Communication method and device

By using the first credential based on key calculation between the terminal and the network device for authentication, the problem of low access efficiency during roaming is solved, and a safe and efficient access authentication is achieved.

WO2025138213A1PCT designated stage expired Publication Date: 2025-07-03GUANGDONG OPPO MOBILE TELECOMMUNICATIONS CORP LTD
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
PCT/CN2023/143553
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2023-12-29
Publication Date
2025-07-03

AI Technical Summary

Technical Problem

During the roaming process, how to improve the efficiency of terminal access to the roaming network and ensure security becomes a challenge.

Method used

By authenticating between the terminal and the network device using the first credential calculated key between the first core network device and the second core network device of the second network, secure access to the terminal on the first network is realized.

Benefits of technology

The authentication efficiency of terminal access to other networks is improved, while ensuring security, and avoiding the inefficiency problem caused by multiple security parameter calculations in the prior art.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2023143553_03072025_PF_FP_ABST
    Figure CN2023143553_03072025_PF_FP_ABST
Patent Text Reader

Abstract

The present application relates to a communication method, a device, a computer-readable storage medium, a computer program product and a computer program. The method comprises: sending an authentication request to a first network device of a first network, wherein the authentication request carries a first credential for authenticating a terminal, the first credential is calculated on the basis of a first key between a first core network device of the first network and a second core network device of a second network, and the terminal belongs to the second network.
Need to check novelty before this filing date? Find Prior Art

Description

Communication method and device Technical Field

[0001] The present application relates to the field of communications, and more specifically, to a communication method and device. Background Art

[0002] Roaming agreements, as they are commonly known, refer to mobile communications agreements that allow terminals to switch between different carriers' networks and access services. These agreements enable users to communicate through other carriers' networks even when outside their carrier's coverage area. The development and implementation of roaming agreements improve user experience, enabling terminals to freely switch between networks maintained by different carriers in different regions. However, ensuring the efficiency of terminals accessing roaming networks (i.e., networks not their own) during roaming becomes a challenge.

[0003] Summary of the Invention

[0004] The embodiments of the present application provide a communication method and device.

[0005] An embodiment of the present application provides a communication method performed by a terminal, including:

[0006] An authentication request is sent to a first network device of a first network, wherein the authentication request carries a first credential for authenticating the terminal, the first credential is calculated based on a first key between a first core network device of the first network and a second core network device of a second network, and the terminal belongs to the second network.

[0007] An embodiment of the present application provides a communication method performed by an access network device, including:

[0008] Receive an authentication request from a terminal, wherein the authentication request carries a first credential for authenticating the terminal, the first credential is calculated based on a first key between a first core network device of a first network and a second core network device of a second network, the terminal belongs to the second network, and the access network device belongs to the first network.

[0009] An embodiment of the present application provides a communication method performed by a first core network device, including:

[0010] Receive an authentication request from an access network device, wherein the authentication request carries a first credential for authenticating a terminal, the first credential is calculated based on a first key between the first core network device of the first network and the second core network device of the second network, the terminal belongs to the second network, and the access network device belongs to the first network.

[0011] This embodiment of the present application provides a communication method performed by a second core network device, including:

[0012] A first resource response message is sent to the terminal, wherein the first resource response message carries a first credential for authenticating the terminal, the first credential is calculated based on a first key between a first core network device of the first network and the second core network device of the second network, and the terminal belongs to the second network.

[0013] A communication method performed by a first core network device according to an embodiment of the present application includes:

[0014] Receive an authentication request from a terminal, wherein the authentication request carries a first credential for authenticating the terminal, the first credential is calculated based on a first key between the first core network device of the first network and the second core network device of the second network, and the terminal belongs to the second network.

[0015] An embodiment of the present application provides a terminal, including:

[0016] A first communication unit is used to send an authentication request to a first network device of a first network, wherein the authentication request carries a first credential for authenticating the terminal, the first credential is calculated based on a first key between a first core network device of the first network and a second core network device of a second network, and the terminal belongs to the second network.

[0017] An embodiment of the present application provides an access network device, including:

[0018] A second communication unit is used to receive an authentication request from a terminal, wherein the authentication request carries a first credential for authenticating the terminal, the first credential is calculated based on a first key between a first core network device of a first network and a second core network device of a second network, the terminal belongs to the second network, and the access network device belongs to the first network.

[0019] An embodiment of the present application provides a first core network device, including:

[0020] The third communication unit is used to receive an authentication request from an access network device, wherein the authentication request carries a first credential for authenticating the terminal, the first credential is calculated based on a first key between the first core network device of the first network and the second core network device of the second network, the terminal belongs to the second network, and the access network device belongs to the first network.

[0021] An embodiment of the present application provides a second core network device, including:

[0022] A fourth communication unit is used to send a first resource response message to the terminal, wherein the first resource response message carries a first credential for authenticating the terminal, the first credential is calculated based on a first key between a first core network device of the first network and the second core network device of the second network, and the terminal belongs to the second network.

[0023] An embodiment of the present application provides a first core network device, including:

[0024] A third communication unit is used to receive an authentication request from a terminal, wherein the authentication request carries a first credential for authenticating the terminal, the first credential is calculated based on a first key between the first core network device of the first network and the second core network device of the second network, and the terminal belongs to the second network.

[0025] By adopting the above solution, when a terminal belonging to the second network accesses the first network, it sends an authentication request carrying a first credential to the network device of the first network. Because the first credential is calculated based on the key between the first core network device of the first network and the second core network device of the second network, the terminal can be authenticated on the first network side using the first credential. In this way, when the terminal needs to access other networks, it can be authenticated only using the first credential, ensuring security while also improving authentication efficiency. BRIEF DESCRIPTION OF THE DRAWINGS

[0026] FIG1 is a schematic diagram of an application scenario according to an embodiment of the present application.

[0027] FIG2 is a schematic flowchart of a communication method according to an embodiment of the present application.

[0028] FIG3 is a schematic flowchart of a communication method according to another embodiment of the present application.

[0029] FIG4 is a schematic flowchart of a communication method according to yet another embodiment of the present application.

[0030] FIG5 is a schematic flowchart of a communication method according to yet another embodiment of the present application.

[0031] FIG6 is a schematic flowchart of a communication method according to yet another embodiment of the present application.

[0032] FIG7 is a schematic flowchart of the issuance process of a primary certificate according to an embodiment of the present application.

[0033] FIG8 is a schematic flowchart of the issuance process of a secondary certificate according to an embodiment of the present application.

[0034] FIG9 is a schematic flowchart of a terminal using a secondary credential to perform access processing according to an embodiment of the present application.

[0035] FIG10 is a schematic flowchart of a process of rejecting a service by a first core network device according to an embodiment of the present application.

[0036] FIG11 is a schematic flowchart of processing a claim for a second core network device according to an embodiment of the present application.

[0037] FIG12 is another schematic flowchart of a communication method according to an embodiment of the present application.

[0038] FIG13 is a schematic block diagram of a terminal according to an embodiment of the present application.

[0039] FIG14 is a schematic block diagram of an access network device according to an embodiment of the present application.

[0040] Figure 15 is a schematic block diagram of a first core network device according to an embodiment of the present application.

[0041] Figure 16 is a schematic block diagram of a second core network device according to an embodiment of the present application. DETAILED DESCRIPTION

[0042] The technical solutions of the embodiments of the present application can be applied to various communication systems, such as LTE, LTE-A, NR, NR evolution, WLAN, WiFi, or other communication systems.

[0043] The embodiments of the present application describe various embodiments in conjunction with network devices and terminals. The terminals can be mobile or fixed, and can also be referred to as mobile stations, user units, etc. The terminal can be a site in a WLAN, and can be a smart terminal, wireless modem, laptop computer, tablet computer, or other terminal. In the embodiments of the present application, the terminal can be a VR terminal / AR terminal, an industrial control terminal, an unmanned driving terminal, a telemedicine terminal, a smart grid terminal, a transportation safety terminal, a smart city terminal, or a wireless terminal for a smart home, etc. As an example and not a limitation, in the embodiments of the present application, the terminal can also be a wearable device.

[0044] In the embodiment of the present application, the network device may be a device for communicating with a terminal, an access point in a WLAN, an evolved base station in LTE, or a relay station, or a network device (gNB) in an in-vehicle device, a wearable device, and an NR network, or a network device in a future evolved PLMN network or a network device in a non-terrestrial network. As an example and not a limitation, in the embodiment of the present application, the network device may have a mobile feature, for example, the network device may be a mobile device.

[0045] To facilitate understanding of the technical solutions of the embodiments of the present application, the relevant technologies of the embodiments of the present application are described below. The following relevant technologies can be arbitrarily combined with the technical solutions of the embodiments of the present application as optional solutions, and they all fall within the protection scope of the embodiments of the present application.

[0046] Figure 1 exemplarily illustrates a communication system 100. The communication system includes a network device 110 and two terminals 120. In one possible implementation, the communication system 100 may include multiple network devices 110, and each network device 110 may include a different number of terminals 120 within its coverage area, although this embodiment of the present application does not limit this. In one possible implementation, the communication system 100 may also include a mobility management entity, access and mobility management functions, and other network entities, although this embodiment of the present application does not limit this. The network devices may include access network devices and core network devices. That is, the communication system may also include multiple core networks for communicating with the access network devices. The access network devices may be base stations of LTE, LTE-A, or NR systems. Taking the communication system shown in Figure 1 as an example, the communication devices may include network devices and terminals with communication functions. The communication devices may also include other devices in the communication system, such as network controllers, mobility management entities, and other network entities, although this embodiment of the present application does not limit this.

[0047] FIG2 is a schematic flow chart of a communication method executed by a terminal according to an embodiment of the present application. The method includes at least part of the following contents.

[0048] S210. Send an authentication request to a first network device of a first network, wherein the authentication request carries a first credential for authenticating the terminal, the first credential is calculated based on a first key between a first core network device of the first network and a second core network device of a second network, and the terminal belongs to the second network.

[0049] Figure 3 is a schematic flow chart of a communication method performed by an access network device according to an embodiment of the present application. The method includes at least part of the following contents.

[0050] S310. Receive an authentication request from a terminal, wherein the authentication request carries a first credential for authenticating the terminal, the first credential is calculated based on a first key between a first core network device of a first network and a second core network device of a second network, the terminal belongs to the second network, and the access network device belongs to the first network.

[0051] Figure 4 is a schematic flow chart of a communication method performed by a first core network device according to an embodiment of the present application. The method includes at least part of the following contents.

[0052] S410. Receive an authentication request from an access network device, wherein the authentication request carries a first credential for authenticating the terminal, the first credential is calculated based on a first key between the first core network device of the first network and the second core network device of the second network, the terminal belongs to the second network, and the access network device belongs to the first network.

[0053] Figure 5 is a schematic flow chart of a communication method performed by a second core network device according to an embodiment of the present application. The method includes at least part of the following contents.

[0054] S510. Send a first resource response message to the terminal, wherein the first resource response message carries a first credential for authenticating the terminal, the first credential is calculated based on a first key between a first core network device of the first network and a second core network device of the second network, and the terminal belongs to the second network.

[0055] Figure 6 is a schematic flow chart of a communication method performed by a first core network device according to an embodiment of the present application. The method includes at least part of the following contents.

[0056] S610. Receive an authentication request from a terminal, wherein the authentication request carries a first credential for authenticating the terminal, the first credential is calculated based on a first key between the first core network device of the first network and the second core network device of the second network, and the terminal belongs to the second network.

[0057] The first core network device and the second core network device belong to different networks; the first network and the second network are different, the first network and the second network belong to different operators respectively, or the first network and the second network are managed by different operators.

[0058] The function of the first core network device may be to be responsible for and manage the resources (or spectrum resources) of the first network, and to meet the communication needs of the subscribers of the first network in mobile communications. The function of the second core network device may be to be responsible for and manage the resources (or spectrum resources) of the second network, and to meet the communication needs of the subscribers of the second network in mobile communications. This embodiment does not limit the device types of the first core network device and the second core network device. For example, the first core network device and the second core network device may be control plane network elements within their respective networks, and the possible device types of the first core network device and the second core network device are not limited or enumerated herein.

[0059] The terminal belonging to the network where the second core network device is located means that the terminal is a subscribed terminal of the second network, in other words, the second network is the home network of the terminal. The first network refers to the roaming network of the terminal.

[0060] The first network device may include one of the following: an access network device or a first core network device. That is, the terminal's authentication request may be sent to the access network device of the first network, or the terminal's authentication request may be sent to the first core network device of the first network. Here, the first core network device may refer to a core network device in the terminal's roaming network, or an access network device in the terminal's roaming network.

[0061] In some possible implementations, the first credential is generated based on a first key between the first core network device and the second core network device, where the first key between the first core network device and the second core network device is encrypted and carried by the second credential. A process of generating and issuing the second credential is required to be performed between the first core network device and the second core network device.

[0062] On the second core network device side, the method may also include: sending a second resource request message to the first core network device, wherein the second resource request message is used to request the use of the second resource of the first network; downloading a second credential from the blockchain, wherein the second credential includes the first key encrypted based on the public key of the second core network device.

[0063] On the first core network device side, the method may further include: receiving a second resource request message from the second core network device, wherein the second resource request message is used to request the use of the second resource of the first network; uploading a second resource response message to the blockchain, wherein the second resource response message is used to indicate that the second core network device is allowed to use the second resource of the first network, and the second resource response message carries a second credential, and the second credential includes the first key encrypted based on the public key of the second core network device.

[0064] Since the second credential is an interactive process at the core network level of the two networks, it needs to be allocated or issued before the terminal uses the first credential to access the network where the first core network device is located. Therefore, in some possible examples, the second credential can also be called a first-level credential.

[0065] In one embodiment, the second resource request message may carry at least one of the following: a first signature, information requesting the use of the second resource of the first network, and an identifier of the second core network device.

[0066] Here, the identifier of the second core network device can be used by the first core network device to determine the identity of the device that sends the second resource request message.

[0067] The first signature may be calculated based on the private key of the second core network device and at least one of the following parameters: an identifier of the second core network device and information requesting use of the second resource of the first network. The signature algorithm used to calculate the first signature may be configured according to actual circumstances.

[0068] For example, the calculation of the first signature can be: using a signature algorithm to calculate the first signature based on the private key of the second core network device and at least one of the identification of the second core network device and the information requesting to use the second resource of the first network.

[0069] For example, the calculation of the first signature may include: performing a hash calculation based on at least one of the identification of the second core network device and the information requesting the use of the second resource of the first network to obtain a first hash value; and encrypting the first hash value based on the private key of the second core network device to obtain a first signature.

[0070] It should be understood that the parameters used to calculate the first signature and the other parameters carried by the second resource request message except the first signature may be the same or partially the same. For example, in addition to the first signature, the second resource request message carries the identifier of the second core network device and the information requesting the use of the second resource of the first network; the first signature can be calculated using any one of the identifier of the second core network device and the information requesting the use of the second resource of the first network. For another example, the second resource request message carries the identifier of the second core network device and the information requesting the use of the second resource of the first network; the first signature can also be calculated using the identifier of the second core network device and the information requesting the use of the second resource of the first network.

[0071] The information requesting to use the second resource of the first network refers to the relevant information of the second core network device applying to use the second resource of the first network. The resource may refer to a time domain resource and / or a frequency domain resource.

[0072] Specifically, the information requesting the use of the second resource of the first network may include at least one of the following: an identifier of the first core network device, an identifier (or number) for requesting the use of the second resource of the first network, a usage period for requesting the use of the second resource of the first network, and a price for requesting the use of the second resource of the first network.

[0073] The number of second resources of the first network requested for use by the second core network device may be one or more; that is, the second resources requested for use by the second core network device may be one or more resources among all resources supported or managed by the network (first network) where the first core network device is located. The second core network device may indicate which resource or resources in the first network are requested for use by using the identifier of each second resource. That is, the identifier of the second resource requested for use of the first network may refer to the identifier of each second resource in at least one second resource requested for use by the second core network device among all resources of the first network.

[0074] The usage period for requesting to use the second resource of the first network may include at least one of the following: the start time for requesting to use the second resource of the first network, the end time for requesting to use the second resource of the first network, and the effective duration for requesting to use the second resource of the first network.

[0075] For example, the usage period of the request to use the second resource of the first network may only include the end time of the request to use the second resource of the first network. Accordingly, the first core network device may use the moment of receiving the second resource request message as the start time of the request to use the second resource of the first network.

[0076] For example, the usage period of the request to use the second resource of the first network may only include the effective duration of the request to use the second resource of the first network. Accordingly, the first core network device can use the moment of receiving the second resource request message as the starting timing moment of the effective duration of the request to use the second resource of the first network.

[0077] For example, the usage period for requesting to use the second resource of the first network may include: a usage start time for requesting to use the second resource of the first network and an usage end time for requesting to use the second resource of the first network.

[0078] For example, the usage period of the request to use the second resource of the first network may include: the usage start time of the request to use the second resource of the first network and the validity period of the request to use the second resource of the first network.

[0079] It should be understood that the above is merely an exemplary description. In actual processing, the usage period of the request to use the second resource of the first network may also be indicated in other ways, but this embodiment does not limit or exhaustively list them.

[0080] The price for requesting use of the second resource of the first network may refer to the total price for using the second resource of the first network during the usage period for which use of the second resource of the first network is requested. This price may be calculated based on the unit price of each second resource in the network where the first core network device is located and the usage period. The specific calculation method of this price, the definition of the unit price, etc. are not limited in this embodiment.

[0081] In one embodiment, after the first core network device receives the second resource request message from the second core network device, it can first verify the reliability of the second resource request message, and generate a second credential if the verification passes.

[0082] Here, verifying the reliability of the second request message may include at least one of the following: verifying the second core network device based on the first signature; verifying the information of the request to use the second resource of the first network. Accordingly, verification passed may mean: if only the processing of verifying the second core network device based on the first signature is performed, then if the verification of the second core network device is successful, the verification is determined to be passed; if only the processing of verifying the information of the request to use the second resource of the first network is performed, then if the information of the request to use the second resource of the first network is correct, the verification is determined to be passed; if the second core network device is verified based on the first signature, and the information of the request to use the second resource of the first network is verified, then if the verification of the second core network device is successful and the information of the request to use the second resource of the first network is correct, the verification is determined to be passed.

[0083] Optionally, verifying the second core network device based on the first signature may include: verifying the second core network device based on the public key of the second core network device, the first signature and at least one other information carried in the second resource request message: the identification of the second core network device, and information requesting the use of the second resource of the first network.

[0084] The public key of the second core network device may be disclosed on the blockchain, and the first core network device may obtain the public key of the second core network device from the blockchain. Exemplarily, the first core network device may obtain the public key of the second core network device from the blockchain based on an identifier of the second core network device.

[0085] The signature verification algorithm used to verify the first signature should correspond to the algorithm used to calculate the first signature; and the parameters used to verify the first signature should be the same as the parameters used to calculate the first signature.

[0086] For example, assuming that the first signature is calculated based on the identifier of the second core network device and the information requesting to use the second resource of the first network, verifying the second core network device based on the first signature may include: using a signature verification algorithm, decrypting the first signature based on the public key of the second core network device to obtain a parameter to be verified; and verifying the second core network device based on the parameter to be verified, the identifier of the second core network device, and the information requesting to use the second resource of the first network.

[0087] Among them, based on the parameters to be verified and the identification of the second core network device and the information requesting to use the second resources of the first network, the verification of the second core network device can be at least one of the following: when the parameters to be verified are the same as the identification of the second core network device and the information requesting to use the second resources of the first network, it is determined that the verification of the second core network device is successful; when the parameters to be verified are different from the identification of the second core network device and the information requesting to use the second resources of the first network, it is determined that the verification of the second core network device has failed.

[0088] For example, assume that the first signature is calculated based on the identification of the second core network device and the information requesting the use of the second resource of the first network. Verifying the second core network device based on the first signature can be: performing a hash calculation based on the identification of the second core network device and the information requesting the use of the second resource of the first network to obtain a first verification hash value, decrypting the first signature based on the public key of the second core network device to obtain a first decryption value; and verifying the second core network device based on the first decryption value and the first verification hash value. Wherein, verifying the second core network device based on the first decryption value and the first verification hash value may include at least one of the following: if the first decryption value and the first verification hash value are the same, verifying the second core network device is successful; if the first decryption value and the first verification hash value are different, verifying the second core network device fails.

[0089] It should be noted that if verification of the second core network device based on the first signature fails, the first core network device may terminate the processing and / or return a verification failure response message to the second core network device.

[0090] Optionally, verifying the information regarding the request to use the second resource of the first network may include: verifying whether the identifiers of each second resource in the information regarding the request to use the second resource of the first network are identifiers of resources of the network to which the second resource belongs, and / or verifying whether the price of the second resource requested to use the first network is accurate, etc. The specific possible contents to be verified and the verification methods are not limited or exhaustive herein.

[0091] In one embodiment, the second credential includes a first key encrypted based on the public key of the second core network device. Here, the manner in which the first core network device generates the first key between the first core network device and the second core network device is not limited in this embodiment.

[0092] In some examples, the second credential may also be referred to as an authorization credential (or a primary credential) for the second resource requested or applied for use by the second core network device.

[0093] Optionally, after generating the second credential, the first core network device uploads it to the blockchain by carrying it in the second resource response.

[0094] Optionally, in addition to the second credential, the second resource response message may also carry at least one of the following: an identifier of the second core network device, authorization for the second core network device to use the second resource of the first network, zero-knowledge proof data, and a second signature. That is, after generating the second credential, the first core network device uploads the second credential and at least one of the following parameters to the blockchain in the second resource response: an identifier of the second core network device, authorization for the second core network device to use the second resource of the first network, zero-knowledge proof data, and a second signature.

[0095] The specific content included in the authorization for the second core network device to use the second resource of the first network may be the same as the content included in the information requesting the use of the second resource of the first network, and will not be repeated here.

[0096] The zero-knowledge proof data (ZK) can be simply expressed as ZK.

[0097] The second signature can be calculated based on the private key of the first core network device and the parameters included in the second certificate.

[0098] Exemplarily, the calculation of the second signature can be: using a signature algorithm, based on the private key of the first core network device, to calculate at least one of the encrypted first key, the identification of the second core network device, the authorization for the second core network device to use the second resource of the first network, and zero-knowledge proof data.

[0099] Exemplarily, the calculation of the second signature can be: performing a hash calculation based on the encrypted first key, the identification of the second core network device, the authorization for the second core network device to use the second resource of the first network, and at least one of the zero-knowledge proof data to obtain a second hash value; encrypting the second hash value based on the private key of the first core network device to obtain a second signature.

[0100] The encrypted first key, ZK and / or second signature in the second certificate can provide public verification capabilities to ensure that after the second certificate is uploaded to the blockchain, the blockchain (such as the on-chain node of the blockchain) can confirm that the second resource authorized by the second certificate is provided by the first core network device to the second core network device, and the blockchain (such as the on-chain node of the blockchain) can also confirm that the encrypted first key is indeed encrypted using the public key of the second core network device.

[0101] After the blockchain receives the second resource response message uploaded by the first core network device, the blockchain may further include: other nodes on the blockchain verifying the second resource response and, if the verification is successful, triggering a smart contract. The function of the smart contract may be to deduct relevant fees from the second core network device.

[0102] Exemplarily, the processing of verifying the second resource response by other on-chain nodes on the blockchain may include at least one of the following: using the public key of the second core network device and the encrypted first key to verify that the encrypted first key is encrypted using the public key of the second core network device; based on the encrypted first key extracted from the second credential, the ZK extracted from the second resource response, and the second signature, verifying that the second resource authorized by the second credential is provided by the first core network device to the second core network device. For example, using the public key of the second core network device and the encrypted first key to verify that the encrypted first key is encrypted using the public key of the second core network device may be: using the public key of the second core network device to decrypt the encrypted first key, and when the decryption is correct, determining that the encrypted first key is encrypted using the public key of the second core network device. For example, based on the encrypted first key extracted from the second credential, the ZK extracted from the second resource response, and the second signature, verifying that the second resource authorized by the second credential is provided by the first core network device to the second core network device can be: based on the encrypted first key extracted from the second credential, the ZK and other parameters extracted from the second resource response message and the public key of the second core network device, verifying the second signature. If the verification passes, it is determined that the second resource authorized by the second credential is provided by the first core network device to the second core network device.

[0103] After the blockchain (e.g., a node on the blockchain) completes the above processing, a deduction notification is sent to the second core network device. Correspondingly, after receiving the deduction notification, the second core network device can execute the process of downloading the second certificate from the blockchain.

[0104] The issuance process of the above second certificate is described below in conjunction with Example 1. In Example 1, the second certificate is a first-level certificate, the first core network device is represented as core network device B (or core network B), and the second core network device is represented as core network device A (or core network A). The process of Example 1 is summarized as follows: After core network device A and core network device B have negotiated the use rules of spectrum resources, core network device B uses PK A (The public key of core network device A) encrypts the symmetric key between it and core network device A (i.e., the first key in the aforementioned implementation) and uploads it to the blockchain. Core network device A downloads the first-level certificate from the blockchain. It should be noted that the nodes on the blockchain are composed of different operators, and the public keys of the nodes on the chain are public. With the help of the PKI certificate management system, each node (including core network device A and core network device B) trusts each other's public key information. Specific explanation is given in conjunction with Figure 7:

[0105] Step 701: Core network device A sends a resource request (i.e., a second resource request message) to core network device B in the off-chain mode to request a specific spectrum resource. The resource request includes at least one of the following: ID A Indicates the identity of the requester, that is, the core network device A, the relevant data of the spectrum resources applied for by the core network device A (that is, the information requesting the use of the second resource of the first network, which can be simply represented as RS-Att (Resource Attribute)), the first signature Sig[H(ID A ,RS-Att)].

[0106] Exemplarily, step 701 can be represented as: core network device A → core network device B: ID A ,RS-Att,Sig[H(ID A ,RS-Att)].

[0107] Among them, the first signature is to ensure the integrity of the message and enable core network device B to ensure that the message comes from core network device A.

[0108] The specific content or format of the spectrum resource data applied for by core network device A is shown in Table 1 below:

[0109] Table 1

[0110] Specifically, ID B The ID of the core network device B is used to indicate the owner of the spectrum resource; the resource number is the number of the second resource applied for by the core network device A, and the number of the second resource can be simply represented as Nom1. BThe relevant descriptions of , resource number, usage period and price are the same as those in the previous embodiment and will not be repeated here.

[0111] Step 702: After verifying the authenticity of the message sent by core network device A (by verifying the signature and checking the spectrum resource-related data), core network device B responds to the request of core network device A (i.e., the second resource response message), and core network device B uploads the response to the blockchain.

[0112] Among them, the response (Response) is uploaded to the blockchain by core network device B. The response (Response) can be used as the transaction content, so that other nodes on the chain can verify that the response is indeed sent by core network device B to core network device A; on the blockchain, the response can trigger a smart contract to automatically deduct A's fees.

[0113] The response (Response) includes the primary credentials and the signature of the message Sig[H(Response)]. For example, step 702 can be expressed as: core network device B → blockchain (smart contract): Response, Sig[H(Response)].

[0114] For example, the content included in the response is shown in Table 2:

[0115] Table 2

[0116] Specifically, in conjunction with Table 2, the response includes: the identity ID of the requester core network device A A ; Authorization certificate issued for a specific spectrum resource RS-Att (ie, the authorization for the second core network device to use the second resource of the first network in the aforementioned embodiment); Level 1 certificate That is, the first-level certificate includes the public key (PK) of the core network device A used by the core network device B. A ) encrypted key material K for two-way authentication between operator A (i.e. core network device A) and operator B (core network device B) A-B (ie, the first key); zero-knowledge proof data ZK; and the second signature Sig[H(Response)] of the core network device B.

[0117] Among them, the first-level certificate, ZK, and the second signature Sig[H(Response)] of core network device B provide the capability of public verification, ensuring that the blockchain can confirm that the spectrum data is provided by core network device B to core network device A, and that the key material is indeed encrypted using A's public key.

[0118] The smart contract mentioned in this step is a blockchain-based, automated contract execution program that digitally records contract rules and terms. It is highly timely and decentralized, ensuring that contract participants receive their fees promptly and accurately, and adapting to the high-speed demands of the 6G era. Furthermore, smart contracts can set refund conditions, which will automatically execute the refund once the conditions are met.

[0119] Step 703: After core network device A receives the notification of fee deduction (which can be sent to core network device A by the blockchain smart contract), core network device A downloads the first-level certificate from the blockchain.

[0120] Exemplarily, step 703 can be expressed as: core network device A←blockchain (smart contract): download first-level certificate.

[0121] In some possible implementations, the terminal may request the second core network device of the network to which the terminal belongs to issue the first certificate.

[0122] Since the first credential is generated after the second credential is obtained through interactive processing at the core network level of the two networks and is further processed based on the second credential, in some possible examples, the first credential can also be called a secondary credential.

[0123] The processing of the terminal before sending the authentication request may also include: sending a first resource request message to the second core network device, wherein the first resource request message is used to request use of the first resource of the first network. Further, it may also include: receiving a first resource response message from the second core network device, wherein the first resource response message carries the first credential.

[0124] The processing by the second core network device may include: receiving a first resource request message from the terminal, wherein the first resource request message is used to request the use of a first resource of the first network, and further, sending a first resource response message to the terminal.

[0125] Specifically, the first resource request message may carry at least one of the following: an identifier of the terminal, an identifier (or number) of a first resource of the first network requested by the terminal, a third random number, and a second check code.

[0126] Among them, the identifier of the terminal may refer to one of the following: the terminal's SUPI (Subscription Permanent Identifier), the terminal's SUCI (Subscription Concealed Identifier), the terminal's PEI (Permanent Equipment Identifier), the terminal's 5G-GUTI (5G Globally Unique Temporary Identifier), the terminal's Internal-Group Identifier (IGI), the terminal's GPSI (Generic Public Subscription Identifier), etc.

[0127] The first resource may be included in the second resource of the first network requested by the aforementioned second core network device. In other words, the first resource may be part or all of the second resource. For example, the second core network device may request the use of multiple second resources of the first network, namely, resource 0, resource 1, and resource 2 of the first network; the terminal may also request the use of one or more first resources, for example, the first resource may be resource 0 or resource 1 of the first network. It should be understood that this is merely an example and is not intended to be limiting or exhaustive.

[0128] The third random number may be generated by the terminal, and the generation method of the third random number is not limited in this embodiment.

[0129] The second verification code may be calculated based on at least one of the following parameters of a fourth key pair between the terminal and the second core network device: the identifier of the terminal, the number of the first resource, and a third random number.

[0130] The key type of the fourth key may be related to the type of the second core network device. For example, if the second core network device is an AMF, the corresponding fourth key may be Kamf; if the second core network device is an AUSF, the corresponding fourth key may be Kseaf, and so on. This does not limit or exhaustively enumerate all possible types of the fourth key.

[0131] For example, the second verification code can be obtained by hashing the identifier of the terminal, the identifier of the first resource, and the first random number based on the key between the terminal and the second core network device. For example, the calculation of the second verification code can be expressed as: Among them, HMAC represents the hash function, K A-a Indicates the fourth key, ID arepresents the identifier of the terminal, Nom2 is the identifier of the first resource, and N1 is the third random number.

[0132] For example, the second check code can be calculated based on the key between the terminal and the second core network device, the identifier of the terminal, the identifier of the first resource, and the first random number using an integrity protection algorithm. For example, the calculation of the second check code can be expressed as: MAC[K A-a ,ID a ,Nom2,N1], where MAC represents the integrity protection algorithm, K A-a Indicates the fourth key, ID a represents the identifier of the terminal, Nom2 is the identifier of the first resource, and N1 is the third random number.

[0133] When the first resource request message carries a second verification code, after the second core network device receives the first resource request message from the terminal, it can also verify the identity of the terminal and the integrity of the first resource request message based on the second verification code.

[0134] Specifically, the second core network device verifies the identity of the terminal and the integrity of the first resource request message based on the second verification code, which may include: calculating the second verification code based on the fourth key pair, the identification of the terminal, the identification of the first resource, and at least one of the third random numbers; and verifying the identity of the terminal and the integrity of the first resource request message based on the second verification code and the second verification code. Here, the calculation method of the second verification code and the calculation parameters used should be the same as the calculation method and calculation parameters of the second verification code in the aforementioned embodiment, so they are not repeated.

[0135] Among them, based on the second verification code and the second check code, verifying the identity of the terminal and the integrity of the first resource request message may include at least one of the following: when the second verification code and the second check code are consistent, determining that the verification of the identity of the terminal is successful and the integrity verification of the first resource request message is successful; when the second verification code and the second check code are inconsistent, determining that the verification of the identity of the terminal fails and the integrity verification of the first resource request message fails.

[0136] In addition, it may also include: if it is determined that the identity verification of the terminal fails and the integrity verification of the first resource request message fails, the second core network device may also end the processing and / or send a verification failure response message to the terminal.

[0137] Here, the second core network device may determine the fourth key by determining the fourth key between itself and the terminal based on the identifier of the terminal carried in the first resource request message.

[0138] On the second core network device side, the first credential is calculated based on the first key and at least one of the following parameters: a second key between the terminal and the first core network device, and a temporary identifier of the terminal.

[0139] The specific calculation method of the first credential may include: encrypting at least one of the second key between the terminal and the first core network device and the temporary identifier of the terminal based on the first key to obtain the first credential.

[0140] Preferably, the first credential can be obtained by encrypting the second key and the temporary identifier of the terminal using the first key, for example, it can be expressed as: Among them, Ticket a Indicates the first certificate, Enc[] indicates encryption calculation, K A-B Represents the first key, K a-B Indicates the second key, ID va Indicates the temporary identifier of the terminal.

[0141] The second key between the terminal and the first core network device may be generated by the second core network device. This embodiment does not limit the manner in which the second core network device generates the second key. For example, the second key may be calculated based on the identifier of the first core network device and the identifier of the terminal. The algorithm for calculating the second key and the specific parameters used to calculate the second key are not limited or exhaustive.

[0142] The temporary identifier of the terminal is generated by the second core network device. The correspondence between the terminal identifier and the temporary identifier of the terminal is stored on the second core network device side. The specific possible content or value of the temporary identifier of the terminal is not limited in this embodiment. As long as the temporary identifier of the terminal is different from the identifier of the terminal, it is within the protection scope of this embodiment. The temporary identifier of the terminal can be used to hide its true identity from the first core network device.

[0143] In one example, the second core network device may add the first credential to a first resource response message and send it to the terminal.

[0144] In one example, in addition to the first credential, the first resource response message also carries at least one of the following: a second key between the terminal and the first core network device, and a temporary identifier of the terminal.

[0145] Furthermore, the first resource response message may also carry at least one of the following: an identifier of the terminal, an identifier of the first core network device, an identifier of the first resource, and a fourth random number.

[0146] The fourth random number is used to indicate that the first resource response message is not a replay. The fourth random number is related to the third random number. For example, the fourth random number may be equal to the third random number; for example, the fourth random number may be equal to the third random number plus the first specified value; wherein the first specified value may be configured according to actual conditions. In some examples, the first specified value may be equal to 1, that is, the fourth random number is equal to the third random number plus 1. In some other examples, the first specified value may also be greater than 1. All possible values ​​of the first specified value are not limited or enumerated here.

[0147] By carrying the identifier of the first resource in the first resource response message, it can be used to indicate that the terminal is allowed, agreed or supported to use the first resource of the first network.

[0148] Optionally, when generating the first resource response message, the second core network device can directly add the first credential and at least one of the following parameters to the first resource response message: the second key, the temporary identifier of the terminal, the identifier of the terminal, the identifier of the first core network device, the identifier of the first resource, and a fourth random number.

[0149] For example, the content carried by the first resource response message can be expressed as: ID a ,K a-B ,ID va ,ID B ,N1+1,Nom2,Ticket a , where ID a represents the terminal identifier, "N1+1" represents a fourth random number, which is equal to the third random number N1 plus 1. The rest of the content is the same as the description of the previous example and will not be repeated here.

[0150] In this case, the terminal can directly receive and obtain the first credential carried in the first resource response message, and can also obtain at least one of the following carried in the first resource response message: the second key, the temporary identifier of the terminal, the identifier of the terminal, the identifier of the first core network device, the identifier of the first resource, and the fourth random number.

[0151] Optionally, when generating the first resource response message, the second core network device can calculate the first ciphertext information based on the fourth key pair, the first credential and at least one of the following parameters: the second key, the temporary identifier of the terminal, the identifier of the first core network device, the identifier of the first resource, and a fourth random number; and add the identifier of the terminal and the first ciphertext information to the first resource response message.

[0152] For example, the content carried by the first resource response message may be expressed as: in, It indicates that the fourth key is used for encryption calculation. The rest of the content is the same as the description of the previous example and will not be repeated here.

[0153] In this case, after receiving the first resource response message, the terminal can directly obtain the terminal identification, and decrypt the first ciphertext information in the first resource response message based on the fourth key to obtain the first credential and at least one of the following parameters: the second key, the temporary identification of the terminal, the identification of the first core network device, the identification of the first resource, and the fourth random number.

[0154] For example, if the first ciphertext information is obtained by encrypting the first credential, the second key, the temporary identifier of the terminal, the identifier of the first core network device, the identifier of the first resource, and the fourth random number, and the first resource response message also carries the identifier of the terminal, then the processing after the terminal receives the first resource response message may also include: based on the identifier of the terminal, it can be determined that the first resource response message is sent to itself; based on the fourth key, the first ciphertext information is decrypted to obtain the first credential, the second key, the temporary identifier of the terminal, the identifier of the first core network device, the identifier of the first resource, and the fourth random number.

[0155] By using the first ciphertext information transmission parameter in the first resource response message, the confidentiality of the message can be guaranteed, and the terminal can verify that the message does come from the second core network device by decrypting the first ciphertext information, and at the same time believe that the message has not been tampered with.

[0156] Optionally, when generating the first resource response message, the second core network device can calculate a fourth verification code based on the fourth key pair, the first credential and at least one of the following parameters: the second key, the temporary identifier of the terminal, the identifier of the first core network device, the identifier of the first resource, and a fourth random number; and add the identifier of the terminal and the third verification code to the first resource response message.

[0157] In this case, after the terminal receives the first resource response message, it can calculate the fourth verification code based on the fourth key pair, the first credential and at least one of the following parameters: the second key, the temporary identifier of the terminal, the identifier of the first core network device, the identifier of the first resource, and a fourth random number; when the fourth verification code and the fourth check code are consistent, it is determined that the first resource response message is credible (i.e., it has not been tampered with).

[0158] The terminal receives the first resource response message and can obtain the first credential, which can be used for the terminal to access the network where the first core network device is located.

[0159] Optionally, the terminal may also obtain its own temporary identifier through the first resource response message, so as to hide its true identity when accessing the network where the first core network device is located.

[0160] Optionally, the terminal may also obtain the second key through the first resource response message, so that the terminal can use the key when accessing the network where the first core network device is located.

[0161] Optionally, the terminal may further obtain a fourth random number through the first resource response message, and determine that the first resource response message is not a replay by comparing the fourth random number with the third random number.

[0162] The issuance process of the above first certificate is described below in conjunction with Example 2. In Example 2, the first certificate is a secondary certificate, the terminal is simply represented as UE-a, the first core network device is represented as core network device B (or core network B), and the second core network device is represented as core network device A (or core network A). The process of Example 2 is summarized as follows: Core network device A issues a secondary certificate to its UE-a (user a), and the secondary certificate is issued via K A-B Encryption, since only core network device A and core network device B know K A-B Therefore, when UE-a subsequently uses the secondary certificate to access the network where the core network device B is located, the core network device B can trust the validity of the secondary certificate. After decrypting the secondary certificate, the core network device B obtains the session symmetric key K between itself and UE-a. a-B .

[0163] The character definitions involved in Example 2 are shown in Table 3:

[0164] Table 3

[0165] The issuance process of the secondary certificate involved in Example 2 is exemplarily described with reference to FIG8 :

[0166] Step 801: UE-a in the jurisdiction of operator A sends a first resource request message to core network device A to indicate.

[0167] The first resource request message may include: the spectrum resource Nom2 required by UE-a (i.e., the identifier of the first resource), N1 indicating the freshness of the session, and the identity ID of the applicant UE-a. a The core network device A can know to use the corresponding key material to authenticate UE-a and use the key material K for the above message. A-a (The key between core network device A and UE-a) is hashed to obtain the first message authentication code (i.e., the second check code in the aforementioned embodiment) HMAC, which enables core network device A to verify the identity of the message sender and the integrity of the message (the received message is hashed once using the key material unique to the two and then compared with the received HMAC1).

[0168] Exemplarily, step 801 may be represented as: UE-a → core network device A:

[0169] Step 802: After verifying the reliability of the received first resource request message, the core network device A sends a first resource response message to UE-a.

[0170] The first resource response message may carry: ID a Indicates that core network device A has received UE-a's request, K a-B It is the key material (i.e., the second key) distributed by core network device A (the network) to UE-a and core network device B, ID va It is the temporary identity (or temporary identification) of UE-a (hiding its true identity from the network where the core network device B is located), N1+1 indicates that the message is not a replay, Nom2 refers to the spectrum resource corresponding to the secondary certificate, and Ticket a It is the secondary certificate that UE-a can successfully access the network where the core network device B is located. The above parameters (K a-B ,ID va ,ID B ,N1+1,Nom,Ticket a ) is sent through the secure channel between core network device A and UE-a, that is, it is encrypted using the key material between core network device A and UE-a. This not only ensures the confidentiality of the message but also enables UE-a to verify that the message does come from core network device A, and at the same time believe that the message has not been tampered with.

[0171] Optionally, the core network device A can also (K a-B ,ID va ,ID B ,N1+1,Nom,Ticket a ) calculates the message verification code and sends it to UE-a; accordingly, UE-a also verifies the message verification code to verify whether the first resource response message has been tampered with.

[0172] It should be noted that the terminal ID will be saved on the core network device A side a Temporary identification ID of the terminal va The corresponding relationship between them.

[0173] Among them, the secondary certificate Specifically, the secondary certificate Ticket a It is a string of ciphertext that only core network device A and core network device B can decrypt, so core network device B can verify that it holds the ticket. a The UE is a UE under operator A (that is, the network where core network device A is located).

[0174] Exemplarily, step 802 may be represented as: core network device A → UE-a:

[0175] In some possible implementations, when the terminal accesses a roaming network (ie, the first network), the first network device of the roaming network needs to perform relevant authentication processing.

[0176] The terminal may send an authentication request to the first network device after receiving the first resource response message carrying the first credential.

[0177] In addition to the first credential, the authentication request also carries a first verification code for verifying the identity of the terminal, where the first verification code is calculated based on a second key between the terminal and the first core network device and the first credential.

[0178] Optionally, the first check code can be obtained by performing integrity protection calculation based on the second key and the first credential. For example, the process of calculating the first check code can be expressed as MAC[K a-B ,Ticket a ].

[0179] Optionally, the first verification code may be obtained by performing a hash calculation on the first credential based on the second key. For example, the process of calculating the first verification code may be expressed as:

[0180] Furthermore, the authentication request also carries at least one of the following: an identifier of a first resource of the first core network device requested to be used, a temporary identifier of the terminal, an identifier of the first network device, and a first random number, wherein the first random number is generated by the terminal.

[0181] The above-mentioned embodiment has explained that the first network device can be an access network device or a first core network device. Therefore, the identifier of the first network device carried in the above-mentioned authentication request can vary according to the actual situation. When the terminal sends an authentication request to the access network device, the identifier of the above-mentioned first network device is the identifier of the access network device; when the terminal sends an authentication request to the access network device, the identifier of the above-mentioned first network device is the identifier of the first core network device.

[0182] Correspondingly, the first verification code is calculated based on the second key, the first credential and at least one of the following parameters: an identifier of the first resource of the first network requested for use, a temporary identifier of the terminal, an identifier of the access network device, and a first random number.

[0183] The parameters used to calculate the first verification code may be at least partially the same as the content or parameters carried in the authentication request. For example, the authentication request carries the first credential, the identifier of the first resource, the temporary identifier of the terminal, the identifier of the first network device, and the first random number, but the first verification code may be calculated using the first credential, the temporary identifier of the terminal, and the first random number; for another example, the authentication request carries the first credential, the identifier of the first resource, the temporary identifier of the terminal, the identifier of the first network device, and the first random number, and the first verification code may also be calculated using the first credential, the identifier of the first resource, the temporary identifier of the terminal, the identifier of the access network device, and the first random number.

[0184] For example, the first verification code is calculated based on the second key, the first credential, the identifier of the first resource, the temporary identifier of the terminal, the identifier of the first network device, and the first random number. For example, the process of calculating the first verification code can be expressed as MAC[K a-B ,ID va ,ID b ,N2,Nom2,Ticket a ], where N2 represents the first random number, ID b It can be the identifier of the access network device (when the authentication request is sent to the access network device), or it can be the identifier of the first core network device (when the authentication request is sent to the first core network device). The meaning of the rest of the content in the formula is the same as that of the previous embodiment and will not be repeated.

[0185] For example, the first verification code can be calculated by hashing the first credential, the identifier of the first resource, the temporary identifier of the terminal, the identifier of the first network device, and the first random number based on the second key. For example, the process of calculating the first verification code can be expressed as The meanings of the contents in the formula are the same as those in the above embodiment and are not described in detail.

[0186] In some possible implementations, the first network device is an access network device of the first network. That is, the authentication request is sent to the access network device. It should be noted that in this implementation, the identifier of the first network device involved in the aforementioned embodiment may specifically be the identifier of the access network device, and this description is not repeated below.

[0187] After the access network device receives the authentication request, it is unable to determine whether the parameters or content contained in the authentication request are correct. Therefore, it is necessary to send the content or parameters in the authentication request to the first core network device for verification. The processing after the access network device receives the authentication request may also include: sending an authentication request to the first core network device, wherein the authentication request carries the first credential. The processing after the first core network device receives the authentication request may also include: decrypting the first credential based on the first key to obtain a decryption result; and authenticating the terminal based on the decryption result.

[0188] Specifically, authenticating the terminal based on the decryption result may include: if the decryption result is correct, determining that the terminal is successfully authenticated; if the decryption result is incorrect, determining that the terminal is failed to be authenticated.

[0189] Here, the process of determining whether the decryption result is correct may include at least one of the following: if the decryption result does not contain garbled characters and the format of the decryption result is correct, determining that the decryption result is correct; if the decryption result contains garbled characters and / or the format of the decryption result is incorrect, determining that the decryption result is incorrect. In addition, if the decryption result is incorrect, the first core network device may terminate the process and / or return a response message indicating that the terminal authentication failed to the access network device.

[0190] Furthermore, if the decryption result is correct, the first core network device may save the content or parameters contained in the decryption result. Specifically, the decryption result includes at least one of the following: a second key between the terminal and the first core network device, and a temporary identifier of the terminal.

[0191] Optionally, after the first core network device obtains the decryption result, the method further includes: sending an authentication response to the access network device, wherein the authentication response carries a first verification code, and the first verification code is calculated based on the second key between the terminal and the first core network device and the first credential.

[0192] Here, the calculation method of the first verification code should be the same as the calculation method of the first verification code in the above embodiment, so it will not be repeated.

[0193] Optionally, in addition to carrying the first credential, the authentication request also carries at least one of the following: an identifier of the first resource of the first core network device requested to be used, a temporary identifier of the terminal, an identifier of the access network device, and a first random number.

[0194] In this case, the first verification code is calculated based on the second key, the first credential, and at least one of the following parameters: the identifier of the first resource, the temporary identifier of the terminal, the identifier of the access network device, and the first random number. The calculation method and parameters of the first verification code should also be the same as the calculation method and parameters used for the first verification code in the aforementioned embodiment, and therefore are not further described.

[0195] Optionally, the authentication request sent by the access network device may also carry a third verification code, which is calculated based on the fifth key between the access network device and the first core network device and at least one of the following parameters: the first credential, the identifier of the first resource, the temporary identifier of the terminal, the identifier of the access network device, and the first random number.

[0196] The fifth key between the access network device and the first core network device may be a shared key between the access network device and the first core network device. This embodiment does not limit the possible type of the fifth key.

[0197] The parameters carried in the authentication request may be the same as the parameters carried in the authentication request sent by the terminal to the access network device. For example, the authentication request carries the first credential, the identifier of the first resource, the temporary identifier of the terminal, the identifier of the access network device, and the first random number. The authentication request may also carry the first credential, the identifier of the first resource, the temporary identifier of the terminal, the identifier of the access network device, and the first random number.

[0198] The parameters used to calculate the third check code may be at least partially the same as the parameters carried in the authentication request. For example, if the contract signing request carries the first credential, the identifier of the first resource, the temporary identifier of the terminal, the identifier of the access network device, and the first random number, the third check code may be calculated using only the first credential, the temporary identifier of the terminal, the identifier of the access network device, and the first random number; for another example, if the contract signing request carries the first credential, the identifier of the first resource, the temporary identifier of the terminal, the identifier of the access network device, and the first random number, the same parameters may be used to calculate the third check code.

[0199] For example, the third check code is calculated based on the fifth key, the first credential, the identifier of the first resource, the temporary identifier of the terminal, the identifier of the access network device, and the first random number. For example, the process of calculating the third check code can be expressed as MAC[K b-B ,ID va ,ID b ,N2,Nom2,Ticket a ], where K b-Brepresents the fifth key between the access network device and the first core network device, N2 represents the first random number, and the meaning of the remaining contents in the formula is the same as that in the previous embodiment and will not be repeated.

[0200] For example, the third verification code can be calculated by hashing the first credential, the identifier of the first resource, the temporary identifier of the terminal, the identifier of the access network device, and the first random number based on the fifth key. For example, the process of calculating the third verification code can be expressed as The meanings of the contents in the formula are the same as those in the above embodiment and are not described in detail.

[0201] Correspondingly, the first core network device may also verify the message integrity of the authentication request based on the third verification code.

[0202] The way in which the first core network device verifies the message integrity of the authentication request based on the third verification code may include: calculating the third verification code based on the fifth key and at least one of the following parameters: the first credential, the identifier of the first resource, the temporary identifier of the terminal, the identifier of the access network device, and the first random number; and verifying the message integrity of the authentication request based on the third verification code and the third verification code.

[0203] Among them, the calculation method and parameters used by the first core network device to calculate the third verification code should be the same as the calculation method and parameters used by the access network device to calculate the third verification code, and no repeated explanation is given.

[0204] Based on the third verification code and the third check code, verifying the message integrity of the authentication request may include at least one of the following: when the third verification code and the third check code are consistent, determining that the message integrity verification of the authentication request passes; when the third verification code and the third check code are consistent, determining that the message integrity verification of the authentication request fails.

[0205] In addition, it may also include: if the message integrity verification of the authentication request fails, the first core network device may end the processing and / or send a response message of message integrity verification failure to the access network device.

[0206] This embodiment does not limit the order in which the first core network device verifies the message integrity of the authentication request based on the third verification code and authenticates the terminal based on the decryption result. For example, the first core network device may first authenticate the terminal based on the decryption result, and upon determining that the terminal authentication has passed, verify the message integrity of the authentication request based on the third verification code; and upon verifying that the message integrity of the authentication request has passed, perform the subsequent processing of generating the first verification code. For another example, the first core network device may first verify the message integrity of the authentication request based on the third verification code; upon verifying that the message integrity of the authentication request has passed, authenticate the terminal based on the decryption result, and upon determining that the terminal authentication has passed, perform the subsequent processing of generating the first verification code.

[0207] In one embodiment, the authentication response carries a first verification code. After the access network device sends the authentication request, the method further includes: receiving an authentication response from the first core network device, wherein the authentication response carries a first verification code; and verifying the identity of the terminal based on the first verification code and the first check code.

[0208] Verifying the identity of the terminal based on the verification code and the first check code may mean: when the first verification code and the first check code are consistent, determining that the identity authentication of the terminal is successful; when the first verification code and the first check code are inconsistent, determining that the identity authentication of the terminal has failed.

[0209] Furthermore, it may also include: in the event that the terminal identity verification fails, the access network device may terminate the processing and / or send a response message of identity authentication failure to the terminal (for example, the access network device may send an authentication response to the terminal, and the authentication result carried by the authentication response is authentication failure).

[0210] Optionally, the authentication response further carries a third key used for communication between the terminal and the access network device. The generation method of the third key is not limited in this embodiment.

[0211] Specifically, the authentication response may carry second ciphertext information, which is calculated based on the fifth key pair, the third key and the third ciphertext information, and the third ciphertext information is calculated based on the second key pair between the terminal and the first core network device.

[0212] The third ciphertext information is calculated based on the second key between the terminal and the first core network device and the third key and the second random number. The second random number may be related to the first random number, for example, the second random number may be the same as the first random number, or the second random number may be equal to the first random number plus a second specified value. The second specified value may be configured according to actual conditions, for example, it may be 1 or another value. The second specified value is not limited or exhaustive herein.

[0213] In one embodiment, when the access network device receives an authentication response that carries a third key, the processing of the access network device may further include: sending an authentication response to the terminal, wherein the authentication response carries the third key. Correspondingly, the processing of the terminal may include: receiving an authentication response from the access network device, wherein the authentication response carries the third key used for communication between the terminal and the access network device.

[0214] Here, the authentication response may also be used to indicate an authentication result of the terminal, which may be authentication success or authentication pass.

[0215] The authentication response may be generated by the access network device decrypting the second ciphertext carried in the authentication response using the fifth key to obtain the third key and third ciphertext information, and then adding the third ciphertext information to the authentication response. In this way, the access network device locally stores the third key, thereby ensuring that the access network device can obtain the same third key as the terminal.

[0216] Correspondingly, the processing after the terminal receives the authentication response may include: extracting third ciphertext information from the authentication response, decrypting the third ciphertext information based on the second key between the terminal and the first core network device, and obtaining the third key.

[0217] Furthermore, in a case where the third ciphertext information also includes a second random number, the terminal may also decrypt to obtain the second random number, and the terminal may verify that the authentication response is not a replayed message based on the second random number.

[0218] After the terminal completes the above processing, the terminal can use the third key to perform subsequent communications with the access network device.

[0219] The following describes the above process of using the first credential in conjunction with Example 3. In Example 3, the first credential is a secondary credential, the terminal is represented as UE-a, the first core network device is represented as core network device B, the access network device is represented as base station b, and the second core network device is represented as core network device A.

[0220] The character definitions involved in Example 3 are shown in Table 4:

[0221] Table 4

[0222] The process of using the secondary credentials provided in Example 3 is exemplarily described with reference to FIG9 :

[0223] Step 901: UE-a sends an authentication request to base station b under core network device B to request the use of spectrum resources (ie, the first resource in the aforementioned embodiment).

[0224] Exemplarily, step 901 may be expressed as:

[0225] UE-a→base station b:

[0226] Specifically, the authentication request may carry: Nom2 indicating the identifier (or number) of the first resource of the network where the core network device B is located that UE-a requests to use, Ticket a Secondary credentials, the first random number N2 indicates the freshness of the message, ID va It is the temporary identity of the requester, UE-a, ID b Indicates the identity of the base station to be accessed, and the above message is hashed using the key material between UE-a and core network device B to obtain the message authentication code (i.e. the first check code in the aforementioned embodiment) HMAC. HMAC enables core network device B to authenticate that the source of the message is ID va and that the message has not been tampered with.

[0227] Step 902: After receiving the authentication request from UE-a, base station b initiates an authentication request to core network device B because it cannot verify the reliability of the request.

[0228] Specifically, base station b uses the key material K between itself and core network device B to obtain the parameters contained in the received authentication request. b-B After hashing to obtain the message authentication code (HMAC) (i.e., the third check code in the aforementioned embodiment), the parameters contained in the authentication request and the HMAC are added to the authentication request and sent to core network device B. The HMAC enables core network device B to verify that the authentication request indeed comes from base station b and that the message has not been tampered with (core network device B uses the key material between itself and base station b to hash the received message and compare the received HMAC).

[0229] Exemplarily, step 902 may be represented as: base station b → core network device B:

[0230] Step 903: After verifying the reliability of the authentication request sent by base station b, core network device B sends an authentication response to base station b.

[0231] To ensure the confidentiality of the authentication response, the authentication response is sent through the secure channel between the core network device B and the base station b, that is, using the key material K b-B The parameters in the authentication response to be sent are encrypted and sent. The parameters in the authentication response include: the session key K distributed between UE-a and base station b for communication a-b , encrypted session key And the first verification code

[0232] Exemplarily, step 903 may be represented as: core network device B → base station b:

[0233] Step 904: After base station b verifies the authenticity of the received authentication response (the source is core network device B and the message has not been tampered with), it compares the HMAC received from UE-a with the HMAC received from core network device B. If they are the same, it indicates that UE-a is a legitimate UE-a (or the identity of UE-a is legitimate). Base station b sends an authentication response to UE-a, which The message is forwarded to UE-a, which decrypts it using the key material between itself and the core network to obtain the session key for base station b. The decrypted N2+1 indicates that the message was not a replay. UE-a can now use the received session key to access base station b and successfully utilize spectrum resources.

[0234] Exemplarily, step 904 may be represented as: base station b → UE-a:

[0235] In some possible implementations, the first network device is a first core network device of the first network. That is, the authentication request is sent to the first core network device. It should be noted that in this implementation, the identifier of the first network device involved in the aforementioned embodiment may specifically be the identifier of the first core network device, and this description is not repeated below.

[0236] The processing after the first core network device receives the authentication request may further include: decrypting the first credential based on the first key to obtain a decryption result; and authenticating the terminal based on the decryption result.

[0237] Specifically, authenticating the terminal based on the decryption result may include: determining that the terminal authentication is successful if the decryption result is correct; and determining that the terminal authentication is unsuccessful if the decryption result is incorrect. The process of determining whether the decryption result is correct is the same as in the previous embodiment and is not further described.

[0238] Furthermore, if the decryption result is correct, the first core network device may save the content or parameters contained in the decryption result. Specifically, the decryption result includes at least one of the following: a second key between the terminal and the first core network device, and a temporary identifier of the terminal.

[0239] Optionally, the authentication request further carries a first verification code for verifying the identity of the terminal.

[0240] After the first core network device obtains the decryption result, the method further includes: verifying the identity of the terminal based on a first verification code and the first check code, wherein the first verification code is calculated based on the second key between the terminal and the first core network device and the first credential.

[0241] Optionally, the authentication request also carries at least one of the following: an identifier of the first resource of the first core network device requested to be used, a temporary identifier of the terminal, an identifier of the first core network device, and a first random number.

[0242] In this case, the first verification code is calculated based on the second key, the first credential and at least one of the following parameters: the identifier of the first resource, the temporary identifier of the terminal, the identifier of the first core network device, and the first random number.

[0243] Here, the calculation method of the first verification code should be the same as the calculation method of the first verification code in the above embodiment, so it will not be repeated.

[0244] It should be noted that verifying the identity of the terminal based on the first verification code and the first check code may include: when the first verification code and the first check code are consistent, the identity of the terminal is successfully verified (or the verification is passed). In addition, it may also include: when the first verification code and the first check code are inconsistent, the identity of the terminal fails to be verified, and the first core network device may end processing and / or send a failure response message to the terminal.

[0245] After the first core network device completes the above authentication and the authentication is successful, the method further includes at least one of the following: sending an authentication response to the terminal, wherein the authentication response carries a third key used for communication between the terminal and the access network device of the first network; and sending the third key to the access network device. The authentication response also carries a third key used for communication between the terminal and the access network device. The method for generating the third key is not limited in this embodiment.

[0246] Optionally, the authentication response may carry third ciphertext information, where the third key information is calculated based on the third key between the terminal and the first core network device. Furthermore, the third key sent by the first core network device to the access network device may be encrypted using a fifth key between the access network device and the first core network device and then sent, but this embodiment does not impose any limitations thereon.

[0247] Accordingly, the processing of the terminal may include: receiving an authentication response from the first core network device, wherein the authentication response carries a third key for communication between the terminal and the access network device of the first network. The processing of the access network device may include receiving the third key from the first core network device.

[0248] Optionally, the processing after the terminal receives the authentication response may include: extracting third ciphertext information from the authentication response, decrypting the third ciphertext information based on the second key between the terminal and the first core network device, and obtaining the third key.

[0249] Optionally, when the third ciphertext information also includes a second random number, the terminal may further decrypt to obtain the second random number, and the terminal may verify that the authentication response is not a replay message based on the second random number.

[0250] After the terminal completes the above processing, the terminal can use the third key to perform subsequent communications with the access network device in the first network.

[0251] In some possible implementations, if the terminal fails to access the first network, the terminal may further send information of access failure or registration failure to the second core network device.

[0252] Optionally, after receiving the authentication request, the first core network device may further include: sending an authentication response to the access network device when it is determined based on the local policy that the terminal is denied access to the network, where the authentication response is used to indicate that service to the terminal is denied.

[0253] Optionally, after receiving the authentication request from the terminal, the first core network device may further include: sending an authentication response to the terminal when it is determined based on a local policy that the terminal is denied access to the network, where the authentication response is used to indicate a denial of service to the terminal.

[0254] The local policy on the first core network device side can be configured according to actual conditions. For example, when giving priority to serving the network or local users, the terminal service can be rejected.

[0255] The authentication response indicating the denial of service for the terminal may carry denial-of-service indication information and a denial-of-service credential. The denial-of-service credential may be a third signature, calculated based on the private key of the first core network device against the denial-of-service indication information and at least one of the following parameters: the first credential, the identifier of the first resource, the temporary identifier of the terminal, the identifier of the access network device, and a first random number. The algorithm for this third signature is similar to that of the first or second signature in the aforementioned embodiments and is not described again.

[0256] Optionally, the authentication response indicating refusal to serve the terminal may also carry at least one of the following: the first credential, the identifier of the first resource, the temporary identifier of the terminal, the identifier of the access network device, and a first random number.

[0257] After receiving the authentication response indicating that the service to the terminal is rejected, the access network device sends an authentication response indicating that the service to the terminal is rejected to the terminal. The authentication response indicating that the service to the terminal is rejected carries the same content as the authentication response indicating that the service to the terminal is rejected.

[0258] The following describes the process of the first core network device denying service in conjunction with Example 4. In Example 4, the terminal is represented as UE-a, the first core network device is represented as core network device B, the access network device is represented as base station b, and the second core network device is represented as core network device A. Specifically, as shown in Figure 10, it includes:

[0259] Steps 1001 to 1002 are the same as steps 901 to 902 and are not described in detail.

[0260] Step 1003: The core network device B strategically denies service (such as giving priority to local users). At this time, the core network device B will send an authentication response to the base station b, which carries the indication information of the denial of service and the denial of service certificate.

[0261] Exemplarily, step 1003 may be represented as: core network device B → base station b:

[0262] False,M1,SigB[False,M1]. False indicates a denial of service indication, M1 includes the secondary credential, the identifier of the first resource, the temporary identifier of UE-a, the identifier of base station b, and the first random number N2, and SigB is the denial of service credential (specifically, the third signature).

[0263] Step 1004: Base station b sends an authentication response to UE-a, which carries the same content as the authentication response in step 1003.

[0264] That is, the core network device B sends a signal to UE-a (IDva ) returns a denial of service credential that signs the secondary credential for a specific resource.

[0265] In some embodiments, after the terminal receives the authentication response from the access network device indicating that service to the terminal is refused, the method may further include: sending a refusal of service certificate to the second core network device.

[0266] Optionally, the terminal sends a denial of service credential to the second core network device, which may mean that the terminal sends all the contents contained in the authentication response to the second core network device; or, it may mean that the terminal sends the denial of service credential and at least one of the following parameters to the second core network device: the first credential, the identifier of the first resource, the temporary identifier of the terminal, the identifier of the access network device, and the first random number.

[0267] After receiving the denial of service certificate, the second core network device can also verify the denial of service certificate. For example, the denial of service certificate specifically includes a third signature. The second core network device can perform verification based on the public key of the first core network device, the third signature, and at least one of the following parameters: the first certificate, the identifier of the first resource, the temporary identifier of the terminal, the identifier of the access network device, and the first random number. The specific processing of verifying the third signature is similar to the aforementioned verification of the first signature or the verification of the second signature, and will not be repeated here.

[0268] The processing by the second core network device may further include: uploading all received denial-of-service credentials to the blockchain when the second credential expires. Accordingly, after receiving all denial-of-service credentials from the second core network device, the node (other node) on the blockchain deducts the corresponding fee from the first core network device if all denial-of-service credentials are verified to be successful.

[0269] The expiration date of the second certificate may be the same as the usage period of the second resource of the first network requested by the second core network device.

[0270] Uploading all received denial of service credentials to the blockchain may refer to uploading all received denial of service credentials and parameters related to each denial of service credential to the blockchain. The parameters related to each denial of service credential may include the first credential, an identifier of a first resource related to each denial of service credential, a temporary identifier of a terminal related to each denial of service credential, an identifier of an access network device related to each denial of service credential, and a first random number related to each denial of service credential.

[0271] The node on the blockchain verifies that any one of the denial of service credentials is successful, which may mean that the denial of service credentials are determined when the third signature is successfully verified using the public key of the first core network device and the identifier of the first resource is included in the identifier of the second resource paid (or purchased) by the second core network device.

[0272] The following describes the processing of claims for the second core network device in conjunction with Example 5. In Example 5, the terminal is represented as UE-a, the first core network device is represented as core network device B, the access network device is represented as base station b, and the second core network device is represented as core network device A. Specifically, as shown in Figure 11, it includes:

[0273] Step 1101: After UE-a receives the denial of service certificate from core network device B, it hands the denial of service certificate to its core network device A; when the first-level certificate expires, core network device A will collect the denial of service certificates signed by core network device B, and after self-verification, it will upload the denial of service certificate to the chain for verification by other nodes on the blockchain (using B's public key to verify that the signature is indeed from core network B, and Nom is consistent with the resource number at the time of purchase).

[0274] In Figure 11, multiple UEs (UE-a, UE-b to UE-n, where n is a positive integer greater than 1) are shown. After receiving the denial of service certificate, each UE will perform the same processing as UE-a, which will not be repeated.

[0275] Step 1102: After the on-chain node of the blockchain verifies the denial of service certificate, it triggers the smart contract to automatically deduct the corresponding proportion of fees from the core network device B.

[0276] Finally, in conjunction with Example 6, the aforementioned communication method is exemplified by taking the terminal as a user, the first core network device as core network B, the access network device as base station b, and the second core network device as core network A as an example. In the symmetric key scheme provided in this embodiment, a symmetric key is used for identity authentication between the user and core network B, but operators A and B pre-store each other's public keys. Specifically, as shown in Figure 12, it includes:

[0277] Step 1201: Core network A applies for resources (such as spectrum resources) from core network B in the downlink.

[0278] Step 1202: Core network B uses the public key of core network A to encrypt the first-level certificate using a verifiable encryption algorithm. The first-level certificate proves that there is a spectrum sharing billing contract between operator A and operator B. Core network B puts the first-level certificate on the chain, triggering the generation of a smart contract, thereby supporting automatic deductions from operator A after subsequent users incur expenses for using the spectrum of operator B.

[0279] Step 1203: After receiving the notification that the contract is uploaded to the chain, core network A downloads the first-level certificate from the chain.

[0280] Step 1204: When users in the jurisdiction of core network A have a demand for resources of core network B (such as spectrum resources), they apply to core network A for the use of resources of core network B (spectrum resources).

[0281] Step 1205: Core network A may use the primary certificate to issue a secondary certificate to the user, and authorize spectrum resources to users in the jurisdiction through the secondary certificate.

[0282] Step 1206: After user a obtains the secondary certificate, he can use the secondary certificate to access base station b under core network B (i.e., send an authentication request).

[0283] Step 1207: Base station b sends an authentication request to core network B.

[0284] Step 1208: Core network B returns the verification result (ie, authentication result) to base station b.

[0285] Step 1209: Base station b feeds back the authentication result to the user, completing the two-way authentication and obtaining the session key.

[0286] By adopting the above solution, when a terminal belonging to the second network accesses the first network, it sends an authentication request carrying a first credential to the network device of the first network. Because the first credential is calculated based on the key between the first core network device of the first network and the second core network device of the second network, the terminal can be authenticated on the first network side using the first credential. In this way, when the terminal needs to access other networks, it can be authenticated only using the first credential. This ensures security while improving authentication efficiency, avoiding the problems of low efficiency caused by the need to perform multiple security parameter calculations to achieve authentication in related technologies.

[0287] Furthermore, in the above scheme, since the two core network devices will pre-process resource requests and the issuance of the second certificate, this allows networks managed by multiple operators to securely share their respective idle authorized spectrum. In addition, in the above scheme, since terminals belonging to the network where the second core network device is located will use temporary identifiers to generate relevant information when accessing the first network, user privacy can also be protected. Furthermore, the high timeliness and decentralized nature of smart contracts can be utilized to support terminals in the network where the second core network device is located to use the spectrum resources of the first network without leaking the terminal's own location, consumption records, etc.

[0288] Furthermore, by uploading the second credential and the relevant information about the resources requested by the second core network device to the blockchain, a smart contract on the blockchain can be triggered, thereby implementing billing in a full-lease model and achieving efficient charging. Furthermore, the above solution can also meet the needs of efficient spectrum sharing in the 6G era.

[0289] FIG13 is a schematic diagram of the structure of a terminal according to an embodiment of the present application, including:

[0290] The first communication unit 1301 is used to send an authentication request to a first network device of a first network, wherein the authentication request carries a first credential for authenticating the terminal, the first credential is calculated based on a first key between a first core network device of the first network and a second core network device of the second network, and the terminal belongs to the second network.

[0291] The authentication request also carries a first verification code for verifying the identity of the terminal, where the first verification code is calculated based on a second key between the terminal and the first core network device and the first credential.

[0292] The first verification code is calculated based on the second key, the first credential and at least one of the following parameters: an identifier of the first resource of the first network requested to be used, a temporary identifier of the terminal, an identifier of the first network device, and a first random number.

[0293] The authentication request further carries at least one of the following: an identifier of the first resource of the first network requested to be used, a temporary identifier of the terminal, an identifier of the first network device, and a first random number.

[0294] The first communication unit is configured to receive an authentication response from the first network device, wherein the authentication response carries a third key used for communication between the terminal and the access network device of the first network.

[0295] The first communication unit is used to receive a first resource response message from the second core network device, wherein the first resource response message carries the first credential.

[0296] The first resource response message also carries at least one of the following: a second key between the terminal and the first core network device, and a temporary identifier of the terminal.

[0297] The first communication unit is used to send a first resource request message to the second core network device, wherein the first resource request message is used to request the use of a first resource of the first network.

[0298] The first network device includes one of the following: an access network device and the first core network device.

[0299] FIG14 is a schematic diagram of the structure of an access network device according to an embodiment of the present application, including:

[0300] The second communication unit 1401 is used to receive an authentication request from a terminal, wherein the authentication request carries a first credential for authenticating the terminal, the first credential is calculated based on a first key between a first core network device of a first network and a second core network device of a second network, the terminal belongs to the second network, and the access network device belongs to the first network.

[0301] The authentication request also carries a first verification code for verifying the identity of the terminal.

[0302] The authentication request also carries at least one of the following: an identifier of the first resource of the first network requested to be used, a temporary identifier of the terminal, an identifier of the access network device, and a first random number.

[0303] The second communication unit is configured to send an authentication request to the first core network device, wherein the authentication request carries the first credential.

[0304] The authentication request also carries at least one of the following: an identifier of the first resource, a temporary identifier of the terminal, an identifier of the access network device, and the first random number.

[0305] As shown in FIG14 , the access network device further includes:

[0306] A second processing unit 1402 is configured to verify the identity of the terminal based on the first verification code and the first check code;

[0307] The second communication unit is configured to receive an authentication response from the first core network device, wherein the authentication response carries a first verification code.

[0308] The authentication response also carries a third key used for communication between the terminal and the access network device.

[0309] The second communication unit is configured to send an authentication response to the terminal, wherein the authentication response carries the third key.

[0310] FIG15 is a schematic diagram of the composition structure of a first core network device according to an embodiment of the present application, including:

[0311] The third communication unit 1501 is used to receive an authentication request from an access network device, wherein the authentication request carries a first credential for authenticating the terminal, the first credential is calculated based on a first key between the first core network device of the first network and the second core network device of the second network, the terminal belongs to the second network, and the access network device belongs to the first network.

[0312] As shown in FIG15 , the first core network device further includes:

[0313] The third processing unit 1502 is configured to decrypt the first credential based on the first key to obtain a decryption result; and authenticate the terminal based on the decryption result.

[0314] The decryption result includes at least one of the following: a second key between the terminal and the first core network device, and a temporary identifier of the terminal.

[0315] The third communication unit is used to send an authentication response to the access network device, wherein the authentication response carries a first verification code, and the first verification code is calculated based on the second key between the terminal and the first core network device and the first credential.

[0316] The authentication request also carries at least one of the following: an identifier of the first resource of the first core network device requested to be used, a temporary identifier of the terminal, an identifier of the access network device, and a first random number.

[0317] The first verification code is calculated based on the second key, the first credential and at least one of the following parameters: an identifier of the first resource, a temporary identifier of the terminal, an identifier of the access network device, and the first random number.

[0318] The authentication response also carries a third key used for communication between the terminal and the access network device.

[0319] The third communication unit is used to receive a second resource request message from the second core network device, wherein the second resource request message is used to request the use of the second resource of the first network; upload a second resource response message to the blockchain, wherein the second resource response message is used to indicate that the second core network device is allowed to use the second resource of the first network, and the second resource response message carries a second credential, and the second credential includes the first key encrypted based on the public key of the second core network device.

[0320] FIG16 is a schematic diagram of the composition structure of a second core network device according to an embodiment of the present application, including:

[0321] The fourth communication unit 1601 is used to send a first resource response message to the terminal, wherein the first resource response message carries a first credential for authenticating the terminal, the first credential is calculated based on a first key between a first core network device of the first network and the second core network device of the second network, and the terminal belongs to the second network.

[0322] The first credential is calculated based on the first key and at least one of the following parameters: a second key between the terminal and the first core network device, and a temporary identifier of the terminal.

[0323] The first resource response message also carries at least one of the following: a second key between the terminal and the first core network device, and a temporary identifier of the terminal.

[0324] The fourth communication unit is configured to receive a first resource request message from the terminal, wherein the first resource request message is used to request use of a first resource of the first network.

[0325] The fourth communication unit is used to send a second resource request message to the first core network device, wherein the second resource request message is used to request the use of the second resource of the first network; download a second credential from the blockchain, wherein the second credential includes the first key encrypted based on the public key of the second core network device.

[0326] A first core network device according to an embodiment of the present application includes:

[0327] A third communication unit is used to receive an authentication request from a terminal, wherein the authentication request carries a first credential for authenticating the terminal, the first credential is calculated based on a first key between the first core network device of the first network and the second core network device of the second network, and the terminal belongs to the second network.

[0328] The first core network device further includes: a third processing unit, configured to decrypt the first credential based on the first key to obtain a decryption result; and authenticate the terminal based on the decryption result.

[0329] The decryption result includes at least one of the following: a second key between the terminal and the first core network device, and a temporary identifier of the terminal.

[0330] The authentication request also carries a first verification code for verifying the identity of the terminal.

[0331] The third processing unit is configured to verify the identity of the terminal based on a first verification code and the first check code, wherein the first verification code is calculated based on a second key between the terminal and the first core network device and the first credential.

[0332] The authentication request also carries at least one of the following: an identifier of the first resource of the first core network device requested to be used, a temporary identifier of the terminal, an identifier of the first core network device, and a first random number.

[0333] The first verification code is calculated based on the second key, the first credential and at least one of the following parameters: an identifier of the first resource, a temporary identifier of the terminal, an identifier of the first core network device, and the first random number.

[0334] The third communication unit is used to perform at least one of the following: sending an authentication response to the terminal, wherein the authentication response carries a third key used for communication between the terminal and the access network device of the first network; and sending the third key to the access network device.

[0335] The device of the embodiment of the present application can realize the corresponding functions of each device in the aforementioned communication method embodiment. The processes, functions, implementation methods and beneficial effects corresponding to each module (sub-module, unit or component, etc.) in the device can be found in the corresponding description in the above-mentioned method embodiment, which will not be repeated here. It should be noted that the functions described by each module (sub-module, unit or component, etc.) in the device of the embodiment of the application can be implemented by different modules (sub-module, unit or component, etc.) or by the same module (sub-module, unit or component, etc.).

[0336] It should be understood that in the various embodiments of the present application, the size of the serial numbers of the above-mentioned processes does not mean the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of the present application.

[0337] Those skilled in the art will clearly understand that, for the convenience and brevity of description, the specific working processes of the systems, devices and units described above can refer to the corresponding processes in the aforementioned method embodiments and will not be repeated here.

[0338] The above description is merely a specific embodiment of the present application, but the scope of protection of the present application is not limited thereto. Any modifications or substitutions that can be easily conceived by a person skilled in the art within the technical scope disclosed in the present application should be included within the scope of protection of the present application. Therefore, the scope of protection of the present application should be based on the scope of protection of the claims.

Claims

1. A communication method executed by a terminal, comprising: Sending an authentication request to a first network device of a first network, wherein the authentication request carries a first credential for authenticating the terminal, and the first credential is calculated based on a first key between a first core network device of the first network and a second core network device of a second network, and the terminal belongs to the second network.

2. The method according to claim 1, wherein, The authentication request further carries a first verification code for verifying the identity of the terminal, and the first verification code is calculated based on a second key between the terminal and the first core network device and the first credential.

3. The method according to claim 2, wherein, The first verification code is calculated based on the second key, the first credential, and at least one of the following parameters: an identifier of a first resource of the first network requested to be used, a temporary identifier of the terminal, an identifier of the first network device, a first random number.

4. The method according to any one of claims 1-3, wherein The authentication request further carries at least one of the following: an identifier of a first resource of the first network requested to be used, a temporary identifier of the terminal, an identifier of the first network device, a first random number.

5. The method according to any one of claims 1-4, wherein, The method further comprises: Receiving an authentication response from the first network device, wherein the authentication response carries a third key for communication between the terminal and an access network device of the first network.

6. The method according to any one of claims 1-5, wherein, The method further comprises: Receiving a first resource response message from the second core network device, wherein the first resource response message carries the first credential.

7. The method according to claim 6, wherein, The first resource response message further carries at least one of the following: a second key between the terminal and the first core network device, a temporary identifier of the terminal.

8. The method according to claim 6 or 7, wherein The method further comprises: Sending a first resource request message to the second core network device, wherein the first resource request message is used to request to use a first resource of the first network.

9. The method according to any one of claims 1-8, wherein, The first network device includes one of the following: an access network device, the first core network device.

10. A communication method executed by an access network device, comprising: Receiving an authentication request from a terminal, wherein the authentication request carries a first credential for authenticating the terminal, and the first credential is calculated based on a first key between a first core network device of a first network and a second core network device of a second network, the terminal belongs to the second network, and the access network device belongs to the first network.

11. The method according to claim 10, wherein, The authentication request further carries a first verification code for verifying the identity of the terminal.

12. The method according to claim 11, wherein, The authentication request further carries at least one of the following: an identifier of a first resource of the first network requested to be used, a temporary identifier of the terminal, an identifier of the access network device, a first random number.

13. The method according to claim 12, wherein, The method further comprises: Sending an authentication request to the first core network device, wherein the authentication request carries the first credential.

14. The method according to claim 13, wherein, The authentication request further carries at least one of the following: an identifier of the first resource, a temporary identifier of the terminal, an identifier of the access network device, the first random number.

15. The method according to claim 13 or 14, wherein, The method further comprises: Receiving an authentication response from the first core network device, wherein the authentication response carries a first verification code; Verifying the identity of the terminal based on the first verification code and the first verification code.

16. The method according to claim 15, wherein, The authentication response also carries a third key for communication between the terminal and the access network device.

17. The method according to claim 16, wherein, The method further includes: Sending an authentication response to the terminal, where the authentication response carries the third key.

18. A communication method performed by a first core network device, including: Receiving an authentication request from an access network device, where the authentication request carries a first credential for authenticating a terminal, the first credential being calculated based on a first key between the first core network device of a first network and a second core network device of a second network, the terminal belonging to the second network, and the access network device belonging to the first network.

19. The method according to claim 18, wherein, The method further includes: Decrypting the first credential based on the first key to obtain a decryption result; Authenticating the terminal based on the decryption result.

20. The method according to claim 19, wherein The decryption result includes at least one of the following: a second key between the terminal and the first core network device, a temporary identifier of the terminal.

21. The method according to claim 20, wherein, The method further includes: Sending an authentication response to the access network device, where the authentication response carries a first verification code, the first verification code being calculated based on the second key between the terminal and the first core network device and the first credential.

22. The method according to claim 21, wherein, The authentication request further carries at least one of the following: an identifier of a first resource of the first core network device requested to be used, a temporary identifier of the terminal, an identifier of the access network device, a first random number.

23. The method according to claim 22, wherein, The first verification code is calculated based on the second key, the first credential, and at least one of the following parameters: an identifier of the first resource, a temporary identifier of the terminal, an identifier of the access network device, the first random number.

24. The method according to claim 22 or 23, wherein, The authentication response also carries a third key for communication between the terminal and the access network device.

25. The method according to any one of claims 18-24, wherein, The method further includes: Receiving a second resource request message from the second core network device, where the second resource request message is used to request the use of a second resource of the first network; Uploading a second resource response message to the blockchain, where the second resource response message is used to indicate that the second core network device is allowed to use the second resource of the first network, the second resource response message carries a second credential, and the second credential includes the first key encrypted based on the public key of the second core network device.

26. A communication method performed by a second core network device, including: Sending a first resource response message to a terminal, where the first resource response message carries a first credential for authenticating the terminal, the first credential being calculated based on a first key between a first core network device of a first network and the second core network device of a second network, and the terminal belonging to the second network.

27. The method according to claim 26, wherein, The first credential is calculated based on the first key and at least one of the following parameters: a second key between the terminal and the first core network device, a temporary identifier of the terminal.

28. The method according to claim 26 or 27, wherein, The first resource response message further carries at least one of the following: a second key between the terminal and the first core network device, a temporary identifier of the terminal.

29. The method according to any one of claims 26 - 28, wherein, The method further includes: Receive a first resource request message from the terminal, where the first resource request message is used to request to use a first resource of the first network.

30. The method according to any one of claims 26-29, wherein, The method further includes: Send a second resource request message to the first core network device, where the second resource request message is used to request to use a second resource of the first network; Download a second credential from the blockchain, where the second credential includes the first key encrypted based on the public key of the second core network device.

31. A communication method performed by a first core network device, including: Receive an authentication request from a terminal, where the authentication request carries a first credential for authenticating the terminal, the first credential is calculated based on a first key between the first core network device of the first network and the second core network device of the second network, and the terminal belongs to the second network.

32. The method according to claim 31, wherein, The method further includes: Decrypt the first credential based on the first key to obtain a decryption result; Authenticate the terminal based on the decryption result.

33. The method according to claim 32, wherein, The decryption result includes at least one of the following: a second key between the terminal and the first core network device, a temporary identifier of the terminal.

34. The method according to claim 33, wherein The authentication request further carries a first check code for verifying the identity of the terminal.

35. The method according to any one of claims 31-34, wherein, The method further includes: Verify the identity of the terminal based on a first verification code and the first check code, where the first verification code is calculated based on the second key between the terminal and the first core network device and the first credential.

36. The method according to claim 35, wherein, The authentication request further carries at least one of the following: an identifier of a first resource of the first core network device requested to be used, a temporary identifier of the terminal, an identifier of the first core network device, a first random number.

37. The method according to claim 36, wherein, The first verification code is calculated based on the second key, the first credential, and at least one of the following parameters: an identifier of the first resource, a temporary identifier of the terminal, an identifier of the first core network device, the first random number.

38. The method according to any one of claims 31 - 37, wherein The method further includes at least one of the following: Send an authentication response to the terminal, where the authentication response carries a third key for communication between the terminal and an access network device of the first network; Send the third key to the access network device.

39. A terminal, including: A first communication unit, configured to send an authentication request to a first network device of a first network, where the authentication request carries a first credential for authenticating the terminal, the first credential is calculated based on a first key between the first core network device of the first network and the second core network device of the second network, and the terminal belongs to the second network.

40. An access network device, including: A second communication unit, configured to receive an authentication request from a terminal, where the authentication request carries a first credential for authenticating the terminal, the first credential is calculated based on a first key between the first core network device of the first network and the second core network device of the second network, the terminal belongs to the second network, and the access network device belongs to the first network.

41. A first core network device, including: A third communication unit, configured to receive an authentication request from an access network device, where the authentication request carries a first credential for authenticating a terminal, and the first credential is calculated based on a first key between a first core network device of a first network and a second core network device of a second network, and the terminal belongs to the second network and the access network device belongs to the first network.

42. A second core network device, comprising: A fourth communication unit, configured to send a first resource response message to a terminal, where the first resource response message carries a first credential for authenticating the terminal, and the first credential is calculated based on a first key between a first core network device of a first network and the second core network device of the second network, and the terminal belongs to the second network.

43. A first core network device, comprising: A third communication unit, configured to receive an authentication request from a terminal, where the authentication request carries a first credential for authenticating the terminal, and the first credential is calculated based on a first key between the first core network device of the first network and the second core network device of the second network, and the terminal belongs to the second network.

Citation Information

Patent Citations

  • Sponsored connectivity to cellular networks using existing credentials

    CN110086833A

  • Network access method, target terminal, certificate management network element and verification network element

    CN114978698A

  • Communication method and device

    CN116684865A

  • Method and apparatus for setup, authentication, authorization, and user equipment (UE) key generation and distribution in on-demand networks

    CN117203935A

  • Method for distributing security keys during hand-off in a wireless communication system

    US20070003062A1