Method, device and storage medium for authentication of NSWO services
The method addresses the challenge of authenticating NSWO services in 5G networks by using the EAP-AKA' authentication algorithm within the authentication process, ensuring compatibility with varying network architectures and avoiding authentication failures.
Patent Information
- Application Number
- JP2023568581
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Priority Date
- 2021-05-08
- Filing Date
- 2022-05-07
- Publication Date
- 2025-05-22
- Estimated Expiration
- 2042-05-07
AI Technical Summary
The challenge of implementing authentication for Non-Seamless Wireless Local Area Network Offload (NSWO) services in 5G networks, where different devices and authentication algorithms are used compared to 4G networks, necessitates a method to ensure seamless authentication across varying network architectures.
A method for authenticating NSWO services in 5G networks involves sending a SUCI to an access network device, receiving a third authentication request message using the EAP-AKA' authentication algorithm, performing authentication verification, and subsequently sending a fourth authentication request message. This method utilizes network elements like UE, AN device, NSWO network element, AUSF, and UDM to ensure authentication is performed using the appropriate EAP-AKA' authentication method.
The proposed method effectively implements authentication for NSWO services in 5G networks, avoiding authentication failures caused by selecting the 5G AKA authentication method, and ensures compatibility with the different devices and authentication algorithms supported by 5G networks.
Smart Images

Figure 0007681725000004 
Figure 0007681725000005 
Figure 0007681725000006
Abstract
Description
[Technical field]
[0002] TECHNICAL FIELD Embodiments of the present application relate to the field of communication technologies, and in particular to a method, device, and storage medium for authentication of NSWO services. [Background technology]
[0003] In the fourth generation (4G) communication system network, the third generation partnership project (3GPP) has introduced a non-seamless wireless local area network offload (NSWO) service. When a terminal device performs an NSWO service, service data can be offloaded by using an access network (AN) device to directly access the Internet.
[0004] Before the terminal device performs the NSWO service, the AN device, a 3GPP authentication, authorization and accounting (AAA) server, and a home subscriber server (HSS) need to complete authentication for the terminal device. It can be understood that the AN device completes the authentication on the terminal device by using an operator. The AN device provides the NSWO service to the terminal device only after the operator successfully performs authentication on the terminal device.
[0005] With the development of communication technology, the fifth generation (5G) communication system network also supports NSWO service. The 5G network and the 4G network may include different devices. For example, the 5G network may not include a 3GPP AAA server. In addition, the 5G network and the 4G network support different authentication algorithms. Therefore, how to implement authentication on a terminal device for the NSWO service in the 5G network needs to be urgently solved. Summary of the Invention [Means for solving the problem]
[0006] Embodiments of the present application provide a method, device, and storage medium for authentication of NSWO services to implement authentication on a terminal device for NSWO services in a 5G network or the like.
[0007] According to a first aspect, there is provided a method for authentication of an NSWO service, the method including: after a terminal device decides to perform an NSWO service, sending a SUCI to an access network device; receiving a third authentication request message sent by an NSWO network element via the access network device, where the third authentication request message is an authentication request message corresponding to an EAP-AKA' authentication algorithm; performing authentication verification on a network by using the EAP-AKA' authentication algorithm; and after the authentication verification is successful, sending a fourth authentication request message to the NSWO network element via the access network device.
[0008] The method for authentication of the NSWO service provided in the first aspect can be applied to a terminal device or a UE. The relevant network elements in the complete authentication procedure for the NSWO service include a UE, an AN device, an NSWO network element, an AUSF, and a UDM. After deciding to perform the NSWO service, the UE starts the authentication procedure of the NSWO service. In the authentication process, it is decided to use the EAP-AKA' authentication method, thereby avoiding the authentication failure caused by selecting the 5G AKA authentication method, and implementing the authentication of the NSWO service in the 5G network, etc.
[0009] In a possible implementation form, a type of SUPI included in the SUCI indicates that authentication of an NSWO service is to be performed, and / or the SUCI includes service instruction information, and the service instruction information indicates that authentication of an NSWO service is to be performed.
[0010] In this implementation, the AN device, the NSWO network element, the AUSF, or the UDM can directly decide to perform authentication for the NSWO service based on the SUCI.
[0011] In a possible implementation form, before receiving the third authentication request message sent by the NSWO network element through the access network device, the method further includes sending a first NSWO indication information to the access network device, the first NSWO indication information indicating to perform authentication of the NSWO service.
[0012] In this implementation, the AN device, the NSWO network element, the AUSF, or the UDM can directly decide to perform authentication for the NSWO service based on the first NSWO indication information.
[0013] In a possible implementation form, the first NSWO indication information and the SUCI are in one message.
[0014] In this implementation, the first NSWO indication information and the SUCI are carried in one message, thereby reducing the amount of air interface messages.
[0015] In one possible implementation, after the authentication verification is successful, the method includes: calculating keys CK' and IK', deleting keys CK' and IK', calculating keys CK' and IK', deleting keys K and K ... AUSF Stop computing the key K AUSF is calculated based on the keys CK' and IK', and then the keys CK' and IK' are deleted, the keys CK' and IK' are calculated, and the key K is calculated based on the keys CK' and IK'. AUSF Then, delete the keys CK' and IK' and calculate the key K AUSF or delete the key K stored locally on the terminal device. AUSF or ceasing to calculate the key CK' and the key IK' after the authentication verification is successful.
[0016] In this implementation, after successfully completing the authentication verification on the network, the UE does not need to calculate the key CK' or the key IK', or can simply use the calculated key CK' and the key IK' or the key K. AUSF or key K AUSF After is calculated, the newly generated key K AUSF is a locally existing key K AUSF , thereby avoiding any impact on the existing key architecture of the UE.
[0017] In a possible implementation form, before the terminal device decides to perform the NSWO service, the method further includes receiving second NSWO indication information sent by the access network device, where the second NSWO indication information indicates that the access network device supports the NSWO service, and determining based on the second NSWO indication information whether to perform authentication based on a 5G key, or based on the SIM, or based on a key used for initial user authentication.
[0018] In this implementation, the AN device sends second NSWO indication information to the UE to notify the UE that the AN device supports the NSWO service, so that authentication of the NSWO service can be implemented.
[0019] In a possible implementation, sending the SUCI to the access network device may include sending a connection establishment request message to the access network device. The connection establishment request message includes the SUCI and the first NSWO indication information.
[0020] In this implementation, after determining to perform the NSWO service, the UE accesses the AN to establish a connection. The connection establishment request message carries both the SUCI and the first NSWO indication information to initiate the authentication procedure of the NSWO service, thereby reducing the amount of air interface messages.
[0021] In a possible implementation, sending the SUCI to the access network device may include receiving a first request message sent by the access network device and sending a first response message to the access network device, the first response message including the first NSWO indication information and the SUCI.
[0022] In this implementation, the AN device sends a first request message to the UE to trigger the UE to perform EAP authentication. After deciding to perform the NSWO service, the UE receives the first request message, decides to perform EAP authentication, and decides to perform authentication for the NSWO service.
[0023] According to a second aspect, a method is provided for authentication of an NSWO service, the method including: receiving a SUCI sent by a terminal device; determining an address of an NSWO network element based on the SUCI; sending a second request message to the NSWO network element based on the address of the NSWO network element, where the second request message includes the SUCI; receiving a third authentication request message sent by the NSWO network element, where the third authentication request message is an authentication request message corresponding to an EAP-AKA' authentication algorithm; sending the third authentication request message to the terminal device; receiving a fourth authentication request message sent by the terminal device; and sending the fourth authentication request message to the NSWO network element.
[0024] The method for authentication of the NSWO service provided in the second aspect can be applied to an AN device. The relevant network elements in the complete authentication procedure for the NSWO service include a UE, an AN device, an NSWO network element, an AUSF, and a UDM. In the authentication procedure of the NSWO service, it is decided to use the EAP-AKA' authentication method, thereby avoiding the authentication failure caused by selecting the 5G AKA authentication method, and implementing the authentication of the NSWO service in the 5G network, etc.
[0025] In a possible implementation form, a type of SUPI included in the SUCI indicates that authentication of an NSWO service is to be performed, and / or the SUCI includes service instruction information, and the service instruction information indicates that authentication of an NSWO service is to be performed.
[0026] In a possible implementation form, before determining the address of the NSWO network element based on the SUCI, the method further includes receiving a first NSWO indication information sent by the terminal device, the first NSWO indication information indicating to perform authentication of the NSWO service.
[0027] In a possible implementation form, the first NSWO indication information and the SUCI are in one message.
[0028] In a possible implementation form, the second request message further includes the first NSWO indication information.
[0029] In this implementation, the NSWO network element, the AUSF, or the UDM may directly decide to perform authentication for the NSWO service based on the first NSWO indication information.
[0030] In a possible implementation form, the second request message further includes third NSWO indication information, and the third NSWO indication information indicates to perform authentication of the NSWO service.
[0031] In this implementation, the NSWO network element, the AUSF, or the UDM can directly decide to perform authentication of the NSWO service based on the third NSWO indication information.
[0032] In a possible implementation form, before receiving the SUCI sent by the terminal device, the method further includes sending a second NSWO indication information to the terminal device, the second NSWO indication information indicating that the access network device supports the NSWO service.
[0033] In a possible implementation, the second request message further includes an access network identity of the access network device.
[0034] In this implementation, the access network identity may be used by the NSWO network element to send a first identification information of the AN device to the AUSF, so that the UDM ultimately uses the first identification information when calculating the EAP-AKA' authentication vector.
[0035] In a possible implementation form, determining the address of the NSWO network element based on the SUCI includes obtaining a target network identifier and / or a target routing identifier from the SUCI, and obtaining an address of the NSWO network element corresponding to the target network identifier and / or the target routing identifier based on a mapping relationship between the network identifier and / or the routing identifier and the NSWO network element address.
[0036] In a possible implementation, determining the address of the NSWO network element based on the SUCI includes obtaining a target network identifier and / or a target routing identifier from the SUCI, sending the target network identifier and / or the target routing identifier to a first address management network element, and receiving the address of the NSWO network element sent by the first address management network element.
[0037] In a possible implementation, receiving the SUCI sent by the terminal device includes receiving a connection establishment request message sent by the terminal device. The connection establishment request message includes the SUCI and the first NSWO indication information.
[0038] In a possible implementation, receiving the SUCI sent by the terminal device includes sending a first request message to the terminal device and receiving a first response message sent by the terminal device, the first response message including the first NSWO indication information and the SUCI.
[0039] According to a third aspect, there is provided a method for authentication of an NSWO service, the method including: receiving a second request message sent by an access network device, the second request message including a SUCI of a terminal device; determining to perform authentication of an NSWO service based on the second request message; sending a first authentication request message to an AUSF, the first authentication request message including a SUCI; receiving a first authentication response message sent by the AUSF, the first authentication response message being an authentication response message corresponding to an EAP-AKA' authentication algorithm; sending a third authentication request message to the access network device based on the first authentication response message, the third authentication request message being an authentication request message corresponding to the EAP-AKA' authentication algorithm; receiving a fourth authentication request message sent by the access network device; and sending a fifth authentication request message to the AUSF based on the fourth authentication request message.
[0040] The method for authentication of the NSWO service provided in the third aspect can be applied to the NSWO network element. The relevant network elements in the complete authentication procedure for the NSWO service include a UE, an AN device, an NSWO network element, an AUSF, and a UDM. In the authentication procedure of the NSWO service, it is decided to use the EAP-AKA' authentication method, thereby avoiding the authentication failure caused by selecting the 5G AKA authentication method, and implementing the authentication of the NSWO service in the 5G network, etc.
[0041] In a possible implementation form, deciding to perform authentication of the NSWO service based on the second request message includes at least one of the following cases: deciding to perform authentication of the NSWO service based on NSWO indication information included in the second request message, deciding to perform authentication of the NSWO service based on SUCI, or determining an address or access network identity of the access network device based on the second request message and determining that the access network device supports the NSWO service based on the address or access network identity of the access network device, and then deciding to perform authentication of the NSWO service.
[0042] In a possible implementation form, a type of SUPI included in the SUCI indicates that authentication of an NSWO service is to be performed, and / or the SUCI includes service instruction information, and the service instruction information indicates that authentication of an NSWO service is to be performed.
[0043] In a possible implementation form, the first authentication request message further includes fourth NSWO indication information, and the fourth NSWO indication information indicates to perform authentication of the NSWO service.
[0044] In this implementation, the AUSF or UDM can directly decide to perform authentication of the NSWO service based on the fourth NSWO indication information.
[0045] In a possible implementation, the first authentication request message further includes one of the following: an access network identity of the access network device carried in the second request message, a serving network name corresponding to the access network identity of the access network device, an access network identity determined based on related information of the access network device, a pre-configured access network identity indicating to perform authentication of the NSWO service, or a pre-configured serving network name indicating to perform authentication of the NSWO service.
[0046] In a possible implementation, the second authentication request message further includes a second identification information of the access network device, where the access network device is an access network device connected to the terminal device. The second identification information includes the first information or the first identification information carried in the first authentication request message. If the first identification information carried in the first authentication request message is an access network identity of the access network device, the first information is a serving network name corresponding to the access network identity. If the first authentication request message does not carry the first identification information, the first information is a pre-configured access network identity or a pre-configured serving network name. Both the pre-configured access network identity and the pre-configured serving network name indicate authentication of the NSWO service.
[0047] In a possible implementation form, the first authentication request message is an authentication service request message for UE authentication, and the first authentication response message is an authentication service response message for UE authentication.
[0048] In a possible implementation form, both the first authentication request message and the first authentication response message are messages corresponding to a newly added AUSF service, and the newly added AUSF service indicates that authentication is to be performed for an NSWO service.
[0049] In this implementation, the AUSF can directly decide to perform authentication of the NSWO service based on the newly added AUSF service.
[0050] According to a fourth aspect, there is provided a method for authentication of an NSWO service, the method including: receiving a first authentication request message sent by an NSWO network element, the first authentication request message including a SUCI; determining to perform authentication of the NSWO service based on the first authentication request message; sending a second authentication request message to a UDM, the second authentication request message including a SUCI; receiving a second authentication response message sent by the UDM, the second authentication response message including a second EAP-AKA' authentication vector; sending a first authentication response message to the NSWO network element based on the second authentication response message, the first authentication response message being an authentication response message corresponding to an EAP-AKA' authentication algorithm; receiving a fifth authentication request message sent by the NSWO network element; and performing authentication of the terminal device based on the fifth authentication request message.
[0051] The method for authentication of the NSWO service provided in the fourth aspect can be applied to the AUSF. The relevant network elements in the complete authentication procedure for the NSWO service include the UE, the AN device, the NSWO network element, the AUSF, and the UDM. In the authentication procedure of the NSWO service, it is decided to use the EAP-AKA' authentication method, thereby avoiding the authentication failure caused by selecting the 5G AKA authentication method, and implementing the authentication of the NSWO service in the 5G network, etc.
[0052] In a possible implementation form, deciding to perform authentication of the NSWO service based on the first authentication request message includes at least one of the following cases: deciding to perform authentication of the NSWO service based on NSWO instruction information included in the first authentication request message, where the NSWO instruction information indicates that authentication of the NSWO service is to be performed; deciding to perform authentication of the NSWO service if it is determined that the first authentication request message is a request message corresponding to an AUSF service of a newly added authentication server function, where the newly added AUSF service indicates that authentication of the NSWO service is to be performed; deciding to perform authentication of the NSWO service based on SUCI; or determining a type or address of an NSWO network element based on the first authentication request message and determining that the NSWO network element supports the NSWO service based on the type or address of the NSWO network element, and then deciding to perform authentication of the NSWO service.
[0053] In a possible implementation form, a type of SUPI included in the SUCI indicates that authentication of an NSWO service is to be performed, and / or the SUCI includes service instruction information, and the service instruction information indicates that authentication of an NSWO service is to be performed.
[0054] In a possible implementation form, the second authentication request message further includes fifth NSWO indication information, and the fifth NSWO indication information indicates to perform authentication of the NSWO service.
[0055] In this implementation, the second authentication request message carries the fifth NSWO indication information, so that the UDM can directly decide to perform authentication of the NSWO service.
[0056] In a possible implementation form, after determining to perform authentication of the NSWO service based on the first authentication request message, the method further includes determining to use an EAP-AKA' authentication algorithm. Correspondingly, the second authentication request message further includes algorithm indication information, where the algorithm indication information indicates to perform EAP-AKA' authentication.
[0057] In this implementation, the second authentication request message carries algorithm indication information, so that the UDM can directly decide to use the EAP-AKA' authentication algorithm, thereby simplifying the processing of the UDM.
[0058] In a possible implementation, the first authentication request message further includes a first identification information of the access network device, where the access network device is an access network device connected to the terminal device, and the first identification information includes one of the following: an access network identity of the access network device, a serving network name corresponding to the access network identity of the access network device, a pre-configured access network identity indicating to perform authentication of the NSWO service, or a pre-configured serving network name indicating to perform authentication of the NSWO service.
[0059] In this implementation, the first identity may be used by the AUSF to send a second identity of the AN device to the UDM, so that the UDM ultimately uses the second identity when calculating the EAP-AKA' authentication vector.
[0060] In a possible implementation, the second authentication request message further includes a second identification information of the access network device, where the access network device is an access network device connected to the terminal device. The second identification information includes the first information or the first identification information carried in the first authentication request message. If the first identification information carried in the first authentication request message is an access network identity of the access network device, the first information is a serving network name corresponding to the access network identity. If the first authentication request message does not carry the first identification information, the first information is a pre-configured access network identity or a pre-configured serving network name. Both the pre-configured access network identity and the pre-configured serving network name indicate authentication of the NSWO service.
[0061] In this implementation, the second identity may be used when the UDM later calculates the EAP-AKA' authentication vector.
[0062] In a possible implementation form, the first authentication request message is an authentication service request message for UE authentication, and the first authentication response message is an authentication service response message for UE authentication.
[0063] In a possible implementation form, both the first authentication request message and the first authentication response message are messages corresponding to a newly added AUSF service, and the newly added AUSF service indicates that authentication is to be performed for an NSWO service.
[0064] In a possible implementation form, the second authentication request message is a service acquisition request message for UE authentication, and the second authentication response message is a service acquisition response message for UE authentication.
[0065] In a possible implementation form, both the second authentication request message and the second authentication response message are messages corresponding to a newly added UDM service, and the newly added UDM service indicates that it will authenticate the NSWO service.
[0066] In this implementation, the UDM can directly decide to perform authentication of the NSWO service based on the newly added UDM service.
[0067] In a possible implementation, the second authentication response message further includes a SUPI of the terminal device. The method further includes sending a first NSWO authentication result to the UDM after the authentication performed on the terminal device based on the fifth authentication request message is successful. The first NSWO authentication result includes the SUPI, and / or an access network identity of the access network device, and / or a serving network name corresponding to the access network identity, and the access network device is an access network device connected to the terminal device.
[0068] In this implementation, after determining that the authentication performed on the UE for the NSWO service is successful, the AUSF may notify the UDM of the successfully authenticated UE and / or the AN device accessed by the successfully authenticated UE, so that the UDM may record the successfully authenticated UE and / or the AN device accessed by the successfully authenticated UE and subsequently complete charging for the UE or AN device.
[0069] In a possible implementation form, the first NSWO authentication result further includes authentication indication information, where the authentication indication information indicates that the authentication performed on the terminal device for the NSWO service was successful.
[0070] In a possible implementation form, the first NSWO authentication result is included in a UE authentication result confirmation message.
[0071] In a possible implementation, the second EAP-AKA' authentication vector does not include key CK' or key IK', and the first authentication response message includes the second EAP-AKA' authentication vector.
[0072] In a possible implementation, the second EAP-AKA' authentication vector includes the key CK' and the key IK', and the first authentication response message includes the second EAP-AKA' authentication vector.
[0073] In a possible implementation, the second EAP-AKA' authentication vector includes a key CK' and a key IK', and sending a first authentication response message to the NSWO network element based on the second authentication response message includes deleting the key CK' and the key IK' from the second EAP-AKA' authentication vector and sending the first authentication response message to the NSWO network element. The first authentication response message includes the second EAP-AKA' authentication vector with the keys deleted.
[0074] In this implementation, the AUSF deletes key CK' and key IK' from the second EAP-AKA' authentication vector, thereby preventing the newly generated key CK' and key IK' in the authentication process of the NSWO service from affecting related keys already generated in the existing authentication procedure.
[0075] In a possible implementation, after performing authentication on the terminal device based on the fifth authentication request message and after the keys CK′ and IK′ are received, the method further comprises: AUSF , and ceasing to compute the key K AUSF is calculated based on the key CK' and the key IK', or is calculated based on the key CK' and the key IK'. AUSF and calculates the key K AUSF It further includes ceasing to replace.
[0076] In this implementation, the AUSF generates a new key K AUSF or a new key K AUSFNo substitution is performed after computing the newly generated key K AUSF does not affect any associated keys generated by the AUSF in existing authentication procedures.
[0077] In a possible implementation, the method includes deleting the keys CK′ and IK′ and / or deleting the key K AUSF The method further includes:
[0078] In this implementation, the AUSF deletes the newly generated key in the authentication process of the NSWO service, thereby preventing the newly generated key from affecting the related key generated by the AUSF in the existing authentication procedure.
[0079] In a possible implementation, the method further includes, if authentication on the terminal device based on the fifth authentication request message is successful, sending a second NSWO authentication result to the charging NF, where the second NSWO authentication result includes a SUPI of the terminal device, and / or an access network identity of the access network device, and / or a serving network name corresponding to the access network identity, the SUPI being included in the second authentication response message, and the access network device is an access network device connected to the terminal device.
[0080] In this implementation, after determining that the authentication performed on the UE for the NSWO service is successful, the AUSF may notify the charging NF of the successfully authenticated UE and / or the AN device accessed by the successfully authenticated UE, so that the charging NF subsequently completes charging for the UE or the AN device.
[0081] According to a fifth aspect, there is provided a method for authentication of an NSWO service, including: receiving a second authentication request message sent by an AUSF, where the second authentication request message includes a SUCI, calculating a SUPI based on the SUCI, determining to use an EAP-AKA' authentication method based on the second authentication request message, obtaining a first EAP-AKA' authentication vector based on the SUPI, and sending a second authentication response message to the AUSF, where the second authentication response message includes the second EAP-AKA' authentication vector.
[0082] The method for authentication of the NSWO service provided in the fifth aspect can be applied to the UDM. The relevant network elements in the complete authentication procedure for the NSWO service include the UE, the AN device, the NSWO network element, the AUSF, and the UDM. In the authentication procedure of the NSWO service, the UDM decides to use the EAP-AKA' authentication method, thereby avoiding the authentication failure caused by selecting the 5G AKA authentication method, and implementing the authentication of the NSWO service in the 5G network, etc.
[0083] In a possible implementation, determining to use the EAP-AKA' authentication method based on the second authentication request message includes at least one of the following cases: determining to perform authentication of the NSWO service if it is determined that the second authentication request message is a request message corresponding to a newly added UDM service, where the newly added UDM service indicates to perform authentication of the NSWO service, or determining to use the EAP-AKA' authentication method based on second information in the second authentication request message. The second information includes at least one of the following: the second information is NSWO indication information, where the NSWO indication information indicates to perform authentication of the NSWO service, the second information is SUCI, where the SUCI indicates to perform authentication of the NSWO service, or the second information is algorithm indication information, where the algorithm indication information indicates to perform EAP-AKA' authentication.
[0084] In a possible implementation form, a type of SUPI included in the SUCI indicates that authentication of an NSWO service is to be performed, and / or the SUCI includes service instruction information, and the service instruction information indicates that authentication of an NSWO service is to be performed.
[0085] In a possible implementation, the second EAP-AKA' authentication vector does not include key CK' or key IK'.
[0086] In this implementation, key CK' and key IK' are removed and not sent to the AUSF, thereby preventing the newly generated key CK' and key IK' in the authentication process of the NSWO service from affecting related keys already generated by the UE or AUSF in the existing authentication procedure.
[0087] In a possible implementation, the second authentication request message further includes a second identification information of the access network device, where the access network device is an access network device connected to the terminal device. The second identification information includes the first information or the first identification information carried in the first authentication request message. The first authentication request message is a message sent by the NSWO network element to the AUSF. If the first identification information carried in the first authentication request message is an access network identity of the access network device, the first information is a serving network name corresponding to the access network identity. If the first authentication request message does not carry the first identification information, the first information is a pre-configured access network identity or a pre-configured serving network name. Both the pre-configured access network identity and the pre-configured serving network name indicate to perform authentication of the NSWO service.
[0088] In a possible implementation form, the second authentication request message is a service acquisition request message for UE authentication, and the second authentication response message is a service acquisition response message for UE authentication.
[0089] In a possible implementation form, both the second authentication request message and the second authentication response message are messages corresponding to a newly added UDM service, and the newly added UDM service indicates that it will authenticate the NSWO service.
[0090] In this implementation, the UDM can directly decide to perform authentication of the NSWO service based on the newly added UDM service.
[0091] In a possible implementation, the method further includes receiving a first NSWO authentication result sent by the AUSF, where the first NSWO authentication result includes a SUPI, and / or an access network identity of the access network device, and / or a serving network name corresponding to the access network identity, where the access network device is an access network device connected to the terminal device, and the first NSWO authentication result indicates that authentication performed on the terminal device for the NSWO service was successful.
[0092] In a possible implementation form, the first NSWO authentication result further includes authentication indication information, where the authentication indication information indicates that the authentication performed on the terminal device for the NSWO service was successful.
[0093] In a possible implementation form, the first NSWO authentication result is included in a UE authentication result confirmation message.
[0094] According to a sixth aspect, there is provided an apparatus comprising units or means configured to perform the steps of any one of the preceding aspects.
[0095] According to a seventh aspect, a communication apparatus is provided. The communication apparatus includes a processor, a memory, and a transceiver. The transceiver is configured to communicate with another device, and the processor is configured to read instructions in the memory and to enable the communication apparatus to perform a method provided in any one of the previous aspects according to the instructions.
[0096] According to an eighth aspect, there is provided a program, the program being configured, when executed by a processor, to perform a method as provided in any one of the previous aspects.
[0097] According to a ninth aspect, a computer-readable storage medium is provided, the computer-readable storage medium storing instructions which, when executed on a computer or processor, implement the method provided in any one of the previous aspects.
[0098] According to a tenth aspect, there is provided a program product, the program product including a computer program, the computer program being stored in a readable storage medium, and at least one processor of a device being capable of reading the computer program from the readable storage medium, and the at least one processor executing the computer program to enable the device to implement the method provided in any one of the preceding aspects. [Brief description of the drawings]
[0099] [Figure 1] FIG. 1 is a diagram of a 4G network architecture according to an embodiment of the present application. [Diagram 2] FIG. 1 is a diagram of a 5G network architecture according to an embodiment of the present application. [Diagram 3] 2 is a schematic diagram of relevant messages in a method for authentication of an NSWO service according to an embodiment of the present application; [Figure 4A] FIG. 2 is a message exchange diagram of a method for authentication of an NSWO service according to an embodiment of the present application. [Figure 4B] FIG. 2 is a message exchange diagram of a method for authentication of an NSWO service according to an embodiment of the present application. [Figure 5A] FIG. 2 is another diagram of a message exchange of a method for authentication of an NSWO service according to an embodiment of the present application. [Figure 5B] FIG. 2 is another diagram of a message exchange of a method for authentication of an NSWO service according to an embodiment of the present application. [Figure 6] FIG. 13 is yet another diagram of a message exchange of a method for authentication of an NSWO service according to an embodiment of the present application. [Figure 7] FIG. 13 is yet another diagram of a message exchange of a method for authentication of an NSWO service according to an embodiment of the present application. [Figure 8] FIG. 13 is yet another diagram of a message exchange of a method for authentication of an NSWO service according to an embodiment of the present application. [Figure 9] FIG. 13 is yet another diagram of a message exchange of a method for authentication of an NSWO service according to an embodiment of the present application. [Figure 10] FIG. 13 is yet another diagram of a message exchange of a method for authentication of an NSWO service according to an embodiment of the present application. [Figure 11] FIG. 13 is yet another diagram of a message exchange of a method for authentication of an NSWO service according to an embodiment of the present application. [Figure 12] FIG. 13 is yet another diagram of a message exchange of a method for authentication of an NSWO service according to an embodiment of the present application. [Figure 13] FIG. 13 is yet another diagram of a message exchange of a method for authentication of an NSWO service according to an embodiment of the present application. [Figure 14] 1 is a schematic diagram of the structure of a communication device according to an embodiment of the present application; [Figure 15] 1 is a schematic diagram of the structure of a communication device according to an embodiment of the present application; DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS
[0100] Hereinafter, embodiments of the present application will be described in detail with reference to the accompanying drawings.
[0101] The embodiments of the present application may be combined with each other, and the same or similar concepts or processes may not be repeatedly described in some embodiments. The terms "first," "second," "third," "fourth," etc. (if any) in the embodiments of the present application are used to distinguish similar objects, but do not necessarily describe a particular order or sequence.
[0102] The method for authenticating an NSWO service provided in the embodiment of the present application is applicable to the authentication procedure performed when a terminal device performs an NSWO service in a 5G network. First, the NSWO service, the 4G network architecture, and the 5G network architecture are described.
[0103] In order to implement interoperability between 3GPP networks and wireless local area networks (WLANs), the 3GPP organization defines a series of standard documents and network architectures. To allow user equipment (UE) to access packet switching domain (PS) services through WLAN networks, 3GPP AAA-related devices are introduced to implement access control and authentication based on 3GPP networks without modifying the existing architectures of 3GPP networks and WLAN networks.
[0104] For example, Figure 1 is a diagram of the architecture of a 4G network according to one embodiment of the present application. As shown in Figure 1, the 4G network includes non-3GPP networks, visited public land mobile networks (VPLMN), and home public land mobile networks (HPLMN). The non-3GPP networks include UEs, trusted non-3GPP access network devices, and untrusted non-3GPP access network devices. The VPLMN includes a 3GPP AAA proxy. The HPLMN includes a 3GPP AAA server and a home subscriber server (HSS). Please refer to Table 1 for a functional description of each device.
[0105] [Table 1]
[0106] It should be noted that other devices included in the 4G network are not limited to this embodiment of the present application.
[0107] 4G networks support NSWO services, which means that data used when a UE performs PS services can be offloaded by using an AN device to directly access the internet, for example, as shown by the dotted line in Figure 1.
[0108] Before the AN device determines whether to perform the NSWO service for the UE, the UE and the network side need to complete authentication of the NSWO service. As shown in FIG. 1, the authentication for the UE may be completed by using a trusted non-3GPP access network device, a 3GPP AAA proxy, a 3GPP AAA server, and an HSS. Alternatively, the authentication on the UE may be completed by using a non-trusted non-3GPP access network device, a 3GPP AAA proxy, a 3GPP AAA server, and an HSS. If the authentication for the UE is successful, the HSS and the 3GPP AAA server send an authentication result indicating that the authentication is successful to the AN device, so that the AN device performs the NSWO service for the UE. For example, the AN device assigns an internet protocol (IP) address of an external network to the UE so that the UE can connect to the Internet. The above authentication process may be understood as follows: that is, the AN device completes authentication for the UE by using an operator. The AN device provides the NSWO service for the UE only after the operator successfully performs authentication on the UE and determines that the UE is an authorized user of the operator.
[0109] Currently, in 4G networks, the key on which the authentication process is based is the key used during authentication to the UE for 3GPP network access, e.g., the key stored in the universal subscriber identity module (USIM). Authentication algorithms include the extensible authentication protocol-authentication and key agreement (EAP-AKA) authentication algorithm and the EAP-AKA' authentication algorithm.
[0110] With the development of communication technology, the 5G network also supports NSWO services. For example, Figure 2 is an architecture diagram of a 5G network according to an embodiment of the present application.
[0111] As shown in Figure 2, the 5G network includes a UE, an AN device, an NSWO network element, an authentication server function (AUSF), and a unified data management (UDM). Please refer to Table 2 for a functional description of each device.
[0112] [Table 2]
[0113] It should be noted that other devices included in the 5G network are not limited to this embodiment of the present application.
[0114] It may be known that the 5G network and the 4G network may include different devices. For example, as shown in FIG. 1 and FIG. 2, the 5G network may not include a 3GPP AAA server. In addition, the 5G network and the 4G network support different authentication algorithms. The 4G network supports the EAP-AKA authentication algorithm and the EAP-AKA' authentication algorithm, and the 5G network supports the EAP-AKA' authentication algorithm and the 5G AKA authentication algorithm. The 5G AKA authentication algorithm is not applicable to the existing access authentication of the AN device in the NSWO service scenario. Therefore, one embodiment of the present application provides an authentication procedure applicable when the UE performs the NSWO service in the 5G network.
[0115] The method for authentication of NSWO service provided in this embodiment of the present application involves a relatively large amount of network elements, and a relatively large amount of messages are exchanged between the network elements. For ease of understanding, the messages exchanged between the network elements are briefly described. For example, FIG. 3 is a message exchange diagram of the method for authentication of NSWO service according to one embodiment of the present application. It should be noted that FIG. 3 does not limit the names of the exchanged messages. As shown in FIG. 3, the relevant messages include:
[0116] 1. Messages when UE starts authentication At the stage where the UE initiates authentication, the UE and the AN device need to determine that both support the NSWO service. Optionally, the UE may initiate authentication of the NSWO service. For example, when it determines to perform the NSWO service, the UE may initiate authentication of the NSWO service. Optionally, the AN device may trigger the UE to initiate authentication of the NSWO service.
[0117] The message at the stage when the UE initiates authentication may include at least one of a connection establishment request message, a first request message, a first response message, or a broadcast message. A detailed description is provided below with reference to Figures 6 to 9.
[0118] 2. Second request message This is a message sent by the AN device to the NSWO network element to request authorization for the NSWO service, and contains the subscription concealed identifier (SUCI) of the UE.
[0119] Optionally, the second request message may be an AAA message.
[0120] 3. First authentication request message and first authentication response message The first authentication request message and the first authentication response message are a pair of messages exchanged between the NSWO network element and the AUSF. The first authentication request message and the first authentication response message are request messages and response messages corresponding to the AUSF service, respectively.
[0121] Optionally, the AUSF service is an existing service. For example, the existing AUSF service is an authentication service for UE authentication (Nausf_UEAuthentication_Authenticate). The first authentication request message is an authentication service request message for UE authentication (Nausf_UEAuthentication_Authenticate request), and the first authentication response message is an authentication service response message for UE authentication (Nausf_UEAuthentication_Authenticate response).
[0122] Optionally, the AUSF service may be a newly added service, and the newly added AUSF service indicates performing authentication of the NSWO service. The name of the newly added AUSF service and the names of the request message and the response message in the newly added AUSF service are not limited in this embodiment of the present application. For example, the name of the newly added AUSF service may be NSWO authentication service for UE authentication (Nausf_UEAuthentication_NSWO_Authenticate). The first authentication request message can be referred to as a NSWO authentication service request message for UE authentication (Nausf_UEAuthentication_NSWO_Authenticate request), and the first authentication response message can be referred to as a NSWO authentication service response message for UE authentication (Nausf_UEAuthentication_NSWO_Authenticate response).
[0123] 4. Second authentication request message and second authentication response message The second authentication request message and the second authentication response message are a pair of messages exchanged between the AUSF and the UDM. The second authentication request message and the second authentication response message are request and response messages corresponding to a UDM service, respectively.
[0124] Optionally, the UDM service is an existing service. For example, the existing UDM service is a service get for UE authentication (Nudm_UEAuthentication_Get). The second authentication request message is a service get request message for UE authentication (Nudm_UEAuthentication_Get request), and the second authentication response message is a service get response message for UE authentication (Nudm_UEAuthentication_Get response).
[0125] Optionally, the UDM service may be a newly added service, and the newly added UDM service indicates to perform authentication of the NSWO service. The name of the newly added UDM service and the names of the request message and the response message in the newly added UDM service are not limited in this embodiment of the present application. For example, the name of the newly added UDM service may be NSWO authentication service for UE authentication (Nudm_UEAuthentication_NSWO_Authenticate). The second authentication request message can be called NSWO authentication service request message for UE authentication (Nudm_UEAuthentication_NSWO_Authenticate request), and the second authentication response message can be called NSWO authentication service response message for UE authentication (Nudm_UEAuthentication_NSWO_Authenticate response).
[0126] 5. Third authentication request message and fourth authentication request message The third authentication request message and the fourth authentication request message are authentication-related messages sent between the UE and the NSWO network element by using the AN device, and are used by the UE to perform authentication verification on the network.
[0127] 6. Fifth Authentication Request Message This is a message sent by the NSWO network element to the AUSF and is used by the AUSF to perform authentication verification on the UE.
[0128] 7. First and second messages The AUSF sends a first message carrying an EAP authentication result to the NSWO network element. The NSWO network element sends a second message carrying the EAP authentication result to the AN device. The EAP authentication result notifies the AN device of authentication success or authentication failure.
[0129] It should be noted that in this embodiment of the present application, the contents contained in the first message and the second message are not limited, and the implementation form of the EAP authentication result is not limited, and may be related messages in the existing EAP-AKA' authentication procedure.
[0130] 8.NSWO Service Indication Messages and Rejection Messages If the EAP authentication result indicates successful authentication, the AN device may perform an NSWO service operation, for example, assigning an IP address to the UE for accessing an external network. The AN device sends an NSWO service indication message to the UE. Optionally, the NSWO service indication message may include at least one of the following: an IP address, an NSWO authorization indicator, or an authentication success indicator.
[0131] If the EAP authentication result indicates authentication failure, the AN device sends a rejection message to the UE, indicating that the UE's request to use the NSWO service is rejected.
[0132] It should be noted that the contents contained in the NSWO service indication message and the rejection message are not limited to this embodiment of the present application, and may be related messages in the existing EAP-AKA' authentication procedure.
[0133] The following describes related concepts in embodiments of the present application.
[0134] 1. Subscription permanent identifier (SUPI) In a 5G network, the actual identity of the UE may be referred to as SUPI, which is similar to the international mobile subscriber identity (IMSI). Generally, the SUPI does not appear on the air interface. The air interface refers to the radio interface between the UE and the network device.
[0135] 2.SUCI The SUCI is a ciphertext obtained after the UE encrypts and encapsulates the SUPI by using a key, and may be transmitted over the air interface. Correspondingly, the network device may decrypt the SUCI to obtain the SUPI to determine the identity of the UE.
[0136] Optionally, the SUCI is in a network access identifier (NAI) format.
[0137] Optionally, in one implementation, the SUCI may be an existing SUCI generated based on the SUPI, for example, a SUCI used in a 5G network.
[0138] Optionally, in another implementation, the SUCI indicates to authenticate the NSWO service, in which the AN device, the NSWO network element, the AUSF, or the UDM may decide to authenticate the NSWO service based on the SUCI.
[0139] Optionally, the type of SUPI included in the SUCI indicates that authentication of the NSWO service is to be performed.
[0140] Currently, for the types of SUPI, please refer to Table 3. SUPI type values 4 to 7 indicate reserved types. In this implementation, a new type of SUPI may be defined for the NSWO service, and the newly defined type of SUPI indicates authentication of the NSWO service. Optionally, the value of the newly defined type of SUPI may be any value from 4 to 7.
[0141] [Table 3]
[0142] For example, typeX is defined to indicate an NSWO service. An example of a SUCI in the NAI format is typeX.rid678.schid1.hnkey27.ecckey<ECC ephemeral public key> .cip<encryption of user17>.mac<MAC tag value> @example.com. Optionally, the value of X may be any value between 4 and 7.
[0143] Optionally, the SUCI includes service instruction information, where the service instruction information indicates to authenticate the NSWO service.
[0144] An example is used for illustration. For example, the SUCI example in the NAI format is: type0.NSWO indicator.rid678.schid1.hnkey27.ecckey<ECC ephemeral public key> .cip<encryption of user17>.mac<MAC tag value> The NSWO indicator is service indication information.
[0145] 3.NSWO instruction information The NSWO indication information indicates to perform authentication of the NSWO service. Optionally, the NSWO indication information may be carried in at least one of the following messages in FIG. 3: a message at the stage when the UE starts authentication, a second request message, a first authentication request message, or a second authentication request message.
[0146] In the communication process, after receiving the message, device A may send the message to device B. Optionally, device A may not process the message and send the message to device B transparently. Optionally, device A may process the message and send the processed message to device B. According to the processing manners of different devices, the NSWO indication information may be further refined; A first NSWO indication information, which is an NSWO indication information generated by the UE and sent to the AN device at the stage when the UE initiates authentication; A second NSWO indication information, which is an NSWO indication information generated by the AN device and sent to the UE at the stage when the UE initiates authentication, to inform the UE that the AN device supports the NSWO service; a third NSWO indication information, which is an NSWO indication information added by the AN device to the second request message; A fourth NSWO indication information, which is an NSWO indication information added to the first authentication request message by the NSWO network element; and The fifth NSWO indication information is added to the second authentication request message by the AUSF.
[0147] 4. First EAP-AKA' authentication vector and second EAP-AKA' authentication vector After receiving the second authentication request message, if it is decided to use the EAP-AKA' authentication algorithm, the UDM calculates an EAP-AKA' authentication vector, called the first EAP-AKA' authentication vector (RAND, AUTN, XRES, CK', IK'), which includes the key CK' and the key IK'.
[0148] The UDM sends a second authentication response message to the AUSF. The second authentication response message includes a second EAP-AKA' authentication vector. Optionally, the second EAP-AKA' authentication vector is the first EAP-AKA' authentication vector. Optionally, the second EAP-AKA' authentication vector is a portion obtained after the keys CK' and IK' are deleted from the first EAP-AKA' authentication vector, i.e., (RAND, AUTN, XRES).
[0149] The following describes the technical solutions of the present application in detail by using specific embodiments. The following embodiments can be combined with each other, and the same or similar concepts or processes may not be repeatedly described in some embodiments.
[0150] For ease of understanding, the same steps in the embodiments of this application use the same step numbers.
[0151] Please note that AN device has the same meaning as AN.
[0152] It should be noted that in an embodiment of the present application, the access network identity (AN ID) may be equivalent to the serving network name.
[0153] 4A and 4B are message exchange diagrams of a method for authentication of an NSWO service according to one embodiment of the present application. The method for authentication of an NSWO service provided in this embodiment is performed by a UE, an AN device, an NSWO network element, an AUSF, and a UDM. As shown in FIG. 4A and FIG. 4B, the method for authentication of an NSWO service provided in this embodiment may include the following steps:
[0154] Step 1: After the UE determines to perform the NSWO service, the UE sends a SUCI to the AN device. In response, the AN device receives the SUCI sent by the UE.
[0155] This step is related to the stage where the UE initiates authentication in Figure 3. For the SUCI, please refer to the above description. The details will not be described again in this specification. The UE sends the SUCI to the AN device, thereby initiating the authentication procedure of the NSWO service.
[0156] Optionally, the UE may further send a first NSWO indication information to the AN device, where the first NSWO indication information indicates to authenticate the NSWO service. Correspondingly, the AN device may further receive the first NSWO indication information sent by the UE.
[0157] The first NSWO indication information is sent, so that the AN device determines that authentication of the NSWO service needs to be performed based on the first NSWO indication information, thereby helping to distinguish different authentication procedures.
[0158] Optionally, the first NSWO indication information and the SUCI may be separately in different messages. Alternatively, the first NSWO indication information and the SUCI may be in one message.
[0159] The first NSWO indication information and the SUCI are sent by using one message, or the first NSWO indication information and the SUCI are sent separately by using different messages, thereby improving the diversity of message procedures. When the first NSWO indication information and the SUCI are sent by using one message, the amount of air interface messages is reduced.
[0160] It should be noted that the message type and the message name of the message carrying the SUCI and / or the first NSWO indication information are not limited in this embodiment. For example, the message type may be an EAP message.
[0161] Step 2: The AN device determines the address of the NSWO network element based on the SUCI.
[0162] Specifically, after receiving the SUCI sent by the UE, if the AN device decides to perform authentication for the NSWO service, the AN device determines the address of the NSWO network element based on the SUCI.
[0163] Optionally, in an implementation for the AN device to determine to perform authentication for the NSWO service, if the AN device supports the NSWO service by default, the AN device determines that authentication for the NSWO service needs to be performed when the AN device receives a SUCI sent by the UE. Optionally, in another implementation, if the SUCI indicates to perform authentication for the NSWO service, the AN device decides to perform authentication for the NSWO service. Optionally, in yet another implementation, if the AN device further receives first NSWO indication information, the AN device decides to perform authentication for the NSWO service based on the first NSWO indication information.
[0164] Optionally, in one implementation, the AN device determining the address of the NSWO network element based on the SUCI may include:
[0165] The AN device obtains a target network identifier and / or a target routing identifier from the SUCI. The target network identifier is an identifier of the UE's home network, e.g., a mobile country code (MCC) and a mobile network code (MNC). The target routing identifier (routing ID) is used to further select network elements involved in the UE authentication, e.g., to select an AUSF and / or a UDM.
[0166] The AN device obtains an address of the NSWO network element corresponding to the target network identifier and / or the target routing identifier based on a mapping relationship between the network identifier and / or the routing identifier and the NSWO network element address.
[0167] In this implementation, the AN device may locally store a mapping relationship between the network identifier and / or the routing identifier and the NSWO network element address. Optionally, the mapping relationship between the network identifier and / or the routing identifier and the NSWO network element address may include at least one of the following: a mapping relationship between the network identifier and the NSWO network element address, a mapping relationship between the routing identifier and the NSWO network element address, or a mapping relationship between the network identifier, the routing identifier, and the NSWO network element address. The implementation is easy.
[0168] Optionally, in another implementation, the AN device determining the address of the NSWO network element based on the SUCI may include:
[0169] The AN device obtains a target network identifier and / or a target routing identifier from the SUCI.
[0170] The AN device sends the target network identifier and / or the target routing identifier to the first address managing network element.
[0171] The AN device receives the address of the NSWO network element sent by the first address managing network element.
[0172] In this implementation, the AN device may not locally store the mapping relationship between the network identifier and / or the routing identifier and the NSWO network element address. The address of the NSWO network element is obtained from the first address managing network element by sending the target network identifier and / or the target routing identifier to the first address managing network element. The name of the first address managing network element is not limited in this embodiment. Optionally, the first address managing network element may locally store the mapping relationship between the network identifier and / or the routing identifier and the NSWO network element address.
[0173] Step 3: The AN device sends a second request message to the NSWO network element based on the address of the NSWO network element. The second request message includes the SUCI. In response, the NSWO network element receives the second request message sent by the AN device.
[0174] Optionally, the second request message may further include NSWO indication information. Optionally, the NSWO indication information may include at least one of the following: first NSWO indication information or third NSWO indication information. That is, the NSWO indication information is the first NSWO indication information, or the NSWO indication information is the third NSWO indication information, or the NSWO indication information includes the first NSWO indication information and the third NSWO indication information. For the first NSWO indication information and the third NSWO indication information, please refer to the previous description in this application. The details will not be described again in this specification. For example, the UE sends an EAP-RSP message to the AN device. The EAP-RSP message carries the SUCI. The EAP-RSP message may include the first NSWO indication information or may not include the first NSWO indication information. After receiving the EAP-RSP message, the AN device may add a third NSWO indication information outside the EAP-RSP message.
[0175] The second request message carries NSWO indication information, so that the NSWO network element determines that authentication of the NSWO service needs to be performed based on the NSWO indication information, thereby helping to distinguish different authentication procedures.
[0176] Optionally, the second request message may further include an access network identity (AN ID) of the AN device. Optionally, the AN ID is then used by the NSWO network element to send the first identification information of the AN device to the AUSF. For details, see step 5.
[0177] Step 4: The NSWO network element decides to perform authentication for the NSWO service based on the second request message.
[0178] Optionally, in one implementation, the AN device may support the NSWO service by default, and when the second request message is received from the AN device, it may be determined to perform authentication of the NSWO service.
[0179] In some cases, in another implementation, it may be determined that the NSWO network element supports the NSWO service by default and performs authentication of the NSWO service when the second request message is received from the AN device.
[0180] Optionally, in yet another implementation, it may be determined to perform authentication of the NSWO service according to the NSWO indication information included in the second request message.For the NSWO indication information included in the second request message, please refer to the relevant description of step 3. Details will not be described again in this specification.
[0181] Optionally, in yet another implementation, it may be determined to authenticate the NSWO service based on the SUCI, in which the SUCI indicates that the NSWO service is to be authenticated.
[0182] Optionally, in yet another implementation, an address or an access network identity of the AN device may be determined based on the second request message, and after it is determined that the AN device supports the NSWO service based on the address or access network identity of the AN device, it is determined to perform authentication for the NSWO service.
[0183] Optionally, in yet another implementation, the NSWO network element may transparently send a second request message, and when the second request message is received from the AN device, it may be determined to perform authentication of the NSWO service.
[0184] Step 5: The NSWO network element sends a first authentication request message to the AUSF. The first authentication request message includes the SUCI. In response, the AUSF receives the first authentication request message sent by the NSWO network element.
[0185] Specifically, after deciding to perform authentication for the NSWO service, the NSWO network element may determine the address of the AUSF based on the SUCI, and the NSWO network element sends a first authentication request message to the AUSF based on the address of the AUSF.
[0186] Optionally, in one implementation, the NSWO network element determining the address of the AUSF based on the SUCI may include:
[0187] The NSWO network element obtains a target network identifier and / or a target routing identifier from the SUCI. For the target network identifier, see the relevant description in step 2. The target routing identifier (routing ID) is used to determine the address of the AUSF or UDM.
[0188] The NSWO network element obtains the address of the AUSF corresponding to the target network identifier and / or the target routing identifier based on the mapping relationship between the network identifier and / or the routing identifier and the AUSF address.
[0189] In this implementation, the NSWO network element can locally store a mapping relationship between the network identifier and / or the routing identifier and the AUSF address. Optionally, the mapping relationship between the network identifier and / or the routing identifier and the AUSF address may include at least one of the following: a mapping relationship between the network identifier and the AUSF address, a mapping relationship between the routing identifier and the AUSF address, or a mapping between the network identifier, the routing identifier, and the AUSF address. The implementation is easy.
[0190] Optionally, in another implementation, the NSWO network element determining the address of the AUSF based on the SUCI may include:
[0191] The NSWO network element obtains a target network identifier and / or a target routing identifier from the SUCI.
[0192] The NSWO network element sends the target network identifier and / or the target routing identifier to a second address management network element.
[0193] The NSWO network element receives the address of the AUSF sent by the second address managing network element.
[0194] In this implementation, the NSWO network element may not locally store the mapping relationship between the network identifier and / or the routing identifier and the AUSF address. The address of the AUSF is obtained from the second address managing network element by sending the target network identifier and / or the target routing identifier to the second address managing network element. The name of the second address managing network element is not limited in this embodiment. Optionally, the second address managing network element may locally store the mapping relationship between the network identifier and / or the routing identifier and the AUSF address.
[0195] Optionally, the first authentication request message may further include NSWO indication information. Optionally, the NSWO indication information may include at least one of the following: first NSWO indication information or fourth NSWO indication information. That is, the NSWO indication information is the first NSWO indication information, or the NSWO indication information is the fourth NSWO indication information, or the NSWO indication information includes the first NSWO indication information and the fourth NSWO indication information. For the first NSWO indication information and the fourth NSWO indication information, please refer to the preceding description in this application. Details will not be described again in this specification.
[0196] The first authentication request message carries NSWO indication information, so that the AUSF determines that authentication for the NSWO service needs to be performed based on the NSWO indication information, thereby helping to distinguish different authentication procedures.
[0197] Optionally, the first authentication request message may further include a first identification information of the AN device. The first identification information is then used by the AUSF to send a second identification information of the AN device to the UDM. For details, see step 7.
[0198] Optionally, the first identification information may be one of the following:
[0199] (1) An access network identity (AN ID) of the AN device carried in the second request message. In this implementation, the NSWO network element sends the AN ID sent by the AN device to the AUSF.
[0200] (2) A serving network name corresponding to the access network identity of the AN device. In this implementation, the NSWO network element can convert the obtained AN ID into a serving network name and send the serving network name to the AUSF.
[0201] (3) Access network identity determined based on related information of AN device. In this implementation, the NSWO network element locally stores related information of the AN device, determines an access network identity based on the related information, and then sends the access network identity to the AUSF. The specific content of the related information is not limited in this embodiment.
[0202] (4) A preconfigured access network identity that indicates authentication for the NSWO service.
[0203] (5) A preconfigured serving network name indicating that the NSWO service is to be authenticated.
[0204] Optionally, the first authentication request message may be a request message corresponding to an existing AUSF service. Please refer to the above description in this application. Details will not be described again in this specification. In this implementation, the first authentication request message includes information indicating to the AUSF to perform authentication of the NSWO service. Optionally, the information may include at least one of SUCI or NSWO indication information.
[0205] Optionally, the first authentication request message may be a request message corresponding to a newly added AUSF service. Please refer to the above description in this application. Details will not be described again in this specification. In this implementation, the newly added AUSF service directly indicates to the AUSF to perform authentication of the NSWO service. Optionally, the first authentication request message may not include information indicating to the AUSF to perform authentication of the NSWO service. For example, the first authentication request message does not include NSWO indication information, and the SUCI may be a SUCI used in the existing 5G network. Optionally, the first authentication request message may alternatively include information indicating to the AUSF to perform authentication of the NSWO service. Optionally, the information may include at least one of SUCI or NSWO indication information.
[0206] Step 6: The AUSF decides to perform authentication for the NSWO service based on the first authentication request message.
[0207] Optionally, in one implementation, it may be determined that the NSWO network element supports the NSWO service by default, and performs authentication of the NSWO service when a first authentication request message is received from the NSWO network element.
[0208] Optionally, in another implementation, the AUSF may determine to support the NSWO service by default, and perform authentication of the NSWO service when a first authentication request message is received from the NSWO network element.
[0209] Optionally, in yet another implementation, it may be determined to perform authentication of the NSWO service according to the NSWO indication information included in the first authentication request message. For the NSWO indication information included in the first authentication request message, please refer to the relevant description of step 5. Details will not be described again in this specification.
[0210] Optionally, in yet another implementation, it may be determined to authenticate the NSWO service based on the SUCI, in which the SUCI indicates that the NSWO service is to be authenticated.
[0211] Optionally, in yet another implementation, when it is determined that the first authentication request message is a request message corresponding to a newly added AUSF service, it is determined to perform authentication of the NSWO service. The newly added AUSF service indicates to perform authentication for the NSWO service. For example, when the first authentication request message is Nausf_UEAuthentication_NSWO_Authenticate request, the AUSF determines to perform authentication of the NSWO service.
[0212] Optionally, in yet another implementation, the type or address of the NSWO network element may be determined based on the first authentication request message, and after it is determined that the NSWO network element supports the NSWO service based on the type or address of the NSWO network element, it is determined to perform authentication of the NSWO service.
[0213] Step 7: The AUSF sends a second authentication request message to the UDM. The second authentication request message includes the SUCI. In response, the UDM receives the second authentication request message sent by the AUSF.
[0214] Specifically, after deciding to authenticate to the NSWO service, the AUSF may send a second authentication request message to the UDM.
[0215] Optionally, the second authentication request message may further include NSWO indication information. Optionally, the NSWO indication information may include at least one of the following: first NSWO indication information or fifth NSWO indication information. That is, the NSWO indication information is the first NSWO indication information, or the NSWO indication information is the fifth NSWO indication information, or the NSWO indication information includes the first NSWO indication information and the fifth NSWO indication information. For the first NSWO indication information and the fifth NSWO indication information, please refer to the preceding description in this application. Details will not be described again in this specification.
[0216] The second authentication request message carries NSWO indication information, so that the UDM determines that authentication of the NSWO service needs to be performed based on the NSWO indication information, thereby helping to distinguish different authentication procedures.
[0217] Optionally, the second authentication request message may further include a second identification information of the AN device. The AN device is an AN device connected to the UE. The second identification information may be used by the UDM to later calculate the first EAP-AKA' authentication vector. For details, see step 10.
[0218] Optionally, the second identification information may be one of the following:
[0219] (1) The first identification information carried in the first authentication request message. Please refer to the related description of step 5. The details will not be described again in this specification. In this implementation, the AUSF directly sends the first identification information sent by the NSWO network element to the UDM.
[0220] (2) First information.
[0221] Optionally, in one implementation, when the first identification information carried in the first authentication request message is an access network identity of the AN device, the first information is a serving network name corresponding to the access network identity. In this implementation, the first identification information sent by the NSWO network element to the AUSF is an access network identity (AN ID), and the AUSF can convert the obtained AN ID into a serving network name and then send the serving network name to the UDM.
[0222] Optionally, in another implementation, when the first authentication request message does not carry the first identification information, the first information is a pre-configured access network identity or a pre-configured serving network name. Both the pre-configured access network identity and the pre-configured serving network name indicate authentication of the NSWO service.
[0223] Optionally, the second authentication request message may be a request message corresponding to an existing UDM service. Please refer to the above description in this application. Details will not be described again in this specification. In this implementation, the second authentication request message includes information that indicates to the UDM to perform authentication of the NSWO service. Optionally, the information may include at least one of SUCI or NSWO indication information.
[0224] Optionally, the second authentication request message may be a request message corresponding to a newly added UDM service. Please refer to the above description in this application. Details will not be described again in this specification. In this implementation, the newly added UDM service directly indicates to the UDM to perform authentication of the NSWO service. Optionally, the second authentication request message may not include information indicating to the UDM to perform authentication of the NSWO service. For example, the second authentication request message does not include NSWO indication information, and the SUCI may be a SUCI used in the existing 5G network. Optionally, the second authentication request message may alternatively include information indicating a UDM to perform authentication of the NSWO service. Optionally, the information may include at least one of SUCI or NSWO indication information.
[0225] Step 8: The UDM calculates the SUPI based on the SUCI.
[0226] This step may be implemented in an existing manner and will not be specifically described.
[0227] Step 9: The UDM determines to use the EAP-AKA' authentication method based on the second authentication request message.
[0228] In some cases, in one implementation, it may be determined that the AUSF supports the NSWO service by default, and performs authentication of the NSWO service when a second authentication request message is received from the AUSF.
[0229] Optionally, in another implementation, when it is determined that the second authentication request message is a request message corresponding to a newly added UDM service, it is determined to perform authentication of the NSWO service. The newly added UDM service indicates to perform authentication of the NSWO service. For example, when the second authentication request message is Nudm_UEAuthentication_NSWO_Authenticate request, the UDM determines to perform authentication for the NSWO service.
[0230] Optionally, in yet another implementation, the UDM may determine to use the EAP-AKA' authentication method based on second information in the second authentication request message. The second information includes at least one of the following:
[0231] (1) The second information is NSWO indication information, and the NSWO indication information indicates that authentication of the NSWO service is to be performed. For the NSWO indication information included in the second authentication request message, please refer to the relevant description of step 7. Details will not be described again in this specification.
[0232] (2) The second piece of information is SUCI, which indicates that the NSWO service is to be authenticated.
[0233] In a scenario where authentication is performed on the UE for an NSWO service in a 5G network, since the AN device supports the EAP-AKA authentication method and the EAP-AKA' authentication method and the 5G network supports the EAP-AKA' authentication method and the 5G AKA authentication method, it may be known that the UDM decides to use the EAP-AKA' authentication method to avoid authentication failures caused when the 5G AKA authentication method is selected and to implement the authentication procedure for the NSWO service in the 5G network.
[0234] Optionally, the UDM determines that the UE expects to use the NSWO service, and the UDM determines subscription data of the UE based on the SUPI, and checks whether the UE is authorized to use the NSWO service based on the subscription data. If the UE is authorized to use the NSWO service, further steps are performed. If not, the UDM sends a rejection message to the AUSF, which then sends a rejection message to the NSWO network element, which then sends a rejection message to the AN device. The rejection message carries an indicator that the UE is not authorized to use the NSWO service. Based on the rejection message, the AN device rejects the UE's NSWO service request, or informs the UE that the UE is not authorized to use the NSWO service, or the UE is not authorized to use the NSWO service in the network corresponding to the AN ID or serving network name.
[0235] Optionally, the UDM determines that the UE expects to use the NSWO service, and the UDM determines subscription data of the UE based on the SUPI, and checks whether the UE is authorized to use the NSWO service in the network corresponding to the AN ID or serving network name based on the subscription data and the AN ID or serving network name. If the UE is authorized to use the NSWO service, further steps are performed. If not, the UDM sends a rejection message to the AUSF, which then sends a rejection message to the NSWO network element, which then sends a rejection message to the AN device. The rejection message carries an indicator that the UE is not authorized to use the NSWO service in the network corresponding to the AN ID or serving network name. Based on the rejection message, the AN device rejects the UE's NSWO service request, or informs the UE that the UE is not authorized to use the NSWO service, or the UE is not authorized to use the NSWO service in the network corresponding to the AN ID or serving network name.
[0236] Step 10: The UDM obtains a first EAP-AKA' authentication vector (RAND, AUTN, XRES, CK', IK') based on the SUPI.
[0237] Specifically, after determining to use the EAP-AKA' authentication method, the UDM may obtain an EAP-AKA' authentication vector, referred to as a first EAP-AKA' authentication vector, based on the SUPI and the identity information of the AN device. The AN device is specifically the AN device accessed by the UE. The first EAP-AKA' authentication vector includes a key CK' and a key IK'.
[0238] Optionally, the identity of the AN device used by the UDM to calculate the first EAP-AKA′ authentication vector may be one of the following:
[0239] (1) The identification information is the second identification information of the AN device carried in the second authentication request message. Please refer to the related description of step 7. The details will not be described again in this specification.
[0240] (2) If the second authentication request message does not carry the second identification information of the AN device, the identification information is a pre-configured access network identity or a serving network identifier. The pre-configured access network identity or the pre-configured serving network identifier indicates authentication for the NSWO service.
[0241] (3) If the second authentication request message does not carry the second identification information of the AN device, the identification information is a pre-configured serving network name. The pre-configured serving network name indicates authentication for the NSWO service.
[0242] Step 11: The UDM sends a second authentication response message to the AUSF. The second authentication response message includes a second EAP-AKA' authentication vector. In response, the AUSF receives the second authentication response message sent by the UDM.
[0243] The second EAP-AKA' authentication vector is the part obtained after the keys CK' and IK' are deleted from the first EAP-AKA' authentication vector, i.e. (RAND, AUTN, XRES). In other words, the second EAP-AKA' authentication vector does not include the keys CK' or IK'.
[0244] Specifically, when performing an NSWO service, the UE needs to perform authentication of the NSWO service. When performing a non-NSWO service, the UE may perform another authentication procedure, for example, an authentication procedure based on a SIM card. The key CK' and the key IK' are removed from the first EAP-AKA' authentication vector, thereby preventing the key CK' and the key IK' newly generated in the authentication process of the NSWO service from affecting the related keys already generated by the UE or AUSF in the existing authentication procedure, and ensuring that the authentication procedure provided in this embodiment is applicable to the authentication of the NSWO service.
[0245] For the second authentication response message, please refer to the above description in this application, and the details will not be described again in this specification.
[0246] Optionally, the second authentication response message may further include a SUPI.
[0247] Step 12: The AUSF sends a first authentication response message to the NSWO network element based on the second authentication response message. The first authentication response message is an authentication response message corresponding to the EAP-AKA' authentication algorithm. In response, the NSWO network element receives the first authentication response message sent by the AUSF.
[0248] Specifically, the AUSF may perform an existing EAP-AKA' authentication procedure and send a first authentication response message to the NSWO network element. The first authentication response message may include RAND and AUTN, which is not specifically described in this embodiment. The first authentication response message does not include the key CK' or the key IK'.
[0249] Optionally, the first authentication response message may include an Extensible Authentication Protocol / Authentication and Key Agreement-Challenge (EAP / AKA-challenge).
[0250] For the first authentication response message, please refer to the above description in this application, and the details will not be described again in this specification.
[0251] Step 13: The NSWO network element uses the AN device to send a third authentication request message to the UE based on the first authentication response message. The third authentication request message is an authentication request message corresponding to the EAP-AKA' authentication algorithm and may include RAND and AUTN.
[0252] In response, the UE receives a third authentication request message sent by the NSWO network element by using the AN device.
[0253] Specifically, the NSWO network element may perform an existing EAP-AKA' authentication procedure and send a third authentication request message to the UE, which is not specifically described in this embodiment.
[0254] Optionally, the third authentication request message may include an EAP / AKA-challenge(RAND, AUTN) sent by the AUSF.
[0255] Step 14: The UE performs authentication verification on the network by using the EAP-AKA' authentication algorithm. For example, it verifies whether the MAC in the AUTN is correct based on the RAND, and it verifies whether the freshness of the SQN calculated based on the RAND and the AUTN meets the requirement. The verification of the RAND and the AUTN belongs to the prior art and is not limited.
[0256] Specifically, the UE can carry out an existing EAP-AKA' authentication procedure to perform authentication verification on the network by using an EAP-AKA' authentication algorithm, which is not specifically described in this embodiment.
[0257] Step 15: After the authentication verification is successful, the UE calculates the RES and sends a fourth authentication request message to the NSWO network element by using the AN device. The fourth authentication request message includes the RES. Correspondingly, the NSWO network element receives the fourth authentication request message sent by the UE by using the AN device.
[0258] In a further optional implementation form, the UE is internally divided into two parts, namely the USIM and the ME. The ME may be understood as a part of the UE other than the USIM. The USIM performs security verification on the RAND and AUTN. After the USIM successfully performs the verification, the USIM calculates the CK, IK, and RES and sends the CK, IK, and RES to the ME. Thereafter, the ME performs operations corresponding to the CK, IK, and RES, for example, calculates CK' and IK' based on the CK and IK.
[0259] Specifically, the UE may perform the existing EAP-AKA' authentication procedure and send a fourth authentication request message to the NSWO network element. The fourth authentication request message includes the RES. This is not specifically described in this embodiment.
[0260] Optionally, the fourth authentication request message may include an EAP / AKA-challenge.
[0261] Optionally, after the UE determines that the authentication verification is successful in Step 15, the method may further include one of the following:
[0262] (1) The UE or ME calculates the key CK' and the key IK', and then deletes the key CK' and the key IK'. In this implementation, the UE calculates the key CK' and the key IK', but then deletes them, thereby preventing the key CK' and the key IK' newly generated in the authentication process of the NSWO service from affecting the related keys generated by the UE in the existing authentication procedure, and ensuring that the authentication procedure provided in this embodiment is applicable to the authentication of the NSWO service.
[0263] (2) The UE or ME calculates the key CK' and the key IK' and obtains the key K AUSF Stop computing the key K AUSF is calculated based on the keys CK' and IK', and then deletes the keys CK' and IK'. In this implementation, the UE calculates the keys CK' and IK', but does not delete the keys K. AUSF and delete the key CK' and the key IK', thereby preventing the newly generated key CK' and the key IK' in the authentication process of the NSWO service from affecting the related keys generated by the UE in the existing authentication procedure.
[0264] (3) The UE or ME calculates keys CK' and IK', and generates key K based on CK' and IK'. AUSF Then, delete the keys CK' and IK' and calculate the key K AUSF In this implementation, the UE deletes the key CK′, the key IK′, and the key K. AUSF , but then delete them all, thereby preventing the newly generated keys CK′ and IK′ in the authentication process of the NSWO service from affecting the related keys generated by the UE in the existing authentication procedure.
[0265] (4) The UE or ME calculates keys CK' and IK', and generates key K based on CK' and IK'. AUSF Then, delete the keys CK′ and IK′ and use the key K stored locally in the UE. AUSFIn this implementation, the UE stops replacing the keys CK′, IK′, and K. AUSF , but then delete the keys CK' and IK'. AUSF is newly generated, but the key K stored locally in the UE AUSF is not replaced. The newly generated key K AUSF It can be seen that the newly generated key is not used. Therefore, the newly generated key does not affect the associated key generated by the UE in the existing authentication procedure.
[0266] (5) The UE or ME stops calculating the key CK' and the key IK'. In this implementation, the UE does not calculate the key CK' or the key IK', thereby preventing the key CK' and the key IK' newly generated in the authentication process of the NSWO service from affecting the related keys generated by the UE in the existing authentication procedure.
[0267] Optionally, the ME AUSF to the USIM to retrieve the old K AUSF Replace with.
[0268] (6) After determining that authentication is performed for the NSWO service, the ME also sends an authentication indicator to the USIM card when sending RAND and AUTN to the USIM card. Optionally, the authentication indicator indicates that the USIM card does not need to send a CK or IK after the verification is successful, or indicates to the USIM card that an authentication-only service is performed, etc. After the USIM successfully performs the verification, the USIM calculates only a RES based on the authentication indicator and sends the RES to the ME. Alternatively, based on the authentication indicator, the USIM does not calculate a CK or IK, or even if the CK and IK are calculated, the USIM does not send the CK or IK to the ME. In this case, the ME cannot obtain a CK or IK and does not calculate a CK' or IK' based on the CK and IK.
[0269] (7) The ME sends RAND and AUTN to the USIM card, and the USIM operates normally and sends CK, IK, and RES to the ME. In this case, the ME performs authentication based on the NSWO service. Optionally, the ME can discard or delete the CK and IK, or do not perform other additional use, such as calculating CK' and IK' based on the CK and IK. This prevents the key CK' and key IK' newly generated in the authentication process of the NSWO service from affecting the related keys generated by the UE in the existing authentication procedure, and ensures that the authentication procedure provided in this embodiment is applicable to the authentication of the NSWO service.
[0270] Step 16: The NSWO network element sends a fifth authentication request message to the AUSF based on the fourth authentication request message. In response, the AUSF receives the fifth authentication request message sent by the NSWO network element.
[0271] Specifically, the NSWO network element may perform an existing EAP-AKA' authentication procedure and send a fifth authentication request message to the AUSF, which is not specifically described in this embodiment.
[0272] Optionally, the fifth authentication request message may include an EAP / AKA-challenge sent by the UE.
[0273] Optionally, the fifth authentication request message may be a Nausf_UEAuthentication_Authenticate request.
[0274] Step 17: The AUSF performs authentication on the UE based on the fifth authentication request message. For example, it verifies whether RES and XRES are equal. If they are equal, the verification is successful; otherwise, the verification fails.
[0275] Specifically, the AUSF may perform an existing EAP-AKA' authentication procedure to perform authentication on the UE, which is not specifically described in this embodiment.
[0276] Step 18: After the authentication verification, the AUSF sends a first message to the NSWO network element. In response, the NSWO network element receives the first message sent by the AUSF. The first message includes an authentication verification result.
[0277] Step 19: The NSWO network element sends a second message to the AN device based on the first message. In response, the AN device receives the second message sent by the NSWO network element.
[0278] Step 20: Optionally, if the authentication verification is successful, the AN device sends an NSWO service indication message to the UE. Alternatively, the AN device may perform an operation corresponding to the NSWO service after determining that the authentication is successful.
[0279] Step 21: If the authentication verification fails, the AN device sends a rejection message to the UE.
[0280] Step 17 to step 21 are steps in the existing EAP-AKA' authentication procedure. For related messages, please refer to the previous description in this application. The details will not be described again in this specification.
[0281] This embodiment provides an authentication procedure applicable when a UE performs an NSWO service in a 5G network, and it can be known that the related network elements include a UE, an AN device, an NSWO network element, an AUSF, and a UDM. After deciding to perform authentication of the NSWO service, the UDM decides to use the EAP-AKA' authentication method, thereby avoiding authentication failure caused by selecting the 5G AKA authentication method. In addition, after calculating the EAP-AKA' authentication vector by using the EAP-AKA' authentication method, the UDM deletes the key CK' and the key IK' from the EAP-AKA' authentication vector, and then sends the EAP-AKA' authentication vector to the AUSF, thereby preventing the newly generated key CK' and the key IK' in the authentication process of the NSWO service from affecting the related keys already generated by the UE or the AUSF in the existing authentication procedure, and avoiding the impact on the existing key architecture of the UE or the AUSF. In addition, after successfully performing authentication verification on the network, the UE may not calculate the key CK' or the key IK', or may delete the calculated key CK' and the key IK' or the key K. AUSF or the key K AUSF After is calculated, the newly generated key K AUSF is a locally existing key K AUSF , thereby avoiding any impact on the existing key architecture of the UE.
[0282] 5A and 5B are another diagram of message exchange of the method for authentication of NSWO service according to one embodiment of the present application. The method for authentication of NSWO service provided in this embodiment is performed by the UE, the AN device, the NSWO network element, the AUSF, and the UDM. The difference between this embodiment and the embodiment shown in FIG. 4A and FIG. 4B is that the UDM sends the complete EAP-AKA' authentication vector to the AUSF after calculating the EAP-AKA' authentication vector by using the EAP-AKA' authentication method. In this way, the AUSF or the UE can receive the newly generated key CK', key IK', or key K in the authentication process of the NSWO service. AUSF Indeed, the AUSF or UE can use the newly generated key CK', key IK', or key K. AUSF may not be used instead.
[0283] As shown in Figures 5A and 5B, the method for authentication of the NSWO service provided in this embodiment may include the following steps.
[0284] Step 1: After the UE determines to perform the NSWO service, the UE sends a SUCI to the AN device. In response, the AN device receives the SUCI sent by the UE.
[0285] Step 2: The AN device determines the address of the NSWO network element based on the SUCI.
[0286] Step 3: The AN device sends a second request message to the NSWO network element based on the address of the NSWO network element. The second request message includes the SUCI. In response, the NSWO network element receives the second request message sent by the AN device.
[0287] Step 4: The NSWO network element decides to perform authentication for the NSWO service based on the second request message.
[0288] Step 5: The NSWO network element sends a first authentication request message to the AUSF. The first authentication request message includes the SUCI. In response, the AUSF receives the first authentication request message sent by the NSWO network element.
[0289] Step 6: The AUSF decides to perform authentication for the NSWO service based on the first authentication request message.
[0290] For steps 1 to 6, please refer to the embodiment shown in Figure 4A and Figure 4B, and the details will not be described again in this specification.
[0291] Step 107: The AUSF sends a second authentication request message to the UDM, where the second authentication request message includes the SUCI. In response, the UDM receives the second authentication request message sent by the AUSF.
[0292] Specifically, after deciding to authenticate to the NSWO service, the AUSF may send a second authentication request message to the UDM.
[0293] Optionally, the second authentication request message may further include NSWO indication information. Optionally, the NSWO indication information may include at least one of the following: first NSWO indication information or fifth NSWO indication information. That is, the NSWO indication information is the first NSWO indication information, or the NSWO indication information is the fifth NSWO indication information, or the NSWO indication information includes the first NSWO indication information and the fifth NSWO indication information. For the first NSWO indication information and the fifth NSWO indication information, please refer to the preceding description in this application. Details will not be described again in this specification.
[0294] The second authentication request message carries NSWO indication information, so that the UDM determines that authentication of the NSWO service needs to be performed based on the NSWO indication information, thereby helping to distinguish different authentication procedures.
[0295] Optionally, the second authentication request message may further include a second identification of the AN device, which is an AN device connected to the UE. The second identification may be used by the UDM to subsequently calculate the first EAP-AKA' authentication vector.
[0296] Optionally, the second identification information may be one of the following:
[0297] (1) The first identification information carried in the first authentication request message. Please refer to the related description of step 5. The details will not be described again in this specification. In this implementation, the AUSF directly sends the first identification information sent by the NSWO network element to the UDM.
[0298] (2) First information.
[0299] Optionally, in one implementation, when the first identification information carried in the first authentication request message is an access network identity of the AN device, the first information is a serving network name corresponding to the access network identity. In this implementation, the first identification information sent by the NSWO network element to the AUSF is an access network identity (AN ID), and the AUSF can convert the obtained AN ID into a serving network name and send the serving network name to the UDM.
[0300] Optionally, in another implementation, when the first authentication request message does not carry the first identification information, the first information is a pre-configured access network identity or a pre-configured serving network name. Both the pre-configured access network identity and the pre-configured serving network name indicate authentication of the NSWO service.
[0301] Optionally, the second authentication request message may be a request message corresponding to an existing UDM service. Please refer to the above description in this application. Details will not be described again in this specification. In this case, optionally, in one implementation, the second authentication request message includes information indicating to the UDM to perform authentication of the NSWO service. Optionally, the information may include at least one of SUCI or NSWO indication information.
[0302] Optionally, in another implementation, after determining to perform authentication of the NSWO service, the AUSF further determines to use an EAP-AKA' authentication algorithm. Correspondingly, the second authentication request message further includes algorithm indication information to indicate to perform EAP-AKA' authentication. The algorithm indication information is carried, so that the UDM can directly determine to use the EAP-AKA' authentication method, thereby simplifying the complexity of the process of selecting an authentication algorithm by the UDM.
[0303] Optionally, the second authentication request message may be a request message corresponding to a newly added UDM service. Please refer to the above description in this application. Details will not be described again in this specification. In this implementation, the newly added UDM service directly indicates to the UDM to perform authentication of the NSWO service. Optionally, the second authentication request message may not include information indicating to the UDM to perform authentication of the NSWO service. For example, the second authentication request message does not include NSWO indication information, and the SUCI may be a SUCI used in the existing 5G network. Optionally, the second authentication request message may alternatively include information indicating a UDM to perform authentication of the NSWO service. Optionally, the information may include at least one of SUCI or NSWO indication information.
[0304] Optionally, after determining to perform authentication for the NSWO service, the AUSF further determines to use the EAP-AKA' authentication algorithm. The second authentication request message may or may not include algorithm indication information.
[0305] Step 8: The UDM calculates the SUPI based on the SUCI.
[0306] Please refer to the embodiment shown in Figures 4A and 4B, the details will not be described again here.
[0307] Step 109: The UDM determines, based on the second authentication request message, to use the EAP-AKA' authentication method.
[0308] In some cases, in one implementation, it may be determined that the AUSF supports the NSWO service by default, and performs authentication of the NSWO service when a second authentication request message is received from the AUSF.
[0309] Optionally, in another implementation, when it is determined that the second authentication request message is a request message corresponding to a newly added UDM service, it is determined to perform authentication of the NSWO service. The newly added UDM service indicates to perform authentication of the NSWO service. For example, when the second authentication request message is Nudm_UEAuthentication_NSWO_Authenticate request, the UDM determines to perform authentication for the NSWO service.
[0310] Optionally, in yet another implementation, the UDM may determine to use the EAP-AKA' authentication method based on second information in the second authentication request message. The second information includes at least one of the following:
[0311] (1) The second information is NSWO indication information, and the NSWO indication information indicates that authentication of the NSWO service is to be performed. For the NSWO indication information included in the second authentication request message, please refer to the relevant description of step 7. Details will not be described again in this specification.
[0312] (2) The second piece of information is SUCI, which indicates that the NSWO service is to be authenticated.
[0313] (3) The second information is algorithm instruction information, and the algorithm instruction information indicates that EAP-AKA' authentication is to be performed.
[0314] In a scenario where authentication is performed on the UE for an NSWO service in a 5G network, since the AN device supports the EAP-AKA authentication method and the EAP-AKA' authentication method and the 5G network supports the EAP-AKA' authentication method and the 5G AKA authentication method, it may be known that the UDM decides to use the EAP-AKA' authentication method to avoid authentication failures caused when the 5G AKA authentication method is selected and to implement the authentication procedure for the NSWO service in the 5G network.
[0315] Optionally, the UDM determines that the UE expects to use the NSWO service, and the UDM determines subscription data of the UE based on the SUPI, and checks whether the UE is authorized to use the NSWO service based on the subscription data. If the UE is authorized to use the NSWO service, further steps are performed. If not, the UDM sends a rejection message to the AUSF, which then sends a rejection message to the NSWO network element, which then sends a rejection message to the AN device. The rejection message carries an indicator that the UE is not authorized to use the NSWO service. Based on the rejection message, the AN device rejects the UE's NSWO service request, or informs the UE that the UE is not authorized to use the NSWO service, or the UE is not authorized to use the NSWO service in the network corresponding to the AN ID or serving network name.
[0316] Optionally, the UDM determines that the UE expects to use the NSWO service, and the UDM determines subscription data of the UE based on the SUPI, and checks whether the UE is authorized to use the NSWO service in the network corresponding to the AN ID or serving network name based on the subscription data and the AN ID or serving network name. If the UE is authorized to use the NSWO service, further steps are performed. If not, the UDM sends a rejection message to the AUSF, which then sends a rejection message to the NSWO network element, which then sends a rejection message to the AN device. The rejection message carries an indicator indicating that the UE is not authorized to use the NSWO service in the network corresponding to the AN ID or serving network name. Based on the rejection message, the AN device rejects the UE's NSWO service request, or informs the UE that the UE is not authorized to use the NSWO service, or the UE is not authorized to use the NSWO service in the network corresponding to the AN ID or serving network name.
[0317] Step 10: The UDM obtains a first EAP-AKA' authentication vector (RAND, AUTN, XRES, CK', IK') based on the SUPI.
[0318] Please refer to the embodiment shown in Figures 4A and 4B, the details will not be described again here.
[0319] Step 111: The UDM sends a second authentication response message to the AUSF. The second authentication response message includes a second EAP-AKA' authentication vector. In response, the AUSF receives the second authentication response message sent by the UDM.
[0320] The second EAP-AKA' authentication vector is the first EAP-AKA' authentication vector, and the second EAP-AKA' authentication vector includes key CK' and key IK'.
[0321] The complete EAP-AKA' authentication vector is carried in the second authentication response message and sent to the AUSF, so that the AUSF can use the newly generated keys CK' and IK' in the authentication process of the NSWO service, thereby improving the flexibility of the key usage scheme.
[0322] For the second authentication response message, please refer to the above description in this application, and the details will not be described again in this specification.
[0323] Optionally, the second authentication response message may further include a SUPI.
[0324] Step 112: The AUSF sends a first authentication response message to the NSWO network element based on the second authentication response message. The first authentication response message is an authentication response message corresponding to the EAP-AKA' authentication algorithm. In response, the NSWO network element receives the first authentication response message sent by the AUSF.
[0325] Specifically, the AUSF may perform an existing EAP-AKA' authentication procedure and send a first authentication response message to the NSWO network element, which is not specifically described in this embodiment. The second EAP-AKA' authentication vector carried in the second authentication response message received by the AUSF is a complete EAP-AKA' authentication vector, including a key CK' and a key IK'.
[0326] Optionally, in one implementation, sending the first authentication response message to the NSWO network element based on the second authentication response message includes: This may include sending a first authentication response message to the NSWO network element, where the first authentication response message includes the RAND and the AUTN.
[0327] In this implementation, the AUSF deletes key CK' and key IK' from the second EAP-AKA' authentication vector, thereby preventing the newly generated key CK' and key IK' in the authentication process of the NSWO service from affecting the related keys already generated by the UE in the existing authentication procedure.
[0328] Optionally, the first authentication response message may include an EAP / AKA-challenge(RAND, AUTN).
[0329] For the first authentication response message, please refer to the above description in this application, and the details will not be described again in this specification.
[0330] Step 13: The NSWO network element uses the AN device to send a third authentication request message to the UE based on the first authentication response message. The third authentication request message is an authentication request message corresponding to the EAP-AKA' authentication algorithm. In response, the UE receives the third authentication request message sent by the NSWO network element by using the AN device.
[0331] Step 14: The UE performs authentication verification on the network by using the EAP-AKA' authentication algorithm. For example, it verifies whether the MAC in the AUTN is correct based on the RAND, and it verifies whether the freshness of the SQN calculated based on the RAND and the AUTN meets the requirement. The verification of the RAND and the AUTN belongs to the prior art and is not limited.
[0332] Step 15: After the authentication verification is successful, the UE calculates RES and sends a fourth authentication request message to the NSWO network element by using the AN device. The fourth authentication request message includes RES. In response, the NSWO network element receives the fourth authentication request message sent by the UE by using the AN device.
[0333] In a further optional implementation, the UE is internally divided into two parts: USIM and ME. The ME may be understood as a part of the UE other than the USIM. The USIM performs security verification on the RAND and AUTN. After the USIM successfully performs the verification, the USIM calculates CK, IK, and RES, and sends the CK, IK, and RES to the ME. The ME then performs operations corresponding to the CK, IK, and RES, for example, calculating CK' and IK' based on the CK and IK.
[0334] For steps 13 to 15, please refer to the embodiment shown in Figure 4A and Figure 4B, and the details will not be described again in this specification.
[0335] Optionally, after the UE, USIM, or ME determines in step 15 that the authentication verification is successful, the method may further include one of the following:
[0336] (1) The UE or ME calculates the key CK' and the key IK', and then deletes the key CK' and the key IK'. In this implementation, the UE calculates the key CK' and the key IK', but then deletes them, thereby preventing the key CK' and the key IK' newly generated in the authentication process of the NSWO service from affecting the related keys generated by the UE in the existing authentication procedure, and ensuring that the authentication procedure provided in this embodiment is applicable to the authentication of the NSWO service.
[0337] (2) The UE or ME calculates the key CK' and the key IK' and obtains the key K AUSFStop computing the key K AUSF is calculated based on the keys CK' and IK', and then deletes the keys CK' and IK'. In this implementation, the UE calculates the keys CK' and IK', but does not delete the keys K. AUSF and delete the key CK' and the key IK', thereby preventing the newly generated key CK' and the key IK' in the authentication process of the NSWO service from affecting the related keys generated by the UE in the existing authentication procedure.
[0338] (3) The UE or ME calculates keys CK' and IK', and generates key K based on CK' and IK'. AUSF Then, delete the keys CK' and IK' and calculate the key K AUSF In this implementation, the UE deletes the key CK′, the key IK′, and the key K. AUSF , but then delete them all, thereby preventing the newly generated keys CK′ and IK′ in the authentication process of the NSWO service from affecting the related keys generated by the UE in the existing authentication procedure.
[0339] (4) The UE or ME calculates keys CK' and IK', and generates key K based on CK' and IK'. AUSF Then, delete the keys CK′ and IK′ and use the key K stored locally in the UE. AUSF In this implementation, the UE stops replacing the keys CK′, IK′, and K. AUSF , but then delete the keys CK' and IK'. AUSF is newly generated, but the key K stored locally in the UE AUSF is not replaced. The newly generated key K AUSF It can be seen that the newly generated key is not used. Therefore, the newly generated key does not affect the associated key generated by the UE in the existing authentication procedure.
[0340] (5) The UE or ME stops calculating the key CK' and the key IK'. In this implementation, the UE does not calculate the key CK' or the key IK', thereby preventing the key CK' and the key IK' newly generated in the authentication process of the NSWO service from affecting the related keys generated by the UE in the existing authentication procedure.
[0341] (6) The UE or ME calculates keys CK' and IK', and generates key K based on CK' and IK'. AUSF and then calculates a key K AUSF In this implementation, the UE replaces the key CK′, the key IK′, and the key K AUSF and calculates the key K AUSF i.e., replace the locally stored key K AUSF Let K be the newly generated key. AUSF Then, the UE replaces the newly generated key K AUSF Optionally, the ME may use K AUSF to the USIM to retrieve the old K AUSF Replace with.
[0342] (7) After determining that authentication is performed for the NSWO service, the ME also sends an authentication indicator to the USIM card when sending RAND and AUTN to the USIM card. Optionally, the authentication indicator indicates that the USIM card does not need to send a CK or IK after the verification is successful, or indicates to the USIM card that an authentication-only service is performed, etc. After the USIM successfully performs the verification, the USIM calculates only a RES based on the authentication indicator and sends the RES to the ME. Alternatively, based on the authentication indicator, the USIM does not calculate a CK or IK, or even if the CK and IK are calculated, the USIM does not send the CK or IK to the ME. In this case, the ME cannot obtain a CK or IK and does not calculate a CK' or IK' based on the CK and IK.
[0343] (8) The ME sends RAND and AUTN to the USIM card, and the USIM operates normally and sends CK, IK, and RES to the ME. In this case, the ME performs authentication based on the NSWO service. Optionally, the ME can discard or delete the CK and IK, or have no other additional use. This prevents the key CK' and key IK' newly generated in the authentication process of the NSWO service from affecting the related keys generated by the UE in the existing authentication procedure, and ensures that the authentication procedure provided in this embodiment is applicable to the authentication of the NSWO service.
[0344] Step 16: The NSWO network element sends a fifth authentication request message to the AUSF based on the fourth authentication request message. In response, the AUSF receives the fifth authentication request message sent by the NSWO network element.
[0345] Step 17: The AUSF performs authentication on the UE based on the fifth authentication request message. For example, it verifies whether RES and XRES are equal. If they are equal, the verification is successful; otherwise, the verification fails.
[0346] Step 18: After the authentication verification, the AUSF sends a first message to the NSWO network element. In response, the NSWO network element receives the first message sent by the AUSF. The first message includes an authentication verification result.
[0347] For steps 16 to 18, please refer to the embodiment shown in Figures 4A and 4B, and the details will not be described again in this specification.
[0348] Optionally, in step 112, if the first authentication response message includes a second EAP-AKA' authentication vector carried in the second authentication response message, i.e., if the AUSF does not delete the key CK' and the key IK' received from the UDM, after the AUSF determines in step 18 that the authentication verification is successful, the method may further include one of the following:
[0349] (1) AUSF is a key K AUSF Stop computing the key K AUSF is calculated based on the key CK' and the key IK'. In this implementation, the AUSF calculates a new key K based on the new key CK' and the key IK'. AUSF , and thus the newly generated key K AUSF from affecting related keys that have already been generated by the AUSF in existing authentication procedures.
[0350] (2) AUSF derives key K based on key CK' and key IK'. AUSF and calculates the key K AUSF In this implementation, the AUSF generates a new key K based on the new key CK' and the key IK'. AUSF , but using the key K AUSF The newly generated key K in the authentication process of the NSWO service is not replaced. AUSF It can be seen that the newly generated key K AUSF does not affect the associated keys generated by the AUSF in the existing authentication procedure.
[0351] Optionally, the method may further include at least one of the following:
[0352] (1) The AUSF deletes the key CK' and the key IK'. In this implementation, the AUSF deletes the key CK' and the key IK' received in the authentication process of the NSWO service, thereby preventing the newly generated key CK' and the key IK' from affecting the related keys generated by the AUSF in the existing authentication procedure.
[0353] (2) AUSF generates the key K AUSF In this implementation, the AUSF deletes the newly generated key K AUSF , and the newly generated key K AUSF from affecting related keys generated by the AUSF in existing authentication procedures.
[0354] Step 19: The NSWO network element sends a second message to the AN device based on the first message. In response, the AN device receives the second message sent by the NSWO network element.
[0355] Step 20: Optionally, if the authentication verification is successful, the AN device sends an NSWO service indication message to the UE. Alternatively, the AN may perform an operation corresponding to the NSWO service after determining that the authentication is successful.
[0356] Step 21: If the authentication verification fails, the AN device sends a rejection message to the UE.
[0357] For steps 19 to 21, please refer to the embodiment shown in Figure 4A and Figure 4B, and the details will not be described again in this specification.
[0358] This embodiment provides an authentication procedure applicable when a UE performs an NSWO service in a 5G network, and it can be known that the related network elements include a UE, an AN device, an NSWO network element, an AUSF, and a UDM. The UDM determines to use the EAP-AKA' authentication method, thereby avoiding authentication failure caused by selecting the 5G AKA authentication method. In addition, after calculating the EAP-AKA' authentication vector by using the EAP-AKA' authentication method, the UDM sends the complete EAP-AKA' authentication vector to the AUSF, thereby reducing the change to the processing manner of the UDM and reducing the impact on the UDM, and the AUSF or the UE receives the newly generated key CK', key IK', or key K in the authentication process of the NSWO service. AUSF In addition, after successfully completing the authentication verification on the network, the UE may not calculate the key CK' or the key IK', or may use the calculated key CK' and the key IK' or the key K. AUSF or key K AUSF After is calculated, the newly generated key K AUSF is a locally existing key K AUSF , thereby avoiding any impact on the existing key architecture of the UE. Alternatively, after successfully completing authentication verification on the network, the UE may use the key K AUSF Calculate the locally stored key K AUSF , resulting in a new key K AUSF Furthermore, after receiving the key CK' and the key IK' from the UDM, the AUSF may use the calculated key K AUSF or key K AUSF After is calculated, the newly generated key K AUSF is a locally existing key K AUSF , thereby avoiding the impact of AUSF on existing key architectures. Alternatively, AUSF may use a key K AUSF Calculate the locally stored key K AUSF , resulting in a new key K AUSF may be used.
[0359] Optionally, based on the above embodiment, another embodiment of the present application provides a specific implementation form of the stage where the UE initiates authentication in Figures 3 to 5A and 5B.
[0360] Optionally, in one implementation, Figure 6 is yet another diagram of a message exchange of a method for authentication of an NSWO service according to an embodiment of the present application. As shown in Figure 6, in step 1, the UE sending a SUCI to the AN device may include the following steps:
[0361] S601: The UE sends a first connection establishment request message to an AN device. The first connection establishment request message includes a SUCI and a first NSWO indication information. In response, the AN device receives the first connection establishment request message sent by the UE.
[0362] Optionally, the first connection establishment request message may be an EAP message.
[0363] Optionally, the SUCI may be an existing SUCI generated based on the SUPI, for example, a SUCI used in a 5G network.
[0364] Optionally, the SUCI may indicate that it performs authentication of the NSWO service.
[0365] Optionally, the first NSWO indication information may be carried within the EAP message, or may be carried outside the EAP message.
[0366] In this implementation, after deciding to perform the NSWO service, the UE accesses the AN to establish a connection. The first connection establishment request message carries both the SUCI and the first NSWO indication information to initiate an authentication procedure for the NSWO service, thereby reducing the amount of air interface messages.
[0367] Optionally, in another implementation, Figure 7 is yet another diagram of a message exchange of a method for authentication of an NSWO service according to an embodiment of the present application. As shown in Figure 7, in step 1, the UE sending a SUCI to the AN device may include the following steps:
[0368] S701: The AN device sends a first request message to the UE. In response, the UE receives the first request message sent by the AN device.
[0369] S702: The UE sends a first response message to the AN device. The first response message includes the first NSWO indication information and the SUCI. In response, the AN device receives the first response message sent by the UE.
[0370] In this implementation, the AN device sends a first request message to the UE to trigger the UE to perform EAP authentication. After determining to perform the NSWO service, the UE receives the first request message, decides to perform EAP authentication, and decides to perform authentication for the NSWO service.
[0371] Optionally, the first request message and the first response message may be EAP messages. For example, the first request message is an Extensible Authentication Protocol-Request / Identity message (EAP-REQ / Identity). The first response message is an Extensible Authentication Protocol-Response message (EAP-RSP).
[0372] Optionally, the SUCI may be an existing SUCI generated based on the SUPI, for example, a SUCI used in a 5G network.
[0373] Optionally, the SUCI may indicate that it performs authentication of the NSWO service.
[0374] Optionally, the first NSWO indication information may be carried within the EAP message, or may be carried outside the EAP message.
[0375] Optionally, before S701, the method may include:
[0376] S703: The UE sends a second connection establishment request message to the AN device. In response, the AN device receives the second connection establishment request message sent by the UE.
[0377] Optionally, the second connection establishment request message may be an EAP message.
[0378] Optionally, the second connection establishment request message may include the first NSWO indication information. Specifically, the UE adds the first NSWO indication information to the second connection establishment request message, so that the AN device determines that authentication of the NSWO service needs to be performed, and the AN device triggers the UE to perform EAP authentication.
[0379] Optionally, in yet another implementation, Figure 8 is yet another diagram of a message exchange of a method for authentication of an NSWO service according to an embodiment of the present application. As shown in Figure 8, in step 1, the UE sending a SUCI to the AN device may include the following steps:
[0380] S801: The UE sends a third connection establishment request message to the AN device. The third connection establishment request message includes a SUCI, and the SUCI indicates that authentication of the NSWO service is to be performed. In response, the AN device receives the third connection establishment request message sent by the UE.
[0381] Optionally, the third connection establishment request message may be an EAP message.
[0382] In this implementation, after determining to perform the NSWO service, the UE accesses the AN to establish a connection. The third connection establishment request message carries a SUCI indicating that authentication of the NSWO service is to be performed to start the authentication procedure of the NSWO service, thereby reducing the amount of air interface messages.
[0383] Optionally, Figure 9 is yet another diagram of message exchange of the method for authentication of NSWO service according to an embodiment of the present application. As shown in Figure 9, before step 1, the method for authentication of NSWO service provided in this embodiment may further include the following steps:
[0384] S901: The AN device sends second NSWO indication information to the UE, where the second NSWO indication information indicates that the AN device supports the NSWO service. In response, the UE receives the second NSWO indication information sent by the AN device.
[0385] S902: Based on the second NSWO instruction information, the UE decides to perform authentication based on a 5G key, or based on a SIM, or based on a key used for initial user authentication.
[0386] In this implementation, the AN device sends second NSWO indication information to the UE to notify the UE that the AN device supports the NSWO service, so that authentication of the NSWO service can be implemented.
[0387] The second NSWO indication information may be carried in a message sent by the AN device to the UE. The type and name of the message are not limited in this embodiment. Optionally, the message may be a broadcast message sent by the AN device. Optionally, the message may be the first request message in S701.
[0388] Optionally, based on the above embodiment, Figure 10 is yet another diagram of message exchange of the method for authentication of NSWO service according to an embodiment of the present application. As shown in Figure 10, after step 21, the method for authentication of NSWO service provided in this embodiment may further include the following steps:
[0389] Step 22: After the authentication performed on the UE based on the fifth authentication request message is successful, the AUSF sends the first NSWO authentication result to the UDM.
[0390] Optionally, the SUPI, and / or the access network identity of the access network device, and / or the serving network name corresponding to the access network identity may be sent simultaneously. The SUPI is included in the second authentication response message, and the access network device is an access network device connected to the terminal.
[0391] Optionally, the SUPI may not be transmitted, but information to identify the UE, such as a correlation ID or a URI, is transmitted.
[0392] In response, the UDM receives the first NSWO authentication result sent by the AUSF.
[0393] Step 23: The UDM determines and records that the authentication performed on the UE corresponding to the SUPI for the NSWO service is successful.
[0394] Specifically, the first NSWO authentication result indicates that the authentication performed on the UE for the NSWO service is successful. In the UDM, different UEs may be distinguished by using SUPI, correlation ID, or URI, and different access network devices may be distinguished by using the access network identity or serving network name of the access network device. After determining that the authentication performed on the UE for the NSWO service is successful, the AUSF may send the first NSWO authentication result to the UDM to inform the UDM of the successfully authenticated UE and / or the AN device accessed by the successfully authenticated UE. The UDM records the successfully authenticated UE and / or the AN device accessed by the successfully authenticated UE, and completes the charging for the UE or AN device thereafter.
[0395] Optionally, the first NSWO authentication result may further include authentication indication information, where the authentication indication information indicates that the authentication performed on the terminal for the NSWO service is successful.
[0396] From the authentication indication information, it may be known that the UDM can explicitly determine that the authentication performed on the UE corresponding to the SUPI for the NSWO service has been successful.
[0397] Optionally, the first NSWO authentication result may be carried in a message sent by the AUSF to the UDM. The type and name of the message are not limited in this embodiment.
[0398] Optionally, the message may be a message corresponding to a newly added UDM service. The name of the newly added UDM service and the name of the message corresponding to the newly added UDM service are not limited in this embodiment. The UDM may directly determine that this is a service that notifies SUPI authentication success based on the newly added UDM service, and determine that the authentication performed on the UE corresponding to the SUPI for the NSWO service is successful.
[0399] Optionally, the message may be a message corresponding to an existing UDM service. For example, a message corresponding to an existing UDM service may be a UE authentication result confirmation message (Nudm_UEAuthentication_ResultConfirmation).
[0400] Optionally, based on the foregoing embodiments, FIG. 11 is yet another diagram of message exchange for a method for authenticating an NSWO service according to an embodiment of the present application. As shown in FIG. 11, after step 21, the method for authenticating the NSWO service provided in this embodiment may further include the following steps:
[0401] Step 24: After the authentication performed on the UE based on the fifth authentication request message is successful, the AUSF sends a second NSWO authentication result to a charging network function (NF). The second NSWO authentication result includes the SUPI, and / or the access network identity of the access network device, and / or the serving network name corresponding to the access network identity, where the SUPI is included in the second authentication response message, and the access network device is the access network device connected to the terminal. Optionally, the SUPI may not be sent, but information for identifying the UE, such as a correlation ID or a URI, is sent.
[0402] Correspondingly, the charging NF receives the second NSWO authentication result sent by the AUSF.
[0403] Step 25: The charging NF determines and records that the authentication performed on the UE corresponding to the SUPI for the NSWO service is successful.
[0404] The principle of the second NSWO authentication result is the same as that of the first NSWO authentication result in the embodiment shown in FIG. 10. See the related description. Details are not described again herein.
[0405] The difference between this embodiment and the embodiment shown in Fig. 10 is that the message carrying the second NSWO authentication result and sent by the AUSF to the charging NF may be different. The type and name of the message carrying the second NSWO authentication result are not limited in this embodiment.
[0406] Optionally, based on the embodiment shown in FIG. 10, another embodiment of the present application provides a method for authentication of an NSWO service. In this embodiment, the AUSF and the UE receive a newly generated key K in the authentication procedure of the NSWO service. AUSF As a result, the newly generated key K AUSF The AUSF information is updated, that is, the relevant network element (e.g., UDM or AMF) needs to update the locally stored AUSF information to the AUSF information corresponding to the NSWO service-related authentication.
[0407] Optionally, in one implementation, Figure 12 is yet another diagram of message exchange of a method for authentication of an NSWO service according to an embodiment of the present application. As shown in Figure 12, the method for authentication of an NSWO service provided in this embodiment is performed by UDM and AMF. After step 23, the method may further include the following steps:
[0408] Step 26: After determining that the EAP-AKA' authentication is successful, the UDM updates the AUSF information.
[0409] Optionally, the AUSF information may include information for identifying the AUSF, such as AUSF group information or an AUSF instance ID.
[0410] Step 27: The UDM sends a first notification message to the AMF. The first notification message includes the AUSF information and the identification information of the UE. In response, the AMF receives the first notification message sent by the UDM.
[0411] Step 28: The AMF determines a UE context based on the identification information of the UE, and replaces the AUSF information in the UE context with the AUSF information in the first notification message.
[0412] The UE identity is used to uniquely distinguish different UEs. Optionally, the UE identity can be one of the following: SUP, A callback uri that corresponds to the SUPI, or It may also include one of the correlation ids that correspond to the SUPI.
[0413] Optionally, the first notification message is a message corresponding to an existing UDM service. The name of the existing UDM service and the name of the message corresponding to the existing UDM service are not limited in this embodiment. For example, the first notification message is an SDM notification message (Numd_SDM_notification).
[0414] In this implementation, the UDM may be known to notify the AMF to update the locally stored AUSF information to complete the update of the AUSF information.
[0415] Optionally, in another implementation, Figure 13 is yet another diagram of message exchange of a method for authentication of an NSWO service according to an embodiment of the present application. As shown in Figure 13, the method for authentication of an NSWO service provided in this embodiment is performed by the AUSF and the AMF. After step 22, the method may further include the following steps:
[0416] Step 29: The AUSF sends a second notification message to the AMF. The second notification message includes the AUSF information and the identification information of the UE. In response, the AMF receives the second notification message sent by the AUSF.
[0417] Step 30: The AMF determines a UE context based on the identity information of the UE, and replaces the AUSF information in the UE context with the AUSF information in the second notification message.
[0418] The UE identity is used to uniquely distinguish different UEs. Optionally, the UE identity can be one of the following: SUP, The callback uri for SUPI. A correlation id corresponding to the SUPI, The authentication context ID that corresponds to the SUPI, or It may also include one of the authentication event IDs that correspond to the SUPI.
[0419] Optionally, the second notification message is a message corresponding to an existing AUSF service. The name of the existing AUSF service and the name of the message corresponding to the existing AUSF service are not limited in this embodiment. For example, the second notification message is an SDM notification message (Nausf_SDM_notification).
[0420] In this implementation, the AUSF may be known to notify the AMF to update the locally stored AUSF information to complete the update of the AUSF information.
[0421] An embodiment of the present application further provides a method for authentication of an NSWO service, which is applicable to a scenario in which authentication of the NSWO service needs to be performed again after the UE completes authentication of the NSWO service for the first time, for example, a scenario in which the UE and the AUSF share a key after the UE registers with a 5G network.
[0422] Optionally, in one implementation, the UE and the AUSF may receive a key K AUSF The method for sharing and authenticating an NSWO service may include the following steps:
[0423] 201: UE has key K AUSF Based on this, HMAC-SHA256 (with key K AUSF , fresh parameters, and NSWO indicator).
[0424] HMAC stands for hashed-based message authentication, and HMAC-SHA256() represents the encryption function.
[0425] The freshness parameter may be a counter, a sequence number, etc. to reflect the freshness of the message.
[0426] The NSWO indicator indicates that authentication for the NSWO service is to be performed.
[0427] 202: The UE sends the SUCI, the NSWO indicator, the MAC, and the fresh parameters to the AN device.
[0428] 203: The AN device determines an NSWO network element based on the SUCI, and sends the SUCI, the NSWO indicator, the MAC, and the fresh parameters to the NSWO network element.
[0429] 204: The NSWO network element determines a UDM based on the SUCI, and sends the SUCI, the NSWO indicator, the MAC, and the fresh parameter to the UDM.
[0430] 205: The UDM decrypts the SUCI to obtain the SUPI, and obtains the corresponding AUSF information and the corresponding AUSF address based on the SUPI. The UDM verifies whether the MAC is correct and obtains the verification result.
[0431] Optionally, in one implementation, the UDM verifying whether the MAC is correct may include:
[0432] The UDM sends the SUPI, NSWO indicator, MAC, and fresh parameters to the AUSF.
[0433] AUSF uses the key K based on SUPI. AUSF Determine the key K AUSF , ,and ,the ,NSWO ,indicator ,and ,the ,fresh ,parameter ,are ,used ,to ,verify ,whether ,the ,received ,MAC ,is ,correct.
[0434] If the MAC is verified to be correct, a success indicator is sent to the UDM.
[0435] Optionally, in another implementation, the UDM verifying whether the MAC is correct may include:
[0436] The UDM sends the SUPI, the NSWO indicator, and the fresh parameters to the AUSF.
[0437] The AUSF calculates the MAC' in the same way and sends the MAC' to the UDM.
[0438] The UDM verifies whether the MAC and MAC' are equal.
[0439] If they are equal, the MAC verification is determined to be successful.
[0440] 206: The UDM sends the verification result to the NSWO network element.
[0441] Please refer to step 19 to step 21 in the above embodiment of this application.
[0442] Optionally, in another implementation, the UE and the AMF share a key Knasint, and the method for authentication of the NSWO service may include the following steps:
[0443] 301: The UE calculates a MAC based on the key Knasint, which is HMAC-SHA256(Knasint, fresh parameter, NSWO indicator).
[0444] For the meanings of MAC, HMAC-SHA256(), fresh parameter, and NSWO indicator, please refer to the explanation in the above step 201. The details will not be described again in this specification.
[0445] 302: The UE sends the SUCI, the NSWO indicator, the MAC, and the fresh parameters to the AN device.
[0446] Optionally, a 5G globally unique temporary UE identity (5G-GUTI) may also be transmitted.
[0447] 303: The AN device determines an NSWO network element based on the SUCI, and sends the SUCI, the NSWO indicator, the MAC, and the fresh parameters to the NSWO network element.
[0448] Optionally, if the AN device further receives a 5G-GUTI and the AN can determine the AMF by using the 5G-GUTI, step 307 is performed.
[0449] 304: The NSWO network element determines a UDM based on the SUCI, and sends the SUCI, the NSWO indicator, the MAC, and the fresh parameters to the UDM.
[0450] Optionally, if the NSWO network element further receives 5G-GUTI, and the NSWO network element can determine the AMF by using the 5G-GUTI, step 308 is performed.
[0451] 305: The UDM decrypts the SUCI to obtain the SUPI, and obtains the corresponding AMF information and the corresponding AMF address according to the SUPI. The UDM verifies whether the MAC is correct and obtains the verification result.
[0452] Optionally, in one implementation, the UDM verifying whether the MAC is correct may include:
[0453] The UDM sends the SUPI (or callback uri and / or correlation id), NSWO indicator, MAC, and fresh parameters to the AMF.
[0454] The AMF determines the Knasint based on the SUPI (or callback uri and / or correlation id) and verifies whether the received MAC is accurate using the Knasint, the NSWO indicator, and the fresh parameter.
[0455] If the MAC is verified to be correct, a success indicator is sent to the UDM.
[0456] Optionally, in another implementation, the UDM verifying whether the MAC is correct may include:
[0457] The UDM sends the SUPI (or callback uri and / or correlation id), NSWO indicator, and fresh parameters to the AMF.
[0458] The AMF calculates the MAC' in the same way and sends the MAC' to the UDM.
[0459] The UDM verifies whether the MAC and MAC' are equal.
[0460] If they are equal, the verification is determined to be successful.
[0461] 306: The UDM sends the verification result to the NSWO network element.
[0462] For subsequent actions, please refer to step 19 to step 21 in the above embodiment of this application.
[0463] 307: The AN device sends the 5G-GUTI, NSWO indicator, MAC, and fresh parameters to the AMF.
[0464] The AMF determines the Knasint based on the SUPI (or callback uri and / or correlation id), and verifies whether the received MAC is correct using the Knasint, the NSWO indicator, and the fresh parameter. The AMF sends the verification result to the AN. For the subsequent operations of the AN, please refer to the above embodiment.
[0465] 308: The NSWO network element sends the 5G-GUTI, the NSWO indicator, the MAC, and the fresh parameters to the AMF.
[0466] The AMF determines the Knasint based on the SUPI (or the callback uri and / or the correlation id), and verifies whether the received MAC is correct using the Knasint, the NSWO indicator, and the fresh parameter. The AMF sends the verification result to the NSWO network element. For the subsequent operation of the NSWO network element, please refer to the above embodiment.
[0467] An embodiment of the present application further provides a method for authentication of an NSWO service, which is applied to a scenario in which a 5G network includes a UE, an AN device, an AAA network element, an AUSF, and a UDM.
[0468] Optionally, the embodiment shown in Figures 4A and 4B can be reused. The UDM directly removes CK' and IK' and sends the authentication vector with CK' and IK' removed to the AUSF. The AUSF then sends the authentication vector with CK' and IK' removed to the AAA network element. The UE and the AAA network element then perform two-way authentication. The subsequent actions of the AAA network element are consistent with the operation of the AUSF in the embodiment shown in Figures 4A and 4B. The AAA network element then sends the authentication result to the AN. For the subsequent operation of the AN, please refer to the previous embodiment.
[0469] Optionally, the embodiment shown in Figures 5A and 5B can be reused. The UDM sends the complete authentication vector to the AUSF. After receiving the complete authentication vector from the UDM, the AUSF deletes the CK' and IK', and then sends the authentication vector to the AAA network element. Then, the UE and the AAA network element perform two-way authentication. The subsequent actions of the AAA network element are consistent with the operation of the AUSF in the embodiment shown in Figures 5A and 5B. Then, the AAA network element sends the authentication result to the AN. For the subsequent operation of the AN, please refer to the previous embodiment.
[0470] An embodiment of the present application further provides a method for authentication of an NSWO service, which is applied to a scenario in which a 5G network includes a UE, an AN device, an AAA network element, and a UDM.
[0471] In this case, the AN device may directly connect to the AAA network element, or may first connect to the AAA proxy and then connect to the AAA network element by using the AAA proxy. Then, the AAA network element can obtain the authentication vector from the UDM. In this case, the functions of both the NSWO network element and the AUSF may be implemented by the AAA network element. The AAA network element can obtain the authentication vector from the UDM that does not include the key CK' or IK', and perform the corresponding operation of the AUSF. Alternatively, after the keys CK' and IK' are obtained, the key may be deleted, or another operation is performed. For the specific operation, the action of processing the key by the AUSF in the previous embodiment of the present application may be reused.
[0472] It should be noted that the method for authentication of the NSWO service provided in the embodiment of the present application is not limited to the authentication of the NSWO service, but is also applicable to the authentication of another service. It can be understood that the authentication method and procedure are described in the present application by using the NSWO service as an example. In the authentication procedure of another service, the NSWO network element may be replaced with a service authentication network element, and the service authentication network element participates in the authentication for the UE. If the authentication is successful, the service authentication network element receives the authentication result from the AUSF and sends the result to the AN. The operations for the other keys include CK', IK', K AUSF The operations are similar to those described above for the AN, etc. Furthermore, the operations performed by the AN based on the authentication result are not limited.
[0473] To implement the aforementioned functions, it can be understood that the device in this application includes corresponding hardware and / or software modules for performing the functions. With reference to the algorithms and steps in the examples described in the embodiments disclosed herein, the application can be implemented by hardware or a combination of hardware and computer software. Whether the functions are performed by hardware or by hardware driven by computer software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the functions described for each specific application with reference to the embodiments. However, the implementation should not be considered to go beyond the scope of this application.
[0474] In the embodiment of the present application, each device may be divided into functional modules based on the above-mentioned method example. For example, the functional modules may be divided according to functions, or two or more functions may be integrated into one processing module. It should be noted that the division of modules in the embodiment of the present application is an example, and is merely a division of logical functions. During actual implementation, other division methods may be used. It should be noted that the names of modules in the embodiment of the present application are an example, and the names of modules are not limited during actual implementation.
[0475] When each functional module is obtained by dividing according to each corresponding function, FIG. 14 is a schematic diagram of a structure of a communication device according to an embodiment of the present application. As shown in FIG. 14, the communication device may include a sending module 1402, a receiving module 1403 and a processing module 1401.
[0476] The transmitting module 1402 is configured to transmit data.
[0477] The receiving module 1403 is configured to receive data.
[0478] The processing module 1401 is configured to perform other steps for implementing the method for authentication of NSWO services provided in the above method embodiments.
[0479] FIG. 15 is a schematic diagram of another structure of a communication device according to an embodiment of the present application. Optionally, the communication device may be a terminal device, an AN device, an NSWO network element, an AUSF, or a UDM. As shown in FIG. 15, the communication device may include a processor 1501, a receiver 1502, a transmitter 1503, a memory 1504, and a bus 1505. The processor 1501 includes one or more processing cores. The processor 1501 executes software programs and modules to perform various function applications and information processing. The receiver 1502 and the transmitter 1503 may be implemented as communication components, and the communication components may be baseband chips. The memory 1504 is connected to the processor 1501 by using the bus 1505. The memory 1504 may be configured to store at least one program instruction, and the processor 1501 is configured to execute at least one program instruction to implement the technical solutions in the foregoing embodiments. The principles and technical effects of the implementation are similar to those of the method-related embodiments described above, and the details will not be described again herein.
[0480] In this embodiment of the present application, the processor may be a general-purpose processor, a digital signal processor, an application-specific IC, a field programmable gate array or another programmable logic device, a discrete gate or transistor logic device, or a discrete hardware component, and may implement or perform the methods, steps, and logic block diagrams disclosed in the embodiments of the present application. The general-purpose processor may be a microprocessor or any conventional processor, etc. The steps of the methods disclosed with reference to the embodiments of the present application may be performed directly by a hardware processor, or may be performed by using a combination of hardware and software modules in a processor.
[0481] In this embodiment of the application, the memory may be a non-volatile memory such as a hard disk drive (HDD) or a solid-state drive (SSD), or a volatile memory such as a random access memory (RAM). The memory may be any medium that can be used to carry or store expected program code in the form of, but not limited to, instructions or data structures and that can be accessed by a computer. Alternatively, the memory in this embodiment of the application may be a circuit or any other device that can implement a storage function and is configured to store program instructions and / or data.
[0482] An embodiment of the present application provides a computer program product. When the computer program product runs on a device, the device is enabled to perform the technical solutions in the above-mentioned embodiments. The principles and technical effects of its implementation are similar to those of the above-mentioned related embodiments, and the details are not described again in this specification.
[0483] An embodiment of the present application provides a computer-readable storage medium. The computer-readable storage medium stores program instructions. When the program instructions are executed by a device, the device is enabled to perform the technical solutions in the above-mentioned embodiments. The principles and technical effects of the implementation forms thereof are similar to those of the above-mentioned related embodiments, and the details are not described again in this specification.
[0484] In conclusion, the above embodiments are only intended to describe the technical solutions of the present application, and are not intended to limit the present application. Although the present application has been described in detail with reference to the above embodiments, it should be understood that those skilled in the art can still make modifications to the technical solutions described in the above embodiments, or make equivalent substitutions to some technical features thereof, without departing from the scope of the technical solutions of the embodiments of the present application. [Explanation of symbols]
[0485] 1401 Processing Module 1402 Transmitting Module 1403 Receiver Module 1501 Processor 1502 Receiver 1503 Transmitter 1504 Memory 1505 Bus
Claims
1. 1. A method for authentication of a non-seamless wireless local area network offload (NSWO) service, comprising: receiving a first authentication request message from an NSWO network element, the first authentication request message including a subscription hiding identifier (SUCI) and fourth NSWO indication information, the fourth NSWO indication information indicating authentication of the NSWO service; sending a second authentication request message to a unified data management based on the fourth NSWO indication information, the second authentication request message including the SUCI and fifth NSWO indication information, the fifth NSWO indication information indicating to authenticate the NSWO service; receiving a second authentication response message from the unified data management, the second authentication response message including a second Extensible Authentication Protocol-Authentication and Key Agreement (EAP-AKA') authentication vector and a Subscription Persistent Identifier (SUPI) of a terminal device, the SUPI corresponding to the SUCI; sending a first authentication response message to the NSWO network element based on the second authentication response message, the first authentication response message being an authentication response message corresponding to an EAP-AKA' authentication algorithm; receiving a fifth authentication request message from the NSWO network element; performing authentication on the terminal device based on the fifth authentication request message and the second EAP-AKA' authentication vector; A method comprising:
2. The method of claim 1 , further comprising: determining to perform authentication of the NSWO service based on the fourth NSWO indication information.
3. The second authentication response message includes a RAND and an AUTN, and the step of sending the first authentication response message to the NSWO network element based on the second authentication response message includes: sending the first authentication response message including the RAND and the AUTN to the NSWO network element; 2. The method of claim 1, comprising:
4. The method of claim 1 , wherein the first authentication response message comprises an Extensible Authentication Protocol / authentication and key agreement-challenge.
5. the fifth authentication request message includes RES and the second EAP-AKA' authentication vector includes XRES, and the step of authenticating the terminal device based on the fifth authentication request message and the second EAP-AKA' authentication vector includes: verifying whether said RES and said XRES are equal 2. The method of claim 1, comprising:
6. the second EAP-AKA' authentication vector includes a key CK' and a key IK', and after the step of authenticating the terminal device based on the fifth authentication request message, the method further comprises: key K AUSF wherein said step of calculating said key K AUSF is calculated based on said key CK' and said key IK', The method of claim 1, further comprising:
7. 2. The method of claim 1, wherein the first authentication request message is an authentication service request message for user equipment (UE) authentication, the first authentication response message is an authentication service response message for UE authentication, the second authentication request message is a service request obtain message for user equipment (UE) authentication, and the second authentication response message is a service response obtain message for UE authentication.
8. The method of claim 1, wherein the first authentication request message further includes an access network identity, and the second authentication request message further includes the access network identity, and the access network identity is used to perform authentication of the NSWO service.
9. The second EAP-AKA' authentication vector includes a key CK' and a key IK', and the step of sending the first authentication response message to the NSWO network element based on the second authentication response message includes: deleting the key CK' and the key IK' from the second EAP-AKA' authentication vector; sending the first authentication response message to the NSWO network element, the first authentication response message including the second EAP-AKA' authentication vector with the key deleted; 2. The method of claim 1, comprising:
10. 1. A method for authentication of a non-seamless wireless local area network offload (NSWO) service, comprising: receiving a second authentication request message from an authentication server function, the second authentication request message including a subscription hiding identifier (SUCI) and a fifth NSWO indication, the fifth NSWO indication indicating to authenticate the NSWO service; calculating a Subscription Persistent Identifier (SUPI) based on the SUCI; determining, based on the second authentication request message, to use an Extensible Authentication Protocol-Authentication and Key Agreement (EAP-AKA') authentication method; obtaining a first EAP-AKA' authentication vector based on the SUPI; sending a second authentication response message to the authentication server function, the second authentication response message including a second EAP-AKA' authentication vector, the second EAP-AKA' authentication vector being associated with the first EAP-AKA' authentication vector; A method comprising:
11. the second EAP-AKA' authentication vector is associated with the first EAP-AKA' authentication vector; the second EAP-AKA' authentication vector is the same as the first EAP-AKA' authentication vector; The method of claim 10.
12. the second EAP-AKA' authentication vector is associated with the first EAP-AKA' authentication vector; the second EAP-AKA' authentication vector being a portion obtained after keys CK' and IK' are deleted from the first EAP-AKA' authentication vector. The method of claim 10.
13. The method of claim 10, wherein the second authentication request message further includes an access network identity, and the access network identity is used to perform authentication of the NSWO service.
14. 11. The method of claim 10, wherein the second authentication request message is a service acquisition request message for user equipment (UE) authentication, and the second authentication response message is a service acquisition response message for UE authentication.
15. 1. A method for authentication of a non-seamless wireless local area network offload (NSWO) service, comprising: After the terminal device determines to perform the NSWO service, sending a subscription hidden identifier (SUCI) of the terminal device to an access network device, the SUCI being used to determine an address of an NSWO network element; receiving a third authentication request message via the access network device from the NSWO network element, the third authentication request message being an authentication request message corresponding to an Extensible Authentication Protocol-Authentication and Key Agreement EAP-AKA' authentication algorithm; performing authentication verification to a network by using the EAP-AKA' authentication algorithm; calculating RES after the authentication verification is successful; sending the RES to the NSWO network element via the access network device, the RES being used to perform authentication for the terminal device; A method comprising:
16. After the authentication verification is successful, the method further comprises: Calculate the key CK' and the key IK', and AUSF cancelling the step of calculating the key K AUSF is calculated based on said key CK' and said key IK', 16. The method of claim 15, further comprising:
17. 17. The method of claim 16, after the step of calculating the keys CK' and IK', the method further comprises the step of deleting the keys CK' and IK'.
18. 1. A communications device comprising at least one processor and at least one memory, the at least one memory configured to store instructions, and the at least one processor configured to execute the instructions, thereby providing the communications device with: receiving a first authentication request message from a non-seamless wireless local area network offload (NSWO) network element, the first authentication request message including a subscription hiding identifier (SUCI) and fourth NSWO indication information, the fourth NSWO indication information indicating authentication for an NSWO service; Sending a second authentication request message to a unified data management based on the fourth NSWO indication information, the second authentication request message including the SUCI and fifth NSWO indication information, the fifth NSWO indication information indicating to authenticate the NSWO service; receiving a second authentication response message from the unified data management, the second authentication response message including a second Extensible Authentication Protocol-Authentication and Key Agreement (EAP-AKA') authentication vector and a Subscription Persistent Identifier (SUPI) of a terminal device, the SUPI corresponding to the SUCI; Sending a first authentication response message to the NSWO network element based on the second authentication response message, the first authentication response message being an authentication response message corresponding to an EAP-AKA' authentication algorithm; receiving a fifth authentication request message from the NSWO network element; performing authentication on the terminal device based on the fifth authentication request message and the second EAP-AKA' authentication vector; A communication device that performs the above.
19. The at least one processor is further configured to execute the instructions, thereby causing the communication device to: determining to authenticate the NSWO service based on the fourth NSWO instruction information; 20. The communication device of claim 18.
20. The second authentication response message includes RAND and AUTN, and the at least one processor is further configured to execute the instructions, thereby causing the communication device to: causing the NSWO network element to transmit the first authentication response message including the RAND and the AUTN; 20. The communication device of claim 18.
21. 20. The communications device of claim 18, wherein the first authentication response message comprises an Extensible Authentication Protocol / authentication and key agreement-challenge.
22. the fifth authentication request message includes RES and the second EAP-AKA' authentication vector includes XRES, and the at least one processor is further configured to execute the instructions, thereby causing the communication device to: Verify whether the RES and the XRES are equal.
20. The communication device of claim 18.
23. the second EAP-AKA' authentication vector includes a key CK' and a key IK', and the at least one processor is further configured to execute the instructions, thereby causing the communication device to: After authenticating the terminal device based on the fifth authentication request message, a key K AUSF , and the key K AUSF is calculated based on the key CK′ and the key IK′, 20. The communication device of claim 18.
24. 20. The communications device of claim 18, wherein the first authentication request message is an authentication service request message for user equipment (UE) authentication, the first authentication response message is an authentication service response message for UE authentication, the second authentication request message is a service request obtain message for user equipment (UE) authentication, and the second authentication response message is a service response obtain message for UE authentication.
25. 20. The communications device of claim 18, wherein the first authentication request message further includes an access network identity, and the second authentication request message further includes the access network identity, the access network identity being used to perform authentication of the NSWO service.
26. the second EAP-AKA' authentication vector includes a key CK' and a key IK', and the at least one processor is further configured to execute the instructions, thereby causing the communication device to: deleting the key CK' and the key IK' from the second EAP-AKA' authentication vector; sending the first authentication response message to the NSWO network element, the first authentication response message including the second EAP-AKA' authentication vector with the key deleted; The communication device according to claim 18,
27. 1. A communications device comprising at least one processor and at least one memory, the at least one memory configured to store instructions, and the at least one processor configured to execute the instructions, thereby providing the communications device with: receiving a second authentication request message from an authentication server function, the second authentication request message including a subscription hiding identifier (SUCI) and a fifth NSWO indication, the fifth NSWO indication indicating authentication for an NSWO service; calculating a subscription persistent identifier (SUPI) based on the SUCI, determining to use an Extensible Authentication Protocol-Authentication and Key Agreement (EAP-AKA) authentication method based on the second authentication request message, and obtaining a first EAP-AKA authentication vector based on the SUPI; sending a second authentication response message to the authentication server function, the second authentication response message including a second EAP-AKA' authentication vector, the second EAP-AKA' authentication vector being associated with the first EAP-AKA' authentication vector; A communication device that performs the above.
28. the second EAP-AKA' authentication vector is associated with the first EAP-AKA' authentication vector; the second EAP-AKA' authentication vector is the same as the first EAP-AKA' authentication vector; 28. A communication device as claimed in claim 27.
29. the second EAP-AKA' authentication vector is associated with the first EAP-AKA' authentication vector; the second EAP-AKA' authentication vector being a portion obtained after keys CK' and IK' are deleted from the first EAP-AKA' authentication vector.
28. A communication device as claimed in claim 27.
30. 28. The communications device of claim 27, wherein the second authentication request message further includes an access network identity, the access network identity being used to perform authentication for the NSWO service.
31. 28. The communications apparatus of claim 27, wherein the second authentication request message is a service acquisition request message for user equipment (UE) authentication, and the second authentication response message is a service acquisition response message for UE authentication.
32. 1. A communications device comprising at least one processor and at least one memory, the at least one memory configured to store instructions, and the at least one processor configured to execute the instructions, thereby providing the communications device with: After it is determined to perform a non-seamless wireless local area network offload (NSWO) service, sending a subscription concealment identifier (SUCI) of the terminal device to the access network device, where the SUCI is used to determine an address of an NSWO network element; receiving a third authentication request message from the NSWO network element via the access network device, the third authentication request message being an authentication request message corresponding to an Extensible Authentication Protocol-Authentication and Key Agreement EAP-AKA' authentication algorithm; performing authentication verification to a network by using the EAP-AKA' authentication algorithm; After the authentication verification is successful, calculating RES; Sending the RES to the NSWO network element via the access network device, the RES being used to perform authentication for the terminal device; and A communication device that performs the above.
33. The at least one processor is further configured to execute the instructions, thereby causing the communication device to: After the authentication verification is successful, Calculate the key CK' and the key IK', and AUSF , and the key K AUSF is calculated based on the key CK′ and the key IK′, 33. A communication device as claimed in claim 32.
34. The at least one processor is further configured to execute the instructions, thereby causing the communication device to: After calculating the keys CK' and IK', deleting the keys CK' and IK'.
34. A communication device as claimed in claim 33.
35. 17. A computer readable storage medium storing computer instructions which, when executed on an electronic device, enable the electronic device to perform the method according to any one of claims 1 to 9, or to perform the method according to any one of claims 10 to 14, or to perform the method according to any one of claims 15 to 17.
36. A communication device configured to perform a method according to any one of claims 1 to 9.
37. A communication device configured to perform a method according to any one of claims 10 to 14.
38. A communications device configured to perform a method according to any one of claims 15 to 17.
39. A communication system comprising a network device configured to perform the method according to any one of claims 1 to 9 and a network device configured to perform the method according to any one of claims 10 to 14.
40. 1. A method for authentication of a non-seamless wireless local area network offload (NSWO) service, comprising: receiving, by an authentication server function, a first authentication request message sent by an NSWO network element, the first authentication request message including a subscription hiding identifier, a SUCI, and fourth NSWO indication information, the fourth NSWO indication information indicating to perform authentication for the NSWO service; determining, by the authentication server function, to authenticate the NSWO service based on the fourth NSWO instruction information; sending, by the authentication server function, a second authentication request message including the SUCI and a fifth NSWO indication to a unified data management, the fifth NSWO indication indicating to authenticate the NSWO service; receiving, by the unified data management, the second authentication request message sent by the authentication server function; calculating, by the unified data management, a subscription persistent identifier (SUPI) based on the SUCI; determining, by the unified data management, based on the second authentication request message, to use an Extensible Authentication Protocol-Authentication and Key Agreement (EAP-AKA') authentication method; obtaining, by the unified data management, a first EAP-AKA' authentication vector based on the SUPI; sending, by the unified data management, a second authentication response message to the authentication server function, the second authentication response message including a second EAP-AKA' authentication vector, the second EAP-AKA' authentication vector being associated with the first EAP-AKA' authentication vector; receiving, by the authentication server function, the second authentication response message sent by the unified data management; sending, by the authentication server function, a first authentication response message to the NSWO network element based on the second authentication response message, the first authentication response message being an authentication response message corresponding to an EAP-AKA' authentication algorithm; receiving, by the authentication server function, a fifth authentication request message sent by the NSWO network element; performing, by the authentication server function, authentication of a terminal device based on the fifth authentication request message and the second EAP-AKA' authentication vector; A method comprising: