Communication method and apparatus
By adopting a domain name-based authentication mechanism under the service-oriented architecture of 5G networks, the network element authentication process is simplified, the system complexity and manual management needs are reduced, and the reliability and security of authentication are improved.
Patent Information
- Application Number
- PCT/CN2024/127404
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2023-11-01
- Filing Date
- 2024-10-25
- Publication Date
- 2025-05-08
AI Technical Summary
Under the service-oriented architecture of 5G networks, the existing network element authentication and certificate issuance methods are complex, requiring the deployment and manual management of multiple CAs, which increases costs and security risks.
The domain name-based authentication mechanism is adopted to verify the domain name of the network functional network element through the first authentication device, issue domain name certificates, simplify the authentication process, reduce the system complexity, and realize automated and efficient network element authentication through the ACME protocol.
It realizes simplification and efficiency of network element authentication, reduces the number of CA deployments and manual management needs, and improves the reliability and security of authentication.
Smart Images

Figure CN2024127404_08052025_PF_FP_ABST
Abstract
Description
Communication method and device
[0001] CROSS-REFERENCE TO RELATED APPLICATIONS
[0002] This application claims priority to the Chinese patent application filed with the State Intellectual Property Office of the People's Republic of China on November 1, 2023, with application number 202311447842.7 and invention name "A Communication Method and Device", the entire contents of which are incorporated by reference into this application. Technical Field
[0003] The present application relates to the field of mobile communication technologies, and in particular to a communication method and device. Background Art
[0004] The core network of the fifth generation (5G) mobile communication network utilizes network function virtualization (NFV) technology. This technology breaks down the functions of network elements into distinct network functions (NFs) and deploys them in a virtualized form on the network platform, enabling rapid deployment of network functions. To simplify communication and access control between network elements, 5G networks employ a service-based architecture (SBA), through which virtualized network elements interact.
[0005] For network security reasons, interactions between different NFs are based on their authentication certificates. In the NF authentication scheme currently used in service-oriented networks, a third-party certificate authority (CA) is required to issue the NF's public key certificate. During the communication authorization process, the authenticity of the NF's public key certificate is verified based on public key infrastructure (PKI) technology. If verified, communication is permitted.
[0006] However, a service-oriented architecture may involve the authentication of various types of network function elements across multiple networks, requiring the deployment of numerous CAs and manual management of CA deployment. This not only increases costs but is also prone to errors and security incidents. Therefore, in current service-oriented 5G networks, the authentication and certificate issuance methods for NF elements need to be optimized.
[0007] Summary of the Invention
[0008] The present application provides a communication method and device for providing an authentication and certificate issuance mechanism for network function network elements suitable for a service-oriented architecture, so as to reduce the complexity of the network function network element authentication mechanism and improve the authentication efficiency.
[0009] In a first aspect, a communication method is provided. The method may be implemented by a first communication device. The first communication device may be a network function element (NFE) or a component within the NFE. The component in this application may include, for example, at least one of a chip, a chip system, a processor, a transceiver, a processing unit, or a transceiver unit. The NFE may be a NFE deployed in a core network with a service-oriented architecture.
[0010] Taking the execution subject as an example, the method can be implemented by the following steps: the network function network element obtains the domain name of the network function network element, where the network function network element is a network element in a service-oriented architecture network. The network function network element sends the domain name of the network function network element to the first authentication device, where the domain name of the network function network element is used to verify the network function network element. The network function network element obtains a first domain name certificate issued by the first authentication device, where the first domain name certificate is used to indicate that the verification is successful.
[0011] Based on the first aspect, the network function network element under the service-oriented architecture can obtain the domain name of the network function network element, and send the domain name of the network function network element to the first authentication device, so that the first authentication device verifies the network function network element based on the domain name. After the verification is passed, the first authentication device can issue a first domain name certificate to indicate that the network function network element has passed the verification. The above authentication mechanism of the first domain name certificate is based on the domain name of the network function network element of the service-oriented architecture, that is, the identity of the network function network element is verified based on the domain name of the network function network element. Therefore, there is no need to issue a public key certificate to the network function network element in advance, which can reduce the complexity of the authentication system and does not require the introduction of too many manual deployment operations. In addition, the above authentication process does not require verification of the public key certificate, which saves a lot of calculations in the public key certificate verification process, and thus can achieve efficient network element authentication.
[0012] In a possible implementation, the verification is based on the Automatic Certificate Management Environment (ACME) protocol, which can realize automatic authentication and certificate issuance of network elements in a service-oriented architecture.
[0013] In one possible implementation, the domain name of the network function network element is determined based on the type information of the network function network element. In other words, there is a correspondence between the domain name of the network function network element and the type information of the network function network element, or the domain name of the network function network element and the type information of the network function network element can be converted to each other through the correspondence. As an example, there is a correspondence between the domain name of the network function network element and the type information of the network function network element, for example, the domain name of the network function network element includes the type information of the network function network element.
[0014] In one possible implementation, the network function network element further sends type information of the network function network element to the first authentication device. This type information can be used to verify the type information corresponding to the domain name of the network function network element. Based on this implementation, before the first authentication device issues the first domain name certificate, the first authentication device can determine the type information corresponding to the domain name based on the domain name provided by the network function network element. Furthermore, the first authentication device can compare the type information corresponding to the domain name of the network function network element with the type information provided by the network function network element to verify whether the network function network element has impersonated information from other network elements or devices. If the comparison is consistent, it indicates that there has been no identity theft, and the first authentication device can then authenticate the network function network element. If the comparison is inconsistent, it indicates that there has been identity theft, and the first authentication device can then refuse to authenticate the network function network element, or determine that the authentication result is a failure. Therefore, based on this implementation, the authentication reliability of the network function network element can be further improved.
[0015] In a possible implementation, the network function network element may also receive DNS challenge information from the first authentication server. The network function network element may also generate a DNS challenge response based on the domain name service (DNS) challenge information. The network function network element requests the second device to write the DNS challenge response into the domain name record of the network function network element in the DNS server. The network function network element receives a domain name record modification completion indication from the second device. The network function network element notifies the first authentication device to obtain the DNS challenge response from the DNS server, and the DNS challenge response and the DNS challenge information obtained by the first authentication device from the DNS server are used to verify the network function network element. The network function network element receives information from the first authentication device indicating that the verification is successful.
[0016] Based on this implementation, when DNS is used for domain name challenge verification, the network function network element can request the second device to write the DNS challenge information to the DNS server. The second device is a device configured to have the right to modify the domain name record in the DNS, and its rights include: in the process of receiving the DNS challenge response from the network function network element, the domain name of the network function network element is determined based on the connection information (such as tunnel information) between the network function network element and the second device can also trigger or request the DNS server to modify the record corresponding to the domain name based on the domain name of the network function network element. The domain name determined by the second device is the domain name of the network function network element obtained in the process of establishing a connection with the network function network element, so it can only request the DNS server to write the DNS challenge response to the record of the domain name of the network function network element, and will not write the DNS challenge response to the corresponding record of the false domain name of the DNS server based on the false domain name provided by the network function network element when sending the DNS challenge response. This can avoid the network function network element providing a false domain name when requesting the second device to write the DNS challenge response, and obtaining a domain name certificate based on the false domain name, which can reduce the risk of domain name impersonation. Exemplarily, the second device may be a management device or a network repository function (NRF) network element. The management device may be, for example, an operation and maintenance (OAM) device.
[0017] In one possible implementation, the first authentication device is deployed in a first network, and the first domain name certificate is specifically used for the network function element to communicate with network elements in the first network. Based on this implementation, the first authentication device, deployed in the same network as the network function element, can issue the first domain name certificate to the network function element for use in communication within the network. This architecture can achieve secure communication within the same network.
[0018] In one possible implementation, the network function network element sends a domain name certificate acquisition request to a certificate management network element in the first network based on the first domain name certificate. The domain name certificate acquisition request is used to request a certificate of the network function network element issued by a second authentication device in the second network, and the domain name certificate acquisition request includes the domain name of the network function network element. The network function network element receives the second domain name certificate from the certificate management network element, where the second domain name certificate is issued by the second authentication device.
[0019] Based on this implementation, a second authentication device deployed in the second network can issue a second domain name certificate to the network function network element, which is used for the network function network element to communicate with network elements or devices in the second network. The network function network element can communicate with a certificate management network element deployed in the first network, and communicate with the second authentication device of the second network through the certificate management network element. For example, the domain name of the network function network element is provided to the second authentication device through the certificate management network element, and the second authentication device verifies the network function network element based on the domain name of the network function network element. If the verification is successful, the second authentication device can issue a second domain name certificate.
[0020] In a possible implementation, the second domain name certificate is used for the network function network element to communicate with the network element of the second network. Therefore, secure communication across networks can be achieved based on the second domain name certificate.
[0021] In one possible implementation, the network function element receives information about the second authentication device from a management device, and the domain name certificate acquisition request also includes information about the second authentication device. Based on this implementation, the management device can provide the network function element with information about the second authentication device, so that the network function element can send the domain name to the second authentication device via the certificate management device for verification.
[0022] In a possible implementation, the network function network element sends a domain name certificate acquisition request to the certificate management network element in the first network based on the first domain name certificate, including: the network function network element sends the first domain name certificate to the certificate management network element; the network function network element receives a first indication from the certificate management network element, the first indication indicating that the first domain name certificate is authenticated; the network function network element sends the domain name certificate acquisition request to the certificate management network element.
[0023] Based on this implementation method, the communication between the network function network element and the certificate management network element can be based on the first domain name certificate of the network function network element, avoiding the network function network element that does not have the communication authority within the first network requesting the second authentication device to obtain the domain name certificate through the certificate management network element, which can improve the security of the cross-network communication process.
[0024] In one possible implementation, the first domain name certificate includes the domain name and type information of the network function network element. The type information in the first domain name certificate is used to verify the domain name of the network function network element. Accordingly, before establishing communication with other network elements, the other network elements can verify whether the type information corresponding to the domain name in the first domain name certificate is consistent with the type information contained in the first domain name certificate. If the verification result is inconsistent, the request can be rejected. This can thus identify whether the domain name certificate is forged, further improving network security.
[0025] In a second aspect, a communication method is provided. The method may be implemented by a second communication device. In the present application, the second communication device may be a management device or a component of the management device. The management device may be, for example, an OAM device. Taking the management device as an example, the method may be implemented by the following steps: the management device provides the domain name of the network function element to the network function element; the management device sends a registration message to a DNS server, the registration message including the domain name of the network function element.
[0026] In a possible implementation, the management device may further send information of a second authentication device to the network function network element, where the second authentication device is used to issue a second domain name certificate to the network function network element.
[0027] For the beneficial effects of the above second aspect and its possible implementation methods, reference can be made to the description of the beneficial effects of the corresponding implementation methods in the first aspect.
[0028] On the third aspect, a communication method is provided. The method can be implemented by a third communication device. In the present application, the third communication device can be a second device or a component in the second device. The second device is, for example, an OAM device or an NRF network element, which is used to request a DNS server to modify a domain name record. Taking the execution subject as the second device as an example, the method can be implemented by the following steps: the second device receives a DNS challenge response from the network function network element; the second device determines the domain name of the network function network element based on the connection information between the second device and the network function network element; the second device writes the DNS challenge response into the domain name record of the network function network element in the DNS server based on the domain name of the network function network element.
[0029] For the beneficial effects of the third aspect and its possible implementations, please refer to the description of the beneficial effects of the corresponding implementations in the first aspect.
[0030] In a fourth aspect, a communication method is provided. The method can be implemented by a fourth communication device. In the present application, the fourth communication device can be a first authentication device or a component in the first authentication device. The first authentication device is, for example, a CA. Taking the execution subject as the first authentication device as an example, the method can be implemented by the following steps: the first authentication device receives the domain name and type information of the network function network element from the network function network element; the first authentication device verifies the type information and the type information corresponding to the domain name of the network function network element; if the verification passes, for example, the two are consistent, the first authentication device issues the first domain name certificate.
[0031] In a possible implementation, the first authentication device obtains the DNS challenge response from the DNS server;
[0032] The first authentication device verifies the network function network element according to the DNS challenge response and the DNS challenge information;
[0033] In the case where the verification is successful, the first authentication device provides the network function network element with the information indicating that the verification is successful.
[0034] The beneficial effects of the fourth aspect and its possible implementation methods can be found in the description of the beneficial effects of the corresponding implementation methods in the first aspect.
[0035] In a fifth aspect, a communication method is provided. The method can be implemented by a fifth communication device. In the present application, the fifth communication device can be a certificate management network element or a component in the certificate management network element. Taking the execution subject as the certificate management network element as an example, the method can be implemented by the following steps: the certificate management network element receives a domain name certificate acquisition request from a network function network element, the domain name certificate acquisition request is used to request a certificate of the network function network element issued by a second authentication device in a second network, the domain name certificate acquisition request includes the domain name of the network function network element, the network function network element and the certificate management network element belong to a first network, the first domain name certificate is used for the network function network element to communicate with the network elements in the first network; the certificate management network element sends the domain name of the network function network element to the second authentication device, the domain name of the network function network element is used to verify the network function network element; the certificate management network element obtains a second domain name certificate issued by the second authentication device, the second domain name certificate is used to indicate that the verification is passed; the certificate management network element sends the second domain name certificate to the network function network element.
[0036] In one possible implementation, the certificate management network element may also obtain domain name service DNS challenge information from the second authentication device; the certificate management network element generates a DNS challenge response based on the DNS challenge information; the certificate management network element writes the DNS challenge response into the domain name record of the network function network element in the domain name service DNS server; or, the certificate management network element requests the second device to write the DNS challenge response into the domain name record of the network function network element in the DNS server; the certificate management network element receives a domain name record modification completion indication from the second device; the certificate management network element notifies the second authentication device to obtain the DNS challenge response from the DNS server, and the DNS challenge response and the DNS challenge information are used by the second authentication device to verify the network function network element; if the verification is successful, the certificate management network element obtains information provided by the second authentication device to indicate that the verification is successful.
[0037] In a possible implementation, the second device receives a DNS challenge response from the certificate management network element; and the second device writes the DNS challenge response into a domain name record of the network function network element in the DNS server.
[0038] In one possible implementation, the first authentication device may also obtain the DNS challenge response from the DNS server; the first authentication device verifies the network function network element based on the DNS challenge response and the DNS challenge information; if the verification is successful, the first authentication device provides the network function network element with the information indicating that the verification is successful.
[0039] In a possible implementation, the certificate management network element may also receive a first domain name certificate from the network function network element, where the first domain name certificate is used to indicate that the domain name of the network function network element has passed verification, and the first domain name certificate includes the domain name and type information of the network function network element; the certificate management network element verifies the type information and the type information corresponding to the domain name of the network function network element; if the verification passes, the certificate management network element sends a first indication to the network function network element, where the first indication indicates that the first domain name certificate authentication has passed.
[0040] In a possible implementation, the second domain name certificate is used for the network function network element to communicate with the network element of the second network.
[0041] The beneficial effects of the above fifth aspect and its possible implementation methods can be found in the description of the beneficial effects of the corresponding implementation methods in the first aspect.
[0042] In a sixth aspect, a communication device is provided. The device can implement the method described in any possible implementation of any of the first to fifth aspects. The device has the functions of any of the first to fifth communication devices. The device is, for example, a network function network element, a management device, a second device, a first authentication device, or a certificate management network element, or is a component in a network function network element, a component in a management device, a component in a second device, a component in a first authentication device, or a component in a certificate management network element.
[0043] In an optional implementation, the device may include a module corresponding to the method / operation / step / action described in any possible implementation of any aspect from the first to the fifth aspect, and the module may be a hardware circuit, or software, or a hardware circuit combined with software. In an optional implementation, the device includes a processing unit (sometimes also referred to as a processing module) and a communication unit (sometimes also referred to as a transceiver module, a communication module, etc.). The transceiver unit can implement a sending function and a receiving function. When the transceiver unit implements the sending function, it can be called a sending unit (sometimes also referred to as a sending module). When the transceiver unit implements the receiving function, it can be called a receiving unit (sometimes also referred to as a receiving module). The sending unit and the receiving unit can be the same functional module, which is called a transceiver unit, and the functional module can implement a sending function and a receiving function; or, the sending unit and the receiving unit can be different functional modules, and the transceiver unit is a general term for these functional modules.
[0044] Exemplarily, when the device is used to execute the method described in any one of the first to fifth aspects, the device may include a communication unit and a processing unit.
[0045] In the seventh aspect, an embodiment of the present application also provides a communication device, including a processor for executing a computer program (or computer executable instructions) stored in a memory. When the computer program (or computer executable instructions) is executed, the device executes the method described in any possible implementation of any aspect from the first to the fifth aspect.
[0046] In one possible implementation, the processor and memory are integrated;
[0047] In another possible implementation, the memory is located outside the communication device.
[0048] The communication device also includes a communication interface, which is used for the communication device to communicate with other devices, such as sending or receiving data and / or signals. Exemplarily, the communication interface can be a transceiver, circuit, bus, module or other type of communication interface.
[0049] In an eighth aspect, a computer-readable storage medium is provided, which is used to store computer programs or instructions, and when the computer-readable storage medium is executed, the method described in any possible implementation of any aspect from the first to the fifth aspect and the method shown in any possible implementation thereof are implemented.
[0050] In a ninth aspect, a computer program product comprising instructions is provided, which, when executed on a computer, enables the method described in any possible implementation of any one of the first to fifth aspects to be implemented.
[0051] In the tenth aspect, an embodiment of the present application further provides a communication device for executing the method described in any possible implementation of any one of the first to fifth aspects above.
[0052] In the eleventh aspect, a chip system is provided, which includes a logic circuit (or it can be understood that the chip system includes a processor, and the processor may include a logic circuit, etc.), and may also include an input and output interface. The input and output interface can be used to input messages and can also be used to output messages. The input and output interfaces can be the same interface, that is, the same interface can implement both the sending function and the receiving function; or, the input and output interfaces include an input interface and an output interface, the input interface is used to implement the receiving function, that is, for receiving messages; the output interface is used to implement the sending function, that is, for sending messages. The logic circuit can be used to perform the operations other than the sending and receiving functions in the method described in any possible implementation of any one of the first to fifth aspects above; the logic circuit can also be used to transmit messages to the input and output interface, or receive messages from other communication devices from the input and output interface. The chip system can be used to implement the method described in any possible implementation of any one of the first to fifth aspects above. The chip system can be composed of a chip, or it can include a chip and other discrete devices.
[0053] Optionally, the chip system may further include a memory, which may be used to store instructions, and the logic circuit may call the instructions stored in the memory to implement corresponding functions.
[0054] In a twelfth aspect, a communication method is provided. The communication system may include the method implemented by the first communication device as described in the first aspect and any possible implementation thereof, and the method implemented by the fifth communication device as described in the fifth aspect and any possible implementation thereof. Optionally, the method may also include the methods described in the second to fourth aspects and any possible implementation thereof.
[0055] In a thirteenth aspect, a communication system is provided, which may include a first communication device and a fifth communication device, and optionally may also include at least one of a second communication device to a fourth communication device. The first communication device may be used to implement the method described in the first aspect and any possible implementation thereof. The fifth communication device may be used to implement the method described in the fifth aspect and any possible implementation thereof. The second communication device may be used to implement the method described in the second aspect and any possible implementation thereof. The third communication device may be used to implement the method described in the third aspect and any possible implementation thereof. The fourth communication device may be used to implement the method described in the fourth aspect and any possible implementation thereof.
[0056] The technical effects brought about by the above-mentioned sixth to thirteenth aspects can be found in the description of the beneficial effects of the corresponding implementation methods in the above-mentioned first aspect, and will not be repeated here. BRIEF DESCRIPTION OF THE DRAWINGS
[0057] FIG1 is a schematic diagram of the architecture of a wireless communication system provided in an embodiment of the present application;
[0058] Figure 2 is a schematic diagram of an authentication system under a service-oriented architecture;
[0059] FIG3 is a flow chart of a communication method provided in an embodiment of the present application;
[0060] FIG4 is a schematic diagram of a domain name verification process based on the ACME protocol provided in an embodiment of the present application;
[0061] FIG5 is a schematic diagram of an authentication system based on the ACME protocol provided in an embodiment of the present application;
[0062] FIG6 is a flow chart of another communication method provided in an embodiment of the present application;
[0063] FIG7 is a flow chart of another communication method provided in an embodiment of the present application;
[0064] FIG8 is a schematic structural diagram of a communication device provided in an embodiment of the present application;
[0065] FIG9 is a schematic structural diagram of another communication device provided in an embodiment of the present application. DETAILED DESCRIPTION
[0066] The present application provides a communication method and apparatus. The method and apparatus are based on the same inventive concept. Since the method and apparatus solve similar problems, the implementation of the apparatus and method can refer to each other, and the repetitive parts will not be repeated.
[0067] To enhance the flexibility and agility of network deployment, NFV technology is used in the core network of mobile networks to break down the functions of network elements into distinct network functions (NFs). These functions are then virtualized and deployed on the network platform, enabling rapid deployment of these functions. To simplify communication and access control between NFs, a service-based architecture is being adopted in 5G networks. NFs in this service-based architecture can use Hypertext Transfer Protocol Secure (HTTPS) to send and receive service requests.
[0068] Figure 1 is a schematic diagram of a network architecture based on a service-oriented architecture, which can include the service-oriented architecture of 5G and future mobile communication systems. The network architecture shown in Figure 1 may include terminal devices, access network devices, and core network devices. Terminal devices access the data network (DN) through access network devices and core network devices. The core network devices include various NF network elements. For example, the NF network elements in the service-oriented network architecture include some or all of the following network elements: unified data management (UDM) network element, unified data repository (UDR) network element, network exposure function (NEF) network element (not shown in the figure), application function (AF) network element, policy control function (PCF) network element, access and mobility management function (AMF) network element, session management function (SMF) network element, user plane function (UPF) network element, network data analytics function (NWDAF) network element, NRF (not shown in the figure), and location management function (LMF) network element (not shown in the figure). The description and function of the above network elements can be referred to the relevant 5G protocols and will not be expanded here.
[0069] Access network equipment can be radio access network (RAN) equipment. Examples include base stations, evolved NodeBs (eNodeBs), transmission reception points (TRPs), next-generation NodeBs (gNBs) in 5G mobile communication systems, future mobile communication systems such as the 6th generation (6G), next-generation base stations in open RAN (O-RAN or ORAN) mobile communication systems or cloud radio access network (CRAN) mobile communication systems, base stations in future mobile communication systems, or access nodes in wireless fidelity (WiFi) systems. Access network equipment can also be modules or units that perform some of the functions of a base station, such as centralized units (CUs) or distributed units (DUs). Access network equipment can be macro base stations, micro base stations, indoor stations, relay nodes, donor nodes, and the like. The access network device may also be an open access network (open RAN, O-RAN or ORAN), a cloud radio access network (CRAN), or a wireless fidelity (WiFi) system. The access network device may also be a communication system that integrates two or more of the above systems. The embodiments of the present application do not limit the specific technology and specific device form used by the wireless access network device.
[0070] Terminal devices can be user equipment (UE), mobile stations, mobile terminals, etc. Terminal devices can be widely used in various scenarios, such as device-to-device (D2D), vehicle-to-everything (V2X) communication, machine-type communication (MTC), the Internet of Things (IoT), virtual reality, augmented reality, industrial control, autonomous driving, telemedicine, smart grids, smart furniture, smart offices, smart wearables, smart transportation, and smart cities. Terminal devices can be mobile phones, tablets, computers with wireless transceiver capabilities, wearable devices, vehicles, urban air vehicles (such as drones and helicopters), ships, robots, robotic arms, smart home devices, etc.
[0071] Access network equipment and terminal devices can be fixed or mobile. They can be deployed on land, including indoors or outdoors, handheld or vehicle-mounted; on water; or in the air on aircraft, balloons, and satellites. The embodiments of this application do not limit the application scenarios of access network equipment and terminal devices.
[0072] It can be understood that the above network elements and communication equipment are examples of an implementation method of a 5G network under a service-oriented architecture. This application does not exclude the existence of network elements or devices with the above network element functions in 6G or newer wireless communication systems, which have other names or other forms.
[0073] In Figure 1, Nudr, Npcf, Namf, Nudm, Nsmf, Naf, and Nnwdaf are service-oriented interfaces provided by the UDR, PCF, AMF, UDM, SMF, AF, and NWDAF, respectively, and are used to invoke corresponding service-oriented operations. N1, N2, N3, N4, and N6 are interface serial numbers, and their meanings are as follows:
[0074] 1) N1: The interface between the AMF network element and the terminal device, which can be used to transmit non-access stratum (NAS) signaling (such as QoS rules from the AMF network element) to the terminal device.
[0075] 2) N2: The interface between the AMF network element and the access network equipment, which can be used to transmit radio bearer control information from the core network side to the access network equipment.
[0076] 3) N3: The interface between the access network equipment and the UPF network element, mainly used to transmit uplink and downlink user plane data between the access network equipment and the UPF network element.
[0077] 4) N4: The interface between the SMF network element and the UPF network element, which can be used to transmit information between the control plane and the user plane, including controlling the issuance of forwarding rules, QoS rules, traffic statistics rules, etc. for the user plane and reporting information on the user plane.
[0078] 5) N6: Interface between UPF network element and DN, used to transmit uplink and downlink user data flows between UP network element F and DN.
[0079] It is understood that the above-mentioned network element or function can be a network element in a hardware device, a software function running on dedicated hardware, or a virtualized function instantiated on a platform (e.g., a cloud platform). As a possible implementation method, the above-mentioned network element or function can be implemented by a single device, or can be implemented by multiple devices together, or can be a functional module within a single device, which is not specifically limited in the embodiments of the present application.
[0080] In addition, each of the above NF network elements can also be referred to as NF for short. For example, the AMF network element can be referred to as AMF for short.
[0081] It can be understood that Figure 1 is an example of a 5G service-oriented network architecture. The present application can also be applied to service-oriented architectures in other 5G or future mobile networks (such as 6G) other than Figure 1 to implement certificate issuance for NF network elements in the service-oriented network architecture.
[0082] Currently, authentication of NF elements (NFs) within a service-oriented architecture requires a CA to issue a public key certificate to the NF element. However, the scope of effectiveness of CAs is generally limited, requiring the deployment of different CAs in different networks. Furthermore, authentication of NF elements' communication permissions requires verification of their public key certificates based on PKI technology, with the NF element's authentication result determined based on the verification results. This authentication process requires the participation of numerous CAs, resulting in extensive CA deployment and manual management. This increases costs and is prone to errors, leading to security incidents and requiring optimization.
[0083] For example, Figure 2 shows a framework for NF certificate issuance within a service-oriented architecture. Network A and Network B represent different networks, such as different public land mobile networks (PLMNs). Alternatively, Network A and Network B represent different security domains or operator networks. Currently, when a NF needs to obtain services from another NF, a transport layer security (TLS) link is first established between the two NFs. According to the requirements of the 3rd Generation Partnership Project (3GPP) System Architecture Group 3 (SA3) Technical Specification (TS) 33.310, two NFs must perform mutual authentication when establishing a secure link. This mutual authentication is based on X.509 public key certificates based on public key infrastructure (PKI). However, since different NFs may be located in different network domains, authentication between NFs involves cross-domain authentication. Therefore, 3GPP SA3 introduces a cross-domain certificate issuance architecture. Different networks need to deploy a subordinate certificate authority (CA) in each other's domain to issue X.509 certificates to each other's NFs to achieve trust transfer.
[0084] Due to the large number of NFs in 5G networks, and to ensure mutual trust between NFs in different operators' core networks, different operators need to deploy numerous subordinate CAs in other operators' networks. For example, Network A and Network B could deploy interconnection CAs, TLS server CAs, and TLS client CAs, respectively. Specifically, this involves providing cross-authorized intermediate root certificates for other operators' second- or third-tier CAs. These cross-authorized subordinate CA certificates include TLS client CA certificates and TLS server CA certificates. Clients establishing TLS connections mutually authenticate each other based on these certificates and establish TLS connections. Because a single operator needs to establish interconnection relationships with multiple operators, each operator must authorize the deployment of subordinate CAs by dozens or even hundreds of other operators. Each operator also needs to maintain and operate dozens or even hundreds of subordinate CAs, resulting in an extremely complex certificate management system and the need for manual management of CA deployment, which not only increases costs but is also prone to errors and security incidents. Therefore, a certificate issuance solution for NFs suitable for the 5G service-based architecture is needed.
[0085] The present application provides a network element verification method, which is used to provide a NF network element verification method suitable for a service-oriented architecture network. In this method, the domain name (domain name) of the NF network element is verified (or authenticated) based on the authentication device, and a domain name certificate is issued to indicate that the NF network element has passed the verification. Among them, the authentication device can authenticate the domain name of the NF network element based on the ACME protocol, so that an automated and efficient NF network element verification and certificate management mechanism can be achieved. ACME is a certificate management challenge solution developed by the Internet Engineering Task Force (IETF). The domain name challenge schemes supported by the ACME protocol include the Hypertext Transfer Protocol (HTTP)-01 method and the -01 method.
[0086] In HTTP-01, when an ACME client requests a domain name certificate from a server, ACME must first verify the client's control over the domain name. The ACME server instructs the ACME client to place challenge data provided by the ACME server in a specified directory on the web server corresponding to the domain name it controls. After receiving the challenge data, the ACME client generates challenge verification information based on the challenge data and stores it in the specified directory. The ACME client then instructs the ACME server to retrieve the challenge verification information from the specified directory. Upon receiving this instruction, the ACME server first resolves the domain name from a DNS server, obtains the IP address corresponding to the domain name, then uses this IP address to access the corresponding web server and download the challenge verification information from the specified directory. The ACME server compares the downloaded verification information with its own stored challenge verification data. If they match, verification is successful, and the ACME server changes the corresponding certificate verification status to passed. After the ACME client detects that the domain name has been verified, it sends a certificate signing request (CSR) to the ACME server. ACME then forwards the request to the backend CA. The CA generates a domain name certificate based on the request and returns it to the ACME server. The ACME server then stores the certificate in the corresponding directory on the ACME server. The ACME client then downloads the certificate and deploys it on the corresponding internet server for use.
[0087] Similarly, the DNS-01 challenge verification method involves the ACME client inserting the challenge verification information provided by the ACME server into the corresponding domain name record on the target DNS server and notifying the ACME server to retrieve the challenge verification information. Upon receiving the challenge verification indication, the ACME server uses the DNS resolution service to retrieve the record for the domain name from the corresponding DNS server, extract the corresponding challenge verification information from the record, and complete the challenge verification. The subsequent steps are similar to those of HTTP-01, including the ACME client sending the CSR, the ACME server forwarding the request to the CA to obtain the corresponding domain name certificate, and finally the ACME client downloading the certificate from the ACME server.
[0088] The following describes the network elements and devices used in the method provided by this application. The method can be implemented by the NF network element to be verified and the authentication device.
[0089] The NF network element may be a NF to be verified in a service-oriented architecture network. Specifically, the NF network element may be an AMF or SMF network element.
[0090] The authentication device may be a device for verifying the domain name. After the domain name of the NF network element passes the verification, the authentication device may issue a domain name certificate. For example, the authentication device may be a CA.
[0091] In some embodiments, the method may also be performed by one or more devices among an OAM, a certificate management function (CMF) network element, and a DNS server.
[0092] Among them, the OAM device can be an operation and maintenance network entity within the operator's network, which can be used to be responsible for the creation of NF network elements and / or CMF network elements, etc. For example, it can provide the initialization configuration of NF network elements and / or CMF network elements, and the domain name registered for NF network elements and / or CMF network elements.
[0093] The CMF network element can serve as the NF network element of the core network and is used to provide certificate management agent functions. In some embodiments of the present application, the CMF can help the NF network element perform domain name verification in some cases.
[0094] DNS servers can be used to register domain names and resolve domain names to Internet Protocol (IP) addresses. Furthermore, when using an ACME-based domain name verification scheme, DNS servers can assist authentication devices in performing domain name verification using the DNS-01 method, as described below in conjunction with the following examples.
[0095] As shown in FIG3 , a network element verification method provided in an embodiment of the present application may include the following steps shown in S101 to S104:
[0096] S101: The NF network element obtains the domain name of the NF network element.
[0097] The following describes the domain name of the NF network element.
[0098] The domain name of the NF network element can be a name consisting of a string of characters separated by dots (.), which can be used to identify the communicating device during communication. The domain name of the NF network element and the NF IP address can be registered in a DNS server, so that the DNS server can support resolution of the domain name and IP address of the NF network element.
[0099] In this application, the domain name of the NF network element can be used by the first authentication device to verify the identity of the NF network element. Therefore, based on S101, the NF network element can send the domain name of the NF network element to the first authentication device, so that the first authentication device can authenticate the identity of the NF network element. Specifically, the first authentication device can verify the identity of the NF network element based on the domain name.
[0100] Optionally, in this application, the OAM device may allocate a domain name to the NF network element, so in S101, the NF network element may obtain the domain name allocated by the OAM. In addition, the domain name of the NF network element may also be allocated by other devices, or may be stored in a local configuration such as the factory configuration of the NF network element.
[0101] For example, after being started (e.g., instantiated), the NF network element may execute S101 to request domain name verification. After the domain name verification is successful, the NF network element may obtain a domain name certificate, which is used as a trust certificate for inter-NF communication. Alternatively, the NF network element may execute S101 to initiate domain name verification when communicating with other NFs.
[0102] Optionally, the NF network element also obtains information of the first authentication device.
[0103] The information of the first authentication device is described below.
[0104] It is understood that the information about the first authentication device in S101 can be used by the NF network element to send information or messages to the first authentication device. For example, the NF network element can send a domain name verification request to the first authentication device based on the information about the first authentication device. The information about the first authentication device may include the identifier or address information of the first authentication device. The address information may include the domain name or IP address of the first authentication device, or a combination of an IP address and a port number.
[0105] Optionally, the first authentication device can be deployed in the same network as the NF network element. In this application, the network can refer to a PLMN, a security domain, an operator network, etc., without specific limitation.
[0106] S102: The NF network element sends the domain name of the NF network element to the first authentication device. The domain name of the NF network element is used to verify the NF network element.
[0107] Optionally, the NF network element may initiate domain name verification to the first authentication device based on the ACME protocol. The domain name verification method required by the ACME protocol will be described below in conjunction with embodiments and will not be expanded here.
[0108] As an example of S102, after the NF network element is started and / or before the NF network element communicates with other network elements, the NF network element may execute S102 to obtain a certificate required for communication.
[0109] S103: The first authentication device verifies the NF network element according to the domain name of the NF network element.
[0110] In S103, the verification of the NF network element by the first authentication device includes identity verification of the NF network element. Specifically, it may be verification of the ownership or possession of the domain name provided by the NF network element by the NF network element.
[0111] The first authentication device can perform domain name verification on the NF network element based on the ACME protocol to achieve NF network element authentication. As previously described, based on the ACME protocol, the first authentication device can perform domain name verification using HTTP-01 and / or DNS-01. Domain name verification methods based on the ACME protocol are described below with reference to Figures 4 and 5 and will not be expanded upon here.
[0112] S104: The NF network element obtains the first domain name certificate issued by the first authentication device.
[0113] In one possible embodiment of S104, the first authentication device may send the first domain name certificate to the NF network element according to the certificate issuance request of the NF network element. In another possible embodiment of S104, the first authentication device may submit (or publish) the first domain name certificate to a CA or ACME server, so that in S104, the NF network element may obtain (e.g., download) the first domain name certificate from the CA or ACME server.
[0114] For example, the first domain name certificate may include the domain name of the NF network element. Subsequently, when the NF network element needs to obtain services from an NF service provider (NF producer, NFp) or needs to communicate with other network elements, it can send a message carrying the first domain name certificate. The network element receiving this message can confirm that the NF network element has passed verification based on the first domain name certificate, thereby enabling further communication with the NF network element.
[0115] Based on the process shown in Figure 3 above, the NF network element in the service-oriented architecture can obtain its own domain name and the information of the first authentication device, and provide the domain name to the first authentication device based on the information of the first authentication device. The first authentication device can further verify the NF network element based on the domain name and issue a first domain name certificate. Accordingly, the NF network element can obtain a certificate issued by the first authentication device. Therefore, this application provides a NF network element authentication method suitable for a server-oriented architecture, which can improve the efficient authentication and certificate issuance of NF network elements in the service-oriented architecture.
[0116] Based on the process shown in Figure 3, this application can further improve the authentication reliability of the NF network element according to the type information of the NF network element.
[0117] In a possible embodiment, the domain name of the NF network element in this application corresponds to the type information of the NF network element and / or the identifier (ID) of the NF network element. The type information of the NF network element can be used to indicate the function or type of the NF network element. For example, when the type of the NF network element is AMF, the type information of the NF network element can be used to indicate that the NF network element is AMF. The type information of the NF network element can be "AMF" or an index used to indicate that the type of the NF network element is AMF. In addition, the identifier of the NF network element can be a device identifier of the NF network element.
[0118] As an example of the above correspondence, the domain name of a NF network element can include the type information of the NF network element. In other words, the type information of the NF network element can be used as part of its domain name. In addition, a domain name can be assigned to the NF network element based on the type information of the NF network element. Accordingly, the domain name can be used to identify the type information of the NF network element. For example, the domain name of the NF network element itself does not include the type information of the NF network element, but rather includes information corresponding to the type information.
[0119] Optionally, the domain name of the NF network element also corresponds to the identifier (ID) of the NF network element. For example, the domain name of the NF network element includes the identifier of the NF network element.
[0120] As an example, the domain name of the AMF network element identified as "1234" can be "1234.AMF.aaa.bbb". "aaa" can be the name or abbreviation of a specific business entity, such as an operator, and "bbb" can represent the top-level domain name registered by the business entity, such as com or org, or a country domain name code, such as cn.
[0121] In this embodiment, the NF network element may optionally further send the NF network element's type information to the first authentication device, for the first authentication device to verify the type information sent by the NF network element and the type information corresponding to the NF network element's domain name. If the two types of information are consistent, S103 may be further executed, i.e., verifying the NF network element based on the domain name. Optionally, the domain name and type information of the NF network element may be carried in the same information or message sent by the NF network element to the first authentication device, or they may be carried in different information or messages. For example, in S102, the NF network element may send the NF network element's domain name and type information to the first authentication device, where the domain name and the type information of the NF network element have a corresponding relationship. Accordingly, before S103, the first authentication device may determine the corresponding type information based on the domain name provided by the NF network element, and verify the type information provided by the NF network element with the type information corresponding to the domain name to verify whether the NF network element is impersonating the domain name of another network element or device. Among them, the association between the domain name and type information of the NF network element can be known to the first authentication device. For example, the management device used to allocate the domain name of the NF network element can provide the corresponding relationship to the first authentication device, or the management device and the first authentication device can obtain the corresponding relationship based on the same configuration.
[0122] If the comparison result of the first authentication device shows that the two types of information are consistent, it means that the domain name and the type information provided by the NF network element match, and the NF network element's ownership of the domain name can be further verified. Otherwise, if the comparison result of the first authentication device shows that the two types of information are inconsistent, it means that the domain name and the type information provided by the NF network element do not match, and there may be domain name impersonation. In this case, further verification is rejected, or it is determined that the NF network element has failed verification. In other words, the first authentication device can execute S103 if it determines that the type information provided by the NF network element is consistent with the type information determined based on the domain name of the NF network element. This can prevent the NF network element from impersonating the identity information of another network element or device from obtaining a domain name certificate. In this application, the identity information may include one or more of the domain name, type information, or domain name certificate.
[0123] Alternatively, when issuing the first domain name certificate, the first authentication device may add the type information of the NF network element to a field such as an extension field of the first domain name certificate to indicate that the type information of the NF network element has been verified. Furthermore, the domain name included in the first domain name certificate may also be used to determine the verified type information of the NF network element. For example, the domain name of the NF network element in the first domain name certificate may include the type information, or the domain name of the NF network element in the first domain name certificate may correspond to the type information.
[0124] Furthermore, in this embodiment, when a NF network element needs to communicate with another network element (e.g., to obtain services from an NFp), the NF network element may include a first domain name certificate and type information in the communication request sent to the other network element. The first domain name certificate may include the NF's domain name. The NF network element's domain name corresponds to the NF network element's type information, and / or the type information may be included in an extension field or other field in the first domain name certificate. Accordingly, before establishing communication with the NF network element, the other network element may inspect the received first domain name certificate. This inspection may include comparing or verifying the type information provided by the NF network element in the communication request with the type information determined based on the first domain name certificate. If the comparison results are inconsistent, the service request may be rejected, indicating possible fraudulent use of the domain name certificate. If the comparison results are consistent, the NF network element's service request may be further processed, such as to determine whether the domain name certificate is legitimate. The type information determined based on the first domain name certificate may specifically be type information corresponding to the domain name of the NF network element determined based on the domain name of the NF network element in the first domain name certificate, or may be type information included in a field such as an extension field of the first domain name certificate.
[0125] In addition, the type information corresponding to the domain name in the first domain name certificate can also be compared with the type information contained in the extension field or other fields in the first domain name certificate to verify whether the first domain name certificate is forged, further improving the reliability of communication. For example, if the type information corresponding to the domain name in the first domain name certificate is inconsistent with the type information carried in the extension field of the first domain name certificate, it indicates that the first domain name certificate may be forged. In this case, the network element that receives the first domain name certificate can refuse to establish a connection with the NF network element that provided the first domain name certificate.
[0126] The following describes how the NF network element obtains the domain name of the NF network element.
[0127] As a possible way, the NF network element can obtain the domain name of the NF network element from local configuration information. For example, before the NF network element is started, the NF network element creation and configuration device (or management device) can provide the NF network element with the domain name of the NF network element and / or the information of the first authentication device during the configuration process of the NF network element; for example, the domain name of the NF network element and / or the information of the first authentication device can be included in the initialization information configured by the NF network element creation and configuration device to the NF network element, and the NF network element can be configured according to the initialization information during the startup process. The initialization information can also include the type information and / or identifier of the NF network element. In addition, the domain name of the NF network element and / or the information of the first authentication device can also be included in the local configuration information such as the factory configuration of the NF network element. The NF network element creation and configuration device can be, for example, an OAM device or an NRF network element, or can be other network elements or devices for providing NF network element creation and / or configuration functions.
[0128] Taking the OAM device as an example of a device for creating and configuring NF network elements, after determining to start a NF network element, the OAM device can configure a domain name and IP address for the NF network element based on the NF network element's configuration policy. Specifically, the OAM device can determine to start the NF network element based on a startup instruction from the NF network element. This instruction can be sent by another network element or device, or manually triggered. Optionally, the startup instruction can include type information and / or an identifier of the NF network element, so that the OAM device can configure the domain name of the NF network element based on the type information and / or identifier of the NF network element. The OAM device can send the domain name of the NF network element to the NF network element. Furthermore, the OAM device can also send a registration message to a DNS server, including the domain name and IP address of the NF network element, to register the domain name and IP address of the NF network element with the DNS server. Furthermore, the OAM device can also send a startup message to the NF network element to start the NF network element.
[0129] As another possible approach, the NF network element may receive the domain name of the NF network element from an OAM device, such as a device that creates and configures the NF network element. For example, after startup, or when there is a need to communicate with other NF network elements, the NF network element may send a domain name request or registration request to the OAM device. The OAM device may then provide the NF network element with the domain name of the NF network element and / or information about the first authentication device based on the request of the NF network element. The OAM device may configure the domain name and IP address of the NF network element and send the domain name and IP address to the NF network element after determining to start the NF network element and / or after sending a startup message to the NF network element to start the NF network element. The OAM network element may also send the domain name of the NF network element to the NF network element and / or send a registration message containing the domain name and IP address of the NF network element to the DNS server after receiving the domain name request or registration request from the NF network element. It is understood that the communication method between the NF network element and an OAM device, such as a device that creates and configures the NF network element, is not within the scope of this application.
[0130] Optionally, the NF network element may also obtain type information from the NF network element creation and configuration device. For example, the type information may be included in configuration information provided by the NF network element creation and configuration device to the NF network element, or the NF network element may receive type information from the NF network element creation and configuration device. The type information of the NF network element may be carried in the same system or in a different message or information than the domain name of the NF network element.
[0131] It is understood that, similar to how a NF network element obtains a domain name, the NF network element can obtain the first authentication device information from local configuration information, or it can receive the first authentication device information from a NF network element creation and configuration device, such as an OAM device. If the NF network element obtains the domain name and first authentication device information from local configuration information, the domain name and first authentication device information can both be factory-configured configuration information or configuration information from the NF network element creation and configuration device. Alternatively, either the domain name or the first authentication device information can be factory-configured configuration information, while the other can be configuration information from the NF network element creation and configuration device. If the NF network element receives the domain name and first authentication device information from the NF network element creation and configuration device, the domain name and first authentication device information can come from the same device, such as an OAM device. Furthermore, the domain name and first authentication device information can be carried in the same or different messages. For example, the OAM device can carry the domain name and first authentication device information in the same message.
[0132] Optionally, the NF network element may also obtain, from local configuration information, information required for domain name verification of the first authentication device, such as a root certificate and / or domain name verification method configuration. This root certificate can be used to verify the certificate provided by the first authentication device during the certificate application process, thereby indicating that the first authentication device is a trusted entity. The domain name verification method configuration can be used to configure the challenge type used by the NF network element for domain name verification, where the challenge type can be HTTP-01 or DNS-01. Optionally, the root certificate and other information required for domain name verification of the first authentication device can be included in the same local configuration information of the NF network element, along with the NF network element's domain name and / or information about the first authentication device.
[0133] Alternatively, the NF network element may also receive information required for domain name verification of the first authentication device, such as a root certificate and / or domain name verification method configuration, from a device that creates and configures the NF network element. Optionally, the root certificate and other information required for domain name verification of the first authentication device may be carried along with the domain name of the NF network element and / or information about the first authentication device in the same configuration information or configuration message sent by the device that creates and configures the NF network element to the NF network element. For example, the initialization information sent by the OAM device to the NF network element may include the domain name of the NF network element, information about the first authentication device, and the root certificate and other information required for domain name verification of the first authentication device.
[0134] The verification process in S103 is described below with reference to FIG. 4 and FIG. 5 .
[0135] As shown in Figure 4, the domain name verification process based on the ACME protocol can be performed by an ACME client and an ACME server. As shown in Figure 5, the ACME client can be deployed in a NF network element, for example, the ACME client can be a functional module in the NF network element. The ACME server can be deployed in an authentication device, for example, the ACME server can be a functional module in the authentication device.
[0136] As shown in Figure 4, a NF network element can initiate domain name verification based on the ACME protocol. For example, in S102, upon startup, the NF network element can request domain name verification based on the following process: obtaining a public-private key pair based on a root certificate and sending an account registration request to the ACME server to register the public-private key pair and account. The public-private key pair can be used for encrypted communication between the ACME client and the ACME server. The account can be used to manage metadata related to domain name verification. After registration, the ACME client can request a certificate order from the ACME server, such as by sending a verification request including the domain name. In response to the verification request, the ACME server can send a token and supported challenge types for the domain name to the ACME client. Challenge types can include HTTP-01 and / or DNS-01. The ACME client can then select a challenge type and provision key authorization. Based on the selected challenge type, the ACME client can also write a challenge response to the device, function, or service request corresponding to the challenge type. The challenge response can be generated based on challenge information provided by the ACME server. The challenge information can be a random number generated by the ACME server, which the ACME client can download from the server. The challenge response can be generated by concatenating a random number provided by the ACME server, the ACME client's account public key, and a challenge verification method such as HTTP-01 into a string of characters and inputting it into a hash function to obtain a hash value, which is used as the challenge response.
[0137] Among them, if the challenge type selected by the ACME client is HTTP-01 challenge, the function or service corresponding to the challenge type may include an Internet (web) server. In this application, the web server may be a functional module in the NF network element. Among them, the web server in the ACME client can be used to provide domain name verification based on HTTP-01 challenge. Specifically, the ACME client can request the web server to write a challenge response in a specified directory and return the above challenge response content to the ACME server via the HTTPS protocol when receiving an access request from the ACME server. The ACME server can verify whether the challenge response returned via the HTTPS protocol is consistent with the challenge response generated based on a random number to verify whether the challenge is passed.
[0138] In addition, if the challenge type selected by the ACME client is a DNS-01 challenge, the device corresponding to the challenge type may be a DNS server. In this application, the ACME client may be used to request that a challenge response (herein referred to as a DNS challenge response) be written to the DNS server. Specifically, the DNS challenge response may be written to the record of the NF network element domain name in the DNS server. In other words, the DNS server may write the DNS challenge response to the record of the corresponding domain name based on the domain name of the NF network element.
[0139] Optionally, during the process of the ACME client requesting the DNS server to write the DNS challenge response into the record of the NF network element domain name, the NF network element may send a DNS challenge response to the second device, requesting the second device to write the DNS challenge response into the record of the NF network element domain name in the DNS server. Accordingly, upon receiving a notification from the ACME client indicating that the DNS challenge response has been written to the DNS server, the ACME server may read the DNS challenge response from the record associated with the domain name to be verified in the DNS server. If the DNS challenge response is verified against the characteristic information, the NF network element may be determined to have passed verification. The verification method may, for example, concatenate a corresponding random number stored on the ACME server with the ACME client's key and the challenge verification method DNS-01, and input the result into a hash function to obtain a hash value. The hash value is then verified against the DNS challenge response extracted from the DNS record. If the verification result is that the hash value DNS challenge response is identical, the ACME server determines that the NF network element has passed verification. If the verification result is that the hash value DNS challenge response is different, the ACME server determines that verification has failed.
[0140] Exemplarily, the second device may be a DNS challenge response writing device, configured to write the DNS challenge response of the NF to be verified to the DNS server. Specifically, the second device may be an OAM device or an NRF. The second device may have permission to modify the DNS server's domain name records and may be configured to filter out illegal DNS notification message write requests.
[0141] For example, when a NF network element requests a second device to modify a domain name in a DNS server, the second device only supports modifying records associated with the domain name of the NF network element. The second device can obtain and store the domain name of the NF network element during the connection establishment process with the NF network element, for example, storing the association between the domain name of the NF network element and connection information (such as tunnel information). When the second device receives a DNS challenge response from the NF network element, it can query the domain name of the NF network element based on the connection information received in the DNS challenge response to determine the domain name of the NF network element, and modify the record with the corresponding domain name in the DNS server, thereby writing the DNS challenge response to the record with the corresponding domain name in the DNS server. Therefore, the second device can only request the DNS server to write the DNS challenge response to the record corresponding to the domain name of the NF network element, which can prevent the NF network element from providing a false domain name when requesting the second device to write a DNS challenge response. In other words, even if the NF network element provides a false domain name when requesting to write a DNS challenge response, if the second device determines that the domain name of the NF network element when establishing a connection with the NF network element is inconsistent with the false domain name, it can refuse to modify the domain name record in the DNS server, thereby avoiding network security risks caused by impersonation of domain names. In addition, if the ACME server determines that the HTTP-01 challenge passes or the DNS-01 challenge passes, it may provide the ACME client with information indicating that the verification passed.
[0142] Optionally, after receiving information from the ACME server indicating successful verification, the ACME client can send a CSR to the ACME server. In response to the CSR, the ACME server can request the CA module of the first authentication device to issue a first domain name certificate. The first domain name certificate can indicate that the NF network element has passed verification, meaning that the NF network element has obtained communication permission.
[0143] It is understood that the communication permissions for the NF network element represented by the first domain name certificate are related to the scope of validity or authority of the first authentication device. For example, if the first authentication device only has permission to authenticate the NF network element within the network where the authentication device resides, then the first domain name certificate only indicates that the NF network element has communication permissions within that network. The first authentication device and the NF network element may belong to the same or different networks. For another example, if the first authentication device has permission to authenticate NF network elements in multiple networks, the first domain name certificate may indicate the NF network element's permission to communicate across multiple networks.
[0144] It can also be understood that the above actions performed by the ACME client can be replaced by being performed by the NF network element, and the above actions performed by the ACME server can be replaced by being performed by the first authentication device.
[0145] In one embodiment of the present application, if the OAM device is used as a management device for providing domain names to NF network elements, a network element verification method provided in an embodiment of the present application may include the steps shown in FIG6 :
[0146] S201: After receiving the startup instruction of the NF network element, the OAM device allocates a domain name and an IP address to the NF network element according to the domain name generation policy. The OAM device may generate the domain name according to the domain name generation policy, the type information and the identifier of the NF network element.
[0147] The NF network element startup instruction can be used to trigger OAM device configuration and / or startup of the NF network element. The NF network element startup instruction can include the type information and / or identification of the NF network element. The NF network element startup instruction can be manually triggered on the OAM device or triggered by another network element or control device to the OAM device.
[0148] In addition, S201 can also be replaced by: after obtaining the NF startup instruction, the OAM device provides the type information and identifier of the NF network element to the domain name issuance function. At this time, the domain name issuance function can generate a domain name based on the domain name generation policy, the type information and identifier of the NF network element. For example, the domain name can include the identifier and type information of the NF network element. The domain name issuance function can also provide the domain name of the NF network element to the OAM. Optionally, the domain name issuance function can be part of the OAM device, for example, the domain name issuance function is a functional module deployed in the OAM device. In addition, the domain name issuance function can also be an entity independent of the OAM device. In this case, the domain name issuance function as an entity can have a communication interface with the OAM device.
[0149] S202: The OAM device sends a registration message to the DNS server to register the domain name and IP address of the NF network element with the DNS server. The registration message may include the domain name and IP address of the NF network element.
[0150] S203: Before starting the NF network element, the OAM device sends initialization information to the NF network element. The information includes the NF network element's domain name, IP address, information about the first authentication device, and the first authentication device's root certificate. The initialization information may also include the NF network element's type and / or identifier. The initialization information may also include configuration information for ACME-based authentication, such as HTTP-01 and / or DNS-01 challenge information.
[0151] The first authentication device may be deployed with an ACME server, which may be a CA or other network element or device.
[0152] It can be understood that the step in S203 where the OAM device provides the domain name to the NF network element can be considered as an example of an implementation of S101.
[0153] S204: Optionally, the OAM starts the NF network element.
[0154] S205: After the NF network element is started, it obtains the domain name, IP address, address of the first authentication device, and root certificate of the NF network element from the initialization information.
[0155] S206: The NF network element starts the ACME client.
[0156] Optionally, the NF network element may also start a web server. Alternatively, the NF network element may start the web server after deciding to use the HTTP-01 challenge.
[0157] S207: The ACME client of the NF network element requests the ACME server of the first authentication device to create an ACME account according to the configuration information.
[0158] S208: The ACME client of the NF network element requests the ACME server to create a certificate order for initiating a challenge verification based on the ACME protocol. The challenge verification process can be referred to Figure 4.
[0159] It is understood that in the ACME protocol-based challenge, the NF network element may send the domain name of the NF network element to the first authentication device. For example, the domain name may be included in the certificate order request. This action can be considered as an example of an implementation of S102. In addition, the ACME protocol-based challenge can be considered as an example of an implementation of S103.
[0160] Figure 6 uses the DNS-01 challenge as an example for illustration.
[0161] Optionally, if the DNS-01 method is used for the domain name challenge, the NF network element may request the second device to write the DNS challenge response to the DNS server. For example, in S209, the NF network element may send the DNS challenge response to the second device. It should be understood that the description in Figure 6 uses the example of the second device being OAM-identified as an example and should not be construed as limiting. Optionally, the second device may send the NF network element's domain name to the DNS server.
[0162] S210: The second device may determine the domain name of the NF network element according to the connection information of the received DNS challenge response.
[0163] The second device can obtain and store the domain name of the NF network element during the process of establishing a connection with the NF network element. Therefore, after receiving a DNS challenge response through the connection, the second device can determine the domain name of the NF network element based on the connection information of the connection for which the DNS challenge response was received, and modify the DNS challenge response to the domain name record in the DNS server based on the domain name. Therefore, even if the NF network element impersonates another domain name and requests the second device to modify the record of the impersonated domain name, if the second device determines that the domain name of the NF network element when the second device established a connection with the NF network element is inconsistent with the impersonated domain name, it can refuse to modify the domain name record in the DNS server, thereby avoiding network security risks caused by the impersonation of the domain name.
[0164] S211: The second device sends a DNS challenge response to the DNS server. The DNS challenge response may be generated by the ACME client of the NF network element based on the DNS challenge information obtained from the ACME server. Optionally, the second device may provide the DNS server with the domain name of the NF network element, so that the DNS server can modify the record of the domain name.
[0165] S212: The DNS server writes the DNS challenge response into the record of the domain name of the NF network element in the DNS server.
[0166] S213: The DNS server indicates to the second device that the domain name record modification of the DNS server is completed, such as sending a domain name record modification completion indication.
[0167] S214: The second device indicates to the ACME client of the NF network element that the modification of the domain name record of the DNS server is completed.
[0168] S215: The ACME client of the NF network element sends a message to the ACME server indicating that the modification of the domain name record of the DNS server is completed.
[0169] S216: The ACME server obtains the DNS challenge response from the domain name record of the NF network element in the DNS server. Subsequent verification can be performed based on the DNS challenge response and the DNS challenge information, as shown in FIG4 .
[0170] S217: If the ACME server determines that the DNS challenge response obtained from the DNS server matches the DNS feature information provided to the ACME client, it confirms that the DNS-01 challenge is passed.
[0171] S218: If the ACME server determines that the DNS-01 challenge passes, it provides information indicating that the verification has passed to the ACME client. Alternatively, the ACME client may send an access request to the ACME server, and the ACME server may provide information indicating that the verification has passed to the ACME client based on the access request.
[0172] S219: The ACME client sends the CSR to the ACME server.
[0173] S220: The ACME server provides the first domain name certificate to the ACME client.
[0174] S220 can be considered as an example of an implementation of S104. For example, in S220, the ACME server can store the issued first domain name certificate in a designated directory of the ACME server, and the ACME client can download the first domain name certificate from the designated directory.
[0175] It can be understood that in the process shown in Figure 6 above, the ACME client refers to the ACME client deployed in the NF network element, and the ACME server refers to the ACME server deployed in the first authentication device.
[0176] In one possible embodiment of the present application, when a NF network element has not yet obtained a certificate supporting communication with network elements or devices in a network other than the network in which the NF network element is located (e.g., referred to as the first network), the NF network element may obtain the certificate from an authentication device in the other network (e.g., the second network) through a CMF network element. It will be understood that the first network and the second network may be different PLMNs or operator networks, respectively. For ease of explanation, the authentication device in the second network may be referred to as a second authentication device.
[0177] It is understandable that the second authentication device may be understood to belong to a different network than the NF network element. For example, the first authentication device and the second authentication device are authentication devices deployed in different networks.
[0178] In this embodiment, the NF network element may send a domain name certificate acquisition request to the CMF network element. The domain name certificate acquisition request may be used to request a certificate of the NF network element issued by the second authentication device. The domain name certificate acquisition request may include the domain name of the NF network element.
[0179] Optionally, the domain name certificate acquisition request may also include information about a second authentication device. For example, the second authentication device information may include an identifier or address of the second authentication device. The second authentication device information may be provided by the management device to the NF network element, for example, by referring to the method used to provide information about the first authentication device. Alternatively, the second authentication device information may be configured in the CMF network element, for example, by the management device providing the second authentication device information to the CMF network element. In this case, the NF network element does not need to obtain and provide the second authentication device information to the CMF network element.
[0180] Accordingly, upon receiving the domain name certificate acquisition request, the CMF network element can send the domain name of the NF network element to the second authentication device to trigger the second authentication device to verify the NF network element. For example, referring to the ACME protocol, the CMF network element can request the second authentication device to create a certificate order, such as sending a verification request containing the domain name.
[0181] The second authentication network element can use a domain name verification method based on the ACME protocol to perform verification based on the domain name of the NF network element. For example, the verification method of the second authentication device can refer to the instructions for the first authentication network element to verify the NF network element based on the domain name. After determining that the domain name of the NF network element passes the HTTP-01 challenge or DNS-01 challenge, the second authentication device determines that the NF network element has passed the authentication. The CMF network element can obtain the permission to modify the domain name record of the web server or DNS server. Therefore, during the HTTP-01 challenge process, the CMF network element can write the challenge response to the web server; during the DNS-01 challenge process, the CMF network element can write the DNS challenge response to the DNS server. The verification process of the second authentication network element can refer to the description of the process shown in Figure 7.
[0182] Optionally, communication between the NF and the CMF can be based on a first domain name certificate issued by a first authentication device to the NF network element. In other words, before the NF network element sends a domain name certificate acquisition request to the CMF, it needs to establish communication with the CMF network element based on the first domain name certificate. The CMF network element can determine that the NF network element has passed the verification of the first authentication device based on the first domain name certificate, or in other words, determine that the NF network element obtains communication authority based on the first domain name certificate. For example, the CMF network element can parse the first domain name certificate to obtain the domain name of the NF network element, and compare it with the domain name provided by the NF network element to determine whether the NF network element has impersonated the domain name certificate of another network element, thereby avoiding providing a certificate issued by the second authentication device to the NF network element that has impersonated the domain name certificate of another network element.
[0183] If the CMF network element determines that the first domain name certificate has passed authentication, that is, the first domain name certificate of the NF network element is a qualified domain name certificate, an indication (such as a first indication) indicating that the authentication of the first domain name certificate has passed may be sent to the NF network element. The function of the first indication may also be described as: being used to indicate that the NF network element is allowed to request a domain name certificate issued by the second authentication device.
[0184] In addition, when the domain name of the NF network element contains the type information of the NF network element, or when the domain name of the NF network element corresponds to the type information of the NF network element, the CMF network element may also determine the type information of the NG network element based on the first domain name certificate, and compare the type information determined based on the first domain name certificate with the type information provided by the NF network element in the connection request to see if they are consistent. The CMF network element may establish a connection with the NF network element and / or send a first indication only when the type information determined based on the first domain name certificate is consistent with the type information provided by the NF network element. If the type information determined based on the first domain name certificate is inconsistent with the type information provided by the NF network element, the CMF network element may refuse to establish a connection with the NF network element, so that the NF network element cannot obtain the domain name certificate issued by the second authentication device, thereby preventing the NF network element from obtaining a certificate issued by the second authentication device by impersonating the identity information of another network element.
[0185] Among them, the CMF network element can obtain the authority to communicate with the NF network element. For example, the CMF and the NF network element can be located in the same network, and the CMF can obtain a domain name certificate (for example, called a third domain name certificate) issued by the first authentication device to indicate that the CMF has passed the verification.
[0186] In addition, the CMF network element can also obtain permission to communicate with network elements in the second network (such as including the second authentication device). For example, the CMF network element can also obtain a domain name certificate (such as a fourth domain name certificate) issued by the second authentication device, that is, this certificate can be used by the CMF to communicate with network elements in the second network. For another example, the CMF network element is configured to have permission to communicate with the second authentication device, such as when a connection has been established between the CMF network element and the second authentication device.
[0187] As an example, a CMF network element can be deployed with an ACME client, for example, as an internal module of the CMF network element. Accordingly, the second authentication device can be deployed with an ACME server to perform domain name authentication based on the ACME protocol with the ACME client of the CMF network element (or other network elements). Furthermore, a web server can be deployed in the CMF network element to support HTTP-01-based challenges.
[0188] Optionally, the CMF network element may also deploy a certificate proxy module, and accordingly, the NF network element may also deploy a certificate proxy module. The certificate proxy module of the NF network element may be configured to request the certificate proxy module of the CMF network element to obtain the domain name certificate issued by the second authentication device. For example, the certificate proxy module of the NF network element may be configured to send a domain name certificate acquisition request to the certificate proxy module of the CMF network element. In addition, the first indication and / or the second domain name certificate may be transmitted between the certificate proxy module of the NF network element and the certificate proxy module of the CMF network element.
[0189] As shown in Figure 7, when the NF network element requests the domain name certificate issued by the second authentication device through the CMF network element, the process may include the following steps:
[0190] S301: The NF network element sends the first domain name certificate of the NF network element to the CMF network element to request to establish a TLS connection with the CMF.
[0191] The first domain name certificate may be used to indicate that the NF network element has passed the verification of the first authentication device. The first domain name certificate may include the domain name of the NF network element.
[0192] It is understandable that before S301, the NF network element may obtain the first domain name certificate with reference to the process shown in FIG6 .
[0193] S302: The CMF network element determines whether the first domain name certificate meets the requirements.
[0194] For example, the NF network element may provide a domain name to the CMF network element in S301, and the CMF network element may determine whether the domain name contained in the first domain name certificate is consistent with the domain name provided by the NF network element. If they are consistent, subsequent steps may be executed.
[0195] For example, the NF network element can also provide type information to the CMF network element in S301. In S302, the CMF network element can verify whether the type information provided by the NF network element is consistent with the type information determined according to the domain name in the first domain name certificate (or the type information contained in the first domain name certificate). If they are consistent, the subsequent steps can be executed.
[0196] In addition, the CMF network element can also compare the type information corresponding to the domain name in the first domain name certificate and the type information contained in the extension domain and other fields in the first domain name certificate to see if they are consistent. If they are consistent, the subsequent steps can be executed.
[0197] S303: Optionally, the CMF network element may determine whether the NF network element has the authority to obtain the certificate issued by the second authentication device.
[0198] For example, a management device or an NRF network element may provide a permission configuration to the CMF network element. The permission configuration may be used to indicate the type information and / or identifier of the NF network element that is permitted and / or prohibited from obtaining a certificate issued by the second authentication device. If the NF network element is not one of the NF network elements that is prohibited from obtaining a certificate issued by the second authentication device, S304 may be executed.
[0199] S304: The CMF network element sends a first indication to the NF network element, indicating that the first domain name certificate authentication is successful.
[0200] S305: The NF network element sends a domain name certificate acquisition request to the CMF network element, which includes the domain name of the NF network element.
[0201] S306: The ACME client of the CMF network element requests the ACME server of the second authentication device to create a certificate order for initiating a domain name challenge verification based on the ACME protocol. The ACME client needs to send the domain name of the NF network element to the ACME server to implement the challenge verification of the domain name.
[0202] The process for a domain name challenge initiated by the CMF can be seen in Figure 4. The difference is that the domain name being verified is not the domain name of the CMF element itself, but that of the NF element. Furthermore, the CMF element has permission to modify the domain name records of the web server or DNS server. Therefore, during a domain name challenge, the CMF element can modify the domain name records of the NF element through the web server or DNS server.
[0203] S307: After determining that the domain name of the NF network element has passed the verification, the ACME server of the second authentication device sends information indicating that the verification has passed to the CMF network element, thereby indicating that the NF network element has passed the verification of the second authentication device.
[0204] S308: The ACME client of the CMF network element sends a CSR to the ACME server of the second authentication device, requesting the second authentication device to issue a second domain name certificate for the NF network element.
[0205] S309: The ACME client of the CMF network element obtains the second domain name certificate provided by the second authentication device.
[0206] For example, in S309 , the ACME server in the second authentication device may store the issued first domain name certificate in a designated directory of the ACME server, and the ACME client may download the first domain name certificate from the designated directory.
[0207] S310: The CMF network element sends the second domain name certificate to the NF network element.
[0208] For example, the CMF network element sends the second domain name certificate to the NF network element through the certificate proxy module.
[0209] Based on the process shown in Figure 7, the NF network element can request a second domain name certificate from the second authentication device through the CMF network element. The second authentication device can be deployed in a different network from the NF network element. In this case, the second domain name certificate can obtain communication permissions on behalf of the NF network element in other networks outside its own network, thereby providing secure authentication for the NF network element's cross-network communication.
[0210] Based on the various embodiments shown in this application, the trusted authentication of the NF network element is performed based on the domain name of the NF network element. There is no need to allocate a public key certificate for the NF network element in advance, and there is no need to deploy a complex CA authentication system to verify the public key certificate of the NF network element. A relatively simple authentication system deployment can be achieved under the service-oriented architecture, and a more efficient certificate issuance mechanism can be provided.
[0211] It is understood that, in order to implement the functions in the above embodiments, the base station and the terminal include hardware structures and / or software modules corresponding to the execution of each function. Those skilled in the art should readily appreciate that, in conjunction with the units and method steps of the various examples described in the embodiments disclosed in this application, this application can be implemented in the form of hardware or a combination of hardware and computer software. Whether a function is executed in hardware or in a computer software-driven hardware manner depends on the specific application scenario and design constraints of the technical solution.
[0212] Figures 8 and 9 are schematic diagrams of the structures of possible communication devices provided in the embodiments of the present application. These communication devices can be used to implement the functions of the terminal device or base station in the above-mentioned method embodiments, thereby also achieving the beneficial effects of the above-mentioned method embodiments. In the embodiments of the present application, the communication device can be a NF network element, a management device, a first authentication device, a second device, or a CMF network element, and can also be a component applied to the above-mentioned modules or network elements, such as a functional module or chip.
[0213] As shown in Figure 8, a communication device 800 includes a processing unit 810 and a transceiver unit 820. The communication device 800 is used to implement the functions of the NF network element, management device, first authentication device, second device, or CMF network element in the method embodiments shown in Figures 3, 6, or 7 above.
[0214] When the communication device 800 is used to implement the functions of the NF network element in the method embodiment shown in FIG3 , the processing unit 810 may be configured to obtain the domain name of the NG network element. The transceiver unit 820 may be configured to send the domain name of the NF network element to the first authentication device and obtain a first domain name certificate issued by the first authentication device.
[0215] When the communication device 800 is used to implement the function of the first authentication device in the method embodiment shown in FIG3 , the transceiver unit 820 can be used to receive the domain name of the NF network element. The processing unit 810 can be used to verify the NF network element based on the domain name of the NF network element and issue a first domain name certificate.
[0216] For a more detailed description of the processing unit 810 and the transceiver unit 820 , reference may be made to the relevant description in the method embodiment shown in FIG. 3 .
[0217] As shown in Figure 9, the communication device 900 includes a processor 910 and an interface circuit 920. The processor 910 and the interface circuit 920 are coupled to each other. It will be understood that the interface circuit 920 can be a transceiver or an input / output interface. Optionally, the communication device 900 may further include a memory 930 for storing instructions executed by the processor 910, or storing input data required by the processor 910 to execute instructions, or storing data generated after the processor 910 executes instructions. When the communication device 900 is used to implement the method shown in Figure 4, the processor 910 is used to implement the functions of the above-mentioned processing unit 810, and the interface circuit 920 is used to implement the functions of the above-mentioned transceiver unit 820.
[0218] When the above-mentioned communication device is a chip applied to a NF network element, a management device, a first authentication device, a second device, or a CMF network element, the chip implements the functions of the NF network element, the management device, the first authentication device, the second device, or the CMF network element in the above-mentioned method embodiment. The chip can receive information sent by other network elements or devices to the NF network element, the management device, the first authentication device, the second device, or the CMF network element through other modules (such as communication interfaces) in the NF network element, the management device, the first authentication device, the second device, or the CMF network element, or the chip can send information to other modules (such as communication interfaces) in the NF network element, the management device, the first authentication device, the second device, or the CMF network element. The information is sent by the NF network element, the management device, the first authentication device, the second device, or the CMF network element to other network elements or devices.
[0219] It is understood that the processor in the embodiments of the present application may be a central processing unit (CPU), or may be other general-purpose processors, digital signal processors (DSP), application-specific integrated circuits (ASIC), field programmable gate arrays (FPGA), or other programmable logic devices, transistor logic devices, hardware components, or any combination thereof. The general-purpose processor may be a microprocessor or any conventional processor.
[0220] The method steps in the embodiments of the present application can be implemented in hardware or in software instructions executable by a processor. The software instructions can be composed of corresponding software modules, which can be stored in random access memory, flash memory, read-only memory, programmable read-only memory, erasable programmable read-only memory, electrically erasable programmable read-only memory, registers, hard disk, removable hard disk, CD-ROM, or any other form of storage medium known in the art. An exemplary storage medium is coupled to the processor so that the processor can read information from the storage medium and write information to the storage medium. The storage medium can also be an integral part of the processor. The processor and storage medium can be located in an ASIC. In addition, the ASIC can be located in a NF network element, a management device, a first authentication device, a second device, or a CMF network element. The processor and storage medium can also exist as discrete components in a NF network element, a management device, a first authentication device, a second device, or a CMF network element.
[0221] An embodiment of the present application also provides a communication system, including one or more network elements or devices among a NF network element, a management device, a first authentication device, a second device or a CMF network element for implementing the above-mentioned method embodiment.
[0222] An embodiment of the present application further provides a computer-readable storage medium, which is used to store computer programs or instructions. When the computer-readable storage medium is executed, the method shown in the above method embodiment is implemented.
[0223] The embodiment of the present application also provides a computer program product, which, when executed on a computer, enables the method shown in the method embodiment to be implemented.
[0224] In the above embodiments, all or part of the embodiments may be implemented using software, hardware, firmware, or any combination thereof. When implemented using software, all or part of the embodiments may be implemented in the form of a computer program product. The computer program product includes one or more computer programs or instructions. When the computer program or instructions are loaded and executed on a computer, the processes or functions described in the embodiments of the present application are performed in whole or in part. The computer may be a general-purpose computer, a special-purpose computer, a computer network, a network device, a user device, or other programmable device. The computer program or instructions may be stored in a computer-readable storage medium or transferred from one computer-readable storage medium to another. For example, the computer program or instructions may be transferred from one website, computer, server, or data center to another website, computer, server, or data center via wired or wireless means. The computer-readable storage medium may be any available medium that can be accessed by a computer or a data storage device such as a server or data center that integrates one or more available media. The available medium may be a magnetic medium, such as a floppy disk, hard disk, or magnetic tape; an optical medium, such as a digital video disk; or a semiconductor medium, such as a solid-state drive. The computer-readable storage medium may be a volatile or nonvolatile storage medium, or may include both volatile and nonvolatile types of storage media.
[0225] In the various embodiments of the present application, unless otherwise specified or there is a logical conflict, the terms and / or descriptions between different embodiments are consistent and can be referenced by each other. The technical features in different embodiments can be combined to form new embodiments according to their inherent logical relationships.
[0226] In this application, "at least one" means one or more, and "more" means two or more. "And / or" describes the association relationship of associated objects, indicating that three relationships may exist. For example, A and / or B can mean: A exists alone, A and B exist at the same time, and B exists alone, where A and B can be singular or plural. In the text description of this application, the character " / " generally indicates that the previous and next associated objects are in an "or" relationship; in the formula of this application, the character " / " indicates that the previous and next associated objects are in a "division" relationship. "Including at least one of A, B and C" can mean: including A; including B; including C; including A and B; including A and C; including B and C; including A, B and C.
[0227] It is understood that the various numbers used in the embodiments of this application are merely for ease of description and are not intended to limit the scope of the embodiments of this application. The order of the sequence numbers of the above-mentioned processes does not necessarily imply a specific order of execution; the order of execution of the processes should be determined by their functions and inherent logic.
Claims
1. A network element verification method, characterized in that: include: The network function network element obtains the domain name of the network function network element, and the network function network element is a network element in the service-oriented architecture network; The network function network element sends the domain name of the network function network element to the first authentication device, where the domain name of the network function network element is used to verify the network function network element; The network function network element obtains a first domain name certificate issued by the first authentication device, and the first domain name certificate is used to indicate that the verification is passed.
2. The method according to claim 1, characterized in that The verification is based on the automated certificate management environment ACME protocol.
3. The method according to claim 1 or 2, characterized in that The domain name of the network function network element is determined according to the type information of the network function network element.
4. The method according to any one of claims 1 to 3, characterized in that: The method further comprises: The network function network element sends type information of the network function network element to the first authentication device, where the type information of the network function network element is used to compare type information corresponding to the domain name of the network function network element.
5. The method according to any one of claims 1 to 4, characterized in that: The method further comprises: The network function network element receives domain name service DNS challenge information from the first authentication server; The network function network element generates a DNS challenge response according to the DNS challenge information; The network function network element requests the second device to write the DNS challenge response into the domain name record of the network function network element in the DNS server; The network function network element receives a domain name record modification completion indication from the second device; The network function network element notifies the first authentication device to obtain the DNS challenge response from the DNS server, where the DNS challenge response and the DNS challenge information are used to verify the network function network element; The network function network element receives information indicating that the verification is successful from the first authentication device.
6. The method according to claim 5, characterized in that The method further comprises: The second device receives a DNS challenge response from the network function network element; The second device determines the domain name of the network function network element according to the connection information between the second device and the network function network element; The second device writes the DNS challenge response into the domain name record of the network function network element in the DNS server according to the domain name of the network function network element.
7. The method according to claim 4 or 5, characterized in that The method further comprises: The first authentication device obtains the DNS challenge response from the DNS server; The first authentication device verifies the network function network element according to the DNS challenge response and the DNS challenge information; In the case where the verification is successful, the first authentication device provides the information indicating that the verification is successful to the network function network element.
8. The method according to any one of claims 1 to 7, characterized in that: The first authentication device is deployed in a first network, and the first domain name certificate is specifically used for the network function network element to communicate with the network element in the first network.
9. The method according to claim 8, characterized in that The method further comprises: The network function network element sends a domain name certificate acquisition request to the certificate management network element in the first network according to the first domain name certificate, wherein the domain name certificate acquisition request is used to request a certificate of the network function network element issued by a second authentication device in the second network, and the domain name certificate acquisition request includes the domain name of the network function network element; The network function network element receives a second domain name certificate from the certificate management network element, where the second domain name certificate is issued by the second authentication device.
10. The method according to claim 9, characterized in that The second domain name certificate is used for the network function network element to communicate with the network elements in the second network.
11. The method according to claim 9 or 10, characterized in that The method further comprises: The network function network element receives the information of the second authentication device from the management device, and the domain name certificate acquisition request also includes the information of the second authentication device.
12. The method according to any one of claims 9 to 11, characterized in that: The network function network element sends a domain name certificate acquisition request to a certificate management network element in the first network according to the first domain name certificate, including: The network function network element sends the first domain name certificate to the certificate management network element; The network function network element receives a first indication from the certificate management network element, where the first indication indicates that the first domain name certificate is authenticated; The network function network element sends the domain name certificate acquisition request to the certificate management network element.
13. The method according to claim 12, characterized in that The first domain name certificate includes the domain name and type information of the network function network element, and the type information of the network function network element is used to verify the type information corresponding to the domain name of the network function network element.
14. The method according to any one of claims 1 to 13, characterized in that: The method further comprises: The management device provides the domain name of the network function network element to the network function network element; The management device sends a registration message to the DNS server, where the registration message includes the domain name of the network function network element.
15. The method according to claim 14, characterized in that The method further comprises: The management device sends information of a second authentication device to the network function network element, where the second authentication device is used to issue a second domain name certificate to the network function network element.
16. The method according to any one of claims 1 to 15, characterized in that: The method further comprises: The first authentication device receives the domain name and type information of the network function network element from the network function network element; The first authentication device verifies the type information and type information corresponding to the domain name of the network function network element; If the verification passes, the first authentication device issues the first domain name certificate.
17. The method according to any one of claims 1 to 16, characterized in that: The first domain name certificate includes the domain name and type information of the network function network element, and the type information in the first domain name certificate is used to verify the domain name of the network function network element.
18. A network element verification method, characterized in that: include: The certificate management network element receives a domain name certificate acquisition request from a network function network element, the domain name certificate acquisition request is used to request a certificate of the network function network element issued by a second authentication device in a second network, the domain name certificate acquisition request includes a domain name of the network function network element, the network function network element and the certificate management network element belong to a first network, and the first domain name certificate is used for the network function network element to communicate with a network element in the first network; The certificate management network element sends the domain name of the network function network element to the second authentication device, where the domain name of the network function network element is used to verify the network function network element; The certificate management network element obtains a second domain name certificate issued by the second authentication device, where the second domain name certificate is used to indicate that the verification is successful; The certificate management network element sends the second domain name certificate to the network function network element.
19. The method according to claim 18, characterized in that The method further comprises: The certificate management network element obtains domain name service DNS challenge information from the second authentication device; The certificate management network element generates a DNS challenge response according to the DNS challenge information; The certificate management network element writes the DNS challenge response into the domain name record of the network function network element in the domain name service DNS server; or, the certificate management network element requests the second device to write the DNS challenge response into the domain name record of the network function network element in the DNS server; the certificate management network element receives a domain name record modification completion indication from the second device; The certificate management network element notifies the second authentication device to obtain the DNS challenge response from the DNS server, where the DNS challenge response and the DNS challenge information are used by the second authentication device to verify the network function network element; In the case where the verification is successful, the certificate management network element obtains information provided by the second authentication device indicating that the verification is successful.
20. The method of claim 19, wherein: The method further comprises: The second device receives a DNS challenge response from the certificate management network element; The second device writes the DNS challenge response into the domain name record of the network function network element in the DNS server.
21. The method according to claim 19 or 20, characterized in that The method further comprises: The first authentication device obtains the DNS challenge response from the DNS server; The first authentication device verifies the network function network element according to the DNS challenge response and the DNS challenge information; In the case where the verification is successful, the first authentication device provides the information indicating that the verification is successful to the network function network element.
22. The method according to any one of claims 18 to 21, characterized in that: The method further comprises: The certificate management network element receives a first domain name certificate from the network function network element, where the first domain name certificate is used to indicate that the domain name of the network function network element has passed verification, and the first domain name certificate includes the domain name and type information of the network function network element; The certificate management network element verifies the type information and the type information corresponding to the domain name of the network function network element; If the verification passes, the certificate management network element sends a first indication to the network function network element, where the first indication indicates that the first domain name certificate authentication passes.
23. The method according to any one of claims 18 to 22, characterized in that: The second domain name certificate is used for the network function network element to communicate with the network element of the second network.
24. A communication device, characterized in that: The method comprises a unit or module for executing the method according to any one of claims 1 to 17, or comprises a unit or module for executing the method according to any one of claims 18 to 23.
25. A communication device, characterized in that: The method comprises a processor configured to execute a computer program or an instruction to implement the method according to any one of claims 1 to 17, or to implement the method according to any one of claims 18 to 23.
26. A computer-readable storage medium, characterized in that: The storage medium stores a computer program or an instruction. When the computer program or the instruction is executed by the communication device, the method according to any one of claims 1 to 23 is implemented.
27. A computer program product, characterized in that When the computer program product is executed by a computer, the computer is caused to execute the method according to any one of claims 1 to 17, or the method according to any one of claims 18 to 23.
28. A communication system, characterized in that: include: A network function network element, used to implement the method as claimed in any one of claims 1-5, 8-13, and 17; A certificate management network element, used to implement the method as described in any one of claims 18, 19, 22, and 23.
29. The communication system according to claim 28, characterized in that It also includes a management device for implementing the method according to claim 14 or 15.
30. The communication system according to claim 28 or 29, characterized in that: It also includes a first authentication device for implementing the method as claimed in claims 7, 16, and 21.
31. The communication system according to claim 28 or 29, characterized in that: Also included is a second device for implementing the method according to claim 6 or 20.
Citation Information
Patent Citations
Certificate acquisition method and device
CN106464495A
ACME centralized management system and load balancing method thereof
CN111865992A
Secure communication method and device
CN117118622A
Certificate management method and apparatus
WO2023011158A1