Authentication method and system, and apparatus

By realizing three-party authentication between base stations, gateway devices and Internet of Things devices in the industrial 5G network scenario, and using specific parameters to determine the authentication value and compare it, the problem of non-trusted gateway counterfeit devices accessing the 5G service network is solved, and the security and credibility of data transmission are improved.

WO2025098120A9PCT designated stage expired Publication Date: 2025-06-26CHINA TELECOM NETWORK SECURITY TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
PCT/CN2024/125937
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2023-11-09
Filing Date
2024-10-18
Publication Date
2025-06-26

AI Technical Summary

Technical Problem

In the industrial 5G network scenario, how to prevent non-trusted and unauthorized industrial gateways from counterfeiting industrial IoT devices to access the 5G service network, and implement monitoring, tampering, forgery and other attacks to destroy the authentication process and subsequent data secure transmission.

Method used

By implementing mutual authentication between base stations, gateway devices and IoT devices, the authentication value is determined and compared to the parameters such as subscribed hidden identifiers, temporary public keys, serial numbers, random numbers and authentication values, to ensure the security and credibility of the transmission process.

Benefits of technology

It realizes mutual authentication between Internet of Things devices, gateway devices and base stations, ensures the security of industrial Internet of Things devices during the access process, and improves the credibility of cross-node communication.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2024125937_26062025_PF_FP_ABST
    Figure CN2024125937_26062025_PF_FP_ABST
Patent Text Reader

Abstract

Provided in the present application are an authentication method and system, and an apparatus, belonging to the technical field of 5G communications. The system comprises: a base station, which receives a first message from a gateway device and determines a third authentication value and a fourth authentication value on the basis of the first message, and if the third authentication value is equal to a second authentication value, then determines that the gateway device is successfully authenticated, and if the fourth authentication value is equal to a first authentication value, then determines that an Internet of Things device is successfully authenticated; the gateway device, which receives a second message from the base station and determines a seventh authentication value on the basis of the second message, and if the seventh authentication value is equal to a fifth authentication value, then determines that the base station and the Internet of Things device are successfully authenticated; and the Internet of Things device, which receives a third message from the gateway device and determines a ninth authentication value on the basis of the third message, and if the ninth authentication value is equal to an eighth authentication value, then determines that the base station and the gateway device are successfully authenticated, and ends authentication.
Need to check novelty before this filing date? Find Prior Art

Description

Authentication method, device and system

[0001] CROSS-REFERENCE TO RELATED APPLICATIONS

[0002] This application claims priority to the Chinese patent application filed with the State Intellectual Property Office of the People's Republic of China on November 9, 2023, with application number 202311489824.5 and application name "A Authentication Method, Device and System", the entire contents of which are incorporated by reference into this application. Technical Field

[0003] The embodiments of the present invention relate to the field of network security technology, and in particular to an authentication method, device, and system. Background Art

[0004] At present, the industrial 5G network can extend the application of 5G networks in industrial environments such as industrial manufacturing, ports and terminals, energy mines, etc., laying the communication foundation for IoT devices in industrial scenarios to obtain 5G services.

[0005] In industrial 5G network scenarios, IIoT devices accessing 5G network services must access the 5G network through a 5G industrial gateway. The 5G home network authenticates the device's identity and establishes session keys to ensure the reliability and transmission security of the 5G network services provided to IIoT devices over open wireless channels. However, during the access process, preventing untrusted, unauthorized, or even hijacked industrial gateways from impersonating IIoT devices to access the 5G service network and potentially conducting attacks such as eavesdropping, tampering, and forgery to disrupt the authentication process and subsequent secure data transmission remains a pressing issue.

[0006] Summary of the Invention

[0007] The embodiments of the present invention provide an authentication method, device and system for improving network security.

[0008] In a first aspect, an embodiment of the present invention provides an authentication system, comprising: a base station, receiving a first message from a gateway device, wherein the first message is used to request authentication of the network device and the Internet of Things device, and the first message includes: a first subscription anonymity identifier SUCI i , the second subscription anonymity identifier SUCI j , the first temporary public key pk i , the second temporary public key pk j , first sequence number dsqn i , second serial number dsqn j , the first random number dr i , the second random number dr j , the first authentication value ver i , the second authentication value verj , first timestamp, second timestamp; according to the second subscription anonymity identifier SUCI j , the second serial number dsqn j The second random number dr j , the first authentication value ver i , the first timestamp, the second timestamp determine a third authentication value; if the third authentication value is equal to the second authentication value ver j , it is determined that the gateway device authentication is successful; according to the first subscription anonymity identifier SUCI i 、The first serial number dsqn i , the first temporary public key pk i 、The first random number dr j , the first timestamp, the second timestamp determine a fourth authentication value; if the fourth authentication value is equal to the first authentication value ver i , it is determined that the IoT device is successfully authenticated, and a second message is sent to the gateway device;

[0009] The gateway device receives a second message from the base station, the second message is used to request authentication of the base station and the Internet of Things device, and the second message includes: a first globally unique temporary identifier dguti i , second globally unique temporary identifier dguti j , third sequence number rsqn i , the fourth sequence number rsqn j , the third temporary public key pk hn 、The third random number xr hn 、The fifth authentication value ver hn-i 、The sixth authentication value ver hn-j , a third timestamp; according to the first globally unique temporary identifier dguti i , the second globally unique temporary identifier dguti j , the third sequence number rsqn i , the third temporary public key pk hn , the third random number xr hn , the fifth authentication value ver hn-i , the third timestamp determines a seventh authentication value; if the seventh authentication value is equal to the fifth authentication value ver hn-i , it is determined that the authentication between the base station and the IoT device is successful, and a third message is sent to the IoT device;

[0010] The Internet of Things device receives a third message from the gateway device, the third message being used to request authentication of the gateway device and the base station, the third message including: the second subscription anonymity identifier SUCI j , the first globally unique temporary identifier dguti i , the third sequence number rsqn i , the third temporary public key pk hn , the eighth authentication value ver j-i , the third timestamp and the fourth timestamp; according to the first subscription anonymity identifier SUCI i , the second globally unique temporary identifier dguti j , the third temporary public key pk hn , the third sequence number rsqn i , the fifth authentication value ver hn-i 、The first random number dr i , the third timestamp and the fourth timestamp determine a ninth authentication value; if the ninth authentication value is equal to the eighth authentication value ver j-i , it is determined that the authentication of the base station and the gateway device is successful and the authentication is completed.

[0011] Through the above solution, mutual authentication between IoT devices, gateway devices and base stations is achieved, ensuring the security of industrial IoT devices during the access process and improving the reliability of cross-node communication.

[0012] In a possible implementation manner, according to the second subscription anonymity identifier SUCI j , the second serial number dsqn j The second random number dr j , the first authentication value ver i , the first timestamp, the second timestamp to determine a third authentication value, including: according to the second subscription anonymity identifier SUCI j Determine the first shared authentication key K j According to the second serial number dsqn j , the second subscription anonymity identifier SUCI j , the first shared authentication key K j , the first authentication value ver i , the second timestamp determines the fifth sequence number SQN′ j According to the second random number dr j , the fifth sequence number SQN′ j , the second subscription anonymity identifier SUCI j , the first shared authentication key Kj , the second timestamp determines the fourth random number rand′ j According to the second subscription anonymity identifier SUCI j , the fifth sequence number SQN′ j , the fourth random number rand′ j , the first authentication value ver i , the first timestamp and the second timestamp determine the third authentication value.

[0013] Through the above scheme, the base station obtains the first message sent by the gateway device, parses and calculates the corresponding authentication value based on the first message, and compares it with the authentication value of the gateway device. It can timely detect whether the data has been tampered with during the transmission process between the gateway device and the base station. If it has been tampered with, the authentication process is stopped, thereby improving the security and credibility of the data.

[0014] In a possible implementation, according to the first subscription anonymity identifier SUCI i 、The first serial number dsqn i , the first temporary public key pk i 、The first random number dr j , the first timestamp, and the second timestamp to determine a fourth authentication value, including: determining a fourth authentication value according to the first subscription anonymity identifier SUCI i , determine the second shared authentication key K i ; According to the first serial number dsqn i , the first subscription anonymous identifier SUCI i , the second shared authentication key K i , the first temporary public key pk i , the first timestamp determines the sixth sequence number SQN′ i According to the first random number dr i , the sixth sequence number SQN′ i , the first subscription anonymous identifier SUCI i , the second shared authentication key K i , the first timestamp determines the fifth random number rand′ i According to the first subscription anonymity identifier SUCI i , the first temporary public key pk i , the sixth sequence number SQN′ i , the fifth random number rand′ i , the first timestamp determines the fourth authentication value.

[0015] Through the above scheme, the base station obtains the first message sent by the gateway device, parses and calculates the corresponding authentication value based on the first message, and compares it with the authentication value of the IoT device. It can timely detect whether the data has been tampered with during the transmission process between the gateway device and the base station. If it has been tampered with, the authentication process is stopped, thereby improving the security and credibility of the data.

[0016] In a possible implementation manner, according to the first globally unique temporary identifier dguti i , the second globally unique temporary identifier dguti j , the third sequence number rsqn i , the third temporary public key pk hn , the third random number xr hn , the fifth authentication value ver hn-i , the third timestamp determines the seventh authentication value, including: according to the third random number xr hn With the second random number dr j Calculate the fourth random number rand′ j According to the second globally unique temporary identifier dguti j , determine the third globally unique temporary identifier GUTI′ j According to the fourth sequence number rsqn j Determine the seventh serial number According to the third globally unique temporary identifier GUTI′ j , the first globally unique temporary identifier dguti i , the third temporary public key pk hn , the third sequence number rsqn i , the seventh serial number The fifth authentication value ver hn-i , the first shared authentication key K j , the fifth random number rand′ i , the third timestamp determines the seventh authentication value.

[0017] Through the above solution, the gateway device obtains the second message sent by the base station, parses and calculates the corresponding authentication value based on the second message, and compares it with the authentication values ​​of the base station and the IoT device. It can timely detect whether the data has been tampered with during the transmission process of the base station. If it has been tampered with, the authentication process is stopped, thereby improving the security and credibility of the data.

[0018] In a possible implementation, according to the first subscription anonymity identifier SUCI i , the second globally unique temporary identifier dguti j , the third temporary public key pkhn , the third sequence number rsqn i , the fifth authentication value ver hn-i 、The first random number dr i , the third timestamp and the fourth timestamp to determine a ninth authentication value, comprising: according to the first subscription anonymity identifier SUCI i , the second subscription anonymity identifier SUCI j 、The sixth random number rand i , the third temporary public key pk hn , the first timestamp and the third timestamp, determine the first session key Key i-hn According to the third sequence number rsqn i Determine the eighth serial number According to the first globally unique temporary identifier dguti i , determine the fourth globally unique temporary identifier GUTI′ i According to the first subscription anonymity identifier SUCI i , the second subscription anonymity identifier SUCI j , the fourth globally unique temporary identifier GUTI′ i , the first temporary public key pk i 、The fifth serial number SQN i , the second shared authentication key K i , the sixth random number rand i and the third timestamp, determine the fifth authentication value ver hn-i According to the fifth authentication value ver hn-i , the first subscription anonymous identifier SUCI i , the first globally unique temporary identifier dguti i , the third temporary public key pk hn , the third sequence number rsqn i , the sixth random number rand i And the third timestamp and the fourth timestamp determine the ninth authentication value.

[0019] Through the above solution, the IoT device obtains the third message sent by the gateway device, parses and calculates the corresponding authentication value based on the third message, and compares it with the authentication values ​​of the base station and the gateway device. It can timely detect whether the data has been tampered with during the transmission process of the base station. If it has been tampered with, the authentication process is stopped, thereby improving the security and credibility of the data.

[0020] In a possible implementation, the authentication system includes: the base station obtains the first session serial number of the IoT device The base station obtains the second session sequence number of the gateway device Get the fifth sequence number SQN' j , calculate the fifth sequence number SQN′ j The second session sequence number Get the first difference of the sixth sequence number SQN' i , calculate the sixth sequence number SQN′ i The first session sequence number If the first difference is greater than the first threshold and the second difference is also greater than the first threshold, the base station terminates the authentication process; if the first difference and the second difference are both zero, the sixth sequence number SQN′ i and the fifth sequence number SQN′ i are all correct serial numbers, the base station does not need to send the third serial number rsqn to the IoT device and the gateway device i , the fourth sequence number rsqn j If the first difference is zero, and the second difference is not zero and is less than the first threshold, then the fifth sequence number SQN′ j For the correct serial number, the base station does not need to send the fourth serial number rsqn to the IoT device and the gateway device. j ; The sixth sequence number SQN′ i If the serial number is incorrect, the base station needs to send the fifth serial number rsqn to the IoT device and the gateway device. i If the first difference is not zero and is less than the first threshold, and the second difference is zero, then the fifth sequence number SQN′ j If the serial number is incorrect, the base station needs to send the fifth serial number rsqn to the IoT device and the gateway device. j ; The sixth sequence number SQN′ i If the fourth serial number is an incorrect serial number, the base station does not need to send the fourth serial number rsqn to the IoT device and the gateway device. i If both the first difference and the second difference are not zero and are less than the first threshold, then the fifth sequence number SQN′ j is an error sequence number, the sixth sequence number SQN′ i It is also an error sequence number. The base station needs to send the fifth sequence number rsqn to the IoT device and the gateway device. j and the fourth sequence number rsqn i .

[0021] Through the above solution, the problem of inconsistency between the session serial numbers of IoT devices and base stations can be solved. IoT devices and gateway devices can synchronize the correct session serial numbers with the base station at the same time. Moreover, the session serial numbers, as device privacy information, will not be leaked in open channels and stolen by other devices.

[0022] In one possible implementation, the system includes: when the base station receives the first message from the gateway device, calculating whether the difference between the first timestamp and the current time is greater than a second threshold, and if the difference is greater than the second threshold, stopping authentication; when the base station receives the first message from the gateway device, calculating whether the difference between the second timestamp and the current time is greater than the second threshold; if the difference is greater than the second threshold, stopping authentication; when the gateway device receives the second message from the base station, calculating whether the difference between the third timestamp and the current time is greater than the second threshold, and if the difference is greater than the second threshold, stopping authentication; when the Internet of Things device receives the third message from the gateway device, calculating whether the difference between the fourth timestamp and the current time is greater than the second threshold, and if the difference is greater than the second threshold, stopping authentication.

[0023] Through the above scheme, the timeliness, integrity, identity legitimacy and validity of the received authentication message are verified, which effectively avoids the problem of obtaining historical data or data from a time period that does not meet the requirements during the reception of the authentication response, and improves the reliability of the authentication results and the reliability of industrial network transmission.

[0024] In a second aspect, an embodiment of the present invention provides an authentication method, comprising: a base station receiving a first message from a gateway device, wherein the first message is used to request authentication of the gateway device and the Internet of Things device, and the first message includes: a first subscription anonymity identifier SUCI i , the second subscription anonymity identifier SUCI j , the first temporary public key pk i , the second temporary public key pk j , first sequence number dsqn i , second serial number dsqn j , the first random number dr i , the second random number dr j , the first authentication value ver i , the second authentication value ver j , first timestamp, second timestamp; according to the second subscription anonymity identifier SUCI j , the second serial number dsqn j The second random number dr j , the first authentication value ver i, the first timestamp, the second timestamp determine a third authentication value; if the third authentication value is equal to the second authentication value ver j , it is determined that the gateway device authentication is successful; according to the first subscription anonymity identifier SUCI i 、The first serial number dsqn i , the first temporary public key pk i 、The first random number dr j , the first timestamp, the second timestamp determine a fourth authentication value; if the fourth authentication value is equal to the first authentication value ver i , it is determined that the authentication of the Internet of Things device is successful, and a second message is sent to the gateway device; the gateway device receives the second message from the base station, the second message is used to request authentication of the base station and the Internet of Things device, and the second message includes: a first globally unique temporary identifier dguti i , second globally unique temporary identifier dguti j , third sequence number rsqn i , the fourth sequence number rsqn j , the third temporary public key pk hn 、The third random number xr hn 、The fifth authentication value ver hn-i 、The sixth authentication value ver hn-j , a third timestamp; according to the first globally unique temporary identifier dguti i , the second globally unique temporary identifier dguti j , the third sequence number rsqn i , the third temporary public key pk hn , the third random number xr hn , the fifth authentication value ver hn-i , the third timestamp determines a seventh authentication value; if the seventh authentication value is equal to the fifth authentication value ver hn-i , it is determined that the authentication between the base station and the Internet of Things device is successful, and a third message is sent to the Internet of Things device; the Internet of Things device receives the third message from the gateway device, the third message is used to request authentication of the gateway device and the base station, and the third message includes: the second subscription anonymity identifier SUCI j , the first globally unique temporary identifier dguti i , the third sequence number rsqn i , the third temporary public key pk hn , the eighth authentication value ver j-i , the third timestamp and the fourth timestamp; according to the first subscription anonymity identifier SUCI i, the second globally unique temporary identifier dguti j , the third temporary public key pk hn , the third sequence number rsqn i , the fifth authentication value ver hn-i 、The first random number dr i , the third timestamp and the fourth timestamp determine a ninth authentication value; if the ninth authentication value is equal to the eighth authentication value ver j-i , it is determined that the authentication of the base station and the gateway device is successful and the authentication is completed.

[0025] In a third aspect, an authentication method is provided, which can be executed by a base station and can also be used in a module in the base station. The method includes: receiving a first message from a gateway device, the first message being used to request authentication of the network device and the Internet of Things device, the first message including: a first subscription anonymity identifier (SUCI); i , the second subscription anonymity identifier SUCI j , the first temporary public key pk i , the second temporary public key pk j , first sequence number dsqn i , second serial number dsqn j , the first random number dr i , the second random number dr j , the first authentication value ver i , the second authentication value ver j , first timestamp, second timestamp; if the fourth authentication value is equal to the first authentication value ver i , it is determined that the Internet of Things device is successfully authenticated, and a second message is sent to the gateway device; according to the second subscription anonymity identifier SUCI j , the second serial number dsqn j The second random number dr j , the first authentication value ver i , the first timestamp, the second timestamp determine a third authentication value; if the third authentication value is equal to the second authentication value ver j , it is determined that the gateway device authentication is successful; according to the first subscription anonymity identifier SUCI i 、The first serial number dsqn i , the first temporary public key pk i 、The first random number dr j , the first timestamp, and the second timestamp determine a fourth authentication value.

[0026] In a fourth aspect, an authentication method is provided, which can be executed by a gateway device and can also be used in a module in the gateway device. The method includes: receiving a second message from the base station, the second message is used to request authentication of the base station and the IoT device, and the second message includes: a first globally unique temporary identifier dguti i , second globally unique temporary identifier dguti j , third sequence number rsqn i , the fourth sequence number rsqn j , the third temporary public key pk hn 、The third random number xr hn 、The fifth authentication value ver hn-i 、The sixth authentication value ver hn-j , a third timestamp; if the seventh authentication value is equal to the fifth authentication value ver hn-i , it is determined that the authentication between the base station and the Internet of Things device is successful, and a third message is sent to the Internet of Things device; according to the first globally unique temporary identifier dguti i , the second globally unique temporary identifier dguti j , the third sequence number rsqn i , the third temporary public key pk hn , the third random number xr hn , the fifth authentication value ver hn-i , the third timestamp determines a seventh authentication value; if the seventh authentication value is equal to the fifth authentication value ver hn-i , it is determined that the authentication of the base station and the IoT device is successful.

[0027] In a fifth aspect, an authentication method is provided, which can be executed by an IoT device and can also be used in a module in the IoT device. The method includes: receiving a third message from the gateway device, the third message being used to request authentication of the gateway device and the base station, the third message including: the second subscription anonymity identifier SUCI j , the first globally unique temporary identifier dguti i , the third sequence number rsqn i , the third temporary public key pk hn , the eighth authentication value ver j-i , the third timestamp and the fourth timestamp; according to the first subscription anonymity identifier SUCI i , the second globally unique temporary identifier dguti j , the third temporary public key pk hn , the third sequence number rsqn i , the fifth authentication value verhn-i 、The first random number dr i , the third timestamp and the fourth timestamp determine a ninth authentication value; if the ninth authentication value is equal to the eighth authentication value ver j-i , it is determined that the authentication of the base station and the gateway device is successful.

[0028] In a sixth aspect, a device is provided, comprising a processor and an interface circuit, wherein the processor is configured to communicate with other devices via the interface circuit and execute the method described in any one of the third to fifth aspects. The processor comprises one or more.

[0029] In a seventh aspect, a device is provided, comprising a processor coupled to a memory, the processor configured to execute a program stored in the memory to perform the method described in any one of aspects 3 to 5. The memory may be located within or outside the device, and the processor may be one or more.

[0030] In an eighth aspect, a device is provided, comprising a processor and a memory; the memory is used to store computer instructions, and when the device is running, the processor executes the computer instructions stored in the memory to enable the device to perform the method described in any one of the third to fifth aspects above.

[0031] In a ninth aspect, a chip system is provided, comprising: a processor or a circuit for executing the method described in any one of the third to fifth aspects above.

[0032] In a tenth aspect, a computer-readable storage medium is provided, wherein instructions are stored in the computer-readable storage medium, which, when executed on a communication device, enables the method described in any one of the third to fifth aspects to be executed.

[0033] In an eleventh aspect, a computer program product is provided, which includes a computer program or instructions. When the computer program or instructions are executed by a device, the method described in any one of the third to fifth aspects above is executed. BRIEF DESCRIPTION OF THE DRAWINGS

[0034] FIG1 is a structural diagram of an authentication method provided by an embodiment of the present invention;

[0035] FIG2 is a schematic diagram of a flow chart of an authentication method provided by an embodiment of the present invention;

[0036] FIG3 is a flow chart of an authentication method according to an embodiment of the present invention;

[0037] FIG4 is a schematic diagram of an authentication device according to an embodiment of the present invention;

[0038] FIG5 is a schematic diagram of an authentication device provided by an embodiment of the present invention. DETAILED DESCRIPTION

[0039] To make the objectives, technical solutions, and advantages of the present invention more apparent, the present invention will be further described in detail below with reference to the accompanying drawings. It is apparent that the embodiments described are only some of the embodiments of the present invention, rather than all of them. All other embodiments derived by persons of ordinary skill in the art based on the embodiments of the present invention without creative effort are intended to fall within the scope of protection of the present invention.

[0040] Figure 1 is a system architecture diagram of an embodiment of the present invention. As shown in Figure 1, the system provided by the embodiment of the present invention includes a base station 101, a gateway device 102 and an Internet of Things device 103. For example, the base station 101 is located in a home network (Home Network, HN), and the HN may also include devices such as servers. The gateway device 102 can represent a gateway (GW) device, which may include routers, switches and other devices. The Internet of Things device 103 can represent a device in the Industrial Internet of Things (IIoT), for example, it may include equipment in industrial manufacturing, equipment in energy extraction, etc. It should be noted that the above-mentioned device is only an example and is not limited to this embodiment of the present invention. By mutual authentication between the base station 101, the gateway device 102 and the Internet of Things device 103, the reliability and security of the Industrial Internet of Things accessing the 5G home network can be effectively improved, and at the same time, it can be verified whether it has been tampered with.

[0041] In one embodiment, the base station 101 can be used to issue a subscription permanent identifier (SUPI), a key (K), a public key (PK), and a globally unique temporary identifier (GUTI) to the IoT device and the gateway device; the gateway device 102 and the IoT device 103 can be used to generate a subscription concealed identifier (SUCI), obtain a sequence number (SQN), and generate a random number (rand); it should be noted that the above parameters are only an example and are not limited to this embodiment of the present invention.

[0042] In this application, a base station may also be referred to as an access network device, which may refer to a radio access network (RAN) node (or device) that connects a terminal device to a wireless network, such as a base station. Some examples of RAN nodes may include: a gNB, a transmission reception point (TRP), an evolved Node B (eNB), a radio network controller (RNC), a Node B (NB), a base station controller (BSC), a base transceiver station (BTS), a home base station (e.g., a home evolved NodeB, or a home Node B, HNB), a base band unit (BBU), or a wireless fidelity (Wifi) access point (AP).

[0043] In one network architecture, access network equipment may include centralized unit (CU) nodes, distributed unit (DU) nodes, or both CU and DU nodes. RAN equipment including CU and DU nodes splits the protocol layers of the gNB in ​​the NR system, centrally controlling some protocol layer functions within the CU and distributing some or all of the remaining protocol layer functions within the DU, which is then centrally controlled by the CU. Furthermore, the CU can be divided into a control plane (CU-CP) and a user plane (CU-UP). The CU-CP is responsible for control plane functions, primarily including radio resource control (RRC) and the control plane's corresponding packet data convergence protocol (PDCP) (i.e., PDCP-C). PDCP-C is primarily responsible for encryption, decryption, integrity protection, and data transmission of control plane data. The CU-UP is responsible for user plane functions, primarily including the service data adaptation protocol (SDAP) and the user plane's corresponding PDCP (i.e., PDCP-U). SDAP is primarily responsible for processing core network data and mapping flows to bearers. The PDCP-U is primarily responsible for data plane encryption and decryption, integrity protection, header compression, sequence number maintenance, and data transmission. The CU-CP and CU-UP are connected via the E1 interface. The CU-CP represents the gNB's connection to the core network via the NG interface and to the DU via the F1 interface control plane (i.e., F1-C). The CU-UP connects to the DU via the F1 interface user plane (i.e., F1-U). Alternatively, the PDCP-C may also reside in the CU-UP.

[0044] It is understandable that in different systems, CU (including CU-CP or CU-UP) or DU may have different names, but those skilled in the art can understand their meanings. For example, in an open radio access network (O-RAN) system, CU may also be referred to as O-CU (open CU), DU may also be referred to as O-DU, CU-CP may also be referred to as O-CU-CP, and CU-UP may also be referred to as O-CU-UP. For the convenience of description, this application uses CU, CU-CP, CU-UP and DU as examples for description.

[0045] The preferred embodiments of the present invention are described below in conjunction with the drawings. It should be understood that the preferred embodiments described herein are only used to illustrate and explain the present invention and are not used to limit the present invention. In addition, the embodiments of the present invention and the features in the embodiments may be combined with each other if there is no conflict.

[0046] Based on the user equipment structure diagram shown in FIG1 , FIG2 exemplarily shows a system schematic diagram provided by an embodiment of the present invention.

[0047] As shown in Figure 2, the system includes:

[0048] Base station 201 is used to generate system public parameters, distribute subscription permanent identifiers (SUPIs) and long-term authentication keys to gateway devices and IoT devices, and authenticate IoT devices and gateway devices. The steps for base station 201 to authenticate IoT devices and gateway devices are as follows:

[0049] Step 2011: Receive a first message from a gateway device.

[0050] For example, the first message includes at least one of the following: a first subscription anonymity identifier SUCI i , the second subscription anonymity identifier SUCI j , the first temporary public key pk i , the second temporary public key pk j , first sequence number dsqn i , second serial number dsqn j , the first random number dr i , the second random number dr j , the first authentication value ver i , the second authentication value ver j , first timestamp, second timestamp; wherein, the first message may represent a 5G relay authentication response.

[0051] Specifically, the base station passes the second random number dr j XOR with the corresponding hash function to obtain the fourth random number rand′ j ; The second serial number dsqn j With the second subscription anonymized identifier SUCI j , the first shared authentication key K j , first authentication value ver i , and the hash value of the second timestamp are XORed to determine the fifth sequence number SQN′ j ; The second random number dr j and the fifth serial number SQN′ j , second subscription anonymity identifier SUCI j , the first shared authentication key K j , and the hash function value of the second timestamp are XORed to obtain the fourth random number rand′ j ;

[0052] In one embodiment, the base station uses the first subscription anonymity identifier SUCIi , obtain SUPI′ i , and according to SUPI′ i Determine the second shared authentication key K i ; The first serial number dsqn i With the first subscription anonymous identifier SUCI i , the second shared authentication key K i , the first temporary public key pk i , XOR the hash value of the first timestamp to determine the sixth sequence number SQN′ i According to the first random number dr i , the sixth sequence number SQN′ i , the first subscription anonymous identifier SUCI i , the second shared authentication key K i , the first timestamp determines the fifth random number rand′ i .

[0053] Step 2012: Determine a third authentication value between the base station and the gateway device, and a fourth authentication value between the base station and the Internet of Things device based on the first message.

[0054] Specifically, by calculating the second subscription anonymity identifier SUCI j , fifth sequence number SQN′ j , the fourth random number rand′ j , first authentication value ver i , the first timestamp and the hash function value of the second timestamp to determine the third authentication value.

[0055] By calculating the first subscription anonymous identifier SUCI i , the first temporary public key pk i , sixth sequence number SQN′ i , the fifth random number rand′ i , the hash function value of the first timestamp determines the fourth authentication value.

[0056] In step 2013, the base station authenticates the gateway device and the IoT device; if the third authentication value is equal to the first authentication value in the first message, and the fourth authentication value is equal to the second authentication value in the first message, it is determined that the authentication of the gateway device and the IoT device is successful, and a second message is sent.

[0057] The second message is sent to the gateway device 202, and the second message may represent a 5G relay authentication response.

[0058] Through the above steps, the base station completes the verification of the legitimacy of the identities of the IoT device and the gateway device, and confirms the integrity and validity of the 5G relay authentication request.

[0059] The gateway device 202 is used to assist the IoT device in accessing the home network base station, send a first message to the base station, and authenticate the base station and the IoT device. The gateway device 202 authenticates the IoT device and the base station in the following steps:

[0060] Step 2021: Receive a second message from the base station.

[0061] For example, the second message includes at least one of the following: a first globally unique temporary identifier dguti i , second globally unique temporary identifier dguti j , third sequence number rsqn i , the fourth sequence number rsqn j , the third temporary public key pk hn 、The third random number xr hn 、The fifth authentication value ver hn-i 、The sixth authentication value ver hn-j , a third timestamp; wherein the second message may represent a 5G relay authentication response.

[0062] Specifically, the gateway device passes the second random number dr j and the third random number xr hn Perform XOR to obtain the fifth random number rand′ i According to the second globally unique temporary identifier dguti j and the corresponding hash function to determine the third globally unique temporary identifier GUTI′ j ; According to the fourth sequence number rsqn j And the corresponding hash function determines the seventh serial number

[0063] Step 2022: Determine a seventh authentication value between the gateway device, the base station, and the IoT device based on the second message.

[0064] Specifically, according to the third globally unique temporary identifier GUTI′ j , first globally unique temporary identifier dguti i , the third temporary public key pk hn , third sequence number rsqn i 、Seventh serial number The fifth authentication value ver hn-i , the first shared authentication key K j , the fifth random number rand′ i , the hash function value of the third timestamp determines the seventh authentication value.

[0065] In step 2023, the gateway device authenticates the base station and the IoT device; if the seventh authentication value is equal to the fifth authentication value in the second message, it is determined that the authentication of the base station and the IoT device is successful, and a third message is sent; wherein, the third message is sent to the IoT device 203, and the third message can represent a 5G relay authentication response.

[0066] Through the above steps, the gateway device completes the verification of the legitimacy of the identities of the IoT device and the base station, and confirms the integrity and validity of the 5G relay authentication request.

[0067] The IoT device 203 is used to connect to the base station and authenticate the base station and the gateway device. The IoT device 203 authenticates the gateway device and the base station in the following steps:

[0068] Step 2031: Receive a third message from the gateway device.

[0069] For example, the third message includes at least one of the following: a second subscription anonymity identifier SUCI j , first globally unique temporary identifier dguti i , third sequence number rsqn i , the third temporary public key pk hn 、The eighth authentication value ver j-i , a third timestamp and a fourth timestamp; wherein the third message may represent a 5G relay authentication response.

[0070] Specifically, according to the first subscription anonymity identifier SUCI i , second subscription anonymity identifier SUCI j 、The sixth random number rand i , the third temporary public key pk hn , the first timestamp and the third timestamp, determine the first session key Key i-hn ; According to the third sequence number rsqn i Determine the eighth serial number According to the first globally unique temporary identifier dguti i , determine the fourth globally unique temporary identifier GUTI′ i ;

[0071] According to the first subscription anonymity identifier SUCI i , second subscription anonymity identifier SUCI j , fourth globally unique temporary identifier GUTI′ i , the first temporary public key pk i 、The fifth serial number SQN i , the second shared authentication key K i 、The sixth random number rand iand the third timestamp, determine the fifth authentication value ver hn-i .

[0072] Step 2032: Determine an eighth authentication value of the IoT device, the base station, and the gateway device based on the third message.

[0073] Specifically, according to the fifth authentication value ver hn-i , first subscription anonymity identifier SUCI i , first globally unique temporary identifier dguti i , the third temporary public key pk hn , third sequence number rsqn i 、The sixth random number rand i The third timestamp and the fourth timestamp determine a ninth authentication value.

[0074] In step 2033, the IoT device authenticates the gateway device and the base station. If the eighth authentication value is equal to the sixth authentication value in the third message, it is determined that the authentication of the base station and the gateway device is successful.

[0075] Among them, the third message is sent to the Internet of Things device 203, and the third message can represent a 5G relay authentication response.

[0076] Through the above steps, the IoT device completes the verification of the legitimacy of the identity of the gateway device and the base station, confirms the integrity and validity of the 5G relay authentication request, and the base station, IoT device and gateway device authenticate each other in pairs.

[0077] In one embodiment, the base station also obtains the first session sequence number of each IoT device according to the SUPI. And the second session serial number of the gateway device Among them, the first session sequence number and the second session sequence number Represents the correct session sequence number of the IoT device and gateway device in the current session respectively;

[0078] The gateway device calculates the real fifth sequence number SQN′ j , the fifth sequence number SQN′ j and the second session sequence number Subtract; if the difference is 0, then the fifth serial number SQN' of the gateway device j is the correct session sequence number and does not need to be updated again; if the difference is not 0 and is less than the first threshold, the fifth sequence number SQN′ j It is not the correct sequence number, but it is still within the reasonable threshold range. Therefore, the gateway device obtains the correct sequence number from the base station and generates the fifth sequence number SQN′. jUpdate; if the difference is greater than the first threshold, the fifth sequence number SQN′ j If it is not within the reasonable threshold, the certification will be stopped.

[0079] IoT devices calculate the real sixth serial number SQN′ i , the sixth sequence number SQN′ i First session sequence number Subtract; if the difference is 0, then the sixth serial number SQN' of the gateway device i is the correct session sequence number and does not need to be updated again; if the difference is not 0 and is less than the first threshold, the sixth sequence number SQN′ i It is not the correct sequence number, but it is still within the reasonable threshold range. Therefore, the gateway device obtains the correct sequence number from the base station and generates the sixth sequence number SQN′. i Update; if the difference is greater than the first threshold, the sixth sequence number SQN′ i If it is not within the reasonable threshold, the certification will be stopped.

[0080] In this way, the base station not only verifies the accuracy of the serial numbers of the gateway device and the IoT device, but also avoids the duplication of retransmitting the data with the correct serial number while transmitting the correct serial number.

[0081] In one embodiment, when receiving the first message from the gateway device, the base station calculates whether the difference between the first timestamp and the current time is greater than a second threshold, and stops authentication if the difference is greater than the second threshold;

[0082] When receiving the first message from the gateway device, the base station calculates whether the difference between the second timestamp and the current time is greater than a second threshold; if the difference is greater than the second threshold, the authentication is stopped;

[0083] When receiving the second message from the base station, the gateway device calculates whether the difference between the third timestamp and the current time is greater than a second threshold, and stops authentication if the difference is greater than the second threshold;

[0084] When receiving the third message from the gateway device, the IoT device calculates whether the difference between the fourth timestamp and the current time is greater than a second threshold, and stops authentication if the difference is greater than the second threshold.

[0085] In one embodiment, authentication can be performed according to the process shown in Figure 3. The process shown in Figure 3 is a specific embodiment based on the system schematic diagram shown in Figure 2. It should be noted that the process is only an example and other methods can be used in the specific implementation process, which is not limited by the embodiment of the present invention. The specific implementation process shown in Figure 3 includes the following steps:

[0086] Step 301: The base station initializes and generates system public parameters.

[0087] The base station selects a secure one-way hash function (Hash function, h), a key derivation function (Key Derivation Function, KDF), a finite field F P The non-singular elliptic curve E defined on p (ab):y 2 =x 3 +ax+b and base point P, where a,b∈F P , 4a 3 +27b 2 modp≠0, P∈E p (a, b); The scalar multiplication formula of the elliptic curve E is defined as n·P=P+P+P++P(n times, n∈F p ); The base station randomly selects the master private key S hn ∈F p , calculate the master public key PK hn =S hn ·P.

[0088] In step 302, the IoT device and the gateway device are registered on the base station respectively.

[0089] In one embodiment, the base station first allocates a SUPI to the IoT device. i Then select a long-term authentication key K shared by the base station and the IoT device i ; Finally, the base station stores {SUPI i ,K i}, IoT device storage {SUPI i ,K i ,E p (a,b),P,PK hn ,h(·),KDF(·)};

[0090] In one embodiment, the base station allocates a subscription permanent identifier SUPI to the gateway device. j Then select a long-term authentication key K shared by the base station and the gateway device j ; Finally, the base station stores {SUPI j ,K j}, Gateway device storage {SUPI j ,K j ,E p (a,b),P,PK hn ,h(·),KDF(·)}.

[0091] Step 303: The IoT device sends an access authentication request message {SUCIi , pk i ,dsqn i ,drand i ,ver i , t1}.

[0092] In one embodiment, the IoT device selects a session key negotiation private key s i ∈F p and the random number rand i , calculate the temporary public key pk i =s i ·P; IoT devices to SUPI i Obtained using the E encryption algorithm Use hash function and XOR algorithm to i XOR to obtain dsqn i , use hash function and XOR algorithm to i XOR to get drand i , calculate ver i =h(SUCI i ,pk i ,SQN i ,rand i ,t1), and {SUCI i , pk i ,dsqn i ,drand i ,ver i , t1} is sent to the gateway device.

[0093] Step 304: The gateway device sends a relay authentication request message {SUCI i , SUCI j , pk i , pk j ,dsqn i ,dsqn j ,drand i ,drand j ,ver i ,ver j , t1, t2}.

[0094] In one embodiment, the gateway device receives access authentication request information from the IoT device and verifies the freshness of t1; the gateway device selects a temporary private key s j ∈F p and the random number rand j , calculate the temporary public key pk j =s j ·P; Gateway device to SUPI jObtained using the E encryption algorithm Use hash function and XOR algorithm to j XOR to obtain dsqn j , use hash function and XOR algorithm to j XOR to get drand j , calculate ver i =h(SUCI i ,pk i ,SQN i ,rand i ,t1), and relay the authentication request {SUCI i , SUCI j , pk i ,pk j ,dsqn i ,dsqn j ,drand i ,drand j ,ver i ,ver j , t1, t2} is sent to the gateway device.

[0095] Step 305: The base station receives the relay authentication request information sent by the gateway device and authenticates the reliability of the gateway device.

[0096] In one embodiment, the base station receives the access authentication request information from the gateway device and verifies the freshness of t1 and t2; j Use D decryption algorithm to obtain Then according to SUPI j 'Get the shared authentication key K with the gateway device j and the current session sequence number Next, the base station uses the hash function and XOR algorithm to dsqn j XOR to obtain Use hash function and XOR algorithm to drand j XOR to obtain Verify the equation j =h(SUCI j ,SQN j ,rand j ,ver i ,t1,t2) is established. If the equation is established, the base station confirms that the gateway device is a trusted system authorized node, and the relay authentication request {SUCI j ,pk j ,dsqn j ,drand j ,ver i ,verj ,t1,t2} are complete and not tampered with, otherwise the base station rejects the relay authentication request and terminates the authentication process.

[0097] Step 306: The base station receives the relay authentication request information sent by the gateway device and authenticates the reliability of the IoT device.

[0098] In one embodiment, the base station sends a SUCI i Use D decryption algorithm to obtain Then according to SUPI′ i Obtain the shared authentication key K with the IoT device i and the current session sequence number Next, the base station uses the hash function and XOR algorithm to dsqn i XOR to obtain Use hash function and XOR algorithm to drand i XOR to obtain Verify the equation i =h(SUCI i ,pk i ,SQN i ,rand i ,t1) is established. If the equation is established, the base station confirms that the IoT device is a trusted system authorized node, and the relay authentication request {SUCI i ,pk i ,dsqn i ,drand i} is complete and not tampered with, otherwise the base station rejects the relay authentication request and terminates the authentication process;

[0099] In one embodiment, the base station obtains the current session sequence number The current session sequence number and calculate and SQN i '、 and SQN j ’ to determine whether the session sequence number is within the valid sequence number error threshold; SQN′ j and Subtract; if the difference is 0, then SQN′ j is the correct session sequence number and does not need to be updated again; if the difference is not 0 and is less than the first threshold, then SQN′ j It is not the correct serial number, but it is still within the valid threshold range, so the base station sends the SQN′ to the gateway device. j Update; if the difference is greater than the first threshold, then SQN′ j If the value is not within a reasonable threshold, the base station stops authenticating the gateway device.

[0100] In one embodiment, the IoT device calculates the real SQN′ i , SQN′ i and Subtract; if the difference is 0, then the SQN′ of the gateway device i is the correct session sequence number and does not need to be updated again; if the difference is not 0 and is less than the first threshold, then SQN′ i It is not the correct serial number, but it is still within the reasonable threshold range, so the base station sends the SQN' of the gateway device to the gateway device. i Update; if the difference is greater than the first threshold, then SQN′ i If it is not within a reasonable threshold, the base station stops authenticating the IoT device or considers the authentication failed.

[0101] Step 307: The base station sends a relay authentication response to the gateway device. hn ,pk hn ,rsqn i ,rsqn j ,dguti i ,dguti j ,ver hn-i ,ver hn-j ,t3}.

[0102] In one embodiment, the base station uses a key derivation function to obtain a session key Key associated with the IoT device. hn-i =KDF(SUCI i ,SUCI j ,rand′ i ,s hn ·pk i ,t1,t2), using the XOR algorithm to obtain Among them, Key hn-i HN and IIoT i The session key is negotiated based on the temporary public and private keys and the random challenge value; XOR the corresponding hash function, calculate The base station uses the hash function and XOR algorithm to calculate the temporary identifier update parameter of the gateway device Calculating temporary identifier update parameters for IoT devices Calculate the authentication value of IoT devices Calculate the authentication value for the gateway device

[0103] In one implementation, the base station sends the acquired parameters as a relay authentication response to the gateway device.

[0104] In step 308, the gateway device receives the relay authentication request information sent by the base station and authenticates the reliability of the base station and the IoT device.

[0105] In one embodiment, the gateway device receives the relay authentication request information from the base station and verifies the freshness of t3; according to xrand hn 、rand j , calculated using the XOR algorithm Next, the gateway device uses the hash function and XOR algorithm to check rsqn j XOR to obtain Use hash function and XOR algorithm to dguti j Perform XOR calculation Verify the equation hn-j =h(GUTI′ j ,dguti i ,pk hn ,ver hn-i ,SQN j ,K j ,rand′ i ,t3) is established, if the equation is established, the gateway device confirms that the base station and the IoT device are trusted system authorized nodes, and relays the authentication request {xrand hn ,pk hn ,rsqn i ,dguti i ,dguti j ,ver hn-i ,ver hn-j ,t3} is complete and not tampered with, otherwise the gateway device rejects the relay authentication request and terminates the authentication process.

[0106] Step 309: The gateway device sends an authentication response {SUCI j ,rsqn i ,dguti i ,pk hn ,ver j-i ,t3,t4}.

[0107] In step 310, the IoT device receives the authentication response information sent by the gateway device and authenticates the reliability of the base station and the gateway device.

[0108] In one embodiment, the IoT device receives the authentication response information from the gateway device and verifies the freshness of t3 and t4; i SUCI j 、rand i 、s i ·pk hnAnd t1 and t3 use the key derivation function to obtain the Key i-hn ; IoT devices use hash functions and XOR algorithms to detect dguti i Perform XOR calculation to obtain Use hash function and XOR algorithm to rsqn i XOR to obtain IoT device computing And verify the equation j-i =h(SUCI i ,dguti i ,rsqn i pk hn ,ver h ' n-i ,rand i ,t3,t4) is established. If the equation is established, the IoT device confirms that the base station and gateway device are trusted system authorized nodes, and Key i-hn =Key hn-i , otherwise the IoT device rejects the authentication response and terminates the access.

[0109] Step 311: The base station successfully authenticates the IoT device.

[0110] Through the above steps, the IoT device confirms the legitimacy of the base station and gateway device, and obtains the globally unique temporary identifier GUTI′ issued by the base station. i , and verifies the integrity and validity of the authentication response, and calculates the session key Key shared with the base station i-hn =Key hn-i ;

[0111] At this point, through the above process, a mutual trust relationship has been established between the IoT device, gateway device and base station in the scenario, and the IoT device and base station have jointly negotiated a session key Key for secure data transmission based on the elliptic curve cryptography system and random challenge value. i-hn =Key hn-i =h(SUCI i ,SUCI j ,rand i ,s i ·s hn ·P,t1,t3), where the long-term authentication key {k i ,k j} and the current session key will not affect the session keyKey i-hnForward / backward security. To address the issues of session sequence number synchronization and temporary identifier update, the process of this method provides a corresponding synchronization mechanism to ensure trusted and anonymous communication of IoT devices in industrial 5G scenarios. In subsequent access authentication, the IoT device and gateway device use the updated globally unique identifier to replace the subscription hidden identifier to ensure the anonymity of the IoT device and gateway device.

[0112] Based on the same technical concept, a communication device is provided in an embodiment of the present application. The communication device can be a base station, an Internet of Things device, or a gateway device. The communication device can perform some or all of the steps in the embodiment of the present application. These steps or operations are only examples. The embodiment of the present application can also perform other operations or variations of various operations. In addition, the various steps can be performed in a different order than those presented in the embodiment of the present application, and it is possible that not all operations in the embodiment of the present application need to be performed.

[0113] It is understandable that in order to implement the functions in the above embodiments, the base station or IoT device or gateway device includes hardware structures and / or software modules corresponding to the execution of each function. It should be readily apparent to those skilled in the art that, in combination with the units and method steps of each example described in the embodiments disclosed in this application, the present application can be implemented in the form of hardware or a combination of hardware and computer software. Whether a function is executed in hardware or in a computer software-driven hardware manner depends on the specific application scenario and design constraints of the technical solution.

[0114] Figures 4 and 5 are schematic diagrams of the structures of possible communication devices provided by embodiments of the present application. These communication devices can be used to implement the functions of the base station or Internet of Things device or gateway device in the above method embodiments, and thus can also achieve the beneficial effects possessed by the above method embodiments. In the embodiments of the present application, the communication device can be a base station or Internet of Things device or gateway device, and can also be a module (such as a chip) applied to a base station or Internet of Things device or gateway device.

[0115] When the communication device 400 is used to implement the functions of the base station in the above embodiment:

[0116] The communication unit 401 is configured to receive a first message from a gateway device, wherein the first message is used to request authentication of the network device and the IoT device, and the first message includes: a first subscription anonymity identifier SUCI i , the second subscription anonymity identifier SUCI j , the first temporary public key pk i , the second temporary public key pk j , first sequence number dsqn i , second serial number dsqn j , the first random number dri , the second random number dr j , the first authentication value ver i , the second authentication value ver j , first timestamp, second timestamp; if the fourth authentication value is equal to the first authentication value ver i , it is determined that the IoT device is successfully authenticated, and a second message is sent to the gateway device;

[0117] The processing unit 402 is configured to: j , the second serial number dsqn j The second random number dr j , the first authentication value ver i , the first timestamp, the second timestamp determine a third authentication value; if the third authentication value is equal to the second authentication value ver j , it is determined that the gateway device authentication is successful; according to the first subscription anonymity identifier SUCI i 、The first serial number dsqn i , the first temporary public key pk i 、The first random number dr j , the first timestamp, the second timestamp determine a fourth authentication value; if the fourth authentication value is equal to the first authentication value ver i , it is determined that the IoT device authentication is successful.

[0118] When the communication device 400 is used to implement the functions of the gateway device in the above embodiment:

[0119] The communication unit 401 is configured to receive a second message from the base station, the second message being used to request authentication of the base station and the IoT device, the second message including: a first globally unique temporary identifier dguti i , second globally unique temporary identifier dguti j , third sequence number rsqn i , the fourth sequence number rsqn j , the third temporary public key pk hn 、The third random number xr hn 、The fifth authentication value ver hn-i 、The sixth authentication value ver hn-j , a third timestamp; if the seventh authentication value is equal to the fifth authentication value ver hn-i , it is determined that the authentication between the base station and the IoT device is successful, and a third message is sent to the IoT device;

[0120] The processing unit 402 is configured to: i , the second globally unique temporary identifier dguti j , the third sequence number rsqn i , the third temporary public key pk hn , the third random number xr hn , the fifth authentication value ver hn-i , the third timestamp determines a seventh authentication value; if the seventh authentication value is equal to the fifth authentication value ver hn-i , it is determined that the authentication of the base station and the IoT device is successful.

[0121] When the communication device 400 is used to implement the IoT device functions in the above embodiments:

[0122] The communication unit 401 is configured to receive a third message from the gateway device, wherein the third message is used to request authentication of the gateway device and the base station, and the third message includes: the second subscription anonymity identifier SUCI j , the first globally unique temporary identifier dguti i , the third sequence number rsqn i , the third temporary public key pk hn , the eighth authentication value ver j-i , the third timestamp and the fourth timestamp;

[0123] The processing unit 402 is configured to: i , the second globally unique temporary identifier dguti j , the third temporary public key pk hn , the third sequence number rsqn i , the fifth authentication value ver hn-i 、The first random number dr i , the third timestamp and the fourth timestamp determine a ninth authentication value; if the ninth authentication value is equal to the eighth authentication value ver j-i , it is determined that the authentication of the base station and the gateway device is successful.

[0124] The communication device 500 shown in Figure 5 includes a processor 501, an interface 502 and a memory 503; the specific connection medium between the above-mentioned processor 501, interface 502 and memory 503 is not limited in the embodiment of the present invention. In Figure 5 of the embodiment of the present application, the processor 501, interface 502 and memory 503 are connected by a bus, and the connection method between other components is only for schematic illustration and is not limiting. The bus can be divided into an address bus, a data bus, a control bus, etc. The memory 503 is used to store instructions executed by the processor 501 or to store input data required by the processor 501 to run instructions or to store data generated after the processor 501 runs instructions.

[0125] Memory 503 can be a volatile memory, such as random-access memory (RAM); it can also be a non-volatile memory, such as read-only memory, flash memory, a hard disk drive (HDD), or a solid-state drive (SSD); or it can be any other medium that can be used to carry or store desired program code in the form of instructions or data structures and can be accessed by a computer, but is not limited thereto. Memory 503 can be a combination of the above memories.

[0126] An embodiment of the present application further provides a computer-readable storage medium, wherein the computer-readable storage medium stores a computer program or instructions. When the computer program or instructions are executed, any one of the methods provided in the present application is implemented.

[0127] In some possible implementations, various aspects of the product business component determination method provided by the present invention can also be implemented in the form of a program product, which includes program code. When the program product is run on an electronic device, the program code is used to enable the electronic device to execute the steps of the table item update method according to various exemplary embodiments of the present invention described above in this specification.

[0128] Those skilled in the art will appreciate that the embodiments of the present application can be provided as methods, systems, or computer program products. Therefore, the present application can adopt the form of a complete hardware embodiment, a complete software embodiment, or an embodiment in combination with software and hardware. Moreover, the present application can adopt the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to magnetic disk storage, CD-ROM, optical storage, etc.) that contain computer-usable program code.

[0129] The present application is described with reference to the flowcharts and / or block diagrams of the methods, devices (systems), and computer program products according to the present application. It should be understood that each flow and / or box in the flow chart and / or block diagram, as well as the combination of the flow chart and / or box in the flow chart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device produce a device for implementing the functions specified in one or more flow charts and / or one or more boxes in the block diagram.

[0130] These computer program instructions may also be stored in a computer-readable memory that can direct a computer or other programmable data processing device to operate in a specific manner, so that the instructions stored in the computer-readable memory produce a product including an instruction device that implements the functions specified in one or more processes in the flowchart and / or one or more boxes in the block diagram.

[0131] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operating steps are executed on the computer or other programmable device to produce a computer-implemented process, so that the instructions executed on the computer or other programmable device provide steps for implementing the functions specified in one or more processes in the flowchart and / or one or more boxes in the block diagram.

[0132] Obviously, those skilled in the art may make various changes and modifications to this application without departing from the spirit and scope of this application. Thus, if these modifications and variations of this application fall within the scope of the claims of this application and their equivalents, this application is intended to include these modifications and variations.

Claims

1. An authentication system, characterized in that: include: A base station receives a first message from a gateway device, wherein the first message is used to request authentication of the network device and the Internet of Things device, and the first message includes: a first subscription anonymity identifier SUCI i , the second subscription anonymity identifier SUCI j , the first temporary public key pk i , the second temporary public key pk j , first sequence number dsqn i , the second sequence number dsqn j , the first random number dr i , the second random number dr j , the first authentication value ver i , the second authentication value ver j , first timestamp, second timestamp; According to the second subscription concealment identifier SUCI j , the second serial number dsqn j The second random number dr j , the first authentication value ver i , determining a third authentication value using the first timestamp and the second timestamp; If the third authentication value is equal to the second authentication value ver j , it is determined that the gateway device is successfully authenticated; According to the first subscription concealed identifier SUCI i 、The first serial number dsqn i , the first temporary public key pk i 、The first random number dr j , determining a fourth authentication value using the first timestamp and the second timestamp; If the fourth authentication value is equal to the first authentication value ver i , it is determined that the IoT device is successfully authenticated, and a second message is sent to the gateway device; The gateway device receives a second message from the base station, the second message is used to request authentication of the base station and the IoT device, and the second message includes: a first globally unique temporary identifier dguti i , second globally unique temporary identifier dguti j 、The third sequence number rsqn i , the fourth sequence number rsqn j 、The third temporary public key pk hn 、The third random number xr hn 、The fifth authentication value ver hn-i 、The sixth authentication value ver hn-j , third timestamp; According to the first globally unique temporary identifier dguti i , the second globally unique temporary identifier dguti j , the third sequence number rsqn i , the third temporary public key pk hn , the third random number xr hn , the fifth authentication value ver hn-i , the third timestamp determines a seventh authentication value; If the seventh authentication value is equal to the fifth authentication value ver hn-i , it is determined that the authentication between the base station and the IoT device is successful, and a third message is sent to the IoT device; The Internet of Things device receives a third message from the gateway device, the third message is used to request authentication of the gateway device and the base station, and the third message includes: the second subscription anonymity identifier SUCI j , the first globally unique temporary identifier dguti i , the third sequence number rsqn i , the third temporary public key pk hn , the eighth authentication value ver j-i , the third timestamp and the fourth timestamp; According to the first subscription concealed identifier SUCI i , the second globally unique temporary identifier dguti j , the third temporary public key pk hn , the third sequence number rsqn i , the fifth authentication value ver hn-i 、The first random number dr i , determining a ninth authentication value using the third timestamp and the fourth timestamp; If the ninth authentication value is equal to the eighth authentication value ver j-i , it is determined that the authentication of the base station and the gateway device is successful.

2. The system according to claim 1, characterized in that The second subscription concealed identifier SUCI j , the second serial number dsqn j The second random number dr j , the first authentication value ver i , determining a third authentication value using the first timestamp and the second timestamp, comprising: According to the second subscription concealment identifier SUCI j Determine the first shared authentication key K j ; According to the second sequence number dsqn j , the second subscription concealed identifier SUCI j , the first shared authentication key K j , the first authentication value ver i , the second timestamp determines the fifth sequence number SQN′ j ; According to the second random number dr j , the fifth sequence number SQN′ j , the second subscription concealed identifier SUCI j , the first shared authentication key K j , the second timestamp determines a fourth random number rand′ j ; According to the second subscription concealment identifier SUCI j , the fifth sequence number SQN′ j , the fourth random number rand′ j , the first authentication value ver i , the first timestamp and the second timestamp determine the third authentication value.

3. The system according to claim 1, characterized in that The first subscription concealed identifier SUCI i 、The first serial number dsqn i , the first temporary public key pk i 、The first random number dr j , determining a fourth authentication value based on the first timestamp and the second timestamp, comprising: According to the first subscription concealed identifier SUCI i , determine the second shared authentication key K i ; According to the first sequence number dsqn i , the first subscription anonymous identifier SUCI i , the second shared authentication key K i , the first temporary public key pk i , the first timestamp determines the sixth sequence number SQN′ i ; According to the first random number dr i , the sixth sequence number SQN′ i , the first subscription anonymous identifier SUCI i , the second shared authentication key K i , the first timestamp determines the fifth random number rand′ i ; According to the first subscription concealed identifier SUCI i , the first temporary public key pk i , the sixth sequence number SQN′ i , the fifth random number rand′ i , the first timestamp determines the fourth authentication value.

4. The system according to claim 1, characterized in that The first globally unique temporary identifier dguti i , the second globally unique temporary identifier dguti j , the third sequence number rsqn i , the third temporary public key pk hn , the third random number xr hn , the fifth authentication value ver hn-i , the third timestamp determines a seventh authentication value, comprising: According to the third random number xr hn With the second random number dr j Calculate the fourth random number rand′ j ; According to the second globally unique temporary identifier dguti j , determine the third globally unique temporary identifier GUTI′ j ; According to the fourth sequence number rsqn j Determine the seventh serial number According to the third globally unique temporary identifier GUTI′ j , the first globally unique temporary identifier dguti i , the third temporary public key pk hn , the third sequence number rsqn i , the seventh serial number The fifth authentication value ver hn-i , the first shared authentication key K j , the fifth random number rand′ i , the third timestamp determines the seventh authentication value.

5. The system according to claim 1, wherein: The first subscription concealed identifier SUCI i , the second globally unique temporary identifier dguti j , the third temporary public key pk hn , the third sequence number rsqn i , the fifth authentication value ver hn-i 、The first random number dr i , determining a ninth authentication value using the third timestamp and the fourth timestamp, comprising: According to the first subscription concealed identifier SUCI i , the second subscription concealed identifier SUCI j 、The sixth random number rand i , the third temporary public key pk hn , the first timestamp and the third timestamp, determine the first session key Key i-hn ; According to the third sequence number rsqn i Determine the eighth sequence number According to the first globally unique temporary identifier dguti i , determine the fourth globally unique temporary identifier GUTI′ i ; According to the first subscription concealed identifier SUCI i , the second subscription concealed identifier SUCI j , the fourth globally unique temporary identifier GUTI′ i , the first temporary public key pk i 、5th serial number SQN i , the second shared authentication key K i , the sixth random number rand i and the third timestamp, determine the fifth authentication value ver hn-i ; According to the fifth authentication value ver hn-i , the first subscription anonymous identifier SUCI i , the first globally unique temporary identifier dguti i , the third temporary public key pk hn , the third sequence number rsqn i , the sixth random number rand i And the third timestamp and the fourth timestamp determine the ninth authentication value.

6. An authentication method, characterized in that: include: Receive a first message from a gateway device, wherein the first message is used to request the network device and the Internet of Things device to be The first message includes: a first subscription anonymity identifier SUCI i , the second subscription anonymity identifier SUCI j , the first temporary public key pk i , the second temporary public key pk j , first sequence number dsqn i , the second sequence number dsqn j , the first random number dr i , the second random number dr j , the first authentication value ver i , the second authentication value ver j , first timestamp, second timestamp; According to the second subscription concealment identifier SUCI j , the second serial number dsqn j The second random number dr j , the first authentication value ver i , determining a third authentication value using the first timestamp and the second timestamp; If the third authentication value is equal to the second authentication value ver j , it is determined that the gateway device is successfully authenticated; According to the first subscription concealed identifier SUCI i 、The first serial number dsqn i , the first temporary public key pk i 、The first random number dr j , determining a fourth authentication value using the first timestamp and the second timestamp; If the fourth authentication value is equal to the first authentication value ver i , it is determined that the IoT device is authenticated successfully.

7. An authentication method, characterized in that: include: Receive a second message from the base station, the second message is used to request authentication of the base station and the Internet of Things device, the second message includes: a first globally unique temporary identifier dguti i , second globally unique temporary identifier dguti j 、The third sequence number rsqn i , the fourth sequence number rsqn j 、The third temporary public key pk hn 、The third random number xr hn 、The fifth authentication value ver hn-i 、The sixth authentication value ver hn-j , third timestamp; According to the first globally unique temporary identifier dguti i , the second globally unique temporary identifier dguti j , the third sequence number rsqn i , the third temporary public key pk hn , the third random number xr hn , the fifth authentication value ver hn-i , the third timestamp determines a seventh authentication value; If the seventh authentication value is equal to the fifth authentication value ver hn-i , it is determined that the authentication of the base station and the IoT device is successful.

8. An authentication method, characterized in that: include: receiving a third message from a gateway device, the third message being used to request authentication of the gateway device and the base station, the third message comprising: the second subscription anonymity identifier SUCI j , the first globally unique temporary identifier dguti i , the third sequence number rsqn i , the third temporary public key pk hn , the eighth authentication value ver j-i , the third timestamp and the fourth timestamp; According to the first subscription concealed identifier SUCI i , the second globally unique temporary identifier dguti j , the third temporary public key pk hn , the third sequence number rsqn i , the fifth authentication value ver hn-i 、The first random number dr i , determining a ninth authentication value using the third timestamp and the fourth timestamp; If the ninth authentication value is equal to the eighth authentication value ver j-i , it is determined that the authentication of the base station and the gateway device is successful.

9. A communication device, characterized in that: including a processor and a memory; The memory is used to store computer instructions; The processor is connected to the memory, and is used to execute the computer instructions in the memory to implement the method as claimed in any one of claims 6 to 8.

10. A storage medium, characterized in that: The computer-readable storage medium stores a computer program or instruction, and when the computer program or instruction is executed by the communication device, the method according to any one of claims 6 to 8 is implemented.

11. A computer program product, characterized in that The computer program product comprises a computer program stored on a computer-readable storage medium, wherein the computer program comprises program instructions, and when the program instructions are executed by a computer, the computer is caused to execute the steps of the method according to any one of claims 6 to 8.