Authentication method, device and system, storage medium and computer program product
By generating and encrypting password values in wireless base station equipment and combining them with dynamic codes from the management server for dual authentication, the problem of static account password authentication mechanisms being easily cracked is solved, thereby improving the security of wireless base station equipment and the stability of communication networks.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- CHINA MOBILE COMM LTD RES INST
- Filing Date
- 2026-01-09
- Publication Date
- 2026-05-12
AI Technical Summary
The static account password authentication mechanism of wireless base station equipment is easily cracked, leading to network security threats to mobile communication networks. In particular, the local operation and maintenance management ports of wireless base station equipment in open or semi-open areas are vulnerable to attack.
A dynamic authentication method is adopted, in which a password value is generated by the network device, encrypted and sent to the terminal device, and combined with a dynamic code generated by the management server for dual authentication to ensure the security of the terminal device.
It reduces the possibility of attacks on local operation and maintenance management ports, improves the security and stability of mobile communication networks, and ensures the security and reliability of terminal devices.
Smart Images

Figure CN122028038A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of wireless communication technology, and in particular to an authentication method, apparatus, system, storage medium, and computer program product. Background Technology
[0002] With the long-term iterative evolution of mobile communication technology, wireless base stations, which undertake wireless access functions, have also evolved into various types, mainly including macro base stations, micro base stations, pico base stations, and femto base stations. Wireless base station hardware mainly consists of three categories of equipment: core processing unit equipment, such as the Building Baseband Unit (BBU), Centralized Unit (CU), Distributed Unit (DU), Active Antenna Unit (AAU) in the radio frequency and antenna system, and traditional Radio Remote Unit (RRU), as well as supporting hardware such as power systems, cooling systems, and transmission equipment. Among these, the core wireless base station equipment, such as the BBU, CU, DU, AAU, and RRU, all have management ports, allowing technicians to log in locally to perform corresponding operation and maintenance management operations.
[0003] In implementing operation and maintenance management, a static account and password authentication mechanism is typically used. This involves authenticating through pre-set operation and maintenance management accounts and passwords for the device. However, these pre-set accounts and passwords are widely known and used by operation and maintenance technicians, posing a high risk of leakage. Furthermore, wireless base station equipment is located at the edge of the mobile communication network, typically deployed in open or semi-open areas. The local operation and maintenance management ports reserved on the device are easily accessible and exploited by attackers. If an attacker obtains a leaked operation and maintenance management account and password, they can easily infiltrate the device and gain control of the system, subsequently launching attacks on other devices within the mobile communication network and threatening the network's security. Addressing these risks has become a pressing technical challenge. Summary of the Invention
[0004] To address the aforementioned technical problems, this application aims to provide an authentication method, apparatus, system, storage medium, and computer program product. This addresses the issue that static account password authentication mechanisms are easily cracked during the operation and maintenance of current wireless base station equipment, posing a security threat. The application proposes an authentication method that performs dynamic authentication based on the static account password authentication mechanism, reducing the likelihood of attacks on local operation and maintenance management ports and ensuring the security of mobile communication networks.
[0005] The technical solution of this application is implemented as follows: This application provides an authentication method, which is applied to a network device, and the method includes: After confirming that the terminal device has passed static identity authentication, a password value is generated; The password value is encrypted using the first encryption key to obtain the first encrypted information; The first encrypted information and the first identity identifier of the network device are sent to the terminal device, so that the terminal device requests the management server to perform dynamic identity authentication for the terminal device based on the first encrypted information and the first identity identifier.
[0006] Optionally, after sending the first encrypted information and the first identity identifier of the network device to the terminal device, the method further includes: Obtain the first dynamic code; wherein the first dynamic code is generated by the management server; Based on the first dynamic code and the password value, the terminal device is authenticated to obtain a verification result; wherein, the verification result is used to indicate whether the terminal device has passed dynamic identity authentication.
[0007] Optionally, the step of authenticating the terminal device based on the first dynamic code and the password value to obtain the authentication result includes: Check the validity period of the password value; If the password value is currently within its validity period, verify whether the first dynamic code matches the password value, and obtain the matching result; Based on the matching results, the verification result is determined.
[0008] Optionally, the method further includes: If the verification result indicates that the terminal device has passed dynamic authentication, the password value will be cleared. Based on the device information of the terminal device, the password value, and the verification result, authentication log information is generated.
[0009] Optionally, the method further includes: The verification result is sent to the terminal device.
[0010] Optionally, the method further includes: Before the network device leaves the factory, a first request for identity information is sent to the management server, so that the management server assigns a first identity identifier and a first encryption key to the network device to the network management terminal. Receive the first identity identifier and the first encryption key sent by the network management terminal; Store the first identity identifier and the first encryption key.
[0011] Optionally, the method further includes: An update request is sent to the network management terminal, so that the network management terminal sends the update request to the management server to request an update of the encryption key; wherein the update request includes at least the first identity identifier.
[0012] Optionally, the method further includes: Receive a second encryption key sent by the network management terminal; wherein, the second encryption key is key information generated by the management server based on the first identity identifier and sent to the network management terminal; Update the network device's current encryption key to the first encryption information.
[0013] This application provides an authentication method applied to a management server, the method comprising: The terminal device receives first encrypted information and a first identity identifier; wherein the first identity identifier is used to identify the network device, and the first encrypted information is dynamic encrypted information generated by the network device to verify the identity information of the terminal device. The first encrypted information is decrypted based on the first decryption information corresponding to the first identity identifier to obtain the first dynamic code; The first dynamic code is output so that the network device can perform dynamic identity authentication of the terminal device through the first dynamic code.
[0014] Optionally, outputting the first dynamic code includes: Output the first dynamic code to the terminal device; or... The first dynamic code is output to the display interface of the management server.
[0015] Optionally, the method further includes: If a first request is received from the network device, the first request is sent to the network management terminal; wherein, the first request is used to assign an identity identifier and an encryption key to the network device.
[0016] Optionally, before receiving the first encrypted information and the first identity identifier sent by the receiving terminal device, the method further includes: The network device receives an update request from the network management terminal. The update request is a request sent by the network device to the network management terminal to request an update of the network device's encryption key. The update request includes at least the network device's first identity identifier.
[0017] Optionally, the method further includes: Based on the first identity identifier included in the update request, a key pair is generated; wherein the key pair includes a second encryption key and a second decryption key; The second encryption key is sent to the network management terminal, so that the network management terminal sends the second encryption key to the network device to update the encryption key.
[0018] This application provides a first authentication device, which is applied to a network device. The device includes: a generation unit, an encryption unit, and a first sending unit; wherein: The generation unit is used to generate a password value after the terminal device has passed static identity authentication; The encryption unit is used to encrypt the password value using a first encryption key to obtain first encrypted information; The first sending unit is configured to send the first encrypted information and the first identity identifier of the network device to the terminal device, so that the terminal device requests the management server to perform dynamic identity authentication on the terminal device based on the first encrypted information and the first identity identifier.
[0019] This application provides a second authentication device, which is applied to a management server. The device includes: a first receiving unit, a decryption unit, and an output unit; wherein: The first receiving unit is configured to receive first encrypted information and a first identity identifier sent by the terminal device; wherein, the first identity identifier is used to identify the network device, and the first encrypted information is dynamically encrypted information generated by the network device; The decryption unit is used to decrypt the first encrypted information based on the first decryption information corresponding to the first identity identifier to obtain the first dynamic code; The output unit is used to output the first dynamic code so that the network device can perform dynamic identity authentication of the terminal device through the first dynamic code.
[0020] This application provides an authentication system, which includes at least: a terminal device, a network device, and a management server; wherein: The terminal device is used for equipment maintenance of the network device; The network device is configured to implement the steps of the authentication method as described in any of the above claims; The management server is used to implement the steps of the authentication method as described in any of the above.
[0021] This application provides a storage medium storing an authentication program, which, when executed, implements the steps of the authentication method as described in any of the preceding claims.
[0022] This application provides a computer program product, including a computer program that, when executed by a processor, implements the steps of the authentication method as described in any of the preceding claims.
[0023] This application provides an authentication method, apparatus, system, storage medium, and computer program product. After a network device determines that a terminal device has passed static identity authentication, it generates a password value, encrypts the password value using a first encryption key to obtain first encrypted information, and sends the first encrypted information and the network device's first identity identifier to the terminal device. This allows the terminal device to request a management server to perform dynamic identity authentication based on the first encrypted information and the first identity identifier. After receiving the first encrypted information and the first identity identifier sent by the terminal device, the management server decrypts the first encrypted information based on the first decryption information corresponding to the first identity identifier to obtain a first dynamic code, and outputs the first dynamic code. In this way, when the network device determines that the terminal device has passed static identity authentication, the network device generates a password value and encrypts the password value using a pre-stored first encryption key to obtain the first encrypted information. The network device then sends the first encrypted information and the network device's first identity identifier to the terminal device. The terminal device then sends the received first encrypted information and the network device's first identity identifier to the management server. The management server, based on the first identity identifier reported by the terminal device, obtains the corresponding first decryption information to decrypt the first encrypted information, obtaining a first dynamic code. This first dynamic code is then output so that the terminal device can be re-authenticated using the first dynamic code, thus realizing the dynamic identity authentication process. In this way, while the terminal device passes static identity authentication, it also undergoes dynamic identity authentication based on the management server, achieving dual identity authentication for the terminal device. This ensures the security and reliability of the terminal device and solves the problem of the static account password authentication mechanism being easily cracked and causing security threats in the current wireless base station equipment operation and maintenance process. This proposes an authentication method that performs dynamic authentication based on the static account password authentication mechanism, reducing the possibility of attacks on the local operation and maintenance management port and ensuring the security of the mobile communication network. Attached Figure Description
[0024] Figure 1 A flowchart illustrating an authentication method provided in an embodiment of this application; Figure 2 A flowchart illustrating another authentication method provided in an embodiment of this application; Figure 3 This application provides a schematic diagram of the connection between devices according to an embodiment of the present application; Figure 4 This application provides a schematic diagram of information flow between devices. Figure 5 A schematic diagram of an application embodiment provided in this application. Figure 1 ; Figure 6 A schematic diagram of an application embodiment provided in this application. Figure 2 ; Figure 7 This is a schematic diagram of the structure of a first authentication device provided in an embodiment of this application; Figure 8 This is a schematic diagram of the structure of a second authentication device provided in an embodiment of this application; Figure 9 This is a schematic diagram of the structure of an authentication system provided in an embodiment of this application. Detailed Implementation
[0025] The technical solutions in the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings.
[0026] The embodiments of this application provide an authentication method, referring to Figure 1 As shown, the method is applied to a network device and includes the following steps: Step 101: After confirming that the terminal device has passed static identity authentication, generate a password value.
[0027] In this embodiment, the network device is a device used to provide communication network services to mobile terminal devices, such as a base station or a wireless network access node. The network device also supports local connection for management operations. The terminal device can be a field maintenance terminal used for on-site operation and maintenance management of the network device, such as a computer device like a laptop computer, used for authentication and interaction with the network device.
[0028] When the network device is a base station, it can specifically be a wireless base station device, which can be a main wireless base station device with a local management port, including the baseband processing unit (BBU), centralized unit (CU), and distributed unit (DU) in the core processing unit device, as well as the active antenna unit (AAU) and traditional radio remote unit (RRU) in the radio frequency and antenna system.
[0029] A field maintenance terminal is a computer terminal device, such as a laptop, used by base station maintenance technicians at the maintenance site to connect to the local management port of the wireless base station equipment. Field maintenance terminals typically have base station maintenance management client software, testing software, network data analysis software, etc., installed.
[0030] Static authentication can be a method of identity verification using a preset username and password. When a terminal device connects to a network device, the network device obtains the terminal device's username and password and performs static authentication. If the network device determines that the received username and password match the pre-stored password corresponding to the username, the terminal device has basic access permissions to the network device, and the network device can continue with the subsequent dynamic authentication process. If the network device determines that the received username and password do not match the pre-stored password corresponding to the username, the network device will not perform subsequent operations. It should be noted that in some application scenarios, the static authentication process can also be performed on the terminal device side. After performing the static authentication operation, the terminal device sends the obtained static authentication result to the network device so that the network device can perform subsequent related operations based on the static authentication result reported by the terminal device.
[0031] When a terminal device accesses a network device for operation and maintenance management, after the network device determines that the terminal device has passed static identity authentication, the network device generates a password value. The password value can be a password value randomly generated using a password generation algorithm, or it can be a one-time password value. The password value is used to implement a dynamic identity authentication mechanism for the terminal device.
[0032] In some applications, the password value can be a random string or a combination of numbers. In other applications, the password value can also be time-limited, for example, the password value is only valid within a specific time window.
[0033] Step 102: Encrypt the password value using the first encryption key to obtain the first encrypted information.
[0034] In this embodiment of the application, the first encryption key is pre-allocated to the network device by the network management terminal. The network device obtains the first encryption key from its storage area or from the network management terminal, and uses the first encryption key to encrypt the password value randomly generated for the terminal device to obtain the first encrypted information.
[0035] The network management terminal can be a network management system, such as the network management function in the core network, or other servers that perform network management. It is a system that can be used to monitor and manage wireless base station equipment on the network in real time, and is usually placed in the operator's computer room.
[0036] Step 103: Send the first encrypted information and the first identity identifier of the network device to the terminal device.
[0037] Specifically, the first encrypted information and the first identity identifier of the network device are sent to the terminal device, so that the terminal device requests the management server to perform dynamic identity authentication for the terminal device based on the first encrypted information and the first identity identifier.
[0038] In this embodiment, the management server can be an operation and maintenance management system, typically a platform built by each wireless base station equipment manufacturer for operation and maintenance management. This system can manage the identities of operation and maintenance personnel, the software versions and configurations of various wireless base station models, etc. The operation and maintenance management system can also interface with the network management system located on the operator's side, enabling online monitoring and remote operation and maintenance of the wireless base station equipment on the network.
[0039] The first identity information of a network device is an identifier used to uniquely identify the network device, which can be the identity information assigned to the network device by the network management terminal. The network device sends the encrypted first encrypted information and the network device's first identity information to the terminal device. The first encrypted information and the first identity information can be sent simultaneously or separately, depending on the actual application scenario, and no specific limitation is made here.
[0040] In this way, dynamic authentication of the terminal device is only performed after static identity authentication is successful, ensuring overall security. Furthermore, the password value is encrypted using primary encryption information, reducing the possibility of direct identification and exploitation after password leakage, thus guaranteeing security during data transmission. Combining the primary encryption information with the primary identity identifier ensures the accuracy and uniqueness of the dynamic authentication process, while avoiding security risks caused by key leakage. In addition, the entire authentication process does not depend on the online status of the core network; therefore, even when the wireless base station is in offline mode, the static and dynamic authentication processes can still be executed normally, reducing the possibility of unauthorized use of terminal devices and improving the security of the entire communication system.
[0041] Based on the foregoing embodiments, in other embodiments of this application, after the network device performs step 103 to send the first encrypted information and the network device's first identity identifier to the terminal device, it is further configured to perform the following steps: Obtain the first dynamic code; the first dynamic code is generated by the management server. Based on the first dynamic code and password value, the terminal device is authenticated to obtain the authentication result; the authentication result is used to indicate whether the terminal device has passed the dynamic identity authentication.
[0042] In this embodiment, the first dynamic code can be sent from the management server to the network device, or it can be output by the management server and then input by the user into the network device. The specific implementation can be determined by the actual application scenario.
[0043] After obtaining the first dynamic code, the network device compares and analyzes the first dynamic code with the password value to verify the identity of the terminal device and obtain the verification result.
[0044] In this way, by generating a first dynamic code through the management server to perform secondary dynamic identity authentication on terminal devices that have passed static identity authentication, the access security of terminal devices when accessing network devices is improved, and the stability and reliability of the communication network system are guaranteed.
[0045] Based on the foregoing embodiments, in other embodiments of this application, the step of authenticating the terminal device based on the first dynamic code and password value to obtain the verification result can be implemented by the following steps: Check the validity period of the password value; If the password value is currently within its validity period, verify whether the first dynamic code matches the password value and obtain the matching result; Based on the matching results, the verification result is determined.
[0046] In this embodiment, the validity period of the password value can be a specific time period allowed for its use, such as a specific duration. If the validity period of the password value is exceeded, the password value is considered expired and cannot be used for authentication, thus preventing the security risks associated with long-term use of fixed passwords.
[0047] When authenticating a terminal device based on a first dynamic code and a password, the validity period of the password is first determined. If the password is currently within its validity period, the matching degree between the first dynamic code output by the management server and the password is further verified to obtain a matching result. Based on the matching result, the verification result of the terminal device is obtained. Specifically, if the first dynamic code matches the password (e.g., the first dynamic code and password are the same), the verification result is determined to be that the terminal device has passed dynamic authentication. If the first dynamic code does not match the password (e.g., the first dynamic code and password are different), the verification result is determined to be that the terminal device has failed dynamic authentication.
[0048] It should be noted that if the terminal device fails dynamic identity authentication, the verification result can be fed back to the terminal device so that the terminal device can generate a prompt message indicating that the terminal device has failed dynamic identity authentication.
[0049] Thus, since the first dynamic code for dynamic authentication is generated by the management server, even if the terminal device passes static identity authentication, it cannot bypass the authentication of the first dynamic code, thereby improving the security of the local management port of the network device.
[0050] Based on the foregoing embodiments, in other embodiments of this application, the network device is further configured to perform the following steps: If the verification result indicates that the terminal device has passed dynamic authentication, the password value will be cleared. Authentication log information is generated based on the device information, password value, and verification result of the terminal device.
[0051] In this embodiment of the application, after the verification result indicates that the terminal device has passed the dynamic authentication, the network device cleans up the password value and records the dynamic authentication process in the form of a log. That is, the device information of the terminal device, the password value generated for the terminal device, and the verification result of the dynamic authentication are recorded to generate the authentication log information of the terminal device, so that the log can be queried and the problem can be traced and resolved when necessary in the future.
[0052] In some application scenarios, when the verification result indicates that the terminal device has failed dynamic authentication, the device information, password value, and verification result of the terminal device can be recorded in the form of logs to obtain corresponding log information for subsequent analysis of behaviors such as unauthorized intrusion. The specific method can be determined by the actual application scenario, such as the storage space of the network device, and is not specifically limited here.
[0053] Based on the foregoing embodiments, in other embodiments of this application, the network device is further configured to perform the following steps: Send the verification result to the terminal device.
[0054] In this embodiment, when the network device receives the verification results after static and dynamic authentication processing for the terminal device, it can also send the verification results to the terminal device so that the terminal device can display the verification results and facilitate the corresponding operators to perform operations such as operation and maintenance management of the network device through the terminal device based on the verification results.
[0055] Based on the foregoing embodiments, in other embodiments of this application, the network device is further configured to perform the following steps: Before the network device leaves the factory, a first request for identity information is sent to the management server so that the management server can assign a first identity identifier and a first encryption key to the network device to the network management terminal. Receive the first identity identifier and the first encryption key sent by the network management terminal; Store the first identity identifier and the first encryption key.
[0056] In this embodiment, for network devices, before they leave the factory after production, the network device sends a first request for identity information to the management server. Upon receiving the first request, the management server requests the network management terminal to assign a unique identifier to the network device within the communication network, namely a first identity identifier. The first identity identifier can be a serial number, serial number, or text name assigned to the network device by the network management terminal. The first encryption key can be a password specifically generated for the network device using a key generation algorithm, used for subsequent dynamic authentication. After the network device sends the request for identity information to the network management terminal through the management server, the network management terminal sends the first identity identifier and the first encryption key assigned to the network device to the network device. Upon receiving the first identity identifier and the first encryption key, the network device stores them for use in subsequent dynamic identity authentication and other application authentication processes.
[0057] Based on the foregoing embodiments, in other embodiments of this application, the network device is further configured to perform the following steps: An update request is sent to the network management terminal, which then sends the update request to the management server to request an update of the encryption key; the update request includes at least the first identity identifier.
[0058] In this embodiment of the application, when the network device has been put into service application, the network device can send an update request to the network management terminal at a pre-agreed time or when a specific event is triggered. Since the encryption key is generated in the management server, after the network management terminal receives the update request sent by the network device, it sends the update request to the management server so that the management server updates the encryption key for the network device based on the update request.
[0059] In some application scenarios, network devices can also directly send update requests to the management server, requesting the management server to update the encryption key.
[0060] The update request is used to request an update to the first encryption key in the network device. This allows for irregular or periodic updates to the first encryption key in the network device, reducing the possibility of the first encryption key being leaked and dynamic authentication being cracked, reducing the possibility of the network device's port being misused, and improving the security of the entire communication network system.
[0061] Based on the foregoing embodiments, in other embodiments of this application, the network device is further configured to perform the following steps: Receive a second encryption key sent by the network management terminal; wherein, the second encryption key is key information generated by the management server based on the first identity identifier and sent to the network management terminal; Update the network device's current encryption key to the second encryption key.
[0062] In this embodiment, after the network management terminal generates a second encryption key for encryption on the network device, it sends the second encryption key to the network device, causing the network device to update its currently stored encryption key to the second encryption key. In some application scenarios, the second encryption key may be the first encryption key.
[0063] The authentication method provided in this application embodiment determines that the terminal device has passed static identity authentication through the network device, generates a password value, encrypts the password value using a first encryption key to obtain first encrypted information, and sends the first encrypted information and the first identity identifier of the network device to the terminal device, so that the terminal device requests the management server to perform dynamic identity authentication for the terminal device based on the first encrypted information and the first identity identifier. In this way, when the network device determines that the terminal device has passed static identity authentication, the network device generates a password value and encrypts the password value using a pre-stored first encryption key to obtain the first encrypted information. The network device then sends the first encrypted information and the network device's first identity identifier to the terminal device. The terminal device then sends the received first encrypted information and the network device's first identity identifier to the management server. The management server, based on the first identity identifier reported by the terminal device, obtains the corresponding first decryption information to decrypt the first encrypted information, obtaining a first dynamic code. This first dynamic code is then output so that the terminal device can be re-authenticated using the first dynamic code, thus realizing the dynamic identity authentication process. In this way, while the terminal device passes static identity authentication, it also undergoes dynamic identity authentication based on the management server, achieving dual identity authentication for the terminal device. This ensures the security and reliability of the terminal device and solves the problem of the static account password authentication mechanism being easily cracked and causing security threats in the current wireless base station equipment operation and maintenance process. This proposes an authentication method that performs dynamic authentication based on the static account password authentication mechanism, reducing the possibility of attacks on the local operation and maintenance management port and ensuring the security of the mobile communication network.
[0064] The embodiments of this application provide an authentication method, referring to Figure 2 As shown, the method is applied to a management server, and the method includes at least the following steps: Step 201: Receive the first encrypted information and the first identity identifier sent by the terminal device.
[0065] The first identity identifier is used to identify the network device, and the first encrypted information is dynamic encrypted information generated by the network device to verify the identity information of the terminal device.
[0066] In this embodiment of the application, after the terminal device receives the first encrypted information and the first identity identifier sent by the network device through static identity authentication, the terminal device sends the first encrypted information and the first identity identifier to the management server to realize dynamic authentication of the terminal device's terminal identity information.
[0067] Step 202: Decrypt the first encrypted information based on the first decryption information corresponding to the first identity identifier to obtain the first dynamic code.
[0068] In this embodiment of the application, the management server obtains the first decryption information corresponding to the first identity identifier based on the received first identity identifier, and uses the first decryption information to decrypt the first encrypted information to obtain the first dynamic code.
[0069] Step 203: Output the first dynamic code so that the network device can perform dynamic identity authentication of the terminal device through the first dynamic code.
[0070] In this embodiment, the management server outputs the decrypted first dynamic code. Thus, the management server obtains the first dynamic code and then outputs it, thereby authenticating the terminal device at the management server and ensuring the security of the communication system.
[0071] Based on the foregoing embodiments, in other embodiments of this application, step 203, outputting the first dynamic code, can be implemented by the following steps: Output the first dynamic code to the terminal device; or, Output the first dynamic code to the display interface of the management server.
[0072] In this embodiment, one implementation of the management server outputting the first dynamic code is that the management server directly outputs the first dynamic code to the terminal device. In this way, technicians can input the first dynamic code displayed on the terminal device into the network device, allowing the network device to automatically match the first dynamic code output by the management server, thus achieving dynamic authentication of the terminal device's identity information. Alternatively, after the management server inputs the first dynamic code into the terminal device, the terminal device actively sends the received first dynamic code to the network device, achieving an automatic dynamic authentication process. The specific implementation can be determined by the actual application scenario and is not specifically limited here.
[0073] Another way to implement the management server outputting the first dynamic code is to output the first dynamic code to the management server's display interface. The management server's display interface can be provided by a display terminal with a communication connection to the management server, such as a monitor, or it could be a smart mobile terminal device with a communication connection to the management server, etc., depending on the actual situation; no specific limitation is made here. In this way, when the management server outputs the first dynamic code to its display interface, the user can input the first dynamic code into the network device. Thus, the network device performs dynamic authentication of the terminal device based on the first dynamic code input by the management and maintenance personnel.
[0074] Based on the foregoing embodiments, in this embodiment of the application, the management server is further configured to perform the following steps: If a first request is received from a network device, the first request is sent to the network management terminal; wherein, the first request is used to assign an identity identifier and an encryption key to the network device.
[0075] In this embodiment, the first request is sent by the network device to the management server before it leaves the factory. The management server requests the identity information and the encryption key used for subsequent dynamic authentication from the network management terminal. In this way, the network device obtains its first identity and corresponding encryption key from the network management terminal through the management server before it leaves the factory, which improves the security of the communication system.
[0076] Based on the foregoing embodiments, in this embodiment of the application, before the management server executes step 201 (receiving the first encrypted information and the first identity identifier sent by the terminal device), it is further configured to execute the following steps: Receive update requests sent by the network management terminal; wherein, the update request is a request sent by the network device to the network management terminal to request an update of the network device's encryption key, and the update request includes at least the network device's first identity identifier.
[0077] In this embodiment, when the network management terminal determines that the encryption key in the network device needs to be updated, a key update operation is triggered, and an update request is sent to the management server to request an update to the encryption key of the network device. This achieves dynamic updating of the encryption key and ensures its security.
[0078] Based on the foregoing embodiments, in this embodiment of the application, the management server is further configured to perform the following steps: A key pair is generated based on the first identity identifier included in the update request; wherein the key pair includes a second encryption key and a second decryption key; Send the second encryption key to the network management terminal so that the network management terminal can send the second encryption key to the network device to update the encryption key.
[0079] In this embodiment, a key generation algorithm is used to obtain a key pair corresponding to the first identity identifier. In some application scenarios, the key generation algorithm can also be used to generate a key pair from the first identity identifier. Then, the second encryption key in the key pair is sent to the network management terminal, which then sends the second encryption key to the network device so that the network device updates the encryption key.
[0080] The authentication method provided in this application embodiment receives first encrypted information and first identity identifier sent by a terminal device through a management server, decrypts the first encrypted information based on the first decryption information corresponding to the first identity identifier, obtains a first dynamic code, and outputs the first dynamic code. In this way, when the network device determines that the terminal device has passed static identity authentication, the network device generates a password value and encrypts the password value using a pre-stored first encryption key to obtain the first encrypted information. The network device then sends the first encrypted information and the network device's first identity identifier to the terminal device. The terminal device then sends the received first encrypted information and the network device's first identity identifier to the management server. The management server, based on the first identity identifier reported by the terminal device, obtains the corresponding first decryption information to decrypt the first encrypted information, obtaining a first dynamic code. This first dynamic code is then output so that the terminal device can be re-authenticated using the first dynamic code, thus realizing the dynamic identity authentication process. In this way, while the terminal device passes static identity authentication, it also undergoes dynamic identity authentication based on the management server, achieving dual identity authentication for the terminal device. This ensures the security and reliability of the terminal device and solves the problem of the static account password authentication mechanism being easily cracked and causing security threats in the current wireless base station equipment operation and maintenance process. This proposes an authentication method that performs dynamic authentication based on the static account password authentication mechanism, reducing the possibility of attacks on the local operation and maintenance management port and ensuring the security of the mobile communication network.
[0081] Based on the foregoing embodiments, this application provides an authentication method that, in addition to the existing static account password authentication on the local operation and maintenance management port of the wireless base station device, performs secondary dynamic password authentication through the joint cooperation of the operation and maintenance management system, the network management system, the on-site operation and maintenance terminal, and the wireless base station device. In other words, the wireless base station device, with the cooperation of the network management system and the operation and maintenance management system, completes the preset of the secondary dynamic password authentication mechanism. During the secondary dynamic password authentication process for on-site operation and maintenance personnel, the operation and maintenance management system first performs high-security two-factor authentication on the on-site operation and maintenance personnel. Then, with the assistance of the operation and maintenance management system, the wireless base station device transmits the secondary dynamic password to the on-site operation and maintenance personnel to help them complete the secondary dynamic password authentication.
[0082] The interconnections between the network management system, operation and maintenance management system, field operation and maintenance terminals, and wireless base station equipment can be described as follows: Figure 3 As shown. The connections between the network management system and the wireless base station equipment, and between the network management system and the operation and maintenance management system, can utilize existing secure connection methods in the mobile communication network system. However, the field operation and maintenance terminal needs to undergo two-factor authentication before connecting to the operation and maintenance management system. The two-factor authentication scheme for the field operation and maintenance terminal can be chosen by the operation and maintenance vendor and is not limited. The physical connection method and static password access authentication method between the field operation and maintenance terminal and the wireless base station equipment remain unchanged. After completing the static password authentication process required to establish a connection between the operation and maintenance terminal and the local management port of the wireless base station equipment, and the two-factor authentication between the operation and maintenance terminal and the operation and maintenance management system, the operation and maintenance personnel will obtain a dynamic password through the operation and maintenance terminal to complete a secondary dynamic password authentication for the wireless base station equipment. Figure 3 In this system, the network management system and the operation and maintenance management system can communicate via wide area network (WAN) or virtual private network (VPN); the operation and maintenance management system and the field operation and maintenance terminals can communicate via WAN; the wireless base station equipment and the field operation and maintenance terminals can communicate via wired means, such as through local area network cable (LAN cable); and the network management system and the wireless base station equipment can communicate via local area network (LAN) based on Internet Protocol Security (IPSec).
[0083] In implementing two-factor dynamic password authentication, the operation and maintenance management system can add a dynamic password authentication management module to generate and update public-private key pairs (SKm, PKm). Corresponding to the aforementioned key pairs, a first identity identifier (VID) is assigned to the wireless base station device, and during the dynamic password authentication process, the wireless base station device returns a decrypted dynamic password authentication code to the on-site operation and maintenance terminal. The wireless base station device can add a dynamic password authentication challenge module to receive and store the public key PKm from the operation and maintenance management system and handle interactions with the on-site operation and maintenance terminal during the dynamic password authentication process. The network management system adds a dynamic password authentication information transmission module to transmit preset information for the dynamic password authentication mechanism, including the public key PKm and VID, between the wireless base station device and the operation and maintenance management system. The on-site operation and maintenance terminal adds a dynamic password authentication response module to handle information interactions between the wireless base station device and the operation and maintenance management system during the dynamic password authentication process.
[0084] like Figure 4 As shown, the secondary dynamic password authentication includes a configuration phase and an authentication phase information flow diagram. The configuration of the dynamic password authentication mechanism occurs between the wireless base station equipment and the operation and maintenance management system, with the management system sending the public key PKm and VID to the wireless base station equipment for storage. During the dynamic password authentication phase, in the authentication challenge and response process between the wireless base station equipment and the dynamic password authentication module on the field operation and maintenance terminal, the dynamic password authentication response module on the field operation and maintenance terminal obtains the dynamic password information from the operation and maintenance management system to complete the secondary dynamic password authentication.
[0085] In this embodiment, the configuration phase of the dynamic password authentication mechanism needs to be performed in two scenarios. First, before the wireless base station equipment leaves the factory, the manufacturer presets the generated PKm and VID into the wireless base station equipment through the operation and maintenance management system. Second, during the online operation of the wireless base station equipment after it completes network registration, the operation and maintenance management system updates the PKm of the wireless base station equipment online through the network management system.
[0086] Specifically, the following dynamic password authentication mechanism is pre-programmed before the wireless base station equipment leaves the factory: Figure 5 As shown, it includes: Step a11: After the wireless base station equipment and the operation and maintenance management system complete the internal secure connection, the dynamic password authentication challenge module in the wireless base station equipment sends the first request for identity identification to the operation and maintenance management system.
[0087] Step a12: The dynamic password authentication module in the network management system generates a dynamic password authentication management identity code (VID) for the wireless base station device, generates (SKm, PKm), and securely saves (SKm, PKm) along with the VID. Then, it sends PKm along with the VID to the dynamic password authentication challenge module in the wireless base station device.
[0088] Among them, the dynamic password authentication management identity code VID corresponds to the aforementioned first identity identifier.
[0089] Step a13: The dynamic password authentication challenge module in the wireless base station device securely stores the VID and PKm.
[0090] Reference Figure 5 As shown, after the wireless base station equipment completes network registration, it can periodically or as needed execute the following dynamic password authentication mechanism update process: Step b11: The dynamic password authentication challenge module in the wireless base station device sends a dynamic password authentication mechanism update request and VID to the dynamic password authentication information transmission module in the network management system.
[0091] The dynamic password authentication mechanism update request corresponds to the aforementioned update request.
[0092] Step b12: The dynamic password authentication information transmission module in the network management system forwards the dynamic password authentication mechanism update request and VID to the dynamic password authentication management module in the operation and maintenance management system.
[0093] Step b13: The dynamic password authentication management module in the operation and maintenance management system checks the VID, then regenerates (SKm, PKm), and securely saves (SKm, PKm) along with the VID.
[0094] Step b14: The dynamic password authentication management module in the operation and maintenance management system returns the PKm to the dynamic password authentication information transmission module in the network management system.
[0095] Step b15: The dynamic password authentication information transmission module in the network management system returns the PKm to the dynamic password authentication challenge module in the wireless base station device. Step b16: The dynamic password authentication challenge module in the wireless base station device securely saves the PKm.
[0096] On-site maintenance personnel use maintenance terminals to connect to the maintenance management system via static account passwords and two-factor authentication. After connecting the maintenance terminals to the local management port of the wireless base station equipment and completing static account password authentication with the access management program of the wireless base station equipment, the implementation process for the corresponding dynamic password authentication phase can be referred to... Figure 6 As shown, the specific implementation steps may include the following: Step c11: After the dynamic password authentication challenge module in the wireless base station device confirms that the static account password authentication has been passed, it randomly generates a password value RP, and then uses PKm to encrypt RP: ERP=Epub(PKm, RP), and sends VID and ERP to the dynamic password authentication response module on the field operation and maintenance terminal.
[0097] Step c12: The dynamic password authentication response module on the on-site operation and maintenance terminal forwards the VID and ERP to the dynamic password authentication management module in the operation and maintenance management system to request a dynamic password authentication code.
[0098] The dynamic password authentication management module in the operation and maintenance management system captures c13, checks the VID, and then uses the corresponding SKm to decrypt the ERP to obtain the dynamic password authentication code RP'=Dpub(SKm,ERP).
[0099] Step c14: The dynamic password authentication management module in the operation and maintenance management system sends RP' to the dynamic password authentication response module on the on-site operation and maintenance terminal, or displays RP' on the operation and maintenance system interface.
[0100] Step c15: On-site maintenance personnel input RP' as a dynamic password authentication code into the local management access authentication interface of the wireless base station device.
[0101] Step c16: The dynamic password authentication challenge module in the wireless base station device checks whether RP is within the freshness time T range, and then compares RP and RP'. If they are equal, the authentication is passed, RP is cleared and reset, and the authentication log is recorded.
[0102] Step c17: The dynamic password authentication challenge module in the wireless base station equipment returns the authentication result to the dynamic password authentication response module on the on-site operation and maintenance terminal.
[0103] Thus, through a two-stage dynamic password authentication process, attackers can be effectively prevented from logging into devices through the local maintenance management port using illegally obtained static accounts and passwords without increasing the complexity of operation and maintenance, thereby enhancing the security of local maintenance port access. Furthermore, it can still function normally when the network connection between the wireless base station equipment and the core network management system fails, avoiding the problem of SMS dynamic verification code mechanisms failing in such scenarios.
[0104] Based on the foregoing embodiments, embodiments of this application provide a first authentication device, which can be applied to... Figure 1 The authentication method provided in the corresponding embodiment is applied to network devices, as shown in the following example. Figure 7 As shown, the first authentication device 3 may include: a generation unit 31, an encryption unit 32, and a first sending unit 33; wherein: The generation unit 31 is used to generate a password value after the terminal device has passed static identity authentication; Encryption unit 32 is used to encrypt the password value using the first encryption key to obtain the first encrypted information; The first sending unit 33 is used to send the first encrypted information and the first identity identifier of the network device to the terminal device, so that the terminal device requests the management server to perform dynamic identity authentication on the terminal device based on the first encrypted information and the first identity identifier.
[0105] In other embodiments of this application, after the first sending unit, the first authentication device further includes: an acquisition unit and a verification unit; wherein: The acquisition unit is used to acquire the first dynamic code; wherein the first dynamic code is generated by the management server; The verification unit is used to authenticate the terminal device based on the first dynamic code and the password value, and obtain the verification result; wherein the verification result is used to indicate whether the terminal device has passed the dynamic identity authentication.
[0106] In other embodiments of this application, the verification unit is specifically used to implement the following steps: Check the validity period of the password value; If the password value is currently within its validity period, verify whether the first dynamic code matches the password value and obtain the matching result; Based on the matching results, the verification result is determined.
[0107] In other embodiments of this application, the verification unit is further configured to implement the following steps: If the verification result indicates that the terminal device has passed dynamic authentication, the password value will be cleared. Authentication log information is generated based on the device information, password value, and verification result of the terminal device.
[0108] In other embodiments of this application, the first sending unit is further configured to send the verification result to the terminal device.
[0109] In other embodiments of this application, the first sending unit is further configured to send a first request for applying for identity information to the management server before the network device leaves the factory, so that the management server assigns a first identity identifier and a first encryption key to the network device to the network management terminal; Receive the first identity identifier and the first encryption key sent by the network management terminal; Store the first identity identifier and the first encryption key.
[0110] In other embodiments of this application, the first sending unit is further configured to send an update request to the network management terminal, so that the network management terminal sends the update request to the management server to request an update of the encryption key; wherein the update request includes at least a first identity identifier.
[0111] In other embodiments of this application, the first authentication device further includes: a second receiving unit and an updating unit; wherein: The second receiving unit is used to receive the first encryption key sent by the network management terminal; wherein, the first encryption key is key information generated by the management server based on the first identity identifier and sent to the network management terminal; The update unit is used to update the network device's current encryption key to a second encryption key.
[0112] It should be noted that the process of information interaction between units and modules in this embodiment can be referred to the description in other embodiments, and will not be repeated here.
[0113] The first authentication device provided in this application, after determining that the terminal device has passed static identity authentication through the network device, generates a password value, encrypts the password value using a first encryption key to obtain first encrypted information, and sends the first encrypted information and the first identity identifier of the network device to the terminal device, so that the terminal device requests the management server to perform dynamic identity authentication for the terminal device based on the first encrypted information and the first identity identifier. In this way, when the network device determines that the terminal device has passed static identity authentication, the network device generates a password value and encrypts the password value using a pre-stored first encryption key to obtain the first encrypted information. The network device then sends the first encrypted information and the network device's first identity identifier to the terminal device. The terminal device then sends the received first encrypted information and the network device's first identity identifier to the management server. The management server, based on the first identity identifier reported by the terminal device, obtains the corresponding first decryption information to decrypt the first encrypted information, obtaining a first dynamic code. This first dynamic code is then output so that the terminal device can be re-authenticated using the first dynamic code, thus realizing the dynamic identity authentication process. In this way, while the terminal device passes static identity authentication, it also undergoes dynamic identity authentication based on the management server, achieving dual identity authentication for the terminal device. This ensures the security and reliability of the terminal device and solves the problem of the static account password authentication mechanism being easily cracked and causing security threats in the current wireless base station equipment operation and maintenance process. This proposes an authentication method that performs dynamic authentication based on the static account password authentication mechanism, reducing the possibility of attacks on the local operation and maintenance management port and ensuring the security of the mobile communication network.
[0114] Based on the foregoing embodiments, embodiments of this application provide a second authentication device, which can be applied to... Figure 2 The authentication method provided in the corresponding embodiment is applied to the management server, as shown in the following example. Figure 8 As shown, the second authentication device 4 may include: a first receiving unit 41, a decryption unit 42, and an output unit 43; wherein: The first receiving unit 41 is used to receive first encrypted information and a first identity identifier sent by the terminal device; wherein, the first identity identifier is used to identify the network device, and the first encrypted information is dynamically encrypted information generated by the network device. Decryption unit 42 is used to decrypt the first encrypted information based on the first decryption information corresponding to the first identity identifier to obtain the first dynamic code; Output unit 43 is used to output a first dynamic code so that the network device can perform dynamic identity authentication of the terminal device through the first dynamic code.
[0115] In other embodiments of this application, the output unit is specifically used to implement the following steps: Output the first dynamic code to the terminal device; or, Output the first dynamic code to the display interface of the management server.
[0116] In other embodiments of this application, the second authentication device further includes: a second sending unit; wherein: The second sending unit is used to send a first request to the network management terminal if it receives a first request sent by a network device; wherein the first request is used to assign an identity identifier and an encryption key to the network device.
[0117] In other embodiments of this application, before the first receiving unit performs the step of receiving the first encrypted information and the first identity identifier sent by the terminal device, it is further configured to receive an update request sent by the network management terminal; wherein, the update request is a request sent by the network device to the network management terminal to request an update of the network device's encryption key, and the update request includes at least the first identity identifier of the network device.
[0118] In other embodiments of this application, the generating unit is further configured to generate a key pair based on the first identity identifier included in the update request; wherein the key pair includes a second encryption key and a second decryption key; The second sending unit is also used to send the second encryption key to the network management terminal, so that the network management terminal sends the second encryption key to the network device to update the encryption key.
[0119] It should be noted that the process of information interaction between units and modules in this embodiment can be referred to the description in other embodiments, and will not be repeated here.
[0120] The second authentication device provided in this application embodiment receives first encrypted information and first identity identifier sent by a terminal device through a management server, decrypts the first encrypted information based on the first decryption information corresponding to the first identity identifier, obtains a first dynamic code, and outputs the first dynamic code. In this way, when the network device determines that the terminal device has passed static identity authentication, the network device generates a password value and encrypts the password value using a pre-stored first encryption key to obtain the first encrypted information. The network device then sends the first encrypted information and the network device's first identity identifier to the terminal device. The terminal device then sends the received first encrypted information and the network device's first identity identifier to the management server. The management server, based on the first identity identifier reported by the terminal device, obtains the corresponding first decryption information to decrypt the first encrypted information, obtaining a first dynamic code. This first dynamic code is then output so that the terminal device can be re-authenticated using the first dynamic code, thus realizing the dynamic identity authentication process. In this way, while the terminal device passes static identity authentication, it also undergoes dynamic identity authentication based on the management server, achieving dual identity authentication for the terminal device. This ensures the security and reliability of the terminal device and solves the problem of the static account password authentication mechanism being easily cracked and causing security threats in the current wireless base station equipment operation and maintenance process. This proposes an authentication method that performs dynamic authentication based on the static account password authentication mechanism, reducing the possibility of attacks on the local operation and maintenance management port and ensuring the security of the mobile communication network.
[0121] Based on the foregoing embodiments, embodiments of this application provide an authentication system that can be applied to... Figure 1 or Figure 2 In the authentication method provided in the corresponding embodiment, refer to Figure 9 As shown, the authentication system 5 may include: a terminal device 51, a network device 52, and a management server 53; wherein: Terminal device 51 is used for equipment maintenance of network device 52; Network device 52 is used to achieve, for example Figure 1 The implementation process of the authentication method provided in the corresponding embodiments will not be described in detail here; Management server 53 is used to implement, for example Figure 2 The implementation process of the authentication method provided in the corresponding embodiments will not be described in detail here.
[0122] Based on the foregoing embodiments, embodiments of this application provide a computer-readable storage medium, simply referred to as a storage medium, which stores one or more programs that can be executed by one or more processors to implement the reference. Figure 1 or Figure 2The implementation process of the authentication method provided in the corresponding embodiments will not be described in detail here.
[0123] Based on the foregoing embodiments, this application also provides a computer program product, including a computer program that can be executed by the processor of a network device or the processor of a management server to complete any of the foregoing method steps.
[0124] Those skilled in the art will understand that embodiments of this application can be provided as methods, systems, or computer program products. Therefore, this application can take the form of hardware embodiments, software embodiments, or embodiments combining software and hardware aspects. Furthermore, this application can take the form of a computer program product embodied on one or more computer-usable storage media (including, but not limited to, disk storage and optical storage) containing computer-usable program code.
[0125] This application is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of this application. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, generate instructions for implementing the flowchart... Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.
[0126] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.
[0127] These computer program instructions may also be loaded onto a computer or other programmable data processing equipment to cause a series of operational steps to be performed on the computer or other programmable equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.
[0128] The above description is merely a preferred embodiment of this application and is not intended to limit the scope of protection of this application.
Claims
1. An authentication method, characterized in that, The method is applied to a network device, and the method includes: After confirming that the terminal device has passed static identity authentication, a password value is generated; The password value is encrypted using the first encryption key to obtain the first encrypted information; The first encrypted information and the first identity identifier of the network device are sent to the terminal device, so that the terminal device requests the management server to perform dynamic identity authentication for the terminal device based on the first encrypted information and the first identity identifier.
2. The method according to claim 1, characterized in that, After sending the first encrypted information and the first identity identifier of the network device to the terminal device, the method further includes: Obtain the first dynamic code; wherein the first dynamic code is generated by the management server; Based on the first dynamic code and the password value, the terminal device is authenticated to obtain a verification result; wherein, the verification result is used to indicate whether the terminal device has passed dynamic identity authentication.
3. The method according to claim 2, characterized in that, The step of authenticating the terminal device based on the first dynamic code and the password value to obtain the authentication result includes: Check the validity period of the password value; If the password value is currently within its validity period, verify whether the first dynamic code matches the password value, and obtain the matching result; Based on the matching results, the verification result is determined.
4. The method according to claim 3, characterized in that, The method further includes: If the verification result indicates that the terminal device has passed dynamic authentication, the password value will be cleared. Based on the device information of the terminal device, the password value, and the verification result, authentication log information is generated.
5. The method according to claim 3, characterized in that, The method further includes: The verification result is sent to the terminal device.
6. The method according to any one of claims 1 to 5, characterized in that, The method further includes: Before the network device leaves the factory, a first request for identity information is sent to the management server, so that the management server assigns a first identity identifier and a first encryption key to the network device to the network management terminal. Receive the first identity identifier and the first encryption key sent by the network management terminal; Store the first identity identifier and the first encryption key.
7. The method according to any one of claims 1 to 5, characterized in that, The method further includes: An update request is sent to the network management terminal, so that the network management terminal sends the update request to the management server to request an update of the encryption key; wherein the update request includes at least the first identity identifier.
8. The method according to claim 7, characterized in that, The method further includes: Receive a second encryption key sent by the network management terminal; wherein, the second encryption key is key information generated by the management server based on the first identity identifier and sent to the network management terminal; Update the network device's current encryption key to the first encryption information.
9. An authentication method, characterized in that, The method is applied to a management server, and the method includes: The terminal device receives first encrypted information and a first identity identifier; wherein the first identity identifier is used to identify the network device, and the first encrypted information is dynamic encrypted information generated by the network device to verify the identity information of the terminal device. The first encrypted information is decrypted based on the first decryption information corresponding to the first identity identifier to obtain the first dynamic code; The first dynamic code is output so that the network device can perform dynamic identity authentication of the terminal device through the first dynamic code.
10. The method according to claim 9, characterized in that, The output of the first dynamic code includes: Output the first dynamic code to the terminal device; or... The first dynamic code is output to the display interface of the management server.
11. The method according to claim 9 or 10, characterized in that, The method further includes: If a first request is received from the network device, the first request is sent to the network management terminal; wherein, the first request is used to assign an identity identifier and an encryption key to the network device.
12. The method according to claim 9 or 10, characterized in that, Before receiving the first encrypted information and the first identity identifier sent by the receiving terminal device, the method further includes: The network device receives an update request from the network management terminal. The update request is a request sent by the network device to the network management terminal to request an update of the network device's encryption key. The update request includes at least the network device's first identity identifier.
13. The method according to claim 12, characterized in that, The method further includes: Based on the first identity identifier included in the update request, a key pair is generated; wherein the key pair includes a second encryption key and a second decryption key; The second encryption key is sent to the network management terminal, so that the network management terminal sends the second encryption key to the network device to update the encryption key.
14. A first authentication device, characterized in that, The apparatus is applied to a network device, and the apparatus includes: a generation unit, an encryption unit, and a first transmission unit; wherein: The generation unit is used to generate a password value after the terminal device has passed static identity authentication; The encryption unit is used to encrypt the password value using a first encryption key to obtain first encrypted information; The first sending unit is configured to send the first encrypted information and the first identity identifier of the network device to the terminal device, so that the terminal device requests the management server to perform dynamic identity authentication on the terminal device based on the first encrypted information and the first identity identifier.
15. A second authentication device, characterized in that, The device is used in a management server, and the device includes: a first receiving unit, a decryption unit, and an output unit; wherein: The first receiving unit is configured to receive first encrypted information and a first identity identifier sent by the terminal device; wherein, the first identity identifier is used to identify the network device, and the first encrypted information is dynamically encrypted information generated by the network device; The decryption unit is used to decrypt the first encrypted information based on the first decryption information corresponding to the first identity identifier to obtain the first dynamic code; The output unit is used to output the first dynamic code so that the network device can perform dynamic identity authentication of the terminal device through the first dynamic code.
16. An authentication system, characterized in that, The system includes at least: terminal devices, network devices, and a management server; wherein: The terminal device is used for equipment maintenance of the network device; The network device is configured to implement the steps of the authentication method as described in any one of claims 1 to 8; The management server is used to implement the steps of the authentication method as described in any one of claims 9 to 13.
17. A storage medium, characterized in that, The storage medium stores an authentication program, which, when executed, is used to implement the steps of the authentication method as described in any one of claims 1 to 8, or claims 9 to 13.
18. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by a processor, it implements the steps of the authentication method as described in any one of claims 1 to 8, or claims 9 to 13.