Authentication methods, devices, media, and chips
By using an Authentication Proxy entity to derive an Application Key based on FQDN for UE authentication, the method addresses the inefficiencies in existing wireless communication systems by centralizing authentication, reducing AF entity load and improving system efficiency.
Patent Information
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- BEIJING XIAOMI MOBILE SOFTWARE CO LTD
- Filing Date
- 2022-05-09
- Publication Date
- 2026-04-24
AI Technical Summary
Existing wireless communication systems face increased load and decreased efficiency of application function (AF) entities due to direct message exchanges for determining user equipment access rights, which complicates secure session establishment.
A communication method and device that utilize an Authentication Proxy (AP) entity to derive an Application Key based on the fully qualified domain name (FQDN) of a target entity, enabling UE authentication and reducing the load on AF entities by centralizing authentication through a trusted proxy entity within the 3GPP operator domain.
This approach reduces the load on AF entities and improves their efficiency by centralizing authentication, allowing user equipment to achieve authorization and authentication through a unified proxy entity, thereby simplifying the authentication process and enhancing system performance.
Smart Images

Figure 0007851424000001 
Figure 0007851424000002 
Figure 0007851424000003
Abstract
Description
[Technical Field]
[0001] This disclosure relates to the field of telecommunications technology, specifically to authentication methods, devices, media, and chips. [Background technology]
[0002] In wireless communication systems, 3GPP (3rd Generation Partnership Project) defines session security protection features between user equipment (UE) and application functions, and provides an application-based key management method called AKMA (Authentication and Key Management for Applications based on 3GPP credentials).
[0003] In related technologies, user equipment can exchange messages with application function (AF) entities based on AKMA, and by determining the user equipment's access rights to the application function (AF) entities, a secure session is established with the application function (AF) entities, which increases the load on the application function (AF) entities and decreases their efficiency. [Overview of the project] [Problems that the invention aims to solve]
[0004] To solve the above-mentioned problems present in related technologies, this disclosure provides a communication method, apparatus, medium, and chip. [Means for solving the problem]
[0005] According to a first embodiment of the embodiments of the present disclosure, a communication method is provided which is applied to user equipment (UE), and the communication method is A step of determining a target entity from among one or more application servers (AS), wherein the UE communicates with the target entity via an Authentication Proxy (AP) entity, The steps include: deriving an Application Key based on the fully qualified domain name (FQDN) of the target entity, wherein the Application Key is used by the AP entity to perform UE authentication against the UE.
[0006] In one embodiment, the communication method is The further step includes sending the AKMA (Authentication and Key Management for Applications) key identifier (AKMA Key Identifier, A-KID) of the UE, and / or the FQDN of the target entity, to the AP entity.
[0007] In one embodiment, the communication method is The step of sending an application session establishment request message to the AP entity, further comprising the step of the application session establishment request message including the A-KID of the UE and / or the FQDN of the target entity.
[0008] In one embodiment, the communication method is The process further includes receiving an application session establishment response message sent from the aforementioned AP entity.
[0009] In one embodiment, the communication method is The step further includes determining a first communication authority based on the aforementioned application session establishment response message, The aforementioned first communication authority is, The UE has access rights to the target entity, The UE has access rights to the AP entity, The AP entity has proxy authority over the target entity, This includes one or more of the following: the target entity has the right to retrieve the subscriber identifier of the UE.
[0010] In one embodiment, the application session establishment response message is received by the AP entity when the AP entity receives the application key from the AKMA Anchor Function (AAnF) entity and the AP entity sends the application session establishment response message to the UE, and the application key is derived by the AAnF entity based on the FQDN of the target entity sent from the AP entity to the AAnF entity, Or, The application session establishment response message is received by the AP entity if the AP entity does not receive the application key from the AAnF entity and the AP entity sends the application session establishment response message to the UE, the application session response message includes a failure instruction, and the application key is driven by the AAnF entity based on the FQDN of the target entity sent from the AP entity to the AAnF entity.
[0011] According to a second aspect of an embodiment of the present disclosure, a communication method is provided, which is applicable to an Authentication Proxy (AP) entity, and the communication method includes: performing UE authentication on a User Equipment (UE) based on an application key, where the application key is derived based on the fully qualified domain name (FQDN) of a target entity among one or more Application Servers (ASs), and the step that the UE communicates with the target entity through the AP entity.
[0012] In one embodiment, the communication method includes: when the UE authentication on the UE by the AP entity is successful, further including the step of sending a subscriber identifier to the target entity.
[0013] In one embodiment, the communication method includes: further including the step of sending the A-KID of the UE and / or the FQDN of the target entity to an AAnF entity.
[0014] In one embodiment, the communication method includes: receiving the application key sent from the AAnF entity, where the application key is derived by the AAnF entity based on the FQDN of the target entity.
[0015] In one embodiment, the communication method includes: further including the step of receiving, from the UE, the A-KID of the UE and / or the FQDN of the target entity.
[0016] In one embodiment, the communication method includes: Receiving, from the UE, an application session establishment request message, wherein the application session establishment request message includes the UE's AKMA key identifier (AKMA Key Identifier, A-KID) and / or the FQDN of the target entity.
[0017] In one embodiment, the communication method further includes: Sending an application session establishment response message to the UE.
[0018] In one embodiment, the communication method further includes: Determining a first communication authority based on the application key received from the AAnF entity, The first communication authority includes: The UE has access authority to the target entity; The UE has access authority to the AP entity; The AP entity has proxy authority to the target entity; The target entity has acquisition authority to the subscriber identifier of the UE, including one or more of the above.
[0019] According to a third aspect of the embodiments of the present disclosure, a communication method is provided, which is applicable to a target entity among one or more application servers (AS), and the communication method includes: When the user equipment (UE) authentication by the authentication proxy (AP) entity to the UE is successful, receiving the subscriber identifier sent from the AP entity, and the target entity communicates with the UE through the AP entity.
[0020] In one embodiment, when the AP entity performs UE authentication on the UE, The AP entity performs UE authentication with the UE based on an application key, the application key being derived based on the fully qualified domain name (FQDN) of the target entity.
[0021] In one embodiment, the communication method is Further including the step of determining the first communications authority, The aforementioned first communication authority is, The UE has access rights to the target entity, The UE has access rights to the AP entity, The AP entity has proxy authority over the target entity, This includes one or more of the following: the target entity has the right to retrieve the subscriber identifier of the UE.
[0022] According to a fourth embodiment of the embodiments of this disclosure, a communication method is provided which is applied to an AAnF entity, and the communication method is The steps include receiving the A-KID of the User Equipment (UE) and / or the fully qualified domain name (FQDN) of the target entity from the AP entity, The process includes sending an application key to the AP entity, wherein the application key is derived based on the fully qualified domain name (FQDN) of the target entity.
[0023] In one embodiment, the application key is used by the AP entity to authenticate the UE with the UE, and the UE communicates with the target entity via the AP entity.
[0024] According to a fifth embodiment of the embodiments of the present disclosure, a communication device is provided which is applied to user equipment, the device including a processing module, The aforementioned processing module The UE determines a target entity from among one or more application servers (AS), and communicates with the target entity via an Authentication Proxy (AP) entity. The system is configured to derive an Application Key based on the fully qualified domain name (FQDN) of the target entity, and the Application Key is used by the AP entity to perform UE authentication against the UE.
[0025] According to a sixth embodiment of the embodiments of this disclosure, a communication device is provided which is applied to an AP entity, and the device is A processing module configured to perform UE authentication to a user equipment (UE) based on an application key, wherein the application key is derived based on the fully qualified domain name (FQDN) of a target entity among one or more application servers (AS), and the processing module includes a mechanism by which the UE communicates with the target entity via the AP entity.
[0026] According to a seventh embodiment of the embodiments of this disclosure, a communication device is provided which is applied to a target entity among one or more application servers (AS), and the device is A transceiver module configured to receive a subscriber identifier sent from an Authentication Proxy (AP) entity when the AP entity successfully authenticates the User Equipment (UE) to the UE, and including a transceiver module in which the target entity communicates with the UE via the AP entity.
[0027] According to an eighth aspect of the embodiments of this disclosure, a communication device is provided which is applied to an AAnF entity, and the device includes a transceiver module, The aforementioned transmitting and receiving module Receive the A-KID of the user equipment and / or the fully qualified domain name (FQDN) of the target entity from the AP entity. The application key is configured to send an application key to the aforementioned AP entity, and the application key is derived based on the fully qualified domain name (FQDN) of the target entity.
[0028] According to a ninth embodiment of the embodiments of the present disclosure, a communication device is provided, comprising one or more processors and a memory coupled to the processors and storing computer-readable instructions, wherein when the computer-readable instructions are executed by the processors, the communication device is made to execute a communication method provided by any of the first to fourth embodiments of the present disclosure.
[0029] According to a tenth embodiment of the embodiments of the present disclosure, a computer-readable storage medium is provided in which computer program instructions are stored, and when the computer program instructions are executed by a processor, a communication method provided by any of the first to fourth embodiments of the present disclosure is realized. According to an eleventh embodiment of the embodiments of the present disclosure, a computer program is provided, and when the computer program is executed by a processor, a communication method provided by any of the first to fourth embodiments of the present disclosure is realized. [Effects of the Invention]
[0030] The technical inventions provided by embodiments of this disclosure can have the following beneficial effects: one or more first entities determine a target entity requesting communication; the first authorization request parameters are determined based on the target entity; an application session establishment request message is sent to a first proxy entity based on the first authorization request parameters; in response to receiving an application session establishment response message sent from the first proxy entity, it is determined whether the user equipment and the target entity have first communication authorization; and if the user equipment and the target entity have first communication authorization, the first proxy entity performs user equipment authentication. Here, the application session establishment request message instructs the first proxy entity to determine whether the user equipment and the target entity have first communication authorization based on the first authorization request parameters, the first entity may include an entity that provides application functionality, the first proxy entity may include a trusted entity that provides authentication functionality within a 3GPP operator domain, and the first proxy entity provides authentication proxy functionality to the first entity. In this way, a trusted first proxy entity within the 3GPP operator domain can determine whether the user equipment and the first entity have first communication authority, perform identity verification of the user equipment if they have first communication authority, and enable some of the first entity's functions to be implemented by the first proxy entity. As a result, the load on the first entity is reduced and its efficiency is improved. Furthermore, the user equipment can achieve authorization authentication for one or more first entities and user equipment authentication through a unified first proxy entity, reducing the complexity of authentication by the user equipment and improving the efficiency of the user equipment.
[0031] The above general explanation and the following detailed explanation are illustrative and explanatory, and do not limit this disclosure. [Brief explanation of the drawing]
[0032] The drawings herein are incorporated into the specification and constitute part of this specification, illustrating embodiments consistent with the present disclosure and are used together with the specification to illustrate the principles of the present disclosure. [Figure 1] This is a schematic diagram of a communication system to which an embodiment of the present disclosure, shown in one exemplary embodiment, is applied. [Figure 2] This is a schematic diagram of a communication system to which another embodiment of the present disclosure, shown in one exemplary embodiment, is applied. [Figure 3] This is a flowchart of an authentication method shown in one exemplary embodiment. [Figure 4] This is a flowchart of an authentication method shown in one exemplary embodiment. [Figure 5] This is a flowchart of an authentication method shown in one exemplary embodiment. [Figure 6] This is a flowchart of an authentication method shown in one exemplary embodiment. [Figure 7] This is a flowchart of an authentication method shown in one exemplary embodiment. [Figure 8] This is a flowchart of an authentication method shown in one exemplary embodiment. [Figure 9] This is a flowchart of an authentication method shown in one exemplary embodiment. [Figure 10] This is a flowchart of an authentication method shown in one exemplary embodiment. [Figure 11] This is a flowchart of an authentication method shown in one exemplary embodiment. [Figure 12] This is a flowchart of an authentication method shown in one exemplary embodiment. [Figure 13] This is a block diagram of an authentication device shown in one exemplary embodiment. [Figure 14] This is a block diagram of an authentication device shown in one exemplary embodiment. [Figure 15]This is a block diagram of an authentication device shown in one exemplary embodiment. [Figure 16] This is a block diagram of an authentication device shown in one exemplary embodiment. [Figure 17] This is a block diagram of an authentication device shown in one exemplary embodiment. [Figure 18] This is a block diagram of an authentication device shown in one exemplary embodiment. [Figure 19] This is a block diagram of an authentication device shown in one exemplary embodiment. [Figure 20] This is a block diagram of an authentication device shown in one exemplary embodiment. [Modes for carrying out the invention]
[0033] Herein, exemplary embodiments are described, and these examples are shown in the drawings. The following description is related to the drawings, and unless otherwise specified, the same numbers in different drawings represent the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with the present disclosure. Rather, they are merely examples of apparatuses and methods consistent with certain aspects of the present disclosure, which are exaggerated in the appended claims.
[0034] Furthermore, in this disclosure, all operations for acquiring signals, information, or data are conducted in accordance with the corresponding data protection laws and policies of the country in which they are located, and with the permission of the owner of the corresponding equipment.
[0035] In this disclosure, terms such as "First," "Second," etc., are used to distinguish similar subjects and should not be understood as a specific order or sequence. Furthermore, unless otherwise specified, in descriptions referring to drawings, identical marks in different drawings represent the same element.
[0036] In this disclosure, unless otherwise specified, “plural” refers to two or more, and other classifiers are similar. “At least one of” or similar expressions include any combination of these options, including any combination of one or more items. For example, “At least one of a, b, or c” could mean a, b, c, ab, ac, bc, or abc, where a, b, and c may be singular or plural; “and / or” is used to describe the relational relationship of the related objects, indicating that there may be three types of relationships, for example, A and / or B could mean that A exists alone, A and B exist together, or B exists alone, where A and B may be singular or plural.
[0037] In the embodiments of this disclosure, the drawings describe and perform operations in a specific order, but it is not required that these operations be performed in a specific order or sequence, or that the desired results be obtained by performing all the operations shown. In certain environments, multitasking and parallel processing may be advantageous.
[0038] In related technologies, user equipment can exchange messages with application function (AF) entities based on AKMA to determine its access rights to those application function (AF) entities, thereby establishing a secure session with the application function (AF) entities. However, message exchanges generated by multiple user equipment increase the load on application function (AF) entities and decrease their efficiency. Furthermore, if multiple application function (AF) entities exist on the network, and the UE directly exchanges messages with the AFs to determine access rights, it becomes less efficient for the UE.
[0039] To solve the above problems, this disclosure provides an authentication method, apparatus, medium, and chip.
[0040] The implementation environment of the embodiments of this disclosure will be described below.
[0041] The embodiments of this disclosure are applicable to 4G (the 4th Generation) network systems such as Long Term Evolution (LTE) systems, or to 5G (the 5th Generation) network systems such as access networks using New Radio Access Technology (New RAT) and communication systems such as Cloud Radio Access Networks (CRAN).
[0042] Figure 1 is a schematic diagram of a communication system to which an embodiment of the present disclosure, shown as an exemplary example, is applied. The embodiment of the present disclosure is not limited to the system shown in Figure 1, and the entities in Figure 1 may be hardware, functionally separated software, or a combination of both. The entities shown in Figure 1 may be entities within any communication network architecture, and the communication network may be a 4G network, a 5G network, or a 6G network, etc.
[0043] As shown in Figure 1, the communication system may include a first entity 101, a third entity 103, a first proxy entity 110, and user equipment 160, where the first entity 101 may be one or more entities, for example, the first entity 101 may include first entities 1011, first entities 1012, ..., first entities 101n, etc. The first proxy entity 110 may be connected to one or more of the first entities 101 (for example, via a wired network, a wireless network, or a combination thereof), the first proxy entity may be connected to the third entity, and the user equipment may be connected to the first proxy entity and the third entity.
[0044] In some embodiments, the first entity 101 may include a trusted entity that provides application functionality within the 3GPP operator domain, the first proxy entity 110 may include a trusted entity that provides authentication proxy functionality within the 3GPP operator domain, and the third entity 103 may include an entity that provides AKMA authorization and application key derivation functionality. For example, the third entity 103 may be a functional entity that provides AKMA anchor functionality and authenticates the communication rights between user equipment and the first entity.
[0045] For example, the first entity may include an Application Function (AF) entity or an Application Server (SCS / AS), the first proxy entity may include an Authentication Proxy (AP) entity, and the third entity may include an AKMA Anchor Function (AAnF) entity.
[0046] In some embodiments, the first entity may include a trusted entity that provides application functionality within the 3GPP operator domain, and the first proxy entity may include a trusted entity that provides authentication functionality within the 3GPP operator domain, the first proxy entity providing authentication proxy functionality to the first entity, and the first entity may include one or more entities.
[0047] Figure 2 is a schematic diagram of a communication system to which another embodiment of the present disclosure, shown in one exemplary embodiment, is applied, as shown in Figure 2, the communication system may include a first entity 101, a second entity 122, a third entity 103, a first proxy entity 110, and user equipment 160, where the first entity 101 may be one or more. The second entity 102 may be connected to the one or more first entities 101 (for example, via a wired network, a wireless network, or a combination thereof), the first proxy entity may be connected to the second and third entities, and the user equipment may be connected to the first proxy entity and the third entities.
[0048] In Figure 2, the first entity 101 may include an untrusted entity that provides application functionality outside the 3GPP operator domain, for example, an Application Function (AF) entity or an Application Server (SCS / AS). The first proxy entity 110 may include a trusted entity that provides authentication proxy functionality within the 3GPP operator domain, for example, an AKMA Authentication Proxy (AP) entity. The third entity 103 may include an entity that provides AKMA authorization and application key derivation functionality, for example, an AKMA Anchor Function (AAnF) entity. The second entity may include an entity that provides network exposure functionality, for example, a Network Exposure Function (NEF) entity or a Service Capability Exposure Function (SCEF) entity.
[0049] Figure 3 shows an authentication method in an exemplary embodiment, which is applicable to user equipment in the above-mentioned communication system. As shown in Figure 3, the method may include the following S301 to S305.
[0050] S301, User Equipment determines the target entity requesting communication from one or more First Entities.
[0051] For example, the first entity may include entities that provide application functionality, such as application functionality (AF) entities. User equipment can determine which AF entities to request communication from, depending on the user functionality needs.
[0052] S302, User Equipment determines the first authorization request parameters based on the target entity.
[0053] In some embodiments, the first target entity identifier of the target entity can be obtained, and the first authorization parameter can be determined based on the first target entity identifier.
[0054] For example, the first target entity identifier may include the target entity's FQDN (Fully Qualified Domain Name), an IP (Internet Protocol) address, and a port number, or one or more of these.
[0055] In some embodiments, the first authorization request parameters can be obtained based on the first target entity identifier and a user equipment identifier representing the identity of the user equipment.
[0056] Here, the user equipment identifier may include a key identifier (A-KID) corresponding to the user equipment, and the key identifier (A-KID) may be generated based on the hardware information of the user equipment and the registration information transmitted from the communication system when the user equipment registers and accesses the communication system, and the key identifier (A-KID) can uniquely identify a single user equipment in the communication system.
[0057] For example, the first target entity identifier and the key identifier (A-KID) corresponding to the user equipment can be the first authorization request parameters.
[0058] S303, User Equipment sends an application session establishment request message to the first proxy entity based on the first authorization request parameter.
[0059] Here, the application session establishment request message may instruct the first proxy entity to determine, based on the first authorization request parameters, whether the user equipment and the target entity have first communication authorization.
[0060] In some embodiments, the first proxy entity is connected to one or more first entities. Exemplarily, a unified first proxy entity can be configured within a trust domain or edge node, and the first proxy entity can be connected to each first entity within the trust domain or edge node. When user equipment requests communication with a target entity within the trust domain or edge node, an application session establishment request message (e.g., an Application Session Establishment Request message) may be sent to the first proxy entity.
[0061] In some embodiments, the first entity may include entities that provide application functionality (for example, trusted entities that provide application functionality within a 3GPP operator domain, or untrusted entities that provide application functionality outside a 3GPP operator domain), and the first proxy entity may include trusted entities that provide authentication functionality within a 3GPP operator domain, the first proxy entity providing authentication proxy functionality to the first entity, and the first entity may include one or more entities.
[0062] In some embodiments, the user equipment may pre-configure the proxy domain name (e.g., FQDN) of the first proxy entity, and the user equipment can exchange messages or transmit data with the first proxy entity using the FQDN.
[0063] S304, User Equipment, in response to receiving an application session establishment response message sent from the first proxy entity, determines whether User Equipment and the target entity have first communication authority.
[0064] In some embodiments, when the user equipment receives the application session establishment response message, it may determine that the user equipment and the target entity have first communication authority.
[0065] Conversely, if the user equipment does not receive the application session establishment response message within a predetermined time, it can be determined that the user equipment and the target entity do not have the first communication authority.
[0066] In some other embodiments, if the user equipment has received an application session establishment response message and the application session establishment response message contains success instruction information, the user equipment and the target entity may determine that they have first communication authority.
[0067] Conversely, if the application session establishment response message received by the user equipment does not contain success instruction information, or if it contains failure instruction information, it can be determined that the user equipment and the target entity do not have first communication authority. The success instruction information may be any instruction information that has been set in advance.
[0068] In some other embodiments, if the user equipment has received an application session establishment response message and the application session establishment response message does not contain any failure instruction information, the user equipment may determine that the target entity has first communication authority.
[0069] Conversely, if the application session establishment response message received by the user equipment contains failure instruction information, it can be determined that the user equipment and the target entity do not have the first communication authority. This failure instruction information may be any pre-configured error code.
[0070] S305, If the user equipment and the target entity have first communication authority, the user equipment performs user equipment authentication by the first proxy entity.
[0071] For example, user equipment corresponds to the target entity based on the FQDN of the target entity. Application Features Key K AF (Application Key K) AF (Also known as) derive the application Key K AF It is possible to perform user equipment authentication (perform UE authentication) based on the first proxy entity.
[0072] The method by which user equipment performs user equipment authentication should be referred to in the implementations in related technologies. For example, user equipment authentication may be performed based on entity key information corresponding to the target entity, or user equipment authentication may be performed based on user key information corresponding to the user equipment and entity key information corresponding to the target entity. This disclosure is not limited to these methods.
[0073] Using the above method, one or more first entities determine a target entity requesting communication, determine first authorization request parameters based on the target entity, send an application session establishment request message to a first proxy entity based on the first authorization request parameters, and in response to receiving an application session establishment response message sent from the first proxy entity, determine whether the user equipment and the target entity have first communication authorization, and if the user equipment and the target entity have first communication authorization, perform user equipment authentication by the first proxy entity. Here, the application session establishment request message instructs the first proxy entity to determine whether the user equipment and the target entity have first communication authorization based on the first authorization request parameters, the first entity may include an entity that provides application functionality, the first proxy entity may include a trusted entity that provides authentication functionality within the 3GPP operator domain, and the first proxy entity provides authentication proxy functionality to the first entity. In this way, a trusted first proxy entity within the 3GPP operator domain can determine whether the user equipment and the first entity have first communication authority, perform identity verification of the user equipment if they have first communication authority, and enable some of the first entity's functions to be implemented by the first proxy entity. As a result, the load on the first entity is reduced and its efficiency is improved. Furthermore, the user equipment can achieve authorization authentication for one or more first entities and user equipment authentication through a unified first proxy entity, reducing the complexity of authentication by the user equipment and improving the efficiency of the user equipment.
[0074] In some embodiments, the first communication authority described above may include one or more of the following authorities: Permission 1: User Equipment has access rights to the target entity. Permission 2: User Equipment has access rights to the first proxy entity. Authority 3: The first proxy entity has proxy authority over the target entity. Permission 4: The target entity has permission to retrieve the subscriber identifier of the user equipment.
[0075] For example, if it is determined that user equipment has access rights to a target entity, it can be determined that user equipment and the target entity have first communication rights; if it is determined that user equipment has access rights to a first proxy entity and the first proxy entity has proxy rights to a target entity, it can be determined that user equipment and the target entity have first communication rights; and if it is determined that user equipment has access rights to a target entity, user equipment has access rights to a first proxy entity and the first proxy entity has proxy rights to a target entity, it can be determined that user equipment and the target entity have first communication rights.
[0076] In some embodiments, the fact that user equipment and target entities have a first communication privilege may include the user equipment having access privileges to a first proxy entity, and the first proxy entity having proxy privileges to the target entity, for example, if the first proxy entity is the same as the FQDN of the target entity, then the first communication privilege can be used.
[0077] In some other embodiments, the fact that user equipment and target entities have a first communication authority may include the user equipment having access rights to the target entity, the user equipment having access rights to a first proxy entity, and the first proxy entity having proxy authority over the target entity, for example, if the first proxy entity is different from the FQDN of the target entity, the first communication authority can be used.
[0078] In some embodiments, the first proxy entity described above may include a trusted authenticated proxy (AP) entity within a 3GPP operator domain.
[0079] In some embodiments, the first entity may include a trusted entity that provides application functionality within a 3GPP operator domain. For example, the first entity may include a trusted application functionality (AF) entity within a 3GPP operator domain, or a trusted application server (SCS / AS) entity within a 3GPP operator domain.
[0080] In some other embodiments, the first entity may include an untrusted entity that provides application functionality outside the 3GPP operator domain, the first proxy entity may communicate with the first entity through a second entity, the second entity may include an entity that provides network exposure functionality. Exemplarily, the first entity may include an untrusted application functionality (AF) entity outside the 3GPP operator domain, or an untrusted application server (SCS / AS) entity outside the 3GPP operator domain, the second entity may include a network exposure functionality (NEF) entity or a service capability exposure functionality (SCEF) entity.
[0081] In this way, user equipment can communicate with AF entities outside the operator domain through the AP.
[0082] In some embodiments, after the first proxy entity successfully authenticates the user equipment, the user equipment can communicate with the target entity.
[0083] For example, user equipment may communicate directly with the target entity, or it may communicate with the target entity through a first proxy entity, for instance, the first proxy entity forwards communication messages between the user equipment and the target entity.
[0084] In some other embodiments, after the first proxy entity successfully authenticates the user equipment, the user equipment may determine whether the proxy domain name of the first proxy entity is the same as the first domain name of the target entity, and if the proxy domain name is different from the first domain name, it may communicate with the target entity.
[0085] In contrast, if the proxy domain name is the same as the first domain name, a secure session between the user equipment and the proxy entity further determines whether the user equipment and the target entity have second communication rights, and if they do, they can communicate with the target entity.
[0086] The proxy domain name may be the fully qualified domain name (FQDN) corresponding to the first proxy entity, and the first domain name may be the fully qualified domain name (FQDN) corresponding to the target entity. In some scenarios, the first proxy entity and the target entity may use the same FQDN but different IP addresses or port numbers. In such scenarios, the first communication authority may indicate that the user equipment has access to the FQDN, but not necessarily that the user equipment has access to the target entity corresponding to the IP address or port number. In this case, a secure session between the user equipment and the proxy entity can further determine whether the user equipment and the target entity have a second communication authority.
[0087] Figure 4 shows an example authentication method that can be applied to user equipment. As shown in Figure 4, the method may include the following S401 to S405.
[0088] S401, If the user equipment and the target entity have first communication authority, the user equipment performs user equipment authentication through the first proxy entity.
[0089] In S402, after the first proxy entity successfully authenticates the user equipment, the user equipment establishes a secure session with the first proxy entity.
[0090] For example, the secure session may be a TLS (Transport Layer Security) session, which can provide confidentiality and data integrity for communications between the user equipment and the first proxy entity.
[0091] S403, User Equipment obtains the proxy domain name of the first proxy entity and the first domain name of the target entity.
[0092] In some embodiments, the proxy domain name may be a fully qualified domain name (FQDN) corresponding to the first proxy entity, and the first domain name may be a fully qualified domain name (FQDN) corresponding to the target entity.
[0093] S404, if the proxy domain name is the same as the first domain name, the user equipment determines, through a secure session, whether the user equipment and the target entity have second communication authority.
[0094] S405, If it is determined that the user equipment and the target entity have second communication authority, the user equipment communicates with the target entity.
[0095] Similarly, user equipment may communicate directly with the target entity, or it may communicate with the target entity through a first proxy entity, for example, the first proxy entity forwards communication messages between the user equipment and the target entity.
[0096] Thus, through authentication for the first and second communication privileges, if the first proxy entity is the same as the target entity's FQDN, it can be determined that the user equipment has access privileges to the target entity, thereby further enhancing security.
[0097] In some embodiments, the S404 step described above may include the following steps to determine whether the user equipment and target entity have second communication privileges through the secure session.
[0098] First, the user equipment sends a target entity service request message to the first proxy entity via the secure session described above.
[0099] For example, the target entity service request message may include a second target entity identifier, which is a protected entity identifier obtained by the user equipment based on the first target entity identifier, and the target entity service request message instructs the first proxy entity to determine, based on the second target entity identifier, whether the user equipment and the target entity have second communication rights.
[0100] In some embodiments, the second target entity identifier is determined after protecting the first target entity identifier corresponding to the target entity, based on a request for a secure session (e.g., a TLS session).
[0101] In some other embodiments, the first target entity identifier can be directly used as the second target entity identifier, and the second target entity identifier can be transmitted via a secure session to provide protection for the first target entity identifier, thereby preventing the entity identifier from being tampered with during transmission.
[0102] Subsequently, in response to receiving the target entity service response message sent from the first proxy entity, the user equipment determines whether the user equipment and the target entity have second communication authority.
[0103] In some embodiments, when user equipment receives the target entity service response message, it may determine that user equipment and the target entity have second communication authority.
[0104] Conversely, if the user equipment does not receive the target entity service response message within a predetermined time, it can be determined that the user equipment and the target entity do not have second communication rights.
[0105] In some other embodiments, the user equipment may determine that the user equipment and the target entity have second communication rights if the user equipment receives a target entity service response message and the target entity service response message contains success indication information.
[0106] Conversely, if the target entity service response message received by the user equipment does not contain success instruction information, or if it contains failure instruction information, it can be determined that the user equipment and the target entity do not have second communication authority. The success instruction information may be any instruction information that has been set in advance.
[0107] In some other embodiments, if the user equipment receives a target entity service response message and the target entity service response message does not contain failure instruction information, the user equipment and the target entity may determine that they have second communication authority.
[0108] In contrast, if the target entity service response message received by the user equipment contains failure instruction information, it can be determined that the user equipment and the target entity do not have second communication authority. The failure instruction information may be any pre-configured error code.
[0109] In this way, the user equipment can determine whether the user equipment and the target entity have secondary communication privileges through a secure session.
[0110] In some embodiments, the second communication authority described above may include one or more of the following authority: Permission 6: User Equipment has access rights to the target entity. Authority 7: The first proxy entity has proxy authority over the target entity. Permission 8: The target entity has permission to retrieve the subscriber identifier of the user equipment.
[0111] In this way, a secure session between the user equipment and the first proxy entity allows for the determination of whether the user equipment and the target entity have second communication authority, further improving the reliability of authentication.
[0112] Figure 5 shows an authentication method in an exemplary embodiment, which is applicable to the first proxy entity in the above communication system. As shown in Figure 5, the method may include steps S501 to S503.
[0113] S501, the first proxy entity receives an application session establishment request message sent from the user equipment.
[0114] Here, the application session establishment request message includes a first authorization request parameter, which instructs the first proxy entity to determine, based on the first authorization request parameter, whether the user equipment and the target entity have first communication authorization, the target entity being an entity requesting communication, determined by the user equipment from one or more first entities, the first entity may include entities that provide application functionality, and the first proxy entity may include trusted entities that provide authentication functionality within the 3GPP operator domain, the first proxy entity providing authentication proxy functionality to the first entity, the first entity may include one or more.
[0115] S502, The first proxy entity determines, based on the first authorization request parameters, whether the user equipment and the target entity have the first communication authorization.
[0116] In this way, a trusted first proxy entity within the 3GPP operator domain can determine whether the user equipment and the first entity have first communication authority, perform identity verification of the user equipment if they have first communication authority, and enable some of the first entity's functions to be implemented by the first proxy entity. As a result, the load on the first entity is reduced and its efficiency is improved. Furthermore, the user equipment can achieve authorization authentication for one or more first entities and user equipment authentication through a unified first proxy entity, reducing the complexity of authentication by the user equipment and improving the efficiency of the user equipment.
[0117] In some embodiments, the first proxy entity can determine whether the user equipment and target entity have first communication privileges through message exchange with the third entity. For example, this may include the following steps:
[0118] First, the first proxy entity determines the second authorization request parameter based on the first authorization request parameter.
[0119] In some embodiments, the first authorization request parameter and the proxy entity identifier corresponding to the first proxy entity may be the second authorization request parameter. For example, if the first authorization request parameter includes the first target entity identifier of the target entity and the key identifier (A-KID) corresponding to the user equipment, the second authorization request parameter may include the first target entity identifier, the key identifier (A-KID), and the proxy entity identifier corresponding to the first proxy entity.
[0120] In some other embodiments, the first authorization request parameter can be a second authorization request parameter.
[0121] Here, the first proxy entity sends the second authorization request parameter to the third entity.
[0122] Exemplary, the third entity may include an entity that provides AKMA authorization and application key derivation functionality. The second authorization request parameter is used to instruct the third entity to determine whether the user equipment and target entity have first communication authority.
[0123] Next, the first proxy entity retrieves the first pending key information sent from the third entity.
[0124] The first pending key information is key information obtained by the third entity based on the second authorization request parameter.
[0125] In some embodiments, the first pending key information is the application key K corresponding to the target entity. AF It may include.
[0126] In some other embodiments, the first pending key information is the application key K corresponding to the target entity. AF and key validity time K AF The expiration time may be included.
[0127] In some embodiments, a first proxy entity may send a second authorization request parameter to a third entity through a first key request message, which is used to instruct the third entity to obtain first pending key information and a user equipment subscriber identifier, and the first proxy entity may further receive a first key response message sent from the third entity and obtain first pending key information contained in the first key response message.
[0128] Furthermore, the first key response message may further include a second subscriber identifier corresponding to the user equipment, and the first proxy entity can obtain the second subscriber identifier based on the received first key response message. The second subscriber identifier may include a Subscription Permanent Identifier (SUPI) corresponding to the user equipment.
[0129] In some embodiments, the first proxy entity can send the second permission request parameter to the third entity through the second key request message, and the second key request message indicates that the first proxy entity requests to obtain the first pending key information. The first proxy entity can further receive the second key response message sent from the third entity and obtain the first pending key information included in the second key response message. Finally, the first proxy entity determines whether the user equipment and the target entity have the first communication permission based on the first pending key information.
[0130] Exemplarily, when the first pending key information includes the application key K corresponding to the target entity AF it can be determined that the user equipment and the target entity have the first communication permission. In contrast, when the first pending key information does not include the application key K corresponding to the target entity AF or when the first pending key information does not include the valid application key K AF or when the first pending key information is not received within the preset time, it can be determined that the user equipment and the target entity do not have the first communication permission.
[0131] In this way, the first proxy entity can determine whether the user equipment and the target entity have the first communication permission by interacting with the third entity.
[0132] In some other embodiments, when the user equipment communication permission policy is stored in the first proxy entity, it can be directly determined whether the user equipment and the target entity have the first communication permission based on the first permission request parameter.
[0133] S503. If the user equipment and the target entity have first communication authority, the first proxy entity sends an application session establishment response message to the user equipment and performs user equipment authentication on the user equipment.
[0134] In some embodiments, the first proxy entity may indicate that the user equipment and target entity have first communication privileges by sending the application session establishment response message, or by not sending the application session establishment response message, that the user equipment and target entity do not have first communication privileges.
[0135] In some other embodiments, the first proxy entity may include success instruction information in the application session establishment response message, which indicates that the user equipment and target entity have first communication rights, while the application session establishment response message may not include success instruction information, which indicates that the user equipment and target entity do not have first communication rights. Here, the success instruction information may be any pre-configured instruction information.
[0136] In some other embodiments, if the user equipment and target entity do not have first communication privileges, the first proxy entity may indicate that the instructing user equipment and target entity do not have first communication privileges by including failure instruction information in the application session establishment response message; conversely, if the user equipment and target entity do have first communication privileges, the first proxy entity may indicate that the user equipment and target entity have first communication privileges by not including failure instruction information in the application session establishment response message.
[0137] By using the above method, authentication of communication rights between user equipment and the first entity can be achieved based on the first proxy entity, thereby reducing the problem of excessive load caused by authorization authentication by the first entity.
[0138] In some embodiments, the first communication authority described above may include one or more of the following authorities: Permission 1: User Equipment has access rights to the target entity. Permission 2: User Equipment has access rights to the first proxy entity. Authority 3: The first proxy entity has proxy authority over the target entity. Permission 4: The target entity has permission to retrieve the subscriber identifier of the user equipment.
[0139] In some embodiments, the first proxy entity may include a trusted authenticated proxy (AP) entity within a 3GPP operator domain.
[0140] In some embodiments, the first entity may include a trusted application function (AF) entity within the 3GPP operator domain, or a trusted application server (SCS / AS) entity within the 3GPP operator domain, or an untrusted application function (AF) entity outside the 3GPP operator domain, or an untrusted application server (SCS / AS) entity outside the 3GPP operator domain.
[0141] In some embodiments, the second entity may include a network exposure function (NEF) entity or a service capability exposure function (SCEF) entity.
[0142] In some embodiments, the third entity may include an AKMA anchor function (AAnF) entity.
[0143] In some embodiments, if the first proxy entity successfully authenticates the user equipment, the first proxy entity can notify the target entity of the first authentication result of the user equipment authentication. Here, the first authentication result indicates that the target entity and the user equipment have the authority to communicate.
[0144] For example, if the target entity is a trusted entity that provides application functionality within a 3GPP operator domain, the first proxy entity may send a first notification message to the target entity, which may include a first authentication result. Furthermore, if the first proxy entity obtains a second subscriber identifier for user equipment (for example, by obtaining a second subscriber identifier through a first key response message), the first notification message may further include the second subscriber identifier.
[0145] Furthermore, for example, if the target entity is an untrusted entity providing application functionality outside the 3GPP operator domain, the first proxy entity may instruct the second entity to send the first authentication result to the target entity by sending a second notification message to the second entity based on the first authentication result. Similarly, if the first proxy entity obtains a second subscriber identifier for user equipment (for example, by obtaining the second subscriber identifier through the first key response message), the second notification message may further include the second subscriber identifier.
[0146] Furthermore, the authentication result notification message may further include a first subscriber identifier corresponding to the user equipment. For example, if the first key response message includes a first subscriber identifier corresponding to the user equipment, the first proxy entity may transmit the first subscriber identifier to the target entity through the authentication result notification message.
[0147] The first subscriber identifier may be any identifier representing user equipment, for example, a general-purpose public subscription identifier (GPSI) corresponding to user equipment.
[0148] In this way, the first proxy entity can verify the communication rights between the user equipment and the first entity, and if the user equipment and the first entity have the right to communicate, it instructs the user equipment to communicate with the first entity.
[0149] In some other embodiments, if the first proxy entity successfully authenticates the user equipment, the first proxy entity can obtain the proxy domain name of the first proxy entity and the first domain name of the target entity. If the proxy domain name is different from the first domain name, the first proxy entity notifies the target entity of the authentication result, indicating that it has permission to communicate with the user equipment or instructing the target entity to communicate with the user equipment.
[0150] In contrast, if the proxy domain name is the same as the first domain name, the first proxy entity will not temporarily notify the target entity of the first authentication result. It will wait to determine whether the user equipment and the target entity have second communication authority, and only after it is determined that the user equipment and the target entity have second communication authority will it notify the target entity of the second authentication result.
[0151] For example, the first proxy entity can determine whether the user equipment and the target entity have a second communication authority based on the target entity service request message sent from the user equipment.
[0152] The proxy domain name may be the fully qualified domain name (FQDN) corresponding to the first proxy entity, and the first domain name may be the fully qualified domain name (FQDN) corresponding to the target entity. In some scenarios, the first proxy entity and the target entity may use the same FQDN but different IP addresses or port numbers. In such scenarios, the first communication authority may indicate that the user equipment has access to the FQDN, but not necessarily that the user equipment has access to the target entity corresponding to the IP address or port number. In this case, a secure session between the user equipment and the proxy entity can further determine whether the user equipment and the target entity have a second communication authority.
[0153] Figure 6 shows an authentication method in an exemplary embodiment, which is applicable to a first proxy entity. As shown in Figure 6, the method may include the following S601 to S604.
[0154] S601, after successful user equipment authentication for the user equipment, the first proxy entity establishes a secure session with the user equipment.
[0155] For example, the secure session may be a TLS (Transport Layer Security) session, which can provide confidentiality and data integrity for communications between the first proxy entity and the user equipment.
[0156] S602, the first proxy entity receives a target entity service request message sent from the user equipment via a secure session.
[0157] The target entity service request message includes a second target entity identifier, which is a protected entity identifier obtained by the user equipment based on the target entity's first target entity identifier, and the target entity service request message is a message sent when the user equipment determines that the proxy domain name of the first proxy entity and the first domain name of the target entity are the same.
[0158] S603, The first proxy entity determines, based on the second target entity identifier, whether the user equipment and the target entity have second communication authority.
[0159] In some embodiments, if the second target entity identifier is the same as the first target entity identifier, it can be determined that the user equipment and the target entity have second communication rights.
[0160] In some other embodiments, if the second target entity identifier is different from the first target entity identifier, the first proxy entity can determine whether the user equipment and the target entity have second communication rights by exchanging messages with the third entity.
[0161] S604, the first proxy entity sends a target entity service response message to the user equipment.
[0162] The target entity service response message indicates whether the user equipment and the target entity have second communication authority.
[0163] In some embodiments, the first proxy entity may indicate that the user equipment and the target entity have second communication rights by sending the target entity service response message, or indicate that the user equipment and the target entity do not have second communication rights by not sending the target entity service response message.
[0164] In some other embodiments, the first proxy entity may include success instruction information in the application session establishment response message, which indicates that the user equipment and target entity have second communication rights, while the application session establishment response message may not include success instruction information, which indicates that the user equipment and target entity do not have second communication rights. Here, the success instruction information may be any pre-configured instruction information.
[0165] In some other embodiments, if the user equipment and target entity do not have second communication rights, the first proxy entity can indicate that the user equipment and target entity do not have second communication rights by including failure instruction information in the target entity service response message. Conversely, if the user equipment and target entity do have second communication rights, the first proxy entity can indicate that the user equipment and target entity do have second communication rights by including failure instruction information in the target entity service response message. The failure instruction information may be any pre-configured error code.
[0166] In this way, the first proxy entity can determine whether the user equipment and the target entity have second communication authority through a secure session, and can send the authority authentication result to the target device.
[0167] In some other embodiments, the first proxy entity can determine whether the user equipment and target entity have second communication rights by exchanging messages with the third entity.
[0168] Figure 7 shows an authentication method in an exemplary embodiment, which is applicable to a first proxy entity. As shown in Figure 7, if the second target entity identifier is different from the first target entity identifier, the first proxy entity can determine based on this method whether the user equipment and the target entity have second communication rights, and this method may include the following S701 to S704.
[0169] S701, The first proxy entity determines the third authorization request parameters based on the second target entity identifier.
[0170] S702, the first proxy entity sends the third authorization request parameter to the third entity.
[0171] S703, the first proxy entity retrieves the authorization result parameters sent from the third entity.
[0172] S704, The first proxy entity determines, based on the authorization result parameters, whether the user equipment and the target entity have second communication authority.
[0173] By this method, if the second target entity identifier is different from the first target entity identifier, the first proxy entity can determine, through message exchange with the third entity, whether the user equipment and the target entity have second communication authority.
[0174] Here, the third authorization request parameter instructs the third entity to determine whether the user equipment and target entity have second communication authorization. The authorization result parameter may be used to indicate whether the user equipment and target entity have second communication authorization. Exemplaryly, the third authorization request parameter may include a key identifier (A-KID), a second target entity identifier, and a proxy entity identifier corresponding to the first proxy entity, and the third authorization request parameter may be used to determine whether the third entity user equipment and target entity have second communication authorization.
[0175] In some embodiments, the first proxy entity may send third authorization request parameters to the third entity through a third key request message instructing the third entity to retrieve authorization result parameters and a user equipment subscriber identifier. The first proxy entity may receive a third key response message sent from the third entity and retrieve the authorization result parameters contained in the third key response message.
[0176] Furthermore, the third key response message may further include a second subscriber identifier corresponding to the user equipment, and the first proxy entity may also obtain the second subscriber identifier based on the received third key response message. The second subscriber identifier may include a Subscription Permanent Identifier (SUPI) corresponding to the user equipment.
[0177] In some embodiments, the third key request message may include authorization instruction parameters. These authorization instruction parameters may be used to instruct a third entity to determine, based on the third key request message, whether the user equipment and target entity have second communication authority. Similarly, the third key response message may include authorization instruction parameters to indicate that the third key response message is a response to the third key request message.
[0178] In some other embodiments, the first proxy entity may send third authorization request parameters to the third entity through a fourth key request message indicating that the first proxy entity is requesting the acquisition of authorization result parameters. The first proxy entity may then receive a fourth key response message sent from the third entity and acquire the authorization result parameters contained in the fourth key response message.
[0179] In some embodiments, the fourth key request message further includes authorization instruction parameters, which are used to instruct the third entity to determine, based on the fourth key request message, whether the user equipment and the target entity have second communication authority. Similarly, the fourth key response message may include authorization instruction parameters to indicate that the fourth key response message is a response corresponding to the fourth key request message.
[0180] In some embodiments, the authorization result parameter can indicate authorization success or authorization failure. Based on the authorization result parameter, the first proxy entity determines whether the user equipment and target entity have second communication rights. Exemplaryly, if the authorization result parameter indicates authorization success, it can be determined that the user equipment and target entity have second communication rights; on the other hand, if the authorization result parameter indicates authorization failure, or if the key response message (e.g., third key response message or fourth key response message) does not include the authorization result parameter, it can be determined that the user equipment and target entity do not have second communication rights.
[0181] In some embodiments, the second communication authority described above may include one or more of the following authority: Permission 6: User Equipment has access rights to the target entity. Authority 7: The first proxy entity has proxy authority over the target entity. Permission 8: The target entity has permission to retrieve the subscriber identifier of the user equipment.
[0182] In this way, a secure session between the user equipment and the first proxy entity allows for the determination of whether the user equipment and the target entity have second communication authority, further improving the reliability of authentication.
[0183] In some embodiments, if it is determined that the user equipment and the target entity have second communication authority based on the authorization result parameters, the first proxy entity can notify the target entity of the second authentication result.
[0184] Here, the second authentication result is used to indicate that the target entity and the user equipment have the authority to communicate.
[0185] For example, if the target entity is a trusted entity providing application functionality within a 3GPP operator domain, the first proxy entity may send a third notification message to the target entity containing the second authentication result. Furthermore, if the first proxy entity obtains a second subscriber identifier for the user equipment (for example, by obtaining the second subscriber identifier through a third key response message), the third notification message may further include the second subscriber identifier.
[0186] Furthermore, for example, if the target entity is an untrusted entity providing application functionality outside the 3GPP operator domain, the first proxy entity may instruct the second entity to send the first authentication result to the target entity by sending a fourth notification message to the second entity based on the first authentication result. Additionally, if the first proxy entity obtains the second subscriber identifier of the user equipment (for example, by obtaining the second subscriber identifier through the third key response message), the fourth notification message may include the second subscriber identifier.
[0187] In this way, the first proxy entity can verify the second communication authority between the user equipment and the first entity through a secure session, further improving the reliability of authentication, and if the user equipment and the first entity have the second communication authority, it instructs the user equipment to communicate with the first entity.
[0188] Figure 8 shows an authentication method illustrated in an exemplary embodiment, which is applicable to a third entity. As shown in Figure 8, the method may include the following S801 to S804.
[0189] S801, the third entity receives the second authorization request parameter sent from the first proxy entity.
[0190] The second authorization request parameter instructs the third entity to determine whether the user equipment and the target entity have first communication authorization, the target entity being the entity requesting communication, determined by the user equipment from one or more first entities, the first entities including entities that provide application functionality, the first proxy entity including trusted entities that provide authentication functionality within the 3GPP operator domain, the first proxy entity providing authentication proxy functionality to the first entity, and the third entity including entities that provide AKMA authorization and application key derivation functionality.
[0191] S802, the third entity determines, based on the second authorization request parameter, whether the user equipment and the target entity have the first communication authorization.
[0192] In some embodiments, the second authorization request parameter may include a proxy entity identifier corresponding to the first proxy entity. After receiving the second authorization request parameter, the third entity can determine, based on a first preconfigured policy, whether or not it has the authority to provide services to the first proxy entity. The first preconfigured policy may include preconfigured parameters.
[0193] If it is determined that the third entity has the authority to provide services to the first proxy entity, then, based on the second authority request parameter, it is determined whether the user equipment and the target entity have the first communication authority.
[0194] In contrast, if it is determined that the third entity does not have the authority to provide services to the first proxy entity, the process is terminated and no further checks are performed to determine whether the user equipment and target entity have the authority to communicate with the first entity. At this point, the third entity may send a failure instruction to the first proxy entity to cause it to perform the corresponding failure processing, or the third entity may stop processing directly and not send any messages.
[0195] In some embodiments, the second authorization request parameter includes a key identifier (A-KID) corresponding to the user equipment, a first target entity identifier for the target entity, and a proxy entity identifier corresponding to the first proxy entity. In this step, the method for determining whether the user equipment and the target entity have first communication authorization includes one or more of the following methods. Method 1: Determine whether the user equipment has access rights to the target entity based on the key identifier (A-KID) and the first target entity identifier. Method 2 determines whether the user equipment has access rights to the first proxy entity based on the key identifier (A-KID) and the proxy entity identifier. Method 3: Based on the proxy entity identifier and the first target entity identifier, it is determined whether the first proxy entity has proxy authority over the target entity. Method 4: Based on the key identifier (A-KID) and the first target entity identifier, it is determined whether the target entity has the right to retrieve the user equipment subscriber identifier. Method 5: Determine whether the user equipment has the authority to use AKMA based on the key identifier (A-KID).
[0196] In some embodiments, the third entity may determine that the user equipment and the target entity have first communication rights if the user equipment has access rights to both the first proxy entity and the target entity, and the first proxy entity has proxy rights over the target entity.
[0197] In some other embodiments, the third entity may determine that the user equipment and the target entities have first communication rights if it is determined that the user equipment has access rights to both target entities and the first proxy entity has proxy rights to the target entities.
[0198] S803, the third entity obtains the first pending key information if the user equipment and the target entity have the first communication authority.
[0199] For example, the first pending key information can be obtained based on the entity key information corresponding to the target entity.
[0200] In some embodiments, the entity key information corresponding to the target entity is the application key K corresponding to the target entity. AF It may include.
[0201] In some other embodiments, the entity key information corresponding to the target entity is the application key K corresponding to the target entity. AF and key validity time K AF The expiration time may be included.
[0202] S804, the third entity sends the first pending key information to the first proxy entity.
[0203] This allows the first proxy entity to determine, based on the first pending key information, whether the user equipment and target entity have the first communication authority.
[0204] In some embodiments, a third entity may receive a second authorization request parameter sent from a first proxy entity through a first key request message, which is used to instruct the third entity to retrieve the first pending key information and the user equipment subscriber identifier. The third entity may further send the first pending key information to the first proxy entity through a first key response message.
[0205] Furthermore, if the third entity determines that the target entity has the authority to obtain the subscriber identifier, it may also send the first pending key information and the second subscriber identifier corresponding to the user equipment to the first proxy entity via a first key response message.
[0206] For example, if the third entity determines that the target entity has the authority to retrieve a subscriber identifier, it sends the first pending key information and the second subscriber identifier corresponding to the user equipment to the first proxy entity via a third key response message. For instance, it retrieves the second subscriber identifier corresponding to the user equipment and then sends the second subscriber identifier and authorization result parameters to the first proxy entity via a third key response message.
[0207] In some embodiments, the second subscriber identifier may be an identifier representing the user equipment within the 3GPP operator domain. Exemplarily, the second subscriber identifier may be a subscription persistence identifier (SUPI) corresponding to the user equipment.
[0208] In some other embodiments, a third entity may receive a second authorization request parameter sent from a first proxy entity via a second key request message. The second key request message instructs the third entity to retrieve the first pending key information. The third entity may further send the first pending key information to the first proxy entity via a second key response message.
[0209] In this way, the third entity can determine whether the user equipment and the target entity have the first communication authority and notify the first proxy entity of this using the first pending key information.
[0210] In some embodiments, the first proxy entity may include a trusted authenticated proxy (AP) entity within a 3GPP operator domain.
[0211] In some embodiments, the first entity may include a trusted application function (AF) entity within the 3GPP operator domain, or a trusted application server (SCS / AS) entity within the 3GPP operator domain, or an untrusted application function (AF) entity outside the 3GPP operator domain, or an untrusted application server (SCS / AS) entity outside the 3GPP operator domain.
[0212] In some embodiments, the third entity may include an AKMA anchor function (AAnF) entity.
[0213] Figure 9 shows an authentication method illustrated in an exemplary embodiment, which is applicable to a third entity. As shown in Figure 9, after sending a third key response message to the second entity, the method may further include the following S901-S903.
[0214] S901, The third entity receives the third authorization request parameters sent from the first proxy entity.
[0215] S902, the third entity determines whether the user equipment and target entity have second communication authority based on the third authority request parameter.
[0216] S903, the third entity sends authorization result parameters to the first proxy entity.
[0217] The authorization result parameter may be used to inform the first proxy entity whether the user equipment and target entity have second communication authority.
[0218] In some embodiments, the third authorization request parameter may include a proxy entity identifier corresponding to the first proxy entity. After receiving the fourth key request message, the third entity can determine, based on a first preconfigured policy, whether or not it has the authority to provide services to the first proxy entity. The first preconfigured policy may include preconfigured parameters.
[0219] If it is determined that the third entity has the authority to provide services to the first proxy entity, then, based on the fourth key request message, it is determined whether the user equipment and the target entity have the second communication authority.
[0220] In contrast, if the third entity does not have the authority to provide services to the first proxy entity, it may terminate the process and not further check whether the user equipment and target entity have the authority to communicate with the first entity. In this case, the third entity may send a failure instruction to the second entity, which will then perform the corresponding failure processing. Alternatively, the third entity may stop processing directly and not send any messages.
[0221] In some embodiments, the third authorization request parameter may include a key identifier (A-KID), a second target entity identifier, and a proxy entity identifier corresponding to the first proxy entity, the second target entity identifier being a protected entity identifier obtained by the user equipment based on the first target entity identifier of the target entity, and the method for determining whether the user equipment and the target entity have second communication authorization in step S902 may include one or more of the following: Method 6 determines whether the user equipment has access rights to the target entity based on the key identifier (A-KID) and the second target entity identifier. Method 7: Based on the proxy entity identifier and the second target entity identifier, it is determined whether the first proxy entity has proxy authority over the target entity. Method 8 determines whether the target entity has the right to retrieve the subscriber identifier of the user equipment, based on the key identifier (A-KID) and the first target entity identifier.
[0222] In some embodiments, the third entity may determine that the user equipment and the target entity have a second communication privilege if it is determined that the user equipment has access privileges to the target entity and the first proxy entity has proxy privileges to the target entity.
[0223] In some embodiments, a third entity may receive third authorization request parameters sent from a first proxy entity via a third key request message, which instructs the third entity to retrieve authorization result parameters and a subscriber identifier for user equipment. The third entity may further send the authorization result parameters to the first proxy entity via a third key response message.
[0224] Furthermore, the third key request message may include authorization instruction parameters, which instruct the third entity to determine, based on the third key request message, whether the user equipment and the target entity have second communication authority. Similarly, the third key response message may include authorization instruction parameters.
[0225] Furthermore, if the third entity determines that the target entity has the authority to obtain the subscriber identifier, it may send the authorization result parameters and the second subscriber identifier corresponding to the user equipment to the first proxy entity via a third key response message.
[0226] For example, if the third entity determines that the target entity has the authority to retrieve the subscriber identifier, it sends the authorization result parameters and the second subscriber identifier corresponding to the user equipment to the first proxy entity via a third key response message. For instance, it retrieves the second subscriber identifier corresponding to the user equipment and sends the second subscriber identifier and the authorization result parameters to the first proxy entity via a third key response message.
[0227] For example, the second subscriber identifier may include a subscription persistence identifier (SUPI) corresponding to user equipment.
[0228] In some other embodiments, the third entity may receive the third authorization request parameters sent from the first proxy entity through a fourth key request message, which instructs the third entity to retrieve the authorization result parameters. The third entity may also send the authorization result parameters to the first proxy entity through a fourth key response message.
[0229] Furthermore, the fourth key request message may further include authorization instruction parameters that instruct the third entity to determine, based on the third key request message, whether the user equipment and the target entity have second communication authority. Similarly, the fourth key response message may include authorization instruction parameters to indicate that the fourth key response message is a response to the fourth key request message.
[0230] In some embodiments, the authorization result parameter indicates authorization success or authorization failure. Exemplaryly, a third entity can determine the possible values of the authorization result parameter based on whether the user equipment and target entity have second communication rights. For example, if the third entity determines that the user equipment and target entity have second communication rights, it can set the authorization result parameter to authorization success (e.g., 1), and if it determines that the user equipment and target entity do not have second communication rights, it can set the possible values of the authorization result parameter to authorization failure (e.g., 0).
[0231] In some other embodiments, the third entity may indicate that the user equipment and target entity do not have second communication rights by not including the authorization result information in the key response message (e.g., the third key response message or the fourth key response message). For example, if the third entity determines that the user equipment and target entity do not have second communication rights, it may not include the authorization result information in the key response message; on the other hand, if it determines that the user equipment and target entity do have second communication rights, it may include the authorization result information in the key response message.
[0232] Figure 10 shows an authentication method illustrated in an exemplary embodiment, which is applicable to a first entity. As shown in Figure 10, the method may further include the following S1001 to S1002.
[0233] S1001, the first entity obtains the authentication result of the user equipment from the first proxy entity.
[0234] S1002, the first entity, communicates with the user equipment based on the authentication result.
[0235] The authentication result includes either a first or second authentication result, the first indicating that the user equipment and the target entity have first communication authority, and the second indicating that the user equipment and the target entity have second communication authority, the target entity being an entity requesting communication, determined by the user equipment from one or more first entities, the first entities including entities that provide application functionality, the first proxy entity including trusted entities that provide authentication functionality within the 3GPP operator domain, and the first proxy entity providing authentication proxy functionality to the first entities.
[0236] The first entity may wait for the user equipment to initiate communication. The first entity may also initiate communication with the user equipment on its own initiative, and this disclosure is not limited thereto.
[0237] In some embodiments, the authentication result notification message includes a first subscriber identifier for the user equipment. This first subscriber identifier may be an identifier representing the user equipment outside the 3GPP operator domain. Exemplarily, the first subscriber identifier is the generic public subscription identifier (GPSI) corresponding to the user equipment.
[0238] If the target entity is a trusted entity that provides application functionality within a 3GPP operator domain, the target entity may receive a first notification message containing a first authentication result sent from the first proxy entity, or a third notification message containing a second authentication result sent from the first proxy entity.
[0239] Furthermore, the first or third notification message may further include a second subscriber identifier corresponding to the user equipment. The second subscriber identifier may include a subscription persistent identifier (SUPI) corresponding to the user equipment.
[0240] If the target entity is an untrusted entity providing application functionality outside the 3GPP operator domain, the target entity may receive a fifth notification message sent by the second entity, where the fifth notification message includes the first authentication result and is sent by the second entity in response to the receipt of the second notification message, or the target entity may receive a sixth notification message sent by the second entity, where the sixth notification message includes the second authentication result and is sent by the second entity in response to the receipt of the fourth notification message.
[0241] Furthermore, the fifth or sixth notification message further includes a first subscriber identifier for the user equipment. The first subscriber identifier may be a general-purpose public subscription identifier (GPSI) corresponding to the user equipment.
[0242] In some embodiments, the first proxy entity may include a trusted authenticated proxy (AP) entity within a 3GPP operator domain.
[0243] In some embodiments, the first entity may include a trusted application function (AF) entity within the 3GPP operator domain, or a trusted application server (SCS / AS) entity within the 3GPP operator domain, or an untrusted application function (AF) entity outside the 3GPP operator domain, or an untrusted application server (SCS / AS) entity outside the 3GPP operator domain.
[0244] In some embodiments, the second entity may include a network exposure function (NEF) entity or a service capability exposure function (SCEF) entity.
[0245] In this way, the first entity can determine whether the user equipment and the first entity have the right to communicate with the first entity based on the authentication result notification message from the first proxy entity, thereby reducing the load on the first entity and improving its efficiency.
[0246] Figure 11 shows an authentication method as an exemplary embodiment, which is applicable to a second entity. As shown in Figure 11, the method may include the following S1101 to S1102.
[0247] S1101, the second entity obtains the authentication result of the user equipment from the first proxy entity.
[0248] The authentication result includes either a first or second authentication result, the first indicating that the user equipment and the target entity have first communication authority, the second indicating that the user equipment and the target entity have second communication authority, the target entity is an entity requesting communication, determined by the user equipment from one or more first entities, the first entities include untrusted entities providing application functionality outside the 3GPP operator domain, the first proxy entity includes trusted entities providing authentication functionality within the 3GPP operator domain, and the first proxy entity provides authentication proxy functionality to the first entity.
[0249] S1102, the second entity sends the authentication result to the target entity.
[0250] This allows the target entity to communicate with the user equipment based on the authentication result.
[0251] Using the above method, communication between a first proxy entity within the 3GPP operator domain and a first entity outside the 3GPP operator domain can be realized through the second entity.
[0252] In some embodiments, the second entity may include a Network Exposure Function (NEF) entity or a Service Capability Exposure Function (SCEF) entity, the first proxy entity may include a Trusted Authentication Proxy (AP) entity within the 3GPP operator domain, and the first entity may include an Untrusted Application Function (AF) entity outside the 3GPP operator domain, or an Untrusted Application Server (SCS / AS) entity outside the 3GPP operator domain.
[0253] In some embodiments, the second entity can receive a second notification message sent from the first proxy entity, obtain a first authentication result based on the second notification message, and send a fifth notification message to the first entity based on the first authentication result. Here, the second notification message is a message sent by the first proxy entity to the second entity based on the first authentication result when the target entity is an untrusted entity providing an application function outside the 3GPP operator domain.
[0254] Furthermore, when a second subscriber identifier corresponding to a user equipment improvement is included in the second notification message, the second entity can obtain a first subscriber identifier corresponding to the user equipment improvement based on the second subscriber identifier, and send a fifth notification message to the first entity based on the first authentication result and the first subscriber identifier.
[0255] In some other embodiments, the second entity may receive a fourth notification message sent from the first proxy entity, obtain a second authentication result based on the second notification message, and send a sixth notification message to the first entity based on the second authentication result. Here, the fourth notification message may be a message sent by the first proxy entity to the second entity based on the second authentication result if the target entity is an untrusted entity providing application functionality outside the 3GPP operator domain.
[0256] Furthermore, if the fourth notification message includes a second subscriber identifier corresponding to the user equipment, the second entity can obtain the first subscriber identifier corresponding to the user equipment based on the second subscriber identifier, and then send a sixth notification message to the first entity based on the second authentication result and the first subscriber identifier.
[0257] In some embodiments, the second subscriber identifier may be an identifier representing the user equipment within the 3GPP operator domain, and the first subscriber identifier may be an identifier representing the user equipment outside the 3GPP operator domain. Exemplarily, the second subscriber identifier may be a Subscription Permanent Identifier (SUPI) corresponding to the user equipment, and the first subscriber identifier may be a Generic Public Subscription Identifier (GPSI) corresponding to the user equipment.
[0258] The second entity can determine the first subscriber identifier corresponding to the second subscriber identifier based on a pre-configured correspondence of identifiers, and the pre-configured correspondence of identifiers may include the correspondence between the second subscriber identifier and the first subscriber identifier.
[0259] Figure 12 shows an example of an authentication method, which may include the following steps S1201 to S1213, as shown in Figure 12.
[0260] S1201, User Equipment sends an Application Session Establishment Request message to the First Proxy Entity.
[0261] For example, the application session establishment request message may include a first authorization request parameter, which may include a key identifier (A-KID) of the user equipment and a first target entity identifier (Target AF ID) of the target entity. The target entity may be an entity requesting communication, determined by the user equipment from one or more first entities.
[0262] In some embodiments, user equipment can obtain a key identifier (A-KID) based on a pre-configured functional entity within the communication system, which may include an Authentication Server Function (AUSF) entity.
[0263] S1202, the first proxy entity sends the second authorization request parameter to the third entity in response to receiving the application session establishment request message.
[0264] In some embodiments, a first proxy entity can receive an application session establishment request message sent from user equipment and determine a second authorization request parameter based on a first authorization request parameter in the application session establishment request message.
[0265] For example, if the first authorization request parameter includes the key identifier (A-KID) of the user equipment and the first target entity identifier (Target AF ID) of the target entity, then it can be determined that the second authorization request parameter includes the key identifier (A-KID), the first target entity identifier (Target AF ID), and the proxy entity identifier of the first proxy entity.
[0266] In some embodiments, a first proxy entity may send a second authorization request parameter to a third entity through a first key request message, which instructs the third entity to retrieve the first pending key information and the user equipment subscriber identifier. Exemplarily, the first key request message may be a Naanf_AKMA_ApplicationKey_Get Request message.
[0267] In some other embodiments, the first proxy entity may send a second authorization request parameter to the third entity through a second key request message, the second key request message indicating that the first proxy entity is requesting the retrieval of first pending key information. Exemplarily, the second key request message may be a Naanf_AKMA_ApplicationKey_AnonUser_Get Request message.
[0268] S1203, The third entity retrieves the first pending key information if it determines, based on the second authorization request parameters, that the user equipment and the target entity have the first communication authorization.
[0269] The third entity can determine whether the user equipment and the target entity have the first communication rights by authenticating the communication rights of the user equipment and the target entity based on a pre-configured permission policy. For example, In some embodiments, the method by which the third entity determines whether the user equipment and the target entity have first communication rights includes one or more of the following methods: Method 1: Determine whether the user equipment has access rights to the target entity based on the key identifier (A-KID) and the first target entity identifier. Method 2 determines whether the user equipment has access rights to the first proxy entity based on the key identifier (A-KID) and the proxy entity identifier. Method 3: Based on the proxy entity identifier and the first target entity identifier, it is determined whether the first proxy entity has proxy authority over the target entity. Method 4: Based on the key identifier (A-KID) and the first target entity identifier, it is determined whether the target entity has the right to retrieve the user equipment subscriber identifier. Method 5: Determine whether the user equipment has the authority to use AKMA based on the key identifier (A-KID).
[0270] In some other embodiments, when the user equipment has access rights to both the target entity and the first proxy entity has proxy rights to the target entity, the third entity can determine that the user equipment and the target entity have the first communication right. Exemplarily, the third entity can determine whether the user equipment and the target entity have the first communication right through the following steps S11 to S13.
[0271] S11. Determine whether the first proxy entity has proxy rights to the target entity based on the proxy entity identifier and the first target entity identifier.
[0272] If it is determined that the first proxy entity does not have proxy rights to the target entity, directly determine that the user equipment and the target entity do not have the first communication right, and do not execute step S12. In contrast, if it is determined that the first proxy entity has proxy rights to the target entity, continue to execute step S12.
[0273] S12. Determine whether the user equipment has access rights to the target entity based on the key identifier (A-KID) and the first target entity identifier.
[0274] If it is determined that the user equipment does not have access rights to the target entity, directly determine that the user equipment and the target entity do not have the first communication right, and do not execute step S13. In contrast, if it is determined that the user equipment has access rights to the target entity, continue to execute step S13.
[0275] S13. Based on the key identifier (A-KID), it is determined whether the user equipment has the authority to use AKMA.
[0276] If it is determined that the user equipment has the authority to use AKMA, then it can be determined that the user equipment and the target entity have primary communication authority. Conversely, if it is determined that the user equipment does not have the authority to use AKMA, then it can be determined that the user equipment and the target entity do not have primary communication authority.
[0277] The first pending key information may also include entity key information corresponding to the target entity.
[0278] In some embodiments, the entity key information corresponding to the target entity is the application key K corresponding to the target entity. AF It may include.
[0279] In some other embodiments, the entity key information corresponding to the target entity is the application key K corresponding to the target entity. AF and key validity time K AF The expiration time may be included.
[0280] S1204, the third entity transmits the first pending key information to the first proxy entity.
[0281] In some embodiments, a third entity may send first pending key information to a first proxy entity through a first key response message. Exemplarily, the first key response message may be a Naanf_AKMA_ApplicationKey_Get Response message.
[0282] In some other embodiments, the third entity may send the first pending key information to the first proxy entity through a second key response message. Exemplarily, the second key response message may be a Naanf_AKMA_ApplicationKey_AnonUser_Get Response message.
[0283] In some embodiments, the first key response message may further include a second subscriber identifier for user equipment, the second subscriber identifier may be an identifier for representing the user equipment within a 3GPP operator domain. Exemplarily, the second subscriber identifier may be a subscription persistence identifier (SUPI) corresponding to the user equipment.
[0284] S1205, the first proxy entity sends an application session establishment response message to the user equipment.
[0285] The first proxy entity receives the application key K in the first key response message. AF If this is obtained, it can be determined that the user equipment and the target entity have first communication authority, and at this time, the first proxy entity can send an application session establishment response message to the user equipment.
[0286] S1206, User Equipment performs User Equipment authentication by the First Proxy Entity.
[0287] User equipment can be authenticated by the first proxy entity if it is determined that the user equipment and the target entity have first communication authority. For example, the user equipment can authenticate the target entity based on the target entity's FQDN. application Key K AFIt is possible to drive the application Key K AF User equipment authentication is performed based on the first proxy entity.
[0288] S1207a, the first proxy entity notifies the target entity of the first authentication result.
[0289] The first authentication result may indicate that the target entity and the user equipment have the right to communicate.
[0290] In some embodiments, if the target entity is a trusted entity providing application functionality within a 3GPP operator domain, the first proxy entity may send a first notification message to the target entity, which may include a first authentication result. Furthermore, if the first proxy entity obtains a second subscriber identifier for user equipment (for example, by obtaining a second subscriber identifier through a first key response message), the first notification message may further include the second subscriber identifier.
[0291] In some other embodiments, if the target entity is an untrusted entity providing application functionality outside the 3GPP operator domain, the first proxy entity may instruct the second entity to send the first authentication result to the target entity by sending a second notification message to the second entity based on the first authentication result. Similarly, if the first proxy entity obtains a second subscriber identifier for user equipment (for example, by obtaining the second subscriber identifier through the first key response message), the second notification message may further include the second subscriber identifier.
[0292] In some embodiments, if the first proxy entity successfully authenticates the user equipment, the first proxy entity can notify the target entity of the first authentication result (by executing step S1207a and not S1207b and subsequent steps).
[0293] In some other embodiments, if the first proxy entity successfully authenticates the user equipment, the first proxy entity obtains the proxy domain name of the first proxy entity and the first domain name of the target entity. If the proxy domain name is different from the first domain name, the first proxy entity can notify the target entity of the first authentication result (by executing step S1207a and not S1209b and subsequent steps) to indicate that the target entity and the user equipment have the authority to communicate or to communicate.
[0294] In some other embodiments, if the proxy domain name is the same as the first domain name, the first proxy entity does not need to temporarily send an authentication result notification message to the target entity. Instead, it first determines whether the user equipment and the target entity have second communication authority, and after determining that the user equipment and the target entity have second communication authority, it notifies the target entity of the first authentication result. In other words, it does not execute step S1207a, but proceeds to execute S1207b and subsequent steps.
[0295] S1207b, User Equipment establishes a secure session with the first proxy entity.
[0296] The secure session may include a TLS session.
[0297] S1208, User Equipment sends a Target Entity Service Request message to the First Proxy Entity.
[0298] Here, the target entity service request message includes a second target entity identifier, which is a protected entity identifier obtained by the user equipment based on the first target entity identifier of the target entity.
[0299] In some embodiments, the target entity service request message may include a key identifier (A-KID) and a second target entity identifier.
[0300] In some embodiments, if the second target entity identifier is the same as the first target entity identifier, it can be determined that the user equipment and the target entity have second communication authority, thereby enabling the sending of an authentication result notification message to the target entity and a target entity service response message to the user equipment. In other words, steps S1209a and S1213 are executed, and steps S1209b to S1212 do not need to be executed.
[0301] In some other embodiments, if the second target entity identifier is different from the first target entity identifier, the first proxy entity can interact with the second entity's key request message to determine whether the user equipment and the target entity have second communication authority. In other words, step S1209a is not performed, and S1209b and subsequent steps are performed instead.
[0302] S1209a, the first proxy entity notifies the target entity of the first authentication result.
[0303] S1209b, the first proxy entity sends the third authorization request parameter to the third entity.
[0304] In some embodiments, the third authorization request parameter may include a key identifier (A-KID), a second target entity identifier, and a proxy entity identifier corresponding to the first proxy entity, and the third authorization request parameter may be used to instruct the third entity to determine whether the user equipment and the target entity have second communication authority.
[0305] In some embodiments, a first proxy entity may send third authorization request parameters to a third entity through a third key request message, which instructs the third entity to retrieve authorization result parameters and a subscriber identifier for user equipment. Exemplaryly, the third key request message may be a Naanf_AKMA_ApplicationKey_Get Request message.
[0306] In some other embodiments, the first proxy entity may send the third authorization request parameters to the third entity through a fourth key request message, the fourth key request message indicating that the first proxy entity is requesting the acquisition of authorization result parameters. Exemplarily, the fourth key request message may be a Naanf_AKMA_ApplicationKey_AnonUser_Get Request message.
[0307] S1210, the third entity determines, based on the third authorization request parameters, whether the user equipment and the target entity have second communication authorization.
[0308] For example, the method by which a third entity determines whether user equipment and target entities have second communication rights may include one or more of the following methods: Method 6 determines whether the user equipment has access rights to the target entity based on the key identifier (A-KID) and the second target entity identifier. Method 7: Based on the proxy entity identifier and the second target entity identifier, it is determined whether the first proxy entity has proxy authority over the target entity. Method 8 determines whether the target entity has the right to retrieve the subscriber identifier of the user equipment, based on the key identifier (A-KID) and the first target entity identifier.
[0309] In some embodiments, the third entity may determine that the user equipment and the target entity have a second communication privilege if it determines that the user equipment has access privileges to the target entity and the first proxy entity has proxy privileges to the target entity.
[0310] S1211, the third entity sends authorization result parameters to the first proxy entity.
[0311] The authorization result parameter may be used to inform the first proxy entity whether the user equipment and target entity have second communication authority.
[0312] In some embodiments, a third entity can send authorization result parameters to a first proxy entity through a third key response message. Exemplarily, the third key response message may be a Naanf_AKMA_ApplicationKey_Get Response message.
[0313] In some other embodiments, the third entity may send authorization result parameters to the first proxy entity through a fourth key response message. Exemplarily, the fourth key response message may be a Naanf_AKMA_ApplicationKey_AnonUser_Get Response message.
[0314] In some embodiments, the third entity may include a second subscriber identifier for the user equipment in the third key response message if it determines that the target entity has the authority to retrieve the subscriber identifier. Similarly, the fourth key response message may include a second subscriber identifier for the user equipment. The second subscriber identifier may be a subscription persistent identifier (SUPI) corresponding to the user equipment.
[0315] S1212, the first proxy entity notifies the target entity of the second authentication result.
[0316] Here, the second authentication result may be used to indicate that the target entity and the user equipment have the authority to communicate.
[0317] For example, if the target entity is a trusted entity providing application functionality within a 3GPP operator domain, the first proxy entity may send a third notification message to the target entity, which includes the second authentication result. Furthermore, if the first proxy entity obtains a second subscriber identifier for the user equipment (for example, by obtaining the second subscriber identifier through a third key response message), the third notification message may further include the second subscriber identifier.
[0318] Furthermore, for example, if the target entity is an untrusted entity providing application functionality outside the 3GPP operator domain, the first proxy entity may send a fourth notification message to the second entity based on the first authentication result, thereby instructing the second entity to send the first authentication result to the target entity. Additionally, if the first proxy entity obtains a second subscriber identifier for the user equipment (for example, by obtaining the second subscriber identifier through a third key response message), the fourth notification message may further include the second subscriber identifier.
[0319] In some embodiments, the second subscriber identifier may be a subscription persistent identifier (SUPI) corresponding to user equipment.
[0320] S1213, the first proxy entity sends a target entity service response message to the user equipment.
[0321] The target entity service response message is used to indicate whether the user equipment and the target entity have second communication authority.
[0322] In some embodiments, the first proxy entity may include a trusted authenticated proxy (AP) entity within a 3GPP operator domain.
[0323] In some embodiments, the first entity may include a trusted application function (AF) entity within the 3GPP operator domain, or a trusted application server (SCS / AS) entity within the 3GPP operator domain, or an untrusted application function (AF) entity outside the 3GPP operator domain, or an untrusted application server (SCS / AS) entity outside the 3GPP operator domain.
[0324] In some embodiments, the second entity may include a network exposure function (NEF) entity or a service capability exposure function (SCEF) entity.
[0325] In some embodiments, the third entity may include an AKMA anchor function (AAnF) entity.
[0326] In this way, a trusted first proxy entity within the 3GPP operator domain determines whether the first entity has the authority to communicate with the user equipment. If it is determined that the first entity has the authority to communicate, the first proxy entity verifies the identity of the user equipment and enables some of the functions of the first entity to be implemented by the first proxy entity. This reduces the load on the first entity and improves its efficiency. Furthermore, the user equipment can achieve authorization authentication for one or more first entities and user equipment authentication through a unified first proxy entity, reducing the complexity of authentication by the user equipment and improving its efficiency.
[0327] Figure 13 is a block diagram of an authentication device 1300 shown in an exemplary embodiment, which is applicable to user equipment. As shown in Figure 13, the device 1300 is A target entity determination module 1301 configured to determine a target entity requesting communication from one or more first entities, A parameter determination module 1302 configured to determine a first authorization request parameter based on the target entity, A first message sending module 1303 configured to send an application session establishment request message to a first proxy entity based on the first authorization request parameter, wherein the application session establishment request message instructs the first proxy entity to determine, based on the first authorization request parameter, whether the user equipment and the target entity have first communication authority, the first entity includes an entity that provides application functionality, the first proxy entity includes a trusted entity that provides authentication functionality within a 3GPP operator domain, and the first proxy entity provides authentication proxy functionality to the first entity, A first message receiving module 1304 is configured to determine whether the user equipment and the target entity have first communication rights in response to receiving an application session establishment response message sent from the first proxy entity, The system may also include an authentication module configured to perform user equipment authentication by the first proxy entity if the user equipment and the target entity have first communication authority.
[0328] The parameter determination module 1302 is optionally configured to use the first target entity identifier of the target entity and the key identifier (A-KID) corresponding to the user equipment as the first authorization request parameters.
[0329] Selectively, the first communication authority is, The user equipment has access rights to the target entity, The user equipment has access rights to the first proxy entity, The first proxy entity has proxy authority over the target entity, This includes one or more of the following: the target entity has the right to retrieve the subscriber identifier of the user equipment.
[0330] Figure 14 is a block diagram of an authentication device 1300 shown in an exemplary embodiment, and as shown in Figure 14, the device is The system may further include a user communication module 1305 configured to communicate with the target entity after successful authentication of the user equipment by the first proxy entity, establish a secure session with the first proxy entity, obtain the proxy domain name of the first proxy entity and the first domain name of the target entity, and if the proxy domain name and the first domain name are exactly the same, determine whether the user equipment and the target entity have second communication rights through the secure session, and if it is determined that the user equipment and the target entity have second communication rights, communicate with the target entity.
[0331] Optionally, the user communication module 1305 is configured to send a target entity service request message to the first proxy entity via the secure session, the target entity service request message including a second target entity identifier, the second target entity identifier being a protected entity identifier obtained by the user equipment based on the first target entity identifier, the target entity service request message instructing the first proxy entity to determine, based on the second target entity identifier, whether the user equipment and the target entity have second communication rights, and to determine whether the user equipment and the target entity have second communication rights in response to receiving a target entity service response message sent from the first proxy entity.
[0332] Selectable, the second communication authority is, The user equipment has access rights to the target entity, The first proxy entity has proxy authority over the target entity, This includes one or more of the following: the target entity has the right to retrieve the subscriber identifier of the user equipment.
[0333] The first message receiving module 1304 is optionally configured to determine that the user equipment and the target entity have first communication rights if the application session establishment response message is received, or if the application session establishment response message is received and the session establishment response message contains success instruction information.
[0334] Optionally, the first proxy entity may include a trusted authenticated proxy (AP) entity within the 3GPP operator domain.
[0335] Optionally, the first entity may include a trusted entity that provides application functionality within the 3GPP operator domain.
[0336] Selectively, the first entity may include a trusted application function (AF) entity within the 3GPP operator domain, or a trusted application server (SCS / AS) entity within the 3GPP operator domain.
[0337] Optionally, the first entity includes an untrusted entity that provides application functionality outside the 3GPP operator domain, the first proxy entity communicates with the first entity via a second entity, and the second entity includes an entity that provides network exposure functionality.
[0338] Selectively, the first entity may include an untrusted application function (AF) entity outside the 3GPP operator domain, or an untrusted application server (SCS / AS) entity outside the 3GPP operator domain.
[0339] Selectively, the second entity may include a Network Exposure Function (NEF) entity or a Service Capability Exposure Function (SCEF) entity.
[0340] Figure 15 is a block diagram of an authentication device 1500 shown in an exemplary embodiment, which is applicable to a first proxy entity. As shown in Figure 15, the device 1500 is A first proxy receiving module 1501 configured to receive an application session establishment request message sent from user equipment, wherein the application session establishment request message includes a first authorization request parameter, the application session establishment request message instructs the first proxy entity to determine, based on the first authorization request parameter, whether the user equipment and the target entity have first communication authorization, the target entity is an entity requesting communication, determined by the user equipment from one or more first entities, the first entity includes an entity that provides application functionality, the first proxy entity includes a trusted entity that provides authentication functionality within a 3GPP operator domain, and the first proxy entity provides authentication proxy functionality to the first entity; A first proxy determination module 1502 is configured to determine whether the user equipment and the target entity have first communication privileges based on the first privilege request parameters, The system may also include a first proxy transmission module 1503 configured to send an application session establishment response message to the user equipment and perform user equipment authentication to the user equipment if the user equipment and the target entity have first communication authority.
[0341] Optionally, the first authorization request parameter includes the first target entity identifier of the target entity and the key identifier (A-KID) corresponding to the user equipment.
[0342] Selectable, the first communication authority is, The user equipment has access rights to the target entity, The user equipment has access rights to the first proxy entity, The first proxy entity has proxy authority over the target entity, This includes one or more of the following: the target entity has the right to retrieve the subscriber identifier of the user equipment.
[0343] Optionally, the first proxy determination module 1502 is configured to determine a second authorization request parameter based on the first authorization request parameter, transmit the second authorization request parameter to a third entity, the third entity including an entity that provides AKMA authorization and application key derivation functions, the second authorization request parameter instructing the third entity to determine whether the user equipment and the target entity have first communication authorization, obtain first pending key information transmitted from the third entity, the first pending key information being key information obtained by the third entity based on the second authorization request parameter, and to determine whether the user equipment and the target entity have first communication authorization based on the first pending key information.
[0344] The first proxy determination module 1502 is optionally configured to use the first authorization request parameter and the proxy entity identifier corresponding to the first proxy entity as the second authorization request parameter.
[0345] Optionally, the first proxy determination module 1502 is configured to send the second authorization request parameters to a third entity through a first key request message, the first key request message instructing the third entity to obtain first pending key information and the subscriber identifier of the user equipment, receive a first key response message sent from the third entity, and obtain first pending key information contained in the first key response message.
[0346] Optionally, the first key response message further includes a second subscriber identifier corresponding to the user equipment, and the first proxy determination module 1502 is configured to obtain the second subscriber identifier based on the received first key response message.
[0347] Optionally, the second subscriber identifier includes a subscription persistence identifier (SUPI) corresponding to the user equipment.
[0348] Optionally, the first proxy determination module 1502 is configured to send the second authorization request parameters to the third entity through a second key request message, the second key request message indicating that the first proxy entity requests the acquisition of the first pending key information, receive a second key response message sent from the third entity, and acquire the first pending key information contained in the second key response message.
[0349] Selectively, the first proxy determination module 1502 determines that the user equipment and the target entity have first communication rights if the first pending key information includes entity key information corresponding to the target entity.
[0350] If user equipment authentication for the user equipment is selected to be successful, the first proxy transmission module 1503 is configured to notify the target entity of the first authentication result of the user equipment authentication.
[0351] Optionally, the first proxy transmission module 1503 is configured to obtain the proxy domain name of the first proxy entity and the first domain name of the target entity, and to notify the target entity of the first authentication result if the proxy domain name is different from the first domain name.
[0352] If the target entity is optionally a trusted entity that provides application functionality within a 3GPP operator domain, the first proxy transmission module 1503 is configured to send a first notification message containing the first authentication result to the target entity.
[0353] If the first proxy entity optionally obtains the second subscriber identifier of the user equipment, the first notification message further includes the second subscriber identifier.
[0354] If the target entity is an untrusted entity that provides application functionality outside the 3GPP operator domain, the first proxy transmission module 1503 is configured to instruct the second entity to transmit the first authentication result to the target entity by sending a second notification message to the second entity based on the first authentication result.
[0355] If the second subscriber identifier of the user equipment is optionally obtained by the first proxy entity, the second notification message further includes the second subscriber identifier.
[0356] Selectively, after successfully authenticating the user equipment for the user equipment, the device further includes the following:
[0357] Figure 16 is a block diagram of an authentication device 1500 shown in an exemplary embodiment, and as shown in Figure 16, the device may further include a first proxy communication module 1504. The first proxy communication module 1504 is configured to establish a secure session with the user equipment, receive a target entity service request message sent from the user equipment via the secure session, and that the target entity service request message includes a second target entity identifier, the second target entity identifier being a protected entity identifier obtained by the user equipment based on the first target entity identifier of the target entity, the target entity service request message being a message sent when the user equipment has determined that the proxy domain name of the first proxy entity and the first domain name of the target entity are the same, determine whether the user equipment and the target entity have second communication rights based on the second target entity identifier, and send a target entity service response message to the user equipment indicating whether the user equipment and the target entity have second communication rights.
[0358] The second communication authority is selectable. The user equipment has access rights to the target entity, The first proxy entity has proxy authority over the target entity, This includes one or more of the following: the target entity has the right to retrieve the subscriber identifier of the user equipment.
[0359] Optionally, the first proxy communication module 1504 is configured to determine that the user equipment and the target entity have second communication rights if the second target entity identifier is the same as the first target entity identifier.
[0360] Optionally, the first proxy communication module 1504 is configured to determine a third authorization request parameter based on the second target entity identifier if the second target entity identifier is different from the first target entity identifier, to send the third authorization request parameter to the third entity to instruct the third entity to determine whether the user equipment and the target entity have second communication authorization, to receive an authorization result parameter sent from the third entity, the authorization result parameter representing whether the user equipment and the target entity have second communication authorization, and to determine whether the user equipment and the target entity have second communication authorization based on the authorization result parameter.
[0361] The first proxy communication module 1504 is optionally configured to use the second target entity identifier, the key identifier (A-KID) corresponding to the user equipment, and the proxy entity identifier corresponding to the first proxy entity as the third authorization request parameters.
[0362] Optionally, the first proxy communication module 1504 is configured to send the third authorization request parameters to the third entity through a third key request message instructing the third entity to obtain the authorization result parameters and the subscriber identifier of the user equipment, to receive a third key response message sent from the third entity, and to obtain the authorization result parameters contained in the third key response message.
[0363] Optionally, the third key response message further includes a second subscriber identifier corresponding to the user equipment, and the first proxy communication module 1504 is configured to obtain the second subscriber identifier based on the received third key response message.
[0364] Optionally, the third key request message further includes authorization instruction parameters, which instruct the third entity to determine, based on the third key request message, whether the user equipment and the target entity have second communication authority.
[0365] Optionally, the first proxy communication module 1504 is configured to send the third authorization request parameter to the third entity through a fourth key request message indicating that the first proxy entity requests the acquisition of the authorization result parameter, to receive a fourth key response message sent from the third entity, and to acquire the authorization result parameter contained in the fourth key response message.
[0366] Optionally, the fourth key request message further includes authorization instruction parameters, which instruct the third entity to determine, based on the fourth key request message, whether the user equipment and the target entity have second communication authority.
[0367] Optionally, the first proxy communication module 1504 is configured to notify the target entity of a second authentication result indicating that the target entity and the user equipment have communication rights, if it is determined based on the authorization result parameters that the user equipment and the target entity have second communication rights.
[0368] Optionally, the first proxy communication module 1504 is configured to send a third notification message, including the second authentication result, to the target entity if the target entity is a trusted entity that provides application functionality within the 3GPP operator domain.
[0369] If the first proxy entity optionally obtains the second subscriber identifier of the user equipment, the third notification message further includes the second subscriber identifier.
[0370] Optionally, the first proxy communication module 1504 is configured to instruct the second entity to transmit the first authentication result to the target entity by sending a fourth notification message to the second entity based on the first authentication result, if the target entity is an untrusted entity providing application functionality outside the 3GPP operator domain.
[0371] If the first proxy entity optionally obtains the second subscriber identifier of the user equipment, the fourth notification message further includes the second subscriber identifier.
[0372] Selectable, the first pending key information is application key K AF This includes the key validity period.
[0373] Selectively, the second entity may include a Network Exposure Function (NEF) entity or a Service Capability Exposure Function (SCEF) entity.
[0374] Optionally, the first proxy entity may include a trusted authenticated proxy (AP) entity within the 3GPP operator domain.
[0375] Selectively, the first entity includes a trusted application function (AF) entity within a 3GPP operator domain, or a trusted application server (SCS / AS) entity within a 3GPP operator domain, or an untrusted application function (AF) entity outside a 3GPP operator domain, or an untrusted application server (SCS / AS) entity outside a 3GPP operator domain.
[0376] Figure 17 is a block diagram of an authentication device 1700 shown in an exemplary embodiment, which is applicable to a second entity. As shown in Figure 17, the device 1700 is A second receiving module 1701 configured to obtain the authentication result of a user equipment by a first proxy entity, wherein the authentication result includes a first authentication result or a second authentication result, the first authentication result indicating that the user equipment and the target entity have first communication authority, the second authentication result indicating that the user equipment and the target entity have second communication authority, the target entity is an entity requesting communication, determined by the user equipment from one or more first entities, the first entity includes an untrusted entity that provides application functionality outside the 3GPP operator domain, the first proxy entity includes a trusted entity that provides authentication functionality within the 3GPP operator domain, and the first proxy entity provides authentication proxy functionality to the first entity. The system may also include a second transmitting module 1702 configured to transmit the authentication result to the target entity so that the target entity communicates with user equipment based on the authentication result.
[0377] Optionally, the second receiving module 1701 is configured to receive a second notification message sent from the first proxy entity, the second notification message being a message sent by the first proxy entity to the second entity based on the first authentication result if the target entity is an untrusted entity providing application functionality outside the 3GPP operator domain, and to obtain the first authentication result based on the second notification message. The second transmission module 1702 is configured to send a fifth notification message to the target entity based on the first authentication result.
[0378] If the second notification message optionally includes a second subscriber identifier corresponding to the user equipment, the second transmission module 1702 is configured to obtain a first subscriber identifier corresponding to the user equipment based on the second subscriber identifier, and to send a fifth notification message to the target entity based on the first authentication result and the first subscriber identifier.
[0379] Selectively, the first subscriber identifier is a general public subscription identifier (GPSI) corresponding to the user equipment, and the second subscriber identifier includes a subscription persistent identifier (SUPI) corresponding to the user equipment.
[0380] Optionally, the second receiving module 1701 is configured to receive a fourth notification message sent from the first proxy entity, the fourth notification message being a message sent by the first proxy entity to the second entity based on the second authentication result if the target entity is an untrusted entity providing application functionality outside the 3GPP operator domain, and to obtain the second authentication result based on the second notification message. The second transmission module 1702 is configured to send a sixth notification message to the target entity based on the second authentication result.
[0381] If the fourth notification message includes, optionally, a second subscriber identifier corresponding to the user equipment, the second transmission module 1702 obtains a first subscriber identifier corresponding to the user equipment based on the second subscriber identifier, and sends a sixth notification message to the target entity based on the second authentication result and the first subscriber identifier.
[0382] Selectively, the second entity may include a Network Exposure Function (NEF) entity or a Service Capability Exposure Function (SCEF) entity.
[0383] Figure 18 is a block diagram of an authentication device 1800 shown in an exemplary embodiment, and the authentication device is applicable to a third entity. As shown in Figure 18, the device 1800 is A third receiving module 1801 configured to receive a second authorization request parameter transmitted from a first proxy entity, wherein the second authorization request parameter instructs the third entity to determine whether the user equipment and the target entity have first communication authorization, the target entity being an entity requesting communication, determined by the user equipment from one or more first entities, the first entity including an entity that provides application functionality, the first proxy entity including a trusted entity that provides authentication functionality within the 3GPP operator domain, the first proxy entity providing authentication proxy functionality to the first entity, and the third entity including an entity that provides AKMA authorization and application key derivation functionality. A third decision module 1802 is configured to determine whether the user equipment and the target entity have first communication authority based on the second authority request parameter, If the user equipment and the target entity have first communication rights, a third key module 1803 is configured to acquire first pending key information, The system may also include a third transmission module 1804 configured to transmit the first pending key information to the first proxy entity.
[0384] Selectively, the second authorization request parameter includes a key identifier (A-KID) corresponding to the user equipment, a first target entity identifier of the target entity, and a proxy entity identifier corresponding to the first proxy entity, and the third decision module 1802, Based on the key identifier (A-KID) and the first target entity identifier, it is determined whether the user equipment has access rights to the target entity. Based on the key identifier (A-KID) and the proxy entity identifier, it is determined whether the user equipment has access rights to the first proxy entity. One or more of the following: determining whether the first proxy entity has proxy authority over the target entity based on the proxy entity identifier and the first target entity identifier, The system is configured to determine whether the user equipment and the target entity have first communication authority.
[0385] Selectively, the third key module 1803 is, The system is configured to acquire the first pending key information based on the entity key information corresponding to the target entity.
[0386] Optionally, the third receiving module 1801 is configured to receive the second authorization request parameters sent from the first proxy entity through a first key request message, the first key request message instructing the third entity to obtain the first pending key information and the subscriber identifier of the user equipment. The third transmission module 1804 is configured to transmit the first pending key information to the first proxy entity through a first key response message.
[0387] Optionally, the third transmitting module 1804 is configured to transmit first pending key information and a second subscriber identifier corresponding to the user equipment to the first proxy entity via a first key response message if it is determined that the target entity has the authority to obtain the subscriber identifier.
[0388] Optionally, the second subscriber identifier is a subscription persistent identifier (SUPI) corresponding to the user equipment.
[0389] Optionally, the third receiving module 1801 is configured to receive the second authorization request parameters sent from the first proxy entity through a second key request message instructing the third entity to obtain the first pending key information. The third transmission module 1804 is configured to transmit the first pending key information to the first proxy entity through a second key response message.
[0390] Optionally, the third decision module 1802 is configured to transmit the first pending key information to the first proxy entity, receive a third authorization request parameter transmitted from the first proxy entity, determine whether the user equipment and the target entity have second communication authorization based on the third authorization request parameter, and transmit an authorization result parameter to the first proxy entity to notify the first proxy entity whether the user equipment and the target entity have second communication authorization.
[0391] Selectively, the third authorization request parameter includes the key identifier (A-KID), a second target entity identifier, and a proxy entity identifier corresponding to the first proxy entity, wherein the second target entity identifier is a protected entity identifier obtained by the user equipment based on the first target entity identifier of the target entity, and the third decision module 1802, Based on the key identifier (A-KID) and the second target entity identifier, it is determined whether the user equipment has access rights to the target entity. One or more of the following: determining whether the first proxy entity has proxy authority over the target entity based on the proxy entity identifier and the second target entity identifier, The system is configured to determine whether the user equipment and the target entity have a second communication authority.
[0392] Optionally, the third decision module 1802 is configured to receive the third authorization request parameters sent from the first proxy entity through a third key request message instructing the third entity to obtain the authorization result parameters and the subscriber identifier of the user equipment, and to send the authorization result parameters to the first proxy entity through a third key response message.
[0393] Optionally, the third key request message further includes authorization instruction parameters, which instruct the third entity to determine, based on the third key request message, whether the user equipment and the target entity have second communication authority.
[0394] Optionally, if the third decision module 1802 determines that the target entity has the authority to obtain the subscriber identifier, it sends the authorization result parameter and the second subscriber identifier corresponding to the user equipment to the first proxy entity via a third key response message.
[0395] Optionally, the second subscriber identifier is a subscription persistent identifier (SUPI) corresponding to the user equipment.
[0396] Optionally, the third decision module 1802 is configured to receive the third authorization request parameter sent from the first proxy entity through a fourth key request message instructing the third entity to obtain the authorization result parameter, and to send the authorization result parameter to the first proxy entity through a fourth key response message.
[0397] Optionally, the third decision module 1802 is configured to determine, based on a first pre-configured policy, whether the third entity has the authority to provide services to the first proxy entity, and, if the third entity does have the authority to provide services to the first proxy entity, to determine, based on the third authority request parameter, whether the user equipment and the target entity have second communication authority.
[0398] Optionally, the third decision module 1802 is configured to determine, based on a first pre-configured policy, whether the third entity has the authority to provide services to the first proxy entity, and, if the third entity has the authority to provide services to the first proxy entity, to determine, based on the second authority request parameter, whether the user equipment and the target entity have the first communication authority.
[0399] Optionally, the first proxy entity includes a trusted authenticated proxy (AP) entity within the 3GPP operator domain, and the third entity includes an AKMA anchor function (AAnF) entity.
[0400] Selectively, the first entity includes a trusted application function (AF) entity within a 3GPP operator domain, or a trusted application server (SCS / AS) entity within a 3GPP operator domain, or an untrusted application function (AF) entity outside a 3GPP operator domain, or an untrusted application server (SCS / AS) entity outside a 3GPP operator domain.
[0401] Figure 19 is a block diagram of an authentication device 1900 shown in an exemplary embodiment, which is applicable to a first entity. As shown in Figure 19, the device 1900 may include a first communication module 1901. The first communication module 1901 obtains the authentication result of the user equipment by the first proxy entity, wherein the authentication result includes either a first or second authentication result, wherein the first authentication result indicates that the user equipment and the target entity have first communication authority, and the second authentication result indicates that the user equipment and the target entity have second communication authority; wherein the first entity includes an entity that provides application functionality, and the target entity is an entity that requests communication, determined by the user equipment from one or more first entities; wherein the first proxy entity includes a trusted entity that provides authentication functionality within the 3GPP operator domain, and the first proxy entity is configured to provide authentication proxy functionality to the first entity and communicate with the user equipment based on the authentication result.
[0402] Selectively, the first communication module 1901 is configured to receive a first notification message containing the first authentication result sent from the first proxy entity, or a third notification message containing the second authentication result sent from the first proxy entity, if the target entity is a trusted entity providing application functionality within the 3GPP operator domain.
[0403] Selectively, the first notification message or the third notification message further includes a second subscriber identifier corresponding to the user equipment.
[0404] Optionally, the second subscriber identifier includes a subscription persistence identifier (SUPI) corresponding to the user equipment.
[0405] Optionally, the first communication module 1901 is configured to receive a fifth notification message sent from the second entity if the target entity is an untrusted entity providing application functionality outside the 3GPP operator domain, wherein the fifth notification message includes the first authentication result and is sent by the second entity in response to the receipt of the second notification message, or it is configured to receive a sixth notification message sent from the second entity, wherein the sixth notification message includes the second authentication result and is sent by the second entity in response to the receipt of the fourth notification message.
[0406] Selectively, the fifth notification message or the sixth notification message further includes a first subscriber identifier of the user equipment.
[0407] Optionally, the first subscriber identifier is a General Public Subscription Identifier (GPSI) corresponding to the user equipment.
[0408] Optionally, the first proxy entity may include a trusted authenticated proxy (AP) entity within the 3GPP operator domain.
[0409] Selectively, the first entity includes a trusted application function (AF) entity within a 3GPP operator domain, or a trusted application server (SCS / AS) entity within a 3GPP operator domain, or an untrusted application function (AF) entity outside a 3GPP operator domain, or an untrusted application server (SCS / AS) entity outside a 3GPP operator domain.
[0410] The specific methods by which each module performs operations in the apparatus described above are explained in detail in the embodiments related to the method, and a detailed explanation is omitted here.
[0411] Figure 20 is a block diagram of an authentication device shown in an exemplary embodiment. Exemplarily, the authentication device 2000 may be a terminal device such as a mobile phone, computer, digital broadcast terminal, message sending and receiving device, game console, tablet device, medical device, fitness equipment, or personal digital assistant; the authentication device 200 may be a server such as a local server or cloud server; the authentication device 2000 may be the user equipment shown in Figure 1; or the authentication device 2000 may be any one of the network entities in the communication system shown in Figure 1, such as the first entity, first proxy entity, second entity, or third entity.
[0412] Referring to Figure 20, the device 2000 includes one or more of the following components: a processing component 2002, a memory 2004, and a communication component 2006.
[0413] The processing component 2002 typically controls the overall operation of the device 2000, including operations related to display, telephone calling, data communication, camera operation, and recording. The processing component 2002 may include one or more processors 2020 for executing instructions to complete all or some of the steps of the above method. The processing component 2002 may also include one or more modules to facilitate interaction between the processing component 2002 and other components. For example, the processing component 2002 may include a multimedia module to facilitate interaction between a multimedia component and the processing component 2002.
[0414] Memory 2004 is configured to store various types of data to support operations on the device 2000. Examples of this data include instructions for any application programs or methods operated on the device 2000, contact data, phonebook data, messages, photographs, videos, etc. Memory 2004 can be implemented using any type of volatile or non-volatile storage device, or a combination thereof, such as static random access memory (SRAM), electrically erasable programmable read-only memory (EEPROM), erasable programmable read-only memory (EPROM), programmable read-only memory (PROM), read-only memory (ROM), magnetic memory, flash memory, magnetic disk, or optical disk.
[0415] The communication component 2006 is configured to facilitate wired or wireless communication between the device 2000 and other devices. The device 2000 can access wireless networks based on communication standards, such as WiFi, 2G or 3G, or a combination thereof. In an exemplary embodiment, the communication component 2006 receives broadcast signals or broadcast-related information from an external broadcast management system via a broadcast channel. In an exemplary embodiment, the communication component 2006 further includes a Near Field Communication (NFC) module to facilitate short-range communication. For example, the NFC module can be implemented using radio frequency identification (RFID) technology, infrared data association (IrDA) technology, ultra-wideband (UWB) technology, Bluetooth (BT) technology, and other technologies.
[0416] In exemplary embodiments, the apparatus 2000 may be implemented by one or more dedicated integrated circuits (ASICs), digital signal processors (DSPs), digital signal processing units (DSPDs), programmable logic devices (PLDs), field-programmable gate arrays (FPGAs), controllers, microcontrollers, microprocessors, or other electronic components, or one or more applications, to perform the above method.
[0417] The above-mentioned device 2000 may be an independent electronic device or part of an independent electronic device. For example, in one embodiment, the electronic device may be an integrated circuit (IC) or a chip, and the integrated circuit may be a single IC or a combination of multiple ICs. The chip includes, but is not limited to, a GPU (Graphics Processing Unit), a CPU (Central Processing Unit), an FPGA (Field Programmable Gate Array), a DSP (Digital Signal Processor), an ASIC (Application Specific Integrated Circuit), or a SOC (System on Chip). The above-mentioned integrated circuit or chip can realize the above-mentioned authentication method by executing executable instructions (or code). Here, the executable instructions can be stored in the integrated circuit or chip, or can be obtained from other devices. For example, the integrated circuit or chip includes a processor, memory, and interfaces for communicating with other devices. The executable instruction can be stored in the processor, and when the executable instruction is executed by the processor, the authentication method is realized, or the integrated circuit or chip can realize the authentication method by receiving the executable instruction through the interface and sending it to the processor for execution.
[0418] In an exemplary embodiment, a non-temporary computer-readable storage medium containing instructions is provided, for example, a memory 2004 containing instructions, which can be executed by a processor 2020 of terminal 2000 to complete the method. For example, the non-temporary computer-readable storage medium may be ROM, random access memory (RAM), CD-ROM, magnetic tape, floppy disk, optical data storage device, etc.
[0419] In another exemplary embodiment, a computer program product is further provided, which includes a computer program executable by a programmable device, the computer program having a code portion that, when executed by the programmable device, performs the authentication method described above.
[0420] A person skilled in the art, after considering the specification and practicing the invention disclosed herein, may readily conceive of other embodiments of the present disclosure. This disclosure is intended to cover all variations, uses, or adaptive changes of the present disclosure, which will follow the general principles of the present disclosure and include common or commonly used technical means in the art not disclosed herein. The specification and examples are illustrative only, and the true scope and spirit of the present disclosure are indicated by the following claims.
[0421] This disclosure is not limited to the exact structure described above and shown in the drawings, and various modifications and changes may be made as long as they do not deviate from its scope. The scope of this disclosure is limited only to the attached claims.
Claims
1. A communication method, which is applied to user equipment (UE), and the communication method is A step of determining a target entity from among one or more application servers (AS), wherein the UE communicates with the target entity via an Authentication Proxy (AP) entity, The steps include: driving an application key based on the fully qualified domain name (FQDN) of the target entity, wherein the application key is used by the AP entity to perform UE authentication with the UE; The aforementioned communication method is, The further step includes sending the FQDN of the target entity to the AP entity. A communication method characterized by the following features.
2. The aforementioned communication method is, The process further includes sending the UE's AKMA (Authentication and Key Management for Applications) key identifier (AKMA Key Identifier, A-KID) to the AP entity, The communication method according to feature 1.
3. The aforementioned communication method is, A step of sending an application session establishment request message to the AP entity, further comprising the step of the application session establishment request message including the A-KID of the UE and / or the FQDN of the target entity, The communication method according to feature 2.
4. The aforementioned communication method is, The step further includes receiving an application session establishment response message sent from the aforementioned AP entity, The communication method according to feature 3.
5. The aforementioned communication method is, The step further includes determining a first communication authority based on the aforementioned application session establishment response message, The aforementioned first communication authority is, The UE has access rights to the target entity, The UE has access rights to the AP entity, The AP entity has proxy authority over the target entity, The target entity has the right to retrieve the identity of the subscriber of the UE, and one or more of the following: The communication method according to feature 4.
6. The application session establishment response message is received by the AP entity when the AP entity receives the application key from the AKMA Anchor Function (AAnF) entity and the AP entity sends the application session establishment response message to the UE, and the application key is derived by the AAnF entity based on the FQDN of the target entity sent from the AP entity to the AAnF entity, Or, The application session establishment response message is received by the AP entity when the AP entity does not receive the application key from the AAnF entity and the AP entity sends the application session establishment response message to the UE, the application session response message includes a failure instruction, and the application key is driven by the AAnF entity based on the FQDN of the target entity sent from the AP entity to the AAnF entity. The communication method according to feature 4.
7. A communication method, which is applied to an Authentication Proxy (AP) entity, and the communication method is A step of performing UE authentication on a user equipment (UE) based on an application key, wherein the application key is derived based on the fully qualified domain name (FQDN) of a target entity among one or more application servers (AS), and the UE communicates with the target entity via the AP entity, The aforementioned communication method is, The further step includes receiving the FQDN of the target entity from the UE, A communication method characterized by the following features.
8. The aforementioned communication method is, If the AP entity successfully authenticates the UE to the UE, the process further includes sending a subscriber identifier to the target entity. The communication method according to feature 7.
9. The aforementioned communication method is, The further step includes transmitting the A-KID of the UE and / or the FQDN of the target entity to the AAnF entity, The communication method according to feature 7.
10. The aforementioned communication method is, A step of receiving the application key transmitted from the AAnF entity, further comprising the step of the application key being driven by the AAnF entity based on the FQDN of the target entity, The communication method according to feature 9.
11. The aforementioned communication method is, The further step includes receiving the A-KID of the UE from the UE, The communication method according to feature 9.
12. The aforementioned communication method is, The step of receiving an application session establishment request message from the UE, further comprising the step of the application session establishment request message including the UE's AKMA key identifier (AKMA Key Identifier, A-KID) and / or the FQDN of the target entity, The communication method according to feature 11.
13. The aforementioned communication method is, The step further includes sending an application session establishment response message to the aforementioned UE, The communication method according to feature 12.
14. The aforementioned communication method is, The step further includes determining a first communication authority based on the application key received from the AAnF entity, The aforementioned first communication authority is, The UE has access rights to the target entity, The UE has access rights to the AP entity, The AP entity has proxy authority over the target entity, The target entity has the right to retrieve the subscriber identifier of the UE, and one or more of the following: The communication method according to feature 10.
15. A communication method, which is applied to a target entity among one or more application servers (AS), wherein the communication method is If an Authentication Proxy (AP) entity performing the communication method described in claim 7 successfully authenticates a User Equipment (UE), the target entity receives a subscriber identifier transmitted from the AP entity, and the target entity communicates with the UE via the AP entity. A communication method characterized by the following features.
16. The AP entity performing UE authentication on the UE means that The AP entity performs UE authentication with the UE based on an application key, the application key being derived based on the fully qualified domain name (FQDN) of the target entity, The communication method according to feature 15.
17. The aforementioned communication method is, Further including the step of determining the first communications authority, The aforementioned first communication authority is, The UE has access rights to the target entity, The UE has access rights to the AP entity, The AP entity has proxy authority over the target entity, The target entity has the right to retrieve the subscriber identifier of the UE, and one or more of the following: The communication method according to feature 15.
18. A communication method, which is applied to an AAnF entity, and the communication method is The steps of receiving the A-KID of the user equipment (UE) and / or the fully qualified domain name (FQDN) of the target entity from an AP entity that performs the communication method described in claim 7, The steps include sending an application key to the AP entity, wherein the application key is derived based on the fully qualified domain name (FQDN) of the target entity, A communication method characterized by the following features.
19. The aforementioned application key is used by the AP entity to perform UE authentication with the UE, and the UE communicates with the target entity via the AP entity. The communication method according to feature 18.
20. A communication device, applied to user equipment, the communication device includes a processing module, The aforementioned processing module The UE determines a target entity from among one or more application servers (AS), and communicates with the target entity via an Authentication Proxy (AP) entity. The system is configured to delegate an Application Key based on the fully qualified domain name (FQDN) of the target entity, and the Application Key is used by the AP entity to perform UE authentication against the UE. The communication device further transmits the FQDN of the target entity to the AP entity. A communication device characterized by the following features.
21. A communication device, which is applied to an AP entity, and the communication device is A processing module configured to perform UE authentication on a user equipment (UE) based on an application key, wherein the application key is derived based on the fully qualified domain name (FQDN) of a target entity among one or more application servers (AS), and the processing module includes a mechanism by which the UE communicates with the target entity via the AP entity. The communication device further receives the FQDN of the target entity from the UE. A communication device characterized by the following features.
22. A communication device, which is applied to a target entity among one or more application servers (AS), the communication device is A transceiver module configured to receive a subscriber identifier transmitted from an Authentication Proxy (AP) entity to which the communication device described in claim 21 is applied when UE authentication to a User Equipment (UE) is successful, the transceiver module includes a transceiver module to which the target entity communicates with the UE via the AP entity. A communication device characterized by the following features.
23. A communication device, which is applied to an AAnF entity, and the communication device includes a transmit / receive module, The aforementioned transmitting and receiving module The communication device according to claim 21 receives the A-KID of the user equipment and / or the fully qualified domain name (FQDN) of the target entity from the AP entity to which the communication device described in claim 21 is applied. It is configured to send an application key to the aforementioned AP entity, and the application key is derived based on the fully qualified domain name (FQDN) of the target entity. A communication device characterized by the following features.
24. A communication device, One or more processors, The processor includes a memory that stores computer-readable instructions, When the computer-readable instruction is executed by the processor, the communication device is instructed to perform the method according to any one of claims 1 to 19. A communication device characterized by the following features.
25. A computer-readable storage medium storing computer program instructions, wherein when the computer program instructions are executed by a processor, the method according to any one of claims 1 to 19 is realized. A computer-readable storage medium characterized by the following features.
26. A computer program, in which the computer program is executed by a processor, the method according to any one of claims 1 to 19 is realized. A computer program characterized by the following features.