Authentication method, communication apparatus, and storage medium

By generating and sending authentication vectors by visiting domain data management network elements, the problem of terminal inaccessibility caused by home domain network elements is solved, and the normal authentication and access of terminals in the visiting domain is realized, and the distributed architecture of 6G network is adapted to.

WO2025139415A1PCT designated stage expired Publication Date: 2025-07-03ZTE CORP
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
PCT/CN2024/131278
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2023-12-28
Filing Date
2024-11-11
Publication Date
2025-07-03

AI Technical Summary

Technical Problem

In 5G networks, when the network elements related to the authentication service in the home domain fail, the terminal cannot access the network normally, especially under the distributed network architecture, how to ensure that the terminal can perform effective authentication and access in the visiting domain.

Method used

By receiving the request message of the authentication service network element in the access domain, generating and sending the terminal's authentication vector, local authentication of the terminal is realized, ensuring that the terminal can access the visiting domain network normally under the abnormal situation of the home domain element.

Benefits of technology

It solves the problem that the terminal cannot access when the home domain element is abnormal, realizes normal authentication and network access of the terminal in the visiting domain, and adapts to the distributed architecture requirements of the future 6G network.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2024131278_03072025_PF_FP_ABST
    Figure CN2024131278_03072025_PF_FP_ABST
Patent Text Reader

Abstract

The present disclosure provides an authentication method, a communication apparatus, and a storage medium. The authentication method comprises: a data management network element in a visited domain receives a first request message sent by an authentication service network element in the visited domain, the first request message being used for requesting an authentication vector of a terminal roaming into the visited domain; and the data management network element in the visited domain sends a first response message to the authentication service network element in the visited domain, the first response message comprising the authentication vector of the terminal.
Need to check novelty before this filing date? Find Prior Art

Description

Authentication method, communication device and storage medium

[0001] This application claims priority to Chinese patent application No. 202311838353.4 filed on December 28, 2023, the entire contents of which are incorporated by reference into this application. Technical Field

[0002] The present disclosure relates to the field of communication technology, and in particular to an authentication method, a communication device, and a storage medium. Background Art

[0003] In the authentication process of the relevant fifth-generation mobile communication technology (5G), if the authentication service-related network elements in the home domain fail, such as the authentication service network element, data management network element, and data warehouse network element, the connected users can only use the relevant security context for encryption and security processing.

[0004] Summary of the Invention

[0005] On the one hand, an authentication method is provided, which is applied to a data management network element in a visited domain. The authentication method includes: receiving a first request message sent by an authentication service network element in the visited domain, the first request message being used to request an authentication vector of a terminal roaming to the visited domain; and sending a first response message to the authentication service network element in the visited domain, the first response message including an authentication vector of the terminal.

[0006] On the other hand, an authentication method is provided, which is applied to an authentication service network element in a visited domain. The authentication method includes: sending a first request message to a data management network element in the visited domain, the first request message being used to request an authentication vector for a terminal roaming into the visited domain; and receiving a first response message sent by the data management in the visited domain, the first response message including the authentication vector of the terminal.

[0007] In another aspect, an authentication device is provided for use in a data management network element in a visited domain. The authentication device includes: a communication module configured to receive a first request message sent by an authentication service network element in the visited domain, the first request message being used to request an authentication vector for a terminal roaming into the visited domain; and a communication module configured to send a first response message to the authentication service network element in the visited domain, the first response message including the authentication vector of the terminal.

[0008] In another aspect, an authentication device is provided for use in an authentication service network element in a visited domain. The authentication device includes a communication module and a processing module. The communication module is configured to send a first request message to a data management network element in the visited domain, the first request message being used to request an authentication vector for a terminal roaming into the visited domain. The communication module is further configured to receive a first response message from the data management network element in the visited domain, the first response message including the authentication vector of the terminal. The processing module is configured to authenticate the terminal based on the authentication vector of the terminal.

[0009] In another aspect, a communication device is provided, comprising: a memory and a processor. The memory is coupled to the processor; the memory is used to store computer program instructions executable by the processor; and the processor implements the above-mentioned authentication method when executing the computer program instructions.

[0010] On the other hand, a computer-readable storage medium is provided, on which computer program instructions are stored. When the computer program instructions are executed on a computer (such as a communication device or an authentication device), the above-mentioned authentication method is implemented.

[0011] In another aspect, a computer program product is provided, which includes computer program instructions, and the computer program instructions implement the above authentication method when executed. BRIEF DESCRIPTION OF THE DRAWINGS

[0012] FIG1 is a flow chart of an authentication method in a 5G network according to an embodiment of the present disclosure.

[0013] FIG2 is a schematic diagram of key generation and distribution according to an embodiment of the present disclosure.

[0014] FIG3 is a schematic diagram of the architecture of a 5G network according to an embodiment of the present disclosure.

[0015] FIG4 is an interactive flow chart of an authentication method according to an embodiment of the present disclosure.

[0016] FIG5 is an interactive flow chart of another authentication method according to an embodiment of the present disclosure.

[0017] FIG6 is an interactive flow chart of another authentication method according to an embodiment of the present disclosure.

[0018] FIG7 is an interactive flow chart of another authentication method according to an embodiment of the present disclosure.

[0019] FIG8 is a schematic structural diagram of an authentication device according to an embodiment of the present disclosure.

[0020] FIG9 is a schematic structural diagram of another authentication device according to an embodiment of the present disclosure.

[0021] FIG10 is a schematic structural diagram of a communication device according to an embodiment of the present disclosure. DETAILED DESCRIPTION

[0022] The following will be combined with the accompanying drawings in the embodiments of the present disclosure to clearly and completely describe the technical solutions in the embodiments of the present disclosure. Obviously, the embodiments described are only part of the embodiments of the present disclosure, not all of the embodiments. Based on the embodiments of the present disclosure, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of the present disclosure.

[0023] In the description of the present disclosure, unless otherwise specified, " / " means "or", for example, A / B can mean A or B. "And / or" in this article is only used to describe the association relationship of associated objects, indicating that there can be three relationships. For example, A and / or B can mean: only A, only B, and A and B. In addition, "at least one" means one or more, and "a plurality" means two or more. Words such as "first" and "second" do not limit the quantity and execution order, and words such as "first" and "second" do not limit them to be necessarily different.

[0024] It should be noted that, in this disclosure, words such as "exemplary" or "for example" are used to describe examples, illustrations, or explanations. Any embodiment or design described in this disclosure using words such as "exemplary" or "for example" should not be interpreted as being more preferred or advantageous than other embodiments or designs. Rather, the use of words such as "exemplary" or "for example" is intended to present the relevant concepts in a concrete manner.

[0025] Authentication in 5G networks is a centralized control architecture. When roaming, user equipment (UE) must authenticate in its home domain. For example, as shown in Figure 1, the authentication process is described below using 5G Authentication and Key Agreement (5G-AKA) authentication in a 5G network as an example.

[0026] 1. The UE sends an access request message to the access and mobility management function (AMF) (or security anchor functionality (SEAF)) to request access to the 5G system (5G system). The access request message carries the subscription concealed identifier (SUCI) or the 5G globally unique temporary identifier (5G-GUTI).

[0027] 2. AMF determines that the UE needs to be authenticated, and sends a first authentication request message (Nausf_UEAuthentication_Authenticate Request) to the authentication service network element (authentication server function, AUSF) (denoted as hAUSF) in the home domain, and calls hAUSF to perform UE authentication service operation with SUCI or subscription permanent identifier (SUPI) as the identifier.

[0028] 3. The hAUSF sends a Nudm_UEAuthentication_Get Request message to the Unified Data Management (UDM) (or the Authentication Credential Repository and Processing Function (ARPF)) in the home domain to obtain the UE's authentication vector. If the Nudm_UEAuthentication_Get Request message carries the SUCI, the UDM (hUDM) (or the ARPF) in the home domain needs to decrypt the SUCI into the SUPI.

[0029] 4. hUDM calls the Nudr server to the unified data repository (UDR) in the home domain (referred to as hUDR) to obtain the UE's authentication data.

[0030] The UE authentication data includes the authentication algorithm, the encrypted key (PermanentKey), the encrypted operator secondary key (OPC), the protection parameter identifier (protectionParameterid) used to decrypt the PermanentKey and OPC, and the sequence number (SQN).

[0031] 5. hUDM generates the UE's authentication vector (5G HE AV) based on the UE's authentication data. The calculation process is as follows (1) to (3).

[0032] (1) Run the UMTS AKA (Universal Mobile Telecommunications System Authentication and Key Agreement) algorithm to calculate and generate the specified number of authentication groups AV (RAND, XRES, CK, IK, AUTN). When generating the UE's authentication vector, the AMF separation bit (bit 0 of the AMF) should be set to 1.

[0033] (2) Call the key derivation function (KDF) to calculate and generate KAUSF and XRES* again, and assemble them into a set of 5G HE AV (RAND, AUTN, XRES*, KAUSF).

[0034] (3) Update the user's latest SQNhe to hUDR.

[0035] 6. hUDM returns an Authentication Acquisition Response message to hAUSF, which carries the 5G HE AV. If the Authentication Acquisition Response message also carries the SUCI, the first Authentication Response message returned to hAUSF shall also carry the SUPI.

[0036] 7. hAUSF temporarily stores XRES* and generates 5G SE AV (RAND, AUTN, HXRES*, KSEAF) according to 5G HE AV. HXRES* is generated by XRES*; Kseaf is generated by Kausf.

[0037] 8. hAUSF returns the first authentication response message (Nausf_UEAuthentication_Authenticate Response) to AMF (or SEAF), carrying the 5G SE AV.

[0038] 9. The AMF (or SEAF) returns a second authentication request message (Authenticate Request) to the UE, which carries RAND and AUTN.

[0039] After receiving the second authentication request message, the terminal Universal Subscriber Identity Module (USIM) verifies the message authentication code (MAC). If the verification fails, it is treated as an authentication failure; the USIM verifies the SQN. If it fails, it initiates authentication weight synchronization.

[0040] After completing the above verification, the USIM and mobile equipment (ME) continue the following processing: the USIM refers to the EPS (Evolved Packet System) AKA method to calculate and generate RES / CK / IK.

[0041] 10. The ME continues to calculate RES* based on the RES generated by the USIM (the method is the same as the UDM calculates XRES* based on XRES).

[0042] The ME calculates KAUSF based on CK||IK in the same way as the network side, and calculates KSEAF based on KAUSF.

[0043] NOTE: The ME shall confirm that the separation bit (bit 0 of AMF) of the AMF field in the authentication parameters is set to 1.

[0044] 11. The UE returns a second authentication response message (Authenticate Response) to the AMF (or SEAF), where the second authentication response message includes RES*.

[0045] 12. The AMF (or SEAF) receives the RES* returned by the UE, calculates the HRES* based on the RES*, and compares the HRES* with the HXRES*. If the HRES* and HXRES* match, the SEAF considers the authentication successful; otherwise, the SEAF rejects the authentication.

[0046] If the UE is unreachable or SEAF does not receive RES* from the UE, SEAF considers the authentication failed and returns a failure response to AUSF, while sending an Authentication Reject message to the UE.

[0047] 13. If the authentication is successful, the AMF (or SEAF) will send a third authentication request message (Nausf_UEAuthentication_Authenticate Request) to the hAUSF. The third authentication request message includes RES* and the UE identifier so that the hAUSF can perform authentication confirmation.

[0048] 14. hAUSF checks whether the authentication AV has expired. If so, hAUSF considers the authentication confirmation failed. Otherwise, hAUSF compares the received RES* with the saved XRES*. If they match, hAUSF considers the confirmation message verified.

[0049] 15. hAUSF sends a third authentication response message (Nausf_UEAuthentication_Authenticate Response) to AMF (or SEAF), where the third authentication response message carries the authentication confirmation result.

[0050] If the previous authentication request carries SUCI, if the authentication is successful, the third authentication response message should carry SUPI.

[0051] If the authentication is successful, the AUSF returns K as shown in FIG2. SEAF As the anchor key of SEAF. AMF is based on K SEAF Derived K AMF .

[0052] In the authentication process of the relevant 5G network, if the home domain hAUSF / hUDM / hUDR fails, the connected user can only use the relevant security context for encryption and security processing. When the security context maintained on the terminal side or the network side is deleted due to some abnormality, due to security constraints (the terminal will verify the correctness of NAS (Non-access stratum) signaling integrity protection), the terminal will be unable to access the network subsequently.

[0053] To meet the business requirements of diverse scenarios, 6G networks need to achieve three-dimensional coverage in the air, space, land, and sea, as well as the integrated coexistence of multiple heterogeneous networks. At the same time, the converged development of data, optical, information, and communication technology (DOICT) is driving the continued openness of communication networks, enabling both centralized network control and flexible access to nearby forwarding equipment and local traffic diversion. Therefore, the future 6G network architecture will be a new type of network architecture that integrates centralized mobile communication networks with the open Internet, with centralized and distributed coexistence. Its key elements include: distributed access, distributed connectivity, distributed computing, distributed data, and distributed trust.

[0054] The distributed network architecture of 6G includes the following concepts.

[0055] Intra-domain autonomy: A certain number of wireless base stations, infrastructure, and distributed core networks form an independent autonomous domain within a certain spatial range.

[0056] Inter-domain interconnection: Network coverage is expanded through autonomous inter-domain interconnection. When the network needs to increase coverage or access capacity, the original network is basically unaffected.

[0057] Inter-domain migration: When users move across the edge of an autonomous domain, they need to migrate between autonomous domains to achieve multi-domain access and seamless switching.

[0058] Distributed intra-domain autonomy is a key feature of 6G. When hUDM is abnormal, the access subdomain should be able to operate normally. How to ensure that users can access normally when the security context is discarded is a problem that needs to be solved.

[0059] In view of this, the present disclosure proposes an authentication method in which a data management network element in a visited domain receives a first request message sent by an authentication service network element in a visited domain, the first request message being used to request an authentication vector for a terminal roaming into the visited domain. The data management network element in the visited domain then sends a first response message to the authentication service network element in the visited domain, the first response message including the terminal's authentication vector. In this way, the authentication service network element in the visited domain can locally authenticate the terminal roaming into the visited domain based on the terminal's authentication vector sent by the data management network element in the visited domain. This method solves the problem of being unable to authenticate a terminal when an authentication service-related network element in the home domain is abnormal, ensuring that the terminal can normally access the network after roaming into the visited domain.

[0060] The technical solutions provided by the embodiments of the present disclosure can be applied to various mobile communication networks, for example, new radio (NR) mobile communication networks using fifth-generation mobile communication technology (5G), future mobile communication networks, or systems integrating multiple communication technologies, etc., but the embodiments of the present disclosure are not limited to this.

[0061] For example, Figure 3 is a schematic diagram of the architecture of a 5G network according to the present disclosure. As shown in Figure 3, the 5G network may include user equipment (UE), radio access network (RAN) equipment, UPF, AMF, AUSF, network slice selection function (NSSF), network exposure function (NEF), network exposure function repository function (NRF), UDM, UDR, AF (Application Function) or charging function (CHF), etc.

[0062] As shown in Figure 3, the terminal device accesses the 5G network through the RAN device. The terminal device communicates with the AMF through the N1 interface (referred to as N1); the RAN device communicates with the AMF through the N2 interface (referred to as N2); the RAN device communicates with the UPF through the N3 interface (referred to as N3); the SMF communicates with the UPF through the N4 interface (referred to as N4), and the UPF accesses the data network through the N6 interface (referred to as N6). In addition, the control plane functions shown in Figure 3, such as AUSF, AMF, SMF, NSSF, NEF, NRF, PCF, UDM, UDR, CHF, or AF, interact using service-based interfaces. For example, the service interface provided by AUSF to the outside world is Nausf; the service interface provided by AMF to the outside world is Namf; the service interface provided by SMF to the outside world is Nsmf; the service interface provided by NSSF to the outside world is Nnssf; the service interface provided by NEF to the outside world is Nnef; the service interface provided by NRF to the outside world is Nnrf; the service interface provided by PCF to the outside world is Npcf; the service interface provided by UDM to the outside world is Nudm; the service interface provided by UDR to the outside world is Nudr; the service interface provided by CHF to the outside world is Nchf; and the service interface provided by AF to the outside world is Naf.

[0063] In some embodiments, the terminal device can be a device with wireless transceiver capabilities, which can be deployed on land (including indoors or outdoors, handheld, wearable, or vehicle-mounted); can also be deployed on the water (such as ships, etc.); can also be deployed in the air (for example, on airplanes, balloons, and satellites, etc.). The terminal can be a mobile phone, a tablet computer, a computer with wireless transceiver capabilities, a virtual reality (VR) terminal, an augmented reality (AR) terminal, a wireless terminal in industrial control, a wireless terminal in self-driving, a wireless terminal in remote medical care, a wireless terminal in a smart grid, a wireless terminal in transportation safety, a wireless terminal in a smart city, a wireless terminal in a smart home, etc. The embodiments of the present disclosure do not limit the application scenarios. The terminal may sometimes also be referred to as a user, user equipment, access terminal, UE unit, UE station, mobile station, mobile station, remote station, remote terminal, mobile device, UE terminal, wireless communication equipment, UE agent or UE device, etc., which is not limited to the embodiments of the present disclosure.

[0064] The application scenarios of the embodiments of the present disclosure are not limited. The system architecture and business scenarios described in the embodiments of the present disclosure are intended to more clearly illustrate the technical solutions of the embodiments of the present disclosure and do not constitute a limitation on the technical solutions provided by the embodiments of the present disclosure. It is known to those skilled in the art that with the evolution of network architecture and the emergence of new business scenarios, the technical solutions provided by the embodiments of the present disclosure are also applicable to similar technical problems.

[0065] The embodiment of the present disclosure provides an authentication method. As shown in FIG4 , the authentication method includes the following S101 to S103.

[0066] In S101, an authentication service network element in a visited domain sends a first request message to a data management network element in the visited domain. Correspondingly, the data management network element in the visited domain receives the first request message sent by the authentication service network element in the visited domain. The first request message is used to request an authentication vector for a terminal roaming into the visited domain.

[0067] In some embodiments, after the data management network element in the visited domain receives a first request message sent by the authentication service network element in the visited domain, if the data warehouse network element in the visited domain contains the authentication data of the terminal, the data management network element in the visited domain obtains the authentication data of the terminal from the data warehouse network element in the visited domain; the data management network element in the visited domain generates an authentication vector for the terminal based on the authentication data of the terminal.

[0068] Exemplarily, as shown in FIG5 , assuming that the terminal has roamed through the visited domain in FIG5 , and the data warehouse network element (denoted as vUDR) in the visited domain in FIG5 stores the authentication data of the terminal, when the terminal roams to the visited domain in FIG5 again, if the data management network element in the visited domain in FIG5 receives the first request message corresponding to the terminal sent by the authentication service network element (denoted as vAUSF) in the visited domain, the authentication vector determination process of the terminal may include the following S201 and S202.

[0069] In S201, a data management network element (denoted as vUDM) in a visited domain obtains authentication data of a terminal from a data warehouse network element in the visited domain.

[0070] In S202, the data management network element in the visited domain generates an authentication vector of the terminal based on the authentication data of the terminal.

[0071] In some embodiments, after the data management network element in the visited domain receives the first request message sent by the authentication service network element in the visited domain, the data management network element in the visited domain obtains the authentication data of the terminal from the data warehouse network element in the home domain; and generates an authentication vector for the terminal based on the authentication data of the terminal.

[0072] In some embodiments, after the data management network element in the visited domain receives a first request message sent by the authentication service network element in the visited domain, if the data warehouse network element in the visited domain does not contain the authentication data of the terminal, the data management network element in the visited domain obtains the authentication data of the terminal from the data management network element in the home domain; and generates an authentication vector for the terminal based on the authentication data of the terminal.

[0073] Exemplarily, after the data management network element in the visited domain receives the first request message sent by the authentication service network element in the visited domain, the data management network element in the visited domain first obtains the authentication data of the terminal from the data warehouse network element in the visited domain; if the data management network element in the visited domain fails to obtain the authentication data of the terminal from the data warehouse network element in the visited domain, the data management network element in the visited domain obtains the authentication data of the terminal from the data management network element in the home domain; the data management network element in the visited domain generates an authentication vector for the terminal based on the authentication data of the terminal.

[0074] In some embodiments, after the data management network element in the visited domain receives a first request message sent by the authentication service network element in the visited domain, the data management network element in the visited domain sends a second request message to the data management network element in the home domain, where the second request message is used to request the authentication data of the terminal; the data management network element in the visited domain receives a second response message sent by the data management network element in the home domain, where the second response message includes the authentication data of the terminal.

[0075] In some embodiments, the data management network element in the visited domain stores the terminal's authentication data obtained from the data management network element in the home domain in the data warehouse network element in the visited domain. This allows the data management network element in the visited domain to obtain the terminal's authentication data from the data warehouse network element in the visited domain the next time the terminal roams into the visited domain, improving authentication efficiency.

[0076] For example, as shown in FIG6 , assume that the terminal roams into the visited domain in FIG6 for the first time, and the data repository network element (denoted as vUDR) in the visited domain in FIG6 does not store the authentication data of the terminal. After the data management network element (denoted as vUDM) in the visited domain receives the first request message corresponding to the terminal sent by the authentication service network element (denoted as vAUSF) in the visited domain, the terminal's authentication vector determination process includes the following steps S301 to S305.

[0077] In S301, the data management network element in the visited domain sends a second request message to the data management network element in the home domain (denoted as hUDM), where the second request message is used to request authentication data of the terminal.

[0078] In S302, the data management network element in the home domain obtains the authentication data of the terminal from the data warehouse network element (denoted as hUDR) in the home domain.

[0079] In S303, the data management network element in the visited domain receives a second response message sent by the data management network element in the home domain, where the second response message includes the authentication data of the terminal.

[0080] In S304, the data management network element in the visited domain stores the authentication data of the terminal obtained from the data management network element in the home domain into the data warehouse network element in the visited domain.

[0081] In S305 , the data management network element in the visited domain generates an authentication vector of the terminal based on the authentication data of the terminal.

[0082] In some embodiments, the authentication data includes at least: a derived root key.

[0083] In some embodiments, the derived root key is generated according to the root key corresponding to the terminal and an identifier of the visited domain.

[0084] In some embodiments, a derived root key is generated based on a derivation algorithm in combination with a root key corresponding to the terminal and an identifier of the visited domain.

[0085] Derivation algorithms include but are not limited to: PBKDF2, Bcrypt, Scrypt, Argon2.

[0086] Exemplarily, the calculation process of the derived root key Exk is as follows:

[0087] derived key=HMAC-SHA-256(Key,S)

[0088] in:

[0089] 1. Enter Key as PermanentKey;

[0090] 2. S=FC||P0||L0||P1||L1||P2||L2||P3||L3||...||Pn||Ln

[0091] -FC=0x6A; (can be assigned via 33.220)

[0092] -P0=autonomous domain name;

[0093] -L0=length of the autonomous domain name;

[0094] 3. The output derived key is Exk.

[0095] In some embodiments, the authentication data further includes at least one of the following: an operator secondary key (OPC), an identifier of a protection parameter, and a serial number. The protection parameter is used to decrypt the encrypted derived root key and OPC included in the authentication data.

[0096] In some embodiments, based on the protection parameter identifier, a key corresponding to the protection parameter identifier is determined in a pre-configured key table, and the encrypted derived root key and OPC are decrypted based on the key. The pre-configured key table contains the correspondence between the protection parameter identifier and the key.

[0097] In S102, the data management network element in the visited domain sends a first response message to the authentication service network element in the visited domain. Correspondingly, the first response message sent by the data management in the visited domain is received; the first response message includes the authentication vector of the terminal.

[0098] In some embodiments, before sending the first request message to the data management network element in the visited domain, the data management network element in the visited domain sends a third request message sent by the mobility and access management network element (denoted as vAMF) in the visited domain to the authentication service network element in the visited domain. The third request message is used to request authentication of the terminal.

[0099] In S103, the authentication service network element in the visited domain authenticates the terminal based on the authentication vector of the terminal.

[0100] For example, Figure 7 provides an interactive flow chart of an authentication method. After the UE roams into a visited domain, the steps of authenticating the UE include the following: 1 to 15.

[0101] 1. The UE sends an access request message to the vAMF. The access request message carries the subscription identifier (SUCI) or 5G-GUTI.

[0102] 2. The vAMF sends a third request message to the vAUSF. The third request message is used to request authentication of the UE.

[0103] 3. vAUSF sends a first request message to vUDM. The first request message is used to request the UE's authentication vector.

[0104] 4. vUDM obtains the terminal's authentication data.

[0105] As an example, the step of obtaining the authentication data of the terminal may be step 4-1.

[0106] 4-1. vUDM obtains the terminal's authentication data from vUDR.

[0107] As another example, the steps of obtaining the authentication data of the terminal may be, for example, 4-2-1 to 4-2-4.

[0108] 4-2-1. vUDM sends a second request message to hUDM. The second request message is used to request the authentication data of the terminal.

[0109] 4-2-2. hUDM obtains the terminal's authentication data from hUDR.

[0110] 4-2-3. vUDM receives the second response message sent by hUDM. The second response message includes the authentication data of the terminal.

[0111] 4-2-4. vUDM stores the terminal authentication data obtained from hUDM in the data warehouse network element in the visited domain.

[0112] The authentication data includes at least: a derived root key. The authentication data may also include an operator secondary key (OPC), a protection parameter identifier, and a serial number. The derived root key is generated based on the UE's corresponding root key and the visited domain identifier.

[0113] 5. vUDM generates the terminal's authentication vector based on the terminal's authentication data.

[0114] The calculation process can refer to the calculation method of the terminal authentication vector described above using the authentication in the 5G network and 5G-AKA authentication as examples.

[0115] 6. vUDM sends a first response message to vAUSF, where the first response message includes the authentication vector (5G HE AV) of the terminal.

[0116] 7 to 15. The vAUSF / vUDM / vAMF of the visited domain completes the subsequent authentication process. The subsequent authentication process can be referred to the description of steps 7 to 15 in Figure 1 and will not be repeated in this example.

[0117] Based on this, the authentication service NE in the visited domain can locally authenticate terminals roaming into the visited domain based on the terminal's authentication vector sent by the data management NE in the visited domain. This solves the problem of being unable to authenticate terminals when the authentication service-related NE in the home domain is abnormal, ensuring that terminals can access the network normally after roaming into the visited domain.

[0118] The above mainly introduces the solutions of the embodiments of the present disclosure from the perspective of methods. The following also shows an authentication device, which is used to execute the authentication method in any of the above embodiments and their implementations.

[0119] It is understandable that, in order to implement the authentication method, the authentication device includes hardware structures and / or software modules corresponding to the execution of each function. It should be readily apparent to those skilled in the art that, in conjunction with the algorithmic steps of the various examples described in the embodiments of the present disclosure, the present disclosure can be implemented in the form of hardware or a combination of hardware and computer software. Whether a function is executed in the form of hardware or computer software driving hardware depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered to be beyond the scope of the present disclosure.

[0120] The embodiments of the present disclosure can divide the functional modules of the authentication device according to the above-mentioned method embodiments. For example, each functional module can be divided corresponding to each function, or two or more functions can be integrated into one functional module. The above-mentioned integrated modules can be implemented in the form of hardware or software. It should be noted that the division of modules in the embodiments of the present disclosure is schematic and is only a logical functional division. There may be other division methods in actual implementation. The following is an example of dividing each functional module corresponding to each function.

[0121] FIG8 shows an authentication device according to an embodiment of the present disclosure, which is applied to a data management network element in a visited domain. The authentication device 800 includes a communication module 801 and a processing module 802 .

[0122] The communication module 801 is configured to receive a first request message sent by an authentication service network element in a visited domain. The first request message is used to request an authentication vector for a terminal roaming into the visited domain.

[0123] The communication module 801 is further configured to send a first response message to the authentication service network element in the visited domain. The first response message includes the authentication vector of the terminal.

[0124] In some embodiments, the communication module 801 is configured to obtain the authentication data of the terminal from the data warehouse network element in the visited domain when the data warehouse network element in the visited domain contains the authentication data of the terminal; and the processing module 802 is configured to generate an authentication vector of the terminal based on the authentication data of the terminal.

[0125] In some embodiments, the communication module 801 is configured to obtain authentication data of the terminal from a data management network element in the home domain; and the processing module 802 is configured to generate an authentication vector of the terminal based on the authentication data of the terminal.

[0126] In some embodiments, the communication module 801 is configured to send a second request message to a data management network element in a home domain, where the second request message is used to request authentication data of the terminal.

[0127] The communication module 801 is configured to receive a second response message sent by a data management network element in a home domain, where the second response message includes authentication data of the terminal.

[0128] In some embodiments, the processing module 802 is configured to store the authentication data in a data warehouse network element in the visited domain.

[0129] In some embodiments, the authentication data includes at least: a derived root key.

[0130] In some embodiments, the derived root key is generated according to the root key corresponding to the terminal and an identifier of the visited domain.

[0131] In some embodiments, the authentication data further includes at least one of the following: an operator secondary key (OPC), an identifier of a protection parameter, and a serial number; the protection parameter is used to decrypt the encrypted derived root key and OPC included in the authentication data.

[0132] FIG9 shows an authentication device according to an embodiment of the present disclosure, which is applied to an authentication service network element in a visited domain. The authentication device 900 includes: a communication module 901 and a processing module 902 .

[0133] The communication module 901 is configured to send a first request message to a data management network element in a visited domain, where the first request message is used to request an authentication vector of a terminal roaming into the visited domain.

[0134] The communication module 901 is further configured to receive a first response message sent by the data management in the visited domain, where the first response message includes an authentication vector of the terminal;

[0135] The processing module 902 is configured to authenticate the terminal based on the authentication vector of the terminal.

[0136] In some embodiments, the authentication vector of the terminal is generated based on authentication data of the terminal, the authentication data including at least a derived root key.

[0137] In some embodiments, the derived root key is generated according to the root key corresponding to the terminal and an identifier of the visited domain.

[0138] In some embodiments, the authentication data further includes at least one of the following: an OPC, an identifier of a protection parameter, and a serial number. The protection parameter is used to decrypt the encrypted derived root key and the OPC included in the authentication data.

[0139] In some embodiments, the communication module 901 is further configured to receive a third request message sent by a mobility and access management network element in a visited domain, where the third request message is used to request authentication of the terminal.

[0140] In the case of implementing the functions of the above-mentioned integrated modules in hardware, the embodiments of the present disclosure also provide a structure of a communication device for executing the authentication method provided in the embodiments of the present disclosure. As shown in Figure 10, the communication device 100 includes: a communication interface 103, a processor 102, and a bus 104. In some embodiments, the communication device may also include a memory 101.

[0141] The processor 102 may implement or execute the various exemplary logic blocks, modules, and circuits described in conjunction with the embodiments of the present disclosure. The processor 102 may be a central processing unit, a general-purpose processor, a digital signal processor, an application-specific integrated circuit, a field programmable gate array, or other programmable logic device, a transistor logic device, a hardware component, or any combination thereof, and may implement or execute the various exemplary logic blocks, modules, and circuits described in conjunction with the embodiments of the present disclosure. The processor 102 may also be a combination that implements computing functions, such as a combination of one or more microprocessors, a combination of a DSP (digital signal processor) and a microprocessor, and the like.

[0142] The communication interface 103 is used to connect to other devices via a communication network, such as Ethernet, wireless access network, or wireless local area network (WLAN).

[0143] The memory 101 may be a read-only memory (ROM) or other type of static storage device that can store static information and instructions, a random access memory (RAM) or other type of dynamic storage device that can store information and instructions, or an electrically erasable programmable read-only memory (EEPROM), a disk storage medium or other magnetic storage device, or any other medium that can be used to carry or store desired program code in the form of instructions or data structures and can be accessed by a computer, but is not limited thereto.

[0144] As an implementation, the memory 101 may exist independently of the processor 102. The memory 101 may be connected to the processor 102 via a bus 104 and used to store instructions or program codes. When the processor 102 calls and executes the instructions or program codes stored in the memory 101, the authentication method provided in the embodiment of the present disclosure can be implemented.

[0145] In another implementation, the memory 101 may also be integrated with the processor 102 .

[0146] Bus 104 can be an Extended Industry Standard Architecture (EISA) bus, etc. Bus 104 can be divided into an address bus, a data bus, a control bus, etc. For ease of illustration, FIG10 shows only one thick line, but this does not mean that there is only one bus or only one type of bus.

[0147] Some embodiments of the present disclosure provide a computer-readable storage medium (e.g., a non-transitory computer-readable storage medium) having computer program instructions stored therein. When the computer program instructions are executed on a computer, the computer executes the authentication method described in any of the above embodiments.

[0148] In an exemplary embodiment, the computer may be the aforementioned communication device, and the present disclosure does not limit the specific form of the computer.

[0149] In some examples, the computer-readable storage media described above may include, but are not limited to, magnetic storage devices (e.g., hard disks, floppy disks, or magnetic tapes), optical disks (e.g., compact disks (CDs), digital versatile disks (DVDs), etc.), smart cards, and flash memory devices (e.g., erasable programmable read-only memories (EPROMs), cards, sticks, or key drives, etc.). The various computer-readable storage media described in this disclosure may represent one or more devices and / or other machine-readable storage media for storing information. The term "machine-readable storage medium" may include, but is not limited to, wireless channels and various other media capable of storing, containing, and / or carrying instructions and / or data.

[0150] An embodiment of the present disclosure provides a computer program product comprising instructions. When the computer program product is run on a computer, the computer is enabled to execute the authentication method described in any one of the above embodiments.

[0151] In the technical solution provided by the embodiments of the present disclosure, a data management network element in a visited domain receives a first request message sent by an authentication service network element in a visited domain, the first request message being used to request an authentication vector for a terminal roaming into the visited domain. The data management network element in the visited domain then sends a first response message to the authentication service network element in the visited domain, the first response message including the terminal's authentication vector. In this way, the authentication service network element in the visited domain can locally authenticate the terminal roaming into the visited domain based on the terminal's authentication vector sent by the data management network element in the visited domain. This solves the problem of being unable to authenticate a terminal when an authentication service-related network element in the home domain is abnormal, ensuring that the terminal can normally access the network after roaming into the visited domain.

[0152] The above description is merely a specific embodiment of the present disclosure, but the scope of protection of the present disclosure is not limited thereto. Any changes or substitutions within the technical scope disclosed in the present disclosure shall be covered by the scope of protection of the present disclosure. Therefore, the scope of protection of the present disclosure shall be subject to the scope of protection of the claims.

Claims

1. An authentication method, applied to a data management network element in a visited domain, includes: Receiving a first request message sent by an authentication service network element in the visited domain, where the first request message is used to request an authentication vector of a terminal roaming to the visited domain; Sending a first response message to the authentication service network element in the visited domain, where the first response message includes the authentication vector of the terminal.

2. The method according to claim 1, wherein After receiving the first request message sent by the authentication service network element in the visited domain, the method further includes: When the authentication data of the terminal is included in a data warehouse network element in the visited domain, obtaining the authentication data of the terminal from the data warehouse network element in the visited domain; Generating an authentication vector of the terminal based on the authentication data of the terminal.

3. The method according to claim 1, wherein, After receiving the first request message sent by the authentication service network element in the visited domain, the method further includes: Obtaining the authentication data of the terminal from a data management network element in a home domain; Generating an authentication vector of the terminal based on the authentication data of the terminal.

4. The method according to claim 3, wherein, The obtaining the authentication data of the terminal from the data management network element in the home domain includes: Sending a second request message to the data management network element in the home domain, where the second request message is used to request the authentication data of the terminal; Receiving a second response message sent by the data management network element in the home domain, where the second response message includes the authentication data of the terminal.

5. The method according to claim 3, further includes: Storing the authentication data of the terminal into a data warehouse network element in the visited domain.

6. The method according to claim 2 or 3, wherein The authentication data at least includes: a derived root key.

7. The method according to claim 6, wherein, The derived root key is generated according to a root key corresponding to the terminal and an identifier of the visited domain.

8. The method according to claim 6, wherein, The authentication data further includes at least one of the following: an operator secondary key OPC, an identifier of a protection parameter, a serial number; the protection parameter is used to decrypt the encrypted derived root key and the OPC included in the authentication data.

9. An authentication method, applied to an authentication service network element in a visited domain, includes: Sending a first request message to a data management network element in the visited domain, where the first request message is used to request an authentication vector of a terminal roaming to the visited domain; Receiving a first response message sent by the data management in the visited domain, where the first response message includes the authentication vector of the terminal; Authenticating the terminal based on the authentication vector of the terminal.

10. The method according to claim 9, wherein, The authentication vector is generated based on the authentication data of the terminal, and the authentication data at least includes a derived root key.

11. The method according to claim 10, wherein, The derived root key is generated according to a root key corresponding to the terminal and an identifier of the visited domain.

12. The method according to claim 9, wherein, Before sending the first request message to the data management network element in the visited domain, the method further includes: Receiving a third request message sent by a mobility and access management network element in the visited domain, where the third request message is used to request authentication of the terminal.

13. A communication device, comprising: A memory and a processor; wherein the memory is coupled to the processor; the memory is used to store instructions executable by the processor; the processor executes the instructions to perform the method according to any one of claims 1 to 12.

14. A computer-readable storage medium, wherein, Computer instructions are stored on the computer-readable storage medium, and when the computer instructions run on the communication device, the communication device is caused to execute the method according to any one of claims 1 to 12.

Citation Information

Patent Citations

  • Data processing method, visited network element and terminal equipment

    CN111769944A

  • Communication method and communication device

    CN115038081A

  • Authentication method, communication device and computer readable storage medium

    CN117062071A

  • Home network-triggered authentication procedure

    WO2023216060A1