Authentication Method, Device, Medium, and Chip

By using an Authentication Proxy (AP) entity to perform UE authentication based on an application key derived from the FQDN of a target entity, the method addresses the efficiency and load issues in existing AKMA-based systems, enhancing communication system performance.

JP2025517170AActive Publication Date: 2025-06-03BEIJING XIAOMI MOBILE SOFTWARE CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
JP2024566456
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2022-05-09
Publication Date
2025-06-03
Estimated Expiration
2042-05-09

AI Technical Summary

Technical Problem

In wireless communication systems, the existing AKMA-based authentication and key management methods increase the load on Application Function (AF) entities and reduce their efficiency, as User Equipment (UE) needs to perform message exchanges directly with multiple AF entities to determine access rights.

Method used

A communication method where a User Equipment (UE) determines a target entity from one or more application servers and communicates with it via an Authentication Proxy (AP) entity, deriving an application key based on the fully qualified domain name (FQDN) of the target entity for UE authentication by the AP entity.

Benefits of technology

This approach reduces the load on AF entities, improves their efficiency, and simplifies authentication for UE by allowing it to authenticate with a unified AP entity, thereby reducing complexity and enhancing efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025517170000001_ABST
    Figure 2025517170000001_ABST
Patent Text Reader

Abstract

The present disclosure relates to a communication method, apparatus, medium, and chip. The method is applied to a User Equipment (UE), and includes steps of determining a target entity from one or more Application Servers (ASs), where the UE communicates with the target entity via an Authentication Proxy (AP) entity, and deriving an Application Key based on a Fully Qualified Domain Name (FQDN) of the target entity, where the Application Key is used for the AP entity to perform UE authentication on the UE.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to the field of communication technologies, and specifically, to an authentication method, apparatus, medium, and chip.

Background Art

[0002] In a wireless communication system, 3GPP (3rd Generation Partnership Project) defines a session security protection function between a User Equipment (UE) and an application function, and provides an application-based key management method abbreviated as AKMA (Authentication and Key Management for Applications based on 3GPP credentials).

[0003] In related technologies, a User Equipment can perform message exchange with an Application Function (AF) entity based on AKMA, and by determining the access right of the User Equipment to the Application Function (AF) entity, establish a secure session with the Application Function (AF) entity, which increases the load of the Application Function (AF) entity and reduces the efficiency of the AF entity.

Summary of the Invention

Problems to be Solved by the Invention

[0004] To solve the above problems existing in related technologies, the present disclosure provides a communication method, apparatus, medium, and chip.

Means for Solving the Problems

[0005] According to a first aspect of an embodiment of the present disclosure, a communication method is provided, which is applicable to a user equipment (UE), and the communication method includes: Determining a target entity from one or more application servers (ASs), wherein the UE communicates with the target entity via an authentication proxy (AP) entity; Deriving an application key based on a fully qualified domain name (FQDN) of the target entity, wherein the application key is used for the AP entity to perform UE authentication on the UE.

[0006] In one embodiment, the communication method further includes: Sending, to the AP entity, an AKMA (Authentication and Key Management for Applications) key identifier (A-KID) of the UE and / or the FQDN of the target entity.

[0007] In one embodiment, the communication method further includes: Sending an application session establishment request message to the AP entity, wherein the application session establishment request message includes the A-KID of the UE and / or the FQDN of the target entity.

[0008] In one embodiment, the communication method further includes: Receiving an application session establishment response message sent from the AP entity.

[0009] In one embodiment, the communication method further includes: Further comprising the step of determining a first communication authority based on the application session establishment response message, The first communication authority is The UE has access authority to the target entity, The UE has access authority to the AP entity, The AP entity has proxy authority to the target entity, The target entity has acquisition authority for the subscriber identifier of the UE (identity of the subscriber), including one or more of them.

[0010] In one embodiment, the application session establishment response message is that the AP entity receives the application key from the AKMA Anchor Function (AAnF) entity, and is received from the AP entity when the AP entity sends the application session establishment response message to the UE. The application key is driven by the AAnF entity based on the FQDN of the target entity sent from the AP entity to the AAnF entity, or Or, The application session establishment response message is that the AP entity does not receive the application key from the AAnF entity, and is received from the AP entity when the AP entity sends the application session establishment response message to the UE. The application session response message includes a failure indication, and the application key is driven by the AAnF entity based on the FQDN of the target entity sent from the AP entity to the AAnF entity.

[0011] According to a second aspect of the embodiments of the present disclosure, a communication method is provided, which is applicable to an Authentication Proxy (AP) entity. The communication method includes: performing UE authentication on a User Equipment (UE) based on an application key, where the application key is derived based on the fully qualified domain name (FQDN) of a target entity among one or more Application Servers (ASs), and includes the step of the UE communicating with the target entity via the AP entity.

[0012] In one embodiment, the communication method further includes: when the UE authentication by the AP entity on the UE is successful, further including the step of sending a subscriber identifier to the target entity.

[0013] In one embodiment, the communication method further includes: sending the A-KID of the UE and / or the FQDN of the target entity to an AAnF entity.

[0014] In one embodiment, the communication method further includes: receiving the application key sent from the AAnF entity, where the application key is derived by the AAnF entity based on the FQDN of the target entity.

[0015] In one embodiment, the communication method further includes: receiving, from the UE, the A-KID of the UE and / or the FQDN of the target entity.

[0016] In one embodiment, the communication method further includes: Receiving, from the UE, an application session establishment request message, where the application session establishment request message includes the UE's AKMA key identifier (AKMA Key Identifier, A-KID), and / or the FQDN of the target entity.

[0017] In one embodiment, the communication method further includes: Sending, to the UE, an application session establishment response message.

[0018] In one embodiment, the communication method further includes: Determining a first communication permission based on the application key received from the AAnF entity, The first communication permission includes: The UE has access permission to the target entity; The UE has access permission to the AP entity; The AP entity has proxy permission for the target entity; The target entity has acquisition permission for the subscriber identifier of the UE, including one or more of the above.

[0019] According to a third aspect of the embodiments of the present disclosure, a communication method is provided, which is applicable to a target entity among one or more application servers (AS). The communication method includes: When the user equipment (UE) authentication by the authentication proxy (AP) entity to the UE is successful, receiving the subscriber identifier sent from the AP entity, including the step that the target entity communicates with the UE through the AP entity.

[0020] In one embodiment, the AP entity performing UE authentication on the UE is: The step that the AP entity performs UE authentication on the UE based on an application key, where the application key is derived based on the fully qualified domain name (FQDN) of the target entity is included.

[0021] In one embodiment, the communication method further includes the step of determining a first communication permission, wherein the first communication permission includes one or more of: the UE having access permission to the target entity; the UE having access permission to the AP entity; the AP entity having proxy permission to the target entity; and the target entity having acquisition permission to the subscriber identifier of the UE. the UE having access permission to the AP entity; the AP entity having proxy permission to the target entity; and the target entity having acquisition permission to the subscriber identifier of the UE.

[0022] According to a fourth aspect of the embodiments of the present disclosure, a communication method is provided, which is applied to an AAnF entity, and the communication method includes receiving, from an AP entity, the A-KID of a user equipment (UE) and / or the fully qualified domain name (FQDN) of a target entity; and sending an application key to the AP entity, where the application key is derived based on the fully qualified domain name (FQDN) of the target entity.

[0023] In one embodiment, the application key is used by the AP entity to perform UE authentication on the UE, and the UE communicates with the target entity via the AP entity.

[0024] According to a fifth aspect of the embodiments of the present disclosure, a communication device is provided, which is applied to a user equipment, and the device includes a processing module. The processing module, determines a target entity from among one or more application servers (ASs), and the UE communicates with the target entity via an Authentication Proxy (AP) entity, is configured to derive an Application Key based on the fully qualified domain name (FQDN) of the target entity, and the Application Key is used for the AP entity to perform UE authentication on the UE.

[0025] According to a sixth aspect of an embodiment of the present disclosure, a communication device is provided, which is applied to an AP entity, and the device includes a processing module configured to perform UE authentication on a User Equipment (UE) based on an Application Key, where the Application Key is derived based on the fully qualified domain name (FQDN) of a target entity among one or more application servers (ASs), and the UE communicates with the target entity via the AP entity.

[0026] According to a seventh aspect of an embodiment of the present disclosure, a communication device is provided, which is applied to a target entity among one or more application servers (ASs), and the device includes a transceiver module configured to receive a subscriber identifier transmitted from the AP entity when UE authentication on a User Equipment (UE) by the Authentication Proxy (AP) entity is successful, where the target entity communicates with the UE via the AP entity.

[0027] According to an eighth aspect of an embodiment of the present disclosure, a communication device is provided, which is applied to an AAnF entity, and the device includes a transceiver module, The transceiver module receives the A-KID of the user equipment and / or the fully qualified domain name (FQDN) of the target entity from the AP entity, and is configured to transmit an application key to the AP entity, where the application key is derived based on the fully qualified domain name (FQDN) of the target entity.

[0028] According to a ninth aspect of an embodiment of the present disclosure, there is provided a communication device including one or more processors and a memory coupled to the processor and storing computer-readable instructions. When the computer-readable instructions are executed by the processor, the communication device is caused to execute the communication method provided by any one of the first to fourth aspects of the present disclosure.

[0029] According to a tenth aspect of an embodiment of the present disclosure, there is provided a computer-readable storage medium storing computer program instructions. When the computer program instructions are executed by a processor, the communication method provided by any one of the first to fourth aspects of the present disclosure is realized. According to an eleventh aspect of an embodiment of the present disclosure, there is provided a computer program. When the computer program is executed by a processor, the communication method provided by any one of the first to fourth aspects of the present disclosure is realized.

Advantages of the Invention

[0030] The technical solutions provided by the embodiments of the present disclosure can achieve the following beneficial effects. Determine a target entity that requests communication from one or more first entities, determine first authorization request parameters based on the target entity, send an application session establishment request message to a first proxy entity based on the first authorization request parameters, and in response to receiving an application session establishment response message sent from the first proxy entity, determine whether the user equipment and the target entity have a first communication authorization. When the user equipment and the target entity have the first communication authorization, perform user equipment authentication by the first proxy entity. Here, the application session establishment request message instructs the first proxy entity to determine whether the user equipment and the target entity have the first communication authorization based on the first authorization request parameters. The first entity may include an entity that provides an application function. The first proxy entity may include a reliable entity that provides an authentication function within the 3GPP operator domain. The first proxy entity provides an authentication proxy function for the first entity. In this way, a reliable first proxy entity within the 3GPP operator domain can determine whether the user equipment and the first entity have the first communication authorization, perform identity verification of the user equipment when they have the first communication authorization, and implement some functions of the first entity by the first proxy entity. As a result, the load of the first entity is reduced, the efficiency of the first entity is improved, and the user equipment can implement the authorization authentication of one or more first entities and the user equipment authentication by a unified first proxy entity, reducing the complexity of authentication by the user equipment and improving the efficiency of the user equipment.

[0031] Note that the above general description and the following detailed description are exemplary and explanatory, and do not limit the present disclosure.

Brief Description of the Drawings

[0032] The accompanying drawings are incorporated herein and form a part of this specification, showing embodiments consistent with the present disclosure and used to explain the principles of the present disclosure together with the specification.

Figure 1

Figure 2

Figure 3

Figure 4

Figure 5

Figure 6

Figure 7

Figure 8

Figure 9

Figure 10

Figure 11

Figure 12

Figure 13

Figure 14

Figure 15

Figure 16

Figure 17

Figure 18

Figure 19

Figure 20

[0033] Here, exemplary embodiments will be described, and the examples are shown in the drawings. The following description is related to the drawings. Unless otherwise specified, the same numbers in different drawings represent the same elements or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments that conform to the present disclosure. Rather, they are merely examples of devices and methods that conform to some aspects of the present disclosure defined in the appended claims.

[0034] In the present disclosure, all operations of acquiring signals, information, or data are performed on the premise of complying with the corresponding data protection laws and policies of the country where the location is located and obtaining the permission of the owner of the corresponding device.

[0035] In the present disclosure, terms such as "first" and "second" are used to distinguish similar objects and are not understood as a specific order or a front - back order. Also, unless otherwise specified, in the description with reference to the drawings, the same marks in different drawings represent the same elements.

[0036] In the description of the present disclosure, unless otherwise specified, "a plurality" refers to two or more, and other quantifiers are similar. "At least one item (one)" or similar expressions include any combination of these options, including any combination of one item (one) or a plurality of items (pieces). For example, at least one item (one) of a, b, or c can represent a, b, c, a - b, a - c, b - c, or a - b - c, where a, b, c can be one or a plurality, and "and / or" is used to explain the relationship of the related objects, indicating that three types of relationships can exist. For example, A and / or B can represent three cases: A exists alone, A and B exist simultaneously, and B exists alone, where A and B can be singular or plural.

[0037] In the embodiments of the present disclosure, the description and operations are carried out in a specific order in the drawings, but it is not necessary to execute these operations in a specific order or sequence, nor is it necessary to obtain the desired result by executing all the operations shown. In a specific environment, multitasking and parallel processing may be advantageous.

[0038] In the related art, a user equipment can exchange messages with an application function (AF) entity based on AKMA to determine the access right of the user equipment to the application function (AF) entity, thereby establishing a secure session with the application function (AF) entity. However, the message exchange generated by multiple user equipments increases the load of the application function (AF) entity, reduces the efficiency of the application function (AF) entity, and when there are multiple application function (AF) entities in the network, if the UE determines the access right by directly exchanging messages with the AF, the efficiency of the UE will decrease.

[0039] To solve the above problems, the present disclosure provides an authentication method, apparatus, medium, and chip.

[0040] First, the implementation environment of the embodiments of the present disclosure will be described below.

[0041] The embodiments of the present disclosure are applicable to a 4G (the 4th Generation) network system such as a Long Term Evolution (LTE) system, or can also be applied to a 5G (the 5th Generation) network system such as an access network using a New Radio Access Technology (New RAT), a Cloud Radio Access Network (CRAN), or other communication systems.

[0042] FIG. 1 is a schematic diagram of a communication system to which the embodiments of the present disclosure shown in an exemplary embodiment are applied. It should be noted that the embodiments of the present disclosure are not limited to the system shown in FIG. 1, and the entities in FIG. 1 may be hardware, may be functionally divided software, or may be a structure combining the above two. The entities shown in FIG. 1 may be entities in any communication network architecture, and the communication network may be a 4G network, a 5G network, a 6G network, or the like.

[0043] As shown in FIG. 1, the communication system may include a first entity 101, a third entity 103, a first proxy entity 110, and user equipment 160. Here, the first entity 101 may be one or more. For example, the first entity 101 may include a first entity 1011, a first entity 1012, ……, a first entity 101n, etc. The first proxy entity 110 may be connected to the one or more first entities 101 (for example, connected via a wired network, a wireless network, or a combination of both), and the first proxy entity may be connected to the third entity, and the user equipment may be connected to the first proxy entity and the third entity.

[0044] In some embodiments, the first entity 101 may include a reliable entity that provides application functions within the 3GPP operator domain. The first proxy entity 110 may include a reliable entity that provides an authentication proxy function within the 3GPP operator domain. The third entity 103 may include an entity that provides AKMA authorization and application key derivation functions. For example, the third entity 103 may be a functional entity that provides an AKMA anchor function and authenticates the communication rights between the user equipment and the first entity.

[0045] Exemplarily, the first entity may include an application function AF (Application Function) entity or an application server SCS / AS (Services Capability Server / Application Server). The first proxy entity may include an authentication proxy AP (Authentication Proxy) entity. The third entity may include an AKMA anchor function AAnF (AKMA Anchor Function) entity.

[0046] In some embodiments, the first entity may include a trustworthy entity that provides application functions within the 3GPP operator domain, the first proxy entity may include a trustworthy entity that provides an authentication function within the 3GPP operator domain, the first proxy entity provides an authentication proxy function to the first entity, and the first entity may include one or more.

[0047] FIG. 2 is a schematic diagram of a communication system to which another embodiment of the present disclosure shown in an exemplary embodiment is applied. As shown in FIG. 2, the communication system may include a first entity 101, a second entity 102, a third entity 103, a first proxy entity 110, and user equipment 160. Here, the first entity 101 may be one or more. The second entity 102 may be connected to the one or more first entities 101 (for example, connected via a wired network, a wireless network, or a combination of both), the first proxy entity may be connected to the second entity and the third entity, and the user equipment may be connected to the first proxy entity and the third entity.

[0048] In FIG. 2, the first entity 101 may include an untrusted entity that provides an application function outside the 3GPP operator domain. For example, it may be an application function AF (Application Function) entity or an application server SCS / AS (Services Capability Server / Application Server). The first proxy entity 110 may include a trusted entity that provides an authentication proxy function within the 3GPP operator domain. For example, it may be an authentication proxy AP (AKMA Authentication Proxy) entity. The third entity 103 may include an entity that provides an AKMA authorization and application key derivation function. For example, it may be an AKMA anchor function AAnF (AKMA Anchor Function) entity. The second entity may include an entity that provides a network exposure function. For example, it may be a network exposure function NEF (Network Exposure Function) entity or a service capability exposure function SCEF (Service Capability Exposure Function) entity.

[0049] FIG. 3 shows an exemplary authentication method shown in an embodiment and is applicable to user equipment in the above communication system. As shown in FIG. 3, the method may include the following S301 to S305.

[0050] S301, the user equipment determines a target entity that requests communication from one or more first entities.

[0051] Exemplarily, the first entity may include an entity that provides an application function, such as an application function (AF) entity. The user equipment can determine the AF entity that requests communication according to the needs of the user function.

[0052] S302. The user equipment determines a first permission request parameter based on the target entity.

[0053] In some embodiments, first, a first target entity identifier of the target entity is obtained, and a first permission parameter can be determined based on the first target entity identifier.

[0054] Exemplarily, the first target entity identifier may include one or more of the FQDN (Fully Qualified Domain Name) of the target entity, an IP (Internet Protocol) address, and a port number.

[0055] In some embodiments, the first permission request parameter can be obtained based on the first target entity identifier and a user equipment identifier representing the identity of the user equipment.

[0056] Here, the user equipment identifier may include a key identifier (A-KID) corresponding to the user equipment. The key identifier (A-KID) may be generated based on the hardware information of the user equipment and the registration information transmitted from the communication system when the user equipment registers and accesses the communication system. The key identifier (A-KID) can uniquely identify one user equipment in the communication system.

[0057] Exemplarily, the first target entity identifier and the key identifier (A-KID) corresponding to the user equipment can be used as the first permission request parameter.

[0058] S303. The user equipment sends an application session establishment request message to a first proxy entity based on the first permission request parameter.

[0059] Here, the application session establishment request message can instruct the first proxy entity to determine whether the user equipment and the target entity have the first communication right based on the first right request parameter.

[0060] In some embodiments, the first proxy entity is connected to one or more first entities. Exemplarily, a unified first proxy entity can be set within a trusted domain or an edge node, and the first proxy entity can be connected to each first entity within the trusted domain or the edge node. When the user equipment requests communication with a target entity within the trusted domain or the edge node, an application session establishment request message (e.g., Application Session Establishment Request message) may be sent to the first proxy entity.

[0061] In some embodiments, the first entity may include an entity that provides an application function (e.g., a trusted entity that provides an application function within the 3GPP operator domain, or an untrusted entity that provides an application function outside the 3GPP operator domain), the first proxy entity may include a trusted entity that provides an authentication function within the 3GPP operator domain, the first proxy entity provides an authentication proxy function to the first entity, and the first entity may include one or more.

[0062] In some embodiments, the user equipment may pre-set the proxy domain name (e.g., FQDN) of the first proxy entity, and through the FQDN, the user equipment can perform message exchange or data transmission with the first proxy entity.

[0063] S304. In response to receiving an application session establishment response message sent from the first proxy entity, the user equipment determines whether the user equipment and the target entity have the first communication authority.

[0064] In some embodiments, when the user equipment receives the application session establishment response message, the user equipment can determine that the user equipment and the target entity have the first communication authority.

[0065] On the contrary, if the user equipment does not receive the application session establishment response message within a preset time, the user equipment can determine that the user equipment and the target entity do not have the first communication authority.

[0066] In some other embodiments, when the user equipment has received the application session establishment response message and the application session establishment response message contains success indication information, the user equipment can determine that the user equipment and the target entity have the first communication authority.

[0067] On the contrary, if the application session establishment response message received by the user equipment does not contain success indication information or contains failure indication information, the user equipment can determine that the user equipment and the target entity do not have the first communication authority. The success indication information may be any preset indication information.

[0068] In some other embodiments, when the user equipment has received the application session establishment response message and the application session establishment response message does not contain failure indication information, the user equipment can determine that the user equipment and the target entity have the first communication authority.

[0069] On the contrary, if the failure indication information is included in the application session establishment response message received by the user equipment, it can be determined that the user equipment and the target entity do not have the first communication authority. The failure indication information may be any preset error code.

[0070] S305. When the user equipment and the target entity have the first communication authority, the user equipment authenticates the user equipment by the first proxy entity.

[0071] Exemplarily, the user equipment derives the Application function key K AF (Also called application key K AF ) based on the FQDN of the target entity, and can perform UE authentication based on the Application key K AF and the first proxy entity.

[0072] It should be noted that the method for the user equipment to perform user equipment authentication refers to the implementation in the related art. For example, the user equipment authentication may be performed based on the entity key information corresponding to the target entity, or may be performed based on the user key information corresponding to the user equipment and the entity key information corresponding to the target entity. The present disclosure does not limit this.

[0073] Using the above method, a target entity that requests communication is determined from one or more first entities, a first permission request parameter is determined based on the target entity, an application session establishment request message is sent to a first proxy entity based on the first permission request parameter, and in response to receiving an application session establishment response message sent from the first proxy entity, it is determined whether the user equipment and the target entity have a first communication permission. When the user equipment and the target entity have the first communication permission, the first proxy entity authenticates the user equipment. Here, the application session establishment request message instructs the first proxy entity to determine whether the user equipment and the target entity have the first communication permission based on the first permission request parameter. The first entity may include an entity that provides an application function. The first proxy entity may include a reliable entity that provides an authentication function within the 3GPP operator domain. The first proxy entity provides an authentication proxy function to the first entity. In this way, it is possible to determine whether the user equipment and the first entity have the first communication permission by a reliable first proxy entity within the 3GPP operator domain. When they have the first communication permission, the identity verification of the user equipment is performed. Some functions of the first entity can be realized by the first proxy entity. As a result, the load of the first entity is reduced, the efficiency of the first entity is improved, and the user equipment can realize the permission authentication of one or more first entities and the user equipment authentication by a unified first proxy entity, reducing the complexity of authentication by the user equipment and improving the efficiency of the user equipment.

[0074] In some embodiments, the first communication permission may include one or more of the following permissions. Right 1: The user equipment has access rights to the target entity. Right 2: The user equipment has access rights to the first proxy entity. Right 3: The first proxy entity has proxy rights to the target entity. Right 4: The target entity has the right to obtain the user identifier of the user equipment.

[0075] Exemplarily, if it is determined that the user equipment has access rights to the target entity, it can be determined that the user equipment and the target entity have the first communication right. If it is determined that the user equipment has access rights to the first proxy entity and the first proxy entity has proxy rights to the target entity, it can also be determined that the user equipment and the target entity have the first communication right. If it is determined that the user equipment has access rights to the target entity, the user equipment has access rights to the first proxy entity, and the first proxy entity has proxy rights to the target entity, it can also be determined that the user equipment and the target entity have the first communication right.

[0076] In some embodiments, the fact that the user equipment and the target entity have the first communication right may include that the user equipment has access rights to the first proxy entity and the first proxy entity has proxy rights to the target entity. For example, if the first proxy entity is the same as the FQDN of the target entity, the first communication right can be used.

[0077] In some other embodiments, the user equipment and the target entity having the first communication right may include that the user equipment has access rights to the target entity, the user equipment has access rights to the first proxy entity, and the first proxy entity has proxy rights to the target entity. For example, when the first proxy entity is different from the FQDN of the target entity, the first communication right can be used.

[0078] In some embodiments, the first proxy entity may include a trusted authentication proxy (AP) entity within the 3GPP operator domain.

[0079] In some embodiments, the first entity may include a trusted entity that provides an application function within the 3GPP operator domain. Exemplarily, the first entity may include a trusted application function (AF) entity within the 3GPP operator domain, or a trusted application server (SCS / AS) entity within the 3GPP operator domain.

[0080] In some other embodiments, the first entity may include an untrusted entity that provides an application function outside the 3GPP operator domain. The first proxy entity can communicate with the first entity through a second entity, and the second entity may include an entity that provides a network exposure function. Exemplarily, the first entity may include an untrusted application function (AF) entity outside the 3GPP operator domain, or an untrusted application server (SCS / AS) entity outside the 3GPP operator domain, and the second entity includes a network exposure function (NEF) entity or a service capability exposure function (SCEF) entity.

[0081] In this way, the user equipment can communicate with AF entities outside the operator domain through the AP.

[0082] In some embodiments, after successfully authenticating the user equipment by the first proxy entity, the user equipment can communicate with the target entity.

[0083] Exemplarily, the user equipment may communicate directly with the target entity, or communicate with the target entity through the first proxy entity. For example, the first proxy entity transfers communication messages between the user equipment and the target entity.

[0084] In some other embodiments, after successfully authenticating the user equipment by the first proxy entity, the user equipment determines whether the proxy domain name of the first proxy entity is the same as the first domain name of the target entity. If the proxy domain name is different from the first domain name, the user equipment may communicate with the target entity.

[0085] On the contrary, if the proxy domain name is the same as the first domain name, it is further determined whether the user equipment and the target entity have a second communication right through a secure session between the user equipment and the proxy entity. If they have the second communication right, they can communicate with the target entity.

[0086] Note that the above proxy domain name may be a fully qualified domain name FQDN corresponding to the first proxy entity, and the first domain name may be a fully qualified domain name FQDN corresponding to the target entity. In some scenarios, the first proxy entity and the target entity can use the same FQDN but different IP addresses or port numbers. In this scenario, the above first communication authority can indicate that the user equipment has access authority to the FQDN, but it does not necessarily mean that the user equipment has access authority to the target entity corresponding to the IP address or port number. In this case, through the secure session between the user equipment and the proxy entity, it can be further determined whether the user equipment and the target entity have the second communication authority.

[0087] FIG. 4 is an authentication method shown in an exemplary embodiment and is applicable to user equipment. As shown in FIG. 4, the method may include the following S401 to S405.

[0088] S401. When the user equipment and the target entity have the first communication authority, the user equipment authenticates the user equipment by the first proxy entity.

[0089] S402. After successfully authenticating the user equipment by the first proxy entity, the user equipment establishes a secure session with the first proxy entity.

[0090] Exemplarily, the secure session may be a TLS (Transport Layer Security) session. Through the TLS session, confidentiality and data integrity for the communication between the user equipment and the first proxy entity can be realized.

[0091] S403. The user equipment obtains the proxy domain name of the first proxy entity and the first domain name of the target entity.

[0092] In some embodiments, the proxy domain name may be a fully qualified domain name FQDN corresponding to the first proxy entity, and the first domain name may be a fully qualified domain name FQDN corresponding to the target entity.

[0093] S404. If the proxy domain name is the same as the first domain name, the user equipment determines, through a secure session, whether the user equipment and the target entity have a second communication permission.

[0094] S405. If it is determined that the user equipment and the target entity have a second communication permission, the user equipment communicates with the target entity.

[0095] Similarly, the user equipment may communicate directly with the target entity or communicate with the target entity through the first proxy entity. For example, the first proxy entity transfers communication messages between the user equipment and the target entity.

[0096] In this way, through the authentication for the first communication permission and the second communication permission, when the first proxy entity is the same as the FQDN of the target entity, it can be determined that the user equipment has access permission to the target entity, thereby further improving security.

[0097] In some embodiments, in step S404, determining whether the user equipment and the target entity have a second communication permission through a secure session may include the following steps.

[0098] First, the user equipment sends a target entity service request message to the first proxy entity through the above secure session.

[0099] Exemplarily, the target entity service request message may include a second target entity identifier, and the second target entity identifier is a protected entity identifier obtained by the user equipment based on the first target entity identifier. The target entity service request message instructs the first proxy entity to determine whether the user equipment and the target entity have the second communication authority based on the second target entity identifier.

[0100] In some embodiments, the second target entity identifier is an identifier determined after protecting the first target entity identifier corresponding to the target entity based on the request of a secure session (e.g., a TLS session).

[0101] In some other embodiments, the first target entity identifier can be directly used as the second target entity identifier, and the protection for the first target entity identifier can be achieved by transmitting the second target entity identifier through a secure session, thereby avoiding the modification of the entity identifier during transmission.

[0102] Thereafter, in response to receiving the target entity service response message sent from the first proxy entity, the user equipment determines whether the user equipment and the target entity have the second communication authority.

[0103] In some embodiments, when the user equipment receives the target entity service response message, the user equipment can determine that the user equipment and the target entity have the second communication authority.

[0104] On the contrary, if the user equipment does not receive the target entity service response message within a preset time, it can be determined that the user equipment and the target entity do not have the second communication authority.

[0105] In some other embodiments, if the user equipment receives the target entity service response message and the success indication information is included in the target entity service response message, it can be determined that the user equipment and the target entity have the second communication authority.

[0106] On the contrary, if the success indication information is not included in the target entity service response message received by the user equipment, or if the failure indication information is included, it can be determined that the user equipment and the target entity do not have the second communication authority. The success indication information may be any preset indication information.

[0107] In some other embodiments, if the user equipment receives the target entity service response message and the failure indication information is not included in the target entity service response message, it can be determined that the user equipment and the target entity have the second communication authority.

[0108] On the contrary, if the failure indication information is included in the target entity service response message received by the user equipment, it can be determined that the user equipment and the target entity do not have the second communication authority. The failure indication information may be any preset error code. The failure indication information may be any preset error code.

[0109] In this way, the user equipment can determine whether the user equipment and the target entity have the second communication authority through a secure session.

[0110] In some embodiments, the second communication authority may include one or more of the following authorities. Authority 6: The user equipment has access authority to the target entity. Authority 7: The first proxy entity has proxy authority to the target entity. Authority 8: The target entity has the right to obtain the subscriber identifier of the user equipment.

[0111] In this way, through the secure session between the user equipment and the first proxy entity, it can be determined whether the user equipment and the target entity have the second communication authority, and the reliability of authentication is further improved.

[0112] FIG. 5 is an exemplary authentication method shown in an embodiment and is applicable to the first proxy entity in the communication system. As shown in FIG. 5, the method may include S501 to S503.

[0113] S501: The first proxy entity receives an application session establishment request message sent from the user equipment.

[0114] Here, the application session establishment request message includes first authorization request parameters. The application session establishment request message instructs the first proxy entity to determine whether the user equipment and the target entity have the first communication authorization based on the first authorization request parameters. The target entity is the entity that requests communication determined by one or more first entities by the user equipment. The first entity may include an entity that provides an application function. The first proxy entity may include a reliable entity that provides an authentication function within the 3GPP operator domain. The first proxy entity provides an authentication proxy function to the first entity, and the first entity may include one or more of them.

[0115] S502. The first proxy entity determines whether the user equipment and the target entity have the first communication authorization based on the first authorization request parameters.

[0116] In this way, a reliable first proxy entity within the 3GPP operator domain can determine whether the user equipment and the first entity have the first communication authorization. When they have the first communication authorization, the identity verification of the user equipment is performed. Some functions of the first entity can be realized by the first proxy entity. As a result, the load of the first entity is reduced, the efficiency of the first entity is improved, and the user equipment can realize the authorization authentication of one or more first entities and the user equipment authentication by a unified first proxy entity, reducing the complexity of authentication by the user equipment and improving the efficiency of the user equipment.

[0117] In some embodiments, the first proxy entity can determine whether the user equipment and the target entity have the first communication permission through message exchange with the third entity. For example, it may include the following steps.

[0118] First, the first proxy entity determines the second permission request parameter based on the first permission request parameter.

[0119] In some embodiments, the first permission request parameter and the proxy entity identifier corresponding to the first proxy entity can be used as the second permission request parameter. Exemplarily, when the first permission request parameter includes the first target entity identifier of the target entity and the key identifier (A-KID) corresponding to the user equipment, the second permission request parameter may include the first target entity identifier, the key identifier (A-KID), and the proxy entity identifier corresponding to the first proxy entity.

[0120] In some other embodiments, the first permission request parameter can be used as the second permission request parameter.

[0121] Here, the first proxy entity sends the second permission request parameter to the third entity.

[0122] Exemplarily, the third entity may include an entity that provides AKMA authorization and application key derivation functions. The second permission request parameter is used to instruct the third entity to determine whether the user equipment and the target entity have the first communication permission.

[0123] Next, the first proxy entity obtains the first pending key information sent from the third entity.

[0124] The first pending key information is key information obtained by a third entity based on second authorization request parameters.

[0125] In some embodiments, the first pending key information may include an application key K corresponding to the target entity. AF It may be included.

[0126] In some other embodiments, the first pending key information may include an application key K corresponding to the target entity. AF and a key expiration time K AF expiration time. It may be included.

[0127] In some embodiments, the first proxy entity can send second authorization request parameters to the third entity through a first key request message. The first key request message is used to instruct the third entity to obtain the first pending key information and a subscriber identifier of the user equipment. The first proxy entity can further receive a first key response message sent from the third entity and obtain the first pending key information included in the first key response message.

[0128] Furthermore, the first key response message may further include a second subscriber identifier corresponding to the user equipment. The first proxy entity can obtain the second subscriber identifier based on the received first key response message. The second subscriber identifier may include a subscription permanent identifier SUPI (Subscription Permanent Identifier) corresponding to the user equipment.

[0129] In some embodiments, the first proxy entity can send the second permission request parameter to the third entity through the second key request message, where the second key request message indicates that the first proxy entity requests to obtain the first pending key information. The first proxy entity can further receive the second key response message sent from the third entity and obtain the first pending key information included in the second key response message. Finally, the first proxy entity determines whether the user equipment and the target entity have the first communication permission based on the first pending key information.

[0130] Exemplarily, if the first pending key information includes the application key K corresponding to the target entity AF it can be determined that the user equipment and the target entity have the first communication permission. In contrast, if the first pending key information does not include the application key K corresponding to the target entity AF or the first pending key information does not include the valid application key K AF or the first pending key information is not received within the preset time, it can be determined that the user equipment and the target entity do not have the first communication permission.

[0131] In this way, the first proxy entity can determine whether the user equipment and the target entity have the first communication permission by interacting with the third entity.

[0132] In some other embodiments, if the user equipment communication permission policy is stored in the first proxy entity, it can be directly determined whether the user equipment and the target entity have the first communication permission based on the first permission request parameter.

[0133] When the user equipment and the target entity have the first communication authority, the first proxy entity sends an application session establishment response message to the user equipment and performs user equipment authentication on the user equipment.

[0134] In some embodiments, the first proxy entity can indicate that the user equipment and the target entity have the first communication authority by sending the application session establishment response message, and conversely, can indicate that the user equipment and the target entity do not have the first communication authority by not sending the application session establishment response message.

[0135] In some other embodiments, the first proxy entity may include success indication information in the application session establishment response message, and use the success indication information to indicate that the user equipment and the target entity have the first communication authority. Conversely, by making the application session establishment response message not include success indication information, it can be indicated that the user equipment and the target entity do not have the first communication authority. Here, the success indication information may be any preset indication information.

[0136] In some other embodiments, when the user equipment and the target entity do not have the first communication authority, the first proxy entity can indicate that the user equipment and the target entity do not have the first communication authority by including failure indication information in the application session establishment response message. Conversely, when the user equipment and the target entity have the first communication authority, the first proxy entity can indicate that the user equipment and the target entity have the first communication authority by making the application session establishment response message not include failure indication information.

[0137] Using the above method, based on the first proxy entity, it is possible to authenticate the communication authority between the user equipment and the first entity, thereby reducing the problem that the load caused by the authority authentication by the first entity is too high.

[0138] In some embodiments, the first communication authority may include one or more of the following authorities. Authority 1: The user equipment has access authority to the target entity. Authority 2: The user equipment has access authority to the first proxy entity. Authority 3: The first proxy entity has proxy authority to the target entity. Authority 4: The target entity has the right to obtain the user equipment's subscriber identifier.

[0139] In some embodiments, the first proxy entity may include a reliable authentication proxy (AP) entity within the 3GPP operator domain.

[0140] In some embodiments, the first entity may include a reliable application function (AF) entity within the 3GPP operator domain, or a reliable application server (SCS / AS) entity within the 3GPP operator domain, or an unreliable application function (AF) entity outside the 3GPP operator domain, or an unreliable application server (SCS / AS) entity outside the 3GPP operator domain.

[0141] In some embodiments, the second entity may include a network exposure function (NEF) entity or a service capability exposure function (SCEF) entity.

[0142] In some embodiments, the third entity may include an AKMA anchor function (AAnF) entity.

[0143] In some embodiments, when the user equipment authentication by the first proxy entity is successful, the first proxy entity can notify the target entity of the first authentication result of the user equipment authentication. Here, the first authentication result indicates that the target entity and the user equipment have communication permissions.

[0144] For example, when the target entity is a reliable entity that provides an application function within the 3GPP operator domain, the first proxy entity can send a first notification message to the target entity, and the first notification message may include the first authentication result. Further, when the first proxy entity obtains the second subscriber identifier of the user equipment (for example, when obtaining the second subscriber identifier through the first key response message), the first notification message may further include the second subscriber identifier.

[0145] Also, for example, when the target entity is an unreliable entity that provides an application function outside the 3GPP operator domain, the first proxy entity can instruct the second entity to send the first authentication result to the target entity by sending a second notification message to the second entity based on the first authentication result. Similarly, when the first proxy entity obtains the second subscriber identifier of the user equipment (for example, when obtaining the second subscriber identifier through the first key response message), the second notification message may further include the second subscriber identifier.

[0146] Furthermore, the authentication result notification message may further include a first subscriber identifier corresponding to the user equipment. Exemplarily, if the first key response message includes the first subscriber identifier corresponding to the user equipment, the first proxy entity may transmit the first subscriber identifier to the target entity through the authentication result notification message.

[0147] Note that the first subscriber identifier may be any identifier for representing the user equipment. For example, it may be a general public subscription identifier (GPSI) corresponding to the user equipment.

[0148] In this way, the first proxy entity can verify the communication authority between the user equipment and the first entity. When the user equipment and the first entity have the communication authority, the first proxy entity instructs the user equipment to communicate with the first entity.

[0149] In some other embodiments, when the user equipment authentication by the first proxy entity is successful, the first proxy entity can obtain the proxy domain name of the first proxy entity and the first domain name of the target entity. If the proxy domain name is different from the first domain name, the first proxy entity notifies the target entity of the first authentication result, thereby indicating that the user equipment has the communication authority or instructing the target entity to communicate with the user equipment.

[0150] On the contrary, if the proxy domain name is the same as the first domain name, the first proxy entity does not temporarily notify the target entity of the first authentication result. Wait to determine whether the user equipment and the target entity have the second communication authority. After it is determined that the user equipment and the target entity have the second communication authority, the second authentication result is notified to the target entity.

[0151] Exemplarily, the first proxy entity can further determine whether the user equipment and the target entity have a second communication right according to a target entity service request message sent from the user equipment.

[0152] Note that the proxy domain name may be a fully qualified domain name FQDN corresponding to the first proxy entity, and the first domain name may be a fully qualified domain name FQDN corresponding to the target entity. In some scenarios, the first proxy entity and the target entity can use the same FQDN but different IP addresses or port numbers. In this scenario, the first communication right can indicate that the user equipment has access rights to the FQDN, but it does not necessarily indicate that the user equipment has access rights to the target entity corresponding to the IP address or port number. In this case, it is possible to further determine whether the user equipment and the target entity have a second communication right through a secure session between the user equipment and the proxy entity.

[0153] FIG. 6 shows an authentication method illustrated in an exemplary embodiment and applicable to the first proxy entity. As shown in FIG. 6, the method may include the following S601 to S604.

[0154] S601, after successful user equipment authentication for the user equipment, the first proxy entity establishes a secure session with the user equipment.

[0155] Exemplarily, the secure session may be a TLS (Transport Layer Security) session, and the TLS session can realize confidentiality and data integrity for the communication between the first proxy entity and the user equipment.

[0156] S602. The first proxy entity receives a target entity service request message sent from the user equipment via a secure session.

[0157] The target entity service request message includes a second target entity identifier, where the second target entity identifier is a protected entity identifier obtained by the user equipment based on the first target entity identifier of the target entity, and the target entity service request message is a message sent by the user equipment when it is determined that the proxy domain name of the first proxy entity is the same as the first domain name of the target entity.

[0158] S603. The first proxy entity determines whether the user equipment and the target entity have a second communication right based on the second target entity identifier.

[0159] In some embodiments, when the second target entity identifier is the same as the first target entity identifier, it can be determined that the user equipment and the target entity have a second communication right.

[0160] In some other embodiments, when the second target entity identifier is different from the first target entity identifier, the first proxy entity can determine whether the user equipment and the target entity have a second communication right through message exchange with a third entity.

[0161] S604. The first proxy entity sends a target entity service response message to the user equipment.

[0162] The target entity service response message indicates whether the user equipment and the target entity have a second communication permission.

[0163] In some embodiments, the first proxy entity can indicate that the user equipment and the target entity have a second communication permission by sending the target entity service response message. In contrast, by not sending the target entity service response message, it can be indicated that the user equipment and the target entity do not have a second communication permission.

[0164] In some other embodiments, the first proxy entity may make the application session establishment response message include success indication information, and the success indication information indicates that the user equipment and the target entity have a second communication permission. In contrast, by making the application session establishment response message not include success indication information, it can be indicated that the user equipment and the target entity do not have a second communication permission. Here, the success indication information may be any preset indication information.

[0165] In some other embodiments, when the user equipment and the target entity do not have a second communication permission, the first proxy entity can indicate that the user equipment and the target entity do not have a second communication permission by making the target entity service response message include failure indication information. In contrast, when the user equipment and the target entity have a second communication permission, the first proxy entity can indicate that the user equipment and the target entity have a second communication permission by making the target entity service response message include failure indication information. The failure indication information may be any preset error code.

[0166] In this way, the first proxy entity can determine whether the user equipment and the target entity have the second communication authority through a secure session, and send the authentication result to the target device.

[0167] In some other embodiments, the first proxy entity can determine whether the user equipment and the target entity have the second communication authority through message exchange with a third entity.

[0168] FIG. 7 shows an exemplary authentication method applicable to the first proxy entity. As shown in FIG. 7, when the second target entity identifier is different from the first target entity identifier, the first proxy entity can determine whether the user equipment and the target entity have the second communication authority based on this method, and this method may include the following S701 to S704.

[0169] S701. The first proxy entity determines the third authority request parameter based on the second target entity identifier.

[0170] S702. The first proxy entity sends the third authority request parameter to the third entity.

[0171] S703. The first proxy entity obtains the authorization result parameter sent from the third entity.

[0172] S704. The first proxy entity determines whether the user equipment and the target entity have the second communication authority based on the authorization result parameter.

[0173] According to this method, when the second target entity identifier is different from the first target entity identifier, the first proxy entity can determine whether the user equipment and the target entity have the second communication authority through message exchange with the third entity.

[0174] Here, the third authority request parameter instructs the third entity to determine whether the user equipment and the target entity have the second communication authority. The authorization result parameter may be used to indicate whether the user equipment and the target entity have the second communication authority. Exemplarily, the third authority request parameter may include a key identifier (A-KID), the second target entity identifier, and a proxy entity identifier corresponding to the first proxy entity, and the third authority request parameter may be used to determine whether the third entity user equipment and the target entity have the second communication authority.

[0175] In some embodiments, the first proxy entity can send the third authority request parameter to the third entity through a third key request message for instructing the third entity to obtain the authorization result parameter and the subscriber identifier of the user equipment. The first proxy entity can receive the third key response message sent by the third entity and obtain the authorization result parameter included in the third key response message.

[0176] Furthermore, the third key response message further includes a second subscriber identifier corresponding to the user equipment, and the first proxy entity can also obtain the second subscriber identifier based on the received third key response message. The second subscriber identifier may include a subscription permanent identifier (SUPI) corresponding to the user equipment.

[0177] In some embodiments, the third key request message may include an authorization instruction parameter. The authorization instruction parameter may be used for the third entity to determine whether the user equipment and the target entity have the second communication authority based on the third key request message. Similarly, the third key response message may include an authorization instruction parameter for indicating that the third key response message is a response to the third key request message.

[0178] In some other embodiments, the first proxy entity can send the third authority request parameter to the third entity through a fourth key request message for indicating that the first proxy entity requests to obtain the authorization result parameter. The first proxy entity can further receive the fourth key response message sent from the third entity and obtain the authorization result parameter included in the fourth key response message.

[0179] In some embodiments, the fourth key request message further includes an authorization instruction parameter, and the authorization instruction parameter is used for the third entity to determine whether the user equipment and the target entity have the second communication authority based on the fourth key request message. Similarly, the fourth key response message may include an authorization instruction parameter for indicating that the fourth key response message is a response corresponding to the fourth key request message.

[0180] In some embodiments, the authorization result parameter can indicate authorization success or authorization failure. The first proxy entity determines whether the user equipment and the target entity have the second communication authority based on the authorization result parameter. Exemplarily, if the authorization result parameter is authorization success, it can be determined that the user equipment and the target entity have the second communication authority. On the contrary, if the authorization result parameter is authorization failure, or if the authorization result parameter is not included in the above key response message (for example, the third key response message or the fourth key response message), it can be determined that the user equipment and the target entity do not have the second communication authority.

[0181] In some embodiments, the second communication authority may include one or more of the following authorities. Authority 6, the user equipment has access authority to the target entity. Authority 7, the first proxy entity has proxy authority to the target entity. Authority 8, the target entity has the right to obtain the subscriber identifier of the user equipment.

[0182] In this way, through the secure session between the user equipment and the first proxy entity, it can be determined whether the user equipment and the target entity have the second communication authority, further improving the reliability of authentication.

[0183] In some embodiments, when it is determined that the user equipment and the target entity have the second communication authority based on the authorization result parameter, the first proxy entity can notify the target entity of the second authentication result.

[0184] Here, the second authentication result is used to indicate that the target entity and the user equipment have communication authority.

[0185] For example, when the target entity is a reliable entity that provides an application function within the 3GPP operator domain, the first proxy entity can send a third notification message including the second authentication result to the target entity. Further, when the first proxy entity obtains the second subscriber identifier of the user equipment (for example, when obtaining the second subscriber identifier through the third key response message), the third notification message may further include the second subscriber identifier.

[0186] Also, for example, when the target entity is an unreliable entity that provides an application function outside the 3GPP operator domain, the first proxy entity can instruct the second entity to send the first authentication result to the target entity by sending a fourth notification message to the second entity based on the first authentication result. Further, when the first proxy entity obtains the second subscriber identifier of the user equipment (for example, when obtaining the second subscriber identifier through the third key response message), the fourth notification message may include the second subscriber identifier.

[0187] In this way, the first proxy entity can verify the second communication authority between the user equipment and the first entity through a secure session, further improve the reliability of authentication, and instruct the user equipment to communicate with the first entity when the user equipment and the first entity have the second communication authority.

[0188] FIG. 8 is an authentication method shown in an exemplary embodiment and is applicable to a third entity. As shown in FIG. 8, the method may include the following S801 to S804.

[0189] S801. The third entity receives the second authority request parameter sent from the first proxy entity.

[0190] The second authorization request parameter instructs the third entity to determine whether the user equipment and the target entity have the first communication authorization. The target entity is the entity that requests communication determined from one or more first entities by the user equipment. The first entity includes the entity that provides the application function. The first proxy entity includes the reliable entity that provides the authentication function within the 3GPP operator domain. The first proxy entity provides the authentication proxy function to the first entity. The third entity includes the entity that provides the AKMA authorization and the application key derivation function.

[0191] S802. The third entity determines whether the user equipment and the target entity have the first communication authorization based on the second authorization request parameter.

[0192] In some embodiments, the second authorization request parameter may include the proxy entity identifier corresponding to the first proxy entity. After receiving the second authorization request parameter, the third entity can determine whether the third entity has the right to provide services to the first proxy entity based on the first preset policy. The first preset policy may include preset parameters.

[0193] If it is determined that the third entity has the right to provide services to the first proxy entity, it is determined whether the user equipment and the target entity have the first communication authorization based on the second authorization request parameter.

[0194] On the contrary, if it is determined that the third entity does not have the authority to provide services to the first proxy entity, the process ends, and it is no longer checked whether the user equipment and the target entity have the first communication authority. At this time, the third entity can send a failure instruction to the first proxy entity so that the first proxy entity performs the corresponding failure processing, or the third entity can directly stop the processing and not send any messages.

[0195] In some embodiments, the second authority request parameter includes a key identifier (A-KID) corresponding to the user equipment, a first target entity identifier of the target entity, and a proxy entity identifier corresponding to the first proxy entity. In this step, the method for determining whether the user equipment and the target entity have the first communication authority includes one or more of the following methods. Method 1: Based on the key identifier (A-KID) and the first target entity identifier, determine whether the user equipment has the access authority to the target entity. Method 2: Based on the key identifier (A-KID) and the proxy entity identifier, determine whether the user equipment has the access authority to the first proxy entity. Method 3: Based on the proxy entity identifier and the first target entity identifier, determine whether the first proxy entity has the proxy authority to the target entity. Method 4: Based on the key identifier (A-KID) and the first target entity identifier, determine whether the target entity has the acquisition authority to the subscriber identifier of the user equipment. Method 5: Based on the key identifier (A-KID), determine whether the user equipment has the authority to use AKMA.

[0196] In some embodiments, the third entity may determine that the user equipment has access rights to both the first proxy entity and the target entity, and if the first proxy entity has proxy rights to the target entity, determine that the user equipment and the target entity have the first communication right.

[0197] In some other embodiments, the third entity may determine that the user equipment and the target entity have the first communication right when it is determined that the user equipment has access rights to both the target entity and the first proxy entity has proxy rights to the target entity.

[0198] S803. When the third entity determines that the user equipment and the target entity have the first communication right, the third entity obtains the first pending key information.

[0199] Exemplarily, the first pending key information can be obtained based on the entity key information corresponding to the target entity.

[0200] In some embodiments, the entity key information corresponding to the target entity may include the application key K AF corresponding to the target entity.

[0201] In some other embodiments, the entity key information corresponding to the target entity may include the application key K AF corresponding to the target entity and the key expiration time K AF expiration time.

[0202] S804. The third entity sends the first pending key information to the first proxy entity.

[0203] Thereby, the first proxy entity determines whether the user equipment and the target entity have the first communication authority based on the first pending key information.

[0204] In some embodiments, the third entity can receive the second authority request parameters sent from the first proxy entity through the first key request message, and the first key request message is used to instruct the third entity to obtain the first pending key information and the subscriber identifier of the user equipment. The third entity can further send the first pending key information to the first proxy entity through the first key response message.

[0205] Furthermore, when it is determined that the target entity has the authority to obtain the subscriber identifier, the third entity can also send the first pending key information and the second subscriber identifier corresponding to the user equipment to the first proxy entity through the first key response message.

[0206] Exemplarily, when it is determined that the target entity has the authority to obtain the subscriber identifier, the third entity sends the first pending key information and the second subscriber identifier corresponding to the user equipment to the first proxy entity through the third key response message. For example, obtain the second subscriber identifier corresponding to the user equipment, and send the second subscriber identifier and the authorization result parameters to the first proxy entity through the third key response message.

[0207] In some embodiments, the second subscriber identifier may be an identifier for representing the user equipment within the 3GPP operator domain. Exemplarily, the second subscriber identifier may be a subscription permanent identifier (SUPI) corresponding to the user equipment.

[0208] In some other embodiments, the third entity can receive the second authorization request parameters sent from the first proxy entity through the second key request message. The second key request message instructs the third entity to obtain the first pending key information. The third entity may further send the first pending key information to the first proxy entity through the second key response message.

[0209] In this way, the third entity can determine whether the user equipment and the target entity have the first communication authorization, and notify the first proxy entity with the first pending key information.

[0210] In some embodiments, the first proxy entity may include a reliable authentication proxy (AP) entity within the 3GPP operator domain.

[0211] In some embodiments, the first entity may include a reliable application function (AF) entity within the 3GPP operator domain, or a reliable application server (SCS / AS) entity within the 3GPP operator domain, or an unreliable application function (AF) entity outside the 3GPP operator domain, or an unreliable application server (SCS / AS) entity outside the 3GPP operator domain.

[0212] In some embodiments, the third entity may include an AKMA anchor function (AAnF) entity.

[0213] FIG. 9 is an exemplary authentication method shown in an embodiment and is applicable to the third entity. As shown in FIG. 9, after sending the third key response message to the second entity, the method may further include the following S901-S903.

[0214] S901. The third entity receives the third permission request parameter sent from the first proxy entity.

[0215] S902. The third entity determines whether the user equipment and the target entity have the second communication permission based on the third permission request parameter.

[0216] S903. The third entity sends the authorization result parameter to the first proxy entity.

[0217] The authorization result parameter may be used to notify the first proxy entity whether the user equipment and the target entity have the second communication permission.

[0218] In some embodiments, the third permission request parameter may include a proxy entity identifier corresponding to the first proxy entity. After receiving the fourth key request message, the third entity can determine whether the third entity has the right to provide services to the first proxy entity based on a first preset policy. The first preset policy may include preset parameters.

[0219] If it is determined that the third entity has the right to provide services to the first proxy entity, based on the fourth key request message, it is determined whether the user equipment and the target entity have the second communication permission.

[0220] On the contrary, if the third entity does not have the right to provide services to the first proxy entity, the process may end, and it is not necessary to further check whether the user equipment and the target entity have the first communication permission. At this time, the third entity may send a failure indication to the second entity, whereby the second entity performs corresponding failure processing. Alternatively, the third entity directly stops the process and does not send any messages.

[0221] In some embodiments, the third authorization request parameter may include a key identifier (A-KID), a second target entity identifier, and a proxy entity identifier corresponding to the first proxy entity. The second target entity identifier is a protected entity identifier obtained by the user equipment based on the first target entity identifier of the target entity. The method for determining whether the user equipment and the target entity have the second communication authorization in step S902 may include one or more of the following. Method 6: Determine whether the user equipment has access authority to the target entity based on the key identifier (A-KID) and the second target entity identifier. Method 7: Determine whether the first proxy entity has proxy authority for the target entity based on the proxy entity identifier and the second target entity identifier. Method 8: Determine whether the target entity has the acquisition authority for the subscriber identifier of the user equipment based on the key identifier (A-KID) and the first target entity identifier.

[0222] In some embodiments, when it is determined that the third entity has the access authority for the target entity and the first proxy entity has the proxy authority for the target entity, it can be determined that the user equipment and the target entity have the second communication authorization.

[0223] In some embodiments, the third entity can receive the third authorization request parameters sent from the first proxy entity through the third key request message, and the third key request message instructs the third entity to obtain the authorization result parameters and the subscriber identifier of the user equipment. The third entity can further send the authorization result parameters to the first proxy entity through the third key response message.

[0224] Furthermore, the third key request message may include authorization instruction parameters, and the authorization instruction parameters instruct the third entity to determine whether the user equipment and the target entity have the second communication authority based on the third key request message. Similarly, the third key response message may include authorization instruction parameters.

[0225] Furthermore, when it is determined that the target entity has the authority to obtain the subscriber identifier, the third entity can send, through the third key response message, the authorization result parameters and the second subscriber identifier corresponding to the user equipment to the first proxy entity.

[0226] Exemplarily, when it is determined that the target entity has the authority to obtain the subscriber identifier, the third entity sends, through the third key response message, the authorization result parameters and the second subscriber identifier corresponding to the user equipment to the first proxy entity. For example, obtain the second subscriber identifier corresponding to the user equipment, and send the second subscriber identifier and the authorization result parameters to the first proxy entity through the third key response message.

[0227] Exemplarily, the second subscriber identifier may include a subscription permanent identifier (SUPI) corresponding to the user equipment.

[0228] In some other embodiments, the third entity can receive the third authorization request parameters sent from the first proxy entity through the fourth key request message, and the fourth key request message instructs the third entity to obtain the authorization result parameters. The third entity can also send the authorization result parameters to the first proxy entity through the fourth key response message.

[0229] Furthermore, the fourth key request message may further include an authorization instruction parameter, and the authorization instruction parameter instructs the third entity to determine whether the user equipment and the target entity have the second communication authority based on the third key request message. Similarly, the fourth key response message may include an authorization instruction parameter for indicating that the fourth key response message is a response to the fourth key request message.

[0230] In some embodiments, the authorization result parameter indicates authorization success or authorization failure. Exemplarily, the third entity can determine the possible value of the authorization result parameter based on whether the user equipment and the target entity have the second communication authority. For example, if the third entity determines that the user equipment and the target entity have the second communication authority, the authorization result parameter can be set to authorization success (e.g., 1), and if it is determined that the user equipment and the target entity do not have the second communication authority, the possible value of the authorization result parameter can be set to authorization failure (e.g., 0).

[0231] In some other embodiments, the third entity can indicate that the user equipment and the target entity do not have the second communication authority by ensuring that the authorization result information is not included in the key response message (for example, the third key response message or the fourth key response message). For example, when it is determined that the user equipment and the target entity do not have the second communication authority, the third entity can ensure that the authorization result information is not included in the key response message. In contrast, when it is determined that the user equipment and the target entity have the second communication authority, the third entity can ensure that the authorization result information is included in the key response message.

[0232] FIG. 10 is an authentication method shown in an exemplary embodiment and is applicable to the first entity. As shown in FIG. 10, the method may further include the following S1001 to S1002.

[0233] S1001. The first entity obtains the authentication result of the user equipment by the first proxy entity.

[0234] S1002. The first entity communicates with the user equipment based on the authentication result.

[0235] The authentication result includes a first authentication result or a second authentication result. The first authentication result indicates that the user equipment and the target entity have the first communication authority. The second authentication result indicates that the user equipment and the target entity have the second communication authority. The target entity is an entity that requests communication determined by the user equipment from one or more first entities. The first entity includes an entity that provides an application function. The first proxy entity includes a reliable entity that provides an authentication function within the 3GPP operator domain. The first proxy entity provides an authentication proxy function to the first entity.

[0236] Note that the first entity may wait for the user equipment to initiate communication. The first entity may also initiate communication with the user equipment autonomously, and the present disclosure is not limited thereto.

[0237] In some embodiments, the authentication result notification message includes a first subscriber identifier of the user equipment. The first subscriber identifier may be an identifier for representing the user equipment outside the 3GPP operator domain. Exemplarily, the first subscriber identifier is a general public subscription identifier (GPSI) corresponding to the user equipment.

[0238] When the target entity is a reliable entity that provides an application function within the 3GPP operator domain, the target entity can receive a first notification message including a first authentication result sent from the first proxy entity, or can receive a third notification message including a second authentication result sent from the first proxy entity.

[0239] Furthermore, the first notification message or the third notification message may further include a second subscriber identifier corresponding to the user equipment. The second subscriber identifier may include a subscription permanent identifier (SUPI) corresponding to the user equipment.

[0240] If the target entity is an untrusted entity that provides application functions outside the 3GPP operator domain, the target entity can receive a fifth notification message sent from a second entity. Here, the fifth notification message includes a first authentication result, and the fifth notification message is a message sent in response to the second entity receiving the second notification message, or receives a sixth notification message sent from the second entity. Here, the sixth notification message includes a second authentication result, and the sixth notification message is a message sent in response to the second entity receiving the fourth notification message.

[0241] Furthermore, the fifth notification message or the sixth notification message may further include a first subscriber identifier of the user equipment. The first subscriber identifier may be a general public subscription identifier (GPSI) corresponding to the user equipment.

[0242] In some embodiments, the first proxy entity may include a trusted authentication proxy (AP) entity within the 3GPP operator domain.

[0243] In some embodiments, the first entity may include a trusted application function (AF) entity within the 3GPP operator domain, or a trusted application server (SCS / AS) entity within the 3GPP operator domain, or an untrusted application function (AF) entity outside the 3GPP operator domain, or an untrusted application server (SCS / AS) entity outside the 3GPP operator domain.

[0244] In some embodiments, the second entity may include a network exposure function (NEF) entity or a service capability exposure function (SCEF) entity.

[0245] In this way, based on the authentication result notification message of the first proxy entity, the first entity can determine whether the user equipment has the first communication authority with the first entity, thereby reducing the load of the first entity and improving the efficiency of the first entity.

[0246] FIG. 11 shows an authentication method illustrated in an exemplary embodiment and is applicable to a second entity. As shown in FIG. 11, the method may include the following S1101 to S1102.

[0247] S1101, the second entity obtains the authentication result of the user equipment by the first proxy entity.

[0248] The authentication result includes a first authentication result or a second authentication result. The first authentication result indicates that the user equipment and the target entity have the first communication authority. The second authentication result indicates that the user equipment and the target entity have the second communication authority. The target entity is an entity determined from one or more first entities by the user equipment to request communication. The first entity includes an untrusted entity that provides application functions outside the 3GPP operator domain. The first proxy entity includes a trusted entity that provides an authentication function within the 3GPP operator domain. The first proxy entity provides an authentication proxy function for the first entity.

[0249] S1102, the second entity sends the authentication result to the target entity.

[0250] Thereby, the target entity communicates with the user equipment based on the authentication result.

[0251] Using the above method, communication between a first proxy entity within the 3GPP operator domain and a first entity outside the 3GPP operator domain can be realized through the second entity.

[0252] In some embodiments, the second entity may include a Network Exposure Function (NEF) entity or a Service Capability Exposure Function (SCEF) entity, the first proxy entity may include a Trusted Authentication Proxy (AP) entity within the 3GPP operator domain, and the first entity may include an Untrusted Application Function (AF) entity outside the 3GPP operator domain, or an Untrusted Application Server (SCS / AS) entity outside the 3GPP operator domain.

[0253] In some embodiments, the second entity can receive a second notification message sent from the first proxy entity, obtain a first authentication result based on the second notification message, and send a fifth notification message to the first entity based on the first authentication result. Here, the second notification message is a message sent by the first proxy entity to the second entity based on the first authentication result when the target entity is an untrusted entity that provides an application function outside the 3GPP operator domain.

[0254] Furthermore, when a second subscriber identifier corresponding to a user equipment improvement is included in the second notification message, the second entity can obtain a first subscriber identifier corresponding to the user equipment improvement based on the second subscriber identifier, and send a fifth notification message to the first entity based on the first authentication result and the first subscriber identifier.

[0255] In some other embodiments, the second entity may receive a fourth notification message sent from the first proxy entity, obtain a second authentication result based on the second notification message, and send a sixth notification message to the first entity based on the second authentication result. Here, when the target entity is an untrusted entity that provides application functions outside the 3GPP operator domain, the fourth notification message may be a message sent by the first proxy entity to the second entity based on the second authentication result.

[0256] Furthermore, when the fourth notification message includes a second subscriber identifier corresponding to the user equipment, the second entity may obtain a first subscriber identifier corresponding to the user equipment based on the second subscriber identifier, and send a sixth notification message to the first entity based on the second authentication result and the first subscriber identifier.

[0257] In some embodiments, the second subscriber identifier may be an identifier for representing the user equipment within the 3GPP operator domain, and the first subscriber identifier may be an identifier for representing the user equipment outside the 3GPP operator domain. Exemplarily, the second subscriber identifier may be a subscription permanent identifier (SUPI) corresponding to the user equipment, and the first subscriber identifier may be a generic public subscription identifier (GPSI) corresponding to the user equipment.

[0258] The second entity can determine a first subscriber identifier corresponding to the second subscriber identifier based on a pre-set correspondence relationship of identifiers, and the pre-set correspondence relationship of identifiers may include the correspondence relationship between the second subscriber identifier and the first subscriber identifier.

[0259] FIG. 12 is an authentication method shown in an exemplary embodiment. As shown in FIG. 12, the method may include the following steps S1201 to 1213.

[0260] S1201. The user equipment sends an application session establishment request message to the first proxy entity.

[0261] Exemplarily, the application session establishment request message may include a first permission request parameter, and the first permission request parameter may include a key identifier (A-KID) of the user equipment and a first target entity identifier Target AF ID of the target entity. The target entity may be an entity that requests communication determined from one or more first entities by the user equipment.

[0262] In some embodiments, the user equipment can obtain a key identifier (A-KID) based on a pre-set functional entity in the communication system, and the pre-set functional entity may include an authentication server function AUSF (Authentication Server Function) entity.

[0263] S1202. In response to receiving the application session establishment request message, the first proxy entity sends a second permission request parameter to the third entity.

[0264] In some embodiments, the first proxy entity can receive an application session establishment request message sent from the user equipment, and determine a second authorization parameter based on the first authorization parameter in the application session establishment request message.

[0265] Exemplarily, when the first authorization parameter includes the key identifier (A-KID) of the user equipment and the first target entity identifier Target AF ID of the target entity, it can be determined that the second authorization parameter includes the key identifier (A-KID), the first target entity identifier Target AF ID, and the proxy entity identifier of the first proxy entity.

[0266] In some embodiments, the first proxy entity can send the second authorization parameter to the third entity through a first key request message, and the first key request message instructs the third entity to obtain the first pending key information and the subscriber identifier of the user equipment. Exemplarily, the first key request message may be a Naanf_AKMA_ApplicationKey_Get Request message.

[0267] In some other embodiments, the first proxy entity can send the second authorization parameter to the third entity through a second key request message, and the second key request message indicates that the first proxy entity requests to obtain the first pending key information. Exemplarily, the second key request message may be a Naanf_AKMA_ApplicationKey_AnonUser_Get Request message.

[0268] S1203. When the third entity determines that the user equipment and the target entity have the first communication authority based on the second authorization parameter, the third entity obtains the first pending key information.

[0269] Based on a preset permission policy, the third entity can determine whether the user equipment and the target entity have the first communication permission by authenticating the communication permission between the user equipment and the target entity. Exemplarily, In some embodiments, the manner in which the third entity determines whether the user equipment and the target entity have the first communication permission includes one or more of the following manners. Manner 1: Determine whether the user equipment has access permission to the target entity based on the key identifier (A-KID) and the first target entity identifier. Manner 2: Determine whether the user equipment has access permission to the first proxy entity based on the key identifier (A-KID) and the proxy entity identifier. Manner 3: Determine whether the first proxy entity has proxy permission for the target entity based on the proxy entity identifier and the first target entity identifier. Manner 4: Determine whether the target entity has the acquisition permission for the subscriber identifier of the user equipment based on the key identifier (A-KID) and the first target entity identifier. Manner 5: Determine whether the user equipment has the permission to use AKMA based on the key identifier (A-KID).

[0270] In some other embodiments, when it is determined that the user equipment has access rights to both the target entity and the first proxy entity has proxy rights to the target entity, the third entity may determine that the user equipment and the target entity have the first communication right. Exemplarily, the third entity can determine whether the user equipment and the target entity have the first communication right through the following steps S11 to S13.

[0271] S11. Determine whether the first proxy entity has proxy rights to the target entity based on the proxy entity identifier and the first target entity identifier.

[0272] If it is determined that the first proxy entity does not have proxy rights to the target entity, directly determine that the user equipment and the target entity do not have the first communication right, and do not execute step S12. In contrast, if it is determined that the first proxy entity has proxy rights to the target entity, continue to execute step S12.

[0273] S12. Determine whether the user equipment has access rights to the target entity based on the key identifier (A-KID) and the first target entity identifier.

[0274] If it is determined that the user equipment does not have access rights to the target entity, directly determine that the user equipment and the target entity do not have the first communication right, and do not execute step S13. In contrast, if it is determined that the user equipment has access rights to the target entity, continue to execute step S13.

[0275] S13. Determine whether the user equipment has the right to use the AKMA based on the key identifier (A-KID).

[0276] If it is determined that the user equipment has the right to use the AKMA, it can be determined that the user equipment and the target entity have the first communication right. In contrast, if it is determined that the user equipment does not have the right to use the AKMA, it can be determined that the user equipment and the target entity do not have the first communication right.

[0277] Note that the first pending key information may include entity key information corresponding to the target entity.

[0278] In some embodiments, the entity key information corresponding to the target entity may include the application key K corresponding to the target entity. AF may be included.

[0279] In some other embodiments, the entity key information corresponding to the target entity may include the application key K corresponding to the target entity. AF and the key expiration time K AF expiration time may be included.

[0280] S1204. The third entity sends the first pending key information to the first proxy entity.

[0281] In some embodiments, the third entity can send the first pending key information to the first proxy entity through the first key response message. Exemplarily, the first key response message may be a Naanf_AKMA_ApplicationKey_Get Response message.

[0282] In some other embodiments, the third entity can send the first pending key information to the first proxy entity through the second key response message. Exemplarily, the second key response message may be a Naanf_AKMA_ApplicationKey_AnonUser_Get Response message.

[0283] In some embodiments, the first key response message may further include a second subscriber identifier of the user equipment, and the second subscriber identifier may be an identifier for representing the user equipment within the 3GPP operator domain. Exemplarily, the second subscriber identifier may be a subscription permanent identifier (SUPI) corresponding to the user equipment.

[0284] S1205. The first proxy entity sends an application session establishment response message to the user equipment.

[0285] When the first proxy entity obtains the application key K in the first key response message, it can determine that the user equipment and the target entity have the first communication authority. At this time, the first proxy entity can send an application session establishment response message to the user equipment. AF When the first proxy entity obtains the application key K in the first key response message, it can determine that the user equipment and the target entity have the first communication authority. At this time, the first proxy entity can send an application session establishment response message to the user equipment.

[0286] S1206. The user equipment authenticates the user equipment by the first proxy entity.

[0287] When it is determined that the user equipment and the target entity have the first communication authority, the user equipment can authenticate the user equipment by the first proxy entity. Exemplarily, the user equipment can, based on the FQDN of the target entity, Application key K AFcan be driven, and the Application key K AF and the first proxy entity perform user equipment authentication.

[0288] S1207a, the first proxy entity notifies the target entity of the first authentication result.

[0289] The first authentication result may indicate that the target entity and the user equipment have communication authority.

[0290] In some embodiments, when the target entity is a reliable entity that provides an application function within the 3GPP operator domain, the first proxy entity can send a first notification message to the target entity, and the first notification message may include the first authentication result. Further, when the first proxy entity obtains the second subscriber identifier of the user equipment (for example, when obtaining the second subscriber identifier through the first key response message), the first notification message may further include the second subscriber identifier.

[0291] In some other embodiments, when the target entity is an unreliable entity that provides an application function outside the 3GPP operator domain, the first proxy entity can send a second notification message to a second entity based on the first authentication result to instruct the second entity to send the first authentication result to the target entity. Similarly, when the first proxy entity obtains the second subscriber identifier of the user equipment (for example, when obtaining the second subscriber identifier through the first key response message), the second notification message may further include the second subscriber identifier.

[0292] In some embodiments, if the user equipment authentication by the first proxy entity is successful, the first proxy entity can notify the target entity of the first authentication result (execute the step S1207a and do not execute the steps S1207b and subsequent steps).

[0293] In some other embodiments, if the user equipment authentication by the first proxy entity is successful, the first proxy entity obtains the proxy domain name of the first proxy entity and the first domain name of the target entity. If the proxy domain name is different from the first domain name, by notifying the target entity of the first authentication result (execute the step S1207a and do not execute the steps S1209b and subsequent steps), the target entity and the user equipment can be instructed to have communication authority or to communicate.

[0294] In some other embodiments, if the proxy domain name is the same as the first domain name, the first proxy entity may not temporarily send an authentication result notification message to the target entity. First, it is determined whether the user equipment and the target entity have a second communication authority. After it is determined that the user equipment and the target entity have the second communication authority, the first authentication result is notified to the target entity. That is, the step S1207a is not executed, and the steps S1207b and subsequent steps are continuously executed.

[0295] S1207b, the user equipment establishes a secure session with the first proxy entity.

[0296] The secure session may include a TLS session.

[0297] S1208, the user equipment sends a target entity service request message to the first proxy entity.

[0298] Here, the target entity service request message includes a second target entity identifier, and the second target entity identifier is a protected entity identifier obtained based on the first target entity identifier of the target entity by the user equipment.

[0299] In some embodiments, the target entity service request message may include a key identifier (A-KID) and a second target entity identifier.

[0300] In some embodiments, when the second target entity identifier is the same as the first target entity identifier, it can be determined that the user equipment and the target entity have a second communication right, whereby an authentication result notification message can be sent to the target entity, and a target entity service response message can be sent to the user equipment. That is, steps S1209a and S1213 are executed, and it is not necessary to execute steps S1209b to S1212.

[0301] In some other embodiments, when the second target entity identifier is different from the first target entity identifier, the first proxy entity can interact with the key request message of the second entity to determine whether the user equipment and the target entity have a second communication right. That is, step S1209a is not executed, and steps S1209b and subsequent steps are continuously executed.

[0302] S1209a. The first proxy entity notifies the target entity of the first authentication result.

[0303] S1209b. The first proxy entity sends third authority request parameters to a third entity.

[0304] In some embodiments, the third authorization request parameter may include a key identifier (A-KID), a second target entity identifier, and a proxy entity identifier corresponding to the first proxy entity, and the third authorization request parameter may be used for the third entity to determine whether the user equipment and the target entity have the second communication authorization.

[0305] In some embodiments, the first proxy entity can send the third authorization request parameter to the third entity through a third key request message, and the third key request message instructs the third entity to obtain an authorization result parameter and a subscriber identifier of the user equipment. Exemplarily, the third key request message may be a Naanf_AKMA_ApplicationKey_Get Request message.

[0306] In some other embodiments, the first proxy entity can send the third authorization request parameter to the third entity through a fourth key request message, and the fourth key request message indicates that the first proxy entity requests to obtain an authorization result parameter. Exemplarily, the fourth key request message may be a Naanf_AKMA_ApplicationKey_AnonUser_Get Request message.

[0307] S1210. The third entity determines whether the user equipment and the target entity have the second communication authorization based on the third authorization request parameter.

[0308] Exemplarily, the method by which the third entity determines whether the user equipment and the target entity have the second communication authorization may include one or more of the following methods. Method 6: Determine whether the user equipment has access rights to the target entity based on the key identifier (A-KID) and the second target entity identifier. Method 7: Determine whether the first proxy entity has proxy rights to the target entity based on the proxy entity identifier and the second target entity identifier. Method 8: Determine whether the target entity has the right to obtain the subscriber identifier of the user equipment based on the key identifier (A-KID) and the first target entity identifier.

[0309] In some embodiments, when the third entity determines that the user equipment has access rights to the target entity and the first proxy entity has proxy rights to the target entity, the third entity can determine that the user equipment and the target entity have the second communication rights.

[0310] S1211: The third entity sends the authorization result parameter to the first proxy entity.

[0311] The authorization result parameter may be used to notify the first proxy entity whether the user equipment and the target entity have the second communication rights.

[0312] In some embodiments, the third entity can send the authorization result parameter to the first proxy entity through the third key response message. Exemplarily, the third key response message may be the Naanf_AKMA_ApplicationKey_Get Response message.

[0313] In some other embodiments, the third entity can send the authorization result parameters to the first proxy entity through a fourth key response message. Exemplarily, the fourth key response message may be a Naanf_AKMA_ApplicationKey_AnonUser_Get Response message.

[0314] In some embodiments, when the third entity determines that the target entity has the right to obtain the subscriber identifier, the second subscriber identifier of the user equipment may be included in the third key response message. Similarly, the fourth key response message may also include the second subscriber identifier of the user equipment. The second subscriber identifier may be a subscription permanent identifier (SUPI) corresponding to the user equipment.

[0315] S1212. The first proxy entity notifies the target entity of the second authentication result.

[0316] Here, the second authentication result may be used to indicate that the target entity and the user equipment have the communication right.

[0317] For example, when the target entity is a reliable entity that provides application functions within the 3GPP operator domain, the first proxy entity can send a third notification message to the target entity, and the third notification message includes the second authentication result. Further, when the first proxy entity obtains the second subscriber identifier of the user equipment (for example, obtains the second subscriber identifier through the third key response message), the third notification message may further include the second subscriber identifier.

[0318] Also, for example, if the target entity is an untrusted entity that provides application functions outside the 3GPP operator domain, the first proxy entity can send a fourth notification message to the second entity based on the first authentication result, thereby instructing the second entity to send the first authentication result to the target entity. Further, if the first proxy entity obtains the second subscriber identifier of the user equipment (for example, obtains the second subscriber identifier through the third key response message), the fourth notification message may further include the second subscriber identifier.

[0319] In some embodiments, the second subscriber identifier may be a subscription permanent identifier (SUPI) corresponding to the user equipment.

[0320] S1213. The first proxy entity sends a target entity service response message to the user equipment.

[0321] The target entity service response message is used to indicate whether the user equipment and the target entity have a second communication right.

[0322] In some embodiments, the first proxy entity may include a trusted authentication proxy (AP) entity within the 3GPP operator domain.

[0323] In some embodiments, the first entity may include a trusted application function (AF) entity within the 3GPP operator domain, or a trusted application server (SCS / AS) entity within the 3GPP operator domain, or an untrusted application function (AF) entity outside the 3GPP operator domain, or an untrusted application server (SCS / AS) entity outside the 3GPP operator domain.

[0324] In some embodiments, the second entity may include a Network Exposure Function (NEF) entity or a Service Capability Exposure Function (SCEF) entity.

[0325] In some embodiments, the third entity may include an AKMA Anchor Function (AAnF) entity.

[0326] Thus, for the first entity, a reliable first proxy entity within the 3GPP operator domain determines whether the user equipment and the first entity have communication authority. If it is determined that they have the first communication authority, the identity verification of the user equipment is performed, and some functions of the first entity can be realized by the first proxy entity, thereby reducing the load of the first entity, improving the efficiency of the first entity, and the user equipment can realize the authentication of one or more first entities and the user equipment authentication through the unified first proxy entity, reducing the complexity of authentication by the user equipment and improving the efficiency of the user equipment.

[0327] FIG. 13 is a block diagram of an authentication device 1300 shown in an exemplary embodiment, and the authentication device is applicable to user equipment. As shown in FIG. 13, the device 1300 includes a target entity determination module 1301 configured to determine a target entity that requests communication from one or more first entities, a parameter determination module 1302 configured to determine first permission request parameters based on the target entity, A first message sending module 1303 configured to send an application session establishment request message to a first proxy entity based on the first permission request parameter, where the application session establishment request message instructs the first proxy entity to determine whether the user equipment and the target entity have a first communication permission based on the first permission request parameter, the first entity includes an entity that provides an application function, the first proxy entity includes a reliable entity that provides an authentication function within a 3GPP operator domain, and the first proxy entity provides an authentication proxy function to the first entity, the first message sending module 1303; A first message receiving module 1304 configured to determine whether the user equipment and the target entity have a first communication permission in response to receiving an application session establishment response message sent from the first proxy entity; Optionally, it may further include an authentication module configured to perform user equipment authentication by the first proxy entity when the user equipment and the target entity have a first communication permission.

[0328] Optionally, the parameter determination module 1302 is configured to use the first target entity identifier of the target entity and the key identifier (A-KID) corresponding to the user equipment as the first permission request parameter.

[0329] Optionally, the first communication permission includes: The user equipment has an access permission to the target entity; The user equipment has an access permission to the first proxy entity; The first proxy entity has a proxy permission to the target entity; including one or more of: the target entity having the right to obtain the subscriber identifier of the user equipment.

[0330] FIG. 14 is a block diagram of an exemplary authentication device 1300 shown in an exemplary embodiment. As shown in FIG. 14, the device After successfully authenticating the user equipment by the first proxy entity, establish a secure session with the first proxy entity, obtain the proxy domain name of the first proxy entity and the first domain name of the target entity. If the proxy domain name and the first domain name are exactly the same, determine whether the user equipment and the target entity have the second communication right through the secure session. If it is determined that the user equipment and the target entity have the second communication right, it may further include a user communication module 1305 configured to communicate with the target entity.

[0331] Optionally, the user communication module 1305 sends a target entity service request message to the first proxy entity through the secure session. The target entity service request message includes a second target entity identifier, and the second target entity identifier is a protected entity identifier obtained based on the first target entity identifier by the user equipment. The target entity service request message instructs the first proxy entity to determine whether the user equipment and the target entity have the second communication right based on the second target entity identifier. In response to receiving the target entity service response message sent from the first proxy entity, it is configured to determine whether the user equipment and the target entity have the second communication right.

[0332] Optionally, the second communication right The user equipment has access rights to the target entity, and The first proxy entity has proxy rights to the target entity, and The target entity has the right to obtain the subscriber identifier of the user equipment, including one or more of the above.

[0333] Optionally, when the first message receiving module 1304 receives the application session establishment response message, it is configured to determine whether the user equipment and the target entity have the first communication rights, or when the application session establishment response message is received and the session establishment response message includes success indication information, it is configured to determine that the user equipment and the target entity have the first communication rights.

[0334] Optionally, the first proxy entity includes a trusted authentication proxy (AP) entity within the 3GPP operator domain.

[0335] Optionally, the first entity includes a trusted entity that provides an application function within the 3GPP operator domain.

[0336] Optionally, the first entity includes a trusted application function (AF) entity within the 3GPP operator domain, or a trusted application server (SCS / AS) entity within the 3GPP operator domain.

[0337] Optionally, the first entity includes an untrusted entity that provides an application function outside the 3GPP operator domain, the first proxy entity communicates with the first entity via a second entity, and the second entity includes an entity that provides a network exposure function.

[0338] Optionally, the first entity includes an untrusted Application Function (AF) entity outside the 3GPP operator domain, or an untrusted Application Server (SCS / AS) entity outside the 3GPP operator domain.

[0339] Optionally, the second entity includes a Network Exposure Function (NEF) entity or a Service Capability Exposure Function (SCEF) entity.

[0340] FIG. 15 is a block diagram of an exemplary authentication device 1500 shown in an exemplary embodiment, which is applicable to a first proxy entity. As shown in FIG. 15, the device 1500 includes a first proxy receiving module 1501 configured to receive an application session establishment request message sent from a user equipment, where the application session establishment request message includes a first authorization request parameter, and the application session establishment request message instructs the first proxy entity to determine whether the user equipment and a target entity have a first communication authorization based on the first authorization request parameter, the target entity is an entity that requests communication determined from one or more first entities by the user equipment, the first entity includes an entity that provides an application function, the first proxy entity includes a trusted entity that provides an authentication function within the 3GPP operator domain, and the first proxy receiving module 1501 that provides an authentication proxy function to the first entity; a first proxy determination module 1502 configured to determine whether the user equipment and the target entity have a first communication authorization based on the first authorization request parameter; When the user equipment and the target entity have a first communication right, a first proxy transmission module 1503 configured to send an application session establishment response message to the user equipment and perform user equipment authentication on the user equipment may be included.

[0341] Optionally, the first right request parameter includes a first target entity identifier of the target entity and a key identifier (A-KID) corresponding to the user equipment.

[0342] Optionally, the first communication right the user equipment having an access right to the target entity, the user equipment having an access right to the first proxy entity, the first proxy entity having a proxy right to the target entity, the target entity having an acquisition right to the subscriber identifier of the user equipment, includes one or more of them.

[0343] Optionally, the first proxy determination module 1502 determines second permission request parameters based on the first permission request parameters, sends the second permission request parameters to a third entity, the third entity includes an entity that provides AKMA authorization and an application key derivation function, the second permission request parameters instruct the third entity to determine whether the user equipment and the target entity have a first communication permission, obtains first pending key information sent from the third entity, the first pending key information is key information obtained by the third entity based on the second permission request parameters, and is configured to determine whether the user equipment and the target entity have a first communication permission based on the first pending key information.

[0344] Optionally, the first proxy determination module 1502 is configured to use the first permission request parameters and a proxy entity identifier corresponding to the first proxy entity as the second permission request parameters.

[0345] Optionally, the first proxy determination module 1502 sends the second permission request parameters to a third entity through a first key request message, the first key request message instructs the third entity to obtain first pending key information and a subscriber identifier of the user equipment, receives a first key response message sent from the third entity, and is configured to obtain the first pending key information included in the first key response message.

[0346] Optionally, the first key response message further includes a second subscriber identifier corresponding to the user equipment, and the first proxy determination module 1502 is configured to obtain the second subscriber identifier based on the received first key response message.

[0347] Optionally, the second subscriber identifier includes a subscription permanent identifier (SUPI) corresponding to the user equipment.

[0348] Optionally, the first proxy determination module 1502 transmits the second authorization request parameter to a third entity through a second key request message, where the second key request message indicates that the first proxy entity requests to obtain the first pending key information, receives a second key response message sent from the third entity, and is configured to obtain the first pending key information included in the second key response message.

[0349] Optionally, when the first pending key information includes entity key information corresponding to the target entity, the first proxy determination module 1502 determines that the user equipment and the target entity have a first communication authorization.

[0350] Optionally, when the user equipment authentication for the user equipment is successful, the first proxy transmission module 1503 is configured to notify the target entity of the first authentication result of the user equipment authentication.

[0351] Optionally, the first proxy transmission module 1503 obtains the proxy domain name of the first proxy entity and the first domain name of the target entity, and when the proxy domain name is different from the first domain name, is configured to notify the target entity of the first authentication result.

[0352] Optionally, when the target entity is a reliable entity that provides an application function within a 3GPP operator domain, the first proxy transmission module 1503 is configured to transmit a first notification message including the first authentication result to the target entity.

[0353] Optionally, when the second subscriber identifier of the user equipment is obtained by the first proxy entity, the first notification message further includes the second subscriber identifier.

[0354] Optionally, when the target entity is an untrusted entity that provides an application function outside the 3GPP operator domain, the first proxy transmission module 1503 is configured to instruct the second entity to transmit the first authentication result to the target entity by transmitting a second notification message to the second entity based on the first authentication result.

[0355] Optionally, when the second subscriber identifier of the user equipment is obtained by the first proxy entity, the second notification message further includes the second subscriber identifier.

[0356] Optionally, after successfully authenticating the user equipment for the user equipment, the device further includes the following.

[0357] FIG. 16 is a block diagram of an authentication device 1500 shown in an exemplary embodiment. As shown in FIG. 16, the device may further include a first proxy communication module 1504. The first proxy communication module 1504 establishes a secure session with the user equipment, receives, via the secure session, a target entity service request message sent from the user equipment, where the target entity service request message includes a second target entity identifier, and the second target entity identifier is a protected entity identifier obtained by the user equipment based on a first target entity identifier of the target entity, and the target entity service request message is a message sent when the user equipment determines that a proxy domain name of the first proxy entity is the same as a first domain name of the target entity, determines whether the user equipment and the target entity have a second communication authority based on the second target entity identifier, and is configured to send a target entity service response message for instructing whether the user equipment and the target entity have the second communication authority to the user equipment.

[0358] Optionally, the second communication authority includes the user equipment having access authority to the target entity, the first proxy entity having proxy authority to the target entity, and / or the target entity having acquisition authority to a subscriber identifier of the user equipment.

[0359] Optionally, when the second target entity identifier is the same as the first target entity identifier, the first proxy communication module 1504 is configured to determine that the user equipment and the target entity have the second communication authority.

[0360] Optionally, when the second target entity identifier is different from the first target entity identifier, the first proxy communication module 1504 determines a third permission request parameter based on the second target entity identifier, and transmits the third permission request parameter for instructing the third entity to determine whether the third entity, the user equipment, and the target entity have a second communication permission to the third entity, obtains an authorization result parameter transmitted from the third entity, the authorization result parameter indicates whether the user equipment and the target entity have a second communication permission, and is configured to determine whether the user equipment and the target entity have a second communication permission based on the authorization result parameter.

[0361] Optionally, the first proxy communication module 1504 is configured to use the second target entity identifier, the key identifier (A-KID) corresponding to the user equipment, and the proxy entity identifier corresponding to the first proxy entity as the third permission request parameter.

[0362] Optionally, the first proxy communication module 1504 transmits the third permission request parameter to the third entity through a third key request message for instructing the third entity to obtain an authorization result parameter and a subscriber identifier of the user equipment, receives a third key response message transmitted from the third entity, and is configured to obtain the authorization result parameter included in the third key response message.

[0363] Optionally, the third key response message further includes a second subscriber identifier corresponding to the user equipment, and the first proxy communication module 1504 is configured to obtain the second subscriber identifier based on the received third key response message.

[0364] Optionally, the third key request message further includes an authorization instruction parameter, and the authorization instruction parameter instructs the third entity to determine whether the user equipment and the target entity have a second communication authority based on the third key request message.

[0365] Optionally, the first proxy communication module 1504 is configured to transmit the third authority request parameter to a third entity through a fourth key request message for representing that the first proxy entity requests to obtain the authorization result parameter, receive a fourth key response message sent from the third entity, and obtain the authorization result parameter included in the fourth key response message.

[0366] Optionally, the fourth key request message further includes an authorization instruction parameter, and the authorization instruction parameter instructs the third entity to determine whether the user equipment and the target entity have a second communication authority based on the fourth key request message.

[0367] Optionally, when it is determined based on the authorization result parameter that the user equipment and the target entity have a second communication authority, the first proxy communication module 1504 is configured to notify the target entity of a second authentication result for instructing that the target entity and the user equipment have a communication authority.

[0368] Optionally, when the target entity is a reliable entity that provides an application function within a 3GPP operator domain, the first proxy communication module 1504 is configured to send a third notification message including the second authentication result to the target entity.

[0369] Optionally, when the second subscriber identifier of the user equipment is obtained by the first proxy entity, the third notification message further includes the second subscriber identifier.

[0370] Optionally, when the target entity is an untrusted entity that provides an application function outside the 3GPP operator domain, the first proxy communication module 1504 is configured to instruct the second entity to send the first authentication result to the target entity by sending a fourth notification message to the second entity based on the first authentication result.

[0371] Optionally, when the second subscriber identifier of the user equipment is obtained by the first proxy entity, the fourth notification message further includes the second subscriber identifier.

[0372] Optionally, the first pending key information includes the application key K AF and the key validity period.

[0373] Optionally, the second entity includes a network exposure function (NEF) entity or a service capability exposure function (SCEF) entity.

[0374] Optionally, the first proxy entity includes a trusted authentication proxy (AP) entity within the 3GPP operator domain.

[0375] Optionally, the first entity includes a reliable Application Function (AF) entity within the 3GPP operator domain, or a reliable Application Server (SCS / AS) entity within the 3GPP operator domain, or an unreliable Application Function (AF) entity outside the 3GPP operator domain, or an unreliable Application Server (SCS / AS) entity outside the 3GPP operator domain.

[0376] FIG. 17 is a block diagram of an exemplary authentication device 1700 shown in an exemplary embodiment, which is applicable to a second entity. As shown in FIG. 17, the device 1700 includes a second receiving module 1701 configured to obtain an authentication result of user equipment by a first proxy entity, where the authentication result includes a first authentication result or a second authentication result, the first authentication result indicates that the user equipment and a target entity have a first communication right, the second authentication result indicates that the user equipment and the target entity have a second communication right, the target entity is an entity that requests communication determined by the user equipment from one or more first entities, the first entity includes an unreliable entity that provides an application function outside the 3GPP operator domain, the first proxy entity includes a reliable entity that provides an authentication function within the 3GPP operator domain, and the second receiving module 1701 where the first proxy entity provides an authentication proxy function to the first entity, and a second transmitting module 1702 configured to transmit the authentication result to the target entity so that the target entity communicates with the user equipment based on the authentication result.

[0377] Optionally, the second receiving module 1701 receives a second notification message sent from the first proxy entity, where the second notification message is a message sent by the first proxy entity to the second entity based on the first authentication result when the target entity is an untrusted entity providing application functions outside the 3GPP operator domain, and is configured to obtain the first authentication result based on the second notification message. The second transmitting module 1702 is configured to transmit a fifth notification message to the target entity based on the first authentication result.

[0378] Optionally, when a second subscriber identifier corresponding to the user equipment is included in the second notification message, the second transmitting module 1702 obtains a first subscriber identifier corresponding to the user equipment based on the second subscriber identifier, and is configured to transmit a fifth notification message to the target entity based on the first authentication result and the first subscriber identifier.

[0379] Optionally, the first subscriber identifier is a general public subscription identifier (GPSI) corresponding to the user equipment, and the second subscriber identifier includes a subscription permanent identifier (SUPI) corresponding to the user equipment.

[0380] Optionally, the second receiving module 1701 receives a fourth notification message sent from the first proxy entity, where the fourth notification message is a message sent by the first proxy entity to the second entity based on the second authentication result when the target entity is an untrusted entity providing application functions outside the 3GPP operator domain, and is configured to obtain the second authentication result based on the second notification message. The second transmission module 1702 is configured to transmit a sixth notification message to the target entity based on the second authentication result.

[0381] Optionally, when a second subscriber identifier corresponding to the user equipment is included in the fourth notification message, the second transmission module 1702 obtains a first subscriber identifier corresponding to the user equipment based on the second subscriber identifier, and transmits a sixth notification message to the target entity based on the second authentication result and the first subscriber identifier.

[0382] Optionally, the second entity includes a network exposure function (NEF) entity or a service capability exposure function (SCEF) entity.

[0383] FIG. 18 is a block diagram of an authentication device 1800 shown in an exemplary embodiment, and the authentication device is applicable to a third entity. As shown in FIG. 18, the device 1800 includes a third receiving module 1801 configured to receive second authorization request parameters transmitted from a first proxy entity, where the second authorization request parameters instruct the third entity to determine whether the user equipment and the target entity have a first communication authorization, the target entity is an entity that requests communication determined by the user equipment from one or more first entities, the first entities include entities that provide application functions, the first proxy entity includes a reliable entity that provides an authentication function within a 3GPP operator domain, the first proxy entity provides an authentication proxy function to the first entity, and the third entity includes an entity that provides an AKMA authorization and an application key derivation function; the third receiving module 1801 A third determination module 1802 configured to determine whether the user equipment and the target entity have a first communication right based on the second right requirement parameter; A third key module 1803 configured to obtain first pending key information when the user equipment and the target entity have the first communication right; It may include a third transmission module 1804 configured to transmit the first pending key information to the first proxy entity.

[0384] Optionally, the second right requirement parameter includes a key identifier (A-KID) corresponding to the user equipment, a first target entity identifier of the target entity, and a proxy entity identifier corresponding to the first proxy entity, and the third determination module 1802 Determine whether the user equipment has access rights to the target entity based on the key identifier (A-KID) and the first target entity identifier; Determine whether the user equipment has access rights to the first proxy entity based on the key identifier (A-KID) and the proxy entity identifier; Based on the proxy entity identifier and the first target entity identifier, determine whether the first proxy entity has proxy rights to the target entity, and one or more of It is configured to determine whether the user equipment and the target entity have the first communication right.

[0385] Optionally, the third key module 1803 It is configured to obtain the first pending key information based on the entity key information corresponding to the target entity.

[0386] Optionally, the third receiving module 1801 is configured to receive the second permission request parameter transmitted from the first proxy entity through a first key request message, and the first key request message instructs the third entity to obtain first pending key information and a subscriber identifier of the user equipment, The third transmitting module 1804 is configured to transmit the first pending key information to the first proxy entity through a first key response message.

[0387] Optionally, when it is determined that the target entity has the right to obtain a subscriber identifier, the third transmitting module 1804 is configured to transmit, through a first key response message, the first pending key information and a second subscriber identifier corresponding to the user equipment to the first proxy entity.

[0388] Optionally, the second subscriber identifier is a subscription permanent identifier (SUPI) corresponding to the user equipment.

[0389] Optionally, the third receiving module 1801 is configured to receive the second permission request parameter transmitted from the first proxy entity through a second key request message for instructing the third entity to obtain the first pending key information, The third transmitting module 1804 is configured to transmit the first pending key information to the first proxy entity through a second key response message.

[0390] Optionally, after the third decision module 1802 transmits the first pending key information to the first proxy entity, it receives third authorization request parameters transmitted from the first proxy entity, and determines whether the user equipment and the target entity have a second communication authorization based on the third authorization request parameters, and is configured to transmit authorization result parameters for notifying the first proxy entity whether the user equipment and the target entity have a second communication authorization to the first proxy entity.

[0391] Optionally, the third authorization request parameters include the key identifier (A-KID), a second target entity identifier, and a proxy entity identifier corresponding to the first proxy entity. The second target entity identifier is a protected entity identifier obtained based on the first target entity identifier of the target entity by the user equipment, and the third decision module 1802 determines whether the user equipment has an access right to the target entity based on the key identifier (A-KID) and the second target entity identifier, and determines whether the first proxy entity has a proxy right to the target entity based on the proxy entity identifier and the second target entity identifier, and is configured to determine whether the user equipment and the target entity have a second communication authorization by one or more of the above. is configured to determine whether the user equipment and the target entity have a second communication authorization.

[0392] Optionally, the third determination module 1802 is configured to receive the third authorization request parameter transmitted from the first proxy entity through a third key request message for instructing the third entity to obtain an authorization result parameter and a subscriber identifier of the user equipment, and to transmit the authorization result parameter to the first proxy entity through a third key response message.

[0393] Optionally, the third key request message further includes an authorization instruction parameter, and the authorization instruction parameter instructs the third entity to determine whether the user equipment and the target entity have a second communication authorization based on the third key request message.

[0394] Optionally, when it is determined that the target entity has the right to obtain a subscriber identifier, the third determination module 1802 transmits, through a third key response message, an authorization result parameter and a second subscriber identifier corresponding to the user equipment to the first proxy entity.

[0395] Optionally, the second subscriber identifier is a subscription permanent identifier (SUPI) corresponding to the user equipment.

[0396] Optionally, the third determination module 1802 is configured to receive the third authorization request parameter transmitted from the first proxy entity through a fourth key request message for instructing the third entity to obtain an authorization result parameter, and to transmit the authorization result parameter to the first proxy entity through a fourth key response message.

[0397] Optionally, the third determination module 1802 determines whether the third entity has the authority to provide services to the first proxy entity based on a first preset policy, and if the third entity has the authority to provide services to the first proxy entity, based on the third authority request parameter, determines whether the user equipment and the target entity have a second communication authority.

[0398] Optionally, the third determination module 1802 determines whether the third entity has the authority to provide services to the first proxy entity based on a first preset policy, and if the third entity has the authority to provide services to the first proxy entity, based on the second authority request parameter, determines whether the user equipment and the target entity have a first communication authority.

[0399] Optionally, the first proxy entity includes a reliable authentication proxy (AP) entity within the 3GPP operator domain, and the third entity includes an AKMA anchor function (AAnF) entity.

[0400] Optionally, the first entity includes a reliable application function (AF) entity within the 3GPP operator domain, or a reliable application server (SCS / AS) entity within the 3GPP operator domain, or an unreliable application function (AF) entity outside the 3GPP operator domain, or an unreliable application server (SCS / AS) entity outside the 3GPP operator domain.

[0401] FIG. 19 is a block diagram of an authentication device 1900 shown in an exemplary embodiment, which is applicable to a first entity. As shown in FIG. 19, the device 1900 may include a first communication module 1901. The first communication module 1901 obtains the authentication result of the user equipment by the first proxy entity, the authentication result includes a first authentication result or a second authentication result, the first authentication result indicates that the user equipment and the target entity have a first communication right, the second authentication result indicates that the user equipment and the target entity have a second communication right, the first entity includes an entity that provides an application function, the target entity is an entity that requests communication determined from one or more first entities by the user equipment, the first proxy entity includes a reliable entity that provides an authentication function within the 3GPP operator domain, the first proxy entity provides an authentication proxy function to the first entity, and is configured to communicate with the user equipment based on the authentication result.

[0402] Optionally, when the target entity is a reliable entity that provides an application function within the 3GPP operator domain, the first communication module 1901 is configured to receive a first notification message including the first authentication result sent from the first proxy entity, or to receive a third notification message including the second authentication result sent from the first proxy entity.

[0403] Optionally, the first notification message or the third notification message further includes a second subscriber identifier corresponding to the user equipment.

[0404] Optionally, the second subscriber identifier includes a subscription permanent identifier (SUPI) corresponding to the user equipment.

[0405] Optionally, if the target entity is an untrusted entity that provides application functions outside the 3GPP operator domain, the first communication module 1901 is configured to receive a fifth notification message sent from the second entity, where the fifth notification message includes the first authentication result, and the fifth notification message is a message sent in response to the second entity receiving the second notification message, or is configured to receive a sixth notification message sent from the second entity, where the sixth notification message includes the second authentication result, and the sixth notification message is a message sent in response to the second entity receiving the fourth notification message.

[0406] Optionally, the fifth notification message or the sixth notification message further includes a first subscriber identifier of the user equipment.

[0407] Optionally, the first subscriber identifier is a general public subscription identifier (GPSI) corresponding to the user equipment.

[0408] Optionally, the first proxy entity includes a trusted authentication proxy (AP) entity within the 3GPP operator domain.

[0409] Optionally, the first entity includes a trusted application function (AF) entity within the 3GPP operator domain, or a trusted application server (SCS / AS) entity within the 3GPP operator domain, or an untrusted application function (AF) entity outside the 3GPP operator domain, or an untrusted application server (SCS / AS) entity outside the 3GPP operator domain.

[0410] Regarding the device in the above embodiments, the specific manner in which each module executes operations has been described in detail in the embodiments related to the method, and detailed description is omitted here.

[0411] FIG. 20 is a block diagram of an authentication device shown in an exemplary embodiment. Exemplarily, the authentication device 2000 may be a terminal device such as a mobile phone, a computer, a digital broadcast terminal, a message transceiver device, a game console, a tablet device, a medical device, a fitness device, a personal digital assistant, etc., and the authentication device 200 may be a server such as a local server or a cloud server, etc., and the authentication device 2000 may be the user equipment shown in FIG. 1, and the authentication device 2000 may be any one of the network entities in the communication system shown in FIG. 1, such as the first entity, the first proxy entity, the second entity, or the third entity.

[0412] Referring to FIG. 20, the device 2000 includes one or more components of a processing component 2002, a memory 2004, and a communication component 2006.

[0413] The processing component 2002 generally controls all operations of the device 2000, such as operations related to display, phone calls, data communication, camera operations, and recording operations. The processing component 2002 can include one or more processors 2020 for executing instructions to complete all or some of the steps of the above method. Also, the processing component 2002 can include one or more modules to facilitate the interaction between the processing component 2002 and other components. For example, the processing component 2002 can include a multimedia module to facilitate the interaction between the multimedia component and the processing component 2002.

[0414] Memory 2004 is configured to store various types of data to support operations on device 2000. Examples of these data include instructions of any application program or method operated on device 2000, contact data, phone book data, SMS messages, photos, videos, etc. Memory 2004 can be implemented by any type of volatile or non-volatile storage device such as static random access memory (SRAM), electrically erasable programmable read-only memory (EEPROM), erasable programmable read-only memory (EPROM), programmable read-only memory (PROM), read-only memory (ROM), magnetic memory, flash memory, magnetic disk or optical disk, or a combination thereof.

[0415] Communication component 2006 is configured to facilitate wired or wireless communication between device 2000 and other devices. Device 2000 can access a wireless network based on a communication standard, such as WiFi, 2G or 3G, or a combination thereof. In an exemplary embodiment, communication component 2006 receives a broadcast signal or broadcast-related information from an external broadcast management system via a broadcast channel. In an exemplary embodiment, the communication component 2006 further includes a near field communication (NFC) module to facilitate short-range communication. For example, the NFC module can be implemented by radio frequency identification (RFID) technology, infrared data association (IrDA) technology, ultra-wideband (UWB) technology, Bluetooth (BT) technology and other technologies.

[0416] In an exemplary embodiment, device 2000 can be implemented by one or more application specific integrated circuits (ASICs), digital signal processors (DSPs), digital signal processing devices (DSPDs), programmable logic devices (PLDs), field programmable gate arrays (FPGAs), controllers, microcontrollers, microprocessors, or other electronic components, by one or more applications to execute the above method.

[0417] In addition to being an independent electronic device, the above device 2000 may also be a part of an independent electronic device. For example, in one embodiment, the electronic device may be an integrated circuit (IC) or a chip. The integrated circuit may be a single IC or a combination of multiple ICs. The chip may include, but is not limited to, a GPU (Graphics Processing Unit), a CPU (Central Processing Unit), an FPGA (Field Programmable Gate Array), a DSP (Digital Signal Processor), an ASIC (Application Specific Integrated Circuit), an SOC (System on Chip or System Level Chip), etc. In the above integrated circuit or chip, the above authentication method can be realized by executing executable instructions (or code). Here, the executable instructions can be stored in the integrated circuit or chip, or can be obtained from other devices or devices. For example, the integrated circuit or chip includes a processor, a memory, and an interface for communicating with other devices. The executable instructions can be stored in the processor. When the executable instructions are executed by the processor, the above authentication method is realized. Or, the integrated circuit or chip can realize the above authentication method by receiving executable instructions via the interface and transmitting them to the processor for execution.

[0418] In an exemplary embodiment, a non-transitory computer-readable storage medium containing instructions, such as a memory 2004 containing instructions, is provided, and the above instructions can be executed by a processor 2020 of a terminal 2000 to complete the above method. For example, the non-transitory computer-readable storage medium may be a ROM, a random access memory (RAM), a CD-ROM, a magnetic tape, a floppy disk, an optical data storage device, etc.

[0419] In another exemplary embodiment, a computer program product is further provided, and the computer program product includes a computer program executable by a programmable device, and the computer program has a code portion for executing the above authentication method when executed by the programmable device.

[0420] After considering the specification and practicing the invention disclosed herein, those skilled in the art can easily conceive of other embodiments of the present disclosure. The present disclosure aims to cover any modifications, uses, or adaptations of the present disclosure, and these modifications, uses, or adaptations follow the general principles of the present disclosure and include common general knowledge in the technical field not disclosed in the present disclosure or commonly used technical means. The specification and examples are only to be regarded as exemplary, and the true scope and spirit of the present disclosure are indicated by the following claims.

[0421] It should be noted that the present disclosure is not limited to the exact structure described above and shown in the drawings, and various modifications and changes can be made without departing from its scope. The scope of the present disclosure is limited only by the appended claims.

Claims

1. An authentication method applied to a user equipment, the method comprising: determining a target entity that requests communication from one or more first entities; determining first permission request parameters based on the target entity; sending an application session establishment request message to a first proxy entity based on the first permission request parameters, the application session establishment request message instructing the first proxy entity to determine whether the user equipment and the target entity have a first communication permission based on the first permission request parameters, the first entity including an entity that provides an application function, the first proxy entity including a reliable entity that provides an authentication function within a 3GPP operator domain, and the first proxy entity providing an authentication proxy function to the first entity; determining whether the user equipment and the target entity have a first communication permission in response to receiving an application session establishment response message sent from the first proxy entity; when the user equipment and the target entity have a first communication permission, performing user equipment authentication by the first proxy entity. An authentication method characterized by the above.

2. The step of determining first permission request parameters based on the target entity includes: using a first target entity identifier of the target entity and a key identifier (A-KID) corresponding to the user equipment as the first permission request parameters. The method according to claim 1, characterized by the above.

3. The first communication permission includes: the user equipment having an access permission to the target entity; the user equipment having an access permission to the first proxy entity; the first proxy entity having a proxy permission to the target entity. including one or more of: the target entity having the right to obtain the subscriber identifier of the user equipment The method according to claim 1, characterized in that.

4. After successfully performing user equipment authentication by the first proxy entity, the method comprises: establishing a secure session with the first proxy entity; obtaining the proxy domain name of the first proxy entity and the first domain name of the target entity; if the proxy domain name is the same as the first domain name, determining, by the secure session, whether the user equipment and the target entity have a second communication right; if it is determined that the user equipment and the target entity have a second communication right, further comprising communicating with the target entity. The method according to claim 1, characterized in that.

5. The step of determining, by the secure session, whether the user equipment and the target entity have a second communication right comprises: sending, by the secure session, a target entity service request message to the first proxy entity, the target entity service request message including a second target entity identifier, the second target entity identifier being a protected entity identifier obtained by the user equipment based on the first target entity identifier, and the target entity service request message instructing the first proxy entity to determine whether the user equipment and the target entity have a second communication right based on the second target entity identifier; determining, in response to receiving a target entity service response message sent from the first proxy entity, whether the user equipment and the target entity have a second communication right. The method according to claim 4, characterized in that.

6. The second communication right is the user equipment has access rights to the target entity; the first proxy entity has proxy rights to the target entity; the target entity has acquisition rights to the subscriber identifier of the user equipment, including one or more of the above. The method according to claim 4, characterized in that.

7. In response to receiving the application session establishment response message sent from the first proxy entity, the step of determining whether the user equipment and the target entity have first communication rights is: When the application session establishment response message is received, the step of determining that the user equipment and the target entity have first communication rights, or When the application session establishment response message is received and the session establishment response message includes success indication information, the step of determining that the user equipment and the target entity have first communication rights is included. The method according to claim 1, characterized in that.

8. The first proxy entity includes a reliable authentication proxy (AP) entity within the 3GPP operator domain. The method according to any one of claims 1 to 7, characterized in that.

9. The first entity includes a reliable entity that provides an application function within the 3GPP operator domain. The method according to claim 8, characterized in that.

10. The first entity includes a reliable application function (AF) entity within the 3GPP operator domain, or a reliable application server (SCS / AS) entity within the 3GPP operator domain. The method according to claim 9, characterized in that.

11. The first entity includes an unreliable entity that provides an application function outside the 3GPP operator domain. The first proxy entity communicates with the first entity via a second entity, and the second entity includes an entity that provides a network exposure function. The method according to claim 8, characterized in that.

12. The first entity includes an untrusted application function (AF) entity outside the 3GPP operator domain or an untrusted application server (SCS / AS) entity outside the 3GPP operator domain. The method according to claim 11, characterized in that.

13. The second entity includes a network exposure function (NEF) entity or a service capability exposure function (SCEF) entity. The method according to claim 11, characterized in that.

14. An authentication method applied to a first proxy entity, the method comprising: Receiving an application session establishment request message sent from a user equipment, the application session establishment request message including a first authorization request parameter, the application session establishment request message instructing the first proxy entity to determine whether the user equipment and a target entity have a first communication authorization based on the first authorization request parameter, the target entity being an entity that requests communication determined from one or more first entities by the user equipment, the first entity including an entity that provides an application function, the first proxy entity including a trusted entity that provides an authentication function within the 3GPP operator domain, and the first proxy entity providing an authentication proxy function to the first entity; Determining whether the user equipment and the target entity have a first communication authorization based on the first authorization request parameter; When the user equipment and the target entity have a first communication authorization, sending an application session establishment response message to the user equipment and performing user equipment authentication on the user equipment. An authentication method, characterized in that.

15. The first authorization request parameter includes a first target entity identifier of the target entity and a key identifier (A-KID) corresponding to the user equipment. The method according to claim 14, characterized in that.

16. The first communication permission is that the user equipment has access permission to the target entity, that the user equipment has access permission to the first proxy entity, that the first proxy entity has proxy permission to the target entity, and that the target entity has acquisition permission to the subscriber identifier of the user equipment, including one or more of the above. The method according to claim 14, characterized in that.

17. Based on the first permission request parameter, the step of determining whether the user equipment and the target entity have the first communication permission includes: determining a second permission request parameter based on the first permission request parameter; sending the second permission request parameter to a third entity, where the third entity includes an entity that provides AKMA authentication and an application key derivation function, and the second permission request parameter instructs the third entity to determine whether the user equipment and the target entity have the first communication permission; obtaining first pending key information sent from the third entity, where the first pending key information is key information obtained by the third entity based on the second permission request parameter; and determining whether the user equipment and the target entity have the first communication permission based on the first pending key information. The method according to claim 14, characterized in that.

18. The step of determining a second permission request parameter based on the first permission request parameter includes: including the step of using the first permission request parameter and the proxy entity identifier corresponding to the first proxy entity as the second permission request parameter. The method according to claim 17, characterized in that.

19. The step of sending the second permission request parameter to the third entity is Sending the second permission request parameter to a third entity through a first key request message, the first key request message including an instruction for the third entity to obtain first pending key information and a subscriber identifier of the user equipment The step of obtaining the first pending key information sent from the third entity comprises: Receiving a first key response message sent from the third entity; and Obtaining the first pending key information included in the first key response message. The method according to claim 17, characterized in that.

20. The first key response message further includes a second subscriber identifier corresponding to the user equipment, and the method further comprises: Obtaining the second subscriber identifier based on the received first key response message. The method according to claim 19, characterized in that.

21. The second subscriber identifier includes a subscription permanent identifier (SUPI) corresponding to the user equipment. The method according to claim 20, characterized in that.

22. The step of sending the second permission request parameter to the third entity comprises: Sending the second permission request parameter to a third entity through a second key request message, the second key request message including an instruction for a first proxy entity to request obtaining the first pending key information. The step of obtaining the first pending key information sent from the third entity comprises: Receiving a second key response message sent from the third entity; and Obtaining the first pending key information included in the second key response message. The method according to claim 17, characterized in that.

23. The step of determining whether the user equipment and the target entity have a first communication permission based on the first pending key information comprises: When the first pending key information includes entity key information corresponding to the target entity, determining that the user equipment and the target entity have the first communication permission. The method according to claim 17, characterized in that

24. When the user equipment authentication for the user equipment is successful, the method further includes the step of notifying the target entity of the first authentication result of the user equipment authentication, The method according to claim 17, characterized in that

25. The step of notifying the target entity of the first authentication result of the user equipment authentication includes the step of obtaining the proxy domain name of the first proxy entity and the first domain name of the target entity, and when the proxy domain name is different from the first domain name, the step of notifying the target entity of the first authentication result, The method according to claim 24, characterized in that

25. When the target entity is a reliable entity that provides an application function within the 3GPP operator domain, the step of notifying the target entity of the first authentication result of the user equipment authentication includes the step of sending a first notification message including the first authentication result to the target entity, The method according to claim 24, characterized in that

26. When the second subscriber identifier of the user equipment is obtained by the first proxy entity, the first notification message further includes the second subscriber identifier, The method according to claim 25, characterized in that

27. When the target entity is an unreliable entity that provides an application function outside the 3GPP operator domain, the step of notifying the target entity of the first authentication result of the user equipment authentication includes the step of instructing the second entity to send the first authentication result to the target entity by sending a second notification message to the second entity based on the first authentication result, The method according to claim 24, characterized in that

28. When the second subscriber identifier of the user equipment is obtained by the first proxy entity, the second notification message further includes the second subscriber identifier, The method according to claim 27, characterized in that

29. After successfully authenticating the user equipment against the user equipment, the method comprises: establishing a secure session between the user equipment and the secure session; receiving, by the secure session, a target entity service request message sent from the user equipment, wherein the target entity service request message includes a second target entity identifier, and the second target entity identifier is a protected entity identifier obtained by the user equipment based on a first target entity identifier of the target entity, and the target entity service request message is a message sent when the user equipment determines that a proxy domain name of the first proxy entity is the same as a first domain name of the target entity; determining, based on the second target entity identifier, whether the user equipment and the target entity have a second communication right; sending, to the user equipment, a target entity service response message indicating whether the user equipment and the target entity have a second communication right; and The method according to claim 14, characterized in that.

30. The second communication right includes: the user equipment has an access right to the target entity; the first proxy entity has a proxy right to the target entity; the target entity has an acquisition right to a subscriber identifier of the user equipment; and one or more of the above. The method according to claim 29, characterized in that.

31. The step of determining, based on the second target entity identifier, whether the user equipment and the target entity have a second communication right includes: when the second target entity identifier is the same as the first target entity identifier, determining that the user equipment and the target entity have a second communication right. The method according to claim 29, characterized in that

32. The step of determining whether the user equipment and the target entity have a second communication authority based on the second target entity identifier comprises: When the second target entity identifier is different from the first target entity identifier, the step of determining a third authority request parameter based on the second target entity identifier; The step of sending the third authority request parameter to a third entity, wherein the third authority request parameter instructs the third entity to determine whether the user equipment and the target entity have a second communication authority; The step of obtaining an authorization result parameter sent from the third entity, wherein the authorization result parameter indicates whether the user equipment and the target entity have a second communication authority; Determining whether the user equipment and the target entity have a second communication authority based on the authorization result parameter. The method according to claim 29, characterized in that

33. The step of determining a third authority request parameter based on the second target entity identifier comprises: Including the step of using the second target entity identifier, a key identifier (A-KID) corresponding to the user equipment, and a proxy entity identifier corresponding to the first proxy entity as the third authority request parameter. The method according to claim 32, characterized in that

34. The step of sending the third authority request parameter to the third entity comprises: Sending the third authority request parameter to the third entity through a third key request message, wherein the third key request message includes the step of instructing the third entity to obtain an authorization result parameter and a subscriber identifier of the user equipment; The step of obtaining an authorization result parameter sent from the third entity comprises: Receiving a third key response message sent from the third entity; Obtaining the authorization result parameter included in the third key response message. The method according to claim 32, characterized in that.

35. The third key response message further includes a second subscriber identifier corresponding to the user equipment, and the method further includes: Based on the received third key response message, further including the step of obtaining the second subscriber identifier. The method according to claim 34, characterized in that.

36. The third key request message further includes an authorization instruction parameter, and the authorization instruction parameter instructs the third entity to determine whether the user equipment and the target entity have a second communication authority based on the third key request message. The method according to claim 34, characterized in that.

37. The step of transmitting the third authority request parameter to the third entity is: Transmitting the third authority request parameter to the third entity through a fourth key request message, the fourth key request message including the step of indicating that the first proxy entity requests to obtain the authorization result parameter. The step of obtaining the authorization result parameter transmitted from the third entity is: Receiving a fourth key response message transmitted from the third entity; and Obtaining the authorization result parameter included in the fourth key response message. The method according to claim 33, characterized in that.

38. The fourth key request message further includes an authorization instruction parameter, and the authorization instruction parameter instructs the third entity to determine whether the user equipment and the target entity have a second communication authority based on the fourth key request message. The method according to claim 37, characterized in that.

39. Based on the authorization result parameter, when it is determined that the user equipment and the target entity have a second communication authority, the method further includes: Further including the step of notifying the target entity of a second authentication result for instructing that the target entity and the user equipment have a communication authority. The method according to claim 31, characterized in that.

40. When the target entity is a reliable entity that provides an application function within the 3GPP operator domain, The step of notifying the target entity of the second authentication result is Including the step of sending a third notification message including the second authentication result to the target entity, The method according to claim 39, characterized in that.

41. When the second subscriber identifier of the user equipment is obtained by the first proxy entity, the third notification message further includes the second subscriber identifier, The method according to claim 40, characterized in that.

42. When the target entity is an unreliable entity that provides an application function outside the 3GPP operator domain, The step of notifying the target entity of the second authentication result is Based on the first authentication result, including the step of instructing the second entity to send the first authentication result to the target entity by sending a fourth notification message to the second entity, The method according to claim 39, characterized in that.

43. When the second subscriber identifier of the user equipment is obtained by the first proxy entity, the fourth notification message further includes the second subscriber identifier, The method according to claim 43, characterized in that.

44. The first pending key information includes an application key K AF and a key expiration time The method according to claim 17, characterized in that.

45. The second entity includes a network exposure function (NEF) entity or a service capability exposure function (SCEF) entity, The method according to claim 17, characterized in that.

46. The first proxy entity includes a reliable authentication proxy (AP) entity within the 3GPP operator domain, The method according to any one of claims 14 to 45, characterized in that.

47. The first entity includes a reliable Application Function (AF) entity within the 3GPP operator domain, or a reliable Application Server (SCS / AS) entity within the 3GPP operator domain, or an unreliable Application Function (AF) entity outside the 3GPP operator domain, or an unreliable Application Server (SCS / AS) entity outside the 3GPP operator domain, The method according to any one of claims 14 to 45, characterized in that. **Claim 48** An authentication method applied to a third entity, the method comprising: Receiving second authorization request parameters sent from a first proxy entity, wherein the second authorization request parameters instruct the third entity to determine whether the user equipment and the target entity have a first communication authorization, the target entity being an entity that requests communication determined from one or more first entities by the user equipment, the first entity including an entity that provides an application function, the first proxy entity including a reliable entity that provides an authentication function within the 3GPP operator domain, the first proxy entity providing an authentication proxy function to the first entity, and the third entity including an entity that provides an AKMA authorization and an application key derivation function; Determining whether the user equipment and the target entity have a first communication authorization based on the second authorization request parameters; When the user equipment and the target entity have a first communication authorization, obtaining first pending key information; Transmitting the first pending key information to the first proxy entity. The authentication method is characterized by the above. **Claim 49** The second authorization request parameters include a key identifier (A-KID) corresponding to the user equipment, a first target entity identifier of the target entity, and a proxy entity identifier corresponding to the first proxy entity. The step of determining whether the user equipment and the target entity have a first communication right based on the second right requirement parameter is as follows: Determining whether the user equipment has access rights to the target entity based on the key identifier (A-KID) and the first target entity identifier; Determining whether the user equipment has access rights to the first proxy entity based on the key identifier (A-KID) and the proxy entity identifier; Determining whether the first proxy entity has proxy rights to the target entity based on the proxy entity identifier and the first target entity identifier; Determining whether the target entity has the right to obtain the subscriber identifier of the user equipment based on the key identifier (A-KID) and the first target entity identifier, including one or more of the above steps. The method according to claim 48, characterized in that.

50. The step of obtaining the first pending key information is as follows: The step of obtaining the first pending key information based on the entity key information corresponding to the target entity. The method according to claim 48, characterized in that.

51. The step of receiving the second right requirement parameter sent from the first proxy entity is as follows: Receiving the second right requirement parameter sent from the first proxy entity through a first key request message, wherein the first key request message includes the step of instructing the third entity to obtain the first pending key information and the subscriber identifier of the user equipment. The step of sending the first pending key information to the first proxy entity is as follows: Sending the first pending key information to the first proxy entity through a first key response message. The method according to claim 48, characterized in that.

52. The step of sending the first pending key information to the first proxy entity through the first key response message is as follows: When it is determined that the target entity has the right to obtain the subscriber identifier, the method includes the step of transmitting, through a first key response message, first pending key information and a second subscriber identifier corresponding to the user equipment to the first proxy entity. The method according to claim 51, characterized in that.

53. The second subscriber identifier is a subscription persistent identifier (SUPI) corresponding to the user equipment. The method according to claim 52, characterized in that.

54. The step of receiving the second authorization request parameter transmitted from the first proxy entity is The step of receiving the second authorization request parameter transmitted from the first proxy entity through a second key request message, wherein the second key request message includes the step of instructing the third entity to obtain the first pending key information. The step of transmitting the first pending key information to the first proxy entity is The method includes the step of transmitting the first pending key information to the first proxy entity through a second key response message. The method according to claim 48, characterized in that.

55. After the step of transmitting the first pending key information to the first proxy entity, the method further includes The step of receiving a third authorization request parameter transmitted from the first proxy entity; Determining whether the user equipment and the target entity have a second communication right based on the third authorization request parameter; And transmitting an authorization result parameter for notifying the first proxy entity whether the user equipment and the target entity have a second communication right to the first proxy entity. The method according to claim 48, characterized in that.

56. The third authorization request parameter includes the key identifier (A-KID), the second target entity identifier, and the proxy entity identifier corresponding to the first proxy entity. The second target entity identifier is a protected entity identifier obtained based on the first target entity identifier of the target entity by the user equipment. The step of determining whether the user equipment and the target entity have a second communication authorization based on the third authorization request parameter is as follows: Based on the key identifier (A-KID) and the second target entity identifier, determining whether the user equipment has an access right to the target entity; Based on the proxy entity identifier and the second target entity identifier, determining whether the first proxy entity has a proxy right to the target entity; Based on the key identifier (A-KID) and the second target entity identifier, determining whether the target entity has an acquisition right to the subscriber identifier of the user equipment, and including one or more of the above steps. The method according to claim 55, characterized in that.

57. The step of receiving the third authorization request parameter sent from the first proxy entity is as follows: Receiving the third authorization request parameter sent from the first proxy entity through a third key request message, where the third key request message includes an instruction for the third entity to obtain an authorization result parameter and the subscriber identifier of the user equipment. The step of sending the authorization result parameter to the first proxy entity is as follows: Including the step of sending the authorization result parameter to the first proxy entity through a third key response message. The method according to claim 53, characterized in that.

58. The third key request message further includes an authorization instruction parameter, and the authorization instruction parameter instructs the third entity to determine whether the user equipment and the target entity have a second communication authority based on the third key request message. The method according to claim 57, characterized in that.

59. The step of transmitting authorization result parameters to the first proxy entity through the third key response message is When it is determined that the target entity has the authority to obtain a subscriber identifier, the step of transmitting, through a third key response message, authorization result parameters and a second subscriber identifier corresponding to the user equipment to the first proxy entity is included. The method according to claim 57, characterized in that.

60. The second subscriber identifier is a subscription persistent identifier (SUPI) corresponding to the user equipment. The method according to claim 59, characterized in that.

61. The step of receiving the third authority request parameters transmitted from the first proxy entity is The step of receiving the third authority request parameters transmitted from the first proxy entity through a fourth key request message, the fourth key request message including the step of instructing the third entity to obtain authorization result parameters. The step of transmitting the authorization result parameters to the first proxy entity is The step of transmitting the authorization result parameters to the first proxy entity through a fourth key response message is included. The method according to claim 53, characterized in that.

62. Before the step of determining whether the user equipment and the target entity have a second communication authority based on the third authority request parameters, the method further includes The step of determining, based on a first preset policy, whether the third entity has the authority to provide services to the first proxy entity. The step of determining whether the user equipment and the target entity have a second communication authority based on the third authority request parameters is When the third entity has the right to provide services to the first proxy entity, the method includes determining, based on the third authorization request parameter, whether the user equipment and the target entity have a second communication right. The method according to claim 55, characterized in that.

63. Before the step of determining, based on the second authorization request parameter, whether the user equipment and the target entity have a first communication right, the method includes: Further including determining, based on a first preset policy, whether the third entity has the right to provide services to the first proxy entity. The step of determining, based on the second authorization request parameter, whether the user equipment and the target entity have a first communication right includes: When the third entity has the right to provide services to the first proxy entity, the method includes determining, based on the second authorization request parameter, whether the user equipment and the target entity have a first communication right. The method according to claim 48, characterized in that.

64. The first proxy entity includes a reliable authentication proxy (AP) entity within the 3GPP operator domain, and the third entity includes an AKMA anchor function (AAnF) entity. The method according to any one of claims 48 to 63, characterized in that.

65. The first entity includes a reliable application function (AF) entity within the 3GPP operator domain, or a reliable application server (SCS / AS) entity within the 3GPP operator domain, or an unreliable application function (AF) entity outside the 3GPP operator domain, or an unreliable application server (SCS / AS) entity outside the 3GPP operator domain. The method according to any one of claims 48 to 63, characterized in that.

66. An authentication method applied to a target entity among one or more first entities, the method includes: A step of obtaining an authentication result of user equipment by a first proxy entity, wherein the authentication result includes a first authentication result or a second authentication result, the first authentication result indicates that the user equipment and the target entity have a first communication authority, the second authentication result indicates that the user equipment and the target entity have a second communication authority, the first entity includes an entity that provides an application function, the target entity is an entity that requests communication, determined from one or more first entities by the user equipment, the first proxy entity includes a reliable entity that provides an authentication function within a 3GPP operator domain, and the step of the first proxy entity providing an authentication proxy function to the first entity; A step of communicating with the user equipment based on the authentication result; An authentication method characterized by the above.

67. When the target entity is a reliable entity that provides an application function within a 3GPP operator domain, The step of obtaining an authentication result of user equipment by the first proxy entity is Receiving a first notification message including the first authentication result transmitted from the first proxy entity, or Receiving a third notification message including the second authentication result transmitted from the first proxy entity. The method according to claim 66, characterized by the above.

68. The first notification message or the third notification message further includes a second subscriber identifier corresponding to the user equipment. The method according to claim 67, characterized by the above.

69. The second subscriber identifier includes a subscription permanent identifier (SUPI) corresponding to the user equipment. The method according to claim 68, characterized by the above.

70. When the target entity is an unreliable entity that provides an application function outside the 3GPP operator domain, The step of obtaining an authentication result of user equipment by the first proxy entity is Receiving a fifth notification message sent from the second entity, wherein the fifth notification message includes the first authentication result, and the fifth notification message is a message sent by the second entity in response to receiving a second notification message, or, Receiving a sixth notification message sent from the second entity, wherein the sixth notification message includes the second authentication result, and the fifth notification message is a message sent by the second entity in response to receiving a fourth notification message, The method according to claim 66, characterized in that.

71. The fifth notification message or the sixth notification message further includes a first subscriber identifier of the user equipment. The method according to claim 70, characterized in that.

72. The first subscriber identifier is a general public subscription identifier (GPSI) corresponding to the user equipment. The method according to claim 71, characterized in that.

73. The first proxy entity includes a reliable authentication proxy (AP) entity within the 3GPP operator domain. The method according to any one of claims 66 to 72, characterized in that.

74. The first entity includes a reliable application function (AF) entity within the 3GPP operator domain, or a reliable application server (SCS / AS) entity within the 3GPP operator domain, or an unreliable application function (AF) entity outside the 3GPP operator domain, or an unreliable application server (SCS / AS) entity outside the 3GPP operator domain. The method according to any one of claims 66 to 72, characterized in that.

75. An authentication method, applied to a second entity, the method comprising: A step of obtaining an authentication result of user equipment by a first proxy entity, wherein the authentication result includes a first authentication result or a second authentication result, the first authentication result indicates that the user equipment and a target entity have a first communication authority, the second authentication result indicates that the user equipment and the target entity have a second communication authority, the target entity is an entity that requests communication determined from one or more first entities by the user equipment, the first entity includes an untrusted entity that provides an application function outside the 3GPP operator domain, the first proxy entity includes a trusted entity that provides an authentication function within the 3GPP operator domain, and the step of the first proxy entity providing an authentication proxy function to the first entity; A step of enabling the target entity to communicate with the user equipment based on the authentication result by transmitting the authentication result to the target entity. An authentication method characterized by the above.

76. The step of obtaining an authentication result of user equipment by the first proxy entity is: Receiving a second notification message transmitted from the first proxy entity, wherein the second notification message is a message transmitted by the first proxy entity to a second entity based on the first authentication result when the target entity is an untrusted entity that provides an application function outside the 3GPP operator domain; Obtaining the first authentication result based on the second notification message. The step of transmitting the authentication result to the target entity is: Including the step of transmitting a fifth notification message to the target entity based on the first authentication result. The method according to claim 75, characterized by the above.

77. When the second notification message includes a second subscriber identifier corresponding to the user equipment, The step of transmitting a fifth notification message to the target entity based on the first authentication result is: Obtaining a first subscriber identifier corresponding to the user equipment based on the second subscriber identifier; Sending a fifth notification message to the target entity based on the first authentication result and the first subscriber identifier; The method according to claim 76, characterized in that.

78. The first subscriber identifier is a general public subscription identifier (GPSI) corresponding to the user equipment, and the second subscriber identifier includes a subscription persistent identifier (SUPI) corresponding to the user equipment. The method according to claim 77, characterized in that.

79. The step of obtaining an authentication result of the user equipment by the first proxy entity includes: Receiving a fourth notification message sent from the first proxy entity, where the fourth notification message is a message sent by the first proxy entity to the second entity based on the second authentication result when the target entity is an untrusted entity providing an application function outside the 3GPP operator domain; Obtaining the second authentication result based on the second notification message; The step of sending the authentication result to the target entity includes: Sending a sixth notification message to the target entity based on the second authentication result. The method according to claim 75, characterized in that.

80. When the second subscriber identifier corresponding to the user equipment is included in the fourth notification message, The step of sending a sixth notification message to the target entity based on the second authentication result includes: Obtaining a first subscriber identifier corresponding to the user equipment based on the second subscriber identifier; Sending a sixth notification message to the target entity based on the second authentication result and the first subscriber identifier. The method according to claim 79, characterized in that.

81. The second entity includes a Network Exposure Function (NEF) entity or a Service Capability Exposure Function (SCEF) entity. The method according to any one of claims 66 to 80, characterized in that.

82. An authentication device applied to user equipment, the device comprising: A target entity determination module configured to determine a target entity that requests communication from one or more first entities; A parameter determination module configured to determine first authorization request parameters based on the target entity; A first message transmission module configured to transmit an application session establishment request message to a first proxy entity based on the first authorization request parameters, wherein the application session establishment request message instructs the first proxy entity to determine whether the user equipment and the target entity have a first communication authorization based on the first authorization request parameters, the first entity includes an entity that provides an application function, the first proxy entity includes a reliable entity that provides an authentication function within a 3GPP operator domain, and the first proxy entity provides an authentication proxy function to the first entity. The first message transmission module; A first message reception module configured to determine whether the user equipment and the target entity have a first communication authorization in response to receiving an application session establishment response message transmitted from the first proxy entity; When the user equipment and the target entity have a first communication authorization, an authentication module configured to perform user equipment authentication by the first proxy entity. An authentication device, characterized in that.

83. An authentication device applied to a first proxy entity, the device comprising: A first proxy receiving module configured to receive an application session establishment request message sent from a user equipment, wherein the application session establishment request message includes a first authorization request parameter, and the application session establishment request message instructs the first proxy entity to determine whether the user equipment and the target entity have a first communication authorization based on the first authorization request parameter, the target entity is an entity that requests communication determined from one or more first entities by the user equipment, the first entities include entities that provide application functions, the first proxy entity includes a reliable entity that provides an authentication function within a 3GPP operator domain, and the first proxy receiving module in which the first proxy entity provides an authentication proxy function to the first entity. A first proxy determination module configured to determine whether the user equipment and the target entity have a first communication authorization based on the first authorization request parameter. A first proxy transmission module configured to transmit an application session establishment response message to the user equipment and perform user equipment authentication on the user equipment when the user equipment and the target entity have a first communication authorization. An authentication device, characterized by the above.

84. An authentication device applied to a third entity, the device comprising: A third receiving module configured to receive second authorization request parameters transmitted from a first proxy entity, wherein the second authorization request parameters instruct the third entity to determine whether the user equipment and the target entity have a first communication authorization, and the target entity is an entity that requests communication determined from one or more first entities by the user equipment, the first entity includes an entity that provides an application function, the first proxy entity includes a reliable entity that provides an authentication function within a 3GPP operator domain, the first proxy entity provides an authentication proxy function to the first entity, and the third entity includes an entity that provides an AKMA authorization and an application key derivation function; a third receiving module; A third determination module configured to determine, based on the second authorization request parameters, whether the user equipment and the target entity have a first communication authorization; A third key module configured to obtain first pending key information when the user equipment and the target entity have a first communication authorization; A third transmission module configured to transmit the first pending key information to the first proxy entity; and An authentication device characterized by the above. **Claim 85** An authentication device applied to a target entity among one or more first entities, the device including a first communication module; The first communication module obtains an authentication result of user equipment by a first proxy entity, the authentication result includes a first authentication result or a second authentication result, the first authentication result indicates that the user equipment and the target entity have a first communication right, the second authentication result indicates that the user equipment and the target entity have a second communication right, the first entity includes an entity that provides an application function, the target entity is an entity that requests communication determined from one or more first entities by the user equipment, the first proxy entity includes a reliable entity that provides an authentication function within the 3GPP operator domain, the first proxy entity provides an authentication proxy function to the first entity, and is configured to communicate with the user equipment based on the authentication result. An authentication device characterized by the above.

86. An authentication device applied to a second entity, the device includes: A second receiving module configured to obtain an authentication result of user equipment by a first proxy entity, the authentication result includes a first authentication result or a second authentication result, the first authentication result indicates that the user equipment and the target entity have a first communication right, the second authentication result indicates that the user equipment and the target entity have a second communication right, the target entity is an entity that requests communication determined from one or more first entities by the user equipment, the first entity includes an unreliable entity that provides an application function outside the 3GPP operator domain, the first proxy entity includes a reliable entity that provides an authentication function within the 3GPP operator domain, and the first proxy entity provides an authentication proxy function to the first entity; and A second transmitting module configured to transmit the authentication result to the target entity so that the target entity communicates with the user equipment based on the authentication result. An authentication device characterized by the above.

87. An authentication device, including a processor and a memory for storing instructions executable by the processor, wherein the processor is configured to execute the steps of the method according to any one of claims 1 to 13, or the processor is configured to execute the steps of the method according to any one of claims 14 to 47, or the processor is configured to execute the steps of the method according to any one of claims 48 to 65, or the processor is configured to execute the steps of the method according to any one of claims 66 to 74, or the processor is configured to execute the steps of the method according to any one of claims 75 to 81, An authentication device characterized by the above.

88. A computer-readable storage medium storing computer program instructions, wherein when the computer program instructions are executed by a processor, the steps of the method according to any one of claims 1 to 13 are realized, or when the computer program instructions are executed by a processor, the steps of the method according to any one of claims 14 to 47 are realized, or when the computer program is executed by a processor, the steps of the method according to any one of claims 48 to 65 are realized, or when the computer program instructions are executed by a processor, the steps of the method according to any one of claims 66 to 74 are realized, or when the computer program instructions are executed by a processor, the steps of the method according to any one of claims 75 to 81 are realized, A computer-readable storage medium characterized by the above.

89. A chip, including a processor and an interface, The processor reads instructions to execute the steps of the method according to any one of claims 1 to 13, or the processor reads instructions to execute the steps of the method according to any one of claims 14 to 47, or the processor reads instructions to execute the steps of the method according to any one of claims 48 to 65, or the processor reads instructions to execute the steps of the method according to any one of claims 66 to 74, or the processor reads instructions to execute the steps of the method according to any one of claims 75 to 81, A chip characterized by the above.