Access authentication method and related apparatus
Through accessing the authentication device and distributed storage system, the terminal directly conducts public key authentication with the network element of the target operator, solving the problems of multi-operators one-card and complex authentication processes, and achieving improvements in security and user experience.
Patent Information
- Application Number
- PCT/CN2025/072874
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-01-22
- Filing Date
- 2025-01-16
- Publication Date
- 2025-07-31
AI Technical Summary
In the prior art, users need to bind to a single operator, and cannot realize a one-card card for multiple operators, resulting in operators needing to maintain a large amount of user information, posing a risk of single-point attack leakage, and the network access authentication process is complex and the user experience is poor.
Through the access authentication device, the terminal and the target operator can be directly authenticated, and the terminal's public key is used for authentication, reducing dependence on the home operator, and a distributed storage system such as blockchain to store user information is used to improve security and flexibility.
It simplifies the authentication process, improves security and flexibility, reduces the risks of operators' user information maintenance, and improves user experience.
Smart Images

Figure CN2025072874_31072025_PF_FP_ABST
Abstract
Description
Access authentication method and related device
[0001] This application claims priority to the Chinese patent application filed with the State Intellectual Property Office of China on January 22, 2024, with application number 202410095134.X and application name “An access authentication method and related device”, the entire contents of which are incorporated by reference into this application. Technical Field
[0002] The present application relates to the field of communications, and in particular to an access authentication method and related devices. Background Art
[0003] Currently, users (or user cards) must be bound to a carrier, making it impossible to implement a single card for multiple carriers. This means that each carrier independently manages its own user information, and even carriers of the same type in different regions manage their own user information independently. Carriers need to maintain a large amount of user information, creating the risk of leakage through single-point attacks. Furthermore, network access authentication is generally controlled by the home carrier, which refers to the carrier in the location where the user signs up.
[0004] If a terminal is located outside of its home region, it will need to be authenticated by the home operator before accessing the network. For example, a user is signed up with a mobile operator in Region A, but is located in Region B. Therefore, they access the mobile operator in Region B. The specific access authentication process involves sending the user ID to the serving network (the Region B network) before accessing the network. The serving network then sends the user ID to the home network, which then completes the terminal's access authentication. This means that if the serving network cannot authenticate the terminal, the entire process becomes complex and the user experience is poor. Summary of the Invention
[0005] This application provides an access authentication method and related devices, which can provide a secure and flexible authentication process, thereby improving the service experience.
[0006] In the first aspect, the present application provides an access authentication method, which can be executed by an access authentication device. The access authentication device can be a verification network element, or a component configured in the verification network element (such as a chip, chip system, etc.), or it can also be a logic module or software that can realize all or part of the verification network element functions. The present application does not limit this.
[0007] In this application, the verification network element is the network element of the target operator accessed by the terminal. For example, the verification network element may be a core network element of the target operator accessed by the terminal, such as an authentication server function (AUSF) network element, an access and mobility management function (AMF) network element, or other core network elements. For another example, the verification network element may also be an access network element of the target operator accessed by the terminal, such as an access network node accessed by the terminal, which is not limited in this application.
[0008] Exemplarily, the method includes: receiving a user identification from a terminal; obtaining file information corresponding to the user identification from a storage network element, wherein the file information includes a public key of the terminal; and authenticating the terminal based on the file information.
[0009] In this application, the verification network element and the storage network element can be the same network element or different network elements, and this application does not limit this. When the verification network element and the storage network element are the same network element, the verification network element obtains the file information corresponding to the user identifier from the storage network element, which can be understood as the verification network element obtaining the file information corresponding to the user identifier from the memory or local storage; when the verification network element and the storage network element are different network elements, the verification network element obtains the file information corresponding to the user identifier from the storage network element, which can be understood as the verification network element sending the user identifier to the storage network element and receiving the file information corresponding to the above-mentioned user identifier from the storage network element.
[0010] In the above technical solution, the verification network element can obtain the file information corresponding to the user identifier from the storage network element based on the user identifier from the terminal, so as to complete the authentication of the terminal based on the above file information. The verification network element can be the network element of the target operator to which the terminal accesses. In other words, even if the verification network element is not the network element of the home operator, it can still obtain the file information corresponding to the user identifier to complete the authentication of the terminal without falling back to the home operator authentication, which is conducive to simplifying the authentication process and thus reducing latency. In addition, the above file information includes the public key of the terminal. Authentication of the terminal based on the terminal's public key is more secure and flexible than using a symmetric key.
[0011] In some possible implementations of the first aspect, the above-mentioned authentication of the terminal based on file information includes: receiving a first message from the terminal and a digital signature of the terminal, the digital signature of the terminal being obtained by signing a second message or a hash value of the second message based on the private key of the terminal, wherein the second message is a message exchanged between the above-mentioned terminal and the above-mentioned verification network element or the above-mentioned first message; and verifying the digital signature of the terminal based on the public key of the terminal.
[0012] The second message may be one or more of all messages exchanged between the terminal and the verification network element, and this application does not impose any limitation on this.
[0013] The verification network element may verify the digital signature of the terminal based on the public key of the terminal in the file information, wherein the digital signature of the terminal is obtained by signing the second message or the hash value of the second message based on the private key of the terminal. If the verification network element successfully verifies the digital signature of the terminal, it is considered that the verification network element has successfully authenticated the terminal. Correspondingly, if the verification network element fails to verify the digital signature of the terminal, it is considered that the verification network element has failed to authenticate the terminal.
[0014] Verifying the digital signature of the terminal based on the terminal's public key makes the selection of the verification network element relatively flexible. In other words, the verification network element is not limited to a specific network element, and any network element can complete the authentication of the terminal, which is more flexible.
[0015] In certain possible implementations of the first aspect, before verifying the digital signature of the terminal based on the public key of the terminal, the above method also includes: obtaining the authentication certificate of the issuer from the storage network element, where the issuer is the issuer of the authentication certificate of the terminal; and verifying the authentication certificate of the terminal based on the authentication certificate of the issuer.
[0016] The issuer can be any one of the operators, equipment manufacturers or card manufacturers. The verification network element can obtain the authentication credentials of any issuer and verify the authentication credentials of the terminal based on the authentication credentials. In this way, the verification is more flexible.
[0017] In some possible implementations of the first aspect, the above method also includes: sending a third message and the digital signature of the verification network element to the terminal, where the digital signature of the verification network element is obtained by signing the fourth message or the hash value of the fourth message based on the private key of the verification network element, wherein the fourth message is a message exchanged between the terminal and the verification network element or the above third message.
[0018] The fourth message may be one or more of all messages exchanged between the terminal and the verification network element. It is understood that since the verification network element receives the second message and sends the third message at different times, the messages exchanged between the terminal and the verification network element may also change, and therefore the second message and the fourth message may be different.
[0019] The verification network element sends the digital signature of the verification network element to the terminal, so that the terminal can verify the digital signature of the verification network element based on the public key of the verification network element. By verifying the verification network element based on the public key of the verification network element, the terminal can verify the verification network element corresponding to any operator. In this way, the terminal can access different operators with greater flexibility.
[0020] In addition, the verification network element may receive the first message and the digital signature of the terminal before sending the third message and the digital signature of the verification network element, or may receive the first message and the digital signature of the terminal after sending the third message and the digital signature of the verification network element. This application does not limit this. For example, the verification network element may receive the first message and the digital signature of the terminal, and verify the digital signature of the terminal based on the public key of the terminal. If the verification passes, the verification network element may send the third message and the digital signature of the verification network element to the terminal.
[0021] In some possible implementations of the first aspect, the method further includes: sending the certificate of the verification network element to the terminal.
[0022] The certificate of the verification network element includes, for example, the public key of the verification network element, the issuer, the validity period, the issuer's signature, the version number, the identifier of the verification network element, and a certificate status query method (such as revocation list information, online certificate status protocol (OCSP)). When the terminal does not pre-install the certificate of the verification network element, the terminal may pre-install the certificate of the target operator, wherein the certificate of the target operator includes the operator's public key. The terminal may verify the certificate of the verification network element based on the certificate of the target operator, and then verify the digital signature of the verification network element based on the public key of the verification network element. The certificate of the verification network element is issued by the operator, that is, the signature of the verification network element certificate is generated using the operator's private key. The terminal may use the public key in the operator's certificate to verify the signature of the verification network element certificate; and use the public key of the verification network element certificate to verify the digital signature of the verification network element. If both of the above processes are verified successfully, it is considered that the terminal has successfully authenticated the verification network element.
[0023] By sending the certificate of the verification network element to the terminal, the terminal does not need to pre-set the certificate of the verification network element. When there are a large number of verification network elements, the terminal does not need to pre-set the certificate of each verification network element, which is conducive to saving the storage space of the terminal.
[0024] Optionally, the certificate of the verification network element and the digital signature of the verification network element can be carried in the same signaling or in different signalings, which is not limited in this application.
[0025] In certain possible implementations of the first aspect, the above-mentioned file information also includes at least one authentication credential and an algorithm corresponding to each authentication credential in the at least one authentication credential; and the above-mentioned method also includes: determining a target authentication credential from the at least one authentication credential; and sending first indication information to the terminal, where the first indication information is used to indicate the target authentication credential and / or the algorithm corresponding to the target authentication credential.
[0026] In this application, one possible design is that different authentication credentials can be understood as certificates of different format standards, such as certificates in X.509 format, lightweight certificates, certificates in operator-customized formats, etc. The algorithms corresponding to each authentication credential may include the signature algorithm used in the certificate and the signature verification algorithm that needs to be used. The algorithms corresponding to each authentication credential may be one or more, and this application does not limit this. Another possible design is that different authentication credentials may be multiple certificates of the same format standard. For example, a terminal may have three authentication credentials, and the formats of the three authentication credentials are all in X.509 format.
[0027] The verification network element can indicate the target authentication credential and / or the algorithm corresponding to the target authentication credential to the terminal. The above-mentioned target authentication credential and / or the algorithm corresponding to the target authentication credential can be determined, for example, based on the network status, security level, etc. That is to say, the target authentication credential and / or the algorithm corresponding to the target authentication credential can be flexibly selected instead of always using a certain authentication credential and / or the algorithm corresponding to the authentication credential, which makes authentication more flexible.
[0028] On the second aspect, the present application provides an access authentication method, which can be executed by an access authentication device. The access authentication device can be a terminal, or a component configured in the terminal (such as a chip, chip system, etc.), or it can also be a logic module or software that can realize all or part of the terminal functions. This application does not limit this.
[0029] Exemplarily, the method includes: obtaining a user identifier; sending the above-mentioned user identifier to a verification network element, wherein the verification network element is a network element of the target operator accessed by the terminal, and the above-mentioned user identifier corresponds to file information stored in the storage network element, and the file information includes the public key of the above-mentioned terminal, and the file information is used to authenticate the terminal.
[0030] In the above technical solution, the terminal can send a user ID to the verification network element, and the user ID corresponds to the file information in the storage network element. In other words, after the verification network element obtains the user ID, it can obtain the corresponding file information based on the user ID, and then complete the authentication of the terminal based on the above file information. The verification network element can be the network element of the target operator accessed by the terminal. In other words, even if the verification network element is not the network element of the home operator, it can obtain the file information corresponding to the user ID to complete the authentication of the terminal without falling back to the home operator authentication, which is conducive to simplifying the authentication process. In addition, the above file information includes the public key of the terminal. Authentication of the terminal based on the public key of the terminal is more secure and flexible than using a symmetric key.
[0031] In some possible implementations of the second aspect, the above method also includes: receiving a third message from the verification network element and the digital signature of the verification network element, wherein the digital signature of the verification network element is obtained by signing a fourth message or a hash value of the fourth message based on the private key of the verification network element, wherein the fourth message is a message exchanged between the terminal and the verification network element or the above third message; and verifying the digital signature of the verification network element based on the public key of the verification network element.
[0032] The fourth message may be one or more of all messages exchanged between the terminal and the verification network element. The terminal may pre-set the verification network element's public key, and verify the verification network element's digital signature based on the verification network element's public key. If the terminal successfully verifies the verification network element's digital signature, the terminal is deemed to have successfully authenticated the verification network element. Using public key signature verification for authentication makes the authentication process relatively simple.
[0033] The terminal verifies the digital signature of the verification network element based on the public key of the verification network element, so that the terminal can verify the verification network element corresponding to any operator. In this way, the terminal can access different operators with greater flexibility.
[0034] In some possible implementations of the second aspect, the above method also includes: sending a first message and the digital signature of the terminal to the verification network element, where the digital signature of the terminal is obtained by signing the second message or the hash value of the second message based on the terminal's private key, wherein the second message is a message exchanged between the terminal and the verification network element or the above-mentioned first message.
[0035] The second message may be one or more of all messages exchanged between the terminal and the verification network element, and this application does not impose any limitation on this.
[0036] It can be understood that since the verification network element receives the second message and sends the third message at different times, the messages exchanged between the terminal and the verification network element will also change, so the second message and the fourth message may be different.
[0037] The terminal can send its digital signature to the verification network element so that the verification network element can verify the digital signature based on the terminal's public key, thereby completing the authentication of the terminal. By using public key signature verification for authentication, the authentication process is relatively simple.
[0038] In addition, the terminal may receive the third message and the digital signature of the verification network element before sending the first message and the digital signature of the terminal to the verification network element, or may receive the third message and the digital signature of the verification network element after sending the first message and the digital signature of the terminal to the verification network element. This application does not limit this. For example, the terminal may receive the third message and the digital signature of the verification network element, and verify the digital signature of the verification network element based on the public key of the verification network element. If the verification is successful, the terminal sends the first message and the digital signature of the terminal to the verification network element.
[0039] The terminal sends its digital signature so that the verification network element can verify the digital signature of the terminal based on the terminal's public key. Verifying the digital signature of the terminal based on the terminal's public key makes the selection of the verification network element relatively flexible. In other words, the verification network element is not limited to a specific network element. Any network element can complete the authentication of the terminal, which is more flexible.
[0040] In some possible implementations of the second aspect, the method further includes: receiving a certificate of the verification network element.
[0041] The certificate of the verification network element includes, for example, the verification network element's public key, issuer, validity period, issuer's signature, version number, verification network element identifier, and certificate status query method (e.g., revocation list information, OCSP, etc.). If the terminal does not have the certificate of the verification network element pre-installed, the terminal may pre-install the target operator's certificate, where the target operator's certificate includes the operator's public key. The terminal may verify the verification network element's certificate based on the target operator's certificate, and then verify the verification network element's digital signature based on the verification network element's public key. The verification network element's certificate is issued by the operator, meaning that the signature of the verification network element's certificate is generated using the operator's private key. The terminal may use the public key in the operator's certificate to verify the signature of the verification network element's certificate; and use the public key in the verification network element's certificate to verify the verification network element's digital signature. If both processes are successful, the terminal is deemed to have successfully authenticated the verification network element.
[0042] By receiving the certificate of the verification network element, the terminal does not need to pre-set the certificate of the verification network element. It can be imagined that when the number of verification network elements is large, the terminal does not need to pre-set the certificate of each verification network element, which is conducive to saving the storage space of the terminal.
[0043] Optionally, the certificate of the verification network element and the digital signature of the verification network element can be carried in the same signaling or in different signalings, which is not limited in this application.
[0044] In some possible implementations of the second aspect, before obtaining the user identifier, the method further includes: determining a target operator from multiple operators.
[0045] The terminal can determine the target operator from multiple operators. The multiple operators can be operators that have signed contracts with the user or operators that have not signed contracts with the user. This application does not limit this. In other words, each operator has the opportunity to be selected, which is conducive to improving the fairness of competition between operators.
[0046] In certain possible implementations of the second aspect, the above-mentioned determining the target operator from multiple operators includes: determining the target operator from multiple operators based on one or more of the user's location, the service quality of each of the multiple operators (such as signal strength), the cost of each of the multiple operators, or the security of each of the multiple operators.
[0047] For example, the terminal can select the operator with the strongest signal strength, lowest cost, and highest security in the user's location among multiple operators as the target operator, providing users with better services, which is conducive to improving user experience.
[0048] In some possible implementations of the second aspect, the determining of the target operator from the multiple operators includes: determining the target operator from the multiple operators in response to a user operation, wherein the user operation is an operation of the user selecting the target operator from the multiple operators.
[0049] The terminal can display multiple operators for the user to select through the user interface. In response to the user selecting a target operator from the multiple operators, the terminal determines the target operator, which helps the user flexibly select the target operator they want to access, thereby improving the user experience.
[0050] In combination with the first and second aspects, in some possible implementations, the above-mentioned user identifier is carried in a first signaling, which also includes the type of the user identifier and / or the identifier of the distributed storage system, and the identifier of the distributed storage system is used to identify the distributed storage system where the file information corresponding to the user identifier is located.
[0051] On the third aspect, the present application provides an access authentication method, which can be executed by an access authentication device. The access authentication device can be a storage network element, or a component configured in the storage network element (such as a chip, chip system, etc.), or it can also be a logic module or software that can realize all or part of the storage network element functions. The present application does not limit this.
[0052] Exemplarily, the method includes: receiving a user identifier of a terminal from a verification network element, which is a network element of a target operator to which the terminal accesses; based on the above-mentioned user identifier, determining file information corresponding to the user identifier, the file information including the public key of the terminal, and the file information being used to authenticate the terminal; and sending the above-mentioned file information to the verification network element.
[0053] It can be understood that when the verification network element and the storage network element are the same network element, the verification network element (or storage network element) directly receives the user identification from the terminal, and then determines the corresponding file information based on the user identification without sending the above file information.
[0054] In the above technical solution, the storage network element can store the user's user identification and corresponding file information, so that the verification network element can query the corresponding file information based on the user identification, and then complete the authentication of the terminal based on the above file information. The verification network element can be the network element of the target operator to which the terminal accesses. In other words, even if the verification network element is not the network element of the home operator, it can obtain the file information corresponding to the user identification to complete the authentication of the terminal without falling back to the home operator authentication, which is conducive to simplifying the authentication process. In addition, the above file information includes the public key of the terminal. Authentication of the terminal based on the terminal's public key is more secure and flexible than using a symmetric key.
[0055] In combination with the first to third aspects, in some possible implementations, the above-mentioned user identification includes decentralized root credentials (DRC), decentralized identity credentials (DIC), decentralized self-control credentials (DSCC) or self-control identity credentials (SCIC).
[0056] The DRC is pre-set on the card by the card vendor / terminal manufacturer at the time of shipment. The DIC is a collection of temporary / derived identities derived from the DRC. The DSCC is generated by the user to control their identity information and is independent of the DRC or DIC. The SCIC is derived from the DSCC. Each DRC, DIC, DSCC, or SCIC has corresponding file information.
[0057] In combination with the first to third aspects, in some possible implementations, the above-mentioned user identifier includes a pseudo identifier (pseudo identifier, pseudo ID), and there is a corresponding relationship between the pseudo identifier and the real identifier, and the real identifier and corresponding file information are stored in the storage network element.
[0058] In other words, the terminal sends a false identity, which helps to improve security.
[0059] In combination with the first to third aspects, in some possible implementations, the user identifier includes a transaction address, which is used to indicate the location of the file information corresponding to the user identifier on the distributed storage system.
[0060] In combination with the first to third aspects, in some possible implementations, the above-mentioned storage network element is a node on a distributed storage system, and the node stores at least one user identifier and file information corresponding to each user identifier.
[0061] It can be understood that the distributed storage system may include one or more nodes, each node may store at least one user identifier and file information corresponding to each user identifier, and the above-mentioned storage network element may be any one of the above-mentioned one or more nodes.
[0062] Optionally, the above-mentioned distributed storage system is a blockchain, a decentralized shared file information storage system, or an interplanetary file system (IPFS).
[0063] Fourthly, the present application provides an access authentication method, which can be executed by an access authentication device. The access authentication device can be a verification network element, or a component configured in the verification network element (such as a chip, chip system, etc.), or it can also be a logic module or software that can realize all or part of the verification network element functions. The present application does not limit this.
[0064] In this application, the verification network element is the network element of the target operator accessed by the terminal. For example, the verification network element can be the core network element of the target operator accessed by the terminal, for example, the verification network element can be an AUSF network element, or an AMF network element, or other core network element. For another example, the verification network element can also be the access network element of the target operator accessed by the terminal, such as the access network node accessed by the terminal, etc. This application does not limit this. The verification network element will not be described in detail below.
[0065] Exemplarily, the method includes: receiving a user identification from a terminal and file information corresponding to the user identification, where the file information includes a public key of the terminal; and authenticating the terminal based on the file information.
[0066] The user identification may be used to identify the authenticated terminal (or the universal integrated circuit card in the terminal).
[0067] In the above technical solution, the verification network element can complete the authentication of the terminal directly based on the obtained user identification of the terminal and the file information corresponding to the user identification, and the verification network element can be the network element of the target operator accessed by the terminal. That is to say, even if the verification network element is not the network element of the home operator, it can complete the authentication of the terminal without falling back to the home operator authentication, which is conducive to simplifying the authentication process.
[0068] In some possible implementations of the fourth aspect, the above-mentioned authentication of the terminal based on file information includes: receiving a first message from the terminal and a digital signature of the terminal, the digital signature of the terminal being obtained by signing a second message or a hash value of the second message based on the private key of the terminal, wherein the second message is a message exchanged between the above-mentioned terminal and the above-mentioned verification network element or the above-mentioned first message; and verifying the digital signature of the terminal based on the public key of the terminal.
[0069] The second message may be one or more of all messages exchanged between the terminal and the verification network element, and this application does not impose any limitation on this.
[0070] The verification network element may verify the digital signature of the terminal based on the public key of the terminal in the file information, wherein the digital signature of the terminal is obtained by signing the second message or the hash value of the second message based on the private key of the terminal. If the verification network element successfully verifies the digital signature of the terminal, it is considered that the verification network element has successfully authenticated the terminal. Correspondingly, if the verification network element fails to verify the digital signature of the terminal, it is considered that the verification network element has failed to authenticate the terminal.
[0071] In some possible implementations of the fourth aspect, the above method also includes: sending a third message and the digital signature of the verification network element to the terminal, and the digital signature of the verification network element is obtained by signing the fourth message or the hash value of the fourth message based on the private key of the verification network element, wherein the fourth message is a message exchanged between the terminal and the verification network element or the above third message.
[0072] The fourth message may be one or more of all messages exchanged between the terminal and the verification network element. It is understood that since the verification network element receives the second message and sends the third message at different times, the messages exchanged between the terminal and the verification network element may also change, and therefore the second message and the fourth message may be different.
[0073] In addition, the verification network element may receive the first message and the digital signature of the terminal before sending the third message and the digital signature of the verification network element, or may receive the first message and the digital signature of the terminal after sending the third message and the digital signature of the verification network element. This application does not limit this. For example, the verification network element may receive the first message and the digital signature of the terminal, and verify the digital signature of the terminal based on the public key of the terminal. If the verification passes, the verification network element may send the third message and the digital signature of the verification network element to the terminal.
[0074] In some possible implementations of the fourth aspect, the method further includes: sending the certificate of the verification network element to the terminal.
[0075] The certificate of the verification network element includes, for example, the verification network element's public key, issuer, validity period, issuer's signature, version number, verification network element identifier, and certificate status query method (e.g., revocation list information, OCSP, etc.). If the terminal does not have the certificate of the verification network element pre-installed, the terminal may pre-install the target operator's certificate, where the target operator's certificate includes the operator's public key. The terminal may verify the verification network element's certificate based on the target operator's certificate, and then verify the verification network element's digital signature based on the verification network element's public key. The verification network element's certificate is issued by the operator, meaning that the signature of the verification network element's certificate is generated using the operator's private key. The terminal may use the public key in the operator's certificate to verify the signature of the verification network element's certificate; and use the public key in the verification network element's certificate to verify the verification network element's digital signature. If both processes are successful, the terminal is deemed to have successfully authenticated the verification network element.
[0076] Optionally, the certificate of the verification network element and the digital signature of the verification network element can be carried in the same signaling or in different signalings, which is not limited in this application.
[0077] In some possible implementations of the fourth aspect, the method further includes: obtaining a hash value of the file information corresponding to the user identifier from a storage network element based on the user identifier; and verifying the file information based on the hash value.
[0078] In the fifth aspect, the present application provides an access authentication method, which can be executed by an access authentication device. The access authentication device can be a terminal, or a component configured in the terminal (such as a chip, chip system, etc.), or it can also be a logic module or software that can realize all or part of the terminal functions. The present application does not limit this.
[0079] Exemplarily, the method includes: obtaining the user identification of the terminal and the file information corresponding to the user identification, wherein the file information includes the public key of the terminal; sending the above-mentioned user identification and the file information corresponding to the user identification to the verification network element, which is the network element of the target operator accessed by the terminal, and the file information is used to authenticate the terminal.
[0080] In the above technical solution, the terminal can send the user identification and the file information corresponding to the user identification to the verification network element, so that the verification network element can complete the authentication of the terminal based on the above file information, and the verification network element can be the network element of the target operator accessed by the terminal. That is to say, even if the verification network element is not the network element of the home operator, it can obtain the file information corresponding to the user identification to complete the authentication of the terminal without falling back to the home operator authentication, which is conducive to simplifying the authentication process.
[0081] In some possible implementations of the fifth aspect, the above method also includes: receiving a third message from the verification network element and the digital signature of the verification network element, the digital signature of the verification network element being obtained by signing a fourth message or a hash value of the fourth message based on the private key of the verification network element, wherein the fourth message is a message exchanged between the terminal and the verification network element or the above third message; and verifying the digital signature of the verification network element based on the public key of the verification network element.
[0082] The fourth message may be one or more of all messages exchanged between the terminal and the verification network element. The terminal may pre-set the verification network element's public key, and verify the verification network element's digital signature based on the verification network element's public key. If the terminal successfully verifies the verification network element's digital signature, the terminal is deemed to have successfully authenticated the verification network element. Using public key signature verification for authentication makes the authentication process relatively simple.
[0083] In some possible implementations of the fifth aspect, the above method also includes: sending a first message and the digital signature of the terminal to the verification network element, where the digital signature of the terminal is obtained by signing the second message or the hash value of the second message based on the terminal's private key, wherein the second message is a message exchanged between the terminal and the verification network element or the above-mentioned first message.
[0084] The second message may be one or more of all messages exchanged between the terminal and the verification network element, and this application does not impose any limitation on this.
[0085] It can be understood that since the verification network element receives the second message and sends the third message at different times, the messages exchanged between the terminal and the verification network element will also change, so the second message and the fourth message may be different.
[0086] The terminal can send its digital signature to the verification network element so that the verification network element can verify the digital signature based on the terminal's public key, thereby completing the authentication of the terminal. By using public key signature verification for authentication, the authentication process is relatively simple.
[0087] In addition, the terminal may receive the third message and the digital signature of the verification network element before sending the first message and the digital signature of the terminal to the verification network element, or may receive the third message and the digital signature of the verification network element after sending the first message and the digital signature of the terminal to the verification network element. This application does not limit this. For example, the terminal may receive the third message and the digital signature of the verification network element, and verify the digital signature of the verification network element based on the public key of the verification network element. If the verification is successful, the terminal sends the first message and the digital signature of the terminal to the verification network element.
[0088] In some possible implementations of the fifth aspect, the method further includes: receiving a certificate of a verification network element.
[0089] In some possible implementations of the fifth aspect, before obtaining the user identifier and the file information corresponding to the user identifier, the method further includes: determining a target operator from a plurality of operators.
[0090] The terminal can determine the target operator from multiple operators. The multiple operators can be operators that have signed contracts with the user or operators that have not signed contracts with the user. This application does not limit this. In other words, each operator has the opportunity to be selected, which is conducive to improving the fairness of competition between operators.
[0091] In certain possible implementations of the fifth aspect, the above-mentioned determination of the target operator from multiple operators includes: determining the target operator from multiple operators based on one or more of the user's location, the service quality of each of the multiple operators (such as signal strength), the cost of each of the multiple operators, or the security of each of the multiple operators.
[0092] For example, the terminal can select the operator with the strongest signal strength, lowest cost, and highest security in the user's location among multiple operators as the target operator, providing users with better services, which is conducive to improving user experience.
[0093] In some possible implementations of the fifth aspect, the determining of the target operator from the multiple operators includes: determining the target operator from the multiple operators in response to a user operation, wherein the user operation is an operation of the user selecting the target operator from the multiple operators.
[0094] The terminal can display multiple operators for the user to select through the user interface. In response to the user selecting a target operator from the multiple operators, the terminal determines the target operator, which helps the user flexibly select the target operator they want to access, thereby improving the user experience.
[0095] In combination with the fourth and fifth aspects, in some possible implementations, the above-mentioned user identifier is carried in a first signaling, which also includes the type of the user identifier and / or the identifier of the distributed storage system, and the identifier of the distributed storage system is used to identify the distributed storage system where the file information corresponding to the user identifier is located.
[0096] In the sixth aspect, the present application provides an access authentication method, which can be executed by an access authentication device. The access authentication device can be a storage network element, or a component configured in the storage network element (such as a chip, chip system, etc.), or it can also be a logic module or software that can realize all or part of the storage network element functions. The present application does not limit this.
[0097] Exemplarily, the method includes: receiving a user identifier of a terminal from a verification network element, which is a network element of a target operator accessed by the terminal; based on the above user identifier, determining a hash value of file information corresponding to the above user identifier, wherein the file information includes a public key of the terminal; and sending the hash value of the above file information to the verification network element.
[0098] It can be understood that when the verification network element and the storage network element are the same network element, the verification network element (or storage network element) directly receives the user identification from the terminal, and then determines the hash value of the corresponding file information based on the user identification, without sending / receiving the hash value of the above file information.
[0099] In the above technical solution, the storage network element can store the user's user identification and the hash value of the corresponding file information, so that the verification network element can query the hash value of the corresponding file information based on the user identification, and then verify the file information obtained from the terminal, which is conducive to improving the accuracy of the file information.
[0100] In combination with the fourth to sixth aspects, in some possible implementations, the user identifier includes DRC, DIC, DSCC, or SCIC.
[0101] In combination with the fourth to sixth aspects, in some possible implementations, the above-mentioned user identifier includes a false identity identifier, and there is a corresponding relationship between the false identity identifier and the real identity identifier, and the storage network element stores the hash value of the real identity identifier and the corresponding file information.
[0102] In other words, the terminal sends a false identity, which helps to improve security.
[0103] In combination with the fourth to sixth aspects, in some possible implementations, the above-mentioned user identifier includes a transaction address, which is used to indicate the location of the hash value of the file information corresponding to the user identifier on the distributed storage system.
[0104] In combination with the fourth to sixth aspects, in some possible implementations, the above-mentioned storage network element is a node on a distributed storage system, and the node stores at least one user identifier and a hash value of file information corresponding to each user identifier.
[0105] Optionally, the above-mentioned distributed storage system is a blockchain, a decentralized shared file information storage system, or an interplanetary file system.
[0106] In a seventh aspect, the present application provides an access authentication device that can implement the methods described in aspects 1 to 6 and any possible implementation of aspects 1 to 6. The device includes corresponding modules for executing the above methods. The modules included in the device can be implemented in software and / or hardware.
[0107] In an eighth aspect, the present application provides an access authentication device, which includes a processor, and the processor can be used to execute a computer program in a memory to implement the method described in the first to sixth aspects and any possible implementation method of the first to sixth aspects.
[0108] Optionally, the device further includes a communication interface, and the processor is coupled to the communication interface. The communication interface is configured to receive signals from other communication devices outside the device and transmit them to the processor, or to transmit signals from the processor to other communication devices outside the device. Exemplarily, the communication interface may be a transceiver, circuit, bus, module, pin, or other type of communication interface.
[0109] Optionally, the apparatus further comprises a memory, the processor being coupled to the memory. The memory is configured to store program instructions and data. The memory is coupled to the processor, and when the processor executes instructions stored in the memory, the methods described in the above aspects can be implemented.
[0110] In a ninth aspect, the present application provides an access authentication device, comprising a processor and a communication interface, wherein the communication interface is configured to receive signals from a communication device other than the communication device and transmit them to the processor, or to transmit signals from the processor to a communication device other than the communication device, wherein the processor implements the method described in aspects 1 to 6 and any possible implementation of aspects 1 to 6 through a logic circuit or by executing code instructions. Exemplarily, the communication interface may be a transceiver, circuit, bus, module, pin, or other type of communication interface.
[0111] Optionally, the device further includes a memory for storing instructions and / or data. The memory may be coupled to the processor, and when the processor executes the instructions stored in the memory, the method described in any one of the first to sixth aspects and any possible implementation of the first to sixth aspects is implemented.
[0112] In the tenth aspect, the present application provides an access authentication device, including a processor and a memory, wherein the memory is used to store instructions and data. When the processor executes the instructions stored in the memory, it can implement the methods described in the first to sixth aspects and any possible implementation methods of the first to sixth aspects.
[0113] Optionally, the device further includes a communication interface, which is used for the device to communicate with other communication devices. Exemplarily, the communication interface may be a transceiver, circuit, bus, module, pin or other types of communication interfaces.
[0114] In the eleventh aspect, the present application provides a computer-readable storage medium, which stores a computer program or instructions. When the computer program or instructions are executed, the method described in the first to sixth aspects and any possible implementation method of the first to sixth aspects is implemented.
[0115] In a twelfth aspect, the present application provides a computer program product comprising instructions, which, when executed, implement the method described in aspects 1 to 6 and any possible implementation of aspects 1 to 6.
[0116] In the thirteenth aspect, the present application provides a chip system comprising at least one processor for supporting the functions involved in the implementation of the first to sixth aspects and any possible implementation of the first to sixth aspects, such as receiving or processing the data involved in the above method.
[0117] In one possible design, the chip system further includes a memory, which is used to store program instructions and data, and the memory is located inside or outside the processor.
[0118] The chip system can be composed of chips, or can include chips and other discrete devices.
[0119] In the fourteenth aspect, the present application provides a communication system, which includes a verification network element and a storage network element, wherein the verification network element is used to implement the method described in the first aspect and any possible implementation method of the first aspect, and the storage network element is used to implement the method described in the third aspect and any possible implementation method of the third aspect.
[0120] Optionally, the above-mentioned communication system also includes a terminal, which is used to implement the method described in the second aspect and any possible implementation manner of the second aspect.
[0121] In the fifteenth aspect, the present application provides a communication system, which includes a verification network element and a storage network element, wherein the verification network element is used to implement the method described in the fourth aspect and any possible implementation method of the fourth aspect, and the storage network element is used to implement the method described in the sixth aspect and any possible implementation method of the sixth aspect.
[0122] Optionally, the above-mentioned communication system also includes a terminal, which is used to implement the method described in the fifth aspect and any possible implementation manner of the fifth aspect.
[0123] It should be understood that the fourth to fifteenth aspects of the present application correspond to the technical solutions of the first to third aspects of the present application, and the beneficial effects achieved by each aspect and the corresponding feasible implementation methods are similar and will not be repeated. BRIEF DESCRIPTION OF THE DRAWINGS
[0124] FIG1 is a schematic diagram of a possible access authentication process;
[0125] FIG2A is a schematic diagram of the architecture of a communication system applicable to the access authentication method provided in this application;
[0126] FIG2B is a schematic diagram of a blockchain provided in an embodiment of the present application;
[0127] FIG3 is a schematic flow chart of an access authentication method provided in an embodiment of the present application;
[0128] FIG4 is a schematic diagram of various operator contracting methods provided in an embodiment of the present application;
[0129] FIG5 is a schematic diagram of the format of the first signaling provided in an embodiment of the present application;
[0130] FIG6 is a schematic diagram of an access authentication process provided in an embodiment of the present application;
[0131] FIG7 is another schematic diagram of the access authentication process provided in an embodiment of the present application;
[0132] FIG8 is another schematic diagram of the access authentication process provided in an embodiment of the present application;
[0133] FIG9 is a schematic flow chart of another access authentication method provided in an embodiment of the present application;
[0134] FIG10 is another schematic diagram of the access authentication process provided in an embodiment of the present application;
[0135] FIG11 is a schematic block diagram of an access authentication device according to an embodiment of the present application;
[0136] FIG12 is another schematic block diagram of the access authentication device provided in an embodiment of the present application. DETAILED DESCRIPTION
[0137] The technical solution in this application will be described below with reference to the accompanying drawings.
[0138] Before introducing the method provided in the embodiments of the present application, the following points are explained.
[0139] First, in this application, indications include explicit indications (also called direct indications) and implicit indications (also called indirect indications). Specifically, explicit indication information A refers to including information A; implicit indication information A refers to indicating information A through the correspondence between information A and information B and directly indicating information B. The correspondence between information A and information B can be predefined, pre-stored, pre-burned, or pre-configured; or, it can also refer to indicating information A through information B and preset rules.
[0140] Second, in this application, information C is used to determine information D, which includes both information D being determined solely based on information C and information D being determined based on information C and other information. Furthermore, information C can also be used to determine information D indirectly, for example, when information D is determined based on information E, and information E is determined based on information C.
[0141] Third, in this application, "at least one" means one or more, and "more" means two or more. "And / or" describes the association relationship of associated objects, indicating that three relationships may exist. For example, A and / or B can mean: A exists alone, A and B exist at the same time, and B exists alone, where A and B can be singular or plural. The character " / " generally indicates that the previous and next associated objects are in an "or" relationship, but it does not exclude the situation where the previous and next associated objects are in an "and" relationship. The specific meaning can be understood in conjunction with the context. "At least one of the following items" or similar expressions refers to any combination of these items, including any combination of single items or plural items. For example, at least one of a, b, or c can mean: a, b, c; a and b; a and c; b and c; or a and b and c. Where a, b, c can be single or multiple.
[0142] Fourth, in this application, prefixes such as "first" and "second" are used solely to distinguish between different items belonging to the same category and do not constrain the order, size, or quantity of the items. For example, "first message" and "second message" can refer to different messages or the same message, and this application does not limit this.
[0143] Fifth, "sending" and "receiving" in this application indicate the direction of signal transmission. For example, "sending information to the verification network element" can be understood as the destination end of the information is the verification network element, which can include direct sending through the air interface, and also include indirect sending through the air interface by other units or modules. "Receiving information from the terminal" can be understood as the source end of the information is the terminal, which can include direct receiving from the terminal through the air interface, and also include indirect receiving from the terminal through the air interface from other units or modules. "Sending" can also be understood as the "output" of the chip interface, and "receiving" can also be understood as the "input" of the chip interface.
[0144] In other words, sending and receiving can be carried out between devices, for example, between a terminal and a verification network element; it can also be carried out within a device, for example, sending or receiving between components, modules, chips, software modules or hardware modules within the device through a bus, wiring or interface.
[0145] Sixth, in this application, "when", "if" and "if" all mean that the device will take corresponding actions under certain objective circumstances, which does not limit the time, nor does it require that the device must perform judgment actions when it is implemented, nor does it mean that there are other limitations.
[0146] Seventh, in this application, words such as "example," "exemplarily," "for example," or "such as" are used to indicate examples, illustrations, or explanations. Any embodiment or design described in this application as "example," "exemplarily," "for example," or "such as" should not be construed as being preferred or advantageous over other embodiments or designs. Rather, the use of words such as "example," "exemplarily," "for example," or "such as" is intended to present the relevant concepts in a concrete manner.
[0147] Currently, users (or user cards) must be bound to a carrier, making it impossible to implement a single card for multiple carriers. This means that each carrier independently manages its own user information, and even carriers of the same type in different regions manage their own user information independently. Carriers need to maintain a large amount of user information, creating the risk of leakage through single-point attacks. Furthermore, network access authentication is generally controlled by the home carrier, which refers to the carrier in the location where the user signs up.
[0148] If a terminal is located outside of its home region, it will need access authentication from the home region's operator before accessing the network. For example, a user is signed up with a mobile operator in Region A, but is located in Region B. Therefore, they access the mobile operator in Region B. The specific access authentication process involves sending the user ID to the serving network (the Region B network) before accessing the network. The serving network then sends the user ID to the home region's network, which then completes access authentication for the terminal. The existing access authentication process is described in detail below, with reference to Figure 1.
[0149] Figure 1 is a schematic diagram of a possible access authentication process, wherein a) in Figure 1 shows the registration phase, and b) in Figure 1 shows the authentication phase.
[0150] In step 101, the terminal encrypts the subscription permanent identifier (SUPI) through an elliptic curve integrate encrypt scheme (ECIES) to obtain a subscription concealed identifier (SUCI).
[0151] The terminal encrypts SUPI through ECIES, which solves the security risks of plain text transmission and improves security.
[0152] In step 102, the terminal sends a SUCI and a home network (HN) identifier to a serving network (SN). Correspondingly, the serving network receives the SUCI and the home network identifier from the terminal.
[0153] The serving network refers to the network accessed by the terminal, and the home network refers to the network in the location where the user signed up. For example, if a user signs up with a mobile operator in Beijing, the Beijing mobile operator is the home network. After arriving in Guangzhou, the user connects to the Guangzhou mobile operator, and the Guangzhou mobile operator is the serving network.
[0154] The home network identifier is used to identify the home network. The terminal encrypts the SUPI to obtain the SUCI, and then sends the SUCI and the home network identifier to the serving network. The serving network can then determine the corresponding home network based on the home network identifier.
[0155] In step 103, the serving network sends the SUCI, the home network identifier, and the serving network identifier to the home network. Correspondingly, the home network receives the SUCI, the home network identifier, and the serving network identifier from the serving network.
[0156] In step 104, the home network decrypts the SUCI through ECIES to obtain the SUPI.
[0157] After receiving the SUCI, the home network decrypts it using ECIES to obtain the SUPI. Since the home network stores the information required for terminal authentication, the home network can determine the information required for authentication, such as the authentication credentials used, based on the SUPI.
[0158] It should be understood that the authentication process shown in b) of Figure 1 is illustrated using the Authentication and Key Agreement (AKA) protocol as an example. The specific principle of AKA-based authentication is that the home network and the terminal hold the same key, which corresponds to the SUPI. During the authentication process, both parties perform calculations based on the challenge value and the key. If the calculation results are the same, it proves that they hold the same key, and authentication is successful.
[0159] The following will explain in detail the process of authenticating the terminal through AKA in conjunction with b) in FIG. 1 .
[0160] In step 105, the home network generates an authentication quadruple.
[0161] The above authentication quadruple is (random number (RAND), authentication token (AUTN), hash value of expected response value (HXRES), key security anchor function (KSEAF)). The specific calculation process can refer to known technologies and will not be described in detail here.
[0162] RAND is a 128-bit random number. AUTN is an authentication token consisting of the exclusive-or value of AK and the home network sequence number (SQNHN) (denoted as C) and a message authentication code (MAC). HXRES is the hash of RAND and the expected response (XRES). KSEAF is the anchor key established with the serving network.
[0163] In step 106, the home network sends the authentication quadruple (RAND, AUTN, HXRES, KSEAF) to the serving network. Correspondingly, the serving network receives the authentication quadruple (RAND, AUTN, HXRES, KSEAF).
[0164] In step 107, the service network sends (RAND, AUTN) to the terminal, and the terminal receives (RAND, AUTN).
[0165] After receiving the authentication quadruple, the service network sends (RAND, AUTN) in the authentication quadruple to the terminal.
[0166] In step 108, the terminal calculates a MAC value based on (RAND, AUTN).
[0167] For example, the terminal splits AUTN into C and MAC, and calculates AK using the shared key k and RAND (the AK is used to hide the sequence number (SQN) in the message). This is then XORed with C to obtain SQNHN. Finally, the MAC value is calculated based on the SQNHN and compared with the received MAC value. The MAC value is calculated using the sequence number on the home network side, not the terminal side.
[0168] If the MAC values are the same and the serial number on the terminal side is smaller than the serial number on the home network side, authentication of the HN is successful, and the terminal executes steps 109 to 113. If the MAC values are the same, but the serial number on the terminal side is larger than the serial number on the home network side, the terminal executes step 114. If the MAC values are different, authentication fails, and the terminal executes step 115.
[0169] The terminal will think that there is a sequence number out-of-sync problem and will resynchronize. On the terminal side, this is also a major cause of link attacks.
[0170] In step 109, the terminal generates a response value (RES) and KSEAF.
[0171] In step 110, the terminal sends a RES to the service network, and the service network receives the RES accordingly.
[0172] In step 111, the serving network hashes the RES to obtain a hash response (HRES), and compares the HRES with the hash value sent by the home network.
[0173] If they are the same, step 112 is executed; if they are not the same, the authentication fails.
[0174] In step 112, the serving network sends an HRES to the home network, and accordingly, the home network receives the HRES.
[0175] In step 113, the home network compares the HRES with the HXRES.
[0176] If they are the same, the home network returns the SUPI to the serving network and completes the authentication of the terminal. If they are not the same, the authentication of the terminal fails.
[0177] In step 114, the terminal sends a data packet to the home network via the service network, wherein the data packet includes a message indicating synchronization failure.
[0178] In step 115, the terminal sends a MAC failure message to the service network. Correspondingly, the service network receives the MAC failure message.
[0179] As shown in Figure 1, during the authentication process, the home network stores the necessary information, while the service network does not. Therefore, the service network cannot authenticate the terminal's access, requiring the home network to complete the authentication. This makes the entire authentication process complex. Furthermore, operators need to maintain a large amount of user information, which poses a risk of leakage through a single point of attack, resulting in lower security. Furthermore, the home network and the terminal authenticate using a symmetric key. If either party is attacked, the key is also compromised, resulting in lower security. For example, if the home network is attacked, the key is compromised, resulting in lower security.
[0180] To solve the above problems, this application provides an access authentication method. The network element of the target operator that the terminal accesses this time (referred to as the verification network element) can obtain the file information corresponding to the user identifier from the storage network element based on the user identifier from the terminal, so as to complete the authentication of the terminal based on the above file information. In other words, even if the verification network element is not the network element of the home operator, the file information corresponding to the user identifier can be obtained to complete the authentication of the terminal without falling back to the home operator authentication, which is conducive to simplifying the authentication process. The above file information includes the public key of the terminal. Authentication of the terminal based on the public key of the terminal is more secure and flexible than using a symmetric key.
[0181] The access authentication method provided in the embodiment of the present application can be applied to a fourth generation (4G) communication system, such as a long term evolution (LTE) communication system, and can also be applied to a fifth generation (5G) communication system, such as a 5G new radio (NR) communication system, or to various communication systems evolved after 5G, such as a sixth generation (6G) communication system. The method provided in the embodiment of the present application can also be applied to a Bluetooth system, a wireless fidelity (Wi-Fi) system, a long range Internet of Things (LoRa) system, or a vehicle network system. The method provided in the embodiment of the present application can also be applied to a satellite communication system, wherein the satellite communication system can be integrated with the above-mentioned communication system.
[0182] To facilitate understanding of the embodiments of the present application, the application scenarios applicable to the present application are described using the communication system architecture shown in Figure 2A as an example. Figure 2A is a possible, non-limiting system schematic diagram. As shown in Figure 2A, the communication system 1000 includes a radio access network (RAN) 100 and a core network (CN) 200. The RAN 100 includes at least one network device (such as 110a and 110b in Figure 2A, collectively referred to as 110) and at least one terminal (such as 120a-120j in Figure 2A, collectively referred to as 120). The RAN 100 may also include other RAN nodes, such as wireless relay devices and / or wireless backhaul devices (not shown in Figure 2A). The terminal 120 is connected to the network device 110 via a wireless method. The network device 110 is connected to the core network 200 via a wireless or wired method. The core network device in the core network 200 and the network device 110 in the RAN 100 may be different physical devices, or may be the same physical device that integrates core network logical functions and radio access network logical functions.
[0183] The RAN 100 may be a cellular system related to the Third Generation Partnership Project (3GPP), such as a 4G or 5G mobile communication system, or an evolved system beyond 5G (such as a 6G mobile communication system). The RAN 100 may also be an open access network (O-RAN or ORAN), a cloud radio access network (CRAN), or a Wi-Fi system. The RAN 100 may also be a communication system that integrates two or more of the above systems.
[0184] In the present application, the terminal may be, for example, the terminal 120 in FIG. 2A ; the verification network element may be, for example, a network element in the core network 200 shown in FIG. 2A , or the network device 110 shown in FIG. 2A ; the storage network element may be, for example, a network element in the core network 200 shown in FIG. 2A , or the network device 110 shown in FIG. 2A . The present application does not limit the specific types of the terminal, verification network element, and storage network element. It is understood that FIG. 2A only illustrates a possible communication system architecture that can be applied in embodiments of the present application. In other possible scenarios, the communication system architecture may also include other devices.
[0185] The network device 110 is a node in the radio access network (RAN), and can also be called an access network device or a RAN node (or device). The network device 110 is used to help terminals achieve wireless access. The multiple network devices 110 in the communication system 1000 can be nodes of the same type or different types. In some scenarios, the roles of the network device 110 and the terminal 120 are relative. For example, the network element 120i in Figure 2A can be a helicopter or a drone, which can be configured as a mobile base station. For the terminal 120j that accesses the RAN 100 through the network element 120i, the network element 120i is a base station; but for the base station 110a, the network element 120i is a terminal. The network device 110 and the terminal 120 are sometimes referred to as communication devices. For example, the network elements 110a and 110b in Figure 2A can be understood as communication devices with base station functions, and the network elements 120a-120j can be understood as communication devices with terminal functions.
[0186] In one possible scenario, a network device may be a base station, an evolved NodeB (eNodeB), a transmitting and receiving point (TRP), a transmitting point (TP), a next-generation NodeB (gNB), a next-generation base station in a 6G mobile communication system, a base station in a future mobile communication system, a satellite, an access point (AP) in a Wi-Fi system, an integrated access and backhaul (IAB) node, a mobile switching center, or a network device in a non-terrestrial network (NTN) communication system, i.e., it may be deployed on a high-altitude platform or satellite. The network device may be a macro base station (such as 110a in FIG2A ), a micro base station or an indoor station (such as 110b in FIG2A ), a relay node or a donor node, or a wireless controller in a CRAN scenario. The network device may also be a device that functions as a base station in device-to-device (D2D) communication, vehicle-to-vehicle communication, drone communication, or machine communication. Optionally, the network device may also be a server, a wearable device, a vehicle or an onboard device, etc. For example, the access network device in vehicle to everything (V2X) technology may be a road side unit (RSU).
[0187] In another possible scenario, multiple network devices collaborate to assist the terminal in achieving wireless access, and different network devices respectively implement part of the functions of the base station. For example, the network device can be a centralized unit (CU), a distributed unit (DU), a CU-control plane (CP), a CU-user plane (UP), or a radio unit (RU). The CU and DU can be set separately, or can also be included in the same network element, such as a baseband unit (BBU). The RU can be included in a radio frequency device or a radio frequency unit, such as a remote radio unit (RRU), an active antenna unit (AAU), or a remote radio head (RRH). It can be understood that the network device can be a CU node, a DU node, or a device including a CU node and a DU node. In addition, the CU can be divided into a network device in the access network RAN, or the CU can be divided into a network device in the core network CN, which is not limited here.
[0188] In different systems, CU (or CU-CP and CU-UP), DU or RU may also have different names, but those skilled in the art can understand their meanings. For example, in the ORAN system, CU may also be called O-CU (Open CU), DU may also be called O-DU, CU-CP may also be called O-CU-CP, CU-UP may also be called O-CU-UP, and RU may also be called O-RU. For the convenience of description, this application uses CU, CU-CP, CU-UP, DU and RU as examples for description. Any unit of CU (or CU-CP, CU-UP), DU and RU in this application can be implemented by a software module, a hardware module, or a combination of a software module and a hardware module.
[0189] In the embodiments of the present application, the form of the network device is not limited. The device used to implement the function of the network device can be a network device; it can also be a device that can support the network device to implement the function, such as a chip system. The device can be installed in the network device or used in conjunction with the network device.
[0190] A terminal can also be called a terminal device, user equipment (UE), mobile station (MS), mobile terminal (MT), or a device that provides voice or data connectivity to users. It can also be an IoT device. For example, terminal devices include handheld devices with wireless connectivity, in-vehicle devices, etc. Currently, terminals may include, for example, mobile phones, tablet computers, laptop computers, PDAs, mobile internet devices (MIDs), wearable devices (such as smart watches, smart bracelets, pedometers, smart glasses, etc.), vehicle-mounted equipment (such as cars, bicycles, electric vehicles, airplanes, ships, trains, high-speed trains, etc.), satellite terminals, virtual reality (VR) equipment, augmented reality (AR) equipment, smart point of sale (POS) machines, customer-premises equipment (CPE), wireless terminals in industrial control, smart home devices (such as refrigerators, televisions, air conditioners, electricity meters, etc.), intelligent robots, robotic arms, workshop equipment, wireless terminals in unmanned driving, wireless terminals in smart medical care, wireless terminals in smart grids, wireless terminals in transportation safety, wireless terminals in smart cities, or wireless terminals in smart homes, flying equipment (such as intelligent robots, hot air balloons, drones, airplanes), etc. The terminal device can also be a vehicle device, such as a complete vehicle device, a vehicle-mounted module, a vehicle-mounted chip, an on-board unit (OBU) or a telematics box (T-BOX), etc. The terminal device can also be other devices with terminal functions. For example, the terminal device can also be a device that serves as a terminal function in D2D communication.
[0191] The embodiments of this application do not limit the device form factor of the terminal. The device used to implement the terminal's function can be a terminal; it can also be a device that supports the terminal in implementing the function, such as a chip system. The device can be installed in the terminal or used in conjunction with the terminal. In the embodiments of this application, the chip system can be composed of a chip or include a chip and other discrete components.
[0192] Before describing in detail the access authentication method provided by this application, the blockchain is first explained in detail in conjunction with Figure 2B.
[0193] Figure 2B is a schematic diagram of a blockchain provided in an embodiment of the present application. It should be understood that, in the present application, blockchain is an example of a distributed storage system and should not constitute any limitation to the present application. For example, nodes on other types of distributed storage systems may also store user identifiers and corresponding file information.
[0194] As shown in Figure 2B, card vendors (such as universal integrated circuit cards (UICC), which can be referred to as block chain UICC (B-UICC) in this application), terminal manufacturers, operators, social authorities, third-party organizations, and other parties jointly build (or maintain) a blockchain and publish their respective identifiers and file information corresponding to the identifiers on the blockchain. In other words, the identifiers and corresponding file information can be shared between each node in at least one node on the blockchain. Therefore, in this application, when a terminal accesses a network in a different place (non-home location), it can be authenticated by the accessed network without returning to the home network for authentication. In addition, in Figure 2B, the air card writing server can be used to write relevant information about the contract between the user and the operator into the file information. The air card writing server can be deployed jointly with the operator or the card vendor.
[0195] It should be noted that, in the present application, the identifier may specifically be a self-control identity (scID), and several types of scID will be introduced in detail below.
[0196] For institutions (such as card vendors, terminal equipment manufacturers, operators, social authorities or third-party institutions), scID includes centralized user root credentials (DRC) or decentralized user identity credentials (DIC). Among them, DRC is the trust root of the institution, and DIC is derived from DRC. For example, China Mobile serves as DRC, Beijing Mobile serves as DIC 1, and Shanghai Mobile serves as DIC 2. Each DRC or DIC corresponds to file information (profile). The authentication credentials in the DIC file are signed and endorsed by the private key corresponding to the DRC, and the file information includes information about the services that can be provided.
[0197] For users (such as terminals or B-UICCs), scID can include DRC, DIC, decentralized self-control credentials (DSCC) or self-control identity credentials (SCIC). Among them, DRC is preset in the card by the card vendor / terminal device manufacturer when it leaves the factory. The credential information (or authentication credential) in the file information corresponding to DRC is endorsed by the card vendor / terminal manufacturer, for example, signed by the card vendor / terminal manufacturer's private key. DIC is one or more temporary / derived identities derived from DRC. The credential information in the file information corresponding to DIC can be endorsed by DRC, for example, signed by DRC's private key, or endorsed by the operator, for example, signed by the operator's private key. DSCC is generated by the user himself for the purpose of controlling his identity information and is independent of DRC or DIC. The credential information in the file information corresponding to DSCC is signed by the terminal / card itself, or endorsed by the contracted operator after signing the contract, for example, signed by the operator's private key. SCIC is derived from DSCC. The credential information in the file information corresponding to the SCIC can be endorsed by the DSCC, for example, signed by the DSCC's private key, or endorsed by the operator, that is, signed by the operator's private key. Each DRC, DIC, DSCC, or SCIC corresponds to a file information, which includes information required to authenticate the terminal. For example, this file information includes but is not limited to: the terminal's public key, contracting party, validity period, and other information. This file information may also include at least one authentication credential that can be used to authenticate the terminal and / or the algorithm corresponding to each authentication credential. As shown in Figure 2B, the verification network element can obtain the information required to authenticate the terminal from the blockchain.
[0198] The access authentication method provided by this application will be described in detail below with reference to the accompanying drawings.
[0199] Figure 3 is a schematic flow chart of the access authentication method 300 provided in an embodiment of the present application. Figure 3 only describes the method from the perspective of the interaction between the terminal, the verification network element, and the storage network element, and should not constitute any limitation to the present application. The terminal in Figure 3 can be replaced by a component configured in the terminal (such as a chip, a chip system, a processor, etc.), or a logic module or software that can implement all or part of the functions of the terminal; the verification network element can be replaced by a component configured in the verification network element (such as a chip, a chip system, a processor, etc.), or a logic module or software that can implement all or part of the functions of the verification network element; the storage network element can be replaced by a component configured in the storage network element (such as a chip, a chip system, a processor, etc.), or a logic module or software that can implement all or part of the functions of the storage network element.
[0200] The method 300 shown in Figure 3 includes steps 310 to 340. Each step in the method 300 will be described in detail below.
[0201] In step 310, the terminal obtains a user identifier.
[0202] The user identifier is used to identify the terminal, or in other words, the user identifier is used to identify the UICC in the terminal, wherein the UICC can be a physical card, an embedded card embedded in hardware, or a software card, etc., which is not limited in this application. The above user identifier corresponds to the file information stored in the network element.
[0203] In the present application, the terminal may include one or more user identifiers, each user identifier corresponds to a file information, and the file information includes the credential information required to authenticate the terminal. For example, the file information includes the public key of the terminal, the validity period of the authentication credential, the issuer of the authentication credential, etc., wherein the authentication credential can be, for example, a certificate (this application does not limit the format standard of the certificate, such as a certificate in X.509 format, a lightweight certificate, or a certificate in an operator-defined format, etc.).
[0204] Exemplarily, the terminal obtains the user ID required for this access to the operator. This user ID can be the user ID used when the user signed a contract with the operator being accessed. For example, the terminal completes the contract with operator 1 based on user ID 1, and the contract-related information is written to the file information corresponding to user ID 1. When the terminal accesses operator 1, user ID 1 can be obtained to complete authentication.
[0205] It is understood that the terminal may have contracts with multiple operators, or in other words, the terminal may pre-set user identifiers and file information corresponding to multiple operators without having signed a contract with an operator. In one possible implementation, before obtaining the user identifier, the terminal may determine the target operator to be connected to the terminal from the multiple operators.
[0206] In a first possible implementation, the terminal determines a target operator from among multiple operators based on one or more of the following: the user's location, the service quality of each of the multiple operators (e.g., signal strength), the cost of each of the multiple operators, or the security of each of the multiple operators. By way of example and not limitation, the terminal may select the operator at the user's location as the target operator, the operator with the strongest signal strength among the multiple operators as the target operator, or the operator with the lowest cost among the multiple operators as the target operator.
[0207] Exemplarily, in response to a user selecting one or more of the following conditions, the terminal determines the target operator based on the conditions selected by the user: the target operator is the operator at the user's location among multiple operators; the target operator is the operator with the strongest signal strength among multiple operators; or, the target operator is the operator with the lowest cost among multiple operators, or, the target operator is the operator with the highest security among multiple operators.
[0208] A second possible implementation manner is that the terminal determines the target operator from multiple operators in response to a user operation, wherein the user operation is an operation of the user selecting the target operator from the multiple operators.
[0209] Exemplarily, in response to a user selecting a target operator from multiple operators, the terminal determines the target operator. For example, the terminal displays Operator 1, Operator 2, Operator 3, and Operator 4 through a user interface, each operator corresponding to signal strength, location, or cost, etc. In response to the user selecting Operator 1, the terminal determines the target operator to be Operator 1. In other words, the terminal selects Operator 1 for access authentication.
[0210] A third possible implementation manner is that the terminal randomly selects any one of multiple operators as the target operator.
[0211] It should be noted that the above-mentioned multiple operators may be operators on a distributed storage system (such as a blockchain), or they may not be operators on a distributed storage system, and this application does not limit this. For example, when the above-mentioned multiple operators are not operators on a distributed storage system, the above-mentioned multiple operators take operator A and operator B as an example. Operator A and operator B have signed mutually trustworthy certificates, that is, both parties can obtain the information required by the other party to authenticate the terminal. In the first case, operators A and B both pre-set each other's certificates as trusted certificates; or, in the second case, operator A and operator B signed cross-certification certificates with each other; or, in the third case, operator A and operator B established trust through a bridge. Then operators A and B are not on the blockchain. When a terminal holding a certificate issued by operator A accesses the network of operator B, in the first case, operator B pre-sets operator A's certificate as the root of trust, and operator B can directly authenticate the terminal (verify the terminal's certificate based on operator A's certificate); in the second case, the cross-certificate issued by operator B to operator A is verified based on operator B's certificate, and the terminal's certificate is further verified; in the third case, the certificate of operator A is verified based on the bridge's certificate, and the terminal's certificate is further verified based on operator A's certificate. It is understandable that if operator A and operator B are neither operators on the distributed storage system nor have signed mutually trusted certificates, it may be necessary to return to the home operator to authenticate the terminal. However, in this application, each operator on the distributed storage system can authenticate the terminal as the home operator, which has more options and higher flexibility.
[0212] FIG4 is a schematic diagram of the contract signing methods of various operators provided in an embodiment of the present application.
[0213] As shown in Figure 4, the terminal is pre-installed with multiple user identifiers, such as the DSCC, DRC, SCIC 1 to SCIC m derived from the DSCC, and DIC 1 to DIC p derived from the DRC. Each user identifier corresponds to file information, where m and p are positive integers greater than or equal to 1. A user can sign a contract with operator 1 based on DIC 1. Contract-related information (such as the contracting party, validity period, and the terminal's public key) is written to the file information corresponding to DIC 1. When the user accesses operator 1's network, the terminal can use DIC 1 for access authentication. The user can also sign a contract with operator 2 based on DIC 2. Contract-related information is written to the file information corresponding to DIC 2. When the user accesses operator 2's network, the terminal uses DIC 2 for access authentication. The user can also sign a contract with operator 3 based on the DRC. The operator will then issue the SUPI and its corresponding file information. When the user accesses operator 3's network, the terminal uses the SUPI for access authentication.
[0214] Optionally, the information required for terminal access authentication (or the file information corresponding to the user identification) can be obtained from the blockchain. It will be understood that the above-mentioned blockchain is only an example and should not constitute any limitation to the embodiments of the present application. For example, other types of distributed storage systems, such as decentralized shared file information storage systems, or IPFS, etc., can also store file information, and this application does not limit this. The nodes of these distributed storage systems can be network elements of the core network. In addition, there can also be a network element inside the core network as an agent of the distributed storage system, which regularly synchronizes the file information on the distributed storage system to provide it to the verification network element for authentication.
[0215] In step 320, the terminal sends a user identifier to the verification network element, and the verification network element receives the user identifier.
[0216] The verification network element is a network element of the target operator accessed by the terminal. For example, the verification network element may be a core network element of the target operator accessed by the terminal, such as an AUSF network element, an AMF network element, or any other core network element. For another example, the verification network element may also be an access network element of the target operator accessed by the terminal, such as an access network node accessed by the terminal, which is not limited in this application.
[0217] The user identification may be encrypted using a session key, where the session key may be generated, for example, based on the terminal's temporary private key and the verification network element's public key. In other words, the terminal may generate a session key based on the terminal's temporary private key and the verification network element's public key, encrypt information such as the user identification using the session key, and send the encrypted user identification to the verification network element.
[0218] In one possible implementation, the user identifier includes a DRC, DIC, DSCC, or SCIC. As described above, each DRC, DIC, DSCC, or SCIC corresponds to file information. The operator can use other endorsement credential information of the DRC, DIC, DSCC, or SCIC to complete the initial contract authentication and then issue a credential endorsed by the operator for access authentication. Alternatively, the operator can directly use other endorsement credentials from the initial authentication for subsequent access authentication.
[0219] That is, the terminal may send DRC, DIC, DSCC or SCIC to the verification network element, and accordingly, the verification network element may receive the above user identification to obtain the file information corresponding to the above user identification, and then authenticate the terminal.
[0220] The file information may include authentication credentials (such as certificates), which may include one or more of the following information: public key, issuer, validity period, issuer's signature, version number, terminal identification, certificate status query method (such as revocation list information, OCSP, etc.). Among them, the issuer specifies the identification of the endorser who endorses the authentication credential. For example, DIC has two authentication credentials, one of which is derived from DRC, then the issuer of this authentication credential is DRC; the other authentication credential is signed by the operator, then the issuer of this authentication credential is the operator's scID. For another example, if DSCC is self-generated, then the issuer of this authentication credential is the terminal.
[0221] In a possible implementation, the user identifier includes a false identity identifier, the false identity identifier corresponds to a real identity identifier, and the real identity identifier and corresponding file information are stored in the storage network element.
[0222] It is understandable that sending a false identity identifier by the terminal helps improve security. The storage network element can store the real identity identifier (or the identity identifier used during contract signing) and the corresponding file information. There is a corresponding relationship between the false identity identifier and the real identity identifier. The storage network element can determine the real identity identifier based on the false identity identifier and the above corresponding relationship, and then determine the corresponding file information based on the real identity identifier.
[0223] Among them, the above-mentioned real identity identifier can be, for example, the DRC, DIC, DSCC or SCIC mentioned above, and this application does not limit this.
[0224] In a possible implementation, the user identifier includes a transaction address, and the transaction address is used to indicate the location of the file information corresponding to the user identifier on the distributed storage system.
[0225] The user identification may include a transaction address, that is, the location of the file information used to authenticate the terminal on the distributed storage system.
[0226] Optionally, the transaction address may be one or more, which is not limited in this application. When there are multiple transaction addresses, it means that the file information used to authenticate the terminal is split into multiple parts and stored in multiple locations on the distributed storage system. The storage unit can determine the parts of the file information stored in each location based on the transaction address, and then synthesize the entire file information. The entire file information can correspond to a DRC, DIC, DSCC, or SCIC.
[0227] In one possible scenario, the terminal may send a transaction address to the verification network element, and the verification network element obtains the corresponding file information from the storage network element based on the transaction address. Accordingly, the storage network element determines the corresponding file information based on the transaction address.
[0228] In another possible scenario, the terminal can send a transaction address and one of the following: DRC, DIC, DSCC, SCIC, or a false identity identifier to the verification network element. For example, one of the following: DRC, DIC, DSCC, SCIC, or a false identity identifier can be used to query the corresponding file information. Assuming that the file information includes multiple authentication credentials and the algorithm corresponding to each authentication credential, the transaction address can be used to determine the target authentication credential from the multiple authentication credentials. In other words, the terminal can indicate which authentication credential to select using the transaction address. In one possible implementation, the authentication credential can be understood as a certificate, and different authentication credentials can be understood as certificates with different format standards, such as X.509 certificates or lightweight certificates. The algorithm corresponding to each authentication credential can include the signature algorithm used in the certificate and the signature verification algorithm to be used. Each authentication credential can correspond to one or more algorithms, which is not limited in this application. In another possible implementation, the different authentication credentials may be multiple certificates with the same format standard. For example, a terminal may have three authentication credentials, all in X.509 format.
[0229] In one possible implementation, in addition to the public key, issuer and other information listed above, the file information may also include the transaction address of the issuer's information on the blockchain. The transaction address can be one or more, and this application does not limit this.
[0230] In one possible implementation, the user identifier is carried in the first signaling, which also includes the type of the user identifier and / or an identifier of the distributed storage system, where the identifier of the distributed storage system is used to identify the distributed storage system where the file information corresponding to the user identifier is located.
[0231] The user identifier type is used to indicate the format of the first signaling to the verification network element. For example, if the user identifier type indicates that the user identifier carried in the first signaling is a SUCI, the verification network element parses the signaling based on the format of the signaling carrying the SUCI. If the user identifier type indicates that the user identifier carried in the first signaling is not a SUCI, or indicates that the user identifier carried in the first signaling is any of the above-mentioned scIDs, transaction addresses, or false identities, the verification network element may parse the signaling based on the signaling format shown in FIG5 . Optionally, the user identifier type may also inform the verification network element of the type of the user identifier carried in the first signaling, for example, the user identifier type is a DRC, DIC, DSCC, SCIC, transaction address, or false identity.
[0232] The distributed storage system identifier is used to identify the distributed storage system where the file information corresponding to the user identifier is located. Taking a blockchain as an example, the distributed storage system is used to identify the blockchain to which the identity information belongs, or in other words, to identify the blockchain where the file information corresponding to the current user identifier is located. It will be appreciated that when multiple blockchains exist, the blockchain identifier facilitates the verification network element in determining the blockchain where the file information corresponding to the user identifier is located, thereby obtaining the file information corresponding to the user identifier on the corresponding blockchain.
[0233] It should be understood that the information carried in the above-mentioned first signaling is only an example and should not constitute any limitation to this application. For example, the first signaling may also include a network identifier (network identifier), a network public key (PK), a terminal temporary public key, etc. Among them, the network PK is used to identify the network public key used to encrypt the user identifier. For example, the network may have multiple public keys, so the terminal needs to indicate which public key is used when calculating the session key, so that the network can determine which public key corresponds to the private key used when calculating the session key.
[0234] An example of the signaling format for interaction between the terminal and the verification network element will be given below in conjunction with Figure 5. Figure 5 is a schematic diagram of the format of the first signaling provided in an embodiment of the present application. As shown in Figure 5, the first signaling includes a plaintext part and a ciphertext part. The plaintext part includes the type of user identifier, network identifier, network PK, and terminal temporary public key. Optionally, the plaintext part also includes the identifier of the blockchain. The ciphertext part includes encrypted data, which is ciphertext data obtained by encrypting the user identifier, random number, session identifier, etc. based on the session key, wherein the session key can be a symmetric key generated based on the temporary private key of the terminal and the network public key.
[0235] In step 330, the verification network element obtains the file information corresponding to the user identifier from the storage network element. The file information includes the public key of the terminal. Step 330 may specifically include steps 331 and 332.
[0236] In step 331, the verification network element sends the user identification to the storage network element.
[0237] In step 332, the storage network element sends the file information corresponding to the user identifier to the verification network element.
[0238] After receiving the user identification from the verification network element, the storage network element determines the file information corresponding to the user identification, and then sends the file information corresponding to the user identification to the verification network element.
[0239] In one example, the user identifier is DRC, DIC, DSCC or SCIC. The storage network element determines the file information corresponding to the user identifier according to the user identifier, and sends the file information corresponding to the user identifier to the verification network element.
[0240] In another example, the user identifier is a false identifier. The storage network element can determine the real identifier based on the false identifier and the above correspondence, and then determine the corresponding file information based on the real identifier, and send the above file information to the verification network element.
[0241] In another example, the user identifier is a transaction address. The storage network element can determine one or more locations where file information is stored on the distributed storage system based on the transaction address, and then obtain the file information at the corresponding location. After obtaining the file information, it sends the file information corresponding to the above transaction address to the verification network element.
[0242] In a possible implementation, the storage network element is a node on a distributed storage system, and the node stores at least one user identifier and file information corresponding to each user identifier.
[0243] In the present application, the distributed storage system may include one or more nodes, each node may store at least one user identifier and file information corresponding to each user identifier, and the above-mentioned storage network element may be any one of the above-mentioned one or more nodes.
[0244] It should be noted that the aforementioned storage network element is a node in a distributed storage system for illustrative purposes only and should not constitute any limitation to this application. For example, in actual applications, the storage network element may also be another management network element, such as a network element within the core network. This network element can act as a proxy for the distributed storage system, regularly synchronizing file information on the distributed storage system and providing it to the verification network element for authentication.
[0245] In addition, in this application, the verification network element and the storage network element can be the same network element or different network elements, and this application does not limit this. When the verification network element and the storage network element are the same network element, the verification network element obtains the file information corresponding to the user identifier from the storage network element, which can be understood as the verification network element obtaining the file information corresponding to the user identifier from the memory or local storage; when the verification network element and the storage network element are different network elements, the verification network element obtains the file information corresponding to the user identifier from the storage network element, which can be understood as the verification network element sending the user identifier to the storage network element and receiving the file information corresponding to the above-mentioned user identifier from the storage network element.
[0246] In one possible implementation, the distributed storage system is a blockchain, a decentralized shared file information storage system, or an InterPlanetary File System. For details about the blockchain, see Figure 2B.
[0247] In step 340, the verification network element authenticates the terminal based on the above file information.
[0248] After obtaining the file information corresponding to the user identifier from the storage network element, the verification network element authenticates the terminal based on the file information, wherein the file information includes information required for terminal authentication, such as the public key of the terminal.
[0249] One possible implementation method is that the verification network element can verify the digital signature of the terminal based on the public key of the above-mentioned terminal. If the verification network element succeeds in verifying the digital signature of the terminal, it is considered that the verification network element has succeeded in authenticating the terminal. Correspondingly, if the verification network element fails to verify the digital signature of the terminal, it is considered that the verification network element has failed in authenticating the terminal.
[0250] Exemplarily, a verification network element receives a first message from a terminal and a digital signature of the terminal, where the digital signature of the terminal is obtained by signing a second message or a hash value of the second message using the terminal's private key, where the second message is a message previously exchanged between the terminal and the verification network element or the first message; and verifies the digital signature of the terminal based on the terminal's public key. The second message may be one or more of all messages previously exchanged between the terminal and the verification network element, which is not limited in this application.
[0251] For example, before the terminal sends the first message, the messages exchanged between the terminal and the verification network element include message 1 (for example, it can be a message sent by the terminal to the verification network element), message 2 (for example, it can be a message sent by the verification network element to the terminal), and message 3 (for example, it can be a message sent by the verification network element to the terminal). The terminal can sign the hash value of message 1, the hash value of message 2, and the hash value of message 3 based on the terminal's private key to obtain the terminal's digital signature, and send the first message and the above-mentioned digital signature of the terminal to the verification network element, where message 1, message 2, and message 3 are examples of the second message. After receiving the first message and the digital signature of the terminal, the verification network element verifies the digital signature of the terminal based on the terminal's public key.
[0252] Optionally, before verifying the digital signature of the terminal based on the public key of the terminal, the above method also includes: obtaining the authentication certificate of the issuer from the storage network element, the issuer is the issuer of the authentication certificate of the terminal; verifying the authentication certificate of the terminal based on the authentication certificate of the issuer.
[0253] It is understood that the verification network element can obtain the corresponding file information based on the terminal's user identity and verify the terminal's signature based on the public key. Prior to this, the verification network element can also verify the terminal's authentication credentials based on the issuer information of the terminal's authentication credentials. For example, taking a certificate as an example of an authentication credential, the verification network element verifies the terminal's signature by first obtaining the terminal's certificate based on the user identity. Based on the issuer information (or transaction address information) in the certificate, the verification network element obtains the issuer's certificate from the blockchain or storage network element. For example, a certain operator / card dealer, the operator / card dealer's public key is first used to verify the terminal's certificate. Further, the terminal's digital signature is verified using the public key in the terminal's certificate. The verification chain can be even longer (indicating that the user can derive more identities), for example: verifying the DRC's certificate based on the public key in the card dealer's certificate, then verifying the DIC's certificate based on the DRC's public key, and then verifying the terminal's digital signature based on the DIC's public key; or verifying the DIC's certificate based on the operator's public key, and then verifying the terminal's digital signature based on the DIC's public key. Optionally, the above method 300 also includes: the verification network element sends a third message and the digital signature of the verification network element to the terminal, and the digital signature of the verification network element is obtained by signing the fourth message or the hash value of the fourth message based on the private key of the verification network element, wherein the fourth message is a message exchanged between the terminal and the verification network element or the above third message.
[0254] The verification network element sends the digital signature of the verification network element to the terminal, so that the terminal can verify the digital signature of the verification network element based on the public key of the verification network element. By verifying the verification network element based on the public key of the verification network element, the terminal can verify the verification network element corresponding to any operator. In this way, the terminal can access different operators with greater flexibility.
[0255] The fourth message may be one or more of all messages exchanged between the terminal and the verification network element. It is understood that since the verification network element receives the second message and sends the third message at different times, the messages exchanged between the terminal and the verification network element may also change, and therefore the second message and the fourth message may be different.
[0256] Exemplarily, before the verification network element sends the third message, the messages exchanged between the terminal and the verification network element include message 1 (for example, a message sent by the terminal to the verification network element) and message 2 (for example, a message sent by the verification network element to the terminal). The verification network element can sign the hash value of message 1 and the hash value of message 2 based on the private key of the verification network element to obtain the digital signature of the verification network element, and send the third message and the digital signature of the verification network element to the terminal, where message 1 and message 2 are examples of the second message. After receiving the third message and the digital signature of the verification network element, the terminal verifies the digital signature of the verification network element based on the public key of the verification network element.
[0257] It should be noted that the verification network element may receive the first message and the digital signature of the terminal before sending the third message and the digital signature of the verification network element, or may receive the first message and the digital signature of the terminal after sending the third message and the digital signature of the verification network element. This application does not limit this. For example, the verification network element may receive the first message and the digital signature of the terminal, and verify the digital signature of the terminal based on the public key of the terminal. If the verification passes, the verification network element may send the third message and the digital signature of the verification network element to the terminal.
[0258] Optionally, the method 300 further includes: the verification network element sending a certificate of the verification network element to the terminal.
[0259] By sending the certificate of the verification network element to the terminal, the terminal does not need to pre-set the certificate of the verification network element. When there are a large number of verification network elements, the terminal does not need to pre-set the certificate of each verification network element, which is conducive to saving the storage space of the terminal.
[0260] The certificate of the verification network element includes, for example, the verification network element's public key, issuer, validity period, issuer's signature, version number, verification network element identifier, and certificate status query method (e.g., revocation list information, OCSP, etc.). If the terminal does not have the certificate of the verification network element pre-installed, the terminal may pre-install the target operator's certificate, where the target operator's certificate includes the operator's public key. The terminal may verify the verification network element's certificate based on the target operator's certificate, and then verify the verification network element's digital signature based on the verification network element's public key. The verification network element's certificate is issued by the operator, meaning that the signature of the verification network element's certificate is generated using the operator's private key. The terminal may use the public key in the operator's certificate to verify the signature of the verification network element's certificate; and use the public key in the verification network element's certificate to verify the verification network element's digital signature. If both of the above processes are successful, the authentication terminal successfully authenticates the verification network element.
[0261] Optionally, the certificate of the verification network element and the digital signature of the verification network element can be carried in the same signaling or in different signalings, which is not limited in this application.
[0262] Optionally, the above-mentioned file information also includes at least one authentication credential and the algorithm corresponding to each authentication credential in the at least one authentication credential; and the above-mentioned method 300 also includes: the verification network element determines the target authentication credential from the at least one authentication credential; and sends a first indication information to the terminal, and the first indication information is used to indicate the target authentication credential and / or the algorithm corresponding to the target authentication credential.
[0263] In this application, one possible design is that different authentication credentials can be understood as certificates of different format standards, such as certificates in X.509 format, lightweight certificates, certificates in operator-customized formats, etc. The algorithms corresponding to each authentication credential may include the signature algorithm used in the certificate and the signature verification algorithm that needs to be used. The algorithms corresponding to each authentication credential may be one or more, and this application does not limit this. Another possible design is that different authentication credentials may be multiple certificates of the same format standard. For example, a terminal may have three authentication credentials, and the formats of the three authentication credentials are all in X.509 format.
[0264] Exemplarily, after the verification network element obtains the file information corresponding to the above-mentioned file identifier, it can determine the target authentication credential from at least one authentication credential included in the file information, and indicate the target authentication credential and / or the algorithm corresponding to the target authentication credential to the terminal. For example, the above-mentioned file information includes certificate 1, certificate 2, and certificate 3, wherein each certificate includes the public key, issuer, validity period, etc. of the terminal, and the above-mentioned certificate 1, certificate 2, and certificate 3 can be certificates of different format standards. The verification network element can determine that the target authentication credential is certificate 1, and then indicate certificate 1 and the corresponding algorithm (such as the signature algorithm used in the certificate and the signature verification algorithm to be used, etc.) to the terminal.
[0265] The access authentication process shown in Figure 3 is described in detail below in conjunction with Figures 6 to 8. In the embodiment shown in Figure 6, the user identifier sent by the terminal to the verification network element includes a DRC, DIC, DSCC, or SCIC, which can be collectively referred to as an scID. In the embodiment shown in Figure 7, the user identifier sent by the terminal to the verification network element includes a transaction address. In the embodiment shown in Figure 8, the user identifier sent by the terminal to the verification network element includes a false identity identifier.
[0266] FIG6 is a schematic diagram of the access authentication process provided in an embodiment of the present application.
[0267] In step 601, the terminal generates a first ciphertext, which includes an encrypted scID, a random number 1, and a session identifier.
[0268] The first ciphertext may be obtained by encrypting the scID, a random number 1, and a session identifier based on a session key. The session key may be generated based on the terminal's temporary private key and the verification network element's public key. The session identifier is used to identify the current session. The random number 1 can be used to prevent replay attacks. For example, if the terminal includes a random number 1 in a message sent to the verification network element, the digital signature of the verification network element sent by the verification network element will include the random number 1 to prevent a third party from performing a replay attack on the terminal.
[0269] Exemplarily, the terminal generates a temporary public-private key pair used for this access to the network, and generates a session key based on the temporary private key and the public key of the verification network element (the public key of the verification network element can be preset), and uses the session key to encrypt scID, random number 1, and session identifier, etc.
[0270] Optionally, the public key of the verification network element can also be replaced by the public key of the operator. In this case, the verification network element needs to have the private key of the operator. The operator and the verification network element can be a set of public and private keys.
[0271] In step 602, the terminal sends the first ciphertext and plaintext part to the verification network element. Correspondingly, the verification network element receives the first ciphertext and plaintext part.
[0272] The plain text part refers to the part that does not need to be encrypted, and the plain text part includes, but is not limited to: the type of user identification, network identification, network public key, terminal temporary public key, and distributed storage system identification.
[0273] Exemplarily, after generating the first ciphertext, the terminal sends the first ciphertext and plaintext parts to the verification network element. Correspondingly, the verification network element receives the first ciphertext and plaintext parts.
[0274] In step 603, the verification network element decrypts to obtain the scID, the random number 1, and the session identifier.
[0275] Exemplarily, the verification network element may use the private key of the verification network element and the temporary public key of the terminal to generate the above-mentioned session key, and decrypt the first ciphertext based on the above-mentioned session key to obtain the scID, the random number 1 and the session identifier.
[0276] In step 604, the verification network element obtains the file information corresponding to the scID from the storage network element based on the scID.
[0277] Exemplarily, the verification network element sends the scID to the storage network element, and the storage network element receives the scID accordingly. Further, the storage network element determines the file information corresponding to the scID based on the scID, and sends the file information to the verification network element. Accordingly, the verification network element receives the file information.
[0278] Optionally, the file information may include at least one authentication credential and an algorithm corresponding to each of the at least one authentication credential. For an explanation of the at least one authentication credential and the algorithm corresponding to each of the at least one authentication credential, please refer to the method corresponding to FIG3 and will not be repeated here.
[0279] In step 605, the verification network element generates a random number 2 and signs the fourth message based on the private key of the verification network element. The fourth message may be one or more of all messages exchanged between the terminal and the verification network element.
[0280] The random number 2 can be used to prevent replay attacks. For example, if the verification network element includes the random number 2 in the message sent to the terminal, the digital signature sent by the terminal includes the random number 2 to prevent a third party from replaying the verification network element.
[0281] The fourth message may be the message sent by the terminal to the verification network element in step 602, or the third message sent by the verification network element to the terminal in step 606, which is not limited in this application.
[0282] It can be understood that the verification network element can also sign the hash value of the fourth message based on the private key of the verification network element, and this application does not limit this.
[0283] In step 606, the verification network element sends the digital signature of the verification network element and a third message to the terminal, where the third message includes the verification network element identifier, random number 1, and random number 2. Accordingly, the terminal receives the digital signature of the verification network element and the third message.
[0284] The third message may be encrypted, for example, may be encrypted based on a session key generated by the verification network element.
[0285] Optionally, the third message may also include the verification network element's certificate. If it is the verification network element's certificate, the terminal's pre-installed certificate will be used to determine the certificate. If the terminal has the pre-installed certificate of the verification network element, direct verification can be performed. If the terminal has the pre-installed operator's certificate, the operator's certificate is first used to verify the verification network element's certificate, and then the verification network element's digital signature is verified using the verification network element's public key. For the specific process, please refer to the relevant description of Figure 3.
[0286] In step 607, the terminal verifies the digital signature of the verification network element based on the public key of the verification network element, and signs the second message based on the private key of the terminal.
[0287] The second message may be one or more of all messages exchanged between the terminal and the verification network element. For example, the second message may be the message sent by the terminal to the verification network element in step 602, the third message sent by the verification network element to the terminal in step 606, or the first message sent by the terminal to the verification network element in step 608. This application does not limit this.
[0288] It is understandable that the terminal may also sign the hash value of the second message based on the private key of the terminal, and this application does not limit this.
[0289] If the terminal successfully verifies the digital signature of the verification network element, step 608 is executed; if the terminal fails to verify the digital signature of the verification network element, the terminal access fails. For example, the terminal can try to re-access. In other words, the terminal can restart step 601.
[0290] In step 608, the terminal sends the digital signature of the terminal and a first message to the verification network element, where the first message includes the scID, random number 1, and random number 2. Correspondingly, the verification network element receives the digital signature of the terminal and the first message.
[0291] The first message may be encrypted, for example, may be encrypted based on a session key generated by the terminal.
[0292] Optionally, the terminal may also send its digital signature in step 602. In other words, the terminal may send its digital signature, the first ciphertext, and the plaintext portion in step 602. The terminal's digital signature may be obtained by signing the first ciphertext and plaintext portion using the terminal's private key, for example. In this case, the verification network element may perform step 609 after step 604, namely, verifying the terminal's digital signature using the terminal's public key. Furthermore, the terminal may not perform step 608.
[0293] In step 609 , the verification network element verifies the digital signature of the terminal based on the public key of the terminal obtained in step 604 .
[0294] After receiving the digital signature of the terminal and the first message, the verification network element verifies the digital signature of the terminal according to the public key of the terminal in the file information in step 604. If the verification network element succeeds in verifying the digital signature of the terminal, it is considered that the verification network element has successfully authenticated the terminal. Correspondingly, if the verification network element fails to verify the digital signature of the terminal, it is considered that the verification network element has failed to authenticate the terminal.
[0295] In step 610, the verification network element sends an indication message to the terminal indicating successful network registration and access. Correspondingly, the terminal receives the indication message.
[0296] FIG7 is another schematic diagram of the access authentication process provided in an embodiment of the present application.
[0297] In step 701, the terminal generates a first ciphertext, which includes encrypted transaction address information, a random number 1, and a session identifier.
[0298] The first ciphertext may be obtained by encrypting the transaction address information, the random number 1, and the session identifier based on a session key, where the session key may be generated based on a temporary private key of the terminal and a public key of the verification network element. The session identifier is used to identify the current session.
[0299] In one possible implementation, the transaction address information may include a list of transaction addresses and their number. The number refers to the number of transaction addresses in the transaction address list. The transaction address list includes one or more transaction addresses, which are used to indicate the location of file information on the distributed storage system. A more detailed description of the transaction address can be found in Figure 3 and will not be repeated here.
[0300] Exemplarily, the terminal generates a temporary public-private key pair used for this access to the network, and generates a session key based on the temporary private key and the public key of the verification network element (the public key of the verification network element can be preset), and uses the session key to encrypt the transaction address list and quantity, random number 1, and session identifier, etc.
[0301] In step 702, the terminal sends the first ciphertext and plaintext part to the verification network element. Correspondingly, the verification network element receives the first ciphertext and plaintext part.
[0302] For the description of step 702 , please refer to step 602 .
[0303] In step 703, the verification network element decrypts and obtains the transaction address information, the random number 1, and the session identifier.
[0304] Exemplarily, the verification network element may use the private key of the verification network element and the temporary public key of the terminal to generate the above-mentioned session key, and decrypt the first ciphertext based on the above-mentioned session key to obtain the transaction address list and quantity, random number 1 and session identifier.
[0305] In step 704, the verification network element obtains corresponding file information from the storage network element based on the transaction address information.
[0306] Exemplarily, the verification network element sends the transaction address information to the storage network element. The transaction address information includes a transaction address list and the number of transaction addresses in the transaction address list. Accordingly, the storage network element receives the transaction address information. Furthermore, the storage network element determines the various locations of the file information on the distributed storage system based on the transaction addresses in the transaction address list and obtains the file information. Furthermore, the storage network element sends the file information to the verification network element. Accordingly, the verification network element receives the file information.
[0307] Optionally, the file information may include at least one authentication credential and an algorithm corresponding to each of the at least one authentication credential. For an explanation of the at least one authentication credential and the algorithm corresponding to each of the at least one authentication credential, please refer to FIG3 and will not be repeated here.
[0308] In step 705, the verification network element generates a random number 2 and signs the fourth message based on the private key of the verification network element. The fourth message may be one or more of all messages exchanged between the terminal and the verification network element.
[0309] For example, the fourth message may be the message sent by the terminal to the verification network element in step 702, or the third message sent by the verification network element to the terminal in step 706, which is not limited in this application.
[0310] It can be understood that the verification network element can also sign the hash value of the fourth message based on the private key of the verification network element, and this application does not limit this.
[0311] In step 706, the verification network element sends the digital signature of the verification network element and a third message to the terminal, where the third message includes the verification network element identifier, random number 1, and random number 2. Accordingly, the terminal receives the digital signature of the verification network element and the third message.
[0312] The third message may be encrypted, for example, may be encrypted based on a session key generated by the verification network element.
[0313] In step 707, the terminal verifies the digital signature of the verification network element based on the public key of the verification network element, and signs the second message based on the private key of the terminal.
[0314] The second message may be one or more of all messages exchanged between the terminal and the verification network element. For example, the second message may be the message sent by the terminal to the verification network element in step 702, the third message sent by the verification network element to the terminal in step 706, or the first message sent by the terminal to the verification network element in step 708. This application does not limit this.
[0315] It is understandable that the terminal may also sign the hash value of the second message based on the private key of the terminal, and this application does not limit this.
[0316] In step 708, the terminal sends the digital signature of the terminal and a first message to the verification network element, where the first message includes transaction address information, random number 1, and random number 2. Correspondingly, the verification network element receives the digital signature of the terminal and the first message.
[0317] The first message may be encrypted, for example, may be encrypted based on a session key generated by the terminal.
[0318] In step 709 , the verification network element verifies the digital signature of the terminal based on the public key of the terminal obtained in step 704 .
[0319] After receiving the digital signature of the terminal and the first message, the verification network element verifies the digital signature of the terminal according to the public key of the terminal in the file information in step 704. If the verification network element succeeds in verifying the digital signature of the terminal, it is considered that the verification network element has successfully authenticated the terminal. Correspondingly, if the verification network element fails to verify the digital signature of the terminal, it is considered that the verification network element has failed to authenticate the terminal.
[0320] In step 710, the verification network element sends an indication message to the terminal indicating successful network registration and access. Correspondingly, the terminal receives the indication message.
[0321] For a more detailed description of FIG7 , please refer to FIG6 , which will not be repeated here.
[0322] FIG8 is another schematic diagram of the access authentication process provided in an embodiment of the present application.
[0323] In step 801, the terminal generates a first ciphertext, which includes an encrypted false identity, a random number 1, and a session identifier.
[0324] The first ciphertext may be obtained by encrypting the false identity, the random number 1, and the session identifier based on the session key, and the session key may be generated based on the temporary private key of the terminal and the public key of the verification network element. The session identifier is used to identify the current session.
[0325] Exemplarily, the terminal generates a temporary public-private key pair used for this access to the network, and generates a session key based on the temporary private key and the public key of the verification network element (the public key of the verification network element can be preset), and uses the session key to encrypt a false identity, random number 1, and session identifier, etc.
[0326] In step 802, the terminal sends the first ciphertext and plaintext part to the verification network element. Correspondingly, the verification network element receives the first ciphertext and plaintext part.
[0327] For the description of step 802 , please refer to step 602 .
[0328] In step 803, the verification network element decrypts to obtain a false identity, a random number 1, and a session identifier.
[0329] Exemplarily, the verification network element may use the private key of the verification network element and the temporary public key of the terminal to generate the above-mentioned session key, and decrypt the first ciphertext based on the above-mentioned session key to obtain a false identity identifier, a random number 1 and a session identifier.
[0330] In step 804, the verification network element obtains corresponding file information from the storage network element based on the false identity identifier.
[0331] Exemplarily, the verification network element sends the false identity identifier to the storage network element, and accordingly, the storage network element receives the false identity identifier. Furthermore, the storage network element determines the true identity identifier based on the false identity identifier and the corresponding relationship (the corresponding relationship between the false identity identifier and the true identity identifier), and further obtains the file information corresponding to the true identity identifier. Furthermore, the storage network element sends the file information to the verification network element. Accordingly, the verification network element receives the file information. For an explanation of the false identity identifier, please refer to FIG. 3 and will not be repeated here.
[0332] In step 805, the verification network element generates a random number 2 and signs the fourth message based on the private key of the verification network element. The fourth message may be one or more of all messages exchanged between the terminal and the verification network element.
[0333] For example, the fourth message may be the message sent by the terminal to the verification network element in step 802, or the third message sent by the verification network element to the terminal in step 806, which is not limited in this application.
[0334] It can be understood that the verification network element can also sign the hash value of the fourth message based on the private key of the verification network element, and this application does not limit this.
[0335] In step 806, the verification network element sends the digital signature of the verification network element and a third message to the terminal, where the third message includes the verification network element identifier, random number 1, and random number 2. Accordingly, the terminal receives the digital signature of the verification network element and the third message.
[0336] The third message may be encrypted, for example, may be encrypted based on a session key generated by the verification network element.
[0337] In step 807, the terminal verifies the digital signature of the verification network element based on the public key of the verification network element, and signs the second message based on the private key of the terminal.
[0338] The second message may be one or more of all messages exchanged between the terminal and the verification network element. For example, the second message may be the message sent by the terminal to the verification network element in step 802, the third message sent by the verification network element to the terminal in step 806, or the first message sent by the terminal to the verification network element in step 808. This application does not limit this.
[0339] It is understandable that the terminal may also sign the hash value of the second message based on the private key of the terminal, and this application does not limit this.
[0340] In step 808, the terminal sends the digital signature of the terminal and a first message to the verification network element, where the first message includes a false identity, random number 1, and random number 2. Correspondingly, the verification network element receives the digital signature of the terminal and the first message.
[0341] The first message may be encrypted, for example, may be encrypted based on a session key generated by the terminal.
[0342] In step 809 , the verification network element verifies the digital signature of the terminal based on the public key of the terminal obtained in step 804 .
[0343] After receiving the digital signature of the terminal and the first message, the verification network element verifies the digital signature of the terminal according to the public key of the terminal in the file information in step 804. If the verification network element succeeds in verifying the digital signature of the terminal, it is considered that the verification network element has successfully authenticated the terminal. Correspondingly, if the verification network element fails to verify the digital signature of the terminal, it is considered that the verification network element has failed in authenticating the terminal.
[0344] In step 810, the verification network element sends an indication message to the terminal indicating successful network registration and access. Correspondingly, the terminal receives the indication message.
[0345] Based on the above technical solution, the verification network element can obtain the file information corresponding to the user ID from the storage network element according to the user ID of the terminal, so as to complete the authentication of the terminal based on the above file information, and the verification network element can be the network element of the target operator accessed by the terminal. That is to say, even if the verification network element is not the network element of the home operator, it can also obtain the file information corresponding to the user ID to complete the authentication of the terminal without falling back to the home operator authentication, which is conducive to simplifying the authentication process.
[0346] For a more detailed description of FIG8 , please refer to FIG6 , which will not be repeated here.
[0347] Figure 9 is a schematic flow chart of the access authentication method 900 provided in an embodiment of the present application. Figure 9 only describes the method from the perspective of the interaction between the terminal, the verification network element, and the storage network element, and should not constitute any limitation to the present application. The terminal in Figure 9 can be replaced by a component configured in the terminal (such as a chip, a chip system, a processor, etc.), or a logic module or software that can implement all or part of the functions of the terminal; the verification network element can be replaced by a component configured in the verification network element (such as a chip, a chip system, a processor, etc.), or a logic module or software that can implement all or part of the functions of the verification network element; the storage network element can be replaced by a component configured in the storage network element (such as a chip, a chip system, a processor, etc.), or a logic module or software that can implement all or part of the functions of the storage network element.
[0348] The method 900 shown in Figure 9 includes steps 910 to 930. Each step in the method 900 is described in detail below.
[0349] In step 910, the terminal obtains a user identifier and file information corresponding to the user identifier.
[0350] The user identifier is used to identify the terminal, or in other words, the user identifier is used to identify the UICC in the terminal, where the UICC can be a physical card, an embedded card embedded in hardware, or a software card, etc., which is not limited in this application. The verification network element can determine which terminal (or UICC) to authenticate based on the user identifier.
[0351] In the present application, the terminal may include one or more user identifiers, each user identifier corresponds to a file information, and the file information includes the information required to authenticate the terminal. For example, the file information includes the public key of the terminal, the validity period of the authentication certificate, the issuer of the authentication certificate, etc., wherein the authentication certificate can be, for example, a certificate (this application does not limit the format standard of the certificate, such as a certificate in X.509 format, a lightweight certificate, a certificate in an operator-defined format, etc.).
[0352] Exemplarily, the terminal obtains the user identifier required for this operator access and the file information corresponding to the user identifier. It will be appreciated that the terminal may store user identifiers and file information corresponding to multiple operators. Therefore, the terminal can determine the target operator for the terminal's current access from among the multiple operators. For a description of the multiple operators and how the terminal determines the target operator, please refer to Figure 3 and will not be repeated here.
[0353] In step 920, the terminal sends the user identification and the file information corresponding to the user identification to the verification network element.
[0354] The verification network element is a network element of the target operator accessed by the terminal. For example, the verification network element may be a core network element of the target operator accessed by the terminal, such as an AUSF network element, an AMF network element, or any other core network element. For another example, the verification network element may also be an access network element of the target operator accessed by the terminal, such as an access network node accessed by the terminal, which is not limited in this application.
[0355] The user identification and file information may be encrypted using a session key, where the session key may be generated, for example, based on the terminal's temporary private key and the verification network element's public key. In other words, the terminal may generate a session key based on the terminal's temporary private key and the verification network element's public key, encrypt the user identification and the file information corresponding to the user identification using the session key, and send the encrypted user identification and file information to the verification network element.
[0356] Optionally, the user identifier includes DRC, DIC, DSCC, SCIC, transaction address or false identity identifier. For the relevant explanation of the user identifier, please refer to Figure 3 and will not be repeated here.
[0357] In step 930, the verification network element authenticates the terminal based on the above file information.
[0358] The specific process of the verification network element authenticating the terminal can be found in the description of FIG3 , which will not be repeated here.
[0359] Optionally, before or after step 930, the method 900 further includes: the verification network element sending a third message and the verification network element's digital signature to the terminal, where the verification network element's digital signature is obtained by signing a fourth message or a hash value of the fourth message based on the verification network element's private key, wherein the fourth message is a message exchanged between the terminal and the verification network element or the third message. Furthermore, the terminal verifies the verification network element's digital signature based on the verification network element's public key.
[0360] The process of the terminal receiving the third message and verifying the digital signature of the network element and performing verification thereof can be referred to FIG3 , which will not be described in detail here.
[0361] In a possible implementation, the method 900 further includes step 925 , where the verification network element obtains a hash value of the file information corresponding to the user identifier from the storage network element based on the user identifier.
[0362] Among them, the hash value of the file information can be the hash value corresponding to each authentication credential in the file information, each authentication credential can correspond to a hash value, and each hash value can be stored in the same location or different locations of the distributed storage system. This application does not limit this.
[0363] The file information includes the public key of the terminal. Step 925 may specifically include steps 9251 and 9252.
[0364] In step 9251, the verification network element sends the user identifier to the storage network element.
[0365] In step 9252, the storage network element sends the hash value of the file information corresponding to the above user identifier to the verification network element.
[0366] After receiving the user identifier from the verification network element, the storage network element determines the hash value of the file information corresponding to the user identifier and then sends the hash value of the file information corresponding to the user identifier to the verification network element. The process of obtaining the hash value of the file information for different user identifiers can be referred to the relevant explanation of step 332. Simply replace the file information with the hash value of the file information, and no further explanation is given here.
[0367] After obtaining the hash value of the file information corresponding to the user identifier, the storage network element can verify the file information obtained from the terminal based on the hash value of the file information. If the verification is successful, the terminal is authenticated based on the file information.
[0368] Based on the user identifier, the verification network element obtains the hash value of the file information corresponding to the user identifier from the storage network element. In other words, the storage network element stores the hash value of the file information instead of the file information itself. This saves storage space and helps protect user privacy. It should be understood that the explanation of the storage network element can be found in Figure 3 and will not be repeated here.
[0369] The access authentication method shown in FIG. 9 will be described in detail below in conjunction with FIG. 10 .
[0370] FIG10 is another schematic diagram of the access authentication process provided in an embodiment of the present application.
[0371] In step 1001, the terminal generates a first ciphertext, which includes an encrypted user identifier, file information, a random number 1, and a session identifier.
[0372] The first ciphertext may be obtained by encrypting the user identifier, file information, random number 1, and session identifier based on a session key, where the session key may be generated based on a temporary private key of the terminal and a public key of the authentication network element. The session identifier is used to identify the current session.
[0373] Exemplarily, the terminal generates a temporary public-private key pair for this network access, and generates a session key based on the temporary private key and the public key of the verification network element (the public key of the verification network element may be preset), and uses the session key to encrypt the user identifier, the file information corresponding to the user identifier, the random number 1, and the session identifier. The present application does not limit the type of user identifier.
[0374] In step 1002, the terminal sends the first ciphertext and plaintext part to the verification network element. Correspondingly, the verification network element receives the first ciphertext and plaintext part.
[0375] For the description of step 1002 , please refer to step 602 .
[0376] In step 1003, the verification network element decrypts to obtain the user ID, file information, random number 1, and session ID.
[0377] Exemplarily, the verification network element may use the private key of the verification network element and the temporary public key of the terminal to generate the above-mentioned session key, and decrypt the first ciphertext based on the above-mentioned session key to obtain the user identification, file information, random number 1 and session identification.
[0378] In step 1004, the verification network element obtains the hash value of the corresponding file information from the storage network element based on the user identifier.
[0379] Exemplarily, the verification network element sends the user identifier to the storage network element, and the storage network element receives the user identifier accordingly. Furthermore, the storage network element obtains a hash value of the corresponding file information based on the user identifier. Furthermore, the storage network element sends the hash value of the file information to the verification network element. Accordingly, the verification network element receives the hash value of the file information.
[0380] In step 1005, the verification network element verifies the file information from the terminal based on the hash value of the file information.
[0381] If the verification is successful, proceed to step 1006 .
[0382] In step 1006, the verification network element generates a random number 2 and signs the fourth message based on the private key of the verification network element. The fourth message may be one or more of all messages exchanged between the terminal and the verification network element.
[0383] For example, the fourth message may be the message sent by the terminal to the verification network element in step 1002, or the third message sent by the verification network element to the terminal in step 1007, which is not limited in this application.
[0384] It can be understood that the verification network element can also sign the hash value of the fourth message based on the private key of the verification network element, and this application does not limit this.
[0385] In step 1007, the verification network element sends the digital signature of the verification network element and a third message to the terminal, where the third message includes the verification network element identifier, random number 1, and random number 2. Accordingly, the terminal receives the digital signature of the verification network element and the third message.
[0386] The third message may be encrypted, for example, may be encrypted based on a session key generated by the verification network element.
[0387] In step 1008, the terminal verifies the digital signature of the verification network element based on the public key of the verification network element, and signs the second message based on the private key of the terminal.
[0388] The second message may be one or more of all messages exchanged between the terminal and the verification network element. For example, the second message may be the message sent by the terminal to the verification network element in step 1002, the third message sent by the verification network element to the terminal in step 1007, or the first message sent by the terminal to the verification network element in step 1009. This application does not limit this.
[0389] It is understandable that the terminal may also sign the hash value of the second message based on the private key of the terminal, and this application does not limit this.
[0390] In step 1009, the terminal sends its digital signature and a first message to the verification network element, where the first message includes a user identifier, file information, random number 1, and random number 2. Correspondingly, the verification network element receives the digital signature and the first message.
[0391] The first message may be encrypted, for example, may be encrypted based on a session key generated by the terminal.
[0392] In step 1010, the verification network element verifies the digital signature of the terminal based on the public key of the terminal.
[0393] After receiving the digital signature of the terminal and the first message, the verification network element verifies the digital signature of the terminal based on the public key of the terminal in the file information. If the verification network element succeeds in verifying the digital signature of the terminal, the verification network element is deemed to have successfully authenticated the terminal. Correspondingly, if the verification network element fails to verify the digital signature of the terminal, the verification network element is deemed to have failed in authenticating the terminal.
[0394] In step 1011, the verification network element sends an indication message to the terminal indicating successful network registration and access. Correspondingly, the terminal receives the indication message.
[0395] For a more detailed description of FIG10 , please refer to FIG6 , which will not be repeated here.
[0396] Based on the above technical solution, the terminal can send the user ID and the file information corresponding to the user ID to the verification network element, so that the verification network element can complete the authentication of the terminal based on the above file information, and the verification network element can be the network element of the target operator accessed by the terminal. That is to say, even if the verification network element is not the network element of the home operator, it can obtain the file information corresponding to the user ID to complete the authentication of the terminal without falling back to the home operator authentication, which is conducive to simplifying the authentication process.
[0397] The method provided in the embodiment of the present application is described in detail above with reference to the accompanying drawings. Below, the device provided in the embodiment of the present application is described in detail with reference to the accompanying drawings.
[0398] It should be understood that the apparatus shown in FIG. 11 and FIG. 12 can be used to implement the functions of the terminal, verification network element or storage network element in the above method embodiments, and thus can also achieve the beneficial effects possessed by the above method embodiments.
[0399] FIG11 is a schematic block diagram of an access authentication device 1100 provided in an embodiment of the present application.
[0400] As shown in Figure 11, the apparatus 1100 includes a transceiver module 1110 and a processing module 1120. The apparatus 1100 can be used to implement the functions of a terminal, a verification network element, or a storage network element in any of the method embodiments shown in Figures 3 to 10 above.
[0401] When the device 1100 is used to implement the function of verifying the network element in the method embodiment shown in Figure 3, the transceiver module 1110 can be used to receive a user identifier from a terminal; the processing module 1120 can be used to obtain file information corresponding to the user identifier from a storage network element, the file information including the public key of the terminal; and based on the file information, the terminal is authenticated.
[0402] In one possible implementation, the processing module 1120 is specifically used to receive a first message from the terminal and a digital signature of the terminal, where the digital signature of the terminal is obtained by signing a second message or a hash value of the second message based on the private key of the terminal, wherein the second message is a message exchanged between the terminal and the verification network element or the first message; and the digital signature of the terminal is verified based on the public key of the terminal.
[0403] In a possible implementation, the processing module 1120 is further configured to obtain an authentication credential of an issuer from a storage network element, where the issuer is the issuer of the authentication credential of the terminal; and verify the authentication credential of the terminal based on the authentication credential of the issuer.
[0404] In one possible implementation, the transceiver module 1110 can also be used to: send a third message and the digital signature of the verification network element to the terminal, the digital signature of the verification network element is obtained by signing the fourth message or the hash value of the fourth message based on the private key of the verification network element, wherein the fourth message is the message exchanged between the terminal and the verification network element or the third message.
[0405] In a possible implementation, the transceiver module 1110 may also be configured to: send the certificate of the verification network element to the terminal.
[0406] In one possible implementation, the file information also includes at least one authentication credential and an algorithm corresponding to each of the at least one authentication credential; and the processing module 1120 can also be used to determine the target authentication credential from the at least one authentication credential; the transceiver module 1110 can also be used to send a first indication information to the terminal, and the first indication information is used to indicate the target authentication credential and / or the algorithm corresponding to the target authentication credential.
[0407] When the device 1100 is used to implement the function of the terminal in the method embodiment shown in Figure 3, the processing module 1120 can be used to obtain a user identifier; the transceiver module 1110 can be used to send the user identifier to a verification network element, wherein the verification network element is a network element of the target operator accessed by the terminal, and the user identifier corresponds to file information stored in the storage network element, the file information includes the public key of the terminal, and the file information is used to authenticate the terminal.
[0408] In one possible implementation, the transceiver module 1110 can also be used to receive a third message from the verification network element and the digital signature of the verification network element, where the digital signature of the verification network element is obtained by signing the fourth message or the hash value of the fourth message based on the private key of the verification network element, wherein the fourth message is the message exchanged between the terminal and the verification network element or the third message; the processing module 1120 can also be used to verify the digital signature of the verification network element based on the public key of the verification network element.
[0409] In one possible implementation, the transceiver module 1110 can also be used to send a first message and the digital signature of the terminal to the verification network element, where the digital signature of the terminal is obtained by signing the second message or the hash value of the second message based on the private key of the terminal, wherein the second message is the message exchanged between the terminal and the verification network element or the first message.
[0410] In a possible implementation, the transceiver module 1110 may also be configured to receive the certificate of the verification network element.
[0411] In a possible implementation, the processing module 1120 may also be configured to determine the target operator from multiple operators.
[0412] In one possible implementation, the processing module 1120 is specifically used to determine the target operator from the multiple operators based on one or more of the user's location, the service quality of each of the multiple operators, the cost of each of the multiple operators, or the security of each of the multiple operators.
[0413] In a possible implementation, the processing module 1120 is specifically configured to determine the target operator from the multiple operators in response to a user operation, wherein the user operation is an operation of the user selecting the target operator from the multiple operators.
[0414] In one possible implementation, the user identifier is carried in a first signaling, which also includes the type of the user identifier and / or an identifier of a distributed storage system, where the identifier of the distributed storage system is used to identify the distributed storage system where the file information corresponding to the user identifier is located.
[0415] When the device 1100 is used to implement the function of storing a network element in the method embodiment shown in Figure 3, the transceiver module 1110 can be used to receive a user identifier of a terminal from a verification network element, where the verification network element is a network element of a target operator to which the terminal accesses; the processing module 1120 can be used to determine file information corresponding to the user identifier based on the user identifier, where the file information includes a public key of the terminal, and the file information is used to authenticate the terminal; the transceiver module 1110 can also be used to send the file information to the verification network element.
[0416] In one possible implementation, the user identification includes a decentralized user root credential, a decentralized user identity credential, a decentralized self-controlled identity credential, or a self-controlled identity credential.
[0417] In a possible implementation, the user identifier includes a false identity identifier, a corresponding relationship exists between the false identity identifier and a real identity identifier, and the real identity identifier and corresponding file information are stored in the storage network element.
[0418] In a possible implementation, the user identifier includes a transaction address, and the transaction address is used to indicate a location of the file information corresponding to the user identifier or a hash value of the file information on the distributed storage system.
[0419] In a possible implementation, the storage network element is a node on a distributed storage system, and the node stores at least one user identifier and file information corresponding to each user identifier.
[0420] In one possible implementation, the distributed storage system is a blockchain, a decentralized shared file information storage system, or an InterPlanetary File System.
[0421] A more detailed description of each of the above modules can be directly obtained by referring to the relevant description in the method embodiment shown in FIG3 , which is not repeated here.
[0422] It should be understood that the division of modules in the embodiments of the present application is illustrative and is merely a logical functional division. In actual implementation, other division methods may be used. Furthermore, the functional modules in the various embodiments of the present application may be integrated into a single processor, or may exist physically as separate modules, or two or more modules may be integrated into a single module. The aforementioned integrated modules may be implemented in the form of hardware or software functional modules.
[0423] FIG12 is another schematic block diagram of an access authentication device 1200 provided in an embodiment of the present application.
[0424] The device 1200 may be a chip system, or may be a device configured with a chip system for implementing the method described in the above method embodiment. In the embodiment of the present application, the chip system may be composed of a chip, or may include a chip and other discrete devices.
[0425] As shown in Figure 12, the device 1200 may include a processor 1210, which can be used to execute computer programs or instructions in the memory to implement the steps performed by the terminal, verification network element or storage network element in any one of the embodiments shown in Figures 3 to 10.
[0426] Optionally, the apparatus 1200 further includes a communication interface 1220. The communication interface 1220 can be used to communicate with other devices via a transmission medium, thereby enabling the apparatus 1200 to communicate with other devices. The communication interface 1220 can be, for example, a transceiver, an interface, a bus, a circuit, or a device capable of performing transceiver functions. The processor 1210 can utilize the communication interface 1220 to input and output data and to implement the steps performed by the terminal, verification network element, or storage network element in any of the embodiments shown in Figures 3 to 10.
[0427] Optionally, the device 1200 further includes at least one memory 1230 for storing program instructions and / or data. The memory 1230 is coupled to the processor 1210. Coupling in the embodiments of the present application is an indirect coupling or communication connection between devices, units, or modules, which can be electrical, mechanical, or other forms, and is used for information exchange between devices, units, or modules. The processor 1210 may operate in conjunction with the memory 1230. The processor 1210 may execute program instructions stored in the memory 1230. At least one of the at least one memory may be included in the processor.
[0428] It should be understood that the coupling in the embodiments of the present application is an indirect coupling or communication connection between devices, units or modules, which can be electrical, mechanical or other forms, and is used for information exchange between devices, units or modules. The processor 1210 may operate in conjunction with the memory 1230. The specific connection medium between the above-mentioned processor 1210, communication interface 1220 and memory 1230 is not limited in the embodiments of the present application. Optionally, the processor 1210, communication interface 1220 and memory 1230 are connected via a bus 1240. The bus 1240 is represented by a bold line in Figure 12, and the connection methods between other components are only for schematic illustration and are not limiting. The bus can be a peripheral component interconnect (PCI) bus or an extended industry standard architecture (EISA) bus, etc. The bus can be divided into an address bus, a data bus, a control bus, etc. For ease of representation, only one bold line is used in Figure 12, but this does not mean that there is only one bus or one type of bus.
[0429] In one possible implementation, the device 1200 is a system-on-a-chip (SoC). Alternatively, the processor 1210 is a SoC.
[0430] The present application also provides a computer program product, which includes: a computer program (also referred to as code, or instructions). When the computer program is run, it can implement the steps executed by the terminal, verification network element or storage network element in any one of the embodiments shown in Figures 3 to 10.
[0431] The present application also provides a computer-readable storage medium storing a computer program (also referred to as code or instructions). When the computer program is executed, the steps performed by the terminal, verification network element, or storage network element in any of the embodiments shown in Figures 3 to 10 can be implemented.
[0432] An embodiment of the present application provides an access authentication system, which includes the terminal, verification network element and storage network element as described above.
[0433] It should be understood that the processor in the embodiments of the present application can be an integrated circuit chip with signal processing capabilities. During implementation, each step of the above-mentioned method embodiment can be completed by hardware integrated logic circuits in the processor or by software instructions. The above-mentioned processor can be a general-purpose processor, a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field programmable gate array (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, or discrete hardware components. The various methods, steps, and logic block diagrams disclosed in the embodiments of the present application can be implemented or executed. The general-purpose processor can be a microprocessor or any conventional processor. The steps of the method disclosed in the embodiments of the present application can be directly implemented and executed by a hardware decoding processor, or by a combination of hardware and software modules in the decoding processor. The software module can be located in a storage medium well-known in the art, such as random access memory, flash memory, read-only memory, programmable read-only memory, electrically erasable programmable memory, registers, etc. The storage medium is located in the memory, and the processor reads the information in the memory and, in conjunction with its hardware, completes the steps of the above-mentioned method.
[0434] It should also be understood that the memory in the embodiments of the present application may be a volatile memory or a non-volatile memory, or may include both volatile and non-volatile memories. Among them, the non-volatile memory may be a read-only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM), or a flash memory. The volatile memory may be a random access memory (RAM), which is used as an external cache. By way of example and not limitation, many forms of RAM are available, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), double data rate SDRAM (DDR SDRAM), enhanced SDRAM (ESDRAM), synchronous link DRAM (SLDRAM), and direct RAM bus RAM (DR RAM). It should be noted that the memory of the systems and methods described herein is intended to include, but is not limited to, these and any other suitable types of memory.
[0435] The terms "unit", "module", etc. used in this specification can be used to refer to computer-related entities, hardware, firmware, a combination of hardware and software, software, or software in execution. The terms "unit" and "module" in the embodiments of this application have the same meaning and can be used interchangeably.
[0436] Those skilled in the art will appreciate that the various illustrative logical blocks and steps described in conjunction with the embodiments disclosed herein can be implemented using electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professionals and technicians may use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application. In the several embodiments provided in this application, it should be understood that the disclosed devices, equipment, and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the division of the units is only a logical function division. In actual implementation, there may be other division methods, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not performed. In addition, the coupling or direct coupling or communication connection shown or discussed can be through some interface, indirect coupling or communication connection of devices or units, and can be electrical, mechanical, or other forms.
[0437] The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of these units may be selected to achieve the purpose of this embodiment according to actual needs.
[0438] In addition, each functional unit in each embodiment of the present application may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit.
[0439] In the above embodiments, the functions of each functional unit can be implemented in whole or in part by software, hardware, firmware or any combination thereof. When implemented using software, it can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions (programs). When the computer program instructions (program) are loaded and executed on a computer, the process or function described in the embodiment of the present application is generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another computer-readable storage medium. For example, the computer instructions can be transmitted from one website, computer, server or data center to another website, computer, server or data center via wired (e.g., coaxial cable, optical fiber, digital subscriber line (DSL)) or wireless (e.g., infrared, wireless, microwave, etc.) means. The computer-readable storage medium can be any available medium that can be accessed by a computer or a data storage device such as a server or data center that includes one or more available media integrated therein. The available medium may be a magnetic medium (eg, a floppy disk, a hard disk, a magnetic tape), an optical medium (eg, a digital versatile disc (DVD)), or a semiconductor medium (eg, a solid state disk (SSD)).
[0440] If the functions are implemented in the form of software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application, or the part that contributes to the technology or the part of the technical solution, can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions for enabling a computer device (which can be a personal computer, server, or network device, etc.) to execute all or part of the steps of the method described in each embodiment of the present application. The aforementioned storage medium includes various media that can store program codes, such as a USB flash drive, a mobile hard disk, a ROM, a RAM, a magnetic disk, or an optical disk.
[0441] The above description is merely a specific embodiment of the present application, but the scope of protection of the present application is not limited thereto. Any changes or substitutions that can be easily conceived by a person skilled in the art within the technical scope disclosed in this application should be included in the scope of protection of this application. Therefore, the scope of protection of this application should be based on the scope of protection of the claims.
Claims
1. An access authentication method, characterized in that, Applied to a verification network element, where the verification network element is a network element of a target operator accessed by a terminal, the method includes: receiving a user identification from the terminal; Obtaining file information corresponding to the user identifier from a storage network element, where the file information includes a public key of the terminal; The terminal is authenticated based on the file information.
2. The method according to claim 1, wherein The authenticating the terminal based on the file information includes: receiving a first message from the terminal and a digital signature of the terminal, where the digital signature of the terminal is obtained by signing a second message or a hash value of the second message based on a private key of the terminal, wherein the second message is a message exchanged between the terminal and the verification network element or the first message; The digital signature of the terminal is verified based on the public key of the terminal.
3. The method according to claim 2, wherein Before verifying the digital signature of the terminal based on the public key of the terminal, the method further includes: Acquire an authentication credential of an issuer from a storage network element, where the issuer is the issuer of the authentication credential of the terminal; The authentication credentials of the terminal are verified based on the authentication credentials of the issuer.
4. The method according to any one of claims 1 to 3, characterized in that The method further comprises: Send a third message and the digital signature of the verification network element to the terminal, where the digital signature of the verification network element is obtained by signing the fourth message or the hash value of the fourth message based on the private key of the verification network element, wherein the fourth message is the message exchanged between the terminal and the verification network element or the third message.
5. The method according to claim 4, characterized in that, The method further comprises: Sending the certificate of the verification network element to the terminal.
6. The method according to any one of claims 1 to 5, characterized in that, The file information also includes at least one authentication credential and an algorithm corresponding to each authentication credential in the at least one authentication credential; and the method further includes: determining a target authentication credential from the at least one authentication credential; First indication information is sent to the terminal, where the first indication information is used to indicate the target authentication credential and / or an algorithm corresponding to the target authentication credential.
7. An access authentication method, characterized in that, Applied to a terminal, the method includes: Get user ID; The user identifier is sent to a verification network element, where the verification network element is a network element of a target operator accessed by the terminal, the user identifier corresponds to file information stored in a storage network element, the file information includes a public key of the terminal, and the file information is used to authenticate the terminal.
8. The method according to claim 7, wherein The method further comprises: receiving a third message from the verification network element and a digital signature of the verification network element, where the digital signature of the verification network element is obtained by signing a fourth message or a hash value of the fourth message based on a private key of the verification network element, wherein the fourth message is a message exchanged between the terminal and the verification network element or the third message; The digital signature of the verification network element is verified based on the public key of the verification network element.
9. The method according to claim 7 or 8, characterized in that, The method further comprises: Send a first message and the digital signature of the terminal to the verification network element, where the digital signature of the terminal is obtained by signing the second message or the hash value of the second message based on the private key of the terminal, wherein the second message is the message exchanged between the terminal and the verification network element or the first message.
10. The method according to claim 9, wherein The method further comprises: Receive the certificate of the verification network element.
11. The method according to any one of claims 7 to 10, characterized in that Before obtaining the user identifier, the method further includes: The target operator is determined from a plurality of operators.
12. The method according to claim 11, wherein The determining the target operator from a plurality of operators includes: The target operator is determined from the multiple operators according to one or more of a user location, a service quality of each of the multiple operators, a cost of each of the multiple operators, or a security of each of the multiple operators.
13. The method according to claim 11, wherein The determining the target operator from a plurality of operators includes: The target operator is determined from the plurality of operators in response to a user operation, wherein the user operation is an operation of the user selecting the target operator from the plurality of operators.
14. The method according to any one of claims 1 to 13, characterized in that The user identifier is carried in the first signaling, which also includes the type of the user identifier and / or an identifier of a distributed storage system. The identifier of the distributed storage system is used to identify the distributed storage system where the file information corresponding to the user identifier is located.
15. An access authentication method, characterized in that, Applied to a storage network element, the method includes: receiving a user identifier of the terminal from a verification network element, where the verification network element is a network element of a target operator to which the terminal is to access; Based on the user identifier, determining file information corresponding to the user identifier, wherein the file information includes a public key of the terminal, and the file information is used to authenticate the terminal; Send the file information to the verification network element.
16. The method according to any one of claims 1 to 15, characterized in that The user identification includes a decentralized user root credential, a decentralized user identity credential, a decentralized self-controlled identity credential, or a self-controlled identity credential.
17. The method according to any one of claims 1 to 15, characterized in that, The user identifier includes a false identity identifier, and there is a corresponding relationship between the false identity identifier and the real identity identifier. The real identity identifier and corresponding file information are stored in the storage network element.
18. The method according to any one of claims 1 to 17, characterized in that The user identifier includes a transaction address, and the transaction address is used to indicate the location of the file information corresponding to the user identifier or the hash value of the file information on the distributed storage system.
19. The method according to any one of claims 1 to 18, characterized in that The storage network element is a node on a distributed storage system, and the node stores at least one user identification and file information corresponding to each user identification.
20. The method according to claim 19, wherein The distributed storage system is a blockchain, a decentralized shared file information storage system, or an interplanetary file system.
21. An access authentication method, characterized in that, Applied to verifying a network element, the method includes: Receiving a user identification and file information corresponding to the user identification from a terminal, wherein the file information includes a public key of the terminal; Based on the above file information, the terminal is authenticated.
22. The method according to claim 21, wherein Authenticating the terminal based on the file information includes: receiving a first message from the terminal and a digital signature of the terminal, where the digital signature of the terminal is obtained by signing a second message or a hash value of the second message based on a private key of the terminal, wherein the second message is a message exchanged between the terminal and the verification network element or the first message; The digital signature of the terminal is verified based on the public key of the terminal.
23. The method according to claim 21 or 22, wherein: The method further comprises: Send a third message and the digital signature of the verification network element to the terminal, where the digital signature of the verification network element is obtained by signing the fourth message or the hash value of the fourth message based on the private key of the verification network element, wherein the fourth message is the message exchanged between the terminal and the verification network element or the third message.
24. The method according to claim 23, wherein The method further comprises: Sending the certificate of the verification network element to the terminal.
25. The method according to any one of claims 21 to 24, characterized in that The method further comprises: Based on the user identifier, obtaining a hash value of the file information corresponding to the user identifier from a storage network element; The file information is verified based on the hash value.
26. An access authentication method, characterized in that, Applied to a terminal, the method includes: Obtaining a user identification of the terminal and file information corresponding to the user identification, wherein the file information includes a public key of the terminal; The user identifier and the file information corresponding to the user identifier are sent to a verification network element, where the verification network element is a network element of a target operator accessed by the terminal, and the file information is used to authenticate the terminal.
27. The method according to claim 26, wherein The method further comprises: receiving a third message from the verification network element and a digital signature of the verification network element, where the digital signature of the verification network element is obtained by signing a fourth message or a hash value of the fourth message based on a private key of the verification network element, wherein the fourth message is a message exchanged between the terminal and the verification network element or the third message; The digital signature of the verification network element is verified based on the public key of the verification network element.
28. The method according to claim 26 or 27, characterized in that, The method further comprises: Send a first message and the digital signature of the terminal to the verification network element, where the digital signature of the terminal is obtained by signing the second message or the hash value of the second message based on the private key of the terminal, wherein the second message is the message exchanged between the terminal and the verification network element or the first message.
29. The method of claim 28, wherein The method further comprises: Receive the certificate of the verification network element.
30. The method according to any one of claims 26 to 29, characterized in that, The method further comprises: A target operator is determined from among multiple operators.
31. The method of claim 30, wherein: The determining of a target operator from a plurality of operators includes: A target operator is determined from the plurality of operators based on one or more of a user location, a service quality of each of the plurality of operators, a cost of each of the plurality of operators, or a security of each of the plurality of operators.
32. The method of claim 30, wherein: The determining of a target operator from a plurality of operators includes: In response to a user operation, a target operator is determined from the plurality of operators, wherein the user operation is an operation of the user selecting the target operator from the plurality of operators.
33. The method according to any one of claims 21 to 32, characterized in that The user identifier is carried in the first signaling, which also includes the type of the user identifier and / or an identifier of a distributed storage system. The identifier of the distributed storage system is used to identify the distributed storage system where the file information corresponding to the user identifier is located.
34. An access authentication method, characterized in that, Applied to a storage network element, the method includes: receiving a user identifier of the terminal from a verification network element, where the verification network element is a network element of a target operator to which the terminal is to access; Based on the user identifier, determining a hash value of file information corresponding to the user identifier, where the file information includes a public key of the terminal; Sending the hash value of the file information to the verification network element.
35. The method according to any one of claims 21 to 34, characterized in that, The user identifier includes DRC, DIC, DSCC or SCIC.
36. The method according to any one of claims 21 to 34, characterized in that, The user identifier includes a false identity identifier, and there is a corresponding relationship between the false identity identifier and the real identity identifier. The storage network element stores the real identity identifier and the hash value of the corresponding file information.
37. The method according to any one of claims 21 to 36, characterized in that, The user identifier includes a transaction address, and the transaction address is used to indicate the location of the hash value of the file information corresponding to the user identifier on the distributed storage system.
38. The method according to any one of claims 21 to 37, wherein The storage network element is a node on a distributed storage system, and the node stores at least one user identification and a hash value of file information corresponding to each user identification.
39. The method according to claim 38, wherein The distributed storage system is a blockchain, a decentralized shared file information storage system, or an interplanetary file system.
40. An access authentication device, characterized in that, Comprising a module for implementing the method as claimed in any one of claims 1 to 6, 14, 16 to 20; or, comprising a module for implementing the method as claimed in any one of claims 7 to 14, 16 to 20; or comprising a module for implementing the method as claimed in any one of claims 15 to 20; or, comprising a module for implementing the method as claimed in any one of claims 21 to 25, 33, 35 to 39; or, comprising a module for implementing the method as claimed in any one of claims 26 to 33, 35 to 39; or, comprising a module for implementing the method as claimed in any one of claims 34 to 39.
41. An access authentication device, characterized in that: comprising a processor coupled to a memory, wherein: The memory is used to store computer programs; The processor is used to call the computer program so that the device implements the method as described in any one of claims 1 to 6, 14, 16 to 20; or, implements the method as described in any one of claims 7 to 14, 16 to 20; or, implements the method as described in any one of claims 15 to 20; or, implements the method as described in any one of claims 21 to 25, 33, 35 to 39; or, implements the method as described in any one of claims 26 to 33, 35 to 39; or, implements the method as described in any one of claims 34 to 39.
42. A computer-readable storage medium, characterized in that, The storage medium stores a computer program or instructions. When the computer program or instructions are executed by a computer, the method according to any one of claims 1 to 39 is implemented.
43. A computer program product, characterized in that, The computer program product comprises instructions, and when the instructions are executed by a computer, the method according to any one of claims 1 to 39 is implemented.
44. A communication system, characterized in that include: A verification network element and a storage network element, wherein the verification network element is used to implement the method according to any one of claims 1 to 6, 14, and 16 to 20; The storage network element is used to implement the method as described in any one of claims 15 to 20; or, the verification network element is used to implement the method as described in any one of claims 21 to 25, 33, 35 to 39; the storage network element is used to implement the method as described in any one of claims 34 to 39.
45. The communication system according to claim 44, wherein It also includes a terminal, which is used to implement the method according to any one of claims 7 to 14 and 16 to 20; or, the terminal is used to implement the method according to any one of claims 26 to 33 and 35 to 39.
Citation Information
Patent Citations
Access authentication method and related device
CN120358494A
Equipment identity authentication method and device
CN106899410A
Realization method and device of attachment procedure
CN108880813A
Secure simple enrollment
US20140258724A1
Security implementation method and apparatus, device and network element
WO2023178691A1
Cited By
Network architecture, network resource management method and related device
CN120935173A