Access control method and communication device
By transmitting authentication server information and manufacturer data, communication devices can authenticate and configure certificates without initial network credentials, addressing security risks and ensuring legitimate access.
Patent Information
- Application Number
- JP2024162070
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Priority Date
- 2020-03-20
- Filing Date
- 2024-09-19
- Publication Date
- 2025-12-15
- Estimated Expiration
- 2041-03-19
AI Technical Summary
Communication devices often lack network credentials, such as Standalone Non-Public Network (SNPN) credentials at shipment, preventing successful network authentication and exposing them to security risks like resource consumption by unauthorized terminals.
The method involves transmitting index and address information of a second authentication server, along with manufacturer-related info, to request certificates or indicate restricted access, enabling authentication and configuration even without initial network credentials, using manufacturer servers for verification.
This approach supports authentication and secure configuration of communication devices, preventing unauthorized access and resource misuse, ensuring legitimate terminals obtain necessary certificates.
Smart Images

Figure 0007785888000001 
Figure 0007785888000002 
Figure 0007785888000003
Abstract
Description
CROSS-REFERENCE TO RELATED APPLICATIONS
[0001] This application claims priority from Chinese Patent Application No. 202010203175.8, filed in China on March 20, 2020, the entire contents of which are incorporated herein by reference. [Technical Field]
[0002] The present invention relates to the technical field of wireless communication, and in particular to an access control method and a communication device. [Background technology]
[0003] In some communication scenarios, there are scenarios in which a communication device accesses a network without having a network credential, for example, a terminal does not have a Standalone Non-Public Network (SNPN) credential at the time of shipment, and therefore cannot successfully authenticate the SNPN. Currently, information related to the authentication of the communication device cannot be obtained before successfully authenticating the network. Summary of the Invention [Problem to be solved by the invention]
[0004] The embodiments of the present invention provide an access control method and a communication device for solving the problem of not being able to obtain information related to the authentication of a communication device. [Means for solving the problem]
[0005] According to a first aspect, an embodiment of the present invention provides an access control method for use in a first communication device, the access control method comprising: transmitting first information and / or first instruction information to the first target end, wherein the first information is: index information of a second authentication server; Related information about the manufacturer of the first communication device; and address related information of the second authentication server; The first indication information is used to request obtaining a certificate related to the first network or to indicate that the type of access is a restricted service.
[0006] According to a second aspect, an embodiment of the present invention provides an access control method for use in a second communication device, the access control method comprising: Obtaining at least one of first information, first instruction information, a valid device list, and third information; performing a first operation based on at least one of the first information, first instruction information, a list of authorized devices, and third information; wherein the first information includes at least one of index information of a second authentication server, related information of a manufacturer of the first communication device, and address related information of the second authentication server; the first indication information is used to indicate that a type of access to a first network requires obtaining a certificate related to the first network or is a restricted service; The third information is Mapping information between index information of the second authentication server and address-related information of the second authentication server; and address related information of the second authentication server.
[0007] According to a third aspect, an embodiment of the present invention provides an access control method for use in a third communication device, the access control method comprising: determining the third information; and transmitting third information; Among them, the third information is: Mapping information between index information of a second authentication server and address-related information of the second authentication server; and address related information of the second authentication server.
[0008] According to a fourth aspect, an embodiment of the present invention provides an access control method for use in a fourth communication device, the access control method comprising: Obtaining second information; and performing a second operation based on the second information; Among them, the second information is: a first terminal routing selection policy; Setting the default DNN information to empty, Setting the default slice information to empty, relevant information for establishing a first data channel; a second instruction; and a third instruction; and Address-related information of the first server; and address related information of the second authentication server; Wherein, the first server is a server that can locate a certificate related to a first network; the first terminal routing selection policy is used to access a first server or a certificate download application; the first data channel is a data channel in a first network; The second instruction information is the first data channel is used for interaction between a first communication device and a first server; the first data channel is used by a first communication device to request a certificate associated with a first network; the first data channel is used to configure a certificate associated with a first network in a first communication device; The third instruction information is used to instruct at least one of allowing only restricted services, allowing only the control plane, not allowing the user plane, allowing only access to the first server, and allowing only the certificate download application.
[0009] According to a fifth aspect, an embodiment of the present invention provides an access control method for use in a fifth communication device, the access control method comprising: transmitting second information, wherein the second information comprises: a first terminal routing selection policy; Setting the default DNN information to empty, Setting the default slice information to empty, relevant information for establishing a first data channel; a second instruction; and a third instruction; and Address-related information of the first server; and address related information of the second authentication server; Wherein, the first server is a server that can locate a certificate related to a first network; the first terminal routing selection policy is used to access a first server or a certificate download application; the first data channel is a data channel in a first network; The second instruction information is the first data channel is used for interaction between a first communication device and a first server; the first data channel is used by a first communication device to request a certificate associated with a first network; the first data channel is used to configure a certificate associated with a first network in a first communication device; The third instruction information is used to instruct at least one of allowing only restricted services, allowing only the control plane, not allowing the user plane, allowing only access to the first server, and allowing only the certificate download application.
[0010] According to a sixth aspect, an embodiment of the present invention provides a communications device, the communications device being a first communications device, the communications device comprising: a first transmitting module for transmitting first information and / or first instruction information to a first target end, wherein the first information is: index information of a second authentication server; Related information about the manufacturer of the first communication device; and address related information of the second authentication server; The first indication information is used to request obtaining a certificate related to the first network or to indicate that the type of access is a restricted service.
[0011] According to a seventh aspect, an embodiment of the present invention provides a communication device, the communication device being a second communication device, the communication device comprising: an acquisition module for acquiring at least one of the first information, the first instruction information, and the third information; an execution module for executing a first operation based on at least one of the first information, first instruction information, and third information; wherein the first information includes at least one of index information of a second authentication server, related information of a manufacturer of the first communication device, and address related information of the second authentication server; the first indication information is used to indicate that a type of access to a first network requires obtaining a certificate related to the first network or is a restricted service; The third information is Mapping information between index information of the second authentication server and address-related information of the second authentication server; and address related information of the second authentication server.
[0012] According to an eighth aspect, an embodiment of the present invention provides a third communication device, the communication device comprising: a transmitting module for transmitting third information; Among them, the third information is: Mapping information between index information of a second authentication server and address-related information of the second authentication server; and address related information of the second authentication server.
[0013] According to a ninth aspect, an embodiment of the present invention provides a communication device, the communication device being the fourth communication device, comprising: an acquisition module for acquiring second information; an execution module for executing a second operation based on the second information; Among them, the second information is: relevant information for establishing a first data channel; a second instruction; and Address-related information of the first server; and address related information of the second authentication server; Wherein, the first server is a server that can locate a certificate related to a first network; the first data channel is a data channel in a first network; The second instruction information is the first data channel is used for interaction between a first communication device and a first server; the first data channel is used by a first communication device to request a certificate associated with a first network; the first data channel is used to configure a certificate associated with a first network in a first communications device.
[0014] According to a tenth aspect, an embodiment of the present invention provides a communication device, which is the fifth communication device, comprising: a transmitting module for transmitting second information, wherein the second information is: relevant information for establishing a first data channel; a second instruction; and Address-related information of the first server; and address related information of the second authentication server; Wherein, the first server is a server that can locate a certificate related to a first network; the first data channel is a data channel in a first network; The second instruction information is the first data channel is used for interaction between a first communication device and a first server; the first data channel is used by a first communication device to request a certificate associated with a first network; the first data channel is used to configure a certificate associated with a first network in a first communications device.
[0015] According to an eleventh aspect, an embodiment of the present invention provides a communications device, the communications device including a processor, a memory, and a computer program stored in the memory and operable to run on the processor, the computer program being configured to, when executed by the processor, perform steps of the access control method according to the first aspect, or the second aspect, or the third aspect, or the fourth aspect, or the fifth aspect.
[0016] According to a twelfth aspect, an embodiment of the present invention provides a computer-readable storage medium having a computer program stored thereon, which, when executed by the processor, causes the steps of the access control method according to the first aspect, the steps of the access control method according to the second aspect, the steps of the access control method according to the third aspect, the steps of the access control method according to the fourth aspect, or the steps of the access control method according to the fifth aspect. [Effects of the Invention]
[0017] In an embodiment of the present invention, first information and / or first instruction information is sent to a first target end, where the first information includes at least one of index information of a second authentication server, information related to the manufacturer of the first communication device, and information related to the address of the second authentication server, and the first instruction information is used to request the first communication device to obtain a certificate associated with the first network or to indicate that the access type is a restricted service. In this way, it is possible to support obtaining authentication-related information for the communication device, and it is also possible to support authenticating and configuring the communication device when the communication device has not obtained a certificate associated with the network. Specifically, the first network can select a second authentication server to authenticate the first communication device, thereby supporting authenticating the terminal when the terminal accesses the first network without a certificate associated with the first network, thereby avoiding security attacks on the first network by impersonating terminals and unauthorized terminals, and supporting configuration for the first communication device, thereby supporting the authorized terminal to obtain a certificate associated with the first network. [Brief explanation of the drawings]
[0018] Various other advantages and benefits will become apparent to those skilled in the art upon reading the following detailed description of the preferred embodiments. The accompanying drawings are used only for purposes of illustrating the preferred embodiments and are not to be considered as limiting the invention, and like parts are represented by like reference characters throughout the accompanying drawings. In the accompanying drawings: [Figure 1] 1 is a schematic diagram of the architecture of a wireless communication system according to an embodiment of the present invention; [Figure 2] 2 is a flowchart of an access control method according to an embodiment of the present invention. [Figure 3] 4 is a flowchart of another access control method according to an embodiment of the present invention. [Figure 4] 4 is a flowchart of another access control method according to an embodiment of the present invention. [Figure 5] 4 is a flowchart of another access control method according to an embodiment of the present invention. [Figure 6] 4 is a flowchart of another access control method according to an embodiment of the present invention. [Figure 7] 1 is a schematic diagram of an access control method according to an embodiment of the present invention; [Figure 8] FIG. 4 is a schematic diagram of another access control method according to an embodiment of the present invention. [Figure 9] FIG. 4 is a schematic diagram of another access control method according to an embodiment of the present invention. [Figure 10] FIG. 4 is a schematic diagram of another access control method according to an embodiment of the present invention. [Figure 11] 1 is a structural diagram of a communication device according to the present invention; [Figure 12] FIG. 2 is a structural diagram of another communication device according to the present invention; [Figure 13] FIG. 2 is a structural diagram of another communication device according to the present invention; [Figure 14] FIG. 2 is a structural diagram of another communication device according to the present invention; [Figure 15] FIG. 2 is a structural diagram of another communication device according to the present invention; [Figure 16] FIG. 2 is a structural diagram of another communication device according to the present invention; DETAILED DESCRIPTION OF THE INVENTION
[0019] The following clearly and completely describes the technical solutions in the embodiments of the present invention, in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only some of the embodiments of the present invention, and not all of the embodiments. All other embodiments obtained by those skilled in the art based on the embodiments of the present invention without any creative effort are also within the scope of protection of the present invention.
[0020] The term "comprises" and any variations thereof in the specification and claims of this application are intended to cover a non-exclusive "comprises," for example, a process, method, system, product, or apparatus comprising a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units that are not explicitly listed or that are inherent to the process, method, product, or apparatus. Note that "and / or" used in the specification and claims represents at least one of the connected objects, for example, A and / or B represents the three cases of A alone, B alone, and a combination of A and B.
[0021] In the embodiments of the present invention, terms such as "exemplary" or "for example" are used to describe as an example, illustration, or explanation. In the embodiments of the present invention, any embodiment or design described as "exemplary" or "for example" should not be construed as preferred or advantageous over other embodiments or designs. Rather, the use of terms such as "exemplary" or "for example" is intended to present the relevant concept in a concrete manner.
[0022] The following describes embodiments of the present invention in conjunction with the accompanying drawings. An access control method and a communication device according to the embodiments of the present invention can be used in a wireless communication system, which may be a 5G system, an evolved long term evolution (eLTE) system, or a subsequent evolution communication system.
[0023] The following describes an embodiment of the present invention with reference to the accompanying drawings. The access control method and communication device according to the embodiment of the present invention can be used in the network system shown in Figure 1. The network system shown in Figure 1 includes a terminal (UE), a first network, and devices other than the first network, such as manufacturer's devices.
[0024] Among them, the terminal can access a first network, for example, an SNPN (non-public network), and the SNPN may be a 5G communication network, for example, including a 5G radio access network (NG-RAN), an access and mobility management function (AMF), a session management function (SMF), and a user plane function (UPF).
[0025] The manufacturer equipment may be related equipment of the terminal manufacturer (also called vendor), such as a vendor server, an application function (AF), and an authentication, authorization, and accounting (AAA) server.
[0026] The manufacturer equipment may authenticate the terminal, or the SNPN may authenticate the terminal according to the information of the manufacturer equipment.
[0027] 1 is merely an illustrative example to which the access control method and communication device according to the embodiment of the present invention can be applied, and the embodiment of the present invention is not particularly limited thereto. For example, the above network system is It may further include a Unified Data Management (UDM), a network exposure function (NEF), and a Config server.
[0028] It can also be used in communication systems such as 4G and 6G.
[0029] The access control method according to the embodiment of the present invention can solve the following technical problems.
[0030] Problem 1: When a UE accesses a first network without having a certificate associated with the first network, the problem of how to select an authentication server needs to be solved.
[0031] Scenario 1: A terminal UE of a first network (e.g., an SNPN) does not yet have a certificate (e.g., credential) of the SNPN when shipped and cannot successfully authenticate the SNPN. One way to think about this is that the UE first initially accesses the SNPN, the SNPN configures a certificate for the UE, and the UE accesses the SNPN based on the newly configured certificate.
[0032] During the initial access process of a UE without an SNPN certificate, the SNPN cannot authenticate the UE and can only authorize all UEs requesting access, such as establishing a user plane PDU session to certificate configuration server. Because there is no authentication mechanism within the SNPN, it must rely on the certificate configuration server to trigger authentication for the UE. After authentication fails, it releases the UE connection, PDU session resources, etc.
[0033] This method of allocating resources without authentication presents a risk of attack, i.e., any unauthorized UE in the SNPN may initiate initial access and consume all of the resources of the SNPN, while a spoofed UE may spoof legitimate UE access.
[0034] Therefore, even during the initial access process of a UE without a certificate for the SNPN, the UE needs to be authenticated. One possible method is authentication by the authentication server of the manufacturer to which the UE is shipped. When shipping the UE, the UE manufacturer places a certificate in the UE that can be authenticated by the manufacturer's authentication server. After an interface is opened between the SNPN and the manufacturer's server, allowing the UE to access the SNPN, mutual authentication between the UE and the SNPN is achieved through authentication between the UE and the manufacturer's authentication server. Since there may be multiple manufacturers of UEs for an SNPN, there will be multiple authentication servers for the manufacturers. Therefore, when a UE accesses a first network without a certificate associated with the first network, it is necessary to solve the problem of how to select an authentication server.
[0035] Scenario 2: Also, the Tracking Area Code (TAC) information included in the International Mobile Equipment Identity (IMEI) or Permanent Equipment Identifier (PEI) can be used to identify the manufacturer, but one manufacturer's TAC can only cover a few hundred devices. Identifying the manufacturer with the TAC requires constant synchronization with the SNPN, which increases maintenance complexity. Therefore, it is necessary to solve the problem of how to efficiently select the manufacturer's authentication server.
[0036] In one alternative method, an interface between a manufacturer-related device and the first network is opened, and mapping information between authentication server address information and authentication server index information is provided to the first network. A UE that does not have a first network-related certificate provides the authentication server index information when accessing the first network. The first network verifies the authentication server address based on the authentication server index information provided by the UE and the mapping information between authentication server address information and authentication server index information provided by the manufacturer, and initiates an authentication request for the UE to the authentication server. The authentication server may be a device related to the UE manufacturer.
[0037] In another alternative method, the manufacturer-related device and the first network perform mutual authentication to obtain the address-related information of a reliable authentication server. When a UE that does not have a first network-related certificate accesses the first network, the UE provides the address-related information of the authentication server. Based on the address-related information of the authentication server provided by the UE and the address-related information of the authentication server provided externally, the first network verifies that the address-related information of the authentication server is reliable and initiates an authentication request for the UE to the authentication server.
[0038] Scenario 3: When there is only one manufacturer of terminals in the first network, there is only one authentication server for that manufacturer. When a terminal that does not have a certificate associated with the first network accesses the first network, the first network cannot distinguish whether the terminal is accessing the first network for another restricted service (e.g., emergency service) or for distributing a certificate associated with the first network. Only in the latter case does the terminal need to be authenticated by the manufacturer's authentication server. Therefore, it is necessary to solve the problem of whether to authenticate the terminal by an external authentication server.
[0039] In one alternative method, when the UE accesses the first network, the UE sends first indication information to request obtaining a certificate related to the first network or to indicate that the access type is a restricted service, and based on the first indication information, the first network can determine whether to authenticate the terminal through an external authentication server (e.g., an authentication server of a terminal manufacturer).
[0040] Problem 2: The problem of how the UE obtains the address-related information of the certificate configuration server needs to be solved.
[0041] When shipped, the terminal UE of the first network (eg, SNPN) does not yet have a certificate related to the first network, and does not have related information of the certificate configuration server.
[0042] As an alternative, the UE manufacturer configures the address-related information or index information of the configuration server in the UE, and the configuration server and the first network need to additionally configure information of the first network, which has a corresponding meaning.
[0043] In another alternative method, the UE accesses the first network, and after successful authentication, the first network provides the UE with address-related information or index information of the configuration server. Since the UE has been successfully authenticated, the UE and the first network mutually trust each other. As can be easily understood, the address-related information of the configuration server provided at this time is trustworthy.
[0044] Problem 3: If the authentication server successfully authenticates the UE, it can prove the identity of the UE and it is not a fake UE. However, it is necessary to solve the problem of how to verify whether the UE is a legitimate UE of the first network and whether to allow the UE to configure a certificate related to the first network.
[0045] As an alternative, successful authentication of the UE by the authentication server indicates that the UE is a valid UE in the first network, i.e., the authentication server not only authenticates that the UE is a UE, but also authenticates that the UE is a valid UE in the first network.
[0046] Alternatively, once the UE has been successfully authenticated by the authentication server, the first network will confirm that the UE is a valid UE of the first network.
[0047] Problem 4: The UE requests the configuration server to configure a certificate related to a first network, and to configure the certificate in the UE, the configuration server needs to confirm that the UE is a valid UE of the first network or confirm that the UE is authorized to configure a certificate related to the first network.
[0048] As an alternative method, mutual authentication between the UE and the authentication server is realized by the configuration server. By opening the interface between the configuration server and the authentication server, mutual authentication between the UE, the configuration server, and the authentication server is realized. Since there may be multiple manufacturers of UEs in an SNPN, there are authentication servers for multiple manufacturers. Therefore, when the UE does not have a certificate related to the first network and requests the configuration server to configure a certificate related to the first network, it is necessary to solve the problem of how to select an authentication server. This problem is similar to problem 1.
[0049] As another alternative, the location server relies on the first network's valid authentication of the UE, and considers the UE valid as long as it can access the location server via the SNPN. The first network's valid authentication of the UE is similar to problem 3.
[0050] Problem 5: When shipped, a terminal UE of a first network (e.g., an SNPN) does not yet have a certificate related to the first network, and does not have the configuration of related parameters for requesting the establishment of a PDU session in the first network, such as NSSAI, SSC Mode, DNN, etc. It is necessary to solve the problem of the UE obtaining the information required to initiate a first PDU session establishment request, and the first PDU session is used to request the configuration of a certificate related to the first network.
[0051] One alternative is to configure the terminal routing selection policy with the address of the configuration server, and only allow the UE to access the configuration server.
[0052] In one alternative embodiment of the present invention, the first network includes an SNPN.
[0053] In one alternative embodiment of the invention, the credentials, which may be referred to as security information, include authentication and / or encryption parameters, such as a root private key, which may be used to derive CK and IK.
[0054] In one alternative embodiment of the present invention, the certificate related to the first network may include a certificate for accessing the first network. The certificate for accessing the first network may include a certificate that can be directly authenticated by an authentication server of the first network or a certificate that can be indirectly authenticated. Authentication by an authentication server other than the first network may be understood as indirect authentication. As can be easily understood, in this case, the configuration server can configure the UE with a certificate that can be directly authenticated by the first network or a certificate that can be directly authenticated by the first network.
[0055] In one alternative embodiment of the present invention, the certificate related to the first network may include at least one of a certificate directly related to the first network, a certificate for accessing normal services of the first network, a certificate that cannot be directly authenticated by the authentication server of the first network, and a certificate for accessing unrestricted services of the first network. As can be easily understood, in this case, the configuration server can configure the certificate that can be directly authenticated by the first network to the UE.
[0056] In another alternative embodiment of the present invention, the certificate not related to the first network may include at least one certificate not directly related to the first network. The certificate not directly related to the first network may include a certificate that cannot be directly authenticated by an authentication server of the first network. A certificate authenticated by an authentication server other than the first network may be understood as a certificate not related to or not directly related to the first network.
[0057] In one alternative embodiment of the present invention, the second certificate comprises: A certificate that is not related to the first network, a certificate for accessing the first network if the terminal does not have a certificate associated with the first network; and If the terminal requests the deployment of a certificate related to the first network, a certificate for accessing the first network; a certificate for accessing a restricted service of the first network; a certificate placed on the first communications device by the first communications device manufacturer; and a certificate that can be authenticated by a second authentication server.
[0058] In one alternative embodiment of the present invention, the restricted service includes at least one of allowing only the control plane, not allowing the user plane, allowing only access to a first server (which may include a configuration server), and allowing only a certificate download application. In one embodiment, the control plane configures the terminal with a certificate related to the first network. Thus, the terminal's access to the first network may be restricted and only the control plane may be permitted. In another embodiment, the user plane configures the terminal with a certificate related to the first network. Thus, as can be easily understood, the restricted service may only permit the terminal to access the first server. Allowing only access to the first server includes using a data channel established by the terminal in the first network only to access the first server.
[0059] In one alternative embodiment of the present invention, the first server includes a configuration server, which can process a request to configure a certificate related to the first network in a terminal, and which can configure a certificate related to the first network in a communication device. The first server may be a server belonging to the first network.
[0060] In one alternative embodiment of the present invention, the first server may request authentication of the terminal from a second authentication server when placing a request for a certificate associated with the first network on the terminal, wherein the first server is an authentication intermediate server.
[0061] In one alternative embodiment of the present invention, the initial authentication includes authentication of the terminal by the first network when the terminal accesses the first network without having a certificate associated with the first network. As can be easily understood, the initial authentication belongs to indirect authentication.
[0062] In one alternative embodiment of the invention, the configuration server is also called a first server.
[0063] In one alternative embodiment of the present invention, the terms first network associated certificate and first network related certificate may be used interchangeably and refer to the same thing.
[0064] In one alternative embodiment of the present invention, the manufacturer-related information may be referred to as manufacturer information or manufacturer information for short. The manufacturer-related information includes manufacturer identification information (e.g., Vendor ID or TAC).
[0065] In one embodiment of the present invention, the server address-related information may include at least one of an IP address, a MAC address, a port number, a Fully Qualified Domain Name (FQDN), a Uniform Resource Locator (URL), an operating system identification information, and an application identification information. The authentication server address-related information or the first server address-related information is similar to the server address-related information.
[0066] In one embodiment of the present invention, unless otherwise specified (e.g., authentication server of the first network), the authentication server is an abbreviation for the second authentication server, which includes the authentication server of the terminal manufacturer.
[0067] In the embodiment of the present invention, selectively, obtaining may be understood as generating, obtaining from configuration, receiving, receiving after a successful request, obtaining by self-learning, deriving and obtaining based on unreceived information, or obtaining after processing based on received information, and may be specifically determined based on actual needs. In the embodiment of the present invention, there is no particular limitation thereon. For example, if a certain capability indication information transmitted by a device is not received, it can be determined that the device does not support this capability.
[0068] Alternatively, transmitting may include broadcasting, broadcasting in a system message, or returning in response to a request.
[0069] Alternatively, the pre-configuration may be referred to as a default.
[0070] In one alternative embodiment of the present invention, the data channel may include, but is not limited to, one of a PDU session, a PDN connection, a QoS stream, a bearer, and an Internet Protocol Security (IPsec) channel, where the bearer may be an Evolved Radio Access Bearer (E-RAB), a Radio Access Bearer (RAB), a Data Radio Bearer (DRB), a Signaling Radio Bearer (SRB), etc.
[0071] In one alternative embodiment of the present invention, the communications equipment may include at least one of a communications network element and a terminal.
[0072] In one embodiment of the present invention, the communication network elements may include at least one of a core network element and a network element of a radio access network.
[0073] In an embodiment of the present invention, the core network element (CN network element) may be a core network device, a core network node, a core network function, a core network element, a mobility management entity (MME), an access management function (AMF), a session management function (SMF), a user plane function (UPF), a serving gateway (SGW), a PDN gateway (PDN gateway), a policy control function (PCF), a policy and charging rules function (PCRF), a serving GPRS support node (SGSN), a gateway GPRS support node (GGSN), a unified data management (UDM), a unified data repository (UDR), a home subscriber server (HSS), an application function (AF), a centralized network deployment (Centralized Network Deployment (CNS)), a centralized service provider (CNS) or a centralized service provider (CNS). The network configuration (CNC) may include, but is not limited to, at least one of the following:
[0074] In an embodiment of the present invention, a Radio Access Network (RAN) network element may include, but is not limited to, at least one of a radio access network device, a radio access network node, a radio access network function, a radio access network unit, a Third Generation Partnership Project (3GPP) radio access network, a non-3GPP radio access network, a centralized unit (CU), a distributed unit (DU), a base station, an evolved base station (evolved Node B (eNB), a 5G base station (gNB), a radio network controller (RNC), a base station (NodeB), a non-3GPP inter working function (N3IWF), an access control (AC) node, an access point (AP) device, or a wireless local area network (WLAN) node, and an N3IWF.
[0075] The base station may be a base transceiver station (BTS) in a Global System for Mobile Communications (GSM) or a Code Division Multiple Access (CDMA), a base station (Node B) in a Wideband Code Division Multiple Access (WCDMA), an evolutionary Node B (eNB or e-NodeB) in LTE, and a 5G base station (gNB), and is not limited to these in the embodiments of the present invention.
[0076] In an embodiment of the present invention, the UE is a terminal. The terminal may include a terminal that supports terminal function relaying and / or supports a relay function. The terminal may also be referred to as terminal equipment or user equipment (UE), and may be a terminal-side device such as a mobile phone, a tablet personal computer, a laptop computer, a personal digital assistant (PDA), a mobile internet device (MID), a wearable device, or an in-vehicle device. Note that the specific type of the terminal is not limited in the embodiment of the present invention.
[0077] The method and communication device according to the embodiment of the present invention can be used in a wireless communication system. The wireless communication system may be a fifth-generation mobile communication (5G) system, an evolved packet system (EPS), or a subsequent evolved communication system. The wireless communication network of the embodiment of the present invention may be a fifth-generation mobile communication network (5GS) or an LTE network.
[0078] The following clearly and completely describes the technical solutions in the embodiments of the present invention, in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only some of the embodiments of the present invention, and not all of the embodiments. All other embodiments obtained by those skilled in the art based on the embodiments of the present invention without any creative effort are also within the scope of protection of the present invention.
[0079] Referring to Figure 2, an embodiment of the present invention provides an access control method for a first communication device, which includes, but is not limited to, one of a terminal (UE), a first server, and a CN network element (e.g., AMF, Security Anchor Function (SEAF)). The method includes, but is not limited to, the following steps:
[0080] In step 201, first information and / or first instruction information is sent to a first target end, where the first information is: index information of a second authentication server; Related information about the manufacturer of the first communication device; and address related information of the second authentication server; The first indication information is used to request obtaining a certificate related to the first network or to indicate that the type of access is a restricted service.
[0081] In one embodiment, the first target end may include a communication device of a first network, for example, an AMF in the first network, and the first network may be an SNPN.
[0082] In another embodiment, the first target end may include a first server (including a configuration server or an intermediate server for authentication).
[0083] If the first communication device is a terminal, the first target end may be a communication device or a first server of the first network.
[0084] If the first communication device is a CN device (e.g., AMF) of the first network, the first target end may be a first server.
[0085] In one embodiment, the first communications device may have a second certificate.In one embodiment, the second authentication server may have a second certificate.
[0086] Optionally, the second certificate comprises: A certificate that is not related to the first network, a certificate for accessing the first network if the terminal does not have a certificate associated with the first network; and If the terminal requests the deployment of a certificate related to the first network, a certificate for accessing the first network; a certificate for accessing a restricted service of the first network; a certificate placed on the first communications device by the first communications device manufacturer; and a certificate that can be authenticated by a second authentication server.
[0087] In one embodiment, the second authentication server includes at least one of an authentication server other than the first network, an authentication server of a service vendor, an authentication server of a manufacturer of the first communications device, and an authentication server that has a second certificate or can authenticate the second certificate.
[0088] Optionally, the service vendor may be located outside the first network.
[0089] In one embodiment, the manufacturer is the manufacturer of the first communications device to which the second authentication server belongs.
[0090] Optionally, the manufacturer-related information includes manufacturer identification information (eg, Vendor ID or TAC).
[0091] In one embodiment, the index information of the second authentication server may include at least one of the address-related information of the second authentication server (e.g., IP, FQDN, or URL) and identification information of the terminal manufacturer to which the second authentication server belongs.
[0092] In one embodiment, the first instruction information being used to request acquisition of a certificate associated with the first network may be to request acquisition of a certificate associated with the first network using the first instruction information.
[0093] In one alternative embodiment of the present invention, the certificate associated with the first network may include at least one of a certificate directly associated with the first network, a certificate for accessing normal services of the first network, a certificate that can be directly authenticated by an authentication server of the first network, and a certificate for accessing unrestricted services of the first network. As can be easily understood, in this case, the first server may configure the certificate that can be directly authenticated by the first network in the UE.
[0094] In another alternative embodiment of the present invention, the certificate not related to the first network may include at least one certificate not directly related to the first network. The certificate not directly related to the first network may include a certificate that cannot be directly authenticated by an authentication server of the first network. A certificate authenticated by an authentication server other than the first network may be understood as a certificate not related to or not directly related to the first network.
[0095] In this embodiment of the present invention, the above can be achieved by sending the first information and / or first instruction information to the first target terminal, so that the first target terminal can perform a first operation based on the first information and / or first instruction information, as specifically described in the embodiment of FIG. 3.
[0096] Illustratively, the first operation is: An operation of determining the second authentication server; an operation of determining an operation of requesting authentication of the first communication device from the second authentication server; an operation of requesting the second authentication server to authenticate the first communication device; an operation of requesting a first server to authenticate the first communications device; an operation of transmitting the first information to the first server; an operation of confirming whether the first communication device is an authorized device of a first network; an operation of confirming whether to permit placement of a certificate related to the first network in the first communication device; and an operation of confirming whether to permit the first network to accept the registration request of the first communication device, Wherein, the first server is a server that can locate a certificate related to the first network for the first communication device.
[0097] The purpose of access control to the first communication device via the first network is realized.
[0098] Optionally, the transmitting of the first information as described above may include: transmitting first information if a first condition is met; Among them, the first condition is: the first communications device having a second certificate; the first communication device does not have a certificate associated with the first network; the first communications device has requested access to a first network; the first communications device has requested access to a restricted service of a first network; and the first communications device has requested acquisition of a certificate associated with a first network; Obtaining at least one of the first pieces of information; obtaining request information for the first information; The first network has obtained information supporting the restricted service; and obtaining information that the first network supports and / or requires authentication for the restricted service; a first network has obtained information that supports and / or requires authentication for the first communication device; and the first network has obtained information supporting the deployment of a certificate associated with the first network on the first communications device.
[0099] In one embodiment, obtaining an identity request sent by a first target end, the type of which is related to a manufacturer of the first communication device; Among them, the second certificate is as described above and will not be further described here.
[0100] In one embodiment, the first network supporting and / or requiring authentication for the first communication device comprises: A first communication device, supported and / or required by the first network, performs authentication between the first network and a second authentication server; and the first network supporting and / or requiring authentication for the first communication device based on the second certificate.
[0101] Wherein, the first communication device may be a terminal that does not have a certificate associated with the first network. As can be easily understood, if the terminal accesses the first network before the certificate associated with the first network is configured, the first network may require the terminal to authenticate based on a second certificate (e.g., a certificate configured in the terminal by the terminal manufacturer) for security reasons. Under this requirement, the terminal may provide the first network with relevant index information of a second authentication server to support authentication.
[0102] In one embodiment, obtaining information that the first network supports and / or requires authentication for the first communication device includes: the first network has obtained information supporting and / or requiring authentication of the first communications device by a second authentication server; and the first network has obtained information that supports and / or requires authentication of the first communication device via the second certificate.
[0103] Wherein, the first communication device may be a terminal that does not have a certificate related to the first network.
[0104] As can be easily understood, if the terminal accesses the first network before the relevant certificate is deployed in the first network, the first network may, as a more secure consideration, request that the terminal authenticate based on the second certificate, and under this request, the terminal may provide the first network with relevant index information of the second authentication server to support the authentication.
[0105] In one embodiment, the first information is pre-populated in the first communication device. As can be easily understood, the first information is pre-populated in the first communication device by its manufacturer when the first communication device is shipped.
[0106] In particular, the certificates associated with the first network are as described above and will not be further described here.
[0107] In one embodiment, the first network comprises: information that the first network supports restricted services; Information that the first network supports and / or requires authentication for restricted services; and information that a first network supports and / or requires authentication for the first communication device; and information that supports the first network in configuring the first communication device with a certificate associated with the first network.
[0108] In one embodiment, the information that the first network supports and / or requires authentication of the first communications device includes information of initial authentication supported and / or required by the first network. The supporting and / or requiring initial authentication includes still supporting and / or requiring authentication of the first communications device before the first communications device accesses the first network without a certificate associated with the first network or the first communications device requests deployment of a certificate associated with the first network. The initial authentication may be performed over the first network by a first authentication server and the first communications device.
[0109] As can be easily understood, if the first communication device does not have a certificate associated with the first network, the first network can still authenticate the first communication device via the first authentication server.
[0110] In one embodiment, the first device requests index information of the second authentication server from the first network only if the first network broadcasts an indication in the cell requesting initial authentication.
[0111] Optionally, the request information for the first information is: first request information for requesting manufacturer information of the first communication device; second request information for requesting index information of the second authentication server; and third request information for requesting address-related information of the second authentication server.
[0112] In one embodiment, the aforementioned acquiring first request information for requesting manufacturer information of the first communication device, sent by the first target end (e.g., AMF of the first network), includes acquiring an identity request sent by the first target end, the type of which is an association type of the manufacturer of the first communication device (e.g., terminal manufacturer type). In one embodiment, the first information and / or the first indication information are sent by control plane signaling. In one embodiment, the first information and / or the first indication information are sent by a non-access layer access request (e.g., a registration request message, an attach request message, etc.).
[0113] Optionally, before the step of transmitting the first information, the method further comprises: further comprising sending an access request and / or sending first instruction information to the first target end; Wherein, the first indication information is used to request obtaining a certificate related to the first network or to indicate that the type of access is a restricted service.
[0114] In one embodiment, the first indication information may be expressed as a cause of access (e.g., a Radio Resource Control (RRC) cause or a Non-access stratum (NAS) layer access cause), an access request or a type of access.
[0115] Optionally, before the step of transmitting the first information, the method further comprises: transmitted by the first target end, request information for the first information; information that the first network supports restricted services; Information that the first network supports and / or requires authentication for restricted services; and information that a first network supports and / or requires authentication for the first communication device; and information supporting the first network in deploying a certificate associated with the first network on the first communications device.
[0116] In one embodiment, the first target end sends request information for the first information after receiving the access request and / or the first instruction of the first communication device.
[0117] In one embodiment, the authentication information for the first communication device may be related information of a terminal manufacturer, index information of a second authentication server, and address information of the second authentication server.
[0118] Optionally, the method further comprises: The method further includes obtaining second information, which is specifically the second information as described in the embodiment of FIG.
[0119] Exemplarily, the second information is: a first terminal routing selection policy (e.g., URSP); Setting the default DNN information to empty, Setting the default slice information to empty, relevant information for establishing a first data channel; a second instruction; and a third instruction; and Address-related information of the first server; and address related information of the second authentication server; Wherein, the first server is a server that can locate a certificate related to a first network; the first terminal routing selection policy is used to access a first server or a certificate download application; the first data channel is a data channel in a first network; The second instruction information is the first data channel is used for interaction between a first communication device and a first server; the first data channel is used by a first communication device to request a certificate associated with a first network; the first data channel is used to configure a certificate associated with a first network in a first communication device; The third instruction information is used to instruct at least one of allowing only restricted services, allowing only the control plane, not allowing the user plane, allowing only access to the first server, and allowing only the certificate download application.
[0120] In one embodiment, the relevant information for establishing the first data channel (the data channel is, for example, a PDU session) comprises: It includes at least one of a Data Network Name (DNN), slice information (e.g., NSSAI), a Session and Service Continuity Mode (SSC Mode), and a data channel type (e.g., PDU Session Type).
[0121] In one embodiment, the first data channel is a data channel in a first network for downloading a first network certificate.
[0122] In one embodiment, the first communications device may establish the first data channel upon receiving the second information.
[0123] In an embodiment of the present invention, first information and / or first instruction information is sent to the first target end, where the first information is as described above and will not be further described here. In this way, on the one hand, the first network can support the first communication device to select a second authentication server to authenticate the first communication device, thereby supporting the terminal to be authenticated when the terminal accesses the first network without a first network-related certificate, thereby avoiding security attacks on the first network by impersonating terminals and unauthorized terminals. On the other hand, the present invention supports the first communication device to be configured to support the authorized terminal to obtain a first network-related certificate to access services of the first network.
[0124] Referring to Figure 3, an embodiment of the present invention further provides an access control method for a second communication device, which includes, but is not limited to, one of a communication device (such as AMF, SEAF, or AF) in a first network, a first server, and a second authentication server. Step 301 of obtaining at least one of first information, first instruction information, a valid device list, and third information; a step 302 of performing a first operation based on at least one of the first information, the first instruction information, the authorized device list, and the third information; wherein the first information includes at least one of index information of a second authentication server, related information of a manufacturer of the first communication device, and address related information of the second authentication server; the first indication information is used to indicate that a type of access to a first network requires obtaining a certificate related to the first network or is a restricted service; The third information is Mapping information between index information of the second authentication server and address-related information of the second authentication server; and address related information of the second authentication server.
[0125] In one embodiment, the third information provides information related to the legitimate second authentication server. As can be easily understood, the authenticity of the "address related information of the second authentication server" in the first information may be confirmed by comparing the "address related information of the second authentication server" in the third information with the "address related information of the second authentication server" in the first information.
[0126] In one embodiment, at least one of the first information, the first instruction information, and the third information may include any one of the first information, the first instruction information, and the third information, or a combination of any two or more of the first information, the first instruction information, and the third information.
[0127] In one embodiment, the first information may refer to the first information in the example shown in FIG. 2, and the first instruction information may refer to the first instruction information in the example shown in FIG. 2, which will not be further described here.
[0128] In one embodiment, the first information and / or first instruction information is obtained from a first communication device, and in one embodiment, the third information is obtained from a third communication device.
[0129] In one embodiment, the first information and / or the first indication information is obtained by an access request (eg, a registration request message or an attachment request message).
[0130] In one embodiment, the address related information of the second authentication server can be confirmed by mapping information between the index information of the second authentication server and the address related information of the second authentication server.
[0131] Optionally, the first operation comprises: An operation of determining the second authentication server; an operation of determining an operation of requesting authentication of the first communication device from the second authentication server; an operation of requesting the second authentication server to authenticate the first communication device; an operation of requesting a first server to authenticate the first communications device; an operation of transmitting the first information to the first server; an operation of confirming whether the first communication device is an authorized device of a first network; an operation of confirming whether to permit placement of a certificate related to the first network in the first communication device; and an operation of confirming whether to permit the first network to accept the registration request of the first communication device, Wherein, the first server is a server that can locate a certificate related to the first network for the first communication device.
[0132] As mentioned above, determining the second authentication server includes determining address-related information of the second authentication server.
[0133] Furthermore, the step of determining the second authentication server described above may include, but is not limited to, at least one of the following: 1) The second authentication server can be determined based on "index information of the second authentication server" in the first information and "mapping information between the index information of the second authentication server and address-related information of the second authentication server" in the third information. As can be easily understood, the step of determining the second authentication server described above may include selecting, for the terminal, one second authentication server that satisfies the index information of the second authentication server.
[0134] 2) The second authentication server can be determined based on the "information related to the manufacturer of the first communication device" in the first information and the "mapping information between the index information of the second authentication server and the address-related information of the second authentication server" in the third information. As can be easily understood, determining the second authentication server described above may include selecting, for the terminal, a second authentication server corresponding to the "information related to the manufacturer of the first communication device."
[0135] 3) The second authentication server can be determined based on the "address-related information of the second authentication server" in the first information and / or the "address-related information of the second authentication server" in the third information. As can be easily understood, determining the second authentication server described above may include selecting, for the terminal, one second authentication server that satisfies the "address-related information of the second authentication server" in the first information. By comparing the "address-related information of the second authentication server" in the first information with the "address-related information of the second authentication server" in the third information, it can be confirmed that the "address-related information of the second authentication server" in the first information is the address-related information of a legitimate second authentication server.
[0136] 4) The second authentication server can be determined based on the "address-related information of the second authentication server" in the first instruction information and / or the third information. As can be easily understood, determining the second authentication server described above may include selecting the second authentication server corresponding to the "address-related information of the second authentication server" in one piece of third information based on the first instruction information.
[0137] Furthermore, the step of determining to request authentication of the first communication device from the second authentication server includes: 1) determining, based on first instruction information and / or first information, to request authentication of the first communication device from the second authentication server; 2) It may include at least one of the following, but is not limited to: determining to request authentication of the first communications device from the second authentication server based on the "address-related information of the second authentication server" in the first instruction information and / or the third information.
[0138] In one embodiment, the first network may verify whether the first communication device is a legitimate device through authentication by the second authentication server. If the authentication of the first communication device by the second authentication server is successful, the first network may further verify whether the first communication device is a legitimate device of the first network and / or whether to allow deployment of a first network-related certificate based on a list of legitimate devices.
[0139] In another embodiment, through authentication by the second authentication server, the first network may verify whether the first communication device is an impersonating device or whether it is a legitimate device of the first network. In one embodiment, the legitimate device may include a device (e.g., a terminal) that authorizes the deployment of a certificate associated with the first network. In another embodiment, the legitimate device may include a device (e.g., a terminal) that does not have a certificate associated with the first network but authorizes the deployment of a certificate associated with the first network.
[0140] In one embodiment, the authorized terminal list may be located in a user management server (e.g., a UDM, HSS, or UDR) of the first network. The authorized device list may be obtained from the user management server.
[0141] The list of authorized devices includes at least one of authorized communication devices of the first network that do not have a certificate related to the first network deployed thereon and communication devices that allow deployment of a certificate related to the first network.
[0142] Optionally, the authorized device list is an authorized terminal list. The authorized terminal list may be information of a group of terminals. In one embodiment, the information of the terminals may include terminal identifiers, such as IMEI, PEI, GPSI, MAC address, or SUPI (in this case, the SUPI is not the SUPI of the first network).
[0143] Optionally, the list of authorized terminals may include at least one of authorized terminals of the first network that do not have a certificate associated with the first network deployed thereon and terminals that authorize the deployment of a certificate associated with the first network.
[0144] As can be easily understood, in one embodiment, through authentication by the second authentication server, the first network may confirm that the terminal is a terminal (i.e., not an impersonated terminal), and through the list of authorized terminals, the first network may confirm whether the terminal is an authorized terminal and whether to allow the placement of a first network-related certificate.
[0145] As can be easily understood, in another embodiment, the authentication server may authenticate the first network to determine that the terminal is a terminal and is a legitimate terminal of the first network, i.e., the authentication server directly authenticates that the terminal is not an impersonated terminal but is a legitimate terminal of the first network, and allows the deployment of a certificate associated with the first network.
[0146] The first server may be called a configuration server or an authentication intermediate server.
[0147] optionally, if the first communication device satisfies a second condition, confirming that the first communication device is a valid device of the first network; Among them, the second condition is: the first communication device has been successfully authenticated by the second authentication server; and the first communication device is a communication device on a list of authorized devices.
[0148] The valid device list is described above and will not be further described here.
[0149] Optionally, prior to obtaining the first information as described above, the method further comprises: receiving first indication information indicating that a type of access request from the first communication device and / or requesting acquisition of a credential associated with the first network or access is a restricted service; The method further includes transmitting request information for the first information based on the access request and / or the first instruction information.
[0150] In one embodiment, the sending of the request information for the first information may be sending the request information to the first communication device to request the first communication device to send the first information.
[0151] In one embodiment, an access request and / or first instruction information of the first communication device is received from the first communication device.
[0152] In one embodiment, a request for the first information is sent to the first communication device.
[0153] Optionally, the request information for the first information is: first request information for requesting manufacturer information of the first communication device; second request information for requesting index information of the second authentication server; and third request information for requesting address-related information of the second authentication server.
[0154] In one embodiment, the aforementioned sending of first request information for requesting manufacturer information of the first communication device includes sending an identity request, and the type of the identity request is an associated type of the manufacturer of the first communication device, for example, a manufacturer type of the terminal.
[0155] Optionally, the method further comprises: If the first communication device is determined to be a legitimate device of the first network, transmitting second information, wherein the second information is: relevant information for establishing a first data channel; a second instruction; and and address related information of the first server; Wherein, the first server is a server that can locate a certificate related to a first network; the first data channel is a data channel in a first network; The second instruction information is the first data channel is used for interaction between a first communication device and a first server; the first data channel is used by a first communication device to request a certificate associated with a first network; the first data channel is used to configure a certificate associated with a first network in a first communications device.
[0156] In one embodiment, the first information and / or first instruction information is obtained from a first communication device.
[0157] In one embodiment, the third information is obtained from a third communication device.
[0158] In one embodiment, the first information and / or the first indication information is obtained by an access request (eg, a registration request message or an attachment request message).
[0159] In one embodiment, the address-related information of the second authentication server may be confirmed based on the "index information of the second authentication server" in the first information and the "mapping information between the index information of the second authentication server and the address-related information of the second authentication server" in the third information.
[0160] In another embodiment, based on the first instruction information and the "address-related information of the second authentication server" in the third information, authentication of the first communication device by the second authentication server may be confirmed and / or the address-related information of the second authentication server may be confirmed.
[0161] In this embodiment, at least one of first information, first instruction information, a list of authorized devices, and third information can be obtained, and a first operation can be performed based on at least one of the first information, first instruction information, a list of authorized devices, and third information. In this way, on the one hand, the first network can support selecting a second authentication server to authenticate a first communication device, thereby supporting authenticating a terminal when the terminal accesses the first network without a first-network-related certificate, and preventing security attacks on the first network by spoofing terminals and unauthorized terminals. On the other hand, by supporting configuration for the first communication device, the authorized terminal can support obtaining a certificate associated with the first network to access services of the first network.
[0162] Referring to Figure 4, Figure 4 is another access control method used in a third communication device according to an embodiment of the present invention, where the third communication device includes, but is not limited to, one of an AF, a second authentication server, and a related device of the manufacturer of the first communication device. As shown in Figure 4, a step 401 of determining third information; and transmitting 402 third information; Among them, the third information is: Mapping information between index information of a second authentication server and address-related information of the second authentication server; and address related information of the second authentication server.
[0163] In one embodiment, the third information is the third information in the example shown in FIG. 3, which will not be further described here.
[0164] In one embodiment, mapping information between the index information of the second authentication server and the address-related information of the second authentication server may be used to confirm the address-related information of the second authentication server.
[0165] In one embodiment, the above-mentioned transmitting the third information may be transmitting the third information to the second communication device.
[0166] Optionally, transmitting the second authentication server related information includes: If a third condition is met, sending related information of the second authentication server; The third condition is: the third communication device and the second authentication server have successfully completed mutual authentication; and the third communication device and the first network have successfully completed mutual authentication.
[0167] Optionally, the third communication device is a communication device other than the first network.
[0168] In one embodiment, the third communication device and the second authentication server may have previously been successful in mutual authentication.
[0169] In one embodiment, the third communication device and the first network successfully authenticate each other.
[0170] In this embodiment, the third information is transmitted, and the second communication device acquires the third information.
[0171] In this way, the first network can support selecting a second authentication server to authenticate the first communication device, thereby supporting authenticating the terminal when the terminal accesses the first network without having a first network-related certificate, and avoiding security attacks on the first network by impersonating terminals and unauthorized terminals.
[0172] Referring to Figure 5, Figure 5 is another access control method used in a fourth communication device according to an embodiment of the present invention, where the fourth communication device includes but is not limited to a terminal. As shown in Figure 5, Step 501 of obtaining second information; and performing a second operation based on the second information. Among them, the second information is: a first terminal routing selection policy (e.g., URSP); Setting the default DNN information to empty, Setting the default slice information to empty, relevant information for establishing a first data channel; a second instruction; and a third instruction; and Address-related information of the first server; and address related information of the second authentication server; Wherein, the first server is a server that can locate a certificate related to a first network; the first terminal routing selection policy is used to access a first server or a certificate download application; the first data channel is a data channel in a first network; The second instruction information is the first data channel is used for interaction between a first communication device and a first server; the first data channel is used by a first communication device to request a certificate associated with a first network; the first data channel is used to configure a certificate associated with a first network in a first communication device; The third instruction information is used to instruct at least one of allowing only restricted services, allowing only the control plane, not allowing the user plane, allowing only access to the first server, and allowing only the certificate download application.
[0173] In one embodiment, the second information may refer to the second information in the embodiment shown in FIG. 5, and will not be further described here.
[0174] In one embodiment, the above-mentioned acquiring the second information may be acquiring the second information from the first network.
[0175] Optionally, the second operation comprises: an operation of establishing a first data channel, the first data channel satisfying at least one of the following: the first data channel is used for interaction between a first communication device and a first server; the first data channel is used for requesting a certificate related to the first network by the first communication device; and the first data channel is used to configure the first communication device with a certificate related to the first network; requesting a first server to locate a certificate associated with the first network; requesting a second authentication server to locate a certificate associated with the first network; An operation of rejecting an access request or a data transmission request other than the target first server and / or the certificate download application of the application layer; and allowing only access requests or data transmission requests whose targets are the first server and / or the certificate download application.
[0176] In one embodiment, the relevant information for establishing the first data channel (the data channel is, for example, a PDU session) comprises: It includes at least one of the following: DNN, slice information (e.g., NSSAI), SSC Mode, and data channel type (e.g., PDU session type).
[0177] In one embodiment, the first data channel is a data channel in a first network for downloading a first network certificate.
[0178] In one embodiment, the establishment of the first data channel is requested based on the associated information for the establishment of the first data channel and / or the second indication information.
[0179] A request is made to the first server to locate a certificate associated with the first network based on the address-related information of the first server.
[0180] Based on the address-related information of the second authentication server, the second authentication server requests the second authentication server to allocate a certificate related to the first network. As can be easily understood, the second authentication server first authenticates the fourth communication device based on the request, and if the authentication is successful, requests the first server to allocate a certificate related to the first network to the fourth communication device.
[0181] In this embodiment, by obtaining second information and performing a second operation based on the second information, when a terminal accesses the first network without having a certificate related to the first network, the terminal can obtain the necessary configuration, thereby supporting a legitimate terminal to obtain a certificate related to the first network and access services of the first network.
[0182] Referring to Figure 6, Figure 6 is another access control method used in a fifth communication device according to an embodiment of the present invention. The fifth communication device is a communication device of a first network, for example, including but not limited to one of AMF. As shown in Figure 6, the method includes the following steps:
[0183] In step 601, second information is transmitted, wherein the second information is: a first terminal routing selection policy (e.g., URSP); Setting the default DNN information to empty, Setting the default slice information to empty, relevant information for establishing a first data channel; a second instruction; and a third instruction; and Address-related information of the first server; and address related information of the second authentication server; Wherein, the first server is a server that can locate a certificate related to a first network; the first terminal routing selection policy is used to access a first server or a certificate download application; the first data channel is a data channel in a first network; The second instruction information is the first data channel is used for interaction between a first communication device and a first server; the first data channel is used by a first communication device to request a certificate associated with a first network; the first data channel is used to configure a certificate associated with a first network in a first communication device; The third instruction information is used to instruct at least one of allowing only restricted services, allowing only the control plane, not allowing the user plane, allowing only access to the first server, and allowing only the certificate download application.
[0184] Optionally, before the step of transmitting the second information, a determination of an associated operation of the second information is performed.
[0185] Executing a determination of the associated operation of the second information determining an operation of a first terminal routing selection policy; Set the default DNN information to empty or do not set the default DNN information; This includes setting the default slice information to empty or not setting the default (NSSAI) slice information.
[0186] As can be easily understood, in addition to the first server, the first network does not allow the terminal to access other services. If a default DNN is used for the terminal's application or the access target does not have a DNN in the corresponding routing selection policy, a default DNN is selected and a data channel is established to access the application or access target. Therefore, not configuring the default DNN means that the terminal is not allowed to initiate other services. If default slice information is used for the terminal's application or the access target does not have slice information in the corresponding routing selection policy, a default slice information is selected and a data channel is established to access the application or access target. Therefore, not configuring the default slice information means that the terminal is not allowed to initiate other services.
[0187] Optionally, the operation of determining the first terminal routing selection policy as described above may include: An operation of setting an application description in the first terminal routing selection policy as address-related information of the first server (for example, setting the application description as the IP ternary group of the first server or the FQDN of the first server); An operation of setting an application description in the first terminal routing selection policy to certificate download application information (for example, setting the application description as a certificate download application); and setting the application description in the first terminal routing selection policy as the DNN of the restricted service.
[0188] The certificate download application is used to request the location of a certificate associated with a first network from a first server.
[0189] In one embodiment, the control plane signaling may be used to configure a certificate associated with the first network, and as can be easily understood, the third indication may be used to restrict the user plane to only allow the control plane.
[0190] Optionally, if a fourth condition is met, determining an associated operation of the second information and / or transmitting the second information. Among them, the fourth condition is: The terminal accesses a restricted service of a first network or receives first indication information sent by the terminal; The terminal confirms that the initial authentication has been successful or the terminal confirms that the second authentication server has been successfully authenticated; and confirming that the first communication device is a non-spoofed device; and confirming that the terminal is a valid device of the first network or that the terminal is a communication device in a valid device list; and confirming that the terminal authorizes deployment of a certificate associated with the first network.
[0191] Optionally, second information is transmitted to the terminal.
[0192] When a terminal accesses a first network without having a certificate associated with the first network, the terminal is supported to obtain a necessary configuration, thereby supporting a legitimate terminal to obtain a certificate associated with the first network and access services of the first network. The following describes an access control method according to an embodiment of the present invention in conjunction with a specific application scenario.
[0193] Application scenario 1 of the embodiment of the present invention: The application scenario 1 of the embodiment of the present invention mainly describes the access control between the UE, the SNPN and the second authentication server, and includes the following steps, as shown in FIG.
[0194] Step 1: The AF sends the third information (related information of the second authentication server) to the first network.
[0195] The third information includes at least one of mapping information between index information of the second authentication server and address information of the second authentication server, and the address information of the second authentication server.
[0196] The index information of the second authentication server in the mapping information between the index information of the second authentication server and the address information of the second authentication server can index the address information of the second authentication server to be mapped.
[0197] The AF may be the AF of the terminal manufacturer.
[0198] The AF may send the information to the UDM of the first network via the NEF of the first network.
[0199] Step 2: The UE initiates a registration request to the AMF of the first network.
[0200] Optionally, the registration request includes index information of the second authentication server, or only terminal manufacturer information is provided.
[0201] The index information of the second authentication server may include at least one of address information (for example, IP, FQDN, URL) of the second authentication server and identification information of the terminal manufacturer to which the second authentication server belongs.
[0202] Step 3 (optional): The AMF sends an identity authentication request to the UE, and the identity authentication type is set as at least one of an associated type such as a terminal manufacturer (e.g., a Vendor ID), index information of the second authentication server, and address information of the second authentication server.
[0203] The UE includes index information of the second authentication server, for example, identification information of the UE vendor, in the identity authentication response.
[0204] Step 4 (optionally): The AMF sends the index information of the second authentication server to the UDM and obtains the address information of the authentication server.
[0205] The UDM can confirm the address information of the second authentication server based on the mapping information between the index information of the second authentication server and the address information of the second authentication server, and the index information of the second authentication server.
[0206] The UDM sends the address information of the second authentication server to the AMF.
[0207] In one embodiment, step 4 employs a non-UE related signaling process.
[0208] Step 5: The AMF performs a first operation, the first operation being: determining an address of a second authentication server; requesting an authentication / security terminal from a second authentication server; and verifying whether the terminal is a valid terminal of the first network or a terminal that authorizes the deployment of a certificate associated with the first network.
[0209] In one embodiment, mapping information between index information of the second authentication server and address information of the second authentication server is obtained from the AF.
[0210] In another embodiment, index information of the second authentication server is obtained from the terminal.
[0211] Furthermore, if the terminal satisfies the conditions of a legitimate terminal, it can be confirmed that the terminal is a legitimate terminal of the first network. The conditions of a legitimate terminal may include at least one of the following: the terminal has been successfully authenticated by the second authentication server; and the terminal is a terminal in a list of legitimate terminals. The legitimate terminal may be a terminal that allows the deployment of a certificate related to the first network.
[0212] Step 6: If it is confirmed that the terminal is a valid terminal of the first network, it sends the second information and a registration acceptance message to the terminal.
[0213] The second information is as described in the embodiment of FIG. 5. Illustratively, the second information is: Related information for establishing a PDU session for the restricted service (e.g., DNN, slice information, SSC, etc.); and address related information of the first server.
[0214] In one embodiment, the transmitted registration receipt message includes address related information of the first server.
[0215] Step 7: The UE establishes a session with the SNPN.
[0216] Step 8: An SNPN credential configuration request and a configuration response are transmitted between the UE and the configuration server.
[0217] Application scenario 2 of the present invention: The application scenario 2 of the embodiment of the present invention mainly describes the access control between the UE, the SNPN, the configuration server and the second authentication server. As shown in Figure 8, it includes the following steps:
[0218] Step 1 (optionally): The configuration server obtains the third information (also called the related information of the second authentication server).
[0219] The related information of the second authentication server includes at least one of mapping information between index information of the second authentication server and address information of the second authentication server, and the address information of the second authentication server.
[0220] The index information of the second authentication server in the mapping information between the index information of the second authentication server and the address information of the second authentication server can index the address information of the second authentication server to be mapped.
[0221] Step 2: The UE initiates an access request to the AMF of the first network and sends index information of the second authentication server.
[0222] The index information of the second authentication server may include at least one of the address information (for example, IP, FQDN, URL) of the second authentication server and identification information of the terminal manufacturer to which the second authentication server belongs.
[0223] Step 3 (optional): The AMF sends index information of the second authentication server to the UDM to obtain address information of the authentication server.
[0224] The UDM can confirm the address information of the second authentication server based on the mapping information between the index information of the second authentication server and the address information of the second authentication server, and the index information of the second authentication server.
[0225] The UDM sends the address information of the second authentication server to the AMF.
[0226] In one embodiment, step 4 employs a non-UE related signaling process.
[0227] Step 4: AMF determining the address of a second authentication server; requesting an authentication terminal from a deployment server of the first network; and transmitting address information of the second authentication server or index information of the second authentication server to the configuration server of the first network.
[0228] The deployment server is determining the address of a second authentication server; and requesting an authentication terminal from the second authentication server.
[0229] After the authentication step, the AMF: An operation of confirming whether the terminal is an authorized terminal of the first network or an authorized terminal for disposing a certificate related to the first network; and an operation to confirm whether or not to permit terminal registration.
[0230] Furthermore, if the terminal satisfies the conditions of a legitimate terminal, it can be confirmed that the terminal is a legitimate terminal of the first network. The conditions of a legitimate terminal may include at least one of the following: the terminal has been successfully authenticated by the second authentication server; and the terminal is a terminal in a list of legitimate terminals. The legitimate terminal may be a terminal that allows the deployment of a certificate related to the first network.
[0231] Step 5: If it is confirmed that the terminal is a valid terminal of the first network, it sends the second information and a registration acceptance message to the terminal.
[0232] The second information is as described in the embodiment of FIG. 5. Illustratively, the second information is: Related information for establishing a PDU session for the restricted service (e.g., DNN, slice information, SSC, etc.); and address related information of the first server.
[0233] In one embodiment, the transmitted registration receipt message includes address related information of the first server.
[0234] Step 6: The UE establishes a session with the SNPN.
[0235] Step 7: The UE and the configuration server transmit the SNPN credential configuration.
[0236] Application scenario 3 of the present invention: The application scenario 3 of the embodiment of the present invention mainly describes the access control between the UE, the configuration server and the authentication server, and includes the following steps, as shown in FIG.
[0237] Step 1 (optional): The configuration server obtains the relevant information of the second authentication server.
[0238] The related information of the second authentication server includes at least one of mapping information between index information of the second authentication server and address information of the second authentication server, and the address information of the second authentication server.
[0239] The index information of the second authentication server in the mapping information between the index information of the second authentication server and the address information of the second authentication server can index the address information of the second authentication server to be mapped.
[0240] Step 2: The UE initiates a registration request to the AMF of the first network.
[0241] The AMF sends the second information and a registration acceptance message to the terminal.
[0242] The second information is Related information for establishing a PDU session for the restricted service (e.g., DNN, slice information, SSC, etc.); and address related information of the first server.
[0243] In one embodiment, the transmitted registration receipt message includes address related information of the first server (eg, the deployment server).
[0244] Step 3: The UE establishes a PDU session with the first network, where the PDU session is a PDU session of a restricted service.
[0245] In another alternative manner, the SMF transmits second information to the terminal.
[0246] Step 4: The UE initiates a configuration request to the configuration server, and sends index information of the second authentication server to the configuration server.
[0247] The index information of the second authentication server may include at least one of the address information (for example, IP, FQDN, URL) of the authentication server and identification information of the terminal manufacturer to which the authentication server belongs.
[0248] Step 5: The deployment server determining the address of a second authentication server; and requesting an authentication terminal from the second authentication server.
[0249] After the authentication completion step, the placement server: An operation of confirming whether the terminal is an authorized terminal of the first network or an authorized terminal for disposing a certificate related to the first network; and if the terminal satisfies the conditions of a legitimate terminal, performing at least one of the following operations to confirm that the terminal is a legitimate terminal of the first network. The conditions of a legitimate terminal may include at least one of the following: the terminal has been successfully authenticated by the second authentication server; and the terminal is a terminal in a list of legitimate terminals. The legitimate terminal may be a terminal that allows placement of a certificate related to the first network.
[0250] Step 6: If the terminal is confirmed to be a valid terminal of the first network, a credential associated with the first network is placed on the terminal.
[0251] Application scenario 4 of the present invention: Application scenario 4 of the embodiment of the present invention mainly describes the access control between the UE and the configuration server, and includes the following steps, as shown in FIG.
[0252] Step 1: The UE initiates a registration request to the AMF of the first network.
[0253] The AMF sends the second information and a registration acceptance message to the terminal.
[0254] The second information is as described in the embodiment of FIG. 5. Illustratively, the second information is: Related information for establishing a PDU session for the restricted service (e.g., DNN, slice information, SSC, etc.); and address related information of the first server.
[0255] In one embodiment, the transmitted registration receipt message includes address related information of the first server (eg, the deployment server).
[0256] Step 2: The UE establishes a PDU session with the first network, where the PDU session is a PDU session of a restricted service.
[0257] In another alternative manner, the SMF transmits second information to the terminal.
[0258] Step 3: The UE initiates a configuration request to the configuration server.
[0259] Step 4: The configuration server authenticates the terminal.
[0260] After the authentication step, the placement server: An operation of confirming whether the terminal is an authorized terminal of the first network or an authorized terminal for disposing a certificate related to the first network; and if the terminal satisfies the conditions of a legitimate terminal, performing at least one of the following operations to confirm that the terminal is a legitimate terminal of the first network. The conditions of a legitimate terminal may include at least one of the following: the terminal has been successfully authenticated by the second authentication server; and the terminal is a terminal in a list of legitimate terminals. The legitimate terminal may be a terminal that allows placement of a certificate related to the first network.
[0261] Step 5: If the terminal is confirmed to be a valid terminal of the first network, a certificate associated with the first network is placed on the terminal.
[0262] In an embodiment of the present invention, this may be implemented as follows.
[0263] When the UE accesses the SNPN immediately after delivery or when accessing the SNPN's configuration server, it provides relevant information identifying the UE manufacturer (vendor), which, after receiving the SNPN, is used to select the UE manufacturer's second authentication server (e.g., AAA) to authenticate the UE.
[0264] The SNPN may define a new identity type to obtain index information of a second authentication server, such as the UE manufacturer.
[0265] The SNPN sends address related information of the configuration server to the UE, and the UE is used to initiate a configuration request to the configuration server via the user plane, or the SNPN is used to request a certificate related to the first network from the configuration server for the UE via the control plane.
[0266] An embodiment of the present invention supports authentication and configuration for a UE when the UE accesses an SNPN without having a certificate for the SNPN, thereby avoiding security attacks caused by spoofed UEs and unauthorized UEs, while also supporting configuration of a certificate for the SNPN in the UE.
[0267] Referring to FIG. 11, FIG. 11 is a structural diagram of a communication device according to an embodiment of the present invention, the communication device is a first communication device, as shown in FIG. 11, the communication device 1100 includes: A first transmitting module 1101 is provided for transmitting first information and / or first instruction information to a first target end, wherein the first information is: index information of a second authentication server; Related information about the manufacturer of the first communication device; and address related information of the second authentication server; The first indication information is used to request obtaining a certificate related to the first network or to indicate that the type of access is a restricted service.
[0268] Optionally, the transmitting of the first information as described above may include: transmitting first information if a first condition is met; Among them, the first condition is: the first communications device having a second certificate; the first communication device does not have a certificate associated with the first network; the first communications device has requested access to a first network; the first communications device has requested access to a restricted service of a first network; and the first communications device has requested acquisition of a certificate associated with a first network; Obtaining at least one of the first pieces of information; obtaining request information for the first information; The first network has obtained information supporting the restricted service; and obtaining information that the first network supports and / or requires authentication for the restricted service; a first network has obtained information that supports and / or requires authentication for the first communication device; and the first network has obtained information supporting the deployment of a certificate associated with the first network on the first communications device.
[0269] Optionally, the request information for the first information is: first request information for requesting the manufacturer information; second request information for requesting index information of the second authentication server; and third request information for requesting address-related information of the second authentication server.
[0270] Optionally, before the step of transmitting the first information, the communication device: Further comprising a second transmitting module for transmitting an access request and / or first instruction information to the first target end; Wherein, the first indication information is used to request obtaining a certificate related to the first network or to indicate that the type of access is a restricted service.
[0271] Optionally, the communication device comprises: Further including a receiving module, the receiving module receiving the signal transmitted by the first target end: request information for the first information; information that the first network supports restricted services; Information that the first network supports and / or requires authentication for restricted services; and information that the first network supports and / or requires authentication for the first communication device; and information supporting deployment of a certificate associated with the first network to the first communications device.
[0272] Optionally, the communication device comprises: Further including an acquisition module for acquiring second information, wherein the second information is: a first terminal routing selection policy; Setting the default DNN information to empty, Setting the default slice information to empty, relevant information for establishing a first data channel; a second instruction; and a third instruction; and Address-related information of the first server; and address related information of the second authentication server; Wherein, the first server is a server that can locate a certificate related to a first network; the first terminal routing selection policy is used to access a first server or a certificate download application; the first data channel is a data channel in a first network; The second instruction information is the first data channel is used for interaction between a first communication device and a first server; the first data channel is used by a first communication device to request a certificate associated with a first network; the first data channel is used to configure a certificate associated with a first network in a first communication device; The third instruction information is used to instruct at least one of allowing only restricted services, allowing only the control plane, not allowing the user plane, allowing only access to the first server, and allowing only the certificate download application.
[0273] The communication device 1100 can implement each process implemented by the first communication device in the method embodiment of the present invention and achieve the same technical effects, and will not be further described here to avoid repetition.
[0274] 12, an embodiment of the present invention provides another communication device, which is a second communication device. As shown in FIG. 12, the communication device 1200 includes: an acquiring module 1201 for acquiring at least one of first information, first instruction information, a valid device list, and third information; an execution module 1202 for executing a first operation based on at least one of the first information, first instruction information, a valid device list, and third information; wherein the first information includes at least one of index information of a second authentication server, related information of a manufacturer of the first communication device, and address related information of the second authentication server; the first indication information is used to indicate that a type of access to a first network requires obtaining a certificate related to the first network or is a restricted service; The third information is Mapping information between index information of the second authentication server and address-related information of the second authentication server; and address related information of the second authentication server.
[0275] Optionally, the first operation comprises: An operation of determining the second authentication server; an operation of determining an operation of requesting authentication of the first communication device from the second authentication server; an operation of requesting the second authentication server to authenticate the first communication device; an operation of requesting a first server to authenticate the first communications device; an operation of transmitting the first information to the first server; an operation of confirming whether the first communication device is an authorized device of a first network; an operation of confirming whether to permit placement of a certificate related to the first network in the first communication device; and an operation of confirming whether to permit the first network to accept the registration request of the first communication device, Wherein, the first server is a server that can locate a certificate related to the first network for the first communication device.
[0276] Optionally, the step of determining the second authentication server includes: determining a second authentication server based on index information of the second authentication server in the first information and mapping information between the index information of the second authentication server in the third information and address-related information of the second authentication server; determining a second authentication server based on the manufacturer related information of the first communication device in the first information and mapping information between index information of the second authentication server and address related information of the second authentication server in the third information; determining a second authentication server based on address-related information of the second authentication server in the first information and / or address-related information of the second authentication server in the third information; determining a second authentication server based on address-related information of the second authentication server in the first instruction information and / or the third information; and / or The step of determining to request authentication of the first communication device from the second authentication server includes: determining, based on the first instruction information and / or the first information, to request authentication of the first communication device from the second authentication server; and determining to request authentication of the first communication device from the second authentication server based on address-related information of the second authentication server in the first instruction information and / or the third information, but is not limited to these.
[0277] optionally, if the first communication device satisfies a second condition, confirming that the first communication device is a valid device of the first network; Among them, the second condition is: the first communication device has been successfully authenticated by the second authentication server; and the first communication device is a communication device on a list of authorized devices.
[0278] Optionally, the valid device list comprises: a legitimate communication device of the first network that does not have a certificate associated with the first network; and a communications device that authorizes deployment of a certificate associated with the first network.
[0279] Optionally, the communication device comprises: a receiving module for receiving an access request and / or first instruction information from a first communication device, the first instruction information being used to request obtaining a certificate related to the first network or to indicate that the access type is a restricted service; and a first sending module for sending request information for the first information based on the access request and / or first instruction information.
[0280] Optionally, the request information for the first information is: first request information for requesting manufacturer information of the first communication device; second request information for requesting index information of the second authentication server; and third request information for requesting address-related information of the second authentication server.
[0281] Optionally, the communication device comprises: and a second transmitting module for transmitting second information when the first communication device is determined to be a legitimate device of the first network, wherein the second information includes: relevant information for establishing a first data channel; a second instruction; and and address related information of the first server; Wherein, the first server is a server that can locate a certificate related to a first network; the first data channel is a data channel in a first network; The second instruction information is the first data channel is used for interaction between a first communication device and a first server; the first data channel is used by a first communication device to request a certificate associated with a first network; the first data channel is used to configure a certificate associated with a first network in a first communications device.
[0282] The communication device 1200 can implement each process implemented by the second communication device in the method embodiment of the present invention and achieve the same technical effects, and will not be further described here to avoid repetition.
[0283] 13, an embodiment of the present invention provides another communication device, which is a third communication device. As shown in FIG. 13, the communication device 1300 includes: a determination module 1301 for determining third information; a transmitting module 1302 for transmitting third information; Among them, the third information is: Mapping information between index information of a second authentication server and address-related information of the second authentication server; and address related information of the second authentication server.
[0284] Optionally, the step of transmitting the information related to the second authentication server includes: If a third condition is met, sending related information of the second authentication server; The third condition is: the third communication device and the second authentication server have successfully completed mutual authentication; and the third communication device and the first network have successfully completed mutual authentication.
[0285] The communication device 1300 can implement each process implemented by the third communication device in the method embodiment of the present invention and achieve the same technical effect, and will not be further described here to avoid repetition of description.
[0286] 14, an embodiment of the present invention provides another communication device, which is a fourth communication device. As shown in FIG. 14, the communication device 1400 includes: an acquiring module 1401 for acquiring second information; an execution module 1402 for performing a second operation based on the second information; Among them, the second information is: a first terminal routing selection policy; Setting the default DNN information to empty, Setting the default slice information to empty, relevant information for establishing a first data channel; a second instruction; and a third instruction; and Address-related information of the first server; and address related information of the second authentication server; Wherein, the first server is a server that can locate a certificate related to a first network; the first terminal routing selection policy is used to access a first server or a certificate download application; the first data channel is a data channel in a first network; The second instruction information is the first data channel is used for interaction between a first communication device and a first server; the first data channel is used by a first communication device to request a certificate associated with a first network; the first data channel is used to configure a certificate associated with a first network in a first communication device; The third instruction information is used to instruct at least one of allowing only restricted services, allowing only the control plane, not allowing the user plane, allowing only access to the first server, and allowing only the certificate download application.
[0287] Optionally, the second operation comprises: an operation of establishing a first data channel, the first data channel satisfying at least one of the following: the first data channel is used for interaction between a first communication device and a first server; the first data channel is used for requesting a certificate related to the first network by the first communication device; and the first data channel is used to configure the first communication device with a certificate related to the first network; requesting a first server to locate a certificate associated with the first network; requesting a second authentication server to locate a certificate associated with the first network; Rejecting an access request or a data transmission request other than the first server and / or the certificate download application of the target of the application layer; and allowing only access requests or data transmission requests whose targets are the first server and / or the certificate download application.
[0288] The communication device 1400 can implement each process implemented by the fourth communication device in the method embodiment of the present invention and achieve the same technical effect, and will not be further described here to avoid repetition.
[0289] 15, an embodiment of the present invention provides another communication device, which is a fifth communication device. As shown in FIG. 15, the communication device 1500 includes: a transmitting module 1501 for transmitting second information, wherein the second information is: a first terminal routing selection policy; Setting the default DNN information to empty, Setting the default slice information to empty, relevant information for establishing a first data channel; a second instruction; and a third instruction; and Address-related information of the first server; and address related information of the second authentication server; Wherein, the first server is a server that can locate a certificate related to a first network; the first terminal routing selection policy is used to access a first server or a certificate download application; the first data channel is a data channel in a first network; The second instruction information is the first data channel is used for interaction between a first communication device and a first server; the first data channel is used by a first communication device to request a certificate associated with a first network; the first data channel is used to configure a certificate associated with a first network in a first communication device; The third instruction information is used to instruct at least one of allowing only restricted services, allowing only the control plane, not allowing the user plane, allowing only access to the first server, and allowing only the certificate download application.
[0290] Optionally, if a fourth condition is met, performing a determination of an associated operation of the second information and / or transmitting the second information; Among them, the fourth condition is: The terminal accesses a restricted service of a first network or receives first indication information sent by the terminal; The terminal confirms that the initial authentication has been successful or the terminal confirms that the second authentication server has been successfully authenticated; and confirming that the first communication device is a non-spoofed device; and confirming that the terminal is a valid device of the first network or that the terminal is a communication device in a valid device list; and confirming that the terminal authorizes the deployment of a certificate associated with the first network.
[0291] The communication device 1500 can implement each process implemented by the third communication device in the method embodiment of the present invention and achieve the same technical effect, and will not be further described here to avoid repetition of description.
[0292] Referring to Figure 16, Figure 16 is a fifth structural diagram of a communication device according to an embodiment of the present invention. As shown in Figure 16, the communication device 1600 includes a memory 1601, a processor 1602, and a computer program 16011 stored in the memory 1601 and operable on the processor 1602.
[0293] Wherein, when the communication device 1600 is represented as the first communication device in the above embodiment of the method, the computer program 16011, when executed by the processor 1602, A step of transmitting first information and / or first instruction information to a first target end is realized, wherein the first information is: index information of a second authentication server; Related information about the manufacturer of the first communication device; and address related information of the second authentication server; The first indication information is used to request obtaining a certificate related to the first network or to indicate that the type of access is a restricted service.
[0294] Optionally, the transmitting of the first information as described above may include: transmitting first information if a first condition is met; Among them, the first condition is: the first communications device having a second certificate; the first communication device does not have a certificate associated with the first network; the first communications device has requested access to a first network; the first communications device has requested access to a restricted service of a first network; and the first communications device has requested acquisition of a certificate associated with a first network; Obtaining at least one of the first pieces of information; obtaining request information for the first information; The first network has obtained information supporting the restricted service; and obtaining information that the first network supports and / or requires authentication for the restricted service; a first network has obtained information that supports and / or requires authentication for the first communication device; and the first network has obtained information supporting the deployment of a certificate associated with the first network on the first communications device.
[0295] Optionally, the request information for the first information is: first request information for requesting manufacturer information of the first communication device; second request information for requesting index information of the second authentication server; and third request information for requesting address-related information of the second authentication server.
[0296] Optionally, before the step of transmitting the first information, when the computer program 16011 is executed by the processor 1602, Further implementing a step of sending an access request and / or sending first instruction information to the first target end; Wherein, the first indication information is used to request obtaining a certificate related to the first network or to indicate that the type of access is a restricted service.
[0297] Optionally, before the step of transmitting the first information, when the computer program 16011 is executed by the processor 1602, transmitted by the first target end, request information for the first information; information that the first network supports restricted services; Information that the first network supports and / or requires authentication for restricted services; and information that a first network supports and / or requires authentication for the first communication device; and information supporting the first network in deploying a certificate associated with the first network in the first communications device.
[0298] Optionally, the computer program 16011, when executed by the processor 1602, Further implementing a step of obtaining second information, wherein the second information is: a first terminal routing selection policy; Setting the default DNN information to empty, Setting the default slice information to empty, relevant information for establishing a first data channel; a second instruction; and a third instruction; and Address-related information of the first server; and address related information of the second authentication server; Wherein, the first server is a server that can locate a certificate related to a first network; the first terminal routing selection policy is used to access a first server or a certificate download application; the first data channel is a data channel in a first network; The second instruction information is the first data channel is used for interaction between a first communication device and a first server; the first data channel is used by a first communication device to request a certificate associated with a first network; the first data channel is used to configure a certificate associated with a first network in a first communication device; The third instruction information is used to instruct at least one of allowing only restricted services, allowing only the control plane, not allowing the user plane, allowing only access to the first server, and allowing only the certificate download application.
[0299] Wherein, when the communication device 1600 is represented as the second communication device in the above embodiment of the method, the computer program 16011, when executed by the processor 1602, acquiring at least one of first information, first instruction information, a valid device list, and third information; performing a first operation based on at least one of the first information, the first instruction information, the authorized device list, and the third information; wherein the first information includes at least one of index information of a second authentication server, related information of a manufacturer of the first communication device, and address related information of the second authentication server; the first indication information is used to indicate that a type of access to a first network requires obtaining a certificate related to the first network or is a restricted service; The third information is Mapping information between index information of the second authentication server and address-related information of the second authentication server; and address related information of the second authentication server.
[0300] Optionally, the first operation comprises: An operation of determining the second authentication server; an operation of determining an operation of requesting authentication of the first communication device from the second authentication server; an operation of requesting the second authentication server to authenticate the first communication device; an operation of requesting a first server to authenticate the first communications device; an operation of transmitting the first information to the first server; an operation of confirming whether the first communication device is an authorized device of a first network; an operation of confirming whether to permit placement of a certificate related to the first network in the first communication device; and an operation of confirming whether to permit the first network to accept the registration request of the first communication device, Wherein, the first server is a server that can locate a certificate related to the first network for the first communication device.
[0301] Optionally, the step of determining the second authentication server includes: determining a second authentication server based on index information of the second authentication server in the first information and mapping information between the index information of the second authentication server in the third information and address-related information of the second authentication server; determining a second authentication server based on the manufacturer related information of the first communication device in the first information and mapping information between index information of the second authentication server and address related information of the second authentication server in the third information; determining a second authentication server based on address-related information of the second authentication server in the first information and / or address-related information of the second authentication server in the third information; determining a second authentication server based on address-related information of the second authentication server in the first instruction information and / or the third information; and / or The step of determining to request authentication of the first communication device from the second authentication server includes: determining, based on the first instruction information and / or the first information, to request authentication of the first communication device from the second authentication server; and determining to request authentication of the first communication device from the second authentication server based on address-related information of the second authentication server in the first instruction information and / or the third information, but is not limited to these.
[0302] optionally, if the first communication device satisfies a second condition, confirming that the first communication device is a valid device of the first network; Among them, the second condition is: the first communication device has been successfully authenticated by the second authentication server; and the first communication device is a communication device on a list of authorized devices.
[0303] Optionally, the valid device list comprises: a legitimate communication device of the first network that does not have a certificate associated with the first network; and a communications device that authorizes deployment of a certificate associated with the first network.
[0304] Optionally, before acquiring the first information, the computer program 16011 is executed by the processor 1602 to: receiving first indication information indicating that a type of access request from the first communication device and / or requesting acquisition of a credential associated with the first network or access is a restricted service; and transmitting request information for the first information based on the access request and / or the first instruction information.
[0305] Optionally, the request information for the first information is: first request information for requesting manufacturer information of the first communication device; second request information for requesting index information of the second authentication server; and third request information for requesting address-related information of the second authentication server.
[0306] Optionally, the computer program 16011, when executed by the processor 1602, If the first communication device is determined to be a legitimate device of the first network, the method further includes transmitting second information, wherein the second information includes: relevant information for establishing a first data channel; a second instruction; and and address related information of the first server; Wherein, the first server is a server that can locate a certificate related to a first network; the first data channel is a data channel in a first network; The second instruction information is the first data channel is used for interaction between a first communication device and a first server; the first data channel is used by a first communication device to request a certificate associated with a first network; The first data channel is used to indicate at least one of the following: to configure a first communication device with a certificate associated with a first network;
[0307] Wherein, when the communication device 1600 is represented as the third communication device in the above embodiment of the method, when the computer program 16011 is executed by the processor 1602, determining third information; and transmitting third information; Among them, the third information is: Mapping information between index information of a second authentication server and address-related information of the second authentication server; and address related information of the second authentication server.
[0308] Optionally, the step of transmitting the information related to the second authentication server includes: If a third condition is met, sending related information of the second authentication server; The third condition is: the third communication device and the second authentication server have successfully completed mutual authentication; and the third communication device and the first network have successfully completed mutual authentication.
[0309] Wherein, when the communication device 1600 is represented as the fourth communication device in the above embodiment of the method, when the computer program 16011 is executed by the processor 1602, obtaining second information; and performing a second operation based on the second information; Among them, the second information is: a first terminal routing selection policy; Setting the default DNN information to empty, Setting the default slice information to empty, relevant information for establishing a first data channel; a second instruction; and a third instruction; and Address-related information of the first server; and address related information of the second authentication server; Wherein, the first server is a server that can locate a certificate related to a first network; the first terminal routing selection policy is used to access a first server or a certificate download application; the first data channel is a data channel in a first network; The second instruction information is the first data channel is used for interaction between a first communication device and a first server; the first data channel is used by a first communication device to request a certificate associated with a first network; the first data channel is used to configure a certificate associated with a first network in a first communication device; The third instruction information is used to instruct at least one of allowing only restricted services, allowing only the control plane, not allowing the user plane, allowing only access to the first server, and allowing only the certificate download application.
[0310] Optionally, the second operation comprises: an operation of establishing a first data channel, the first data channel satisfying at least one of the following: the first data channel is used for interaction between a first communication device and a first server; the first data channel is used for requesting a certificate related to the first network by the first communication device; and the first data channel is used to configure the first communication device with a certificate related to the first network; requesting a first server to locate a certificate associated with the first network; requesting a second authentication server to locate a certificate associated with the first network; An operation of rejecting an access request or a data transmission request other than the target first server and / or the certificate download application of the application layer; and allowing only access requests or data transmission requests whose targets are the first server and / or the certificate download application.
[0311] Wherein, when the communication device 1600 is represented as the fifth communication device in the above embodiment of the method, when the computer program 16011 is executed by the processor 1602, and transmitting second information, wherein the second information is: a first terminal routing selection policy; Setting the default DNN information to empty, Setting the default slice information to empty, relevant information for establishing a first data channel; a second instruction; and a third instruction; and Address-related information of the first server; and address related information of the second authentication server; Wherein, the first server is a server that can locate a certificate related to a first network; the first terminal routing selection policy is used to access a first server or a certificate download application; the first data channel is a data channel in a first network; The second instruction information is the first data channel is used for interaction between a first communication device and a first server; the first data channel is used by a first communication device to request a certificate associated with a first network; the first data channel is used to configure a certificate associated with a first network in a first communication device; The third instruction information is used to instruct at least one of allowing only restricted services, allowing only the control plane, not allowing the user plane, allowing only access to the first server, and allowing only the certificate download application.
[0312] Optionally, if a fourth condition is met, performing a determination of an associated operation of the second information and / or transmitting the second information; Among them, the fourth condition is: The terminal accesses a restricted service of a first network or receives first indication information sent by the terminal; The terminal confirms that the initial authentication has been successful or the terminal confirms that the second authentication server has been successfully authenticated; and confirming that the first communication device is a non-spoofed device; and confirming that the terminal is a valid device of the first network or that the terminal is a communication device in a valid device list; and confirming that the terminal authorizes the deployment of a certificate associated with the first network.
[0313] The communication device 1600 may implement each process implemented by the communication device in the above method embodiments, which will not be further described here to avoid repetition.
[0314] An embodiment of the present invention further provides a computer-readable storage medium having a computer program stored thereon. When the computer program is executed by a processor, it can realize each process of any one of the above access control method embodiments and achieve the same technical effects. To avoid repetition, the computer-readable storage medium is not further described here. The computer-readable storage medium may be, for example, a read-only memory (ROM), a random access memory (RAM), a magnetic disk, or an optical disk.
[0315] It should be noted that, in this specification, the terms "comprises," "including," or any other variation thereof, are intended to cover a non-exclusive "comprise," whereby a process, method, article, or apparatus that includes a set of elements not only includes those elements, but also includes other elements not expressly listed or inherent in such process, method, article, or apparatus. In the absence of further limitations, an element limited by the phrase "comprises one of," does not exclude the presence of other identical elements in a process, method, article, or apparatus that includes that element.
[0316] As will be apparent to those skilled in the art from the above description of the embodiments, the methods of the above embodiments may be realized in the form of software and a necessary general-purpose hardware platform. Of course, they can also be realized in hardware, but in many cases the former is the preferred embodiment. Based on this understanding, the technical solution of the present invention, in substance or in part contributing to the prior art, may be expressed in the form of a software product. This computer software product is stored in a storage medium (e.g., ROM / RAM, magnetic disk, optical disk) and includes some instructions for causing a terminal (which may be a mobile phone, computer, server, air conditioner, network device, etc.) to execute the methods described in each embodiment of the present invention.
[0317] Although the embodiments of the present invention have been described above in conjunction with the accompanying drawings, the present invention is not limited to the specific embodiments described above, and the specific embodiments described above are merely illustrative and not restrictive. Those skilled in the art can make many modifications based on the teachings of the present invention without departing from the spirit of the present invention or the scope of protection of the claims, and all of them fall within the scope of protection of the present invention.
Claims
1. An access control method for use in a terminal, comprising: receiving second information transmitted by the fifth communication device; performing a second operation based on the second information; Wherein, the second information includes address-related information of the first server; Wherein, the first server is a server that can locate a certificate related to a first network; The second operation is requesting a first server to locate a certificate associated with the first network; 1. A method for access control, comprising: an operation of establishing a first data channel, the first data channel satisfying at least one of the following operations: the first data channel is used for interaction between the terminal and a first server; the first data channel is used for the terminal to request a certificate associated with a first network; and the first data channel is used to configure the terminal with a certificate associated with a first network.
2. The method of claim 1 , wherein the address-related information includes at least one of an IP address, a Free Qualified Domain Name (FQDN).
3. The method of claim 1 , wherein the certificate associated with the first network comprises a certificate for accessing the first network or a certificate that can be directly authenticated by an authentication server of the first network.
4. The method of claim 1 , wherein the first network comprises a separate non-public network SNPN.
5. An access control method for use in a fifth communication device, comprising: transmitting second information to the terminal; Wherein, the second information includes address-related information of the first server; Wherein, the first server is a server that can locate a certificate related to a first network; If a fourth condition is satisfied, transmitting second information to the terminal; Among them, the fourth condition is: The terminal confirms that the initial authentication has been successful or the terminal confirms that the second authentication server has been successfully authenticated; It has been confirmed that the terminal is a non-spoofed device; and confirming that the terminal is a valid device of the first network or that the terminal is a communication device in a valid device list; and confirming that the terminal allows deployment of a certificate associated with the first network.
6. The method of claim 5 , wherein the address-related information includes at least one of an IP address, a Free Qualified Domain Name (FQDN).
7. The method of claim 5 , wherein the certificate associated with the first network comprises a certificate for accessing the first network or a certificate that can be directly authenticated by an authentication server of the first network.
8. The method of claim 5 , wherein the first network comprises a separate non-public network SNPN.
9. A terminal, an acquisition module for receiving the second information transmitted by the fifth communication device; an execution module for executing a second operation based on the second information; Wherein, the second information includes address-related information of the first server; Wherein, the first server is a server that can locate a certificate related to a first network; The second operation is requesting deployment of a certificate associated with the first network from the first server; a terminal, the terminal including at least one of the following operations: establishing a first data channel, the first data channel satisfying at least one of: the first data channel being used for interaction between the terminal and a first server; the first data channel being used for requesting a certificate associated with a first network by the terminal; and the first data channel being used to configure the terminal with a certificate associated with a first network.
10. The terminal of claim 9, wherein the address-related information includes at least one of an IP address and a Free Qualified Domain Name (FQDN).
11. The terminal of claim 9 , wherein the certificate associated with the first network comprises a certificate for accessing the first network or a certificate that can be directly authenticated by an authentication server of the first network.
12. The terminal of claim 9, wherein the first network comprises a separate non-public network SNPN.
13. A fifth communication device, a transmitting module for transmitting second information to the terminal; Wherein, the second information includes address-related information of the first server; Wherein, the first server is a server that can locate a certificate related to a first network; If a fourth condition is satisfied, transmitting second information to the terminal; Among them, the fourth condition is: The terminal confirms that the initial authentication has been successful or the terminal confirms that the second authentication server has been successfully authenticated; It has been confirmed that the terminal is a non-spoofed device; and confirming that the terminal is a valid device of the first network or that the terminal is a communication device in a valid device list; and confirming that the terminal authorizes the deployment of a certificate associated with the first network.
14. 14. The fifth communication device according to claim 13, wherein the address-related information includes at least one of an IP address and a Free Qualified Domain Name (FQDN).
15. 14. The fifth communication device of claim 13, wherein the certificate associated with the first network includes a certificate for accessing the first network or a certificate that can be directly authenticated by an authentication server of the first network.
16. 14. The fifth communication device according to claim 13, wherein the first network comprises a separate non-public network SNPN.
17. A computer-readable storage medium having a computer program stored thereon, the computer program causing the steps of the access control method according to any one of claims 1 to 4 to be realized when executed by a processor.
18. A computer-readable storage medium having a computer program stored thereon, the computer program causing the steps of the access control method according to any one of claims 5 to 8 to be realized when executed by a processor.
Citation Information
Patent Citations
Authentication method
JP2004235890A
Authentication transferring device
JP2009031848A
Method and apparatus for performing secure bluetooth communication
US20160277923A1