Authentication method, communication apparatus, storage medium, and computer program product
The authentication situation of the terminal is determined through the first access management network element and the authentication process is triggered, which solves the security risk of abnormal user terminals accessing public land mobile networks and ensures network security.
Patent Information
- Application Number
- PCT/CN2024/123909
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-02-08
- Filing Date
- 2024-10-10
- Publication Date
- 2025-08-14
AI Technical Summary
In the prior art, abnormal user terminals that pass non-public network registration authentication may obtain access to public land mobile networks, resulting in network security risks.
An authentication method is provided, which receives a request message of the second access management network element through the first access management network element, determines the authentication status of the terminal, and triggers the authentication process of the terminal in the first network if necessary, to ensure that only the certified terminal can obtain services.
It effectively avoids the security risks caused by abnormal terminals directly accessing the first network and improves network security.
Smart Images

Figure CN2024123909_14082025_PF_FP_ABST
Abstract
Description
Authentication method, communication device, storage medium, and computer program product
[0001] This application claims priority to Chinese patent application No. 202410178162.8, filed on February 8, 2024, the entire contents of which are incorporated by reference into this application. Technical Field
[0002] The present disclosure relates to the field of communication technology, and in particular to an authentication method, a communication device, a storage medium, and a computer program product. Background Art
[0003] Currently, when a terminal accessing a non-public network is disconnected from an operator network, it can register and authenticate through the non-public network, and directly access the operator network after the non-public network is connected to the operator network.
[0004] Summary of the Invention
[0005] On the one hand, an authentication method is provided, which is applied to a first access management network element. The authentication method includes: receiving a first message sent by a second access management network element, the first message being used to request the first access management network element to provide services for a terminal, and the second access management network element belonging to a second network; based on the first message, determining the authentication status of the terminal; and triggering the authentication process of the terminal in the first network based on whether the terminal completes authentication in the second network or does not complete authentication in the first network.
[0006] In another aspect, an authentication device is provided, applied to a first access management network element. The authentication device includes a receiving module, a determining module, and a processing module. The receiving module is configured to receive a first message sent by a second access management network element, the first message being used to request that the first access management network element provide services for a terminal, the second access management network element belonging to a second network. The determining module is configured to determine, based on the first message, the authentication status of the terminal. The processing module is configured to trigger an authentication process for the terminal in the first network, based on the authentication status, indicating whether the terminal has completed authentication in the second network or has not completed authentication in the first network.
[0007] On the other hand, an authentication method is provided, which is applied to a second access management network element, which belongs to a second network. The authentication method includes: sending a first message to the first access management network element, which is used to request the first access management network element to provide services for the terminal; and receiving a second message sent by the first access management network element, which is a response message to the first message.
[0008] In another aspect, an authentication device is provided for use with a second access management network element (NE), the second access management network element belonging to a second network. The authentication device includes a sending module and a receiving module. The sending module is configured to send a first message to a first access management network element (NE), the first message being a request for the first access management network element to provide a service to a terminal. The receiving module is configured to receive a second message sent by the first access management network element, the second message being a response message to the first message.
[0009] In another aspect, a communication device is provided, comprising: a memory and a processor. The memory is coupled to the processor; the memory is used to store a computer program; and the processor implements the above-mentioned authentication method when executing the computer program.
[0010] On the other hand, a computer-readable storage medium is provided, on which computer program instructions are stored. When the computer program instructions are executed by a processor, the above-mentioned authentication method is implemented.
[0011] In another aspect, a computer program product is provided, comprising computer program instructions that, when executed by a processor, implement the aforementioned authentication method. An embodiment of the present disclosure provides an authentication scheme in which a first access management network element may receive a first message sent by a second access management network element, the first message being used to request that the first access management network element provide services to a terminal, the second access management network element belonging to a second network. The first access management network element determines the authentication status of the terminal based on the first message and, based on the authentication status, completes authentication for the terminal in the second network. Thus, even if the terminal is authenticated only in the second network, the first access management network element will also perform an authentication process for the terminal in the first network before providing services to the terminal. Therefore, the authentication process for the terminal in the first network is triggered both if the terminal has not been authenticated by the first network and if the terminal has been authenticated by the second network. This avoids security risks to the first network caused by the first access management network element directly providing services to a terminal that has been authenticated by the second network if it is an abnormal terminal, thereby more reliably ensuring the network security of the first network. BRIEF DESCRIPTION OF THE DRAWINGS
[0012] In order to more clearly illustrate the technical solutions in the present disclosure, the following briefly introduces the drawings required for use in some embodiments of the present disclosure. Obviously, the drawings described below are only drawings of some embodiments of the present disclosure. For ordinary technicians in this field, other drawings can also be obtained based on these drawings.
[0013] FIG1 is a system architecture diagram according to some embodiments of the present disclosure.
[0014] FIG2 is another system architecture diagram according to some embodiments of the present disclosure.
[0015] FIG3 is a flow chart of an authentication method according to some embodiments of the present disclosure.
[0016] FIG4 is a flowchart of another authentication method according to some embodiments of the present disclosure.
[0017] FIG5 is a flowchart of another authentication method according to some embodiments of the present disclosure.
[0018] FIG6 is a flowchart of another authentication method according to some embodiments of the present disclosure.
[0019] FIG7 is a flowchart of another authentication method according to some embodiments of the present disclosure.
[0020] FIG8 is a flowchart of another authentication method according to some embodiments of the present disclosure.
[0021] FIG9 is a flowchart of another authentication method according to some embodiments of the present disclosure.
[0022] FIG10 is a flowchart of another authentication method according to some embodiments of the present disclosure.
[0023] FIG11 is a flow chart of another authentication method according to some embodiments of the present disclosure.
[0024] FIG12 is a flowchart of another authentication method according to some embodiments of the present disclosure.
[0025] FIG13 is a flow chart of another authentication method according to some embodiments of the present disclosure.
[0026] FIG14 is a flowchart of another authentication method according to some embodiments of the present disclosure.
[0027] FIG15 is a flowchart of another authentication method according to some embodiments of the present disclosure.
[0028] FIG16 is a flowchart of another authentication method according to some embodiments of the present disclosure.
[0029] FIG17 is a schematic structural diagram of an authentication device according to some embodiments of the present disclosure.
[0030] FIG18 is a schematic structural diagram of another authentication device according to some embodiments of the present disclosure.
[0031] FIG19 is a schematic structural diagram of a communication device according to some embodiments of the present disclosure. DETAILED DESCRIPTION
[0032] The following will clearly and completely describe the technical solutions of this disclosure in conjunction with the accompanying drawings. Obviously, the embodiments described are only some of the embodiments of this disclosure, not all of them. All other embodiments derived by persons of ordinary skill in the art based on the embodiments of this disclosure without inventive effort are within the scope of protection of this disclosure.
[0033] It should be noted that, in this disclosure, words such as "exemplary" or "for example" are used to describe examples, illustrations, or explanations. Any embodiment or design described in this disclosure using words such as "exemplary" or "for example" should not be interpreted as being more preferred or advantageous over other embodiments or designs. Rather, the use of words such as "exemplary" or "for example" is intended to present the relevant concepts in a concrete manner.
[0034] In the following, the terms "first," "second," etc. are used for descriptive purposes only and should not be understood as indicating or implying relative importance or implicitly specifying the quantity of the technical features indicated. Thus, a feature described by "first," "second," etc. may explicitly or implicitly include one or more of the features.
[0035] In the description of this disclosure, unless otherwise specified, " / " means "or." For example, A / B can mean A or B. "And / or" in this document is simply used to describe the association relationship between associated objects, indicating that three relationships can exist. For example, A and / or B can mean: A exists alone, A and B exist simultaneously, or B exists alone. In addition, "at least one" means one or more, and "a plurality" means two or more.
[0036] Currently, relevant network architectures include non-public networks (NPNs) and public land mobile networks (PLMNs). A non-public network is a dedicated mobile communications network built for a specific organization or enterprise. A non-public network has independent network elements and can independently handle all services required for user terminals to access the non-public network. Furthermore, a non-public network can establish a connection with a public land mobile network. Consequently, user terminals connected to the non-public network can access the public land mobile network.
[0037] When a user terminal accesses a service, it must register and authenticate before it can access the service. If the non-public network can establish a connection with the public land mobile network, the user terminal completes registration and authentication through the public land mobile network. If the non-public network can disconnect from the public land mobile network, the user terminal can complete registration and authentication through the non-public network. After registration and authentication are completed, the user terminal can access the service through either the non-public network or the public land mobile network.
[0038] However, in the above method, the user terminal that has passed the non-public network registration authentication may be an abnormal user terminal, that is, the user terminal has passed the non-public network registration authentication through abnormal means. In this case, the abnormal user terminal has access rights to the public land mobile network, which may pose a security risk to the public land mobile network.
[0039] To address the above-mentioned issues, embodiments of the present disclosure provide an authentication method in which a first access management network element (NE) may receive a first message sent by a second access management network element (NE), requesting that the first access management network element provide services to a terminal. The second access management network element belongs to a second network. The first access management network element determines the authentication status of the terminal based on the first message, and completes authentication for the terminal in the first network based on the authentication status. In this manner, even if the terminal is authenticated only in the second network, the first access management network element will still perform the authentication process for the terminal in the first network before providing services to the terminal. Therefore, the authentication process for the terminal in the first network is triggered both if the terminal has not been authenticated by the first network and if the terminal has been authenticated by the second network. This avoids security risks to the first network caused by the first access management network element directly providing services to a terminal that has been authenticated by the second network but is considered abnormal, thereby more reliably ensuring the network security of the first network.
[0040] The authentication method provided in the embodiments of the present disclosure can be applied to the communication system shown in Figure 1. As shown in Figure 1, the communication system includes: a first network 101, a second network 102, a terminal 103, a first access management network element 1011, a first data management network element 1012, a first authentication service network element 1013, a second access management network element 1021, and a second data management network element 1022.
[0041] The first network 101 includes a first access management network element 1011 , a first data management network element 1012 , and a first authentication service network element 1013 . The second network 102 includes a second access management network element 1021 and a second data management network element 1022 .
[0042] In an embodiment of the present disclosure, the first access management network element 1011 can receive a first message sent by the second access management network element 1021. The first access management network element 1011 can then determine the authentication status of the terminal 103 based on the first message, and based on the authentication status meeting the preset authentication status, trigger the authentication process of the terminal 103 in the first network 101, so that the first network 101 provides services to the terminal 103 when the terminal has access rights to the first network 101, thereby ensuring the network security of the first network 101.
[0043] The first data management network element 1012 can store the authentication status of the terminal 103 in the first network 101. The first access management network element 1011 can query the authentication status of the terminal 103 in the first network 101 from the first data management network element 1012. The first authentication service network element 1013 can also query the authentication status of the terminal 103 in the first network 101. The second data management network element 1022 can store the authentication status of the terminal 103 in the second network 102. The second access management network element 1021 can query the authentication status of the terminal 103 in the second network 102 from the second data management network element 1022.
[0044] In an exemplary implementation, the first network 101 may be a public land mobile network, the second network 102 may be a non-public network, the first access management network element 1011 or the second access management network element 1021 may be an access and mobility management function network element (AMF), the first data management network element 1012 or the second data management network element 1022 may be a unified data management network element (UDM), and the first authentication service network element 1013 may be an authentication service function network element (AUSF).
[0045] In some embodiments, the above authentication method can also be applied to the communication system shown in Figure 2. As shown in Figure 2, the communication system includes a third network 201, a fourth network 202, a fifth network 203, and a terminal 204. The third network 201 includes a third access management network element 2011, a third data management network element 2012, a third authentication function network element 2013, and a third session management function network element 2014 (session management function, SMF). The fourth network includes a fourth access management network element 2021, a fourth data management network element 2022, a fourth authentication function network element 2023, a fourth session management function network element 2024, a fourth network slice selection function network element 2025 (network slice selection function, NSSF), a fourth network slice-specific authentication and authorization function network element 2026 (network slice-specific authentication and authorization function, NSSAAF), a fourth network slice admission control function network element 2027 (network slice admission control function, NSACF), a fourth application function network element 2028 (application function, AF) and a fourth policy control function network element 2029 (policy control function, PCF). The fifth network 203 includes an access network 2031 (access network, AN), a fifth user plane function network element 2032 (user plane function, UPF) and a data network 2033 (data network, DN).
[0046] The third access management network element 2011 is connected to the third data management network element 2012, the third authentication function network element 2013, the third session management function network element 2014, the terminal 204, and the access network 2031. The third data management network element 2012 is connected to the third authentication function network element 2013 and the third access management network element 2011. The third session management function network element 2014 is connected to the fifth user plane function network element 2032. The terminal 204 is also connected to the access network 2031. The access network 2031 is also connected to the fifth user plane function network element 2032. The fifth user plane function network element 2032 is also connected to the data network 2033. The fourth access management network element 2021 is connected to the fourth data management network element 2022, the fourth authentication function network element 2023, the fourth session management function network element 2024, the fourth network slice selection function network element 2025, the fourth network slice-specific authentication and authorization function network element 2026, the fourth network slice admission control function network element 2027, and the fourth policy control function network element 2029. The fourth data management network element 2022 is also connected to the fourth authentication function network element 2023, the fourth session management function network element 2024, and the fourth network slice-specific authentication and authorization function network element 2026. The fourth session management function network element 2024 is also connected to the fourth network slice admission control function network element 2027 and the fourth policy control function network element 2029. The fourth policy control function network element 2029 is also connected to the fourth application function network element 2028.
[0047] The third access management network element 2011 is configured to provide access and management services for the terminal 204 , and send a message to the fourth access management network element 2021 to request the fourth access management network element 2021 to provide services for the terminal 204 .
[0048] The third data management network element 2012 is used to store the authentication status of the terminal 204 on the third network.
[0049] The third authentication function network element 2013 is configured to query the authentication status of the terminal 204 in the third network 201 from the third data management network element 2012 .
[0050] The third session management function network element 2014 is used for session management and routing user plane data.
[0051] The fourth access management network element 2021 is configured to query the third data management network element 2012 for the authentication status of the terminal 204 in the third network 201 or query the fourth data management network element 2022 for the authentication status of the terminal 204 in the fourth network.
[0052] The fourth data management network element 2022 is configured to store the authentication status of the terminal 204 in the fourth network.
[0053] The fourth authentication function network element 2023 is used to query the authentication status of the terminal 204 in the fourth network from the fourth data management network element 2022.
[0054] The fourth session management function network element 2024 is used to allocate an IP (Internet Protocol) address to the terminal 204 and manage various channels between the terminal 204 and the core network.
[0055] The fourth network slice selection function network element 2025 is used to determine the network slice that the terminal 204 can access based on slice selection auxiliary information, contract information, etc.
[0056] The fourth network-specific slice authentication and authorization function network element 2026 is used to implement separate authentication and authorization for each network slice.
[0057] The fourth network slice admission control function network element 2027 is used to: monitor and control the number of registered terminals on each network slice; monitor and control the number of sessions established on each network slice; and generate network slice usage reports based on event-based network slice status notifications.
[0058] The fourth application function network element 2028 is used to interact with the fourth policy control function network element 2029 and provide business services.
[0059] The fourth policy control function network element 2029 is used to manage network behavior and provide policy rules.
[0060] The access network 2031 is used to enable the terminal 204 to access the core network element.
[0061] The fifth user plane function network element 2032 is configured to route data sent by the terminal to the third network 201 .
[0062] Data network 2033 is used to carry and transmit various forms of data traffic.
[0063] In some embodiments, the access network 2031 may be a radio access network (RAN).
[0064] The application scenarios of the embodiments of the present disclosure are not limited. The system architecture and business scenarios described in the embodiments of the present disclosure are intended to more clearly illustrate the technical solutions of the embodiments of the present disclosure and do not constitute a limitation on the technical solutions provided by the embodiments of the present disclosure. It is known to those skilled in the art that with the evolution of network architecture and the emergence of new business scenarios, the technical solutions provided by the embodiments of the present disclosure are also applicable to similar technical problems.
[0065] The authentication method provided in the embodiments of the present disclosure can be applied to the first access management network element 1011 or the fourth access management network element 2021 in the communication system shown in Figure 1 or Figure 2. Figure 3 provides a flowchart of an authentication method. As shown in Figure 3, the authentication method includes the following S301 to S303.
[0066] In S301, a first access management network element receives a first message sent by a second access management network element.
[0067] The first message is used to request the first access management network element to provide services for the terminal. The second access management network element belongs to the second network.
[0068] It should be understood that the terminal accesses the second network and is served by the second access management network element. When the terminal needs to switch to the first access management network element for service, the second access management network element sends the first message to the first access management network element to request the first access management network element to provide service for the terminal.
[0069] In S302, the first access management network element determines the authentication status of the terminal based on the first message.
[0070] It should be understood that before providing services to the terminal, the first access management network element needs to determine whether providing services to the terminal poses a security risk. At this time, the first access management network element determines the authentication status of the terminal.
[0071] It is understandable that, since the first message is used to request the first access management network element to provide services to the terminal, the first message serves to identify the terminal. That is, the first access management network element can determine the terminal based on the first message, and further, the first access management network element can determine the authentication status of the terminal based on the first message.
[0072] In S303, the first access management network element triggers an authentication process of the terminal in the first network based on the authentication condition meeting a preset authentication condition.
[0073] It should be understood that when the first access management network element determines that the authentication condition meets the preset authentication condition, it means that the terminal needs to go through an authentication process in the first network.
[0074] It is understandable that after the terminal goes through the authentication process in the first network, the first access management network element may determine whether the terminal has the authority to be served by the first access management network element.
[0075] In an exemplary implementation, after the first access management network element determines that the terminal has passed the authentication process in the first network and that the terminal is authorized to be provided with services by the first access management network element, the first access management network element may provide services to the terminal. Therefore, before the first access management network element can provide services to the terminal, it is necessary for the first access management network element to trigger the authentication process for the terminal in the first network.
[0076] In an embodiment of the present disclosure, a first access management network element receives a first message sent by a second access management network element, determines the authentication status of the terminal based on the first message, and triggers the authentication process of the terminal in the first network based on the authentication status meeting the preset authentication status. Since the first message is a request to the first access management network element to provide services to the terminal, the first access management network element needs to determine the authentication status of the terminal. If the authentication request meets the preset authentication status, it means that the first access management network element cannot determine whether there is a security risk in providing services to the terminal. At this time, the first access management network element triggers the authentication process for the terminal in the first network. In this way, through the authentication process for the terminal in the first network, the network security risk brought about by the first access management network element providing services to the abnormal terminal when the terminal may be an abnormal terminal is avoided, thereby reliably ensuring the network security of the first network.
[0077] As shown in FIG4 , in an exemplary implementation, the authentication process of the terminal in the first network includes: S401 to S406 .
[0078] In S401, the terminal sends an authentication request message to a security anchor function (SEAF) network element.
[0079] The authentication request message includes a subscription concealed identifier (SUCI) (or a 5G globally unique temporary identifier (5G-GUTI)). The 5G globally unique temporary identifier may include a user concealed identifier or a user permanent identifier (SUPI)).
[0080] In S402, the security anchor function network element sends a network access and mobility management user equipment (UE) authentication request (Nausf UE authentication authenticate request) message to the authentication service function network element.
[0081] The network access and mobility management terminal authentication and verification request message includes a service network name and a user hidden identifier (or a service network name and a user permanent identifier).
[0082] In S403, the authentication service function network element determines whether the service network name exists in the preset service network names.
[0083] In S404, the authentication service function network element sends a unified data management user terminal authentication obtain request message (Nudm UE authentication get request) to the unified data management network element based on the existence of the service network name in the preset service network names.
[0084] In one implementation, the authentication service function network element sends a network access and mobility management user terminal authentication verification response (Nausf UE authentication authenticate response) message to the security anchor function network element based on the fact that the service network name does not exist in the preset service network names.
[0085] The unified data management user terminal authentication acquisition request message includes the service network name and the user hidden identifier. The network access and mobility management user terminal authentication verification response message includes "unauthorized service network" information.
[0086] In S405, the unified data management network element calls the subscription identifier de-concealing function (SIDF) network element based on the unified data management user terminal authentication acquisition request message including the service network name and the user hidden identifier to obtain the user permanent identifier from the user hidden identifier.
[0087] In S406, the unified data management network element authenticates the terminal based on the authentication rule corresponding to the subscriber data.
[0088] In one implementation, the unified data management network element determines an authentication rule corresponding to the subscribed user data based on the unified data management user terminal authentication acquisition request message including the service network name and the user permanent identifier, and authenticates the terminal based on the authentication rule.
[0089] In some embodiments, the unified data management network element in the authentication process of the terminal in the first network may also be replaced by an authentication credential repository and processing function (ARPF) network element.
[0090] In some embodiments, after or during the authentication process of the terminal in the first network, a process of determining the authentication result of the terminal is further included. As shown in FIG5 , the process of determining the authentication result of the terminal includes: S501 to S503.
[0091] In S501, the authentication service function network element sends a unified data management user terminal authentication result confirmation request message (Nudm UE authentication result confirmation request) to the unified data management network element.
[0092] In S502, the unified data management network element stores the authentication status of the terminal based on the unified data management user terminal authentication result confirmation request message.
[0093] In S503, the unified data management network element sends a unified data management user terminal authentication result confirmation response message (Nudm UE authentication result confirmation response) to the authentication service function network element.
[0094] In combination with FIG3 , as shown in FIG6 , the authentication method provided by the embodiment of the present disclosure further includes S601 .
[0095] In S601, after the authentication process of the terminal in the first network is completed, the first access management network element sends a second message to the second access management network element.
[0096] The second message is a response message to the first message.
[0097] It should be understood that the second message may indicate whether the terminal has passed the authentication of the first network or has failed the authentication of the first network.
[0098] It can be understood that since the first message is a request from the second access management network element to the first access management network element to provide services for the terminal, after the authentication process of the terminal in the first network is completed, a second message can be sent to the second access management network element so that the second access management network element can determine whether the first access management network element can provide services for the terminal.
[0099] In some embodiments, the authentication status information of the terminal in the second network is stored in a second data management network element. The second access management network element, upon receiving the second message, sends an authentication status information deletion request to the second data management network element. The second data management network element deletes the authentication status information of the terminal in the second network based on the authentication status information.
[0100] In an embodiment of the present disclosure, after the authentication process of the terminal in the first network is completed, the first access management network element sends a second message to the second access management network element so that the second access management network element determines whether the first access management network element can provide services for the terminal, so that the second access management network element can send to the terminal: whether the request to the first access management network element to provide services is successful, so as to complete the information interaction process between the terminal and the second access management network element and the information interaction between the second access management network element and the second data management network element.
[0101] The above-mentioned first access management network element determines the authentication status of the terminal based on the first message, which can be implemented based on multiple methods, and the multiple methods will be described below. For example, the multiple methods may include the following five methods: Method 1, when the first authentication indication included in the first message indicates that the terminal has completed authentication in the second network, determine the authentication status of the terminal based on the first data management network element; Method 3, when the first message does not include the first authentication indication, determine the authentication status of the terminal based on the second data management network element; Method 4, when the first authentication indication indicates that the terminal has completed authentication in the first network, determine the authentication status of the terminal based on the first data management network element; Method 5, when the first authentication indication indicates that the terminal has completed authentication in the first network, determine the authentication status of the terminal based on the first authentication service network element.
[0102] Method 1: When the first authentication indicates that the terminal has completed authentication on the second network, determining the authentication status of the terminal.
[0103] In some embodiments, the preset authentication condition is that the terminal completes authentication in the second network. In conjunction with Figure 3 , as shown in Figure 7 , the first access management network element determines the authentication condition of the terminal based on the first message, including S701 .
[0104] In S701, the first access management network element completes authentication for the terminal in the second network based on the first authentication indication included in the first message, and determines that the authentication status is that the terminal completes authentication in the second network.
[0105] The first authentication indication is used to indicate that the terminal has completed authentication in the second network or that the terminal has not completed authentication in the second network.
[0106] It should be understood that the first authentication indication included in the first message indicates that the terminal completes authentication in the second network, and the first access management network element may determine that the authentication status is that the terminal completes authentication in the second network.
[0107] It is understood that the preset authentication condition is that the terminal has completed authentication in the second network, indicating that the terminal is authorized to receive services from the second access management network element. However, the terminal has not completed authentication on the first network, meaning that the terminal may be an abnormal terminal. If the first access management network element provides services to the terminal, it may pose a security risk to the first network. Therefore, after the first access management network element determines that the authentication condition is that the terminal has completed authentication in the second network, the first access management network element may further determine that the authentication condition meets the preset authentication condition.
[0108] In some embodiments, the process of completing the authentication of the terminal in the second network is completed based on the second access management network element and the second authentication service network element, and the second authentication service network element belongs to the second network.
[0109] In some embodiments, the first authentication indication is stored by the second access management network element or obtained by the second access management network element from the second data management network element.
[0110] In the disclosed embodiment, the first access management network element completes authentication for the terminal on the second network based on the first authentication indication included in the first message, and determines that the authentication status is that the terminal has completed authentication in the second network. In this way, the first access management network element can accurately determine the authentication status of the terminal. Furthermore, because the preset authentication status is that the terminal has completed authentication in the second network, the first access management network element can determine that the authentication status satisfies the preset authentication status, thereby triggering the authentication process for the terminal in the first network.
[0111] Method 2: When the first message does not include the first authentication indication, the authentication status of the terminal is determined based on the first data management network element.
[0112] In some embodiments, the preset authentication condition is that the terminal has not completed authentication in the first network. In conjunction with Figure 3, as shown in Figure 8, the first access management network element determines the authentication condition of the terminal based on the first message, including S801 and S802.
[0113] In S801, the first access management network element queries the first data management network element for the authentication status of the terminal based on the fact that the first message does not include the first authentication indication.
[0114] The first authentication indication is used to indicate that the terminal completes authentication in the second network or the terminal does not complete authentication in the second network, and the first data management network element belongs to the first network.
[0115] It should be understood that the first data management network element is used to store the authentication status information of the terminal authenticated by the first network. When the first message does not include the first authentication indication, the first access management network element can query the first data management network element for the authentication status of the terminal.
[0116] In an exemplary implementation, the first access management network element queries the first data management network element for the authentication status of the terminal, including: the first access management network element sends an authentication check message (or an access management registration message) to the first data management network element; the first data management network element sends an authentication check response message (or an access management registration response message) to the first access management network element, and the authentication check response message (or the access management registration response message) includes the authentication status information of the terminal in the first network, and the authentication status information can be one of authentication failure and authentication pass (or can be one of authentication failure, authentication pass and unauthenticated).
[0117] In S802, the first access management network element determines that the authentication status is that the terminal has not completed authentication in the first network based on the fact that the authentication status of the terminal cannot be queried from the first data management network element; or determines that the authentication status is that the terminal has completed authentication in the first network based on the fact that the authentication status of the terminal can be queried from the first data management network element.
[0118] It should be understood that, based on the failure to query the terminal's authentication status from the first data management network element, the first access management network element indicates that the terminal has not been authenticated by the first network. In this case, the first access management network element determines that the authentication status is that the terminal has not completed authentication in the first network. Based on the ability to query the terminal's authentication status from the first data management network element, the first access management network element indicates that the terminal has been authenticated by the first network. In this case, the first access management network element determines that the authentication status is that the terminal has completed authentication in the first network. In this way, if the first message does not include a first authentication indication, the first access management network element can determine the authentication status of the terminal based on the authentication status of the terminal queried from the first data management network element. Furthermore, because the preset authentication status is that the terminal has not completed authentication in the first network, the first access management network element can reliably determine whether the authentication status meets the preset authentication status, and thus the first access management network element can determine whether to trigger the authentication process for the terminal in the first network.
[0119] Method three: when the first message does not include the first authentication indication, the authentication status of the terminal is determined based on the second data management network element.
[0120] In some embodiments, the preset authentication condition is that the terminal completes authentication in the second network. In conjunction with Figure 3 , as shown in Figure 9 , the first access management network element determines the authentication condition of the terminal based on the first message, including S901 and S902 .
[0121] In S901 , the first access management network element queries the second data management network element for the authentication status of the terminal based on the fact that the first message does not include the first authentication indication.
[0122] The first authentication indication is used to indicate that the terminal has completed authentication in the second network or that the terminal has not completed authentication in the second network, and the second data management network element belongs to the second network.
[0123] In S902, the first access management network element determines that the terminal has completed authentication in the second network based on the authentication status of the terminal queried from the second data management network element; or determines that the terminal has completed authentication in the first network based on the authentication status of the terminal that can be queried from the first data management network element.
[0124] In the embodiment of the present disclosure, the first access management network element queries the second data management network element for the authentication status of the terminal based on the fact that the first message does not include the first authentication indication. The first access management network element determines that the authentication status is that the terminal has completed authentication in the second network based on the authentication status of the terminal queried from the second data management network element; or determines that the authentication status is that the terminal has completed authentication in the first network based on the authentication status of the terminal that can be queried from the first data management network element. In this way, when the first message does not include the first authentication indication, the first access management network element can also query the second data management network element for the authentication status of the terminal to determine the authentication status, and since the preset authentication status is that the terminal has completed authentication in the second network, the first access management network element can reliably determine whether the authentication status meets the preset authentication status, thereby determining whether to trigger the authentication process of the terminal in the first network.
[0125] Method 4: When the first authentication indication indicates that the terminal has completed authentication in the first network, the authentication status of the terminal is determined based on the first data management network element.
[0126] In some embodiments, the preset authentication condition is that the terminal has not completed authentication in the first network. In conjunction with Figure 3 , as shown in Figure 10 , the first access management network element determines the authentication condition of the terminal based on the first message, including S1001 and S1002 .
[0127] In S1001, based on the first message including the first authentication indication and the first authentication indication indicating that the terminal has completed authentication in the first network, the first access management network element queries the first data management network element for the authentication status of the terminal.
[0128] The first authentication indication is used to indicate that the terminal has completed authentication in the first network or that the terminal has not completed authentication in the first network; the first data management network element belongs to the first network.
[0129] It should be understood that when the first authentication indicates that the terminal has completed authentication in the first network, the first access management network element queries the first data management network element about the authentication status of the terminal to verify that there is an authentication record for the terminal in the first network, so as to avoid the security risk brought about by the first access management network element directly providing services to the terminal when the information sent by the second access management network element that the terminal has completed authentication in the first network is a false message.
[0130] In S1002, the first access management network element determines that the authentication status is that the terminal has not completed authentication in the first network based on the fact that the authentication status of the terminal cannot be queried from the first data management network element; or determines that the authentication status is that the terminal has completed authentication in the first network based on the fact that the authentication status of the terminal can be queried from the first data management network element.
[0131] In an embodiment of the present disclosure, based on a first message including a first authentication indication and the first authentication indication indicating that the terminal has completed authentication in the first network, the first access management network element queries the first data management network element for the terminal's authentication status. Based on the failure to obtain the terminal's authentication status from the first data management network element, the first access management network element determines that the terminal has not completed authentication in the first network. Based on the ability to obtain the terminal's authentication status from the first data management network element, the first access management network element determines that the terminal has completed authentication in the first network. In this manner, if the first authentication indication indicates that the terminal has completed authentication in the first network, the first access management network element can retrieve the authentication status of the terminal in the first network stored in the first data management network element using the authentication status of the terminal obtained from the first data management network element, thereby determining the authentication status. Furthermore, because the preset authentication status indicates that the terminal has not completed authentication in the first network, the first access management network element can reliably determine whether the authentication status meets the preset authentication condition, thereby determining whether to trigger the authentication process for the terminal in the first network.
[0132] Method 5: When the first authentication indication indicates that the terminal has completed authentication in the first network, the authentication status of the terminal is determined based on the first authentication service network element.
[0133] In some embodiments, the preset authentication condition is that the terminal has not completed authentication in the first network. In conjunction with Figure 3 , as shown in Figure 11 , the first access management network element determines the authentication condition of the terminal based on the first message, including S1101 and S1102 .
[0134] In S1101, the first access management network element queries the first authentication service network element for the authentication status of the terminal based on that the first message includes the first authentication indication and the identifier of the first authentication service network element, and the first authentication indication indicates that the terminal has completed authentication in the first network.
[0135] The first authentication indication is used to indicate that the terminal completes authentication in the first network or the terminal does not complete authentication in the first network, and the first authentication service network element belongs to the first network.
[0136] It should be understood that when the terminal completes the authentication process on the first network for the second access management network element through the first authentication service network element, the first authentication indication sent by the second access management network element to the first access management network element indicates that the terminal has completed authentication in the first network. In this case, the first access management network element can query the first authentication service network element for the terminal's authentication status based on the identifier of the first authentication service network element to determine the terminal's authentication status in the first network. In this way, by verifying the information indicating that the terminal has completed authentication in the first network, the terminal's authentication status in the first network can be reliably determined.
[0137] In S1102, the first access management network element determines that the authentication status is that the terminal has not completed authentication in the first network based on the failure to query the authentication status of the terminal from the first authentication service network element; or determines that the authentication status is that the terminal has completed authentication in the first network based on the authentication status of the terminal queried from the first authentication service network element.
[0138] In an embodiment of the present disclosure, the first access management network element queries the first authentication service network element for the authentication status of the terminal based on the first message including the first authentication indication and the identifier of the first authentication service network element, and the first authentication indication indicates that the terminal has completed authentication in the first network. The first access management network element determines that the authentication status is that the terminal has not completed authentication in the first network based on the failure to query the authentication status of the terminal from the first authentication service network element; or determines that the authentication status is that the terminal has completed authentication in the first network based on the authentication status of the terminal queried from the first authentication service network element.
[0139] In some embodiments, the first access management network element may belong to the first network or the second network. When the first access management network element belongs to the first network, data can be exchanged between the first access management network element and each network element in the first network. When the first access management network element belongs to the second network, the first access management network element may exchange data with each network element in the second network when the first network and the second network are connected.
[0140] The communication method provided in the embodiments of the present disclosure can be applied to the first access management network element in the communication system shown in Figure 1 or the third access management network element in the communication system shown in Figure 2. Figure 12 shows a flow chart of an authentication method. As shown in Figure 12, the authentication method includes the following steps S1201 and S1202.
[0141] In S1201, the second access management network element sends a first message to the first access management network element.
[0142] The first message is used to request the first access management network element to provide services for the terminal.
[0143] In S1202, the second access management network element receives a second message sent by the first access management network element.
[0144] The second message is a response message to the first message.
[0145] It can be understood that the content of S1201 can refer to S301, and the content of S1202 can refer to S601, and the embodiments of the present disclosure will not be repeated here.
[0146] In combination with FIG12 , as shown in FIG13 , the authentication method provided by the embodiment of the present disclosure further includes S1301 .
[0147] In S1301, the second access management network element instructs the second data management network element to delete the authentication status of the terminal based on the second message.
[0148] The second data management network element belongs to the second network.
[0149] It should be understood that the second access management network element's receipt of the second message indicates that the terminal has completed the authentication process on the first network. At this point, the second data management network element deletes the terminal's authentication status. This conserves storage resources within the second data management network element. Furthermore, after the second data management network element deletes the terminal's authentication status, the inability to query the terminal's authentication status on the second data management network element can serve as judgment information in certain processes.
[0150] Figure 14 shows a flowchart of another authentication method applied to the first access management network element in the communication system shown in Figure 1 or the third access management network element in the communication system shown in Figure 2. As shown in Figure 14, the authentication method includes the following S1401 and S1402.
[0151] In S1401, after connecting to the first network, the second access management network element determines the authentication status of the terminal.
[0152] It should be understood that after the second access management network element is connected to any network element in the first network, the second access management network element is connected to the first network.
[0153] In some embodiments, the second access management network element starts a timer and periodically queries whether the first network is connected based on the timer.
[0154] In S1402, the second access management network element completes authentication for the terminal in the second network or fails to complete authentication in the first network based on the authentication situation, and triggers an authentication process of the terminal in the first network.
[0155] It should be understood that if the terminal completes authentication in the second network or fails to complete authentication in the first network, this indicates that there may be a security risk in the first access management network element providing services to the terminal. In this case, the second access management network element triggers the terminal's authentication process in the first network. Thus, if the terminal completes authentication in the second network or fails to complete authentication in the first network, the second access management network element triggers the terminal's authentication process in the first network, causing the first network to authenticate the terminal, thereby ensuring the network security of the first network when the terminal accesses the first network.
[0156] After connecting to the first network, the second access management network element can determine the terminal's authentication status based on a variety of methods, which are described below. For example, the various methods include the following two methods: Method 1, in which the second access management network element determines the terminal's authentication status based on the first data management network element; Method 2, in which the second access management network element determines the terminal's authentication status based on the second data management network element.
[0157] Method 1: The second access management network element determines the authentication status of the terminal based on the first data management network element.
[0158] In some embodiments, as shown in FIG15 in combination with FIG14 , the above-mentioned determination of the authentication status of the terminal includes S1501 and S1502 .
[0159] In S1501, the second access management network element queries the first data management network element for the authentication status of the terminal.
[0160] The first data management network element belongs to the first network.
[0161] In S1502, the second access management network element determines that the authentication status of the terminal is not completed in the first network based on not querying the authentication status of the terminal from the first data management network element.
[0162] In the disclosed embodiment, the second access management network element queries the first data management network element for the terminal's authentication status. Based on the failure to retrieve the terminal's authentication status from the first data management network element, the second access management network element determines that the terminal has not completed authentication in the first network. This allows the second access management network element to accurately and quickly determine the terminal's authentication status through the first data management network element.
[0163] Method 2: The second access management network element determines the authentication status of the terminal based on the second data management network element.
[0164] In some embodiments, as shown in FIG16 in combination with FIG14 , the above-mentioned determination of the authentication status of the terminal includes S1601 and S1602 .
[0165] In S1601, the second access management network element queries the second data management network element for the authentication status of the terminal.
[0166] The second data management network element belongs to the second network.
[0167] In S1602, the second access management network element determines, based on the authentication status of the terminal queried from the second data management network element, that the terminal has completed authentication in the second network.
[0168] In the disclosed embodiment, the second access management network element queries the second data management network element for the terminal's authentication status. Based on the authentication status of the terminal queried from the second data management network element, the second access management network element determines that the terminal has completed authentication in the second network. In this way, the second access management network element can quickly determine the terminal's authentication status through the second data management network element.
[0169] It is understandable that, in order to implement the above functions, the authentication device includes hardware structures and / or software modules corresponding to the execution of each function. Those skilled in the art should easily realize that, in combination with the algorithm steps of each example described in the embodiments of the present disclosure, the present disclosure can be implemented in the form of hardware or a combination of hardware and computer software. Whether a function is executed in the form of hardware or computer software driving hardware depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered to be beyond the scope of the present disclosure.
[0170] The embodiment of the present disclosure can divide the functional modules of the authentication device according to the above-mentioned method embodiment. For example, each functional module can be divided according to each function, or two or more functions can be integrated into one functional module. The above-mentioned integrated module can be implemented in the form of hardware or software. It should be noted that the division of modules in the embodiment of the present disclosure is schematic and is only a logical functional division. In actual implementation, there may be other division methods. The following is an example of dividing each functional module according to each function.
[0171] Figure 17 is a schematic diagram of the structure of an authentication device according to an embodiment of the present disclosure, which can execute the authentication method provided by the above method embodiment. As shown in Figure 17, the authentication device 30, applied to the first access management network element, includes: a receiving module 301, a determining module 302 and a processing module 303.
[0172] The receiving module 301 is configured to receive a first message sent by a second access management network element. The first message is used to request the first access management network element to provide a service for the terminal. The second access management network element belongs to a second network.
[0173] The determination module 302 is configured to determine the authentication status of the terminal based on the first message.
[0174] The processing module 303 is configured to trigger an authentication process of the terminal in the first network based on the authentication status, indicating that the terminal has completed authentication in the second network or has not completed authentication in the first network.
[0175] Figure 18 is a schematic diagram of the structure of another authentication device according to an embodiment of the present disclosure, which can perform the authentication method provided by the above method embodiment. As shown in Figure 18, authentication device 40 is applied to a second access management network element, which belongs to a second network. Authentication device 40 includes a sending module 401 and a receiving module 402.
[0176] The sending module 401 is configured to send a first message to a first access management network element, wherein the first message is used to request the first access management network element to provide a service for the terminal.
[0177] The receiving module 402 is configured to receive a second message sent by the first access management network element, where the second message is a response message to the first message.
[0178] In the case of implementing the functions of the above-mentioned integrated modules in hardware, the embodiments of the present disclosure provide another structure of the communication device involved in the above-mentioned embodiments. As shown in Figure 19, the communication device 50 includes: a processor 502 and a bus 504. In some embodiments, the communication device may also include a memory 501. In some embodiments, the communication device may also include a communication interface 503.
[0179] The processor 502 may implement or execute the various exemplary logic blocks, modules, and circuits described in conjunction with the embodiments of the present disclosure. The processor 502 may be a central processing unit, a general-purpose processor, a digital signal processor, an application-specific integrated circuit, a field programmable gate array, or other programmable logic device, a transistor logic device, a hardware component, or any combination thereof, and may implement or execute the various exemplary logic blocks, modules, and circuits described in conjunction with the embodiments of the present disclosure. The processor 502 may also be a combination that implements computing functions, such as a combination of one or more microprocessors, a combination of a DSP (digital signal processor) and a microprocessor, and the like.
[0180] The communication interface 503 is used to connect to other devices via a communication network, such as Ethernet, wireless access network, or wireless local area network (WLAN).
[0181] The memory 501 may be a read-only memory (ROM) or other type of static storage device that can store static information and instructions, a random access memory (RAM) or other type of dynamic storage device that can store information and instructions, or an electrically erasable programmable read-only memory (EEPROM), a disk storage medium or other magnetic storage device, or any other medium that can be used to carry or store desired program code in the form of instructions or data structures and can be accessed by a computer, but is not limited thereto.
[0182] As an implementation, the memory 501 may exist independently of the processor 502. The memory 501 may be connected to the processor 502 via a bus 504 and used to store instructions or program codes. When the processor 502 calls and executes the instructions or program codes stored in the memory 501, the authentication method provided in the embodiment of the present disclosure can be implemented.
[0183] In another implementation, the memory 501 may also be integrated with the processor 502 .
[0184] Bus 504 can be an Extended Industry Standard Architecture (EISA) bus, etc. Bus 504 can be divided into an address bus, a data bus, a control bus, etc. For ease of illustration, FIG19 shows only one thick line, but this does not mean that there is only one bus or only one type of bus.
[0185] Some embodiments of the present disclosure provide a computer-readable storage medium (e.g., a non-transitory computer-readable storage medium). The computer-readable storage medium stores computer program instructions, which, when executed on a computer, cause the computer to execute the authentication method described in any of the above embodiments.
[0186] Exemplarily, the above-mentioned computer-readable storage media may include, but are not limited to: magnetic storage devices (e.g., hard disks, floppy disks, or magnetic tapes), optical disks (e.g., compact disks (CDs), digital versatile disks (DVDs), etc.), smart cards, and flash memory devices (e.g., erasable programmable read-only memories (EPROMs), cards, sticks, or key drives, etc.). The various computer-readable storage media described in the present disclosure may represent one or more devices and / or other machine-readable storage media for storing information. The term "machine-readable storage medium" may include, but is not limited to, wireless channels and various other media capable of storing, containing, and / or carrying instructions and / or data.
[0187] An embodiment of the present disclosure provides a computer program product comprising instructions. When the computer program product is run on a computer, the computer is enabled to execute the authentication method described in any one of the above embodiments.
[0188] The above is only a specific embodiment of the present disclosure, but the scope of protection of the present disclosure is not limited thereto. Any changes or replacements within the technical scope disclosed in the present disclosure should be included in the scope of protection of the present disclosure. Therefore, the scope of protection of the present disclosure should be based on the scope of protection of the claims.
Claims
1. An authentication method, applied to a first access management network element, comprising: receiving a first message sent by a second access management network element; wherein the first message is used to request the first access management network element to provide services to the terminal; the second access management network element belongs to a second network; Determining an authentication status of the terminal based on the first message; Based on the authentication condition satisfying a preset authentication condition, an authentication process of the terminal in the first network is triggered.
2. The method according to claim 1, further comprising: After the authentication process of the terminal in the first network is completed, a second message is sent to the second access management network element, where the second message is a response message to the first message.
3. The method according to claim 1, wherein The preset authentication condition is that the terminal completes authentication in the second network, and determining the authentication condition of the terminal based on the first message includes: Based on the first authentication indication included in the first message, the terminal completes authentication in the second network, and determines that the authentication status is that the terminal completes authentication in the second network; wherein the first authentication indication is used to indicate that the terminal completes authentication in the second network or that the terminal does not complete authentication in the second network.
4. The method according to claim 1, wherein The preset authentication condition is that the terminal has not completed authentication in the first network, and determining the authentication condition of the terminal based on the first message includes: Based on the fact that the first message does not include a first authentication indication, querying a first data management network element for an authentication status of the terminal; wherein the first authentication indication is used to indicate that the terminal has completed authentication in the second network or that the terminal has not completed authentication in the second network, and the first data management network element belongs to the first network; determining, based on failure to query the authentication status of the terminal from the first data management network element, that the authentication status is that the terminal has not completed authentication in the first network; or Based on the authentication status of the terminal queried from the first data management network element, it is determined that the authentication status is that the terminal has completed authentication in the first network.
5. The method according to claim 1, wherein The preset authentication condition is that the terminal completes authentication in the second network, and determining the authentication condition of the terminal based on the first message includes: Based on the fact that the first message does not include a first authentication indication, querying a second data management network element for an authentication status of the terminal; wherein the first authentication indication is used to indicate that the terminal has completed authentication in the second network or that the terminal has not completed authentication in the second network, and the second data management network element belongs to the second network; Determining, based on the authentication status of the terminal queried from the second data management network element, that the authentication status is that the terminal has completed authentication in the second network; or Based on the authentication status of the terminal queried from the first data management network element, it is determined that the authentication status is that the terminal has completed authentication in the first network.
6. The method according to claim 1, wherein The preset authentication condition is that the terminal has not completed authentication in the first network, and determining the authentication condition of the terminal based on the first message includes: Based on the first message including a first authentication indication and the first authentication indication indicating that the terminal has completed authentication in the first network, the first access management network element queries the first data management network element for an authentication status of the terminal; wherein the first authentication indication is used to indicate that the terminal has completed authentication in the first network or that the terminal has not completed authentication in the first network; and the first data management network element belongs to the first network; determining, based on failure to query the authentication status of the terminal from the first data management network element, that the authentication status is that the terminal has not completed authentication in the first network; or Based on the authentication status of the terminal queried from the first data management network element, it is determined that the authentication status is that the terminal has completed authentication in the first network.
7. The method according to claim 1, wherein The preset authentication condition is that the terminal has not completed authentication in the first network, and determining the authentication condition of the terminal based on the first message includes: Based on the first message including a first authentication indication and an identifier of a first authentication service network element, and the first authentication indication indicating that the terminal has completed authentication in the first network, querying the first authentication service network element for an authentication status of the terminal; wherein the first authentication indication is used to indicate that the terminal has completed authentication in the first network or that the terminal has not completed authentication in the first network; and the first authentication service network element belongs to the first network; determining, based on failure to query the authentication status of the terminal from the first authentication service network element, that the authentication status is that the terminal has not completed authentication in the first network; or Based on the authentication status of the terminal queried from the first authentication service network element, it is determined that the authentication status is that the terminal has completed authentication in the first network.
8. The method according to claim 1, wherein The first access management network element belongs to the first network or the second network.
9. An authentication method, applied to a second access management network element, the second access management network element belonging to a second network, the method comprising: Sending a first message to a first access management network element, where the first message is used to request the first access management network element to provide service to the terminal; Receive a second message sent by the first access management network element, where the second message is a response message to the first message.
10. The method according to claim 9, wherein: The first message includes a first authentication indication, where the first authentication indication is used to indicate that the terminal has completed authentication in the second network or that the terminal has not completed authentication in the second network.
11. The method according to claim 9, wherein The first message also includes an identifier of a first authentication service network element, and the first authentication service network element belongs to the first network.
12. The method according to claim 9, further comprising: Instructing the second data management network element to delete the authentication status of the terminal based on the second message; The second data management network element belongs to the second network.
13. An authentication method, applied to a second access management network element, the second access management network element belonging to a second network, the method comprising: After connecting to the first network, determining the authentication status of the terminal; Based on the authentication situation, whether the terminal completes authentication in the second network or fails to complete authentication in the first network, triggering an authentication process of the terminal in the first network.
14. The method according to claim 13, wherein The determining the authentication status of the terminal includes: querying a first data management network element for an authentication status of the terminal, where the first data management network element belongs to the first network; Based on the failure to query the authentication status of the terminal from the first data management network element, it is determined that the authentication situation is that the terminal has not completed authentication in the first network.
15. The method according to claim 13, wherein The determining the authentication status of the terminal includes: querying a second data management network element for an authentication status of the terminal, where the second data management network element belongs to the second network; Based on the authentication status of the terminal queried from the second data management network element, it is determined that the authentication status is that the terminal has completed authentication in the second network.
16. A communication device comprising: A memory and a processor; wherein the memory is coupled to the processor; the memory is used to store instructions executable by the processor; when the processor executes the instructions, it performs the method according to any one of claims 1-8, or the method according to any one of claims 9-12, or the method according to any one of claims 13-15.
17. A computer-readable storage medium, wherein: The computer-readable storage medium stores computer instructions, which, when executed on a computer, enable the computer to execute the method according to any one of claims 1 to 8, or the method according to any one of claims 9 to 12, or the method according to any one of claims 13 to 15.
18. A computer program product, wherein The computer program product comprises computer program instructions, which, when executed by a processor, cause the processor to perform the method according to any one of claims 1 to 8, or the method according to any one of claims 9 to 12, or the method according to any one of claims 13 to 15.
Citation Information
Patent Citations
Communication method and device
CN114902789A
Access to second network
CN116671183A
Authentication method and device, network equipment and computer storage medium
CN116965075A
Authentication method, communication device, storage medium, and computer program product
CN118055408A
Method and apparatus for switching network
WO2020098609A1