Authentication processing method and device for avoiding resynchronization and authentication equipment
By configuring a quadruple index field during the 4G to 5G handover process, the HSS sequence number and the number of authentication vectors used are obtained, and the expected sequence number is determined. This solves the resynchronization problem during the 4G to 5G handover, and improves the authentication success rate and user service continuity.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- ASIAINFO TECH CHINA INC
- Filing Date
- 2026-03-05
- Publication Date
- 2026-05-01
AI Technical Summary
During the 4G to 5G transition, the inconsistent number of authentication vectors issued by HSS and UDM can easily trigger unnecessary resynchronization mechanisms, leading to authentication failure.
When switching from 4G to 5G, the 4G HSS sequence number and the number of authentication vectors used are obtained by configuring a quadruple index field in the relevant communication interface, the expected sequence number is determined, and authentication matching is performed based on the sequence number.
Significantly reduces the risk of authentication failure caused by serial number misalignment, and improves the authentication success rate and user business continuity in cross-generational switching scenarios.
Smart Images

Figure CN121968102A_ABST
Abstract
Description
An authentication processing method, apparatus, and authentication device to avoid resynchronization Technical Field
[0001] This application relates to the field of communication technology, and in particular to an authentication processing method, apparatus and authentication equipment that avoids resynchronization. Background Technology
[0002] In the core network of 4G / 5G, when a user equipment (UE) registers, the network side triggers an authentication process for the UE. This authentication process relies on the Sequence Number (SQN), which is jointly maintained by the Home Subscriber Server (HSS) of 4G, the Unified Data Management (UDM) of 5G, and the UE's USIM (Universal Subscriber Identity Module) card.
[0003] The HSS / UDM maintains an independent SQN value for each user. Upon receiving an authentication request, the HSS / UDM generates a new set of authentication vectors (AVs) based on the current SQN, incrementing the SQN. The USIM card then synchronizes its stored SQN value (SQN_UE) with the network's SQN value (SQN_network). However, when the UE receives an authentication challenge containing SQN_network, if SQN_network equals SQN_UE, authentication is successful, and SQN_UE is updated to SQN_network. If SQN_network does not equal SQN_UE, the USIM card determines a desynchronization, rejects authentication, and triggers a resynchronization mechanism. In particular, because the number of authentication vectors issued by the HSS and the UDM each time may differ, unnecessary resynchronization mechanisms can be easily triggered during the 4G to 5G handover process. Summary of the Invention
[0004] In view of this, this application provides an authentication processing method, apparatus and authentication device to avoid resynchronization, aiming to reduce resynchronization during the 4G to 5G handover process.
[0005] Firstly, this application provides an authentication processing method to avoid resynchronization, comprising: In response to a registration request sent by a User Equipment (UE), if the UE is from 4G, the AMF obtains a quadruple index field from the Mobility Management Entity (MME) of the 4G network. The quadruple index field indicates the number of authentication vectors used in the last batch of authentication vectors issued. The AMF sends a request message carrying the quadruple index field to the Authentication Server Function (AUSF) to obtain a predicted sequence number and its corresponding new authentication vector determined by the ASF through the Unified Data Management (UDM) of the 5G network. The predicted sequence number is a sequence number determined based on the quadruple index field and the Home Subscriber Server (HSS) sequence number, which is the sequence number corresponding to the last batch of authentication vectors issued by the 4G Home Subscriber Server (HSS) for the UE. The AMF sends an authentication request to the UE, carrying the predicted sequence number and its corresponding new authentication vector, so that the UE determines the authentication result based on the predicted sequence number and the local sequence number.
[0006] Optionally, the AUSF determines the expected sequence number through the 5G Unified Data Management (UDM), including: the UDM responding to the authentication request message sent by the AUSF; if the authentication request message contains the quadruple index field, it is determined that a 4G handover has occurred and the quadruple index field is available; the UDM obtains the HSS sequence number from the HSS; and determines the expected sequence number based on the quadruple index field, the HSS sequence number, and the total number of authentication vectors issued by the HSS for the last batch of UEs.
[0007] Optionally, before step S101, the method further includes: configuring a quadruple index field in the messages transmitted by each communication interface; the communication interface includes the communication interface that participates in authentication when switching from 4G to 5G.
[0008] Optionally, the communication interface includes a first interface connecting the AMF and the MME, a second interface connecting the AMF and the AUSF, and a third interface connecting the AUSF and the UDM.
[0009] Optionally, configuring a four-tuple index field in the messages transmitted by each communication interface includes: configuring a four-tuple index field in the EPS security context and four-tuple structure of the context response of the first interface, configuring a four-tuple index field in the authentication information structure of the request message of the second interface, and configuring a four-tuple index field in the authentication request structure of the authentication request message of the third interface.
[0010] Optionally, in the second and third interfaces, the existence configuration of the quadruple index field is optional and the number of occurrences is constrained to once; the method further includes: in the case of 4G to 5G switching, displaying the quadruple index field once in the request message sent to AUSF through the second interface and the authentication request message sent to the UDM through the third interface.
[0011] Optionally, determining the expected sequence number based on the quadruple index field, the HSS sequence number, and the total number of authentication vectors issued by the HSS to the UE in the last batch includes: determining the difference between the total number and the value of the quadruple index field; and subtracting the difference from the HSS sequence number to obtain the expected sequence number.
[0012] Optionally, the method for determining the total number of authentication vectors issued by the HSS for the UE in the last batch includes: the UDM obtaining the total number of authentication vectors issued by the HSS for the UE in the last batch, or determining the total number of authentication vectors issued by the HSS for the UE in the last batch according to the default batch size configured by the operator.
[0013] Secondly, this application provides an authentication processing apparatus to avoid resynchronization, comprising: an acquisition unit, configured to, in response to a registration request sent by a User Equipment (UE), in the case that the UE is from 4G, the AMF acquires a quadruple index field from the Mobility Management Entity (MME) of the 4G, the quadruple index field being used to indicate the number of authentication vectors used in the last batch of authentication vectors issued; a processing unit, configured to, send a request message carrying the quadruple index field to an Authentication Server Function (AUSF), to obtain an expected sequence number and its corresponding new authentication vector determined by the ASF through the Unified Data Management (UDM) of 5G, the expected sequence number being a sequence number determined based on the quadruple index field and the HSS sequence number, the HSS sequence number being the sequence number corresponding to the last batch of authentication vectors issued by the Home Subscriber Server (HSS) of 4G for the UE; and an analysis unit, configured to, send an authentication request to the UE, the authentication request carrying the expected sequence number and its corresponding new authentication vector, so that the UE determines the authentication result based on the expected sequence number and the local sequence number.
[0014] Thirdly, this application provides an authentication device that employs an authentication processing method to avoid resynchronization as described in any of the above-mentioned methods.
[0015] This application provides an authentication processing method, apparatus, and authentication device to avoid resynchronization. In this method, the Access and Mobility Management Function (AMF) responds to a registration request sent by a User Equipment (UE). If the UE is from 4G, the AMF obtains a quad-tuple index field from the 4G Mobility Management Entity (MME). This quad-tuple index field indicates the number of authentication vectors used in the last batch of authentication vectors issued. The AMF sends a request message carrying the quad-tuple index field to the Authentication Server Function (AUSF) to obtain the expected sequence number and its corresponding new authentication vector determined by the ASF through the 5G Unified Data Management (UDM). The expected sequence number is a sequence number determined based on the quad-tuple index field and the Home Subscriber Server (HSS) sequence number, which is the sequence number corresponding to the last batch of authentication vectors issued by the 4G Home Subscriber Server (HSS) for the UE. The AMF sends an authentication request to the UE, carrying the expected sequence number and its corresponding new authentication vector, so that the UE determines the authentication result based on the expected sequence number and its local sequence number. In this way, during the 4G to 5G transition, there may be unused authentication vectors in the last batch of authentication vectors issued by the 4G HSS. Therefore, the number of authentication vectors actually used in the last batch of authentication vectors is determined based on the index field of this quadruple, and the expected sequence number on the network side is determined. Authentication is then matched with the sequence number on the user equipment side based on this expected sequence number. This significantly reduces the risk of authentication failure caused by sequence number misalignment and significantly improves the authentication success rate and user service continuity in cross-generational handover scenarios. Attached Figure Description
[0016] To more clearly illustrate the technical solutions in this embodiment or the prior art, the drawings used in the description of the embodiment or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0017] Figure 1 is a flowchart illustrating an authentication processing method to avoid resynchronization provided in an embodiment of this application; Figure 2 is a flowchart illustrating an authentication process during the 4G to 5G handover provided in an embodiment of this application; Figure 3 is a structural diagram illustrating an authentication processing device to avoid resynchronization provided in an embodiment of this application. Detailed Implementation
[0018] Based on the above statements, in the mechanism where the USIM card determines a synchronization failure, refuses authentication, and triggers a resynchronization if SQN_network is not equal to SQN_UE, the specific resynchronization process can be as follows: First, after the UE detects a synchronization failure with the network's SQN, it generates a resynchronization token (Authentication Token from Subscriber, AUTS) and sends it to the serving network (HSS / UDM). Then, the HSS / UDM uses a key to parse the AUTS, infers SQN_UE, and adjusts its own SQN to SQN_UE, completing the synchronization. Finally, an authentication vector based on the new SQN is generated, and the serving network re-initiates authentication.
[0019] According to 3GPP protocols, 4G HSS typically distributes a group (1-5) of authentication vectors in batches to the Mobility Management Entity (MME) for caching. 5G UDM typically distributes only one authentication vector at a time. The applicant noted that during the 4G to 5G handover process, the MME transmits the authentication vector group to the AMF via the N26 interface. However, the N26 interface definition does not include information about the number of AVs already used by the MME. Since the number of used authentication vectors is uncertain, the 5G UDM (through the HSS) uses the UE's SQN value to determine the SQN corresponding to the final authentication vector generated by the HSS (this may be higher than the UE's current SQN_UE, because some AVs are cached by the MME and not yet distributed). When the AMF performs an authentication challenge on the UE based on the newly distributed SQN from the UDM, the UE finds that SQN_network is much larger than SQN_UE, exceeding the acceptance window, thus inevitably triggering an unnecessary resynchronization process. Therefore, in response to the problem that in the 4G to 5G network handover scenario, the incomplete authentication vector group information transmitted by the N26 interface (lacking consumed AV counts) leads to a mismatch between the SQN used by the UDM and the SQN value of the UE during subsequent 5G network authentication, thus triggering an unnecessary SQN resynchronization process, the applicant proposes a method to avoid resynchronization during the 4G to 5G network handover.
[0020] This application configures a four-tuple index field in the messages transmitted through the relevant communication interfaces for authentication. Before generating a new authentication vector in 5G AUSF, since there may be cases where the last batch of authentication vectors issued by 4G HSS is not fully used, the number of authentication vectors actually used in the last batch of authentication vectors is determined based on the four-tuple index field. This determines the expected sequence number on the network side, and then the authentication matching is performed based on the expected sequence number and the sequence number on the user equipment side. This significantly reduces the risk of authentication failure caused by sequence number misalignment and significantly improves the authentication success rate and user service continuity in cross-generation handover scenarios.
[0021] To provide a more detailed understanding of the features and technical content of the embodiments of this disclosure, the implementation of the embodiments of this disclosure will be described in detail below with reference to the accompanying drawings. The accompanying drawings are for illustrative purposes only and are not intended to limit the embodiments of this disclosure. In the following technical description, for ease of explanation, several details are used to provide a full understanding of the disclosed embodiments. However, one or more embodiments may still be implemented without these details. In other cases, well-known structures and devices may be simplified in their depiction to simplify the drawings.
[0022] The terms "first," "second," etc., used in the specification, claims, and accompanying drawings of this disclosure are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate for the embodiments of this disclosure described herein. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover non-exclusive inclusion.
[0023] Unless otherwise stated, the term "multiple" means two or more.
[0024] In this embodiment of the disclosure, the character " / " indicates that the objects before and after it are in an "or" relationship. For example, A / B means: A or B.
[0025] The term "and / or" describes an association between objects, indicating that three relationships can exist. For example, A and / or B means: A or B, or A and B.
[0026] To make the objectives, technical solutions, and advantages of the embodiments of this application clearer, the technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, and not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those of ordinary skill in the art without creative effort are within the scope of protection of this application.
[0027] Referring to Figure 1, Figure 1 is a flowchart of an authentication processing method to avoid resynchronization provided in an embodiment of this application, including: S101, the Access and Mobility Management Function (AMF) responds to a registration request sent by the User Equipment (UE). In the case that the UE is from 4G, the AMF obtains a quad tuple index field from the MME. The quad tuple index field is used to indicate the number of authentication vectors used in the last batch of authentication vectors issued.
[0028] 4G: 4th Generation Mobile Communication Technology.
[0029] UE: User Equipment.
[0030] AMF: Access and Mobility Management Function.
[0031] MME: Mobility Management Entity.
[0032] The aforementioned 5G Access and Mobility Management Function (AMF) is an evolution and functional splitting product of the 4G Mobility Management Entity (MME). It inherits the core mobility and access control capabilities, while separating authentication and other functions into independent network elements such as AUSF according to the 5G Service Architecture (SBA).
[0033] In addition, before step S101 or after step S101 in response to sending a registration request, it is determined that there is a first interface support connection between the AMF and the Mobility Management Entity (MME), and then bidirectional communication between the AMF and the MME is established through the first interface.
[0034] S102, the AMF sends a request message carrying the quadruple index field to the authentication server function AFS to obtain the expected sequence number and its corresponding new authentication vector determined by the AFS through the 5G unified data management UDM. The expected sequence number is a sequence number determined based on the quadruple index field and the HSS sequence number (denoted as SQN_HSS). The HSS sequence number is the sequence number corresponding to the last batch of authentication vectors issued by the 4G Home Subscriber Server (HSS) to the UE.
[0035] 5G: 5th Generation Mobile Communication Technology.
[0036] AUSF: Authentication Server Function.
[0037] SQN: Sequence Number.
[0038] UDM: Unified Data Management, the unified data management system for 5G.
[0039] HSS: Home Subscriber Server, the 4G home subscriber server.
[0040] AV: Authentication Vector.
[0041] S103, AMF sends an authentication request to the UE, the authentication request carrying the expected sequence number and its corresponding new authentication vector, so that the UE can determine the authentication result based on the expected sequence number and the local sequence number.
[0042] In one example, the UE verifies that SQN_network (SQN_UE_expected) is consistent with the local SQN_UE and is within an acceptable window, thus authentication is successful and no resynchronization is triggered.
[0043] Based on the above steps S101-S103, this application achieves smooth coordination of the core network authentication mechanism during the 4G to 5G handover process. Specifically, this application improves the success rate of cross-generation handover by significantly reducing the authentication failure rate caused by sequence number mismatch.
[0044] Based on the above embodiments, prior to step S101, the above-mentioned authentication processing method for avoiding resynchronization further includes: configuring a quadruple index field in the messages transmitted by each communication interface; the communication interface is the communication interface for implementing authentication when switching from 4G to 5G, and the quadruple index field is used to indicate the number of authentication vectors used in the last batch of authentication vectors issued by the UE to the 4G Home Subscriber Server (HSS).
[0045] In one possible implementation, the communication interface may include a first interface connecting the 5G Access and Mobility Management Function (AMF) to the 4G Mobility Management Entity (MME), a second interface connecting the AMF to the Authentication Server Function (AUSF), and a third interface connecting the ASF to the UDM.
[0046] In one example, the first interface can be the N26 interface connecting the 5G Access and Mobility Management Function (AMF) and the 4G Mobility Management Entity (MME), as shown in Figure 2, to achieve cross-generational state synchronization and security context interoperability between the AMF and MME for 5G and 4G.
[0047] In one example, the second interface is the N12 interface that connects the AMF and the Authentication Server Function (AUSF). It can be understood that the AMF is used for UE access and process initiation, while the ASF acts as the authentication execution and key management party, and completes UE access authentication, security context establishment and key derivation through the N12 interface.
[0048] In one example, the third interface is the N13 interface connecting the AUSF and the 5G UDM. When user authentication is required, the AUSF sends a request to the UDM via N13 to obtain the corresponding UE authentication credentials and related information.
[0049] In one possible implementation, configuring the quadruple index field in the messages transmitted by each communication interface includes: configuring the quadruple index field in the EPS security context and quadruple structure of the context response of the first interface, configuring the quadruple index field in the authentication information structure of the request message of the second interface, and configuring the quadruple index field in the authentication request structure of the request message of the third interface.
[0050] Before generating a new authentication vector, 5G's AUSF (Authenticating Authentication Service) addresses the issue that some authentication vectors were not fully used in the last batch issued by the 4G HSS (Hyper-Security Service). Therefore, it uses the quadruple index field to determine the number of authentication vectors actually used in the last batch, thereby determining the expected sequence number on the network side. Authentication is then matched with the sequence number on the user equipment side based on this expected sequence number, significantly reducing the risk of authentication failure caused by sequence number misalignment and significantly improving the authentication success rate and user service continuity in cross-generation handover scenarios.
[0051] The EPS mentioned above stands for Evolved Packet System.
[0052] In one example, the EPS SecurityContext and Quadruplets structure of the context response MM Context passed by the first interface above is supplemented with a quadrupletsIndex field, as shown in Table 1. The name of the quadruplets index field is Index of Quintuplets.
[0053] Table 1
[0054] In one example, a `quadrupletsIndex` field is added to the `AuthenticationInfo` structure (authentication information structure) of the service-oriented resource request message provided to AUSF in the second interface (N12 interface) mentioned above, identified by the URI `{apiRoot} / nausf-auth / v1 / ue-authentications`. As shown in Table 2, the configuration in Table 2 includes: attribute name `quadrupletsIndex` (quadruplet index), data type `string`, presence (P) `O` (Optional, indicating that this field can be selected to appear or omitted in the message as needed), cardinality (the number of occurrences constraint) `1` (configured according to actual needs; here, 1 means it appears at most once), and description `Contains index of quadruplets` (contains the index value of the quadruplets).
[0055] Therefore, in the second and third interfaces, the existence configuration of the quadruple index field is optional and the number of occurrences is constrained to once; the above method also includes: in the case of 4G to 5G switching, displaying the quadruple index field once in the request message sent by the second interface to AUSF and the authentication request message sent by the third interface to the UDM.
[0056] Table 2
[0057] In one example, the quadrupletsIndex field is added to the AuthenticationInfoRequest structure (authentication request structure) of the service resource provided by UDM in the N13 interface, identified by the URI {apiRoot} / nudm-ueau / v1 / {supiOrSuci} / security-information, as shown in Table 3. The configuration content is the same as that in Table 2 above.
[0058] Table 3
[0059] Furthermore, in the UDM, the process of calculating the expected sequence number can be as follows: After receiving the authentication request message through the third interface, the UDM determines whether the quadrupletsIndex field (quadruplet index field) exists based on the authentication request structure in the authentication request message. If it exists, it indicates that the UE has switched from 4G and the information is available. Then, the UDM requests the corresponding UE's authentication data (HSS sequence number) from the HSS. The SQN obtained by the UDM from the HSS reflects the SQN corresponding to the AV finally generated by the HSS, and can be denoted as SQN_HSS.
[0060] Furthermore, the UDM can calculate the expected sequence number SQN_UE_expected = SQN_HSS - (Total_AVs_Sent - N_used) based on the value of the quadrupletsIndex field (denoted as N_used, indicating the number of authentication vectors used in the last batch of authentication vectors issued before handover). Here, Total_AVs_Sent is the total number of AVs issued to the MME in the last batch by the HSS before handover (this information can be provided by the HSS in the response, or preset by the UDM based on the default batch size configured by the known operator). Thus, the UDM generates a new 5G authentication vector (5G HE AV) based on the expected sequence number SQN_UE_expected (not SQN_HSS), and then responds to the AUSF with the generated new authentication parameters, which include the expected sequence number and its corresponding newly generated 5G authentication vector.
[0061] Based on the above statements, referring to Figure 2, which shows a schematic diagram of the authentication process during the 4G to 5G handover, the authentication process of this application during the 4G to 5G handover can be as follows: Step A1, the UE initiates a registration request to the AMF. Specifically, the UE initiates initial registration under the 5G network, and the registration request message is sent to the AMF through the gNB (gNodeB, next-generation base station), carrying the mapped 5G-GUTI (derived from 4G-GUTI).
[0062] The aforementioned 5G-GUTI stands for 5G Globally Unique Temporary Identifier.
[0063] Step A2: If the AMF determines that the UE is from 4G and there is a first interface supporting the connection between the AMF and the MME, the AMF sends a context request to the MME.
[0064] The first interface mentioned above is the interface for connecting the AMF and MME, and it can be N26.
[0065] Step A2 above is to prepare for the switch from 4G to 5G, carrying the aforementioned GUTI.
[0066] Step A3: After receiving the context request, the MME verifies the parameter information in the context request and returns a context response to the AMF.
[0067] The Mobility Management Context (MMContext) carried in this context response includes the EPS Security Context and Quadruplets, as well as the newly added quadrupletsIndex field, International Mobile Subscriber Identity (IMSI), etc.
[0068] Step A4: AMF initiates the authentication process. AMF sends a request message to AUSF through the N12 interface, requesting authentication resources ({apiRoot} / nausf-auth / v1 / ue-authentications). The request includes the quadrupletsIndex field information obtained from MME (through private extensions or newly defined parameters via the N12 interface).
[0069] Step A5: AUSF sends a request message to UDM, requesting security information ({apiRoot} / nudm-ueau / v1 / {supi} / security-information), and carries the quadrupletsIndex field information in the AuthenticationInfoRequest structure.
[0070] Step A6: UDM requests authentication data from HSS ({apiRoot} / nhss-ueau / ) <apiversion>( / generate-av) retrieves the SQN corresponding to the authentication vector AV generated in the last batch of the aforementioned UEs from the HSS. This SQN can be denoted as SQN_HSS. Based on this SQN_HSS, SQN_UE_expected is calculated using the value of the quadrupletsIndex field.
[0071] The specific calculation method is as follows: SQN_UE_expected = SQN_HSS - (Total_AVs_Sent - N_used). Where Total_AVs_Sent is the number of authentication vectors used in the last batch of authentication vectors issued to the UE by the HSS. N_used is the value of the quadrupletsIndex field (indicating the number of authentication vectors used in the last batch issued to the UE by the HSS); Total_AVs_Sent is the total number of AVs issued to the MME by the HSS in the last batch before handover (this information can be provided by the HSS in the response, or preset by the UDM based on the known default batch size configured by the operator).
[0072] Step A7: HSS replies to UDM with a response message, which carries the authentication vector information that has been generated for UE.
[0073] Step A8: UDM generates 5G HE AV and sends a response to AUSF.
[0074] Step A9: AUSF processes and replies with a response to AMF.
[0075] Step A10: The AMF sends an Authentication Request to the UE, carrying new authentication parameters generated based on SQN_UE_expected.
[0076] Step A11: The UE verifies that SQN_network (SQN_UE_expected) is consistent with the local SQN_UE and within the acceptable window. Authentication is successful, no resynchronization is triggered, and the UE updates its SQN_UE.
[0077] Based on the foregoing, this application proposes that when a UE switches from a 4G network to a 5G network, in step A3 above, the MME feeds back the value N_used of the quadrupletsIndex field to the AMF to determine the number of authentication vectors already used in the last batch of authentication vectors issued before the switch. Furthermore, the AMF can pass this field information to the AFS and UDM in subsequent UE authentication processes. This ensures that the UDM can obtain the UE's current sequence number information when calculating authentication vectors for the UE, further ensuring the consistency of sequence numbers between the network side (UDM / HSS) and the UE side, thereby avoiding the UE initiating a resynchronization process later.
[0078] The above describes some specific implementations of an authentication processing method to avoid resynchronization, as provided in this application. Based on this, this application also provides a corresponding apparatus. The apparatus provided in this application will be described below from the perspective of functional modularity.
[0079] Referring to Figure 3, a schematic diagram of an authentication processing device for avoiding resynchronization is shown. The device includes: an acquisition unit 301, used by the Access and Mobility Management Function (AMF) in response to a registration request sent by a User Equipment (UE). If the UE is from 4G, the AMF acquires a quadruple index field from the Mobility Management Entity (MME) of the 4G network. This quadruple index field indicates the number of authentication vectors already used in the last batch of issued authentication vectors. A processing unit 302 is used by the AMF to send a request message carrying the quadruple index field to the Authentication Server Function (AUSF) to obtain the expected sequence number and its corresponding new authentication vector determined by the ASF through the Unified Data Management (UDM) of 5G. The expected sequence number is a sequence number determined based on the quadruple index field and the Home Subscriber Server (HSS) sequence number, where the HSS sequence number is the 4G Home Subscriber Server (HSS). The sequence number is the last batch of authentication vectors issued to the UE; the analysis unit 303 is used for the AMF to send an authentication request to the UE, the authentication request carrying the expected sequence number and its corresponding new authentication vector, so that the UE can determine the authentication result based on the expected sequence number and the local sequence number.
[0080] According to the above-mentioned device, when switching from 4G to 5G, there may be cases where the authentication vectors in the last batch of authentication vectors issued by the 4G HSS are not fully used. Therefore, the number of authentication vectors actually used in the last batch of authentication vectors is determined based on the quadruple index field, and the expected sequence number on the network side is determined. Then, authentication matching is performed based on the expected sequence number and the sequence number on the user equipment side. This greatly reduces the risk of authentication failure caused by sequence number misalignment and significantly improves the authentication success rate and user service continuity in cross-generation switching scenarios.
[0081] In one possible implementation, the processing unit is specifically configured to: respond to the authentication request message sent by the AUSF; if the authentication request message contains the quadruple index field, determine that a 4G handover has occurred and the quadruple index field is available; the UDM obtains the HSS sequence number from the HSS; and determine the expected sequence number based on the quadruple index field, the HSS sequence number, and the total number of authentication vectors issued by the HSS to the UE in the last batch.
[0082] Optionally, the processing unit is specifically used to determine the difference between the total quantity and the value of the quadruple index field; and to subtract the difference from the HSS sequence number to obtain the expected sequence number.
[0083] Optionally, the UDM obtains the total number of authentication vectors issued to the UE in the last batch from the HSS, or determines the total number of authentication vectors issued to the UE in the last batch by the HSS based on the default batch size configured by the operator.
[0084] In one possible implementation, the apparatus further includes a configuration unit; the configuration unit is configured to configure a quadruple index field in the messages transmitted by each communication interface; the communication interface includes a communication interface that participates in authentication when switching from 4G to 5G.
[0085] Optionally, the communication interface includes a first interface connecting the AMF and the MME, a second interface connecting the AMF and the AUSF, and a third interface connecting the AUSF and the UDM.
[0086] Optionally, the configuration unit is specifically configured to configure a quadruple index field in the EPS security context and quadruple structure of the context response of the first interface, configure a quadruple index field in the authentication information structure of the request message of the second interface, and configure a quadruple index field in the authentication request structure of the authentication request message of the third interface.
[0087] In one possible implementation, the existence configuration of the quadruple index field in the second and third interfaces is optional and the occurrence count is constrained to once; the processing unit is further configured to display the quadruple index field once in each of the request messages sent to AUSF through the second interface and the authentication request messages sent to the UDM through the third interface when switching from 4G to 5G.
[0088] This application also provides a corresponding authentication device for implementing the solution provided in this application.
[0089] The device executes an authentication processing method for avoiding resynchronization as described in any embodiment of this application.
[0090] In the embodiments of this application, the terms "first" and "second" (if they exist) are used only as name identifiers and do not represent the order of first and second.
[0091] As can be seen from the above description of the embodiments, those skilled in the art can clearly understand that all or part of the steps in the methods of the above embodiments can be implemented by means of software plus a general-purpose hardware platform. Based on this understanding, the technical solution of this application can be embodied in the form of a software product. This computer software product can be stored in a storage medium, such as a read-only memory (ROM) / RAM, magnetic disk, optical disk, etc., including several instructions to cause a computer device (which may be a personal computer, a server, or a network communication device such as a router) to execute the methods described in various embodiments or some parts of the embodiments of this application.
[0092] The various embodiments in this specification are described in a progressive manner. Similar or identical parts between embodiments can be referred to mutually. Each embodiment focuses on its differences from other embodiments. In particular, the apparatus embodiments are basically similar to the method embodiments, so the description is relatively simple; relevant parts can be referred to the descriptions in the method embodiments. Some or all of the modules can be selected to achieve the purpose of this embodiment according to actual needs. Those skilled in the art can understand and implement this without creative effort.
[0093] The above description is merely an exemplary implementation of this application and is not intended to limit the scope of protection of this application.< / apiversion>
Claims
1. An authentication processing method to avoid resynchronization, characterized in that, include: In response to a registration request sent by a User Equipment (UE), if the UE is from 4G, the Access and Mobility Management Function (AMF) obtains a quad-tuple index field from the 4G Mobility Management Entity (MME). This quad-tuple index field indicates the number of authentication vectors used in the last batch of authentication vectors issued. The AMF then sends a request message carrying the quad-tuple index field to the Authentication Server Function (AUSF) to obtain the expected sequence number and its corresponding new authentication vector determined by the ASF through the 5G Unified Data Management (UDM). The expected sequence number is a sequence number determined based on the quad-tuple index field and the Home Subscriber Server (HSS) sequence number, which is the sequence number corresponding to the last batch of authentication vectors issued to the UE by the 4G Home Subscriber Server (HSS). Finally, the AMF sends an authentication request to the UE, carrying the expected sequence number and its corresponding new authentication vector, so that the UE can determine the authentication result based on the expected sequence number and the local sequence number.
2. The method according to claim 1, characterized in that, The AUSF determines the expected sequence number through the 5G Unified Data Management (UDM), including: the UDM responding to the authentication request message sent by the AUSF; if the authentication request message contains the quadruple index field, it is determined that a 4G handover has occurred and the quadruple index field is available; the UDM obtains the HSS sequence number from the HSS; and determines the expected sequence number based on the quadruple index field, the HSS sequence number, and the total number of authentication vectors issued by the HSS for the last batch of UEs.
3. The method according to claim 2, characterized in that, Prior to step S101, the method further includes: configuring a quadruple index field in the messages transmitted by each communication interface; the communication interface includes the communication interface that participates in authentication when switching from 4G to 5G.
4. The method according to claim 3, characterized in that, The communication interface includes a first interface connecting the AMF and the MME, a second interface connecting the AMF and the AUSF, and a third interface connecting the AUSF and the UDM.
5. The method according to claim 4, characterized in that, The step of configuring a quadruple index field in the messages transmitted by each communication interface includes: configuring a quadruple index field in the EPS security context and quadruple structure of the context response of the first interface, configuring a quadruple index field in the authentication information structure of the request message of the second interface, and configuring a quadruple index field in the authentication request structure of the authentication request message of the third interface.
6. The method according to claim 5, characterized in that, In the second and third interfaces, the existence configuration of the quadruple index field is optional and the number of occurrences is constrained to once; the method further includes: in the case of 4G to 5G switching, displaying the quadruple index field once in the request message sent to AUSF through the second interface and the authentication request message sent to UDM through the third interface.
7. The method according to claim 2, characterized in that, The step of determining the expected sequence number based on the quadruple index field, the HSS sequence number, and the total number of authentication vectors issued by the HSS to the UE in the last batch includes: determining the difference between the total number and the value of the quadruple index field; and subtracting the difference from the HSS sequence number to obtain the expected sequence number.
8. The method according to claim 7, characterized in that, The method for determining the total number of authentication vectors issued by the HSS to the UE in the last batch includes: the UDM obtaining the total number of authentication vectors issued by the HSS to the UE in the last batch, or determining the total number of authentication vectors issued by the HSS to the UE in the last batch according to the default batch size configured by the operator.
9. An authentication processing device for avoiding resynchronization, characterized in that, include: The acquisition unit is used for the Access and Mobility Management Function (AMF) to respond to a registration request sent by a User Equipment (UE). In the case that the UE is from 4G, the AMF acquires a quad tuple index field from the Mobility Management Entity (MME) of the 4G. The quad tuple index field is used to indicate the number of authentication vectors used in the last batch of authentication vectors issued. The processing unit is configured to send a request message carrying the quadruple index field to the authentication server function (AUSF) to obtain the expected sequence number and its corresponding new authentication vector determined by the AMF through the 5G unified data management (UDM). The expected sequence number is a sequence number determined based on the quadruple index field and the HSS sequence number, where the HSS sequence number is the sequence number corresponding to the last batch of authentication vectors issued by the 4G Home Subscriber Server (HSS) to the UE. The analysis unit is configured to send an authentication request to the UE, the authentication request carrying the expected sequence number and its corresponding new authentication vector, so that the UE determines the authentication result based on the expected sequence number and the local sequence number.
10. An authentication device, characterized in that, The authentication processing method for avoiding resynchronization described in any one of claims 1-8 is adopted.