Communication method and related apparatus

By generating the first request message to request the second authenticated entity to change the authenticated entity, and using blockchain or distributed storage system to store terminal identity information, the delay problem caused by the change of the authenticated entity in the 5G communication system is solved, fast access and secure identity authentication are achieved, and system resource utilization and business continuity are improved.

WO2025162146A1PCT designated stage Publication Date: 2025-08-07HUAWEI TECH CO LTD
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
PCT/CN2025/074083
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-02-02
Filing Date
2025-01-22
Publication Date
2025-08-07

AI Technical Summary

Technical Problem

In 5G communication systems, frequent changes in authentication entities lead to an extended delay in identity authentication, affecting business continuity.

Method used

By generating the first request message, directly or indirectly requesting the second authentication entity to change the authentication entity, the blockchain or distributed storage system stores terminal identity information and historical authentication results, reduce authentication delay, and relieve the pressure on core network equipment if necessary.

Benefits of technology

It reduces the delay of authentication entities changes, improves network access speed, enhances network security and resource utilization, and ensures business continuity.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2025074083_07082025_PF_FP_ABST
    Figure CN2025074083_07082025_PF_FP_ABST
Patent Text Reader

Abstract

The present application provides a communication method and a related apparatus, which can be used in the technical field of communications. In the technical solution provided by the present application, a first authentication entity may generate a first request message, the first request message being used for requesting to change the authentication entity of a first terminal, and send the first request message to a second authentication entity. The method can reduce time delay of authentication entity change for the first terminal.
Need to check novelty before this filing date? Find Prior Art

Description

Communication method and related device

[0001] This application claims priority to the Chinese patent application filed with the State Intellectual Property Office of China on February 2, 2024, with application number 202410157827.7 and application name “Communication Methods and Related Devices”, the entire contents of which are incorporated by reference into this application. Technical Field

[0002] The present application relates to the field of communication technology, and in particular to a communication method and related devices. Background Art

[0003] In a communication system, when a terminal accesses the network, the network needs to authenticate the terminal. In some scenarios, the authentication entity used to authenticate the terminal may change. For example, moving a terminal from one user registration area to another may cause the authentication entity to change.

[0004] In the fifth generation (5G) communication system, the authentication entity change scheme includes the following: when a terminal moves to a new user registration area, the radio access network (RAN) device receives a registration request message from the terminal, which includes the identity information of the target access and mobility management function (AMF), and sends a registration request message to the target AMF network element based on the identity information of the target AMF network element; after receiving the registration request message, the target AMF network element can obtain the identity information of the terminal from the unstructured data storage function (UDSF) or the original AMF network element, and then select an authentication entity based on the identity information of the terminal. Depending on the network policy configured by the operator, the target authentication server function (AUSF) network element selected by the target AMF network element may be different from the original AUSF.

[0005] However, when this method is used, frequently initiating new registration processes results in a large delay in changing the authentication entity, affecting business continuity. Summary of the Invention

[0006] This application provides a communication method and related devices that can reduce the delay in changing authentication entities and ensure business continuity.

[0007] In a first aspect, the present application provides a communication method, which is applied to a first authentication entity, the first authentication entity being used to authenticate a terminal. The method comprises: generating a first request message, the first request message being used to request a change in the authentication entity of the first terminal; and sending the first request message to a second authentication entity.

[0008] In this method, the first terminal may be a terminal in the system architecture shown in FIG1 or the system architecture shown in FIG4 .

[0009] In the method, the first authentication entity may be the authentication entity of the first terminal before the change, and the second authentication entity may be the authentication entity required by the first terminal after the change.

[0010] Optionally, the first authentication entity may be a direct authentication entity or an indirect authentication entity. A direct authentication entity is configured to directly obtain the terminal's identity information, authentication parameters, and the like from the core network and perform identity authentication on the terminal based on the terminal's identity information and authentication parameters. An indirect authentication entity performs identity authentication on the terminal without obtaining authentication parameters.

[0011] Optionally, the second authentication entity may also be a direct authentication entity or an indirect authentication entity.

[0012] In this method, the first authentication entity can directly send a first request message to the second authentication entity. Compared with the target AMF network element obtaining the identity information of the terminal after receiving the registration request message and selecting an authentication entity to authenticate the terminal based on the identity information of the terminal, the second authentication entity can quickly determine that the first terminal needs to change the authentication entity, which is conducive to the subsequent first terminal quickly accessing the network through the second authentication entity and reducing the delay in changing the authentication entity.

[0013] When the second authentication entity is an indirect authentication entity, the second authentication entity may be deployed at a relatively close distance to the first terminal, which may also reduce the delay in changing the authentication entity.

[0014] When the second authentication entity is an indirect authentication entity, the second authentication entity may not limit the operator to be accessed by the first terminal, so that the first terminal can select the operator to be accessed.

[0015] When the second authentication entity is an indirect authentication entity, the second authentication entity can be deployed in an access network device or an edge computing node. Compared with deploying all authentication entities in the core network device, it can alleviate the pressure on the core network device. In addition, it can eliminate malicious first terminals before the first terminal accesses the core network, thereby ensuring the security of the core network.

[0016] In some possible implementations, the first request message carries first information, and the first information includes at least one of the following information: identity information of the first terminal, encrypted identity information of the first terminal, index information corresponding to the identity information of the first terminal in the storage system, historical authentication results of the first terminal, authentication records of the first terminal, or index information corresponding to the historical authentication results of the first terminal in the storage system.

[0017] Optionally, the identity information of the first terminal may be stored in the blockchain. In this way, the index information corresponding to the identity information of the first terminal in the storage system may include the blockchain transaction identifier corresponding to the identity information of the first terminal and / or the block identifier corresponding to the identity information of the first terminal.

[0018] Optionally, the identity information of the first terminal may be stored in a distributed storage system, such as a decentralized shared file repository (dSPR) system. In this way, the index information corresponding to the identity information of the first terminal in the storage system may include an index identifier corresponding to the identity information of the first terminal in the dSPR system.

[0019] In this implementation, when the first information includes the index information corresponding to the identity information of the first terminal in the storage system, the identity information of the first terminal may not be directly transmitted between the first authentication entity and the second authentication entity. This can reduce the risk of leakage of the identity information of the first terminal and is conducive to improving the security of the network.

[0020] In this implementation, the historical authentication result of the first terminal may include an authentication result of the first authentication entity authenticating the first terminal.

[0021] In this implementation, the authentication record of the first terminal may include a record of the first authentication entity authenticating the first terminal, and may include information such as the identity of the authenticated party, the identity of the authenticator, the authentication result, and a timestamp.

[0022] Optionally, the historical authentication results of the first terminal may be stored in a blockchain. In this way, the index information corresponding to the historical authentication results of the first terminal in the storage system may include a blockchain transaction identifier corresponding to the historical authentication results of the first terminal and / or a block identifier corresponding to the historical authentication results of the first terminal.

[0023] Optionally, the historical authentication results of the first terminal may be stored in a distributed storage system, such as a dSPR system. Thus, the index information corresponding to the historical authentication results of the first terminal in the storage system may include the index identifier corresponding to the historical authentication results of the first terminal in the dSPR.

[0024] In this implementation, when the first information includes the historical authentication results of the first terminal, the authentication record of the first terminal, or the corresponding index information of the historical authentication results of the first terminal in the storage system, the identity information of the first terminal may not be transmitted between the first authentication entity and the second authentication entity. This can also reduce the risk of leakage of the identity information of the first terminal, which is conducive to improving the security of the network.

[0025] In some possible implementations, before generating the first request message, the method further includes: determining that a coverage area of ​​the first authentication entity is updated, or determining that a network capability of the first authentication entity is updated.

[0026] As an example, when the first authentication entity moves to a new area, the coverage area of ​​the first authentication entity is updated. In this example, the first authentication entity is an indirect authentication entity, such as a satellite.

[0027] As an example, the update of the network capability of the first authentication entity may include: an increase in the load of the network where the first authentication entity is located or an upgrade in the authentication capability of other devices in the network where the first authentication entity is located.

[0028] In this implementation, after determining that the coverage area of ​​the first authentication entity has been updated, or after determining that the network capabilities of the first authentication entity have been updated, the first authentication entity may decide to change the authentication entity. Only if the authentication entity has been changed will the first authentication entity generate the first request message. This avoids generating the first request message when a change of the authentication entity is not necessary, avoids unnecessary resource consumption, and improves system resource utilization.

[0029] In some possible implementations, before generating the first request message, the method further includes: receiving second information from the first terminal, the second information indicating at least one of the following information: the location of the first terminal is updated, the access type of the first terminal is updated, the reception quality of the signal received by the first terminal from the first authentication entity is lower than a first preset threshold, the reception quality of the signal received by the first terminal from the second authentication entity is higher than a second preset threshold, the first terminal requests to change the authentication entity, or the identity information of the second authentication entity.

[0030] In this implementation, the first authentication entity can generate the first request message only after confirming, through the received second information, that the first terminal has decided to change the authentication entity. This avoids generating the first request message when no authentication entity change is necessary, avoids unnecessary resource consumption, and helps improve system resource utilization.

[0031] In some possible implementations, the first authentication entity and the second authentication entity belong to the same operator, or the first authentication entity and the second authentication entity are in the same blockchain.

[0032] In this implementation, if the first authentication entity determines that it and the second authentication entity belong to the same operator, or that they are on the same blockchain, the first authentication entity can determine that the second authentication entity's identity is legitimate. Generating the first request message when the second authentication entity's identity is legitimate improves user security on the network side and reduces the risk of users accessing fake base stations.

[0033] In some possible implementations, before generating the first request message, the method further includes: receiving third information from the first terminal, the third information including operator information of the second authentication entity and / or blockchain information of the second authentication entity.

[0034] Among them, the blockchain information of the second authentication entity can be used to indicate the chain identifier of the blockchain to which the second authentication entity belongs.

[0035] In this implementation, the first authentication entity can determine whether the first authentication entity and the second authentication entity belong to the same operator through the received third information, and / or determine whether the first authentication entity and the second authentication entity are on the same blockchain through the received third information, and then determine whether the identity of the second authentication entity is legal, which is conducive to improving the security of the system.

[0036] Optionally, the first authentication entity may also determine whether the first authentication entity and the second authentication entity are on the same blockchain using a locally stored list of blockchain nodes. As an example, the first authentication entity may directly query the locally stored list of blockchain nodes to determine whether the list contains the second authentication entity. If the locally stored list of blockchain nodes contains the second authentication entity, then the first authentication entity and the second authentication entity are determined to be on the same blockchain; otherwise, then the first authentication entity and the second authentication entity are determined to be not on the same blockchain.

[0037] In some possible implementations, the method further includes: receiving a first response message from the second authentication entity, where the first response message indicates whether the second authentication entity agrees to change the authentication entity of the first terminal.

[0038] In this implementation method, the first authentication entity can determine whether the second authentication entity agrees to change the authentication based on the first response message, and execute the authentication entity change process if it is determined that the second authentication entity agrees to change the authentication, thereby avoiding executing the authentication entity change process if the second authentication entity does not agree to change the authentication, thereby avoiding waste of resources.

[0039] In some possible implementations, when the first response message indicates that the second authentication entity agrees to change the authentication entity of the first terminal, the method further includes: sending a second response message to the first terminal, the second response message including at least one of the following information: agreement to change the authentication entity of the first terminal, or identity information of the second authentication entity.

[0040] Optionally, the second response message may further include operator information that the first terminal can access. Here, the operator information that the first terminal can access may be the operator information of the second authentication entity. In other words, the operator information that the first terminal can access may indicate the operator to which the second authentication entity belongs.

[0041] In this implementation method, the first terminal can determine based on the second response message that the first authentication entity and the second authentication entity agree to change the authentication entity, and then execute the authentication entity change process, avoiding executing the authentication entity change process when the first authentication entity or the second authentication entity does not agree to change the authentication, thereby avoiding waste of resources.

[0042] In some possible implementations, the method further includes: when it is determined that the first terminal meets a first condition, sending first indication information to the second authentication entity, where the first indication information indicates that there is no need to initiate authentication for the first terminal.

[0043] In this implementation, the second authentication entity may not initiate authentication for the first terminal based on the first indication information, thereby avoiding repeated authentication, reducing signaling interaction and delay, and ensuring continuity of user services.

[0044] In some possible implementations, the first condition includes at least one of the following conditions: the access type of the first terminal is an emergency type, the delay requirement of the first terminal is lower than a preset delay threshold, or the frequency of the first terminal changing the authentication entity exceeds a preset frequency threshold.

[0045] In this implementation, when the access type of the first terminal is an emergency type, the second authentication entity may not initiate authentication for the first terminal, which can increase the rate at which the first terminal accesses the network through the second authentication entity to meet the first terminal's network access needs.

[0046] In this implementation, when the delay requirement of the first terminal is lower than the preset delay threshold, the second authentication entity may not initiate authentication for the first terminal, which can increase the rate at which the first terminal accesses the network through the second authentication entity, thereby reducing the delay of the first terminal accessing the network.

[0047] In this implementation, when the frequency of the first terminal changing the authentication entity exceeds a preset frequency threshold, the second authentication entity may not initiate authentication for the first terminal, which can increase the rate at which the first terminal accesses the network through the second authentication entity, thereby reducing the delay in the first terminal accessing the network, and thus helping to meet the frequency of the first terminal changing the authentication entity.

[0048] In some possible implementations, the method further includes: sending the security context of the first authentication entity and the first terminal to the second authentication entity.

[0049] The security context between the first authentication entity and the first terminal may include a security algorithm used when the first authentication entity communicates with the first terminal, such as a key, an encryption algorithm, an integrity protection algorithm, a privacy protection method, and the like.

[0050] Optionally, the security context sent by the first authentication entity to the second authentication entity may be a partial security context. For example, the first authentication entity may not send a key to the second authentication entity, but may send an integrity protection algorithm or a privacy protection method.

[0051] In this method, the second authentication entity can communicate with the first terminal based on the security context. This not only ensures the security of communication between the second authentication entity and the first terminal, but also avoids the second authentication entity from repeatedly establishing a security context with the first terminal, thereby improving the communication efficiency between the second authentication entity and the first terminal.

[0052] In a second aspect, the present application provides a communication method, which is applied to a second authentication entity, the second authentication entity being used to authenticate the identity of a terminal. The method may include: receiving a first request message from a first authentication entity, the first request message being used to request a change in the authentication entity of the first terminal; and sending a first response message to the first authentication entity, the first response message indicating whether the second authentication entity agrees to change the authentication entity of the first terminal.

[0053] In some possible implementations, the first request message carries first information, and the first information includes at least one of the following information: identity information of the first terminal, encrypted identity information of the first terminal, index information corresponding to the identity information of the first terminal in the storage system, historical authentication results of the first terminal, authentication records of the first terminal, or index information corresponding to the historical authentication results of the first terminal in the storage system.

[0054] In some possible implementations, when a second condition is met, the first response message indicates that the second authentication entity agrees to change the authentication entity of the first terminal.

[0055] Alternatively, when the second condition is not met, the method further includes: initiating authentication for the first terminal.

[0056] In this implementation, the second authentication entity can determine whether to initiate authentication for the first terminal based on the second condition. Only when it determines that authentication is required for the first terminal device will it initiate authentication for the second terminal. This avoids repeated authentication, reduces signaling interactions and latency, and ensures continuity of user service.

[0057] In some possible implementations, after the second authentication entity determines to initiate authentication for the first terminal, it may also determine a timing for initiating authentication for the first terminal.

[0058] In one implementation, the second authentication entity may determine to initiate authentication for the first terminal before the authentication entity is changed.

[0059] Optionally, when the second authentication entity has higher security requirements and a larger workload, or the first authentication entity has a smaller workload, the second authentication entity may determine to initiate authentication on the first terminal before the authentication entity is changed.

[0060] Optionally, the workload of the first authentication entity can be represented by the number of users served by the first authentication entity (ie, the number of terminals served by the first authentication entity). The more users the first authentication entity serves, the greater the workload of the first authentication entity.

[0061] The workload of the second authentication entity can also be characterized by the number of users served by the second authentication entity (ie, the number of terminals served by the second authentication entity). The more users the second authentication entity serves, the greater the workload of the second authentication entity.

[0062] For example, when the number of users served by the second authentication entity exceeds a preset number, or the number of users served by the first authentication entity does not exceed a preset number, the second authentication entity may determine to initiate authentication for the first terminal before the authentication entity is changed.

[0063] In this implementation, the second authentication entity performs identity authentication on the first terminal before changing the authentication entity. This can protect the security of the second authentication entity and effectively avoid the situation where a malicious first terminal and a maliciously controlled first authentication entity jointly deceive the second authentication entity. At the same time, it can ensure that the second authentication entity only provides services to legitimate users, thereby ensuring work efficiency.

[0064] In another implementation, the second authentication entity may determine to initiate authentication for the first terminal after the authentication entity is changed.

[0065] Optionally, when the second authentication entity has lower security requirements and a smaller workload, or the first authentication entity has a larger workload, the second authentication entity may determine to initiate authentication on the first terminal after the authentication entity is changed.

[0066] For example, when the number of users served by the second authentication entity does not exceed a preset number, or the number of users served by the first authentication entity exceeds a preset number, the second authentication entity may determine to initiate authentication for the first terminal after the authentication entity is changed.

[0067] In this implementation, after the authentication entity is changed, authentication-related messages can be directly transmitted between the second authentication entity and the first terminal, which eliminates the need to forward authentication-related messages through the first authentication entity, thereby ensuring the work efficiency of the first authentication entity.

[0068] In some possible implementations, the second condition includes at least one of the following conditions: the second authentication entity and the first authentication entity have performed mutual authentication within the first validity period and the authentication results have been saved, the number of users served by the second authentication entity exceeds a threshold, the second authentication entity and the first authentication entity belong to the same operator, the second authentication entity and the first authentication entity are on the same blockchain, the authentication result of the first terminal is within the second validity period, the access type of the first terminal is an emergency type, the delay requirement of the first terminal is lower than a preset delay threshold, the frequency of the first terminal changing the authentication entity exceeds a preset frequency threshold, or, alternatively, receiving first indication information from the first authentication entity, the first indication information indicating that the second authentication entity does not need to initiate authentication for the first terminal.

[0069] In this implementation, if the second authentication entity and the first authentication entity have mutually authenticated each other within the first validity period and the authentication results have been saved, or if the number of users served by the second authentication entity exceeds a threshold, the second authentication entity can determine that it trusts the first authentication entity and, therefore, does not need to initiate authentication on the first terminal. This avoids repeated authentication, reduces signaling interactions and latency, and ensures continuity of user service.

[0070] In this implementation, if the second authentication entity and the first authentication entity belong to the same operator or are on the same blockchain, and the first terminal's authentication result is within the second validity period, the second authentication entity can trust the first terminal's authentication result and obtain the first terminal's authentication result. Furthermore, if the authentication result indicates a successful authentication result for the first terminal, the second authentication entity can determine that it does not need to initiate authentication for the first terminal. This avoids duplicate authentication, reduces signaling interactions and latency, and ensures continuity of user service.

[0071] In this implementation, when the first terminal's access type is emergency, the first terminal's latency requirement is lower than a preset latency threshold, the first terminal's frequency of changing authentication entities exceeds a preset frequency threshold, or after receiving the first indication information, the second authentication entity can determine that it trusts the first terminal and, therefore, does not need to initiate authentication for the first terminal. This avoids repeated authentication, reduces signaling interactions and latency, and ensures user service continuity.

[0072] In some possible implementations, initiating authentication of the first terminal includes: obtaining identity information of the first terminal based on first information in the first request message, the identity information of the first terminal including an identity identifier of the first terminal; and initiating authentication of the first terminal based on the identity information of the first terminal.

[0073] In this implementation, the second authentication entity may obtain authentication parameters or authentication methods based on the identity information of the first terminal, and then initiate authentication on the first terminal based on the authentication parameters or authentication method.

[0074] As an example, the second authentication entity can obtain the file information (profile) corresponding to the identity information of the first terminal by parsing the identity information of the first terminal. The file information can be used to store the method for authenticating the first terminal, and then obtain the authentication method from the file information, and initiate authentication for the first terminal based on the obtained authentication method.

[0075] Alternatively, the second authentication entity obtains the authentication method in the file information corresponding to the identity information of the first terminal by parsing the identity information of the first terminal, and initiates authentication on the first terminal based on the authentication method.

[0076] Optionally, the second authentication entity may be a blockchain node. When the second authentication entity is a blockchain node, the identity information of the first terminal and the file information corresponding to the identity information of the first terminal may be stored on the blockchain.

[0077] In this case, the second authentication entity can obtain the file information stored on the blockchain by parsing the identity information of the first terminal, and obtain the authentication method in the file information, and initiate authentication on the first terminal based on the obtained authentication method.

[0078] Alternatively, the second authentication entity may parse the identity information of the first terminal and directly obtain the authentication method from the file information stored on the blockchain, and then initiate authentication on the first terminal based on the authentication method.

[0079] Optionally, the identity information of the first terminal may include the scID of the first terminal.

[0080] In this implementation, the second authentication entity can initiate authentication for the first terminal after obtaining the file information of the first terminal, even if the operator to which the second authentication entity belongs is not the operator contracted by the first terminal, so that the first terminal can flexibly access multiple operator networks.

[0081] In some possible implementations, if the authentication of the first terminal fails, the first response message indicates that the second authentication entity does not agree to change the authentication entity of the first terminal; or, if the authentication of the first terminal succeeds, the first response message indicates that the second authentication entity agrees to change the authentication entity of the first terminal.

[0082] In this implementation, the second authentication entity may determine the first response message based on the authentication result of the first terminal, that is, the second authentication entity may determine whether to agree to change the authentication entity of the first terminal based on the authentication result of the first terminal.

[0083] In some possible implementations, the method further includes: receiving a security context of the first authentication entity and the first terminal.

[0084] In some possible implementations, the method further includes: receiving an access request message from the first terminal when the first response message indicates that the second authentication entity agrees to change the authentication entity of the first terminal.

[0085] Optionally, when the first response message indicates that the second authentication entity agrees to change the authentication entity of the first terminal, the first response message may further include information about operators that the first terminal can access.

[0086] Optionally, the access request message further includes the operator that the first terminal requests to access. It is understandable that the effects achievable in the second aspect can be referred to the description in the first aspect, and will not be elaborated here.

[0087] In a third aspect, the present application provides a communication method, applied to a first terminal. The method may include: receiving a second response message from a first authentication entity, the second response message including at least one of the following information: consent to change the authentication entity of the first terminal, or identity information of a second authentication entity; and sending an access request message to the second authentication entity.

[0088] In this method, the first terminal can determine through the received second response message that the first authentication entity and the second authentication entity agree to change the authentication entity, and then execute the authentication entity change process, avoiding the situation where the first authentication entity or the second authentication entity does not agree to change the authentication but the authentication entity change process is executed, thereby avoiding wasting resources.

[0089] In some possible implementations, the second response message further includes information about operators that the first terminal can access.

[0090] In this implementation, the first terminal can determine the operator that the first terminal can access based on the second response message, which is helpful for the first terminal to determine the operator it needs to access and facilitates the subsequent access of the first terminal to the network through the second authentication entity.

[0091] In some possible implementations, the access request message further includes the operator that the first terminal requests to access.

[0092] In this implementation, the second authentication entity can determine the operator that the first terminal needs to access based on the access request message, thereby providing corresponding operator services for the first terminal to meet the operator requirements of the first terminal.

[0093] It can be understood that the effects obtainable in the third aspect can be referred to the description in the first or second aspect and will not be elaborated here.

[0094] In a fourth aspect, the present application provides a communication method, which can be applied to a first authentication entity. The method may include: receiving an authentication entity change suggestion message from the first terminal, wherein the authentication entity change suggestion message is used to suggest changing the authentication entity.

[0095] In this method, when deciding to change the authentication entity, the first terminal may generate an authentication entity change suggestion message and send the authentication entity change suggestion message to the first authentication entity.

[0096] Optionally, when the location of the first terminal is updated, or the access type of the first terminal is updated, or the reception quality of the signal received by the first terminal from the first authentication entity is lower than a first preset threshold, or the reception quality of the signal received by the first terminal from the second authentication entity is higher than a second threshold, the first terminal decides to change the authentication entity.

[0097] Optionally, the authentication entity change proposal message may also include third information, which includes the operator information of the second authentication entity and / or the blockchain information of the second authentication entity. The operator information of the second authentication entity is used to indicate the operator that the first terminal wants to access, and the blockchain information of the second authentication entity can indicate the chain identifier of the blockchain to which the second authentication entity belongs.

[0098] In this method, the first terminal can independently decide whether the authentication entity can be changed, which makes it easier to meet the needs of the first terminal.

[0099] In some possible implementations, the method may further include: if the first authentication entity and the second authentication entity do not belong to the same operator, and the first authentication entity and the second authentication entity are not in the same blockchain, sending an authentication entity change rejection message to the first terminal, the authentication entity change rejection message indicating the rejection of changing the authentication entity and the reason for rejecting the change of the authentication entity.

[0100] In this implementation, if the first authentication entity and the second authentication entity do not belong to the same operator, and the first authentication entity and the second authentication entity are not in the same blockchain, the first authentication entity can determine that the identity of the second authentication entity is illegal, and then send an authentication entity change rejection message to the first terminal, which is conducive to improving the security of the system.

[0101] In some possible implementations, the method further includes: if the first authentication entity and the second authentication entity belong to the same operator, and / or the first authentication entity and the second authentication entity are on the same blockchain, sending a first request message to the second authentication entity, wherein the first request message is used to request a change of the authentication entity of the first terminal.

[0102] In this implementation, if the first authentication entity and the second authentication entity belong to the same operator, and / or the first authentication entity and the second authentication entity are on the same blockchain, the first authentication entity can determine that the identity of the second authentication entity is legal, and then send a first request message to the second authentication entity, which is conducive to improving the security of the system.

[0103] In a fifth aspect, the present application provides a communication method, applied in a first terminal, comprising: sending an authentication entity change suggestion message to a first authentication entity, wherein the authentication entity change suggestion message is used to suggest changing the authentication entity.

[0104] In some possible implementations, an authentication entity change recommendation message is sent to the first authentication entity when at least one of the following conditions is met: the location of the first terminal is updated, the access type of the first terminal is updated, the reception quality of the signal received by the first terminal from the first authentication entity is lower than a first preset threshold, or the reception quality of the signal received by the first terminal from the second authentication entity is higher than a second preset threshold.

[0105] In this implementation, when these conditions are met, the first terminal decides to change the authentication entity, which is beneficial to improving the signal reception quality of the first terminal and can also meet the service needs of the first terminal.

[0106] In some possible implementations, the method further includes: receiving an authentication entity change rejection message from the first authentication entity, wherein the authentication entity change rejection message indicates rejection of changing the authentication entity and a reason for rejecting the change of the authentication entity.

[0107] It can be understood that the effects obtainable in the fifth aspect can be referred to the description in the fourth aspect and will not be elaborated here.

[0108] In a sixth aspect, the present application provides a communication device, which can be used for the first authentication entity of the first aspect. The communication device can be the first authentication entity, or a device in the first authentication entity (for example, a chip, a chip system, or a circuit), or can be a logic module or software that can implement all or part of the functions of the first authentication entity. In one possible implementation, it includes a module or unit for implementing the method in the first aspect and any possible implementation of the first aspect. For example, it can include a module or unit that corresponds one-to-one to the method / operation / step / action described in the first aspect. The module or unit can be a hardware circuit, or software, or a combination of a hardware circuit and software. Optionally, each module or unit can implement the corresponding function by executing a computer program.

[0109] In the seventh aspect, the present application provides a communication device, which can be used for the second authentication entity of the second aspect. The communication device can be the second authentication entity, or a device in the second authentication entity (for example, a chip, a chip system, or a circuit), or can be a logic module or software that can implement all or part of the functions of the second authentication entity. In one possible implementation, it includes a module or unit for implementing the method in the second aspect and any possible implementation of the second aspect. For example, it can include a module or unit that corresponds one-to-one to the method / operation / step / action described in the second aspect. The module or unit can be a hardware circuit, or software, or a combination of a hardware circuit and software. Optionally, each module or unit can implement the corresponding function by executing a computer program.

[0110] In an eighth aspect, the present application provides a communication device, which can be used for the first terminal of the third aspect. The communication device can be the first terminal, or a device in the first terminal (for example, a chip, a chip system, or a circuit), or can be a logic module or software that can implement all or part of the functions of the first terminal. In one possible implementation, a module or unit for implementing the method in the third aspect and any possible implementation of the third aspect is included. For example, it can include a module or unit that corresponds one-to-one to the method / operation / step / action described in the third aspect, and the module or unit can be a hardware circuit, or software, or a combination of a hardware circuit and software. Optionally, each module or unit can implement the corresponding function by executing a computer program.

[0111] In the ninth aspect, the present application provides a communication device, which can be used for the first authentication entity of the fourth aspect. The communication device can be the first authentication entity, or a device in the first authentication entity (for example, a chip, a chip system, or a circuit), or can be a logic module or software that can implement all or part of the functions of the first authentication entity. In one possible implementation, it includes a module or unit for implementing the method in the fourth aspect and any possible implementation of the fourth aspect. For example, it can include a module or unit that corresponds one-to-one to the method / operation / step / action described in the fourth aspect, and the module or unit can be a hardware circuit, or software, or a combination of a hardware circuit and software. Optionally, each module or unit can implement the corresponding function by executing a computer program.

[0112] In the tenth aspect, the present application provides a communication device, which can be used for the first terminal of the fifth aspect. The communication device can be the first terminal, or a device in the first terminal (for example, a chip, a chip system, or a circuit), or can be a logic module or software that can implement all or part of the functions of the first terminal. In one possible implementation, a module or unit for implementing the method in the fifth aspect and any possible implementation of the fifth aspect is included. For example, it can include a module or unit that corresponds one-to-one to the method / operation / step / action described in the fifth aspect, and the module or unit can be a hardware circuit, or software, or a combination of a hardware circuit and software. Optionally, each module or unit can implement the corresponding function by executing a computer program.

[0113] In an eleventh aspect, the present application provides a communication device comprising a processor for causing the device to execute a method as in any one of aspects one to five and any possible implementation thereof by executing a computer program (or computer executable instructions) stored in a memory and / or through a logic circuit.

[0114] In a possible implementation, the device further includes a memory.

[0115] In one possible implementation, the processor and the memory are integrated together.

[0116] In another possible implementation, the memory is located outside the communication device.

[0117] In one possible implementation, the communication device further includes a communication interface, which is used for the communication device to communicate with other devices, such as sending or receiving data and / or signals. Exemplarily, the communication interface can be a transceiver, circuit, bus, module, or other type of communication interface.

[0118] In the twelfth aspect, the present application provides a computer-readable storage medium that stores a computer program or instruction for execution by a communication device. When the computer program or instruction runs on the communication device, the method described in any one of the first to fifth aspects and any possible implementation method thereof is implemented.

[0119] In a thirteenth aspect, the present application provides a computer program product comprising instructions, which, when executed on a communication device, enables the method described in any one of the first to fifth aspects and any possible implementation thereof to be implemented.

[0120] In a fourteenth aspect, the present application provides a communication system, comprising a first authentication entity and a second authentication entity. The first authentication entity is configured to execute the method described in the first aspect and any possible implementation thereof, or to execute the method described in the fourth aspect and any possible implementation thereof. The second authentication entity is configured to execute the method described in the second aspect and any possible implementation thereof.

[0121] Optionally, the communication system further includes a first terminal, which is used to execute the method described in the third aspect and any possible implementation method of the third aspect, or to execute the method described in the fifth aspect and any possible implementation method of the fifth aspect.

[0122] It can be understood that the effects that can be obtained in the sixth to fourteenth aspects can be referred to the description in the first to fifth aspects and will not be repeated here. BRIEF DESCRIPTION OF THE DRAWINGS

[0123] FIG1 is a schematic diagram of a communication system applicable to an embodiment of the present application;

[0124] FIG2 is a schematic diagram of a user device identity authentication process;

[0125] FIG3 is a schematic diagram of an authentication entity change process;

[0126] FIG4 is a schematic diagram of a blockchain architecture applicable to an embodiment of the present application;

[0127] FIG5 is a flow chart of a communication method provided by an embodiment of the present application;

[0128] FIG6 is a schematic diagram of a method for a first authentication entity to determine whether to generate a first request message according to an embodiment of the present application;

[0129] 7 is a schematic diagram of a method for a first authentication entity to determine whether to generate a first request message according to another embodiment of the present application;

[0130] FIG8 is a flow chart of a communication method provided by another embodiment of the present application;

[0131] FIG9 is a flow chart of a communication method provided by another embodiment of the present application;

[0132] FIG10 is a flow chart of a communication method provided by another embodiment of the present application;

[0133] FIG11 is a flow chart of a communication method provided by another embodiment of the present application;

[0134] FIG12 is a flow chart of a communication method provided by another embodiment of the present application;

[0135] FIG13 is a flow chart of a communication method provided by another embodiment of the present application;

[0136] FIG14 is a schematic structural diagram of a communication device provided in one embodiment of the present application;

[0137] FIG15 is a schematic structural diagram of a communication device provided in another embodiment of the present application;

[0138] FIG16 is a schematic structural diagram of a communication device provided in yet another embodiment of the present application;

[0139] FIG17 is a schematic structural diagram of a communication device provided in yet another embodiment of the present application. DETAILED DESCRIPTION

[0140] The technical solutions in the embodiments of the present application will be described below in conjunction with the drawings in the embodiments of the present application.

[0141] To facilitate a clear description of the technical solutions of the embodiments of the present application, in the embodiments of the present application, words such as "first" and "second" are used to distinguish between identical or similar items with substantially the same functions and effects. For example, the first information and the second information are merely used to distinguish different information and do not limit their order. Those skilled in the art will understand that words such as "first" and "second" do not limit the quantity or execution order, and words such as "first" and "second" do not necessarily limit differences.

[0142] In the embodiments of the present application, "at least one" refers to one or more, and "more" refers to two or more. "And / or" describes the association relationship of associated objects, indicating that three relationships may exist. For example, A and / or B can represent: the existence of A alone, the existence of A and B at the same time, and the existence of B alone, where A and B can be singular or plural. The character " / " generally indicates that the previous and next associated objects are in an "or" relationship. "At least one of the following items" or similar expressions refers to any combination of these items, including any combination of single items or plural items. For example, at least one of a, b and (or) c can represent: a, b, c; a and b; a and c; b and c; or a and b and c. Where a, b, c can be single or multiple.

[0143] The technical solution of the present application can be applied to fifth-generation (5G) communication systems, such as 5G new radio (NR) communication systems, or to various communication systems evolved after 5G, such as sixth-generation (6G) communication systems. The method provided in the embodiment of the present application can also be applied to wireless fidelity (WiFi) systems, long-range Internet of Things (LoRa) systems, or Internet of Vehicles systems. The method provided in the embodiment of the present application can also be applied to satellite communication systems. The satellite communication system can be integrated with the above-mentioned communication system, which is not limited by the present application.

[0144] Below, the embodiments of the present application are described in detail with reference to the accompanying drawings.

[0145] To facilitate understanding of the embodiments of the present application, a communication system applicable to the embodiments of the present application is first described with reference to FIG1. ​​As shown in FIG1, the communication system 100 may include at least one network device (such as 110a and 110b in FIG1) and may also include at least one terminal (such as 120a to 120j in FIG1).

[0146] Among them, the network equipment may include wireless access network (RAN) equipment and core network equipment. The terminal may be connected to the wireless access network equipment wirelessly, and the wireless access network equipment may be connected to the core network equipment wirelessly or by wire. The core network equipment and the wireless access network equipment may be independent and different physical devices, or the functions of the core network equipment and the logical functions of the wireless access network equipment may be integrated into the same physical device, or a physical device may integrate some functions of the core network equipment and some functions of the wireless access network equipment. Terminals and wireless access network equipment may be connected to each other by wire or wirelessly. Figure 1 is only a schematic diagram. The communication system may also include other network equipment, such as wireless relay equipment and wireless backhaul equipment, which are not shown in Figure 1.

[0147] A radio access network device may be a device with wireless transceiver functions. The radio access network device may be a device that provides wireless communication function services, typically located on the network side, and may include but is not limited to: a next-generation base station (gNodeB, gNB) in a 5G communication system, a next-generation base station in a sixth-generation (6G) mobile communication system, a base station in a future mobile communication system, or an access node in a WiFi system, an evolved node B (eNB) in a long-term evolution (LTE) system, a radio network controller (RNC), a home base station (e.g., home evolved NodeB, or home Node B, HNB), a baseband unit (BBU), a transmission reception point (TRP), a transmitting point (TP), etc.

[0148] The radio access network equipment provides services for a cell. The user equipment communicates with the base station through the transmission resources used by the cell. The cell can be the cell corresponding to the base station. The cell can belong to a macro base station or a base station corresponding to a small cell. The small cells here can include: metro cells, micro cells, pico cells, femto cells, etc.

[0149] The wireless access network device can also be a device that acts as a base station in device-to-device (D2D) communication, vehicle-to-vehicle communication, drone communication, and machine communication. Optionally, the wireless access network device can be a satellite, a macro base station, a micro base station or an indoor station, a relay node or a donor node, a device that provides wireless communication services to user devices, a wireless controller in the cloud radio access network (CRAN) scenario, a server, a relay station, a vehicle or vehicle-mounted device, a wearable device, and a network device in a future evolution network. For example, the wireless access network device in vehicle to everything (V2X) technology can be a road side unit (RSU).

[0150] In another possible scenario, multiple radio access network devices collaborate to assist the terminal in achieving wireless access, and different radio access network devices respectively implement part of the functions of the base station. For example, the radio access network device can be a centralized unit (CU), a distributed unit (DU), a CU-control plane (CP), a CU-user plane (UP), or a radio unit (RU). The CU and DU can be set separately, or can also be included in the same network element, such as a BBU. The RU can be included in a radio frequency device or a radio frequency unit, such as a remote radio unit (RRU), an active antenna unit (AAU), or a remote radio head (RRH). It can be understood that the radio access network device can be a CU node, a DU node, or a device including a CU node and a DU node. In addition, the CU can be divided into a network device in the radio access network device, or the CU can be divided into a network device in the core network device, which is not limited here.

[0151] In different systems, CU (or CU-CP and CU-UP), DU or RU may also have different names, but those skilled in the art can understand their meanings. For example, in an open radio access network (O-RAN) system, CU may also be called O-CU (open CU), DU may also be called O-DU, CU-CP may also be called O-CU-CP, CU-UP may also be called O-CU-UP, and RU may also be called O-RU. For the convenience of description, this application uses CU, CU-CP, CU-UP, DU and RU as examples for description. Any unit of CU (or CU-CP, CU-UP), DU and RU in this application can be implemented by a software module, a hardware module, or a combination of a software module and a hardware module.

[0152] In the embodiments of the present application, the form of the wireless access network device is not limited. The device used to implement the functions of the wireless access network device can be the wireless access network device; it can also be a device that supports the wireless access network device to implement the functions, such as a chip system. The device can be installed in the wireless access network device or used in conjunction with the wireless access network device.

[0153] A terminal can also be referred to as a terminal device, user equipment (UE), mobile station (MS), mobile terminal (MT), or a device that provides voice or data connectivity to users. It can also be an IoT device. For example, terminal devices include handheld devices with wireless connectivity, in-vehicle devices, etc. Currently, terminal devices may include: mobile phones, tablet computers, laptop computers, PDAs, mobile internet devices (MIDs), wearable devices (such as smart watches, smart bracelets, pedometers, smart glasses, etc.), vehicle-mounted devices (such as cars, bicycles, electric vehicles, airplanes, ships, trains, high-speed trains, etc.), satellite terminals, virtual reality (VR) devices, augmented reality (AR) devices, smart point of sale (POS) machines, customer-premises equipment (CPE), light UEs, reduced capability UEs (REDCAP UEs), wireless terminals in industrial control, smart home devices (such as refrigerators, televisions, air conditioners, and electricity meters), intelligent robots, robotic arms, workshop equipment, wireless terminals in unmanned driving, wireless terminals in telemedicine, wireless terminals in smart grids, wireless terminals in transportation safety, wireless terminals in smart cities, wireless terminals in smart homes, and flying devices (such as intelligent robots, hot air balloons, drones, and airplanes). The terminal device can also be a vehicle device, such as a complete vehicle device, a vehicle-mounted module, a vehicle-mounted chip, an on-board unit (OBU) or a telematics box (T-BOX), etc. The terminal device can also be other devices with terminal functions. For example, the terminal device can also be a device that serves as a terminal function in D2D communication.

[0154] In the embodiment of the present application, the device for realizing the function of the terminal may be a terminal, or a device that can support the terminal to realize the function, such as a chip system, a communication module, or a modem, etc., and the device can be installed in the terminal. In the embodiment of the present application, the chip system may be composed of chips, or may include chips and other discrete devices. In the technical solution provided in the embodiment of the present application, the device for realizing the function of the terminal is a terminal, and the terminal is a UE as an example to describe the technical solution provided in the embodiment of the present application. The embodiment of the present application does not limit the specific technology and specific device form adopted by the terminal.

[0155] In this application, the number of wireless access network devices and terminals may not be limited. For example, the number of wireless access network devices may be at least one, and each of the at least one wireless access network devices may be connected to at least one terminal.

[0156] In this application, wireless access network devices and terminals can be deployed on land, including indoors or outdoors, handheld or vehicle-mounted; can also be deployed on water; and can also be deployed in the air on aircraft, balloons, and satellites. The embodiments of this application do not limit the application scenarios of wireless access network devices and terminals.

[0157] The embodiments of the present application can be applied to downlink signal transmission, uplink signal transmission, and device-to-device (D2D) signal transmission. For downlink signal transmission, the transmitting device is a wireless access network device, and the corresponding receiving device is a terminal. For uplink signal transmission, the transmitting device is a terminal, and the corresponding receiving device is a wireless access network device. For D2D signal transmission, the transmitting device is a terminal, and the corresponding receiving device is also a terminal. The embodiments of the present application do not limit the direction of signal transmission.

[0158] The wireless access network device and the terminal, as well as the terminals, can communicate through the authorized spectrum, through the unlicensed spectrum, or through both the authorized spectrum and the unlicensed spectrum. The wireless access network device and the terminal, as well as the terminals, can communicate through the spectrum below 6G, through the spectrum above 6G, or through both the spectrum below 6G and the spectrum above 6G. The embodiments of the present application do not limit the spectrum resources used between the wireless access network device and the terminal.

[0159] In this application, core network equipment is primarily used to provide terminal connectivity, manage terminals, and carry services. It can act as a bearer network, providing an interface to external networks to process and distribute services across the entire network. Furthermore, core network equipment can also generate contract information based on the terminal's identity information, initiate authentication for the terminal based on the terminal's identity information, and generate authentication results for the terminal based on the terminal's identity information.

[0160] In the present application, the identity information of the terminal may include the terminal's self-controlled identity identifier (scID). The terminal's scID may include at least one of the following information: decentralized root credentials (DRC), decentralized identity credentials (DIC), or decentralized self-control credentials (DSCC). DRC may be preset in the card by the card vendor / terminal device manufacturer when it leaves the factory, and the credential information (or authentication credential) in the file information corresponding to the DRC may be endorsed by the card vendor / terminal manufacturer, for example, signed by the card vendor / terminal manufacturer's private key. DIC may be one or more temporary / derived identities derived from the DRC. The credential information in the file information corresponding to the DIC may be endorsed by the DRC, for example, signed by the DRC's private key, or may be endorsed by the operator, for example, signed by the operator's private key. DSCC is for the user's control over identity information. The user generates the DSCC by himself and may be independent of the DRC or DIC. The credential information in the file information corresponding to the DSCC is self-signed by the terminal / card, and can also be endorsed by the contracted operator after signing the contract.

[0161] Optionally, the identity information of the terminal device may further include a user permanent identifier (SUPI) of the terminal device and / or a subscription concealed identifier (SUCI) of the terminal device.

[0162] The core network equipment may include multiple network elements (not shown in Figure 1), such as access and mobility management function (AMF), session management function (SMF), policy control function (PCF), network repository function (NRF), user plane function (UPF), unified data management (UDM), unified data repository function (UDR), authentication server function (AUSF), security anchor function (SEAF), authentication credential repository and processing function (ARPF), unstructured data storage function (UDSF), etc.

[0163] Among them, AMF is mainly used to perform registration, connection, reachability, and mobility management, provide session management message transmission channels for UE and SMF network elements, provide authentication and authorization functions for user access, and serve as access points for terminals and wireless core network control planes.

[0164] The SMF is mainly responsible for tunnel maintenance, Internet Protocol (IP) address allocation and management, UP function selection, policy implementation and control of QoS parameters, billing control collection, roaming, etc.

[0165] PCF should support the provision of a unified policy framework to manage network behavior, provide policy rules to network entities for implementation, and be responsible for obtaining user contract information related to policy decisions.

[0166] NRF can be used to provide registration and discovery capabilities for network elements in the network, enabling network function (NF) elements to discover each other and communicate through interfaces.

[0167] The UPF is primarily responsible for forwarding and receiving user data from terminals. UPF network elements can receive user data from the data network and transmit it to terminals via access network equipment. They can also receive user data from terminals via access network equipment and forward it to the data network. The transmission resources and scheduling functions provided by the UPF network element to terminals are managed and controlled by the SMF network element.

[0168] UDM is mainly used to generate authentication credentials, user identification processing (such as storing and managing user identities), access authorization control and contract data management.

[0169] UDR is mainly used by UDM network elements to store subscription data or read subscription data, and PCF network elements to store policy data or read policy data.

[0170] AUSF is mainly used to receive the request from AMF network element to authenticate the UE (or identity authentication), request the key from UDM, and then forward the key issued by UDM to AMF for authentication processing.

[0171] SEAF mainly provides authentication functions through AMF in the service network.

[0172] The ARPF is mainly responsible for storing contract information and generating authentication vectors based on the contract information. The authentication vectors are used by the UE to confirm the legitimacy of the network and by the network to confirm the legitimacy of the UE during the authentication process.

[0173] UDSF mainly stores unstructured data, which is data not defined in the protocol.

[0174] In a communication system, when a UE accesses a network, the network side needs to authenticate the UE. The network side may include an authentication entity, which may be used to authenticate the UE. Optionally, the authentication entity may be a communication device, or a chip or chip system used in a communication device. Exemplarily, the authentication entity may be the above-mentioned AUSF.

[0175] As an example, the UE reports its identity when joining the network, and the core network initiates an authentication process through non-access stratum (NAS) signaling. The specific authentication algorithm may include an authentication algorithm based on a symmetric key and an authentication algorithm based on an asymmetric key.

[0176] Taking an authentication algorithm based on a symmetric key as an example, the UE identity authentication process may be shown in FIG2 .

[0177] S201: A UE sends UE identity information to a UDM network element / UDR network element. The UE identity information includes the UE's SUPI. Correspondingly, the UDM / UDR network element receives the UE identity information.

[0178] In this method, the UE may sign a contract with the operator in advance, obtain UE identity information, and store the UE's root key and identity information in a universal subscriber identity module (USIM) card of the UE.

[0179] In addition, the UE may also send the root key and identity information of the UE to the UDM network element / UDR network element. After receiving the root key and identity information of the UE, the UDM network element / UDR network element may store the root key and identity information of the UE.

[0180] S202: The UDM network element / UDR network element generates an authentication vector based on the UE identity information. The authentication vector includes a challenge value and a first authentication response.

[0181] The challenge value may include a random number (RAND) and an authentication token (AUTN).

[0182] The first authentication response may include a first response number (response).

[0183] S203: The UDM network element / UDR network element sends an authentication vector to the AUSF network element, and the AUSF network element receives the authentication vector accordingly.

[0184] S204, the AUSF network element sends the challenge value in the authentication vector to the UE.

[0185] S205: The UE generates a second authentication response based on the challenge value in the authentication vector and its own preset key.

[0186] In this method, the second authentication response may include a second RES.

[0187] S206, the UE sends a second authentication response to the AUSF network element. Correspondingly, the AUSF network element receives the second authentication response.

[0188] S207: The AUSF network element determines whether the first authentication response and the second authentication response are the same. If the first authentication response and the second authentication response are the same, execute S208; if the first authentication response and the second authentication response are different, execute S209.

[0189] S208, the AUSF network element sends first indication information to the UE, where the first indication information indicates that the authentication is successful.

[0190] Optionally, the AUSF network element can also send the first indication information to the AMF network element / SEAF network element.

[0191] S209, the AUSF network element sends second indication information to the UE, where the second indication information indicates that the authentication has failed.

[0192] Optionally, the AUSF network element can also send the second indication information to the AMF network element / SEAF network element.

[0193] In this method, the radio access network device can be responsible for transparently transmitting signaling between the UE and the core network device. After confirming that the AUSF network element is successfully authenticated, the AMF network element requests the radio access network device to establish a UE context through NG application protocol (NGAP) signaling. After the radio access network device and the UE negotiate a security algorithm, the access stratum (AS) security is activated, the UE's identity is trusted, and services are provided to the UE.

[0194] In this method, the authentication entity is an AUSF network element. The AUSF network element can obtain UE identity information and authentication parameters from the core network and authenticate the UE based on the UE identity information and authentication parameters. This process of authenticating the UE by obtaining the UE identity information and authentication parameters can be called direct authentication, and the authentication entity that authenticates the UE based on the direct authentication method can be called a direct authentication entity. In the embodiment shown in Figure 2, the AUSF network element can be the direct authentication entity.

[0195] For direct authentication, the UE can only choose to access a specific operator, and cannot realize a multi-operator one-card pass, nor can it flexibly select an operator based on signal, tariff, location, etc.; when the UE needs to access multiple operators, multiple card slots need to be set up, taking up mobile phone space; when the user roams, it needs to return to the home location for identity authentication, and cross-border roaming charges are high.

[0196] Furthermore, when a UE accesses the network, network-side authentication of the UE can only occur at the core network element (NE), an entity with direct access to sensitive information such as user subscription information and root keys. Because authentication entities are typically deployed far from the user, the authentication signaling must travel a longer path, resulting in delays in UE access.

[0197] Furthermore, since direct authentication can only be verified within the core network, malicious UEs could launch distributed denial of service (DDoS) attacks or degradation attacks against the core network, potentially leaking UE privacy, causing abnormal UE network disconnection, or even leading to partial network failure. Furthermore, if a large number of terminals in a network system initiate authentication with the core network within a short period of time, this can lead to a surge in core network traffic and potentially cause network congestion.

[0198] Therefore, a new authentication method can be provided, for example, authenticating the UE without obtaining authentication parameters. This method of authenticating the UE without obtaining authentication parameters can be called an indirect authentication method, and the authentication entity that authenticates the UE based on the indirect authentication method can be called an indirect authentication entity.

[0199] The indirect authentication entity may be deployed in a radio access network device or a core network device. For example, a RAN-AUSF may be deployed in a radio access network device as an indirect authentication entity.

[0200] Optionally, the indirect authentication entity can also be merged with the radio access network equipment or core network equipment. For example, the base station directly serves as the indirect authentication entity (it can be limited to base stations with strong computing power and a large number of access users), the edge computing node serves as the indirect authentication entity, and the core network AMF network element serves as the indirect authentication entity.

[0201] In indirect authentication scenarios, the UE can be given the flexibility to choose its operator, regardless of the operator it is signed to. Furthermore, indirect authentication entities can be deployed at the network edge, such as access network base stations and edge computing nodes. Placing the authentication process at the network edge can reduce latency in the UE's network access process. Furthermore, placing the authentication process at the network edge can alleviate pressure on the core network and prevent malicious UEs from entering the core network, thus protecting the core network's security.

[0202] In some scenarios, the authentication entity may change. For example, when a terminal moves from one user registration area to another, the authentication entity may change.

[0203] In addition, in the indirect authentication scenario, since the area covered by the indirect authentication entity is smaller than that of the AUSF, it is easier for the terminal to re-register with the network when it moves, that is, it is easier to cause the authentication entity to change.

[0204] FIG3 is a schematic diagram of an authentication entity change process.

[0205] S301: When a UE moves to a user registration area, it sends a registration request message to a wireless access network device. The registration request message includes the identity information of the target AMF network element. In response, the wireless access network device receives the registration request message.

[0206] S302: The wireless access network device sends the registration request information to the target AMF network element based on the identity information of the target AMF network element. Correspondingly, the target AMF network element receives the registration request information.

[0207] S303: The target AMF network element sends a first message to the UDSF network element or the original AMF network element. The first message instructs the UDSF network element or the original AMF network element to send UE identity information, where the UE identity information includes the UE SUPI and UE context. Accordingly, the UDSF network element or the original AMF network element receives the first message.

[0208] Optionally, the UE identity information may further include the SUCI of the UE.

[0209] S304, the UDSF network element or the original AMF network element sends the UE identity information to the target AMF network element.

[0210] Optionally, the target AMF network element may further send second information to the UE, where the second information instructs the UE to report the SUPI. Accordingly, after receiving the second information, the UE may report the SUPI to the target AMF network element.

[0211] S305: The target AMF network element selects an authentication entity based on the UE identity information.

[0212] In this method, the target AMF network element can select the target AUSF network element as the authentication entity according to the network policy configured by the operator. The target AUSF network element may be different from the original AUSF network element.

[0213] In this method, the target AUSF network element can authenticate the UE based on the method shown in Figure 2.

[0214] When this method is used to change the authentication entity, the UE experiences a significant delay in changing the authentication entity. This is because the network reselects the target AUSF to initiate authentication for the UE. There is no message exchange between the target AUSF and the original AUSF, so the authentication process must be re-initiated. This prevents the effective use of the previous authentication result, impacting the UE's service continuity while in motion.

[0215] To this end, the present application provides a communication method to solve the problem of long delay in changing the authentication entity.

[0216] The communication method of the present application can be applied to a blockchain architecture, which may include a distributed ledger anchor function (DLAF) and a distributed ledger enabler (DLE).

[0217] DLAF is the anchor point for overall management and blockchain-related operations within the communication network. It can be used to perform blockchain management functions, DLE registration management, chain creation, DLE activation, and blockchain access control. DLAF is typically deployed in the core network as a network function, but may also exist in a hierarchical structure, such as deploying RAN-DLAF in the access network.

[0218] The DLE is a blockchain-enabling module within the communication network. It receives configuration and management from the DLAF and distinguishes between different on-chain node types based on their capabilities. A DLE can perform one or more of the following functions: transaction proposal, transaction endorsement / execution, smart contract deployment and execution, consensus, transaction / block synchronization, and ledger storage. The DLE exists at every node in the network, including terminals, access network nodes, and core network elements (e.g., network functions). All nodes requiring blockchain capabilities can deploy the DLE. Within the core network, the DLE can also function as an independent network function, providing blockchain proxy capabilities to other NFs.

[0219] The blockchain architecture can include a native blockchain architecture for a CU-DU non-separation scenario (as shown in FIG4(a) ) and a native blockchain architecture for a CU-DU separation scenario (as shown in FIG4(b) ). A data network is a network used to provide data transmission, such as a carrier network.

[0220] In the architecture shown in (a) of Figure 4, the wireless access network device can be used to authenticate the terminal, and the wireless access network device can be used to change the authentication entity. At this time, the authentication process and the authentication entity change process can be executed by the wireless access network.

[0221] In the architecture shown in (b) of Figure 4 , the radio access network device can be used to authenticate the terminal and change the authentication entity. In this case, the authentication process and the authentication entity change process can be executed by the CU in the radio access network device, and the DU in the radio access network device can be used to transmit relevant information in the authentication process and the authentication entity change process.

[0222] In this application, the terminal has the ability to store the terminal's identity information, the authentication function supported by the identity information, and the reporting function of the identity information (for example, the ability to upload the identity information to the blockchain, carry the identity information when accessing the network, etc.).

[0223] In this application, the wireless access network device can authenticate the terminal based on the terminal's identity information and generate an authentication result for authenticating the terminal based on the terminal's identity information. That is, the authentication entity in this application can be the wireless access network device.

[0224] Optionally, if the wireless access network adopts a CU-DU separation architecture, the CU may perform identity authentication on the terminal based on the identity information of the terminal, and generate an authentication result for authenticating the terminal based on the identity information of the terminal.

[0225] FIG5 is a flow chart of a communication method according to an embodiment of the present application. As shown in FIG5 , the communication method may include S501 to S506.

[0226] S501: A first authentication entity generates a first request message, where the first request message is used to request a change of an authentication entity of a first terminal.

[0227] In this method, the first terminal may be a terminal in the system architecture shown in FIG1 or the system architecture shown in FIG4 .

[0228] In this method, the first authentication entity may be the authentication entity of the first terminal before the change.

[0229] Optionally, the first authentication entity may be a direct authentication entity or an indirect authentication entity. Exemplarily, the first authentication entity may be an AUSF network element, in which case the first authentication entity is a direct authentication entity. Exemplarily, the first authentication entity may also be a wireless access network device, in which case the first authentication entity is an indirect authentication entity.

[0230] Optionally, the first request message may carry a first message, and the first message may include at least one of the following information: identity information of the first terminal, encrypted identity information of the first terminal, index information corresponding to the identity information of the first terminal in the storage system, historical authentication results of the first terminal, authentication records of the first terminal, or index information corresponding to the historical authentication results of the first terminal in the storage system.

[0231] Optionally, the identity information of the first terminal may be stored in the blockchain. In this way, the index information corresponding to the identity information of the first terminal in the storage system may include the blockchain transaction identifier corresponding to the identity information of the first terminal and / or the block identifier corresponding to the identity information of the first terminal.

[0232] The blockchain transaction identifier corresponding to the identity information of the first terminal can be understood as the transaction identifier of the blockchain used to store the identity information of the first terminal. The block identifier corresponding to the identity information of the first terminal can be understood as the identifier of the blockchain used to store the identity information of the first terminal.

[0233] Optionally, the identity information of the first terminal may be stored in a distributed storage system, such as a decentralized shared profile repository (dSPR) system. In this way, the index information corresponding to the identity information of the first terminal in the storage system may include an index identifier corresponding to the identity information of the first terminal in the dSPR.

[0234] In this method, when the first information includes the index information corresponding to the identity information of the first terminal in the storage system, the identity information of the first terminal may not be directly transmitted between the first authentication entity and the second authentication entity. This can reduce the risk of leakage of the identity information of the first terminal and is conducive to improving the security of the network.

[0235] Optionally, the historical authentication results of the first terminal may include the authentication results of the first authentication entity authenticating the first terminal. In this case, the authentication record of the first terminal may include the record of the first authentication entity authenticating the first terminal. The authentication record of the first terminal may include information such as the identity of the party being authenticated, the identity of the authenticator, and the authentication result. The identity of the party being authenticated may include the identity information of the first terminal, the identity of the authenticator may include the identity information of the first authentication entity, and the authentication result may include the result of the first authentication entity authenticating the first terminal. Optionally, the authentication record of the first terminal may also include a timestamp, which may indicate the time when the first authentication entity authenticated the first terminal.

[0236] Optionally, the historical authentication results of the first terminal may be stored in a blockchain. In this way, the index information corresponding to the historical authentication results of the first terminal in the storage system may include a blockchain transaction identifier corresponding to the historical authentication results of the first terminal and / or a block identifier corresponding to the historical authentication results of the first terminal.

[0237] The blockchain transaction identifier corresponding to the historical authentication result of the first terminal can be understood as the transaction identifier of the blockchain used to store the historical authentication result of the first terminal. The block identifier corresponding to the historical authentication result of the first terminal can be understood as the identifier of the blockchain used to store the historical authentication result of the first terminal.

[0238] Optionally, the historical authentication results of the first terminal may be stored in a distributed storage system, such as a dSPR system. Thus, the index information corresponding to the historical authentication results of the first terminal in the storage system may include the index identifier corresponding to the historical authentication results of the first terminal in the dSPR.

[0239] In this method, when the first information includes the historical authentication results of the first terminal, the authentication record of the first terminal, or the corresponding index information of the historical authentication results of the first terminal in the storage system, the identity information of the first terminal may not be transmitted between the first authentication entity and the second authentication entity. This can also reduce the risk of leakage of the identity information of the first terminal and is conducive to improving the security of the network.

[0240] In this method, the information used to obtain the terminal identity information may be referred to as direct parameter information. The direct parameter information may include the identity information of the first terminal, the encrypted identity information of the first terminal, and the index information corresponding to the identity information of the first terminal in the storage system.

[0241] As an example, when the first terminal accesses the network where the first authentication entity is located and sends the identity information of the first terminal to the first authentication entity, and the first authentication entity does not authenticate the first terminal, the first message may include direct parameter information.

[0242] For example, when the first terminal recently changes from another authentication entity to the first authentication entity and the first authentication entity trusts the previous authentication entity / authentication result, or the user access type is emergency access, the first message may include direct parameter information.

[0243] As another example, when the first authentication entity authenticates the user but does not save the authentication result, or the authentication result has expired, or the second authentication entity does not have the authority to obtain the authentication result, the first message may include direct parameter information.

[0244] For example, when the second authentication entity and the first authentication entity do not belong to the same blockchain, or the second authentication entity and the first authentication entity belong to different operators, or the second authentication entity does not have the authority to access the dSPR (dSPR used to store the identity information of the first terminal), the first message may include direct parameter information.

[0245] The second authentication entity may be a changed authentication entity required by the first terminal.

[0246] Optionally, the second authentication entity may be a direct authentication entity or an indirect authentication entity. Exemplarily, the second authentication entity may be an AUSF network element, in which case the second authentication entity is a direct authentication entity. Exemplarily, the second authentication entity may also be a wireless access network device, in which case the second authentication entity is an indirect authentication entity.

[0247] In this method, the second authentication entity may be determined based on a measurement result of the first terminal.

[0248] In an example, the first terminal may perform cell measurement, obtain measurement results, and then determine measurement report information and send the measurement report information to the first authentication entity. The measurement report information includes identity information of the second authentication entity.

[0249] In this example, the first terminal may determine the network device whose signal quality reaches a preset threshold based on the measurement result, and then determine the second authentication entity based on the network device whose signal quality reaches the preset threshold.

[0250] Optionally, the number of network devices whose signal quality reaches the preset threshold may be one. In this case, the first terminal may determine the network device whose signal quality reaches the preset threshold as the second authentication entity.

[0251] Optionally, there may be multiple network devices whose signal quality reaches the preset threshold. In this case, the first terminal may determine each of the multiple network devices as a candidate second authentication entity, and then determine the one with the strongest signal quality among the multiple candidate second authentication entities as the second authentication entity.

[0252] In another example, the first terminal may perform cell measurement, obtain a measurement result, and then send the measurement result to the first authentication entity. The first authentication entity determines the second authentication entity based on the measurement result.

[0253] In this example, the first authentication entity may determine the network device whose signal quality reaches a preset threshold based on the measurement result, and then determine the second authentication entity based on the network device whose signal quality reaches the preset threshold.

[0254] Optionally, the number of network devices whose signal quality reaches the preset threshold may be one. In this case, the first authentication entity may determine the network device whose signal quality reaches the preset threshold as the second authentication entity.

[0255] Optionally, there may be multiple network devices whose signal quality reaches the preset threshold. In this case, the first authentication entity may determine each of the multiple network devices as a candidate second authentication entity, and then determine the one with the strongest signal quality among the multiple candidate second authentication entities as the second authentication entity.

[0256] In this method, the information used to obtain the terminal authentication result may be referred to as indirect parameter information. The indirect parameter information may include historical authentication results of the first terminal, authentication records of the first terminal, and index information corresponding to the historical authentication results of the first terminal in a storage system.

[0257] As an example, when the first terminal accesses the network where the first authentication entity is located and the first authentication entity receives the authentication result of the first terminal, and the authentication result is within the validity period, the first message may include indirect parameter information.

[0258] For example, if the first terminal is recently changed from another authentication entity to the first authentication entity, and the first authentication entity receives the authentication result of the first terminal during the change, and the authentication result is within the validity period, the first message may include indirect parameter information.

[0259] As another example, when the first authentication entity authenticates the user, saves the authentication result, the authentication result is within the validity period, and the second authentication entity has the authority to obtain the authentication result, the first message may include indirect parameter information.

[0260] For example, when the second authentication entity and the first authentication entity belong to the same blockchain, or the second authentication entity and the first authentication entity belong to the same operator, or the second authentication entity has the authority to access dSPR (dSPR used to store the authentication results of the first terminal), the first message may include indirect parameter information.

[0261] In a possible implementation, the first authentication entity may first determine whether to generate the first request message, and only generate the first request message if it is determined to generate the first request message.

[0262] In a possible implementation, after determining that the coverage area of ​​the first authentication entity is updated, or after determining that the network capability of the first authentication entity is updated, the first authentication entity may decide to change the authentication entity, and then determine whether to generate the first request message.

[0263] For example, when a first authentication entity moves to a new area, its coverage area is updated, and the first authentication entity needs to initiate authentication for terminals within the new area. In this example, the first authentication entity is an indirect authentication entity. For example, if the first authentication entity is a satellite, when the satellite moves to a new area, it needs to initiate authentication for terminals within the new area.

[0264] The update of the network capability of the first authentication entity may include: an increase in the load of the network where the first authentication entity is located or an upgrade of the authentication capability of other devices in the network where the first authentication entity is located.

[0265] As an example, when the number of terminals on the network where the first authentication entity is located increases, the load on the network where the first authentication entity is located increases.

[0266] As an example, when the service capability provided by the network where the first authentication entity is located is upgraded, the authentication capabilities of other devices in the network where the first authentication entity is located are upgraded. For example, the network originally does not provide indirect authentication capability, but can provide indirect authentication capability after the upgrade.

[0267] In another possible implementation, if the first terminal decides to change the authentication entity, the first terminal may send second information to the first authentication entity, where the second information indicates at least one of the following: an update to the first terminal's location, an update to the first terminal's access type, a reception quality of a signal received by the first terminal from the first authentication entity below a first preset threshold, a reception quality of a signal received by the first terminal from the second authentication entity above a second preset threshold, a request by the first terminal to change the authentication entity, or identity information of the second authentication entity. Accordingly, after receiving the second information, the first authentication entity may confirm the first terminal's decision to change the authentication entity and then further determine whether to generate a first request message.

[0268] S502: The first authentication entity sends a first request message to the second authentication entity. Correspondingly, the second authentication entity receives the first request message.

[0269] Optionally, when determining that the first terminal meets the first condition, the first authentication entity may further send first indication information to the second authentication entity, where the first indication information indicates that there is no need to initiate authentication for the first terminal.

[0270] In this method, the second authentication entity may not initiate authentication for the first terminal based on the first indication information, thereby avoiding repeated authentication, reducing signaling interaction and delay, and ensuring continuity of user services.

[0271] Optionally, the first condition may include at least one of the following conditions: the access type of the first terminal is an emergency type, the delay requirement of the first terminal is lower than a preset delay threshold, or the frequency of the first terminal changing the authentication entity exceeds a preset frequency threshold.

[0272] The delay requirement of the first terminal being lower than the preset delay threshold can be understood as that the network access delay required by the first terminal is lower than the delay threshold preset by the operator.

[0273] Optionally, the preset frequency threshold may be set by an operator when configuring the network. The frequency of the first terminal changing the authentication entity exceeding the preset frequency threshold may be understood as: the first terminal frequently changing the authentication entity, or the time difference between the timestamp of the first terminal's last authentication entity change and the current timestamp is less than the preset time threshold.

[0274] In this method, the first authentication entity can obtain the access type of the first terminal, the delay requirement of the first terminal, and the frequency of the first terminal changing the authentication entity.

[0275] Optionally, the first indication information may be carried in the first request message, that is, the first request message includes the first message and the first indication information.

[0276] In this method, when the access type of the first terminal is an emergency type, the second authentication entity may not initiate authentication for the first terminal, which can increase the rate at which the first terminal accesses the network through the second authentication entity to meet the first terminal's network access needs.

[0277] In this method, when the delay requirement of the first terminal is lower than the preset delay threshold, the second authentication entity may not initiate authentication for the first terminal, which can increase the rate at which the first terminal accesses the network through the second authentication entity, thereby reducing the delay of the first terminal accessing the network.

[0278] In this method, when the frequency of the first terminal changing the authentication entity exceeds a preset frequency threshold, the second authentication entity may not initiate authentication for the first terminal, which can increase the rate at which the first terminal accesses the network through the second authentication entity, thereby reducing the delay in the first terminal accessing the network, and thus helping to meet the frequency of the first terminal changing the authentication entity.

[0279] S503: The second authentication entity sends a first response message to the first authentication entity, where the first response message indicates whether the second authentication entity agrees to change the authentication entity of the first terminal. Correspondingly, the first authentication entity receives the first response message.

[0280] Optionally, when the first response message indicates that the second authentication entity agrees to change the authentication entity of the first terminal, the first response message may further include identity information of the second authentication entity and operator information of the second authentication entity.

[0281] In this method, the first authentication entity can determine whether the second authentication entity agrees to change the authentication based on the first response message, and execute the authentication entity change process if it is determined that the second authentication entity agrees to change the authentication, thereby avoiding executing the authentication entity change process if the second authentication entity does not agree to change the authentication, thereby avoiding waste of resources.

[0282] S504, when the first response message indicates that the second authentication entity agrees to change the authentication entity of the first terminal, the first authentication entity generates a second response message, and the second response message includes at least one of the following information: agreement to change the authentication entity of the first terminal, or identity information of the second authentication entity.

[0283] As an example, the identity information of the second authentication entity may be carried in the authentication entity change suggestion message, so that the first authentication entity can obtain the identity information of the second authentication entity from the authentication entity change suggestion message sent by the first terminal.

[0284] As another example, the identity information of the second authentication entity may be carried in the first response message. In this way, the first authentication entity may obtain the identity information of the second authentication entity from the first response message sent by the second authentication entity.

[0285] As another example, the identity information of the second authentication entity may be pre-configured into the first authentication entity, and the first authentication entity may store the identity information of the second authentication entity. In this way, the first authentication entity may obtain the identity information of the second authentication entity based on the identity information of the second authentication entity stored in the first authentication entity.

[0286] Optionally, the second response message may further include operator information that the first terminal can access. Here, the operator information that the first terminal can access may be the operator information of the second authentication entity. In other words, the operator information that the first terminal can access may indicate the operator to which the second authentication entity belongs.

[0287] Optionally, information about operators that the first terminal can access may also be carried in the authentication entity change suggestion message or the first response message.

[0288] S505: The first authentication entity sends a second response message to the first terminal. Correspondingly, the first terminal receives the second response message.

[0289] In this method, after receiving the second response message, the first terminal may determine that the first authentication entity and the second authentication entity agree to change the authentication entity.

[0290] In this method, the first terminal can determine based on the second response message whether the first authentication entity and the second authentication entity agree to change the authentication entity, and then execute the authentication entity change process, avoiding executing the authentication entity change process when the first authentication entity or the second authentication entity does not agree to change the authentication, thereby avoiding waste of resources.

[0291] In addition, the first terminal can also determine the operator that the first terminal can access based on the second response message, which is helpful for the first terminal to determine the operator it needs to access and facilitates the subsequent access of the first terminal to the network through the second authentication entity.

[0292] S506: The first terminal sends an access request message to the second authentication entity. The access request message is used to request access to the second authentication entity.

[0293] In this method, the first terminal may determine the identity information of the second authentication entity based on the second response message, and then send an access request message to the second authentication entity based on the identity information of the second authentication entity.

[0294] Optionally, the access request message includes the operator that the first terminal requests to access.

[0295] As an example, when the second response message contains information about operators that the first terminal can access, the first terminal can determine the operators that the first terminal can access based on the second response message, and then determine the operator that the first terminal requests to access based on the operators that the first terminal can access.

[0296] Optionally, the first terminal may be able to access at least one operator, and the first terminal may select one operator from among them to request access.

[0297] As an example, the first terminal may store an operator selection rule, and the first terminal may select an operator based on the operator selection rule to request access.

[0298] Assume that the operators that the first terminal can access include operator 1 and operator 2, and the operator selection rule can be: operator 1 is selected by default, and operator 2 is selected when the signal quality of operator 1 is lower than a preset threshold. Then, the first terminal can select operator 1 as the operator requested to access, and select operator 2 as the operator requested to access when the signal quality of operator 1 is lower than the preset threshold.

[0299] In this method, the second authentication entity can determine the operator that the first terminal needs to access based on the access request message, thereby providing corresponding operator services for the first terminal to meet the operator requirements of the first terminal.

[0300] Optionally, in some embodiments, if the first response message indicates that the second authentication entity does not agree to change the authentication entity, the first authentication entity may reselect one of the candidate second authentication entities as a new second authentication entity. For example, the network device with the second strongest signal quality among the multiple network devices may be determined as the second authentication entity.

[0301] In the technical solution of the present application, the first authentication entity can directly send a first request message to the second authentication entity. Compared with the target AMF network element obtaining the identity information of the terminal after receiving the registration request message and selecting an authentication entity to authenticate the terminal based on the identity information of the terminal, the second authentication entity can quickly determine that the first terminal needs to change the authentication entity, which is conducive to the subsequent first terminal quickly accessing the network through the second authentication entity and reducing the delay in changing the authentication entity.

[0302] When the second authentication entity is an indirect authentication entity, the second authentication entity may be deployed at a relatively close distance to the first terminal, which may also reduce the delay in changing the authentication entity.

[0303] When the second authentication entity is an indirect authentication entity, the second authentication entity may not limit the operator to be accessed by the first terminal, so that the first terminal can select the operator to be accessed.

[0304] When the second authentication entity is an indirect authentication entity, the second authentication entity can be deployed in an access network device or an edge computing node. Compared with deploying all authentication entities in the core network device, it can alleviate the pressure on the core network device. In addition, it can eliminate malicious first terminals before the first terminal accesses the core network, thereby ensuring the security of the core network.

[0305] Next, a method for the first authentication entity to determine whether to generate a first request message is introduced in detail.

[0306] In a possible implementation, after determining that the coverage area of ​​the first authentication entity is updated, or after determining that the network capability of the first authentication entity is updated, the first authentication entity may decide to change the authentication entity, and then determine whether to generate the first request message.

[0307] In this implementation, assuming that the first authentication entity is a wireless access network device, the method for the first authentication entity to determine whether to generate a first request message may be as shown in FIG. 6 .

[0308] S601: A first terminal performs cell measurement to obtain a measurement result, where the measurement result includes a signal quality of a cell corresponding to at least one network device.

[0309] S602: The first terminal determines measurement report information based on the measurement result, where the measurement report information includes identity information of the second authentication entity.

[0310] In this method, the second authentication entity may be a network device, such as a base station.

[0311] In this method, the identity information of the second authentication entity may include the scID of the second authentication entity.

[0312] In this method, the first terminal may determine the network device whose signal quality reaches a preset threshold based on the measurement result, and then determine the second authentication entity based on the network device whose signal quality reaches the preset threshold.

[0313] Optionally, the number of network devices whose signal quality reaches the preset threshold may be one. In this case, the first terminal may determine the network device whose signal quality reaches the preset threshold as the second authentication entity.

[0314] Optionally, there may be multiple network devices whose signal quality reaches the preset threshold. In this case, the first terminal may determine each of the multiple network devices as a candidate second authentication entity, and then determine the one with the strongest signal quality among the multiple candidate second authentication entities as the second authentication entity.

[0315] In the method, the identity information of the second authentication entity is used to indicate that the first terminal can access the second authentication entity.

[0316] Optionally, in some embodiments, the measurement report information may include information that the first terminal can access the second authentication entity.

[0317] Optionally, the measurement report information may further include operator information of the second authentication entity.

[0318] The operator information of the second authentication entity may indicate the operator to which the second authentication entity belongs. Optionally, the number of operators to which the second authentication entity belongs may be at least one.

[0319] The identity information of the second authentication entity and the operator to which the second authentication entity belongs may be configured in advance for the first terminal, or may be broadcast in advance by the second authentication entity.

[0320] Optionally, the measurement report information may also include blockchain information of the second authentication entity.

[0321] Among them, the blockchain information of the second authentication entity can indicate the chain identifier of the blockchain to which the second authentication entity belongs.

[0322] S603: The first terminal sends measurement report information to the first authentication entity. Correspondingly, the first authentication entity receives the measurement report information.

[0323] Optionally, in some embodiments, the first terminal may further directly send the measurement result to the first authentication entity, and the first authentication entity may then determine the second authentication entity based on the measurement result. The method for the first authentication entity to determine the second authentication entity based on the measurement result may refer to the aforementioned method for the first terminal to determine the second authentication entity based on the measurement result, and will not be repeated here.

[0324] S604: The first authentication entity determines whether the first authentication entity and the second authentication entity belong to the same operator. If the first authentication entity and the second authentication entity belong to the same operator, execute S605; if the first authentication entity and the second authentication entity do not belong to the same operator, execute S606.

[0325] The first authentication entity may determine the operator to which the second authentication entity belongs based on the operator information of the second authentication entity, and then determine whether the first authentication entity and the second authentication entity belong to the same operator.

[0326] S605: The first authentication entity determines whether the second authentication entity is trustworthy based on the identity information of the second authentication entity. If the second authentication entity is trustworthy, execute S607; if the second authentication entity is not trustworthy, execute S608.

[0327] In this method, the first authentication entity can determine whether the second authentication entity is trustworthy based on a locally stored list of blockchain nodes. As an example, the first authentication entity can directly query the locally stored list of blockchain nodes to determine whether the second authentication entity is included therein. If the second authentication entity is included in the locally stored list of blockchain nodes of the first authentication entity, the second authentication entity is determined to be trustworthy; otherwise, the second authentication entity is determined to be untrustworthy.

[0328] Optionally, the first authentication entity may also perform a two-way authentication process with the second authentication entity to determine whether the second authentication entity is trustworthy.

[0329] Optionally, the first authentication entity may also determine whether the second authentication entity is trustworthy based on historical two-way authentication results stored locally.

[0330] In step S606, the first authentication entity determines whether it and the second authentication entity belong to the same blockchain. If the first authentication entity and the second authentication entity belong to the same blockchain, the process proceeds to step S607; if the first authentication entity and the second authentication entity do not belong to the same blockchain, the process proceeds to step S608.

[0331] In this method, the first authentication entity can determine the blockchain to which the second authentication entity belongs based on the blockchain information of the second authentication entity, and then determine whether the second authentication entity belongs to the same blockchain.

[0332] Optionally, the first authentication entity may also determine whether the first authentication entity and the second authentication entity are on the same blockchain using a locally stored list of blockchain nodes. As an example, the first authentication entity may directly query the locally stored list of blockchain nodes to determine whether the list contains the second authentication entity. If the locally stored list of blockchain nodes contains the second authentication entity, then the first authentication entity and the second authentication entity are determined to be on the same blockchain; otherwise, then the first authentication entity and the second authentication entity are determined to be not on the same blockchain.

[0333] S607: The first authentication entity generates a first request message.

[0334] In this method, if the first authentication entity determines that the second authentication entity belongs to the same operator or is on the same blockchain, the first authentication entity can determine that the identity of the second authentication entity is legitimate. If the identity of the second authentication entity is determined to be legitimate, a first request message is generated.

[0335] S608: The first authentication entity generates an authentication entity change rejection message, where the authentication entity change rejection message indicates rejection of changing the authentication entity and the reason for rejecting the change of the authentication entity.

[0336] S609: The first authentication entity sends an authentication entity change rejection message to the first terminal.

[0337] In this method, after determining that the coverage area of ​​the first authentication entity has been updated, or after determining that the network capabilities of the first authentication entity have been updated, the first authentication entity may decide to change the authentication entity. Only after determining that the authentication entity has been changed will the first authentication entity generate a first request message. This avoids generating the first request message when a change of the authentication entity is not necessary, avoids unnecessary resource consumption, and helps improve system resource utilization.

[0338] In addition, the first authentication entity can also determine whether the identity of the second authentication entity is legitimate, which can improve user security from the network side and reduce the risk of users accessing a fake base station.

[0339] In another possible implementation, after receiving the second information, the first authentication entity may confirm that the first terminal decides to change the authentication entity, and then further determine whether to generate the first request message.

[0340] In this implementation, the method for the first authentication entity to determine whether to generate the first request message may be as shown in FIG. 7 .

[0341] S701: When the first terminal decides to change the authentication entity, it generates an authentication entity change suggestion message, where the authentication entity change suggestion message is used to suggest changing the authentication entity.

[0342] Optionally, the authentication entity change suggestion message may include second information. The second information may refer to the relevant content in the above embodiment and will not be described in detail here.

[0343] Optionally, the first terminal decides to change the authentication entity when at least one of the following conditions is met: the location of the first terminal is updated, or the access type of the first terminal is updated, or the reception quality of the signal received by the first terminal from the first authentication entity is lower than a first preset threshold, or the reception quality of the signal received by the first terminal from the second authentication entity is higher than a second threshold.

[0344] In this method, when these conditions are met, the first terminal decides to change the authentication entity, which is beneficial to improving the signal reception quality of the first terminal and can also meet the service needs of the first terminal.

[0345] Optionally, the authentication entity change proposal message may also include third information, which includes the operator information of the second authentication entity and / or the blockchain information of the second authentication entity. The operator information of the second authentication entity is used to indicate the operator to which the second authentication entity belongs, and the blockchain information of the second authentication entity can indicate the chain identifier of the blockchain to which the second authentication entity belongs.

[0346] Optionally, the first terminal may perform cell measurement to obtain a measurement result, and then determine measurement report information based on the measurement result. The measurement report information may include identity information of the second authentication entity.

[0347] In this method, the first terminal may determine the network device whose signal quality reaches a preset threshold based on the measurement result, and then determine the second authentication entity based on the network device whose signal quality reaches the preset threshold.

[0348] Optionally, the number of network devices whose signal quality reaches the preset threshold may be one. In this case, the first terminal may determine the network device whose signal quality reaches the preset threshold as the second authentication entity.

[0349] Optionally, there may be multiple network devices whose signal quality reaches the preset threshold. In this case, the first terminal may determine each of the multiple network devices as a candidate second authentication entity, and then determine the one with the strongest signal quality among the multiple candidate second authentication entities as the second authentication entity.

[0350] In the method, the identity information of the second authentication entity is used to indicate that the first terminal can access the second authentication entity.

[0351] Optionally, in some embodiments, the measurement report information may include information that the first terminal can access the second authentication entity.

[0352] Optionally, the measurement report information may further include operator information of the second authentication entity.

[0353] The operator information of the second authentication entity may indicate the operator to which the second authentication entity belongs. Optionally, the number of operators to which the second authentication entity belongs may be at least one.

[0354] The identity information of the second authentication entity and the operator to which the second authentication entity belongs may be configured in advance for the first terminal, or may be broadcast in advance by the second authentication entity.

[0355] Optionally, the measurement report information may also include blockchain information of the second authentication entity.

[0356] Among them, the blockchain information of the second authentication entity can indicate the chain identifier of the blockchain to which the second authentication entity belongs.

[0357] S702: The first terminal sends an authentication entity change suggestion message to the first authentication entity. Correspondingly, the first authentication entity receives the authentication entity change suggestion message.

[0358] In one implementation, the change proposal message includes at least one of the following information: the location of the first terminal is updated, or the access type of the first terminal is updated, or the reception quality of the signal received by the first terminal from the first authentication entity is lower than a first preset threshold, or the reception quality of the signal received by the first terminal from the second authentication entity is higher than a second threshold. In other words, after the first terminal decides to change the authentication entity, it can send at least one of the following information to the first authentication entity: the location of the first terminal is updated, or the access type of the first terminal is updated, or the reception quality of the signal received by the first terminal from the first authentication entity is lower than a first preset threshold, or the reception quality of the signal received by the first terminal from the second authentication entity is higher than a second threshold. Accordingly, after receiving the information, the first authentication entity can determine that the first terminal has decided to change the authentication entity.

[0359] In another implementation, the change proposal message includes information indicating that the first terminal is requesting a change of authentication entity. In other words, after the first terminal decides to change the authentication entity, it may also send a message to the first authentication entity requesting a change of authentication entity. Upon receiving this message, the first authentication entity may confirm the first terminal's decision to change the authentication entity and then obtain the identity information of the second authentication entity.

[0360] As an example, the first authentication entity may store the identity information of a second authentication entity that the first authentication entity trusts. In this way, after the first authentication entity confirms that the first terminal has decided to change the authentication entity, it may obtain the identity information of the second authentication entity based on the identity information of the second authentication entity stored in itself.

[0361] In another implementation, the change proposal message includes the identity information of the second authentication entity. In other words, after the first terminal decides to change the authentication entity, it can send the identity information of the second authentication entity to the first authentication entity. In response, the first authentication entity can receive the identity information of the second authentication entity and then confirm the first terminal's decision to change the authentication entity.

[0362] S703: The first authentication entity determines whether to approve the first terminal to change the authentication entity. If so, S704 is executed; if not, S705 is executed.

[0363] Optionally, when the identity information of the second authentication entity includes the index information corresponding to the identity information of the second authentication entity in the storage system, the first authentication entity can determine whether the first authentication entity and the second authentication entity belong to the same blockchain based on the identity information of the second authentication entity. If the first authentication entity and the second authentication entity belong to the same blockchain, the first authentication entity agrees to the first terminal to change the authentication entity.

[0364] In this method, the first authentication entity may store node information of the blockchain to which the first authentication entity belongs. This node information is used to indicate the device in the blockchain to which the first authentication entity belongs. For example, the first authentication entity may search the node information to determine whether the identity information of the second authentication entity exists. If the identity information of the second authentication entity exists in the node information, it is determined that the first authentication entity and the second authentication entity belong to the same blockchain.

[0365] Optionally, the first authentication entity can also determine the blockchain to which the second authentication entity belongs based on the third information, and then determine whether the first authentication entity and the second authentication entity belong to the same blockchain. If the first authentication entity and the second authentication entity belong to the same blockchain, the first authentication entity determines that the identity of the second authentication entity is legal, and then agrees to the first terminal to change the authentication entity.

[0366] Optionally, the first authentication entity may also determine the operator information of the second authentication entity based on the third information, and then determine whether to approve the change of authentication entity for the first terminal based on the operator information of the second authentication entity. As an example, when the first authentication entity and the second authentication entity belong to the same operator, the first authentication entity determines that the identity of the second authentication entity is legitimate and then approves the change of authentication entity for the first terminal.

[0367] S704: The first authentication entity generates a first request message.

[0368] S705: The first authentication entity generates an authentication entity change rejection message, where the authentication entity change rejection message indicates rejection of changing the authentication entity and the reason for rejecting the change of the authentication entity.

[0369] S706: The first authentication entity sends an authentication entity change rejection message to the first terminal.

[0370] In this method, the first authentication entity can generate the first request message only after confirming, through the received second information, that the first terminal has decided to change the authentication entity. This avoids generating the first request message when there is no need to change the authentication entity, avoids unnecessary resource consumption, and helps improve system resource utilization.

[0371] In this method, the first authentication entity can also determine whether the identity of the second authentication entity is legitimate, which can improve user security from the network side and reduce the risk of users accessing a fake base station.

[0372] In addition, the first terminal can independently decide whether the authentication entity can be changed, which makes it easier to meet the needs of the first terminal.

[0373] In the technical solution of the present application, after receiving the first request message, the second authentication entity may also determine whether it is necessary to initiate authentication for the first terminal.

[0374] In some embodiments, when the second condition is met, the second authentication entity may not initiate authentication for the first terminal. In this case, the first response information may indicate that the second authentication entity agrees to change the authentication entity of the first terminal.

[0375] Among them, the second condition may include at least one of the following conditions: the second authentication entity and the first authentication entity have performed mutual authentication within the first validity period and the authentication results have been saved, the number of users served by the second authentication entity (or the number of terminals served by the second authentication entity) exceeds the threshold, the second authentication entity and the first authentication entity belong to the same operator, the second authentication entity and the first authentication entity are on the same blockchain, the authentication result of the first terminal is within the second validity period, the access type of the first terminal is an emergency type, the delay requirement of the first terminal is lower than the preset delay threshold, the frequency of the first terminal changing the authentication entity exceeds the preset frequency threshold, or the second authentication entity receives a first indication information from the first authentication entity, and the first indication information indicates that the second authentication entity does not need to initiate authentication for the first terminal.

[0376] In a first possible implementation manner, the communication method may be as shown in FIG8 .

[0377] In S801, the first authentication entity sends a first request message to the second authentication entity, and the second authentication entity receives the first request message accordingly.

[0378] In the method, the first request message may include at least one of the following information: identity information of the first terminal, encrypted identity information of the first terminal, or index information corresponding to the identity information of the first terminal in the storage system.

[0379] In S802, the second authentication entity determines to trust the first authentication entity.

[0380] In a possible implementation, when the second authentication entity and the first authentication entity have performed mutual authentication within the first validity period and have saved the authentication results, the second authentication entity may determine that it trusts the first authentication entity and further determine that it is not necessary to initiate authentication for the first terminal.

[0381] In one possible implementation, when the number of users served by the second authentication entity exceeds a threshold, and the second authentication entity confirms that it belongs to the same blockchain as the first authentication entity or the second authentication entity confirms that it belongs to the same operator as the first authentication entity, the second authentication entity can determine that it trusts the first authentication entity, and further determine that there is no need to initiate authentication for the first terminal.

[0382] In S803, the second authentication entity sends a first response message to the first authentication entity, and the first authentication entity receives the first response message accordingly.

[0383] In this implementation, the second authentication entity can trust the first authentication entity. If the authentication entity is subsequently changed, there is no need to initiate authentication on the first terminal. This can avoid repeated authentication, reduce signaling overhead and latency, and ensure user service continuity.

[0384] In a second possible implementation manner, the communication method may be as shown in FIG9 .

[0385] In S901, the first authentication entity sends a first request message to the second authentication entity, and the second authentication entity receives the first request message accordingly.

[0386] In this method, the first request message may include at least one of the following information: identity information of the first terminal, encrypted identity information of the first terminal, index information corresponding to the identity information of the first terminal in the storage system, historical authentication results of the first terminal, authentication records of the first terminal, or index information corresponding to the historical authentication results of the first terminal in the storage system.

[0387] In S902, the second authentication entity determines to trust the authentication result of the first terminal based on the first request message.

[0388] In the method, the authentication result of the first terminal may be an authentication result obtained when one or more third authentication entities authenticate the first terminal. Optionally, the third authentication entity may also be a direct authentication entity or an indirect authentication entity. As an example, the third authentication entity may be an AUSF network element or a wireless access network device.

[0389] Optionally, the one or more third authentication entities may include the first authentication entity.

[0390] In this method, the second authentication entity may first obtain the authentication result of the first terminal, and then determine whether to trust the authentication result of the first terminal.

[0391] Optionally, when the first information in the first request message includes a historical authentication result of the first terminal or an authentication record of the first terminal, the second authentication entity may obtain the authentication result of the first terminal based on the first information.

[0392] Optionally, when the first information in the first request message includes the index information corresponding to the historical authentication results of the first terminal in the storage system, the second authentication entity can obtain the authentication results of the first terminal from the storage system based on the index information corresponding to the historical authentication results of the first terminal in the storage system.

[0393] Optionally, when the first request message includes at least one of the identity information of the first terminal, the encrypted identity information of the first terminal, and the index information corresponding to the identity information of the first terminal in the storage system, the second authentication entity may obtain the authentication result of the first terminal from the third authentication entity. For example, the second authentication entity sends a message to the third authentication entity requesting the authentication result of the first terminal. After receiving the message, the third authentication entity sends the authentication result of the first terminal to the second authentication entity.

[0394] When the second authentication entity and the third authentication entity belong to the same operator or are on the same blockchain, and the authentication result of the first terminal is within the second validity period, the second authentication entity may verify whether the authentication result of the first terminal is signed by a trusted authentication entity. If the authentication result of the first terminal is signed by a trusted authentication entity and the authentication result indicates that the authentication result of the first terminal is successful, the second authentication entity may determine that it is not necessary to initiate authentication for the first terminal.

[0395] The authentication result of the first terminal within the second validity period can be understood as: the time difference between the timestamp of the current time and the timestamp of the authentication result of the first terminal is less than or equal to the second validity period, or the time difference between the timestamp of the current time and the timestamp of the transaction in which the authentication result of the first terminal is located is less than or equal to the second validity period.

[0396] In S903, the second authentication entity sends a first response message to the first authentication entity, and the first authentication entity receives the first response message accordingly.

[0397] In this implementation, the second authentication entity can trust the authentication result of the first terminal. If the authentication entity is subsequently changed, there is no need to initiate authentication on the first terminal. This can avoid unnecessary repeated authentication and ensure the continuity of user services.

[0398] In addition, the second authentication entity also needs to perform signature verification on the authentication result of the first terminal, which can improve security.

[0399] In a third possible implementation, the communication method may be as shown in FIG10 .

[0400] In S1001, a first authentication entity sends a first request message to a second authentication entity, and the second authentication entity receives the first request message accordingly.

[0401] The content of the first request message can refer to the relevant content in the aforementioned embodiment and will not be repeated here.

[0402] In S1002, the first authentication entity sends first indication information to the second authentication entity, where the first indication information indicates that the second authentication entity does not need to initiate authentication for the first terminal. Correspondingly, the second authentication entity receives the first indication information.

[0403] When the access type of the first terminal is emergency, the latency requirement of the first terminal is lower than a preset latency threshold, or the frequency of the first terminal changing authentication entities exceeds a preset frequency threshold, the first authentication entity may send first indication information to the second authentication entity, where the first indication information indicates that the second authentication entity does not need to initiate authentication for the first terminal. After the second authentication entity receives the first indication information, the second authentication entity may determine that it trusts the first terminal and, therefore, does not need to initiate authentication for the first terminal.

[0404] Optionally, the first indication information may be represented by a numerical value. For example, the value of the first indication information may be 1, and the first indication information indicates that no authentication is required for the first terminal.

[0405] Optionally, the value of the first indication information may also be 0. In this case, the first indication information indicates that authentication needs to be initiated for the first terminal.

[0406] Optionally, the first indication information may be carried in the first request message.

[0407] In S1003, the second authentication entity sends a first response message to the first authentication entity, and the first authentication entity receives the first response message accordingly.

[0408] In this implementation, the second authentication entity can trust the first terminal. If a subsequent authentication entity change is detected, there is no need to initiate authentication on the first terminal. This avoids unnecessary repeated authentication and ensures continuity of user service. Furthermore, this method can meet the needs of the first terminal.

[0409] In other embodiments, when the second condition is not met and the identity authentication of the first terminal is not completed, the second authentication entity needs to initiate authentication for the first terminal.

[0410] In some possible implementations, the second authentication entity may also determine a timing for initiating authentication for the first terminal.

[0411] In a possible implementation, the second authentication entity may determine to initiate authentication for the first terminal before the authentication entity is changed. In this case, the communication method may be as shown in FIG11 .

[0412] S1101: A first authentication entity sends a first request message to a second authentication entity. Correspondingly, the second authentication entity receives the first request message.

[0413] The content of the first request message can refer to the relevant content in the aforementioned embodiment and will not be repeated here.

[0414] S1102: The second authentication entity confirms that authentication needs to be initiated for the first terminal based on the first request message.

[0415] The method for the second authentication entity to confirm whether authentication needs to be initiated for the first terminal based on the first request message may refer to the relevant content in the aforementioned embodiment and will not be repeated here.

[0416] S1103: The second authentication entity determines to initiate authentication for the first terminal before the authentication entity is changed.

[0417] Optionally, when the second authentication entity has higher security requirements and a larger workload, or the first authentication entity has a smaller workload, the second authentication entity may determine to initiate authentication on the first terminal before the authentication entity is changed.

[0418] Optionally, the workload of the first authentication entity can be represented by the number of users served by the first authentication entity (ie, the number of terminals served by the first authentication entity). The more users the first authentication entity serves, the greater the workload of the first authentication entity.

[0419] The workload of the second authentication entity can also be characterized by the number of users served by the second authentication entity (ie, the number of terminals served by the second authentication entity). The more users the second authentication entity serves, the greater the workload of the second authentication entity.

[0420] For example, when the number of users served by the second authentication entity exceeds a preset number, or the number of users served by the first authentication entity does not exceed a preset number, the second authentication entity may determine to initiate authentication for the first terminal before the authentication entity is changed.

[0421] S1104: The second authentication entity obtains the identity information of the first terminal.

[0422] In this method, the second authentication entity may obtain the identity information of the first terminal based on the first request message.

[0423] As an example, assuming that the first request message includes direct parameter information, the second authentication entity may obtain the identity information of the first terminal based on the direct parameter information.

[0424] As another example, assuming that the first request message includes indirect parameter information, the second authentication entity may send a message to the first authentication entity requesting the identity information of the first terminal. Accordingly, after receiving the message, the first authentication entity may send the identity information of the first terminal to the second authentication entity.

[0425] S1105: The second authentication entity initiates authentication for the first terminal based on the identity information of the first terminal.

[0426] In this method, the second authentication entity may determine that the first terminal is a terminal requiring authentication based on the identity information of the first terminal, and then initiate authentication for the first terminal.

[0427] In this method, the second authentication entity may obtain authentication parameters or authentication methods based on the identity information of the first terminal, and then initiate authentication for the first terminal based on the authentication parameters or authentication methods.

[0428] As an example, the second authentication entity can obtain file information corresponding to the identity information of the first terminal by parsing the identity information of the first terminal. The file information can be used to store the method for authenticating the first terminal, and then obtain the authentication method from the file information, and initiate authentication for the first terminal based on the obtained authentication method.

[0429] Alternatively, the second authentication entity obtains the authentication method in the file information corresponding to the identity information of the first terminal by parsing the identity information of the first terminal, and initiates authentication on the first terminal based on the authentication method.

[0430] Optionally, the second authentication entity may be a blockchain node. When the second authentication entity is a blockchain node, the identity information of the first terminal and the file information corresponding to the identity information of the first terminal may be stored on the blockchain.

[0431] In this case, the second authentication entity can obtain the file information stored on the blockchain by parsing the identity information of the first terminal, and obtain the authentication method in the file information, and initiate authentication on the first terminal based on the obtained authentication method.

[0432] Alternatively, the second authentication entity may parse the identity information of the first terminal and directly obtain the authentication method from the file information stored on the blockchain, and then initiate authentication on the first terminal based on the authentication method.

[0433] Optionally, the identity information of the first terminal may include the scID of the first terminal.

[0434] Optionally, the authentication method for performing identity authentication on the first terminal may include a symmetric authentication algorithm and an asymmetric authentication algorithm.

[0435] As an example, in a symmetric authentication algorithm, the second authentication entity can first obtain authentication parameters based on the identity information of the first terminal, where the authentication parameters include a challenge value and a first authentication response, and then send the challenge value to the first terminal, and receive a second authentication response generated by the first terminal based on the challenge value and its own preset root key. If the first authentication response and the second authentication response are the same, the authentication of the first terminal is successful.

[0436] As an example, in an asymmetric authentication algorithm, the second authentication entity can obtain the public key of the first terminal, encrypt the generated random number r1 based on the first terminal's public key, and send a first decryption result (i.e., the result obtained by encrypting the random number r1) and the second authentication entity's public key to the first terminal. If the first terminal successfully verifies the second authentication entity's public key, it decrypts the first encryption result using the first terminal's private key to obtain the decrypted random number r1'. In addition, the first terminal also generates a random number r2, encrypts the decrypted random number r1' and the random number r2 using the second authentication entity's public key, and sends a second encryption result (i.e., the result obtained by encrypting the decrypted random number r1' and the random number r2) to the second authentication entity. The second authentication entity then decrypts the second encryption result using its private key to obtain the random number r1' and the random number r2'. If the random number r1' is the same as the random number r1, authentication of the first terminal is successful. At this point, the random number r2' is also the same as the random number r2, and the second authentication entity and the first terminal can use the random number r2 as a key for communication.

[0437] Optionally, the second authentication entity may initiate authentication for the first terminal through the first authentication entity, and the first authentication entity may be used to forward relevant messages between the second authentication entity and the first terminal.

[0438] In this method, the second authentication entity can initiate authentication for the first terminal after obtaining the file information of the first terminal. Even if the operator to which the second authentication entity belongs is not the operator contracted by the first terminal, the first terminal can flexibly access multiple operator networks.

[0439] S1106: The second authentication entity sends a first response message to the first authentication entity. Correspondingly, the first authentication entity receives the first response message.

[0440] In the method, when it is determined that the first terminal authentication is successful, the second authentication entity determines that the first response message indicates that the second authentication entity agrees to change the authentication entity of the first terminal.

[0441] Alternatively, in the case of determining that the first terminal authentication fails, the second authentication entity determines that the first response message indicates that the second authentication entity does not agree to change the authentication entity of the first terminal.

[0442] In this method, the second authentication entity performs identity authentication on the first terminal before changing the authentication entity. This can protect the security of the second authentication entity and effectively avoid the situation where a malicious first terminal and a maliciously controlled first authentication entity jointly deceive the second authentication entity. At the same time, it can ensure that the second authentication entity only provides services to legitimate users, thereby ensuring work efficiency.

[0443] In another possible implementation, the second authentication entity may determine to initiate authentication on the first terminal after the authentication entity is changed. In this case, the communication method may also be as shown in FIG12 .

[0444] S1201: A first authentication entity sends a first request message to a second authentication entity. Correspondingly, the second authentication entity receives the first request message.

[0445] The content of the first request message can refer to the relevant content in the aforementioned embodiment and will not be repeated here.

[0446] S1202: The second authentication entity confirms that authentication needs to be initiated for the first terminal based on the first request message.

[0447] The method for the second authentication entity to confirm whether authentication needs to be initiated for the first terminal based on the first request message may refer to the relevant content in the aforementioned embodiment and will not be repeated here.

[0448] S1203: The second authentication entity determines to initiate authentication for the first terminal after the authentication entity is changed.

[0449] Optionally, when the second authentication entity has lower security requirements and a smaller workload, or the first authentication entity has a larger workload, the second authentication entity may determine to initiate authentication on the first terminal after the authentication entity is changed.

[0450] Optionally, the workload of the first authentication entity can be represented by the number of users served by the first authentication entity (ie, the number of terminals served by the first authentication entity). The more users the first authentication entity serves, the greater the workload of the first authentication entity.

[0451] The workload of the second authentication entity can also be characterized by the number of users served by the second authentication entity (ie, the number of terminals served by the second authentication entity). The more users the second authentication entity serves, the greater the workload of the second authentication entity.

[0452] For example, when the number of users served by the second authentication entity does not exceed a preset number, or the number of users served by the first authentication entity exceeds a preset number, the second authentication entity may determine to initiate authentication for the first terminal after the authentication entity is changed.

[0453] S1204: The second authentication entity sends a first response message to the first authentication entity. Correspondingly, the first authentication entity receives the first response message.

[0454] Optionally, the content in the first response message can refer to the relevant content in the aforementioned embodiment and will not be repeated here.

[0455] S1205: When the first response message indicates that the second authentication entity agrees to change the authentication entity, the first authentication entity sends a second response message to the first terminal. Correspondingly, the first terminal receives the second response message.

[0456] In this method, the content in the second response message can refer to the relevant content in the aforementioned embodiment and will not be repeated here.

[0457] S1206: The first terminal sends an access request message to the second authentication entity. The access request message is used to request access to the second authentication entity.

[0458] Optionally, the content in the access request message can refer to the relevant content in the aforementioned embodiment and will not be repeated here.

[0459] S1207: The second authentication entity obtains the identity information of the first terminal.

[0460] In this method, the method for the second authentication entity to obtain the identity information of the first terminal can be referred to S1104 and will not be repeated here.

[0461] S1208: The second authentication entity initiates authentication for the first terminal based on the identity information of the first terminal.

[0462] In this method, the method for the second authentication entity to initiate authentication on the first terminal can refer to the relevant description in S1105 and will not be repeated here.

[0463] In this method, after the authentication entity is changed, authentication-related messages can be directly transmitted between the second authentication entity and the first terminal, so that the authentication-related messages do not need to be forwarded through the first authentication entity, thereby ensuring the work efficiency of the first authentication entity.

[0464] Optionally, in the technical solution of the present application, when the first authentication entity receives a first response message from the second authentication entity and the first response message indicates that the second authentication entity agrees to change the authentication entity, the first authentication entity may also send the security context of the first authentication entity and the first terminal to the second authentication entity.

[0465] The security context between the first authentication entity and the first terminal may include a security algorithm used when the first authentication entity communicates with the first terminal, such as a key, an encryption algorithm, an integrity protection algorithm, a privacy protection method, and the like.

[0466] Optionally, the security context sent by the first authentication entity to the second authentication entity may be a partial security context. For example, the first authentication entity may not send a key to the second authentication entity, but may send an encryption algorithm, an integrity protection algorithm, or a privacy protection method.

[0467] In this method, the second authentication entity can communicate with the first terminal based on the security context. This not only ensures the security of communication between the second authentication entity and the first terminal, but also avoids the second authentication entity from repeatedly establishing a security context with the first terminal, thereby improving the communication efficiency between the second authentication entity and the first terminal.

[0468] Next, this application will take the first authentication entity as the first wireless access network device, the second authentication entity as the second wireless access network device, and the first wireless access network device and the second wireless access network device both as CU-DU separation architecture as an example to further introduce the solution of this application.

[0469] Figure 13 is a flow chart of a communication method according to an embodiment of the present application. In the method, the first radio access network device may include DU1 and CU-CP1, and the second radio access network device may include DU2 and CU-CP2.

[0470] S1301. The first terminal determines measurement report information.

[0471] In this method, the content included in the measurement report information and the method for the first terminal to determine the measurement report information can refer to the relevant content in the aforementioned embodiment and will not be repeated here.

[0472] S1302: The first terminal sends measurement report information to DU1 in the first radio access network device. Correspondingly, DU1 in the first radio access network device receives the measurement report information.

[0473] S1303: DU1 in the first radio access network device sends measurement report information to CU-CP1 in the first radio access network device. Correspondingly, CU-CP1 in the first radio access network device receives the measurement report information.

[0474] S1304: CU-CP1 in the first radio access network device generates a first request message based on the measurement report information.

[0475] In this method, the content included in the first request message can refer to the relevant content of the aforementioned embodiment and will not be repeated here.

[0476] In this method, the method for the CU-CP1 in the first radio access network device to generate the first request message based on the measurement report information can refer to the method for the first authentication entity to generate the first request message in the aforementioned embodiment, which will not be repeated here.

[0477] S1305: CU-CP1 in the first radio access network device sends a first request message to CU-CP2 in the second radio access network device. Correspondingly, CU-CP2 in the second radio access network device receives the first request message.

[0478] S1306: The CU-CP2 in the second radio access network device determines whether authentication needs to be initiated for the first terminal. If it is determined that authentication needs to be initiated for the first terminal, S1307 is executed; if it is determined that authentication does not need to be initiated for the first terminal, S1308 is executed.

[0479] In this method, the method for the CU-CP2 in the second wireless access network device to determine whether it is necessary to initiate authentication for the first terminal can refer to the method for the second authentication entity to determine whether it is necessary to initiate authentication for the first terminal in the aforementioned embodiment, which will not be repeated here.

[0480] S1307: CU-CP2 in the second radio access network device initiates authentication for the first terminal.

[0481] In this method, the process of the CU-CP2 in the second radio access network device initiating authentication on the first terminal can refer to the aforementioned embodiment and will not be repeated here.

[0482] S1308: CU-CP2 in the second radio access network device sends a first response message to CU-CP1 in the first radio access network device. The first response message indicates whether CU-CP2 agrees to change the authentication entity of the first terminal.

[0483] In this method, the content of the first response message can refer to the relevant content in the aforementioned embodiment and will not be repeated here.

[0484] S1309: When the first response message indicates that CU-CP2 agrees to change the authentication entity, CU-CP1 in the first radio access network device generates a second response message.

[0485] In this method, the content in the second response message can refer to the relevant content in the aforementioned embodiment and will not be repeated here.

[0486] S1310: CU-CP1 in the first radio access network device sends a second response message to DU1 in the first radio access network device.

[0487] S1311: DU1 in the first radio access network device sends a second response message to the first terminal.

[0488] S1312: The first terminal sends an access request message to DU2 in the second radio access network device. The access request message is used to request access to the second radio access network device.

[0489] In this method, the content in the access request message can refer to the relevant content in the aforementioned embodiment and will not be repeated here.

[0490] Optionally, when the CU-CP2 in the second radio access network device determines that authentication needs to be initiated for the first terminal, it also needs to determine an authentication timing for initiating authentication for the first terminal.

[0491] The method for the CU-CP2 in the second radio access network device to determine the authentication timing for initiating authentication for the first terminal can refer to the method for the second authentication entity to determine re-initiating authentication for the first terminal in the aforementioned embodiment, which will not be repeated here.

[0492] In a possible implementation, assuming that the CU-CP2 in the second radio access network device determines that the authentication timing for initiating authentication for the first terminal is the authentication before the change, S1307 may be located before S1308.

[0493] In another possible implementation, assuming that the CU-CP2 in the second radio access network device determines that the authentication timing for initiating authentication for the first terminal is authentication after the change, S1307 may be located after S1312.

[0494] FIG14 is a schematic diagram of the structure of a communication device provided in one embodiment of the present application. As shown in FIG14 , the communication device 1400 may include a processing module 1401 , a sending module 1402 , and a receiving module 1403 .

[0495] As an example, the communication device 1400 may be used to implement the communication method of the embodiment shown in Figure 5. The processing module 1401 may be used to execute S501 and S504, the sending module 1402 may be used to execute S502 and S505, and the receiving module 1403 may be used to execute S503.

[0496] As another example, the communication device 1400 may be used to implement the communication method of the embodiment shown in Figure 6. The processing module 1401 may be used to execute S603 to S607, the sending module 1402 may be used to execute S608, and the receiving module 1403 may be used to execute S602.

[0497] As another example, the communication device 1400 may be used to implement the communication method of the embodiment shown in Figure 7. The processing module 1401 may be used to execute S703 to S705, the sending module 1402 may be used to execute S706, and the receiving module 1403 may be used to execute S702.

[0498] As another example, the communication device 1400 may be used to implement the communication method of the embodiment shown in Figure 8. The sending module 1402 may be used to execute S801, and the receiving module 1403 may be used to execute S803.

[0499] As another example, the communication device 1400 may be used to implement the communication method of the embodiment shown in Figure 9. The sending module 1402 may be used to execute S901, and the receiving module 1403 may be used to execute S903.

[0500] As another example, the communication device 1400 may be used to implement the communication method of the embodiment shown in Figure 10. The sending module 1402 may be used to execute S1001 and S1002, and the receiving module 1403 may be used to execute S1003.

[0501] As another example, the communication device 1400 may be used to implement the communication method of the embodiment shown in Figure 11. The sending module 1402 may be used to execute S1101, and the receiving module 1403 may be used to execute S1106.

[0502] As another example, the communication device 1400 may be used to implement the communication method of the embodiment shown in Figure 12. The sending module 1402 may be used to execute S1201, and the receiving module 1403 may be used to execute S1204.

[0503] Optionally, the communication device 1400 may be a first authentication entity, or a chip used in the first authentication entity.

[0504] FIG15 is a schematic diagram of the structure of a communication device provided in another embodiment of the present application. As shown in FIG15 , the communication device 1500 may include a receiving module 1501 and a sending module 1502 .

[0505] As an example, the communication device 1500 may be used to implement the communication method of the embodiment shown in Figure 5. The receiving module 1501 may be used to execute S502 and S506, and the sending module 1502 may be used to execute S503.

[0506] Optionally, the communication device 1500 may further include a processing module 1503 .

[0507] As another example, the communication device 1500 may be used to implement the communication method of the embodiment shown in Figure 8. The receiving module 1501 may be used to execute S801, the sending module 1502 may be used to execute S803, and the processing module 1503 may be used to execute S802.

[0508] As another example, the communication device 1500 may be used to implement the communication method of the embodiment shown in Figure 9. The receiving module 1501 may be used to execute S901, the sending module 1502 may be used to execute S903, and the processing module 1503 may be used to execute S902.

[0509] As another example, the communication device 1500 may be used to implement the communication method of the embodiment shown in Figure 10. The receiving module 1501 may be used to execute S1001, the sending module 1502 may be used to execute S1003, and the processing module 1503 may be used to execute S1002.

[0510] As another example, the communication device 1500 may be used to implement the communication method of the embodiment shown in Figure 11. The receiving module 1501 may be used to execute S1101, the sending module 1502 may be used to execute S1106, and the processing module 1503 may be used to execute S1102 to S1105.

[0511] As another example, the communication device 1500 may be used to implement the communication method of the embodiment shown in Figure 12. The receiving module 1501 may be used to execute S1201 and S1206, the sending module 1502 may be used to execute S1204, and the processing module 1503 may be used to execute S1202 to S1203, S1207, and S1208.

[0512] Optionally, the communication device 1500 may be a second authentication entity, or a chip used in the second authentication entity.

[0513] FIG16 is a schematic diagram of the structure of a communication device provided in another embodiment of the present application. As shown in FIG16 , the communication device 1600 may include a sending module 1601 and a receiving module 1602 .

[0514] As an example, the communication device 1600 may be used to implement the communication method of the embodiment shown in Figure 5. The sending module 1601 may be used to execute S506, and the receiving module 1602 may be used to execute S505.

[0515] Optionally, the communication device 1600 may further include a processing module 1603 .

[0516] As another example, the communication device 1600 may be used to implement the communication method of the embodiment shown in Figure 6. The sending module 1601 may be used to execute S602, the receiving module 1602 may be used to execute S608, and the processing module 1603 may be used to execute S601.

[0517] As another example, the communication device 1600 may be used to implement the communication method of the embodiment shown in Figure 7. The sending module 1601 may be used to execute S702, the receiving module 1602 may be used to execute S706, and the processing module 1603 may be used to execute S701.

[0518] As another example, the communication device 1600 may be used to implement the communication method of the embodiment shown in Figure 11. The receiving module 1602 may be used to execute S1106, and the processing module 1603 may be used to execute S1105.

[0519] As another example, the communication device 1600 may be used to implement the communication method of the embodiment shown in Figure 12. The sending module 1601 may be used to execute S1206, the receiving module 1602 may be used to execute S1205, and the processing module 1603 may be used to execute S1208.

[0520] Optionally, the communication device 1600 may be a first terminal, or a chip used in the first terminal.

[0521] Figure 17 is a schematic diagram of the structure of a communication device provided in another embodiment of the present application. As shown in Figure 17, the communication device 1700 includes a processor 1701 and an interface circuit 1702. The processor 1701 and the interface circuit 1702 are coupled to each other. It is understood that the interface circuit 1702 can be a transceiver or an input / output interface. Optionally, the communication device 1700 may also include a memory 1703 for storing instructions executed by the processor 1701, or storing input data required by the processor 1701 to execute instructions, or storing data generated after the processor 1701 executes instructions.

[0522] As a first example, the processor 1701 may be used to implement the functions of the processing module 1401 , and the interface circuit 1702 may be used to implement the functions of the sending module 1402 and the receiving module 1403 .

[0523] In this example, the communication device 1700 may be a first authentication entity, or a chip or a chip system used in the first authentication entity.

[0524] As a second example, the processor 1701 may be used to implement the functions of the processing module 1503 , and the interface circuit 1702 may be used to implement the functions of the receiving module 1501 and the sending module 1502 .

[0525] In this example, the communication device 1700 may be a second authentication entity, or a chip or chip system used in the second authentication entity.

[0526] As a third example, the processor 1701 may be used to implement the functions of the processing module 1603 , and the interface circuit 1702 may be used to implement the functions of the sending module 1601 and the receiving module 1602 .

[0527] In this example, the communication device 1700 may be a first terminal, or a chip or a chip system applied to the first terminal.

[0528] The method steps in the embodiments of the present application can be implemented by hardware or by a processor executing software instructions. The software instructions can be composed of corresponding software modules, which can be stored in a memory or any other form of storage medium well known in the art. An exemplary storage medium is coupled to the processor so that the processor can read information from the storage medium and write information to the storage medium. Of course, the storage medium can also be an integral part of the processor. The processor and the storage medium can be located in an ASIC. In addition, the ASIC can be located in a network device or a terminal. Of course, the processor and the storage medium can also be present in a network device or a terminal as discrete components.

[0529] In the present application, memory may include: cache, random access memory (RAM), flash memory, read-only memory (ROM), synchronous dynamic random access memory (SDRAM), programmable read-only memory, erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory, register, hard disk drive (HDD) or solid-state drive (SSD), mobile hard disk, or portable read-only memory (CD-ROM), etc. Memory is any other medium that can be used to carry or store desired program code in the form of instructions or data structures and can be accessed by a computer, but is not limited to this. The memory in the embodiment of the present application can also be a circuit or any other device that can realize a storage function, for storing computer programs or instructions, and / or data.

[0530] In this application, the processor may be one or more central processing units (CPUs). In the case where the processor is a CPU, the CPU may be a single-core CPU or a multi-core CPU. The processor may be a general-purpose processor, a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a programmable logic device (PLD), a graphics processing unit (GPU), an application-specific integrated circuit, a field programmable gate array or other programmable logic device, a discrete gate or transistor logic device, or a discrete hardware group. A general-purpose processor may be a microprocessor or any conventional processor.

[0531] In the above embodiments, all or part of the embodiments may be implemented using software, hardware, firmware, or any combination thereof. When implemented using software, all or part of the embodiments may be implemented in the form of a computer program product. The computer program product includes one or more computer programs or instructions. When the computer program or instructions are loaded and executed on a computer, the processes or functions described in the embodiments of the present application are performed in whole or in part. The computer may be a general-purpose computer, a special-purpose computer, a computer network, a network device, a user device, or other programmable device. The computer program or instructions may be stored in a computer-readable storage medium or transferred from one computer-readable storage medium to another. For example, the computer program or instructions may be transferred from one website, computer, server, or data center to another website, computer, server, or data center via wired or wireless means. The computer-readable storage medium may be any available medium that can be accessed by a computer or a data storage device such as a server or data center that integrates one or more available media. The available medium may be a magnetic medium, such as a floppy disk, hard disk, or magnetic tape; an optical medium, such as a digital video disk; or a semiconductor medium, such as a solid-state drive.

[0532] An embodiment of the present application also provides a computer-readable storage medium, which stores a computer program or instructions, and the computer program or instructions are executed by a computer (e.g., a processor) to implement part or all of the steps of any method performed by any device in the embodiment of the present application.

[0533] An embodiment of the present application also provides a computer program product including a computer program or a set of instructions, which, when executed on a computer, implements part or all of the steps of any method performed by any device in the embodiment of the present application.

[0534] In the various embodiments of the present application, unless otherwise specified or there is a logical conflict, the terms and / or descriptions between different embodiments are consistent and can be referenced by each other. The technical features in different embodiments can be combined to form new embodiments according to their inherent logical relationships.

[0535] It is understood that the various numbers used in the embodiments of this application are merely for ease of description and are not intended to limit the scope of the embodiments of this application. The order of the sequence numbers of the above-mentioned processes does not necessarily imply a specific order of execution; the order of execution of the processes should be determined by their functions and inherent logic.

Claims

1. A communication method, characterized in that: Applied to a first authentication entity, the first authentication entity being used to perform identity authentication on a terminal, the method comprising: generating a first request message, where the first request message is used to request a change in an authentication entity of the first terminal; Send the first request message to the second authentication entity.

2. The method according to claim 1, characterized in that The first request message carries first information, and the first information includes at least one of the following information: identity information of the first terminal, encrypted identity information of the first terminal, index information corresponding to the identity information of the first terminal in the storage system, historical authentication results of the first terminal, authentication records of the first terminal, or index information corresponding to the historical authentication results of the first terminal in the storage system.

3. The method according to claim 1 or 2, characterized in that Before generating the first request message, the method further includes: It is determined that the coverage area of the first authentication entity is updated, or it is determined that the network capability of the first authentication entity is updated.

4. The method according to claim 1 or 2, characterized in that Before generating the first request message, the method further includes: Receive second information from the first terminal, where the second information indicates at least one of the following information: an update of the location of the first terminal, an update of the access type of the first terminal, a reception quality of a signal from the first authentication entity received by the first terminal is lower than a first preset threshold, a reception quality of a signal from the second authentication entity received by the first terminal is higher than a second preset threshold, the first terminal requests a change of the authentication entity, or identity information of the second authentication entity.

5. The method according to any one of claims 1 to 4, characterized in that The first authentication entity and the second authentication entity belong to the same operator, or the first authentication entity and the second authentication entity are in the same blockchain.

6. The method according to claim 5, characterized in that Before generating the first request message, the method further includes: Receive third information from the first terminal, where the third information includes operator information of the second authentication entity and / or blockchain information of the second authentication entity.

7. The method according to any one of claims 1 to 6, characterized in that The method further comprises: A first response message is received from the second authentication entity, where the first response message indicates whether the second authentication entity agrees to change the authentication entity of the first terminal.

8. The method according to claim 7, characterized in that When the first response message indicates that the second authentication entity agrees to change the authentication entity of the first terminal, the method further includes: A second response message is sent to the first terminal, where the second response message includes at least one of the following information: consent to change the authentication entity of the first terminal, or identity information of the second authentication entity.

9. The method according to any one of claims 1 to 8, characterized in that The method further comprises: When it is determined that the first terminal meets the first condition, first indication information is sent to the second authentication entity, where the first indication information indicates that there is no need to initiate authentication for the first terminal.

10. The method according to claim 9, characterized in that The first condition includes at least one of the following conditions: the access type of the first terminal is an emergency type, the delay requirement of the first terminal is lower than a preset delay threshold, or the frequency of the first terminal changing the authentication entity exceeds a preset frequency threshold.

11. The method according to any one of claims 1 to 10, characterized in that The method further comprises: Sending the security context of the first authentication entity and the first terminal to the second authentication entity.

12. A communication method, characterized in that: Applied to a second authentication entity, the second authentication entity is used to authenticate the identity of the terminal, the method comprising: receiving a first request message from a first authentication entity, where the first request message is used to request a change of the authentication entity of the first terminal; A first response message is sent to the first authentication entity, where the first response message indicates whether the second authentication entity agrees to change the authentication entity of the first terminal.

13. The method according to claim 12, characterized in that The first request message carries first information, and the first information includes at least one of the following information: identity information of the first terminal, encrypted identity information of the first terminal, index information corresponding to the identity information of the first terminal in the storage system, historical authentication results of the first terminal, authentication records of the first terminal, or index information corresponding to the historical authentication results of the first terminal in the storage system.

14. The method according to claim 12 or 13, characterized in that If the second condition is met, the first response message indicates that the second authentication entity agrees to change the authentication entity of the first terminal; Alternatively, when the second condition is not met, the method further includes: Authentication is initiated for the first terminal.

15. The method according to claim 14, characterized in that The second condition includes at least one of the following conditions: the second authentication entity and the first authentication entity have performed mutual authentication within the first validity period and the authentication results have been saved, the number of users served by the second authentication entity exceeds a threshold, the second authentication entity and the first authentication entity belong to the same operator, the second authentication entity and the first authentication entity are on the same blockchain, the authentication result of the first terminal is within the second validity period, the access type of the first terminal is an emergency type, the delay requirement of the first terminal is lower than a preset delay threshold, the frequency of the first terminal changing the authentication entity exceeds a preset frequency threshold, or, receiving first indication information from the first authentication entity, the first indication information indicates that the second authentication entity does not need to initiate authentication for the first terminal.

16. The method according to claim 14 or 15, characterized in that The initiating authentication on the first terminal includes: Acquire identity information of the first terminal based on first information in the first request message, where the identity information of the first terminal includes an identity identifier of the first terminal; Authentication is initiated for the first terminal based on the identity information of the first terminal.

17. The method according to claim 16, characterized in that In the case where the first terminal fails in authentication, the first response message indicates that the second authentication entity does not agree to change the authentication entity of the first terminal; Alternatively, when the first terminal is successfully authenticated, the first response message indicates that the second authentication entity agrees to change the authentication entity of the first terminal.

18. The method according to any one of claims 12 to 17, characterized in that The method further comprises: Receive a security context of the first authentication entity and the first terminal.

19. The method according to any one of claims 12 to 18, characterized in that The method further comprises: When the first response message indicates that the second authentication entity agrees to change the authentication entity of the first terminal, an access request message from the first terminal is received.

20. A communication method, characterized in that: Applied to a first terminal, the method includes: receiving a second response message from the first authentication entity, where the second response message includes at least one of the following information: consent to change the authentication entity of the first terminal, or identity information of the second authentication entity; Send an access request message to the second authentication entity.

21. The method according to claim 20, characterized in that The second response message further includes information about operators that the first terminal can access.

22. The method according to claim 21, characterized in that The access request message also includes the operator that the first terminal requests to access.

23. A communication method, characterized in that: Applied to a first authentication entity, the first authentication entity being used to perform identity authentication on a terminal, the method comprising: An authentication entity change suggestion message is received from the first terminal, where the authentication entity change suggestion message is used to suggest changing the authentication entity.

24. The method according to claim 23, wherein The authentication entity change suggestion message also includes third information, which includes the operator information of the second authentication entity and / or the blockchain information of the second authentication entity. The operator information of the second authentication entity is used to indicate the operator that the first terminal wants to access, and the blockchain information of the second authentication entity is used to indicate the chain identifier of the blockchain to which the second authentication entity belongs.

25. The method according to claim 24, characterized in that If the first authentication entity and the second authentication entity do not belong to the same operator, and the first authentication entity and the second authentication entity are not in the same blockchain, an authentication entity change rejection message is sent to the first terminal, and the authentication entity change rejection message indicates the rejection of changing the authentication entity and the reason for rejecting the change of the authentication entity.

26. The method according to claim 24, characterized in that If the first authentication entity and the second authentication entity belong to the same operator, and / or the first authentication entity and the second authentication entity are in the same blockchain, a first request message is sent to the second authentication entity, where the first request message is used to request a change in the authentication entity of the first terminal.

27. A communication method, characterized in that: Applied to a first terminal, the method includes: An authentication entity change suggestion message is sent to the first authentication entity, where the authentication entity change suggestion message is used to suggest changing the authentication entity.

28. The method according to claim 27, characterized in that When at least one of the following conditions is met, an authentication entity change recommendation message is sent to the first authentication entity: the location of the first terminal is updated, the access type of the first terminal is updated, the reception quality of the signal received by the first terminal from the first authentication entity is lower than a first preset threshold, or the reception quality of the signal received by the first terminal from the second authentication entity is higher than a second preset threshold.

29. The method according to claim 28, characterized in that The method further comprises: An authentication entity change rejection message is received from the first authentication entity, wherein the authentication entity change rejection message indicates rejection of changing the authentication entity and a reason for rejecting the change of the authentication entity.

30. A communication device, characterized in that: The method comprises functional modules for implementing the method according to any one of claims 1 to 29.

31. A communication device, characterized in that: The device comprises a processor for causing the device to perform the method according to any one of claims 1 to 11, or causing the device to perform the method according to any one of claims 12 to 19, or causing the device to perform the method according to any one of claims 20 to 22, or causing the device to perform the method according to any one of claims 23 to 26, or causing the device to perform the method according to any one of claims 27 to 29 by executing a computer program or instruction stored in a memory and / or through a logic circuit.

32. The device according to claim 31, characterized in that The communication device further comprises a memory for storing the computer program or instructions.

33. A computer-readable storage medium, characterized in that The computer-readable storage medium stores computer-executable instructions, which, when executed on a communication device, enable the method of any one of claims 1 to 11 to be implemented, or enable the method of any one of claims 12 to 19 to be implemented, or enable the device to execute the method of any one of claims 20 to 22 to be implemented, or enable the device to execute the method of any one of claims 23 to 26, or enable the device to execute the method of any one of claims 27 to 29.

34. A computer program product, characterized in that The computer program product comprises instructions for implementing the method according to any one of claims 1 to 29.

35. A communication system, characterized in that: The method comprises a first authentication entity and a second authentication entity, wherein the first authentication entity is used to execute the method according to any one of claims 1 to 11 or 23 to 26, and the second authentication entity is used to execute the method according to any one of claims 12 to 19.

Citation Information

Patent Citations

  • Data transmission method, user equipment, related network equipment and storage medium

    CN114245376A

  • Communication method and communication device

    CN115038081A

  • Communication method and communication device

    CN115843027A

  • Communication method, device and system

    CN115884177A

  • Method and system for accessing private network services

    US10959097B1