Access authority management method and device and storage medium
By introducing the first functional network element to unify the management of the terminal's digital identity and structured information, the problem of low access control efficiency in roaming scenarios is solved, and efficient access control management is achieved.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- DATANG MOBILE COMM EQUIP CO LTD
- Filing Date
- 2024-11-06
- Publication Date
- 2026-05-08
AI Technical Summary
In roaming scenarios, access control through offline signing of roaming agreements between the terminal's home network device and the visited network device is inefficient.
The first functional network element is introduced to manage the digital identity and structured information of the terminal. Access control is achieved through interaction, avoiding frequent signaling interactions and offline signing of roaming agreements.
It improves the efficiency of access control management and enables efficient access control management in roaming scenarios.
Smart Images

Figure CN122002285A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of communication technology, and in particular to an access control method, apparatus and storage medium. Background Technology
[0002] To ensure the security of communication between a terminal and a visited network device, it is necessary to determine whether the terminal is allowed to access the visited network device when the terminal requests access to the visited network device.
[0003] Currently, the main method for determining whether a terminal is allowed to access a visited network device is through the authentication and key agreement (AKA) process. However, this method requires the terminal's home network device and the visited network device to sign a roaming agreement offline, which is inefficient. Summary of the Invention
[0004] This application provides an access permission management method, apparatus, and storage medium, which solves the technical problem of low efficiency in roaming scenarios where the terminal's home network device and visited network device sign roaming agreements offline and manage access permissions based on the AKA process.
[0005] Firstly, this application provides an access control method applied to a first functional network element, the method comprising:
[0006] Receives a digital identity identifier sent by the first network device, where the digital identity identifier is the terminal's digital identity identifier;
[0007] Based on the digital identity identifier, determine the terminal's structured information;
[0008] Structured information is sent to the first network device. The digital identity and structured information are used to determine whether the terminal has access rights to the first network device.
[0009] In some embodiments, the structured information includes at least one of the following:
[0010] Type information, used to indicate that the digital identity is a terminal type digital identity;
[0011] Encryption mechanism identifier, used to indicate the encryption mechanism of the digital identity identifier;
[0012] Key credential information, used to indicate the terminal's public key;
[0013] Home network device information, used to indicate the home network device of the terminal;
[0014] Access network device information, used to indicate the network devices that the terminal is allowed to access.
[0015] In some embodiments, a digital identity includes at least one of the following:
[0016] Identifiers for digital identity schemes;
[0017] Identifiers for digital identity methods;
[0018] The terminal's string identifier in the digital identity method is obtained by encrypting the terminal's SUCI and the identifier of the second network device through an encryption mechanism. The second network device is the terminal's home network device.
[0019] In some embodiments, the method further includes:
[0020] Receive home network device information sent by the first network device;
[0021] Determine whether the terminal has access to the first network device based on the network device information;
[0022] A response message is sent to the first network device, which indicates whether the terminal has access rights to the first network device.
[0023] In some embodiments, determining whether a terminal has access to a first network device based on the home network device information includes:
[0024] The string identifier is decrypted according to the encryption mechanism to obtain the terminal's SUCI and the identifier of the second network device;
[0025] Based on the terminal's SUCI and the access control information corresponding to the second network device, it is determined whether the terminal has access rights to the first network device. The access control information is determined by the home network device information and is used to indicate the network devices that each terminal is allowed to access. The home network devices of each terminal are the second network device.
[0026] In some embodiments, where the response message indicates that the terminal has access to the first network device, the response message may also include the terminal's SUCI.
[0027] Secondly, this application provides an access control method applied to a first network device, the method comprising:
[0028] The receiving terminal sends a first access request message, which includes the terminal's digital identity identifier.
[0029] Send a digital identity identifier to the first functional network element;
[0030] Receive structured information sent by the first functional network element;
[0031] Based on the structured information, determine whether the terminal has access rights to the first network device.
[0032] In some embodiments, the structured information includes at least one of the following:
[0033] Type information, used to indicate that the digital identity is a terminal type digital identity;
[0034] Encryption mechanism identifier, used to indicate the encryption mechanism of the digital identity identifier;
[0035] Key credential information, used to indicate the terminal's public key;
[0036] Home network device information, used to indicate the home network device of the terminal;
[0037] Access network device information, used to indicate the network devices that the terminal is allowed to access.
[0038] In some embodiments, the first access request further includes the terminal's digital signature information. Based on the structured information, determining whether the terminal has access to the first network device includes:
[0039] The digital signature information is verified using the terminal's public key to obtain the verification result;
[0040] If the verification result is successful, determine whether the terminal has access rights to the first network device based on the home network device information and / or the access network device information.
[0041] In some embodiments, determining whether the terminal has access rights to the first network device based on the home network device information and / or the access network device information includes:
[0042] If the network device access information includes the identifier of the first network device, it is determined that the terminal has access rights to the first network device.
[0043] In some embodiments, the method further includes:
[0044] Send a query request message to the terminal. The query request message is used to request the query terminal's SUCI.
[0045] SUCI sent by the receiving terminal;
[0046] According to SUCI, a second access request message is sent to the second network device. The second access request message is used for the terminal to perform initial registration on the second network device, which is the terminal's home network device.
[0047] In some embodiments, determining whether a terminal has access to a first network device based on the home network device information and / or the access network device information includes:
[0048] If the identifier of the first network device is not included in the accessed network device information, send the home network device information to the first functional network element.
[0049] The terminal receives a response message sent by the first functional network element. The response message is used to indicate whether the terminal has access rights to the first network device.
[0050] In some embodiments, where the response message indicates that the terminal has access to the first network device, the response message also includes the terminal's SUCI, and the method further includes:
[0051] A second access request message is sent to the second network device. The second access request message is used for the terminal to perform initial registration on the second network device, which is the terminal's home network device.
[0052] In some embodiments, the second access request message includes at least one of the following:
[0053] Digital identity;
[0054] Digital signature information;
[0055] SUCI of the terminal.
[0056] In some embodiments, a digital identity includes at least one of the following:
[0057] Identifiers for digital identity schemes;
[0058] Identifiers for digital identity methods;
[0059] The terminal's string identifier in the digital identity method is obtained by encrypting the terminal's SUCI and the identifier of the second network device through an encryption mechanism. The second network device is the terminal's home network device.
[0060] Thirdly, this application provides an access control method applied to a terminal, the method comprising:
[0061] A first access request message is sent to a first network device. The first access request message includes the terminal's digital identity identifier. The digital identity identifier is used to obtain the terminal's structured information. The digital identity identifier and the structured information are used to determine whether the terminal has access rights to the first network device.
[0062] In some embodiments, the structured information includes at least one of the following:
[0063] Type information, used to indicate that the digital identity is a terminal type digital identity;
[0064] Encryption mechanism identifier, used to indicate the encryption mechanism of the digital identity identifier;
[0065] Key credential information, used to indicate the terminal's public key;
[0066] Home network device information, used to indicate the home network device of the terminal;
[0067] Access network device information, used to indicate the network devices that the terminal is allowed to access.
[0068] In some embodiments, a digital identity includes at least one of the following:
[0069] Identifiers for digital identity schemes;
[0070] Identifiers for digital identity methods;
[0071] The terminal's string identifier in the digital identity method is obtained by encrypting the terminal's SUCI and the identifier of the second network device through an encryption mechanism. The second network device is the terminal's home network device.
[0072] In some embodiments, the method further includes:
[0073] In response to a query request message received from the first network device, the terminal sends its SUCI to the first network device.
[0074] Fourthly, this application provides an access control method applied to a second network device, the method comprising:
[0075] The terminal receives a second access request message sent by a first network device. The second access request message is used for the terminal to perform initial registration on the second network device, which is the terminal's home network device.
[0076] In some embodiments, the second access request message includes at least one of the following:
[0077] Digital identity;
[0078] Digital signature information;
[0079] SUCI of the terminal.
[0080] In some embodiments, a digital identity includes at least one of the following:
[0081] Identifiers for digital identity schemes;
[0082] Identifiers for digital identity methods;
[0083] The terminal's string identifier in the digital identity method is obtained by encrypting the terminal's SUCI and the identifier of the second network device through an encryption mechanism. The second network device is the terminal's home network device.
[0084] In some embodiments, the method further includes:
[0085] Send access control information corresponding to the second network device to the first functional network element, wherein the access control information is used to indicate the network devices that at least one terminal is allowed to access, and the network devices to which at least one terminal belongs are the second network devices.
[0086] Fifthly, this application provides an access control device, the device comprising:
[0087] The first receiving module is used to receive a digital identity identifier sent by the first network device, wherein the digital identity identifier is the digital identity identifier of the terminal.
[0088] The first processing module is used to determine the structured information of the terminal based on the digital identity identifier;
[0089] The first sending module is used to send structured information to the first network device. The digital identity and structured information are used to determine whether the terminal has access rights to the first network device.
[0090] Sixthly, this application provides an access control device, the device comprising:
[0091] The second receiving module is used to receive a first access request message sent by the terminal, the first access request message including the digital identity identifier of the terminal;
[0092] The second sending module is used to send digital identity identifiers to the first functional network element;
[0093] The third receiving module is used to receive structured information sent by the first functional network element;
[0094] The second processing module is used to determine whether the terminal has access rights to the first network device based on the structured information.
[0095] Seventhly, this application provides an access control device, the device comprising:
[0096] The first transceiver module is used to send a first access request message to the first network device. The first access request message includes the digital identity of the terminal. The digital identity is used to obtain the structured information of the terminal. The digital identity and the structured information are used to determine whether the terminal has access rights to the first network device.
[0097] Eighthly, this application provides an access control device, the device comprising:
[0098] The second transceiver module is used to receive a second access request message sent by the first network device. The second access request message is used by the terminal to perform initial registration on the second network device, which is the terminal's home network device.
[0099] Ninthly, this application provides an access control device, including a memory, a transceiver, and a processor:
[0100] A memory for storing computer programs; a transceiver for sending and receiving data under the control of a processor; and a processor for reading computer programs from the memory and executing the access control method of any one of the first aspects.
[0101] In a tenth aspect, this application provides an access control device, including a memory, a transceiver, and a processor:
[0102] A memory is used to store computer programs; a transceiver is used to send and receive data under the control of a processor; and a processor is used to read computer programs from the memory and execute the access control method of any of the second aspects.
[0103] Eleventhly, this application provides an access control device, including a memory, a transceiver, and a processor:
[0104] A memory is used to store computer programs; a transceiver is used to send and receive data under the control of a processor; and a processor is used to read computer programs from the memory and execute access control methods of any of the third aspects.
[0105] In a twelfth aspect, this application provides an access control device, including a memory, a transceiver, and a processor:
[0106] Memory is used to store computer programs; transceiver is used to send and receive data under the control of the processor; processor is used to read computer programs from memory and execute access control methods of any of the fourth aspects.
[0107] In a thirteenth aspect, this application provides a non-transitory readable storage medium storing a computer program for causing a processor to execute the method of any one of the first to fourth aspects.
[0108] In a fourteenth aspect, this application provides a computer program product, including a computer program, wherein when the computer program is executed by a processor, it implements the method of any one of the first to fourth aspects.
[0109] The access permission management method, apparatus, and storage medium provided in this application embodiment allow a terminal to send a first access request message to the first network device when it needs to access a first network device. The first access request message includes the terminal's digital identity identifier. The first network device then sends the digital identity identifier to a first functional network element. The first functional network element determines the terminal's structured information based on the digital identity identifier and sends the structured information back to the first network device. This solution uses a first functional network element to uniformly manage the terminal's digital identity identifier and structured information. When a terminal requests access to the first network device, the first functional network element sends the terminal's structured information to the first network device, enabling the first network device to determine whether the terminal has access rights to the first network device based on the digital identity identifier and structured information. This achieves high efficiency in access permission management based on digital identity identifiers and structured information in roaming scenarios without requiring offline roaming agreements between the terminal's home network device and the first network device, or frequent signaling interactions.
[0110] It should be understood that the content described in the foregoing summary section is not intended to limit the key or essential features of the embodiments of this application, nor is it intended to limit the scope of this application. Other features of this application will become readily apparent from the following description. Attached Figure Description
[0111] To more clearly illustrate the technical solutions in this application or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0112] Figure 1 A signaling diagram of a 5A-AKA process is provided for an embodiment of this application;
[0113] Figure 2 This application provides a schematic diagram of identity verification management under a 6G network.
[0114] Figure 3 Signaling diagram of the access control method provided in the embodiments of this application;
[0115] Figure 4 A schematic diagram of a connection relationship provided for an embodiment of this application;
[0116] Figure 5 A schematic diagram illustrating the composition of a DID identifier provided in an embodiment of this application;
[0117] Figure 6A schematic diagram illustrating the composition of a DID document provided in an embodiment of this application;
[0118] Figure 7 A schematic diagram of the composition of a VC provided in an embodiment of this application;
[0119] Figure 8 Signaling for the access control method provided in the embodiments of this application Figure 1 ;
[0120] Figure 9 Signaling for the access control method provided in the embodiments of this application Figure 2 ;
[0121] Figure 10 Schematic diagram of the access control device provided in the embodiments of this application Figure 1 ;
[0122] Figure 11 Schematic diagram of the access control device provided in the embodiments of this application Figure 2 ;
[0123] Figure 12 Schematic diagram of the access control device provided in the embodiments of this application Figure 3 ;
[0124] Figure 13 Schematic diagram of the access control device provided in the embodiments of this application Figure 4 ;
[0125] Figure 14 Schematic diagram of the access control device provided in the embodiments of this application Figure 5 ;
[0126] Figure 15 Schematic diagram of the access control device provided in the embodiments of this application Figure 6 ;
[0127] Figure 16 Schematic diagram of the access control device provided in the embodiments of this application Figure 7 ;
[0128] Figure 17 Schematic diagram of the access control device provided in the embodiments of this application Figure 8 . Detailed Implementation
[0129] In the embodiments of this application, the term "and / or" describes the relationship between associated objects, indicating that three relationships can exist. For example, A and / or B can represent three cases: A alone, A and B simultaneously, and B alone. The character " / " generally indicates that the preceding and following associated objects have an "or" relationship.
[0130] In the embodiments of this application, the term "at least one" refers to one or more, "multiple" refers to two or more, and other quantifiers are similar.
[0131] The terms "first," "second," etc., used in the embodiments of this application are for illustrative purposes and to distinguish the objects being described. They do not indicate any order and do not imply any special limitation on the number of objects in the embodiments of this application. They do not constitute any limitation on the embodiments of this application.
[0132] The technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only a part of the embodiments of this application, and not all of the embodiments. Based on the embodiments of this application, all other embodiments obtained by those of ordinary skill in the art without creative effort are within the scope of protection of this application.
[0133] This application provides an access permission management method, apparatus, and storage medium to solve the technical problem of low efficiency in access permission management for terminals when they need to access network devices in roaming scenarios.
[0134] The method and apparatus are based on the same concept of the application. Since the methods and apparatus solve problems in similar ways, the implementation of the apparatus and methods can refer to each other, and the repeated parts will not be described again.
[0135] The technical solutions provided in this application can be applied to a variety of systems. For example, applicable systems may include Long Term Evolution (LTE) systems, LTE Frequency Division Duplex (FDD) systems, LTE Time Division Duplex (TDD) systems, Long Term Evolution Advanced (LTE-A) systems, Universal Mobile Telecommunications System (UMTS), Worldwide Interoperability for Microwave Access (WiMAX) systems, 5G New Radio (NR) systems and their evolved communication systems, and 6G (sixth generation mobile communication technology) systems. These systems may include terminal equipment and network equipment. The systems may also include a core network component, such as the Evolved Packet Core (EPC) and the 5G Core Network (5GC).
[0136] The terminal devices involved in the embodiments of this application can be devices that provide voice and / or data connectivity to users, handheld devices with wireless connectivity, or other processing devices connected to a wireless modem. The names of the terminal devices may differ in different systems; for example, in 5G or 6G systems, the terminal device may be called User Equipment (UE). Wireless terminal devices can be USB storage devices, other personal computer memory devices, and dongles. They can also communicate with one or more core networks (CNs) via a Radio Access Network (RAN). Wireless terminal devices can be mobile terminal devices, such as mobile phones (or "cellular" phones) and computers with mobile terminal devices. For example, they can be portable, pocket-sized, handheld, computer-embedded, or vehicle-mounted mobile devices that exchange voice and / or data with the radio access network. Examples of such devices include Personal Communication Service (PCS) phones, cordless phones, Session Initiated Protocol (SIP) phones, Wireless Local Loop (WLL) stations, Personal Digital Assistants (PDAs), personal computers, tablets, and Machine-type Communication (MTC) terminal devices. Wireless terminal devices can also be referred to as systems, subscriber units, subscriber stations, mobile stations, mobile devices, remote stations, access points, remote terminals, access terminals, user terminals, user agents, user devices, and wireless access devices and routers / modems that meet the limitations of this definition; however, this application does not limit the scope of the embodiments.
[0137] The network device involved in this application embodiment can be a base station, which may include multiple cells providing services to terminals. Depending on the specific application, the base station may also be called an access point, or a device in the access network that communicates with wireless terminal devices through one or more sectors on the air interface, or other names. The network device can be used to exchange received air frames with Internet Protocol (IP) packets, acting as a router between the wireless terminal device and the rest of the access network, where the rest of the access network may include an Internet Protocol (IP) communication network. The network device can also coordinate the attribute management of the air interface. For example, the network device involved in this application embodiment can be an evolved Node B (eNB or e-NodeB) in a long term evolution (LTE) system, a 5G base station (gNB) in a next generation system, or a Home evolved Node B (HeNB), relay node, femto, pico, network testing equipment, etc., and is not limited in this application embodiment. In some network architectures, network devices may include centralized unit (CU) nodes and distributed unit (DU) nodes, which may also be geographically separated.
[0138] In roaming scenarios, terminals have a need to access network devices. The network device where the terminal is registered can be called the terminal's home network device, and the network device that the terminal needs to access when roaming to other locations can be called the terminal's visited network device.
[0139] To ensure the security of data transmission between the terminal and the visited network device, when the terminal requests access to the visited network device, it is necessary to manage the terminal's access permissions to determine whether the terminal is allowed to access the visited network device.
[0140] In 5G New Radio (NR), terminal access permission management is implemented through the AKA process. The following section will explain... Figure 1 This section introduces the AKA process in 5G networks.
[0141] Figure 1 A signaling diagram of a 5A-AKA process is provided for an embodiment of this application, as follows: Figure 1As shown, the main network elements involved include User Data Management (UDM) network elements, Authentication Credential Repository and Processing Function (ARPF) network elements, Authentication Server Function (AUSF) network elements, Security Anchor Function (SEAF) network elements, and terminals. Among these, AUSF, UDM, and ARPF network elements belong to the home network device, while the SEAF network element belongs to the visited network device. Figure 1 As shown, the process includes the following steps:
[0142] 1. UDM network elements generate authentication vectors (AVs).
[0143] AV (Authenticator) is a set of parameters used for authentication, verifying the authenticity of terminals or network devices to ensure secure communication. AV typically includes the following parameters:
[0144] Random challenge (RAND) is an unpredictable random number provided to the terminal by the home network device to initiate the authentication process;
[0145] An authentication token (AUTN) is used to ensure two-way authentication between a terminal and a visited network device. The AUTN provides information to the terminal, enabling the terminal to authenticate the visited network device based on the AUTN.
[0146] 2. The UDM / ARPF network element sends an authentication vector retrieval request response message (Nudm_UEAuthenticate_Get Response) to the AUSF network element.
[0147] The authentication vector retrieval request response message includes RAND, AUTN, and ExpectedResponse (XRES*), where XRES* represents the authentication response that the network device expects to receive from the terminal. If the authentication vector retrieval request message contains a Subscription Concealed Identifier (SUCI), the authentication vector retrieval request response message also carries a Subscription Permanent Identifier (SUPI).
[0148] 3. AUSF network element storage XRES*.
[0149] 4. Calculate the hidden expected response (Hidden XRES*, HXRES*) for AUSF network elements.
[0150] HXRES* is an encrypted or hidden form of XRES*, used to enhance the security of the authentication process. During authentication, the terminal calculates an authentication response RES* based on the RAND and key provided by the home network device. To verify the terminal's identity, the home network device expects a hidden authentication response XRES* that matches the RES calculated by the terminal. For added security, the network device does not transmit XRES* directly, but instead transmits its hidden form, HXRES*.
[0151] The introduction of HXRES* prevents XRES* from being maliciously intercepted or abused during the authentication process. By hiding XRES*, HXRES* can reduce security risks while ensuring the effectiveness of the authentication process.
[0152] 5. The AUSF network element sends an authentication request service response message (Nausf_UEAuthentication_Authenticate_Response) to the SEAF network element.
[0153] The authentication request service response message carries 5G SE AV (RAND, AUTN, and HXRES*).
[0154] 6. The SEAF network element sends a NAS message (Authentication-Request) to the terminal.
[0155] SEAF network elements initiate an authentication process for the terminal via NAS messages, carrying authentication parameters RAND and AUTN, as well as Network Key Security Information (ngKSI).
[0156] 7. Terminal calculation of RES*.
[0157] After receiving RAND and AUTN, the terminal verifies the freshness of the received AUTN. If the verification is successful, the terminal calculates RES*.
[0158] 8. The terminal sends a NAS authentication response message to the SEAF network element.
[0159] The NAS authentication response message includes RES*.
[0160] 9. SEAF network elements calculate HRES* and compare HRES* with HXRES*.
[0161] The SEAF network element calculates HRES* based on the RES* sent by the terminal. SEAF compares HRES* and HXRES*. If they match, the terminal is considered to have successfully authenticated with the currently visited network device.
[0162] 10. The SEAF network element sends an authentication request message (Nausf_UEAuthentication_Authenticate_Request) to the AUSF network element.
[0163] SEAF network element sends an authentication request message to the home network authentication center (AUSF) network element, and the authentication request message includes RES*.
[0164] 11. AUSF network elements compare and verify RES* and XRES*.
[0165] After receiving the authentication request message, the AUSF network element first determines whether the AV has expired. If it has expired, the authentication is considered to have failed. Otherwise, it compares RES* and XRES*. If they are equal, the authentication is considered to have succeeded from the perspective of the home network device.
[0166] 12. The AUSF network element sends an authentication response message (Nausf_UEAuthentication_Authenticate_Response) to the SEAF network element.
[0167] The authentication response message includes the authentication result of the terminal on the home network device, and the SEAF network element is notified of the authentication result of the terminal on the home network device through the authentication response message.
[0168] In the 5G AKA protocol, the AUSF network element requests an authentication vector from the UDM network element. Upon receiving the authentication vector, the AUSF network element returns it to the SEAF network element. The SEAF network element then returns the authentication vector to the terminal. The terminal authenticates the network device based on the authentication vector and sends RES* back to the visited network device. The visited network device uses RES* to authenticate the terminal. After successful authentication by the visited network device, RES* is sent to the home network device. The home network device verifies RES* to determine if the terminal is legitimate.
[0169] From the above steps, it can be seen that in the current 5G AKA process, the access control management of the terminal by the visited network device depends on the RES* generated by the authentication vector sent to the terminal by the home network device. The visited network device manages the access control of the terminal by comparing the RES* with the locally calculated HXRES* (based on the authentication vector of the home network device). The home network device verifies the RES* and authenticates the terminal.
[0170] In the above process, the access control of the terminal by the visited network device relies on the authentication vector provided by the home network device during the primary authentication process, making it overly dependent on the home network device. With the development of communication technology, to meet the diverse service needs of various scenarios, future 6G networks will adopt a decentralized hierarchical network with centralized and distributed collaboration. 6G networks will be organized through centralized and distributed collaboration and distributed autonomy, which can meet the diverse heterogeneous access scenarios and network performance requirements of air, land, and sea. In a distributed network, a logical node may be deployed on multiple physical entities or implemented by different software modules depending on the node's functions. Facing the 6G distributed network, there is plug-and-play functionality for distributed subnets. If a terminal of a home network device wants to access a distributed visited network device, according to the existing 5G mechanism, the home network device needs to sign a roaming agreement offline with the visited network device, which is inefficient. Furthermore, the dynamic network topology of the 6G distributed network leads to an increase in the number of subnets and frequent changes. From the terminal's perspective, this requires the terminal to frequently adjust the visited network list via NAS signaling, and the list also needs to maintain too many network device names and access technology categories.
[0171] In the architecture of a 6G distributed network, devices are located in different management domains. Within the same management domain, they are considered trusted. In order to establish trust between devices located in different management domains, the participating devices need to perform mutual authentication across management domains without involving trusted third parties, so as to manage the access permissions of the terminals.
[0172] This process can be found in [reference]. Figure 2 , Figure 2 This application provides a schematic diagram of identity verification management under a 6G network, as shown in the embodiment. Figure 2 As shown, this example illustrates how devices in two different management domains (domain A and domain B) can perform cross-management domain mutual authentication.
[0173] Each management domain includes the following components:
[0174] Proxy Server: The proxy server is a node in the blockchain, serving the key generation center and periodically updating and uploading device public keys and system information. Each key generation center in the management domain needs to build a node to maintain the global ledger of the blockchain.
[0175] Key Generation Center: Generates private keys for corresponding devices based on the identity information and system information sent by devices within this management domain. The public key serves as the device's identity information, which is a temporary identifier generated by the device and needs to be updated periodically. It does not require signatures from authoritative institutions or digital certificates, simplifying the complexity of key system management. The Key Generation Center uploads the device's public key and system information to the blockchain through a proxy server and updates it periodically.
[0176] Authentication server: A device used for authentication. It can request the system information and public key information required for authentication of cross-domain devices in the blockchain from the proxy server in this management domain, and perform authentication of cross-domain devices on behalf of the requesting device.
[0177] When a device needs to perform authentication, it sends its identity information to a key generation center to generate a device private key. Blockchain, as an immutable distributed ledger, can provide trust endorsement for device public keys and system information across different management domains. When a device performs cross-domain authentication, it downloads the public key stored in the blockchain and uses it to verify the authentication message sent by the cross-domain device.
[0178] like Figure 2 As shown, for domain A, the devices under domain A include proxy server 201, key generation center 202, device 203 and authentication server 204; for domain B, the devices under domain B include proxy server 211, key generation center 212, device 213 and authentication server 214.
[0179] Taking device 203 in domain A accessing domain B as an example, device 203 first needs to send an authentication request to the authentication server 214. The authentication request includes device 203's signature information. This signature information is generated based on device 203's private key, which is generated by the key generation center 202 based on device 203's identity information.
[0180] After receiving the authentication request from device 203, authentication server 214 obtains the signature information of device 203, downloads the public key and system information of domain A from the blockchain through proxy server 211, and then verifies the signature information using the public key of domain A to confirm the legitimacy of the authentication request. If legitimate, device 203 is allowed to access domain B; otherwise, device 203 is not allowed to access domain B. The authentication process for device 213 is similar and will not be described further here.
[0181] However, the aforementioned cross-domain authentication mechanism based on identity information mainly targets the authentication of terminals, i.e. whether the terminal is a registered user. It does not include access control of the terminal by the visiting network device. That is, if the visiting network device authenticates the terminal, it considers the terminal registered on the blockchain network to be a legitimate terminal, but it fails to implement further access control over the terminal registered on the blockchain network.
[0182] Based on this, embodiments of this application provide an access permission management method, which introduces a first functional network element to manage the digital identity and structured information of the terminal. When the terminal needs to access the first network device, access permission management of the terminal is achieved through the interaction between the first functional network element and the first network device. This eliminates the need for frequent signaling interactions to access the visited network list, thereby enabling access permission management based on digital identity and structured information in roaming scenarios with high efficiency.
[0183] Figure 3 The signaling diagram for the access control method provided in the embodiments of this application is as follows: Figure 3 As shown, the method includes:
[0184] S31, the terminal sends a first access request message to the first network device, the first access request message including the terminal's digital identity identifier.
[0185] In all embodiments of this application, the terminal is registered with the first functional network element. The registration process can be offline registration or the terminal can send a registration request to the first functional network element to complete the terminal registration.
[0186] Taking a terminal sending a registration request to a first functional network element as an example, the registration request includes the terminal's identity information, which is used to uniquely identify the terminal. After receiving the terminal's identity information, the first functional network element generates a digital identity identifier for the terminal and corresponding structured information.
[0187] The terminal's digital identity can be a universal identity identifier used across different platforms to uniquely identify the terminal. Optionally, the first functional network element can perform calculations or encryption on the terminal's identity information to obtain the terminal's digital identity. Optionally, the registration request may also include a configuration file, which indicates the terminal's home network device and the network devices the terminal is allowed to access. The first functional network element can perform calculations or encryption on the terminal's identity information, as well as the identifiers of the home network device and the network devices the terminal is allowed to access, to obtain the terminal's digital identity.
[0188] The structured information of a terminal is a detailed description of the terminal's digital identity, and there is a one-to-one relationship between the digital identity and the structured information. For example, the structured information may indicate the terminal's home network device and / or the network devices that the terminal is allowed to access. For example, the structured information may include key credential information to indicate the terminal's public key. For example, if the terminal's digital identity is generated based on a certain encryption mechanism, the structured information may indicate that encryption mechanism, and so on.
[0189] When a terminal needs to access a first network device, the terminal sends a first access request message to the first network device, which is the visited network device of the terminal. The first access request message includes the digital identity identifier of the terminal.
[0190] S32, the first network device sends a digital identity identifier to the first functional network element.
[0191] The first network device receives a first access request message sent by the terminal, and can obtain the terminal's digital identity from the first access request message. Since the terminal's digital identity and structured information are managed uniformly by the first functional network element, the first network device sends the digital identity to the first functional network element to request the terminal's structured information.
[0192] S33, the first functional network element determines the structured information of the terminal based on the digital identity identifier.
[0193] The first functional network element is used to manage the digital identity identifiers of different terminals. The digital identity identifiers and structured information are in one-to-one correspondence. Therefore, after receiving the digital identity identifier sent by the first network device, the first functional network can determine the structured information of the terminal based on the digital identity identifier and the one-to-one correspondence between the digital identity identifier and the structured information.
[0194] S34, the first functional network element sends structured information to the first network device.
[0195] After determining the structured information of the terminal, the first functional network sends the structured information to the first network device, and the first network device receives the structured information accordingly.
[0196] S35, the first network device determines whether the terminal has access rights to the first network device based on the structured information.
[0197] After receiving the structured information sent by the first functional network element, the first network device uses the structured information to determine whether the terminal has access rights to the first network device, that is, whether the terminal is allowed to access the first network device.
[0198] For example, if the structured information can be used to indicate the network devices that the terminal is allowed to access, and the first network device is included among the network devices that the terminal is allowed to access, then it is determined that the terminal has access rights to the first network device; if the first network device is not included among the network devices that the terminal is allowed to access, then it is determined that the terminal does not have access rights to the first network device.
[0199] For example, when the structured information can be used to indicate the home network device of the terminal, the first network device can send the home network device information to the first functional network element. The first functional network element determines whether the terminal has access rights to the first network device based on the home network device information, and then the first functional network element instructs the first network device whether the terminal has access rights to the first network device.
[0200] The access permission management method provided in this application embodiment involves a terminal sending a first access request message to the first network device when it needs to access a first network device. This first access request message includes the terminal's digital identity identifier. The first network device then sends this digital identity identifier to a first functional network element. The first functional network element determines the terminal's structured information based on the digital identity identifier and sends this structured information back to the first network device. This solution uses a first functional network element to uniformly manage the terminal's digital identity identifier and structured information. When a terminal requests access to the first network device, the first functional network element sends the terminal's structured information to the first network device, enabling the first network device to determine whether the terminal has access rights to the first network device based on the digital identity identifier and structured information. This method achieves high efficiency in roaming scenarios by eliminating the need for the terminal's home network device and the first network device to sign a roaming agreement offline or to engage in frequent signaling interactions.
[0201] The solutions of the embodiments of this application will be further described below with reference to the accompanying drawings.
[0202] First, combine Figure 4 This section describes the connection relationships between the first functional network element, the terminal, and the network equipment. Figure 4 A schematic diagram of a connection relationship provided for an embodiment of this application, such as... Figure 4 The diagram illustrates the connection relationships between terminal A, the first network device, the second network device, and the first functional network element.
[0203] The first functional network element, also known as the digital identity management platform, identity management platform, digital identity management server, etc., is used to manage the digital identity identifiers and structured information of all terminals, and can also be used to manage the identifiers of all network devices.
[0204] The terminal is a user registered with the first functional network element. After registering with the first functional network element, the terminal can obtain the services provided by the first functional network element. The connection between the terminal and the first functional network element can be a wired connection or a wireless connection. Figure 4 As shown, after terminal A completes its registration on the first functional network element side, terminal A establishes a connection with the first functional network element and can obtain the services provided by the first functional network element.
[0205] The first network device is the visited network device for terminal A. The first network device can also register with the first functional network element. After registering with the first functional network element, the first network device can obtain the services provided by the first functional network element. The connection between the first network device and the first functional network element can be a wired connection or a wireless connection.
[0206] The second network device is the home network device of terminal A, and the second network device can also register with the first functional network element. After registering with the first functional network element, the second network device can obtain the services provided by the first functional network element. The connection between the second network device and the first functional network element can be a wired connection or a wireless connection.
[0207] For any given network device, it may include one or more network elements. Establishing a connection between the network device and the first functional network element can mean that each network element in the network device establishes a connection with the first functional network element, or it can mean that a certain proxy network element in the network device establishes a connection with the first functional network element.
[0208] like Figure 4 As shown, the first network device includes three network elements, namely network function 1, network function 2 and network function 3. The establishment of a connection between the first network device and the first functional network element means that network function 1, network function 2 and network function 3 are all connected to the first functional network element.
[0209] like Figure 4 As shown, the second network device includes three network elements: a proxy network element, network function 2, and network function 3. The connection between the second network device and the first function network element indicates that the proxy network element has established a connection with the first function network element.
[0210] For example, for any network device, if all network elements in the network device establish connections with the first functional network element, then subsequent information interaction between the network device and the first functional network element is achieved through the interaction between the corresponding network element in the network device and the first functional network element; if only a proxy network element in the network device establishes a connection with the first functional network element, then subsequent information interaction between the network device and the first functional network element is achieved through the interaction between the proxy network element and the first functional network element. It is understandable that... Figure 4The interaction process between the first network device and the first functional network element, and the interaction process between the second network device and the first functional network element, are merely examples and do not constitute a limitation on the interaction process. In the following embodiments, interactions between network devices and other devices are described using actions such as "network device sends A" or "network device receives B". "Network device sends A" can mean "network function 1 sends A / network function 2 sends A / network function 3 sends A...", and "network device receives B" can mean "network function 1 receives B / network function 2 receives B / network function 3 receives B..."; or, "network device sends A" can mean "a proxy network element in the network device sends A", and "network device receives B" can mean "a proxy network element in the network device receives B".
[0211] In the above embodiments, combined with Figure 4 This paper describes the connection relationships between the first functional network element, the terminal, and network devices. The terminal can register with the first functional network element through a registration process. The first functional network element generates the terminal's digital identity and structured information, and sends the digital identity to the terminal. Network devices can also register with the first functional network element through a registration process. The first functional network element generates the network device's identifier (which can be the network device's digital identity) and the network device's structured information. The digital identity and structured information of the terminal will be described below with reference to the accompanying diagrams.
[0212] With the widespread adoption of mobile internet, each user has several accounts, collectively known as digital identities. A digital identity serves as a marker in a user's virtual life and forms the basis for their online activities, allowing them to continuously connect with other devices. As digital identity technology and blockchain technology advance, blockchain's private key encryption and distributed storage ensure end-to-end data traceability. Furthermore, the continuous improvement of user digital identity information can fundamentally address the current blockchain limitation of only guaranteeing authenticity on-chain but not verifying forgery, while effectively promoting the flow and sharing of blockchain information, thereby improving overall authentication efficiency.
[0213] After the terminal registers with the first functional network element, the first functional network element generates the terminal's digital identity and structured information. During the registration process, the terminal sends its identity information and configuration file to the first functional network element. This configuration file indicates the terminal's home network device and the network devices the terminal is allowed to access. Based on the terminal's identity information and configuration file, the first functional network element generates the terminal's digital identity and structured information.
[0214] For example, the digital identity of a terminal can be, for instance, the terminal's decentralized identity (DID).
[0215] DID is a new type of identifier, a decentralized identification protocol released by the World Wide Web Consortium (W3C) to identify any entity (such as an individual, organization, abstract entity, virtual entity, etc.). DIDs are platform-independent; a single DID can be used to log in to multiple different platforms. Even if one platform is shut down, it will not affect the ability to log in to other platforms (provided that the platform supports DIDs).
[0216] DID places greater emphasis on decentralization, requiring each terminal in the identity system to interact point-to-point through a DID identifier, ensuring that no single node or group of nodes can control all the data generated in the process. DID requires that all aspects of the identity system architecture be decentralized, including data storage, verification, and transactions, all of which must be conducted on a blockchain or distributed ledger, achieving decentralization from the underlying protocol to the upper-level application.
[0217] Figure 5 This is a schematic diagram illustrating the composition of a DID identifier provided in an embodiment of this application, such as... Figure 5 As shown, the DID identifier mainly consists of three parts: scheme identifier, DID method identifier, and specific identifier in the DID method.
[0218] The scheme identifier is the first part of the DID identifier and is used to distinguish the different schemes to which the DID identifier belongs. The scheme identifier is fixed and usually begins with "did:" (e.g., ...). Figure 5 The example in the text, "did:", indicates that the DID identifier conforms to the DID specification.
[0219] The DID method identifier is the second part of the DID identifier (e.g., ...). Figure 5 The "example" in the example indicates that the DID identifier was generated using a specific DID method that conforms to the DID specification, representing the method and rules used by the DID identifier.
[0220] The specific identifier in the DID method is a string generated by the method using the DID identifier (e.g., ...). Figure 5 The example in the text, “123456789abcdefghi”, is used to uniquely represent the corresponding device.
[0221] There is a one-to-one relationship between the DID identifier and the DID document; the DID document is a detailed description of the DID identifier. Figure 6 This is a schematic diagram illustrating the composition of the DID document provided in the embodiments of this application, as shown below. Figure 6As shown, the DID document mainly consists of two parts: DID metadata and DID public key.
[0222] The DID public key can be used for digital signatures or encryption operations. The DID identifier can be stored on the terminal, while the DID document can be stored in data such as a blockchain (indexed by the DID identifier) to ensure the correctness of the DID document. Since the DID document does not contain any content related to real information, authentication is required through a Verifiable Credential (VC) in the DID application layer.
[0223] A VC is a descriptive statement issued by a DID to endorse certain attributes of another DID, and is accompanied by its own digital signature to prove the authenticity of these attributes. It can be considered a type of digital certificate.
[0224] Figure 7 This is a schematic diagram of the composition of the VC provided in the embodiments of this application, as shown below. Figure 7 As shown, VC mainly includes the following information:
[0225] VC metadata mainly includes information such as the issuer, release date, and type of declaration.
[0226] Declaration: One or more descriptions of the subject, which may include information such as name, gender, date of birth, etc.;
[0227] Proof: This is usually the issuer's digital signature, which ensures that the VC can be verified, prevents the VC content from being tampered with, and verifies the issuer of the VC.
[0228] Because the DID document corresponding to the DID does not contain the actual terminal information, the terminal needs to provide proof, i.e., a VC (Publisher Document), when performing a certain operation. The DID identifier can be obtained through the Uniform Resource Identifier (URI) address in the VC's publisher field. Then, the public key can be obtained from the corresponding DID document. Verifying the signature of the VC using the public key verifies whether the VC was issued by the publisher.
[0229] In one possible implementation, the terminal's digital identity includes at least one of the following: 1.1 to 1.3
[0230] 1.1 Identifiers for digital identity schemes.
[0231] The identifier of a digital identity scheme is used to identify the corresponding digital identity scheme. If the digital identity identifier of a terminal includes the identifier of a digital identity scheme, it means that the digital identity identifier follows the corresponding digital identity scheme specification, or it can mean that the digital identity identifier is compatible with other systems that follow the same digital identity scheme specification.
[0232] In some embodiments, if the digital identity of the terminal is the terminal's DID identifier, then the identifier of the digital identity scheme can be the scheme identifier in the DID identifier.
[0233] 1.2 Identifiers for digital identity methods.
[0234] The identifier of the digital identity method is used to identify the corresponding digital identity method. If the digital identity identifier of the terminal includes the identifier of the digital identity method, then the identifier of the digital identity method indicates which digital identity method in the digital identity scheme specification was used to generate the digital identity identifier.
[0235] In some embodiments, if the digital identity of the terminal is the terminal's DID identifier, then the identifier of the digital identity method can be the DID method identifier in the DID identifier.
[0236] 1.3. String identifier of the terminal in the digital identity method.
[0237] The string identifier is obtained by encrypting the terminal's SUCI and the identifier of the second network device through an encryption mechanism. The second network device is the terminal's home network device.
[0238] In some embodiments, if the digital identity of the terminal is the terminal's DID identifier, then the string identifier of the terminal in the digital identity method can be a specific identifier in the DID method.
[0239] For example, a digital identity for a terminal can take the following form:
[0240] DID: <did-xxmobile>:<H(SUCI∥PLMN)>
[0241] In the aforementioned digital identity identifier, "DID:" is the identifier of the digital identity scheme, used to identify the corresponding digital identity scheme as DID. "did-XXmobile" is the identifier of the digital identity method, used to identify the corresponding digital identity method as "did-XXmobile", where did-XXmobile represents the encryption of the terminal's SUCI and PLMN. "H(SUCI∥PLMN)" is the string identifier in the terminal's digital identity method "did-XXmobile", where SUCI is the terminal's SUCI, PLMN is the terminal's home network device information (i.e., the identifier of the second network device, which is the terminal's home network device), and H represents the encryption mechanism of the digital identity identifier.
[0242] In one possible implementation, the terminal's structured information includes at least one of the following 2.1 to 2.5:
[0243] 2.1 Type information, used to indicate that the digital identity is a terminal type digital identity.
[0244] For the structured information of a terminal, if the structured information includes type information, then the type information is used to indicate that the corresponding digital identity is a digital identity of the terminal type, and is used to identify the terminal.
[0245] 2.2 Encryption Mechanism Identifier, used to indicate the encryption mechanism of the digital identity identifier.
[0246] If the terminal's digital identity includes a string identifier in the digital identity method, this string identifier is obtained by encrypting the terminal's SUCI and the identifier of the second network device using an encryption mechanism. Therefore, this encryption mechanism identifier is used to uniquely identify the encryption mechanism. The corresponding encryption mechanism can be determined through this encryption mechanism, allowing the decryption of the string identifier in the digital identity method to obtain the terminal's SUCI and the identifier of the second network device.
[0247] 2.3 Key credential information, used to indicate the terminal's public key.
[0248] The terminal's public and private keys are paired. The private key can be used to generate digital signature information, while the terminal's public key can be used to verify the digital signature information.
[0249] 2.4 Home network device information, used to indicate the home network device of the terminal.
[0250] The terminal's home network device is the second network device. Therefore, the home network device information can be the identifier of the second network device, such as the device identifier of the second network device, the digital identity identifier of the second network device (such as the DID identifier of the second network device), etc.
[0251] 2.5 Access network device information, used to indicate the network devices that the terminal is allowed to access.
[0252] The network devices that a terminal is allowed to access can be network devices that have pre-signed a roaming agreement with the terminal's home network device. If a network device has signed a roaming agreement with the terminal's home network device, the terminal is allowed to access that network device. If the network devices that the terminal is allowed to access include network device A, the access information for the network device can include the identifier of network device A, such as the device identifier of network device A, the digital identity identifier of network device A (such as the DID identifier of network device A), etc.
[0253] In one possible implementation, the network device can also register at the first functional network element side, whereby the first functional network element generates the network device's digital identity and structured information. The network device's digital identity may include at least one of the following: an identifier for a digital identity scheme, an identifier for a digital identity method, and a string identifier for the network device within the digital identity method. The string identifier for the network device within the digital identity method is obtained by encrypting the network device's device identifier using an encryption mechanism. The components of the digital identity can be found in the relevant descriptions in sections 1.1-1.3 of the above embodiments, and will not be repeated here.
[0254] For example, the digital identity of a network device can take the following form:
[0255] DID: <did-xxmobile>:<H(device ID∥PLMN)>
[0256] In the aforementioned digital identity identifier, "DID:" is the identifier of the digital identity scheme, used to identify the corresponding digital identity scheme as DID. "did-XXmobile" is the identifier of the digital identity method, used to identify the corresponding digital identity method as "did-XXmobile", where did-XXmobile represents the encryption of the network device's device ID and PLMN. "H(device ID∥PLMN)" is the string identifier in the network device's digital identity method "did-XXmobile", where device ID is the network device's device identifier, PLMN is the network device information to which the network device belongs, and H represents the encryption mechanism of the digital identity identifier.
[0257] For example, the structured information of a network device may include at least one of the following: type information, indicating that the digital identity is a network device type; encryption mechanism identifier, indicating the encryption mechanism of the digital identity; and key credential information, indicating the public key of the network device.
[0258] During the registration of network devices with the first functional network element, the first functional network element also needs to maintain the access control information corresponding to the network devices.
[0259] Taking the second network device as an example, the second network device sends access control information corresponding to the second network device to the first functional network element. The access control information corresponding to the second network device is used to indicate the network devices that at least one terminal is allowed to access. The network devices to which at least one terminal belongs are the second network device.
[0260] Optionally, the access control information corresponding to the second network device can be represented by the correspondence between the identifier of the second network device, the SUCI of each of at least one terminal, and the identifiers of the network devices that each terminal is allowed to access.
[0261] Table 1 below illustrates an example of access control information. As shown in Table 1, the access control information corresponding to the first network device and the second network device are illustrated respectively.
[0262] For the first network device, it includes terminal A and terminal B (i.e., the home network device of terminal A and terminal B is the first network device). The SUCI of terminal A is SUCI1, and the SUCI of terminal B is SUCI2. The network devices that terminal A is allowed to access include network device 2 and network device 3, and the network devices that terminal B is allowed to access include network device 2 and network device 4. For the second network device, it includes terminal C and terminal D (i.e., the home network device of terminal C and terminal D is the first network device). The SUCI of terminal C is SUCI3, and the SUCI of terminal D is SUCI4. The network devices that terminal C is allowed to access include network device 1 and network device 3, and the network devices that terminal D is allowed to access include network device 1 and network device 3.
[0263] Table 1
[0264]
[0265] In the above embodiments, digital identity identifiers, structured information, and access control information have been introduced. The access permission management method provided by the embodiments of this application will be further described below with reference to the accompanying drawings.
[0266] Figure 8 Signaling for the access control method provided in the embodiments of this application Figure 1 ,like Figure 8 As shown, the method may include:
[0267] S801, the terminal sends a first access request message to the first network device.
[0268] When a terminal needs to access a first network device, the terminal sends a first access request message to the first network device, and the first network device receives the first access request message accordingly. The first access request message includes the terminal's digital identity identifier, which is generated by the first functional network element when the terminal registers with it. The first functional network element generates the terminal's digital identity identifier and structured information, and sends the terminal's digital identity identifier to the terminal. The first functional network element stores the digital identity identifiers and structured information of different terminals, with a one-to-one correspondence between the digital identity identifier and the structured information.
[0269] Optionally, the first access request message may also include the terminal's digital signature information, which is generated based on the terminal's private key.
[0270] Optionally, the first access request message may also include a request plaintext, which may be used to indicate, for example, the content requested by the first access request message, or other possible information.
[0271] S802, the first network device sends a digital identity identifier to the first functional network element.
[0272] Upon receiving the first access request message, the first network device can obtain the terminal's digital identity and learn that the terminal wants to access the first network device. Since the terminal's digital identity and structured information are uniformly managed by the first functional network element, the first network device sends the digital identity to the first functional network element to obtain the terminal's structured information.
[0273] S803, the first functional network element determines the structured information of the terminal based on the digital identity identifier.
[0274] On the first functional network element side, the digital identity identifiers and structured information of multiple different terminals can be stored and managed. After the first functional network element receives the digital identity identifier sent by the first network device, it can determine the structured information of the terminal from the structured information of multiple different terminals based on the digital identity identifier of the terminal.
[0275] S804, the first functional network element sends structured information to the first network device.
[0276] After determining the structured information of the terminal, the first functional network element sends the structured information to the first network device. The terminal's digital identity and structured information are used to determine whether the terminal has access rights to the first network device.
[0277] S805, the first network device verifies the digital signature information based on the terminal's public key and obtains the verification result.
[0278] In some embodiments, the structured information of the terminal includes key credential information, which indicates the terminal's public key. After receiving the structured information of the terminal, the first network device can determine the terminal's public key based on the key credential information in the structured information, and then verify the digital signature information in the first access request message according to the terminal's public key to obtain the verification result.
[0279] S806, the first network device determines whether the verification result is successful. If not, proceed to S807; if yes, proceed to S808.
[0280] The process of verifying digital signature information is the process of verifying whether the digital signature information was generated based on the terminal's private key.
[0281] S807, the first network device sends the first notification message to the terminal.
[0282] If the verification fails, it indicates that the terminal is not a registered terminal of the first functional network element, and the digital signature information may have been tampered with during transmission. In this case, the first network device will send a first notification message to the terminal. The first notification message is used to inform the terminal that it is not a registered terminal of the first functional network element and therefore does not have access to the first network device.
[0283] S808, the first network device determines whether the access network device information includes the identifier of the first network device.
[0284] If the verification result is successful, it indicates that the digital signature information was generated based on the terminal's private key. This means the terminal is a registered terminal of the first functional network element, and the digital signature information has not been tampered with during transmission. In this case, it is necessary to further determine whether the terminal has access rights to the first network device.
[0285] The first network device can obtain the terminal's access network device information from the terminal's structured information. This access network device information could be, for example, the identifier of a network device that the terminal is allowed to access. Then, the first network device can determine whether the terminal's access network device information includes the identifier of the first network device. If so, the first network device determines that the terminal has access rights to the first network device.
[0286] S809, if the access network device information includes the identifier of the first network device, the first network device sends a query request message to the terminal.
[0287] If the terminal's access network device information includes the identifier of the first network device, the first network device sends a query request message to the terminal. This query request message is used to request a query of the terminal's SUCI, and the terminal receives the query request message accordingly.
[0288] S810, in response to the query request message received from the first network device, the terminal sends the terminal's SUCI to the first network device.
[0289] After receiving the query request message, the terminal sends its SUCI to the first network device, and the first network device receives the terminal's SUCI accordingly.
[0290] S811, the first network device sends a second access request message to the second network device based on the terminal's SUCI.
[0291] The second access request message is used for the terminal to perform initial registration on a second network device, which is the terminal's home network device. The second access request message includes at least one of the following: the terminal's digital identity, the terminal's digital signature information, and the terminal's SUCI. Specifically, after receiving the second access request message, the second network device sends the terminal's SUCI (which may also include digital signature information and the terminal's digital identity) to the first network device's AUSF network element through the second network device's SEAF network element. Then, the AUSF network element in the first network device sends the terminal's SUCI to the UDM network element in the first network device, thus proceeding with subsequent processes (see [link to documentation] for details). Figure 1 The process of the embodiment will not be described in detail here.
[0292] In summary, the solution of this application embodiment, through the unified management of the terminal's digital identity and structured information by the first functional network element, allows the terminal to send a first access request message to the first network device when it needs to access the first network device. This first access request message includes the terminal's digital identity and digital signature information. The first network device then sends the terminal's digital identity to the first functional network element to obtain the terminal's structured information. The first network device verifies the digital signature information using the terminal's public key in the structured information, thereby confirming whether the terminal is registered with the first functional network element. Once the terminal is confirmed to be registered with the first functional network element, the first network device can determine whether the terminal has access rights to the first network device by checking whether the access network device information in the structured information includes the first network device's identifier. This eliminates the need for the terminal's home network device and the first network device to sign a roaming agreement offline, and also avoids frequent signaling interactions, resulting in high efficiency in access control management.
[0293] In the above embodiments, combined with Figure 8 This section introduces the process of managing terminal access permissions when the network device information includes the identifier of the first network device. The following section will combine... Figure 9 This describes the process for managing terminal access permissions when the identifier of the first network device is not included in the network device access information.
[0294] Figure 9 Signaling for the access control method provided in the embodiments of this application Figure 2 ,like Figure 9 As shown, the method may include:
[0295] S901, the terminal sends a first access request message to the first network device.
[0296] S902, the first network device sends a digital identity identifier to the first functional network element.
[0297] S903, the first functional network element determines the structured information of the terminal based on the digital identity identifier.
[0298] S904, the first functional network element sends structured information to the first network device.
[0299] S905, the first network device verifies the digital signature information based on the terminal's public key and obtains the verification result.
[0300] S906, verify whether the verification result is successful. If not, proceed to S907; if yes, proceed to S908.
[0301] S907, the first network device sends the first notification message to the terminal.
[0302] S908, the first network device determines whether the access network device information includes the identifier of the first network device.
[0303] The implementation process of S901 to S908 can be found in the implementation process of S801 to S808 in the above embodiments, and will not be repeated here.
[0304] S909, if the identifier of the first network device is not included in the accessed network device information, the first network device sends the home network device information to the first functional network element.
[0305] If the identifier of the first network device is not included in the access network device information, it does not necessarily mean that the terminal is not allowed to access the first network device. Because the network architecture in a distributed network system is dynamically changing, the terminal may already have access rights to the first network device, but the access network device information in the terminal's structured information has not yet been updated. In this case, the first functional network element needs to determine whether the terminal has access rights to the first network device.
[0306] Therefore, if the identifier of the first network device is not included in the access network device information, the first network device sends the home network device information to the first functional network element.
[0307] S910: The first functional network element determines whether the terminal has access rights to the first network device based on the information of the network device to which it belongs.
[0308] The first functional network element can determine the terminal's structured information based on the terminal's digital identity identifier, thereby obtaining the encryption mechanism identifier from the terminal's structured information and determining the encryption mechanism of the terminal's digital identity identifier. After receiving the home network device information, the first functional network element decrypts the terminal's digital identity identifier according to the encryption mechanism to obtain the terminal's SUCI and the identifier of the second network device, which is the terminal's home network device.
[0309] Then, the first functional network element determines the access control information corresponding to the second network device based on the home network device information, and determines whether the terminal has access rights to the first network device based on the terminal's SUCI and the access control information corresponding to the second network device.
[0310] The access control information corresponding to the second network device is used to indicate the network devices that each of the at least one terminal is allowed to access. The home network device of each of these at least one terminal is the second network device. The access control information corresponding to the second network device can be seen in the example in Table 1 above. In Table 1, at least one terminal includes terminal C and terminal D, and the second network device is the home network device of terminal C and terminal D. If the terminal's SUCI is SUCI3, it can be determined that the network devices the terminal is allowed to access include network device 1 and network device 3. If the first network device is network device 1 or network device 3, the first functional network element can determine that the terminal has access rights to the first network device. If the first network device is not network device 1 or network device 3, the first functional network element can determine that the terminal does not have access rights to the first network device.
[0311] S911, the first functional network element sends a response message to the first network device.
[0312] After the first functional network element determines whether the terminal has access rights to the first network device, the first functional network element sends a response message to the first network device. Correspondingly, the first network device receives the response message sent by the first functional network element, which is used to indicate whether the terminal has access rights to the first network device.
[0313] Optionally, if the response message indicates that the terminal has access to the first network device, the response message may also include the terminal's SUCI. Therefore, after the first network device receives the response message, it can obtain the terminal's SUCI from the response message.
[0314] S912, the first network device determines whether the response message is used to indicate that the terminal has access rights to the first network device. If not, proceed to S913; if yes, proceed to S914.
[0315] S913, the first network device sends a second notification message to the terminal.
[0316] If the response message indicates that the terminal does not have access to the first network device, the first network device sends a second notification message to the terminal, which is used to notify the terminal that it does not have access to the first network device.
[0317] S914, the first network device sends a second access request message to the second network device based on the terminal's SUCI.
[0318] If the response message indicates that the terminal has access to the first network device, the first network device sends a second access request message to the second network device based on the terminal's SUCI, and the second network device receives the second access request message accordingly. The second access request message includes at least one of the terminal's digital identity, the terminal's digital signature information, and the terminal's SUCI. The second access request message is used for the terminal to perform initial registration on the second network device, which is the terminal's home network device. The implementation process of S914 can be found in the relevant description of S811 in the above embodiments, and will not be repeated here.
[0319] In summary, the solution of this application embodiment, through the unified management of the terminal's digital identity and structured information by the first functional network element, allows the terminal to send a first access request message to the first network device when it needs to access the first network device. This first access request message includes the terminal's digital identity and digital signature information. The first network device then sends the terminal's digital identity to the first functional network element to obtain the terminal's structured information. The first network device verifies the digital signature information using the terminal's public key in the structured information, thereby confirming whether the terminal is registered with the first functional network element. If the terminal is confirmed to be registered with the first functional network element, and the access network device information does not include the first network device's identifier, the first functional network element determines whether the terminal has access rights to the first network device. This eliminates the need for the terminal's home network device and the first network device to sign a roaming agreement offline, and also eliminates the need for frequent signaling interactions, resulting in high efficiency in access permission management.
[0320] Figure 10 Schematic diagram of the access control device provided in the embodiments of this application Figure 1 ,like Figure 10 As shown, the device includes: a memory, a transceiver, and a processor.
[0321] The memory 1020 is used to store computer programs; the transceiver 1000 is used to send and receive data under the control of the processor 1010; the processor 1010 is used to read the computer program stored in the memory 1020 and perform the following operations:
[0322] Receives a digital identity identifier sent by the first network device, where the digital identity identifier is the terminal's digital identity identifier;
[0323] Based on the digital identity identifier, determine the terminal's structured information;
[0324] Structured information is sent to the first network device. The digital identity and structured information are used to determine whether the terminal has access rights to the first network device.
[0325] In some embodiments, the structured information includes at least one of the following:
[0326] Type information, used to indicate that the digital identity is a terminal type digital identity;
[0327] Encryption mechanism identifier, used to indicate the encryption mechanism of the digital identity identifier;
[0328] Key credential information, used to indicate the terminal's public key;
[0329] Home network device information, used to indicate the home network device of the terminal;
[0330] Access network device information, used to indicate the network devices that the terminal is allowed to access.
[0331] In some embodiments, a digital identity includes at least one of the following:
[0332] Identifiers for digital identity schemes;
[0333] Identifiers for digital identity methods;
[0334] The terminal's string identifier in the digital identity method is obtained by encrypting the terminal's SUCI and the identifier of the second network device through an encryption mechanism. The second network device is the terminal's home network device.
[0335] In some embodiments, the processor 1010 is also configured to perform the following operations:
[0336] Receive home network device information sent by the first network device;
[0337] Determine whether the terminal has access to the first network device based on the network device information;
[0338] A response message is sent to the first network device, which indicates whether the terminal has access rights to the first network device.
[0339] In some embodiments, determining whether a terminal has access to a first network device based on the home network device information includes:
[0340] The string identifier is decrypted according to the encryption mechanism to obtain the terminal's SUCI and the identifier of the second network device;
[0341] Based on the terminal's SUCI and the access control information corresponding to the second network device, it is determined whether the terminal has access rights to the first network device. The access control information is determined by the home network device information and is used to indicate the network devices that each terminal is allowed to access. The home network devices of each terminal are the second network device.
[0342] In some embodiments, where the response message indicates that the terminal has access to the first network device, the response message may also include the terminal's SUCI.
[0343] Among them, Figure 10 In this context, the bus architecture can include any number of interconnected buses and bridges, specifically linking various circuits together, represented by one or more processors (represented by a processor) and memory (represented by memory). The bus architecture can also link together various other circuits such as peripheral devices, voltage regulators, and power management circuits, which are well known in the art and therefore will not be described further herein. The bus interface provides the interface. The transceiver can be multiple components, including transmitters and receivers, providing units for communicating with various other devices over transmission media, including wireless channels, wired channels, optical fibers, etc. The processor is responsible for managing the bus architecture and general processing, and the memory can store data used by the processor 1010 during operation.
[0344] The processor can be a central processing unit (CPU), an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA), or a complex programmable logic device (CPLD). The processor can also adopt a multi-core architecture.
[0345] The processor 1010 executes any of the methods provided in the embodiments of this application by calling a computer program stored in memory, according to the obtained executable instructions. The processor 1010 and the memory 1020 may also be physically separated.
[0346] It should be noted that the access control device provided in this application embodiment can implement all the method steps implemented in the above method embodiment and can achieve the same technical effect. Here, the parts that are the same as those in the method embodiment and the beneficial effects will not be described in detail.
[0347] Figure 11 Schematic diagram of the access control device provided in the embodiments of this application Figure 2 ,like Figure 11 As shown, the device includes: a memory, a transceiver, and a processor.
[0348] The memory 1120 is used to store computer programs; the transceiver 1100 is used to send and receive data under the control of the processor 1110; the processor 1110 is used to read the computer program stored in the memory 1120 and perform the following operations:
[0349] The receiving terminal sends a first access request message, which includes the terminal's digital identity identifier.
[0350] Send a digital identity identifier to the first functional network element;
[0351] Receive structured information sent by the first functional network element;
[0352] Based on the structured information, determine whether the terminal has access rights to the first network device.
[0353] In some embodiments, the structured information includes at least one of the following:
[0354] Type information, used to indicate that the digital identity is a terminal type digital identity;
[0355] Encryption mechanism identifier, used to indicate the encryption mechanism of the digital identity identifier;
[0356] Key credential information, used to indicate the terminal's public key;
[0357] Home network device information, used to indicate the home network device of the terminal;
[0358] Access network device information, used to indicate the network devices that the terminal is allowed to access.
[0359] In some embodiments, the first access request further includes the terminal's digital signature information. Based on the structured information, determining whether the terminal has access to the first network device includes:
[0360] The digital signature information is verified using the terminal's public key to obtain the verification result;
[0361] If the verification result is successful, determine whether the terminal has access rights to the first network device based on the home network device information and / or the access network device information.
[0362] In some embodiments, determining whether the terminal has access rights to the first network device based on the home network device information and / or the access network device information includes:
[0363] If the network device access information includes the identifier of the first network device, it is determined that the terminal has access rights to the first network device.
[0364] In some embodiments, the processor 1110 is also configured to perform the following operations:
[0365] Send a query request message to the terminal. The query request message is used to request the query terminal's SUCI.
[0366] SUCI sent by the receiving terminal;
[0367] According to SUCI, a second access request message is sent to the second network device. The second access request message is used for the terminal to perform initial registration on the second network device, which is the terminal's home network device.
[0368] In some embodiments, determining whether a terminal has access to a first network device based on the home network device information and / or the access network device information includes:
[0369] If the identifier of the first network device is not included in the accessed network device information, send the home network device information to the first functional network element.
[0370] The terminal receives a response message sent by the first functional network element. The response message is used to indicate whether the terminal has access rights to the first network device.
[0371] In some embodiments, when the response message indicates that the terminal has access rights to the first network device, the response message also includes the terminal's SUCI, and the processor 1110 is further configured to perform the following operations:
[0372] According to SUCI, a second access request message is sent to the second network device. The second access request message is used for the terminal to perform initial registration on the second network device, which is the terminal's home network device.
[0373] In some embodiments, the second access request message includes at least one of the following:
[0374] Digital identity;
[0375] Digital signature information;
[0376] SUCI of the terminal.
[0377] In some embodiments, a digital identity includes at least one of the following:
[0378] Identifiers for digital identity schemes;
[0379] Identifiers for digital identity methods;
[0380] The terminal's string identifier in the digital identity method is obtained by encrypting the terminal's SUCI and the identifier of the second network device through an encryption mechanism. The second network device is the terminal's home network device.
[0381] Among them, Figure 11 In this context, the bus architecture can include any number of interconnected buses and bridges, specifically linking various circuits together, represented by one or more processors (represented by a processor) and memory (represented by a memory). The bus architecture can also link together various other circuits such as peripheral devices, voltage regulators, and power management circuits, which are well known in the art and therefore will not be described further herein. The bus interface provides the interface. The transceiver can be multiple components, including transmitters and receivers, providing a unit for communicating with various other devices over transmission media, including wireless channels, wired channels, optical fibers, etc. The processor is responsible for managing the bus architecture and general processing, and the memory can store data used by the processor 1110 during operation.
[0382] The processor can be a CPU, ASIC, FPGA, or CPLD, and it can also adopt a multi-core architecture.
[0383] The processor 1110 executes any of the methods provided in the embodiments of this application according to the obtained executable instructions by calling a computer program stored in the memory. The processor 1110 and the memory 1120 may also be physically separated.
[0384] It should be noted that the access control device provided in this application embodiment can implement all the method steps implemented in the above method embodiment and can achieve the same technical effect. Here, the parts that are the same as those in the method embodiment and the beneficial effects will not be described in detail.
[0385] Figure 12 Schematic diagram of the access control device provided in the embodiments of this application Figure 3 ,like Figure 12 As shown, the device includes: a memory, a transceiver, and a processor.
[0386] The memory 1220 is used to store computer programs; the transceiver 1200 is used to send and receive data under the control of the processor 1210; the processor 1210 is used to read the computer program stored in the memory 1220 and perform the following operations:
[0387] A first access request message is sent to a first network device. The first access request message includes the terminal's digital identity identifier. The digital identity identifier is used to obtain the terminal's structured information. The digital identity identifier and the structured information are used to determine whether the terminal has access rights to the first network device.
[0388] In some embodiments, the structured information includes at least one of the following:
[0389] Type information, used to indicate that the digital identity is a terminal type digital identity;
[0390] Encryption mechanism identifier, used to indicate the encryption mechanism of the digital identity identifier;
[0391] Key credential information, used to indicate the terminal's public key;
[0392] Home network device information, used to indicate the home network device of the terminal;
[0393] Access network device information, used to indicate the network devices that the terminal is allowed to access.
[0394] In some embodiments, a digital identity includes at least one of the following:
[0395] Identifiers for digital identity schemes;
[0396] Identifiers for digital identity methods;
[0397] The terminal's string identifier in the digital identity method is obtained by encrypting the terminal's SUCI and the identifier of the second network device through an encryption mechanism. The second network device is the terminal's home network device.
[0398] In some embodiments, the processor 1210 is also configured to perform the following operations:
[0399] In response to a query request message received from the first network device, the terminal sends its SUCI to the first network device.
[0400] Among them, Figure 12 In this context, the bus architecture can include any number of interconnected buses and bridges, specifically linking various circuits of one or more processors represented by processor 1210 and memory represented by memory 1220 together. The bus architecture can also link various other circuits such as peripheral devices, voltage regulators, and power management circuits, which are well known in the art and therefore will not be described further herein. The bus interface provides an interface. The transceiver can be multiple components, including transmitters and receivers, providing a unit for communicating with various other devices over a transmission medium, including wireless channels, wired channels, optical fibers, etc. For different user equipment, the user interface 1230 can also be an interface capable of connecting external or internal devices, including but not limited to keypads, displays, speakers, microphones, joysticks, etc.
[0401] The processor 1210 is responsible for managing the bus architecture and general processing, and the memory 1220 can store the data used by the processor 1210 when performing operations.
[0402] Optionally, the processor 1210 can be a CPU, ASIC, FPGA or CPLD, and the processor 1210 can also adopt a multi-core architecture.
[0403] The processor 1210 executes any of the methods provided in the embodiments of this application according to the obtained executable instructions by calling the program stored in the memory 1220. The processor 1210 and the memory 1220 may also be physically separated.
[0404] It should be noted that the access control device provided in this application embodiment can implement all the method steps implemented in the above method embodiment and can achieve the same technical effect. Here, the parts that are the same as those in the method embodiment and the beneficial effects will not be described in detail.
[0405] Figure 13 Schematic diagram of the access control device provided in the embodiments of this application Figure 4 ,like Figure 13 As shown, the device includes: a memory, a transceiver, and a processor.
[0406] The memory 1320 is used to store computer programs; the transceiver 1300 is used to send and receive data under the control of the processor 1310; the processor 1310 is used to read the computer program stored in the memory 1320 and perform the following operations:
[0407] The terminal receives a second access request message sent by a first network device. The second access request message is used for the terminal to perform initial registration on the second network device, which is the terminal's home network device.
[0408] In some embodiments, the structured information includes at least one of the following:
[0409] Type information, used to indicate that the digital identity is a terminal type digital identity;
[0410] Encryption mechanism identifier, used to indicate the encryption mechanism of the digital identity identifier;
[0411] Key credential information, used to indicate the terminal's public key;
[0412] Home network device information, used to indicate the home network device of the terminal;
[0413] Access network device information, used to indicate the network devices that the terminal is allowed to access.
[0414] In some embodiments, a digital identity includes at least one of the following:
[0415] Identifiers for digital identity schemes;
[0416] Identifiers for digital identity methods;
[0417] The terminal's string identifier in the digital identity method is obtained by encrypting the terminal's SUCI and the identifier of the second network device through an encryption mechanism. The second network device is the terminal's home network device.
[0418] In some embodiments, the processor is also configured to perform the following operations:
[0419] Send access control information corresponding to the second network device to the first functional network element, wherein the access control information is used to indicate the network devices that at least one terminal is allowed to access, and the network devices to which at least one terminal belongs are the second network devices.
[0420] Among them, Figure 13 In this context, the bus architecture can include any number of interconnected buses and bridges, specifically linking various circuits together, represented by one or more processors (represented by a processor) and memory (represented by memory). The bus architecture can also link together various other circuits such as peripheral devices, voltage regulators, and power management circuits, which are well known in the art and therefore will not be described further herein. The bus interface provides the interface. The transceiver can be multiple components, including transmitters and receivers, providing a unit for communicating with various other devices over transmission media, including wireless channels, wired channels, optical fibers, etc. The processor is responsible for managing the bus architecture and general processing, and the memory can store data used by the processor 1310 during operation.
[0421] The processor can be a CPU, ASIC, FPGA, or CPLD, and it can also adopt a multi-core architecture.
[0422] The processor 1310 executes any of the methods provided in the embodiments of this application according to the obtained executable instructions by calling a computer program stored in the memory. The processor 1310 and the memory 1320 may also be physically separated.
[0423] It should be noted that the access control device provided in this application embodiment can implement all the method steps implemented in the above method embodiment and can achieve the same technical effect. Here, the parts that are the same as those in the method embodiment and the beneficial effects will not be described in detail.
[0424] Figure 14 Schematic diagram of the access control device provided in the embodiments of this application Figure 5 .like Figure 14 As shown, the access control device 140 includes:
[0425] The first receiving module 141 is used to receive a digital identity identifier sent by the first network device, wherein the digital identity identifier is the digital identity identifier of the terminal.
[0426] The first processing module 142 is used to determine the structured information of the terminal based on the digital identity identifier;
[0427] The first sending module 143 is used to send structured information to the first network device. The digital identity and structured information are used to determine whether the terminal has access rights to the first network device.
[0428] In some embodiments, the structured information includes at least one of the following:
[0429] Type information, used to indicate that the digital identity is a terminal type digital identity;
[0430] Encryption mechanism identifier, used to indicate the encryption mechanism of the digital identity identifier;
[0431] Key credential information, used to indicate the terminal's public key;
[0432] Home network device information, used to indicate the home network device of the terminal;
[0433] Access network device information, used to indicate the network devices that the terminal is allowed to access.
[0434] In some embodiments, a digital identity includes at least one of the following:
[0435] Identifiers for digital identity schemes;
[0436] Identifiers for digital identity methods;
[0437] The terminal's string identifier in the digital identity method is obtained by encrypting the terminal's SUCI and the identifier of the second network device through an encryption mechanism. The second network device is the terminal's home network device.
[0438] In some embodiments,
[0439] The first receiving module 141 is further configured to receive home network device information sent by the first network device;
[0440] The first processing module 142 is further configured to determine whether the terminal has access rights to the first network device based on the home network device information.
[0441] The first sending module 143 is further configured to send a response message to the first network device, the response message being used to indicate whether the terminal has access rights to the first network device.
[0442] In some embodiments, the first processing module 142 is further configured to:
[0443] The string identifier is decrypted according to the encryption mechanism to obtain the terminal's SUCI and the identifier of the second network device;
[0444] Based on the terminal's SUCI and the access control information corresponding to the second network device, it is determined whether the terminal has access rights to the first network device. The access control information is determined by the home network device information and is used to indicate the network devices that at least one terminal is allowed to access. The home network devices of at least one terminal are the second network device.
[0445] In some embodiments, where the response message indicates that the terminal has access to the first network device, the response message may also include the terminal's SUCI.
[0446] It should be noted that the access control device 140 provided in this application can implement all the method steps implemented by the first functional network element in the above method embodiment and can achieve the same technical effect. Here, the parts that are the same as those in the method embodiment and the beneficial effects will not be described in detail.
[0447] Figure 15 Schematic diagram of the access control device provided in the embodiments of this application Figure 6 .like Figure 15 As shown, the access control device 150 includes:
[0448] The second receiving module 151 is used to receive a first access request message sent by the terminal, wherein the first access request message includes the digital identity identifier of the terminal.
[0449] The second sending module 152 is used to send a digital identity identifier to the first functional network element;
[0450] The third receiving module 153 is used to receive structured information sent by the first functional network element;
[0451] The second processing module 154 is used to determine whether the terminal has access rights to the first network device based on the structured information.
[0452] In some embodiments, the structured information includes at least one of the following:
[0453] Type information, used to indicate that the digital identity is a terminal type digital identity;
[0454] Encryption mechanism identifier, used to indicate the encryption mechanism of the digital identity identifier;
[0455] Key credential information, used to indicate the terminal's public key;
[0456] Home network device information, used to indicate the home network device of the terminal;
[0457] Access network device information, used to indicate the network devices that the terminal is allowed to access.
[0458] In some embodiments, the first access request further includes the terminal's digital signature information, and the second processing module 154 is specifically used for:
[0459] The digital signature information is verified using the terminal's public key to obtain the verification result;
[0460] If the verification result is successful, determine whether the terminal has access rights to the first network device based on the home network device information and / or the access network device information.
[0461] In some embodiments, the second processing module 154 is specifically used for:
[0462] If the network device access information includes the identifier of the first network device, it is determined that the terminal has access rights to the first network device.
[0463] In some embodiments,
[0464] The second sending module 152 is also used to send a query request message to the terminal, the query request message being used to request a query of the terminal's SUCI;
[0465] The third receiving module 153 is also used to receive SUCI sent by the terminal;
[0466] The second sending module 152 is further configured to send a second access request message to the second network device according to SUCI. The second access request message is used for the terminal to perform initial registration on the second network device, which is the terminal's home network device.
[0467] In some embodiments, the second processing module 154 is specifically used for:
[0468] If the identifier of the first network device is not included in the accessed network device information, send the home network device information to the first functional network element.
[0469] The terminal receives a response message sent by the first functional network element. The response message is used to indicate whether the terminal has access rights to the first network device.
[0470] In some embodiments, where the response message indicates that the terminal has access to the first network device, the response message also includes the terminal's SUCI, and the second sending module 152 is further configured to:
[0471] According to SUCI, a second access request is sent to the second network device. The second access request is used for the terminal to perform initial registration on the second network device, which is the terminal's home network device.
[0472] In some embodiments, the second access request message includes at least one of the following:
[0473] Digital identity;
[0474] Digital signature information;
[0475] SUCI of the terminal.
[0476] In some embodiments, a digital identity includes at least one of the following:
[0477] Identifiers for digital identity schemes;
[0478] Identifiers for digital identity methods;
[0479] The terminal's string identifier in the digital identity method is obtained by encrypting the terminal's SUCI and the identifier of the second network device through an encryption mechanism. The second network device is the terminal's home network device.
[0480] It should be noted that the access control device 150 provided in this application can implement all the method steps implemented by the first network device in the above method embodiment and can achieve the same technical effect. Here, the parts that are the same as those in the method embodiment and the beneficial effects will not be described in detail.
[0481] Figure 16 Schematic diagram of the access control device provided in the embodiments of this application Figure 7 .like Figure 16 As shown, the access control device 160 includes:
[0482] The first transceiver module 161 is used to send a first access request message to the first network device. The first access request message includes a digital identity identifier of the terminal. The digital identity identifier is used to obtain the structured information of the terminal. The digital identity identifier and the structured information are used to determine whether the terminal has access rights to the first network device.
[0483] In some embodiments, the structured information includes at least one of the following:
[0484] Type information, used to indicate that the digital identity is a terminal type digital identity;
[0485] Encryption mechanism identifier, used to indicate the encryption mechanism of the digital identity identifier;
[0486] Key credential information, used to indicate the terminal's public key;
[0487] Home network device information, used to indicate the home network device of the terminal;
[0488] Access network device information, used to indicate the network devices that the terminal is allowed to access.
[0489] In some embodiments, a digital identity includes at least one of the following:
[0490] Identifiers for digital identity schemes;
[0491] Identifiers for digital identity methods;
[0492] The terminal's string identifier in the digital identity method is obtained by encrypting the terminal's SUCI and the identifier of the second network device through an encryption mechanism. The second network device is the terminal's home network device.
[0493] In some embodiments, the first transceiver module 161 is further configured to:
[0494] In response to a query request message received from the first network device, the terminal sends its SUCI to the first network device.
[0495] It should be noted that the access control device 160 provided in this application can implement all the method steps implemented by the terminal in the above method embodiment and can achieve the same technical effect. Here, the parts that are the same as those in the method embodiment and the beneficial effects will not be described in detail.
[0496] Figure 17 Schematic diagram of the access control device provided in the embodiments of this application Figure 8 .like Figure 17 As shown, the access control device 170 includes:
[0497] The second transceiver module 171 is used to receive a second access request message sent by the first network device. The second access request message is used for the terminal to perform initial registration on the second network device, which is the terminal's home network device.
[0498] In some embodiments, the second access request includes at least one of the following:
[0499] Digital identity;
[0500] Digital signature information;
[0501] SUCI of the terminal.
[0502] In some embodiments, a digital identity includes at least one of the following:
[0503] Identifiers for digital identity schemes;
[0504] Identifiers for digital identity methods;
[0505] The terminal's string identifier in the digital identity method is obtained by encrypting the terminal's SUCI and the identifier of the second network device through an encryption mechanism. The second network device is the terminal's home network device.
[0506] In some embodiments, the second transceiver module 171 is further configured to:
[0507] Send access control information corresponding to the second network device to the first functional network element, wherein the access control information is used to indicate the network devices that at least one terminal is allowed to access, and the network devices to which at least one terminal belongs are the second network devices.
[0508] It should be noted that the access control device 170 provided in this application can implement all the method steps implemented by the second network device in the above method embodiment and can achieve the same technical effect. Here, the parts that are the same as those in the method embodiment and the beneficial effects will not be described in detail.
[0509] It should be noted that the division of units in the embodiments of this application is illustrative and only represents one logical functional division. In actual implementation, other division methods may be used. Furthermore, the functional units in the various embodiments of this application can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated units described above can be implemented in hardware or as software functional units.
[0510] If the integrated unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a processor-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) or processor to execute all or part of the steps of the methods of the various embodiments of this application.
[0511] It should be noted that the apparatus provided in this application embodiment can implement all the method steps implemented in the above method embodiment and can achieve the same technical effect. Here, the parts that are the same as those in the method embodiment and the beneficial effects will not be described in detail.
[0512] This application also provides a processor-readable storage medium storing a computer program for causing the processor to execute all the method steps in the above method embodiments.
[0513] Non-transiently readable storage media can be any available medium or data storage device that the processor can access, including but not limited to magnetic storage (e.g., floppy disks, hard disks, magnetic tapes, magneto-optical disks (MOs), etc.), optical storage (e.g., CDs, DVDs, BDs, HVDs, etc.), and semiconductor storage (e.g., ROMs, EPROMs, EEPROMs, non-volatile memory (NAND flash), solid-state drives (SSDs)).
[0514] This application also provides a computer program product, including a computer program that, when executed by a processor, implements any of the methods described in the above-described method embodiments.
[0515] Processor-readable storage media can be any available medium or data storage device that the processor can access, including but not limited to magnetic storage (e.g., floppy disks, hard disks, magnetic tapes, magneto-optical disks (MOs), etc.), optical storage (e.g., CDs, DVDs, BDs, HVDs, etc.), and semiconductor storage (e.g., ROMs, EPROMs, EEPROMs, non-volatile memory (NAND flash), solid-state drives (SSDs)).
[0516] Those skilled in the art will understand that embodiments of this application can be provided as methods, systems, or computer program products. Therefore, this application can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, this application can take the form of a computer program product implemented on one or more computer-usable storage media (including, but not limited to, disk storage and optical storage) containing computer-usable program code.
[0517] This application is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of this application. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer-executable instructions. These computer-executable instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, generate instructions for implementing the flowchart... Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.
[0518] These processor-executable instructions may also be stored in a processor-readable memory that can direct a computer or other programmable data processing device to operate in a particular manner, such that the instructions stored in the processor-readable memory produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.
[0519] Obviously, those skilled in the art can make various modifications and variations to this application without departing from the spirit and scope of this application. Therefore, if such modifications and variations fall within the scope of the claims of this application and their equivalents, this application also intends to include such modifications and variations.
Claims
1. An access control method, characterized in that, Applied to a first functional network element, the method includes: Receive a digital identity identifier sent by a first network device, wherein the digital identity identifier is the digital identity identifier of the terminal; Based on the digital identity identifier, the structured information of the terminal is determined; The structured information is sent to the first network device, and the digital identity and the structured information are used to determine whether the terminal has access rights to the first network device.
2. The method according to claim 1, characterized in that, The structured information includes at least one of the following: Type information, used to indicate that the digital identity is a terminal type digital identity; An encryption mechanism identifier is used to indicate the encryption mechanism of the digital identity identifier; Key credential information, used to indicate the public key of the terminal; Home network device information, used to indicate the home network device of the terminal; Access network device information, used to indicate the network devices that the terminal is allowed to access.
3. The method according to claim 2, characterized in that, The digital identity identifier includes at least one of the following: Identifiers for digital identity schemes; Identifiers for digital identity methods; The string identifier of the terminal in the digital identity method is obtained by encrypting the terminal's subscription hidden identifier SUCI and the identifier of the second network device through the encryption mechanism. The second network device is the terminal's home network device.
4. The method according to claim 3, characterized in that, The method further includes: Receive the home network device information sent by the first network device; Determine whether the terminal has access to the first network device based on the home network device information; A response message is sent to the first network device, the response message indicating whether the terminal has access rights to the first network device.
5. The method according to claim 4, characterized in that, Determining whether the terminal has access to the first network device based on the home network device information includes: The string identifier is decrypted according to the encryption mechanism to obtain the SUCI of the terminal; Based on the SUCI of the terminal and the access control information corresponding to the second network device, it is determined whether the terminal has access rights to the first network device. The access control information is determined by the home network device information and is used to indicate the network devices that at least one terminal is allowed to access. The home network devices of the at least one terminal are the second network device.
6. The method according to claim 4 or 5, characterized in that, If the response message indicates that the terminal has access to the first network device, the response message may also include the terminal's SUCI.
7. An access control method, characterized in that, Applied to a first network device, the method includes: The receiving terminal sends a first access request message, the first access request message including the digital identity identifier of the terminal; Send the digital identity identifier to the first functional network element; Receive the structured information of the terminal sent by the first functional network element; Based on the structured information, it is determined whether the terminal has access rights to the first network device.
8. The method according to claim 7, characterized in that, The structured information includes at least one of the following: Type information, used to indicate that the digital identity is a terminal type digital identity; An encryption mechanism identifier is used to indicate the encryption mechanism of the digital identity identifier; Key credential information, used to indicate the public key of the terminal; Home network device information, used to indicate the home network device of the terminal; Access network device information, used to indicate the network devices that the terminal is allowed to access.
9. The method according to claim 8, characterized in that, The first access request also includes the digital signature information of the terminal. The step of determining whether the terminal has access rights to the first network device based on the structured information includes: The digital signature information is verified using the public key of the terminal to obtain a verification result; If the verification result is successful, it is determined whether the terminal has access rights to the first network device based on the home network device information and / or the access network device information.
10. The method according to claim 9, characterized in that, The step of determining whether the terminal has access rights to the first network device based on the home network device information and / or the access network device information includes: If the access network device information includes the identifier of the first network device, it is determined that the terminal has access rights to the first network device.
11. The method according to claim 10, characterized in that, The method further includes: Send a query request message to the terminal, the query request message being used to request a query of the terminal's SUCI; Receive the SUCI sent by the terminal; According to the SUCI, a second access request message is sent to the second network device. The second access request message is used for the terminal to perform initial registration on the second network device, which is the terminal's home network device.
12. The method according to claim 9, characterized in that, The step of determining whether the terminal has access rights to the first network device based on the home network device information and / or the access network device information includes: If the identifier of the first network device is not included in the access network device information, the home network device information is sent to the first functional network element. The terminal receives a response message sent by the first functional network element, the response message being used to indicate whether the terminal has access rights to the first network device.
13. The method according to claim 12, characterized in that, If the response message indicates that the terminal has access rights to the first network device, and the response message also includes the terminal's SUCI, the method further includes: According to the SUCI, a second access request message is sent to the second network device. The second access request message is used for the terminal to perform initial registration on the second network device, which is the terminal's home network device.
14. The method according to claim 11 or 13, characterized in that, The second access request message includes at least one of the following: The digital identity identifier; The digital signature information; The terminal's SUCI.
15. The method according to any one of claims 8-14, characterized in that, The digital identity identifier includes at least one of the following: Identifiers for digital identity schemes; Identifiers for digital identity methods; The string identifier of the terminal in the digital identity method is obtained by encrypting the SUCI of the terminal and the identifier of the second network device through the encryption mechanism, wherein the second network device is the home network device of the terminal.
16. An access control method, characterized in that, Applied to a terminal, the method includes: A first access request message is sent to a first network device. The first access request message includes the digital identity identifier of the terminal. The digital identity identifier is used to obtain the structured information of the terminal. The digital identity identifier and the structured information are used to determine whether the terminal has access rights to the first network device.
17. The method according to claim 16, characterized in that, The method further includes: In response to the received query request message sent by the first network device, the terminal's SUCI is sent to the first network device.
18. An access control method, characterized in that, Applied to a second network device, the method includes: The terminal receives a second access request message sent by a first network device, the second access request message being used for initial registration of the terminal on the second network device, the second network device being the terminal's home network device.
19. The method according to claim 18, characterized in that, The method further includes: Send access control information corresponding to the second network device to the first functional network element, wherein the access control information is used to indicate the network devices that at least one terminal is allowed to access, and the home network devices of the at least one terminal are the second network device.
20. An access control device, characterized in that, Includes memory, transceiver, and processor: Memory, used to store computer programs; Transceiver, used to send and receive data under the control of the processor; A processor for reading a computer program from the memory and executing the access control method according to any one of claims 1-6.
21. An access control device, characterized in that, Includes memory, transceiver, and processor: Memory, used to store computer programs; Transceiver, used to send and receive data under the control of the processor; A processor for reading a computer program from the memory and executing the access control method according to any one of claims 7-15.
22. An access control device, characterized in that, Includes memory, transceiver, and processor: Memory, used to store computer programs; Transceiver, used to send and receive data under the control of the processor; A processor for reading a computer program from the memory and executing the access control method according to any one of claims 16-17.
23. An access control device, characterized in that, Includes memory, transceiver, and processor: Memory, used to store computer programs; Transceiver, used to send and receive data under the control of the processor; A processor for reading a computer program from the memory and executing the access control method according to any one of claims 18-19.
24. A non-transiently readable storage medium, characterized in that, The non-transiently readable storage medium stores a computer program that causes a processor to perform the method according to any one of claims 1 to 19.