An access authentication method for heterogeneous converged networks, characterized in that, The method is applied to the access network side of a heterogeneous converged network, wherein the access network side is deployed with an access authentication management module, an access function module, and an authentication function module, and includes: The access authentication management module receives requests sent by terminal devices, selects an access scheme for the terminal device when the request is an access request, and selects an authentication scheme for the terminal device when the request is a connection request or a service request and authentication of the terminal device is required. The access function module completes the access process of the terminal device according to the access scheme selected by the access authentication management module. The authentication function module completes the authentication process of the terminal device according to the authentication scheme selected by the access authentication management module.

2. The access authentication method for heterogeneous converged networks as described in claim 1, characterized in that, The access request carries the device information of the terminal device, which includes device type and identity identifier; Before selecting an access scheme for the terminal device, the method further includes: The trust assessment status of the terminal device is obtained from the core network side based on the device information. The trust assessment is performed on the terminal device based on the trust assessment status to determine whether to allow the access operation to be performed on the terminal device. If the trust assessment result is satisfactory, it is determined that access operation is permitted for the terminal device; wherein, the access operation refers to selecting an access scheme for the terminal device; If the trust assessment result is unqualified, it is determined to perform an access denial operation or an access restriction operation on the terminal device; wherein, the access restriction operation means allowing the terminal device to perform an access operation, but marking the terminal device and restricting the access permissions of the terminal device after access.

3. The access authentication method for heterogeneous converged networks as described in claim 2, characterized in that, The access request also carries access point information; the step of selecting an access scheme for the terminal device specifically includes: Based on the access point information, determine whether the current network status of the access point meets the access requirements of the terminal device; If satisfied, an access method is selected for the terminal device based on the device information, and the access request and the selected access method are sent to the access function module of the access point. The process of completing the access process of the terminal device through the access function module according to the access scheme selected by the access authentication management module specifically includes: The access function module of the access point completes the access process of the terminal device according to the access request and the selected access method.

4. The access authentication method for heterogeneous converged networks as described in claim 3, characterized in that, The step of selecting an access scheme for the terminal device further includes: If the requirements are not met, a new access point that meets the access requirements will be selected for the terminal device, and the new access point information will be sent to the terminal device. Receive a new access request sent by the terminal device based on the new access point information, reselect an access method for the terminal device according to the device information carried in the new access request, and send the new access request and the newly selected access method to the access function module of the new access point; The process of completing the access process of the terminal device through the access function module according to the access scheme selected by the access authentication management module specifically includes: The access function module of the new access point completes the access process of the terminal device according to the new access request and the newly selected access method.

5. The access authentication method for heterogeneous converged networks as described in claim 1, characterized in that, After the access function module completes the access process of the terminal device according to the access scheme selected by the access authentication management module, the process further includes: The access function module sends the access status indication information to the access authentication management module. The access authentication management module sends access request response information back to the terminal device based on the access status indication information.

6. The access authentication method for heterogeneous converged networks as described in claim 1, characterized in that, The connection request or service request carries device information of the terminal device, including device type and identity identifier; before selecting an authentication scheme for the terminal device, the following is also included: Determine whether authentication is required for the terminal device based on the device information; If not required, the connection request or service request will be sent to the core network side for processing. If necessary, an authentication operation is performed on the terminal device; wherein, the authentication operation refers to selecting an authentication scheme for the terminal device.

7. The access authentication method for heterogeneous converged networks as described in claim 6, characterized in that, The connection request or service request also carries service information, which includes the service type and the service's QoS requirements for the network. The step of selecting an authentication scheme for the terminal device specifically includes: Based on the device information, the service information, and the trust assessment result of the terminal device, an authentication method is selected for the terminal device, and the authentication request and the selected authentication method are sent to the authentication function module. The authentication process of the terminal device, which is completed by the authentication function module according to the authentication scheme selected by the access authentication management module, specifically includes: The authentication function module completes the authentication process of the terminal device based on the authentication request and the selected authentication method.

8. The access authentication method for heterogeneous converged networks as described in claim 1, characterized in that, After the authentication process of the terminal device is completed by the authentication function module according to the authentication scheme selected by the access authentication management module, the process further includes: The authentication result information is sent to the access authentication management module through the authentication function module. The authentication result information is fed back to the terminal device through the access authentication management module.

9. An access authentication device for heterogeneous converged networks, characterized in that, Deployed on the access network side of a heterogeneous converged network, the device includes: The access authentication management module is used to receive requests sent by terminal devices, and when the request is an access request, select an access scheme for the terminal device; when the request is a connection request or a service request and authentication of the terminal device is required, select an authentication scheme for the terminal device. The access function module is used to complete the access process of the terminal device according to the access scheme selected by the access authentication management module. The authentication function module is used to complete the authentication process of the terminal device according to the authentication scheme selected by the access authentication management module.

10. A computer-readable storage medium, characterized in that, The device includes a stored computer program that, when executed, controls the device containing the computer-readable storage medium to perform the access authentication method for heterogeneous converged networks as described in any one of claims 1 to 8.

11. A computer program product, characterized in that, It includes a computer program that, when executed by a processor, implements the access authentication method for heterogeneous converged networks as described in any one of claims 1 to 8.

12. A terminal device, characterized in that, The system includes a processor, a memory, and a computer program stored in the memory and configured to be executed by the processor, wherein the processor, when executing the computer program, implements the access authentication method for heterogeneous converged networks as described in any one of claims 1 to 8.