Identity verification method and device

By converting identity legality information between networks with different standards, using existing EIR devices to solve the overhead problems caused by new EIR devices, and cross-network compatibility of identity legality verification is achieved.

WO2025138779A1PCT designated stage expired Publication Date: 2025-07-03HUAWEI TECH CO LTD
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
PCT/CN2024/108595
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2023-12-29
Filing Date
2024-07-30
Publication Date
2025-07-03

AI Technical Summary

Technical Problem

When verifying the legitimacy of devices in communication networks of different standards, the prior art requires the establishment of new EIR devices, resulting in high overhead.

Method used

The first information is obtained through the first network element and converted into the second information used in the second network, and the signaling conversion between different standard networks is realized using existing EIR devices to avoid the creation of new EIR devices.

Benefits of technology

Identity legality verification between different networks is realized, without the need to create new EIR devices, reducing overhead.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2024108595_03072025_PF_FP_ABST
    Figure CN2024108595_03072025_PF_FP_ABST
Patent Text Reader

Abstract

The present application provides an identity verification method and device. In the method, first information and second information are carried in signaling that requests verification of identity legitimacy of a terminal, and a first network element can be used as a conversion function entity and converts the first information used in a first network for verification of identity legitimacy into the second information used in a second network for verification of identity legitimacy, achieving signaling conversion between networks of different standards. Existing EIR devices can be multiplexed to implement verification of identity legitimacy of a user equipment, without needing to build a new EIR device, and reducing overhead.
Need to check novelty before this filing date? Find Prior Art

Description

Method and device for verifying identity

[0001] This application claims priority to the Chinese patent application filed with the State Intellectual Property Office on December 29, 2023, with application number 202311867677.0 and application name “Method and Device for Verifying Identity”, the entire contents of which are incorporated by reference into this application. Technical Field

[0002] The present application relates to the field of communication technology, and in particular to a method and device for verifying identity. Background Art

[0003] The communication system defines an equipment identity register (EIR) based on the service-based architecture (SBA) framework. The EIR supports the function of checking the identity status of the device, that is, verifying the legitimacy of the device. Taking the 5G-EIR as an example, the 5G-EIR can check whether the permanent equipment identifier (PEI) is on the blacklist.

[0004] However, if the legitimacy of a device needs to be verified in a communication system on networks of different standards, operators need to build new EIR devices suitable for networks of different standards, which is very costly.

[0005] Summary of the Invention

[0006] The embodiments of the present application provide a method and apparatus for verifying identity, which eliminates the need for building a new EIR device when verifying the identity of a device, thereby reducing overhead.

[0007] To achieve the above objectives, this application adopts the following technical solutions:

[0008] In a first aspect, a method for verifying identity is provided. The method is applied to a first network element and may include: during a terminal registration process with a first network, the first network element obtaining first information, where the first information is used to verify the legitimacy of the terminal's identity in the first network. The first network element, based on the first information, sends second information to a second network element, where the second information is used to verify the legitimacy of the terminal's identity in the second network, the first network and the second network being of different standards, and the second network element being used to verify the legitimacy of the terminal's identity in the second network. The first network element obtains a result of the terminal's identity verification from the second network element.

[0009] Based on the method of the first aspect, it can be known that the first information and the second information are carried in the signaling requesting verification of the legitimacy of the identity of the terminal. The first network element can serve as a conversion functional entity to convert the first information used to verify the legitimacy of the identity in the first network into the second information used to verify the legitimacy of the identity in the second network, thereby realizing signaling conversion between networks of different standards. The existing EIR equipment can be reused to realize the verification of the legitimacy of the user equipment identity, without the need for new EIR equipment, thereby reducing overhead.

[0010] Optionally, the first network may include a 5G network, and the second network may include a 2 / 3G network, or a 4G network. That is to say, in the 5G independent networking stage, 2 / 3G network or 4G network equipment can be used to verify the legitimacy of the user device identity, without the need for new 5G-EIR equipment, thereby reducing overhead.

[0011] In one possible design scheme, the first information may include at least one of the following items of the terminal: a first device identifier or a first user identity identifier, the first device identifier is used to verify the legitimacy of the terminal in the first network, and the first user identity identifier is used to verify the legitimacy of the identity of the user using the terminal in the first network.

[0012] It can be understood that the first device identifier and the first user identity identifier can be applicable to the first network, wherein the first device identifier may include a permanent equipment identifier PEI, that is, information that can uniquely identify the terminal in the 5G system, and the first user identity identifier may include a user permanent identifier SUPI, that is, information that can uniquely identify the user of the terminal in the 5G system. The first device identifier and / or the first user identity identifier can be used to verify the legitimacy of the terminal's identity in the 5G network to avoid errors in the verification results.

[0013] In one possible design scheme, the second information may include at least one of the following items of the terminal: a second device identifier or a second user identity identifier, the second device identifier is used to verify the legitimacy of the terminal in the second network, and the second user identity identifier is used to verify the legitimacy of the identity of the user using the terminal in the second network.

[0014] It can be understood that the second device identifier and the second user identity identifier can be applicable to the second network, wherein the second device identifier can include the International Mobile Equipment Identity (IMEI) or terminal information, i.e., information that can uniquely identify the terminal in the 2 / 3G network or the 4G network, and the first user identity identifier can include user information or the International Mobile Subscriber Identity (IMSI), i.e., information that can uniquely identify the user of the terminal in the 2 / 3G network or the 4G network. It can be seen that the second device identifier has a mapping relationship with the first device identifier, and the second user identity identifier has a mapping relationship with the first user identity identifier. The mapping relationship of signaling parameters can realize the conversion of signaling of networks of different standards, avoid errors in the conversion, and make it impossible to verify the legitimacy of the terminal identity.

[0015] Optionally, the first information and the second information have a corresponding relationship. It can be understood that the signaling parameters in the first information and the second information have a mapping relationship, which facilitates signaling conversion.

[0016] In one possible design, the first network element receives an identity verification result returned by the second network element based on the second information. The identity verification result is used to indicate whether the terminal's identity in the second network is legitimate. If the terminal's identity in the second network is legitimate, then the terminal's identity in the first network is also legitimate; otherwise, the terminal's identity in the first network is illegitimate.

[0017] It can be understood that the identity legitimacy verification result returned based on the second information is applicable to the second network, and the identity legitimacy of the terminal is consistent in the first network and the second network. Therefore, the identity legitimacy of the terminal can be verified by the second network element of the second network, and the verification result can be applied to the first network to facilitate the registration of the terminal in the first network.

[0018] In one possible design, the first network element receives first information from a third network element, where the third network element may be a network element in the first network. Accordingly, the identity verification method may further include: the first network element sending information to the third network element indicating whether the identity of the terminal in the first network is legitimate.

[0019] It can be understood that the third network element can be an access and mobility management function (AMF network element). The first network element receives information from the AMF network element requesting verification of the legitimacy of the terminal's identity in the first network, and after obtaining the identity legitimacy verification result applicable to the second network, the identity legitimacy verification result is converted into information applicable to the first network. The terminal can be registered in the first network without the participation of the device for verifying the legitimacy of the identity in the first network, thereby reducing overhead.

[0020] Optionally, the identity legitimacy verification result is further used to indicate device status information of the terminal. The device status information may include whether the terminal is included in a whitelist, a blacklist, or a graylist. It is understood that if the device status information includes that the terminal is included in a whitelist, the identity legitimacy verification result indicates that the terminal's identity is legitimate. If the device status information includes that the terminal is included in a blacklist or a graylist, the identity legitimacy verification result indicates that the terminal's identity is illegal or questionable. Whether the terminal is allowed to register with the first network is determined based on the device status information, thereby improving the security of terminal registration.

[0021] Optionally, the first information is carried in signaling in a 5G device identification registration device interface, and the second information is carried in signaling in a 2 / 3G device identification registration device interface, or in signaling in a 4G device identification registration device interface. It is understandable that the second network element may be a 2 / 3G or 4G EIR device, and the second information is carried in signaling in a 2 / 3G or 4G EIR device interface. By converting the signaling in the 5G-EIR device interface with the signaling in the 2 / 3G or 4G EIR device interface, the legitimacy of the user device identity is verified, without the need for a new 5G-EIR device, thereby reducing overhead.

[0022] In a second aspect, a method for verifying identity is provided. The method is applied to a second network element and includes: during a terminal registration process with a first network, the second network element receives second information sent by the first network element based on first information, wherein the first information is used to verify the legitimacy of the terminal's identity in the first network, and the second information is used to verify the legitimacy of the terminal's identity in a second network, and the first network and the second network are networks of different standards. The second network element verifies the legitimacy of the terminal's identity in the second network based on the second information. The second network element sends a result of the terminal's identity verification to the first network element.

[0023] It can be understood that the relevant technical effects of the method of the second aspect mentioned above can also refer to the relevant introduction of the first aspect mentioned above, and will not be repeated here.

[0024] In a third aspect, a communication device is provided. The communication device includes: a module for executing the method described in any one of aspects 1 to 2, such as a transceiver module and a processing module. For example, the transceiver module is configured to indicate the transceiver function of the communication device, and the processing module is configured to perform functions of the communication device other than the transceiver function.

[0025] Optionally, the transceiver module may include a sending module and a receiving module, wherein the sending module is used to implement the sending function of the communication device described in the third aspect, and the receiving module is used to implement the receiving function of the communication device described in the third aspect.

[0026] Optionally, the communication device described in the third aspect may further include a storage module, wherein the storage module stores a program or instruction. When the processing module executes the program or instruction, the communication device may execute the method described in any one of the first aspect to the second aspect.

[0027] It can be understood that the communication device described in the third aspect can be a terminal or a network device, or a chip (system) or other parts or components that can be set in a terminal or a network device, or a device that includes a terminal or a network device. This application does not limit this.

[0028] In addition, the technical effects of the communication device described in the third aspect can refer to the technical effects of the above-mentioned first aspect and will not be repeated here.

[0029] In a fourth aspect, a communication device is provided, comprising: a processor configured to execute the method described in any one of the first to second aspects.

[0030] In one possible design solution, the communication device described in the fourth aspect may further include a transceiver. The transceiver may be a transceiver circuit or an interface circuit. The transceiver may be used for the communication device described in the fourth aspect to communicate with other communication devices.

[0031] In one possible design, the communication device described in the fourth aspect may further include a memory. The memory may be integrated with the processor or provided separately. The memory may be used to store the computer program and / or data involved in the method described in any one of the first and second aspects.

[0032] In an embodiment of the present application, the communication device described in the fourth aspect can be the terminal or network device described in any one of the first to second aspects, or a chip (system) or other parts or components that can be set in the terminal or network device, or a device that includes the terminal or network device.

[0033] In addition, the technical effects of the communication device described in the fourth aspect can refer to the technical effects of the methods described in any one of the first aspect to the second aspect, and will not be repeated here.

[0034] In a fifth aspect, a communication device is provided, comprising: a processor coupled to a memory, the processor configured to execute a computer program stored in the memory, so that the communication device performs the method described in any one of the first to second aspects.

[0035] In one possible design solution, the communication device described in the fifth aspect may further include a transceiver. The transceiver may be a transceiver circuit or an interface circuit. The transceiver may be used for the communication device described in the fifth aspect to communicate with other communication devices.

[0036] In an embodiment of the present application, the communication device described in the fifth aspect can be the terminal or network device described in any one of the first to second aspects, or a chip (system) or other parts or components that can be set in the terminal or network device, or a device that includes the terminal or network device.

[0037] In addition, the technical effects of the communication device described in the fifth aspect can refer to the technical effects of the method described in the first aspect, and will not be repeated here.

[0038] In a sixth aspect, a communication device is provided, comprising: a processor and a memory; the memory is used to store a computer program, and when the processor executes the computer program, the communication device executes the method described in any one of the first to second aspects.

[0039] In one possible design solution, the communication device described in the sixth aspect may further include a transceiver. The transceiver may be a transceiver circuit or an interface circuit. The transceiver may be used for the communication device described in the sixth aspect to communicate with other communication devices.

[0040] In an embodiment of the present application, the communication device described in the sixth aspect can be the terminal or network device described in any one of the first aspect to the second aspect, or a chip (system) or other parts or components that can be set in the terminal or network device, or a device that includes the terminal or network device.

[0041] In addition, the technical effects of the communication device described in the sixth aspect can refer to the technical effects of the methods described in any one of the first aspect to the second aspect, and will not be repeated here.

[0042] In a seventh aspect, a communication system is provided, comprising: a first network element for executing the method described in the first aspect, and a second network element for executing the method described in the second aspect.

[0043] In an eighth aspect, a computer-readable storage medium is provided, comprising: a computer program or instructions; when the computer program or instructions are run on a computer, the computer is caused to execute the method described in any one of the first to second aspects.

[0044] In a ninth aspect, a computer program product is provided, comprising a computer program or instructions, which, when executed on a computer, causes the computer to execute the method described in any one of the first to second aspects. BRIEF DESCRIPTION OF THE DRAWINGS

[0045] Figure 1 is a schematic diagram of the reference model of the service-oriented interface N5g-eir;

[0046] FIG2 is a schematic diagram of a protocol conversion process;

[0047] FIG3 is a schematic diagram of the architecture of a communication system according to an embodiment of the present application;

[0048] FIG4 is a schematic diagram of a first process for verifying identity provided in an embodiment of the present application;

[0049] FIG5 is a second schematic diagram of the architecture of the communication system provided in an embodiment of the present application;

[0050] FIG6 is a second schematic diagram of the identity verification process provided in an embodiment of the present application;

[0051] FIG7 is a third schematic diagram of the architecture of the communication system provided in an embodiment of the present application;

[0052] FIG8 is a third schematic diagram of the identity verification process provided in an embodiment of the present application;

[0053] FIG9 is a first structural diagram of a communication device provided in an embodiment of the present application;

[0054] FIG10 is a second structural diagram of the communication device provided in an embodiment of the present application. DETAILED DESCRIPTION

[0055] The fifth generation (5G) communication system defines an EIR based on the SBA framework, namely 5G-EIR, and provides a service interface N5g-eir. 5G-EIR is an optional network function that can support checking the device identity status, for example, checking whether the permanent equipment identity (PEI) is on a blacklist (prohibited list).

[0056] Figure 1 is a schematic diagram of the reference model of the service-oriented interface N5g-eir. As shown in Figure 1, N17 is the reference point between the AMF network element and the 5G-EIR device, and N5g-eir is the service-oriented interface of the 5G-EIR. For details, please refer to the relevant definitions of 3GPP. The AMF network element and the interworking function (IWF) interact through the reference point N17 or the service-oriented interface N5g-eir.

[0057] For the scenario of verifying the international mobile equipment identity (IMEI), 3GPP defines the interworking function (IWF) to support protocol conversion between the mobile application part (MAP) and the billing authentication protocol (Diameter). Figure 2 is a schematic diagram of the protocol conversion process.

[0058] As shown in FIG. 2 , the protocol conversion process may include S201 - S204 .

[0059] S201: The MME network element, the SGSN network element, or the MME network element combined with the SGSN network element sends an ECR message to the IWF network element.

[0060] S13 is the interface between the Mobility Management Entity (MME) network element and the EIR. The EIR and MME network elements can be directly connected via the S13 interface. S13' is the reference point between the Serving GPRS Support Node (SGSN) network element and the EIR device. The S13 / S13' interface uses the billing authentication protocol. Specifically, the S13 / S13' interface maps to the Mobile Equipment Identity Check Request (ME-Identity-Check-Request, ECR) signaling or the Mobile Equipment Identity Check Answer (ME-Identity-Check-Answer, ECA) signaling in the specified Diameter application. ECR signaling is used to request verification of the legitimacy of the mobile device's identity, and ECA signaling is the response message to the ECR signaling. The MME network element is primarily responsible for mobility management, bearer management, user authentication, and serving gateway (SGW) selection. The EIR can verify the terminal's device identity to determine its legitimacy, thereby ensuring network security.

[0061] S202: The IWF network element sends a message to the EIR to check the IMEI.

[0062] The IMEI check message is called the Check IMEI message. The IWF converts the ECR message into a Check IMEI message and sends it to the EIR. Gf is the interface between the SGSN and the EIR. The Gf interface uses the MAP protocol. The MAP_CHECK_IMEI service signaling in the MAP protocol is used by the SGSN to request an IMEI check from the EIR. The MAP operation corresponding to the MAP_CHECK_IMEI service is Check IMEI.

[0063] S203: The EIR sends a response message for checking the IMEI to the IWF network element.

[0064] The response message for checking IMEI is a Check IMEI ACK message.

[0065] S204: The IWF network element sends an ECA message to the MME network element, the SGSN network element, or the MME network element combined with the SGSN network element.

[0066] The IWF network element converts the Check IMEI ACK message into an ECA message and sends it to the MME network element, the SGSN network element, or the MME network element combined with the SGSN network element.

[0067] In the 5G network stage, the operator network needs to build new 5G-EIR equipment and migrate the existing user IMEI to the 5G-EIR equipment, which is costly. In addition, the parameter mapping relationship between the ECR / ECA signaling in the S13 / S13' interface and the equipment identification check (N5g-eir_Equipment Identity Check) signaling in the N5g-eir interface, as well as the parameter mapping relationship between the check IMEI / check IMEI_ACK signaling in the Gf interface and the N5g-eir_Equipment Identity Check signaling in the N5g-eir interface is not given.

[0068] In response to the above technical problems, the embodiments of the present application propose the following technical solutions.

[0069] The technical solution in this application will be described below with reference to the accompanying drawings.

[0070] The technical solutions of the embodiments of the present application can be applied to various communication systems, such as wireless network (Wi-Fi) systems, vehicle to everything (V2X) communication systems, device-to-device (D2D) communication systems, Internet of Vehicles communication systems, fourth generation (4G) mobile communication systems, such as long term evolution (LTE) systems, world-wide interoperability for microwave access (WiMAX) communication systems, and fifth generation (5G) systems, such as new radio (NR) systems.

[0071] In the embodiment of the present application, "indication" may include direct indication and indirect indication, and may also include explicit indication and implicit indication. The information indicated by a certain information (such as the first indication information, the second indication information, or the third indication information below) is called information to be indicated. In the specific implementation process, there are many ways to indicate the information to be indicated, such as but not limited to, the information to be indicated can be directly indicated, such as the information to be indicated itself or the index of the information to be indicated. The information to be indicated can also be indirectly indicated by indicating other information, where there is an association between the other information and the information to be indicated. It is also possible to indicate only a part of the information to be indicated, while the other parts of the information to be indicated are known or agreed in advance. For example, the indication of specific information can be achieved by means of the arrangement order of each piece of information agreed in advance (such as specified in the protocol), thereby reducing the indication overhead to a certain extent. At the same time, the common parts of each piece of information can be identified and indicated uniformly to reduce the indication overhead caused by indicating the same information separately.

[0072] In addition, the specific indication method can also be various existing indication methods, such as but not limited to the above-mentioned indication methods and various combinations thereof. The specific details of the various indication methods can be referred to the prior art and will not be repeated herein. As can be seen from the above, for example, when it is necessary to indicate multiple information of the same type, there may be a situation where the indication methods for different information are different. In the specific implementation process, the required indication method can be selected according to specific needs. The embodiment of the present application does not limit the selected indication method. In this way, the indication method involved in the embodiment of the present application should be understood to cover various methods that can enable the party to be indicated to obtain the information to be indicated.

[0073] It should be understood that the information to be indicated can be sent as a whole or divided into multiple sub-information and sent separately, and the sending period and / or sending time of these sub-information can be the same or different. The specific sending method is not limited in the embodiments of this application. The sending period and / or sending time of these sub-information can be predefined, for example, predefined according to a protocol, or can be configured by the transmitting device by sending configuration information to the receiving device.

[0074] "Pre-definition" or "pre-configuration" can be implemented by pre-saving corresponding codes, tables or other methods that can be used to indicate relevant information in the device, and the embodiments of the present application do not limit the specific implementation method. Among them, "saving" can mean saving in one or more memories. The one or more memories can be set separately or integrated in an encoder or decoder, a processor, or a communication device. The one or more memories can also be partially set separately and partially integrated in a decoder, a processor, or a communication device. The type of memory can be any form of storage medium, and the embodiments of the present application do not limit this.

[0075] The "protocol" involved in the embodiments of the present application may refer to a protocol family in the communication field, a standard protocol with a similar protocol family frame structure, or a related protocol used in future communication systems. The embodiments of the present application do not make specific limitations on this.

[0076] In the embodiments of the present application, descriptions such as "when...", "in the case of...", "if" and "if" all mean that the device will perform corresponding processing under certain objective circumstances. It does not limit the time, nor does it require the device to perform judgment actions when implemented, nor does it mean that there are other limitations.

[0077] In the description of the embodiments of the present application, unless otherwise specified, " / " indicates that the objects associated with each other are in an "or" relationship. For example, A / B can represent A or B. "And / or" in the embodiments of the present application is only a description of the association relationship of the associated objects, indicating that there can be three relationships. For example, A and / or B can represent: A exists alone, A and B exist at the same time, and B exists alone. A and B can be singular or plural. In addition, in the description of the embodiments of the present application, unless otherwise specified, "multiple" refers to two or more than two. "At least one of the following" or similar expressions refers to any combination of these items, including any combination of single or plural items. For example, at least one of a, b, or c can represent: a, b, c, ab, ac, bc, or abc, where a, b, and c can be single or multiple. In addition, in order to facilitate the clear description of the technical solutions of the embodiments of the present application, in the embodiments of the present application, words such as "first" and "second" are used to distinguish between identical or similar items with basically the same functions and effects. Those skilled in the art will understand that words such as "first" and "second" do not limit the quantity and execution order, and words such as "first" and "second" do not necessarily limit differences. At the same time, in the embodiments of the present application, words such as "exemplary" or "for example" are used to indicate examples, illustrations or explanations. Any embodiment or design described as "exemplary" or "for example" in the embodiments of the present application should not be interpreted as being more preferred or more advantageous than other embodiments or design. Specifically, the use of words such as "exemplary" or "for example" is intended to present related concepts in a concrete way for easy understanding.

[0078] The network architecture and business scenarios described in the embodiments of the present application are intended to more clearly illustrate the technical solutions of the embodiments of the present application, and do not constitute a limitation on the technical solutions provided in the embodiments of the present application. Ordinary technicians in this field will know that with the evolution of network architecture and the emergence of new business scenarios, the technical solutions provided in the embodiments of the present application are also applicable to similar technical problems.

[0079] To facilitate understanding of the embodiments of the present application, a communication system applicable to the embodiments of the present application is first described in detail using the communication system shown in Figure 3 as an example. For example, Figure 3 is a schematic diagram of the architecture of a communication system applicable to the method provided in the embodiments of the present application.

[0080] As shown in Figure 3, the communication system may include: a first network element and a second network element. The first network element may be a network element having a signaling conversion function between networks of different standards, such as the aforementioned IWF network element, and the second network element may be a network function or entity that supports verification of the identity status of the terminal, such as a 2G / 3G network EIR or a 4G network EIR device.

[0081] The communication system may also include a third network element, which may be an AMF network element. The AMF network element is mainly responsible for access management in the wireless network, such as user access, user location update, user registration network, cell switching, etc., and mainly involves the functions of the user registration network in the embodiment of the present application.

[0082] A terminal may also be referred to as a terminal device, user equipment (UE), mobile station, mobile terminal, etc. Terminals can be widely used in various scenarios, such as device-to-device (D2D), vehicle-to-everything (V2X) communication, machine-type communication (MTC), Internet of Things (IOT), virtual reality, augmented reality, industrial control, autonomous driving, telemedicine, smart grid, smart furniture, smart office, smart wearable, smart transportation, smart city, etc. A terminal may be a mobile phone, tablet computer, computer with wireless transceiver function, wearable device, vehicle, drone, helicopter, airplane, ship, robot, robotic arm, smart home device, etc. The embodiments of the present application do not limit the device form of the terminal.

[0083] In this communication system, the first information and the second information are carried in the signaling requesting verification of the legitimacy of the identity of the terminal. The first network element can serve as a conversion functional entity to convert the first information used to verify the legitimacy of the identity in the first network into the second information used to verify the legitimacy of the identity in the second network, thereby realizing signaling conversion between networks of different standards. The existing EIR equipment can be reused to realize the verification of the legitimacy of the user equipment identity, without the need for new EIR equipment, thereby reducing overhead.

[0084] The embodiments of this application do not limit the device form factor of the network device. The device used to implement the function of the network device can be a network device; it can also be a device that supports the network device to implement the function, such as a chip system. The device can be installed in the network device or used in conjunction with the network device. In the embodiments of this application, the chip system can be composed of chips or can include chips and other discrete components.

[0085] The following will specifically describe the interaction process between each network element / device in the above communication system through a method embodiment in conjunction with Figure 4. The identity verification method provided in the embodiment of the present application can be applied to the above communication system and specifically applied to various scenarios / processes mentioned in the above communication system, which will be described in detail below.

[0086] Figure 4 is a flow chart of a method for verifying identity provided in an embodiment of the present application. The method for verifying identity is applicable to the above communication system, and mainly involves interaction between a first network element and a second network element.

[0087] As shown in FIG4 , the process of the identity verification method is as follows:

[0088] S401: During the process of a terminal registering with a first network, a first network element obtains first information.

[0089] Among them, the first network may include a 5G network. During the process of the terminal registering to the 5G network, the legitimacy of the terminal's identity in the 5G network needs to be verified based on the first information. The first information may be information used to verify the legitimacy of the terminal's identity in the first network. The first information may be information sent by a high layer, that is, carried in a message (signaling) sent by a high layer. The message may be a signaling for requesting verification of the legitimacy of the terminal's identity. For example, the first information may be carried in the N5g-eir_Equipment Identity Check message received from the AMF network element. The N5g-eir_Equipment Identity Check signaling is used to request verification of the legitimacy of the terminal's identity. It can be seen that the first information can be carried in the signaling in the service-oriented interface N5g-eir.

[0090] The first network element may be a network element having a signaling conversion function between networks of different standards, for example, an IWF network element.

[0091] S402: The first network element sends second information to the second network element based on the first information.

[0092] Correspondingly, the second network element receives the second information sent by the first network element.

[0093] The second information may be information used to verify the legitimacy of the terminal's identity in the second network. The first network and the second network are networks of different standards. The second network element is used to verify the legitimacy of the terminal's identity in the second network. That is, the second information may be information applicable to the second network. The second network may include a 2G / 3G network or a 4G network. If the second network is a 2G / 3G network, the second information may be carried in signaling within a 2G / 3G device identity registration device interface. That is, the second information may be carried in a Check IMEI message. The Check IMEI message is used to request verification of the terminal's IMEI. The second network element may be a 2G / 3G network EIR. The 2G / 3G network EIR verifies the legitimacy of the terminal's identity based on the terminal's IMEI. If the second network is a 4G network, the second information may be carried in signaling within a 4G device identity registration device interface. That is, the second information may be carried in an ECR message. The ECR message is used to request verification of the terminal's identity. The second network element may be a 4G network EIR. The 4G network EIR verifies the legitimacy of the terminal's identity based on the terminal's IMEI.

[0094] It can be understood that the first information used to verify the legitimacy of the identity in the first network is converted into the second information used to verify the legitimacy of the identity in the second network, so as to realize the signaling conversion between networks of different standards. For example, the IWF network element converts the signaling in the 5G-EIR device interface and the signaling in the 2 / 3G or 4G EIR device interface, that is, the N5g-eir_Equipment Identity Check message is converted into a Check IMEI message or an ECR message. That is to say, in the 5G independent networking stage, 2 / 3G network or 4G network equipment can be used to realize the verification of the legitimacy of the user device identity, without the need for new equipment, thereby reducing overhead.

[0095] In one possible design scheme, the first information may include at least one of the following items of the terminal: a first device identifier or a first user identity identifier, the first device identifier is used to verify the legitimacy of the terminal in the first network, and the first user identity identifier is used to verify the legitimacy of the identity of the user using the terminal in the first network.

[0096] Among them, the first device identifier and the first user identity identifier can be applicable to the first network. It can be understood that when the first network is a 5G network, the first device identifier or the first user identity identifier can be carried in the N5g-eir_Equipment Identity Check message. The first device identifier may include a permanent equipment identifier (PEI), that is, information that can uniquely identify the terminal in the 5G system. The first user identity identifier may include a user permanent identifier (SUPI), where the SUPI may be the SUPI corresponding to the above-mentioned terminal, that is, information that can uniquely identify the user of the terminal in the 5G system.

[0097] The first device identifier and / or the first user identifier can be used to verify the legitimacy of the terminal's identity in the 5G network, thereby avoiding errors in the verification results.

[0098] In one possible design scheme, the second information may include at least one of the following items of the terminal: a second device identifier or a second user identity identifier, the second device identifier is used to verify the legitimacy of the terminal in the second network, and the second user identity identifier is used to verify the legitimacy of the identity of the user using the terminal in the second network.

[0099] It can be understood that the second device identifier and the second user identity identifier can be applicable to the second network. When the second network is a 2 / 3G network, the second device identifier or the first user identity identifier can be carried in the Check IMEI message. The second device identifier can include the International Mobile Equipment Identity IMEI, that is, information that can uniquely identify the terminal in the 2 / 3G network. The first user identity identifier can include user information (USER-INFOMATION), that is, information that can uniquely identify the user using the terminal in the 2 / 3G network. When the second network is a 4G network, the second device identifier or the first user identity identifier can be carried in the ECR message. The second device identifier can include terminal information (Terminal-Information). Terminal-Information can be a parameter of the ECR message in the 4G network, which is equivalent to the IMEI information. The first user identity identifier can include the International Mobile Subscriber Identification Number (IMSI), that is, information that can uniquely identify the user using the terminal in the 4G network.

[0100] It can be seen that the second device identifier has a mapping relationship with the first device identifier, and the second user identity identifier has a mapping relationship with the first user identity identifier. The mapping relationship of signaling parameters can realize the conversion of signaling of networks of different standards, avoiding errors in signaling conversion, which makes it impossible to verify the legitimacy of the terminal identity.

[0101] Optionally, the first information and the second information have a corresponding relationship. It can be understood that the signaling parameters in the first information and the second information have a corresponding relationship, for example, the second device identifier has a corresponding relationship with the first device identifier, and the second user identity identifier has a corresponding relationship with the first user identity identifier.

[0102] If the first information contains a field / parameter newly added by the first network, that is, there is no information element corresponding to the field / parameter in the second network, then the field / parameter does not need to be converted during signaling conversion. For example, the parameters in the N5g-eir_Equipment Identity Check message include a generic public subscription identifier (GPSI) and supported features (supported-features), and there is no information element corresponding to these two parameters in the Check IMEI message or the ECR message, so no conversion is required. This facilitates signaling conversion.

[0103] In one possible design, the first network element receives an identity verification result returned by the second network element based on the second information. The identity verification result is used to indicate whether the terminal's identity in the second network is legitimate. If the terminal's identity in the second network is legitimate, then the terminal's identity in the first network is also legitimate; otherwise, the terminal's identity in the first network is illegitimate.

[0104] It can be understood that the identity legitimacy verification result returned based on the second information is applicable to the second network. For example, when the second network is a 2 / 3G network, the identity legitimacy verification result can be carried in the Check IMEI ACK message. When the second network is a 4G network, the identity legitimacy verification result can be carried in the Mobile Device Identity Check Response (ECA) message. The identity legitimacy of the terminal is consistent in the first network and the second network. Therefore, the identity legitimacy of the terminal can be verified by the second network element of the second network, and the verification result can be applied to the first network. For example, the identity legitimacy verification result applicable to the 2 / 3G network or the 4G network is applied to the 5G network. In this way, it is convenient to realize the registration of the terminal in the 5G network.

[0105] In one possible design, the first network element receives first information from a third network element, where the third network element may be a network element in the first network. Accordingly, the identity verification method may further include: the first network element sending information to the third network element indicating whether the identity of the terminal in the first network is legitimate.

[0106] It can be understood that the third network element can be an AMF network element, and the first network element receives information from the AMF network element requesting verification of the legitimacy of the terminal's identity in the first network, and after obtaining the identity legitimacy verification result applicable to the second network, converts the identity legitimacy verification result into information applicable to the first network. For example, when the second network is a 2 / 3G network, the IWF network element converts the Check IMEI ACK message into an equipment identification check response (N5g-eir_Equipment Identity Check Response) message in the N5g-eir interface. When the second network is a 4G network, the IWF network element converts the ECA message into an N5g-eir_Equipment Identity Check Response message. In this way, the terminal can be registered in the first network without the participation of the device that verifies the legitimacy of the identity in the first network, thereby reducing overhead.

[0107] Optionally, the identity legitimacy verification result is also used to indicate the device status information of the terminal, and the device status information may include whether the terminal is included in the whitelist, or the terminal is included in the blacklist, or the terminal is included in the graylist. It can be understood that if the device status information includes that the terminal is included in the whitelist, the identity legitimacy verification result indicates that the identity of the terminal is legal, and if the device status information includes that the terminal is included in the blacklist or the terminal is included in the graylist, the identity legitimacy verification result indicates that the identity of the terminal is illegal or questionable. For example, the device status information of the terminal can be a parameter in a Check IMEI ACK message or an ECA message, and the IWF network element converts the device status information of the terminal in the Check IMEI ACK message or the ECA message into the device status information of the terminal in the N5g-eir_Equipment Identity Check Response message. Whether the terminal is allowed to register to the first network is determined by the device status information, thereby improving the security of terminal registration.

[0108] S403: The second network element verifies the legitimacy of the identity of the terminal in the second network based on the second information.

[0109] S404: The first network element obtains the terminal's identity legitimacy verification result from the second network element.

[0110] The specific implementation principles of S403-S404 are similar to those of the above-mentioned S401-S402, which can be understood by reference and will not be repeated here.

[0111] In summary, the first information and the second information are carried in the signaling requesting verification of the legitimacy of the identity of the terminal. The first network element can serve as a conversion functional entity to convert the first information used to verify the legitimacy of the identity in the first network into the second information used to verify the legitimacy of the identity in the second network, thereby realizing signaling conversion between networks of different standards. The existing EIR equipment can be reused to realize the verification of the legitimacy of the user equipment identity, without the need for new EIR equipment, thereby reducing overhead.

[0112] The above describes the overall process of the identity verification method provided in the embodiment of the present application in combination with Figure 4. The following describes the specific process of the identity verification method provided in the embodiment of the present application in various scenarios in combination with Figures 5-8.

[0113] Scenario 1:

[0114] Figure 5 is a second schematic diagram of the architecture of the communication system provided in an embodiment of the present application, specifically involving the interaction between the IWF network element (i.e., the first network element mentioned above), the 2 / 3G network EIR (i.e., the second network element mentioned above), and the AMF network element (i.e., the third network element mentioned above). The 2 / 3G network EIR and the IWF network element interact through the Gf interface, and the IWF network element and the AMF network element interact through the N5g-eir interface. Figure 6 is a second flow diagram of the identity verification method provided in this embodiment. The identity verification method is applicable to the above-mentioned communication system. In scenario 1, the IWF network element can serve as a conversion functional entity to convert the first information used to verify the legitimacy of the identity in the 5G network into the second information used to verify the legitimacy of the identity in the 2 / 3G network, thereby realizing signaling conversion between networks of different standards. In the 5G independent networking stage, 2 / 3G network equipment can be used to verify the legitimacy of the user device identity without the need for new equipment, thereby reducing overhead.

[0115] Specifically, as shown in FIG6 , the process of the identity verification method is as follows:

[0116] S601, the AMF network element sends a device identification check signaling message in the N5g-eir interface to the IWF network element. Correspondingly, the IWF network element receives a device identification check signaling message in the N5g-eir interface from the AMF network element.

[0117] The equipment identification check signaling message in the N5g-eir interface, namely the N5g-eir_Equipment Identity Check message, may be signaling in the N5g-eir interface, and may be used to request verification of the legitimacy of the identity of the terminal.

[0118] S602, the IWF network element converts the device identification check signaling message in the N5g-eir interface into an IMEI check signaling message.

[0119] The IMEI check signaling message, namely the Check IMEI message, can be a signaling in the 2 / 3G EIR device interface, and can be used to request a check on the legitimacy of the IMEI, thereby verifying the legitimacy of the terminal's identity. In the process of converting the N5g-eir_Equipment Identity Check message to the Check IMEI message, the mapping rules between the parameters in the N5g-eir_Equipment Identity Check message and the parameters in the Check IMEI message are involved. The parameter mapping rules are shown in Table 1:

[0120] Table 1: Parameter mapping rules

[0121] It can be seen that the parameters in the N5g-eir_Equipment Identity Check message may specifically include PEI, SUPI, GPSI and supported-feature. For specific implementation, please refer to the relevant introduction in S402 above, which will not be repeated here. The parameters in the Check IMEI message may specifically include IMEI, USER-INFORMATION, requested equipment information (Requested Equipment Info) and extension parameters (Extension Container). Among them, the specific implementation of IMEI may refer to the relevant introduction in S402 above, which will not be repeated here. There are no information elements corresponding to GPSI and supported-features in the Check IMEI message, so no conversion is required. USER-INFORMATION can be carried in the transaction capabilities application part protocol (TCAP) session layer. The value of Requested Equipment Info refers to the value range of Equipment Status. Extension Container is an optional field and may not be carried in the Check IMEI message.

[0122] S603: The IWF network element sends a check IMEI signaling message to the 2 / 3G network EIR.

[0123] Correspondingly, the 2 / 3G network EIR receives the Check IMEI message and verifies the legitimacy of the terminal's identity based on the IMEI, USER-INFORMATION and other parameters carried in the Check IMEI message. The 2 / 3G network EIR carries the terminal's identity verification result in the Check IMEI ACK message and sends it to the IWF network element.

[0124] S604: The IWF network element receives a response message of the IMEI check signaling returned by the 2 / 3G network EIR.

[0125] The response message of the IMEI check signaling is the Check IMEI ACK message.

[0126] S605, the IWF network element converts the response message of the IMEI check signaling into a response message of the device identification check signaling in the N5g-eir interface.

[0127] The response message to the equipment identity check signaling in the N5g-eir interface is the N5g-eir_Equipment Identity Check Response message. The Check IMEI ACK message can be signaling in the 2 / 3G EIR device interface or a response message to the Check IMEI message. The process of converting the Check IMEI ACK message to the N5g-eir_Equipment Identity Check Response message involves mapping rules between parameters in the Check IMEI ACK message and parameters in the N5g-eir_Equipment Identity Check Response message, i.e., response parameter mapping rules, as shown in Table 2:

[0128] Table 2: Response parameter mapping rules

[0129] It can be seen that the parameters in the N5g-eir_Equipment Identity Check Response message may specifically include Eir Response Data::=Status:, "WHITELISTED", "BLACKLISTED" and "GREYLISTED", which can respectively represent the terminal's device status information, whitelist, blacklist and graylist. The parameters in the Check IMEI ACK message may specifically include Equipment Status::=ENUMERATED, White Listed(0), Black Listed(1) and Grey Listed(2), which can respectively represent the terminal's device status information, whitelist, blacklist and graylist, and have a corresponding relationship with the parameters in the N5g-eir_Equipment Identity Check Response message. For specific implementation, please refer to the relevant introduction in S402 above, which will not be repeated here.

[0130] In addition, the conversion between the N5g-eir_Equipment Identity Check Response message and the Check IMEI ACK message can also include the conversion of response codes. The response codes in the N5g-eir_Equipment Identity Check Response message can include: 200 ok, 404 Not Found (ERROR_EQUIPMENT_UNKNOWN), 504 Gateway Timeout (TARGET_NF_NOT_REACHABLE), and 503 Service Unavailable. 200 ok can be the response result of the N5g-eir_Equipment Identity Check Response message, indicating that the 2 / 3G EIR device is processing normally. If the Check IMEI ACK message carries the Equipment Status information element, the EIR device is considered to be processing normally. 404 Not Found indicates an unknown device error, that is, the corresponding 2 / 3G EIR device is not found and the 2 / 3G EIR device does not respond. The parameter corresponding to 404 Not Found in the Check IMEI ACK message is Unknown Equipment. 504Gateway Timeout indicates a request timeout, an error caused by the 2 / 3G EIR device failing to respond in a timely manner. The parameter corresponding to 404Not Found in the Check IMEI ACK message is MAP_P_ABORT. 503Service Unavailable indicates access failure, which may be caused by system resource limitations, network congestion, or the 2 / 3G EIR device being turned off. The parameter corresponding to 503Service Unavailable in the Check IMEI ACK message is MAP_U_ABORT, indicating that some mobile application protocols have caused the termination of an abnormal process.

[0131] S606, the IWF network element sends a response message of the device identification check signaling in the N5g-eir interface to the AMF network element.

[0132] Correspondingly, the AMF network element receives the N5g-eir_Equipment Identity Check Response message, that is, it receives the identity legitimacy verification result of the terminal, and then realizes the registration of the terminal in the 5G network.

[0133] It can be understood that the IWF network element can serve as a conversion functional entity to convert the first information used to verify the legitimacy of the identity in the 5G network into the second information used to verify the legitimacy of the identity in the 2 / 3G network, thereby realizing signaling conversion between networks of different standards. In the 5G independent networking stage, 2 / 3G network equipment can be used to verify the legitimacy of the user device identity without the need for new equipment, thereby reducing overhead.

[0134] Scenario 2:

[0135] Figure 7 is the third architectural diagram of the communication system provided in the embodiment of the present application, which specifically involves the interaction between the IWF network element (i.e., the first network element mentioned above), the 4G network EIR (i.e., the second network element mentioned above), and the AMF network element (i.e., the third network element mentioned above). The 4G network EIR and the IWF network element interact through the S13 / S13' interface, and the IWF network element and the AMF network element interact through the N5g-eir interface. Figure 8 is the third flow diagram of the identity verification method provided in the present embodiment. The identity verification method is applicable to the above-mentioned communication system. In scenario 2, the IWF network element can serve as a conversion functional entity to convert the first information used to verify the legitimacy of the identity in the 5G network into the second information used to verify the legitimacy of the identity in the 4G network, thereby realizing signaling conversion between networks of different standards. In the 5G independent networking stage, 4G network equipment can be used to verify the legitimacy of the user device identity without the need for new equipment, thereby reducing overhead.

[0136] Specifically, as shown in FIG8 , the process of the identity verification method is as follows:

[0137] S801, the IWF network element receives the device identification check signaling message in the N5g-eir interface from the AMF network element.

[0138] The N5g-eir_Equipment Identity Check message may be signaling in the N5g-eir interface, and may be used to request verification of the legitimacy of the terminal's identity.

[0139] S802, the IWF network element converts the device identification check signaling message in the N5g-eir interface into an ECR message.

[0140] The ECR message can be a signaling in the 4G EIR device interface, which can be used to request the legitimacy of the IMEI to verify the legitimacy of the terminal. In the process of converting the N5g-eir_Equipment Identity Check message into the ECR message, the mapping rules between the parameters in the N5g-eir_Equipment Identity Check message and the parameters in the ECR message are involved. The parameter mapping rules are shown in Table 3:

[0141] Table 3: Parameter mapping rules

[0142] It can be seen that the parameters in the N5g-eir_Equipment Identity Check message can specifically include PEI, SUPI, GPSI and supported-feature. For specific implementation, please refer to the relevant introduction in S402 above, which will not be repeated here. The parameters in the ECR message can specifically include the IMEI field in Terminal-Information, User-NAME and Software-Version in Terminal-Information, among which the IMEI field in Terminal-Information is equivalent to the IMEI information, and User-NAME can be IMSI information. For specific implementation, please refer to the relevant introduction in S402 above, which will not be repeated here. There are no information elements corresponding to GPSI and supported-features in the ECR message, so no conversion is required. The Software-Version in Terminal-Information can be a parameter that is not included in the N5g-eir_Equipment Identity Check message. When performing signaling conversion, if PEI is the software version number of the device (IMEI software version, IMEISV), the 15 / 16-digit number is converted into an integer and assigned to the Software-Version in Terminal-Information.

[0143] S803, the IWF network element sends an ECR message to the 4G network EIR.

[0144] Correspondingly, the 4G network EIR receives the ECR message and verifies the legitimacy of the terminal's identity based on the Terminal-Information, User-NAME and other parameters carried in the ECR message. The 4G network EIR carries the result of the terminal's identity verification in the ECA message and sends it to the IWF network element.

[0145] S804: The IWF network element receives the ECA message returned by the 4G network EIR.

[0146] S805, the IWF network element converts the ECA message into a response message of the device identification check signaling in the N5g-eir interface.

[0147] The ECA message can be signaling in the 4G EIR device interface or a response message to the ECR message. The process of converting the ECA message to the N5g-eir_Equipment Identity Check Response message involves mapping rules between parameters in the ECA message and parameters in the N5g-eir_Equipment Identity Check Response message, i.e., response parameter mapping rules, as shown in Table 4:

[0148] Table 4: Response parameter mapping rules

[0149] It can be seen that the parameters in the N5g-eir_Equipment Identity Check Response message may specifically include Eir Response Data::=Status:, "WHITELISTED", "BLACKLISTED", and "GREYLISTED", which may respectively represent the terminal's device status information, whitelist, blacklist, and graylist. The parameters in the ECA message may specifically include Equipment-Status:, WHITELISTED(0), BLACKLISTED(1), and GREYLISTED(2), which may respectively represent the terminal's device status information, whitelist, blacklist, and graylist. These parameters correspond to the parameters in the N5g-eir_Equipment Identity Check Response message. For specific implementation, please refer to the relevant introduction in S402 above, which will not be repeated here.

[0150] In addition, the conversion between the N5g-eir_Equipment Identity Check Response message and the ECA message can also include the conversion of response codes. The response codes in the N5g-eir_Equipment Identity Check Response message can include: 200ok, 404Not Found (ERROR_EQUIPMENT_UNKNOWN), 504Gateway Timeout (TARGET_NF_NOT_REACHABLE), and 503Service Unavailable. For details, please refer to the description in Scenario 1 and will not be repeated here. The parameter corresponding to 200ok in the ECA message is DIAMETER_SUCCESS (2001), indicating that the 4G EIR equipment is processing normally. The parameter corresponding to 404Not Found in the ECA message is DIAMETER_ERROR_EQUIPMENT_UNKNOWN (5422), indicating an error of an unknown device. The parameter corresponding to 404 Not Found in the ECA message is 3002 DIAMETER_UNABLE_TO_DELIVER, indicating that the 4G EIR device failed to respond in time. The parameter corresponding to 503 Service Unavailable in the ECA message is 3004 DIAMETER_TOO_BUSY, which may be caused by system resource limitations, network congestion, or the 4G EIR device being turned off.

[0151] S806, the IWF network element sends a response message of the device identification check signaling in the N5g-eir interface to the AMF network element.

[0152] Correspondingly, the AMF network element receives the N5g-eir_Equipment Identity Check Response message, that is, it receives the identity legitimacy verification result of the terminal, and then realizes the registration of the terminal in the 5G network.

[0153] It can be understood that the IWF network element can serve as a conversion functional entity to convert the first information used to verify the legitimacy of the identity in the 5G network into the second information used to verify the legitimacy of the identity in the 4G network, thereby realizing signaling conversion between networks of different standards. In the 5G independent networking stage, 4G network equipment can be used to verify the legitimacy of the user device identity without the need for new equipment, thereby reducing overhead.

[0154] The method provided by the embodiment of the present application is described in detail above in conjunction with Figures 4 to 8. The communication device for executing the identity verification method provided by the embodiment of the present application is described in detail below in conjunction with Figures 9 and 10.

[0155] Figure 9 is a structural diagram of a communication device according to an embodiment of the present application. As shown in Figure 9 , the communication device 900 includes a transceiver module 901 and a processing module 902. For ease of illustration, Figure 9 only shows the main components of the communication device.

[0156] The transceiver module 901 is used to perform the transceiver function of the method shown in FIG. 4 , and the processing module 902 is used to perform other functions of the method shown in FIG. 4 except the transceiver function.

[0157] Optionally, the transceiver module 901 may include a sending module (not shown in FIG9 ) and a receiving module (not shown in FIG9 ). The sending module is used to implement the sending function of the communication device 900 , and the receiving module is used to implement the receiving function of the communication device 900 .

[0158] Optionally, the communication device 900 may further include a storage module (not shown in FIG9 ) that stores a program or instruction. When the processing module 902 executes the program or instruction, the communication device 900 may perform the functions of the terminal or network device in the method shown in FIG4 in the above method.

[0159] It can be understood that the communication device 900 can be a terminal or a network device, or a chip (system) or other parts or components that can be set in a terminal or a network device, or a device that includes a terminal or a network device. This application does not limit this.

[0160] In addition, the technical effects of the communication device 900 can refer to the technical effects of the identity verification method shown in Figures 4 to 8, and will not be repeated here.

[0161] Figure 10 is a second structural diagram of a communication device provided in an embodiment of the present application. Exemplarily, the communication device may be a terminal, or a chip (system) or other component or assembly that can be provided in a terminal. As shown in Figure 10, the communication device 1000 may include a processor 1001. Optionally, the communication device 1000 may further include a memory 1002 and / or a transceiver 1003. The processor 1001 is coupled to the memory 1002 and / or the transceiver 1003, such as by connecting via a communication bus, by connecting via an interface within the chip, or by connecting via other communication lines. Optionally, the memory 1002 may be integrated with the processor 1001.

[0162] The following is a detailed introduction to the various components of the communication device 1000 in conjunction with FIG10 :

[0163] The processor 1001 is the control center of the communication device 1000 and can be a single processor or a collective term for multiple processing elements. For example, the processor 1001 can be one or more central processing units (CPUs), an application specific integrated circuit (ASIC), or one or more integrated circuits configured to implement the embodiments of the present application, such as one or more digital signal processors (DSPs) or one or more field programmable gate arrays (FPGAs).

[0164] Optionally, the processor 1001 can execute various functions of the communication device 1000 by running or executing software programs stored in the memory 1002 and calling data stored in the memory 1002, such as executing the identity verification method shown in Figure 8 above.

[0165] In a specific implementation, as an embodiment, the processor 1001 may include one or more CPUs, such as CPU0 and CPU1 shown in FIG10 .

[0166] In a specific implementation, as an embodiment, the communication device 1000 may also include multiple processors, such as the processor 1001 and the processor 1004 shown in FIG10 . Each of these processors may be a single-core processor (single-CPU) or a multi-core processor (multi-CPU). The processor herein may refer to one or more devices, circuits, and / or processing cores for processing data (e.g., computer program instructions).

[0167] The memory 1002 is used to store the software program for executing the solution of the present application, and the execution is controlled by the processor 1001. The specific implementation method can refer to the above method embodiment and will not be repeated here.

[0168] Alternatively, the memory 1002 may be a read-only memory (ROM) or other type of static storage device that can store static information and instructions, a random access memory (RAM) or other type of dynamic storage device that can store information and instructions, or an electrically erasable programmable read-only memory (EEPROM), a compact disc read-only memory (CD-ROM) or other optical disc storage, an optical disc storage (including a compact disc, laser disc, optical disc, digital versatile disc, Blu-ray disc, etc.), a magnetic disk storage medium or other magnetic storage device, or any other medium that can be used to carry or store desired program code in the form of instructions or data structures and can be accessed by a computer, but is not limited thereto. The memory 1002 may be integrated with the processor 1001 or exist independently and be coupled to the processor 1001 via an interface circuit (not shown in FIG. 10 ) of the communication device 1000. This embodiment of the present application does not specifically limit this.

[0169] Transceiver 1003 is used for communication with other communication devices. For example, if communication device 1000 is a terminal, transceiver 1003 can be used to communicate with a network device or another terminal device. For another example, if communication device 1000 is a network device, transceiver 1003 can be used to communicate with a terminal or another network device.

[0170] Optionally, the transceiver 1003 may include a receiver and a transmitter (not shown separately in FIG10 ), wherein the receiver is used to implement a receiving function, and the transmitter is used to implement a sending function.

[0171] Optionally, the transceiver 1003 may be integrated with the processor 1001 or exist independently and be coupled to the processor 1001 through an interface circuit (not shown in FIG. 10 ) of the communication device 1000 . This embodiment of the present application does not specifically limit this.

[0172] It is understandable that the structure of the communication device 1000 shown in FIG10 does not constitute a limitation on the communication device, and an actual communication device may include more or fewer components than shown in the figure, or combine certain components, or arrange the components differently.

[0173] In addition, the technical effects of the communication device 1000 can refer to the technical effects of the methods described in the above method embodiments, and will not be repeated here.

[0174] It should be understood that the processor in the embodiments of the present application may be a central processing unit (CPU), and the processor may also be other general-purpose processors, digital signal processors (DSP), application-specific integrated circuits (ASIC), field programmable gate arrays (FPGA) or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor may be a microprocessor or any conventional processor, etc.

[0175] It should also be understood that the memory in the embodiments of the present application may be a volatile memory or a non-volatile memory, or may include both volatile and non-volatile memories. Among them, the non-volatile memory may be a read-only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM), or a flash memory. The volatile memory may be a random access memory (RAM), which is used as an external cache. By way of example and not limitation, many forms of random access memory (RAM) are available, such as static RAM (SRAM), dynamic random access memory (DRAM), synchronous DRAM (SDRAM), double data rate SDRAM (DDR SDRAM), enhanced SDRAM (ESDRAM), synchronous link DRAM (SLDRAM), and direct rambus RAM (DR RAM).

[0176] The above embodiments can be implemented in whole or in part by software, hardware (such as circuits), firmware or any other combination. When implemented using software, the above embodiments can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions or computer programs. When the computer instructions or computer program are loaded or executed on a computer, the process or function described in the embodiment of the present application is generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another computer-readable storage medium. For example, the computer instructions can be transmitted from one website, computer, server or data center to another website, computer, server or data center via a wired (such as infrared, wireless, microwave, etc.) method. The computer-readable storage medium can be any available medium that can be accessed by a computer or a data storage device such as a server or data center that contains one or more available media sets. The available medium can be a magnetic medium (for example, a floppy disk, a hard disk, a tape), an optical medium (for example, a DVD), or a semiconductor medium. The semiconductor medium can be a solid-state drive.

[0177] It should be understood that the term "and / or" as used herein simply describes a relationship between associated objects, indicating that three possible relationships exist. For example, "A and / or B" can represent: A alone, A and B together, or B alone. A and B can be singular or plural. Furthermore, the character " / " as used herein generally indicates an "or" relationship between the associated objects, but it may also indicate an "and / or" relationship. For specific understanding, please refer to the context.

[0178] In this application, "at least one" means one or more, and "plurality" means two or more. "At least one of the following" or similar expressions refers to any combination of these items, including any combination of single or plural items. For example, at least one of a, b, or c can mean: a, b, c, ab, ac, bc, or abc, where a, b, and c can be single or plural.

[0179] It should be understood that in the various embodiments of the present application, the size of the serial numbers of the above-mentioned processes does not mean the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of the present application.

[0180] Those skilled in the art will appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.

[0181] Those skilled in the art will clearly understand that, for the convenience and brevity of description, the specific working processes of the systems, devices and units described above can refer to the corresponding processes in the aforementioned method embodiments and will not be repeated here.

[0182] In the several embodiments provided in this application, it should be understood that the disclosed systems, devices and methods can be implemented in other ways. For example, the device embodiments described above are merely schematic. For example, the division of the units is merely a logical function division. In actual implementation, there may be other division methods, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of devices or units, which can be electrical, mechanical or other forms.

[0183] The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of these units may be selected to achieve the purpose of this embodiment according to actual needs.

[0184] In addition, each functional unit in each embodiment of the present application may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit.

[0185] If the functions are implemented in the form of software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application, or the part that contributes to the prior art, or the part of the technical solution, can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions for enabling a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the method described in each embodiment of the present application. The aforementioned storage medium includes various media that can store program codes, such as a USB flash drive, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk.

Claims

1. A method for verifying identity, characterized in that, Applied to a first network element, including: During the process of the terminal registering to the first network, the first network element obtains first information, where the first information is the information used to verify the identity legality of the terminal in the first network; The first network element sends second information to a second network element according to the first information, where the second information is the information used to verify the identity legality of the terminal in the second network, the first network and the second network are networks of different systems, and the second network element is used to verify the identity legality of the terminal in the second network; The first network element obtains the identity legality verification result of the terminal from the second network element.

2. The method according to claim 1, wherein The first information includes at least one of the following of the terminal: a first device identifier, or a first user identity identifier, the first device identifier is used to verify the device legality of the terminal in the first network, and the first user identity identifier is used to verify the identity legality of the user using the terminal in the first network.

3. The method according to claim 2, wherein The first device identifier includes a permanent equipment identifier (PEI), and the first user identity identifier includes a subscriber permanent identifier (SUPI).

4. The method according to any one of claims 1 to 3, characterized in that, The second information includes at least one of the following of the terminal: a second device identifier, or a second user identity identifier, the second device identifier is used to verify the device legality of the terminal in the second network, and the second user identity identifier is used to verify the identity legality of the user using the terminal in the second network.

5. The method according to claim 4, wherein The second device identifier includes an international mobile equipment identity (IMEI) or terminal information, and the second user identity identifier includes user information or an international mobile subscriber identity (IMSI).

6. The method according to any one of claims 1 to 5, characterized in that The first information and the second information have a corresponding relationship.

7. The method according to claim 1, characterized in that The first network element obtaining the identity legality verification result of the terminal from the second network element includes: The first network element receives the identity legality verification result returned by the second network element based on the second information, and the identity legality verification result is used to represent whether the identity of the terminal in the second network is legal.

8. The method according to claim 7, wherein If the identity of the terminal in the second network is legal, then the identity of the terminal in the first network is also legal; otherwise, the identity of the terminal in the first network is illegal.

9. The method according to claim 8, wherein The obtaining of the first information includes: The first network element receives the first information from a third network element, where the third network element is a network element in the first network; Correspondingly, the method further includes: The first network element sends information for indicating whether the identity of the terminal in the first network is legal to the third network element.

10. The method according to any one of claims 7 to 9, characterized in that The identity legality verification result is further used to indicate the device status information of the terminal, and the device status information includes that the terminal is included in a white list, or the terminal is included in a black list, or the terminal is included in a gray list.

11. The method according to any one of claims 1 to 10, characterized in that, The first network includes a 5G network, and the second network includes a 2 / 3G network, or a 4G network.

12. The method according to any one of claims 1 to 11, characterized in that, The first information is carried in the signaling in the 5G device identity registration device interface, and the second information is carried in the signaling in the 2 / 3G device identity registration device interface or the signaling in the 4G device identity registration device interface.

13. A method for verifying identity, characterized in that, Applied to a second network element, including: During the process of the terminal registering to the first network, the second network element receives the second information sent by the first network element according to the first information, where the first information is the information used to verify the identity legality of the terminal in the first network, the second information is the information used to verify the identity legality of the terminal in the second network, and the first network and the second network are networks of different systems; The second network element verifies the identity legality of the terminal in the second network based on the second information; The second network element sends the identity legality verification result of the terminal to the first network element.

14. A communication device, characterized in that, The device includes: a module for executing the method according to any one of claims 1-13.

15. A communication device, characterized in that, The communication device includes: a processor and a memory; the memory is used to store computer instructions, and when the processor executes the instructions, the method according to any one of claims 1-13 is executed.

16. A computer-readable storage medium, characterized in that, The computer-readable storage medium includes computer programs or instructions, and when the computer programs or instructions run on a computer, the computer is caused to execute the method according to any one of claims 1-13.

Citation Information

Patent Citations

  • Identity verification method and device

    CN120238863A

  • System and method for seamless user equipment authentication

    US11184356B1

  • METHODS, SYSTEMS, AND COMPUTER READABLE MEDIA FOR PROVIDING SERVICE-BASED INTERFACE (SBI) SUPPORT FOR NETWORK FUNCTIONS (NFs) NOT SUPPORTING SBI SERVICE OPERATIONS

    US20220322270A1