User authentication and activation method, device and system
By obtaining the IP address, port number, and/or MAC address of the terminal device for identification and indexing, the problem of the terminal device not supporting the AKMA mechanism is solved, and the authentication and activation of user identifiers or users is realized, thus improving the user authentication and activation mechanism.
Patent Information
- Application Number
- CN202410784233.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-06-17
- Publication Date
- 2025-12-19
AI Technical Summary
Some terminal devices do not support the AKMA mechanism, which makes it impossible to perform user authentication and activation, affecting the user authentication experience.
By obtaining the IP address, port number, and/or MAC address of the terminal device for identification and indexing, user identification or user authentication and activation can be achieved.
Regardless of whether the terminal device supports the AKMA mechanism, it can realize the authentication and activation of user identifiers or users, thus improving the user authentication and activation mechanism.
Smart Images

Figure CN121173484A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the field of communication technology, and particularly relates to a user authentication and activation method, device and system. BACKGROUND
[0002] With the development of Internet technology, business requirements are constantly enriched, and one or more user identity application servers (UIAS) are deployed in a communication system to manage user identities; a UIAS deployed by a third-party service provider can use a network exposure function (NEF) to implement interworking with a 5G core (5g core, 5GC), and the UIAS can perform user authentication / authorization on a user through an application layer, such as a webpage or a user equipment (UE) application; when the user successfully creates a user identity, relevant credentials are shared between the user and the UIAS.
[0003] In the related art, a UE is identified and indexed by using a secret key identifier in an authentication and key management for applications (AKMA) mechanism when performing user authentication, and the user is authenticated and activated, however, currently, some UEs do not support the AKMA mechanism, which causes these UEs to be unable to authenticate and activate a user based on the secret key identifier of the AKMA mechanism, and affects the user experience of user authentication. SUMMARY
[0004] The present application provides a user authentication and activation method, device and system, which identifies and indexes a terminal device by obtaining an IP address and / or a port number and / or a MAC address of the terminal device, so as to authenticate and activate a user identity or a user in the terminal device.
[0005] The above object is not achieved, and the present application adopts the following technical solutions:
[0006] In a first aspect, the present application provides a user authentication and activation method, which can include: a first UIAS obtaining first information corresponding to a first UE, the first information including an IP address and / or a port number and / or a MAC address, the IP address and / or the port number and / or the MAC address being used to indicate the first UE; the first UIAS sending a first activation request, the first activation request including a first user identifier and the first information, the first activation request being used to request to activate or deactivate the first user identifier in the first UE or a first user corresponding to the first user identifier. Based on this, the first UIAS obtains the first information corresponding to the first UE, for example, an IP address, an IP address and a port number, or a MAC address, and then sends the first activation request based on the first information, and realizes authentication and activation of the first user identifier or the first user in the first UE through the first information and the first user identifier carried in the first activation request.
[0007] The above-mentioned first aspect provides a solution, the first UIAS obtains the IP address and / or the port number and / or the MAC address of the first UE, realizes identification and indexing of the first UE, and sends the first activation request based on the identification and indexing of the first UE through the IP address and / or the port number and / or the MAC address, so as to authenticate and activate the user identifier in the first UE. In this way, the problem that some terminal devices cannot be indexed and identified by A-KID and cannot perform user identity authentication is solved, and the mechanism of user authentication and activation in the terminal device is more perfect. Whether the terminal device has A-KID or not, authentication and activation of the user identifier or the user can be realized according to the present solution. It can also be understood that authentication and activation of the user identifier are realized, and then authentication and activation of the user corresponding to the user identifier are realized.
[0008] As a possible implementation manner, the first UIAS obtaining the first information corresponding to the UE can include: in a case where it is determined that the first UE satisfies a first preset condition, the first UIAS obtains the first information of the first UE. Based on this, the first UIAS obtains the first information of the first UE when it is determined that the first UE satisfies the first preset condition, that is, the first UIAS cannot directly obtain the terminal identifier that can be used to identify and index the first UE. The first information of the first UE is used to indicate the first UE, and the first terminal identifier corresponding to the first UE is further determined. In this way, in a case where the first preset condition is used as a trigger condition, the first UIAS can obtain the first information of the first UE to realize authentication and activation of the user identifier or the first user in the first UE.
[0009] As a possible implementation manner, the first UE satisfying the first preset condition can include that the first UE does not support an authentication and key management AKMA mechanism of the application, and / or the first UE cannot determine a key identifier corresponding to the AKMA mechanism. Based on this, when the first UE does not support the AKMA mechanism or cannot determine the key identifier corresponding to the AKMA mechanism, the first information of the first UE can be acquired, the first UE is indicated through the first information of the first UE, and further, the first terminal identifier corresponding to the first UE is determined. In this way, in the case that the first UE does not support the AKMA mechanism or cannot determine the key identifier corresponding to the AKMA mechanism, the first UIAS can acquire the first information of the first UE, so as to implement authentication and activation of the first UE.
[0010] As a possible implementation manner, the first UIAS acquiring the first information of the first UE can include that the first UIAS receives the first information from the first UE, and / or the first UIAS receives a first data packet from the first UE, and determines the first information corresponding to the first UE according to the first data packet. Based on this, when the first UIAS acquires the first information of the first UE, the first UIAS can receive the first information directly sent by the first UE, that is, when the first UE does not support the AKMA mechanism or cannot determine the key identifier corresponding to the AKMA mechanism, the first UE can actively send the first information to the first UIAS. In addition, the first UIAS can acquire the first information of the first UE by analyzing the first data packet from the first UE. It can be understood that the first data packet can be directly sent by the first UE to the first UIAS, or can be acquired by the first UIAS from other devices, which is not limited herein.
[0011] As a possible implementation manner, the method can further include that the first UIAS sends a second activation request; the second activation request includes the configuration file corresponding to the first user identifier, the first user identifier and the first information; and the second activation request is used to request to create the first user configuration file, and activate or deactivate the first user identifier or the first user of the first UE. Based on this, the first UIAS acquires the first information of the first UE, for example, an IP address, an IP address and a port number, a MAC address, and then sends the second activation request based on the first information. The second activation request includes the first user identifier and the first information, and further includes the configuration file corresponding to the first user identifier, which is used for creation of the first user configuration file. The first user identifier and the first information are used to implement authentication, activation or deactivation of the first user identifier or the first user on the first UE.
[0012] As a possible implementation, the second activation request comprises a first user activation indication, the first user activation indication being used to indicate to activate or deactivate the first user identity or the first user. Based on this, when the second activation request comprises the first user activation indication, the first UIAS indicates to activate the first user identity on the first UE, so that the network device receiving the second activation request, such as the NEF or the UDM, determines that the first user identity is activated on the first UE.
[0013] As a possible implementation, the method can further comprise: the first UIAS receiving a first terminal identity corresponding to the first UE, the first terminal identity comprising an application function, AF, specific identity and / or a generic public subscription identity, the first terminal identity being used to indicate the first UE; and the first UIAS sending a third activation request, the third activation request comprising the first terminal identity, the first user identity and a profile corresponding to the first user identity, the third activation request being used to request to create the first user profile and to activate or deactivate the first user identity or the first user of the first UE. Based on this, the first UIAS can obtain the AF specific identity for the first UIAS and / or the generic public subscription identity, such as the GPSI and the SUPI, of the first UE from the first UE after establishing a secure session with the first UE, as the first terminal identity used to identify the first UE, and based on the obtained first terminal identity, send the third activation request, the third activation request comprising the first user identity and the first terminal identity, and further comprising the profile corresponding to the first user identity, for the creation of the first user profile, the first user identity and the first terminal identity being used to implement the authentication, activation or deactivation of the first user identity or the first user on the first UE.
[0014] As a possible implementation, the third activation request comprises a first user activation indication, the first user activation indication being used to indicate to activate or deactivate the first user identity or the first user. Based on this, when the third activation request comprises the first user activation indication, the first UIAS indicates to activate the first user identity on the first UE, so that the network device receiving the third activation request, such as the NEF or the UDM, determines that the first user identity is activated on the first UE.
[0015] In a second aspect, the present application provides a user authentication and activation method, which can include: a first UE obtaining first information corresponding to the first UE, the first information including an IP address and / or a port number and / or a MAC address; the first UE sending the first information to a first UIAS, the IP address and / or the port number and / or the MAC address in the first information being used to indicate the first UE in an activation request sent by the first UIAS. Based on this, the first UE determines the first information, such as an IP address, an IP address and a port number, and a MAC address, allocated by a network device to the first UE, and sends it to the first UIAS, which is used to indicate the first UE in the activation request sent by the first UIAS. Exemplarily, the activation request can be a first activation request, a second activation request, or a third activation request, to achieve authentication and activation of a first user identity or a first user on the first UE. Wherein, the first information can be sent through the same or different messages, which is not limited here.
[0016] The above-mentioned second aspect provides a scheme, the first UE can obtain the IP address and / or the port number and / or the MAC address corresponding to itself, and provide it to the UIAS, so as to identify and index the first UE through the IP address and / or the port number and / or the MAC address in the process of user identity authentication and activation, to achieve authentication and activation of a first user identity or a first user on the first UE.
[0017] As a possible implementation manner, sending the first information to the first UIAS can include: in a case where the first UE meets a first preset condition, the first UE sends the first information to the first UIAS. Based on this, when the first UE meets the first preset condition, that is, when the first UE does not have a terminal identity that can be used to identify and index the first UE, the first UE can be indicated by the first information of the first UE, and further, a first terminal identity corresponding to the first UE is determined. In this way, in a case where the first preset condition is used as a trigger condition, the first UE sends the first information to the first UIAS, to achieve authentication and activation of a user identity or a first user in the first UE.
[0018] As a possible implementation manner, the first UE meeting the first preset condition can include: the first UE not supporting the AKMA mechanism, and / or the first UE being unable to determine a key identifier corresponding to the AKMA mechanism. Based on this, when the first UE does not support the AKMA mechanism, or is unable to determine the key identifier corresponding to the AKMA mechanism, the first UE can be indicated by the first information of the first UE, and further, a first terminal identity corresponding to the first UE is determined. In this way, in a case where the first UE does not support the AKMA mechanism, or is unable to determine the key identifier corresponding to the AKMA mechanism, the first UE sends the first information to the first UIAS, to achieve authentication and activation of a user identity or a first user in the first UE.
[0019] As a possible implementation, the method can further include: the first UE determining and sending a corresponding first terminal identifier according to the first UIAS of the connection, the first terminal identifier being used to indicate the first UE. Based on this, the first UE can determine the first terminal identifier according to the first UIAS of the connection after establishing a secure session with the first UIAS, and synchronize to the first UIAS, so that the first UIAS sends a third activation request to implement authentication, activation or deactivation of the first user identifier or the first user on the first UE.
[0020] As a possible implementation, the first terminal identifier includes an application function (AF) specific identifier and / or a generic public subscription identifier. Based on this, the first terminal identifier determined by the first UE according to the first UIAS of the connection can include an AF specific identifier for the first UIAS and / or a generic public subscription identifier of the first UE, such as a GPSI and a SUPI, as a first terminal identifier used to identify the first UE, to implement authentication, activation or deactivation of the first user identifier or the first user on the first UE.
[0021] In a third aspect, the present application provides a user authentication and activation method, which can include: a first NEF receiving a first activation request from a first UIAS, the first activation request including a first user identifier and first information, the first information including an IP address and / or a port number and / or a MAC address; the first NEF determining a first terminal identifier corresponding to a first UE according to the IP address and / or the port number and / or the MAC address, and sending a fourth activation request, the fourth activation request including the first user identifier, the first terminal identifier and a first AF identifier corresponding to the first UIAS, the fourth activation request being used to request to activate or deactivate the first user identifier or a first user corresponding to the first user identifier of the first UE. Based on this, after the first NEF receives the first activation request sent by the first UE, the first NEF processes the first information used to indicate the first terminal identifier in the first activation request to obtain the first terminal identifier corresponding to the first information, and then sends the fourth activation request including the first terminal identifier, the first user identifier and the first AF identifier, to indicate that the first user identifier or the first user is authenticated, activated or deactivated when the fourth activation request is received.
[0022] The scheme provided by the above third aspect, in the case where the network device includes an NEF, the first NEF receiving a first activation request from a first UIAS can process the first information carried in the first activation request to obtain a first terminal identifier, and generate and send a fourth activation request based on the first terminal identifier obtained by processing the first information, so as to authenticate and activate the user identifier in the terminal device, so that the mechanism of user authentication and activation in the terminal device is more perfect.
[0023] As a possible implementation manner, the method can further include: the first NEF receiving a second activation request from the first UIAS, the second activation request including the profile corresponding to the first user identifier, the first user identifier, and the first information; the first NEF determining the first terminal identifier of the first UE according to the IP address and / or the port number and / or the MAC address, and sending a fifth activation request, the fifth activation request including the first AF identifier, the first user identifier, the profile corresponding to the first user identifier, and the first terminal identifier, the fifth activation request being used to request to create the first user profile and to activate or deactivate the first user identifier of the first UE. Based on this, after the first NEF receives the second activation request sent by the first UE, the first NEF processes the first information used to indicate the first terminal identifier in the second activation request to obtain the first terminal identifier corresponding to the first information, and then sends the fifth activation request including the first terminal identifier, the first user identifier, the profile corresponding to the first user identifier, and the first AF identifier, so as to indicate that when the fifth activation request is received, the first user profile is created and the first user identifier of the first UE is activated or deactivated.
[0024] As a possible implementation manner, the fifth activation request includes a first user activation indication, the first user activation indication being used to indicate to activate or deactivate the first user identifier. Based on this, when the fifth activation request includes the first user activation indication, the first NEF indicates to activate the first user identifier on the first UE, so that the network device receiving the fifth activation request, such as the NEF or the UDM, determines that the first user identifier is activated on the first UE.
[0025] As a possible implementation manner, the method can further include: the first NEF receiving a third activation request from the first UIAS, the third activation request including the first terminal identifier, the first user identifier, and the profile corresponding to the first user identifier; and the first NEF sending a sixth activation request, the sixth activation request including the first AF identifier, the first user identifier, the profile corresponding to the first user identifier, and the first terminal identifier, the sixth activation request being used to request to create the first user profile and to activate or deactivate the first user identifier or the first user of the first UE. After the first NEF receives the third activation request sent by the first UE, the first NEF sends the sixth activation request including the first terminal identifier, the first user identifier, the profile corresponding to the first user identifier, and the first AF identifier, so as to indicate that when the sixth activation request is received, the first user profile is created and the first user identifier of the first UE is activated or deactivated.
[0026] As a possible implementation, the sixth activation request comprises a first user activation indication, the first user activation is used to indicate activation or deactivation of the first user identifier or the first user. Based on this, when the sixth activation request comprises the first user activation indication, the first NEF indicates that the first user identifier is activated on the first UE, so that the network device receiving the sixth activation request, such as the NEF or the UDM, determines that the first user identifier is activated on the first UE.
[0027] In a fourth aspect, the present application provides a user authentication and activation method, which can comprise: a first UDM receiving a first activation request from a first UIAS, the first activation request comprising a first user identifier and first information, the first information comprising an IP address and / or a port number and / or a MAC address; the first UDM determining a first terminal identifier corresponding to the first UE according to the IP address and / or the port number and / or the MAC address; based on the first terminal identifier and the first user identifier, the first UDM activates or deactivates the first user identifier or a first user corresponding to the first user identifier of the first UE. Based on this, after the first UDM receives the first activation request sent by the first UIAS, the first information in the first activation request for indicating the first terminal identifier is processed first to obtain the first terminal identifier corresponding to the first information, and then the first user identifier or the first user is authenticated, activated or deactivated based on the first terminal identifier and the first user identifier carried in the first activation request, and the subscription data of the first UE is overwritten according to the first user identifier. Optionally, the first activation request can carry a first AF identifier.
[0028] The above-mentioned fourth aspect provides a scheme, after the first UDM receives the first activation request, the corresponding first terminal identifier is determined according to the first information, and then the first user identifier or the first user is activated or deactivated based on the determined first terminal identifier, the first user identifier and the first AF identifier, which realizes indexing the first UE through the first information, and performs authentication, activation or deactivation of the first user identifier or the first user on the first UE; solves the problem that some terminal devices do not have corresponding A-KID to identify and index the guide, so that user identity authentication cannot be performed, so that the mechanism of user authentication and activation in the terminal device is more perfect, and whether the terminal device has A-KID or not, the authentication and activation of the user identifier or the first user can be realized according to the scheme.
[0029] As a possible implementation manner, the method can further include: the first UDM receiving a second activation request from the first UIAS, the second activation request including a profile corresponding to the first user identifier, the first user identifier, and first information; the first UDM creating a first user profile according to the profile corresponding to the first user identifier; the first UDM determining a first terminal identifier corresponding to the first UE according to the IP address and / or the port number and / or the MAC address; and the first UDM activating or deactivating the first user identifier or the first user of the first UE based on the first terminal identifier and the first user identifier. Based on this, after the first UDM receives the second activation request sent by the first UIAS, the first UDM processes the first information in the second activation request for indicating the first terminal identifier to obtain the first terminal identifier corresponding to the first information, then creates the first user profile according to the profile corresponding to the first user identifier carried in the second activation request, and based on the first user profile, authenticates, activates or deactivates the first user identifier or the first user according to the first terminal identifier and the first user identifier, determines the mapping relationship between the first terminal identifier and the first user identifier, and marks the first UE as an activated state to indicate that the first UE is being used or occupied by the first user identifier.
[0030] As a possible implementation manner, the method can further include: the first UDM receiving a third activation request from the first UIAS, the third activation request including the first terminal identifier, the first user identifier, and a profile corresponding to the first user identifier; the first UDM creating a first user profile according to the profile corresponding to the first user identifier; and the first UDM activating or deactivating the first user identifier of the first UE based on the first terminal identifier and the first user identifier. Based on this, after the first UDM receives the third activation request sent by the first UIAS, the first UDM processes the first information in the third activation request for indicating the first terminal identifier to obtain the first terminal identifier corresponding to the first information, then creates the first user profile according to the profile corresponding to the first user identifier carried in the third activation request, and based on the first user profile, authenticates, activates or deactivates the first user identifier or the first user according to the first terminal identifier and the first user identifier, determines the mapping relationship between the first terminal identifier and the first user identifier, and marks the first UE as an activated state.
[0031] As a possible implementation manner, the method can further include: the first UDM receiving a fourth activation request from the first NEF, the fourth activation request including the first user identifier, the first terminal identifier, and a first AF identifier corresponding to the first UIAS; based on the first terminal identifier, the first user identifier, and the first AF identifier, the first UDM activating or deactivating the first user identifier or the first user of the first UE. Based on this, after the first UDM receives the fourth activation request sent by the first NEF, the first UDM authenticates, activates, or deactivates the first user identifier or the first user based on the first terminal identifier and the first user identifier carried in the fourth activation request, and overwrites the subscription data of the first UE according to the first user identifier. Optionally, the first activation request can carry the first AF identifier.
[0032] As a possible implementation manner, the method can further include: the first UDM receiving a fifth activation request from the first NEF, the fifth activation request including the first AF identifier, the first user identifier, a configuration file corresponding to the first user identifier, and the first terminal identifier; the first UDM creating a first user configuration file according to the configuration file corresponding to the first user identifier; based on the first terminal identifier, the first user identifier, and the first AF identifier, the first UDM activating or deactivating the first user identifier or the first user of the first UE. Based on this, after the first UDM receives the fifth activation request sent by the first UIAS, the first UDM creates a first user configuration file according to the configuration file corresponding to the first user identifier carried in the fifth activation request, authenticates, activates, or deactivates the first user identifier or the first user according to the first terminal identifier and the first user identifier based on the first user configuration file, determines the mapping relationship between the first terminal identifier and the first user identifier, and marks the first UE as an activated state to indicate that the first UE is being used or occupied by the first user identifier.
[0033] As a possible implementation manner, the method can further include: the first UDM receiving a sixth activation request from the first NEF, the sixth activation request including the first terminal identifier, the first user identifier, and a configuration file corresponding to the first user identifier; the first UDM creating a first user configuration file according to the configuration file corresponding to the first user identifier; based on the first terminal identifier, the first user identifier, and the first AF identifier, the first UDM activating or deactivating the first user identifier or the first user of the first UE. Based on this, after the first UDM receives the sixth activation request sent by the first UIAS, the first UDM creates a first user configuration file according to the configuration file corresponding to the first user identifier carried in the sixth activation request, authenticates, activates, or deactivates the first user identifier or the first user according to the first terminal identifier and the first user identifier based on the first user configuration file, determines the mapping relationship between the first terminal identifier and the first user identifier, and marks the first UE as an activated state.
[0034] As a possible implementation, the first UDM activating or deactivating the first user identity or the first user of the first UE can comprise: the first UDM activating / deactivating the first user identity or the first user based on a first user activation indication; and / or, the first UDM activating or deactivating the first user identity or the first user upon determining that the first UE is in a registered state. Based on this, when the first user activation indication is carried in the first activation request, the second activation request, the third activation request, the fourth activation request, the fifth activation request or the sixth activation request, the first UDM can activate or deactivate the first user identity or the first user according to the first user activation indication, in addition, the first UDM can determine whether to activate the first user identity by obtaining the state information of the first UE, for example, when the first UE is in RM REGISTERED state or the UE is registered with the network. The first UDM activates the first user identity.
[0035] In a fifth aspect, the present application provides a communication apparatus, comprising units or modules for performing the method of any one of the first aspect or the second aspect or the third aspect or the fourth aspect.
[0036] In a sixth aspect, the present application provides a communication system, comprising a first communication apparatus, a second communication apparatus, a third communication apparatus and a fourth communication apparatus, the first communication apparatus is used to implement the method of any one of the first aspect; the second communication apparatus is used to implement the method of any one of the second aspect, the third communication apparatus is used to implement the method of any one of the third aspect, and the fourth communication apparatus is used to implement the method of any one of the fourth aspect.
[0037] In a seventh aspect, the present application provides a computer readable storage medium, the computer readable storage medium stores computer program instructions, when the computer program instructions are executed by a processing circuit, the method of any one of the first aspect or the second aspect or the third aspect or the fourth aspect is implemented.
[0038] In an eighth aspect, the present application provides a computer program product comprising instructions which, when the computer program product is executed on a computer, cause the method of any one of the first aspect or the second aspect or the third aspect or the fourth aspect to be implemented.
[0039] In a ninth aspect, the present application provides a communication device, comprising a processor configured to implement the method of any one of the first aspect or the second aspect or the third aspect or the fourth aspect. Optionally, the communication device further comprises a memory configured to store computer program instructions; and the computer program instructions, when executed by the processor, implement the method of any one of the first aspect or the second aspect or the third aspect or the fourth aspect. BRIEF DESCRIPTION OF DRAWINGS
[0040] Figure 1 A flowchart of a method for creating / updating / deleting a user profile through a UIAS;
[0041] Figure 2 A flowchart of a method for activating / deactivating a user identity in a UE;
[0042] Figure 3 A schematic diagram of a principle of creating a new user profile through an application;
[0043] Figure 4 A flowchart of a method for creating a new user profile through an application;
[0044] Figure 5 A flowchart of a method for indexing a UE through an AF-specific identity;
[0045] Figure 6 A schematic diagram of a registration management state model of a UE;
[0046] Figure 7 A flowchart of a user authentication and activation method provided by an embodiment of the present application;
[0047] Figure 8 A detailed flowchart of a user authentication and activation method provided by an embodiment of the present application;
[0048] Figure 9 A detailed flowchart of another user authentication and activation method provided by an embodiment of the present application;
[0049] Figure 10 A detailed flowchart of still another user authentication and activation method provided by an embodiment of the present application;
[0050] Figure 11 A schematic diagram of a component structure of a communication device provided by an embodiment of the present application;
[0051] Figure 12 A schematic diagram of a hardware structure of a communication device provided by an embodiment of the present application. DETAILED DESCRIPTION
[0052] The technical solutions in the embodiments of the present application will be described below with reference to the drawings in the embodiments of the present application. In the description of the embodiments of the present application, unless otherwise specified, " / " represents the meaning of or, for example, A / B can represent A or B; "and / or" herein only represents a description of the association relationship of the associated objects, which means that there can be three relationships, for example, A and / or B can represent: A alone, A and B together, and B alone. In addition, in the description of the embodiments of the present application, "multiple" means two or more than two.
[0053] Hereinafter, the terms "first", "second", and the like are only used to distinguish different description objects, and have no limiting effect on the position, order, priority, quantity, or content of the described objects. For example, the described object is "field", and the ordinal number before "field" in "first field" and "second field" does not limit the position or order between "fields", and "first" and "second" do not limit whether the "fields" modified by them are in the same message or not, nor limit the order of "first field" and "second field". For example, the described object is "level", and the ordinal number before "level" in "first level" and "second level" does not limit the priority between "levels". For example, the quantity of the described object is not limited by the ordinal number, which can be one or more. For example, "first device", where the quantity of "device" can be one or more. In addition, the objects modified by different prefix words can be the same or different, for example, the described object is "device", and "first device" and "second device" can be the same type of device or different types of device. For example, the described object is "information", and "first information" and "second information" can be information of the same content or information of different content. In summary, the use of ordinal numbers and other prefix words in the embodiments of the present application for distinguishing description objects does not limit the described objects, and the description of the described objects in the claims or embodiments should not be limited by the use of such prefix words.
[0054] In addition, in the embodiments of the present application, "connection" can be direct connection or indirect connection; in addition, it can mean electrical connection or communication connection; for example, two electrical elements A and B are connected, which can mean that A is directly connected with B, or can mean that A and B are indirectly connected through other electrical elements or connection medium, or can mean that A and B are indirectly connected through other communication devices or communication medium, as long as A and B can communicate with each other.
[0055] With the development of Internet technology, business requirements are constantly enriched, and one or more UIASs are deployed in the communication system for user identity management, which can include authentication and de-authentication of users, or authentication and de-authentication of user identities. If the UIAS is deployed by a third-party service provider, it can be interconnected with the 5GC using a network exposure function (NEF). The UIAS can authenticate and / or authorize users through an application layer, for example, a web application, a UE application, etc., and when a user successfully creates a user identity, the related credentials of the user identity are shared between the user and the UIAS.
[0056] In some embodiments, the UIAS includes management of user identity information and management of user security mechanisms when performing user identity management. When a user creates a user identity, the UIAS can request the 5GC to generate a 5G user profile for the user identity; for example, the user profile includes information as shown in Table 1:
[0057] Table 1
[0058]
[0059] In some embodiments, the user interacts with the UIAS through an application layer to configure the activation / deactivation of the user identifier in a specific UE. When the UIAS requests the UDM to activate the user identity in a specific UE, the UDM updates the UE subscription data and associates the user subscription data with the specific UE subscription data.
[0060] In some examples, see Figure 1 , which shows a flowchart of a method for creating / updating / deleting a user profile through a UIAS, as shown in Figure 1 , the method comprises:
[0061] S1. The user interacts with the UIAS through an application layer (e.g., a web page, a UE application) to create / update / delete a user identity.
[0062] S2. If the operation request of the user identity is accepted by the UIAS, the UIAS can trigger a user profile creation / update / deletion request to configure user-specific services. For example, user-specific Quality of Service (QoS).
[0063] Exemplarily, the UIAS requests to create / update / delete the user profile through Nnef_ParameterProvision_Create / Update / Delete sent to the NEF; after receiving the creation request, the NEF determines whether the requester is allowed to perform the requested service operation by checking the identifier of the requester (i.e. the UIAS identifier).
[0064] S3. If the NEF authorizes the UIAS to provide parameters, the NEF requests to create, update or delete the user profile parameters as part of the user subscription data through Nnef_ParameterProvision_Create / Update / Delete.
[0065] S4. After receiving the operation request, the UDM verifies whether the update of the user profile is authorized according to the query of the user subscription data in the UDR, and the UDM requests to create, update or delete the user profile parameters provided as part of the user data.
[0066] S5. The UDM updates the user subscription data in the UDR.
[0067] S6-S7. The UDM responds to the request through the NEF to the UIAS.
[0068] In some embodiments, referring to Figure 2 which shows a flowchart of a method for activating / deactivating a user identifier in a UE, as shown in Figure 2 In the process of activating / deactivating the user identifier of the UE, the method can include:
[0069] S1. A network function (Network Function, NF) sends a UE subscription data subscription request and subscribes to the UDM notification of the UE subscription data update.
[0070] S2. A secure application session is established between the UE and the UIAS.
[0071] In the process of establishing the secure application session, the UE derives an A-KID (AKMA Key IDentifier) and sends it to the UIAS.
[0072] S3. The user requests the UIAS to activate / deactivate the user identity initiated by the UE through the secure application session request UIAS. If the user identity operation request is accepted by the UIAS, the UIAS can trigger the user identity activation / deactivation request to the UE. The UIAS can use the received A-KID to identify the UE without retrieving the UE subscription ID, e.g. GPSI. The UIAS provides the activation / deactivation parameters (e.g. User Identifier, A-KID) in the request to the key anchor function (akma anchor function, AAnF).
[0073] S4. The AAnF provides the activation / deactivation parameters (e.g. User Identifier, A-KID) to the UDM through the request message. When the UIAS is deployed in a non-trusted domain of the 5GS, the NEF can be applied between the UIAS and the AAnF. The UDM computes the SUPI and GPSI of the UE from the received A-KID upon receiving the activation / deactivation request.
[0074] S5. The UDM verifies whether the activation / deactivation of the user identity is authorized based on the UDR query of the UE subscription data and the user profile.
[0075] S6. The UDM activates / deactivates the user profile in the UE. The UDM updates the user subscription data, adding or removing the user identity in the user subscription information.
[0076] S7-S8. The UDM responds to the request through the AAnF to the UIAS.
[0077] S9. The UDM notifies the NF of the UE subscription data update. The merged UE subscription data and User Profile parameters can be sent to the NF in the notification. The NF can update the existing PDU session and apply in future new PDU sessions according to the activated / deactivated user profile to provide proper QoS control and / or policy and charging control.
[0078] In some embodiments, referring to Figure 3 which shows a schematic diagram of creating a new user profile through an application, as Figure 3shown in FIG. 1. It is based on the introduction of a new function in the 5G core network (5GC) network, called the User Identity Management Function (UIMF). The UIMF is accessible by the device through the 5GC network or through the Internet, i.e. using any third party ASP other than 5G through open protocols, e.g. public WiFi networks, cable residential access, etc. All communication between the device and the UIMF happens at the application layer. For example, by using an MNO application that can be downloaded in the device. After the user downloads the MNO application, an account is created by the UIMF and the mobile number is confirmed. At this point, the created account is linked to the mobile subscription of this user. The user can access the UIMF using any device as long as the device has the MNO application and the user can log into the UIMF using the credentials of its UIMF account. The device accessing the UIMF does not need to have a USIM card.
[0079] In some examples, the user interacts with the UIMF using the MNO application to create a new user profile linked to the user's mobile subscription. The device can be a typical smartphone equipped with a USIM module or any USIM-less device, e.g. a tablet, a laptop, a PC, etc. The UIMF configures the UE with the user profile data (DUPD). The DUPD contains one (or more) user identifier that can be associated with the user. The configuration can be done through an application layer program or a CP program. The UIMF ensures that the used user identifier is unique for the PLMN where the user profile is created. The UIMF provides the user profile information to the 5G core network through the NEF service. The UDR supports the storage of the user profile.
[0080] In some examples, the user profile includes one or more of the following: a user profile reference ID that uniquely identifies the user profile among all user profiles in the same mobile subscription; one of a plurality of user identifiers (e.g. user@example.com); authentication information such as credentials (e.g. password, digital certificate, etc.) and authentication type; a generic public subscription identifier (GPSI) to identify the mobile subscription linked to the user profile; one or more devices that can use this user profile; one or more applications associated with this user profile; QoS settings applied to traffic associated with this user profile; a list of services available for this user profile.
[0081] In some embodiments, referring to Figure 4 which shows a flow diagram of a method of creating a new user profile through an application, as Figure 4As shown, a user can leverage the MNO application and interact with the UIMF to create a new user profile associated with his / her mobile subscription. The device shown in the figure can be a typical smartphone equipped with a USIM module or any USIM-less device such as a tablet, a laptop, a PC, etc. The method specifically comprises:
[0082] The user profile created by the device using the application layer procedure can be linked to a third party account.
[0083] S1. After the application in the device is launched, the device establishes a secure connection with the UIMF. The IP address of the UIMF can be preconfigured in the MNO application or discovered through DNS.
[0084] S2. The user logs in using the credentials associated with the mobile subscription. By way of example, the user can log in to the UIMF using the credentials of his / her UIMF account.
[0085] S3. The device creates a user profile request. By way of example, the device uses the UI of the MNO application and the user requests to create a new user profile. The type of user profile can be selected from a list of predefined profiles (e.g. "secure browsing", "social media", "video streaming", etc.) or can be specified by selecting the individual services of the user profile. The user can provide a new set of credentials for this user profile, e.g. a user identity and a password. Alternatively, the user can choose to link this user profile to an existing third party account. In this case, the user does not need to provide a set of credentials for the user profile, as the existing credentials of the third party account will be reused.
[0086] S4. If the user decides to link the user profile to a third party account, an open protocol is established and the UIMF triggers a known OAuth 2.0 procedure to the third party application service provider (ASP) to obtain access to the user's third party account. The authentication message can be sent to the UE through the application layer.
[0087] S5. In the OAuth 2.0 procedure, the UIMF receives an access token from the third party application server (ASP) and then uses the access token to retrieve user information from the third party ASP, including the user identity, preferences, possible subscription status (i.e. if the user holds a gold or silver subscription with the third party service provider), etc.
[0088] S6. The UIMF creates a new user profile. In the case where the user profile is associated with a third party account, the UIMF can create the new user profile by taking into account the user information received from the third party ASP in S5 and the SLA already established between the mobile operator and the third party service provider.
[0089] In some examples, the UIMF-created user profile is automatically associated with the user's mobile subscription. The user profile includes one or more of the following: a user profile reference ID that uniquely identifies the user profile among all user profiles in the same mobile subscription; one of a plurality of user identifiers; authentication information such as credentials (e.g., password, digital certificate, etc.) and authentication type; a generic public subscription identifier (GPSI) to identify the mobile subscription linked to the user profile; one or more devices that can use this user profile (assuming the UIMF can get the device identification from the client); one or more applications associated with this user profile; QoS settings applied to traffic associated with this user profile; a list of services available to this user profile;
[0090] S7. The UIMF sends the device user profile data GPSI, user identifier authentication information, the UIMF sends the data about the user profile that should be stored in the UE to the MNO application.
[0091] S8. The UIMF sends the user profile data to all other devices connected with the same GPSI and allowed to use the user profile, in some examples, the UIMF sends the DUPD not only to the device that initiated the user profile creation, but also to all other devices connected to the UIMF using the same UIMF account, which are allowed to use the user profile. For example, if a user has a smartphone, a tablet, and a PC, all devices run the MNO application and are logged into the UIMF using the same UIMF account, then all three devices will receive the DUPD of the new user profile, assuming they are all allowed to use this user profile; all user profiles of a mobile user are synchronized across all devices of the mobile user.
[0092] S9. After the NEF receives and creates the user profile, the UIMF sends a create user profile request to a network function in the 5GC (e.g., a network exposure function (NEF)) in order to store the created user profile in the associated mobile subscription data. The create user profile request contains the GPSI of the linked mobile subscription and information about the user profile itself (user profile information).
[0093] S10. The NEF determines the GPSI of the associated mobile subscription and, based on the UDM, converts the identifier to a SUPI, which is needed before storing the user profile in the UDR.
[0094] S11. The device updates the data for the UDR everywhere.
[0095] S12. The NEF derives the updated data of the user profile information in the UDR from the received user profile.
[0096] S13. Finally, the NEF responds to the UIMF and completes the creation of the new user profile.
[0097] In some embodiments, based on the user profile information, a separate user profile can be created in the AM, SM, and referenced in the PDU session related control data, for example, a user profile reference ID that uniquely identifies the user profile among all user profiles in the same mobile subscription; one of the multiple user identifiers (e.g. user@example.com); in the AM subscription data: one or more devices (i.e. PEI) that can use this user profile; in the SMS subscription data; authentication information such as credentials (e.g. password, digital certificate, etc.) and authentication type; in the PDU session related control data: one or more applications associated with this user profile; QoS settings applied to traffic associated with this user profile; and a list of services available to this user profile. The user profile reference ID can be added as a data sub-key in the PDU session for PDU session policy control related data.
[0098] In some embodiments, referring to Figure 5 , which shows a flowchart of indexing a UE by an AF specific identifier, as shown in Figure 5 , in the process of retrieving the AF specific UE ID, the AF specific UE identifier is represented by an external identifier; after retrieving the AF specific UE ID, the AF can invoke the services provided by the NEF (e.g. location monitoring). The NEF can obtain the allocated IP address of the UE, SUPI and DNN and S-NSSAI. The method includes:
[0099] S1. The AF requests to obtain the UE ID through the Nnef_UEId_Get service operation. The request message should include the UE address (IP address or MAC address) and the AF identifier, which can include the port number associated with the IP address, MTC provider information, application port ID, IP domain. The MTC provider information identifies the MTC service provider and / or the MTC application. If available, the AF can also provide the corresponding DNN and / or S-NSSAI.
[0100] In some examples, the MTC provider information can be used by any type of service provider (MTC or non-MTC) or company or external party, e.g. for differentiating its different customers; if the UE is behind NAT, the 5GC can use the combination of IP address and port number to derive the UE private IP address assigned by the 5GC, see S3-S6 below. The application port ID is defined in Nnef_Trigger_Delivery; the NEF can validate the provided MTC provider information and override it to the NEF selected MTC provider information according to the configuration. How the NEF determines the MTC provider information (if not present) is left to implementation (e.g. based on the requesting AF).
[0101] S2. The NEF authorizes the AF request. If authorization is not granted, the NEF replies to the AF with a Result value of authorization failure, otherwise the NEF proceeds with S3. The NEF determines the corresponding DNN and / or S-NSSAI information: this can have been provided by the AF, or determined by the NEF based on the requesting AF identifier, MTC provider information.
[0102] If the NEF receives a port number in S1, according to the configuration, the NEF can recognize that the received address is a different IP address than the actual UE private IP address assigned by the 5GC, i.e. the UE is behind NAT in the UPF. If yes, S3-S6 are executed. Otherwise S3-S6 are skipped.
[0103] S3. The NEF uses the Nnrf_NFDiscovery service operation to obtain the address of the UPF that implements NAT functionality for the UE (public) IP address. The request contains the UE (public) IP address. The NEF can also include the DNN and S-NSSAI associated with the AFID and the IP domain.
[0104] S4. The NRF responds with a Nnrf_NFDiscovery response message including the UPF address of the UPF that implements NAT functionality for the UE (public) IP address.
[0105] S5. The NEF requests the UE's (private) IP address from the UPF via the Nupf_GetUEPrivateIPaddrAndIdentifiers_Get service operation. The request includes the UE (public) IP address and port number and optionally the IP domain, DNN and S-NSSAI associated with the AFID.
[0106] S6. The UPF responds the Nupf_GetUEPrivateIPaddrAndIdentifiers_Get response message including the IP address of the UE and optionally the IP domain. If the UPF applies NAT function, the IP address of the UE returned by the UPF is the private IP address of the UE. If the UPF returns the IP domain of the UE private IP address, it always takes precedence regardless of whether the AF also provided the IP domain information when invoking the Nnef_UEId_Get service operation. If the UPF has the SUPI or GPSI of the UE, the UPF can return the SUPI or GPSI, in which case S7-S8 are skipped.
[0107] For the HR-SBO case as described in clause 4.3.6.1 and TS 23.548
[74] , the UE PDU session is indicated to work in HR-SBO mode, the SUPI of the PDU session and the HPLMN DNN and S-NSSAI are also provided by the UPF.
[0108] NOTE 7: SUPI / GPSI is only available if the SMF provides it to the UPF for the purpose defined in TS 29.244
[69] .
[0109] S7-S8. The NEF uses the Nbsf_Management_Discovery service operation with the UE address and IP domain and / or DNN and / or S-NSSAI to retrieve the session binding information of the UE. If no SUPI is received in the session binding information sent by the BSF, the NEF returns a Result to the AF indicating that the UE ID is not available.
[0110] S9. The NEF interacts with the UDM to retrieve the AF specific UE Identifier by the Nudm_SDM_Get service operation. The request message includes the SUPI or GPSI and at least one of the application port ID, MTC provider information or AF identity.
[0111] S10. The UDM responds to the NEF with the AF specific UE Identifier expressed as an external identifier that is uniquely associated with the application port ID, MTC provider information and / or AF identity.
[0112] S11. The NEF further responds to the AF using the response information received from the UDM including the AF specific UE Identifier expressed as an external identifier and based on this response information.
[0113] In some embodiments, the method for defining a terminal device identifier includes a generic public subscription identifier (GPSI). The GPSI can represent an MSISDN or an External Identifier. Or, according to the protocol used to transmit the GPSI, the GPSI type can take different formats, which are not limited herein.
[0114] In some examples, addressing a 3GPP subscription in different data networks outside the 3GPP system requires a generic public subscription identifier (GPSI). The 3GPP system stores the association between the GPSI and the corresponding SUPI in the subscription data. The GPSI is a common identifier used inside and outside the 3GPP system. The GPSI is an MSISDN or an external identifier, see TS 23.003
[19] . If the MSISDN is included in the subscription data, the same MSISDN value can be supported in 5GS and EPS. In addition, there is no implicit one-to-one relationship between the GPSI and the SUPI.
[0115] In some examples, the method for defining a terminal device identifier includes an A-KID (AKMA Key Identifier). The AKMA (Authentication and Key Management for Applications) key identifier (A-KID) should be globally unique. The A-KID should be usable as a key identifier in the protocol used in the reference point Ua*. The AKMA AF should be able to identify the AAnF serving the UE from the A-KID.
[0116] In some embodiments, see Figure 6 which shows an architectural diagram of a UE registration management state model, as shown in Figure 6 The terminal device is in the RM-REGISTERED state, in which the terminal has registered with the network. In the RM-REGISTERED state, the terminal device can receive services that require registration with the network. When the terminal device receives a registration request from another device, it can choose to accept the registration or reject the registration.
[0117] In some embodiments, the UE is identified and authenticated and activated by using the A-KID in the AKMA mechanism when performing user authentication. However, some UEs do not currently support the AKMA mechanism, which prevents these UEs from using the A-KID to authenticate and activate user identification, affecting the user experience of user authentication.
[0118] Based on this, the embodiments of the present application provide a user authentication and activation method, device and system. The UIAS acquires the IP address and / or port number and / or MAC address corresponding to the terminal device, which is used to indicate the terminal device. The UIAS sends an activation request based on the IP address and / or port number and / or MAC address, and the activation request is used to request to activate or deactivate the user identity from the terminal device. In this way, the UIAS identifies and indexes the terminal device through the IP address, IP address and port number, and MAC address of the terminal device, sends the activation request, and realizes the authentication and activation of the user of the terminal device.
[0119] The embodiments of the present application can be applied to but are not limited to the following communication systems: a narrow band-internet of things (NB-IoT) system, a wireless local access network (WLAN) system, a long term evolution (LTE) system, a 5th generation mobile networks or 5th generation wireless systems (5G) also known as a new radio (NR) system, or a future communication system after 5G, for example, the future communication system can be a 6G system, a device to device (D2D) communication system, a vehicle-to-everything (V2X) system, etc.
[0120] The interaction relationship between network functions and entities and the corresponding interfaces are demonstrated by taking the network service architecture of a 5G system as an example. The 3GPP service-based architecture (SBA) of the 5G system includes network functions and entities such as a user equipment (UE), an access network (AN) or a radio access network (RAN), a user plane function (UPF), a data network (DN), an access management function (AMF), a session management function (SMF), an authentication server function (AUSF), a policy control function (PCF), an application function (AF), a network slice selection function (NSSF), a unified data management (UDM), a network exposure function (NEF), and a network storage function (NF repository function, NRF).
[0121] The main functions of the related network elements involved in the present application are described below.
[0122] The UIAS is mainly responsible for managing user identities, for example, the UIAS has one or more of the following functions: managing user identities, authenticating and or authorizing users, requesting the network to create / update / delete user profiles, requesting the network to activate or deactivate users on UE devices, requesting the network to establish a correspondence between UE devices and UE users, and requesting the network to bind, activate, deactivate, etc. the correspondence between UE devices and UE users. In some examples, the UIAS can be other devices with one or more of the above functions, and devices with the same functions as the UIAS in the communication system are also applicable to the embodiments provided in the present application in principle, and are not limited herein.
[0123] AMF: mainly responsible for processing of control plane messages, such as: access control, mobility management, lawful interception, access authentication / authorization, etc. Specifically, the main functions of AMF are: 1) processing of access network control plane; 2) processing of NAS messages, responsible for NAS encryption and integrity protection; 3) registration management; 4) connection management; 5) access management; 6) mobility management; 7) lawful interception of information; 8) providing session management messages between UE and SMF; 9) implementing transparent transmission for routing session management (SM) messages, similar to a transparent proxy; 10) access authentication; 11) access authorization; 12) forwarding SMS messages (short messages) between UE and short message service function SMSF; 13) interacting with AUSF and UE to obtain UE authentication intermediate key; 14) calculating access network specific key.
[0124] SMF: mainly used for session management, UE internet protocol (IP) address allocation and management, selection of manageable user plane functions, terminal point of policy control and charging function interface, downlink data notification, etc. Specifically, the main functions of SMF are: 1) session management, session establishment, modification and release, including maintenance of channels between UPF and AN nodes; 2) UE IP address allocation and management; 3) selection and control of user plane functions; 4) configuration of correct traffic routing on UPF; 5) implementation of policy control functions; 6) control part of policy implementation and QoS; 7) lawful interception; 8) processing of session management part in NAS messages; 9) downlink data indication; 10) initiation of access network specific session management information (routed through AMF); 11) determination of mode of session and service continuity; 12) roaming function.
[0125] PCF: mainly used for providing UE policy rules, AM policy rules and SM policy rules related parameters to UE, AMF or SMF respectively, managing user subscription information, accessing UDM to access subscription user information related to policy decision, etc. PCF generally makes policy decisions based on subscription information, etc.
[0126] NEF: is the interface network element of the information bidirectional interaction between the internal and external entities of the network, and is also a logical unit of internal information distribution and collection, mainly including three capabilities: monitoring capability, supply capability, and policy / charging capability; among them, the monitoring capability mainly refers to the monitoring of special events of the UE, and outputting the monitoring information outward, for example, the UE location information, connectivity, roaming state, connection retention, etc. can be output through the NEF; the supply capability refers to that the external entity can provide information for the UE through the NEF, and these information can include mobility management and session management information, such as periodic communication time, communication duration, and scheduled communication time; the policy / charging capability refers to that the external entity transmits the demand through the NEF to handle the QoS and charging policy.
[0127] UDM: consists of two parts, one part is called application front end (FE), and the other part is called user data warehouse (UDR); the application front end is mainly used for: 1) authentication credit processing; 2) user identification processing; 3) access authorization; 4) registration / mobility management; 5) subscription management; 6) short message management.
[0128] Among them, the to-be-transmitted data can be transmitted through the PDU session (i.e. the communication bearer described in the specification) established between the UE and the DN, and the transmission will pass through two network function entities of (R)AN and UPF, the UE and the (R)AN communicate with each other by using a certain air interface technology, N1 is the interface point between the UE and the AMF, N2 is the interface point between the (R)AN and the AMF, N3 is the interface between the (R)AN and the UPF, N4 is the interface between the SMF and the UPF, N6 is the interface between the UPF and the DN; Namf is the service-based interface exhibited by the AMF, Nsmf is the service-based interface exhibited by the SMF, Nausf is the service-based interface exhibited by the AUSF, Nnssf is the service-based interface exhibited by the NSSF, Nnef is the service-based interface exhibited by the NEF, Nnrf is the service-based interface exhibited by the NRF, Npcf is the service-based interface exhibited by the PCF, Nudm is the service-based interface exhibited by the UDM, and Naf is the service-based interface exhibited by the AF.
[0129] The UE in the present application can be a desktop device, a laptop device, a handheld device, a wearable device, a smart home device, a computing device, a vehicle-mounted device, and the like with a wireless connection function. For example, a netbook, a tablet, a smart watch, an ultra-mobile personal computer (UMPC), a smart camera, a netbook, a personal digital assistant (PDA), a portable multimedia player (PMP), an AR (augmented reality) / VR (virtual reality) device, a wireless device on an aircraft, a wireless device on a robot, a wireless device in industrial control, a wireless device in telemedicine, a wireless device in a smart grid, a wireless device in a smart city, a wireless device in a smart home, and the like. Alternatively, the UE can also be a wireless device in a narrow band (NB) technology, and the like.
[0130] The UE in the present application can also refer to an access terminal, a subscriber unit, a subscriber station, a mobile station, a mobile, a relay station, a remote station, a remote terminal, a mobile device, a user terminal, a terminal, a wireless communication device, a user agent, or a user equipment. The terminal device can also be a cellular phone, a cordless phone, a session initiation protocol (SIP) phone, a wireless local loop (WLL) station, a personal digital assistant (PDA), a handheld device with wireless communication function, a computing device, or other processing devices connected to a wireless modem, a vehicle-mounted device, a wearable device, a terminal device in a future 5G network, or a terminal device in a future evolved public land mobile network (PLMN), or a terminal device in a future vehicle-to-everything (V2X) network, and the like. The specific type and structure of the UE are not limited in the present application.
[0131] In addition, in the present application, the UE can also be a terminal device in an IoT system, which mainly features connecting objects to a network through communication technology to realize the interconnection of man and machine, and the intelligent network of interconnection of things. IOT technology can achieve massive connection, deep coverage, and terminal power saving through, for example, narrow band (NB) technology.
[0132] The user authentication and activation method provided by the embodiments of the present application will be specifically introduced below with reference to the accompanying drawings.
[0133] In a possible implementation, referring to Figure 7 which shows a flowchart of a user authentication and activation method provided by an embodiment of the present application, as shown in Figure 7 , the method can include:
[0134] S701: The first UE acquires first information, wherein the first information includes an IP address and / or a port number and / or a MAC address corresponding to the first UE.
[0135] It should be noted that the first UE acquiring the first information can be understood as the first UE determining the first information, and the first information can include an IP address and / or a port number and / or a MAC address. For example, the first information can include an IP address, an IP address and a port number, or a MAC address, wherein the IP address can include an ipv4 address or an ipv6 address or an ipv6 address prefix.
[0136] In some embodiments, the first UE acquires the first information allocated to the first UE by a network device, which can be understood as the first UE determining an IP address or an IP address and a port number or a MAC address allocated to the first UE by a network device. The IP address or the IP address and the port number or the MAC address can be used to determine a first terminal identifier of the first UE. In some examples, the network device that allocates the IP address or the IP address and the port number or the MAC address to the first UE can be a 5GC.
[0137] In some embodiments, the first UE determines the first information of the first UE according to local information, for example, the first information can include an IP address or an IP address and a port number or a MAC address, and the IP address or the IP address and the port number or the MAC address can be used to determine a first terminal identifier of the first UE. For example, the local information includes physical network card device information of the first UE device, which can be understood as the first UE device using the physical network card device to use a communication network service. The first UE determines the first information according to the physical network card device information.
[0138] In some embodiments, the first UE acquiring the first information is optional, that is, the first UE can omit the step of acquiring or determining the first information, and directly sends an IP address or an IP address and a port number or a MAC address to the first UIAS.
[0139] S702: The first UE sends the first information to the first UIAS, and the IP address and / or the port number and / or the MAC address in the first information is used to indicate the first UE. Correspondingly, the first UIAS receives the first information of the first UE.
[0140] In some embodiments, the first UIAS has one or more of the following functions: managing user identity, authenticating and / or authorizing a user, requesting the network to create / update / delete a user profile, requesting the network to activate or deactivate a user on a UE device, requesting the network to establish a correspondence between a UE device and a UE user, and requesting the network to bind, activate, deactivate, etc. the correspondence between a UE device and a UE user.
[0141] In some embodiments, the first UIAS can be another device having one or more of the above functions, which has the same function as the first UIAS in the communication system, and the embodiments provided in the present application are applicable in principle without any limitation.
[0142] In some embodiments, the first UE sends the first information to the first UIAS when it is determined that the first UE satisfies the first preset condition. The first information of the first UE indicates the first UE, and further determines the first terminal identifier corresponding to the first UE. It can be understood that the first information of the first UE corresponds to the first terminal. When the first preset condition is used as a trigger condition, the first UE sends the first information to the first UIAS to achieve authentication and activation of the user identity or user in the first UE. It can also be understood that by authenticating and activating the user identity, the authentication and activation of the user corresponding to the user identity are achieved.
[0143] In some embodiments, the first UE sends the first information to the first UIAS when it is determined that the first UE does not support the AKMA mechanism and / or the first UE cannot obtain the key identifier (e.g., A-KID (AKMA Key Identifier)) corresponding to the AKMA mechanism. When the first UE does not support the AKMA mechanism and / or cannot determine the key identifier corresponding to the AKMA mechanism, the first information of the first UE is used to indicate the first UE. It can be understood that the first information of the first UE indicates the first UE, and further determines the first terminal identifier corresponding to the first UE to achieve authentication and activation of the user identity or user in the first UE.
[0144] In some embodiments, the first information can be sent through the same or different messages, which are not limited herein.
[0145] In some embodiments, the first UIAS can obtain the first information corresponding to the first UE according to the situation of the first UE. The first information includes an IP address and / or a port number and / or a MAC address. The first UIAS can use the IP address and / or the port number and / or the MAC address to indicate the first UE to achieve authentication and activation of the first user identity or the first user on the first UE. It can also be understood that by authenticating and activating the first user identity, the authentication and activation of the first user corresponding to the first user identity are achieved.
[0146] In some embodiments, the first UIAS triggers to obtain the first information of the first UE upon determining that the first UE meets the first preset condition. The first UIAS can obtain the first information of the first UE upon determining that the first UE meets the first preset condition, that is, the first UIAS cannot directly obtain the terminal identifier that can be used to identify and index the first UE. The first information of the first UE indicates the first UE, and further determines the first terminal identifier corresponding to the first UE. In this way, under the condition that the first preset condition is used as the trigger condition, the first UIAS can obtain the first information of the first UE to achieve the authentication and activation of the user identifier in the first UE.
[0147] In some embodiments, the first UIAS triggers to obtain the first information of the first UE upon determining that the first UE does not support the application of the authentication and key management AKMA mechanism, and / or the first UE cannot determine the key identifier corresponding to the AKMA mechanism. The first information of the first UE indicates the first UE, and further determines the first terminal identifier corresponding to the first UE. In this way, under the condition that the first UE does not support the AKMA mechanism or cannot determine the key identifier corresponding to the AKMA mechanism, the first UIAS can obtain the first information of the first UE to achieve the authentication and activation of the user identifier in the first UE.
[0148] In some embodiments, when the first UIAS obtains the first information, on the one hand, the first UIAS can obtain the first information by receiving the first information from the first UE; on the other hand, the first UIAS can also receive the first data packet from the first UE, and the first data packet includes the first information corresponding to the first UE. The first UIAS can obtain the first information corresponding to the first UE in the first data packet by analyzing the first data packet from the first UE. It can be understood that the first data packet can be directly sent by the first UE to the first UIAS, or the first UIAS can obtain the first data packet from other devices, which is not limited here.
[0149] S703: The first UIAS sends a first activation request to the first NEF, and the first activation request includes the first user identifier and the first information.
[0150] Correspondingly, the first NEF receives the first activation request from the first UIAS.
[0151] It should be noted that the first UIAS sends the first activation request, the first activation request includes the first user identifier and the first information, and the first activation request is used to request to activate or deactivate the first user identifier in the first UE or the first user corresponding to the first user identifier indicated by the first information, wherein the first user identifier is a user identifier that needs to be activated / deactivated, and the first activation request is used to request to activate or deactivate the first user identifier from the first UE. The first information and the first user identifier carried in the first activation request are used to realize authentication and activation of the first user identifier or the first user on the first UE.
[0152] In some embodiments, the first activation request includes: the first user identifier and / or the first user profile identifier, and the IP address, the port number, and the MAC address of the first information UE. In some examples, the first activation request further includes a UE activation indication.
[0153] S704: The first NEF sends a fourth activation request to the first UDM, and the fourth activation request includes the first user identifier and the first terminal identifier.
[0154] The corresponding first UDM receives the fourth activation request from the first NEF.
[0155] In some embodiments, after the first NEF receives the first activation request from the first UIAS, the first activation request includes the first user identifier and the first information, and the first information includes the IP address and / or the port number and / or the MAC address; the first NEF processes the first information in the first information to determine the first terminal identifier corresponding to the first UE, and then sends one or more of the first terminal identifier, the first user identifier, and the first AF identifier as the fourth activation request to indicate that when the fourth activation request is received, the first user identifier or the first user is authenticated, activated, or deactivated. The fourth activation request includes the first user identifier, the first terminal identifier, and the first AF identifier corresponding to the first UIAS, and the fourth activation request is used to request to activate or deactivate the first user identifier from the first UE.
[0156] In some embodiments, after the first NEF receives the first activation request, the first NEF authorizes the first activation request. The first terminal identifier (such as GPSI or SUPI) of the UE is determined according to the IP address of the UE, and the fourth activation request is sent by the first NEF to the UDM, including the AFID (i.e. the UIAS ID), the first user identifier, the SUPI, or the GPSI.
[0157] S705: The first UDM receives the fourth activation request from the first NEF, and activates / deactivates the first user identifier from the UE according to the fourth activation request.
[0158] In some embodiments, after the first UDM receives the fourth activation request sent by the first NEF, the fourth activation request includes the first user identifier, the first terminal identifier, and the first AF identifier corresponding to the first UIAS; based on the first terminal identifier, the first user identifier, and the first AF identifier, the first UDM activates or deactivates the first user identifier from the first UE. For example, based on the first terminal identifier and the first user identifier carried in the fourth activation request, the first user identifier or the first user is authenticated, activated, or deactivated, and the subscription data of the first UE is overwritten according to the first user identifier.
[0159] In some examples, the first UDM determines to activate the first user identifier or the first user on the first UE, and the first UDM modifies the content in the UE subscription request response according to the configuration file content corresponding to the first terminal identifier, and the subscription content of the UE does not change.
[0160] In some embodiments, the first UIAS can directly send the first activation request to the first UDM, that is, the first UIAS sends the first activation request to the UDM, and the first activation request includes the first user identifier and the first information.
[0161] Correspondingly, the first UDM receives the first activation request from the first UIAS.
[0162] In some embodiments, the first UDM receives the first activation request from the first UIAS, the first activation request includes the first user identifier and the first information, and the first information includes an IP address and / or a port number and / or a MAC address; the first UDM first processes the first information in the first activation request for indicating the first terminal identifier to obtain the first terminal identifier corresponding to the first information, and then authenticates, activates, or deactivates the first user identifier or the first user based on the first terminal identifier and the first user identifier carried in the first activation request, and overwrites the subscription data of the first UE according to the first user identifier. Optionally, the first activation request carries the first AF identifier.
[0163] In some examples, referring to Figure 8 , a detailed flowchart of a user authentication and activation method provided by an embodiment of the application is shown, as Figure 8 shown, the method can include:
[0164] S801: Pre-configure a UIAS authentication server (application or special device), and establish a secure session between the UE and the UIAS after the UE is connected to the network.
[0165] It should be noted that in the security application session establishment process, optionally: the UE determines the IP address and / or port number allocated by the 5GC to the UE, and sends the IP address and / or port number to the UIAS in the case that the UE does not support the AKMA mechanism, or the UE cannot determine the A-KID.
[0166] S802: The UE requests the UIAS to activate / deactivate the user identifier in the UE through the security application session; the user identifier operation request is authenticated by the UIAS.
[0167] S803: The UIAS determines whether the UE supports the AKMA mechanism, and if not, determines the IP address and port number of the UE.
[0168] In some examples, the UIAS determines the IP address and port number used by the UE, and the determination method includes the following: the UIAS determines the IP address and port number of the UE according to the source IP address and port number of the data packet sent by the UE; the UIAS determines the IP address and port number of the UE according to the received IP address and port number (sent by the UE through an application layer message).
[0169] S804: The UIAS provides the activation / deactivation parameters (e.g., User Identifier, IP address and port number) to the UDM through the activation / deactivation request (i.e., the first activation request in the foregoing embodiment). When the UIAS is deployed in a non-trusted domain of the 5GS, the NEF is applied between the UIAS and the UDM. If there is no NEF, the UDM can complete the following actions.
[0170] S805: The NEF authorizes the UIAS server, and the NEF determines that the UIAS has the right to use the User Profile related service.
[0171] S806: The NEF determines the SUPI or GPSI of the UE corresponding to the IP address and port number provided by the UIAS.
[0172] S807: The NEF sends a user profile request (i.e., the fourth activation request in the foregoing embodiment) to the UDM, including one or more of the following: AF identifier, user identifier, SUPI or GPSI of the UE, and the UDM can verify whether the activation / deactivation of the user identifier is authorized based on querying the UDR, UE subscription data and user profile.
[0173] S808: The UDM activates / deactivates the user profile in the UE. The UDM updates the subscription information of the UE, and adds or deletes the User Identifier in the user subscription information.
[0174] S8081: The UDM requests to subscribe to the UE subscription data.
[0175] S8082: The UDM overwrites the user identity in the UE subscription according to the user identity.
[0176] S8083: The UDM notifies the NF of the UE subscription data update.
[0177] It should be noted that the merged UE subscription data and User Profile parameters can be sent to the NF in the notification, and the NF can update the existing PDU session and apply in the future new PDU session according to the activated / deactivated user profile to provide appropriate QoS control and / or policy and charging control. The UDM can overwrite the UE subscription data returned to the NF, such as: the UDM overwrites the UE subscription data according to the QoS control and / or policy in the User Profile. It can be understood that this overwrite only works for this subscription request, the subscription information of the UE has not changed, and the modified content is limited to the subscription data in the subscription notification. The NF receiving the modified content is unaware of the existence of the User.
[0178] S809-S810: The UDM sends an activation / deactivation user profile response to the UIAS through the NEF.
[0179] In a possible implementation, the first UIAS sends a second activation request; wherein the second activation request includes one or more of the following: the configuration file corresponding to the first user identity, the first user identity, and the first information; the second activation request is used to request to create the first user profile, and to activate or deactivate the first user identity from the first UE. After the first UIAS obtains the first information of the first UE, for example, the IP address, the IP address and the port number, the MAC address, and then sends the second activation request based on the first information, the second activation request includes the first user identity and the first information, and also includes the configuration file corresponding to the first user identity, which is used for the creation of the first user profile, and the first user identity and the first information are used to realize the authentication, activation or deactivation of the first user identity or the first user on the first UE.
[0180] In some embodiments, the configuration file corresponding to the first user identity includes the first user identity, and when the configuration file corresponding to the first user identity includes the first user identity, the second activation request includes the configuration file corresponding to the first user identity and the first information, without the need to repeatedly carry the first user identity, so as to save transmission resources.
[0181] In some embodiments, the second activation request can further include a first user activation indication, the first user activation indication being used to indicate activation or deactivation of the first user identity. When the second activation request includes the first user activation indication, the first UIAS indicates that the first user identity is activated on the first UE, so that the network device receiving the second activation request, such as the NEF or the UDM, determines that the first user identity is activated on the first UE.
[0182] In some embodiments, the NEF receives and authorizes the user profile creation activation request (i.e. the second activation request in the foregoing embodiments), determines the corresponding GPSI or SUPI according to the IP address of the UE, sends a user profile activation request (i.e. the fifth activation request in the foregoing embodiments) to the UDM, the user profile activation request includes the AFID (i.e. the UIASID), the user identity, the SUPI or the GPSI, the user profile, and optionally, the user profile activation request includes the user activation indication.
[0183] In some embodiments, the first NEF receives the second activation request from the first UIAS, wherein the second activation request includes one or more of the following: the first user identity corresponding profile, the first user identity and the first information; the first NEF first processes the first information in the second activation request for indicating the first terminal identity to obtain the first terminal identity corresponding to the first information, and then sends one or more of the first terminal identity, the first user identity, the first user identity corresponding profile and the first AF identity as the fifth activation request to indicate that when the fifth activation request is received, the first user profile is created, and the first user identity from the first UE is activated or deactivated.
[0184] In some embodiments, the first UDM receives the fifth activation request from the first NEF, and the fifth activation request includes one or more of the following: the first AF identity, the first user identity, the first user identity corresponding profile and the first terminal identity; the first UDM creates the first user profile according to the first user identity corresponding profile; based on the first terminal identity, the first user identity and the first AF identity, the first UDM activates or deactivates the first user identity from the first UE. After the first UDM receives the fifth activation request sent by the first UIAS, the first UDM creates the first user profile according to the first user identity corresponding profile carried in the fifth activation request, based on the first user profile, authenticates, activates or deactivates the first user identity or the first user according to the first terminal identity and the first user identity, determines the mapping relationship between the first terminal identity and the first user identity, and marks the first UE as an activated state to indicate that the first UE is being used or occupied by the first user identity.
[0185] In some embodiments, the first user identifier is included in the first user identifier corresponding profile, and when the first user identifier is included in the first user identifier corresponding profile, the fifth activation request does not need to repeatedly carry the first user identifier, so as to save transmission resources.
[0186] In some embodiments, the fifth activation request includes a first user activation indication, and the first user activation indication is used to indicate activation or deactivation of the first user identifier. When the fifth activation request includes the first user activation indication, the first NEF indicates that the first user identifier is activated on the first UE, so that the network device receiving the fifth activation request, such as the NEF or the UDM, determines that the first user identifier is activated on the first UE.
[0187] In some embodiments, the first UDM receives a second activation request from the first UIAS, wherein the second activation request includes one or more of the following: the first user identifier corresponding profile, the first user identifier, and the first information; the first UDM first processes the first information in the second activation request to indicate the first terminal identifier to obtain the first terminal identifier corresponding to the first information, and then creates the first user profile according to the first user identifier corresponding profile carried in the second activation request, and based on the first user profile, authenticates, activates or deactivates the first user identifier or the first user according to the first terminal identifier and the first user identifier, determines the mapping relationship between the first terminal identifier and the first user identifier, and marks the first UE as an active state to indicate that it is being used or occupied by the first user identifier.
[0188] In some embodiments, the first UIAS can send a user profile creation and activation request to the NEF, including: the first user identifier, the first user identifier corresponding profile, and the first information (IP address, port number, MAC address of the UE), and in some examples, the first user activation indication of the UE.
[0189] In some examples, referring to Figure 9 , which shows a detailed flowchart of another user authentication and activation method provided by the embodiments of the present application, as shown in Figure 9 , the method can include:
[0190] S901: Pre-configure the UIAS authentication server (APP or special device), and establish a secure session between the UE and the UIAS after the UE is connected to the network.
[0191] S902: The user identifier operation request is authenticated by the UIAS.
[0192] S903: The UE creates and activates the user profile for the User, the UIAS sends the Create / Activate User Profile to the NEF (i.e. the second activation request in the foregoing embodiment) including the IP address and / or MAC address and / or port number of the UE, the user identifier, the user identifier corresponding profile, optionally, including the user activation indication.
[0193] S904: The NEF authorizes the UIAS server.
[0194] S905: The NEF determines the SUPI or GPSI of the UE according to the IP address and / or MAC address and / or port number of the UE.
[0195] S906: The NEF sends the User Profile Create Request (i.e. the fifth activation request in the foregoing embodiment) to the UDM, the User Profile Create Request including one or more of the following: AF ID (UIAS id), the user identifier, the user profile, the determined GPSI / SUPI, optionally: the User Profile Create Request further including the user activation indication.
[0196] S907: The UDM authorizes the User Profile Create / Activate Request. The UDM creates the user profile, determines the correspondence between the GPSI corresponding UE and the user identifier corresponding User, and activates the User and the UE, marking that the GPSI corresponding UE is being used or occupied by the user identifier.
[0197] S9071: The UDM requests to subscribe to the UE subscription data.
[0198] S9072: The UDM notifies the NF of the UE subscription data update.
[0199] It should be noted that the merged UE subscription data and User Profile parameters can be sent to the NF in the notification, and the NF can update the existing PDU session and apply in future new PDU session according to the activated / deactivated user profile to provide appropriate QoS control and / or policy and charging control. The UDM can overwrite the UE subscription data returned to the NF, such as: the UDM overwrites the UE subscription data according to the QoS control and / or policy in the User Profile. It can be understood that this overwrite only acts on this subscription request, the subscription information of the UE has not changed, and the modified content is limited to the subscription data in the subscription notification. The NF receiving the modified content is not aware of the existence of the User.
[0200] S908-S909: The UDM returns the Create Success Response to the NEF. The Create Success Response includes the GPSI of the UE, the UIAS determines the User Identifier and the GPSI of the UE, and optionally, the Create Success Response includes the activation indication.
[0201] In some embodiments, the UIAS directly uses the IP address and port number of the UE to identify the UE, the NEF or the UDM supports identifying the UE according to the IP address and port number index, avoiding the UIAS first determining the IP address of the UE, and then requesting to obtain the port number corresponding to the IP address, reducing the signaling overhead between the UIAS and the network. At the same time, the User Profile and the IP address activation indication are added to support synchronous activation after the User Profile is created. The UIAS directly uses the IP address and port number of the UE to identify the UE. The User profile activation indication is added.
[0202] In a possible implementation, the first UE determines and sends a corresponding first terminal identifier according to the connected first UIAS, the first terminal identifier being used to indicate the first UE. The first UE can determine the first terminal identifier according to the connected first UIAS after establishing a secure session with the first UIAS, and synchronize the first terminal identifier to the first UIAS, so that the first UIAS sends a third activation request to implement authentication, activation or deactivation of the first user identifier or the first user on the first UE.
[0203] In some embodiments, the first terminal identifier includes an application function (AF) specific identifier and / or a generic public subscription identifier. The first terminal identifier determined by the first UE according to the connected first UIAS can include an AF specific identifier for the first UIAS and / or a generic public subscription identifier of the first UE, such as a GPSI and a SUPI, as the first terminal identifier used to identify the first UE, to implement authentication, activation or deactivation of the first user identifier or the first user on the first UE.
[0204] In some embodiments, the first UIAS receives a first terminal identifier corresponding to the first UE, wherein the first terminal identifier includes an application function (AF) specific identifier and / or a generic public subscription identifier, and the first terminal identifier is used to indicate the first UE; the first UIAS sends a third activation request, the third activation request including one or more of the following: the first terminal identifier, the first user identifier, and a configuration file corresponding to the first user identifier, the third activation request being used to request to create the first user configuration file, and activate or deactivate the first user identifier from the first UE.
[0205] In some embodiments, the first user identifier is included in the configuration file corresponding to the first user identifier, and when the first user identifier is included in the configuration file corresponding to the first user identifier, the third activation request includes the first terminal identifier and the configuration file corresponding to the first user identifier, without the need to repeatedly carry the first user identifier, to save transmission resources.
[0206] In some examples, the first UIAS can obtain, after establishing the secure session with the first UE, an AF-specific identity for the first UIAS and / or a generic public subscription identity of the first UE, e.g., GPSI, SUPI, from the first UE as the first terminal identity for identifying the first UE, and send the third activation request based on the obtained first terminal identity, the third activation request including the first user identity and the first terminal identity, and further including the profile corresponding to the first user identity for creation of the first user profile, the first user identity and the first terminal identity being used for implementing authentication, activation or deactivation of the first user identity or the first user on the first UE.
[0207] In some embodiments, the third activation request includes a first user activation indication, the first user activation indication being used to indicate activation or deactivation of the first user identity. When the third activation request includes the first user activation indication, the first UIAS indicates that the first user identity is activated on the first UE, so that the network device receiving the third activation request, e.g., NEF or UDM, determines that the first user identity is activated on the first UE.
[0208] In some embodiments, the first NEF receives the third activation request from the first UIAS, the third activation request including one or more of the following: the first terminal identity, the first user identity, the profile corresponding to the first user identity; the first NEF sends the sixth activation request, the sixth activation request including one or more of the following: the first AF identity, the first user identity, the profile corresponding to the first user identity and the first terminal identity, the sixth activation request being used to request creation of the first user profile and activation or deactivation of the first user identity from the first UE. After receiving the third activation request sent by the first UE, the first NEF sends the first terminal identity, the first user identity, the profile corresponding to the first user identity and the first AF identity as the sixth activation request, to indicate that when the sixth activation request is received, it is used to request creation of the first user profile and activation or deactivation of the first user identity from the first UE.
[0209] In some embodiments, the profile corresponding to the first user identity includes the first user identity, and when the profile corresponding to the first user identity includes the first user identity, the sixth activation request does not need to repeatedly carry the first user identity, so as to save transmission resources.
[0210] In some embodiments, the sixth activation request further includes a first user activation indication, the first user activation being used to indicate activation or deactivation of the first user identity. When the sixth activation request includes the first user activation indication, the first NEF indicates that the first user identity is activated on the first UE, so that the network device receiving the sixth activation request, e.g., NEF or UDM, determines that the first user identity is activated on the first UE.
[0211] In some embodiments: the first UDM receives a sixth activation request from the first NEF, wherein the sixth activation request includes one or more of the following: the first terminal identifier, the first user identifier, and the profile corresponding to the first user identifier; the first UDM creates a first user profile according to the profile corresponding to the first user identifier; and the first UDM activates or deactivates the first user identifier from the first UE based on the first terminal identifier, the first user identifier, and the first AF identifier.
[0212] In some examples, after the first UDM receives the sixth activation request sent by the first UIAS, the first UDM creates a first user profile according to the profile corresponding to the first user identifier carried in the sixth activation request, authenticates, activates, or deactivates the first user identifier or the first user according to the first terminal identifier and the first user identifier based on the first user profile, determines the mapping relationship between the first terminal identifier and the first user identifier, and marks the first UE as an activated state.
[0213] In some embodiments, the first UDM receives a third activation request from the first UIAS, wherein the third activation request includes one or more of the following: the first terminal identifier, the first user identifier, and the profile corresponding to the first user identifier; the first UDM creates a first user profile according to the profile corresponding to the first user identifier; and the first UDM activates or deactivates the first user identifier from the first UE based on the first terminal identifier and the first user identifier.
[0214] In some examples, after the first UDM receives the third activation request sent by the first UIAS, the first UDM processes the first information in the third activation request for indicating the first terminal identifier to obtain the first terminal identifier corresponding to the first information, then creates a first user profile according to the profile corresponding to the first user identifier carried in the third activation request, authenticates, activates, or deactivates the first user identifier or the first user according to the first terminal identifier and the first user identifier based on the first user profile, determines the mapping relationship between the first terminal identifier and the first user identifier, and marks the first UE as an activated state.
[0215] In some embodiments, the UE is activated with the User Identifier, and the UDM modifies the content in the UE subscription request response according to the Profile content corresponding to the User Identifier, noting that the subscription content of the UE has not changed. The UDM creates and activates the UE and the User Identifier according to the registration management state of the UE being RM-REGISTERED.
[0216] In some embodiments, the first UDM activates / deactivates the first user identity or the first user based on the first user activation indication; and / or, the first UDM activates the first user identity or the first user in a case where it is determined that the first UE is in a registered state. When the first user activation indication is carried in the first activation request, the second activation request, the third activation request, the fourth activation request, the fifth activation request or the sixth activation request, the first UDM can activate / deactivate the first user identity or the first user according to the first user activation indication, in addition, the first UDM can determine whether to activate the first user identity by obtaining the state information of the first UE, for example, when the first UE is in the RM REGISTERED state or the UE is registered with the network. The first UDM activates the first user identity.
[0217] In some embodiments, the UE determines the identity (GPSI, AF specific ID) of the UE corresponding to the UIAS according to the information of the UIAS triggered by the User;
[0218] In some examples, referring to Figure 10 , a detailed flowchart of another user authentication and activation method provided by the embodiments of the present application is shown, as shown in Figure 10 , the method can include:
[0219] S1001: Preconfigure the UIAS authentication server (APP or special device), and establish a secure session between the UE and the UIAS after the UE is networked.
[0220] S1002: The UE determines the terminal identity for the UIAS according to the user request to connect the UIAS, and the terminal identity includes GPSI, AF Specific ID, IP address, etc.
[0221] S1003: The UE and the UIAS pass the user authentication. The UIAS determines the GPSI, AF Specific ID, IP address, etc. of the UE to the UE.
[0222] S1004: The UIAS sends a user profile creation activation request (i.e. the third activation request in the foregoing embodiments) to the NEF. The user profile creation activation request includes GPSI (AF Specific ID, IP address), user identity, user profile, and optionally, the user profile creation activation request includes UE activation indication.
[0223] S1005: The NEF authorizes the UIAS server.
[0224] S1006: The NEF obtains the SUPI or GPSI of the UE corresponding to the IP address and port number according to the IP address and port number.
[0225] S1007: The NEF sends a user profile request (i.e., the sixth activation request in the foregoing embodiment) to the UDM, which can be an example of a Nudm_parameterProvision service request. The user profile request includes the AF identifier, the user identifier, and the user profile. Optionally, the user profile request includes a UE activation indication.
[0226] S1008: The UDM creates the user profile, and the UDM activates the user identifier together with the UE subscription to be in an active state, i.e., the User is in an active state (active state) for the UE.
[0227] In some examples, the UDM activating the UE includes: the UDM activating the user identifier according to the user activation indication; and the UDM activating the user identifier according to the state of the UE, which is an example of the UDM activating the user identifier when the UE is in an RM REGISTERED state, i.e., the UE is registered with the network.
[0228] S10081: The UDM requests subscription UE subscription data.
[0229] S10082: The UDM notifies the NF of the UE subscription data update.
[0230] It should be noted that the merged UE subscription data and User Profile parameters can be sent to the NF in the notification, and the NF can update the existing PDU session and apply it in a new PDU session in the future according to the activated / deactivated user profile to provide appropriate QoS control and / or policy and charging control. The UDM can overwrite the UE subscription data returned to the NF, such as: the UDM overwrites the UE subscription data according to the QoS control and / or policy in the User Profile. It can be understood that this overwrite only affects this subscription request, and the subscription information of the UE has not changed, and the modified content is limited to the subscription data in the subscription notification. The NF receiving the modified content is unaware of the existence of the User.
[0231] S1009: The UDM returns a creation success indication to the NEF, which can be optional: including an activation indication.
[0232] S1010: The NEF returns a creation success indication to the UIAS, which can be optional: including an activation indication. The UIAS determines that the User Identifier is activated for the UE.
[0233] In some embodiments, the UDM determines whether the User identifier can be activated according to the state of the UE. If the UE is in the RM-REGISTERED state, the User identifier is activated and an activation indication is returned.
[0234] Based on the same inventive concept as the foregoing embodiments, see Figure 11 which shows a constituent structure schematic diagram of a communication device provided by an embodiment of the present application. As shown in Figure 11 , in an example, the communication device can be used to implement any one of the user authentication and activation methods in the foregoing embodiments. Specifically, the communication device can include:
[0235] The transceiver 1101 is configured to acquire, by the first UIAS, first information corresponding to the first UE, the first information including an IP address and / or a port number and / or a MAC address, the first information being used to indicate the first UE.
[0236] The transceiver 1101 is further configured to send, by the first UIAS, a first activation request, the first activation request including the first user identifier and the first information, the first activation request being used to request to activate or deactivate the first user identifier of the first UE or the first user corresponding to the first user identifier.
[0237] In some embodiments, the transceiver 1101 is specifically configured to acquire, by the first UIAS, the first information of the first UE in a case where it is determined that the first UE meets a first preset condition.
[0238] In some embodiments, the first UE does not support an application identity authentication and key management (AKMA) mechanism, and / or the first UE is unable to determine a key identifier corresponding to the AKMA mechanism.
[0239] In some embodiments, the transceiver 1101 is specifically configured to receive, by the first UIAS, the first information from the first UE; and / or receive, by the first UIAS, a first data packet from the first UE, and determine the first information corresponding to the first UE according to the first data packet.
[0240] In some embodiments, the transceiver 1101 is specifically configured to send, by the first UIAS, a second activation request; the second activation request including a configuration file corresponding to the first user identifier, the first user identifier, and the first information; the second activation request being used to request to create the first user configuration file, and to activate or deactivate the first user identifier of the first UE or the first user.
[0241] In some embodiments, the second activation request includes a first user activation indication, the first user activation indication being used to indicate to activate or deactivate the first user identifier or the first user.
[0242] In some embodiments, the transceiver 1101 is specifically configured to receive, by the first UIAS, a first terminal identifier corresponding to the first UE, the first terminal identifier comprising an application function (AF) specific identifier and / or a generic public subscription identifier, the first terminal identifier being used to indicate the first UE; and send, by the first UIAS, a third activation request, the third activation request comprising the first terminal identifier, a first user identifier, and a profile corresponding to the first user identifier, the third activation request being used to request to create the first user profile and to activate or deactivate the first user identifier or the first user.
[0243] In some embodiments, the third activation request comprises a first user activation indication, the first user activation indication being used to indicate to activate or deactivate the first user identifier or the first user.
[0244] In some embodiments, the transceiver 1101 is specifically configured to obtain, by the first UE, first information corresponding to the first UE, the first information comprising an IP address and / or a port number and / or a MAC address; and send, by the first UE, the first information to the first UIAS, the first information being used to indicate the first UE in the activation request sent by the first UIAS.
[0245] In some embodiments, the transceiver 1101 is specifically configured to send, by the first UE, the first information to the first UIAS, when the first UE satisfies a first preset condition.
[0246] In some embodiments, the first UE does not support the AKMA mechanism, and / or the first UE is unable to determine a key identifier corresponding to the AKMA mechanism.
[0247] In some embodiments, the processing unit 1102 is specifically configured to determine and send, by the first UE, a first terminal identifier corresponding to the first UIAS according to the connected first UIAS, the first terminal identifier being used to indicate the first UE.
[0248] In some embodiments, the first terminal identifier comprises an application function (AF) specific identifier and / or a generic public subscription identifier.
[0249] In some embodiments, the transceiver 1101 is specifically configured to receive, by the first NEF, a first activation request from the first UIAS, the first activation request comprising a first user identifier and first information, the first information comprising an IP address and / or a port number and / or a MAC address; and the processing unit 1102 is specifically configured to determine, by the first NEF, a first terminal identifier corresponding to the first UE according to the first information, and send, by the first NEF, a fourth activation request, the fourth activation request comprising the first user identifier, the first terminal identifier, and a first AF identifier corresponding to the first UIAS, the fourth activation request being used to request to activate or deactivate the first user identifier or a first user corresponding to the first user identifier.
[0250] In some embodiments, the transceiver 1101 is specifically configured to receive, by the first NEF, a second activation request from the first UIAS, the second activation request comprising a first user identifier corresponding profile, the first user identifier, and first information; and the processing unit 1102 is specifically configured to determine, by the first NEF, a first terminal identifier of the first UE according to the first information, and send, by the first NEF, a fifth activation request, the fifth activation request comprising one or more of the following: the first AF identifier, the first user identifier, the first user identifier corresponding profile, and the first terminal identifier, the fifth activation request being used to request to create the first user profile, and to activate or deactivate the first user identifier or the first user of the first UE.
[0251] In some embodiments, the fifth activation request further comprises a first user activation indication, the first user activation indication being used to indicate to activate or deactivate the first user identifier or the first user.
[0252] In some embodiments, the transceiver 1101 is specifically configured to receive, by the first NEF, a third activation request from the first UIAS, the third activation request comprising the first terminal identifier, the first user identifier, and the first user identifier corresponding profile; and the first NEF sends a sixth activation request, the sixth activation request comprising one or more of the following: the first AF identifier, the first user identifier, the first user identifier corresponding profile, and the first terminal identifier, the sixth activation request being used to request to create the first user profile, and to activate or deactivate the first user identifier or the first user of the first UE.
[0253] In some embodiments, the sixth activation request further comprises a first user activation indication, the first user activation indication being used to indicate to activate or deactivate the first user identifier or the first user.
[0254] In some embodiments, the transceiver 1101 is specifically configured to receive, by the first UDM, a first activation request from the first UIAS, the first activation request comprising the first user identifier and first information, the first information comprising an IP address and / or a port number and / or a MAC address; and the processing unit 1102 is specifically configured to determine, by the first UDM, a first terminal identifier corresponding to the first UE according to the first information; and activate or deactivate, by the first UDM, the first user identifier or the first user of the first UE based on the first terminal identifier and the first user identifier.
[0255] In some embodiments, the transceiving unit 1101 is specifically configured to receive, by the first UDM, a second activation request from the first UIAS, the second activation request comprising a profile corresponding to a first user identifier, the first user identifier, and first information; and the processing unit 1102 is specifically configured to create, by the first UDM, a first user profile according to the profile corresponding to the first user identifier; determine, by the first UDM, a first terminal identifier corresponding to the first UE according to the first information; and activate or deactivate, by the first UDM, the first user identifier or the first user of the first UE based on the first terminal identifier and the first user identifier.
[0256] In some embodiments, the transceiving unit 1101 is specifically configured to receive, by the first UDM, a third activation request from the first UIAS, the third activation request comprising a first terminal identifier, a first user identifier, and a profile corresponding to the first user identifier; and the processing unit 1102 is specifically configured to create, by the first UDM, a first user profile according to the profile corresponding to the first user identifier; and activate or deactivate, by the first UDM, the first user identifier or the first user of the first UE based on the first terminal identifier and the first user identifier.
[0257] In some embodiments, the transceiving unit 1101 is specifically configured to receive, by the first UDM, a fourth activation request from the first NEF, the fourth activation request comprising a first user identifier, a first terminal identifier, and a first AF identifier corresponding to the first UIAS; and the processing unit 1102 is specifically configured to activate or deactivate, by the first UDM, the first user identifier or the first user of the first UE based on the first terminal identifier, the first user identifier, and the first AF identifier.
[0258] In some embodiments, the transceiving unit 1101 is specifically configured to receive, by the first UDM, a fifth activation request from the first NEF, the fifth activation request comprising a first AF identifier, a first user identifier, a profile corresponding to the first user identifier, and a first terminal identifier; and the processing unit 1102 is specifically configured to create, by the first UDM, a first user profile according to the profile corresponding to the first user identifier; and activate or deactivate, by the first UDM, the first user identifier or the first user of the first UE based on the first terminal identifier, the first user identifier, and the first AF identifier.
[0259] In some embodiments, the transceiving unit 1101 is specifically configured to receive, by the first UDM, a sixth activation request from the first NEF, the sixth activation request comprising a first terminal identifier, a first user identifier, and a profile corresponding to the first user identifier; and the processing unit 1102 is specifically configured to create, by the first UDM, a first user profile according to the profile corresponding to the first user identifier; and activate or deactivate, by the first UDM, the first user identifier or the first user of the first UE based on the first terminal identifier, the first user identifier, and the first AF identifier.
[0260] In some embodiments, the processing unit 1102 is specifically configured to activate or deactivate the first user identity or the first user based on the first user activation indication by the first UDM; and / or, activate or deactivate the first user identity or the first user by the first UDM in a case where it is determined that the first UE is in a registered state.
[0261] It can be understood that, in this embodiment, the "unit" can be a part of circuit, a part of processor, a part of program or software, etc., and of course can also be a module, and can also be non-modular. Moreover, each component in this embodiment can be integrated in a processing unit, or each unit can exist physically alone, or two or more units can be integrated in one unit. The integrated unit can be realized in the form of hardware or in the form of a software function module.
[0262] The integrated unit, if realized in the form of a software function module and not sold or used as an independent product, can be stored in a computer readable storage medium, based on such understanding, the technical solutions of the embodiment can be embodied in the form of a software product in essence or in the form of a software product that contributes to the prior art or the whole or part of the technical solutions. The computer software product is stored in a storage medium, and includes a plurality of instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) or a processor to execute all or part of the steps of the method provided by the embodiment. The foregoing storage medium includes: a U disk, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk, and various media that can store program codes.
[0263] Therefore, the embodiment provides a computer storage medium, which stores a paging program. When the paging program is executed by at least one processor, the steps of the method provided in any one of the foregoing embodiments are implemented.
[0264] Based on the composition of the communication device and the computer storage medium, refer to Figure 12 which shows a hardware structure schematic diagram of a communication device provided by an embodiment of the application. As Figure 12 indicated, it can include a processor 1201. Optionally, the communication device can also include a memory 1202 and / or a communication interface 1203. The various components are coupled together through a communication line 1204. It can be understood that the communication line 1204 is used to realize the connection and communication between the components. In addition to the data bus, the communication line 1204 also includes a power supply bus, a control bus and a state signal bus. However, for the purpose of clear illustration, only the data bus is shown in Figure 12The various buses are labeled as communication lines 1204.
[0265] The processor 1201 is configured to execute the following steps when running the computer program: the first UIAS acquires first information corresponding to the first UE, the first information comprising an IP address and / or a port number and / or a MAC address, the first information being used to indicate the first UE; the first UIAS sends a first activation request, the first activation request comprising a first user identifier and the first information, the first activation request being used to request to activate or deactivate the first user identifier of the first UE.
[0266] In some embodiments, the processor 1201 is configured to execute the steps of the method in any of the preceding embodiments when running the computer program.
[0267] The memory 1202 is configured to store the computer program capable of running on the processor 1201.
[0268] The communication interface 1203 is configured to receive and send signals in the process of transceiving information with other external network elements.
[0269] It is to be appreciated that the memory 1202 in embodiments of the application can be volatile, nonvolatile, or a combination of both. By way of example, the nonvolatile memory can be read-only memory (ROM), programmable ROM (PROM), erasable PROM (EPROM), electrically EPROM (EEPROM), or flash memory. The volatile memory can be random access memory (RAM), which acts as external cache. By way of example and not limitation, many forms of RAM are available, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), double-data rate SDRAM (DDR SDRAM), enhanced SDRAM (ESDRAM), SynchBurst DRAM (SLDRAM), and direct Rambus RAM (DRRAM). The memory 1202 of the subject systems and methods is intended to include, without being limited to, these and any other suitable types of memory.
[0270] The processor 1201 can be an integrated circuit chip including a processing unit that is configured to process signals. In implementation, the steps of the above-described method can be completed by the integrated logic circuit of the processor 1201 or by an instruction in a form of software. The processor 1201 described above can be a general-purpose processor, a Digital Signal Processor (DSP), an Application Specific Integrated Circuit (ASIC), a Field Programmable Gate Array (FPGA) or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components. The methods, steps and logical block diagrams disclosed in the embodiments of the present application can be implemented or executed by the processor. The general-purpose processor can be a microprocessor or the processor can also be any conventional processor. The steps of the methods disclosed in conjunction with the embodiments of the present application can be directly embodied as a hardware code executed by the processor, or a combination of hardware and software modules in the processor. The software module can be located in a storage medium such as random access memory (RAM), flash memory, read-only memory (ROM), programmable read-only memory (PROM), electrically programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), registers, or other mature storage media. The storage medium is located in the storage 1202, and the processor 1201 reads information in the storage 1202 and combines the hardware to complete the steps of the above-described method.
[0271] It can be understood that the embodiments described herein can be implemented in hardware, software, firmware, middleware, microcode, or a combination thereof. For hardware implementation, the processing units can be implemented within one or more application specific integrated circuits (ASICs), digital signal processors (DSPs), digital signal processing devices (DSPDs), programmable logic devices (PLDs), field programmable gate arrays (FPGAs), processors, controllers, micro-controllers, microprocessors, other electronic units designed to perform the functions described herein, or a combination thereof.
[0272] For software implementation, the techniques described herein can be implemented with modules (e.g., procedures, functions, and so on) that perform the functions described herein. The software codes can be stored in the memory and executed by the processor. The memory can be implemented within the processor or external to the processor.
[0273] Optionally, as another embodiment, the processor 1201 is further configured to execute the steps of the method in any of the preceding embodiments when running the computer program.
[0274] In some embodiments, based on the composition of the communication device described above, the embodiments of the present application provide a communication system, which can include the communication device in any of the preceding embodiments.
[0275] Optionally, the computer-executable instructions in the present application can also be referred to as application program codes, which are not specifically limited in the present application.
[0276] In a specific implementation, as an embodiment, the processor 1201 can include one or more CPUs, for example, CPU0 and CPU1 in Figure 12
[0277] It should be noted that, Figure 12 Only as an example of the communication device, and does not limit the specific structure of the communication device. For example, the communication device includes terminal equipment and network equipment, and the communication device can also include other functional modules.
[0278] The embodiments of the present application provide a computer program product containing instructions, which, when the computer program product runs on a computer, causes the computer to execute the method provided by any of the preceding embodiments.
[0279] The embodiments of the present application provide a chip system, which can include processing circuitry and a storage medium, and the storage medium stores computer program instructions; the computer program instructions are executed by the processing circuitry to implement the method provided by any of the preceding embodiments.
[0280] It should be noted that, in the present application, the term "comprise", "include" or any other variant thereof is intended to cover non-exclusive inclusion, so that a process, method, article or apparatus including a series of elements includes not only those elements, but also other elements not explicitly listed, or further includes elements inherent to such a process, method, article or apparatus. Without more limitations, the element defined by the statement "comprises a" does not exclude the presence of additional identical elements in the process, method, article or apparatus that includes the element.
[0281] The methods disclosed in the several method embodiments of the present application can be combined arbitrarily without conflict to obtain new method embodiments. The features disclosed in the several product embodiments of the present application can be combined arbitrarily without conflict to obtain new product embodiments. The features disclosed in the several method or device embodiments of the present application can be combined arbitrarily without conflict to obtain new method embodiments or device embodiments. The above is merely specific embodiments of the present application, but the protection scope of the present application is not limited thereto, and any person skilled in the art can easily think of changes or replacements within the technical range disclosed by the present application, which should be covered within the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.
Claims
1. A user authentication and activation method, characterized in that, The method includes: The first user identification application server (UIAS) obtains the first information corresponding to the first UE. The first information includes an IP address and / or a port number and / or a MAC address. The IP address and / or the port number and / or the MAC address are used to indicate the first UE. The first UE IAS sends a first activation request, which includes a first user identifier and the first information. The first activation request is used to request activation or deactivation of the first user identifier or the first user corresponding to the first user identifier in the first UE indicated by the first information.
2. The method according to claim 1, characterized in that, The first UE IAS obtains the first information corresponding to the first UE, including: If the first UE is determined to meet the first preset condition, the first UE IAS obtains the first information of the first UE.
3. The method according to claim 2, characterized in that, The first UE satisfies a first preset condition, including: The first UE does not support the application's authentication and key management AKMA mechanism, and / or the first UE cannot determine the key identifier corresponding to the AKMA mechanism.
4. The method according to any one of claims 1-3, characterized in that, The first UE IAS obtains the first information of the first UE, including: The first UE IAS receives the first information from the first UE; and / or, The first UE IAS receives a first data packet from the first UE and determines the first information corresponding to the first UE based on the first data packet.
5. The method according to claim 1, characterized in that, The method further includes: The first UE IAS sends a second activation request; the second activation request includes a configuration file corresponding to the first user identifier, the first user identifier, and the first information; the second activation request is used to request the creation of the first user configuration file, and to activate or deactivate the first user identifier or the first user from the first UE.
6. The method according to claim 5, characterized in that, The second activation request includes a first user activation indication, which indicates whether to activate or deactivate the first user identifier or the first user.
7. The method according to any one of claims 1-6, characterized in that, The method further includes: The first UE IAS receives the first terminal identifier from the first UE, the first terminal identifier including an application function AF specific identifier and / or a general public subscription identifier, the first terminal identifier being used to indicate the first UE; The first UE IAS sends a third activation request, which includes the first terminal identifier, the first user identifier, and the configuration file corresponding to the first user identifier. The third activation request is used to request the creation of a first user configuration file and to activate or deactivate the first user identifier or the first user from the first UE.
8. The method according to claim 7, characterized in that, The third activation request includes a first user activation indication, which is used to indicate whether to activate or deactivate the first user identifier or the first user.
9. A user authentication and activation method, characterized in that, The method includes: The first terminal device (UE) obtains the first information corresponding to the first UE, the first information including IP address and / or port number and / or MAC address; The first UE sends the first information to the first UIAS, and the IP address and / or the port number and / or the MAC address in the first information are used to instruct the first UE in the activation request sent by the first UIAS.
10. The method according to claim 9, characterized in that, Sending the first information to the first UIAS includes: When the first UE meets the first preset condition, the first UE sends the first information to the first UE IAS.
11. The method according to claim 10, characterized in that, The first UE satisfies a first preset condition, including: The first UE does not support the AKMA mechanism, and / or the first UE cannot determine the key identifier corresponding to the AKMA mechanism.
12. The method according to any one of claims 9-11, characterized in that, The method further includes: The first UE determines and sends a corresponding first terminal identifier based on the first UIAS it is connected to, and the first terminal identifier is used to indicate the first UE.
13. The method according to claim 12, characterized in that, The first terminal identifier includes an application function AF-specific identifier and / or a general public subscription identifier.
14. A user authentication and activation method, characterized in that, The method includes: The first Network Open Function (NEF) receives a first activation request from the first UIAS. The first activation request includes a first user identifier and the first information, which includes an IP address and / or a port number and / or a MAC address. The first NEF determines the first terminal identifier corresponding to the first UE based on the IP address and / or the port number and / or the MAC address; The first NEF sends a fourth activation request, which includes a first user identifier, a first terminal identifier, and a first AF identifier corresponding to the first UE. The fourth activation request is used to request activation or deactivation of the first user identifier or the first user corresponding to the first user identifier from the first UE.
15. The method according to claim 14, characterized in that, The method further includes: The first NEF receives a second activation request from the first UIAS, the second activation request including the configuration file corresponding to the first user identifier, the first user identifier, and the first information; The first NEF determines the first terminal identifier of the first UE based on the IP address and / or the port number and / or the MAC address; The first NEF sends a fifth activation request, which includes the first AF identifier, the first user identifier, the configuration file corresponding to the first user identifier, and the first terminal identifier. The fifth activation request is used to request the creation of a first user configuration file and to activate or deactivate the first user identifier or the first user from the first UE.
16. The method according to claim 15, characterized in that, The fifth activation request includes a first user activation indication, which is used to indicate the activation or deactivation of the first user identifier or the first user.
17. The method according to any one of claims 14-16, characterized in that, The method further includes: The first NEF receives a third activation request from the first UIAS, the third activation request including the first terminal identifier, the first user identifier, and the configuration file corresponding to the first user identifier; The first NEF sends a sixth activation request, which includes the first AF identifier, the first user identifier, the configuration file corresponding to the first user identifier, and the first terminal identifier. The sixth activation request is used to request the creation of a first user configuration file and to activate or deactivate the first user identifier or the first user from the first UE.
18. The method according to claim 17, characterized in that, The sixth activation request includes a first user activation indication, which indicates whether to activate or deactivate the first user identifier or the first user.
19. A user authentication and activation method, characterized in that, The method includes: The first unified data management function UDM receives a first activation request from the first U IAS. The first activation request includes a first user identifier and the first information, the first information including an IP address and / or a port number and / or a MAC address. The first UDM determines the first terminal identifier corresponding to the first UE based on the IP address and / or the port number and / or the MAC address; Based on the first terminal identifier and the first user identifier, the first UDM activates or deactivates the first user identifier of the first UE or the first user corresponding to the first user identifier.
20. The method according to claim 19, characterized in that, The method further includes: The first UDM receives a second activation request from the first UIAS, the second activation request including the configuration file corresponding to the first user identifier, the first user identifier, and the first information; The first UDM creates a first user profile based on the profile corresponding to the first user identifier; The first UDM determines the first terminal identifier corresponding to the first UE based on the IP address and / or the port number and / or the MAC address; Based on the first terminal identifier and the first user identifier, the first UDM activates or deactivates the first user identifier or the first user of the first UE.
21. The method according to claim 19, characterized in that, The method further includes: The first UDM receives a third activation request from the first U IAS, the third activation request including the first terminal identifier, the first user identifier, and the configuration file corresponding to the first user identifier; The first UDM creates a first user profile based on the profile corresponding to the first user identifier; Based on the first terminal identifier and the first user identifier, the first UDM activates or deactivates the first user identifier or the first user of the first UE.
22. The method according to claim 20, characterized in that, The method further includes: The first UDM receives a fourth activation request from the first NEF, the fourth activation request including a first user identifier, a first terminal identifier, and a first AF identifier corresponding to the first UIAS; Based on the first terminal identifier, the first user identifier, and the first AF identifier, the first UDM activates or deactivates the first user identifier or the first user from the first UE.
23. The method according to claim 20, characterized in that, The method further includes: The first UDM receives a fifth activation request from the first NEF, the fifth activation request including the first AF identifier, the first user identifier, the configuration file corresponding to the first user identifier, and the first terminal identifier; The first UDM creates a first user profile based on the profile corresponding to the first user identifier; Based on the first terminal identifier, the first user identifier, and the first AF identifier, the first UDM activates or deactivates the first user identifier or the first user of the first UE.
24. The method according to claim 20, characterized in that, The method further includes: The first UDM receives a sixth activation request from the first NEF, the sixth activation request including the first terminal identifier, the first user identifier, and the configuration file corresponding to the first user identifier; The first UDM creates a first user profile based on the profile corresponding to the first user identifier; Based on the first terminal identifier, the first user identifier, and the first AF identifier, the first UDM activates or deactivates the first user identifier or the first user of the first UE.
25. The method according to any one of claims 19-24, characterized in that, The first UDM activates or deactivates the first user identifier or the first user of the first UE, including: The first UDM activates or deactivates the first user identifier or the first user based on the first user activation indication; and / or, When the first UDM determines that the first UE is in a registered state, it activates or deactivates the first user identifier or the first user.
26. A communication device, characterized in that, The communication device includes a unit or module for performing the method as described in any one of claims 1-8, 9-13, 14-18, or 19-25.
27. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer program instructions that, when executed by a processing circuit, implement the method as described in any one of claims 1-8, 9-13, 14-18, or 19-25.
28. A computer program product containing instructions, characterized in that, When the computer program product is run on a computer, the method as described in any one of claims 1-8, 9-13, 14-18, or 19-25 is implemented.
29. A communication device, characterized in that, include: A processor coupled to a memory for storing a program or instructions that, when executed by the processor, cause the apparatus to perform the method as claimed in any one of claims 1 to 8, or the method as claimed in any one of claims 9 to 13, or the method as claimed in any one of claims 14 to 18, or the method as claimed in any one of claims 19 to 25.