Authentication method and apparatus
The verification value is sent to the terminal device through the core network device, so that the terminal device can authenticate the core network simply and with low power consumption, solving the problem of complex and high energy consumption of terminal device authentication in the prior art. It is suitable for low-cost and low-power environmental Internet of Things terminal devices.
Patent Information
- Application Number
- PCT/CN2024/127899
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2023-10-31
- Filing Date
- 2024-10-28
- Publication Date
- 2025-05-08
AI Technical Summary
The existing technology is difficult to effectively solve the problem of how to authenticate terminal devices with low cost and low power consumption requirements. The existing authentication methods are complex and energy-consuming, and cannot be applied to low cost and low power consumption environmental IoT terminal devices.
The verification value is sent to the terminal device through the core network device, so that the terminal device can authenticate the core network, with simple processes and low power consumption. The specific steps include receiving the first verification value from the core network device, generating the second verification value, and authenticating the core network based on both.
It realizes simple and low-power authentication of terminal devices, and is suitable for environmental IoT terminal devices with low cost and low power consumption requirements, preventing illegal network attacks and user information theft.
Smart Images

Figure CN2024127899_08052025_PF_FP_ABST
Abstract
Description
Authentication method and device
[0001] CROSS-REFERENCE TO RELATED APPLICATIONS
[0002] This application claims priority to the Chinese patent application filed with the State Intellectual Property Office of the People's Republic of China on October 31, 2023, with application number 202311439875.7 and application name "A Authentication Method and Device", the entire contents of which are incorporated by reference into this application. Technical Field
[0003] The present application relates to the field of communication technology, and in particular to an authentication method and device. Background Art
[0004] Passive radio frequency identification (RFID) technology works by converting wireless signals from a reader into energy, which it then uses to power itself. In the development of communications, the introduction of RFID technology into communication networks has been proposed to reduce power consumption in terminal devices. Specifically, a base station can integrate the capabilities of a card reader and transmit wireless signals to a tag, such as a passive or semi-passive terminal device. The terminal device then uses this signal conversion capability to power itself, such as sending data packets to the base station.
[0005] Currently, terminal devices rely on a complex two-way authentication process for authentication. Tags, however, are typically simple in design, low-cost, and have poor measurement capabilities. Therefore, current authentication methods are unsuitable for low-cost, low-power terminal devices. Authentication for these low-cost, low-power terminal devices has become a pressing issue.
[0006] Summary of the Invention
[0007] The present application provides an authentication method and apparatus for reducing the process complexity and power consumption of terminal device authentication.
[0008] In a first aspect, an authentication method is provided. The execution subject of the method can be a terminal device or a chip, chip system or circuit located in the terminal device. The method can be implemented by the following steps: receiving a first verification value from a core network device; generating a second verification value; and authenticating the core network based on the first verification value from the core network device and the generated second verification value.
[0009] This application uses a core network device to send a check value to a terminal device, allowing the terminal device to authenticate the core network, thereby preventing attacks from illegal networks or theft of user information by illegal networks. Furthermore, in this application, a check value generated by the core network device is sent to the terminal device, and the terminal device can authenticate the core network based on the check value it generates and the check value sent by the core network device. This process is simple and has low power consumption.
[0010] In one possible design, the first check value is carried in a first paging message. By sending the check value in a multicast message such as a paging message, multiple terminal devices can be triggered to perform core network authentication simultaneously. Compared to triggering core network authentication via a unicast message, this approach can reduce signaling overhead and enable multiple terminal devices to authenticate the core network in parallel, thereby quickly achieving multiple terminal devices authenticating the core network.
[0011] In one possible design, generating a second verification value includes: generating a second verification value based on at least one of the following: a first key, a first random number, or a second random number, or a first serial number, wherein the first key is a group key, the first random number is a random number indicated by the core network, the second random number is a generated random number, and the first serial number is a serial number for data packet transmission.
[0012] The above method generates a second check value through symmetric information such as the first secret key, so that the second check value can verify the first check value generated by the core network. The authentication method is simple and the power consumption is low.
[0013] In one possible design, the method further includes: receiving at least one of the following: an index of the group key, and a first random number.
[0014] In one possible design, the method also includes: if the core network authentication is successful, sending a random access request; or if the core network authentication is unsuccessful, not sending a random access request.
[0015] The above method can improve communication security by performing random access when the core network authentication is successful.
[0016] In one possible design, the method further includes: sending a third verification value, the third verification value being used to authenticate the terminal device. This method can authenticate the terminal device by sending the third verification value, thereby achieving two-way authentication.
[0017] In one possible design, the third verification value is carried in an authentication request message, and the authentication request message is used to request authentication of the terminal device.
[0018] In one possible design, the method also includes: generating a third verification value based on at least one of the following: a second key, or a third random number, or a first serial number, wherein the second key is a group key or a root key, the third random number is a generated random number, and the first serial number is the serial number of the data packet transmission.
[0019] The above method generates the third check value through symmetric information such as the second secret key, and the authentication method is simple and has low power consumption.
[0020] In one possible design, the method further includes sending at least one of the following: a third random number, a first serial number, or an identifier of the terminal device.
[0021] In one possible design, the method further includes: receiving first information, where the first information is used to indicate whether the authentication method is one-way authentication or two-way authentication. In this way, the authentication behaviors of the terminal device and the core network can be aligned, which is conducive to improving communication security.
[0022] In one possible design, the method further includes: sending a second message, where the second message is used to indicate that the supported authentication method or the specified authentication method is one-way authentication or two-way authentication. In this way, the authentication behaviors of the terminal device and the core network can be aligned, which is conducive to improving communication security.
[0023] In one possible design, the method is applied to an environmental IoT terminal device. The method provided in this application has a simple authentication process and low power consumption, making it more suitable for environmental IoT terminal devices with low cost and low power consumption requirements.
[0024] On the second aspect, an authentication method is provided. The executor of the method can be a core network device or a chip, chip system or circuit located in the core network device. The method can be implemented through the following steps: receiving a service request; sending a first verification value to the terminal device, and the first verification value is used to authenticate the core network.
[0025] This application uses a core network device to send a check value to a terminal device, allowing the terminal device to authenticate the core network, thereby preventing attacks from illegal networks or theft of user information by illegal networks. Furthermore, in this application, the generated check value is sent to the terminal device by the core network device, and the terminal device can authenticate the core network based on the check value sent by the core network device. This process is simple and has low power consumption.
[0026] In one possible design, the first check value is carried in the second paging message. By sending the check value in a multicast message such as a paging message, multiple terminal devices can be triggered to perform core network authentication simultaneously. Compared with triggering core network authentication via a unicast message, this method can reduce signaling overhead and enable multiple terminal devices to authenticate the core network in parallel, thereby quickly achieving multiple terminal devices authenticating the core network.
[0027] In one possible design, the method further includes generating a first check value based on at least one of the following: a first key and a first random number, wherein the first key is a group key and the first random number is a generated random number. This method generates the first check value using symmetric information such as the first key, simplifies the authentication method, and reduces power consumption.
[0028] In one possible design, the method also includes: the method also includes: sending at least one of the following: a group key, a first random number.
[0029] In one possible design, the method further includes: receiving a third verification value, the third verification value being used to authenticate the terminal device; generating a fourth verification value; and authenticating the terminal device based on the first verification value and the fourth verification value. In this method, the terminal device sends the third verification value, and the core network device authenticates the terminal device based on the fourth verification value generated by the core network device and the third verification value of the terminal device, thereby achieving two-way authentication.
[0030] In one possible design, the third verification value is carried in an authentication request message, which is used to request authentication of the terminal device.
[0031] In one possible design, generating a fourth check value includes: generating a fourth check value based on at least one of the following: a second key, or a third random number, or a fourth random number, or a first serial number, wherein the second key is a group key or a root key, the third random number is a random number indicated by the terminal device, the fourth random number is a generated random number, and the first serial number is a data packet number indicated by the terminal device.
[0032] The above method generates a fourth check value through symmetric information such as the second secret key, so that the fourth check value can verify the third check value generated by the terminal device. The authentication method is simple and the power consumption is low.
[0033] In one possible design, the method further includes: receiving at least one of the following: a third random number, a first serial number, or an identifier of the terminal device.
[0034] In one possible design, the method further includes: sending first information, where the first information is used to indicate whether the authentication method is one-way authentication or two-way authentication. In this way, the authentication behaviors of the terminal device and the core network can be aligned, which is conducive to improving communication security.
[0035] In one possible design, the method further includes: receiving second information, where the second information is used to indicate whether the supported authentication method or the specified authentication method is one-way authentication or two-way authentication. In this way, the authentication behaviors of the terminal device and the core network can be aligned, which is conducive to improving communication security.
[0036] In one possible design, the terminal device is an environmental IoT terminal device. The method provided in this application has a simple authentication process and low power consumption, making it more suitable for environmental IoT terminal devices with low cost and low power consumption requirements.
[0037] According to a third aspect, an authentication method is provided. The execution subject of the method may be a terminal device or a chip, chip system or circuit located in the terminal device. The method may be implemented by the following steps: receiving a first paging message from a network device; sending an authentication request message to the network device, the authentication request message carrying a first verification value, the first verification value being used to authenticate the terminal device, and the authentication request message being used to request authentication of the terminal device.
[0038] In this manner, the terminal device can be authenticated by sending the first verification value through the terminal device.
[0039] In one possible design, the method also includes: generating a first verification value based on at least one of the following: a first key, or a first random number, or a first serial number, wherein the first key is a group key or a root key, the first random number is a generated random number, and the first serial number is a serial number of a data packet transmission.
[0040] The above method generates the first check value through symmetric information such as the first secret key, and the authentication method is simple and has low power consumption.
[0041] In one possible design, the method also includes: the authentication request message further indicates a first random number and / or a first serial number.
[0042] In one possible design, the method also includes: the authentication request message further indicates a root key, or the first paging message indicates a group key.
[0043] In one possible design, the method also includes: receiving an authentication acceptance message from a network device, the authentication acceptance message indicating a second verification value; generating a third verification value; and authenticating the core network based on the second verification value and the third verification value.
[0044] By sending a check value to a terminal device through a core network device, the terminal device can authenticate the core network, thereby preventing attacks from illegal networks or theft of user information by illegal networks. In addition, in this application, a check value generated by the core network device is sent to the terminal device. The terminal device can authenticate the core network based on the check value generated by itself and the check value sent by the core network device. This process is simple and power consumption is low.
[0045] In one possible design, generating a third verification value includes: generating the third verification value based on at least one of the following: a second key, a second random number, or a third random number, wherein the second key is a group key or a root key, the second random number is a random number indicated by an authentication acceptance message, and the third random number is a generated random number.
[0046] The above method generates a third check value through symmetric information such as the first secret key, so that the third check value can verify the second check value generated by the core network. The authentication method is simple and the power consumption is low.
[0047] In one possible design, the first paging message indicates whether the authentication method is single authentication or two-way authentication. This method can align the authentication behaviors of the terminal device and the core network, which is conducive to improving communication security.
[0048] In one possible design, before sending an authentication request message to the network device, the method further includes: sending a random access message or a non-access stratum message to the network device, where the random access message or the non-access stratum message indicates a supported authentication method or specifies whether the authentication method is one-way authentication or two-way authentication. This method can align the authentication behaviors of the terminal device and the core network, thereby improving communication security.
[0049] In one possible design, the method is applied to an environmental IoT terminal device. The method provided in this application has a simple authentication process and low power consumption, making it more suitable for environmental IoT terminal devices with low cost and low power consumption requirements.
[0050] In a fourth aspect, an authentication method is provided, the execution subject of the method can be a network device or a chip, chip system or circuit located in the network device, and the method can be implemented by the following steps: receiving a second paging message from a core network device; sending a first paging message to a terminal device; receiving an authentication request message from a core network device, the authentication request message carries a first verification value, the first verification value is used to authenticate the terminal device, and the authentication request message is used to request authentication of the terminal device; sending the authentication request message to the terminal device.
[0051] In this manner, the terminal device can be authenticated by sending the first verification value through the terminal device.
[0052] In one possible design, the authentication request message also indicates a first random number and / or a first serial number.
[0053] In one possible design, the authentication request message also indicates a root key; or, the second paging message indicates a group key, and the first paging message indicates a group key.
[0054] In one possible design, the method also includes: receiving an authentication acceptance message from a core network device, the authentication acceptance message indicating a second verification value, and the second verification value is used to verify the core network; and sending the authentication acceptance message to the terminal device.
[0055] By sending a check value to a terminal device through a core network device, the terminal device can authenticate the core network, thereby preventing attacks from illegal networks or theft of user information by illegal networks. In addition, in this application, a check value generated by the core network device is sent to the terminal device. The terminal device can authenticate the core network based on the check value generated by itself and the check value sent by the core network device. This process is simple and power consumption is low.
[0056] In one possible design, the authentication acceptance message indicates a second random number.
[0057] In one possible design, the second paging message further indicates whether the authentication method is one-way authentication or two-way authentication; the first paging message further indicates whether the authentication method is one-way authentication or two-way authentication. This method can align the authentication behaviors of the terminal device and the core network, which is conducive to improving communication security.
[0058] In one possible design, before receiving the authentication request message, the method also includes: receiving a random access message or a non-access layer message from the terminal device, the random access message or the non-access layer message indicating that the authentication method supported by the terminal device or the specified authentication method is one-way authentication or two-way authentication.
[0059] In one possible design, the terminal device is an environmental IoT terminal device. The method provided in this application has a simple authentication process and low power consumption, making it more suitable for environmental IoT terminal devices with low cost and low power consumption requirements.
[0060] In the fifth aspect, an authentication method is provided, the executor of which can be a core network device or a chip, chip system or circuit located in the core network device. The method can be implemented through the following steps: sending a second paging message to the network device; receiving an authentication request message from the network device, the authentication request message carries a first verification value, and the first verification value is used to authenticate the terminal device; generating a fourth verification value; and authenticating the terminal device based on the first verification value from the terminal device and the generated fourth verification value.
[0061] In this manner, the terminal device can be authenticated by sending the first verification value through the terminal device.
[0062] In one possible design, generating a fourth check value includes: generating a check value based on at least one of the following: a first key, a first random number, or a fourth random number, or a first serial number, wherein the first key is a group key or a root key indicated by an authentication request message, the first random number is a random number indicated by the authentication request message, the fourth random number is a generated random number, and the first serial number is a data packet number indicated by the authentication request message.
[0063] The above method generates a fourth check value through symmetric information such as the first secret key, so that the fourth check value can verify the first check value generated by the terminal device. The authentication method is simple and the power consumption is low.
[0064] In one possible design, the method also includes: sending an authentication acceptance message to the network device, the authentication acceptance message indicating a second verification value, and the second verification value is used to verify the core network.
[0065] By sending a check value to a terminal device through a core network device, the terminal device can authenticate the core network, thereby preventing attacks from illegal networks or theft of user information by illegal networks. In addition, in this application, a check value generated by the core network device is sent to the terminal device. The terminal device can authenticate the core network based on the check value generated by itself and the check value sent by the core network device. This process is simple and power consumption is low.
[0066] In one possible design, the method further includes: generating a second verification value based on at least one of the following: a second secret key, or a second random number, wherein the second secret key is a group key, and the second random number is a generated random number.
[0067] The above method generates the second check value through symmetric information such as the second secret key, and the authentication method is simple and has low power consumption.
[0068] In one possible design, the authentication acceptance message further indicates a second random number.
[0069] In one possible design, the second paging message also indicates whether the authentication method is single authentication or two-way authentication. This method can align the authentication behaviors of the terminal device and the core network, which is conducive to improving communication security.
[0070] In one possible design, the authentication request message indicates the authentication method supported by the terminal device or specifies whether the authentication method is single-way authentication or two-way authentication. This method can align the authentication behaviors of the terminal device and the core network, which is conducive to improving communication security.
[0071] In one possible design, the terminal device is an environmental IoT terminal device. The method provided in this application has a simple authentication process and low power consumption, making it more suitable for environmental IoT terminal devices with low cost and low power consumption requirements.
[0072] In a sixth aspect, the present application further provides a communication device, which is a terminal device or a chip in a terminal device. The communication device has the function of implementing any of the methods provided in the first or third aspects above. The communication device can be implemented in hardware or by hardware executing corresponding software implementations. The hardware or software includes one or more units or modules corresponding to the above functions.
[0073] In one possible design, the communication device includes a processor configured to support the communication device in executing the corresponding functions of the terminal device in the method described above. The communication device may also include a memory, which may be coupled to the processor and stores program instructions and data necessary for the communication device. Optionally, the communication device also includes an interface circuit for supporting communication between the communication device and other devices, such as network equipment, such as the transmission and reception of data or signals. Exemplarily, the communication interface may be a transceiver, circuit, bus, module, or other type of communication interface.
[0074] In one possible design, the communication device includes corresponding functional modules for implementing the steps in the above method. The functions can be implemented by hardware or by hardware executing corresponding software implementations. The hardware or software includes one or more modules corresponding to the above functions.
[0075] In one possible design, the structure of the communication device includes a processing unit and a communication unit, which can perform the corresponding functions in the above method examples. For details, please refer to the description of the method provided in the first aspect or the third aspect, which will not be repeated here.
[0076] In a seventh aspect, the present application further provides a communication device, which is a network device or a chip in a network device. The communication device has the function of implementing any of the methods provided in the fourth aspect. The communication device can be implemented by hardware or by hardware executing corresponding software implementations. The hardware or software includes one or more units or modules corresponding to the above functions.
[0077] In one possible design, the communication device includes: a processor configured to support the communication device in executing the corresponding functions of the network device in the method shown above. The communication device may also include a memory, which may be coupled to the processor and stores the necessary program instructions and data for the communication device. Optionally, the communication device also includes an interface circuit, which is used to support communication between the communication device and devices such as terminal devices and core network devices, such as the transmission and reception of data or signals. Exemplarily, the communication interface can be a transceiver, circuit, bus, module, or other type of communication interface.
[0078] In one possible design, the communication device includes corresponding functional modules for implementing the steps in the above method. The functions can be implemented by hardware or by hardware executing corresponding software implementations. The hardware or software includes one or more modules corresponding to the above functions.
[0079] In one possible design, the structure of the communication device includes a processing unit and a communication unit, which can perform the corresponding functions in the above method example. For details, please refer to the description of the method provided in the fourth aspect, which will not be repeated here.
[0080] In an eighth aspect, the present application further provides a communications device, which is a core network device or a chip in a core network device. The communications device has the function of implementing any of the methods provided in the second or fifth aspects. The communications device can be implemented in hardware or by hardware executing corresponding software. The hardware or software includes one or more units or modules corresponding to the above-mentioned functions.
[0081] In one possible design, the communication device includes: a processor configured to support the communication device in executing the corresponding functions of the core network device in the method shown above. The communication device may also include a memory, which may be coupled to the processor and stores the necessary program instructions and data for the communication device. Optionally, the communication device also includes an interface circuit, which is used to support communication between the communication device and a network device or other device, such as the transmission and reception of data or signals. Exemplarily, the communication interface may be a transceiver, circuit, bus, module, or other type of communication interface.
[0082] In one possible design, the communication device includes corresponding functional modules for implementing the steps in the above method. The functions can be implemented by hardware or by hardware executing corresponding software implementations. The hardware or software includes one or more modules corresponding to the above functions.
[0083] In one possible design, the structure of the communication device includes a processing unit and a communication unit, which can perform the corresponding functions in the above method examples. For details, please refer to the description of the method provided in the second aspect or the fifth aspect, which will not be repeated here.
[0084] In the ninth aspect, a communication device is provided, comprising a processor and an interface circuit, the interface circuit being used to receive signals from other communication devices outside the communication device and transmit them to the processor or to send signals from the processor to other communication devices outside the communication device, the processor being used to implement the methods in the aforementioned first aspect or third aspect and any possible design through logic circuits or execution code instructions.
[0085] In the tenth aspect, a communication device is provided, comprising a processor and an interface circuit, the interface circuit being used to receive signals from other communication devices outside the communication device and transmit them to the processor or to send signals from the processor to other communication devices outside the communication device, the processor being used to implement the methods in the aforementioned second aspect or fifth aspect and any possible design through logic circuits or execution code instructions.
[0086] In the eleventh aspect, a communication device is provided, comprising a processor and an interface circuit, the interface circuit being used to receive signals from other communication devices outside the communication device and transmit them to the processor or to send signals from the processor to other communication devices outside the communication device, the processor being used to implement the method in the aforementioned fourth aspect and any possible design through logic circuits or execution code instructions.
[0087] In the twelfth aspect, a computer-readable storage medium is provided, which stores a computer program or instruction. When the computer program or instruction is executed by a processor, it implements the method in any one of the aforementioned aspects 1 to 5 and any possible design.
[0088] In the thirteenth aspect, a computer program product storing instructions is provided, which, when executed by a processor, implements the method in any one of the first to fifth aspects and any possible design.
[0089] In a fourteenth aspect, a chip system is provided, comprising a processor and possibly a memory, for implementing the method of any of the first through fifth aspects and any possible designs. The chip system may be comprised of a chip alone or may include a chip and other discrete components.
[0090] In the fifteenth aspect, a communication system is provided, which includes the device described in the first aspect (such as a terminal device) and the device described in the second aspect (such as a core network device).
[0091] In the sixteenth aspect, a communication system is provided, the system including a terminal device, a network device and a core network device, wherein the core network device sends a first verification value to the network device. The network device sends the first verification value from the core network device to the terminal device. The terminal device generates a second verification value and authenticates the core network based on the first verification value from the core network device and the generated second verification value. In one possible design, the terminal device is also used to execute the method described in the first aspect or the third aspect; the network device is also used to execute the method described in the fourth aspect, and the core network device is also used to execute the method described in the second aspect or the fifth aspect. In the seventeenth aspect, a communication system is provided, the system including the device described in the third aspect (such as a terminal device), the device described in the fourth aspect (such as a network device) and the device described in the fifth aspect (such as a core network device).
[0092] The technical effects that can be achieved by the technical solutions of any of the above-mentioned aspects 6 to 16 can be described with reference to the technical effects that can be achieved by the technical solutions of the above-mentioned aspects 1 to 5, and the repetitions will not be repeated. BRIEF DESCRIPTION OF THE DRAWINGS
[0093] FIG1 is a schematic diagram of the architecture of a communication system according to an embodiment of the present application;
[0094] FIG2 is a schematic diagram of the architecture of another communication system according to an embodiment of the present application;
[0095] FIG3 is a schematic diagram of a 5G authentication process according to an embodiment of the present application;
[0096] FIG4 is a schematic diagram of a flow chart of an authentication method according to an embodiment of the present application;
[0097] FIG5 is a schematic diagram of a process flow of an authentication terminal device according to an embodiment of the present application;
[0098] FIG6 is a flow chart of an authentication method according to an embodiment of the present application;
[0099] FIG7 is a schematic diagram of a flow chart of an authentication method according to an embodiment of the present application;
[0100] FIG8 is a schematic structural diagram of a communication device according to an embodiment of the present application;
[0101] FIG9 is a schematic structural diagram of a communication device according to an embodiment of the present application. DETAILED DESCRIPTION
[0102] The embodiments of the present application provide an authentication method that can be used for authenticating Internet of Things (IoT) terminals, including ambient IoT (A-IoT), narrowband internet of things (NB-IoT), etc. IoT technology is widely used in various industries. For example, IoT technology can be applied to logistics, warehousing, industrial manufacturing, identity recognition, or environmental monitoring, agriculture, animal husbandry, and forestry. For example, logistics management is a typical application that implements logistics management by taking inventory of tags on objects. Taking inventory of tags means that a reader performs an inventory operation on some tags within the coverage area to obtain the identification of the tags within the coverage area of the reader.
[0103] The IoT is based on radio frequency identification (RFID) technology. RFID is a contactless communication technology that uses radio frequency communication. Its principle is that data communication between a reader and a tag is achieved through radio waves, without contact.
[0104] The technical solutions provided in the embodiments of the present application can be applied to IoT systems, such as A-IoT systems; they can also be applied to communication systems related to the 3rd Generation Partnership Project (3GPP), such as the Long Term Evolution (LTE) communication system, the 5th Generation (5G) mobile communication system, or they can also be applied to other next-generation mobile communication systems, such as the 6th Generation (6G) communication system, or other similar communication systems. Other similar communication systems may include wireless fidelity (Wi-Fi), vehicle to everything (V2X), and the like.
[0105] Please refer to Figure 1, which is a schematic diagram of a communication system provided in an embodiment of the present application. The communication system includes at least one terminal device and at least one network device. Figure 1 takes a communication system including one terminal device and one network device as an example. The network architecture shown in Figure 1 is only a schematic, and the number of terminal devices and / or network devices may be less or more. Optionally, the communication system of the present application may also include core network devices, such as access and mobility management function (AMF) network elements and application function (AF) network elements. It should be understood that the above-mentioned communication system may also include other core network devices, which are not limited here.
[0106] The communication system described in the embodiment of the present application is intended to more clearly illustrate the technical solutions of the embodiment of the present application and does not constitute a limitation on the communication systems to which the embodiment of the present application is applicable. Those skilled in the art will appreciate that, with the evolution of network architecture, the technical solutions provided in the embodiment of the present application are equally applicable to similar technical problems. When applying the technical solutions of the embodiment of the present application to other communication systems, the devices, components, modules, etc. in the embodiment can be replaced with corresponding devices, components, modules in other communication systems without limitation.
[0107] Among them, any device that can communicate data with network devices can be considered a terminal device. Terminal devices are also called terminals, terminal devices, user equipment (UE), mobile stations, or mobile terminals. For example, terminal devices can be: mobile phones, computers, mobile internet devices (MIDs), wearable devices, virtual reality (VR) devices, augmented reality (AR) devices, robotic arms, cameras, robots, or smart home devices (such as TVs, air conditioners, vacuum cleaners, speakers, set-top boxes), relays, customer premise equipment (CPE), and devices with tag device functions. For example, terminal devices can be tags in IoT / A-IoT. Figure 1 takes the example of an A-IoT terminal as the terminal device.
[0108] Tags can be called RFID tags, electronic tags, or A-IoT terminals or devices. They are typically attached to objects to identify them. Tags receive radio frequency signals from a reader and, using the energy gained from the induced current, transmit information stored in the tag's internal chip. Alternatively, tags can actively transmit signals of a certain frequency to the reader, which then reads the information. Tags have a relatively simple design, integrating application layer signaling with air interface signaling, resulting in low power consumption. Tags are categorized as active, passive, and semi-active / semi-passive. Active tags are also called active tags, passive tags are also called passive tags, and semi-active / semi-passive tags are also called semi-passive tags. Active tags are equipped with a power supply and utilize an actively generated carrier wave communication method. This means they can actively transmit signals to the reader without needing to rely on received signals for signal transmission energy. Passive tags / passive tags are not equipped with modules such as power supply, or the power supply module has low power. They can adopt a communication method based on reflection (backscatter), which can obtain energy from the environment and send signals through the energy. Passive tags can work in reflection communication scenarios. For example, passive tags obtain energy by reflecting signals from readers and writers to transmit data. Semi-active / semi-passive tags integrate the advantages of active tags and passive tags and can be used as a special marker. Usually, semi-active / semi-passive tags are in a dormant state and may not work or send signals to the outside world. Only when they enter the activation signal range of the low-frequency activator, the semi-active / semi-passive tag is activated and starts working. The tags involved in the embodiments of the present application may be active tags, passive tags or semi-active / semi-passive tags, etc.
[0109] In the embodiments of the present application, a tag can be considered as a terminal device. Accordingly, the terminal devices in the present application can be of the following three types: passive terminal: a device without energy storage and independent signal generation, such as a backscatter transmission device with such characteristics, such as device A; semi-passive terminal: a device with energy storage but no independent signal generation, such as a backscatter transmission device with such characteristics, such as device B, where the use of stored energy may include amplification of reflected signals; active terminal: a device with energy storage and independent signal generation, such as an active wireless radio frequency (RF) component for transmission, such as device C.
[0110] Both the tag device and the reader / writer can be implemented based on the infrastructure of the cellular network, or the tag device and the reader / writer can be devices within the cellular network. For example, the reader / writer functionality can be implemented by a network device or a terminal device, while the tag device can be implemented by a terminal device within the cellular network. For example, the tag device can be an extremely low-power, low-complexity IoT terminal. When a terminal device has the functionality of a tag device, it can perform contactless data communication with the network device or another terminal device.
[0111] The various terminal devices introduced above, if located on a vehicle (e.g., placed / installed in a vehicle), can be considered as on-board terminal devices. On-board terminal devices can be on-board modules, on-board modules, on-board components, on-board chips, or on-board units built into a vehicle as one or more components or units. On-board terminal devices can also be complete vehicle equipment, on-board modules, vehicles, on-board units (OBU), roadside units (RSU), telematics boxes (T-boxes), chips, or system-on-chips (SOCs), etc. The above chips or SOCs can be installed in vehicles, OBUs, RSUs, or T-boxes.
[0112] In the embodiments of the present application, the device for implementing the functions of the terminal device can be the terminal device itself, or it can be a device that can support the terminal device to implement the functions, such as a chip system or a combination of devices or components that can implement the functions of the terminal device, and the device can be installed in the terminal device. The embodiments of the present application do not limit the specific technology and specific device form used by the terminal device. For example, in the embodiments of the present application, the terminal device can be in the form of a tag or other terminal form.
[0113] The network devices involved in the embodiments of the present application are mainly access network devices. Therefore, in the following text, unless otherwise specified, the "network devices" referred to are radio access network (RAN) devices, which can be referred to as access network devices for short. The RAN may be a 3GPP-related cellular system, such as an LTE system, a new radio (NR) system, or a future-oriented evolution system (such as a 6G mobile communication system). The RAN may also be an open access network (O-RAN or ORAN), a cloud radio access network (CRAN), or a virtualized RAN (vRAN). The RAN may also be a communication system that integrates two or more of the above systems. A RAN device may also be referred to as a RAN node, a RAN entity, or an access node. For example, a RAN node may be a base station, an evolved NodeB (eNodeB), an access point (AP), a transmission reception point (TRP), a next-generation NodeB (gNB), a next-generation base station in a 6G mobile communication system, or a base station in a future mobile communication system. A RAN node may be a RAN node in V2X technology, an RSU, an access node in a Wi-Fi system, or the like.
[0114] A RAN node may also be a module or unit that performs some of the functions of a base station; or multiple RAN nodes collaborate to assist terminal devices in achieving wireless access, with different RAN nodes respectively performing some of the functions of a base station. For example, a RAN node may be a centralized unit (CU), a distributed unit (DU), or a radio unit (RU). In different systems, CU, DU, or RU may have different names, but those skilled in the art will understand their meanings. For example, in an ORAN system, CU may also be called O-CU (Open CU), DU may also be called O-DU, CU-CP may also be called O-CU-CP, CU-UP may also be called O-CU-UP, and RU may also be called O-RU. For ease of description, this application uses CU, CU-CP, CU-UP, DU, and RU as examples for description. CU and DU may be configured according to the protocol layer functions of the wireless network they implement, and the embodiments of this application do not limit which protocol layers the CU and DU are configured with. Any of the CU, DU, and RU in this application may be implemented by a software module, a hardware module, or a combination of a software module and a hardware module.
[0115] In an embodiment of the present application, the network device may have a built-in reader / writer. When the terminal device is a tag, the tag and the network device can communicate through the Uu port, as shown in Figure 1. The functions of the reader / writer can be further separated, and the reader / writer is divided into a receiver (receiver) and an exciter (helper). The receiver is also called a receiving end or a receiving unit, and the exciter is also called an excitation end or an excitation unit. The excitation unit is equivalent to the transmitter in the reader / writer, and the receiving unit is equivalent to the receiver in the reader / writer. When the reader / writer is implemented in a separated architecture, different entities of the reader / writer can be deployed on different network devices, as shown in Figure 2. In Figure 2, the exciter is deployed on the first network device to perform the sending function of the reader / writer; the receiver is deployed on the second network device to perform the receiving function of the reader / writer.
[0116] In the embodiments of the present application, the device for implementing the functions of the network device can be the network device itself, or a device that can support the network device to implement the functions, such as a chip system or a combination of devices or components that can implement the functions of the network device, which can be installed in the network device. The embodiments of the present application do not limit the specific technology and specific device form used by the network device.
[0117] In the embodiments of the present application, "at least one" refers to one or more, and "more" refers to two or more. "And / or" describes the association relationship of associated objects, indicating that three relationships may exist. For example, A and / or B can represent: the existence of A alone, the existence of A and B at the same time, and the existence of B alone, where A and B can be singular or plural. The character " / " generally indicates that the previous and next associated objects are in an "or" relationship. "At least one of the following items" or similar expressions refers to any combination of these items, including any combination of single items or plural items. For example, at least one of a, b, or c can represent: a, b, c, a and b, a and c, b and c, or a and b and c, where a, b, c can be single or multiple.
[0118] Furthermore, unless otherwise indicated, ordinal numbers such as "first" and "second" in the embodiments of this application are used to distinguish between multiple objects and are not used to limit the size, content, order, timing, priority, or importance of the multiple objects. For example, the first information and the second information are only used to distinguish different information and do not indicate a difference in priority or importance between the two pieces of information.
[0119] It should be noted that, in this application, words such as "exemplary" or "for example" are used to indicate examples, illustrations, or descriptions. Any embodiment or design described in this application as "exemplary" or "for example" should not be construed as being preferred or advantageous over other embodiments or designs. Rather, the use of words such as "exemplary" or "for example" is intended to present the relevant concepts in a concrete manner.
[0120] The terms "including," "having," and any variations thereof mentioned in the following description of the embodiments of the present application are intended to cover non-exclusive inclusions. For example, a process, method, system, product, or apparatus comprising a series of steps or units is not limited to the listed steps or units, but may optionally include other steps or units not listed, or may optionally include other steps or units inherent to the process, method, product, or apparatus.
[0121] To ensure the security of the communication network, authentication is required after the terminal device accesses the network. As shown in Figure 3, the authentication process for 5G communication is as follows:
[0122] S301, UE sends a registration request (Registration Request) to the AMF network element.
[0123] The registration request may carry the UE's 5G globally unique temporary UE identifier (5G-GUTI) or user hidden identifier (SUbscription Concealed Identifier, SUCI) (or 5G subscription permanent identifier (SUPI)).
[0124] S302, the AMF network element sends an authentication request to the authentication server function (AUSF) network element.
[0125] If the Registration Request carries a valid 5G-GUTI or SUPI, the Authentication Request carries the corresponding SUPI. If the Registration Request carries a SUCI, the Authentication Request carries the SUCI.
[0126] S303, the AUSF network element determines whether the AMF network element is authorized to use the service network.
[0127] If the AMF network element is authorized to use the service network, execute S304.
[0128] S304, the AUSF network element sends an authentication data request (Nudm_UEAuthentication_Get) to the unified data management (UDM) network element.
[0129] S305: The UDM network element selects an authentication method for the UE.
[0130] S306, the UDM network element sends a 5G authentication vector (5G HE AV) to the AUSF network element.
[0131] Among them, 5G HE AV includes a random number (RAND), an authentication token (AUTN), an expected UE authentication response parameter (Expected user RESponse*, XRES*) and an AUSF key (KAUSF).
[0132] S307, the AUSF network element sends the 5G serving environment authentication vector (5G SE AV) to the AMF network element.
[0133] Among them, 5G SE AV includes RAND, AUTN and HXRES*, among which HXRES* is calculated based on XRES*.
[0134] S308, the AMF network element sends an air interface message to the UE.
[0135] The air interface message carries RAND, AUTN, NAS key set identifier (ngKSI), and ABBA. The anti-bidding down between architectures parameter (ABBA) is used to prevent network degradation attacks.
[0136] S309, the UE calculates a response parameter (RES*).
[0137] S310, the UE sends an authentication response (Authentication Response) to the AMF network element.
[0138] The authentication response carries RES*.
[0139] S311, the AMF network element calculates HRES* based on RES*.
[0140] S312, the AMF network element compares the calculated HRES* with the HXRES* included in the 5G SE AV.
[0141] If HRES* and HXRES* are consistent, the terminal device authentication is successful. If HRES* and HXRES* are inconsistent, the terminal device authentication fails.
[0142] Due to the low cost and design complexity of IoT devices, their coverage is limited and their application scenarios are limited. The aforementioned authentication process for terminal devices is complex and unsuitable for IoT devices. Authentication for low-cost, low-power IoT devices has become a pressing issue.
[0143] Based on this, the present invention provides an authentication method and device. The method and device are based on the same concept. Since the method and device solve similar problems, the implementation of the device and method can refer to each other, and the repeated parts will not be repeated.
[0144] The authentication method provided in the embodiments of the present application is particularly suitable for the authentication of A-IoT terminal devices (such as tags), and of course it is also suitable for the authentication of other types of terminal devices.
[0145] The following describes the authentication method provided in the embodiments of the present application with reference to the accompanying drawings.
[0146] For ease of understanding, some terms in the embodiments of the present application are explained to facilitate understanding by those skilled in the art.
[0147] 1) Slotted Aloha: Slotted Aloha divides the time domain into discrete time slots, each equal to or longer than a frame. Tags can only transmit data at the beginning of a slot. The slots used for data transmission are controlled by the reader. Only when the reader allocates all slots can the tag use them for data transmission.
[0148] In the embodiment of the present application, the paging message may be a paging message or a Select signaling. It is understandable that the Select signaling is used for paging tags. Accordingly, if terminal device A is paged, when the paging message is a paging message, the identifier of terminal device A included in the paging message may be the identifier (ID) of terminal device A. When the paging message is a Select signaling, the paging message may include mask information, and the mask information is used to filter terminal device A. For example, the mask carried by the Select signaling is 4 bits of "0000", and the mask of terminal device A is "00001111". Since the first 4 bits of "00001111" are the mask carried by the Select signaling, terminal device A meets the selection range of the Select signaling, and terminal device A can respond to the Select signaling. Of course, the Select signaling may also carry the identifier / group identifier of the terminal device; or, the Select signaling includes a filter, and the filter is used to filter the terminal devices to be paged. The filter can be a terminal device identifier or group identifier, used to page a specific terminal device or group of terminal devices. Alternatively, the filter can indicate the type of terminal device, i.e., used to page a class of terminal devices. It is understood that a filter is used to screen terminal devices and can also be referred to as filtering information. The specific name of the filter is not limited in this embodiment of the application.
[0149] In the embodiments of the present application, "authentication" can also be replaced by "authentication", "authentication authentication", etc.
[0150] The following is an example of the authentication method provided in the embodiment of the present application being performed by a core network device, a network device, and a terminal device. The steps performed by the network device can be implemented by the RAN device itself, or by a component in the RAN device (such as a baseband chip, or other processing units or processor modules). For example, the network device can be the network device in Figure 1, or it can also be a chip (system) in the network device in Figure 1. The steps performed by the terminal device can be implemented by the terminal device itself, or by a component in the terminal device (such as a chip, a processing unit, or a processor module). The terminal device can be the terminal device shown in Figure 1, or it can also be a chip (system) in the terminal device in Figure 1. The terminal device can be a UE or an A-IoT terminal device, for example, the terminal device can be a tag. The steps performed by the core network device can be implemented by the core network device itself, or by a component in the core network device (such as a chip, or other processing units or processor modules). The following is an example of the core network device being an AMF network element. It should be noted that the actions performed by the AMF network element can also be performed by other network elements, such as a network element for managing tags. The network element for managing tags may be referred to as a tag management function (TMF) network element, or may be referred to as another type of network element, which is not specifically limited herein. Referring to FIG4 , FIG4 shows a flow chart of an authentication method provided in an embodiment of the present application.
[0151] S401, the AMF network element sends a first verification value to the terminal device.
[0152] Correspondingly, the terminal device receives the first verification value from the AMF network element.
[0153] In one possible implementation, the AMF network element may send the first verification value through the network device. Specifically, the AMF network element sends the first verification value to the network device, and the network device transparently transmits the first verification value to the terminal device.
[0154] As an example, the first check value can be carried in a paging message or other broadcast message (or groupcast message or multicast message). For example, taking a paging message as an example, the AMF network element sends a second paging message to the network device, and the second paging message carries the first check value. The network device sends a first paging message to the terminal device, and the first paging message carries the first check value.
[0155] By sending a checksum in a multicast message such as a paging message, multiple terminal devices can be triggered to authenticate the core network at the same time. Compared with triggering the core network authentication through a unicast message, this method can reduce signaling overhead on the one hand, and on the other hand, it can enable multiple terminal devices to authenticate the core network in parallel, thereby quickly achieving multiple terminal devices authenticating the core network. Especially in the A-IoT scenario, multiple terminal devices can authenticate the core network in parallel, which can increase the inventory rate of terminal devices and thus improve the efficiency of A-IoT management. For example, in logistics management, the above method can enable multiple tags in the logistics to authenticate the core network in parallel, thereby reducing the inventory delay and improving the efficiency of logistics management.
[0156] As another example, the first verification value can be carried in an authentication acceptance message. For example, the AMF network element sends an authentication acceptance message to the network device, and the authentication acceptance message carries the first verification value. The authentication acceptance message is used to notify the terminal device that the authentication is successful. The network device forwards (or transparently transmits) the authentication acceptance message to the terminal device. Optionally, before S401, the AMF network element can authenticate the terminal device. The authentication process of the terminal device can refer to the method described in Figure 5 below, or the terminal device can be authenticated through other processes, which is not specifically limited here.
[0157] As another example, the first verification value can be carried in an authentication request message, which is used to request authentication of the core network. For example, the AMF network element sends an authentication request message to the terminal device through a network device, and the authentication request message carries the first verification value.
[0158] Optionally, before S401, the AMF network element may receive a service request from the AF network element. It should be noted that the operations performed by the AF network element in this application may also be performed by other network elements.
[0159] For example, the service request may include, but is not limited to, a service identifier (or event identifier), an identifier of at least one terminal device (or a group identifier or mask information of a terminal device group), and region information. The service identifier (or event identifier) is used to identify a service (or event or session). For example, the service request may include an inventory service identifier. The identifier of at least one terminal device (or a group identifier or mask information of a terminal device group) is used to identify the terminal device being paged. The region information indicates the region where the service is to be performed.
[0160] In one implementation, the AMF network element may generate the first verification value based on at least one of the following: a first key, a first random number, or a first sequence number, where the first key is a group key and the first random number is a generated random number.
[0161] Optionally, the AMF network element may further send relevant parameters for generating the first verification value, such as a first secret key, a first random number, or a first serial number, to the terminal device. For example, the AMF network element sends the relevant parameters for generating the first verification value to the network device, and the network device sends the relevant parameters for generating the first verification value to the terminal device through an air interface message such as a paging message.
[0162] S402: The terminal device generates a second verification value.
[0163] In one implementation, the terminal device may generate the second verification value based on at least one of the following: the first secret key, the first random number, a second random number generated by the terminal device, or a first serial number, where the first serial number is a serial number of the data packet transmission.
[0164] S403, the terminal device authenticates the core network according to the first verification value and the second verification value.
[0165] Specifically, if the first check value and the second check value meet the first condition, the core network authentication is successful. If the first check value and the second check value do not meet the first condition, the core network authentication fails. Exemplarily, the first condition may be that the first check value and the second check value are consistent, or the first condition may be that the first N high-order bits of the first check value and the second check value are consistent, or the first condition may be that the first M low-order bits of the first check value and the second check value are consistent, or the first condition may also be other matching conditions, which are not specifically limited here. N and M are both integers greater than 0.
[0166] Optionally, the above-mentioned process of authenticating the core network device can be performed before the terminal device randomly accesses or after the random access.
[0167] In one implementation, if the core network device authentication process is performed before the terminal device initiates random access, the terminal device may determine whether to send a random access request based on the core network authentication result. For example, if the core network authentication is successful, the terminal device may initiate random access, which may be a four-step random access or a two-step random access process, which is not specifically limited here.
[0168] Specifically, if it is a 4-step random access, the terminal device can send a preamble, and after receiving the random access response sent by the network device, send message 3 (Msg3), and wait to receive message 4 (Msg4) sent by the network device. The specific process can be referred to the relevant description of 3GPP protocol 38.321 or 36.321 protocol, which will not be explained here.
[0169] If it is a two-step random access, the terminal device can send a random access request message (such as message A (MsgA)), and then receive a response message (such as message B (MsgB)) sent by the network device. Specifically, the two-step random access can adopt the time slot aloha method. Other methods can also be used. Among them, the access opportunity used for random access can be an access opportunity of a fixed time unit in the time domain, or an access opportunity of variable length. In the case of a variable length opportunity, the access opportunity can be a timing triggered by a special signaling, that is, a time domain resource for terminal access is triggered only when the special signaling is received.
[0170] Alternatively, if the core network authentication is unsuccessful, the terminal device does not send a random access request.
[0171] In another implementation, if the process of authenticating the core network device is performed after the terminal device randomly accesses, the terminal device can notify the AMF network element of the result of the core network authentication. If the core network authentication fails, the terminal device notifies the AMF network element of the authentication failure, for example, by sending an authentication failure message to the AMF network element through the network device. If the core network authentication is successful, the terminal device can also notify the core network of the authentication success, for example, by sending an authentication acceptance message to the AMF network element through the network device. Optionally, the authentication acceptance message can be sent together with the identification information of the terminal device, or it can also be sent together with an authentication request message from the terminal device, wherein the authentication request message is used to request authentication of the terminal device. Alternatively, the terminal device can also implicitly indicate to the core network that the authentication has been successful by sending an authentication request message.
[0172] This application sends a check value to the terminal device through the AMF network element, allowing the terminal device to authenticate the core network, thereby preventing attacks from illegal networks or theft of user information by illegal networks. In addition, in this application, the generated check value is sent to the terminal device through the AMF network element. The terminal device compares the check value generated by itself with the check value sent by the core network device, thereby authenticating the core network. The process is simple and power consumption is low.
[0173] It should be noted that the method of authenticating the core network in this application can also be applied to scenarios where network devices are authenticated, such as authenticating network devices in scenarios without a core network. When the method described in Figure 4 is used to authenticate a network device, the network device can perform the actions of the AMF network element in Figure 4.
[0174] The above describes a method for authenticating the core network. Optionally, this application can also authenticate terminal devices. The following describes a method for authenticating terminal devices. It should be noted that the method for authenticating terminal devices (i.e., the method described in Figure 5) can be implemented independently of the method described in Figure 4 above, or it can be combined with the method described in Figure 4 to achieve two-way authentication.
[0175] As shown in FIG5 , the method for authenticating a terminal device includes:
[0176] S501: The terminal device generates a third verification value.
[0177] Exemplarily, the terminal device may generate a third verification value based on at least one of the following: a second key, a third random number, or a first serial number, wherein the second key is a group key or a root key, the third random number is a generated random number, and the first serial number is a serial number for data packet transmission. Optionally, the terminal device may store one or more group keys. If the terminal device stores multiple group keys, the AMF network element may instruct the terminal device which group key to use to generate the third verification value. For example, the AMF network element may send an index of the group key to the terminal device. Alternatively, the terminal device determines which group key to use to generate the third verification value. Alternatively, the terminal device may also generate a group key based on a root key or a derived key of the root key.
[0178] Of course, the terminal device may also determine the group key for generating the third verification value in other ways, which are not specifically limited here.
[0179] Optionally, the terminal device may also send relevant parameters for generating a third check value to the AMF network element, such as the terminal device identifier, the index of the group key, the third random number, the first serial number, etc. The terminal device identifier may be used to determine the root key or the derived key of the root key.
[0180] It should be noted that S501 is an optional step.
[0181] S502, the terminal device sends a third verification value to the AMF network element, and the third verification value is used to authenticate the terminal device.
[0182] In one possible implementation, the terminal device may send a third verification value to the AMF network element through the network device. Specifically, the terminal device sends the third verification value to the network device, and the network device transparently transmits the third verification value to the AMF network element.
[0183] As an example, the third check value can be carried in an authentication request message, a random access request, or a non-access stratum (NAS) message. For example, taking the authentication request message as an example, the terminal device sends an authentication request message to the AMF network element through the network device. The authentication request message carries the third check value, and the authentication request message is used to request authentication of the terminal device.
[0184] S503, the AMF network element generates a fourth verification value after receiving the third verification value.
[0185] Optionally, the AMF network element may generate a fourth verification value based on at least one of the following: the second key, the third random number, the fourth random number, or the first serial number. The fourth random number is a random number generated by the AMF network element.
[0186] S504, the AMF network element authenticates the terminal device based on the third verification value and the fourth verification value.
[0187] Specifically, if the third check value and the fourth check value meet the second condition, the terminal device is authenticated successfully. If the third check value and the fourth check value do not meet the second condition, the terminal device authentication fails. Exemplarily, the second condition may be that the third check value is consistent with the fourth check value, or the second condition may be that the first n high-order bits of the third check value and the fourth check value are consistent, or the second condition may be that the first m low-order bits of the first check value and the second check value are consistent, or the second condition may be other matching conditions, which are not specifically limited here. Both n and m are integers greater than 0.
[0188] Optionally, if the third verification value and the fourth verification value meet the second condition, the AMF network element can also send the third verification value and related parameters for generating the third verification value to the AUSF network element for further authentication.
[0189] In one possible implementation, if the terminal device is successfully authenticated, the AMF network element sends an authentication acceptance message to the terminal device via the network device. If the terminal device is unsuccessful in authentication, the AMF network element may send an authentication failure message to the terminal device via the network device.
[0190] In the 5G authentication process described in Figure 3, the authentication of the terminal device requires first sending the terminal device's identifier to the UDM network element, which determines the terminal device's authentication method. The UDM network element then generates the authentication vector 5G HE AV. The AUSF network element then further calculates the 5G SE AV based on the 5G HE AV and sends it to the AMF network element. At this point, the AMF network element obtains the authentication parameter HXRES* on the core network side. As for the authentication parameter on the terminal device side, the terminal device first generates the response parameter RES*, and then the AMF network element generates the authentication parameter HRES* on the terminal device side based on RES*. Finally, the AMF network element authenticates the terminal device by comparing the authentication parameter HXRES* on the core network side with the authentication parameter HRES* on the terminal device side. The method described in Figure 5 above only requires the terminal device to generate a verification value, and then the AMF network element can authenticate the terminal device by comparing the verification value generated by the terminal device with the reference value generated by itself. It can be seen that compared with the 5G authentication process, the process of the method described in Figure 5 above is simple in terminal device authentication process, has low power consumption, and is more suitable for A-IoT devices.
[0191] As described above, one-way authentication can be performed between the terminal device and the core network. For example, one-way authentication of the core network can be performed in the method described in Figure 4, and another example is one-way authentication of the terminal device can be performed in the method described in Figure 5. Alternatively, two-way authentication can be performed between the terminal device and the core network. For example, the method described in Figure 4 and the method described in Figure 5 can be combined to achieve two-way authentication. In a specific implementation, the terminal device and the AMF network element can negotiate the authentication method.
[0192] For example, the AMF network element can indicate to the terminal device whether the authentication method is one-way authentication or two-way authentication. For example, the AMF network element sends first information to the terminal device through the network device, and the first information is used to indicate whether the authentication method is one-way authentication or two-way authentication. As an example, the first information can be carried in a paging message. For example, the AMF network element sends a paging message to the network device, and the paging message carries the first information. The network device sends the first information to the terminal device through the paging message.
[0193] In one implementation, the first information may be determined as follows: the terminal device sends identification information to the AMF network element through the network device. The AMF network element obtains the authentication capability of the terminal device based on the identification, and determines the first information based on the authentication capability of the terminal device.
[0194] For another example, the terminal device may also report the supported (or recommended or expected or specified) authentication method to the AMF network element. For example, the terminal device sends the second information to the AMF network element through the network device, and the second information is used to indicate that the supported authentication method or the specified authentication method is one-way authentication or two-way authentication. As an example, the terminal device may send the second information to the network device by carrying it in a message of the random access process (such as message 3 (Msg3) or a random access request message, etc.), or may send the second information to the network device by carrying it in a NAS message. The network device may send the second information to the AMF network element by carrying it in an authentication request message, and the authentication request message is used to request authentication of the terminal device. Furthermore, after receiving the second information, the AMF network element may reply to the terminal device with a response message through the network device, and the response message indicates the authentication method used.
[0195] It should be noted that if the authentication method negotiated by the terminal device and the core network device is one-way authentication, the one-way authentication can be to authenticate the terminal device or to authenticate the core network. The specific type of one-way authentication can be indicated in the above-mentioned first information or second information, or it can also be defined by the protocol.
[0196] To facilitate understanding of the solution, the authentication method described in this application is introduced below in conjunction with specific scenarios.
[0197] Example 1, as shown in Figure 6, the authentication method includes:
[0198] S601, the AF network element sends a service request to the AMF network element.
[0199] The service request can be found in the previous description and will not be repeated here.
[0200] It should be understood that S601 is an optional step.
[0201] S602, the AMF network element sends a second paging message to the network device.
[0202] The second paging message carries the first verification value. The method for generating the first verification value can refer to the relevant description of S401 and will not be repeated here.
[0203] The second paging message may also carry a service identifier (or event identifier), an identifier of at least one terminal device (or a group identifier or mask information of a terminal device group), and relevant parameters for generating a first verification value (such as a first secret key, a first random number, etc.).
[0204] The second paging message may also carry the first information. If the first information indicates one-way authentication, S603 to S604 are executed to authenticate the core network. If the first information indicates two-way authentication and the core network authentication is successful, S605 is executed after S604, and after S605, S606 to S608 are executed to authenticate the terminal device.
[0205] S603: The network device sends a first paging message to the terminal device.
[0206] The first paging message may carry a first check value.
[0207] The first paging message may also carry an identifier of at least one terminal device (or a group identifier or mask information of a terminal device group) and relevant parameters for generating a first check value (such as a first secret key, a first random number, etc.).
[0208] The first paging message may also carry first information.
[0209] S604: The terminal device authenticates the core network.
[0210] Specifically, the terminal device may generate a second verification value and authenticate the core network according to the first verification value and the second verification value. Detailed descriptions of S402 and S403 are available and will not be further elaborated here.
[0211] In one possible implementation, if the core network authentication is successful, the terminal device initiates random access. If the core network authentication is unsuccessful, the terminal device does not initiate random access.
[0212] Assuming that the first information indicates bidirectional authentication and the authentication on the core network is successful, S605 is executed after S604.
[0213] S605: The terminal device initiates random access.
[0214] The specific process can be found in the description of S403, which will not be repeated here.
[0215] S606: The terminal device sends an authentication request message to the core network device through the network device.
[0216] The authentication request message carries a third verification value. The method for generating the third verification value can refer to the relevant description of S501 and will not be repeated here.
[0217] The authentication request message may also carry relevant parameters for generating the third verification value (such as the identifier of the terminal device, the index of the group key, the third random number, the first serial number, etc.).
[0218] S607, the AMF network element authenticates the terminal device.
[0219] Specifically, the AMF network element may generate a fourth check value and authenticate the terminal device based on the third check value and the fourth check value. For details, please refer to the relevant description of S503 and S504, which will not be further described here.
[0220] Optionally, if the third verification value and the fourth verification value meet the second condition, the AMF network element can also send the third verification value and related parameters for generating the third verification value to the AUSF network element for further authentication.
[0221] In one possible implementation, if the terminal device is successfully authenticated, the AMF network element sends an authentication acceptance message to the terminal device via the network device. If the terminal device is unsuccessful in authentication, the AMF network element may send an authentication failure message to the terminal device via the network device.
[0222] As a possible implementation method, after the terminal device and the core network have successfully completed bidirectional authentication, the terminal device and the core network (or network device) perform data transmission.
[0223] Example 2, as shown in Figure 7, the authentication method includes:
[0224] S701, the AF network element sends a service request to the AMF network element.
[0225] The service request can be found in the previous description and will not be repeated here.
[0226] It should be understood that S601 is an optional step.
[0227] S702, the AMF network element sends a first paging message to the network device.
[0228] The first paging message may carry a service identifier (or an event identifier) and an identifier of at least one terminal device (or a group identifier or mask information of a terminal device group).
[0229] Optionally, the first paging message may further carry first information. If the first information indicates one-way authentication, then S705 to S707 are executed to authenticate the terminal device.
[0230] If the first information indicates bidirectional authentication and the terminal device is successfully authenticated, the first verification value is carried in the authentication acceptance message in S708, and S709 is continued to be executed to authenticate the core network.
[0231] S703: The network device sends a second paging message to the terminal device.
[0232] The second paging message may carry an identifier of at least one terminal device (or a group identifier or mask information of a terminal device group).
[0233] Optionally, the second paging message may also carry the first information.
[0234] S704: The terminal device initiates random access.
[0235] The second information may be carried in the message of the random access process. For example, the second information may be carried in message 3 (Msg3) or the random access request. If the second information indicates one-way authentication, S705 to S707 are executed to authenticate the terminal device.
[0236] If the second information indicates bidirectional authentication or the second paging message indicates bidirectional authentication, and the terminal device is successfully authenticated, the first verification value is carried in the authentication acceptance message in S708, and S709 is continued to be executed to authenticate the core network.
[0237] It should be noted that S702 to S703 and S704 are optional steps.
[0238] In one implementation, the terminal device and the core network may negotiate an authentication method through S702 to S703. Optionally, in this method, S704 may or may not be performed. If S704 is performed, the random access process message may not carry the second information.
[0239] In another implementation, the terminal device and the core network may negotiate an authentication method through S704. In this implementation, the network device may carry the second information in a subsequent authentication request message (such as the authentication request message in S706), thereby sending the second information to the AMF network element. Optionally, in this method, S702 to S703 may or may not be executed. If S702 to S703 are executed, the third and fourth paging messages may not carry the first information.
[0240] S705 to S706 can refer to the above-mentioned S606 to S607, and will not be repeated here.
[0241] If the terminal device is successfully authenticated, the AMF network element sends an authentication acceptance message to the terminal device through the network device.
[0242] If the authentication of the terminal device fails, the AMF network element can send an authentication failure message to the terminal device through the network device.
[0243] Assume that the authentication mode indicated by the first information or the second information is bidirectional authentication, and the terminal device is successfully authenticated. Continue to execute S708.
[0244] S707, the AMF network element sends an authentication acceptance message to the terminal device through the network device.
[0245] The authentication acceptance message may carry a first verification value.
[0246] S708: The terminal device authenticates the core network.
[0247] Specifically, the terminal device may generate a second verification value and authenticate the core network according to the first verification value and the second verification value. Detailed descriptions of S402 and S403 are available and will not be further elaborated here.
[0248] Optionally, if the core network authentication is successful, the terminal device sends an authentication acceptance message to the AMF network element through the network device.
[0249] If the core network authentication is unsuccessful, the terminal device sends an authentication failure message to the AMF network element through the network device.
[0250] As a possible implementation, after the terminal device and the core network have successfully completed bidirectional authentication, the terminal device and the core network (or network device) perform data transmission.
[0251] This application sends a check value to the terminal device through the AMF network element, allowing the terminal device to authenticate the core network, thereby preventing attacks from illegal networks or theft of user information by illegal networks. In addition, in this application, the generated check value is sent to the terminal device through the AMF network element. The terminal device compares the check value generated by itself with the check value sent by the core network device, thereby authenticating the core network. The process is simple and power consumption is low.
[0252] Compared with the 5G authentication process, the process of the method described in Figure 5 above only requires the terminal device to generate a verification value. Then the AMF network element can authenticate the terminal device by comparing the verification value generated by the terminal device with the reference value generated by itself. There is no need for UDM network elements and AUSF network elements to participate in the calculation of the core network verification value. The terminal device authentication process is simple, the power consumption is low, and it is more suitable for A-IoT devices.
[0253] Based on the same inventive concept as the method embodiment, an embodiment of the present application provides a communication device, the structure of which may be as shown in FIG8 , including a communication unit 801 and a processing unit 802 .
[0254] In one embodiment, a communication device can be specifically used to implement the method performed by the terminal device in the embodiment of Figure 4. The device can be the terminal device itself, or a chip, chipset, or portion of a chip in the terminal device that performs the functions of the related method. The communication unit 801 is configured to receive a first verification value from a core network device. The processing unit 802 is configured to generate a second verification value and authenticate the core network based on the first verification value and the second verification value.
[0255] Exemplarily, the first check value is carried in the first paging message.
[0256] Optionally, when generating the second verification value, the processing unit 802 is specifically used to: generate the second verification value according to at least one of the following: a first key, a first random number, or a second random number, or a first serial number, wherein the first key is a group key, the first random number is a random number indicated by the core network, the second random number is a generated random number, and the first serial number is the serial number of the data packet transmission.
[0257] Optionally, the communication unit 801 is further configured to receive at least one of the following: an index of a group key and a first random number.
[0258] Optionally, the communication unit 801 is further configured to: send a random access request if the core network authentication is successful; or not send a random access request if the core network authentication is unsuccessful.
[0259] Optionally, the communication unit 801 is further used to: send a third verification value, where the third verification value is used to authenticate the terminal device.
[0260] Exemplarily, the third verification value is carried in the authentication request message.
[0261] Optionally, the processing unit 802 is also used to: generate a third verification value based on at least one of the following: a second key, or a third random number, or a first serial number, wherein the second key is a group key or a root key, the third random number is a generated random number, and the first serial number is the serial number of the data packet transmission.
[0262] Optionally, the communication unit 801 is further used to send at least one of the following: a third random number, a first serial number, or an identifier of the terminal device.
[0263] Optionally, the communication unit 801 is further used to: receive first information, where the first information is used to indicate whether the authentication method is one-way authentication or two-way authentication.
[0264] Optionally, the communication unit 801 is further used to: send second information, where the second information is used to indicate that the supported authentication method or the specified authentication method is one-way authentication or two-way authentication.
[0265] Exemplarily, the above-mentioned terminal device is an environmental Internet of Things terminal device.
[0266] In one embodiment, a communication device can be specifically used to implement the method performed by the core network device in the embodiment of Figure 4. The device can be the core network device itself, or a chip, chipset, or a portion of a chip in the core network device that performs the functions of the related method. The processing unit 802 is configured to receive a service request via the communication unit 801; and to send a first verification value to the terminal device via the communication unit 801. The first verification value is used to authenticate the core network.
[0267] Exemplarily, the first check value is carried in the second paging message.
[0268] Optionally, the processing unit 802 is further used to: generate a first verification value according to at least one of the following: a first key, a first random number, wherein the first key is a group key, and the first random number is a generated random number.
[0269] Optionally, the communication unit 801 is further used to: send at least one of the following: a group key, a first random number.
[0270] Optionally, the communication unit 801 is further used to: receive a third verification value, which is used to authenticate the terminal device; the processing unit 802 is further used to generate a fourth verification value; and authenticate the terminal device based on the first verification value and the fourth verification value.
[0271] Exemplarily, the third verification value is carried in the authentication request message.
[0272] Optionally, when generating the fourth verification value, the processing unit 802 is specifically used to: generate the fourth verification value according to at least one of the following: a second key, or a third random number, or a fourth random number, or a first serial number, wherein the second key is a group key or a root key, the third random number is a random number indicated by the terminal device, the fourth random number is a generated random number, and the first serial number is a data packet number indicated by the terminal device.
[0273] Optionally, the communication unit 801 is further used to receive at least one of the following: a third random number, a first serial number, or an identifier of the terminal device.
[0274] Optionally, the communication unit 801 is further used to: send first information, where the first information is used to indicate whether the authentication method is one-way authentication or two-way authentication.
[0275] Optionally, the communication unit 801 is further used to: receive second information, where the second information is used to indicate that the authentication method supported by the terminal device or the specified authentication method is one-way authentication or two-way authentication.
[0276] Exemplarily, the above-mentioned terminal device is an environmental Internet of Things terminal device.
[0277] The division of modules in the embodiments of the present application is schematic and is only a logical function division. In actual implementation, there may be other division methods. In addition, the functional modules in the various embodiments of the present application can be integrated into a processor, or can exist physically separately, or two or more modules can be integrated into one module. The above-mentioned integrated modules can be implemented in the form of hardware or in the form of software functional modules. It is understood that the functions or implementations of the various modules in the embodiments of the present application can be further referred to the relevant description of the method embodiment.
[0278] In one possible embodiment, a communication device may be as shown in FIG9 . The device may be a communication device or a chip in a communication device, wherein the communication device may be a terminal device or a core network device in the above embodiments. The device includes a processor 901 and a communication interface 902, and may also include a memory 903. The processing unit 802 may be the processor 901. The communication unit 801 may be the communication interface 902. Optionally, the processor 901 and the memory 903 may be integrated.
[0279] The processor 901 may be a CPU, a digital processing unit, or the like. The communication interface 902 may be a transceiver, an interface circuit such as a transceiver circuit, or a transceiver chip, or the like. The apparatus further includes a memory 903 for storing programs executed by the processor 901. The memory 903 may be a non-volatile memory, such as a hard disk drive (HDD) or a solid-state drive (SSD), or a volatile memory (volatile memory), such as a random-access memory (RAM). The memory 903 is any other medium that can be used to carry or store desired program code in the form of instructions or data structures and can be accessed by a computer, but is not limited thereto.
[0280] The processor 901 is used to execute the program code stored in the memory 903, specifically to execute the actions of the processing unit 802, which will not be described in detail in this application. The communication interface 902 is specifically used to execute the actions of the communication unit 801, which will not be described in detail in this application.
[0281] The specific connection medium between the communication interface 902, processor 901, and memory 903 is not limited in the embodiments of the present application. In Figure 9, the embodiment of the present application shows that the memory 903, processor 901, and communication interface 902 are connected via bus 904. The bus is represented by a bold line in Figure 9. The connection method between other components is only for schematic illustration and is not limiting. Buses can be divided into address buses, data buses, control buses, etc. For ease of representation, only one bold line is used in Figure 9, but this does not mean that there is only one bus or one type of bus.
[0282] An embodiment of the present application also provides a computer-readable storage medium for storing computer software instructions required to execute the above-mentioned processor, which includes a program required to execute the above-mentioned processor.
[0283] The present application also provides a communication system including a communication device for implementing the terminal device function in the embodiment of Figure 4 and a communication device for implementing the core network device function in the embodiment of Figure 4. The system may also include a communication device for implementing the network device function in the embodiment of Figure 4.
[0284] Those skilled in the art will appreciate that the embodiments of the present application can be provided as methods, systems, or computer program products. Therefore, the present application can adopt the form of a complete hardware embodiment, a complete software embodiment, or an embodiment in combination with software and hardware. Moreover, the present application can adopt the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to magnetic disk storage, CD-ROM, optical storage, etc.) that contain computer-usable program code.
[0285] The present application is described with reference to the flowcharts and / or block diagrams of the methods, devices (systems), and computer program products according to the present application. It should be understood that each flow and / or box in the flow chart and / or block diagram, as well as the combination of the flow chart and / or box in the flow chart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device produce a device for implementing the functions specified in one or more flow charts and / or one or more boxes in the block diagram.
[0286] These computer program instructions may also be stored in a computer-readable memory that can direct a computer or other programmable data processing device to operate in a specific manner, so that the instructions stored in the computer-readable memory produce a product including an instruction device that implements the functions specified in one or more processes in the flowchart and / or one or more boxes in the block diagram.
[0287] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operating steps are executed on the computer or other programmable device to produce a computer-implemented process, so that the instructions executed on the computer or other programmable device provide steps for implementing the functions specified in one or more processes in the flowchart and / or one or more boxes in the block diagram.
Claims
1. An authentication method, characterized in that: The method comprises: Receiving a first verification value from a core network device; generating a second check value; The core network is authenticated according to the first verification value and the second verification value.
2. The method according to claim 1, characterized in that The first check value is carried in the first paging message.
3. The method according to claim 1 or 2, characterized in that The generating of the second check value comprises: The second check value is generated according to at least one of the following: a first key, a first random number, a second random number, or a first serial number, wherein the first key is a group key, the first random number is a random number indicated by the core network, the second random number is a generated random number, and the first serial number is a serial number for data packet transmission.
4. The method according to claim 3, characterized in that The method further comprises: Receive at least one of the following: an index of the group key, and the first random number.
5. The method according to any one of claims 1 to 4, characterized in that: The method further comprises: If the core network authentication is successful, sending a random access request; Alternatively, if the core network authentication is unsuccessful, no random access request is sent.
6. The method according to any one of claims 1 to 5, characterized in that: The method further comprises: A third verification value is sent, where the third verification value is used to authenticate the terminal device.
7. The method according to claim 6, characterized in that The third verification value is carried in the authentication request message.
8. The method according to claim 6 or 7, characterized in that The method further comprises: The third verification value is generated according to at least one of the following: a second key, a third random number, or a first serial number, wherein the second key is a group key or a root key, the third random number is a generated random number, and the first serial number is a serial number of a data packet transmission.
9. The method according to claim 8, characterized in that The method further comprises: Send at least one of the following: the third random number, the first serial number, or an identifier of the terminal device.
10. The method according to any one of claims 1 to 9, characterized in that: The method further comprises: First information is received, where the first information is used to indicate whether the authentication method is one-way authentication or two-way authentication.
11. The method according to any one of claims 1 to 9, characterized in that: The method further comprises: Sending second information, where the second information is used to indicate that the supported authentication method or the specified authentication method is one-way authentication or two-way authentication.
12. The method according to any one of claims 1 to 11, characterized in that: The method is applied to environmental Internet of Things terminal equipment.
13. An authentication method, characterized in that: The method comprises: Receive service requests; A first verification value is sent to the terminal device, where the first verification value is used to authenticate the core network.
14. The method according to claim 13, characterized in that The first check value is carried in the second paging message.
15. The method according to claim 13 or 14, characterized in that The method further comprises: The first verification value is generated according to at least one of the following: a first secret key, a first random number, wherein the first secret key is a group secret key, and the first random number is a generated random number.
16. The method according to claim 15, characterized in that The method further comprises: Send at least one of the following: a group key and the first random number.
17. The method according to any one of claims 13 to 16, characterized in that: The method further comprises: receiving a third verification value, wherein the third verification value is used to authenticate the terminal device; generating a fourth check value; The terminal device is authenticated according to the first verification value and the fourth verification value.
18. The method according to claim 17, characterized in that The third verification value is carried in the authentication request message.
19. The method according to claim 17 or 18, characterized in that The generating of the fourth check value comprises: The fourth check value is generated according to at least one of the following: a second key, a third random number, a fourth random number, or a first serial number, wherein the second key is a group key or a root key, the third random number is a random number indicated by the terminal device, the fourth random number is a generated random number, and the first serial number is a data packet number indicated by the terminal device.
20. The method of claim 19, wherein: The method further comprises: Receive at least one of the following: the third random number, the first serial number, or an identifier of a terminal device.
21. The method according to any one of claims 13 to 20, characterized in that: The method further comprises: Sending first information, where the first information is used to indicate whether the authentication method is one-way authentication or two-way authentication.
22. The method according to any one of claims 13 to 20, characterized in that: The method further comprises: Receive second information, where the second information is used to indicate that the authentication method supported by the terminal device or the specified authentication method is one-way authentication or two-way authentication.
23. The method according to any one of claims 13 to 22, characterized in that The terminal device is an environmental Internet of Things terminal device.
24. A communication device, characterized in that: The method comprises a unit or module for executing the method according to any one of claims 1 to 12, or comprises a unit or module for executing the method according to any one of claims 13 to 23.
25. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores computer-readable instructions, and when the computer-readable instructions are executed on the communication device, the method according to any one of claims 1 to 12 is executed, or the method according to any one of claims 13 to 23 is executed.
26. A computer program product, characterized in that When the computer program product is executed on a device, the device is caused to execute the method according to any one of claims 1 to 23.
Citation Information
Patent Citations
Information interaction method and device
CN109756451A
Paging method and device
CN116074805A
Paging method and device
WO2023071979A1
Mobility management method for terminal, apparatus, and device
WO2023143168A1