Communication method and device
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- GUANGDONG OPPO MOBILE TELECOMMUNICATIONS CORP LTD
- Filing Date
- 2023-12-29
- Publication Date
- 2026-07-31
AI Technical Summary
During the roaming process, how to improve the efficiency of terminals to access non-own-home networks, while ensuring security and authentication efficiency.
By passing the first credential of carrying verification permissions between the terminal and the network device, using blockchain technology to perform secure authentication, reducing the computing burden of core network devices and achieving rapid authentication.
It improves the authentication efficiency of terminals to access other networks, ensures security, and protects user privacy, adapts to the efficient spectrum sharing needs in the 6G era.
Smart Images

Figure CN122498162A_ABST
Abstract
Description
Communication method and device Technical Field
[0001] The present application relates to the field of communications, and more specifically, to a communication method and device. Background Art
[0002] Roaming agreements, as they are commonly known, refer to mobile communications agreements that allow terminals to switch between different carriers' networks and access services. These agreements enable users to communicate through other carriers' networks even when outside their carrier's coverage area. The development and implementation of roaming agreements improve user experience, enabling terminals to freely switch between networks maintained by different carriers in different regions. However, ensuring the efficiency of terminals accessing roaming networks (i.e., networks not their own) during roaming becomes a challenge.
[0003] Summary of the Invention
[0004] The embodiments of the present application provide a communication method and device.
[0005] An embodiment of the present application provides a communication method performed by a terminal, including:
[0006] An authentication request is sent to a first network device in a first network, wherein the authentication request carries a first credential for verifying the authority of the terminal belonging to the second network to use resources of the first network.
[0007] An embodiment of the present application provides a communication method performed by a first network device, including:
[0008] An authentication request is received from a terminal, wherein the authentication request carries a first credential for verifying authority of the terminal belonging to a second network to use resources of a first network, and the first network device belongs to the first network.
[0009] This embodiment of the present application provides a communication method performed by a second core network device, including:
[0010] A first resource authorization message is sent to the terminal, wherein the first resource authorization message carries a first credential for verifying the authority of the terminal belonging to the second network to use resources of the first network, and the second core network device belongs to the second network.
[0011] An embodiment of the present application provides a communication method performed by a first core network device, including:
[0012] Upload a second resource authorization message to the blockchain, wherein the second resource authorization message carries a second credential, and the second credential carries a second signature for verifying the second network's authority to use resources of the first network, and the first core network device belongs to the first network.
[0013] An embodiment of the present application provides a terminal, including:
[0014] The first communication unit is configured to send an authentication request to a first network device in a first network, wherein the authentication request carries a first credential for verifying the authority of the terminal belonging to the second network to use resources of the first network.
[0015] An embodiment of the present application provides a first network device, including:
[0016] The second communication unit is configured to receive an authentication request from a terminal, wherein the authentication request carries a first credential for verifying the authority of the terminal belonging to the second network to use resources of the first network, and the first network device belongs to the first network.
[0017] An embodiment of the present application provides a second core network device, including:
[0018] The third communication unit is used to send a first resource authorization message to the terminal, wherein the first resource authorization message carries a first credential for verifying the authority of the terminal belonging to the second network to use the resources of the first network, and the second core network device belongs to the second network.
[0019] An embodiment of the present application provides a first core network device, including:
[0020] The fourth communication unit is used to upload a second resource authorization message to the blockchain, wherein the second resource authorization message carries a second credential, and the second credential carries a second signature for verifying the second network's authority to use the resources of the first network, and the first core network device belongs to the first network.
[0021] By adopting the above solution, when the terminal accesses a first network to which it does not belong, a first certificate carrying the verification permission of the terminal belonging to the second network to use the resources of the first network can be sent to the network device under the first network. In this way, when the terminal has the need to access other networks, the terminal can be authenticated only through the first certificate. While ensuring security, the authentication efficiency can also be improved, avoiding the problem of low efficiency caused by the need for core network equipment to perform security calculations to achieve authentication in related technologies. BRIEF DESCRIPTION OF THE DRAWINGS
[0022] FIG1 is a schematic diagram of an application scenario according to an embodiment of the present application.
[0023] FIG2 is a schematic flowchart of a communication method according to an embodiment of the present application.
[0024] FIG3 is a schematic flowchart of a communication method according to another embodiment of the present application.
[0025] FIG4 is a schematic flowchart of a communication method according to yet another embodiment of the present application.
[0026] FIG5 is a schematic flowchart of a communication method according to yet another embodiment of the present application.
[0027] FIG6 is a schematic flowchart of the issuance process of a primary certificate according to an embodiment of the present application.
[0028] FIG7 is a schematic flowchart of the issuance process of a secondary certificate according to an embodiment of the present application.
[0029] FIG8 is a schematic flowchart of a terminal accessing a network using a secondary credential according to an embodiment of the present application.
[0030] FIG9 is a schematic flowchart of a processing flow for denying access according to an embodiment of the present application.
[0031] FIG10 is a schematic block diagram of a terminal according to an embodiment of the present application.
[0032] FIG11 is a schematic block diagram of a first network device according to an embodiment of the present application.
[0033] FIG12 is a schematic block diagram of a second core network device according to an embodiment of the present application.
[0034] Figure 13 is a schematic block diagram of a first core network device according to an embodiment of the present application. DETAILED DESCRIPTION
[0035] The technical solutions of the embodiments of the present application can be applied to various communication systems, such as LTE, LTE-A, NR, NR evolution, WLAN, WiFi, or other communication systems.
[0036] The embodiments of the present application describe various embodiments in conjunction with network devices and terminals. The terminals can be mobile or fixed, and can also be referred to as mobile stations, user units, etc. The terminal can be a site in a WLAN, and can be a smart terminal, wireless modem, laptop computer, tablet computer, or other terminal. In the embodiments of the present application, the terminal can be a VR terminal / AR terminal, an industrial control terminal, an unmanned driving terminal, a telemedicine terminal, a smart grid terminal, a transportation safety terminal, a smart city terminal, or a wireless terminal for a smart home, etc. As an example and not a limitation, in the embodiments of the present application, the terminal can also be a wearable device.
[0037] In the embodiment of the present application, the network device may be a device for communicating with a terminal, an access point in a WLAN, an evolved base station in LTE, or a relay station, or a network device (gNB) in an in-vehicle device, a wearable device, and an NR network, or a network device in a future evolved PLMN network or a network device in a non-terrestrial network. As an example and not a limitation, in the embodiment of the present application, the network device may have a mobile feature, for example, the network device may be a mobile device.
[0038] To facilitate understanding of the technical solutions of the embodiments of the present application, the relevant technologies of the embodiments of the present application are described below. The following relevant technologies can be arbitrarily combined with the technical solutions of the embodiments of the present application as optional solutions, and they all fall within the protection scope of the embodiments of the present application.
[0039] Figure 1 exemplarily illustrates a communication system 100. The communication system includes a network device 110 and two terminals 120. In one possible implementation, the communication system 100 may include multiple network devices 110, and each network device 110 may include a different number of terminals 120 within its coverage area, although this embodiment of the present application does not limit this. In one possible implementation, the communication system 100 may also include a mobility management entity, access and mobility management functions, and other network entities, although this embodiment of the present application does not limit this. The network devices may include access network devices and core network devices. That is, the communication system may also include multiple core networks for communicating with the access network devices. The access network devices may be base stations of LTE, LTE-A, or NR systems. Taking the communication system shown in Figure 1 as an example, the communication devices may include network devices and terminals with communication functions. The communication devices may also include other devices in the communication system, such as network controllers, mobility management entities, and other network entities, although this embodiment of the present application does not limit this.
[0040] FIG2 is a schematic flow chart of a communication method executed by a terminal according to an embodiment of the present application. The method includes at least part of the following contents.
[0041] S210: Send an authentication request to a first network device in a first network, wherein the authentication request carries a first credential for verifying permission of the terminal belonging to the second network to use resources of the first network.
[0042] Figure 3 is a schematic flow chart of a communication method performed by a first network device according to an embodiment of the present application. The method includes at least part of the following contents.
[0043] S310: Receive an authentication request from a terminal, wherein the authentication request carries a first credential for verifying permission of the terminal belonging to the second network to use resources of the first network, and the first network device belongs to the first network.
[0044] Figure 4 is a schematic flow chart of a communication method performed by a second core network device according to an embodiment of the present application. The method includes at least part of the following contents.
[0045] S410. Send a first resource authorization message to the terminal, wherein the first resource authorization message carries a first credential for verifying the authority of the terminal belonging to the second network to use resources of the first network, and the second core network device belongs to the second network.
[0046] Figure 5 is a schematic flow chart of a communication method performed by a first core network device according to an embodiment of the present application. The method includes at least part of the following contents.
[0047] S510. Upload a second resource authorization message to the blockchain, wherein the second resource authorization message carries a second credential, and the second credential carries a second signature for verifying the second network's permission to use resources of the first network, and the first core network device belongs to the first network.
[0048] The first core network device and the second core network device belong to different networks. The first core network device may be a core network device in the first network, and the second core network device may be a core network device in the second network. The first network and the second network are different. The first network and the second network belong to different operators, or the first network and the second network are managed by different operators.
[0049] The function of the first core network device may be to be responsible for and manage the resources (or spectrum resources) of the first network, and to meet the communication needs of the subscribers of the first network in mobile communications. The function of the second core network device may be to be responsible for and manage the resources (or spectrum resources) of the second network, and to meet the communication needs of the subscribers of the second network in mobile communications. This embodiment does not limit the device types of the first core network device and the second core network device. For example, the first core network device and the second core network device may be control plane network elements within their respective networks, and the possible device types of the first core network device and the second core network device are not limited or enumerated herein.
[0050] The fact that the terminal belongs to the network where the second core network device is located means that the terminal is a subscribed terminal of the second network. In other words, the second network is the home network of the terminal.
[0051] The first network device may include one of the following: an access network device, a third core network device. That is, the first network device may be an access network device belonging to the first network, or a third core network device belonging to the first network.
[0052] The access network device provides mobile communication services and connects the terminal to the first core network device. In other words, when a terminal subscribed to a second network wishes to access or use resources on the first network where the first core network device resides, the terminal can initiate authentication through the access network device. In this case, the first network refers to the terminal's roaming network, and the access network device is the access network device in the terminal's roaming network.
[0053] Although the third core network device and the first core network device both belong to the first network, the third core network device is different from the first core network device and can be a core network device that performs authentication. This embodiment does not limit the possible entity names of the third core network device and the first core network device.
[0054] In some possible implementations, a process of generating and issuing a second credential needs to be first performed between the first core network device and the second core network device, where the second credential is used to generate the first credential.
[0055] On the second core network device side, the method may further include: sending a second resource request message to the first core network device, wherein the second resource request message is used to request the use of resources of the first network; and downloading the second credential from the blockchain.
[0056] On the first core network device side, the method may further include: receiving a second resource request message from a second core network device of the second network, wherein the second resource request message is used to request use of resources of the first network. The method may further include: uploading the second resource authorization message to the blockchain.
[0057] Since the second credential is an interactive process at the core network level of the two networks, it needs to be allocated or issued before the terminal uses the first credential to access the first network. Therefore, in some possible examples, the second credential can also be called a first-level credential.
[0058] In one embodiment, the second resource request message may carry at least one of the following: a sixth signature, information requesting the use of resources of the first network, and an identifier of the second core network device.
[0059] Here, the identifier of the second core network device can be used by the first core network device to determine the identity of the device that sends the second resource request message.
[0060] The sixth signature may be calculated based on the private key of the second core network device and at least one of the following parameters: an identifier of the second core network device and information requesting use of resources of the first network. The signature algorithm used to calculate the sixth signature may be configured based on actual circumstances.
[0061] For example, the calculation of the sixth signature can be: using a signature algorithm to calculate at least one of the identification of the second core network device and the information requesting to use the resources of the first network based on the private key of the second core network device to obtain the sixth signature.
[0062] For example, the calculation of the sixth signature may include: performing a hash calculation based on at least one of the identification of the second core network device and the information requesting the use of resources of the first network to obtain a sixth hash value; and encrypting the sixth hash value based on the private key of the second core network device to obtain a sixth signature.
[0063] It should be understood that the parameters used to calculate the sixth signature and the other parameters carried by the second resource request message, except for the sixth signature, may be the same or partially the same. For example, in addition to the sixth signature, the second resource request message carries the identifier of the second core network device and information requesting use of resources of the first network; the calculation of the sixth signature may use at least one of the identifier of the second core network device and information requesting use of resources of the first network.
[0064] The information requesting to use the resources of the first network refers to the relevant information of the second core network device applying to use the resources of the first network, wherein the resources may refer to time domain resources and / or frequency domain resources.
[0065] Specifically, the information requesting the use of the resources of the first network may include at least one of the following: the identifier of the first core network device, the identifier (or number) for requesting the use of the resources of the first network, the time period for requesting the use of the resources of the first network, and the price for requesting the use of the resources of the first network.
[0066] The number of resources of the first network requested by the second core network device may be one or more; that is, the second resource requested by the second core network device may be one or more resources among all resources supported or managed by the first network (first network). The second core network device may indicate which resource or resources in the first network are requested to be used by the second core network device through the identifier of each resource. That is, the identifier of the resource requested to be used in the first network may refer to the identifier of at least one resource requested to be used by the second core network device among all resources in the first network.
[0067] The usage period of the request to use the resources of the first network may include at least one of the following: the start time of the request to use the resources of the first network, the end time of the request to use the resources of the first network, and the effective duration of the request to use the resources of the first network.
[0068] For example, the usage period of the request to use the resources of the first network may only include the end time of the request to use the resources of the first network. Accordingly, the first core network device can use the moment of receiving the second resource request message as the start time of the request to use the resources of the first network.
[0069] For example, the usage period of the request to use the resources of the first network may only include the effective duration of the request to use the resources of the first network. Accordingly, the first core network device can use the moment of receiving the second resource request message as the starting timing moment of the effective duration of the request to use the resources of the first network.
[0070] For example, the usage period for requesting to use the resources of the first network may include: a start time for requesting to use the resources of the first network and an end time for requesting to use the resources of the first network.
[0071] For example, the usage period of the request to use the resources of the first network may include: the usage start time of the request to use the resources of the first network and the validity period of the request to use the resources of the first network.
[0072] It should be understood that the above is merely an exemplary description. In actual processing, the usage period of requesting to use the resources of the first network may also be indicated in other ways, but this embodiment does not limit or exhaustively list them.
[0073] The price for requesting use of the resources of the first network may refer to the total price for using the resources of the first network during the usage period for which use of the resources of the first network is requested. This price may be calculated based on the unit price of each resource in the first network and the usage period. The specific calculation method of this price, the definition of the unit price, etc. are not limited in this embodiment.
[0074] In one embodiment, after the first core network device receives the second resource request message from the second core network device, it can first verify the reliability of the second resource request message, and generate a second credential if the verification passes.
[0075] Here, verifying the reliability of the second request message may include at least one of the following: verifying the second core network device based on the sixth signature; verifying the information of the request to use the resources of the first network. Accordingly, verification passed may mean: if only the processing of verifying the second core network device based on the sixth signature is performed, then if the verification of the second core network device is successful, the verification is determined to be passed; if only the processing of verifying the information of the request to use the resources of the first network is performed, then if the information of the request to use the resources of the first network is correct, the verification is determined to be passed; if the second core network device is verified based on the sixth signature, and the information of the request to use the resources of the first network is verified, then if the verification of the second core network device is successful and the information of the request to use the resources of the first network is correct, the verification is determined to be passed.
[0076] Optionally, verifying the second core network device based on the sixth signature may include: verifying the second core network device based on the public key of the second core network device, the sixth signature and at least one of the following information carried in the second resource request message: the identification of the second core network device, and information requesting the use of resources of the first network.
[0077] The public key of the second core network device may be disclosed on the blockchain, and the first core network device may obtain the public key of the second core network device from the blockchain. Exemplarily, the first core network device may obtain the public key of the second core network device from the blockchain based on an identifier of the second core network device.
[0078] The signature verification algorithm used to verify the sixth signature should correspond to the algorithm used to calculate the sixth signature; and the parameters used to verify the sixth signature should be the same as the parameters used to calculate the sixth signature.
[0079] For example, assuming that the sixth signature is calculated based on the identifier of the second core network device and the information requesting use of resources of the first network, verifying the second core network device based on the sixth signature may include: employing a signature verification algorithm, decrypting the sixth signature based on the public key of the second core network device to obtain a parameter to be verified; and verifying the second core network device based on the parameter to be verified, the identifier of the second core network device, and the information requesting use of resources of the first network.
[0080] Among them, based on the parameters to be verified and the identification of the second core network device and the information requesting to use the resources of the first network, the verification of the second core network device can be at least one of the following: when the parameters to be verified are the same as the identification of the second core network device and the information requesting to use the resources of the first network, it is determined that the verification of the second core network device is successful; when the parameters to be verified are different from the identification of the second core network device and the information requesting to use the resources of the first network, it is determined that the verification of the second core network device has failed.
[0081] For example, assume that the sixth signature is calculated based on the identification of the second core network device and the information requesting the use of the resources of the first network. Verifying the second core network device based on the sixth signature may include: performing a hash calculation based on the identification of the second core network device and the information requesting the use of the resources of the first network to obtain a sixth verification hash value, decrypting the sixth signature based on the public key of the second core network device to obtain a sixth decrypted value; and verifying the second core network device based on the sixth decrypted value and the sixth verification hash value. Verifying the second core network device based on the sixth decrypted value and the sixth verification hash value may include at least one of the following: if the sixth decrypted value and the sixth verification hash value are the same, verification of the second core network device is successful; if the sixth decrypted value and the sixth verification hash value are different, verification of the second core network device fails.
[0082] It should be noted that if verification of the second core network device based on the sixth signature fails, the first core network device may terminate the processing and / or return a verification failure response message to the second core network device.
[0083] Optionally, verifying the information regarding the request for use of the resources of the first network may include: verifying whether identifiers of various resources in the information regarding the request for use of the resources of the first network are identifiers of resources of the own network, and / or verifying whether prices of the resources requested for use of the first network are accurate, etc. The specific possible contents to be verified and the verification methods are not limited or exhaustive herein.
[0084] In one embodiment, the second credential carries a second signature for verifying the authority of the second core network device to use resources of the first core network device.
[0085] On the first core network device side, the second signature may be calculated based on the private key of the first core network device and the parameters included in the second certificate.
[0086] Specifically, the second certificate also carries at least one of the following: the identification of the second core network device, the public key of the second core network device, the identification of the first core network device, the public key of the first core network device, and information about the resources of the first network authorized for use by the second network.
[0087] The parameters or contents included in the information of authorizing the second core network device to use the resources of the first network are similar to the contents included in the information of requesting to use the resources of the first network, and are not repeated here.
[0088] The second signature is calculated based on the private key of the first core network device and at least one of the following information: the identification of the first core network device, the public key of the first core network device, the identification of the second core network device in the second network, the public key of the second core network device, and information about the resources of the first network authorized for use by the second network.
[0089] Exemplarily, the second signature can be calculated by using a signature algorithm, based on the private key of the first core network device, to calculate at least one of the identification of the second core network device, the public key of the second core network device, the identification of the first core network device, the public key of the first core network device, and the information of the resources of the first network authorized for use by the second network.
[0090] Exemplarily, the calculation of the second signature can be: performing a hash calculation based on at least one of the identification of the second core network device, the public key of the second core network device, the identification of the first core network device, the public key of the first core network device, and the information of the resources of the first network authorized for use by the second core network device to obtain a second hash value; and encrypting the second hash value based on the private key of the first core network device to obtain a second signature.
[0091] The second signature in the second certificate serves to bind the authorized resources with the identity and public key of the second core network device, that is, to authorize the second core network device for specific spectrum resources.
[0092] After the blockchain receives the second resource authorization message uploaded by the first core network device, the blockchain may further include: other nodes on the blockchain verifying the second resource authorization message, and triggering a smart contract if the verification passes. The function of the smart contract may be to deduct relevant fees from the second core network device.
[0093] Exemplarily, the processing of verifying the second resource authorization message by other on-chain nodes on the blockchain may include at least one of the following: verifying the second resource authorization message based on the second signature from the second certificate, and at least one of the following information in the second certificate: the identification of the second core network device, the public key of the second core network device, the identification of the first core network device, the public key of the first core network device, and information about the resources of the first network authorized for use by the second network. If the verification passes, it is determined that the resources authorized by the second certificate are provided by the first core network device to the second core network device.
[0094] After the blockchain (e.g., a node on the blockchain) completes the above processing, it sends a deduction notification to the second core network device. Accordingly, upon receiving the deduction notification, the second core network device can download the second voucher from the blockchain. Furthermore, upon receiving the deduction notification, the second core network device can deduct the corresponding fee to pay the first core network device.
[0095] The issuance process of the above second certificate is described below in conjunction with Example 1. In Example 1, the second certificate is a first-level certificate, the first core network device is represented as core network device B (or core network B), and the second core network device is represented as core network device A (or core network A) as an example for description. The process of Example 1 is summarized as follows: When core network A applies for spectrum resources from core network B, core network B will associate the specific spectrum resources with the identity ID of core network A. A , public key PK A Binding is done (core network B uses private key signature) to generate a first-level certificate to authorize spectrum resources; core network B uploads this first-level certificate to the chain for other nodes to verify (verifying the signature in the certificate confirms that it is issued by core network B, the relevant identity in the certificate is core network A, and the transaction content is the specific spectrum resources owned by core network B). After verification, the smart contract is triggered to automatically deduct fees from core network A. Specific explanation is given in conjunction with Figure 6:
[0096] Step 601: Core network device A sends a resource request (i.e., a second resource request message) to core network device B in the off-chain mode to request specific spectrum resources. The resource request includes at least one of the following: ID A Indicates the identity of the requester, that is, the core network device A, the relevant data of the spectrum resources applied for by the core network device A (that is, the information requesting the use of the resources of the first network, which can be simply represented as RS-Att (Resource Attribute)), the sixth signature Sig[H(ID A ,RS-Att)].
[0097] Exemplarily, step 601 can be represented as: core network device A → core network device B: ID A ,RS-Att,Sig[H(ID A ,RS-Att)].
[0098] Among them, the sixth signature is to ensure the integrity of the message while enabling core network device B to ensure that the message comes from core network device A.
[0099] The specific content or format of the spectrum resource data applied for by core network device A is shown in Table 1 below:
[0100] Table 1
[0101] Specifically, ID B The ID of the core network device B is used to indicate the owner of the spectrum resource; the resource number is the number of the resource applied for by the core network device A, and the resource number can be simply represented as Nom. B The relevant descriptions of resource number, usage period and price are the same as those in the above embodiment and will not be repeated here.
[0102] Step 602: After verifying the authenticity of the message sent by core network device A (by verifying the signature and checking the spectrum resource-related data), core network device B responds to the request of core network device A and generates a first-level certificate. Core network device B uploads the resource response (Response) carrying the first-level certificate (i.e., the second resource authorization message) to the blockchain.
[0103] Exemplarily, step 602 can be represented as: Core network device B → Blockchain (smart contract): Cert B-A (Level 1 certificate).
[0104] The purpose of this response is to authorize the requested spectrum resources through a first-level certificate and charge through a smart contract.
[0105] The contents of the first-level certificate are shown in Table 2:
[0106] Table 2
[0107] Specifically, the first-level credential includes the identity ID of core network device A A , core network device A's public key PK A , spectrum resource related data RS-Att, core network device B's identity ID B , core network device B's public key PK B , the signature of the above message by core network device B (i.e. the second signature) Sig B Among them, the identity ID of core network device A A , core network device A's public key PK A , spectrum resource related data RS-Att, core network device B's identity ID B , core network device B's public key PK B Expressed as M1, the second signature can be expressed as Sig B [H(M1)] where Sig B It plays the role of binding the spectrum resources with the identity and public key of core network device A, that is, authorizing core network device A for specific spectrum resources.
[0108] Furthermore, after core network device B completes the issuance of the first-level certificate, it will upload the first-level certificate to the chain for verification by other nodes (the signature in the certificate confirms that the first-level certificate comes from core network device B, the user of the resources in the first-level certificate is core network device A, and the transaction content is the specific spectrum resources owned by core network device B); after the verification is passed, the smart contract is triggered to automatically deduct fees from core network device A to core network device B.
[0109] The smart contract mentioned in this step is a blockchain-based, automated contract execution program that digitally records contract rules and terms. It is highly timely and decentralized, ensuring that contract participants receive their fees promptly and accurately, and adapting to the high-speed demands of the 6G era. Furthermore, smart contracts can set refund conditions, which will automatically execute the refund once the conditions are met.
[0110] Step 603: After core network device A receives the notification of fee deduction (which can be sent to core network device A by the blockchain smart contract), core network device A downloads the first-level certificate from the blockchain.
[0111] Exemplarily, step 603 can be expressed as: core network device A←blockchain (smart contract): download first-level certificate.
[0112] In some possible implementations, the terminal may request the first credential from the second core network device of the network to which the terminal belongs.
[0113] Since the first credential is generated based on the second credential after the second credential is obtained through interactive processing at the core network level of the two networks, in some possible examples, the first credential can also be called a secondary credential.
[0114] In one embodiment, the processing of the terminal before sending the authentication request may also include: sending a first resource request message to the second core network device, wherein the first resource request message is used to request the use of resources of the first network. Further, it may also include: receiving a first resource authorization message from the second core network device of the second network, wherein the first resource authorization message carries the first credential.
[0115] The first resource request message may carry at least one of the following: a temporary identifier of the terminal, and a temporary public key of the terminal.
[0116] Among them, the temporary identifier of the terminal is generated by the terminal. The specific possible content or value of the temporary identifier of the terminal is not limited in this embodiment. As long as the temporary identifier of the terminal is different from the identifier of the terminal, it is within the protection scope of this embodiment. The function of the temporary identifier of the terminal can be to hide its true identity from the first core network device. The identifier of the terminal may refer to one of the following: the terminal's SUPI (Subscription Permanent Identifier), the terminal's SUCI (Subscription Concealed Identifier), the terminal's PEI (Permanent Equipment Identifier), the terminal's 5G-GUTI (5G Globally Unique Temporary Identifier), the terminal's Internal-Group Identifier (IGI), the terminal's GPSI (Generic Public Subscription Identifier), etc.
[0117] The temporary public key of the terminal may be generated by the terminal. This embodiment does not limit the method for generating the temporary public key of the terminal.
[0118] Furthermore, the first resource request may also carry at least one of the following: an identifier of the resource of the first network requested by the terminal, a third random number, a seventh signature, and a certificate of the terminal.
[0119] Here, the resources of the first network requested by the terminal may be included in the resources of the first network requested by the aforementioned second core network device. In other words, the resources of the first network requested by the terminal may be part or all of the resources of the first network requested by the second core network device. For example, the resources of the first network requested by the second core network device are resource 0, resource 1, and resource 2 respectively; the resources requested by the terminal may be resource 0 and resource 1 of the first network. It should be understood that this is merely an example and is not intended to be limiting or exhaustive.
[0120] The third random number may be generated by the terminal, and the generation method of the third random number is not limited in this embodiment.
[0121] Optionally, the seventh signature may be calculated based on the private key of the terminal and at least one of the following parameters: an identifier of the resource of the first network requested by the terminal, a third random number, a temporary identifier of the terminal, and a temporary public key of the terminal.
[0122] Exemplarily, the calculation of the seventh signature may be: using a signature algorithm, based on the private key of the terminal, to calculate at least one of the identifier of the first network resource requested by the terminal, the third random number, the temporary identifier of the terminal, and the temporary public key of the terminal. For example, it can be expressed by the following formula: Sig[N1,ID va ,PK va ,Nom], where N1 represents the third random number, ID va is the temporary identifier of the terminal, PK va is the temporary public key of the terminal, and Nom is the identifier (or number) of the resource of the first network requested by the terminal.
[0123] Exemplarily, the calculation of the seventh signature may be: performing a hash calculation based on at least one of the identifier of the first network resource requested by the terminal, the third random number, the temporary identifier of the terminal, and the temporary public key of the terminal to obtain a seventh hash value; and encrypting the seventh hash value based on the private key of the terminal to obtain the seventh signature. For example, the following formula may be used to represent the seventh signature: Sig[H(N1,ID va ,PK va ,Nom)], where N1 represents the third random number, ID va is the temporary identifier of the terminal, PK va is the temporary public key of the terminal, and Nom is the identifier (or number) of the resource of the first network requested by the terminal.
[0124] Optionally, the seventh signature can be calculated based on the private key of the terminal for the first ciphertext information, and the first ciphertext information is calculated by encrypting at least one of the following parameters using the public key of the second core network device: an identifier of the resources of the first network requested by the terminal, a temporary identifier of the terminal, and a temporary public key of the terminal.
[0125] Exemplarily, the calculation of the first ciphertext information can be expressed as: Among them, PK A is the public key of the second core network device, Enc represents encryption calculation, and the meanings of other parameters in the formula are the same as those in the previous embodiment and are not repeated here.
[0126] Exemplarily, the seventh signature may be calculated by using a signature algorithm based on the private key of the terminal to calculate the first ciphertext information and the third random number. For example, the following formula may be used: The meanings of the parameters in the formula are the same as those in the above embodiment and are not described in detail.
[0127] Exemplarily, the calculation of the seventh signature may be: performing a hash calculation based on the first ciphertext information and the third random number to obtain a seventh hash value; and encrypting the seventh hash value based on the terminal's private key to obtain the seventh signature. For example, the following formula may be used: The meanings of the parameters in the formula are the same as those in the above embodiment and are not described in detail.
[0128] The certificate of the terminal may be issued by the second core network device for the terminal. This embodiment does not limit the method of issuing or obtaining the certificate of the terminal.
[0129] The terminal certificate carries the terminal's public key, wherein the method for generating the terminal's public key is not limited in this embodiment.
[0130] Furthermore, the certificate of the terminal may also carry at least one of the following: an identifier of the second core network device, an identifier of the terminal, and an eighth signature.
[0131] The eighth signature may be generated by the second core network device, and the timing of generating the eighth signature is not limited in this embodiment. The eighth signature may be calculated based on the private key of the second core network device and at least one of the following parameters: the public key of the terminal and the identifier of the terminal.
[0132] Exemplarily, the calculation of the eighth signature may be: using a signature algorithm, based on the private key of the second core network device, to calculate at least one of the public key of the terminal and the identifier of the terminal. For example, the following formula may be used to represent it: Sig[ID a ,PK a ], where ID a is the terminal identifier, PK a The public key of the terminal.
[0133] Exemplarily, the calculation of the eighth signature may be: performing a hash calculation based on at least one of the public key of the terminal and the identifier of the terminal to obtain an eighth hash value; and encrypting the eighth hash value based on the private key of the second core network device to obtain the eighth signature. For example, the following formula may be used to represent the eighth signature: A [H(ID a ,PK a )], where Sig A [] indicates that the signature is calculated using the private key of the second core network device. The meaning of the parameters in the formula is the same as in the previous embodiment and will not be repeated.
[0134] In one embodiment, the processing by the second core network device may include: receiving a first resource request message from the terminal. Further, the processing may include: sending a first resource authorization message to the terminal, wherein the first resource authorization message carries the first credential.
[0135] The second core network device may execute the process of sending the first resource authorization message after completing verification of the first resource request message.
[0136] Optionally, when the first resource request message carries the terminal's certificate, after the second core network device receives the first resource request message from the terminal, it can also verify the authenticity of the terminal's certificate based on the public key of the second core network device. Specifically, the second core network device can verify the authenticity of the terminal's certificate based on the public key and the eighth signature in the terminal's certificate. For example, the above verification process can be: using a signature verification algorithm, decrypting the eighth signature based on the public key of the second core network device to obtain an eighth parameter to be verified; when the eighth parameter to be verified is the same as the terminal's identifier and the terminal's public key, determining that the authenticity of the terminal's certificate has been verified. Alternatively, the above verification process can be: performing a hash calculation based on the terminal's identifier and the terminal's public key to obtain an eighth verification hash value, decrypting the eighth signature based on the public key of the second core network device to obtain an eighth decrypted value; when the eighth decrypted value and the eighth verification hash value are the same, determining that the terminal's identifier and the terminal's public key have been verified.
[0137] Optionally, when the first resource request message carries the seventh signature, after the second core network device receives the first resource request message from the terminal, it can also verify the validity of the first resource request message (that is, the first resource request message has not been tampered with) based on the terminal's public key (which can be the terminal's public key carried in the terminal's certificate). For example, the above verification process can be: using a signature verification algorithm, decrypting the seventh signature based on the terminal's public key to obtain a seventh parameter to be verified; when the seventh parameter to be verified is the same as the parameter carried by the first resource request message (parameters other than the first signature and the terminal's certificate), it is determined that the validity of the first resource request message has been verified. Alternatively, the above verification process can be: performing a hash calculation based on the parameters carried by the first resource request message (parameters other than the first signature and the terminal's certificate) to obtain a seventh verification hash value, decrypting the seventh signature based on the terminal's public key to obtain a seventh decrypted value; when the seventh decrypted value and the seventh verification hash value are the same, it is determined that the terminal's identity and the terminal's public key have been verified.
[0138] In addition, it may also include: if the first resource request message fails, the second core network device may also end the processing and / or send a verification failure response message to the terminal.
[0139] Optionally, when the first resource request message carries the first encrypted information, the second core network device can also perform the following processing: use the public key of the second core network device to decrypt the first encrypted information to obtain at least one of the following parameters: the identifier of the resource of the first network requested by the terminal, the temporary identifier of the terminal, and the temporary public key of the terminal.
[0140] The first credential includes at least a first signature and a second signature. The second signature is carried by the second credential within the first credential. Specifically, the first credential includes the first signature and the second credential; the first credential also includes at least one of the following: a temporary identifier of the terminal and a temporary public key of the terminal. The generation method of the second credential has been detailed in the previous embodiment and will not be repeated here.
[0141] Optionally, the first signature is calculated based on the private key of the second core network device and at least one of the following information: the temporary identifier of the terminal, the temporary public key of the terminal, and the second certificate.
[0142] Exemplarily, the calculation of the first signature may be: using a signature algorithm, based on the private key of the second core network device, to calculate at least one of the temporary identifier of the terminal, the temporary public key of the terminal, and the second certificate. For example, assuming that the second certificate, the temporary identifier of the terminal, and the temporary public key of the terminal are represented as M2, the calculation of the first signature may be represented by the following formula: Sig A [M2].
[0143] Exemplarily, the calculation of the first signature may be: performing a hash calculation based on the temporary identifier of the terminal, the temporary public key of the terminal, and at least one of the second credentials to obtain a first hash value; and encrypting the first hash value based on the private key of the second core network device to obtain the first signature. For example, assuming that the second credential, the temporary identifier of the terminal, and the temporary public key of the terminal are represented as M2, the calculation of the first signature may be represented by the following formula: Sig A [H(M2)].
[0144] The first credential generated by the above solution can be used to identify the second credential with the temporary identification ID of the terminal. va , the terminal's temporary public key PK va The private key of the second core network device is used for signing and binding to authorize the terminal to request the use of the resources of the first network through the first certificate.
[0145] Optionally, the first resource authorization message may also carry a fourth random number. The fourth random number is used to indicate that the first resource authorization message is not a replay. The fourth random number is related to the third random number. For example, the fourth random number may be equal to the third random number; for example, the fourth random number may be equal to the third random number plus a first specified value; wherein the first specified value may be configured according to actual conditions. In some examples, the first specified value may be equal to 1, that is, the fourth random number is equal to the third random number plus 1. In some other examples, the first specified value may also be greater than 1. All possible values of the first specified value are not limited or enumerated here.
[0146] The issuance process of the above first certificate is described below in conjunction with Example 2. In Example 2, the first certificate is a secondary certificate, the terminal is indicated as UE-a, the first core network device is indicated as core network device B (or core network B), and the second core network device is indicated as core network device A (or core network A) as an example for description. The process of Example 2 is summarized as follows: When UE-a in the jurisdiction of core network A applies for spectrum resources to core network A, core network A combines the primary certificate with the temporary identity ID of UE-a. va , temporary public key PK va Binding (core network A uses private key signature) generates a secondary certificate to authorize spectrum resources. The temporary identity can hide the real identity from the service provider, thereby achieving privacy protection. The issuance process of the secondary certificate involved in Example 2 is illustrated in conjunction with Figure 7:
[0147] Step 701: UE-a in the operator A area sends a first resource request message to the core network device A, carrying the UE-a certificate Cert A-a , signature Sig (i.e. the seventh signature in the aforementioned embodiment), a third random number N1, and the first ciphertext information.
[0148] Exemplarily, step 701 may be represented as: UE-a → core network device A:
[0149] The meaning of each content is the same as that of the above embodiment and will not be repeated here.
[0150] About UE-a's certificate Cert A-a The specific contents carried are shown in Table 3:
[0151] Table 3
[0152] Among them, UE-a's certificate Cert A-a The signature Sig enables the core network A to verify that the identity of a is legitimate and the message is complete, that is, the source of the message is a and has not been tampered with (Cert in the request A-a It is issued by core network A to user a, so the public key of core network A can be used to verify the certificate Cert A-a The authenticity of the certificate Cert A-a Afterwards, the signature Sig sent by a can be verified using the public key in the certificate. If the signature verification is successful, it indicates that the message is indeed from a and the message has not been tampered with); Nom (the identifier (or number) of the resource of the network where the core network device B is located that UE-a requests to use) indicates the spectrum resource that UE-a wants to apply for; the third random number N1 indicates the freshness of the session; The ciphertext corresponding to the temporary identity of UE-a will not reveal the corresponding relationship between its real identity and the temporary identity.
[0153] Step 702: After verifying the authenticity of the received first resource request message, the core network device A sends a first resource authorization message to UE-a, carrying the secondary credential.
[0154] For example, step 702 can be represented as: core network device A→UE-a:Enc[Cert B-A-a ], N1+1; among them, Cert B-A-a Indicates the secondary certificate; "N1+1" indicates the fourth random number.
[0155] N1+1 indicates that the message is not a replay; the secondary credential implements the authorization of spectrum resources. The secondary credential is a combination of the primary credential and the temporary identity ID of user a. va , temporary public key PK va Do binding (A signs with private key).
[0156] The contents of the secondary certificate are as shown in Table 4:
[0157] Table 4
[0158] Specifically, ID B PK B 、RS-Att、ID A PK A 、Sig B [H(M1)] is the content of the first-level certificate. Its specific description is the same as that of Figure 6 above, so it will not be repeated. The content of M2 includes all the content of the first-level certificate and ID va ,PK va .
[0159] In some possible implementations, when the terminal accesses a roaming network (ie, the first network), a network device of the roaming network needs to perform relevant authentication processing.
[0160] In one embodiment, the terminal may send an authentication request to the access network device after receiving the first resource authorization message carrying the first credential.
[0161] Optionally, the authentication request carries a first credential, and the first credential carries at least one of the following: a first signature for verifying the terminal's authority to use the resources of the first network authorized by the second network, and a second signature for verifying the second network's authority to use the resources of the first network.
[0162] The first credential also carries at least one of the following: a temporary identification of the terminal, and a temporary public key of the terminal.
[0163] The second signature is carried by the second certificate in the first certificate, and the second certificate also carries at least one of the following: the identification of the first core network device in the first network, the public key of the first core network device, the identification of the second core network device in the second network, the public key of the second core network device, and information about the resources of the first network authorized for use by the second network.
[0164] The detailed description of the first certificate and the second certificate is the same as that of the above embodiment and will not be repeated.
[0165] Optionally, in addition to the first credential, the authentication request also carries at least one of the following: an identifier of the first network device, a first random number, and a first security parameter for calculating a communication key between the terminal and the first network device.
[0166] The authentication request also carries a third signature for verifying the validity of the authentication request. The third signature is calculated based on the temporary private key of the terminal and at least one of the following information: an identifier of the first network device, a first random number, and a first security parameter used to calculate a communication key between the terminal and the first network device. The temporary private key of the terminal is generated locally by the terminal, and the specific generation method is not limited.
[0167] The identifier of the first network device may refer to the identifier of the access network device or the identifier of the third core network device. It should be understood that the identifier of the first network device may also be further combined with other identifiers related to the first network, for example, at least one of the following other identifiers related to the first network: the identifier of the first network (such as PLMN ID, etc.), the cell-related identifier of the first network, etc. Here, the cell-related identifier may include at least one of C-RNTI (Cell Radio Network Temporary Identity), PCI, etc.
[0168] Exemplarily, the third signature may be calculated by using a signature algorithm and calculating at least one of the identifier of the first network device, the first random number, and the first security parameter based on the temporary private key of the terminal.
[0169] Exemplarily, the calculation of the third signature may be: performing a hash calculation based on at least one of the identifier of the first network device, the first random number, and the first security parameter to obtain a third hash value; and encrypting the third hash value based on the temporary private key of the terminal to obtain the third signature. For example, the calculation of the third signature is expressed by the following formula: Sigva [H(ID b ,N,X va ·P)], where Sig va [] indicates that the temporary private key of the terminal is used to calculate the signature, H() indicates the hash function, ID b is the identifier of the first network device, N is the first random number, and "X va ·P” is the first safety parameter.
[0170] In one embodiment, after receiving the authentication request, the first network device first verifies the authentication request and its related contents.
[0171] Optionally, the authority of the second network to use the resources of the first network is verified based on the public key of the first core network device, the second signature and at least one of the following information: the identification of the first core network device, the public key of the first core network device, the identification of the second core network device, the public key of the second core network device, and information on the resources of the first network authorized for use by the second network.
[0172] For example, the above verification process may be: using a signature verification algorithm, decrypting the second signature based on the public key of the first core network device to obtain a second parameter to be verified; when the second parameter to be verified is the same as the identifier of the second core network device, the public key of the second core network device, the identifier of the first core network device, the public key of the first core network device, and the information of the resources of the first network authorized for use by the second network, determining that the second core network device has passed the permission verification for using the resources of the first core network device. Alternatively, the above verification process may be: performing a hash calculation based on the identifier of the first core network device, the public key of the second core network device, the identifier of the first core network device, the public key of the first core network device, and the information of the resources of the first network authorized for use by the second network to obtain a second verification hash value, decrypting the second signature based on the public key of the second core network device to obtain a second decrypted value; when the second decrypted value and the second verification hash value are the same, determining that the second core network device has passed the permission verification for using the resources of the first core network device.
[0173] In addition, the method may further include ending the processing and / or returning an authentication failure result to the terminal when verification of the authority of the second network to use the resources of the first network fails.
[0174] Optionally, the processing of the first network device based on the first signature verification may include: verifying the terminal's authority to use the resources of the first network authorized by the second network based on the public key of the second core network device, the first signature and at least one of the following information: the temporary identification of the terminal, the temporary public key of the terminal, and the second certificate.
[0175] Specifically, the authority of the terminal to use the resources of the first network authorized by the second network is verified based on the public key of the second core network device, the first signature and at least one of the following information: the temporary identifier of the terminal, the temporary public key of the terminal, the identifier of the second core network device, the public key of the second core network device, the identifier of the first core network device, the public key of the first core network device, and the information of the resources of the first network authorized for use by the second network.
[0176] For example, the above verification process may be: using a signature verification algorithm, decrypting the first signature based on the public key of the second core network device to obtain a first parameter to be verified; if the first parameter to be verified is the same as the temporary identifier of the terminal, the temporary public key of the terminal, the second signature, the identifier of the second core network device, the public key of the second core network device, the identifier of the first core network device, the public key of the first core network device, and the information of the resources of the first network authorized for use by the second network, determining that the authentication is successful. Alternatively, the above verification process may be: performing a hash calculation based on the temporary identifier of the terminal, the temporary public key of the terminal, the second signature, the identifier of the second core network device, the public key of the second core network device, the identifier of the first core network device, the public key of the first core network device, and the information of the resources of the first network authorized for use by the second network to obtain a first verification hash value, decrypting the first signature based on the public key of the second core network device to obtain a first decrypted value; if the first decrypted value and the first verification hash value are the same, determining that the authentication is successful.
[0177] The above-mentioned processing sequence for verification based on the first signature and the second signature in the first credential can be as follows: first, based on the public key and the second signature of the first core network device, the second network's permission to use the resources of the first network is verified. If the verification is confirmed to be successful, the public key of the second core network device carried in the second credential can be determined to be authentic; further, the terminal is authenticated based on the public key and the first signature of the second core network device. This is because the first network device itself belongs to the first network, so the first network device can assume that the public key of the first core network device is authentic, so the verification process can be performed based on the public key and the second signature of the first core network device first.
[0178] Optionally, the first network device can verify the validity of the authentication message based on the third signature. This can specifically include verifying the validity of the authentication request based on the terminal's temporary public key, the third signature, and at least one of the following information: an identifier of the first network device, a first random number, and a first security parameter used to calculate a communication key between the terminal and the first network device. Because the second signature in the first credential is first verified, it can be determined that the terminal's temporary public key carried in the first credential is authentic, and the third signature can then be verified based on the terminal's temporary public key.
[0179] For example, the above verification process may include: using a signature verification algorithm, decrypting the third signature based on the temporary public key of the terminal to obtain a third parameter to be verified; if the third parameter to be verified is the same as the identifier, first random number, and first security parameter of the first network device, determining that the validity verification of the authentication message has passed. Alternatively, the above verification process may include: performing a hash calculation based on the identifier, first random number, and first security parameter of the first network device to obtain a third verification hash value, decrypting the third signature based on the temporary public key of the terminal to obtain a third decrypted value; if the third decrypted value and the third verification hash value are the same, determining that the validity verification of the authentication message has passed.
[0180] In addition, the method may also include ending the processing and / or returning an authentication failure result to the terminal when the validity verification of the authentication message fails.
[0181] In one embodiment, after the first network device performs one or more of the aforementioned verification processes based on the authentication request and the verification passes, it may send an authentication response to the terminal. The method further includes: sending an authentication response to the terminal, wherein the authentication response carries the certificate of the first network device, and the certificate of the first network device includes a fourth signature for authenticating the first network device. On the terminal side, the method further includes: receiving an authentication response from the first network device, wherein the authentication response carries the certificate of the first network device, and the certificate of the first network device includes a fourth signature for authenticating the first network device.
[0182] The authentication response may also carry an authentication result, which may indicate that the terminal authentication is successful.
[0183] Optionally, the certificate of the first network device further includes at least one of the following: an identifier of the first core network device, an identifier of the first network device, and a public key of the first network device. The certificate of the first network device may be issued by the first core network device for the first network device.
[0184] On the terminal side, the method further includes: authenticating the first network device based on the public key of the first core network device, the fourth signature and at least one of the following information: the identification of the first network device, the public key of the first network device.
[0185] For example, the above verification process may be: using a signature verification algorithm, decrypting the fourth signature based on the public key of the first core network device to obtain a fourth parameter to be verified; if the fourth parameter to be verified is the same as the identifier of the first network device and the public key of the first network device, determining that the authentication of the first network device is successful. Alternatively, the above verification process may be: performing a hash calculation based on the identifier of the first network device and the public key of the first network device to obtain a fourth verification hash value, decrypting the fourth signature based on the public key of the first core network device to obtain a fourth decrypted value; if the fourth decrypted value and the fourth verification hash value are the same, determining that the authentication of the first network device is successful.
[0186] In addition, the method may further include ending the processing and / or returning an authentication failure result to the first network device when the authentication of the first network device fails.
[0187] Optionally, the authentication response further carries at least one of the following: a temporary identifier of the terminal, a second random number, and a second security parameter used to calculate a communication key between the terminal and the first network device.
[0188] The authentication response also carries a fifth signature for verifying the validity of the authentication response. The fifth signature is calculated based on the private key of the first network device and at least one of the following information: a temporary identifier of the terminal, a second random number, and a second security parameter for calculating a communication key between the terminal and the first network device.
[0189] The second random number is used to indicate that the message is not a replay. The second random number is related to the first random number. For example, the second random number can be equal to the first random number; for example, the second random number can be equal to the first random number plus a second specified value. The second specified value can be configured based on actual circumstances. In some examples, the second specified value can be equal to 1, that is, the second random number is equal to the first random number plus 1. In other examples, the second specified value can also be greater than 1. This does not limit or exhaustively list all possible values of the second specified value.
[0190] Exemplarily, the process of calculating the fifth signature on the first network device side may be: using a signature algorithm, based on the private key of the first network device, to calculate at least one of the temporary identifier of the terminal, the second random number, and the second security parameter.
[0191] Exemplarily, the process of calculating the fifth signature on the first network device side may be: performing a hash calculation based on at least one of the temporary identifier of the terminal, the second random number, and the second security parameter to obtain a fifth hash value; and encrypting the fifth hash value based on the private key of the first network device to obtain the fifth signature. For example, the calculation of the fifth signature is expressed by the following formula: Sig b [H(ID va ,N+1,X b ·P), where Sig b [] indicates that the signature is calculated using the private key of the first network device, H() indicates the hash function, and ID va is the temporary identifier of the terminal, N+1 is the second random number, and "X b P" is the second safety parameter.
[0192] On the terminal side, the method also includes: the method also includes: verifying the validity of the authentication response based on the public key of the first network device, the fifth signature and at least one of the following information: the temporary identifier of the terminal, the second random number, and the second security parameter.
[0193] The public key of the first network device can be carried in the certificate of the first network device. The terminal can first verify the certificate of the first network device to confirm that the first network device has passed the authentication, and then confirm the authenticity of the public key of the first network device, and then verify the validity of the authentication response based on the public key of the first network device and the fifth signature.
[0194] For example, the terminal's verification process may include: using a signature verification algorithm to decrypt the fifth signature based on the public key of the first network device to obtain the fifth parameter to be verified; if the fifth parameter to be verified is identical to the terminal's temporary identifier, the second random number, and the second security parameter, determining that the authentication response has passed the validity verification. Alternatively, the verification process may include: performing a hash calculation based on the terminal's temporary identifier, the second random number, and the second security parameter to obtain a fifth verification hash value; decrypting the fifth signature based on the public key of the first network device to obtain a fifth decrypted value; if the fifth decrypted value and the fifth verification hash value are identical, determining that the authentication response has passed the validity verification.
[0195] In addition, the method may further include ending the processing and / or returning an authentication failure result to the first network device when the validity verification of the authentication response fails.
[0196] Furthermore, through the above two-way authentication process between the terminal and the first network device, the first network device can obtain the first security parameter sent by the terminal, and the first network device has already generated the second security parameter locally; the terminal can also obtain the second security parameter sent by the first network device, and the terminal has already generated the first security parameter locally. Therefore, the processing performed by the terminal and the first network device respectively may also include: calculating a communication key between the terminal and the first network device based on the second security parameter and the first security parameter. In this way, the terminal and the first network device obtain the same communication key, and can subsequently communicate using this communication key (or session key).
[0197] The following describes the above process of using the first credential in conjunction with Example 3. In Example 3, the first credential is a secondary credential, the terminal is UE-a, the first network device is base station b, and the first core network device to which the first network device belongs is core network device B (or referred to as core network B) as an example for description. The overview is as follows: UE-a can access base station b under core network B with the secondary credential. After UE-a and base station b complete two-way authentication, UE-a can successfully use spectrum resources. The process of using the secondary credential provided in Example 3 is exemplarily described in conjunction with Figure 8:
[0198] Step 801: UE-a requests access to base station b under core network device B. Specifically, UE-a requests authentication from base station b and negotiates a session key with base station b. The request sent by UE-1 may carry a secondary credential and a first security parameter X used to calculate the session key between UE-a and base station b. va ·P and so on.
[0199] Exemplarily, step 801 may be expressed as:
[0200] UE-a→base station b:Cert B-A-a ,ID b ,N,X va ·P,Sig va [H(ID b ,N,X va ·P)].
[0201] Specifically, the authentication request can carry: Cert B-A-a Secondary certificate, Sig va It enables base station b to ensure ID va The identity of the request message is legal and has not been tampered with (the Sig B A's public key PK can be trusted by B A ,Sig A It can make b trust the public key PK va ), ID bIndicates the identity of the base station b to be accessed; the first random number N can indicate the freshness of the session, X va P is the DH parameter (first security parameter) used by UE-a to negotiate the session key.
[0202] Step 802: After verifying the authenticity of the received request message, base station b performs two-way authentication with UE-a and negotiates a session key.
[0203] Exemplarily, step 802 may be represented as: base station b → UE-a: Cert B-b ,ID va ,N+1,X b ·P,Sig b [H(ID va ,N+1,X b ·P)].
[0204] Specifically, base station b provides its own identity credential, i.e., base station b's certificate Cert, to UE-a. B-b , where the certificate Cert B-b and signature Sig b It allows user a to verify that the source of the message received is user b and that the message has not been tampered with (Cert B-b is the certificate issued by core network B to base station b); N+1 is the second random number used to indicate that the message is not a replay, ID va Indicates that base station b has received the request (authentication request) from UE-a, X b P is the DH parameter (i.e., the second security parameter) used by b to negotiate the session key.
[0205] The certificate of base station b includes the following contents:
[0206] Table 5
[0207] Among them, ID b It may also be further combined with other identifiers, such as at least one of PLMN ID (ie, the identifier of the first network), C-RNTI, PCI, and the like.
[0208] It should also be noted that this example is an illustrative description using the first network device as a base station. In some other examples, the first network device may also be a third core network device in the first network. In this case, the above ID b It can also be replaced with the ID of the third core network device, and can further be combined with at least one of PLMN ID, C-RNTI, PCI, etc.
[0209] After the negotiation between base station b and UE-a is completed, base station b and UE-a will calculate the session key X b·X va P, and the base station b and UE-a can subsequently communicate using this session key.
[0210] In some possible implementations, if the terminal fails to access the network where the first network device is located, the terminal may further send information of access failure or registration failure to the second core network device.
[0211] After the first network device receives the authentication request, the method may further include: sending a denial of service response message to the terminal in a case where it is determined based on the local policy that the terminal is denied access to the network.
[0212] The denial of service response message may carry indication information of the denial of service, a denial of service credential, a certificate of the first network device, a temporary identifier of the terminal, a first credential, and a first random number.
[0213] The denial-of-service credential may be a ninth signature, calculated based on the private key of the first network device against the denial-of-service indication and at least one of the following parameters: the temporary identifier of the terminal, the first credential, and the first random number. The algorithm for this ninth signature is similar to that of the signature in the preceding embodiment and is not described again.
[0214] The following describes the process of the first network device denying service in conjunction with Example 4. In Example 4, the terminal is represented as UE-a, the first core network device is represented as core network device B, and the first network device is represented as base station b. Specifically, as shown in Figure 9, it includes:
[0215] Step 901 is the same as step 801 and will not be described in detail.
[0216] Step 902: Base station b strategically denies service (e.g., prioritizes local users), and then base station b sends a denial of service response message to UE-a. For example, step 902 can be represented as: Base station b → UE-a: Cert B-A-a ,ID va ,N,False,Cert B-b ,Sig b [H(M)] False indicates the indication of denial of service, Sig b [H(M)] represents the ninth signature, where M includes the secondary certificate, the temporary identifier of UE-a, indication information of denial of service, and the first random number N.
[0217] In some embodiments, after the terminal receives the authentication response from the first network device indicating that service for the terminal is refused, the method may further include: sending a refusal of service certificate to the second core network device.
[0218] Optionally, the terminal sends a denial of service credential to the second core network device, which may mean that the terminal sends all the contents contained in the authentication response to the second core network device; or, it may mean that the terminal sends the denial of service credential and at least one of the following parameters to the second core network device: indication information of denial of service, certificate of the first network device, temporary identification of the terminal, first credential, and first random number.
[0219] After receiving the denial of service certificate, the second core network device can also verify the denial of service certificate. For example, the denial of service certificate specifically includes the ninth signature. The second core network device can perform verification based on the public key of the first network device, the ninth signature, and at least one of the following parameters: denial of service indication information, the certificate of the first network device, the temporary identification of the terminal, the first certificate, and the first random number. The specific process of verifying the ninth signature is similar to the process of verifying the aforementioned signature and will not be repeated here.
[0220] The processing by the second core network device may further include: uploading all received denial-of-service credentials to the blockchain when the second credential expires. Accordingly, after receiving all denial-of-service credentials from the second core network device, the node (other node) on the blockchain deducts the corresponding fee from the first core network device if all denial-of-service credentials are verified to be successful.
[0221] The term of the second certificate may be the same as the period of use during which the second core network device requests to use the resources of the first network.
[0222] Uploading all received denial of service credentials to the blockchain may refer to uploading all received denial of service credentials and parameters associated with each denial of service credential to the blockchain. The parameters associated with each denial of service credential may include indication information for each denial of service, a certificate of the first network device corresponding to each denial of service credential, a temporary identifier of the terminal corresponding to each denial of service credential, the first credential, and a first random number corresponding to each denial of service credential.
[0223] Verification by a node on the blockchain of any one of the denial of service credentials may refer to: successfully verifying the ninth signature using the public key of the first network device, thereby determining that the denial of service credential verification has passed.
[0224] By adopting the above solution, when the terminal accesses a first network to which it does not belong, a first certificate carrying the verification permission of the terminal belonging to the second network to use the resources of the first network can be sent to the network device under the first network. In this way, when the terminal has the need to access other networks, the terminal can be authenticated only through the first certificate. While ensuring security, the authentication efficiency can also be improved, avoiding the problem of low efficiency caused by the need for core network equipment to perform security calculations to achieve authentication in related technologies.
[0225] The above blockchain-based inter-operator spectrum resource sharing security solution implements secure authentication, billing, user ID privacy protection, and dispute resolution. Specifically, this invention enables networks belonging to different operators to securely share their available authorized spectrum and efficiently charge for it while protecting user privacy. By leveraging the timeliness and decentralized nature of smart contracts, terminals can use shared spectrum resources across roaming networks without disclosing their location or consumption history.
[0226] Furthermore, the present invention adopts a billing model with a full lease. That is, when all terminals on one operator's network use the shared spectrum of another operator's network, the contract between the two networks stipulates that all terminal bills are bundled together for billing and settlement between the two operators. Only abnormal bills indicating denial of service are processed on the chain to avoid disputes. The above solution provided by this embodiment can meet the needs of efficient spectrum sharing in the 6G era.
[0227] In addition, in the above scheme, the terminal's privacy information such as identification and public key are hidden. When the terminal accesses a network that does not belong to itself, it uses the hidden temporary identification and hidden temporary public key as well as signature and other information to complete authentication, thereby ensuring the privacy security of the terminal.
[0228] FIG10 is a schematic diagram of the structure of a terminal according to an embodiment of the present application, including:
[0229] The first communication unit 1001 is configured to send an authentication request to a first network device in a first network, wherein the authentication request carries a first credential for verifying the authority of the terminal belonging to the second network to use resources of the first network.
[0230] The first credential carries at least one of the following: a first signature for verifying the terminal's authority to use resources of the first network authorized by the second network; and a second signature for verifying the second network's authority to use resources of the first network.
[0231] The first credential also carries at least one of the following: a temporary identification of the terminal, and a temporary public key of the terminal.
[0232] The second signature is carried by the second certificate in the first certificate, and the second certificate also carries at least one of the following: the identification of the first core network device in the first network, the public key of the first core network device, the identification of the second core network device in the second network, the public key of the second core network device, and information about the resources of the first network authorized for use by the second network.
[0233] The authentication request also carries a third signature for verifying the validity of the authentication request, and the third signature is calculated based on the temporary private key of the terminal and at least one of the following information: an identifier of the first network device, a first random number, and a first security parameter for calculating a communication key between the terminal and the first network device.
[0234] The authentication request also carries at least one of the following: an identifier of the first network device, a first random number, and a first security parameter used to calculate a communication key between the terminal and the first network device.
[0235] The first communication unit 1001 is configured to receive an authentication response from the first network device, wherein the authentication response carries a certificate of the first network device, and the certificate of the first network device includes a fourth signature for authenticating the first network device.
[0236] The certificate of the first network device further includes at least one of the following: an identifier of a first core network device in the first network, an identifier of the first network device, and a public key of the first network device.
[0237] As shown in Figure 10, the terminal also includes: a first processing unit 1002, which is used to authenticate the first network device based on the public key of the first core network device, the fourth signature and at least one of the following information: the identification of the first network device, the public key of the first network device.
[0238] The authentication response also carries a fifth signature for verifying the validity of the authentication response.
[0239] The authentication response further carries at least one of the following: a temporary identifier of the terminal, a second random number, and a second security parameter used to calculate a communication key between the terminal and the first network device.
[0240] The first processing unit 1002 is configured to verify the validity of the authentication response based on the public key of the first network device, the fifth signature, and at least one of the following information: the temporary identifier of the terminal, the second random number, and the second security parameter.
[0241] The first processing unit 1002 is configured to calculate a communication key between the terminal and the first network device based on the second security parameter and the first security parameter.
[0242] The first communication unit 1001 is configured to receive a first resource authorization message from a second core network device of the second network, wherein the first resource authorization message carries the first credential.
[0243] The first communication unit 1001 is used to send a first resource request message to the second core network device, wherein the first resource request message is used to request the use of resources of the first network.
[0244] The first resource request message carries at least one of the following: a temporary identifier of the terminal and a temporary public key of the terminal.
[0245] The first network device includes one of the following: an access network device, a third core network device.
[0246] FIG11 is a schematic diagram of the composition structure of a first network device according to an embodiment of the present application, including:
[0247] The second communication unit 1101 is configured to receive an authentication request from a terminal, wherein the authentication request carries a first credential for verifying the authority of the terminal belonging to the second network to use resources of the first network, and the first network device belongs to the first network.
[0248] The first credential carries at least one of the following: a first signature for verifying the terminal's authority to use resources of the first network authorized by the second network; and a second signature for verifying the second network's authority to use resources of the first network.
[0249] The first credential also carries at least one of the following: a temporary identification of the terminal, and a temporary public key of the terminal.
[0250] The second signature is carried by the second certificate in the first certificate, and the second certificate also carries at least one of the following: the identification of the first core network device in the first network, the public key of the first core network device, the identification of the second core network device in the second network, the public key of the second core network device, and information about the resources of the first network authorized for use by the second network.
[0251] As shown in Figure 11, it also includes: a second processing unit 1102, which is used to verify the terminal's authority to use the resources of the first network authorized by the second network based on the public key of the second core network device, the first signature and at least one of the following information: the temporary identifier of the terminal, the temporary public key of the terminal, and the second certificate.
[0252] The second processing unit 1102 is used to verify the authority of the second network to use the resources of the first network based on the public key of the first core network device, the second signature and at least one of the following information: the identification of the first core network device, the public key of the first core network device, the identification of the second core network device, the public key of the second core network device, and information about the resources of the first network authorized for use by the second network.
[0253] The authentication request also carries a third signature for verifying the validity of the authentication request.
[0254] The authentication request also carries at least one of the following: an identifier of the first network device, a first random number, and a first security parameter used to calculate a communication key between the terminal and the first network device.
[0255] The second processing unit 1102 is used to verify the validity of the authentication request based on the temporary public key of the terminal, the third signature and at least one of the following information: the identification of the first network device, the first random number, and the first security parameter used to calculate the communication key between the terminal and the first network device.
[0256] The second communication unit 1101 is configured to send an authentication response to the terminal, wherein the authentication response carries the certificate of the first network device, and the certificate of the first network device includes a fourth signature for authenticating the first network device.
[0257] The certificate of the first network device further includes at least one of the following: an identifier of a first core network device of the first network, an identifier of the first network device, and a public key of the first network device.
[0258] The authentication response also carries a fifth signature for verifying the validity of the authentication response, and the fifth signature is calculated based on the private key of the first network device and at least one of the following information: a temporary identifier of the terminal, a second random number, and a second security parameter for calculating a communication key between the terminal and the first network device.
[0259] The authentication response further carries at least one of the following: a temporary identifier of the terminal, a second random number, and a second security parameter used to calculate a communication key between the terminal and the first network device.
[0260] The second processing unit 1102 is configured to calculate a communication key between the terminal and the first network device based on the first security parameter and the second security parameter.
[0261] The first network device includes one of the following: an access network device, a third core network device.
[0262] FIG12 is a schematic diagram of the composition structure of a second core network device according to an embodiment of the present application, including:
[0263] The third communication unit 1201 is used to send a first resource authorization message to the terminal, wherein the first resource authorization message carries a first credential for verifying the authority of the terminal belonging to the second network to use the resources of the first network, and the second core network device belongs to the second network.
[0264] The first credential carries at least one of the following: a first signature for verifying the terminal's authority to use resources of the first network authorized by the second network; and a second signature for verifying the second network's authority to use resources of the first network.
[0265] The first credential further includes at least one of the following: a temporary identification of the terminal, a temporary public key of the terminal.
[0266] The second signature is carried by the second certificate in the first certificate, and the second certificate also carries at least one of the following: the identification of the second core network device, the public key of the second core network device, the identification of the first core network device, the public key of the first core network device, and information about resources of the network where the first core network device is located that the second core network device is authorized to use.
[0267] The first signature is calculated based on the private key of the second core network device and at least one of the following information: the temporary identifier of the terminal, the temporary public key of the terminal, and the second certificate.
[0268] The third communication unit 1201 is configured to receive a first resource request message from the terminal, wherein the first resource request message is used to request the use of resources of the first network.
[0269] The first resource request message carries at least one of the following: a temporary identifier of the terminal and a temporary public key of the terminal.
[0270] The third communication unit 1201 is used to send a second resource request message to the first core network device, wherein the second resource request message is used to request the use of resources of the first network; and download the second certificate from the blockchain.
[0271] FIG13 is a schematic diagram of the composition structure of a first core network device according to an embodiment of the present application, including:
[0272] The fourth communication unit 1301 is used to upload a second resource authorization message to the blockchain, wherein the second resource authorization message carries a second certificate, and the second certificate carries a second signature for verifying the second network's authority to use the resources of the first network, and the first core network device belongs to the first network.
[0273] The second signature is calculated based on the private key of the first core network device and at least one of the following information: the identification of the first core network device, the public key of the first core network device, the identification of the second core network device in the second network, the public key of the second core network device, and information about the resources of the first network authorized for use by the second network.
[0274] The second certificate also carries at least one of the following: the identification of the second core network device, the public key of the second core network device, the identification of the first core network device, the public key of the first core network device, and information about resources of the first network authorized for use by the second network.
[0275] The fourth communication unit 1301 is configured to receive a second resource request message from a second core network device of the second network, wherein the second resource request message is used to request the use of resources of the first network.
[0276] The device of the embodiment of the present application can realize the corresponding functions of each device in the aforementioned communication method embodiment. The processes, functions, implementation methods and beneficial effects corresponding to each module (sub-module, unit or component, etc.) in the device can be found in the corresponding description in the above-mentioned method embodiment, which will not be repeated here. It should be noted that the functions described by each module (sub-module, unit or component, etc.) in the device of the embodiment of the application can be implemented by different modules (sub-module, unit or component, etc.) or by the same module (sub-module, unit or component, etc.).
[0277] It should be understood that in the various embodiments of the present application, the size of the serial numbers of the above-mentioned processes does not mean the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of the present application.
[0278] Those skilled in the art will clearly understand that, for the convenience and brevity of description, the specific working processes of the systems, devices and units described above can refer to the corresponding processes in the aforementioned method embodiments and will not be repeated here.
[0279] The above description is merely a specific embodiment of the present application, but the scope of protection of the present application is not limited thereto. Any modifications or substitutions that can be easily conceived by a person skilled in the art within the technical scope disclosed in the present application should be included within the scope of protection of the present application. Therefore, the scope of protection of the present application should be based on the scope of protection of the claims.
Claims
1. A communication method executed by a terminal, comprising: Sending an authentication request to a first network device in a first network, wherein the authentication request carries a first credential for verifying the permission of the terminal belonging to a second network to use the resources of the first network.
2. The method according to claim 1, wherein The first credential carries at least one of the following: a first signature for verifying the permission of the terminal to use the authorized resources of the first network obtained from the second network, a second signature for verifying the permission of the second network to use the resources of the first network.
3. The method according to claim 2, wherein The first credential further carries at least one of the following: a temporary identifier of the terminal, a temporary public key of the terminal.
4. The method according to claim 2 or 3, wherein The second signature is carried by a second credential in the first credential, and the second credential further carries at least one of the following: an identifier of a first core network device in the first network, a public key of the first core network device, an identifier of a second core network device in the second network, a public key of the second core network device, information about the resources of the first network authorized for use by the second network.
5. The method according to any one of claims 1-4, wherein, The authentication request further carries a third signature for verifying the validity of the authentication request, and the third signature is calculated based on the temporary private key of the terminal and at least one of the following information: an identifier of the first network device, a first random number, a first security parameter for calculating a communication key between the terminal and the first network device.
6. The method according to any one of claims 1-5, wherein, The authentication request further carries at least one of the following: an identifier of the first network device, a first random number, a first security parameter for calculating a communication key between the terminal and the first network device.
7. The method according to any one of claims 1-6, wherein The method further comprises: Receiving an authentication response from the first network device, wherein the authentication response carries a certificate of the first network device, and the certificate of the first network device includes a fourth signature for authenticating the first network device.
8. The method according to claim 7, wherein, The certificate of the first network device further includes at least one of the following: an identifier of a first core network device in the first network, an identifier of the first network device, a public key of the first network device.
9. The method according to claim 8, wherein, The method further comprises: Authenticating the first network device based on the public key of the first core network device, the fourth signature, and at least one of the following information: an identifier of the first network device, a public key of the first network device.
10. The method according to any one of claims 7-9, wherein, The authentication response further carries a fifth signature for verifying the validity of the authentication response.
11. The method according to claim 10, wherein, The authentication response further carries at least one of the following: a temporary identifier of the terminal, a second random number, a second security parameter for calculating a communication key between the terminal and the first network device.
12. The method according to claim 11, wherein, The method further comprises: Verifying the validity of the authentication response based on the public key of the first network device, the fifth signature, and at least one of the following information: a temporary identifier of the terminal, the second random number, the second security parameter.
13. The method according to claim 11 or 12, wherein, The method further comprises: Calculating a communication key between the terminal and the first network device based on the second security parameter and the first security parameter.
14. The method according to any one of claims 1 to 13, wherein The method further comprises: Receiving a first resource authorization message from a second core network device in the second network, wherein the first resource authorization message carries the first credential.
15. The method according to claim 14, wherein, The method further includes: Sending a first resource request message to the second core network device, where the first resource request message is used to request to use the resources of the first network.
16. The method according to claim 15, wherein, The first resource request message carries at least one of the following: a temporary identifier of the terminal, a temporary public key of the terminal.
17. The method according to any one of claims 1-16, wherein, The first network device includes one of the following: an access network device, a third core network device.
18. A communication method performed by a first network device, including: Receiving an authentication request from a terminal, where the authentication request carries a first credential for verifying the authority of the terminal belonging to a second network to use the resources of the first network, and the first network device belongs to the first network.
19. The method according to claim 18, wherein, The first credential carries at least one of the following: a first signature for verifying the authority of the terminal to use the resources of the first network authorized by the second network, a second signature for verifying the authority of the second network to use the resources of the first network.
20. The method according to claim 19, wherein, The first credential further carries at least one of the following: a temporary identifier of the terminal, a temporary public key of the terminal.
21. The method according to claim 20, wherein, The second signature is carried by a second credential in the first credential, and the second credential further carries at least one of the following: an identifier of a first core network device in the first network, a public key of the first core network device, an identifier of a second core network device in the second network, a public key of the second core network device, information about the resources of the first network authorized for the second network to use.
22. The method according to claim 21, wherein The method further includes: Based on the public key of the second core network device, the first signature, and at least one of the following information, verifying the authority of the terminal to use the resources of the first network authorized by the second network: the temporary identifier of the terminal, the temporary public key of the terminal, the second credential.
23. The method according to claim 21, wherein, The method further includes: Based on the public key of the first core network device, the second signature, and at least one of the following information, verifying the authority of the second network to use the resources of the first network: the identifier of the first core network device, the public key of the first core network device, the identifier of the second core network device, the public key of the second core network device, information about the resources of the first network authorized for the second network to use.
24. The method according to any one of claims 18-23, wherein, The authentication request further carries a third signature for verifying the validity of the authentication request.
25. The method according to claim 24, wherein The authentication request further carries at least one of the following: an identifier of the first network device, a first random number, a first security parameter for calculating a communication key between the terminal and the first network device.
26. The method according to claim 25, wherein, The method further includes: Based on the temporary public key of the terminal, the third signature, and at least one of the following information, verifying the validity of the authentication request: an identifier of the first network device, a first random number, a first security parameter for calculating a communication key between the terminal and the first network device.
27. The method according to any one of claims 18 - 26, wherein, The method further includes: Sending an authentication response to the terminal, where the authentication response carries a certificate of the first network device, and the certificate of the first network device includes a fourth signature for authenticating the first network device.
28. The method according to claim 27, wherein The certificate of the first network device further includes at least one of the following: the identifier of the first core network device of the first network, the identifier of the first network device, and the public key of the first network device.
29. The method according to claim 27 or 28, wherein The authentication response further carries a fifth signature for verifying the validity of the authentication response, and the fifth signature is calculated based on the private key of the first network device and at least one of the following information: the temporary identifier of the terminal, the second random number, and the second security parameter for calculating the communication key between the terminal and the first network device.
30. The method according to any one of claims 27-29, wherein, The authentication response further carries at least one of the following: the temporary identifier of the terminal, the second random number, and the second security parameter for calculating the communication key between the terminal and the first network device.
31. The method according to claim 25 or 26, wherein, The method further includes: Calculating the communication key between the terminal and the first network device based on the first security parameter and the second security parameter.
32. The method according to any one of claims 18 - 31, wherein, The first network device includes one of the following: an access network device, a third core network device.
33. A communication method performed by a second core network device, including: Sending a first resource authorization message to a terminal, where the first resource authorization message carries a first credential for verifying the permission of the terminal belonging to the second network to use the resources of the first network, and the second core network device belongs to the second network.
34. The method according to claim 33, wherein, The first credential carries at least one of the following: a first signature for verifying the permission of the terminal to use the resources of the first network authorized by the second network, and a second signature for verifying the permission of the second network to use the resources of the first network.
35. The method according to claim 34, wherein, The first credential further carries at least one of the following: the temporary identifier of the terminal, the temporary public key of the terminal.
36. The method according to any one of claims 34 or 35, wherein, The second signature is carried by a second credential in the first credential, and the second credential further carries at least one of the following: the identifier of the second core network device, the public key of the second core network device, the identifier of the first core network device, the public key of the first core network device, and information on the resources of the network where the first core network device is located authorized for the second core network device to use.
37. The method according to claim 36, wherein, The first signature is calculated based on the private key of the second core network device and at least one of the following information: the temporary identifier of the terminal, the temporary public key of the terminal, and the second credential.
38. The method according to any one of claims 33 - 37, wherein, The method further includes: Receiving a first resource request message from the terminal, where the first resource request message is used to request the use of the resources of the first network.
39. The method according to claim 38, wherein, The first resource request message carries at least one of the following: the temporary identifier of the terminal, the temporary public key of the terminal.
40. The method according to claim 36, wherein The method further includes: Sending a second resource request message to the first core network device, where the second resource request message is used to request the use of the resources of the first network; Downloading the second credential from the blockchain.
41. A communication method performed by a first core network device, including: Uploading a second resource authorization message to the blockchain, where the second resource authorization message carries a second credential, and the second credential carries a second signature for verifying the permission of the second network to use the resources of the first network, and the first core network device belongs to the first network.
42. The method according to claim 41, wherein, The second signature is calculated based on the private key of the first core network device and at least one of the following information: the identifier of the first core network device, the public key of the first core network device, the identifier of the second core network device in the second network, the public key of the second core network device, and the information about the resources of the first network authorized for use by the second network.
43. The method according to claim 41 or 42, wherein The second credential also carries at least one of the following: the identifier of the second core network device, the public key of the second core network device, the identifier of the first core network device, the public key of the first core network device, and the information about the resources of the first network authorized for use by the second network.
44. The method according to any one of claims 41 to 43, wherein, The method further includes: Receiving a second resource request message from a second core network device in the second network, where the second resource request message is used to request the use of resources of the first network.
45. A terminal, comprising: A first communication unit, configured to send an authentication request to a first network device in a first network, where the authentication request carries a first credential for verifying the permission of the terminal belonging to a second network to use the resources of the first network.
46. A first network device, comprising: A second communication unit, configured to receive an authentication request from a terminal, where the authentication request carries a first credential for verifying the permission of the terminal belonging to a second network to use the resources of the first network, and the first network device belongs to the first network.
47. A second core network device, comprising: A third communication unit, configured to send a first resource authorization message to a terminal, where the first resource authorization message carries a first credential for verifying the permission of the terminal belonging to a second network to use the resources of the first network, and the second core network device belongs to the second network.
48. A first core network device, comprising: A fourth communication unit, configured to upload a second resource authorization message to a blockchain, where the second resource authorization message carries a second credential, and the second credential carries a second signature for verifying the permission of the second network to use the resources of the first network, and the first core network device belongs to the first network.