Authentication method and device
By calculating and sending group request messages to authenticate multiple zero-power devices, the network congestion problem caused by a large number of zero-power devices accessing the network is solved, and the authentication efficiency is improved.
Patent Information
- Application Number
- PCT/CN2023/112382
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2023-08-10
- Publication Date
- 2025-11-27
AI Technical Summary
In communication systems, when a large number of zero-power devices are connected, network devices need to perform authentication interactions with them, which leads to an increase in signaling overhead, network congestion, and reduced authentication efficiency in a short period of time.
The first device calculates the first signature of multiple zero-power devices and sends a group request message to the authentication function entity. The authentication function entity authenticates multiple devices based on the signature, reducing the need for separate authentication of each device on the network side, reducing communication signaling overhead, and improving authentication efficiency.
This avoids network congestion, reduces communication signaling overhead, and improves authentication processing efficiency.
Smart Images

Figure CN2023112382_27112025_PF_FP_ABST
Abstract
Description
Authentication method and device TECHNICAL FIELD
[0001] The present application relates to the field of communication, and more particularly, to an authentication method, device, computer readable storage medium, computer program product and computer program. BACKGROUND
[0002] With the development of technology, zero-power devices also have the need to access a communication system or a communication network. In order to access the communication system or the network, the zero-power devices need to perform authentication interaction with the network device of the communication system. However, a large number of zero-power devices may exist within a certain communication range. Thus, the network device may need to perform authentication interaction with a large number of zero-power devices within a short time, which may cause an increase in signaling overhead of the network device within a short time, network congestion, and thus reduced authentication efficiency.
[0003] SUMMARY
[0004] The present application provides an authentication method, device, computer readable storage medium, computer program product and computer program.
[0005] The present application provides an authentication method performed by a first device, comprising:
[0006] receiving authentication requests from a plurality of second devices, wherein each authentication request of the plurality of second devices carries a first security parameter;
[0007] sending a group request message to an authentication function entity, wherein the group request message carries a first signature used for authenticating the plurality of second devices, and the first signature is calculated based on the first security parameter corresponding to each second device.
[0008] The present application provides an authentication method performed by an authentication function entity, comprising:
[0009] receiving a group request message from a first device, wherein the group request message carries a first signature used for authenticating a plurality of second devices, and the first signature is calculated based on a first security parameter corresponding to each second device of the plurality of second devices.
[0010] The present application provides an authentication method performed by a target second device, comprising:
[0011] sending an authentication request to a first device, wherein the authentication request carries a first security parameter corresponding to the target second device, and the first security parameter corresponding to the target second device is used for calculating a first signature.
[0012] The present application provides an authentication method performed by a first device, comprising:
[0013] receiving a group response message from the authentication function entity, wherein the group response message carries a second signature for authenticating the authentication function entity.
[0014] Embodiments of the present application provide an authentication method performed by an authentication function entity, comprising:
[0015] sending a group response message to the first device, wherein the group response message carries a second signature for authenticating the authentication function entity.
[0016] Embodiments of the present application provide a first device, comprising:
[0017] a first communication unit, configured to receive authentication requests from a plurality of second devices, wherein the authentication request of each second device of the plurality of second devices carries a first security parameter; and send a group request message to an authentication function entity, wherein the group request message carries a first signature for authenticating the plurality of second devices, and the first signature is calculated based on the first security parameter corresponding to each second device.
[0018] Embodiments of the present application provide an authentication function entity, comprising:
[0019] a second communication unit, configured to receive a group request message from a first device, wherein the group request message carries a first signature for authenticating a plurality of second devices, and the first signature is calculated based on a first security parameter corresponding to each second device of the plurality of second devices.
[0020] Embodiments of the present application provide a target second device, comprising:
[0021] a third communication unit, configured to send an authentication request to a first device, wherein the authentication request carries a first security parameter corresponding to the target second device, and the first security parameter corresponding to the target second device is used to calculate a first signature.
[0022] Embodiments of the present application provide a first device, comprising:
[0023] a first communication unit, configured to receive a group response message from an authentication function entity, wherein the group response message carries a second signature for authenticating the authentication function entity.
[0024] Embodiments of the present application provide an authentication function entity, comprising:
[0025] a second communication unit, configured to send a group response message to a first device, wherein the group response message carries a second signature for authenticating the authentication function entity.
[0026] The embodiment of the present application provides a first device, comprising a transceiver, a processor and a memory. The memory is used for storing a computer program, and the processor is used for calling and running the computer program stored in the memory, so that the first device executes the above method.
[0027] The embodiment of the present application provides an authentication function entity, comprising a transceiver, a processor and a memory. The memory is used for storing a computer program, and the processor is used for calling and running the computer program stored in the memory, so that the authentication function entity executes the above method.
[0028] The embodiment of the present application provides a second device, comprising a transceiver, a processor and a memory. The memory is used for storing a computer program, and the processor is used for calling and running the computer program stored in the memory, so that the second device executes the above method.
[0029] The embodiment of the present application provides a chip, which is used for implementing the above method.
[0030] Specifically, the chip comprises a processor, which is used for calling and running a computer program from a memory, so that the device installed with the chip executes the above method.
[0031] The embodiment of the present application provides a computer readable storage medium, which is used for storing a computer program, and when the computer program is run by a device, the device executes the above method.
[0032] The embodiment of the present application provides a computer program product, comprising computer program instructions, which make a computer execute the above method.
[0033] The embodiment of the present application provides a computer program, which, when running on a computer, makes the computer execute the above method.
[0034] By adopting the scheme provided in the embodiment, the first device calculates a first signature according to the first security parameter carried in the authentication request of each second device in the plurality of second devices, sends a group request message carrying the first signature to the authentication function entity, so that the authentication function entity authenticates the plurality of second devices based on the first signature. In this way, the problem of network congestion caused by the authentication function entity of the network side individually authenticating each second device in the case that a large number of second devices access the network in a short time is avoided, the communication signaling overhead between the first device and the authentication function entity is reduced, and the efficiency of the authentication processing is improved. BRIEF DESCRIPTION OF DRAWINGS
[0035] Fig. 1 is a schematic diagram of an application scenario according to the embodiment of the present application.
[0036] Fig. 2 is a schematic flowchart of an authentication method according to an embodiment of the present application.
[0037] Figure 3 is a schematic flowchart of an authentication method according to another embodiment of the application.
[0038] Figure 4 is a schematic flowchart of an authentication method according to another embodiment of the application.
[0039] Figure 5 is a schematic flowchart of an authentication method according to another embodiment of the application.
[0040] Figure 6 is a schematic flowchart of an authentication method according to another embodiment of the application.
[0041] Figure 7 is a schematic block diagram of an authentication method according to an embodiment of the application.
[0042] Figures 8a and 8b are two schematic flowcharts of an authentication method according to an embodiment of the application.
[0043] Figure 9 is a schematic diagram of various scenarios of a zero-power device according to an embodiment of the application.
[0044] Figure 10 is a schematic diagram of an asymmetric cryptography system according to an embodiment of the application.
[0045] Figure 11 is a schematic block diagram of a first device according to an embodiment of the application.
[0046] Figure 12 is a schematic block diagram of an authentication function entity according to an embodiment of the application.
[0047] Figure 13 is a schematic block diagram of a target second device according to an embodiment of the application.
[0048] Figure 14 is a schematic block diagram of a communication device according to an embodiment of the application.
[0049] Figure 15 is a schematic block diagram of a chip according to an embodiment of the application.
[0050] Figure 16 is a schematic block diagram of a communication system according to an embodiment of the application. DETAILED DESCRIPTION
[0051] The technical solutions of embodiments of the application can be applied to various communication systems, for example: LTE, LTE-A, NR, evolution of NR, WLAN, WiFi, or other communication systems, etc.
[0052] In the embodiments of the present application, the network device can be a device for communicating with the terminal, which can be an access point in WLAN, an evolved base station in LTE, or a relay station, or a vehicle-mounted device, a wearable device, and a network device (gNB) in an NR network, or a network device in a future evolved PLMN network, or a network device in a non-ground network, etc. As an example but not limitation, in the embodiments of the present application, the network device can have mobile characteristics, for example, the network device can be a mobile device.
[0053] In the embodiments of the present application, the network device can be a device for communicating with the terminal, which can be an access point in WLAN, an evolved base station in LTE, or a relay station, or a vehicle-mounted device, a wearable device, and a network device (gNB) in an NR network, or a network device in a future evolved PLMN network, or a network device in a non-ground network, etc. As an example but not limitation, in the embodiments of the present application, the network device can have mobile characteristics, for example, the network device can be a mobile device.
[0054] It should be understood that the terms "system" and "network" are often used interchangeably herein. The term "and / or" herein is only a description of the associated relationship between the objects. It means that there can be three relationships, for example, A and / or B can represent the three cases of A alone, A and B together, and B alone. In addition, the character " / " herein generally represents an "or" relationship between the associated objects. It should be understood that the "indication" mentioned in the embodiments of the present application can be direct indication or indirect indication, or can represent an associated relationship. For example, A indicates B, which can mean that B can be obtained through A, or A indirectly indicates B, for example, A indicates C, and B can be obtained through C, or A and B have an associated relationship. In the description of the embodiments of the present application, the term "corresponding" can represent a direct or indirect corresponding relationship between the two, or an associated relationship between the two, or an indication and being indicated, configuration and being configured, etc.
[0055] In order to facilitate the understanding of the technical solutions of the embodiments of the present application, the related technologies of the embodiments of the present application are described as follows, which can be combined with the technical solutions of the embodiments of the present application in any way, and all belong to the protection scope of the embodiments of the present application.
[0056] FIG. 1 illustrates a communication system 100. The communication system includes one network device 110 and two terminals 120. In a possible implementation, the communication system 100 can include multiple network devices 110, and each network device 110 can include other numbers of terminals 120 within its coverage, which are not limited in the embodiments of the present application. In a possible implementation, the communication system 100 can further include a mobility management entity, an access and mobility management function, and other network entities, which are not limited in the embodiments of the present application. The network device can include an access network device and a core network device. That is, the communication system can include multiple core networks for communicating with the access network device. The access network device can be a base station of an LTE, LTE-A, or NR system. For example, the communication system shown in FIG. 1 can include network devices and terminals with communication functions, and can further include other devices in the communication system, such as a network controller, a mobility management entity, and other network entities, which are not limited in the embodiments of the present application.
[0057] FIG. 2 is a schematic flowchart of an authentication method performed by a first device according to an embodiment of the present application. The method includes at least part of the following.
[0058] S210, receiving authentication requests from multiple second devices, wherein each authentication request of the multiple second devices carries a first security parameter corresponding to the second device;
[0059] S220, sending a group request message to an authentication function entity, wherein the group request message carries a first signature for authenticating the multiple second devices, and the first signature is calculated based on the first security parameter corresponding to each second device.
[0060] FIG. 3 is a schematic flowchart of an authentication method performed by an authentication function entity according to another embodiment of the present application. The method includes at least part of the following.
[0061] S310, receiving a group request message from a first device, wherein the group request message carries a first signature for authenticating multiple second devices, and the first signature is calculated based on a first security parameter corresponding to each second device of the multiple second devices.
[0062] FIG. 4 is a schematic flowchart of an authentication method performed by a target second device according to another embodiment of the present application. The method includes at least part of the following.
[0063] S410, sending an authentication request to a first device, wherein the authentication request carries a first security parameter corresponding to the target second device, and the first security parameter corresponding to the target second device is used to calculate a first signature.
[0064] The first device is one of: a terminal, an access network device. The access network device can refer to an access network device, for example, the access network device can be any one of: a base station, a gNB, an eNB, an integrated access backhaul (IAB) node, and the like.
[0065] Each of the plurality of second devices can be a zero-power device. Alternatively, each of the plurality of second devices can be an Internet of Things (IoT) device. The target second device can be any one of the plurality of second devices, and the target second device can also be a zero-power device; or the target second device can also be an IoT device. The number of the plurality of second devices is not limited in the embodiment, and in some possible examples, the plurality of second devices can also be represented as N second devices, where N is an integer greater than or equal to 2.
[0066] In some embodiments, any one of the second devices can be any one of: an ambient power-enabled IoT (AIoT) device, an active zero-power device, a passive zero-power device, a semi-passive zero-power device, and the like. In some embodiments, any one of the second devices can also be a terminal with low computing power. In some possible embodiments, any one of the second devices can be referred to as a tag. The possible names or possible device types of the second devices are not exhaustively listed here.
[0067] In some embodiments, the first device is a terminal, and in such embodiments, the first device and any one of the second devices can communicate by transmitting sidelink messages. In some embodiments, the first device can be an access network device, and in such embodiments, the first device and any one of the second devices can communicate by transmitting AS (Access Stratum) messages.
[0068] The authentication function entity can be deployed in at least one of the following: an application function (AF), an access and mobility management function (AMF), a session management function (SMF), an authentication server function (AUSF), a unified data management function (UDM), a unified data repository (UDR), a home subscriber system (HSS), an authentication credential repository and processing function (ARPF), a bootstrapping server function (BSF), a security anchor function (SEAF), and a core network dedicated network element.
[0069] The authentication function entity can refer to a network element with authentication function. The authentication function can at least include an AIOT group authentication function and / or a group authentication function. In some possible examples, an A-NF can be used to represent the A-IoT group authentication function (NF, Network Function) and / or the group authentication function. In other possible examples, the authentication function can further include at least one of the following: a zero-power group authentication function and / or a group authentication function, an Internet of Things device group authentication function and / or a group authentication function, and the like.
[0070] For example, the authentication function entity can be newly added on the basis of an AF of an application server.
[0071] Exemplarily, the authentication function entity can be a newly added core network dedicated network element, which is provided with or set or configured with an authentication function. In this example, the core network dedicated network element can be referred to as an AIOT authentication function entity, or a zero-power function dedicated authentication function entity, or a zero-power dedicated network element, or a zero-power device dedicated network element, and the like. That is, the core network dedicated network element can refer to a network element at least provided with a zero-power related function (such as an AIOT authentication function), or a core network network element at least capable of serving AIOT (or serving a zero-power device). It should be understood that the core network dedicated network element can be separately set, or it can be an existing core network network element to which a zero-power authentication related function (such as an AIOT or tag authentication function) is added. This embodiment does not exhaustively enumerate all possible cases.
[0072] Exemplarily, the authentication function entity can be an existing core network network element, and an authentication function is newly added or provided or newly configured in the core network network element. For example, the core network network element can newly add an authentication function on the basis of being provided with or having at least one of the following functions: AMF, SMF, AUSF, UDM, UDR, HSS, ARPF, BSF, SEAF, and the like.
[0073] In some possible implementation manners, the authentication request of each second device in the plurality of second devices carries a first security parameter, which means that the authentication request of each second device carries the first security parameter corresponding to the second device. In other words, the authentication request of any second device carries the first security parameter corresponding to the second device itself.
[0074] Taking any one second device as a target second device, the authentication request carries the first security parameter corresponding to the target second device, specifically, the authentication request of the target second device carries the first security parameter corresponding to the target second device.
[0075] The first security parameter corresponding to the target second device is calculated based on a first random number generated by the target second device. Specifically, the target second device calculates the first security parameter corresponding to the target second device, which can include that the target second device adopts a security algorithm to calculate the first security parameter corresponding to the target second device based on the first random number corresponding to the target second device.
[0076] The first random number corresponding to the target second device can be generated or selected by the target second device. The manner of generating or selecting the first random number by the target second device is not limited in this embodiment.
[0077] Optionally, the security algorithm can be a Diffie-Hellman (DH) algorithm, which can also be referred to as a Diffie-Hellman key exchange algorithm.
[0078] In this example, the first security parameter corresponding to the target second device is calculated by the security algorithm based on a first random number corresponding to the target second device and a shared parameter.
[0079] The shared parameter can include a large prime number and a primitive element, where the primitive element is a primitive element of the large prime number. Here, the shared parameter can refer to a parameter shared by each second device and the authentication function entity.
[0080] The first random number corresponding to the target second device is less than the large prime number.
[0081] The DH algorithm can include at least an exponentiation calculation, a modulo function, and the like. That is, the target second device calculating the first security parameter corresponding thereto can include: the target second device performing an exponentiation calculation based on the first random number corresponding to the target second device and the primitive element by using the DH algorithm to obtain a first value, and calculating the first security parameter corresponding to the target second device based on the first value and the large prime number by using the modulo function. For example, assuming that the large prime number is represented as p, the primitive element is represented as g, the first random number corresponding to the target second device is represented as r1, and the modulo function is represented as mod(), the target second device calculating the first security parameter can be calculated by using the following formula: R1=g r1 mod(p).
[0082] Optionally, the security algorithm can be an Elliptic Curve Diffie-Hellman (ECDH) algorithm based on elliptic curve cryptography.
[0083] In this example, the first security parameter corresponding to the target second device is calculated by the security algorithm based on a first random number corresponding to the target second device and a generator. The generator is a generator of an additive cyclic group GP, and the generator can be a public parameter, that is, the generator can be a parameter preconfigured at each second device and the authentication function entity, and the preconfiguration or setting manner of the generator is not limited in this embodiment.
[0084] The ECDH algorithm can include at least point multiplication calculation, etc. For example, the target second device calculates the corresponding first security parameter, which can include that the target second device uses the ECDH algorithm to perform point multiplication calculation on the first random number corresponding to the target second device and the generator to obtain the first security parameter corresponding to the target second device. For example, assuming that the generator is represented as P, the first random number corresponding to the target second device is represented as r1, and the point multiplication calculation is represented as "*"; the target second device can calculate the first security parameter using the following formula: R1 = r1 * P.
[0085] It should be noted that the above embodiment only takes any one of the plurality of second devices as the target second device as an example, and describes the way in which the target second device calculates the corresponding first security parameter. Each second device calculates its own first security parameter in the same way as the target second device, but this embodiment does not go into detail.
[0086] In some possible implementations, the authentication request of each second device also carries the identification of the second device. In other words, the authentication request of any second device carries its own identification.
[0087] Still taking any one of the plurality of second devices as the target second device as an example, the authentication request can carry the identification of the target second device; that is, the authentication request of the target second device can carry not only the first security parameter corresponding to the target second device, but also the identification of the target second device.
[0088] In an example, each device (such as each zero-power device) in the network or system can not set a device group, or can not configure a device group, or can specify that the group identification of the device group is not used in the authentication process. In this example, the authentication request of the target second device can carry the first security parameter corresponding to the target second device and the identification of the target second device.
[0089] In an example, each device (such as each zero-power device) in the network or system can set a device group, or can configure a device group, or can specify that the group identification of the device group is used in the authentication process. In this example, the authentication request can also carry the group identification, which can be represented as GID (Group ID). The group identification can be pre-set in the target second device, and the configuration manner is not limited in this embodiment. In this case, the authentication request of the target second device can carry the first security parameter corresponding to the target second device, the identification of the target second device, and the group identification.
[0090] It should be noted that the above embodiments only take the target second device as an example, and the authentication request sent by the target second device is described. In fact, the content type of the authentication request sent by each second device is the same as that of the authentication request sent by the target second device, and thus is not described again.
[0091] In an embodiment, the authentication request of each second device carries the first security parameter corresponding to each second device, the identity of the second device, and the authentication request of each second device does not carry the group identity.
[0092] In this embodiment, the first device receives the authentication request from the plurality of second devices, which can include that the first device receives the authentication request from each second device in the plurality of second devices within a first time length. That is, the first device can start a timer and begin to receive the authentication request sent by any device in the case that the current time is the aggregation start time; in the case that the time length of the timer reaches the first time length, the devices corresponding to all the authentication requests received within the first time length are all regarded as second devices. In this case, the first device can obtain the first security parameter corresponding to each second device, the identity of the second device through the authentication request of each second device.
[0093] The aggregation start time can be determined according to actual conditions, for example, the aggregation start time can be the time when the authentication request sent by any device is first received; for another example, the aggregation start time can be indicated by the authentication function entity, and the embodiment does not exhaust and limit it. The first time length can be pre-configured, for example, the first time length can be 1 time unit, or 10 time units, or longer or shorter, and the time unit can be minute, or second, or time slot, or symbol, etc. The embodiment does not limit and exhaust the first time length.
[0094] In an embodiment, the authentication request of each second device can carry the identity of the second device, and the authentication request of each second device carries the group identity.
[0095] In this embodiment, the first device receiving the authentication request from the plurality of second devices can include: the first device receiving the authentication request from each of the plurality of devices within a first time length, aggregating the plurality of devices based on the group identifier carried in the authentication request of each of the plurality of devices to obtain a plurality of devices under each of one or more device groups, taking the kth device group in the one or more device groups as the device group for this authentication, and taking the plurality of devices in the kth device group as the plurality of second devices, where k is a positive integer. In this embodiment, the description of the first time length is the same as that in the foregoing embodiments, and thus will not be repeated. That is, regardless of how many authentication requests reported by the devices are received by the first device, the first device will take the plurality of devices in the same device group as the plurality of second devices for subsequent authentication processing. In this case, the first device can obtain the first security parameter corresponding to each second device, the identifier of the second device, and the group identifier of the same device group to which each second device belongs through the authentication request of each second device.
[0096] The foregoing aggregation of the plurality of devices by the first device based on the group identifier carried in the authentication request of each of the plurality of devices to obtain a plurality of devices under each of one or more device groups can further include: the first device extracting the identifier of the jth device and the kth group identifier from the authentication request of the jth device, determining the group information of the kth device group based on the kth group identifier, determining whether the identifier of the jth device is in the device group list of the group information of the kth device group, if not, not performing subsequent processing on the jth device, and if yes, determining that the jth device is one of the devices in the kth device group. In this way, after the same processing as that on the jth device is performed on each of the plurality of devices, a plurality of devices under each of one or more device groups can be obtained. Wherein, j and k are positive integers, the jth device is any one of the plurality of devices that sends the authentication request to the first device, and the kth device group is any one of the one or more device groups. The group information of the kth device group can be preset, and the group information at least includes a device group list, which can include the identifier of one or more candidate devices of the kth device group. The setting method and generation method of the group information are not limited in this embodiment.
[0097] It should be understood that, since the same processing as that on the kth device group can be performed on each device group, the processing on all device groups will not be repeated. It should be further pointed out that, the description of taking any one device group as an example in the following of the present application does not mean that the scheme provided by the present application can only be used for processing one device group, but is for the sake of brevity and not repeating the same processing on all device groups.
[0098] In some possible implementation manners, after the first device receives the authentication requests from the plurality of second devices, the first device can calculate the first signature and send a group request message to the authentication function entity.
[0099] In an embodiment, the first signature is calculated based on a private key of the first device and a group security parameter, wherein the group security parameter is calculated based on the first security parameter corresponding to each second device.
[0100] The manner in which the first device calculates the group security parameter can include that the first device calculates the first security parameter corresponding to each second device by using a first calculation manner to obtain the group security parameter. The first calculation manner can be any one of addition calculation, XOR calculation, direct connection calculation, and the like.
[0101] Taking the first calculation manner as addition calculation as an example, assuming that the number of the plurality of second devices is N (N is an integer greater than or equal to 2), the first device calculating the group security parameter can be represented as: R = R1 + R2 + … + RN. N , wherein R1 ~ RN are the first security parameters corresponding to each of the N second devices respectively, and R is the group security parameter. N
[0102] The manner in which the first device calculates the first signature can include that the first device calculates the first signature based on the private key of the first device and the group security parameter by using a signature algorithm.
[0103] The signature algorithm includes at least one of RSA, SM2, JSON Web Signatures (JWS) algorithm, and an elliptic curve-based signature algorithm. The SM2 algorithm is a domestic algorithm promoted by the National Cryptography Administration of China, which is an asymmetric algorithm based on an elliptic curve. The signature algorithm is not exhaustively listed and limited herein.
[0104] For example, the first device calculating the first signature can be that the first device calculates the first signature based on the group security parameter by using the signature algorithm and the private key of the first device. For example, the first device calculating the first signature can be represented as Ey(R), wherein y is the private key of the first device, and E represents the signature algorithm.
[0105] For example, the signature algorithm includes a hash calculation and an encryption calculation; accordingly, the manner in which the first device calculates the first signature can include: the first device performing a hash calculation based on the group security parameter to obtain a first hash value, and performing an encryption on the first hash value based on a private key of the first device to obtain the first signature. Here, the hash calculation can be a SHA (Secure Hash Algorithm), and more specifically, the SHA can be a SHA-256. It should be understood that this is merely an example, and as long as any hash calculation algorithm is used in actual processing, it is within the protection scope of the present embodiment, and all possible hash calculation algorithms are not enumerated and limited here.
[0106] It should be noted that the above is an example of calculating the first signature, and as long as the group security parameter and the private key of the first device are used to calculate the first signature in actual processing, it is within the protection scope of the present embodiment, and the manner of calculating the first signature is not limited and enumerated here.
[0107] In an embodiment, the first signature is calculated based on the private key of the first device, the group security parameter, the identity of each second device, and the identity of the first device.
[0108] The manner of calculating the group security parameter has been described in detail in the foregoing embodiments, and will not be repeated here.
[0109] The manner in which the first device calculates the first signature can include: the first device using a signature algorithm, and the first device calculating the first signature based on the group security parameter, the private key of the first device, the identity of each second device, and the identity of the first device.
[0110] For example, the first device calculating the first signature can be using a signature algorithm, and the first signature is calculated based on the private key of the first device, the group security parameter, the identity of each second device, and the identity of the first device. For example, the first device calculating the first signature can be represented as Ey(R||UE ID||Tag ID1||……||Tag IDN), where y is the private key of the first device, E represents the signature algorithm, R is the group security parameter, UE ID represents the identity of the terminal when the first device is a terminal, and Tag ID1-Tag IDN represent the identity of each second device in the N second devices.
[0111] It should be understood that the above is only one possible example of calculating the first signature, and in actual processing, other ways of calculating the first signature can also be used, such as the identity of each of the N second devices (such as N Tag IDs) can be first XOR calculated, and then combined with the group security parameter (such as R), the identity of the first device (such as UE ID), and the private key of the first device (such as y) to calculate the first signature, which can be represented as: For another example, the identity of the first device (such as UE ID) and the identity of each of the N second devices (such as N Tag IDs) can be first XOR calculated, and then combined with the group security parameter (such as R) and the private key of the first device (such as y) to calculate the first signature, which can be represented as: and so on.
[0112] For another example, the signature algorithm can include hash calculation and encryption calculation; the way in which the first device calculates the first signature can include: the first device performs hash calculation based on the group security parameter, the identity of each second device, and the identity of the first device to obtain a second hash value, and performs encryption on the second hash value based on the private key of the first device to obtain the first signature.
[0113] It should be noted that the above is only an exemplary description of calculating the first signature, and in actual processing, as long as the identity of each of the plurality of second devices, the identity of the first device, the group security parameter, and the private key of the first device are used to calculate the first signature, it is within the protection scope of the embodiment, and the above various contents are not limited and exhausted in terms of how to participate in the calculation of the first signature.
[0114] In an embodiment, after the first device completes the calculation of the first signature, the group request message carrying the first signature can be sent to the authentication function entity.
[0115] Optionally, in addition to carrying the first signature, the group request message can also carry the group security parameter.
[0116] Optionally, the authentication request of each second device carries the identity of each second device and the first security parameter corresponding to each second device. In this case, in addition to carrying the first signature and the group security parameter, the group request message also carries the identity of the first device and the identity of each second device; further, the group request message can also carry the first security parameter corresponding to each second device.
[0117] Optionally, the authentication request of each second device carries the identity of each second device, the first security parameter corresponding to each second device, and the group identity. In this case, the group request message can carry at least one of the following in addition to the first signature, the group security parameter, the identity of the first device, and the identity of each second device: the group identity, and the first security parameter corresponding to each second device.
[0118] Optionally, since the public key of the first device needs to be used in the authentication processing of the first signature by the authentication function entity, whether the public key of the first device is pre-stored by the authentication function entity can also be used to determine whether the public key of the first device is carried in the group request message, and the two cases are as follows:
[0119] In the case where the authentication function entity pre-stores the public key of the first device, the group request message can carry the identity of the first device and the identity of each second device in addition to the first signature and the group security parameter. Further, the group request message can carry at least one of the following: the group identity and the first security parameter corresponding to each second device.
[0120] In the case where the authentication function entity does not pre-store the public key of the first device, the group request message can carry the identity of the first device and the identity of each second device in addition to the first signature and the group security parameter. Further, the group request message can carry at least one of the following: the group identity, the first security parameter corresponding to each second device, and the public key of the first device.
[0121] In some possible implementations, after receiving the group request message from the first device, the authentication function entity can authenticate the plurality of second devices based on the first signature.
[0122] In an embodiment, the first signature is calculated based on the private key of the first device and the group security parameter. In this embodiment, the process of authenticating the plurality of second devices by the authentication function entity based on the first signature can include authenticating the plurality of second devices based on the public key of the first device, the group security parameter, and the first signature.
[0123] The way in which the authentication function entity obtains the public key of the first device has been described in the foregoing embodiments and will not be repeated here.
[0124] For example, the authentication function entity authenticates the plurality of second devices based on the public key of the first device, the group security parameter, and the first signature can include that the authentication function entity uses a signature verification algorithm to decrypt the first signature based on the public key of the first device to obtain a to-be-verified security parameter, and authenticates the plurality of second devices based on the to-be-verified security parameter and the group security parameter. Wherein, authenticating the plurality of second devices based on the to-be-verified security parameter and the group security parameter can include one of the following: in the case that the to-be-verified security parameter and the group security parameter are the same, it is determined that the authentication of the plurality of second devices is successful; in the case that the to-be-verified security parameter and the group security parameter are different, it is determined that the authentication of the plurality of second devices fails. For example, the authentication function entity verifies the first signature can be represented as R=Dx(R), where R is the group security parameter, D is the signature verification algorithm, and x is the public key of the first device.
[0125] For another example, the authentication function entity authenticates the plurality of second devices based on the public key of the first device, the group security parameter, and the first signature can include that the authentication function entity uses a signature verification algorithm to perform a hash calculation based on the group security parameter to obtain a first verification hash value, and decrypts the first signature based on the public key of the first device to obtain a first decryption value; and authenticates the plurality of second devices based on the first decryption value and the first verification hash value. Wherein, authenticating the plurality of second devices based on the first decryption value and the first verification hash value can include at least one of the following: in the case that the first decryption value and the first verification hash value are the same, it is determined that the authentication of the plurality of second devices is successful; in the case that the first decryption value and the first verification hash value are different, it is determined that the authentication of the plurality of second devices fails.
[0126] In this embodiment, since the first signature is calculated based on the group security parameter calculated based on the first security parameter corresponding to each second device, the authentication function entity verifies the first signature, and at least the plurality of second devices can be authenticated. It should be noted that, since the first signature is also calculated based on the private key of the first device, the authentication function entity verifies the first signature, and in addition to the plurality of second devices, the first device can also be authenticated, that is, the authentication function entity can authenticate the plurality of second devices and the first device based on the public key of the first device, the group security parameter, and the first signature; further, the aforementioned determination of the authentication of the plurality of second devices being successful can mean that the authentication of the first device and the plurality of second devices is successful, and the aforementioned determination of the authentication of the plurality of second devices failing can mean that the authentication of the first device and the plurality of second devices fails.
[0127] In an embodiment, the first signature is calculated based on a private key of the first device, the group security parameter, the identity of each second device, and the identity of the first device. In this embodiment, the authentication function entity authenticates the plurality of second devices based on the first signature can include: authenticating the plurality of second devices based on a public key of the first device, the group security parameter, the identity of each second device, the identity of the first device, and the first signature.
[0128] For example, the authentication function entity authenticates the plurality of second devices based on the public key of the first device, the group security parameter, the identity of each second device, the identity of the first device, and the first signature can be: using a signature verification algorithm to decrypt the first signature based on the public key of the first device to obtain first to-be-verified content, and authenticating the plurality of second devices based on the first to-be-verified content, the group security parameter, the identity of each second device, and the identity of the first device.
[0129] The first to-be-verified content can include: group to-be-verified security parameter, to-be-verified identity of the first device, and to-be-verified identity of each second device. The authentication of the plurality of second devices based on the first to-be-verified content, the group security parameter, the identity of each second device, and the identity of the first device can include one of the following: in the case that the group to-be-verified security parameter is the same as the group security parameter, the to-be-verified identity of the first device is the same as the identity of the first device, and the to-be-verified identity of each second device is respectively the same as the identity of the corresponding second device, it is determined that the authentication of the plurality of second devices is successful; in the case that the group to-be-verified security parameter is different from the group security parameter, and / or the to-be-verified identity of the first device is different from the identity of the first device, and / or the to-be-verified identity of any one second device is different from the identity of the corresponding second device, it is determined that the authentication of the plurality of second devices is failed. For example, the authentication function entity verifying the first signature can be represented as R||UE ID||Tag ID1||……||Tag IDN=Dx(R||UE ID||Tag ID1||……||Tag IDN), where the meaning of each content is the same as in the foregoing embodiments, and no repeated description is given.
[0130] For example, the authentication function entity authenticates the plurality of second devices based on the public key of the first device, the group security parameter, the identity of each second device, the identity of the first device, and the first signature, can include that the authentication function entity uses a signature verification algorithm to hash the group security parameter, the identity of each second device, and the identity of the first device to obtain a second verification hash value, and decrypts the first signature based on the public key of the first device to obtain a first decrypted value; and authenticates the plurality of second devices based on the first decrypted value and the second verification hash value.
[0131] In some possible embodiments, the authentication function entity authenticates the plurality of second devices based on the public key of the first device, the group security parameter, the identity of each second device, the identity of the first device, and the first signature, can include that the authentication function entity uses a signature verification algorithm to hash the group security parameter, the identity of each second device, and the identity of the first device to obtain a second verification hash value, and decrypts the first signature based on the public key of the first device to obtain a first decrypted value; and authenticates the plurality of second devices based on the first decrypted value and the second verification hash value.
[0132] In the embodiment, since the first signature is calculated based on the identity of each second device, the identity of the first device, and the first security parameter corresponding to each second device, the group security parameter is calculated, and thus the authentication function entity verifies the first signature, which can at least authenticate the plurality of second devices and can also authenticate the first device. That is, in the embodiment, the authentication function entity can authenticate the first device and the plurality of second devices based on the public key of the first device, the group security parameter, the identity of each second device, the identity of the first device, and the first signature. Further, the foregoing determination of the authentication success of the plurality of second devices can refer to the determination of the authentication success of the first device and the plurality of second devices, and the foregoing determination of the authentication failure of the plurality of second devices can refer to the determination of the authentication failure of the first device and the plurality of second devices.
[0133] It should be noted that, unless otherwise specified, the following description of the authentication success of the plurality of second devices can be alternatively expressed as the authentication success of the first device and the plurality of second devices, and the following description of the authentication failure of the plurality of second devices can be alternatively expressed as the authentication failure of the first device and the plurality of second devices, which is for the sake of brevity and will not be repeated hereinafter.
[0134] In some possible embodiments, after the authentication function entity obtains the authentication result of the plurality of second devices, the authentication function entity further sends a group response message to the first device. Here, the authentication result of the plurality of second devices can include the authentication success of the plurality of second devices or the authentication failure of the plurality of second devices.
[0135] In one embodiment, in case that the authentication result of the plurality of second devices is authentication failure, the processing of the authentication function entity can comprise: sending a group response message to the first device, the group response message carrying an indication that the authentication result of the plurality of second devices is authentication failure. Correspondingly, the processing of the first device can comprise: receiving the group response message from the authentication function entity. Further, the processing of the first device can further comprise: in case that the group response message indicates that the authentication result of the plurality of second devices is authentication failure, ending the processing.
[0136] In one embodiment, in case that the authentication result of the plurality of second devices is authentication success, the processing of the authentication function entity can comprise: sending a group response message to the first device, the group response message carrying a second signature for authenticating the authentication function entity. Correspondingly, the processing of the first device can comprise: receiving the group response message from the authentication function entity, the group response message carrying the second signature for authenticating the authentication function entity.
[0137] Optionally, the authentication function entity can implicitly indicate to the first device that the authentication result of the plurality of second devices is authentication success by carrying the second signature in the group response message. That is, the first device can determine that the authentication result of the plurality of second devices is authentication success in case that the first device receives the group response message and the group response message carries the second signature.
[0138] Optionally, the authentication function entity can explicitly indicate to the first device that the authentication result of the plurality of second devices is authentication success by carrying an indication that the authentication result of the plurality of second devices is authentication success in the group response message.
[0139] In one embodiment, the second signature is calculated based on a private key of the authentication function entity and an identity of the authentication function entity.
[0140] Optionally, the processing of the authentication function entity for calculating the second signature can comprise: the authentication function entity employs a signature algorithm to calculate the second signature based on a private key of the authentication function entity and an identity of the authentication function entity. The signature algorithm is similar to the aforementioned embodiments and is not repeated here. For example, the calculation of the second signature can be represented as E Kpri (ID NF ), where E is the signature algorithm, K pri is the private key of the authentication function entity, and ID NF is the identity of the authentication function entity.
[0141] Optionally, the process of the authentication function entity calculating the second signature may include: the authentication function entity using a signature algorithm to perform a hash calculation on the identifier of the authentication function entity to obtain a third hash value, and encrypting the third hash value based on the private key of the authentication function entity to obtain the second signature.
[0142] In this embodiment, in addition to carrying a second signature, the group response message may also carry the identifier of the authentication function entity.
[0143] Furthermore, in addition to carrying a second signature and the identifier of the authentication entity, the group response message may also carry a second security parameter. This second security parameter is calculated based on a second random number generated by the authentication entity.
[0144] Specifically, the authentication function entity calculates the second security parameter, which may include: the authentication function entity using a security algorithm to calculate the second security parameter based on the second random number. The method of generating the second random number is not limited in this embodiment.
[0145] Optionally, the security algorithm may be the DH algorithm. The DH algorithm may include at least exponentiation, modulo operations, etc. Correspondingly, the authentication function entity's calculation of the second security parameter may include: the authentication function entity using the DH algorithm to perform exponentiation based on a second random number and a primitive element to obtain a second value, and then using a modulo operation on this second value and a large prime number to calculate the second security parameter. For example, suppose the large prime number is represented as p, the primitive element as g, and the second random number as r. NF The remainder function is represented by mod(); the second safety parameter R can be calculated using the following formula. NF =g rNF mod(p).
[0146] Optionally, the security algorithm may be the ECDH algorithm. The ECDH algorithm may include at least dot multiplication, etc. Correspondingly, the authentication function entity calculating the second security parameter may include: the authentication function entity using the ECDH algorithm to perform a dot multiplication of the second random number and the generator to obtain the second security parameter. For example, assuming the generator is represented as P, and the second random number is represented as r... NF The dot product is represented by "*"; the second safety parameter R can be calculated using the following formula. NF =r NF *P.
[0147] In one embodiment, the second signature is calculated based on the private key of the authentication function entity, the identifier of the authentication function entity, and the second security parameter.
[0148] Optionally, the processing of the authentication function entity for calculating the second signature can include: the authentication function entity employs a signature algorithm to calculate the second signature based on a private key of the authentication function entity, an identity of the authentication function entity and the second security parameter. The signature algorithm is similar to the foregoing embodiment, and thus no repeated description is made. For example, the calculation of the second signature can be represented as E Kpri (ID NF , R NF ), where E is a signature algorithm, K pri is a private key of the authentication function entity, ID NF is an identity of the authentication function entity, and R NF is the second security parameter.
[0149] Optionally, the processing of the authentication function entity for calculating the second signature can include: the authentication function entity employs a signature algorithm to calculate a third hash value based on the identity of the authentication function entity and the second security parameter, encrypts the third hash value based on the private key of the authentication function entity to obtain the second signature.
[0150] In the embodiment, the group response message can further carry the identity of the authentication function entity and the second security parameter in addition to the second signature.
[0151] In some possible implementation, the first device receives the group response message from the authentication entity, and the group response message carries the second signature of the authentication function entity. In this case, the first device can authenticate the authentication function entity based on the second signature.
[0152] In one embodiment, the second signature is calculated based on a private key of the authentication function entity and an identity of the authentication function entity, and the group response message further carries at least the identity of the authentication function entity. In this case, the processing of the first device can include authenticating the authentication function entity based on a public key of the authentication function entity, the identity of the authentication function entity and the second signature.
[0153] The public key of the authentication function entity is preconfigured, and specifically, the public key of the authentication function entity is preconfigured at the first device.
[0154] For example, the authentication of the authentication function entity based on the public key of the authentication function entity, the identity of the authentication function entity and the second signature can be that the first device uses a signature verification algorithm to decrypt the second signature based on the public key of the authentication function entity to obtain the identity of the authentication function entity to be verified, and authenticates the authentication function entity based on the identity of the authentication function entity to be verified and the identity of the authentication function entity. Wherein, the authentication of the authentication function entity based on the identity of the authentication function entity to be verified and the identity of the authentication function entity can include one of the following: in the case that the identity of the authentication function entity to be verified and the identity of the authentication function entity are the same, it is determined that the authentication of the authentication function entity is successful; in the case that the identity of the authentication function entity to be verified and the identity of the authentication function entity are different, it is determined that the authentication of the authentication function entity fails.
[0155] For another example, the authentication of the authentication function entity based on the public key of the authentication function entity, the identity of the authentication function entity and the second signature can be that the first device uses a signature verification algorithm to perform a hash calculation based on the identity of the authentication function entity to obtain a third verification hash value, and decrypts the second signature based on the public key of the authentication function entity to obtain a second decryption value; and authenticates the authentication function entity based on the second decryption value and the third verification hash value. Wherein, the authentication of the authentication function entity based on the second decryption value and the third verification hash value can include at least one of the following: in the case that the second decryption value and the third verification hash value are the same, it is determined that the authentication of the authentication function entity is successful; in the case that the second decryption value and the third verification hash value are different, it is determined that the authentication of the authentication function entity fails.
[0156] In this embodiment, the first device authenticates the second signature generated by the identity of the authentication function entity, which can ensure the accuracy and authenticity of the identity of the authentication function entity, thereby achieving the identity authentication of the authentication function entity.
[0157] In an embodiment, the second signature is calculated based on the private key of the authentication function entity, the identity of the authentication function entity and the second security parameter, and the group response message further carries at least the identity of the authentication function entity and the second security parameter. In this case, the authentication of the authentication function entity based on the public key of the authentication function entity, the identity of the authentication function entity and the second signature includes the authentication of the authentication function entity based on the public key of the authentication function entity, the identity of the authentication function entity, the second signature and the second security parameter.
[0158] For example, the authenticating the authentication function entity based on the public key of the authentication function entity, the identity of the authentication function entity, the second signature, and the second security parameter can be that the first device adopts a signature verification algorithm to decrypt the second signature based on the public key of the authentication function entity to obtain second to-be-verified content, and authenticates the authentication function entity based on the second to-be-verified content, the identity of the authentication function entity, and the second security parameter.
[0159] The second to-be-verified content can include a second to-be-verified security parameter and a to-be-verified identity of the authentication function entity. The authenticating the authentication function entity based on the second to-be-verified content, the identity of the authentication function entity, and the second security parameter can include one of the following: in a case where the second to-be-verified security parameter is the same as the second security parameter and the to-be-verified identity of the authentication function entity is the same as the identity of the authentication function entity, determining that the authentication of the authentication function entity is successful; in a case where the second to-be-verified security parameter is different from the second security parameter and / or the to-be-verified identity of the authentication function entity is different from the identity of the authentication function entity, determining that the authentication of the authentication function entity fails.
[0160] For example, the authenticating the authentication function entity based on the public key of the authentication function entity, the identity of the authentication function entity, the second signature, and the second security parameter can include that the first device adopts a signature verification algorithm to perform a hash calculation on the identity of the authentication function entity and the second security parameter to obtain a fourth verification hash value, and decrypts the second signature based on the public key of the authentication function entity to obtain a second decryption value; and authenticating the authentication function entity based on the second decryption value and the fourth verification hash value.
[0161] The authenticating the authentication function entity based on the second decryption value and the fourth verification hash value can include at least one of the following: in a case where the second decryption value and the fourth verification hash value are the same, determining that the authentication of the authentication function entity is successful; in a case where the second decryption value and the fourth verification hash value are different, determining that the authentication of the authentication function entity fails.
[0162] In this embodiment, the first device authenticates the second signature generated by the identity of the authentication function entity, so that the accuracy and authenticity of the identity of the authentication function entity can be ensured, and thus the identity authentication of the authentication function entity is implemented; further, the authentication of the second security parameter by the first device can ensure the accuracy and authenticity of the second security parameter.
[0163] In a case where the first device determines that the authentication of the authentication function entity fails, the processing of the first device can further include that the first device ends the processing, or the first device sends an indication that the authentication of the authentication function entity fails to the authentication function entity and / or each second device.
[0164] In case the first device determines that the authentication to the authentication function entity is successful, the processing of the first device can further comprise: the first device sending an indication that the authentication to the authentication function entity is successful to the authentication function entity and / or each second device.
[0165] In some possible implementation manners, the authentication request of each second device further carries uplink encryption information corresponding to the second device. In other words, the authentication request of any second device carries uplink encryption information corresponding to the second device.
[0166] Taking a target second device as an example, the authentication request further carries uplink encryption information, which is encrypted based on the first random number and the public key of the authentication function entity.
[0167] In an embodiment, the processing of the target second device can be: encrypting the first random number based on the public key of the authentication function entity to obtain the uplink encryption information.
[0168] Here, the calculation manner of the encryption is not limited in the embodiment. The public key of the authentication function entity can be preconfigured, that is, the public key of the authentication function entity is preconfigured in the target second device. The first random number is the same as that in the foregoing embodiments, and will not be described herein again.
[0169] For example, the target second device can calculate the uplink encryption information as: E Kpub (r1), where E represents an encryption algorithm, K pub is the public key of the authentication function entity, and r1 is the first random number corresponding to the target second device.
[0170] Since the processing of each second device is the same as that of the target second device, the processing manner of each second device for generating the uplink encryption information corresponding to the second device will not be described herein again.
[0171] After receiving the authentication request of each second device, the processing of the first device can further comprise: decrypting the uplink encryption information corresponding to each second device based on the public key of the authentication function entity to obtain the first random number corresponding to each second device. Here, the algorithm of the decryption can be corresponding to the algorithm of the encryption, which will not be limited in the embodiment.
[0172] Still taking any one of the plurality of second devices as a target second device as an example, the process of the first device decrypting the first random number corresponding to the target second device can be: decrypting the uplink encrypted information corresponding to the target second device based on the public key of the authentication function entity to obtain the first random number corresponding to the target second device. Since the process of each second device is the same as that of the target second device, the processing manner of the first device decrypting the first random number corresponding to each second device will not be described one by one here.
[0173] In an embodiment, the uplink encrypted information is encrypted based on the public key of the authentication function entity and the first random number and uplink plaintext data. That is, the process of the target second device can be: encrypting the uplink encrypted information based on the public key of the authentication function entity and the first random number and uplink plaintext data.
[0174] The uplink plaintext data can be service data of the target second device, and the embodiment does not limit the acquisition or obtaining manner thereof.
[0175] For example, the target second device calculating the uplink encrypted information can be expressed as: E Kpub (r1||m1), where E represents an encryption algorithm, K pub is the public key of the authentication function entity, r1 is the first random number corresponding to the target second device, and m1 is the uplink plaintext data of the target second device.
[0176] Since the process of each second device is the same as that of the target second device, the processing manner of each second device generating the uplink encrypted information corresponding thereto will not be described one by one here.
[0177] After receiving the authentication request of each second device, the process of the first device can further include: decrypting the uplink encrypted information corresponding to each second device based on the public key of the authentication function entity to obtain the first random number and uplink plaintext data corresponding to each second device.
[0178] Still taking any one of the plurality of second devices as a target second device as an example, the process of the first device decrypting the first random number corresponding to the target second device can be: decrypting the uplink encrypted information corresponding to the target second device based on the public key of the authentication function entity to obtain the first random number corresponding to the target second device and uplink plaintext data.
[0179] Here, after obtaining the first random number and uplink plaintext data corresponding to the target second device, the first device can only save the first random number corresponding to the target second device and not save the uplink plaintext data of the target second device; or the first device can only save the first random number corresponding to the target second device and save the uplink plaintext data of the target second device.
[0180] Since the processing of each second device is the same as that of the target second device, the processing manner of the first device for decrypting the first random number and the uplink plaintext data corresponding to each second device is not described here.
[0181] It should be noted that the first device can also perform the processing of calculating the first signature and the like provided in the foregoing embodiments on the basis of the first random number corresponding to each second device, which is not repeated here.
[0182] In an embodiment, the processing of the first device can further include sending the uplink encrypted information corresponding to each second device to the authentication function entity. In this embodiment, the group request message can also carry the uplink encrypted information corresponding to each second device. Correspondingly, the processing of the authentication function entity after receiving the group request message further includes that the authentication function entity decrypts the uplink encrypted information corresponding to each second device to obtain the uplink plaintext data corresponding to each second device.
[0183] Still taking the target second device as an example, the authentication function entity decrypting the uplink encrypted information corresponding to each second device to obtain the uplink plaintext data corresponding to each second device can be that the authentication function entity decrypts the uplink encrypted information corresponding to the target second device based on the public key of the authentication function entity to obtain the uplink plaintext data corresponding to the target second device. It should be understood that the first random number corresponding to the target second device can also be obtained after the uplink encrypted information corresponding to the target second device is decrypted, in which case the authentication function entity can ignore or not save the first random number of the target second device, or can save but not use the first random number of the target second device, which is not limited in this embodiment. Since the processing of the authentication function entity for each second device is the same as that for the target second device, the processing manner of the authentication function entity for decrypting the uplink plaintext data corresponding to each second device is not described here.
[0184] In an embodiment, the first device can also only send the uplink plaintext data corresponding to each second device to the authentication function entity, such as that the group request message can also carry the uplink plaintext data corresponding to each second device. In this embodiment, the processing of the authentication function entity after receiving the group request message further includes that the authentication function entity receives and saves the uplink plaintext data corresponding to each second device.
[0185] It should be noted that the authentication function entity can also perform the processing of calculating the second signature and the like provided in the foregoing embodiments on the basis of the uplink plaintext data corresponding to each second device, which is not repeated here.
[0186] In some possible implementation, after receiving the group response message and in the case that the authentication to the authentication function entity succeeds, the first device can further include: calculating a first communication key based on the second security parameter and the first random number corresponding to each of the second devices, where the first communication key is used for communication between the first device and the authentication function entity. Correspondingly, in the case that the authentication to the plurality of second devices succeeds, the method further includes: calculating a first communication key based on the second random number and the group security parameter, where the first communication key is used for communication between the first device and the authentication function entity.
[0187] Here, the first device calculating the first communication key based on the second security parameter and the first random number corresponding to each of the second devices can include: the first device calculating a group random number based on the first random number corresponding to each of the second devices, and performing point multiplication calculation based on the group random number and the second security parameter to obtain the first communication key.
[0188] For example, the first device calculating the group random number based on the first random number corresponding to each of the second devices can refer to: the first device performing addition calculation based on the first random number corresponding to each of the second devices to obtain the group random number. It should be understood that this is only an example, and other calculation manners can also be set according to actual conditions, such as at least one of exclusive-OR calculation, direct connection calculation, etc., which are not limited and exhausted here.
[0189] For example, the first device calculating the first communication key can be represented as: SK = R NF *r, r = r1 + r2 + … + rn, where SK represents the first communication key, R NF represents the second security parameter, “*” represents point multiplication calculation, r represents the group random number, and r1-rn are the first random numbers corresponding to each of the N second devices.
[0190] Correspondingly, the authentication function entity calculating the first communication key based on the second random number and the group security parameter can be: performing point multiplication calculation based on the second random number and the group security parameter to obtain the first communication key. For example, the authentication function entity calculating the first communication key can be represented as: SK = r NF *R, where SK represents the first communication key, r NF is the second random number, and R is the group security parameter.
[0191] In some possible implementation manners, the group response message further carries downlink encryption information corresponding to each second device; the downlink encryption information of each second device is obtained by encrypting downlink plaintext data of the second device based on a second communication key corresponding to the second device, and the second communication key corresponding to each second device is calculated based on the second random number and a first security parameter corresponding to the second device.
[0192] In this embodiment, the downlink plaintext data of different second devices in the plurality of second devices can be the same or different, and the embodiment is not limited in this regard.
[0193] The authentication function entity can start to calculate the second communication key corresponding to each second device and encrypt the downlink plaintext data of each second device after successfully authenticating the plurality of second devices, or the authentication function entity can start to calculate the second communication key corresponding to each second device and encrypt the downlink plaintext data of each second device after successfully authenticating the plurality of second devices and completing the calculation of the second signature. As long as the processing time of starting to calculate the second communication key corresponding to each second device and encrypting the downlink plaintext data of each second device is before sending the group response message, the embodiment is not limited in this regard.
[0194] The authentication function entity can calculate the second communication key corresponding to each second device by performing point multiplication calculation based on the second random number and the first security parameter corresponding to each second device. For example, the authentication function entity can calculate the second communication key corresponding to the target second device, and the calculation can be represented as: sk1=r NF *R1, where sk1 represents the second communication key corresponding to the target second device, r NF represents the second random number, and R1 represents the first security parameter corresponding to the target second device.
[0195] The authentication function entity can calculate the downlink encryption information of each second device by encrypting the downlink plaintext data of the second device based on the second communication key corresponding to the second device. For example, the authentication function entity can calculate the downlink encryption information of the target second device, and the calculation can be represented as: E sk1 (M), where E represents encryption calculation, M represents the downlink plaintext data, and sk1 is the second communication key corresponding to the target second device.
[0196] In the embodiment, after the first device receives the group response message, the processing after the authentication function entity is successfully authenticated based on the second signature can further include: sending an authentication response to each second device, wherein the authentication response corresponding to each second device carries the second security parameter.
[0197] Here, since the second security parameter sent by the first device to each second device is the same, the authentication response can be a broadcast message; of course, the first device can also send a corresponding authentication response to each second device respectively, and at this time the authentication response corresponding to each second device can be a unicast message.
[0198] Taking a target second device as an example, the processing of the target second device after sending the authentication request can include: receiving an authentication response from the first device, wherein the authentication response carries a second security parameter; and calculating a second communication key based on the second security parameter and the first random number.
[0199] Calculating a second communication key based on the second security parameter and the first random number can include: the target second device performing point multiplication calculation on the second security parameter and the first random number corresponding to itself to obtain the second communication key. For example, the processing of the target second device to calculate the second communication key can be represented as sk1 = r1 * R NF , wherein r1 is the first random number corresponding to the target second device, R NF is the second security parameter, and sk1 is the second communication key corresponding to the target second device.
[0200] Since each second device performs the same processing as the target second device to obtain the second communication key corresponding to each second device respectively, details are not repeated here.
[0201] Further, since the group response message in the embodiment also carries the downlink encryption information of each second device, correspondingly, the authentication response corresponding to each second device also carries the downlink encryption information.
[0202] Here, although the second security parameter sent by the first device to each second device is the same, the downlink encryption information of different second devices can be different, so the authentication response corresponding to each second device can be a unicast message.
[0203] Taking a target second device as an example, the authentication response also carries downlink encryption information, and the processing of the target second device further includes: decrypting the downlink encryption information based on the second communication key to obtain downlink plaintext information. For example, the processing of the target second device to calculate the downlink plaintext data can be represented as: M = D sk1 (E sk1(M), where D denotes a decryption calculation, E denotes an encryption calculation, and the rest of the formula is the same as the previous embodiment, which will not be repeated here. Since each second device performs the same processing as the target second device, the downlink plaintext data corresponding to each second device is obtained, which will not be repeated here.
[0204] In some embodiments, the group response message also carries the second communication key corresponding to each second device. In this embodiment, the authentication function entity can also send the second communication key corresponding to each second device to the first device, so that the first device and each second device can also communicate. It should be pointed out that in this embodiment, after the first device receives the second communication key corresponding to each second device, it locally saves the second communication key corresponding to each second device, but does not send the second communication key corresponding to any second device to any second device.
[0205] In some possible implementations, the authentication request reported by the plurality of second devices can be triggered by the first device.
[0206] Before receiving the authentication request sent by each second device, the first device can further include: sending a trigger message to each second device, wherein the trigger message is used to trigger each second device to send the authentication request. Correspondingly, taking the target second device as an example, in addition to sending the authentication request to the first device, the method further includes: receiving a trigger message from the first device, wherein the trigger message is used to trigger the target second device to send the authentication request.
[0207] The trigger message can carry a group identifier.
[0208] Optionally, the trigger message can be a power supply signal or a power supply message, which is used to provide environmental power supply for each second device in the plurality of second devices. Optionally, the trigger message can be a paging message, which is used to page the plurality of second devices. In this case, the authentication request sent by each second device in the plurality of second devices can be a paging response. Optionally, the trigger message can be a discovery message, which is used to discover the plurality of second devices. In this case, the authentication request sent by each second device in the plurality of second devices can be a discovery response. Optionally, the trigger message can be a group authentication trigger message, which is used to trigger the group to perform authentication. In this case, the authentication request sent by each second device can be an authentication response.
[0209] FIG. 5 is a schematic flowchart of an authentication method performed by a first device according to an embodiment of the present application. The method includes at least part of the following content.
[0210] S510, receiving a group response message from the authentication function entity, wherein the group response message carries a second signature for authenticating the authentication function entity.
[0211] FIG. 6 is a schematic flowchart of an authentication method performed by an authentication function entity according to an embodiment of the present application. The method comprises at least part of the following.
[0212] S610, sending a group response message to the first device, wherein the group response message carries a second signature for authenticating the authentication function entity.
[0213] The first device, the authentication function entity and the foregoing embodiments are the same as described above, and will not be repeated.
[0214] In a possible implementation, before the first device receives the group response message from the authentication function entity, the method can further comprise: receiving authentication requests from a plurality of second devices, wherein each authentication request from each second device of the plurality of second devices carries an identity of the second device; and sending a group request message to the authentication function entity, wherein the group request message carries identities of the plurality of second devices and an identity of the first device.
[0215] Correspondingly, before the authentication function entity sends the group response message to the first device, the method further comprises: receiving a group request message from the first device, wherein the group request message carries identities of a plurality of second devices and an identity of the first device.
[0216] The second device is described as in the foregoing embodiments, and will not be repeated.
[0217] Optionally, before the first device receives the authentication request from the plurality of second devices, the method can further comprise: sending a trigger message to each second device, wherein the trigger message is used to trigger the second device to send the authentication request. The related processing and description of the trigger message are the same as in the foregoing embodiments, and will not be repeated.
[0218] In some possible implementations, the group response message further carries an identity of the authentication function entity. The second signature is calculated based on a private key of the authentication function entity and the identity of the authentication function entity. After the first device receives the group response message, the processing can comprise: authenticating the authentication function entity based on a public key of the authentication function entity, the identity of the authentication function entity and the second signature.
[0219] Further, the group response message further carries a second security parameter, the second security parameter is calculated based on a second random number, the second random number is generated by the authentication function entity. The second signature is calculated based on a private key of the authentication function entity, an identity of the authentication function entity and the second security parameter. The first device authenticates the authentication function entity based on a public key of the authentication function entity, the identity of the authentication function entity and the second signature, including authenticating the authentication function entity based on the public key of the authentication function entity, the identity of the authentication function entity, the second signature and the second security parameter.
[0220] As to the authentication function entity calculating the second signature, the first device verifying the second signature to authenticate the authentication function entity and the like in the present embodiment, the processes are the same as the processes related to the second signature in the foregoing embodiments, and thus will not be repeated.
[0221] The above various embodiments differ from the foregoing embodiments in that, since the authentication function entity does not need to perform the authentication process for each second device and first device, in the present embodiment, each second device can no longer generate the first random number, and further each second device can no longer calculate the first security parameter, that is, the authentication function entity can only need to know the identity of each second device and the identity of the first device, and further can determine the identity of each second device and the first device and their relationship, and then perform the process of calculating the second signature and sending to the first device.
[0222] It should be further pointed out that in the scheme provided in the present embodiment, the first device, each second device and the authentication function entity, in addition to being able to perform the second signature related processes, can also perform at least part of the processes provided by the various embodiments corresponding to the foregoing FIG. 2 to FIG. 4, but for the sake of brevity, will not be repeated.
[0223] The applicable architecture of the authentication method provided by each of the embodiments is described in combination with FIG. 7, in which network elements that can be included in the system are shown, such as the UE, the (R)AN, the UPF, the DN, the NSSAAF, the NSSAF, the SCP, the EASDF, the NSACF, and the like. The 3GPP system needs to support a new function, that is, an A-IoT group authentication function (A-NF). The A-IoT group authentication function can be set or configured in a newly added core network dedicated network element, or the A-IoT group authentication function can be set or configured in a core network network element with at least one of the AMF, the SMF, the AUSF, the UDM, the HSS, the ARPF, the BSF, the SEAF, or the like, or the A-IoT group authentication function can also be completed in cooperation with the AUSF and the UDM. It should be understood that in FIG. 7, the service interfaces provided by each network element to the outside are also shown, for example, the service interface provided by the AMF to the outside can be Namf, the service interface provided by the SMF to the outside can be Nsmf, and the like, and the service interface provided by the newly added network element A-NF to the outside can be Nanf. This is only an exemplary description, and the service interfaces provided by other network elements to the outside are explicitly shown in FIG. 7, and thus are not described herein.
[0224] In combination with FIG. 8a, an exemplary description of the foregoing authentication method is given by taking a plurality of second devices as Tags and a first device as a proxy node as an example.
[0225] Step 800: Preconfigure the public key K of the network side authentication function entity in the Tag group pub . The proxy node is configured with a public-private key pair (x, y) of the proxy node and the public key K of the network side authentication function entity pub . The network side is configured with a public-private key pair (K pub , K pri ) of the authentication function entity.
[0226] Step 801: Take any one of the Tag group as Tag1 as an example, and Tag1 selects a first random number r1 to calculate a first security parameter R1.
[0227] Here, R1 has multiple calculation methods, for example, one method is to use the DH key exchange algorithm, in which R1 = g r1 mod (p), where p is a large prime number and g is a primitive element of p; another calculation method uses the ECDH algorithm, in which R1 = r1*P, * is a point multiplication calculation, and P is a generator of the additive cyclic group GP, which is a public parameter.
[0228] Step 802: The multiple Tags in the Tag group send an authentication request (Tag Auth-Req) of each Tag to the proxy node, wherein the authentication request of Tag 1 includes Tag ID 1, GID (optionally), first security parameter R1, and can further include uplink encryption information E Kpub (r1||m1) (optionally).
[0229] Step 803: The proxy node aggregates the authentication requests of each Tag with the same GID in a period of time, calculates the group security parameter R, and calculates the first signature; the detailed description of calculating the group security parameter R and the first signature in this step is the same as the foregoing embodiment, and will not be described herein.
[0230] Step 804: The proxy node sends a group authentication request (i.e., the group request message in the foregoing embodiment) to the authentication function entity, wherein the group authentication request can include GID (optionally), the first signature, the public key x of the proxy node, the group security parameter R, and the first security parameter (R1, R2, …) of each Tag.
[0231] Step 805: The authentication function entity verifies the first signature using the public key x of the proxy node, and authenticates the Tag group by verifying the first signature; then the authentication function entity calculates the second signature E Kpri (ID NF ); selects a second random number r NF , calculates the second security parameter R NF =g rNF mod(p); calculates the symmetric key (i.e., the first communication key) SK=r NF *R with the proxy node; calculates the symmetric key (i.e., the second communication key corresponding to each Tag) with each Tag and calculates the downlink encryption information of each Tag; for example, the symmetric key sk1 of Tag 1 is r NF *R1, and the downlink encryption information E sk1 (M) of Tag 1, wherein M is downlink plaintext information.
[0232] Here, the authentication function entity can also authenticate the proxy node by verifying the first signature.
[0233] Step 806: The authentication function entity sends a group authentication response (i.e., the group response message in the foregoing embodiment) to the proxy node, including the second signature E Kpri (ID NF )||ID NF , the downlink encryption information of each Tag, the second security parameter R NF , and the symmetric key of each Tag.
[0234] Step 807: The proxy node verifies the second signature, and if the verification is successful, step 808 is performed; if the verification fails, the process can be ended, and the processing of the verification failure is not described in detail here.
[0235] Step 808: The proxy node broadcasts or unicasts an authentication response (such as a Tag Auth-Res message) to the Tag group, and the authentication response corresponding to each Tag includes the downlink encryption information of the Tag, the second security parameter R NF .
[0236] Step 809: Each Tag calculates the shared key (i.e., the second communication key corresponding to each Tag) between the authentication function entity, and decrypts the downlink encryption information based on the shared key. Taking Tag1 as an example, Tag1 calculates the shared key sk1 = r1 * R NF between the authentication function entity, and decrypts the downlink message M = D sk1 (E sk1 (M)), where E denotes encryption and D denotes decryption.
[0237] For the example of the foregoing FIG. 8a, it should be noted that the square brackets [] in FIG. 8a represent possible parameters, and the dashed line represents a device or message that may exist.
[0238] In the example of FIG. 8a, the proxy node can be at least one of an access network device, such as a base station, gNB, eNB, (R)AN node, etc. Taking the base station as an example, in the scenario of the Tag directly connecting to the base station, the base station aggregates the authentication requests from the Tags, and the 5GC or AF can configure the group information of the Tags to the base station. In the example of FIG. 8a, the proxy node can be a terminal, such as a UE, which can be connected to the network side (authentication function entity) through its corresponding access network device (base station, gNB, eNB, (R)AN node, etc.). In this case, the UE also needs to interact with the authentication function entity through its corresponding access network device.
[0239] The authentication function entity illustrated in FIG. 8a is described in the same way as in the foregoing embodiments, and no repeated description is given.
[0240] In combination with FIG. 8b, another exemplary description of the foregoing authentication method is given, taking a plurality of second devices as Tags (s) and a first device as a proxy node as an example:
[0241] Step 800 of FIG. 8b is the same as step 800 of the foregoing FIG. 8a, and no further description is given.
[0242] Step 801': the proxy node broadcasts at least one of an authentication request of the Tag (group), a paging of the Tag (group), a discovery request of the Tag (group), triggers group authentication of the Tag, and the at least one of the authentication request of the Tag (group), the paging of the Tag (group), and the discovery request of the Tag (group) can also carry the GID.
[0243] Step 801 of FIG. 8b is the same as the aforementioned step 801 of FIG. 8a, and will not be described herein.
[0244] In step 802', each tag sends any one of an authentication response, a paging response, and a discovery response based on the triggering mode. Taking Tag1 as an example, the authentication response, the paging response, and the discovery response of Tag1 can carry the Tag ID1, the GID (optionally), the first security parameter R1, and can also include the uplink encryption information E Kpub (r1||m1) (optionally).
[0245] Steps 803-809 of FIG. 8b are the same as the aforementioned steps 803-809 of FIG. 8a, and will not be described herein.
[0246] In combination with FIG. 9, taking any one of the second devices as a zero-power device as an example, the possible architecture of the second device accessing the cellular system in the embodiment is exemplarily described: in part 901 of FIG. 9, for the zero-power communication system based on the cellular, wherein the base station provides the wireless energy supply signal and the trigger signal to the zero-power device. The wireless energy supply signal is used to provide energy to the zero-power device; the trigger signal can carry the control information sent to the zero-power device; the zero-power device transmits the information to the base station in the form of backscatter. Case 1 is the cellular direct connection, and the base station and the zero-power device directly communicate. The base station provides the wireless energy supply signal and the trigger signal to the zero-power device. Case 2 is the zero-power wake-up, and the zero-power device can be combined with the traditional terminal and undertake and complete some low-power operations to assist the energy saving of the traditional terminal, wherein the base station sends the wake-up signal when it needs to communicate with the traditional terminal, and the zero-power device wakes up when detecting the wake-up signal. Case 3 is the auxiliary energy supply cellular direct connection, and the zero-power device can not only obtain the wireless energy supply from the base station in communication with it, but also obtain the energy supply from the third party device. In part 902 of FIG. 9, for the zero-power communication system based on the cellular and the sidelink communication, wherein mode one is the intelligent terminal auxiliary energy supply triggered zero-power communication, mode two is the network energy supply / triggered zero-power sidelink communication, mode three is the intelligent terminal auxiliary energy supply zero-power communication, and mode four is the network controlled zero-power sidelink communication.
[0247] For the asymmetric encryption system of the foregoing embodiment, the asymmetric encryption system, also known as a public key encryption mechanism, is characterized in that two related keys are used to separate the encryption and decryption capabilities, one of which is public and can be understood as being capable of being transmitted over the air interface, referred to as a public key (such as the public key x of the first device in the foregoing embodiment and the public key K pub of the authentication function entity) for encryption; the other is user-specific and thus secret, and can be understood as being held only by the user himself, referred to as a private key (such as the private key y of the first device in the foregoing embodiment and the private key K pri of the authentication function entity) for decryption. Common encryption algorithms include RSA algorithms, elliptic curve algorithms, and SM2 algorithms.
[0248] In the foregoing asymmetric encryption system, the key generation manner can adopt a DH key exchange algorithm (which will be referred to as a DH algorithm in the present application), which is a typical key generation manner in the asymmetric encryption system. The only purpose of the algorithm is to enable two users (or two devices for transmitting and receiving messages) to securely exchange keys to obtain a shared session key. The security of the algorithm is based on the difficulty of solving a discrete logarithm. The DH algorithm is exemplarily described in combination with FIG. 10: p (a large prime number) and g (a primitive element of p) are elements known to user A and user B (that is, two devices A and B for transmitting and receiving messages, referred to as A and B hereinafter), A and B select random numbers a1 and b1 (a1 < p and b1 < p) respectively, A calculates Y A = g a1 mod p based on the random number a1, B calculates Y B = g b1 mod p based on the random number b1, then A transmits Y A to B, B transmits Y B to A, and finally A calculates K = Y B a1 = g a1b1 mod p, and B also calculates K = Y A b1 = g a1b1 mod p, that is, the same K obtained is taken as a shared key of A and B. In the processing of A and B described above, since the random numbers a1 and b1 selected by A and B are secret, an eavesdropper can only obtain Y A and Y B transmitted over the air interface, and the eavesdropper cannot calculate K if the eavesdropper wants to calculate K, and thus the eavesdropper cannot calculate K. Further, there is also an ECDH algorithm for a DH key exchange on an elliptic curve, which is referred to as an ECDH algorithm. The ECDH algorithm is a variant of the DH algorithm, which will not be described herein again.
[0249] The digital signature (i.e., the first signature and the second signature in the foregoing embodiment) is developed from the public key cryptography, and the sender uses the ciphertext obtained by encrypting the message M by using the private key of the sender as the digital signature of M, and the receiver decrypts the message by using the public key of the sender. Since only the sender has the private key, the receiver can believe that the message received by the receiver is indeed from the legitimate sender. Commonly used signature algorithms include RSA, SM2, JSON Web Signatures (JWS) algorithm, and an elliptic curve-based signature algorithm, which are not described herein again.
[0250] The prior art authentication process has the characteristics of high complexity of key architecture, interaction process, and secure computation. For a zero-power device (i.e., any one of the second devices in the foregoing embodiment), the characteristics are low computing and storage capacity, and the ability to use only environmental power supply. These characteristics make the access authentication technology unsuitable for the zero-power device. In addition, there can be a large number of zero-power devices in a region. If a large number of zero-power devices access the network in a short time, a large amount of authentication signaling overhead and network computing overhead will be brought to the network, which can cause network congestion and affect the quality of service.
[0251] By using the method provided in the embodiment, the first device calculates a first signature according to the first security parameter carried in the authentication request of each second device in the plurality of second devices, and sends a group request message carrying the first signature to the authentication function entity, so that the authentication function entity authenticates the plurality of second devices based on the first signature. In this way, the problem of network congestion that can be caused by the authentication function entity of the network side individually authenticating each second device in the case that a large number of second devices access the network in a short time is avoided, the communication signaling overhead between the first device and the authentication function entity is reduced, and the efficiency of the authentication processing is improved.
[0252] FIG. 11 is a schematic diagram of the composition structure of the first device according to an embodiment of the present application, which includes:
[0253] The first communication unit 1101 is configured to receive authentication requests from a plurality of second devices, wherein the authentication request of each second device in the plurality of second devices carries a first security parameter; and send a group request message to an authentication function entity, wherein the group request message carries a first signature used for authenticating the plurality of second devices, and the first signature is calculated based on the first security parameter corresponding to each second device.
[0254] The first signature is calculated based on the private key of the first device and a group security parameter, wherein the group security parameter is calculated based on the first security parameter corresponding to each second device.
[0255] The group request message further carries the group security parameter.
[0256] The first signature is calculated based on a private key of the first device, the group security parameter, the identity of each second device and the identity of the first device.
[0257] The authentication request of each second device further carries the identity of each second device.
[0258] The group request message further carries the identity of the first device, the identity of each second device.
[0259] The authentication request of each second device further carries a group identity.
[0260] The group request message further carries at least one of the following: the group identity, the first security parameter corresponding to each second device, the public key of the first device.
[0261] The first communication unit is configured to receive a group response message from the authentication function entity, wherein the group response message carries a second signature used to authenticate the authentication function entity.
[0262] The group response message further carries an identity of the authentication function entity.
[0263] As shown in FIG. 11, the first device further includes a first processing unit 1102:
[0264] The first processing unit is configured to authenticate the authentication function entity based on the public key of the authentication function entity, the identity of the authentication function entity and the second signature.
[0265] The group response message further carries a second security parameter.
[0266] The first processing unit is configured to authenticate the authentication function entity based on the public key of the authentication function entity, the identity of the authentication function entity, the second signature and the second security parameter.
[0267] The authentication request of each second device further carries uplink encryption information corresponding to each second device.
[0268] The first processing unit is configured to decrypt the uplink encryption information corresponding to each second device based on the public key of the authentication function entity to obtain a first random number corresponding to each second device.
[0269] The first processing unit is configured to calculate a first communication key based on the second security parameter and the first random number corresponding to each second device, wherein the first communication key is used for communication between the first device and the authentication function entity.
[0270] The group request message further carries uplink encryption information corresponding to each second device.
[0271] The first communication unit is configured to send an authentication response to each second device, wherein the authentication response corresponding to each second device carries the second security parameter.
[0272] The group response message further carries downlink encryption information of each second device; and the authentication response corresponding to each second device further carries downlink encryption information.
[0273] The group response message further carries a second communication key corresponding to each second device.
[0274] The public key of the authentication function entity is preconfigured.
[0275] The first communication unit is configured to send a trigger message to each second device, wherein the trigger message is used to trigger each second device to send the authentication request.
[0276] The first device includes one of the following: a terminal and an access network device; the second device includes a zero-power device; and the authentication function entity is deployed in at least one of the following: an application function (AF), an access and mobility management function (AMF), a session management function (SMF), an authentication service function (AUSF), a unified data management function (UDM), a unified data repository (UDR), a home subscription system (HSS), an authentication credential processing function (ARPF), a bootstrapping service function (BSF), a security anchor function (SEAF), and a core network dedicated network element.
[0277] FIG. 12 is a schematic diagram of the composition structure of an authentication function entity according to an embodiment of the present application, including:
[0278] The second communication unit 1201 is configured to receive a group request message from a first device, wherein the group request message carries a first signature used to authenticate a plurality of second devices, and the first signature is calculated based on a first security parameter corresponding to each second device in the plurality of second devices.
[0279] As shown in FIG. 12, the authentication function entity further includes a second processing unit 1202:
[0280] The group request message further carries a group security parameter; and the second processing unit is configured to authenticate the plurality of second devices based on a public key of the first device, the group security parameter, and the first signature.
[0281] The second processing unit is configured to authenticate the plurality of second devices based on the public key of the first device, the group security parameter, the identity of each second device, the identity of the first device, and the first signature.
[0282] The group request message further carries the identity of the first device and the identity of each second device.
[0283] The group request message further carries at least one of the following: a group identity, a first security parameter corresponding to each second device, and a public key of the first device.
[0284] The group request message further carries uplink encryption information corresponding to each second device; and the second processing unit is configured to decrypt the uplink encryption information corresponding to each second device to obtain uplink plaintext data corresponding to each second device.
[0285] The second communication unit is configured to send a group response message to the first device, where the group response message carries a second signature used to authenticate the authentication function entity.
[0286] The group response message further carries an identity of the authentication function entity.
[0287] The second signature is calculated based on a private key of the authentication function entity and the identity of the authentication function entity.
[0288] The group response message further carries a second security parameter, which is calculated based on a second random number generated by the authentication function entity.
[0289] The second signature is calculated based on a private key of the authentication function entity, the identity of the authentication function entity, and the second security parameter.
[0290] The second processing unit is configured to calculate a first communication key based on the second random number and the group security parameter, where the first communication key is used for communication between the first device and the authentication function entity.
[0291] The group response message further carries downlink encryption information corresponding to each second device; the downlink encryption information of each second device is obtained by encrypting downlink plaintext data of each second device based on a second communication key corresponding to each second device, which is calculated based on the second random number and a first security parameter corresponding to each second device.
[0292] The group response message further carries the second communication key corresponding to each second device.
[0293] The first device comprises one of a terminal and an access network device; the second device comprises a zero-power device; the authentication function entity is deployed in at least one of an application function (AF), an access and mobility management function (AMF), a session management function (SMF), an authentication service function (AUSF), a unified data management function (UDM), a unified data repository (UDR), a home subscriber system (HSS), an authentication credential processing function (ARPF), a bootstrapping service function (BSF), a security anchor function (SEAF), and a core network-specific network element.
[0294] Fig. 13 is a schematic diagram of a constituent structure of a second device according to an embodiment of the present application, comprising:
[0295] A third communication unit 1301 is configured to send an authentication request to a first device, wherein the authentication request carries a first security parameter corresponding to the target second device, and the first security parameter corresponding to the target second device is used to calculate a first signature.
[0296] The first security parameter corresponding to the target second device is calculated based on a first random number, and the first random number is generated by the target second device.
[0297] The authentication request further carries an identifier of the target second device.
[0298] The authentication request further carries a group identifier.
[0299] The authentication request further carries uplink encryption information, and the uplink encryption information is obtained by encrypting the first random number based on a public key of an authentication function entity.
[0300] The uplink encryption information is obtained by encrypting the first random number and uplink plaintext data based on the public key of the authentication function entity.
[0301] The public key of the authentication function entity is preconfigured.
[0302] As shown in Fig. 13, the second device further comprises a third processing unit 1302:
[0303] The third processing unit is configured to calculate a second communication key based on the second security parameter and the first random number.
[0304] The third communication unit is configured to receive an authentication response from the first device, wherein the authentication response carries a second security parameter.
[0305] The authentication response further carries downlink encryption information; and the third processing unit is configured to decrypt the downlink encryption information based on the second communication key to obtain downlink plaintext information.
[0306] The third communication unit is configured to receive a trigger message from the first device, wherein the trigger message is used to trigger a target second device to send the authentication request.
[0307] The first device comprises one of a terminal and an access network device, and the second device comprises a zero-power device.
[0308] An embodiment of the present application further provides a first device, which comprises:
[0309] The first communication unit is configured to receive a group response message from an authentication function entity, wherein the group response message carries a second signature used to authenticate the authentication function entity.
[0310] The group response message further carries an identifier of the authentication function entity.
[0311] The first device further comprises a first processing unit.
[0312] The first processing unit is configured to authenticate the authentication function entity based on a public key of the authentication function entity, the identifier of the authentication function entity and the second signature.
[0313] The group response message further carries a second security parameter.
[0314] The first processing unit is configured to authenticate the authentication function entity based on the public key of the authentication function entity, the identifier of the authentication function entity, the second signature and the second security parameter.
[0315] The first communication unit is configured to receive authentication requests from a plurality of second devices, wherein the authentication request of each second device of the plurality of second devices carries an identifier of each second device; and send a group request message to the authentication function entity, wherein the group request message carries identifiers of the plurality of second devices and an identifier of the first device.
[0316] The first communication unit is configured to send a trigger message to each second device, wherein the trigger message is used to trigger each second device to send the authentication request.
[0317] An embodiment of the present application further provides an authentication function entity, which comprises:
[0318] The second communication unit is configured to send a group response message to a first device, wherein the group response message carries a second signature used to authenticate the authentication function entity.
[0319] The group response message further carries an identifier of the authentication function entity.
[0320] The second signature is calculated based on a private key of the authentication function entity, an identity of the authentication function entity, and the second security parameter.
[0321] The group response message further carries a second security parameter, which is calculated based on a second random number generated by the authentication function entity.
[0322] The second signature is calculated based on a private key of the authentication function entity, an identity of the authentication function entity, and the second security parameter.
[0323] The second communication unit is configured to receive a group request message from the first device, wherein the group request message carries identities of a plurality of second devices and an identity of the first device.
[0324] The device according to the embodiments of the present application can realize the corresponding functions of each device in the authentication method embodiments described above. The processes, functions, implementation manners and advantages of each module (sub-module, unit or component, etc.) in the device can be referred to the corresponding description in the method embodiments described above, and will not be described here again. It should be noted that the functions described with respect to each module (sub-module, unit or component, etc.) in the device according to the embodiments of the present application can be realized by different modules (sub-modules, units or components, etc.), or can be realized by the same module (sub-module, unit or component, etc.).
[0325] FIG. 14 is a schematic structural diagram of a communication device 1400 according to an embodiment of the present application. The communication device 1400 includes a processor 1410, which can invoke and run a computer program from a memory to enable the communication device 1400 to implement the method according to the embodiments of the present application.
[0326] In a possible implementation, the communication device 1400 can further include a memory 1420. The processor 1410 can invoke and run a computer program from the memory 1420 to enable the communication device 1400 to implement the method according to the embodiments of the present application. The memory 1420 can be a separate device independent of the processor 1410, or can be integrated in the processor 1410.
[0327] In a possible implementation, the communication device 1400 can further include a transceiver 1430, and the processor 1410 can control the transceiver 1430 to communicate with other devices, specifically, to send information or data to other devices, or to receive information or data sent by other devices. The transceiver 1430 can include a transmitter and a receiver. The transceiver 1430 can further include an antenna, and the number of antennas can be one or more.
[0328] An embodiment of the present application provides a first device, comprising: a processor, a memory in communication with the processor, the memory configured to store instructions which, when executed by the processor, cause the first device to perform: receiving authentication requests from a plurality of second devices, wherein each authentication request of the plurality of second devices carries a first security parameter; sending a group request message to an authentication function entity, wherein the group request message carries a first signature used for authenticating the plurality of second devices, the first signature being calculated based on the first security parameter corresponding to each second device.
[0329] The first signature is calculated based on a private key of the first device and a group security parameter, wherein the group security parameter is calculated based on the first security parameter corresponding to each second device.
[0330] The group request message further carries the group security parameter.
[0331] The first signature is calculated based on the private key of the first device, the group security parameter, an identity of each second device and an identity of the first device.
[0332] The authentication request of each second device further carries the identity of each second device.
[0333] The group request message further carries the identity of the first device and the identity of each second device.
[0334] The authentication request of each second device further carries a group identity.
[0335] The group request message further carries at least one of the following: the group identity, the first security parameter corresponding to each second device, and a public key of the first device.
[0336] The instructions cause the first device to perform: receiving a group response message from the authentication function entity, wherein the group response message carries a second signature used for authenticating the authentication function entity.
[0337] The group response message further carries an identity of the authentication function entity.
[0338] The instructions cause the first device to perform: authenticating the authentication function entity based on a public key of the authentication function entity, the identity of the authentication function entity and the second signature.
[0339] The group response message further carries a second security parameter.
[0340] The instructions cause the first device to perform: authenticating the authentication function entity based on the public key of the authentication function entity, the identity of the authentication function entity, the second signature, and the second security parameter.
[0341] The authentication request of each second device further carries uplink encryption information corresponding to the second device.
[0342] The instructions cause the first device to perform: decrypting the uplink encryption information corresponding to each second device based on the public key of the authentication function entity to obtain a first random number corresponding to each second device.
[0343] The instructions cause the first device to perform: calculating a first communication key based on the second security parameter and the first random number corresponding to each second device, wherein the first communication key is used for communication between the first device and the authentication function entity.
[0344] The group request message further carries uplink encryption information corresponding to each second device.
[0345] The instructions cause the first device to perform: sending an authentication response to each second device, wherein the authentication response corresponding to each second device carries the second security parameter.
[0346] The group response message further carries downlink encryption information of each second device; and the authentication response corresponding to each second device further carries downlink encryption information.
[0347] The group response message further carries a second communication key corresponding to each second device.
[0348] The public key of the authentication function entity is preconfigured.
[0349] The instructions cause the first device to perform: sending a trigger message to each second device, wherein the trigger message is used to trigger each second device to send the authentication request.
[0350] The first device includes one of the following: a terminal, an access network device; the second device includes a zero-power device; and the authentication function entity is deployed in at least one of the following: an application function (AF), an access and mobility management function (AMF), a session management function (SMF), an authentication service function (AUSF), a unified data management function (UDM), a unified data repository (UDR), a home subscription system (HSS), an authentication credential storage and processing function (ARPF), a bootstrapping service function (BSF), a security anchor function (SEAF), and a core network dedicated network element.
[0351] An authentication function entity is provided in an embodiment of the present application, comprising: a processor, a memory in communication with the processor, the memory configured to store instructions which, when executed by the processor, cause the authentication function entity to perform: receiving a group request message from a first device, wherein the group request message carries a first signature for authenticating a plurality of second devices, the first signature being calculated based on a first security parameter corresponding to each of the plurality of second devices.
[0352] The group request message further carries a group security parameter; and the instructions cause the authentication function entity to perform: authenticating the plurality of second devices based on a public key of the first device, the group security parameter, and the first signature.
[0353] The instructions cause the authentication function entity to perform: authenticating the plurality of second devices based on a public key of the first device, the group security parameter, an identity of each of the second devices, an identity of the first device, and the first signature.
[0354] The group request message further carries: the identity of the first device and the identity of each of the second devices.
[0355] The group request message further carries at least one of: a group identity, the first security parameter corresponding to each of the second devices, and the public key of the first device.
[0356] The group request message further carries uplink encryption information corresponding to each of the second devices; and the instructions cause the authentication function entity to perform: decrypting the uplink encryption information corresponding to each of the second devices to obtain uplink plaintext data corresponding to each of the second devices.
[0357] The instructions cause the authentication function entity to perform: sending a group response message to the first device, wherein the group response message carries a second signature for authenticating the authentication function entity.
[0358] The group response message further carries an identity of the authentication function entity.
[0359] The second signature is calculated based on a private key of the authentication function entity and the identity of the authentication function entity.
[0360] The group response message further carries a second security parameter, the second security parameter being calculated based on a second random number generated by the authentication function entity.
[0361] The second signature is calculated based on a private key of the authentication function entity, the identity of the authentication function entity, and the second security parameter.
[0362] The instructions cause the authentication function entity to perform: calculating a first communication key based on the second random number and the group security parameter, wherein the first communication key is used for communication between the first device and the authentication function entity.
[0363] The group response message further carries downlink encryption information corresponding to each second device; the downlink encryption information of each second device is obtained by encrypting downlink plaintext data of each second device based on a second communication key corresponding to each second device, and the second communication key corresponding to each second device is calculated based on the second random number and a first security parameter corresponding to each second device.
[0364] The group response message further carries a second communication key corresponding to each second device.
[0365] The first device includes one of the following: a terminal, an access network device; the second device includes a zero-power device; the authentication function entity is deployed in at least one of the following: an application function (AF), an access and mobility management function (AMF), a session management function (SMF), an authentication service function (AUSF), a unified data management function (UDM), a unified data storage (UDR), a home subscription system (HSS), an authentication credential storage and processing function (ARPF), a bootstrapping service function (BSF), a security anchor function (SEAF), and a core network dedicated network element.
[0366] Embodiments of the present application provide a second device, comprising: a processor, a memory in communication with the processor, the memory being configured to store instructions, when the instructions are executed by the processor, the instructions cause the second device to perform: sending an authentication request to a first device, wherein the authentication request carries first security parameters corresponding to the target second device, and the first security parameters corresponding to the target second device are used to calculate a first signature.
[0367] The first security parameters corresponding to the target second device are calculated based on a first random number, and the first random number is generated by the target second device.
[0368] The authentication request further carries an identifier of the target second device.
[0369] The authentication request further carries a group identifier.
[0370] The authentication request further carries uplink encryption information, and the uplink encryption information is obtained by encrypting the first random number based on a public key of an authentication function entity.
[0371] The uplink encryption information is obtained by encrypting the first random number and uplink plaintext data based on a public key of an authentication function entity.
[0372] The public key of the authentication function entity is preconfigured.
[0373] The instructions cause the second device to perform: calculating a second communication key based on the second security parameter and the first random number; and receiving an authentication response from the first device, wherein the authentication response carries a second security parameter.
[0374] The authentication response further carries downlink encrypted information; and the instructions cause the second device to perform: decrypting the downlink encrypted information based on the second communication key to obtain downlink plaintext information.
[0375] The instructions cause the second device to perform: receiving a trigger message from the first device, wherein the trigger message is used to trigger a target second device to send the authentication request.
[0376] The first device comprises one of the following: a terminal and an access network device; and the second device comprises a zero-power device.
[0377] The application further provides a first device, comprising: a processor, and a memory in communication with the processor, the memory being configured to store instructions, when the instructions are executed by the processor, the instructions cause the first device to perform: receiving a group response message from an authentication function entity, wherein the group response message carries a second signature used to authenticate the authentication function entity.
[0378] The group response message further carries an identity of the authentication function entity.
[0379] The instructions cause the first device to perform: authenticating the authentication function entity based on a public key of the authentication function entity, the identity of the authentication function entity, and the second signature.
[0380] The group response message further carries a second security parameter.
[0381] The instructions cause the first device to perform: authenticating the authentication function entity based on a public key of the authentication function entity, the identity of the authentication function entity, the second signature, and the second security parameter.
[0382] The instructions cause the first device to perform: receiving authentication requests from a plurality of second devices, wherein the authentication request of each second device of the plurality of second devices carries an identity of each second device; and sending a group request message to the authentication function entity, wherein the group request message carries identities of the plurality of second devices and an identity of the first device.
[0383] The instructions cause the first device to perform: sending a trigger message to each second device, wherein the trigger message is used to trigger each second device to send the authentication request.
[0384] The embodiment of the application further provides an authentication function entity, comprising: a processor, a memory in communication with the processor, the memory being used to store instructions, when the instructions are executed by the processor, the instructions make the authentication function entity execute: sending a group response message to a first device, wherein the group response message carries a second signature used for authenticating the authentication function entity.
[0385] The group response message further carries an identity of the authentication function entity.
[0386] The second signature is calculated based on a private key of the authentication function entity and the identity of the authentication function entity.
[0387] The group response message further carries a second security parameter, the second security parameter is calculated based on a second random number, and the second random number is generated by the authentication function entity.
[0388] The second signature is calculated based on the private key of the authentication function entity, the identity of the authentication function entity and the second security parameter.
[0389] The instructions make the authentication function entity execute: receiving a group request message from the first device, wherein the group request message carries identities of a plurality of second devices and an identity of the first device.
[0390] FIG. 15 is a schematic structural diagram of a chip 1500 according to an embodiment of the present application. The chip 1500 includes a processor 1510, which can invoke and run a computer program from a memory to implement the method in the embodiments of the present application. In a possible implementation, the chip 1500 can further include a memory 1520. The processor 1510 can invoke and run a computer program from the memory 1520 to implement the method performed by an access network device or a core network side device in the embodiments of the present application. The memory 1520 can be a separate device independent of the processor 1510, or can be integrated in the processor 1510. In a possible implementation, the chip 1500 can further include an input interface 1530. The processor 1510 can control the input interface 1530 to communicate with other devices or chips, and specifically, can acquire information or data sent by other devices or chips. In a possible implementation, the chip 1500 can further include an output interface 1540. The processor 1510 can control the output interface 1540 to communicate with other devices or chips, and specifically, can output information or data to other devices or chips. In a possible implementation, the chip can be applied to various devices in the embodiments of the present application, and the chip can implement the corresponding processes implemented by various devices in various methods of the embodiments of the present application. For brevity, details are not described herein. It should be understood that the chip mentioned in the embodiments of the present application can also be referred to as a system-on-chip, a system chip, a chip system or a system-on-chip, etc.
[0391] The processor mentioned above can be a general processor, a digital signal processor, a ready programmable gate array, an application specific integrated circuit or other programmable logic device, a transistor logic device, a discrete hardware component, etc. The general processor mentioned above can be a microprocessor or any conventional processor, etc. The memory mentioned above can be a volatile memory or a non-volatile memory, or can include both volatile and non-volatile memories. The non-volatile memory can be a read only memory, a programmable read only memory, an erasable programmable read only memory, an electrically erasable programmable read only memory or a flash memory. The volatile memory can be a random access memory.
[0392] It should be understood that the memory above is an example but not a limiting description, for example, the memory in the embodiments of the present application can also be a static random access memory, a dynamic random access memory, etc. That is, the memory in the embodiments of the present application is intended to include but not limited to these and any other suitable types of memory.
[0393] FIG. 16 is a schematic block diagram of a communication system 1600 according to an embodiment of the present application. The communication system 1600 includes a first device 1620, a second device 1630, and an authentication function entity 1610. In the above embodiments, all or part of the processes can be implemented by software, hardware, firmware, or any combination thereof. When implemented by software, all or part of the processes can be implemented in the form of a computer program product. The computer program product includes one or more computer instructions. When loaded and executed by a computer, all or part of the processes generate the flows or functions according to the embodiments of the present application. The computer can be a general purpose computer, a special purpose computer, a computer network, or other programmable apparatus. The computer instructions can be stored in a computer readable storage medium or transferred from one computer readable storage medium to another computer readable storage medium, for example, the computer instructions can be transferred from one website, computer, server, or data center to another website, computer, server, or data center through a wired (for example, coaxial cable, optical fiber, digital subscriber line) or wireless (for example, infrared, wireless, microwave, etc.) manner. The computer readable storage medium can be any available medium accessible by a computer or a data storage device such as a server, data center, etc. containing one or more available media sets. The available medium can be a magnetic medium (for example, a hard disk), or a semiconductor medium (for example, a solid state disk), etc.
[0394] It should be understood that the size of the sequence number of each process described above in various embodiments of the present application does not mean the order of execution, and the execution order of each process should be determined according to its function and inherent logic, and should not constitute any limitation on the implementation process of the embodiments of the present application.
[0395] Those skilled in the art can clearly understand that, for the convenience and brevity of description, the specific working process of the system, device and unit described above can refer to the corresponding process in the foregoing method embodiments, which will not be described here.
[0396] The above is only a specific implementation of the present application, but the protection scope of the present application is not limited thereto, and any person skilled in the art can easily think of changes or replacements within the technical scope disclosed in the present application, which should be covered within the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.
Claims
1. An authentication method performed by a first device, the method comprising: receiving authentication requests from a plurality of second devices, wherein each authentication request from a second device of the plurality of second devices carries a first security parameter; sending a group request message to an authentication function entity, wherein the group request message carries a first signature for authenticating the plurality of second devices, the first signature being computed based on the first security parameter corresponding to each second device.
2. The method of claim 1, wherein, the first signature being computed based on a private key of the first device and a group security parameter, wherein the group security parameter is computed based on the first security parameter corresponding to each second device.
3. The method of claim 2, wherein, the group request message further carrying the group security parameter.
4. The method of claim 2 or 3, wherein, the first signature being computed based on the private key of the first device, the group security parameter, an identity of each second device, and an identity of the first device.
5. The method according to any one of claims 1 to 4, wherein, the authentication request from each second device further carrying the identity of each second device.
6. The method of claim 5, wherein, the group request message further carrying the identity of the first device and the identity of each second device.
7. The method of claim 6, wherein, the authentication request from each second device further carrying a group identity.
8. The method of claim 7, wherein, the group request message further carrying at least one of the group identity, the first security parameter corresponding to each second device, and a public key of the first device.
9. The method of any one of claims 1-8, wherein, the method further comprising: receiving a group response message from the authentication function entity, wherein the group response message carries a second signature for authenticating the authentication function entity.
10. The method of claim 9, wherein, the group response message further carrying an identity of the authentication function entity.
11. The method of claim 10, wherein, the method further comprising: authenticating the authentication function entity based on a public key of the authentication function entity, the identity of the authentication function entity, and the second signature.
12. The method of claim 11, wherein, the group response message further carrying a second security parameter.
13. The method of claim 12, wherein, authenticating the authentication function entity based on the public key of the authentication function entity, the identity of the authentication function entity, and the second signature comprises: authenticating the authentication function entity based on the public key of the authentication function entity, the identity of the authentication function entity, the second signature, and the second security parameter.
14. The method of claim 12 or 13, wherein, the authentication request from each second device further carrying uplink encryption information corresponding to each second device.
15. The method of claim 14, wherein, the method further comprising: decrypting the uplink encryption information corresponding to each second device based on a public key of the authentication function entity to obtain a first random number corresponding to each second device.
16. The method of claim 15, wherein, the method further comprising: computing a first communication key based on the second security parameter and the first random number corresponding to each second device, wherein the first communication key is used for communication between the first device and the authentication function entity.
17. The method of any one of claims 14-16, wherein, the group request message further carrying the uplink encryption information corresponding to each second device.
18. The method of any one of claims 12-17, wherein, the method further comprising: sending an authentication response to each second device, wherein the authentication response corresponding to each second device carries the second security parameter.
19. The method of claim 18, wherein, the group response message further carrying downlink encryption information corresponding to each second device; and the authentication response corresponding to each second device further carrying the downlink encryption information.
20. The method of any one of claims 9-19, wherein, The group response message further carries a second communication key corresponding to each second device.
21. The method of any one of claims 11-19, wherein, The public key of the authentication function entity is pre-configured.
22. The method of any one of claims 1-21, wherein, The method further comprises: sending a trigger message to each second device, wherein the trigger message is used to trigger each second device to send the authentication request.
23. The method of any one of claims 1-22, wherein, The first device comprises one of the following: a terminal, an access network device; the second device comprises a zero-power device; the authentication function entity is deployed in at least one of the following: an application function (AF), an access and mobility management function (AMF), a session management function (SMF), an authentication service function (AUSF), a unified data management function (UDM), a unified data repository (UDR), a home subscription system (HSS), an authentication credential repository and processing function (ARPF), a bootstrapping service function (BSF), a security anchor function (SEAF), and a core network dedicated network element.
24. An authentication method performed by an authentication function entity, comprising: receiving a group request message from a first device, wherein the group request message carries a first signature for authenticating a plurality of second devices, and the first signature is calculated based on a first security parameter corresponding to each second device in the plurality of second devices.
25. The method of claim 24, wherein, The group request message further carries a group security parameter; the method further comprises: authenticating the plurality of second devices based on a public key of the first device, the group security parameter, and the first signature.
26. The method of claim 25, wherein, The authentication of the plurality of second devices based on the public key of the first device, the group security parameter, and the first signature comprises: authenticating the plurality of second devices based on the public key of the first device, the group security parameter, an identity of each second device, an identity of the first device, and the first signature.
27. The method of any one of claims 24-26, wherein, The group request message further carries the identity of the first device and the identity of each second device.
28. The method of any one of claims 24-27, wherein, The group request message further carries at least one of the following: a group identity, a first security parameter corresponding to each second device, and a public key of the first device.
29. The method of any one of claims 24-28, wherein, The group request message further carries uplink encryption information corresponding to each second device; the method further comprises: The authentication function entity decrypts the uplink encryption information corresponding to each second device to obtain uplink plaintext data corresponding to each second device.
30. The method of any one of claims 24-29, wherein, The method further comprises: sending a group response message to the first device, wherein the group response message carries a second signature for authenticating the authentication function entity.
31. The method of claim 30, wherein, The group response message further carries an identity of the authentication function entity.
32. The method of claim 31, wherein, The second signature is calculated based on a private key of the authentication function entity and the identity of the authentication function entity.
33. The method of claim 32, wherein, The group response message further carries a second security parameter, which is calculated based on a second random number generated by the authentication function entity.
34. The method of claim 33, wherein, The second signature is calculated based on the private key of the authentication function entity, the identity of the authentication function entity, and the second security parameter.
35. The method of claim 33 or 34, wherein, The method further comprises: compute a first communication key based on the second random number and the group security parameter, wherein the first communication key is used for communication between the first device and the authentication function entity.
36. The method of any one of claims 33-35, wherein, The group response message further carries downlink encryption information corresponding to each second device; the downlink encryption information corresponding to each second device is obtained by encrypting downlink plaintext data of each second device based on a second communication key corresponding to each second device, and the second communication key corresponding to each second device is computed based on the second random number and a first security parameter corresponding to each second device.
37. The method of claim 36, wherein, The group response message further carries a second communication key corresponding to each second device.
38. The method of any one of claims 24-37, wherein, The first device comprises one of the following: a terminal, an access network device; the second device comprises a zero-power device; the authentication function entity is deployed in at least one of the following: an application function (AF), an access and mobility management function (AMF), a session management function (SMF), an authentication service function (AUSF), a unified data management function (UDM), a unified data repository (UDR), a home subscription system (HSS), an authentication credential repository and processing function (ARPF), a bootstrapping service function (BSF), a security anchor function (SEAF), and a core network dedicated network element.
39. An authentication method performed by a target second device, comprising: sending an authentication request to a first device, wherein the authentication request carries a first security parameter corresponding to the target second device, and the first security parameter corresponding to the target second device is used to compute a first signature.
40. The method of claim 39, wherein, The first security parameter corresponding to the target second device is computed based on a first random number, and the first random number is generated by the target second device.
41. The method of claim 39 or 40, wherein, The authentication request further carries an identifier of the target second device.
42. The method of any one of claims 39-41, wherein, The authentication request further carries a group identifier.
43. The method of any one of claims 39-42, wherein, The authentication request further carries uplink encryption information, and the uplink encryption information is obtained by encrypting the first random number based on a public key of an authentication function entity.
44. The method of claim 43, wherein, The uplink encryption information is obtained by encrypting the first random number and uplink plaintext data based on the public key of the authentication function entity.
45. The method of claim 43 or 44, wherein, The public key of the authentication function entity is preconfigured.
46. The method of any one of claims 39-45, wherein, The method further comprises: receiving an authentication response from the first device, wherein the authentication response carries a second security parameter; computing a second communication key based on the second security parameter and the first random number.
47. The method of claim 46, wherein, The authentication response further carries downlink encryption information; the method further comprises: decrypting the downlink encryption information based on the second communication key to obtain downlink plaintext information.
48. The method of any one of claims 39-47, wherein, The method further comprises: receiving a trigger message from the first device, wherein the trigger message is used to trigger the target second device to send the authentication request.
49. The method of any one of claims 39-48, wherein, The first device comprises one of the following: a terminal, an access network device; the second device comprises a zero-power device.
50. An authentication method performed by a first device, comprising: receiving a group response message from an authentication function entity, wherein the group response message carries a second signature used to authenticate the authentication function entity.
51. The method of claim 50, wherein, The group response message further carries an identifier of the authentication function entity.
52. The method of claim 51, wherein, The method further comprises: authenticate the authentication function entity based on the public key of the authentication function entity, the identity of the authentication function entity, and the second signature.
53. The method of claim 52, wherein, The group response message further carries a second security parameter.
54. The method of claim 53, wherein, The authentication of the authentication function entity based on the public key of the authentication function entity, the identity of the authentication function entity, and the second signature comprises: authenticate the authentication function entity based on the public key of the authentication function entity, the identity of the authentication function entity, the second signature, and a second security parameter.
55. The method of any one of claims 50-54, wherein, The method further comprises: receiving authentication requests from a plurality of second devices, wherein each authentication request from each second device of the plurality of second devices carries an identity of the each second device; sending a group request message to the authentication function entity, wherein the group request message carries the identities of the plurality of second devices and an identity of the first device.
56. The method of claim 55, wherein, The method further comprises: sending a trigger message to the each second device, wherein the trigger message is used to trigger the each second device to send the authentication request.
57. An authentication method performed by an authentication function entity, comprising: sending a group response message to a first device, wherein the group response message carries a second signature used to authenticate the authentication function entity.
58. The method of claim 57, wherein, The group response message further carries an identity of the authentication function entity.
59. The method of claim 58, wherein, The second signature is calculated based on a private key of the authentication function entity and the identity of the authentication function entity.
60. The method of claim 59, wherein, The group response message further carries a second security parameter, which is calculated based on a second random number generated by the authentication function entity.
61. The method of claim 60, wherein, The second signature is calculated based on the private key of the authentication function entity, the identity of the authentication function entity, and the second security parameter.
62. The method of any one of claims 57-61, wherein, The method further comprises: receiving a group request message from the first device, wherein the group request message carries identities of a plurality of second devices and an identity of the first device.
63. A first device, comprising: a first communication unit configured to receive authentication requests from a plurality of second devices, wherein each authentication request from each second device of the plurality of second devices carries a first security parameter; and send a group request message to an authentication function entity, wherein the group request message carries a first signature used to authenticate the plurality of second devices, which is calculated based on the first security parameter corresponding to the each second device.
64. The first device of claim 63, wherein, The first signature is calculated based on a private key of the first device and a group security parameter, wherein the group security parameter is calculated based on the first security parameter corresponding to the each second device.
65. The first device of claim 64, wherein, The group request message further carries the group security parameter.
66. The first device of claim 64 or 65, wherein, The first signature is calculated based on the private key of the first device, the group security parameter, an identity of the each second device, and an identity of the first device.
67. The first device of any of claims 63-66, wherein, The authentication request from the each second device further carries the identity of the each second device.
68. The first device of claim 67, wherein, The group request message further carries the identity of the first device and the identity of the each second device.
69. The first device of claim 68, wherein, The authentication request from the each second device further carries a group identity.
70. The first device of claim 69, wherein, The group request message further carries at least one of the group identity, the first security parameter corresponding to each second device, and a public key of the first device.
71. The first device of any of claims 63-70, wherein, The first communication unit is configured to receive a group response message from the authentication function entity, where the group response message carries a second signature for authenticating the authentication function entity.
72. The first device of claim 71, wherein, The group response message further carries an identity of the authentication function entity.
73. The first device of claim 72, wherein, The first device further includes: The first processing unit is configured to authenticate the authentication function entity based on the public key of the authentication function entity, the identity of the authentication function entity, and the second signature.
74. The first device of claim 73, wherein, The group response message further carries a second security parameter.
75. The first device of claim 74, wherein, The first processing unit is configured to authenticate the authentication function entity based on the public key of the authentication function entity, the identity of the authentication function entity, the second signature, and the second security parameter.
76. The first device of claim 74 or 75, wherein, The authentication request of each second device further carries uplink encryption information corresponding to each second device.
77. The first device of claim 76, wherein, The first processing unit is configured to decrypt the uplink encryption information corresponding to each second device based on the public key of the authentication function entity to obtain a first random number corresponding to each second device.
78. The first device of claim 77, wherein, The first processing unit is configured to calculate a first communication key based on the second security parameter and the first random number corresponding to each second device, where the first communication key is used for communication between the first device and the authentication function entity.
79. The first device of any one of claims 76-78, wherein, The group request message further carries uplink encryption information corresponding to each second device.
80. The first device of any one of claims 74-79, wherein, The first communication unit is configured to send an authentication response to each second device, where the authentication response corresponding to each second device carries the second security parameter.
81. The first device of claim 80, wherein, The group response message further carries downlink encryption information of each second device; and the authentication response corresponding to each second device further carries downlink encryption information.
82. The first device of any of claims 71-81, wherein, The group response message further carries a second communication key corresponding to each second device.
83. The first device of any of claims 73-81, wherein, The public key of the authentication function entity is preconfigured.
84. The first device of any of claims 63-83, wherein, The first communication unit is configured to send a trigger message to each second device, where the trigger message is used to trigger each second device to send the authentication request.
85. The first device of any one of claims 63-84, wherein, The first device includes one of a terminal and an access network device; the second device includes a zero-power device; and the authentication function entity is deployed in at least one of an application function (AF), an access and mobility management function (AMF), a session management function (SMF), an authentication service function (AUSF), a unified data management function (UDM), a unified data repository (UDR), a home subscriber system (HSS), an authentication credential processing function (ARPF), a bootstrapping service function (BSF), a security anchor function (SEAF), and a core network specific network element.
86. An authentication function entity, comprising: A second communication unit configured to receive a group request message from a first device, where the group request message carries a first signature for authenticating a plurality of second devices, and the first signature is calculated based on a first security parameter corresponding to each second device in the plurality of second devices.
87. The authentication function entity of claim 86, wherein, The group request message further carries a group security parameter; The authentication function entity further comprises: The second processing unit is configured to authenticate the plurality of second devices based on the public key of the first device, the group security parameter, and the first signature.
88. The authentication function entity of claim 87, wherein, The second processing unit is configured to authenticate the plurality of second devices based on the public key of the first device, the group security parameter, the identity of each second device, the identity of the first device, and the first signature.
89. The authentication function entity of any of claims 86-88, wherein, The group request message further carries the identity of the first device and the identity of each second device.
90. The authentication function entity of any of claims 86-89, wherein, The group request message further carries at least one of the following: a group identity, a first security parameter corresponding to each second device, and a public key of the first device.
91. The authentication function entity of any of claims 86-90, wherein, The group request message further carries uplink encrypted information corresponding to each second device; and the second processing unit is configured to decrypt the uplink encrypted information corresponding to each second device to obtain uplink plaintext data corresponding to each second device.
92. The authentication function entity of any of claims 86-91, wherein, The second communication unit is configured to send a group response message to the first device, where the group response message carries a second signature used to authenticate the authentication function entity.
93. The authentication function entity of claim 92, wherein, The group response message further carries an identity of the authentication function entity.
94. The authentication function entity of claim 93, wherein, The second signature is calculated based on a private key of the authentication function entity and the identity of the authentication function entity.
95. The authentication function entity of claim 94, wherein, The group response message further carries a second security parameter, which is calculated based on a second random number generated by the authentication function entity.
96. The authentication function entity of claim 95, wherein, The second signature is calculated based on a private key of the authentication function entity, the identity of the authentication function entity, and the second security parameter.
97. The authentication function entity of claim 95 or 96, wherein, The second processing unit is configured to calculate a first communication key based on the second random number and the group security parameter, where the first communication key is used for communication between the first device and the authentication function entity.
98. The authentication function entity of any of claims 95-97, wherein, The group response message further carries downlink encrypted information corresponding to each second device; the downlink encrypted information of each second device is obtained by encrypting downlink plaintext data of each second device based on a second communication key corresponding to each second device, which is calculated based on the second random number and a first security parameter corresponding to each second device.
99. The authentication function entity of claim 98, wherein, The group response message further carries the second communication key corresponding to each second device.
100. The authentication function entity of any of claims 86-99, wherein, The first device comprises one of the following: a terminal and an access network device; the second device comprises a zero-power device; and the authentication function entity is deployed in at least one of the following: an application function (AF), an access and mobility management function (AMF), a session management function (SMF), an authentication service function (AUSF), a unified data management function (UDM), a unified data repository (UDR), a home subscriber system (HSS), an authentication credential processing function (ARPF), a bootstrapping service function (BSF), a security anchor function (SEAF), and a core network-specific network element.
101. A second device, comprising: The third communication unit is configured to send an authentication request to the first device, wherein the authentication request carries a first security parameter corresponding to the target second device, and the first security parameter corresponding to the target second device is used to calculate a first signature.
102. The second device of claim 101, wherein, The first security parameter corresponding to the target second device is calculated based on a first random number, and the first random number is generated by the target second device.
103. The second device of claim 101 or 102, wherein, The authentication request further carries an identity of the target second device.
104. The second device of any of claims 101-103, wherein, The authentication request further carries a group identity.
105. The second device of any of claims 101-104, wherein, The authentication request further carries uplink encryption information, and the uplink encryption information is obtained by encrypting the first random number based on a public key of the authentication function entity.
106. The second device of claim 105, wherein, The uplink encryption information is obtained by encrypting the first random number and uplink plaintext data based on the public key of the authentication function entity.
107. The second device of claim 105 or 106, wherein, The public key of the authentication function entity is preconfigured.
108. The second device of any of claims 101-107, wherein, The second device further comprises a third processing unit: The third processing unit is configured to calculate a second communication key based on the second security parameter and the first random number. The third communication unit is configured to receive an authentication response from the first device, wherein the authentication response carries a second security parameter.
109. The second device of claim 108, wherein, The authentication response further carries downlink encryption information, and the third processing unit is configured to decrypt the downlink encryption information based on the second communication key to obtain downlink plaintext information.
110. The second device of any of claims 101-109, wherein, The third communication unit is configured to receive a trigger message from the first device, wherein the trigger message is used to trigger the target second device to send the authentication request.
111. The second device of any of claims 101-110, wherein, The first device comprises one of the following: a terminal and an access network device; and the second device comprises a zero-power device.
112. A first device, comprising: A first communication unit is configured to receive a group response message from an authentication function entity, wherein the group response message carries a second signature used to authenticate the authentication function entity.
113. The first device of claim 112, wherein, The group response message further carries an identity of the authentication function entity.
114. The first device of claim 113, wherein, The first device further comprises: A first processing unit is configured to authenticate the authentication function entity based on a public key of the authentication function entity, the identity of the authentication function entity, and the second signature.
115. The first device of claim 114, wherein, The group response message further carries a second security parameter.
116. The first device of claim 115, wherein, The first processing unit is configured to authenticate the authentication function entity based on the public key of the authentication function entity, the identity of the authentication function entity, the second signature, and the second security parameter.
117. The first device of any of claims 112-116, wherein, The first communication unit is configured to receive authentication requests from a plurality of second devices, wherein the authentication request of each second device in the plurality of second devices carries an identity of each second device; and send a group request message to the authentication function entity, wherein the group request message carries identities of the plurality of second devices and an identity of the first device.
118. The first device of claim 117, wherein, The first communication unit is configured to send a trigger message to each second device, wherein the trigger message is used to trigger each second device to send the authentication request.
119. An authentication function entity, comprising: A second communication unit is configured to send a group response message to a first device, wherein the group response message carries a second signature used to authenticate the authentication function entity.
120. An authentication function entity according to claim 119, wherein, The group response message further carries an identity of the authentication function entity.
121. The authentication function entity of claim 120, wherein, The second signature is calculated based on a private key of the authentication function entity, the identity of the authentication function entity.
122. The authentication function entity of claim 121, wherein, The group response message further carries a second security parameter, which is calculated based on a second random number generated by the authentication function entity.
123. The authentication function entity of claim 122, wherein, The second signature is calculated based on a private key of the authentication function entity, the identity of the authentication function entity, and the second security parameter.
124. The authentication function entity of any of claims 119-123, wherein, The second communication unit is configured to receive a group request message from the first device, wherein the group request message carries identities of a plurality of second devices and an identity of the first device.
125. A first device comprising: The transceiver, the processor, and the memory configured to store a computer program, wherein the processor is configured to invoke and run the computer program stored in the memory to cause the first device to perform the method according to any one of claims 1-23 or 50-56.
126. An authentication function entity, comprising: The transceiver, the processor, and the memory configured to store a computer program, wherein the processor is configured to invoke and run the computer program stored in the memory to cause the authentication function entity to perform the method according to any one of claims 24-38 or 57-62.
127. A second device, comprising: The transceiver, the processor, and the memory configured to store a computer program, wherein the processor is configured to invoke and run the computer program stored in the memory to cause the second device to perform the method according to any one of claims 39-49.
128. A chip comprising: The processor is configured to invoke and run a computer program from the memory to cause a device in which the chip is installed to perform the method according to any one of claims 1-23 or 24-38 or 39-49 or 50-56 or 57-62.
129. A computer readable storage medium configured to store a computer program, which, when run by a device, causes the device to perform the method according to any one of claims 1-23 or 24-38 or 39-49 or 50-56 or 57-62.
130. A computer program product comprising computer program instructions configured to cause a computer to perform the method according to any one of claims 1-23 or 24-38 or 39-49 or 50-56 or 57-62.
131. A computer program configured to cause a computer to perform the method according to any one of claims 1-23 or 24-38 or 39-49 or 50-56 or 57-62.