Identifier processing method, device, and computer-readable storage medium
The identifier processing method and device address abnormal terminations and security issues in GBA and AKMA by determining the current stage based on key queries, ensuring correct processing and secure key management.
Patent Information
- Application Number
- JP2025536764
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2022-12-21
- Filing Date
- 2023-12-15
- Publication Date
- 2025-12-11
- Estimated Expiration
- 2043-12-15
AI Technical Summary
The existing Generic Bootstrapping Architecture (GBA) and Authentication Key Management Architecture (AKMA) systems face issues with abnormal termination and security vulnerabilities due to identical HTTP request messages being forwarded in different stages, leading to errors and bypassed authorization operations.
An identifier processing method and device that determine the current stage of the GBA or AKMA flow by querying a first key based on an attached identifier, sending appropriate messages to obtain or forward keys to the second or third device accordingly, ensuring correct processing and preventing bypassing of authorization operations.
Prevents abnormal termination and enhances security by accurately determining the stage of the GBA or AKMA flow, thereby avoiding HTTP errors and ensuring secure key management.
Smart Images

Figure 2025540489000001_ABST
Abstract
Description
[Technical Field]
[0001] (CROSS-REFERENCE TO RELATED APPLICATIONS) This disclosure is based on and claims priority from a Chinese patent application bearing application number 202211655203.5 and filing date December 21, 2022, the entire contents of which are incorporated herein by reference. The present disclosure relates to the field of communications technology, and in particular to an identifier processing method, device, and computer-readable storage medium. [Background technology]
[0002] Generic Bootstrapping Architecture (GBA) is a universal authentication architecture based on the 4G or 5G network root key. By utilizing standard authentication and key negotiation mechanisms, GBA can achieve two-way identity authentication and key agreement between terminals and networks.
[0003] In an enhanced GBA system, a Network Application Function (NAF) network element or an Authentication Proxy (AP) network element is located in the carrier network and provides services to multiple Application Servers (ASs). While authenticating the identity of a User Equipment (UE), the NAF or AP must also authorize the UE's service request. If the UE's service request is authorized, the NAF or AP generates a one-time GBA application layer session key Ks_NAF* for the current session between the UE and the application server, and provides the Ks_NAF* to the application server so that the application server knows that the UE's service request is authorized. Otherwise, the NAF or AP rejects the UE's service request. In this case, the Ks_NAF* is not generated and is not provided to the application server.
[0004] The extended GBA system workflow includes four stages: GBA initialization, bootstrapping, bootstrapping secure correlation usage, and application secure correlation usage. In the fourth stage, two processing methods are supported for obtaining the GBA application layer session key Ks_NAF*: active push by NAF or AP and active request by Server.
[0005] In an extended GBA flow, the NAF or AP must perform accurate processing based on the current stage of the GBA flow. For example, in stage 3, the NAF or AP must directly respond to the Hypertext Transfer Protocol (HTTP) message it receives. In stage 4, the NAF or AP must forward the HTTP message to the server for processing. However, during actual testing, it was discovered that the HTTP request messages sent by the UE in stages 3 and 4 were the same. In this case, the NAF or AP could forward both received HTTP request messages to the server for processing, resulting in the following errors: One error is that the NAF or AP forwards the HTTP message to the server, which treats it as an abnormal situation and returns an HTTP 404 error response, ultimately terminating the extended GBA workflow in stage 3. The other error is that the authorization operation in stage 4 of the extended GBA mechanism is bypassed, resulting in a security issue. A similar problem exists in the application layer's authentication and key management (AKMA) architecture. Summary of the Invention [Problem to be solved by the invention]
[0006] The embodiments of the present disclosure aim to provide an identifier processing method, device, and computer-readable storage medium to solve the problem of abnormal termination of a business flow in an extended GBA flow or AKMA flow in the prior art. [Means for solving the problem]
[0007] In a first aspect of an embodiment of the present disclosure, there is provided an identifier processing method performed by a first device, the method including: receiving a first message transmitted from a user equipment (UE), the first message being accompanied by a first identifier; and, if the first key has not been queried based on the first identifier, transmitting a second message to the second device to obtain the first key, and / or, if the first key has been queried based on the first identifier, transmitting a third message to the third device.
[0008] In some embodiments, the third message comprises: The encryption key includes at least one of the first identifier, the first key, a second key derived from the first key, information obtained by encrypting the first key, and information obtained by encrypting the second key.
[0009] In some embodiments, after sending a second message to the second device to obtain the first key, the method further includes sending a fourth message to the UE.
[0010] In some embodiments, the fourth message is used to indicate successful processing of the first message, or successful retrieval of the first key by the first device, or successful retrieval of the first key by the first device and successful verification of the first message, and / or the fourth message is used to indicate unsuccessful processing of the first message, or unsuccessful retrieval of the first key by the first device, or successful retrieval of the first key by the first device but unsuccessful verification of the first message.
[0011] In some embodiments, the first device is a Network Application Function (NAF) network element or an Authentication Agent (AP) network element, and the first identifier is a Bootstrapping Transaction Identifier (B-TID); sending a second message to the second device to obtain the first key if the second device has not queried the first key based on the first identifier, and / or sending a third message to the third device if the first key has been queried based on the first identifier; If the first key has not been queried based on the B-TID, determining that the process is in a third phase of the extended generic bootstrapping architecture GBA business flow and sending a second message to the generic service function BSF network element to obtain the first key; and / or if the first key has been queried based on the B-TID, determining that the process is in a fourth phase of the extended GBA business flow and sending a third message to the application server.
[0012] In some embodiments, the first identifier is a key identifier (A-KID); sending a second message to the second device to obtain the first key if the second device has not queried the first key based on the first identifier, and / or sending a third message to the third device if the first key has been queried based on the first identifier; If the first key is not queried based on the A-KID, sending a second message to an application layer Identity Verification and Key Management Anchor Function (AAnF) network element to obtain the first key, and / or if the first key is queried based on the A-KID, sending a third message to an application function AF network element or AS.
[0013] In some embodiments, the third message includes the first identifier, and the method further comprises: receiving a fifth message requesting the key sent from the third device; sending a sixth message to the third device; The sixth message includes at least one of the first key, a second key derived from the first key, information obtained by encrypting the first key, and information obtained by encrypting the second key.
[0014] In a second aspect of an embodiment of the present disclosure, there is further provided a first device including a processor and a transceiver, the transceiver transmitting and receiving data under control of the processor; The processor: receiving a first message transmitted from the UE, the first message being accompanied by a first identifier; If the first key has not been queried based on the first identifier, sending a second message to the second device to obtain the first key, and / or if the first key has been queried based on the first identifier, sending a third message to the third device.
[0015] In some embodiments, the third message comprises: The encryption key includes at least one of the first identifier, the first key, a second key derived from the first key, information obtained by encrypting the first key, and information obtained by encrypting the second key. In some embodiments, the processor is further adapted to perform transmitting a fourth message to the UE.
[0016] In some embodiments, the fourth message is used to indicate successful processing of the first message, or successful retrieval of the first key by the first device, or successful retrieval of the first key by the first device and successful verification of the first message; and / or The fourth message is used to indicate that the first message has not been processed, or that the first device has not been able to obtain the first key, or that the first device has successfully obtained the first key but has not been able to verify the first message.
[0017] In some embodiments, the first device is a NAF / AP, the first identifier is a B-TID, The processor further comprises: If the first key has not been queried based on the B-TID, it is determined that the process is in the third stage of the extended GBA business flow and sends a second message to the BSF to obtain the first key, and / or if the first key has been queried based on the B-TID, it is determined that the process is in the fourth stage of the extended GBA business flow and sends a third message to the application server.
[0018] In some embodiments, the first identifier is an A-KID; The processor further comprises: It is used to send a second message to the AAnF to obtain the first key if the first key has not been queried based on the A-KID, and / or to send a third message to the AF or AS if the first key has been queried based on the A-KID.
[0019] In some embodiments, the third message includes the first identifier, and the processor further: receiving a fifth message requesting the key sent from the third device; and transmitting a sixth message to the third device; The sixth message includes at least one of the first key, a second key derived from the first key, information obtained by encrypting the first key, and information obtained by encrypting the second key.
[0020] In a third aspect of an embodiment of the present disclosure, a first device is further provided that includes a memory, a processor, and a program stored in the memory and executable on the processor, and that realizes the above-mentioned identifier processing method when the processor executes the program.
[0021] In a fourth aspect of an embodiment of the present disclosure, there is further provided a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the steps of the identifier processing method described above. [Effects of the Invention]
[0022] The above technical solutions of the present disclosure have at least the following beneficial effects: According to the identifier processing method, device, and computer-readable storage medium of the present disclosure, the first device queries the first key through the first identifier attached to the first message, and takes corresponding action depending on whether the first device queries the first key, thereby indirectly determining the current stage of the flow, preventing bypassing of the authorization operation at a certain stage, and improving the security of the extended GBA system and / or the AKMA system. In addition, the present disclosure can further prevent abnormal termination of the extended GBA operation flow and / or the AKMA operation flow. [Brief explanation of the drawings]
[0023] [Figure 1] 1 is a flowchart illustrating steps of an identifier processing method according to an embodiment of the present disclosure. [Figure 2] FIG. 1 is a schematic diagram illustrating an example of an identifier processing method according to an embodiment of the present disclosure. [Figure 3] FIG. 10 is a schematic principle diagram of a second example of an identifier processing method according to an embodiment of the present disclosure. [Figure 4] FIG. 2 is a structural schematic diagram of a first device according to an embodiment of the present disclosure. DETAILED DESCRIPTION OF THE INVENTION
[0024] To make the technical problems to be solved, technical solutions and advantages of the present disclosure clearer, the following detailed description will be given with reference to the drawings and specific embodiments.
[0025] As shown in FIG. 1, an embodiment of the present disclosure provides an identifier processing method performed by a first device, which includes the following steps 101-102.
[0026] In step 101, a first message sent from a user equipment (UE) is received, and the first message is accompanied by a first identifier.
[0027] Optionally, the first message may be an HTTP message, an HTTP request message, or the like. In step 102, if the first key has not been queried based on the first identifier, a second message is sent to the second device to obtain the first key, and / or if the first key has been queried based on the first identifier, a third message is sent to the third device.
[0028] Optionally, if the first key has not been queried, it determines that the current flow is in a certain stage, and if the first key has been queried, it determines that the current flow is in another stage. In an embodiment of the present disclosure, when processing the first message of the UE, the first device can determine the current stage of the flow depending on whether the first key has been queried, and then take a corresponding processing method. For example, the first device can clearly distinguish between the third and fourth stages of the GBA from a business perspective. In the third stage, the first device should not forward the first message of the UE to the application server. In the fourth stage, the first device should actively push a key to the application server, or the application server should actively request the first device to obtain a key, based on a preset key acquisition method.
[0029] Optionally, the identifier processing method according to the embodiment of the present disclosure may have multiple embodiments, of which two optional embodiments are an identifier processing method applied to GBA and an identifier processing method applied to AKMA.
[0030] In one alternative embodiment, the third message comprises: The encryption key includes at least one of the first identifier, the first key, a second key derived from the first key, information obtained by encrypting the first key, and information obtained by encrypting the second key.
[0031] Here, the first key may be a GBA session key Ks_NAF or Ks_(int / ext)_NAF, and the second key may be a GBA application layer session key Ks_NAF*. Alternatively, the first key may be a KAKMA or KAF, and the second key may be a key derived from the KAKMA or KAF.
[0032] In at least one embodiment of the present disclosure, after sending a second message to a second device to obtain the first key, the method further includes sending a fourth message to the UE.
[0033] In at least one embodiment of the present disclosure, the fourth message is used to indicate successful processing of the first message, or successful acquisition of the first key by the first device, or successful acquisition of the first key by the first device and successful verification of the first message, and / or the fourth message is used to indicate unsuccessful processing of the first message, or unsuccessful acquisition of the first key by the first device, or successful acquisition of the first key by the first device but unsuccessful verification of the first message.
[0034] In at least one embodiment of the present disclosure, the first device is a Network Application Function (NAF) network element or an Authentication Agent (AP) network element, and the first identifier is a Bootstrapping-transaction identifier (B-TID), in which case step 102 comprises: If the first key has not been queried based on the B-TID, determining that the third step of the Extended Generic Bootstrapping Architecture (GBA) workflow is in progress, and sending a second message to a Bootstrapping Server Function (BSF) network element to obtain the first key; and / or If the first key is being queried based on the B-TID, determining that the fourth step of the extended GBA business flow is in progress includes sending a third message to the application server.
[0035] According to the extended GBA workflow, the NAF / AP does not initially have a GBA session key Ks_(int / ext)_NAF. In the third step, when the NAF / AP receives an HTTP request message from the UE, it realizes that Ks_(int / ext)_NAF for authenticating the HTTP request message does not exist locally, so it requests the BSF to obtain Ks_(int / ext)_NAF and then performs HTTP digest authentication using the key. In the fourth step, when the NAF / AP receives an HTTP request message from the UE, it realizes that Ks_(int / ext)_NAF already exists locally, so it performs HTTP digest authentication using the key.
[0036] Therefore, in the embodiment of the present disclosure, the NAF / AP determines the current stage of the GBA authentication flow by determining whether a GBA session key Ks_(int / ext)_NAF exists on the NAF / AP. When the NAF / AP receives an HTTP request message (i.e., the first message) sent from the UE, it first queries whether an available Ks_(int / ext)_NAF exists locally based on the B-TID information in the message. If an available Ks_(int / ext)_NAF does not exist, it determines that the flow is currently in the third stage, and then interacts with the BSF via a Bootstrapping-Info-Answer (BIR) / Bootstrapping-Info-Request (BIA) message to request the acquisition of Ks_(int / ext)_NAF. If an available Ks_(int / ext)_NAF exists, it determines that the flow is currently in the fourth stage. Here, the availability of Ks_(int / ext)_NAF means that the NAF / AP has stored Ks_(int / ext)_NAF locally and that it is within its valid lifetime, not an expired key. The NAF / AP then performs HTTP digest authentication on the HTTP request message based on Ks_(int / ext)_NAF. If the digest authentication on the HTTP request message is successful, the NAF / AP proceeds to the third or fourth stage depending on the result of the above determination. If the digest authentication on the HTTP request message fails, the NAF / AP returns an HTTP 401 message, requests the UE to retry the GBA bootstrapping process, and performs AKA (Authentication Key Agreement) identity authentication.
[0037] In another preferred embodiment of the present disclosure, the first identifier is a key identifier (AKMA Key Identifier, A-KID), in which case step 102 comprises: If the first key has not been queried based on the A-KID, sending a second message to an Application Layer Identity Verification and Key Management Anchor Function (AAnF) network element to obtain the first key; and / or If the application function is querying the first key based on the A-KID, it includes sending a third message to the AF network element or the AS.
[0038] Here, the first device may have various embodiments, including but not limited to, an AAP (AKMA Application Proxy), an AKMA AP (AKMA Application Proxy), an AKMA application agent, an AS agent, an agent server, an AF agent, etc.
[0039] In one alternative embodiment, if the third message includes the first identifier, the method further includes receiving a fifth message for requesting a key sent from a third device; sending a sixth message to the third device; The sixth message includes at least one of the first key, a second key derived from the first key, information obtained by encrypting the first key, and information obtained by encrypting the second key.
[0040] In an embodiment of the present disclosure, the first device queries the first key via the first identifier attached to the first message, and takes corresponding action depending on whether the first device queries the first key, thereby indirectly determining the stage in which the flow is currently located, preventing bypassing of the authorization operation at a certain stage, improving the security of the extended GBA system and / or the AKMA system, and avoiding an HTTP 404 error response from the AS for abnormal situation processing and abnormal termination of the extended GBA operation flow and / or the AKMA operation flow.
[0041] To more clearly explain the identifier processing method according to the embodiments of the present disclosure, the following description will be given in conjunction with two examples of extended GBA authentication flows.
[0042] [Example 1] The NAF / AP can use a stage identifier method to determine the stage the enhanced GBA flow is currently in. When using a stage identifier method, the stage information can be recorded in different ways. For example, a flag can be set to indicate stage 3 and not set to indicate stage 4, or a flag can be set to 0 to indicate stage 3 and 1 to indicate stage 4. The specific flow is shown in Figure 2.
[0043] In step 1, the NAF or AP receives an HTTP request message sent from the UE.
[0044] In step 2, the NAF or AP queries whether there is a locally available GBA session key Ks_(int / ext)_NAF based on the B-TID.
[0045] If there is no Ks_(int / ext)_NAF available in step 3, determine that you are currently in the third stage, record the identifier, and proceed to step 4.
[0046] In step 4, the NAF or AP obtains Ks_(int / ext)_NAF from the BSF and proceeds to step 6.
[0047] In step 5, if there is an available Ks_(int / ext)_NAF, determine that you are currently in the fourth stage, record the identifier, and proceed to step 6.
[0048] In step 6, the NAF or AP performs HTTP Digest authentication.
[0049] In step 7, if authentication is successful, the current stage is determined based on the identifier, and if it is determined to be the third stage, proceed to step 8; if it is determined to be the fourth stage, proceed to step 9.
[0050] In step 8, return an HTTP response message to the UE.
[0051] In step 9, the HTTP request message is forwarded to the application server Server, and Ks_NAF* is provided to Server in an appropriate manner.
[0052] In step 10, if the authentication fails, return an HTTP 401 message to the UE.
[0053] [Example 2] The NAF / AP can use a method without a stage identifier to determine the stage the extended GBA flow is currently in. The specific flow is shown in Figure 3.
[0054] In step 1, the NAF or AP receives an HTTP request message sent from the UE.
[0055] In step 2, the NAF or AP queries whether there is a locally available GBA session key Ks_(int / ext)_NAF based on the B-TID.
[0056] In step 3, if there is an available Ks_(int / ext)_NAF, it is determined that the current state is the fourth stage, and the NAF or AP performs HTTP digest authentication and proceeds to step 5 or step 6.
[0057] If in step 4 there is no Ks_(int / ext)_NAF available, determine that you are currently in the third phase, obtain Ks_(int / ext)_NAF from the BSF, and proceed to step 7.
[0058] In step 5, if the authentication is successful, the HTTP request message is forwarded to the application server Server, and Ks_NAF* is provided to the Server in an appropriate manner.
[0059] In step 6, if the authentication fails, return an HTTP 401 message to the UE.
[0060] In step 7, the NAF or AP performs HTTP Digest authentication.
[0061] In step 8, if the authentication is successful, return an HTTP 200 OK message to the UE.
[0062] In step 9, if the authentication fails, return an HTTP 401 message to the UE.
[0063] As shown in FIG. 4 , an embodiment of the present disclosure further provides a first device including a processor 400 and a transceiver 410, wherein the transceiver 410 transmits and receives data under the control of the processor 400; The processor 400 receiving a first message transmitted from a user equipment (UE), the first message having a first identifier attached thereto; If the first key has not been queried based on the first identifier, sending a second message to the second device to obtain the first key, and / or if the first key has been queried based on the first identifier, sending a third message to the third device.
[0064] In one alternative embodiment, the third message comprises: The encryption key includes at least one of the first identifier, the first key, a second key derived from the first key, information obtained by encrypting the first key, and information obtained by encrypting the second key.
[0065] In one alternative embodiment, the processor is further adapted to execute transmitting a fourth message to the UE.
[0066] In one alternative embodiment, the fourth message is used to indicate successful processing of the first message, or successful acquisition of the first key by the first device, or successful acquisition of the first key by the first device and successful verification of the first message; and / or the fourth message is used to indicate unsuccessful processing of the first message, or unsuccessful acquisition of the first key by the first device, or successful acquisition of the first key by the first device but unsuccessful verification of the first message.
[0067] In one alternative embodiment, the first device is a NAF / AP, the first identifier is a B-TID, and the processor further: If the first key has not been queried based on the B-TID, it is determined that the process is in the third stage of the extended GBA business flow and sends a second message to the BSF to obtain the first key, and / or if the first key has been queried based on the B-TID, it is determined that the process is in the fourth stage of the extended GBA business flow and sends a third message to the application server.
[0068] In one alternative embodiment, the first identifier is an A-KID, and the processor is further configured to: send a second message to the AAnF to obtain the first key if the first key has not been queried based on the A-KID; and / or send a third message to the AF or AS if the first key has been queried based on the A-KID.
[0069] In one alternative embodiment, the third message includes the first identifier, and the processor is further adapted to receive a fifth message for requesting a key sent from a third device and to send a sixth message to the third device; The sixth message includes at least one of the first key, a second key derived from the first key, information obtained by encrypting the first key, and information obtained by encrypting the second key.
[0070] In an embodiment of the present disclosure, the first device queries the first key via the first identifier attached to the first message, and takes corresponding action depending on whether the first device queries the first key, thereby indirectly determining the stage in which the flow is currently located, preventing bypassing of the business authorization operation at a certain stage, and improving the security of the extended GBA system and / or the AKMA system. Also, an HTTP 404 error response returned by the business server in response to an abnormal situation process can be eliminated, thereby avoiding abnormal termination of the extended GBA business flow and / or the AKMA business flow.
[0071] Furthermore, since the first device in the embodiment of the present disclosure is a device capable of executing the above-mentioned identifier processing method, all embodiments of the above-mentioned identifier processing method can be applied to the device to achieve the same or similar beneficial effects, and therefore, the description here is omitted.
[0072] An embodiment of the present disclosure further provides a first device including a memory, a processor, and a computer program stored in the memory and executable on the processor, and when the processor executes the program, it can realize each step in the above-mentioned identifier processing method embodiment to achieve the same technical effect, and to avoid duplication, description will be omitted here.
[0073] It should be understood that the processor in the embodiments of the present disclosure may be an integrated circuit chip capable of processing signals. In the implementation process, each step of the above method embodiments may be performed by a hardware integrated logic circuit in the processor or by instructions in software format. The processor may be a general-purpose processor, a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field programmable gate array (FPGA) or other programmable logic device, a discrete gate or transistor logic device, or a discrete hardware component, and may implement or execute each method, step, and logic block diagram disclosed in the embodiments of the present disclosure. The general-purpose processor may be a microprocessor or any conventional processor, etc. The steps of the methods disclosed in the embodiments of the present disclosure may be directly embodied as a hardware decoding processor execution complete, or may be embodied as a combination of hardware and software modules in the decoding processor execution complete. The software modules may reside in storage media known in the art, such as random memory, flash memory, read-only memory, programmable read-only memory, electrically erasable programmable memory, registers, etc. The storage medium is located in a memory, and a processor reads the information in the memory and adjusts its hardware to complete the steps of the above method.
[0074] It should be understood that memory in the embodiments of the present disclosure may be volatile or non-volatile memory, or may include both volatile and non-volatile memory. Here, non-volatile memory may be read-only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), or flash memory. Volatile memory may be random access memory (RAM) used as an external cache. By way of example and not limitation, many forms of RAM are available. Examples include static random access memory (Static RAM, SRAM), dynamic random access memory (DRAM), synchronous dynamic random access memory (Synchronous DRAM, SDRAM), double data rate synchronous dynamic random access memory (Double Data Rate SDRAM, DDR SDRAM), enhanced synchronous dynamic random access memory (Enhanced SDRAM, ESDRAM), synchronously linked dynamic random access memory (Synchlink DRAM, SLDRAM), and direct memory bus associated access memory (Direct Rambus RAM, DR RAM). Memory as described herein is intended to include, without being limited to, these and any other suitable types of memory.
[0075] The above-described memories are exemplary and not limiting. For example, the memory in the embodiments of the present disclosure may further include static random access memory (static RAM, SRAM), dynamic random access memory (dynamic RAM, DRAM), synchronous dynamic random access memory (synchronous DRAM, SDRAM), double data rate synchronous dynamic random access memory (double data rate SDRAM, DDR SDRAM), enhanced synchronous dynamic random access memory (enhanced SDRAM, ESDRAM), synchronous link dynamic random access memory (synch link DRAM, SLDRAM), direct memory bus random access memory (Direct Rambus RAM, DR RAM), etc. That is, the memory in the embodiments of the present disclosure is intended to include, but is not limited to, these and any other suitable types of memory.
[0076] The embodiments of the present disclosure further provide a computer-readable storage medium storing a computer program, which, when executed by a processor, can realize the respective steps in the above-described embodiments of the identifier processing method to achieve the same technical effects, and to avoid repetition, the description thereof will be omitted here. Here, the computer-readable storage medium may include a read-only memory (ROM), a random access memory (RAM), a magnetic disk, an optical disk, etc.
[0077] Those skilled in the art will appreciate that embodiments of the present disclosure may be provided as a method, a system, or a computer program product. Therefore, the present disclosure may take the form of an entirely hardware embodiment, an entirely software embodiment, or an embodiment combining software and hardware aspects. The present disclosure may also take the form of a computer program product embodied on a computer-readable storage medium (including, but not limited to, a disk memory, an optical memory, etc.) containing computer-usable program code.
[0078] The present disclosure will be described with reference to flowcharts and / or block diagrams of methods, devices (systems), and computer program products according to embodiments of the present disclosure. It should be understood that each flow and / or block of the flowcharts and / or block diagrams, and combinations of flows and / or blocks in the flowcharts and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to generate an apparatus; thus, the instructions executed by the processor of the computer or other programmable data processing device can generate an apparatus for implementing the functions specified in one or more flows and / or one or more blocks of the flowcharts.
[0079] These computer program instructions may also be stored on a computer-readable storage medium that can cause a computer or other programmable data processing apparatus to operate in a particular manner, such that the instructions stored on the computer-readable storage medium produce an article of manufacture including an instruction device that implements the functions specified in the flowchart or flowcharts and / or block or blocks of the block diagrams.
[0080] These computer program instructions may also be loaded into a computer or other programmable data processing apparatus, causing the computer or other programmable apparatus to execute a series of operational steps to generate a computer-implemented process, whereby the instructions executing on the computer or other scientific programmable device provide steps for implementing the functions specified in one or more flows in the flowcharts and / or in one or more blocks in the block diagrams.
[0081] It should be pointed out that the above are preferred embodiments of the present disclosure, and some improvements and refinements can be made by those skilled in the art without departing from the principle of the present disclosure, which should be regarded as the protection scope of the present disclosure.
Claims
1. 1. A method of identifier processing performed by a first device, the method comprising: receiving a first message transmitted from a user equipment (UE), the first message being accompanied by a first identifier; sending a second message to the second device to obtain the first key if the first key has not been queried based on the first identifier, and / or sending a third message to the third device if the first key has been queried based on the first identifier.
2. The third message is 2. The method of claim 1, including at least one of the first identifier, the first key, a second key derived from the first key, information obtained by encrypting the first key, and information obtained by encrypting the second key.
3. After sending a second message to the second device to obtain the first key, the method further comprises: The method of claim 1 , comprising transmitting a fourth message to the UE.
4. the fourth message is used to indicate successful processing of the first message, or successful retrieval of the first key by the first device, or successful retrieval of the first key by the first device and successful verification of the first message; and / or 4. The method of claim 3, wherein the fourth message is used to indicate a failure in processing the first message, or a failure in retrieving the first key by the first device, or a failure in verifying the first message while successfully retrieving the first key by the first device.
5. the first device is a Network Application Function (NAF) network element or an Authentication Agent (AP) network element, and the first identifier is a Bootstrapping Transaction Identifier (B-TID); Sending a second message to the second device to obtain the first key if the second device has not queried the first key based on the first identifier and / or sending a third message to the third device if the first key has been queried based on the first identifier includes:
2. The method of claim 1, further comprising: determining a third phase of an extended Generic Bootstrapping Architecture (GBA) transaction flow if the first key has not been queried based on the B-TID and sending a second message to a Bootstrapping Service Function (BSF) network element to obtain the first key; and / or determining a fourth phase of an extended GBA transaction flow if the first key has been queried based on the B-TID and sending a third message to the application server.
6. the first identifier is an Application Layer Identity Verification and Key Management (AKMA)-Key Identifier (A-KID); Sending a second message to the second device to obtain the first key if the second device has not queried the first key based on the first identifier and / or sending a third message to the third device if the first key has been queried based on the first identifier includes:
10. The method of claim 1, further comprising: sending a second message to an AKMA Anchor Function (AAnF) network element to obtain the first key if the first key is not queried based on the A-KID; and / or sending a third message to an Application Function (AF) network element or an Application Server (AS) if the first key is queried based on the A-KID.
7. The third message includes the first identifier, and the method further comprises: receiving a fifth message requesting the key sent from the third device; sending a sixth message to the third device; 3. The method of claim 2, wherein the sixth message includes at least one of the first key, a second key derived from the first key, information obtained by encrypting the first key, and information obtained by encrypting the second key.
8. a first device including a processor and a transceiver; the transceiver transmits and receives data under the control of a processor; The processor: receiving a first message transmitted from a user equipment (UE), the first message being accompanied by a first identifier; If the first key has not been queried based on the first identifier, sending a second message to the second device to obtain the first key, and / or if the first key has been queried based on the first identifier, sending a third message to the third device.
9. The third message is The device of claim 8 , comprising at least one of the first identifier, the first key, a second key derived from the first key, information obtained by encrypting the first key, and information obtained by encrypting the second key.
10. The device of claim 8 , wherein the processor is further adapted to perform transmitting a fourth message to the UE.
11. the fourth message is used to indicate successful processing of the first message, or successful retrieval of the first key by the first device, or successful retrieval of the first key by the first device and successful verification of the first message; and / or 11. The device of claim 10, wherein the fourth message is used to indicate a failure in processing the first message, or a failure in retrieving the first key by the first device, or a failure in verifying the first message while successfully retrieving the first key by the first device.
12. the first device is a Network Application Function (NAF) network element or an Authentication Agent (AP) network element, and the first identifier is a Bootstrapping Transaction Identifier (B-TID); The processor further comprises: If the first key has not been queried based on the B-TID, determining that the process is in a third phase of the extended Generic Bootstrapping Architecture (GBA) workflow and sending a second message to the Bootstrapping Service Function (BSF) to obtain the first key; and / or The device of claim 8, which is used to determine that the fourth stage of the extended GBA business flow is reached when querying the first key based on the B-TID, and to perform sending a third message to the application server.
13. the first identifier is an Application Layer Identity Verification and Key Management (AKMA)-Key Identifier (A-KID), and the processor further: If the first key has not been queried based on the A-KID, sending a second message to an AKMA Anchor Function (AAnF) network element to obtain the first key; and / or The device of claim 8, adapted to perform sending a third message to an application function (AF) or an application server (AS) when querying the first key based on the A-KID.
14. The third message includes the first identifier, and the processor further: receiving a fifth message requesting the key sent from the third device; and transmitting a sixth message to the third device; 10. The device of claim 9, wherein the sixth message includes at least one of the first key, a second key derived from the first key, information obtained by encrypting the first key, and information obtained by encrypting the second key.
15. a first device including a memory, a processor, and a program stored in the memory and executable on the processor; A first device that implements the identifier processing method according to any one of claims 1 to 7 when the processor executes the program.
16. A computer-readable storage medium on which a computer program is stored, A computer-readable storage medium that, when the program is executed by a processor, implements the steps of the identifier processing method according to any one of claims 1 to 7.
17. 1. A computer program product comprising instructions, A computer program product, wherein the instructions, when executed by a processor, cause the processor to perform the steps of the identifier processing method of any one of claims 1 to 7.
Citation Information
Patent Citations
An identity web service framework system and authentication method thereof
WO2007104245A1