Industrial device-based secondary authentication method, system, and storage medium
Patent Information
- Application Number
- CN202611060570.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-07-16
- Publication Date
- 2026-09-22
Smart Images

Figure CN122802905A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of communication technology, and in particular to a secondary authentication method, system and storage medium based on industrial equipment. Background Technology
[0002] Secondary authentication is an important security mechanism in 5G systems. It refers to the additional authentication and authorization process implemented by the external data network (DN) for the UE during the PDU session establishment process after the user terminal (UE) and the core network (5GC) have completed the initial primary authentication. The core objective of this mechanism is to enable the DN to achieve fine-grained control over the UE's service access permissions.
[0003] In existing industrial scenarios, UEs are typically connected to multiple industrial devices. The secondary authentication management of these multiple industrial devices generally adopts a "one-size-fits-all" approach, that is, either all industrial devices undergo secondary authentication, or none of them undergo secondary authentication.
[0004] Therefore, existing secondary authentication mechanisms do not consider the scenario where a UE is connected to multiple industrial devices with different authentication requirements. For example, some industrial devices require secondary authentication, while others do not. Consequently, existing secondary authentication mechanisms cannot differentiate between these industrial devices, resulting in poor flexibility in secondary authentication. Summary of the Invention
[0005] The purpose of this application is to address the shortcomings of the prior art by providing a secondary authentication method, system, and storage medium based on industrial equipment, thereby improving the flexibility of the secondary authentication method.
[0006] To achieve the above objectives, the technical solutions adopted in the embodiments of this application are as follows: In a first aspect, the present invention provides a secondary authentication method based on industrial equipment, applied to a terminal in a data communication system, wherein at least one industrial device is mounted on the terminal, and the terminal is communicatively connected to a network management server and a DN-AAA server in the data communication system, the method comprising: The terminal receives a target data packet sent by the target industrial device and retrieves local data records using the MAC source address in the target data packet as an index. The target industrial device is any industrial device attached to the terminal. The local data records include a mapping relationship between the industrial device's data network name, the industrial device's IP address, the industrial device's MAC address, and the industrial device's virtual LAN identifier. The industrial device's data network name is determined based on the industrial device's IP address and the industrial device's virtual LAN identifier. If a local data record has a local matching item, a secondary authentication request is initiated to the DN-AAA server based on the target data network name corresponding to the local matching item. This allows the DN-AAA server to query the local authentication record matching item from the local secondary authentication information based on the target data network name, and then send the target authentication information corresponding to the local authentication record matching item to the UPF. The UPF is configured to generate packet filtering rules based on the target authentication information corresponding to the local authentication record matching item. The local secondary authentication information includes the mapping relationship between PDU session association identifier, frame routing identifier and allowed VLAN tag list. The PDU session association identifier is obtained by converting the data network name of the industrial equipment, the frame routing identifier is obtained by converting the IP address of the industrial equipment, and the allowed VLAN tag list is obtained by converting the virtual local area network identifier of the industrial equipment.
[0007] In an optional implementation, before receiving the target data packet sent by the target industrial device and retrieving the local data record using the MAC source address in the target data packet as an index, the method further includes: Based on the local data record, local device connection information is generated and reported to the network management server. This allows the network management server to initiate a user subscription data modification request to the UDM via NEF based on the local device connection information. The request aims to add the terminal corresponding to the general public subscription identifier in the local device connection information to the target virtual local area network group with the virtual local area network identifier as the external identifier. The local device connection information includes the local data record and the general public subscription identifier of the terminal.
[0008] In an optional implementation, before receiving the target data packet sent by the target industrial device and retrieving the local data record using the MAC source address in the target data packet as an index, the method further includes: Send a registration request to the network management server and receive a first response data packet returned by the network management server according to the registration request. The first response data includes: the mapping relationship between the data network name of the industrial equipment, the IP address of the industrial equipment, and the target virtual local area network identifier of the industrial equipment. Based on the IP addresses of each industrial device in the first response data packet, send ARP requests to each industrial device and receive ARP responses returned by each industrial device; The local data record is generated based on the APR responses returned by each industrial device.
[0009] In an optional implementation, the step of initiating a secondary authentication request to the DN-AAA server based on the target data network name corresponding to the local matching item, so that the DN-AAA server queries the local authentication record matching item from the local secondary authentication information based on the target data network name, and sends the target authentication information corresponding to the local authentication record matching item to the UPF, includes: A PDU session connection is initiated to the SMF using the target data network name corresponding to the local matching item as an identifier. The SMF then initiates a secondary authentication request to the DN-AAA server based on the PDU session connection. The DN-AAA server queries the local authentication record matching item from the local secondary authentication information based on the target data network name and sends the target authentication information corresponding to the local authentication record matching item to the UPF through the SMF.
[0010] In an optional implementation, the DN-AAA server is further configured to return an authentication failure response message to the SMF if no matching local authentication record is found in the local secondary authentication information based on the target data network name. The SMF is further configured to return a PDU session establishment rejection response message to the terminal if the authentication failure response message is received.
[0011] In an optional implementation, the network management server is further configured to generate a data network name for the industrial equipment based on the equipment information of the industrial equipment, and send target generation information to the DN-AAA server. The target generation information includes: the data network name of the industrial equipment and the equipment information of the industrial equipment, wherein the equipment information includes: the IP address of the industrial equipment and the virtual local area network identifier of the industrial equipment.
[0012] In an optional implementation, the DN-AAA server is further configured to generate the local secondary authentication information based on the target generation information.
[0013] Secondly, this invention provides a secondary authentication method based on industrial equipment, applied to a DN-AAA server in a data communication system. The DN-AAA server is communicatively connected to a network management server and a terminal in the data communication system. At least one industrial device is mounted on the terminal. The method includes: The receiving terminal determines that a local matching item exists in the local data record and sends a secondary authentication request based on the target data network name corresponding to the local matching item. The local matching item is determined by the terminal based on the target data packet sent by the target industrial device and by retrieving the local data record using the MAC source address in the target data packet as an index. The target industrial device is any industrial device mounted on the terminal. The local data record includes the mapping relationship between the data network name of the industrial device, the IP address of the industrial device, the MAC address of the industrial device, and the virtual LAN identifier of the industrial device. Based on the target data network name, query the local authentication record matching item from the local secondary authentication information, and send the target authentication information corresponding to the local authentication record matching item to the UPF. The UPF is configured to generate packet filtering rules based on the target authentication information corresponding to the local authentication record matching item. The local secondary authentication information includes the mapping relationship between PDU session association identifier, frame routing identifier and allowed VLAN tag list. The PDU session association identifier can be obtained by converting the data network name of the industrial equipment, the frame routing identifier can be obtained by converting the IP address of the industrial equipment, and the allowed VLAN tag list can be obtained by converting the virtual local area network identifier of the industrial equipment.
[0014] Thirdly, the present invention provides a secondary authentication system based on industrial equipment. The secondary authentication system includes: a terminal, a network management server, and a DN-AAA server. At least one industrial device is mounted on the terminal. The terminal is communicatively connected to the network management server and the DN-AAA server. The terminal is used to execute the steps of the secondary authentication method based on industrial equipment as described in any of the foregoing embodiments.
[0015] Fourthly, the present invention provides a computer-readable storage medium storing a computer program, which, when executed by a processor, performs the steps of the secondary authentication method based on industrial equipment as described in any of the foregoing embodiments.
[0016] The beneficial effects of this application are: The secondary authentication method, system, and storage medium based on industrial equipment provided in this application include: receiving a target data packet sent by a target industrial device, and retrieving local data records using the MAC source address in the target data packet as an index. The target industrial device is any industrial device mounted on a terminal. The local data records include a mapping relationship between the industrial device's data network name, IP address, MAC address, and virtual local area network (VLAN) identifier. The industrial device's data network name is determined based on its IP address and VLAN identifier. If a local matching item exists in the local data records, a secondary authentication request is initiated to the DN-AAA server based on the target data network name corresponding to the local matching item, so that the DN-AAA server retrieves the data from the local secondary authentication information based on the target data network name. The system queries local authentication record matches and sends the target authentication information corresponding to the local authentication record matches to the UPF. The UPF is configured to generate packet filtering rules based on the target authentication information corresponding to the local authentication record matches. The local secondary authentication information includes the mapping relationship between the PDU session association identifier, frame routing identifier, and allowed VLAN tag list. The PDU session association identifier is converted from the data network name of the industrial device, the frame routing identifier is converted from the IP address of the industrial device, and the allowed VLAN tag list is converted from the virtual LAN identifier of the industrial device. This enables the generation of a DNN for a specific downstream industrial device based on the IP address and virtual LAN identifier of the industrial device, determines the device-level identity identifier, and enables independent secondary authentication authorization for a single industrial device, improving the flexibility of the secondary authentication method. Attached Figure Description
[0017] To more clearly illustrate the technical solutions of the embodiments of this application, the accompanying drawings used in the embodiments will be briefly introduced below. It should be understood that the following drawings only show some embodiments of this application and should not be regarded as a limitation of the scope. For those skilled in the art, other related drawings can be obtained based on these drawings without creative effort.
[0018] Figure 1 This is a schematic diagram of the network architecture applicable to the data communication system provided in the embodiments of this application; Figure 2 A flowchart illustrating a secondary certification method for industrial equipment provided in this application embodiment; Figure 3 A flowchart illustrating another secondary certification method for industrial equipment provided in this application embodiment; Figure 4 A flowchart illustrating another secondary certification method for industrial equipment provided in this application embodiment; Figure 5 A flowchart illustrating another secondary certification method for industrial equipment provided in this application embodiment; Figure 6 This is a schematic diagram of an electronic device structure provided in an embodiment of this application. Detailed Implementation
[0019] To make the objectives, technical solutions, and advantages of the embodiments of this application clearer, the technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, and not all embodiments. The components of the embodiments of this application described and shown in the accompanying drawings can generally be arranged and designed in various different configurations.
[0020] Therefore, the following detailed description of the embodiments of this application provided in the accompanying drawings is not intended to limit the scope of the claimed application, but merely to illustrate selected embodiments of the application. All other embodiments obtained by those skilled in the art based on the embodiments of this application without inventive effort are within the scope of protection of this application.
[0021] It should be noted that similar labels and letters in the following figures indicate similar items. Therefore, once an item is defined in one figure, it does not need to be further defined and explained in subsequent figures.
[0022] The technical solutions of this application embodiment can be applied to various local communication systems, such as: Global System for Mobile Communications (GSM) system, Code Division Multiple Access (CDMA) system, Wideband Code Division Multiple Access (WCDMA) system, General Packet Radio Service (GPRS), Long Term Evolution (LTE) system, LTE Frequency Division Duplex (FDD) system, LTE Time Division Duplex (TDD) system, Universal Mobile Telecommunication System (UMTS), Worldwide Interoperability for Microwave Access (WiMAX) communication system, 5th Generation (5G) communication system, or future new radio access technology (NR), etc.
[0023] Figure 1 This is a schematic diagram of the network architecture applicable to the data communication system provided in the embodiments of this application. For example... Figure 1 As shown, this network architecture can be, for example, a non-roaming architecture. Specifically, this network architecture may include the following network elements: 1. User Equipment (UE): This can be referred to as user equipment, terminal, access terminal, user unit, user station, mobile station, mobile station, remote station, remote terminal, mobile device, user terminal, wireless communication equipment, user agent, or user device. UE can also be a cellular phone, cordless phone, session initiation protocol (SIP) phone, wireless local loop (WLL) station, personal digital assistant (PDA), handheld device with wireless communication capabilities, computing device or other processing device connected to a wireless modem, vehicle-mounted device, wearable device, terminal equipment in a 5G network, or terminal equipment in a future evolved public land mobile network (PLMN), etc. It can also be an end device, logical entity, smart device, such as a mobile phone, smart terminal, or other terminal equipment; or a server, gateway, base station, controller, or other communication equipment; or an Internet of Things (IoT) device, such as a sensor, electricity meter, water meter, etc. This application's embodiments do not limit this.
[0024] 2. Access Network (AN): Provides network access functionality for authorized users in a specific area and can use transmission tunnels of different quality depending on the user's level and service requirements. Access networks can employ different access technologies. Currently, there are two types of radio access technologies: 3rd Generation Partnership Project (3GPP) access technologies (such as those used in 3G, 4G, or 5G systems) and non-3GPP access technologies. 3GPP access technologies refer to access technologies that conform to 3GPP standards and specifications. Access networks using 3GPP access technologies are called radio access networks (RANs). In 5G systems, access network equipment is called next-generation node base stations (gNBs). Non-3GPP access technologies refer to access technologies that do not conform to 3GPP standards and specifications, such as air interface technologies represented by access points (APs) in Wi-Fi.
[0025] An access network that uses wireless communication technology to implement access network functions can be called a radio access network (RAN). A RAN manages radio resources, provides access services to terminals, and facilitates the forwarding of control signals and user data between terminals and the core network.
[0026] The access network equipment may include devices within the access network that communicate with wireless terminals via one or more sectors on the air interface. The access network system may be used to convert received air frames to and from Internet Protocol (IP) packets, and act as a router between the wireless terminal and the rest of the access network, which may include an IP network. The wireless access network system may also coordinate the attribute management of the air interface. It should be understood that access network equipment includes, but is not limited to: evolved node B (eNB), radio network controller (RNC), node B (NB), base station controller (BSC), base transceiver station (BTS), home base station (e.g., home evolved node B, or home node B, HNB), base band unit (BBU), access point (AP), wireless relay node, wireless backhaul node, transmission and reception point (TRP or transmission point, TP) in a wireless fidelity (WIFI) system, and can also be gNB in 5G, such as NR, or transmission point (TRP or TP), one or a group of antenna panels (including multiple antenna panels) of a base station in a 5G system, or network nodes constituting a gNB or transmission point, such as base band unit (BBU) or distributed unit (DU), etc.
[0027] In some deployments, a gNB may include a centralized unit (CU) and a DU. A gNB may also include a radio unit (RU). The CU implements some of the gNB's functions, and the DU implements others. For example, the CU implements radio resource control (RRC) and packet data convergence protocol (PDCP) layer functions, while the DU implements radio link control (RLC), media access control (MAC), and physical (PHY) layer functions. Since RRC layer information ultimately becomes PHY layer information, or is derived from PHY layer information, in this architecture, higher-layer signaling, such as RRC layer signaling, can be considered to be sent by the DU, or by the DU+CU. It is understood that access network equipment can be a CU node, a DU node, or a device including both CU and DU nodes. Furthermore, the CU can be classified as an access network device in the radio access network (RAN) or as an access network device in the core network (CN), without any restrictions.
[0028] 3. Access and Mobility Management Function (AMF) Entity: Primarily used for mobility management and access management, it can implement functions other than session management within the Mobility Management Entity (MME) functionality, such as lawful interception or access authorization (or authentication). In the embodiments of this application, it can be used to implement the functions of the access and mobility management network element.
[0029] 4. Session Management Function (SMF) Entity: Primarily used for session management, UE Internet Protocol (IP) address allocation and management, selection of manageable user plane functions, policy control, or endpoints for charging function interfaces, and downlink data notification, etc. In this application embodiment, it can be used to implement the functions of the session management network element.
[0030] 5. User Plane Function (UPF) Entity: This is the data plane gateway. It can be used for packet routing and forwarding, or for quality of service (QoS) processing of user plane data. User data can access the data network (DN) through this network element. In this embodiment, it can be used to implement the functions of a user plane gateway.
[0031] 6. Policy control function (PCF) entity: A unified policy framework used to guide network behavior, providing policy rule information to control plane functional network elements (such as AMF, SMF, etc.).
[0032] 7. Unified Data Management (UDM) entity: Used to handle user identification, access authentication, registration, or mobility management, etc.
[0033] 8. N3IWF (Non-3GPP Interworking Function): Responsible for connecting untrusted non-3GPP access networks (such as Wi-Fi) to the 5G core network. The UE establishes an IPsec tunnel with the N3IWF, and the N3IWF accesses the control plane and user plane of the 5G core network through the N2 and N3 interfaces respectively.
[0034] 9. Network Exposure Function (NEF) Element: Serving as the interface between the 5G core network and other external services, enabling third-party applications and services to securely access network resources and services. Its main functions include: Service Exposure: The NEF is responsible for exposing services and functions in the 5G network, allowing external applications and services to invoke these services; Policy and Access Management: The NEF ensures that only authenticated and authorized applications and services can access specific network functions; Data Conversion: The NEF handles data format conversion to ensure compatibility and interoperability between different systems; Traffic Filtering and Monitoring: The NEF can filter and monitor traffic passing through it to protect the network from malicious attacks; Event Notification: The NEF can send event notifications to external entities, such as applications, when certain important events occur in the network.
[0035] In this network architecture, such as Figure 1As shown, the N1 interface is the reference point between the terminal and the AMF entity; the N2 interface is the reference point between the AN and the AMF entity, used for sending non-access stratum (NAS) messages, etc.; the N3 interface is the reference point between the (R)AN and the UPF entity, used for transmitting user plane data, etc.; the N4 interface is the reference point between the SMF entity and the UPF entity, used for transmitting information such as tunnel identification information for the N3 connection, data buffer indication information, and downlink data notification messages, etc.; the N6 interface is the reference point between the UPF entity and the DN, used for transmitting user plane data, etc.
[0036] In addition, such as Figure 1 As shown, NEF network elements, Network Repository Function (NRF) network elements, Application Function (AF) network elements, PCF network elements, Unified Data Repository (UDR) network elements, UDM network elements, AMF network elements, and SMF network elements can communicate using externally provided service interfaces. For example, the externally provided service interface for NEF network elements is the Nnef interface, for UDM network elements it is the Nudm interface, for AMF network elements it is the Namf interface, for AF network elements it is the Naf interface, for SMF network elements it is the Nsmf interface, for PCF network elements it is the Npcf interface, and for UDR network elements it is the Nudr interface.
[0037] It should be understood that the network architecture described above in the embodiments of this application is merely an example of a network architecture described from the perspective of a traditional point-to-point architecture and a service-oriented architecture. The network architecture applicable to the embodiments of this application is not limited to this, and any network architecture that can realize the functions of the above-mentioned network elements is applicable to the embodiments of this application.
[0038] It should also be understood that Figure 1 The AMF, SMF, UPF, PCF, and UDM entities shown can be understood as network elements in the core network used to implement different functions, such as network slices that can be combined as needed. These core network elements can be independent devices or integrated into the same device to implement different functions; this application does not limit this.
[0039] In the following text, for ease of explanation, the entity used to implement AMF will be referred to as AMF, and the entity used to implement PCF will be referred to as PCF. It should be understood that the above naming is only for distinguishing different functions and does not mean that these network elements are independent physical devices. This application does not limit the specific form of the above network elements; for example, they can be integrated into the same physical device or they can be different physical devices. Furthermore, the above naming is only for distinguishing different functions and should not constitute any limitation on this application. This application does not exclude the possibility of using other naming in 5G networks and other future networks. For example, in 6G networks, some or all of the above network elements may use the terminology from 5G, or they may use other names, etc. This is explained uniformly here and will not be repeated below.
[0040] It should also be understood that Figure 1 The interface names between the various network elements are merely examples; in actual implementations, the interface names may differ, and this application does not impose any specific limitations on them. Furthermore, the names of the messages (or signaling) transmitted between the aforementioned network elements are also merely examples and do not constitute any limitation on the function of the messages themselves.
[0041] In existing industrial scenarios, UEs are typically connected to multiple industrial devices. The secondary authentication management of these multiple industrial devices generally adopts a "one-size-fits-all" approach, that is, either all industrial devices undergo secondary authentication, or none of them undergo secondary authentication.
[0042] It can be seen that the existing secondary authentication mechanism does not take into account the situation where the UE is connected to multiple industrial devices with different authentication requirements. For example, some industrial devices require secondary authentication, while others do not. Therefore, the existing secondary authentication mechanism cannot differentiate between these industrial devices, resulting in poor flexibility in secondary authentication.
[0043] Furthermore, existing secondary authentication mechanisms often require manual configuration of the DNN on the UE to ensure that the secondary authentication process is triggered on the SMF side. When there are many UEs deployed in the field, the manual configuration work will be cumbersome and prone to errors, resulting in low efficiency of secondary authentication. Moreover, existing secondary authentication mechanisms require that the MAC address list allowed by the PDU session cannot exceed 16. When the number of downstream devices connected to the UE exceeds 16, it will be impossible to guarantee that all downstream devices pass the secondary authentication, resulting in poor applicability of secondary authentication.
[0044] In view of this, this application provides a secondary certification method based on industrial equipment, which can improve the flexibility, certification efficiency and applicability of the secondary certification method.
[0045] Figure 2This application provides a flowchart illustrating a secondary authentication method for industrial equipment, which can be applied to... Figure 1 The data communication system shown includes a terminal UE (User Equipment) with at least one industrial device mounted on it. The terminal communicates with the network management server and the Data Network Authentication, Authorization, Accounting (DN-AAA) server within the data communication system. The network management server and DN-AAA server are respectively connected to the UPF (User Platform Provider) within the data communication system. Optionally, each industrial device can be mounted via the terminal's network port. For better understanding of this application, the following embodiments use 5G network access as an example.
[0046] like Figure 2 As shown, the secondary authentication method includes: S101: Receive the target data packet sent by the target industrial equipment, and retrieve the local data record using the MAC source address in the target data packet as an index.
[0047] The target industrial device is any industrial device mounted on the terminal. The local data record includes the mapping relationship between the industrial device's data network name, IP address, MAC address, and virtual LAN identifier.
[0048] In some implementations, the local data record can be represented in the following ways:<IP,MAC,DNN,VLAN ID> Here, DNN represents the data network name of the industrial equipment, IP represents the IP address of the industrial equipment, MAC represents the MAC address of the industrial equipment, and VLAN ID represents the virtual LAN identifier of the industrial equipment. Optionally, multiple industrial equipment connected to the same terminal can have the same virtual LAN identifier. Of course, the specific configuration method is not limited to this and can vary depending on the actual application scenario.
[0049] Optionally, the data network name, IP address, and virtual LAN identifier of the industrial equipment in the local data record can be determined by the UE sending a registration request to the network management server and based on the first response data packet returned by the network manager; the MAC address of the industrial equipment in the local data record can be obtained by the UE querying based on the ARP protocol and the IP address of the industrial equipment.
[0050] Optionally, after receiving a target data packet from the target industrial device connected to the local network port, the UE can retrieve local data records using the MAC source address of the target data packet as an index.
[0051] S102. If a local data record has a local matching item, then a secondary authentication request is initiated to the DN-AAA server based on the target data network name corresponding to the local matching item, so that the DN-AAA server can query the local authentication record matching item from the local secondary authentication information based on the target data network name, and send the target authentication information corresponding to the local authentication record matching item to the UPF.
[0052] UPF is configured to generate packet filtering rules based on the target authentication information corresponding to the matching items in the local authentication records.
[0053] The local secondary authentication information includes the mapping relationship between the PDU session association identifier, frame routing identifier, and the allowed VLAN tag list. The PDU session association identifier is converted from the data network name of the industrial equipment, the frame routing identifier is converted from the IP address of the industrial equipment, and the allowed VLAN tag list is converted from the virtual LAN identifier of the industrial equipment.
[0054] Optionally, the local secondary authentication information in the DN-AAA server can be generated based on the target generation information issued by the network management server. The target generation information may include: the data network name of the industrial equipment and the equipment information of the industrial equipment. The equipment information includes: the IP address of the industrial equipment and the virtual LAN identifier of the industrial equipment.
[0055] After obtaining the target generation information, the DN-AAA server can establish a correspondence between the secondary authentication result and the PDU session by converting the data network name of the industrial equipment into a PDU session association identifier, thus avoiding confusion of authorization parameters between multiple PDU sessions. By converting the IP address of the industrial equipment into a frame routing identifier, it can provide a basis for the UPF to configure Layer 3 access policies at the IP layer. By converting the virtual LAN identifier of the industrial equipment into an allowed VLAN tag list, it can provide a basis for the UPF to configure Layer 2 filtering rules at the data link layer.
[0056] If a local data record is found to have a local match for the MAC source address, a PDU session connection is initiated using the target data network name corresponding to the local match as an identifier. Based on this PDU session connection, a secondary authentication request is sent to the DN-AAA server. Optionally, this secondary authentication request may carry the target data network name.
[0057] After receiving the secondary authentication request, the DN-AAA server can retrieve local secondary authentication information using the target data network name as an index.
[0058] Optionally, if there is a local authentication record matching item corresponding to the target data network name in the local secondary authentication information, the target authentication information corresponding to the local authentication record matching item is sent to the UPF. The UPF generates packet filtering rules based on the target authentication information corresponding to the local authentication record matching item, realizing joint access control of the second-layer link layer and the third-layer IP layer, so that the secondary authentication authorization result of the DN-AAA server for a single industrial device can be effective on the UPF side.
[0059] The target authentication information may include: the target frame routing identifier corresponding to the target data network name and the target allowed VLAN tag list.
[0060] By applying the embodiments of this application, a DNN for a specific downstream industrial device can be generated based on the IP address and virtual LAN identifier of the industrial device, and a device-level identity identifier can be determined. This enables independent secondary authentication and authorization for a single industrial device, and differentiated processing can be performed for multiple industrial devices connected to the same UE. For example, secondary authentication can be set for some industrial devices, while authentication can be exempted for others. This solves the problem of one-size-fits-all management of authentication for different industrial devices in traditional secondary authentication and improves the flexibility of the secondary authentication method.
[0061] In summary, this application's embodiment of a secondary authentication method based on industrial equipment is applied to a terminal in a data communication system. The terminal is equipped with at least one industrial device, and the terminal is communicatively connected to a network management server and a DN-AAA server in the data communication system. The method includes: receiving a target data packet sent by the target industrial device, and retrieving local data records using the MAC source address in the target data packet as an index. The target industrial device is any industrial device mounted on the terminal. The local data records include a mapping relationship between the industrial device's data network name, IP address, MAC address, and virtual LAN identifier. The industrial device's data network name is determined based on its IP address and virtual LAN identifier. If a local matching item exists in the local data records, a secondary authentication request is initiated to the DN-AAA server based on the target data network name corresponding to the local matching item, thereby enabling DN-AAA authentication. The AAA server queries local authentication record matches from local secondary authentication information based on the target data network name, and sends the target authentication information corresponding to the local authentication record matches to the UPF. The UPF is configured to generate packet filtering rules based on the target authentication information corresponding to the local authentication record matches. The local secondary authentication information includes the mapping relationship between PDU session association identifier, frame routing identifier, and allowed VLAN tag list. The PDU session association identifier is converted from the data network name of the industrial device, the frame routing identifier is converted from the IP address of the industrial device, and the allowed VLAN tag list is converted from the virtual LAN identifier of the industrial device. This enables the generation of DNN for a specific downstream industrial device based on the IP address and virtual LAN identifier of the industrial device, determines the device-level identity identifier, and enables independent secondary authentication authorization for a single industrial device, improving the flexibility of the secondary authentication method.
[0062] Figure 3 This is a schematic flowchart illustrating another secondary certification method for industrial equipment provided in an embodiment of this application. In optional implementations, such as... Figure 3 As shown, before receiving the target data packet sent by the target industrial equipment and retrieving local data records using the MAC source address in the target data packet as an index, the process also includes: S201. Based on local data records, generate local device connection information and report the local device connection information to the network management server, so that the network management server can initiate a user subscription data modification request to UDM through NEF based on the local device connection information, so as to add the terminal corresponding to the general public subscription identifier in the local device connection information into the target virtual local area network group with the virtual local area network identifier as the external identifier.
[0063] Local device connection information includes: local data records and the terminal's general public subscription identifier.
[0064] Among them, the UE records the generated local data.<IP,MAC,DNN,VLAN ID> It can query its own GPSI and generate local device connection information based on it. The local device connection information can be displayed in the following formats:<IP,MAC,DNN,VLANID,GPSI> For details on IP, MAC, DNN, and VLAN ID, please refer to the relevant descriptions in the local data records. GPSI is the UE's Generic Public Subscription Identifier.
[0065] After receiving the connection information of the local device, the network management server can extract the VLAN ID and GPSI from the connection information and send a user subscription data modification request to the UDM through NEF, requesting that the UE corresponding to the GPSI be added to the VN group with the VLAN ID as the external identifier.
[0066] By applying the embodiments of this application, the UE can report local device connection information to the network management server in real time, and the network side can dynamically modify the user subscription data through NEF (add the UE to the corresponding VLAN group) to ensure real-time synchronization of permissions.
[0067] Figure 4 This is a schematic flowchart illustrating another secondary certification method for industrial equipment provided in an embodiment of this application. In optional implementations, such as... Figure 4 As shown, before receiving the target data packet sent by the target industrial equipment and retrieving local data records using the MAC source address in the target data packet as an index, the process also includes: S301. Send a registration request to the network management server and receive the first response data packet returned by the network management server based on the registration request.
[0068] The first response data includes the mapping relationship between the data network name of the industrial equipment, the IP address of the industrial equipment, and the virtual LAN identifier of the industrial equipment.
[0069] S302. Based on the IP addresses of each industrial device in the first response data packet, send ARP requests to each industrial device and receive ARP responses returned by each industrial device.
[0070] S303. Generate local data records based on the APR responses returned by each industrial device.
[0071] After the terminal UE accesses the 5G network, it can send a registration request to the network management server. After receiving the registration request from the UE, the network management server can generate a first response data packet based on the pre-stored data network name of the industrial equipment and the equipment information of the industrial equipment and send it to the UE.
[0072] The equipment information includes: the IP address and virtual LAN identifier of the industrial equipment. The first response data can be in the following format:<DNN,IP,VLAN ID> Wherein, DNN represents the data network name of the industrial equipment, IP represents the IP address of the industrial equipment, and VLAN ID represents the virtual local area network identifier of the industrial equipment.
[0073] After receiving the first response data packet, the UE can extract the IP address from it and use it as the query target to initiate an ARP request to the industrial equipment connected to the local network port. Each industrial device, upon receiving the ARP request, can return an ARP response to the UE. After receiving the ARP response from the industrial device connected to the local network port, the UE generates a local data record, the specific form of which is as follows:<IP,MAC,DNN,VLAN ID> Wherein, IP is the IP address of the industrial device connected to the UE's local network port, MAC is the MAC address of the industrial device connected to the UE's local network port, DNN is the data network name of the industrial device connected to the UE's local network port, and VLAN ID represents the virtual LAN identifier of the industrial device connected to the UE's local network port.
[0074] By applying the embodiments of this application, the network management server can automatically send the first response data packet carrying the industrial device's DNN to the UE. Then, the UE can automatically detect the MAC address of the industrial device and generate a local data record through the ARP protocol. This avoids the tedious operation of manually configuring the DNN, reduces the risk of configuration errors, enables large-scale access scenarios for industrial devices, and improves the efficiency of secondary authentication.
[0075] In an optional implementation, a secondary authentication request is initiated to the DN-AAA server based on the target data network name corresponding to the local matching item. This allows the DN-AAA server to query the local authentication record matching item from the local secondary authentication information based on the target data network name, and then send the target authentication information corresponding to the local authentication record matching item to the UPF, including: A PDU session connection is initiated to the SMF using the target data network name corresponding to the local matching item as an identifier. This enables the SMF to send a secondary authentication request to the DN-AAA server based on the PDU session connection. The DN-AAA server then queries the local authentication record matching item from the local secondary authentication information based on the target data network name and sends the target authentication information corresponding to the local authentication record matching item to the UPF through the SMF.
[0076] In some implementations, if a local matching item exists in the local data record, a PDU session connection can be initiated to the SMF using the target data network name corresponding to the local matching item as an identifier. After receiving the PDU session connection, the SMF can initiate a secondary authentication request carrying the target data network identifier to the DN-AAA server.
[0077] Furthermore, the DN-AAA server uses the target DNN reported by the SMF as an index to retrieve local secondary authentication information. If a matching record exists, the local authentication record matching item corresponding to the target DNN is sent to the UPF via the SMF. For details on this part, please refer to the aforementioned related explanations; they will not be repeated here.
[0078] In an optional implementation, the DN-AAA server is further configured to return an authentication failure response message to the SMF if no matching local authentication record is found in the local secondary authentication information based on the target data network name. SMF is also configured to return a PDU session establishment rejection response message to the terminal if an authentication failure response message is received.
[0079] Of course, in some implementations, there may be situations where the DN-AAA server cannot find a matching local authentication record in the local secondary authentication information based on the target data network name. In this scenario, the DN-AAA server can return an authentication failure response message to the SMF.
[0080] After receiving the authentication failure response message, the SMF can return a PDU session establishment rejection response message to the UE.
[0081] By applying the embodiments of this application, SMF can construct a secure closed loop from discovery to authentication based on PDU session connections initiated by DNN, thereby improving the reliability and flexibility of the authentication method.
[0082] In an optional implementation, the network management server is further configured to generate a data network name for the industrial equipment based on the equipment information of the industrial equipment, and send target generation information to the DN-AAA server. The target generation information includes: the data network name of the industrial equipment and the equipment information of the industrial equipment, which includes: the IP address of the industrial equipment and the virtual local area network identifier of the industrial equipment.
[0083] Optionally, for industrial equipment that requires secondary authentication, the network administrator can enter the equipment information of the industrial equipment into the network management server. The equipment information may include the industrial equipment's IP address and virtual local area network identifier (VLAN ID).
[0084] Furthermore, based on the equipment information of the industrial equipment entered by the network administrator, the network management server can generate a Data Network Name (DNN) for that industrial equipment. In some implementations, the DNN can be a string representation of "IP + VLAN ID".
[0085] Based on the generated data network name for the industrial equipment, the network management server can send target generation information to the DN-AAA server. Specifically, the target generation information can be represented in the following form:<DNN,IP,VLAN ID> Where DNN is the data network name of the industrial equipment, IP is the IP address of the industrial equipment, and VLAN ID is the VLAN ID of the industrial equipment.
[0086] In an optional implementation, the DN-AAA server is also configured to convert and generate local secondary authentication information based on the target generation information.
[0087] The DN-AAA server can be configured to receive target generation information from the network management server and convert it into local secondary authentication information. Specifically, the DN-AAA server can convert the DNN in the target generation information into the PDU session association identifier in the local secondary authentication information, convert the IP address in the target generation information into the framed route identifier in the local secondary authentication information, and convert the VLAN ID in the target generation information into the allowed VLAN tag list in the local secondary authentication information.
[0088] By applying the embodiments of this application, the network management server can automatically send target generation information carrying the industrial equipment DNN to the DN-AAA server. Then, the DN-AAA server can automatically generate local secondary authentication information based on the target generation information, avoiding the tedious operation of manually configuring the DNN, reducing the risk of configuration errors, enabling support for large-scale access scenarios of industrial equipment, and improving the efficiency of secondary authentication.
[0089] Compared to existing technical solutions where all industrial devices connected to the same UE share the same public DNN and only one PDU session is established, the DN-AAA server needs to uniformly fill in the MAC addresses and VLAN-IDs of all connected devices into the authorization list corresponding to this PDU session. Furthermore, it is constrained by 3GPP protocols, limiting the allowed MAC address list and VLANs for each PDU session. The ID list can only be configured with a maximum of 16 entries. When the number of devices connected to the UE exceeds 16, the excess entries will not be sent to the UPF, resulting in secondary authentication failure. This application can allocate an independent device-level DNN to each connected industrial device. Each industrial device corresponds to an independent PDU session. Each PDU session is configured with only the MAC address and VLAN-ID of one industrial device, which can support the elastic access of a large number of industrial devices and meet the concurrent needs of a single UE connecting to multiple industrial devices, thereby improving the applicability of the secondary authentication method of this application.
[0090] In summary, in the secondary authentication method based on industrial equipment provided in this application embodiment, the network management server can dynamically generate device-level DNN information and synchronize it to the DN-AAA server; when the UE accesses the 5G network, it can automatically generate local device connection information from the network management server, report it to the network management server, and trigger the subscription data update; the UE can initiate a device-level PDU session based on the MAC address of the downstream target industrial equipment to achieve differentiated secondary authentication and access control.
[0091] Figure 5 This is a flowchart illustrating another secondary authentication method for industrial equipment provided in an embodiment of this application. This method can be applied to... Figure 1 The data communication system shown includes a DN-AAA server, which is communicatively connected to the network management server and terminals within the same system. Each terminal is equipped with at least one industrial device. Figure 5 As shown, the method includes: S501. The receiving terminal determines that a local matching item exists in the local data record and sends a secondary authentication request based on the target data network name corresponding to the local matching item. The local matching item is determined by the terminal based on the target data packet sent by the target industrial equipment and by retrieving the local data record using the MAC source address in the target data packet as an index.
[0092] The target industrial device is any industrial device mounted on the terminal. The local data record includes the mapping relationship between the industrial device's data network name, IP address, MAC address, and virtual LAN identifier. S502. Based on the target data network name, query the local authentication record matching item from the local secondary authentication information, and send the target authentication information corresponding to the local authentication record matching item to the UPF. The UPF is configured to generate packet filtering rules based on the target authentication information corresponding to the local authentication record matching item.
[0093] The local secondary authentication information includes the mapping relationship between PDU session association identifier, frame routing identifier and allowed VLAN tag list. The PDU session association identifier can be obtained by converting the data network name of the industrial equipment, the frame routing identifier can be obtained by converting the IP address of the industrial equipment, and the allowed VLAN tag list can be obtained by converting the virtual local area network identifier of the industrial equipment.
[0094] By applying the embodiments of this application, a DNN for a specific downstream industrial device can be generated based on the IP address and the virtual local area network identifier of the industrial device, and a device-level identity identifier can be determined. This enables independent secondary authentication and authorization for a single industrial device, and differentiated processing can be performed for multiple industrial devices connected to the same UE. For example, secondary authentication can be set for some industrial devices, while authentication can be exempted for others. This solves the problem of one-size-fits-all management of authentication for different industrial devices in traditional secondary authentication and improves the flexibility of the secondary authentication method.
[0095] In an optional implementation, the method further includes: Receive a secondary authentication request initiated by the SMF based on the PDU session connection, wherein the PDU session is initiated by the UE to the SMF using the target data network name corresponding to the local matching item as an identifier; Based on the target data network name, query the local authentication record matching item from the local secondary authentication information, and send the target authentication information corresponding to the local authentication record matching item to the UPF through the SMF.
[0096] In an optional implementation, the method further includes: If no matching local authentication record is found in the local secondary authentication information based on the target data network name, an authentication failure response message is returned to the SMF. The SMF is further configured to return a PDU session establishment rejection response message to the terminal if it receives the authentication failure response message.
[0097] In an optional implementation, the method further includes: The system receives target generation information sent by a network management server. This target generation information is sent by the network management server based on the data network name of the industrial equipment. The data network name of the industrial equipment is generated by the network management server based on the equipment information of the industrial equipment. The target generation information includes: the data network name of the industrial equipment and the equipment information of the industrial equipment. The equipment information includes: the IP address of the industrial equipment and the virtual local area network identifier of the industrial equipment.
[0098] In an optional implementation, the method further includes: Based on the target information, the local secondary authentication information is generated.
[0099] Optionally, the present invention also provides a secondary authentication system based on industrial equipment. The secondary authentication system includes: a terminal, a network management server, and a DN-AAA server. At least one industrial device is mounted on the terminal. The terminal is communicatively connected to the network management server and the DN-AAA server. The terminal is used to execute the steps of the secondary authentication method based on industrial equipment as described in any of the foregoing embodiments. Its implementation principle and technical effects are similar and will not be described again here.
[0100] Figure 6 This is a schematic diagram of an electronic device structure provided in an embodiment of this application. The electronic device can be a terminal or a DN-AAA server. Figure 6 As shown, the electronic device may include a processor 210, a storage medium 220, and a bus 230. The storage medium 220 stores machine-readable instructions executable by the processor 210. When the electronic device is running, the processor 210 communicates with the storage medium 220 via the bus 230, and the processor 210 executes the machine-readable instructions to perform the steps of the corresponding method embodiment described above. The specific implementation and technical effects are similar and will not be repeated here.
[0101] Optionally, this application also provides a storage medium storing a computer program, which, when run by a processor, executes the steps of the above-described method embodiments. The specific implementation and technical effects are similar and will not be repeated here.
[0102] In the several embodiments provided in this application, it should be understood that the disclosed apparatus and methods can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative; for instance, the division of units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be through some interfaces; the indirect coupling or communication connection between apparatuses or units may be electrical, mechanical, or other forms.
[0103] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.
[0104] Furthermore, the functional units in the various embodiments of this application can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or in the form of hardware plus software functional units.
[0105] The integrated units implemented as software functional units described above can be stored in a computer-readable storage medium. These software functional units, stored in a storage medium, include several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) or processor to execute some steps of the methods of the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.
[0106] It should be noted that in this document, relational terms such as "first" and "second" are used merely to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Unless otherwise specified, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes that element. It should be noted that similar reference numerals and letters in the following figures denote similar items; therefore, once an item is defined in one figure, it does not need to be further defined and explained in subsequent figures.
[0107] The above are merely preferred embodiments of this application and are not intended to limit this application. Various modifications and variations can be made to this application by those skilled in the art. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this application should be included within the protection scope of this application.
Claims
1. A secondary certification method for industrial equipment, characterized in that, A terminal used in a data communication system, wherein at least one industrial device is mounted on the terminal, and the terminal is communicatively connected to a network management server and a DN-AAA server in the data communication system, the method comprising: The terminal receives a target data packet sent by the target industrial device and retrieves local data records using the MAC source address in the target data packet as an index. The target industrial device is any industrial device attached to the terminal. The local data records include a mapping relationship between the industrial device's data network name, the industrial device's IP address, the industrial device's MAC address, and the industrial device's virtual LAN identifier. The industrial device's data network name is determined based on the industrial device's IP address and the industrial device's virtual LAN identifier. If a local data record has a local matching item, a secondary authentication request is initiated to the DN-AAA server based on the target data network name corresponding to the local matching item. This allows the DN-AAA server to query the local authentication record matching item from the local secondary authentication information based on the target data network name, and then send the target authentication information corresponding to the local authentication record matching item to the UPF. The UPF is configured to generate packet filtering rules based on the target authentication information corresponding to the local authentication record matching item. The local secondary authentication information includes the mapping relationship between PDU session association identifier, frame routing identifier and allowed VLAN tag list. The PDU session association identifier is obtained by converting the data network name of the industrial equipment, the frame routing identifier is obtained by converting the IP address of the industrial equipment, and the allowed VLAN tag list is obtained by converting the virtual local area network identifier of the industrial equipment.
2. The method according to claim 1, characterized in that, Before receiving the target data packet sent by the target industrial equipment and retrieving the local data record using the MAC source address in the target data packet as an index, the method further includes: Based on the local data record, local device connection information is generated and reported to the network management server. This allows the network management server to initiate a user subscription data modification request to the UDM via NEF based on the local device connection information. The request aims to add the terminal corresponding to the general public subscription identifier in the local device connection information to the target virtual local area network group with the virtual local area network identifier as the external identifier. The local device connection information includes the local data record and the general public subscription identifier of the terminal.
3. The method according to claim 1, characterized in that, Before receiving the target data packet sent by the target industrial equipment and retrieving the local data record using the MAC source address in the target data packet as an index, the method further includes: Send a registration request to the network management server and receive a first response data packet returned by the network management server according to the registration request. The first response data includes: the mapping relationship between the data network name of the industrial equipment, the IP address of the industrial equipment, and the target virtual local area network identifier of the industrial equipment. Based on the IP addresses of each industrial device in the first response data packet, send ARP requests to each industrial device and receive ARP responses returned by each industrial device; The local data record is generated based on the APR responses returned by each industrial device.
4. The method according to claim 1, characterized in that, The step of initiating a secondary authentication request to the DN-AAA server based on the target data network name corresponding to the local matching item, so that the DN-AAA server queries the local authentication record matching item from the local secondary authentication information based on the target data network name, and sends the target authentication information corresponding to the local authentication record matching item to the UPF, includes: A PDU session connection is initiated to the SMF using the target data network name corresponding to the local matching item as an identifier. The SMF then initiates a secondary authentication request to the DN-AAA server based on the PDU session connection. The DN-AAA server queries the local authentication record matching item from the local secondary authentication information based on the target data network name and sends the target authentication information corresponding to the local authentication record matching item to the UPF through the SMF.
5. The method according to claim 4, characterized in that, The DN-AAA server is further configured to return an authentication failure response message to the SMF if no matching local authentication record is found in the local secondary authentication information based on the target data network name. The SMF is further configured to return a PDU session establishment rejection response message to the terminal if the authentication failure response message is received.
6. The method according to any one of claims 1-5, characterized in that, The network management server is further configured to generate the data network name of the industrial equipment based on the equipment information of the industrial equipment, and send target generation information to the DN-AAA server. The target generation information includes: the data network name of the industrial equipment and the equipment information of the industrial equipment, wherein the equipment information includes: the IP address of the industrial equipment and the virtual local area network identifier of the industrial equipment.
7. The method according to claim 6, characterized in that, The DN-AAA server is also configured to generate the local secondary authentication information based on the target generation information.
8. A secondary certification method for industrial equipment, characterized in that, A DN-AAA server is used in a data communication system, wherein the DN-AAA server is communicatively connected to a network management server and a terminal in the data communication system, and at least one industrial device is mounted on the terminal. The method includes: The receiving terminal determines that a local matching item exists in the local data record and sends a secondary authentication request based on the target data network name corresponding to the local matching item. The local matching item is determined by the terminal based on the target data packet sent by the target industrial device and by retrieving the local data record using the MAC source address in the target data packet as an index. The target industrial device is any industrial device mounted on the terminal. The local data record includes the mapping relationship between the data network name of the industrial device, the IP address of the industrial device, the MAC address of the industrial device, and the virtual LAN identifier of the industrial device. Based on the target data network name, query the local authentication record matching item from the local secondary authentication information, and send the target authentication information corresponding to the local authentication record matching item to the UPF. The UPF is configured to generate packet filtering rules based on the target authentication information corresponding to the local authentication record matching item. The local secondary authentication information includes the mapping relationship between PDU session association identifier, frame routing identifier and allowed VLAN tag list. The PDU session association identifier can be obtained by converting the data network name of the industrial equipment, the frame routing identifier can be obtained by converting the IP address of the industrial equipment, and the allowed VLAN tag list can be obtained by converting the virtual local area network identifier of the industrial equipment.
9. A secondary authentication system based on industrial equipment, characterized in that, The secondary authentication system includes: a terminal, a network management server, and a DN-AAA server. The terminal is equipped with at least one industrial device. The terminal is communicatively connected to the network management server and the DN-AAA server. The terminal is used to execute the steps of the secondary authentication method based on industrial equipment as described in any one of claims 1-7.
10. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program that, when executed by a processor, performs the steps of the secondary authentication method based on industrial equipment as described in any one of claims 1-8.